StateRAMP
StateRAMP (operating as GovRAMP) is a nonprofit that provides NIST-based cloud security verification tiers (Snapshot through Authorized) for state, local, and education governments and the cloud service providers serving them, supported by a 1,200+-member community spanning more than half of U.S. states.
- Company typePrivate
- Founded2020
- HeadquartersIndianapolis, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What StateRAMP does
StateRAMP, operating as GovRAMP, is a U.S.-based nonprofit membership organization founded in 2020 and headquartered in Indianapolis. It provides a standardized, NIST-based cloud security verification framework for state, local, and education government organizations and the cloud service providers that serve them. Its product portfolio is structured as a five-tier progression: Security Snapshot and Progressing Security Snapshot (40 NIST controls for initial maturity assessment), Core Verification (60 controls with PMO validation and quarterly monitoring), Ready Verification (80 controls with independent 3PAO assessment and monthly monitoring), and Authorized/Provisional Verification (300+ controls with continuous monitoring). The program is operated through a community governance model with board oversight, working groups, and task forces (including CJIS-Aligned and AI initiatives), and is supported by founding Program Management Office RAMPQuest.
The organization's business model is membership-driven, with separate public sector and private sector membership tracks providing access to guidance, working groups, and the GovRAMP ecosystem, alongside tiered verification subscriptions that are billed annually. Distribution is reinforced through partnerships with hyperscale cloud providers (AWS, Microsoft, Google), government procurement bodies (NASPO, NASCIO), security vendors (Crowdstrike, Zscaler, Wiz, Varonis), 3PAO assessors (Coalfire, A-LIGN, 360Advanced, Prescient Security), and government-focused resellers (Carahsoft, Second Front, PSN). As of the latest data, the program spans 1,200+ member organizations, 70 participating government organizations, 330 products in program, and coverage of more than half of U.S. states following the addition of North Carolina in early 2026.
StateRAMP firmographics
Firmographics- Name
- StateRAMP
- Legal name
- StateRAMP
- Website
- https://stateramp.org
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- StateRAMP (operating as GovRAMP) is a nonprofit that provides NIST-based cloud security verification tiers (Snapshot through Authorized) for state, local, and education governments and the cloud service providers serving them, supported by a 1,200+-member community spanning more than half of U.S. states.
- Ownership category
- akta.pro rank
StateRAMP industry classification
Industry- Product category
- Cybersecurity Compliance and Risk Management
- NAICS
- Executive, Legislative, and Other General Government Support (921)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Policy, Governance & Compliance Management for Private Cloud (HDABABAI)
Keywords
Where StateRAMP is headquartered
LocationHeadquarters
- HQ city
- Indianapolis
- HQ country
- United States
- HQ region
- North America
Markets served
StateRAMP business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Membership Programs: GovRAMP offers public and private sector membership options that provide access to guidance, tools, working groups, and direct connection to the GovRAMP ecosystem. Membership enables organizations to participate in the standardized cloud security verification process.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Security Snapshot Assessment |
| Subscription | Annual | Core Verification |
| Subscription | Annual | Ready Verification |
| Subscription | Annual | Authorized/Provisional Verification |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels6 records
StateRAMP product offering
Product offeringCore offering
StateRAMP (operating as GovRAMP) is a nonprofit community that provides a standardized, NIST-based cloud security verification program for state, local, and education government agencies and the cloud service providers that sell to them. It sells tiered verification products (Security Snapshot, Core, Ready, and Authorized/Provisional Verification) and supporting membership programs that enable cloud providers to demonstrate security maturity and governments to evaluate vendor risk.
