USCG Information Assurance (IA) Risk Management Framework (RMF) Services
Closed Pre-Solicitation Posted
This opportunity was awarded. See the award notice from , or the latest solicitation from .
- Solicitation number
- 70Z04423IESDIAB01
- Agency
- Coast Guard Department of Homeland Security
- Responses due
- Set-aside
- Competitive 8(a)
Opportunity facts
- NAICS code
- 541519 Other Computer Related Services
Notice details come from SAM.gov. Updated .
About this opportunity
The Federal Contract Opportunity involves the provision of various labor categories including Program Manager, Project Manager, Program Analyst, Security Control Assessor, Information System Security Officer, Information System Security Engineer, Database Specialist, and Data Analyst. These roles will be responsible for tasks such as contract management, task/delivery order interface, data analysis, security control assessment, risk analysis, database administration, and data interpretation. The contract also includes the provision of Risk Management Framework (RMF) Support Services for the U.S. Coast Guard. The contract is expected to be awarded as a single-award Indefinite Delivery Indefinite Quantity (IDIQ) contract with a maximum estimated value of $160M and a five-year ordering period.
List of services and products to be provided:
- Program Management services
- Project Management services
- Program Analysis services
- Security Control Assessment services
- Information System Security services
- Information System Security Engineering services
- Database Administration services
- Data Analysis services
- Risk Management Framework (RMF) Support Services for the U.S. Coast Guard.
Notice text
4 versions
Update #4 · Latest ·
Post-RFI Update #3 (12/14/2023):
Due to delays in the internal business clearance process, RFP release is now expected in the late January 2024 timeframe.
Post-RFI Update #2 (11/7/2023):
Due to delays in the internal business clearance process, RFP release is now expected in the early December 2023 timeframe.
Post-RFI Update (8/11/2023):
(1) The Combined Synoposis/Solicitation/Request for Proposal (RFP) is anticipated for release in September 2023.
(2) Please see new attachment "RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23" for Government responses to selected vendor questions and comments from the Request For Information (RFI) responses.
(3) Please see the added web links (direct links in "Attachments/Links" section below) providing brief overviews of the USCG Programs anticipated to be supported under this requirement:
CG Headquarters, CG-933: https://www.dvidshub.net/video/888637/coast-guard-cg-933-program-office-industry-overview-presentation
CG Surface Forces Logistics Center (SFLC): https://www.dvidshub.net/video/888639/coast-guard-cybersecurity-sflc-overview-challenges-industry-presentation
CG Command, Control, Communications, Computers, Cyber and Intelligence Service Center (C5I SC): https://www.dvidshub.net/video/888638/coast-guard-c5isc-information-assurance-branch-customer-industry-overview-presentation
*************** THE RFI RESPONSE PERIOD IS CLOSED. ****************
Request for Information #: 70Z04423IESDIAB01
Information Assurance (IA) Risk Management Framework (RMF) Services
Disclaimer and Important Notes: This is a Request for Information (RFI) and is issued solely for informational, market research, and planning purposes. This is not a Request for Proposals or a Request for Quotations, and it is not considered to be a commitment by the Government to award a contract/order nor is the Government responsible for any costs incurred in furnishing information provided under this RFI. No basis for claim against the Government shall arise as a result from a response to this RFI or Government use of any information provided. Further, the Government is not seeking proposals and will not accept unsolicited proposals at this time. No proprietary, classified, confidential, or sensitive information should be included in your response to this RFI. The Government reserves the right to use any information provided by respondents for any purpose deemed necessary and legally appropriate, including using technical information provided by respondents in any resultant solicitation. Responses will assist the Government in determining the availability of potential solutions. The information and requirements in this RFI, and any attachments, is subject to change at the sole discretion of the Government.
Requirement: The Command Control Communications Cyber and Intelligence Service Center (C5ISC) Information Assurance (IA) Branch, the Surface Forces Logistics Center (SFLC), and the C5I Acquisition Directorate (CG-933) provide comprehensive IA services prescribed by the Risk Management Framework (RMF) for over 150 enterprise information technology (IT) systems and platform IT systems, to include those aboard USCG Cutters. These services are essential to ensuring the confidentiality, integrity, and availability of our IT systems. Contract services for labor are required by the C5ISC IA Program, SFLC and CG-933, including Information System Security Officer (ISSO) and Alternate ISSO (AISSO) services, Information System Security Engineer (ISSE) services, Security Control Assessor (SCA) services, and Cybersecurity Compliance and Readiness Services in support of the USCG Cybersecurity RMF process and cybersecurity of USCG Information Systems. (See attached DRAFT IDIQ contract Scope of Work and first Task Order Performance Work Statement [PWS])
The anticipated NAICS Code for this requirement is 541519 – Other Computer Related Services.
The anticipated Product Service Code (PSC) is DJ01 – IT and Telecom - Security And Compliance Support Services (Labor).
DHS Acquisition Planning Forecast System (APFS) Number: F2022058687
Small Business Set-Aside: 100% set-aside for qualified 8(a) businesses.
SAM: Contractors doing business with the Government are required to register in the System for Award Management (SAM) database. Information regarding SAM registration can be found at: SAM.gov | Entity Registrations
Submission of Information: Interested parties are encouraged to submit an RFI response which supports the company's claim that it presently has the technology, qualifications, experience, and capabilities to satisfy the requirements.
Specifically, interested parties are requested to provide the following information in an RFI response:
- Response to all questions in “Attachment 1 – Questionnaire”.
- A DRAFT IDIQ contract Solicitation and Attachments (Attachments 2 through 4) and DRAFT Task Order PWS (Attachment 5) are attached to allow prospective offerors the opportunity to review and provide comments/questions regarding the requirements and terms/conditions. A “commented” version of the Draft documents should be submitted as part of your RFI response, if applicable. (Click the “Review” tab within the MS Word document. Then click or highlight the area of concern in the document and click “New Comment” to write your comment.) Please use Attachment 6, Vendor Questions/Comments Form, to submit any other questions or comments related to this RFI.
- Please identify all concerns with the draft IDIQ RFP/Scope and Task Order PWS.
Total combined file sizes cannot be more than 10MB total per email. Zip files shall not be submitted.
Submit your RFI response(s) electronically via e-mail to:
Eric St. Pierre at Eric.R.St.Pierre@uscg.mil and
Jessica Coltz at Jessica.L.Coltz@uscg.mil.
RFI responses are due by June 26, 2023, at 11:00AM, Eastern Time.
Upon receiving RFI responses, the Coast Guard will assess all feedback and its impact on the development of the final specifications and acquisition strategy to meet the Government’s requirements.
List of RFI Attachments:
Attachment 1 – RFI Questionnaire
Attachment 2 – Draft Request For Proposal (DRFP)
Attachment 3 – Draft IDIQ Contract Scope of Work
Attachment 4 – Draft IDIQ Contract Labor Categories
Attachment 5 – Draft of first Task Order Performance Work Statement (PWS)
Attachment 6 – Vendor Questions/Comments Form
Update #3 ·
Post-RFI Update #2 (11/7/2023):
Due to delays in the internal business clearance process, RFP release is now expected in the early December 2023 timeframe.
Post-RFI Update (8/11/2023):
(1) The Combined Synoposis/Solicitation/Request for Proposal (RFP) is anticipated for release in September 2023.
(2) Please see new attachment "RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23" for Government responses to selected vendor questions and comments from the Request For Information (RFI) responses.
