Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 19 at 2:00 PM EDT

Register Free →

Notification of Award of Sole Source Bridge Action_Cybersecurity and Privacy Program Support Services

Awarded
IT-1Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

General Info

Agency

Department Of Transportation → 693JJ6 Federal Railroad AdministrationView Agency

NAICS

541513 - Computer Facilities Management ServicesView NAICS

Place of Performance

Washington, DC, 20590, USA

Set-Aside

NONE

Documents

(2)

Criterion+Sole+Source_Bridge_Redacted.pdf

PDF

Criterion+Sole+Source_Bridge_Redacted.pdf

PDF

AI Contract Breakdown

Uniform Contract Format

What is UCF?

Uniform Contract Format (UCF) uses AI to break down any contract into standardized sections—scope, pricing, deliverables, and evaluation criteria.

Timeline

1 update
PhaseAwarded
Posted

Justification (J&A)

Justification (J&A)

Justification & Approval published

Awarded

Contract was awarded

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Transportation → 693JJ6 Federal Railroad Administration
Contacts1 person available
OfficeWASHINGTON, DC, 20590, USA
Organization / Agency
Department Of Transportation → 693JJ6 Federal Railroad Administration
View Agency Profile
Office AddressWASHINGTON, DC, 20590, USA
Contacts

Full Description

Show more

In strict compliance with GSAR 538.7104-3(b)(ii), this notice is being made publicly available within 14 days after the award of the modification to ensure procedural transparency under GSA’s modernized FSS ordering procedures.  This action is a 12-month sole source award to the incumbent contractor, Criterion, for uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. This bridge extends the period of performance from July 20, 2026 to 07/19/2027.  This contract action is necessitated by the United States Department of Transportation’s (USDOT) reorganization of its Information Technology (IT) function into a digital factory model under the 1DOT reorganization


The FRA requires uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. These services ensure the FRA fully complies with the Federal Information Security Modernization Act (FISMA) of 2014, OMB Circular A-130, and relevant Departmental cybersecurity directives.


The scope of work encompasses comprehensive coverage for all FRA FISMA-reportable systems, requiring the continuous maintenance of the Risk Management Framework (RMF) and the Information Security Continuous Monitoring Program (ISCMP). The architecture currently under administration includes:


  • Eight (8) production systems (including three hosted in the cloud, seven Moderate Security Impact systems, and five Privacy systems).
  • Four (4) systems under active development, bringing the total technical architecture to twelve (12) IT systems.
  • Environment Composition: Microsoft Dynamics 365 applications, cloud environments (SaaS, PaaS, IaaS), and on-premises datacenters.

The contractor is required to operate, monitor, and configure the DOT and DHS Security Tool Suites utilized within the FRA enclave. This includes specialized engineering and administration of tools such as Tenable Nessus, BigFix, SCCM, SCOM, DB Protect, Netsparker, Burp Suite, and the DOT Cybersecurity Assessment and Management (CSAM) repository. The required services mandate senior key personnel—specifically a Project Manager and Senior Information System Security Specialists—possessing advanced credentials (CISSP, CISA, CAP/SSCP, CIPP, CCSK) and deep, institutionalized knowledge of FRA’s safety-critical infrastructure.


These services are essential for the integration of FRA team under the new Digital Factory model mandated by the FY26 THUD Appropriations Act – passed as section D of the Consolidated Appropriations Act, 2026, Consolidated Appropriations Act, 2026 (P.L. 119-75).


Please see the attached sole source justification.

Similar Contracts

Same NAICS industry code

NAICS: 541513
New
International
TBIPS - Implementation and Deployment of Cloud Analytics Solutions
Solicitation # W6369-24-P5PN
The Directorate Joint Defence Cloud Program (DJDCP) under the Department of National Defence is seeking informatics professional services to support the implementation, deployment, and ongoing operational management of cloud analytics solutions across public cloud environments including GCP and AWS. The contract, identified by solicitation number W6369-24-P5PN, is structured as an Indefinite Delivery Indefinite Quantity (IDIQ) arrangement delivered through Task Authorizations, enabling flexible, on-demand execution of cloud modernization activities such as infrastructure-as-code provisioning, application migration, network configuration, security engineering, and system integration. Work will occur primarily within the National Capital Region, with performance locations determined per task and restricted from Comprehensive Land Claims Agreement territories. Offerors must demonstrate proven experience in cloud adoption, enterprise cloud analytics, and public cloud initiatives, with technical merit accounting for 90% of the award decision and price for 10%, evaluated on a trade-off basis with a minimum 120 out of 150 technical points required for eligibility. All proposed personnel must hold SECRET-level security clearances, possess verified technical qualifications and English language proficiency, and be fully available during contract performance, with strict prohibitions against storing classified or protected information on contractor systems. Contractors are required to submit comprehensive documentation including architecture diagrams, test plans, SOPs, and migration assessments in editable Microsoft Office formats and must comply with all DND/CAF security protocols, ITIL-based service management processes, and the Contract Security Manual. Mandatory certifications include Employment Equity compliance under the Federal Contractors Program, accurate representation of personnel qualifications and availability, full disclosure of resource allocation across multiple contracts, and independent bid determination. Bids must be submitted in three separately bound volumes—technical, financial, and certifications—via email or postal delivery by the specified deadline, using only approved file formats and environmentally responsible paper standards. The contract has no set term extension mechanisms and carries a two-year duration, with no explicit ceiling value established due to the task-based nature of delivery and incomplete pricing schedules provided for evaluation purposes only.
Department of National Defence

