PCI DSS Compliance Technical Support
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
Amendment 01 to RFQ# F41999-26-Q-0055 for PCI DSS Compliance Technical Support & Sustainment has been issued by the Department of the Air Force, Air Force Services Center (AFSVC). This amendment provides government responses to industry questions, updates key solicitation attachments, and extends the quotation submission deadline to 4:00 PM, CDT, Thursday, 7 May 2026.
Scope of Work
AFSVC seeks expert technical support to achieve a proactive, centrally governed security posture, ensure long-term verifiable PCI DSS compliance, and empower local personnel for self-sufficient operation. The effort is structured into three phases and option years:
- Phase 1: Conduct a technical gap analysis and develop a solution strategy, including tool recommendations (SIEM, DLP, MFA), integration into a reporting framework, cost analysis, and an implementation plan (target completion August 2026).
- Phase 2: Support the deployment and integration of security tools and services, validate implemented controls, and provide gap analysis remediation.
- Phase 3 & Option Years: Provide steady-state daily operations and flexible surge support for up to 30 installations, including monitoring, SOP development, 24/7 support, PCI DSS assessment preparation, and knowledge transfer/training.
The contractor will assist with SIEM co-management, collaborate with a Government-designated QSA firm (without performing QSA functions), and report suspected security incidents within one hour. The central repository for PCI data is Telos Xacta.360 and Xacta.io.
Contract Details
- Type: Firm-Fixed Price (FFP) Request for Quote (RFQ).
- Duration: One (1) base year with four (4) one-year options, for a potential total of five (5) years.
- Set-Aside: None. This is a Nonappropriated Fund (NAF) purchase; Federal Acquisition Regulation (FAR) rules do not apply.
- Place of Performance: Primarily JBSA Lackland, TX, with on-site support for up to 30 installations. Remote work is authorized.
- Payment: By NAF Purchase Card (Visa) within 30 days of receipt of proper invoice and NAFI acceptance.
Submission & Evaluation
Quotes are due by 4:00 PM, CDT, Thursday, 7 May 2026. Submissions must be in Adobe PDF format via email to whitney.ward.1@us.af.mil and valerie.baltimore@us.af.mil. Required documents include:
- Price Quote along with a technical response (Contractor Statement of Work - CSOW) demonstrating understanding of the Statement of Objectives (SOO).
- Confirmation of acceptance or exceptions to NAF Standard Clauses (30 May 2025).
- Confirmation of acceptance or disagreement to Contract Admin Data (ATCH 08).
- Past Performance Information (PPI) for the prime contractor (minimum three references within the last five years) and any subcontractors/teaming partners.
Quotes must remain valid for a minimum of 180 calendar days. Award will be made on a Lowest Price Technically Acceptable (LPTA) basis, evaluating the CSOW/Technical Solution, Past Performance (both Acceptable/Unacceptable), and Cost/Price (for realism, balance, and reasonableness). The government may require an oral presentation from the LPTA-deemed contractor.
Key Clarifications & Notes
This amendment replaces the original RFQ, ATCH 01 (Instructions to Contractors), and ATCH 06 (Evaluation Factors - LPTA) with updated versions dated April 20, 2026. Offerors must acknowledge receipt of this amendment in their final quotation package. Tier 1 security clearance is required for personnel.