Regarding #2 - Clarification is probably needed, especially with regard to who the contract is with/for, but it is not unreasonable to assume that they might be selling through another org that is on GSA and/or a Prime on the contract.
The FIPS stuff is still debateable. I have worked with numerous agencies in DC that have bought devices that make use of encryption that have not received a government certification. IMO, it would depend on what classification of information the devices are intended to store. There is a big difference between sensitive but unclassified (SBU) and secret/top secret.
If the contract was for USB keys and "oh, great, they also have the capability to encrypt our SBU data", then it shouldn't be a big deal.
Like I said though, Jim could clarify this in a simple interview with prearranged questions that the investors would like answered.
What I say is only my opinion or so my wife tells me.