Menu

California Public Sector Cal-Secure, FedRAMP and SOC 2 Controls

California Public Sector Cal-Secure, FedRAMP and SOC 2 Controls

California state agencies are increasing their focus on cybersecurity maturity, cloud security, identity protection, continuous monitoring, software security, and resilience. For technology companies pursuing California public sector opportunities, understanding these priorities can make existing security evidence more useful during procurement.

A key point needs to be established first: Cal-Secure is not a vendor certification program. It is California's cybersecurity roadmap for its Executive Branch. The current Cal-Secure 2.0 roadmap, released in 2026, sets statewide cybersecurity priorities around people, process, and technology. Vendors can still be affected because agencies may translate those priorities into procurement requirements, security questionnaires, contractual provisions, cloud security expectations, and evidence requests.

For vendors that already maintain FedRAMP or SOC 2 controls, this creates an opportunity to reuse relevant policies, control evidence, assessment results, monitoring records, and security artifacts where the California agency's requirements permit it. However, FedRAMP or SOC 2 should not automatically be treated as a substitute for California-specific requirements.

Explore SOC 2 Assessment Services. Evaluate your controls against SOC 2 requirements and demonstrate your commitment to security and trust.

What Is Cal-Secure and Why Does It Matter to California Public Sector Vendors?

Cal-Secure's Role in California's Statewide Cybersecurity Strategy

Cal-Secure is California's multi-year cybersecurity roadmap for strengthening information security across the state's Executive Branch. The original roadmap was released in 2021 and established priorities covering people, process, and technology. The state released Cal-Secure 2.0 in July 2026 as the updated cybersecurity roadmap for 2026 and beyond.

Cal-Secure 2.0 focuses on strengthening the cybersecurity workforce, improving statewide coordination and governance, modernizing technology, and addressing changing cyber risks. California's 2026 technology roadmap also connects Cal-Secure activities with cybersecurity maturity, NIST CSF 2.0 alignment, zero trust objectives, security monitoring, and state-critical system security.

For technology providers, the relevance is primarily indirect. Cal-Secure establishes the security direction for state entities, while the actual requirements applicable to a vendor can come from procurement documents, contracts, California security policies, cloud security requirements, or an individual agency's security review.

Who Needs to Consider Cal-Secure Requirements?

Cal-Secure primarily addresses California Executive Branch state entities rather than creating a universal certification obligation for private companies. The California Department of Technology describes Cal-Secure 2.0 as a multi-year cybersecurity roadmap for state entities.

Technology vendors should therefore examine the requirements attached to the specific California procurement, agency, service, system, and data involved. A SaaS provider, cloud service provider, managed security provider, software company, or technology contractor may encounter security requirements that reflect California's statewide cybersecurity priorities.

The precise obligations can differ between procurements. A vendor should not assume that every California public sector contract requires the same control set simply because Cal-Secure is referenced.

Cal-Secure Security Priorities for State Entities and Technology Vendors

The original Cal-Secure roadmap identified baseline capabilities involving areas such as asset management, privileged access management, multifactor authentication, continuous vulnerability management, application security, software supply chain management, security operations, network protection, and security awareness.

Cal-Secure 2.0 continues the broader emphasis on people, process, and technology while incorporating newer priorities such as cybersecurity maturity, zero trust, cloud security monitoring, and changing technology risks. California's 2026 roadmap also states that cybersecurity maturity scoring is being aligned with NIST CSF 2.0.

These areas overlap with many controls commonly maintained by organizations pursuing FedRAMP authorization or a SOC 2 examination.

Cal-Secure Security Controls Relevant to Public Sector Technology Providers

Identity and Access Management Controls

Identity and access management is a central area of overlap between California's cybersecurity priorities and federal security controls. Cal-Secure materials identify capabilities such as privileged access management and multifactor authentication, while California's 2026 technology roadmap includes a statewide zero trust objective focused on identity, access, and network protections.

