GitHub
What this guide covers
How to actually buy GitHub for a Maryland agency — which path you ride (and why it is not the usual Carahsoft COTS line), which reseller fulfills the order, the FedRAMP/ATO ceiling you inherit, and the functionality gates to clear before you sign. GitHub is the honest-edge-case page in this catalog: it is not FedRAMP Moderate and not on a Maryland Carahsoft COTS line, and both gaps shape the buy.
Who it’s for
Engineering leads, program staff, and procurement officers at a Maryland State agency or education entity who have decided they need GitHub for source control and CI/CD (or are comparing it against self-hosted Git hosting) and need the path from “we want it” to “it’s authorized and on contract.”
Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.
Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and licensing channels change as awards are renewed and authorizations are re-baselined. Verify every figure below against the FedRAMP Marketplace, the GitHub FedRAMP FAQ, and the DoIT Statewide Contracts hub before relying on it. GitHub’s Maryland purchasing path and its FedRAMP Moderate status are both unsettled (see below) and should be re-checked with your procurement officer.
TL;DR
- Category: DevOps & source control — Git hosting, code review, CI/CD via GitHub Actions.
- Maryland vehicle: No confirmed Maryland COTS line for GitHub. GitHub is absent from the Carahsoft MD COTS publisher catalog. GitHub is Microsoft-owned; its public-sector motion runs through Microsoft licensing channels and large-account resellers (e.g., SHI), often via cooperative vehicles like NASPO ValuePoint SVAR. The specific Maryland vehicle is unverified — confirm with your procurement officer / DoIT.
- Reseller: Microsoft channel / SHI — not Carahsoft for SLG. (Contrast GitLab, which is a Carahsoft MD COTS publisher.)
- Authorization: GitHub Enterprise Cloud is FedRAMP Tailored / Li-SaaS (Low) — authorized 2018, GSA-sponsored. GitHub announced in October 2024 that it is pursuing FedRAMP Moderate; that is not yet authorized.
- The ATO trap: GitHub Enterprise Cloud is Low, not Moderate. If your system needs Moderate for CUI, the managed cloud does not meet it today — the higher-assurance option is GitHub Enterprise Server self-hosted in your own authorized boundary (e.g., AWS GovCloud), which you authorize yourself.
What This Tool Is
GitHub is a SaaS platform for Git hosting, code review (pull requests), and CI/CD via GitHub Actions, with issue tracking, packages, and an integrated security toolset (code scanning, secret scanning, Dependabot). In this stack it is the managed choice for source control and automation; the self-hostable alternatives are GitLab CE, Gitea, and Forgejo, which matter precisely because GitHub’s managed FedRAMP ceiling is Low today and a self-hosted Git server can be authorized inside whatever boundary you control. Agencies reach for GitHub for the ecosystem, Actions, and developer familiarity — a legitimate trade, but one that turns a $0-license self-hosted option into a procurement-and-ATO exercise. This page is that exercise.
Which Maryland Vehicle
There is no confirmed Maryland COTS line for GitHub. GitHub does not appear on the Carahsoft MD COTS publisher catalog — do not cite a Carahsoft MD COTS BPO for it. GitHub is Microsoft-owned, so its public-sector purchasing typically rides Microsoft’s licensing channels rather than a Carahsoft software line.
| Path | Status | How GitHub might ride it |
|---|---|---|
| Microsoft licensing channel (large-account reseller, e.g., SHI) | Unverified for Maryland | GitHub may be reachable through the same Microsoft licensing route as the Microsoft 365 & Azure ICPA rather than via Carahsoft COTS. Confirm with your procurement officer / DoIT. |
| NASPO ValuePoint SVAR (cooperative) | Unverified for Maryland | Software Value-Added Reseller cooperative vehicle SHI and others hold; confirm a Maryland participating addendum and that GitHub is in scope before relying on it. |
| Carahsoft MD COTS | Not applicable | GitHub is absent from Carahsoft’s MD COTS publisher list. This is the GitLab contrast: GitLab is a Carahsoft MD COTS publisher; GitHub is not. |
Because the same publisher can be reachable through more than one vehicle — and which one you ride affects ceiling pricing, terms, and approvals — confirm the actual Maryland path before you quote. See Maryland Master Contracts → Where Carahsoft Fits for how reseller awards map to vehicles, and treat the Microsoft-channel path here as the working hypothesis to verify, not a settled fact.
Resellers and Pricing Path
GitHub’s public-sector fulfillment runs through the Microsoft channel and large-account resellers such as SHI — not Carahsoft for Maryland SLG. The likely Maryland route is the same Microsoft licensing motion that carries Microsoft 365 & Azure, possibly via the NASPO ValuePoint SVAR cooperative vehicle; confirm the specific Maryland vehicle and participating addendum with your procurement officer / DoIT before quoting. GitHub Enterprise is seat-licensed (per-user, per-tier — Enterprise Cloud vs. Enterprise Server), with GitHub Actions and storage metered on top, so size your seat count and Actions usage before you ask. Do not assume a Carahsoft COTS ceiling applies; GitHub is not on that line.
