Skip to main content

Elevate

FedRAMP High After CR26: What Replaces the Baseline

FedRAMP High is a legacy term. The label itself, along with Low and Moderate, was retired from FedRAMP’s vocabulary under the Consolidated Rules for 2026, replaced by a four-tier Certification Class structure running A through D. A cloud service that would have been described as FedRAMP High a year ago is now certified at Class D, and understanding that mapping is only the first step. What actually changes operationally, beyond the label, is what most guidance on this topic gets wrong by treating the shift as a simple rename.

This article explains why the High designation was retired, what Class D actually is and is not, and what genuinely changes for a provider operating at this tier, versus what stays the same underneath new terminology.

Why “FedRAMP High” Disappeared From FedRAMP’s Vocabulary

The retirement of Low, Moderate, and High was not a cosmetic decision. It traces to a specific, formally documented problem the old terminology created.

The DoD Impact Level Confusion That Drove the Change

FedRAMP’s Low, Moderate, and High impact levels, drawn from FIPS 199, existed alongside a completely separate Department of Defense Impact Level system, IL2 through IL6, used for DoD cloud authorizations. The two systems shared vocabulary without sharing meaning. A cloud service described as FedRAMP Moderate did not automatically satisfy DoD IL4, and a FedRAMP High system did not automatically satisfy IL5, but the overlapping language in marketing materials, procurement documents, and security collateral produced genuine confusion about which standard actually applied to a given requirement. FedRAMP’s decision to move to lettered Classes rather than a renumbered or renamed level system was deliberately chosen to break this overlap entirely. There is no Class equivalent to a DoD Impact Level, and treating Class D as interchangeable with IL5 repeats the exact confusion the rename was designed to eliminate.

NTC-0004 and the Formal Retirement

The retirement of impact-level terminology was formally anchored in Public Notice NTC-0004, published February 25, 2026, and finalized as part of the Consolidated Rules for 2026 when CR26 launched in late June 2026. The rules calls the old designations FIPS 199 impact levels; the new structure is the Certification Class system, and the mapping FedRAMP itself describes runs largely one to one: Class A is a new transitional tier with no direct predecessor, Class B covers what was previously Low, including the LI-SaaS variant, Class C covers what was previously Moderate, and Class D covers what was previously High.

What Class D Actually Is

Class D is the direct successor to the FedRAMP High designation, applying to cloud services handling the most sensitive non-classified federal data, where a breach could cause severe or catastrophic harm to operations, assets, or individuals.

The Control Baseline Behind Class D

The underlying NIST SP 800-53 Rev 5 control baseline behind the old High designation does not disappear under the new terminology. The former High baseline required roughly 410 controls across the program’s 17 control families, the most extensive of the three legacy baselines, and that depth of control implementation is what Class D still demands. The rename changes the label applied to this baseline, not the substance of what a provider has to implement and demonstrate to operate at this tier.

Class D Stays on the Agency Path, Not 20x

The single most consequential operational fact about Class D has nothing to do with terminology. Class D is the only Certification Class with no Program path and no FedRAMP 20x path available. Every Class D certification runs through the traditional Agency path, which means a Class D provider still produces the documented evidence package, a System Security Plan, a Security Assessment Plan and Report from an independent assessor, and a Plan of Action and Milestones, rather than the machine-readable Key Security Indicator model available to Classes A through C. This is not a temporary oversight. FedRAMP has been explicit that the 20x pilot program for the highest-sensitivity tier is not yet mature enough to extend the automated evidence model to it, which means a provider requiring what used to be called FedRAMP High should plan for a documentation-intensive certification process regardless of how sophisticated its underlying infrastructure automation already is.

Timing for Providers Currently Pursuing or Holding This Tier

A provider currently working toward a High-tier authorization, or holding one and planning a reauthorization cycle, needs to track two separate dates that interact with Class D specifically. CR26 becomes mandatory for all stakeholders on January 1, 2027, which means a Class D provider’s next assessment after that date is evaluated against the updated Rev5 baseline the Consolidated Rules establish, not the pre-CR26 control set. Separately, FedRAMP stops accepting applications for entirely new Rev5 certifications on June 11, 2027, and since Class D has no alternative path, a provider that has not started a new Class D certification by that date has no route to this tier available at all until FedRAMP potentially opens a 20x option for it in the future, on a timeline the program has not committed to. A provider evaluating whether it genuinely needs Class D, rather than a lower tier, should weigh this closing window as a real planning input, not a distant contingency.

What Actually Changes Operationally

Beyond the terminology itself, three practical changes matter for a provider currently operating, or planning to operate, at this tier.

