FedRAMP Class C (Moderate) vs Class D (High)

FedRAMP Class C (formerly Moderate, ~323–325 controls) and Class D (formerly High, ~421 controls) differ in far more than control count — cost roughly doubles to triples, encryption and MFA requirements change categorically, and Class D remains Rev 5-only until FedRAMP 20x Class D opens in early 2027. Most federal SaaS companies need Class C; Class D is reserved for law enforcement, health, financial, and emergency services data.

Adam Johnson
|
53
min read

In This Article

FedRAMP Class C and Class D are two of the four certification classes FedRAMP uses to scope how rigorously a cloud service gets assessed — Class C (formerly Moderate) covers controlled unclassified information and general federal SaaS, while Class D (formerly High) covers the most sensitive data: law enforcement, health, financial, and emergency services systems. 

The gap between them isn't small: roughly 100 more controls, at least double the cost, and a meaningfully harder assessment. 

If you're deciding which one your organization actually needs, here's the real difference.

FedRAMP Class C vs. Class D: The side-by-side comparison

Class C (Moderate) Class D (High)
Data sensitivity Serious harm — CUI, PII, financial records Severe or catastrophic harm — law enforcement, health, financial, emergency services
Controls (NIST SP 800-53 Rev 5) ~323–325 ~421
Encryption requirement FIPS 140-3 validated modules FIPS 140-3 Level 3+
MFA Standard multi-factor Hardware token (e.g., YubiKey) typically required
Initial certification cost $500K–$1.5M $1M–$3M+
Ongoing annual cost $200K–$500K $500K–$1M
Share of FedRAMP marketplace ~80% of certified CSPs Smallest share — reserved for the most sensitive systems
20x historical KSI requirement (CR26) 6 months 18 months

FYI, if you’re evaluating Class D, it's not just "more of the same controls." 

FIPS 140-3 Level 3 and hardware-token MFA are different infrastructure requirements, not scaled-up versions of what Class C requires, we’ll get deeper into that below.

Considering Class B too, not just C and D? Paramify's full Class B, C, D breakdown covers all three side by side.

Who actually needs Class C vs. Class D?

Class C (Moderate) is where the majority of federal SaaS live.

It’s for CRM systems, collaboration platforms, anything handling CUI or general business data where a breach would cause serious but not catastrophic harm.

Class D (High) exists for a narrower set of systems: law enforcement records and criminal justice data, health data tied to patient safety, financial systems where compromise could destabilize operations, and emergency services systems where downtime has physical-world consequences. 

Real-world Class D holders include the major cloud infrastructure providers (AWS GovCloud, Microsoft Azure Government, Google Cloud) and specialists like UberEther, which holds both FedRAMP High and DoD IL5.

The overlap with DoD isn't an accident. Basically every DoD Impact Level Authorization builds on top of Class D. If DoD workloads are on your roadmap, see FedRAMP vs. DoD IL ATO for how the two stack.

FedRAMP's own guidance discourages jumping straight to Class D without a confirmed agency requirement driving it. If you're not certain which class you need, FedRAMP recommends you get started with Class A, but Class C will open the most doors. 

Find Your Best FedRAMP Class

Get a Free Gap Assessment

What changes when you go from Class C to Class D?

Moving from Class C to Class D is not a simple upgrade. You aren’t just adding ~100 controls. \

Several of Class D's requirements are categorically different, like these:

  • Encryption infrastructure changes. FIPS 140-3 Level 3 validated modules are a different procurement and implementation decision than Level 1/2, not a configuration toggle.
  • MFA hardware requirement. A hardware token like YubiKey is typically expected at Class D — software-based MFA that satisfied Class C usually doesn't clear the bar.
  • Assessor scrutiny increases. The same 3PAO reviewing your Class D package is now looking for evidence that maps to catastrophic-harm scenarios, and control narratives that passed review at Class C routinely get kicked back at Class D.

Budget for this as a new certification effort layered on your existing one, not a delta project.

Can you get Class D under FedRAMP 20x yet?

Not yet, but FedRAMP 20x Class D will be available in 2027, if all goes according to plan.  

FYI: New Rev 5 certification applications stop being accepted entirely on June 11, 2027, and existing Rev 5 certifications sunset December 31, 2028. If Class D is on your roadmap, you're choosing now between racing the Rev 5 deadline or waiting for 20x Class D to open.

How Paramify helps with FedRAMP Class C and Class D Certification

Paramify is a risk management platform first — certification is the outcome of managing that risk posture well, not the goal itself. That shows up differently at each class.

At Class C, Paramify auto-generates any required deliverables. 

At Class D, the same engine handles the larger control set — in one case, a Paramify customer maintaining their Class D certification needed a complete package in under two weeks. Paramify generated it in 3.5 hours. Read the full case study. 

Class D also has more moving parts, and that's where inheritance modeling matters most — documenting what's inherited from AWS GovCloud or Azure Government versus what your team owns, across roughly 421 controls instead of 325. Paramify's Solution Capabilities model that ownership and inheritance natively rather than requiring it to be rebuilt by hand for each system.

You can easily meet and maintain new CR26 requirements for both Class C and Class D with Paramify. 

New to Paramify? See what the platform does and who it's for.

Read the overview

The bottom line

Class C and Class D aren't two points on the same scale — Class D is a different cost structure, a different encryption and MFA baseline, and a harder assessment, not just more of what Class C already requires. Knowing which one your organization actually needs, before you commit budget to either, is the decision this comparison exists to inform.

FedRAMP Class C vs Class D

Ready to find out where you stand?

Paramify gives security teams continuous visibility into control effectiveness at either class, so whatever certification you pursue reflects real, current posture — not a document that goes stale the moment it's signed.

Schedule a Demo

FAQ

Is FedRAMP Class D the same as FedRAMP High?
Yes. Class D is the new name for the legacy High baseline, effective from FedRAMP's May 2026 terminology change (Notice NTC-0004). The controls and intent are unchanged; only the label changed. Both terms are in active use during the transition to mandatory adoption in January 2027.

What's the difference between FedRAMP Class C and Class D?
Class C (formerly Moderate) requires roughly 323–325 NIST SP 800-53 Rev 5 controls for controlled unclassified information and general federal data. Class D (formerly High) requires roughly 421 controls for highly sensitive data — law enforcement, health, financial, and emergency services — plus stricter encryption (FIPS 140-3 Level 3) and typically hardware-based MFA.

How much more does Class D cost than Class C?
Class C typically runs $500K–$1.5M in initial certification costs with $200K–$500K in ongoing annual costs. Class D typically runs $1M–$3M+ initially with $500K–$1M annually — roughly double to triple across the board.

Who needs FedRAMP Class D?
Cloud service providers handling highly sensitive data where a breach would cause severe or catastrophic harm — law enforcement, health, financial, and emergency services systems most commonly. Most federal SaaS companies need Class C, not Class D.

Can I get FedRAMP Class D through 20x yet?
Not yet as a general pipeline. Class D is planned to pilot under FedRAMP 20x in late 2026, with formal availability expected in early 2027. Today, Class D certifications go through the traditional Rev 5 path.

If I'm already Class C, can I just add controls to reach Class D?
Not cleanly. Several Class D requirements — FIPS 140-3 Level 3 encryption, hardware MFA tokens, an 18-month KSI evidence history under 20x — are different infrastructure and process decisions, not incremental additions. Budget it as a new certification effort.

Do I need a 3PAO for Class D?
Yes, under the traditional Rev 5 path. Once 20x Class D opens, some 3PAO functions shift toward automated KSI validation, similar to how Class B/C work under 20x today.

What's the difference between FedRAMP Class D and DoD Impact Level 5?
Class D is a FedRAMP baseline for civilian and general federal use. DoD Impact Levels (IL4, IL5, IL6) are DoD-specific and typically build additional controls on top of a Class D/High baseline. See FedRAMP vs. DoD IL ATO for the full comparison.

Should I start at Class C or go straight to Class D?
Start at Class C unless you have a confirmed agency requirement driving Class D specifically. FedRAMP's own guidance discourages jumping to the highest class without one — starting at Class C and expanding later is the lower-risk path for most CSPs.

What's the 18-month KSI history requirement about?
Under CR26, FedRAMP 20x Class D will require 18 months of historical Key Security Indicator metrics at application — versus 6 months for Class C. It can't be backfilled, so organizations planning a future Class D pursuit should start collecting KSI evidence well before they apply.

Adam Johnson
A 15 year veteran in software development, product marketing and product management. He's now specializing in Cybersecurity and Compliance.‍ A family man at heart, Adam enjoys biking, soccer, and traveling with his wife and three kids.
Sep 2026
Related posts

Paramify blog

Interviews, tips, guides, industry best practices, and news.

What is FedRAMP Class B?

FedRAMP Class B is the second of four FedRAMP Certification Classes, replacing the old Low impact level. It requires providers to address every applicable Key Security Indicator directly, with at least one automated validation method per KSI, an annual independent assessment, and a maintained Security Decision Record — without the stricter automation, historical-metrics, or GovCloud requirements that kick in at Class C and up.
Read post

What Does Paramify Do?

Paramify is a risk management platform that unifies and automates implementation, monitoring, and reporting across NIST 800-53, FedRAMP 20x, CMMC, SOC 2, and other federal and commercial frameworks from a single platform. Learn how Paramify works and see customer results.
Read post

Which CR26 Deliverables Does Paramify Automate?

