Authorization program · Last verified
GovRAMP
GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025. It grants Core, Ready, Provisionally Authorized and Authorized statuses, published on its Authorized Product List, with monthly continuous monitoring after award.
- Class
- Authorization program
- Owner
- StateRAMP, a 501(c)(6) nonprofit organization, operating as (dba) GovRAMP
- Public register
- Verified working
- Last verified
What it is
GovRAMP is a membership programme, not a government agency. It describes itself as "a nonprofit membership organization that brings governments and technology providers together to improve cybersecurity, protect public data, and enable trusted technology adoption," working "Through a standardized, NIST-aligned framework" that "helps service providers demonstrate security and enables governments to make informed, risk-based decisions."
The programme grants verification statuses rather than certificates, and it publishes them: "Verified offerings with a security status of Core, Ready, Provisionally Authorized, or Authorized are listed below on the Authorized Product List (APL)." A status is not a one-off event — "Continuous Monitoring (ConMon) begins immediately upon the award of a verified security status," under which "providers must: Submit monthly and quarterly security reports to the PMO, Conduct annual assessments with an approved 3PAO, and Remediate Plan of Action and Milestones (POA&M) items according to prescribed timelines."
Who owns it
The programme is run by a 501(c)(6) nonprofit. It rebranded on 14 February 2025: "StateRAMP, a 501(c)(6) nonprofit organization dedicated to advancing cybersecurity in the public sector, today announced its transition to GovRAMP," and "As part of this transition, StateRAMP will legally remain the organization's name but will operate as (dba) GovRAMP." The stated reach is "all levels of government, including state, local, tribal, and educational institutions."
Who assesses it
Assessment differs by status. For Core, "Core assessments are conducted directly by the GovRAMP PMO." For the higher statuses, "Authorized Verification requires an independent assessment conducted by a GovRAMP-approved Third-Party Assessment Organization (3PAO)," and providers "Work with an approved Third-Party Assessment Organization to conduct a Readiness Assessment Report (RAR) or Security Assessment Report (SAR)."
Verification statuses
- Core —
Core Verification confirms the implementation of foundational security controls—providing a clear, credible signal of your security maturity without requiring a full third-party assessment. Core Verification validates the implementation of 60 foundational controls aligned to NIST SP 800-53 Rev. 5 and the Moderate Impact Level baseline.
- Ready —
Ready Verification confirms that your product meets GovRAMP's minimum mandatory requirements through an independent third-party assessment.
- Provisionally Authorized —
Authorized requirements fully met and validated. Relies on interconnected technology not yet GovRAMP or FedRAMP verified. May include limited items tracked through a Plan of Action and Milestones (POA&M). Eligible to transition to Authorized once dependencies are resolved.
- Authorized —
All requirements fully met and validated. Complete alignment with GovRAMP standards. No outstanding dependencies. Demonstrates the highest level of verified security.
Sources
- GovRAMP — about (program owner) ↗ — accessed
- GovRAMP — StateRAMP announces rebrand to GovRAMP (14 February 2025) ↗ — accessed
- GovRAMP — Core Verification ↗ — accessed
- GovRAMP — Ready Verification ↗ — accessed
- GovRAMP — Authorized / Provisional Verification ↗ — accessed
- GovRAMP — FAQs (Continuous Monitoring obligations) ↗ — accessed
- GovRAMP — Authorized Product List ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.