(3) Please see the added web links (direct links in "Attachments/Links" section below) providing brief overviews of the USCG Programs anticipated to be supported under this requirement:
CG Headquarters, CG-933: https://www.dvidshub.net/video/888637/coast-guard-cg-933-program-office-industry-overview-presentation
CG Surface Forces Logistics Center (SFLC): https://www.dvidshub.net/video/888639/coast-guard-cybersecurity-sflc-overview-challenges-industry-presentation
CG Command, Control, Communications, Computers, Cyber and Intelligence Service Center (C5I SC): https://www.dvidshub.net/video/888638/coast-guard-c5isc-information-assurance-branch-customer-industry-overview-presentation
*************** THE RFI RESPONSE PERIOD IS CLOSED. ****************
Request for Information #: 70Z04423IESDIAB01
Information Assurance (IA) Risk Management Framework (RMF) Services
Disclaimer and Important Notes: This is a Request for Information (RFI) and is issued solely for informational, market research, and planning purposes. This is not a Request for Proposals or a Request for Quotations, and it is not considered to be a commitment by the Government to award a contract/order nor is the Government responsible for any costs incurred in furnishing information provided under this RFI. No basis for claim against the Government shall arise as a result from a response to this RFI or Government use of any information provided. Further, the Government is not seeking proposals and will not accept unsolicited proposals at this time. No proprietary, classified, confidential, or sensitive information should be included in your response to this RFI. The Government reserves the right to use any information provided by respondents for any purpose deemed necessary and legally appropriate, including using technical information provided by respondents in any resultant solicitation. Responses will assist the Government in determining the availability of potential solutions. The information and requirements in this RFI, and any attachments, is subject to change at the sole discretion of the Government.
Requirement: The Command Control Communications Cyber and Intelligence Service Center (C5ISC) Information Assurance (IA) Branch, the Surface Forces Logistics Center (SFLC), and the C5I Acquisition Directorate (CG-933) provide comprehensive IA services prescribed by the Risk Management Framework (RMF) for over 150 enterprise information technology (IT) systems and platform IT systems, to include those aboard USCG Cutters. These services are essential to ensuring the confidentiality, integrity, and availability of our IT systems. Contract services for labor are required by the C5ISC IA Program, SFLC and CG-933, including Information System Security Officer (ISSO) and Alternate ISSO (AISSO) services, Information System Security Engineer (ISSE) services, Security Control Assessor (SCA) services, and Cybersecurity Compliance and Readiness Services in support of the USCG Cybersecurity RMF process and cybersecurity of USCG Information Systems. (See attached DRAFT IDIQ contract Scope of Work and first Task Order Performance Work Statement [PWS])
The anticipated NAICS Code for this requirement is 541519 – Other Computer Related Services.
The anticipated Product Service Code (PSC) is DJ01 – IT and Telecom - Security And Compliance Support Services (Labor).
DHS Acquisition Planning Forecast System (APFS) Number: F2022058687
Small Business Set-Aside: 100% set-aside for qualified 8(a) businesses.
SAM: Contractors doing business with the Government are required to register in the System for Award Management (SAM) database. Information regarding SAM registration can be found at: SAM.gov | Entity Registrations
Submission of Information: Interested parties are encouraged to submit an RFI response which supports the company's claim that it presently has the technology, qualifications, experience, and capabilities to satisfy the requirements.
Specifically, interested parties are requested to provide the following information in an RFI response:
- Response to all questions in “Attachment 1 – Questionnaire”.
- A DRAFT IDIQ contract Solicitation and Attachments (Attachments 2 through 4) and DRAFT Task Order PWS (Attachment 5) are attached to allow prospective offerors the opportunity to review and provide comments/questions regarding the requirements and terms/conditions. A “commented” version of the Draft documents should be submitted as part of your RFI response, if applicable. (Click the “Review” tab within the MS Word document. Then click or highlight the area of concern in the document and click “New Comment” to write your comment.) Please use Attachment 6, Vendor Questions/Comments Form, to submit any other questions or comments related to this RFI.
- Please identify all concerns with the draft IDIQ RFP/Scope and Task Order PWS.
Total combined file sizes cannot be more than 10MB total per email. Zip files shall not be submitted.
Submit your RFI response(s) electronically via e-mail to:
Eric St. Pierre at Eric.R.St.Pierre@uscg.mil and
Jessica Coltz at Jessica.L.Coltz@uscg.mil.
