Notice to Industry - Application of Cybersecurity Maturity Model Certification (CMMC) Requirements
Contract Overview
Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.
AI Contract Overview
NAVFAC Southwest is issuing an important notice to current and potential contractors regarding the implementation of the Cybersecurity Maturity Model Certification (CMMC) requirements applicable to all NAVFAC Southwest Planning, Design, and Construction Multiple Award Construction Contracts (MACCs) and Architect-Engineer IDIQ Contracts. Effective future contract actions will include CMMC requirements as guided by the Department of War's ongoing CMMC program rollout. Contracts and solicitations will specify when contractor information systems must handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), and will identify the required CMMC level. Contractors must have an up-to-date CMMC status recorded in the Supplier Performance Risk System (SPRS), including relevant assessments and affirmations, as a prerequisite for award of contracts, task orders, or options where CMMC applies. Beginning November 10, 2026, contractors seeking NAVFAC SW IDIQ awards must demonstrate at least a CMMC Level 2 certification validated by an accredited C3PAO. While some task orders might require a lower CMMC level, the majority of construction and architect-engineering work under NAVFAC SW contracts will necessitate this Level 2 certification or higher. To avoid disruptions in contract eligibility, contractors and subcontractors are urged to promptly access SPRS via PIEE, ensure their CMMC status is posted and accurate, and familiarize themselves with available resources and tutorials to support the certification process. This notice is informational and does not serve as a solicitation or guarantee of contract award. Points of contact are available for assistance.
General Info
Agency
NAICS
Place of Performance
San Diego, CA, USASet-Aside
Timeline
Organization & Contact Information
Full Description
Notice to Industry – Application of Cybersecurity Maturity Model Certification (CMMC) Requirements
NAVFAC SOUTHWEST (SW) provides this notice to Industry to inform current and prospective contractors about the CMMC Requirements under all NAVFAC SW Planning, Design and Construction (PDC) Multiple Award Construction Contracts (MACCs) and Architect-Engineer IDIQ Contracts.
Future contract actions shall include the CMMC requirements in accordance with Department of War (DoW) implementation of the CMMC program.
As DoW continues implementation of the CMMC program, solicitations and contracts shall identify when contractor information systems are expected to process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The applicable CMMC level will be identified in the solicitation and contract.
Offerors shall be required to have a current CMMC status recorded in the Supplier Performance Risk System (SPRS), including applicable assessment results and affirmations, as a condition of award for the contract, task order, and associated options where CMMC requirements apply.
In order to receive an IDIQ award from NAVFAC SW PDC, on or after November 10, 2026, prospective contractors must show that they have obtained a CMMC Level 2 (C3PAO) or higher. Task orders issued under NAVFAC SW IDIQs may be assigned a CMMC Level below Level 2 (C3PAO); however, for the majority of work under Construction and Architect-Engineering IDIQs, it is anticipated that a Level 2 (C3PAO) certification will be required after November 10, 2026.
Immediate Steps Required
We urge all contractors and subcontractors to take the following immediate steps to prevent any disruption to your contract eligibility:
- Access SPRS: Log in to the SPRS on PIEE, at https://piee.eb.mil/
- SPRS Vendor (Role) & Cyber Reports Access:
https://www.sprs.csd.disa.mil/pdf/SPRS_Access_CyberReports.pdf
- SPRS CMMC Level 2 Entry tutorial: https://www.sprs.csd.disa.mil/videos/Tutorials/CMMCL2SelfAssessment/CMMCLevel2selfassessmenttutorial.html
- How to upload CMMC Level Training offered on SPRS as an Affirming Official (AO) https://www.sprs.csd.disa.mil/cmmc.htm
- Verify Your Status: Confirm that your firm has a current CMMC status type properly posted in SPRS.
- Ensure Accuracy: Validate that the posted CMMC status type accurately reflects your current cybersecurity posture as it aligns with the CMMC level required by your existing or potential contracts.
This notice is for informational purposes only and does not constitute a solicitation, a request for proposal, nor a guarantee of award.
Similar Contracts
Same NAICS industry code
More opportunities from Department Of Defense → Department Of The Navy
Same awarding agency
