Skip to content

Amazon Web Services (AWS)

What this guide covers

How to actually buy AWS cloud for a Maryland agency — which statewide vehicle you ride (the exact Maryland line is unverified and you must confirm it), which reseller fulfills the order, the FedRAMP/ATO path across the commercial regions and GovCloud, and the functionality gates to clear before you sign.

Who it’s for

Engineering leads, program staff, and procurement officers at a Maryland State agency or education entity who have decided they need AWS infrastructure (or are comparing it against the self-hosted stack) and need the path from “we want it” to “it’s authorized and on contract.”

Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.

Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and BPO numbers change as awards are renewed and authorizations are re-baselined. Verify every figure below against the FedRAMP Marketplace, the AWS compliance pages, and the DoIT Statewide Contracts hub before relying on it. The exact Maryland vehicle for AWS is not confirmed in the facts below — see Which Maryland Vehicle.


TL;DR

  • Category: Cloud platform — IaaS/PaaS (compute, storage, networking, managed services).
  • Maryland vehicle: UNVERIFIED. AWS does not appear on the Carahsoft MD COTS publisher list, and (per research) not on the MD NASPO addendum publisher list either. The realistic paths are the NASPO ValuePoint Cloud Solutions addendum (Carahsoft master agreement AR2472) or COTS 2012 (BPO 060B2490021) via Carahsoft — confirm the current vehicle with DoIT.
  • Reseller: Carahsoft (which absorbed DLT), AWS’s SLG aggregator.
  • Authorization: AWS GovCloud (US) is FedRAMP High (JAB P-ATO); AWS US East/West commercial regions are FedRAMP Moderate (JAB P-ATO), some services High at agency level. AWS is recognized on GovRAMP.
  • The ATO trap: GovCloud (US) is a physically and logically separate partition — separate accounts and credentials; you cannot reach High workloads from commercial AWS accounts.

What This Tool Is

AWS is the IaaS/PaaS cloud — compute (EC2, Lambda), storage (S3), networking (VPC), and a long catalog of managed databases, analytics, and platform services. Agencies reach for it when they want a managed hyperscaler rather than operating infrastructure themselves. The self-hostable alternative is the Kubernetes/Postgres/MinIO stack from Tools and Software → Infrastructure, which can substitute for AWS’s core compute/storage/database primitives, but there is no drop-in OSS swap for the full managed-services catalog — so for most agencies this is a procurement-and-ATO exercise.


Which Maryland Vehicle

VehicleIdentifierHow AWS rides it
NASPO ValuePoint Cloud Solutions (MD participating addendum, Carahsoft)Carahsoft master agreement AR2472The most likely path — the State extended Carahsoft’s NASPO Cloud contract into Maryland. AWS’s presence on the MD addendum publisher list is unverified — confirm with DoIT.
COTS 2012 (via Carahsoft)060B2490021A possible alternative path, but AWS does not appear on the Carahsoft MD COTS publisher list in current research — confirm before relying on it.

The exact Maryland line for AWS is UNVERIFIED. AWS does not appear on the Carahsoft Maryland COTS publisher list, nor (per research) on the MD NASPO addendum publisher list. The two realistic paths are the NASPO Cloud addendum or COTS 060B2490021 via Carahsoft — confirm the current vehicle directly with DoIT before you build a requisition. Carahsoft, which absorbed DLT, is AWS’s state-and-local-government aggregator. See Maryland Master Contracts → Where Carahsoft Fits.


Resellers and Pricing Path

Carahsoft (formerly DLT, which it absorbed) is AWS’s primary public-sector aggregator and the reseller you will most likely buy through in Maryland. You do not buy a “Carahsoft contract” — Carahsoft fulfills your order against whichever vehicle DoIT confirms is current (NASPO Cloud addendum or COTS). Request a quote referencing the confirmed Maryland vehicle so the order is priced against the statewide ceiling rather than commercial list price. AWS is usage-metered across hundreds of services, so the quote depends on your projected consumption — size it before you ask, and revisit it, because usage-based bills drift upward.


Authorization and ATO

OfferingFedRAMP statusMarketplace ID
AWS GovCloud (US)FedRAMP High (JAB P-ATO)confirm on Marketplace
AWS US East/West (commercial regions)FedRAMP Moderate (JAB P-ATO); some services High at agency levelAGENCYAMAZONEW
GovRAMPAWS is recognized on GovRAMPsee GovRAMP product list

The single thing to get right for the ATO: AWS GovCloud (US) is a physically and logically separate partition. It requires separate accounts and separate credentials — you cannot reach FedRAMP High workloads from a commercial AWS account. If your data classification needs the High boundary, you must provision GovCloud from the start; a commercial-region account gives you only the Moderate authorization to inherit (and only for in-scope services). FedRAMP scope is also service-by-service — confirm each AWS service you intend to use is in boundary at the impact level you need before you commit.


Functionality Gates to Verify

Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.

GateAWS-specific note
SSO (SAML/OIDC) + SCIMSupported via IAM Identity Center (formerly AWS SSO), with SCIM provisioning; confirm it federates to your IdP.
Audit logsCloudTrail provides API-level audit; confirm retention and log-archive configuration meet your records policy.
RBACIAM policies and roles are granular; map to least-privilege before rollout.
Data residency / FedRAMP boundaryGovCloud (US) is the High residency answer; commercial regions are Moderate — and FedRAMP scope is service-by-service.
Accessibility (VPAT/ACR)Request AWS’s current VPAT; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement.
BAA / DPAAvailable; required if any workload could carry PII/PHI — confirm for the specific partition you buy.

Procurement Steps

  1. Confirm the need over the alternative. AWS’s core compute/storage/database overlaps the self-hostable Kubernetes/Postgres/MinIO stack ($0 license); the managed-services catalog has no full OSS drop-in. Document why managed is worth the spend — that rationale is the core of the budget justification.
  2. Register / confirm eMMA. Your agency and the reseller must be set up in eMMA.
  3. Confirm the vehicle with DoIT. Because the exact AWS Maryland line is unverified, resolve this first — NASPO Cloud addendum (AR2472) or COTS 060B2490021 via Carahsoft.
  4. Get a Carahsoft quote referencing the confirmed vehicle, sized to your projected consumption, for the specific partition you need (GovCloud (US) vs. commercial regions).
  5. Check the threshold. The order’s dollar value drives the method. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
  6. Run the ATO package. Inherit the FedRAMP controls for the specific partition and the in-scope services — verify service-level scope first.
  7. Issue the order against the confirmed vehicle once approvals clear.

Sources

ClaimSource
AWS FedRAMP program overviewAWS — FedRAMP compliance
AWS GovCloud (US) FedRAMP High (JAB P-ATO)AWS — GovCloud receives JAB FedRAMP High P-ATO
AWS commercial regions (US East/West) Moderate listingFedRAMP Marketplace — AGENCYAMAZONEW
AWS recognized on GovRAMPAWS — recognized by GovRAMP

The exact Maryland vehicle for AWS is unverified — AWS appears on neither the Carahsoft MD COTS publisher list nor (per research) the MD NASPO addendum publisher list. Confirm the current vehicle with DoIT before relying on any path here.