This Solicitation opportunity from Department Of Defense was posted on June 15, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.
CAP-PLUG, PROTECTIVE
Contract Overview
Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.
AI Contract Overview
The procurement is for National Stock Numbers (NSNs) related to 6.2L diesel engine and transmission components, structured as an indefinite quantity contract with a three-year base period and two option years, for a total potential duration not to exceed five years. The contract will be awarded through an open solicitation available exclusively online via DIBBS, with no hard copies provided, and responses are due by July 16, 2026. CLINs 0001 through 0003 are reserved exclusively for small businesses under a 100% small business set-aside, each governed by distinct NAICS codes and size standards ranging from 600 to 1,500 employees, while CLINs 0004 through 0010 are open to all eligible offerors with size standards up to 1,500 employees under NAICS 333618 and other applicable codes. The Government has determined the items to be commercial and is applying the policies of FAR Part 12.201-1, and this acquisition consolidates multiple requirements under FAR 7.107-2 as necessary and justified. FOB Origin delivery terms apply, and awards will be made based on a combination of price, past performance, delivery capability, and small business participation, with no specific weights provided for each factor. All required NSNs and associated details, including quantities, are listed in Attachment #1, and the contracting office is located in Columbus, Ohio, under the DLA Land and Maritime organization.
General Info
Agency
NAICS
Place of Performance
USASet-Aside
Timeline
Submission Closed
Organization & Contact Information
Full Description
(see Attachment # 2 for PIDs and Packaging)
SPE7LX-26-R-X026
Form (CONTINUED)
Part 12 Clauses
52.212-4 TERMS AND CONDITIONS -COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (DEVIATION 2026-O0038) (FEB
2026) FAR
CLAUSES ADDED TO PART 12 BY ADDENDUM
52.202-1 DEFINITIONS (JUN 2020) FAR
52.203-3 GRATUITIES (APR 1984) FAR
52.203-5 COVENANT AGAINST CONTINGENT FEES (MAY 2014) FAR
52.203-6 RESTRICTIONS ON SUBCONTRACTOR SALES TO THE GOVERNMENT (JUN 2020) FAR
52.203-6 RESTRICTIONS ON SUBCONTRACTOR SALES TO THE GOVERNMENT ALTERNATE I (NOV 2021) FAR
52.203-11 CERTIFICATION AND DISCLOSURE REGARDING PAYMENTS TO INFLUENCE CERTAIN FEDERAL TRANSACTIONS
(SEP 2007) FAR
52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN FEDERAL TRANSACTIONS (JUN 2020) FAR
52.203-13 CONTRACTOR CODE OF BUSINESS ETHICS AND CONDUCT (NOV 2021) FAR
52.203-19 PROHIBITION ON REQUIRING CERTAIN INTERNAL CONFIDENTIALITY AGREEMENTS OR STATEMENTS (JAN 2017)
FAR
252.203-7000 REQUIREMENTS RELATING TO COMPENSATION OF FORMER DOD OFFICIALS (SEP 2011) DFARS
252.203-7001 PROHIBITION ON PERSONS CONVICTED OF FRAUD OR OTHER DEFENSE-CONTRACT-RELATED FELONIES (JAN
2023) DFARS
252.203-7002 REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (DEC 2022) DFARS
252.203-7003 AGENCY OFFICE OF THE INSPECTOR GENERAL (AUG 2019) DFARS
52.204-13 SYSTEM FOR AWARD MANAGEMENT -MAINTENANCE (DEVIATION 2026-O0038) (FEB 2026) FAR
52.204-13 SYSTEM FOR AWARD MANAGEMENT -MAINTENANCE ALT I (DEVIATION 2026-O0038) (FEB 2026) FAR
52.204-19 INCORPORATION BY REFERENCE OF REPRESENTATIONS AND CERTIFICATIONS (DEVIATION 2026-O0038) (FEB
2026) FAR
52.204-90 OFFEROR IDENTIFICATION (DEVIATION 2026-O0038) (FEB 2026) (FAR)
As prescribed in 4.208(c)(1), insert the following provision: If the Offeror will not have an active Federal Government contracts registration in the System for Award Management (https://www.sam.gov) when submitting its offer, it shall complete paragraphs (c) and (d) of this provision and include its responses with its offer. (a) Definitions. As used in this provision -Commercial and Government Entity (CAGE) code has the meaning provided in the clause at FAR 52.204-91, Contractor Identification, of this solicitation. Common parent means that corporate entity that owns or controls an affiliated group of corporations that files its Federal income tax returns on a consolidated basis, and of which the offeror is a member.
SPE7LX-26-R-X026
Part 12 Clauses (CONTINUED)
Electronic Funds Transfer (EFT) indicator means a bank account identifier to establish additional System for Award Management records for identifying alternative EFT accounts (see part 32) for the same entity. Highest-level owner means the entity that owns or controls an immediate owner of the offeror, or that owns or controls one or more entities that control an immediate owner of the offeror. No entity owns or exercises control of the highest-level owner. Immediate owner means an entity, other than the offeror, that has direct control of the offeror. Indicators of control include, but are not limited to, one or more of the following: ownership or interlocking management, identity of interests among family members, shared facilities and equipment, and the common use of employees. There may be more than one immediate owner (e.g., joint ventures). Predecessor means an entity whose assets were acquired by the offeror or another entity (most often through merger or acquisition) and whose affairs are now carried out by the offeror or the other entity under a new name. Taxpayer Identification Number means the number required by the Internal Revenue Service (IRS) to be used by the offeror to report income tax and other returns. It may be either a Social Security Number or an Employer Identification Number. Unique entity identifier (UEI) has the meaning provided in the clause at FAR 52.204-91, Contractor Identification, of this solicitation. (b) Unique entity identifier (UEI). (1) The Offeror shall enter, in the block with its name and address on the cover page of its offer, the annotation “Unique Entity Identifier” followed by the UEI that identifies the Offeror's name and address exactly as stated in the offer. The Offeror shall also enter its EFT indicator, if applicable. (2) If the Offeror does not have a UEI, it shall go to https://www.sam.gov to obtain one. The Government will independently validate the existence and uniqueness of the Offeror before assigning a UEI. (c) Taxpayer identification. The Offeror shall provide with its offer the following information that is necessary to comply with debt collection requirements of 31 U.S.C. 7701(c) and 3325(d); reporting requirements of 26 U.S.C. 6041, 6041A, and 6050M; and the implementing IRS regulations: (1) Taxpayer identification number (TIN) □ TIN: ____________; □ TIN has been applied for; or □ TIN is not required because: □ Offeror is a nonresident alien, foreign corporation, or foreign partnership that does not have income effectively connected with the conduct of a trade or business in the United States and does not have an office or place of business or a fiscal paying agent in the United States; □ Offeror is an agency or instrumentality of a foreign government; or □ Offeror is an agency or instrumentality of the Federal Government. (2) Type of organization. □ Sole proprietorship; □ Partnership; □ Corporate entity (not tax-exempt); □ Corporate entity (tax-exempt); □ Government entity (Federal, State, or local); □ Foreign government; □ International organization per 26 CFR 1.6049-4; or □ Other. (3) Common parent. □ Offeror is not owned or controlled by a common parent as defined in paragraph (a) of this provision; or □ Name and TIN of common parent: Name: ____________ TIN: ____________ (4) The TIN provided in paragraph (c)(1) of this provision may be matched with IRS records to verify the accuracy of the Offeror's TIN. The Government may use the TIN to collect and report on any delinquent amounts arising out of the Offeror's relationship with the Government (31 U.S.C. 7701(c)(3)). (d) Commercial and Government Entity (CAGE) code. (1) The Offeror shall provide its CAGE code with its offer with its name and location address or otherwise include it prominently in its offer. The CAGE code shall be for that name and location address. Insert the word “CAGE” before the code. The Offeror may obtain a CAGE code as indicated in the following table.
If the Offeror is... Then... Located in the United States or its outlying areas
Submit a request to the DLA CAGE Branch via https://cage.dla.mil
Located outside the United States and its outlying areas and its country is a member of the North Atlantic Treaty Organization (NATO) or a sponsored nation
Contact the appropriate National Codification Bureau (https://www.nato. int/structur/ac/135/about/ contacts)
Located outside the United States and its outlying
Contact the NATO Support and Procurement Agency
SPE7LX-26-R-X026
Part 12 Clauses (CONTINUED)
If the Offeror is... Then... areas and its country is not a member of NATO or a sponsored nation
(NSPA) (https://eportal. nspa.nato.int/AC135Public/ scage/CageList.aspx)
(2) The Offeror shall provide the CAGE code and legal business name (Do not use a “doing business as” name) for—
(i) Its immediate owner(s), if any;
(ii) Its highest-level owner, if any; and
(iii) Any predecessor(s), or predecessor of an Offeror’s predecessor, that held a Federal contract or grant within the last three years.
Owner Type CAGE Code Legal Business Name Immediate owner Highest-level owner Predecessor
Predecessor CAGE code may be marked “Unknown.”
(3) If the Offeror has more than one immediate owner (such as a joint venture), give the information for each owner (or joint venture participant). If the Offeror has more than one predecessor, provide information for each predecessor in reverse chronological order. (End of provision)
52.204-91 CONTRACTOR IDENTIFICATION (DEVIATION 2026-O0038) (FEB 2026) (FAR)
As prescribed in 4.208(c)(2), insert the following clause: Definitions. As used in this clause -Commercial and Government Entity code means -(1) An identifier assigned to entities located in the United States or its outlying areas by the Defense Logistics Agency (DLA) Commercial and Government Entity (CAGE) Branch to identify a commercial or government entity by unique location (referred to as “CAGE code”); or (2) An identifier assigned by a member of the North Atlantic Treaty Organization (NATO) or by the NATO Support and Procurement Agency (NSPA) to entities located outside the United States and its outlying areas that the DLA CAGE Branch records and maintains in the CAGE master file (referred to as “NCAGE code”). Unique entity identifier means an identifier used to identify a specific commercial, nonprofit, or Government entity. (b) Unique entity identifier (UEI). The Contractor shall ensure that its UEI is maintained throughout the life of the contract. (c) Commercial and Government Entity (CAGE) code. The Contractor shall ensure that the CAGE code is maintained throughout the life of the contract. The Contractor shall request changes to a CAGE code as indicated in the following table
If the Contractor is... Then... Registered in the System for Award Management (SAM)
Initiate the change by updating its SAM registration Located in the United States or its outlying areas and is not registered in SAM
Submit a change request to the DLA CAGE Branch via https://cage.dla.mil
Located outside the United States and its outlying areas and is not registered in SAM
Request a change by contacting the appropriate National Codification Bureau ( https://www.nato. int/structur/ac/135/about/ contacts) or NSPA ( https:// eportal.nspa.nato.int/ AC135Public/scage/ CageList.aspx)
(d) Communicating changes. The Contractor shall communicate any change to its UEI or CAGE code to the Contracting Officer within 30 days after the change, so a modification can be issued to update the UEI or CAGE code on this contract. A change in the UEI does not necessarily require a novation. (End of clause)
252.204-7003 CONTROL OF GOVERNMENT PERSONNEL WORK PRODUCT (APR 1992) DFARS
SPE7LX-26-R-X026
Part 12 Clauses (CONTINUED)
252.204-7022 EXPEDITING CONTRACT CLOSEOUT (MAY 2021) DFARS
252.204-7025 NOTICE OF CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025) DFARS
(a) Definitions. As used in this provision, controlled unclassified information (CUI), current, Cybersecurity Maturity Model Certification (CMMC) status, Cybersecurity Maturity Model Certification unique identifier (CMMC UID),Federal contract information (FCI), and Plan of action and milestones have the meaning given in the Defense Federal Acquisition Regulation Supplement 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements, clause of this solicitation. (b)(1) Cybersecurity Maturity Model Certification (CMMC) level. The CMMC level required by this solicitation is: [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]. This CMMC level, or higher (see 32 CFR part 170), is required prior to award for each contractor information system that will process, store, or transmit Federal contract information (FCI) or controlled unclassified information (CUI) during performance of the contract. (2) The Offeror will not be eligible for award of a contract, task order, or delivery order resulting from this solicitation if the Offeror does not have, for each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of a contract resulting from this solicitation -(i) The current CMMC status entered in the Supplier Performance Risk System (SPRS) ( https://piee.eb.mil) at the CMMC level required by paragraph (b)(1) of this provision; and (ii) A current affirmation of continuous compliance with the security requirements identified at 32 CFR part 170 in SPRS. (c) Plan of action and milestones. If the Offeror has a CMMC Status of Conditional, the Offeror shall successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final. (d) CMMC unique identifiers. The Offeror shall provide, in the proposal, the CMMC unique identifier(s) (CMMC UIDs) issued by SPRS for each contractor information system that will process, store, or transmit FCI or CUI during performance of a contract, task order, or delivery order resulting from this solicitation. The Offeror also shall update the list when new CMMC UIDs are generated in SPRS. The CMMC UIDs are provided in SPRS after the Offeror enters the results of self-assessment(s) for each such information system. (End of provision)
252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING (DEVIATION 2024-O0013)
(MAY 2024) DFARS
(a) Definitions. As used in this clause
Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
Contractor attributional/proprietary information means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
Controlled technical information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
Covered contractor information system means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
Covered defense information means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI)
Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is -
(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
Cyber incident means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an
SPE7LX-26-R-X026
Part 12 Clauses (CONTINUED)
information system and/or the information residing therein.
Forensic analysis means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
Malicious software means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
Media means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
Operationally critical support means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
Rapidly report means within 72 hours of discovery of any cyber incident.
Technical information means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data --Other Than Commercial Products and Commercial Services, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:
(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:
(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract. (ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.
(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:
(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”, Revision 2 (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171 ).
(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.
(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
(C) If the DoD CIO has previously adjudicated the contractor's requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.
(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ( https:// http://www.fedramp.gov/resources/documents/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
SPE7LX-26-R-X026
Part 12 Clauses (CONTINUED)
(c) Cyber incident reporting requirement.
(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall -
(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor's network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor's ability to provide operationally critical support; and
(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.
(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.
(d) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with NSN/Part Number: 5340-00-960-9340
More opportunities from Department Of Defense → STRATEGIC ACQ PROGRAM DIRECTORATE
Same awarding agency
Find Active Opportunities Like This
Get AI-powered intelligence on the opportunities still open
Every page of the solicitation package shredded into a compliance breakdown
AI-powered matching based on your capabilities and past performance
Competitor and incumbent history on the requirement
Automated alerts on amendments, Q&A deadlines, and award
Join 650+ contractors already using CLEATUS
