Skip to main content
All frameworks

TX-RAMP Level 1 / Level 2 Support

TX-RAMP certification requirements,evidenced from continuous scans.

CISGuard maps 50 NIST 800-53 controls underlying TX-RAMP Level 1 and Level 2 requirements, giving cloud vendors serving Texas state agencies continuous configuration evidence instead of questionnaire snapshots.

United States (Texas)Cloud Service Providers serving Texas State Agencies
Authority
Texas Department of Information Resources (DIR)
Statutory basis
Senate Bill 475 (2021)
Certification levels
Level 1 (lower impact) and Level 2 (confidential data)
Who must comply
Cloud services storing, processing, or transmitting Texas state agency data
Reciprocity
FedRAMP and StateRAMP status recognized in DIR reciprocity paths
Control basis
NIST 800-53; CISGuard maps 50 controls across 13 families

Overview

What is TX-RAMP?

TX-RAMP is the Texas Department of Information Resources (DIR) program for assessing the security of cloud computing services used by Texas state agencies, created under Senate Bill 475 (2021). Cloud products that store, process, or transmit state agency data must obtain TX-RAMP certification for the contract to proceed. Level 1 applies to lower-impact services handling public or non-confidential data; Level 2 applies to services handling confidential data. The control requirements derive from NIST 800-53, and DIR provides reciprocity paths for providers holding FedRAMP or StateRAMP status. Because certification depends on demonstrating security control implementation, the recurring work is evidence: CISGuard's continuous CIS benchmark scanning and NIST 800-53 mapping produce the technical-control evidence for the configuration, access, and monitoring requirements at both levels.

How CISGuard automates TX-RAMP evidence

TX-RAMP certification questions resolve to the same underlying problem every 800-53-derived program has: proving technical controls are implemented and stay implemented. Vendors typically answer with screenshots and policy documents assembled per assessment cycle. CISGuard replaces that with a standing evidence pipeline: continuous CIS benchmark scans across 22 benchmarks evidence secure configuration (CM-2, CM-6), drift detection documents change control (CM-3), and the immutable audit trail covers the AU family. The Framework Coverage Report presents per-control status in NIST 800-53 structure, directly usable for TX-RAMP submissions and for the continuous monitoring expectations that follow certification. Vendors pursuing FedRAMP or StateRAMP alongside TX-RAMP reuse the identical scan dataset across all three. CISGuard does not issue TX-RAMP certification; DIR does. CISGuard supplies the technical evidence your submission and ongoing compliance depend on.

Control mapping

TX-RAMP-relevant NIST 800-53 families CISGuard automates.

Each CIS control is tagged with its framework reference. One scan produces the per-framework coverage report, with satisfied, partially satisfied and not-met status for every control.

Control areaControlsMapped by
Access Control (AC)AC-2, AC-3, AC-6, AC-7, AC-17CIS Account + Privilege Management benchmarks
Audit and Accountability (AU)AU-2, AU-3, AU-6, AU-12CIS Audit Policy benchmarks (Windows + Linux)
Configuration Management (CM)CM-2, CM-3, CM-6, CM-7, CM-8Continuous CIS scanning + drift detection
Identification & Authentication (IA)IA-2, IA-5, IA-8CIS Password + MFA + SSO controls
System and Communications Protection (SC)SC-7, SC-8, SC-13CIS Cryptography + Network benchmarks
Continuous Assessment (CA)CA-7Continuous CIS posture monitoring

Auditor evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF, HTML, JSON, CSV and SARIF. No spreadsheets, no screenshots, no manual cross-referencing.

  • NIST 800-53 Framework Coverage Report supporting TX-RAMP Level 1 and Level 2 submissions
  • Continuous configuration evidence for post-certification monitoring expectations
  • Drift detection events documenting configuration change control
  • Per-control satisfaction status with underlying CIS scan data and timestamps
  • Immutable audit trail for audit and accountability requirements
  • Exception register with documented justification and auto-expiry

Frequently asked

TX-RAMP questions, answered directly.

Who needs TX-RAMP certification?

Cloud computing services that store, process, or transmit data for Texas state agencies. Under Senate Bill 475 (2021), Texas agencies may only enter or renew contracts for cloud services that hold the appropriate TX-RAMP certification from the Department of Information Resources. If you sell SaaS, PaaS, or IaaS into Texas state government, TX-RAMP applies to you, at Level 1 or Level 2 depending on the data your service handles.

What is the difference between TX-RAMP Level 1 and Level 2?

Level 1 applies to lower-impact cloud services, such as those handling public or non-confidential agency data. Level 2 applies to services handling confidential data and carries a larger set of required controls. Both levels derive from NIST 800-53, so the same CISGuard control mapping applies; Level 2 simply exercises more of it. DIR determines the required level based on the data and service categorization.

Does CISGuard get my product TX-RAMP certified?

No. TX-RAMP certification is granted by the Texas Department of Information Resources through its own assessment process, and CISGuard is not an assessor or certifying body. CISGuard produces the technical-control evidence the process consumes: continuous CIS benchmark scan results mapped to NIST 800-53 controls, drift detection history, and audit trails. That evidence substantiates your responses and supports the monitoring obligations that continue after certification.

I already have FedRAMP or StateRAMP status. Do I still need TX-RAMP?

You still need TX-RAMP certification to contract with Texas state agencies, but DIR provides reciprocity paths that recognize FedRAMP and StateRAMP status, substantially shortening the process. Because all three programs build on NIST 800-53, the evidence base is shared: the same CISGuard Framework Coverage Report and continuous scan history support your existing authorization and your TX-RAMP submission without separate evidence collection.

What happens after TX-RAMP certification?

Certification is not permanent: certified products are expected to maintain their security posture and satisfy DIR's ongoing monitoring requirements, and certifications are subject to renewal. This is where point-in-time evidence collapses. CISGuard's scheduled scans every 4-24 hours, baseline comparison, and 365-day posture history give you a standing record that your configuration controls kept operating, ready whenever DIR or an agency customer asks.

TX-RAMP readiness, on request.

Our compliance engineers have helped organizations achieve regulatory readiness through a seamless, fully managed deployment.