Scrutineer.ai

Scrutineer · By framework

TX-RAMP certification software for Texas DIR vendors

A Texas state agency cannot enter or renew a cloud contract with you unless your service carries the right TX-RAMP certification. That makes this a procurement deadline wearing a security program's clothing.

DIR charges no fee and publishes the whole control baseline, so the assessment is not the hard part. The schedule is. Scrutineer holds your NIST SP 800-53 evidence once, maps it to both certification levels, and keeps the provisional and renewal dates in front of you.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with TX-RAMP

Your provisional runway is twelve months now, not eighteen

This is the number most likely to be wrong in your Texas plan. TX-RAMP Program Manual 4.0 took effect on February 12, 2026 and states that Provisional Certification "is effective for 12 months from the date TX-RAMP grants the provisional certification." Almost every published TX-RAMP guide still says eighteen months, and so does the Frequently Asked Questions page on DIR's own site, which reads "TX-RAMP Provisional Certification may be obtained for a period of 18 months." We are not guessing which one governs: the Program Manual is the document the program is administered under, and the manual is the one that changed. If you built a schedule where provisional status covers a contract while you assemble a Level 2 package, you have six fewer months than the schedule assumes, and the exposure is not yours alone. Provisional status is what lets a state agency contract for your product in the first place.

Texas stopped adding federal authorizations to its list on its own

The most repeated claim about TX-RAMP is that a FedRAMP or GovRAMP authorization carries across automatically. It satisfies the criteria. It has not been automatic since October 30, 2024, when DIR stopped adding FedRAMP and StateRAMP certified products to the TX-RAMP certified products list on its own initiative. Reciprocity is now a change request form you file. Manual 4.0 puts it plainly: a provider that reaches an accepted GovRAMP or FedRAMP status "must submit a change request form notifying TX-RAMP of the status change to receive a full reciprocal TX-RAMP certification." Nothing appears until you file. Teams discover this the way it always gets discovered, when a Texas agency searches the certified products list mid procurement and does not find them. The upside of reciprocity is real, though: a service certified through the FedRAMP or GovRAMP equivalence route is not required to provide continuous monitoring artifacts to TX-RAMP at all.

The certification is free, which is exactly why teams underprice it

DIR charges nothing. Its FAQ states that "there are no fees associated with a TX-RAMP certification, as it is funded by the state of Texas," and once a review actually begins the DIR goal is a recommendation within four weeks. So the cost is entirely on your side of the line: a Level 1 package answers 117 controls and Level 2 answers 223, drawn from NIST SP 800-53, submitted with a Security Plan Workbook and a POA&M. Two details change the math and are almost never published. Recertification does not repeat the full baseline: Manual 4.0 sets it at 38 control requirements for Level 1 and 48 for Level 2. And the renewed certificate expires three years from the previous expiration date "regardless of when the recertification process is complete," so every month you let slide is a month of certification you simply do not get back.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Holds one NIST SP 800-53 control library and maps it to the TX-RAMP Level 1 and Level 2 baselines at the same time, so a second state program is a review rather than a rebuild
  • Tracks which of your controls answer the 117 Level 1 requirements and the 223 Level 2 requirements, by control family, with the evidence attached to each
  • Runs the provisional clock as a deadline you can see, on the twelve month figure Program Manual 4.0 sets rather than the eighteen months still published elsewhere
  • Flags the reciprocity change request that a FedRAMP or GovRAMP status does not file for you, so you are not missing from the certified products list during a procurement
  • Keeps the Security Plan Workbook, the Acknowledgment and Inventory responses and a live POA&M current instead of rebuilt at submission time
  • Schedules the quarterly Level 2 or annual Level 1 vulnerability reporting SPECTRIM asks for, with the remediation and mitigation notes attached
  • Watches the recertification window that opens twelve months before expiry, and scopes it to the 38 or 48 control requirements recertification actually reviews
  • Reuses the same evidence for SOC 2, ISO 27001, FedRAMP and GovRAMP, because a Texas assessment tests controls your other frameworks already test
TX-RAMP readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

TX-RAMP deadline reference

Every TX-RAMP clock, what Program Manual 4.0 sets it to, and where the published figure is wrong

Guides to this program describe the certification. The certification is free and the controls are published, so it is rarely what costs anyone a contract. What costs contracts is a set of dates that live in different sections of the Program Manual and have never been put in one table, including one figure that changed in February 2026 and has not propagated, not even to the FAQ page DIR itself publishes.

TX-RAMP obligation What Program Manual 4.0 sets What starts the clock What is widely published What it costs you to miss
Provisional certification window 12 months from the date TX-RAMP grants it TX-RAMP approving your Acknowledgment and Inventory Questionnaire 18 months, including on DIR's own FAQ page Full certification is due at the end of the window, and the agency contract that provisional status enabled is what is exposed
Level 1 and Level 2 certification Valid 3 years from the date the certification was conferred The date certification is granted, not the date you submitted Stated correctly in most places The service is removed from the TX-RAMP certified products list
Recertification window May be initiated 12 months before expiry, with reminders at 12 months and 90 days An automated SPECTRIM email to your listed point of contact Rarely mentioned at all If no action is taken by the expiration date the certification simply expires
Recertification scope 38 control requirements at Level 1, 48 at Level 2 Your recertification A&I submission Usually described as repeating the full 117 or 223 controls Teams budget and staff a full reassessment they do not owe
Recertification expiry math The new certificate runs 3 years from the previous expiration date regardless of when you finish The old certificate, not the new one Almost never published Every month of delay is certification time you paid for in effort and do not receive
Level 2 continuous monitoring Quarterly vulnerability reports through SPECTRIM The certification grant Often stated as annual for both levels TX-RAMP may require greater frequency or revoke the certification
Level 1 continuous monitoring Annual vulnerability reports through SPECTRIM The certification grant Usually correct The same revocation exposure applies
FedRAMP or GovRAMP reciprocity A change request form you file. Nothing is added on your behalf You, when you file it Widely described as automatic You never reach the certified products list, and the agency checking it mid procurement cannot find you

Figures are taken from the TX-RAMP Program Manual version 4.0, effective February 12, 2026, and from the TX-RAMP Frequently Asked Questions published by the Texas Department of Information Resources. Where the two disagree, as they do on the provisional window, the manual is cited and the difference is shown rather than resolved silently. Program rules change and House Bill 150 moves these duties to Texas Cyber Command over time, so confirm your own dates with DIR. Scrutineer prepares readiness evidence and does not grant TX-RAMP certification.

