Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance for CUI Protection

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract requires full implementation and ongoing maintenance of NIST Special Publication 800-171 security controls to safeguard Controlled Unclassified Information critical to contract performance. This effort is focused on ensuring compliance with federal cybersecurity standards for protecting sensitive but unclassified data throughout the lifecycle of work performed under the agreement. The scope encompasses not only the initial deployment of required technical, administrative, and physical safeguards but also continuous monitoring, documentation, and adaptation to maintain adherence as threats and regulations evolve. This is a small business set-aside subcontract under the SBA Total Small Business Set-Aside program, with NAICS code 541512 covering computer systems design services. It is issued by the Maritime Supply Chain office within the Department of Defense and carries a submission deadline of July 28, 2026. The work must be performed in support of defense-related operations, and performance locations remain unspecified, though the obligation to comply with NIST 800-171 applies wherever CUI is processed, stored, or transmitted. Compliance is mandatory and non-negotiable, with failure to implement and maintain controls potentially resulting in contract termination or other enforcement actions.

General Info

Small business subcontract to implement and maintain NIST 800-171 controls for CUI protection in defense operations.

Agency

Department Of Defense → MARITIME SUPPLY CHAINView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

US

Set-Aside

SBA

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → MARITIME SUPPLY CHAIN
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → MARITIME SUPPLY CHAIN
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Implementation and maintenance of NIST SP 800-171 security controls to protect Controlled Unclassified Information (CUI) related to contract performance.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
SLED
Azure Consulting IDIQThe Port of Seattle is preparing to engage a qualified cloud services partner through an Indefinite Delivery/Indefinite Quantity (IDIQ) contract to support the modernization and optimization of its Microsoft Azure and Hybrid cloud environment. The contractor will be tasked with validating and enhancing the existing Azure architecture, guiding the implementation of new services, and strengthening the organization’s security posture, system resiliency, and operational efficiency. Work will focus on ensuring all cloud designs and deployments align with the Port’s enterprise standards, operational demands, and long-term scalability goals, with an emphasis on best practices in cloud governance and architecture. The contract is classified under NAICS code 541512 for Computer Systems Design Services and is managed by the ICT Enterprise Infrastructure Services division under the Port of Seattle. Primary point of contact is Carol Hassard, with Jim Dawson serving as the Project Manager; inquiries can be directed via their provided email addresses and phone numbers. The solicitation is forecasted for release in July 2026, with no set-aside designation specified, and will be executed under a single contract vehicle to allow for flexible, task-order-based engagements as needs arise. The place of performance and administrative details are not yet defined, but work is expected to primarily support the Port’s internal infrastructure and cloud initiatives.
ICT Enterprise Infrastructure Services

POSTED

about 3 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
SLED
FIDS Software ReplacementThe Port of Seattle is forecasted to procure a new software solution for its Flight Information Display System, aiming to replace legacy systems with modern, reliable technology that enhances passenger information delivery at airport terminals. The solicitation, posted on July 24, 2026, falls under NAICS code 541512, indicating it is for custom computer programming services, and is managed by ICT Enterprise Infrastructure Services. The project will require a vendor to deliver a fully functional, scalable, and secure software platform capable of integrating with existing airport systems while supporting real-time flight updates, multilingual displays, accessibility features, and high availability under heavy operational loads. Performance is expected to occur at the Port of Seattle’s facilities, though specific location details are not provided. Primary point of contact for inquiries is Farlis Lewis, reachable via phone or email, with Krista Sadler listed as the Project Manager for operational coordination. While the contract has not yet been solicited and no set-aside provisions are indicated, interested vendors should prepare proposals that demonstrate technical expertise in aviation display systems, experience with airport infrastructure, and adherence to industry standards for reliability and uptime. The official solicitation details and submission instructions can be accessed through the provided UI link, and responses should be tailored to meet the Port’s operational requirements for seamless integration, minimal downtime during transition, and long-term support capabilities.
ICT Enterprise Infrastructure Services

