Skip to content

HashiCorp

What this guide covers

How to actually buy HashiCorpTerraform (infrastructure-as-code) and Vault (secrets management) — for a Maryland agency, which vehicle reaches it, and why the ATO path is fundamentally different from the SaaS pages in this catalog: there is no HashiCorp-managed FedRAMP-authorized SaaS to inherit. You self-host inside your own authorized boundary and authorize it yourself.

Who it’s for

Engineering leads, platform/DevOps staff, and procurement officers at a Maryland State agency or education entity who have decided they need Terraform and/or Vault and need the path from “we want it” to “it’s authorized and on contract” — including the realization that the authorization is yours to build, not yours to buy.

Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.

Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and vendor vehicle lists change as awards are renewed and authorizations are re-baselined — and HashiCorp is now IBM-owned, which may move all of the below. Verify every figure against the FedRAMP Marketplace, the Carahsoft HashiCorp contracts page, and the DoIT Statewide Contracts hub before relying on it. The Maryland vehicle for HashiCorp is disputed across two Carahsoft pages (see below) and must be confirmed with Carahsoft / DoIT.


TL;DR

  • Category: Infrastructure automation & secrets — Terraform (infrastructure-as-code) and Vault (secrets management). Now IBM-owned.
  • Maryland vehicle: Disputed — confirm before relying on it. Carahsoft’s Maryland COTS catalog page lists HashiCorp as an available manufacturer, but Carahsoft’s HashiCorp contracts page reaches state/local primarily via NASPO ValuePoint (AR2472) and OMNIA Partners (R240303) and does not list the Maryland COTS contract. The two pages disagree — confirm the actual Maryland vehicle with Carahsoft / DoIT.
  • Reseller: Carahsoft.
  • Authorization: No FedRAMP-authorized HashiCorp-managed SaaS. HCP (HashiCorp Cloud Platform) FedRAMP is roadmap/planned, not achieved — no Authorized or In-Process Marketplace listing found for Terraform, Vault, or HCP. Vault holds FIPS 140-2 / 140-3 cryptographic module validation (not a FedRAMP ATO).
  • The ATO trap: there is no HashiCorp-managed FedRAMP SaaS to inherit. For an ATO you self-host Terraform/Vault inside your own authorized boundary (e.g., AWS GovCloud) and authorize it yourself. You do not “buy” a HashiCorp ATO.

What This Tool Is

HashiCorp publishes the infrastructure-automation and secrets tooling that underpins most modern platform engineering: Terraform declares and provisions infrastructure as code, and Vault stores and brokers secrets, certificates, and encryption keys. The company is now IBM-owned, which may shift its public-sector vehicles, FedRAMP roadmap, and product packaging — re-verify everything here against current sources. On open-source licensing: Terraform is now BSL-licensed, and the MPL-licensed community fork is OpenTofu; Vault remains the secrets standard — see Tools and Software → Infrastructure & Delivery. Unlike the managed-SaaS tools elsewhere in this catalog, HashiCorp’s products are usually run inside your own boundary, which is exactly why its ATO story is different — there is no vendor-managed authorized region to point at.


Which Maryland Vehicle

The Maryland vehicle for HashiCorp is disputed across two Carahsoft pages, and this page does not assert a single settled COTS line. Present both, and confirm with Carahsoft / DoIT before quoting.

Source / vehicleWhat it saysStatus
Carahsoft Maryland COTS catalog pageLists HashiCorp as an available manufacturer under the MD COTS publisher catalog (BPO 060B2490021).Needs confirmation — see the discrepancy below.
Carahsoft HashiCorp contracts pageReaches state & local primarily via NASPO ValuePoint (AR2472) and OMNIA Partners (R240303); does not list the Maryland COTS contract among HashiCorp’s vehicles.Listed on the HashiCorp contracts page.

The discrepancy, stated plainly: Carahsoft’s Maryland COTS catalog page does show HashiCorp as an available manufacturer, but Carahsoft’s HashiCorp-specific contracts page routes state/local buyers through NASPO ValuePoint (AR2472) and OMNIA Partners (R240303) and does not list a Maryland COTS line. These two Carahsoft pages disagree. Do not treat the MD COTS line as settled — confirm the actual vehicle with Carahsoft and DoIT, and in the meantime treat NASPO ValuePoint and OMNIA Partners as the documented state/local routes. The same publisher can be reachable through more than one vehicle, and which one you ride affects ceiling pricing, terms, and approvals — see Maryland Master Contracts → Where Carahsoft Fits.


Resellers and Pricing Path

Carahsoft is HashiCorp’s public-sector aggregator. Because the Maryland vehicle is unsettled, request the quote referencing whichever vehicle Carahsoft / DoIT confirm applies — the disputed MD COTS line (BPO 060B2490021) if confirmed, otherwise the documented NASPO ValuePoint (AR2472) or OMNIA Partners (R240303) cooperative routes. HashiCorp’s enterprise products are licensed per workload/node/cluster and by tier (for example, Vault Enterprise features such as namespaces and HSM/FIPS support sit in the higher tiers); size your deployment and required enterprise features before you ask. Do not assume a single ceiling price applies until the vehicle is confirmed.


