How to Sell Software to the Federal Government: The Complete 2026 Guide for ISVs

#federal-market #isv #saas #compliance

The U.S. federal government is the single largest buyer of technology in the world — spending more than $100 billion annually on IT goods and services. For software companies that have found product-market fit in commercial markets, federal is the most defensible revenue expansion available: long contract terms, programmatic renewals, and a buyer that doesn’t churn on price.

But federal procurement runs on its own set of rules. The sales cycles are longer, the compliance requirements are real, and the entry points are not obvious. This guide covers the practical path from commercial ISV to federal vendor — in the right sequence, without the assumptions consultants make when they assume you have a lobbyist and a six-month runway.


1. Understand the federal market structure

Before you build a pipeline, you need to understand who buys and how.

Who buys: The federal government has over 430 departments, agencies, and sub-agencies. For software companies, the primary buyers cluster around civilian IT (GSA, HHS, DHS, Treasury), defense (DoD and its components — Army, Navy, Air Force, DARPA, DISA), and intelligence-adjacent (NRO, NSA via cleared channels). Your NAICS code determines which set-asides and vehicles apply to you; most software companies file under 541511 (Custom Computer Programming) or 541512 (Computer Systems Design).

How they buy: Federal agencies use contract vehicles — pre-negotiated agreements that let agencies purchase from approved vendors without running a new competition for every purchase. The most important vehicles for software companies are GSA Multiple Award Schedule (MAS), SEWP V (NASA), CIO-SP4 (NIH), and OASIS+ (GSA). Agencies can also do open-market purchases (micro-purchases up to $10,000) or issue task orders on existing IDIQs. Most early federal traction for ISVs comes from task orders on vehicles, not standalone contracts.

The timeline reality: Expect 6–18 months from first contact to first revenue. SAM.gov registration takes days. Getting on a vehicle takes 3–6 months. The first task order after that takes another 3–9 months. The pipeline work you do today produces revenue in 12–18 months. Federal is a long game — but once won, the average contract term is 3–5 years with option periods.


2. Register in SAM.gov and get your UEI

Every company doing business with the federal government must be registered in the System for Award Management (SAM.gov). This is not optional, and it is the first thing contracting officers check.

Getting your UEI: The Unique Entity Identifier (UEI) replaced DUNS numbers in April 2022. It is issued by SAM.gov during registration and is now your permanent federal identity. You need it before any solicitation, subcontracting arrangement, or grant application.

What SAM.gov registration requires:

  • Legal business name and address
  • CAGE code (assigned or existing)
  • NAICS codes (pick your primary and up to 9 secondary codes)
  • Tax Identification Number (TIN/EIN)
  • Financial institution information (for EFT payments)
  • Annual renewal — registrations expire after 12 months

The registration itself is free and takes 7–10 business days. Third-party services that charge for SAM.gov registration are resellers — you don’t need them. After registration, your SAM.gov profile becomes your public federal identity: agencies search it, primes vet you against it, and your certifications are pulled from it for set-aside eligibility.

Certifications that open doors: Small Business designation is automatic if you qualify (size standard varies by NAICS code — typically $27.5M–$41.5M for IT companies). 8(a) certification (SBA-administered, 9-year program for disadvantaged businesses), HUBZone, WOSB (women-owned), and SDVOSB (service-disabled veteran-owned) each unlock specific set-aside competitions. Set-asides are the single fastest path to early federal wins because you’re only competing against other certified companies — not Leidos or Booz Allen Hamilton.


3. Map your compliance requirements

This is the section most ISVs underestimate. Federal compliance is not a one-size-fits-all checklist — it depends on your data environment, your target agencies, and your deployment model. Getting this wrong costs 12 months and several hundred thousand dollars.

FedRAMP (if you host federal data)

FedRAMP (Federal Risk and Authorization Management Program) is required for any cloud service that processes, stores, or transmits federal information. If your product is SaaS and any federal data lives in your environment, you need FedRAMP authorization.

The process has two paths: Agency Authorization (work with a single sponsoring agency) and Program Authorization (via the PMO). Historically, both took 12–24 months and $1–3M. That is changing in 2026.

FedRAMP 20x is the GSA’s redesigned authorization program, announced in early 2025 and with Phase 3 opening in mid-2026. It replaces the manual review process with machine-readable security packages and continuous validation. Early movers who authorize under 20x will have a significant window before incumbents retool. For the detailed timeline and eligibility criteria, see our deep dive: FedRAMP 20x: What SaaS Companies Need to Know in 2026.

