Rev. 4 Templates and Resources

StateRAMP’s security templates are developed based on policies adopted by the Board of Directors and recommended by the Standards & Technical Committee. Find the policies, templates and resources you need on this page.

2024 Rev. 4 to Rev. 5 Transition Note: 

Throughout 2023, the StateRAMP Standards & Technical Committee met to update the baseline requirements to align with NIST 800-53 Rev. 5. The Committee and Board recommended a transition for providers so that those submitting for or maintaining a status of StateRAMP Ready, Authorized or Provisional have until October 1, 2024, to update security packages, including annual Third Party Assessment Organization (3PAO) audits, to comply with the updated Rev. 5 requirements. The updated StateRAMP Security Snapshot criteria and scoring will be in effect beginning January 2024. 

Announcing StateRAMP's New Rev. 5 Baselines

In May, the StateRAMP Board of Directors adopted the Standards & Technical Committee’s recommended baseline controls that incorporate NIST 800-53 Rev.5 into StateRAMP’s security requirements. 

Security Policies

Baseline Requirements

[doc_library doc_category="baseline-requirements" sort_by="modified" search_box="false" reset_button="false" pagination="false" totals="false" docs_per_page="-1"]

Ready Requirements

[doc_library doc_category="ready-requirements" search_box="false" reset_button="false" pagination="false" totals="false" docs_per_page="-1"]

Continuous Monitoring

[doc_library doc_category="continuous-monitoring" search_box="false" reset_button="false" pagination="false" totals="false" docs_per_page="-1"]

Sample Policies & Procedures

The following templates are associated with Rev. 4 baseline requirements and will not be accepted after October 1, 2024. View updated requirements and templates here.

Authorized Product List

The first Authorized Product List (APL) includes a listing of Subscriber Members who are actively pursuing third party verification for their offerings. Follow the steps below to be listed on the Authorized Product List.

Find a StateRAMP 3PAO

Assessors play an important role in conducting independent security audits.

Government Sponsors

A government sponsor is required for providers wishing to submit a request for authorization.

Submit a Review Request

Do you want your products included on the StateRAMP Authorized Product List? Submit a Security Review Request to begin the process.

Connect with the
StateRAMP PMO

StateRAMP is proud to partner with Knowledge Services to serve as the PMO.

Receive StateRAMP Updates

Interested in StateRAMP? Sign up below to receive StateRAMP Updates.