Contacts, documents and full notice history are available with a subscription.
Special Notice NONE 1 notice

Potential Application of Cybersecurity Maturity Model Certification (CMMC) Requirements For SCB MAC N00024-25-RFPREQ-PMS-300-0009

Solicitation N00024-25-RFPREQ-PMS-300-0009 Copied Notice ID adab71134464418b9c07c20e7a50eb0b Copied DEPT OF DEFENSE — DEPT OF THE NAVY
SAM.gov
Posted
Mar 17, 2026
Deadline
No deadline
Set-aside
NONE
NAICS
336612
PSC
1940

Summary

AI-generated · Mar 18, 2026

Future contract actions for the SCB MAC IDIQ will include Cybersecurity Maturity Model Certification (CMMC) requirements as DoW implements the program. This notice is informational only and does not constitute a solicitation. When contractor information systems process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), the applicable CMMC level will be specified in the solicitation or delivery order, and offers must have a current CMMC status in SPRS (including assessment results and affirmations) as a condition of award where CMMC applies.

Solicitations and orders will include the related FAR/DFARS cybersecurity provisions and clauses (e.g., FAR 52.204-21 and DFARS 252.204-7008, 7012, 7019, 7020, 7021, 7025). Review official CMMC guidance and ensure any required cybersecurity assessments are recorded in SPRS. This notice does not change existing contracts or impose new requirements by itself; the exact level and assessment type will be identified in future solicitations, which will be posted on SAM.gov and through DoW channels.

NAVSEA provides this notice to Industry to inform current and prospective contractors for the SCB MAC IDIQ that future contract actions issued shall include the Cybersecurity Maturity Model Certification (CMMC) requirements in accordance with Department of War (DoW) implementation of the CMMC program. This notice is informational only and does not constitute a solicitation, request for proposals. As DoW continues implementation of the CMMC program, Contracting Officers shall include applicable CMMC requirements in solicitations and contracts when contractor information systems are expected to process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The applicable CMMC level, will be identified in the solicitation, or delivery order. Offerors shall be required to have a current CMMC status recorded in the Supplier Performance Risk System (SPRS), including applicable assessment results and affirmations, as a condition of award for the contract, task order, or delivery order where CMMC requirements apply. The solicitation and any subsequent task/delivery orders shall include applicable Federal Acquisition Regulation (FAR) and Defense Federal Acquisition Regulation Supplement (DFARS) cybersecurity provisions and clauses, including but not limited to: FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems DFARS 252.204-7008, Compliance with Safeguarding Covered Defense Information Controls DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements DFARS 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements DFARS 252.204-7025, Notice of Cybersecurity Maturity Model Certification Level Requirements Contractors are encouraged to review official CMMC guidance and resources published by the Department of War and to ensure that any required cybersecurity assessments and related information are accurately recorded in the Supplier Performance Risk System (SPRS), as applicable. This notice does not change any existing contracts and does not by itself impose new requirements. Specific cybersecurity and CMMC requirements, including the applicable level and assessment type, will be identified in the solicitations, task/delivery order solicitations. Interested vendors should continue to monitor SAM.gov and other official Department of War communication channels for future opportunities that will identify applicable cybersecurity and CMMC requirements.

From Special Notice posted on Mar 17, 2026

Notice history

1
  1. Special Notice LATEST Posted Mar 17, 2026

Details

Solicitation number N00024-25-RFPREQ-PMS-300-0009
Notice ID adab71134464418b9c07c20e7a50eb0b
Notice type Special Notice
Product / Service (PSC) 1940
NAICS 336612
Set-aside No Set aside used
Place of performance USA
Archive date May 17, 2026

Award Information

Not yet awarded

Documents

No files available

View on SAM.gov

Contacts

primary
Jason Pratt

Email

secondary
Rufus Brown

Email

Phone

Agency

DEPT OF DEFENSE
DEPT OF THE NAVY

Place of Performance


USA

Dates

Posted Mar 17, 2026 4 months ago
Last Updated Aug 06, 2026 1 day ago