Maryland government acquisition
Cybersecurity and technology support for Maryland public-sector missions.
Explore a Maryland-specific acquisition path for cybersecurity, managed IT, CMMC and GRC support, cloud, continuity, and governed AI—without mixing state programs with federal contract vehicles.
How to buy
Match the requirement to the current acquisition route.
Define the mission need
Identify the buyer, authority, outcomes, security obligations, performance measures, evidence, and timeline.
Verify current records
Use eMMA and the applicable Maryland program source to confirm vendor registration, any certification status, solicitation terms, and buyer authority.
Bound the order
Confirm scope, deliverables, responsibilities, data handling, acceptance, pricing, and change control before commitment.
Maryland program terms
Keep certification, reserve programs, and tax incentives distinct.
CSB and SBR
Certified Small Business (CSB) is the certification term; Small Business Reserve (SBR) is the reserve program. Current eTrepid CSB status must be confirmed in eMMA before any public credential claim is enabled.
VSBE
The Veteran-Owned Small Business Enterprise program directs designated agencies and departments toward a program participation goal. This candidate does not assert current eTrepid VSBE certification; eMMA is the State’s verification platform for that status.
QMCS
Qualified Maryland Cybersecurity Seller status relates to the Buy Maryland Cybersecurity Tax Credit for qualifying commercial buyers; it is not a procurement set-aside.
Capability domains
Connect the acquisition to an operating outcome.
Cybersecurity and managed operations
Defined safeguards, monitoring, service management, incident support, access governance, and evidence-producing work within agreed scope.
CMMC and GRC
Scope, ownership, implementation, evidence, review, and controlled remediation without promises of certification or official outcomes.
Cloud, continuity, and governed AI
Shared-responsibility cloud support, resilient operations, and governed AI adoption with named human accountability.
Acquisition resources
Start with the requirement, acquisition context, and responsible contacts.
Use a brief consultation to establish the mission need, applicable acquisition path, handling expectations, and the right next step. Capability materials are shared only when the exact current version fits the request.
Public intake boundary
Do not submit classified information, CUI, source-selection information, passwords, vulnerabilities, assessment artifacts, or confidential architecture through a public form.
Government Solutions
Bring the requirement and acquisition context.
Use the initial discussion to establish fit, routing, handling requirements, and the appropriate next step.