FEDERAL CYBER BRIEF

Issue #9 — August 11, 2026

Cleared to Bid

212 notices screened · 34 biddable · 15 worth your week.

Act 1 — What you can win this week

This week's signal

The window to tell the Department of War what CMMC actually cost your firm closes at noon Eastern on Friday. Five of the seven questions it asks are about money and administrative burden, which is the part a twenty-person shop can answer better than any trade association. Full analysis below.

Top 3 opportunities

1. Navy (NAVSUP) — Naval Information Warfighting Development Center Electronic Warfare Data IDIQ

Combined Synopsis/Solicitation · Response due August 25, 2026 · Total Small Business Set-Aside · NAICS 541511

An indefinite-delivery vehicle for electronic warfare data work at the Navy's information warfighting development center. Set aside entirely for small business, open for quote now, and structured as a multi-year ordering relationship rather than a single delivery.

Bid/No-Bid: BID — an IDIQ set aside at this level is the closest thing to a durable revenue base a small firm gets. Fourteen days is tight for an IDIQ response, so start today if EW or signals data is your domain.

View on SAM.gov →

2. State Dept (INL) — Guatemala Automated Biometric Identification System

Solicitation · Response due August 24, 2026 · 8(a) Set-Aside · NAICS 518210

A biometric identification system for the Bureau of International Narcotics and Law Enforcement Affairs, deployed in Guatemala. Identity infrastructure with an overseas deployment component, restricted to 8(a) firms.

Bid/No-Bid: BID — the 8(a) restriction plus the overseas requirement narrows this to a handful of credible bidders. If you hold 8(a) status and have deployed identity systems abroad, this is the least crowded item in the issue.

View on SAM.gov →

3. VA (Technology Acquisition Center) — WILMAC Call Recording Extraction Service

Sources Sought · Response due September 3, 2026 · Total Small Business Set-Aside · NAICS 541519

A new requirement, still at market research, for extracting call recording data from a legacy WILMAC system. Twenty-three days is the longest shaping window in this issue, and the requirement is explicitly labeled new rather than a follow-on.

Bid/No-Bid: WATCH — a new requirement with a small-business set-aside already attached at the sources-sought stage is unusually favorable. Answer it to influence what the solicitation asks for.

View on SAM.gov →

The other 12

The three above, in depth. The other twelve, at a glance.

Small Business Set-Aside

1. Navy (NAVSEA) — AV Equipment Upgrade for Split Conference Rooms

Combined Synopsis/Solicitation · Due 08/19/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: BID — defined rooms, defined equipment, eight days. Quotable this week by any AV integrator with a Navy facility clearance.

2. Army (AMC) — BPAs for Security, Access Control and Building Management

Solicitation · Due 08/20/2026 · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — blanket purchase agreements, plural. Winning a BPA slot is worth more than the first call order suggests.

3. NOAA — Senior C++ Programmer to Modify the COMPASS Model

Solicitation · Due 08/20/2026 · NAICS 541511 · View on SAM.gov →

Bid/No-Bid: BID — a single named skill set against a specific scientific model. This is a one-developer requirement, which makes it winnable by a firm too small to bid anything else in this issue.

4. Army (National Guard Bureau) — 250 IS Storage Area Network (SAN)

Combined Synopsis/Solicitation · Due 08/21/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: BID — storage hardware plus integration for an intelligence squadron. Straightforward for resellers who can handle the clearance side.

5. Air Force (50 CONS) — Central Plant Computer System (CPCS) Maintenance

Solicitation · Due 08/24/2026 · NAICS 541512 · View on SAM.gov →

Bid/No-Bid: BID — building control systems at a space operations base. Operational technology work, which stays one of the least crowded corners of federal IT.

6. NOAA — Security System, NMS American Samoa

Combined Synopsis/Solicitation · Due 08/26/2026 · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — remote-site security installation in the South Pacific. Travel and logistics thin the field considerably.

7. Labor Dept — Video Security Camera Repairs and Maintenance

Combined Synopsis/Solicitation · Due 08/26/2026 · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — recurring maintenance against an installed base, fifteen days to price it. Unremarkable work that builds a civilian past-performance record.

