FDA Cybersecurity Risk Management and Compliance Services
Contract Opportunity Analysis
The U.S. Food and Drug Administration (FDA) is seeking qualified small businesses, specifically SBA certified 8(a) vendors, to provide Cybersecurity Risk Management and Compliance Services as part of a market research initiative. The primary objective is to enhance the FDA's cybersecurity posture and ensure compliance with federal mandates, including FISMA and Executive Order 14028, by addressing evolving threats to its extensive IT infrastructure. The scope of services includes security authorization support, policy development, Enterprise Governance Risk and Compliance (eGRC) support, and cybersecurity risk management documentation, with the potential for various task order types such as Firm Fixed Price and Labor Hour. Interested parties must submit their responses by February 4, 2026, at 2:00 PM ET, detailing their qualifications and experience, and can contact Michelle Dacanay at michelle.dacanay@fda.hhs.gov for further information.