PCI DSS Compliance Technical Support

SOL #: F41999-26-Q-0055Combined Synopsis/Solicitation

Overview

Buyer

DEPT OF DEFENSE
Dept Of The Air Force
FA9000 AF NAF PO
JBSA LACKLAND, TX, 78236-9800, United States

Place of Performance

DWG, TX

NAICS

Computer Systems Design Services (541512)

PSC

Engineering And Technical Services (R425)

Set Aside

No set aside specified

Timeline

1
Posted
Mar 18, 2026
2
Last Updated
Apr 23, 2026
3
Submission Deadline
May 7, 2026, 9:00 PM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

Amendment 01 to RFQ# F41999-26-Q-0055 for PCI DSS Compliance Technical Support & Sustainment has been issued by the Department of the Air Force, Air Force Services Center (AFSVC). This amendment provides government responses to industry questions, updates key solicitation attachments, and extends the quotation submission deadline to 4:00 PM, CDT, Thursday, 7 May 2026.

Scope of Work

AFSVC seeks expert technical support to achieve a proactive, centrally governed security posture, ensure long-term verifiable PCI DSS compliance, and empower local personnel for self-sufficient operation. The effort is structured into three phases and option years:

  • Phase 1: Conduct a technical gap analysis and develop a solution strategy, including tool recommendations (SIEM, DLP, MFA), integration into a reporting framework, cost analysis, and an implementation plan (target completion August 2026).
  • Phase 2: Support the deployment and integration of security tools and services, validate implemented controls, and provide gap analysis remediation.
  • Phase 3 & Option Years: Provide steady-state daily operations and flexible surge support for up to 30 installations, including monitoring, SOP development, 24/7 support, PCI DSS assessment preparation, and knowledge transfer/training.

The contractor will assist with SIEM co-management, collaborate with a Government-designated QSA firm (without performing QSA functions), and report suspected security incidents within one hour. The central repository for PCI data is Telos Xacta.360 and Xacta.io.

Contract Details

  • Type: Firm-Fixed Price (FFP) Request for Quote (RFQ).
  • Duration: One (1) base year with four (4) one-year options, for a potential total of five (5) years.
  • Set-Aside: None. This is a Nonappropriated Fund (NAF) purchase; Federal Acquisition Regulation (FAR) rules do not apply.
  • Place of Performance: Primarily JBSA Lackland, TX, with on-site support for up to 30 installations. Remote work is authorized.
  • Payment: By NAF Purchase Card (Visa) within 30 days of receipt of proper invoice and NAFI acceptance.

Submission & Evaluation

Quotes are due by 4:00 PM, CDT, Thursday, 7 May 2026. Submissions must be in Adobe PDF format via email to whitney.ward.1@us.af.mil and valerie.baltimore@us.af.mil. Required documents include:

  • Price Quote along with a technical response (Contractor Statement of Work - CSOW) demonstrating understanding of the Statement of Objectives (SOO).
  • Confirmation of acceptance or exceptions to NAF Standard Clauses (30 May 2025).
  • Confirmation of acceptance or disagreement to Contract Admin Data (ATCH 08).
  • Past Performance Information (PPI) for the prime contractor (minimum three references within the last five years) and any subcontractors/teaming partners.

Quotes must remain valid for a minimum of 180 calendar days. Award will be made on a Lowest Price Technically Acceptable (LPTA) basis, evaluating the CSOW/Technical Solution, Past Performance (both Acceptable/Unacceptable), and Cost/Price (for realism, balance, and reasonableness). The government may require an oral presentation from the LPTA-deemed contractor.

Key Clarifications & Notes

This amendment replaces the original RFQ, ATCH 01 (Instructions to Contractors), and ATCH 06 (Evaluation Factors - LPTA) with updated versions dated April 20, 2026. Offerors must acknowledge receipt of this amendment in their final quotation package. Tier 1 security clearance is required for personnel.

People

Points of Contact

Files

Files

Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download

Versions

Version 4
Combined Synopsis/Solicitation
Posted: Apr 23, 2026
View
Version 3Viewing
Combined Synopsis/Solicitation
Posted: Apr 20, 2026
Version 2
Combined Synopsis/Solicitation
Posted: Apr 16, 2026
View
Version 1
Combined Synopsis/Solicitation
Posted: Mar 18, 2026
View