CMMC (if you serve DoD)

The Cybersecurity Maturity Model Certification (CMMC) applies to DoD contractors and their subcontractors who handle Controlled Unclassified Information (CUI). CMMC 2.0 has three levels:

  • Level 1 (Foundational): 17 practices from NIST SP 800-171. Annual self-assessment. Required for contracts involving Federal Contract Information (FCI) only.
  • Level 2 (Advanced): 110 practices from NIST SP 800-171. Third-party assessment (C3PAO) required for contracts with CUI.
  • Level 3 (Expert): 110+ practices including NIST SP 800-172. Government-led assessment. Required for high-priority DoD programs.

Most software companies serving DoD will be assessed at Level 2. The assessment process with a C3PAO runs 3–6 months and typically costs $50,000–$150,000. Start your CMMC gap analysis well before you need to respond to a DoD solicitation — the clock starts from the date of the RFP, and “we’re in the process” is not a compliant response.

What you can skip (for now)

Unless you’re selling into classified programs: you don’t need security clearances in your early federal years. Most software sold to civilian agencies operates at the Unclassified level. ITAR applies to defense articles and related technical data — if your product isn’t a munition or satellite component, ITAR is not your problem. Section 508 (accessibility) applies to any software procured by the federal government — this one you cannot skip, but it is the most straightforward of the compliance requirements.


4. Size your federal TAM before you build a pipeline

Before you invest in business development, you need to know whether there is meaningful spend in your product category. ISVs consistently overestimate their federal TAM because they reason from the total IT budget ($100B+) rather than the specific NAICS codes that match their product.

The authoritative source is USASpending.gov — the public federal spending database that tracks every prime contract over $10,000. Query by NAICS code, product service code (PSC), and agency to get the actual spend in your category. The data is updated nightly and goes back to FY2008.

What you’re looking for:

  • Category spend: Total federal spending on your NAICS codes, per year for the last 5 years
  • Agency concentration: Which agencies account for 80% of that spend
  • Award size distribution: Whether the typical award is $500K or $50M (this determines whether you need a GSA Schedule or a prime contract strategy)
  • Incumbents: Which companies are winning the awards — and what certifications or vehicles they hold

Companies like Palantir, Anduril Industries, and Leidos publish their federal revenue in earnings reports. SAIC and Microsoft publish government-segment breakdowns. These are useful benchmarks for the ceiling of what’s possible in a given category — and their contract vehicles reveal which vehicles dominate your space.

For a step-by-step walkthrough of the TAM sizing methodology, see: How to Estimate Your Federal Total Addressable Market as an ISV.


5. Choose your contract vehicle strategy

You cannot sell to the federal government without a vehicle. Agencies cannot buy from you if you don’t have a mechanism. The question is not whether to pursue a vehicle — it’s which vehicle to prioritize, in what order, and in what sequence relative to business development.

GSA Multiple Award Schedule (MAS)

GSA MAS is the most broadly applicable vehicle for commercial software companies. It covers:

  • SINs (Special Item Numbers) for software (SIN 518210C), IT products, professional services
  • Open to any commercially available product or service
  • Used by virtually every civilian agency and many DoD components
  • Allows direct agency purchasing without a new competition

The application process takes 3–6 months. You submit a price list, your commercial pricing history, and past performance evidence. GSA negotiates prices and issues your Schedule contract, which is valid for up to 20 years (base + options). Once on Schedule, you market directly to agency COs and contracting vehicles.

Is it worth it for SaaS? Yes, with one caveat: GSA MAS requires you to have at least two years of commercial past performance and existing customers with verifiable pricing. Early-stage companies (< $2M ARR, < 2 years in business) should pursue subcontracting first to build the past performance record. For the full analysis, see: GSA Schedule for SaaS Companies: Is It Worth It?

SEWP V (NASA)

The Solutions for Enterprise-Wide Procurement (SEWP) vehicle covers IT products and services and is used by DoD and civilian agencies. SEWP is quota-managed — you must partner with a current prime to add products — but the process is faster than MAS and the agencies that use SEWP tend to be higher-spend defense customers.

CIO-SP4 (NIH)

The Chief Information Officer Solutions and Partners 4 (CIO-SP4) is an IDIQ covering IT services across government. Significant awards ($500M+ TCV) go through CIO-SP4. It is a primary vehicle for healthcare IT, data analytics, and cybersecurity work at HHS agencies. Access requires a prime contract — usually won through teaming with an established prime during the initial award competition.