RFI responses are due by June 26, 2023, at 11:00AM, Eastern Time.
Upon receiving RFI responses, the Coast Guard will assess all feedback and its impact on the development of the final specifications and acquisition strategy to meet the Government’s requirements.
List of RFI Attachments:
Attachment 1 – RFI Questionnaire
Attachment 2 – Draft Request For Proposal (DRFP)
Attachment 3 – Draft IDIQ Contract Scope of Work
Attachment 4 – Draft IDIQ Contract Labor Categories
Attachment 5 – Draft of first Task Order Performance Work Statement (PWS)
Attachment 6 – Vendor Questions/Comments Form
Update #2 ·
Post-RFI Update (8/11/2023):
(1) The Combined Synoposis/Solicitation/Request for Proposal (RFP) is anticipated for release in September 2023.
(2) Please see new attachment "RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23" for Government responses to selected vendor questions and comments from the Request For Information (RFI) responses.
(3) Please see the added web links (direct links in "Attachments/Links" section below) providing brief overviews of the USCG Programs anticipated to be supported under this requirement:
CG Headquarters, CG-933: https://www.dvidshub.net/video/888637/coast-guard-cg-933-program-office-industry-overview-presentation
CG Surface Forces Logistics Center (SFLC): https://www.dvidshub.net/video/888639/coast-guard-cybersecurity-sflc-overview-challenges-industry-presentation
CG Command, Control, Communications, Computers, Cyber and Intelligence Service Center (C5I SC): https://www.dvidshub.net/video/888638/coast-guard-c5isc-information-assurance-branch-customer-industry-overview-presentation
*************** THE RFI RESPONSE PERIOD IS CLOSED. ****************
Request for Information #: 70Z04423IESDIAB01
Information Assurance (IA) Risk Management Framework (RMF) Services
Disclaimer and Important Notes: This is a Request for Information (RFI) and is issued solely for informational, market research, and planning purposes. This is not a Request for Proposals or a Request for Quotations, and it is not considered to be a commitment by the Government to award a contract/order nor is the Government responsible for any costs incurred in furnishing information provided under this RFI. No basis for claim against the Government shall arise as a result from a response to this RFI or Government use of any information provided. Further, the Government is not seeking proposals and will not accept unsolicited proposals at this time. No proprietary, classified, confidential, or sensitive information should be included in your response to this RFI. The Government reserves the right to use any information provided by respondents for any purpose deemed necessary and legally appropriate, including using technical information provided by respondents in any resultant solicitation. Responses will assist the Government in determining the availability of potential solutions. The information and requirements in this RFI, and any attachments, is subject to change at the sole discretion of the Government.
Requirement: The Command Control Communications Cyber and Intelligence Service Center (C5ISC) Information Assurance (IA) Branch, the Surface Forces Logistics Center (SFLC), and the C5I Acquisition Directorate (CG-933) provide comprehensive IA services prescribed by the Risk Management Framework (RMF) for over 150 enterprise information technology (IT) systems and platform IT systems, to include those aboard USCG Cutters. These services are essential to ensuring the confidentiality, integrity, and availability of our IT systems. Contract services for labor are required by the C5ISC IA Program, SFLC and CG-933, including Information System Security Officer (ISSO) and Alternate ISSO (AISSO) services, Information System Security Engineer (ISSE) services, Security Control Assessor (SCA) services, and Cybersecurity Compliance and Readiness Services in support of the USCG Cybersecurity RMF process and cybersecurity of USCG Information Systems. (See attached DRAFT IDIQ contract Scope of Work and first Task Order Performance Work Statement [PWS])
The anticipated NAICS Code for this requirement is 541519 – Other Computer Related Services.
The anticipated Product Service Code (PSC) is DJ01 – IT and Telecom - Security And Compliance Support Services (Labor).
