Scrutineer · By framework
TX-RAMP certification software for Texas DIR vendors
A Texas state agency cannot enter or renew a cloud contract with you unless your service carries the right TX-RAMP certification. That makes this a procurement deadline wearing a security program's clothing.
DIR charges no fee and publishes the whole control baseline, so the assessment is not the hard part. The schedule is. Scrutineer holds your NIST SP 800-53 evidence once, maps it to both certification levels, and keeps the provisional and renewal dates in front of you.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with TX-RAMP
Your provisional runway is twelve months now, not eighteen
This is the number most likely to be wrong in your Texas plan. TX-RAMP Program Manual 4.0 took effect on February 12, 2026 and states that Provisional Certification "is effective for 12 months from the date TX-RAMP grants the provisional certification." Almost every published TX-RAMP guide still says eighteen months, and so does the Frequently Asked Questions page on DIR's own site, which reads "TX-RAMP Provisional Certification may be obtained for a period of 18 months." We are not guessing which one governs: the Program Manual is the document the program is administered under, and the manual is the one that changed. If you built a schedule where provisional status covers a contract while you assemble a Level 2 package, you have six fewer months than the schedule assumes, and the exposure is not yours alone. Provisional status is what lets a state agency contract for your product in the first place.
Texas stopped adding federal authorizations to its list on its own
The most repeated claim about TX-RAMP is that a FedRAMP or GovRAMP authorization carries across automatically. It satisfies the criteria. It has not been automatic since October 30, 2024, when DIR stopped adding FedRAMP and StateRAMP certified products to the TX-RAMP certified products list on its own initiative. Reciprocity is now a change request form you file. Manual 4.0 puts it plainly: a provider that reaches an accepted GovRAMP or FedRAMP status "must submit a change request form notifying TX-RAMP of the status change to receive a full reciprocal TX-RAMP certification." Nothing appears until you file. Teams discover this the way it always gets discovered, when a Texas agency searches the certified products list mid procurement and does not find them. The upside of reciprocity is real, though: a service certified through the FedRAMP or GovRAMP equivalence route is not required to provide continuous monitoring artifacts to TX-RAMP at all.
The certification is free, which is exactly why teams underprice it
DIR charges nothing. Its FAQ states that "there are no fees associated with a TX-RAMP certification, as it is funded by the state of Texas," and once a review actually begins the DIR goal is a recommendation within four weeks. So the cost is entirely on your side of the line: a Level 1 package answers 117 controls and Level 2 answers 223, drawn from NIST SP 800-53, submitted with a Security Plan Workbook and a POA&M. Two details change the math and are almost never published. Recertification does not repeat the full baseline: Manual 4.0 sets it at 38 control requirements for Level 1 and 48 for Level 2. And the renewed certificate expires three years from the previous expiration date "regardless of when the recertification process is complete," so every month you let slide is a month of certification you simply do not get back.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Holds one NIST SP 800-53 control library and maps it to the TX-RAMP Level 1 and Level 2 baselines at the same time, so a second state program is a review rather than a rebuild
- Tracks which of your controls answer the 117 Level 1 requirements and the 223 Level 2 requirements, by control family, with the evidence attached to each
- Runs the provisional clock as a deadline you can see, on the twelve month figure Program Manual 4.0 sets rather than the eighteen months still published elsewhere
- Flags the reciprocity change request that a FedRAMP or GovRAMP status does not file for you, so you are not missing from the certified products list during a procurement
- Keeps the Security Plan Workbook, the Acknowledgment and Inventory responses and a live POA&M current instead of rebuilt at submission time
- Schedules the quarterly Level 2 or annual Level 1 vulnerability reporting SPECTRIM asks for, with the remediation and mitigation notes attached
- Watches the recertification window that opens twelve months before expiry, and scopes it to the 38 or 48 control requirements recertification actually reviews
- Reuses the same evidence for SOC 2, ISO 27001, FedRAMP and GovRAMP, because a Texas assessment tests controls your other frameworks already test
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
TX-RAMP deadline reference
Every TX-RAMP clock, what Program Manual 4.0 sets it to, and where the published figure is wrong
Guides to this program describe the certification. The certification is free and the controls are published, so it is rarely what costs anyone a contract. What costs contracts is a set of dates that live in different sections of the Program Manual and have never been put in one table, including one figure that changed in February 2026 and has not propagated, not even to the FAQ page DIR itself publishes.
| TX-RAMP obligation | What Program Manual 4.0 sets | What starts the clock | What is widely published | What it costs you to miss |
|---|---|---|---|---|
| Provisional certification window | 12 months from the date TX-RAMP grants it | TX-RAMP approving your Acknowledgment and Inventory Questionnaire | 18 months, including on DIR's own FAQ page | Full certification is due at the end of the window, and the agency contract that provisional status enabled is what is exposed |
| Level 1 and Level 2 certification | Valid 3 years from the date the certification was conferred | The date certification is granted, not the date you submitted | Stated correctly in most places | The service is removed from the TX-RAMP certified products list |
| Recertification window | May be initiated 12 months before expiry, with reminders at 12 months and 90 days | An automated SPECTRIM email to your listed point of contact | Rarely mentioned at all | If no action is taken by the expiration date the certification simply expires |
| Recertification scope | 38 control requirements at Level 1, 48 at Level 2 | Your recertification A&I submission | Usually described as repeating the full 117 or 223 controls | Teams budget and staff a full reassessment they do not owe |
| Recertification expiry math | The new certificate runs 3 years from the previous expiration date regardless of when you finish | The old certificate, not the new one | Almost never published | Every month of delay is certification time you paid for in effort and do not receive |
| Level 2 continuous monitoring | Quarterly vulnerability reports through SPECTRIM | The certification grant | Often stated as annual for both levels | TX-RAMP may require greater frequency or revoke the certification |
| Level 1 continuous monitoring | Annual vulnerability reports through SPECTRIM | The certification grant | Usually correct | The same revocation exposure applies |
| FedRAMP or GovRAMP reciprocity | A change request form you file. Nothing is added on your behalf | You, when you file it | Widely described as automatic | You never reach the certified products list, and the agency checking it mid procurement cannot find you |
Figures are taken from the TX-RAMP Program Manual version 4.0, effective February 12, 2026, and from the TX-RAMP Frequently Asked Questions published by the Texas Department of Information Resources. Where the two disagree, as they do on the provisional window, the manual is cited and the difference is shown rather than resolved silently. Program rules change and House Bill 150 moves these duties to Texas Cyber Command over time, so confirm your own dates with DIR. Scrutineer prepares readiness evidence and does not grant TX-RAMP certification.
Good questions
Questions about TX-RAMP
Keep reading
Guides that go deeper on this framework
TX-RAMP certification cost and timeline
What DIR charges, what the work actually costs you, and the deadlines that decide the schedule.
Read the guideGovRAMP certification cost
The published fee schedule, what the 3PAO adds, and which status is cheapest to reach.
Read the guideGovRAMP and StateRAMP
What changed in the rename, and which name your contracts and state rules still use.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification