Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 16 at 2:00 PM EDT

Register Free →

Cybersecurity & Compliance Auditor

Active
State & Local

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The Cybersecurity and Compliance Auditor subcontract for the California Department of Cannabis Control involves performing security assessments and penetration testing for prime contractors. The selected provider will be responsible for verifying SOC 2 Type II compliance, auditing FIPS 140-3 cryptography, and utilizing SIEM tools to monitor system events for potential attacks. Additionally, the role requires conducting security incident investigations and applying expertise in OWASP standards to ensure robust system security. Key deliverables for this engagement include comprehensive penetration test results, a detailed Security Plan, and formal Security Audit reports. The opportunity was posted on June 19, 2026, with a response deadline of April 14, 2027. This subcontract falls under NAICS code 541519 and is managed through the California state procurement system.

General Info

Cybersecurity auditor providing penetration testing and compliance audits for California Department of Cannabis Control.

Agency

California Department of Cannabis ControlView Agency

NAICS

541519 - Other Computer Related ServicesView NAICS

Place of Performance

CA, USA

Set-Aside

NONE

Documents

This scope was carved out of RFP 2026-001.

The full solicitation package (6 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

Cannabis Integration System (CSI) - DCC

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyCalifornia Department of Cannabis Control
ContactsNo contacts available
OfficeN/A
Organization / Agency
California Department of Cannabis Control
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Performs security assessments and penetration testing for prime contractors on Department of Cannabis Control (DCC) projects. Verifies SOC 2 Type II compliance, audits FIPS 140-3 cryptography, and monitors system events for attacks using SIEM tools. Conducts security incident investigations. Requires expertise in OWASP standards. Delivers penetration test results, a Security Plan, and Security Audit reports.

Similar Contracts

Same NAICS industry code

NAICS: 541519
New
Federal
IRS Audio-Visual (AV) and Video Teleconferencing (VTC) Enterprise Systems Integration, Support, and Maintenance Master IDIQ
Solicitation # 205AE9-26-Q-00053
The Department of the Treasury, Internal Revenue Service (IRS) is soliciting proposals to establish up to three Multiple-Award Indefinite-Delivery Indefinite-Quantity (IDIQ) contracts for the integration, support, and maintenance of Audio-Visual (AV) and Video Teleconferencing (VTC) enterprise systems. This 100% Total Small Business Set-Aside under NAICS 541519 has a total maximum ordering value of $24,746,987.96 over a five-year lifecycle, estimated from March 1, 2027, to February 29, 2032. The scope includes turn-key solutions for equipment procurement, installation, staging, maintenance, and technology refreshes for approximately 410 conference rooms nationwide. All solutions must strictly align with the IRS enterprise ecosystem, including Poly/HP, Crestron, Q-SYS, AVer, NVX, and Microsoft Teams Rooms. The procurement follows a strict two-phase submission process. Phase 1 is an administrative gate focusing on brand authorizations and staffing compliance, with a revised closing date of September 16, 2026. Only offerors who pass this binary screen will be invited to Phase 2, which requires a blinded technical narrative, past performance records, and a native Excel pricing matrix, with a revised closing date of October 13, 2026. Awards will be based on a Best Value Trade-Off, where technical factors are significantly more important than price. Key requirements include compliance with FISMA, NIST SP 800-53, and ADA accessibility standards. Personnel must hold a favorably adjudicated Moderate Risk Background Investigation (MBI) clearance. The contract utilizes Firm-Fixed-Price (FFP) task orders, and invoicing is mandatory via the Invoice Processing Platform (IPP). Bidders must adhere to strict formatting and blinding protocols for Volume II to ensure a fair evaluation and must utilize the revised pricing and staffing workbooks provided in Amendment 0001.
It Strategy And Modernization

POSTED

about 15 hours ago

DEADLINE

in 7 days
View Details

More opportunities from California Department of Cannabis Control

Same awarding agency

NAICS: 541720
SLED
RFP 26-001 Economic Impact Assessment Services
Solicitation # 26-001
The California Department of Cannabis Control is soliciting a consulting contractor to provide economic impact assessment and advisory services from November 2, 2026, through June 30, 2029, with a potential one-year extension. The primary objective is to evaluate the economic effects of regulatory actions, legislation, market conditions, and cannabis tax structures. Key deliverables include performing 10 to 12 annual standardized regulatory impact assessments, analyzing statutory changes to the Medicinal and Adult-Use Cannabis Regulation and Safety Act, providing annual California cannabis market assessments, and delivering a specialized Cannabis Tax Report per AB 564. The contractor must utilize econometric modeling and ensure all work complies with specific Government and Business and Professions Codes. Proposals are evaluated based on experience with California state regulatory policies, statutory change analysis, and survey and data management, with the lowest average cost receiving maximum points. The contract is managed through individual Work Order Authorizations that define specific completion criteria and locations. Requirements for bidders include certification of a commercially useful function for small businesses, compliance with the Darfur Contracting Act, and adherence to the Americans with Disabilities Act. Payments are based on actual expenditures incurred, with invoices submitted monthly in triplicate. The Department reserves the right to disqualify bidders who fail to disclose the use of Generative AI in their proposals.
Research and Development in the Social Sciences and Humanities

POSTED

16 days ago

DEADLINE

in 21 days
View Details
NAICS: 518210
SLED
Cannabis Integration System (CSI) - DCC
Solicitation # RFP 2026-001
The California Department of Cannabis Control is soliciting proposals for the Cannabis Integration System (CSI) project to consolidate two separate Accela platform instances, the Cannabis Licensing, Enforcement, and Reporting (CLEaR) system and the Cultivation Licensing System (CLS), into one unified SaaS solution. This integration aims to improve operational efficiency and regulatory oversight for all cannabis activities, including licensure, compliance, and enforcement. The project will be executed in two phases, beginning with the migration of one legacy system followed by the remaining system, utilizing agile Scrum practices. The contract has a maximum term of five and a half years, with the possibility of two additional one-year extensions for maintenance and operations, and a six-month extension for implementation. The solicitation is a fixed-price, deliverable-based contract where award is based on a value-effective solution. Evaluation is weighted heavily toward cost at 40 percent, with the remaining points allocated to the bidder's narrative response, references, and qualifications. Bidders must meet mandatory pass/fail gates regarding administrative requirements and key personnel qualifications. High security standards are required, including compliance with NIST, FedRAMP, and CJIS, and contractors must maintain cyber liability insurance of five million dollars per occurrence. Performance is measured through formal state acceptance of deliverables, and the contractor is required to provide transition assistance for thirty to ninety days upon contract expiration.
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services

POSTED

3 months ago

DEADLINE

in 7 months
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 650+ contractors already using CLEATUS