The City of Santa Monica is seeking a comprehensive Cybersecurity Managed Services provider through a Request for Proposal (RFP) to enhance the security of its network, systems, and applications. The procurement targets firms capable of managing a complex IT environment with approximately 8,000 devices/IPs across hybrid on-premises and cloud-based systems. Required services include penetration testing, risk assessments, security policy reviews, incident response exercises, and ongoing security management. Proposers must demonstrate at least five years of experience, possess industry-recognized certifications, and have expertise in advanced threat detection and real-world attack scenarios. The evaluation process will score proposals across six criteria: quality control, stability/references, value-added services, cost, experience/technical competence, and ability to meet work plans and timelines, with a total possible score of 100 points. Key dates include proposal release on September 22, 2025, with questions due by September 29, 2025, and final proposal submissions required by October 24, 2025, at 3:00 pm. The contract term is initially five years, with two potential one-year renewal options. While no specific set-aside designations are explicitly mentioned, the RFP covers jurisdictions including Los Angeles County and San Francisco City. The vendor must maintain comprehensive insurance coverage, including a $5,000,000 Technology Professional Errors and Omissions/Cyber Liability policy that covers intellectual property infringement, information theft, privacy violations, and network security. Potential optional services include cybersecurity training, phishing simulations, web application penetration testing, and cybersecurity grant management. Insurers must be California-authorized with an A.M. Best rating of at least A:VII, and the City of Santa Monica will be listed as an additional insured. The contract includes provisions for potential subconsultant involvement, with the city retaining approval rights. While a specific budget range is not disclosed, the Professional Services Agreement template indicates the contract will be structured with compensation not to exceed a predetermined amount, with 30-day invoice payment terms for undisputed amounts.
Name | Description | Size | Type (Click to sort descending) | Posted (Click to sort descending) |
|---|---|---|---|---|
Cyber_Security_Managed_Services.pdf | 254KB | 9/22/25 | ||
Cyber_Security_Insurance_Requirements.docx | 27KB | Document | 7/21/25 | |
PSA_Template.docx | 49KB | Document | 7/21/25 | |
RE__summarizing_today's_ISD_expiring_contacts_conversations.pdf | 288KB | 7/21/25 | ||
Vendor_questionnaire.docx | 40KB | Document | 7/21/25 |