📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

GovRAMP (formerly StateRAMP)

The same cloud-security program for products sold to state and local government · renamed in 2025

GovRAMP is a standardized security assessment and authorization program for cloud products sold to US state and local government, the way FedRAMP works for federal agencies. It was called StateRAMP until 2025; the name changed, nothing underneath it did. Its verification ladder runs Security Snapshot, Core, Ready, Provisional, and Authorized. You do not need a government sponsor to get on it.

Map to the GovRAMP baselineSee the ladder

What are the GovRAMP verification levels?

There are five, and they are a ladder, not a menu. Each one adds evidence and cost, so a provider climbs only as far as its buyers actually require. The two lowest rungs need neither a sponsor nor a paid assessor, which is exactly where most of the sponsor myth falls apart.

LevelWhat it confirms3PAO?Sponsor?
Security SnapshotEarly benchmarking against the Ready requirements, scored on critical NIST 800-53 Rev 5 controlsNoNo
CoreImplementation of 60 foundational NIST controls, selected via MITRE ATT&CK and aligned to the Moderate baselineNoNo
ReadyMeets the Minimum Mandatory Requirements; the first rung an independent assessor must verifyYesNot required
ProvisionalMeets the authorization bar but relies on a technology not yet GovRAMP- or FedRAMP-authorizedYesAuthorizing decision
AuthorizedFull compliance with the required controls for the impact levelYesAuthorizing decision

A 3PAO — an independent, GovRAMP-recognized assessor the provider engages and pays — first enters at Ready. Below that, Snapshot and Core are provider-driven, so a vendor can show a real, scored security posture to a procurement officer before spending on an assessment.

Do you need a government sponsor to start?

No, and this is the myth that stops vendors before they begin. You can reach Snapshot, Core, and Ready without any government sponsoring you.

Many providers do work directly with a sponsoring government, and that is a legitimate path. But a provider without one is not locked out: the GovRAMP Approvals Committee acts as the authorizing body on behalf of participating governments, so the authorizing decision that Provisional and Authorized require can come from the Committee rather than from a specific agency willing to sponsor you. If a sales conversation has stalled on "we would need a government to sponsor us first," that premise is wrong for the lower rungs and optional for the top ones.

Where a sponsor does exist, they must be a CIO or designee from a government entity and a GovRAMP Individual Government Member before they can sponsor a product. That is the sponsor's requirement, not yours.

What changed when StateRAMP became GovRAMP?

The name, and nothing that affects a compliance decision. StateRAMP was renamed GovRAMP in 2025 to reflect that it now serves cities, counties, states, and other government bodies rather than states alone.

It is the same organization with the same leadership and program. Statuses, requirements, pricing, and existing authorizations all carried across unchanged, so a product that held a StateRAMP status holds the equivalent GovRAMP status, and a procurement document that still says StateRAMP is asking for the same thing. This is the last time this page uses the old name; everywhere else it is GovRAMP.

How Lavawall® helps with GovRAMP

GovRAMP is mostly NIST SP 800-53 controls you have to implement, evidence, and then keep evidencing through a continuous-monitoring cycle. That continuous part is where point-in-time paperwork falls down. Lavawall runs the technical controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to the GovRAMP baseline for your target impact level, and keeps timestamped evidence current instead of reassembled the week before a review.

  • Map your product or program to the GovRAMP baseline and see the gap to Snapshot, Core, or Ready from one shared control library.
  • Remediate with the same platform — patching, configuration hardening, breach detection, backups, and access review — rather than a separate project.
  • Evidence continuously, with exportable records a 3PAO and a continuous-monitoring reviewer accept.

Because GovRAMP leans on the same NIST 800-53 base as CJIS and IRS Publication 1075, mapping once satisfies much of all three. Lavawall does not represent that it currently holds a specific GovRAMP status; it maps and evidences against the baseline, and will give you its accurate current position if your procurement needs it.

Related

Primary source: GovRAMP (formerly StateRAMP). Last verified August 27, 2026.

Frequently asked questions

Is GovRAMP the same thing as StateRAMP?

Yes. StateRAMP was renamed GovRAMP in 2025 to reflect its use across all levels of government. It is the same organization with the same leadership, and statuses, requirements, pricing, and existing authorizations all carried over unchanged. A product listed under the old name is the same product.

What are the GovRAMP verification levels?

Five, lowest to highest: Security Snapshot (early benchmarking), Core (implementation of 60 foundational NIST SP 800-53 controls), Ready (meets the Minimum Mandatory Requirements), Provisional (meets the authorization bar but depends on a technology not yet authorized), and Authorized (full compliance for the impact level).

Do I need a government sponsor to earn a GovRAMP status?

No. Many providers work directly with a sponsoring government, but a provider without one can use the GovRAMP Approvals Committee, which acts as the authorizing body on behalf of participating governments. The belief that you need a sponsor before you can start is the single most common GovRAMP myth.

When is a third-party assessor (3PAO) first required?

At the Ready level. Security Snapshot and Core are provider-driven; a Ready or Authorized status requires an independent GovRAMP-recognized 3PAO, which the provider engages and pays for. Snapshot and Core let a provider show real progress before taking on that cost.

What is a GovRAMP Security Snapshot?

An early-stage self-assessment that scores a product against the Ready-level requirements using a standardized methodology based on critical NIST SP 800-53 Revision 5 controls. It is the entry point on the ladder and needs neither a 3PAO nor a sponsor.

When does a municipality or its vendor need GovRAMP?

GovRAMP is aimed at cloud products sold to state and local government, much as FedRAMP is for federal. An agency encounters it when it procures cloud services; a vendor needs a status to sell into that market. Whether it is mandatory depends on the individual government's procurement rules, not on GovRAMP itself.

Does Lavawall hold a GovRAMP Authorized status?

Lavawall maps your product or program to the GovRAMP baseline and keeps continuous, timestamped evidence for the continuous-monitoring cycle rather than a point-in-time snapshot. For Lavawall's own current status on the GovRAMP ladder, ask us and we will give you the accurate answer rather than a marketing one.

Data residency: We place your data and our AI processing in the region your obligations require: Canada, the United States, Europe, or Australia. How data residency works →