Frameworks

FedRAMP High vs Moderate: what is the difference?

4 August 2026 · 8 min read · CertAssist

Moderate needs 323 controls, High needs 410. Here is what sets your FedRAMP level, and why the data decides, not you.

FedRAMP High and Moderate are two impact levels a cloud service can be authorised at, set by how damaging a breach would be. A Moderate authorisation, which covers the large majority of federal cloud use, applies where a breach would cause serious harm and requires 323 controls under Rev 5. A High authorisation applies where a breach would cause severe or catastrophic harm, such as law enforcement, healthcare or financial data, and requires 410 controls, 87 more than Moderate. The level is not a choice of ambition; it is dictated by the sensitivity of the data. Here is how the two compare.

Comparison matrix of FedRAMP Moderate and High across impact, control counts and typical data

What determines your FedRAMP impact level?

Your FedRAMP impact level is determined by the sensitivity of the data your service handles, categorised using the federal standard FIPS 199. The categorisation looks at the potential impact of a loss of confidentiality, integrity or availability, rated Low, Moderate or High. The highest of the three ratings sets the system's level. So the level follows the data, not your preference: a service handling routine federal information lands at Moderate, while one handling data whose loss would be severe or catastrophic lands at High.

How many controls are in FedRAMP Moderate and High?

Under the Rev 5 baselines, FedRAMP Moderate requires 323 controls and FedRAMP High requires 410 controls. That is a difference of 87 controls and control enhancements that are unique to High, spanning most of the control families. The Low baseline, for comparison, is around 156 controls. These counts come from the NIST 800-53 Rev 5 catalogue as tailored by FedRAMP, which is why they shifted when FedRAMP moved from Rev 4 to Rev 5.

Bar chart of FedRAMP Low, Moderate and High control counts showing High at 410 controls

What is the difference between FedRAMP High and Moderate?

The difference between FedRAMP High and Moderate is the severity of harm the level is designed to withstand, and the additional controls that follow. Moderate protects against serious adverse effects and needs 323 controls; High protects against severe or catastrophic effects and needs 410. The 87 extra controls at High tighten areas such as access control, auditing, incident response and physical protection. High authorisation is correspondingly more expensive and time consuming to achieve and maintain, because there is more to implement, evidence and assess.

Which FedRAMP level do you need?

You need the level that matches the most sensitive data your service will handle for the government, as categorised under FIPS 199. If you will process law enforcement, healthcare, financial or similarly sensitive data whose loss would be severe, you need High. For most other federal workloads, Moderate is the right and most common target. Do not aim higher than the data requires, because the extra controls at High add real cost without benefit if your data does not warrant them.

How much harder is FedRAMP High?

FedRAMP High is meaningfully harder than Moderate because of the 87 additional controls and the stricter expectations around them, which increase the implementation, documentation and continuous-monitoring workload. Both levels require a rigorous authorisation process, but High demands more evidence, more frequent scrutiny in some areas, and typically a more capable security team or partner. Budget and timeline both rise. This is why organisations confirm their true impact level early, so they neither under-scope and fail nor over-scope and overspend.

How CertAssist helps you prepare

CertAssist is not a FedRAMP authorisation service, and no tool can grant an authorisation, which comes through the official FedRAMP process. What CertAssist does is help you organise the underlying NIST 800-53 based controls, with editable templates and evidence tracking on one board, so your team can prepare methodically and see where the gaps are before a formal assessment. Because CertAssist covers overlapping frameworks too, groundwork you lay for other standards carries across. The price is a published US$225 per month during its launch.

How long does a FedRAMP authorisation take?

A FedRAMP authorisation typically takes many months to well over a year, and High usually takes longer than Moderate because there is more to implement, document and assess. The timeline depends on how mature your security is when you start, whether you have a sponsoring agency, and how quickly you close findings from the assessment. Continuous monitoring then continues for as long as the authorisation is live, so FedRAMP is an ongoing commitment rather than a one-off project. Teams shorten the path by getting their controls and evidence in order before the formal assessment begins, so the assessor finds a tidy, well documented system rather than gaps to chase. That preparation is where organising the 800-53 based controls on a single board pays back the most, well before any agency or assessor is involved.

Frequently asked questions

What is the difference between FedRAMP High and Moderate?

FedRAMP Moderate covers data whose breach would cause serious harm and requires 323 controls under Rev 5. FedRAMP High covers data whose breach would cause severe or catastrophic harm and requires 410 controls, 87 more than Moderate. The level is set by data sensitivity under FIPS 199, not by choice, and High is more costly to achieve and maintain.

How many controls are in FedRAMP High vs Moderate?

Under the Rev 5 baselines, FedRAMP Moderate requires 323 controls and FedRAMP High requires 410 controls, a difference of 87 controls and enhancements unique to High. The Low baseline is around 156 controls. These figures come from the NIST 800-53 Rev 5 catalogue as tailored by FedRAMP.

Which FedRAMP level do I need?

You need the level that matches the most sensitive data your service handles for the government, categorised under FIPS 199. High is for law enforcement, healthcare, financial or similarly sensitive data whose loss would be severe. Moderate suits most other federal workloads and is the most common target. Aim no higher than the data requires.

Why is FedRAMP High more expensive?

FedRAMP High is more expensive because it adds 87 controls and enhancements over Moderate and applies stricter expectations, which increase implementation, documentation and continuous-monitoring effort. More controls mean more to build, evidence and assess, and typically a more capable security team, so both budget and timeline rise relative to a Moderate authorisation.

Does a tool make you FedRAMP authorised?

No. No tool can grant a FedRAMP authorisation, which comes through the official FedRAMP process with an assessor and a sponsoring agency or the program office. Software can help you organise the underlying NIST 800-53 controls and evidence and find gaps before assessment, but the authorisation itself is issued through FedRAMP, not by any product.

Related guides

Organise the controls before the assessment

CertAssist lays out NIST 800-53 based controls with editable templates and evidence tracking, for a published $225 a month during the launch.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.