Skip to main content
Category: Contracting & Acquisition

Source Selection

Also known as: Competitive Source Selection
Simply put

Source selection is the government's process for evaluating competing bids or proposals to decide which vendor should receive a contract. The goal is generally to choose the offer that provides the best overall value to the government, not simply the lowest price. Agency leadership is responsible for carrying out this process.

Formal definition

Source selection is the structured process by which a Government agency evaluates competitive offers or proposals in order to award a procurement contract, with the stated objective of selecting the proposal that represents the best value. Under FAR Subpart 15.3, agency heads are responsible for source selection, and the activities are generally organized and documented through a Source Selection Plan (SSP) that specifies how evaluation activities will be initiated and conducted. Source selection criteria, used to determine best value, define how offerors are assessed against the Government's requirements. This entry addresses the general concept of source selection as reflected in the cited evidence; readers should consult FAR Subpart 15.3, applicable defense pricing and contracting policy, and any agency-specific supplements for procedural, contractual, and evaluation-methodology specifics, which may vary and change across revisions.

Why it matters

Source selection is the decision point at which the government commits public funds to a particular vendor, and its structure directly affects the integrity and defensibility of that decision. Because the stated objective is to select the proposal representing the best value rather than simply the lowest price, agencies must apply consistent, documented evaluation criteria that can withstand scrutiny. For compliance officers and contracting personnel, a properly organized source selection is what separates a defensible award from one exposed to protest, delay, or reversal.

For cybersecurity and defense practitioners specifically, source selection is often where security and compliance expectations become concrete. The criteria used to evaluate offerors define how the government assesses proposals against its requirements, and where those requirements include safeguarding of information or adherence to applicable security controls, the source selection process is the mechanism through which such expectations influence award decisions. Understanding this process helps stakeholders anticipate how compliance posture may factor into competition.

Because procedures, evaluation methodologies, and applicable defense pricing and contracting policy can vary by agency and change across revisions, readers should not treat the general concept described here as a substitute for the governing text. The specific rules that apply to any given procurement should be confirmed against FAR Subpart 15.3, applicable defense policy, and any agency-specific supplements.

Who it's relevant to

Contracting Officers and Acquisition Personnel
Those responsible for soliciting offers and awarding government contracts rely on source selection to structure and document how competing proposals are evaluated. They typically work from a Source Selection Plan and apply established criteria to reach a best-value decision that is consistent with FAR Subpart 15.3 and applicable agency policy.
Compliance Officers and ISSMs
Where security and compliance expectations are embedded in a procurement, source selection is a point at which those requirements can influence award decisions through the evaluation criteria. Understanding the process helps these stakeholders anticipate how an offeror's compliance posture may be assessed, though they should confirm the specific criteria and requirements against the governing solicitation and applicable policy.
Government Contractors and Offerors
Vendors competing for government contracts are evaluated through the source selection process against the government's stated requirements. A clear understanding of how best value is determined and how criteria are applied helps offerors prepare proposals that respond to the government's needs, while recognizing that evaluation methodologies may vary by agency and revision.
Auditors and Oversight Personnel
Because source selection decisions must be defensible and are documented through instruments such as the Source Selection Plan, auditors and oversight staff review these processes to confirm that evaluations were organized, conducted, and documented consistent with FAR Subpart 15.3 and any applicable agency supplements.

Inside Source Selection

Evaluation Factors
The criteria against which offeror proposals are assessed, which may include technical approach, past performance, price or cost, and other factors identified in the solicitation. For cybersecurity-relevant acquisitions, these factors can incorporate an offeror's ability to meet applicable safeguarding requirements, though the specific factors and their relative weighting are established by the acquiring agency in each solicitation.
Solicitation Requirements
The stated conditions offerors must address, which for procurements involving Controlled Unclassified Information generally include the safeguarding and cyber incident reporting obligations imposed through applicable contract clauses such as DFARS 252.204-7012 in defense acquisitions. Readers should verify the specific clauses and requirements against the current text of the solicitation and applicable regulation.
Past Performance Consideration
An assessment of an offeror's demonstrated history on prior contracts, which in some cybersecurity-sensitive acquisitions may include prior handling of safeguarding requirements or self-assessment scores. The weight given to past performance is determined by the individual solicitation and is not uniform across agencies or acquisitions.
Best Value versus Lowest Price Technically Acceptable (LPTA)
Two general approaches to award. A best value tradeoff process allows the acquiring agency to weigh non-price factors against price, while LPTA awards to the lowest-priced offer meeting stated acceptability thresholds. The chosen approach is defined in the solicitation and affects how cybersecurity-related factors are evaluated.
Documentation and Record
The written basis supporting the award decision, generally required to demonstrate that the evaluation was conducted consistent with the stated factors. Specific documentation requirements are governed by applicable acquisition regulation and agency policy, which the reader should confirm against current authoritative sources.

Common questions

Answers to the questions practitioners most commonly ask about Source Selection.

Does completing source selection mean the awarded system is authorized to operate?
No. Source selection is a procurement and contracting activity used to evaluate offers and award a contract; it is distinct from the authorization process. Even after award, the resulting information system generally must go through its own assessment and authorization process (for example, under the RMF for DoD systems or FISMA for civilian systems) before an Authority to Operate (ATO) is granted. Assessment and authorization are separate from, and not satisfied by, winning a competition.
If a vendor selected through source selection holds a FedRAMP authorization, does that satisfy the DoD's requirements for the awarded work?
Not automatically. A FedRAMP authorization, which is administered through the FedRAMP PMO for federal civilian cloud use, does not by itself satisfy DoD-specific requirements. DoD systems are generally governed by the RMF under DoD CIO direction, and cloud services intended for DoD use are typically subject to additional DoD requirements and impact-level considerations. Any reliance on an existing authorization during or after source selection should be verified against the applicable current DoD guidance and contract terms.
How are cybersecurity and compliance requirements typically reflected in a source selection?
Cybersecurity and compliance expectations are generally incorporated through the solicitation's requirements, applicable contract clauses (such as DFARS provisions addressing safeguarding of covered defense information, where applicable), and stated evaluation criteria. In most implementations, the government defines what offerors must demonstrate and how those factors will be weighed. Because clause applicability and evaluation approaches vary by acquisition and change across revisions, the specific requirements should be confirmed against the current solicitation and authoritative sources.
Where do CUI protection obligations fit into a source selection?
When an acquisition involves Controlled Unclassified Information, the protection obligations that will apply to the contractor are generally identified in the solicitation and flowed down through applicable contract terms. Protections associated with CUI, such as those commonly aligned to NIST SP 800-171 for nonfederal systems, typically become contractual obligations upon award rather than something resolved by the selection decision itself. Confirm the applicable requirements and any assessment expectations against the current DFARS and NIST guidance referenced in the specific procurement.
Should offerors treat a demonstrated compliance posture as evidence of security during evaluation?
Compliance and security are not equivalent, and this distinction is relevant during evaluation. A demonstrated compliance posture reflects alignment with specified controls or requirements at a point in time, but it does not by itself establish that a system is secure or that risk is being actively managed. Evaluators and offerors should treat compliance representations as one input, and recognize that ongoing security depends on continuous monitoring and risk management beyond the selection event.
How do continuous monitoring and time-bound authorizations relate to obligations that begin at award?
Because an ATO is time-bound and subject to continuous monitoring rather than permanent, the compliance and security obligations that attach through source selection generally continue throughout performance. Winning the award does not freeze the security posture; the awarded contractor is typically expected to maintain required protections and support ongoing monitoring as defined in the contract and applicable authorization requirements. The precise obligations should be verified against the current authoritative text and contract terms.

Common misconceptions

A FedRAMP authorization or a favorable self-assessment automatically makes an offeror the successful selection or satisfies all cybersecurity requirements in a source selection.
Authorization or an assessment score is generally only one input among the evaluation factors, and FedRAMP authorization does not automatically satisfy DoD-specific requirements. Compliance status is distinct from being selected, and the acquiring agency evaluates each proposal against the factors stated in that solicitation.
Meeting stated cybersecurity or safeguarding requirements in a proposal is equivalent to being secure, so no further scrutiny is needed after award.
Demonstrating compliance with safeguarding requirements during source selection does not equate to actual security, and contractual obligations such as continuous safeguarding and cyber incident reporting generally continue throughout performance. Assessment of a proposal is not the same as ongoing verification during the contract.
Cybersecurity requirements are applied identically across all source selections regardless of the type of system or information involved.
Requirements vary by scope. Obligations tied to Controlled Unclassified Information, defense systems under the RMF, classified work under the NISPOM, and civilian agency systems under FISMA may differ, and the applicable clauses and factors are set by each solicitation rather than being uniform.

Best practices

Read the specific solicitation carefully to identify which cybersecurity-related evaluation factors apply and how they are weighted, rather than assuming a standard set of factors across acquisitions.
Confirm which safeguarding and incident reporting clauses are incorporated into the solicitation, verifying the current clause text and applicability against authoritative regulatory sources before relying on any assumption.
Distinguish between an offeror's compliance status and the award decision, treating assessment results as one input among multiple evaluation factors rather than a determinant of selection.
Do not treat a FedRAMP authorization as automatically satisfying DoD requirements; verify that the applicable defense-specific requirements are addressed separately where relevant.
Maintain thorough documentation of how each proposal was evaluated against the stated factors to support a defensible award decision consistent with applicable acquisition regulation.
Recognize that cybersecurity obligations generally continue after award through continuous monitoring and reporting, and ensure post-award oversight is planned rather than assuming compliance ends at selection.