Government security teams managing multiple Amazon EKS clusters and ECS services are evaluating Cloud-Native Application Protection Platforms (CNAPP) to improve vulnerability management by reducing alert noise and prioritizing actionable runtime risks. Community feedback highlights vendors like Wiz and Upwind for their runtime context capabilities, which help focus remediation efforts on vulnerabilities that truly impact active workloads. Procurement professionals should note the importance of vendor responsiveness and organizational readiness to remediate findings, as well as the value of extended renewal timelines to allow thorough proof-of-concept evaluations. Additionally, considering vendors specializing in backport-focused patching and patched open-source software libraries, such as Chainguard, can enhance security posture for containerized environments at scale.
Why this matters: Agencies managing containerized workloads on EKS and ECS face alert fatigue from vulnerability scanners; runtime context sensors can significantly reduce false positives and prioritize critical risks.
Procurement teams should evaluate CNAPP vendors based on runtime reachability features, support responsiveness, and integration ease to optimize security operations.
Extended contract renewal periods enable comprehensive testing and validation of CNAPP solutions before full deployment.
Organizations may benefit from incorporating patched OSS library vendors to address vulnerabilities in third-party components effectively.
Upwind's eBPF sensor watches what actually loads at runtime, so most of those "critical" CVEs in unused packages drop off the priority list on their own. Our actionable vuln count went from unmanageable to something two people could clear in a sprint. Rollout was a daemonset per cluster, not weeks of work.
The Department of Defense (DoD) has formalized the suspension of third-party assessments under the Cybersecurity Maturity Model Certification (CMMC) Phase 2 by issuing a binding class deviation that removes these requirements from defense contracts. While contractors must still self-attest compliance with NIST cybersecurity standards, the DoD is conducting a 60-day review of the CMMC program to evaluate its future direction. This suspension addresses challenges such as limited third-party assessor capacity, shifting standards, and support gaps for small contractors and their managed service providers. Procurement professionals and contractors should prepare for potential changes in cybersecurity compliance requirements and verification processes based on forthcoming DoD recommendations.
The suspension affects all DoD contracts requiring CMMC Phase 2 third-party assessments, reverting to self-assessments for cybersecurity compliance.
Contractors, especially small businesses and their service providers, may experience reduced immediate compliance burdens but should anticipate revised verification frameworks.
Procurement officials should adjust contract requirements and evaluation criteria to align with the current suspension and monitor the DoD's review outcomes.
Industry stakeholders should engage with forthcoming rulemaking and guidance to understand evolving cybersecurity obligations and maintain eligibility for DoD contracts.
π
Contracting Vehicles
π‘οΈ
Defense & Military
The Naval Information Warfare Systems Command (NAVWAR) is conducting an Industry Day on September 24, 2026, in Washington, D.C., to present upcoming contracting opportunities under the Direct Reporting Portfolio Manager for Robotic and Autonomous Systems (DRPM RAS). This event will highlight key solicitations including the Maritime Marketplace and the Medium Unmanned Surface Vessel Phase II Request for Proposal (RFP). Attendance is limited to two representatives per organization and requires prior registration, with Christopher J. Murr serving as the primary contact for inquiries and registration.
Why this matters: Procurement professionals and contractors specializing in robotic and autonomous maritime systems have a direct opportunity to engage with NAVWAR leadership and gain insights into forthcoming solicitations.
The event signals NAVWAR's continued investment in unmanned surface vessel technologies and maritime autonomous systems, indicating potential contract awards in these domains.
Companies should prepare to register promptly and plan participation to position themselves competitively for the Medium Unmanned Surface Vessel Phase II and Maritime Marketplace procurements.
Engagement at this Industry Day can facilitate early understanding of technical requirements and acquisition strategies, aiding proposal development and partnership formation.
Honeywell Aerospace Inc. agreed to a $2.04 million settlement on September 1, 2026, resolving allegations of noncompliance with NIST SP 800-171 cybersecurity requirements under a Department of Defense contract governed by DFARS 252.204-7012. This settlement underscores the continuing risk of False Claims Act (FCA) liability for defense contractors who fail to adequately protect covered defense information, despite the current pause on CMMC Phase II implementation. The U.S. Department of Justice emphasized that contractors must adhere to required cybersecurity standards when handling defense information, and knowingly submitting false claims related to compliance can result in significant financial penalties.
Why this matters: Defense contractors must maintain strict compliance with NIST 800-171 controls under DFARS 252.204-7012 to avoid FCA exposure, even as CMMC Phase II requirements are on hold.
Procurement professionals should ensure contract clauses related to cybersecurity compliance are enforced and monitored to mitigate legal and financial risks.
Companies providing cybersecurity services to DoD contractors can expect sustained demand for compliance support and risk mitigation solutions.
Organizations should review internal controls and reporting mechanisms to prevent submission of false claims regarding cybersecurity compliance.
The Cybersecurity and Infrastructure Security Agency (CISA) has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws affecting AI workflow engines and VPN appliances. Federal agencies are mandated under Binding Operational Directive 26-04 to address these vulnerabilities promptly, with some requiring immediate mitigation and others, specifically AI-related flaws, having a compliance deadline of September 16, 2026. This update underscores the increasing cybersecurity risks associated with AI infrastructure and VPN technologies, emphasizing the need for rapid patching, key rotation, and enhanced security measures to protect federal networks.
Why this matters: Federal procurement professionals must prioritize acquisition and deployment of security solutions that address AI infrastructure vulnerabilities and VPN security gaps.
Agencies should ensure contracts and vendor engagements include provisions for timely patch management and compliance with BOD 26-04 deadlines.
Organizations supporting federal cybersecurity efforts can leverage this update to offer specialized services in AI workload monitoring and VPN appliance hardening.
This development signals growing federal focus on securing AI operational environments, creating opportunities for vendors with expertise in AI security and infrastructure protection.
The General Services Administration (GSA) Office of Small Business (OSB) is conducting a virtual webinar titled "Small Business Resources Overview, Part 1" on September 24, 2026. This event is designed to inform small businesses about key federal resources including counseling, mentoring, funding guidance, and pathways to access GSA procurement opportunities. Speakers from the Minority Business Development Agency (MBDA), Small Business Administration (SBA), and GSA OSB will provide expert insights to help small businesses navigate federal contracting processes and enhance their competitiveness.
Why this matters: Small businesses seeking to engage with federal procurement should leverage this webinar to understand available support mechanisms and improve their access to GSA contracting opportunities.
The involvement of MBDA and SBA highlights targeted assistance for minority-owned and small enterprises, which can influence outreach and partnership strategies.
Procurement professionals should note the emphasis on resource awareness as a critical factor in expanding the small business supplier base.
Companies can prepare questions and materials ahead of the September 24 event to maximize the benefit from expert guidance on federal procurement pathways.
The Port of Los Angeles recorded its busiest three-month cargo period in history from June through August 2026, processing over 2.9 million TEUs, with August alone reaching 955,907 TEUs. This surge is driven by resilient consumer demand, early holiday shipments, and efficient cargo handling, signaling sustained high activity levels through the end of the year. Procurement professionals and contractors in logistics, transportation, and supply chain management should note the increased operational tempo and potential contracting opportunities to support port infrastructure, cargo handling, and related services.
The Port of Los Angeles is experiencing unprecedented cargo throughput, indicating a need for expanded logistics and transportation services.
Contractors specializing in supply chain optimization, cargo handling equipment, and transportation infrastructure may find increased demand.
This trend suggests opportunities for procurement planning focused on capacity expansion and efficiency improvements at one of the nationβs busiest ports.
Stakeholders should consider aligning proposals and service offerings to support the portβs sustained high-volume operations and early holiday shipment surges.
Washington State, supported by a coalition of other states, successfully challenged the U.S. Department of Housing and Urban Development's (HUD) attempt to impose new conditions on the Fair Housing Assistance Program (FHAP) federal funding. HUD agreed to dismiss the lawsuit and will not enforce the contested conditions for Fiscal Years 2025 and 2026, ensuring continued federal funding ranging from $180,000 to $365,000 annually to support state and local enforcement of fair housing laws.
