FedRAMP Impact Levels: Civilian Baselines to DoD IL6

FedRAMP impact levels rank federal cloud systems by how much harm a security failure would cause. There are three civilian baselines (Low, Moderate, and High) set under the Federal Information Processing Standards, and the Department of Defense layers its own Impact Levels 2, 4, 5, and 6 on top for military and defense workloads. Picking the right level matters because each step up adds controls, cost, and engineering complexity; picking the wrong one either wastes money or leaves sensitive data underprotected.

How Your System’s Level Gets Set

Federal systems are categorized under Federal Information Processing Standards Publication 199. FIPS 199 requires a rating of Low, Moderate, or High for each of three security objectives: confidentiality (preventing unauthorized disclosure), integrity (keeping data accurate and unaltered), and availability (making sure authorized users can reach it).1National Institute of Standards and Technology. FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems

Low means a breach would cause limited harm. Moderate means serious consequences like significant financial loss or operational disruption. High means severe or catastrophic effects, potentially including threats to human safety.

Here is the rule that trips people up: the overall system rating equals the highest of the three objective ratings, not an average. FIPS 199 sets the security category of an information system as “the most severe impact level assigned to the three security objectives.”2National Institute of Standards and Technology. FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems Rate confidentiality and availability Low but integrity High, and the whole system is High. One elevated objective pulls the entire categorization up with it.

The Three Civilian Baselines

FedRAMP takes the FIPS 199 category and turns it into a defined baseline of security controls drawn from NIST Special Publication 800-53. Each baseline adds substantially more controls than the one below it.

Low Impact

Low fits cloud services handling data intended for public consumption, where loss of confidentiality, integrity, or availability would cause only limited harm.3FedRAMP. Understanding Baselines and Impact Levels in FedRAMP Public-facing informational sites and open data portals are typical fits. The baseline requires roughly 125 controls covering foundations like password policies, basic encryption, and audit logging.

Moderate Impact

Moderate is the workhorse of FedRAMP and accounts for nearly 80 percent of authorized cloud service offerings.3FedRAMP. Understanding Baselines and Impact Levels in FedRAMP It covers non-public, unclassified data where a failure could cause serious adverse effects: significant operational damage, financial loss, or individual harm short of loss of life. Personally identifiable information and protected health information usually land here. The Moderate baseline runs to roughly 325 controls, adding substantial requirements around access management, vulnerability scanning, and incident response.

High Impact

High protects the government’s most sensitive unclassified data in the cloud, covering systems where a breach could involve protection of life or cause financial ruin.3FedRAMP. Understanding Baselines and Impact Levels in FedRAMP Emergency services platforms and law enforcement communication systems are typical examples. The baseline mandates roughly 421 controls and demands continuous monitoring, strict multi-factor authentication, and hardened network segmentation. The step up from Moderate to High is where costs and engineering complexity climb sharply.

DoD Impact Levels: IL2, IL4, IL5, and IL6

The Department of Defense adds a second classification through the Cloud Computing Security Requirements Guide, maintained by the Defense Information Systems Agency. The SRG defines four Impact Levels numbered 2, 4, 5, and 6. Levels 1 and 3 were retired years ago.4Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide

Impact Level 2 covers non-controlled unclassified information, including data that has been or is intended for public release, along with non-critical mission data categorized as low-impact. IL2 is generally equivalent to the FedRAMP Moderate baseline.4Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide

Impact Level 4 is designed for Controlled Unclassified Information, which includes personally identifiable information, protected health information, and sensitive financial or business data. IL4 requires NIST SP 800-53 controls plus DoD-specific overlays that strengthen authentication, event logging, and audit retention.4Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide

Impact Level 5 accommodates higher-sensitivity CUI and unclassified National Security Systems. IL5 requires the cloud offering to be physically or logically isolated from lower-impact environments and prohibits mixing IL5 data with data from other impact levels.4Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide

Impact Level 6 is reserved for classified information up to the Secret level. IL6 environments must be physically and logically separated from all other cloud environments and must operate as a National Security System.4Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide

The Mapping Mistake to Avoid

A common assumption is that FedRAMP Moderate maps automatically to DoD IL4. It does not. FedRAMP Moderate is equivalent to IL2. Reaching IL4 or IL5 requires meeting additional DoD overlay controls and undergoing a separate third-party assessment on top of an existing FedRAMP authorization. DISA oversees the DoD Provisional Authorization review, which optimally takes about three months for a strong submission package.5Department of the Navy. DoD Cloud Provisional Authorizations Save Mission Owners Time and Money

What Each Level Costs

FedRAMP does not publish official cost figures, and actual spending varies with the provider’s existing security maturity and whether work is done in-house or with consultants. The ranges below reflect industry figures that appear consistently across sources.

  • Low Impact: initial authorization typically runs $160,000 to $485,000, with annual continuous monitoring in the $50,000 to $100,000 range.
  • Moderate Impact: initial authorization generally costs $500,000 to $1,500,000, reflecting the roughly three-fold increase in required controls. Annual maintenance runs $200,000 to $500,000.
  • High Impact: costs exceed the Moderate range substantially. Engineering complexity around network segmentation and continuous monitoring infrastructure pushes initial authorization well above $1 million.

The 3PAO assessment is often the most visible line item, but the engineering remediation work to actually close compliance gaps before the assessor arrives is where the real money goes. Providers entering the process with a mature security program already aligned to NIST SP 800-53 land at the lower end. Those starting from scratch should budget toward the higher end and add time for the learning curve.

State and Local Work: StateRAMP

State and local governments use a separate framework called StateRAMP, with categories that map roughly to FedRAMP baselines. Its Category 1 aligns with FedRAMP Low, and its Moderate impact level mirrors FedRAMP Moderate with approximately the same number of required controls. StateRAMP has no High impact category, reflecting the kinds of data state governments typically handle. Providers that already hold a FedRAMP authorization can use a reciprocity pathway to reach StateRAMP Authorized status with minimal additional work.

Choosing the Right Level

Work backward from the data. Run the FIPS 199 categorization honestly across confidentiality, integrity, and availability, take the highest of the three, and that is your FedRAMP baseline. If your buyer is a defense agency or you will handle CUI for DoD, add the matching DoD Impact Level on top: IL2 for public or low-impact data, IL4 for standard CUI, IL5 for sensitive CUI and unclassified NSS, IL6 for Secret. Overshooting the baseline is a real cost; undershooting it means the authorization will not cover the data your customer actually intends to put in the system.