Minnesota mandates GovRAMP moderate authorization for cloud vendors
The fourth state to adopt the FedRAMP-modeled framework as a procurement requirement, and Minnesota's version is notably rigid: SOC 2, ISO 27001, and TX-RAMP won't substitute.
TL;DR
Minnesota now requires GovRAMP moderate-impact authorization for cloud products processing high-risk state data. Vendors must submit a Snapshot score within 60 days of contract execution and achieve full authorization by April 1, 2027. Scores below 100% trigger mandatory enrollment in a remediation program with quarterly re-scoring, monthly advisory calls, and continuous monitoring access granted to Minnesota IT Services. SOC 2, ISO 27001, HITRUST, and TX-RAMP are explicitly rejected as substitutes; only GovRAMP or FedRAMP Rev 5 counts. Minnesota is the fourth state to mandate the framework in procurement.
Minnesota has adopted GovRAMP as a mandatory procurement requirement for cloud contracts handling high-risk state data, making it the fourth state to embed the FedRAMP-modeled framework into its contracting process. Arizona, Indiana, and Massachusetts preceded it; eleven states now use GovRAMP in some form, but mandating it as a contract condition is a narrower club.
The requirement applies to any IaaS, PaaS, or SaaS product that processes, transmits, or stores what Minnesota defines as high-risk data. That definition is one of the more granular in state procurement: it enumerates HIPAA-protected PHI, Social Security Administration data, Criminal Justice Information under the FBI CJIS Security Policy, Federal Tax Information under IRS Publication 1075, PCI account data, and government-issued ID numbers including driver's licenses and passports. A vendor unsure of its data classification is directed to contact the requesting agency or Minnesota's Vendor Security and Risk Management team.
The compliance clock starts at contract execution
Vendors who don't hold an existing GovRAMP or FedRAMP Rev 5 authorization must submit a GovRAMP Snapshot score within 60 days of contract execution. A score below 100% triggers mandatory enrollment in the Progressing Snapshot Program, a paid subscription that delivers quarterly re-scoring and monthly one-hour consultative calls with GovRAMP's security team. The state also requires access to all progress reports and updated Snapshot scores until the vendor hits 100%. Full moderate-impact authorization must be achieved by April 1, 2027. GovRAMP Core, Ready, or Authorized at the low-impact level can substitute in the interim, but continuous monitoring access must be granted to Minnesota IT Services and maintained until moderate authorization is reached.
SOC 2, ISO 27001, and TX-RAMP are explicitly out
Minnesota's program draws a hard line on substitutes. The state will accept only GovRAMP or FedRAMP Rev 5, not TX-RAMP, SOC 2, ISO 27001, HITRUST, or self-attestations. The stated rationale cites the 2018 National Cyber Strategy's identification of NIST as the sole cybersecurity framework for assessing SaaS, PaaS, or IaaS environments. This is a tighter gate than many vendors might expect, particularly those who'd assumed TX-RAMP reciprocity would carry over or that a SOC 2 report would satisfy a state-level cloud security review. GovRAMP does provide a Fast Track for products already holding or pursuing FedRAMP Rev 5: no need to re-engage a 3PAO, just submit the existing security package to the GovRAMP PMO after enrolling as a member.
For cloud vendors bidding on Minnesota state work, the immediate to-do is data-classification triage. If your product touches any of the enumerated high-risk categories, you'll need a GovRAMP membership and a Snapshot submission within two months of winning the contract. Membership fees range from $1,500 to $10,000 and Snapshots from $1,000 to $2,500 depending on revenue tier, with the remediation subscription running $750 to $1,600 per month. For a small vendor, that's a material cost to bake into the bid.
Published ·Deep Fathom