Skip to main content
Category: Risk Assessment & Analysis

Impact Level (Low/Moderate/High)

Also known as: Security Impact Level, FedRAMP Impact Level
Simply put

An impact level is a rating that describes how much harm could result if a system's information or operations were compromised. There are three levels, Low, Moderate, and High, that reflect increasing potential consequences of a security breach. These ratings help determine how strong a system's security protections need to be.

Formal definition

Impact levels are the three broadly defined categories, Low, Moderate, and High, used to characterize the potential impact of a security breach on an information system, as referenced in the NIST glossary derived from FIPS 200. The impact levels correspond to the potential adverse effect on organizational operations, assets, or individuals, and are generally assessed across the security objectives of confidentiality, integrity, and availability. In cloud contexts, the FedRAMP program (administered by the FedRAMP PMO) categorizes Cloud Service Offerings into one of these three impact levels and assigns a corresponding control baseline; the number of controls generally increases from the Low baseline through Moderate to High, though readers should verify current baseline control counts and tailoring against the applicable authoritative FedRAMP and NIST publications, as these change across revisions. Note that assignment of an impact level is a categorization step and does not by itself constitute an authorization to operate.

Why it matters

Impact level is the foundational categorization step that drives nearly every downstream security decision for a system. Because the required control baseline generally scales upward from Low through Moderate to High, an inaccurate categorization can cascade into either under-protecting a system that handles sensitive information or over-engineering controls for a system that does not warrant them. For compliance officers and information system security managers, getting this rating right at the outset is essential, since it shapes the assessment effort, the resources required, and the expectations of authorizing officials.

In cloud environments, the FedRAMP program (administered by the FedRAMP PMO) uses these same three impact levels to categorize Cloud Service Offerings and assign a corresponding control baseline. This matters directly to government contractors and cloud service providers, because the impact level determines the scope and rigor of the authorization process, a Low categorization is generally narrower in scope and faster to complete, while a High categorization involves substantially more controls and more comprehensive testing and validation.

A common and consequential mistake is treating the assignment of an impact level as if it were itself an authorization. It is not. Categorizing a system as Moderate does not grant an Authority to Operate; it establishes the applicable baseline against which the system must still be assessed and authorized. Experts would also caution readers not to assume that meeting a given impact-level baseline is equivalent to being secure, or that a FedRAMP authorization at a particular impact level automatically satisfies DoD or other agency-specific requirements. Impact level should be understood as a scoping and categorization decision, not an endpoint.

Who it's relevant to

Information System Security Managers and Security Officers
These practitioners rely on the impact level to determine the applicable control baseline and the rigor of protections a system requires. Because the categorization drives the scope of assessment and the effort involved, an accurate Low, Moderate, or High determination is central to planning and to setting expectations before authorization.
Cloud Service Providers and Government Contractors
Providers pursuing FedRAMP authorization need to understand which impact level their Cloud Service Offering falls into, since a Low categorization is generally narrower and faster to complete while Moderate and High involve more comprehensive testing and validation. Contractors should confirm that a given impact-level authorization actually meets the requirements of the specific agency or program they are serving, rather than assuming one authorization satisfies all.
Authorizing Officials
Authorizing officials depend on a sound impact-level categorization as the basis for the baseline against which a system is assessed and, ultimately, authorized. They should recognize that assigning an impact level is distinct from granting an authorization to operate, and that categorization alone does not establish that a system is adequately protected.
Auditors and Assessors
Assessors use the impact level to scope their evaluation and to confirm that the controls implemented align with the appropriate baseline. Because baseline control counts and tailoring change across revisions, assessors should validate the applicable requirements against current authoritative FedRAMP and NIST publications rather than secondary sources.

Inside Impact Level (Low/Moderate/High)

Security Categorization (FIPS 199)
The three-tier Low, Moderate, and High impact scale is established in FIPS 199, which provides the standard for categorizing federal information and information systems based on potential impact. FIPS 200 references these categories when specifying minimum security requirements but does not itself define the impact scale. Readers should verify against the current authoritative text.
Confidentiality, Integrity, and Availability Objectives
Impact is assessed separately against the three security objectives of confidentiality, integrity, and availability, with each assigned a Low, Moderate, or High rating based on the potential adverse effect of a loss.
High-Water Mark
In most implementations, the overall system impact level is generally determined by the highest impact rating among the confidentiality, integrity, and availability objectives, though agency tailoring may apply.
Potential Adverse Effect Gradations
Low generally corresponds to a limited adverse effect, Moderate to a serious adverse effect, and High to a severe or catastrophic adverse effect on organizational operations, assets, or individuals, as described in the applicable revision of the governing standard.
Basis for Control Baseline Selection
The categorized impact level informs selection of a corresponding security control baseline, an activity commonly aligned with NIST SP 800-53 baselines, subject to organizational tailoring and the applicable revision.

