Skip to main content

Elevate

FedRAMP Moderate Is Now Class C: What Changed

FedRAMP Moderate certification no longer exists as a standalone destination on the FedRAMP Marketplace. Under the Consolidated Rules for 2026, the designation formerly known as FedRAMP Moderate is now Class C, and a provider searching for how to pursue Moderate authorization today is searching for a label the program retired. The underlying risk tier survives largely intact. What changed is the name, the terminology it no longer collides with, and, depending on which certification type a provider pursues, the entire evidence model behind it. This article covers why the rename happened, what actually moved versus what only got relabeled, and what a provider pursuing Class C through FedRAMP 20x specifically has to prove.

Why FedRAMP Moderate Became Class C

The Renaming Traces to a Specific, Documented Problem

The retirement of Low, Moderate, and High was not a cosmetic decision made for its own sake. FedRAMP’s impact levels, drawn from FIPS 199, existed alongside a completely separate Department of Defense Impact Level system, IL2 through IL6, used for DoD cloud authorizations. The two systems shared vocabulary without sharing meaning. A cloud service described as FedRAMP Moderate did not automatically satisfy DoD IL4, and the overlapping language in marketing materials and procurement documents produced genuine confusion about which standard actually applied to a given requirement.

The retirement was formally anchored in Public Notice NTC-0004, published February 25, 2026, and finalized as part of the Consolidated Rules for 2026 when CR26 launched in late June. The new Certification Class structure maps largely one to one to the retired levels: Class A is a new transitional tier with no direct predecessor, Class B covers what was previously Low, Class C covers what was previously Moderate, and Class D covers what was previously High.

What Actually Changed Versus What Only Got Relabeled

The mapping between old and new terminology is close to direct, which is worth stating plainly because it resolves the most common anxiety providers have about this change. A provider authorized at Moderate today becomes FedRAMP Certified at Class C without needing to re-authorize from scratch. The underlying risk tier, the type of data in scope, and the general severity of a breach at that tier did not move.

What did change is more specific than the class label. The evidence model a provider builds against Class C depends on which certification type it pursues, Rev5 or 20x, and that choice determines whether the provider is still assembling a traditional NIST 800-53 control set or building toward a machine-readable rules and indicators structure that did not exist under the legacy Moderate baseline at all. The name change is close to cosmetic. The evidence model underneath it, for a provider on the 20x path, is not.

What FedRAMP Moderate, Now Class C, Actually Covers

The Data and Risk Profile Did Not Move

Class C applies to systems handling Controlled Unclassified Information and other non-public federal data, where a breach could cause serious harm, meaning disrupted operations, compromised personal data, or financial loss, without rising to the catastrophic consequences reserved for Class D. This is the same profile FedRAMP Moderate covered under the legacy terminology, and it remains the most common certification tier in the program. Historical GAO reporting put roughly three-quarters of agency-leveraged authorizations at the moderate-impact tier, and there is no indication the underlying distribution of federal cloud workloads shifted when the label did.

Where Class C Sits Among the Four Classes

Class C sits between Class B, the lightest tier, and Class D, the tier reserved for mission-critical systems where a breach could be catastrophic. Elevate’s guide to FedRAMP controls and classes covers the full breakdown across all four classes and their approximate control counts under Rev5. What is worth stating here, rather than repeating that full breakdown, is the practical reason Class C matters disproportionately to the provider community: most SaaS products that handle any federal data land at Class C, which makes it the tier the largest share of the market actually has to build toward, rather than a specialized case.

Two Paths to Class C: Rev5 and 20x

Rev5 Class C Is Still the Traditional Control Model

A provider pursuing Class C through Rev5 builds against the NIST SP 800-53 control catalog, roughly 323 to 325 controls at this tier, documented through a System Security Plan, assessed by a FedRAMP Recognized Assessor, and reported through the traditional narrative and spreadsheet-based evidence model that has defined FedRAMP for over a decade. This path suits providers with complex or legacy infrastructure, and it remains available through the Agency Certification path with a sponsoring agency, or in limited cases through the temporary sponsorless pipelines described in Elevate’s guide to FedRAMP ATO in 2026.

20x Class C Replaces the Control Count With Rules and Indicators

A provider pursuing Class C through FedRAMP 20x builds against a structurally different evidence model. Instead of a control count, the 20x path defines Class C, labeled Significant, through a specific set of applicable rules drawn from the FedRAMP Consolidated Rules, organized across the rulesets that cover marketplace listing, certification, boundary definition, assurance, and package requirements, alongside a defined set of Key Security Indicators mapped back to NIST 800-53 controls. A provider on this path is not producing a narrative SSP. It is producing machine-readable evidence against a named, versioned rule set, submitted through the Program Certification path without requiring an agency sponsor.

