ContractSources Sought

FDA Cybersecurity Risk Management and Compliance Services

DEPARTMENT OF HEALTH AND HUMAN SERVICES SS-75F40126Q00036
Response Deadline
Feb 4, 2026
Deadline passed
Days Remaining
0
Closed
Set-Aside
Full & Open
Notice Type
Sources Sought

Contract Opportunity Analysis

The U.S. Food and Drug Administration (FDA) is seeking qualified small businesses, specifically SBA certified 8(a) vendors, to provide Cybersecurity Risk Management and Compliance Services as part of a market research initiative. The primary objective is to enhance the FDA's cybersecurity posture and ensure compliance with federal mandates, including FISMA and Executive Order 14028, by addressing evolving threats to its extensive IT infrastructure. The scope of services includes security authorization support, policy development, Enterprise Governance Risk and Compliance (eGRC) support, and cybersecurity risk management documentation, with the potential for various task order types such as Firm Fixed Price and Labor Hour. Interested parties must submit their responses by February 4, 2026, at 2:00 PM ET, detailing their qualifications and experience, and can contact Michelle Dacanay at michelle.dacanay@fda.hhs.gov for further information.

Solicitation Documents

2 Files
SS_75F40126Q00036 Attachment Draft SOW.pdf
PDF824 KBJan 6, 2026
AI Summary
The FDA is seeking cybersecurity risk management services through a Blanket Purchase Agreement (BPA) to enhance its cybersecurity posture and comply with federal mandates. The services will address evolving threats to the FDA's extensive IT infrastructure, which includes 111 FISMA-reportable systems and various cloud environments. Key objectives include improving security controls, strengthening information security against threats, expanding awareness and collaboration, mitigating IT enterprise weaknesses, and developing IT security policies. The scope covers technical and management services, and subscriptions/licenses. Task areas include security authorization support, policy and data call support, Enterprise Governance Risk and Compliance (eGRC) support, cybersecurity risk management documentation, and transition services. The contract type allows for Firm Fixed Price, Labor Hour, or Time and Material task orders. Personnel must be adequately trained and certified, with specific requirements for Program Managers and Technical Writers. The place of performance is primarily the Washington, D.C. metropolitan area, with remote work options available. The contractor must adhere to stringent security and privacy requirements, including safeguarding sensitive information, mandatory training, incident response protocols, and compliance with federal regulations such as FISMA, NIST, and the Privacy Act.
SS_75F40126Q00036 Cybersecurity Compliance.pdf
PDF292 KBJan 6, 2026
AI Summary
The U.S. Food and Drug Administration (FDA) has issued a Sources Sought Notice (SS-75F40126Q00036) for Cybersecurity Risk Management and Compliance Services. This notice is for market research to identify small businesses, specifically SBA certified 8(a) vendors, under GSA Multiple Award Schedule (MAS) categories 54151S and 54151HACS. The FDA seeks professional services to enhance its cybersecurity posture, aligning with federal mandates like FISMA and EO 14028. The scope includes ongoing security authorization, LMS support, security policy, eGRC support, risk management documentation, and transition services. Responses, due by February 4, 2026, at 2:00 PM ET, should detail contact information, socio-economic status, GSA contract numbers, and experience in security authorizations, FedRAMP, and audit activities.

Related Contract Opportunities

Project Timeline

postedOriginal Solicitation PostedJan 6, 2026
deadlineResponse DeadlineFeb 4, 2026
expiryArchive DateFeb 19, 2026

Agency Information

Department
DEPARTMENT OF HEALTH AND HUMAN SERVICES
Sub-Tier
FOOD AND DRUG ADMINISTRATION
Office
FDA OFFICE OF ACQ GRANT SVCS

Point of Contact

Name
Michelle Dacanay

Place of Performance

St James, Maryland, UNITED STATES

Official Sources