Back to Blog
Compliance9 min read

TX-RAMP Penetration Testing Requirements (2026 Guide)

P

Pentestas Team

Security Analyst

7/29/2026
TX-RAMP Penetration Testing Requirements (2026 Guide)
TX-RAMP penetration testing requirements

💫 TX-RAMP penetration testing requirements — the short version

  • StateRAMP requires internal and external penetration testing, as often as every 6 months (and after significant change).
  • Exploitable findings must be fixed and re-tested, with evidence retained for your assessor.
  • Scope must cover the application and network layers, external and internal.
  • An AI penetration testing system can run these tests continuously — for a fraction of a periodic manual engagement.

Here is the position every organization bound by StateRAMP / TX-RAMP is in. Your state-government contract is blocked until you produce a 3PAO penetration test of your full authorization boundary — miss the TX-RAMP/StateRAMP deadline and the deal (and your renewal) walks. And it is not one-and-done: you must repeat it every 12 months and after any significant change to stay authorized.

Most teams answer this the expensive way: they buy a single, five-figure, point-in-time manual penetration test, sweat through weeks of scheduling, then hope nothing changes until the next cycle. It always changes. This guide breaks down exactly what the TX-RAMP penetration testing requirements demand, what an assessor needs to see, and how to stay continuously in-scope — without a five-figure invoice every time your environment moves.

📋

The requirement

What StateRAMP requires for penetration testing

Both programs mandate an independent 3PAO penetration test for Moderate / Level 2 authorizations (systems handling confidential/regulated state data), aligned to NIST SP 800-53 CA-8 and the methodology in NIST SP 800-115. StateRAMP/GovRAMP: per the StateRAMP Penetration Test Guidance (v1.0), the initial pentest must be performed no more than 6 months prior to SAR submission, and thereafter penetration testing must be repeated at least every 12 months during continuous monitoring (unless an authorizing body approves otherwise with documented rationale). TX-RAMP Level 2 requires annual (or more frequent) penetration testing covering the full authorization boundary — web apps, APIs, cloud infra config, network segmentation, and authentication. So: mandatory, periodic/annual, plus after significant change.

What StateRAMP asks for

StateRAMP testing clausepenetration testing requiredInternal + externalapplication + network layerCadenceas often as every 6 months (and af
StateRAMP / TX-RAMP requires penetration testing as an auditable control.
🎯

The scope

Who it binds and what must be tested

Who must comply: Cloud service providers (CSPs) / SaaS vendors selling to US state and local government. StateRAMP/GovRAMP is required by a growing coalition of participating states and localities; TX-RAMP is mandated for any cloud service that processes, stores, or transmits data of Texas state agencies (enforced by Texas DIR, required for state contracts). Level 2 / Moderate applies to services handling confidential state data; Level 1 covers low-impact/non-confidential.

A compliant test has to hit the environment from two directions — the external internet-facing surface and the internal surface reachable from inside your network — and at both the network and application layers. The most common reason a first attempt fails review is incomplete scope: the public site was tested, but the internal APIs, admin panels, and the controls that isolate sensitive systems were not.

Typical pentest scope

In-scope environmentApplication layerNetwork layerExternal surfaceinternet-facingInternal surfacebehind the firewall
External + internal, application + network layer — the coverage an assessor expects.
💰

The offer

Why periodic-only pentesting is the expensive option

A traditional manual penetration test runs roughly $10,000–$30,000 and lands as a PDF that is accurate for about a day. Then your environment changes and you are out of coverage until the next cycle. That is a lot of money for a snapshot, and it leaves you blind between assessments.

Pentestas is pentesting as a service: an AI penetration testing system that runs StateRAMP-aligned internal and external tests on your environment continuously — automatically, after every deploy — starting at $79/month. It is penetration testing with AI at the core, orchestrated by frontier models (we run penetration testing with Claude for deep reasoning and cost-controlled penetration testing with DeepSeek for high-volume passes), delivered as a B2B SaaS pentest platform that maps every finding straight to the requirement it satisfies.

Cost of staying compliant

Manual pentest (periodic)$10k–$30k+once per cycle · stale in a dayAI platform (continuous)from $79/more-runs after every change
Point-in-time manual testing vs. continuous AI-driven coverage.

The mapping

How Pentestas satisfies StateRAMP

The platform exercises the external surface from the internet and the internal surface through a lightweight agent inside your network, so one engagement covers both directions. It tests the application and network layers, re-tests every exploitable finding after you fix it (capturing before-and-after evidence), and — because it re-runs after every change — handles the “after significant change” obligation automatically instead of turning it into a fire drill. Every finding ships with real exploit evidence, a severity rating, and remediation steps.

Point-in-time vs. continuous

A periodic test is accurate for about a day.Continuous coverage closes the blind spot between audits
Continuous testing keeps you in-scope between assessments.

How Pentestas maps to the requirement

External testinternet-facingInternal testvia lightweight agentRe-test fixesbefore/after evidenceContinuousafter every deployAudit-ready reportmaps to the clause
One continuous engagement covers internal + external, re-tests fixes, and produces assessor-ready evidence.

FAQ

StateRAMP penetration testing, quick answers

How often does StateRAMP require penetration testing?

As Often As Every 6 Months (and After Significant Change). The exact cadence and scope are set out in the requirement text above.

Is a vulnerability scan the same as a penetration test?

No. A scan enumerates known weaknesses; a penetration test actively exploits them across the application and network layers to prove real impact. Most frameworks expect both.

Who can perform the test?

A qualified internal or external tester who is organizationally independent of the systems under test. Your assessor/auditor must be satisfied the methodology and scope meet the requirement.

How much does it cost?

A manual engagement typically runs $10,000–$30,000+. A continuous, AI-driven platform that keeps you in-scope after every change starts at $79/month — which is why most teams now run both.

A straight answer on manual vs. AI

A manual penetration test by senior human testers is still the highest-value assessment you can buy — a skilled human chains business-logic flaws and reasons about your specific threat model in ways no tool fully matches. It also typically costs 20–30× more than an AI-driven platform. Both have a place. Use continuous, AI-driven pentesting to stay in scope after every change and catch the large majority of issues that are findable programmatically; commission a manual pentest for the deep, creative, high-assurance milestone. The strongest StateRAMP programs run both: AI for coverage and cadence, humans for depth — and the AI platform keeps you compliant every single day in between.

Bottom line: StateRAMP is not satisfied by one lucky PDF per cycle. It rewards continuous coverage of the whole environment, internal and external, re-tested after every change — exactly the shape of problem an AI penetration testing system is built to solve, at a fraction of the cost of being compliant for one day out of the year.

Get StateRAMP-aligned coverage that keeps up with your deploys

Continuous internal + external penetration testing mapped to your framework, from $79/month.

See plans & pricing
Alexander Sverdlov

Alexander Sverdlov

Founder of Pentestas. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.