SOC 2 Won't Clear a Texas Agency Deal - What TX-RAMP Actually Requires for SaaS
A Texas state agency, university system, or public community college puts TX-RAMP required on an RFP or security pack. You already have SOC 2 Type II and a Trust Center that lists AWS or Azure as TX-RAMP certified. The instinctive reply - that your commercial attestation or the hyperscaler badge should clear the deal - is wrong for in-scope cloud computing services under Texas law. The Texas Risk and Authorization Management Program (TX-RAMP) from Texas DIR is a separate authorization. Program Manual 4.0 (effective 12 Feb 2026) is the current rulebook.
This post is for growth SaaS founders, Heads of Sales, and lone compliance owners bidding or selling into Texas agencies and higher ed who just saw TX-RAMP on a security pack - especially teams that already invested in SOC 2 and need a clear read on levels, Fast Track, hyperscaler limits, and continuous monitoring. If you are searching for TX-RAMP SaaS requirements versus SOC 2, the short version below covers the statute, Level 1 vs Level 2, provisional status, and a practical playbook that keeps Trust Center language accurate.
Does Texas law actually require TX-RAMP for my SaaS?
Short answer: For in-scope cloud computing services, Texas Government Code Section 2054.0593 requires state agencies to contract only with TX-RAMP-certified offerings. SOC 2 is a commercial attestation; it is not a substitute for TX-RAMP.
DIR eligibility framing is clear: state agencies - including university systems and institutions of higher education under Education Code Section 61.003 - must comply when contracting for cloud computing services as defined in Section 2054.0593(a). Cloud service providers must demonstrate compliance to receive and maintain TX-RAMP certification for a given offering. Products that are not cloud computing services sit outside the statute; DIR points vendors and agencies to Appendix D of the Program Manual and the TX-RAMP scoping tool when the boundary is ambiguous. Final determination of whether a product is in scope - and which minimum level applies - sits with the contracting agency or higher-ed buyer (DIR TX-RAMP hub; eligibility; FAQs).
You typically see the ask when:
- A Texas agency or public higher-ed buyer puts TX-RAMP Level 1 or Level 2 language in an RFP, contract, or onboarding pack for a SaaS that will store, process, or transmit agency data.
- Procurement or security reviewers ask for your TX-RAMP certification ID and level - not just a SOC 2 PDF.
- A buyer assumes your hyperscaler TX-RAMP listing means your product is covered, and the review stalls until someone clarifies shared responsibility.
Not every Texas commercial deal needs TX-RAMP. Private-sector Texas buyers often stop at SOC 2, ISO 27001, or questionnaire packs. Treat the agency scope decision and the RFP as the source of truth for that opportunity.
What is TX-RAMP Level 1 vs Level 2 (and provisional)?
DIR describes three certification outcomes that matter commercially (eligibility; Program Manual 4.0):
| Outcome | When it applies | Practical note |
|---|---|---|
| Level 1 | Nonconfidential / low-impact agency data | Minimum level for that data category |
| Level 2 | Confidential / moderate-or-high-impact agency data | Higher bar; agency sets the floor |
| Provisional | Lets agencies contract while you finish full assessment | Manual 4.0: 12 months from grant |
The contracting agency decides the minimum level. Do not guess Level 1 because your SOC 2 report looks clean - ask what data category and impact the buyer assigned to the engagement.
Provisional certification is how many SaaS vendors keep a live procurement moving. Prefer Program Manual 4.0 over older FAQ language here: Manual 4.0 sets provisional at 12 months from the date granted. Older FAQ pages have described an 18-month provisional window; treat Manual 4.0 as controlling for current planning. Full Level 1 or Level 2 is still required by the end of the provisional period. Plan the full assessment calendar when provisional is granted - do not wait until month eleven.
Can SOC 2 Fast Track replace a full TX-RAMP assessment?
No. Fast Track can shorten evidence review; it does not skip TX-RAMP.
Manual 4.0 Section 15 accepts recognized third-party artifacts - including SOC 2 Type 2, ISO 27001 / 27017 / 27018, HITRUST, PCI AOC, CSA STAR II, FISMA, and other DIR-listed reports - as Fast Track inputs when they were conducted within the prior 24 months and are relevant to the SaaS itself. Artifacts that cover only the underlying IaaS do not qualify. DIR may still demand more evidence; Fast Track is discretionary, not a guaranteed shortcut (Program Manual 4.0; FAQs).
DIR also notes that TX-RAMP does not mandate a FedRAMP-style 3PAO. DIR performs the TX-RAMP assessment internally. Existing third-party audit reports help when Fast Track applies; they do not replace the DIR request process.
Timeline honesty: once review starts, the DIR published goal is about 4 weeks to recommendation if documentation is complete and responses are timely. That is a DIR goal, not a service-level guarantee. Volume, gaps, and remediation feedback all move the calendar. DIR charges no certification fee for TX-RAMP - do not invent partner or assessor price bands in your internal briefings (FAQs).
For the broader pattern of why a SOC 2 PDF rarely closes diligence alone, see SOC 2 vs security questionnaires and security compliance questionnaires.
Does my hyperscaler TX-RAMP cover my SaaS?
