Box is FedRAMP Class D (High) Certified
Box meets key requirements for handling highly sensitive U.S. government data

Box and FedRAMP
Box is FedRAMP Class D (High) Certified – meeting some of the highest standards for protecting sensitive U.S. government data. Our certification builds on years of investment in federal security, including an independent assessment of over 421 security controls. Like Box’s sponsoring agency, the U.S. Department of Veterans Affairs, over 300 federal government and more than 10,000 state and local government agencies trust Box to manage highly sensitive information, from personal identifiable information and patient records to financial data and Controlled Unclassified Information (CUI).
With the average cost of a data breach now at $4.88M, Intelligent Content Management helps organizations consolidate systems, enable digital-first services, and strengthen cyber defense – all while driving AI-powered efficiency through secure access controls, continuous monitoring.
Get to know FedRAMP
FedRAMP (Federal Risk and Authorization Management Program) standardizes security assessments and continuous monitoring for cloud services used by the U.S. federal government.
Under FISMA, federal agencies must use cloud services with FedRAMP Certification at a Certification Class matching their data sensitivity. Agencies categorize information under FIPS 199 and select appropriately certified services. FedRAMP was codified by the FedRAMP Authorization Act of 2022, with policy set by OMB Memorandum M-24-15.
As of July 4, 2026, FedRAMP operates under the Consolidated Rules for 2026 (CR26) through December 31, 2028. Under CR26, cloud services are certified at one of four Certification Classes (A through D), replacing the former Low, Moderate, and High impact levels.
The importance of FedRAMP
For cloud providers serving the federal government, FedRAMP Certification isn't optional. Federal agencies are required to use FedRAMP Certified cloud services for federal information in the cloud, with limited exceptions defined in law and OMB policy. FedRAMP Certification enables government agencies to reduce duplicative security assessments, and provides consistent, independently assessed security.
For cloud providers like Box, it provides a single, transparent standard. And for the public, it means sensitive government data, from controlled unclassified information to law enforcement and health data, is protected by continuously monitored, independently verified controls based on NIST Special Publication 800-53, Revision 5.
FedRAMP Certification Classes
Under CR26, FedRAMP certifies cloud services at four Certification Classes. Each class reflects the sensitivity of the federal information the service is certified to handle and determines the depth of assessment and continuous monitoring required. The classes are grounded in the same FIPS 199 analysis of impact to confidentiality, integrity, and availability that underpinned the former impact levels.
For more information on the FedRAMP certification classes, see the FedRAMP website.
FedRAMP Class A (Ready)
Class A Certifications include adequate information for most non-sensitive use cases and some Low, Moderate, or High security objectives.
FedRAMP Class B (Low)
Class B Certifications include adequate information for most Low security objectives and some Moderate or High security objectives.
FedRAMP Class C (Moderate)
Class C Certifications include adequate information for most Low and Moderate security objectives, as well as some High security objectives.
FedRAMP Class D (High)
Class D Certifications include adequate information for most use cases regardless of security objective (this does not include systems that process classified information).
How agencies select a Certification Class
In practice, agencies determine their security objectives (using FIPS 199 categorization of their information) and select cloud services certified at a class that provides adequate assurance for those objectives. During the CR26 transition, the classes map to the legacy baselines as follows: Class B encompasses the former LI-SaaS and Low baselines, Class C the former Moderate baseline, and Class D the former High baseline.
Box is FedRAMP Certified at Class D (High). This class is defined by FedRAMP as adequate for most use cases regardless of security objective, excluding classified systems.
Using Box for FedRAMP Class D (High) compliance
A longstanding commitment to security and compliance
Customer data is securely processed and stored within the United States with continuous monitoring. Plus, access to annual audit reports and ongoing FedRAMP Class D continuous monitoring documentation contributes to transparency and trust.
Seamlessly integrate with FedRAMP Class D (High)-compliant platforms
Box lets you leverage the tools you rely on while staying within the boundaries of secure, compliant environments, assisting you with meeting regulatory requirements.
Tap into technical expertise and guidance
Benefit from continental U.S.-based support escalations for Box Help Desk services, Box AI support, and the option to leverage Box Consulting Guidance to help with FedRAMP Class D (High) configuration.
FAQs
Learn more about Box’s approach to security and compliance

Discover how we approach Security and Compliance
We're dedicated to earning and keeping our customers' trust — every day.
