FRAMEWORKS & CERTIFICATIONS
What Is GovRAMP?
DEFINITION
GovRAMP, formerly StateRAMP, is a nonprofit program that verifies the cloud security of providers selling to state and local governments and educational institutions. Rebranded from StateRAMP in February 2025, it uses security requirements based on NIST SP 800-53 with independent assessments, modeled on FedRAMP, and a growing number of state and local procurement offices recognize or require its verified statuses.
GovRAMP fills the gap FedRAMP leaves below the federal level. State agencies, cities, counties, and school systems buy cloud services too, but most lack the resources to assess vendor security themselves. GovRAMP provides a shared verification model: providers are assessed by accredited third-party assessment organizations against NIST SP 800-53 based requirements, and their verified status is published for participating governments to rely on. The organization operated as StateRAMP from its founding until the rebrand to GovRAMP in February 2025, which reflected a scope covering all non-federal public sector buyers, including local government and education.
Procurement offices in participating states are the ones who ask for it, increasingly by writing GovRAMP status requirements directly into solicitations. Providers that already hold FedRAMP authorization can typically reuse much of that work, since the underlying control baselines are closely aligned.
For a mid-market SaaS company targeting the state, local, and education market, GovRAMP is usually the realistic entry point: it is meaningfully lighter than a full FedRAMP authorization while still demonstrating 800-53 based security to public sector buyers. Z Cyber's compliance services support providers working toward verified status.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →