Three programs with nearly identical names sit between a SaaS company and a government contract: FedRAMP, StateRAMP, and TX-RAMP. They look like variations on one thing. They are not interchangeable, and choosing the wrong one costs you a year and a budget. One question settles most of the confusion: which government is your buyer.
This post covers what each program governs, where they overlap, how an authorization in one can carry to another, and how to tell which you actually need.
FedRAMP, StateRAMP, and TX-RAMP answer to different governments.
The programs differ by who they serve far more than by how they work. That single fact resolves most of the choice.
FedRAMP authorizes cloud services for the federal government.
FedRAMP is the federal program. It governs how cloud service providers prove their security to United States federal agencies, and it is built on the NIST 800-53 control catalog. An authorization lets any federal agency buy and run your service. If your buyer is a federal department or agency, FedRAMP is the gate. For the plain-language version of how it works, see what FedRAMP is and how it works.
StateRAMP, now GovRAMP, covers state and local government.
StateRAMP is the state and local counterpart. It is a nonprofit program, launched in 2021, that applies the same NIST 800-53 foundation to cloud services sold to states, counties, cities, school districts, and public universities. In February 2025 the organization announced a rebrand to GovRAMP, reflecting how far past state agencies its membership had grown. The legal entity is still StateRAMP, operating as GovRAMP, so both names will appear in contracts and on the authorized product list for a while. The deeper side-by-side is in StateRAMP vs FedRAMP, the key differences.
TX-RAMP is Texas running its own program.
TX-RAMP is Texas-specific. The state requires it under Texas Government Code section 2054.0593: state agencies can only contract for cloud computing services that hold TX-RAMP certification. It is run by the Texas Department of Information Resources and has two levels that track data sensitivity. Texas is also reorganizing its cybersecurity oversight under the new Texas Cyber Command, covered in what the new Texas rules mean for cloud vendors. For the steps to get certified, see how to navigate TX-RAMP.
Underneath, they share most of their security.
The reason these programs feel alike is that they are. All three rest on NIST 800-53 and sort systems by impact using FIPS 199, the Low, Moderate, and High levels set by how much harm a breach would cause. The control counts are the same baselines: 156 controls at Low, 323 at Moderate, and 410 at High. The difference between Moderate and High is worth settling before you commit to a level, because it drives most of the cost.
The practical result: the security engineering you do for one program is most of what you need for the others. What changes is who reviews it, how it is submitted, and which marketplace lists you at the end.
An authorization in one program can carry to another.
Because the programs share a spine, they recognize each other's work, in one direction more than the other.
FedRAMP is the highest bar, and it travels the furthest. A FedRAMP authorization feeds StateRAMP through a Fast Track path that reuses the same security package and 3PAO assessment you already produced, with no second full assessment. It also satisfies TX-RAMP by reciprocity: FedRAMP Moderate maps to TX-RAMP Level 2, and FedRAMP Low maps to Level 1.
The reverse is weaker. A StateRAMP authorization earns no formal credit toward FedRAMP. You can reuse the engineering and much of the evidence, and you still complete the full federal process. So when both a state and a federal contract are realistic, doing FedRAMP first and carrying it down is usually the more efficient order. See what transfers between TX-RAMP and FedRAMP, and what does not.
One Texas detail catches teams off guard. Since October 30, 2024, holding FedRAMP or StateRAMP no longer adds you to the TX-RAMP certified products list automatically. You submit a reciprocity request to Texas DIR to be listed. The credit exists. The paperwork does not file itself.
Which one you need.
Match the program to the buyer in front of you.
A federal agency means FedRAMP. No state-level authorization substitutes for a federal contract. A state or local government, a school district, or a public university points to StateRAMP, now GovRAMP, unless that government runs its own program. The State of Texas means TX-RAMP specifically, because Texas mandates its own certification by statute. A pipeline that spans Texas plus other states is covered by TX-RAMP alongside StateRAMP. A pipeline that spans federal plus states is served best by FedRAMP first, for the reuse it carries downstream. Inside Texas, the choice between TX-RAMP Level 1 and Level 2 follows the sensitivity of the data you handle.
When more than one program applies, sequence by reach. Earn the authorization that carries to the most other programs first.
The hard part is the same in all three.
Whichever program you pursue, the work that consumes the calendar is identical: producing evidence for every control and writing the narratives that connect that evidence to the requirement in a form a reviewer accepts. The control list is published. Proving you meet it, control by control, is the months-long part. That holds for a TX-RAMP package and a FedRAMP package alike.
This is the part SentrIQ is built for, on the federal side. The platform ingests live system evidence and your policy documents, maps them to the FedRAMP control families, and generates assessor-credible authorization artifacts, each one traceable to the evidence that produced it. Because a FedRAMP authorization is what carries furthest into StateRAMP and TX-RAMP, getting the federal evidence right is the work that pays off in every direction. If the cost of FedRAMP is what gives you pause, the evidence and narrative stage is where that cost concentrates, and where it can come down.
One naming note. StateRAMP now operates as GovRAMP after a February 2025 rebrand, and FedRAMP renamed its authorization to a Certification in 2026. The programs and the requirements described here did not change. The labels are catching up to a faster-moving market.