Framework Cloud & Government Authorization
TX-RAMP
TX-RAMP (Texas Risk and Authorization Management Program) is the Texas Department of Information Resources program that certifies cloud computing services before Texas state agencies, public universities and community colleges may contract for them. It was created under Texas Government Code section 2054.0593.
There are two certification levels, Level 1 for public or low-impact data and Level 2 for confidential or moderate and high-impact data, plus a Provisional certification valid for 18 months that lets procurement proceed while full certification is pursued. The contracting agency decides the level required.
Unlike FedRAMP, DIR performs the assessment itself from the provider's questionnaire responses and supporting evidence; engaging a 3PAO is not required. In writing, a provider needs control responses to the TX-RAMP assessment criteria (drawn from NIST SP 800-53), security policies and procedures, an incident response plan and vulnerability management reporting.
FedRAMP and GovRAMP authorizations no longer convert automatically; since October 30, 2024 providers must submit a reciprocity request that DIR validates.
help
Who has to comply
Cloud service providers whose services are procured by Texas state agencies, institutions of higher education and public community colleges, when the service is a cloud computing service under the statute. Agencies may not contract for in-scope services without an appropriate certification.
What the assessor asks to see
Completed TX-RAMP assessment questionnaire for the required level; system description and boundary; security policies and procedures mapped to the criteria; vulnerability scan results; incident response plan; evidence of encryption, access control and logging; for reciprocity, the FedRAMP or GovRAMP authorization letter and package.
Levels
Level 1: nonconfidential or low-impact agency data. Level 2: confidential data or moderate and high-impact systems. Provisional: an interim status valid 18 months for services under evaluation.
Certifications are granted by DIR and listed on the DIR TX-RAMP site; check the current Program Manual for out-of-scope service types.
Assessors
Who assesses TX-RAMP
Government reviewer: DIR staff assess the provider's questionnaire responses and evidence. No third-party assessor is required, though FedRAMP or GovRAMP 3PAO packages can be submitted for reciprocity. DIR is the program authority.
No firm has claimed a TX-RAMP assessor listing yet. Claim yours →
Consultants
Who helps with TX-RAMP
A small ecosystem: GRC platforms and consultants help complete the assessment questionnaire, map existing FedRAMP, GovRAMP or SOC 2 evidence, and prepare reciprocity requests. Engagements are usually short because DIR reviews the submission directly.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a TX-RAMP consultant listing yet. Claim yours →
Software
Tools for TX-RAMP
Tools that name this framework in their own material.
No firm has claimed a TX-RAMP tool listing yet. Claim yours →
Related reading
- TX-RAMP guidance for cloud purchasesA covered institution explains the certification levels and how it checks vendor status before a purchase goes through.University of Houston System
- TX-RAMP information for faculty and staffShows the buyer's side of the process, including what happens when a product has no certification yet.University of Texas at San Antonio
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for TX-RAMP
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with TX-RAMP
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.