Impact Level (Low/Moderate/High)
An impact level is a rating that describes how much harm could result if a system's information or operations were compromised. There are three levels, Low, Moderate, and High, that reflect increasing potential consequences of a security breach. These ratings help determine how strong a system's security protections need to be.
Impact levels are the three broadly defined categories, Low, Moderate, and High, used to characterize the potential impact of a security breach on an information system, as referenced in the NIST glossary derived from FIPS 200. The impact levels correspond to the potential adverse effect on organizational operations, assets, or individuals, and are generally assessed across the security objectives of confidentiality, integrity, and availability. In cloud contexts, the FedRAMP program (administered by the FedRAMP PMO) categorizes Cloud Service Offerings into one of these three impact levels and assigns a corresponding control baseline; the number of controls generally increases from the Low baseline through Moderate to High, though readers should verify current baseline control counts and tailoring against the applicable authoritative FedRAMP and NIST publications, as these change across revisions. Note that assignment of an impact level is a categorization step and does not by itself constitute an authorization to operate.
Why it matters
Impact level is the foundational categorization step that drives nearly every downstream security decision for a system. Because the required control baseline generally scales upward from Low through Moderate to High, an inaccurate categorization can cascade into either under-protecting a system that handles sensitive information or over-engineering controls for a system that does not warrant them. For compliance officers and information system security managers, getting this rating right at the outset is essential, since it shapes the assessment effort, the resources required, and the expectations of authorizing officials.
In cloud environments, the FedRAMP program (administered by the FedRAMP PMO) uses these same three impact levels to categorize Cloud Service Offerings and assign a corresponding control baseline. This matters directly to government contractors and cloud service providers, because the impact level determines the scope and rigor of the authorization process, a Low categorization is generally narrower in scope and faster to complete, while a High categorization involves substantially more controls and more comprehensive testing and validation.
A common and consequential mistake is treating the assignment of an impact level as if it were itself an authorization. It is not. Categorizing a system as Moderate does not grant an Authority to Operate; it establishes the applicable baseline against which the system must still be assessed and authorized. Experts would also caution readers not to assume that meeting a given impact-level baseline is equivalent to being secure, or that a FedRAMP authorization at a particular impact level automatically satisfies DoD or other agency-specific requirements. Impact level should be understood as a scoping and categorization decision, not an endpoint.
Who it's relevant to
Inside Impact Level (Low/Moderate/High)
Common questions
Answers to the questions practitioners most commonly ask about Impact Level (Low/Moderate/High).