What's new
Sign in / Sign up
Search3
Glossary Term: fips-199
Learn BureauifySign In

Top Agencies

  • DOD
  • HHS
  • VA
  • DHS
  • DOE
  • DOI
  • NASA
  • GSA
  • DOJ
  • Treasury
  • USDA
  • DOT
  • Commerce
  • State
  • EPA
  • All Agencies

States

  • California
  • Virginia
  • Texas
  • Maryland
  • Florida
  • Georgia
  • Colorado
  • Ohio
  • New York
  • Pennsylvania
  • Illinois
  • North Carolina
  • Washington
  • Arizona
  • DC
  • All States
  • Cities & Metros
  • US Embassies

Industries

  • IT Services & Software
  • Cybersecurity
  • Construction
  • Healthcare & Medical
  • Management Consulting
  • Engineering Services
  • Cloud Computing
  • Security Guards
  • Research & Development
  • Data Analytics & AI
  • Manufacturing
  • Logistics
  • All Industries

Set-Asides

  • Small Business
  • 8(a)
  • SDVOSB
  • WOSB
  • HUBZone
  • EDWOSB
  • VOSB
  • SDB
  • All Set-Asides

Record Types

  • Contracts
  • Grants
  • Bills
  • Research
  • Federal Jobs
  • Audits
  • Protests
  • Regulations
  • Press
  • Patents
  • Exclusions
  • Closing Soon
  • New This Week
  • Trends

Resources

  • GovCon Guide
  • FAR Parts
  • DFARS
  • NAICS Codes
  • PSC Codes
  • Glossary
  • Sources Graph
  • People Graph
  • Certifications
  • Contract Types
  • FAQ
  • Comparisons
  • Military Bases
  • Federal Courts
  • National Labs

Company

  • Search
  • About
  • Blog
  • Partners
  • Press
  • Data Sources
  • SAM.gov Alternative
  • Privacy
  • Terms
© 2026 Bureauify100M+ federal records · 110+ data sources
PrivacyTermsAboutLearn BureauifyChangelogMethodologySourcesPeopleHelp

Federal glossary · Regulation

FIPS 199

FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems) defines three impact levels — Low, Moderate, High — based on the potential impact of a security breach on confidentiality, integrity, and availability. The categorization determines which NIST 800-53 controls must be applied.

Example: FAR Part 15, DFARS, or a statute such as the NDAA.

Type
Regulation
Defined by
Federal acquisition and regulatory source
Last reviewed
Jul 2, 2026

Reference record · Sources: Federal acquisition and regulatory source · Verified Jul 2, 2026 · Covers definition, governing source

Home/Glossary/FIPS 199
Regulation

FIPS 199

Also known as

FIPS199

Definition

FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems) defines three impact levels — Low, Moderate, High — based on the potential impact of a security breach on confidentiality, integrity, and availability. The categorization determines which NIST 800-53 controls must be applied.

Why does FIPS 199 matter?

is a regulation concept federal contractors and grant writers run into across solicitations, regulations, and award filings

Where this matters in federal contracting

FIPS 199 is part of the federal regulatory framework that governs procurement, performance, or compliance. For example: Example: FAR Part 15, DFARS, or a statute such as the NDAA. For contractors, FIPS 199 is not just background — it shapes solicitation language, evaluation criteria, source-selection authority, and what counts as compliant performance. Understanding when FIPS 199 applies and (more importantly) when it doesn't apply is the difference between a proposal that's competitive within its actual constraint set and one that over-engineers compliance. Contracting officers use FIPS 199 as common vocabulary, so reading their decisions, modifications, and source-selection memoranda gets easier when the regulation is in your working memory. Pair FIPS 199 with the related terms above to see how it interacts with adjacent regulatory mechanisms.

Example

Example: FAR Part 15, DFARS, or a statute such as the NDAA.

Meaning in practice

FIPS 199 is part of the federal rule set that governs procurement, compliance, or program administration.

Where you’ll see it

You will see it in the FAR, DFARS, the Federal Register, clauses, and compliance checklists. Example: Example: FAR Part 15, DFARS, or a statute such as the NDAA..

Common confusion

People often confuse a regulation with agency guidance or with a checklist that merely references the rule.

What to do next

Find the exact citation and confirm whether the page links to a part, clause, or agency interpretation.

Frequently Asked Questions

What is FIPS 199 in government contracting?▾
FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems) defines three impact levels — Low, Moderate, High — based on the potential impact of a security breach on confidentiality, integrity, and availability. The categorization determines which NIST 800-53 controls must be applied.
Can you give an example of FIPS 199?▾
Yes. Example: FAR Part 15, DFARS, or a statute such as the NDAA.
Why is FIPS 199 important for government contractors?▾
FIPS 199 is a regulation governing federal procurement. Compliance with acquisition regulations is mandatory for all government contractors and is evaluated during source selection.
Where will I see FIPS 199?▾
You will see it in the FAR, DFARS, the Federal Register, clauses, and compliance checklists. Example: Example: FAR Part 15, DFARS, or a statute such as the NDAA..
What is FIPS 199 commonly confused with?▾
People often confuse a regulation with agency guidance or with a checklist that merely references the rule.
What should I do next when I see FIPS 199?▾
Find the exact citation and confirm whether the page links to a part, clause, or agency interpretation.

