Skip to main content
Category: FedRAMP Program

FedRAMP Low/Moderate/High Baseline

Also known as: FedRAMP Security Control Baselines, FedRAMP Baselines, Low Baseline, Moderate Baseline, High Baseline
Simply put

FedRAMP baselines are predefined sets of security controls that cloud service providers must implement to sell cloud services to U.S. federal agencies, organized into three main tiers, Low, Moderate, and High. Each tier corresponds to how sensitive the government information is and how damaging a security breach could be, with Low being the least sensitive and High the most. A provider generally selects and implements the baseline matching the impact level of the data its service will handle in order to pursue a FedRAMP authorization.

Formal definition

The FedRAMP Low, Moderate, and High baselines are catalogs of security controls that a cloud service offering must implement and have assessed as part of the FedRAMP authorization process, with the applicable baseline determined by the system's impact level. In addition to the three primary baselines, FedRAMP maintains a specialized LI-SaaS (Low-Impact Software-as-a-Service) baseline. As of the applicable revision, the current control baselines reflect FedRAMP Rev. 5, which was approved by the FedRAMP Joint Authorization Board and released in May 2023; associated artifacts such as the Plan of Action and Milestones (POA&M) templates were released for the High, Moderate, and Low baselines under that revision. Practitioners should note that selecting and implementing a baseline is an assessment prerequisite and is distinct from receiving an authorization; the specific control counts, tailoring, and continuous monitoring requirements should be verified against the current authoritative FedRAMP baseline documents, as these change across revisions.

Why it matters

FedRAMP baselines exist because federal agencies increasingly rely on cloud service offerings to handle government data, and the sensitivity of that data varies widely. By defining Low, Moderate, and High tiers, plus the specialized LI-SaaS baseline, FedRAMP gives agencies a standardized way to match the rigor of a cloud service provider's security controls to the potential impact of a compromise. Without such tiering, agencies would have to evaluate each provider ad hoc, and providers would face inconsistent expectations across the federal market. The baselines therefore serve as the common yardstick that makes cloud authorization portable across civilian agencies.

For compliance officers and authorizing officials, the baseline selection is consequential because it determines the scope of controls that must be implemented, assessed, and continuously monitored. Choosing a baseline that is too low for the data a service will process can leave sensitive information under-protected, while over-scoping can impose unnecessary cost and effort. Practitioners should be careful to distinguish two frequently conflated ideas: selecting and implementing a baseline is a prerequisite for assessment, but it is not the same as receiving an authorization. A provider that has implemented the Moderate baseline has not, by that fact alone, achieved a FedRAMP authorization.

Baselines also evolve. The current control baselines reflect FedRAMP Rev. 5, approved by the FedRAMP Joint Authorization Board and released in May 2023, with associated Plan of Action and Milestones (POA&M) templates released for the High, Moderate, and Low baselines under that revision. Because control counts, tailoring decisions, and continuous monitoring requirements change across revisions, treating any baseline as static is a common and avoidable mistake. Readers should verify the applicable controls against the current authoritative FedRAMP baseline documents rather than relying on prior-revision assumptions. It is also worth noting that a FedRAMP authorization addresses federal civilian cloud use and does not automatically satisfy DoD-specific requirements, which readers must confirm separately.

Who it's relevant to

Cloud Service Providers (CSPs)
Providers pursuing the federal market must select the baseline corresponding to the impact level of the data their offering will handle, implement the associated controls, and prepare for assessment. Understanding the distinction between implementing a baseline and achieving an authorization is essential, as is tracking which revision (currently Rev. 5, released May 2023) governs their control set.
Authorizing Officials and Agency Compliance Teams
Agency stakeholders use the baselines to determine whether a cloud service's implemented and assessed controls align with the sensitivity of the data the agency intends to place in it. They should treat any resulting authorization as time-bound and subject to continuous monitoring rather than permanent, and should not assume a FedRAMP authorization satisfies DoD-specific requirements without separate verification.
Assessors (Third-Party Assessment Organizations)
Independent assessors evaluate whether a provider has correctly implemented the controls in the applicable baseline and its environment of operation, and document deficiencies via artifacts such as the POA&M. Assessors must work from the current authoritative baseline documents, since control counts and tailoring change across revisions.
Federal Contractors and Integrators
Organizations building or reselling cloud-based solutions to federal customers need to know which baseline their offering must meet based on the data involved, and should verify current baseline requirements against official FedRAMP sources. They should confirm any additional contractual, DoD, or agency-specific obligations separately, as those fall outside the scope of the FedRAMP civilian baselines.

Inside FedRAMP Low/Moderate/High Baseline

Impact Level Baselines
FedRAMP defines security control baselines corresponding to the FIPS 199 impact levels (Low, Moderate, and High), which reflect the potential adverse impact on organizational operations, assets, or individuals resulting from a loss of confidentiality, integrity, or availability. The applicable baseline is selected based on the categorization of the information handled by the cloud service offering.
Derivation from NIST SP 800-53
FedRAMP baselines are derived from the control catalog in NIST SP 800-53 (as of the applicable revision) and the associated control baselines in NIST SP 800-53B. FedRAMP generally tailors and, in some cases, adds parameters or supplemental controls beyond the corresponding NIST baseline to address cloud-specific risks. Practitioners should verify against the current FedRAMP baseline documents, as control selections change across revisions.
FedRAMP PMO Governance
The FedRAMP baselines and program requirements are maintained by the FedRAMP Program Management Office (PMO). This is distinct from NIST, which issues the underlying SP 800-53 control catalog, and from CISA or agency authorizing officials who play separate roles in the authorization ecosystem.
Low-Impact Scope (including LI-SaaS)
The Low baseline applies to cloud service offerings where the loss of confidentiality, integrity, or availability would generally have a limited adverse impact. FedRAMP has also offered a tailored Low-Impact Software-as-a-Service (LI-SaaS) approach for certain low-risk SaaS offerings, which reduces the applicable control set relative to the full Low baseline.
Moderate-Impact Scope
The Moderate baseline applies where a loss would generally have a serious adverse impact and is commonly used for cloud offerings handling data such as certain non-public information. It contains a substantially larger control set than the Low baseline.
High-Impact Scope
The High baseline applies where a loss would generally have a severe or catastrophic adverse impact, such as offerings supporting sensitive mission or life/safety functions. It represents the most extensive FedRAMP control set.
Authorization Artifacts
Regardless of baseline, a FedRAMP authorization is supported by documentation such as a System Security Plan (SSP), a security assessment conducted by a Third Party Assessment Organization (3PAO), and ongoing continuous monitoring deliverables. The selected baseline determines the scope of controls to be documented and assessed.

Common questions

Answers to the questions practitioners most commonly ask about FedRAMP Low/Moderate/High Baseline.

Does achieving a FedRAMP Moderate or High authorization automatically satisfy DoD requirements for handling CUI?
No. FedRAMP authorization and DoD authorization are distinct processes with different governing authorities. A FedRAMP authorization is issued through the FedRAMP PMO's processes and is generally oriented toward federal civilian agency cloud use, while DoD cloud requirements are governed separately, including DoD-specific security requirements and impact level guidance. A cloud service that holds a FedRAMP Moderate or High authorization may still need to meet additional DoD conditions before it can be used for DoD systems or for handling CUI in a DoD context. Readers should confirm the applicable DoD cloud requirements against current official DoD sources rather than assuming FedRAMP status is sufficient.
Once a cloud service earns a FedRAMP baseline authorization, is that authorization permanent?
No. A FedRAMP authorization, like an Authority to Operate generally, is time-bound and subject to continuous monitoring rather than being permanent. Cloud service providers are generally expected to maintain ongoing monitoring activities and reporting, and the authorizing party retains the ability to reassess the risk posture over time. Meeting a baseline at the point of authorization does not by itself demonstrate ongoing compliance, and it is a common mistake to treat an initial authorization as a lasting guarantee. Readers should verify current continuous monitoring expectations against authoritative FedRAMP sources.
How do I determine which FedRAMP baseline (Low, Moderate, or High) applies to a given system?
The applicable baseline generally corresponds to the impact level determined for the information and system, consistent with the federal categorization approach used for confidentiality, integrity, and availability. In most implementations, the categorization drives which baseline of security controls applies, with higher impact levels associated with more extensive control requirements. Because categorization involves agency judgment and can vary by data type and mission, the specific determination should be confirmed with the responsible authorizing official and against current official categorization guidance rather than assumed.
Where do the security controls in each FedRAMP baseline come from?
The control sets underlying the FedRAMP baselines are drawn from the NIST SP 800-53 catalog maintained by NIST, with FedRAMP-specific selection and tailoring applied through the FedRAMP PMO. It is important not to conflate the NIST source catalog with the FedRAMP baseline itself: FedRAMP applies its own selection, parameters, and additions on top of the NIST controls. Because both the NIST catalog and the FedRAMP baselines change across revisions, readers should confirm which revision applies to their engagement against current authoritative text.
Does meeting a FedRAMP baseline mean a cloud service is secure?
Not necessarily. Meeting a baseline demonstrates that a defined set of controls has been implemented and assessed against the applicable requirements, but compliance and security are not equivalent. A baseline represents a documented control expectation at a point in time and does not guarantee protection against all threats or account for how the service is configured and used by a customer. Organizations generally remain responsible for their portion of shared responsibilities and for ongoing risk management beyond the baseline itself.
What is the difference between assessment and authorization in the FedRAMP baseline process?
Assessment and authorization are distinct steps that should not be confused. Assessment generally refers to evaluating whether the applicable baseline controls are implemented and effective, often performed by an independent assessor. Authorization is the separate decision by the responsible authorizing party to accept the associated risk and permit operation. An assessment produces evidence about control implementation, but it does not by itself constitute permission to operate; that permission comes only through the authorization decision. Readers should verify the specific roles and required deliverables against current FedRAMP guidance.

Common misconceptions

A FedRAMP baseline is identical to the corresponding NIST SP 800-53 baseline.
FedRAMP baselines are derived from NIST SP 800-53 and SP 800-53B but are tailored by the FedRAMP PMO, which may adjust parameters or add controls to address cloud-specific risk. They should be treated as FedRAMP-maintained artifacts, verified against current FedRAMP documentation rather than assumed equivalent to the raw NIST baseline.
A FedRAMP authorization at any baseline automatically satisfies DoD requirements.
FedRAMP authorization does not by itself meet DoD-specific requirements. DoD applies its own processes and impact-level constructs for cloud, and additional requirements may apply for CUI or defense systems. Readers should confirm DoD-specific obligations against current authoritative DoD guidance.
Selecting and meeting a baseline is a one-time compliance milestone.
Compliance with a baseline is not equivalent to security, and an authorization is time-bound and subject to continuous monitoring. Meeting the control set at assessment does not guarantee ongoing security or a permanent authorization; ongoing monitoring and periodic reassessment are generally required.

Best practices

Categorize the information handled by the cloud offering using FIPS 199 before selecting a baseline, and document the rationale so the Low, Moderate, or High selection is defensible to the authorizing official.
Verify the applicable baseline against the current FedRAMP PMO baseline documents and the corresponding NIST SP 800-53 revision, rather than relying on memory or prior-revision control selections.
Confirm whether the tailored LI-SaaS approach genuinely applies before assuming a reduced Low control set, since not all low-risk SaaS offerings qualify.
Do not assume a FedRAMP authorization satisfies DoD, CUI, or other agency-specific requirements; independently confirm additional obligations against current DoD and agency guidance.
Treat the authorization as time-bound and stand up continuous monitoring processes and deliverables from the outset, rather than treating baseline compliance as a one-time event.
Engage an accredited 3PAO and align the System Security Plan to the selected baseline early, so the documented control implementation matches the scope that will actually be assessed.