Hosting and Security the Buyers Accept
NARMD runs on a secure cloud that supports government. What mattered to the buyers was the vendor behind the hosting, one their offices already trusted, after they had rejected the other platforms NAR evaluated.
NAR's government customer ran its own continuous security scans against the portal, and findings were fixed as they came in. Security updates went on within 48 hours of release, usually within 24, and every module was brought current monthly. Card data never touched the portal. Payment ran through Braintree hosted fields, which kept NARMD in the simplest PCI scope.
How a Government Order Gets Placed
Government purchasing separates authority on purpose. The person who builds an order is not the person who can commit the money. NARMD matches that chain with three roles.
- A group administrator, usually the office's senior buyer, controls who is on the account and what each person can see and spend.
- An order creator assembles the cart and submits it as a purchase request. They never touch payment.
- An order approver reviews the request line by line, approves, adjusts, or rejects each item with a note, then releases the order or sends it back. Offices with a separate payer route the approved order to that person.
Every step is timestamped, and rejected items go back to the creator with the reason attached. Purchase-order and contract numbers ride on the order and appear on the invoice. Contract accounts carry a per-order spending limit the platform enforces. When a contracting officer asks how a purchase happened, the record already answers.
The same structure serves hospital purchasing committees and any large procurement team.
Regulated Products Stay With Licensed Buyers
Pharmaceuticals and controlled substances can only be sold to buyers who hold the right licenses, and the rules are federal. On NARMD, standard trauma gear sells to any approved account. Pharmaceuticals and controlled substances stay locked until the buyer's DEA registration and state licensing check out. A medical director registers those credentials once, and purchasing rights extend to the providers working under that license.
The controls keep themselves current. If a license lapses, the account loses access to regulated products until it is renewed, with no spreadsheet and no manual audit. Every product carries a safety data sheet where one is required, and the drug class and stock numbers that came over from the ERP, so a buyer's own systems recognize what was ordered.
The ERP Runs the Portal
NARMD runs off NAR's system of record. We integrated the portal with NAR's ERP in both directions, so the catalog, the prices, and the orders are never maintained twice.
Products flow from the ERP to the portal. An item flagged for the web in the ERP appears on NARMD on its own, with its description, unit of measure, and prices at every level. It arrives carrying the fields government buyers order against: national stock number, NDC, manufacturer and part number, drug type, pharmaceutical class, and hazard and temperature flags.
The portal checks for changed items every few minutes. A price or availability change in the ERP is live on the portal without anyone touching it.
Customers and price lists flow the same way. When NAR's service team approves a new account, the portal links it to its ERP customer record and pulls the price level that customer is entitled to, and a scheduled check keeps the two matched. ERP price levels synchronize to the portal's price lists, so each buyer sees its contract pricing with no spreadsheet in between.
Orders flow back. Once a purchase request is approved and paid, the order and its line items go into the ERP for picking, packing, and shipping, and the ERP's order number is written onto the portal order. If the ERP is down for maintenance, orders wait and then deliver. Nothing is lost between the portal and the warehouse.
Most of the portal's administration happens in the ERP NAR already runs. That left NAR's team free to focus on its life-saving products and the government customers in the field who depend on them, rather than on running a website.
What Happened After Launch
A government contract customer was purchasing on NARMD from day one, and that office's requirements shaped the launch scope. Contract accounts check out on a purchase order rather than a card. Per-order spending limits keep each order inside its contract. Purchase-order numbers appear on every order and every report.
NAR kept investing in the channel. A second phase added automatic approval for registrations from recognized government email domains, and each new buyer lands on the right contract price list at signup. Government and municipal accounts see separate price lists, and the catalog shows each buyer only what its contract covers.
Within its first year, NARMD had outgrown the hosting tier it launched on. The buyers it was built for registered and bought.
Two Platforms, One Team
While NARMD was being built and after it launched, Igility also ran NAR's existing NARescue.com storefront on Magento for the broader tactical-medical market. Security patching, payments, and coordination with NAR's other developers all ran through the same team, so neither platform slipped while the other moved.
