Skip to main content
Language Translation
  Close Menu

Indiana RAMP At-a-Glance

Indiana Risk Authorization Management Program (RAMP) At-a-Glance

Any technology product or service that is hosted outside of IOT’s cloud tenant or IOT’s data center is subject to Indiana RAMP.

Any transfer of data outside of IOT’s API is also subject to Indiana RAMP.

Who does Indiana RAMP apply to? Any vendors/agencies/entities that utilize, integrate with, or are otherwise connected to the State’s systems, network, or other IT infrastructure, even if through a 3rd party are subject to the Indiana RAMP policy.

All executive branch state agencies, departments, institutions, and similar entities that are responsible to the Governor of the state of Indiana are also subject to the Indiana RAMP policy. (Referred to in corresponding policies as “Covered Entities.”)

Simply put, if a vendor does business with the state of Indiana, collecting data as a service to a state agency, by definition that data is state data, and that vendor would be subject to the Indiana RAMP policy.

Frequently Asked Questions

The Indiana RAMP (Risk and Authorization Management Program) security level requirements are aligned with GovRAMP Status levels based on the data classification and any additional compliance or regulatory requirements. GovRAMP provides a clear, standardized approach for governments to evaluate, adopt, and manage secure cloud solutions—while aligning procurement, reducing risk, and connecting with a growing network of participating agencies. The GovRAMP Security Program provides a standardized framework to assess and verify cloud security, enabling confident adoption and transparent, ongoing risk management.

Per Executive Order 25-19, Indiana established a Risk and Authorization Management Program (RAMP) effective as of October 14, 2025. The due date for compliance is determined by the execution date of any contract action (including amendments, renewals, or new contract execution). Providers are allowed a period of 12-18 months from the date of contract action/execution to achieve their required compliance level, depending on data type and system criticality.  

GovRAMP strengthens Indiana’s security posture by increasing security standards to national level security hardening. Additional benefits include providing standardization and consistency through a uniform assessment process, cost efficiency leveraging a shared assessment framework, and alignment with National Cybersecurity Strategy.

The best place to start is at https://govramp.org/ or https://govramp.org/programs/state-of-indiana. For GovRAMP related inquiries, contact info@govramp.org or Stacey@govramp.org

For a contract to be executed/signed, Steps 1-2 are all that is required – sign up as a GovRAMP member and submit the snapshot. Once these steps are completed, the process has begun and you will be added to the Progressing List.

It depends on the type of data involved, and how it supports critical infrastructure. Please review the categories below.

GovRAMP Core

  • Data Sensitivity Classification: Nonconfidential OR Confidential – Proprietary
  • No Compliance/Regulatory Requirement
  • Data that is NOT required to be kept confidential by law, by contract, for business reasons, or for any other reason

GovRAMP Authorized

  • Data Sensitivity Classification: Confidential – Sensitive OR Confidential – Proprietary
  • Compliance/Regulatory Requirement: Indiana Code, IRS Pub 1075, HIPAA, PCI, DSS, CMS, FISMA, 20 CFR, 603, FERPA, others as applicable
  • Data that includes PII, PHI, FTI, PCI Data, SSA Data, education records, unemployment records, any other information that is required to be kept confidential by law, by contract, for business reasons, or for any other reasons

GovRAMP Authorized + CJIS Overlay

  • Data Sensitivity Classification: Confidential – Sensitive OR Confidential – Proprietary
  • Compliance/Regulatory Requirement: CJIS Security Policy
  • Specific for CJIS Data

Do cloud offerings support or otherwise affect “critical infrastructure”? AKA - Will the state stop running or will people be in danger if we no longer have access to the system? (The systems and assets that are vital for society’s smooth and safe operation. Examples include, but are not limited to: roads, bridges, power plants, electrical grids, communication or transportation networks, hospitals, banks, essential government facilities, the internet, essential government services.)

No – GovRAMP Core

YES – GovRAMP Authorized

It is important to note that covered entities must abide by GovRAMP requirements for all contracts for any software offerings/cloud offerings, including the API.

In short, each product offering must be certified as compliant, not the vendor as a whole. This policy compliance ensures the highest level of protection for our state network and data.

Does FedRAMP or TxRAMP count?

No, because we are not a federal entity or party to Texas data sharing, therefore we cannot do the continuous monitoring that is required by the Indiana RAMP Policy and Executive Order.

The company I want to contract with said they’re “on prem” so why all the details about a cloud offering?

For the purposes of the Indiana GovRAMP policy, a “cloud offering” is defined as any computing services provided outside of Indiana Office of Technology (IOT) data centers and environments.

Our aim is protect State of Indiana data and systems, while ensuring our valued vendor partners are working toward the same goal. Because we understand the certification process can take time, we regularly review progress made towards certification, and providers are allowed a period of 12-18 months from the date of contract execution to achieve the required category.

Very rarely exceptions may be granted. Exception requests may only originate from a State of Indiana agency. Vendors cannot submit exception requests.

Exception requests will only be received when submitted via IOTContractEceptions@iot.in.gov. All submissions must include agency and vendor contact information to be processed.