Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance for Subcontractors

Active
State & Local

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

Subcontractors accessing SCDOT systems are required to implement one of three recognized cybersecurity frameworks—NIST CSF, SOC 2, or ISO 27001—to ensure consistent and robust security postures across the supply chain. The solicitation, posted on August 11, 2026, with an identical response deadline, applies to all entities performing work under SCDOT contracts and mandates full compliance with the selected framework as a condition of participation. The effort is classified under NAICS code 541512, indicating it targets computer systems design and related services, and the place of performance is specified as Clarendon, South Carolina. This requirement is designed to mitigate cyber risks associated with third-party access to state systems and aligns with broader state and federal expectations for vendor cybersecurity accountability. All qualifying subcontractors must demonstrate active implementation, not merely adoption, of one of the frameworks and maintain documented controls, policies, and monitoring practices consistent with the chosen standard.

General Info

Subcontractors must implement NIST CSF, SOC 2, or ISO 27001 to access SCDOT systems in Clarendon, SC.

Agency

South Carolina → SCDOTView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

Clarendon, SC, US

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencySouth Carolina → SCDOT
ContactsNo contacts available
OfficeN/A
Organization / Agency
South Carolina → SCDOT
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Implementation of NIST CSF, SOC 2, or ISO 27001 cybersecurity frameworks for subcontractors accessing SCDOT systems.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
SLED
FIDS Software ReplacementThe Port of Seattle through its ICT Enterprise Infrastructure Services is forecasting the replacement of its existing Flight Information Display System software to modernize airport operations and enhance passenger experience. This initiative targets the development and deployment of new software that will replace legacy systems, ensuring real-time flight data accuracy, improved reliability, and seamless integration with current airport infrastructure. The project falls under NAICS code 541512, indicating it involves custom computer programming services tailored to the specific operational needs of the airport environment, with the primary place of performance located at the Port of Seattle facilities. The primary point of contact for this opportunity is Farlis Lewis, reachable via email and phone, with Krista Sadler serving as the project manager for technical oversight. The solicitation is classified as a forecast, meaning no formal request for proposals has been issued yet, but interested vendors should prepare for an upcoming procurement process. The agency has not specified a set-aside type, suggesting the opportunity is open to all eligible contractors without preferential sizing or socioeconomic considerations. Although the exact timeline and requirements remain undeclared, stakeholders are encouraged to monitor the official portal link for future updates and formal solicitations.
ICT Enterprise Infrastructure Services

POSTED

1 day ago

DEADLINE

N/A
View Details
NAICS: 541512
New
DIBBS
Cybersecurity and Covered Defense Information (CDI) SafeguardingThe contract requires the implementation and maintenance of cybersecurity controls to safeguard Covered Defense Information in accordance with NIST SP 800-171 and DFARS 252.204-7012, ensuring that all systems handling sensitive defense data meet federal standards for protection. This subcontract is aimed at securing information systems against unauthorized access, disclosure, or compromise, with specific focus on technical, administrative, and physical safeguards defined by the referenced frameworks. Compliance is mandatory and must be demonstrated throughout the performance period, with continuous monitoring and documentation of control effectiveness as a core expectation. The work is to be performed at the APO location with zip code 09094-3219, under the oversight of the Department of Defense through the Medical Supply Chain Pharm FSA. The solicitation was posted on July 29, 2026, with responses due by August 4, 2026, indicating a tight turnaround for proposers to demonstrate capability and readiness. The NAICS code 541512 identifies the work as related to computer systems design services, suggesting the need for specialized technical expertise in cybersecurity architecture and integration. All parties must be prepared to meet rigorous compliance standards, maintain audit-ready records, and ensure ongoing adherence to federal cybersecurity requirements without exception.
MEDICAL SUPPLY CHAIN PHARM FSA

POSTED

1 day ago

DEADLINE

in 5 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance (CMMC/NIST) ImplementationThe contract requires support for achieving Cybersecurity Maturity Model Certification (CMMC) Level 2 compliance by implementing all necessary NIST Special Publication 800-171 controls to safeguard covered defense information in accordance with Defense Federal Acquisition Regulation Supplement (DFARS) requirements. The work involves conducting a self-assessment to identify gaps in current cybersecurity practices and executing a remediation plan to meet the specified control objectives, ensuring the contractor can authentically demonstrate compliance with federal standards for handling sensitive government data. This effort is part of a broader initiative to secure the defense supply chain against cyber threats and maintain eligibility for future DoD contract work. This is a subcontract under a HUBZone Set-Aside, designated for businesses located in and controlled from historically underutilized business zones, with the North American Industry Classification System code 541512 indicating information technology consulting services. The solicitation was posted on July 29, 2026, with a response deadline of August 12, 2026, and is managed by the ASC Commodities Division within the Department of Defense. Performance is expected to occur at an unspecified location, and the contract is accessible via the DIBBS portal for interested HUBZone-qualified subcontractors seeking to support defense cybersecurity compliance initiatives.
ASC COMMODITIES DIVISION

POSTED

1 day ago

DEADLINE

in 13 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance for Contractor Information SystemsThis contract requires the implementation of NIST Special Publication 800-171 controls to safeguard Covered Defense Information on contractor information systems, ensuring alignment with federal cybersecurity standards for protecting sensitive defense data. The scope encompasses establishing, maintaining, and validating a robust cybersecurity posture that meets all regulatory requirements for data protection, access control, audit logging, and system integrity, while also fulfilling mandatory cyber incident reporting obligations as stipulated by applicable Department of Defense directives. The subcontract is issued by the Defense Logistics Agency under the Department of Defense and falls under NAICS code 541512, indicating it pertains to computer systems design services with a focus on cybersecurity compliance. The solicitation is open for responses until August 10, 2026, and the performance location is not specified, implying work may be performed at the contractor’s secure facility or wherever the system hosting Covered Defense Information resides. As a subcontract, the awardee must ensure full alignment with prime contract cybersecurity obligations and may be subject to verification, assessment, or audit by the government or its representatives. Compliance is non-negotiable, and failure to implement the required controls or report incidents timely may result in contract termination, financial penalties, or loss of eligibility for future defense work. The target audience includes contractors with experience in defense information systems, NIST controls implementation, and incident response protocols.
Defense Logistics Agency

POSTED

1 day ago

DEADLINE

in 11 days
View Details