Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity and Compliance Management

Active
State & Local

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract requires ongoing cybersecurity and compliance management services focused on maintaining adherence to NIST SP 800-53 standards, sustaining authority to operate status, implementing robust encryption protocols, and ensuring effective incident response capabilities for payment systems. These responsibilities are critical to safeguarding sensitive financial data and ensuring regulatory alignment across all operational aspects of the systems under management. The work must be performed continuously to uphold security controls, detect and mitigate threats promptly, and respond to breaches in a manner that minimizes disruption and meets state and federal requirements. This subcontract is issued by the California State Controller’s office with a posted date of July 31, 2026, and a response deadline of September 9, 2026. The North American Industry Classification System code 541612 indicates the service falls under computer facilities management services, signaling a need for technical expertise in securing and managing hosted or cloud-based financial infrastructure. The place of performance and point of contact details are not specified, suggesting the work may be performed remotely or across multiple locations within California. All deliverables must align with the state’s cybersecurity framework and support uninterrupted, secure payment processing operations.

General Info

Provide ongoing cybersecurity and compliance services for California payment systems per NIST SP 800-53 standards.

Agency

California → State ControllerView Agency

NAICS

541612 - Human Resources Consulting ServicesView NAICS

Place of Performance

CA, USA

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyCalifornia → State Controller
ContactsNo contacts available
OfficeN/A
Organization / Agency
California → State Controller
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Maintain NIST SP 800-53 compliance, ATO status, encryption, and incident response for payment systems.

Similar Contracts

Same NAICS industry code

NAICS: 541612
New
SLED
Cybersecurity Compliance Support (Third-Party Assessment Provider)The contract engages a third-party provider to deliver cybersecurity validation services for financial institutions by administering and certifying the Cyber Risk Assessment Questionnaire as an alternative to traditional SOC-2 reports. This arrangement shifts the compliance burden from standardized auditing frameworks to a specialized, tailored assessment process designed to evaluate and validate the cybersecurity postures of financial entities. The provider is responsible for ensuring the integrity, consistency, and regulatory alignment of the questionnaire throughout its deployment, maintaining rigorous standards for certification without reliance on established external audit reports. The agreement is structured as a subcontract under the NAICS code 541612, targeting cybersecurity consulting and related services, with a response deadline of June 1, 2028, and a posted date of July 31, 2026. It is affiliated with the Finance agency in California, though specific office locations and point of contact details are not provided. The scope emphasizes replacing SOC-2 validation with a proprietary assessment framework, implying the need for the provider to establish credible, audit-ready methodologies that financial institutions can confidently use for regulatory and partner compliance purposes. The contract does not specify set-aside status or geographic performance constraints beyond the broader jurisdiction of California.
Finance

POSTED

1 day ago

DEADLINE

in almost 2 years
View Details
NAICS: 541612
New
SLED
Equal Employment Opportunity (EEO) and Contractor Certification ManagementThe contract requires management and administration of key certifications essential for public procurement compliance, including Equal Employment Opportunity (EEO) requirements, a non-collusion affidavit, E-Verify verification, conflict of interest disclosures, and a contingent fee warranty. These certifications must be maintained and submitted by the contractor to ensure adherence to federal and state regulations governing fair hiring practices, transparency in bidding, and employee verification. The obligations are specific to subcontracting under the North American Industry Classification System code 541612, which pertains to management consulting services. All certifications must remain current throughout the contract period, and failure to comply may result in disqualification or penalties. The contract opportunity was posted on July 31, 2026, with a response deadline of August 20, 2026, and is associated with the Finance agency in South Carolina. Although specific office or performance locations are not provided, the requirement applies to all activities under this subcontract, regardless of geographic scope. The contracting entity operates through an online procurement portal, and all submissions and documentation must be managed in accordance with the specified compliance frameworks. There is no set-aside designation, meaning the opportunity is open to all qualified contractors without preference based on size, ownership, or other categories, but full adherence to the listed certifications remains mandatory for eligibility.
Finance

