What DISA is, and why that matters to a vendor
The Defense Information Systems Agency is not a buying office that happens to run some networks. It is a combat support agency that operates the Department of Defense's worldwide transport and hosting layer, accredits the commercial clouds allowed to hold defense data, publishes the Security Technical Implementation Guides that every DoD system is graded against, and runs a contracting organization that issues a very large volume of the department's information technology awards. Any firm selling AI, machine learning, data engineering, or cloud work into DoD will meet DISA on the way in, whether or not DISA is the customer, because DISA sets the conditions the work has to satisfy.

The agency is headquartered at Fort George G. Meade, Maryland, having relocated from Arlington under the 2005 BRAC round, with major operating locations at Scott Air Force Base in Illinois, Columbus, Ohio, Oklahoma City, and forward field offices supporting the combatant commands. Its published organization describes a workforce in the tens of thousands once military, federal civilian, and contractor staff are counted together. The mission statement is short: conduct DODIN operations for the joint warfighter. Everything the agency buys traces back to that sentence.
One structural fact explains most vendor confusion. DISA is funded through a combination of direct appropriations and the Defense Working Capital Fund, which means a large share of its business is fee for service. DISA delivers circuits, hosting, collaboration tools, identity services, and cyber defense to paying customers: the military services, the combatant commands, and the Fourth Estate defense agencies. The requirement and the money often originate at the customer, and DISA is the delivery mechanism. A vendor who pitches only DISA and never the paying customer is talking to the wrong half of the transaction.
Reachability of DISA work for a small engineering firm
Editorial weighting from public sources and practitioner reading, illustrative rather than a measured statistic.
The dual hat, and what it does to requirements
The Director of DISA is dual hatted as Commander of Joint Force Headquarters Department of Defense Information Network, a subordinate command of U.S. Cyber Command. JFHQ-DODIN holds the operational authority to direct defensive actions across DoD networks. DISA holds the service provider role that supplies the capability those actions run on.
That arrangement shapes how technical requirements are written. An operational need identified by JFHQ-DODIN, faster detection of a class of intrusion, better visibility into east-west traffic, quicker enforcement of a configuration change, becomes a DISA capability requirement, which becomes a task order, which becomes work. Vendors who follow only the acquisition forecast see the task order. Vendors who follow the operational orders and the readiness inspection findings see the requirement about a year earlier. Command Cyber Readiness Inspections, run against DoD components, generate findings that turn directly into remediation and tooling requirements.
The offices that hold the budget
Directorate names shift with each reorganization; the functions do not. Learn the functions, then confirm the current titles against the agency's own organization page before you write anything addressed to a specific office.
- Hosting and Compute: Enterprise data centers, DoD cloud services, and the Joint Warfighting Cloud Capability program office. The home of most hosting and migration work.
- Cyber Security and Analytics: Endpoint security, cyber analytics, identity and access management, and the analytic platforms JFHQ-DODIN operates against.
- Operations and Infrastructure: The transport layer: DISN circuits, satellite and terrestrial links, network operations, and the global service desk.
- Services Development: Collaboration, voice and video, enterprise email and productivity, and the application portfolio DoD users touch daily.
- Emerging Technology: Zero trust experimentation, AI and machine learning pilots, 5G, and technology assessment ahead of program of record decisions.
- Procurement Services and DITCO: The contracting organization. The Defense Information Technology Contracting Organization at Scott AFB and Fort Meade writes the awards.
- Office of Small Business Programs: The set-aside advocate and the office that runs matchmaking around DISA industry events.
The networks, and where the boundaries fall
DISA operates the Defense Information Systems Network, the transport backbone carrying the unclassified NIPRNet and the SECRET-level SIPRNet. Getting a system onto either one is a governed process, not a network engineering task. The Connection Approval Process, tracked in DISA's SNAP system of record, requires an accreditation package, a registered system owner, and a defensible security posture before a connection is authorized.
The Joint Worldwide Intelligence Communications System is a common point of confusion. JWICS carries Top Secret and Sensitive Compartmented Information traffic and is operated by the Defense Intelligence Agency, not DISA, though it rides in part on DISA-provided long-haul transport. Intelligence Community systems follow Intelligence Community Directive 503 for risk management and ICD 705 for facility standards, a different governance chain from the DoD Risk Management Framework in DoD Instruction 8510.01. A vendor who conflates the two in a capability briefing signals inexperience in the first two minutes.
The practical consequence is that the classification of the target environment determines your entry cost. Unclassified development work at NIPRNet sensitivity is reachable with cleared-adjacent staff and a solid security package. SIPRNet work requires cleared people and, in most cases, a sponsored facility clearance. JWICS work requires TS/SCI access and an accredited space, which is a materially larger commitment.
Cloud brokerage, impact levels, and the language DISA speaks
DISA authors and maintains the DoD Cloud Computing Security Requirements Guide and acts as the DoD cloud authorizing official. A commercial cloud service that wants to hold defense data needs a DoD Provisional Authorization at the right impact level, built on top of a FedRAMP authorization rather than instead of one.
Impact Level 2 covers public and non-critical mission information. Impact Level 4 covers Controlled Unclassified Information. Impact Level 5 covers higher-sensitivity CUI and unclassified National Security Systems. Impact Level 6 covers information classified up to SECRET. IL4 and IL5 build on the FedRAMP Moderate baseline plus DoD-specific controls; IL6 builds on FedRAMP High plus the national security overlay in CNSSI 1253. The Secure Cloud Computing Architecture adds the connection pattern: traffic between a commercial cloud and the DODIN passes through a Cloud Access Point, with virtual datacenter security and management stacks in between.
For an AI or data firm this is the single most useful vocabulary to master. Saying "our pipeline runs at IL5 behind a Cloud Access Point, with the model artifacts stored inside the authorization boundary and no inference traffic leaving it" answers three evaluator questions at once. Saying "we are FedRAMP ready" answers none of them. Our engineers write the boundary description before the architecture diagram, because the boundary is what gets reviewed.
Zero trust and the FY2027 clock
The DoD Zero Trust Strategy, published in November 2022, organizes the department's target end state into seven pillars, 45 capabilities, and 152 activities. Ninety-one of those activities make up Target Level, which DoD components are directed to achieve across the enterprise by the end of fiscal year 2027; the remaining activities define Advanced Level. The DoD Zero Trust Portfolio Management Office under the DoD CIO tracks component progress against that list.
DISA's own implementation is Thunderdome, which began as a prototype other transaction agreement awarded in January 2022 at roughly $6.8 million and moved into production deployment across DoD after the prototype closed out. Thunderdome bundles software defined perimeter, identity-driven access, and application security stacks, and its expansion is the reason the older Joint Regional Security Stacks architecture is being retired.
The FY2027 date is the most reliable demand signal in the DISA portfolio. Every component owes evidence of activity completion, and evidence means instrumented data: device inventories, identity records, policy decision logs, and analytics that map telemetry to specific activities. That mapping work is engineering, it is unglamorous, and it is exactly the kind of scope a small team can own end to end.
The data DISA actually holds
Three categories matter for an AI or data proposal. First, cyber telemetry: endpoint security agent data across millions of DoD endpoints, network flow records, sensor alerts, and the analytic platforms that hold them, historically fielded as the department's big data platform supporting cyber situational awareness. This is the largest and most interesting corpus, and it is also the most access-restricted.
Second, infrastructure and service records: circuit inventories and telecom orders placed through DISA's ordering systems, service desk tickets, configuration baselines, and the working capital fund billing records that show who consumes what. This is a records and reconciliation problem before it is a machine learning problem, and it is frequently the place where an outside team can show value fastest.
Third, identity: DoD public key infrastructure, certificate issuance, and the identity attributes that feed access decisions. Zero trust turns identity from a directory into an analytic surface, because policy decisions have to be logged, explained, and audited.
None of these arrive as a clean dataset. Expect fragmented schemas, mixed retention rules, and boundaries that prevent joining two sources that obviously belong together. Design for that up front. Most federal AI projects stall at the data access step, not the modeling step.
Contract vehicles, and how work really flows
Very little DISA work reaches a firm as a fresh standalone competitive prime contract. It reaches firms as task orders against existing multiple-award vehicles, as delivery orders through other agencies' vehicles, or as subcontracts under an incumbent. The vehicle map is the map of the market.
| Vehicle | What it buys | How a small firm participates |
|---|---|---|
| ENCORE III | Broad IT services for DISA and DoD customers, with a ceiling reported at $17.5 billion across unrestricted and small business tracks. | Hold a seat on the small business track, or team with a holder for a defined workshare. |
| SETI | Systems engineering, technology and innovation work, ceiling reported at $7.5 billion, structured to reward non-traditional approaches. | Two pools including a small business pool. Watch for on-ramp notices posted through DITCO. |
| JWCC | Commercial cloud awarded in December 2022 to AWS, Google, Microsoft and Oracle, multiple-award IDIQ with a $9 billion ceiling. | Not a seat you can win. Position as the integrator or workload owner on a task order. |
| DEOS | Enterprise productivity and collaboration for DoD, a GSA blanket purchase agreement with a $4.4 billion ceiling. | Subcontract to the BPA holder; migration and data work sit under it. |
| GSM-O II | DODIN operations and network services, DISA's largest single operations services award. | Subcontract. The prime's small business liaison is the entry point. |
| Other transactions | Prototype projects under 10 U.S.C. § 4022, the authority Thunderdome was awarded under. | Nontraditional defense contractor status improves your standing. Direct agreement or consortium membership. |
DISA also buys through GSA vehicles including the Multiple Award Schedule and OASIS+, and through NASA SEWP for hardware and product-adjacent services. A GSA Schedule contract does not get you DISA work by itself, but its absence removes a fast ordering path a program office may prefer.
What DITCO needs from you
The Defense Information Technology Contracting Organization is the contracting arm, with its largest presence at Scott Air Force Base in Illinois and a Pacific office overseas. DITCO writes awards for DISA programs and, for telecommunications, for customers across DoD. Contracting officers there see a high order volume and reward proposals that are easy to evaluate.
Practically that means: a capability statement written to a named directorate and a named program rather than to the agency generally; NAICS codes that match what the office actually buys, most often 541512, 541519 and 541715; a SAM.gov registration in active status with no exclusions; and past performance framed as the specific technical task you would own. When a program office asks industry for input through a sources sought notice, answer the question that was asked and state clearly whether the work can be performed as a small business set-aside. That single sentence influences the acquisition strategy more than the rest of the response.
The security gates that decide whether you can bid at all
Several requirements act as hard filters. Treat them as go or no-go before investing capture hours.
- Facility clearance under 32 CFR Part 117, the codified NISPOM, sponsored by a government customer or a cleared prime. There is no self-service path.
- Personnel clearances at Secret for most SIPRNet-adjacent work and TS/SCI for intelligence-side environments, with position sensitivity designated as IT-I or IT-II.
- Cyber workforce qualification under DoD Manual 8140.03, which replaced the older 8570.01-M certification framework and phases qualification requirements into contract language.
- DFARS 252.204-7012 safeguarding of covered defense information, with 72-hour incident reporting, plus 7019 and 7020 requiring a current NIST SP 800-171 self-assessment score in SPRS.
- CMMC, whose program rule at 32 CFR Part 170 took effect on December 16, 2024, with the acquisition rule that inserts requirements into solicitations following in 2025 on a phased schedule.
- DFARS 252.239-7010 for cloud computing services, which binds the provider to the Cloud Computing SRG and to incident reporting obligations.
- Section 889 prohibitions at FAR 52.204-25 on covered telecommunications equipment, verified at registration and again at award.
Where a small engineering firm realistically fits
The honest shape of the opportunity is this. Enterprise transport, hosting, and service desk work goes to large integrators with the staffing depth to run global operations. The work that fits a small, senior engineering team sits one layer in: the discrete technical problems inside those programs that the prime would rather not staff and the government would rather not wait for.
That includes STIG-hardened container baselines and the automation that keeps them current; accreditation packages assembled in eMASS with real control evidence rather than narrative; data engineering that reconciles fragmented cyber and infrastructure records into something an analyst can query; model deployment inside an IL4 or IL5 boundary where nothing may leave; zero trust activity instrumentation that produces auditable completion evidence; and evaluation suites that tell a program office whether a delivered model performs on its own data. Each of these is a scoped deliverable with a testable definition of done, which is what makes it fundable as a subcontract line rather than a staffing body.
One more door deserves attention. A federal agency may award a Small Business Innovation Research Phase III contract on a sole source basis when the work derives from, extends, or completes an earlier SBIR effort, and the awarding agency need not be the agency that funded Phase I or Phase II. That means a technology matured under an Army, Navy, or DARPA SBIR can transition into a DISA-run environment without a new competition. For firms with an existing SBIR data rights position, this is the shortest legitimate path from a prototype to a DISA production environment, and it deserves a named target program rather than a general hope.
