The deck is not the meeting
A capability deck almost never fails in the room where it was presented. The sponsor asked good questions, said the work sounded useful, and asked for the file. Then the file left the room, and nothing happened. Whatever went wrong went wrong in a place you cannot see: the deck was forwarded to people who never met you, opened cold on a laptop between two other meetings, and judged against a standard nobody described. The presenter's version of the deck, the one that works when a person is talking over it, is not the version that gets read. The forwarded version is.
Gartner's widely cited finding on complex business-to-business purchases is that a typical buying group runs six to ten decision-makers, each arriving with four or five pieces of information they gathered on their own. Buying technical delivery inside a prime, an integrator, or an advisory firm sits at the harder end of that range, because at least one of those readers holds a veto unrelated to whether your engineering is any good. Procurement does not care about your architecture. Independence does not care about your benchmark. Both care whether you can be onboarded without creating a problem for someone senior.
Everything below follows from one design constraint. The deck's job is not to explain your company. It is to survive being read alone, by a stranger, at speed, and to leave that stranger able to say yes in writing.

Three readers, three vetoes
Three people decide whether a second meeting happens, and only one of them met you. The sponsor is the partner, capture lead, or program manager who liked the conversation. The technical reviewer is the person the sponsor forwards it to with a note that says some version of "does this hold up." The risk reviewer is whoever owns supplier onboarding, security, contracts, or independence, and that person's default answer is no until a file is complete.
The sponsor is the only reader with enthusiasm and holds the weakest veto. A deck written entirely for the sponsor gets forwarded once and then stops. A deck that serves all three converts, because the sponsor stops having to advocate and starts merely having to circulate.
| Reader | Opens the file to find | What ends it |
|---|---|---|
| The sponsor partner, capture lead, program manager | A sentence they can paste into an internal email with your name attached, and a scope matching a live pursuit | Nothing quotable. If the sponsor has to write your value proposition, the forward does not happen |
| The technical reviewer chief architect, delivery lead, principal engineer | A method specific enough to argue with, and one number with a denominator, an instrument, and a date | Claims with no measurement behind them, or a benchmark that cannot be reproduced from the page |
| The risk reviewer supplier onboarding, security, contracts, independence | Entity identifiers, registration status, size and socioeconomic representations, cyber posture, insurance, a contracting path | A missing block. Not a bad answer, a blank one. Blanks generate emails, and emails generate delay |
| All three together | Consistency: the same numbers, entity name, and scope description on every page | Two versions of one fact in a single file. It reads as carelessness and invites a full re-check |
Why the "who we are" deck stalls
The stalled deck has a recognizable shape. The company name over a photograph. A founding story. A mission. A grid of technology logos. A timeline of milestones that mean something internally and nothing externally. "Our approach" in four boxes that would fit any firm in the category. Near the end, a slide of client logos, several of which are not customers at all.
Every one of those slides is about the seller, and none can be extracted. That is the diagnostic worth running on your own file right now: open it and try to copy one sentence into an email a sponsor could send to a colleague. If no sentence survives the copy without the speaker attached to it, the deck is a presentation aid rather than a document, and presentation aids do not get forwarded.
The second diagnostic: hand the file to an engineer who never heard your pitch and ask them to find something to disagree with. If they cannot, the deck holds no claim specific enough to be wrong, which means none specific enough to be right. Generic decks are safe and inert, and reviewers do not forward inert files.
What moves a deck from read to forwarded
Editorial weighting from public sources and practitioner reading. Illustrative ordering, not a measured statistic.
The ordering above is the argument, not the numbers. The elements at the top are the ones whose absence most often stops a file from moving; the element at the bottom is the one that absorbs the most redesign hours. Polish is not worthless, since a careless-looking deck makes a reviewer read everything else more suspiciously. But polish is a floor, and past that floor another hour of design returns almost nothing against an hour spent making one number checkable.
Nine slides that do work
The spine below is short on purpose. Nine slides carries a real argument and still lets a reviewer reach the end. Anything else belongs in an appendix after the ask, where a curious reader finds it and a busy reader is not slowed by it.
1. The claim. One line naming the problem you close, written in the buyer's language, not yours. Not "AI and data engineering for federal missions." Something closer to "we take document-heavy adjudication workflows from manual review to audited automation, and we show the error rate." The sponsor will paste this sentence. Write it so it survives the paste.
