FEDCertified™ logo
← All Frameworks
Framework

GovRAMP (formerly StateRAMP) Compliance

GovRAMP — known as StateRAMP until its February 2025 rebrand — gives state, local, tribal, and territorial (SLTT) governments a shared framework for evaluating cloud service security, modeled on FedRAMP and built on the same NIST control catalog.

Who This Applies To

  • SaaS, PaaS, and IaaS companies selling cloud services to state agencies, municipalities, public universities, K-12 districts, or tribal governments

Current Status (as of July 2026)

The organization rebranded from StateRAMP to GovRAMP on February 14, 2025 (the legal entity remains StateRAMP; the program operates as GovRAMP). Built on NIST SP 800-53, with authorization levels of Low, Low+, Moderate, and High. A lighter-weight Core tier (60 foundational controls mapped to NIST SP 800-53 and MITRE ATT&CK) launched May 2025 as an accessible entry point for smaller vendors. Participation is voluntary and uneven — roughly half of U.S. states participate at some level, but mandates vary widely; some states (Texas via its own TX-RAMP, North Carolina) have hard procurement mandates, while others have only partial-agency participation. Verify the specific target state's requirements rather than assuming blanket adoption.

What It Covers

The same NIST SP 800-53 control foundation as FedRAMP, scaled to impact level, with a formal authorization pipeline (Ready → Provisionally Authorized → Authorized) validated by accredited third-party assessment organizations.

How FEDCertified™ Helps

Request early access to connect with vetted assessors and cloud security consultants experienced with state and local authorization. Assessment coverage for this framework is planned but not yet live.

Sources

govramp.org; NIST SP 800-53.

Privacy Policy

Effective Date: July 22, 2026  ·  Last Updated: July 22, 2026

1. Introduction

FEDCertified™ ("FEDCertified™," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect through fedcertified.com (the "Site"), how we use it, how we protect it, and the choices you have regarding your information.

By submitting information through this Site, you agree to the practices described in this Privacy Policy. If you do not agree, please do not submit information to us.

This Site is currently in a pre-launch phase, offering early access registration for prospective customers and a partner application for prospective solution providers. This Privacy Policy will be updated as the FEDCertified™ marketplace platform is developed and launched.

2. Information We Collect

We collect information you voluntarily provide when you complete a form on this Site. Currently, the Site offers two forms:

Early Access Request (for organizations seeking compliance solutions):

  • Organization name
  • Industry
  • Company size
  • Primary compliance goal (e.g., CMMC, FedRAMP, NIST SP 800-171, NIST SP 800-53, HIPAA, PCI DSS, other)
  • Estimated timeline
  • Your name and title
  • Business email address
  • Phone number (optional)
  • Comments you choose to provide

Partner Application (for prospective solution providers):

  • Company name and website
  • Primary contact name and title
  • Business email address and phone number
  • Primary service category and compliance expertise
  • Geographic coverage
  • Description of services
  • Existing certifications (e.g., SOC 2, ISO 27001, CMMC ecosystem roles, FedRAMP experience)

We also automatically collect limited technical information when you visit the Site, such as IP address, browser type, device type, referring pages, and general usage data, typically through standard web analytics tools. This helps us understand how the Site is used and improve it.

We do not knowingly collect sensitive personal information (such as Social Security numbers, financial account numbers, or health information) through these forms, and we ask that you not include such information in any form field, including free-text comments.

3. How We Use Your Information

We use the information we collect to:

  • Respond to your early access request or partner application
  • Communicate with you about FEDCertified™, including updates, educational resources, and launch announcements
  • Evaluate prospective solution providers for potential inclusion in the FEDCertified™ marketplace
  • Understand demand and improve the Site and our services
  • Maintain the security and proper functioning of the Site
  • Comply with legal obligations

We do not use automated decision-making or profiling to make decisions that produce legal or similarly significant effects about you.

4. How We Share Your Information

We do not sell your personal information. We may share the information you provide with:

  • Service providers who help us operate the Site, process form submissions, or send communications on our behalf — currently including Tally (our form-processing provider) and, if added later, email/newsletter platforms — under obligations to protect your information and use it only for the purposes we specify.
  • Legal and safety purposes, if required to comply with a legal obligation, protect our rights, or respond to a valid legal request.
  • In connection with a business transaction, such as a merger, acquisition, or sale of assets, in which case personal information may be transferred as part of that transaction.

Information submitted through the Partner Application may be reviewed internally to evaluate potential inclusion in the FEDCertified™ marketplace. It is not shared with prospective customers or other third parties unless and until you are onboarded as a marketplace partner, which will involve a separate agreement and additional notice.

We do not currently share or sell personal information with third parties for their own direct marketing purposes.

5. Data Retention

We retain the information you submit for as long as reasonably necessary to fulfill the purposes described in this Policy — including maintaining our early access list, evaluating partner applications, and communicating with you — or until you ask us to delete it, whichever comes first. If you are not selected as a marketplace partner or the marketplace does not proceed as described, we will retain your information only as long as needed for legitimate business or legal purposes, or until you request deletion.

6. Your Privacy Rights

Depending on where you live, you may have rights regarding your personal information, which may include the right to:

  • Know what personal information we have collected about you
  • Request a copy of, or access to, your personal information
  • Request correction of inaccurate personal information
  • Request deletion of your personal information
  • Opt out of marketing communications at any time
  • Not be discriminated against for exercising these rights

To exercise any of these rights, contact us using the information in Section 10 below. We will respond within a reasonable timeframe and in accordance with applicable law.

Opting out of communications: You may unsubscribe from marketing emails at any time using the unsubscribe link included in those emails, or by contacting us directly.

7. Cookies and Tracking Technologies

We may use cookies and similar technologies (such as web analytics tools) to understand how visitors use the Site and to improve its performance. These technologies may collect information such as pages visited, time spent on the Site, and general location (based on IP address).

You can control cookies through your browser settings. Disabling cookies may affect some functionality of the Site, though the core forms will continue to work.

8. Data Security

We use reasonable administrative, technical, and organizational safeguards designed to protect the information you provide from unauthorized access, use, or disclosure. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

9. Children's Privacy

This Site is intended for business professionals and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can address it.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:

Email: privacy@fedcertified.com
Website: fedcertified.com

11. Changes to This Policy

We may update this Privacy Policy from time to time, including as the FEDCertified™ marketplace platform develops beyond its current pre-launch phase. We will post the updated policy on this page with a revised "Last Updated" date. Material changes will be communicated through reasonable means, such as a notice on the Site.

FEDCertified™ is an independent marketplace focused on connecting organizations with cybersecurity compliance solution providers. FEDCertified™ is not a certification body, accreditation organization, or government agency, and does not issue compliance certifications.