TX-RAMP penetration testing
TX-RAMP (Texas Risk and Authorization Management Program)
Penetration testing and vulnerability evidence for the CA-8 and RA-5 controls in your TX-RAMP assessment package.
Engagement at a glance
Drives testing
NIST SP 800-53 CA-8 and RA-5: Penetration testing and vulnerability monitoring
Cadence
At least annually, plus ongoing scanning under continuous monitoring
Typical duration
2 to 4 weeks of testing, plus retest
Region
Texas, United States
Issued by
Certified by the Texas Department of Information Resources (DIR)
CA-8
Control directly evidenced
117 / 223
Level 1 and Level 2 controls
3 yr
Certification validity
Annual
Testing cadence
The requirement
What TX-RAMP asks for
NIST SP 800-53 CA-8 and RA-5 · Penetration testing and vulnerability monitoring
TX-RAMP control baselines are drawn from NIST SP 800-53. CA-8 requires penetration testing of the system at a defined frequency. RA-5 requires vulnerabilities to be monitored, scanned and remediated. Level 1 requires 117 controls and Level 2 requires 223.
TX-RAMP certification is required for cloud products that handle data for Texas state agencies and public universities. Its control baselines come from NIST SP 800-53: 117 controls at Level 1 and 223 at Level 2, with certifications valid for three years under continuous monitoring.
Two of those controls need an independent offensive security team. CA-8 covers penetration testing of the system. RA-5 covers vulnerability monitoring, scanning and remediation. Assessors want evidence for both, and for RA-5 they want to see that findings were actually remediated within your defined timeframes, not just logged.
XHack delivers that evidence. We test your cloud environment, report against the relevant control families, support remediation, retest to closure and sign an attestation letter. Your System Security Plan, POA&M and the assessment submission to DIR are your programme, often run with a compliance partner.
What your auditor checks
The report has to clear every one of these
These are the questions a TX-RAMP auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.
Independent testing of the cloud service in scope
Scope matching the authorization boundary in your SSP
Recognised methodology documented in the report
Findings rated consistently with CVSS v4.0
Evidence mapped to CA-8 and RA-5
Remediation within your defined RA-5 timeframes
Independent retest confirming closure
Open items suitable for tracking on the POA&M
Evidence fit for the continuous monitoring cadence
Signed attestation letter from the testing firm
What we test
Where the testing effort concentrates
The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.
Cloud service authorization boundary
The system as defined in your SSP
95%
Access control and identity
IAM, MFA, privilege boundaries
90%
External perimeter and boundary protection
Internet-facing services, SC family
85%
Configuration and patch posture
RA-5 and CM family evidence
80%
Data protection in transit and at rest
Encryption verified under attack
70%
Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.
How the engagement runs
Scope, test, close, attest
Typically 2 to 4 weeks of testing, plus retest. The retest is included, because a report full of open findings is not evidence of anything.
Scope to the authorization boundary
We work from your System Security Plan so the test covers the boundary the assessor will review, and we confirm which level applies.
Test the cloud service
External and internal testing of the service, its perimeter and its cloud configuration, under a signed rules of engagement and within the provider's testing policy.
Report mapped to control families
Findings mapped to CA-8, RA-5 and the access, configuration and boundary families, so the evidence lands where the assessor is looking.
Remediation inside RA-5 timeframes
RA-5 expects remediation within defined windows by severity. We support your team to close inside them, and anything that cannot close becomes a clean POA&M item.
Retest and attestation
Each finding retested and closed, with an attestation letter for your assessment package and the continuous monitoring record.
Where the effort goes
Share of a typical engagement, by phase
Scoping & rules of engagement
15%
Testing & exploitation
45%
Reporting & mapping
20%
Retest & attestation
20%
What we bring
Built for the TX-RAMP auditor specifically
The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.
NIST SP 800-53 fluency
The same catalogue behind FedRAMP and StateRAMP. Findings are mapped to control families, not left as generic vulnerabilities.
RA-5 timeframes respected
We plan remediation and retest around the windows RA-5 defines, so the evidence shows closure and not just effort.
POA&M ready
Anything that cannot close in the window is written so it drops straight onto your Plan of Action and Milestones.
Cloud aware testing
Testing designed around the cloud provider's policy and your tenancy, including IAM and storage exposure.
The deliverable
What lands on your auditor's desk
A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.
In the report
Signed letter of attestation with testing dates
Scope tied to the authorization boundary in the SSP
Methodology, qualifications and independence statement
Findings with CVSS v4.0, evidence and reproduction steps
Mapping to CA-8, RA-5 and related control families
Remediation implemented and independent retest result
Residual items formatted for the POA&M
Control mapping
How the report evidences each control
CA-8
The independent penetration test the control requires, at the defined frequency.
RA-5
Vulnerabilities identified, rated and remediated within defined timeframes.
AC family
Access control and privilege findings tested and closed.
SC family
Boundary protection and transmission confidentiality verified under attack.
CM family
Configuration weaknesses surfaced against your baselines.
Where our work stops, and who takes it from there
XHack provides the penetration testing evidence for NIST SP 800-53 CA-8 and RA-5. We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For TX-RAMP, that sits with: Certified by the Texas Department of Information Resources (DIR). Staying independent of them is exactly what makes our evidence worth something when they review it.
Questions
TX-RAMP testing, answered
No. We provide the CA-8 and RA-5 testing evidence. The System Security Plan, the POA&M and the submission to DIR are your programme, usually run in-house or with a compliance partner. We make sure the testing evidence in that package holds up.
It depends on the data your product handles for the agency. Level 1 covers public or low impact data and 117 controls. Level 2 covers confidential or higher impact data and 223 controls. The contracting agency confirms it, and the testing scope follows from there.
TX-RAMP recognises FedRAMP and StateRAMP through reciprocity, so your existing package may cover most of it. Where your FedRAMP penetration testing is current and in scope, it usually carries across. We assess that before proposing new work.
We test within the provider's published penetration testing policy and confirm any required notification before the window opens. That is part of the scoping and authorization step, not an afterthought.
Other frameworks we test for
Get the TX-RAMP evidence sorted
Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.