What a federal capability statement should actually say

Pull-quote: “A statement that claims everything is worth nothing, because the reader has no way to tell which part of it is true.”
A federal capability statement earns its place when a contracting officer can act on it, and most of them cannot be acted on at all. The typical page opens with a paragraph about being a trusted partner delivering innovative solutions, lists five services in title case, and closes with a logo. Nothing on it is checkable. Nothing on it tells the reader whether this company can take the work in front of them.
The reader is skimming, often with a set-aside decision or a market research memo to write, and looking for specific things: are you registered, what size and status do you hold, which NAICS and PSC codes cover your work, what have you built, and how would a contract reach you. The adjectives answer none of that.
This post is for any small business writing or rewriting a capability statement. It goes through the sections that carry real information and why each one matters, and uses Zorost Intelligence’s own posture as the worked example, including the credentials Zorost does not hold. That last part is the argument: the statements that get taken seriously are the ones a reader can verify, and verifiability requires saying where the boundaries are.
What you will be able to do
- Name the sections of a capability statement that carry information a contracting officer can use.
- Choose NAICS and PSC codes deliberately, and know what each classification system is for.
- Write core competencies as work performed rather than as capability adjectives.
- Present past performance credibly when you cannot name a single customer.
- List engagement routes so a buyer can see the mechanism by which work could reach you.
- State status accurately, including what you do not hold, without weakening the document.
What belongs in a federal capability statement?
Six sections carry the information: registration and identifiers, NAICS and PSC codes, core competencies stated as work performed, differentiators a reader can verify, past performance, and engagement routes. Everything else on the page is decoration competing for the reader’s attention.
The page has one job: survive a skim and stay in the pile. A contracting officer conducting market research is deciding whether to include you in a list, send you a sources sought notice, or pass your name to a prime looking for a subcontractor. Each of those decisions needs the same underlying facts. If the page cannot supply them in under a minute, the decision gets made without you.

The discipline in what follows is simple to describe and uncommon in practice: write only claims that survive being checked, and put the checkable ones first.
Which registration details does a contracting officer need first?
Legal name, place of business, business size, and active registration in SAM.gov, with the unique entity identifier and CAGE code available. Those establish that you exist as a contractable entity, which is the precondition for everything else on the page.
Zorost Intelligence LLC is a Washington, DC small business, registered in SAM.gov, with its UEI and CAGE on file and furnished on request. Both identifiers are public record in SAM.gov, so printing them on a public web page is a presentation choice rather than a disclosure question. On a statement you hand to a contracting officer, include them. A statement without a UEI asks the reader to do the lookup, and the reader has other statements to read.
State business size accurately, and state socio-economic status only where you hold it. Status claims are the easiest thing on the page to verify and the most damaging to get wrong.
How do you choose NAICS and PSC codes that hold up?
Pick the codes that match work you can actually perform, because the two systems are how buyers find you and how they classify what they are buying. They are different classifications and both belong on the page.
NAICS is the North American Industry Classification System, which the government uses to classify what kind of business you are and, through the size standard attached to each code, whether you count as small for a given procurement. PSC codes, from the Product and Service Code manual, classify what is being bought rather than who is selling it. A solicitation names a PSC; market research often filters on NAICS. Listing both means you appear in both kinds of search.
Zorost’s NAICS codes and their official titles:
| Code | Title |
|---|---|
| 541511 | Custom Computer Programming Services |
| 541512 | Computer Systems Design Services |
| 541519 | Other Computer Related Services |
| 541715 | Research and Development in the Physical, Engineering, and Life Sciences |
| 541690 | Other Scientific and Technical Consulting Services |
| 518210 | Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services |
The PSC list is D302, D307, D308, D310, R425, and AC11 through AC34: the D-series covers information technology and telecommunications services, R425 sits in professional support services, and the AC range covers research and development. Six NAICS codes and a focused PSC list describe a company that knows what it does. Twenty describe a company that will bid on anything, which is not what wins a subcontract.

How do you write core competencies that are not adjectives?
Write each competency as work performed, in the noun phrase a buyer would use to describe the task. “Applied AI and machine learning” is a competency. “Innovative AI-driven solutions” is a sentence fragment with no content in it.
Zorost lists six: applied AI and machine learning, generative and agentic systems, cloud modernization and data engineering, Databricks modernization, decision support and simulation, and AI governance. Read that list back and notice what it does. Each item names a body of work a contracting officer could put in a statement of work. None of them contains an evaluative adjective, because an adjective in a competency line is a claim about quality that the reader cannot check and did not ask for.
The test is whether the competency could appear in a solicitation. If a phrase would never survive into a statement of work, it does not belong in a capability statement either. “Cloud modernization and data engineering” could be the title of a task order. “Transformative digital excellence” could not be anything.
Differentiators follow the same rule, with one addition: they should be verifiable by a third party. Individual professional certifications qualify, because a certificate has an issuer and a holder. The credentials held by Zorost practitioners include Federal COR Level 1, PMP, Azure Solutions Architect Expert, Azure AI Engineer, Fabric Analytics Engineer, Fabric Data Engineer, AWS AI Practitioner, Databricks Data Engineer Associate and Professional, Databricks ML Professional, Databricks GenAI Engineer Associate, Databricks Spark Developer Associate, and a PhD in Systems Engineering from George Washington University. Those are individual credentials held by named practitioners, which is a different kind of claim from a company certification, and the statement should say which kind it is offering.
What goes in past performance when you cannot name customers?
Present the work itself. When contracts are covered by confidentiality, or when the entity is newer than its people, the honest and useful substitute is platform past performance: systems you built and operate, described by what they do.
Zorost presents past performance as the seven platforms it operates, with no customer names, contract numbers, or program identifiers on the public site. That is a deliberate choice rather than an omission, and it works because a platform is evidence of the same underlying things a past-performance citation is meant to demonstrate: that you can scope a system, build it, ship it, and keep it running.
If you use this approach, be precise about what you are offering. Say plainly that these are platforms you built and operate rather than contract citations, so the reader knows how to weigh them. A contracting officer who wants CPARS records will ask for CPARS records, and a straight answer beats a page that implies more. When you can cite contracts, cite them with the agency, the period of performance, and the value, because that is stronger evidence and the reader knows it.
Which engagement routes belong on the page?
List the mechanisms by which a contract could actually reach you, because a reader who likes your capabilities still needs a path, and the path is often the reason a small business gets skipped.
Zorost’s routes are subcontracting, available now; teaming and mentor-protege arrangements, actively pursued; SBIR and STTR, an active pipeline; other transaction authorities and commercial solutions openings, open; and direct award at simplified acquisition levels. GSA Multiple Award Schedule is being pursued and is not held, which is stated in exactly those words.
Notice the tense discipline in that paragraph. “Available”, “actively pursued”, “an active pipeline”, “being pursued”. Each phrase describes a different state, and a reader who works in acquisition reads those differences precisely. Writing “GSA Schedule” on a page when the schedule is an application in progress is the kind of error that ends a conversation, because the reader will check, and the check takes them forty seconds.
Why does stating what you do not hold make the statement stronger?
Because it tells the reader that the rest of the page is calibrated, and calibration is the scarce quality in this document. Every capability statement claims capability. Very few of them draw a boundary, so the ones that do are the ones a reader can use.
Here is the boundary in Zorost’s case, stated the way it should be stated. Zorost does not hold Small Disadvantaged Business status. It does not hold 8(a) status, and there is no application in progress. It does not hold FedRAMP authorization, CMMC certification, SOC 2 attestation, or ISO certification for the company or for any Zorost platform. It has no FISMA authorization to operate, and it does not present NIST 800-171 as a held certification. GSA MAS is being pursued, not held.
That list costs nothing, because a contracting officer was going to establish every one of those facts anyway, and it buys something: the reader now knows this page distinguishes held from pursued. When the same page says the practitioner certifications are real, that claim inherits the credibility.
One distinction on this page is worth making carefully, because it is easy to blur by accident. ComplyGrid, one of the platforms Zorost operates, provides DCAA-aligned timekeeping as a product capability for its customers. That is a statement about what the software does. It is not a statement that Zorost has passed a DCAA audit, and the two must never be run together in a sentence. The same care applies to any platform capability that sounds like an accreditation. Naming a standard your product supports is fine; letting a reader infer that you hold an accreditation against that standard is not.

Where this goes wrong
Status inflation. The symptom is a set-aside conversation that ends abruptly. The cause is a socio-economic status listed as held when it is applied for, or a schedule listed as active when it is pending. Write the status exactly as SAM.gov shows it, and use “pursuing” for anything in progress.
Certification blur. The symptom is a reader assuming your company holds a certification that individual staff hold, or that a product’s alignment with a standard means the company was audited against it. The cause is mixing company and practitioner credentials in one list. Separate them under different headings and label both.
NAICS sprawl. The symptom is a code list long enough to imply you do everything. The cause is adding codes to catch more searches, and it backfires, because a reader treats a long list as an absence of focus. Keep the codes where you can describe delivered work.
Competency adjectives. The symptom is a list of phrases that could describe any company in the sector. The cause is writing for a marketing audience. Rewrite each line as the title of a task order and delete the ones that cannot survive it.
A statement with no route. The symptom is interest that never becomes a contract action. The cause is a page that lists capabilities and never says how to buy. Name the vehicles and the mechanisms, including subcontracting and simplified acquisition, so the reader can see the path.
Common questions
How long should a capability statement be?
One page, in almost every case. The reader is skimming to make an include-or-exclude decision, and a second page usually means the first page was not prioritised. Keep the identifiers, codes, competencies, differentiators, past performance, and engagement routes on one side, and let a longer document exist separately for readers who ask for it.
What if my company is new and has no past performance?
Present the work you have built and operate, and label it accurately as platform past performance rather than as contract citations. Systems you built and run demonstrate scoping, delivery, and sustainment. Add the individual credentials of the people doing the work, again labelled as individual rather than corporate, and let the reader weigh it.
Should I list every NAICS code that might apply?
No. List the codes where you can describe work you have delivered. A reader treats a long NAICS list as a signal that the company has no focus, and the size standard that matters is the one attached to the code in the solicitation, not the number of codes you carry.
Is it damaging to say we do not hold a certification?
The opposite, in practice. The reader can verify certifications in minutes, so an inflated claim is discovered at the worst possible moment. Saying plainly which credentials you hold and which you do not tells the reader that your other claims are calibrated, and that is the quality that makes a statement usable.
What is the difference between NAICS and PSC codes?
NAICS classifies your business and carries the size standard that determines whether you count as small for a given procurement. PSC classifies what the government is buying in a specific solicitation. Buyers use both, in different systems and at different stages, so a statement that lists only one is invisible in half the searches that matter.
Next steps
Take your current capability statement and mark every sentence a reader could verify in under two minutes. If fewer than half survive, rewrite around the six sections above, starting with identifiers and codes and ending with engagement routes.
For a worked example of this discipline applied to a different artefact, publishing an open source capability statement covers what happens when the evidence is code a reader can inspect. If the discipline you need is on the compliance side rather than the marketing side, DCAA timekeeping audit discipline explains what an auditable time record requires, and contract obligations that surface themselves covers keeping track of what you committed to once the award exists.
Zorost’s own posture, written exactly as described here including the credentials it does not hold, is published at federal solutions and the capability statement. The timekeeping capability referenced above runs in ComplyGrid, where DCAA-aligned records are a product feature for its customers rather than a claim about Zorost’s own audit history.
