Every defense supplier you evaluate will eventually send you a capabilities statement — sometimes called a Capability Brief, Supplier Profile, or Corporate Overview. It is the document that tells you who they are, what they make, and why they are qualified. Procurement teams see dozens of these. Most are poorly organized, some are misleading, and a few contain outright fabrications. Here is how to read one efficiently.
What Is a Capabilities Statement?
A capabilities statement is a one-to-three-page document that introduces a supplier to a potential buyer. Defense primes and government contracting officers use them to conduct preliminary market research, identify qualified sources, and pre-screen suppliers for bid opportunities. Unlike a proposal, a capabilities statement is not a response to a solicitation — it is an unsolicited introduction.
Standard government format follows SF 294 or the condensed one-page version used in SAM.gov entity registrations. Defense contractors also produce proprietary versions that vary widely in quality. The format matters less than what it contains.
Key Sections to Read First
Do not read capabilities statements top-to-bottom. Scan these sections first:
CAGE Code
The Commercial and Government Entity (CAGE) code is a five-character identifier assigned to any entity doing business with the federal government. A valid CAGE code is a prerequisite for any defense contract. If the capabilities statement does not include a CAGE code, that alone is a disqualifier for DoD work.
Once you find the CAGE code, verify it at sam.gov. The registered entity name, address, and status should match what is on the capabilities statement. Mismatches are a red flag — sometimes the CAGE code is copied from another company, sometimes the supplier is using an outdated code.
NAICS Codes
The North American Industry Classification System (NAICS) codes tell you what type of work the company is registered to perform. Defense suppliers typically list multiple NAICS codes covering their manufacturing processes, materials, and services. If the NAICS codes on their statement do not include the work you need done, move on. A company registered for "metal forging" may not be registered for "machining" or "sheet metal fabrication" — even if their capabilities statement claims they do both.
| Element | What to look for | Red flag |
|---|---|---|
| CAGE Code | Valid on sam.gov, matches statement | Missing, invalid, or mismatched |
| NAICS Codes | Covers your required work type | Wrong category, stale codes |
| Certifications | AS9100D, ITAR, CMMC with dates | Expired, missing scope, unverifiable |
| Past Performance | Relevant programs, prime/sub work | Vague descriptions, no contract numbers |
| Employee Count | Actual headcount, shop sq footage | Missing or suspiciously round numbers |
Quality Certifications
Look for AS9100D (aerospace QMS), ISO 9001 (baseline QMS), ITAR registration (with DDTC registration number), and CMMC level. The statement should include certification scope and expiration dates. "AS9100 certified" without a scope statement or expiration date is a claim you cannot verify. Cross-reference against the relevant registries — AS9100 certificates can be verified through the applicable certification body.
Past Performance
Strong capabilities statements list actual programs, prime contractors, and contract numbers — not just "served defense customers." Look for programs relevant to your application. A supplier with past performance on submarine components may not be the right fit for aerospace turbine parts, even if both are "defense work." The closer the past performance to your program type, the more credible the supplier's claims.
How to Verify Claims Against Public Databases
Capabilities statements often contain claims that should be cross-checked. Here are the key verification steps:
- CAGE code — verify on sam.gov (Entity Information tab). Confirm active status and registered address.
- ITAR registration — ask for the DDTC registration number and verify at pmddtc.state.gov. Active registration is required to receive ITAR-controlled data.
- AS9100 / ISO 9001 certification — request the certificate. Verify the certifying body (Registrar) and expiration. Valid certificates can usually be looked up on the Registrar's public registry.
- CMMC level — check the DoD CMMC EML marketplace or ask the supplier for their SPRS score (NIST SP 800-171 assessment). The score is public information submitted to the DoD SPRS system.
- Past performance contracts — if they list specific contract numbers, you can look them up in USASpending.gov or the Federal Procurement Data System (FPDS) to confirm scope and value.
Red Flags in a Capabilities Statement
These indicators suggest the supplier is not a qualified defense manufacturer — or is at minimum not worth spending time on:
How ForgeLine Verifies Supplier Capabilities
ForgeLine's supplier directory does the initial verification work for you. Every supplier listed in our directory has been pre-screened for:
- Active CAGE code registered on sam.gov
- ITAR registration with the US State Department DDTC
- AS9100 or ISO 9001 certification with current scope statement
- CMMC level (when applicable for their customer base)
- Verified domestic manufacturing address (US-based production)
You can filter by certification type, material and process, and state to build a shortlist of verified suppliers without doing the SAM.gov and DDTC verification manually for each candidate. Our supplier evaluation guide walks through the follow-up questions to ask once you have a capabilities statement in hand.
Frequently Asked Questions
Find Verified Defense Suppliers
ForgeLine pre-screens every supplier in our directory — no need to manually verify CAGE codes and certifications from a capabilities statement. Search by material, process, state, or certification level.