Access to the drawings is a readiness milestone

Access to the drawings is a readiness milestone

A Navy RFQ shows why drawing access belongs on the pursuit schedule, with an owner, supporting evidence and a plan for receiving controlled data.

Deep Fathom Last verified

On 25 August 2026, Naval Air Warfare Center Aircraft Division issued a request for quotation for upper and lower Hellfire missile adapters, a build-to-print job under a foreign military sales case. Thirty-seven pages. The schedule, the CDRLs and the clause list are all there. The drawings aren’t. Page 2 explains why.

“Government owns the Build-to-Print Technical Drawing Package and the drawings are considered Export Controlled. All Offerors must be able to provide a certified DD Form 2345. All requesting Offerors must have a current certified DD2345 to obtain the drawings. Drawings will be provided to your designated data custodian on your certified DD2345 via the DoD Safe website.”

Then, one section later, the same RFQ adds a second condition on the same package.

“Access will be granted only to entities that demonstrate: 1) Current and valid CMMC Level [2(Self)]; and 2) Compliance with applicable safeguarding requirements; and 3) Valid DD Form 2345.”

And the consequence, in paragraph (l): “Failure to obtain the CUI drawing package will render the Offeror ineligible for award.”

Read those three passages in order and the shape of the pursuit changes. The first evaluated thing you send the Navy isn’t a quote. It’s an access request, and the government checks SPRS before it releases anything.

What the access section asks for

Strip the clause language away and the RFQ wants four things before an estimator sees a drawing.

A current Joint Certification Program certification, the DD Form 2345, with a named data custodian on it. A CMMC Level 2 (Self) status the government can verify in the Supplier Performance Risk System. Safeguarding that meets the applicable clause, in this package DFARS 252.204-7012 with a 2026 deviation. And a way to receive the files through DoD SAFE, which means confirming the custodian’s ability to receive the transfer and the system the files will land on before downloading them.

None of those four is a proposal task. Each has a lead time and an owner somewhere other than the estimating desk. That’s the whole argument.

Why capable shops miss it

The estimate is the habit. When a solicitation arrives, the people who decide whether to bid go to the part number, the quantity, the delivery date and the drawing list, because that’s where the money question lives. Access conditions sit in Section A, in prose, before the schedule. A review that stops at the schedule can miss the access instructions.

The second reason is vocabulary. “DD Form 2345” reads like a registration item, something the office manager handles. On this RFQ it’s a condition of eligibility, and it travels with a cyber status and a named person. Three different owners, one gate.

We saw this while building our campaign research. In the Hellfire RFQ the access conditions sit on pages 2 and 3, ahead of every line item. In a DLA Land Warren package we read the same month, they sit on pages 11 and 12 of 75, behind the schedule. Either way, a team that starts at the part number reads them last. A capable manufacturer still needs to identify the access conditions early enough to act on them.

Put access on the milestone list

Treat access as a dated line in the pursuit plan, with an owner, ahead of the estimate. For a package with access conditions like these, review three parts of that milestone.

JCP certification. Is the DD Form 2345 current, and is the custodian named on it still the right person? A certified form with a departed custodian is a problem you find the day you request the package. The DLA portal now handles applications and renewals online, and the JCP versus DLA Enhanced Validation guide explains when a second DLA step applies.

Cyber status. Which status does the solicitation name, and at which point? The Hellfire RFQ names Level 2 (Self) for access in paragraph (d) and “CMMC Level [2] certification” at award in paragraph (c). Those aren’t the same words. Record both and ask the contracting officer which applies where.

Receipt. Where will the files land, who can open them, and does that system sit inside the environment your SPRS entry describes? The controlled technical data guide lists the security and evidence work before the download.

Use those three lines to decide when a detailed estimate can start and which preliminary work can proceed meanwhile. If the JCP renewal takes longer than the response window, the pursuit decision changes on day one instead of day twenty.

Access is a milestone, and not the last one

Obtaining the package doesn’t settle the pursuit. The Hellfire RFQ makes the CMMC status a condition of award as well, verified again before the contracting officer signs. After award, DFARS 252.204-7021 requires the status to be maintained for the systems used in performance. And every offeror that doesn’t win must “destroy all export control data, regardless of form” and send a signed letter on letterhead to the contracting officer proving it.

So the milestone list runs: access, submission, award, performance, and for the losing bidders, destruction. Access is the first, and the one with the least slack.

One case doesn’t make a rule. Plenty of defense buys have no controlled data at all, and access approval says nothing about whether you’ll win. Where the package is marked export-controlled or CUI, though, the pattern in this RFQ is worth planning around.

Where Deep Fathom fits

Your team owns the access request, receiving environment and pursuit decision. When a release condition depends on assessment evidence or safeguarding work, Deep Fathom’s evidence-management and CMMC/NIST SP 800-171 workflows may be relevant. Bring the public requirement to a platform evaluation so our team can demonstrate the applicable workflow.

Deep Fathom organizes the readiness work and the evidence. Your company decides whether to pursue. The contracting officer sets the access conditions and the Joint Certification Program decides the certification.

If the access conditions in front of you name a cyber status or a safeguarding capability, tell our team which solicitation section and deadline you’re working through. We’ll show which Deep Fathom workflow applies to the evidence behind it. Review bid requirements

Further reading: DD Form 2345 and controlled package access, CUI boundary scoping, CUI banner markings.

Reviewed 7 Sep 2026. Solicitation text reflects the retained version on the date shown. Check the SAM.gov notice history for later actions before relying on it.

References · 4 official sources
SourceWhat it coversType
Hellfire adapter RFQ notice actionPublic notice history for RFQ N6833526Q1186. Pages 2–3 of the retained package supply the access conditionsDirectory
DLA Joint Certification Program portalJCP application, renewal and controlled technical data access processGuidance
DFARS 252.204-7021, CMMC contractor compliance clauseMaintaining the required CMMC status for covered systems during performanceRegulation
DFARS 252.225-7048, export-controlled items clauseSafeguarding and handling obligations for export-controlled itemsRegulation