The first step, concretely
Do these five things in order, and expect the sequence to take a quarter, not a week.
One. Get the registration clean. SAM.gov active, UEI and CAGE current, NAICS codes set to 541512, 541519 and 541715, no exclusions, and a capability statement that names impact levels and clearance levels rather than adjectives.
Two. Read the last Forecast to Industry. DISA runs an annual Forecast to Industry event where each directorate briefs the acquisitions it expects to run, and the slides are posted publicly afterward. Pull the most recent deck and identify one program with a recompete or a follow-on inside the next eighteen months.
Three. Find the incumbent. Look the program up in USAspending and the federal procurement data system, identify the prime and the period of performance, and note whether the requirement has a small business subcontracting plan attached. It almost certainly does.
Four. Write one page to the prime. Address it to the small business liaison officer. Name the task you would own, the impact level you would work at, the clearances your people hold, and what you would deliver in the first ninety days. Do not send a corporate overview.
Five. Register with the government side in parallel. Contact the DISA Office of Small Business Programs, ask about matchmaking at the next industry event, and respond to every sources sought notice in your lane with a substantive technical answer.
The firms that get inside DISA are the ones that show up with a specific technical task, a security posture that already satisfies the gate, and the patience to work through the vehicle structure rather than around it. That is a solvable problem, and it rewards engineering depth more than it rewards sales volume.
Common questions on positioning
Should we chase a DISA prime award directly?
Rarely as a first move. Most DISA services work flows through existing multiple-award vehicles and their incumbents. A defined workshare under a prime produces revenue, a performance record, and a reference inside the program office, which is what makes a later prime bid credible. Set-aside task orders under vehicles you already hold are the exception worth watching closely.
Do we need a facility clearance before we start?
Not for every opportunity. Plenty of DISA-adjacent work happens at unclassified sensitivity with CUI handling requirements only. A facility clearance becomes necessary for classified performance, and it must be sponsored by a government customer or a cleared prime with a contract that requires it. Sequence it against a real requirement rather than pursuing it speculatively.
How does FedRAMP relate to DoD impact levels?
They stack rather than compete. A DoD Provisional Authorization at IL4 or IL5 builds on a FedRAMP Moderate authorization plus DoD-specific controls, and IL6 builds on FedRAMP High plus the national security overlay. FedRAMP is a prerequisite step, not a substitute. Our team treats the boundary diagram and the control inheritance story as the first deliverable on any cloud-hosted federal build.
Is DISA a realistic target for AI work specifically?
Yes, though the framing matters. The demand is less about novel model architectures and more about applied analytics on operational data: anomaly detection in network telemetry, reconciliation across service records, evaluation of delivered models against mission data, and instrumentation that produces audit evidence. Proposals that lead with model novelty land worse than proposals that lead with the operational decision the model improves.
Frequently asked questions
DISA is a DoD combat support agency that operates the department's global network and hosting infrastructure, provides enterprise services such as collaboration and identity, accredits commercial cloud offerings for defense data, publishes DoD security configuration guidance, and runs a large IT contracting organization. Its director is dual hatted as commander of Joint Force Headquarters DODIN.
ENCORE III for broad IT services, SETI for systems engineering and innovation work, JWCC for commercial cloud, DEOS for enterprise productivity, and GSM-O II for network operations. DISA also orders through GSA vehicles and NASA SEWP, and awards prototype other transactions under 10 U.S.C. section 4022.
Impact Level 4 covers Controlled Unclassified Information, Impact Level 5 covers higher-sensitivity CUI and unclassified National Security Systems, and Impact Level 6 covers information classified up to SECRET. IL4 and IL5 build on the FedRAMP Moderate baseline with DoD-specific controls added; IL6 builds on FedRAMP High with the national security overlay.
DISA operates the Defense Information Systems Network, which carries NIPRNet and SIPRNet, and it runs the connection approval process for both. JWICS is operated by the Defense Intelligence Agency for Top Secret and SCI traffic, though it uses DISA-provided long-haul transport in part. The governance chains differ, and mixing them up in a proposal is a visible error.
Some of it. Unclassified work involving CUI is reachable with a strong security package, a current SPRS score, and CMMC readiness. Classified performance requires cleared personnel and a sponsored facility clearance, so the practical route is to start with unclassified scope under a cleared prime and let the clearance follow a contract that requires it.