Scrutineer.ai

Scrutineer · By framework

GovRAMP compliance software for TX-RAMP and StateRAMP

State procurement now runs on published security status. Texas will not contract for a cloud service without TX-RAMP, and North Carolina began requiring GovRAMP of executive branch vendors on April 1, 2026.

Scrutineer holds your NIST 800-53 controls and evidence once, then maps them to GovRAMP and TX-RAMP at the same time, so the second state costs a fraction of the first.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with GovRAMP

The FedRAMP baseline names on your GovRAMP paperwork were retired in June

FedRAMP finalized its Consolidated Rules for 2026 on June 25, 2026, with an effective date of July 4, 2026 and mandatory adoption on January 1, 2027. CR26 retires the Low, Moderate and High labels and replaces them with Certification Classes A through D: Class A for the old Ready baseline, Class B for Li-SaaS and Low, Class C for Moderate, Class D for High. The reason given was that the FIPS 199 labels kept colliding with the Defense Department impact levels, which use similar words for a different framework. The catch for anyone selling to states is that the programs downstream have not moved. The GovRAMP Security Assessment Framework version 4.2, published April 2026, still defines its three impact levels as aligned to FedRAMP Rev. 5 Low, Moderate and High control baselines, and the Texas reciprocity rules still name StateRAMP Category 1 and Category 2. Until those documents catch up, the vendor is the translation layer, and a reciprocity request that names the wrong label is a request that comes back.

Texas quietly stopped honoring your federal authorization automatically

The single most repeated claim about TX-RAMP is that a FedRAMP Moderate or StateRAMP Category 2 authorization satisfies TX-RAMP Level 2 automatically. It satisfies the criteria. It has not been automatic since October 30, 2024, when Texas DIR stopped adding FedRAMP and StateRAMP certified products to the TX-RAMP certified products list on its own. Reciprocity is now a request you file, and nothing appears on the list until you file it. Teams find this out when a Texas agency checks the certified products list mid procurement and does not find them. The rest of the program is unusually vendor friendly by comparison: TX-RAMP carries no fee because the state funds it, Level 1 and Level 2 certifications last three years, and a provisional certification buys eighteen months to finish. The deadline that bites is the one nobody filed for.

Core is the only status with no 3PAO, and the fee table makes it look expensive

Read the published GovRAMP fee schedule effective January 1, 2025 and Core looks like the wrong answer. For a provider under 1 million dollars in revenue the PMO fee is 10,000 dollars for Core, against 3,500 dollars for Ready and 4,500 dollars for Authorized. Core appears to cost more than full authorization. It does not. The Ready and Authorized lines exclude the third party assessor, billed separately, and a 3PAO engagement is usually the largest single invoice in the whole program. Core needs no 3PAO at all: the GovRAMP PMO reviews your evidence directly against 60 foundational NIST 800-53 Rev. 5 controls, selected using the MITRE ATT&CK framework and aligned to the Moderate baseline. Core status runs twelve months, extends indefinitely through an annual assessment, and requires quarterly continuous monitoring. One caveat worth checking before you budget: GovRAMP publishes the Core PMO assessment as 9,000 to 17,000 dollars on its Core page and as 10,000, 13,000 and 21,000 dollars by revenue tier on its pricing overview. The two figures do not agree, so confirm yours with the PMO.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps one NIST 800-53 Rev. 5 control library to GovRAMP and TX-RAMP at the same time, so the second program is a review rather than a rebuild
  • Tracks which of your controls satisfy the 60 Core controls, the GovRAMP Ready minimum mandatory requirements, and the full Authorized baseline
  • Holds the System Security Plan, boundary diagram, inventory worksheet and roles and permissions matrix that a GovRAMP package will not be accepted without
  • Keeps a live POA&M so the monthly update GovRAMP continuous monitoring requires is an export rather than a scramble
  • Flags the gap between a FedRAMP authorization label under CR26 and the Rev. 5 baseline names GovRAMP and Texas DIR still use
  • Reuses the same evidence for SOC 2, ISO 27001, CMMC and FedRAMP, because state programs and federal programs test the same controls
  • Tracks certification expiry across states, including the three year TX-RAMP clock and the eighteen month provisional window
  • Produces the reciprocity paperwork trail a state agency asks for when it cannot find you on a certified products list
GOVRAMP readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

State authorization reference

What your existing authorization actually gets you in each state program

Every published comparison runs the same axis: FedRAMP versus GovRAMP versus TX-RAMP, pick a program. That is not the decision in front of most vendors. They already hold something, and the real question is what it carries across and what still needs a separate filing. This table runs on what is already in your evidence room.

What you already hold What it opens at GovRAMP What it maps to in TX-RAMP Does it happen automatically What you still have to file
Nothing formal, and a first state RFP on the desk A Security Snapshot or a Core listing, both reviewed by the GovRAMP PMO with no 3PAO involved Neither satisfies TX-RAMP on its own No A Core evidence package to the GovRAMP PMO, and a separate TX-RAMP questionnaire to Texas DIR
GovRAMP Core A Core entry on the Authorized Product List, valid twelve months and extendable annually Nothing. Core sits below the line the Texas reciprocity rules are written against No The full TX-RAMP Level 1 or Level 2 assessment, plus quarterly Core continuous monitoring to keep the listing alive
GovRAMP Ready at Moderate Ready status, backed by a 3PAO Readiness Assessment Report and the minimum mandatory requirements Nothing on its own. Texas writes reciprocity against authorization, not readiness No The remaining gap to Authorized, then a reciprocity request to DIR
GovRAMP Authorized at Moderate, formerly StateRAMP Category 2 The strongest GovRAMP status, awarded by a sponsoring government body on a 3PAO Security Assessment Report The TX-RAMP Level 2 criteria, which is 223 NIST 800-53 controls No, and it has not been since October 30, 2024 An explicit reciprocity request to Texas DIR. Nothing lands on the certified products list without one
FedRAMP Ready, an ATO or a P-ATO GovRAMP Fast Track. No new audit is required and you may submit the FedRAMP package you already have Depends on the baseline behind the authorization No A Security Review Request Form to GovRAMP, and a separate reciprocity request to Texas DIR
A FedRAMP Moderate authorization, now issued as Class C under CR26 GovRAMP Authorized at Moderate through Fast Track, with no second audit The TX-RAMP Level 2 criteria No, and both destinations still use the label your new certificate no longer carries Both filings, plus your own translation between the CR26 class on the certificate and the Rev. 5 baseline names the state programs still publish
A FedRAMP Low authorization, now issued as Class B under CR26 GovRAMP Authorized at Low through Fast Track The TX-RAMP Level 1 criteria, which is 117 NIST 800-53 controls No Both filings. Level 1 also carries a lighter monitoring load: annual vulnerability reports rather than quarterly

Program details reflect the GovRAMP Security Assessment Framework version 4.2 dated April 2026, the FedRAMP Consolidated Rules for 2026 launched June 25, 2026, and the TX-RAMP rules Texas DIR publishes under Texas Government Code 2054.0593. Reciprocity policy and control counts change, and the state programs are mid transition on baseline naming, so confirm your own mapping with GovRAMP and with DIR before you file. Scrutineer prepares readiness evidence and does not award any of these statuses.

Good questions

Questions about GovRAMP

GovRAMP is a nonprofit program that standardizes cloud security verification for state, local, tribal and education government buyers, built on NIST SP 800-53 Rev. 5. Cloud providers submit a security package, receive a status of Core, Ready, Provisionally Authorized or Authorized, and appear on a public Authorized Product List that agencies check during procurement.
They are the same program. StateRAMP rebranded to GovRAMP in February 2025 to reflect a mission that had grown past state agencies to local, tribal and education buyers. Older authorizations, contract language and state rules still say StateRAMP, and Texas DIR still names StateRAMP Category 1 and Category 2 in its reciprocity rules, so treat the two names as interchangeable when reading procurement documents.
FedRAMP authorizes cloud services for federal agencies and GovRAMP does the same job for state and local government. Both run on NIST SP 800-53 Rev. 5 and both use FedRAMP accredited third party assessors. The practical differences are cost and direction of travel: GovRAMP is cheaper and faster, and it accepts a FedRAMP package through Fast Track with no new audit, while FedRAMP does not accept a GovRAMP package in return.
GovRAMP publishes four verified statuses rather than levels. Core confirms 60 foundational controls reviewed by the PMO with no third party assessor. Ready requires a 3PAO Readiness Assessment Report against the minimum mandatory requirements. Provisionally Authorized covers packages that meet authorization requirements but carry an open dependency or a remediable finding. Authorized is full authorization on a 3PAO Security Assessment Report.
On the fee schedule effective January 1, 2025, a provider under 1 million dollars in revenue pays 500 dollars in member dues plus a PMO fee of 3,500 dollars for Ready or 4,500 dollars for Authorized, rising to 15,750 and 19,500 dollars above 5 million dollars in revenue. Those figures exclude the third party assessor, which is usually the largest cost. Core is quoted between 9,000 and 21,000 dollars depending on which GovRAMP page you read, and includes no 3PAO.
The Authorized Product List is the public register of cloud products holding a Core, Ready, Provisionally Authorized or Authorized status, updated daily on the GovRAMP Program Participants page. Government buyers use it as a shortlist during procurement. GovRAMP has since unified its Authorized and Progressing lists into that single Program Participants list, so products still working toward a status appear there too, marked Progressing, In Process or Pending.
A Core status and a Security Snapshot are each valid for twelve months from issuance. Core can be extended for a further twelve months through an annual assessment completed before expiry, with no limit on the number of extensions. Ready, Provisionally Authorized and Authorized statuses are maintained through continuous monitoring, which includes a monthly executive summary, a monthly POA&M update and an annual 3PAO assessment of roughly one third of the controls.
GovRAMP counts more than twenty three state members, including California, Florida and Georgia, but membership alone does not create a procurement mandate. Two states have gone further. Texas runs its own program, TX-RAMP, which state agencies and public higher education must contract against. North Carolina began requiring executive branch cloud vendors to meet the GovRAMP standard on April 1, 2026, with full compliance due April 1, 2027.
You need it if you sell a cloud computing service, meaning IaaS, PaaS or SaaS, to a Texas state agency or public institution of higher education. Texas Government Code 2054.0593, which came out of Senate Bill 475, bars those bodies from contracting for a cloud service that does not meet TX-RAMP requirements. On premise software and professional services fall outside the scope, and the contracting agency makes the final determination.
Level 1 covers nonconfidential agency data and low impact systems and currently requires 117 NIST SP 800-53 controls. Level 2 covers confidential data and moderate or high impact systems, requires 223 controls, and adds an independent 3PAO assessment with a penetration test of the cloud environment. Level 1 reports vulnerabilities to DIR annually; Level 2 reports quarterly. Both certifications last three years.
There is no TX-RAMP program fee. Texas funds the program itself, so DIR charges nothing to review a submission or grant a certification. Your real costs are internal: assembling the control evidence, and for Level 2 the independent 3PAO assessment and penetration test, which you pay for directly. That makes TX-RAMP one of the cheapest state authorizations to hold and one of the more expensive to reach if your evidence is not already organized.
It satisfies the assessment criteria but no longer gets you listed on its own. Since October 30, 2024, DIR has not automatically added FedRAMP and StateRAMP certified products to the TX-RAMP certified products list. You have to submit an explicit reciprocity request. A FedRAMP Low authorization maps to the Level 1 criteria and a FedRAMP Moderate authorization to the Level 2 criteria, but the mapping only becomes a certification once you file for it.
Eighteen months from the date it is granted. Provisional status lets a Texas agency contract with you while you finish full certification, and it does not renew, so the eighteen months is a working deadline rather than a grace period. Full Level 1 and Level 2 certifications last three years from grant, provided the service stays compliant with program requirements and keeps up its vulnerability reporting.
No. Scrutineer is readiness software, not a third party assessment organization, a program management office or a state authorizing body. Only a GovRAMP approved 3PAO can produce the Readiness Assessment Report or Security Assessment Report, and only GovRAMP and Texas DIR can grant a status. What Scrutineer does is hold the controls and evidence those bodies ask for, map one library across both programs, and keep continuous monitoring current so a status does not lapse.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification