INDIANAPOLIS (Sept. 9, 2026) — The Georgia Technology Authority (GTA) Office of Information Security (OIS) today announced that Georgia will adopt GovRAMP as the state's primary framework for authorizing and continuously monitoring third-party cloud services.
Effective Oct. 1, 2026, all new state procurements and contracts that include cloud services must comply with Georgia's Third-Party Cloud Service Authorization and Oversight Policy and Standard. New contracts will incorporate security and risk assessment requirements aligned with the GovRAMP framework.
This statewide approach will provide agencies with a consistent method for evaluating cloud services, improve visibility into cybersecurity risks, reduce duplicative security assessments, and support more standardized procurement and risk management practices. Agencies will continue to assess business needs, make risk-based decisions, manage agency-specific controls, and oversee system risk. Cloud services procured through the state's enterprise IT procurement process will require GovRAMP validation and GTA approval.
“Georgia is committed to delivering secure and innovative digital services. Our partnership with GovRAMP provides a trusted framework for evaluating and monitoring cloud solutions, helping agencies adopt technology faster, strengthen cybersecurity and better protect the systems and data that support state government,” said Shawnzia Thomas, State Chief Information Officer (CIO) and GTA Executive Director.
“Georgia's adoption of GovRAMP marks an important step toward a more consistent and efficient approach to cloud security across government,” said Leah McGrath, Executive Director of GovRAMP. “By establishing a common framework for authorization, security verification and continuous monitoring, Georgia can reduce duplicative assessments while providing agencies greater visibility into the security of the cloud services they use.”
GovRAMP provides a standardized framework for security verification and continuous monitoring of cloud service providers. The framework aligns with National Institute of Standards and Technology (NIST) Special Publication 800-53 Revision 5 security controls and supports reusable security assessments and standardized verification processes across participating government organizations.
The new requirements will take effect Oct. 1, 2026. To support the transition, Georgia will provide an initial on-ramp period for vendors to achieve the required GovRAMP status under applicable contract requirements. Interim verification pathways will be available to qualifying providers actively progressing through the GovRAMP process.
Beginning July 1, 2027, full compliance with the state's GovRAMP verification requirements will be mandatory for all procurements containing a cloud service component. Existing contracts containing cloud services will align with GovRAMP verification requirements upon renewal, extension, major modification or new solicitation.
Additional implementation guidance, procurement requirements, vendor resources and educational materials will be published ahead of the Oct. 1, 2026, implementation date.
GTA OIS and GovRAMP will host informational sessions for agencies and vendors ahead of implementation. Sessions will cover GovRAMP verification pathways, continuous monitoring expectations, procurement and onboarding requirements, interim verification processes, and roles and responsibilities for agencies and providers.
Additional webinar dates and registration information will be distributed separately.
Full details are available on the state's GovRAMP program page.
GovRAMP is a nonprofit membership organization dedicated to advancing consistent, trusted cybersecurity practices across state, local, tribal, and educational government. Guided by its mission to make cybersecurity easier to understand, implement, and maintain, GovRAMP provides a standardized framework, independent validation, and community-driven education that help governments adopt secure cloud solutions with confidence while enabling service providers to demonstrate trusted security through clear, evidence-based practices. By bringing together public and private sector partners, GovRAMP supports policy collaboration, strengthens shared assurance, and helps build a more resilient cybersecurity ecosystem that protects government services, data, and the communities they serve. Learn more at GovRAMP.org.
The Georgia Technology Authority (GTA) provides technology and cybersecurity leadership, services, and solutions that enable state and local government entities to better serve Georgians. GTA supports secure, reliable and innovative government operations through enterprise technology services, cybersecurity, digital services, emerging technology, data innovation, broadband initiatives and statewide technology policies and standards. Through collaboration with public- and private-sector partners, GTA helps strengthen Georgia’s technology infrastructure and advance efficient, accessible and responsive government services.