NCUA Cybersecurity Spt RFI_091725.pdf

PDF 268 KB Posted

Attached to
Request for Information: Cybersecurity and Program Support Federal contract opportunity
Solicitation number
NCUA25RFI0028
Issued by
National Credit Union Administration

About this file

This is a Request for Information (RFI) issued by the National Credit Union Administration (NCUA) seeking capabilities for comprehensive cybersecurity and program support services. The RFI outlines 11 task areas including cybersecurity program support, audit management, security operations, incident management, forensics, threat intelligence, project management, and optional surge support. Respondents are required to provide a detailed capabilities statement addressing technical capabilities across these areas, personnel availability, experience with specific software products (including Axonius, CrowdStrike, Microsoft Defender), and contractual considerations such as available federal contract vehicles and recommended contract types.

The RFI requires interested companies to submit a response by 2:00 p.m. ET on October 8, 2025, via email to VBertucci@ncua.gov, with a maximum 10-page response. Submissions should include a company profile, capabilities overview addressing the detailed task areas, draft Statement of Work comments, and responses to contractual questions about evaluation factors, service level agreements, and estimated levels of effort. The document emphasizes that this is a market research effort only, does not constitute a formal solicitation, and will not result in immediate contract award. All submissions will become government property and will not be returned.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information: Cybersecurity and Program Support, newest first.
File Type Posted
Draft SOW_Cybersecurity Spt.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

For Official Use Only

REQUEST FOR INFORMATION

Request for Information

Cybersecurity and Program Support

ISSUANCE DATE: September 17, 2025

1.0 Background

The National Credit Union Administration (NCUA) is an independent federal agency that regulates, charters, and supervises federal credit unions throughout the United States and its territories. NCUA administers the Federal Credit Union Act created by Congress to serve, protect, and promote a safe, stable national system of cooperative financial institutions that encourage thrift and offer a source of credit for their members. NCUA insures savings in federal and most state-chartered credit unions through the National Credit Union Share Insurance Fund (NCUSIF), a federal fund backed by the full faith and credit of the United States Government.

The NCUSIF insures the savings of more than 143 million credit union account holders.

2.0 Purpose & Objective

THIS IS A REQUEST FOR INFORMATION (RFI) ONLY. The NCUA is seeking information regarding your company’s capabilities with respect to a potential requirement related to the NCUA’s cybersecurity program. The responses from this RFI will assist the NCUA in the acquisition strategy determination and fine tuning our requirements.

This RFI is issued solely for information and planning purposes – it does not constitute a Request for Proposal (RFP) or a promise to issue an RFP in the future. This RFI does not commit the Government to contract for any supply or service whatsoever. Further, the NCUA is not at this time seeking proposals and will not accept unsolicited proposals. Responders are advised that the NCUA will not pay for any information or administrative costs incurred in response to this RFI;

all costs associated with responding to this RFI will be solely at the interested party’s expense.

Not responding to this RFI does not preclude participation in any future RFP, if any is issued.

Please be advised that all submissions become Government property and will not be returned.

Not responding to this RFI does not preclude participation in any future RFP, if any is issued.

Responses to this notice are not offers and cannot be accepted by the Government to form a binding contract.

3.0 Scope of RFI

NCUA is conducting market research to identify companies that can provide services to govern, identify, protect, detect, respond, recover, operate, maintain and continuously improve the NCUA’s cybersecurity program. These requirements are further described in the attached Draft Statement of Work (SOW).

4.0 Capabilities Statement

The requested information is to assist the NCUA in determining the capability of firms in the marketplace. Respondents to this notice shall provide a written capabilities statement which addresses the questions outlined below and any relevant information that specifically addresses the company’s capabilities to provide the services outlined.

National Credit Union Administration Office of Chief Financial Officer (OCFO)

4.1 Company Profile (Cover Page)

1. Vendor Name

2. Vendor Point of Contact (POC)

3. POC Telephone Number

4. POC Email Address

5. Unique Entity ID (SAM)

4.2 Capabilities Statement

The capability statement shall address your ability and experience in providing cybersecurity support services similar to the requirements outlined in the draft SOW.

