Procurement
What this section covers
How to choose tools and software, and how to actually buy them inside the rules that govern public-sector spending. Tool selection and the purchasing process are two different problems — this library keeps them separate but linked.
Who it’s for
Engineering leads, program managers, contracting officers, and anyone preparing a budget request, a sole-source justification, or a competitive solicitation.
Disclaimer. These guides are practitioner references, not legal or contracting advice. Dollar thresholds and procedures change with statute, regulation, and agency delegation. Every figure here is marked with the source to check and a
last_verifieddate — confirm the current number against the cited authority before you rely on it. When in doubt, talk to your procurement officer.
The guides
| Guide | What it covers |
|---|---|
| Tools and Software | The canonical stack — license, self-hostability, paid alternative replaced, budget-justification template, and the enterprise functionality (SSO first) to verify before buying anything |
| Federal Procurement | FAR thresholds (micro-purchase, simplified acquisition), GSA Schedules, SAM.gov, purchase cards, and small-business set-asides |
| Maryland Procurement | Board of Public Works (BPW), eMaryland Marketplace Advantage (eMMA), COMAR Title 21, small-procurement and purchasing-card limits |
| Maryland Master Contracts | The statewide IT master contracts (COTS, CATS+, Hardware) with BPO numbers, where Carahsoft fits as a reseller, and the full publisher catalog |
| SaaS Catalog — Playbook | Worked, per-tool procurement playbooks for the most-requested SaaS (GitHub, Datadog, Salesforce, Microsoft, AWS, ServiceNow, Splunk, CrowdStrike, Okta…) — each mapping the tool to its Maryland vehicle, reseller, FedRAMP/StateRAMP status, and ATO path |
| ATO & FedRAMP | Plain-language explainer: what an Authorization to Operate is, the NIST RMF lifecycle (SSP, POA&M, ConMon), FedRAMP vs GovRAMP, Maryland’s rules, and why you must buy the government edition |
| SaaS Setup — Implementation | The phase after you buy: Day 0 → Day 2 setup for each tool — the simplest first use case, the five gov-readiness must-dos, and scaling as the team grows |
How to use this section
- Decide what to buy with Tools and Software. Confirm the tool clears every functionality gate — SSO/SCIM, audit logs, accessibility (VPAT/ACR), data residency — before you compare price. The cheapest option that fails a required control is not an option.
- Find your jurisdiction’s rules in the Federal or Maryland guide. The dollar value of the buy determines the method — purchase card, small procurement, simplified acquisition, or full competition.
- Match the method to the threshold. Spending just over a threshold to dodge a competition requirement (or splitting one buy into several to stay under a limit) is a procurement violation in every jurisdiction. The thresholds exist to set the process, not to be gamed.
- To buy a specific named product, jump straight to its page in the SaaS Catalog. Each gives the exact Maryland vehicle, reseller, FedRAMP/authorization status, and the ATO path — so “we picked Datadog” becomes “it’s authorized and on contract.”
- Once it’s on contract, set it up. The SaaS Setup playbook takes each tool from Day 0 to Day 2 — the simplest first use case, the five gov-readiness must-dos (SSO, SCIM, audit→SIEM, gov edition, least-privilege), and how to scale without over-configuring. If the authorization vocabulary is new, read the ATO & FedRAMP explainer first.
Related resources
- STANDARDS.md — §3 Default Tech Stack
- Engineering Discovery — Overview — readiness library that this procurement guidance supports