The Georgia Technology Authority (GTA) announced on Sept. 9 that the state will adopt GovRAMP as its primary framework for authorizing and continuously monitoring third-party cloud services. The new requirement goes into effect Oct. 1.

Under the new policy, all new state procurements and contracts that include cloud services must meet security and risk assessment requirements aligned with GovRAMP, according to a press release. Cloud services purchased through Georgia’s enterprise IT procurement process will require GovRAMP validation and GTA approval.

The framework is intended to give agencies a consistent approach to evaluating cloud services, increase visibility into cybersecurity risks, and reduce duplicative security assessments. GovRAMP aligns with National Institute of Standards and Technology (NIST) Special Publication 800-53 Revision 5 security controls.

“Georgia is committed to delivering secure and innovative digital services,” said Shawnzia Thomas, state chief information officer and GTA executive director.

“Our partnership with GovRAMP provides a trusted framework for evaluating and monitoring cloud solutions, helping agencies adopt technology faster, strengthen cybersecurity and better protect the systems and data that support state government,” Thomas added.

Georgia will provide an initial transition period for vendors to obtain the required GovRAMP status, including interim verification pathways for qualifying providers that are actively progressing through the process.

Beginning July 1, 2027, full compliance with the state’s GovRAMP verification requirements will be mandatory for all procurements containing a cloud service component.

Existing cloud contracts will become subject to the requirements when they are renewed, extended, significantly modified, or put out for a new solicitation. Continuous monitoring must be maintained throughout the lifecycle of contracts subject to Georgia’s requirements, according to the state’s GovRAMP program page.

GTA’s Office of Information Security and GovRAMP will also hold educational sessions for agencies and vendors. The sessions will address verification pathways, continuous monitoring, procurement requirements, and provider responsibilities. The GovRAMP program page lists a vendor training session for Sept. 18.

Read More About