As of 2026-09-15, this is a sample of Govly records from the past 90 days related to cybersecurity procurement updates.
In this sample
A record published on 2026-09-15 reports the United States Space Force issued a sources sought notice for contractors to support space warfighter training including cyber operations (Space Force Seeks Warfighter Training Support).
A record published on 2026-09-15 reports the Department of Defense suspended CMMC Phase II third-party assessments but maintains mandatory compliance with CMMC Level 2 based on NIST SP 800-171 (DoD Pauses CMMC Phase II Assessments).
A record published on 2026-09-15 reports the Department of Defense codified the pause of CMMC Phase 2, removing third-party assessment requirements and reviewing reforms for continuous verification (DoD Revises CMMC Phase 2 Requirements).
Recent Signals
Matching public signals published in the past 90 days.
The Department of Defense continues to underscore the critical importance of the Cybersecurity Maturity Model Certification (CMMC) program to safeguard its supply chain against cyber threats. Industry experts and government stakeholders highlight that weakening or halting CMMC compliance efforts risks exposing sensitive controlled unclassified information (CUI), undermining prior investments, and threatening the viability of small and medium-sized defense contractors. Procurement professionals and contractors are urged to prioritize adherence to evolving cybersecurity requirements and leverage available support resources to meet CMMC standards, ensuring continued eligibility for DoD contracts.
The DoD and associated federal agencies like NIST and NSA remain committed to enforcing CMMC as a mandatory cybersecurity framework for defense contractors.
Companies engaged in DoD contracting should maintain or enhance their cybersecurity posture to protect sensitive data and avoid contract risks.
Small and medium-sized businesses in the defense supply chain must consider CMMC compliance a critical factor for sustaining business viability and competitive positioning.
Service providers specializing in CMMC assessments and cybersecurity can expect ongoing demand as contractors seek to meet certification requirements.
Recent Department of Homeland Security Inspector General reports reveal that 86% of federal civilian executive branch agencies failed to fully implement CISA's Secure Cloud Business Applications (SCuBA) policies by the June 2025 deadline. The findings highlight CISA's limited enforcement authority over Binding Operational Directives (BODs), which has contributed to inconsistent adoption of mandated cloud security standards and increased cybersecurity risks across federal agencies.
Why this matters: Procurement professionals should anticipate increased emphasis on enforceable cloud security requirements in future contracts as agencies work to close compliance gaps.
The limited authority of CISA to mandate compliance suggests potential legislative or policy changes that could impact procurement strategies and contract terms.
Contractors providing cloud services and cybersecurity solutions may find growing demand for offerings aligned with CISA's SCuBA policies and zero trust frameworks.
Agencies and vendors should prioritize robust cloud security implementations to mitigate vulnerabilities and align with evolving federal cybersecurity mandates.
🔒
Cybersecurity
☁️
Cloud Services
🌐
Digital Infrastructure
🚨
Public Safety
💻
Information Technology
🛡️
Defense & Military
The Federal Bureau of Investigation (FBI) is actively investigating a significant cybersecurity breach allegedly perpetrated by the hacking group ShinyHunters, who claim to have exploited a zero-day vulnerability in Oracle's PeopleSoft software hosted on AWS GovCloud. This breach reportedly exposed sensitive personally identifiable information (PII) of nearly 5,000 FBI employees and job applicants, including names, addresses, phone numbers, and family details. The FBIJobs.gov recruitment portal remains offline as mitigation efforts continue in collaboration with third-party providers. This incident highlights critical vulnerabilities in federal HR and cloud systems, underscoring the urgent need for enhanced cybersecurity measures, vendor risk management, and rapid incident response capabilities within federal agencies and their contractors.
Why this matters: The breach exposes significant national security and counterintelligence risks, emphasizing the importance of robust cybersecurity protections for personnel data in federal systems.
Federal contractors specializing in cybersecurity, incident response, forensic analysis, and identity protection may see increased demand as agencies seek to strengthen defenses and remediate vulnerabilities.
Organizations supporting federal HR and cloud infrastructure should evaluate their security posture, patch management, and vendor oversight to align with evolving federal risk management expectations.
This event signals potential procurement opportunities related to modernization of legacy systems, enhanced vulnerability scanning, and cloud security enhancements within the Department of Justice and FBI environments.
CISA and NIST have jointly released final voluntary guidance recommending federal agencies and cloud service providers implement enhanced cybersecurity measures for cloud identity tokens, including limiting token validity to one hour, enforcing automated key rotation, and securing token storage. This guidance aims to mitigate risks of token theft and misuse, particularly in cloud applications, APIs, and AI agent workflows. Procurement professionals and contractors supporting federal IT and cybersecurity systems must align their solutions with these recommendations to meet evolving security expectations and reduce vulnerabilities associated with digital access tokens.
Why this matters: Federal agencies are encouraged to adopt stricter token management policies, impacting procurement requirements for identity and access management solutions.
Contractors providing cloud, cybersecurity, and AI-related services should incorporate automated key management and token expiration features to comply with guidance.
Laboratory and research facility managers should prepare for integration of these security practices in their IT procurements, especially for connected lab environments.
This guidance signals increased emphasis on secure cloud identity token handling, influencing future contract specifications and vendor evaluations.
VIAVI Solutions LLC has successfully achieved Level 2 certification under the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) for multiple aerospace and defense product lines. This certification, conducted by accredited assessor A-LIGN, is mandatory for DoD contractors handling Controlled Unclassified Information (CUI) and enhances VIAVI's eligibility for expanded defense contracting opportunities. The certification underscores VIAVI's commitment to cybersecurity and protecting sensitive national security information, positioning the company as a trusted partner within the Defense Industrial Base. VIAVI also plans to extend this certification to its recently acquired Inertial Labs products, further broadening its compliance footprint.
Why this matters: CMMC Level 2 certification is a critical requirement for contractors seeking to participate in DoD contracts involving CUI, making VIAVI a more competitive and compliant supplier.
Procurement professionals should note the increasing emphasis on cybersecurity certifications as a prerequisite for contract eligibility within the defense sector.
Companies aiming to engage with the DoD should prioritize achieving or maintaining CMMC compliance to meet mandatory cybersecurity standards.
This development signals ongoing enforcement of cybersecurity requirements, impacting supply chain risk management and contractor qualification processes.
🔒
Cybersecurity
🌐
Digital Infrastructure
⚡
Energy & Utilities
💻
Information Technology
Semtech Corporation and Palo Alto Networks have jointly developed and integrated a Zero Trust security solution tailored for industrial IoT and critical infrastructure networks. This solution combines Semtech's AirLink 5G/LTE routers with Palo Alto Networks' Next-Generation Firewalls to provide scalable, resilient connectivity alongside AI-driven threat prevention. The collaboration addresses increasing cybersecurity challenges in distributed utility and infrastructure environments and will be showcased at the Utility Broadband Alliance Summit & Plugfest in Fort Worth, Texas, in October 2026.
This integrated Zero Trust architecture offers procurement professionals and contractors a field-proven, standards-aligned approach to securing critical infrastructure at the industrial edge.
The solution's combination of resilient cellular connectivity and continuous asset visibility supports operational risk prioritization, which is critical for utility and infrastructure agencies managing distributed networks.
Technology providers and contractors should evaluate opportunities to support deployments leveraging 5G/LTE connectivity integrated with advanced cybersecurity frameworks in utility broadband environments.
Participation in the upcoming Utility Broadband Alliance Summit & Plugfest presents a timely venue for networking and understanding evolving procurement requirements in critical infrastructure security.
📋
Contracting Vehicles
💰
Grants & Funding
🏛️
Physical Infrastructure
🏗️
Construction & Infrastructure
🚨
Public Safety
The City of Fort Smith is preparing to award a $2.474 million contract to Arcadis for program management services supporting federally mandated sewer system improvements under a consent decree. This contract, expected to be approved at the October 5, 2026 city board meeting, will engage Arcadis to provide project management, capital improvement planning, cost control, and compliance reporting to meet EPA and DOJ requirements. City officials emphasize that Arcadis' national expertise will enhance project efficiency, transparency, and schedule acceleration. Concurrently, the city is addressing budget considerations including partial salary increases and potential one-time bonuses for police and fire personnel to improve recruitment and retention amid high workloads and turnover. This procurement represents a critical step in managing complex infrastructure compliance while balancing fiscal and workforce priorities.
🔒
Cybersecurity
🤖
Artificial Intelligence
💻
Information Technology
🚨
Public Safety
The Department of Homeland Security Science and Technology Directorate (DHS S&T) is expanding its Remote Identity Validation Rally (RIVR) program in 2026 to broaden testing of advanced identity verification technologies, including document validation, selfie matching, biometric spoofing detection, and defenses against AI-generated deepfake attacks. DHS is actively soliciting industry participation and data contributions, with application windows opening in October and December 2026. This expansion reflects a critical government response to the increasing sophistication of AI-driven identity fraud, emphasizing the need for continuous, risk-based verification systems and adaptive fraud prevention technologies.
Why this matters: Procurement professionals should note the growing demand for innovative identity verification and biometric security solutions driven by DHS S&T’s program expansion.
Contractors specializing in AI-enhanced fraud detection and biometric technologies have new opportunities to contribute to government testing and evaluation efforts.
Agencies are prioritizing modernization of identity verification infrastructure to address rapid fraud evolution, signaling increased funding and legislative support for related procurements.
Organizations should prepare for upcoming application deadlines in late 2026 to engage with DHS S&T’s RIVR program and align offerings with government requirements for adaptive, accountable fraud controls.
🔒
Cybersecurity
✅
Regulatory Compliance
🚨
Public Safety
💻
Information Technology
This Senate Judiciary Committee Subcommittee on Crime and Counterterrorism hearing, held on September 23, 2026, focused on the widespread use and implications of Flock Safety's AI-powered license plate reader (ALPR) surveillance network. The discussion centered on the procurement and deployment of over 120,000 cameras across 49 states, capturing 20 billion images monthly, and the privacy, constitutional, and security concerns arising from this technology. Witnesses, including a falsely accused citizen, legal experts, a sheriff who terminated his department's contract with Flock, and cybersecurity researchers, testified about the risks of mass surveillance, data misuse, lack of oversight, and vulnerabilities to hacking. The hearing highlighted the absence of federal regulation governing ALPR data collection and retention, the role of private companies in managing surveillance data, and the need for legislative action to impose warrant requirements and privacy protections. No direct contract awards or procurement decisions were made during the hearing, but the testimony underscored the potential impact of current and future procurement policies on surveillance technology use and vendor accountability.
The Department of Justice (DOJ) announced a False Claims Act settlement with Honeywell Aerospace requiring payment of over $2 million related to alleged cybersecurity compliance failures on Department of Defense (DoD) contracts spanning April 2020 through December 2023. The settlement highlights enforcement of NIST SP 800-171 cybersecurity standards for handling controlled unclassified information (CUI) within federal contracts. Concurrently, Honeywell faces a shareholder lawsuit alleging nondisclosure of supply chain issues and the federal cybersecurity investigation. This development signals heightened government scrutiny on contractor cybersecurity practices and transparency.
Government contractors working with DoD must prioritize robust cybersecurity compliance programs aligned with NIST SP 800-171 to mitigate False Claims Act risks.
Procurement professionals should incorporate enhanced cybersecurity requirements and monitoring in contract oversight to ensure contractor adherence.
Companies should evaluate supply chain transparency and risk disclosure practices to avoid legal and reputational exposure.
This case underscores the importance of proactive vulnerability management and compliance documentation in federal contracting environments.