Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

StateRAMP, now GovRAMP — cloud security verification for government

StateRAMP Is Now GovRAMP: The Verification Pathway Explained

If you are looking for StateRAMP, you are looking for a programme that has changed its name. stateramp.org now redirects to govramp.org, and the organisation operates as GovRAMP.

The rename is not cosmetic. “State” was always slightly wrong: the programme has been used by local government, higher education and K-12 alongside state agencies, and the new name describes what it actually is. The programme, the pathway and the verifications carry over.

What StateRAMP was built to solve

Public sector buyers face the same problem federal agencies faced: every agency assessing every cloud provider independently, using its own questionnaire, arriving at its own conclusion. Multiply that across fifty states and thousands of local agencies and the cost lands on providers, who answer the same questions in different formats forever.

FedRAMP solved this federally. StateRAMP was created to do the equivalent below the federal line — one standardised assessment, recognised by many government buyers, so a provider proves its security posture once.

The programme reports over 1,200 member organisations, more than 70 government organisations engaged, and over 330 products in the programme.

The verification pathway

The StateRAMP, now GovRAMP, cloud security verification pathway

The Security Program is built on NIST SP 800-53 Rev. 5 and is deliberately progressive: a provider starts where it is and advances, rather than facing a single pass-or-fail gate.

Two features distinguish it from the federal model and both are worth planning around.

You may stop at Core. Core Verification covers 60 prioritised controls aligned to the NIST SP 800-53 Rev. 5 Moderate baseline. For a provider serving a small number of agencies with modest data sensitivity, that may be the right terminal state — a decision the federal programme does not offer.

The Snapshot is a real product, not a warm-up. A Single Security Snapshot scores your posture against a published criteria matrix, and the Progressing Snapshot track adds direct engagement from the Program Management Office. Providers who are not yet ready to verify can still show a government buyer something meaningful.

Administration sits with RAMPQuest as the contracted Program Management Office, which handles documentation review and works with the accredited 3PAOs. The framework, requirements and governance stay with GovRAMP itself.

Overlays: how StateRAMP work maps onto other regimes

The programme publishes overlays specifically to stop providers doing the same work twice.

  • The Federal Overlay aligns the impact levels with federal standards including FedRAMP Rev. 5, so a provider pursuing both is not maintaining two unrelated control sets.
  • The CJIS-Aligned Overlay maps CJIS Policy 6.0 onto the controls, which matters for anyone touching law enforcement or criminal justice data.

There is also an AI task force alongside the CJIS-aligned one, which is where emerging guidance in that area is being developed.

StateRAMP, TX-RAMP and the state-run programmes

A common and expensive confusion: not every state programme is this programme.

TX-RAMP is run by the Texas Department of Information Resources, has its own programme manual, its own request process and its own list of certified cloud products. It is a separate certification with its own identifiers, not a regional branch.

What the state programmes generally share is a reciprocity principle — an existing FedRAMP or GovRAMP status is usually the fastest route into a state programme rather than a fresh start. But “usually” is doing work in that sentence, and the answer is specific to each state’s manual.

Check the requiring agency’s own guidance first. Providers routinely pursue the wrong certification because a contract said “state authorisation” and nobody asked which one.

How this relates to FedRAMP

GovRAMP (formerly StateRAMP) FedRAMP
Buyers State, local, education Federal agencies
Control basis NIST SP 800-53 Rev. 5 NIST SP 800-53 baselines by impact level
Partial status Yes — Snapshot, Progressing, Core No equivalent stopping point
Administration Nonprofit community, PMO contracted to RAMPQuest Government programme, currently mid-transition to 20x

If you are pursuing both, sequence matters. The Federal Overlay exists precisely because the control work overlaps heavily, and doing them in parallel with two separate document sets is the expensive way.

What a StateRAMP submission actually requires

  • A defined authorisation boundary. As with any assessment regime, a loose boundary is the costliest early mistake because every artefact describes it.
  • A System Security Plan built on the published template.
  • Control implementation evidence at the level your target step demands — 60 controls for Core, the full baseline above it.
  • A plan of action for anything not yet met.
  • Continuous monitoring, per the ConMon guidance and escalation process. Verification is not a finish line.
  • A 3PAO relationship, booked early, because assessor capacity is finite.

Where to start

  1. Confirm which programme the contract actually requires — GovRAMP, TX-RAMP, or a different state scheme entirely.
  2. Pick your target step honestly. Core may be enough; Authorized is significantly more work.
  3. Draw the boundary and write it down before any documentation.
  4. Use the published templates rather than adapting a federal package — the formats are what the PMO reviews against.
  5. Apply the Federal Overlay if FedRAMP is also on the roadmap, from the start rather than retrospectively.
  6. Set up continuous monitoring before verification, not after.

This guide reflects govramp.org and dir.texas.gov at 15 August 2026. Update any internal documents, bid libraries or supplier questionnaires that still say StateRAMP — the redirect works, but the name on a tender response is read by a person.

The StateRAMP TX-RAMP Compliance Toolkit provides 50 editable templates covering the System Security Plan, the boundary definition, the control implementation records, the plan of action and the continuous monitoring artefacts. If federal authorisation is also in scope, the FedRAMP Toolkit covers that side.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.