What Is FedRAMP Class C (Moderate)?

This decision guide for cloud service providers weighing FedRAMP Class C explains Class C requirements, what a complete package involves, and how to tell whether your customers actually need it or a lower class is the better starting point.

Isaac Teuscher
|
53
min read

In This Article

Watch the FedRAMP Class C breakdown with FedRAMP Expert, Isaac Teuscher


Is FedRAMP Class C the right target for your cloud service, or a very expensive detour?

It's a hard question to answer quickly. Class C is the most common FedRAMP certification class and opens the door to grow your revenue. But, Class C isn’t the best choice for every CSP. Even FedRAMP recommends starting at A or B.

This article pulls it into one place:

  • What Class C is and how it compares to Classes A, B, and D
  • What Class C requires
  • What a complete package looks like, including rules you haven't fully implemented yet
  • How to know if Class C is right for you

What is FedRAMP Class C?

FedRAMP Class C is the third of four certification classes available to cloud service providers that want to sell their software to federal government agencies. It requires at least two automated validation methods for every Key Security Indicator (KSI) and six months of historical KSI metrics, or a plan to build that history over time.

FedRAMP groups certification into Class A, B, C, and D under the FedRAMP Consolidated Rules for 2026 (CR26). Each class is designed so you can increase your investment as agency interest and requirements grow.

Requirement Class A Class B Class C Class D
Automated validation per KSI Optional Recommended (1+ method) Required (2+ methods) Required (4+ methods)
Historical KSI metrics Optional Recommended Required (6 months, or a plan to reach it) Required (18 months)
Independent assessment within 3 months Optional Required Required Required

Want a closer look at the top two classes? See our comparison of Class C vs. Class D.

What Class C requires

At Class C, you've addressed every FedRAMP requirement that applies to your offering, and what was optional or recommended at Class A and B becomes mandatory. 

Before you apply, you must be listed in the FedRAMP Marketplace.

Here’s what you’ll need:

1

Two automated methods for every KSI

Under FRC-CSX-VVK, each indicator needs at least two automated methods to verify and validate its accuracy and completeness. Class B only recommends one. In Paramify, you map your existing tools and processes to each KSI and run automated validators against them.

2

Six months of KSI history

Under FRC-CSX-MOT, you must supply historical metrics, including status from persistent validation, covering at least the past six months. If your service hasn't been operating with those metrics that long, you can still apply by showing the mechanisms are in place and agreeing to meet the requirement. Paramify keeps validator results as a continuous history, so the record builds from the day validation starts.

3

Continuous, machine-readable evidence

Your program must produce ongoing evidence that your security controls are implemented, and you must make it available to agency customers in machine-readable form. Paramify generates your machine-readable Security Decision Record (SDR) from the same validation data and publishes it through a FedRAMP-ready trust center, so agencies see the evidence your validators produced.

4

Fresh evidence at submission

Your package must reflect your offering's status as validated by you within the previous 7 days. Your independent assessment must come from a FedRAMP Recognized assessor and be completed within the previous 3 months. With validation running continuously in Paramify, you refresh the package from current results instead of rebuilding it by hand. The assessment itself still comes from your assessor.

What a complete certification package looks like

Every MUST and every SHOULD in the rules needs an explanation. If one doesn't have one, your package is incomplete.

That doesn't mean every rule has to show as fully implemented. FedRAMP assessors accept rules and KSIs that are planned or partially implemented, and FedRAMP would rather see accurate, transparent status than a stretched-to-green one. 

Planned or partial status doesn't block certification.

What FedRAMP needs is the explanation that goes with the status:

Status What to include
Implemented An explanation of how you implement the rule.
Partially implemented What is in place today, the planned date for the rest, how you will implement it, and why it isn't there yet.
Planned The planned implementation date, how you will implement it, and why it isn't there yet.
SHOULD not implemented Your reasoning for why you aren't implementing it.

A SHOULD is not a MUST. Still, there may be a reason not to implement the rule, and FedRAMP expects those reasons to be few and limited, and you have to state your reason.

For KSIs, Paramify lets you record the planned date, the method, and the reason for any partial or planned implementation. The status in your SDR reflects what your validators actually ran, so you can show FedRAMP accurate data without stretching anything to green.

Record planned and partial KSIs with the dates, methods, and reasons FedRAMP asks for.

See how Paramify does it

Dates to know

Date Milestone
August 31, 2026 The 20x Class B and Class C pipelines opened.
February 1, 2028 All CR26 grace periods end, and offerings not fully following CR26 lose certification. FedRAMP says there are no extensions.

Class D is in the rules, but its 20x pilot hadn't started as of the CR26 launch. For most providers, Class C is the top of the ladder available today. Your validation mechanisms need to be in place and running before you submit.

Is Class C right for you?

C & D classes are meant for providers that already have an active customer base and have invested in a federal compliance program. If you're new, FedRAMP recommends starting at Class A, which is built for commercial products that already have a SOC 2 Type II and a mature security program. Its decision workflow comes down to two questions:

  • Already certified? Move up to the class your agency customers need and are willing to pay for.
  • Not certified, but an agency requires it? Pick the lowest class that meets their requirements and fits your business.

Being ready for Class C doesn't mean every rule is green. Assessors accept planned and partially implemented rules when they're documented honestly, so the question is whether your customers need Class C, not whether your status is perfect.

Each class takes more preparation, more automation, and more verification, and that cost is ultimately passed on to federal agency customers. 

If a contract does require Class C, it helps to work with people who have done it. Paramify holds its own FedRAMP 20x Class C certification, and its assessor, Coalfire, published a case study on how that certification came together.

For most newcomers, FedRAMP recommends starting at Class A, which is designed for commercial products that already have a SOC 2 Type II and a mature security program. Our Class A step-by-step guide walks through that path.

How Paramify helps with FedRAMP Class C

The hardest parts of Class C are operational. You need two automated validations running against every KSI and a package you can refresh within a seven-day window whenever you submit. Doing that with spreadsheets and screenshots means rebuilding your evidence every time something changes.

Paramify maps your existing tools and processes to each KSI, runs automated validators against them, and keeps the results as a continuous history. 

From that same data, Paramify generates your machine-readable Security Decision Record and publishes it through a trust center, so the evidence agencies see is the evidence your validators produced. We covered what to look for in this kind of platform in 5 things to look for in a FedRAMP 20x GRC tool.

If Class C is on your roadmap, the best time to start building your KSI history is now.

FEDRAMP 20X CLASS C

Get Class C ready with a platform that has been through it.

Paramify automates KSI validation, keeps your six months of history, and publishes your SDR and trust center from one source of truth.

Book a demo

Ready for Class C, or still deciding?

Whether you're ready to start building your Class C evidence or want help deciding if Class C or a lower class is the right place to begin, Paramify can walk you through it. Sign up for a demo below, or reach out with any questions — our team loves to help.

Related Reading:

Frequently asked questions

What is FedRAMP Class C?
The third of four certification classes under CR26. It requires at least two automated validation methods for every KSI and historical KSI metrics covering at least six months, or a plan to reach that.

Is Class C the same as FedRAMP Moderate?
Not exactly. FedRAMP's blog calls Class C the replacement for Moderate, but its rules say classes only loosely align with NIST impact levels. A class reflects the assurance your package provides, so there is no one-to-one mapping.

How many automated validation methods does Class C require?
At least two per KSI, per FRC-CSX-VVK. Class B recommends one, and Class D requires four. Paramify runs automated validators against the tools you map to each KSI.

How much KSI history do I need?
Six months for all KSIs, per FRC-CSX-MOT. You don't need all of it to apply. If your service hasn't been running those metrics that long, FedRAMP says you need the mechanisms in place and must agree to meet the requirement over time.

Do all the rules need to be fully implemented before I apply?
No. Planned and partially implemented rules and KSIs are acceptable and don't block certification. Each one needs a planned implementation date, how you'll implement it, and why it isn't in place yet. FedRAMP prefers accurate status over one stretched to fully implemented. In Paramify, you record the planned date, method, and reason on each partial or planned KSI.

What happens if I don't implement a SHOULD?
You must explain why. Every MUST and SHOULD needs an explanation, or the package is incomplete. FedRAMP expects the reasons for skipping a SHOULD to be limited.

When can I apply?
The Class B and C pipelines opened August 31, 2026. You must be in the FedRAMP Marketplace first and submit the application yourself.

Should I go straight to Class C?
FedRAMP advises against it unless an existing agency contract requires it. Most new providers should start at Class A.

Isaac Teuscher
A Security Engineer leading the technical implementation of cloud and AI-driven security. With experience in NIST 800-53 and FedRAMP, Isaac collaborates with executive teams to build scalable security programs that meet the highest federal compliance standards.
Oct 2026
Related posts

Paramify blog

Interviews, tips, guides, industry best practices, and news.

When Do You Have to Report an Incident to FedRAMP?

An incident is reportable to FedRAMP only if it has affected, or is likely to affect, the confidentiality or integrity of federal customer data. Reportable incidents require three reports, initial, ongoing, and final, all using the FedRAMP Incident Report JSON schema, with timeframes ranging from 15 minutes at Class D to six hours at Class A and B. For Rev 5 systems, the grace period for this ruleset ends June 1, 2027.
Read post

FedRAMP Class C (Moderate) vs Class D (High)

FedRAMP Class C (formerly Moderate, ~323–325 controls) and Class D (formerly High, ~421 controls) differ in far more than control count — cost roughly doubles to triples, encryption and MFA requirements change categorically, and Class D remains Rev 5-only until FedRAMP 20x Class D opens in early 2027. Most federal SaaS companies need Class C; Class D is reserved for law enforcement, health, financial, and emergency services data.
Read post

What is FedRAMP Class B?

