Continuous monitoring is the regular review of a service provider’s security verification. It begins once a product achieves a GovRAMP milestone status of Core, Ready, Provisionally Authorized or Authorized.
Continuous monitoring means continuous assurance.
Continuous monitoring helps ensure a service provider’s solution continues to meet its security requirements and maintain a secure state. It provides ongoing visibility into a solution’s vulnerabilities and security posture, allowing service providers to address findings, resolve outstanding items and remain aligned with GovRAMP requirements.
Continuous monitoring also helps identify areas of risk so service providers can take timely action to protect their systems. When vulnerabilities or other security concerns arise, government agencies can use this information to make informed, risk-based decisions.
A similar process is followed for providers participating in the Progressing Security Snapshot Program to help ensure providers continue to make progress toward meeting GovRAMP security requirements.
Service providers must maintain their Plan of Action and Milestones (POA&M) and executive summary, as well as update their security scans and inventory worksheet. The GovRAMP Program Management Office (PMO) reviews this information monthly for products with a Ready or Authorized verification and quarterly for products with a Core verification on behalf of the governments they serve.
If information indicates that a product may be falling out of scope or no longer meeting applicable requirements, the GovRAMP PMO will follow up with additional questions or concerns.
Annually, service providers with an Authorized or Ready status must submit a new assessment conducted by a Third-Party Assessment Organization (3PAO) for review by the GovRAMP PMO. For products with Core verification, the annual assessment is conducted by the PMO.
New in 2026: For providers with products that maintain both a FedRAMP Certification and GovRAMP Authorized verification, GovRAMP will accept FedRAMP’s new VDR/VER reporting to satisfy applicable continuous monitoring requirements.
View specific continuous monitoring requirements and escalation triggers in the Continuous Monitoring Guide and Escalation Process.
The purpose of continuous monitoring is to ensure service providers maintain compliance with GovRAMP requirements and provide continuous assurance of their security posture. When issues or concerns arise, the GovRAMP team works with service providers to resolve them before escalating in accordance with the Continuous Monitoring Guide and Escalation Process. The escalation process may include a Corrective Action Plan or Detailed Findings Review.
If an issue remains unresolved, a proactive notification is sent to government officials who have been granted access to the product’s continuous monitoring reporting. The notification instructs the official to log in to the PMO Portal to review the escalation.
This process provides transparency into a product’s security posture and enables government agencies to make risk-based decisions and take appropriate action to protect their data and systems, when necessary.
To gain access to continuous monitoring reporting:
The government entity must be a Participating Government with GovRAMP. There is no cost for public sector organizations to participate with GovRAMP. Learn more about government participation here or email get@govramp.org.
A government official must request access to each product’s continuous monitoring reporting, and the service provider must grant access. Requests typically come from agency CIOs, CISOs or ISOs. Because the service provider must approve each access request, GovRAMP recommends including continuous monitoring access requirements in applicable contract terms. GovRAMP publishes resources to help government agencies standardize this process.
Government members may request access to continuous monitoring reporting for products listed on the Authorized Product List (APL) and may request access to Security Snapshots for products listed on the Progressing Product List (PPL). The APL and PPL are public listings available on the Program Participants page.
Today, security documentation is stored in a secure platform that maintains both a GovRAMP Authorized verification at the High Impact Level and a FedRAMP Certification Class D. The GovRAMP PMO security team has access to review the documentation and, with approval from the service provider, can grant access to authorized government partners.
Providers may begin the verification process by becoming a private sector GovRAMP member. Once the required documentation is ready, providers can submit a Security Review Request form to begin the review process. Learn more about the GovRAMP Security Program.
GovRAMP (501c6) establishes the framework, requirements and governance for the GovRAMP Security Program, ensuring alignment with the public sector needs and consistency across participations. GovRAMP has responsibility and manages the membership program that enables organizations to participate and access resources.
GovRAMP contracts with RAMPQuest to operate the National Institute of Standards and Technology (NIST) Program Management Office (PMO), responsible for executing the GovRAMP Security Program with our provider members. RAMPQuest manages the day-to-day operations of the PMO, helping providers navigate compliance and security requirements efficiently. Public sector entities across federal, state, local, tribal, K-12 and higher education can participate with GovRAMP by contacting get@govramp.org to get started.