If you’re a provider looking to sell cloud services to state and local governments, Arizona and Indiana are two states worth paying close attention to. Both use many of the same factors to determine required GovRAMP statuses, including data sensitivity and critical infrastructure considerations.
Those similarities can help providers plan their security strategy more efficiently. But it does not mean the requirements are exactly the same. Understanding the overlap and the differences can help you decide where to invest in your security program and how to prepare for individual opportunities.
Arizona and Indiana both consider the type and sensitivity of data involved and whether a cloud offering supports or affects critical infrastructure when determining the security requirements for an opportunity.
Indiana formalizes these considerations through two minimum security level matrices. One addresses data type, while the other addresses critical infrastructure.
If the two matrices result in different minimum-security levels, Indiana requires the higher level.
For providers pursuing opportunities in both states, this creates a useful starting point. Because both states rely on similar decision factors, there can be significant overlap in the security work needed to support multiple opportunities.
Both states also have provisions for providers that have not yet achieved the required GovRAMP status. In certain circumstances, providers may be required to participate in the GovRAMP Progressing Snapshot program and make progress toward the appropriate security designation before handling certain state data.
When evaluating an opportunity, ask:
What data will the solution handle?
How will the customer use the solution?
Does the solution support or affect critical infrastructure?
Does the solution handle data subject to additional requirements, such as CJIS?
If the required GovRAMP status has not been achieved, does the opportunity require GovRAMP Progressing Snapshot participation?
Depending on those factors, a provider may encounter requirements for:
GovRAMP Core at Moderate
GovRAMP Authorized at Moderate
GovRAMP Authorized at Moderate with a CJIS Overlay
The exact determination still depends on the state’s policy, the customer, and the specific opportunity.
Arizona’s cloud security program is transitioning from the Arizona Risk and Authorization Management Program (AZRAMP) to GovRAMP. For new contracts beginning July 1, 2025, Arizona includes risk assessment requirements aligned with GovRAMP, while renewal contracts beginning July 1, 2026, include requirements aligned with GovRAMP or FedRAMP.
Arizona uses the data impact of a cloud offering and its relationship to critical infrastructure to determine the security requirements that apply to an opportunity.
For example, a solution handling less sensitive data may fall under GovRAMP Core at Moderate, while a solution handling certain types of confidential information may require GovRAMP Authorized at Moderate.
Additional requirements, such as CJIS, may also apply depending on the solution and customer.
Critical infrastructure can also affect the security requirements a provider needs to meet. Arizona considers areas such as:
Energy
Water
Transportation
Communications
Healthcare
Financial services
Essential government services
The same solution could require different GovRAMP statuses depending on the sensitivity of the data involved, the customer’s intended use case, and whether critical infrastructure considerations apply.
Timing is another area providers should evaluate early.
Arizona publishes default timeframes associated with GovRAMP statuses, but the solicitation and resulting contract determine the specific requirements and timeframe for each opportunity.
The current Arizona guidance provides the following default timeframes:
GovRAMP Core: achieved no later than 12 months from contract award
GovRAMP Ready: at least 12 months, but no more than 18 months
GovRAMP Authorized: at least 18 months, but no more than 24 months
These timeframes are statewide defaults, so providers should review the solicitation and contract to confirm the deadline that applies to a specific opportunity.
Arizona also has provisions for certain exceptions and may include additional assessment requirements, such as CJIS or HIPAA, in the contract.
Indiana’s Risk and Authorization Management Program policy took effect October 14, 2025. It applies to covered state entities and cloud contracts executed, amended, or renewed under the policy.
Indiana uses two matrices to determine the minimum GovRAMP status required for a cloud offering.
The first matrix looks at data type:
Nonconfidential data: GovRAMP Core at Moderate
Confidential data: GovRAMP Authorized at Moderate
CJIS data: GovRAMP Authorized at Moderate + CJIS Overlay
The second matrix looks at critical infrastructure.
If a cloud offering supports or could affect critical infrastructure, the minimum requirement under that matrix increases to GovRAMP Authorized at Moderate.
If the two matrices result in different requirements, Indiana requires the higher security level.
For providers, this makes it important to understand both the data involved and how the customer will use the solution before determining the security work an opportunity may require.
Indiana provides a more specific timeline than Arizona.
The policy allows a maximum of 18 months from contract execution to achieve the required GovRAMP status, although the policy also limits the timeframe to one-half of the contract term when that period is shorter.
That means providers should think about the security work needed for an Indiana opportunity early in the sales and contracting process, not after the contract is already underway.
Providers should also account for the continuous monitoring requirements associated with their GovRAMP status.
For example, Indiana requires ongoing monitoring and quarterly evidence that providers continue to meet the required security level.
The biggest differences between Arizona and Indiana are how requirements are applied to an opportunity and how providers are expected to meet them.
Arizona puts more emphasis on the specific solicitation and contract.
The state publishes default GovRAMP timeframes.
The solicitation and resulting contract determine the specific requirements and timeline.
Additional assessment requirements, such as CJIS, may be incorporated into the contract.
Providers should review the opportunity carefully rather than relying solely on statewide defaults.
Indiana takes a more standardized approach.
Statewide matrices determine the minimum GovRAMP status.
Data classification affects the required status.
Critical infrastructure can increase the minimum requirement.
The higher requirement applies when the two matrices result in different levels.
Indiana establishes a maximum timeframe for achieving the required status.
Ongoing requirements are another consideration. Both states have ongoing reporting and security requirements, but providers should review the applicable state policy, solicitation, and contract to understand what they will need to maintain throughout the engagement.
The similarities can make planning easier, but the state-specific differences matter when you pursue an actual opportunity.
Understanding both can help providers identify where their existing security work can be reused and where additional planning may be required.
It can.
Because Arizona and Indiana both recognize GovRAMP Core and GovRAMP Authorized, providers may be able to use the same security foundation across opportunities in both states.
The right target depends on the markets and contracts a provider plans to pursue.
Core may be enough for opportunities with lower security requirements, while Authorized can provide a stronger foundation for opportunities that require a higher level of security.
Meeting a GovRAMP requirement in one state does not automatically satisfy the other.
Providers still need to review:
Specific solicitation requirements
Data requirements
Critical infrastructure considerations
CJIS requirements
Implementation timelines
Contract requirements
The benefit is that the underlying security work—such as controls, policies, documentation, evidence, and processes—can often support multiple state opportunities. For providers looking to expand into more than one state, that can make the investment in their security program more useful over time.
Start by looking at the two states together, but plan for each state's specific requirements.
If you are pursuing opportunities in both Arizona and Indiana, think about these five steps:
The data involved can affect the minimum GovRAMP designation required for an opportunity.
Both states consider how a cloud solution is used and whether it supports or affects critical infrastructure.
If your solution handles CJIS data, additional requirements may apply.
Arizona timelines can be established through the solicitation, while Indiana provides a maximum 18-month timeframe from contract execution.
Rather than approaching every state independently, consider how a GovRAMP strategy can support your broader state and local government sales goals.
Tell us which states you're targeting, and we'll help you identify potential GovRAMP requirements, authorization paths, timelines, and planning considerations that could affect your ability to compete in those markets.
The earlier you understand those requirements, the easier it becomes to make security investments that support multiple state opportunities instead of approaching each new market as a separate compliance effort.