DHS Acquisition Planning Forecast System (APFS) Number: F2022058687
Small Business Set-Aside: 100% set-aside for qualified 8(a) businesses.
SAM: Contractors doing business with the Government are required to register in the System for Award Management (SAM) database. Information regarding SAM registration can be found at: SAM.gov | Entity Registrations
Submission of Information: Interested parties are encouraged to submit an RFI response which supports the company's claim that it presently has the technology, qualifications, experience, and capabilities to satisfy the requirements.
Specifically, interested parties are requested to provide the following information in an RFI response:
- Response to all questions in “Attachment 1 – Questionnaire”.
- A DRAFT IDIQ contract Solicitation and Attachments (Attachments 2 through 4) and DRAFT Task Order PWS (Attachment 5) are attached to allow prospective offerors the opportunity to review and provide comments/questions regarding the requirements and terms/conditions. A “commented” version of the Draft documents should be submitted as part of your RFI response, if applicable. (Click the “Review” tab within the MS Word document. Then click or highlight the area of concern in the document and click “New Comment” to write your comment.) Please use Attachment 6, Vendor Questions/Comments Form, to submit any other questions or comments related to this RFI.
- Please identify all concerns with the draft IDIQ RFP/Scope and Task Order PWS.
Total combined file sizes cannot be more than 10MB total per email. Zip files shall not be submitted.
Submit your RFI response(s) electronically via e-mail to:
Eric St. Pierre at Eric.R.St.Pierre@uscg.mil and
Jessica Coltz at Jessica.L.Coltz@uscg.mil.
RFI responses are due by June 26, 2023, at 11:00AM, Eastern Time.
Upon receiving RFI responses, the Coast Guard will assess all feedback and its impact on the development of the final specifications and acquisition strategy to meet the Government’s requirements.
List of RFI Attachments:
Attachment 1 – RFI Questionnaire
Attachment 2 – Draft Request For Proposal (DRFP)
Attachment 3 – Draft IDIQ Contract Scope of Work
Attachment 4 – Draft IDIQ Contract Labor Categories
Attachment 5 – Draft of first Task Order Performance Work Statement (PWS)
Attachment 6 – Vendor Questions/Comments Form
Update #1 ·
Request for Information #: 70Z04423IESDIAB01
Information Assurance (IA) Risk Management Framework (RMF) Services
Disclaimer and Important Notes: This is a Request for Information (RFI) and is issued solely for informational, market research, and planning purposes. This is not a Request for Proposals or a Request for Quotations, and it is not considered to be a commitment by the Government to award a contract/order nor is the Government responsible for any costs incurred in furnishing information provided under this RFI. No basis for claim against the Government shall arise as a result from a response to this RFI or Government use of any information provided. Further, the Government is not seeking proposals and will not accept unsolicited proposals at this time. No proprietary, classified, confidential, or sensitive information should be included in your response to this RFI. The Government reserves the right to use any information provided by respondents for any purpose deemed necessary and legally appropriate, including using technical information provided by respondents in any resultant solicitation. Responses will assist the Government in determining the availability of potential solutions. The information and requirements in this RFI, and any attachments, is subject to change at the sole discretion of the Government.
Requirement: The Command Control Communications Cyber and Intelligence Service Center (C5ISC) Information Assurance (IA) Branch, the Surface Forces Logistics Center (SFLC), and the C5I Acquisition Directorate (CG-933) provide comprehensive IA services prescribed by the Risk Management Framework (RMF) for over 150 enterprise information technology (IT) systems and platform IT systems, to include those aboard USCG Cutters. These services are essential to ensuring the confidentiality, integrity, and availability of our IT systems. Contract services for labor are required by the C5ISC IA Program, SFLC and CG-933, including Information System Security Officer (ISSO) and Alternate ISSO (AISSO) services, Information System Security Engineer (ISSE) services, Security Control Assessor (SCA) services, and Cybersecurity Compliance and Readiness Services in support of the USCG Cybersecurity RMF process and cybersecurity of USCG Information Systems. (See attached DRAFT IDIQ contract Scope of Work and first Task Order Performance Work Statement [PWS])
The anticipated NAICS Code for this requirement is 541519 – Other Computer Related Services.
