TX-RAMP certification cost and timeline
Texas DIR charges nothing for TX-RAMP certification. What the work really costs, the control counts by level, and the deadline that changed in 2026.
By the Scrutineer team
September 2026 · 7 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
›
Illustrative sample · not an audit attestation
The Texas Department of Information Resources charges nothing for a TX-RAMP certification. That single fact reshapes the whole budget question, because it means every dollar and every week you spend belongs to work you control, and it means the schedule, not the invoice, is what decides whether you keep a Texas contract. The figure most vendors plan against, an eighteen month provisional runway, was cut to twelve months in February 2026 and the correction has barely propagated.
How much does TX-RAMP certification cost?
DIR's own Frequently Asked Questions page answers this in one sentence: "There are no fees associated with a TX-RAMP certification, as it is funded by the state of Texas." There is no program fee, no application fee and no assessor fee owed to Texas, because TX-RAMP does not require a third-party assessment organization the way FedRAMP does. DIR staff review your submission directly.
So the cost is entirely internal, and it lands in four places: writing the control evidence, building the TX-RAMP Security Plan Workbook, remediating whatever the gap analysis finds, and then carrying continuous monitoring for three years. Published third-party estimates for a full Level 2 documentation package run into six figures, but those numbers come from consultancies pricing their own delivery and they vary enormously with how much of your control evidence already exists. We are not going to invent a figure. What actually drives yours is the table below.
| Cost driver | Level 1 | Level 2 | What moves the number |
|---|---|---|---|
| Paid to Texas DIR | Nothing | Nothing | The state funds the program, and no 3PAO is required |
| Controls to evidence | 117 | 223 | How much already exists from SOC 2, ISO 27001 or FedRAMP work |
| Largest control families | Audit and Accountability at 10, Identification and Authentication at 10 | Access Control at 33, System and Communications Protection at 23, Configuration Management at 21 | Level 2 concentrates the added weight in access and network architecture |
| Required documents | A&I Questionnaire, Level 1 Assessment Questionnaire, Security Plan Workbook, POA&M | Same set, Level 2 questionnaire | Whether a current system security plan and boundary diagram exist |
| Ongoing monitoring | Annual vulnerability report through SPECTRIM | Quarterly vulnerability report through SPECTRIM | Level 2 is four times the reporting cadence for three straight years |
| Recertification at year three | 38 control requirements reviewed | 48 control requirements reviewed | Far lighter than the initial baseline, and widely misreported as a full redo |
The control counts and the recertification scope come from Appendix A and Section 20 of the TX-RAMP Program Manual version 4.0, which took effect on February 12, 2026.
How long does TX-RAMP certification take?
DIR states a goal of completing a review and issuing a recommendation within four weeks once the assessment review begins. That number is genuinely short, and it is also the least useful number in your plan, because it measures DIR's queue rather than yours. The review starts when your package is complete. Everything that determines your timeline happens before that.
Three clocks matter more, and they run at once:
- Provisional certification: twelve months. Granted once TX-RAMP approves your Acknowledgment and Inventory Questionnaire, and it is what lets an agency contract for your product while you finish. Program Manual 4.0 says it "is effective for 12 months from the date TX-RAMP grants the provisional certification."
- Full certification: three years. Valid from the date it was conferred, provided you stay compliant.
- Recertification: opens twelve months before expiry. Automated reminders arrive at twelve months and again at ninety days.
The eighteen month figure in your plan is out of date
This is the part worth checking today. Nearly every published TX-RAMP guide says provisional certification lasts eighteen months. So does the FAQ page DIR itself publishes, which still reads "TX-RAMP Provisional Certification may be obtained for a period of 18 months to expedite compliance to assist with active procurements."
Program Manual 4.0 says twelve. The manual is the document the program is administered under, and the manual is the one that was revised, so twelve is the number to plan against. If your Texas schedule assumed a year and a half of provisional cover while you assembled a Level 2 package, you have six fewer months than you budgeted, and the thing at risk is not a certificate. Provisional status is the legal basis on which the agency contracted for your service in the first place.
