Compliance Framework

StateRAMP — state and local government compliance.

StateRAMP is the standardized security assessment program for cloud services sold to state and local government agencies. Built on the same NIST SP 800-53 foundation as FedRAMP, StateRAMP authorization requires demonstrating continuous operation of security controls. MergeGuide enforces the software development controls from the StateRAMP baseline.

StateRAMP and state government procurement

State and local government agencies increasingly require StateRAMP authorization — or FedRAMP equivalent — for cloud software procurement. StateRAMP uses the same NIST SP 800-53 control catalog as FedRAMP, organized into three impact levels (Low, Moderate, High) aligned with data sensitivity.

For software vendors pursuing StateRAMP authorization, the software development controls in the SA and SI families require documented, automated testing processes. MergeGuide provides the automated code-level enforcement and evidence generation required to satisfy these controls.

MergeGuide includes policies that guide implementation of StateRAMP software development controls — with the same OSCAL-compatible evidence artifacts used for FedRAMP, adapted for state agency authorization workflows.

StateRAMP control coverage

MergeGuide templates cover key StateRAMP software development controls at the code level:

  • SA-11 — Developer Testing: automated security testing at PR gate with evidence artifacts
  • SA-15 — Development Process: enforced secure SDLC gates from write time to merge
  • SI-10 — Input Validation: detecting missing validation on externally-facing handlers
  • SI-3 — Malicious Code: detecting injection patterns and insecure code constructs
  • IA-5 — Authenticator Management: detecting hardcoded credentials in code
  • SC-28 — Protection at Rest: detecting unencrypted sensitive data handling
  • AC-3 — Access Enforcement: detecting overprivileged access definitions in code

StateRAMP detection patterns

800-53 Control (StateRAMP) What MergeGuide Detects Severity
IA-5 — Authenticator ManagementHardcoded passwords, API keys, and secrets in source codeCritical
SI-10 — Input ValidationSQL injection patterns — unparameterized queries with user-controlled inputCritical
SI-3 — Malicious Code ProtectionCommand injection and unsafe deserialization patternsCritical
SC-28 — Protection at RestGovernment data fields stored without encryption in application codeHigh
SC-8 — Transmission ConfidentialityData transmitted over HTTP or deprecated TLS protocolsHigh
AC-3 — Access EnforcementOverprivileged IAM role definitions in infrastructure-as-codeHigh
SA-11 — Developer TestingSecurity coverage gaps at PR evaluation gateMedium
🏛️

State agency ready

MergeGuide's StateRAMP template maps directly to the NIST SP 800-53 controls required by state authorization programs. Evidence artifacts are compatible with state agency security review processes and support third-party assessor (3PAO equivalent) reviews.

📄

OSCAL evidence output

Every PR Gate evaluation generates OSCAL Assessment Results mapped to 800-53 control IDs. These artifacts feed directly into your StateRAMP System Security Plan documentation and satisfy continuous monitoring reporting requirements.

🔄

FedRAMP reuse

Organizations pursuing both FedRAMP and StateRAMP authorization can use a single MergeGuide policy set for both programs. PolicyMerge resolves any control differences between the two baselines, eliminating duplicate assessment work across federal and state authorization tracks.

Selling software to state and local government?

See how MergeGuide enforces StateRAMP controls and generates continuous authorization evidence in a live demo.

Book a demo Talk to sales