Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, October 14 at 2:00 PM EDT

Register Free →

DevSecOps Pipeline & Security Engineering

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The DevSecOps Pipeline and Security Engineering subcontract supports prime contractors for the Millennium Challenge Corporation by establishing and maintaining secure deployment pipelines. The scope of work focuses on implementing Zero Trust principles, managing vulnerabilities within third-party and open-source libraries, and ensuring strict adherence to NIST and OMB security compliance standards. Key deliverables include the functional secure pipelines, detailed vulnerability reports, and the necessary documentation to achieve Authority to Operate status. This opportunity is categorized under NAICS code 541519 and is based in Washington, DC. Personnel assigned to this project must hold a Moderate Risk Public Trust clearance. Interested parties should note the response deadline of October 29, 2026.

General Info

DevSecOps subcontract for MCC focusing on secure pipelines, NIST compliance, and Zero Trust.

NAICS

541519 - Other Computer Related Services

Place of Performance

Washington, DC, 20005, USA

Set-Aside

NONE

Documents

This scope was carved out of 95332427K0001.

The full solicitation package (3 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

MCC Software Development Recompete

AI Contract Breakdown

Uniform Contract Format

No documents to break down

The breakdown needs solicitation documents. None were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyMillennium Challenge Corporation
ContactsNo contacts available
OfficeN/A
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Establishes and maintains DevSecOps pipelines for prime contractors on Millennium Challenge Corporation (MCC) projects. Implements Zero Trust principles, manages third-party/open-source library vulnerabilities, and ensures security compliance per NIST and OMB standards. Requires Moderate Risk Public Trust (MRPT). Delivers secure deployment pipelines, vulnerability reports, and ATO documentation.

Similar Contracts

Same NAICS industry code

NAICS: 541519
New
Federal
Endpoint Security Event Management
Solicitation # 842674854
The Defense Information Systems Agency is seeking industry capabilities and white papers to develop an Endpoint Security Event Management System (ESEMS) supporting the Army's Unified Network Zero Trust Architecture. This initiative focuses on Endpoint Detection and Response, Comply to Connect, and Unified Security Information and Event Management to secure endpoints connected to DOWIN-A. The anticipated requirement is for a single-award IDIQ contract with an estimated ceiling of 850 million dollars. The period of performance is expected to include a base period and multiple option years, with full operational capability required within 180 days of award. Primary performance will be centered at the Global Cyber Center in Fort Huachuca, Arizona, with additional mission locations across Maryland, Georgia, Virginia, and North Carolina. The contractor will be responsible for operating a global endpoint ecosystem, processing telemetry streams up to 50,000 events per second, and maintaining agent health on 85 to 95 percent of active endpoints. Key technical requirements include the use of virtualized Army Cloud environments, normalization of telemetry to ARCYBER-approved schemas, and strict adherence to DOW/Army RMF security controls to maintain an Authority to Operate. The contract mandates compliance with CMMC level requirements, Section 508 accessibility standards, and rigorous supply chain risk management. Administrative requirements include 24/7/365 service desk operations, the submission of quarterly technology innovation briefs, and the implementation of a phased deployment strategy for system validation.
It Contracting Division - PL84

POSTED

about 14 hours ago

DEADLINE

in 1 day
View Details

More opportunities from Millennium Challenge Corporation

Same awarding agency

NAICS: 541512
New
Federal
MCC Software Development Recompete
Solicitation # 95332427K0001
The Millennium Challenge Corporation (MCC) Office of the Chief Information Officer (OCIO) Digital Services Team is seeking a contractor for the MCC Software Development Recompete under solicitation 95332427K0001. The scope of work involves providing comprehensive application engineering, operations and maintenance (O&M), platform customization, configuration, and Tier 3 user support for all enterprise applications. The contractor will be responsible for monitoring cloud-based applications, managing performance faults, and executing new development tasks using Agile and test-driven methodologies. Additional requirements include providing program management, administrative support, and surge capacity to handle fluctuating workloads or special projects. Performance must align with industry best practices, NIST, OMB, and MCC policies, with a strong emphasis on integrating cybersecurity and Zero Trust principles throughout the software lifecycle. The primary place of performance is anticipated to be the contractor's site or via telework, though some work requiring direct network access will occur at MCC headquarters in Washington, D.C. Personnel must undergo a National Agency Checks with Law and Credit (NACLC) background investigation for a Moderate Risk Public Trust (MRPT) position and comply with HSPD-12 identity verification. Deliverables include formal operational, administrative, and training documentation, with product acceptance based on a rapid, repetitive development process in a joint team environment.
Computer Systems Design Services

POSTED

1 day ago

DEADLINE

in 22 days
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 750+ contractors already using CLEATUS