SaaS Catalog — Procurement Playbook
What this guide covers
A worked, per-tool answer to the question the other procurement guides leave open: “I know I need GitHub / Datadog / Salesforce — now how do I actually get it, on what Maryland contract, through which reseller, and how does it pass an ATO?” The master matrix below maps each popular tool to its Maryland vehicle, reseller, FedRAMP/authorization status, and the one ATO caveat that matters. Each row links to a full page for that tool.
Who it’s for
Engineering leads, program managers, and procurement officers at a Maryland State agency or education entity who have chosen a product and need the path from decision to authorized-and-on-contract.
Part of the Procurement library. This is the execution layer. Decide what with Tools and Software, learn the process in Maryland Procurement, learn the vehicles in Maryland Master Contracts — then come here for the named-product playbook.
Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and BPO numbers change constantly — and several facts in the matrix below were volatile at the
last_verifieddate (Datadog’s move to FedRAMP High, the exact Microsoft 365 government baseline, and whether some publishers sit on a specific Maryland line item). Verify every cell against the FedRAMP Marketplace, the relevant reseller’s Maryland contract page, and the DoIT Statewide Contracts hub before relying on it.
TL;DR
- Know the tool? Find its row in the matrix, click through to its page.
- Know the need? Scan the Category column — observability, SIEM, IdP, cloud, ITSM — to compare the tools that fit.
- The recurring trap: the FedRAMP authorization almost always attaches to a dedicated government edition (GovCloud, GCC High, “for Government”), not the commercial SaaS. Buying the commercial product gives you nothing to inherit for an ATO.
- Carahsoft is the workhorse reseller for most of these on the Maryland COTS contract (BPO 060B2490021). The big exceptions: Microsoft rides the OMNIA ICPA via SHI, Salesforce rides its own statewide contract, and GitHub has no Maryland COTS line at all.
- Bought it? Set it up. Each tool has a Day 0 → Day 2 SaaS Setup guide — configure small, make it gov-ready, scale as you grow.
How to use the matrix
The matrix is sorted by Category, then tool, so the need-driven buyer (“I need an approved observability tool”) sees the candidates adjacent, and the tool-driven buyer (“I need Datadog”) can scan straight to the name. Every tool also has a sidebar entry under SaaS Catalog for direct access.
Vehicle legend:
| Short form | Full vehicle | BPO |
|---|---|---|
| COTS | Commercial Off-the-Shelf Software 2012 (via Carahsoft) | 060B2490021 |
| CATS+ | Consulting & Technical Services+ (implementation labor) | 060B2490023 |
| Salesforce 2023 | Salesforce Licenses statewide contract (Carahsoft) | 001B3600044 |
| MS ICPA | Microsoft Licensing Packages via OMNIA Partners (SHI) | 001B5600254 |
| NASPO Cloud | NASPO ValuePoint Cloud Solutions, MD participating addendum (Carahsoft) | AR2472 |
Authorization legend: High / Moderate / Low = FedRAMP impact level of the authorized government edition. “GovRAMP” is the renamed StateRAMP. Levels and editions are volatile — treat the cell as a pointer to verify, not a guarantee.
The Master Matrix
| Tool | Category | Maryland vehicle | Reseller(s) | FedRAMP (gov edition) | The one ATO caveat |
|---|---|---|---|---|---|
| Microsoft 365 & Azure | Cloud platform | MS ICPA 001B5600254; also COTS | SHI (OMNIA) | Azure Gov High; M365 GCC/GCC High (verify level) | Only GCC High meets ITAR/CUI — commercial/GCC-Moderate does not |
| Amazon Web Services | Cloud platform | NASPO Cloud AR2472 (confirm vs. COTS) | Carahsoft (DLT) | GovCloud High; commercial regions Moderate | GovCloud is a separate partition — separate accounts/credentials |
| Google Workspace | Cloud platform | NASPO Cloud AR2472; also COTS | Carahsoft | Workspace High; GCP High | GCP High coverage is per-service + needs Assured Workloads |
| Salesforce | CRM & platform | Salesforce 2023 001B3600044 | Carahsoft | Government Cloud Plus = High (older Gov Cloud = Moderate) | Pick Government Cloud Plus for High — the older edition is Moderate |
| Snowflake | Data & analytics | COTS 060B2490021 | Carahsoft | High (AWS GovCloud); Moderate (other) | High is AWS-GovCloud-only; Moderate is a different boundary |
| Databricks | Data & analytics | COTS (unverified — confirm) | Carahsoft | High (AWS GovCloud); IL-5 (Azure Gov) | High is GovCloud/Azure-Gov only; DoD vs Community offerings are separate |
| Tableau | Data & analytics | COTS 060B2490021 | Carahsoft | Moderate (Tableau Government Cloud) | Classic Tableau Gov Cloud is Moderate, not High (High = Tableau Next) |
| Atlassian | DevOps & collaboration | COTS 060B2490021 | Carahsoft | Moderate (Atlassian Government Cloud) | Covers Jira/Confluence/JSM only; confirm Jira Align is in scope |
| GitHub | DevOps & source control | No MD COTS line — Microsoft/SHI channel (verify) | SHI / Microsoft channel | Li-SaaS (Low); Moderate pursued, not granted | GitHub is not FedRAMP Moderate — don’t represent it as such |
| GitLab | DevOps & source control | COTS 060B2490021 | Carahsoft | Moderate (GitLab Dedicated for Government) | Only Dedicated for Government is in boundary — not GitLab.com / self-managed |
| Okta | Identity (IdP / SSO) | NASPO Cloud AR2472 / DoIT Okta ICPA | Carahsoft (named NASPO reseller) | High (Okta for Government High / GHC) | Use the GHC boundary — the commercial tenant is a different one |
| ServiceNow | IT service management | COTS 060B2490021 (via Carahsoft — verify) | Carahsoft / SHI | High (Government Community Cloud) | Order must specify the GCC environment, not commercial |
| Datadog | Observability | COTS 060B2490021 | Carahsoft | High (was Moderate, ~May 2026) | Only US1-FED region is in boundary — commercial regions are not |
| Splunk | Security — SIEM / log | COTS 060B2490021 | Carahsoft | High and Moderate (two separate listings) | Pick the right listing — Moderate and High are separate boundaries |
| CrowdStrike | Security — endpoint (EDR) | COTS 060B2490021 | Carahsoft | High (Gov-1); IL-4/IL-5 (Gov-2) | FedRAMP High and DoD IL-5 are separate environments |
| Tenable | Security — vuln management | COTS 060B2490021 | Carahsoft | Moderate (Tenable Government Cloud) | Vuln scanning is an ATO ConMon requirement; only the Gov Cloud is in boundary |
| HashiCorp | Infrastructure & secrets | COTS / NASPO (disputed — confirm) | Carahsoft | None — no managed gov SaaS | No FedRAMP SaaS to inherit — self-host Terraform/Vault & authorize it yourself |
New to authorization? Read the ATO & FedRAMP explainer — what an ATO is, the RMF lifecycle, FedRAMP vs GovRAMP, Maryland’s rules, and the continuous-monitoring obligations that outlast the purchase. Every “ATO caveat” above is grounded there.
Already bought it? Once a tool is on contract, jump to the SaaS Setup playbook to stand it up small, make it gov-ready, and scale as the team grows — each tool has a Day 0 → Day 2 guide.
The pattern every page follows
Each tool page answers the same seven questions in the same order, so you can jump to the same section across products:
- What This Tool Is — category and what it does, plus the OSS alternative it replaces.
- Which Maryland Vehicle — the contract you ride, with the BPO number.
- Resellers and Pricing Path — who fulfills the order and how it’s priced.
- Authorization and ATO — the government edition, its FedRAMP level, and what you inherit.
- Functionality Gates to Verify — SSO/SCIM, audit logs, VPAT/ACR, residency, for that tool.
- Procurement Steps — the ordered path from need to issued order.
- Sources — every claim, linked to its authority.
Three rules that apply to every tool
- Buy the government edition, not the commercial one. The FedRAMP boundary — and therefore everything you inherit for the ATO — lives in the dedicated gov offering (GovCloud, GCC High, “for Government”). This is the most common and most expensive mistake.
- A master contract pre-competes the vendor, not the approval. Riding COTS or NASPO does not waive BPW review thresholds or MBE/SBR/VSBE goals. A large order off a master contract can still need Board of Public Works approval.
- Clear the functionality gates before price. SSO/SCIM, audit logs, accessibility (VPAT/ACR, Maryland NVA), and data residency are pass/fail. The cheapest option that fails one is not an option — see Tools and Software → Enterprise Functionality.
Related Resources
- ATO & FedRAMP explainer — what authorization actually means, and the continuous monitoring that outlasts the buy
- SaaS Setup — Implementation Playbook — Day 0 → Day 2 configuration once a tool is on contract
- Maryland Master Contracts — the vehicles (COTS, CATS+, Salesforce 2023, OMNIA ICPA) and the Carahsoft catalog
- Maryland Procurement — BPW, eMMA, COMAR Title 21, thresholds
- Tools and Software — deciding what to buy, and the functionality gates
- Federal Procurement — the federal analog (FAR, GSA Schedules, SAM.gov)
- Procurement — Overview — the full library