Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

TX-RAMP - Texas Risk and Authorization Management Program (Tex. Gov Code 2054.0593)

TX-RAMP is the Texas Risk and Authorization Management Program, mandated by Texas Government Code Section 2054.0593, which directs the Texas Department of…

What TX-RAMP - Texas Risk and Authorization Management Program (Tex. Gov Code 2054.0593) requires

TX-RAMP is the Texas Risk and Authorization Management Program, mandated by Texas Government Code Section 2054.0593, which directs the Texas Department of Information Resources (DIR) to establish a state risk and authorization management program to provide a standardized approach for security assessment, authorization, and continuous monitoring of cloud computing services that process the data of a state agency. The statute requires that a state agency shall require each vendor contracting with the agency to provide cloud computing services for the agency to comply with the requirements of the state risk and authorization management program, and that a state agency may not enter or renew a contract with a vendor to purchase cloud computing services subject to the program unless the vendor demonstrates compliance with program requirements; vendors must maintain program compliance and certification throughout the term of the contract. The statute also permits a vendor to demonstrate compliance by submitting documentation showing compliance with a risk and authorization management program of the federal government or another state that DIR approves. Under the TX-RAMP Program Manual (version 3.1), Level 1 certification is required for cloud computing services categorized by the agency as low-impact information resources and Level 2 certification is required for services categorized as moderate or high impact information resources, as defined by 1 Texas Administrative Code Section 202.1; the state agency determines the required certification level. Provisional certification is achieved after DIR approval of the TX-RAMP Acknowledgment and Inventory Questionnaire and is effective for 18 months, and may also be achieved after a cloud computing service receives an accepted status from StateRAMP or FedRAMP; full certifications are valid for three years subject to compliance with program requirements including required continuous monitoring reports. Section 2054.0593 was added by Acts 2021, 87th Legislature, R.S., Chapter 567 (S.B. 475), Section 2, effective June 14, 2021.

Pillar: Cloud & SaaS · Authority: Texas Department of Information Resources (DIR) under Texas Government Code Section 2054.0593 (added by Acts 2021, 87th Leg., R.S., Ch. 567 (S.B. 475), Sec. 2, effective June 14, 2021); TX-RAMP Program Manual version 3.1; impact categorization definitions per 1 Texas Administrative Code Section 202.1 · Version: 1.0.0 · Last updated:

Primary source: https://dir.texas.gov/sites/default/files/2025-05/TX-RAMP%20Program%20Manual%203.1.pdf

SHA-256 integrity: ac28a39d33bc9ae2c749f14d62ad7982ce25d6837025bff3a85c95c67f6298f6

Primary Citations — 7 traced to source

  • Texas Government Code Sec. 2054.0593(b): the department shall establish a state risk and authorization management program to provide a standardized approach for security assessment, authorization, and continuous monitoring of cloud computing services that process the data of a state agency; the program must allow a vendor to demonstrate compliance by submitting documentation showing compliance with a risk and authorization management program of the federal government or another state that the department approves
  • Texas Government Code Sec. 2054.0593(d)-(f): a state agency shall require each vendor contracting with the agency to provide cloud computing services to comply with program requirements; a state agency may not enter or renew a contract unless the vendor demonstrates compliance; the vendor must maintain program compliance and certification throughout the term of the contract; added by Acts 2021, 87th Leg., R.S., Ch. 567 (S.B. 475), Sec. 2, effective June 14, 2021

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.