What Is GovRAMP? A Guide to State-Level Cloud Authorization
State and local government cloud demand spans state executive agencies, counties, cities, courts, K-12 districts, and universities, and for years many relied on one-off vendor security reviews. GovRAMP, a nonprofit authorization program modeled on the Federal Risk and Authorization Management Program (FedRAMP), gives those buyers one shared standard, and a growing list of states now writes it into cloud contracts.
For Software-as-a-Service (SaaS) vendors, the complication is that federal authorization can require substantial upfront investment and does not automatically carry over. GovRAMP now affects state, local, tribal, and education cloud procurement, and SaaS vendors need to plan for it alongside FedRAMP.
Key Takeaways
- StateRAMP became GovRAMP. The rebrand took effect in February 2025 and recognized that local, tribal, and education members had outgrown the state-only name. Fees did not change.
- GovRAMP control baseline. GovRAMP is built on the National Institute of Standards and Technology (NIST) SP 800-53 Rev5, and its three impact levels map directly onto FedRAMP Rev5 baselines.
- State mandates multiply. Utah's requirements took effect in 2025, North Carolina's in April 2026, and Nevada's on July 1, 2026, while Texas handles GovRAMP through TX-RAMP reciprocity review.
- FedRAMP reciprocity limits. The Fast Track program lets FedRAMP-authorized vendors reuse their federal packages, but membership, Program Management Office (PMO) review, and separate continuous monitoring still apply.
GovRAMP Standardizes Cloud Security for State and Local Government
GovRAMP is a 501(c)(6) nonprofit that operates a cloud security authorization program for state, local, tribal, and education governments. Established in April 2020 and headquartered in Indianapolis, it verifies that infrastructure, platform, and software-as-a-service offerings handling government data meet a defined security baseline before agencies buy them.
The program mirrors FedRAMP in four operating mechanics:
- Security packages built on NIST SP 800-53 Rev5
- Independent GovRAMP assessments by Third-Party Assessment Organizations (3PAOs)
- GovRAMP PMO validation
- Continuous monitoring after authorization
Those mechanics turn a jurisdiction-specific review into a reusable authorization package. Verified products appear on a public Program Participants List, and the GovRAMP homepage reports more than 330 products in the program with more than 70 government organizations engaged.
Vendors can reuse one authorization across participating jurisdictions, replacing the one-off questionnaires and state-by-state assessments that never transferred anywhere. That reusability is exactly what the program's original state-only branding failed to convey, which is why the organization rebranded in 2025.
GovRAMP Was Renamed From StateRAMP to Reflect a Broader Mission
The organization announced its transition from StateRAMP to GovRAMP on February 14, 2025. Legally, it continues to operate as StateRAMP dba GovRAMP, and leadership confirmed the change would not affect existing agreements, procurements, or fees. The rebrand codified what had already become true in practice: the program serves a broader public sector than a state-only label suggested.
That shift carries several practical implications for vendors and buyers:
- Wider buyer coverage. Verified products are positioned for county, city, K-12, higher education, and tribal buyers, not just state executive agencies.
- Unified brand and URL. All program assets now live under govramp.org, reducing confusion during procurement and legal review.
- Legacy state programs converging. Arizona folded its proprietary AZ-RAMP into GovRAMP on April 18, 2025, after former state CIO J.R. Sloan cited the resource burden of monitoring vendors in-house.
- Reciprocity retained where it existed. Texas kept its statutory TX-RAMP program separate but continues to accept GovRAMP authorization as satisfying it.
The broader mission also changed how vendors should think about sequencing, because a single authorization now travels further than it did under the state-only framing. That makes the mechanics of getting authorized worth walking through in detail.
GovRAMP Authorization Follows a Defined Process
Vendors pursuing GovRAMP authorization work through a sequence of five stages that connects membership to independent assessment, formal review, and ongoing oversight. Each stage builds on the last, and skipping any of them stops the package from advancing.
1. Join GovRAMP and Scope the Offering
Every vendor must be an active GovRAMP member before entering the security program. From there, it determines its impact level (Low, Moderate, or High) and defines an authorization boundary covering every technology and service that stores, processes, or transmits government data.
2. Complete a Readiness Stage
Vendors not ready for a full audit can start with the Progressing Security Snapshot, a PMO-reviewed check against the top 40 NIST controls with quarterly reassessment and no 3PAO involvement. Alternatively, they can engage a 3PAO for a Readiness Assessment Report.
3. Undergo a Third-Party Assessment
An approved 3PAO performs the GovRAMP full assessment and produces the Security Assessment Report. The vendor engages and pays the assessor directly, which keeps the assessment independent of the PMO.
4. Submit the Package for PMO Review and Sponsorship
The System Security Plan and related assessment and Plan of Action and Milestones (POA&M) materials go to the PMO in GovRAMP templates. Authorized status requires approval through the GovRAMP approval process, and a government sponsor is part of that path.
5. Maintain Continuous Monitoring (ConMon)
ConMon begins immediately upon award of a verified status. Monthly and quarterly reports go to the PMO, vendors complete an annual 3PAO assessment with penetration testing, and POA&M remediation follows prescribed timelines. Missed obligations can end in revocation.
Completing these stages places a product on the Program Participants List, but the listing itself is not a single binary. GovRAMP layers several statuses on top of the process to signal how far along an offering actually is.
GovRAMP Uses Several Security Statuses to Track Progress
Because vendors reach full authorization on different timelines, GovRAMP publishes distinct statuses that show where a product sits in the process rather than treating verification as pass/fail. Each status carries its own control coverage and monitoring obligations.
- Core: Core is an entry-level milestone that covers 60 NIST controls from NIST SP 800-53 Rev5 drawn from the Moderate baseline and selected using the MITRE ATT&CK framework. The PMO validates it directly, with no 3PAO required and quarterly monitoring.
- Ready: Ready is based on a Readiness Assessment Report conducted by an accredited 3PAO. The report documents the system's posture, observations, and gaps against the full baseline as a step toward full authorization.
- Provisionally Authorized: Provisionally Authorized products meet the full baseline but either rely on interconnected systems not yet authorized or carry limited outstanding conditions that do not materially affect security posture.
- Authorized: Authorized is the highest status and confirms compliance with the applicable full baseline at the product's impact level. Authorized offerings appear on the Program Participants List alongside vendors such as Microsoft, Salesforce, Okta, and Zoom, with monthly monitoring and an annual assessment to keep the status current.
Each of these statuses maps onto a shared control catalog that GovRAMP inherits directly from the federal program, which is where the comparison with FedRAMP becomes unavoidable.
GovRAMP Shares a Foundation With FedRAMP but Is Not Interchangeable With It
Both programs assess against NIST SP 800-53 Rev5. GovRAMP's impact levels map directly onto FedRAMP's Rev5 baselines, which include Moderate and High. The shared baseline does not make the two authorizations interchangeable, and the differences show up most clearly where vendors try to reuse work between them.
Fast Track Rewards Vendors With Existing FedRAMP Status
Fast Track lets vendors with existing federal security documentation reuse that work to accelerate GovRAMP verification. The GovRAMP PMO accepts documents in FedRAMP formatting, and a FedRAMP-authorized offering can use that prior work to move through GovRAMP review without unnecessary duplication.
GovRAMP's framing is literal: "Build Once. Use Everywhere." Official GovRAMP pricing applies to certain membership and authorization activities, but the FedRAMP PMO does not charge Cloud Service Providers (CSPs) for package review or Marketplace designation, and continuous monitoring costs are driven by industry and internal program expenses rather than FedRAMP PMO fees. Vendors still have to submit documentation for PMO review and maintain GovRAMP ConMon.
The Two Programs Serve Different Government Buyers
FedRAMP authorizes cloud services for federal agency authorizations, and a vendor cannot obtain it without doing business with the federal government. GovRAMP serves state, local, tribal, and education (SLED) buyers through a separate nonprofit with its own board, its own PMO, its own government sponsorship requirement, and its own monthly ConMon reporting.
Two more distinctions carry weight in any StateRAMP vs. FedRAMP analysis. First, authorization does not flow down: running on FedRAMP- or GovRAMP-authorized infrastructure does not make the SaaS product on top of it compliant. Second, reciprocity runs one direction: FedRAMP work counts toward GovRAMP, while GovRAMP is still requesting a fast-track path toward FedRAMP and none exists today. Those directional rules matter more each quarter as additional states convert GovRAMP from a voluntary posture into a contract requirement.
A Growing Number of States Require GovRAMP for Cloud Contracts
Participation has grown since StateRAMP launched in January 2021 and later transitioned to GovRAMP, whose list of participating government organizations now includes state, local, tribal, and education entities, including K-12 networks, higher education systems such as The University of Texas System, and the Lower Sioux Indian Community in Minnesota. GovRAMP itself notes that participation "can reflect exploration, planning, or active implementation," so the raw count overstates hard mandates. A distinct subset, though, has moved from voluntary participation to contractual requirement.
