What SOSSEC is
SOSSEC, Inc. is a consortium management firm based in Salem, New Hampshire. It does not sponsor work and it does not fund anything. What it does is hold base other transaction agreements signed with government sponsors, recruit and administer the member companies eligible to compete underneath them, and run the competition and negotiation cycle for each individual project agreement. In the vocabulary the Department uses, it is the Consortium Administrative Organization: the entity with the legal authority to speak for, organize, and commit the consortium it represents.
That structure is worth stating precisely, because the word "consortium" makes people picture a club that lobbies for its members. It is closer to a clearing house. The government signs one agreement with the consortium. Members then compete against each other for project agreements issued under that base. The manager sits in the middle, distributing the calls, running the evaluations, and papering the awards.
SOSSEC runs two consortia rather than one, which is the first thing most write-ups get wrong. The firm's own materials name them as the SOSSEC Consortium and the SCEC Consortium — Sensors, Communications and Electronics. Membership materials state that SOSSEC, Inc. manages over 1,800 member companies across its two consortia, and that nearly 80% of that membership is non-traditional. Both numbers come from the manager rather than from a government audit, so treat them as the firm's own account of its size.
The acronym itself is rendered inconsistently across the internet. MITRE's acquisition reference names the managing firm System of Systems Consortium, Inc. Several vendor pages expand it as System of Systems Security Consortium. The manager's own site mostly just uses the letters. If you are writing a teaming memo, use SOSSEC, Inc. and cite the agreement by name — nothing downstream depends on the expansion, and getting it wrong in front of a sponsor is an avoidable tell.
Two consortia, two different portfolios
The SOSSEC Consortium is the broader of the two. Its published agreements reach across the Air Force, the Army, and one intelligence community customer, and its subject matter runs from defensive cyber to aircraft engines to spare-parts sustainment. Nothing about the name predicts the scope, which is why firms screen it out early and shouldn't.
SCEC is narrower and reads like an Army portfolio, because it is one. Its published capability areas are assured positioning, navigation and timing; mine, improvised explosive device and minefield detection and defeat; intelligence, surveillance, reconnaissance and targeting; tactical and deployed power; cyberspace operations; electronic warfare; intelligence analysis, exploitation and dissemination; mission command; and tactical and strategic networks. The sponsor described on that page is the Army's Command, Control, Computers, Communications, Cyber, Intelligence, Surveillance and Reconnaissance Center, under Army Futures Command's development command. Anyone who has read a C5ISR Center portfolio will recognize all nine areas immediately.
For a software or data firm, that nine-item list is a better targeting document than any capability brief. Seven of the nine are, in practice, bought as software: PNT resilience, ISR and targeting, cyberspace operations, electronic warfare, intelligence analysis, mission command, and networks. The two that are not — detection and defeat hardware, and deployed power — still carry algorithm and instrumentation work underneath them.
The eight agreements
SOSSEC publishes its current agreements by name and sponsor. This is the whole list, with what each one means for a firm that writes software. Scope language is the manager's; the reading in the last column is ours.
| Agreement | Government sponsor | Published scope | What software work looks like here |
|---|---|---|---|
| COBRA Cyberspace Operations Broad Responsive Agreement | Army Program Executive Office Enterprise Information Systems | Defensive cyberspace operations prototypes, delivered through an acquisition process the office calls C-RAPID | Detection and triage tooling, host and network telemetry pipelines, analyst workflow, model evaluation harnesses |
| AFLCMC/ACI Air Force Consortium Initiative | Air Force Life Cycle Management Center | Development, test, integration and delivery of C4ISR information-sharing systems | Interface and integration work against named mission systems, data conditioning, cross-domain transfer support |
| AFRL OTAFI | Air Force Research Laboratory | Prototyping and testing of C4ISR technologies | Applied machine learning, autonomy components, experimentation and evaluation infrastructure |
| PCI 2.0 and the Propulsion Directorate agreement | Air Force Life Cycle Management Center, Propulsion Acquisition Directorate | Propulsion prototyping including digital engineering, artificial intelligence, engine health monitoring, small engines, and platform integration | Anomaly detection on engine telemetry, prognostics, model-based engineering tooling, test-data pipelines |
| SCCI Supply Chain Consortium Initiative | 448th Supply Chain Management Wing | Research, development, test and evaluation for military aviation supply chain and sustainment | Demand and reliability forecasting, parts-record extraction, sustainment analytics |
| ERDC | Army Engineer Research and Development Center | Protective structures, geophysical sensors, vulnerability assessment, mobility enhancement, infrastructure technologies | Sensor signal processing, geospatial and structural modeling, simulation tooling |
| NGA agreement | National Geospatial-Intelligence Agency, Office of Ventures and Innovation | Prototypes supporting the National System for Geospatial-Intelligence; published at roughly a $30M ceiling for multiple project awards | Imagery and geospatial analytics, data conditioning, tradecraft automation |
Two notes on reading that table. First, the propulsion line covers two separately listed agreements, and the manager lists them under slightly different office designations; if propulsion is your lane, ask which of the two a given call sits under, because the periods differ. Second, the NGA ceiling was published years ago. Ceilings on these agreements get raised, extended, and occasionally allowed to lapse. Confirm the current ceiling and period before you build a pipeline forecast on any of them.
What the $500 actually buys
SOSSEC's published annual membership fee is $500, and it is described as a single fee covering all SOSSEC OTAs. That is unusually clean. Several defense consortia scale dues by company revenue, and a few reach into five figures at the top band. A flat $500 across a multi-agreement portfolio is one of the lower barriers in the market.
Eligibility is broad: traditional and non-traditional firms, academic institutions, and non-profit organizations. Non-voting affiliate participation is available to national laboratories, university affiliated research centers, and federally funded research and development centers, which is a term the government agreement itself permits rather than a courtesy the manager extends.
What the fee buys is standing to compete. It does not buy an award, a contracting officer relationship, past performance, or a sponsor who knows your name. It puts you on the distribution list when a call goes out and makes your white paper eligible to be read.
The fee is also not the real cost of membership, and the second cost is the one that changes a price model. Consortium managers are generally compensated by a percentage assessment applied to each project agreement awarded under the base — that is how the model works across the market, and MITRE's acquisition reference describes it in exactly those terms. SOSSEC does not publish its rate. Get it in writing before you price a bid, because a percentage taken off the top of a fixed-price milestone schedule comes out of your margin, not the government's budget.
Three numbers to have before you build a price
The management assessment rate and whether it applies to the full award value or to a subset. Whether that assessment is billable as a direct cost on the project agreement or absorbed. And the payment cadence against milestones, since an agreement paying on demonstrated technical events rather than incurred cost changes how much working capital a project consumes. None of the three appear in the membership application, and all three change the arithmetic more than the $500 does.
The statute underneath all of it
Every one of these agreements rests on the same authority. Prototype other transactions for the Department of Defense sit at 10 U.S.C. § 4022, recodified from the old § 2371b. A separate section, § 4021, covers research other transactions. Because an other transaction is not a procurement contract, the FAR does not apply on its own — anything the FAR would have supplied has to be written into the agreement or it is simply absent.
The provision that decides whether a project can use the authority at all is § 4022(d)(1). At least one of four conditions must be met: a nontraditional defense contractor or nonprofit research institution participates to a significant extent; or every significant non-federal participant is a small business or a nontraditional defense contractor; or at least one third of total project cost comes from non-federal sources; or the senior procurement executive determines in writing that exceptional circumstances justify a business arrangement not feasible under a contract.
This is where a software firm holds something the team needs, and it is worth being blunt about why. The definition of nontraditional at 10 U.S.C. § 3014 turns on Cost Accounting Standards coverage, not on size or revenue — an entity that is not currently performing, and has not performed for at least the year preceding the solicitation, any DoD contract or subcontract subject to full CAS coverage. Most independent software and data firms clear that test comfortably. Bringing that status onto a team opens condition (d)(1)(A) for a prime that could not otherwise use the authority. That is a real bargaining position, and firms routinely give it away for free.
Two other subsections matter for planning. Dollar thresholds and approval levels appear at § 4022(a)(2), where prototype projects expected to cost more than $100,000,000 require a written head-of-contracting-activity determination and those above $500,000,000 require senior procurement executive approval plus a 30-day congressional notice. And § 4022(f) is the follow-on production provision: a production contract or transaction may be awarded without further competition when competitive procedures were used to select the prototype participants and the prototype was successfully completed. Almost every SOSSEC project agreement is far below those approval thresholds. Almost every one of them is theoretically within reach of (f).
Where software-shaped work actually sits
Not every agreement in the portfolio is equally reachable for a firm whose deliverable is code. The differences are large enough to change which calls are worth reading. The weighting below reflects how much of each published scope can be delivered as software or data work by a firm without a hardware line, a test range, or a facility clearance beyond the ordinary.
Share of published scope reachable as software work
Editorial weighting of published scope language. A judgement about reachability, not a measurement of award data.
The propulsion number is the one that surprises people, and it is the one worth arguing with. A 64% reading looks low next to the cyber line, but PCI 2.0's own published mission areas name digital engineering, artificial intelligence, and engine health monitoring before they name any hardware. The reason the score is not higher is that the remaining scope — materials, small engines, platform integration — genuinely requires a hardware partner. The practical read is that propulsion is a teaming lane for a software firm rather than a prime lane, and that most software firms never look at it because the word "propulsion" filters them out.
How work reaches a member
The sequence is the same across the portfolio, and it is short. What varies is the response window, which can be brutal on the cyber side where the sponsoring office built its process around speed.
