StateRAMP Is Now GovRAMP: The 2026 Guide to GovRAMP and TX-RAMP Authorization
StateRAMP rebranded to GovRAMP on February 14, 2025, though StateRAMP Inc. remains the legal entity operating as GovRAMP. GovRAMP is a voluntary, NIST 800-53-based cloud authorization program adopted by state and local governments. TX-RAMP is Texas’s separate, statutorily mandated program, which grants Level 2 certification reciprocally to products holding GovRAMP Core, Ready, or Authorized status.
- StateRAMP is now GovRAMP. The rebrand was announced February 14, 2025; StateRAMP Inc. remains the legal name, operating as (dba) GovRAMP, so existing memberships and authorizations carried over unchanged.
- GovRAMP is a ladder, not a gate. Snapshot (40 controls), Progressing Snapshot (40), Core (60, no 3PAO), Ready (80, 3PAO), and Authorized/Provisional (300+, 3PAO plus government sponsorship).
- TX-RAMP is mandatory; GovRAMP is not. Texas Government Code 2063.408 requires TX-RAMP certification for state agencies, higher education, and public community colleges. GovRAMP is adopted voluntarily, state by state.
- GovRAMP Core earns full TX-RAMP Level 2 without a third-party assessor — often the cheapest defensible route into Texas for moderate and high impact systems.
- Reciprocity now runs both ways. Updated FedRAMP Class A Certification Rules recognize GovRAMP as an approved alternative security framework, so state-level work can count toward federal authorization.
Did StateRAMP become GovRAMP?
Yes. On February 14, 2025, StateRAMP announced it was rebranding to GovRAMP. According to the organization’s rebrand announcement, the name change reflects a mission that had outgrown the word “state” — the program serves state, local, tribal, territorial, and educational government organizations, and increasingly works alongside federal programs.
The detail practitioners need is that this was a naming change, not a corporate one. The announcement is explicit: “StateRAMP will legally remain the organization’s name but will operate as (dba) GovRAMP.” That is why the fee schedule on the GovRAMP pricing page still directs membership dues to “StateRAMP Inc. dba GovRAMP.” Existing contracts, memberships, and authorizations carried over without interruption or re-papering.
On the program side the transition is complete: stateramp.org now issues a permanent redirect to govramp.org, and every current program document, status name, and product list uses GovRAMP branding.
Where you will still see “StateRAMP”
Downstream government documentation lags, and that is the practical trap. Texas is the clearest example. The TX-RAMP Program Manual 4.0, effective February 12, 2026, uses GovRAMP throughout and adds a footnote stating that “wherever the term ‘GovRAMP’ is used, it shall be understood to implicitly include ‘StateRAMP.'” But the Texas DIR TX-RAMP Eligibility and Requirements page still describes reciprocity in terms of “StateRAMP Category 1” and “StateRAMP Category 2” — terminology GovRAMP itself has retired.
Two rules keep you out of trouble: treat the current Program Manual as authoritative over any web page summarizing it, and when an RFP says “StateRAMP,” answer with your GovRAMP status and cite the equivalence rather than assuming the buyer knows they are the same program.
What is GovRAMP and how does the program work?
GovRAMP is a nonprofit membership organization running a standardized, NIST-based security verification program for cloud products sold to government. Rather than every agency running its own vendor review, a provider is assessed once against a common baseline and the result is reusable across participating governments — the “verify once, serve many” model.
The program is built on NIST SP 800-53 Revision 5, according to the GovRAMP Security Program overview. If your team already runs an 800-53-aligned control set, most of the underlying work is done; what changes is the packaging, evidence discipline, and monitoring cadence. Our NIST SP 800-53 pre-implementation checklist covers that groundwork, and our guide to NIST compliance explains how the publication family fits together.
GovRAMP is a progressive ladder rather than a pass/fail gate, so providers can stop at the tier matching their customers’ risk appetite. Day-to-day administration is handled by RAMPQuest, the contracted Program Management Office (PMO), while GovRAMP owns the framework, governance, and membership.
- Single Security Snapshot — 40 foundational NIST controls, PMO-validated, 12-month status. A gap assessment, not a verification.
- Progressing Security Snapshot — same 40 controls, assessed quarterly with monthly guidance to show measurable improvement.
