ATO Cybersecurity Testing (DRAFT SIR)
Closed Pre-Solicitation Posted
A newer special notice was posted. See the latest special notice from .
- Solicitation number
- 693KA8-20-R-00017
- Agency
- Headquarters Federal Aviation Administration, Department of Transportation
- Responses due
- Set-aside
- Total Small Business
Opportunity facts
- NAICS code
- 541519 Other Computer Related Services
Notice details come from SAM.gov. Updated .
About this opportunity
The Federal Aviation Administration is seeking to establish an independent risk assessment and cybersecurity testing services contract to meet its continuous monitoring requirements under the Federal Information Security Management Act and other directives. Services will include program management, security assessments, vulnerability analysis, penetration testing, aircraft testing, and specialized assessments across multiple FAA facilities nationwide. Interested small businesses may submit feedback on the draft solicitation and attachments by July 31, 2020 to inform finalization. Responses will be evaluated based on reference to specific document sections and pages.
This pre-solicitation notice establishes a small business set-aside, with a period of performance of one base year plus four option years. The contract will utilize time-and-materials pricing for various labor categories and other direct costs. Services will support over 100 FAA information systems categorized under NIST standards for potential confidentiality, integrity and availability impacts. The NAICS code is 541511 and PSC code is D302. The total contract value is estimated between $50-100M over the five-year period of performance.
Notice text
2 versions
Update #2 · Latest ·
The FAA is currently in the planning stages of a Small Business Set-Aside.
Background:
Market Survey / Request for Information #34910 was posted in October 2019 for the purpose of soliciting
feedback from Industry. This posting closed November 2019 and the FAA is not looking for any further input pertaining to this Market Survey.
Introduction:
The sustainment of Independent Risk Assessment capabilities, Information Systems Security (ISS)
Assurance and the performance of penetration testing are key components in meeting Office of
Management and Budget’s (OMB) continuous monitoring requirement, Federal Information Security
Management Act (FISMA), and Executive Order 13636 and its implementation through Presidential
Policy Directive (PPD-21) and the ATO Cyber Security Strategic Plan.
Objective:
The objective of this posting is to provide Industry with the opportunity to have a preliminary review of the DRAFT SIR and available attachments.
Response Guidance:
The FAA intends to review all responses received and to use the informtion towards maturing the FINAL SIR PACKET. The FAA may determine not to respond to one or any comment, question, or other feedback received from interested parties. All information received will become the property of the FAA unless otherwise marked.
Industry is to provide their comments, questions, concerns cross-referecing the document/section/page if possible in writing. The FAA will post their responses NLT at the time of the posting of the Official SIR. Please note that the Official SIR will also allow an opportuntiy for clarity and additional information pertaining to Q&A will be made available in that post.
The FAA also asks that when submitting your Q&As to please provide a copy of your SAM registration.
Please sunmit your written Q&As via email to Contracting Officer, Leslie.fisher@faa.gov, NLT 3 pm. EST., July 31, 2020 . Please, do not call the Contracting officer or program office. The FAA is not entertaining individual conference calls or any other requests for meetings or one-on-one calls.
Interested parties are advised that all costs associated with responding to this announcement are the responsibility of the responding party.
Update #1 ·
The FAA is currently in the planning stages of a Small Business Set-Aside.
Background:
Market Survey / Request for Information #34910 was posted in October 2019 for the purpose of soliciting
feedback from Industry. This posting closed November 2019 and the FAA is not looking for any further input pertaining to this Market Survey.
Introduction:
The sustainment of Independent Risk Assessment capabilities, Information Systems Security (ISS)
Assurance and the performance of penetration testing are key components in meeting Office of
Management and Budget’s (OMB) continuous monitoring requirement, Federal Information Security
Management Act (FISMA), and Executive Order 13636 and its implementation through Presidential
Policy Directive (PPD-21) and the ATO Cyber Security Strategic Plan.
Objective:
The objective of this posting is to provide Industry with the opportunity to have a preliminary review of the DRAFT SIR and available attachments.
Response Guidance:
The FAA intends to review all responses received and to use the informtion towards maturing the FINAL SIR PACKET. The FAA may determine not to respond to one or any comment, question, or other feedback received from interested parties. All information received will become the property of the FAA unless otherwise marked.
Industry is to provide there comments, questions, concerns crossreferecing the document/section/page if possible. The FAA will post their response NLT the posting of the Official SIR. Please note that the Official SIR will allow an opportuntiy for clarity and additional information will be made available at that time. The FAA also asks that when submitting your Q&As to please provide a copy of your SAM registration.
Please email Contracting Officer, Leslie.fisher@faa.gov, NLT 3 pm. EST., July 31, 2020 . Please, we ask that you not call the Contracting officer or program office. The FAA is not entertaining individual conference calls or other like contact.
Interested parties are advised that all costs associated with responding to this announcement are the responsibility of the responding party.
Attachments
| File | Type | Posted |
|---|---|---|
| Attachment _ FISMA Systems.xlsx | XLSX spreadsheet | |
| Attachment L002 - Section B - Price Worksheet.xlsx | XLSX spreadsheet | |
| Attachment L003 - Past Performance Questionnaire.docx | DOCX document | |
| J Attach J002 - Labor Category Descriptions and Qualifications.docx | DOCX document | |
| Attachment L001 - Q and A Template (1).xlsx | XLSX spreadsheet | |
| Cybersecurity Testing DRAFT SIR _ 693KA8-20-R-00017.pdf | ||
| Attachment _ NIST.FIPS.199.pdf |
Notice history
| Notice | Type | Posted |
|---|---|---|
| Single Source Notification _ SPECIAL NOTICE | Special Notice | |
| Notice of award - cybersecurity test - notice of award | Solicitation | |
| ATO Cybersecurity Testing (DRAFT SIR) | Pre-Solicitation |
On GovTribe
Work this opportunity on GovTribe
- Track it in your pipeline
- Find teaming partners
- Similar opportunities
- Ask GovTribe AI about this opportunity