8. Army (Ohio National Guard) — Building 2 Security Upgrades

Combined Synopsis/Solicitation · Due 08/31/2026 · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — twenty days, a single building, a defined upgrade scope. The most comfortable clock on any set-aside here.

9. Interior (Bureau of Indian Affairs) — Cloud-Based Adult Education SaaS Platform

Combined Synopsis/Solicitation · Due 09/03/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: BID — reposted from an earlier cycle under a new notice with a longer clock. If you looked at this in July and ran out of time, it is open again.

Full & Open

10. Defense Health Agency — PEO DHMS Enterprise Software Services (ESS) Next

Solicitation · Due 08/20/2026 · NAICS 541513 · View on SAM.gov →

Bid/No-Bid: PASS — we tracked this at the RFI stage in July; it is now a live solicitation with no set-aside. A prime will carry the enterprise software backbone of the military health system. Read it to find the team you want to be on.

11. Treasury (OCC) — Palo Alto Unit 42 Public Sector Expertise on Demand Subscription

Combined Synopsis/Solicitation · Due 08/21/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: PASS — an incident response retainer tied to one vendor's named service. Only an authorized Palo Alto partner can quote it, and the field is effectively pre-selected. Worth reading as a signal that OCC is buying retained IR capacity.

12. Air Force (AFMC) — Virtual Imagery Processing Capability (VIP-C) III Support and Sustainment IDIQ (RFI)

Sources Sought · Due 09/08/2026 · NAICS 541511 · View on SAM.gov →

Bid/No-Bid: WATCH — twenty-eight days, the longest window in this issue. The "III" tells you there were two before it, which means an incumbent and a documented history to read before you respond.

Closing before the next brief

These missed the fifteen on runway alone. Every one closes before Issue #10.

⚠️ VA — Intrusion Detection System Services

Due 08/17/2026 (6 days) · SDVOSB Set-Aside · NAICS 561621 · View on SAM.gov →

An SDVOSB set-aside on detection services. If you qualify, this is a one-week decision.

⚠️ DoD — Data, Analytics, and AI Modernization Services

Due 08/18/2026 (7 days) · Total Small Business Set-Aside · NAICS 541511 · View on SAM.gov →

Broad modernization scope with a small-business restriction. Seven days is enough for a capability statement, not for a full proposal.

⚠️ HHS — Network Operations and Support Center (NOSC)

Due 08/17/2026 (6 days) · No set-aside · NAICS 541519 · View on SAM.gov →

Network operations centre support at HHS. No set-aside, so treat it as a teaming call rather than a solo bid.

Recompete pipeline

Contracts in our seven codes with every option exhausted, which means the work has to be re-competed rather than extended. Sorted by how long you have.

DISA — Defensive Cyber Operations Program Management Support

Incumbent: Octo Metric LLC · Set-aside (current): Total Small Business · Ceiling $55,549,718 · Obligated $46,252,652 · Est. completion: 01/13/2027 · 155 days out

The largest small-business cyber vehicle expiring in our codes this cycle. At five months out, a serious pursuit needs a teaming decision this month.

DISA — ID6 Analytics CrowdStrike Threat Feed

Incumbent: Norseman Inc · Set-aside (current): Total Small Business · Ceiling $8,644,923 · Obligated $8,644,923 · Est. completion: 01/27/2027 · 169 days out

Fully obligated against its ceiling, which usually means the requirement is stable and will return. A reseller relationship with the threat-feed vendor is the entry condition.

DISA — DCMA Cybersecurity Support Services

Incumbent: Crest Security Assurance LLC · Set-aside (current): 8(a) Competed · Ceiling $18,518,376 · Obligated $16,008,948 · Est. completion: 02/07/2027 · 180 days out

An 8(a) cybersecurity services contract at Defense Contract Management Agency. Six months is genuine capture runway if you start now.

NOAA — FISMA and ISSO Support Services

Incumbent: Alpha Omega Integration LLC · Set-aside (current): 8(a) Competed · Ceiling $10,379,386 · Obligated $10,379,386 · Est. completion: 03/18/2027 · 219 days out

Compliance and information system security officer support on the civilian side. Fully obligated, seven months out, and squarely sized for a small firm.

Interior — ICAM Support Services

Incumbent: Business Performance Systems LLC · Set-aside (current): Total Small Business · Ceiling $3,076,344 · Obligated $3,076,344 · Est. completion: 04/14/2027 · 246 days out

Identity, credential and access management at departmental level. The smallest ceiling on this list and the most accessible entry point.

