GovRAMP Adoption
The State of Georgia is strengthening how third-party cloud services are evaluated, authorized and continuously monitored. The Georgia Technology Authority (GTA), in partnership with GovRAMP, is introducing a standardized framework to help state agencies manage cloud security risk while giving technology providers a clearer, more consistent path for demonstrating that their cloud products meet government security expectations.
Using NIST-based security principles, GovRAMP's framework helps support:
Stronger cloud security: Establish consistent expectations for protecting government information and systems.
Reduced duplication: Use standardized security documentation and assessments to reduce repetitive reviews.
Risk-informed decisions: Give agencies greater visibility into the security posture of cloud products.
Continuous monitoring: Extend security oversight beyond an initial assessment through ongoing monitoring requirements.
More consistent procurement: Create clearer security expectations for agencies and technology providers.
Policy and Requirements
Effective October 1, 2026
New state procurements and contracts that include a cloud service component will align with Georgia’s Third-Party Cloud Service Authorization and Oversight Policy and Standard, consistent with the National Institute of Standards and Technology (NIST) Special Publication 800-53 Revision 5 security controls. New contracts will include security and risk assessment requirements aligned with the GovRAMP framework, and cloud services procured through the State’s enterprise IT procurement process will undergo GovRAMP validation and GTA approval.
Effective July 1, 2027
Full compliance with the State’s GovRAMP verification requirements will be mandatory for all procurements containing a cloud service component. Existing contracts containing cloud services will align with GovRAMP verification requirements upon renewal, extension, major modification, or new solicitation.
What State Agencies Need to Know
GovRAMP adoption does not replace an agency's responsibility to manage technology and cybersecurity risk. Agencies should continue to follow applicable GTA policies, standards, procurement processes, data-handling requirements and other state or federal requirements.
GovRAMP Resources for Vendors
Frequently Asked Questions
-
What is GovRAMP?
GovRAMP is a nonprofit program that provides a standardized, risk-based framework for assessing and continuously monitoring the security of cloud products used by government organizations.
-
Why is Georgia adopting GovRAMP?
A standardized framework can help Georgia strengthen cloud security oversight, create more consistent security expectations and reduce duplicative assessment processes.
-
Does GovRAMP replace GTA security policies?
No. Agencies must continue to comply with applicable GTA policies, standards, procurement requirements and other state or federal requirements.
-
Does every cloud provider need the same GovRAMP status?
Not necessarily. Requirements may vary based on policy, risk, data, procurement method, contract and use case. Review the applicable Georgia requirements before making a procurement decision.
-
Where can I check a provider's GovRAMP status?
Use the GovRAMP Program Participants directory.
-
What if my current provider is not GovRAMP verified?
Review the applicable Georgia policy and contract requirements and work with your agency's appropriate IT, cybersecurity and procurement teams to determine next steps.
-
Does GovRAMP approval guarantee that a product can be used by my agency?
No. GovRAMP status can support the security review process, but agencies may have additional technology, cybersecurity, privacy, legal, procurement or program-specific requirements.
-
Where can vendors get help?
Providers should begin with GovRAMP's Security Program, document library and provider resources. Questions specific to a Georgia solicitation should follow the contact instructions provided with that procurement.
Need Help?
State Agencies
For questions about Georgia's GovRAMP adoption, security requirements or implementation, contact GTA Office of Information Security at [email protected].
Vendors
Questions about GovRAMP verification or the GovRAMP Security Program? Contact GovRAMP. Questions about doing business with GTA? Contact the GTA Office of Procurement Management at [email protected].