States risk rebuilding the cloud compliance maze

sankai via Getty Images
COMMENTARY | Some are moving towards their own procurement mandates, but might find themselves in a fragmented environment that could make compliance challenging.
The promise behind the Government Risk and Authorization Management Program is straightforward: a cloud provider should be able to prove its security posture once and reuse that evidence across government. States now risk undermining that promise by layering different thresholds, timelines and reciprocity procedures onto the same basic framework.
That would replace one familiar problem with another. Instead of answering repetitive agency questionnaires, vendors could find themselves navigating a collection of state-specific authorization regimes. Government would gain stronger security controls but lose some of the speed, competition and portability that standardization was supposed to deliver.
The risk is becoming more immediate as states move from voluntary participation to procurement mandates.
North Carolina began requiring new executive-branch contracts with a cloud component to include GovRAMP-aligned risk-assessment provisions on April 1, 2026. Vendors currently may receive time to reach the required status. Beginning April 1, 2027, full compliance will be mandatory for covered contracts without an on-ramp, while existing contracts must align when renewed or re-solicited.
Indiana implemented its own GovRAMP-aligned policy in Oct. 2025. Nevada’s mandate took effect July 1, 2026. Texas operates the separate Texas Risk and Authorization Management Program known as TX-RAMP and no longer places GovRAMP- or FedRAMP-authorized products on its approved list automatically. A provider must submit a reciprocity request and wait for Texas to validate the outside authorization before reciprocal certification is issued.
Each decision is defensible on its own. States are responsible for protecting their data and may face different laws, systems and risk tolerances. But the combined effect matters. A national cloud provider can satisfy a common security baseline and still confront different status labels, data mappings and transition periods from one state to the next.
That is precisely the kind of fragmentation GovRAMP was created to reduce.
Route Fifty reported this year that framework harmonization had become one of GovRAMP’s largest recent initiatives. The organization’s leadership acknowledged that full harmonization may be unrealistic given the uniqueness of jurisdictions and data but argued that getting most of the way there would make compliance more manageable.
States should now turn that principle into procurement policy.
First, equivalent authorizations should receive presumptive reciprocity. A state may still verify that an authorization is active and appropriate for the data involved, but a vendor should not have to seek what amounts to a second certification merely because it crosses a state line. Extra review should be reserved for a clearly identified state-specific requirement.
Second, states should publish a common crosswalk showing how GovRAMP, FedRAMP and state-specific statuses correspond. Vendors should be able to determine before a solicitation whether an existing authorization qualifies, what additional controls are required and how long any transition period lasts. Agencies should not have to interpret that question from scratch either.
Third, state-specific overlays should be narrow, public and tied to an identifiable risk.
Criminal-justice information, tax records or unique statutory requirements may justify additional controls. General preference or institutional habit should not. If every state builds a broad overlay, the common baseline stops functioning as a common baseline.
These changes are not favors to industry. They are procurement safeguards for government.
Duplicative compliance raises the cost of entering a market. Large incumbents may absorb that cost across many contracts. Smaller providers may decide that one state’s potential revenue does not justify another application, another review and another monitoring process. The result can be fewer bidders, less negotiating leverage and slower access to emerging technology.
Fragmentation can also burden the government teams these programs are supposed to help. State security and procurement officials must maintain separate guidance, answer recurring equivalency questions and evaluate whether outside credentials satisfy local rules. Counties, cities and school systems may then create still more variations if the state does not offer a clear reusable model.
None of this argues for weaker cybersecurity. A cloud product handling sensitive public data should face independent validation and continuing oversight. The question is whether governments can demand strong evidence without repeatedly repackaging the same evidence.
North Carolina says its GovRAMP adoption is intended to streamline procurement and reduce duplicative assessments. That should become the test for every state implementation. Does the policy create a genuinely portable security credential, or does it merely move duplication from the agency level to the state level?
The window to answer that question is narrowing. More states are turning cloud authorization into a contractual requirement, and GovRAMP is intended for use beyond state agencies by local governments and educational institutions. Once separate processes are embedded in statutes, portals and contract templates, harmonizing them will become harder.
States should coordinate now on reciprocity, common mappings and limited overlays. Otherwise, the country may end up with fifty versions of a program designed to prevent government from asking the same security question 50 different ways.
Colton Overcash is the founder of Vertex Strategies and a former presidential appointee at the U.S. Department of Homeland Security. He previously led a multi state government affairs program for a Fortune 500 technology company and advises businesses on government strategy, critical infrastructure, technology and public-sector markets.