2. The gap. The specific hole this fills on their side: a capability their bench lacks, a scored weakness in a bid, a delivery date they cannot hit, a rate structure that prices them out. Naming the gap correctly is the strongest available signal that you understand the buyer's business rather than your own.
3. The evidence. One result, measured, with the instrument named. This slide is discussed at length below because it is the one that decides the technical veto.
4. The method. How the result was produced, deep enough that a technical reviewer can push on it. Two or three architectural choices and why each was made. A method slide that could describe any firm is worse than none, because it says there is nothing underneath.
5. The people. Named individuals who would do the work, at availability you can honor. If someone is at sixty percent, write sixty percent.
6. The shapes of an engagement. How work starts: a scoped assessment, a fixed-price proof of value, a delivery subcontract, a staff-augmented workstream. Two or three shapes, what each produces, how long each runs. This lets the sponsor pick the easiest door to open.
7. The compliance block. Everything the risk reviewer needs, on one page, in a form that can be screenshotted and pasted into an onboarding ticket.
8. Record and references. Prior work, published methods, reproducible artifacts, and named people who will take a reference call. What goes here when the federal record is short is below.
9. The ask. One thing, named, smaller than "let us work together."
The evidence slide carries the whole deck
Most decks contain numbers, and most of those numbers are not evidence. "Ninety-two percent accuracy" has no denominator, no instrument, no baseline, no date, and no way to tell whether the test set was the training set. A number without a denominator, an instrument, and a date is a claim about your marketing, not your engineering. Reviewers read it that way, and they do not write back to say so.
Evidence has four parts. The denominator: how many items, from where. The instrument: what defined a correct answer, and who adjudicated disagreements. The baseline: the prior number, measured the same way on the same set. The date: when it was measured, because a result from a superseded model version is a historical note.
One more discipline, from watching how technical readers respond to charts. A chart where every bar reads at the same perfect value is read as a chart that was drawn rather than measured. Real measurement is uneven. If a result is strong in three places and merely adequate in a fourth, show the fourth. The adequate bar is what makes the strong ones believable, and a reviewer who finds the honest bar stops hunting for the dishonest one. The audit a buyer would run on your number is in how to verify an AI vendor's benchmark claim; running it on your own deck first is the fastest edit available.
The compliance block is a slide, not an appendix
Risk reviewers work from tickets. A ticket that opens complete gets closed; one that opens with three known fields and eight blanks becomes a thread, and threads take weeks. Put the whole block on one page, as text rather than an image, so it can be copied.
- Legal entity name exactly as registered, the Unique Entity ID, the CAGE code, and the date the SAM.gov registration expires. Registrations renew every 365 days to stay active; the UEI does not expire, and CAGE codes issued after August 26, 2016 renew every five years.
- NAICS codes with the size standard printed beside each one. For 541512, Computer Systems Design Services, the SBA standard is $34 million in average annual receipts, computed over five fiscal years under 13 CFR 121.104.
- Size and socioeconomic status in SBA's exact words, with certified and self-certified marked differently. A prime counting dollars toward a goal needs to know which applies.
- Section 889 representation status under FAR 52.204-24 and 52.204-26, and an acknowledgment that the prohibition at FAR 52.204-25 flows down into subcontracts, including commercial-item subcontracts.
- Cyber posture with a date attached. The SPRS score, when it was assessed, whether a system security plan and a plan of action and milestones exist, and which revision of NIST SP 800-171 was scored.
- DFARS 252.204-7012 acknowledgment where defense work is in scope: NIST SP 800-171 safeguarding under paragraph (b)(2)(i), reporting within 72 hours of discovery to dibnet.dod.mil, and the flowdown at paragraph (m).
- Commercial attestations. A SOC 2 report or an ISO/IEC 27001 certificate, and ISO/IEC 42001, the AI management system standard published in December 2023, where AI governance is what is being bought. Accredited certificates run three years.
- Insurance and paperwork. General liability, professional liability, and cyber coverage with limits and carrier named, plus a W-9 and the contracting address.
- Accounting and data handling. How you invoice, the terms you accept, whether timekeeping supports a cost-reimbursement subcontract, where data lives, and who touches it.
Cyber posture in the second half of 2026
This is the part of a deck most likely to be out of date right now, and a stale claim here is read as evidence that you are not tracking your own obligations. The Department of War suspended Phase 2 assessment requirements of the Cybersecurity Maturity Model Certification program through two memoranda issued on July 13, 2026, pausing a phase that had been scheduled to begin on November 10, 2026 and opening a review of the program.
