State & Local Meeting

2026-09-22 Policy Committee

βœ… Regulatory Compliance πŸ“‹ Contracting Vehicles πŸ“š Education πŸ’Ό Professional Services

Watch meeting recording

The Wake County Schools Policy Committee met on September 22, 2026, to discuss several policy revisions and updates. Key procurement-related discussions included updates to parental leave policy 7525 to align with new General Assembly provisions, extending paid leave to 12 weeks for eligible full-time employees without differentiating between birthing and non-birthing parents. The committee also reviewed grievance policy 1740, focusing on clarifying roles and responsibilities for grievance submissions and tracking, including the use of technology to monitor grievance timelines and ensure accountability. Additionally, the committee discussed the code of ethics for board members (policy 2120), emphasizing accountability, communication protocols, and the balance between board member rights and responsibilities. No direct contract awards, RFPs, or vendor selections were addressed, but the discussions on grievance tracking and policy enforcement may influence future administrative procurement of related technology solutions. The committee approved moving parental leave policy 7525 to consent for first reading on October 6, 2026, and planned further review of grievance policy 1740 and the code of ethics in upcoming meetings.

Sources

FAR Council Proposes Comprehensive FAR Overhaul

Federal News

FAR Council Proposes Comprehensive FAR Overhaul

βœ… Regulatory Compliance πŸ“‹ Contracting Vehicles πŸ’Ό Professional Services πŸ’» Information Technology πŸ—οΈ Construction & Infrastructure

The Federal Acquisition Regulatory (FAR) Council has released a second set of four proposed rules as part of a broad overhaul of the FAR aimed at simplifying federal procurement processes, reducing administrative burdens, and enhancing competition. These proposals, open for public comment until October 19, 2026, address multiple FAR parts including commercial acquisitions, contract types, negotiated procurements, and architect-engineer services. Key changes include granting contracting officers greater flexibility in contract type selection, eliminating the longstanding catch-all FAR clause lists, introducing a new consumption-based contract type for metered supplies and services (notably cloud pricing), and correcting the architect fee limitation to align with statutory requirements. These reforms seek to modernize acquisition regulations, streamline commercial buying, and reduce friction while maintaining accountability across federal agencies.

  • Why this matters: Procurement professionals and contractors should carefully review the proposed changes to understand impacts on contract eligibility, bidding strategies, and compliance requirements.
  • The expanded discretion for contracting officers and new contract types may affect contract structuring and risk management approaches.
  • Small businesses, especially architecture firms, may benefit from revised fee limitations and clearer contracting provisions.
  • The October 19, 2026 comment deadline provides a critical opportunity for stakeholders to influence the final regulatory framework and acquisition policy direction.

Sources

Federal News

Canadian Federal Agencies Invest in Office Reconfiguration

πŸ›οΈ Physical Infrastructure πŸ’Ό Professional Services

Thirteen Canadian federal departments and agencies are collectively investing over $18.7 million in 2026 to reconfigure office spaces and acquire additional accommodations to support a return-to-office policy requiring most public servants to work on-site four days per week. Key agencies leading this effort include Innovation, Science and Economic Development Canada (ISED) and Fisheries and Oceans Canada (DFO), with Public Services and Procurement Canada (PSPC) managing space optimization to meet increased on-site presence demands.

  • This contract reflects a significant procurement opportunity in office space reconfiguration and related services to support evolving workplace policies.
  • Procurement professionals should note the emphasis on physical workspace modifications to accommodate hybrid work models, indicating demand for construction, furniture, and technology integration services.
  • Vendors specializing in office design, space planning, and facility upgrades may find opportunities to engage with multiple federal agencies.
  • The investment signals a broader trend toward increased on-site federal workforce presence, impacting future facility management and procurement strategies.

Sources

DOJ Settles Honeywell Cybersecurity Claims

Federal Analysis

DOJ Settles Honeywell Cybersecurity Claims

πŸ”’ Cybersecurity πŸ›‘οΈ Defense & Military

The Department of Justice (DOJ) announced a False Claims Act settlement with Honeywell Aerospace requiring payment of over $2 million related to alleged cybersecurity compliance failures on Department of Defense (DoD) contracts spanning April 2020 through December 2023. The settlement highlights enforcement of NIST SP 800-171 cybersecurity standards for handling controlled unclassified information (CUI) within federal contracts. Concurrently, Honeywell faces a shareholder lawsuit alleging nondisclosure of supply chain issues and the federal cybersecurity investigation. This development signals heightened government scrutiny on contractor cybersecurity practices and transparency.

  • Government contractors working with DoD must prioritize robust cybersecurity compliance programs aligned with NIST SP 800-171 to mitigate False Claims Act risks.
  • Procurement professionals should incorporate enhanced cybersecurity requirements and monitoring in contract oversight to ensure contractor adherence.
  • Companies should evaluate supply chain transparency and risk disclosure practices to avoid legal and reputational exposure.
  • This case underscores the importance of proactive vulnerability management and compliance documentation in federal contracting environments.