FedRAMP Rev. 5 uses NIST SP 800-53 Rev. 5 controls for areas including access control and identification and authentication. FedRAMP's current control reference includes controls covering account management, privileged access, authentication, and multifactor authentication.

A vendor with an established FedRAMP control environment can therefore have relevant evidence for identity-related questions in a California procurement. The exact evidence required still depends on the agency and contract.

Vulnerability Management and Continuous Monitoring

Vulnerability management and continuous monitoring are important components of California's cybersecurity roadmap. The original Cal-Secure roadmap identified continuous vulnerability management as a technical capability, while California's current security operations program identifies continuous security monitoring and cloud security monitoring as important statewide capabilities.

FedRAMP Rev. 5 also contains controls addressing flaw remediation, system monitoring, vulnerability detection, configuration management, and related security activities. For example, FedRAMP's SI-02 addresses identifying, reporting, and correcting system flaws, while SI-04 addresses system monitoring.

SOC 2 can also provide evidence concerning security monitoring, vulnerability management, access controls, change management, and related control activities when those areas fall within the examination scope.

Incident Response and Security Operations

California's cybersecurity strategy places significant emphasis on security operations, threat detection, incident response, and coordination. The state's security operations program describes continuous monitoring, threat information sharing, and response capabilities across state entities.

FedRAMP includes a dedicated Incident Response control family under NIST SP 800-53 Rev. 5. The framework also includes assessment and monitoring requirements that evaluate whether controls operate as intended.

For SOC 2, security is the required Trust Services Criteria category, while availability, processing integrity, confidentiality, and privacy can also be included depending on the engagement scope. procurement may therefore request incident response policies, incident records, monitoring evidence, escalation procedures, or independent assurance reports. The applicable contract determines what evidence is required.

Cloud Security and Data Protection

Cloud security is particularly important for technology providers selling SaaS, infrastructure, or platform services to California state entities. California's Cloud Services Assessment process references Cal-Secure goals and technical capabilities alongside the state's Cloud Security Standard, Cloud Security Guide, zero trust architecture, security risk assessment requirements, and data classification requirements.

FedRAMP is directly relevant to cloud service providers because its security controls are designed around cloud service offerings and use NIST SP 800-53 as the detailed control foundation.

SOC 2 can provide evidence about how a service organization manages security and, when applicable, availability, confidentiality, processing integrity, or privacy. However, the SOC 2 scope and system description must be examined to determine whether the report addresses the specific California service and environment.

Application and Software Supply Chain Security

Application security and software supply chain security have been part of California's cybersecurity priorities. The original Cal-Secure roadmap specifically identified application development security, application security, and software supply chain management as relevant capabilities.

FedRAMP Rev. 5 includes System and Services Acquisition and Supply Chain Risk Management control families. The current FedRAMP control reference lists SA and SR families among the NIST SP 800-53 Rev. 5 control families used in the program.

For a software vendor, relevant evidence can include secure development practices, vulnerability management records, software component inventories, supplier risk processes, change controls, code security testing, and related independent assessment evidence. The appropriate evidence depends on the procurement's stated requirements.

Cal-Secure and FedRAMP: Where Security Controls Overlap

Cal-Secure and FedRAMP Security Control Alignment

The relationship between Cal-Secure and FedRAMP is best understood as control and evidence overlap rather than formal equivalence.

Cal-Secure is a California state cybersecurity roadmap. FedRAMP is a federal authorization program for cloud services that uses NIST security controls and a defined assessment and authorization structure. FedRAMP Rev. 5 uses NIST SP 800-53 Rev. 5 controls and establishes specific baselines, parameters, assessment procedures, and ongoing monitoring expectations.

This common security language makes crosswalking possible. A California agency can examine evidence generated for a FedRAMP environment and determine whether that evidence addresses the agency's particular requirement.

Mapping Cal-Secure Controls to FedRAMP Rev. 5 Controls

A practical mapping exercise should start with the California requirement and then identify the corresponding security objective, FedRAMP control, evidence source, scope, and any remaining requirement.

For example, identity management requirements may correspond to FedRAMP AC and IA controls. Vulnerability management may correspond to SI and RA controls. Security monitoring may correspond to AU and SI controls. Configuration management may correspond to CM controls. Incident response may correspond to IR controls. Supply chain security may correspond to SA and SR controls.

FedRAMP's current control reference contains 20 NIST SP 800-53 Rev. 5 control families, providing a structured basis for this type of crosswalk. The mapping should not rely solely on similar terminology. Control intent, scope, parameters, assessment frequency, system boundary, responsible party, and evidence type all matter.

FedRAMP Controls That Can Provide Reusable Security Evidence

A mature FedRAMP environment can generate a significant body of security evidence. Depending on the service and authorization level, this may include system security information, control descriptions, assessment results, monitoring records, vulnerability information, incident response evidence, configuration records, access management evidence, and other security artifacts.

FedRAMP Rev. 5 includes formal control assessment requirements. The assessment process considers whether controls are implemented correctly, operating as intended, and producing the desired outcome.

This evidence can be valuable during California procurement because it provides a documented record of how security controls operate. It should still be reviewed against the California agency's exact requirements rather than presented as automatic evidence of Cal-Secure conformity.

Where Cal-Secure Requirements May Extend Beyond FedRAMP

A FedRAMP authorization does not automatically establish that every California requirement has been satisfied.

California may impose requirements related to state-specific procurement terms, data handling, breach notification, system authorization, contractual responsibilities, service-specific conditions, or other state policies. California's Cloud Services Assessment process, for example, references state-specific security and data classification requirements alongside Cal-Secure objectives.

The scope of the FedRAMP authorization also matters. A vendor may have multiple products, environments, service boundaries, inherited controls, or system components that are not covered by the specific FedRAMP authorization being presented.

The safest approach is to treat FedRAMP as a substantial source of security evidence while separately validating every California requirement.

Cal-Secure and SOC 2: Mapping Common Security Controls

Cal-Secure Controls and SOC 2 Common Criteria

SOC 2 evaluates controls against the AICPA Trust Services Criteria. The criteria cover Security, Availability, Processing Integrity, Confidentiality, and Privacy, with Security serving as the common category for every SOC 2 examination.

This creates meaningful overlap with Cal-Secure areas such as access control, monitoring, incident response, change management, risk management, system security, and data protection.

However, SOC 2 and Cal-Secure have different structures and purposes. SOC 2 is an examination of controls at a service organization against selected Trust Services Criteria. Cal-Secure is a state cybersecurity roadmap intended to mature California Executive Branch security capabilities.

SOC 2 Security Controls Relevant to California Public Sector Vendors

A SOC 2 report may contain evidence relating to logical access, authentication, security monitoring, change management, incident response, risk management, vendor management, system operations, and other security activities.

The usefulness of that report for a California procurement depends on the report's scope. Buyers may examine the service description, control objectives, testing period, exceptions, subservice organizations, complementary user entity controls, and the systems included in the report.

A SOC 2 Type 2 report can provide evidence about the operating effectiveness of controls over a defined period. A Type 1 report addresses the design of controls at a specified point in time. These differences matter when a procurement requests evidence about ongoing control operation.

Using SOC 2 Evidence Across California Public Sector Requirements

A vendor can organize its SOC 2 evidence according to the security topics requested by a California agency. Access controls can be connected to identity requirements. Monitoring evidence can be connected to logging and security operations requirements. Change management evidence can be connected to application and configuration controls. Incident response evidence can be connected to cybersecurity response requirements.

The key consideration is traceability. The vendor should be able to show what the SOC 2 report covers, which controls were examined, what period was tested, and how those controls relate to the California requirement.

