Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, October 14 at 2:00 PM EDT

Register Free →

DevSecOps & Cybersecurity Compliance

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

This DevSecOps and Cybersecurity Compliance subcontract supports prime contractors on Defense Health Agency projects by ensuring continuous security compliance and automating software delivery. The scope of work involves implementing CI/CD checks, STIG compliance, and IAVM remediation while maintaining RMF ATO postures through the use of Azure DevOps and Zero Trust Architecture. The primary deliverables include verified CI/CD pipelines and comprehensive ATO documentation. Personnel assigned to this contract must possess a Tier 1-3 Security Clearance and maintain DoD 8570 compliance. The opportunity is categorized under NAICS code 541519 and is associated with the Department of Defense. Interested parties should note the response deadline of October 28, 2026.

General Info

DevSecOps and cybersecurity compliance subcontract for DHA projects; deadline October 28, 2026.

NAICS

541519 - Other Computer Related Services

Place of Performance

0, VA, USA

Set-Aside

NONE

Documents

This scope was carved out of HT003826SC005-AOI0002.

The full solicitation package (2 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

Defense Health Agency (DHA), Program Acquisition Executive, Digital Medical Solutions (PAE DMS), Enterprise Intelligence & Data Solutions (EIDS) Program Management Office (PMO), Data Exchange Services Operations, Modernization, and Development

AI Contract Breakdown

Uniform Contract Format

No documents to break down

The breakdown needs solicitation documents. None were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → Defense Health Agency
ContactsNo contacts available
OfficeN/A
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Ensures continuous security compliance and automates software delivery for prime contractors on Defense Health Agency (DHA) projects. Implements CI/CD checks, STIG compliance, IAVM remediation, and maintains RMF ATO postures using Azure DevOps and Zero Trust Architecture. Requires Tier 1-3 Security Clearance and DoD 8570 compliance. Delivers verified CI/CD pipelines and ATO documentation.

Similar Contracts

Same NAICS industry code

NAICS: 541519
New
Federal
Endpoint Security Event Management
Solicitation # 842674854
The Defense Information Systems Agency is seeking industry capabilities and white papers to develop an Endpoint Security Event Management System (ESEMS) supporting the Army's Unified Network Zero Trust Architecture. This initiative focuses on Endpoint Detection and Response, Comply to Connect, and Unified Security Information and Event Management to secure endpoints connected to DOWIN-A. The anticipated requirement is for a single-award IDIQ contract with an estimated ceiling of 850 million dollars. The period of performance is expected to include a base period and multiple option years, with full operational capability required within 180 days of award. Primary performance will be centered at the Global Cyber Center in Fort Huachuca, Arizona, with additional mission locations across Maryland, Georgia, Virginia, and North Carolina. The contractor will be responsible for operating a global endpoint ecosystem, processing telemetry streams up to 50,000 events per second, and maintaining agent health on 85 to 95 percent of active endpoints. Key technical requirements include the use of virtualized Army Cloud environments, normalization of telemetry to ARCYBER-approved schemas, and strict adherence to DOW/Army RMF security controls to maintain an Authority to Operate. The contract mandates compliance with CMMC level requirements, Section 508 accessibility standards, and rigorous supply chain risk management. Administrative requirements include 24/7/365 service desk operations, the submission of quarterly technology innovation briefs, and the implementation of a phased deployment strategy for system validation.
It Contracting Division - PL84

POSTED

about 20 hours ago

DEADLINE

in 1 day
View Details
NAICS: 541519
New
International
Cybersecurity services
Solicitation # 9F032-20250160
The Canadian Space Agency is seeking bids from qualified Canadian suppliers to provide specialized cybersecurity professional services for a period of three years. The scope of work focuses on supporting security assessment and authorization activities, as well as Information Technology threat and risk assessments. This procurement is restricted to holders of the Task-Based Informatics Professional Services Supply Arrangement EN578-170432 within the Montreal Metropolitan Area. The agency requires two Level 2 Information Technology security threat and risk assessment and certification and accreditation analysts, with the option to propose one additional resource from either the Level 3 analyst category or the Level 2 or 3 vulnerability analysis specialist categories. Eligibility is limited to Canadian suppliers under the Policy on the Prioritization of Canadian Suppliers in Federal Strategic Procurement, and the process is governed by the Canadian Free Trade Agreement. Minimum security requirements include a corporate clearance of Protected B and a resource clearance of Reliability, though supply arrangement holders are not required to possess these clearances at the time of bid submission. The solicitation process has undergone four amendments to extend bid deadlines, clarify technical evaluation methodologies, amend corporate mandatory technical criteria, and provide responses to industry questions.
Canadian Space Agency

