GovRAMP — the program formerly known as StateRAMP — brings a FedRAMP-style security assessment model to state, local, and education (SLED) government and the vendors that serve them. The 2025 rebrand to GovRAMP reflects a broader mission to unite public-sector buyers and private-sector providers around a common security standard.
What GovRAMP is
Like FedRAMP, GovRAMP is built on NIST SP 800-53 and uses independent assessment plus continuous monitoring. Providers earn a verified status — commonly Ready, Authorized, or Provisional — and appear on GovRAMP’s Authorized and Progressing Product Lists, where government buyers can find vetted vendors.
How it compares to FedRAMP
- Audience. FedRAMP serves federal agencies; GovRAMP serves state, local, and education government.
- Shared backbone. Both rest on NIST 800-53, so the underlying control work is largely transferable.
- Reuse. Because the frameworks align, a provider that has invested in one is well-positioned for the other, though each has its own authorization process.
Who needs it
Cloud and managed-service providers selling to state and local agencies increasingly find GovRAMP status expected in procurement. Getting listed signals that your security posture has been independently verified, shortening the trust-building cycle with public-sector buyers.
How to start
Identify your target impact level, engage an accredited assessor, document your controls, and pursue a Ready or Authorized status. Many providers pursue GovRAMP and FedRAMP together to cover the full public-sector market.