State CIOs adopted generative AI faster than almost anyone predicted: 82% of state IT organizations report employees using GenAI tools daily in 2025, and 90% have pilot projects running (NASCIO 2025 State CIO Survey, via StateScoop), up from just 53% who said the same in NASCIO's 2024 survey (StateScoop, "Just Half of State CIOs Say Employees Use Generative AI in Daily Work"). Only 25% have dedicated funding for it. That gap between adoption and budget is exactly where a rushed GPU vendor decision goes wrong, and it's why the question "is this GPU cloud GovRAMP compliant" is showing up in more state and local RFPs every quarter.
GovRAMP is the state, local, and education (SLED) equivalent of FedRAMP, and unlike a lot of compliance framework noise, it has real, checkable substance right now: a February 2025 rebrand that widened its scope, a brand-new Core Status fast path launched in May 2025, and live state mandates already on the books in North Carolina and Arizona. This guide covers what GovRAMP actually requires, where GPU clouds stand against it today, and how to handle confidential state workloads while you wait. For the federal-only version of this same question, see our FedRAMP GPU cloud buyer's guide, which walks through the equivalent authorization chain for civilian and defense agencies.
GovRAMP vs FedRAMP: What's Different for State and Local Agencies
GovRAMP and FedRAMP both build their control baselines on NIST SP 800-53 Rev 5, but they authorize different customers. FedRAMP authorizes cloud services for federal agencies. GovRAMP authorizes them for state, local, tribal, and education governments, administered by a nonprofit rather than a federal program office (Vanta, "GovRAMP vs. FedRAMP"). If your agency is a state executive branch, a county government, a school district, or a public university, GovRAMP is the framework built for you, not FedRAMP.
The StateRAMP-to-GovRAMP Rebrand and Why the Scope Widened (Feb 2025)
StateRAMP announced its public rebrand to GovRAMP on February 14, 2025, keeping StateRAMP as the organization's legal name while operating publicly under the new one. President J.R. Sloan explained the reasoning plainly: "Our mission remains the same, advancing trusted cloud security standards, but our name is evolving to better reflect the community we serve" (GovRAMP announcement).
The rename wasn't cosmetic. GovRAMP's scope now explicitly covers state executive agencies, cities and counties, judicial courts, K-12 schools and regional networks, higher education institutions, and at least one tribal territory (StateTech Magazine, "StateRAMP Rebrands to GovRAMP"). Executive Director Leah McGrath said the old name had been turning away exactly the governments it was built to serve: "StateRAMP was a misnomer because many of these local government leaders would call us and say, 'We would really like to participate, but we're not sure if StateRAMP is for us,' because of the word state in our name." If you're a school IT director or a county CISO who assumed StateRAMP didn't apply to you, that assumption is now out of date.
FedRAMP Covers Federal Agencies Only, GovRAMP Covers SLED
The practical split is straightforward. A cloud vendor selling to the Department of Defense or a civilian federal agency needs FedRAMP. A vendor selling to a state DMV, a public school district, or a city police department needs GovRAMP. A vendor that touches both needs both, and one authorization doesn't substitute for the other, even though both frameworks assess against overlapping NIST 800-53 control families.
Vanta's comparison also flags a scope difference worth noting: GovRAMP's SLED customer base handles "a wider range of sensitive non-federal information, including individual health records and student data" than a typical federal civilian agency workload (Vanta). Student records under FERPA and health data under state privacy law both live inside GovRAMP's authorization scope in a way that doesn't map cleanly onto FedRAMP's federal-only frame. If your agency handles K-12 student data specifically, our FERPA-compliant GPU cloud guide covers that overlap in more detail.
Where the Two Frameworks Overlap on NIST 800-53 Controls
Both frameworks derive their control catalogs from the same NIST SP 800-53 Rev 5 baseline, which is genuinely useful if your organization is pursuing both: a lot of the underlying evidence, documentation, and control implementation work transfers. It's not automatic reciprocity, but it's not starting from zero either. A vendor that's done the work for FedRAMP Moderate has already built most of what GovRAMP Moderate requires; the gap is procedural, not architectural.