POSTED

1 day ago

DEADLINE

in 18 days
View Details

More opportunities from California → State Controller

Same awarding agency

NAICS: 518210
New
SLED
Customer Portal Development and SupportThe contract titled Customer Portal Development and Support calls for the design, development, and ongoing maintenance of a secure electronic payment portal capable of handling an unlimited number of payees. The system must ensure robust security measures to protect sensitive financial data and facilitate reliable, efficient payment processing for diverse recipients. This is a subcontract under NAICS code 518210, focused on data processing and related services, with the State Controller of California as the overseeing agency. The portal must be scalable, user-friendly, and compliant with state and federal standards for data integrity and confidentiality. The solicitation was posted on July 31, 2026, with a response deadline of September 9, 2026, and is open for bids through the CalEProcure website. There is no specified set-aside designation, meaning the contract is open to all qualified subcontractors regardless of business size or category. The place of performance and office address details are not provided, suggesting that work may be performed remotely or at the contractor’s location. No point of contact is listed, so potential bidders should rely on the official portal for communications and updates. The project requires long-term support, indicating an expectation of sustained performance and system updates well beyond initial deployment.
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services

POSTED

1 day ago

DEADLINE

in about 1 month
View Details
NAICS: 522299
New
SLED
Global Digital Payment ServicesThe contract seeks to establish a global digital payment infrastructure capable of facilitating international electronic disbursements to a minimum of 70 countries, ensuring seamless multi-currency processing and strict adherence to global compliance standards. This subcontract under the State Controller’s office in California will enable secure, efficient, and scalable cross-border financial transactions, supporting government and institutional payments with currency flexibility and regulatory alignment across diverse jurisdictions. The system must integrate robust compliance mechanisms to meet anti-money laundering, sanctions screening, and data privacy requirements in each target country. The solicitation is open for responses until September 9, 2026, and is classified under the NAICS code 522299 for other financial investment activities. It will be performed in alignment with California’s operational requirements, though specific performance locations are not defined. Interested parties must submit proposals by the stated deadline through the official procurement portal, with no set-aside provisions or small business preferences indicated. The initiative aims to modernize the state’s disbursement capabilities for international obligations, prioritizing reliability, transparency, and interoperability with global financial networks.
International, Secondary Market, and All Other Nondepository Credit Intermediation

POSTED

1 day ago

DEADLINE

in about 1 month
View Details
New
SLED
RFP - EDIS90126 Electronic Payment Services
Solicitation # EDIS90126
The State Controller’s Office of California is seeking a contractor to provide comprehensive Electronic Payment Services through Solicitation EDIS90126, with proposals due by September 9, 2026. The scope encompasses processing a wide array of electronic disbursements including Electronic Funds Transfer (EFT) transactions, digital checks, physical paycards, returned item handling, and addenda record processing, serving all state agencies under the Disbursements Bureau. The contract, structured as a fixed-price arrangement with an estimated value of $8 million over a six-year base term, includes two optional two-year extensions, though pricing for those options is not specified. Performance is strictly limited to California, with all services required to be delivered and supported within the state, ensuring compliance with California laws regarding data confidentiality, accessibility, and civil rights. The contractor must support high-volume transactions—over 500 million payment items annually—with guaranteed 24-hour turnaround for returned items and same-day or next-business-day fund availability through integration with ACH, wire transfers, or ERP systems. Proposals must adhere to rigid submission criteria including a 100-page narrative response, a 70-page work plan, and all 20 mandatory attachments, such as security disclosures, DVBE and CSBE certifications, GenAI disclosure, confidentiality agreements, and detailed cost worksheets. Evaluation follows a Lowest Price Technically Acceptable (LPTA) model, where proposals must score a minimum of 1,130 out of 1,570 possible technical points—earned through narrative depth, interview performance, security readiness (Green/Yellow/Red flag ratings), and organizational qualifications—before cost becomes the deciding factor. Security requirements are extensive, mandating FIPS-compliant encryption for all data in transit and at rest, adherence to NIST SP 800-53 Rev. 5, FedRAMP or StateRAMP compliance, and ATO validation, with all systems hosted exclusively within the continental United States. All payment cards must be issued under major networks like Visa or Mastercard, individually labeled with recipient names, and delivered through neutral packaging with real-time tracking. Invoicing is monthly, submitted via email to ADMAP@sco.ca.gov on contractor letterhead with full line-item detail, and payment remittance is processed by the State Controller’s Departmental Accounting Office. No federal contract clauses are formally incorporated; instead, administrative and state-specific requirements govern the agreement, with no security clearances required for personnel but strong emphasis on

POSTED

1 day ago

DEADLINE

in about 1 month
View Details