From membership to a signed project agreement
Step five is where firms lose money they never see. The FAR clauses that would have set intellectual property defaults are not present. DFARS 252.227-7013 and 252.227-7014 attach when a contracting officer puts them in a contract, and here there is no contract for them to attach to. Whatever the project agreement says about rights in your code, your models, and your data is what is true. Arrive with a background intellectual property schedule already drafted and every pre-existing component listed on it. Anything unlisted is at risk of being read as developed under the agreement.
The COBRA lane in particular
COBRA is the agreement most software firms will care about first. The Army's Program Executive Office Enterprise Information Systems awarded it to SOSSEC for defensive cyber operations prototypes, with the stated purpose of spurring innovative development, demonstration, and expedited delivery of prototypes. Inside it sits an acquisition process the office calls C-RAPID, built around rapidly delivering prototypes to soldiers. Reporting at the time of award put the vehicle ceiling at $100 million over five years.
Two cautions about that figure. It is an award-era number, and the agreement has been in place long enough that the current ceiling and period should be confirmed rather than assumed. And a ceiling is a maximum, not a budget. What a ceiling tells you is the size of the container, not how much money the sponsor actually has this year. The question that predicts whether a call turns into an award is whether the program office has funds of the right appropriation on hand, and that question is answered by the sponsor, not by the consortium.
What makes the cyber lane different in practice is tempo. Offices that build a named rapid-prototyping process around an agreement generally run short response windows, and a firm that starts writing when the call drops is already behind one that had a technical position ready. The white paper is the whole first round. Five pages, a specific problem, a specific method, and evidence the method has been run on something real will beat a longer document that describes a company.
Straight answers on the parts people get wrong
Is SOSSEC the same organization as NSTXL?
No. They are separate consortium management firms holding separate base agreements with separate sponsors. Some published consortia maps conflate them. If a teaming email says a SOSSEC agreement is accessed through another manager's membership, that email is wrong, and the fix is to check the manager's own agreement list.
Does the name mean it is only for security work?
No, and this is the single most expensive misreading of the acronym. The published portfolio spans aircraft propulsion, aviation supply chain sustainment, engineering research, geospatial intelligence, and C4ISR information systems as well as defensive cyber. Screening the manager out on the strength of how a third-party site expanded its acronym removes six agreements from your pipeline for no reason.
Does one membership cover both consortia?
The published fee is described as a single annual fee covering all SOSSEC OTAs. Whether that language reaches the SCEC Consortium, which sits under the same manager but is a separate consortium, is not something the public materials settle. Ask before assuming, particularly if the Army capability areas are the reason you are joining.
Can a firm with no defense work at all join?
Yes, and the membership is deliberately structured to attract exactly that firm. Non-traditional participation is what opens the statutory condition the sponsor needs. A commercial software company with no DoD history is more useful to a prototype team, in the narrow legal sense, than an incumbent with full Cost Accounting Standards coverage.
Bottom line
SOSSEC is worth understanding as a portfolio rather than as an organization. The manager is not the product. The eight agreements are, and they are heterogeneous enough that a firm can be a poor fit for six of them and a strong fit for two. Read the sponsor list, find the one or two sponsors whose mission your technical work already touches, and treat the $500 as the price of being allowed to read their calls.
The membership is cheap enough that the decision rarely turns on the fee. It turns on whether you have a technical position worth writing about when a call appears, and whether anyone on the sponsoring side has heard of you before the white paper arrives. Consortium membership solves the eligibility problem. It has never solved the second one, and no consortium manager has ever claimed it does.
Frequently asked questions
SOSSEC, Inc. is a consortium management firm that holds base other transaction agreements with government sponsors and administers the member companies that compete for project agreements under them. It manages two consortia, the SOSSEC Consortium and the SCEC Consortium, and publishes eight agreements across Air Force, Army, and National Geospatial-Intelligence Agency sponsors.
The published annual membership fee is $500, described as a single fee covering all SOSSEC other transaction agreements. The fee is not the whole cost. Consortium managers are typically compensated through a percentage assessment on each project agreement awarded, and that rate should be confirmed in writing before you price a bid.
Traditional and non-traditional firms, academic institutions, and non-profit organizations. Non-voting affiliate participation is available to national laboratories, university affiliated research centers, and federally funded research and development centers under the terms of the government agreement.
Not personally, but the project has to satisfy one of the four conditions at 10 U.S.C. § 4022(d)(1), and nontraditional participation to a significant extent is the most common route. The definition at 10 U.S.C. § 3014 turns on full Cost Accounting Standards coverage rather than company size, so most independent software firms qualify.
It can, but not automatically. Under 10 U.S.C. § 4022(f) a follow-on production award can skip further competition when competitive procedures were used to select the prototype participants and the prototype was successfully completed. Check that your project agreement contemplates a follow-on and defines "successfully completed" against measurable acceptance criteria rather than satisfaction language.
