If you are new to GovRAMP or looking to understand how requirements are applied, start with these foundational resources.
These documents provide a practical starting point and help you understand how controls, requirements, and assessment expectations are structured across the GovRAMP program.
Explains the end-to-end process service providers follow to complete a GovRAMP Rev. 5 security assessment, outlining key steps, roles, and expectations for providers and 3PAOs.
GovRAMP System Security Plan (SSP)
Defines how security control responsibilities are allocated across a service provider's system under GovRAMP Rev. 5, documenting control implementation and responsibility boundaries to support assessments, authorization, and ongoing monitoring.
GovRAMP Core Controls
Defines the 60 prioritized security controls required for GovRAMP Core verification, helping providers understand Core-level requirements and prepare for PMO-led review.
GovRAMP Core Control Evidence Package
A standardized collection of templates designed to help organizations organize and submit evidence for each GovRAMP Core Control. This package provides a structured location for control narratives, supporting documentation, screenshots, policies, procedures, and other artifacts needed to demonstrate implementation and compliance during a GovRAMP Core assessment.
GovRAMP Federal Overlay
Aligns GovRAMP Low, Moderate, and High Impact requirements with corresponding FedRAMP Rev. 5 baselines, helping service providers meet both state and federal security expectations while reducing duplicated effort.
GovRAMP CJIS-Aligned Overlay Control and Parameters
Provides a unified framework aligning CJIS Policy 6.0 with GovRAMP controls, offering tailored guidance for secure cloud procurement decisions.
Verification Boundary Guidance
Explains how to define a system's verification boundary for a GovRAMP security review, helping identify which components, services, and connections are in scope for assessment.
Verification Boundary Diagram Checklist and Example
Provides a checklist and example to help service providers create an verification boundary diagram that meets GovRAMP security package submission requirements.
GovRAMP Snapshot Controls Matrix
Defines the control criteria used to generate a Security Snapshot, providing a high-level view of a service provider's security posture and explaining how snapshot scoring is calculated based on implemented controls and risk.
GovRAMP Progressing Security Snapshot Program Requirements and Progressing Improvement Guide
Outlines the requirements, roles, and processes for participating in the GovRAMP Progressing Security Snapshot Program, including assessment expectations, improvement activities, and continuous monitoring responsibilities.
GovRAMP Service Provider Package – Low Impact
Contains the required templates and guidance for completing a GovRAMP Ready or Authorized security review at the Low Impact level, helping service providers prepare documentation and demonstrate baseline security requirements.
GovRAMP Service Provider Package – Moderate Impact
Contains the required templates and guidance for completing a GovRAMP Core, Ready, or Authorized security review at the Moderate Impact level, helping service providers prepare documentation and demonstrate Moderate Impact security requirements.
GovRAMP Service Provider Package – Moderate Impact with CJIS Overlay
Contains the required templates and guidance for completing a GovRAMP Core, Ready, or Authorized security review at the Moderate Impact level with the CJIS Overlay, helping service providers document and demonstrate compliance with CJIS-aligned security requirements.
GovRAMP Service Provider Package – High Impact
Contains the required templates and guidance for completing a GovRAMP Ready or Authorized security review at the High Impact level, helping service providers prepare documentation and demonstrate High Impact security requirements.
GovRAMP 3PAO Package – Low Impact
Contains the required templates and guidance for conducting a GovRAMP Ready or Authorized security assessment at the Low Impact level, helping 3PAOs perform consistent evaluations and validate baseline security requirements.
GovRAMP 3PAO Package – Moderate Impact
Contains the required templates and guidance for conducting a GovRAMP Core, Ready, or Authorized security assessment at the Moderate Impact level, helping 3PAOs perform consistent evaluations and validate Moderate Impact security requirements.
GovRAMP 3PAO Package – Moderate Impact with CJIS Overlay
Contains the required templates and guidance for conducting a GovRAMP Core, Ready, or Authorized security assessment at the Moderate Impact level with the CJIS Overlay, helping 3PAOs evaluate and validate CJIS-aligned security requirements.
GovRAMP 3PAO Package – High Impact
Contains the required templates and guidance for conducting a GovRAMP Ready or Authorized security assessment at the High Impact level, helping 3PAOs perform consistent evaluations and validate High Impact security requirements.
Penetration Test Guidance
Outlines the requirements and best practices for conducting penetration testing as part of a GovRAMP security assessment, helping ensure testing is properly scoped and aligned with Rev. 5 requirements.
