Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 19 at 2:00 PM EDT

Register Free →

Security, Privacy, and Compliance Documentation

Active
Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

This subcontract opportunity with the CDC Office of Acquisition Services under the Department of Health and Human Services requires the preparation and submission of FedRAMP-compliant security and privacy documentation. The primary objective is to support the Authority to Deploy for the VAERS system through the development of a Privacy Threshold Analysis, Privacy Impact Assessment, System Security Plan, Security Assessment Report, and Plan of Action and Milestones. The procurement is designated as a total Small Business Set Aside under NAICS code 541618. Interested parties must submit their responses by September 4, 2026, at 2:00 PM. Performance of the contract is centered in the 30341 zip code area.

General Info

CDC small business subcontract for FedRAMP security and privacy documentation due September 4, 2026.

Agency

Department Of Health And Human Services → CDC Office Of Acquisition ServicesView Agency

NAICS

541618 - Other Management Consulting ServicesView NAICS

Place of Performance

GA, 30341, USA

Set-Aside

SBA

Documents

This scope was carved out of 75D301-26-Q-00146.

The full solicitation package (1 document), including the RFP, is on the prime solicitation, not on this scope.

View the prime solicitation

Modernized VAERS Reporting Application

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

Posted

subcontract

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Health And Human Services → CDC Office Of Acquisition Services
ContactsNo contacts available
OfficeN/A
Organization / Agency
Department Of Health And Human Services → CDC Office Of Acquisition Services
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
Prepare and submit FedRAMP-compliant security and privacy documentation including PTA, PIA, SSP, SAR, and POA&M to support Authority to Deploy (ATD) for the VAERS system.

Similar Contracts

Same NAICS industry code

More opportunities from Department Of Health And Human Services → CDC Office Of Acquisition Services

Same awarding agency

NAICS: 541511
New
Federal
Modernized VAERS Reporting Application
Solicitation # 75D301-26-Q-00146
The Department of Health and Human Services, through the CDC Office of Acquisition Services, is seeking a small business contractor to develop a modernized web application for the Vaccine Adverse Event Reporting System (VAERS). This firm fixed price effort focuses on enhancing the reporting experience for consumers and healthcare providers through a redesigned landing page, a guided workflow with branching logic, intelligent form validation, and a low-code backend for CDC staff. The project requires a responsive design compatible with both mobile and desktop platforms and must be integrated within the CDC's Microsoft Azure cloud environment. Performance is scheduled from September 28, 2026, to June 27, 2027, with a primary remote place of performance and coordination based in Atlanta, Georgia. The acquisition is a total small business set-aside under NAICS 541511, with an award based on a best value tradeoff. Evaluation factors prioritize technical merit, management approach, and similar experience over price. The contractor must adhere to stringent federal standards, including FISMA, FedRAMP, HIPAA, and Section 508 accessibility. Key deliverables include UX design artifacts, vulnerability scan reports, and a transition-out plan. Security requirements are rigorous, necessitating specific personnel investigation tiers and the signing of non-disclosure agreements. Payments will be processed electronically via the Department of Treasury Invoice Processing Platform.
Custom Computer Programming Services

POSTED

about 9 hours ago

DEADLINE

in 18 days
View Details