Davis-Monthan Air Force Base had an ordinary problem. Its backflow prevention program tracked roughly 1,200 assemblies in an aging install of XC2 — a standalone copy with a standalone database, sitting on base servers, of the kind an authorizing official would like to see retired. The base needed to keep meeting Arizona Administrative Code Title 18 Chapter 4 and AFMAN 32-1067, migrate the historical records, train six people, and answer a help line between 0700 and 1430 local.
In September 2025 it issued RFQ FA487725QA234 as a combined synopsis under FAR 12.6 and FAR 13: a total small business set-aside, lowest price technically acceptable, base year plus four options.
The solicitation was pulled.
Nobody did anything unreasonable. The requirement was real, the security instinct behind it was right, and the contracting shop ran a normal buy. What went wrong is arithmetic, and all of it was knowable before the RFQ was written. That is the part worth borrowing.
The clause
From Attachment 1, the salient characteristics:
"Software must Meet AICPA / SOC 2 Type II Certification. As part of that certification, it must be FedRAMP (Federal Risk and Authorization management Program) and DODSRG (the Department of Defense Security Requirements Guide) Level 2 and 4 certified."
Three names, three separate systems, run by three different bodies. SOC 2 Type II is an attestation performed by a CPA firm under AICPA standards; nothing federal is contained within it. FedRAMP does not certify anyone — it authorizes, through a provisional authorization or a sponsoring agency's authorization. The DoD impact levels come from the Cloud Service Provider SRG and are carried by a provisional authorization issued by the DISA authorizing official, which is why the SRG says plainly that "Impact Levels are a DOD construct only."
Asking for Level 2 and Level 4 compounds it, because those are not rungs a product collects on the way up. Under the SRG, a service already carrying FedRAMP Moderate or High "may be used at DOD Impact Level 2 without a written DOD PA" — essentially free. IL4 is a different animal: DoW-specific requirements, an accredited third-party assessment, a DISA risk determination and a separate authorization. One sentence asked for something nearly automatic and something genuinely expensive as though they were the same thing.
When a vendor asked whether the salient characteristics were mandatory or merely preferred, the answer was:
"Mandatory. The DoD has very specific IT requirements for certification on, and use on, DoD networks."
That answer is correct. DoW networks do impose real requirements. The document just named the wrong instruments, which is what happens when three vocabularies maintained by different authorities get compressed into one line.
The arithmetic
Fix the wording and the outcome does not change, because the numbers were settled before anyone wrote a clause.
What this software costs. In August 2021 the City of Tampa awarded RFP #41012821 for backflow assembly management software. The winning price schedule, inside the city's award package, reads: "Total Year 1 - All inclusive $18,875", then $11,375 a year recurring — for "up to 8,000 backflow assemblies tested per year". Five years comes to about $64,000. Eight vendors bid, at between $0.25 and $12 per assembly per year.
Davis-Monthan has about 1,200 assemblies. A sixth of Tampa's volume. On commercial terms this is a five-figure contract, and a modest one.
What the authorization costs the vendor. GAO examined this and reported in January 2024 that cloud providers pursuing FedRAMP authorization spent "from $300,000 to $3.7 million" — a total of roughly $12.4 million across eight providers. One reported about $367,000 for the third-party assessor alone. A small business reported $3 million, covering labor, contractor support, the assessor, and rebuilding its infrastructure to meet the requirements. GAO also noted its figures excluded the Department of Defense, whose data "are classified and were reported by the department separately" — so the DoD side of the ledger is not even in the public number.
Put the two together. The authorization alone costs somewhere between about five and sixty times the entire five-year value of a contract like Tampa's — before the DoD impact level work on top, and against a base a sixth of that size.
No vendor buys a federal authorization to win one installation. That decision is made years earlier, against the whole federal market, or it is not made at all. Which means the clause did not raise the bar for this buy. It removed the buy from the set of things that can be purchased.
"Or equal" did not open the field
The solicitation named a product: "Software will be SwiftComply or equal." Ordinarily that invites alternatives.
Here it did not, because XC2 is now part of SwiftComply — stated on XC2's own site. The legacy product the base was trying to retire and the brand named as the standard belong to the same company. Combined with an award on lowest price and a security clause no small vendor could satisfy, the competitive space was narrow before the first quote arrived.
This is worth checking in any market where consolidation has been busy. A brand-name-or-equal reference assumes a field of equals still exists.
