Glossary / Defense / FedRAMP

FedRAMP

Also known as: Federal Risk and Authorization Management Program · FedRAMP levels · FedRAMP impact levels · FedRAMP Low · FedRAMP Moderate · FedRAMP High · FedRAMP authorization levels

Defense

The U.S. government's standardized security-authorization program for cloud products and services sold to federal agencies.

FedRAMP (the Federal Risk and Authorization Management Program) is the U.S. government's standard for cloud security, a government-wide program launched in 2011 to standardize cloud security assessment, certification, and continuous monitoring for cloud products and services used by federal agencies. It follows an "assess once, use many" model, so a single FedRAMP authorization (an Authority to Operate, or ATO) can be leveraged across agencies rather than re-earned each time, with security controls assessed against NIST SP 800-53. If your AI, space, or defense startup provides cloud-based software to federal agencies, a FedRAMP authorization is generally required, and it is a significant, ongoing compliance undertaking involving continuous monitoring, assessments, and documentation. Importantly, FedRAMP does not use a "Class A" label or any Class A/B/C scheme; instead it recognizes impact levels that determine how many controls you must meet, based on the sensitivity of the data (a categorization that derives from FIPS 199). The four levels are LI-SaaS (Low Impact SaaS, a streamlined subset of Low with roughly 50-plus controls, for SaaS apps that do not retain PII beyond basic login credentials such as a username and password), Low (about 156 controls, for less sensitive federal information where a loss of confidentiality would have a limited adverse effect), Moderate (about 323 controls, applied to the majority of systems handling federal data, where a loss would have a serious adverse effect), and High (about 410 controls, for the most sensitive unclassified data such as law enforcement, emergency services, financial, and health systems, where a loss could be catastrophic). An authorization is granted at one of these levels, so if a client asks about "Class A FedRAMP," the closest real concept is choosing the correct impact level (LI-SaaS, Low, Moderate, or High) for the data the system handles.

Source: A-LIGN — What is FedRAMP?

Where you'll see it

Vendor contractApplicationQuote

Why it matters for your business

  • FedRAMP authorization is often a prerequisite to sell cloud software to federal agencies.
  • It signals a startup's cyber/security maturity, which underwriters weigh when pricing cyber and tech E&O coverage.
  • The continuous-monitoring obligations shape ongoing federal-contract risk exposure.

People also ask

Do I need FedRAMP to sell to the government?

If you offer a cloud product or service that a federal agency will use to handle federal information, you generally need a FedRAMP authorization at the appropriate impact level. It is a significant, ongoing compliance program — not a one-time certificate.

How does FedRAMP affect my insurance?

FedRAMP status is evidence of cyber-security maturity, which can improve how underwriters view your cyber liability and technology E&O risk. It also reflects federal-contract exposure that should be matched to your coverage.

What are the FedRAMP impact levels?

FedRAMP has four impact levels tied to how sensitive the federal data is that your system handles: LI-SaaS (Low Impact SaaS), Low, Moderate, and High. LI-SaaS is a streamlined version of Low, with roughly 50-plus controls, for SaaS apps that do not store PII beyond basic login credentials like a username and password. Low uses about 156 controls, Moderate about 323 controls (the level the majority of systems handling federal data fall under), and High about 410 controls for the most sensitive unclassified data, such as law enforcement, emergency services, financial, and health systems. Your required level comes from a FIPS 199 categorization of the potential impact if the data's confidentiality, integrity, or availability were lost, and all controls are assessed against NIST SP 800-53.

Is there a Class A FedRAMP level?

No. FedRAMP does not have a "Class A" designation, and there is no Class A, B, or C scheme at all. FedRAMP uses impact levels (LI-SaaS, Low, Moderate, and High), and your authorization, an Authority to Operate, is granted at one of those levels. If someone references "Class A FedRAMP," they most likely mean selecting the correct impact level for the data their system handles.

What is the difference between FedRAMP High and Moderate?

The difference is the sensitivity of the data and the number of security controls involved. Moderate (about 323 controls) applies to the majority of systems handling federal data, where a loss would have a serious adverse effect. High (about 410 controls) is reserved for the most sensitive unclassified data, such as law enforcement, emergency services, financial, and health systems, where a loss could be catastrophic. In practice, High layers stricter controls on top of the Moderate baseline.

Ready to take the next step?

Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.

Reviewed by Andrei Craciunescu, CA Licensed Insurance Broker #4467994

Last updated: July 2026.