The GovRAMP program, known as StateRAMP until 2025, is a nonprofit program that verifies the security of cloud services sold to state and local governments, and increasingly to other public-sector bodies such as educational institutions. It is modeled on the federal FedRAMP program and uses requirements based on NIST security controls. StateRAMP remains the legal name of the organization, which operates as GovRAMP. Governments that participate can rely on one shared verification instead of each reviewing every provider from scratch. This entry is general information, not legal advice; confirm requirements with the government buyer and the program.
At a glance
- GovRAMP is a nonprofit, not a government agency; participating governments decide whether to require or accept its statuses.
- It offers progressing programs for providers still maturing and verified statuses (Core, Ready, Provisionally Authorized and Authorized) for those that pass review.
- Ready and the authorized statuses require an independent third-party assessment and program office validation, followed by monthly continuous monitoring; Core is validated by the program office.
- Status applies to a specific product or service, not to everything a provider sells.
- The name changed from StateRAMP in 2025, and both names still appear in RFPs and policies.
What problem it solves
State agencies, counties, cities and school systems buy many of the same cloud services, but each used to send its own security questionnaire and run its own review. Providers repeated the same work over and over, and smaller governments often lacked the staff to judge the answers.
GovRAMP gives them a common standard and a shared review. A provider is verified once, and participating governments can check its status instead of starting over. For buyers, it is a quicker way to see whether a provider’s security program has been independently checked.
How it works
Membership. Providers and governments join the program. Governments can adopt its statuses in their policies.
Choose an impact level. The provider’s package is based on the impact level its government customers need, typically Low, Moderate or High, depending on data sensitivity.
Assessment. Progressing programs and Core are run or validated by the program management office against a smaller set of controls; Ready and the authorized statuses require an approved third-party assessment organization (3PAO).
Approval. For the Provisionally Authorized and Authorized statuses, a government sponsor or the program’s approvals committee reviews the security package.
Continuous monitoring. Verified providers report quarterly (Core) or monthly (Ready and the authorized statuses), and the higher statuses are reassessed annually.
Reuse of federal work. Providers with FedRAMP materials can submit them for review, which can shorten the process.
Verification statuses
GovRAMP separates progressing programs, for providers still building toward verification, from verified statuses listed on its Authorized Product List. The summary below reflects the program’s published descriptions in general terms; offerings and requirements change, so confirm details with GovRAMP.
| Offering or status | Type | How it is validated | Monitoring and renewal | Typical evidence |
|---|---|---|---|---|
| Security Snapshot | Progressing | Program-run assessment of a core set of NIST-based controls | 12-month result | Snapshot score |
| Progressing Security Snapshot | Progressing | Same core controls, with program office review and advisory support | Quarterly updated scores; must show improvement to stay on the Progressing Product List | Listing on the Progressing Product List |
| Core | Verified | Program office validation of a foundational control set; no 3PAO | 12-month status with quarterly continuous monitoring | Core listing on the Authorized Product List |
| Ready | Verified | Independent 3PAO assessment plus program office validation | 12-month status with monthly continuous monitoring and an annual assessment | Ready listing on the Authorized Product List |
| Provisionally Authorized | Verified | Full 3PAO assessment, program office validation and sponsor or approvals committee review; relies on connected technology not yet verified, tracked in a plan of action | 12-month status with monthly continuous monitoring and an annual assessment | Provisional listing on the Authorized Product List |
| Authorized | Verified | Full 3PAO assessment, program office validation and sponsor or approvals committee review | 12-month status with monthly continuous monitoring and an annual assessment | Authorized listing on the Authorized Product List |
When it matters for buyers
- When a state or local RFP mentions StateRAMP or GovRAMP. It may be a requirement or a scoring factor.
- When you are a public-sector buyer. A listing can replace or shorten your own vendor review.
- When a provider claims government readiness. Check the status, impact level and exact product listed.
- When handling criminal justice data. GovRAMP status does not replace state CJIS requirements.
- When you also sell to federal agencies. FedRAMP and GovRAMP are separate, though work can be reused.
Our governance, risk and compliance overview covers advisors who help providers and buyers navigate these programs.
Questions to ask vendors
- Which GovRAMP status and impact level do you hold, and for which exact product?
- When was your last assessment, and are you current on continuous monitoring?
- Can our agency request access to your continuous monitoring information?
- Do you also hold FedRAMP status for the same service, and how do the boundaries compare?
- Which controls are your responsibility and which are ours?
- If the service will hold criminal justice information, how do you meet the CJIS Security Policy as well?
How it differs from FedRAMP
FedRAMP is a federal government program for cloud services used by federal agencies, operating under the federal security law FISMA. GovRAMP is a nonprofit program for state, local and other public-sector buyers, modeled on FedRAMP and using similar NIST-based controls. Status in one does not automatically carry over to the other, though GovRAMP can review FedRAMP materials and FedRAMP’s newer process can accept a recent GovRAMP status for its entry-level class. Neither replaces the CJIS Security Policy for criminal justice data, and a SOC 2 report or security questionnaire may still be requested alongside either.
