TX-RAMP Level 2 — Texas Risk and Authorization Management Program

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
TX-RAMP Level 2 is a cybersecurity and risk management framework established to assess and authorize cloud computing services used by Texas state agencies handling confidential or regulated data. It aims to ensure that service providers implement robust security controls and meet compliance obligations specific to higher-risk data environments.
Published by the Texas Department of Information Resources (DIR), TX-RAMP applies to cloud vendors and state agencies across Texas that process, store, or transmit confidential or regulated information. The framework outlines requirements for cybersecurity controls, privacy safeguards, risk assessment, and ongoing compliance oversight in alignment with state regulations.
Organizations achieve TX-RAMP Level 2 compliance by implementing prescribed security controls, maintaining documentation, and undergoing regular assessments to verify compliance. The program supports state agencies in fulfilling regulatory requirements for third-party risk management and aligns with broader security frameworks such as NIST SP 800-53 to facilitate interoperability within established information security programs.
Why it Matters
TX-RAMP Level 2 provides a comprehensive approach for Texas stateagencies to manage cybersecurity risk when using cloud services forsensitive data.
Key benefits include:
- Strengthen third-party risk management
Enable agenciesto systematically assess and monitor cloud vendors, reducing exposureto risks from external service providers.
- Enhance data protection practices
Require robustcontrols that support secure processing, storage, and transmission ofconfidential and regulated information.
- Increase audit readiness
Maintain thoroughdocumentation and compliance evidence, supporting timely andefficient responses during regulatory audits and assessments.
- Improve regulatory alignment
Align securitypractices with Texas state requirements and national standards,simplifying compliance efforts across multiple frameworks.
- Promote ongoing compliance oversight
Facilitatecontinuous monitoring and regular assessments to ensure thatimplemented security measures remain effective over time.
How it Works
TX-RAMP Level 2 structures cloud security around a control catalogaligned with NIST SP 800-53 and the FedRAMP Moderate baseline,grouping requirements into control families and governance domains.It establishes an authorization lifecycle and formal risk managementprocesses, including continuous monitoring and periodic reassessmentsto maintain an authorized state.
Organizations implement TX-RAMP Level 2 by mapping security controlsto existing governance programs, performing risk assessments, andbuilding authorization packages for agency review. Teams deploytechnical and procedural security practices, run continuousmonitoring and vulnerability management, coordinate third-partyassessments, and execute incident response and remediation to sustaincompliance and reduce risk.
Within SmartSuite, teams operationalize TX-RAMP Level 2 usingconfigurable control libraries, a centralized risk register, andpolicy governance modules. SmartSuite supports evidence collection,automated compliance tracking, remediation workflows, audit readinesschecklists, and reporting dashboards to monitor posture anddemonstrate adherence to security controls, risk management,governance, and regulatory requirements.
Key Elements
- Security Control Requirements
Establishesdetailed categories of technical and administrative safeguardsmandated for cloud service providers.
- Confidential Data Safeguards
Describesprotocols and criteria for handling, storing, and transmittingconfidential or regulated information.
- Risk Assessment and Management
Outlinesprocesses for identifying, evaluating, and mitigating risksassociated with cloud-hosted sensitive data.
- Continuous Compliance Monitoring
Specifiesmechanisms for ongoing assessment and verification of adherence tosecurity and privacy standards.
- Documentation and Reporting Standards
Definesexpectations for maintaining, updating, and submittingcompliance-related documentation.
- Third-Party Oversight
Organizesresponsibilities and procedures for evaluating and managing thesecurity posture of external vendors.
Framework Scope
TX-RAMP Level 2 is adopted by Texas state agencies and cloud vendorsprocessing, storing, or transmitting confidential or regulated datawithin cloud environments. The framework governs cybersecuritycontrols and privacy safeguards, and is typically implemented whenaddressing regulatory requirements, improving risk management, andsupporting assurance programs for higher-risk data environments.
Framework Objectives
TX-RAMP Level 2 establishes requirements for cybersecurity, riskmanagement, and regulatory compliance for cloud services handlingsensitive Texas state data.
Safeguard confidential and regulated information through robust dataprotection controls
Strengthen risk management processes supporting higher-risk cloudenvironments
Ensure compliance with Texas state cybersecurity and privacyregulations
Enhance ongoing security governance and oversight of cloud serviceproviders
Improve audit readiness by maintaining documentation and evidencingcontrol effectiveness
Support operational resilience against evolving cybersecurity threatsand vulnerabilities TX-RAMP Level 2 aligns Texas cloud authorizationrequirements with FedRAMP and maps controls to NIST SP 800-53 (andcommonly to CIS Controls or the CSA Cloud Controls Matrix), enablingcloud service providers to pursue state authorization, demonstrateregulatory compliance, and strengthen security governance andoperational controls for sensitive state data.
Framework in Context
TX-RAMP Level 2aligns Texas cloud authorization requirements with FedRAMP and mapscontrols to NIST SP 800-53 (and commonly to CIS Controls or the CSACloud Controls Matrix), enabling cloud service providers to pursuestate authorization, demonstrate regulatory compliance, andstrengthen security governance and operational controls for sensitivestate data.
Common Framework Mappings
Organizations map TX-RAMP Level 2 to established federal,international, and industry frameworks to streamline controls, reuseevidence, and speed authorization across cloud, privacy, and riskprograms.
Mapped frameworks include:
CIS Critical Security Controls
CSA Cloud Controls Matrix
Federal Information Security Modernization Act (FISMA)
FedRAMP
HITRUST CSF
ISO/IEC 27001
NIST Cybersecurity Framework
NIST SP 800-171
NIST SP 800-53
- ClassificationCategoryCloud SecurityDomainCloud SecurityFramework FamilyFedRAMP
- Regulatory ContextTypeCertification / Assurance ProgramLegal InstrumentProgramSectorGovernment SectorIndustryGovernment & Public Sector
- Region / PublisherRegionNorth AmericaRegion DetailTexasPublisherTexas Department of Information Resources (DIR)
- VersioningVersionTX-RAMP Level 2 BaselineEffective Date2021Issue Date2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
TX-RAMP documentation is publicly available through the Texas Department of Information Resources.
How SmartSuite Supports US-TX TX-RAMP Level 2
Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.
Moderate-Risk Scope and Boundary
Define Level 2 scope, sensitive data handling, and service dependencies.
Level 2 Control Baseline Library
Track controls with owners, implementation details, and proof of operation.
Assessment and Remediation Workflow
Manage findings, remediation plans, retesting, and closure evidence.
Continuous Monitoring Operations
Schedule scanning, monitoring, and recurring evidence capture to prevent drift.
Vendor Obligation and Review Tracking
Track vendor obligations, evidence, and ongoing reviews for dependencies.
Audit-Ready Reporting
Report readiness, gaps, and monitoring status for assessors and stakeholders.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