Terminology in Marketing and Procurement Collateral

Every reference to FedRAMP High in a provider’s marketing materials, procurement documentation, contract language, and security collateral needs updating to Class D to stay accurate and to avoid the exact confusion the rename was meant to eliminate. This is a genuinely tedious but low-risk task, and it is worth treating as a project with an owner and a deadline rather than an update made piecemeal whenever someone happens to notice outdated language in a given document.

Existing High Authorizations Are Not Affected in Substance

A cloud service that already holds a FedRAMP Authorization at the High impact level retains that status; the terminology shift applies going forward to new certifications issued under CR26 rather than retroactively invalidating anything already in place. The practical translation for an existing High-authorized provider is that the next time its authorization language appears in official FedRAMP communications, marketplace listings, or renewal documentation, it will be described as Class D, without the underlying controls, boundary, or assessment history changing as a result of the label alone.

Inheritance Still Works the Same Way, With the Same Class Logic

Control inheritance between cloud service layers continues to function under the new terminology exactly as it did under the old one, just described in Class terms rather than impact-level terms. A service built on top of a Class D platform inherits controls implemented to that platform’s standard, which over-satisfies the requirements of a service that only needs to operate at Class C or Class B itself. This inheritance logic was already true under the old Low, Moderate, High structure, and CR26 did not change the underlying mechanism, only the vocabulary used to describe which tier is doing the inheriting.

A concrete version of this: an application that only needs to meet Class C requirements, but is hosted on infrastructure certified at Class D, inherits the physical and environmental protection controls, among others, at the Class D standard the underlying platform actually implements. The application’s own documentation does not need to re-justify meeting a Class D standard for those inherited controls; it needs to correctly identify which controls are inherited, at what standard, and which remain the application’s own responsibility to implement and document. Getting this division wrong, either by claiming inheritance for a control the platform does not actually cover, or by failing to claim inheritance the organization is genuinely entitled to, produces avoidable rework during assessment either way.

Continuous Monitoring Obligations Do Not Shrink

A Class D certification’s ongoing continuous monitoring obligations remain the most demanding in the program, consistent with what the former High designation required. A provider should not read the terminology change as a signal that ongoing monitoring, reporting cadence, or vulnerability response timelines have relaxed at this tier. If anything, CR26’s broader push toward more frequent, more structured continuous monitoring reporting applies with full force to Class D providers, on top of the tier’s already substantial control set, which means the standing operational cost of holding this certification remains real and recurring, not a one-time certification milestone.

Who Actually Needs Class D

Class D, like the High designation before it, applies to a meaningfully smaller population of cloud services than Class C. Government Accountability Office reporting on FedRAMP authorizations found that approximately 76 percent of agency-leveraged authorizations were moderate-impact as of April 2023, with roughly 17 percent at the high-impact tier and the remainder at low. Most SaaS providers pursuing FedRAMP land at Class C, and a provider evaluating which tier its offering actually requires should treat Class D as the exception rather than a default assumption, since the documentation burden, the required control depth, and the Agency-path-only certification route make it a meaningfully heavier commitment than Class C.

The Determination Is About Data Sensitivity, Not Ambition

The tier a service requires follows from the sensitivity of the federal data it will actually process, store, or transmit, and from the severity of harm a breach would cause, not from how comprehensive an organization wants its security posture to appear. A provider sometimes assumes that pursuing the highest tier signals the strongest security commitment to prospective agency customers, but targeting Class D for data that does not actually require that level of protection adds substantial cost and timeline without a corresponding security or commercial benefit. The correct approach is a genuine data sensitivity determination, typically conducted alongside the agency sponsor or through a FIPS 199-style categorization exercise translated into current Class terminology, before committing to a certification path.

When Class D Is the Right Call

Class D is the right target when the offering will handle information where unauthorized disclosure, modification, or loss of availability would cause severe or catastrophic effects on organizational operations, assets, or individuals, the same threshold that previously defined FedRAMP High. This most commonly applies to systems supporting law enforcement, emergency services, financial systems with systemic significance, or certain categories of personally identifiable information at scale. An organization uncertain whether its offering meets this threshold should work through the determination with its agency sponsor early, since discovering partway through a Class C certification that the actual data sensitivity requires Class D is a far more expensive correction than getting the determination right at the outset.

Understanding the full picture of FedRAMP certification requirements under CR26 sets Class D in context alongside the Key Security Indicator model available to Classes A through C, and mapping the underlying control language that survives the terminology change helps a security team translate its existing control knowledge into the new Class vocabulary without relearning security fundamentals that did not actually change. A provider transitioning an existing High authorization should also review the broader Rev5 transition timeline, since Class D’s exclusive reliance on the Agency path ties it directly to the Rev5 evidence model rather than the 20x path most other providers are moving toward.

