Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

TX-RAMP certification levels explained

TX-RAMP: A Clear Guide to the 2 Texas Certification Levels

TX-RAMP is Texas’s own cloud authorization programme, and it is the reason a vendor can hold a FedRAMP authorization and still be unable to sell to a Texas state agency. It was created under Senate Bill 475, is run by the Texas Department of Information Resources, and applies to state agencies, institutions of higher education and public community colleges when they contract for cloud services.

This guide covers who has to comply, the difference between Level 1 and Level 2, how provisional status buys time, and the reciprocity that lets other authorizations count.

TX-RAMP certification levels, provisional status and the equivalent authorizations accepted
Two levels, one provisional route, and the authorizations Texas accepts in place of each.

Who TX-RAMP applies to

The obligation sits on the buyer, not the seller. Texas state agencies, institutions of higher education and public community colleges must ensure that the cloud services they contract for hold the appropriate certification. The practical effect is the same for a vendor — no certification, no contract — but it explains why the pressure to certify arrives from the customer rather than from DIR.

Scope is limited to cloud computing services as defined in the Texas Government Code. Some offerings that feel like cloud services fall outside that definition, and DIR’s programme manual is where the exclusions are listed. Check it before assuming you are in or out, because both errors are expensive: an unnecessary certification costs months, and an assumed exemption stops a contract at signature.

TX-RAMP Level 1 and Level 2

  Level 1 Level 2
Data and system impact Public or non-confidential information, low-impact systems Confidential or regulated data, moderate or high-impact systems
How to achieve it Submit assessment responses meeting the Level 1 minimum requirements Meet the Level 2 assessment criteria
Accepted equivalents StateRAMP Category 1 or FedRAMP Low authorization StateRAMP Category 2 or FedRAMP Moderate authorization

The equivalence column is the most valuable line in the programme. If you already hold a FedRAMP or StateRAMP authorization at the matching level, TX-RAMP is largely an evidence submission rather than a fresh assessment — which is the case for most vendors who arrive at Texas after federal work. Note that StateRAMP now operates as GovRAMP; the categories referenced by the Texas programme are the same ones under the new name, and our guide to the GovRAMP verification pathway covers how those are earned.

Provisional status, and the eighteen-month clock

Provisional certification exists so that a procurement is not blocked while a vendor works through a full assessment. It permits a state agency to contract for a product for up to eighteen months, and it is obtained by completing the TX-RAMP acknowledgment and inventory questionnaire.

The clock is the point. A cloud service granted provisional status must achieve Level 1 or Level 2 — or present an equivalent FedRAMP or StateRAMP authorization — within that eighteen-month window. Vendors who treat provisional status as the destination discover the deadline when the agency’s contract renewal comes round, which is far too late to start an assessment.

What a TX-RAMP submission actually asks for

The programme is built on the same machinery as its federal cousin, so the documentation you need is familiar:

  • A defined service boundary — what is in the assessed offering, what is not, and which components are inherited from an underlying provider.
  • Control responses at the right level, with the implementation described rather than asserted.
  • Evidence of continuous monitoring, because certification is a state you maintain, not a document you file.
  • An incident notification path to the contracting agency, matching what the contract requires.
  • Sub-processor and hosting disclosure, since inherited controls only count if the inheritance is stated.

Certifications run for a defined term with continuous monitoring throughout — DIR’s programme manual is the controlling document for the current period and for what a lapse means, and it is the source worth reading in full rather than a summary.

How TX-RAMP fits with the other programmes

Three programmes overlap in this space and vendors routinely conflate them:

  • FedRAMP authorizes cloud services for US federal agencies. It is the heaviest and the most widely recognized, and it feeds the other two. Our guide to the FedRAMP ATO covers how the agency decision now works.
  • GovRAMP, formerly StateRAMP, serves state and local government with a verification pathway and its own categories.
  • TX-RAMP is Texas-specific, run by DIR, and accepts the other two as equivalents at matching levels.

The sequencing question is commercial rather than technical. If Texas is your first public-sector market, TX-RAMP directly is the shortest route. If you expect federal work within two years, doing FedRAMP first and claiming equivalence usually costs less in total than doing both separately.

Frequently asked questions

Who has to comply with TX-RAMP?
Texas state agencies, institutions of higher education and public community colleges must contract only for appropriately certified cloud services. The requirement reaches vendors through those contracts.

Does FedRAMP satisfy TX-RAMP?
At matching levels, yes — FedRAMP Low maps to Level 1 and FedRAMP Moderate to Level 2, as do StateRAMP Categories 1 and 2 respectively. You still submit evidence to DIR.

How long does provisional status last?
Up to eighteen months, within which the service must achieve Level 1 or Level 2 certification or present an accepted equivalent.

Which level do we need?
It follows the data and the system impact: public or non-confidential data in low-impact systems is Level 1; confidential or regulated data in moderate or high-impact systems is Level 2. The contracting agency’s categorization decides it, not the vendor’s preference.

Is TX-RAMP the same as StateRAMP?
No. They are separate programmes with separate governance. Texas accepts StateRAMP categories as equivalents, which is not the same as being the same programme.

Where this leaves you

Treat TX-RAMP as a procurement gate with a documentation answer. Confirm you are inside the Texas definition of a cloud service, get the level right from the agency’s data classification rather than your own, and if you already hold FedRAMP or GovRAMP at the matching level, lead with equivalence instead of starting a fresh assessment. If provisional status is what unblocked the contract, put the eighteen-month date in the calendar the day it is granted — that deadline arrives at renewal, and by then there is no time left to assess.

References

More on government cloud authorization

Boundary documents, control responses and continuous monitoring records are in the GovRAMP (StateRAMP) TX-RAMP Compliance Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.