Sources

Federal News

DHS Awards Cumulus Cloud Contracts

☁️ Cloud Services πŸ’» Information Technology

The Department of Homeland Security (DHS) has awarded multiple single-award IDIQ contracts under its Cumulus program to provide commercial cloud services departmentwide, marking a strategic shift toward centralized and standardized cloud procurement. In September 2026, Google Public Sector received a contract valued just under $876 million, joining earlier awards to Amazon Web Services (nearly $3 billion in June 2026) and Oracle (potentially $568 million in August 2026). Microsoft Azure is anticipated to join the program, further expanding the pool of approved cloud providers. The Cumulus model aims to consolidate cloud purchasing, standardize security and oversight, and deliver cost savings and operational efficiencies across DHS IT modernization efforts.

  • Why this matters: Procurement professionals should note the move toward a multi-vendor, centralized cloud acquisition strategy that simplifies contracting and enhances security compliance across DHS.
  • The IDIQ contracts provide flexible, scalable access to commercial cloud services including Anything as a Service (XaaS), enabling agencies to tailor solutions to evolving mission needs.
  • Contractors and vendors can evaluate opportunities to participate in future task orders under the Cumulus contracts, especially as Microsoft Azure joins the pool.
  • This approach signals a broader federal trend toward consolidated cloud procurement vehicles that reduce duplication and improve oversight, relevant for agencies planning cloud modernization initiatives.

Sources

Federal Event

VA Hosts Industry Day for EHRM Construction in CT and ME

πŸ›οΈ Physical Infrastructure πŸ₯ Healthcare πŸ—οΈ Construction & Infrastructure

The Department of Veterans Affairs (VA) is conducting industry days on October 7, 2026, at the Donaldson Center in West Haven, Connecticut, and October 8, 2026, at the Auditorium, Building 210 in Augusta, Maine, to engage general contractors for two significant Electronic Health Record Modernization (EHRM) infrastructure upgrade construction projects. These projects, valued between $40 million and $100 million, involve complex phased design-bid-build construction including electrical and HVAC renovations, telecommunication room expansions, power upgrades, CAT6A data cabling replacement, and data center renovations at the West Haven and Togus VA Medical Centers. The industry days will provide contractors an opportunity to review detailed project requirements, participate in site walkthroughs, and offer feedback that may influence procurement strategies and potential set-aside considerations.

  • Why this matters: This event signals a major upcoming construction procurement opportunity within the VA's EHRM modernization efforts, emphasizing infrastructure critical to healthcare IT systems.
  • Contractors of all sizes should prepare to engage with VA representatives to understand project scope and procurement methods, potentially positioning themselves for set-aside eligibility.
  • Procurement professionals should note the dual-location approach and phased construction complexity, which may impact bidding strategies and resource allocation.
  • Early participation in the industry days can provide valuable insights into VA expectations and influence contract structuring for these multi-million-dollar projects.

Sources

Federal News

HHS Strengthens 988 Lifeline Cybersecurity

πŸ”’ Cybersecurity πŸ₯ Healthcare

The Government Accountability Office (GAO) has identified significant cybersecurity weaknesses in the Department of Health and Human Services' (HHS) 988 suicide and crisis lifeline network. Key issues include incomplete implementation of identity and access controls and insufficient cybersecurity contingency planning. GAO issued 10 recommendations aimed at enhancing security measures and strengthening oversight and enforcement mechanisms with the network administrator and local crisis contact centers. These actions are critical to preventing service disruptions and protecting vulnerable users relying on this essential mental health resource.

  • Why this matters: Procurement professionals should anticipate increased cybersecurity requirements and potential contract modifications or new solicitations focused on securing the 988 Lifeline infrastructure.
  • Agencies and contractors involved with HHS and SAMHSA must prepare for enhanced compliance mandates related to identity management and contingency planning.
  • Organizations providing cybersecurity services to crisis networks may find new opportunities as HHS implements GAO's recommendations.
  • This development underscores the importance of robust cybersecurity controls in federally funded health and crisis intervention programs, influencing future procurement strategies and contract oversight.

Sources

Federal News

CISA Reports Federal Agencies Miss Cloud Security Deadlines

πŸ”’ Cybersecurity πŸ’» Information Technology

A Department of Homeland Security Inspector General report reveals that by the June 2025 deadline, 86% of federal civilian executive branch agencies failed to fully implement the Cybersecurity and Infrastructure Security Agency's Secure Cloud Business Applications (SCuBA) policies. This widespread noncompliance increases cybersecurity risks across federal cloud environments and highlights CISA's limited enforcement authority over Binding Operational Directives, which undermines efforts to strengthen federal cloud security posture.

