Key Takeaways
- FedRAMP High applies to cloud systems holding data where compromise would be severe or catastrophic, including law enforcement, emergency services, and mission-critical federal information.
- The High baseline requires 410 controls under NIST SP 800-53 Rev 5, compared with 323 at Moderate, and the depth of evidence matters more than the count.
- The 2026 consolidated rules renamed the impact levels as certification Classes A through D, so FedRAMP High is now Class D, and “Authorized” became “Certified.”
- Class D has no FedRAMP 20x path. It still runs through the Rev 5 agency route, which stops accepting new applications on June 11, 2027.
- Hosting in a FedRAMP High environment gives you inherited infrastructure controls. It does not make the application above it certified, and it does not make your own workflows compliant.
- Every remaining FIPS 140-2 certificate moves to NIST’s Historical list on September 21, 2026, so any vendor still citing 140-2 validated cryptography needs a newer answer.
Table of Contents
ToggleFedRAMP High is the most demanding baseline in the federal cloud security program, covering systems where a breach would have a severe or catastrophic effect on agency operations, assets, or individuals. It requires 410 NIST SP 800-53 Rev 5 controls across 17 families. Under the 2026 consolidated rules, it is now called Class D.
FedRAMP High is the baseline most often cited in vendor security pages and most often misread in procurement. The rules behind it changed materially over the past two years, including the removal of the Joint Authorization Board, the arrival of an automated certification path, and a renaming that touches every status you have on file.
This piece covers what the High baseline actually requires, how it compares with Moderate, how certification works now, and where the boundary sits between inherited infrastructure controls and your own responsibilities when regulated documents move between organizations. Product and vendor claims sit at the end, where you can weigh them against the rest.
What FedRAMP High Covers, and What It Is Now Called
FedRAMP High is the baseline for cloud systems where the loss of confidentiality, integrity, or availability would cause severe or catastrophic harm. In practice that covers law enforcement and emergency services data, financial systems central to an agency mission, health records, and information supporting national security functions. The level is assigned through the FIPS 199 categorization of the data, using the high watermark rule, so the most sensitive data type in the system sets the baseline for the whole system.
The naming changed on June 25, 2026, when FedRAMP finalized its Consolidated Rules for 2026. Impact levels became certification classes, and the terms “FedRAMP Authorization” and “FedRAMP Authorized” were retired in favor of “FedRAMP Certification” and “FedRAMP Certified.” If your vendor documentation, contract language, or security questionnaire still uses the old labels, it is not wrong in substance, and it will read as out of date to an assessor.
| Former label | Current label | What it covers |
|---|---|---|
| New in 2026 | Class A | Entry path onto the Marketplace, with no prior equivalent |
| Low | Class B | Limited adverse effect from compromise |
| Moderate | Class C | Serious adverse effect, and the most widely used baseline |
| High | Class D | Severe or catastrophic effect, mission-critical federal data |
Table 1: How the 2026 certification classes map to the impact levels they replaced.
One reason for the change is that the old FIPS 199 labels were routinely confused with Department of Defense impact levels, which use similar language for a different classification scheme. Reading “High” and “IL5” as the same thing has cost more than one procurement team a wasted evaluation cycle.
FedRAMP High Requirements and Controls
The High baseline requires 410 controls drawn from NIST SP 800-53 Rev 5, spanning the same 17 families used at every level. The families most affected by the step up from Moderate are access control, audit and accountability, configuration management, incident response, system and information integrity, personnel security, and media protection. Supply chain risk management joined the baselines in Rev 5 and now carries real weight in assessments.
Control count is the least useful way to understand the tier. What separates High from the levels below it is the parameter values inside shared controls and the volume of evidence required to demonstrate them. Incident response testing runs every six months rather than annually. Audit records are retained longer and reviewed more often. Personnel screening requirements tighten. The operational maturity needed to sustain that year after year is the real cost, and it is why continuous monitoring, rather than the assessment, is where most providers struggle.
| Did You Know
The move to Rev 5 reduced the High baseline from 421 controls to 410, even though NIST added controls overall. FedRAMP removed 60 and added 49, with many of the removed items folded into other controls as parameters rather than dropped. Source: FedRAMP Rev 5 Transition Overview |
FedRAMP Moderate vs High
Moderate, now Class C, covers systems where compromise would cause serious harm, which describes most agency cloud applications and most Controlled Unclassified Information. High covers the systems where harm would be severe or catastrophic. The gap between them is roughly 90 controls, and considerably more than 90 controls worth of work.
| Moderate (Class C) | High (Class D) | |
|---|---|---|
| Data at stake | Serious adverse effect on operations, assets, or individuals | Severe or catastrophic effect, including threats to life or mission failure |
| Controls | 323 under Rev 5 | 410 under Rev 5 |
| Typical use | Most agency SaaS and CUI workloads | Law enforcement, emergency services, national security support, critical infrastructure |
| Certification paths | Rev 5 agency path or the FedRAMP 20x path | Rev 5 agency path only |
| Evidence burden | Rigorous, with a large but manageable artifact set | Deeper testing, tighter parameters, more frequent reviews |
Table 2: FedRAMP Moderate vs High, compared on data sensitivity, controls, and available paths.
