CrafterCMS Achieves TX-RAMP Certification: What It Means for Government Digital Experiences
Sara Williams
Security and compliance are increasingly important considerations for government agencies modernizing their digital infrastructure. Moving websites, portals, applications, and content platforms to the cloud can provide significant advantages in agility, scalability, and cost efficiency, but government organizations also need confidence that their cloud providers follow appropriate security practices.
That's the idea behind the Texas Risk and Authorization Management Program (TX-RAMP).
We're pleased to announce that CrafterCMS has achieved TX-RAMP certification, demonstrating that our cloud platform meets the security requirements established by the State of Texas for cloud computing services used by state government organizations.
For CrafterCMS, this represents another important milestone in our continued investment in enterprise security and makes it easier for Texas government organizations to adopt a modern, AI-native content platform for their digital experiences.
What Is TX-RAMP?
TX-RAMP is administered by the Texas Department of Information Resources (DIR) and provides a standardized framework for assessing, certifying, and continuously monitoring the security of cloud computing services that process data for Texas state agencies.
The program was established to solve a challenge familiar to almost every government IT organization. Government agencies increasingly want to take advantage of SaaS and cloud computing, but each new cloud service introduces potential security risks. Evaluating every provider independently can be expensive, inconsistent, and time consuming.
TX-RAMP creates a common security assessment framework. Cloud service providers demonstrate that they meet defined security requirements, and Texas agencies can use that certification as part of their evaluation and procurement process.
TX-RAMP requirements apply to Texas state agencies, institutions of higher education, and public community colleges when using covered cloud computing services.
What Does TX-RAMP Evaluate?
TX-RAMP certification goes considerably deeper than filling out a security questionnaire.
The certification process requires cloud service providers to document their environment, security architecture, operational practices, and implementation of applicable security controls. DIR then reviews that information against the requirements of the TX-RAMP security baseline.
The framework incorporates security practices derived from established standards, including NIST SP 800-53, along with requirements specific to the State of Texas.
The controls cover many of the core areas government security teams care about when evaluating a cloud platform.
Access Control and Identity Management
A secure cloud platform needs to tightly control who can access systems and information.
TX-RAMP evaluates controls around areas such as user access, authentication, account management, privileged access, and the principle of least privilege.
For an enterprise CMS, these considerations are particularly important. Content platforms frequently support many different types of users — administrators, developers, content authors, marketers, communications teams, contractors, and others — with different levels of access to content and platform capabilities.
System and Communications Protection
Government systems need safeguards protecting information as it moves between users, applications, infrastructure, and external services.
TX-RAMP therefore evaluates technical controls designed to protect systems and communications, including how cloud providers secure data transmission, network boundaries, system connections, and sensitive information.
For modern digital experience platforms, where content may be delivered through websites, applications, APIs, search services, and other channels, these protections form an important part of the overall security architecture.
Configuration and Change Management
Security isn't simply about preventing unauthorized users from accessing a system. Organizations also need control over how production systems change.
TX-RAMP addresses configuration management practices intended to ensure that systems are deployed and operated in a controlled manner.
This is an area that aligns particularly well with CrafterCMS's architecture.
CrafterCMS uses Git as its underlying content repository, providing a complete version history for content and configuration changes. That architecture supports traceability, auditing, controlled deployment processes, and the ability to understand how digital experiences change over time.
Vulnerability and Risk Management
Cloud security is not a one-time event. New vulnerabilities are discovered constantly, infrastructure evolves, applications change, and new threats emerge. Cloud providers therefore need processes for identifying vulnerabilities, assessing their severity, and remediating or mitigating them.
TX-RAMP incorporates vulnerability management and ongoing reporting requirements so that certification represents an operational security commitment rather than simply a point-in-time assessment.
Incident Response
Even organizations with strong preventative controls need to prepare for the possibility of a security incident.
TX-RAMP evaluates incident-response capabilities and establishes requirements around how security incidents affecting government information are handled and reported.
This means providers need documented processes for identifying, investigating, responding to, and communicating security incidents rather than developing those procedures after an event occurs.
Logging, Monitoring, and Auditability
Understanding what is happening inside a cloud environment is fundamental to security.
Security logging and monitoring help organizations detect suspicious activity, investigate incidents, and establish an audit trail of important system events.
TX-RAMP therefore includes requirements addressing areas such as audit records, monitoring, event analysis, and the protection of security information.
Business Continuity and Availability
Government digital services increasingly operate as essential infrastructure.
