Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

IT Security Plan Development and System Accreditation Support

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract involves the development and support of an IT Security Plan specifically tailored for BaseOps, with the primary goal of achieving accreditation from the Department of Transportation (DOT). Key responsibilities include conducting comprehensive risk assessments, implementing necessary security controls, and maintaining ongoing coordination with DOT assessors throughout the accreditation process. The scope is designed to ensure that BaseOps meets stringent security standards, thereby safeguarding its systems and data in alignment with federal requirements. This subcontract, identified under NAICS code 541512, relates to computer systems design services and is issued by the Volpe National Transportation System Center, a division of the Department of Transportation. The place of performance is in the 02142 zip code area, indicating a probable location near Cambridge, Massachusetts. The contract was posted in April 2026 and emphasizes collaboration between the contractor and DOT officials to successfully navigate the accreditation process, ensuring compliance with all applicable guidelines and security frameworks.

General Info

Develop IT Security Plan for BaseOps, risk assessments, DOT accreditation, and compliance coordination.

Agency

Department Of Transportation → 6913G6 Volpe National Transportation System CntrView Agency

NAICS

541512 - Computer Systems Design ServicesView NAICS

Place of Performance

MA, 02142, USA

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Transportation → 6913G6 Volpe National Transportation System Cntr
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Transportation → 6913G6 Volpe National Transportation System Cntr
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Develop and support approval of an IT Security Plan for BaseOps to achieve DOT accreditation, including risk assessment, control implementation, and coordination with assessors.

Similar Contracts

Same NAICS industry code

NAICS: 541512
New
SLED
Azure Consulting IDIQThe Port of Seattle is preparing to engage a qualified cloud services partner through an Indefinite Delivery/Indefinite Quantity (IDIQ) contract to support the modernization and optimization of its Microsoft Azure and Hybrid cloud environment. The contractor will be tasked with validating and enhancing the existing Azure architecture, guiding the implementation of new services, and strengthening the organization’s security posture, system resiliency, and operational efficiency. Work will focus on ensuring all cloud designs and deployments align with the Port’s enterprise standards, operational demands, and long-term scalability goals, with an emphasis on best practices in cloud governance and architecture. The contract is classified under NAICS code 541512 for Computer Systems Design Services and is managed by the ICT Enterprise Infrastructure Services division under the Port of Seattle. Primary point of contact is Carol Hassard, with Jim Dawson serving as the Project Manager; inquiries can be directed via their provided email addresses and phone numbers. The solicitation is forecasted for release in July 2026, with no set-aside designation specified, and will be executed under a single contract vehicle to allow for flexible, task-order-based engagements as needs arise. The place of performance and administrative details are not yet defined, but work is expected to primarily support the Port’s internal infrastructure and cloud initiatives.
ICT Enterprise Infrastructure Services

POSTED

about 6 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
SLED
FIDS Software ReplacementThe Port of Seattle is forecasted to procure a new software solution for its Flight Information Display System, aiming to replace legacy systems with modern, reliable technology that enhances passenger information delivery at airport terminals. The solicitation, posted on July 24, 2026, falls under NAICS code 541512, indicating it is for custom computer programming services, and is managed by ICT Enterprise Infrastructure Services. The project will require a vendor to deliver a fully functional, scalable, and secure software platform capable of integrating with existing airport systems while supporting real-time flight updates, multilingual displays, accessibility features, and high availability under heavy operational loads. Performance is expected to occur at the Port of Seattle’s facilities, though specific location details are not provided. Primary point of contact for inquiries is Farlis Lewis, reachable via phone or email, with Krista Sadler listed as the Project Manager for operational coordination. While the contract has not yet been solicited and no set-aside provisions are indicated, interested vendors should prepare proposals that demonstrate technical expertise in aviation display systems, experience with airport infrastructure, and adherence to industry standards for reliability and uptime. The official solicitation details and submission instructions can be accessed through the provided UI link, and responses should be tailored to meet the Port’s operational requirements for seamless integration, minimal downtime during transition, and long-term support capabilities.
ICT Enterprise Infrastructure Services

POSTED

about 6 hours ago

DEADLINE

N/A
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance and NIST SP 800-171 Assessment SupportThe contract requires support for achieving and maintaining NIST SP 800-171 compliance in alignment with DFARS requirements, encompassing comprehensive system assessments, detailed documentation of security controls, and robust cyber incident reporting procedures. The effort is geared toward ensuring that covered systems meet federal standards for protecting controlled unclassified information, with a focus on thorough evaluations of security posture, control implementation, and continuous compliance monitoring. All activities must adhere strictly to the framework established by NIST and the Department of Defense, with deliverables including validated assessment reports and timely incident notifications as mandated by regulation. This subcontract is issued under the NAICS code 541512 for computer systems design services by the Strategic Acquisition Program Directorate within the Department of Defense, and responses are due by July 28, 2026. The work will be performed in support of defense-related operations, though the specific location of performance is not outlined. The solicitation is part of a broader initiative to strengthen cybersecurity readiness across the defense industrial base, emphasizing accountability, documentation integrity, and rapid response to cyber threats. Contractors must demonstrate proven experience in NIST SP 800-171 assessments and DFARS compliance, and the selection process will prioritize technical capability and demonstrated success in similar government cybersecurity engagements.
STRATEGIC ACQ PROGRAM DIRECTORATE

POSTED

about 20 hours ago

DEADLINE

in 4 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance & Incident ReportingThis contract requires the implementation of NIST Special Publication 800-171 cybersecurity controls to protect covered defense information on nonfederal systems, ensuring alignment with federal standards for safeguarding sensitive data. The contractor must establish and maintain a comprehensive cybersecurity framework that meets all applicable requirements under NIST SP 800-171, including access control, audit and accountability, configuration management, and incident response measures. Compliance must be demonstrated through documented policies, procedures, and technical safeguards validated to the standards outlined in the publication. In addition to implementing the controls, the contractor is obligated to report any cyber incidents involving covered defense information within 72 hours of discovery, providing full detail of the nature, scope, and impact of the incident to the appropriate government entities. The contract is structured as a small business set-aside under SBA guidelines, specifically reserved for total small businesses, and falls under the NAICS code 541512 for computer systems design services. The solicitation is issued by the Department of Defense’s Strategic Acquisition Program Directorate, with a response deadline of July 28, 2026, and is intended for subcontracting purposes under a broader defense acquisition effort.
STRATEGIC ACQ PROGRAM DIRECTORATE

POSTED

about 20 hours ago

DEADLINE

in 4 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity and NIST SP 800-171 Compliance SupportThe contract requires full compliance with DFARS 252.204-7012 and NIST SP 800-171 to ensure the proper safeguarding of controlled unclassified information across all systems and processes involved in the performance of work. This obligation extends to implementing the full spectrum of security controls outlined in NIST SP 800-171, including access control, audit, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, system and communications protection, and system and information integrity. The subcontractor must demonstrate a formal, documented cybersecurity program aligned with these standards and be prepared to validate compliance through assessments or audits as required by the Department of Defense. The effort is classified as a subcontract under the NAICS code 541512 for computer systems design services and is managed by the Strategic Acquisition Program Directorate within the Department of Defense. The solicitation was posted on July 23, 2026, with a strict response deadline of July 28, 2026, indicating a limited window for qualified vendors to submit proposals. Performance location details are not specified, but the work likely involves supporting DoD systems handling CUI, requiring secure, controlled environments and potentially remote or onsite support. Compliance is non-negotiable and forms the core requirement for award and continued contract execution, with failure to meet these standards resulting in immediate disqualification or contract termination.
STRATEGIC ACQ PROGRAM DIRECTORATE

POSTED

about 20 hours ago

DEADLINE

in 4 days
View Details
NAICS: 541512
New
DIBBS
Cybersecurity Compliance (NIST SP 800-171)The contract requires the implementation and documentation of NIST SP 800-171 security controls to safeguard Controlled Unclassified Information (CUI) on contractor systems. This effort is critical to ensuring compliance with federal cybersecurity standards for handling sensitive but unclassified data, and all required controls must be fully activated, tested, and formally recorded to demonstrate adherence. The subcontract is under the Department of Defense, specifically managed by PUGET SOUND, with performance taking place in BREMERTON, WA, at the zip code 98314-6001. The solicitation is categorized under NAICS code 541512, which corresponds to Computer Systems Design and Related Services, indicating the technical nature of the work involved. Responses are due by July 28, 2026, and the opportunity was posted on July 23, 2026, providing a limited window for interested parties to submit proposals. The work is part of a broader initiative to enforce cybersecurity hygiene across the defense industrial base, and successful execution demands thorough understanding of NIST SP 800-171 requirements, including risk assessments, access controls, audit and accountability measures, system and communications protection, and continuous monitoring. Documentation must be precise and auditable, as non-compliance could jeopardize the contractor’s ability to handle CUI and may lead to termination or penalties. All activities must align with the Department of Defense’s expectations for protecting sensitive information on non-federal systems.
PUGET SOUND

POSTED

about 20 hours ago

DEADLINE

in 4 days
View Details

More opportunities from Department Of Transportation → 6913G6 Volpe National Transportation System Cntr

Same awarding agency

NAICS: 336510
New
Federal
Rail Maintenance and Sustainment (RMS) Multiple-Award IDIQThe solicitation for the Rail Maintenance and Sustainment (RMS) Multiple-Award IDIQ contract, identified by number 6913G626R200002, is a full and open competition under NAICS code 336510 aimed at securing commercial rail products and services from qualified vendors. The contract vehicle will support a range of activities including the manufacture and refurbishment of locomotives, freight cars, and railcar movers, as well as preventive maintenance, inspections, corrective repairs, engineering diagnostics, and emergency repair services. Phase II of the solicitation has been updated through a series of amendments, with Amendment 0004 issued on July 16, 2026, formally releasing four Task Order Requests for Proposals and corresponding Statements of Work: one for Road-Switcher Locomotives, one for 50 Foot Damage Free Railway Boxcars, one for Annual and Periodic 184-Day Locomotive Safety Inspections, and one for Locomotive Sustainment including Technical Field Support. Earlier amendments revised key requirements: Amendment 0003 directed offerors to comply with current AAR guidance in place of the retired Standard S-2034, Amendment 0002 eliminated the need for Mock Task Orders, and Amendment 0001 addressed clarifications to submitted questions. All amendments preserved the original proposal due date of July 31, 2026, and maintained unchanged other solicitation provisions. The contracting office is located at the Volpe National Transportation Systems Center in Cambridge, Massachusetts, with primary point of contact Patricia Barnett and secondary contact Matthew Phelps. The contract is structured as a multiple-award IDIQ with no set-aside, and while estimated value and pricing details are not provided, performance will be centered in Cambridge, MA, under the oversight of the Department of Transportation.
Railroad Rolling Stock Manufacturing

POSTED

1 day ago

DEADLINE

in 7 days
View Details
NAICS: 541330
New
Federal
Track System Safety ResearchThe U.S. Department of Transportation’s Volpe National Transportation Systems Center is soliciting engineering consulting services on track system safety research through a sole-source award to David Jeong of North Reading, MA, under FAR Part 12 and Part 13 procedures. The requirement is for specialized expertise to support the Federal Railroad Administration’s Track Safety Research Program, focusing on preventing rail failures and track buckling through technical analysis and consulting. Services include quarterly one-hour recorded technical consultations covering rail neutral temperature management, slow crack-growth life modeling, rolling contact fatigue, and sensitivity analyses of track and rail performance under stress. The contractor will deliver technical presentations, white papers, and all associated electronic data files—such as software scripts, input/output files, and analysis tools—across a one-year base period with two optional one-year extensions, for a potential total contract duration of three years. All deliverables must be submitted electronically, with files under 20 MB sent via email and larger files uploaded to a government-provided secure portal. The contractor must use only commercially available or open-source software—no proprietary or in-house tools—and must provide complete access to all source code and supporting data for government use, with no licensing restrictions. The government will furnish secure access to the slow crack-growth model and incident data upon request. Proposals must include firm-fixed pricing for each of the three contract line items, and the award is contingent on the contractor maintaining an active SAM registration. All inquiries must be submitted in writing by July 27, 2026, and formal offers are due by August 3, 2026. Deliverables will be reviewed within 10 business days, with revisions required if feedback is provided. The North American Industry Classification System code is 541330, with a small business size standard of $25.5 million, though this solicitation is not set aside for small businesses.
Engineering Services

POSTED

2 days ago

DEADLINE

in 10 days
View Details