Skip to content

Tenable

What this guide covers

How to actually buy Tenable for a Maryland agency — which statewide vehicle you ride, which reseller fulfills the order, the FedRAMP/ATO path, and the functionality gates to clear before you sign. Tenable is a vulnerability-management tool, so for most agencies it is bought because of the ATO: a FedRAMP or GovRAMP authorization mandates ongoing (commonly monthly) vulnerability scanning, and continuous monitoring is where Tenable lands — see Authorization to Operate (ATO). Tenable also ships several distinct government offerings at different authorization levels, so the most important decision here is matching the offering to your FIPS-199 impact level.

Who it’s for

Engineering leads, security and ISSO staff, and procurement officers at a Maryland State agency or education entity who have decided they need Tenable for vulnerability scanning and continuous monitoring (or are comparing it against the open-source scanner lineage) and need the path from “we want it” to “it’s authorized and on contract.”

Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.

Disclaimer. Not legal or procurement advice. FedRAMP/GovRAMP authorizations, contract catalogs, and BPO numbers change as awards are renewed and authorizations are re-baselined. Verify every figure below against the FedRAMP Marketplace, the Carahsoft Tenable contracts page, and the DoIT Statewide Contracts hub before relying on it. Tenable ships multiple government offerings at different FedRAMP levels and several dates/IDs below are flagged unverified — confirm the exact authorization against the official Marketplace listing before you rely on any of them.


TL;DR

  • Category: Security — vulnerability management / scanning. In practice it is an ATO continuous-monitoring (ConMon) requirement, not an optional add-on — any FedRAMP/GovRAMP ATO mandates ongoing vulnerability scanning. See ATO.
  • Maryland vehicle: COTS 2012, BPO 060B2490021, via Carahsoft (confirmed: Tenable is on the Carahsoft MD COTS publisher list). Also NASPO ValuePoint AR2472 via Carahsoft (noted as available only through ~Sep 16, 2026 — time-sensitive, verify).
  • Reseller: Carahsoft is the primary public-sector aggregator.
  • Authorization: Tenable Vulnerability Management (Government Cloud) = FedRAMP Moderate; Tenable One = Moderate (2025-04-02); Tenable Cloud Security = Moderate, Marketplace ID FR2215045786 (2025-03-26). Tenable.io is GovRAMP (StateRAMP) authorized (level unverified). Tenable Enclave Security is designed for High / IL5unverified authorization.
  • The ATO trap: Only the FedRAMP-authorized Tenable Government Cloud instance is in the FedRAMP boundary. Commercial Tenable.io is a separate environment and is NOT FedRAMP-authorized. Match the offering to your impact level.

What This Tool Is

Tenable is a vulnerability-management platform — it scans hosts, containers, cloud resources, and web apps for known vulnerabilities and misconfigurations, then tracks and prioritizes remediation. Its commercial scanning engine, Nessus, descends from the open-source scanner lineage that lives on today as OpenVAS / Greenbone; Nessus is the commercial standard, and the Government Cloud edition is the FedRAMP-authorized managed path.

For a Maryland agency, the reason to buy Tenable is usually structural, not optional. A FedRAMP or GovRAMP Authorization to Operate carries a continuous-monitoring (ConMon) obligation — ongoing, commonly monthly, authenticated vulnerability scanning of the system boundary, with results reported to the authorizing official. Tenable is one of the tools agencies stand up to satisfy that requirement. So this page is less “should we adopt observability tooling” and more “the ATO already requires scanning — here is how to put a compliant scanner on contract.” Read it alongside Authorization to Operate (ATO), which is where the ConMon obligation comes from, and Splunk, the SIEM sibling agencies often run next to it.


Which Maryland Vehicle

VehicleBPO / IDHow Tenable rides it
COTS 2012060B2490021The primary path, and confirmed: Tenable appears on Carahsoft’s Maryland COTS publisher catalog. You issue an order against the COTS master contract and Carahsoft fulfills it.
NASPO ValuePointAR2472 (via Carahsoft)A cloud/SaaS alternative reachable through Carahsoft’s NASPO contract. Time-sensitive: this NASPO listing was cited as available only through ~Sep 16, 2026 — confirm it is still live before relying on it.

The MD COTS term itself runs through roughly Sept 30 / Oct 1, 2027 (public sources vary on the exact date — note it and confirm). The same publisher can be reachable through more than one Carahsoft vehicle, and which one you ride affects ceiling pricing, terms, and which approvals apply — see Maryland Master Contracts → Where Carahsoft Fits and the Tenable entry on Carahsoft’s MD COTS publisher list.


Resellers and Pricing Path

Carahsoft is Tenable’s primary public-sector aggregator and the reseller holding the Maryland awards (Carahsoft maintains a dedicated Tenable contracts page; its federal vehicles include GSA MAS and Army ITES-SW2). You do not buy a “Carahsoft contract” — Carahsoft fulfills your order against the COTS master contract (or the NASPO addendum). Request a quote referencing the Maryland COTS BPO 060B2490021 so the order is priced against the statewide ceiling rather than commercial list price. Tenable is typically licensed by assets under management (per-asset / per-IP, by product tier), so the quote depends on the size of the boundary you must scan — size your asset inventory before you ask, since under-counting assets is the most common way these quotes come back short.


Authorization and ATO

Tenable ships several distinct government offerings authorized (or designed) at different levels. Match the offering to the FIPS-199 impact level of the system you are scanning.

OfferingFedRAMP levelMarketplace IDNotes
Tenable Vulnerability Management / Tenable.io (Government Cloud)ModerateUNVERIFIED — confirm on MarketplaceTenable’s blog dates this to 2021; a third-party aggregator dates the GovCloud listing to 2019-07-30. The exact date and Marketplace ID are unverified — confirm against the official FedRAMP Marketplace listing before relying on either.
Tenable One (exposure-management platform)Moderateconfirm on MarketplaceAuthorized 2025-04-02.
Tenable Cloud Security (former Ermetic; on AWS GovCloud)ModerateFR2215045786Authorized 2025-03-26.
Tenable Enclave SecurityDesigned for High / DoD IL5n/aUNVERIFIED authorization — this is a capability/design claim, not a confirmed marketplace ATO. Do not treat it as an authorized High/IL5 boundary without confirming a live listing.
Tenable.io — GovRAMP (StateRAMP)authorized (impact level unverified)Announced 2022-05-16. Confirm the exact GovRAMP impact level on the GovRAMP product list.

The single thing to get right for the ATO: provision the FedRAMP-authorized Tenable Government Cloud offering that matches your impact level — not commercial Tenable.io. Only the Government Cloud instance is inside the FedRAMP boundary; commercial Tenable.io is a separate environment and carries no FedRAMP authorization to inherit. An order that lands you on commercial Tenable gives you nothing to inherit for your ConMon scanning, and the gap will surface late in your security review. Confirm both the offering and its current baseline against the official Marketplace listing before you commit — several of the IDs and dates above are flagged unverified for exactly this reason.


Functionality Gates to Verify

Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.

GateTenable-specific note
SSO (SAML/OIDC) + SCIMSupported; confirm SAML SSO and SCIM de-provisioning are included at your tier, not gated to a higher plan.
Audit logsAvailable; confirm retention meets your records policy.
RBACGranular roles supported; map them to least-privilege before rollout.
Data residency / FedRAMP boundaryThe Tenable Government Cloud boundary is the residency answer — confirm you are on it, not commercial Tenable.io (see above).
Scan-result data handlingVulnerability scan output is sensitive — it maps your exact attack surface. Confirm where results are stored, who can read them, and that handling matches your data classification.
Accessibility (VPAT/ACR)Request Tenable’s current VPAT/ACR; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement.

Procurement Steps

  1. Anchor the buy to the ATO, not a wishlist. Tenable satisfies the ConMon vulnerability-scanning obligation that your FedRAMP/GovRAMP ATO already imposes. Document that the scanning is a control requirement — that framing is the spine of the budget justification, and it is stronger than “we want a scanner.”
  2. Register / confirm eMMA. Your agency and the reseller must be set up in eMMA.
  3. Pick the vehicle. Default to COTS 060B2490021; compare the NASPO ValuePoint AR2472 addendum if cloud terms suit you better — and confirm the NASPO listing is still live (cited only through ~Sep 16, 2026).
  4. Determine your impact level and offering. Decide whether you need Tenable Vulnerability Management, Tenable One, Tenable Cloud Security, or (if High/IL5) Tenable Enclave Security — and match it to your FIPS-199 level. This drives which boundary you inherit.
  5. Get a Carahsoft quote referencing the BPO, sized to your asset inventory, for the correct Government Cloud offering.
  6. Check the threshold. The order’s dollar value drives the method — purchasing card, small procurement, or BPW review. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
  7. Run the ATO package. Inherit the FedRAMP controls for the correct Tenable Government Cloud offering; wire the scanner into your ConMon cadence and document the rest.
  8. Issue the order against the vehicle once approvals clear.

Sources

ClaimSource
Tenable Cloud Security FedRAMP Moderate (FR2215045786)FedRAMP Marketplace — FR2215045786
Tenable.io FedRAMP Moderate (dated 2021)Tenable — Tenable.io achieves FedRAMP authorization
Tenable One + Cloud Security FedRAMP authorizationTenable — FedRAMP authorization for Tenable One and Cloud Security
Tenable.io StateRAMP/GovRAMP authorization (2022-05-16)Tenable — StateRAMP authorization
Tenable FedRAMP product documentationTenable — FedRAMP docs
Public-sector reseller path (GSA MAS, ITES-SW2)Carahsoft — Tenable contracts
Tenable on the Maryland COTS catalogCarahsoft — Maryland State Contracts

Tenable ships multiple government offerings at different FedRAMP levels, and several dates/IDs above are unverified (the Tenable.io GovCloud authorization date and Marketplace ID; the Tenable Enclave High/IL5 claim; the GovRAMP impact level; the NASPO AR2472 end date; the MD COTS term end). Re-verify each against the official FedRAMP Marketplace, GovRAMP product list, and Carahsoft/DoIT pages before relying on any figure here.