Limitations of Using SOC 2 as a Substitute for Public Sector Requirements

SOC 2 is not a California government authorization. A SOC 2 report also does not automatically demonstrate compliance with every California security requirement.

The report may cover a specific product, service, organizational unit, data center, or system boundary. California procurement requirements may extend beyond that scope. An agency may also request specific security evidence that does not appear in the SOC 2 report.

For this reason, SOC 2 should be positioned as assurance evidence that can contribute to a California security evidence package, rather than as a universal replacement for public sector requirements.

Cal-Secure Controls Mapping: FedRAMP vs SOC 2

Identity and Access Control Mapping

Identity and access controls are an area where all three environments can intersect. Cal-Secure identifies privileged access management and multifactor authentication among its cybersecurity capabilities. FedRAMP uses NIST AC and IA controls for access and authentication. SOC 2 security criteria can cover logical access and authentication controls within the examined system.

A crosswalk should compare the actual control activities rather than simply matching the names. Questions should include who receives access, how privileged accounts are managed, whether MFA applies, how access is reviewed, how terminated users are removed, and what evidence demonstrates that the control operates.

Vulnerability and Threat Management Mapping

Cal-Secure identifies continuous vulnerability management and security operations as important technical capabilities. FedRAMP contains specific controls for flaw remediation and system monitoring. SOC 2 reports can include security controls addressing vulnerability management and monitoring when these activities fall within the examination scope.

The crosswalk should identify the vulnerability scanning process, remediation timelines, exception handling, security monitoring, alert management, and evidence retention requirements applicable to the California procurement.

Incident Response and Monitoring Mapping

California's security operations model emphasizes continuous monitoring, threat detection, information sharing, and response. FedRAMP includes Incident Response and Audit and Accountability control families, along with monitoring requirements. SOC 2 security examinations can include incident response and monitoring controls within the defined system scope.

A vendor should distinguish between having an incident response policy and demonstrating that incident response processes operate effectively. California procurement teams may request policies, procedures, testing records, incident logs, escalation records, monitoring evidence, or independent assessment results.

Data Protection and Encryption Mapping

Data protection requirements can involve encryption, access restrictions, information classification, transmission security, storage protections, and contractual data handling provisions.

FedRAMP contains System and Communications Protection and Media Protection control families. SOC 2 confidentiality and privacy criteria can also be relevant when those categories are included in the engagement. California cloud requirements separately address data classification and security considerations.

The crosswalk should therefore identify where data is stored and processed, which encryption mechanisms apply, who can access the information, and what California-specific contractual or data classification conditions apply.

Business Continuity and Disaster Recovery Mapping

Business continuity is relevant when California agencies depend on a vendor's service for public operations. FedRAMP includes a Contingency Planning control family, while SOC 2 Availability can address controls associated with system availability and resilience when that criterion is included within the engagement.

California's cloud assessment process also references technology recovery planning and recovery objectives.

A vendor should therefore be prepared to demonstrate how recovery objectives, backup controls, disaster recovery testing, service resilience, and recovery procedures relate to the specific service provided to the state.

Application and Supply Chain Security Mapping

Application security and software supply chain security have direct relevance to California's cybersecurity priorities. The original Cal-Secure roadmap identified application development security and software supply chain management as technical capabilities.

FedRAMP's System and Services Acquisition and Supply Chain Risk Management families provide relevant control areas. SOC 2 can also include change management, vendor management, software development, and security controls where these activities fall within scope.

A strong crosswalk should identify the software development lifecycle, code security testing, dependency management, supplier reviews, software component visibility, change approvals, vulnerability remediation, and security testing evidence applicable to the service.

Cal-Secure Compliance Requirements for California Government Vendors

Security Requirements for Technology and Cloud Service Providers

California does not turn every technology supplier into a Cal-Secure-certified vendor. Instead, security requirements can arise from the state's procurement and security framework and from the requirements of the agency purchasing the service.

