Compliance Check: Avoiding Compliance Risks During Q4
With the increased spending expected during the fourth quarter (Q4) of the government fiscal year, GSA Schedule contractors should review the following compliance risks to avoid any issues when responding to opportunities during this busy period:
Accepting Mass Modifications: Contractors will need to accept the recent MAS Solicitation Refresh #32 and any previous Refreshes in the Mass Mods portal prior to having any modifications approved, such as updating prices and adding services, products, or Special Item Numbers (SINs).
Transitioning to the FAS Catalog Platform (FCP): As GSA continues moving contractors from the Schedule Input Program (SIP) to FCP for catalog management, contractors should review whether they have been assigned a transition date yet. After the transition date, contractors cannot submit any catalog-related modifications until the FCP onboarding process is complete.
Current Points of Contact: GSA eLibrary, GSA Advantage!, and GSA eBuy are frequently used by agencies to research contractors and find solutions.By keeping points of contact for these sites up to date, contractors can promptly respond to inquiries and avoid missing out on opportunities that were sent to outdated emails or phone numbers.
SAM.gov Account Renewal: Contractors’ SAM.gov accounts are required to be active, current, and renewed every 12 months to avoid delays in contract awards or modification processing.
Since we are now in the second month of Q4, take a moment to review our recent blog detailing the above and additional compliance risks.
IN CASE YOU MISSED IT
Winvale Awarded NASA SEWP VI Contract
Winvale is excited to announce that we have been awarded a NASA Solutions for Enterprise-Wide Procurement (SEWP) VI contract under Large Category A. Winvale was one out of 364 contractors chosen for this category. Through this contract, Winvale will offer mission critical Information Technology, Communications, and Audio-Visual (ITC/AV) Solutions to many federal agencies including NASA, DoD, DHS, and HHS, while creating new opportunities for our technology partners to access unique federal buyers. The anticipated period of performance for NASA SEWP VI is November 1, 2026, through October 31, 2036. You can learn more in our press release.
Join GSA and the Office of Small Business (OSB) for a webinar on How a Subcontracting Plan Can Benefit You. In this webinar, you will learn what a subcontracting plan is and when it is required, the types of subcontracting plans, and how to find subcontracting opportunities. Register here.
Join the GSA for a webinar on How to Get Your Cloud/Software Small Business on the GSA Schedule. In this webinar, you will learn how your cloud or software small business can become one of their Best-in-Class vendors. Register here.
Join GSA and Market Research as a Service (MRAS) for a webinar on Making Market Research Easy – Enhancing Industry Partnerships. In this webinar, you will learn how to respond to GSA’s RFIs, & tips and tricks on how to fill out the surveys. Register here.
The road to becoming a GSA Multiple Award Schedule (MAS) contractor is a lengthy and often arduous process, but once you get your contract you can hold it for up to 20 years—if it’s in good standing. Knowing how to manage your GSA Schedule is essential to becoming a successful contractor. You’re not alone if you are overwhelmed by all the compliance requirements and don’t know where to start.
Join our consulting manager as he discusses important Schedule maintenance requirements that all contractors should be aware of in our next webinar. We’ll cover:
Filing your Transactional Data Reporting (TDR) sales reports
What changes are being implemented with FAS Catalog (FCP)
What information to be aware of for your SAM registration renewal
How Industrial Operations Analyst (IOA) reports work
The difference between a contractor modification and a mass modification
In late June, FedRAMP released the FedRAMP Consolidated Rules for 2026, which establish a new certification framework. Some of the major changes include new certification pathways, the removal of the FedRAMP Ready, and broader continuous monitoring requirements. The consolidated rules also introduced several terminology changes:
FedRAMP Authorization/Authorized is now FedRAMP Certification/Certified
Third-party Assessment Organization (3PAO) is now Independent Assessor
Impact Levels are now Certification Classes. Certification Classes A, B, C, and D replace the previous levels of FedRAMP Ready, Low, Moderate, and High, respectively.
The major changes to certification pathways include FedRAMP 20x becoming an official certification pathway, while the FedRAMP Ready designation and Rev5 pathways are being phased out. For contractors currently working towards a FedRAMP certification, there are several ways to convert existing applications to align with the new rules, which become mandatory on January 1, 2027. For more details on the Consolidated Rules for 2026, check out our recent blog.
