Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, October 14 at 2:00 PM ET

Register Free →

FY26 FISMA Audit

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The FY26 FISMA Audit is a forecast for a contract with the General Services Administration to conduct an annual independent evaluation of the agency's information security program and practices. Under the direction of the GSA Office of Inspector General, the selected contractor will assess GSA's performance across six security function areas: Govern, Identify, Protect, Detect, Respond, and Recover. The goal is to determine the effectiveness of these programs and assign a maturity level ranging from Ad Hoc to Optimized, as required by the Office of Management and Budget. The audit must be performed in accordance with Government Accountability Office Government Auditing Standards, OMB guidance, and the NIST Cybersecurity Framework. This engagement ensures compliance with the Federal Information Security Modernization Act of 2014. The project is associated with NAICS code 541211 and is slated for performance in Washington.

General Info

GSA contract for annual FISMA audit evaluating information security program effectiveness and maturity.

NAICS

541211 - Offices of Certified Public Accountants

Place of Performance

Washington, DC, USA

Set-Aside

NONE

Documents

0

No documents available

Documents will appear here when they are available.

AI Contract Breakdown

Uniform Contract Format

No documents to break down

The breakdown needs solicitation documents. None were found from this contract's source.

Timeline

Posted

forecast

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyGeneral Services Administration → GSA FAS Office of Acquisition Opera
Contacts2 people available
OfficeN/A

Full Description

Show more
The Federal Information Security Management Act of 2002 (FISMA), as amended in 2014, requires agencies to develop, implement, and document department-wide information security programs. FISMA requires each federal agency to perform an annual independent evaluation of the information security program and practices of the agency to determine the effectiveness of such programs and practices and report the results to the Office of Management and Budget (OMB). For each agency with an Inspector General (IG) appointed under the Inspector General Act of 1978, the annual evaluation must be performed by the IG or by an independent external auditor, as determined by the IG of the agency. GSA OIG has elected to have the annual evaluation performed by an independent external auditor. OMB requires inspectors general to assess metrics in 6 security function areas: Govern, Identify, Protect, Detect, Respond, and Recover to determine the effectiveness of their agencies’ information security programs and the maturity level of each function area. OMB has five defined maturity levels from lowest to highest: Ad Hoc, Defined, Consistently Implemented, Managed and Measurable, and Optimized. Consistent with FISMA and OMB requirements, the objective of the audit is to determine the effectiveness of GSA’s information security program and practices for a specified period each year. Specifically, the Contractor will assess GSA’s performance in the six security function areas. Under the general direction of the U.S. General Services Administration (GSA) Office of Inspector General (OIG), Office of Audits, the Contractor will perform an audit of GSA’s information security program and practices to determine the effectiveness of such program and practices pursuant to the Federal Information Security Modernization Act of 2014 (FISMA). The audit must be conducted in accordance with the Government Accountability Office Government Auditing Standards (GAGAS), the OMB Guidance on Federal Information Security and Privacy Management Requirements, and the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity (Cybersecurity Framework).

Similar Contracts

Same NAICS industry code

NAICS: 541211
New
SLED
Independent Audit Services (FY2027–FY2031)
Solicitation # RFQ No. 2026-007
The City of Santa Fe, Texas, is seeking a licensed certified public accounting firm to provide independent financial audit services for the City and its 4B Economic Development Corporation. The scope of work includes auditing basic financial statements, performing Single Audits when required, and satisfying investment compliance audits under the Texas Government Code. The contract is structured for an initial three-year term beginning with the fiscal year ending September 30, 2027, with two optional one-year renewals extending through fiscal year 2031. All audits must be conducted in accordance with GAAS, GAGAS, the Single Audit Act Amendments of 1996, Uniform Guidance, and GAAP as promulgated by GASB. Selection is based on demonstrated competence and qualifications pursuant to Chapter 2254 of the Texas Government Code, with fees negotiated exclusively with the highest-ranked firm. To be responsive, firms must be registered with the Texas State Board of Public Accountancy, hold a passing AICPA peer review rating including a GAGAS engagement, and have performed at least three audits of Texas municipalities within the last five years. Sealed Statements of Qualifications, limited to 25 pages, and separate sealed fee proposals must be submitted by 2:00 p.m. CT on October 27, 2026. Submissions must include one signed original, three copies, and a searchable PDF on a USB drive delivered to the City Secretary.
City of Santa Fe

POSTED

2 days ago

DEADLINE

in 17 days
View Details
NAICS: 541211
New
International
Regional Internal Audit Services
Solicitation # DP1082
The Police and Crime Commissioner for Derbyshire, acting as the Lead Contracting Body, is seeking to establish a Framework Agreement for the provision of Regional Internal Audit Services. This framework will serve multiple participating organizations, including the Police and Crime Commissioners and respective fire and rescue authorities for Derbyshire, Leicestershire, Lincolnshire, Northamptonshire, and Nottinghamshire. The estimated total value of the contract is 5,000,000 GBP excluding VAT, with a performance period estimated from March 1, 2027, to March 31, 2031. Services will be performed within the East Midlands region of England, and all quoted prices must remain fixed for the full duration of the agreement. The award will be determined based on a weighted evaluation of 80 percent quality and 20 percent price. The quality component is further divided into business requirements and method statements at 60 percent, presentations at 10 percent, and social value at 10 percent. Pricing must be submitted via the DP1082 Pricing Schedule, which will eventually become Schedule 7 of the final agreement. Under this framework, participating organizations will conduct their own call-off processes without further competition to enter into individual contracts with the appointed provider. Tenders must be submitted electronically in English by October 13, 2026.
The Police and Crime Commissioner for Derbyshire

POSTED

2 days ago

DEADLINE

in 3 days
View Details
NAICS: 541211
New
SLED
Financial Statement Auditing Services
Solicitation # 26-049-RFP
The Kenton County Airport Board (KCAB), which maintains jurisdiction and control over the Cincinnati/Northern Kentucky International Airport (CVG), is soliciting proposals for Financial Statement Auditing Services under solicitation number 26-049-RFP. The primary objective of this engagement is to perform annual financial statement audits, test IT general controls, and verify supplies inventory balances. A critical requirement of the scope is supporting KCAB's transition from Basic Financial Statements to a publication-ready Annual Comprehensive Financial Report (ACFR) for the fiscal year ending December 31, 2027. The contract is designed for an initial term of three years, with an option to renew for two additional one-year terms. The selection process is based on a best-value evaluation, with scoring weighted across the experience and qualifications of key personnel (30%), the proposed audit approach (30%), the strength and reputation of the firm (20%), and the engagement fee (20%). Awarded contractors must adhere to generally accepted auditing standards, AICPA Audit standards, Kentucky Revised Statute 65A.030, and Governmental Accounting Standards Board principles. Deliverables include an annual audit plan due by November 15, an ACFR implementation plan for 2027, and regular progress conferences and Audit Committee presentations. Administratively, the successful proposer will be paid on a monthly basis within 30 days of invoice receipt, provided invoices include detailed descriptions of work and supporting documentation for reimbursable expenses. The contract mandates strict compliance with federal nondiscrimination laws, including Title VI of the Civil Rights Act of 1964 and the Americans with Disabilities Act, as well as OSHA safety standards. Proposers must submit a fixed fee for recurring annual services and a separate fixed fee for the Year 1 ACFR transition, while providing a certificate of insurance and a recent quality assurance review.
Finance

POSTED

2 days ago

DEADLINE

in 19 days
View Details

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 750+ contractors already using CLEATUS