What Is TX-RAMP? Texas State Authorization Explained

Written by: 
Team Knox
Published on: 
August 3, 2026

Texas Government Code § 2054.0593 prohibits state agencies from entering or renewing contracts for cloud computing services that do not comply with the Texas Risk and Authorization Management Program (TX-RAMP).

The rule has applied to confidential system contracts since January 1, 2022, and to low-impact system contracts since January 1, 2024. A SaaS vendor without TX-RAMP certification cannot win or renew a covered Texas contract, regardless of product strength or agency relationships.

Texas state government procurement and higher education system contracts fall under the same TX-RAMP mandate. TX-RAMP establishes a contract gate for Texas state and higher-education cloud purchases, with separate certification levels and reciprocity considerations for the federal authorization strategy.

Key Takeaways

  • TX-RAMP governs contracts. The Texas Department of Information Resources (DIR) administers the TX-RAMP program under Texas Government Code § 2054.0593, and state agencies cannot sign or renew cloud contracts without it.  
  • Two levels apply. TX-RAMP certification levels apply based on data sensitivity: Level 1 covers low-impact, nonconfidential systems with 117 controls; Level 2 covers confidential and moderate- or high-impact systems with 223 controls.  
  • Higher education counts. State agencies, universities, and community colleges are covered. Local government entities are not covered purchasers, so the mandate applies to vendors selling into state and higher education contracts.  
  • Reciprocity is one-way. Federal Risk and Authorization Management Program (FedRAMP) Moderate maps to TX-RAMP Level 2 under the FedRAMP reciprocity rules, whereas a state certification does not establish reciprocity for federal authorization. Certification timing affects when agencies can sign, which baseline applies, and whether federal authorization should come first.

TX-RAMP Standardizes Cloud Security Review For Texas State Agencies

TX-RAMP was created by Senate Bill 475 during the 87th Legislative Session and codified at Texas Government Code § 2054.0593. The Texas Department of Information Resources (DIR) administers the TX-RAMP program, which provides a standardized approach to security assessment, certification, and continuous monitoring of cloud computing services that process data for Texas state agencies.

The program covers the SaaS, Infrastructure as a Service (IaaS), and Platform as a Service (PaaS) offerings defined by the National Institute of Standards and Technology (NIST) Special Publication 800-145; products that do not meet that definition of cloud computing fall outside its scope.

The statute imposes two obligations on the parties to any covered contract:

  • Agencies may contract only for TX-RAMP-compliant cloud services.  
  • Vendors must maintain certification for the duration of the contract term.

Those obligations are operationalized through DIR's program documentation and portal workflow. DIR governs the program through the TX-RAMP Program Manual 4.0, effective February 12, 2026. DIR has certified over 2,000 cloud services to date and publishes a list of certified products updated weekly.

Because DIR requires a complete submission before review, vendors need the assessment sequence to estimate the required work and likely timing.

TX-RAMP Certification Follows Three Required Steps

The path from initial submission to a live listing on the certified products page runs through three sequential stages, each with its own artifacts and DIR checkpoints.

1. Assessment Request and Provisional Certification

The cloud service developer submits a DIR assessment request and then completes the Acknowledgment and Inventory (A\&I) Questionnaire, which covers Texas security requirements and the documentation inventory. Approval grants Provisional Certification, which lets agencies contract with the vendor while full certification is in progress. Under Program Manual 4.0, provisional status lasts 12 months.

2. Certification Submission

Vendors complete the full assessment through DIR's SPECTRIM portal and submit the required assessment documents for the security plan (control implementation workbook), along with authorization-boundary and data-flow documentation. Program Manual 4.0 recognizes a TX-RAMP-conducted assessment or reciprocity through an existing GovRAMP or FedRAMP authorization. It also recognizes a Fast Track assessment that reuses a qualifying SOC 2 Type II, PCI DSS, or HITRUST report.

3. DIR Review and Public Listing

DIR reviews submissions in the order received and does not review incomplete packages. DIR says it aims to complete the review and issue a recommendation within four weeks when vendors submit quality documentation and respond on time. Approved services appear on the certified products list, and certification remains valid for three years.

Certification does not end the work. Under the continuous monitoring schedule, Level 2 vendors submit vulnerability questionnaires to DIR quarterly; Level 1 vendors submit them annually. Services certified through FedRAMP or GovRAMP reciprocity are exempt from submitting continuous monitoring artifacts directly to DIR.

Certification level controls both the monitoring cadence and the assessment baseline.

TX-RAMP Certification Levels Set Assessment Scope

The contracting state agency determines which level a given cloud service requires, and each independent cloud service needs its own certification. Two baselines apply, distinguished by data sensitivity, control count, and the depth of evidence DIR expects.

Level 1 (Low Impact Baseline)

Level 1 is required for services handling nonconfidential data or low-impact information resources, where a loss of confidentiality, integrity, or availability would cause a limited adverse effect. The baseline contains 117 controls drawn from the NIST SP 800-53 Rev5 (September 2020), with additional FedRAMP and StateRAMP parameters.

Level 1 is questionnaire-based, and DIR does not mandate a Third-Party Assessment Organization (3PAO) engagement for it.

Level 2 (Moderate or High Impact Baseline)

Level 2 is required for services handling confidential data and moderate- or high-impact information resources. The baseline contains 223 controls built on NIST SP 800-53 Rev5, plus Texas-specific additions such as data residency and incident reporting to Texas state entities. Level 2 can take months depending on documentation readiness, assessment scope, remediation needs, and vendor responsiveness during assessment.

Because agencies determine the required level, vendors need that decision before estimating assessment scope and contract timing. The buyer sits on the other side of the contract, and in turn, decides whether the mandate applies at all.

