Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

CMMC Level 2 Certification Assessment (Third-Party)

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

This contract entails an independent CMMC Level 2 assessment conducted by a Certified Third-Party Assessment Organization, fulfilling the requirements outlined in clause RD005. The scope includes a comprehensive audit of the contractor’s cybersecurity practices, a detailed review of all relevant documentation, and the delivery of a formal reporting package that validates compliance with the CMMC Level 2 framework. The assessment is performed as a subcontract under the authority of the Defense Logistics Agency, a component of the Department of Defense, and is tied to NAICS code 541612, indicating the nature of the services involves administrative management and general management consulting services. The work is expected to be performed in support of defense-related cybersecurity readiness, though the exact location of performance is unspecified. The contract was posted on July 31, 2026, and is accessible via the DIBBS portal under the referenced contract identifiers.

General Info

CMMC Level 2 assessment by certified third party for DOD cybersecurity compliance under NAICS 541612.

Agency

Department Of Defense → Defense Logistics AgencyView Agency

NAICS

541612 - Human Resources Consulting ServicesView NAICS

Place of Performance

Not specified

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → Defense Logistics Agency
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → Defense Logistics Agency
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Independent CMMC Level 2 assessment by a C3PAO, including audit, documentation review, and reporting per clause RD005.

Similar Contracts

Same NAICS industry code

NAICS: 541612
New
SLED
Cybersecurity and Compliance ManagementThe contract requires ongoing cybersecurity and compliance management services focused on maintaining adherence to NIST SP 800-53 standards, sustaining authority to operate status, implementing robust encryption protocols, and ensuring effective incident response capabilities for payment systems. These responsibilities are critical to safeguarding sensitive financial data and ensuring regulatory alignment across all operational aspects of the systems under management. The work must be performed continuously to uphold security controls, detect and mitigate threats promptly, and respond to breaches in a manner that minimizes disruption and meets state and federal requirements. This subcontract is issued by the California State Controller’s office with a posted date of July 31, 2026, and a response deadline of September 9, 2026. The North American Industry Classification System code 541612 indicates the service falls under computer facilities management services, signaling a need for technical expertise in securing and managing hosted or cloud-based financial infrastructure. The place of performance and point of contact details are not specified, suggesting the work may be performed remotely or across multiple locations within California. All deliverables must align with the state’s cybersecurity framework and support uninterrupted, secure payment processing operations.
State Controller

POSTED

2 days ago

DEADLINE

in about 1 month
View Details
NAICS: 541612
New
SLED
Cybersecurity Compliance Support (Third-Party Assessment Provider)The contract engages a third-party provider to deliver cybersecurity validation services for financial institutions by administering and certifying the Cyber Risk Assessment Questionnaire as an alternative to traditional SOC-2 reports. This arrangement shifts the compliance burden from standardized auditing frameworks to a specialized, tailored assessment process designed to evaluate and validate the cybersecurity postures of financial entities. The provider is responsible for ensuring the integrity, consistency, and regulatory alignment of the questionnaire throughout its deployment, maintaining rigorous standards for certification without reliance on established external audit reports. The agreement is structured as a subcontract under the NAICS code 541612, targeting cybersecurity consulting and related services, with a response deadline of June 1, 2028, and a posted date of July 31, 2026. It is affiliated with the Finance agency in California, though specific office locations and point of contact details are not provided. The scope emphasizes replacing SOC-2 validation with a proprietary assessment framework, implying the need for the provider to establish credible, audit-ready methodologies that financial institutions can confidently use for regulatory and partner compliance purposes. The contract does not specify set-aside status or geographic performance constraints beyond the broader jurisdiction of California.
Finance

POSTED

2 days ago

DEADLINE

in almost 2 years
View Details

More opportunities from Department Of Defense → Defense Logistics Agency

Same awarding agency

NAICS: 541690
New
DIBBS
Hazardous Materials Compliance & Labeling ServicesThe contract pertains to regulatory consulting services focused on hazard communication compliance, specifically requiring the preparation of warning labels and safety data sheets (SDS) that meet both OSHA and military standards. This work is critical to ensuring proper handling, storage, and disposal of hazardous materials across defense operations, with all deliverables needing to align with federal safety regulations and Department of Defense requirements. The services will support the Defense Logistics Agency in maintaining stringent compliance for hazardous materials used in military supply chains and facilities. The contract is classified as a subcontract under NAICS code 541690, which covers other scientific and technical consulting services, and is issued by the Department of Defense through the Defense Logistics Agency. Performance is required at a designated location in Albany, Georgia, with a zip code of 31704-0325. The solicitation was posted on August 2, 2026, and responses must be submitted by August 13, 2026. There is no set-aside designation specified, indicating the opportunity is open to all qualified subcontractors regardless of size or status. All work must be completed in accordance with applicable federal regulations, and contractors are expected to demonstrate expertise in hazard communication standards and military-specific documentation protocols.
Other Scientific and Technical Consulting Services

POSTED

about 6 hours ago

DEADLINE

in 11 days
View Details