North Carolina Cloud Contracts Require GovRAMP by April 1
Six weeks out from the deadline, North Carolina hasn't specified which GovRAMP tier satisfies its new cloud contract mandate.
TL;DR
North Carolina's Department of Information Technology will require GovRAMP authorization for all new executive-branch contracts with cloud components starting April 1, 2026. The mandate, announced February 18, aligns with NIST 800-53 security controls and applies to IaaS, PaaS, and SaaS providers. Authorization is transferable across state agencies: a vendor verified once can serve any participating North Carolina agency. But with roughly six weeks between announcement and deadline, and no word yet on which GovRAMP tier satisfies the requirement, vendors without a prior FedRAMP or state authorization face a narrow path.

North Carolina's Department of Information Technology announced February 18 that all new executive-branch contracts with cloud components will require GovRAMP authorization, effective April 1, 2026. The mandate aligns with NIST 800-53 security controls and covers IaaS, PaaS, and SaaS offerings. That gives cloud vendors roughly six weeks between the announcement and the deadline taking effect.
The tension is structural. GovRAMP markets a progressive security model, one where vendors enter at a flexible starting point and, in GovRAMP's framing, security expectations increase over time rather than all at once. The framework was designed in part to avoid excluding small and emerging providers from state procurement by letting them mature into compliance. A hard April 1 deadline doesn't pause for the progression curve.
North Carolina hasn't said which GovRAMP tier satisfies the requirement. The program offers several milestones: a Progressing Security Snapshot (obtainable in roughly three weeks), Core, Ready, Provisionally Authorized, and Authorized. Each carries different assessment depth and continuous monitoring obligations. The state's FAQ notes that assessment fees are tiered by company revenue, a concession to small, veteran-owned, and minority-owned businesses. But a tiered fee structure doesn't answer whether a Snapshot score gets a product into a solicitation or whether only full Authorization counts. "Additional details will be announced shortly," the program page states.
For vendors with existing FedRAMP authorization, GovRAMP offers reciprocity pathways that can accelerate the process. For everyone else, the near-term move is enrollment in the Snapshot program and attendance at the webinars GovRAMP and NCDIT are hosting. The "verify once, serve many" promise (one authorization valid across all participating North Carolina agencies) is genuine, but it's cold comfort if the assessment isn't complete when the RFP drops.
Published ·Deep Fathom