Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

GovRAMP status levels explained

GovRAMP Status: A Clear Guide to All 8 Levels in 2026

GovRAMP status is what a state or local government buyer actually checks before they shortlist you. It is not a single pass or fail: the programme publishes a ladder of statuses, and where you sit on it tells a procurement team how far your security posture has been verified and by whom.

This guide covers the two families of status, what each one requires, what changed for the Progressing Snapshot programme in 2026, and how to choose a target.

GovRAMP status levels: progressing statuses and verified statuses
Two families: showing progress, and having been verified.

The two families of GovRAMP status

StateRAMP was renamed GovRAMP in 2025 to reflect a remit beyond states, and the status model carried across. Statuses fall into two groups:

Family Statuses What it signals
Progressing Progressing, Not Progressing, In Process, Pending The provider is working toward verification and can show movement
Verified Core, Ready, Provisionally Authorized, Authorized An assessment has been performed and reviewed by the PMO

The line between them is the one buyers care about. A progressing status says you are engaged with the programme; a verified GovRAMP status says somebody independent has looked at your controls and the PMO has reviewed the result. Authorized sits at the top, with a sponsoring government entity behind it.

What each verified status means in practice

  • Core — a defined subset of controls verified, aimed at products where a full authorization is disproportionate to the risk.
  • Ready — the minimum requirements are met and verified, signalling the product is a credible candidate for a sponsoring agency.
  • Provisionally Authorized — the assessment is complete and reviewed, with the sponsorship or remaining conditions still to land.
  • Authorized — full requirements met, verified, and sponsored. This is what a procurement document usually means when it names GovRAMP.

What changed for the Progressing Snapshot in 2026

From 1 January 2026 the Progressing Security Snapshot programme tightened, with the explicit aim of ensuring every listed product is actually advancing rather than parked. Three changes matter:

  1. A product must score above zero before it appears on the Progressing Product List at all.
  2. Quarterly snapshots, with monthly progress calls between the provider and the GovRAMP advisory team.
  3. Improvement is expected at each snapshot. An identical or declining score can trigger escalation, and a status can move to Not Progressing.

The practical consequence: listing yourself as progressing is no longer a low-cost marketing position. If you enter the programme, plan the remediation work that produces a better score every quarter, or expect the listing to work against you.

Choosing a target GovRAMP status

Work backwards from the contracts you are chasing when picking a GovRAMP status. Read the solicitations: many name a status and a deadline, and some accept a progressing status at award with a verified status required within a set period. That language decides your target far more reliably than an internal ambition.

Then weigh three things. The data your product handles, since higher categorisation raises the control count. The sponsor, because Authorized needs a government entity willing to sponsor you. And the reuse you can claim: work done for FedRAMP or under NIST SP 800-53 carries over substantially, and providers with an existing authorization usually find the GovRAMP path shorter than expected. Our guides to the GovRAMP verification pathway and TX-RAMP’s two levels cover the neighbouring programmes.

The state programmes that run alongside

Some states run their own schemes and recognise GovRAMP work to varying degrees — Texas being the most prominent. Check the recognition rules for each state you sell into before assuming one status covers them all; reciprocity is real but it is not universal.

Where providers lose time

Entering the programme before the controls exist. The 2026 rules punish stasis. Get the score above the floor and the remediation plan funded before you list.

No sponsor strategy. Authorized requires sponsorship, and providers routinely complete the technical work with no agency relationship to convert it.

Treating the snapshot as an assessment. It is a progress measure, not a verified GovRAMP status. Only the verified statuses tell a buyer that an independent assessment happened.

Ignoring continuous monitoring. Verified statuses come with ongoing obligations. A status earned and then left unmaintained lapses, and lapsing publicly is worse than never having listed.

Frequently asked questions

How many GovRAMP statuses are there?
Eight in total: four progressing statuses — Progressing, Not Progressing, In Process and Pending — and four verified statuses: Core, Ready, Provisionally Authorized and Authorized.

Is GovRAMP the same as StateRAMP?
Yes. StateRAMP was renamed GovRAMP in 2025; the programme, the statuses and the product list continued.

Does FedRAMP work count?
Substantially. Both rest on NIST SP 800-53, so an existing authorization or a mature control set transfers with rework rather than rebuilding.

Do we need a sponsor?
For Authorized, yes — a government sponsor is part of the model. Lower verified statuses can be reached without one.

What happens if our score does not improve?
Under the 2026 rules, identical or declining snapshot scores can trigger escalation and a change of status. Progressing is meant to mean progressing.

Where this leaves you

Read the solicitations you are actually bidding for and take your target GovRAMP status from them, not from ambition. Do the control work before you list, because the 2026 snapshot rules turn a stalled listing into a visible negative. Reuse FedRAMP and 800-53 work aggressively, line up a sponsor early if Authorized is the goal, and budget for continuous monitoring — the status is a subscription, not a purchase.

References

  • GovRAMP — the programme, its statuses and the published product list.
  • NIST SP 800-53 Revision 5 — the control catalogue underneath both GovRAMP and FedRAMP.

More on government cloud authorization

Control mappings, policy templates and the submission checklist are in the GovRAMP (StateRAMP) TX-RAMP Compliance Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.