Authorization and ATO
| Attribute | Value |
|---|---|
| Authorized offering | GitHub Enterprise Cloud |
| FedRAMP status | Authorized — Tailored / Li-SaaS (Low), authorized 2018, GSA-sponsored |
| FedRAMP Moderate | Not authorized. GitHub announced (Oct 2024) it is pursuing Moderate — confirm current status on the Marketplace before relying on it |
| Marketplace ID | FR1812058188 |
| GovRAMP (StateRAMP) | Not confirmed — verify on the GovRAMP product list |
| Higher-assurance option | GitHub Enterprise Server self-hosted inside your own authorized boundary (e.g., AWS GovCloud), authorized by you |
The single thing to get right for the ATO: GitHub Enterprise Cloud is Li-SaaS (Low) — it is not Moderate. If your system needs a Moderate boundary for CUI, GitHub Enterprise Cloud does not yet meet it, and no amount of configuration changes the inherited baseline. The supported higher-assurance path is GitHub Enterprise Server self-hosted inside an authorized boundary you control (for example, on AWS GovCloud), which you then authorize yourself — you inherit the underlying IaaS authorization and own the GitHub layer. Do not represent GitHub as FedRAMP Moderate in your security package; the pursuit announced in October 2024 is a roadmap item, not an authorization. Re-check the Marketplace listing for any change before you commit.
Functionality Gates to Verify
Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.
| Gate | GitHub-specific note |
|---|---|
| SSO (SAML/OIDC) + SCIM | Supported on Enterprise; confirm SCIM de-provisioning is enabled for your org/enterprise account, not just SAML sign-in. |
| Audit logs | Available at the enterprise level; confirm retention and streaming (to your SIEM) meet your records policy. |
| RBAC | Org/team/repo roles supported; map them to least-privilege before rollout. |
| Data residency / FedRAMP boundary | Enterprise Cloud is Low only — see above. For a Moderate boundary you need self-hosted Enterprise Server in your own authorized environment. |
| Accessibility (VPAT/ACR) | Request GitHub’s current VPAT; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement. |
| BAA / DPA | Required if any repository content or metadata could carry PII/PHI; confirm availability for your chosen offering. |
Procurement Steps
- Confirm the need over the OSS alternative. GitHub replaces self-hostable Git hosting (GitLab CE, Gitea, Forgejo — $0 license). Document why managed GitHub is worth the spend — that rationale is the core of the budget justification.
- Resolve the boundary question first. If your system needs Moderate for CUI, Enterprise Cloud will not qualify — decide now between accepting the Low ceiling and standing up Enterprise Server self-hosted in an authorized boundary, because it changes the buy and the ATO.
- Confirm the actual Maryland vehicle. GitHub is not on Carahsoft MD COTS. Work with your procurement officer / DoIT to confirm the Microsoft channel / SHI path (and whether NASPO ValuePoint SVAR or the Microsoft ICPA route applies). Do not assume a COTS BPO.
- Register / confirm eMMA. Your agency and the awarded reseller must be set up in eMMA.
- Get a quote from the Microsoft-channel reseller, sized to your seat count and Actions/storage usage, referencing the confirmed vehicle.
- Check the threshold. The order’s dollar value drives the method — purchasing card, small procurement, or BPW review. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
- Run the ATO package. For Enterprise Cloud, inherit only the Low controls; for Enterprise Server, inherit the IaaS boundary’s controls and authorize the GitHub layer yourself. Verify the current FedRAMP status first.
- Issue the order against the confirmed vehicle once approvals clear.
Sources
| Claim | Source |
|---|---|
| GitHub Enterprise Cloud FedRAMP Tailored / Li-SaaS (Low) listing | FedRAMP Marketplace — FR1812058188 |
| FedRAMP status and offering details | GitHub FedRAMP FAQ |
| GitHub pursuing FedRAMP Moderate (Oct 2024) — not yet authorized | GitHub — to pursue FedRAMP Moderate |
| Microsoft-channel / SHI cooperative reseller path | SHI — NASPO ValuePoint SVAR |
| GitHub absent from Carahsoft MD COTS publisher list | Carahsoft — Maryland State Contracts |
GitHub is not FedRAMP Moderate and not on a Maryland Carahsoft COTS line. Both gaps are load-bearing for this buy. Re-verify the current FedRAMP baseline and the actual Maryland purchasing vehicle before relying on any figure here.
Related Resources
- Next: set it up — GitHub implementation → — Day 0 → Day 2 configuration and gov-readiness
- SaaS Catalog — Playbook — all tools, compared in one matrix
- Maryland Master Contracts — COTS / CATS+ / Carahsoft, and why GitHub is not on the COTS line
- Maryland Procurement — BPW, eMMA, COMAR thresholds, the process that still binds the order
- Federal Procurement — the GSA / NASPO SVAR / SEWP path GitHub’s federal motion realistically rides
- Tools and Software → Enterprise Functionality — the gates to clear before price