There are two ways to meet a subcontracting goal. One is to find firms that resell hardware, license software, or supply staff at a markup, flow enough dollars through them to hit the percentage, and report it. The other is to build a roster of specialist firms that carry real technical scope on programs, and let the goal take care of itself as a consequence of how the work is actually divided. The first is faster in any given quarter. The second is the only one that produces a competitive advantage, and it is also the one that holds up when someone reads the plan closely.
This is written for the small business liaison officer at a large prime who is tired of the first approach: who has watched pass-through dollars produce no technical value, who has to defend performance against a plan at a review, and who suspects that the same money spent on firms doing real work would improve both the bid and the program. It is about how to build that roster, what to check, how to contract for it once, and what the relationship looks like between bids.
Why pass-through volume is expensive even when it is cheap
The dollars count the same on the report. Everything else is different.
It produces nothing on the bid. A subcontracting plan that names percentages with no firms attached, or names firms whose scope is supply rather than engineering, adds nothing an evaluator can score. A plan that names specific firms with specific technical scope, and shows a working relationship, reads as capability. Same percentage, different document.
It invites the wrong kind of attention. A prime whose reported small business volume is concentrated in resellers and staffing suppliers is a prime whose plan will be examined more closely, by contracting officers, by agency small business offices, and eventually by whoever reviews performance against commitments. Volume that corresponds to identifiable technical work does not raise the question in the first place.
It teaches the organization nothing. When goals are met through purchasing, the program managers never work with a small specialist firm and never develop an opinion about which ones are good. The prime's institutional knowledge of the small business base stays at zero, and every pursuit that needs a specialist partner starts from a search.
It leaves the capability gap open. This is the real cost. Primes routinely need teams that have put AI models, data platforms or modern applications into production inside agencies, with the authorization work done. That capability is bought with relationships, and the goal budget is the natural place to build them. Spending it on pass-through means paying for compliance twice: once in dollars flowed, and again when a pursuit needs a partner nobody has vetted.
What a roster of delivering small businesses returns to a prime
Editorial weighting, illustrative rather than measured. The last row is low because the percentage is a byproduct of the others, not a goal on its own.
What a roster is, concretely
A roster is not a vendor list. A vendor list is everyone who has ever been registered in the purchasing system. A roster is a small number of firms, per capability area, that the prime has vetted, contracted with once, worked with on live scope, and can put on a bid tomorrow with a named point of contact and a known rate structure.
Size it deliberately. Two to four firms per capability area is usually right: enough for coverage when one is booked or conflicted out, few enough that each gets real volume and stays interested. A roster of forty firms is a list. A roster of two is a dependency.
Define the capability areas the way the prime's pipeline needs them rather than by industry code. For technology work that often means something like: applied AI and machine learning delivery; data engineering and platform work; cloud infrastructure and migration; application development and modernization; and human-centered design and accessibility. Each of those is a different bench, and a firm strong in one is frequently mediocre in another.
Vetting: the version that takes three weeks
The vetting is the part that determines whether the roster is real, and it does not have to be slow. Run it in this order because each step can end the process cheaply.
- One hour with their senior engineer about a system they deployed. Named, in production, inside a federal environment. Who sponsored it, what it does now, what was hardest to integrate, how it got authorized, what broke after go-live, and how long the first deployment actually took. Engineers who have shipped answer in specifics; firms that have not answer with methodology. This single conversation eliminates most candidates.
- Two hours of engineering review with one of the prime's engineers. Look at a repository, a test suite, a deployment from a clean checkout, and the infrastructure as code. Ask how secrets are handled and how a change reaches production. This is the cheapest high-value hour in the entire process and almost nobody spends it.
- One hour on security posture and data rights. What is in place today for handling controlled unclassified information, where covered data would sit, how access is granted and removed, what the incident process is, and how fast a reportable incident reaches the prime. Then the data-rights position: what they bring as background, what they consider developed under a contract, and whether they can produce an assertions table.
- Subcontracts diligence in parallel. Active registration and current representations confirmed in the government system, exclusions searched, accounting system type confirmed, two years of financial statements, insurance certificates at the flow-down limits naming the right entity, and an honest number for revenue concentration.
- People and capacity. The named engineers who would work on the prime's programs, what each did on the systems discussed, what else they are committed to, and what happens if a start date slips two quarters, which is the normal outcome.
- A small paid pilot if anything is uncertain. A scoped, real task at a size where a poor outcome costs a few weeks. This is the only diligence that is fully truthful, and it is worth the money on any firm the prime expects to carry scored scope.
