FEDERAL CYBER BRIEF

Issue #11 — August 25, 2026

Cleared to Bid

263 notices screened · 47 biddable · 15 worth your week.

Act 1 — What you can win this week

This week's signal

Every cybersecurity contract in this issue with a named incumbent and a real dollar figure is a recompete, not a new posting. The new work in our codes this week was cameras, card readers and alarm panels. The security work with budgets already attached is sitting in contracts that expire between February and August next year, and six of them are below.

Top 3 opportunities

1. Energy (National Energy Technology Laboratory) — ServiceNow Security Operations (SecOps) Implementation

Combined Synopsis/Solicitation · Response due September 3, 2026 · Total Small Business Set-Aside · NAICS 541519

This is the third time this requirement has been posted. We flagged it on August 4 when it closed on the 11th, and again on August 18 when it came back with a two-day fuse. It is now a fresh notice with nine days on the clock, which is the first version of it a small firm could realistically respond to.

Bid/No-Bid: BID — a security operations platform build at a national laboratory, restricted to small business. Three postings in three weeks says the lab has not found what it wants yet, and that is the condition under which a specialist gets read carefully.

View on SAM.gov →

2. FAA — NISC Enterprise Support Tasking (NEST)

Solicitation · Response due October 15, 2026 · WOSB Set-Aside · NAICS 541511

Enterprise support tasking under the FAA's NISC programme, restricted to SBA-certified women-owned small business under FAR 19.15. Fifty-one days of runway, which is the longest clock we have listed in eleven issues.

Bid/No-Bid: BID — if you hold the WOSB certification, this is the single most valuable item in the issue. Seven weeks is enough time to build a teaming arrangement rather than scramble one, and the competitive field is narrow by construction.

View on SAM.gov →

3. Army (ACC-APG) — Total Engineering and Integration Services (TEIS) IV On-Ramp

Combined Synopsis/Solicitation · Response due October 7, 2026 · Small Business Set-Aside, Partial · NAICS 541512

An on-ramp opportunity onto an existing Army engineering and integration vehicle. On-ramps are how a firm without the original award gets onto a multi-year contract vehicle, and they open rarely.

Bid/No-Bid: BID — forty-three days, and the prize is not one task order but access to every task order the vehicle issues for the rest of its life. Weigh this against a single solicitation with a larger face value and the on-ramp usually wins.

View on SAM.gov →

The other 12

The three above, in depth. The other twelve, at a glance.

Small Business Set-Aside

1. DHS (CBP, Air and Marine) — LGDS Unified Sensor Surveillance Processor Software

Presolicitation · Due 09/03/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: WATCH — still pre-solicitation, which is the stage where scope is movable. Sensor processing software for border surveillance, set aside for small business. Nine days to register interest, not to write a proposal.

2. Interior (Bureau of Reclamation, Grand Coulee) — SWISP Phase I SCADA Programming

Presolicitation · Due 09/08/2026 · NAICS 541511 · View on SAM.gov →

Bid/No-Bid: BID — SCADA programming at a hydroelectric facility. This is operational technology rather than enterprise IT, and the firms that can do it credibly are a short list. Reclamation past performance is the differentiator.

3. USSOCOM (MARSOC) — CCTV Installation and Maintenance

Combined Synopsis/Solicitation · Due 09/10/2026 · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — sixteen days, a special operations customer, and both installation and sustainment in one scope. Clearance requirements will thin the field more than technical capability will.

4. USTDA — Europe and Eurasia Digital Infrastructure Project Scoping Services

Combined Synopsis/Solicitation · Due 09/11/2026 · NAICS 541690 · View on SAM.gov →

Bid/No-Bid: BID — seventeen days on a consulting scope rather than a delivery one. USTDA posted four separate scoping requirements this week, so a firm that fits one likely fits several. See the note in Agency intelligence.

5. USTDA — South and Southeast Asia Aviation Infrastructure Project Scoping Mission

Combined Synopsis/Solicitation · Due 09/17/2026 · NAICS 541690 · View on SAM.gov →

Bid/No-Bid: BID — twenty-three days, aviation infrastructure scoping. The longest clock of the USTDA group, and the one to prioritise if you can only resource a single response.

Indian Small Business Economic Enterprise

6. Interior (Bureau of Indian Affairs) — Cisco Secure Firewall Management

Solicitation · Due 09/03/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: BID — one of only two network security requirements in the fifteen. ISBEE is a narrower restriction than the set-asides most readers hold, so check eligibility before you spend time on it. If you qualify, the competitive field here is very small.