This outcome preserves critical FHAP funding streams for Washington State and other participating states, maintaining resources for fair housing enforcement efforts.
Procurement professionals should note that HUD will maintain existing funding conditions through FY 2026, reducing uncertainty for grant management and compliance.
Organizations involved in fair housing enforcement and related services can anticipate stable federal funding levels and should plan accordingly for contract opportunities.
Legal and compliance teams should remain aware of the precedent set by this challenge, which may influence future HUD funding conditions and enforcement program requirements.
Washington State Attorney General Nick Brown is leading a coalition of 21 state attorneys general in lawsuits against recent federal rule changes by the U.S. Fish and Wildlife Service (FWS) and National Marine Fisheries Service (NMFS) that weaken protections under the Endangered Species Act (ESA). These legal challenges focus on the rollback of critical habitat protections for endangered species such as the Southern Resident killer whale and salmon populations in Washington. The litigation underscores ongoing regulatory uncertainty affecting conservation-related projects and environmental compliance requirements for federal and state contractors.
Procurement professionals working on environmental, conservation, or infrastructure projects in Washington and other coalition states should anticipate potential shifts in ESA compliance obligations due to these legal challenges.
Agencies and contractors involved in habitat restoration, environmental impact assessments, or species protection programs may face evolving regulatory frameworks impacting project timelines and contract requirements.
Organizations should engage with legal and environmental experts to assess risks and adapt procurement strategies in response to possible reinstatement or modification of ESA protections.
This situation highlights the importance of monitoring multi-state legal actions that can influence federal environmental regulations and procurement conditions across jurisdictions.
π€
Artificial Intelligence
π»
Information Technology
Senator Ruben Gallego has formally urged Senate leadership to establish a bipartisan Senate Select Committee on Artificial Intelligence at the start of the next Congress. This proposed committee would hold subpoena power and focus on developing legislative recommendations addressing AI's broad impacts on national security, workforce, economy, privacy, and infrastructure. The initiative signals an increased congressional emphasis on AI policy and oversight, which may lead to new regulatory frameworks and procurement priorities affecting government agencies and contractors involved in AI technologies.
Why this matters: Procurement professionals should anticipate potential new AI-related compliance requirements and legislative mandates emerging from this committee's work.
Agencies and contractors engaged in AI development, deployment, or integration may see shifts in contract scopes, funding priorities, and oversight mechanisms.
Organizations can prepare for increased government scrutiny on AI ethics, security, and infrastructure resilience impacting procurement strategies.
This development highlights the growing role of legislative bodies in shaping AI governance, which could influence future federal acquisition regulations and standards.
The Centers for Medicare and Medicaid Services (CMS) and the State of West Virginia have announced a combined federal and state investment exceeding $4.8 million under the Rural Health Transformation Program to strengthen the rural healthcare workforce and expand preventive care services across West Virginia. Governor Patrick Morrisey highlighted initial awards totaling nearly $2.4 million to support worksite clinics and employer-based healthcare services, while a separate $2.4 million award was granted to Ascend WV to recruit and retain healthcare professionals in underserved rural communities. These coordinated efforts aim to improve healthcare access, enhance workforce participation, and build sustainable rural health systems through telehealth, medical transportation, and community integration initiatives.
Why this matters: Procurement professionals should note the availability of significant funding focused on rural healthcare workforce development and preventive care expansion, creating opportunities for healthcare providers, service organizations, and technology vendors specializing in telehealth and mobile health solutions.
The program emphasizes employer-based clinics and workforce recruitment, indicating potential contracts for healthcare staffing, clinic operations, and related support services.
Organizations serving rural healthcare markets in West Virginia should evaluate partnership and bidding opportunities aligned with CMS and state priorities to improve care access and outcomes.
Procurement teams should engage with state and federal contacts to understand upcoming solicitations and program requirements to position for participation in this multi-million-dollar initiative.