The California Department of Technology maintains vendor resources for companies seeking to sell technology products and services to the state. The department directs businesses to the Department of General Services and Cal-eProcure for procurement-related activities and provides access to statewide technology and security resources.

Cloud providers should pay particular attention to California's cloud security requirements because state cloud procurement can involve security assessments, system classification, architecture information, security plans, privacy assessments, and other evidence.

California Public Sector Procurement and Security Expectations

Public sector procurement is more specific than simply demonstrating that a company follows generally recognized security practices. The solicitation, contract, security questionnaire, agency policy, and service characteristics can determine the evidence requested from a vendor.

California's statewide procurement environment therefore needs to be evaluated at the individual opportunity level. A FedRAMP authorization or SOC 2 report can provide valuable evidence, but the vendor should review the procurement language for additional state-specific requirements.

This distinction is particularly important for companies entering California's public sector market for the first time.

Security Evidence and Assurance Considerations for Vendors

California public sector buyers may examine whether a vendor can demonstrate effective security controls through independent assessments, security reports, policies, testing results, monitoring records, and other evidence.

FedRAMP offers a highly structured federal assessment and authorization model. SOC 2 provides an independent examination against the applicable Trust Services Criteria. The evidentiary value of either depends on scope, period, system boundary, assessment coverage, and the exact California requirement being evaluated.

How FedRAMP and SOC 2 Can Strengthen a Vendor's Security Evidence

FedRAMP and SOC 2 can provide different types of assurance evidence. FedRAMP is particularly relevant to cloud service providers operating within the federal authorization environment and is based on NIST SP 800-53 controls. SOC 2 provides an examination framework based on AICPA Trust Services Criteria.

When California requirements overlap with these control areas, existing evidence can reduce duplication in evidence collection. The vendor still needs to establish the connection between the evidence and the California requirement.

Building a Cal-Secure Control Crosswalk for FedRAMP and SOC 2

Identify Applicable Cal-Secure Security Requirements

The first step is to identify the actual California requirements relevant to the opportunity. Start with the solicitation, security questionnaire, contract terms, applicable state policies, cloud requirements, data classification requirements, and agency-specific security conditions.

Do not create a crosswalk based only on a general list of Cal-Secure priorities. Cal-Secure establishes statewide direction, while the actual procurement determines what the vendor must demonstrate.

Map Existing FedRAMP Controls to Cal-Secure Requirements

Once the California requirements are identified, map each requirement to the relevant FedRAMP control or control family. The mapping should record the control objective, control identifier, system scope, responsible party, evidence source, assessment date, and any remaining California-specific requirement.

FedRAMP's Rev. 5 catalog provides a structured control reference covering access control, identification and authentication, audit and accountability, incident response, contingency planning, system and communications protection, system and information integrity, supply chain risk management, and other security areas.

SOC 2 evidence should be mapped at the control activity level. A report's general statement that security controls were examined is not enough to demonstrate that every California requirement is covered.

The mapping should identify the relevant Trust Services Criteria, control description, testing procedure, testing period, result, system boundary, and any exceptions.

Identify Control Coverage and Evidence Differences

A useful crosswalk should clearly distinguish between full evidence coverage, partial coverage, and areas where additional evidence is required.

For example, a SOC 2 report may cover access management but not address a specific California data residency requirement. A FedRAMP authorization may provide extensive cloud security evidence but not cover a separate state contractual requirement. Identifying these differences prevents overstatement of compliance.

Maintain the Crosswalk as Requirements Change

Cal-Secure 2.0 is part of California's continuing cybersecurity strategy, and the state is updating security policies, standards, maturity measurements, and technology priorities. California's 2026 roadmap specifically identifies future changes to cybersecurity maturity measurements and new Cal-Secure capabilities.

Vendors targeting California public sector contracts should therefore treat the crosswalk as a maintained security reference rather than a static document.

