Request for Information: Cybersecurity and Program Support

Closed Pre-Solicitation Posted

Solicitation number
NCUA25RFI0028
Agency
National Credit Union Administration
Responses due
Set-aside
No set-aside

Opportunity facts

NAICS code
541519 Other Computer Related Services
PSC
DJ01 It And Telecom - Security And Compliance Support Services (Labor)
Place of performance
Virginia 22314, United States
Points of contact

Notice details come from SAM.gov. Updated .

About this opportunity

The National Credit Union Administration (NCUA) is conducting a Request for Information to gather market research on comprehensive cybersecurity and program support services for its Office of the Chief Information Officer. This RFI seeks contractor capabilities across 11 task areas including cybersecurity program support, audit management, security operations, incident management, digital forensics, threat intelligence, project management, and optional surge support services. All contractor employees must be U.S. citizens due to the high-risk designation, with personnel performing cyberthreat intelligence work requiring Top Secret security clearance with Sensitive Compartmented Information access. Respondents must demonstrate experience with specific cybersecurity software products including Axonius, CrowdStrike, and Microsoft Defender, along with technical capabilities for vulnerability assessments, penetration testing, and continuous monitoring. The RFI responses are due by 2:00 p.m. ET on October 8, 2025, submitted via email with a maximum 10-page limit including a capabilities questionnaire response.

This opportunity has no set-aside designation and no incumbent contractors are identified in the documentation. The contract structure anticipates a base period of one calendar year with four optional one-year periods, totaling a potential five-year performance period, plus a one-month transition period. Work will be performed primarily at 1775 Duke Street in Alexandria, Virginia, supporting NCUA's cybersecurity operations and strategic objectives. The RFI emphasizes this is strictly for market research purposes and will not result in immediate contract award, with all submissions becoming government property. No specific budget range or award values are disclosed in the pre-solicitation materials, though the comprehensive scope across multiple cybersecurity disciplines suggests a substantial investment in enhancing NCUA's cyber defense capabilities.

Notice text

THIS IS A REQUEST FOR INFORMATION (RFI) ONLY. The NCUA is seeking information regarding your company’s capabilities with respect to a potential requirement related to the NCUA’s cybersecurity program. The responses from this RFI will assist the NCUA in the acquisition strategy determination and fine tuning our requirements. Please see the attached RFI (NCUA Cybersecurity Spt RFI_091725) which details submission requirements and the Draft Statement of Work (Draft SOW_Cybersecurity Spt) which details the draft requirements.

Interested companies are requested to respond to this RFI by 2:00 p.m. ET on October 8, 2025, in a Microsoft compatible file to: VBertucci@ncua.gov. All responses should include the following email subject line: YOUR COMPANY NAME - RFI NCUA Cybersecurity Support. Responses shall be no more than ten (10) pages with the Capabilities Questionnaire response. Those who respond to this RFI should not anticipate feedback with regards to their submission other than acknowledgement of receipt.

Attachments

Files attached to this notice, newest first
File Type Posted
Draft SOW_Cybersecurity Spt.pdf PDF
NCUA Cybersecurity Spt RFI_091725.pdf PDF

On GovTribe

Work this opportunity on GovTribe

  • Track it in your pipeline
  • Find teaming partners
  • Similar opportunities
  • Ask GovTribe AI about this opportunity