What that did not do is repeal anything. The program rule and DFARS 252.204-7021 remain in force as written. Self-assessments, posting scores to the Supplier Performance Risk System, and annual affirmations of continuing compliance still apply, and the safeguarding and 72-hour reporting obligations under DFARS 252.204-7012 were never part of the suspension. What paused is the requirement that new contracts carry third-party certification at the higher levels. For scoring, the controlling program text still points at Revision 2 of NIST SP 800-171 even though NIST has superseded it with Revision 3; moving DoD assessment to Revision 3 would take rulemaking.
This is genuinely in flux, and the honest slide says so: where you stand, the date you assessed, what comes next. An unqualified "CMMC certified" line in August 2026 tells a defense risk reviewer more than you intended. The mechanics for a software firm are in our note on CMMC for software offerors.
Record and references when the federal record is short
Firms with a short federal history often write an apologetic slide, or drop the section. Both are mistakes, and the second is the lesser. Source selection has an explicit rule here: under FAR 15.305(a)(2)(iv), an offeror without a record of relevant past performance, or for whom the information is not available, may not be evaluated favorably or unfavorably on past performance. GAO has held that an agency may not treat a neutral rating as a negative, including by excluding an offeror from the competitive range on that basis.
A blank record is neutral by rule. Writing down the absence converts a neutral into a negative that no rule required. So the slide never explains what is missing. It shows what exists: commercial delivery with outcomes, published methods a reviewer can read, artifacts someone can run, and two or three named references who agreed in advance to take a call. References who answer the phone in a day beat a logo wall, because a logo cannot be interviewed. The longer treatment is in building federal past performance from zero.
The federal facts a prime partner will check
If the buyer is a federal prime, three regulatory facts sit under the conversation, and a deck that reflects them reads as written by someone who has done this before.
Teaming has a short home in the regulation. FAR 9.601 defines a contractor team arrangement as either two or more companies forming a partnership or joint venture to act as a potential prime, or a potential prime agreeing with other companies that they will act as its subcontractors under a specified contract or acquisition program. FAR 9.602 frames the purpose as letting companies complement each other's unique capabilities. FAR 9.603 says the government will recognize the integrity and validity of these arrangements provided the relationships are fully disclosed in an offer, or before the arrangement becomes effective if formed later. FAR 9.604 sets the boundary: nothing in the subpart authorizes arrangements that violate antitrust statutes, and nothing limits the government's right to hold the prime fully responsible for performance regardless of the team arrangement.
Small-business subcontracting is a reporting obligation, not a courtesy. Under FAR 19.702, an other-than-small prime must submit a subcontracting plan on awards expected to exceed the threshold, raised to $900,000 effective October 1, 2025, with $2 million for construction of a public facility. The prime writes percentage goals by socioeconomic category, reports against them, and carries consequences for failing to make a good faith effort. The statutory government-wide goal is 23 percent of prime dollars to small business; SBA's FY2025 scorecard, released in June 2026, reported nearly 28 percent, about $179 billion. That machinery is why a capture manager asks which categories you hold.
One citation caution for anything printed in 2026. The Revolutionary FAR Overhaul is rewriting large parts of the FAR through class deviations ahead of formal rulemaking, and Part 19 is among them, with a revision issued in July 2026. Cite the substance rather than the paragraph number in a document that will be read next year.
Advisory and commercial buyers read the same file differently
Inside a large advisory firm or a global integrator, the veto that surprises specialist firms is neither technical nor financial. It is independence and conflict clearance. A firm with an audit practice carries obligations enforceable against the firm itself, and one holding federal prime contracts carries flow-downs it cannot waive. Neither queue moves faster because a partner is enthusiastic. Both move faster when the answers arrive assembled: legal entity, ownership, conflicting client relationships, security attestations.
Two additions cover this. A line on the engagement slide naming the contracting instruments you have worked under, so the sponsor can tell procurement which door to use. And an ownership and conflicts line in the compliance block, because that is the first thing an independence check asks for and the answer is usually one sentence. The full sequence inside that kind of buyer is mapped in how large advisory firms buy technical delivery.
What happens to the file after you send it
Durations vary by buyer. The ordering does not. A firm that knows the sequence stops reading silence as rejection and starts sending the one artifact that unblocks the step the file is sitting in.