"We were impressed with their confidence and experience with Drupal, as well as their project management for collaborating with Magento developers." — Director of Marketing Communications, North American Rescue, on Clutch
If Your Buyers Purchase This Way
The approval chain, the license gate, the purchase-order checkout, and the ERP connection are the same four pieces for any distributor selling to government or institutional buyers. NARMD is the version we built for a tactical-medical brand. The Helmer Scientific and Mobile Mini platforms are the same approach in other markets, and each is still running years on.
If your buyers cannot purchase from your store today, our ecommerce practice is where to start.
Frequently Asked Questions
What does a B2B ecommerce platform need to sell to government buyers?
Four things. Hosting the procurement office will accept. An approval workflow that separates the person who builds an order from the person who authorizes the spend. Product data in the form government buyers order against: national stock numbers, manufacturer part numbers, and drug classes. And contract pricing, so each account sees only its own price list. A store missing any one of them gets worked around with phone calls and emailed purchase orders.
What is a three-tier approval workflow in B2B commerce?
It splits buying into three roles so no single person controls a purchase. A group administrator manages who is on the account and what they can spend. An order creator builds the cart and submits it. An order approver reviews it line by line and releases it or sends it back with notes. On NARMD every step is recorded, so each order carries its own audit trail.
Why did Igility build NARMD on Drupal Commerce?
NAR's government customers had rejected other platforms NAR evaluated and accepted Drupal on a secure cloud that supports government. Drupal Commerce gave us an open-source foundation we could shape to layered approvals, regulated-product controls, and a full audit trail. It shipped on an eighteen-week plan and went live in 2021.
What does it take to sell pharmaceuticals through a B2B portal?
The platform has to know which products are regulated, verify the buyer's DEA registration and state licensure before they can purchase, and block the account when a license lapses. NARMD does all three at the platform level. It does not remove the distributor's obligations. It makes them the portal's default behavior.
How does NARMD connect to NAR's ERP?
In both directions. Products, availability, customer price levels, and price lists flow from the ERP to the portal every few minutes, so the catalog and pricing are maintained once, in the ERP. Approved orders flow back into the ERP for picking, packing, and shipping. If the ERP is down for maintenance, orders wait rather than fail.
Who buys through NARMD?
Government and institutional medical buyers, including the supply teams that keep personnel ready at remote posts. Which offices buy is NAR's to share. Government procurement is the use case the platform was built around.
References
Client Attestation
- Clutch. Review titled "Web Development for Medical & Rescue Solutions Company," by Richard Rice, VP of Marketing, North American Rescue. 5.0 / 5.0 across quality, schedule, cost, and willingness to refer.
- Clutch. Review titled "E-Commerce Dev & Maintenance for Medical Equipment Provider," by a Director of Marketing Communications, covering the combined NARMD build and parallel Magento maintenance scope.
Customer Profile
- North American Rescue. "Products with a Mission®" — tactical medical equipment supplier serving combat medics, tactical EMS, law enforcement, and Fire / EMS customers.
- NAR Medical Depot. Government B2B ecommerce property serving government and institutional medical procurement teams.
Engagement Source
- Igility internal proposal (2019). "North American Rescue Medical Depot — Project Proposal," October 10, 2019. The eighteen-week proposal that became the NARMD scope of work.
- Igility SOW (2020). "NARMD Integration," July 2020. Two-way ERP API integration: products, customers, and price levels to the portal on a short cycle; approved orders and line items to the ERP.
- Igility SOW (2021). "NARMD Monthly Maintenance," April 2021 – March 2022. Monthly module updates, security updates within 48 hours of release, uptime monitoring and response times.
- Igility internal scope documents. NARMD change orders (order workflow and payer step, line-item approval screen, purchase-order payment, product data fields) and the NARMD Phase 2 project brief (government-domain account approval, contract price lists). Internal source archive.
Referral Source
Hosting and Compliance
- Hosting entitlement report, September 2021. North American Rescue account, NARMD application: confirms the platform exceeded its original hosting entitlement within its first year of launch.