GitLab
What this guide covers
How to actually buy GitLab for a Maryland agency — which statewide vehicle you ride, which reseller fulfills the order, the FedRAMP/ATO path (and the single boundary it attaches to), and the functionality gates to clear before you sign. GitLab is the Carahsoft-channel counterpart to GitHub: where GitHub is absent from the Maryland Carahsoft COTS publisher list, GitLab is on it.
Who it’s for
Engineering leads, program staff, and procurement officers at a Maryland State agency or education entity who have decided they need GitLab for source control, CI/CD, and integrated DevSecOps (or are comparing it against self-hosted Git hosting) and need the path from “we want it” to “it’s authorized and on contract.”
Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.
Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and BPO numbers change as awards are renewed and authorizations are re-baselined. Verify every figure below against the FedRAMP Marketplace, the Carahsoft GitLab contracts page, and the DoIT Statewide Contracts hub before relying on it. GitLab’s FedRAMP authorization attaches to a single boundary (see below) and should be re-checked.
TL;DR
- Category: DevOps & source control — Git hosting, CI/CD, integrated DevSecOps platform.
- Maryland vehicle: COTS 2012, BPO 060B2490021, via Carahsoft (GitLab is on the Carahsoft MD COTS publisher list). Contract term Oct 1 2012 – Sep 30 2027.
- Reseller: Carahsoft is the primary public-sector aggregator.
- Authorization: “GitLab Dedicated for Government” is FedRAMP Moderate (authorized 2025-05-15, GSA-sponsored). It is single-tenant SaaS. Commercial GitLab.com SaaS and self-managed GitLab are outside that boundary. Also GovRAMP authorized (exact level unverified).
- The ATO trap: FedRAMP Moderate applies only to “GitLab Dedicated for Government.” GitLab.com and self-managed GitLab are not in scope.
What This Tool Is
GitLab is a SaaS and self-hostable platform for Git hosting, code review (merge requests), and CI/CD, with an integrated DevSecOps toolset — SAST, DAST, dependency and container scanning, and release management in one application. In this stack it is the managed choice for source control and automation, and the Carahsoft-channel counterpart to GitHub: GitHub is absent from Maryland’s Carahsoft COTS publisher list, while GitLab is on it, which makes GitLab the easier of the two to ride a Maryland COTS line. GitLab also ships a self-hostable Community Edition (CE) you can run and authorize inside your own boundary — relevant as an alternative to “GitLab Dedicated for Government” when you want to own the boundary rather than inherit one. Agencies reach for managed GitLab for the integrated pipeline and the single application — a legitimate trade, but one that turns a $0-license self-hosted option into a procurement-and-ATO exercise. This page is that exercise.
Which Maryland Vehicle
GitLab is on the Carahsoft MD COTS publisher catalog — this is the explicit contrast with GitHub, which is not. The primary Maryland path is therefore a straightforward COTS order through Carahsoft.
| Vehicle | BPO | How GitLab rides it |
|---|---|---|
| COTS 2012 | 060B2490021 | The primary path. GitLab appears on Carahsoft’s Maryland COTS publisher catalog; you issue an order against the COTS master contract and Carahsoft fulfills it. Contract term Oct 1 2012 – Sep 30 2027. |
| SEWP / GSA (federal) | Federal vehicles | Federally reachable through Carahsoft’s GSA and NASA SEWP awards rather than the Maryland COTS line — relevant only if you are buying on a federal vehicle. Confirm against the Carahsoft GitLab contracts page. |
The same publisher can be reachable through more than one Carahsoft vehicle, and which one you ride affects ceiling pricing, terms, and which approvals apply — see Maryland Master Contracts → Where Carahsoft Fits.
Resellers and Pricing Path
Carahsoft is GitLab’s primary public-sector aggregator and the reseller holding the Maryland award. You do not buy a “Carahsoft contract” — Carahsoft fulfills your order against the COTS master contract. Request a quote referencing the Maryland COTS BPO 060B2490021 so the order is priced against the statewide ceiling rather than commercial list price. GitLab is seat-licensed by tier (Free, Premium, Ultimate), with “GitLab Dedicated for Government” priced as a single-tenant managed offering; size your seat count and your tier (DevSecOps features such as the security scanners live in the higher tiers) before you ask.
Authorization and ATO
| Attribute | Value |
|---|---|
| Authorized offering | GitLab Dedicated for Government (single-tenant SaaS) |
| FedRAMP status | Authorized — Moderate, authorized 2025-05-15, GSA-sponsored |
| Marketplace ID | FR2411959145 |
| GovRAMP (StateRAMP) | Authorized — exact level unverified; confirm on the GovRAMP product list |
| Commercial / self-managed in scope? | No — commercial GitLab.com SaaS and self-managed GitLab are outside the FedRAMP boundary |
The single thing to get right for the ATO: the FedRAMP Moderate authorization attaches only to “GitLab Dedicated for Government,” the single-tenant government offering. GitLab.com (the commercial multi-tenant SaaS) and self-managed GitLab are outside that boundary — provisioning either gives you no FedRAMP authorization to inherit, and the gap will surface late in your security review. If you would rather own the boundary than inherit one, the self-hostable Community Edition (CE) can be authorized inside an environment you control (for example, AWS GovCloud), which you then authorize yourself. Confirm the current baseline and the GovRAMP level against the Marketplace and GovRAMP listings before you commit.
Functionality Gates to Verify
Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.
| Gate | GitLab-specific note |
|---|---|
| SSO (SAML/OIDC) + SCIM | Supported; confirm SCIM de-provisioning is included at your tier, not gated to Ultimate. |
| Audit logs | Available; confirm retention and streaming to your SIEM meet your records policy. |
| RBAC | Granular roles supported; map them to least-privilege before rollout. |
| Data residency / FedRAMP boundary | The GitLab Dedicated for Government single-tenant region is the boundary answer — see above. GitLab.com and self-managed are out of scope. |
| Accessibility (VPAT/ACR) | Request GitLab’s current VPAT; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement. |
| BAA / DPA | Required if any repository content or metadata could carry PII/PHI; confirm availability for the government offering. |
Procurement Steps
- Confirm the need over the OSS alternative. GitLab replaces self-hostable Git hosting (GitLab CE, Gitea, Forgejo — $0 license). Document why managed GitLab is worth the spend — that rationale is the core of the budget justification.
- Resolve the boundary question first. If your system needs Moderate for CUI, you must land on GitLab Dedicated for Government — GitLab.com and self-managed are not in the FedRAMP boundary. Decide now between inheriting that boundary and self-hosting CE in an authorized environment you control, because it changes the buy and the ATO.
- Register / confirm eMMA. Your agency and the reseller must be set up in eMMA.
- Pick the vehicle. Default to COTS 060B2490021 via Carahsoft — GitLab is on the MD COTS publisher list. (Use a federal SEWP/GSA vehicle only if you are buying federally.)
- Get a Carahsoft quote referencing the BPO, sized to your seat count and tier, for the GitLab Dedicated for Government offering if you need the FedRAMP boundary.
- Check the threshold. The order’s dollar value drives the method — purchasing card, small procurement, or BPW review. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
- Run the ATO package. Inherit the FedRAMP Moderate controls for the GitLab Dedicated for Government boundary; document the rest. Verify the current baseline first.
- Issue the order against the vehicle once approvals clear.
Sources
| Claim | Source |
|---|---|
| GitLab Dedicated for Government FedRAMP Moderate listing | FedRAMP Marketplace — FR2411959145 |
| FedRAMP Moderate authorization (2025-05-15) | GitLab — Achieves FedRAMP Moderate Authorization |
| GovRAMP authorization (level unverified) | GitLab — GovRAMP / GitLab Dedicated for Government |
| Public-sector reseller path and contract term | Carahsoft — GitLab contracts |
| GitLab on the Maryland COTS publisher catalog | Carahsoft — Maryland State Contracts |
GitLab’s FedRAMP authorization attaches only to “GitLab Dedicated for Government.” Re-verify the current Moderate baseline, the GovRAMP level, and which offerings are in boundary against the Marketplace listing before relying on any figure here.
Related Resources
- Next: set it up — GitLab implementation → — Day 0 → Day 2 configuration and gov-readiness
- SaaS Catalog — Playbook — all tools, compared in one matrix
- GitHub — the contrast: GitHub is not on a Maryland Carahsoft COTS line, GitLab is
- Maryland Master Contracts — COTS / CATS+ / Carahsoft, the vehicle this rides
- Maryland Procurement — BPW, eMMA, COMAR thresholds, the process that still binds the order
- Federal Procurement — the GSA / SEWP path GitLab’s federal motion rides
- Tools and Software → Enterprise Functionality — the gates to clear before price