This Solicitation opportunity from Cherokee Nation was posted on June 1, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.
Cherokee Nation Entertainment FY27 Annual PCI Assessment *Extended to 6/12/2026
Contract Overview
Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.
Active Opportunities Like This One
AI Contract Overview
Cherokee Nation Entertainment is soliciting proposals from PCI Security Standards Council–accredited Qualified Security Assessor companies to perform a comprehensive PCI DSS Gap Assessment and guide the organization through formal certification under PCI DSS v4.0.1. The solicitation, identified as Procurement #164615, was posted on June 1, 2026, with a strict deadline for responses on June 5, 2026, at 3 PM CST. Proposals must be submitted exclusively via email to bids@cnent.com with the exact subject line CNE164615; submissions in person, by mail, or with content in the email body will be rejected. The work is to be performed in Oklahoma and involves validating the Cardholder Data Environment scope, evaluating compliance with specific PCI DSS v4.0.1 requirements including 6.4.3 and 11.6.1, conducting interviews with subject matter experts, assessing third-party dependencies, and leading onsite or remote testing to produce a final Report on Compliance or Self-Assessment Questionnaire/Attestation of Compliance. Deliverables include a scoping memo, gap assessment report, risk matrix, remediation plan, readiness validation summary, and the final signed RoC/AoC, all of which must meet CNE’s brand standards and be delivered within a defined timeline that is a material consideration for award. The evaluation will consider the bidder’s expertise and credentials as a QSA, methodology quality, ability to meet timelines, proposed team strength, and overall value, with no numeric weights assigned. Subcontractors may be evaluated for qualifications and experience, and the bidder must submit a detailed subcontractor plan identifying Indian-owned status and portion of work to be outsourced. Bidders must demonstrate active QSA accreditation, provide references from prior PCI engagements, especially within the gaming industry, and include itemized pricing for gap assessment, remediation, certification, and travel. Insurance requirements are stringent: commercial general liability coverage of at least $1 million per occurrence on an occurrence basis, automobile liability, and workers compensation with employer’s liability of at least $1 million, all of which must name CNE and its affiliates as additional insureds with primary coverage and waiver of subrogation. The provider must also comply with GDPR, Gramm-Leach-Bliley Act, and CNE’s internal data security policies. The successful vendor must obtain necessary Cherokee Nation Gaming Commission licenses, pay a TERO fee of half of one percent of
General Info
Agency
NAICS
Place of Performance
OK, USASet-Aside
Timeline
Submission Closed
Organization & Contact Information
Full Description
Find Active Opportunities Like This
Get AI-powered intelligence on the opportunities still open
Every page of the solicitation package shredded into a compliance breakdown
AI-powered matching based on your capabilities and past performance
Competitor and incumbent history on the requirement
Automated alerts on amendments, Q&A deadlines, and award
Join 650+ contractors already using CLEATUS
