Get authorized to serve state and local government
What is StateRAMP?
StateRAMP is a nonprofit program that brings a standardized, FedRAMP-style approach to cloud security for state and local governments. Like FedRAMP, it is based on the NIST SP 800-53 control catalog and uses accredited third-party assessment organizations (3PAOs), and it maintains an Authorized Product List (APL) of cloud offerings that government agencies can procure with confidence.
Baselines and status
StateRAMP uses Low, Moderate, and High impact baselines drawn from NIST 800-53. Providers progress through recognized statuses — from an early-stage Security Snapshot to Ready and ultimately Authorized — reflecting how far an offering has advanced through assessment and continuous monitoring. Authorization requires a government sponsor or review through the StateRAMP PMO.
FedRAMP reciprocity
Because StateRAMP and FedRAMP share the same NIST 800-53 foundation, StateRAMP offers reciprocity: a provider's FedRAMP authorization work can be leveraged toward StateRAMP status, and a single 800-53 control program can serve both federal and state/local buyers.
How episki helps
episki carries StateRAMP baselines alongside FedRAMP and NIST 800-53, sharing controls and evidence between them rather than duplicating the work. Controls are evaluated continuously, boundaries are enforceable through account, region, resource, and tag rules, and findings carry owners and due dates into Jira, Linear, or GitHub. Start a free trial or book a demo.
StateRAMP outcomes with episki
Why teams choose episki for StateRAMP
- Low, Moderate, and High baselines
- SSP generated from control evidence
- POA&M tracked to closure
- Monthly vulnerability and POA&M reporting
- Significant-change workflow
- Security Snapshot and progressing status
- Shared 800-53 control library
- 3PAO assessment workspace
- One program for federal and SLG buyers
StateRAMP readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ Impact-level determination (Low / Moderate / High)
- ✓ NIST 800-53 baseline implemented as controls
- ✓ System Security Plan from control evidence
- ✓ 3PAO assessment and POA&M tracking
- ✓ Continuous monitoring cadences and reporting
- ✓ Government sponsor or StateRAMP PMO path