POSTED

2 days ago

DEADLINE

in 13 days
View Details
NAICS: 541513
New
Federal
The U.S. Energy Information Administration (EIA), Office of Resources & Technology Management (ORTM), Office of Information Technology (OIT) would like to issue an 8(a) Firm-Fixed-Price (FFP) direct…The U.S. Energy Information Administration, under the Department of Energy, plans to directly award an 8(a) Firm-Fixed-Price contract to Code Plus for IT Service Desk Support services. This procurement is designated as a small business set-aside under the 8(a) program, specifically targeting businesses owned and controlled by socially and economically disadvantaged individuals. The contract will be executed under NAICS code 541513, which covers Computer Facilities Management Services, and performance of the work is expected to occur in the District of Columbia. The award will be made without competition as a direct award under the 8(a) program, reflecting the agency’s commitment to leveraging small business capabilities in delivering essential IT support. Services will include maintaining a responsive, reliable service desk to assist EIA personnel with technical issues, system access, and IT-related inquiries across its operations. Timothy Butka, the Small Business Program Manager, is the designated point of contact for this opportunity, reachable via email at timothy.butka@eia.gov. The contract forecast was posted on August 10, 2026, indicating this is a planned acquisition for future funding and execution. Although no solicitation number has been assigned yet, the firm-fixed-price structure implies a clear scope of work with agreed-upon costs, minimizing financial risk to the government. The contract aims to ensure continuous, high-quality IT support for EIA’s mission-critical functions, with Code Plus positioned as the sole provider under the 8(a) program’s direct award authority.
Energy Information Administration

POSTED

2 days ago

DEADLINE

N/A
View Details
NAICS: 541513
New
Federal
The purpose is to award Indefinite Deliver, Indefinite Quantity Task Order Contract for Information Technology (IT) and Cybersecurity Support Services for the Department of Energy, DOE-SR. 00001 Ente…The Department of Energy’s Office of Environmental Management is seeking to award an Indefinite Delivery, Indefinite Quantity task order contract to provide comprehensive Information Technology and Cybersecurity Support Services specifically for DOE-SR. The contract encompasses three primary areas of support: Enterprise System Management, Service Center, and IT Capital Planning; Cybersecurity Support Services; and Other Direct Costs. These services are critical to maintaining secure, efficient, and resilient IT infrastructure across the department’s operations. The solicitation is designated for small businesses under the 8AN set-aside category, ensuring opportunities for qualified small business concerns to compete for this work. The North American Industry Classification System code 541513 indicates that the services fall under Computer Systems Design and Related Services, aligning with the technical nature of the required support. The contract will be managed through a designated point of contact, Kenneth Johnson, Small Business Program Manager, who can be reached via email for inquiries related to small business participation. Performance of the services is expected to occur at unspecified locations, with no detailed place of performance provided in the forecast. Although no solicitation number or exact award date is listed, the forecast was published on August 10, 2026, signaling upcoming procurement activity. Interested vendors should prepare to respond to future task order solicitations under this contract vehicle, ensuring alignment with the IT and cybersecurity needs defined by the Department of Energy’s environmental management mission.
Office of Environmental Management

POSTED

2 days ago

DEADLINE

N/A
View Details

More opportunities from Department Of Transportation → 693JJ6 Federal Railroad Administration

Same awarding agency

NAICS: 541690
New
Federal
Post-Accident Toxicological Testing Oversight
Solicitation # 693JJ626Q000027
The Federal Railroad Administration (FRA) is seeking a small business contractor to provide technical and scientific oversight services for the Office of Railroad Safety, Drug and Alcohol Division. This effort focuses on ensuring the forensic integrity and scientific credibility of the Post-Accident Toxicological Testing (PATT) Program through forensic toxicology expertise, laboratory testing procedures, proficiency testing, and compliance reviews under 49 CFR Part 219 and Part 40. The scope includes conducting three annual laboratory inspections, five annual Class 1 railroad compliance reviews, and providing 24/7 expert consultation. A critical requirement for eligibility is that inspection team members must hold a Fellow (F-ABFT), Diplomate (D-ABFT-FT, D-ABFT-FA, or D-ABFT-FD), or equivalent certification from the American Board of Forensic Toxicology. The anticipated purchase order has an estimated total value of 2,700,000 dollars, structured with a one-year base period and four subsequent 12-month option periods. Award will be based on a best-value trade-off process, prioritizing prior experience and the technical and management approach over price. The contractor must adhere to strict security and data protocols, including NIST SP 800-171 compliance, mandatory background investigations for personnel, and rapid cyber incident reporting. All deliverables, including laboratory inspection reports and automated audit tools, must be submitted electronically to the FRA Subject Matter Expert and Contracting Officer's Representative.
Other Scientific and Technical Consulting Services

POSTED

1 day ago

DEADLINE

in 16 days
View Details