What actually moves the number
There is a real answer, and it is not a better-worded clause. It is to stop requiring the vendor to hold an authorization and start putting the software somewhere that already has one.
That is what an accredited platform does. Second Front's Game Warden, for instance, holds a DISA provisional authorization at IL5, and applications deployed onto it inherit the platform's controls rather than pursuing their own — the inheritance mechanism the impact-level post describes. Second Front claims a DoD authority to operate in as little as 90 days, against the one to three years a traditional path takes. That is the vendor's claim rather than an audited figure, but the direction is not in dispute: inheriting an authorization is the single largest cost reduction available, and we have taken a commercial product through exactly that route.
It is not free. Somebody still pays for the platform, and for running an accredited service rather than a subscription. What it does is convert an impossible number into a negotiable one — and for a requirement of this size, that is the difference between an acquisition strategy and a pulled solicitation.
The question to ask before posting
The cheapest artifact in this entire story is the half-day of work that would have told the base what it was about to ask for. Before the words are fixed:
Is the data actually CUI? This one determination decides everything downstream, and it belongs to the information owner rather than to whoever is drafting. Backflow inventory and test records may or may not qualify. If they do not, IL2 may be enough, FedRAMP reciprocity applies, and the eligible field is large. If they do, you are at IL4 and the field is small. Knowing which before you post is free; discovering it afterwards costs a solicitation.
Does it have to live on that network at all? A compliance tracker for base utilities is not obviously a system that must sit inside the DoW boundary. That question deserves an answer before the security clause is written, not after.
Who already holds what? The FedRAMP Marketplace and the DoD Cloud Service Catalog will tell you, in an afternoon, whether anyone in your niche holds the authorization you are about to require. If nobody does, that is a finding about your acquisition strategy, not a reason to write the requirement more firmly.
What does this software cost commercially? Tampa's award is public. So are dozens like it. If the commercial price of the product is five figures and the authorization you are requiring costs six or seven, you have your answer already.
What is the gap, and who closes it? If the honest answer is that no fundable compliant path exists, that is enormously valuable to know in the draft stage, when the requirement can still change. It is worth very little on the day the quotes come in.
What was left behind
The solicitation was pulled. The requirement did not go away. The aging XC2 install is still running on base servers, which is the outcome nobody wanted — least of all the authorizing official who would like it gone.
That is the real cost of finding out late. Not the wasted proposal effort on the industry side, though there was some. The cost is that a base with a legitimate need and available money ended the process with the same problem it started with, and the one thing that would have changed the outcome — asking whether anyone could quote it before asking them to quote it — was the cheapest step available.
One base cannot fund this. A command can.
There is a second lesson in the arithmetic, and it points somewhere more useful than a rewritten clause.
Nothing about this requirement is unique to Davis-Monthan. Every installation runs a cross-connection control program, tracks assemblies against the same AFMAN, and keeps the records somewhere. The reason no vendor will authorize a product for this buy is that the authorization has to be recovered from one base's five-figure contract. That is not a solvable problem at base level, and no amount of careful drafting makes it one.
Move the same requirement up a level and the economics invert. An authorization amortized across many installations is ordinary commercial arithmetic rather than an impossible one. The same is true of the platform underneath it: one accredited environment serving many installations costs each of them a fraction of what it costs one.
So for a single base, the honest answer is usually that this should not be bought alone. That is worth knowing in the draft, because the useful next step is a conversation with the command that has the requirement fifty times over — not a second attempt at the same solicitation.
Robert Burckner is the founder of Millabs Corporation, a Service-Disabled Veteran-Owned Small Business. He has served as ISSM and ISSE for legacy weapon systems at the Air Force Lifecycle Management Center and as Division Chief at the Space Warfighting Analysis Center (USSF/NRO). Millabs quoted RFQ FA487725QA234.
If you are drafting a requirement for a single installation and it names an authorization, that question does not need a contract. Send it over and we will tell you on a call whether anyone can quote it, what it would cost, and who already holds what — the answer takes about thirty minutes and it is free.
Where the same requirement runs across a portfolio of installations, the analysis is larger and so is what it saves: which authorization to inherit, what one accredited environment serving many sites costs against many separate buys, and what the acquisition strategy should be. Millabs performs that work for program offices independently of any vendor relationship, through existing government contract vehicles. Contact Millabs.