Agencies do not buy IT consulting the way companies do. The technical evaluation is real, but it happens inside a process where the procurement route, the security requirements in the contract, and the ability to produce documentation on demand decide most outcomes before anyone looks at an architecture diagram.
This applies whether you are a federal agency, a state department, or a city with a council to answer to.
Start with the procurement route
The vehicle shapes everything, including which firms can bid at all.
- Existing contract vehicles. The fastest route where one applies. If a firm already holds a relevant vehicle, a great deal of the process is already done.
- Cooperative purchasing. State and local agencies frequently have access to co-operative agreements that satisfy competitive requirements without a full solicitation. Worth checking before writing an RFP.
- Open solicitation. Necessary sometimes, slow always. If you are writing the requirements, the specification you produce determines the quality of what you receive.
- Small purchase thresholds. Often the right route for an assessment or a scoped project.
If you are writing an RFP for IT services, the single highest-leverage thing you can do is specify outcomes and evidence rather than technologies. A specification that names products will get you those products whether or not they fit.
The security requirements that actually get enforced
Agency contracts increasingly carry security obligations that flow to the consultant as well as to you.
| Requirement | Applies when |
|---|---|
| FAR 52.204-21 | Basic safeguarding, on essentially any federal contract |
| DFARS 252.204-7012 and NIST SP 800-171 | Defense work involving controlled unclassified information |
| CJIS Security Policy | Anything touching criminal justice information |
| HIPAA | Health agencies and anything handling protected health information |
| State-specific frameworks | Varies by jurisdiction; check before assuming federal rules suffice |
Ask a prospective firm which of these they have delivered against, and ask for artefacts. Firms that have done the work can produce a redacted System Security Plan or an audit response quickly. Firms that have not will talk about partnerships and capability statements.
What agency IT consulting engagements usually cover
- Current-state assessment. Inventory, lifecycle, security posture, and where you stand against whichever framework applies.
- Infrastructure and modernisation planning. What to replace, in what order, and what it costs across budget cycles.
- Security architecture. Segmentation, identity, monitoring, and the control set the contract requires.
- Continuity planning. Increasingly a stated requirement rather than a nice-to-have.
- Documentation. The artefacts an auditor, council or inspector general will ask for.
Point five is the one agencies undervalue at procurement and need most at audit.
Evaluating firms fairly
Four questions separate genuine capability from a well-written proposal.
- “Name three comparable agency clients.” Comparable in size and function, not just in sector.
- “Show us a redacted deliverable.” From a real engagement.
- “Which of your staff will be on this, and what do they hold?” Not who is on the website.
- “What happens after the project?” Agencies churn staff. A plan nobody internal can maintain is a plan that expires.
- The procurement route often decides the outcome before technical evaluation begins.
- Specify outcomes and evidence, not products.
- CJIS is discovered late and very few firms are actually certified. Ask for proof.
- Documentation is undervalued at procurement and needed most at audit.
Where IP Consulting fits
We work with federal, state and local government organisations across Virginia and Michigan. We are CJIS Certified and CMMC Registered, both verifiable, and we have supported municipal and agency clients for two decades. See IT for federal agencies, IT for municipalities and IT for government contractors if you are on the contractor side rather than the agency side.
Frequently asked questions
How do government agencies buy IT consulting?
Usually through an existing contract vehicle, a cooperative purchasing agreement, an open solicitation, or under a small purchase threshold. The route shapes which firms can bid and how long it takes, so it is worth settling before writing a specification. Cooperative agreements often satisfy competitive requirements without a full solicitation.
What security requirements apply to agency IT contracts?
FAR 52.204-21 for basic safeguarding on essentially any federal contract, DFARS 252.204-7012 and NIST SP 800-171 for defense work involving controlled unclassified information, the CJIS Security Policy for anything touching criminal justice data, HIPAA for health information, plus state-specific frameworks that vary by jurisdiction.
What should we ask an IT consulting firm before selecting them?
Ask for three comparable agency references, a redacted deliverable from a real engagement, the names and credentials of the staff who will actually do the work, and what happens after the project ends. Agencies churn staff, so a plan nobody internal can maintain will expire.
Why is CJIS compliance often missed?
Because scope is wider than people expect. If any part of the environment touches police, court or corrections data, including shared network segments and backup systems, it falls in scope. Very few IT firms hold actual CJIS certification, so ask for the certification rather than accepting the claim.
Keep exploring
Ready for a clear path forward?
Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.
Start with a Clarity Conversation