The high watermark rule is what usually forces the decision. A system categorized at Moderate for most of its data inherits the High baseline the moment a single high-impact data type enters scope. Moving up after certification means a new assessment against a larger control set, so the categorization conversation belongs at the architecture stage rather than after the first agency asks.
How You Get There Now: Rev 5, 20x, and the Class D Exception
The authorization landscape changed twice in two years, and the sequence matters if you are planning a path.
- The Joint Authorization Board is gone. OMB Memorandum M-24-15 eliminated the JAB and replaced it with the FedRAMP Board, consolidating cloud services under a single designation. JAB prioritization and JAB P-ATO are no longer routes to anything.
- FedRAMP 20x replaced narrative documentation with Key Security Indicators. The 20x path uses automated validation and machine-readable evidence, and it requires no agency sponsor, which removes the barrier that stopped most providers from attempting certification at all.
- Class D has no 20x path. The former High baseline still runs through the Rev 5 agency route with a sponsoring agency and a 3PAO assessment. That route stops accepting new applications on June 11, 2027.
- Work does not transfer between paths. Rev 5 effort does not carry over to 20x, and the reverse is equally true. Choosing the wrong path is expensive rather than merely slow.
For a buyer rather than a provider, the practical takeaway is narrower. A vendor claiming FedRAMP High should be able to name the class, the path, the sponsoring agency, and the current continuous monitoring cadence. A vendor that cannot is describing an environment rather than a certification.
| Common Mistake
Treating a JAB P-ATO reference as current. The Joint Authorization Board was rescinded under OMB M-24-15, and certifications now flow through the Rev 5 agency path or the FedRAMP 20x process. Security documentation that still cites JAB approval has not been reviewed since 2024. Source: FedRAMP Consolidated Rules for 2026 |
What Hosting in a FedRAMP High Environment Does and Does Not Give You
AWS GovCloud (US) is a US-only region set that meets the FedRAMP High baseline at the infrastructure layer, with US persons-only administrative access and support for DoD SRG IL4 and IL5 workloads. Building on it lets an application inherit a large set of platform controls covering physical security, hypervisor isolation, and regional data residency. That inheritance is genuine, and it is bounded.
Three boundaries are worth stating plainly, because vendor pages across this category blur all three:
- Infrastructure certification is not application certification. A SaaS platform hosted in a High environment is not itself FedRAMP Certified unless it completed its own assessment and appears on the Marketplace under its own name.
- A provider’s certification is not your compliance. Inherited controls cover the platform. Your configuration, your permission model, your offboarding process, and your evidence remain yours.
- Aligned is not certified. “FedRAMP High-aligned,” “FedRAMP High-ready,” and “built on FedRAMP High infrastructure” are all different claims from “FedRAMP Certified,” and an assessor will read them as different.
None of that makes inheritance worthless. It means the question to ask is which specific controls you inherit, which you implement, and which you have to evidence yourself, which is exactly the boundary a shared responsibility matrix is supposed to draw.
What This Means for Secure Collaboration on Regulated Data
Controls survive inside a certified system and fail at the point where documents leave it. In defense and government-adjacent work, that point is routine: a prime sending a statement of work to a subcontractor, an assessor collecting evidence, an advisor running diligence on a contractor, a program office circulating drawings. The file passes to a party outside the certification boundary, and the audit trail usually stops there.
| Control family | What it requires | Where document exchange breaks it |
|---|---|---|
| Access Control (AC) | Least privilege and enforced authorization | Folder links shared onward, and access that is never revoked after a program ends |
| Audit and Accountability (AU) | Records of system and user events | Attachments sent by email leave no record of who opened what |
| Media Protection (MP) | Protection of data at rest and in transit | Local copies on reviewer laptops outside any managed environment |
| System and Information Integrity (SI) | Detection of malicious or altered content | Documents returned from an outside party with no scanning or version control |
| Personnel Security (PS) | Screening of those handling controlled data | Access granted to a shared mailbox rather than a named, screened individual |
Table 3: How control families map to the moments when regulated documents move between organizations.
