Introduction
Cisco customers now benefit from immediate access to an enhanced Secure Access for Government solution that meets FedRAMP Certified Class D (High) standards.
By pairing with Cisco SD-WAN, Cisco Secure Access for Government is offered as a SASE solution that delivers comprehensive cybersecurity tailored to the complex requirements of federal agencies and contractors. As a converged Security Service Edge (SSE) solution built on Zero Trust architecture, it integrates key capabilities such as Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and cloud-delivered firewalling to ensure strong protection for users, devices, and applications everywhere. Cisco Secure Access for Government is now available at both FedRAMP Certified Class C (Moderate) and FedRAMP Certified Class D (High) levels, enabling agencies to protect higher-impact data while continuing to serve existing workloads at the FedRAMP Certified Class C (Moderate) level. This flexibility supports agencies as they transition and scale security to meet evolving compliance and data protection needs.
Building on Cisco’s commitment to federal security, Cisco Secure Access for Government officially received FedRAMP Certified Class C (Moderate) in August 2025. Following this milestone, Cisco has now achieved FedRAMP Certified Class D (High), further elevating the protection available for sensitive government data. FedRAMP compliance is critical for these organizations to ensure secure cloud adoption and protect sensitive government data.
This blog explains how a customer can use Secure Access for Government with both Certified Class C (Moderate) and Certified Class D (High) impact data as well as Cisco’s transition from FedRAMP Certified Class C (Moderate) to FedRAMP Certified Class D (High). The blog further defines how FedRAMP Certified Class C (Moderate) maps to the Department of Defense (DoD) Cloud Impact Levels, providing clarity on compliance and security posture for government and defense customers. It’s important to note that there is no action or enablement required from going to FedRAMP Certified Class C (Moderate) to FedRAMP Certified Class D (High) as this upgrade is applied automatically.
Understanding FedRAMP and the DoD Impact Levels
The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program that standardizes security assessment, authorization, and continuous monitoring of cloud services used by federal agencies. FedRAMP levels are categorized by the potential impact a data breach would have on an organization’s ability to conduct its mission.
- FedRAMP Certified Class C (Moderate): Applies to systems handling controlled unclassified information (CUI) where the loss of confidentiality, integrity, and availability could have serious adverse effects, such as significant operational damage or financial loss. This level is the standard for most federal civilian agencies. Security Controls involved in FedRAMP’s Certified Class C (Moderate) Baseline can be found in the following FedRAMP Moderate Security Controls spreadsheet.
- FedRAMP Certified Class D (High): Covers systems processing highly sensitive, non-classified data such as Law Enforcement, Emergency Services, Financial, and Health systems and other systems where the loss of confidentiality, integrity, and availability could cause severe or catastrophic damage to government operations or assets. Achieving FedRAMP Certified Class D (High) provides the enhanced protection necessary for the government’s most mission-critical unclassified workloads. Security Controls involved in FedRAMP’s Certified Class D (High) Baseline can be found in the following FedRAMP Certified Class D (High) Security Controls spreadsheet.
Customer Guide to FedRAMP Certified Class D (High) and DoD Impact Levels
FedRAMP Certified Class D (High) allows agencies and contractors to securely process and store highly sensitive federal data—including Personally Identifiable Information (PII), Protected Health Information (PHI), and mission-critical information—using cloud services that meet rigorous security standards. FedRAMP Certified Class D (High) aligns closely with DoD Impact Level 4 (IL4), which is required for sensitive unclassified data such as For Official Use Only (FOUO), PII, PHI, and other operational information.
FedRAMP Certified Class D (High) and DoD Impact Level 4 (IL4) are both rigorous security frameworks, but they differ primarily in their target audience and control baselines. FedRAMP Certified Class D (High) is the highest security standard for civilian government agencies, designed to protect sensitive unclassified data where a breach could result in catastrophic impacts. It utilizes a comprehensive set of over 400 security controls based on the NIST SP 800-53 High baseline. In contrast, DoD IL4 is specifically designed for the Department of Defense to handle Controlled Unclassified Information (CUI). It is often referred to as “FedRAMP Moderate Plus” because it starts with the FedRAMP Certified Class C (Moderate) baseline and adds approximately 44 DoD-specific security enhancements to address military-specific risks.
