DHS is a holding company, not an agency
Vendors who fail at DHS almost always fail the same way: they write one capability statement addressed to "DHS," send it to a generic mailbox, and wait. There is no such buyer. The Department obligates north of $20 billion a year in contracts, and nearly all of that money is programmed, competed and administered inside components that share a seal and very little else. Customs and Border Protection buys like a large logistics and law-enforcement operator. The Transportation Security Administration buys like a regulated equipment fleet owner. FEMA buys like an insurer that occasionally becomes a war-room. The Coast Guard buys like an armed service. CISA buys like a security operations center with a national footprint. The winning move is to figure out which of those you are actually selling to, and go there directly.

Component autonomy is not an accident of culture. It follows the money. DHS headquarters sets policy through the Management Directorate, the Office of the Chief Procurement Officer and the CIO, but appropriations flow to component accounts and component program offices own the requirement. A headquarters contact who likes your technology can introduce you. A headquarters contact cannot buy it. The program manager inside CBP's Office of Information and Technology can, and so can the contracting officer supporting that office, and the two of them are the entire market for that requirement.
The second structural fact worth internalizing: DHS is one of the most small-business-friendly buyers in the federal government. The statutory government-wide prime goal is 23 percent under 15 U.S.C. § 644(g), and DHS routinely negotiates and hits a materially higher number. That is a real advantage for a firm with strong engineering and no past-performance dynasty, and it is why so much DHS technology work sits on small-business set-aside vehicles rather than on unrestricted full-and-open contracts.
What each component is actually buying
The table below is the shortest useful map of the five components that account for most technology demand. Read the right-hand column as the thing your capability statement has to speak to, because that is where the program office spends its own attention.
| Component | Buying posture | What earns a meeting |
|---|---|---|
| CBP | Highest technology spend in the Department. Large fielded systems, targeting and analytics, sensor and surveillance towers, mobile and biometric. | Evidence you can operate at national scale and integrate with existing targeting and case systems. CBP's Innovation Team (INVNT) inside the Office of Information and Technology runs the fast lane. |
| TSA | Equipment fleets plus the software wrapped around them. Screening algorithms, checkpoint data, credentialing, vetting. | A qualification story. Detection technology has to survive laboratory testing before it can be bought, and the Innovation Task Force is the demonstration path for anything new. |
| FEMA | Grants administration, flood insurance, logistics, and surge response contracting that behaves nothing like steady-state IT. | Data integrity and auditability. FEMA lives with GAO and Inspector General scrutiny on improper payments, so a defensible record beats a clever model. |
| USCG | An armed service inside a civilian department. Command-and-control, maritime domain awareness, sustainment, aviation and cutter systems. | Engineering credibility with the Research and Development Center in New London and with the C5I Service Center. Military systems discipline reads well here. |
| CISA | Cyber defense for federal civilian networks and critical infrastructure. Continuous Diagnostics and Mitigation, analytics, threat hunting, shared services. | Product qualification and operational proof at agency scale. CISA rarely wants a research idea; it wants something that runs on Monday. |
Two components deserve mention outside the table because they buy quietly and well. U.S. Citizenship and Immigration Services runs one of the most software-native shops in the federal government, with genuine agile delivery practice and a long history of buying development capacity rather than finished products. And the Secret Service, small by comparison, buys focused technology for protective operations and financial crime investigation. Both are reachable by a small firm with real engineers.
Entry Difficulty for a New Technology Vendor — Editorial Read
Editorial weighting from public sources and practitioner reading: illustrative, not a measured statistic.
The vehicles that carry DHS technology work
DHS built its own IT services franchise around EAGLE, the Enterprise Acquisition Gateway for Leading-Edge Solutions. EAGLE II reached the end of its life and the Department did not replace it with a single monolith. Today a large share of DHS IT services flows through GSA governmentwide vehicles, through component-level IDIQs and blanket purchase agreements, and through a smaller set of Department-wide contracts that are worth knowing by name.
FirstSource III. The Department's small-business set-aside route for IT commodities, software licenses and value-added reseller work. If your product is licensed rather than delivered as labor, this is often how it physically reaches a DHS end user, even when the program office chose you on the merits months earlier.
PACTS III. A service-disabled veteran-owned small business IDIQ covering program management, administrative and technical services. It carries a surprising volume of analyst and technical support work across components.
GSA MAS and the governmentwide acquisition contracts. DHS contracting officers reach for GSA Multiple Award Schedule SINs and for GWACs such as Alliant 2, 8(a) STARS III and VETS 2 constantly, because ordering under them is fast and the competition pool is pre-vetted. OASIS+ has become a common home for professional and technical services task orders. If you are choosing where to invest, our read is that a GSA MAS contract under the IT professional services and cloud SINs is the single highest-yield vehicle for a technology firm selling to DHS.
Component vehicles. CBP, TSA and USCIS each maintain their own multiple-award IDIQs and BPAs for development and engineering support. These are where recurring work actually lives. Getting on one is a competition of its own, usually announced twelve to eighteen months ahead in the forecast, and missing that window means waiting for the next option cycle.
Other transactions. DHS holds standing other-transaction authority for research, development and prototype projects under 6 U.S.C. § 391. That authority is what lets S&T and CBP write agreements that are not FAR contracts, with negotiated intellectual property terms and much shorter award timelines. For a firm with working software, an OT prototype agreement is frequently the fastest legal path from demonstration to paid work.
The S&T door
The Science and Technology Directorate is the Department's research arm and the most accessible entrance in the building for a technically strong firm without a DHS track record. S&T funds work on behalf of the operating components, which means an S&T award comes with an operational sponsor already attached. Four channels matter.
The Long Range Broad Agency Announcement. S&T keeps an LRBAA open on a rolling basis with published research areas. Entry is a short white paper rather than a full proposal, which makes it cheap to try. A white paper that survives review earns an invitation to submit full, and the review is done by people who own the operational problem.
DHS SBIR. Topics originate with the components and are administered by S&T. Phase I is roughly $150,000 for about six months and Phase II runs up to $1 million over two years. The DHS program is smaller than the Defense Department's and moves more slowly, but the topics are written by the operator who will use the result, and S&T's Transition to Practice work exists specifically to move Phase II technology into component hands.
The Silicon Valley Innovation Program. SVIP awards non-dilutive funding under other-transaction authority, structured as four sequential phases of up to $200,000 each, up to $800,000 in total, with a go or no-go decision at each gate. Solicitation calls are narrow and operationally specific. The program is built for companies with something already running, and the phase gates keep the government's exposure small while giving a vendor real money and a real component sponsor.
The national laboratories and centers. S&T operates specialized facilities including the Transportation Security Laboratory, the National Urban Security Technology Laboratory and the Chemical Security Analysis Center, and it funds university Centers of Excellence. These are testing and evaluation partners as much as research shops. For detection and sensing technology, getting evaluated at the right lab is a prerequisite to being bought, not a nice-to-have.
Component technical gates that are easy to miss
Each component adds its own qualification layer on top of the acquisition process, and each one has ended vendor pursuits that were otherwise going well.
TSA maintains qualification requirements for screening technology. Detection equipment and the algorithms inside it are tested against classified detection standards at the Transportation Security Laboratory, and equipment must appear on the qualified products list before an airport deployment is possible. A vendor who plans a sales cycle without budgeting time and money for qualification testing has planned the wrong cycle. The Innovation Task Force is the pressure-relief valve here, running airport demonstrations of emerging technology outside the formal acquisition path so that operators can see something before a requirement exists.
CISA has an analogous gate on the cyber side. Tools that agencies buy with Continuous Diagnostics and Mitigation funding must be on the CDM Approved Products List, which is reached through the GSA schedule's CDM special item number and requires the product to be validated against program requirements. CISA's shift from the legacy National Cybersecurity Protection System toward the Cyber Analytics and Data System has also changed what the agency wants from vendors, moving emphasis toward data engineering, telemetry normalization and analytics at scale rather than perimeter sensors.
FEMA operates under rules that exist nowhere else in the Department. Under the Stafford Act at 42 U.S.C. § 5150 and FAR subpart 26.2, contracts for disaster relief work carry a preference for firms residing or doing business primarily in the affected area, and vendors who want disaster work must be listed in the Disaster Response Registry in SAM.gov under FAR 26.205. FEMA also pre-positions advance contracts so that capacity exists before an event. If your interest in FEMA is data and analytics rather than debris removal, the steady-state grants and insurance systems are the better target, and they are procured on ordinary timelines.
Getting the first meeting
DHS publishes more of its intent than almost any other department, and most vendors never read it. The path below is the one our team uses when opening a component, and every step in it is public and free.
Opening a DHS Component — Working Sequence
Two of those steps carry most of the weight. The Acquisition Planning Forecast System is the Department's public list of anticipated procurements, and it names a point of contact for each planned action. That is an invitation to have a market-research conversation before a requirement hardens, which is the only moment when a vendor can still influence how a requirement is written. Vendor Outreach Sessions are scheduled one-on-one appointments with the small business specialist for a specific component, and unlike a booth at a conference they produce a named human who owes you a follow-up.
The answer to a sources-sought notice deserves more care than most firms give it. The contracting officer is doing market research to decide whether to set the requirement aside for small business and whether the technical approach is feasible. A response that names the approach, the data, the interfaces and the risks tells that officer the requirement is achievable by a small firm. A response that recites your corporate history tells them nothing.
Security and suitability: the gate that surprises people
The most common schedule surprise at DHS is not technical. It is that your engineers cannot start work on the day the contract starts. DHS requires a favorable fitness determination before a contractor employee gets access to Department information or facilities, and that process runs on its own clock.
The governing document is DHS Instruction 121-01-007, the Personnel Suitability and Security Program, and the contract mechanism is HSAR 3052.204-71, Contractor Employee Access, which appears in nearly every DHS technology contract. Under it, each employee needing access completes the standard forms, an SF-85P for public trust positions or an SF-86 for national security positions, submits fingerprints, and waits for the component security office to issue an entry-on-duty determination. Background investigations are conducted by the Defense Counterintelligence and Security Agency as the governmentwide investigative service provider. Six to twelve weeks is a reasonable planning assumption for public trust; national security positions take longer, and some components apply additional vetting standards of their own on top of the Department baseline.
Physical and logical credentials follow the same path. Homeland Security Presidential Directive 12 and FIPS 201 govern the PIV card an employee needs to badge into a facility or authenticate to a Department network, and a card cannot be issued before the investigation clears. Plan the first sixty days of any DHS task order assuming a subset of the team is still in process.
- Start vetting paperwork the week of award, not the week of kickoff
- Budget non-billable ramp time for staff waiting on entry-on-duty determinations
- Deliver the IT security plan required by HSAR 3052.204-70 within thirty days after award
- Map your handling controls to the DHS 4300A Sensitive Systems Policy baseline before you touch component data
- Meet the CUI safeguarding and incident-reporting terms in HSAR 3052.204-72, including training for every person with access
- Confirm whether the work requires a facility clearance under the National Industrial Security Program, and plan a sponsor if so
Two clauses drive most of the technical compliance work. HSAR 3052.204-70 requires a contractor to submit an IT security plan within thirty days after award and to obtain accreditation before operating a system on behalf of the Department. HSAR 3052.204-72 carries the Department's controlled unclassified information terms, including safeguarding requirements and short incident-reporting deadlines. Cloud-delivered software adds FedRAMP on top, and a component authorizing official will still run a DHS-specific authorization review even when a FedRAMP package already exists.
The Procurement Innovation Lab changes how you should write
DHS runs a Procurement Innovation Lab that tests streamlined source-selection techniques on real acquisitions: oral presentations instead of written volumes, technical demonstrations, confidence-based ratings rather than adjectival scoring, on-the-spot consensus, and phased down-selects. When a solicitation is flagged as a PIL project, the evaluation is likely to reward a team that can show working software and answer questions live, and to punish a firm whose strength is proposal writing. Read the section L instructions closely; the format is often the real test.
What a strong DHS approach looks like
Precision Federal builds AI, data and software systems for federal customers, and the pattern that works at DHS is consistent across components. Start with the operator's problem stated in the operator's words, taken from the forecast entry or the sources-sought notice rather than from a market report. Show the data path end to end, including where records come from, how they are validated, and what happens when a source is late or wrong. Name the security posture explicitly, because a component authorizing official is a real reviewer of your idea. And show the thing running. The engineers and domain specialists we assign to homeland security work build a functioning prototype early, because a fifteen-minute demonstration to a program office moves a pursuit further than a hundred pages of narrative.
The last piece is patience with a clear plan. DHS cycles are slower than Defense Department cycles and considerably slower than commercial ones. A forecast entry seen in July may become an RFP in March. Firms that treat the intervening months as the work, answering RFIs, testing at the right laboratory, getting the vehicle in place, and starting their vetting paperwork early, arrive at the competition already known. Firms that discover the opportunity when the RFP drops are competing against people who helped shape it.
Common questions on the DHS approach
Is it worth pursuing DHS without an existing federal past performance record?
Yes, and DHS is one of the better places to start. The Department's small-business posture, the S&T research channels, and the availability of other-transaction prototype agreements all create entry points that do not require a long contract history. Technical depth substitutes for past performance in the research and prototype lanes in a way it cannot in a major systems competition.
Should a small technology firm chase a component IDIQ seat or a GSA schedule first?
Schedule first in most cases. A GSA MAS contract is faster to obtain, usable across every component and across other departments, and it makes you orderable the moment a program office decides it wants you. Component IDIQ seats are valuable but open on multi-year cycles, and chasing one that is three years from recompete consumes capacity you could spend winning work.
How different is DHS SBIR from the Defense Department's program?
Smaller, slower, and more tightly coupled to a named operational customer. DHS runs far fewer topics per year, each written by the component that will use the result, and the transition support is deliberate rather than incidental. Proposal quality bars are comparable; the pace of the process is not.
Does a firm need facility clearances to work at DHS?
Most technology work does not. The default requirement is a favorable fitness determination for each employee plus a PIV credential, which is a suitability process rather than a clearance. Classified work exists, particularly in intelligence and some CISA and Coast Guard programs, and that work follows the National Industrial Security Program with a sponsoring contract required before a facility clearance can be processed.
Frequently asked questions
Customs and Border Protection, by a wide margin, across targeting and analytics, surveillance and sensing, biometrics, mobile systems and the enterprise IT that supports the largest law enforcement workforce in the federal government. TSA and CISA follow, with different technical profiles.
An other-transaction prototype agreement under the authority at 6 U.S.C. § 391. S&T's Silicon Valley Innovation Program is the best-known structured version, awarding up to $800,000 across four phased gates. OT agreements avoid much of the FAR proposal cycle and allow negotiated intellectual property terms.
Plan on six to twelve weeks for a public trust fitness determination and longer for national security positions. The requirement flows from HSAR 3052.204-71 and DHS Instruction 121-01-007, and a PIV credential cannot be issued until the determination is favorable. Start the paperwork at award.
The Acquisition Planning Forecast System at apfs.dhs.gov lists anticipated procurements by component with estimated value, set-aside status and a named point of contact. Pair it with sources-sought notices on SAM.gov and with Vendor Outreach Sessions run by the DHS small business office.
For disaster response work, yes. The Stafford Act at 42 U.S.C. § 5150 and FAR subpart 26.2 create a preference for local firms in the affected area, and vendors must be listed in the Disaster Response Registry under FAR 26.205. FEMA's steady-state grants, insurance and analytics systems are procured on ordinary timelines.
