What Is FedRAMP Moderate and What It Means for Defense Contractors
FedRAMP Moderate is the mid-level federal cloud security baseline, requiring about 323 controls drawn from NIST Special Publication 800-53 to protect government data where a breach would cause serious harm. For a defense contractor, it is the standard your cloud services have to meet before Controlled Unclassified Information (CUI) can live in them.
Below we cover what the Moderate baseline includes, where it sits among the other levels, what changed when FedRAMP renamed those levels in 2026, how Moderate differs from High on personnel and authentication, and the five steps for checking whether a service you already use actually holds it.
What Does FedRAMP Moderate Mean?
FedRAMP Moderate means a cloud service has been assessed against the baseline built for federal data whose loss would cause serious adverse effects on an agency's operations, assets, or individuals. Serious adverse effects cover operational damage, financial loss, and harm to individuals that stops short of threats to life or national security. Most CUI falls into exactly that band, which is why Moderate is the level defense contracts point at.
Pointing at Moderate happens through DFARS clause 252.204-7012, which requires any external cloud service storing, processing, or transmitting covered defense information to meet the Moderate baseline or a documented equivalent. The table below compares the three baselines, with control counts taken from the NIST SP 800-53 Revision 5 baselines and the class names from the FedRAMP Consolidated Rules for 2026.
Baseline2026 Class NameData SensitivityControlsSatisfies DFARS for CUILowClass BLimited adverse impact if breachedAbout 156NoModerateClass CSerious adverse impact; covers most CUIAbout 323Yes, this is the minimumHighClass DSevere or catastrophic impactAbout 410Yes, exceeds the minimum
How Many Controls Are in FedRAMP Moderate?
FedRAMP Moderate contains about 323 controls from the NIST SP 800-53 Revision 5 Moderate baseline. The figure is sometimes cited as 325 depending on how control enhancements are counted, and either number describes the same baseline. Those controls span access control, audit and accountability, configuration management, identification and authentication, incident response, media protection, risk assessment, and system and communications protection, among other families.
What Are the Different Levels of FedRAMP Certification?
FedRAMP has three traditional levels, Low, Moderate, and High, which the Consolidated Rules for 2026 replaced with Certification Classes A through D. Class B covers what used to be Low, Class C covers Moderate, and Class D covers High, while Class A is a new entry tier that did not previously exist. Low did not become Class A, and that mapping error circulates widely enough to be worth stating plainly.
Plain statements matter during a transition, because both naming conventions appear across contracts, vendor materials, and federal resources right now. The rules were finalized on June 25, 2026, and the renaming exists to end the long-running confusion between FedRAMP Moderate and High and the Department of Defense Impact Levels, which use similar words for an entirely different scale. Our breakdown of FedRAMP certification walks through what the class structure changes for suppliers.
What Is the Difference Between FedRAMP Authorized and FedRAMP Certified?
The difference between FedRAMP authorized and FedRAMP certified is terminology rather than substance. Under the 2026 rules, FedRAMP replaced the word authorization with certification, because FedRAMP certifies that an assessment was completed while the sponsoring agency issues the Authority to Operate. Existing authorizations carry forward with the same controls and the same boundary, so a service authorized in 2024 did not lose anything in the rename.
What Determines Whether a Service Needs Moderate or High?
The level is determined by FIPS 199 categorization, which rates the data across three security objectives and then applies the highest rating to the entire system. The entire system moving up on one data type is called the high watermark rule, and it is the reason a service cannot hold Moderate for most of its data and High for one sensitive slice inside a single authorization boundary.
A single boundary carries one level. FIPS 199 rates confidentiality, integrity, and availability separately at Low, Moderate, or High, and whichever objective scores highest sets the categorization for the whole system. Law enforcement records, health records, and national security information typically push a system to High, while standard CUI, personally identifiable information, and administrative federal data sit at Moderate.
What Is the Difference Between FedRAMP High and Moderate?
