Databricks
What this guide covers
How to actually buy Databricks for a Maryland agency — which statewide vehicle you ride (this one needs confirmation), which reseller fulfills the order, the FedRAMP/ATO path across GovCloud and Azure Government, and the functionality gates to clear before you sign.
Who it’s for
Engineering leads, data and ML/platform staff, and procurement officers at a Maryland State agency or education entity who have decided they need Databricks — lakehouse, data engineering, ML — and need the path from “we want it” to “it’s authorized and on contract.”
Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.
Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and BPO numbers change as awards are renewed and authorizations are re-baselined. Verify every figure below against the FedRAMP Marketplace, the Carahsoft Maryland State Contracts page, and the DoIT Statewide Contracts hub before relying on it. The Maryland vehicle for Databricks is not confirmed — treat the vehicle section as a starting point to verify with Carahsoft and DoIT, not a settled fact.
TL;DR
- Category: Data and analytics — lakehouse / data engineering / ML platform (compare Snowflake; runs on AWS GovCloud).
- Maryland vehicle: Unverified. Databricks is not confirmed on the Carahsoft MD COTS publisher list, and Carahsoft’s primary-aggregator status for Databricks is less certain than for other vendors. Realistic paths are Carahsoft on COTS or NASPO — confirm with Carahsoft/DoIT before quoting.
- Reseller: Carahsoft is a public-sector partner — exclusivity and vehicle for Databricks are unverified.
- Authorization: FedRAMP High on AWS GovCloud (Agency ATO, authorized 2025-02-27). Azure Databricks also holds FedRAMP High + DoD IL-5. Two AWS GovCloud offerings exist — DoD (DoD-only) and Community (non-DoD government & contractors). Supports ITAR.
- The ATO trap: FedRAMP High is AWS GovCloud / Azure Government only — commercial Databricks is not authorized; and the DoD vs. Community GovCloud offerings are separate (DoD is exclusive to DoD).
What This Tool Is
Databricks is a SaaS lakehouse platform — unified data engineering, analytics, and machine learning on top of object storage, built around Apache Spark and the lakehouse architecture. In this stack it is the commercial alternative to a self-hosted lakehouse, and the comparable data-cloud page is Snowflake. The self-hostable lakehouse building blocks are Apache Spark, Trino, and Apache Iceberg; Databricks is the managed, FedRAMP-authorized platform that assembles them. It runs on AWS GovCloud (and Azure Government). Agencies reach for it when their data-engineering and ML workloads outgrow a self-operated stack — which turns a $0-license choice into a procurement-and-ATO exercise. This page is that exercise.
Which Maryland Vehicle
This section is unverified — confirm before quoting. Databricks is not confirmed on the Carahsoft MD COTS publisher list, and unlike the other tools in this catalog, Carahsoft’s status as the primary Maryland aggregator for Databricks is uncertain. Do not assert a COTS line as settled.
| Vehicle | BPO | How Databricks might ride it |
|---|---|---|
| COTS 2012 (unverified) | 060B2490021 (confirm) | A realistic path if Databricks is added to / present on Carahsoft’s Maryland COTS publisher catalog. Confirm Databricks’s presence on the COTS catalog with Carahsoft and DoIT before quoting against this BPO. |
| NASPO ValuePoint Cloud Solutions (unverified) | Maryland participating addendum (Carahsoft) | A cloud/SaaS alternative the State extended into Maryland. Realistic for a SaaS lakehouse, but confirm Databricks is reachable through it before relying on it. |
The same publisher can be reachable through more than one Carahsoft vehicle, and which one you ride affects ceiling pricing, terms, and which approvals apply — see Maryland Master Contracts → Where Carahsoft Fits. Note that Databricks does appear in the reproduced publisher list in Software Publishers Under Carahsoft’s MD COTS, but that list is one contractor’s slice and should be confirmed against the live Carahsoft and DoIT catalogs before you treat the COTS path as settled.
Resellers and Pricing Path
Carahsoft is a Databricks public-sector partner, but its exclusivity and the exact Maryland vehicle for Databricks are unverified — confirm both before you build a quote. You do not buy a “Carahsoft contract” — a reseller fulfills your order against whatever master contract the State and the publisher actually sit under. Once you have confirmed the vehicle, request a quote referencing the matching BPO so the order is priced against the statewide ceiling rather than commercial list price. Databricks is consumption-metered (DBUs plus the underlying cloud compute and storage), so the quote depends on your workload volume — size it before you ask, and revisit it, because consumption-based bills drift upward.
Authorization and ATO
| Attribute | Value |
|---|---|
| Authorized offering (High, AWS) | Databricks on AWS GovCloud — FedRAMP High (Agency ATO, authorized 2025-02-27) |
| Two AWS GovCloud offerings | Databricks AWS GovCloud DoD (DoD-only) and Databricks AWS GovCloud Community (non-DoD government & contractors) — separate boundaries |
| Azure offering | Azure Databricks holds FedRAMP High + DoD IL-5 |
| ITAR | Supported |
| Marketplace ID | Not provided — locate the current Databricks GovCloud listing via the FedRAMP Marketplace search; do not assume an ID |
| GovRAMP (StateRAMP) | Not confirmed — verify on the GovRAMP product list |
The single thing to get right for the ATO: FedRAMP High is AWS GovCloud / Azure Government only — commercial Databricks is not authorized, so an order that lands you on the commercial platform gives you nothing to inherit, and the gap will surface late in your security review. Second, the two AWS GovCloud offerings are separate boundaries: Databricks AWS GovCloud DoD is exclusive to DoD, while non-DoD government and contractors use Databricks AWS GovCloud Community. Pick the offering that matches who you are and your required impact level before you provision — they are not interchangeable. Confirm the current listing and boundary on the Marketplace first.
Functionality Gates to Verify
Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.
| Gate | Databricks-specific note |
|---|---|
| SSO (SAML/OIDC) + SCIM | Supported; confirm SCIM de-provisioning is included at your tier, not gated to a higher plan. |
| Audit logs | Available; confirm delivery and retention meet your records policy. |
| RBAC | Unity Catalog provides fine-grained governance and access control; map to least-privilege before rollout. |
| Data residency / FedRAMP boundary | AWS GovCloud (or Azure Government) is the residency answer — see above; commercial is out of boundary. |
| Accessibility (VPAT/ACR) | Request Databricks’s current VPAT; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement. |
| BAA / DPA | Required if any stored data could carry PII/PHI; confirm availability for the chosen government deployment. |
Procurement Steps
- Confirm the need over the OSS alternative. The self-hostable lakehouse building blocks are Apache Spark, Trino, and Apache Iceberg ($0 license). Document why managed, FedRAMP-authorized Databricks is worth the spend — that rationale is the core of the budget justification.
- Confirm the vehicle — do not assume. Databricks’s Maryland vehicle is unverified. Confirm with Carahsoft and DoIT whether it rides COTS (BPO 060B2490021), the NASPO Cloud addendum, or another path before you proceed.
- Register / confirm eMMA. Your agency and the reseller must be set up in eMMA.
- Get a quote referencing the confirmed BPO, sized to your DBU consumption and cloud footprint, for the AWS GovCloud Community offering (non-DoD) or Azure Government — and match the offering to your impact level.
- Check the threshold. The order’s dollar value drives the method — purchasing card, small procurement, or BPW review. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
- Run the ATO package. Inherit the FedRAMP High controls for the matching boundary (AWS GovCloud Community for non-DoD, or Azure Government); document the rest. Commercial Databricks is not authorized — confirm the boundary first.
- Issue the order against the vehicle once the vehicle and approvals are confirmed.
Sources
| Claim | Source |
|---|---|
| Databricks FedRAMP High on AWS GovCloud (2025-02-27) | Databricks — FedRAMP High on AWS GovCloud |
| Databricks DoD IL-5 on AWS GovCloud | Databricks — DoD IL-5 authorization |
| FedRAMP / Azure High / ITAR / offerings scope | Databricks — FedRAMP compliance |
| Databricks GovCloud FedRAMP listing | FedRAMP Marketplace — locate the Databricks GovCloud listing (no ID provided — confirm the current listing) |
| Carahsoft Maryland State Contracts (vehicle unverified) | Carahsoft — Maryland State Contracts |
The Maryland vehicle for Databricks is unverified, and there are two separate AWS GovCloud offerings (DoD vs. Community) plus an Azure High boundary. Re-verify the vehicle with Carahsoft/DoIT and confirm which boundary matches your classification against the Marketplace before relying on any figure here.
Related Resources
- SaaS Catalog — Playbook — all tools, compared in one matrix
- Snowflake — the comparable data-cloud page
- AWS — Databricks runs on AWS GovCloud; the underlying cloud’s procurement path
- Maryland Master Contracts — COTS / CATS+ / Carahsoft, the vehicle this would ride
- Maryland Procurement — BPW, eMMA, COMAR thresholds, the process that still binds the order
- Federal Procurement — the federal analog (FAR, GSA Schedules, SAM.gov)
- Tools and Software → Enterprise Functionality — the gates to clear before price