TX-RAMP compliance & readiness

TX-RAMP Penetration Testing for Texas Cloud Providers

Prepare your SaaS, PaaS, or IaaS cloud service for TX-RAMP Level 1 or Level 2 with penetration testing, cloud security assessment, remediation validation, and technical evidence.

Blaze findings dashboard

Technical readiness for TX-RAMP Level 1 or Level 2

Validate the cloud service boundary before assessment, close exploitable gaps, and keep vulnerability evidence usable for remediation and continuous monitoring.

Assessment readiness

Validate the controls behind your TX-RAMP submission

Test the applications, APIs, cloud configuration, identities, and exposed infrastructure that support the in-scope cloud service.

Umbrella Web Application dashboard showing workflow status and severity with 8 findings in a donut chart.
Cloud service boundary

Test the service, not just the underlying cloud

Assess the SaaS, PaaS, or IaaS service as its own security boundary, including the controls your product cannot simply inherit from an underlying provider.

Document titled Umbrella Web Application with version control table listing authors, dates, pages, versions, and status.
Continuous monitoring

Keep vulnerability evidence current after certification

Support recurring vulnerability reporting with validated findings, remediation status, and fix validation tied to the certified cloud service.

What Blaze can assess

Focused testing of the technical controls and attack paths inside your TX-RAMP cloud-service boundary.

Area

What we test

Application and API security

Authentication, authorization, business logic, tenant isolation, input handling, data exposure, and abuse paths.

Cloud configuration

IAM, network boundaries, storage, encryption, secrets, logging, monitoring, backups, and exposed services.

Identity and privileged access

Administrative roles, service accounts, trust relationships, MFA, session controls, and escalation paths.

External attack surface

Public applications, APIs, domains, cloud services, administrative interfaces, and exposed infrastructure.

Remediation validation

Re-test agreed fixes and document the updated state when validation is included in the selected package or program.

Significant changes

Targeted security testing after material architecture, data-processing, cryptographic, platform, or control changes that may affect the certified cloud service.

Evidence your team can use through the TX-RAMP process

Testing outputs for assessment, remediation, Fast Track gap closure, and ongoing vulnerability reporting. TX-RAMP—not Blaze—determines certification.

Check Circle

Penetration testing

Manual testing across the agreed cloud-service scope, with exploitable findings validated before reporting.

Chart Donut

Cloud security assessment

Review cloud configuration, identity, network boundaries, logging, storage, encryption, and attack paths inside the service environment.

Users

Evidence-ready reporting

Document scope, methodology, evidence, risk, reproduction steps, remediation, and limitations in a format your team can reuse.

Lock Simple

Live remediation tracking

Manage validated findings, owners, status, and evidence in the Blaze Portal instead of relying on static PDFs and spreadsheets.

Stack

Fast Track evidence support

Identify relevant, current third-party artifacts for the cloud service and organize evidence around gaps TX-RAMP may still need reviewed. Fast Track eligibility remains at TX-RAMP's discretion.

Lightning

Fix validation

Re-verify agreed fixes and provide updated evidence when validation is included in the selected package or annual program.

TX-RAMP compliance questions

TX-RAMP is the Texas Risk and Authorization Management Program administered by the Texas Department of Information Resources (DIR). It provides a standardized approach to security assessment, certification, and continuous monitoring for cloud computing services used by Texas state agencies, institutions of higher education, and public community colleges.
TX-RAMP requirements apply to in-scope cloud computing services used by Texas state agencies, institutions of higher education, and public community colleges. Cloud service providers seeking certification must demonstrate compliance with the applicable security criteria, while the contracting agency determines the required TX-RAMP level.
TX-RAMP has two assessment and certification levels. TX-RAMP Level 1 is for cloud services the agency categorizes as low impact. TX-RAMP Level 2 is for moderate- or high-impact information resources. The contracting state agency determines the minimum certification level required for the service.
TX-RAMP assessment materials ask cloud service providers to describe the frequency, breadth, and depth of vulnerability scanning and penetration testing related to the cloud service. The exact testing expected depends on the applicable Level 1 or Level 2 controls and service scope. Blaze can provide independent application, API, cloud, and infrastructure testing as technical evidence for readiness and remediation.
The TX-RAMP Fast Track assessment process lets eligible cloud service providers submit approved third-party assessments or audit reports—such as SOC 2 Type 2, ISO 27001, certain PCI DSS, HITRUST, CSA STAR II, or FISMA artifacts—for consideration. Under the current Program Manual, the artifact generally must be relevant to the cloud service and completed within the previous 24 months. TX-RAMP decides whether the service qualifies, and Fast Track does not guarantee certification.
For directly TX-RAMP-certified services, Level 1 requires annual vulnerability reporting and Level 2 requires quarterly vulnerability reporting through SPECTRIM. Reporting covers identified vulnerabilities and mitigation or remediation activity for assets delivering the certified cloud service. Contracting agencies may impose additional requirements.
No. TX-RAMP certification is conferred by TX-RAMP, not Blaze. Blaze supports the technical side of the TX-RAMP certification process with penetration testing, cloud security assessment, remediation guidance, fix validation, and evidence for readiness and continuous monitoring.
Related services

Recommended services

Technical services for cloud providers preparing for TX-RAMP assessment, remediation, and ongoing vulnerability reporting.

Penetration Testing

Manual testing across web applications, APIs, mobile, cloud, and networks, with validated findings and clear remediation guidance.

Cloud Security Assessment

Review cloud configuration, identity, network boundaries, logging, storage, encryption, and attack paths inside the service environment.

Penetration Testing as a Service

Use annual testing credits, centralized findings, remediation tracking, and planned validation to maintain security evidence across the year.

Ready to validate your TX-RAMP scope?

Share your cloud-service boundary, target level, assessment timeline, and known gaps. We’ll scope the testing and validation work that makes sense.