FedRAMP High requires about 410 controls to Moderate's 323, and it adds specific operational requirements that Moderate does not impose. Imposing those extra requirements is what makes High meaningfully harder to reach and to maintain:
- Supply chain risk management: required as a full control family at High, not required at Moderate.
- Authentication strength: Moderate requires Authenticator Assurance Level 2 (AAL2); High requires AAL3 with verifier-impersonation resistance.
- Session timeouts: 30 minutes of inactivity at Moderate, 15 minutes at High.
- Re-authentication: single-factor at Moderate, both factors at High.
- Access revocation: a four-hour window after termination at Moderate, one hour at High.
- Personnel: no citizenship requirement for administrative access at Moderate; United States citizens required at High.
- Network posture: standard boundary protections at Moderate; deny-by-default, permit-by-exception at High.
Exception-based networking and one-hour revocation windows are operational commitments rather than documents, which is why moving a service from Moderate to High later means a new assessment package and often an infrastructure migration. Both baselines require cryptography that meets federal standards, and how a contractor handles encryption requirements on its own side of the boundary matters just as much as what the provider runs.
Does FedRAMP Moderate Require US Citizenship?
No, FedRAMP Moderate does not require United States citizenship for administrative access to the cloud service. That requirement belongs to FedRAMP High, which restricts administrative access to US citizens. Contracts involving export-controlled data frequently add their own US person restrictions separately, so a Moderate service can still be the wrong fit when ITAR or EAR obligations apply to the data you are placing in it.
Who Is Required to Become FedRAMP Compliant?
Cloud service providers selling to federal agencies are required to become FedRAMP compliant, and defense contractors are required to use services that hold it. Holding it is a provider achievement. The obligation on your side is selection and verification, which is a different job with a different evidence trail.
Evidence trails come up quickly, because the requirement reaches far into the supply chain. Department of Defense regulatory analysis behind the final rule identifies 337,968 impacted entities, of which 229,818 are small businesses, and nearly all of them use cloud services of some kind. Our fuller treatment of FedRAMP compliance covers what that obligation looks like in practice across a contractor's vendor stack.
Do Defense Contractors Need FedRAMP Moderate Themselves?
No, a defense contractor does not become FedRAMP Moderate as an organization, and no assessor will ever certify your company at that baseline. FedRAMP applies to cloud service offerings, so your requirement under DFARS 252.204-7012 is to confirm that every cloud service touching covered defense information holds Moderate standing or documented equivalency. Your own network is measured against NIST SP 800-171 instead, which is a separate framework with separate requirements, and defense contractors routinely conflate the two.
Does FedRAMP Moderate Satisfy CMMC Level 2?
FedRAMP Moderate satisfies the cloud portion of a CMMC Level 2 assessment, and it does not satisfy the assessment by itself. By itself, a certified platform covers only the controls the provider operates. Your assessor evaluates your entire environment against all 110 requirements of NIST SP 800-171, and the cloud service sits inside that boundary rather than outside it.
Inside the boundary, the split of duties is defined by the Customer Responsibility Matrix that every certified service publishes. That document assigns specific controls to you: configuring access, reviewing permissions, retaining logs, managing keys, and escalating incidents. Those controls appear in your CMMC Level 2 assessment as your controls, and a provider's certification does not perform any of them on your behalf.
What Does FedRAMP Moderate Equivalency Mean?
FedRAMP Moderate equivalency means a cloud service has demonstrated full compliance with the Moderate baseline without holding FedRAMP certification itself, under criteria the Department of Defense defined in a CIO memorandum issued December 21, 2023. Those criteria are narrow and frequently misdescribed, so here they are exactly: 100 percent of the Moderate controls implemented, zero outstanding POA&M items, assessed by an independent FedRAMP-recognized 3PAO, with no self-attestation permitted, and a complete Body of Evidence supplied to the contractor.
Contractors reach for equivalency expecting an easier path, and the standard runs the other way. A certified service is permitted to carry open findings and remain in good standing. An equivalent service cannot carry a single control finding out of its assessment. Equivalency is a taller wall than certification rather than a shortcut around it, which is why a casual equivalency claim in a sales deck deserves more scrutiny than a Marketplace listing, not less.