- Core Verification — 60 prioritized controls, PMO-validated, quarterly continuous monitoring. No 3PAO required.
- Ready Verification — 80 controls, independent 3PAO assessment plus PMO validation, monthly continuous monitoring.
- Authorized / Provisional Verification — 300+ controls, full 3PAO Security Assessment Report, government sponsorship, monthly continuous monitoring.
Alongside the tier, you select an impact level — Low, Moderate, or High — based on the sensitivity of the government data your product handles. The Authorized Verification requirements make impact-level determination step three of the process, ahead of engaging an assessor, because it drives the size of your control set and your documentation package.
Two statuses cause confusion. Provisionally Authorized means you met Authorized requirements but depend on interconnected technology that is not yet GovRAMP or FedRAMP verified, or you carry limited items tracked in a POA&M. It converts to Authorized once those dependencies clear. And a Snapshot is not a verification — it is a point-in-time gap assessment, which matters when a state procurement office asks for “GovRAMP status.”
Which states require GovRAMP?
Participation and mandate are different things, and conflating them is the most common error in vendor GTM planning. As of August 2026, the GovRAMP participating government organizations list shows 73 government and education entities spanning 33 states, plus tribal and federal participants. GovRAMP’s own framing is careful: “Participation can reflect exploration, planning, or active implementation.”
A much smaller group has moved from participation to formal adoption — publishing a state-specific GovRAMP program with defined vendor requirements. GovRAMP maintains dedicated program pages for Arizona, Indiana, Minnesota, Nevada, New Hampshire, North Carolina, North Dakota, Oregon, Texas, and Utah, along with local governments including Arapahoe County (CO), the City of Arlington (TX), the City of Chandler (AZ), the City of Fishers (IN), and Palm Beach Gardens (FL).
Momentum in 2026 has been steady rather than explosive: North Carolina announced its partnership in February 2026, Nevada followed in March 2026, and Arizona folded its homegrown AZ-RAMP program into GovRAMP in April 2025 — a signal that states are consolidating onto a shared standard rather than proliferating their own.
GovRAMP reports 1,200+ member organizations and 330+ products in the program overall. Its adoption guidance for governments describes three postures agencies actually take: recognizing GovRAMP status as acceptable evidence, preferring it in scoring, or mandating it by data classification. Most participating states sit in the first two.
What this means for a vendor: do not build a roadmap around “33 states require GovRAMP.” They do not. Build it around the specific states in your pipeline, check whether each has a published program page and what tier it names, and treat Texas separately — it is the one state with a statutory mandate and its own program.
What is TX-RAMP and who must comply?
TX-RAMP is Texas’s own cloud authorization program, and unlike GovRAMP participation it is compulsory. Texas Government Code Section 2063.408 requires DIR to run a state risk and authorization management program, and requires state agencies to enter or renew cloud contracts only with services that meet TX-RAMP requirements. Per the DIR eligibility guidance, the mandate reaches state agencies, institutions of higher education, and public community colleges as defined in Government Code Section 2054.003(13).
Scope is narrower than vendors assume. Only cloud computing services as defined by NIST SP 800-145 are covered; custom-developed applications and non-substantive use of confidential state data are carved out in the Program Manual. Critically, a SaaS product does not inherit the TX-RAMP certification of the IaaS or PaaS it runs on, though it may inherit applicable controls from that certified infrastructure.
Two levels, set by the agency
TX-RAMP has two certification levels, and the agency — not the vendor — determines which applies:
- Level 1 covers low-impact information resources. Appendix A of Program Manual 4.0 puts this baseline at 117 controls and control enhancements.
- Level 2 covers moderate or high impact information resources, as defined in 1 Texas Administrative Code Section 202.1. This baseline is 223 controls and enhancements.
TX-RAMP Provisional certification is a separate on-ramp: it lets an agency contract for a product before full certification, and is earned by completing the Acknowledgment and Inventory Questionnaire. Under Manual 4.0 it runs 12 months, extendable at DIR’s discretion by six months, with a further six-month extension possible if the provider has actively begun the full certification process. Note that DIR’s public eligibility page still cites an 18-month figure from an earlier manual version — another case where the manual governs.
One structural difference from FedRAMP and GovRAMP: TX-RAMP does not require a 3PAO. DIR conducts assessments internally, as confirmed in the TX-RAMP FAQs. DIR also states plainly that it cannot sign NDAs for any part of the process, including third-party audit reports — plan your evidence sharing accordingly.
A governance change to watch
Program Manual 4.0 carries a footnote that most vendors have missed: in 2025 the Texas Legislature passed House Bill 150, creating the Texas Cyber Command and transferring DIR’s cybersecurity duties — including TX-RAMP — to it. HB 150 took effect September 1, 2025. DIR continues to administer TX-RAMP until a memorandum between the Cyber Command and DIR triggers full transfer, so the operational contacts and portals are unchanged for now, but the program’s home is expected to move.
GovRAMP vs TX-RAMP vs FedRAMP: how do they compare?
These three programs share a NIST SP 800-53 foundation and a reuse philosophy, but differ on who assesses you, who sponsors you, and how long the status lasts.
| Dimension | GovRAMP (formerly StateRAMP) | TX-RAMP | FedRAMP |
|---|---|---|---|
| Who requires it | Voluntary; required by individual participating governments that adopt it | Mandatory by statute (Tex. Gov’t Code 2063.408) for Texas state agencies, higher ed, and public community colleges | Mandatory for U.S. federal agency cloud use |
| Governing body | GovRAMP (legally StateRAMP Inc. dba GovRAMP), nonprofit; PMO run by RAMPQuest | Texas DIR, transferring to Texas Cyber Command under HB 150 | GSA FedRAMP PMO |
| Tiers / levels | Snapshot (40), Progressing Snapshot (40), Core (60), Ready (80), Authorized/Provisional (300+); Low/Moderate/High impact | Level 1 (117 controls), Level 2 (223 controls), plus Provisional certification | Low, Moderate, High baselines; Low-Impact SaaS (Li-SaaS) |
| Independent assessor | 3PAO required for Ready and Authorized; not for Core or Snapshot | Not required — DIR assesses internally | 3PAO required |
| Sponsorship | Government sponsor or GovRAMP Approvals Committee (Authorized only) | None — DIR grants certification directly | Agency sponsorship or JAB/PMO pathway |
| Status duration | 12-month statuses, maintained by continuous monitoring | 3 years for Level 1 and Level 2; 12 months for Provisional | Continuous, maintained via ConMon |
| Continuous monitoring | Quarterly (Core), monthly (Ready, Authorized) | Annual vulnerability reports (Level 1), quarterly (Level 2), via SPECTRIM | Monthly scans and POA&M updates |
| Reciprocity accepted | Accepts federal work toward verification; recognized by TX-RAMP | Accepts GovRAMP and FedRAMP statuses | Recognizes GovRAMP as an approved alternative security framework for Class A |
If FedRAMP is your eventual destination, our guide to what FedRAMP is covers the federal path in depth; the sections below focus on how work in one program travels to the others.
How does reciprocity work between GovRAMP, TX-RAMP, and FedRAMP?
Reciprocity is where the real ROI sits, and Texas has the most generous mapping. Section 9.2 of TX-RAMP Program Manual 4.0 states that providers on the FedRAMP Marketplace or the GovRAMP authorized products list may inherit a corresponding TX-RAMP status simply by requesting reciprocal certification.
The GovRAMP-to-Texas mapping is unusually favorable:
- GovRAMP Core, Ready, Provisionally Authorized, or Authorized → TX-RAMP Level 2 certification. All four map to the higher level, because DIR credits the independent review and continuous monitoring obligations attached to each.
- GovRAMP Snapshot → TX-RAMP Provisional certification only, and DIR states it “will not consider GovRAMP Snapshot as a long-term certification solution.”
- Progressing Snapshot enrollment → TX-RAMP Provisional certification for the length of enrollment.
That first bullet is the single most actionable fact in this guide. GovRAMP Core requires no 3PAO, yet it earns full TX-RAMP Level 2 — the level needed for moderate and high impact Texas systems. For many mid-market SaaS vendors, Core is the cheapest defensible route into Texas.
FedRAMP maps too: FedRAMP Authorized grants the corresponding TX-RAMP level, while FedRAMP In Process and FedRAMP Ready grant TX-RAMP Provisional. One trap — the manual is explicit that FedRAMP Low-Impact SaaS does not inherit any TX-RAMP certification, because TX-RAMP has no Li-SaaS equivalent.
Reciprocity also cuts monitoring overhead: providers certified through the FedRAMP or GovRAMP equivalence process are not required to submit continuous monitoring artifacts to DIR at all. The flip side is that losing the external status drops the TX-RAMP certification back onto the manual’s full requirements.
Reciprocity now runs upward, too
Historically the flow was federal-to-state. That changed in 2026. According to GovRAMP’s July 15, 2026 analysis, the updated FedRAMP Class A Certification Rules recognize GovRAMP as an approved alternative security framework: providers that completed a GovRAMP assessment within the previous 12 months may use it to satisfy the alternative-framework prerequisite, and GovRAMP Readiness Assessment Reports and Security Assessment Reports count as supporting documentation. This sits inside the broader FedRAMP 20x modernization effort. It does not waive any FedRAMP requirement — but state-level work is no longer a dead end federally.
How do you get authorized, step by step?
The sequence differs by program. Below is the practical order of operations for each, drawn from the official process documentation.
GovRAMP Authorized Verification
- Join as a private sector member. Active membership is a prerequisite for any participation in the Security Program.
- Build readiness (optional but common). Snapshot, Progressing Snapshot, Core, or Ready first — each is a legitimate stopping point.
- Determine your impact level. Low, Moderate, or High, based on your government customers and data sensitivity. Use GovRAMP’s data classification tool.
- Engage an approved 3PAO to produce a full Security Assessment Report.
- Complete the documentation package — System Security Plan, policies, and the Service Provider Package matching your impact level.
- Submit to the PMO with a Security Review Request.
- Secure sponsorship. Either a government sponsor or the GovRAMP Approvals Committee, which acts as an appointed sponsor.
- Get listed on the Program Participants List at the granted status.
- Run monthly continuous monitoring to keep the status alive.
TX-RAMP certification
- Submit the TX-RAMP Assessment Request through DIR’s portal (this same form is used to request reciprocity for an existing FedRAMP or GovRAMP status).
- DIR creates an engagement record as the central repository for the cloud service.
- Complete the Acknowledgment and Inventory Questionnaire. Approval here is what unlocks Provisional certification — often enough to let an agency sign.
- Complete the TX-RAMP Assessment Questionnaire, including the Security Plan Control Implementation Workbook.
- Assessment review. Submissions are queued in order received; DIR will not review incomplete packages.
- Certification decision, then entry into continuous monitoring.
- Recertify. You may initiate up to 12 months before expiration.
Fast Track is worth planning around. DIR accepts SOC 2 Type 2, HITRUST validated assessments, PCI DSS QSA Reports on Compliance, ISO 27001, ISO 27017, ISO 27018, CSA STAR Level II, and FISMA assessments — provided the assessment was conducted within the previous 24 months — to reduce the documentation burden. The evidence is in the outcomes: of the 2,630 entries on DIR’s TX-RAMP certified cloud products list as of August 2026, 1,206 were certified through Fast Track, the single largest pathway, ahead of 557 via reciprocity with another RAMP and 531 via full DIR assessment. If you already hold a SOC 2 Type 2 or ISO 27001, use it.
If you are choosing which framework to lead with, our framework library maps the overlaps.
How much does GovRAMP and TX-RAMP authorization cost?
GovRAMP publishes its fee schedule, which is unusual and useful for budgeting. The rates below are from the GovRAMP pricing overview (effective January 1, 2025) for the under-$1M revenue tier, and reflect the lowest available membership level. Fees split between GovRAMP membership dues and PMO fees paid to RAMPQuest.
- Single Security Snapshot — $500 dues + $1,000 PMO = $1,500
- Progressing Security Snapshot — $500 + $9,000 = $9,500
- Core Verification — $500 + $10,000 = $10,500
- Ready Verification — $500 + $3,500 = $4,000, plus 3PAO costs
- Authorized / Provisional — $500 + $4,500 = $5,000, plus 3PAO costs
Two caveats matter more than the numbers. Ready and Authorized look cheaper than Core on the program fee line, but both require a third-party assessment whose cost is excluded — and a 3PAO engagement is typically the largest single line item. Rates also scale with revenue tier, and membership dues fall due annually on June 1.
TX-RAMP does not charge vendors a program fee, since DIR performs assessments internally. Your cost there is internal effort and, if you are going the Fast Track route, maintaining the underlying SOC 2 or ISO certification.
Timelines
Neither program publishes a guaranteed turnaround, and both name the same drivers: documentation completeness, assessment level, and responsiveness. DIR is specific on one point — providers must respond to clarification requests within 10 business days, and failing to do so may mean rejection and reprioritization to the back of the queue.
Plan around the checkpoints you can control. TX-RAMP Provisional certification comes after the A&I Questionnaire, well before full certification, and it is usually enough to let an agency contract with you. Full TX-RAMP certifications then run three years, with recertification notices at 12 months and 90 days out and a lighter review scope — 38 control requirements for Level 1 and 48 for Level 2.
What are the most common mistakes, and how do you prepare?
The programs are documentation-heavy and monitoring-heavy. Most failures are operational, not technical.
Treating a Snapshot as an authorization. A Snapshot is a one-time gap assessment. Texas grants only Provisional certification for it and says plainly it is not a long-term solution. If a buyer asks for GovRAMP status, name the tier.
Letting Provisional status lapse. Under Manual 4.0, failing to reach Level 1 or Level 2 before Provisional expiry means a lapse in certification, and a provider that already used a Provisional certification and failed to convert cannot apply for a new one for that service. Agencies then migrate off under a Transitional Grace Period capped at 24 months. That is a contract you lose.
Underestimating continuous monitoring. GovRAMP Ready and Authorized require monthly ConMon; Core requires quarterly. TX-RAMP Level 2 requires quarterly vulnerability reports through SPECTRIM, Level 1 annual, and any breach of system security must be disclosed to DIR within 48 hours. These are recurring obligations with named cadences, not annual audit prep.
Assuming infrastructure inheritance. A SaaS product running on certified IaaS does not inherit that certification. You may inherit applicable controls, but you still need your own certification and must report significant infrastructure changes.
Answering “StateRAMP” questions as if they are a different program. They are not. State the equivalence, cite the rebrand, and move on.
What good preparation looks like
- Map once to NIST SP 800-53 Rev. 5. It underpins GovRAMP, TX-RAMP, and FedRAMP. Every control you implement once serves all three.
- Inventory your existing attestations. SOC 2 Type 2 or ISO 27001 within 24 months puts you on the Fast Track — the most-used path into Texas.
- Pick the cheapest sufficient tier. If Texas is the target and you need Level 2, GovRAMP Core gets you there without a 3PAO.
- Stand up the monitoring cadence before you apply. Monthly scans, POA&M hygiene, and a 48-hour breach notification path should exist on day one.
- Assign an owner for status changes. Reciprocal certifications are contingent on the upstream status; when it moves, Texas needs to know.
Frequently asked questions
Is StateRAMP the same as GovRAMP?
Does GovRAMP authorization satisfy TX-RAMP?
Do you need a 3PAO for TX-RAMP?
How long does TX-RAMP certification last?
How many states require GovRAMP?
Can a GovRAMP assessment count toward FedRAMP?
- GovRAMP — StateRAMP Announces Rebrand to GovRAMP (Feb 14, 2025)
- GovRAMP — Security Program Overview
- GovRAMP — Authorized / Provisional Verification
- GovRAMP — Participating Government Organizations
- GovRAMP — Security Program Pricing Overview
- GovRAMP — Adoption Guidance for Governments
- GovRAMP — FedRAMP Recognizes GovRAMP in Updated Class A Rules (Jul 15, 2026)
- Texas DIR — TX-RAMP Program Manual Version 4.0 (effective Feb 12, 2026)
- Texas DIR — TX-RAMP Eligibility and Requirements
- Texas DIR — Texas Risk and Authorization Management Program (TX-RAMP)
- Texas DIR — TX-RAMP Frequently Asked Questions
- Texas DIR — TX-RAMP Certified Cloud Products List
- Texas Legislature Online — HB 150, 89th Legislature (Texas Cyber Command)
- FedRAMP — FedRAMP 20x
Run GovRAMP and TX-RAMP on one control set with Compyl
Compyl maps your NIST SP 800-53 controls once and reuses the evidence across GovRAMP tiers, TX-RAMP levels, and FedRAMP, so a single implementation feeds every public sector authorization. Automated continuous monitoring keeps POA&M items, scan cadences, and status changes current instead of scrambling before each review.
About this guide. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.