This is the path where the terminology change matters most in practice, because there was no 20x Class C evidence requirement under the legacy Moderate label at all. A provider that built its entire compliance muscle memory around the Rev5 control-count model is not just relearning a new name. It is potentially building toward a different kind of evidence entirely, depending on which certification type its architecture and market strategy point toward.

The Two Paths, Side by Side

DimensionRev5 Class C20x Class C
Evidence basisNIST SP 800-53 controls, roughly 323 to 325158 rules plus 46 Key Security Indicators
Core artifactSystem Security Plan, narrativeMachine-readable rules and KSI evidence
AssessorFedRAMP Recognized AssessorValidated against Key Security Indicators
SponsorRequired for Agency pathNot required on Program path
Fits bestComplex or legacy infrastructureCloud-native, well-automated services

Reading across that table, the two paths are not a harder and easier version of the same exercise. They are different evidence disciplines built for different kinds of architecture, and a provider should choose based on which one its actual infrastructure and operational maturity already point toward, not based on which path sounds more familiar from prior FedRAMP experience.

What the 20x Class C Rule Set Actually Requires

158 Rules Across 15 Rulesets

Under the current CR2026 ruleset, 158 rules apply to a Class C offering pursuing FedRAMP 20x, organized across 15 rulesets that map to the certification process: marketplace listing, FedRAMP certification itself, boundary rulesets, assurance rulesets, and package rulesets. Each rule carries a defined force, meaning whether it is a MUST or a SHOULD, and an explicit statement of which classes it applies to, which means a provider scoping a Class C effort has to filter the full rule set down to what actually binds at this tier rather than assuming every published rule applies uniformly.

46 Key Security Indicators

Alongside the 158 rules, 46 Key Security Indicators apply to Class C, each mapped to specific NIST SP 800-53 controls. The KSIs are the mechanism that connects the 20x evidence model back to the control catalog Rev5 providers already know, without requiring the full narrative documentation Rev5 demands. A provider that has already built strong technical automation, meaning the kind of continuous, machine-generated evidence covered in Elevate’s guide to FedRAMP vulnerability management, is typically better positioned to satisfy KSIs efficiently than a provider whose evidence has historically been assembled manually for each assessment cycle.

The practical shift is in where the effort goes. Under Rev5, a provider’s team spends much of its cycle writing and updating narrative control implementation statements, the prose that describes how each of roughly 325 controls is satisfied. Under 20x, that writing effort shrinks and the engineering effort grows, because a Key Security Indicator is validated by what a provider’s systems actually produce as evidence, not by how well a document describes intended behavior. A provider evaluating which path fits should weigh this honestly: 20x rewards infrastructure that already generates its own compliance evidence as a byproduct of normal operations, and it punishes infrastructure that does not, regardless of how strong the underlying security posture actually is.

The Rules Specific to Class C

Not every rule in the 158 applies uniformly across every 20x class. A defined subset, 25 rules under the current ruleset, applies specifically to Class C rather than to the shared baseline every class carries. This is the detail most likely to be missed by a provider working from a general understanding of 20x requirements rather than a class-specific one: assuming that meeting a generic 20x baseline is sufficient for Class C skips the roughly one in six rules that exist because Class C’s risk profile demands more than the floor every class shares.

Common Mistakes When Mapping Existing Moderate Work to Class C

Assuming Rev5 Moderate Work Transfers Directly to 20x Class C

The single most expensive assumption a provider can make is treating prior Rev5 Moderate work as a head start on 20x Class C. The two certification types are structurally separate, and work completed toward one does not transfer to the other. A provider with an existing Rev5 Moderate authorization has real operational maturity to draw on, the same way a SOC 2 Type 2 program provides real groundwork without satisfying FedRAMP requirements directly, but the specific evidence, the SSP narrative, the control-by-control documentation, does not convert into 20x rules and KSI evidence without independent work.

Treating the Renaming as Purely Cosmetic

The opposite error is assuming that because Class C maps closely to the retired Moderate label, nothing substantive changed. For a provider staying on the Rev5 path, that assumption is largely safe. For a provider evaluating or moving toward 20x, it is not, because the rules and KSI structure covered above simply did not exist under the legacy terminology. A provider that reads “Class C is just the new name for Moderate” and stops there will miss the entire 20x evidence question.

Skipping the Class-C-Specific Rules

A provider that scopes its 20x Class C effort against a generic 20x checklist, rather than the rules and KSIs filtered specifically to Class C, risks building a package that satisfies the shared baseline while missing the roughly 25 rules that exist because of Class C’s particular risk profile. Those rules are not edge cases. They are the difference between a Class C package and a Class B one wearing a higher label.