The most significant operational differences involve connectivity and personnel requirements. While FedRAMP Certified Class D (High) services are typically accessible over the public internet using high-level encryption (FIPS-validated), DoD IL4 requires a more restricted networking model, mandating connectivity through the NIPRNET via a DoD Cloud Access Point (CAP). Furthermore, DoD IL4 has strict personnel mandates, requiring that all staff with administrative access to the environment be “U.S. Persons” (citizens or lawful permanent residents). FedRAMP Certified Class D (High) does not explicitly require U.S. citizenship in its baseline, although many providers utilize U.S. citizens in specialized “GovCloud” regions to meet the high-security expectations of their federal customers.
For less sensitive workloads, FedRAMP Certified Class C (Moderate) and DoD Impact Level 2 (IL2) support controlled unclassified information (CUI) where a compromise would have a more limited impact. IL2 and FedRAMP Certified Class C (Moderate) are suitable for civilian agencies handling non-classified but sensitive data.
DoD Impact Level 5 (IL5) is designed for mission-critical and national security systems, demanding even stricter security controls—building on FedRAMP Certified Class D (High) with additional DoD requirements for defense-specific operations. Cisco Secure Access for Defense is being developed for IL5, offering capabilities like PIV-CAC card support and FIPS-compliant clients.
Cisco Secure Access for Government FedRAMP Certified Class D (High) provides a unified security platform capable of protecting the most sensitive unclassified data across all federal impact levels, including FedRAMP Certified Class D (High) and DoD Impact Level 4 requirements. By uplifting the entire environment to the Certified Class D baseline, Cisco ensures that agencies can seamlessly secure Controlled Unclassified Information (CUI) and mission-critical data using a Zero Trust architecture that includes ZTNA, DNS security, Secure Web Gateway, and advanced malware protection powered by Cisco Talos. This transition is designed as a backend platform uplift rather than a manual migration, allowing existing FedRAMP Certified Class C (Moderate) users to benefit from enhanced security controls automatically without any operational disruption, product replacement, or reconfiguration.
As a core component of Cisco SASE for Government when paired with Catalyst SD-WAN (which at this time is FedRAMP Certified Class C (Moderate) and under review for FedRAMP Certified Class D (High)), this solution is part of the broader Cisco Secure Cloud for Government ecosystem. This unified ecosystem includes Cisco Umbrella for Government, Cisco Secure Access, Cisco Cloudlock, Defense Orchestrator (CDO), Cisco Multicloud Defense (MCD), and Cisco Privileged Identity and Access Management (PIAM). Together, these tools enable federal agencies to meet stringent security mandates like TIC 3.0 and Executive Order 14028 while maintaining a simplified, high-performance security posture across remote and hybrid work environments.
Key Points:
- Comprehensive Authorization: Cisco Secure Access for Government holds a FedRAMP Certified Class D (High), meaning it can be used for a wide range of impact levels, including both FedRAMP Certified Class D (Moderate) and FedRAMP Certified Class D (High) Impact environments.
- Seamless Transition: Existing customers do not have to take additional steps to benefit from this uplift; there is no migration or upgrade required, as the transition is fully automatic.
- Integrated Ecosystem: This solution is a key pillar of Cisco SASE for Government when paired with Catalyst SD-WAN and is part of the Cisco Secure Cloud for Government suite, which includes:
- Cisco Umbrella for Government
- Cisco Secure Access
- Cisco Cloudlock
- Defense Orchestrator (CDO)
- Cisco Multicloud Defense (MCD)
- Cisco Privileged Identity and Access Management (PIAM)
Why This Matters for Government and Defense Customers
Compliance with evolving federal and DoD security mandates is critical to protect sensitive information and maintain operational resilience. While Cisco Secure Access for Government’s FedRAMP Certified Class C (Moderate) supports many federal civilian agencies, the new FedRAMP Certified Class D (High) uplift enables agencies and contractors handling more sensitive data to meet stricter compliance requirements.
This ensures secure, resilient, and compliant cloud access for distributed and hybrid workforces. Cisco’s commitment to continuous improvement and alignment with federal security frameworks helps government and defense customers confidently adopt cloud technologies while safeguarding their missions.
Conclusion
Cisco’s journey from FedRAMP Certified Class C (Moderate) to FedRAMP Certified Class D (High) reflects our dedication to meeting the highest federal security standards. The FedRAMP Certified Class D (High) uplift enhances security for confidential government data without requiring customers to change products or SKUs and is available NOW with purchase of Secure Access for Government. Additionally, the mapping of FedRAMP Certified Class C (Moderate) to DoD Cloud Impact Levels clarifies compliance pathways for federal civilian and defense agencies. Agencies and contractors are encouraged to take advantage of this transition and engage with Cisco for expert guidance and support on secure access solutions tailored to government and defense requirements.
Reference Document Links