GovRAMP — the program formerly known as StateRAMP — brings a FedRAMP-style security assessment model to state, local, and education (SLED) government and the vendors that serve them. The 2025 rebrand to GovRAMP reflects a broader mission to unite public-sector buyers and private-sector providers around a common security standard.

What GovRAMP is

Like FedRAMP, GovRAMP is built on NIST SP 800-53 and uses independent assessment plus continuous monitoring. Providers earn a verified status — commonly Ready, Authorized, or Provisional — and appear on GovRAMP’s Authorized and Progressing Product Lists, where government buyers can find vetted vendors.

How it compares to FedRAMP

  • Audience. FedRAMP serves federal agencies; GovRAMP serves state, local, and education government.
  • Shared backbone. Both rest on NIST 800-53, so the underlying control work is largely transferable.
  • Reuse. Because the frameworks align, a provider that has invested in one is well-positioned for the other, though each has its own authorization process.
If you previously tracked this program as StateRAMP, update your references and links to GovRAMP (govramp.org). The underlying model carried over, but the brand and some processes have evolved — confirm current requirements before you plan.

Who needs it

Cloud and managed-service providers selling to state and local agencies increasingly find GovRAMP status expected in procurement. Getting listed signals that your security posture has been independently verified, shortening the trust-building cycle with public-sector buyers.

How to start

Identify your target impact level, engage an accredited assessor, document your controls, and pursue a Ready or Authorized status. Many providers pursue GovRAMP and FedRAMP together to cover the full public-sector market.