Skip to content

SaaS Catalog — Procurement Playbook

What this guide covers

A worked, per-tool answer to the question the other procurement guides leave open: “I know I need GitHub / Datadog / Salesforce — now how do I actually get it, on what Maryland contract, through which reseller, and how does it pass an ATO?” The master matrix below maps each popular tool to its Maryland vehicle, reseller, FedRAMP/authorization status, and the one ATO caveat that matters. Each row links to a full page for that tool.

Who it’s for

Engineering leads, program managers, and procurement officers at a Maryland State agency or education entity who have chosen a product and need the path from decision to authorized-and-on-contract.

Part of the Procurement library. This is the execution layer. Decide what with Tools and Software, learn the process in Maryland Procurement, learn the vehicles in Maryland Master Contracts — then come here for the named-product playbook.

Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and BPO numbers change constantly — and several facts in the matrix below were volatile at the last_verified date (Datadog’s move to FedRAMP High, the exact Microsoft 365 government baseline, and whether some publishers sit on a specific Maryland line item). Verify every cell against the FedRAMP Marketplace, the relevant reseller’s Maryland contract page, and the DoIT Statewide Contracts hub before relying on it.


TL;DR

  • Know the tool? Find its row in the matrix, click through to its page.
  • Know the need? Scan the Category column — observability, SIEM, IdP, cloud, ITSM — to compare the tools that fit.
  • The recurring trap: the FedRAMP authorization almost always attaches to a dedicated government edition (GovCloud, GCC High, “for Government”), not the commercial SaaS. Buying the commercial product gives you nothing to inherit for an ATO.
  • Carahsoft is the workhorse reseller for most of these on the Maryland COTS contract (BPO 060B2490021). The big exceptions: Microsoft rides the OMNIA ICPA via SHI, Salesforce rides its own statewide contract, and GitHub has no Maryland COTS line at all.
  • Bought it? Set it up. Each tool has a Day 0 → Day 2 SaaS Setup guide — configure small, make it gov-ready, scale as you grow.

How to use the matrix

The matrix is sorted by Category, then tool, so the need-driven buyer (“I need an approved observability tool”) sees the candidates adjacent, and the tool-driven buyer (“I need Datadog”) can scan straight to the name. Every tool also has a sidebar entry under SaaS Catalog for direct access.

Vehicle legend:

Short formFull vehicleBPO
COTSCommercial Off-the-Shelf Software 2012 (via Carahsoft)060B2490021
CATS+Consulting & Technical Services+ (implementation labor)060B2490023
Salesforce 2023Salesforce Licenses statewide contract (Carahsoft)001B3600044
MS ICPAMicrosoft Licensing Packages via OMNIA Partners (SHI)001B5600254
NASPO CloudNASPO ValuePoint Cloud Solutions, MD participating addendum (Carahsoft)AR2472

Authorization legend: High / Moderate / Low = FedRAMP impact level of the authorized government edition. “GovRAMP” is the renamed StateRAMP. Levels and editions are volatile — treat the cell as a pointer to verify, not a guarantee.


The Master Matrix

ToolCategoryMaryland vehicleReseller(s)FedRAMP (gov edition)The one ATO caveat
Microsoft 365 & AzureCloud platformMS ICPA 001B5600254; also COTSSHI (OMNIA)Azure Gov High; M365 GCC/GCC High (verify level)Only GCC High meets ITAR/CUI — commercial/GCC-Moderate does not
Amazon Web ServicesCloud platformNASPO Cloud AR2472 (confirm vs. COTS)Carahsoft (DLT)GovCloud High; commercial regions ModerateGovCloud is a separate partition — separate accounts/credentials
Google WorkspaceCloud platformNASPO Cloud AR2472; also COTSCarahsoftWorkspace High; GCP HighGCP High coverage is per-service + needs Assured Workloads
SalesforceCRM & platformSalesforce 2023 001B3600044CarahsoftGovernment Cloud Plus = High (older Gov Cloud = Moderate)Pick Government Cloud Plus for High — the older edition is Moderate
SnowflakeData & analyticsCOTS 060B2490021CarahsoftHigh (AWS GovCloud); Moderate (other)High is AWS-GovCloud-only; Moderate is a different boundary
DatabricksData & analyticsCOTS (unverified — confirm)CarahsoftHigh (AWS GovCloud); IL-5 (Azure Gov)High is GovCloud/Azure-Gov only; DoD vs Community offerings are separate
TableauData & analyticsCOTS 060B2490021CarahsoftModerate (Tableau Government Cloud)Classic Tableau Gov Cloud is Moderate, not High (High = Tableau Next)
AtlassianDevOps & collaborationCOTS 060B2490021CarahsoftModerate (Atlassian Government Cloud)Covers Jira/Confluence/JSM only; confirm Jira Align is in scope
GitHubDevOps & source controlNo MD COTS line — Microsoft/SHI channel (verify)SHI / Microsoft channelLi-SaaS (Low); Moderate pursued, not grantedGitHub is not FedRAMP Moderate — don’t represent it as such
GitLabDevOps & source controlCOTS 060B2490021CarahsoftModerate (GitLab Dedicated for Government)Only Dedicated for Government is in boundary — not GitLab.com / self-managed
OktaIdentity (IdP / SSO)NASPO Cloud AR2472 / DoIT Okta ICPACarahsoft (named NASPO reseller)High (Okta for Government High / GHC)Use the GHC boundary — the commercial tenant is a different one
ServiceNowIT service managementCOTS 060B2490021 (via Carahsoft — verify)Carahsoft / SHIHigh (Government Community Cloud)Order must specify the GCC environment, not commercial
DatadogObservabilityCOTS 060B2490021CarahsoftHigh (was Moderate, ~May 2026)Only US1-FED region is in boundary — commercial regions are not
SplunkSecurity — SIEM / logCOTS 060B2490021CarahsoftHigh and Moderate (two separate listings)Pick the right listing — Moderate and High are separate boundaries
CrowdStrikeSecurity — endpoint (EDR)COTS 060B2490021CarahsoftHigh (Gov-1); IL-4/IL-5 (Gov-2)FedRAMP High and DoD IL-5 are separate environments
TenableSecurity — vuln managementCOTS 060B2490021CarahsoftModerate (Tenable Government Cloud)Vuln scanning is an ATO ConMon requirement; only the Gov Cloud is in boundary
HashiCorpInfrastructure & secretsCOTS / NASPO (disputed — confirm)CarahsoftNone — no managed gov SaaSNo FedRAMP SaaS to inherit — self-host Terraform/Vault & authorize it yourself

New to authorization? Read the ATO & FedRAMP explainer — what an ATO is, the RMF lifecycle, FedRAMP vs GovRAMP, Maryland’s rules, and the continuous-monitoring obligations that outlast the purchase. Every “ATO caveat” above is grounded there.

Already bought it? Once a tool is on contract, jump to the SaaS Setup playbook to stand it up small, make it gov-ready, and scale as the team grows — each tool has a Day 0 → Day 2 guide.


The pattern every page follows

Each tool page answers the same seven questions in the same order, so you can jump to the same section across products:

  1. What This Tool Is — category and what it does, plus the OSS alternative it replaces.
  2. Which Maryland Vehicle — the contract you ride, with the BPO number.
  3. Resellers and Pricing Path — who fulfills the order and how it’s priced.
  4. Authorization and ATO — the government edition, its FedRAMP level, and what you inherit.
  5. Functionality Gates to Verify — SSO/SCIM, audit logs, VPAT/ACR, residency, for that tool.
  6. Procurement Steps — the ordered path from need to issued order.
  7. Sources — every claim, linked to its authority.

Three rules that apply to every tool

  1. Buy the government edition, not the commercial one. The FedRAMP boundary — and therefore everything you inherit for the ATO — lives in the dedicated gov offering (GovCloud, GCC High, “for Government”). This is the most common and most expensive mistake.
  2. A master contract pre-competes the vendor, not the approval. Riding COTS or NASPO does not waive BPW review thresholds or MBE/SBR/VSBE goals. A large order off a master contract can still need Board of Public Works approval.
  3. Clear the functionality gates before price. SSO/SCIM, audit logs, accessibility (VPAT/ACR, Maryland NVA), and data residency are pass/fail. The cheapest option that fails one is not an option — see Tools and Software → Enterprise Functionality.