Scrutineer · By framework
GovRAMP compliance software for TX-RAMP and StateRAMP
State procurement now runs on published security status. Texas will not contract for a cloud service without TX-RAMP, and North Carolina began requiring GovRAMP of executive branch vendors on April 1, 2026.
Scrutineer holds your NIST 800-53 controls and evidence once, then maps them to GovRAMP and TX-RAMP at the same time, so the second state costs a fraction of the first.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with GovRAMP
The FedRAMP baseline names on your GovRAMP paperwork were retired in June
FedRAMP finalized its Consolidated Rules for 2026 on June 25, 2026, with an effective date of July 4, 2026 and mandatory adoption on January 1, 2027. CR26 retires the Low, Moderate and High labels and replaces them with Certification Classes A through D: Class A for the old Ready baseline, Class B for Li-SaaS and Low, Class C for Moderate, Class D for High. The reason given was that the FIPS 199 labels kept colliding with the Defense Department impact levels, which use similar words for a different framework. The catch for anyone selling to states is that the programs downstream have not moved. The GovRAMP Security Assessment Framework version 4.2, published April 2026, still defines its three impact levels as aligned to FedRAMP Rev. 5 Low, Moderate and High control baselines, and the Texas reciprocity rules still name StateRAMP Category 1 and Category 2. Until those documents catch up, the vendor is the translation layer, and a reciprocity request that names the wrong label is a request that comes back.
Texas quietly stopped honoring your federal authorization automatically
The single most repeated claim about TX-RAMP is that a FedRAMP Moderate or StateRAMP Category 2 authorization satisfies TX-RAMP Level 2 automatically. It satisfies the criteria. It has not been automatic since October 30, 2024, when Texas DIR stopped adding FedRAMP and StateRAMP certified products to the TX-RAMP certified products list on its own. Reciprocity is now a request you file, and nothing appears on the list until you file it. Teams find this out when a Texas agency checks the certified products list mid procurement and does not find them. The rest of the program is unusually vendor friendly by comparison: TX-RAMP carries no fee because the state funds it, Level 1 and Level 2 certifications last three years, and a provisional certification buys eighteen months to finish. The deadline that bites is the one nobody filed for.
Core is the only status with no 3PAO, and the fee table makes it look expensive
Read the published GovRAMP fee schedule effective January 1, 2025 and Core looks like the wrong answer. For a provider under 1 million dollars in revenue the PMO fee is 10,000 dollars for Core, against 3,500 dollars for Ready and 4,500 dollars for Authorized. Core appears to cost more than full authorization. It does not. The Ready and Authorized lines exclude the third party assessor, billed separately, and a 3PAO engagement is usually the largest single invoice in the whole program. Core needs no 3PAO at all: the GovRAMP PMO reviews your evidence directly against 60 foundational NIST 800-53 Rev. 5 controls, selected using the MITRE ATT&CK framework and aligned to the Moderate baseline. Core status runs twelve months, extends indefinitely through an annual assessment, and requires quarterly continuous monitoring. One caveat worth checking before you budget: GovRAMP publishes the Core PMO assessment as 9,000 to 17,000 dollars on its Core page and as 10,000, 13,000 and 21,000 dollars by revenue tier on its pricing overview. The two figures do not agree, so confirm yours with the PMO.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps one NIST 800-53 Rev. 5 control library to GovRAMP and TX-RAMP at the same time, so the second program is a review rather than a rebuild
- Tracks which of your controls satisfy the 60 Core controls, the GovRAMP Ready minimum mandatory requirements, and the full Authorized baseline
- Holds the System Security Plan, boundary diagram, inventory worksheet and roles and permissions matrix that a GovRAMP package will not be accepted without
- Keeps a live POA&M so the monthly update GovRAMP continuous monitoring requires is an export rather than a scramble
- Flags the gap between a FedRAMP authorization label under CR26 and the Rev. 5 baseline names GovRAMP and Texas DIR still use
- Reuses the same evidence for SOC 2, ISO 27001, CMMC and FedRAMP, because state programs and federal programs test the same controls
- Tracks certification expiry across states, including the three year TX-RAMP clock and the eighteen month provisional window
- Produces the reciprocity paperwork trail a state agency asks for when it cannot find you on a certified products list
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
State authorization reference
What your existing authorization actually gets you in each state program
Every published comparison runs the same axis: FedRAMP versus GovRAMP versus TX-RAMP, pick a program. That is not the decision in front of most vendors. They already hold something, and the real question is what it carries across and what still needs a separate filing. This table runs on what is already in your evidence room.