Product overview
GovRAMP is a nonprofit community providing a standardized, risk-based pathway for governments and providers to verify, adopt, and maintain secure cloud solutions. The portfolio consists of tiered verification products built on NIST-based principles: Security Snapshot and Progressing Security Snapshot (40 NIST controls for initial assessments), Core Verification (60 NIST controls with PMO validation), Ready Verification (80 NIST controls with independent 3PAO assessment), and Authorized/Provisional Verification (300+ NIST controls for the highest security tier). The program is supported by a PMO (Program Management Office), working groups, task forces, and public/private sector membership options. The verification levels follow a progression pathway from Core to Ready to Provisional to Authorized, each requiring increasing documentation, monitoring frequency, and NIST control coverage.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Snapshot
Quantifiable outcome
- 1200+ member organizations participating in the program
- +3 more outcomes
Companies that use StateRAMP
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
StateRAMP technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
StateRAMP partnerships and signals
Strategic signalPartnerships
35 partnerships are on record, tiered founding, strategic and core.
- RAMPQuestfoundingRAMPQuest serves as the founding Program Management Office (PMO), supporting program development, operations, and ongoing advancement of the GovRAMP security verification program.
- A-LIGNstrategicStrategic member supporting the GovRAMP ecosystem with security assessment and compliance services.
- ZscalerstrategicStrategic member providing cloud security expertise and supporting GovRAMP verification standards.
- CarahsoftstrategicGovernment technology distributor and strategic member helping promote GovRAMP to government customers.
- MicrosoftstrategicStrategic member supporting GovRAMP security verification standards for Microsoft cloud services.
- AWSstrategicStrategic member supporting GovRAMP security verification standards for AWS cloud services.
- GooglestrategicStrategic member supporting GovRAMP security verification standards for Google Cloud Platform.
- CrowdstrikestrategicStrategic member providing cybersecurity expertise and supporting GovRAMP verification ecosystem.
- NASPOstrategicNational Association of State Procurement Officials partnership supporting GovRAMP adoption in state procurement.
- NASCIOstrategicNational Association of State Chief Information Officers partnership supporting GovRAMP standards in state government IT.
- Coalfirecore3PAO assessor and strategic member providing independent security assessments for GovRAMP verification.
- PegasystemsstrategicStrategic member supporting GovRAMP ecosystem with enterprise software solutions.
- SAPstrategicStrategic member supporting GovRAMP verification standards for SAP cloud solutions.
- FortinetstrategicStrategic member providing network security expertise to GovRAMP ecosystem.
- MS-ISACstrategicMulti-State Information Sharing and Analysis Center partnership for cybersecurity coordination.
- GovTechstrategicMedia and marketing partner helping promote GovRAMP to government technology audiences.
- BillingtonstrategicGovernment cybersecurity event and media partner supporting GovRAMP awareness.
- Second FrontstrategicGovernment technology solutions provider and channel partner for GovRAMP.
- JPMorgan Chase BankstrategicStrategic member providing financial services sector expertise to GovRAMP ecosystem.
- WizstrategicStrategic member providing cloud security assessment expertise to GovRAMP verification process.
- VaronisstrategicStrategic member providing data security expertise to GovRAMP ecosystem.
- NinjaOnestrategicStrategic member providing endpoint management solutions to GovRAMP ecosystem.
- TwiliostrategicStrategic member providing communications platform expertise to GovRAMP ecosystem.
- OmnissastrategicStrategic member supporting GovRAMP verification standards for Omnissa cloud solutions.
- Pitney BowesstrategicStrategic member supporting GovRAMP ecosystem with technology solutions.
- RiveronstrategicStrategic member providing consulting and advisory services to GovRAMP ecosystem.
- Prescient SecuritycoreSecurity assessment firm and 3PAO providing independent assessments for GovRAMP verification.
- 360Advancedcore3PAO assessor providing independent security assessments for GovRAMP verification.
- PSIcoreAssessment and testing services provider supporting GovRAMP verification process.
- SecuriseacoreSecurity assessment firm providing services for GovRAMP verification process.
- Emagine ITcoreIT services firm providing assessment and consulting for GovRAMP verification.
- FortreumcoreSecurity assessment services supporting GovRAMP verification process.
- Eleven LabsstrategicStrategic member supporting GovRAMP ecosystem.
- PSNstrategicPublic Sector Partners network providing distribution for GovRAMP-verified solutions.
