Guide Pursuit review

Preparing to receive controlled technical data

Prepare the people, systems and evidence needed to receive controlled technical data under the conditions in your solicitation.

Reviewed · Deep Fathom

Wide tables scroll sideways to show all columns.

Identify the package’s release conditions, permitted recipients, receiving systems, subcontractor restrictions and retention or destruction instructions before requesting access. Where JCP certification is required, confirm the named data custodian. Where an assessment or CMMC status is required, check that the receiving environment and evidence match it. The Hellfire RFQ below expressly requires a SPRS check before release. Other packages can use different release conditions.

This page is about the receiving side. The controlled package access guide covers which access process applies, and the JCP versus DLA Enhanced Validation guide covers DLA’s two-step approval.

The worked access case shows how a receiving-environment question remains open through the decision and handoff. It uses a retained Navy RFQ with explicitly fictional company evidence and decisions.

Two obligations arrive with one package

A technical data package can carry both export restrictions and CUI safeguarding requirements. Read the markings and governing instructions to establish which apply. The Hellfire package expressly names both.

Export control. The Navy RFQ for Hellfire adapters (N6833526Q1186, issued 25 August 2026) says the drawings “are considered Export Controlled” and includes DFARS 252.225-7048. That clause makes the contractor responsible for “all applicable laws and regulations regarding export-controlled items, including, but not limited to, the requirement for contractors to register with the Department of State in accordance with the ITAR.” Paragraph (c) adds that this responsibility “exists independent of, and is not established or limited by, the information provided by this clause.” Who may see the data is a question of citizenship and licensing, and the clause doesn’t answer it for you.

CUI safeguarding. The same RFQ says “The technical data package contains CUI” and includes DFARS 252.204-7012 (with a 2026 deviation). That clause requires “adequate security on all covered contractor information systems”, implemented through NIST SP 800-171. Which systems may hold the data is a question of your assessed boundary.

Export control governs people and destinations. Safeguarding governs systems and controls. A shop can be right on one and wrong on the other. Keep them as two rows in the record.

The receiving system

The drawings arrive somewhere. In the Hellfire RFQ they go “to your designated data custodian on your certified DD2345 via the DoD Safe website.” For DLA buys they sit in cFolders. Either way, the question is the same: when the custodian downloads the package, does it land on a system that your SPRS assessment covers?

If the custodian’s laptop, the shared engineering drive or the estimating team’s email isn’t inside the assessed boundary, the download itself is the gap. Decide the landing system, write it down, and check it against the system security plan before the request goes in. The CUI boundary scoping article explains how boundaries get drawn.

The people

Three lists, each short.

The data custodian named on the DD Form 2345. DLA’s guidance is that the custodian should be an employee at the certified CAGE location, and that a change of custodian triggers an immediate revision to the JCP certification. A certified form with a departed custodian is a problem you find on the day you request the package.

The authorized recipients inside your company. The qualified U.S. contractor definition in 32 CFR Part 250 includes a citizenship or permanent-residency condition for the person receiving data on the company’s behalf. That certification does not settle every subsequent disclosure. Have the responsible export-compliance reviewer determine permitted recipients and destinations from the applicable restrictions. For CUI, system access alone is insufficient: authorize access for the people and work that require it, consistent with the package’s dissemination controls.

Write both lists before the download.

The subcontractors who will process, store or transmit the data. The Hellfire RFQ, paragraph (h), requires the offeror to ensure such subcontractors “possess the required CMMC level prior to award of subcontracts”, and DFARS 252.204-7012(m) requires the clause itself to flow down where “subcontract performance will involve covered defense information.”

What the government checks before release

In the Hellfire RFQ it’s explicit. Paragraph (d): access “will be granted only to entities that demonstrate: 1) Current and valid CMMC Level [2(Self)]; and 2) Compliance with applicable safeguarding requirements; and 3) Valid DD Form 2345.” Paragraph (e): “The Government will verify CMMC status in the Supplier Performance Risk System (SPRS) prior to releasing the CUI materials.”

DLA’s U.S. JCP instructions separately require a NIST SP 800-171 self-assessment posted in SPRS. This is a certification prerequisite, not evidence that every release process repeats Hellfire’s CMMC-status check. DLA’s broad banner and Canadian exception instructions differ; Canadian applicants should follow their specific instructions and resolve uncertainty with JCP. See the JCP comparison guide.

A SPRS entry is a representation. What supports it is the assessment behind it: the scope, the 110 requirements, the objectives, the artifacts, the date. That’s the evidence a reviewer asks for when the representation is questioned, and it’s the evidence that has to still be true on the day of the download.

After the decision

Receiving the package creates obligations that outlast the pursuit.

  • If you don’t win, the Hellfire RFQ requires you to “destroy all export control data, regardless of form or the media on which it may be recorded” and to prove it “via signed letter on corporate letterhead” to the contracting officer. Write the procedure before you receive the files. Destruction across email, shared drives and backups is harder after the fact.
  • If you win, DFARS 252.204-7021 requires the CMMC status to be maintained for the duration of the contract on the systems used in performance, and the safeguarding clause continues to apply to the data.
  • Either way, the export-control obligations under 7048 continue for as long as you hold any of the data.

The readiness record

RequirementSourceCheckpointEvidenceOwnerState
Custodian named, current, employee at certified location. Recipient meets the Part 250 testDD 2345, DLA custodian guidance, 32 CFR 250AccessCertified form, HR confirmation
Receiving system inside assessed boundary7012, SSPAccessSSP system inventory, network diagram
SPRS entry at the named statusSolicitation para (d)/(e), 7021Access and awardSPRS screenshot with date, assessment record
Assessment evidence current7012, 800-171Access and awardObjective-level artifacts, assessment date
Authorized recipient lists (export, CUI)7048, 32 CFR 250, 7012AccessNamed lists, citizenship confirmation
Subcontractor flowdown7012(m), solicitation para (h), 7021AwardSubcontract clauses, affirmations
Destruction and retention procedureSolicitation Section APost-decisionWritten procedure, letter template

States: supported, gap, unresolved, not applicable (with reason).

Where Deep Fathom fits

Use the readiness record to identify the assessment, safeguarding and evidence work behind an access request. Deep Fathom supports evidence management and CMMC/NIST SP 800-171 workflows. Your team determines the receiving environment, maintains the custodian and recipient lists, and updates its records when the package or systems change. Our team can demonstrate the relevant compliance workflow during a platform evaluation.

Deep Fathom organizes the readiness work and the evidence. The contracting officer and DLA decide access. Export jurisdiction and licensing are questions for your export-compliance counsel.

Review the safeguarding and evidence work behind this access requirement. Tell our team which solicitation section and deadline you’re working through. We’ll show how Deep Fathom records the requirement, the work and the evidence in one record. Review bid requirements

Sources Reviewed

Read the governing material.

Solicitation text and program guidance reflect the versions reviewed September 7, 2026.