There are Three Levels of FISMA
The unauthorized disclosure of information could be expected to have a limited adverse effect on the organizational operations, organizational assets, or individuals.
FISMA LOW
FIPS 140-3 VALIDATED products required. The unauthorized disclosure of information could be expected to have a SERIOUS adverse effect on the organizational operations, organizational assets, or individuals.
FISMA MODERATE
FIPS 140-3 VALIDATED products required. The unauthorized disclosure of information could be expected to have a SEVERE or CATASTROPHIC adverse effect on the organizational operations, organizational assets, or individuals.
FISMA HIGH
FISMA points to several NIST documents, ALL of which call for FIPS 140-3 for FISMA MODERATE and FISMA HIGH networks.
The MODERATE LEVEL is often though to be in a grey area. This is false. FISMA MODERATE specifically calls out for FIPS 140-3 VALIDATED products on the network.