Related terms

NIST — National Institute of Standards and Technology
bg-red-500/20 text-red-300 border-red-500/30
FAR — Federal Acquisition Regulation
bg-red-500/20 text-red-300 border-red-500/30
DFARS — Defense Federal Acquisition Regulation Supplement
bg-red-500/20 text-red-300 border-red-500/30
FedRAMP — Federal Risk and Authorization Management Program
bg-red-500/20 text-red-300 border-red-500/30
ITAR — International Traffic in Arms Regulations
bg-red-500/20 text-red-300 border-red-500/30
EAR — Export Administration Regulations
bg-red-500/20 text-red-300 border-red-500/30
FISMA — Federal Information Security Modernization Act
bg-red-500/20 text-red-300 border-red-500/30

Related entities

Government contracting guide
Guide

Related questions

No related questions are available yet.

Related records

Search live records for FIPS 199
Open live contracts results for FIPS 199.
Search
Search live records for FIPS199
Open live contracts results for FIPS199.
Search

Related journeys

Search live records for FIPS 199
Open live contracts results for FIPS 199.
Search
Read the contracting guide
Guide

Source trail

FIPS 199 page
Canonical glossary term page last reviewed 2026-07-02.
Glossary
Federal acquisition and regulatory source
Official source trail.
Source

More regulation terms

FARDFARSFedRAMPITAREARFISMACertified Cost or Pricing DataTruth in NegotiationsTINADavis-BaconBuy AmericanFAR Part 8
Source: Federal acquisition and regulatory source·Last updated 2026-07-02 by Bureauify·Category: Regulation

What to ask next

  • What is NIST — National Institute of Standards and Technology?
  • What is FAR — Federal Acquisition Regulation?
  • What is DFARS — Defense Federal Acquisition Regulation Supplement?
  • What is FedRAMP — Federal Risk and Authorization Management Program?
  • What is ITAR — International Traffic in Arms Regulations?
  • What is EAR — Export Administration Regulations?

What can I do?

FollowSave

Route: Orientation path

  1. 1.Discover — you are here
  2. 2.Decide — follow to monitor
  3. 3.Act — follow to monitor

Follow FIPS 199

Get notified when usage of FIPS 199 changes in contracts or guidance.

Follow FIPS 199 →Search FIPS 199 in records

Find FIPS 199-related opportunities

Search active federal contracts and solicitations related to FIPS 199 on Bureauify.

100M+ government records · 110+ gov/news sources · Sourced from official federal systems

Explore Federal Contracting

All ContractsGrantsFederal Agencies90+States & Territories56Set-Aside Programs15+NAICS Industries1,051Industry Sectors20Top Contractors100Closing SoonNew This WeekTrends
← Back to Glossary

Top Agencies

  • DOD
  • HHS
  • VA
  • DHS
  • DOE
  • DOI
  • NASA
  • GSA
  • DOJ
  • Treasury
  • USDA
  • DOT
  • Commerce
  • State
  • EPA
  • All Agencies

States

  • California
  • Virginia
  • Texas
  • Maryland
  • Florida
  • Georgia
  • Colorado
  • Ohio
  • New York
  • Pennsylvania
  • Illinois
  • North Carolina
  • Washington
  • Arizona
  • DC
  • All States
  • Cities & Metros
  • US Embassies

Industries

  • IT Services & Software
  • Cybersecurity
  • Construction
  • Healthcare & Medical
  • Management Consulting
  • Engineering Services
  • Cloud Computing
  • Security Guards
  • Research & Development
  • Data Analytics & AI
  • Manufacturing
  • Logistics
  • All Industries

Set-Asides

  • Small Business
  • 8(a)
  • SDVOSB
  • WOSB
  • HUBZone
  • EDWOSB
  • VOSB
  • SDB
  • All Set-Asides

Record Types

  • Contracts
  • Grants
  • Bills
  • Research
  • Federal Jobs
  • Audits
  • Protests
  • Regulations
  • Press
  • Patents
  • Exclusions
  • Closing Soon
  • New This Week
  • Trends

Resources

  • GovCon Guide
  • FAR Parts
  • DFARS
  • NAICS Codes
  • PSC Codes
  • Glossary
  • Sources Graph
  • People Graph
  • Certifications
  • Contract Types
  • FAQ
  • Comparisons
  • Military Bases
  • Federal Courts
  • National Labs

Company

  • Search
  • About
  • Blog
  • Partners
  • Press
  • Data Sources
  • SAM.gov Alternative
  • Privacy
  • Terms
© 2026 Bureauify100M+ federal records · 110+ data sources
PrivacyTermsAboutLearn BureauifyChangelogMethodologySourcesPeopleHelp