State of Georgia & GovRAMP
Why GovRAMP?
As cloud technologies become increasingly integral to government operations, safeguarding Georgia’s digital infrastructure is foundational to the security, resilience, and well-being of the state and the communities it serves. At the core of the state’s mission to establish and maintain a trusted digital government, partnership with GovRAMP reflects the shared commitment to protect critical systems and data while enabling agencies to confidently modernize systems and services.
Through GovRAMP’s standardized, NIST-aligned approach to cloud security assurance, Georgia benefits from consistent security expectations, independent validation and greater visibility into third-party technology risk. This collaborative approach supports the state’s broader emphasis to strengthen its security posture through:
-
Increased security standards: National level security hardening
-
Standardization and consistency: Uniform assessment process
-
Improved interoperability: Easier collaboration with public sector agencies
-
Cost efficiency: Leveraging a shared assessment framework
-
Alignment with national cybersecurity strategy
For Georgia, a shared assurance model and continuous monitoring capabilities will reduce duplicative assessments, strengthen confidence in technology investments, and create a scalable foundation for secure cloud adoption, resulting in a more sustainable security model for the state’s technology ecosystem.
New Cloud Product Requirements
To create a standardized process and provide resources to its agencies, the Georgia Technology Authority (GTA) has leveraged the GovRAMP framework for authorization and continuous monitoring to protect the confidentiality, integrity and availability of state information.
The GovRAMP requirements for new contracts with cloud components are in effect, as of October 1, 2026. You can review the State of Georgia's Enterprise IT Policies, Standards and Guidelines here.
For more information on Georgia’s information security policies, please visit gta.georgia.gov.
Georgia & GovRAMP
Educational Webinars
Join us for a live training designed to educate vendors working with the State of Georgia on GovRAMP and the upcoming policy changes.
These session include an overview of GovRAMP, Georgia’s new cybersecurity policies, and a Q&A with the GovRAMP team.
Upcoming Sessions:
September 18 | Register Here
Frequently Asked Questions
-
What is GovRAMP?
Founded at the beginning of 2020, GovRAMP was born from the clear need for a standardized approach to the cybersecurity standards required from service providers offering solutions to state and local governments.
As a 501(c)6 nonprofit, our mission is to promote cybersecurity best practices through education and policy development to improve the cyber posture of public institutions and the citizens they serve. GovRAMP is comprised of service providers offering IaaS, PaaS, and/or SaaS solutions, third-party assessment organizations, and government officials. Our members lead, manage, and work in various disciplines across the United States and are all committed to making the digital landscape a safer, more secure place.
-
How do I get a GovRAMP status?
To learn more about how to obtain any of our GovRAMP statuses, visit our GovRAMP for Service Providers page. This page provides an overview of the GovRAMP organization, general onboarding information, a getting started checklist, and complete details regarding the requirements for beginning the GovRAMP verification process.
-
What are the continuous monitoring requirements?
Continuous monitoring involves regular security status checks of a cloud solution, conducted monthly or quarterly. This process starts once the product reaches a GovRAMP milestone status such as Core, Ready, Provisionally Authorized, or Authorized. The purpose of continuous monitoring is to ensure that the service provider’s solution is meeting security requirements and maintaining a secure system state. It provides insights into vulnerabilities, allowing service providers to address issues and comply with GovRAMP standards. By identifying areas of risk, continuous monitoring enables service providers to take prompt action to protect the system.
For more information, refer to the Continuous Monitoring Guide on the Security Overview page located under the Resources section.
Continuous monitoring must be maintained for the lifecycle of your contract with the State of Georgia, and upon request, access to the product’s security package and continuous monitoring artifacts must be granted to the State.
-
Will Georgia accept any other frameworks?
GovRAMP provides a standardized, comprehensive security verification process that includes Continuous Monitoring under the NIST framework. The 2018 National Cyber Strategy of the USA identifies NIST as the only Cybersecurity Framework (CSF) for assessing SaaS, PaaS, or IaaS vendor environments. This allows Georgia to maintain its commitment to upholding the NIST 800-53 standard and streamline the oversight process.
-
How do I enroll in the GovRAMP Progressing Security Snapshot Program?
To participate:
- Become a GovRAMP Member
- Submit a Progressing Security Snapshot Request
- Pay the applicable fee
- Receive onboarding instructions from the GovRAMP PMO
You’ll receive:
- A Snapshot score within ~3 weeks of payment
- Quarterly updated Snapshots
- Monthly one-hour consultative calls with GovRAMP’s security team
If you’re responding to a solicitation, note your time constraints on the request form so we can prioritize accordingly.
-
How much does a GovRAMP assessment cost?
To continue supporting Georgia's small- and medium- sized businesses including veteran and minority owned businesses, the GovRAMP assessment fees are tiered based on the annual revenue for the company. This pricing structure is designed to make participation more accessible while encouraging organizations of all sizes to strengthen their cybersecurity posture.
For more information, please visit Pricing Overview | GovRAMP.
In addition, GovRAMP offers a 3PAO Discount Program that rewards providers for investing in security improvements. Organizations that complete the Progressing Security Snapshot program or achieve Core Verification may qualify for discounted assessment rates, helping reduce costs and accelerate their path toward Ready or Authorized Verification.
-
How much does it cost to engage with a Third-Party Authorization Organization?
The cost of engaging a Third-Party Authorization Organization (3PAO) varies based on factors such as the size and complexity of the environment, scope of the assessment, and overall security readiness. Because 3PAOs are independent organizations that establish their own pricing, GovRAMP is unable to provide a standard cost range.
To help reduce assessment costs, GovRAMP offers a 3PAO Discount Program, which provides eligible service providers access to discounted assessment services through participating 3PAOs.
Please note that a 3PAO is only required when pursuing a GovRAMP Ready or Authorized status.
-
What if I don't own the solution but use cloud products to deliver services to the State of Georgia?
Based on the data processed, transferred, or stored, the State of Georgia may require that the cloud solutions used to deliver services be assessed by GovRAMP or FedRAMP. Specific requirements can be found within the solicitation for the services.
-
What are the guidelines for determining if my product is a cloud computing service?
Georgia identifies three distinct service models for the cloud environment:
Infrastructure as a Service (IaaS) is a cloud environment with computing resource such as virtual servers, storage, and network. The consumer uses their own software, including operating systems, middleware and applications. The underlying physical infrastructure is managed by the Cloud Service Provider (CSP).
Platform as a Service (PaaS) is a cloud environment for development and management of consumer applications. It includes the infrastructure layer – virtual servers, storage and network – while tying in middleware and development tools to allow the consumer to deploy their applications. It is designed to support the complete development lifecycle while leaving the management of the physical infrastructure to the CSP.
Software as a Service (SaaS) is a cloud computing solution that provides the consumer with access to a complete software product. The application resides on a cloud platform and is accessed by the consumer through a web interface or application program interface (API). The physical and virtual infrastructure, operating system, middleware and application are all managed by the CSP.
-
Who can I contact to get started?
For questions or more information about GovRAMP, please contact: info@govramp.org.
For questions about Georgia's GovRAMP adoption, security requirements or implementation, contact GTA Office of Information Security at gtapsg@gta.ga.gov.
Contact Us
If you have any questions for the State of Georgia, please contact gtapsg@gta.ga.gov.
For additional information on how to get started with the GovRAMP process, please contact info@govramp.org.
GovRAMP Participating Governments
GovRAMP is accepted by Georgia and other states. See a list of GovRAMP’s participating governments here.
STAY INFORMED
Receive Updates and Resources
Subscribe to receive program updates, educational briefings, and public sector implementation insights.