Request for Information: Information Assurance Compliance Support Services
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Department of Homeland Security (DHS) Science & Technology (S&T) Directorate is conducting a Request for Information (RFI) for Information Assurance Compliance Support Services. This RFI seeks industry capabilities and experience to support S&T's IT systems with compliance, testing, tracking, and managing cyber-related mandates. Responses are due by February 17, 2026, at 10:00 a.m. EST.
Purpose
This RFI is for market research and planning purposes only, aiming to gather information from qualified sources regarding their ability to provide Information Assurance (IA) and compliance support. It is not a solicitation, and the government is not obligated to issue a formal contract. The DHS S&T CIO Office requires support for approximately 35 distinct IT Systems and 2500 endpoints, covering mandates like FISMA, Executive Orders, and OMB memorandums.
Scope of Interest
The government is interested in capabilities related to the draft Statement of Work (SOW) for IA Compliance Support, which includes:
- Program Management Support
- Compliance Services: POA&M oversight, system security reporting, inventory maintenance, DHS IT security policy development, CISO support, IT Security Review and Assistance Programs, Security Assessment and Authorization (A&A) per NIST SP 800-37, and vulnerability evaluation.
- Information System Security Officer (ISSO) Services
- Information System Security Manager (ISSM) Services
- Security Operations Center (SOC) Services: 24x7x365 monitoring, incident triage, vulnerability management.
- Zero Trust Architecture (ZTA) Services: Implementation, modernization, and program support.
Key Information Requested
Respondents should address their capabilities and experience in:
- Implementing FedRAMP baselines for cloud systems (NIST SP 800-53, 800-37).
- Identifying knowledge, skills, qualifications, and certifications for ISSM and Zero Trust/SOC personnel.
- Supporting Zero Trust Framework implementation in federal environments.
- Developing performance metrics and reporting for cyber mandates.
- Implementing emerging technologies and continuous improvement in cybersecurity programs.
- Managing a Project Management Office (PMO) Level III.
Submission Details
- Deadline: February 17, 2026, 10:00 a.m. EST.
- Format: Microsoft Office applications, 12-point Times New Roman font.
- Length: Maximum eight (8) pages, including a cover letter.
- Cover Letter: Must include company information, socio-economic status, recommended NAICS code, points of contact, and answers to the six questions.
- Additional Information: Identify interest in prime/subcontracting roles, teaming arrangements, and existing Best-in-Class (BIC) vehicles.
- Email: Danette.Williams@hq.dhs.gov and Marco.Macherelli@hq.dhs.gov.
Contract & Timeline
- Type: Request for Information (RFI) / Special Notice.
- Set-Aside: None specified; responses from all interested sources are encouraged.
- Anticipated Contract Type (from Draft SOW): Time and Material (T&M) for base and surge support.
- Anticipated Period of Performance (from Draft SOW): 5 years (July 1, 2026, to June 30, 2031).
- Security Requirements (from Draft SOW): Contractor access up to Top Secret/SCI, Single Scope Background Investigation, Key personnel SECRET Clearance.
- Published: February 12, 2026.
Additional Notes
An Industry Day may be held, and the government may conduct one-on-one meetings with respondents. Previous related work includes a BPA with SiloSmashers, Inc. and a Task Order with APF Technology, LLC. This RFI is associated with previous RFIs under BPA 70RSAT22A00000001, which expires July 31, 2026.