StateRAMP Authorization Services
StateRAMP provides standardized cybersecurity verification for cloud products used by state and local governments. Built on NIST SP 800-53, it offers a "verify once, use many" approach across 30+ states and 90,000+ government entities.
Three Security Tiers
Categories align with FIPS 199 and map to NIST 800-53 baselines, ensuring consistency with FedRAMP.
Category 1 (Low): 156 controls for public-facing sites and non-sensitive data
Category 2 (Moderate): 325 controls for PII, tax records, student data (most common)
Category 3 (Moderate+): 325+ controls for CJIS, health data, financial data
StateRAMP Verification Statuses
StateRAMP Ready
3PAO readiness assessment confirms core controls are implemented and a credible path to authorization exists. Provides procurement visibility.
StateRAMP Provisional
Full 3PAO assessment complete with some POA&M items remaining. Government agencies can procure with understanding remediation is in progress.
StateRAMP Authorized
Highest status. All critical POA&M items resolved, Approvals Committee has reviewed the package. Listed on the Authorized Product List.
FedRAMP Reciprocity
Existing FedRAMP authorization enables expedited StateRAMP verification in 4 to 8 weeks since both use NIST 800-53 baselines.
How It Works
Determine correct security category based on data types processed
Implement NIST 800-53 controls for your category baseline
Develop SSP, policies, and security documentation
Engage accredited 3PAO for independent assessment
Achieve verification status on the Authorized Product List
Maintain continuous monitoring: monthly scans, annual assessments
Frequently Asked Questions
How does StateRAMP relate to FedRAMP?
Both use NIST SP 800-53 baselines. StateRAMP accepts FedRAMP authorizations for expedited verification. A FedRAMP Moderate ATO typically satisfies StateRAMP Category 2.
Which states have adopted StateRAMP?
Over 30 states including Arizona, Indiana, Minnesota, Georgia, Connecticut, Virginia, and others. Texas operates TX-RAMP but recognizes StateRAMP reciprocity for certain categories.
What does 3PAO assessment include?
Control testing, vulnerability scanning, penetration testing, documentation review, and interview validation. The same accredited organizations that conduct FedRAMP assessments.
What happens if verification lapses?
Failure to maintain continuous monitoring requirements can result in suspension or revocation of verification status, removing your product from the Authorized Product List.
How long does StateRAMP verification take?
6 to 12 months for new verification from scratch. 4 to 8 weeks with existing FedRAMP authorization. Petronella Technology Group's automation tools compress preparation timelines significantly.
Explore More
Achieve StateRAMP Verification
Petronella guides cloud service providers through the StateRAMP process from gap assessment to continuous monitoring.