Every defense supplier you evaluate will eventually send you a capabilities statement — sometimes called a Capability Brief, Supplier Profile, or Corporate Overview. It is the document that tells you who they are, what they make, and why they are qualified. Procurement teams see dozens of these. Most are poorly organized, some are misleading, and a few contain outright fabrications. Here is how to read one efficiently.

What Is a Capabilities Statement?

A capabilities statement is a one-to-three-page document that introduces a supplier to a potential buyer. Defense primes and government contracting officers use them to conduct preliminary market research, identify qualified sources, and pre-screen suppliers for bid opportunities. Unlike a proposal, a capabilities statement is not a response to a solicitation — it is an unsolicited introduction.

Standard government format follows SF 294 or the condensed one-page version used in SAM.gov entity registrations. Defense contractors also produce proprietary versions that vary widely in quality. The format matters less than what it contains.

Key Sections to Read First

Do not read capabilities statements top-to-bottom. Scan these sections first:

CAGE Code

The Commercial and Government Entity (CAGE) code is a five-character identifier assigned to any entity doing business with the federal government. A valid CAGE code is a prerequisite for any defense contract. If the capabilities statement does not include a CAGE code, that alone is a disqualifier for DoD work.

Once you find the CAGE code, verify it at sam.gov. The registered entity name, address, and status should match what is on the capabilities statement. Mismatches are a red flag — sometimes the CAGE code is copied from another company, sometimes the supplier is using an outdated code.

NAICS Codes

The North American Industry Classification System (NAICS) codes tell you what type of work the company is registered to perform. Defense suppliers typically list multiple NAICS codes covering their manufacturing processes, materials, and services. If the NAICS codes on their statement do not include the work you need done, move on. A company registered for "metal forging" may not be registered for "machining" or "sheet metal fabrication" — even if their capabilities statement claims they do both.

ElementWhat to look forRed flag
CAGE CodeValid on sam.gov, matches statementMissing, invalid, or mismatched
NAICS CodesCovers your required work typeWrong category, stale codes
CertificationsAS9100D, ITAR, CMMC with datesExpired, missing scope, unverifiable
Past PerformanceRelevant programs, prime/sub workVague descriptions, no contract numbers
Employee CountActual headcount, shop sq footageMissing or suspiciously round numbers

Quality Certifications

Look for AS9100D (aerospace QMS), ISO 9001 (baseline QMS), ITAR registration (with DDTC registration number), and CMMC level. The statement should include certification scope and expiration dates. "AS9100 certified" without a scope statement or expiration date is a claim you cannot verify. Cross-reference against the relevant registries — AS9100 certificates can be verified through the applicable certification body.

Past Performance

Strong capabilities statements list actual programs, prime contractors, and contract numbers — not just "served defense customers." Look for programs relevant to your application. A supplier with past performance on submarine components may not be the right fit for aerospace turbine parts, even if both are "defense work." The closer the past performance to your program type, the more credible the supplier's claims.

How to Verify Claims Against Public Databases

Capabilities statements often contain claims that should be cross-checked. Here are the key verification steps:

  • CAGE code — verify on sam.gov (Entity Information tab). Confirm active status and registered address.
  • ITAR registration — ask for the DDTC registration number and verify at pmddtc.state.gov. Active registration is required to receive ITAR-controlled data.
  • AS9100 / ISO 9001 certification — request the certificate. Verify the certifying body (Registrar) and expiration. Valid certificates can usually be looked up on the Registrar's public registry.
  • CMMC level — check the DoD CMMC EML marketplace or ask the supplier for their SPRS score (NIST SP 800-171 assessment). The score is public information submitted to the DoD SPRS system.
  • Past performance contracts — if they list specific contract numbers, you can look them up in USASpending.gov or the Federal Procurement Data System (FPDS) to confirm scope and value.

Red Flags in a Capabilities Statement

These indicators suggest the supplier is not a qualified defense manufacturer — or is at minimum not worth spending time on:

Expired certifications. If AS9100 or ITAR registration is listed as current but the certificate shows an expiration date in the past, the supplier has a compliance gap. Do not assume they renewed it — follow up and ask for updated documentation.
Missing CAGE code or NAICS codes. A defense supplier working with DoD programs needs both. Absence means either the supplier does not actually work federal contracts, or they are so new they have not completed basic registration. Either way, disqualify until they produce documentation.
Vague capacity descriptions. "We have extensive manufacturing capabilities" and "Our facility can handle large-scale production" tell you nothing. You want employee count, square footage of manufacturing space, key equipment list, and typical lead times. Suppliers who cannot quantify their capacity either do not know it themselves, or are hiding that they subcontract everything.
Outdated contact information or no website. A capabilities statement with a Gmail address, no website, and a phone number from a different company is a warning sign. Legitimate defense manufacturers have professional web presence and corporate email domains.
No relevant past performance. A supplier claiming "defense experience" but unable to name a single prime contractor or program in your sector is not a qualified source for your requirement. Ask for specific examples before investing time in a full evaluation.

How ForgeLine Verifies Supplier Capabilities

ForgeLine's supplier directory does the initial verification work for you. Every supplier listed in our directory has been pre-screened for:

  • Active CAGE code registered on sam.gov
  • ITAR registration with the US State Department DDTC
  • AS9100 or ISO 9001 certification with current scope statement
  • CMMC level (when applicable for their customer base)
  • Verified domestic manufacturing address (US-based production)

You can filter by certification type, material and process, and state to build a shortlist of verified suppliers without doing the SAM.gov and DDTC verification manually for each candidate. Our supplier evaluation guide walks through the follow-up questions to ask once you have a capabilities statement in hand.

Frequently Asked Questions

What sections of a capabilities statement should I read first?
Read the CAGE code, NAICS codes, quality certifications (AS9100, ISO 9001, CMMC), and past performance sections first. CAGE code validates the company is registered in federal systems. NAICS codes confirm they are categorized correctly for the type of work you need. Certifications tell you what quality and cybersecurity standards they meet. Past performance shows relevant program experience. Skip vague capability descriptions until you have verified these basics.
How do I verify a CAGE code is real?
Search the CAGE code on sam.gov. A valid CAGE code confirms the company is registered in the federal contractor database and has an active status. If the CAGE code does not return a match, or returns a different company name, that is a red flag. A CAGE code is required to bid on any federal contract and to receive ITAR-controlled technical data.
What are the biggest red flags in a capabilities statement?
Outdated certifications (expired AS9100, lapsed ITAR registration), missing or invalid CAGE code, vague capacity descriptions with no actual numbers (no employee count, no square footage, no equipment list), outdated contact information, and no past performance relevant to your program. Also watch for capabilities listed without supporting evidence — claims of "ITAR registered" with no registration number, or "AS9100 certified" without a scope statement.

Find Verified Defense Suppliers

ForgeLine pre-screens every supplier in our directory — no need to manually verify CAGE codes and certifications from a capabilities statement. Search by material, process, state, or certification level.

🔍 Search Verified Suppliers → Browse All Suppliers →