Continuous Monitoring Guide and Escalation Process
Outlines the requirements for continuous monitoring after verification, including monitoring activities, reporting requirements, and escalation processes to support ongoing compliance with GovRAMP Rev. 5.
Provides guidance for completing the GovRAMP Continuous Monitoring Matrix template to support achieving and maintaining a GovRAMP security authorization.
Vulnerability Scan Requirements Guide
Defines the requirements for conducting vulnerability scans under GovRAMP, including scanning frequency, scope, and reporting expectations to support ongoing security and compliance with Rev. 5.
Incident Communications Procedures
Outlines the required procedures for communicating with GovRAMP following a security incident, including notification requirements, communication timelines, and stakeholder responsibilities.
Procurement Cloud Security Resource Tool
Demonstrates how procurement, IT, and risk teams can collaborate throughout the cloud procurement process, promoting a coordinated approach to security decision-making.
GovRAMP Significant Change Request Form
Provides the required checklist and submission form for evaluating and documenting planned system changes to determine whether a Significant Change Request must be submitted to GovRAMP.
3PAO Accreditation Process Guide
A brief guide explaining the standards and requirements for 3PAOs to become accredited to perform independent cybersecurity assessments for GovRAMP.
This comprehensive workbook is designed to support 3PAOs and service providers with Provisional Authorized Status or Authorized Status in tracking assessments and maintaining compliance with GovRAMP requirements.
Cybersecurity 101: Understanding Risk and Resilience Guide
This eBook compiles GovRAMP’s Back to the Basics series into a single guide for public-sector teams and providers. It covers twelve foundational cybersecurity concepts — from understanding risk, vulnerabilities, and data integrity to strengthening privacy, policy, and compliance practices.
GovRAMP Data Classification Tool
This document provides instructions for using the GR-199 worksheet to identify data types, review impact levels, and determine the appropriate GovRAMP security category for a product.
GR-199 — Data Classification Determination Tool
This tool helps service providers and governments determine the appropriate GovRAMP security impact level for a product based on the types of data it processes, stores, or transmits.
GovRAMP Adopted Bylaws
The official governing rules for StateRAMP (GovRAMP), outlining its purpose, membership structure, board authority, officer roles, and operational procedures as an Indiana nonprofit.
GovRAMP Ready Minimum Mandatory Requirements for Moderate and High Impact Levels
Defines the minimum mandatory security requirements a Service Provider must meet to achieve GovRAMP Ready at the Moderate or High Impact levels. These requirements establish the baseline controls, documentation, and security practices—aligned with NIST SP 800‑53 Rev. 5—that a 3PAO must validate in the Readiness Assessment Report (RAR).
GovRAMP Service Provider Sponsor Requirements
This document outlines the process (including government sponsorship requirements) for a vendor’s offering to be listed as GovRAMP Authorized on GovRAMP’s Authorized Product List (APL).
GovRAMP AI Self-Reporting Addendum
The AI Self-Reporting Addendum gives governments a high-level overview of an AI-enabled product’s architecture, data use, governance, controls, risks, and limitations. It supports transparency and initial due diligence but does not replace a full procurement or security assessment.
Details
GovRAMP Adopted Charters
Document Title
Description
File
GovRAMP Adopted Bylaws
The official governing rules for StateRAMP (GovRAMP), outlining its purpose, membership structure, board authority, officer roles, and operational procedures as an Indiana nonprofit.
GovRAMP NIST PMO Charter
The PMO Charter defines the objectives, roles, and responsibilities associated with the GovRAMP NIST Program Management Office (PMO), contracted with RAMPQuest.
GovRAMP Appeals Committee Charter
The Appeals Committee serves as the adjudication board for the Program Management Office determinations.
GovRAMP Approvals Committee Charter
This charter outlines the duties and responsibilities of the GovRAMP Approvals Committee and their role in providing approvals for product security packages seeking an Authorized status.
GovRAMP Procurement Committee Charter
The purpose of this charter is to define the objectives, membership, decision making, meeting schedule, and roles and responsibilities associated with the GovRAMP Procurement Committee.
GovRAMP Standards & Technical Committee Charter
The Standards & Technical Committee makes recommendations for best practices and policies that guide cloud security requirements and verification.
GovRAMP Steering Committee Charter
The purpose of this charter is to define the objectives, membership, decision making, meeting schedule, and roles and responsibilities associated with the GovRAMP Steering Committee.
Details
Subscribe for Document Updates
Be the first to know when new GovRAMP documents, templates, or policy updates are released. Subscribe to receive email notifications and stay aligned with the most current program materials.