FEDERAL CYBER BRIEF

Issue #10 — August 18, 2026

Cleared to Bid

258 notices screened · 49 biddable · 15 worth your week.

Act 1 — What you can win this week

This week's signal

There is a belief in this market that costs small software firms more contracts than any regulation does, and it is not written in any rule. The Department of Veterans Affairs just told its own contracting officers to stop repeating it. Full analysis below.

Top 3 opportunities

1. GSA (Federal Acquisition Service) — CISA Strategic Cyber Tools Buying

Sources Sought · Response due September 1, 2026 · Full & open · NAICS 541519

Market research for a strategic approach to how CISA buys cyber tooling. When an agency consolidates tool purchasing, the vendors who shaped the requirement end up inside the resulting vehicle and everyone else buys their way in later.

Bid/No-Bid: WATCH — no set-aside and a strategic scope, so this is not a solo bid. It is the single most consequential cyber notice in our codes this week, and an RFI response costs you an afternoon.

View on SAM.gov →

2. State Dept — CODIS Phase III (Specialized Forensics IT Equipment)

Solicitation · Response due September 17, 2026 · Total Small Business Set-Aside · NAICS 541519

Specialized forensics IT equipment for the third phase of a combined DNA index system deployment. Thirty days of runway on an open solicitation with a small-business restriction, and the phase number tells you the customer already knows what worked in phases one and two.

Bid/No-Bid: BID — the longest clock on any set-aside in this issue. Forensics lab IT is narrow enough that a specialist beats a generalist on credibility.

View on SAM.gov →

3. HHS (CDC) — Modernized VAERS Reporting Application

Combined Synopsis/Solicitation · Response due September 4, 2026 · Total Small Business Set-Aside · NAICS 541511

Modernization of the reporting application behind the Vaccine Adverse Event Reporting System. A public-facing federal application rebuild, set aside for small business, open for quote now rather than sitting in market research.

Bid/No-Bid: BID — seventeen days and a scope a small development shop can hold end to end. Public-health data handling is the differentiator, not headcount.

View on SAM.gov →

The other 12

The three above, in depth. The other twelve, at a glance.

Small Business Set-Aside

1. USDA (Agricultural Research Service) — Enterprise Infrastructure and Critical Operations Support Services

Combined Synopsis/Solicitation · Due 08/26/2026 · NAICS 518210 · View on SAM.gov →

Bid/No-Bid: BID — enterprise infrastructure and operations support at a research agency. Eight days is short for a services bid, so only pursue it if you already hold USDA past performance.

2. Army (MICC Fort Leonard Wood) — CDID MSBL IT and Simulation Support, Base Plus Four Recompete

Sources Sought · Due 08/28/2026 · NAICS 541513 · View on SAM.gov →

Bid/No-Bid: WATCH — the word "recompete" is in the notice title, which is rare and useful. Five-year structure, small-business set-aside, still at market research. Answer it and ask who holds it now.

3. Air Force (Air Mobility Command) — Building 179 Access Control Replacement and Intrusion Detection Upgrade

Solicitation · Due 09/02/2026 · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — one building, two defined systems, fifteen days. Physical security integration, not network defense; price it accordingly.

4. Navy (NAVSEA) — AV Equipment Upgrade for Split Conference Rooms

Combined Synopsis/Solicitation · Due 09/04/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: BID — the same requirement type we listed for NAVSEA last week under a different notice, now with a longer clock. Seventeen days is comfortable for an AV integrator.

5. Army (AMC) — Lenel OnGuard Door Access Control System Upgrade, Amendment 0001

Combined Synopsis/Solicitation · Due 09/10/2026 · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — a named platform upgrade with twenty-three days on the clock. Lenel dealer authorization decides who is competitive here.

6. U.S. Trade & Development Agency — Regional Asia Energy and Critical Minerals Project Scoping Services

Combined Synopsis/Solicitation · Due 09/11/2026 · NAICS 541690 · View on SAM.gov →

Bid/No-Bid: BID — twenty-four days, small-business set-aside, and a consulting scope rather than a delivery one. USTDA posted a parallel requirement for digital infrastructure in the Middle East and North Africa the same day, so a firm that fits one may fit both.

8(a) · SDVOSB · WOSB · HUBZone

7. Air Force (Air Mobility Command) — EOS Web-Based Training

Combined Synopsis/Solicitation · Due 08/26/2026 · WOSB Set-Aside · NAICS 541511 · View on SAM.gov →

Bid/No-Bid: BID — a WOSB set-aside on training development. Eight days, but the deliverable is well defined and the competitive field is small by construction.

