What Is GovRAMP Core? Requirements, Costs & Timeline

Written by: 
Team Knox
Published on: 
August 27, 2026

State and local buyers increasingly require a verified security status before certain cloud contracts can move forward. GovRAMP, the nonprofit formerly known as the State Risk and Authorization Management Program (StateRAMP), launched the Core program on May 5, 2025: a Program Management Office (PMO)-validated Core verification status with no Third-Party Assessment Organization (3PAO) involved.

Key Takeaways

  • PMO validation applies. The GovRAMP PMO reviews documentation and scan results directly; no 3PAO assessment is required until the Ready tier.  
  • Sixty controls apply. They come from NIST SP 800-53 Rev5 at the Moderate Impact Level, selected using the MITRE ATT\&CK Framework.  
  • Fees scale with revenue. The annual PMO assessment fee runs $9,000 to $17,000, plus member dues and monitoring fees.  
  • Verification lasts 12 months. Core products are listed on the Authorized Product List, maintain quarterly Continuous Monitoring (ConMon), and can renew without limit.

GovRAMP Core Gives CSPs a Verified Security Baseline Without a 3PAO

GovRAMP Core is a PMO-validated verification status that confirms a cloud service provider (CSP) has implemented 60 prioritized NIST SP 800-53 Rev5 controls at the Moderate Impact Level baseline. It sits between early program visibility and full authorization on the GovRAMP status ladder, giving providers a credible entry-level designation without engaging a third-party assessor.

The PMO conducts the review itself. CSPs submit a completed System Security Plan (SSP) and other evidence, and the PMO evaluates the documentation package directly. GovRAMP's official Core page calls it "a clear, credible signal of your security maturity without requiring a full third-party assessment".

The program traces to StateRAMP, founded in early 2020 by state and industry technology leaders. The 501(c)(6) nonprofit renamed itself GovRAMP on February 14, 2025, and contracts PMO operations to RAMPQuest. Core, in GovRAMP's words, was developed "in response to direct feedback from states, local governments, and cloud service providers" that needed a lower-cost, faster on-ramp to public sector markets than full authorization allows.

Three Tiers Define the GovRAMP Verification Ladder

GovRAMP's status ladder includes Core, Ready, Provisionally Authorized, and Authorized; the differences across statuses come down to who assesses, how many controls apply, and how often monitoring runs.

DimensionCoreReadyAuthorized
Assessment bodyGovRAMP PMO directly; no 3PAOIndependent 3PAO and PMO validationIndependent assessment and government approval
Controls required60 (NIST SP 800-53 Rev5, Moderate baseline)80 minimumApplicable impact-level controls
Sponsorship neededNo sponsor requirement statedSponsorship is not requiredGovernment sponsor or Approvals Committee approval
Listing outcomeAuthorized Product List (APL)Authorized Product ListAPL
Monitoring cadenceQuarterly ConMonMonthly vulnerability reporting and Plan of Action and Milestones (POA\&M) updates; annual 3PAO assessmentMonthly vulnerability reporting and POA\&M updates; annual 3PAO assessment

Core confirms foundational implementation and formal PMO validation. Ready is a 12-month status based on an independent 3PAO assessment of at least 80 NIST controls with PMO validation, the point where third-party assessment becomes mandatory. Authorized is full validated compliance at the applicable impact level, and it alone requires a government sponsor or Approvals Committee approval.

All three verified statuses are listed on the Authorized Product List; products still working toward a verified status appear separately on the Progressing Product List (PPL) under statuses such as Security Snapshot, Active, In Process, and Pending.

The Core control baseline defines what the PMO evaluates before awarding the entry-level verified status.

Sixty Prioritized NIST 800-53 Controls Form the GovRAMP Core Security Baseline

Core requires 60 security controls drawn from NIST SP 800-53 Rev5 at the Moderate Impact Level baseline. "Prioritized" has a specific meaning: the 60 were selected from the broader Moderate baseline based on the MITRE ATT\&CK Framework, so the set concentrates on controls aligned to known attacker techniques. The authoritative list is the GovRAMP Core Controls workbook, published May 5, 2025, in the GovRAMP Document Library.

Every Core submission requires three plans, along with the completed SSP. The PMO reviews the package as documentation analysis, with no 3PAO engaged.

  • Configuration Management (CM). A Configuration Management Plan is required to document how the provider baselines and tracks the scoped system's configuration.  
  • Incident Response (IR). An Incident Response Plan evidences the detection, reporting, and handling procedures the provider will follow. It is filed as part of the same documentation package the PMO reviews.  
  • Contingency Planning (CP). A Contingency Plan is required for every Core submission and covers how the provider restores service and data after a disruption.  
  • Supporting evidence beyond the named families. Core submissions also require vulnerability scanning evidence and the completed System Security Plan, which documents the system as scoped for verification. Evidence submission to the PMO separates Core from self-attestation; the completed SSP is one example of acceptable documentation.

Providers submit that evidence through a six-step PMO process.

Six Steps Take a CSP from GovRAMP Membership to APL Listing

The path from first membership payment to APL listing runs through six stages administered by GovRAMP and its PMO. The PMO contractor, RAMPQuest, supports the PMO site.

1. Become a GovRAMP Member

All providers must be active GovRAMP Members before participating in the Security Program. Providers under $1M pay $500 in annual dues. Dues rise to $1,000 for revenue from $1M to $5M and $1,500 above $5M. Membership renews each June 1.

2. Implement the 60 Required Controls

Collect and organize evidence for every Core control. GovRAMP describes a documentation package that providers prepare for review. The Progressing Security Snapshot Program helps providers build readiness before a full submission.

3. Prepare and Submit Documentation to the PMO

Complete the standardized documentation templates aligned to the Moderate Impact Level baseline. Submit the three plans listed above and the completed SSP. Submission goes to the GovRAMP PMO through a Service Request Form.

4. Pay the Annual PMO Assessment Fee

Pay the assessment fee to RAMPQuest with the documentation submission. Per the Core page, fees are $9,000 for revenue under $1M, $11,000 for $1M to $5M, and $17,000 above $5M. GovRAMP's pricing page lists higher annual totals of up to $21,000; the official pages do not explicitly reconcile the difference.

5. Complete the PMO Review

The PMO conducts the assessment directly. In GovRAMP's words, "The review includes documentation analysis, scan result validation, and overall program posture evaluation; no 3PAO assessment is required."

6. Begin Quarterly Monitoring and Receive APL Listing

Upon successful validation, the product is awarded Core Verification and listed on the APL. Providers are enrolled in quarterly ConMon. Quarterly billing starts at $250 and rises to $500 for the middle revenue tier and $1,000 for the highest tier.

Federal buyers require a separate Federal Risk and Authorization Management Program (FedRAMP) path.

GovRAMP Core and FedRAMP Serve Different Markets with Different Assessment Models

GovRAMP and FedRAMP serve different buyers. GovRAMP's public-sector security mission serves state, local, tribal, and education governments, while FedRAMP, run by the General Services Administration (GSA) and the Office of Management and Budget (OMB), governs cloud services sold to federal agencies.

FedRAMP's Consolidated Rules for 2026, released June 24, 2026, with mandatory adoption on January 1, 2027, replaced the Low/Moderate/High impact levels with four certification classes and made FedRAMP 20x, which drops the agency-sponsorship requirement, the primary path. Both programs build on NIST SP 800-53.

Providers selling to federal agencies need an Authority to Operate (ATO) through a separate authorization path distinct from GovRAMP's PMO-validated ladder.

DimensionGovRAMP CoreFedRAMP
Governing bodyGovRAMP, a 501(c)(6) nonprofit, with RAMPQuest as contracted PMOGSA and OMB
Market servedState and local governmentsU.S. federal agencies
Assessment modelPMO-direct documentation review; no 3PAO20x: providers work directly with FedRAMP using Key Security Indicators and independent assessors; legacy Rev5 path uses an independent assessor plus an agency ATO
Sponsorship requirementNone statedNone under 20x; agency sponsorship on the legacy Rev5 path
Control frameworkNIST SP 800-53 Rev5, Moderate baseline, mapped to MITRE ATT\&CKNIST SP 800-53 baselines; 20x uses Key Security Indicators aligned to certification classes
Controls at entry level60Not stated as a numbered control count; 20x uses Key Security Indicators rather than a traditional control list

Selling into both markets means meeting GovRAMP requirements and FedRAMP requirements, though FedRAMP recognizes GovRAMP as an approved alternative security framework under its Class A rules.

