Develop and sustain CASTLE KEEP in Army commercial cloud solutions
Contract Overview
Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.
AI Contract Overview
The Army Contracting Command Aberdeen Proving Ground is issuing this Request for Information to conduct market research for the software development and sustainment of CASTLE KEEP, a customer-facing portal for the Army SCI community. The goal is to identify capable vendors who can develop and maintain this sustainable solution within the Army Commercial Cloud Solutions Provider environment. This is a non-personal services contract that emphasizes cybersecurity readiness, requiring vendors to perform infrastructure assessments using red and blue team simulations, implement cyber-network architecture, and utilize infrastructure as code for cloud management. Due to the sensitive nature of the work, the contract mandates strict security requirements, including active Top Secret/SCI clearances for personnel and the ability to operate within SCIFs. The government retains full ownership of all software and application tools developed under this effort. Interested parties from all business sizes and socioeconomic categories are encouraged to submit unclassified responses by September 22, 2026, detailing their technical capabilities, security posture, and proposed acquisition strategies.
General Info
Agency
NAICS
Place of Performance
Washington, DC, 20310, USASet-Aside
Documents
(0)AI Contract Breakdown
Uniform Contract FormatNo contract breakdown available.
Cannot generate Contract Breakdown because no documents were found from this contract's source.
Timeline
Response Deadline
Organization & Contact Information
Full Description
RFI Pursuant to Revolutionary Federal Acquisition Regulation Overhaul RFO FAR 15.101(c)
DISCLAIMER
This is a Request for Information (RFI) issued in accordance with RFO FAR 15.101(c).
- The Government does not intend to award a contract on the basis of this RFI or otherwise pay for the information requested.
- Responses to this RFI will be treated as information only and shall not be construed as a proposal.
This is not a Request for Proposal (RFP), nor does it constitute a solicitation and shall not be construed as a commitment by the Government. Responses in any form are not offers and the Government is under no obligation to award a contract from this announcement. No funds will be made available to pay for the preparation of responses to this announcement. Any information submitted to this notice is strictly voluntary and will not be returned. Not responding to this notice does not preclude participation in future solicitations. If a solicitation is released, it will not be synopsized on the government-wide point of entry due to national security. Only vendors meeting the security requirements will be provided with additional information pertaining to this requirement.
INTENT
Background: HQDA G-2. CASTLE KEEP is a customer-facing portal that provides automated workflow services and Sensitive Compartmented Army SCI program reporting, metrics, analysis, and information sharing within the Army SCI community in accordance with DoDM 5105.21 requirements.
This is non-personal services contract to provide Software Development and Software Sustainment Support of the Department of Army (DA) SSO’s CASTLE KEEP.
The Army Contracting Command Aberdeen Proving Ground (ACC-APG) is issuing this RFI to conduct market research. The intent of the RFI is to identify parties having an interest in bidding on and the resources to support solicitations for G2’s CASTLE KEEP’s sustainable solution for the SSO/SSR community to develop and sustain CASTLE KEEP in Army Commercial Cloud Solutions Provider (AC2SP).
The Government retains ownership to software and application tools; upon completion this contract all information will be turned over to the U.S. Government and is U.S. Government property.
The identified questions are to encourage competition and exchanges of information. Any voluntary response received will be reviewed to assist the Government in arriving at the most suitable approach. The Government is seeking responses to this RFI that describes vendors’ existing capabilities.
Small Business Participation: This RFI is issued on an unrestricted basis (Full and Open) to maximize industry responses. The Government highly encourages submissions from all business sizes and socioeconomic categories (e.g., Small Business, SDVOSB, 8(a), WOSB, HUBZone).
Infrastructure Assessment: Vendor shall simulate the realistic threat exploitation techniques within the legacy, existing, and emerging software system's cybersecurity in the mission context of the representative operating environment. Vendor shall apply the cybersecurity testing process with blue teams of Government and Vendor equivalent organizations and red teams of the certified Government and Vendor equivalent organizations during Developmental/Operational Test & Evaluation (D/O T&E).The Blue team assesses the operational network vulnerability with findings for the independent technical review of the network security posture and implements the mitigation techniques for integration into the community security solution to increase the cybersecurity readiness posture. The Blue teams evaluate the security threats/risks in the operating environment and study the network environment and its current state of security readiness. The Red teams simulate the potential adversary's exploitation capabilities against an enterprise's security posture to enhance the enterprise IA/Cybersecurity via demonstration of the impacts of the successful attacks and the needed countermeasure by the blue teams in the operational environment.
Cyber Integration: Vendor shall coordinate with Government Agencies and industry partners to support interoperability and integration of other capabilities, maintain adequate certified personnel to meet requirements, and provide qualified staff for CASTLE KEEP software development and sustainment. Vendor shall lease workspace with NIPRNet and JWICS access to support three to four personnel.
Multi-level Security: Vendor personnel performing work under this action must have an active Top Secret (TS) security clearance with eligibility for obtaining Sensitive Compartmented Information (SCI) (SI, TK, G, and HCS security clearance IAW DoD 5200.1-R at the time of award and must maintain the level of security required for the life of a contract. This action will require TSI/SCI, but future work related to this action may require a TS/SCI with Counterintelligence Polygraph (TS/SCI w/CI Poly) clearance. The security requirements are IAW the attached DD Form 254, Security Classification Specification. Personnel must perform within the security limitations of AR 381-10, USSID 18, and other security regulations. Any vendor personnel that will need access to SIPRNet terminals will require a TS/SCI clearance because all SIPRNet terminals are in Sensitive Compartmented Information Facility (SCIFs)
Security Boundary Clarification: The vendor shall understand and apply all applicable security classification guidance. Users should notify the originator if information indicates a need to update the guidance. Classification determinations remain the responsibility of the Government Contracting Agency (GCA). The Contract Security Classification Specification (DD254) is required for performance on a classified contract.