Common questions

Answers to the questions practitioners most commonly ask about Impact Level (Low/Moderate/High).

Are the Low, Moderate, and High impact levels established in FIPS 200?
No. The three-tier impact scale of Low, Moderate, and High is established in FIPS 199, which defines the potential impact of a loss of confidentiality, integrity, or availability on an information system. FIPS 200 references those categories when specifying minimum security requirements, but it does not create the scale itself. Referring to these as 'FIPS 200 Impact Levels' is misleading; the categorization is a FIPS 199 construct. Readers should confirm the current text of both publications for authoritative wording.
Is the FIPS 199 impact level the same thing as a FedRAMP or DoD impact level?
Not exactly, and the terminology should not be conflated. FIPS 199 establishes the Low, Moderate, and High categorization used generally for federal information systems. FedRAMP applies authorization baselines that correspond to these categories, and the DoD Cloud Computing Security Requirements Guide uses its own set of impact levels (often expressed as IL2, IL4, IL5, and higher) that account for information sensitivity including CUI and classified concerns. These frameworks are related but distinct, are maintained by different bodies, and a designation in one does not automatically equate to a designation in another. Verify the applicable framework's current guidance.
How is the overall impact level of a system determined when confidentiality, integrity, and availability differ?
Under the FIPS 199 approach, each security objective (confidentiality, integrity, and availability) is assessed separately for potential impact. In most implementations the overall categorization uses a 'high water mark,' meaning the system's impact level is generally set to the highest of the individual objective ratings. Agency tailoring and specific guidance may affect how this is applied, so confirm the methodology against current authoritative sources and any applicable agency policy.
How does the impact level relate to selecting a security control baseline?
The impact level generally drives the starting point for control selection. In most implementations, the FIPS 199 categorization informs which baseline (commonly Low, Moderate, or High) is chosen from the applicable NIST SP 800-53 control catalog, as reflected in associated baseline guidance. The selected baseline is typically a starting point subject to tailoring, and the specific controls and baselines change across revisions. Readers should verify the applicable revision and any agency-specific tailoring.
Does a higher impact level automatically mean a system is more secure?
No. A higher impact level indicates greater potential consequences from a loss of confidentiality, integrity, or availability and therefore generally calls for a more rigorous control baseline and greater assurance. It does not by itself mean the system is more secure. Categorization and compliance with a baseline are not the same as effective security; controls must be correctly implemented, assessed, and continuously monitored. Confirm that assessment results and continuous monitoring support the intended security posture.
Can a system's impact level change after it has been categorized?
Yes. Impact level is not necessarily permanent. Changes to the information the system processes, its mission role, connected environments, or applicable policy can prompt a re-evaluation of the categorization. Because authorization and continuous monitoring depend on an accurate categorization, a change may affect the applicable baseline and the authorization posture. Any re-categorization should follow the applicable process and current authoritative guidance, which the reader should verify.

Common misconceptions

The Low/Moderate/High impact scale is established in FIPS 200.
The three-tier impact scale is established in FIPS 199. FIPS 200 references those categories when setting minimum security requirements but does not define the scale itself. The alias 'FIPS 200 Impact Levels' is misleading and should be avoided.
The overall impact level is an average of the confidentiality, integrity, and availability ratings.
In most implementations the overall categorization uses a high-water mark approach, taking the highest of the three objective ratings rather than averaging them, though agency-specific tailoring should be confirmed against current guidance.
A FIPS 199 impact level is interchangeable with a FedRAMP or DoD cloud impact level.
FIPS 199 categorization and cloud service authorization impact levels are related but distinct constructs maintained by different authorities and scoped differently. Readers should confirm which framework applies and verify requirements against the relevant official sources.

Best practices

Anchor categorization decisions to FIPS 199 for the impact scale and consult FIPS 200 only for the associated minimum security requirements, verifying the current authoritative text.
Categorize confidentiality, integrity, and availability separately before determining the overall system impact level using the high-water mark approach.
Document the rationale for each objective rating so that the resulting control baseline selection is defensible during assessment and authorization.
Do not treat the impact level as static; revisit categorization when the system's information types, mission, or data change, and reflect updates through continuous monitoring.
Confirm any agency-specific tailoring or interpretation, since baselines and categorization guidance can vary across revisions and organizations.
Distinguish a FIPS 199 impact level from cloud service authorization impact levels and verify which applies before mapping to a specific control baseline.