RAMPQuest Blog

Arizona vs Indiana: What Providers Should Know About GovRAMP Requirements

Written by Kassidy Nelessen | Sep 14, 2026, 2:40:16 PM

If you’re a provider looking to sell cloud services to state and local governments, Arizona and Indiana are two states worth paying close attention to. Both use many of the same factors to determine required GovRAMP statuses, including data sensitivity and critical infrastructure considerations.

Those similarities can help providers plan their security strategy more efficiently. But it does not mean the requirements are exactly the same. Understanding the overlap and the differences can help you decide where to invest in your security program and how to prepare for individual opportunities.

What Do Arizona and Indiana Have in Common?

Arizona and Indiana both consider the type and sensitivity of data involved and whether a cloud offering supports or affects critical infrastructure when determining the security requirements for an opportunity.

Both States Consider Data and Critical Infrastructure

Indiana formalizes these considerations through two minimum security level matrices. One addresses data type, while the other addresses critical infrastructure.

If the two matrices result in different minimum-security levels, Indiana requires the higher level.

For providers pursuing opportunities in both states, this creates a useful starting point. Because both states rely on similar decision factors, there can be significant overlap in the security work needed to support multiple opportunities.

Both States Allow for Progressing Toward the Required Status

Both states also have provisions for providers that have not yet achieved the required GovRAMP status. In certain circumstances, providers may be required to participate in the GovRAMP Progressing Snapshot program and make progress toward the appropriate security designation before handling certain state data. 

What Should Providers Ask?

When evaluating an opportunity, ask:

  • What data will the solution handle?

  • How will the customer use the solution?

  • Does the solution support or affect critical infrastructure?

  • Does the solution handle data subject to additional requirements, such as CJIS?

  • If the required GovRAMP status has not been achieved, does the opportunity require GovRAMP Progressing Snapshot participation?

What GovRAMP Status Could Be Required?

Depending on those factors, a provider may encounter requirements for:

  • GovRAMP Core at Moderate

  • GovRAMP Authorized at Moderate

  • GovRAMP Authorized at Moderate with a CJIS Overlay

The exact determination still depends on the state’s policy, the customer, and the specific opportunity.

How Do Arizona GovRAMP Requirements Work?

Arizona’s cloud security program is transitioning from the Arizona Risk and Authorization Management Program (AZRAMP) to GovRAMP. For new contracts beginning July 1, 2025, Arizona includes risk assessment requirements aligned with GovRAMP, while renewal contracts beginning July 1, 2026, include requirements aligned with GovRAMP or FedRAMP.

Arizona uses the data impact of a cloud offering and its relationship to critical infrastructure to determine the security requirements that apply to an opportunity.

How Does Data Sensitivity Affect the Requirement?

For example, a solution handling less sensitive data may fall under GovRAMP Core at Moderate, while a solution handling certain types of confidential information may require GovRAMP Authorized at Moderate.

Additional requirements, such as CJIS, may also apply depending on the solution and customer.

Why Does Critical Infrastructure Matter?

Critical infrastructure can also affect the security requirements a provider needs to meet. Arizona considers areas such as:

  • Energy

  • Water

  • Transportation

  • Communications

  • Healthcare

  • Financial services

  • Essential government services

The same solution could require different GovRAMP statuses depending on the sensitivity of the data involved, the customer’s intended use case, and whether critical infrastructure considerations apply.

What Does Arizona's Timeline Look Like?

Timing is another area providers should evaluate early.

Arizona publishes default timeframes associated with GovRAMP statuses, but the solicitation and resulting contract determine the specific requirements and timeframe for each opportunity.

The current Arizona guidance provides the following default timeframes:

  • GovRAMP Core: achieved no later than 12 months from contract award

  • GovRAMP Ready: at least 12 months, but no more than 18 months

  • GovRAMP Authorized: at least 18 months, but no more than 24 months

These timeframes are statewide defaults, so providers should review the solicitation and contract to confirm the deadline that applies to a specific opportunity.

Arizona also has provisions for certain exceptions and may include additional assessment requirements, such as CJIS or HIPAA, in the contract.

How do Indiana GovRAMP Requirements Work?

Indiana’s Risk and Authorization Management Program policy took effect October 14, 2025. It applies to covered state entities and cloud contracts executed, amended, or renewed under the policy.

Indiana uses two matrices to determine the minimum GovRAMP status required for a cloud offering.

What Does Indiana’s Data Matrix Require?

