Scrutineer.ai
All posts
Guides

GovRAMP vs StateRAMP: What the Rename Changed

StateRAMP became GovRAMP on February 14, 2025. It was a rebrand, not a restructure: existing authorizations, memberships, requirements and pricing all carried across unchanged. Here is what the status ladder actually means, why GovRAMP Ready does not expire the way FedRAMP Ready does, and why the reciprocity between the two programs runs in only one direction.

By the Scrutineer team

August 2026 · 9 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Illustrative sample · not an audit attestation

StateRAMP is now GovRAMP. The organization announced the change on February 14, 2025 and completed the web rollout that March. It was a rebrand, not a restructure: StateRAMP remains the legal entity name and operates as GovRAMP, existing authorizations and memberships carried over untouched, and the requirements, pricing and processes did not change. If you hold a StateRAMP status today, you hold a GovRAMP status today.

The confusion is worth clearing up properly, because the two names are still used interchangeably in state procurement documents, RFP boilerplate and vendor marketing, and a security questionnaire that asks for "StateRAMP Authorized" in 2026 is asking for the same thing as one that asks for "GovRAMP Authorized." What follows is what actually changed, what the status ladder means, and the one structural fact about FedRAMP reciprocity that decides whether the program is worth pursuing for your company.

What changed in the rename, and what did not

The rebrand reflected who was actually participating. The program launched in 2020 aimed at state governments, but adoption spread to local governments, K-12 and higher education, special districts and tribal governments, and the "State" in the name had stopped describing the membership. GovRAMP was chosen to cover all of it.

Three things are worth knowing precisely. First, the change is a doing-business-as arrangement rather than a dissolution and reformation, so contracts signed with StateRAMP remain valid without amendment. Second, the web presence moved to govramp.org, and old StateRAMP links redirect. Third, nothing in the security requirements moved: the control baselines, the audit process, the continuous monitoring obligations and the fee schedule all carried across unchanged.

That last point matters for anyone mid-assessment. A rebrand that reset the baselines would have forced re-scoping. This one did not, so an assessment started under the StateRAMP name finished under the GovRAMP name with the same evidence.

The GovRAMP status ladder

GovRAMP does not have a single pass or fail outcome. It has a ladder, and where you sit on it determines what a procurement officer sees when they look you up on the Program Participants List.

StatusWhat it meansWho assessesPractical use
Security SnapshotA free self-assessment producing a maturity score against the baseline. Not a status and not published as one.Self, via the GovRAMP questionnaire.A gap analysis before you spend money. Useful for deciding whether you are twelve weeks or twelve months away.
ProgressingYou are actively working toward a status, with a government sponsor or on the strength of a submitted package.GovRAMP PMO review.Lets an agency see you are in the pipeline while procurement continues.
CoreIntroduced May 2025. A reduced set of roughly 60 foundational controls drawn from NIST SP 800-53 Rev 5 and mapped against MITRE ATT&CK.Third-party assessor, reviewed by the PMO.An entry point for smaller vendors and lower-risk products that cannot justify a full Moderate package.
ReadyVerified as meeting a minimum threshold of the baseline, with a remediation plan for the rest.Third-party assessor, reviewed by the PMO.Published on the participants list. Unlike FedRAMP Ready, it does not expire after twelve months.
ProvisionalSubstantially meets the baseline with minor items outstanding. Roughly the P-ATO equivalent.Third-party assessor plus PMO and approvals committee.Accepted by most agencies while final remediation closes.
AuthorizedFull authorization against the selected impact level, with continuous monitoring in force.Third-party assessor plus PMO and approvals committee.The status most RFPs name. Requires ongoing monthly reporting to keep.

The status that surprises people is Ready. Under FedRAMP, achieving Ready starts a twelve-month clock to find an agency sponsor, and letting it lapse means starting over. GovRAMP Ready has no such expiry, which changes the sequencing: you can earn and publish a status first and go looking for the agency second, rather than needing the relationship before the work has any visible payoff.

GovRAMP and FedRAMP: the reciprocity runs one way

Both programs sit on NIST SP 800-53 Rev 5, and the GovRAMP impact levels map onto the FedRAMP Rev 5 baselines. Vendors reasonably assume that equivalence means the authorizations are interchangeable. They are not, and the asymmetry runs in a specific direction.

DimensionFedRAMPGovRAMP (formerly StateRAMP)
Who runs itUS federal government, via GSA and the FedRAMP program office.A nonprofit membership organization, independent of any one government.
Who asks for itFederal agencies buying cloud services.State, local, tribal and education buyers, often written into RFPs.
Control basisNIST SP 800-53 Rev 5 baselines.NIST SP 800-53 Rev 5, with impact levels aligned to the FedRAMP baselines.
Sponsor neededYes for an agency ATO. Ready status lapses after twelve months without one.A government sponsor helps but Ready does not expire without one.
Does it count for the other?Yes. A FedRAMP authorization can be carried across through the Fast Track route.No. A GovRAMP authorization does not satisfy FedRAMP.
Continuous monitoringMonthly scans, POA&M updates and annual assessment.Monthly reporting to the PMO, tracked against the same cadence.

