Skip to main content
Framework library
Framework module · govramp-rev5

GovRAMP (formerly StateRAMP)

A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.

Rev. 5 baselines · GovRAMP · published 2024-10-01

Standing today
Directory entry

00Answer

from the registry record
What is GovRAMP (formerly StateRAMP)?
A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.
Who does GovRAMP (formerly StateRAMP) apply to?
GovRAMP (formerly StateRAMP) applies to cloud services, SaaS, state and local government, US, per GovRAMP.
What is the current version of GovRAMP (formerly StateRAMP)?
The current edition is Rev. 5 baselines, issued by GovRAMP and published 2024-10-01. Source: https://govramp.org/document-library.
What does an assessment under GovRAMP (formerly StateRAMP) require?
No control catalog has been ingested for GovRAMP (formerly StateRAMP) yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

GovRAMP (formerly StateRAMP) is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Confirm current GovRAMP template and control-parameter reuse terms before importing program material; verified statuses require the applicable PMO, sponsor, and/or 3PAO process.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Low, Moderate, and High baselines · Core 60-control subset · Third-party assessment · Authorization sponsorship · Continuous monitoring
Applies to
cloud services · SaaS · state and local government · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

2 editions
Rev. 4 baselinesSupersededdate not published
Rev. 5 baselinesCurrent edition · supersedes Rev. 4 baselines2024-10-01

05Change history

06Related frameworks

scored from registry facts
  1. TX-RAMPProgram Manual 4.0

    Also applies to cloud services · Texas's risk and authorization management program for cloud services used by state agencies and public higher education. Level 1, Level 2, and Provisional are service-offering certifications—not company-wide certifications.

  2. Also applies to cloud services · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.

  3. CSA STARSTAR Level 1 and Level 2

    Also applies to cloud services · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.

  4. Also applies to cloud services · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.

GovRAMP (formerly StateRAMP) | ControlFrame