TX-RAMP vs. FedRAMP: Key Differences Explained
Texas Government Code § 2054.0593 prohibits Texas state agencies from entering or renewing a cloud computing contract unless the vendor demonstrates compliance with the Texas Risk and Authorization Management Program (TX-RAMP). At the federal level, the Federal Risk and Authorization Management Program (FedRAMP) is the equivalent federal gatekeeping program for agencies buying cloud services within its scope that handle unclassified federal information.
The names are similar, both programs build on the National Institute of Standards and Technology (NIST) SP 800-53 Rev5 (September 2020), and both operate as contract gates tied to required controls.
That surface similarity can complicate sequencing: SaaS vendors may assume one certification carries into the other market, budget accordingly, and then have to fund a second authorization path during procurement. The sequencing choice depends on scope, control baselines, reciprocity, cost, and whether state or federal buyers come first.
Key Takeaways
- Different buyers. TX-RAMP governs Texas state contracts; FedRAMP governs federal ones. TX-RAMP is mandated by Texas Government Code § 2054.0593, while FedRAMP is codified by the FedRAMP Authorization Act.
- Different baselines. Under the TX-RAMP Program Manual, TX-RAMP Level 2 requires 223 controls reviewed internally by the state; the FedRAMP Rev5 baselines require 323 controls at Moderate assessed by an independent third party.
- One-way reciprocity. FedRAMP authorization can satisfy TX-RAMP through a formal request; FedRAMP authorization paths do not identify TX-RAMP certification as a reciprocity path.
- Federal sequencing. FedRAMP authorization can satisfy TX-RAMP, but TX-RAMP certification is not listed as a federal reciprocity path. Vendors with both state and federal pipeline generally get more value from sequencing FedRAMP first and carrying it down.
TX-RAMP Is Texas's Mandatory Cloud Security Certification Program
The Texas Risk and Authorization Management Program (TX-RAMP) is a state-run cloud security certification program administered by the Texas Department of Information Resources (DIR). Established under Texas Government Code § 2054.0593, TX-RAMP provides a standardized approach to security assessment, certification, and continuous monitoring of cloud computing services that process data from Texas state agencies and public higher education institutions.
DIR conducts the assessments internally through the Statewide Portal for Enterprise Cybersecurity Threat, Risk, and Incident Management (SPECTRIM) portal, charges no program fee, and issues certifications at two levels based on the sensitivity of the data being handled: Level 1 for low-impact information and Level 2 for moderate- and high-impact information.
Certification is valid for three years, and any cloud service sold to a covered Texas entity must hold an active TX-RAMP certification (or an approved reciprocity credential) before a contract can be signed or renewed. The federal equivalent operates under a different statute and assessment model.
FedRAMP Authorizes Cloud Services For The U.S. Federal Government
FedRAMP is the U.S. federal government's standardized program for authorizing and continuously monitoring cloud services used by federal agencies. Originally launched in 2011 and codified in statute by the FedRAMP Authorization Act (December 2022), it applies to cloud services that collect, process, store, or transmit unclassified federal information.
Authorizations are issued at four baselines: Low-Impact SaaS (LI-SaaS), Low, Moderate, and High, with controls drawn from NIST SP 800-53 Rev5. Every FedRAMP authorization requires:
- A full System Security Plan (SSP)
- An independent Third-Party Assessment Organization (3PAO) assessment
- Ongoing Continuous Monitoring (ConMon), including monthly vulnerability scans, updated Plans of Action and Milestones (POA&Ms), and an annual 3PAO assessment.
Once granted, a FedRAMP authorization can be reused across federal agencies, making it a "do once, use many times" credential for cloud service providers selling into the federal market. Placed next to TX-RAMP, that reuse model exposes a broader split in how each program governs cloud security.
TX-RAMP And FedRAMP Share A Common Foundation
Before the differences take over, it helps to see where the two programs actually line up:
- Government-run contract gates. Both are government-run cloud security programs that act as contract gates: no certification, no procurement.
- Same NIST control catalog. Both draw their control catalog from NIST SP 800-53 Rev5, so the underlying security vocabulary, control families, and evidence expectations are the same regardless of which program a vendor targets first.
- Tiered baselines tied to data sensitivity. TX-RAMP uses Level 1 and Level 2; FedRAMP uses LI-SaaS, Low, Moderate, and High.
- Continuous monitoring, not one-time audits. Both programs require ongoing evidence rather than a point-in-time assessment.
- Product-scoped certification. Certification attaches to a specific cloud service, not to the vendor as a whole.
- Reusable artifacts. Any policies, SSP components, or evidence a vendor builds for one program are, at a minimum, reusable inputs for the other.
That shared NIST lineage is why reciprocity is even possible in the first place. But the two programs diverge sharply on who assesses, how often, and for which buyer, and those operational choices are what actually determine cost, timeline, and market access.
TX-RAMP And FedRAMP Differ Across Four Dimensions
The jurisdictional split between Texas and the federal government drives concrete differences in what each program asks of a vendor. Buyer scope, baseline rigor, reciprocity rules, and operating burden each affect budget and timeline in different ways.
- Scope. TX-RAMP covers Texas state agencies, higher education institutions, and public community colleges under Texas Government Code § 2054.0593. FedRAMP covers federal agencies handling unclassified federal information.
- Control baseline rigor. TX-RAMP Level 1 requires 117 controls, and Level 2 requires 223; both are reviewed internally by DIR. FedRAMP requires 156 controls at LI-SaaS and Low, 323 at Moderate, and 410 at High, all assessed by an independent 3PAO against a full System Security Plan (SSP).
