Prequalification used to be about bonding capacity, safety record, financial statements and references. It still is. But increasingly there are two or three more pages, and they ask about multi-factor authentication, cyber insurance limits, incident response, and what happens to the owner's drawings and specifications once they are in your possession.
For a subcontractor, this is the moment technology stops being an overhead line and becomes a condition of being invited to bid.
Where the requirements are coming from
Owners in regulated or high-value sectors have security programmes, and those programmes now extend down the supply chain. A data centre client, a hospital system, a defence-adjacent manufacturer or a public agency all have reasons to care what happens to their building information once it leaves their hands.
General contractors are passing the requirements through, because their own contracts oblige them to.
The practical effect is that a requirement written for a large organisation lands on a hundred-person mechanical contractor with no security function, sixty days before a bid is due.
What they are actually asking for
The forms vary. The substance is consistent, and it is roughly the same short list that appears in every industry:
- Multi-factor authentication on email and remote access
- Cyber liability insurance at a stated limit, sometimes naming the owner
- A written incident response plan, and a commitment to notify within a stated window
- Controls over how project documents are stored, shared and destroyed at closeout
- Background screening for personnel with site or system access
- Confirmation that subcontractors and suppliers are held to the same terms
Nothing on that list is exotic. All of it needs to be true and documented before the form arrives.
The notification clause is the one to read
Buried in most of these packages is an obligation to notify the owner or general contractor of a security incident within a fixed window, often twenty-four or seventy-two hours, sometimes with an obligation to cooperate with their investigation.
That is a contractual commitment with real consequences, and it is undeliverable without a plan naming who decides an incident has occurred and who makes the call. A commitment made in a bid document and discovered during an actual incident is the worst possible sequence.
Turn it into an advantage rather than a cost
The subcontractors who handle this well stop treating each package as a one-off and build the answer once: the evidence, the policies, the insurance certificate, the incident card, and a named person who owns it.
Two things follow. Bid response time drops from weeks to days, which matters when the invitation arrives late. And the firm becomes eligible for work that its competitors are quietly being excluded from, which is where the actual money is.
That eligibility compounds. Owners with security programmes tend to be the owners with the better projects and the better payment behaviour, and the qualification is durable once earned.
What it should not become
It should not become a consulting programme or a certification chase. A hundred-person contractor does not need a formal security certification to satisfy most prequalification packages. It needs a small number of controls that genuinely operate, documented honestly, with a person accountable for them.
The gap between that and what most firms have is measured in weeks, not years, and much of it is configuration of systems already owned.