8. DHS (Federal Protective Service) — Electronic Security Systems Maintenance, Ronald Reagan Building

Solicitation · Due 09/01/2026 · WOSB Set-Aside · NAICS 561621 · View on SAM.gov →

Bid/No-Bid: BID — corrective and preventative maintenance against a known installed base in a landmark federal building. Two WOSB set-asides in one week is unusual; if you hold the certification, this is the better of the pair.

9. GSA (Federal Acquisition Service) — Collaborative Learning Environment Support

Presolicitation · Due 09/03/2026 · SDVOSB Set-Aside · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: WATCH — still pre-solicitation, which is the point where scope is movable. The only SDVOSB item in the fifteen this week.

Full & Open

10. DISA — JWCC UCM Core Draft Solicitation

Solicitation · Due 09/14/2026 · NAICS 518210 · View on SAM.gov →

Bid/No-Bid: PASS — the unified cloud management layer for the Joint Warfighting Cloud Capability. Hyperscaler territory. Read the draft for the security requirements language, because it will propagate into task orders you can reach.

11. Army Corps of Engineers — Electronic Security System VIII Draft Solicitation

Combined Synopsis/Solicitation · Due 09/16/2026 · NAICS 541512 · View on SAM.gov →

Bid/No-Bid: PASS — the eighth iteration of a construction-scale security systems vehicle, which means an incumbent with seven cycles of history. Track it as a subcontracting target.

12. Social Security Administration — Enterprise Artificial Intelligence Strategy

Solicitation · Due 09/28/2026 · NAICS 541519 · View on SAM.gov →

Bid/No-Bid: WATCH — forty-one days, the longest runway in this issue. A strategy engagement rather than a build, which is exactly the kind of work a small specialist firm can win against a large one.

Closing before the next brief

These missed the fifteen on runway alone. Every one closes before Issue #11.

⚠️ Dept. of Energy — ServiceNow Security Operations (SecOps) Implementation

Due 08/20/2026 (2 days) · Total Small Business Set-Aside · NAICS 541519 · View on SAM.gov →

We flagged this two weeks ago when it closed on the 11th. It came back with a new notice and a new date. If you missed it then, this is the second chance, and it is the strongest cyber item in the issue.

⚠️ DoD — CDTF Intrusion Detection System

Due 08/21/2026 (3 days) · SDVOSB Set-Aside · NAICS 561621 · View on SAM.gov →

An SDVOSB set-aside on detection system work. Three days is a quote, not a proposal.

⚠️ DoD — Data, Analytics, and AI Modernization Services

Due 08/25/2026 (7 days) · Total Small Business Set-Aside · NAICS 541511 · View on SAM.gov →

Also a repost from last week's closing block, now with seven days instead of seven. Broad modernization scope, small-business restriction.

Recompete pipeline

Contracts in our seven codes with every option exhausted, which means the work has to be re-competed rather than extended. Sorted by how long you have.

DOJ (FBI) — Company Threat Assessments

Incumbent: SanCorp Consulting, LLC · Set-aside (current): SDVOSB · Ceiling $8,125,285 · Obligated $4,371,935 · Est. completion: 03/13/2027 · 207 days out

Threat assessment services at the Bureau, roughly half obligated against ceiling. Seven months is real capture runway for an SDVOSB firm with cleared analysts.

Commerce (Office of the Secretary) — Modernized Physical Access Control and Security Systems Upgrade

Incumbent: Communications Resource Inc · Set-aside (current): Total Small Business · Ceiling $1,904,349 · Obligated $1,904,349 · Est. completion: 03/29/2027 · 223 days out

Fully obligated against its ceiling, which usually signals a stable requirement that returns. The smallest entry on this list and the most accessible.

DOJ (U.S. Marshals Service) — COTS Integrated Workplace Management System

Incumbent: ITC Federal, LLC · Set-aside (current): SDVOSB · Ceiling $8,803,264 · Obligated $7,032,885 · Est. completion: 03/29/2027 · 223 days out

Commercial off-the-shelf open-architecture software on an SDVOSB vehicle. If you implement IWMS platforms, the incumbent relationship is the thing to understand first.

VA — VISN 8 Biomedical Converged Virtualization Infrastructure

Incumbent: Redhawk IT Solutions, LLC · Set-aside (current): Total Small Business · Ceiling $7,148,747 · Obligated $7,148,747 · Est. completion: 03/29/2027 · 223 days out

Biomedical device virtualization hardware across a VA network, fully obligated. Healthcare IT integrators with VA past performance should be building a capture file now.

