Skip to content

Compliance infrastructure for State & Local Government

GovRAMP verifies cloud security once for its members. CJIS mandates MFA for all criminal justice access. Federal grants carry cybersecurity conditions that outlive the award. Each layer adds complexity. Thalorin unifies it.

Abstract gradient
The Reality

State and local compliance doesn't follow a single framework. It follows dozens—overlapping, evolving, sometimes contradictory.

GovRAMP — the programme that rebranded from StateRAMP in February 2025 — provides standardized cloud security verification for its members. But Texas runs TX-RAMP with different requirements, and other states maintain their own standards. A vendor serving multiple states navigates multiple authorization paths.

Law enforcement systems require FBI CJIS Security Policy compliance—19 policy areas, mandatory MFA since October 2024, fingerprint-based background checks for anyone accessing criminal justice information. Version 6.0 arrived January 2025 with NIST 800-53 alignment.

Federal grants carry 2 CFR 200 requirements, including the new cybersecurity mandate under §200.303(e). SLCGP funding may end after FY 2025. The money comes with strings, and the strings require documentation.

Twenty states will have comprehensive privacy laws by 2026.

Thalorin maps controls across these frameworks once. When GovRAMP updates its baselines or CJIS releases a new version, the mappings update. Your compliance posture stays current without re-implementation.

Framework Coverage

State and local environments require flexibility across state-specific programs, federal requirements, and law enforcement standards. The Feynman Engine maintains mappings across all of them.

StateRAMP/GovRAMP

Automated

Cloud security verification, all categories

TX-RAMP

Complete coverage

Texas state requirements, Level 1 & 2

State Privacy Laws

Requirement tracking

20+ state frameworks

Capabilities

NIST CSF as the foundation. NIST 800-53 for federal alignment. GovRAMP for cloud verification. CJIS for law enforcement. CIS Controls for operational security. Controls mapped once, relationships maintained as each framework evolves independently.

Nineteen policy areas. Thirty-eight access control requirements. Personnel background checks. Training records. Encryption status. MFA implementation across all CJI access points. Thalorin tracks every requirement and prepares documentation for state CSOs and FBI auditors.

Federal grants carry obligations that extend beyond the performance period. SEFA preparation, Single Audit documentation, cost allocation, subrecipient monitoring, match and cost-share calculations, reporting deadlines. Missing a requirement can mean returning funds.

Cloud services must meet GovRAMP, TX-RAMP, or state-specific requirements. Contractors accessing CJI need CJIS Security Addendums. Thalorin tracks vendor certifications, manages security addendums, monitors subcontractor compliance, and alerts when certifications approach expiration.

For cloud providers serving state and local government, a GovRAMP authorization is assessed once and recognised by participating members. Evidence collection, control implementation tracking, Category 1/2/3 baseline alignment, assessment package preparation.

Twenty states with comprehensive privacy laws by 2026—each with different requirements, exemptions, and enforcement. Government exemptions vary by state and don't always apply when agencies act commercially or handle data outside official capacity. Thalorin tracks applicable requirements and monitors legislative changes.

Use Cases

Law Enforcement CJIS Compliance

Challenge

A state law enforcement agency operating systems connected to FBI CJIS databases faced the October 2024 MFA mandate and upcoming v6.0 transition. Personnel background checks, security training, and encryption status tracked across disconnected systems with no unified visibility.

Solution

Comprehensive CJIS compliance dashboard covering all 19 policy areas. MFA implementation tracking across every CJI access point. Personnel security management with fingerprint-based background check status. Training completion monitoring with automated reminders. Encryption verification for data at rest and in transit.

Outcome

Full visibility into CJIS compliance posture. Audit preparation automated. Transition to v6.0 tracked by control priority rather than by a single date: MFA has been sanctionable as a Priority 1 requirement since 1 October 2024, and the remaining tiers run to full v6.0 compliance on 1 October 2027.

By the Numbers
GovRAMP
Formerly StateRAMP
Rebranded February 2025; the legal entity remains StateRAMP. Both names still appear in live solicitations.
19
CJIS Policy Areas
Security domains covered under FBI CJIS Security Policy v6.0.
20+
State Privacy Laws
Comprehensive privacy frameworks enacted by 2026.
300+
Category 3 Controls
GovRAMP controls for high-impact cloud systems.
2 CFR 200
Grant Conditions
Retention, subrecipient monitoring and the §200.303(e) safeguarding duty outlive the grant programme that carried them.
38
Access Controls
CJIS requirements for criminal justice information access.

State and local compliance spans multiple frameworks, jurisdictions, and funding sources.

Questions

Common questions

Is it StateRAMP or GovRAMP?

Both names refer to the same programme. StateRAMP rebranded as GovRAMP in February 2025 to reflect a membership that had grown beyond states to local, tribal and education entities; the organisation's legal name remains StateRAMP, operating as GovRAMP. Existing authorizations, agreements and procurements were not affected by the change. Both names remain in circulation across procurement documents, which is worth knowing when a solicitation cites one and a vendor's evidence cites the other.

What are the CJIS Security Policy v6.0 deadlines?

Version 6.0 was released in December 2024 and phases in by control priority rather than all at once. Multi-factor authentication is a Priority 1 requirement that became subject to sanction from 1 October 2024. The remaining priority tiers run to 30 September 2027, with full compliance with version 6.0 required by 1 October 2027. The phasing matters for planning: the priority tier a control sits in, not the policy's publication date, determines when an agency is actually exposed on it.

Does a GovRAMP authorization satisfy every state?

No. Participation is by state and several states run their own programmes with their own requirements — Texas being the most frequently encountered — so a vendor entering multiple state markets faces a set of overlapping authorizations rather than one. Where reciprocity arrangements exist they can substantially reduce duplicate assessment, but they are specific arrangements between specific programmes and have to be checked rather than assumed.

What happens to our obligations if federal cybersecurity grant funding lapses?

The obligations attached to money already received do not lapse with the authorisation to appropriate more. Awards under 2 CFR Part 200 carry record retention, subrecipient monitoring and audit requirements that run through the period of performance and beyond, and the requirement at §200.303(e) to take reasonable cybersecurity and other measures to safeguard information applies to the award regardless of what happens to the programme. Authorisation for the State and Local Cybersecurity Grant Program has been extended and reauthorisation has been under active consideration in both chambers, so the status is worth confirming against the current position rather than planning around a single date.

How should a small agency approach this without a security team?

By sequencing against exposure rather than attempting coverage. The obligations that carry the sharpest consequences are the ones tied to a specific access — criminal justice information, and any grant condition already accepted — because those come with an audit or a sanction attached to a named system. Broader framework adoption is worth doing and is rarely what an agency is first held to account for. The failure pattern is a general programme started everywhere at once and finished nowhere.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

One assessment. Nineteen policy areas. One platform.

State and local compliance multiplies. The jurisdictions that automate will keep pace with framework updates, audit requirements, and grant deadlines. Those running manual processes will spend their time on documentation instead of security.