Does a FedRAMP authorization make TX-RAMP free?
Cheaper, yes. Automatic, no, and this is the second expensive misunderstanding in this program. Since October 30, 2024, DIR no longer adds FedRAMP and StateRAMP certified products to the TX-RAMP certified products list on its own. Manual 4.0 is explicit that a provider reaching an accepted GovRAMP or FedRAMP status "must submit a change request form notifying TX-RAMP of the status change to receive a full reciprocal TX-RAMP certification."
File it and the savings are substantial: a service certified through the FedRAMP or GovRAMP equivalence route is not required to provide continuous monitoring artifacts to TX-RAMP at all, which removes three years of quarterly reporting. Skip it and you are simply absent from the list an agency searches mid procurement, holding an authorization that nobody in Texas can see. The cost of that omission is a contract, and it is the cheapest mistake on this page to avoid.
Where the money actually goes
For most SaaS vendors the honest answer is engineering hours, not consulting invoices. The Level 2 baseline concentrates its additional controls in access control, system and communications protection, and configuration management, which are the families where a fix is a change to how the product is built and operated rather than a document. If multi-factor coverage is partial, if your production network segmentation is informal, or if configuration baselines live in someone's head, that is the budget line, and it will not be shortened by hiring a writer.
The documentation cost is real but compressible, and it compresses in exactly one way: by not starting from zero. TX-RAMP tests NIST SP 800-53 controls that your existing frameworks already test. Teams that keep a single control library and attach evidence once tend to answer the Level 2 questionnaire as a mapping exercise. Teams that keep evidence in the format of whichever audit last asked for it rebuild it, at full price, every time. That is the argument for treating TX-RAMP certification software as infrastructure rather than paperwork, and it is the same argument that applies to FedRAMP compliance software and to a GovRAMP compliance program covering other states.
The recertification math nobody publishes
Two details in Section 20 of the manual change how you should schedule year three. First, recertification does not repeat the baseline. It reviews 38 control requirements at Level 1 and 48 at Level 2, against the 117 and 223 assessed initially. Plenty of vendors budget a second full assessment they do not owe.
Second, and this one costs real money: the renewed certificate expires three years from the previous expiration date, "regardless of when the recertification process is complete." Finish early and you lose nothing. Drift four months past your window and you have bought two years and eight months of certification at the price of three. Since the reminder arrives a full year ahead, this is a pure calendar discipline problem, which is the cheapest kind to solve.
Who has to do this at all
Texas Government Code Section 2063.408 requires state agencies to enter or renew contracts only for cloud computing services that comply with TX-RAMP. The obligation formally sits on the agency, which is why it reaches you as a procurement condition rather than a letter from a regulator. In scope are state agencies, public institutions of higher education and public community colleges. Each independent cloud service needs its own certification, scoped to the components inside that solution's boundary, so a vendor with three products has three packages, not one.
One change worth tracking: House Bill 150, passed in 2025, creates Texas Cyber Command and transfers DIR's cybersecurity duties, TX-RAMP included. The manual records that DIR continues to perform them until a memorandum between the two identifies that all responsibilities must transfer. Nothing about your obligations changes today, but the name on the program is expected to.
Budgeting it honestly
If you are pricing this internally, the defensible way to present it is not a single number. It is a fee of zero to the state, a control gap analysis against 117 or 223 requirements, a remediation estimate that comes from engineering rather than compliance, and a three-year monitoring commitment at annual or quarterly cadence. Then a schedule built on twelve months of provisional cover, not eighteen. Getting certified is what lets the agency issue the contract and start moving purchase orders against it, so the value on the other side of this work is usually easy to name, which makes the internal case simpler than the compliance framing suggests.
Certification is a readiness exercise, and the evidence you assemble is reusable across every other framework a state or federal buyer will ask about. That is the only part of this budget that compounds.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.