Act 1 — What you can win this week
This week's signal
GSA wants to write a contract clause governing every large language model that touches government data, and the comment window closes August 3. Whether your firm is inside or outside its scope depends on a definition most contractors have not read. Full analysis below.
Top 3 opportunities
1. Defense Microelectronics Activity — DMEA Enterprise Program Support
Combined Synopsis/Solicitation · Response due August 10, 2026 · Women-Owned Small Business · NAICS 541512
Enterprise program support for the office that runs DoD's trusted microelectronics work. A WOSB set-aside inside a defense program office is uncommon, and the requirement is open for quote now rather than sitting in market research.
Bid/No-Bid: BID — scope sits within reach of a small program-support shop, and the set-aside narrows the field before you start.
2. Selective Service System — Readiness Simulation (RS)
Solicitation · Response due August 14, 2026 · Total Small Business Set-Aside · NAICS 541512
A simulation and readiness modeling buy at a small independent agency. Seventeen days of runway on an open solicitation, and a contracting shop small enough that a capable firm gets read rather than screened out.
Bid/No-Bid: BID — software and modeling work at a scale one team can carry. Small-agency past performance is worth more than its dollar value.
3. DHS Transportation Security Laboratory — Cloud-Based Platform for the Screening System Data Sharing Consortium
Sources Sought · Response due August 18, 2026 · Full & open · NAICS 518210
Market research for a cloud platform that would host and share screening-system data across a consortium. Three weeks of runway, and the requirement is still soft enough that a response shapes it.
Bid/No-Bid: WATCH — a consortium platform will likely be led by a prime, but the RFI is how a specialist gets named in someone's team before the solicitation drafts.
The other 12
The three above, in depth. The other twelve, at a glance.
Four of the twelve are physical security this week — installed alarm, camera and intrusion-detection systems at military bases. That is what the pipeline held. They are listed because a small integrator can win them, and each Bid/No-Bid line says which kind of work it is.
Small Business Set-Aside
1. VA (NCO 16) — VISN 16 Secure DICOM Image Sharing Solution
Combined Synopsis/Solicitation · Due 08/07/2026 · NAICS 541519 · View on SAM.gov →
Bid/No-Bid: BID — medical imaging exchange with a security requirement attached. Healthcare integrators with DICOM experience can quote this in the time available.
2. USCG (Base Alameda) — Southwest District Electronic Security Systems Modernization
Combined Synopsis/Solicitation · Due 08/07/2026 · NAICS 561621 · View on SAM.gov →
Bid/No-Bid: BID — electronic security systems across a Coast Guard district. Physical security work, not network defense, so price it as integration.
3. USAF (Air Combat Command) — Offutt AFB Intrusion Detection System Services
Combined Synopsis/Solicitation · Due 08/07/2026 · NAICS 561621 · View on SAM.gov →
Bid/No-Bid: BID — recurring service work on installed IDS at a strategic base. Base access and cleared technicians decide this one.
4. USAF (Air Mobility Command) — PKB Security Systems Maintenance FY26, JSOU
Combined Synopsis/Solicitation · Due 08/12/2026 · NAICS 561621 · View on SAM.gov →
Bid/No-Bid: BID — a maintenance contract with a defined installed base. Fifteen days is enough to walk the site and price it properly.
5. FAA — Screening Information Request: Strategic Sourcing for Various Supplies and Equipment (SAVES)
Solicitation · Due 08/12/2026 · Partial Small Business Set-Aside · NAICS 541519 · View on SAM.gov →
Bid/No-Bid: PASS — a strategic sourcing vehicle. The partial set-aside carves out a lane, but the lane belongs to firms already carrying supply-chain scale. Track it, do not build a proposal team around it.
6. USCG (Base Miami) — Repair/Replace Security Systems, Sector Key West
Combined Synopsis/Solicitation · Due 08/17/2026 · NAICS 561621 · View on SAM.gov →
Bid/No-Bid: BID — twenty days of runway on a defined repair scope. The longest clock on any set-aside this week.
8(a) · SDVOSB · WOSB · HUBZone
7. VA (NCO 02) — Vocera Communication Badges
Presolicitation · Due 08/05/2026 · SDVOSB Set-Aside · NAICS 541519 · View on SAM.gov →
Bid/No-Bid: WATCH — a named-product buy still in pre-solicitation. Worth a response only if you hold Vocera reseller authority; the RFP will move fast once it drops.
Full & Open
8. USPTO — Enterprise Cloud Modernization (ECM)
Solicitation · Due 08/06/2026 · NAICS 541519 · View on SAM.gov →
Bid/No-Bid: PASS — enterprise cloud migration for a patent office running some of the oldest systems in the civilian government. A prime will carry this. Read it for the requirements language, then find the team you want to be on.
9. CMS — Intelligent Coding Assistance Tool (RFI)
Sources Sought · Due 08/20/2026 · NAICS 541512 · View on SAM.gov →
Bid/No-Bid: WATCH — AI-assisted medical coding at CMS scale. Three weeks to answer, and the RFI questions will tell you whether they want a product or a services wrapper.