FISMA is a U.S. law requiring federal agencies and contractors to secure government information systems and manage cybersecurity risks.

HITRUST CSF is a certifiable, risk-based cybersecurity and privacy framework for managing regulatory compliance and protecting sensitive data.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.
Frequently Asked Questions For TX-RAMP Level 2 (Texas Risk and Authorization Management Program)
TX-RAMP Level 2 is used to assess, authorize, and monitor cloud computing services that handle confidential or regulated data for Texas state agencies. Its primary purpose is to ensure that cloud vendors implement strong cybersecurity controls and meet regulatory compliance obligations for higher-risk data environments.
Yes, TX-RAMP Level 2 is mandatory for cloud vendors contracting with Texas state agencies if their services process, store, or transmit confidential, regulated, or otherwise sensitive information. Agencies are required to verify that their cloud service providers have achieved and maintain Level 2 authorization.
TX-RAMP Level 2 applies to all Texas state agencies and higher education institutions utilizing third-party cloud services for regulated or confidential data. It covers any systems that handle sensitive state-regulated data such as personal, financial, or protected health information.
Key requirements include implementation of defined security controls, maintaining detailed documentation, performing third-party assessments, and compiling an authorization package. Artifacts include risk assessment reports, evidence of control operation, continuous monitoring plans, and authorization to operate letters.
Organizations implement TX-RAMP Level 2 by mapping prescribed security controls—aligned with NIST SP 800-53—to existing policies and procedures, conducting risk assessments, and remediating gaps. Continuous monitoring, vulnerability management, and incident response processes are established to maintain ongoing compliance.
TX-RAMP Level 2 is closely aligned with the NIST SP 800-53 control framework and the FedRAMP Moderate baseline, facilitating interoperability with established federal and state security programs. This alignment helps streamline compliance efforts for organizations already familiar with these standards.
Ongoing compliance includes recurring risk assessments, continuous monitoring of controls, periodic third-party reassessments, and timely remediation of identified vulnerabilities. Organizations must maintain up-to-date documentation and provide evidence of ongoing adherence to security and privacy requirements.
SmartSuite facilitates TX-RAMP Level 2 compliance by providing configurable control libraries, centralized risk management, and automated evidence collection workflows. It enables teams to track remediation, prepare for audits, maintain compliance documentation, and generate real-time reports to demonstrate posture and regulatory adherence.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
