Skip to main content
← All frameworks
TX-RAMP Level 1 / Level 2 Support

TX-RAMP certification requirements, evidenced from continuous scans.

CISGuard maps 50 NIST 800-53 controls underlying TX-RAMP Level 1 and Level 2 requirements, giving cloud vendors serving Texas state agencies continuous configuration evidence instead of questionnaire snapshots.

United States (Texas)Cloud Service Providers serving Texas State Agencies
Quick Facts

TX-RAMP at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

Authority
Texas Department of Information Resources (DIR)
Statutory basis
Senate Bill 475 (2021)
Certification levels
Level 1 (lower impact) and Level 2 (confidential data)
Who must comply
Cloud services storing, processing, or transmitting Texas state agency data
Reciprocity
FedRAMP and StateRAMP status recognized in DIR reciprocity paths
Control basis
NIST 800-53; CISGuard maps 50 controls across 20 families
Overview

What is TX-RAMP?

TX-RAMP is the Texas Department of Information Resources (DIR) program for assessing the security of cloud computing services used by Texas state agencies, created under Senate Bill 475 (2021). Cloud products that store, process, or transmit state agency data must obtain TX-RAMP certification for the contract to proceed. Level 1 applies to lower-impact services handling public or non-confidential data; Level 2 applies to services handling confidential data. The control requirements derive from NIST 800-53, and DIR provides reciprocity paths for providers holding FedRAMP or StateRAMP status. Because certification depends on demonstrating security control implementation, the recurring work is evidence: CISGuard's continuous CIS benchmark scanning and NIST 800-53 mapping produce the technical-control evidence for the configuration, access, and monitoring requirements at both levels.

Control Mapping

TX-RAMP-relevant NIST 800-53 families CISGuard automates.

Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.

  • Access Control (AC)
    Controls
    AC-2, AC-3, AC-6, AC-7, AC-17
    Mapped by
    CIS Account + Privilege Management benchmarks
  • Audit and Accountability (AU)
    Controls
    AU-2, AU-3, AU-6, AU-12
    Mapped by
    CIS Audit Policy benchmarks (Windows + Linux)
  • Configuration Management (CM)
    Controls
    CM-2, CM-3, CM-6, CM-7, CM-8
    Mapped by
    Continuous CIS scanning + drift detection
  • Identification & Authentication (IA)
    Controls
    IA-2, IA-5, IA-8
    Mapped by
    CIS Password + MFA + SSO controls
  • System and Communications Protection (SC)
    Controls
    SC-7, SC-8, SC-13
    Mapped by
    CIS Cryptography + Network benchmarks
  • Continuous Assessment (CA)
    Controls
    CA-2, CA-7
    Mapped by
    Continuous CIS posture monitoring
How It Works

How CISGuard automates TX-RAMP evidence.

TX-RAMP certification questions resolve to the same underlying problem every 800-53-derived program has: proving technical controls are implemented and stay implemented. Vendors typically answer with screenshots and policy documents assembled per assessment cycle. CISGuard replaces that with a standing evidence pipeline: continuous CIS benchmark scans across 22 benchmarks evidence secure configuration (CM-2, CM-6), drift detection documents change control (CM-3), and the immutable audit trail covers the AU family. The Framework Coverage Report presents per-control status in NIST 800-53 structure, directly usable for TX-RAMP submissions and for the continuous monitoring expectations that follow certification. Vendors pursuing FedRAMP or StateRAMP alongside TX-RAMP reuse the identical scan dataset across all three. CISGuard does not issue TX-RAMP certification; DIR does. CISGuard supplies the technical evidence your submission and ongoing compliance depend on.

Auditor Evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.

  • NIST 800-53 Framework Coverage Report supporting TX-RAMP Level 1 and Level 2 submissions
  • Continuous configuration evidence for post-certification monitoring expectations
  • Drift detection events documenting configuration change control
  • Per-control satisfaction status with underlying CIS scan data and timestamps
  • Immutable audit trail for audit and accountability requirements
  • Exception register with documented justification and auto-expiry
Frequently Asked

TX-RAMP questions, answered directly.

Who needs TX-RAMP certification?

Cloud computing services that store, process, or transmit data for Texas state agencies. Under Senate Bill 475 (2021), Texas agencies may only enter or renew contracts for cloud services that hold the appropriate TX-RAMP certification from the Department of Information Resources. If you sell SaaS, PaaS, or IaaS into Texas state government, TX-RAMP applies to you, at Level 1 or Level 2 depending on the data your service handles.

What is the difference between TX-RAMP Level 1 and Level 2?

Level 1 applies to lower-impact cloud services, such as those handling public or non-confidential agency data. Level 2 applies to services handling confidential data and carries a larger set of required controls. Both levels derive from NIST 800-53, so the same CISGuard control mapping applies; Level 2 simply exercises more of it. DIR determines the required level based on the data and service categorization.

Does CISGuard get my product TX-RAMP certified?

No. TX-RAMP certification is granted by the Texas Department of Information Resources through its own assessment process, and CISGuard is not an assessor or certifying body. CISGuard produces the technical-control evidence the process consumes: continuous CIS benchmark scan results mapped to NIST 800-53 controls, drift detection history, and audit trails. That evidence substantiates your responses and supports the monitoring obligations that continue after certification.

I already have FedRAMP or StateRAMP status. Do I still need TX-RAMP?

You still need TX-RAMP certification to contract with Texas state agencies, but DIR provides reciprocity paths that recognize FedRAMP and StateRAMP status, substantially shortening the process. Because all three programs build on NIST 800-53, the evidence base is shared: the same CISGuard Framework Coverage Report and continuous scan history support your existing authorization and your TX-RAMP submission without separate evidence collection.

What happens after TX-RAMP certification?

Certification is not permanent: certified products are expected to maintain their security posture and satisfy DIR's ongoing monitoring requirements, and certifications are subject to renewal. This is where point-in-time evidence collapses. CISGuard's scheduled scans every 4-24 hours, baseline comparison, and 365-day posture history give you a standing record that your configuration controls kept operating, ready whenever DIR or an agency customer asks.

Ready for TX-RAMP readiness?

Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.