Box is FedRAMP Class D (High) Certified

Box meets key requirements for handling highly sensitive U.S. government data

FedRAMP authorization details

Box and FedRAMP

Box is FedRAMP Class D (High) Certified – meeting some of the highest standards for protecting sensitive U.S. government data. Our certification builds on years of investment in federal security, including an independent assessment of over 421 security controls. Like Box’s sponsoring agency, the U.S. Department of Veterans Affairs, over 300 federal government and more than 10,000 state and local government agencies trust Box to manage highly sensitive information, from personal identifiable information and patient records to financial data and Controlled Unclassified Information (CUI). 

With the average cost of a data breach now at $4.88M, Intelligent Content Management helps organizations consolidate systems, enable digital-first services, and strengthen cyber defense – all while driving AI-powered efficiency through secure access controls, continuous monitoring.

Get to know FedRAMP

FedRAMP (Federal Risk and Authorization Management Program) standardizes security assessments and continuous monitoring for cloud services used by the U.S. federal government.

Under FISMA, federal agencies must use cloud services with FedRAMP Certification at a Certification Class matching their data sensitivity. Agencies categorize information under FIPS 199 and select appropriately certified services. FedRAMP was codified by the FedRAMP Authorization Act of 2022, with policy set by OMB Memorandum M-24-15.

As of July 4, 2026, FedRAMP operates under the Consolidated Rules for 2026 (CR26) through December 31, 2028. Under CR26, cloud services are certified at one of four Certification Classes (A through D), replacing the former Low, Moderate, and High impact levels.

The importance of FedRAMP

For cloud providers serving the federal government, FedRAMP Certification isn't optional. Federal agencies are required to use FedRAMP Certified cloud services for federal information in the cloud, with limited exceptions defined in law and OMB policy. FedRAMP Certification enables government agencies to reduce duplicative security assessments, and provides consistent, independently assessed security.

For cloud providers like Box, it provides a single, transparent standard. And for the public, it means sensitive government data, from controlled unclassified information to law enforcement and health data, is protected by continuously monitored, independently verified controls based on NIST Special Publication 800-53, Revision 5.

FedRAMP Certification Classes

 

Under CR26, FedRAMP certifies cloud services at four Certification Classes. Each class reflects the sensitivity of the federal information the service is certified to handle and determines the depth of assessment and continuous monitoring required. The classes are grounded in the same FIPS 199 analysis of impact to confidentiality, integrity, and availability that underpinned the former impact levels.

For more information on the FedRAMP certification classes, see the FedRAMP website.

class a
FedRAMP Class A (Ready)

Class A Certifications include adequate information for most non-sensitive use cases and some Low, Moderate, or High security objectives.

FedRAMP Low
FedRAMP Class B (Low)

Class B Certifications include adequate information for most Low security objectives and some Moderate or High security objectives.

FedRAMP Moderate
FedRAMP Class C (Moderate)

Class C Certifications include adequate information for most Low and Moderate security objectives, as well as some High security objectives.

FedRAMP High
FedRAMP Class D (High)

Class D Certifications include adequate information for most use cases regardless of security objective (this does not include systems that process classified information).

How agencies select a Certification Class

In practice, agencies determine their security objectives (using FIPS 199 categorization of their information) and select cloud services certified at a class that provides adequate assurance for those objectives. During the CR26 transition, the classes map to the legacy baselines as follows: Class B encompasses the former LI-SaaS and Low baselines, Class C the former Moderate baseline, and Class D the former High baseline.

Box is FedRAMP Certified at Class D (High). This class is defined by FedRAMP as adequate for most use cases regardless of security objective, excluding classified systems.

Using Box for FedRAMP Class D (High) compliance

A longstanding commitment to security and compliance
A longstanding commitment to security and compliance

Customer data is securely processed and stored within the United States with continuous monitoring. Plus, access to annual audit reports and ongoing FedRAMP Class D continuous monitoring documentation contributes to transparency and trust.

Seamlessly integrate with other FedRAMP High-compliant platforms
Seamlessly integrate with FedRAMP Class D (High)-compliant platforms

Box lets you leverage the tools you rely on while staying within the boundaries of secure, compliant environments, assisting you with meeting regulatory requirements.

Tap into technical expertise and guidance
Tap into technical expertise and guidance

Benefit from continental U.S.-based support escalations for Box Help Desk services, Box AI support, and the option to leverage Box Consulting Guidance to help with FedRAMP Class D (High) configuration.

FAQs

Learn more about Box’s approach to security and compliance

industry compliance
Discover how we approach Security and Compliance

We're dedicated to earning and keeping our customers' trust — every day.

Fedramp High
Box achieves FedRAMP High authorization to deliver new innovation

Learn how U.S. government agencies and authorized government contractors leverage our Intelligent Content Management platform for highly sensitive data.