DHS Network Operations Security Center (NOSC) Network, Cloud, and Cyber Services (NCCS) 2.0
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Department of Homeland Security (DHS) is conducting market research through a Request for Information (RFI) for its Network Operations Security Center (NOSC) Network, Cloud, and Cyber Services (NCCS) 2.0. This RFI seeks industry input on comprehensive cybersecurity, network operations, and cloud management support. Responses are due by March 6, 2026, at 12:00 p.m. Eastern Time.
Purpose
This RFI is solely for information and market research planning purposes for the DHS Office of the Chief Information Officer (OCIO) NCCS Services 2.0, aiming to evolve the DHS Headquarters NOSC into a best-in-class service entity. This is not a solicitation for proposals or quotes, and the Government is not obligated to issue a formal solicitation.
Scope of Work
The anticipated scope, as outlined in the draft Statement of Work (SOW), covers a broad range of services including:
- Network, Cloud, and Cyber Services (NCCS) 2.0: Comprehensive support for cybersecurity, network operations, and management.
- Monitoring and Analysis: Proactive and reactive monitoring of network infrastructure, cloud platforms, systems, and applications across all classification levels (open source, SBU, CUI, Classified, SCI, SAP).
- Event and Incident Management: Alerting, notification, incident response, and recovery for the DHS Onenet.
- Cybersecurity Services: Log management, incident handling, asset visibility, email security, cyber threat intelligence, intrusion defense, threat hunting, forensics, malware analysis, insider threat support, and penetration testing.
- Network and Cloud Operations: 24x7x365 monitoring and management, troubleshooting for DHS Networks, cloud compute, storage, and application hosting platforms.
- Field Engineering Technical Services: Regional IT support requiring hands-on intervention at DHS facilities.
- Program Management: Establishment and continuous improvement of a Program Management Office (PMO).
Key Areas of Interest for RFI Responses
DHS is specifically interested in industry feedback regarding:
- Staffing Approach: Feasibility of proposed skill mix (junior and journeyman level personnel) and resource building/maintenance.
- Contract Type: Recommendations for the most effective contract type (e.g., LH, T&M, FFP, Hybrid) with justification.
- AI Integration: How traditional tools and agentic AI can be leveraged for these services.
- Surge Support: Capabilities and approaches for providing temporary surge support.
- Personnel Security: Requirements for TS/SCI cleared personnel, who must be onsite and within commuting distance of NOSC locations.
Contract & Timeline
- Type: Request for Information (RFI) / Sources Sought
- Set-Aside: None specified
- Response Due: March 6, 2026, 12:00 p.m. Eastern Time
- Published: February 19, 2026 (based on RFI document posted date)
- Anticipated Period of Performance: One 12-month Base Period (August 1, 2026 - July 30, 2027) and four (4) 12-month Optional Ordering Periods (through July 30, 2031).
- Place of Performance: A combination of DHS, Contractor, and remote work locations, including facilities in Washington D.C. metropolitan area, Stennis, Mississippi, Chandler, Arizona, and other potential CONUS locations.
Submission Details
Responses should address one or more of the outlined areas, not exceed 15 pages (excluding cover), and be submitted electronically to opoindustryliaison@hq.dhs.gov. The Government may hold one-on-one meetings with vendors providing comprehensive responses.