GovRAMP
Also known as: StateRAMP, GovRAMP Core, GovRAMP Low, GovRAMP Low+, GovRAMP Moderate, GovRAMP High, Security Snapshot
GovRAMP (formerly StateRAMP) cloud security authorisation programme — GovRAMP
Official site Official change log
The authorisation programme US state and local governments use where FedRAMP applies only to federal agencies. One programme with several impact levels — Core, Low, Low+, Moderate and High — each a baseline of the same control set rather than a separate framework, plus overlays such as CJIS and the federal overlay. Templates and requirements are revised several times a year, and a revision changes what a service provider must submit.
Timeline
July 2026
GovRAMP Medium New document
GovRAMP publishes AI Self-Reporting Addendum for service providersGovRAMP has published the AI Self-Reporting Addendum to standardize how service providers disclose information about AI-enabled products. The addendum requires disclosure of product architecture, data use …
FedRAMP GovRAMP Low Guidance
FedRAMP recognizes GovRAMP as approved alternative security framework in updated Class A RulesFedRAMP has recognized GovRAMP as an approved alternative security framework in its updated Class A Certification Rules. This recognition aligns state and federal cybersecurity requirements, providing …
Monitoring
Watched by 1 official source. Watching since 20 September 2026.