Infrastructure for Cyber Operations: The vendor shall leverage infrastructure as code such as terraform or related for deployments and cloud management.
Cyber-Network Architecture: develop, maintain, and update documentation which includes Standard Operating Procedures, System Architecture Guides, Entity Relationship Diagram (ERD), Install Guides, and Department of Defense Architectural Framework (DoDAF) diagrams for all related system and hardware configurations adhering to organizational templated and policies quarterly.
The vendor shall leverage cross-domain solutions for implementation for tempest hardening and significant equipment installations.
The vendor shall not implement solutions that have licenses or incur additional costs without written approval from the Government stakeholders, COR, and ACOR.
Post-RFI Events: Following the evaluation of RFI responses, the Government anticipates hosting an Industry Day to facilitate open exchanges of information and provide further program details. A separate announcement containing registration, scheduling, and security clearance instructions for the Industry Day will be published on SAM.gov. The feasibility of conducting associated physical site visits is currently under evaluation and will be announced at a later date, if applicable.
SUBMISSION INSTRUCTIONS
Vendors may only submit one (1) submission per CAGE code. Interested sources are requested to submit a response of no more than fifteen (5) pages, written in Times New Roman font of 12-point size or larger. Responses must be in either Microsoft Word or character recognized and searchable Adobe Portable Document Format (PDF).
If your company has different business sectors which hold different CAGE codes, each sector may submit a response. In addition, each CAGE code must provide separate facility clearance documentation. If teaming, use the Prime Vendor's CAGE code in the response.
Submission of proprietary and other sensitive information must be marked and identified with disposition instructions.
The Government shall not be liable or suffer any consequential damage for any improperly identified proprietary information. Proprietary information will be safeguarded in accordance with the applicable Government regulations and requirements.
The information provided and received in response to this announcement is subject to the conditions set forth in RFO FAR 15.101(c).
RFI responses and any questions shall be submitted via email to the following:
- Questions and responses may be sent using either of the following methods:
-
- Emailed to: ricardo.a.rivera50.civ@army.mil and cesar.m.mencia.civ@army.mil
- Sent via DOD Secure Access File Exchange (SAFE) (https://safe.apps.mil) to: ricardo.a.rivera50.civ@army.mil and cesar.m.mencia.civ@army.mil
DO NOT SEND CLASSIFIED INFORMATION. All submissions and attachments to this RFI must be UNCLASSIFIED or Controlled Unclassified Information (CUI).
The subject line of all emails sent in response to this RFI shall be " W56KGY26CKRFI0001". All emails shall identify respondents’ organization, point(s) of contact, and classification/caveats.
Responses to this request shall be submitted via email and must be received no later than 12:00 pm, ET, 22 September 2026.
The Government is not committed nor obligated to pay for the information provided, and no basis for claims against the Government shall arise from a response to this RFI. Respondents to this RFI may be requested to provide additional information via secure methods which may include travel or access to secure locations.
REQUESTED INFORMATION
Interested parties shall provide a response of no more than five (5) pages that address each of the following items:
- Administrative Information:
- Company name
- Mailing Address and Website
- The Unique Entity ID (generated by SAM.gov)
- Commercial and Government Entity (CAGE) Code
- Indicate business size and socioeconomic status (e.g., Large Business, Small Business, Service-Disabled Veteran-Owned Small Business (SDVOSB), 8(a), etc.) under NAICS 541611."
- Location of facility(s)
- Point(s) of Contacts name and contact information
- Facility Security Officer (FSO) name and contact information
- Confirmation of ability to safeguard Controlled Unclassified Information (CUI) at your facility.
- SIPRNet/JWICS email address (if available)
- Assessment Approach: Ensuring the following is conducted: code quality, unit testing, functional testing, integration testing, performance testing, Static, Dynamic, and Passive Security testing (DAST, SAST, and RASP).
- Describe your methodology for code quality, unit testing, functional testing, integration testing, performance testing, Static, Dynamic, and Passive Security testing (DAST, SAST, and RASP).
- Modification Capabilities: Ensuring CASTLE KEEP capability software baseline configurations are documented, maintained, updated and operationally available to all users.
- Details of vendor’s functional, and technical knowledge and experience of products and process being supported
- Security:
a. Detail your experience in working within Department of Defense (DoD) military and Intelligence Community (IC) facilities.
b. What percentage of your current workforce already holds active TS/SCI clearances versus those requiring upgrades?
c. Confirm your company’s capability to provide fully cleared personnel on Day 1 of contract award.
- Maintenance: Outline your plan for in-service engineering, preventative maintenance, troubleshooting, life-cycle support, and your ability to provide staff cleared up to the TS/SCI level.
- Data Rights: Discuss your approach to Intellectual Property (IP). Identify any anticipated proprietary components, software, or technical data that would restrict the Government's ability to achieve organic sustainment or 'right to repair'.
- Please provide additional information that you believe we should know about your company.
- Acquisition Strategy & CLIN Structure: Based on similar efforts, what CLIN structure (e.g., Cost Plus Fixed Fee Completion, Firm Fixed Price, or a hybrid combination) has yielded the fairest and most successful outcomes for integrating cyber networks into varying conditions of legacy chambers?
Similar Contracts
Same NAICS industry code
More opportunities from Department Of Defense → W6QK Acc-Apg
Same awarding agency
Ready to Pursue This Opportunity?
Get AI-powered intelligence on this solicitation and the ones like it
Every page of the solicitation package shredded into a compliance breakdown
AI-powered matching based on your capabilities and past performance
Competitor and incumbent history on the requirement
Automated alerts on amendments, Q&A deadlines, and award
Join 650+ contractors already using CLEATUS