| What you already hold | What it opens at GovRAMP | What it maps to in TX-RAMP | Does it happen automatically | What you still have to file |
|---|---|---|---|---|
| Nothing formal, and a first state RFP on the desk | A Security Snapshot or a Core listing, both reviewed by the GovRAMP PMO with no 3PAO involved | Neither satisfies TX-RAMP on its own | No | A Core evidence package to the GovRAMP PMO, and a separate TX-RAMP questionnaire to Texas DIR |
| GovRAMP Core | A Core entry on the Authorized Product List, valid twelve months and extendable annually | Nothing. Core sits below the line the Texas reciprocity rules are written against | No | The full TX-RAMP Level 1 or Level 2 assessment, plus quarterly Core continuous monitoring to keep the listing alive |
| GovRAMP Ready at Moderate | Ready status, backed by a 3PAO Readiness Assessment Report and the minimum mandatory requirements | Nothing on its own. Texas writes reciprocity against authorization, not readiness | No | The remaining gap to Authorized, then a reciprocity request to DIR |
| GovRAMP Authorized at Moderate, formerly StateRAMP Category 2 | The strongest GovRAMP status, awarded by a sponsoring government body on a 3PAO Security Assessment Report | The TX-RAMP Level 2 criteria, which is 223 NIST 800-53 controls | No, and it has not been since October 30, 2024 | An explicit reciprocity request to Texas DIR. Nothing lands on the certified products list without one |
| FedRAMP Ready, an ATO or a P-ATO | GovRAMP Fast Track. No new audit is required and you may submit the FedRAMP package you already have | Depends on the baseline behind the authorization | No | A Security Review Request Form to GovRAMP, and a separate reciprocity request to Texas DIR |
| A FedRAMP Moderate authorization, now issued as Class C under CR26 | GovRAMP Authorized at Moderate through Fast Track, with no second audit | The TX-RAMP Level 2 criteria | No, and both destinations still use the label your new certificate no longer carries | Both filings, plus your own translation between the CR26 class on the certificate and the Rev. 5 baseline names the state programs still publish |
| A FedRAMP Low authorization, now issued as Class B under CR26 | GovRAMP Authorized at Low through Fast Track | The TX-RAMP Level 1 criteria, which is 117 NIST 800-53 controls | No | Both filings. Level 1 also carries a lighter monitoring load: annual vulnerability reports rather than quarterly |
Program details reflect the GovRAMP Security Assessment Framework version 4.2 dated April 2026, the FedRAMP Consolidated Rules for 2026 launched June 25, 2026, and the TX-RAMP rules Texas DIR publishes under Texas Government Code 2054.0593. Reciprocity policy and control counts change, and the state programs are mid transition on baseline naming, so confirm your own mapping with GovRAMP and with DIR before you file. Scrutineer prepares readiness evidence and does not award any of these statuses.
Good questions
Questions about GovRAMP
Keep reading
Guides that go deeper on this framework
GovRAMP certification cost and TX-RAMP pricing
The published fee schedules for both programs, what the 3PAO adds on top, and why the cheapest status is not the one with the smallest number.
Read the guideGovRAMP vs StateRAMP, and vs FedRAMP
What the 2025 rename changed, the full status ladder, and how reciprocity between the programs actually works.
Read the guideFedRAMP 20x vs Rev 5
How the federal program restructured, and which parts of your existing package survive the change.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification