Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, June 24 at 2:00 PM EDT

Register Free →

This Solicitation opportunity from Social Security Administration was posted on May 5, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.

Request for Information (RFI) -- DAST Tool

Closed
28321326RI0000019Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

Active Opportunities Like This One

NAICS: 513210
New
Federal
D--EO 14398 - This requirement is for support services USGS Alaska Science Center.The U.S. Geological Survey (USGS) plans to award a purchase order to the Alaska Satellite Facility at the University of Alaska for the development of specialized software. The contract will follow the Federal Acquisition Regulation Part 12 for acquiring commercial products and services, and simplified acquisition procedures will be applied. This action is justified as a sole-source procurement, given that the Alaska Satellite Facility is believed to be the only entity capable of meeting this requirement. The software to be developed is a specialized script designed to apply radiometric terrain correction to commercial Synthetic Aperture Radar (SAR) imagery, specifically imagery formatted according to standards set by the National Geospatial-Intelligence Agency and originating from commercial SAR providers like Capella Space, ICEYE, and Umbra. This script must also process Sensor Independent Complex Data from commercial satellite missions managed through the National Reconnaissance Office and tasked by the Civil Applications Committee. The notice serves to comply with FAR Subpart 5.203 and is not a solicitation for competitive bids; however, interested parties may submit capability statements by June 18, 2026, for consideration. No formal solicitation will be issued, and the government retains sole discretion in deciding whether to proceed with competition based on responses. The contracting action is categorized under NAICS code 513210 for Software Publishers, with the contract oversight conducted by the Office of Acquisition Grants within the Department of the Interior. Electronic submissions are to be sent exclusively to the identified government point of contact by the specified deadline. The contract supports services for the USGS Alaska Science Center, with the contracting office located in Sacramento, California.
Office Of Acquisiton Grants

POSTED

2 days ago

DEADLINE

in 2 days

AI Contract Overview

Show more

The Social Security Administration's Office of Acquisition and Grants is seeking information for procuring a Dynamic Application Security Testing (DAST) tool to enhance the security testing of its applications. Currently, the Web Application Security Team (WAST) uses static application security testing (SAST) with Checkmarx and software composition analysis (SCA) with Black Duck to analyze SSA applications’ code during development. The addition of a DAST solution, which performs black box testing by scanning applications during execution, is intended to detect vulnerabilities that static tools cannot identify. This effort aims to improve compliance with FISMA metrics, meet external audit requirements, and bolster cybersecurity by identifying exploits earlier in the development cycle before production deployment. The contract is identified by solicitation number 28321326RI0000019 and was posted on May 5, 2026, with proposals due by May 19, 2026. The procurement falls under the NAICS code 513210 and is managed by the SSA Office of Acquisition and Grants in Baltimore, Maryland. This initiative supports federal mandates and new penetration testing requirements for all Tier 1 applications and systems undergoing the Authority to Operate process. Keelin McGrath is the primary point of contact for this solicitation, reflecting the urgency to secure funding and implement DAST capabilities to strengthen the agency’s application security posture.

General Info

SSA seeks DAST tool procurement to enhance application security and meet FISMA compliance.

Agency

Social Security Administration → SSA Ofc Of Acquisition Grants

NAICS

513210 - Software PublishersView NAICS

Place of Performance

MD

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

PhaseClosed
Posted

Solicitation

Response Deadline

Deadline has passed

Submission Closed

Find active opportunities like this

Start your free trial to discover similar active contracts, track opportunities, and build proposals with AI assistance.

Organization & Contact Information

Show more
AgencySocial Security Administration → SSA Ofc Of Acquisition Grants
Contacts1 person available
OfficeBALTIMORE, MD, 21235, USA
Organization / Agency
Social Security Administration → SSA Ofc Of Acquisition Grants
Office AddressBALTIMORE, MD, 21235, USA
Contacts
Keelin McGrath

Full Description

Show more

The Web Application Security Team (WAST) performs static code scanning of all SSA applications as part of the Office of Information Security’s (OIS) cybersecurity program. This is accomplished with the static application security testing (SAST) tool called Checkmarx and the software composition analysis (SCA) tool called Black Duck. Both of these solutions are white box testing tools that analyze the application’s code as it's being built. WAST is looking to procure a Dynamic Application Security Testing (DAST) solution to better analyze SSA applications, to bolster FISMA metrics, and to satisfy the requirements from multiple external audits and assessments. The DAST tool would scan applications as they are executed to identify exploits that can only be detected from black box testing. This funding is required immediately to better support the workload of multiple federal mandates and to provide black box testing early in the development lifecycle to stop exploits before they go to Production and potentially cause a security breach. This will also support a new requirement to perform penetration testing on all Tier 1 applications and all information systems going through the Authority to Operate (ATO) process.