Payment Card Industry Data Security Standard (PCI DSS) Advisory Consultant
Closed Pre-Solicitation Posted
- Solicitation number
- PCI_DSS_Advisory_Consultant
- Agency
- Air Education and Training Command Air Force, Department of Defense
- Responses due
- Set-aside
- No set-aside
Opportunity facts
- NAICS code
- 541618 Other Management Consulting Services
- PSC
- R710 Support- Management: Financial
- Place of performance
- Jbsa Lackland, Texas 78236, United States
- Points of contact
-
- Fay Cameron fay.cameron@us.af.mil (380) 457-1684
- Valerie Baltimore valerie.baltimore@us.af.mil (380) 456-9205
Notice details come from SAM.gov. Updated .
About this opportunity
The Air Force Services Center (AFSVC) is seeking a consulting company to provide expert guidance on achieving and maintaining Payment Card Industry Data Security Standard (PCI DSS) compliance across 104 geographically separated locations. The Department of the Air Force Air Education and Training Command requires a consultant to help develop robust business processes for merchant processing, implement an effective enterprise PCI compliance program, and enhance security across disparate Point of Sale (POS) systems and network infrastructures. Key contract objectives include delivering strategies, tools, and frameworks to mitigate risks associated with payment card processing and improve overall business system cybersecurity. Interested sources are required to respond with questions and recommendations to valerie.baltimore@us.af.mil and fay.cameron@us.af.mil by 4:00 pm CST on February 13, 2025, with answers to be posted on February 21, 2025. Contractor qualifications should include Qualified Security Assessor (QSA) certification and at least five years of enterprise system experience.
The pre-solicitation notice indicates no specific set-aside designations for this opportunity, and the procurement will be conducted through a sources sought market research process. The contract will cover approximately 2,200+ lines of business processing over 13 million annual credit card transactions across hospitality, food and beverage, and entertainment sectors. The period of performance shall not exceed three years, with work to be performed primarily at AFSVC in Port San Antonio, Texas, though remote work is authorized. While a specific award value is not disclosed, the government is seeking labor categories and estimated labor costs to assist in budgeting and understanding potential pricing strategies. The initiative aims to secure expert guidance on industry best practices, with a focus on creating a comprehensive approach to PCI DSS compliance that optimizes business processes and enhances overall payment card data security.
Notice text
3 versions
Update #3 · Latest ·
THIS IS A SOURCES SOUGHT – FOR PLANNING PURPOSES ONLY
The purpose of this Sources Sought notice is to determine availability and capability of qualified businesses. Responses to this notice will be used for informational and planning purposes only and shall not be construed as a solicitation or as an obligation or commitment by the Government. This notice is intended strictly for market research only.
The Government does not intend to award a contract based on responses and the Government is not obligated to and will not pay for information received as a result of this announcement. We are seeking qualified sources for the potential to be added to our vendors list. Below is a brief synopsis of the services to be performed.
Air Force Services Center (AFSVC) is seeking a consulting company to provide AFSVC assistance in creating and developing robust business processes for merchant processing affecting PCI DSS compliance. Additionally, AFSVC is pursuing advisory support to implement an effective enterprise PCI compliance program for an estimated 104 geographically separated locations operating multiple lines of business (i.e., hospitality, food and beverage, entertainment, etc.). The consulting company must have Commercial PCI DSS expertise and a track record of successfully guiding companies in achieving PCI DSS Compliance utilizing industry best practices. They will have worked within the hospitality and entertainment industry, driving compliance success for businesses with a dispersed business model and multiple Point fo Station (POS) systems, lacking a central network infrastructure. Federal government or Department of Defense (DoD) experience is valued. Please see the Statement of Objectives for (SOO) for additional qualification requirements.
Also, AFSVC seeks to secure expert guidance and insights on industry best practices to support AFSVC in achieving and maintaining compliance with the Payment PCI DSS. This initiative will focus on a strategic, business process, and sustainment approach across disparate POS, hardware and software, network infrastructures, and business processes and procedures related to merchant card servicing activities. The goal is to enhance security, mitigate risks, and ensure a robust and comprehensive approach toward compliance while optimizing business processes.
The consultant will deliver strategies, tools, and frameworks to help AFSVC in developing an effective and robust enterprise PCI compliance program to achieve and maintain PCI DSS compliance, mitigate risks associated with payment card processing, and enhance overall business system processes affecting cybersecurity. The consultant will provide ongoing support throughout the implementation phase and ensure readiness for subsequent assessments.
The deliverable will also include a comprehensive suite of integrated tools and strategies that ensure full PCI DSS compliance while improving the overall security and efficiency of payment processing across business operations and geographically separated locations, protecting payment card data and streamlining related processes.
A SOO is attached. We are requesting the specified industry provide questions & recommendations to the SOO to make our final solicitation requirements package better. We would appreciate if you could provide Labor Categories & estimated Labor Cost by category to assist us in budgeting and to understand the pricing strategy for this type of requirement.
Interested Sources shall respond with questions/comments related to this Sources Sought to valerie.baltimore@us.af.mil and fay.cameron@us.af.mil no later than 4:00 pm CST on Thursday, February 13, 2025. Answers to questions will be posted at 4:00 pm CST February 21, 2025. This RFI closes at 4:00 pm CST March, 6 2025.
Update: Answers will not be posted on 21 Feb 2025 due to pending responses from subject matter experts for questions received. We will provide an update on Tuesday, 25 Feb 2025, on when answers will be available. Thank you.
Update #2 ·
THIS IS A SOURCES SOUGHT – FOR PLANNING PURPOSES ONLY
The purpose of this Sources Sought notice is to determine availability and capability of qualified businesses. Responses to this notice will be used for informational and planning purposes only and shall not be construed as a solicitation or as an obligation or commitment by the Government. This notice is intended strictly for market research only.
The Government does not intend to award a contract based on responses and the Government is not obligated to and will not pay for information received as a result of this announcement. We are seeking qualified sources for the potential to be added to our vendors list. Below is a brief synopsis of the services to be performed.
Air Force Services Center (AFSVC) is seeking a consulting company to provide AFSVC assistance in creating and developing robust business processes for merchant processing affecting PCI DSS compliance. Additionally, AFSVC is pursuing advisory support to implement an effective enterprise PCI compliance program for an estimated 104 geographically separated locations operating multiple lines of business (i.e., hospitality, food and beverage, entertainment, etc.). The consulting company must have Commercial PCI DSS expertise and a track record of successfully guiding companies in achieving PCI DSS Compliance utilizing industry best practices. They will have worked within the hospitality and entertainment industry, driving compliance success for businesses with a dispersed business model and multiple Point fo Station (POS) systems, lacking a central network infrastructure. Federal government or Department of Defense (DoD) experience is valued. Please see the Statement of Objectives for (SOO) for additional qualification requirements.
Also, AFSVC seeks to secure expert guidance and insights on industry best practices to support AFSVC in achieving and maintaining compliance with the Payment PCI DSS. This initiative will focus on a strategic, business process, and sustainment approach across disparate POS, hardware and software, network infrastructures, and business processes and procedures related to merchant card servicing activities. The goal is to enhance security, mitigate risks, and ensure a robust and comprehensive approach toward compliance while optimizing business processes.
The consultant will deliver strategies, tools, and frameworks to help AFSVC in developing an effective and robust enterprise PCI compliance program to achieve and maintain PCI DSS compliance, mitigate risks associated with payment card processing, and enhance overall business system processes affecting cybersecurity. The consultant will provide ongoing support throughout the implementation phase and ensure readiness for subsequent assessments.