Authorization and ATO

AttributeValue
HashiCorp-managed FedRAMP SaaSNone found — no Authorized or In-Process Marketplace listing for Terraform, Vault, or HCP
HCP (HashiCorp Cloud Platform) FedRAMPRoadmap / planned — not achieved. Re-verify, especially given the IBM acquisition
Vault cryptographic validationFIPS 140-2 / 140-3 validated cryptographic modulethis is not a FedRAMP ATO
GovRAMP (StateRAMP)Not confirmed — verify on the GovRAMP product list
Realistic authorized deploymentSelf-host Terraform/Vault inside your own FedRAMP boundary (e.g., AWS GovCloud) and authorize it yourself

The single thing to get right for the ATO — and the whole point of this page: there is no HashiCorp-managed FedRAMP-authorized SaaS to inherit. HCP FedRAMP is a roadmap item, not an achieved authorization, and Vault’s FIPS 140-2 / 140-3 cryptographic module validation is a different thing from a FedRAMP ATO — do not present one as the other. Terraform and Vault are nonetheless widely run inside customers’ own FedRAMP boundaries (self-hosted, often on AWS GovCloud). For an ATO you therefore self-host inside an authorized boundary you control and authorize it yourself — you inherit the underlying IaaS authorization and own the HashiCorp layer. This is fundamentally different from the SaaS pages in this catalog: you do not “buy” a HashiCorp ATO. Re-verify all of this given the IBM acquisition before you commit.


Functionality Gates to Verify

Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.

GateHashiCorp-specific note
SSO (SAML/OIDC) + SCIMSupported (Vault/Terraform Enterprise auth methods); confirm SCIM de-provisioning and that SSO is included at your licensed tier.
Audit logsVault has detailed audit devices; confirm log shipping to your SIEM and retention meet your records policy.
RBACGranular policy-based access (Vault policies, Terraform RBAC) supported; map to least-privilege before rollout.
Data residency / FedRAMP boundaryThere is no vendor-managed FedRAMP region — residency is whatever boundary you self-host into (e.g., AWS GovCloud). See above.
Cryptographic validationVault holds FIPS 140-2 / 140-3 module validation — confirm the validated build/edition is the one you deploy. Not a substitute for an ATO.
Accessibility (VPAT/ACR)Request HashiCorp’s current VPAT; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement.
BAA / DPARequired if any brokered secret or state file could carry PII/PHI; confirm availability for your deployment model.

Procurement Steps

  1. Confirm the need over the OSS alternative. Terraform’s open-source fork is OpenTofu (MPL), and both Terraform CE and Vault CE are self-hostable at $0 license. Document why the enterprise license is worth the spend — that rationale is the core of the budget justification.
  2. Accept the ATO model up front. There is no HashiCorp-managed FedRAMP SaaS to inherit. Plan to self-host inside your own authorized boundary (e.g., AWS GovCloud) and authorize it yourself; this shapes both the buy and the security package.
  3. Confirm the actual Maryland vehicle. The MD COTS line is disputed — Carahsoft’s two pages disagree. Confirm with Carahsoft / DoIT whether HashiCorp rides MD COTS (060B2490021) or the documented NASPO ValuePoint (AR2472) / OMNIA Partners (R240303) cooperative routes. Do not assume a COTS BPO.
  4. Register / confirm eMMA. Your agency and the awarded reseller must be set up in eMMA.
  5. Get a Carahsoft quote referencing the confirmed vehicle, sized to your deployment and required enterprise features.
  6. Check the threshold. The order’s dollar value drives the method — purchasing card, small procurement, or BPW review. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
  7. Run the ATO package. Inherit the IaaS boundary’s controls (e.g., AWS GovCloud) and authorize the self-hosted Terraform/Vault layer yourself. Confirm Vault’s FIPS-validated build if cryptographic validation is in scope.
  8. Issue the order against the confirmed vehicle once approvals clear.

Sources

ClaimSource
State/local vehicles NASPO ValuePoint (AR2472) and OMNIA Partners (R240303); MD COTS not listed on HashiCorp pageCarahsoft — HashiCorp contracts
HashiCorp listed as a manufacturer on the Maryland COTS catalog (disputed vs. above)Carahsoft — Maryland State Contracts
Vault compliance / cryptographic validationHashiCorp — Vault compliance
Vault FIPS 140-3 validationHashiCorp — Vault and FIPS 140-3
HCP FedRAMP on the roadmap (planned, not achieved)TechTarget — HashiCorp CTO on AI strategy, Ansible tie-ins, FedRAMP

HashiCorp has no FedRAMP-authorized managed SaaS to inherit, and its Maryland vehicle is disputed across two Carahsoft pages. Both facts are load-bearing for this buy. Re-verify the vehicle, the FedRAMP roadmap, and HCP’s status — especially given the IBM acquisition — before relying on any figure here.