For GovRAMP Core, maintaining that market-specific status then depends on annual renewal and quarterly monitoring.

GovRAMP Core Verification Is Valid for Twelve Months and Requires ConMon

Core Verification is a 12-month PMO-validated assessment. Per GovRAMP's Security Assessment Framework, the status "is valid for 12 months and may be extended for an additional 12 months by undergoing an annual assessment prior to the status expiration," with no limit on the number of extensions.

Between renewals, providers submit four quarterly ConMon deliverables:

Penetration tests are optional at the Core level. Providers must remediate critical findings within 30 days. These submissions keep the listing current between annual assessments. That is what "Show Verified Progress" means for buyers reviewing the APL: a Core listing is an entry-level milestone covering 60 NIST SP 800-53 Rev5 controls that the PMO validates directly, without a 3PAO; Ready is the 3PAO-backed step toward full authorization.

Whether that recurring burden is worthwhile depends on whether Core clears the procurement gates in the state and local markets the provider is targeting.

Sequencing GovRAMP and Core Narrows the Scope of What Providers Must Prove

GovRAMP is the umbrella program; Core is its entry-level verified status. Choosing Core first, rather than jumping straight to Ready or Authorized, narrows the initial scope of work: 60 prioritized controls instead of 80 or the full Moderate baseline, PMO documentation review instead of a 3PAO engagement, and quarterly ConMon instead of monthly reporting. That sequencing lets providers stand up an APL listing early, then expand the same evidence base as procurement demands change.

The scope decision also depends on the boundary a provider defines. An inherited boundary, where the underlying platform already carries verified controls, shrinks what the CSP itself must implement, document, and monitor. Core evidence assembled on top of an inherited boundary reuses platform-level controls rather than rebuilding them, shortening the runway to APL listing and reducing the ongoing ConMon burden.

Since April 2026, North Carolina has accepted only GovRAMP or FedRAMP Rev5 from executive-agency cloud providers, with a one-year on-ramp to April 1, 2027, while Arizona allows Core for certain data categories within 12 months of contract execution. State acceptance of Core therefore does not settle whether a provider also needs federal authorization.

Moving on GovRAMP Core and FedRAMP in Parallel Reduces Scope

GovRAMP Core clears a growing set of state and local procurement gates at a fraction of the cost and effort of full authorization, but it does not substitute for federal authorization when the pipeline includes agency buyers. Providers who scope both programs together avoid rebuilding evidence twice.

Knox Systems delivers FedRAMP-as-a-Service on a pre-authorized FedRAMP boundary. The company handles the full authorization process in approximately 90 days at roughly 90% less cost than traditional paths, letting teams reuse the same control evidence across programs.

Federal deadlines run on their own calendar. Book a meeting to scope your plan.

FAQs about GovRAMP Core

What Is GovRAMP and What Is Its Purpose?

GovRAMP is the operating name of StateRAMP Inc. It enables participating governments to reuse an existing product verification instead of commissioning a separate security assessment for each procurement.

What Products Are Approved by GovRAMP?

Only products listed on the Authorized Product List hold a verified GovRAMP status. Approval applies to the named product and does not automatically extend to every offering from the same provider.

How Much Does It Cost to Get GovRAMP Core Status?

Published costs include $500 to $1,500 in annual dues, a $9,000 to $17,000 PMO assessment fee, and $250 to $1,000 in quarterly monitoring charges. Internal control implementation and evidence-preparation costs are additional.

What Are the Key Differences Between FedRAMP and GovRAMP?

GovRAMP serves state, local, tribal, and education buyers, while FedRAMP governs cloud services sold to federal agencies. Providers selling into both markets may need to satisfy each program's requirements separately.

Do I Need a 3PAO to Achieve GovRAMP Core?

No. The PMO reviews GovRAMP Core directly; a 3PAO is needed for a 3PAO-backed tier such as Ready.