Department of Defense (DoD) Privacy Information Management System (DPIMS)
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Defense Information Systems Agency (DISA) is conducting a Sources Sought to identify qualified small businesses capable of providing sustainment services for the Department of Defense (DoD) Privacy Information Management System (DPIMS). DPIMS is an enterprise-wide platform for breach reporting, enhancing efficiency and compliance across DoD components. This is market research to determine industry capabilities. Responses are due by March 6, 2026.
Scope of Work
The contractor will be responsible for comprehensive sustainment of the DPIMS platform, which is a Commercial-off-the-Shelf (COTS) SaaS solution hosted in an Azure GovCloud IL5 environment. Key responsibilities include:
- Project Management: Supervision, technical writing, and documentation.
- Operations and Maintenance: 24/7/365 system monitoring, database administration, performance tuning, patching, uptime management, backups, and routine maintenance.
- Cybersecurity Services: Continuous Authority to Operate (ATO) maintenance, vulnerability management (ACAS, IAVMs), eMASS artifact maintenance, secure NIPR connectivity, data protection, and incident response. Compliance with CMMC Level 3 is required.
- Tiered Technical Support: Providing Tier II and Tier III help desk support for DPIMS users, incident management, and SOP development.
- Configuration and Release Management: Formal release process for application changes, including testing, deployment, and documentation.
Contract & Timeline
- Type: Sources Sought (Market Research)
- Period of Performance: One 12-month base period and four 12-month option years, plus a potential 6-month extension.
- Place of Performance: Contractor's site and DISA Headquarters at Ft. Meade, MD. Remote work is possible, and CONUS travel may be required.
- Response Due: March 6, 2026, 5:00 PM ET
- Published: February 18, 2026
Eligibility / Set-Aside
DISA is specifically seeking information from small businesses, including Small Disadvantaged Businesses (SDB), 8(a), Service-Disabled Veteran-Owned Small Businesses (SDVOSB), HUBZone, and Women-Owned Small Businesses (WOSB). The NAICS Code is 541512 (Computer Systems Design Services) with a size standard of $34,000,000.
Special Requirements:
- Company must possess a final Secret security facility clearance.
- Personnel must be US Citizens and able to obtain a Secret clearance.
- Responses must demonstrate ability to comply with FAR clause 52.219-14, Limitations on Subcontracting.
Submission & Evaluation
Interested businesses should submit a capabilities statement (maximum five pages) addressing the required capabilities and special requirements. This is not a Request for Proposal (RFP), and responses are for market research purposes only. Responses should be emailed to Korrina Taitano and Sebrina Lewis.
Additional Notes
The current contract for portions of this requirement is held by Diversified Technical Services, Inc. (a Small Business) with a Period of Performance from September 24, 2021, to September 23, 2026.