Record the outcome somewhere the capture organization can find it. A one-page profile per firm: capability, systems deployed, named engineers, security posture, rate structure, contract status, who at the prime has worked with them, and the date of the last engagement. A roster nobody can search is a roster that does not exist when a solicitation drops on a Friday.
Contract once, issue work in days
The single biggest reason primes fall back on pass-through is friction. When issuing a subcontract takes six weeks and negotiating one takes twelve, the program manager under schedule pressure uses whatever instrument is already in place. Remove the friction and the behavior changes on its own.
The mechanism is a master subcontract, negotiated once per roster firm, with task orders issued underneath it. Pre-negotiate the terms and conditions, the flow-down set with the firm's positions on the ones that are negotiable, the rate structure or the pricing method, intellectual property and data-rights positions, security requirements and incident reporting, insurance, invoicing and payment terms. Then a task order carries only the scope, the deliverables and acceptance criteria, the period, the price and the named people.
Two details make or break it. The rate structure must be current and must have a mechanism for annual adjustment, otherwise it goes stale and every task order reopens pricing. And the flow-downs must be scoped to what actually applies, because a master agreement that flows down everything the prime's largest contract carries will not be signable by a firm that does not hold that kind of work, and the negotiation will stall for a quarter.
| Dimension | Pass-through supplier | Ad hoc subcontract per pursuit | Roster firm on a master subcontract |
|---|---|---|---|
| Time to issue work | Days, through an existing purchase instrument | Six to twelve weeks, if terms are agreed at all | Days, against pre-negotiated terms |
| Value on the technical volume | None an evaluator can score | Some, if the partner is credible and vetted in time | Named scope, named people, a working record |
| Who owns the outcome | The prime; the supplier owns delivery of goods | Negotiated per pursuit, often late and vaguely | The partner, against acceptance criteria in the task order |
| What the prime learns | Nothing about the small business base | Whatever survives one engagement | A durable opinion held by program managers |
| Plan performance quality | Dollars without corresponding technical work | Inconsistent and hard to forecast | Dollars that map to identifiable scope |
| Failure mode | Scrutiny, and a capability gap that stays open | The partner is picked under deadline and unvetted | The roster is built and then never fed work |
Pipeline visibility is the part primes withhold and should not
A roster firm can only prepare for what it knows about. The prime that shares its capture calendar eighteen months out gets partners who have built the specific capability the pursuit needs, written technical text in advance, and confirmed the availability of the engineers who will be named. The prime that shares nothing until a draft solicitation appears gets partners scrambling, and then complains that small firms are not ready.
Sharing does not mean handing over competition-sensitive material. It means telling a partner: this agency, this scope area, this expected timeframe, this is the technical evidence we will need, this is the shape of workshare we would offer. That is enough for a firm to invest. Where more is needed, the ordinary nondisclosure and exclusivity instruments exist for exactly this purpose.
The reciprocal obligation is worth stating too. A roster firm that is given pipeline visibility should be expected to tell the prime what it is seeing in the market, where it holds relationships, and when it is going to be tied up. Partners who bring opportunities to the prime are the ones the arrangement is supposed to produce.
The rhythm between bids
Most partner relationships decay in the quiet periods, and the decay is not about affection. It is about the specific facts going stale: the rate sheet expires, the named engineer leaves, the security posture changes, the firm's capacity shifts. When a solicitation drops, the prime is working from an eighteen-month-old profile and has to re-vet under deadline.
A light rhythm prevents this. A quarterly touch per roster firm, run by whoever owns the relationship, refreshing five things: current capacity and what they are working on, any change in named engineers, current rate structure, any change in security posture or registrations, and what they are seeing in the market. Twenty minutes on a written exchange, not a meeting. Update the profile the same day.
Then an annual review of the roster itself: which firms carried scope, which were bid and lost, which were never used and why, and whether the capability areas still match the pipeline. Firms that have been on the roster for two years with no work should either be given some or removed, because a roster with dead entries is a roster nobody trusts.
And keep an engineer-to-engineer channel open, separate from the business relationship. The most valuable thing a prime's chief engineer can have is a small number of specialists they can call to ask whether an approach is sound. That channel produces better bids than any amount of relationship management, and it costs nothing.
Why a roster goes stale, weighted by how often each is the cause
Editorial weighting, illustrative rather than measured. The last row is low because rosters almost always decay on the prime's side.
When the roster becomes a competitive advantage
The shift happens when the prime stops assembling teams for pursuits and starts selecting from a bench. Concretely, it looks like this. A solicitation appears with an AI and data component the prime cannot staff internally at the required depth. Within a day, the capture director can name two roster firms who have deployed comparable systems, pull their profiles, confirm availability, and have draft technical text from the firm's engineers within a week. The subcontract is already in place. The rates are current. The security posture is known. The teammate's past performance citations have already been reviewed. Nothing about the bid is a scramble.
