Active SLED Opportunity · UTAH · UNIVERSITY OF UTAH - CAMPUS
AI Summary
University of Utah seeks a vendor for a CMMC Level 2 Mock Assessment, Gap Analysis, and remediation roadmap for a research enclave handling Controlled Unclassified Information. Mandatory pre-bid conference on 2026-07-31; bids due by 2026-08-07.
The Vendor shall provide a comprehensive CMMC Level 2 (Advanced) Mock Assessment, Gap Analysis, and remediation advisory roadmap for a designated research enclave managed by the University of Utah College of Engineering. The enclave is tightly scoped, containing fewer than 30 authorized users, and handles Controlled Unclassified Information (CUI), International... **Solicitation Type**: IFB - Invitation for Bid (Formal) **Source ID**: PU.AG.USA.2756265.2757355.C18636076 **Piggyback Contract**: No **Question Acceptance Deadline**: 08/05/2026 07:00 PM EDT **Questions are submitted online**: Yes **Bid Submission Type**: Electronic Bid Submission **Solicitation Number**: UU218803191 **Reference Number**: 0000431967 **Pricing**: In attached document **Bid Documents List**: | Item Name | Description | Mandatory | Limited to 1 file | |---|---|---|---| | Bid Documents | Documents defining the proposal | Yes | No | **Pre-Bidding Events**: Event: Prebid Conference | Date: 07/31/2026 02:00 PM EDT | Location: https://utah.zoom.us/meeting/register/0dyfQvZiSiCQSpSzI6ASTA | Mandatory: True **Questions and Answers**: | Question | Answer | |---|---| | Please list all methods for receiving CUI including: DoD SAFE? PreVeil? GCC High? Secure FTP? Email? Government portals? Prime contractor portals? Physical media? | We maintain a CUI Flow Policy that defines approved methods. We do not host email services. We are familiar with the options listed and will disclose actual methods at time of contract. | | Please answer: Which buildings contain CUI? Which rooms contain CUI? Are server rooms separate? Are labs involved? Is CUI processed from home? Is CUI processed while traveling? Is there dedicated CUI Wi-Fi? Is there a separate CUI VLAN? Is there a dedicated CUI office? | Can disclose CUI locations after award. Server rooms are separate. Labs are involved. CUI is not processed from home. CUI is not processed while traveling. No wifi. Yes, separate vlans. Yes, there are dedicated CUI locations defined in TCP for each project. | | Please verify/answer the number of items in-scope for this Mock: Number of networks? Number of VLANs? Firewalls? Routers? Switches? Wireless access points? External Internet connections where CUI is exchanged? VPN vendor(s)? Jump servers? Cloud services? | Networks: 1 VLANS: 3 Firewalls: 1 Routers: 1 Switches: 1 Wireless Access Points: 0 External Internet Connections where CUI is exchanged: 0 VPN Vendors: 0 Jump servers: 1 Cloud Services: 0 | | How is User / Admin identify managed across the enclave? | Will disclose at time of award | | How are accounts created? | Will disclose at time of award | | Who approves? Who removes? How is MFA enforced? How are privileged accounts managed? | We maintain an Access Control Policy that defines these activities. Will disclose at time of award. | | How many endpoints are there of each type: Windows? Linux? Mac? Thin clients? VDI? Jump servers? Engineering workstations? Research equipment? IoT? Printers? | No endpoints. VDI. No printers. No IOT. | | How many servers are there of each type: Windows? Linux? SQL? Web? Application? Domain Controllers? Jump servers? | Windows: 2 Linux: 2 SQL: 0 Web: 0 Domain Controller: 1 Jump Server: 1 | | Does all the following documentation exist: SSP Network diagrams CUI flow diagrams Asset inventory Policies Procedures POA&M Risk assessment CRM ESP list System inventory Change management Backup documentation Incident Response Plan | Yes it does | | Please describe the security stack including (manufacturer/vendor and number): Firewall EDR XDR SIEM DLP Email security Vulnerability scanner MDM PKI MFA Password manager DNS filter Web proxy | Will disclose at time of award. No Email. No MDM. | | Please describe how remote access is allowed, controlled, authorized, tracked, and analyzed? | Remote access is defined in TCP per project. Access is only allowed from university network space. Access is tracked in the siem. Regular audits of logs analyze traffic, siem alerts notify on user activity. | | Our staff have CCP and CCA certifications with experience conducting Mock Audits, but we have not "invested" in acquiring C3PAO or RPO status for our organization. Is the C3PAO and/or RPO status hard requirements for our organization? | Yes, c3pao or rpo are required of bidders . | | Hello, can we bid even if we missed the mandatory meeting? | No. Any interested vendors were required to have at least one representative present at the mandatory pre-proposal meeting. |
SLED stands for State, Local, and Education. These are solicitations issued by state governments, counties, cities, school districts, utilities, and higher education institutions — as opposed to federal agencies.
SamSearch Platform
AI-powered intelligence for the right opportunities, the right leads, and the right time.