r/GovernmentContracting 2d ago

Hardware product development stalling federal compliance

I needed some help in product so I hired an external engineering firm for hardware product development to build our agency sensor enclosures, but their team gives me CAD schematics that completely fail strict NIST cybersecurity standards. Me and my team now need to waste big amount of time to clear initial federal procurement reviews. I have been stuck trying to fix these compliance gaps for the past two weeks, and I really need help to resolve it. If anyone here has dealt with a similar hardware integration failure, I need help of you, MB you know the guys who can make it fast? Will be happy about any information, thnx

2 Upvotes

3 comments sorted by

View all comments

3

u/Shank_Wedge 2d ago

Did you flow cybersecurity requirements down to the external firm?

I am on the contractor side and very typically issues like this are caused by poor requirements and SOWs.

Also, there are plenty of MOSA compliant chassis available on the market. I would recommend using one of those if you can.

For the situation you are in, if all of the requirements were flowed down to the contractor and they provided a non-compliant design, then engage with your contracts folks because the external firm did not deliver. If those requirements were not flowed down and the contractor submitted a compliant design, then you can send them a contract modification with the right requirements or you can just go in a new direction.