Covered Texas Buyers Determine Vendor Certification Requirements

For vendors, TX-RAMP applicability depends on whether the buyer is a covered Texas state or higher education entity and whether the cloud service handles government data. Three buyer categories set the compliance line.

Vendors Selling To Texas State Agencies

Any cloud service that stores, processes, or transmits agency data under a contract entered into or renewed on or after January 1, 2022, requires certification. Contract renewal dates are compliance deadlines. Existing contracts are grandfathered until renewal, so renewal sets the compliance deadline.

Vendors Selling To Public Higher Education

University systems and institutions of higher education, as defined in Education Code § 61.003, along with public community colleges, are covered entities. A SaaS company selling a learning platform or research tool into the University of Texas system faces the same mandate as one selling to a state commission.

Vendors Selling Only To Local Government

Cities, counties, and school districts are not listed in DIR documentation as covered entities. TX-RAMP is not required for those contracts, though local buyers may still reference the certified products list in their own procurement decisions.

Buyer eligibility is only half of the scope question. Even for covered purchasers, specific service categories fall outside the program regardless of who is buying.

Specific Cloud Services Fall Outside TX-RAMP Scope

Several service categories are exempt from TX-RAMP requirements, either by definition or by explicit DIR carve-out. Three exclusions shape the compliance analysis.

  • Non-cloud products: Products that do not meet the NIST 800-145 cloud definition fall outside the program entirely, since TX-RAMP scope tracks that federal definition of cloud computing.  
  • Negligible confidential data: Low-impact services that process only a negligible quantity and/or quality of confidential data are excluded. A state agency is responsible for determining whether the quantity and/or quality of confidential data is negligible.  
  • DIR-excluded categories: DIR has directly excluded notification distribution services and certain other categories, including social media platforms and graphic design products.

Those exclusions narrow the scope of compliance analysis, but the buyer-specific scope still governs the certification plan on a contract-by-contract basis. Vendors selling across multiple states face distinct authorization requirements and reciprocity mechanisms that extend well beyond Texas.

State-Level Authorization Multiplies The Compliance Burden

TX-RAMP is one program in one state. The GovRAMP program, formerly known as StateRAMP, lists participating government organizations across multiple states, and the mandate footprint is hardening as several states move toward GovRAMP-aligned requirements. Texas operates TX-RAMP as a separate state-specific program from GovRAMP/StateRAMP, with vendors submitting a separate certification request through ARCHER.

Even reciprocity carries administrative weight. FedRAMP- and StateRAMP-certified products became ineligible for automatic TX-RAMP listing on October 30, 2024; vendors must file a reciprocity request through SPECTRIM and wait for DIR validation. GovRAMP's own procurement guide concedes the structural problem: "If each engagement involves a different set of compliance requirements, it simply would not be possible to provide the product at a competitive value."

Under DIR reciprocity, FedRAMP Low maps to TX-RAMP Level 1, while FedRAMP Moderate or High maps to Level 2. TX-RAMP Level 2 contains 223 controls.

Which federal baseline you pursue depends on your federal targets, not on Texas. The reverse path does not exist. FedRAMP states its external framework process "does NOT establish reciprocity with any external framework," so a vendor holding only GovRAMP or TX-RAMP certification starts federal authorization without reciprocity credit. State credentials earned first apply to the narrower asset.

A vendor can reduce duplicated state work by sequencing federal authorization before state-specific certifications.

Federal Authorization Extends Beyond Any Single State Requirement

Sequencing determines how much assessment work can be reused. FedRAMP Moderate satisfies TX-RAMP Level 2 through DIR reciprocity, supports GovRAMP Fast Track without a new 3PAO assessment, and enables government-wide federal reuse when a service is listed on the FedRAMP Marketplace.

Traditional federal authorization demands 12 to 36 months and over $3.5 million. But what if you didn’t have to build everything from scratch? A pre-authorized boundary model compresses both timing and costs.

Pre-Authorized Federal Boundaries Anchor Multi-State Eligibility

Vendors with both federal and multi-state revenue on the roadmap reduce duplicate assessment work by earning the larger credential first.

Knox Systems is a FedRAMP-as-a-Service platform that enables SaaS companies to achieve federal authorization in approximately 90 days at roughly 90% lower cost by inheriting 60% to 80% of controls from a pre-authorized government cloud platform. Automated continuous monitoring then maintains the artifacts ConMon and state reciprocity depend on.

Texas contract renewals set compliance deadlines. Book a meeting to map your fastest path.

FAQs about TX-RAMP

Who will administer TX-RAMP after Texas DIR?

House Bill 150 transfers DIR's cybersecurity functions, including TX-RAMP and SPECTRIM administration, to the new Texas Cyber Command, with the transfer targeted for December 31, 2026. DIR continues performing these duties until a memorandum between the two entities sets the formal transfer date, so vendors in the pipeline should watch for portal and submission changes.

Does DIR charge fees for TX-RAMP certification?

No. The program is state-funded, and DIR charges no program fees. Vendor costs come from preparation, third-party assessment, documentation, and remediation work.

What should vendors track during provisional certification?

Track the 12-month provisional window against full submission readiness. The useful checkpoint is whether the control workbook, authorization boundary, and data-flow documentation are complete early enough for DIR to review a full package before provisional status lapses.

What evidence supports a TX-RAMP reciprocity submission?

Program Manual 4.0 recognizes GovRAMP or FedRAMP authorization and Fast Track assessments when supported by a qualifying SOC 2 Type II, PCI DSS, or HITRUST report. Vendors still file through SPECTRIM for DIR validation rather than relying on automatic listing.