New state cloud rules are rewriting who can sell to government

mustafaU via Getty Images

COMMENTARY | Independently verified security is moving from a review conducted near the end of procurement to a requirement that can determine who competes and on what timetable.

For technology vendors, the most important date in North Carolina’s new cloud-security policy may not be April 1, 2027. It may be the date of their next solicitation or renewal.

Since April 1, 2026, new North Carolina executive-branch contracts containing a cloud component have included risk-assessment requirements aligned with the Government Risk and Authorization Management Program, known as GovRAMP. 

Vendors currently may receive an on-ramp period to reach the required status. Beginning April 1, 2027, full compliance will be required without that transition, while existing contracts must align when they are renewed or put out for a new solicitation.

North Carolina is part of a broader shift. Texas prohibits covered state entities and public higher education institutions from entering or renewing cloud contracts unless the service holds the appropriate certification under the Texas Risk and Authorization Management Program, or TX-RAMP. Vendors relying on FedRAMP or GovRAMP must request reciprocity rather than receive it automatically. 

Indiana’s policy reaches cloud contracts executed, amended or renewed after Oct. 14, 2025. Nevada began adding GovRAMP requirements to new executive-branch cloud contracts on July 1, 2026, with Core as the minimum for many products and higher verification possible based on the data involved.

These programs are not interchangeable. Their scope, thresholds and reciprocity rules differ. But they are sending the same market signal: independently verified security is moving from a review conducted near the end of procurement to a requirement that can determine who competes and on what timetable.

That shift can help government. State technology leaders face more third-party products than their security teams can evaluate repeatedly. A reusable assessment can reduce duplicative questionnaires, give agencies a common body of evidence and provide continuing visibility through monitoring.

For vendors, however, it changes the sales cycle.

North Carolina uses a high-water-mark approach in which the most sensitive information entering a cloud service determines the required status. Public data requires validation of a security snapshot score. Internal data generally maps to GovRAMP Core, while Confidential and Restricted data map to Ready and Authorized. A product built for a routine use case can therefore face a much higher bar when one integration touches personnel records, health information or criminal-justice data.

This makes data mapping a business-development issue, not merely a technical exercise. Vendors need to understand what enters their product, where it moves and whether a new use could raise its classification after award. North Carolina requires agencies to confirm that a provider can satisfy the higher standard, including through a contract modification, before more sensitive information is transferred or processed.

Product architecture matters as well. A software application does not become GovRAMP compliant simply because it runs on authorized infrastructure. Each cloud layer must be evaluated within its own security boundary, although some controls may be inherited from the underlying platform.

Product development can also create new compliance obligations after the initial assessment. GovRAMP’s 2026 modernization identifies the addition of generative AI to cloud products as a significant-change issue involving provider notification and a self-reporting addendum. Features once treated mainly as product-road-map decisions can now carry authorization and procurement consequences.

Channel partners do not remove the problem. North Carolina’s policy expressly reaches professional-services vendors that use cloud services to process, transmit or store state data while performing their work. Resellers and integrators therefore need to know whether the underlying product and the environment used to deliver it can meet the customer’s requirements.

Incumbents face a quieter risk. Past performance does not waive a new security standard when a contract reaches renewal. Providers should review their public-sector contract calendars now and work backward from upcoming renewals, amendments and solicitations.

Compliance also carries real costs. GovRAMP’s published annual dues and PMO fees for Core begin at $10,500 for providers with less than $1 million in revenue. Ready and Authorized require an independent third-party assessment whose cost is not included in that figure.

Governments should keep requirements proportional to the data involved, recognize credible reciprocity and preserve workable on-ramps. Otherwise, a policy intended to reduce cyber risk could also reduce competition and favor vendors best able to absorb the expense.

The implications are not confined to state government. GovRAMP is designed for state and local government buyers, including education systems, and allows verified evidence to be reused across participating jurisdictions. That does not mean every city or county faces the same mandate, but vendors should not assume these expectations will remain contained within state executive agencies.

Cybersecurity readiness now belongs in product planning, pricing and capture strategy. April 2027 is North Carolina’s formal deadline. For companies seeking state and local business, the next solicitation or renewal may be the one that matters more.

Colton Overcash is the founder of Vertex Strategies and is a former presidential appointee at the U.S. Department of Homeland Security. He previously led a multistate government affairs program for a Fortune 500 technology company and advises businesses on government strategy, critical infrastructure, technology and public-sector markets.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.