Search
Logo
Sign Up
Login
Home
Guides
About
Archive
Federal Cyber Brief

Weekly Brief

Newsletter

Six Cybersecurity Contracts Are Up for Re-Bid — Every Incumbent Named

Six Cybersecurity Contracts Are Up for Re-Bid — Every Incumbent Named

The security work with money already attached is not in this week's postings. It is in six contracts that expire between February and August next year, each with the current holder, the ceiling and the amount actually obligated. Plus 15 vetted opportunities, and the SBA rule that would put thousands of larger firms inside your set-aside pool.

Aug 25, 2026

•

14 min read

You Do Not Need FedRAMP Certification to Bid — VA Just Said So in Writing

You Do Not Need FedRAMP Certification to Bid — VA Just Said So in Writing

Small software firms talk themselves out of the federal market over a requirement that was never in the FAR. VA has instructed its contracting officers to stop implying it. Plus 15 vetted opportunities, six contracts coming up for re-competition with the incumbent named, and a FAR cyber rulemaking that was quietly closed on August 14.

Aug 18, 2026

•

11 min read

Two Contracts We Flagged Just Got Awarded — Plus the CMMC RFI Deadline Is Friday

Two Contracts We Flagged Just Got Awarded — Plus the CMMC RFI Deadline Is Friday

Island Automation PC and GigXR just won two contracts we listed in earlier issues, for $147,717 and $60,000. Six more contracts in our seven NAICS codes are coming up for re-competition over the next year, each with the current holder named. Plus: the CMMC Reform RFI closes Friday at noon.

Aug 11, 2026

•

11 min read

The $90 Million Award That Isn't $90 Million — How to Read a Federal Award Notice

The $90 Million Award That Isn't $90 Million — How to Read a Federal Award Notice

Five awards in our codes last week ranged from $868,000 to $90 million, and the numbers mean three different things — a ceiling, a modification, and money actually committed. Plus 15 vetted opportunities, and three cyber requirements that close before we speak again.

Aug 4, 2026

•

10 min read

GSA Wants a Contract Clause for Every LLM That Touches Government Data. Comments Close August 3

GSA Wants a Contract Clause for Every LLM That Touches Government Data. Comments Close August 3

GSAR 552.239-7001 applies only when an LLM processes Government Data — and the two exclusions decide whether your firm is in scope. Flowdown reaches subcontractors, and non-compliance can mean termination for cause. Plus 15 vetted opportunities from a week that ran thin on cyber.

Jul 28, 2026

•

9 min read

CMMC Phase 2 Is Suspended — What Actually Changed, and What Didn't. Plus 15 Vetted Contracts

CMMC Phase 2 Is Suspended — What Actually Changed, and What Didn't. Plus 15 Vetted Contracts

On July 13 the Department of War froze CMMC third-party assessments and launched a 60-day review — but self-assessment, DFARS 7012, and your SPRS affirmation still bind you. What to do now, plus 15 vetted opportunities in a week the government kept buying cyber: Army ICAM, a SIEM set-aside, PKI, and more.

Jul 21, 2026

•

6 min read

Rev 3 Is Coming to CMMC — and the Interim Rule Is Due This Month. Plus 15 Vetted Contracts

Rev 3 Is Coming to CMMC — and the Interim Rule Is Due This Month. Plus 15 Vetted Contracts

The Unified Agenda shows DoD adopting an interim final rule this month to move CMMC from NIST 800-171 Rev 2 to Rev 3 — and it takes effect on publication. Here's what changes and how to prepare. Plus 15 vetted opportunities, including two rare small-business set-asides on classified Air Force infrastructure.

Jul 14, 2026

•

6 min read

The FAR Just Rewrote Civilian CUI Rules. You Have Until July 23 — Plus 15 Vetted Contracts

The FAR Just Rewrote Civilian CUI Rules. You Have Until July 23 — Plus 15 Vetted Contracts

The FAR Council folded civilian CUI rules into Part 40: NIST 800-171 Rev 3, 72-hour incident reporting, one standard form. Comments close July 23. Plus 15 vetted opportunities — including DOJ's managed-attribution buy and an Interior Cisco IDIQ set aside for small business.

Jul 7, 2026

•

6 min read

The Post-Quantum Executive Order: What the 2030 Contractor Deadline Means — Plus 15 Federal Cyber Opportunities

The Post-Quantum Executive Order: What the 2030 Contractor Deadline Means — Plus 15 Federal Cyber Opportunities

A June 22 executive order gives federal contractors until December 31, 2030 to go quantum-safe. Plus this week's full pipeline: a DoD water-plant OT contract, a VA patient-safety system, State Dept vetting work, and 12 more — curated for small business.

Jun 30, 2026

•

5 min read

CMMC Grants for Small Business: What Congress Just Proposed — Plus 15 Live Federal Cyber Opportunities

CMMC Grants for Small Business: What Congress Just Proposed — Plus 15 Live Federal Cyber Opportunities

Senate's FY2027 NDAA proposes up to $100K per firm for CMMC compliance. Plus this week's full pipeline: Air Force COMSEC support, USMC SCADA, DoD cyber range, and 12 more vetted opportunities — curated for small business.

Jun 23, 2026

•

6 min read

DoD's AI security deadline is today — 15 contracts inside

DoD's AI security deadline is today — 15 contracts inside

VA Zero Trust, DoD wireless, 3 AI buys — plus what CMMC going live means for your pipeline.

Jun 16, 2026

•

5 min read

Follow on LinkedIn for daily GovCon intelligence

SUBSCRIBE TO OUR NEWSLETTER

Weekly intelligence for federal IT & cybersecurity contractors. Cleared to Bid.

HOME

GUIDES

ABOUT

ARCHIVE

© 2026 Federal Cyber Brief.
beehiivPowered by beehiiv