The Cost Difference Is Substantial, Not Marginal

The jump from Class C to Class D is not a modest step up in effort. The additional roughly 87 controls the former High baseline required over Moderate, concentrated heavily in areas like access control, audit and accountability, and system and communications protection, translate into a meaningfully longer assessment, a larger body of evidence to produce and maintain, and a correspondingly higher assessment fee from the independent assessor performing the review. Organizations sizing a certification budget should treat Class C and Class D as different orders of magnitude in scope, not adjacent points on a smooth cost curve, and should confirm the target Class early enough that the budget presented to leadership reflects the tier the offering will actually require rather than an assumption made before the data sensitivity determination was complete.

Elevate helps cloud service providers translate their FedRAMP High authorizations and roadmaps into the current Class D structure, confirm which Certification Class their actual offering requires, and navigate the documentation-intensive path Class D still demands under CR26. To determine which Certification Class applies to your service and confirm your compliance posture translates correctly, book a readiness call with an Elevate advisor.

Conclusion

FedRAMP High is retired vocabulary, replaced by Class D under the Consolidated Rules for 2026, but the substance behind the label changes far less than the rename suggests. The control baseline remains as extensive as before, existing authorizations remain valid, and inheritance works the same way it always did. What genuinely changes operationally is narrower and more specific: every reference to the old terminology needs updating, and any provider requiring this tier needs to plan for a documentation-intensive Agency-path certification, since Class D is the one tier CR26’s machine-readable evidence model does not yet reach.

Treating this as a pure terminology exercise misses the one change that actually matters for a provider’s roadmap: no 20x path is coming to this tier anytime soon. Elevate helps providers plan accordingly. Book a readiness call to confirm what Class D actually requires of your specific certification path.

Key Takeaways

  • FedRAMP High is retired terminology, replaced by Certification Class D under CR26. The formal retirement traces to NTC-0004, published February 25, 2026, and finalized in the Consolidated Rules for 2026.
  • The rename resolves confusion with the separate DoD Impact Level system. Class D has no equivalent to DoD IL5, and treating the two as interchangeable repeats the exact confusion the change was designed to eliminate.
  • The underlying control baseline behind Class D has not changed. The former High baseline’s roughly 410 NIST SP 800-53 Rev 5 controls across 17 control families remain the substantive requirement; only the label changed.
  • Class D is the only Certification Class with no 20x path. Every Class D certification runs through the traditional Agency path with a documented SSP, independent assessment, and POA&M, regardless of how automated a provider’s underlying infrastructure already is.
  • Existing High authorizations remain valid without retroactive changes. The terminology shift applies to new certifications going forward; a currently authorized provider’s controls and boundary do not change because of the label alone.

FAQs

What is FedRAMP High called now? FedRAMP High is now called Class D under the Consolidated Rules for 2026. CR26 retired the FIPS 199 impact-level labels of Low, Moderate, and High and replaced them with four lettered Certification Classes: Class B corresponds to the former Low, Class C to the former Moderate, and Class D to the former High.

What is the difference between FedRAMP High and FedRAMP Moderate under the new terminology? Under CR26, the former High designation is Class D and the former Moderate designation is Class C. The underlying difference remains what it always was: Class D applies to systems where a breach could cause severe or catastrophic harm and requires a substantially deeper control baseline, roughly 410 NIST SP 800-53 Rev 5 controls compared to Moderate’s roughly 323, across the same 17 control families. Class D also remains exclusively on the Agency path with no 20x option, while most Class C services can pursue the streamlined 20x model.

What controls are required for FedRAMP High or Class D? Class D requires the full NIST SP 800-53 Rev 5 control baseline that previously defined the FedRAMP High designation, approximately 410 controls across the program’s 17 control families. This remains the most extensive control requirement in the FedRAMP program, and CR26’s terminology change did not reduce or restructure this underlying control depth.

Does my existing FedRAMP High authorization need to be redone under CR26? No. An existing FedRAMP Authorization at the High impact level remains valid, and the terminology shift to Class D applies to how new certifications are labeled going forward rather than invalidating or requiring a redo of an authorization already in place. Over time, official FedRAMP communications and marketplace listings referencing that authorization will describe it as Class D.

Is FedRAMP Class D the same as DoD Impact Level 5? No, and this is one of the specific confusions the terminology change was designed to eliminate. FedRAMP’s Certification Classes and the Department of Defense’s Impact Level system, IL2 through IL6, are separate constructs with no direct equivalence. A FedRAMP Class D certification does not automatically satisfy DoD IL5 requirements, and providers should evaluate each framework’s requirements independently rather than assuming interchangeability based on similar-sounding tier names.