Straight answers.
What is the Federal Readiness Score?
A 100-point diagnostic of how ready a company is to sell to the U.S. federal government, computed from public federal data. It is built from 62 lenses across 12 categories — registration, compliance posture, market fit, past performance, and more. Every company is scored on the same scale, so a score means the same thing whether you are a ten-person ISV or an established prime. It is a diagnostic, not a certification: it tells you where you stand and what to fix, and nothing about it implies the government has endorsed anything.
What data does the score use?
Public federal sources only: SAM.gov registrations, USASpending and FPDS obligation records, the FedRAMP Marketplace, GSA CALC+ labor-rate data, and SBIR.gov awards. Nothing is scraped from private systems and nothing comes from surveys. If a signal is not publicly observable, it is not in the score — which is also why the methodology page lists what we will never show you.
How often does the data refresh?
On a rolling cadence from each public source, and every vendor page carries observation dates so you can see exactly how fresh each signal is. One structural limit worth knowing: federal obligation data reflects FPDS reporting, which carries a standard lag of about 90 days. A brand-new award may take a quarter to appear anywhere public — including here.
Why should I trust a score I can read the methodology for?
That is exactly the point. Most scoring products hide their math; ours is published on the methodology page — the 12 categories, how dollars are counted, the disclosures, and the things we refuse to claim. We are vendor-neutral: we do not sell proposals, cloud hosting, or compliance services, so the score has no incentive to flatter or frighten you. Read the methodology, then check a company you know.
Is vendor search really free?
Yes. Searching any federal vendor and seeing their public-data posture requires no login and no card. The free tier is the community layer of the product and it stays free — that is a term of the contract, not a promotion, and the terms of service say so.
What do the tiers get me?
Free is anonymous vendor search, every vendor page in full, and claiming your own company page — no login, no card, no expiry. Team, at $499 a month or $4,990 a year, adds the full readiness report on your own company and its PDF, plus watchlists and CSV export; access is arranged by email today rather than by self-serve checkout, so write to hello@govexpress.ai. Enterprise, from $24,000 a year, adds single sign-on, seats across the organization, and an advisory session, and it starts with a conversation because those have to be scoped. There is no free trial.
What does the intake ask for?
Basics about your company — identity, offering, team, compliance posture, and federal history — the things a diagnostic needs that public data cannot see. It takes minutes, not hours. Nothing in the intake is resold or shared; it exists to score you, and the report is the output.
What do the FedRAMP, CMMC, and SOC 2 statuses on a vendor card mean?
They are posture signals, not certifications from us. A FedRAMP status comes from the FedRAMP Marketplace; CMMC and SOC 2 signals come from public statements and registers where they exist. Each badge tells you the program, the state of the signal, and — when verified — the source and the date we observed it. GovExpress is a diagnostic, never an assessor or certification body.
What does verified vs. self-reported mean?
Verified means a government-published record we observed ourselves — it renders with a solid check, the source, and the observation date. Self-reported means the company says so but no public register confirms it — it renders as an outlined badge labeled self-reported, and never with a checkmark. The distinction is enforced everywhere on the platform because collapsing it is how buyers get burned.
Is there still a CMMC deadline for ISVs?
No. The Phase 2 step that would have made third-party certification mandatory on applicable contracts was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023, and no replacement date has been published. What did not move: NIST SP 800-171 under DFARS 252.204-7012 still applies, the separate self-assessment requirement is still in force, and a Department of War solicitation can still specify a certified assessment on its own terms. So the bid gate is the contract in front of you, not a calendar — which is exactly why knowing your posture now still beats discovering it inside a solicitation window.
What is FedRAMP 20x?
FedRAMP 20x is the program’s modernized certification path. Its Class A pipeline opened on August 3, 2026, and Class B and C pipelines opened on August 31, 2026. The 2026 Consolidated Rules also retired “Authorized” as the status term — the status a cloud service now holds is FedRAMP Certified. For cloud ISVs, 20x is the fastest route the program has offered, which rewards companies whose readiness is already in order when a pipeline window opens.
Do you write proposals or run capture?
No. We score readiness — we do not write proposals, run capture, or bid on your behalf. That separation is deliberate: the moment a scoring product also sells the remediation, the score stops being trustworthy. Plenty of good firms do proposals; bring them your readiness report and make them argue with the data.
Are you a certification body or a 3PAO?
No. GovExpress is a diagnostic. We report publicly observable compliance posture and always distinguish verified records from self-reported claims, but we do not assess, audit, or certify anything, and no output of this platform should be represented as a certification.
Can you show me a company’s supplier performance risk score or classified work?
No, and neither can anyone else selling to the public. The government’s Supplier Performance Risk System is government-only, and classified awards are exempt from public reporting under FAR 4.606(c). Anything built on public data — including this platform — simply does not contain them, and we say so rather than papering over the gap.