Washington Headquarters Services — Counterintelligence, Law Enforcement and Security Policy Support

Incumbent: Arlo Solutions LLC · Set-aside (current): 8(a) Competed · Ceiling $24,492,411 · Obligated $20,778,351 · Est. completion: 04/28/2027 · 260 days out

Eight months of runway on an 8(a) vehicle in the Pentagon's own administrative arm. The longest lead time we are tracking.

Derived from federal contract records as of August 10, 2026. Confirm live status before acting; end dates move.

Who won last week

Flagged in Issue #2 — now awarded.

Island Automation PC (Swansboro, NC) won the Marine Corps VTSCADA with Support Plus requirement at $147,717.60. Total Small Business Set-Aside, awarded August 4.

We listed it in the free section on June 23 with a June 26 deadline. A North Carolina firm most people have never heard of took an operational technology contract at a Marine Corps installation for under $150,000.

View the award on SAM.gov →

Flagged in Issue #4 — now awarded.

GigXR, Inc. won VA's "GigXR Software or Equal" solicitation at $60,000. Total Small Business Set-Aside, awarded August 8.

Worth sitting with: the brand named in the title won its own "or equal" competition. "Or equal" opens the door legally. It does not mean the door is easy to walk through.

View the award on SAM.gov →

Other awards posted in our codes this week. Figures are as published: on ordering vehicles they are ceilings, not money committed.

DELVIOM LLC (Ashburn, VA) — Justice Dept

$31,831,730 · Information Technology Cyber Security Support Services · Total Small Business Set-Aside · NAICS 541519

MOBOMO, LLC (Damascus, MD) — Selective Service System

$4,523,423 · Website modernization · Total Small Business Set-Aside · NAICS 541519

Alvarez LLC (Leesburg, VA) — Dept of Veterans Affairs

$3,876,078 · Vocera communication solution · SDVOSB Set-Aside · NAICS 541519

Oracle America, Inc. — Dept of Homeland Security

$567,909,108 · Department-wide cloud (Cumulus) · no set-aside · NAICS 518210

Two notes on the data. The Alvarez award was posted twice under separate notice identifiers with an identical contract number and amount; it is one contract, not two. And DHS posted a counter-drone requirement carrying a $1,500,000,000 figure with the awardee listed only as "Multiple" — a ceiling across an unnamed pool of vendors, which is why we have left it out of the list above rather than pretend it tells you something.

Reply with your primary NAICS and set-aside status. I'll flag what fits you next week.

Act 2 — What changed in the market

Compliance flash

The Federal Railroad Administration published a justification this week for a sole-source bridge action on its cybersecurity and privacy program support services. A bridge means the follow-on competition did not finish in time, so the agency extended the incumbent without competing the work. What this means for you: a bridge notice is a timing signal worth acting on. It tells you a recompete slipped, that the requirement is still live, and roughly when the real competition should land. If you are tracking an expiring contract in your lane, set an alert for bridge justifications on it — they are the cheapest early warning available, and they are public.

Agency intelligence

  • Two contracts we listed have now been awarded. Both went to small businesses, and both are detailed below. This is the first time our own pipeline has closed the loop from listing to award, which is the only real test of whether the selection is worth anything.
  • Volume steady, runway short. 212 notices screened and 34 clearing all gates, against 214 and 39 last week. Three weeks under the tightened deadline gate put the working ratio at roughly one notice in six. The harder constraint this week was time: only eight of the thirty-four had more than fourteen days on the clock, and almost every small-business set-aside sat at eight to thirteen days.
  • Five requirements came back under new notice numbers. Fiber optic replacement at an air mobility base, a cell phone repeater swap, water management programming, VA MyPath software support, and the Bureau of Indian Affairs education platform were all listed in earlier issues and have been reposted with later deadlines. Reposting is common enough that a missed deadline is often not final.

The pattern across three weeks is consistent: this market posts small-business work with short fuses. A firm that checks SAM.gov weekly will keep missing things a firm that checks daily catches.

Act 3 — Analysis

Deep dive — Three days left to tell the Pentagon what CMMC cost you

At noon Eastern on Friday, August 14, the Department of War stops accepting responses to its Request for Information on reforming CMMC. After that, the Reform Task Force writes its recommendations with whatever it has. If the small end of the defense industrial base is under-represented in that pile, the program that replaces Phase 2 will be designed around the firms that did write in.

Why this window exists at all

On July 13 the Department suspended CMMC Phase 2, the milestone that would have made third-party certification a condition of award starting November 10. Alongside the suspension it created a Reform Task Force and opened this RFI. The Task Force reports to the Department CIO roughly sixty days after the suspension, which puts its recommendations in mid-September.

The Small Business Administration's Office of Advocacy has been pushing contractors toward it, and held its own roundtable on July 30 to gather small-business input. Advocacy's framing is direct: the information will be used to reduce compliance and cost burdens on small, medium and non-traditional companies. That is an unusually explicit invitation.

What the RFI actually asks

Seven questions. Five of them are about cost, administrative burden, or what should replace the third-party assessment model. The Department also asks about using existing commercial cybersecurity capabilities, optimising self-attestation, and where existing regulatory requirements overlap without adding operational security.

That last one matters more than it looks. The RFI acknowledges duplication between regimes, and the two obvious candidates are the proposed FAR CUI rule and CISA's incident reporting requirements. If you are currently reporting the same incident three ways to three authorities, that is a documented answer to a question they asked.

What actually carries weight

Dollar figures, hours, and named controls. Not adjectives. The Department asked the defense industrial base to price its own compliance, and a subcontractor who can write "we spent 340 hours and $84,000 reaching a passing score, of which $31,000 went to a single control family" has said something no association letter can.

Three things worth putting in writing if they are true for you. What your NIST SP 800-171 implementation cost, separated into consulting, tooling, and internal labour. Which specific controls produced measurable risk reduction and which produced paperwork. And what a workable alternative to a C3PAO assessment would look like at your size, given that self-assessment versus third-party assessment is precisely the axis the Task Force is reconsidering.

How to file

By email. There is no portal, no registration, and no fee. Responses go to the Department's designated mailboxes, and the RFI's own formatting instructions must be followed. Noon Eastern, Friday. A response written this evening still counts the same as one written a month ago.

What has not changed while you write

This is the part contractors keep getting wrong, and it is worth repeating precisely because the suspension was reported as relief. Phase 1 self-assessment is fully in effect. DFARS 252.204-7012 still applies. NIST SP 800-171 Revision 2 compliance is still the standard. Your SPRS score and your annual affirmation are still required, still submitted, and still legally binding.

With no external assessor in the loop, your self-attestation now carries the full legal weight on its own. The Justice Department's Civil Cyber-Fraud Initiative did not pause on July 13. A firm that treats the suspension as permission to let its score drift has increased its exposure, not reduced it.

Write the RFI response. Keep the compliance work running. Those are not in tension, and the firms that do both will be the ones still bidding when the replacement program lands.

FAQ

When is the CMMC RFI deadline?
Noon Eastern Time on Friday, August 14, 2026. Responses are submitted by email to the Department of War's designated mailboxes. There is no registration portal and no fee.

Does the CMMC Phase 2 suspension mean I can stop my compliance work?
No. Phase 1 self-assessment, DFARS 252.204-7012, NIST SP 800-171 Revision 2, SPRS score postings and annual affirmations all remain in full effect. Only the third-party certification tier is suspended pending review.

What does the Department of War actually want to know?
Seven questions, five of which concern compliance cost, administrative burden, and what should replace third-party assessment. Specific dollar figures, hours spent and named controls carry far more weight than general objections.

Is my False Claims Act exposure lower now that assessments are paused?
Arguably higher. Without an external assessor, your self-attestation stands alone as the representation the government relies on, and the Civil Cyber-Fraud Initiative remains active.

When will we know what replaces CMMC Phase 2?
The Reform Task Force reports to the Department CIO around mid-September 2026. Any genuine change would then need to arrive as a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170. The current suspension is a memorandum, which can be reversed as quickly as it was issued.

Sources

Know a small firm drowning in SAM.gov? Forward this brief.
federalcyberbrief.com

Federal Cyber Brief is an independent publication providing general information for educational purposes. It is not legal, financial, or procurement advice. Verify all opportunities and deadlines directly on SAM.gov before acting.