Citizens expect government websites and services to be available when they need them, and agencies need confidence that their technology providers can recover from infrastructure failures or other disruptions.
TX-RAMP consequently addresses contingency planning, system recovery, operational resilience, and related controls intended to help cloud services remain dependable.
TX-RAMP Is an Ongoing Security Program
One of the most important aspects of TX-RAMP is that certification isn't simply a certificate a vendor earns and forgets about.
TX-RAMP includes continuous monitoring requirements designed to ensure that certified cloud services continue meeting the program's security expectations.
Providers must maintain required controls, address vulnerabilities, report required security information, and notify DIR of significant changes that could affect the security posture of the service.
Full Level 1 and Level 2 certifications are generally valid for three years, provided the cloud service remains compliant with ongoing program requirements. That distinction matters.
Security certifications are most useful when they represent an ongoing operational discipline rather than a snapshot of a system at a particular moment.
TX-RAMP Level 1 and Level 2
TX-RAMP uses different certification levels depending upon the sensitivity and impact of the information processed by a cloud service.
- Level 1 is intended for cloud services processing, storing, or transmitting non-confidential agency information or operating as low-impact information resources.
- Level 2 applies to cloud services processing confidential or regulated information and systems classified as moderate or high impact.
Ultimately, the contracting Texas agency determines the appropriate certification level based on its intended use of the cloud service and the sensitivity of the information involved.
This risk-based approach allows agencies to apply security requirements appropriate to the actual workload rather than treating every cloud application identically.
Why TX-RAMP Matters for a CMS
At first glance, a content management system might appear less security-sensitive than transactional government systems.
Modern CMS platforms, however, have become critical infrastructure. They can power public websites, employee intranets, constituent portals, documentation systems, mobile applications, digital signage, emergency communications, and other digital services. They also connect to a growing ecosystem of identity providers, analytics platforms, search engines, APIs, databases, enterprise applications, and increasingly, AI services.
As CMS platforms become more composable and interconnected, their security architecture matters more, not less. Government agencies evaluating a CMS therefore need to consider not only authoring capabilities and developer productivity but also the security and operational practices of the platform itself.
TX-RAMP provides Texas agencies with an independent framework for making that assessment.
Modernizing Government Digital Experiences with CrafterCMS
CrafterCMS provides government organizations with a modern alternative to legacy content management architectures.
As an open source, AI-native headless CMS for the enterprise, CrafterCMS combines powerful content authoring with headless APIs, Git-based content management, DevContentOps capabilities, enterprise integrations, and modern AI technologies.
Government organizations can use CrafterCMS to manage content centrally while delivering experiences across public websites, portals, intranets, mobile applications, kiosks, digital signage, conversational AI experiences, and other digital channels.
Its Git-based architecture provides complete content version history and supports modern development and deployment workflows, while its API-first architecture allows agencies to integrate the CMS with their broader technology environment without locking digital experiences into a proprietary presentation layer.
CrafterCMS can also be deployed as a fully managed private SaaS offering, giving organizations the advantages of cloud operations while supporting the security, availability, governance, and operational requirements expected by enterprise and public-sector customers.
Security as a Foundation for AI-Enabled Government
TX-RAMP certification is also particularly important as government organizations begin exploring AI-powered digital experiences.
AI introduces enormous opportunities to improve how citizens and employees discover information, interact with government services, and complete tasks. But AI capabilities don't eliminate traditional enterprise security requirements.
They make them more important. The systems of record, content repositories, APIs, identity systems, and infrastructure supporting AI-powered experiences still need strong security controls and governance.
Our view is that the next generation of government digital experiences will combine deterministic, governed enterprise content with probabilistic AI intelligence.
That requires a strong security foundation underneath both.
Another Step in CrafterCMS's Enterprise Security Journey
Achieving TX-RAMP certification is another milestone in CrafterCMS's ongoing investment in enterprise security, governance, and cloud operations. More importantly, it reduces another barrier for Texas government organizations looking to modernize their digital experience platforms.
Government agencies shouldn't have to choose between modern architecture and enterprise security. With CrafterCMS, they can have both.
Get Started Today
Try our secure, headless CMS platform today by registering for a free Crafter Cloud trial now.
Related Posts
Turn Your Website AI Chatbot Into an AI Agent
Amanda Lee
Headless CMS Use Case: Modern Brand Sites
Amanda Jones
Why Git-Based CMS Platforms Have an AI Advantage
Sara Williams
Public Sector Website Relaunch in Just One Month with CrafterCMS
Amanda Jones