Where to Start

A Working Reference Beats a Summary

Because the rules and KSIs are versioned and change by ruleset update, a provider scoping this work benefits more from a filterable, verbatim reference than from a narrative summary that has to be re-verified every time the underlying rules shift. Elevate’s FedRAMP 20x Class C Rules Reference reproduces all 158 applicable rules and 46 Key Security Indicators verbatim from the current CR2026 ruleset, filterable by force and by the rules specific to Class C, with Status and Notes columns that turn the reference into a working self-check against a provider’s actual offering.

Where Elevate Fits

Elevate Consult works with cloud service providers mapping existing Moderate or Class C work to the certification type that actually fits their architecture, whether that means completing a Rev5 Class C authorization or building the rules and KSI evidence a 20x Class C certification requires. Bringing a marked-up copy of the rules reference to a working session turns a general question about Class C into a prioritized view of what engineering and assurance work remains. To scope that work for a specific offering, book a readiness call with an Elevate advisor.

Conclusion

FedRAMP Moderate certification is retired vocabulary, not a retired requirement. The risk tier it described lives on as Class C, and a provider already authorized at Moderate carries that status forward as FedRAMP Certified at Class C without re-authorizing. The part of this change that actually demands new work is narrower and more specific than the renaming itself: a provider building toward Class C through FedRAMP 20x is working against a rules and Key Security Indicator structure that has no Rev5 equivalent, filtered to the roughly one in six rules that exist specifically because of Class C’s risk profile.

Getting the terminology right is the easy part. Knowing which of the two paths to Class C an offering is actually building toward, and what that path specifically requires, is the part worth getting an outside read on before assuming prior Moderate work carries further than it does.

Elevate Consult helps cloud service providers map existing FedRAMP work to the current Class C requirements, on both the Rev5 and 20x paths. To scope a specific offering, schedule a readiness call.

Key Takeaways

  • FedRAMP Moderate certification is now Class C. The retirement traces to Public Notice NTC-0004 and eliminates the terminology collision with DoD Impact Levels; a provider authorized at Moderate today carries that status forward as Class C without re-authorizing.
  • The risk profile did not move. Class C still covers systems handling CUI and non-public federal data where a breach could cause serious but not catastrophic harm, the same profile Moderate described.
  • Class C exists on two structurally separate paths. Rev5 Class C uses the traditional NIST 800-53 control model, roughly 323 to 325 controls; 20x Class C uses a rules and Key Security Indicator model that has no Rev5 equivalent.
  • 20x Class C requires 158 rules and 46 KSIs, not a control count. The rules span 15 rulesets covering marketplace listing through package requirements, with each KSI mapped back to NIST 800-53 controls.
  • 25 rules apply specifically to Class C, beyond the shared 20x baseline every class carries. Scoping against a generic 20x checklist rather than the Class C-specific filter misses this set.
  • Work does not transfer between Rev5 and 20x. A provider with existing Rev5 Moderate authorization has real operational maturity but no direct credit toward 20x Class C evidence, which has to be built independently.

FAQs

What is FedRAMP Class C? Class C is the Certification Class that replaced the FedRAMP Moderate impact level under the Consolidated Rules for 2026. It applies to cloud services handling Controlled Unclassified Information and other non-public federal data where a breach could cause serious but not catastrophic harm, and it remains the most common certification tier in the program.

Is FedRAMP Moderate still a valid certification? FedRAMP Moderate is retired terminology, not a retired requirement. Providers previously authorized at Moderate are now described as FedRAMP Certified at Class C, and the underlying risk tier and control requirements carried forward without a required re-authorization. New certification activity should reference Class C rather than Moderate going forward.

What is the difference between Rev5 Class C and 20x Class C? Rev5 Class C uses the traditional evidence model, a System Security Plan documenting implementation against roughly 323 to 325 NIST SP 800-53 controls, assessed by a FedRAMP Recognized Assessor. 20x Class C uses a structurally different model: 158 applicable rules across 15 rulesets and 46 Key Security Indicators mapped to NIST 800-53 controls, submitted as machine-readable evidence through the Program Certification path. The two are separate certification types, and work completed toward one does not transfer to the other.

How many rules apply to a FedRAMP 20x Class C offering? 158 rules apply under the current CR2026 ruleset, organized across 15 rulesets covering marketplace listing, certification, boundary definition, assurance, and package requirements. A defined subset of 25 rules applies specifically to Class C beyond the baseline shared across all 20x classes, alongside 46 Key Security Indicators mapped to NIST 800-53 controls.

Does prior FedRAMP Moderate work count toward a 20x Class C certification? Not directly. A provider’s existing Rev5 Moderate documentation, control implementation, and assessment history reflect real operational maturity, but the specific evidence required for 20x Class C, the rules and Key Security Indicator structure, has no equivalent under the legacy Rev5 model and has to be built and evidenced independently.