NIST has released targeted cybersecurity guidance for resource-constrained operators of building automation and control systems (BACS), which manage critical infrastructure components such as HVAC, lighting, and energy systems. This guidance provides practical steps to mitigate operational technology (OT) cybersecurity risks, including password management, network segmentation, patching, and incident response. The publication highlights the growing importance of securing OT environments and creates procurement opportunities for contractors offering specialized OT cybersecurity solutions and services across multiple critical infrastructure sectors.
Why this matters: Federal agencies and infrastructure operators must address OT cybersecurity vulnerabilities to ensure reliable service delivery and compliance with evolving security expectations.
Contractors specializing in OT cybersecurity can leverage this guidance to tailor solutions for resource-limited BACS operators.
Procurement professionals should consider integrating these NIST recommendations into contract requirements and risk management strategies.
This development signals increased federal focus on OT security, potentially influencing future funding and acquisition priorities.
Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersecurity is an important factor in ensuring the safe and reliable delivery of critical goods and services.
— Keith Stouffer, NIST Researcher
For OT owners/operators, it can be challenging to address the range of cybersecurity threats, vulnerabilities and risks that can negatively impact their operations, especially with limited resources.
— Michael Galler, NIST Researcher
Agencies
National Institute of Standards and Technology, Cybersecurity and Infrastructure Security Agency, National Cybersecurity Center of Excellence
ποΈ
Physical Infrastructure
β
Regulatory Compliance
ποΈ
Construction & Infrastructure
πΌ
Professional Services
The City of South Fulton's Planning Commission held a meeting on August 19, 2026, where several zoning and land use cases were discussed. Key procurement-related actions included the approval of a rezoning request by SDH Central Georgia Care for a 72-home community development on Bishop Road, with conditions such as adherence to an amended site plan, installation of a deceleration lane, walking trails, and exterior facades reflecting neighboring agricultural properties. The commission also approved deferrals for two significant projects to the September 16, 2026 meeting to allow further review and community engagement. Additionally, a rezoning request for a restaurant and lounge with rooftop seating was approved to proceed to the city council. Another case involved a property owner seeking rezoning to correct a duplex use without proper permits; the commission discussed the implications but no final decision was recorded in the transcript. The meeting included public hearings, community concerns about environmental and traffic impacts, and discussions on maintaining quality and compatibility with existing neighborhoods.
The Defense Counterintelligence and Security Agency (DCSA) awarded ASRC Research and Technology Solutions a single-award indefinite-delivery/indefinite-quantity (IDIQ) contract valued up to $494.4 million to support its Case Processing Operations Center over a five-year period. The contract includes a $20 million minimum guarantee and covers personnel security and federal background investigations. Initial work will be performed primarily in Boyers, Pennsylvania, and St. Louis, Missouri, with the first task order obligated at $21.8 million as of August 20, 2026.
Why this matters: This contract represents a significant opportunity for contractors specializing in security clearance processing and federal background investigations, highlighting DCSA's ongoing investment in personnel vetting operations.
The single-award IDIQ structure provides ASRC with a stable workload and potential for multiple task orders, signaling sustained demand in this niche government security service.
Procurement professionals should note the geographic focus on Pennsylvania and Missouri, which may influence subcontracting and staffing strategies.
Companies offering complementary services in case management, investigative support, or security technology may find partnership or subcontracting opportunities under this contract.
π
Digital Infrastructure
π‘οΈ
Defense & Military
The U.S. Army awarded Everforth ECS a $147.8 million indefinite-delivery/indefinite-quantity contract in August 2026 to manage, maintain, transition, and retire the SUNet legacy secure unclassified network system through September 2029. This award continues the Army's investment in sustaining and modernizing its legacy network infrastructure, building on prior contracts awarded to Everforth ECS since 2019. The contract is managed by the Army Contracting Command at Aberdeen Proving Ground, Maryland, reflecting ongoing federal efforts to ensure secure and reliable network operations within Army facilities.
Why this matters: Procurement professionals should note the Army's sustained commitment to legacy network system management, indicating ongoing opportunities in network infrastructure support and transition services.
The contract's indefinite-delivery/indefinite-quantity structure allows for flexible task orders, requiring contractors to maintain readiness for varied scopes of work.
Businesses specializing in secure network management and legacy system transitions can leverage this contract as a benchmark for similar federal opportunities.
The geographic focus on Aberdeen Proving Ground and Fairfax, Virginia, highlights key operational hubs for network services within the Army's infrastructure.
ποΈ
Physical Infrastructure
π
Contracting Vehicles
ποΈ
Construction & Infrastructure
πΌ
Professional Services
The Elkhart County Council held a public meeting on August 21, 2026, addressing various budget appropriations, contract approvals, and procurement-related matters. Key procurement discussions included the approval of $1.5 million from the motor vehicle highway fund and $750,000 from the rainy day fund to purchase two tandem axle dump trucks ahead of upcoming emissions standards changes, as well as multiple appropriations for paving, chip sealing, bridge replacement, and engineering services. The council also approved a $167,870 payment to Baker Tilly for bond calculation services and authorized additional hours compensation for highway department staff to perform in-house engineering tasks, resulting in significant cost savings. Additionally, a limited waiver was approved concerning a landfill gas purchase agreement with Elkhart Project LLC. The council denied a CF1 compliance form for Dynamic Metals due to non-compliance with personal property goals, setting the matter for a hearing. Several smaller appropriations and transfers were also approved, including a $500 donation from Grand Design for staff appreciation and a $90.35 transfer related to community corrections. The meeting concluded with public comments on local tax issues and adjournment.
