TX-RAMP
Texas's risk and authorization management program for cloud services used by state agencies and public higher education. Level 1, Level 2, and Provisional are service-offering certifications—not company-wide certifications.
Program Manual 4.0 · Texas Department of Information Resources
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
TX-RAMP is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Texas DIR publishes the program manual and baseline spreadsheets. Pin Manual 4.0 and the applicable Level 1 or Level 2 baseline before normalization.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Level 1 low-impact baseline · Level 2 moderate/high-impact baseline · Provisional certification · Fast Track assessment · FedRAMP and GovRAMP reciprocity
- Applies to
- cloud services · SaaS · state government · higher education · US-TX
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| Program Manual 3.1 | Superseded | date not published |
| Program Manual 4.0 | Current edition · supersedes Program Manual 3.1 | date not published |
06Related frameworks
- GovRAMP (formerly StateRAMP)Rev. 5 baselines
Also applies to cloud services · A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.
- CSA STARSTAR Level 1 and Level 2
Also applies to cloud services · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.
- CSA CCM and CAIQv4.1
Also applies to cloud services · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.
Also applies to cloud services · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.