10. HUD — Knowledge Management System and Services (KMSS)
Sources Sought · Due 08/21/2026 · NAICS 541511 · View on SAM.gov →
Bid/No-Bid: WATCH — the longest shaping window in this week's list, and a scope a small development shop can actually hold. Answer it.
11. DHA — Cloud Storage Support Services for the DoD Trauma Registry (RFI)
Sources Sought · Due 08/24/2026 · NAICS 541519 · View on SAM.gov →
Bid/No-Bid: WATCH — clinical registry data in the cloud carries real safeguarding requirements. Four weeks of runway, and the eventual award will reward whoever helped write the storage requirements.
12. USACE — Utility Monitoring and Control Systems VI (Draft Solicitation, Amendment 2)
Combined Synopsis/Solicitation · Due 08/24/2026 · NAICS 541512 · View on SAM.gov →
Bid/No-Bid: PASS — control-system work at construction scale, and a draft solicitation still moving. The cybersecurity requirements for DoD control systems are the part worth reading even if you never bid.
Recompete pipeline
DHS/CISA — State & Local Cybersecurity Grant Program Support
Incumbent: PADRON LLC · Set-aside (current): 8(a) · Est. completion: 09/30/2026 · 64 days out
The window for a credible capture story has effectively closed; what remains is deciding whether to team with the incumbent or against them.
(Forecast record F2025069027; confirm live status.)
Second entry withheld. No other opportunity this week could be built to the field schema without inventing an incumbent or a completion date.
Reply with your primary NAICS and set-aside status. I'll flag what fits you next week.
Act 2 — What changed in the market
Compliance flash
The White House has stood up GOLD EAGLE, a clearinghouse meant to coordinate cybersecurity vulnerability handling across open-source maintainers, critical-infrastructure operators, and federal agencies using existing authorities rather than new ones. What this means for you: a coordinated-disclosure channel only works if vendors can receive and act on a report. The post-quantum executive order already put a vulnerability disclosure requirement on the FAR Council's plate, and the direction of travel is consistent. If your firm ships software or a hosted service and has no published intake address for vulnerability reports, that is now the cheapest gap on your list to close.
Agency intelligence
Volume held, biddable collapsed. 199 notices across the seven NAICS codes, 35 clearing all six gates. The comparison to last week's 153 is not valid: our deadline gate now excludes anything closing before the following brief, which removed 62 positions on its own. Treat 91 as the first clean reading under the new definition, not as a market decline.
Only one true cyber solicitation cleared our filters. The pipeline skewed hard toward physical and electronic security systems, CCTV, alarm maintenance and intrusion detection at bases, plus health IT and cloud storage. The week's two genuine cyber requirements, a VA SIEM buy and a Total Small Business wireless deployment at SOCNORTH, both closed on our send date and could not be listed.
Set-asides ran short. Nine of the fifteen carry one, which meets our floor, but almost every set-aside this week closes inside ten days while the long runways sit in full and open competition. A small firm that only bids set-asides had a compressed week.
For a shop that lives on cybersecurity services rather than security hardware, this was a thin week, and the honest read is to spend it answering the three RFIs with long clocks instead of chasing quotes.
Act 3 — Analysis
Deep dive — GSA wants to write the contract clause for every LLM that touches government data
A federal contractor building a large language model into a delivered service has, until now, had no contract clause telling them what happens to the prompts, the outputs, or the model behind them. GSA has drafted one, and the comment window closes on August 3, 2026.
What GSA actually published
The clause is GSAR 552.239-7001, "Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems." GSA published it in the Federal Register on June 17, 2026, amending 48 CFR Parts 539 and 552, and held a public listening session on July 14.
This is the second draft. The first, released in March 2026 through GSA Multiple Award Schedule Refresh 31, applied whenever AI capabilities were provided to or used by a contractor performing a GSA contract. That trigger was broad enough to reach a contractor using an AI tool in virtually any context, and industry said so. The June version is the response.
Who is in scope, and who is not
The clause applies only when Government Data will be processed by a large language model. GSA defines Government Data as both Data Inputs, meaning user prompts and source data, and Data Outputs, meaning system responses, analyses, metadata, and synthetic data.
Two exclusions sit alongside it. An LLM embedded in a common commercial product, such as a word processor or a map navigation system, tracking the definition at Section 7223(4)(B) of Public Law 117-263. And an LLM whose functionality is incidental to the primary purpose of the requirement being procured.
The distinction is practical rather than technical. Drafting a deliverable in a word processor that happens to include an AI assistant sits outside. Wiring a model into a workflow that ingests agency data and returns analysis the agency relies on sits inside.
The flowdown reaches subcontractors
The clause defines four roles across the supply chain: LLM Developer, LLM System Operator, LLM System Integrator, and LLM Service Provider. The prime must extend specific paragraphs of the base clause to whichever party occupies each role.
A subcontractor supplying a model-backed component can therefore inherit obligations without being party to the prime contract. This is the same structural pattern that DFARS 252.204-7012 established on the defense side, where safeguarding and reporting duties travel down the chain regardless of who signed the top-level agreement.
Why the scope change matters more than it looks
The March draft was tethered to GSA Multiple Award Schedule contracts. The June version amends the General Services Acquisition Regulation itself.
The practical effect is reach. Once finalized, the clause is expected to apply across GSA-administered contracts and solicitations, including the Federal Supply Schedules, governmentwide acquisition contracts, and OASIS+. For a firm holding a Schedule, that is the difference between a Schedule-specific requirement and a general condition of selling to GSA.
What non-compliance costs
GSA has attached consequences that go beyond administrative correction. A contractor who fails to comply faces potential suspension of the AI system's use, termination for cause, and liability for decommissioning costs.
That last item deserves attention during pricing. If a model has to be removed from a live system, the draft points at the contractor to pay for unwinding it. Most AI-enabled service proposals carry no line for that today.
The five questions GSA asked
GSA is seeking comment on any aspect of the draft, but named five areas specifically: whether the revised clause prescription adequately addresses earlier concerns about scope; whether the requirements for Government Data ownership, protection, and contractor accountability are clearly defined; whether the roles of Contractor, LLM Developer, LLM System Operator, LLM System Integrator, and LLM Service Provider are clearly defined and the flowdown paragraphs accurately presented; whether implementation of the flowdown clauses is understandable; and whether the clause adequately addresses risks related to foreign ownership of LLMs, where a change to the model could covertly affect government data, outputs, or decisions without the contracting entity changing.
A firm that has actually integrated a model into a federal delivery can answer these from operational experience. That carries more weight with drafters than a general objection.
What to do before August 3
Inventory the touch points. Identify every place a model processes agency data in anything you deliver, including tools your subcontractors use on your behalf.
Test the exclusions honestly. Decide whether the embedded-product or incidental-functionality carve-outs cover you, and document the reasoning. A contracting officer may ask.
Map the roles. Check whether Developer, Operator, Integrator, and Service Provider map cleanly onto your actual supply chain, or whether there is a position nobody occupies. Gaps become disputes later.
Price the decommissioning risk. If suspension or removal is a contractual consequence, it belongs in your risk register before it belongs in a proposal.
Comment if the flowdown is unworkable at your size. The March draft changed because contractors wrote in. Comments go through regulations.gov and close August 3, 2026.
Where this sits in the stack
The compliance layers keep accumulating for small federal IT firms. NIST SP 800-171 governs how controlled data is protected. The Revolutionary FAR Overhaul is reorganizing where security requirements live in the regulation. FedRAMP's CR26 rewrite changed the labels on the cloud services underneath everything else. This clause adds the model itself.
At a twenty-person firm, all four land on the same desk.
FAQ
Does the GSA LLM clause apply to my company?
It applies only when Government Data will be processed by a large language model under a GSA contract. Government Data covers both inputs, such as user prompts and source data, and outputs, such as system responses, analyses, metadata, and synthetic data. If a model in your delivery chain sees any of that, assume you are in scope until you can document otherwise.
What is excluded from GSAR 552.239-7001?
Two things. An LLM embedded in a common commercial product, such as a word processor or a map navigation system, and an LLM whose functionality is incidental to the primary purpose of what is being procured. Both exclusions are narrow, and the second one turns on how the requirement is written rather than on how you use the tool.
Does the clause flow down to subcontractors?
Yes. The clause defines the roles of LLM Developer, LLM System Operator, LLM System Integrator, and LLM Service Provider, and requires the prime contractor to extend specific paragraphs to whoever occupies them. A subcontractor can inherit obligations without ever seeing the prime contract.
What happens if a contractor does not comply?
The draft allows for suspension of the AI system's use, termination for cause, and contractor liability for decommissioning costs. The decommissioning exposure is the one most proposals do not currently price.
When is the comment deadline, and where do comments go?
Comments are due August 3, 2026, and are submitted through regulations.gov. GSA named five specific questions covering scope, data ownership, role definitions, flowdown clarity, and foreign ownership risk.
Rules like this one usually reach small contractors after the comment window has closed, when the clause is already in a solicitation and the only remaining question is whether to bid. Federal Cyber Brief exists to move that moment earlier. Every Tuesday we screen the full federal IT and cybersecurity notice flow, publish the fifteen opportunities a firm under 200 people can realistically pursue, and explain the one regulatory change that will affect how you sell. Free to read.
Sources
Federal Register — General Services Acquisition Regulation; Acquisition of Information and Communication Technology; Notice of Listening Sessions and Request for Comments (91 FR 36559, June 17, 2026)
DHS Acquisition Planning Forecast System — Record F2025069027
Holland & Knight — GSA Proposes Sweeping AI Data Safeguarding Rules for LLM Contractors
SAM.gov — individual opportunity notices linked throughout this brief
Know a small firm drowning in SAM.gov? Forward this brief.
federalcyberbrief.com
Federal Cyber Brief is an independent publication providing general information for educational purposes. It is not legal, financial, or procurement advice. Verify all opportunities and deadlines directly on SAM.gov before acting.