π
Cybersecurity
β
Regulatory Compliance
π‘οΈ
Defense & Military
π»
Information Technology
The Department of Defense (DoD) has suspended the implementation of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements to conduct a comprehensive review of the program, responding to industry feedback and concerns about compliance complexity and inconsistent Controlled Unclassified Information (CUI) marking. This pause provides an opportunity for defense contractors, especially small and mid-sized businesses, to influence reforms aimed at simplifying cybersecurity requirements while maintaining robust protections. The CMMC Reform Task Force is actively evaluating recommendations, including clarifying CUI processes, focusing on high-value controls, and balancing assurance with manageable compliance burdens. Meanwhile, CMMC Level 1 requirements remain mandatory for all federal contractors handling Federal Contract Information (FCI), with enforcement continuing under existing procurement rules.
Why this matters: Procurement professionals should anticipate potential changes to cybersecurity compliance frameworks that could affect contract eligibility and bidding strategies.
Contractors must maintain Level 1 self-assessments and ensure subcontractor compliance to meet current mandatory standards.
The suspension of third-party assessments under Phase II introduces uncertainty in verification processes, prompting contractors to adjust compliance documentation and risk management approaches.
Small and non-traditional defense contractors may benefit from forthcoming graduated compliance paths and clearer guidance on CUI marking, reducing economic and administrative burdens.
π
Cybersecurity
β
Regulatory Compliance
π‘οΈ
Defense & Military
π»
Information Technology
The Department of Defense has suspended third-party assessments under the Cybersecurity Maturity Model Certification (CMMC) program to evaluate its regulatory impact on small businesses and overall effectiveness. This pause has led to increased reliance on contractor self-attestation for cybersecurity compliance, coinciding with a recent study showing defense contractors report their highest cybersecurity scores in five years but simultaneously express significantly reduced confidence in the accuracy of these scores. These developments highlight challenges in verifying cybersecurity readiness and assurance within the defense industrial base, affecting contractor bidding strategies and emphasizing the need for verifiable compliance in future procurements.
The DoD's suspension of CMMC 2.0 Phase 2 third-party verification shifts compliance validation toward self-reporting, raising legal and market concerns among contractors.
Procurement professionals should anticipate evolving verification requirements as the DoD reviews CMMC's impact, potentially affecting contract eligibility and evaluation criteria.
Contractors and vendors specializing in cybersecurity services may find increased demand for independent verification solutions to bridge the confidence gap.
Organizations should prepare for potential updates to CMMC implementation policies discussed at upcoming industry events such as CMMC CON 2026.
The Nigerian Aviation Ministry disbursed over β¦358 million as a mobilization payment to Adroit Landstyle Ltd for the procurement and installation of passenger security screening systems at Lagos and Abuja international airports. This payment was made despite the supporting conditional Advance Payment Guarantee having expired more than a year prior, raising concerns about adherence to the Public Procurement Act and financial risk management in critical airport security contracts.
Procurement professionals should note the importance of verifying the validity of financial guarantees before releasing mobilization payments to mitigate risks of fund loss or contract non-performance.
This case underscores the need for stringent compliance with procurement regulations and enhanced oversight mechanisms in high-value security equipment contracts.
Contractors and insurers involved in government procurements must ensure timely renewal and validity of guarantees to maintain contract integrity and payment security.
Agencies managing airport security procurements may need to review their contract administration processes to prevent similar compliance gaps and safeguard public funds.
The Caddo Parish Commission held a joint meeting of the Appropriations and Economic Development Committees on August 20, 2026. A significant portion of the meeting was dedicated to a presentation by Alicia Mingo, founder of Bury Board, who requested a $65,000 appropriation to support maternal health initiatives, including doula hospital integration and community health worker training. The request was noted as a late application, missing the July 20th deadline, but committee members acknowledged the urgency and importance of maternal health and indicated they would consider the request despite procedural concerns. Additionally, the committees reviewed the 2027 appropriation packets, totaling 83 applications, and discussed the review process and timeline, with a submission deadline set for September 3rd. The meeting emphasized the importance of funding NGOs to enhance community quality of life, with a budget consideration of approximately $500,000 from oil and gas and gaming revenues for economic development projects.
ποΈ
Physical Infrastructure
ποΈ
Construction & Infrastructure
The City of Lawrence, Indiana Economic Redevelopment Commission held a meeting on August 20, 2026, where they approved updated minutes and claims for the previous month. A key procurement-related discussion involved a proposed change order for the Pendleton Pike project due to extreme summer heat causing schedule delays. The commission voted to approve the change order adjusting the mobilization and completion dates. There was also discussion about a potential $5,000 cost increase to replace landscaping with cobblestone in certain areas, but the commission decided not to pursue that change to avoid additional expenses. The executive director provided updates on potential housing infill projects and possible site-specific tax increment financing (TIF) requests related to new apartment developments, indicating ongoing planning and future procurement considerations. No other contract awards or vendor selections were made during the meeting.
The Santa Fe County Board of Commissioners held a special meeting on August 20, 2026, primarily to discuss and approve submitting a grant application to acquire approximately 22.1 acres of real property owned by Dr. Leah Morton adjacent to the Rio and Medio open space. The grant, estimated at around $500,000, would support the acquisition and potentially some capital improvements, though the primary focus is land purchase. The board heard extensive public comment both in support of and opposition to the acquisition, with concerns raised about access, parking, easements, and long-term maintenance costs. The County's Open Space Advisory Committee (COPAC) recommended acquisition, noting the property's ecological significance and potential to expand existing open space. The board unanimously approved applying for the grant and delegated authority to the county manager to negotiate and execute the acquisition if funds are awarded. They also committed to re-engaging with stakeholders, including local residents, tribal governments, and land grant communities, for future planning and management of the property. The meeting included discussions on due diligence, appraisal, access easements, and the need for further community engagement post-acquisition.