Read the reciprocity row carefully, because it drives the build order. If your roadmap includes federal business at any point, doing FedRAMP first and carrying it into GovRAMP through Fast Track is strictly cheaper than the reverse. Going GovRAMP first and federal later means paying for the federal package essentially from scratch. Fast Track still requires GovRAMP membership, PMO review and its own continuous monitoring, so it is a reuse of evidence rather than an automatic transfer, but the evidence is the expensive part.

Which impact level applies to you

GovRAMP uses FIPS 199 categorization, the same instrument as FedRAMP: you assess the potential impact of a confidentiality, integrity or availability failure as Low, Moderate or High, and the highest of the three sets your level. Moderate is where most of the market sits, because it is the level at which a breach would cause serious adverse effect, and that is a fair description of almost any system holding resident or student records.

The practical mistake is categorizing on the size of the agency rather than the sensitivity of the data. A small school district storing student information is a Moderate system. A large agency's public-facing information portal may genuinely be Low. Categorize the system, not the customer.

Who actually needs GovRAMP

If you sell cloud software to US state or local government, K-12 or higher education and your product touches government data, you are in scope for the question even if no customer has asked yet. States including Arizona, Texas, Georgia and others have written the requirement into procurement policy or standard contract language, and the trend has been toward more of that rather than less. Vendors typically discover the requirement in an RFP with a deadline attached, which is the worst moment to start.

If your buyers are exclusively private sector, this is not your program, and a SOC 2 report will do more for you than a GovRAMP status. If your buyers are federal, start with FedRAMP for the reciprocity reason above. If your buyers are defense contractors, the relevant regime is CMMC and NIST SP 800-171, which is a different scheme with its own assessment path.

What the work actually looks like

The assessment itself is a third-party engagement, but the cost driver is the evidence behind it. A Moderate package means a system security plan describing how each control is implemented, policies and procedures that exist and are followed, and artifacts proving both. The heaviest recurring items are the ones tied to a schedule: monthly vulnerability scanning with tracked remediation, access reviews with reviewer sign-off, change management records for every production deployment, annual security awareness training with completion records, and an incident response plan that has actually been exercised.

Change management is where cloud vendors most often lose evidence, because deployments happen faster than the paperwork describing them. Assessors ask for a sample of production changes and expect to see the approval, the test record and the rollback plan for each one, so a deployment pipeline that records every release with its approvals is worth more at assessment time than a policy document describing a process nobody logs.

None of this is unique to GovRAMP. The same access reviews, scan records and change tickets satisfy SOC 2 and ISO 27001, and if you already hold either, a meaningful share of the package is written. What GovRAMP adds is the requirement to keep it current between assessments rather than assembling it once a year, which is why continuous compliance monitoring tends to be the difference between a renewal that takes two weeks and one that takes two months. Scrutineer maps a single control set across the frameworks and keeps the evidence dated, and the same approach applies whether you are preparing a GovRAMP package or a FedRAMP authorization package.

Is StateRAMP still valid?

Yes. StateRAMP and GovRAMP are the same organization and the same program. A StateRAMP Authorized status earned before the rebrand is a GovRAMP Authorized status now, with no reapplication, no fee and no gap in listing. If a customer questionnaire asks for StateRAMP and your certificate says GovRAMP, they are the same document and the participants list will confirm it.

Is GovRAMP the same as FedRAMP?

No. They are separate programs run by separate bodies for separate buyers, built on the same NIST SP 800-53 Rev 5 control catalog. FedRAMP is a federal government program authorizing cloud services for federal agencies. GovRAMP is a nonprofit program serving state, local, tribal and education buyers. The control overlap is high, which is what makes the FedRAMP to GovRAMP Fast Track route work, but a status in one is not a status in the other.

How long does GovRAMP authorization take?

Plan on six to twelve months to Authorized from a standing start, and considerably less if you already hold SOC 2 Type 2 or ISO 27001 and have real evidence behind them. The variable is almost never the assessor's timeline; it is how long remediation takes once the gap analysis comes back. Running the Security Snapshot self-assessment first is the cheapest way to find out which of those two situations you are in before committing budget.

What does GovRAMP cost?

There are two separate costs and vendors routinely budget for only one. The first is GovRAMP membership, which is paid to the organization and scales with company size. The second is the third-party assessment, which is paid to an assessor and scales with the impact level and system complexity. Remediation is a third cost that does not appear on any price list and is usually the largest. Confirm current membership and assessment fees directly, since both are set by the parties involved rather than published as a single number.

The short version

StateRAMP became GovRAMP in 2025 as a rebrand with no change to requirements, statuses or existing authorizations. The program authorizes cloud products for state, local, tribal and education buyers against NIST SP 800-53 Rev 5, through a ladder running from a free Security Snapshot up through Core, Ready, Provisional and Authorized. Ready status does not expire, which is a real advantage over the federal equivalent. And the reciprocity with FedRAMP runs one way only, so if federal business is anywhere on your roadmap, the cheaper sequence is federal first.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.