State of North Carolina and GovRAMP

State of North Carolina - Seal

Why GovRAMP?

Protecting North Carolina’s most sensitive and critical information is essential for operational resilience. As cyber threats rapidly evolve, even the most vigilant cybersecurity teams can’t defend networks from bad actors alone. Cybersecurity isn’t just about defense, it’s about taking proactive measures to safeguard data. One way to accomplish this is to ensure every cloud product handling data meets North Carolina’s strict cybersecurity standards. That’s where GovRAMP comes in.

To protect its digital assets, North Carolina has committed to partnering with GovRAMP to implement a comprehensive cybersecurity strategy, rooted in risk and vulnerability management, threat intelligence, and standardized security verification for cloud products. The State of North Carolina will assist providers with ensuring that their cloud products are meeting those minimum-security controls as indicated by GovRAMP in accordance with the NIST 800-53 security controls. GovRAMP allows providers to verify once to serve many, affording them the benefit of transferable credentials through its standardized cybersecurity verification process, while also simplifying procurement. Product cybersecurity validation can be used with any of GovRAMP’s participating government members.

Through GovRAMP’s standardized approach to security assessment, North Carolina is ensuring every cloud product handling its data meets applicable cybersecurity standards throughout the contract lifecycle. Together, GovRAMP and North Carolina are delivering cybersecurity confidence, compliance, and protection you can trust. 

New Cloud Product Requirements

The State of North Carolina Department of Information Technology (NCDIT) ensures that all executive branch offices utilizing cloud services meet applicable security standards. To create a standardized process and provide resources to its agencies, NCDIT has leveraged the GovRAMP framework for authorization and continuous monitoring to protect the confidentiality, integrity and availability of state information.

The GovRAMP requirements for new contracts with cloud components will go into effect on April 1, 2026. Additional details will be announced shortly.

For more information on North Carolina’s information security policies, please visit it.nc.gov.

North Carolina & GovRAMP

Educational Webinars

Join us for a live training designed to educate vendors working with the State of North Carolina on GovRAMP and the upcoming policy changes.

The session will include an overview of GovRAMP, North Carolina’s new cybersecurity policies, and a Q&A with the GovRAMP team.

Upcoming Sessions:

  • Thursday, February 26 | 11 am – 12 pm ET | Register
  • Monday, March 16 | 1 pm – 2 pm ET | Register
  • Wednesday, April 22 | 3 pm – 4 pm ET | Register
State of North Carolina - Hero Image

Frequently Asked Questions

GovRAMP Participating Governments

GovRAMP is accepted by North Carolina and other states. See a list of GovRAMP’s participating governments here.

Contact Us

For additional information on North Carolina Procurement including bulletins, open bids, contracts and registration, please refer to the North Carolina electronic Vendor Portal.

If you have any questions for the State of North Carolina, please contact ESRMO@nc.gov.

For additional information on how to get started with the GovRAMP process, please contact info@govramp.org.

STAY INFORMED

Receive Updates and Resources

Subscribe to receive program updates, educational briefings, and public sector implementation insights.