Arizona Department of Homeland Security

Arizona Department of Homeland Security

You are here

Arizona Risk and Authorization Management Program (AZRAMP)

The Arizona Risk and Authorization Management Program is a NIST-based assessment developed to analyze a vendor’s threshold for security and data protection. Modeled after the Federal Risk and Authorization Management Program, AZRAMP has successfully vetted over 450 cloud service products as of September 2025. These services must be periodically reviewed to ensure continued compliance with NIST regulation requirements.

**UPDATE**

The State of Arizona’s cloud security program, AZRAMP, is officially transitioning to StateRAMP (dba GovRAMP), reinforcing Arizona’s commitment to standardized cybersecurity requirements and enhanced vendor risk management. The move aligns Arizona’s cloud security policies with the widely adopted GovRAMP framework, ensuring consistency in security assessments and streamlined procurement processes for cloud service providers operating in the state.

With this transition, Arizona will leverage GovRAMP’s established compliance framework, which provides enhanced security oversight and efficiency for state agencies and service providers. This move simplifies compliance efforts for vendors while strengthening Arizona’s cybersecurity posture across public sector entities.

As of July 1, 2025, all new contracts will include risk assessment requirements that align with the GovRAMP program which is based on National Institute of Technology and Standards (NIST) 800-53. Any grace period offered to reach the appropriate assessment level will be defined within the solicitation for the product/service. 

As of July 1, 2026, all renewal contracts will include risk assessment requirements that align with GovRAMP or FedRAMP.

For more information: https://programs.govramp.org/arizona/

The State of Arizona also recognizes FedRAMP Authorizations. Their authorized product list page can be found here: https://marketplace.fedramp.gov/products (FedRAMP).

Below is a list of AZRAMP authorized cloud service products, the solution they provide, when they became AZRAMP authorized, the expiration date of their authorization, the impact level of each, and the entity that reviewed and approved their AZRAMP authorization.

Company Namesort descending Product Authorized Expiration Impact Reviewed by
Numetric
crash analytics for road safety initiatives.
07/28/2024
07/28/2027
Moderate
AZDOHS
OKTA
IDaaS Regulated Cloud + IDaaS Government High Cloud
01/24/2021
07/02/2029
Moderate
AZDOHS
Opengov
Database - CMS
08/03/2025
08/03/2028
Moderate
AZDOHS
OptiMiser
Nexus Project Management Platform
08/30/2022
03/26/2027
Moderate
AZDOHS
Optum/UnitedHealth Group
HSA Program + OptumRx Pharmacy Benefits Management
07/26/2020
11/06/2027
Moderate
AZDOHS
Oracle
Oracle Government Cloud + Oracle Service Cloud
11/08/2020
07/02/2029
Moderate
AZDOHS
Origami
Risk Management Information System
09/19/2023
09/19/2026
Moderate
AZDOHS
Pantheon
Web Hosting
11/04/2015
06/03/2027
Moderate
AZDOHS
Permitium
CCW Permit Application Enhancements + PermitDirector
10/09/2024
10/09/2027
Moderate
AZDOHS
Pipeline AZ
Career Support Services
10/12/2023
10/12/2026
Moderate
AZDOHS