Typical path of a forwarded capability deck
The file itself
Format decisions are small and they compound. Send a PDF, so the layout survives every viewer and nothing offers to open in edit mode. Name it to be findable a month later in a downloads folder: firm, subject, month, year. Keep it small enough to clear a corporate mail gateway, because large attachments get stripped and nobody tells the sender. No embedded video, no animation, no build sequences that leave overlapping text when flattened.
Put the text on the page as text, not as an image of a slide. Reviewers copy from these files constantly, and searchable text is how your sentence ends up inside somebody's internal email. Number the pages, and put a contact line and entity name on every one, because slides get screenshotted individually and an unattributed screenshot is an orphan.
Design each slide to work at two speeds. The headline carries the argument for the reader who spends ninety seconds; the body carries detail for the one who spends twenty minutes. A headline that is a label, like "Our Approach," gives the fast reader nothing. A headline with a verb in it gives them the argument even if they read nothing else.
The cut list
The mission statement and the founding story. Neither answers a question anyone in the chain is asking. If the origin explains a technical advantage, it is one clause inside the method slide.
Logos you cannot describe as customers. A reviewer who recognizes a name asks what you did there, and an answer that shrinks under one question costs more than the slide was worth.
The full technology inventory. Fifteen frameworks signal breadth without depth. Two or three areas of real depth, with evidence a technical reviewer accepts, are what get you staffed.
Adjectives about your own quality. Innovative, world-class, cutting-edge, trusted. Readers skip these, and their presence raises the question of what else is unsupported.
Any slide you cannot defend in one follow-up question. That test removes more material than any other rule.
One ask, and make it small
The last slide is where good decks lose the meeting they earned. "We would love to explore ways to work together" hands the work of finding a fit to the person with the least time for it. A useful ask is specific and cheap to grant: a scoped assessment on one workstream, a technical working session with the named reviewer, a mutual NDA so a real dataset can be discussed, or inclusion in a pursuit the sponsor already named.
Small asks convert because they sit inside the sponsor's own authority. A partner can book an hour with an architect without asking anyone. A partner cannot add a supplier without three queues. Ask for the first thing, then let the compliance block clear the rest while the technical conversation is already running. A short agenda for that conversation is in what to cover on a first teaming call.
Bottom line
A deck that produces second meetings is not a better-looking version of one that does not. It is a different document with a different reader in mind. It assumes the sponsor is enthusiastic and powerless, the technical reviewer is skeptical and decisive, and the risk reviewer is neither, just holding a checklist that has to come back complete. Give the sponsor one sentence worth pasting. Give the technical reviewer one number with a denominator, an instrument, a baseline, and a date. Give the risk reviewer a page complete enough that the onboarding ticket closes on the first pass. Then ask for something small enough that one person can grant it. The file stops being a brochure and becomes what it should have been: the instrument that lets three strangers agree on you without another meeting.
Frequently asked questions
The one-page capability statement is a search and filing artifact for federal buyers, skimmed in ten seconds and kept on file with your identifiers, codes, and competencies. The deck is a decision artifact for internal circulation, carrying evidence and method deep enough for a technical reviewer to test. Both must agree on every fact. The one-pager is covered in the capability statement that gets a callback.
Entity name, UEI, CAGE, SAM registration status with its expiration date, NAICS codes with size standards, size and socioeconomic representations, Section 889 representation status under FAR 52.204-24 and 52.204-26, and cyber posture with a date. On cyber, note that the Department of War suspended CMMC Phase 2 assessment requirements on July 13, 2026, while the program rule, DFARS 252.204-7021, self-assessments, SPRS posting, annual affirmations, and the DFARS 252.204-7012 obligations all remain in force.
Show commercial delivery with measured outcomes, published methods, artifacts a reviewer can run, and two or three named references who have agreed in advance to take a call. Do not write a slide explaining what is missing. Under FAR 15.305(a)(2)(iv) an offeror without a record of relevant past performance may not be evaluated favorably or unfavorably, and GAO has held that a neutral rating cannot be used against an offeror, so a blank record is neutral until you narrate it into a weakness.
Not rates, and not a price list. Include the shapes an engagement takes and roughly how long each runs, so a sponsor can tell procurement which path to open. Rates belong in the rate sheet you send within a day of the request, with labor category descriptions, because a prime assembling a cost volume needs a document it can drop in rather than a slide it has to retype.