Skip to main content

Impact levels

Every system is categorized by how much damage a security breach could cause. That category — Low, Moderate, or High — determines how many controls apply and how rigorous the assessment is.

How categorization works

Impact levels come from FIPS 199, which asks a simple question about three security objectives:

  • Confidentiality — impact if information is disclosed.
  • Integrity — impact if information is modified or destroyed.
  • Availability — impact if access to the system is disrupted.

Each objective is rated Low, Moderate, or High. The system's overall impact level is the highest rating among the three ("high water mark").

The three baselines

Each impact level maps to a baseline — a specific set of security controls drawn from NIST SP 800-53 (Revision 5). The higher the impact, the more controls apply.

  • Low

    Limited adverse effect if compromised.

    Suitable for systems handling information that is largely public or low-sensitivity. Fewest controls.

  • Moderate

    Serious adverse effect if compromised.

    The most common level. Covers the majority of federal cloud systems handling non-public information.

  • High

    Severe or catastrophic adverse effect if compromised.

    For sensitive, mission-critical data — e.g., law enforcement, emergency services, financial or health data. Most controls.

The exact number of controls in each baseline changes with NIST revisions. Treat control counts as approximate and confirm against the current FedRAMP baselines before planning an assessment.

LI-SaaS: a tailored low baseline

For low-impact Software as a Service with a limited scope — think collaboration tools or simple web apps that don't store sensitive data — FedRAMP offers a streamlined baseline often called LI-SaaS (Low-Impact SaaS), sometimes referred to as "FedRAMP Tailored." It reduces the control set to what's practical for these smaller, lower-risk services.

Choosing the right level

Rough guide to picking an impact level
If the data is…Likely level
Public or already broadly availableLow (or LI-SaaS)
Non-public, but a breach wouldn't be catastrophicModerate
Sensitive, mission-critical, or safety-relatedHigh

The categorization drives everything downstream: the number of controls, the depth of testing, and the effort of continuous monitoring.

Where to go next