Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 30 at 2:00 PM EDT

Register Free →

Cybersecurity and Information Assurance

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

This subcontract for Cybersecurity and Information Assurance supports the Defense Health Agency by securing data hosting environments for prime contractors on OBHAT/BHAS projects. The scope of work involves implementing critical security controls for data-at-rest and data-in-transit through the use of IAM systems, encryption software, and SIEM tools. The provider is responsible for delivering continuous monitoring reports and achieving the Security Authorization to Operate. The contract requires strict adherence to HIPAA, NIST SP 800-53, and DoD Impact Level certifications to ensure full regulatory compliance. Performance will take place in Frederick, and the opportunity is categorized under NAICS code 541519. Responses are due by October 26, 2026.

General Info

Cybersecurity subcontract for DHA data hosting, requiring NIST/HIPAA compliance by October 26, 2026.

NAICS

541519 - Other Computer Related Services

Place of Performance

Frederick, MD, USA

Set-Aside

NONE

Documents

This scope was carved out of HT942726RFI707.

The full solicitation package (2 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

RFI for Data Hosting, Integration, and Sustainment Support for the OBHAT/BHAS Program

AI Contract Breakdown

Uniform Contract Format

No documents to break down

The breakdown needs solicitation documents. None were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → Defense Health Agency
ContactsNo contacts available
OfficeN/A
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Secures the data hosting environment for prime contractors on Defense Health Agency (DHA) OBHAT/BHAS projects. Implements security controls for data-at-rest and data-in-transit using SIEM tools, encryption software, and IAM systems. Ensures compliance with NIST SP 800-53, HIPAA, and DoD Impact Level (IL) certifications. Delivers Security Authorization to Operate (ATO) and continuous monitoring reports.

Similar Contracts

Same NAICS industry code

NAICS: 541519
New
Federal
Endpoint Security Event Management
Solicitation # 842674854
The Defense Information Systems Agency (DISA) is conducting market research through a Sources Sought notice to identify qualified sources for an Endpoint Security Event Management System to support Project Manager Command & Control Infrastructure and Network Enterprise Technology Command. The requirement centers on delivering a comprehensive cybersecurity solution for the Department of War Information Network – Army, with a focus on enabling Zero Trust Architecture through Endpoint Detection and Response, Security Incident and Event Management, Comply to Connect, asset management, advanced analytics, network visualization, and integration with the Army’s Big Data Platform and Identity Credentialing and Access Management services. The system must leverage Microsoft Defender for Endpoint and Elastic Defend to manage EDR across Army Unified Directory Services endpoints, enforce default-deny application controls, automate malware response, restrict removable media, collect behavioral telemetry, ingest STIX/TAXII threat data, and prepare infrastructure for post-quantum cryptography migration. The solution must support global fielding across CONUS and OCONUS locations, including contingency theaters and hazardous duty areas, with simultaneous on-prem and cloud deployments. The contract is anticipated to be a single-award IDIQ with a ceiling value of $850 million and a potential performance period of up to ten years, consisting of a two-year base period followed by eight one-year option periods beginning March 29, 2027. Primary performance will be centered at Fort Huachuca, Arizona, with oversight from Aberdeen Proving Ground, Maryland, and support delivered through four regional cyber centers covering Army installations worldwide. All contractors must hold a Top Secret facility clearance and be capable of providing personnel with at least Secret-level clearances, with the ability to assign Top Secret-cleared individuals for mission-critical tasks. Compliance with DoD cybersecurity standards including RMF, STIGs, IAVAs, and Authorization to Operate is mandatory. Subcontracting is limited under FAR 52.219-14, and companies must demonstrate small business status if applicable, adhere to the NAICS code 541519 with a $34 million size standard, and list qualifying prime contract vehicles such as ENCORE III, SETI, GSA OASIS, ALLIANT II, VETS II, STARS III, MAS, NIH CIO-SP4, and NASA SEWP V. Responses must be submitted via email by 12:30 PM EDT on June 29, 2026, and include business information, CAGE code, socio-economic designation, and a capabilities
It Contracting Division - PL84

POSTED

about 15 hours ago

DEADLINE

in 14 days
View Details
NAICS: 541519
New
Federal
Digital Forensics Examiner Services
Solicitation # N0018927Q00010
Navsup Flt Logistics Ctr Norfolk is seeking sources for a single firm, fixed price contract to provide continued Digital Forensics Examiner Support services for the Naval Criminal Investigative Service NCIS Cyber Directorate. The requirement involves providing certified personnel to conduct complex, non-destructive evaluations of target computer systems and detailed forensic examinations of mobile devices and digital media used in criminal investigations or intelligence gathering. The primary objective is to protect Department of Navy personnel, assets, and infrastructure from criminal, terrorist, and foreign intelligence threats. This opportunity is intended to be competed among certified 8(a) Program Participants under NAICS code 541519. The contractor must provide all necessary equipment, supplies, and tools, including mobile phones and cellular service for examiners. Performance is distributed across multiple locations, including Camp Pendleton, California, Camp Lejeune, North Carolina, Naval Station Mayport, Florida, and MCAS Miramar, California, with potential for both CONUS and OCONUS travel. Key deliverables include monthly status reports, non-destructive evaluations, and forensic examinations of cyber cases. Personnel must be compliant with SECNAV M-5239.2 cybersecurity qualifications and maintain valid passports and driver's licenses. The contractor is also required to maintain specific automobile liability insurance and adhere to the DoD Industrial Security Manual for handling classified materials as detailed in DD Form 254. Performance will be monitored via a Quality Assurance Surveillance Plan with a requirement that over 95 percent of deliverables be submitted timely and without rework.
Navsup Flt Logistics Ctr Norfolk

POSTED

about 15 hours ago

DEADLINE

in 7 days
View Details
NAICS: 541519
New
Federal
Travel Management Office (TMO) Travel Program (Defense Travel System (DTS) & Government Travel Charge Card (GTCC)) and Mail Management Center (MMC) Technical and Administrative Support Services.
Solicitation # N0003026JV001
Pae Strategic Systems Programs is conducting market research via a Sources Sought Notice to identify capable firms for a five-year Firm-Fixed-Price, Level-of-Effort contract spanning from May 10, 2027, to May 9, 2032. The requirement is a total small business set-aside under NAICS 541519, focused on providing technical and administrative support for the Travel Management Office (TMO) and the Mail Management Center (MMC). Primary services include Defense Travel System (DTS) profile and routing management, Government Travel Charge Card (GTCC) administration, travel auditing and analysis, help desk operations, and official mail handling. The primary place of performance is the SPHQ at the Washington Navy Yard in District of Columbia. Key personnel must possess a minimum of a favorable Tier 1 background investigation to handle personally identifiable information and access government systems such as CitiManager and Visa IntelliLink. The contractor is responsible for maintaining strict confidentiality and privacy act compliance, as well as ensuring no organizational conflicts of interest exist. The government is requesting white paper capability statements not exceeding five pages to assess industry capacity based on recent performance in travel and mail management. This notice is for market research purposes only and does not constitute a formal solicitation or a promise of a future contract award.
Pae Strategic Systems Programs

POSTED

about 15 hours ago

DEADLINE

in 17 days
View Details

More opportunities from Department Of Defense → Defense Health Agency

Same awarding agency

NAICS: 561720
New
Federal
European Healthcare Environmental Cleaning (HEC) Services
Solicitation # HT9406-26-R-E006
The Defense Health Agency (DHA) is soliciting proposals for a single-award, firm-fixed-price Indefinite Delivery/Indefinite Quantity (ID/IQ) contract to provide highly specialized Healthcare Environmental Cleaning (HEC) and Linen Distribution Services at various Military Treatment Facilities (MTFs) in Germany. The scope of work includes maintaining aseptic environments for clinical and surgical spaces through specialized cleaning, disinfection, linen laundry, and regulated medical waste collection. Performance locations encompass Landstuhl Regional Medical Center (LRMC) and its outlying clinics, Medical Department Activity – Bavaria (MEDDAC-B) in Vilseck and its associated clinics, and the Rhine Ordnance Medical Center (ROBMC). The anticipated ordering period runs from May 15, 2027, to May 14, 2032, which includes a 90-day phase-in period. The contract has a maximum value of approximately $99.99 million. The selection process will utilize a competitive tradeoff source selection method, where performance confidence is significantly more important than price. Evaluation will occur in three sequential phases: Technical Capability, Performance Confidence, and Price. To be considered technically acceptable, offerors must demonstrate at least three consecutive years of healthcare cleaning experience within the last five years and provide detailed cleaning procedures that meet industry and regulatory standards, such as ISO 9001:2015 and ISO 14001. Key personnel, specifically Executive Managers, must be proficient in both English and German. Proposals must be submitted via email by the deadline of October 15, 2026, and successful offerors will be required to implement a comprehensive training program covering infection control, safety, and asbestos awareness.
Janitorial Services

POSTED

about 15 hours ago

DEADLINE

in 19 days
View Details
NAICS: 541611
New
Federal
Program Management Support Services Bridge 4
Solicitation # PANDHA-26-P-0000-046996
The Defense Health Agency intends to award a sole source, firm-fixed-price non-personal services contract to Deloitte Consulting, LLP for Program Management support services. This bridge contract consists of a three-month base period running from November 14, 2026, to February 13, 2027, with three subsequent three-month option periods extending through November 13, 2027. The contractor will provide comprehensive support to the Assistant Director for Health Care Administration and Operations, the Portfolio Acquisition Executive for Medical Digital Solutions, and the J6 Risk Management Executive Division. Performance will take place primarily at the Defense Health Headquarters in Falls Church, Virginia, and Joint Base San Antonio Fort Sam Houston, Texas. The scope of work includes managing Integrated Product Teams, conducting research and analysis, and providing special project support. Key performance metrics require taskers to be disseminated within 24 hours of receipt, research reports delivered within five business days, and meeting minutes completed within two workdays. The contract mandates strict adherence to cybersecurity standards, including DoD IA requirements and NIST SP 800-171, with a requirement for no unmitigated high-severity vulnerabilities. Administrative requirements include the use of iRAPT for invoicing and the execution of DHA Form 49 Non-Disclosure Agreements for all personnel. While intended as a sole source award, the agency will consider capability statements or quotations from responsible sources submitted by 10:00 AM Eastern on October 12, 2026.
Administrative Management and General Management Consulting Services

POSTED

about 15 hours ago

DEADLINE

in 16 days
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 750+ contractors already using CLEATUS