TX-RAMP Level 2 — Texas Risk and Authorization Management Program

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
TX-RAMP Level 2is a cybersecurity and risk management framework established toassess and authorize cloud computing services used by Texas stateagencies handling confidential or regulated data. It aims to ensurethat service providers implement robust security controls and meetcompliance obligations specific to higher-risk data environments.
Published by theTexas Department of Information Resources (DIR), TX-RAMP applies tocloud vendors and state agencies across Texas that process, store, ortransmit confidential or regulated information. The frameworkoutlines requirements for cybersecurity controls, privacy safeguards,risk assessment, and ongoing compliance oversight in alignment withstate regulations.
Organizationsachieve TX-RAMP Level 2 compliance by implementing prescribedsecurity controls, maintaining documentation, and undergoing regularassessments to verify compliance. The program supports state agenciesin fulfilling regulatory requirements for third-party risk managementand aligns with broader security frameworks such as NIST SP 800-53 tofacilitate interoperability within established information securityprograms.
Why it Matters
TX-RAMP Level 2provides a comprehensive approach for Texas state agencies to managecybersecurity risk when using cloud services for sensitive data.
Key benefitsinclude:
• Strengthen third-party risk management
Enable agenciesto systematically assess and monitor cloud vendors, reducing exposureto risks from external service providers.
• Enhance data protection practices
Require robustcontrols that support secure processing, storage, and transmission ofconfidential and regulated information.
• Increase audit readiness
Maintainthorough documentation and compliance evidence, supporting timely andefficient responses during regulatory audits and assessments.
• Improve regulatory alignment
Align securitypractices with Texas state requirements and national standards,simplifying compliance efforts across multiple frameworks.
• Promote ongoing compliance oversight
Facilitatecontinuous monitoring and regular assessments to ensure thatimplemented security measures remain effective over time.
How it Works
TX-RAMP Level 2structures cloud security around a control catalog aligned with NISTSP 800-53 and the FedRAMP Moderate baseline, grouping requirementsinto control families and governance domains. It establishes anauthorization lifecycle and formal risk management processes,including continuous monitoring and periodic reassessments tomaintain an authorized state.
Organizationsimplement TX-RAMP Level 2 by mapping security controls to existinggovernance programs, performing risk assessments, and buildingauthorization packages for agency review. Teams deploy technical andprocedural security practices, run continuous monitoring andvulnerability management, coordinate third-party assessments, andexecute incident response and remediation to sustain compliance andreduce risk.
WithinSmartSuite, teams operationalize TX-RAMP Level 2 using configurablecontrol libraries, a centralized risk register, and policy governancemodules. SmartSuite supports evidence collection, automatedcompliance tracking, remediation workflows, audit readinesschecklists, and reporting dashboards to monitor posture anddemonstrate adherence to security controls, risk management,governance, and regulatory requirements.
Key Elements
• Security Control Requirements
Establishesdetailed categories of technical and administrative safeguardsmandated for cloud service providers.
• Confidential Data Safeguards
Describesprotocols and criteria for handling, storing, and transmittingconfidential or regulated information.
• Risk Assessment and Management
Outlinesprocesses for identifying, evaluating, and mitigating risksassociated with cloud-hosted sensitive data.
• Continuous Compliance Monitoring
Specifiesmechanisms for ongoing assessment and verification of adherence tosecurity and privacy standards.
• Documentation and Reporting Standards
Definesexpectations for maintaining, updating, and submittingcompliance-related documentation.
• Third-Party Oversight
Organizesresponsibilities and procedures for evaluating and managing thesecurity posture of external vendors.
Framework Scope
TX-RAMP Level 2is adopted by Texas state agencies and cloud vendors processing,storing, or transmitting confidential or regulated data within cloudenvironments. The framework governs cybersecurity controls andprivacy safeguards, and is typically implemented when addressingregulatory requirements, improving risk management, and supportingassurance programs for higher-risk data environments.
Framework Objectives
TX-RAMP Level 2establishes requirements for cybersecurity, risk management, andregulatory compliance for cloud services handling sensitive Texasstate data.
• Safeguard confidential and regulated information through robustdata protection controls
• Strengthen risk management processes supporting higher-riskcloud environments
• Ensure compliance with Texas state cybersecurity and privacyregulations
• Enhance ongoing security governance and oversight of cloudservice providers
• Improve audit readiness by maintaining documentation andevidencing control effectiveness
• Support operational resilience against evolving cybersecuritythreats and vulnerabilities TX-RAMP Level 2 aligns Texas cloudauthorization requirements with FedRAMP and maps controls to NIST SP800-53 (and commonly to CIS Controls or the CSA Cloud ControlsMatrix), enabling cloud service providers to pursue stateauthorization, demonstrate regulatory compliance, and strengthensecurity governance and operational controls for sensitive statedata.
Common Framework Mappings
Organizationsmap TX-RAMP Level 2 to established federal, international, andindustry frameworks to streamline controls, reuse evidence, and speedauthorization across cloud, privacy, and risk programs.
Mappedframeworks include:
CIS CriticalSecurity Controls
CSA CloudControls Matrix
FederalInformation Security Modernization Act (FISMA)
FedRAMP
HITRUST CSF
ISO/IEC 27001
NISTCybersecurity Framework
NIST SP 800-171
NIST SP 800-53
- ClassicifationCategoryCloud SecurityDomainCloud SecurityFramework FamilyFedRAMP
- Regulatory ContextTypeCertification / Assurance ProgramLegal InstrumentProgramSectorGovernment SectorIndustryGovernment & Public Sector
- Region / PublisherRegionNorth AmericaRegion DetailTexasPublisherTexas Department of Information Resources (DIR)
- VersioningVersionTX-RAMP Level 2 BaselineEffective Date2021Issue Date2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
TX-RAMP documentation is publicly available through the Texas Department of Information Resources.
How SmartSuite Supports US-TX TX-RAMP Level 2
Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.
Moderate-Risk Scope and Boundary
Define Level 2 scope, sensitive data handling, and service dependencies.
Level 2 Control Baseline Library
Track controls with owners, implementation details, and proof of operation.
Assessment and Remediation Workflow
Manage findings, remediation plans, retesting, and closure evidence.
Continuous Monitoring Operations
Schedule scanning, monitoring, and recurring evidence capture to prevent drift.
Vendor Obligation and Review Tracking
Track vendor obligations, evidence, and ongoing reviews for dependencies.
Audit-Ready Reporting
Report readiness, gaps, and monitoring status for assessors and stakeholders.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

FISMA is a U.S. law requiring federal agencies and contractors to secure government information systems and manage cybersecurity risks.

HITRUST CSF is a certifiable, risk-based cybersecurity and privacy framework for managing regulatory compliance and protecting sensitive data.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.
Frequently Asked Questions For TX-RAMP Level 2 (Texas Risk and Authorization Management Program)
TX-RAMP Level 2 is used to assess, authorize, and monitor cloud computing services that handle confidential or regulated data for Texas state agencies. Its primary purpose is to ensure that cloud vendors implement strong cybersecurity controls and meet regulatory compliance obligations for higher-risk data environments.
Yes, TX-RAMP Level 2 is mandatory for cloud vendors contracting with Texas state agencies if their services process, store, or transmit confidential, regulated, or otherwise sensitive information. Agencies are required to verify that their cloud service providers have achieved and maintain Level 2 authorization.
TX-RAMP Level 2 applies to all Texas state agencies and higher education institutions utilizing third-party cloud services for regulated or confidential data. It covers any systems that handle sensitive state-regulated data such as personal, financial, or protected health information.
Key requirements include implementation of defined security controls, maintaining detailed documentation, performing third-party assessments, and compiling an authorization package. Artifacts include risk assessment reports, evidence of control operation, continuous monitoring plans, and authorization to operate letters.
Organizations implement TX-RAMP Level 2 by mapping prescribed security controls—aligned with NIST SP 800-53—to existing policies and procedures, conducting risk assessments, and remediating gaps. Continuous monitoring, vulnerability management, and incident response processes are established to maintain ongoing compliance.
TX-RAMP Level 2 is closely aligned with the NIST SP 800-53 control framework and the FedRAMP Moderate baseline, facilitating interoperability with established federal and state security programs. This alignment helps streamline compliance efforts for organizations already familiar with these standards.
Ongoing compliance includes recurring risk assessments, continuous monitoring of controls, periodic third-party reassessments, and timely remediation of identified vulnerabilities. Organizations must maintain up-to-date documentation and provide evidence of ongoing adherence to security and privacy requirements.
SmartSuite facilitates TX-RAMP Level 2 compliance by providing configurable control libraries, centralized risk management, and automated evidence collection workflows. It enables teams to track remediation, prepare for audits, maintain compliance documentation, and generate real-time reports to demonstrate posture and regulatory adherence.
Put CRI Profile into action with SmartSuite
Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.