The competitors who have not built this are, at that moment, sending introductory emails.
The second-order effect is on the subcontracting plan itself. When the roster carries real scope, the plan can name firms, describe their technical work, and point to a history of performance rather than a target percentage. That is a materially better document, and it is produced as a byproduct rather than as an exercise.
How we work on a prime's roster
Precision Federal is a small business engineering firm. We build AI systems, data platforms, cloud infrastructure and full-stack web and mobile software, and we deliver them into production inside federal agencies. We work as a specialist subcontractor, teaming partner, protégé and nontraditional partner on other transaction agreements. We take a scope and answer for it rather than supplying hours, and that distinction is the reason to have us on a roster rather than a vendor list.
We vet the way this article says to vet. We will name systems, name the engineers who built them, describe what broke and what changed, and sit with a prime's chief engineer to look at repositories, pipelines and deployments. We will state our data-rights position in writing and produce an assertions table for a proposed scope. We will describe our security posture as it stands, with the assessment and plan behind it.
What a prime gets in the first weeks is concrete. Week one: a written technical position on the scope we would own, with risks named. Weeks two and three: a scoped, priced statement of work with acceptance criteria written as tests rather than adjectives, and, on a live pursuit, draft technical volume text a proposal manager can edit rather than rewrite. On a master subcontract, we will negotiate terms once and then respond to a task order within days.
What the prime keeps is everything a prime should keep. The customer relationship is the prime's and we do not go around it. Code, models, pipelines and documentation are delivered under the assignment terms of the subcontract, with our pre-existing tooling named, carved out and licensed back so nothing is stranded. Markings and assertions are settled before the first delivery. On a proposal we are named and stand behind our resumes where that strengthens the technical volume, and we work behind a single face to the customer where the capture strategy calls for it.
Pricing takes one of two shapes: fixed-price milestones against written acceptance criteria where the scope is definable, or a committed team at an agreed allocation for a stated period where the program needs sustained capacity. Both are quoted against a rate structure that supports the flow-downs the prime's contract carries.
The first step is one email with a one-page brief: the program or pursuit, the technical scope, the environment the result must live in, the security destination, the date that matters, and the contract instrument. We return a scoped, priced statement of work. If the fit is not there, we say so in the same reply.
Bottom line
Goals met with pass-through volume cost more than they appear to, because they buy compliance and leave the capability gap open. A roster of two to four vetted specialist firms per capability area, each on a master subcontract with pre-negotiated terms and a current rate structure, turns the same budget into bidding capability. Vet in three weeks, in the order that ends the process cheapest: a conversation with their engineer about a deployed system, an engineering review of real code, a security and data-rights conversation, and ordinary subcontracts diligence in parallel. Share the pipeline eighteen months out. Refresh the profile quarterly in twenty written minutes. Then the day a solicitation drops, the team is selected rather than assembled, and the plan writes itself out of work that actually happened.
Frequently asked questions
Build a roster of two to four vetted specialist firms per capability area and give them real technical scope on programs. The percentage then follows from how the work is divided rather than from purchasing volume. The difference shows up on the bid, because a plan that names firms with specific technical scope and a working record reads as capability, while a plan of percentages with nobody attached adds nothing an evaluator can score.
One hour with their senior engineer about a system they deployed into a federal environment, which eliminates most candidates. Two hours of engineering review with a prime engineer looking at a repository, tests, a deployment from a clean checkout and infrastructure as code. One hour on security posture and data rights. Subcontracts diligence in parallel: registration, exclusions, accounting system, financials, insurance and revenue concentration. A small paid pilot if anything is still uncertain.
It is an agreement negotiated once per partner, carrying the terms, flow-downs, rate structure, intellectual property and data-rights positions, security requirements, insurance and payment terms, with task orders issued underneath it. It matters because friction is the main reason primes fall back on pass-through: when a new subcontract takes months, a program manager under schedule pressure uses whatever is already in place. Pre-negotiated terms let work be issued in days.
Enough that the partner can prepare: the agency, the scope area, the expected timeframe, the technical evidence the prime will need, and the shape of workshare on offer. That is enough for a firm to invest in building the right capability and confirming the engineers who will be named. Nondisclosure and exclusivity instruments exist where more detail is warranted. Withholding everything until a draft solicitation appears is what makes small partners look unprepared.
A quarterly written exchange of about twenty minutes per roster firm, refreshing five facts: current capacity, any change in named engineers, current rate structure, any change in security posture or registrations, and what they are seeing in the market. Update the profile the same day. Then review the roster annually and either give work to firms that have carried none or remove them, because a roster with dead entries stops being trusted.