Authorization Tiers and the New Core Status Fast Path
GovRAMP has four distinct statuses, and the newest one, Core, exists specifically to lower the bar for vendors that would otherwise sit outside the marketplace entirely. Knowing which status a vendor actually holds, not which one they're "working toward," is the single most important question in any SLED AI procurement conversation.
Core, Ready, Provisional, and Authorized: The Four Statuses Explained
| Status | What it means | Assessor | Expires? |
|---|---|---|---|
| Core | 60 priority controls verified | GovRAMP PMO directly, no 3PAO | Quarterly monitoring |
| Ready | Readiness Assessment Report complete | Accredited 3PAO | Does not expire |
| Provisional | Partial authorization, in progress toward full status | 3PAO + PMO review | Time-limited |
| Authorized | Full authorization to operate, granted by a government body | 3PAO + government authorizing official | Annual continuous monitoring |
Ready status is a genuine procedural advantage over its FedRAMP counterpart: "Unlike FedRAMP Ready (which expires after one year), the GovRAMP RAR does not expire" (Knox Systems, "What is StateRAMP?"). A vendor that earned GovRAMP Ready two years ago is still Ready today, no re-assessment clock running out on them.
GovRAMP's Low and Moderate Baselines (and Why There's No Native High Tier)
GovRAMP Low requires 153 controls; GovRAMP Moderate requires 319, both derived from NIST SP 800-53 Rev 5 (Schellman, "StateRAMP FAQ"). There's no native GovRAMP High. A handful of listed products carry a High designation, but only through reciprocity with an existing FedRAMP High authorization somewhere else in the vendor's stack, not because GovRAMP itself assessed them at that level. If your workload genuinely needs High-level assurance, whether it's a public safety system or a data set with elevated risk, you're looking at a FedRAMP High boundary like AWS GovCloud or Azure Government, not a GovRAMP product, regardless of what a vendor's sales page implies.
Most state AI workloads that touch anything beyond public data land in Moderate. Confidential records, PII, student data, and criminal justice information all typically trigger a Moderate impact determination, which is the baseline every AI vendor conversation in this guide is really about.
Core Status: 60 Controls, No 3PAO, Quarterly Monitoring
GovRAMP launched Core Status on May 5, 2025 as a genuinely new on-ramp, not a rebrand of an existing tier. Core verifies 60 priority NIST SP 800-53 Rev 5 controls, selected using the MITRE ATT&CK framework and aligned with the Moderate Impact baseline, assessed directly by the GovRAMP Program Management Office rather than an outside 3PAO, with quarterly continuous monitoring keeping the status current (GovRAMP, "GovRAMP Introduces Core Status"). Sixty controls against 319 for full Moderate gives you a sense of the size of the gap Core is designed to close, a meaningful floor without the cost and timeline of a full 3PAO engagement.
Maine Deputy CISO Charlie Rote framed why states wanted this tier specifically: Core Status "offers a niche but valuable capability for states to manage third-party risk, providing an additional tool to assess vendor security while enabling cloud providers to demonstrate readiness without requiring a full 3PAO assessment" (GovRAMP). For a procurement officer, that's the practical use case: Core gives you a documented, quarterly-monitored security posture for lower-risk vendor relationships without forcing every vendor through the full Authorized process. It is not, and isn't meant to be, a substitute for Moderate authorization on a system handling confidential data.
Self-Hosting LLMs to Meet GovRAMP Data Handling Requirements
As of mid-2026, no GPU-specific neocloud or GPU IaaS provider shows up with Authorized or Ready status on GovRAMP's Program Participants List, which mirrors the exact gap FedRAMP has at the federal level (GovRAMP, Program Participants List). If your agency's AI workload will touch confidential state data, that absence isn't a technicality to work around, it's the deciding fact. The durable answer right now is the same one we've written about for CUI under CMMC and for PHI under HIPAA: self-host an open-weight model on hardware you control, inside a boundary you can document, rather than betting a procurement timeline on a vendor's compliance roadmap.
Why Shared, Multi-Tenant GPU Instances Are a Non-Starter for Confidential State Data
A shared, multi-tenant GPU instance, the default product most commercial neoclouds sell, puts your inference workload on hardware other tenants also touch, behind a hypervisor and network path that sits outside any boundary you control. For a Moderate-baseline workload handling student records, criminal justice data, or citizen PII, that's disqualifying on its own, independent of whatever other certifications the vendor holds. What Moderate-baseline data actually needs is dedicated capacity: hardware provisioned to your agency alone, on a network segment you control, with no other tenant sharing the box.
This is the identical distinction our CMMC guide makes for CUI and our HIPAA guide makes for PHI: dedicated, single-tenant hardware is a prerequisite for regulated data, not a nice-to-have upsell. The regulated data type changes across those three posts; the architecture answer doesn't.
Sizing an Open-Weight Model to Dedicated, Boundary-Controlled Hardware
Size the model to what you can actually isolate and document, not to whatever tops a leaderboard. A quantized 70B-class open-weight model, Llama, Qwen, or Mistral, runs comfortably on a single dedicated 80GB H100 instance or H200 and covers the bulk of what state agencies actually need from AI right now: document summarization, internal Q&A, and citizen-service chat drafting on data that's already been cleared for that purpose. Every additional GPU in a deployment is another asset that has to sit inside your documented boundary and pass the same access controls as everything else, so a right-sized 70B deployment you can fully account for beats an oversized frontier model you can't.
For unclassified, public-data work that never touches a confidential system, a commercial GPU cloud is a legitimate and much faster option. Spheron pools GPU capacity from 5+ providers through a single API, and current on-demand pricing on the most commonly requested tier looks like this:
| GPU | On-Demand (per GPU/hr) | Spot (per GPU/hr) |
|---|---|---|
| H100 SXM5 | $3.92 | $2.91 |
Pricing fluctuates based on GPU availability. The prices above are based on 01 Aug 2026 and may have changed. Check current GPU pricing → for live rates.
Encryption, Logging, and Data Residency Controls That Map to Moderate Baseline Requirements
Once you have dedicated hardware, the controls that actually satisfy a Moderate baseline determination are the same ones any security team already knows: encryption in transit and at rest, full logging of every prompt and response that touches confidential data, role-based access restricted to authorized personnel, and MFA on the inference endpoint itself. None of that is AI-specific; it's the same identification-and-authentication and audit-and-accountability control families NIST 800-53 already requires, applied to a new kind of endpoint.
For teams that want a hardware-level guarantee on top of that, NVIDIA's Confidential Computing mode encrypts GPU VRAM during computation and supports remote attestation, letting you cryptographically verify the hardware and firmware state before a Moderate-baseline workload ever touches it, available on H100, H200, and B200. Our confidential GPU computing guide covers the attestation flow and KMS integration in detail. Data residency matters too: confirm which physical region your hardware sits in and make sure that region matches whatever data residency language is in your state's procurement contract, since "the cloud" is not a location a Moderate baseline determination will accept as an answer.
What SLED Agencies Should Ask a GPU Cloud Vendor Before Signing
Two states have already turned GovRAMP from a voluntary standard into a contract requirement, and more are following. North Carolina announced that cloud vendors working with executive branch agencies must meet GovRAMP's standard starting April 1, 2026 (StateScoop, "North Carolina to Require GovRAMP"). State CIO Teena Piccione put the stakes in plain terms: "This is about more than compliance. It's about trust and progress." CISO Bernice Russell-Bond added, "Cybersecurity is a shared responsibility." North Carolina's adoption brings the total to more than 23 states that use or recognize the GovRAMP standard, including California, Florida, and Georgia.
Arizona's AZ-RAMP program is transitioning into GovRAMP on its own timeline: new state contracts as of July 1, 2025 already include GovRAMP-aligned risk assessment requirements, and as of July 1, 2026 contract renewals must align with GovRAMP or FedRAMP standards too, with vendors given up to 12 months from contract award to reach Core status and 18 to 24 months to reach full Authorized status, depending on the risk tier assigned (GovRAMP, Arizona program page). A single GovRAMP audit also passports across the ecosystem: one assessment lets a vendor "passport" its status to more than 25 participating states without a separate audit in each one (Captain Compliance, "RAMP Requirements by State"). If your state hasn't mandated GovRAMP yet, this is the direction the market is already moving, and a GPU vendor conversation today should assume that trajectory.
