Skip to main content

State Requirements

GovRAMP (formerly StateRAMP)

GovRAMP is a standardized cybersecurity authorization program that helps state, local, tribal, and education (SLED) governments verify that a cloud service provider meets a NIST SP 800-53–based set of security controls — much like FedRAMP does at the federal level.

What it is

GovRAMP provides a common framework and a published authorization status for cloud products sold to participating governments. An assessor evaluates a provider once against the program's control baseline (Low, Moderate, or High impact), and the provider can then present that single authorization to many state and local buyers, instead of repeating a separate security review for each contract.

Who needs it

Cloud service providers (SaaS, PaaS, IaaS) that want to sell to participating state and local agencies. A growing number of jurisdictions either require or strongly prefer a GovRAMP authorization (or an equivalent like FedRAMP) before a cloud product can touch government data.

How it compares to FedRAMP

Both build on NIST SP 800-53 control baselines and use independent assessors. FedRAMP governs federal agency cloud use, and the federal government runs it; GovRAMP serves the SLED market, and a non-profit runs it. Many providers pursue FedRAMP first and use a "reciprocity" path to satisfy GovRAMP, since the underlying controls overlap heavily.

The impact levels

GovRAMP issues authorizations at Low, Moderate, or High impact, mirroring the data sensitivity tiers used by FedRAMP. The type of government data the cloud product will store or process drives the required level.