Introduction
This guide explains what Hawaii contractors need to know about CMMC compliance, how AI is changing construction operations, and the steps required to win and keep DoD contracts. It is designed for Hawaii-based defense contractors, subcontractors, and construction leaders who want to understand new cybersecurity requirements and stay competitive as federal work increasingly depends on verified compliance.
Hawaii contractors are facing a collision that will reshape who wins federal work over the next three years. On one front, AI is already transforming bid review, proposal drafting, jobsite safety monitoring, and equipment maintenance across the industry. On the other hand, the Department of Defense (DoD), along with the federal government, is enforcing cybersecurity requirements that set standards for the entire defense industrial base, which will gate contract eligibility at Pearl Harbor Naval Shipyard, Joint Base Pearl Harbor-Hickam, Schofield Barracks, and Marine Corps Base Hawaii starting this year.
Key Takeaways
Hawaii-based DoD contractors must meet CMMC 2.0 requirements by November 2025 to bid on new contracts. This is not a future concern—it is affecting solicitations now across NAVFAC Pacific and U.S. Army Corps of Engineers projects statewide.
- CMMC status is already a bid eligibility gatekeeper. As of November 10, 2025, DFARS clauses 252.204-7021 and 252.204-7025 will enforce cybersecurity requirements across the defense supply chain, shifting from self-attestation to verified compliance. CMMC requirements will apply to all applicable contracts as the enforcement phases begin. Projects at Pearl Harbor, JBPHH, Schofield Barracks, PMRF, and Marine Corps Base Hawaii are conditioning awards on SPRS scores.
- AI is actively deployed in construction operations. Leading firms use AI for contract/RFI review, bid drafting, safety monitoring via cameras and sensors, predictive maintenance, and analytics from platforms like Procore, Sage, and Viewpoint.
- Early movers gain a significant competitive advantage. Cybersecurity strategist Nick Espinosa notes that nearly 90% of digital marketers already use AI tools daily, while adoption in construction is 35-45%. Hawaii contractors who move now can capture an 18-24-month lead over competitors.
- Three actions for Hawaii principals and COOs: (1) Audit current AI tool use and lock down free-tier data exposure, (2) Determine whether your pipeline requires CMMC Level 1 or Level 2, (3) Save September 10, 2026, for ABC Hawaii’s Construction Technology Leadership Forum.

Why CMMC Compliance Now Determines Who Wins Federal Work in Hawaii
The Cybersecurity Maturity Model Certification (CMMC) is the DoD’s framework for verifying that defense contractors can protect sensitive information. Organizations must comply with CMMC standards to protect controlled unclassified information and federal contract information, thereby ensuring they meet regulatory cybersecurity requirements.
DFARS Clause 252.204-7012 requires DoD contractors to provide adequate security to safeguard covered defense information from unauthorized access and disclosure. DFARS 252.204-7025 establishes the CMMC requirements that contractors must meet to be eligible for contract award, providing clarity on cybersecurity thresholds before proposals are submitted.
For Hawaii, with $9.1 billion in annual DoD expenditures, this is not theoretical. NAVFAC Pacific and USACE Honolulu District are already conditioning solicitations on CMMC readiness for projects involving federal contract information or controlled unclassified information (CUI). Organizations must assess and address any gaps in their cybersecurity posture to comply with CMMC standards. A 2025 NAVFAC RFP for Pearl Harbor Naval Shipyard drydock renovations rejected non-attested bidders under interim DFARS rules.
Contractors in Hawaii must meet the Cybersecurity Maturity Model Certification (CMMC) requirements for federal contracts. This applies equally to primes and to every subcontractor that touches FCI or CUI. For Hawaii construction firms, organizations failing to comply with these standards risk losing eligibility for applicable contracts—CMMC is no longer an IT project; it is a gatekeeper for your backlog.
How AI Is Already Reshaping Construction Operations
Nick Espinosa, a cybersecurity strategist with deep expertise in cybersecurity and AI, and keynote speaker at the 2026 ABC ONE Conference, reports that nearly 90% of digital marketers already use AI tools daily. Construction sits at roughly 35-45% adoption. This gap creates an 18-24-month window for Hawaii’s early adopters to establish competitive leads in bid efficiency, safety performance, and operational intelligence.
