25.9.28
This website uses cookies to ensure you get the best experience on our website. Learn more

Ensuring Data Security and Compliance

Da'Zhe Flannigan

GovRAMP is all about cybersecurity – built on the National Institute of Standards and Technology’s (NIST) Special Publication 800-53 Rev. 4 framework, based on and similar to FedRAMP, it works on a “complete once, use many” model intended to save both time and money for state governments and CSPs alike.


But simply choosing a CSP from GovRAMP’s list of certified vendors does not guarantee data security and compliance with regulations. Agencies must understand what their vendors are – and are not – responsible for protecting. The agencies have to ensure that they know what they are responsible for, that they have policies, procedures, and resources in place to address their in-house security and compliance responsibilities.

Issued on

April 23, 2025

Expires on

Does not expire