FDA Cybersecurity Risk Management and Compliance Services

SOL #: SS-75F40126Q00036Sources Sought

Overview

Buyer

Health And Human Services
Food And Drug Administration
FDA OFFICE OF ACQ GRANT SVCS
Beltsville, MD, 20705, United States

Place of Performance

St James, MD

NAICS

No NAICS code specified

PSC

No PSC code specified

Set Aside

No set aside specified

Timeline

1
Posted
Jan 6, 2026
2
Response Deadline
Feb 4, 2026, 7:00 PM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

The U.S. Food and Drug Administration (FDA) is conducting market research through a Sources Sought notice to identify Small Businesses, specifically SBA certified 8(a) vendors, capable of providing Cybersecurity Risk Management and Compliance Services. This effort aims to enhance the FDA's cybersecurity posture and ensure compliance with federal mandates. Responses are due by February 4, 2026, at 2:00 PM ET.

Scope of Work

The requirement encompasses professional services for the FDA's Cybersecurity, Counterintelligence, and Insider Threat Program's Risk Management mission. Key task areas include:

  • Security Authorization Support: Developing system security authorization packages in accordance with FISMA 2014, HHS, OMB, NIST SP 800 series, and NIST FIPS.
  • Security Policy and Data Call Support: Developing and managing security policies.
  • Enterprise Governance Risk and Compliance (eGRC) Support Services: Including support for tools like RSA Archer.
  • Cybersecurity Risk Management Documentation Services: Creating necessary documentation.
  • Transition In or Out Services: Facilitating service transitions. The scope also involves ensuring compliance with DHS High Value Asset Control Overlay and supporting ongoing authorization processes.

Contract & Timeline

  • Opportunity Type: Sources Sought (Market Research)
  • Set-Aside: Small Business, specifically SBA certified 8(a) vendors
  • GSA MAS Categories: 54151S (Information Technology Professional Services) and 54151HACS (Highly Adaptive Cybersecurity Services)
  • Response Due: February 4, 2026, 2:00 PM ET
  • Published: January 6, 2026
  • Place of Performance: Primarily Washington, DC Metropolitan area, with potential for remote work and travel to other FDA offices.

Submission & Evaluation

Interested small businesses, particularly 8(a) certified firms, should submit capability statements not exceeding 10 pages. Submissions must include company details, SAM registration, GSA contract numbers, proposed NAICS/GSA Schedule, publicly posted pricing, and detailed responses to specific questions regarding experience in cybersecurity risk management, FISMA, ongoing authorization, FedRAMP, AI, DHS tools, auditing, and subcontracting. Responses will be reviewed confidentially to assess industry capabilities; no individual feedback will be provided. This is for market research only and does not guarantee a future solicitation or contract award.

Special Requirements

Contractor personnel will require background investigations (Tier 2/2S) and mandatory training on cybersecurity awareness, privacy, and records management. Adherence to FedRAMP, HSPD-12, and Section 508 accessibility standards is required.

People

Points of Contact

Michelle DacanayPRIMARY

Files

Files

Download
Download

Versions

Version 1Viewing
Sources Sought
Posted: Jan 6, 2026
FDA Cybersecurity Risk Management and Compliance Services | GovScope