POSTED

about 3 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance & Incident ReportingThis contract requires the implementation of NIST Special Publication 800-171 cybersecurity controls to protect covered defense information on nonfederal systems, ensuring alignment with federal standards for safeguarding sensitive data. The contractor must establish and maintain a comprehensive cybersecurity framework that meets all applicable requirements under NIST SP 800-171, including access control, audit and accountability, configuration management, and incident response measures. Compliance must be demonstrated through documented policies, procedures, and technical safeguards validated to the standards outlined in the publication. In addition to implementing the controls, the contractor is obligated to report any cyber incidents involving covered defense information within 72 hours of discovery, providing full detail of the nature, scope, and impact of the incident to the appropriate government entities. The contract is structured as a small business set-aside under SBA guidelines, specifically reserved for total small businesses, and falls under the NAICS code 541512 for computer systems design services. The solicitation is issued by the Department of Defense’s Strategic Acquisition Program Directorate, with a response deadline of July 28, 2026, and is intended for subcontracting purposes under a broader defense acquisition effort.
STRATEGIC ACQ PROGRAM DIRECTORATE

POSTED

about 16 hours ago

DEADLINE

in 4 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity and NIST SP 800-171 Compliance SupportThe contract requires full compliance with DFARS 252.204-7012 and NIST SP 800-171 to ensure the proper safeguarding of controlled unclassified information across all systems and processes involved in the performance of work. This obligation extends to implementing the full spectrum of security controls outlined in NIST SP 800-171, including access control, audit, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, system and communications protection, and system and information integrity. The subcontractor must demonstrate a formal, documented cybersecurity program aligned with these standards and be prepared to validate compliance through assessments or audits as required by the Department of Defense. The effort is classified as a subcontract under the NAICS code 541512 for computer systems design services and is managed by the Strategic Acquisition Program Directorate within the Department of Defense. The solicitation was posted on July 23, 2026, with a strict response deadline of July 28, 2026, indicating a limited window for qualified vendors to submit proposals. Performance location details are not specified, but the work likely involves supporting DoD systems handling CUI, requiring secure, controlled environments and potentially remote or onsite support. Compliance is non-negotiable and forms the core requirement for award and continued contract execution, with failure to meet these standards resulting in immediate disqualification or contract termination.
STRATEGIC ACQ PROGRAM DIRECTORATE

POSTED

about 16 hours ago

DEADLINE

in 4 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance (NIST SP 800-171)The contract requires the implementation and documentation of NIST SP 800-171 security controls to safeguard Controlled Unclassified Information (CUI) on contractor systems. This effort is critical to ensuring compliance with federal cybersecurity standards for handling sensitive but unclassified data, and all required controls must be fully activated, tested, and formally recorded to demonstrate adherence. The subcontract is under the Department of Defense, specifically managed by PUGET SOUND, with performance taking place in BREMERTON, WA, at the zip code 98314-6001. The solicitation is categorized under NAICS code 541512, which corresponds to Computer Systems Design and Related Services, indicating the technical nature of the work involved. Responses are due by July 28, 2026, and the opportunity was posted on July 23, 2026, providing a limited window for interested parties to submit proposals. The work is part of a broader initiative to enforce cybersecurity hygiene across the defense industrial base, and successful execution demands thorough understanding of NIST SP 800-171 requirements, including risk assessments, access controls, audit and accountability measures, system and communications protection, and continuous monitoring. Documentation must be precise and auditable, as non-compliance could jeopardize the contractor’s ability to handle CUI and may lead to termination or penalties. All activities must align with the Department of Defense’s expectations for protecting sensitive information on non-federal systems.
PUGET SOUND

POSTED

about 16 hours ago

DEADLINE

in 4 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance & NIST SP 800-171 ImplementationThe contract requires the implementation and ongoing maintenance of NIST SP 800-171 cybersecurity controls to safeguard controlled unclassified information within manufacturing and supply chain systems operated by the Department of Defense. This subcontract aims to ensure that all relevant technical, administrative, and physical security measures are properly configured and continuously monitored to meet federal standards for protecting sensitive data handled in operational environments. The work is tied to a NAICS code of 541512, indicating a focus on computer systems design and related services, with performance expected to align with DoD-specific requirements for securing information across industrial and logistical networks. The solicitation was posted on July 23, 2026, with a response deadline set for August 24, 2026, giving potential contractors approximately one month to submit proposals. The contract is managed under the ASC SUPPLIER OPER AE AND AF DIV, a division within the Department of Defense, and although no specific location is provided for performance, the nature of the work implies that compliance activities will be executed at facilities connected to the defense supply chain. The contractor must deliver a robust, auditable cybersecurity posture capable of withstanding inspection and maintaining continuous adherence to NIST 800-171 controls throughout the life of the agreement.
ASC SUPPLIER OPER AE AND AF DIV

POSTED

about 16 hours ago

DEADLINE

in about 1 month
View Details

More opportunities from Department Of Defense → MARITIME SUPPLY CHAIN

Same awarding agency

NAICS: 335312
New
DIBBS
MOTOR, ALTERNATING CThe contract is for the procurement of two alternating current motors with NSN/Part Number 6105-01-313-2546 under solicitation SPE7M1-26-T-207C, with a required delivery within 152 days after order. The solicitation was posted on July 23, 2026, and responses are due by July 28, 2026, with the purchasing organization being the Department of Defense through the Maritime Supply Chain. The contract incorporates all technical and quality requirements listed in the DLA Master List of Technical and Quality Requirements, identified by R or I numbers, with the applicable revision determined based on the solicitation or award date depending on acquisition size. Configuration change management requires formal engineering change proposals or variance requests for any deviations. Mercury or mercury-containing compounds are strictly prohibited from intentional addition or direct contact with supplied hardware, except for specific functional applications such as batteries, fluorescent lights, instruments, sensors, controls, weapon systems, or chemical reagents specified by NAVSEA; portable devices containing mercury must include shockproof construction and a secondary containment barrier per NAVSEA 5100-003D. The alternate offeror must submit a complete data package including technical documentation for both the approved and alternative part, as no data is currently provided. The place of performance is New Cumberland, Pennsylvania, 17070-5002, and the primary point of contact is Michael Reese, reachable via email and phone.
Motor and Generator Manufacturing

POSTED

about 16 hours ago

DEADLINE

in 4 days
View Details
NAICS: 333991
New
DIBBS
RING, CASING USThe contract specifies the procurement of a RING, CASING US, identified by NSN 4320-00-008-7313, for use on Ingersoll-Rand Model 14HM equipment. One unit is required to be delivered FOB origin within 168 days, with no tolerance for quantity variance. The item is classified as a critical application item and must comply with stringent technical and quality standards referenced from the DLA Master List of Technical and Quality Requirements, which are incorporated by reference. Packaging must adhere to MIL-STD-2073-1E and MIL-STD-129, with specific preservation methods and marking codes outlined, and palletization must follow DLA packaging requirements. Mercury or mercury-containing compounds are strictly prohibited in the product, its preservation, packaging, and markings, with limited exceptions only for approved functional uses such as batteries or instrumentation as defined by NAVSEA, and any such items must include a secondary containment boundary. Delivery is directed to the Defense Logistics Agency Distribution San Joaquin warehouse in Tracy, California, with transportation details governed by DLAD procedural notes C19 and C20. The solicitation number is SPE7M1-26-T-223J, issued on July 23, 2026, with proposals due by August 3, 2026, and the required ship date is January 19, 2027, while the original delivery deadline is March 23, 2027. Inspection and acceptance occur at the destination. The unit of issue is each (EA), and the purchase request number is 7017604673. The contract mandates compliance with DoD authorized units of issue as defined by official DLA documentation, and all specifications for material, packaging, and handling are binding with no flexibility for noncompliance. The point of contact for inquiries is Michael Reese, with email and phone details provided for official correspondence.
Power-Driven Handtool Manufacturing

POSTED

about 16 hours ago

DEADLINE

in 10 days
View Details