Scrutineer.ai
All posts
Pricing

GovRAMP Certification Cost and TX-RAMP Pricing

What GovRAMP actually charges at each status on the published fee schedule, what the third party assessor adds on top, why Texas charges nothing at all, and the counterintuitive reason the cheapest looking status is usually the most expensive route.

By the Scrutineer team

August 2026 · 9 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Illustrative sample · not an audit attestation

GovRAMP charges a published PMO fee plus annual member dues, and nothing else. For a cloud provider under 1 million dollars in annual revenue that is 500 dollars in dues plus 3,500 dollars for Ready or 4,500 dollars for Authorized. Above 5 million dollars in revenue the same statuses cost 15,750 and 19,500 dollars. Every one of those figures excludes the third party assessor, which is normally the largest invoice in the program. TX-RAMP, by contrast, costs nothing at all in program fees, because Texas funds it.

That is the short answer. The longer answer matters more, because the fee schedule ranks the statuses in an order that does not survive contact with an actual budget. The status with the biggest number on the published table is usually the cheapest one to reach, and the status with the smallest number is the one that quietly commits you to a six figure assessment.

How much does GovRAMP certification cost?

GovRAMP publishes a fee schedule effective January 1, 2025, split by the provider's annual revenue. Memberships renew annually on June 1. The PMO fees below are what GovRAMP itself charges to review your security package and list the product.

Annual revenueMember duesSingle Security SnapshotCoreReadyAuthorized or Provisional
Under 1 million dollars5001,00010,0003,5004,500
1 to 5 million dollars1,0001,50013,0008,50011,000
Over 5 million dollars1,5002,50021,00015,75019,500

All figures in US dollars, from the GovRAMP pricing overview effective January 1, 2025. The Ready and Authorized columns exclude third party assessor costs, which are billed separately by the assessor. GovRAMP notes that PMO fees may rise annually, capped at the Bureau of Labor Statistics rate published each June, with any change posted by October 1 and effective the following January 1.

One inconsistency is worth catching before you build a budget on it. The GovRAMP Core page describes the initial PMO assessment as 9,000 to 17,000 dollars depending on revenue, while the pricing overview lists 10,000, 13,000 and 21,000 dollars for the same thing. The two published figures do not agree. Ask the PMO for your number in writing rather than quoting either page to a CFO.

Why Core costs more than Authorized on the fee schedule

Read the table straight and Core looks absurd: 10,000 dollars for an entry level status against 4,500 dollars for full authorization. The explanation is that the two numbers are measuring different amounts of work.

Core requires no third party assessor. The GovRAMP PMO reviews your evidence directly against 60 foundational NIST SP 800-53 Rev. 5 controls, chosen using the MITRE ATT&CK framework and aligned to the Moderate impact baseline. The PMO is doing the assessment, so the PMO fee carries the assessment cost. Ready and Authorized both require a GovRAMP approved 3PAO to produce a Readiness Assessment Report or a Security Assessment Report, plus a penetration test. That work never appears on the GovRAMP fee schedule because GovRAMP does not perform it or bill for it.

So the honest comparison is not 10,000 against 4,500. It is 10,000 all in against 4,500 plus an independent audit engagement plus a penetration test. Published 3PAO quotes vary widely enough that any single number would be misleading, and the drivers are the ones you would expect: the size of your authorization boundary, how many cloud services and interconnections sit inside it, whether your System Security Plan already exists in a usable form, and how much remediation the assessor finds. Get two or three quotes scoped against your actual boundary before you assume Ready is the cheaper path.

What GovRAMP costs every year after you get the status

The initial fee is not the interesting part of the budget. Every GovRAMP status carries an ongoing obligation, and the recurring cost is what teams underestimate.

StatusWhat it is valid forRecurring obligationRecurring fee
Security Snapshot12 months from issuance, reusable by multiple governmentsReissue to stay current1,000 to 2,500 by revenue tier
Progressing Security SnapshotOngoing enrollmentQuarterly snapshots plus monthly advisory calls with the PMO team9,000 to 19,200 per year by revenue tier
Core12 months, extendable indefinitely by annual assessmentQuarterly continuous monitoring: web app scans, vulnerability scans, policy compliance scans and a POA&M250 to 1,000 per quarter by revenue tier
ReadyMaintained through continuous monitoringMonthly executive summary, monthly POA&M update, monthly vulnerability scanning, annual 3PAO assessment of roughly one third of controlsPMO fee plus the annual 3PAO engagement
AuthorizedMaintained through continuous monitoringSame monthly cadence plus penetration testing under the continuous monitoring guidePMO fee plus the annual 3PAO engagement

That annual reassessment of roughly a third of your controls is the line that turns GovRAMP from a project into a program. It recurs for as long as you hold the status, and it is the reason the initial certification quote is a poor predictor of what the next three years cost. If compliance spend is a line you have to defend every quarter, it is worth putting an alert on the budget line itself rather than discovering the assessor renewal at the same time as the PMO invoice.

