FedRAMP security controls baseline, explained: What the new 20x Certification Classes changed (and didn't)

Low, Moderate, and High didn't disappear under FedRAMP 20x—they just stopped being certification labels. Here's what’s actually changed.
Mike Kim
Mike Kim
October 6, 2026
15 min read
FedRAMP security controls baseline, explained: What the new 20x Certification Classes changed (and didn't)

TLDR:

  • A FedRAMP baseline still comes from NIST SP 800-53, but Rev5 implements it directly, whereas 20x uses it to build Key Security Indicators.
  • FedRAMP retired its own use of Low, Moderate, and High as certification labels in favor of Certification Classes A through D.
  • The FIPS 199 categorization process itself hasn't changed, and neither has the underlying NIST SP 800-53 catalog it points to.

If your organization is a cloud service provider (CSP) trying to sell into federal agencies, or you're already selling to one and getting asked for your authorization boundary and control documentation for the first time, you're likely pursuing or have already achieved the Federal Risk and Authorization Management Program (FedRAMP) certification. And you can’t achieve that certification without meeting a specific set of baseline security controls to ensure the federal data you’re accessing is secure.

But FedRAMP has been undergoing a major overhaul under FedRAMP 20x, the modern, automated certification program the government introduced to replace the legacy program. The new Consolidated Rules for 2026 (CR26), announced on June 25, 2026, is the regulatory rulebook that defines, governs, and enforces how FedRAMP 20x actually gets implemented. In the past, FedRAMP operated almost entirely through a process called Rev5, with an agency sponsor and a time-consuming, intensive assessment, in which a third-party assessment organization (3PAO) completed evaluations on FedRAMP's behalf. Now, under FedRAMP 20x, much of that same assurance work is expressed as automated, continuously validated evidence rather than long-form narrative documentation, with some paths no longer requiring an agency sponsor to get started.

This is the part that trips most people up: Part of this overhaul changed FedRAMP's impact levels from Low, Moderate, and High to Certification Classes A through D. However, this level name change doesn't touch the underlying Federal Information Processing Standard Publication 199 (FIPS 199) impact categorization, which still determines the actual control baseline a cloud service provider (CSP) is measured against, regardless of which Class ends up on its certification. The confusing part is that FIPS 199 still uses Low, Moderate, and High too—just for something different: Rating the severity of three underlying security objectives (confidentiality, integrity, and availability) that combine to produce your system's overall impact level and, from there, your control baseline.

With so many moving pieces, this piece walks through the FedRAMP security controls baseline, how the new Certification Classes relate to the impact levels they're replacing, how to figure out which one applies to your cloud service, what's inside a baseline, and how that baseline shows up in your certification package.

What is the FedRAMP security controls baseline?

The FedRAMP security controls baseline is the specific set of National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53) controls tied to a cloud service’s FIPS 199 impact categorization. Under the legacy Rev5 process, a cloud service provider (CSP) implements and documents each of these controls directly. Under FedRAMP 20x, the same underlying controls serve as reference material for a set of Key Security Indicators (KSIs) instead, where the KSI is the obligation, not the individual controls it’s built on.

It's the foundation for everything else in the FedRAMP certification process, including your system security plan, security assessment report, and continuous monitoring program.

How FedRAMP layers its own Rules on top of NIST

FedRAMP doesn't invent its own controls from scratch. It adopts the NIST SP 800-53 control catalog as its foundation. Historically, FedRAMP also layered its own assigned parameter values and additional guidance on top of that catalog, but that's also changed recently: As of June 16, 2026, per FedRAMP's own notice of the change, FedRAMP is removing pre-filled defaults and shifting that responsibility onto CSPs, who now set and justify their own parameters directly against NIST's guidance instead. FedRAMP still adds a defined set of FedRAMP Rules that cover requirements uniquely necessary for a cloud service to assure government customers, alongside the underlying NIST controls.

A federal agency reviewing your documentation isn't just checking whether you implemented NIST's version of a control. It's checking whether your own justification for how you implemented that control actually holds up, which puts more responsibility on the CSP than the old pre-filled model did.

One caveat: This control-by-control relationship describes the legacy Rev5 path specifically. Under FedRAMP 20x, a CSP doesn't justify individual control parameters; it supplies evidence against KSIs instead, which reference these same underlying controls without requiring separate implementation of each one.

The difference between FedRAMP Certification Classes and impact levels

It helps to think of Certification Classes and impact levels as two separate questions FedRAMP asks about your cloud service, not two names for the same thing.

  1. How much assurance information have you committed to supplying, and how often do you report it to agencies? That's your Certification Class, brand new under CR26.
  2. How sensitive is the data you handle? That's your impact level, unchanged since FIPS 199 was written.

Certification Classes A through D replace Low, Moderate, and High as the label FedRAMP puts on your certification. But one caution straight from FedRAMP itself: Certification Classes and impact levels aren't meant to be treated as one-for-one replacements. A Certification Class indicates how much assurance a cloud service provides, not an automatic guarantee of the impact level it supports. Agencies still have to determine separately whether a given service fits their specific use case, data, and risk tolerance.

With this in mind, the table below shows how the two “loosely align,” a phrase FedRAMP uses deliberately, since it's explicit that there's no direct correlation between Certification Class and impact level.

Certification Class (under CR26)Impact level (under FIPS 199)
Class ANew entry-level class with no direct legacy equivalent
Class BLow impact
Class CModerate impact
Class DHigh impact

What determines an impact level

Before looking at the Certification Classes themselves, it helps to know what FIPS 199 actually measures. What Certification Classes don't do is describe impact. That rating comes from three security objectives FIPS 199 defines directly.

  • Confidentiality is about who's allowed to see the information, and what happens if it's disclosed to someone who shouldn't have access.
  • Integrity is about whether the information can be trusted, and what happens if it's altered or corrupted without authorization.
  • Availability is about whether the system and its data are accessible when they're needed, and what happens if that access is disrupted.

What each Certification Class actually asks of you

Four Certification Classes now exist, and each asks something different of a cloud service provider.

Class A: The new entry point built on existing security work

This newly added path lets a CSP build on an existing commercial attestation instead of starting a FedRAMP program from scratch, which significantly speeds up the certification process. In fact, FedRAMP's own guidance recommends Class A as the starting point for most CSPs entering the federal market for the first time, since it's built for existing commercial products that already have a SOC 2 Type II certification and a mature security program. See our guide on FedRAMP readiness tools for more on what that path actually involves.

Class B (Low): The standard for public and low-risk data

Class B is generally associated with the legacy Low impact level and applies to publicly available information or systems handling minimal personally identifiable information (PII) beyond what's needed for login, where a security breach would cause only limited adverse effects. A leaner subset, called low-impact software-as-a-service (LI-SaaS), exists for offerings that meet this same low-risk profile, with reduced documentation requirements compared to the standard Low baseline.

Class C (Moderate): The default baseline for most cloud service providers

Class C is generally associated with the legacy Moderate impact level, which covers Controlled Unclassified Information (CUI) and is the most common baseline among CSPs pursuing FedRAMP certification. A security breach at this level is expected to cause serious adverse effects, meaning real but not catastrophic harm to a federal agency's operations, assets, or individuals. If you're building a general-purpose business application for federal customers, this is probably the baseline you're working toward.

Class D (High): When severe impact requires more

Class D is generally associated with the legacy High impact level, where a security breach could cause severe or catastrophic effects. This includes law enforcement, emergency services, and financial systems that support critical infrastructure. It requires the most rigorous control set of the four Classes, and it's also the impact level still tied exclusively to the legacy Rev5 certification, since the 20x path for High-impact systems technically isn't available yet. However, it’s slated for the Phase 4 rollout of FedRAMP 20x, estimated for late 2026 through mid-2027.

Finding your FedRAMP impact level in 3 steps

Figuring out which baseline applies to your cloud service starts with determining your impact level: It’s the fixed set of NIST SP 800-53 controls FedRAMP ties to that impact level, whether you implement them directly or work from them through KSIs. Start with this three-step process straight from FIPS 199.

  1. Identify the types of federal information your system will handle: A system processing routine public information is very different from one processing individually identifiable financial records.
  2. Rate each information type against the three security objectives. Ask what would happen if that information were disclosed without authorization (confidentiality), modified without authorization (integrity), or made inaccessible when needed (availability).
  3. Apply the highest rating across all three objectives, a principle FedRAMP calls the “high-water mark”. If your system is Low for confidentiality and availability but Moderate for integrity, the whole system gets categorized as Moderate. FedRAMP baselines don't allow tailoring based on which specific objective drove the rating.

Inside a FedRAMP baseline: Control families explained

A FedRAMP baseline isn't one long undifferentiated list. It's organized into 20 control families, each covering a distinct area of security practice, from access control to incident response. Note that Program Management (PM) sits outside the baseline. Understanding the structure matters more than memorizing every control, since it's how you'll actually navigate a baseline document once you're implementing one.

These control families are important to keep in mind whether you're on the legacy Rev5 path or working from 20x's KSIs. FedRAMP 20x doesn't invent new categories of security practice. It reframes the same underlying requirements as automatable outcomes rather than narrative documentation, so a KSI covering account management still traces back to the same access control family that a Rev5 provider would document in long form.

