Compliance/TX-RAMP
Government
Testing named in the standard

TX-RAMP penetration testing

TX-RAMP (Texas Risk and Authorization Management Program)

Penetration testing and vulnerability evidence for the CA-8 and RA-5 controls in your TX-RAMP assessment package.

Sample report

Engagement at a glance

Drives testing

NIST SP 800-53 CA-8 and RA-5: Penetration testing and vulnerability monitoring

Cadence

At least annually, plus ongoing scanning under continuous monitoring

Typical duration

2 to 4 weeks of testing, plus retest

Region

Texas, United States

Issued by

Certified by the Texas Department of Information Resources (DIR)

CA-8

Control directly evidenced

117 / 223

Level 1 and Level 2 controls

3 yr

Certification validity

Annual

Testing cadence

The requirement

What TX-RAMP asks for

NIST SP 800-53 CA-8 and RA-5 · Penetration testing and vulnerability monitoring

TX-RAMP control baselines are drawn from NIST SP 800-53. CA-8 requires penetration testing of the system at a defined frequency. RA-5 requires vulnerabilities to be monitored, scanned and remediated. Level 1 requires 117 controls and Level 2 requires 223.

TX-RAMP certification is required for cloud products that handle data for Texas state agencies and public universities. Its control baselines come from NIST SP 800-53: 117 controls at Level 1 and 223 at Level 2, with certifications valid for three years under continuous monitoring.

Two of those controls need an independent offensive security team. CA-8 covers penetration testing of the system. RA-5 covers vulnerability monitoring, scanning and remediation. Assessors want evidence for both, and for RA-5 they want to see that findings were actually remediated within your defined timeframes, not just logged.

XHack delivers that evidence. We test your cloud environment, report against the relevant control families, support remediation, retest to closure and sign an attestation letter. Your System Security Plan, POA&M and the assessment submission to DIR are your programme, often run with a compliance partner.

What your auditor checks

The report has to clear every one of these

These are the questions a TX-RAMP auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.

Independent testing of the cloud service in scope

Scope matching the authorization boundary in your SSP

Recognised methodology documented in the report

Findings rated consistently with CVSS v4.0

Evidence mapped to CA-8 and RA-5

Remediation within your defined RA-5 timeframes

Independent retest confirming closure

Open items suitable for tracking on the POA&M

Evidence fit for the continuous monitoring cadence

Signed attestation letter from the testing firm

What we test

Where the testing effort concentrates

The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.

Cloud service authorization boundary

The system as defined in your SSP

95%

Access control and identity

IAM, MFA, privilege boundaries

90%

External perimeter and boundary protection

Internet-facing services, SC family

85%

Configuration and patch posture

RA-5 and CM family evidence

80%

Data protection in transit and at rest

Encryption verified under attack

70%

Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.

How the engagement runs

Scope, test, close, attest

Typically 2 to 4 weeks of testing, plus retest. The retest is included, because a report full of open findings is not evidence of anything.

01

Scope to the authorization boundary

Week 1

We work from your System Security Plan so the test covers the boundary the assessor will review, and we confirm which level applies.

02

Test the cloud service

Weeks 1 to 3

External and internal testing of the service, its perimeter and its cloud configuration, under a signed rules of engagement and within the provider's testing policy.

03

Report mapped to control families

Week 3

Findings mapped to CA-8, RA-5 and the access, configuration and boundary families, so the evidence lands where the assessor is looking.

04

Remediation inside RA-5 timeframes

Weeks 3 to 6

RA-5 expects remediation within defined windows by severity. We support your team to close inside them, and anything that cannot close becomes a clean POA&M item.

05

Retest and attestation

Week 6 onward

Each finding retested and closed, with an attestation letter for your assessment package and the continuous monitoring record.

Where the effort goes

Share of a typical engagement, by phase

100%EFFORT

Scoping & rules of engagement

15%

Testing & exploitation

45%

Reporting & mapping

20%

Retest & attestation

20%

What we bring

Built for the TX-RAMP auditor specifically

The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.

NIST SP 800-53 fluency

The same catalogue behind FedRAMP and StateRAMP. Findings are mapped to control families, not left as generic vulnerabilities.

RA-5 timeframes respected

We plan remediation and retest around the windows RA-5 defines, so the evidence shows closure and not just effort.

POA&M ready

Anything that cannot close in the window is written so it drops straight onto your Plan of Action and Milestones.

Cloud aware testing

Testing designed around the cloud provider's policy and your tenancy, including IAM and storage exposure.

The deliverable

What lands on your auditor's desk

A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.

In the report

  • Signed letter of attestation with testing dates

  • Scope tied to the authorization boundary in the SSP

  • Methodology, qualifications and independence statement

  • Findings with CVSS v4.0, evidence and reproduction steps

  • Mapping to CA-8, RA-5 and related control families

  • Remediation implemented and independent retest result

  • Residual items formatted for the POA&M

Control mapping

How the report evidences each control

CA-8

The independent penetration test the control requires, at the defined frequency.

RA-5

Vulnerabilities identified, rated and remediated within defined timeframes.

AC family

Access control and privilege findings tested and closed.

SC family

Boundary protection and transmission confidentiality verified under attack.

CM family

Configuration weaknesses surfaced against your baselines.

Where our work stops, and who takes it from there

XHack provides the penetration testing evidence for NIST SP 800-53 CA-8 and RA-5. We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For TX-RAMP, that sits with: Certified by the Texas Department of Information Resources (DIR). Staying independent of them is exactly what makes our evidence worth something when they review it.

Questions

TX-RAMP testing, answered

No. We provide the CA-8 and RA-5 testing evidence. The System Security Plan, the POA&M and the submission to DIR are your programme, usually run in-house or with a compliance partner. We make sure the testing evidence in that package holds up.

It depends on the data your product handles for the agency. Level 1 covers public or low impact data and 117 controls. Level 2 covers confidential or higher impact data and 223 controls. The contracting agency confirms it, and the testing scope follows from there.

TX-RAMP recognises FedRAMP and StateRAMP through reciprocity, so your existing package may cover most of it. Where your FedRAMP penetration testing is current and in scope, it usually carries across. We assess that before proposing new work.

We test within the provider's published penetration testing policy and confirm any required notification before the window opens. That is part of the scoping and authorization step, not an afterthought.

Get the TX-RAMP evidence sorted

Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.

All frameworks