This Solicitation opportunity from Social Security Administration was posted on May 5, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.
Request for Information (RFI) -- DAST Tool
Contract Overview
Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.
Active Opportunities Like This One
AI Contract Overview
The Social Security Administration’s Office of Information Security is seeking a Dynamic Application Security Testing (DAST) solution to complement its existing static code analysis tools, Checkmarx and Black Duck, which are used for white box testing during the build phase of applications. The DAST tool will enable black box testing by scanning applications while they are running, identifying vulnerabilities that are only detectable during execution, such as runtime exploits and configuration flaws. This acquisition is critical to strengthening FISMA compliance, meeting requirements from multiple external audits, and supporting the new mandate to conduct penetration testing on all Tier 1 applications and systems undergoing the Authority to Operate process. The goal is to integrate this testing early in the development lifecycle to prevent security flaws from reaching production and to reduce the risk of breaches. The request is issued as a Request for Information under solicitation number 28321326RI0000019, posted on May 5, 2026, with responses due by May 19, 2026. The procurement falls under NAICS code 513210 and is managed by the Social Security Administration’s Office of Acquisition and Grants in Baltimore, Maryland. Keelin McGrath is the primary point of contact for inquiries. The funding is urgent to address current workload demands and federal compliance obligations, ensuring that security testing is robust, timely, and aligned with the agency’s broader cybersecurity strategy across all mission-critical systems.
General Info
Agency
NAICS
Place of Performance
MDSet-Aside
Documents
(0)AI Contract Breakdown
Uniform Contract FormatNo contract breakdown available.
Cannot generate Contract Breakdown because no documents were found from this contract's source.
Timeline
Submission Closed
Organization & Contact Information
Full Description
The Web Application Security Team (WAST) performs static code scanning of all SSA applications as part of the Office of Information Security’s (OIS) cybersecurity program. This is accomplished with the static application security testing (SAST) tool called Checkmarx and the software composition analysis (SCA) tool called Black Duck. Both of these solutions are white box testing tools that analyze the application’s code as it's being built. WAST is looking to procure a Dynamic Application Security Testing (DAST) solution to better analyze SSA applications, to bolster FISMA metrics, and to satisfy the requirements from multiple external audits and assessments. The DAST tool would scan applications as they are executed to identify exploits that can only be detected from black box testing. This funding is required immediately to better support the workload of multiple federal mandates and to provide black box testing early in the development lifecycle to stop exploits before they go to Production and potentially cause a security breach. This will also support a new requirement to perform penetration testing on all Tier 1 applications and all information systems going through the Authority to Operate (ATO) process.
More opportunities from Social Security Administration → SSA Ofc Of Acquisition Grants
Same awarding agency
Find Active Opportunities Like This
Get AI-powered intelligence on the opportunities still open
Every page of the solicitation package shredded into a compliance breakdown
AI-powered matching based on your capabilities and past performance
Competitor and incumbent history on the requirement
Automated alerts on amendments, Q&A deadlines, and award
Join 650+ contractors already using CLEATUS