- Core ViewstrategicStrategic member supporting GovRAMP ecosystem with security solutions.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
StateRAMP competitors and assessment
Company assessmentDirect peers
- TX-RAMP: Texas's state-level cloud security certification program managed by the Texas Department of Information Resources. Competes directly with StateRAMP for state-level verification adoption and exemplifies the fragmentation risk facing StateRAMP.
- FedRAMP: Federal government's standardized cloud security authorization program using NIST controls. Most direct functional analog to StateRAMP at the federal level; cloud providers frequently pursue both, making FedRAMP the primary substitute and reference point for StateRAMP's value proposition.
- CMMC (Cyber AB): Cybersecurity Maturity Model Certification program for Department of Defense contractors. Comparable as a NIST-based, tiered third-party verification regime targeting a specific government buyer segment (defense industrial base vs. SLED).
- HITRUST: Healthcare-focused cybersecurity assurance framework with tiered assessments and third-party validation. Comparable as a sector-specific, NIST-derived verification standard with subscription-based assurance products.
Broad incumbents
- Secureframe: Compliance automation platform for SOC 2, ISO 27001, HIPAA, PCI, and NIST frameworks. Overlaps with StateRAMP on NIST-based cloud security assurance but automates evidence collection and continuous monitoring.
- Vanta: Compliance automation platform supporting SOC 2, ISO 27001, HIPAA, and other frameworks. Broader incumbent offering automated, multi-framework compliance versus StateRAMP's manual NIST verification; potential substitute for cloud providers seeking faster, lower-friction assurance.
- Drata: Automated compliance and security monitoring platform covering SOC 2, ISO 27001, HIPAA, and others. Competes for the same cloud provider security team budget as StateRAMP verification, but with a software-first, automated approach.
Others
- Coalfire: Leading cybersecurity advisory and FedRAMP/3PAO assessor with deep government compliance practice. Functions as a 3PAO partner to StateRAMP and a competitor for the underlying assessment budget.
- A-LIGN: Accredited 3PAO and strategic StateRAMP member providing independent security assessments. Acts as a delivery partner rather than competitor, but a portion of its business (SOC 2, ISO, HITRUST) competes for the same compliance spend from cloud providers.
- Schellman: Top-tier attestation and cybersecurity assessment firm offering SOC 2, ISO 27001, FedRAMP, and HITRUST services. Comparable delivery capability to StateRAMP's 3PAO network and a partial substitute for providers' compliance spend.
Market position
Competitive moat4 records
Customer concentration
StateRAMP social profiles
Digital presenceStateRAMP financial estimates
Financial estimateRevenue estimate
Valuation estimate
StateRAMP leadership team
Management profileNumber of profiles
Profiles1 record
StateRAMP subsidiaries and ownership
Company hierarchySubsidiaries1 record
StateRAMP funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
StateRAMP M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about StateRAMP
What does StateRAMP do?
StateRAMP (operating as GovRAMP) is a nonprofit community that provides a standardized, NIST-based cloud security verification program for state, local, and education government agencies and the cloud service providers that sell to them. It sells tiered verification products (Security Snapshot, Core, Ready, and Authorized/Provisional Verification) and supporting membership programs that enable cloud providers to demonstrate security maturity and governments to evaluate vendor risk.
Is StateRAMP a public or private company?
StateRAMP is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was StateRAMP founded?
StateRAMP was founded in 2020. It employs 1 to 10 people.
Where is StateRAMP based?
StateRAMP is headquartered in Indianapolis, United States, in the North America region.
How does StateRAMP make money?
One revenue line is on record: membership Programs.
Who are StateRAMP's main competitors?
Direct peers on record are TX-RAMP, FedRAMP, CMMC (Cyber AB) and HITRUST. Broad incumbents are Secureframe, Vanta and Drata. Others are Coalfire, A-LIGN and Schellman.
Does StateRAMP have an API?
No public API is recorded for StateRAMP.
What industry is StateRAMP in?
StateRAMP's product category is Cybersecurity Compliance and Risk Management. Its primary akta.pro industry code is HDABABAI, Policy, Governance & Compliance Management for Private Cloud. Its NAICS code is 921 and its SIC code is 7372.