Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance – NIST SP 800-171 and CMMC Level 2

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract requires the implementation and documentation of all NIST SP 800-171 security controls to safeguard Controlled Unclassified Information (CUI) within contractor systems, ensuring alignment with federal cybersecurity standards. The work includes conducting a comprehensive self-assessment to achieve CMMC Level 2 certification, which involves verifying the proper application of access controls, identification and authentication, audit and accountability, system and communications protection, and other required safeguards. Documentation must be thorough and verifiable to support the self-assessment and demonstrate compliance across all 110 controls outlined in the NIST framework. This subcontract is a total small business set-aside under SBA guidelines, restricted to qualifying small businesses, and falls under NAICS code 541511 for computer systems design services. The performance location is Hill AFB, Utah, with a zip code of 84056-5734. The solicitation was posted on July 30, 2026, and responses are due by August 7, 2026. The contracting activity is under the Department of Defense’s ASC Commodities Division, and the work must be executed in accordance with all applicable federal acquisition regulations. Subcontractors must be prepared to provide full transparency of their cybersecurity posture, including policies, procedures, and evidence of control implementation, to meet CMMC Level 2 requirements without external audit.

General Info

Implement NIST SP 800-171 controls for CUI, achieve CMMC Level 2 at Hill AFB, small business set-aside.

Agency

Department Of Defense → ASC COMMODITIES DIVISIONView Agency

NAICS

541511 - Custom Computer Programming ServicesView NAICS

Place of Performance

HILL AFB, UT, 84056-5734, US

Set-Aside

SBA

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → ASC COMMODITIES DIVISION
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → ASC COMMODITIES DIVISION
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Implement and document NIST SP 800-171 controls and complete CMMC Level 2 self-assessment for protection of Controlled Unclassified Information (CUI) in contractor systems.

Similar Contracts

Same NAICS industry code

NAICS: 541511
New
SLED
Workforce Management Solution
Solicitation # RIP-10-2027
Multnomah County Library is seeking a cloud-based workforce management solution to automate the scheduling of diverse employee groups including student workers and volunteers across its 19 branch locations in Portland and Multnomah County, Oregon. The solution must integrate seamlessly with existing enterprise systems—Workday for HR and payroll data, and Frontline AESOP for substitute management—through secure APIs or SFTP, enforcing real-time synchronization of employee availability, certifications, and time-tracking. The system must support granular task-level assignments in 30- to 60-minute increments, dynamically generate schedules based on skill matrices and seniority rules, ensure compliance with Collective Bargaining Unit agreements including limits on consecutive hours and weekend rotations, detect coverage gaps, and automatically report hours back to Workday. Security and accessibility are non-negotiable: the platform must meet SOC 2 Type II, employ AES-256 encryption and TLS, support SSO and MFA, comply with WCAG 2.0, and restrict access via role-based permissions. Proposals will be evaluated on a best-value, trade-off basis with 75% weight on technical capability—including scheduling accuracy, ease of use, training and reporting functionality, and system independence—and 25% on responsible business practices such as economic and environmental impact. The solicitation, issued as a Request for Intermediate Proposals (RIP-10-2027) under a $250,000 spending threshold, prohibits LPTA selection and requires bidders to certify compliance with organizational conflict of interest rules, debarment status, and Oregon residency laws. Offerors must maintain substantial insurance coverage—$1M in professional and general liability, $5M in cyber liability, and workers’ compensation as required—and undergo a pre-award risk assessment covering financial stability, federal fund management experience, and audit history. All submissions must be made electronically via the Multco Marketplace Supplier Portal by September 2, 2026, including supporting documentation such as a demo script and IT security spreadsheet, with no hard copies accepted. The contract term will be negotiated post-award, with no guaranteed minimum purchases, and the primary point of contact is Maura Platt at Multnomah County Library.
Multnomah County

POSTED

3 days ago

DEADLINE

in about 1 month
View Details
NAICS: 541511
New
Federal
Cybersecurity for Contractor Information SystemsThe contract requires the implementation and ongoing maintenance of cybersecurity controls for contractor-operated information systems that handle sensitive but unclassified information at Brookhaven National Laboratory in Upton, New York, under the Department of Energy. The work is scoped to ensure compliance with federal cybersecurity standards and to protect data integrity, confidentiality, and availability within systems managed by third-party contractors. Performance is expected to be conducted on-site at the Upton location with a zip code of 11973, and the contract is classified as a subcontract under NAICS code 541511, indicating it relates to custom computer programming services. The opportunity was posted on July 29, 2026, and responses are due by August 10, 2026, at 9:00 PM EDT. There is no set-aside designation specified, meaning the contract is open to all eligible contractors regardless of business size or category. The contracting entity is Brookhaven National Laboratory’s DOE contractor, and while no specific point of contact is provided, all submissions and inquiries must adhere to the official SAM.gov portal linked in the posting. The contractor must be prepared to support continuous monitoring, incident response, and system hardening to meet DOE and national cybersecurity requirements without revealing classification levels beyond sensitive but unclassified.
Brookhaven National Labor -Doe Contractor

POSTED

3 days ago

DEADLINE

in 10 days
View Details

More opportunities from Department Of Defense → ASC COMMODITIES DIVISION

Same awarding agency

NAICS: 332710
New
DIBBS
CLEVIS, ADJUSTABLE
Solicitation # SPE4A6-26-R-XC15
This contract, issued under solicitation SPE4A6-26-R-XC15 by the ASC Commodities Division of the Department of Defense, is a Total Small Business Set-Aside for the procurement of adjustable clevises with NSN 5342-01-166-0578, classified under NAICS code 332710. The contract operates as an indefinite-delivery, indefinite-quantity (IDIQ) mechanism with a five-year performance period and a total ceiling value of $350,000, requiring delivery within 80 days of order receipt. Performance is to be conducted at various CONUS stock locations under FOB Origin terms, with all items subject to strict compliance with MIL-STD-2073-1E for packaging and MIL-STD-129 for labeling, barcoding, and marking, including special notations for product verification test samples. The contract mandates use of Wide Area WorkFlow (WAWF) for all invoicing and receiving reports and includes detailed requirements for supply chain traceability, material buffer availability, and Vendor Shipment Module submissions. The contract incorporates a comprehensive set of FAR and DFARS clauses governing quality assurance, inspections, subcontracting, and compliance, with inspections occurring at both origin and destination under MIL-STD-1916, ASQ H1331, and MIL-STD-105 standards, demanding zero non-conformances unless otherwise specified. Subcontracting obligations require flowdown of key clauses, including those addressing commercial product sourcing and counterfeit electronic part avoidance, with specific requirements for subcontracts exceeding the simplified acquisition threshold. The contractor must comply with cybersecurity mandates such as NIST SP 800-171 under 252.204-7012, prohibited use of covered defense telecommunications equipment and foreign satellite services, and hazard communication labeling under OSHA guidelines. The contract prohibits unauthorized use of foreign-flag vessels and requires immediate notification if sea transportation is unexpectedly needed. Representations concerning small business status, labor practices, veteran and disability inclusion, trafficking in persons, and foreign sourcing (including Xinjiang and Russian-linked entities) are required and subject to SAM verification, with affirmative responses triggering additional reporting obligations. The award will be made through a best-value trade-off analysis heavily weighted toward past performance, particularly SPRS assessments, with cost considered as neither the sole nor primary factor. All submissions must be made electronically via DIBBS or email to
Machine Shops

POSTED

about 10 hours ago

DEADLINE

in 20 days
View Details