The Vendor Question Checklist (Status, Sponsor, Data Residency, Hardware)
Ask these in writing before a single confidential record reaches the platform:
- What GovRAMP status do you hold today, exactly, not "in progress"? Core, Ready, Provisional, and Authorized are not interchangeable answers, and as of mid-2026 no GPU-specific neocloud holds the latter two.
- If you're not authorized, do you have a state sponsor and a documented assessment timeline, or is this aspirational?
- Is this dedicated, single-tenant hardware, or a shared multi-tenant instance? Multi-tenant is disqualifying for Moderate-baseline data regardless of other certifications.
- Where physically does the hardware sit, and does that match your contract's data residency requirements?
- Can the deployment run with full prompt-and-response logging, RBAC, and MFA on the inference endpoint, and can you audit that yourself?
A vendor's SOC 2 report doesn't answer any of these; our SOC 2 compliant GPU cloud guide covers why that certification's scope is narrower than it looks and shouldn't be mistaken for a government-authorization equivalent.
Where Spheron Fits (and Doesn't) for SLED AI Workloads
Spheron pools GPU capacity from 5+ providers through a single API and dashboard, a fast, cost-transparent option for the unclassified side of state AI work: public-data research, model evaluation, and internal prototyping that never touches a confidential system (Spheron overview docs). It is not GovRAMP authorized, and as this guide has tried to make clear, neither is any other GPU-specific neocloud on the market right now. If your workload falls under a Moderate baseline determination, that's the line: self-host on dedicated, boundary-controlled hardware, and don't take a vendor's roadmap slide as a substitute for a status they don't yet hold.
If your agency's AI workload is genuinely unclassified, R&D, or evaluation work on public data, Spheron's pooled GPU capacity is a fast way to get started. If it touches confidential state or citizen data, this guide's point stands: self-host on dedicated hardware, and verify a vendor's actual GovRAMP status in writing before you sign.
Frequently Asked Questions
Yes. StateRAMP rebranded its public-facing name to GovRAMP on February 14, 2025 to reflect a scope that now covers cities, counties, K-12 schools, higher education, judicial courts, and tribal governments, not just state executive agencies. StateRAMP remains the organization's legal name; GovRAMP is the name you'll see on the website, the marketing, and most current documentation.
No. As of mid-2026, a review of GovRAMP's public Program Participants List turns up no GPU-specific neocloud or GPU IaaS provider with Authorized or Ready status. The gap mirrors FedRAMP, where no neocloud holds an active federal authorization either. Agencies evaluating GPU vendors for confidential or Moderate-baseline data should assume that status doesn't exist yet and plan accordingly.
Core (launched May 5, 2025) verifies 60 priority NIST 800-53 controls directly through the GovRAMP Program Management Office, no third-party assessor required, with quarterly monitoring. Ready means an accredited 3PAO has completed a Readiness Assessment Report; unlike FedRAMP Ready, it doesn't expire. Authorized is the full status: a state or local government agency has formally granted authorization to operate after a complete assessment against the Low (153 controls) or Moderate (319 controls) baseline.
No. GovRAMP directly authorizes only Low and Moderate baselines. A small number of listed offerings carry a High designation, but only through reciprocity with an existing FedRAMP High authorization elsewhere, not through a direct GovRAMP assessment. If your workload needs High-level assurance, you're looking at a FedRAMP High boundary (AWS GovCloud, Azure Government, and similar), not a native GovRAMP product.
Yes, for workloads that don't touch confidential or citizen data: public-data research, model evaluation, internal prototyping. For anything that would fall under a Moderate baseline determination, self-host an open-weight model on dedicated, single-tenant hardware inside a boundary you control rather than waiting on a vendor's compliance page to change.
