State Risk and Authorization Management Program
Standardized security framework for state and local governments to assess cloud service providers. Based on FedRAMP with state-specific adaptations.
What StateRAMP draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Change Request TrackingTies every database change to the request that authorised it.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
FedRAMP-Aligned Audit
Cloud services MUST implement audit controls based on FedRAMP baseline requirements.
Change control fails at the evidence step far more often than at the approval step. Running SELECT 'CR:12345' WHERE 1 = 0 before a change ties every subsequent statement in that session to the request that authorised it — no agents, no application changes, no database configuration. Schema and configuration changes are captured as they happen, so an unapproved DDL is visible rather than discovered at the next review.
Ongoing Compliance
Providers MUST maintain continuous monitoring and submit monthly/annual reports.
Framework audits do not ask whether you own a tool; they ask you to demonstrate that a named control operated over a period. Access reviews, privileged activity, change monitoring, and audit-log integrity are produced from the activity already being captured and mapped to the control they satisfy, with dashboards showing posture over the audit window rather than at a single point. Our evidence-pack engagement formats it the way assessors expect and answers the database-controls questions on the call.
Independent Verification
Security posture MUST be verified by approved third-party assessment organizations.
An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.
Reassessment
Authorization MUST be renewed annually with evidence of maintained compliance.
Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.
What StateRAMP covers
This instrument defines no data category of its own. Mirrors the FedRAMP impact-level model for state and local procurement, and defines no data category of its own.
How StateRAMP is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The StateRAMP Program Management Office and the participating state or local government.
StateRAMP mirrors the FedRAMP model for state and local procurement. Continuous monitoring deliverables keep a product on the Authorized Product List; missing them moves it to a lower status and eventually removes it, and a growing number of states will not buy from a product that is not listed.
Participation and mandate vary by state, so the commercial consequence varies with your market.
Uncapped exposure that sits outside this instrument
These come from company law rather than from StateRAMP, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for StateRAMP,
not configured for it afterwards
StateRAMP Audit Controls
FedRAMP-aligned audit policy templates
StateRAMP Evidence Package
Monthly and annual compliance evidence reports
Compliance Status Dashboard
Real-time view of control implementation status
Compliance Drift Detection
Alert when audit controls deviate from baseline
Other Government frameworks
Walk into the StateRAMP audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.