FedRAMP Class B is the second of four FedRAMP Certification Classes, replacing the old Low impact level. It requires providers to address every applicable Key Security Indicator directly, with at least one automated validation method per KSI, an annual independent assessment, and a maintained Security Decision Record — without the stricter automation, historical-metrics, or GovCloud requirements that kick in at Class C and up.
Read post

Frequently Asked Questions

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Can compliance advisors or consultants work in Paramify with us, and does it help with managed-service models?

Absolutely. Paramify is used by many advisory partners, RPOs, and MSPs to guide, generate, and manage documentation, perform gap assessments, facilitate policy/procedure drafting, and oversee remediation activities. Advisors can fill out templates, manage controls, and generate client-ready documents.

‍

We have privacy or compliance concerns, can we restrict what external reviewers can access?

Yes, you can assign role-based access controls in Paramify. Advisors or auditors can be given access only to certain programs, assessment and their related evidence.

Sensitive information can be withheld or redacted as needed, and only certified reviewers see specific items.

‍

Can auditors or advisory partners get direct access to our Paramify environment, or do we have to export everything for them?

Yes, Paramify allows external assessors/auditors and advisors to be invited as users, with controlled permission levels. They can review specific evidence, policies, SSPs, POA&Ms, or assessment modules without accessing broader company data. 

Documentation — such as Appendix A, SSPs, procedures, and POAMs — can also be exported in multiple standard formats (Word, Excel, OSCAL, EMASS, PDF) as needed.

Can I get matched with an Advisor based on my specific needs?

Yes. You can use the Get Matched feature on our website. We will review your specific compliance goals and connect you with the partner best suited for your industry and timeline.

How do Advisors use Paramify during a FedRAMP engagement?

Advisors use Paramify to conduct Gap Assessments, map controls, Automate SSPs, and manage POA&Ms.

Instead of spending months writing Word documents, the Advisor inputs the system architecture and control implementations into Paramify, which then generates the required NIST-formatted documentation.

Does Paramify compete with its Advisors?

No. Paramify is a software company. We do not offer independent audit or long-term consulting services. Our goal is to empower Advisors with better tools so they can serve more clients effectively.

‍

What are the different partner tiers?

We feature Premier Partners prominently on our site. These are firms that have demonstrated a high level of proficiency with the Paramify platform and have successfully helped many clients through the certification process using our tools.

How do I become an official Paramify Advisor Partner?

We look for firms with a proven track record in federal compliance. If you are interested in joining our network and leveraging our automation products, you can reach out via our contact page or schedule a demo to see how our tools fit into your workflow.

What is the benefit of using an Advisor who uses Paramify vs. one who doesn't?

Advisors using Paramify can accelerate your implementation and typically deliver documentation in a fraction of the time it takes without Paramify. This means:

  • Faster Implementation: An accelerated implementation roadmap keeps timelines predictable.
  • Lower Costs: Reduced manual consultant hours.
  • Higher Accuracy: Automation eliminates the "copy-paste" errors common in traditional SSPs.‍
  • Easier Maintenance: Your Advisor can help you manage POA&Ms and continuous monitoring within the platform.
Does working with an Advisor on this list guarantee FedRAMP or CMMC authorization?

No firm can "guarantee" authorization, as the final decision rests with the government authorizing body (e.g., the FedRAMP PMO or the DoD).

However, working with a Paramify Advisor significantly reduces the risk of documentation errors and ensures your package is built on a technically sound, automated foundation.

‍

How do I choose the right Advisor for my organization?

Our Advisor page allows you to filter partners by their specific expertise, such as FedRAMP, CMMC, FISMA, or GovRAMP.

Why does Paramify partner with Advisors?

Paramify is an “Iron Man suit” for GRC experts. We provide automation technology to generate and manage compliance documentation (like SSPs snd POA&Ms) while Advisors provide the expert human oversight and implementation expertise.

Together, we offer a "best-of-both-worlds" solution: expert consulting powered by industry-leading automation and risk management planning.

What is the Paramify Advisor Partner Network?

The Paramify Advisor Partner Network is a curated group of cybersecurity and compliance firms — including CMMC Registered Practitioner Organizations (RPOs) and accredited Independent Assessors— that use Paramify’s platform to deliver faster, more accurate compliance outcomes for their clients.

I already have an advisor or very capable GRC team. Why do I need Paramify?

Use Paramify's Risk Solution platform to automate ATO packages, improving cost efficiency, speed, and accuracy. This frees your team to focus on more valuable efforts like security posture enhancement and compliance improvements.