CMMC Phase 2 is Paused
The Pentagon recently announced the suspension of CMMC Phase 2, which was originally scheduled to take effect on November 10, 2026. Phase 2 would have required third-party cybersecurity assessments for applicable DoD contracts involving sensitive but unclassified information (Controlled Unclassified Information, or CUI). Instead, the Pentagon is launching a 60-day, top-to-bottom review of the certification program while Phase 1 self-assessment requirements remain in effect.
QUICK TIP
Don't Overlook Sources Sought Notices
Sources Sought Notices (SSNs) can be a great opportunity for your business within the federal procurement space. Responding to these notices helps federal agencies conduct market research to identify possible vendors (especially small businesses) that can support a particular agency’s requirement in the future.
While responding to a Sources Sought can eventually lead to bids or solicitations, it does not involve an immediate reward. However, Sources Sought Notices are still valuable as they provide an opportunity for you to get your foot in the door early, and possibly shape the scope of any future proposal. Additionally, if your business is assigned to a small business set-aside, it can be advantageous to respond to a Sources Sought Notice, as federal agencies have many small business goals they need to meet. When glossing over contracting opportunities, be sure to consider pursuing Sources Sought Notices on SAM.gov and other acquisition sites during Q4. Read more about Sources Sought Notices in our recent blog post.
On behalf of the Air Force, GSA is conducting market research to get industry feedback on potential solutions fitting the criteria for a Tactical Air Traffic Control (ATC) Command and Control (C2) System (TACOS). The government would prefer a Commercial-Off-The-Shelf (COTS)/GOTS solution or enterprise solution for components of the system where applicable. Full requirements information is linked to the MRAS survey. Responses are due by August 28, 2026.
The Department of Energy is seeking input from respondents with innovative ideas for public-private computing partnerships that can advance national interests, economic security, and national security. Respondents may also suggest criteria for evaluating proposed partnerships. Responses are due by September 8, 2026.
The Department of Homeland Security has issued that it is planning a new competition for technical support services set to release under the OASIS+ contract vehicle. This requirement will be to acquire professional scientific and technical support services with sufficient scientific background and operational expertise to effectively support a full range of operations and programmatic initiatives, inclusive of research, development, test and evaluation. The notice was published on July 28th, 2026 and the estimated solicitation release is October 2026.
FREQUENTLY ASKED QUESTIONS
As of July 1, 2026, all MAS contracts have transitioned to Transactional Data Reporting (TDR). GSA has implemented a grace period now through December 31, 2026, to allow contractors time to become familiar with reporting sales under TDR. With so many new requirements being put in place, here’s some frequently asked questions regarding TDR reporting and the grace period.
Q: Why did GSA implement a grace period?
A: GSA’s temporary grace period means that contractors will not be penalized for non-compliance. It is intended to support contractors as they transition to monthly TDR reporting and will remain in effect until December 31, 2026. During the grace period, contractors may receive “soft flags” for discrepancies in their sales reporting, such as reporting incorrect sales or not reporting items exactly as they appear on their schedule. Beginning on January 1st, 2027, discrepancies in sales reporting data may be subject to enforcement by your Contracting Officer (CO).
Q: What are the new mandatory sales reporting fields?
UCID (contractors who do not list the item for click and buy on GSA Advantage (e.g., use the Services Plus File in FCP)
Cloud Service Type (SIN matches or begins with 518210C only)
*When reporting your monthly sales, it is important to keep in mind that only some of these fields are applicable to products and/or services, so be sure to report only the fields relevant to the items being sold.
Q: What happens if I report my sales wrong after the grace period?
A: If you report your monthly sales incorrectly after the grace period ends, you may be subject to an assessment from your Industrial Operations Analyst (IOA). If inaccuracies are identified in your sales data, you may be required to correct the information within a specified timeframe. With the new administration placing increased emphasis on GSA compliance, it is important to ensure all aspects of your contract remain compliant to avoid potential repercussions.
Need to Talk?
CONNECT WITH US
Richmond, VA
Winvale, 3951 Westerre Parkway, Suite 250, Richmond, VA 23233, United States, (202) 296-5505