Authorization program · Last verified
Texas Risk and Authorization Management Program
TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification. Texas Government Code §2063.408 requires every state agency, including universities, to contract only with vendors that comply, at Level 1 or Level 2 depending on data sensitivity, with no mandatory third-party assessor.
- Class
- Authorization program
- Owner
- Texas Cyber Command (vendor evaluation) and the Texas Department of Information Resources — DIR (certification issuance)
- Last verified
What it is
TX-RAMP was created by Texas Government Code §2054.0593(b): "The department shall establish a state risk and authorization management program to provide a standardized approach for security assessment, authorization, and continuous monitoring of cloud computing services that process the data of a state agency." Effective 1 September 2025, the statute's own history note records that this provision was "Transferred, redesignated and amended from Government Code, Section 2054.0593 by Acts 2025, 89th Leg., R.S., Ch. 331 (H.B. 150), Sec. 16, eff. September 1, 2025," and it now lives as Tex. Gov't Code §2063.408, inside the newly created Chapter 2063, "Texas Cyber Command." The original enacting law is unchanged by that move: the same history note also confirms the provision was "Added by Acts 2021, 87th Leg., R.S., Ch. 567 (S.B. 475), Sec. 2, eff. June 14, 2021."
Compliance is a condition of doing business with the state, not a voluntary credential: §2063.408(e) states "A state agency may not enter or renew a contract with a vendor to purchase cloud computing services ... unless the vendor demonstrates compliance with program requirements."
Vendors are certified against one of two baselines, set out in 1 TAC §202.5: "TX-RAMP Level 1 Baseline — This baseline is required for cloud computing services that are subject to TX-RAMP certification and categorized by a state agency as Low Impact Information Resources," and "TX-RAMP Level 2 Baseline — This baseline is required for cloud computing services that are subject to TX-RAMP and categorized by a state agency as Moderate or High Impact Information Resources."
The statute itself builds in reciprocity with other government risk-authorization programmes: §2063.408(b)(1)-(2) lets a vendor demonstrate compliance by showing conformity with a risk and authorization management program "of: (1) the federal government; or (2) another state that the command approves."
Who owns it
The programme's operating role now sits with Texas Cyber Command: §2063.408(b) states "The command shall establish a state risk and authorization management program ..." Certification itself, however, is still issued by the Texas Department of Information Resources: §2063.408(d) directs that "The command shall evaluate vendors to determine whether a vendor qualifies for a certification issued by the department ..."
Who assesses it
DIR performs the assessments itself rather than delegating to an accredited third party. 1 TAC §202.5 states "The department shall perform assessments to certify cloud computing services provided by cloud computing vendors," and DIR's own published guidance confirms there is no mandatory outside auditor: "Achieving TX-RAMP (Texas Risk and Authorization Management Program) certification does not mandate the engagement of a Third-Party Assessment Organization (3PAO). The Texas Department of Information Resources (DIR) conducts assessments internally, eliminating the requirement for an external 3PAO."
TX-RAMP baselines
- TX-RAMP Level 1 Baseline —
This baseline is required for cloud computing services that are subject to TX-RAMP certification and categorized by a state agency as Low Impact Information Resources.
- TX-RAMP Level 2 Baseline —
This baseline is required for cloud computing services that are subject to TX-RAMP and categorized by a state agency as Moderate or High Impact Information Resources.
Who asks for it
Public procurement. Statutory scope is Texas state government: executive- and judicial-branch state agencies plus university systems and institutions of higher education (Tex. Gov't Code §2054.003(13)) — not a federal or nationwide U.S. requirement.
Texas state agencies are the ones legally required to ask for it before contracting: §2063.408(e) states "A state agency may not enter or renew a contract with a vendor to purchase cloud computing services ... unless the vendor demonstrates compliance with program requirements." That requirement reaches higher education too: Gov't Code §2054.003(13) defines "state agency" to include "a university system or institution of higher education as defined by Section 61.003, Education Code."
Sources
- Texas Statutes — Tex. Gov't Code §2063.408 (current law, opened directly) ↗ — accessed
- Texas DIR — TX-RAMP program page ↗ — accessed
- Texas Statutes — Tex. Gov't Code §2054.0593 (superseded 1 Sept 2025; kept for the enacting-law history note) ↗ — accessed
- Texas Statutes — Tex. Gov't Code §2054.003 ("state agency" definition) ↗ — accessed
- Cornell LII — 1 Texas Administrative Code §202.5 (TX-RAMP baselines and assessment) ↗ — accessed
- Texas DIR — TX-RAMP Program Manual 3.1 (PDF) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.