In This Article
FedRAMP Class B is the second of four FedRAMP Certification Classes (A through D) introduced under the FedRAMP Consolidated Rules for 2026 (CR26). It replaced the old "Low" impact level.
A CSP pursuing Class B has to address the full baseline of FedRAMP Key Security Indicators (KSIs) directly, with a recommendation of at least one automated validation method behind each one.
If an agency customer is asking you for FedRAMP and you're not sure which class fits, Class B is where most SaaS providers with lighter-footprint, lower-risk services land. Here’s what you need to know about Class B to see if it’s right for your business.
How Does Class B Fit into FedRAMP?
There are 4 FedRAMP Certification Classes:
- Class A — A new entry tier. Built for providers with an existing, eligible security certification (SOC 2 or similar) who want a foothold in the federal market without starting from zero.
- Class B — Replaces the old Low impact level, including the former LI-SaaS designation. Full KSI baseline, addressed directly.
- Class C — Replaces Moderate. Same KSI baseline, stricter validation, longer track record required.
- Class D — Replaces High. Still being defined through FedRAMP's Phase 4 pilot.
FedRAMP also renamed "FedRAMP Authorized" to "FedRAMP Certified" and "Impact Levels" to "Certification Classes." If your team still says "FedRAMP Low," that's Class B now. The requirements are the same, just a new label.
What Does FedRAMP Class B Actually Require?
Short answer: the full set of applicable Key Security Indicators, addressed directly, with continuous validation instead of a point-in-time audit.
At Class B, you should:
- Address every applicable KSI within your Minimum Assessment Scope — not a reduced subset.
- Automate at least one validation method per KSI. This is a "should*," not a hard "must." Class C requires two methods per KSI, Class D requires four.
- Maintain a Security Decision Record (SDR). This replaces the old System Security Plan. It’s now a living record of how each KSI is met, verified, and validated, rather than a static narrative document.
- Supply historical KSI metrics — a 30-day summary plus up to a year of trend data where available.
- Complete an annual independent assessment. Class B and C both require a FedRAMP Recognized Independent Assessor (the renamed 3PAO) to review all applicable KSIs at least once a year.
- Apply directly — no agency sponsor required. Under 20x, you go through FedRAMP's Program Certification path rather than waiting on an agency to sponsor you first.
One thing Class B doesn't require: GovCloud. That typically kicks in at Class C and above.
While fully automated evidence validation isn’t required, keep in mind your Class B program can be built incrementally, with automation coverage that grows toward the Class C bar rather than having to land there on day one. If you are automating FedRAMP evidence collection anyway, one automated method per KSI is a reasonable target to set for yourself even though the rule does not force it.
Who is Class B Best For?
Class B is the rough equivalent of the old Low-Impact SaaS (LI-SaaS) category. It’s the best fit for services where a breach would do limited damage.
Think, public-facing content, marketing tools, systems that touch little to no data beyond login credentials.
It's the right call when an agency is asking for FedRAMP but isn't demanding deep operational transparency or supporting a mission-critical workload. If your buyer wants months of continuous-monitoring history or detailed incident-response timelines before they'll sign, that's usually a Class C conversation.
FedRAMP frames Class B this way:
"Adequate for use in most Low impact agency information systems and some Moderate or High impact agency information systems with appropriate compensating controls."
What Does Your Certification Class Say About Your Security?
FedRAMP Certification Classes measure the level of assurance and transparency you're providing to the government — not how secure your system actually is.
A Class B provider can run a tighter security operation than plenty of Class C providers. Choosing Class B over C is usually a cost-and-scope decision, not a statement about your security quality.
Class B vs. Class A vs. Class C
What It Takes to Actually Operate at Class B
The rules describe what you need to show. Building the machinery to show it — automated KSI validation, an SDR that stays current instead of going stale six months after assessment, and historical metrics you can produce on demand — is the harder problem most providers hit once they commit to a class.
What catches teams by surprise with 20x? It's not a documentation exercise you finish once. 20x requires infrastructure you maintain continuously the entire time you hold the certification.
Paramify builds a platform to cover the full compliance lifecycle, from gap assessment and implementation planning through evidence generation and ongoing KSI monitoring.
Bottom Line
FedRAMP Class B is where most SaaS providers with lighter-footprint services land once an agency customer starts asking for FedRAMP.
No, it's not a shortcut, and it's not a signal that your security is lighter than a Class C provider's — it's a scoped level of assurance matched to lower-risk workloads.
What it actually takes to run, day to day, is a compliance program built for continuous, automated evidence, which is worth scoping out before committing to a class.
FAQ
Is FedRAMP Class B the same as the old "Low" impact level?
Functionally, yes. CR26 renamed the old Low impact level, including LI-SaaS, to Class B. The security expectations are the same; the label and the KSI-based evidence model changed.
Do I need an independent assessor for Class B?
Yes. Class B requires an annual review by a FedRAMP Recognized Independent Assessor — the renamed 3PAO — covering all applicable KSIs. We’d be happy to match you with the best assessor for you.
Does FedRAMP Class B require GovCloud?
No. GovCloud isn't typically required at Class B. It becomes more common starting at Class C.
How is Class B different from Class A?
Class A lets you lean on an existing certification, like SOC 2, to get a foothold. Class B requires you to address FedRAMP's KSIs directly, with automated validation behind each one.
Can I move from Class B up to Class C later?
Yes — the classes work as building blocks. Moving up mainly means adding automated validation methods per KSI and extending your historical metrics.



