Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance and NIST SP 800-171 Assessment Support

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

This contract supports compliance with DFARS 252.204-7012 requirements through comprehensive cybersecurity services tailored for government audit readiness. The scope includes developing a System Security Plan, conducting a self-assessment against NIST SP 800-171 controls, and submitting the resulting evaluation to the Supplier Performance Risk System. All activities are designed to ensure the contractor meets Department of Defense standards for protecting controlled unclassified information. The work must be performed in Kittery, with a firm deadline for submission on August 4, 2026. This is a small business set-aside subcontract under NAICS code 541512, specifically reserved for total small businesses, and is managed by DLA Maritime within the Department of Defense.

General Info

Small business subcontract for DFARS compliance in Kittery, due August 4, 2026, under NAICS 541512.

Agency

Department Of Defense → DLA Maritime - PortsmouthView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

Kittery, ME, 03904, USA

Set-Aside

SBA

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → DLA Maritime - Portsmouth
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → DLA Maritime - Portsmouth
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Support for DFARS 252.204-7012 compliance, including SSP development, self-assessment, and SPRS reporting for government audit readiness.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
SLED
Azure Consulting IDIQThe Port of Seattle is seeking a qualified cloud services partner to provide consulting services focused on the adoption, modernization, and optimization of Microsoft Azure cloud and hybrid environments. The engagement aims to validate and enhance the existing Azure architecture, guide the implementation of new services, strengthen security posture, improve system resiliency, and ensure all cloud designs align with organizational standards, operational requirements, and long-term scalability goals. The contractor will work closely with the Port’s IT team to align cloud strategies with business objectives and support the transition to more efficient, secure, and future-ready infrastructure. This opportunity is structured as an Indefinite-Delivery/Indefinite-Quantity (IDIQ) contract under the NAICS code 541512 for other computer-related services. The contract is forecasted to be released with no formal solicitation number yet published, and the anticipated posting date is July 28, 2026. Performance will be centered at the Port of Seattle’s facilities, with primary points of contact being Carol Hassard and Jim Dawson, who will oversee procurement and project execution respectively. Potential vendors should be prepared to demonstrate expertise in Azure cloud platforms, hybrid environments, security frameworks, and enterprise-scale architecture design to meet the Port’s evolving technology needs.
ICT Enterprise Infrastructure Services

POSTED

about 4 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
SLED
FIDS Software ReplacementThe Port of Seattle through ICT Enterprise Infrastructure Services is forecasting a contract for the replacement of its existing Flight Information Display System software, aiming to modernize and enhance the system that provides real-time flight data to passengers and staff across airport terminals. The solicitation, posted on July 28, 2026, falls under NAICS code 541512 for Computer Systems Design Services and is intended to support critical airport operations with a reliable, scalable, and user-friendly digital solution. The project will involve developing and deploying new software tailored to the Port’s specific operational requirements, including integration with existing systems, compliance with aviation standards, and maintenance of continuous uptime during transition. Point of contact for the opportunity is Farlis Lewis, who can be reached via email or phone for general inquiries, with Krista Sadler serving as the project manager for technical and implementation coordination. Although no formal solicitation number has been assigned and the place of performance and set-aside details are not yet specified, all work is expected to support the Port’s infrastructure at its airport locations. Interested vendors should monitor the provided UI link for future updates, including formal RFP issuance, evaluation criteria, and submission deadlines, as this forecast signals upcoming procurement activity in the near term.
ICT Enterprise Infrastructure Services

POSTED

about 4 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance and NIST SP 800-171 Assessment SupportThe contract requires support for conducting NIST SP 800-171 assessments at Medium and High impact levels to ensure compliance with CMMC Level 2 requirements for protecting controlled unclassified information. The work involves evaluating systems and processes against the security controls outlined in NIST SP 800-171, identifying gaps, and implementing remediation measures as needed. All assessment findings must be documented and submitted to the Supplier Performance Risk System to validate cybersecurity readiness and maintain eligibility for DoD contracts. The scope is focused exclusively on cybersecurity compliance activities tied to safeguarding sensitive information and does not include hardware, software procurement, or general IT services. This is a subcontract under the Department of Defense, specifically managed by the ASC SUPPLIER OPER AE AND AF DIV, with a solicitation closing on August 27, 2026. The North American Industry Classification System code 541512 indicates the work falls under computer systems design and related services. Performance is expected to support federal cybersecurity mandates without requiring physical presence at a specific location, as no place of performance details are provided. The contracting activity seeks qualified entities capable of delivering accurate, timely assessments that align with federal standards and can be validated through official DoD reporting channels.
ASC SUPPLIER OPER AE AND AF DIV

POSTED

about 7 hours ago

DEADLINE

in 30 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance & CMMC Implementation SupportThe contract seeks specialized support to achieve CMMC Level 2 compliance for systems operating under DFARS and NIST standards, requiring comprehensive services including the development of a System Security Plan, identification of security gaps, and preparation for third-party audits. The scope is focused entirely on enabling contractors to meet the rigorous cybersecurity requirements mandated by the Department of Defense, ensuring that all controls are properly documented, implemented, and verifiable under the CMMC framework. The contractor must demonstrate expertise in translating NIST SP 800-171 requirements into actionable compliance strategies and maintain alignment with evolving DoD cyber policies. This is a total small business set-aside under NAICS code 541512, reserved exclusively for small businesses certified by the Small Business Administration. The opportunity is structured as a subcontract under the Land Supply Chain initiative of the Department of Defense, with a response deadline of August 27, 2026. All work must be performed in accordance with federal acquisition standards and must deliver measurable outcomes that directly support audit readiness. While no specific location is designated for performance, the successful bidder will be expected to engage with federal stakeholders and provide continuous support throughout the compliance lifecycle, including preparation for both self-assessments and external CMMC validations.
LAND SUPPLY CHAIN

POSTED

about 7 hours ago

DEADLINE

in 30 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance (NIST SP 800-171)The contract requires the implementation and documentation of all NIST SP 800-171 cybersecurity controls to ensure compliance with DFARS 252.204-7012, specifically focusing on the development of a comprehensive System Security Plan and a Plan of Action and Milestones document. These deliverables must detail the organization’s approach to protecting controlled unclassified information within its systems, outlining current security postures, identified gaps, and remediation strategies with defined timelines. The work is scoped as a subcontract under the Defense Logistics Agency, Department of Defense, and is tied to the NAICS code 541512 for computer systems design services, indicating the need for technical expertise in cybersecurity architecture and documentation. Implementation must align precisely with federal cybersecurity standards, requiring thorough assessment of existing controls, gap analysis, and coordinated efforts across technical and administrative teams to achieve full compliance. Documentation must be accurate, up to date, and capable of withstanding audit scrutiny, with all measures designed to safeguard federal contract information. The contract does not specify a place of performance or point of contact, suggesting flexibility in execution location while maintaining strict adherence to DoD cybersecurity requirements. The solicitation was posted in 2026, indicating the timeline for performance is likely to begin shortly thereafter, with all deliverables due within a timeframe consistent with federal acquisition obligations.
Defense Logistics Agency

POSTED

about 7 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
International
Application replacement for the end-of-life IFSMR (Integrated Fire Services Management & Reporting)This solicitation, issued under number W2187-SPO-26-289-B, invites ICO Solutions and One Step Information Systems Inc. to submit proposals for replacing the end-of-life IFSMR application with a modern cloud-based or web-based fire services management and reporting solution. The required system must deliver comprehensive functionality including incident reporting and tracking, inspections and prevention management, training and exercises, asset and inventory control, workflow and communications, dashboards and reporting, and document and media management. The contract is structured as a one-year base period with two optional one-year extensions, and may be further extended by two additional irrevocable one-year periods. Evaluation will prioritize technical merit at 70% weight and price at 30%, with proposals due by August 12, 2026. The solution must be hosted entirely within Canada and fully compliant with Protected A information handling standards, meeting all applicable government security, privacy, and IT security requirements including SRCL and commercial cloud obligations. The contractor must maintain a valid Designated Organization Screening and approved Document Safeguarding Capability at the Protected A level throughout the contract term. All personnel accessing Protected information must hold at least a valid Reliability Status, while the Company Security Officer and any user with privileged access—such as those who can alter security settings, configurations, audit logs, or other user accounts—must hold a minimum Secret clearance. The supplier is prohibited from processing, storing, or producing Protected information until formal written approvals are obtained. Proof of a completed Cloud Service Provider IT Security assessment and full cooperation with the departmental Security Assessment and Authorization process are mandatory. Subcontracts involving security-sensitive work require prior written authorization. The solution must include robust security controls encompassing multi-factor authentication for administrative access, comprehensive activity logging and auditing, incident management, personal information protection, and measures ensuring service continuity, monitoring, and recovery to fulfill all contractual compliance obligations.
Department of National Defence

POSTED

about 19 hours ago

DEADLINE

in 15 days
View Details
NAICS: 541512
New
International
Grants and Contributions (G&C) ProjectTransport Canada is seeking to enhance its grants and contributions administration process by reviewing existing service designs and developing future-state blueprints that improve financial management, claim processing, incentive programs, data analytics, and business reporting. The goal is to create scalable, reusable components that reduce duplication, ensure consistency, and support long-term program evolution, primarily through the design and implementation of no-code/low-code solutions using Microsoft Power Platform tools such as Power Apps, Power Automate, and Power BI, alongside .NET and C#-based applications. The project will be performed in the National Capital Region (NCR) over a two-year contract period following award, with work phases extending through March 2028. Success requires the contractor to deliver integrated technical solutions, deployable packages, feasibility assessments, knowledge-transfer materials, and comprehensive reporting on milestone progress, resource hours, and outstanding activities—all aligned with mutually agreed-upon deliverable specifications. The contract mandates strict compliance with federal security standards, requiring both a SECRET-level facility security clearance and SECRET-level personnel screenings for all staff handling classified or protected information, alongside adherence to safeguarding protocols for electronic media and a mandatory Non-Disclosure Agreement. Contractors must maintain accounting systems capable of tracking estimated and actual costs, including tender calls, contracts, and machine-readable spreadsheets, and must submit time sheets with daily, 24-hour period details to support invoicing. All bids must conform to pass/fail gates including solicitation compliance, mandatory criteria fulfillment, a minimum technical score of 45 out of 60 points, and a total evaluated price within a specified median band of -20% to +30% of the lowest bid. The award will be based on a weighted combination of technical merit, carrying 70% of the scoring, and price at 30%, with the highest combined score winning. Proposals must be submitted electronically in three distinct sections: technical, financial, and attestations—with pricing strictly confined to the financial submission. Bidders must quote a fixed, all-inclusive Canadian-dollar per diem rate for each resource category, with no rate escalation exceeding 5% across time periods, and must provide evidence of legal status, facility security level, employment equity certification, and signed certifications for education and experience. Payments will be made via direct deposit only upon verified time spent performing work under a valid Task Authorization, with contractors liable to repay any overpayment identified during audit. Weekly status reports are required, and resource substitutions are permitted under defined conditions. Infrastructure, software, and tools must be
Department of Transport

POSTED

about 19 hours ago

DEADLINE

in 8 days
View Details

More opportunities from Department Of Defense → DLA Maritime - Portsmouth

Same awarding agency

NAICS: 335312
New
Federal
EnginesThis contract, identified by solicitation number SPMYM326Q4065, is a combined acquisition issued by DLA Maritime - Portsmouth under the Department of Defense for engines, specifically targeting small businesses as a total small business set-aside under FAR 19.5. The North American Industry Classification System code is 335312, and the required deliverable involves the procurement of remanned Detroit Diesel Series 60 14.0L engines, with a stated requirement of three units. The solicitation closes on August 5, 2026, with proposals required to be submitted electronically via email to the primary point of contact, Gary Chandler, or through the DLA Internet Bid Board System and EDI 850 via approved Value Added Networks. The contract operates under a Lowest Price Technically Acceptable (LPTA) evaluation model, with brand-name mandatory compliance for the specified Volvo-derived engine model due to compatibility requirements with existing military equipment. Performance and delivery are centered at the Portsmouth Naval Shipyard in Kittery, Maine, with FOB Destination terms applicable and all shipments required to comply with MIL-STD-129 for marking and ASTM-D-3951 for packaging, prohibiting materials such as loose fill polystyrene, asbestos, and excelsior. All items must include legible markings with NSN, quantity, QA Designator 4, contract number, and origin/destination details, and Product Verification Test samples must be clearly labeled. Contractors must retain full supply chain traceability documentation for six years after final payment and disclose any use of former government surplus property. Compliance with cybersecurity standards under DFARS 252.204-7019 and prohibitions on telecommunications equipment from specified foreign entities such as Huawei, ZTE, and Dahua is mandatory. Invoicing must be processed through the Wide Area Workflow system, with payments administered by DFAS Columbus under net 30 terms post-acceptance, which occurs at the receiving location in BLDG 170, Kittery, ME. Offerors must hold a valid Unique Entity Identifier and CAGE code, certify their small business status under applicable socioeconomic categories, and affirmatively respond to clauses regarding use of covered telecommunications equipment, mercury content, and prohibited supply chain origins, particularly from the Xinjiang Uyghur Autonomous Region. No contract value is listed due to incomplete pricing data in the solicitation, which directs offerors to submit pricing via
Motor and Generator Manufacturing

POSTED

about 12 hours ago

DEADLINE

in 8 days
View Details
NAICS: 335931
New
Federal
SPECIAL CONNECTOR ASSEMBLY P/N M24231/13-003This solicitation, identified by RFQ number SPMYM326Q7027, seeks qualified small businesses to supply two special connector assemblies in accordance with detailed specifications, under a 100% small business set-aside with a NAICS code of 335931 and a small business size standard of $600,000. The acquisition follows Simplified Acquisition Procedures under FAR Part 12 and uses the Lowest Price Technically Acceptable evaluation method, requiring vendors to submit descriptive literature such as brochures or specification sheets to demonstrate compliance, along with traceability documentation if not the manufacturer, including source and part number verification. Failure to provide these will render the quotation technically unacceptable. All offerors must be registered in SAM.gov, complete and include provisions 252.204-7016 and 252.204-7019, and submit responses via email by 1:00 PM EST on August 7, 2026. The contracting office is the Portsmouth Naval Shipyard under DLA Maritime. The contract incorporates a comprehensive suite of FAR, DFARS, DLA, and local clauses governing quality assurance, cybersecurity, supply chain integrity, domestic sourcing, labor standards, and payment procedures. Key requirements include compliance with Safeguarding Covered Defense Information and Cyber Incident Reporting (252.204-7012), adherence to Buy American and Trade Agreements protocols, prohibition of certain foreign-sourced materials including those from the Xinjiang Uyghur Autonomous Region, and strict traceability and documentation retention policies under DLA C03 and C04 provisions. Vendors must disclose country of origin for each item, provide their Cage Code, business size certification, point of contact, and preferred payment method—either Government Commercial Purchase Card or WAWF—with net 30-day payment terms effective after material acceptance. Payment via third-party platforms like PayPal or Venmo is explicitly prohibited. Offers must clearly affirm capability to meet all technical, regulatory, and logistical standards including FOB-Destination delivery, prohibited packing materials, and specific marking and preparation requirements outlined in local clauses.
Current-Carrying Wiring Device Manufacturing

POSTED

1 day ago

DEADLINE

in 10 days
View Details