The Department of Defense is the largest buyer of goods and services in the world, and a meaningful share of that spending is legally reserved for small businesses. Very few of the companies eligible for it ever collect any, and the reason is rarely capability. It is that the entry paperwork is unforgiving, the systems do not talk to each other, and one wrong code or an expired registration removes you from consideration without anyone telling you why.
GERC handles that layer of the work — registrations, certifications, proposals and compliance documentation — so your team can stay on the thing you are actually good at.
Call (909) 454-7076, book a consultation, or use our contact form.
Where companies get stuck
- “We are registered in SAM.gov but have never received a solicitation we could actually bid.”
- “A prime asked for our capability statement and CAGE code and we had neither.”
- “We keep seeing sources sought notices and do not know whether to respond.”
- “We want to sell parts to DLA but cannot work out DIBBS.”
- “A drawing package is restricted and we were told we need JCP certification.”
- “A prime is asking about our SPRS score and we do not have one.”
- “We have real technology and keep hearing we should apply for SBIR.”
- “There is an RFP due in three weeks and no one here has written one.”
- “We won an award and now need a small business subcontracting plan.”
What we do
Registrations and certifications
UEI and SAM.gov registration, CAGE codes, NAICS and PSC selection, DSBS profiles, DLA DIBBS setup, Joint Certification Program (DD Form 2345) applications, and federal small business certifications including 8(a), HUBZone, WOSB, EDWOSB and SDVOSB. We also handle renewals before they lapse.
Proposals and bids
Sources sought and RFI responses, RFP and RFQ proposals, DIBBS quoting, compliance matrices, teaming and subcontracting support, small business subcontracting plans, and defense capability statements written for the prime or program office actually reading them.
SBIR and STTR proposals
DoD SBIR and STTR Phase I and Phase II proposal development, topic fit assessment, commercialization plans, and the technical volume structure agencies expect. Both programs are reauthorized through September 30, 2031.
NIST 800-171 and CMMC readiness
System Security Plans, POA&Ms, policy documentation, self-assessment support and SPRS score submission. Consulting and documentation only — GERC is not an accredited C3PAO and does not perform certification assessments.
What changed in 2026, and what it means for you
CMMC Phase II was suspended
On July 13, 2026 the Department suspended CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026, and launched a reform task force to deliver recommendations after a 60-day review and a public Request for Information. Departmental leadership described the program as imposing prohibitive compliance costs that pushed innovative companies out of the defense industrial base.
What did not change. Phase I self-assessment requirements remain in effect. Contractors and subcontractors are still obligated to meet NIST SP 800-171 Rev 2, to safeguard covered defense information under DFARS clause 252.204-7012, and to maintain a current score in SPRS. During the suspension, new procurement designations are limited to Level 1 (Self) and Level 2 (Self).
The practical read. If you paused your security documentation waiting for CMMC, that was the wrong lesson to draw. The self-assessment and SPRS obligations that primes actually screen on are still live, and the companies that keep their documentation current will be the ones ready when reformed requirements land.
SBIR and STTR were reauthorized
Authorization for both programs expired on September 30, 2025 and lapsed for roughly six months. Reauthorization was signed on April 13, 2026 and extends the programs through September 30, 2031. Three changes matter if you are considering a proposal: agencies must now screen applicants and key personnel for foreign affiliations and investment ties to countries of concern; a new Strategic Breakthrough Award category allows Phase II awards up to $30 million with a 100% matching requirement for experienced recipients; and starting in fiscal year 2027, agencies will set limits on how many proposals a single company may submit.
Who we work with
Companies with no defense revenue yet
You have a product or a service the Department buys, and no idea how to be seen. The work here is foundational: registrations, correct codes, a capability statement that survives a ten-second scan, and a realistic first target — usually a subcontract or a small DIBBS award rather than a prime contract.
Registered companies chasing subcontracts
You are in SAM.gov and nothing is happening. The work here is targeting and outreach: identifying the primes and program offices that buy what you sell, responding to sources sought notices, getting into supplier portals, and answering the compliance questions a prime asks before they will consider you.
Primes and larger contractors
You need small business subcontracting plans, compliance matrices, proposal coordination across contributors, and documentation that holds up under review. We work as an extension of your capture team, or behind your firm as a subcontractor if you prefer to keep the client relationship.
Scope, stated plainly
We prepare documents, research opportunities, write proposals and organize compliance evidence. We do not provide legal advice, tax advice, or certified cybersecurity assessment. GERC is not an accredited CMMC Third-Party Assessment Organization, and any Level 2 certification assessment must be performed by an accredited C3PAO. We do not hold a facility clearance and do not handle classified material. Where your requirement crosses one of those lines, we say so and work alongside the appropriate professional — see our referral partners.
Common questions
How does a small business become a defense contractor?
In sequence: get a UEI and an active SAM.gov registration, obtain a CAGE code, choose accurate NAICS and PSC codes, complete your DSBS profile, then register in the buying systems your customers actually use — the DLA Internet Bid Board System for supplies, and the Joint Certification Program if you need access to controlled technical data. Certifications and past performance come after that, not before.
Do we need CMMC certification to bid on DoD work right now?
Not in the way most companies were told to expect. The Department suspended CMMC Phase II on July 13, 2026 and stood up a reform task force. Phase I self-assessment requirements remain in effect, new procurement designations are limited to Level 1 (Self) and Level 2 (Self), and the underlying obligations have not gone away: NIST SP 800-171 compliance, DFARS 252.204-7012 safeguarding, and posting your score in SPRS.
Is SBIR still funded after the lapse?
Yes. SBIR and STTR authorization expired on September 30, 2025 and lapsed for roughly six months. Reauthorization was signed on April 13, 2026 and runs through September 30, 2031. It also added foreign-affiliation screening, a new Strategic Breakthrough Award category, and per-company proposal limits that agencies begin setting in fiscal year 2027.
What is the difference between a sources sought notice and an RFP?
A sources sought notice or RFI is market research — the agency is deciding whether a set-aside is viable and who can perform. It is not a bid, and responding costs you little. It is also the most overlooked entry point for small businesses, because responses shape how the eventual solicitation gets written. An RFP is the actual solicitation, with evaluation criteria and a deadline.
Can you guarantee we will win a contract?
No, and treat anyone who says otherwise with suspicion. Award decisions belong to the contracting officer. What we control is whether you are registered correctly, eligible, responsive to every stated requirement, and submitted on time — which is where a large share of small-business bids actually fail.
Do you work with companies outside California?
Yes. Registration, proposal and compliance documentation work is delivered nationwide and remotely. Our office is in downtown San Bernardino and we meet in person with companies across Southern California.
Defense markets we cover in California
California takes more defense contract spending than any other state, and the markets below buy very differently from one another. Each page covers who the buyers are, what they purchase and which certifications carry weight locally.
- El Segundo and the South Bay — space, drones and missile defence, and the fastest-growing defense market in the state. CMMC is the gate.
- Los Angeles County — roughly $15 billion in 2025, and the manufacturing base that supplies it, from Santa Fe Springs to Compton.
- San Diego — the largest defense market in California at about $19.8 billion, shaped by the Navy, ship repair and maritime systems.
- Newport Beach, Costa Mesa and Irvine — Anduril, Parker Aerospace, Terran Orbital and a fast-growing defense-tech corridor, including Laguna Beach.
- Huntington Beach, Seal Beach and north Orange County — Boeing, Karman, Mach Industries and Naval Weapons Station Seal Beach.
- Long Beach — Space Beach: Rocket Lab, Vast, Relativity and Anduril’s new $1 billion campus.
- Palmdale, Lancaster and the Antelope Valley — Plant 42, the B-21, Skunk Works and Edwards Air Force Base.
- Ventura County — Point Mugu and Port Hueneme, where more than half of warfare center contract dollars go to small businesses.
- Santa Clarita and the San Fernando Valley — actuators, valves, fluid controls and machined structures for the primes.
- Corona, Norco and the Inland Empire — NSWC Corona, March Air Reserve Base and the desert training bases.
Ready to talk? Book a consultation — a free 15-minute assessment, or a 90-minute Strategy Consultation at $265.
Start with a conversation
Fifteen minutes is usually enough to tell whether the defense market is a realistic channel for your company this year, or whether you are two steps away from being ready. If it is the latter, we will tell you which two steps.
Call (909) 454-7076, book a consultation, or use our contact form.
GERC is a woman-led advisory firm led by Dr. Shirley Ayangbah, a PhD legal economist with more than 14 years of experience. Based in downtown San Bernardino, delivering nationwide. CAGE code 11SD2, registered and active in SAM.gov, certified California Small Business (Micro) and for Public Works.
GERC provides consulting, research, administrative, proposal, procurement and organizational support services. GERC is not a law firm, an accredited CMMC Third-Party Assessment Organization (C3PAO), or a provider of legal or tax advice. Where a matter requires an attorney, CPA or accredited assessor, we say so and work alongside the professional you choose.
