Penetration Testing

Solicitation # 25RFP13436
Posted 5/16/25, 2:50 PM
No Updates
Due 7/1/25, 12:59 AM
Similar Opportunities
The South Dakota Department of Health, Office of Public Health Preparedness and Response is seeking cloud-based software solutions for public health emergency incident management through a Request for Proposal (RFP) covering five distinct project areas: Incident Management, Volunteer Registry and Management, Health Alert Network Operations, Patient Tracking, and Bed Availability Tracking. The procurement targets comprehensive software platforms that will enable information sharing, data...
The South Dakota Department of Revenue is seeking a vendor to manage a comprehensive license plate production and distribution system through a Request for Proposal (RFP #25RFP14522). The contract will cover centralized production and distribution of license plates, establishment of a centralized fulfillment center, and implementation of a print-on-demand system for 68 county offices and the Pierre Department of Revenue office. The state currently manages approximately 1.6 million registered...
The South Dakota Department of Labor and Regulation (SDDLR) is seeking a Request for Proposal (RFP) for a modernized Professional Licensing, Inspection, and Permitting System to serve multiple Boards and Commissions. The procurement aims to develop a scalable, cloud-based licensing portal with comprehensive functionality including registrations, applications, license renewals, continuing education management, inspections, complaints, electronic payments, and public-facing licensee information....
The Iowa Department of Management is seeking a Master Statement of Work (MSOW) for Vulnerability Assessment and Penetration Testing services through a Request for Bid (RFB) PQ-185-2522-2025. This procurement is specifically targeted at prequalified cybersecurity vendors in Category #4, who were previously awarded contracts from procurement 2024BUS0915. The primary objective is to secure comprehensive cybersecurity assessment services, with vendors required to submit hourly rates for services...
The South Dakota Board of Pharmacy (SDBOP) is seeking vendor proposals for a comprehensive licensure and information system replacement, along with website development, through RFP #25-0920900-025. The procurement aims to replace the current licensure, regulation, inspection, and investigation documentation system with a commercially available cloud-hosted solution that supports licensing management for pharmacies, wholesale distributors, pharmacists, pharmacy technicians, and pharmacy...
The South Dakota Department of Education's Division of Learning and Instruction is seeking a School Success Facilitator Advisor through a competitive Request for Proposal (RFP) process. The primary objective is to secure a consultant who will collaborate with the State on the Comprehensive Needs Assessment (CNA) process and provide support to schools identified as needing Comprehensive Support and Improvement (CSI) and Targeted Support and Improvement (TSI). Key deliverables include designing...
The South Dakota Division of Insurance is seeking actuarial services through Request for Proposal #25RFP15020, specifically for two distinct contract opportunities involving health insurance and long-term care rate reviews. The procurement seeks contractors to provide comprehensive actuarial services including monitoring changes in state and federal insurance requirements, consulting with the Division of Insurance, and potentially conducting special project analyses. Contractors will be...

The State of South Dakota's Bureau of Information & Technology (BIT) is seeking a penetration testing service to enhance the state's cybersecurity posture. The procurement specifically requires conducting both red team and purple team exercises to assess the cybersecurity capabilities of the State's Executive Branch, focusing on web applications, networks, and computer systems. Deliverables will include an executive summary with an overall security posture rating, a confidential technical report detailing attack simulations, and comprehensive recommendations for improving cybersecurity. The RFP requires contractors to comply with extensive security protocols, including background investigations, multi-factor authentication, and adherence to specific data protection standards. Proposals are due by July 1, 2025, with an anticipated contract award date of September 30, 2025. The contract will have an initial two-year term with the potential for up to three one-year extensions. Questions regarding the RFP must be submitted via email to BIT.RFPSECURITYREVIEW@state.sd.us, with the subject line "RFP#25RFP13436" by the specified date in the schedule of activities.

While no specific set-aside designations or restrictions on respondent types are explicitly mentioned, the RFP indicates rigorous qualification requirements for potential contractors. The assessment explicitly excludes certain state entities including the Board of Regents, Office of the Attorney General, Unified Judicial System, and K-12 Networks. Contractors must sign a Contractor Security Acknowledgement Form and comply with the state's Information Technology Security Policy (ITSP), which includes comprehensive background checks and data protection protocols. The state will own all data created during the assessment, and contractors must follow strict confidentiality and reporting guidelines. Although a specific budget range is not provided, the RFP allows offerors to submit multiple cost proposals for red and/or purple team exercises, indicating flexibility in pricing. Contractors must include all costs related to services, including third-party software licenses, and understand that access to state technology infrastructure is a privilege that can be revoked at BIT management's discretion.

Generated 6/9/25, 7:34 AM