The practical consequence lands on you rather than on the vendor: you hold the evidence and present it to your assessor, and the Department identifies the contractor as the party approving use of the service. Our full breakdown of what the Body of Evidence has to contain covers the document set in detail.
How Do You Check If a Cloud Service Holds FedRAMP Moderate?
You check a service's standing on the FedRAMP Marketplace, and the check takes five steps rather than one. One step is where most contractors stop, which is how a brand name ends up substituting for a verified listing:
- Search the exact service offering name, not the company name. A vendor may hold certification for one product and nothing for another, and the commercial edition of a platform is a different service from its government edition.
- Confirm the class and the status. Look for Moderate, now Class C, or higher, and confirm the listing shows an active status rather than an in-process or preparation entry.
- Confirm the boundary covers what you use. Certification covers a defined authorization boundary, and plugins, integrations, and add-on modules outside that boundary are not covered even when they move your data.
- Request the Customer Responsibility Matrix. Read which controls the provider assigns to you, and assign each one an owner inside your organization.
- For an equivalency claim, request the 3PAO letter and the Body of Evidence under NDA. A vendor who will not release that package has given you a claim rather than a compliance position.
A compliance position is what an assessor asks to see, and building this check into a standing compliance program costs far less than reconstructing it under deadline. Among the defense supplier base around Huntsville, the inventory step alone routinely surfaces two or three services nobody had scoped.
What Happens If a Cloud Service Loses Its FedRAMP Standing?
A cloud service that loses its FedRAMP standing stops satisfying your DFARS obligation from that moment, and the responsibility for noticing belongs to you. Noticing is the hard part, because nothing about a lapse announces itself inside the product. The service keeps working, the login page looks identical, and the data keeps flowing.
Flowing data into a service that no longer qualifies is what an assessor eventually finds. Standing changes through ordinary business events: a certification lapses at renewal, a provider changes its authorization boundary, a product line gets spun out, or an acquisition reshuffles which entity holds the listing. Quarterly re-verification with dated evidence catches all four, and a cloud-focused gap analysis catches the services that were never eligible in the first place.
First-place eligibility problems are the expensive ones, since migrating a CUI workload out of an unqualified platform means moving mailboxes, re-pointing integrations, retraining staff, and rebuilding evidence. Running these verification cycles as part of managed compliance keeps the documentation current instead of assembling it when a prime asks.
Is FedRAMP Moderate the Same as NIST 800-171?
No, FedRAMP Moderate and NIST SP 800-171 are different standards that apply to different parties. Different parties is the whole distinction. FedRAMP Moderate builds on NIST SP 800-53 and applies to the cloud service provider's platform. NIST SP 800-171 contains 110 requirements and applies to your own systems that handle CUI.
Your own systems and your vendor's platform are assessed separately and prove nothing about each other. A contractor with excellent NIST 800-171 implementation can still fail on the cloud side by putting CUI in an ineligible service, and a perfectly certified platform does nothing for a contractor whose own network falls short.
What Is the Difference Between FedRAMP Moderate and DoD Impact Levels?
FedRAMP levels and DoD Impact Levels are separate scales, and holding one does not automatically confer the other. The other scale comes from the Defense Information Systems Agency Cloud Computing Security Requirements Guide, which uses Impact Levels IL2, IL4, IL5, and IL6 to describe what categories of defense data a cloud environment may hold.
Holding IL5 requires a separate DoD provisional authorization on top of a FedRAMP foundation, and IL5 builds on the High baseline rather than on Moderate. The similar vocabulary between the two systems is exactly the confusion the 2026 class rename was designed to end. For most defense suppliers handling standard CUI, the Moderate baseline is the requirement that appears in the contract, and Impact Levels enter the conversation only on specific programs.
How Long Does FedRAMP Certification Take?
FedRAMP certification at the Moderate baseline typically takes a provider 12 to 18 months from preparation through certification, according to industry estimates. Estimates vary widely with the provider's starting maturity, the size of the authorization boundary, and agency sponsorship timing, and the High baseline commonly runs longer still.
