govrampregulatorNewsThe Broadside2 min read

Texas DIR Codifies GovRAMP-TX-RAMP Reciprocity

The policy update means cloud vendors can satisfy state requirements with a single GovRAMP credential, but DIR notification is still mandatory and the recognition doesn't flow both ways.


TL;DR

Texas DIR has updated the TX-RAMP Program Manual to formally recognize GovRAMP authorizations and the Progressing Security Snapshot Program as meeting state cloud security requirements. GovRAMP Ready or Authorized products now receive automatic TX-RAMP certification via a weekly automated sync. Products in the Progressing Snapshot Program qualify for TX-RAMP Provisional without the standard 18-month expiration. A one-time Security Snapshot also qualifies but carries the 18-month cap. DIR still requires a TX-RAMP Request Form, and the reciprocity is one-directional: TX-RAMP certification doesn't confer GovRAMP standing.

Texas DIR has codified what was previously informal: GovRAMP credentials now satisfy TX-RAMP requirements as a matter of written policy, not just agency practice. The updated TX-RAMP Program Manual (covered in joint DIR-GovRAMP webinars in December and January) spells out exactly how each GovRAMP status maps to a TX-RAMP certification level.

The practical upshot is straightforward. Get your product to GovRAMP Ready or GovRAMP Authorized, and TX-RAMP certification follows automatically via a weekly automated sync. Enroll in the GovRAMP Progressing Security Snapshot Program, and you qualify for TX-RAMP Provisional certification, and unlike standard TX-RAMP provisional status, this one doesn't expire after 18 months. Use a one-time GovRAMP Security Snapshot, and you still get TX-RAMP Provisional, but the 18-month clock starts ticking; after that you'll need GovRAMP Ready, GovRAMP Authorized, or full TX-RAMP certification to stay compliant.

What the reciprocity does (and doesn't) cover

The recognition is real but not frictionless. Providers still have to notify DIR through the TX-RAMP Request Form, matching the product and company names submitted to GovRAMP so DIR can verify the credential. And the reciprocity flows only one way: GovRAMP status translates to TX-RAMP certification, but TX-RAMP certification doesn't confer GovRAMP standing.

For cloud providers selling into multiple states, that one-way flow is the point. A vendor who invests in GovRAMP verification gets Texas access without a separate assessment. The arrangement signals that state procurement offices are willing to accept a nationally portable credential in place of state-specific reviews, at least when the state program was designed to map onto NIST standards from the start. TX-RAMP was modeled on FedRAMP; GovRAMP was built on the same architecture. The alignment was always closer than for programs starting from scratch.

What remains unclear is whether any Texas agencies will impose additional validation on top of DIR's recognition, or whether the program manual update closes the door on agency-level divergence entirely. The joint webinars addressed the mapping but haven't fully resolved how procurement officers at individual agencies should treat a GovRAMP-credentialed vendor who hasn't separately engaged with TX-RAMP. For now, the manual's language is the authoritative answer: GovRAMP status satisfies TX-RAMP requirements.


Published ·Deep Fathom