The anticipated Product Service Code (PSC) is DJ01 – IT and Telecom - Security And Compliance Support Services (Labor).
DHS Acquisition Planning Forecast System (APFS) Number: F2022058687
Small Business Set-Aside: 100% set-aside for qualified 8(a) businesses.
SAM: Contractors doing business with the Government are required to register in the System for Award Management (SAM) database. Information regarding SAM registration can be found at: SAM.gov | Entity Registrations
Submission of Information: Interested parties are encouraged to submit an RFI response which supports the company's claim that it presently has the technology, qualifications, experience, and capabilities to satisfy the requirements.
Specifically, interested parties are requested to provide the following information in an RFI response:
- Response to all questions in “Attachment 1 – Questionnaire”.
- A DRAFT IDIQ contract Solicitation and Attachments (Attachments 2 through 4) and DRAFT Task Order PWS (Attachment 5) are attached to allow prospective offerors the opportunity to review and provide comments/questions regarding the requirements and terms/conditions. A “commented” version of the Draft documents should be submitted as part of your RFI response, if applicable. (Click the “Review” tab within the MS Word document. Then click or highlight the area of concern in the document and click “New Comment” to write your comment.) Please use Attachment 6, Vendor Questions/Comments Form, to submit any other questions or comments related to this RFI.
- Please identify all concerns with the draft IDIQ RFP/Scope and Task Order PWS.
Total combined file sizes cannot be more than 10MB total per email. Zip files shall not be submitted.
Submit your RFI response(s) electronically via e-mail to:
Eric St. Pierre at Eric.R.St.Pierre@uscg.mil and
Jessica Coltz at Jessica.L.Coltz@uscg.mil.
RFI responses are due by June 26, 2023, at 11:00AM, Eastern Time.
Upon receiving RFI responses, the Coast Guard will assess all feedback and its impact on the development of the final specifications and acquisition strategy to meet the Government’s requirements.
List of RFI Attachments:
Attachment 1 – RFI Questionnaire
Attachment 2 – Draft Request For Proposal (DRFP)
Attachment 3 – Draft IDIQ Contract Scope of Work
Attachment 4 – Draft IDIQ Contract Labor Categories
Attachment 5 – Draft of first Task Order Performance Work Statement (PWS)
Attachment 6 – Vendor Questions/Comments Form
Attachments
| File | Type | Posted |
|---|---|---|
| RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23.xlsx | XLSX spreadsheet | |
| RFI Attachment 4-Draft_IA-RMF-IDIQ_Labor Categories_V1_04-17-23.xlsx | XLSX spreadsheet | |
| RFI Attachment 3-Draft_IA-RMF-IDIQ_Scope of Work_20230525_v2.0.4.docx | DOCX document | |
| RFI Attachment 1-Questionaire_RFI ESDIAB01_05-25-23.docx | DOCX document | |
| RFI Attachment 2 - Draft_IA-RMF-IDIQ_RFP_v4_05-22-23.docx | DOCX document | |
| RFI Attachment 5-Draft_IA-RMF_C5ISCTaskOrderPWS_v0.3_05-25-23.docx | DOCX document | |
| RFI Attachment 6-Question-Comment Form - v1_05-22-23.xls | XLS spreadsheet |
Notice history
| Notice | Type | Posted |
|---|---|---|
| USCG Information Assurance (IA) Risk Management Framework (RMF) Support Services | Award Notice | |
| USCG Information Assurance (IA) Risk Management Framework (RMF) Support Services | Solicitation | |
| USCG Information Assurance (IA) Risk Management Framework (RMF) Services | Pre-Solicitation |
On GovTribe
Work this opportunity on GovTribe
- Track it in your pipeline
- Find teaming partners
- Similar opportunities
- Ask GovTribe AI about this opportunity