Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, July 22 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance & Reporting (CUI Safeguarding)

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract requires full implementation and self-attestation of Cybersecurity Maturity Model Certification (CMMC) Level 2 controls to ensure the protection of Controlled Unclassified Information in accordance with NIST Special Publication 800-171 requirements. This includes establishing, documenting, and maintaining the necessary security practices and procedures across all systems handling CUI, as well as ensuring continuous compliance through internal assessments and formal self-attestation. Compliance must be demonstrated prior to contract award and maintained throughout the performance period, with no third-party validation required for attestation. The contractor is also obligated to promptly report any cyber incidents affecting CUI to the appropriate Defense Industrial Base (DIB) portal in line with federal guidelines, ensuring timely notification, containment, and remediation activities. This subcontract is set aside entirely for small businesses under the SBA’s Total Small Business Set-Aside authority and is governed under NAICS code 541512 for computer systems design services. The solicitation deadline is August 20, 2026, and performance will be conducted in support of the Department of Defense’s Strategic Acquisition Program Directorate, with all activities tied to securing sensitive government information within a federally mandated cybersecurity framework.

General Info

Contract requires CMMC Level 2 self-attestation for CUI protection, small business set-aside, incident reporting, and ongoing compliance.

Agency

Department Of Defense → STRATEGIC ACQ PROGRAM DIRECTORATEView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

US

Set-Aside

SBA

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → STRATEGIC ACQ PROGRAM DIRECTORATE
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → STRATEGIC ACQ PROGRAM DIRECTORATE
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Implementation and self-attestation of CMMC Level 2 controls to protect Controlled Unclassified Information (CUI), including NIST SP 800-171 compliance and cyber incident reporting.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
DIBBS
NIST SP 800-171 Compliance and Assessment SupportThe contract provides third-party support to ensure compliance with NIST SP 800-171 and DFARS 252.204-7012 requirements, focusing on system assessment, documentation, and incident reporting for protected information systems. The work is performed under a subcontract and is tied to the Defense Logistics Agency within the Department of Defense, targeting organizations that handle controlled unclassified information and must demonstrate adherence to federal cybersecurity standards. The service includes evaluating existing systems against the NIST framework, developing or refining documentation to meet regulatory obligations, and establishing processes for timely detection, reporting, and response to cybersecurity incidents. The contract was posted on July 20, 2026, and is classified under NAICS code 541512, which pertains to computer systems design and related services. Performance obligations are expected to support the broader defense supply chain's information security posture, requiring rigorous validation of controls and consistent communication of compliance status. While specific location details are not provided, the nature of the work implies coordination with government and contractor systems operating across multiple sites. The contract emphasizes actionable outcomes—such as remediation plans and audit readiness—rather than advisory services alone, ensuring measurable alignment with DoD cybersecurity mandates.
Defense Logistics Agency

POSTED

about 13 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
DIBBS
Cybersecurity and CDI SafeguardingThe contract requires implementation of NIST SP 800-171 security controls to safeguard Covered Defense Information handled by the contractor, ensuring compliance with federal cybersecurity standards for protecting sensitive unclassified information related to DoD operations. All systems and processes must be configured to meet the full scope of the NIST framework, including access control, audit accountability, incident response, and data encryption, to mitigate risks associated with unauthorized access or data breaches. The contractor is obligated to detect, report, and respond to any cyber incident involving Covered Defense Information within 72 hours of discovery, following established DoD protocols for incident reporting and forensic documentation. This subcontract, issued by the ASC Commodities Division under the Department of Defense, pertains to work performed at the place of performance in New Cumberland, Pennsylvania, with a NAICS code of 541512 indicating IT services and related consulting. The solicitation was posted on July 20, 2026, and responses are due by July 28, 2026, with no set-aside classification specified. Compliance with the contractual cybersecurity mandates is non-negotiable and directly tied to the contractor’s ability to handle federal defense information. Failure to adhere to the required controls or timely incident reporting may result in contract termination, penalties, or loss of eligibility for future DoD work.
ASC COMMODITIES DIVISION

POSTED

about 13 hours ago

DEADLINE

in 7 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance and CUI Protection ServicesThe contract requires the provision of cybersecurity compliance services to ensure adherence to CMMC Level 2 and NIST SP 800-171 standards for the protection of controlled unclassified information. The scope of work centers on implementing and maintaining the necessary safeguards, policies, and procedures to meet federal cybersecurity requirements for handling sensitive government data. Performance is expected to be executed at the designated location in Tracy, California, with the contractor responsible for establishing a compliant cybersecurity posture that aligns with Department of Defense standards for subcontractors handling CUI. The contract type is classified as a subcontract under NAICS code 541512, indicating it falls within the computer systems design and related services category. Issued by the ASC Commodities Division under the Department of Defense, the solicitation was posted on July 20, 2026, with responses due by July 28, 2026. All parties engaging in this effort must ensure full alignment with CMMC Level 2 controls, which include access management, audit and accountability, configuration management, incident response, and data protection measures. The contractor is expected to demonstrate readiness for third-party assessment and ongoing compliance validation without relying on external documentation or referenced files.
ASC COMMODITIES DIVISION

POSTED

about 13 hours ago

DEADLINE

in 7 days
View Details

More opportunities from Department Of Defense → STRATEGIC ACQ PROGRAM DIRECTORATE

Same awarding agency

New
DIBBS
SUPPORT, RETRACTABLEThis solicitation, numbered SPE7LX-26-R-0071, is a total small business set-aside under FAR 19.5 for the procurement of surplus government-owned material identified by NSN 2590-01-183-6816, with an estimated contract value ranging from $2,321.18 to $425,930.68. The contract is structured as an indefinite-delivery/indefinite-quantity (IDIQ) firm-fixed-price vehicle with a one-year base period and no described option periods. Offerors must submit complete proposals via DIBBS or email, adhering to the Uniform Contract Format, and must include signed originals of all required forms, including SF-33 and SF-1449, along with completed Attachment 2 pricing spreadsheet with all orange-highlighted cells filled. All proposals must be received by the closing date and time of August 20, 2026, at 3:00 PM local time, with fax and hand-carried submissions explicitly prohibited. The solicitation mandates that offerors designate authorized representatives and mark any Source Selection Information contained within their submissions. The item described under this NSN is governed by detailed specifications in Attachment 1 and must be delivered in accordance with FOB Origin terms, except during the First Article Test phase, where FOB Destination applies. Inspection is performed at origin for all routine deliveries but also includes a government-conducted First Article Test for initial production validation. Deliveries are managed through delivery orders issued by DLA Land and Maritime in Columbus, Ohio, using EDI, email, or manual methods, and are strictly for stock requirements. Packaging must comply with MIL-STD-129 and DFARS Appendix F, requiring a hard-copy receiving report inside each shipment, and all items must be marked with contract number, lot number, item number, and the phrase “Product Verification Test Samples – Do Not Post.” Contractors are prohibited from using Class I ozone-depleting chemicals. Evaluation of proposals is based on price, past performance, and proposed delivery, with award made on a trade-off basis to the offeror providing the best value to the government, not necessarily the lowest price. Contractors must comply with extensive cybersecurity requirements including NIST SP 800-171, CMMC Level 2 self-attestation, and reporting of cyber incidents under 252.204-7012

POSTED

about 13 hours ago

DEADLINE

in about 1 month
View Details
NAICS: 339991
New
DIBBS
SEAL, NONMETALLIC STThis contract is for the supply of three nonmetallic seals under the National Stock Number 5330-01-645-8042, issued as a Simplified Acquisition through a Total Small Business Set-Aside under NAICS code 339991. The solicitation, numbered SPE7LX-26-U-8867, was posted on July 20, 2026, with responses due by August 4, 2026, and delivery is required 126 days after award. The contract is structured as an Indefinite Delivery Contract with a maximum value of $350,000, and orders will be issued over a one-year period following award. Delivery is FOB origin, with inspection and acceptance taking place at the destination. Strict compliance with DLA's Master List of Technical and Quality Requirements, DLA Packaging Requirements for Procurement, and MIL-STD-2073-1E, MIL-STD-129, and MIL-STD-130N is mandated for technical specifications, packaging, marking, and identification. Packaging must use MIL-DTL-117, Type II, Class C, Style 1, with preservation method code 33 and a mandatory 180-month non-extendable shelf life. The use of Class I ozone-depleting chemicals is strictly prohibited, and any substitute chemicals require prior approval. The item involves technical data subject to export controls under ITAR or EAR, limiting access to contractors with approved U.S./Canada Joint Certification Program status, completed DOD export control training, and DLA authorization. CMMC Level 2 certification is required for third-party assessment organizations, and the contractor must comply with DFARS 252.204-7012 for safeguarding covered defense information and cyber incident reporting. Hazardous materials must be labeled per OSHA’s Hazard Communication Standard and accompanied by Safety Data Sheets, with updates required for any material changes. Invoicing must be processed through Wide Area WorkFlow, and payment is subject to DoDAAC routing. The evaluation will be based on a best-value trade-off approach, considering price and other factors, without adopting a Lowest Price Technically Acceptable methodology. All offerors must be registered as small businesses, provide UEI and CAGE codes, and submit responses exclusively via the DLA Internet Bid Board System using Standard Form 18.
Gasket, Packing, and Sealing Device Manufacturing

POSTED

about 13 hours ago

DEADLINE

in 15 days
View Details