Data Sources & Methodology
FedCatalog is designed around a simple rule: show what the public evidence supports and label everything else clearly.
FedCatalog doesn’t rank vendors, sell placement, or decide what software is “best.” It organizes public information so buyers and sellers can understand the path from authorization to procurement.
Nothing here is edited by vendors. Authorization, agency records and federal spending data come from public government sources; procurement links open searches on the marketplaces and vehicles themselves.
Independence is shown structurally rather than claimed: no sponsored ranking, no “best vendors” lists, no preferred marketplace, every important fact linked to its source, a date on the data, this methodology in the open, corrections encouraged, and the builder’s real name and background on the About page.
FedRAMP Marketplace
Source: the FedRAMP Marketplace public data published by GSA (fedramp.gov/marketplace), which FedRAMP republishes as machine-readable files updated daily.
Imported: vendor, offering name, status (Authorized, Ready, In Process), impact level, authorization path and dates, deployment and service model, business categories, agency authorization and reuse records, description, website, assessor, published sales contact, and which offerings leverage which authorized platforms.
Refresh: daily. Each page shows the date of the data it was built from.
Meaning: an authorization belongs to the specific offering and security boundary listed, not to the vendor or to the vendor’s other products. Agency authorization records show that an agency issued or reused an authorization; they do not by themselves show that the agency purchased or deployed the product.
Runs on: FedRAMP records which authorized infrastructure platform an offering leverages. FedCatalog shows that relationship as “runs on.” Where a platform is only named in the offering’s title and no relationship is on record, it is shown with a dashed underline and labeled as such. Running on a cloud is not the same as being sold in that cloud’s marketplace.
DoD Cyber Exchange
Source: the “Current Authorized CSOs” table on the DoD Cyber Exchange (public.cyber.mil).
Meaning: FedCatalog preserves the exact DoD status string: Provisional Authorization, Provisional Authorization to Connect (PA-C), IATT – Not Authorized for Operational Use, or Suspended. These are never rewritten into a FedCatalog score. A Provisional Authorization is not an agency ATO. Where the listed expiration date has passed, the site says so and asks you to verify on the DoD page. A DoD listing may describe a different offering or boundary from the vendor’s FedRAMP listing; FedCatalog links DoD rows to vendors, not to specific FedRAMP offerings.
GSA OneGov
Source: GSA’s IT Vendor Management Office list of current OneGov agreements (itvmo.gsa.gov/onegov), curated by hand and checked against GSA’s feed for new agreements.
Meaning: discount, expiry, vehicle, eligibility and included products are shown as GSA publishes them. Agreements are linked to vendors only where the match is clear. Ordering details are behind a government login; agencies still follow their ordinary FAR 8.4 ordering procedures, and pricing and eligibility should be confirmed with GSA. Expiry dates matter and are shown.
USAspending
Source: the USAspending.gov API, queried live when a vendor page opens, for federal prime contract records (award types A–D) whose recipient name or award description mentions the vendor or, for short or ambiguous names, its offering names. The search terms used are printed on the page.
Meaning: these figures are an observed floor, not a vendor revenue estimate. Most software is bought through resellers whose award descriptions may not name the software vendor; many descriptions are generic; name matching can undercount or occasionally match the wrong thing; and obligations are not bookings or revenue. FedCatalog therefore shows, separately: obligations on awards that mention the vendor; the portion paid directly to the vendor entity; who received the money (vendor direct versus reseller or prime); and the number of buying departments, next to the number of FedRAMP authorization records, because approved is not the same as purchased.
GSA eLibrary, NASA SEWP, Section 508 ACR Repository, SAM.gov
Until records from these sources are joined directly to FedCatalog data, the links on product and vendor pages open searches or lookup pages. They do not mean FedCatalog has confirmed that a product is available on a vehicle or has an accessibility conformance report.
Procurement links
Each offering’s “Buying paths” section shows, in order: confirmed paths (the GSA OneGov agreement, exact marketplace listings matched to this FedRAMP offering, and the vendor’s government sales page from the FedRAMP record); the vendor’s other marketplace listings and seller pages, which are the vendor’s own but not matched to a specific boundary; and searches for the vendor on marketplaces and vehicles where no listing is on file yet. A listing is recorded only after opening it on the marketplace and confirming the publisher, or after a vendor supplies it and FedCatalog reviews it (labeled vendor-supplied); it is tied to a FedRAMP offering only when the listing clearly serves that boundary, such as a GovCloud listing. Where nothing is on file the page says “exact listing not yet verified.” Commercial and government editions can differ; confirm the edition and boundary on the listing itself.
Cloud marketplaces
AWS Marketplace, Azure Marketplace and Google Cloud Marketplace links open a search for the vendor on each marketplace. Listing availability, editions, terms and private offers are confirmed there.
Corrections
Anyone can submit a correction. Public-source facts are corrected by re-checking the source. Vendor-supplied links are reviewed before publication.
Editorial policy
- No pay-to-rank. No vendor is placed or ranked because it sponsors the site.
- No star ratings, reviews, or any “federal readiness” score.
- Facts come from public sources, not vendor claims.
- Comparisons show factual differences and never declare a winner.
- Corrections are welcomed and acknowledged.
FedCatalog is written and maintained by Mark Flournoy.