No. Manual 4.0 Section 16.2 is explicit: SaaS running on certified IaaS/PaaS does not inherit the infrastructure provider TX-RAMP certification. You may inherit applicable infrastructure controls, but you still need separate SaaS certification for the product that touches Texas agency data. There is also no Low-impact SaaS FedRAMP-style shortcut that auto-inherits under TX-RAMP reciprocity notes in the Manual.
| Layer | Who owns it | What TX-RAMP covers |
|---|---|---|
| Physical / hypervisor / base IaaS | Hyperscaler | Hyperscaler TX-RAMP (if certified) |
| Platform defaults vs your configs | Shared | Provider cert does not erase your config risk |
| Your app, identity, tenancy, data handling, logging | You (the SaaS) | Your TX-RAMP certification |
| Agency systems built on your service | Consuming agency | Agency own obligations |
If AEs keep saying we are on AWS, and AWS is TX-RAMP, fix that script before the next Texas RFP. Shared responsibility is the whole point of Section 16.2.
What happens after you certify?
Certification is not a one-time PDF drop. Ongoing obligations include (FAQs; Program Manual 4.0 Section 17 continuous monitoring):
- Vulnerability reporting via SPECTRIM: Level 1 annual; Level 2 quarterly - including severity and remediation/mitigation plans, especially for high and critical findings.
- Breach notification: Notify TX-RAMP within 48 hours of becoming aware of a breach of system security.
- Validity: Level 1 and Level 2 certifications are valid for 3 years with recertification; DIR notifies contacts ahead of expiry (FAQ notes 12- and 6-month reminders).
- Cost to DIR: There is no DIR fee for TX-RAMP certification (state-funded). That does not mean your internal uplift or third-party audit work is free - it means do not invent a DIR filing fee.
- FedRAMP / GovRAMP reciprocity: Reciprocity still exists for FedRAMP and GovRAMP (formerly StateRAMP) authorized products, but auto-add to the TX-RAMP certified list ended in October 2024. You still submit a TX-RAMP request to claim reciprocity. Services certified via those equivalent paths may be exempt from submitting continuous-monitoring artifacts directly to DIR because those duties ride with the equivalent program - agencies should still contract for status-change notice (FAQs).
Holding FedRAMP does not silently equal TX-RAMP after Oct 2024. Plan the request.
How does TX-RAMP differ from FedRAMP, IRAP, and Cyber Essentials?
Same local government assurance family - different geography and artifact. Do not answer a Texas DIR question with a federal marketplace narrative or an AU/UK checklist.
| Artifact | Geography | What it is | Sibling reading |
|---|---|---|---|
| TX-RAMP | Texas state agencies / higher ed cloud | DIR certification for in-scope cloud offerings | This post |
| FedRAMP / FedRAMP 20x | US federal marketplace | US authorization program | FedRAMP 20x requirements; FedRAMP 20x Phase 3 |
| IRAP / ISM | Australian Government cloud | ASD-endorsed assessment; report + matrix; no certificate | IRAP for US SaaS |
| UK Cyber Essentials | UK bids / questionnaires | NCSC baseline cert via IASME bodies | Cyber Essentials for US SaaS |
FedRAMP may help Texas reciprocity - it does not replace the TX-RAMP request. IRAP and Cyber Essentials do not clear Texas agency cloud gates.
A practical TX-RAMP playbook for growth SaaS
- Confirm scope and level with the buying agency - in-scope cloud? Level 1 or Level 2? Provisional acceptable for the procurement calendar?
- Map SOC 2 Type II (and other Fast Track artifacts) to the SaaS boundary - product-relevant reports within 24 months help; IaaS-only reports do not. Decide Fast Track vs full questionnaire path with eyes open that DIR can still ask for more.
- Scope the product boundary that touches Texas agency data - one product path is usually cheaper than platform-wide overscope.
- Put accurate Trust Center language - TX-RAMP Level X certified or provisional status plus certification ID and dates. Never claim FedRAMP covers Texas or that a hyperscaler TX-RAMP listing covers your SaaS. Packaging that language next to SOC 2 is the same Trust Center discipline covered in building trust with a company trust page.
- Plan continuous monitoring before AEs promise go-live - SPECTRIM cadence (annual L1 / quarterly L2), 48-hour breach notify, and 3-year recertification on the calendar.
- Answer Texas agency questionnaires with verifiable specifics - level, certification ID, provisional end date if applicable, boundary summary, hyperscaler non-inheritance note - not we are SOC 2, so we are fine.
Soft next step
If Texas RFPs and security packs are asking for TX-RAMP while your team is still answering we have SOC 2 or our cloud is TX-RAMP certified, the first commercial fix is usually consistent questionnaire and Trust Center language, then a scoped DIR assessment request with the right level and Fast Track artifacts. Workstreet primary help here is security questionnaire automation so level, ID, provisional status, boundary notes, and hyperscaler shared-responsibility wording stay consistent across Texas agency packs. For program ownership on uplift and AE enablement, a light vCISO lane can keep SPECTRIM cadence and Trust Center claims from landing on the founder the week before a bid closes; penetration testing evidence packs often feed the same vulnerability narrative buyers expect alongside continuous monitoring. That is packaging and readiness help - not a claim that Workstreet is DIR or that SOC 2 replaces TX-RAMP for Texas agency buyers.

