HomeFrameworksCloud & Government AuthorizationStateRAMP

Framework  Cloud & Government Authorization

StateRAMP

StateRAMP is a nonprofit program that lets cloud providers prove NIST SP 800-53 Revision 5 based security once and reuse that verification with many state, local, tribal and education government buyers.

In early 2025 the organization began operating as GovRAMP to reflect that whole-of-government scope; the legal entity remains StateRAMP and existing StateRAMP statuses carry over.

Products appear on a public Authorized Product List with one of four verified statuses: Core (60 foundational controls validated by the program office), Ready, Provisionally Authorized and Authorized, the last three requiring an independent 3PAO assessment.

A provider must document its system much as under FedRAMP: a system security plan, policies and procedures per control family, an incident response plan, a continuous monitoring plan, and a plan of action and milestones. Many participating governments write GovRAMP status into procurement rules, so the trigger is usually a state or local contract.

AI-compiled
Share
Sponsored
StateRAMP
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with StateRAMP
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Cloud service providers selling to participating state, local, tribal, territorial and education governments that require a GovRAMP status in procurement. Voluntary for everyone else.

What the assessor asks to see

Security Snapshot or readiness documentation; System Security Plan with control implementation statements; boundary and data flow diagrams; policies and procedures per control family; vulnerability scan results and POA&M; penetration test; incident response and contingency plans; continuous monitoring reports; any FedRAMP package being reused.

StateRAMP to GovRAMP

The program announced its GovRAMP name in February 2025 (verify the exact date on govramp.org). Authorizations issued under the StateRAMP name remain valid and are listed on the GovRAMP Authorized Product List. Reciprocity with FedRAMP is available, and TX-RAMP accepts GovRAMP status through a reciprocity request.

Assessors

Who assesses StateRAMP

A Third Party Assessment Organization (3PAO) accredited by A2LA and recognized by FedRAMP; the provider engages and pays the assessor. Core status is validated by the GovRAMP PMO without a 3PAO. Accredited by A2LA, with FedRAMP recognition of the 3PAO.

Public register of assessors: https://govramp.org/assessors/

A-LIGNOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
CoalfireOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
FortreumOn the public register
What they do
Assessor
Which standards
On the public register for FedRAMP, StateRAMP.
Standards
FedRAMPStateRAMP
Pricing
Not published
Prescient SecurityOn the public register
What they do
Assessor
Which standards
On the public register for FedRAMP, StateRAMP, HITRUST.
Standards
FedRAMPStateRAMPHITRUST
Pricing
Not published
SecuriseaOn the public register
What they do
Assessor
Which standards
On the public register for StateRAMP.
Standards
StateRAMP
Pricing
Not published

Consultants

Who helps with StateRAMP

Yes. FedRAMP advisory firms and GRC platforms offer GovRAMP readiness, SSP writing and continuous monitoring support. GovRAMP runs a Security Snapshot as an entry point and a 3PAO discount program with participating assessors.

Engagement length depends on impact level and FedRAMP reuse.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a StateRAMP consultant listing yet. Claim yours →

Software

Tools for StateRAMP

Tools that name this framework in their own material.

No firm has claimed a StateRAMP tool listing yet. Claim yours →

Related reading

  1. StateRAMP is now GovRAMP, reflecting broader participationTrade press account of the February 2025 rename and what it signals about who now uses the program.Government Technology
  2. StateRAMP rebrands to GovRAMP to reflect its growing cybersecurity missionExplains how the program works for state, local and education buyers, and why vendors pursue one reusable authorization.StateTech Magazine

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for StateRAMP

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with StateRAMP

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.