Full & Open

7. VA (Technology Acquisition Center) — Light Electronic Action Framework (LEAF) Recompete

Sources Sought · Due 09/08/2026 · NAICS 541512 · View on SAM.gov →

Bid/No-Bid: WATCH — the word "recompete" is in the notice title, which is rare and worth acting on. Answer the sources sought and ask who holds it now. A strong small-business response at this stage is how a full-and-open requirement becomes a set-aside.

8. Government Publishing Office — Hosting Service (FDLP eXchange / FDP.gov)

Solicitation · Due 09/10/2026 · NAICS 518210 · View on SAM.gov →

Bid/No-Bid: BID — application hosting for two public-facing federal systems. No set-aside, but GPO is a small buying office and the scope is sized for a small hosting provider rather than a hyperscaler.

9. FDIC — Copado Software Subscription Renewal

Solicitation · Due 09/14/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: WATCH — a named-product renewal, which usually means the reseller relationship decides it rather than the proposal. Worth twenty minutes if you already carry Copado; skip it if you do not.

10. Army Corps of Engineers (Huntsville) — Utility Monitoring and Control Systems VI

Combined Synopsis/Solicitation · Due 09/17/2026 · NAICS 541512 · View on SAM.gov →

Bid/No-Bid: PASS — the sixth iteration of a control systems vehicle, which means five cycles of incumbent history. Track it as a subcontracting target and read the cybersecurity requirements, because control system security language written here propagates into task orders you can reach.

11. Energy (Environmental Management) — EM Mission IT Support Services

Sources Sought · Due 09/18/2026 · NAICS 518210 · View on SAM.gov →

Bid/No-Bid: WATCH — mission IT support across the Environmental Management complex, at market research stage with twenty-four days. Capability statements filed now shape whether this comes out restricted or open.

12. Defense Logistics Agency — RFI: Content Authoring Tools

Sources Sought · Due 09/30/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: WATCH — thirty-six days, the longest runway in the twelve, and an RFI costs you an afternoon. DLA market research is worth answering even when the eventual award looks out of reach, because it puts your name in the file.

Closing before the next brief

These missed the fifteen on runway alone. Every one closes before Issue #12.

⚠️ HHS (Indian Health Service) — Magnet Forensics Axiom Cyber Software Subscription & Support

Due 08/31/2026 (6 days) · Indian Small Business Economic Enterprise · NAICS 541519 · View on SAM.gov →

Digital forensics tooling on a restricted set-aside. The most clearly cyber requirement to appear in our codes this week, and it closes before we speak again.

⚠️ GSA (Federal Acquisition Service) — CISA Strategic Cyber Tools Buying

Due 09/01/2026 (7 days) · Full & open · NAICS 541519 · View on SAM.gov →

We made this our top item last week. It has since been reposted under a different notice identifier with the same deadline, so if you searched for the old link and found nothing, this is why. Still open, still worth an afternoon.

⚠️ DHS (Science and Technology) — Service Maintenance Agreement for Access Control, CCTV and Intrusion Detection Systems

Due 08/27/2026 (2 days) · Total Small Business Set-Aside · NAICS 561621 · View on SAM.gov →

Three systems under one maintenance agreement at a New York site. Two days is a quote against a known installed base, not a proposal.

Recompete pipeline

Contracts in our seven codes with every option exhausted, which means the work has to be re-competed rather than extended. Every entry this week is cybersecurity. Sorted by how long you have.

DoD (DISA) — DCMA Cybersecurity Support Services

Incumbent: Crest Security Assurance LLC · Set-aside (current): 8(a) competed · Ceiling $18,518,376 · Obligated $16,008,948 · Est. completion: 02/07/2027 · 166 days out

Cybersecurity support to the Defense Contract Management Agency, 86 percent obligated against ceiling. The shortest clock on this list and the largest defence customer on it. An 8(a) firm with DoD cyber past performance should be opening a capture file this week, not next quarter.

Commerce (NOAA) — FISMA and ISSO Support Services

Incumbent: Alpha Omega Integration LLC · Set-aside (current): 8(a) competed · Ceiling $10,379,386 · Obligated $10,379,386 · Est. completion: 03/18/2027 · 205 days out

Information system security officer support and FISMA compliance work. Fully obligated against its ceiling, which usually signals a stable requirement that comes back rather than one that gets cancelled. This is compliance labour, so the differentiator is cleared staff you can name, not tooling.

