Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Cybersecurity Compliance (NIST SP 800-171 Assessment & SPRS Reporting)

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

General Info

Agency

Department Of Defense → Defense Logistics AgencyView Agency

NAICS

541612 - Human Resources Consulting ServicesView NAICS

Place of Performance

Not specified

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → Defense Logistics Agency
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Defense → Defense Logistics Agency
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Conduct NIST SP 800-171 assessments for systems handling CUI, achieve minimum score of 110, and submit results to SPRS.

Similar Contracts

Same NAICS industry code

NAICS: 541612
New
SLED
Cybersecurity and Compliance ManagementThe contract requires ongoing cybersecurity and compliance management services focused on maintaining adherence to NIST SP 800-53 standards, sustaining authority to operate status, implementing robust encryption protocols, and ensuring effective incident response capabilities for payment systems. These responsibilities are critical to safeguarding sensitive financial data and ensuring regulatory alignment across all operational aspects of the systems under management. The work must be performed continuously to uphold security controls, detect and mitigate threats promptly, and respond to breaches in a manner that minimizes disruption and meets state and federal requirements. This subcontract is issued by the California State Controller’s office with a posted date of July 31, 2026, and a response deadline of September 9, 2026. The North American Industry Classification System code 541612 indicates the service falls under computer facilities management services, signaling a need for technical expertise in securing and managing hosted or cloud-based financial infrastructure. The place of performance and point of contact details are not specified, suggesting the work may be performed remotely or across multiple locations within California. All deliverables must align with the state’s cybersecurity framework and support uninterrupted, secure payment processing operations.
State Controller

POSTED

2 days ago

DEADLINE

in about 1 month
View Details
NAICS: 541612
New
SLED
Cybersecurity Compliance Support (Third-Party Assessment Provider)The contract engages a third-party provider to deliver cybersecurity validation services for financial institutions by administering and certifying the Cyber Risk Assessment Questionnaire as an alternative to traditional SOC-2 reports. This arrangement shifts the compliance burden from standardized auditing frameworks to a specialized, tailored assessment process designed to evaluate and validate the cybersecurity postures of financial entities. The provider is responsible for ensuring the integrity, consistency, and regulatory alignment of the questionnaire throughout its deployment, maintaining rigorous standards for certification without reliance on established external audit reports. The agreement is structured as a subcontract under the NAICS code 541612, targeting cybersecurity consulting and related services, with a response deadline of June 1, 2028, and a posted date of July 31, 2026. It is affiliated with the Finance agency in California, though specific office locations and point of contact details are not provided. The scope emphasizes replacing SOC-2 validation with a proprietary assessment framework, implying the need for the provider to establish credible, audit-ready methodologies that financial institutions can confidently use for regulatory and partner compliance purposes. The contract does not specify set-aside status or geographic performance constraints beyond the broader jurisdiction of California.
Finance

POSTED

2 days ago

DEADLINE

in almost 2 years
View Details

More opportunities from Department Of Defense → Defense Logistics Agency

Same awarding agency