The subcontracting path (fastest to first revenue)

For most ISVs, the fastest path to federal revenue is subcontracting to a prime. Companies like Booz Allen Hamilton, Leidos, and SAIC win large prime contracts and then bring in commercial software companies as subcontractors for specific capabilities. You don’t need your own vehicle, your compliance requirements are reduced (the prime handles some of the regulatory burden), and you can reference the work as past performance for your own vehicle applications later.

The trade-off: margin compression (primes typically take 15–30%), limited direct agency relationships, and dependency on the prime’s pipeline. Subcontracting is a phase, not a strategy — use it to build past performance and agency relationships, then pursue your own vehicle.


6. Build your federal pipeline

Federal business development is relationship-intensive and information-intensive. The days of simply responding to RFPs are over — well-run federal sales organizations know about opportunities 18 months before the solicitation drops.

Where to find opportunities

SAM.gov Opportunities (beta.SAM.gov) — the official source for federal solicitations. Every contract over $25,000 must be posted here. Search by NAICS code, set-aside type, agency, and keyword. Set up saved searches with email alerts.

Agency Forecast Portals — many large agencies publish their acquisition forecasts (DISA, Army, Air Force, GSA, DHS all publish annual procurement forecasts). These tell you what they plan to buy 6–18 months out — which is when you need to be building the relationship.

FPDS-NG (Federal Procurement Data System) — historical contract awards accessible via SAM.gov. Shows who won what, at what price, on which vehicle. The data source behind USASpending.gov.

SBIR.gov — if your company qualifies as a small business (< 500 employees), SBIR/STTR grants fund R&D with federal agencies. Phase I awards ($150K–$300K) and Phase II awards ($750K–$2M) are non-dilutive. DoD is the largest SBIR funder.

The proposal response process

Federal proposals are structured responses to Requests for Proposals (RFPs). Every section has a point value. The evaluation criteria are public. You must answer exactly what was asked, in the order asked, with the evidence they specified.

Key disciplines:

  • Capture management: Start influencing requirements before the RFP drops. Brief the contracting officer, respond to RFIs (Requests for Information), and attend industry days.
  • Past performance: Your references must be closely analogous to the work being solicited. Scope, complexity, contract value, and agency type all matter.
  • Teaming: For large contracts, assembling the right team (primes, subs, small business partners) is often the deciding factor. A partnership with an 8(a) firm can shift evaluation.
  • Pricing: Federal pricing is more transparent than commercial — your competitors’ prices on existing contracts are public. Price-to-win analysis is a discipline in itself.

7. Your 90-day action plan

If you’re starting from zero, here is the sequence that maximizes your chances of first federal revenue within 12 months:

Days 1–30: Foundation

  1. Register in SAM.gov and get your UEI (starts the clock on the 7–10 business day wait)
  2. Pull your federal TAM from USASpending.gov — be honest about what the category actually spends
  3. Score your company against the six federal readiness dimensions: run your Federal Readiness Score →
  4. Identify 3 target agencies based on where your NAICS codes see the most concentrated spend
  5. Identify 5 primes in your space and research their subcontracting needs

Days 31–60: Positioning

  1. Complete your compliance gap analysis (SOC 2 if not done; FedRAMP assessment if you’re SaaS; CMMC Level if DoD)
  2. Attend one industry day or AFCEA/PSC event — these are where relationships start
  3. Contact the subcontracting offices at 2–3 target primes (they’re required to maintain small business subcontracting plans)
  4. File for any applicable certifications (small business, 8(a), HUBZone) through SBA.gov

Days 61–90: Pipeline

  1. Begin your GSA MAS application (if you qualify — 2+ years, existing customers)
  2. Respond to 1–2 RFIs in your space (no-risk, builds your name in agency awareness)
  3. Set up SAM.gov opportunity alerts for your top NAICS codes + agencies
  4. Build your federal past performance documentation for your first 3 commercial contracts that are analogous to what federal agencies buy

The information advantage

Federal market entry used to require a Washington D.C. office, a network of lobbyists, and years of relationship-building before first revenue. That is still true for prime contract positions on large defense programs. But for ISVs with a strong commercial track record, the path is more accessible than ever — driven by two forces: the federal government’s accelerating need for commercial software (especially AI, cybersecurity, and cloud), and the explosion of public procurement data available via USASpending.gov, SAM.gov, and FPDS.

The companies that move fast are the ones that use that data to understand where they fit — their real TAM, their true compliance gap, their actual competitive position — before they spend 18 months building a pipeline toward a market that doesn’t fit.

That’s exactly what the GovExpress Federal Readiness Score does. Score your company →


Further reading