For example, the access control family governs who can get into your systems and what they can do once they're in, covering account management, least privilege, and remote access. The configuration management family covers how you establish and maintain secure baseline configurations across your cloud environments, including change management and system inventory. And the assessment, authorization, and monitoring family covers your continuous monitoring obligations, demonstrating that your security posture hasn't drifted since your last formal assessment.

Here’s a breakdown of each control family, listed alphabetically by its corresponding code:

CodeFamilyWhat it coversExampleKSI
ACAccess controlRestricting system access to authorized usersAccount management, least privilege, and remote accessKSI-IAM (Identity and Access Management)
ATAwareness and trainingSecurity training requirements for personnelRole-based training contentKSI-CED (Cybersecurity Education)
AUAudit and accountabilityLogging events and reviewing audit recordsLog retention and reviewKSI-MLA (Monitoring, Logging, and Auditing)
CAAssessment, authorization, and monitoringFormal assessment plus ongoing continuous monitoringAnnual assessment schedulingCCM ruleset
CMConfiguration managementSecure baseline configurations and change trackingChange management processKSI-CMT (Change Management) and KSI-SVC (Service configuration)
CPContingency planningBusiness continuity and disaster recoveryBackup and alternate processing sitesKSI-RPL (Recovery Planning)
IAIdentification and authenticationVerifying identity before granting accessMulti-factor authenticationKSI-IAM (Identity and Access Management)
IRIncident responseDetecting, reporting, and responding to incidentsIncident response plan and trainingKSI-INR (Incident Response)
MAMaintenanceControls over system maintenance activitiesMaintenance tool restrictionsKSI-CMT (Change Management) and KSI-SVC (Service configuration)
MPMedia protectionProtecting digital and physical mediaMedia sanitization procedures-
PEPhysical and environmental protectionPhysical access and environmental safeguardsVisitor logging and fire suppression-
PLPlanningDeveloping and maintaining security plansSystem security plan documentationKSI-SVC (Service Configuration)
PMProgram managementOrganization-wide security program governanceSecurity program resourcingKSI-PIY (Policy and Inventory)
PSPersonnel securityScreening and offboarding personnelBackground checks and access revocationKSI-IAM (Identity and Access Management)
PTPII processing and transparencyHandling personally identifiable informationPrivacy controls and consent-
RARisk assessmentIdentifying and evaluating riskVulnerability detection and scanningKSI-SCR and KSI-IAM
SASystem and services acquisitionSecurity requirements in procurementThird-party contract requirementsKSI-SCR (Supply Chain Risk)
SCSystem and communications protectionProtecting data in transit and at restEncryptionKSI-SVC (Service Configuration)
SISystem and information integrityFlaw remediation and malicious code protectionPatch managementKSI-MLA (Monitoring, Logging, and Auditing)
SRSupply chain risk managementVetting suppliers and third-party componentsVendor risk assessmentKSI-SCR (Supply Chain Risk)

How FedRAMP baselines are evolving right now

The baseline you're implementing today continues to evolve, with a major change announced on June 16, 2026, when FedRAMP published the outcome of RFC-0026 through RFC-0030 in Notice NTC-0013. It is removing most of the control parameter values and control-specific guidance it used to assign on top of NIST SP 800-53. Going forward, CSPs are expected to set and justify their own organization-defined parameters directly against NIST's guidance, rather than working from FedRAMP's pre-filled defaults.

The document set is changing too. The System Security Plan, Security Assessment Report, Control Implementation Summary, and Customer Responsibility Matrix are being replaced by three new documents:

  • A Certification Package Overview, which consolidates information about the cloud service offering and its boundary
  • A Security Decision Record, which consolidates control implementation information across FedRAMP Rules, Rev5 controls, and Key Security Indicators in one place
  • A Secure Configuration Guide, which replaces the old Control Implementation Summary and Customer Responsibility Matrix.

Historically, a FedRAMP baseline document broke each control into a Control ID, a FedRAMP-Defined Assignment or Selection Parameter, and Additional FedRAMP Requirements and Guidance. That structure is largely gone now. Today, a CSP works from the base NIST SP 800-53 control text, plus the FedRAMP Rules described above, with the CSP responsible for justifying its own parameters and documenting the result in the Security Decision Record.

Old FedRAMP documentReplaced byWhat changed
System Security Plan (SSP)Certification Package Overview + Security Decision RecordBoundary and service information split apart from control implementation information
Security Assessment Report (SAR)Security Decision RecordConsolidated with control implementation, now covering FedRAMP Rules, Rev5 controls, and Key Security Indicators together
Control Implementation SummarySecure Configuration GuideReplaced by a flexible format; no longer a fixed template
Customer Responsibility MatrixSecure Configuration GuideSame

CSPs with current FedRAMP Rev5 certifications need to adopt this new approach during their first independent assessment completed after January 1, 2027. If you're early in your FedRAMP journey, it's worth building toward the new structure now rather than documenting against a format that's already being phased out.

Mark your calendars: FedRAMP stops accepting new Rev5 applications on June 11, 2027, and the current rules that govern all FedRAMP practices expire no later than December 31, 2028, after which CSPs will need to comply with whatever the new Consolidated Rules are for 2027 or 2028.

This is one of the more disorienting parts of pursuing FedRAMP certification right now for a small IT team without a dedicated compliance hire. You're not implementing a fixed checklist once. You're implementing a baseline whose underlying documentation model is actively being rebuilt while you work. Mycroft's approach centers on mapping your controls and automating evidence collection across control families, so your team spends less time manually tracking documentation by hand.

Meeting FedRAMP requirements as a cloud service provider

Understanding a baseline conceptually is different from implementing one. In practice, meeting FedRAMP requirements now means doing the following three ongoing activities:

  1. Map your existing security controls against the baseline required by your impact level.
  2. Document and justify your own control parameters and configuration decisions rather than working from FedRAMP-assigned defaults.
  3. Sustain a continuous monitoring program that proves your security posture holds up after certification, not just on the day you were assessed.

Once you know which baseline applies to your cloud service, the next question is whether you're ready to pursue certification against it. See our guide on FedRAMP readiness tools for what that process looks like under the current program.

Your baseline is the starting line

A FedRAMP security controls baseline isn't a one-time checklist you complete and file away. It's the foundation a cloud service provider builds its entire security program on, through certification and well beyond. Everything downstream—your readiness process, your formal assessment, your ongoing continuous monitoring—depends on getting the baseline right at the start. That's true whether the label on top of it says "Moderate" or "Class C".

Not sure which FedRAMP baseline applies to your cloud service? Book a demo to see how Mycroft maps your environment against current FedRAMP control families.

Frequently asked questions (FAQs)

When do I have to switch to the new FedRAMP documentation?

A cloud service provider (CSP) that holds a current FedRAMP Rev5 certification must adopt the new Certification Package structure, Certification Package Overview, Security Decision Record, and Secure Configuration Guide by their first independent assessment completed after January 1, 2027. This doesn’t apply to CSPs pursuing FedRAMP 20x for the first time, since that process uses the new structure from the start.

Have the changes to the FedRAMP certification process affected the security controls baseline?

The underlying control set hasn't changed. The Federal Information Processing Standard Publication 199 (FIPS 199) impact categorization still determines your baseline the same way it always has. What's changed is how FedRAMP layers its own guidance on top of it, and the certification level name itself. As of mid-2026, FedRAMP is removing most of its own assigned control parameters, shifting that responsibility to cloud service providers, and replacing the old System Security Plan and Security Assessment Report with a new Certification Package structure.

How many controls are in the FedRAMP Moderate (Class C) baseline?

The baseline, now labeled Certification Class C (formerly called Moderate), is based on NIST SP 800-53 Revision 5 and includes 287 controls, more than Class B's 149 but fewer than Class D's 370. The exact count you'll need to address can still vary slightly depending on which FedRAMP Rules apply to your specific cloud service.

Is a FedRAMP Certification Class the same as an impact level?

No. An impact level, Low, Moderate, or High, comes from Federal Information Processing Standard Publication 199 (FIPS 199) and describes how sensitive your data is. A Certification Class, A through D, is new under CR26 and describes how much assurance information your cloud service commits to supplying, and how often. FedRAMP itself warns against treating the two as one-for-one replacements: A Class indicates the depth of assurance, not an automatic guarantee of the impact level for which a service is suitable.

What is a FedRAMP control family?

A control family is a category grouping related NIST SP 800-53 controls, such as access control or configuration management. FedRAMP organizes all 20 control families into every baseline. Under the legacy Rev5 process, the specific controls required within each family scale up as impact level increases from Low to Moderate to High. Under FedRAMP 20x, these same control families are represented through Key Security Indicators instead of individual control implementation.

How does Mycroft help cloud service providers manage FedRAMP control baselines?

Mycroft maps a company's existing security controls against its required FedRAMP baseline and automates evidence collection across control families. Mycroft also supports the continuous monitoring that a certified cloud service provider needs to maintain afterward.

We turn the compliance nightmare into a dream

Talk to us