What Is FIPS 199? Security Categorization Explained

Written by: 
Team Knox
Published on: 
August 27, 2026

Every federal information system must carry a documented security category before anyone selects a security control. Federal Information Processing Standard (FIPS) 199 is the National Institute of Standards and Technology (NIST) standard that defines how that security category gets assigned.

For SaaS vendors, the category carries direct commercial weight. The Federal Risk and Authorization Management Program (FedRAMP) authorization tier classification a product must achieve, along with the cost and length of authorization, follows from that categorization.

Key Takeaways

  • Mandatory federal categorization. The Federal Information Security Management Act (FISMA) requires every federal agency to categorize its information and information systems, and the standard extends to contractor-operated federal systems processing federal data.  
  • Three independent ratings. Confidentiality, integrity, and availability each receive a Low, Moderate, or High rating based on the potential adverse effect of a breach.  
  • High watermark. The highest rating across the three objectives becomes the system's overall impact level; a single High objective makes the whole system High-impact.  
  • Categorization drives everything downstream. The FIPS 199 output determines the FIPS 200 minimum requirements, the NIST SP 800-53 control baseline, and the FedRAMP tier a vendor must pursue.

FIPS 199 Is NIST's Mandatory Federal Standard for Security Categorization

NIST published FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems, in February 2004. It was the first standard FISMA (Title III of the E-Government Act of 2002) mandated. FISMA directed NIST to develop standards for all federal agencies to use to categorize federal information systems by risk level. FIPS 199 applies to all federal government information except classified information. It also applies to all federal information systems other than national security systems, including systems contractors operate on an agency's behalf.

The assessment produces a documented security category. The standard defines that category as "the characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, or individuals." Every control decision an agency makes afterward is selected against that category.

Three Security Objectives Form the Foundation of Every FIPS 199 Assessment

FIPS 199 assesses every system against three security objectives. It uses the definitions in federal statute (44 U.S.C., Sec. 3542). Each objective is evaluated independently.

  1. Confidentiality means "preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information." A loss of confidentiality is the unauthorized disclosure of information.  
  2. Integrity means "guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity." A loss of integrity is the unauthorized modification or destruction of information.  
  3. Availability means "ensuring timely and reliable access to and use of information." A loss of availability is the disruption of access to or use of information or an information system.

Because each objective is assessed separately, the three ratings need not match. NIST's own example is a public web server: confidentiality protection is not applicable to information already intended for disclosure, while integrity and availability both rate Moderate. Each objective then receives its own impact rating.

Each Objective Receives One of Three Potential Impact Ratings

For each objective, FIPS 199 permits exactly three impact ratings. Each rating reflects the potential adverse effect of a loss.

Impact RatingNIST-Defined Adverse EffectPlain-Language Example
Low"Limited adverse effect": minor damage to organizational assets and minor financial loss, with a noticeable but survivable drop in mission effectivenessA low-impact SaaS application that stores no personally identifiable information (PII) beyond what is generally required for login capability
Moderate"Serious adverse effect": significant damage and significant financial loss, as well as significant harm to individuals that does not involve loss of lifeInternal systems holding employee human resources (HR) data or student financial records
High"Severe or catastrophic adverse effect": loss of one or more primary mission functions or major damage; it can also mean harm involving loss of life or serious life-threatening injuriesLaw enforcement records or emergency services systems

Each rating measures the potential effect on organizational operations, organizational assets, or individuals. NIST notes that harm to individuals includes loss of the privacy to which individuals are entitled under law. NIST's worked example for law enforcement investigative information rates confidentiality High while holding integrity and availability at Moderate.

FIPS 199 also cautions that "the application of these definitions must take place within the context of each organization and the overall national interest," so the same information type can rate differently at different agencies. Those organization-specific ratings become inputs to the system-level aggregation rule.

The Highest Single Impact Rating Across All Three Objectives Sets the Final Category

One High rating makes the entire system High-impact. FIPS 199 states: "The potential impact values assigned to the respective security objectives (confidentiality, integrity, availability) shall be the highest values (i.e., high water mark) from among those security categories that have been determined for each type of information resident on the information system."

To categorize a system, follow this sequence:

  1. Identify the information types the system processes, stores, or transmits, and assess confidentiality, integrity, and availability for each type independently.  
  2. Assign each objective a rating of Low, Moderate, or High. Individual information types may rate an objective as Not Applicable, typically confidentiality for public data, but Not Applicable cannot be assigned at the system level.  
  3. For each objective, take the highest rating assigned to any information type on the system; those three values together form the system security category. The overall impact level used later for baseline selection is the highest of the three, so a system with even one High objective is a High-impact federal system, and one with at least one Moderate and no High is Moderate-impact.  
  4. Document the result in NIST's notation: SC information system = {(confidentiality, impact), (integrity, impact), (availability, impact)}.

A hypothetical payroll system illustrates the rule. Rated High for confidentiality, Moderate for integrity, and Low for availability, it is documented as SC payroll system = {(confidentiality, HIGH), (integrity, MODERATE), (availability, LOW)}. That single High rating makes it a High-impact system subject to the High control baseline.

