In This Article
FedRAMP Class C and Class D are two of the four certification classes FedRAMP uses to scope how rigorously a cloud service gets assessed — Class C (formerly Moderate) covers controlled unclassified information and general federal SaaS, while Class D (formerly High) covers the most sensitive data: law enforcement, health, financial, and emergency services systems.
The gap between them isn't small: roughly 100 more controls, at least double the cost, and a meaningfully harder assessment.
If you're deciding which one your organization actually needs, here's the real difference.
FedRAMP Class C vs. Class D: The side-by-side comparison
FYI, if you’re evaluating Class D, it's not just "more of the same controls."
FIPS 140-3 Level 3 and hardware-token MFA are different infrastructure requirements, not scaled-up versions of what Class C requires, we’ll get deeper into that below.
Considering Class B too, not just C and D? Paramify's full Class B, C, D breakdown covers all three side by side.
Who actually needs Class C vs. Class D?
Class C (Moderate) is where the majority of federal SaaS live.
It’s for CRM systems, collaboration platforms, anything handling CUI or general business data where a breach would cause serious but not catastrophic harm.
Class D (High) exists for a narrower set of systems: law enforcement records and criminal justice data, health data tied to patient safety, financial systems where compromise could destabilize operations, and emergency services systems where downtime has physical-world consequences.
Real-world Class D holders include the major cloud infrastructure providers (AWS GovCloud, Microsoft Azure Government, Google Cloud) and specialists like UberEther, which holds both FedRAMP High and DoD IL5.
The overlap with DoD isn't an accident. Basically every DoD Impact Level Authorization builds on top of Class D. If DoD workloads are on your roadmap, see FedRAMP vs. DoD IL ATO for how the two stack.
FedRAMP's own guidance discourages jumping straight to Class D without a confirmed agency requirement driving it. If you're not certain which class you need, FedRAMP recommends you get started with Class A, but Class C will open the most doors.
What changes when you go from Class C to Class D?
Moving from Class C to Class D is not a simple upgrade. You aren’t just adding ~100 controls. \
Several of Class D's requirements are categorically different, like these:
- Encryption infrastructure changes. FIPS 140-3 Level 3 validated modules are a different procurement and implementation decision than Level 1/2, not a configuration toggle.
- MFA hardware requirement. A hardware token like YubiKey is typically expected at Class D — software-based MFA that satisfied Class C usually doesn't clear the bar.
- Assessor scrutiny increases. The same 3PAO reviewing your Class D package is now looking for evidence that maps to catastrophic-harm scenarios, and control narratives that passed review at Class C routinely get kicked back at Class D.
Budget for this as a new certification effort layered on your existing one, not a delta project.
Can you get Class D under FedRAMP 20x yet?
Not yet, but FedRAMP 20x Class D will be available in 2027, if all goes according to plan.
FYI: New Rev 5 certification applications stop being accepted entirely on June 11, 2027, and existing Rev 5 certifications sunset December 31, 2028. If Class D is on your roadmap, you're choosing now between racing the Rev 5 deadline or waiting for 20x Class D to open.
How Paramify helps with FedRAMP Class C and Class D Certification
Paramify is a risk management platform first — certification is the outcome of managing that risk posture well, not the goal itself. That shows up differently at each class.
At Class C, Paramify auto-generates any required deliverables.
At Class D, the same engine handles the larger control set — in one case, a Paramify customer maintaining their Class D certification needed a complete package in under two weeks. Paramify generated it in 3.5 hours. Read the full case study.
Class D also has more moving parts, and that's where inheritance modeling matters most — documenting what's inherited from AWS GovCloud or Azure Government versus what your team owns, across roughly 421 controls instead of 325. Paramify's Solution Capabilities model that ownership and inheritance natively rather than requiring it to be rebuilt by hand for each system.
You can easily meet and maintain new CR26 requirements for both Class C and Class D with Paramify.
The bottom line
Class C and Class D aren't two points on the same scale — Class D is a different cost structure, a different encryption and MFA baseline, and a harder assessment, not just more of what Class C already requires. Knowing which one your organization actually needs, before you commit budget to either, is the decision this comparison exists to inform.
FAQ
Is FedRAMP Class D the same as FedRAMP High?
Yes. Class D is the new name for the legacy High baseline, effective from FedRAMP's May 2026 terminology change (Notice NTC-0004). The controls and intent are unchanged; only the label changed. Both terms are in active use during the transition to mandatory adoption in January 2027.
What's the difference between FedRAMP Class C and Class D?
Class C (formerly Moderate) requires roughly 323–325 NIST SP 800-53 Rev 5 controls for controlled unclassified information and general federal data. Class D (formerly High) requires roughly 421 controls for highly sensitive data — law enforcement, health, financial, and emergency services — plus stricter encryption (FIPS 140-3 Level 3) and typically hardware-based MFA.
How much more does Class D cost than Class C?
Class C typically runs $500K–$1.5M in initial certification costs with $200K–$500K in ongoing annual costs. Class D typically runs $1M–$3M+ initially with $500K–$1M annually — roughly double to triple across the board.
Who needs FedRAMP Class D?
Cloud service providers handling highly sensitive data where a breach would cause severe or catastrophic harm — law enforcement, health, financial, and emergency services systems most commonly. Most federal SaaS companies need Class C, not Class D.
Can I get FedRAMP Class D through 20x yet?
Not yet as a general pipeline. Class D is planned to pilot under FedRAMP 20x in late 2026, with formal availability expected in early 2027. Today, Class D certifications go through the traditional Rev 5 path.
If I'm already Class C, can I just add controls to reach Class D?
Not cleanly. Several Class D requirements — FIPS 140-3 Level 3 encryption, hardware MFA tokens, an 18-month KSI evidence history under 20x — are different infrastructure and process decisions, not incremental additions. Budget it as a new certification effort.
Do I need a 3PAO for Class D?
Yes, under the traditional Rev 5 path. Once 20x Class D opens, some 3PAO functions shift toward automated KSI validation, similar to how Class B/C work under 20x today.
What's the difference between FedRAMP Class D and DoD Impact Level 5?
Class D is a FedRAMP baseline for civilian and general federal use. DoD Impact Levels (IL4, IL5, IL6) are DoD-specific and typically build additional controls on top of a Class D/High baseline. See FedRAMP vs. DoD IL ATO for the full comparison.
Should I start at Class C or go straight to Class D?
Start at Class C unless you have a confirmed agency requirement driving Class D specifically. FedRAMP's own guidance discourages jumping to the highest class without one — starting at Class C and expanding later is the lower-risk path for most CSPs.
What's the 18-month KSI history requirement about?
Under CR26, FedRAMP 20x Class D will require 18 months of historical Key Security Indicator metrics at application — versus 6 months for Class C. It can't be backfilled, so organizations planning a future Class D pursuit should start collecting KSI evidence well before they apply.
.avif)