The first matrix looks at data type:

  • Nonconfidential data: GovRAMP Core at Moderate

  • Confidential data: GovRAMP Authorized at Moderate

  • CJIS data: GovRAMP Authorized at Moderate + CJIS Overlay

What Does Indiana’s Critical Infrastructure Matrix Require?

The second matrix looks at critical infrastructure.

If a cloud offering supports or could affect critical infrastructure, the minimum requirement under that matrix increases to GovRAMP Authorized at Moderate.

If the two matrices result in different requirements, Indiana requires the higher security level.

For providers, this makes it important to understand both the data involved and how the customer will use the solution before determining the security work an opportunity may require.

What Does Indiana's Timeline Look Like?

Indiana provides a more specific timeline than Arizona.

The policy allows a maximum of 18 months from contract execution to achieve the required GovRAMP status, although the policy also limits the timeframe to one-half of the contract term when that period is shorter.

That means providers should think about the security work needed for an Indiana opportunity early in the sales and contracting process, not after the contract is already underway.

What Happens After the Required Status Is Achieved?

Providers should also account for the continuous monitoring requirements associated with their GovRAMP status.

For example, Indiana requires ongoing monitoring and quarterly evidence that providers continue to meet the required security level.

Where do Arizonia and Indiana Differ?

The biggest differences between Arizona and Indiana are how requirements are applied to an opportunity and how providers are expected to meet them.

Arizona: More Opportunity-Specific

Arizona puts more emphasis on the specific solicitation and contract.

  • The state publishes default GovRAMP timeframes.

  • The solicitation and resulting contract determine the specific requirements and timeline.

  • Additional assessment requirements, such as CJIS, may be incorporated into the contract.

  • Providers should review the opportunity carefully rather than relying solely on statewide defaults.

Indiana: More Standardized

Indiana takes a more standardized approach.

  • Statewide matrices determine the minimum GovRAMP status.

  • Data classification affects the required status.

  • Critical infrastructure can increase the minimum requirement.

  • The higher requirement applies when the two matrices result in different levels.

  • Indiana establishes a maximum timeframe for achieving the required status.

What About Ongoing Requirements?

Ongoing requirements are another consideration. Both states have ongoing reporting and security requirements, but providers should review the applicable state policy, solicitation, and contract to understand what they will need to maintain throughout the engagement.

The similarities can make planning easier, but the state-specific differences matter when you pursue an actual opportunity.

Understanding both can help providers identify where their existing security work can be reused and where additional planning may be required.

Can a GovRAMP Strategy Support Opportunities in Both States?

It can.

Because Arizona and Indiana both recognize GovRAMP Core and GovRAMP Authorized, providers may be able to use the same security foundation across opportunities in both states.

What Status Should Providers Target?

The right target depends on the markets and contracts a provider plans to pursue.

Core may be enough for opportunities with lower security requirements, while Authorized can provide a stronger foundation for opportunities that require a higher level of security.

Meeting a GovRAMP requirement in one state does not automatically satisfy the other.

Providers still need to review:

  • Specific solicitation requirements

  • Data requirements

  • Critical infrastructure considerations

  • CJIS requirements

  • Implementation timelines

  • Contract requirements

The benefit is that the underlying security work—such as controls, policies, documentation, evidence, and processes—can often support multiple state opportunities. For providers looking to expand into more than one state, that can make the investment in their security program more useful over time.

What Should Providers do if They Want to Work in Both Arizona and Indiana?

Start by looking at the two states together, but plan for each state's specific requirements.

If you are pursuing opportunities in both Arizona and Indiana, think about these five steps:

1. Identify the types of data your solution will handle.

The data involved can affect the minimum GovRAMP designation required for an opportunity.

2. Determine whether your solution supports critical infrastructure.

Both states consider how a cloud solution is used and whether it supports or affects critical infrastructure.

3. Determine whether CJIS requirements apply.

If your solution handles CJIS data, additional requirements may apply.

4. Understand the timeline for each opportunity.

Arizona timelines can be established through the solicitation, while Indiana provides a maximum 18-month timeframe from contract execution.

5. Look for opportunities to reuse your security work.

Rather than approaching every state independently, consider how a GovRAMP strategy can support your broader state and local government sales goals.

Planning for Arizona and Indiana? Start With the States You Want to Serve. 

Tell us which states you're targeting, and we'll help you identify potential GovRAMP requirements, authorization paths, timelines, and planning considerations that could affect your ability to compete in those markets.

The earlier you understand those requirements, the easier it becomes to make security investments that support multiple state opportunities instead of approaching each new market as a separate compliance effort.