GovRAMP Advisory and Assessment Services

Earning a State Risk and Authorization Management Program (GovRAMP)—formerly known as StateRAMP—authorization to operate (ATO) not only indicates a cloud service provider’s (CSP) ability to meet a state and local government’s strict security standards but can also help unlock a significant revenue stream.

GovRAMP is a security framework designed to standardize cloud security for state, local, and tribal governments, as well as educational institutions. Modeled after Federal Risk and Authorization Management Program (FedRAMP), it follows NIST 800-53 standards.

Leveraging this opportunity requires navigating an intricate, highly prescriptive process that many CSPs underestimate resulting in delayed authorization, increased costs, and an overburdened team.

Expand your business opportunities and level-up your creditability as a CSP with GovRAMP services that can streamline the authorization process and accelerate your go-to-market strategy.

Leverage GovRAMP Advisory Experience

Create a well-crafted GovRAMP security package that passes the required independent assessment with support from our experienced professionals.

Advisory offerings include:

Gap Analyses

Identify areas of concern and document actionable solutions to address them through one-on-one interviews and collaboration with your SMEs to create a gap analysis report.

Documentation Development

Create high-quality implementation statements, policies, and plans that address all GovRAMP requirements and meet GovRAMP standards by leveraging our professionals’ extensive experience.

Diagram Creation and Review

Diagram your application to clearly depict the authorization boundary in accordance with GovRAMP standards, with guidance and support from our professionals who can implement GovRAMP’s preferred diagram protocols.

Engineering Support

Navigate the complexities of building secure GovRAMP environments by collaborating with our engineers, who can provide your technical teams with cloud engineering and architecture support.

Assessment Support

Overcome assessment challenges and keep your authorization process moving forward with insights and guidance from our experienced professionals.

GovRAMP 101 Preparedness

Prepare your organization to meet GovRAMP’s stringent reporting and compliance requirements with preparedness training led by our professionals.

GovRAMP Assessment Services

Undergoing a rigorous GovRAMP assessment is a complex, thorough process in which our assessors perform all requisite tests against the system. As an A2LA-accredited third-party assessment organization (3PAO), Moss Adams conducts GovRAMP assessments for organizations ready to take the next step in the GovRAMP authorization process.

Assessment services include:

Readiness Assessment Reports (RAR)

Achieve GovRAMP Ready status on the marketplace by undergoing a pre-assessment to determine if your cloud service offering (CSO) aligns with the key system functionalities and capabilities required for GovRAMP authorization. This assessment indicates that the CSP is ready to undergo the GovRAMP authorization process, conferring a preliminary GovRAMP Ready status that demonstrates the provider meets foundational requirements but is not yet fully authorized.

Initial Authorization Assessment

Designed for CSPs undergoing the GovRAMP authorization process for the first time, this assessment allows our expert assessors to guide you through all testing requirements, evidence and artifact requirements, and documentation.

Annual Assessment

Once fully authorized, CSPs are required to submit an annual assessment that tests one-third of the control baseline, in addition to other system updates and findings from the previous year’s continuous monitoring cycle.

Significant Change Request (SCR)

For CSPs contemplating potential system changes, this process helps you determine if the change qualifies as a GovRAMP SCR and helps incorporate the change into your continuous monitoring cycle.

How the Assessment Process Works

Each assessment engagement follows GovRAMP’s prescribed testing protocols. Below is an overview of the process.

  • Analyze Documentation. Our GovRAMP professionals review and analyze your submitted documentation package.
  • Inventory Alignment. We match your inventory against detailed GovRAMP diagrams.
  • Perform GovRAMP Testing. Each CSO undergoes GovRAMP-required manual, technical, penetration, and red team testing.
  • Create Risk Exposure Table & Security Assessment Report. After vulnerabilities or findings are confirmed, we create a risk exposure table and security assessment report summarizing each finding, including its risk level and other relevant information from testing.
  • Create Recommendation Report. Our independent 3PAO review and findings are compiled in a Security Assessment Report (SAR) with a recommendation to either issue or not issue an ATO or provisional ATO (P-ATO) or a continuance depending on the authorization path.

Extensive GovRAMP Advisory and Assessment Expertise

Deeply immersed in more than 30 industries, our professionals provide solutions specific to the nuances, challenges, and operations of the sector in which you work—while customizing plans to meet your unique needs.

Armed with a deep knowledge of and experience with all aspects of the GovRAMP authorization process, our professionals bring insights and guidance that can help you successfully earn a GovRAMP authorization while also identifying how to leverage the authorization across all areas of your business.

From gap analyses to technical testing, our subject matter experts collaborate with you to identify crossover with other frameworks—such as FedRAMP, HIPAA, ISO 27000, PCI, and SOC—that can reduce costs and ease the audit burden on your team. We also have extensive technical experience in the technologies and processes needed to support organizations undergoing GovRAMP authorization, such as cybersecurity, IT compliance, and internal audits.

Our one-firm approach allows your organization to tap into the full resources of our firm, integrating guidance and solutions related to finance, tax, and audit concerns, technology services, and risk and IT compliance.

Primary Contacts