FIPS 199 also permits management to raise a value above the mechanical high watermark. The standard's own supervisory control and data acquisition (SCADA) worked example raises confidentiality from Low to Moderate with documented rationale.

Once documented, that category determines the minimum requirements and control baseline applied downstream.

FIPS 199 Defines Categories; FIPS 200 and NIST SP 800-53 Set Controls

FIPS 199 sets impact; it doesn't prescribe controls. FIPS 200 requirements, Minimum Security Requirements for Federal Information and Information Systems, were published in March 2006. FIPS 200 uses the FIPS 199 output: agencies take the security category, derive the system's overall impact level using the high watermark, and determine the minimum security requirements for that level.

NIST Special Publication 800-53 Rev5 is the control catalog FIPS 200 points to. Its Low, Moderate, High baselines match the impact level.

The full FISMA chain follows four stages:

  1. Categorize the system under FIPS 199.  
  2. Determine required controls under FIPS 200.  
  3. Implement controls from NIST SP 800-53 Rev5.  
  4. Assess and authorize the system under the NIST Risk Management Framework. This process ends in an Authority to Operate (ATO) decision.

Authorization is then followed by a plan of action and milestones (POA\&M), management and continuous monitoring requirements.

Under FedRAMP's legacy Rev5 baselines, Moderate includes 323 controls, and High includes 410 controls, so the categorization decision sets the workload. SaaS vendors selling into federal agencies are categorized under this same federal impact framework.

FIPS 199 Categories Map Directly to FedRAMP Authorization Tiers

For SaaS vendors, the FIPS 199 category of federal data sets the FedRAMP tier they must achieve. Under Consolidated Rules 2026 (CR26) v2026.06.24.01, released June 24, 2026, with mandatory adoption on January 1, 2027, FedRAMP replaced Low, Moderate, and High with Certification Classes A through D. Legacy Rev5 baselines remain operative for existing certifications through December 31, 2028, and only an agency authorizing official can identify a use case's security category.

The category a vendor lands in dictates the raw control count they must implement, assess, and continuously monitor. Moderate carries 323 controls; High carries 410. Every control on that list is either built by the vendor, inherited from an underlying provider, or shared between the two. The mix of those three buckets, not the category itself, determines how much work the vendor actually owns.

This is where an inherited authorization boundary comes on. When a SaaS product is built on an already-authorized platform, the platform's controls pass through to the vendor as inheritable, and the vendor's remaining scope collapses to the controls genuinely unique to their application. The FIPS 199 category still sets the ceiling for what must be satisfied, but inheritance determines how much of that ceiling the vendor must meet on their own. For a High-impact system, the difference between building 410 controls from scratch and inheriting the majority of them is the difference between a multi-year program and a focused, application-layer effort.

An Inherited Boundary Turns the FIPS 199 Category Into a Manageable Path

The FIPS 199 category sets the ceiling for what must be satisfied, but an inherited authorization boundary determines how much of that ceiling a vendor must meet on its own. A category set too low understates mission risk; a category set higher than necessary expands the control baseline, assessment burden, and time to market. Inheritance is what keeps the higher category from translating into a proportionally larger program.

Knox Systems operates as a FedRAMP-as-a-Service platform with a pre-authorized boundary that lets SaaS vendors inherit 60% to 80% of required controls. That inheritance directly reduces the workload created by the selected FIPS 199 impact category and supports FedRAMP authorization in about 90 days at roughly 90% less cost than traditional methods.

Knox currently supports FedRAMP Moderate, FedRAMP High, and DISA IL-4, with IL-5 authorization in process and an estimated completion date of December 2026.

If federal deals are waiting on authorization, book a meeting to map your category to the fastest path.

FAQs about FIPS 199

Can a System Security Category Contain Mixed Impact Ratings?

Yes. Confidentiality, integrity, and availability are rated independently, so a system can carry different impact values for each objective. The highest of those values establishes the overall impact level used for downstream baseline selection.

What Happens When Information Types Have Different Impact Values?

For each security objective, the system takes the highest rating assigned to any information type it processes, stores, or transmits. Those three aggregated values become the documented system security category.

Does the High Water Mark Prevent Management Adjustments?

No. FIPS 199 permits management to raise a value above the mechanical high water mark when the adjustment has documented rationale. The standard's SCADA example raises confidentiality from Low to Moderate on that basis.

Which Standards Apply After FIPS 199 Categorization?

FIPS 200 uses the category to establish minimum security requirements, and NIST SP 800-53 supplies the corresponding control baseline. The system is then assessed and authorized under the NIST Risk Management Framework.

How Do Cryptographic Standards Relate to FIPS 199?

FIPS 199 categorizes entire information systems by impact level, while FIPS 140-3 governs product-level security requirements for cryptographic modules. As a legacy exception, FIPS 140-2 certificates remain active until September 21, 2026; the standards operate at different layers and are not substitutes.