The deliverable will also include a comprehensive suite of integrated tools and strategies that ensure full PCI DSS compliance while improving the overall security and efficiency of payment processing across business operations and geographically separated locations, protecting payment card data and streamlining related processes.
A SOO is attached. We are requesting the specified industry provide questions & recommendations to the SOO to make our final solicitation requirements package better. We would appreciate if you could provide Labor Categories & estimated Labor Cost by category to assist us in budgeting and to understand the pricing strategy for this type of requirement.
Interested Sources shall respond with questions/comments related to this Sources Sought to valerie.baltimore@us.af.mil and fay.cameron@us.af.mil no later than 4:00 pm CST on Thursday, February 13, 2025. Answers to questions will be posted at 4:00 pm CST February 21, 2025. This RFI closes at 4:00 pm CST March, 6 2025.
Update #1 ·
THIS IS A SOURCES SOUGHT – FOR PLANNING PURPOSES ONLY
The purpose of this Sources Sought notice is to determine availability and capability of qualified businesses. Responses to this notice will be used for informational and planning purposes only and shall not be construed as a solicitation or as an obligation or commitment by the Government. This notice is intended strictly for market research only.
The Government does not intend to award a contract based on responses and the Government is not obligated to and will not pay for information received as a result of this announcement. We are seeking qualified sources for the potential to be added to our vendors list. Below is a brief synopsis of the services to be performed.
Air Force Services Center (AFSVC) is seeking a consulting company to provide AFSVC assistance in creating and developing robust business processes for merchant processing affecting PCI DSS compliance. Additionally, AFSVC is pursuing advisory support to implement an effective enterprise PCI compliance program for an estimated 104 geographically separated locations operating multiple lines of business (i.e., hospitality, food and beverage, entertainment, etc.).
Also, AFSVC seeks to secure expert guidance and insights on industry best practices to support AFSVC in achieving and maintaining compliance with the Payment PCI DSS. This initiative will focus on a strategic, business process, and sustainment approach across disparate Point of Sale (POS), hardware and software, network infrastructures, and business processes and procedures related to merchant card servicing activities. The goal is to enhance security, mitigate risks, and ensure a robust and comprehensive approach toward compliance while optimizing business processes.
The consultant will deliver strategies, tools, and frameworks to help AFSVC in developing an effective and robust enterprise PCI compliance program to achieve and maintain PCI DSS compliance, mitigate risks associated with payment card processing, and enhance overall business system processes affecting cybersecurity. The consultant will provide ongoing support throughout the implementation phase and ensure readiness for subsequent assessments.
The deliverable will also include a comprehensive suite of integrated tools and strategies that ensure full PCI DSS compliance while improving the overall security and efficiency of payment processing across business operations and geographically separated locations, protecting payment card data and streamlining related processes.
A Statement of Objectives (SOO) is attached. We are requesting the specified industry provide questions & recommendations to the SOO to make our final solicitation requirements package better. We would appreciate if you could provide Labor Categories & estimated Labor Cost by category to assist us in budgeting and to understand the pricing strategy for this type of requirement.
Interested Sources shall respond with questions/comments related to this Sources Sought to valerie.baltimore@us.af.mil and fay.cameron@us.af.mil no later than 4:00 pm CST on Thursday, February 13, 2025. Answers to questions will be posted at 4:00 pm CST February 21, 2025.
Attachments
| File | Type | Posted |
|---|---|---|
| Q and A PCI DSS Consultant.pdf | ||
| Attachment 1 Verizon Gap Analysis.pdf | ||
| SOO - PCI Advisory Consultant 7 Feb 2025.pdf | ||
| SOO - PCI Advisory Consultant 7 Feb 2025.docx | DOCX document | |
| SOO - PCI Advisory Consultant 7 Feb 2025.docx | DOCX document |
On GovTribe
Work this opportunity on GovTribe
- Track it in your pipeline
- Find teaming partners
- Similar opportunities
- Ask GovTribe AI about this opportunity