POSTED

1 day ago

DEADLINE

in 11 days
View Details

More opportunities from Department Of Defense → Defense Health Agency

Same awarding agency

NAICS: 541512
New
Federal
Defense Health Agency (DHA), Program Acquisition Executive, Digital Medical Solutions (PAE DMS), Enterprise Intelligence & Data Solutions (EIDS) Program Management Office (PMO), Data Exchange Services Operations, Modernization, and Development
Solicitation # HT003826SC005-AOI0002
The Defense Health Agency (DHA), through the Enterprise Information and Data Solutions (EIDS) Program Management Office, is seeking commercial solutions for the operations, modernization, and development of the Data Exchange Platform (DxP). This platform is critical for military health readiness and patient care, facilitating secure, standards-based interoperability and real-time clinical data exchange between the DHA, Department of Veterans Affairs, and other federal healthcare partners. The primary objective is to maintain 24x7 operational availability for legacy systems, including Data Exchange Services, the Clinical Health Data Repository, and the Access Control Services Data Access Layer, while transitioning these services toward a cloud-native, API-driven, and AI/ML-ready architecture utilizing containerized RESTful microservices. This opportunity is published as Area of Interest (AOI) #02 under Commercial Solutions Opening HT003826SC005. The government will utilize a multi-phase assessment process, beginning with a Phase I written technical solution brief, to determine the most appropriate acquisition pathway, which may include a FAR-based contract or a prototype other transaction agreement. The anticipated period of performance includes a 12-month base period with subsequent option periods based on milestone completion. Performance will be conducted at contractor facilities with remote work authorized. Technical requirements emphasize strict adherence to DoD Instruction 8510.01 (RMF), Zero Trust frameworks, and DHA cloud security rules. All contractor personnel must be U.S. citizens with appropriate security clearances (Tier 1, 2, or 3). Interested vendors must submit Phase I responses, including a technical solution brief, a draft SOO crosswalk, a proposed performance-based work statement, and an organizational conflict of interest mitigation plan, to Lacey Lockard by October 28, 2026, at 1400 Eastern Time. Technical and administrative questions are due by October 14, 2026.
Computer Systems Design Services

POSTED

about 20 hours ago

DEADLINE

in 20 days
View Details
NAICS: 811210
New
Federal
Steris Sterilizer Maintenance/Service at Offutt AFB, NE
Solicitation # HT940726Q0001
The Defense Health Agency Contracting Activity Central Division is soliciting quotations for a single-award, Firm-Fixed-Price commercial service contract to provide comprehensive maintenance and repair services for Government-owned Steris sterilization and washer equipment. Located at the 55th Medical Group, Ehrling Bergquist Clinic at Offutt Air Force Base, Nebraska, the scope of work includes scheduled preventive maintenance, safety inspections, calibrations, annual chamber cleanings, and unscheduled emergency repairs. Covered equipment consists of three Steris AMSCO 400 Steam Sterilizers, one Steris Reliance Vision Single Chamber Washer Disinfector, two Steris AMSCO 7052HP Single Chamber Washer Disinfectors, and two Steris IWECO5 Ultrasonic Instrument Washers. All services must be performed by certified technicians using genuine Original Equipment Manufacturer parts and software. This procurement is a 100 percent Total Small Business Set-Aside under NAICS codes 811210 and 811211. The anticipated period of performance includes a 12-month base period, four 12-month option periods, and a potential six-month extension, running from November 1, 2026, through April 30, 2032. Award will be determined using the Lowest Price Technically Acceptable method, evaluating the total price across the base, all option years, and the extension. Technical acceptability is based on the contractor's personnel qualifications, OEM access, technical resources, and parts capability. Key performance standards include a 4-hour telephone response time, on-site arrival within 48 business hours for unscheduled repairs, and a minimum monthly equipment uptime of 95 percent.
Electronic and Precision Equipment Repair and Maintenance

POSTED

about 20 hours ago

DEADLINE

in 11 days
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 750+ contractors already using CLEATUS