FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD
All people, organizations, identifiers, legal conclusions, clinical parameters,
and events are invented for text retrieval practice. Do not use as professional
advice, an authoritative standard, a real filing, or an operational instruction.

RECORD 2: SOLICITATION AMENDMENT 0003 (EXCERPT)
SOLICITATION NO: N00019-26-R-0104-0003
EFFECTIVE DATE: MARCH 10, 2026
================================================================================

AMENDMENT PURPOSE:
The purpose of this Amendment 0003 is to update Section C Cybersecurity Mandates, 
revise Section L Deliverable Schedules, and extend the proposal closing date.

1. REVISION TO SECTION C.3.8 (CYBERSECURITY MANDATES):
Section C.3.8 is hereby deleted in its entirety and replaced with the following:
"The Contractor and all tier-1 subcontractors handling Covered Defense Information (CDI) 
shall possess an active Cybersecurity Maturity Model Certification (CMMC) Level 2 
Third-Party Assessment Organization (C3PAO) certification at the time of proposal 
submission. NIST SP 800-171 self-assessments and open POA&Ms shall NO LONGER be accepted. 
Offerors lacking validated C3PAO certification at submission shall be deemed non-compliant 
and eliminated from the competitive range without evaluation."

2. REVISION TO SECTION L.12 (CDRL A004 SCHEDULE):
Section L.12 is amended to require delivery of CDRL A004 (System Security Architecture) 
within fourteen (14) calendar days after contract award (DACA), accelerated from thirty 
(30) days.

3. EXTENSION OF PROPOSAL SUBMISSION DEADLINE:
The proposal due date is extended from April 2, 2026, to April 24, 2026, at 14:00 EST.
