Arizona Retires AZRAMP for GovRAMP NIST 800-53
The migration makes Arizona the third state to abandon a proprietary cloud security program for the national GovRAMP framework, with hard compliance deadlines beginning July 2025 for new contracts.
TL;DR
Arizona is sunsetting its AZRAMP cloud security program and migrating all vendor authorizations to GovRAMP, requiring NIST 800-53-based assessments for new state contracts starting July 1, 2025, and for renewals by July 1, 2026. Existing AZRAMP authorizations remain valid until they expire, but there will be no further AZRAMP renewals. At expiration, vendors must hold GovRAMP or FedRAMP status. Arizona becomes the third state to fold its homegrown assessment regime into the GovRAMP umbrella, accelerating the consolidation away from state-by-state cloud security programs.

Arizona's State Procurement Office announced the formal transition from AZRAMP to GovRAMP, the nonprofit also operating as StateRAMP, making it the third state to retire a proprietary cloud security assessment program in favor of the national framework. The move aligns Arizona's vendor risk management with NIST 800-53 and GovRAMP's established verification pathway, which already underpins similar mandates in states like Texas and North Carolina.
The deadline structure is two-tiered. New contracts executed on or after July 1, 2025 must include risk assessment requirements aligned with GovRAMP and NIST 800-53. Renewal contracts follow a year later, July 1, 2026, and may also accept FedRAMP authorization as an alternative. Grace periods for reaching the appropriate GovRAMP terminal status are set per-solicitation rather than by blanket rule, but the program FAQ provides baseline expectations: roughly 12 months to reach Core, 12 to 18 months for Ready, and 18 to 24 months for Authorized.
What happens to existing AZRAMP authorizations
Vendors holding an active AZRAMP authorization don't face an immediate cliff. The program page confirms existing AZRAMP statuses remain valid until they expire. But there will be no further AZRAMP renewals. At expiration, the vendor must hold an appropriate GovRAMP or FedRAMP status as determined by the Arizona Department of Homeland Security. The state is also not accepting SOC 2, ISO 27001, HITRUST, or TX-RAMP as substitutes; Arizona's position, citing the 2018 National Cyber Strategy, is that NIST is the sole authorized cybersecurity framework for assessing cloud service environments.
A consolidation signal, not an anomaly
Arizona isn't the first state to make this move, and it won't be the last. GovRAMP's board president is J.R. Sloan, Arizona's own CIO, which signals how closely state IT leadership is aligning behind the framework. For cloud vendors selling into multiple states, each migration from a bespoke program to GovRAMP reduces the compliance matrix by one row, replacing a state-specific authorization with a single assessment that satisfies requirements across participating governments.
The practical question for vendors is timing. If you hold an expiring AZRAMP authorization, the GovRAMP verification process needs to begin now. The 12-to-24-month terminal status timelines mean waiting until your AZRAMP status lapses could leave you unable to bid on Arizona contracts during the gap. Vendors without any current authorization who want to pursue new Arizona business after July 1, 2025 should enroll in GovRAMP's Progressing Snapshot program, which allows data processing to begin before a terminal status is reached, provided quarterly progress is demonstrated.
Published ·Deep Fathom