Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 30 at 2:00 PM EDT

Register Free →

RMF Compliance and ATO Maintenance Services

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The RMF Compliance and ATO Maintenance Services subcontract supports prime contractors on DISA and Army ESEMS projects to ensure the maintenance of Authorization to Operate status. The scope of work involves performing cybersecurity documentation and administrative tasks, including the management of RMF documentation and eMASS records, reviewing DOW STIG documentation, and creating integration guidance for GOTS software. Key deliverables include updated eMASS records and STIG compliance reports. This opportunity is based in Fort Huachuca and is managed by the Department of Defense IT Contracting Division. Qualified candidates must possess a Secret or Top Secret security clearance and hold professional RMF certifications such as CISSP or CISM. The response deadline for this subcontract is October 9, 2026.

General Info

RMF compliance and ATO maintenance services for DoD projects; deadline October 9, 2026.

NAICS

541519 - Other Computer Related Services

Place of Performance

Fort Huachuca, AZ, USA

Set-Aside

NONE

Documents

This scope was carved out of 842674854.

The full solicitation package (4 documents), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

Endpoint Security Event Management

AI Contract Breakdown

Uniform Contract Format

No documents to break down

The breakdown needs solicitation documents. None were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Defense → It Contracting Division - PL84
ContactsNo contacts available
OfficeN/A
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Performs cybersecurity documentation and administrative tasks for prime contractors on DISA/Army ESEMS projects to maintain Authorization to Operate (ATO). Maintains RMF documentation and eMASS records, reviews DOW STIG documentation, and develops integration guidance for GOTS software. Requires Secret or Top Secret clearance and RMF certifications such as CISSP or CISM. Delivers updated eMASS records and STIG compliance reports.

Similar Contracts

Same NAICS industry code

NAICS: 541519
New
Federal
Endpoint Security Event Management
Solicitation # 842674854
The Defense Information Systems Agency (DISA) is conducting market research through a Sources Sought notice to identify qualified sources for an Endpoint Security Event Management System to support Project Manager Command & Control Infrastructure and Network Enterprise Technology Command. The requirement centers on delivering a comprehensive cybersecurity solution for the Department of War Information Network – Army, with a focus on enabling Zero Trust Architecture through Endpoint Detection and Response, Security Incident and Event Management, Comply to Connect, asset management, advanced analytics, network visualization, and integration with the Army’s Big Data Platform and Identity Credentialing and Access Management services. The system must leverage Microsoft Defender for Endpoint and Elastic Defend to manage EDR across Army Unified Directory Services endpoints, enforce default-deny application controls, automate malware response, restrict removable media, collect behavioral telemetry, ingest STIX/TAXII threat data, and prepare infrastructure for post-quantum cryptography migration. The solution must support global fielding across CONUS and OCONUS locations, including contingency theaters and hazardous duty areas, with simultaneous on-prem and cloud deployments. The contract is anticipated to be a single-award IDIQ with a ceiling value of $850 million and a potential performance period of up to ten years, consisting of a two-year base period followed by eight one-year option periods beginning March 29, 2027. Primary performance will be centered at Fort Huachuca, Arizona, with oversight from Aberdeen Proving Ground, Maryland, and support delivered through four regional cyber centers covering Army installations worldwide. All contractors must hold a Top Secret facility clearance and be capable of providing personnel with at least Secret-level clearances, with the ability to assign Top Secret-cleared individuals for mission-critical tasks. Compliance with DoD cybersecurity standards including RMF, STIGs, IAVAs, and Authorization to Operate is mandatory. Subcontracting is limited under FAR 52.219-14, and companies must demonstrate small business status if applicable, adhere to the NAICS code 541519 with a $34 million size standard, and list qualifying prime contract vehicles such as ENCORE III, SETI, GSA OASIS, ALLIANT II, VETS II, STARS III, MAS, NIH CIO-SP4, and NASA SEWP V. Responses must be submitted via email by 12:30 PM EDT on June 29, 2026, and include business information, CAGE code, socio-economic designation, and a capabilities
It Contracting Division - PL84

POSTED

about 8 hours ago

DEADLINE

in 14 days
View Details
NAICS: 541519
New
Federal
Digital Forensics Examiner Services
Solicitation # N0018927Q00010
The Naval Criminal Investigative Service (NCIS) is seeking a United States-based contractor to provide continued Digital Forensics Examiner Support services for FY27. This 8(a) set-aside procurement, under NAICS code 541519, involves performing complex, non-destructive evaluations of target computer systems and detailed forensic examinations of mobile devices and digital media. These services support law enforcement and counter-intelligence missions by analyzing operating systems, file systems, and user logs to recover evidentiary or intelligence value when digital media are instruments of a crime or victims of network attacks. The scope of work requires the contractor to provide certified personnel who comply with SECNAV M-5239.2 cybersecurity workforce qualifications and the DoD Industrial Security Manual. Performance is centered at multiple locations, including Camp Pendleton, California, as well as field offices in North Carolina, Florida, and at MCAS Miramar, with potential for CONUS and OCONUS travel. Key deliverables include monthly status reports, non-destructive evaluations, and the preservation of digital evidence according to DoD and DoN mandates. Contract administration is managed by the Contracting Officer's Representative (COR), who oversees the inspection of deliverables and the approval of travel and GSA vehicle usage. Performance is measured via a Quality Assurance Surveillance Plan (QASP), requiring that over 95 percent of deliverables be submitted timely and without rework. The contractor must also maintain specific automobile liability insurance and ensure that all personnel meet the required security clearances and professional certifications.
Navsup Flt Logistics Ctr Norfolk

POSTED

about 8 hours ago

DEADLINE

in 7 days
View Details

More opportunities from Department Of Defense → It Contracting Division - PL84

Same awarding agency

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 750+ contractors already using CLEATUS