The controls that matter here are the unglamorous ones: access granted to named individuals rather than shared credentials, permissions scoped by program or contract, a complete record of views and downloads that can be exported as evidence, and a way to end access when the work ends. Data privacy practices inside a data room cover the same ground for commercially sensitive material.
| Note
Every remaining FIPS 140-2 certificate moves to NIST’s Historical list on September 21, 2026. Historical modules may stay in existing systems, and they lose standing for new procurements, which matters for any contract clause requiring FIPS-validated cryptography. Source: NIST CMVP FIPS 140-3 transition |
Questions to Ask a Vendor Before You Share Controlled Data
- Are you FedRAMP Certified in your own name, or hosted in a certified environment? Ask for the Marketplace listing if the answer is the first one.
- Which class or baseline, and by which path: Rev 5 agency, or FedRAMP 20x?
- Which controls do we inherit, and which remain ours? Ask for the shared responsibility matrix rather than a summary.
- Are your cryptographic modules covered by a current CMVP certificate, and is it FIPS 140-3?
- Is administrative access restricted to US persons, and is the data resident in a US-only region?
- Can we export a complete access log as evidence, at document and user level, without opening a support ticket?
- What happens to files already downloaded when a contract, program, or user relationship ends?
The last two decide whether a platform produces evidence or merely stores documents. An assessor asking who accessed a specific file in March needs an answer in minutes, not a reconstruction from email.
| Sharing CUI outside your certification boundary?
CapLinked on AWS GovCloud gives defense and government-adjacent teams a US-only workspace with named-user access, exportable logs, and post-download control. Get an Enterprise Quote. |
How CapLinked Supports Compliant Collaboration
CapLinked runs its government deployment on AWS GovCloud (US), the same US-only environment that meets the FedRAMP High baseline at the infrastructure layer and supports ITAR, DFARS, and DoD IL4 and IL5 workloads. To be precise about the boundary described earlier: the platform inherits that infrastructure posture and supports aligned controls, and it does not issue certification, nor does using it make your own program compliant.
What it does provide is control at the point where documents leave your boundary. Workspaces can be organized by program, contract, or subcontractor with least-privilege permissions applied at the folder and document level. Every upload, download, view, and permission change is logged and exportable as a system of record for assessor readiness or an investigation. FileProtect revokes access to files that have already been downloaded, and dynamic watermarking carries viewer identity onto each page. For teams running certification work itself, ConMon workspaces hold system security plans, POA&Ms, scan results, and inventory updates with version history intact, and CMMC document sharing templates carry preconfigured structures for 3PAO and assessor collaboration.
The commercial platform covers the same ground for regulated work outside the defense supply chain, with 256-bit encryption at rest and in transit, enforceable two-factor authentication, IP whitelisting, SAML-based single sign-on, and SOC 2 or SSAE 18 Type II attestation. Full security details and the enterprise feature set are worth checking against your own control matrix rather than a summary. If you want to test the workflow against a real document set, start a 14-day free trial or review the pricing first.
FedRAMP High FAQ
What is FedRAMP High?
FedRAMP High is the federal cloud baseline for systems where compromise would cause severe or catastrophic harm. It requires 410 NIST SP 800-53 Rev 5 controls and is now designated Class D under the 2026 consolidated rules.
How many controls does FedRAMP High require?
410 controls across 17 families under NIST SP 800-53 Rev 5, reduced from 421 under Rev 4. Moderate requires 323 and Low requires 156.
What is the difference between FedRAMP Moderate and High?
Moderate covers serious adverse effects and requires 323 controls. High covers severe or catastrophic effects and requires 410, with stricter parameters, deeper testing, and more frequent reviews.
Who needs FedRAMP High?
Cloud providers serving agencies that handle mission-critical data, including law enforcement, emergency services, national security functions, and critical infrastructure. Their enterprise customers inherit the assurance rather than the certification.
Is there a FedRAMP 20x path for High?
No FedRAMP 20x path exists for Class D, the former High baseline. It runs through the Rev 5 agency authorization path, which closes to new applications on June 11, 2027.
Does hosting on AWS GovCloud make a platform FedRAMP High?
Hosting provides inherited infrastructure controls at the High baseline. The application layer is only certified if it completed its own assessment. CapLinked supports aligned controls and does not issue certification.
How long does FedRAMP High authorization take?
The Rev 5 agency path commonly runs past a year, driven by the system security plan, the 3PAO assessment, and agency review. Continuous monitoring then continues for the life of the service.