DOT (FAA) — AIS Governance Support Services

Incumbent: Cyber Security Solutions LLC · Set-aside (current): 8(a) competed · Ceiling $19,135,941 · Obligated $9,930,588 · Est. completion: 04/30/2027 · 248 days out

Information security governance at the FAA. The largest ceiling on this list and roughly half obligated, which means either the requirement shrank or the option years carry the balance. Worth understanding which before you price against it.

GSA (Office of Administrative Services) — FICAM Subject Matter Expert Support Services

Incumbent: Electrosoft Services, LLC · Set-aside (current): Total Small Business · Ceiling $11,542,240 · Obligated $11,542,240 · Est. completion: 06/13/2027 · 292 days out

Federal identity, credential and access management advisory work, fully obligated. A Total Small Business set-aside rather than an 8(a) restriction, which makes it the most widely accessible entry on this list. Identity is also the one cyber discipline where a five-person specialist beats a large integrator on credibility.

Pension Benefit Guaranty Corporation — Information Security Services

Incumbent: Valiant Solutions, LLC · Set-aside (current): Total Small Business · Ceiling $12,225,274 · Obligated $12,225,274 · Est. completion: 07/31/2027 · 340 days out

A full information security services scope at a small independent agency, fully obligated. Small agencies buy one security contract rather than five, so this is the whole programme. Eleven months is enough runway to build a relationship with the programme office before the solicitation drops.

Commerce (USPTO) — Cybersecurity Architecture and Engineering Contract Services

Incumbent: Zermount, Inc. · Set-aside (current): SDVOSB · Ceiling $11,812,694 · Obligated $11,812,694 · Est. completion: 08/07/2027 · 347 days out

Security architecture and engineering at the Patent and Trademark Office, fully obligated, on an SDVOSB restriction. The longest runway here and the most technical scope. If you hold SDVOSB and do architecture work rather than compliance paperwork, this is the one to watch on this list.

Derived from federal contract records retrieved August 10, 2026. Confirm live status before acting; end dates move.

Who won last week

Awards posted in our seven codes during the coverage window. On ordering vehicles the published figure is a ceiling, not money committed — see our note on reading award numbers. Nothing we listed in an earlier issue appeared in this week's awards.

Oracle Health Government Services, Inc. (Kansas City, MO) — Dept. of Veterans Affairs

$16,941,387,684 · VA electronic health record modernisation IDIQ, expanded scope modification P00008 · no set-aside · NAICS 541512

Peraton Inc. (Herndon, VA) — Dept. of Defense

$953,000,000 · Capacity Services Communications III · no set-aside · NAICS 541519

ThunderCat Technology, LLC (Reston, VA) — Dept. of Veterans Affairs

$8,608,674 · Patient Engagement and Mobile Application extension · SDVOSB Set-Aside · NAICS 541519

V3Gate, LLC (Colorado Springs, CO) — Dept. of Veterans Affairs

$6,191,709 · MongoDB enterprise licence agreement · SDVOSB Set-Aside · NAICS 541519

VCH Partners LLC (Columbia, MD) — Dept. of Agriculture

$9,991,370 · Assurance Network integration into the Public Health Information System · no set-aside · NAICS 541512

Two numbers on this list deserve a second look. The Oracle Health figure is a modification to an existing indefinite-delivery vehicle, not a new award, and the amount is the ceiling of the whole vehicle as modified. And Peraton's Capacity Services Communications III appears at $953,000,000 here, against $279,958,606 in a notice we reported two weeks ago for the same programme. Neither figure is wrong. They describe different things, which is the entire reason we keep saying not to read the headline number as money committed.

Reply with your primary NAICS and set-aside status. I'll flag what fits you next week.

Act 2 — What changed in the market

Compliance flash

SBA published a proposed rule on August 20 that would rewrite how small business size standards are calculated, and it reaches five of the seven NAICS codes this brief screens. The rule collapses roughly 995 size standards into 338, set at four-digit and five-digit NAICS levels instead of six-digit, and removes all eighteen federal contracting exceptions. It also removes the current ceilings entirely: today no revenue-based standard exceeds $47 million and no employee-based standard exceeds 1,500 employees, and under the proposal there is no maximum at all.

What this means for you: SBA's own figures put the net effect at 114,541 additional firms qualifying as small, of which 37,002 already hold federal contracts worth roughly $71 billion in FY2025. In Other Computer Related Services (541519), 2,247 firms that are not small today would become small. In Custom Computer Programming (541511) it is 2,171, in Computer Systems Design (541512) it is 1,663, in Computing Infrastructure and Data Processing (518210) it is 1,105, and in Other Scientific and Technical Consulting (541690) it is 719. Those firms would compete inside the same set-asides you compete in now. SBA states plainly in the rule that growing small businesses nearest the current threshold will face the greatest new competition. Comments close September 21, 2026 under docket SBA-2026-0199. We covered the mechanics and what a comment should actually say in a proposed rule would cut size standards from nearly 1,000 to 338.

Agency intelligence

263 notices screened, 47 clearing all six gates. Five weeks under the tightened deadline gate now read 199/35, 214/39, 212/34, 258/49 and 263/47, which puts the working ratio at close to one notice in five and holds steady.

The cyber pattern inverted this week, and it is the finding worth keeping. Exactly two of the fifteen are network security in the strict sense, and the closing block adds one more. That is three, which meets the recalibrated floor for the first time. But the recompete pipeline told a different story: filtering our seven codes for contracts with every option exhausted produced a pool where genuine cybersecurity work was abundant enough that all six entries this week are security contracts with named incumbents. The security money in this market is already committed. It is not in the new postings, it is in contracts that end between February and August 2027.

One data caution, and it is new. Three requirements we listed in Issue #10 reappeared this week under entirely different notice identifiers with the same scope: the CISA strategic cyber tools market research, the Air Force Building 179 access control replacement, and the CDC VAERS application rebuild. Our continuity check compares notice IDs, and by that test none of them registered as repeats. We caught them by title. If you keep your own watch list keyed on notice ID, it will silently miss reposts. Key it on the solicitation number or the title instead.

Act 3 — Analysis

Deep dive — Your prime is flowing down CMMC Level 2, and you may never touch CUI

Comments filed to the CMMC Reform Task Force became public this month, and one complaint runs through nearly all of them. It is not the cost of the controls. It is that nobody can reliably say which information the controls are supposed to protect.

The Small Business Administration's Office of Advocacy called controlled unclassified information the most frequently cited concern small businesses raised about CMMC. Its explanation of the mechanism is worth understanding precisely, because it describes something that is probably happening to you. When a contractor cannot determine with confidence what counts as CUI, the rational move is to treat everything as CUI and pull all of it inside the compliance boundary. Advocacy reported that small firms described CUI being overmarked, marked inconsistently, and pushed down the supply chain improperly. It also noted cases where the Department treated publicly available information as CUI.

Where the cost actually lands

The Alliance for Digital Innovation described the downstream effect in the sharpest terms of any commenter. Prime contractors, it told the task force, impose blanket Level 2 flow-downs on every subcontractor, including firms producing commercially available products that never handle CUI at all. The reason is not malice. Primes lack confidence in their own scoping determinations, so they default to over-inclusion to avoid audit liability. The cost of that caution does not stay with the prime. It lands on the subcontractor who now has to build and pay for a certified environment around information that was never CUI in the first place.

This is the part that matters for a small firm reading a flow-down clause. The obligation you are being handed may be larger than the rule requires, and the person who handed it to you may not know that. Kate Growley of Crowell & Moring made the underlying point compactly: CMMC follows the data, so if CUI is scoped too broadly, CMMC scope follows it. She also noted that acquisition rules direct prime contractors to consult their contracting officer when they are unsure about CUI scope — which means there is a defined path for resolving the question that does not depend on you absorbing the cost.

The problem is documented, not alleged

The National Defense Industrial Association told the task force its members had identified multiple instances where inconsistency, ambiguity and inaccuracy in CUI marking produced confusion, higher costs, and worse security for everyone involved. The Professional Services Council reported significant variation in how individual contracting officers decide whether to impose certification requirements at all. Notably, PSC did not conclude that the requirements should be weakened; its position was that execution should improve rather than the standard being postponed.

None of this is new. A Department of Defense Inspector General report earlier this year found continuing failures to mark CUI properly, years after the same finding was first made. The governmentwide CUI programme dates to 2010, and the National Archives registry now lists more than a hundred categories of it, from defence technical information to archaeological records. The breadth is a large part of why consistent application has not happened.

A complication that catches small firms specifically

Michael Lowell of Reed Smith raised a scenario that is easy to miss. A contractor can create CUI on the government's behalf during performance, particularly on sensitive technical work. So a firm may receive little or no marked CUI from the customer and still generate information during the contract that qualifies. If the contract does not say what is expected to be CUI, the contractor ends up making judgement calls about its own engineering data, technical reports and drawings, without a rule to check them against.

If you are a subcontractor, this is the harder version of the problem. The prime can at least ask the contracting officer. You are two steps removed from the person who knows.

What to do about it before the reform lands

Ask the question in writing, and ask it specifically. Not "does this contract involve CUI" but which CUI categories the customer expects to be involved, how that information will be transmitted to you, and which deliverables are expected to contain it. Lowell's framing is the useful one: when the CUI boundary is unclear, contractors protect more information, systems and people than necessary, and the cost rises without a matching security benefit. A written answer narrows your assessment scope, and an unanswered question in the file is itself evidence that you scoped in good faith.

Know which trigger you are actually under. The distinction between federal contract information and controlled unclassified information decides whether you owe fifteen basic safeguards or a hundred and ten controls, and a blanket flow-down does not change which one your contract actually involves. If you have not confirmed which applies, that is the first thing to establish, before you price anything.

Read the clause rather than the email. A flow-down instruction in a message from a programme manager is not the same as a clause in your subcontract. DFARS 252.204-7012 and the CMMC clause impose defined obligations, and what binds you is what is written into the agreement you signed.

Do not wait for the outcome. The reform task force is expected to deliver recommendations to the Department CIO in mid-September, and the instruments available to it include a class deviation, a DFARS rule change, or an amendment to the CMMC programme rule itself. Any of those takes time to arrive. Meanwhile Phase 1 obligations, SPRS scoring and False Claims Act exposure all remain exactly where they were. The scoping conversation is worth having now, because it reduces cost under the current rules regardless of what replaces them.

One honest caveat about the reform itself. Several commenters expect the forthcoming governmentwide CUI acquisition rule to resolve part of this by forcing the conversation about what the customer intends to send you. That is a reasonable expectation, not a certainty, and it does not help you on a contract you are pricing this quarter.

FAQ

My prime says I need CMMC Level 2. Can I refuse?

Refusing is not the useful move. Asking is. Request the CUI categories the prime expects to flow to you and how. If the answer is that no CUI will reach your systems, that is the basis for a conversation about whether Level 2 is the correct requirement for your subcontract. The prime can raise the scoping question with its contracting officer, and acquisition rules point it in that direction when it is unsure.

Did the CMMC Phase 2 suspension remove my obligations?

No. It suspended the third-party certification milestone. Phase 1 self-assessment, DFARS 252.204-7012, SPRS score submission and annual affirmations all remain in force, and anything already written into a contract you hold still binds you regardless of what any memorandum says.

Should I comment on the SBA size standards rule?

If you hold a small business set-aside in 541511, 541512, 541519, 518210 or 541690, the proposal changes who competes against you. Comments close September 21 under docket SBA-2026-0199. Firm-specific cost and competitive data is the kind of comment that gets used; general objection is not.

Why are all six recompetes this week cybersecurity?

Because that is what the filter returned, not because we selected for it. Contracts with all options exhausted in our seven codes happened to be dominated by security work this cycle. It is a useful signal about where committed security budget actually sits, but it is one week of data and we would not build a strategy on it alone.

Sources

SBA, Small Business Size Standards, proposed rule, 91 FR 53741, August 20, 2026 (RIN 3245-AI67, docket SBA-2026-0199)
SBA, Small Business Size Standards: Revised Size Standards Methodology, 91 FR 54096, August 20, 2026 (docket SBA-2026-0265)
Federal News Network, "CMMC review: DoD's inconsistent CUI marking continues to plague program," August 19, 2026
Federal News Network, "SBA wants to give 114,000 more companies access to small business contracts," August 20, 2026
SBA Office of Advocacy, comment letter to the CMMC Reform Task Force, August 14, 2026
Alliance for Digital Innovation, National Defense Industrial Association and Professional Services Council, comments to the CMMC Reform Task Force, August 2026
NARA CUI Registry, category list
SAM.gov contract opportunities API, NAICS 541511, 541512, 541513, 541519, 518210, 561621 and 541690, posted August 18–24, 2026
USAspending.gov prime award summaries, retrieved August 10, 2026

Federal Cyber Brief · Cleared to Bid · Weekly intelligence for federal IT and cybersecurity contractors.