  • Why this matters: Procurement professionals should anticipate increased emphasis on cloud security requirements in future solicitations and contract modifications to address these vulnerabilities.
  • Agencies may revise acquisition strategies to incorporate stricter compliance verification and enhanced cybersecurity controls for cloud services.
  • Contractors providing cloud solutions should prepare for more rigorous security mandates and potential audits tied to CISA directives.
  • This situation underscores the need for improved collaboration between agencies, CISA, and vendors to meet federal cybersecurity standards and reduce risk exposure.

Sources

Federal Event

Air Force Hosts AEDC Thermal Metrology Industry Day

πŸ›οΈ Physical Infrastructure πŸ›‘οΈ Defense & Military

The Air Force Test Center at Arnold Engineering Development Complex (AEDC) is conducting an Industry Day on October 15, 2026, at Arnold Air Force Base, Tennessee, to engage manufacturers specializing in advanced optical sensor technologies. This event seeks information from original equipment manufacturers (OEMs) of infrared, high-speed, visible-light cameras, pyrometers, hyperspectral imagers, and spectrometers to support extreme temperature diagnostics, real-time thermal profiling, and debris tracking. The initiative aims to inform upcoming procurements for cutting-edge thermal metrology and optical diagnostic systems critical to Air Force testing capabilities.

  • Why this matters: Procurement professionals and contractors specializing in advanced sensor technologies have a direct opportunity to engage with the Air Force to influence future requirements and position themselves for potential contracts.
  • The focus on extreme temperature diagnostics and real-time analysis highlights a demand for sophisticated optical instrumentation capable of operating in challenging environments.
  • Companies should prepare to demonstrate expertise in infrared and high-speed imaging technologies, as well as spectral analysis tools, to align with AEDC's testing mission needs.
  • This event signals the Air Force's commitment to modernizing test infrastructure through advanced sensor acquisitions, offering strategic business development prospects in defense technology sectors.

Sources

NIST Updates OT Security Guidance

Federal News

NIST Updates OT Security Guidance

πŸ”’ Cybersecurity πŸ’» Information Technology πŸ›‘οΈ Defense & Military πŸ₯ Healthcare

NIST has released a draft revision of Special Publication 800-82 (SP 800-82r4) updating operational technology (OT) security guidance to incorporate zero trust architecture, Cybersecurity Framework 2.0 alignment, and consequence-driven risk management. This update expands coverage to additional sectors including building automation, water operations, and freight rail, and emphasizes enhanced asset management, network monitoring, and OT-specific controls. The public comment period is open until November 30, 2026, providing a window for industry stakeholders to influence the final guidance. Concurrently, CISA has highlighted critical vulnerabilities in Zyxel switches and conducted the Cyber Storm X exercise to test infrastructure cybersecurity readiness across transportation and water sectors. The New York State Senate is also advancing legislative efforts to strengthen healthcare cybersecurity standards with proposed funding and enforcement measures.

  • Why this matters: Federal agencies and contractors managing OT systems should prepare to align with the updated NIST guidance, which will likely influence future procurement requirements and cybersecurity standards.
  • The expanded scope to new critical infrastructure sectors signals growing federal emphasis on OT security, creating opportunities for specialized cybersecurity solution providers.
  • The public comment deadline of November 30, 2026, is a key date for contractors and consultants to contribute expertise and position for upcoming federal solicitations.
  • Legislative and CISA activities underscore increasing regulatory and operational focus on OT cybersecurity risk mitigation, impacting compliance and contract performance expectations.

Sources

Federal Event

NSWCPD Hosts FY27 Hybrid Industry Day in Philadelphia

πŸ“‹ Contracting Vehicles πŸ›‘οΈ Defense & Military

The Naval Surface Warfare Center, Philadelphia Division (NSWCPD) is conducting its FY27 Hybrid Industry Day on November 5, 2026, at the Philadelphia Navy Yard with virtual participation available via Microsoft Teams. This event is designed to inform government contractors and subcontractors about upcoming Department of the Navy and NAVSEA contracting opportunities for fiscal year 2027. Registration is mandatory, with specific attendance restrictions and deadlines, providing a critical platform for vendors to engage directly with NSWCPD leadership and small business specialists to understand future procurement plans and subcontracting possibilities.

  • Why this matters: Procurement professionals and contractors targeting Navy and NAVSEA contracts should prioritize participation to gain early insights into FY27 opportunities.
  • The hybrid format accommodates both in-person and virtual attendance, broadening access for diverse vendors.
  • Early engagement with NSWCPD leadership can enhance competitive positioning for upcoming solicitations.
  • Companies should direct event questions and advance submissions to the designated NSWCPD contact to ensure compliance with registration requirements.

Sources