Specifically, please document in your capability statement to address the following:

Technical:

1. Summarize your company’s capabilities to perform each of the Task Areas identified in the draft SOW. Specifically, provide responses detailing your capabilities providing enterprise-level cybersecurity support services and performing the following functions for a federal agency:

TASK AREA 1: CYBERSECURITY PROGRAM SUPPORT

• Developing cybersecurity policies, plans, and procedures for information systems, to include cloud environments.

• Providing expert guidance and analysis to support the agency’s cybersecurity program, offering ad hoc and strategic input on security policies, risk assessments, emerging threats, and federal compliance requirements.

• Assisting with Authorization & Assessment (A&A) in accordance with (IAW) the National Institute of Standards and Technology Special Publications.

• Ensuring the cybersecurity framework 2.0 is implemented for governing, identifying, protecting, detecting, responding to, and recovering from cyber threats & vulnerabilities.

• Delivering a comprehensive, role-based education program that enhances user vigilance and compliance by integrating phishing simulations, tabletop exercises, outreach campaigns, and cybersecurity awareness initiatives.

TASK AREA 2: AUDIT MANAGEMENT

• Serving as the central coordination point between the Office of Inspector General, IT auditors, and internal stakeholders, ensuring timely delivery of audit artifacts, managing audit communications, tracking findings and remediation, and maintaining documentation integrity across platforms like SharePoint and audit dashboards.

TASK AREA 3: CYBERSECURITY ARCHITECTURE AND ENGINEERING

• Adhering to configuration and change management practices.

• Designing, implementing, and optimizing secure IT infrastructures and enterprise-wide cyber solutions – integrating Zero Trust principles, DevSecOps practices, and advanced security technologies (e.g., SIEM, SOAR, EDR/XDR) – to proactively reduce risk, ensure compliance, and enable resilient, secure operations across all systems and platforms.

• Providing support, identification and integration of innovative/breakthrough technologies (Artificial Intelligence enabled solutions).

TASK AREA 4: SECURITY OPERATIONS

• Using tools to identify, detect, analyze, counter, and mitigate cyber threats and vulnerabilities.

• Managing responses to Cybersecurity and Infrastructure Security Emergency

Directives.

TASK AREA 5: INCIDENT MANAGEMENT

• Validating cybersecurity incidents, assigning severity levels, coordinating with the US-CERT, and managing cross-office response efforts.

• Conducting penetration testing services, including Red Team and Blue Team operations.

TASK AREA 6: FORENSICS SUPPORT, MALWARE ANALYSIS,

ADVANCED THREAT HUNTING, AND E-DISCOVERY

• Identifying, collecting, processing reviewing, and producing electronically stored information in support of legal, regulatory, or investigative needs.

• Acquiring, preserving, and examining digital evidence, while maintaining chain-of-custody, across Windows, Linux, Mac, and mobile platforms.

• Analyzing the behavior and intent of suspicious files using sandboxing, reverse engineering, and static/dynamic analysis techniques.

• Proactively identifying threats that evade traditional detection systems, using threat intelligence to uncover adversary activity across the enterprise environment.

TASK AREA 7: CYBER THREAT INTELLIGENCE AND INFORMATION

SHARING

• Identifying, analyzing, and disseminating actionable intelligence on cyber threats to inform decision-making, support incident response, and enhance the agency’s cybersecurity posture across systems, networks, and cloud environments.

TASK AREA 8: PROJECT MANAGEMENT SUPPORT

• Managing programs and projects using Project Management Institute (PMI) best practices.

• Providing support for the planning, coordination, and execution of technology procurements – ensuring alignment with cybersecurity priorities, budgetary constraints, and federal acquisition regulations – by managing contract lifecycles, capital investments, and performance.

• Developing cybersecurity dashboards for data-driven decision making, transforming complex datasets into actionable insights through interactive dashboards, automated reporting, and executive-level visualizations – supporting transparency and accountability.

OPTIONAL TASK AREA 9: SURGE SUPPORT

• Providing rapid, scalable, and mission-aligned staffing augmentation during periods of heightened operational demand, not to exceed 5% of the annual cost of the contract.

OPTIONAL TASK AREA 10: INFORMATION SYSTEM SECURITY

OFFICER SUPPORT

• Managing the full lifecycle of the Assessment & Authorization process for information systems and services, including preparing and maintaining deliverables required to achieve and sustain an Authority to Operate (ATO) or Authority to Use (ATU).

• Serving as the primary liaison between system owners and stakeholders of the cybersecurity governance framework.

OPTIONAL TASK AREA 11: CYBER SUPPLY CHAIN RISK

MANAGEMENT

• Conducting approved product analysis to ensure uniformity with NCUA security requirements.

• Identifying, assessing, and mitigating risks across the IT product and service lifecycle – ensuring the integrity, security, and resilience of third-party technologies through due diligence, continuous monitoring, and policy-driven controls aligned with NIST.

2. Provide details on your company’s capability to provide the personnel required for this effort in a timely fashion who are United States citizens and have the ability to work on-site at the NCUA Central Office in accordance with SOW Section 7. Also include details regarding your capabilities to provide temporary surge support.

3. Provide a summary of experience using any of the following software products:

• Axonius

• Cellebrite

• Elastic

• Lookout

• Palo Alto Prisma

• Palo Alto Wildfire

• Google Threat Analytics

• Magnet Axiom

• Anomali

• Qualys

• BurpSuite

• Tines

• NinjaOne

• CrowdStrike

• Archer

• Microsoft Defender

• Microsoft Purview

• Microsoft Power Apps / SharePoint

• Exiger

Contractual:

1. Is your solution available under a federal contract vehicle such as GSA, NIH CIO-

SP3, etc.? If so, please provide.

2. Based on the draft SOW, what is your recommendation on contract type (Firm Fixed

Price, Time and Materials, Labor Hour, Mixed)? If mixed, provide recommendations on each Task Area.

3. Based on your knowledge of cybersecurity support services, what type of evaluation factors would you recommend for the NCUA to consider?

4. Based on your knowledge of cybersecurity support services and the NCUA’s draft SOW, what recommendations would you recommend for the draft Service Level Agreement (Key Performance Indicators, Required Service Level, Incentives / Disincentives)?

5. Based on the NCUA’s requirements could you provide an estimated Level of Effort (Total Hours) for each Task Area?

4.3 Draft SOW Comments / Clarifications / Recommendations

We ask that you use this section to provide any comments, clarifications, and/or recommendations to the NCUA’s draft SOW. Identify the page number and section of the SOW in question.

5.0 Submission Requirements

Interested companies are requested to respond to this RFI by 2:00 p.m. ET on October 8, 2025, in a Microsoft compatible file to: VBertucci@ncua.gov. All responses should include the following email subject line: YOUR COMPANY NAME - RFI NCUA Cybersecurity Support. Responses shall be no more than ten (10) pages with the Capabilities Questionnaire response. Those who respond to this RFI should not anticipate feedback with regards to their submission other than acknowledgement of receipt.

Proprietary information, if any, should be minimized and MUST BE CLEARLY MARKED.

Please be advised that all submissions become the property of the Federal Government and will not be returned.

mailto:VBertucci@ncua.gov

REQUEST FOR INFORMATION
1.0 Background
2.0 Purpose & Objective
3.0 Scope of RFI
4.0 Capabilities Statement
4.1 Company Profile (Cover Page)
4.2 Capabilities Statement
4.3 Draft SOW Comments / Clarifications / Recommendations
5.0 Submission Requirements

File details come from the government source that posted it. Updated .