Active AI use cases in construction include:
- Contract and RFI review: AI parses clauses, compares terms across documents, and flags risks faster than manual review
- Proposal and bid drafting: Tools generate scope narratives from past performance data, cutting prep time by 50%
- Jobsite safety monitoring: Computer vision analyzes camera and IoT sensor feeds for PPE compliance, fall hazards, and restricted-area access (88% detection accuracy reported)
- Predictive equipment maintenance: Machine learning from telematics forecasts failures before they cause downtime
- Business intelligence: Platforms like Procore, Sage 300 CRE, and Viewpoint deliver AI-powered dashboards for cashflow forecasting and resource leveling
Many contractors are now leveraging AI-powered services to enhance compliance and operational efficiency, especially as CMMC-compliant Hawaii contractors must meet rigorous cybersecurity standards.
For Hawaii firms, AI also addresses island-specific challenges—optimizing inter-island logistics, coordinating Oʻahu-Kauaʻi material movements for PMRF projects, and managing workforce allocation across multiple islands.

The Hidden Cyber Risk: Free-Tier AI Tools and Your Project Data
Casually pasting bid schedules, cost breakdowns, or client emails into free AI chatbots creates serious exposure. Many free-tier AI tools reserve rights to use submitted data for model training, meaning your proprietary bid strategies or CUI-marked documents could become part of public datasets. These actions can compromise the security of your organization’s information systems, putting sensitive and regulated data at risk.
Consider these scenarios:
| Role | Risk Behavior | Potential Impact |
|---|---|---|
| Estimator | Pastes full NAVFAC RFP into free chatbot | Bid strategy exposed to competitors |
| Project Manager | Summarizes CUI language via consumer AI | DFARS violation, assessment failure |
| Safety Manager | Uploads annotated jobsite photos | Reveals secure facility access controls |
| This behavior directly conflicts with NIST SP 800-171 requirements and undermines your cybersecurity posture for CMMC assessments. The fix: move to enterprise-grade AI tools with written data protection clauses (no training on your data, tenant isolation, audit logging), establish clear AI use policies, and train every team member on what cannot be sent to AI systems. |
CMMC Levels Explained for Hawaii Contractors
The CMMC program uses three maturity levels. Compliance levels depend on whether contractors handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Most Hawaii defense contractors will intersect with Level 1 or Level 2.
CMMC Level 1 (Foundational): Level 1 is required for contractors handling FCI, which includes 15 basic cyber hygiene practices aligned with FAR 52.204-21. This level requires the implementation of controls such as access control, basic incident response, and media protection. Contractors must complete an annual self-assessment, submit assessment results and annual affirmations to SPRS, and ensure that all required steps are completed to maintain compliance.
CMMC Level 2 (Advanced): Level 2 requirements involve implementing all 110 security controls specified in NIST SP 800-171 Rev 2, required for contractors handling CUI. Many contractors, including medium-sized businesses in Hawaii, must assess their cybersecurity posture and readiness and complete all required steps to achieve and maintain Level 2 compliance. For Level 2 CMMC certification, triennial assessments by certified third-party assessors (C3PAO) are typically required, with some exceptions for self-assessment. Cryptographic modules for Level 2 must be FIPS-validated; non-compliance results in points being deducted from the certification scale.
CMMC Level 3 (Expert): Level 3 requirements include all Level 2 controls plus additional enhanced controls from NIST SP 800-172 that are necessary for highly sensitive programs. This level is rare for construction.
To maintain CMMC compliance, contractors must submit an annual affirmation in the Supplier Performance Risk System (SPRS), attesting to their ongoing adherence to required cybersecurity practices.
Many Hawaii firms indirectly handle CUI through design-build projects, secure facility work, or subcontracts with primes on sensitive missions. Many contractors may have gaps in their compliance if they do not formally assess their information flows. Assuming “FCI only” without a formal review is risky.
Subcontractors Are Not Exempt: What This Means Down the Chain
Prime contractors must ensure that their subcontractors meet the required CMMC levels. Under DFARS 252.204-7021, CMMC requirements flow down to all subcontractors that process, store, or transmit FCI or CUI—regardless of tier or size.
On the islands, primes working Pearl Harbor Naval Shipyard, Schofield Barracks, JBPHH, and Marine Corps Base Hawaii projects are screening subs for CMMC status in SPRS before issuing subcontracts. This is happening now.
The merit shop reality: subs that achieve CMMC readiness become preferred partners for risk-averse primes assembling teams for NAVFAC and USACE RFPs. Subs that delay become replaceable. “We’re not sure if we’re compliant” is functionally interpreted as “not compliant” by primes and contracting officers—especially as legal scrutiny grows under the DOJ Civil Cyber-Fraud Initiative.
Hawaii subs, from specialty trades to small GC partners, should treat CMMC readiness as a prequalification requirement for continued compliance with prime expectations.

