Quick answer
A nonprofit program modeled on FedRAMP that certifies cloud services for use by state and local governments.
StateRAMP is a nonprofit organization founded in 2020 to bring a standardized security authorization framework to the state, local, education, and tribal (SLED) government market. It mirrors the structure of the federal FedRAMP program, applying NIST SP 800-53 controls to cloud products procured by non-federal government entities. Unlike FedRAMP, StateRAMP is not created by federal law; states, localities, and other public entities adopt it voluntarily through their own procurement policies.
What is StateRAMP?
StateRAMP operates by requiring cloud service providers to undergo a security assessment conducted by an approved Third Party Assessment Organization (3PAO). Assessments follow NIST SP 800-53 control baselines organized into three security impact levels: Low, Moderate, and High, corresponding to the sensitivity of the data the system will handle.
Products that complete the process are listed on the StateRAMP Authorized Product List (APL), a publicly searchable registry that procurement officers across participating jurisdictions can consult when evaluating cloud vendors. Continuous monitoring requirements apply after initial authorization, obligating vendors to submit monthly vulnerability scans and annual assessments to maintain their listing.
As of 2024, more than 20 states have adopted StateRAMP policies, with some states making authorization a mandatory condition of award for cloud products that process sensitive government data. Jurisdictions without a formal StateRAMP mandate often reference the APL as a preferred evaluation tool, giving authorized vendors a competitive advantage even where the requirement is not yet codified.
Why it matters for contractors
Cloud service providers targeting the SLED market face a growing expectation that they hold StateRAMP authorization, particularly for products that handle personally identifiable information (PII), criminal justice data, or health records. States that have codified StateRAMP as a requirement will reject bids from vendors whose products do not appear on the APL, regardless of other security documentation the vendor submits.
Pursuing StateRAMP authorization requires a meaningful investment: engaging a 3PAO, completing a System Security Plan (SSP), and remediating findings before listing. However, the authorization transfers across participating states, so a single StateRAMP Moderate authorization can open procurement doors in all adopting jurisdictions simultaneously. For vendors already holding a FedRAMP authorization, the overlap in control frameworks reduces the marginal cost of obtaining StateRAMP status.
Contractors bidding on SLED contracts should review the procurement requirements of each state or locality and identify whether StateRAMP authorization is mandatory, preferred, or not yet addressed. Tracking state-level policy adoption is important because the landscape is shifting quickly.
Example
A GovTech startup has built a cloud-based permitting and licensing platform and wants to sell it to county governments across multiple states. The startup engages a 3PAO for a StateRAMP Moderate assessment, remediates identified gaps, and receives authorization. Its platform appears on the StateRAMP APL. When a state procurement officer evaluates bids for a statewide permitting system, she checks the APL, confirms the platform is authorized at the Moderate level, and accepts the vendor's security posture without requiring a separate audit. The authorization is valid across all states that recognize StateRAMP, giving the startup access to a broad public-sector market from a single compliance effort.
How Bidovate helps
Bidovate puts StateRAMP to work inside your capture and proposal workflow.
Find SLED opportunitiesSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
FedRAMP (Federal Risk and Authorization Management Program)
FedRAMP is the federal government's standardized security authorization program for cloud services, enabling agencies to use cloud products that have been pre-approved for federal use.
ViewFedRAMP Moderate
The FedRAMP authorization baseline for cloud services handling government data where a breach would cause serious adverse effects.
ViewSLED Market (State, Local, Education)
The SLED market refers to State, Local, and Education procurement, a $1.5 trillion annual market that is twice the size of the federal contract market and operates under 50 different state procurement codes.
View