- Reciprocity and reuse. FedRAMP Moderate or High maps to TX-RAMP Level 2 by formal request to DIR, and GovRAMP (formerly StateRAMP) maps similarly. The same one-directional logic runs through the broader StateRAMP vs. FedRAMP relationship.
- Timeline and cost. TX-RAMP has no program fee, and the assessment takes up to four weeks, assuming all documentation is correct. Traditional FedRAMP authorization can cost upwards of $3.5 million and take 12 to 36 months.
Those four dimensions turn sequencing into a market-access decision, and the at-a-glance view below makes the tradeoffs concrete.
TX-RAMP vs. FedRAMP At A Glance
The two programs share a NIST control lineage but diverge on nearly every operational dimension that affects a SaaS vendor's budget, timeline, and go-to-market plan. The table below summarizes the differences that matter most when choosing a sequencing strategy.
The higher control counts, independent assessment, and monthly monitoring cadence on the FedRAMP side already exceed what DIR requires, which is exactly why reciprocity runs downhill and not the other way around.
TX-RAMP Certification Leaves Federal Authorization Work
A TX-RAMP Level 2 vendor moving into FedRAMP inherits credit for shared NIST control lineage but still has to close a defined set of gaps before a federal package is complete:
- Controls gap. TX-RAMP Level 2 covers 223 controls; FedRAMP Moderate requires 323. The additional 100 controls must be implemented and documented.
- Assessment gap. DIR relied on an internal questionnaire review. FedRAMP requires an independent 3PAO assessment against a full SSP, with TX-RAMP-treated policies attached only as optional supporting evidence.
- ConMon gap. TX-RAMP Level 2 requires quarterly vulnerability reports and recertification every three years. FedRAMP requires monthly ConMon packages that include an updated POA&M, vulnerability scan results, inventory updates, and an annual 3PAO assessment per the FedRAMP annual assessment guidance.
- Operating model gap. A compliance team calibrated to TX-RAMP's cadence needs a different tempo for the Conmon monthly package.
- Scope gap. FedRAMP LI-SaaS, with the same 156-control count as Low, does not map to any TX-RAMP level, and a TX-RAMP certification obtained through FedRAMP reciprocity lapses if the FedRAMP authorization does. Certification is product-specific: TX-RAMP-certified infrastructure certifies only the infrastructure, not the SaaS layer built on top of it.
Those gaps shape which program a vendor should pursue first.
Vendor Type Determines Which Program Applies
A SaaS vendor whose government pipeline consists of Texas agencies and universities needs TX-RAMP, full stop. FedRAMP adds cost and assessment burden when federal agency demand is absent, and no Texas buyer requires that additional work.
A vendor with a realistic federal pipeline, or a prime contractor relationship that requires federal-grade compliance, should treat FedRAMP as the primary target. FedRAMP authorization satisfies TX-RAMP Level 2 by reciprocity, so the federal investment covers Texas as a byproduct. When both a state and a federal contract are realistic, doing FedRAMP first and carrying it down is usually the more efficient order.
Growth changes that calculus, because Texas eventually stops being the largest addressable market.
Companies Scaling Beyond Texas Eventually Need FedRAMP
Federal authorization can be reused across agencies, while TX-RAMP is limited to Texas procurement. Per the General Services Administration's (GSA) FY2027 Congressional Justification, by December 2025, 484 authorized cloud offerings had been reused more than 12,175 times across the federal government. One authorization, many agency customers.
The obstacle is cost and time. Traditional FedRAMP authorization can cost upwards of $3.5 million and take 12 to 36 months, which is often incompatible with a growth-stage company's runway and the timing of a federal opportunity.
A pre-authorized FedRAMP boundary change that math. When a SaaS vendor deploys into a boundary that already carries an existing FedRAMP authorization, the vendor inherits a large share of required controls on day one and skips the multi-year build. The federal credential arrives quickly enough to matter, and Texas reciprocity follows automatically.
FedRAMP Covers More Procurement Paths Than TX-RAMP
Reciprocity follows the more rigorous assessment. A vendor that builds once to the federal standard acquires a credential that unlocks Texas through TX-RAMP reciprocity, GovRAMP's participating states through its Fast Track pathway, and every federal agency through reuse. A vendor that builds to the state standard acquires a state credential.
Knox Systems is a FedRAMP-as-a-Service platform that lets SaaS vendors inherit up to 80% of required controls by deploying into a pre-authorized FedRAMP boundary. Knox's managed service starts at approximately $500,000 per application, roughly 90% less than the traditional $3.5 million path, and compresses timelines by roughly the same margin.
If federal revenue is part of your plan, book a meeting to get a concrete timeline for your application.
FAQs About TX-RAMP vs. FedRAMP
Does TX-RAMP require a 3PAO assessment?
No. Vendors should still prepare audit-ready evidence because DIR's SPECTRIM portal review depends on the completeness of the questionnaire package. Existing SOC 2 Type II, PCI DSS, or HITRUST evidence may support TX-RAMP's Fast Track Assessment process when it matches the service under review.
How long does TX-RAMP certification last?
Vendors should treat the three-year certification window as a contract-renewal constraint. Recertification can begin up to 12 months before expiration, which gives procurement and security teams time to avoid a lapse during renewal.
What should a GovRAMP-supported TX-RAMP request show?
The request should identify the authorization category, the exact cloud service under review, and the current authorization status DIR is being asked to recognize. Product scope matters because certification of the infrastructure does not automatically certify the SaaS layer built on top of it.
How may FedRAMP 20x change this comparison?
Potentially. The FedRAMP 20x approach replaces traditional documentation packages with automated Key Security Indicator validation, and the legacy Rev5 path stops accepting certifications on June 11, 2027. For Texas purposes, the important question is whether the result is a FedRAMP Authorized Low, Moderate, or High status eligible for reciprocity review.