What California Public Sector Buyers May Look for in Security Assurance

Independent Security Assessments and Assurance

Independent assurance can provide buyers with evidence that security controls have been evaluated against a defined standard or criteria. FedRAMP includes formal control assessments and independent assessment requirements within its authorization structure. SOC 2 provides an independent examination of controls against applicable Trust Services Criteria.

The relevance of an assessment depends on its scope. Buyers may examine whether the assessment covers the product, environment, data, systems, and services included in the procurement.

Security Policies, Control Evidence, and Assessment Reports

California public sector procurement can involve requests for security policies, system descriptions, assessment reports, control evidence, incident response information, vulnerability information, and other security artifacts.

A vendor should maintain a clear relationship between each artifact and the control it demonstrates. This makes it easier to respond when an agency asks for evidence using California-specific terminology.

Cloud Security and Data Protection Evidence

Cloud providers should be prepared to demonstrate how security controls apply to the actual cloud service being offered. California's Cloud Services Assessment process references system classification, cloud architecture, security plans, privacy impact information, recovery planning, and alignment with California cloud security requirements and Cal-Secure capabilities.

FedRAMP evidence can be relevant where the authorized service boundary matches the California offering. SOC 2 evidence can also be relevant when the report covers the same service and security processes.

Ongoing Monitoring and Control Effectiveness

Public sector buyers may place particular importance on evidence showing that security controls remain effective over time. California's cybersecurity operations program emphasizes continuous security monitoring, while FedRAMP includes continuous monitoring expectations and formal assessment activities.

SOC 2 Type 2 reporting can also provide evidence about control operation over a defined examination period. The report's testing period and scope should be reviewed before relying on it for a particular California procurement.

Strengthen Your FedRAMP Readiness. Evaluate your security controls and prepare for the requirements associated with federal cloud security authorization.

Key Differences Between Cal-Secure, FedRAMP, and SOC 2

Scope and Intended Audience

Cal-Secure is a California Executive Branch cybersecurity roadmap. Its primary audience is California state entities.

FedRAMP is a federal program focused on the security assessment and authorization of cloud services for federal use. Its security control structure is based on NIST SP 800-53.

SOC 2 is an examination framework for service organizations based on AICPA Trust Services Criteria. Its scope can address Security and, when selected, Availability, Processing Integrity, Confidentiality, and Privacy.

These different purposes explain why none of the three should automatically be treated as interchangeable.

Control Structure and Security Objectives

Cal-Secure organizes California's cybersecurity maturity priorities around statewide objectives and capabilities. FedRAMP uses defined NIST SP 800-53 controls, control enhancements, baselines, parameters, and assessment procedures. SOC 2 uses Trust Services Criteria and control activities established by the service organization and examined against the selected criteria.

The same security objective can therefore appear under different terminology and structures.

Assessment and Assurance Requirements

FedRAMP has a formal authorization structure with defined control baselines and assessment activities. SOC 2 involves an independent examination performed under the applicable professional standards. Cal-Secure primarily serves as California's statewide cybersecurity maturity roadmap rather than a private-sector certification scheme.

For vendors, this distinction is important when describing their security credentials in a proposal. A FedRAMP authorization should be described as a FedRAMP authorization, and a SOC 2 report should be described according to its actual scope and criteria.

How the Frameworks Can Work Together

The three frameworks can coexist within a vendor's security evidence strategy. Cal-Secure can indicate the cybersecurity priorities relevant to California state entities. FedRAMP can provide NIST-based cloud security evidence. SOC 2 can provide independent assurance over defined service organization controls.

A vendor pursuing California public sector opportunities can use these sources to establish a structured evidence map while separately addressing California-specific procurement requirements.

The practical objective is not to claim that one framework replaces another. It is to establish traceability between the buyer's requirement and the evidence that demonstrates how the vendor addresses it.


Read More:
Know About System Organization Control (SOC 2) Compliance
FedRAMP Authorization: Requirements, Process and Key Steps

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved