CRA is one of the largest federal IT spenders. Vendor sites need to signal IT modernization capability, security clearance posture, and CRA-specific past performance.
CRA procurement bias toward modernization-capable IT services vendors. Sites should emphasize cloud-modernization, mainframe-modernization, taxpayer-service-design, and compliance-system experience where applicable.
CRA is in a multi-year modernization push: legacy mainframe migration, taxpayer-experience redesign, agile delivery adoption, and cloud platform expansion. Vendor sites positioning against CRA should signal modernization-relevant capability: cloud-native experience, legacy-modernization references, agile delivery, and human-centred-design competency. Generic 'we deliver IT services' messaging doesn't differentiate.
CRA vendor work touches taxpayer data — Privacy Act, ITSP-40.111 cyber posture, and CRA-specific data-handling requirements all bleed into vendor evaluation. Site copy should signal awareness: published privacy posture, security.txt or responsible-disclosure page, and named senior personnel with CRA-relevant experience.
Significant share, plus SBIPS for solutions-based files and ProServices for advisory.
Reliability Status is the floor for most files; Secret-level applies to specific files involving sensitive taxpayer data or compliance investigations.
Significant TBIPS share for IT services, plus SBIPS for solutions-based files and ProServices for advisory. CRA also issues directly to standing-offer holders for specific category work.