CR26 replaces FedRAMP's annual Rev 5 documentation with the Trust Center, SDR, VDR/VER, SCN, and CPO that update continuously rather than once a year. Paramify automates all five today, and as of FedRAMP Notice NTC-0014, every certified CSP now has a hard December 7, 2026 deadline to meet VDR/VER, not just providers on the 20x track.
Read post

Frequently Asked Questions

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Can compliance advisors or consultants work in Paramify with us, and does it help with managed-service models?

Absolutely. Paramify is used by many advisory partners, RPOs, and MSPs to guide, generate, and manage documentation, perform gap assessments, facilitate policy/procedure drafting, and oversee remediation activities. Advisors can fill out templates, manage controls, and generate client-ready documents.

‍

We have privacy or compliance concerns, can we restrict what external reviewers can access?

Yes, you can assign role-based access controls in Paramify. Advisors or auditors can be given access only to certain programs, assessment and their related evidence.

Sensitive information can be withheld or redacted as needed, and only certified reviewers see specific items.

‍

Can auditors or advisory partners get direct access to our Paramify environment, or do we have to export everything for them?

Yes, Paramify allows external assessors/auditors and advisors to be invited as users, with controlled permission levels. They can review specific evidence, policies, SSPs, POA&Ms, or assessment modules without accessing broader company data. 

Documentation — such as Appendix A, SSPs, procedures, and POAMs — can also be exported in multiple standard formats (Word, Excel, OSCAL, EMASS, PDF) as needed.

Can I get matched with an Advisor based on my specific needs?

Yes. You can use the Get Matched feature on our website. We will review your specific compliance goals and connect you with the partner best suited for your industry and timeline.

How do Advisors use Paramify during a FedRAMP engagement?

Advisors use Paramify to conduct Gap Assessments, map controls, Automate SSPs, and manage POA&Ms.

Instead of spending months writing Word documents, the Advisor inputs the system architecture and control implementations into Paramify, which then generates the required NIST-formatted documentation.

Does Paramify compete with its Advisors?

No. Paramify is a software company. We do not offer independent audit or long-term consulting services. Our goal is to empower Advisors with better tools so they can serve more clients effectively.

‍

What are the different partner tiers?

We feature Premier Partners prominently on our site. These are firms that have demonstrated a high level of proficiency with the Paramify platform and have successfully helped many clients through the certification process using our tools.

How do I become an official Paramify Advisor Partner?

We look for firms with a proven track record in federal compliance. If you are interested in joining our network and leveraging our automation products, you can reach out via our contact page or schedule a demo to see how our tools fit into your workflow.

What is the benefit of using an Advisor who uses Paramify vs. one who doesn't?

Advisors using Paramify can accelerate your implementation and typically deliver documentation in a fraction of the time it takes without Paramify. This means:

  • Faster Implementation: An accelerated implementation roadmap keeps timelines predictable.
  • Lower Costs: Reduced manual consultant hours.
  • Higher Accuracy: Automation eliminates the "copy-paste" errors common in traditional SSPs.‍
  • Easier Maintenance: Your Advisor can help you manage POA&Ms and continuous monitoring within the platform.
Does working with an Advisor on this list guarantee FedRAMP or CMMC authorization?

No firm can "guarantee" authorization, as the final decision rests with the government authorizing body (e.g., the FedRAMP PMO or the DoD).

However, working with a Paramify Advisor significantly reduces the risk of documentation errors and ensures your package is built on a technically sound, automated foundation.

‍

How do I choose the right Advisor for my organization?

Our Advisor page allows you to filter partners by their specific expertise, such as FedRAMP, CMMC, FISMA, or GovRAMP.

Why does Paramify partner with Advisors?

Paramify is an “Iron Man suit” for GRC experts. We provide automation technology to generate and manage compliance documentation (like SSPs snd POA&Ms) while Advisors provide the expert human oversight and implementation expertise.

Together, we offer a "best-of-both-worlds" solution: expert consulting powered by industry-leading automation and risk management planning.

What is the Paramify Advisor Partner Network?

The Paramify Advisor Partner Network is a curated group of cybersecurity and compliance firms — including CMMC Registered Practitioner Organizations (RPOs) and accredited Independent Assessors— that use Paramify’s platform to deliver faster, more accurate compliance outcomes for their clients.

I already have an advisor or very capable GRC team. Why do I need Paramify?

Use Paramify's Risk Solution platform to automate ATO packages, improving cost efficiency, speed, and accuracy. This frees your team to focus on more valuable efforts like security posture enhancement and compliance improvements.