Snowflake
What this guide covers
How to actually buy Snowflake for a Maryland agency — which statewide vehicle you ride, which reseller fulfills the order, the FedRAMP/ATO path (and which cloud/region the impact level lives in), and the functionality gates to clear before you sign.
Who it’s for
Engineering leads, data and analytics staff, and procurement officers at a Maryland State agency or education entity who have decided they need Snowflake (or are comparing it against a self-hosted analytical database) and need the path from “we want it” to “it’s authorized and on contract.”
Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.
Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and BPO numbers change as awards are renewed and authorizations are re-baselined. Verify every figure below against the FedRAMP Marketplace, the Carahsoft Maryland State Contracts page, and the DoIT Statewide Contracts hub before relying on it.
TL;DR
- Category: Data and analytics — the data cloud (warehouse / lakehouse).
- Maryland vehicle: COTS 2012, BPO 060B2490021, via Carahsoft (Snowflake is on the Carahsoft MD COTS publisher list); also NASPO ValuePoint.
- Reseller: Carahsoft is the primary public-sector aggregator.
- Authorization: “The Data Cloud on AWS GovCloud (High)” is FedRAMP High (authorized 2023-12-11). Snowflake also holds FedRAMP Moderate on AWS US-East and Azure Government (since 2020), plus TX-RAMP and GovRAMP (Moderate and High).
- The ATO trap: FedRAMP High is AWS-GovCloud-only; the Moderate boundary is a different deployment (AWS US-East / Azure Government). Pick the region/cloud matching your required impact level — they are not interchangeable.
What This Tool Is
Snowflake is a SaaS data cloud — a managed warehouse/lakehouse that separates storage from compute and scales to cloud-scale analytics, data sharing, and ML workloads. In this stack it is the commercial alternative to a self-hosted analytical database. For smaller analytical workloads the self-hostable path is PostgreSQL (plus pgvector) — see Tools and Software → Data; Snowflake is for cloud-scale analytics beyond what a single Postgres instance is meant to carry. Agencies reach for it when their data volume and concurrency outgrow that OSS path, which turns a $0-license choice into a procurement-and-ATO exercise. This page is that exercise.
Which Maryland Vehicle
| Vehicle | BPO | How Snowflake rides it |
|---|---|---|
| COTS 2012 | 060B2490021 | The primary path. Snowflake appears on Carahsoft’s Maryland COTS publisher catalog; you issue an order against the COTS master contract and Carahsoft fulfills it. |
| NASPO ValuePoint Cloud Solutions | Maryland participating addendum (Carahsoft) | A cloud/SaaS alternative the State extended into Maryland. Compare ceiling pricing against COTS before choosing. |
The same publisher can be reachable through more than one Carahsoft vehicle, and which one you ride affects ceiling pricing, terms, and which approvals apply — see Maryland Master Contracts → Where Carahsoft Fits. Snowflake is on the reproduced publisher list in Software Publishers Under Carahsoft’s MD COTS.
Resellers and Pricing Path
Carahsoft is Snowflake’s primary public-sector aggregator and the reseller holding the Maryland awards. You do not buy a “Carahsoft contract” — Carahsoft fulfills your order against the COTS master contract (or the NASPO addendum). Request a quote referencing the Maryland COTS BPO 060B2490021 so the order is priced against the statewide ceiling rather than commercial list price. Snowflake is consumption-metered (compute credits plus storage), so the quote depends on your query volume and data footprint — size both before you ask, and revisit it, because consumption-based bills drift upward.
Authorization and ATO
| Attribute | Value |
|---|---|
| Authorized offering (High) | The Data Cloud on AWS GovCloud (High) — AWS GovCloud (US) West and East |
| FedRAMP status | High (authorized 2023-12-11) |
| Marketplace ID | FR2308159208 |
| Moderate boundary | FedRAMP Moderate on AWS US-East and Azure Government (since 2020) — a different deployment |
| Other authorizations | TX-RAMP and GovRAMP (Moderate and High) |
The single thing to get right for the ATO: match the region and cloud to your required impact level. FedRAMP High is AWS GovCloud only (US-West and US-East); the FedRAMP Moderate boundary is a different deployment on AWS US-East or Azure Government. They are not interchangeable — provisioning a Moderate region gives you nothing to inherit at High, and the gap will surface late in your security review. Confirm the impact level your system’s data classification requires before you provision, and order into the matching region/cloud.
Functionality Gates to Verify
Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.
| Gate | Snowflake-specific note |
|---|---|
| SSO (SAML/OIDC) + SCIM | Supported; confirm SCIM de-provisioning is included at your edition, not gated to a higher tier. |
| Audit logs | Access history and query history available; confirm retention meets your records policy. |
| RBAC | Role-based access control is native and granular; map to least-privilege before rollout. |
| Data residency / FedRAMP boundary | The AWS GovCloud (High) deployment is the residency answer for High — see above. |
| Accessibility (VPAT/ACR) | Request Snowflake’s current VPAT; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement. |
| BAA / DPA | Required if any stored data could carry PII/PHI; confirm availability for the chosen government deployment. |
Procurement Steps
- Confirm the need over the OSS alternative. For smaller analytical workloads PostgreSQL (+ pgvector) is the self-hostable $0-license path — see Tools and Software → Data. Document why cloud-scale Snowflake is worth the spend — that rationale is the core of the budget justification.
- Register / confirm eMMA. Your agency and the reseller must be set up in eMMA.
- Pick the vehicle. Default to COTS 060B2490021; compare the NASPO Cloud addendum if cloud terms suit you better.
- Get a Carahsoft quote referencing the BPO, sized to your consumption and storage, for the region/cloud matching your impact level (AWS GovCloud for High).
- Check the threshold. The order’s dollar value drives the method — purchasing card, small procurement, or BPW review. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
- Run the ATO package. Inherit the FedRAMP controls for the matching boundary (High = AWS GovCloud; Moderate = AWS US-East / Azure Government); document the rest. Confirm the impact level first.
- Issue the order against the vehicle once approvals clear.
Sources
| Claim | Source |
|---|---|
| Snowflake “Data Cloud on AWS GovCloud (High)” FedRAMP High listing | FedRAMP Marketplace — FR2308159208 |
| FedRAMP High on AWS GovCloud US-West and US-East | Snowflake — FedRAMP High on AWS GovCloud announcement |
| Compliance scope (Moderate, High, TX-RAMP, GovRAMP, regions) | Snowflake docs — FedRAMP |
| Snowflake on the Maryland COTS catalog | Carahsoft — Maryland State Contracts |
Snowflake’s FedRAMP scope spans multiple clouds and impact levels. Re-verify which region/cloud carries which impact level against the Marketplace listing and Snowflake’s compliance docs before relying on any figure here.
Related Resources
- SaaS Catalog — Playbook — all tools, compared in one matrix
- Maryland Master Contracts — COTS / CATS+ / Carahsoft, the vehicle this rides
- Maryland Procurement — BPW, eMMA, COMAR thresholds, the process that still binds the order
- Federal Procurement — the federal analog (FAR, GSA Schedules, SAM.gov)
- Tools and Software → Data — Snowflake vs. the self-hosted Postgres path it replaces
- Tools and Software → Enterprise Functionality — the gates to clear before price