# FedRAMP Baselines | Secureframe

> Understand FedRAMP security baselines (Low, Moderate, High), control counts per baseline, how baselines map to NIST SP 800-53, and how to select the right baseline.

canonical: https://secureframe.com/glossary/fedramp-baselines

FedRAMP baselines are predefined security control requirements that cloud service providers must meet to achieve FedRAMP authorization.

## What are FedRAMP baselines?

FedRAMP baselines are predefined security control requirements that cloud service providers must meet to achieve [FedRAMP authorization](https://secureframe.com/blog/fedramp-ato). These baselines are categorized into three impact levels—Low, Moderate, and High—based on the sensitivity of the data processed. The controls are derived from the [National Institute of Standards and Technology (NIST) Special Publication 800-53](https://secureframe.com/blog/nist-800-53-compliance) and adapted to meet federal security needs.
