1. Foundational Requirements: Getting Started
Before bidding on any federal or DoD contracts, your organization must complete several foundational administrative steps:
Register in SAM.gov: The System for Award Management (SAM) is the primary database for federal contractors. Registration is completely free and is required to bid on, receive, and get paid for federal contracts.
Unique Entity ID (UEI): Upon registration in SAM, your company will receive a 12-character alphanumeric UEI, which replaces the legacy DUNS number.
CAGE Code: You will also receive a Commercial and Government Entity (CAGE) code, which is a unique identifier used throughout the federal government.
Identify Your NAICS Codes: North American Industry Classification System (NAICS) codes classify your business activities. For the Multi-Mission Dry Dock project, key NAICS codes include:
236220: Building Construction
237990: Commercial and Industrial Building Construction
2. Essential Procurement Systems
DoD contractors must establish accounts and maintain compliance in two critical web-based systems: SAM.gov and Procurement Integrated Enterprise Environment (PIEE)
PIEE is the primary enterprise tool for DoD procurement, used for contract administration, invoicing, receiving, and acceptance (WAWF).
Website: https://piee.eb.mil
3. Cybersecurity Compliance: Understanding CMMC
The DoD has finalized the Cybersecurity Maturity Model Certification (CMMC) framework to protect sensitive digital assets within the Defense Industrial Base. If your contract processes, stores, or transmits Federal Contract Information or Controlled Unclassified Information (CUI), CMMC compliance is mandatory prior to contract award.
What is CUI?
Controlled Unclassified Information is government-created or possessed information that requires safeguarding or dissemination controls. Examples of Controlled Technical Information (CTI) relevant to dry dock construction include engineering drawings, specifications, technical reports, manuals, standards, and computer software executable code.
The CMMC Levels and Requirements
Depending on the sensitivity of the information your business will handle, you must achieve one of three CMMC levels.
4. Recommended Steps for Contractors
Start Now: The audit and certification process can take several months. Certified Third-Party Assessor Organizations (C3PAOs) are in high demand, so expect lead times before an audit can begin.
Mock Assessment: Consider contracting a C3PAO for a Level 2 mock assessment. This acts as a non-certification dry run to identify gaps before your official audit.
Specialized C3PAO: Consider selecting an accredited assessor organization that understands the construction, engineering, or shipbuilding industrial sectors.
Check Solicitations Regularly: Review upcoming opportunities on SAM.gov and carefully examine the required CMMC levels and cybersecurity requirements.
5. Helpful Resources and Free Industry Support
Preparing your business for federal contracting does not have to be done alone. There are multiple federal and regional programs designed to assist you at little or no cost:
Washington APEX Accelerator: Formerly known as PTAC, the APEX Accelerator provides expert, no-cost government contracting advising, marketing assistance, and training. Website: https://kitsapeda.org
Project Spectrum: A DoD-supported initiative providing free cybersecurity assessments, training, and tools to help small and medium-sized businesses achieve CMMC compliance.
Website: https://www.projectspectrum.io/#/
Impact Washington: An organization tailored specifically for manufacturing companies in Washington State, offering specialized cybersecurity consulting and CMMC readiness services.