govrampregulatorNewsThe Broadside2 min read

Nevada Mandates GovRAMP Core for Cloud Contracts

Nevada's new cloud security mandate requires GovRAMP Core. SOC 2, ISO 27001, TXRAMP, and HITRUST won't cut it.


TL;DR

Starting July 1, 2026, all new Nevada executive-branch cloud contracts must include GovRAMP Core certification at minimum, the state's Government Technology Office announced. The mandate, built on NIST SP 800-53 Rev 5, covers all three cloud service models. Vendors get a 12-month on-ramp from contract execution to achieve Core; FedRAMP Rev 5 holders can use a Fast Track process. As of July 1, 2028, the on-ramp disappears. Nevada explicitly rejects TXRAMP, SOC 2, ISO 27001, and HITRUST as substitutes.

Nevada Mandates GovRAMP Core for Cloud Contracts
Editorial illustration · drawn by The Broadside

Nevada is the first state to mandate the GovRAMP framework across all executive-branch cloud procurement, a move that replaces agency-by-agency security reviews with a single transferable credential built on NIST SP 800-53 Rev 5. For cloud vendors selling to state government, the patchwork just got one patch smaller. For other states watching from the sidelines, Nevada is now the test case for whether a standardized, NIST-based verification model can work at the state level without fragmenting into 50 slightly different flavors of the same thing.

The On-Ramp and the Cliff

The mandate takes effect July 1, 2026 for all new contracts containing a cloud component. At minimum, products must achieve GovRAMP Core, an independent assessment against a subset of NIST 800-53 Rev 5 controls. Where the data sensitivity warrants it, Nevada can require the higher Authorized or Provisionally Authorized tier.

Vendors without an existing GovRAMP status at contract award must enroll in the Progressing Snapshot program within 45 days and submit quarterly updates. They have 12 months to reach Core, or 24 months for Authorized. After July 1, 2028, the on-ramp disappears entirely. Certification must be in hand before the contract is signed.

FedRAMP Rev 5 holders get an accelerated path: submit the existing security package to the GovRAMP PMO within 30 days of award and pursue GovRAMP Authorized status through the Fast Track process. It's not full reciprocity, but it avoids re-engaging a 3PAO.

What Nevada Won't Accept

Nevada's FAQ is unusually blunt about what won't substitute. TXRAMP, SOC 2, ISO 27001, and HITRUST are all explicitly rejected. The state cites the 2018 National Cyber Strategy's identification of NIST as the sole cybersecurity framework for assessing cloud environments. For vendors that built their compliance programs around SOC 2 or ISO 27001, particularly smaller shops, the message is blunt. Those investments don't translate.

Less clear is whether GovRAMP authorizations earned through other participating states satisfy Nevada's requirements. GovRAMP's value proposition is "verify once, serve many," and the program page states that product validation "can be used with any of our participating government members." But Nevada's FAQ doesn't confirm cross-state reciprocity, and the requirement that vendors work through the state's Government Technology Office suggests some Nevada-specific process is involved. That's the question multi-state vendors most need answered before July 2026.


Published ·Deep Fathom