Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 16 at 2:00 PM EDT

Register Free →

Cybersecurity and Penetration Testing

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

This subcontract focuses on providing cybersecurity and penetration testing services for BLS systems to support manufacturers pursuing TSA QPL certification. The primary objective is to conduct Cooperative Vulnerability Penetration Assessments using specialized tools to verify that systems meet the rigorous security standards established by the Transportation Security Administration and the Department of Homeland Security. The selected provider will be responsible for delivering comprehensive CVPA reports and detailed vulnerability remediation documentation. This opportunity is managed under NAICS code 541512, with a response deadline of October 15, 2026.

General Info

Cybersecurity and penetration testing for BLS systems to achieve TSA QPL certification.

Agency

Department Of Homeland Security → Transportation Security AdministrationView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

Not specified

Set-Aside

NONE

Documents

This scope was carved out of 70T04026QPL7672BLS001.

The full solicitation package (4 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

Bottle Liquid Scanner (BLS) Qualified Products List (QPL)

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Homeland Security → Transportation Security Administration
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Homeland Security → Transportation Security Administration
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Performs vulnerability assessments and penetration testing for BLS systems for manufacturers seeking TSA QPL certification. Conducts Cooperative Vulnerability Penetration Assessments (CVPA) using specialized cybersecurity testing tools to ensure compliance with TSA and DHS security standards. Delivers the CVPA Report and vulnerability remediation documentation.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
Utilization Management Technical Solutions RFI
Solicitation # utilization-management-technical-solutions-rfi
Noridian Healthcare Solutions, LLC is issuing a Request for Information (RFI) to identify qualified technology providers and strategic partners capable of delivering configurable technical solutions for end-to-end utilization management (UM) workflows. The objective is to support federal and state healthcare programs by evaluating medical necessity, appropriateness of care, provider compliance, and program integrity. The scope of the RFI covers a broad range of capabilities, including clinical operations such as intake, prior authorization, and appeals, as well as workflow automation, business rules, provider engagement portals, and advanced intelligence including AI. Technical requirements emphasize interoperability through HL7, FHIR, and X12 standards, as well as robust security, compliance, and data management frameworks. This opportunity is open to a wide range of small business categories, including SDB, WOSB, HUBZone, VOSB, and SDVOSB, under NAICS code 541512. Interested respondents must notify Noridian via email to gain access to the Agiloft Contract Management System, where all correspondence and the final response must be submitted. Responses are required to be submitted using a specific templated spreadsheet by September 21, 2026. Noridian will comprehensively review the submissions and may invite selected providers to participate in solution demonstrations during the fourth quarter of 2026. Respondents must certify that they are not currently debarred or suspended from government transactions and possess no conflicts of interest.
Noridian Healthcare Solutions, LLC

POSTED

about 11 hours ago

DEADLINE

in 12 days
View Details
NAICS: 541512
New
Federal
Portfolio Acquisition Executive, Medical Digital Solutions, (PAE MDS) End User Services (EUS) Area of Interest Application, Workflow, Adoption, and Change Support (AWACS)
Solicitation # HT003826SC005-AOI0001
The Defense Health Agency's Portfolio Acquisition Executive, Medical Digital Solutions (PAE MDS) is seeking a partner for the End User Services (EUS) Area of Interest (AOI) #1, titled Application, Workflow, Adoption, and Change Support (AWACS). This initiative aims to transition from labor-intensive support contracts to a unified, outcome-based delivery model focusing on three specific service pillars: Application and Clinical Workflow Support, Enablement and Adoption Services, and Change, Communications, and Trust. The goal is to provide flexible, tailored IT solutions for 11 distinct user domains, ranging from point-of-care clinicians to system administrators, while integrating seamlessly with the broader EUS ecosystem and the enterprise ITSM Service Desk. The anticipated contract structure consists of a 12-month base period with four 12-month options, utilizing either a FAR-based contract or a Prototype Project Other Transaction Agreement. The procurement process is divided into two phases, with Phase 1 requiring the submission of a whitepaper by September 14, 2026. Evaluation for this phase is based on a Go/No-Go rating focusing on continuity and transition risk, as well as the quality of proposed Service Level Agreements (SLAs) and Experience Level Agreements (XLAs). Successful offerors will advance to Phase 2, which requires detailed pricing and staffing plans. Key requirements include maintaining a Secret clearance for personnel on day one, adhering to NIST SP 800-171 and CMMC standards, and ensuring all custom deliverables remain government property. The scope of work encompasses remote SME support, defect tracking, role-based training with CME accreditation, and the implementation of microlearning tools to reduce clinician burnout. Virtual work is strongly encouraged, though some activity may occur at OCONUS locations.
Defense Health Agency