Longer timelines are your problem as well as the provider's, because a vendor that is in process today cannot hold your CUI today. Marketplace listings distinguish services in preparation from services with active standing, and a roadmap commitment from a sales team is not a substitute for a listing. Planning around that gap, rather than waiting on it, is where our certified assessors usually start when a contractor's preferred tool is not yet eligible.
Frequently Asked Questions
What Is FedRAMP and What Is Its Purpose?
FedRAMP is the Federal Risk and Authorization Management Program, and its purpose is to give federal agencies one standardized way to assess cloud services rather than each agency running its own duplicate review. It began in 2011 through an Office of Management and Budget memorandum and was codified by Congress in December 2022 through the FedRAMP Authorization Act. The program operates on a do once, use many principle, so an assessed service can be reused across agencies.
Is FedRAMP Only for US Government Use?
FedRAMP exists for United States federal government use, and its requirements reach private companies through contract clauses rather than through direct regulation. Defense contractors encounter it because DFARS 252.204-7012 flows the cloud requirement down to them and to their subcontractors. Some commercial buyers now ask about FedRAMP standing as a security signal, though no obligation applies outside federal contracting.
Do the Major Cloud Platforms Hold FedRAMP Moderate?
The major cloud platforms hold FedRAMP standing for their government offerings, and their standard commercial offerings are separate services with separate standing. This distinction causes more assessment findings than any other cloud issue, because a commercial subscription and a government edition of the same brand are different products under the program. Check the exact service offering name on the Marketplace rather than assuming the brand carries across every product it sells.
Which Companies Are FedRAMP Certified?
The authoritative list of FedRAMP certified companies is the FedRAMP Marketplace, which showed 528 certified cloud services plus 28 certified through the FedRAMP 20x path as of August 2026. No blog list stays accurate, since services are added, renewed, and removed continuously. The Marketplace also shows each service's class, status, and authorization boundary, which a list would not.
What Is a 3PAO?
A 3PAO is a Third-Party Assessment Organization accredited to independently assess cloud service offerings against FedRAMP baselines. The 3PAO tests the controls and produces the Security Assessment Report that separates a tested claim from a marketing claim. Only a 3PAO assessment can support a FedRAMP Moderate equivalency claim, because self-attestation is not permitted under the Department's criteria.
Does FedRAMP Moderate Cover PII as Well as CUI?
Yes, FedRAMP Moderate covers personally identifiable information along with Controlled Unclassified Information, since both typically categorize at the Moderate impact level under FIPS 199. Agencies place financial records, human resources data, and citizen personal information in Moderate services routinely. Certain categories of personal data, particularly health and law enforcement records, categorize higher and require the High baseline instead.
The Bottom Line
FedRAMP Moderate is the baseline that decides whether a cloud service can hold your CUI. About 323 controls from NIST SP 800-53, built for data whose breach would cause serious harm, now labeled Class C under the 2026 rules, and named directly by DFARS 252.204-7012 as the minimum for covered defense information. High exists above it with roughly 410 controls, stricter authentication, tighter revocation windows, and a US citizenship requirement that Moderate does not impose.
Your company never earns this baseline. Your vendors do, and your job is verification: the exact service name on the Marketplace, the class and status, the boundary, the responsibility matrix, and for any equivalency claim a 3PAO letter and Body of Evidence you can hand to an assessor. Equivalency in particular deserves scrutiny rather than relief, since 100 percent of the controls with zero findings is a stricter bar than certification itself.
We have spent more than 20 years building compliant IT environments for defense suppliers across Huntsville and North Alabama, and the cloud inventory is consistently where we find the most exposure. If you want a clear picture of which services in your environment actually qualify, talk it through with our team or call (256) 837-2300. Mapping it properly once is far cheaper than discovering a gap during an assessment, and it is the work Interweave Technologies does every day.
.webp)
.webp)



.webp)





Share Post