How much does TX-RAMP certification cost?

Nothing, in program fees. Texas DIR charges no fee to review a submission or grant a TX-RAMP certification, because the state funds the program. That makes TX-RAMP the cheapest state authorization in the country to hold, and it is the reason so many vendors treat Texas as their first state.

Your costs are entirely internal, and they scale with the level:

  • Level 1 covers nonconfidential agency data and low impact systems, currently 117 NIST SP 800-53 controls, assessed by self attestation. Vulnerability reports go to DIR annually.
  • Level 2 covers confidential data and moderate or high impact systems, 223 controls, and adds an independent 3PAO assessment including a penetration test of the cloud environment. Vulnerability reports go to DIR quarterly.

Both certifications last three years from the date granted. A provisional certification, which lets an agency contract with you while you finish, lasts eighteen months and does not renew. Breaches must be disclosed to DIR within 48 hours of discovery. DIR typically completes its review within two to four weeks of submission.

Does a FedRAMP authorization save you money on GovRAMP?

Yes, and this is the largest single saving available. GovRAMP Fast Track requires no new audit for a product holding FedRAMP Ready, an ATO or a P-ATO. You submit the FedRAMP package and audit you already have, and you can begin before the FedRAMP review process itself is finished. The 3PAO engagement, the expensive part, is already paid for.

The same logic does not run in reverse. FedRAMP does not accept a GovRAMP package, so a state first strategy buys you state revenue but no federal shortcut. If federal business is on the roadmap at all, sequencing FedRAMP first and letting GovRAMP inherit it is materially cheaper than the other order.

There is a wrinkle in 2026 that affects the paperwork rather than the price. FedRAMP finalized its Consolidated Rules for 2026 on June 25, 2026, effective July 4 and mandatory from January 1, 2027. CR26 retires the Low, Moderate and High baseline labels in favor of Certification Classes A through D, where Class B replaces Li-SaaS and Low and Class C replaces Moderate. GovRAMP's own Security Assessment Framework version 4.2, published April 2026, still describes its impact levels as aligned to the FedRAMP Rev. 5 Low, Moderate and High baselines, and the Texas reciprocity rules still refer to StateRAMP Category 1 and Category 2. Until the downstream documents catch up, you are the translation layer between the label on your certificate and the label on the form.

The cost nobody budgets: filing for reciprocity

The most repeated claim about TX-RAMP is that a FedRAMP or StateRAMP authorization satisfies it automatically. It satisfies the criteria. It stopped being automatic on October 30, 2024, when DIR stopped adding FedRAMP and StateRAMP certified products to the TX-RAMP certified products list on its own initiative. Reciprocity is now a request you have to submit.

The fee for that request is zero. The cost is what happens when nobody files it: a Texas agency checks the certified products list in the middle of a procurement, does not find you, and the deal stalls while you assemble a submission you thought you had already made. That is a schedule cost, not a line item, and it is the most expensive mistake in this whole category.

Which status should you actually buy?

Work backwards from the contract rather than forwards from the fee schedule.

If you have no formal authorization and a first state RFP on the desk, Core is the fastest legitimate route onto the Authorized Product List, because it is the only verified status that skips the 3PAO entirely. It will not satisfy TX-RAMP, but it gets a real status published while you decide whether the state market justifies a full assessment.

If a specific agency has told you it requires authorization, go straight to Authorized and treat Ready as a milestone rather than a destination. Ready costs a 3PAO engagement and does not satisfy the reciprocity rules that are written against authorization, so paying for Ready and stopping there is the one genuinely wasteful outcome.

If you already hold a FedRAMP authorization, use Fast Track and file the reciprocity request in Texas the same week. You have already bought the expensive part.

Across all three paths, the variable that actually decides your bill is whether your control evidence already exists in an organized, current, mapped form, or whether the assessor is going to find it scattered across a wiki, a spreadsheet and three people's inboxes. The same NIST 800-53 controls sit behind GovRAMP, TX-RAMP, FedRAMP, FISMA and CMMC. Mapping them once and reusing the mapping is the difference between a state program that pays for itself and one that eats a quarter of your security budget every year.

Scrutineer holds that control library and its evidence, keeps continuous monitoring current so a status does not lapse, and maps one set of controls across both programs. If you want the program mechanics rather than the pricing, start with GovRAMP compliance software, or read how the rename and the reciprocity ladder fit together in GovRAMP vs StateRAMP.

Fees, control counts and reciprocity rules change. Every figure here is as published by GovRAMP and Texas DIR at the time of writing and should be confirmed with the program before you commit a budget. Scrutineer prepares readiness evidence and is not a third party assessment organization, a program management office or a state authorizing body.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.