Good questions

Questions about TX-RAMP

TX-RAMP is the Texas Risk and Authorization Management Program, run by the Texas Department of Information Resources. Texas Government Code Section 2063.408 requires state agencies to contract only for cloud computing services that comply with TX-RAMP, so certification is what makes your product contractable in Texas. Certified services appear on a public certified products list that agencies check during procurement.
DIR charges nothing. Its FAQ states there are no fees associated with a TX-RAMP certification because the program is funded by the state of Texas. The real cost is internal: assembling evidence for 117 controls at Level 1 or 223 at Level 2, writing the Security Plan Workbook and POA&M, and maintaining vulnerability reporting afterward. Published third-party estimates for a full Level 2 documentation package vary widely, so treat any single figure with caution.
There are three certification types. Provisional Certification comes from an approved Acknowledgment and Inventory Questionnaire and now runs 12 months under Program Manual 4.0. Level 1 covers low impact information resources and assesses 117 controls. Level 2 covers moderate or high impact resources and assesses 223 controls. Level 1 and Level 2 certifications are valid for three years.
Your cloud service has to meet a NIST SP 800-53 based control baseline sized to the data it handles, and you have to evidence it. That means an approved Acknowledgment and Inventory Questionnaire, the Level 1 or Level 2 Assessment Questionnaire, a completed TX-RAMP Security Plan Workbook, and a Plan of Action and Milestones for anything not yet closed. After certification you owe continuous monitoring.
Once a review actually begins, DIR's stated goal is to complete the review and issue a recommendation within four weeks. That figure describes the review, not your preparation, which is where the months go. The clock that matters more is provisional status: 12 months from the date it is granted, by which point full certification is required.
Provisional Certification is granted after TX-RAMP approves your Acknowledgment and Inventory Questionnaire, and it lets a state agency contract for your product while you complete a full assessment. Program Manual 4.0, effective February 12, 2026, sets it at 12 months from the grant date. Older guidance and DIR's own FAQ page still say 18 months, so plan against the manual.
It satisfies the criteria, but it does not certify you by itself. Since October 30, 2024 DIR no longer adds FedRAMP or StateRAMP certified products to the TX-RAMP list automatically. You have to submit a change request form to receive a full reciprocal TX-RAMP certification. Services certified through that route are not required to provide continuous monitoring artifacts to TX-RAMP.
Level 1 assesses 117 controls and enhancements, and Level 2 assesses 223, per Appendix A of Program Manual 4.0. The largest Level 2 families are Access Control at 33, System and Communications Protection at 23 and Configuration Management at 21. Personnel Security is the only family with the same count at both levels, at 8.
Level 2 is the certification for cloud services handling confidential or regulated state data in moderate or high impact systems. It assesses 223 NIST SP 800-53 controls and enhancements, and it carries the heavier ongoing obligation: quarterly vulnerability reports submitted through SPECTRIM, against annual reporting at Level 1.
If a Texas state agency, public institution of higher education or public community college is contracting for or renewing a contract for your cloud computing service, yes. The requirement sits on the agency, which may only enter or renew cloud contracts that comply with TX-RAMP, which is why it lands on you as a procurement condition rather than a regulator letter.
You submit the Acknowledgment and Inventory Questionnaire, which can yield provisional certification. You then complete the Level 1 or Level 2 Assessment Questionnaire with a Security Plan Workbook and a POA&M. TX-RAMP reviews and issues a recommendation, targeted at four weeks once the review begins. Certification lasts three years, with vulnerability reporting throughout.
Fast Track lets TX-RAMP assess you at its discretion using an independent third-party certification, assessment or audit report you already hold, rather than a fresh review of everything. You submit a Fast Track Request Form, TX-RAMP decides whether the artifacts qualify, then sends a Fast Track questionnaire. Continuous monitoring obligations are identical to the standard route.
Certifications run three years. Your point of contact gets an automated notice 12 months before expiry and again at 90 days, and you can start at the 12 month mark. Recertification reviews 38 control requirements at Level 1 and 48 at Level 2, not the full baseline. The renewed certificate expires three years from the previous expiration date regardless of when you finish.
TX-RAMP is a Texas state program administered by DIR and required by Texas statute. GovRAMP, formerly StateRAMP, is a nonprofit program serving state, local, tribal and education buyers across many states. A GovRAMP authorization can support a reciprocal TX-RAMP certification, but only after you file the change request, and Texas rules still name the StateRAMP categories.
Program Manual 4.0 notes that House Bill 150, passed in 2025, creates Texas Cyber Command and transfers DIR's cybersecurity duties to it, TX-RAMP included. The manual also records that DIR continues to perform those duties until a memorandum between Texas Cyber Command and DIR identifies that all responsibilities must transfer. In practice you still work with DIR today, and the administering body is expected to change.
Yes. TX-RAMP reserves the right to revoke certification at its discretion, and failure to maintain baseline compliance will result in revocation. Named triggers include failing to report significant changes in a timely manner and failing to provide required continuous monitoring documents. A state agency can also file a grievance if it has credible information that a provider has deviated from program requirements.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification