Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance (NIST SP 800-171)

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract requires the implementation and documentation of all NIST SP 800-171 cybersecurity controls to ensure compliance with DFARS 252.204-7012, specifically focusing on the development of a comprehensive System Security Plan and a Plan of Action and Milestones document. These deliverables must detail the organization’s approach to protecting controlled unclassified information within its systems, outlining current security postures, identified gaps, and remediation strategies with defined timelines. The work is scoped as a subcontract under the Defense Logistics Agency, Department of Defense, and is tied to the NAICS code 541512 for computer systems design services, indicating the need for technical expertise in cybersecurity architecture and documentation. Implementation must align precisely with federal cybersecurity standards, requiring thorough assessment of existing controls, gap analysis, and coordinated efforts across technical and administrative teams to achieve full compliance. Documentation must be accurate, up to date, and capable of withstanding audit scrutiny, with all measures designed to safeguard federal contract information. The contract does not specify a place of performance or point of contact, suggesting flexibility in execution location while maintaining strict adherence to DoD cybersecurity requirements. The solicitation was posted in 2026, indicating the timeline for performance is likely to begin shortly thereafter, with all deliverables due within a timeframe consistent with federal acquisition obligations.

General Info

Implement NIST SP 800-171 controls for DFARS compliance, develop SSP and POA&M for CUI protection.

Agency

Department Of Defense → Defense Logistics AgencyView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

Not specified

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → Defense Logistics Agency
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → Defense Logistics Agency
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Implementation and documentation of NIST SP 800-171 controls, including System Security Plan (SSP) and POA&M, per DFARS 252.204-7012.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
SLED
Azure Consulting IDIQThe Port of Seattle is seeking a qualified cloud services partner to provide consulting services focused on the adoption, modernization, and optimization of Microsoft Azure cloud and hybrid environments. The engagement aims to validate and enhance the existing Azure architecture, guide the implementation of new services, strengthen security posture, improve system resiliency, and ensure all cloud designs align with organizational standards, operational requirements, and long-term scalability goals. The contractor will work closely with the Port’s IT team to align cloud strategies with business objectives and support the transition to more efficient, secure, and future-ready infrastructure. This opportunity is structured as an Indefinite-Delivery/Indefinite-Quantity (IDIQ) contract under the NAICS code 541512 for other computer-related services. The contract is forecasted to be released with no formal solicitation number yet published, and the anticipated posting date is July 28, 2026. Performance will be centered at the Port of Seattle’s facilities, with primary points of contact being Carol Hassard and Jim Dawson, who will oversee procurement and project execution respectively. Potential vendors should be prepared to demonstrate expertise in Azure cloud platforms, hybrid environments, security frameworks, and enterprise-scale architecture design to meet the Port’s evolving technology needs.
ICT Enterprise Infrastructure Services

POSTED

about 3 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
SLED
FIDS Software ReplacementThe Port of Seattle through ICT Enterprise Infrastructure Services is forecasting a contract for the replacement of its existing Flight Information Display System software, aiming to modernize and enhance the system that provides real-time flight data to passengers and staff across airport terminals. The solicitation, posted on July 28, 2026, falls under NAICS code 541512 for Computer Systems Design Services and is intended to support critical airport operations with a reliable, scalable, and user-friendly digital solution. The project will involve developing and deploying new software tailored to the Port’s specific operational requirements, including integration with existing systems, compliance with aviation standards, and maintenance of continuous uptime during transition. Point of contact for the opportunity is Farlis Lewis, who can be reached via email or phone for general inquiries, with Krista Sadler serving as the project manager for technical and implementation coordination. Although no formal solicitation number has been assigned and the place of performance and set-aside details are not yet specified, all work is expected to support the Port’s infrastructure at its airport locations. Interested vendors should monitor the provided UI link for future updates, including formal RFP issuance, evaluation criteria, and submission deadlines, as this forecast signals upcoming procurement activity in the near term.
ICT Enterprise Infrastructure Services

POSTED

about 3 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
International
Application replacement for the end-of-life IFSMR (Integrated Fire Services Management & Reporting)This solicitation, numbered W2187-SPO-26-289-B, is issued to ICO Solutions and One Step Information Systems Inc. to replace the end-of-life IFSMR application with a modern, cloud-based or web-based fire services management and reporting system. The solution must deliver comprehensive functionality including incident reporting and tracking, inspections and prevention, training and exercises, asset and inventory management, workflow and communications, dashboards, reporting, and document and media handling. The contract is structured as a one-year base period with two optional one-year extensions and two additional irrevocable one-year option periods, all subject to performance and funding. Evaluation will prioritize technical merit at 70% and price at 30%, with submissions due by July 17, 2026. All solutions must be hosted entirely within Canada and fully compliant with Protected A information handling requirements, adhering to the SRCL, commercial cloud security standards, privacy mandates, and government IT security protocols. The successful vendor must maintain a valid Designated Organization Screening and Document Safeguarding Capability at the Protected A level. All personnel handling Protected information require at least a Reliability Status, while the Company Security Officer and anyone with privileged access—such as control over security settings, configurations, audit logs, or user accounts—must hold a Secret clearance. The supplier must undergo and submit a Cloud Service Provider IT Security assessment, support the departmental Security Assessment and Authorization process, and secure written approval before any Protected information is processed or stored. Security controls must include multi-factor authentication for privileged access, comprehensive activity logging, incident response, personal data protection, and robust continuity, monitoring, and recovery measures. Subcontractors involving security-sensitive work require prior written authorization from the Government of Canada.
Department of National Defence

POSTED

about 17 hours ago

DEADLINE

in 15 days
View Details
NAICS: 541512
New
International
Grants and Contributions (G&C) ProjectTransport Canada is seeking qualified vendors to design and develop future-state blueprints for improving the administration of grants and contributions, focusing on enhancing financial management, claim processing, incentive programs, data analytics, and business reporting. The project entails the creation of reusable, scalable components built on Microsoft technologies, including Power Platform (Power Apps, Power Automate, Power BI), .NET, and C#, to streamline processes and ensure interoperability across government programs. Work will be performed exclusively in the National Capital Region and is expected to span multiple phases concluding by March 2028, with a contract period of two years from award. Bidders must propose fixed all-inclusive per diem rates in Canadian dollars for specific resource categories including Application Architects, Programmer Analysts, Business System Analysts, and Testers, with estimated annual durations of 220 days per resource over two years. Payment is based on actual time worked, tracked via detailed timesheets and supported by Task Authorizations, and issued via direct deposit. All work must comply with stringent security requirements, including SECRET-level facility and personnel clearances from the Contract Security Program, adherence to safeguarding protocols for electronic media, and mandatory completion of a Non-Disclosure Agreement. Contractors must also maintain insurance, comply with the Federal Contractors Program for Employment Equity, and provide certifications for legal status, business identifier numbers, and resource qualifications. Proposals must be submitted electronically in three distinct sections—technical, financial, and attestations—with pricing restricted solely to the financial section. Evaluation is based on a weighted scoring system where technical merit accounts for 70% and price for 30%, with mandatory pass/fail gates including solicitation compliance, fulfillment of all mandatory criteria, a minimum technical score of 45 out of 60, and bid pricing within a designated median band of -20% to +30%. Deliverables include deployable solution packages, feasibility assessments, knowledge transfer materials, and regular status reports detailing milestones, resource hours, and outstanding actions, all subject to mutual agreement on format and schedule with the Technical Authority prior to initiation. Contractors are required to maintain comprehensive accounting records including tender calls, contracts, quotations, and machine-readable source documents to enable auditability of expenditures.
Department of Transport

POSTED

about 17 hours ago

DEADLINE

in 8 days
View Details

More opportunities from Department Of Defense → Defense Logistics Agency

Same awarding agency

NAICS: 333924
New
DIBBS
PLATE, SEALINGThe contract centers on the procurement of a sealing plate identified by NSN 4610015895272, with a single unit required under each of two CLINs totaling two units. Delivery is mandated within 20 days of award, with FOB destination terms, no acceptance or inspection at origin, and strict zero variance allowed in quantity. Packaging must comply with MIL-STD-2073-1E, including specific preservation, wrapping, and unit container standards, while marking follows MIL-STD-129 without special codes. Palletization adheres to DLA’s packaging requirements, and shipment must avoid parcel post, using instead the fastest traceable means to the specified FPO addresses for USS OAK HILL LSD 51 and USS PEARL HARBOR LSD 52. Mercury or mercury-containing compounds are strictly prohibited unless part of an exempted functional component such as batteries, fluorescent lamps, sensors, or weapon systems, with any exempted mercury devices requiring shockproof design and secondary containment per NAVSEA 5100-003D. All technical and quality requirements referenced by R or I numbers are governed by the DLA Master List, with applicable revisions controlled by the solicitation or award date depending on acquisition size. The contract is issued under SPE8E8-26-T-4877, with a required delivery date of July 23, 2026, and commercial vendor actions must utilize the DLA VSM system for logistics coordination.
Industrial Truck, Tractor, Trailer, and Stacker Machinery Manufacturing

POSTED

about 5 hours ago

DEADLINE

in 13 days
View Details
NAICS: 339999
New
DIBBS
CROSS ASSEMBLY, TESTThis contract, under solicitation SPE8E6-26-T-3895, requires the cross assembly and testing of three units identified by NSN 6920-01-044-5083, with delivery due within five days of award. The work is governed by comprehensive technical and quality standards referenced from the DLA Master List of Technical and Quality Requirements, which must be accessed online and applied in accordance with the acquisition type and timing of solicitation amendments. The contract includes strict compliance with DLA packaging requirements and mandates adherence to configuration change management procedures through formal Engineering Change Proposals. Any deviation or waiver requests must be formally submitted and approved prior to implementation. The item involves export-controlled technical data subject to ITAR or EAR regulations, prohibiting unauthorized disclosure to foreign persons regardless of location and requiring strict compliance with DFARS 252.225-7048. Only contractors with approved US/Canada Joint Certification Program status, completed DOD export control training, and authorized access through the DLA questionnaire are permitted to handle such data. Cybersecurity requirements include CMMC Level 2 certification by a certified third-party assessment organization. The performance location is identified as Albany, Georgia, with a response deadline of August 10, 2026, and all inquiries should be directed to the primary point of contact at the provided DLA email and phone number.
All Other Miscellaneous Manufacturing

POSTED

about 5 hours ago

DEADLINE

in 13 days
View Details