What Is the GovRAMP Program?

Also called: GovRAMP, StateRAMP

Related problems: A state or city RFP asks for StateRAMP or GovRAMP status; Not sure whether a provider's GovRAMP status covers the service we'd buy; Selling cloud services to state and local government for the first time

The GovRAMP program, known as StateRAMP until 2025, is a nonprofit program that verifies the security of cloud services sold to state and local governments, and increasingly to other public-sector bodies such as educational institutions. It is modeled on the federal FedRAMP program and uses requirements based on NIST security controls. StateRAMP remains the legal name of the organization, which operates as GovRAMP. Governments that participate can rely on one shared verification instead of each reviewing every provider from scratch. This entry is general information, not legal advice; confirm requirements with the government buyer and the program.

At a glance

  • GovRAMP is a nonprofit, not a government agency; participating governments decide whether to require or accept its statuses.
  • It offers progressing programs for providers still maturing and verified statuses (Core, Ready, Provisionally Authorized and Authorized) for those that pass review.
  • Ready and the authorized statuses require an independent third-party assessment and program office validation, followed by monthly continuous monitoring; Core is validated by the program office.
  • Status applies to a specific product or service, not to everything a provider sells.
  • The name changed from StateRAMP in 2025, and both names still appear in RFPs and policies.

What problem it solves

State agencies, counties, cities and school systems buy many of the same cloud services, but each used to send its own security questionnaire and run its own review. Providers repeated the same work over and over, and smaller governments often lacked the staff to judge the answers.

GovRAMP gives them a common standard and a shared review. A provider is verified once, and participating governments can check its status instead of starting over. For buyers, it is a quicker way to see whether a provider’s security program has been independently checked.

How it works

Membership. Providers and governments join the program. Governments can adopt its statuses in their policies.

Choose an impact level. The provider’s package is based on the impact level its government customers need, typically Low, Moderate or High, depending on data sensitivity.

Assessment. Progressing programs and Core are run or validated by the program management office against a smaller set of controls; Ready and the authorized statuses require an approved third-party assessment organization (3PAO).

Approval. For the Provisionally Authorized and Authorized statuses, a government sponsor or the program’s approvals committee reviews the security package.

Continuous monitoring. Verified providers report quarterly (Core) or monthly (Ready and the authorized statuses), and the higher statuses are reassessed annually.

Reuse of federal work. Providers with FedRAMP materials can submit them for review, which can shorten the process.

Verification statuses

GovRAMP separates progressing programs, for providers still building toward verification, from verified statuses listed on its Authorized Product List. The summary below reflects the program’s published descriptions in general terms; offerings and requirements change, so confirm details with GovRAMP.

Offering or status Type How it is validated Monitoring and renewal Typical evidence
Security Snapshot Progressing Program-run assessment of a core set of NIST-based controls 12-month result Snapshot score
Progressing Security Snapshot Progressing Same core controls, with program office review and advisory support Quarterly updated scores; must show improvement to stay on the Progressing Product List Listing on the Progressing Product List
Core Verified Program office validation of a foundational control set; no 3PAO 12-month status with quarterly continuous monitoring Core listing on the Authorized Product List
Ready Verified Independent 3PAO assessment plus program office validation 12-month status with monthly continuous monitoring and an annual assessment Ready listing on the Authorized Product List
Provisionally Authorized Verified Full 3PAO assessment, program office validation and sponsor or approvals committee review; relies on connected technology not yet verified, tracked in a plan of action 12-month status with monthly continuous monitoring and an annual assessment Provisional listing on the Authorized Product List
Authorized Verified Full 3PAO assessment, program office validation and sponsor or approvals committee review 12-month status with monthly continuous monitoring and an annual assessment Authorized listing on the Authorized Product List

When it matters for buyers

  • When a state or local RFP mentions StateRAMP or GovRAMP. It may be a requirement or a scoring factor.
  • When you are a public-sector buyer. A listing can replace or shorten your own vendor review.
  • When a provider claims government readiness. Check the status, impact level and exact product listed.
  • When handling criminal justice data. GovRAMP status does not replace state CJIS requirements.
  • When you also sell to federal agencies. FedRAMP and GovRAMP are separate, though work can be reused.

Our governance, risk and compliance overview covers advisors who help providers and buyers navigate these programs.

Questions to ask vendors

  • Which GovRAMP status and impact level do you hold, and for which exact product?
  • When was your last assessment, and are you current on continuous monitoring?
  • Can our agency request access to your continuous monitoring information?
  • Do you also hold FedRAMP status for the same service, and how do the boundaries compare?
  • Which controls are your responsibility and which are ours?
  • If the service will hold criminal justice information, how do you meet the CJIS Security Policy as well?

How it differs from FedRAMP

FedRAMP is a federal government program for cloud services used by federal agencies, operating under the federal security law FISMA. GovRAMP is a nonprofit program for state, local and other public-sector buyers, modeled on FedRAMP and using similar NIST-based controls. Status in one does not automatically carry over to the other, though GovRAMP can review FedRAMP materials and FedRAMP’s newer process can accept a recent GovRAMP status for its entry-level class. Neither replaces the CJIS Security Policy for criminal justice data, and a SOC 2 report or security questionnaire may still be requested alongside either.

Frequently Asked Questions

Is GovRAMP the same as StateRAMP?
Yes. StateRAMP rebranded as GovRAMP in 2025 to reflect members beyond state government, such as local governments and educational institutions. StateRAMP remains the organization's legal name, and it operates as GovRAMP, so some state policies and RFPs still use the StateRAMP name.
Is GovRAMP a government agency?
No. It is a nonprofit membership organization. State and local governments choose whether to require or recognize its statuses in their policies and contracts.
Does FedRAMP status count for GovRAMP?
Not automatically. GovRAMP can review existing FedRAMP assessment materials, which can reduce time and cost, but the provider still needs a GovRAMP status. Check whether the government you sell to also accepts FedRAMP directly.
Is GovRAMP required in every state?
No. Adoption varies. Some states and localities require or prefer it, some run their own programs, and some have no specific requirement. Check the procurement rules of the government you are dealing with.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.