Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 5 at 2:00 PM EDT

Register Free →

Security Operations Center (SOC) & Incident Response

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract requires the provision of continuous 24x7x365 cybersecurity services including threat detection, log analysis, incident investigation, and coordinated incident response for systems under the Department of Health and Human Services. These services must align with FISMA requirements and be delivered in accordance with the CSIRC framework to ensure federal compliance and robust security posture. The performance location is designated as Rockville, Maryland, with a zip code of 20852, and the work falls under NAICS code 541612, indicating it is an information technology services subcontract. The solicitation was posted on July 31, 2026, with responses due by August 10, 2026, and the contracting entity is the Omas Strategic Buying Center - Information Technology.

General Info

24x7x365 cybersecurity services for HHS in Rockville, MD, aligned with FISMA and CSIRC, NAICS 541612.

Agency

Department Of Health And Human Services → Omas Strategic Buying Center - Information TechnologyView Agency

NAICS

541612 - Human Resources Consulting ServicesView NAICS

Place of Performance

Rockville, MD, 20852, USA

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Health And Human Services → Omas Strategic Buying Center - Information Technology
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Health And Human Services → Omas Strategic Buying Center - Information Technology
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Deliver 24x7x365 threat detection, log analysis, incident investigation, and response coordination for cybersecurity events across HHS systems in compliance with FISMA and CSIRC.

Similar Contracts

Same NAICS industry code

NAICS: 541612
New
SLED
Cybersecurity and Compliance ManagementThe contract requires ongoing cybersecurity and compliance management services focused on maintaining adherence to NIST SP 800-53 standards, sustaining authority to operate status, implementing robust encryption protocols, and ensuring effective incident response capabilities for payment systems. These responsibilities are critical to safeguarding sensitive financial data and ensuring regulatory alignment across all operational aspects of the systems under management. The work must be performed continuously to uphold security controls, detect and mitigate threats promptly, and respond to breaches in a manner that minimizes disruption and meets state and federal requirements. This subcontract is issued by the California State Controller’s office with a posted date of July 31, 2026, and a response deadline of September 9, 2026. The North American Industry Classification System code 541612 indicates the service falls under computer facilities management services, signaling a need for technical expertise in securing and managing hosted or cloud-based financial infrastructure. The place of performance and point of contact details are not specified, suggesting the work may be performed remotely or across multiple locations within California. All deliverables must align with the state’s cybersecurity framework and support uninterrupted, secure payment processing operations.
State Controller

POSTED

1 day ago

DEADLINE

in about 1 month
View Details
NAICS: 541612
New
SLED
Cybersecurity Compliance Support (Third-Party Assessment Provider)The contract engages a third-party provider to deliver cybersecurity validation services for financial institutions by administering and certifying the Cyber Risk Assessment Questionnaire as an alternative to traditional SOC-2 reports. This arrangement shifts the compliance burden from standardized auditing frameworks to a specialized, tailored assessment process designed to evaluate and validate the cybersecurity postures of financial entities. The provider is responsible for ensuring the integrity, consistency, and regulatory alignment of the questionnaire throughout its deployment, maintaining rigorous standards for certification without reliance on established external audit reports. The agreement is structured as a subcontract under the NAICS code 541612, targeting cybersecurity consulting and related services, with a response deadline of June 1, 2028, and a posted date of July 31, 2026. It is affiliated with the Finance agency in California, though specific office locations and point of contact details are not provided. The scope emphasizes replacing SOC-2 validation with a proprietary assessment framework, implying the need for the provider to establish credible, audit-ready methodologies that financial institutions can confidently use for regulatory and partner compliance purposes. The contract does not specify set-aside status or geographic performance constraints beyond the broader jurisdiction of California.
Finance

POSTED

1 day ago

DEADLINE

in almost 2 years
View Details
NAICS: 541612
New
SLED
Equal Employment Opportunity (EEO) and Contractor Certification ManagementThe contract requires management and administration of key certifications essential for public procurement compliance, including Equal Employment Opportunity (EEO) requirements, a non-collusion affidavit, E-Verify verification, conflict of interest disclosures, and a contingent fee warranty. These certifications must be maintained and submitted by the contractor to ensure adherence to federal and state regulations governing fair hiring practices, transparency in bidding, and employee verification. The obligations are specific to subcontracting under the North American Industry Classification System code 541612, which pertains to management consulting services. All certifications must remain current throughout the contract period, and failure to comply may result in disqualification or penalties. The contract opportunity was posted on July 31, 2026, with a response deadline of August 20, 2026, and is associated with the Finance agency in South Carolina. Although specific office or performance locations are not provided, the requirement applies to all activities under this subcontract, regardless of geographic scope. The contracting entity operates through an online procurement portal, and all submissions and documentation must be managed in accordance with the specified compliance frameworks. There is no set-aside designation, meaning the opportunity is open to all qualified contractors without preference based on size, ownership, or other categories, but full adherence to the listed certifications remains mandatory for eligibility.
Finance