POSTED

about 15 hours ago

DEADLINE

in 5 days
View Details
NAICS: 541512
New
Federal
Wideband Remote Monitoring Sensor (WRMS) Enhancement and Sustainment (E&S)
Solicitation # 832675541
The Department of Defense, through the IT Contracting Division PL83, has issued a sources sought notice under solicitation 832675541 to identify capable small and large businesses for the Wideband Remote Monitoring Sensor Enhancement and Sustainment project. This effort supports the Project Officer Wideband Control mission to acquire and install strategic satellite network control and planning systems for the Defense Satellite Communications System and Wideband Global Satellite Communications. The primary objective is to sustain the fielded version of WRMS v3.x, which utilizes a hardware agnostic interface and micro-services architecture to identify and resolve anomalies by comparing planned versus actual radio frequency measurement data. The forthcoming contract will focus on sustaining current software, implementing enhancements based on user feedback, and addressing software backlog items. The scope of work includes program management, systems engineering, software development using Agile and CI/CD methodologies, cybersecurity compliance, and logistics support. The anticipated contract structure consists of a one-year base period with four option years, with performance taking place in Colorado Springs, Colorado. Interested vendors must operate under NAICS code 541512 and maintain a Secret facility clearance to be eligible for this requirement.
It Contracting Division - PL83

POSTED

about 15 hours ago

DEADLINE

in 14 days
View Details
NAICS: 541512
New
SLED
Office of Workforce Development Case Management System
Solicitation # STATE 0000000437SL
The State of Missouri, through the Office of Administration and the Department of Higher Education and Workforce Development, is soliciting proposals for a Case Management/Learning Experience (CM/LX) Solution. This Blanket Purchase Agreement aims to replace or integrate with existing systems to improve automation, data consolidation, and scalability for the Office of Workforce Development. The scope includes integrated workforce service delivery, case distribution management, job seeker journey services, and program quality improvement. The contract period extends from the effective date through one year following system implementation, warranty, and acceptance. Proposals are evaluated using a multi-attribute scoring method focusing on organizational experience and past performance, team qualifications, and technical methodology. Key requirements include ADA compliance, annual cybersecurity training for all employees, and the use of an independent escrow agent for software. The contractor must also adhere to federal funding requirements, HIPAA/HITECH compliance via a Business Associate Agreement, and specific Missouri state tax and business certifications. Payment is structured through monthly invoices upon the approval of a Project Deliverable Acceptance Form, with a projected annual budget of approximately 1,000,000 dollars.
PROC OA DIVISION OF PURCHASING PROCUREMENTS

POSTED

about 22 hours ago

DEADLINE

in 7 days
View Details

More opportunities from Department Of Homeland Security → Transportation Security Administration

Same awarding agency

NAICS: 334511
Federal
Explosive Trace Detection (ETD) Qualified Products List (QPL)
Solicitation # 70T04026QPL7672ETD001
The Transportation Security Administration is establishing a qualification process under FAR 9.202 to add vendors to the Explosive Trace Detection (ETD) Qualified Products List (QPL). This process allows Original Equipment Manufacturers to submit Certification Data Packages (CDP) or Qualification Data Packages (QDP) for systems that meet specific TSA Detection Standards (DS 5.0, 6.2, or 6.3) and the ETD Functional Requirements Document Version 2.0. Inclusion on the QPL requires successful completion of a multi-step evaluation, including a review of system architecture, cybersecurity documentation, and technical manuals, followed by qualification testing. TSA funding for this testing is limited to the first five applicants whose QDPs are accepted. The process involves strict security and vetting requirements, including the execution of TSA Form 2815 for access to Sensitive Security Information (SSI) and subsequent use of DHS Form 11000-6 post-award. Applicants must provide CAGE codes, Unique Entity Identifiers, and detailed personnel information for vetting. Qualified systems are subject to a Cyber Vulnerability Penetration Assessment and must comply with the Buy American Act or applicable Trade Agreements. While successful qualification allows a product to be listed on the QPL, it does not guarantee a future contract award. The QPL remains open until closed by the TSA, with the current response deadline set for April 30, 2027.
Search, Detection, Navigation, Guidance, Aeronautical, and Nautical System and Instrument Manufacturing

POSTED

9 days ago

DEADLINE

in 8 months
View Details
NAICS: 334511
Federal
Bottle Liquid Scanner (BLS) Qualified Products List (QPL)
Solicitation # 70T04026QPL7672BLS001
The Transportation Security Administration is establishing a qualification process under FAR 9.202 to add vendors to the Bottle Liquid Scanner (BLS) Qualified Products List (QPL). This initiative aims to identify and certify devices capable of detecting hazardous and prohibited substances in liquids, aerosols, and gels within sealed containers to increase competition for future procurements. To be eligible, applicants must meet specific entrance criteria, including adherence to the BLS Functional Requirements Document v2.95 and Detection Standard 2.3, as well as compliance with IT security and Security Technology Integrated Program compatibility requirements. Successful placement on the QPL does not guarantee a contract award, as future procurements will be handled via competition or sole source justification as requirements arise. The qualification process involves the submission of Certification Data Packages (CDP) and Qualification Data Packages (QDP) on physical thumb drives to designated TSA officials. Applicants must undergo a rigorous evaluation process, including internal system testing at their own cost and government Certification Testing (CERT) at the Transportation Security Laboratory, where three proposed systems must be submitted. Due to the sensitive nature of the technology, participants must comply with strict security protocols, including the execution of TSA Form 2815 Non-Disclosure Agreements, passing Security Threat Assessments, and designating a Senior Official to manage Sensitive Security Information. Additionally, all submitted systems must comply with the Buy American Act and applicable Trade Agreements.
Search, Detection, Navigation, Guidance, Aeronautical, and Nautical System and Instrument Manufacturing

POSTED

28 days ago

DEADLINE

in about 1 month
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 650+ contractors already using CLEATUS