13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not →

SDVOSB · Veteran-Owned · Set-Aside Eligible

Your set-aside list is full of SDVOSBs. Here is what this one has built.

Socioeconomic status gets a firm onto the list. It tells you nothing about whether they can hold a CUI boundary, produce evidence an assessor will accept, or still be standing at the end of a Level 2 assessment - which is the part of the award you actually have to defend.

MacTech operates its own FIPS 140-3 controlled CUI enclave and publishes the evidence map behind it, requirement by requirement, before anyone signs anything. Read the Trust Codex.

01 - What you are buying

Three things you can inspect before you award

A CUI boundary we run ourselves

MacTech operates its own FIPS 140-3 controlled enclave: separate identity, VPN-then-RDP access, USB and clipboard redirection disabled, hardening applied by idempotent scripts that re-run without drift. When we scope your boundary we are describing something we maintain, not something we read about.

How the enclave is built →

An evidence map that is published, not promised

The Trust Codex records every NIST SP 800-171 Rev 2 requirement against the artifact that evidences it, the script that produces that artifact, and the path it lands on. That is the deliverable an assessor works from, and it is on this site rather than behind a form.

See the Trust Codex →

Tools you can run before you call us

The CMMC and STIG reference servers we build with are public. Look up a requirement, get its SPRS point weight and the assessment objectives an assessor tests it against, and check our answers against the source before any statement of work exists.

Run the MCP servers →

02 - Procurement record

The set-aside facts, for the file

Socioeconomic
SDVOSB / VOSB / Small Business
Set-aside eligibility
FAR Part 19 SDVOSB set-aside
Verification
SBA VetCert (active)
Primary NAICS
541512 · 541519 · 541611 · 541330 · 561621
Sec/compliance posture
CMMC 2.0 L2 self-attested · NIST CSF 2.0 · NIST RMF · FedRAMP Moderate aligned · SOC 2 Type I ready
Geographic reach
United States (remote + on-site)

03 - Why the designation matters

What the set-aside is worth, and what it is not

Statutory goal credit

The government-wide small-business contracting goal for service-disabled veteran-owned small businesses is set at 3% by 15 U.S.C. § 644(g). Awarding to MacTech counts toward it and supports the broader veteran-economy commitment.

Set-aside competitive posture

On SDVOSB set-aside solicitations, MacTech is in the eligible pool. On full-and-open cyber competitions, the SDVOSB designation is a meaningful evaluation factor under many source-selection plans.

Technical depth, not just status

SDVOSB is a procurement designation, not a capability. MacTech directors have led DoD RMF programs, ATO package development for mission-critical systems, and CMMC implementations for primes and subs. The federal-credibility tone of the firm reflects who is doing the work.

Right-sized for federal small business

MacTech is built specifically for the federal small-business contracting pattern - fast proposal response, named key personnel, compliance-ready posture, and the documentation contracting officers expect to see during shortlist due diligence.

06 - Questions

SDVOSB cybersecurity - frequently asked

What is SDVOSB and why does it matter for federal contracting?

A Service-Disabled Veteran-Owned Small Business (SDVOSB) is a small business at least 51% owned, controlled, and managed by one or more service-disabled veterans. The federal government has a statutory 3% SDVOSB contracting goal across all agencies, and certain solicitations are set aside exclusively for SDVOSBs. For federal program offices, awarding to an SDVOSB counts toward statutory goals and supports the broader veteran-economy commitment.

How is MacTech's SDVOSB status verified?

MacTech Solutions is verified as an SDVOSB through the SBA's Veteran Small Business Certification (VetCert) program, which absorbed the former VA CVE process in 2023. Verification is current and the firm appears in the SBA's SDVOSB database with active status. SAM.gov entity registration lists the SDVOSB representation under the relevant socioeconomic representations.

Can MacTech bid as a prime on SDVOSB set-aside cybersecurity contracts?

Yes. MacTech is a verified SDVOSB and is eligible to prime SDVOSB set-aside solicitations under FAR Part 19. MacTech has the capacity to perform as prime on cybersecurity, CMMC readiness, NIST 800-171 implementation, RMF support, and CUI-boundary-engineering scopes within typical small-business size standards.

What NAICS codes does MacTech work under?

Primary NAICS codes include 541512 (Computer Systems Design Services), 541519 (Other Computer Related Services), 541611 (Administrative Management and General Management Consulting Services), 541330 (Engineering Services), and 561621 (Security Systems Services). MacTech meets small-business size standards across these codes. The SAM.gov entity record is the authoritative source - contracting officers should verify directly there.

What socioeconomic designations does MacTech hold?

SDVOSB (Service-Disabled Veteran-Owned Small Business) and VOSB (Veteran-Owned Small Business). MacTech is also a small business under SBA size standards for the cybersecurity-related NAICS codes the firm operates under. Other designations may apply depending on the contracting vehicle - see the SAM.gov entity record for the current list.

Can MacTech support GSA HACS, MAS, or other contract vehicles?

MacTech's service portfolio aligns to GSA HACS (Highly Adaptive Cybersecurity Services) sub-categories - Risk and Vulnerability Assessment, High Value Asset assessments, Cyber Hunt, Incident Response, and Penetration Testing - and to GSA MAS IT Professional Services labor categories. Vehicle eligibility evolves; please contact MacTech to confirm current contract access for a specific procurement.

Does MacTech have past performance on federal cybersecurity work?

Yes. MacTech directors have led cybersecurity, RMF, and authorization work for DoD systems and federal civilian programs prior to the firm's formation, and MacTech as an entity holds CMMC 2.0 Level 2 self-attested compliance, NIST CSF 2.0 alignment, NIST RMF alignment, FedRAMP Moderate design alignment, and SOC 2 Type I readiness. Detailed past-performance summaries are available on request and can be furnished as part of a capabilities statement package.

How fast can MacTech respond to an SDVOSB set-aside RFP?

For SDVOSB set-aside solicitations within MacTech's primary NAICS and capability scope, the firm can typically deliver a compliant proposal within the standard response window (5–15 business days for most cybersecurity RFPs). MacTech maintains a current capabilities statement, named key personnel resumes, and a CMMC posture summary ready to attach. Contact the firm as early as possible - even a brief heads-up on an anticipated solicitation lets us pre-position resources.

Need a capabilities statement or a same-week proposal response?

Contact MacTech directly. Typical capabilities-statement turnaround is under 24 hours; SDVOSB set-aside proposal response is within standard solicitation windows. Even a brief heads-up on an anticipated solicitation lets us pre-position resources.