Texas is one of the largest government technology buyers in the country. If you sell SaaS and you want that revenue, you clear a specific bar first. This is what that bar is, and what just changed.
The requirement is TX-RAMP.
Texas requires cloud computing services that handle state data to hold a TX-RAMP certification before a state agency can contract for them. The mandate sits in Texas Government Code 2054.0593, and it has applied to cloud services sold to Texas state agencies since the program took effect in 2021. TX-RAMP is run by the Texas Department of Information Resources, the state's central IT authority.
If you have been through SOC 2 or FedRAMP, the shape is familiar. A defined control set, an assessment against it, and a certification that lets agencies buy. The control baseline draws on NIST 800-53, the same family FedRAMP uses.
The two levels.
TX-RAMP certifies at two levels, and the data your product handles decides which one you need.
Level 1.
Level 1 covers products that handle public or nonconfidential information, or run at low impact. It is the lighter assessment. A vendor meets a defined set of controls drawn from NIST 800-53 and submits the assessment responses to DIR.
Level 2.
Level 2 covers products that store, process, or transmit confidential state data, or run at moderate-to-high impact. This is the level most SaaS vendors selling real workloads to Texas will need. It carries a larger control set and more evidence behind each control. If you handle anything an agency would treat as sensitive, plan for Level 2.
How FedRAMP maps to TX-RAMP.
Texas built reciprocity into the program, and this is the part worth understanding before you spend a dollar.
A FedRAMP authorization satisfies TX-RAMP. FedRAMP Low maps to TX-RAMP Level 1. FedRAMP Moderate maps to TX-RAMP Level 2. A StateRAMP authorization carries the same recognition. If you already hold one of these, you submit evidence of it and receive the equivalent TX-RAMP certification without running a second full assessment.
That reciprocity changes the math. If your roadmap includes federal agencies as well as Texas, FedRAMP Moderate is the authorization that opens both doors, because the harder credential clears the easier one. The trade-offs between the federal levels are covered in FedRAMP High vs Moderate, and how to choose, and what a federal authorization actually costs is in what a FedRAMP certification runs.
If Texas is the only government market you are chasing, a direct TX-RAMP assessment is the shorter path. If federal revenue is anywhere on the horizon, look hard at doing FedRAMP first and letting it carry Texas.
Provisional status buys time.
Texas built in a runway. TX-RAMP provisional status lets a state agency contract for a product for up to 18 months while the vendor completes full certification. If an agency wants you and you are not certified yet, provisional status is the bridge that keeps the deal moving while the assessment runs.
What the Texas Cyber Command changes.
Here is the new piece. In June 2025, Texas created the Texas Cyber Command through House Bill 150. Governor Greg Abbott signed it on June 2, 2025. The Command is a component of the University of Texas System, attached to the University of Texas at San Antonio, and it is built to centralize the state's cybersecurity operations: threat intelligence, incident response, and digital forensics.
The Command came into existence on September 1, 2025. By January 1, 2026, it and DIR were directed to put a memorandum of understanding in place to govern the transition of cybersecurity functions from DIR to the new Command.
For a vendor, the practical read is this. TX-RAMP remains the certification gate for selling cloud to Texas agencies, and DIR still administers it today. What the Cyber Command signals is direction. Texas is consolidating cybersecurity into a single, well-funded authority and raising the priority of state cyber across the board. A state investing in its cyber posture at this scale is signaling that its expectations of vendors will climb. The assessment bar for selling to Texas is more likely to rise than to ease.
Two things are worth watching as the transition proceeds: where TX-RAMP administration finally sits once the DIR-to-Command handoff completes, and whether the control expectations move as the Command stands up its own programs.
What to do now.
Confirm the data first. If your product touches confidential Texas state data, you are looking at Level 2.
Check what you already hold. A FedRAMP or StateRAMP authorization can carry into TX-RAMP through reciprocity, and you may be closer than you think.
Sequence by your full market. If federal is on the roadmap, FedRAMP Moderate is the credential that opens federal and Texas at once. The recurring obligations that come with holding a federal authorization are laid out in FedRAMP continuous monitoring.
The thread running through all of it is the same one that runs through FedRAMP. The certification is an evidence problem. The control set is published and knowable. The work is producing proof an assessor will accept, for every control, with no gaps. That is the part that takes the months, and it is the part worth starting early.