This Sources Sought opportunity from Department Of Veterans Affairs was posted on May 27, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.
DA01--Enterprise Cybersecurity Program Audit Support (VA-26-00036760)
Contract Overview
Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.
Active Opportunities Like This One
AI Contract Overview
The Department of Veterans Affairs is seeking support services under a sources-sought notice for the Enterprise Cybersecurity Program Audit Support, targeted as a Service-Disabled Veteran-Owned Small Business (SDVOSB) set-aside under GSA MAS IT PS SIN 54151S, with a NAICS code of 541512 and a small business size standard of $34 million in annual revenue. The solicitation, numbered 36C10B26Q0155, was posted on May 27, 2026, with responses due by April 7, 2026, at 3:00 PM Eastern Time. Performance is fully remote, with contractors required to operate from U.S.-based facilities during Federal business hours, and no travel or on-site work is anticipated. The base period of performance is 12 months, with three optional 12-month extension periods and a potential 60-day transition period, for a total maximum duration of 50 months. The scope centers on supporting the VA Office of Information & Technology’s Enterprise Cybersecurity Program through end-to-end audit lifecycle management, including FISMA, FISCAM, IRS, and IT security inspections, data analytics, trend analysis, audit preparation, and management of the OIT Audit Portal. Key deliverables include a Contractor Project Management Plan, Monthly Progress Reports, Staff Roster, AI System Documentation, User Guides, and a Transition-Out Plan, all submitted in approved electronic formats. Contractors must comply with stringent security, personnel, and operational requirements, including full adherence to VA Handbook 6500.6, VAAR, and FAR provisions such as 52.227-14 for data rights and 52.203-16 for organizational conflict of interest. All personnel must undergo background investigations aligned with Tier 1, Tier 2, or Tier 4 risk designations, with Tier 4 requiring Top Secret clearance for high-risk tasks. Contractors must submit a detailed Staff Roster within three business days of award, including SSNs via encrypted channels, and update it within one day of any personnel changes. Access to VA systems requires adherence to the principle of least privilege, signing of the VA Information Security Rule of Behavior, and the use of PIV/PIV-I credentials. Equipment must be FIPS 140-2 validated, with disabled Bluetooth, approved antivirus, and sanitized prior to disposal. AI
General Info
Agency
NAICS
Place of Performance
NJSet-Aside
Timeline
Submission Closed
Organization & Contact Information
Full Description
More opportunities from Department Of Veterans Affairs → Technology Acquisition Center Nj (36C10B)
Same awarding agency
Find Active Opportunities Like This
Get AI-powered intelligence on the opportunities still open
Every page of the solicitation package shredded into a compliance breakdown
AI-powered matching based on your capabilities and past performance
Competitor and incumbent history on the requirement
Automated alerts on amendments, Q&A deadlines, and award
Join 650+ contractors already using CLEATUS
