Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance & CUI Protection (Subcontractor Flow-Down)

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The subcontract requires strict adherence to NIST SP 800-171 standards to protect covered defense information, ensuring all controlled unclassified information is safeguarded through appropriate security controls throughout the subcontractor’s systems and processes. Compliance includes implementing access controls, incident detection and reporting procedures, audit logging, and continuous monitoring practices aligned with federal cybersecurity requirements. The subcontractor must maintain full audit readiness at all times, allowing for documentation reviews, system assessments, and compliance verifications by the prime contractor or government representatives without prior notice. Any security incident involving covered defense information must be reported immediately in accordance with established timelines and protocols, with full cooperation required during investigative and remediation efforts. The subcontractor is responsible for ensuring all personnel, subcontractors, and third parties under their control also comply with these cybersecurity obligations. Failure to meet NIST SP 800-171 requirements may result in contract termination, financial penalties, or loss of eligibility for future defense work. This obligation flows directly from the prime contract and applies regardless of the subcontractor’s size or location, reinforcing a zero-tolerance stance for noncompliance with CUI protection standards within the Department of Defense supply chain.

General Info

Subcontractor must fully comply with NIST SP 800-171 for CUI protection, with immediate incident reporting and zero tolerance for noncompliance.

Agency

Department Of Defense → Defense Logistics AgencyView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

Not specified

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → Defense Logistics Agency
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → Defense Logistics Agency
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Ensure subcontractor compliance with NIST SP 800-171 for safeguarding covered defense information, including incident reporting and audit readiness.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
SLED
Azure Consulting IDIQThe Port of Seattle is preparing to engage a qualified cloud services partner through an Indefinite Delivery/Indefinite Quantity (IDIQ) contract to support the adoption, modernization, and optimization of Microsoft Azure cloud and hybrid environments. The primary focus will be on evaluating and strengthening the existing Azure architecture, guiding the implementation of new services, and ensuring all deployments align with organizational standards, operational requirements, and long-term scalability goals. Key objectives include enhancing security posture, improving system resiliency, and optimizing cloud performance to meet evolving business needs. The partner will be expected to provide expert consultation throughout the lifecycle of Azure initiatives, from design and deployment to ongoing refinement and compliance validation. This engagement is managed by the Port of Seattle’s ICT Enterprise Infrastructure Services division, with primary point of contact Carol Hassard and Project Manager Jim Dawson overseeing the process. The solicitation is posted under NAICS code 541512 for computer systems design services, with all work expected to be performed in alignment with the Port’s internal frameworks and security protocols. The anticipated timeline for this initiative begins with a forecast posting in July 2026, signaling the upcoming availability of formal solicitation documents for qualified vendors.
ICT Enterprise Infrastructure Services

POSTED

about 1 hour ago

DEADLINE

N/A
View Details
NAICS: 541512
New
SLED
FIDS Software ReplacementThe Port of Seattle through its ICT Enterprise Infrastructure Services is preparing to replace its existing Flight Information Display System software with a new solution to enhance airport operations and passenger information capabilities. This initiative is classified under NAICS code 541512 for Custom Computer Programming Services and is currently in the forecasting stage with a posted date of July 31, 2026. The project involves developing and deploying modern software tailored to display real-time flight data across multiple terminals, ensuring accuracy, reliability, and seamless integration with existing airport systems. The primary point of contact is Farlis Lewis, reachable via email and phone, with Krista Sadler serving as the project manager for technical coordination and oversight. The software replacement aims to improve system performance, user interface clarity, and system scalability to meet future growth demands at the airport. While the specific technical requirements and procurement timeline have not yet been released, interested vendors should prepare to demonstrate expertise in aviation information systems, real-time data integration, and customer-facing display technologies. The place of performance is likely centered at Seattle-Tacoma International Airport, and there is no indication of a set-aside for small businesses or other socioeconomic categories at this stage. All inquiries and future solicitations will be coordinated through the provided contact information and the official solicitation portal linked in the data.
ICT Enterprise Infrastructure Services

POSTED

about 1 hour ago

DEADLINE

N/A
View Details
NAICS: 541512
New
Federal
J065--Federal EHR Oracle Migration Support in support of the VISN VAHCS
Solicitation # 36C26326Q0989
The Department of Veterans Affairs, through Network Contracting Office 23, intends to award a sole source, firm-fixed price contract to L1 Enterprises, the sole authorized service-disabled veteran-owned small business distributor for KARL STORZ upgraded equipment, under the authority of 38 U.S.C. 8127(c) and implementing regulations. This action is justified under the sole source provision of FAR 13.106-1(b)(2) as the KARL STORZ equipment is required to ensure veteran safety and no other source can provide the specific, authorized product. The acquisition is classified under NAICS code 541512 with service code J065, and the contract will support the VA Health Care System, with performance located in Eagan, Minnesota. While this notice is a presolicitation and not a formal solicitation, the government invites other responsible vendors to submit capability statements demonstrating they can meet the requirement, with submissions due by 10:00 AM Central Time on August 12, 2026, to marie.weathers@va.gov. Any received responses will be evaluated solely to determine whether competitive procurement is feasible, but the government retains exclusive discretion to proceed with the sole source award to L1 Enterprises based on its determination that only one source is reasonably available. The point of contact for inquiries is Contract Specialist Marie Weathers at the provided email and phone number.
Network Contract Office 23 (36C263)

POSTED

about 18 hours ago

DEADLINE

in 12 days
View Details
NAICS: 541512
New
Federal
DE01--ECO Enterprise Service Desk (ESD) Tier One Support - RFI (VA-26-00084022)
Solicitation # 36C10B26Q0700
This Request for Information (RFI) for Enterprise Service Desk (ESD) Tier One Support is issued by the Department of Veterans Affairs for planning purposes only and does not constitute a solicitation, commitment to procure, or obligation to award a contract. Interested vendors are asked to provide detailed technical and operational information on their ability to deliver Tier One support services as outlined in the draft Performance Work Statement, with particular emphasis on the integration of AI-driven tools such as post-interaction summaries, real-time knowledge surfacing, automated ticket triage, and self-service resolution. Responses must be limited to 15 pages, exclude marketing materials and generic capability statements, and include specific, actionable details on how AI and automation will impact agent workflows, training, QA processes, staffing models, and handle time reduction. Vendors must explicitly address how they will measure and report contacts that are attempted by AI but escalated to live agents, how their pricing structure will adapt to changing contact volumes and complexity, and how they will manage workforce redeployment as automation increases. A Rough Order of Magnitude (ROM) with labor categories, hours, unit pricing, and assumptions is required, alongside corporate experience with specific contract references including agency, dollar value, and contract number. Only certified SDVOSBs and VOSBs may respond under the set-aside provision, and they must demonstrate compliance with the 50% service performance limitation for non-certified firms. All submissions must include company details, NAICS code, UEI, existing contract vehicles, and proof of SBA certification for veteran-owned entities, and must be sent via email by the deadline with “Enterprise Service Desk (ESD) Tier One Support” in the subject line and flagged as Proprietary Information if applicable.
Technology Acquisition Center Nj (36C10B)

POSTED

about 18 hours ago

DEADLINE

in 12 days
View Details
NAICS: 541512
New
Federal
Zero Trust Architecture (ZTA) Vendor Framework
Solicitation # SSC-PKA_ZTA-VFC_2026
The U.S. Space Systems Command’s S6 division, under the Department of Defense, has issued a Request for Information to gather detailed information from commercial vendors offering Zero Trust Architecture solutions. This RFI is strictly for planning and informational purposes and does not represent an invitation to bid, nor does it obligate the government to award any contract. Vendors are encouraged to submit product details, technical capabilities, and implementation approaches aligned with the DoD’s Zero Trust Framework and NIST guidelines through a designated online form or fillable PDF. All costs associated with responding to this RFI are the sole responsibility of the respondent, and no reimbursement will be provided. The objective is to build a categorized vendor framework that will help mission system stakeholders evaluate and select commercial ZT solutions that best address specific capability gaps and operational needs. Responses must be submitted by September 11, 2026, and inquiries should be directed to the designated Point of Contact, Abel Moreno, and Alternate Point of Contact, Mark Munoz. While the government may provide clarifications, it is not required to respond to all questions. Participation in this RFI does not guarantee future solicitation participation. The effort aims to standardize vendor assessments across the market, where Zero Trust offerings currently vary widely in maturity and functionality, ultimately enabling more informed decision-making for mission-critical systems within the Space Force and broader defense ecosystem.
FA8802 Integration Operation Pikpke

POSTED

about 18 hours ago

DEADLINE

in about 1 month
View Details
NAICS: 541512
New
International
TBIPS Professional Services
Solicitation # T8493-26-0023
The Canadian Coast Guard’s Aircraft Services Directorate is seeking specialized informatics professional services through a task-based contract under the TBIPS Supply Arrangement to support the Aircraft Services Modernization Project, centered on the Aircraft Inventory Maintenance and Management System (AIMMS) and its integration with Microsoft Dynamics and Oracle R12 EBS. Only Tier 1 holders of the TBIPS Supply Arrangement within the National Capital Region are eligible to bid, and the invited suppliers include fourteen qualified firms, some operating in joint ventures. The work encompasses complex data migration, system integration, development and maintenance of MS Power Apps solutions, project governance, and ensuring architectural integrity across the SaaS platform and corporate systems. All contractors must meet a Minimum Corporate Security Requirement of Secret and support personnel must hold Secret-level clearances, with the Security Requirement Code T8493-26-0023 in effect. The contract is anticipated to last three years with a one-year irrevocable option, and each resource is expected to contribute 200 to 210 days of effort. Proposals must be submitted by August 5, 2026, to Tanya Nadeau, Contracting Authority, and are subject to multiple international and domestic trade agreements including CETA, CPTPP, and the Canadian Free Trade Agreement. Bidders may request a debriefing within 15 working days of notification of results, and all documentation may be submitted in either official language.
Canadian Coast Guard

POSTED

1 day ago

DEADLINE

in 12 days
View Details

More opportunities from Department Of Defense → Defense Logistics Agency

Same awarding agency

NAICS: 325412
New
DIBBS
Azithromycin Tablets Solicitation
Solicitation # SPE2D2-26-R-0008
The solicitation SPE2D2-26-R-0008 for Azithromycin Tablets is a Lowest Price Technically Acceptable (LPTA) acquisition issued by the Defense Logistics Agency under the Department of Defense, targeting pharmaceutical suppliers to provide specified tablet formulations in unit-of-use packaging meeting stringent regulatory and technical standards. The contract encompasses five clinical line items for 250mg, 500mg, and 600mg azithromycin tablets in 6-count, 3-count, and 30-count bottles, with base quantities for each and four one-year option periods allowing for a potential five-year contract duration. Technical acceptability is strictly gated by compliance with current Good Manufacturing Practices, FDA licensing through an approved NDA, ANDA, or BLA, therapeutic equivalence “A” ratings, adherence to the Drug Supply Chain Security Act, and full disclosure of manufacturing facility locations and foreign ownership status. The packaging must be child-proof, cylindrical with minimum dimensional specifications, free of glass, and compatible with automated dispensing systems like Baxter ATC and OptiFill, while requiring GS1-128 or HIBCC barcode labeling at the unit level with NDC, lot number, and expiration date encoded to ANSI/ISO/IEC quality grade C or higher, avoiding barcode placement across perforations or in proximate pairs. Offerors must submit electronic proposals via the DIBBS portal in two volumes—one technical compliance package and one price proposal—with no page limits, but failure to address mandatory representations under FAR 52.204-19, DFARS 252.204-7018, and other referenced clauses results in disqualification. Past performance and technical compliance are evaluated as pass/fail gates before price is considered as the sole award criterion. Delivery is FOB destination to DLA and VA Prime Vendor distribution centers, with performance commencing 45 days after award and pricing effective 15 days after that. Contract payments are routed through Prime Vendor contractors, not directly by the government, and rights to payment cannot be assigned. The closing date has been amended to August 12, 2026, at 3:00 PM EDT, with proposals requiring valid UEI and CAGE codes and certification of small business or other socioeconomic status if applicable. The procurement excludes covered telecommunications equipment and requires full disclosure of country of origin for both active pharmaceutical ingredients and final products, with no tolerance for uncorrected FDA violations
Pharmaceutical Preparation Manufacturing

POSTED

about 18 hours ago

DEADLINE

in 13 days
View Details
NAICS: 238220
New
DIBBS
DSCR B150 ARNG Boiler Replacement
Solicitation # SP4703-26-Q-0061
The Defense Supply Center Richmond (DSCR) is soliciting a firm-fixed price contract for the replacement of the B150 ARNG boiler under solicitation SP4703-26-Q-0061, set aside entirely for small businesses with a size standard of $19 million under NAICS code 238220. The project has an estimated magnitude between $250,000 and $500,000 and requires performance at DSCR in Richmond, Virginia, with a 270-day period of performance beginning from the Notice to Proceed. The prime contractor must maintain a legitimate, publicly visible office within a 120-mile radius of DSCR that is registered and active on SAM.gov; subcontractor locations are not acceptable, and the prime must substantiate its office through documentation such as a lease agreement or proof of business mail delivery. The office must be established and verified in SAM.gov by the solicitation closing date; newly registered offices submitted before the deadline are acceptable. Proposals must be technically acceptable, meeting all mandatory requirements including SAM registration, location validation, and submission of required documentation such as a project narrative, list of definable work features, projected timeline, and at least five relevant past projects completed within the last five years. Past performance will be evaluated using CPARS and SPRS data. Award will go to the lowest-priced, technically acceptable offeror. The contractor must comply with all applicable regulations including OSHA 29 CFR 1926, USACE EM 385-1-1, the Buy American Act, the Hazard Communication Standard, and MIL-STD-129 for packaging and labeling. Hazardous materials must be labeled appropriately, and radioactive materials must meet specific activity thresholds per MIL-STD-129. Liquidated damages of $500 per calendar day will apply for delays in completion, and final acceptance requires successful punch-out, pre-final, and final inspections along with training of Government personnel. Payment requests must be submitted electronically through WAWF, with no hard copies accepted, and payments exceeding 80% of the contract value are contingent upon final inspection approval. All contractor personnel must complete DBIDS pre-enrollment at least five days before the site visit on July 30, 2026, and must pass military installation screening to gain access. The contractor must also comply with DFARS and FAR clauses related to antiterrorism training, whistleblower protections, subcontractor reporting
Plumbing, Heating, and Air-Conditioning Contractors

POSTED

about 18 hours ago

DEADLINE

in 13 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance for Contractor Information SystemsThis contract requires the implementation of NIST Special Publication 800-171 controls to safeguard Covered Defense Information on contractor information systems, ensuring alignment with federal cybersecurity standards for protecting sensitive defense data. The scope encompasses establishing, maintaining, and validating a robust cybersecurity posture that meets all regulatory requirements for data protection, access control, audit logging, and system integrity, while also fulfilling mandatory cyber incident reporting obligations as stipulated by applicable Department of Defense directives. The subcontract is issued by the Defense Logistics Agency under the Department of Defense and falls under NAICS code 541512, indicating it pertains to computer systems design services with a focus on cybersecurity compliance. The solicitation is open for responses until August 10, 2026, and the performance location is not specified, implying work may be performed at the contractor’s secure facility or wherever the system hosting Covered Defense Information resides. As a subcontract, the awardee must ensure full alignment with prime contract cybersecurity obligations and may be subject to verification, assessment, or audit by the government or its representatives. Compliance is non-negotiable, and failure to implement the required controls or report incidents timely may result in contract termination, financial penalties, or loss of eligibility for future defense work. The target audience includes contractors with experience in defense information systems, NIST controls implementation, and incident response protocols.
Computer Systems Design Services

POSTED

1 day ago

DEADLINE

in 10 days
View Details