Agencies do not buy IT consulting the way companies do. The technical evaluation is real, but it happens inside a process where the procurement route, the security requirements in the contract, and the ability to produce documentation on demand decide most outcomes before anyone looks at an architecture diagram.

This applies whether you are a federal agency, a state department, or a city with a council to answer to.

Start with the procurement route

The vehicle shapes everything, including which firms can bid at all.

If you are writing an RFP for IT services, the single highest-leverage thing you can do is specify outcomes and evidence rather than technologies. A specification that names products will get you those products whether or not they fit.

The security requirements that actually get enforced

Agency contracts increasingly carry security obligations that flow to the consultant as well as to you.

RequirementApplies when
FAR 52.204-21Basic safeguarding, on essentially any federal contract
DFARS 252.204-7012 and NIST SP 800-171Defense work involving controlled unclassified information
CJIS Security PolicyAnything touching criminal justice information
HIPAAHealth agencies and anything handling protected health information
State-specific frameworksVaries by jurisdiction; check before assuming federal rules suffice

Ask a prospective firm which of these they have delivered against, and ask for artefacts. Firms that have done the work can produce a redacted System Security Plan or an audit response quickly. Firms that have not will talk about partnerships and capability statements.

Good to know: CJIS is the requirement most often discovered late. If any part of the environment touches police, courts or corrections data — including shared network segments and backup systems — it is in scope, and very few IT firms are actually certified against it. Ask for the certification, not the claim.

What agency IT consulting engagements usually cover

  1. Current-state assessment. Inventory, lifecycle, security posture, and where you stand against whichever framework applies.
  2. Infrastructure and modernisation planning. What to replace, in what order, and what it costs across budget cycles.
  3. Security architecture. Segmentation, identity, monitoring, and the control set the contract requires.
  4. Continuity planning. Increasingly a stated requirement rather than a nice-to-have.
  5. Documentation. The artefacts an auditor, council or inspector general will ask for.

Point five is the one agencies undervalue at procurement and need most at audit.

Evaluating firms fairly

Four questions separate genuine capability from a well-written proposal.

Key takeaways
  • The procurement route often decides the outcome before technical evaluation begins.
  • Specify outcomes and evidence, not products.
  • CJIS is discovered late and very few firms are actually certified. Ask for proof.
  • Documentation is undervalued at procurement and needed most at audit.

Where IP Consulting fits

We work with federal, state and local government organisations across Virginia and Michigan. We are CJIS Certified and CMMC Registered, both verifiable, and we have supported municipal and agency clients for two decades. See IT for federal agencies, IT for municipalities and IT for government contractors if you are on the contractor side rather than the agency side.

Frequently asked questions

How do government agencies buy IT consulting?

Usually through an existing contract vehicle, a cooperative purchasing agreement, an open solicitation, or under a small purchase threshold. The route shapes which firms can bid and how long it takes, so it is worth settling before writing a specification. Cooperative agreements often satisfy competitive requirements without a full solicitation.

What security requirements apply to agency IT contracts?

FAR 52.204-21 for basic safeguarding on essentially any federal contract, DFARS 252.204-7012 and NIST SP 800-171 for defense work involving controlled unclassified information, the CJIS Security Policy for anything touching criminal justice data, HIPAA for health information, plus state-specific frameworks that vary by jurisdiction.

What should we ask an IT consulting firm before selecting them?

Ask for three comparable agency references, a redacted deliverable from a real engagement, the names and credentials of the staff who will actually do the work, and what happens after the project ends. Agencies churn staff, so a plan nobody internal can maintain will expire.

Why is CJIS compliance often missed?

Because scope is wider than people expect. If any part of the environment touches police, court or corrections data, including shared network segments and backup systems, it falls in scope. Very few IT firms hold actual CJIS certification, so ask for the certification rather than accepting the claim.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation