Government Technology Review

Federal Acquisition Regulation Overview for Technology Purchases

Understand where federal IT dollars flow and which contract vehicles actually move technology deals.

Senior Writer · · 10 min read
Cover illustration for “Federal Acquisition Regulation Overview for Technology Purchases”
GovTech Procurement · August 12, 2026 · 10 min read · 2,311 words

The federal government spent roughly $793 billion on contracts in FY2025, a $17.8 billion inflation-adjusted increase over FY2024, according to the GAO. Federal IT investment accounted for $102.31 billion of that total, with $30.696 billion directed toward major investments including modernization initiatives.

Here is where vendors frequently miscalibrate: agencies have historically spent approximately 80% of their IT budgets maintaining legacy systems, leaving only about one-fifth available for new technology. Whether your solution is pitched as modernization or operations support is not a branding question; it determines which budget line you are competing for. The market for each is real, but they are different markets with different buyers, different timelines, and different internal champions.

Software licenses alone represent roughly $20 billion in annual federal spending. The top three vendors by payment volume are Microsoft at 30%, Adobe at 10%, and Salesforce at 9%. That concentration is not closure. It tells you which categories agencies have largely standardized around, which is useful intelligence about where you face entrenched incumbency versus real opportunity. Those two calculations are entirely distinct.

On the civilian side, DHS leads proposed FY2025 IT spend at $11.116 billion, followed by HHS at several billion dollars, Treasury at several billion dollars, and VA at several billion dollars. Those four agencies collectively represent more than half of civilian IT investment. If you are targeting civilian business, that is where the addressable volume actually lives. Go where the money is, then figure out how to get to it.

One complicating factor that rarely surfaces in federal market pitches: civilian agency IT contract obligations fell 11% from FY2024 to FY2025, with a 37% drop in products. Part of that contraction is attributed to elevated contracting officer vacancy rates. The procurement workforce shortage creates a real and frustrating market condition that slows solicitations, extends award timelines, and builds bottlenecks that even a fully compliant vendor cannot accelerate around. No amount of sales energy fixes a contracting office that is simply understaffed.

Diagram: Where Federal IT Dollars Actually Flow. Visualizes: Visualize the cascade of federal IT spending from the total down to the slice available for new technology.

How FAR Part 39 Specifically Governs Technology Acquisitions

Part 39 is the FAR's dedicated chapter for IT acquisitions. In June 2025, the FAR Council issued a class deviation replacing the prior version with a modernized framework built around information and communication technology (ICT), rather than the narrower legacy term "information technology."

That framing shift matters more than it sounds. ICT now explicitly encompasses AI and machine learning platforms, edge devices, 5G infrastructure, IoT sensors, and operational technology. These categories previously occupied regulatory gray zones where agencies either avoided them or improvised compliance arguments on a case-by-case basis. The new language resolves that ambiguity. Vendors in those spaces no longer have to argue their way into a procurement category; the category now exists for them, which is a relief if you have ever tried to explain to a contracting officer why your sensor network is, in fact, an IT purchase.

Three specific provisions define how the revised Part 39 actually functions in practice.

First, modular contracting under FAR 39.102. Short, iterative procurements are now the structural norm, with deliverables expected within tight timeframes, frequently under 18 months from solicitation issuance. If your implementation model is a multi-year waterfall build, the FAR now works against you by design. That is a deliberate policy choice to reduce the risk of large-program failure, and it is probably the right one, given the federal government's track record with large-program failure.

Second, cybersecurity. The legacy clause 52.239-1 has been retired. Cybersecurity requirements are now embedded in FAR 4.19 and clause 52.204-21, a shift from passive enforcement to mandatory baseline compliance written directly into the contract structure. More on this shortly, because the implications extend well beyond a clause number swap.

Third, Section 508 accessibility. Every ICT product or service must comply, or the agency must obtain a documented, approved exemption. Even exempted products must offer alternative access methods. Non-compliance creates legal exposure, and contracting officers know it.

The revised Part 39 still leaves significant gaps. The Information Technology Industry Council has called for the framework to explicitly require commercial terms and conditions when the government buys commercial technology, and to align modular contracting timelines with how the private sector actually develops software. Those asks remain unresolved. The gap between current rules and commercial practice is real, and vendors live in that gap every day, sometimes productively and sometimes not.

The Contract Vehicles That Channel Technology Purchases

Most federal technology spending does not flow through individual agency solicitations. It moves through pre-competed, multiple-award vehicles that agencies use without reopening full competition. Understanding vehicle architecture is, in a practical sense, more important than understanding any individual procurement. And yet it is consistently the thing first-time federal vendors skip, usually because it is less exciting than writing the technical proposal.

Governmentwide Acquisition Contracts (GWACs) are pre-competed, multi-award IT contracts available across all federal agencies. GSA's OASIS+, NASA SEWP, and NIH CIO-CS are the primary examples. Being on a GWAC is frequently a prerequisite for competing on large agency IT opportunities. If your company is on none of the relevant vehicles, you are typically not in the competition, regardless of how good your solution actually is.

The GSA Multiple Award Schedule (MAS) is the broadest on-ramp into federal technology buying. GSA has been actively adding AI solutions to MAS as part of the AI Action Plan implementation, making it an increasingly relevant channel for vendors in emerging technology categories. Worth watching closely.

Agency-specific indefinite-delivery, indefinite-quantity (IDIQ) contracts offer volume but require separate on-ramping per agency. For vendors with deep relationships in one or two agencies, this works well. For those trying to scale across the civilian enterprise, the per-agency on-ramping cost compounds quickly and quietly erodes the economics of growth.

For smaller companies, updated thresholds under FAC 2025-06 create a meaningful entry point. The micro-purchase threshold rose from $10,000 to $15,000, and the simplified acquisition threshold increased meaningfully. Below these thresholds, compliance burden is materially reduced. Not eliminated, but reduced.

Vehicle positioning should precede proposal strategy, not follow it. Experienced federal contractors understand this sequencing intuitively. For everyone else, it is a lesson learned after losing the first bid, which is an expensive way to learn something that could have been discovered by reading this sentence.

Table: Federal IT Contract Vehicles Compared. Compares Scope, Competition Model, OneGov Priority, Best For, and 1 more by GWACs (e.g. SEWP, OASIS+), GSA Multiple Award Schedule and Agency-Specific IDIQs.

GSA's OneGov Consolidation Push and What It Means for Vendor Positioning

In March 2025, Executive Order 14240 designated GSA as the executive agent for governmentwide IT acquisition contracts and directed consolidation of common-goods purchasing. The result is the OneGov strategy, under which agencies are being directed to use governmentwide "best-in-class" and "preferred" contracts rather than maintaining their own vehicles for common technology categories.

OneGov's scope covers exactly the categories most relevant to mid-market technology vendors: software platforms, cloud services, collaboration tools, AI, cybersecurity, and enterprise applications.

GSA reported roughly $1.1 billion in taxpayer savings in the first year through 20 unified technology agreements. That figure is the administration's primary proof point, and it will drive continued centralization whether or not individual agencies prefer their own arrangements.

The efficiency argument underlying consolidation is not invented. Different agencies paying different prices for identical products, repeated duplicative market research, parallel vehicle maintenance across dozens of agencies: the inefficiency is real and worth fixing. Whether consolidation captures the full benefit without introducing new friction is a legitimate question, one that has yet to be fully answered. But the directional shift shows few signs of reversing, and GSA's establishment of the Office of Centralized Acquisition Services in 2026 makes that permanence structural rather than rhetorical.

For vendors, the practical implication is uncomfortable: agency-direct relationships without a GSA vehicle are becoming progressively harder to sustain for common technology categories. Getting on GSA MAS or a GWAC has moved from growth strategy to table stakes. Whether that is good policy depends on whom you ask.

The Revolutionary FAR Overhaul and What Changes Are Already in Effect

The FAR is 41 years old and had, by most credible accounts, grown into something that treats a laptop purchase with the same regulatory weight as a weapons system acquisition. A 2024 Senate committee report and a 2019 advisory panel both concluded it had become a meaningful barrier to commercial technology companies entering the federal market. That conclusion was not controversial among people who had actually tried to navigate the process.

Executive Order 14275, issued in early 2025, directed that the FAR should contain only provisions required by statute or essential to sound procurement. More than 500 burdensome requirements have already been eliminated, with over 1,000 total expected to be removed when the rollback is complete, against a backdrop of nearly $1 trillion in annual federal procurement.

OMB Memorandum M-25-26 structured the reform in two phases. Phase 1 operates in FY2025 through class deviations replacing each FAR part immediately; agencies can already act on these. Phase 2 consists of formal proposed rulemaking through the Federal Register with public comment periods, including the June 2025 Part 39 ICT revision discussed earlier. Under the August 2025 announcement, agencies are authorized to immediately eliminate one-third of contract requirements not required by statute or executive orders.

Beyond clause deletion, proposed rules reorganize the FAR by acquisition phase and rewrite provisions in plain language with active voice. Achieving that goal for a 2,600-page regulatory framework is a substantial undertaking, and anyone who has tried to edit a 2,600-page document into clarity will appreciate just how ambitious that actually is.

One concern raised by public commenters deserves mention: updating workforce certifications, including alignment to the NICE Framework, too frequently creates its own compliance burden. Simplifying the rulebook does not automatically simplify the competency requirements for the people executing under it. Regulatory reform has a way of shifting burden rather than eliminating it.

Cybersecurity Compliance Requirements That Now Travel with Every Technology Contract

FAR 52.204-21, the Basic Safeguarding of Covered Contractor Information Systems clause, is now the mandatory baseline. Not optional. Not agency-discretionary. Every technology vendor operating on a federal contract is required to meet its provisions, and that includes cloud offerings, which must typically operate within FedRAMP-authorized environments.

FedRAMP authorization requires significant time and investment, and it must be completed before a cloud offering is broadly usable on federal contracts. Vendors who treat it as a post-award concern are mispricing both their timeline and their cost structure, sometimes by enough to make the contract unprofitable.

For defense-adjacent vendors, the Cybersecurity Maturity Model Certification (CMMC) adds a third-party certification layer on top of the FAR baseline. The CMMC program rule was published in the Federal Register in October 2024. The tier applicable to any given contract depends on the sensitivity of the information involved, which means there is no single standard to achieve; there is a range of possible requirements depending on what work you pursue. That ambiguity is uncomfortable, and it is intentional.

Three practical realities follow from this. Cybersecurity compliance costs must be built into pricing before bid submission; treating them as post-award line items is an accounting error that erodes margin in ways that are hard to recover. Cybersecurity documentation, including system security plans and incident response procedures, is a contract deliverable that agencies expect to receive and review. And the integration of cybersecurity requirements into FAR 4.19 rather than standalone Part 39 clauses signals that the government now considers these obligations baseline acquisition requirements applicable across all contracts, not technology-specific add-ons.

That last point is where vendors most consistently stumble, in my observation. The obligations are no longer siloed to IT contracts. Acting as though they are is an expensive assumption, and it surfaces at the worst possible moment.

How a Technology Vendor Should Read the FAR Stack Before Pursuing Federal Business

The FAR is not a single document to comply with. It is a layered stack to map: FAR base rules, then agency supplements, then applicable Part 39 ICT provisions, then cybersecurity clauses, then vehicle-specific terms. Each layer adds obligations. Missing one layer is how companies build compliant-looking proposals that fail on technicalities. That is a particularly demoralizing way to lose, and it is almost entirely avoidable.

Identify target agencies first, then check their supplement regulations. DFARS for DoD, HHSAR for HHS; each supplement encodes agency-specific requirements that materially affect compliance scope. Then determine which contract vehicle that agency is authorized and likely to use. OneGov consolidation makes GSA vehicles the default starting point for common technology categories, so that determination is increasingly straightforward, if not always welcome.

Assess cybersecurity compliance posture against FAR 52.204-21 and, for defense work, the applicable CMMC tier, before pricing. Not after. Then evaluate whether the solution architecture fits modular contracting norms: can it be scoped to deliver within 18-month windows? If not, the proposal structure will fight the FAR rather than align with it.

But what if you are tracking the published FAR and assuming it reflects current requirements? That is a real problem worth naming explicitly. The FAR overhaul is removing clauses rather than replacing the framework wholesale. Phase 1 class deviations and Phase 2 formal rules are creating a period where operative requirements vary by solicitation date. A vendor working against only the current published FAR, without accounting for active deviations, is operating against the wrong version of the rules. That happens more than vendors admit.

Speed of compliance readiness is a competitive variable. Agencies under pressure to modernize within tight budget windows, with only roughly one-fifth of IT budgets available for new technology, will favor vendors who arrive pre-compliant. Requiring government-side compliance support during contract execution is a tax on scarce contracting officer time, and those officers are already stretched thin.

The vendors who win consistently in federal technology markets are rarely the ones with the best products. They are the ones who demonstrate FAR fluency before the award, show modular delivery credibility in their proposals, and arrive at the solicitation with vehicle positioning, cybersecurity documentation, and ICT compliance already assembled. Forty-one years of revision have not changed that fundamental dynamic.

More in GovTech Procurement