Cloud Security
DETAIL

TX-RAMP Level 2 — Texas Risk and Authorization Management Program

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

TX-RAMP Level 2 is a cybersecurity and risk management framework established to assess and authorize cloud computing services used by Texas state agencies handling confidential or regulated data. It aims to ensure that service providers implement robust security controls and meet compliance obligations specific to higher-risk data environments.

Published by the Texas Department of Information Resources (DIR), TX-RAMP applies to cloud vendors and state agencies across Texas that process, store, or transmit confidential or regulated information. The framework outlines requirements for cybersecurity controls, privacy safeguards, risk assessment, and ongoing compliance oversight in alignment with state regulations.

Organizations achieve TX-RAMP Level 2 compliance by implementing prescribed security controls, maintaining documentation, and undergoing regular assessments to verify compliance. The program supports state agencies in fulfilling regulatory requirements for third-party risk management and aligns with broader security frameworks such as NIST SP 800-53 to facilitate interoperability within established information security programs.

Why it Matters

TX-RAMP Level 2 provides a comprehensive approach for Texas stateagencies to manage cybersecurity risk when using cloud services forsensitive data.

Key benefits include:

  • Strengthen third-party risk management

Enable agenciesto systematically assess and monitor cloud vendors, reducing exposureto risks from external service providers.

  • Enhance data protection practices

Require robustcontrols that support secure processing, storage, and transmission ofconfidential and regulated information.

  • Increase audit readiness

Maintain thoroughdocumentation and compliance evidence, supporting timely andefficient responses during regulatory audits and assessments.

  • Improve regulatory alignment

Align securitypractices with Texas state requirements and national standards,simplifying compliance efforts across multiple frameworks.

  • Promote ongoing compliance oversight

Facilitatecontinuous monitoring and regular assessments to ensure thatimplemented security measures remain effective over time.

How it Works

TX-RAMP Level 2 structures cloud security around a control catalogaligned with NIST SP 800-53 and the FedRAMP Moderate baseline,grouping requirements into control families and governance domains.It establishes an authorization lifecycle and formal risk managementprocesses, including continuous monitoring and periodic reassessmentsto maintain an authorized state.

Organizations implement TX-RAMP Level 2 by mapping security controlsto existing governance programs, performing risk assessments, andbuilding authorization packages for agency review. Teams deploytechnical and procedural security practices, run continuousmonitoring and vulnerability management, coordinate third-partyassessments, and execute incident response and remediation to sustaincompliance and reduce risk.

Within SmartSuite, teams operationalize TX-RAMP Level 2 usingconfigurable control libraries, a centralized risk register, andpolicy governance modules. SmartSuite supports evidence collection,automated compliance tracking, remediation workflows, audit readinesschecklists, and reporting dashboards to monitor posture anddemonstrate adherence to security controls, risk management,governance, and regulatory requirements.

Key Elements

  • Security Control Requirements

Establishesdetailed categories of technical and administrative safeguardsmandated for cloud service providers.

  • Confidential Data Safeguards

Describesprotocols and criteria for handling, storing, and transmittingconfidential or regulated information.

  • Risk Assessment and Management

Outlinesprocesses for identifying, evaluating, and mitigating risksassociated with cloud-hosted sensitive data.

  • Continuous Compliance Monitoring

Specifiesmechanisms for ongoing assessment and verification of adherence tosecurity and privacy standards.

  • Documentation and Reporting Standards

Definesexpectations for maintaining, updating, and submittingcompliance-related documentation.

  • Third-Party Oversight

Organizesresponsibilities and procedures for evaluating and managing thesecurity posture of external vendors.

Framework Scope

TX-RAMP Level 2 is adopted by Texas state agencies and cloud vendorsprocessing, storing, or transmitting confidential or regulated datawithin cloud environments. The framework governs cybersecuritycontrols and privacy safeguards, and is typically implemented whenaddressing regulatory requirements, improving risk management, andsupporting assurance programs for higher-risk data environments.

Framework Objectives

TX-RAMP Level 2 establishes requirements for cybersecurity, riskmanagement, and regulatory compliance for cloud services handlingsensitive Texas state data.

Safeguard confidential and regulated information through robust dataprotection controls

Strengthen risk management processes supporting higher-risk cloudenvironments

Ensure compliance with Texas state cybersecurity and privacyregulations

Enhance ongoing security governance and oversight of cloud serviceproviders

Improve audit readiness by maintaining documentation and evidencingcontrol effectiveness

Support operational resilience against evolving cybersecurity threatsand vulnerabilities TX-RAMP Level 2 aligns Texas cloud authorizationrequirements with FedRAMP and maps controls to NIST SP 800-53 (andcommonly to CIS Controls or the CSA Cloud Controls Matrix), enablingcloud service providers to pursue state authorization, demonstrateregulatory compliance, and strengthen security governance andoperational controls for sensitive state data.

Framework in Context

TX-RAMP Level 2aligns Texas cloud authorization requirements with FedRAMP and mapscontrols to NIST SP 800-53 (and commonly to CIS Controls or the CSACloud Controls Matrix), enabling cloud service providers to pursuestate authorization, demonstrate regulatory compliance, andstrengthen security governance and operational controls for sensitivestate data.

Common Framework Mappings

Organizations map TX-RAMP Level 2 to established federal,international, and industry frameworks to streamline controls, reuseevidence, and speed authorization across cloud, privacy, and riskprograms.