POSTED

1 day ago

DEADLINE

in 18 days
View Details

More opportunities from Department Of Health And Human Services → Omas Strategic Buying Center - Information Technology

Same awarding agency

NAICS: 541512
New
Federal
HHS OCIO OPS Engineering & Security Services
Solicitation # 75P00126Q00021
The Department of Health and Human Services, through its Office of Mission Acquisition Solutions, is issuing a Sources Sought Notice to identify qualified vendors, particularly small businesses, capable of providing enterprise-wide operations engineering and security support services. The requirement centers on five key areas: IT Infrastructure Management, Infrastructure Engineering, Infrastructure Operations, Information Assurance, and Cloud-Based Infrastructure & Identity Management. The North American Industry Classification System code is 541512 with a size standard of $34 million, and responses will help the government evaluate the potential for a small business set aside, though no contract award is intended from this notice. All submissions must include a completed Vendor Questionnaire and supporting documentation such as capabilities statements or product brochures, and must be submitted via email to Julie Rodriguez and John Russell by 9:00 AM ET on August 10, 2026, referencing the notice number 75775P00126Q00021. This notice is strictly for information gathering and carries no obligation for the government to award a contract or compensate respondents. Responses are voluntary and will be used solely to inform future acquisition planning, including the development of a potential solicitation. The government retains the right to use any non-proprietary technical information submitted without obligation or notification, and no classified, confidential, or sensitive data should be included. Small business responses will be prioritized to assess eligibility for set-asides, but submission does not guarantee future opportunity. Respondents should ensure their submissions are detailed enough to demonstrate capability, though the government is under no obligation to acknowledge receipt or provide feedback. All submissions must be sent to the specified email addresses, and the place of performance is Rockville, Maryland.
Computer Systems Design Services

POSTED

1 day ago

DEADLINE

in 8 days
View Details
NAICS: 423430
Federal
Enterprise Laptop Initiative
Solicitation # HHS-DaaS-07-2026
The Department of Health and Human Services is conducting market research under FAR Part 10 to inform the development of a future mandatory enterprise-wide acquisition strategy for end-user computing devices, targeting a potential fiscal year 2027 contract. This Request for Information seeks detailed industry input on optimal models for acquiring and managing approximately 133,000 laptops and 26,800 desktops across HHS divisions, with an estimated total device count of 160,000 and a projected 5% annual growth over five years. The Government is evaluating traditional purchasing, Device as a Service (DaaS), and hybrid approaches, focusing on lifecycle management including provisioning, refresh cycles, warranty handling, disposition, sanitization, and asset tracking. Responses must address transition strategies from existing government-owned fleets over 12 to 36 months, cost comparisons between contractor-owned, government-owned contractor-managed, and hybrid structures, and the feasibility of supporting multiple OEMs—primarily Dell, HP, and Apple—under a single contract vehicle. Specific attention is requested on integration with existing HHS systems for endpoint management, identity, cybersecurity, CMDB, and service desk operations, as well as support for remote, hybrid, and field users. The RFI demands comprehensive insights into operational performance metrics such as time to deploy, repair turnaround, refresh completion rates, user satisfaction, and cost per endpoint, alongside technical capabilities like zero-touch deployment, Autopilot enrollment, encryption, endpoint security compliance, supply chain risk management, and secure disposition procedures. Respondents must outline governance models for catalog management, refresh planning, exception handling, and continuous improvement, and describe how their solutions handle surge demand, supply chain disruptions, and emergency onboarding. Financial modeling is required for a notional five-year lifecycle cost analysis under each acquisition model, including all associated cost drivers such as hardware, accessories, shipping, provisioning, repairs, warranty, asset management, reporting, and disposition. The Government is also exploring alignment with existing governmentwide acquisition vehicles like GSA MAS, NASA SEWP, or other Best in Class contracts and seeks input on preferred contract structures including CLIN design, pricing models (per-device, per-user, subscription, or blended), economic price adjustments, and ordering flexibility for operating divisions. Responses must be submitted as a 50-page PDF narrative by July 29, 2026, with no financial liability assumed by the Government for responses, and proprietary information must be clearly marked. Data required from HHS must be
Computer and Computer Peripheral Equipment and Software Merchant Wholesalers

POSTED

12 days ago

DEADLINE

in 4 days
View Details