Closed Solicitation · DEPT OF DEFENSE
AI Summary
NAVFAC Southwest is notifying industry about the application of Cybersecurity Maturity Model Certification (CMMC) requirements for future contracts. Contractors must achieve CMMC Level 2 or higher by November 10, 2026, to be eligible for IDIQ awards. This notice serves as a reminder for contractors to verify their CMMC status in the Supplier Performance Risk System (SPRS) to ensure compliance.
Notice to Industry – Application of Cybersecurity Maturity Model Certification (CMMC) Requirements
NAVFAC SOUTHWEST (SW) provides this notice to Industry to inform current and prospective contractors about the CMMC Requirements under all NAVFAC SW Planning, Design and Construction (PDC) Multiple Award Construction Contracts (MACCs) and Architect-Engineer IDIQ Contracts.
Future contract actions shall include the CMMC requirements in accordance with Department of War (DoW) implementation of the CMMC program.
As DoW continues implementation of the CMMC program, solicitations and contracts shall identify when contractor information systems are expected to process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The applicable CMMC level will be identified in the solicitation and contract.
Offerors shall be required to have a current CMMC status recorded in the Supplier Performance Risk System (SPRS), including applicable assessment results and affirmations, as a condition of award for the contract, task order, and associated options where CMMC requirements apply.
In order to receive an IDIQ award from NAVFAC SW PDC, on or after November 10, 2026, prospective contractors must show that they have obtained a CMMC Level 2 (C3PAO) or higher. Task orders issued under NAVFAC SW IDIQs may be assigned a CMMC Level below Level 2 (C3PAO); however, for the majority of work under Construction and Architect-Engineering IDIQs, it is anticipated that a Level 2 (C3PAO) certification will be required after November 10, 2026.
Immediate Steps Required
We urge all contractors and subcontractors to take the following immediate steps to prevent any disruption to your contract eligibility:
https://www.sprs.csd.disa.mil/pdf/SPRS_Access_CyberReports.pdf
This notice is for informational purposes only and does not constitute a solicitation, a request for proposal, nor a guarantee of award.
NOTICE TO INDUSTRY - APPLICATION OF CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) REQUIREMENTS is a federal acquisition solicitation issued by DEPT OF DEFENSE. Review the full description, attachments, and submission requirements on SamSearch before the response deadline.
SamSearch Platform
AI-powered intelligence for the right opportunities, the right leads, and the right time.