RAMPQuest Blog

What Do Cloud Service Providers Need to Know About Indiana RAMP?

Written by Kassidy Nelessen | Sep 18, 2026, 2:49:00 PM

Indiana has established a statewide Risk and Authorization Management Program (RAMP) to create more consistent security requirements for cloud offerings used by Indiana state agencies and other covered entities connected to the state’s systems, networks, or IT infrastructure. The program was established following Executive Order 25-19, which directed the Indiana Office of Technology (IOT) to implement a RAMP policy for cloud computing services.

Built on GovRAMP, Indiana RAMP connects cloud procurement with established security verification requirements.

For cloud service providers (CSPs), this means understanding which GovRAMP verification level applies to their offering, how to meet the requirements, and how to maintain that verification over time.

For providers outside Indiana, the policy is worth looking into as well. Indiana is an early example of how states can use standardized cloud security requirements in their procurement processes.

What is Indiana RAMP & Who Does It Affect?

Indiana RAMP is a statewide policy that establishes security requirements for cloud offerings used by Indiana State entities. The policy was established by the Indiana Office of Technology (IOT) and took effect on October 14, 2025.

It applies to executive branch state agencies, departments, institutions, and similar entities responsible to the Governor, as well as other entities that utilize, integrate with, or are otherwise connected to the state's systems, networks, or other IT infrastructure.

The policy can apply to many types of cloud offerings, including:

  • SaaS

  • IaaS

  • PaaS

  • Commercial off-the-shelf products

  • Systems developed by outside vendors

How Does Indiana RAMP Use GovRAMP?

Rather than creating a separate security framework, Indiana RAMP uses GovRAMP verification levels to establish minimum security requirements for cloud offerings.

In other words, Indiana RAMP is Indiana's policy, while GovRAMP provides the security verification framework Indiana uses to establish the required security level.

What Does Indiana RAMP Mean for Cloud Service Providers?

Indiana RAMP means that cloud providers pursuing covered Indiana government opportunities need to understand and meet the GovRAMP verification level required for their offering.

The required verification level depends on factors such as the type of data a cloud offering handles and whether it supports critical state systems.

Providers may have time after contract execution to achieve the required verificatied security level. Indiana's policy allows providers time to achieve the required security level after the contract begins.

That timeframe cannot exceed:

  • 18 months from the effective date of the contract, or

  • One-half of the contract term

Whichever is shorter.

For example, a provider with a four-year contract would have up to 18 months to meet the requirements, while a two-year contract could allow up to one year.

That does not mean providers can wait indefinitely to address security requirements. The time between contract execution and the required verification can be used to close identified security, control, documentation, and evidence gaps.

Preparing before an Indiana opportunity is underway gives providers more time to understand the requirements and address gaps without working against a procurement deadline.

Which GovRAMP Verification Level Does Indiana Require?

The GovRAMP verification level required by Indiana depends on the type of data a cloud offering handles and how the offering is used.

The minimum requirements generally include:

If different requirements apply, the higher security level takes precedence. Indiana entities may also require a higher level when they determine that additional security is needed.

For example, a cloud application that handles only nonconfidential information may otherwise qualify for GovRAMP Core. If that application supports critical infrastructure, however, the minimum requirement may increase to GovRAMP Authorized.

Does Indiana RAMP Require Ongoing Security Monitoring?

Yes. Indiana RAMP requires providers to maintain their required security level throughout the contract, rather than just achieving it once.

Providers must have evidence that their cloud offering continues to meet the required security level at least quarterly. The policy also requires ongoing risk assessments and continuous monitoring throughout the contract.

This means providers need processes that support the ongoing maintenance of their security program, including:

  • Maintaining security controls

  • Keeping documentation and evidence current

  • Monitoring changes to their environment

  • Supporting regular assessments

  • Providing required reports and evidence

For providers, GovRAMP verification should be viewed as an ongoing commitment rather than a one-time milestone.

What If I Already Have FedRAMP?

Cloud providers that already have or are pursuing FedRAMP Rev. 5 status may have a more direct path to meeting Indiana's requirements.

Under GovRAMP's guidance for Indiana, providers with FedRAMP Rev. 5 status or those pursuing FedRAMP Rev. 5 can use the GovRAMP Fast Track program. This allows providers to leverage their existing federal security package rather than starting the process from scratch.

For providers already investing in federal security requirements, understanding this pathway can help reduce unnecessary duplication when expanding into Indiana or other public-sector markets.

What If Your Product Isn't GovRAMP Verified Yet?

Not having a GovRAMP verification status today does not necessarily prevent a provider from pursuing an Indiana Opportunity. Indiana provides a path for providers to work toward the required security level.

Providers that do not currently hold a GovRAMP status are required to enroll in the GovRAMP Progressing Snapshot Program until the minimum verified status is achieved.

The Progressing Snapshot Program provides a structured way for providers to:

  • Assess their current security maturity

  • Identify gaps in required controls

  • Prioritize improvements

  • Build and organize supporting evidence

  • Demonstrate progress toward the required GovRAMP verification level

The goal is to establish a practical path toward verification rather than waiting until a contract deadline makes every security gap urgent.

The Indiana policy allows providers up to 18 months from the effective date of the resulting contract, or one-half of the contract term, whichever is shorter, to achieve the required verified status.

How Can RAMPQuest Help Cloud Providers Get GovRAMP Verified?

As the founding GovRAMP Program Management Office (PMO), RAMPQuest has extensive experience interpreting GovRAMP requirements and evaluating cloud security programs.

That experience gives RAMPQuest a deep understanding of the requirements that form the foundation of Indiana RAMP and what providers need to prepare for GovRAMP verification.

The Consulting & Advisory team can help providers:

  • Understand the GovRAMP requirements that apply to their offering

  • Evaluate their current security program

  • Identify readiness gaps

  • Strategically guide toward verification

  • Help prepare documentation and evidence

  • Establish processes for ongoing monitoring and maintenance

The Consulting & Advisory team focuses on helping organizations prepare, while the GovRAMP PMO independently performs its designated review responsibilities.

For Indiana providers, this means RAMPQuest can help connect Indiana's requirements to the GovRAMP program they are built on. For providers in other states, it provides an opportunity to get ahead of potential government security requirements before they become part of a procurement.

Ready to Get Ahead of GovRAMP Requirements?

Indiana RAMP has made GovRAMP verification an important part of cloud security for providers doing business with the state. But providers do not have to wait for a contract or solicitation to start preparing.

Getting verified now can help your organization address today's requirements while building a stronger foundation for future government opportunities.

RAMPQuest's Consulting & Advisory team can help you understand where you stand, identify what needs to be addressed, and develop a practical path toward GovRAMP verification and ongoing maintenance.