Mapped frameworks include:

CIS Critical Security Controls

CSA Cloud Controls Matrix

Federal Information Security Modernization Act (FISMA)

FedRAMP

HITRUST CSF

ISO/IEC 27001

NIST Cybersecurity Framework

NIST SP 800-171

NIST SP 800-53

At a Glance
TX-RAMP Level 2 – Moderate
  • checklist
    Classification
    Category
    info
    Cloud Security
    Domain
    info
    Cloud Security
    Framework Family
    info
    FedRAMP
  • info
    Regulatory Context
    Type
    info
    Certification / Assurance Program
    Legal Instrument
    info
    Program
    Sector
    info
    Government Sector
    Industry
    info
    Government & Public Sector
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    North America
    Region Detail
    info
    Texas
    Publisher
    info
    Texas Department of Information Resources (DIR)
  • published_with_changes
    Versioning
    Version
    info
    TX-RAMP Level 2 Baseline
    Effective Date
    info
    2021
    Issue Date
    info
    2021
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

TX-RAMP documentation is publicly available through the Texas Department of Information Resources.

Official Resources
TX-RAMP Level 2 Requirements
Describes the cybersecurity and compliance requirements for cloud services handling sensitive state data.
chevron_forward
Texas Department of Information Resources: TX-RAMP Overview
Provides detailed information about the TX-RAMP framework and its application to Texas state agencies.
chevron_forward
TX-RAMP Compliance Guidelines
Outlines the steps and documentation needed for achieving TX-RAMP Level 2 compliance.
chevron_forward
Texas DIR’s Security Control Standards Catalog
Defines the security controls required for TX-RAMP compliance, aligned with state regulations.
chevron_forward
SMARTSUITE

How SmartSuite Supports US-TX TX-RAMP Level 2

Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.

Moderate-Risk Scope and Boundary

Define Level 2 scope, sensitive data handling, and service dependencies.

Level 2 Control Baseline Library

Track controls with owners, implementation details, and proof of operation.

Assessment and Remediation Workflow

Manage findings, remediation plans, retesting, and closure evidence.

Continuous Monitoring Operations

Schedule scanning, monitoring, and recurring evidence capture to prevent drift.

Vendor Obligation and Review Tracking

Track vendor obligations, evidence, and ongoing reviews for dependencies.

Audit-Ready Reporting

Report readiness, gaps, and monitoring status for assessors and stakeholders.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
FISMA

FISMA is a U.S. law requiring federal agencies and contractors to secure government information systems and manage cybersecurity risks.

Learn More
arrow_forward
HITRUST CSF v11.5

HITRUST CSF is a certifiable, risk-based cybersecurity and privacy framework for managing regulatory compliance and protecting sensitive data.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-171 Rev.2

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For TX-RAMP Level 2 (Texas Risk and Authorization Management Program)

What is TX-RAMP Level 2 used for?

TX-RAMP Level 2 is used to assess, authorize, and monitor cloud computing services that handle confidential or regulated data for Texas state agencies. Its primary purpose is to ensure that cloud vendors implement strong cybersecurity controls and meet regulatory compliance obligations for higher-risk data environments.

Is TX-RAMP Level 2 required for cloud service providers?

Yes, TX-RAMP Level 2 is mandatory for cloud vendors contracting with Texas state agencies if their services process, store, or transmit confidential, regulated, or otherwise sensitive information. Agencies are required to verify that their cloud service providers have achieved and maintain Level 2 authorization.

What organizations and data types does TX-RAMP Level 2 apply to?

TX-RAMP Level 2 applies to all Texas state agencies and higher education institutions utilizing third-party cloud services for regulated or confidential data. It covers any systems that handle sensitive state-regulated data such as personal, financial, or protected health information.

What are the key requirements and artifacts for TX-RAMP Level 2 compliance?

Key requirements include implementation of defined security controls, maintaining detailed documentation, performing third-party assessments, and compiling an authorization package. Artifacts include risk assessment reports, evidence of control operation, continuous monitoring plans, and authorization to operate letters.

How do organizations implement TX-RAMP Level 2 controls?

Organizations implement TX-RAMP Level 2 by mapping prescribed security controls—aligned with NIST SP 800-53—to existing policies and procedures, conducting risk assessments, and remediating gaps. Continuous monitoring, vulnerability management, and incident response processes are established to maintain ongoing compliance.

How does TX-RAMP Level 2 relate to other security frameworks?

TX-RAMP Level 2 is closely aligned with the NIST SP 800-53 control framework and the FedRAMP Moderate baseline, facilitating interoperability with established federal and state security programs. This alignment helps streamline compliance efforts for organizations already familiar with these standards.

What are the ongoing compliance requirements for TX-RAMP Level 2?

Ongoing compliance includes recurring risk assessments, continuous monitoring of controls, periodic third-party reassessments, and timely remediation of identified vulnerabilities. Organizations must maintain up-to-date documentation and provide evidence of ongoing adherence to security and privacy requirements.

How would SmartSuite support TX-RAMP Level 2?

SmartSuite facilitates TX-RAMP Level 2 compliance by providing configurable control libraries, centralized risk management, and automated evidence collection workflows. It enables teams to track remediation, prepare for audits, maintain compliance documentation, and generate real-time reports to demonstrate posture and regulatory adherence.

Operationalize TX-RAMP Level 2 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward