New state cloud rules are rewriting who can sell to government

mustafaU via Getty Images
COMMENTARY | Independently verified security is moving from a review conducted near the end of procurement to a requirement that can determine who competes and on what timetable.
For technology vendors, the most important date in North Carolina’s new cloud-security policy may not be April 1, 2027. It may be the date of their next solicitation or renewal.
Since April 1, 2026, new North Carolina executive-branch contracts containing a cloud component have included risk-assessment requirements aligned with the Government Risk and Authorization Management Program, known as GovRAMP.
Vendors currently may receive an on-ramp period to reach the required status. Beginning April 1, 2027, full compliance will be required without that transition, while existing contracts must align when they are renewed or put out for a new solicitation.
North Carolina is part of a broader shift. Texas prohibits covered state entities and public higher education institutions from entering or renewing cloud contracts unless the service holds the appropriate certification under the Texas Risk and Authorization Management Program, or TX-RAMP. Vendors relying on FedRAMP or GovRAMP must request reciprocity rather than receive it automatically.
Indiana’s policy reaches cloud contracts executed, amended or renewed after Oct. 14, 2025. Nevada began adding GovRAMP requirements to new executive-branch cloud contracts on July 1, 2026, with Core as the minimum for many products and higher verification possible based on the data involved.
These programs are not interchangeable. Their scope, thresholds and reciprocity rules differ. But they are sending the same market signal: independently verified security is moving from a review conducted near the end of procurement to a requirement that can determine who competes and on what timetable.
That shift can help government. State technology leaders face more third-party products than their security teams can evaluate repeatedly. A reusable assessment can reduce duplicative questionnaires, give agencies a common body of evidence and provide continuing visibility through monitoring.
For vendors, however, it changes the sales cycle.
North Carolina uses a high-water-mark approach in which the most sensitive information entering a cloud service determines the required status. Public data requires validation of a security snapshot score. Internal data generally maps to GovRAMP Core, while Confidential and Restricted data map to Ready and Authorized. A product built for a routine use case can therefore face a much higher bar when one integration touches personnel records, health information or criminal-justice data.
This makes data mapping a business-development issue, not merely a technical exercise. Vendors need to understand what enters their product, where it moves and whether a new use could raise its classification after award. North Carolina requires agencies to confirm that a provider can satisfy the higher standard, including through a contract modification, before more sensitive information is transferred or processed.
Product architecture matters as well. A software application does not become GovRAMP compliant simply because it runs on authorized infrastructure. Each cloud layer must be evaluated within its own security boundary, although some controls may be inherited from the underlying platform.
Product development can also create new compliance obligations after the initial assessment. GovRAMP’s 2026 modernization identifies the addition of generative AI to cloud products as a significant-change issue involving provider notification and a self-reporting addendum. Features once treated mainly as product-road-map decisions can now carry authorization and procurement consequences.
Channel partners do not remove the problem. North Carolina’s policy expressly reaches professional-services vendors that use cloud services to process, transmit or store state data while performing their work. Resellers and integrators therefore need to know whether the underlying product and the environment used to deliver it can meet the customer’s requirements.
Incumbents face a quieter risk. Past performance does not waive a new security standard when a contract reaches renewal. Providers should review their public-sector contract calendars now and work backward from upcoming renewals, amendments and solicitations.
Compliance also carries real costs. GovRAMP’s published annual dues and PMO fees for Core begin at $10,500 for providers with less than $1 million in revenue. Ready and Authorized require an independent third-party assessment whose cost is not included in that figure.
Governments should keep requirements proportional to the data involved, recognize credible reciprocity and preserve workable on-ramps. Otherwise, a policy intended to reduce cyber risk could also reduce competition and favor vendors best able to absorb the expense.
The implications are not confined to state government. GovRAMP is designed for state and local government buyers, including education systems, and allows verified evidence to be reused across participating jurisdictions. That does not mean every city or county faces the same mandate, but vendors should not assume these expectations will remain contained within state executive agencies.
Cybersecurity readiness now belongs in product planning, pricing and capture strategy. April 2027 is North Carolina’s formal deadline. For companies seeking state and local business, the next solicitation or renewal may be the one that matters more.
Colton Overcash is the founder of Vertex Strategies and is a former presidential appointee at the U.S. Department of Homeland Security. He previously led a multistate government affairs program for a Fortune 500 technology company and advises businesses on government strategy, critical infrastructure, technology and public-sector markets.




