Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 16 at 2:00 PM EDT

Register Free →

Cybersecurity and PII Compliance Services

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The Cybersecurity and PII Compliance Services subcontract supports prime contractors on GSA SmartPay 4 projects by providing security auditing, PII protection, and privacy assessments. The scope of work includes preparing Privacy Threshold Assessments, implementing NIST SP 800-53 security controls, and performing continuous vulnerability monitoring. To execute these tasks, the contractor must utilize encryption tools and SIEM systems to deliver Security Compliance Reports and maintain an Authority to Operate. This opportunity is managed by the General Services Administration under the GSA/FAS/PSHC/Contract Operations office, with performance located in Washington, DC. The project falls under NAICS code 541519. Interested parties must submit their responses by the deadline of October 5, 2026.

General Info

Cybersecurity and PII compliance subcontract for GSA SmartPay 4, due October 5, 2026.

Agency

General Services Administration → Gsa/fas/pshc/contract OperationsView Agency

NAICS

541519 - Other Computer Related ServicesView NAICS

Place of Performance

Washington, DC, 20405, USA

Set-Aside

NONE

Documents

This scope was carved out of 47QRAB26N0003.

The full solicitation package (2 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

Request for Information 3- Next Generation of the GSA SmartPay® Master Contract

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyGeneral Services Administration → Gsa/fas/pshc/contract Operations
ContactsNo contacts available
OfficeN/A
Organization / Agency
General Services Administration → Gsa/fas/pshc/contract Operations
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Performs security auditing, PII protection, and privacy assessments for prime contractors on GSA SmartPay 4 projects. Prepares Privacy Threshold Assessments (PTA), implements NIST SP 800-53 security controls, and conducts continuous vulnerability monitoring. Requires encryption tools and SIEM systems. Delivers Privacy Threshold Assessments, Security Compliance Reports, and a maintained ATO.

Similar Contracts

Same NAICS industry code

NAICS: 541519
New
Federal
ISBEE: Brand Name-Grammarly Business Enterprise (Base + 4)
Solicitation # 75H70426Q00025
The Indian Health Service (IHS) is conducting a sources sought notice under the authority of the Buy Indian Act, 25 U.S.C. 47, to identify qualified Indian Small Business Economic Enterprises (ISBEEs) and other Indian Economic Enterprises (IEEs) capable of providing Grammarly Business Enterprise (Part Number GRMLYENT-200), a cloud-based writing assistance software tool, for approximately 600 employees across IHS facilities. This notice is not a solicitation for proposals but a market research initiative to assess the availability and capability of small Indian-owned businesses to fulfill this requirement, with the intent to potentially structure a future acquisition using a set-aside reserved exclusively for ISBEEs. Interested parties must submit a complete response by 11:00 a.m. EST on May 11, 2026, to Javier.medina-velazquez@ihs.gov, including their company name, address, Unique Entity ID and CAGE code, point of contact, size classification under NAICS code 541519 (150-employee size standard), a capability statement, and a signed Buy Indian Act Indian Economic Enterprise Representation Form. Responses are restricted to five pages total and must not include proprietary, classified, or sensitive information, as the government reserves the right to use non-proprietary details in any future solicitation without obligation to compensate respondents. The requirement involves licensing Grammarly Business Enterprise, with baseline authorization for 600 users in the base year and anticipated increases of 80 users annually across four option years, extending the potential contract period through June 14, 2031. Performance is entirely electronic, with no physical delivery, and all services must be accessed via secure online platforms. Compliance with federal cybersecurity and privacy standards is mandatory, including adherence to FedRAMP Moderate authorization, HIPAA, the Privacy Act, FISMA, NIST SP 800-53, and SOC 2 Type II certification. Contractors must execute a Business Associate Agreement, prevent the input of protected health information, ensure data remains under IHS ownership with no secondary use, implement SCIM for identity provisioning, enable BYOK and Confidential Mode, and provide annual compliance reporting. Any data breach must be reported within 24 hours. The contracting officer is Javier Medina-Velazquez, with Kevin Fulbright serving as the technical point of contact. The government will not acknowledge receipt, guarantee an award, or pay for submissions
Division Of Acquisitions Policy Hq

POSTED

about 22 hours ago

DEADLINE

in 6 days
View Details
NAICS: 541519
New
Federal
Non-Core Telecommunications Operations & Maintenance
Solicitation # 693JJ126Q000005
The Department of Transportation is soliciting a single Blanket Purchase Agreement (BPA) for non-core telecommunications operations and maintenance support services. This small business set-aside contract, with an estimated total value of 150 million dollars, covers an 84-month ordering period with a potential six-month extension. The scope includes the management of cabling and connectivity infrastructure, telecommunications closets, asset inventory, and moves, adds, and changes for voice and data customer provided equipment. Support services extend to IPTV, distributive antenna systems, data center operations and infrastructure management, and wireless support across DOT Headquarters, field sites, the FAA, the US Merchant Marine Academy, and the Stennis, MS disaster recovery location. Award will be based on the lowest price technically acceptable (LPTA) basis, following a pass/fail evaluation of a detailed certification checklist requiring specific industry certifications and experience. Technical evaluation focuses on the approach to the statement of work, management strategy, and corporate experience as a prime contractor within the last three years. The contractor must provide 24/7 support for assets in the Washington DC area and adhere to ITIL integrated processes and BICSI cabling standards. Administrative requirements include the use of the DELPHI eInvoicing system and compliance with various TAR and FAR clauses regarding security, personnel qualifications, and organizational conflicts of interest.
693JJ3 Acquisition And Grants Mgt

POSTED

about 22 hours ago

DEADLINE

in 2 days
View Details

More opportunities from General Services Administration → Gsa/fas/pshc/contract Operations

Same awarding agency

NAICS: 522110
New
Federal
Request for Information 3- Next Generation of the GSA SmartPay® Master Contract
Solicitation # 47QRAB26N0003
The General Services Administration Payment Solutions Service Center is conducting market research through Request for Information 47QRAB26N0003 to plan the next iteration of the GSA SmartPay master contract. The goal is to establish a full-service, innovative commercial charge card and payments program supporting approximately 250 federal agencies, organizations, and Native American Tribal organizations across three primary business lines: Purchase, Travel, and Fleet. This initiative focuses on commerciality, innovation, and security to reduce barriers for both traditional financial institutions and new industry entrants while addressing previous concerns regarding system functionality and the need for greater agency-specific flexibility. The government is seeking industry feedback on a draft Performance Work Statement and pricing structure that utilizes Fixed-Price with Economic Price Adjustment CLINs. Key requirements for the future contractor include the provision of dedicated account managers for each ordering office, adherence to strict cybersecurity and PII protection standards, and a commitment to a transition-out period of up to 18 months. Performance will be monitored via a Quality Control Plan and a Performance Requirements Summary Matrix, with a specific benchmark of 95 percent accuracy for data warehouse quality. The estimated total spend volume used to establish the maximum contract value is approximately 1.1 trillion dollars.
Commercial Banking

POSTED

2 days ago

DEADLINE

in 20 days
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 750+ contractors already using CLEATUS