GovRAMP Adoption

The State of Georgia is strengthening how third-party cloud services are evaluated, authorized and continuously monitored. The Georgia Technology Authority (GTA), in partnership with GovRAMP, is introducing a standardized framework to help state agencies manage cloud security risk while giving technology providers a clearer, more consistent path for demonstrating that their cloud products meet government security expectations.

Using NIST-based security principles, GovRAMP's framework helps support:

Stronger cloud security: Establish consistent expectations for protecting government information and systems.

Reduced duplication: Use standardized security documentation and assessments to reduce repetitive reviews.

Risk-informed decisions: Give agencies greater visibility into the security posture of cloud products.

Continuous monitoring: Extend security oversight beyond an initial assessment through ongoing monitoring requirements.

More consistent procurement: Create clearer security expectations for agencies and technology providers.

Policy and Requirements

Effective October 1, 2026

New state procurements and contracts that include a cloud service component will align with Georgia’s Third-Party Cloud Service Authorization and Oversight Policy and Standard, consistent with the National Institute of Standards and Technology (NIST) Special Publication 800-53 Revision 5 security controls. New contracts will include security and risk assessment requirements aligned with the GovRAMP framework, and cloud services procured through the State’s enterprise IT procurement process will undergo GovRAMP validation and GTA approval.

Effective July 1, 2027

Full compliance with the State’s GovRAMP verification requirements will be mandatory for all procurements containing a cloud service component. Existing contracts containing cloud services will align with GovRAMP verification requirements upon renewal, extension, major modification, or new solicitation.

About GovRAMP

GovRAMP is a nonprofit program that provides government organizations and cloud service providers with a standardized, risk-based approach to cloud security. Using NIST-based security principles, GovRAMP provides a common framework that can support greater consistency, transparency and reuse across the public sector.

What State Agencies Need to Know

GovRAMP adoption does not replace an agency's responsibility to manage technology and cybersecurity risk. Agencies should continue to follow applicable GTA policies, standards, procurement processes, data-handling requirements and other state or federal requirements. 

Find a Cloud Provider

Explore GovRAMP program participants offering verified and in-progress cloud products and services with verification statuses such as Core, Ready, Provisionally Authorized, or Authorized.

Frequently Asked Questions

  • What is GovRAMP?

    GovRAMP is a nonprofit program that provides a standardized, risk-based framework for assessing and continuously monitoring the security of cloud products used by government organizations.

  • Why is Georgia adopting GovRAMP?

    A standardized framework can help Georgia strengthen cloud security oversight, create more consistent security expectations and reduce duplicative assessment processes.

  • Does GovRAMP replace GTA security policies?

    No. Agencies must continue to comply with applicable GTA policies, standards, procurement requirements and other state or federal requirements.

  • Does every cloud provider need the same GovRAMP status?

    Not necessarily. Requirements may vary based on policy, risk, data, procurement method, contract and use case. Review the applicable Georgia requirements before making a procurement decision.

  • Where can I check a provider's GovRAMP status?

    Use the GovRAMP Program Participants directory.

  • What if my current provider is not GovRAMP verified?

    Review the applicable Georgia policy and contract requirements and work with your agency's appropriate IT, cybersecurity and procurement teams to determine next steps.

  • Does GovRAMP approval guarantee that a product can be used by my agency?

    No. GovRAMP status can support the security review process, but agencies may have additional technology, cybersecurity, privacy, legal, procurement or program-specific requirements.

  • Where can vendors get help?

    Providers should begin with GovRAMP's Security Program, document library and provider resources. Questions specific to a Georgia solicitation should follow the contact instructions provided with that procurement.

Need Help?

State Agencies

For questions about Georgia's GovRAMP adoption, security requirements or implementation, contact GTA Office of Information Security at [email protected].

Vendors

Questions about GovRAMP verification or the GovRAMP Security Program? Contact GovRAMP. Questions about doing business with GTA? Contact the GTA Office of Procurement Management at [email protected].