North Carolina Requires GovRAMP for Executive Agency Cloud Contracts
North Carolina's Department of Information Technology announced in February 2026 that cloud vendors working with executive agencies must meet GovRAMP security standards starting with the April 2026 deadline. The state folded the requirement into its existing technology governance rather than creating a new approval process. State CIO Teena Piccione said the requirement is meant to build trust and support progress while satisfying compliance obligations.
Nevada and Utah Set Statewide Requirements
Nevada partnered with GovRAMP to standardize cloud security across executive branch agencies, with requirements effective July 1, 2026. Utah's requirements took effect in 2025, and the state has since reported "meaningful improvements in the consistency and quality of security documentation across vendors."
Texas Accepts GovRAMP Through TX-RAMP Reciprocity Review
Texas Government Code §2054.0593 has required TX-RAMP compliance for state agency cloud contracts since January 1, 2022. TX-RAMP remains a separate program, and Texas recognizes FedRAMP authorization through TX-RAMP, but vendors may need to submit a separate request through ARCHER and undergo a reciprocity review rather than relying on automatic GovRAMP reciprocity.
As each of these mandates hardens, vendors selling into both federal and state markets have to reconcile two authorization tracks that share a control catalog but nothing else.
SaaS Vendors Should Track GovRAMP Alongside Federal Compliance Goals
For a vendor selling into both federal and SLED markets, the same NIST control catalog now sits behind two separate authorization machines, and building both in parallel duplicates line items that were already heavy on their own:
- Two 3PAO engagements. GovRAMP 3PAO assessment costs are separate and vary by provider, while traditional FedRAMP authorization sits at upwards of $3.5 million with a 12- to 36-month timeline once assessment, remediation, and internal labor stack up.
- Two fee stacks. GovRAMP membership dues and annual PMO fees run alongside federal advisory and package costs.
- Two ConMon streams. Monthly deliverables go to the GovRAMP Program Management Office while FedRAMP post-Authority to Operate (ATO) requirements continue on their own cadence.
- Two documentation sets. Each program has its own templates for System Security Plans and assessment and POA&M materials.
Fast Track collapses the GovRAMP column to program fees, but only for vendors already holding a federal authorization in good standing. That inverts the instinct to start with the cheaper state program and reduces the build-versus-inherit decision to the federal side alone. Which is why, for vendors that need federal authorization anyway, sequencing hinges on how quickly and cheaply they can secure the FedRAMP asset in the first place.
Federal Authorization Should Come First When Federal Sales Are on the Roadmap
FedRAMP work flows into GovRAMP through Fast Track and into Texas through TX-RAMP reciprocity, while GovRAMP work flows nowhere federal. Vendors with any federal pipeline that lead with GovRAMP end up paying for state authorization twice, once now and again in duplicated effort when the federal program starts from zero, so the federal package should be the root asset.
Knox Systems offers a FedRAMP-as-a-Service platform that helps SaaS companies achieve federal authorization in approximately 90 days at 90% less cost. Vendors inherit 60% to 80% of required controls on day one, with automated continuous monitoring across AWS, Azure, and GCP. Knox currently supports FedRAMP Moderate, FedRAMP High, and Defense Information Systems Agency (DISA) Impact Level 4 (IL-4); IL-5 authorization is in process, with an estimated completion date of December 2026.
To map a sequencing plan across both programs, book a meeting.
FAQs about GovRAMP
What Does GovRAMP Participation Cost in Program Fees?
Annual dues begin at $1,500, and the 2025 fee schedule separates PMO review charges from assessor costs. Budgeting should treat membership, review fees, ConMon reviews, and 3PAO work as separate categories.
Who Can Perform GovRAMP Third-Party Assessments?
GovRAMP relies on assessors that meet its program requirements, not any security consultant a vendor already uses. The 2026 discount program is aimed at vendors moving up from snapshot or Core milestones.
Does GovRAMP Address Artificial Intelligence (AI)-Enabled Products?
Yes. The AI Self-Reporting Addendum adds product-specific disclosure for AI-enabled offerings and sits within GovRAMP's broader modernization agenda.
What Happens if a Vendor Falls Behind on Continuous Monitoring?
The PMO can move an offering to a remediation posture or revoke its status when monthly reports, annual assessments, or POA&M timelines lapse. Restoring status generally requires re-engaging a 3PAO and resubmitting materials rather than resuming the prior cadence.
Can a Vendor Start GovRAMP Without a Government Sponsor Already Lined Up?
Yes. Vendors can enter as members and progress through readiness or Core without a named sponsor, but full Authorized status requires government sponsorship as part of the PMO approval path.