VA — Physical Access Control Systems Program Management

Incumbent: Trofholz Technologies, Inc. · Set-aside (current): SDVOSB · Ceiling $6,583,667 · Obligated $4,707,561 · Est. completion: 03/29/2027 · 223 days out

Program management rather than installation, which is the higher-margin end of physical security work and the harder one to displace an incumbent from.

DOT (Federal Highway Administration) — Invicti On-Premises Software Subscription and Resident Engineer

Incumbent: New Tech Solutions, Inc. · Set-aside (current): Total Small Business · Ceiling $3,413,328 · Obligated $3,321,944 · Est. completion: 04/16/2027 · 241 days out

Web application security scanning licences plus an embedded engineer. The longest runway here and the closest to a pure cyber requirement in this batch.

Derived from federal contract records retrieved August 10, 2026. Confirm live status before acting; end dates move.

Who won last week

Awards posted in our seven codes during the coverage window. On ordering vehicles the published figure is a ceiling, not money committed — see our note on reading award numbers. Nothing we listed in an earlier issue appeared in this week's awards.

Progressive Technology Federal Systems (Rockville, MD) — Dept. of Defense

$680,391 · Library services support · Total Small Business Set-Aside · NAICS 518210

Alvarez LLC (Leesburg, VA) — Dept. of Defense

$769,007 · V5000 Smartbadge and device licences · SDVOSB Set-Aside · NAICS 541519

Veterans Management Services, Inc. (Sterling, VA) — Dept. of Veterans Affairs

$4,999,942 · Acquisition and program support services · full & open · NAICS 541511

EM Key Solutions, Inc. (St. Petersburg, FL) — Dept. of Veterans Affairs

$5,695,771 · Healthcare Identity Management support · SDVOSB Set-Aside · NAICS 518210

Peraton Inc. (Herndon, VA) — Dept. of Defense

$279,958,606 · Capacity Services Communications III · no set-aside · NAICS 541519

The "III" is the useful part: this is the third cycle of a recurring vehicle, which puts the fourth on a predictable clock.

Reply with your primary NAICS and set-aside status. I'll flag what fits you next week.

Act 2 — What changed in the market

Compliance flash

The semiannual regulatory agenda published August 14 confirms that a FAR cybersecurity rulemaking has been closed outright. The reason given is that it was written to implement Office of Management and Budget direction that no longer exists: OMB memorandum M-26-05 of January 23, 2026 rescinded both M-22-18 and M-23-16, the memos that established secure software development attestations for federal software purchases. What this means for you: if you sell software to the government and have been budgeting for a self-attestation regime built on those memos, that specific rulemaking is dead. Do not read it as the end of software supply chain scrutiny. The replacement memo describes a risk-based approach, agencies remain free to impose requirements contractually, and anything already written into a contract you hold still binds you. Check your active awards for attestation clauses before you change anything internally.

Agency intelligence

  • The largest week we have processed, by a clear margin. 258 notices screened and 49 clearing all six gates, against 199, 214 and 212 in the three prior weeks. Four weeks under the tightened deadline gate now put the working ratio at roughly one notice in five. DoD accounted for 23 of the 49.
  • Physical security keeps crowding out network security. Access control replacements, CCTV maintenance, alarm systems and intrusion detection installations dominated the set-aside pool again. Exactly one notice in the fifteen is cybersecurity in the strict sense, and the genuine cyber work sat where it has sat for a month: in short-deadline notices, now in the closing block above.
  • Two requirements from earlier closing blocks came back. The Energy Department's ServiceNow security operations buy and a DoD data and AI modernization requirement both reappeared under fresh notices with later deadlines. A missed short-fuse deadline in this market is frequently not final, which is an argument for keeping a watch list rather than writing off anything you could not reach in time.

One caution on the data itself. Three requirements were posted twice this week under separate notice identifiers — the State Department forensics buy, an NIH datacentre relocation, and a VA clinical information system sustainment. In the NIH case the two copies carry different set-aside status, one restricted to small business and one not. Read the notice you intend to bid, not the one you found first.

Act 3 — Analysis

Deep dive — You do not need FedRAMP certification to bid

Ask a small software company why it does not sell to the federal government and the answer is often a single word. FedRAMP. The belief is that a cloud or SaaS product must already carry a completed authorization before anyone will look at it, that getting one costs hundreds of thousands of dollars, and that no agency will sponsor a company that has no federal customer yet. It is a closed loop, and firms talk themselves out of the market because of it.

The loop is not real. It has never been written into the FAR, and the Department of Veterans Affairs has now told its own workforce so in writing.

What VA actually said

In a memo signed by Zack Schwartz, principal deputy assistant secretary in VA's Office of Information and Technology, the department instructed that acquisition documents — including requests for information, proposals and quotations — should not state or imply that a cloud vendor must have already completed FedRAMP certification in order to compete for or win a VA contract. Cloud providers are instead expected to supply security and privacy documentation after award, so the agency can make an authorization determination for its own environment.

One caveat on sourcing, because it matters for how much weight to put on this. The memo has not been published publicly. It is known through reporting by FedScoop, which obtained it, and through subsequent analysis. Treat the substance as reliable and the exact wording as second-hand until VA posts it.

Why the myth took hold anyway

Nothing about this is a policy change, which is the part worth understanding. Federal News Network described the memo as mythbusting rather than new direction, and that framing is right. The requirement drifted into solicitations through habit rather than regulation, and once it appears in one agency's template it propagates into the next.

The cost of that drift falls in a predictable direction. A government official familiar with the memo put the mechanism plainly to Federal News Network: agencies that expect companies to spend millions on certification before being eligible for award end up selecting from a smaller pool, which leaves the agency itself in a tight spot. Some authorized products also run versions behind their commercial equivalents, so the agency loses capability in exchange for the paperwork.

Readiness is not certification, and the distinction is where you win

None of this means security documentation is optional. It means the sequence is different from what most firms assume. What an agency needs at award is confidence that you can move through its authorization process, not proof that you already have.

Practically, that means having a security assessment report you can hand over, architecture and data flow diagrams that match what you actually run, an asset inventory, recent vulnerability scans, and a clear account of which controls you have implemented and which you have not. A firm with no certification but mature, current documentation is more competitive under this model than a firm that assumes the question can be handled after the contract is signed.

The FedRAMP CR26 rewrite that took effect on July 1 changed the vocabulary here — authorizations became certifications, impact levels became classes — so make sure the labels in your documentation match the current scheme rather than the one you learned two years ago.

Where this does not apply

Be careful about generalising. VA's memo binds VA. Other agencies write their own solicitations, and some will keep asking for existing authorization until someone tells them otherwise. When a solicitation does state a pre-award certification requirement, that is a question for the contracting officer during the question period, not a reason to assume the whole market is closed.

The defense side is a separate matter entirely. If controlled unclassified information touches your system, DFARS 252.204-7012 requires cloud services that store or process it to meet a FedRAMP Moderate equivalent baseline, and that is a contractual obligation rather than a market-entry preference. The same applies to the NIST SP 800-171 control set underneath it.

What to do this week

If you have been filtering federal opportunities out of your pipeline on the assumption that certification is a prerequisite, reopen that filter. Read the actual solicitation language rather than the received wisdom. Where a notice is silent on the point, it is silent, and you are eligible.

Then close the documentation gap, because that is the real one. The firms that benefit from this are not the ones who now bid anything with a cloud component. They are the ones who can answer, on the day of award, exactly what their architecture looks like and where the gaps are.

FAQ

Do I need FedRAMP authorization before bidding on a federal contract?
Not as a general rule. No FAR provision requires existing FedRAMP certification as a condition of competing. VA has explicitly instructed its contracting officers not to state or imply otherwise in solicitations, requests for information, or requests for quotation.

What does an agency expect instead?
Documentation that supports its own authorization decision after award: a security assessment report, architecture and data flow diagrams, an asset inventory, vulnerability scan results, and a clear statement of implemented and unimplemented controls.

Does this apply to every agency?
No. The VA memo binds VA. Other agencies may still include pre-award certification language in solicitations. Where they do, raise it during the question period rather than treating it as settled.

Does this change anything for defense contracts involving CUI?
No. DFARS 252.204-7012 requires cloud services that store, process or transmit covered defense information to meet a FedRAMP Moderate equivalent baseline. That is a contract requirement and is unaffected by how agencies handle pre-award eligibility.

Is FedRAMP certification still worth pursuing?
For a firm with a federal customer base it remains valuable and eventually necessary for many cloud offerings. The point is sequencing: it is not the gate you must pass before you are allowed to compete.

Sources

Know a small firm drowning in SAM.gov? Forward this brief.
federalcyberbrief.com

Federal Cyber Brief is an independent publication providing general information for educational purposes. It is not legal, financial, or procurement advice. Verify all opportunities and deadlines directly on SAM.gov before acting.