Three Immediate Actions for Hawaii Construction Leaders
The phased CMMC rollout through 2028 rewards preparation. Here are three actions every Hawaii principal, COO, and operations leader should execute now.
Action 1 – Audit AI Use and Lock Down Data Exposure
Inventory where AI is already in use across your organization—free chatbots, embedded features in Procore or Sage, point solutions for estimating or safety. Identify any flows of FCI, CUI, or proprietary bid data into free-tier tools. Move sensitive use cases to enterprise platforms with documented data protection, logging, and access controls. Conduct training so every team member understands what cannot be input into AI systems.
Action 2 – Determine Your Required CMMC Level
Map your current and target pipeline (NAVFAC, USACE, GSA, and large mainland primes operating in Hawaii) to the data types you handle. If you process only FCI, Level 1 with self-assessment applies. If you touch CUI—even indirectly—Level 2 with a third-party assessment is likely required. Assign an internal executive owner to drive a gap analysis against the applicable level.
Action 3 – Build a 12-24 Month Roadmap
Create a sequenced plan covering basic controls (passwords, MFA, backups, endpoint protection), policy and procedures development, staff training (including AI policies), and alignment with NIST 800-171 cybersecurity practices where applicable. Time your roadmap against CMMC phased enforcement: Phase 1 (November 2025), Phase 2 (November 2026), full rollout by 2028.
How ABC Hawaii Is Helping Members Navigate AI and CMMC
ABC Hawaii is the merit-shop trade association representing contractors, subcontractors, and suppliers statewide. Beyond craft training and apprenticeship programs, OSHA programs, and regulatory advocacy, ABC Hawaii is developing resources that connect AI adoption with CMMC and DFARS compliance—including AI use policy templates, executive briefings on cyber risk, and curated referrals to vetted cybersecurity partners familiar with Hawaii’s defense projects.
The flagship event is the Construction Technology Leadership Forum on September 10, 2026. Confirmed speakers include:
- Paul Doherty (The Digit Group) – Smart cities, digital twins, and AI-driven design/construction for federal projects
- Matt Abeles (ABC National’s Tech Alliance) – National construction technology trends and CMMC impacts across ABC chapters
- Kevin Soohoo (Egnyte) – Secure collaboration, data governance, and CMMC-aligned documentation for project teams
Hawaii principals, COOs, and operations leaders with federal or military work in scope should block September 10, 2026, and contact ABC Hawaii for preregistration and member briefings.

FAQ: CMMC and AI for Hawaii Construction Firms
Do Hawaii contractors without current federal contracts really need to worry about CMMC yet?
Yes. Firms pursuing future work at Pearl Harbor, Schofield Barracks, JBPHH, PMRF, or Marine Corps Base Hawaii must assume CMMC clauses will appear in RFPs starting late 2025. You need 12-18 months of runway to prepare. Primes are already building prequalified benches of CMMC-ready subs, so early preparation affects both compliance and inclusion on future teams.
How can a mid-sized Hawaii contractor afford CMMC and AI at the same time?
Take a phased approach. Focus first on low-cost, high-impact cyber basics (MFA, backups, endpoint security, staff training) that support CMMC Level 1. Then, selectively adopt AI where ROI is clear. Many enterprise AI features are bundled in platforms you already pay for. Free or low-cost cybersecurity assistance programs are available to Hawaii-based contractors, including Cyber Ready Hawaii and the Hawaii Defense Economy Cyber Compliance Education Program.
What is the practical difference between FCI and CUI for a construction company?
Federal contract information includes schedules, basic statements of work, and non-technical contract communications—information from or generated for the government under contract that is not public. Controlled unclassified information is more sensitive, such as detailed facility drawings, security system layouts, or mission-related technical data that the government marks as controlled. When in doubt, review contract language and consult with primes rather than self-declaring.
Can we just let our MSP or IT provider handle CMMC for us?
While a managed service provider can implement technical controls and provide support for documentation, legal responsibility for accurate CMMC certification rests with your company’s leadership. CMMC also covers policies, training, physical security, and supply chain oversight—areas that cannot be fully outsourced. Treat CMMC as a cross-functional initiative with input from operations, HR, legal, and finance, supported but not owned by IT.
How do we get started with ABC Hawaii’s AI and CMMC resources?
Contact ABC Hawaii directly to access member briefings, upcoming workshops, and curated partner referrals for cybersecurity assessments. Registration information for the September 10, 2026, Construction Technology Leadership Forum will be promoted through ABC Hawaii newsletters and direct member outreach. Involve your executive team early to align AI and CMMC planning with your broader business strategy.



