The State of South Dakota's Bureau of Information & Technology (BIT) is seeking a penetration testing service to enhance the state's cybersecurity posture. The procurement specifically requires conducting both red team and purple team exercises to assess the cybersecurity capabilities of the State's Executive Branch, focusing on web applications, networks, and computer systems. Deliverables will include an executive summary with an overall security posture rating, a confidential technical report detailing attack simulations, and comprehensive recommendations for improving cybersecurity. The RFP requires contractors to comply with extensive security protocols, including background investigations, multi-factor authentication, and adherence to specific data protection standards. Proposals are due by July 1, 2025, with an anticipated contract award date of September 30, 2025. The contract will have an initial two-year term with the potential for up to three one-year extensions. Questions regarding the RFP must be submitted via email to BIT.RFPSECURITYREVIEW@state.sd.us, with the subject line "RFP#25RFP13436" by the specified date in the schedule of activities. While no specific set-aside designations or restrictions on respondent types are explicitly mentioned, the RFP indicates rigorous qualification requirements for potential contractors. The assessment explicitly excludes certain state entities including the Board of Regents, Office of the Attorney General, Unified Judicial System, and K-12 Networks. Contractors must sign a Contractor Security Acknowledgement Form and comply with the state's Information Technology Security Policy (ITSP), which includes comprehensive background checks and data protection protocols. The state will own all data created during the assessment, and contractors must follow strict confidentiality and reporting guidelines. Although a specific budget range is not provided, the RFP allows offerors to submit multiple cost proposals for red and/or purple team exercises, indicating flexibility in pricing. Contractors must include all costs related to services, including third-party software licenses, and understand that access to state technology infrastructure is a privilege that can be revoked at BIT management's discretion.
Name | Description | Size | Type (Click to sort descending) | Posted (Click to sort descending) |
|---|---|---|---|---|
RFP Document.pdf | 382KB | 5/16/25 | ||
Attachment A Certificate of Media Santization (002).docx | 568KB | Document | 5/16/25 | |
Attachment B ITSP.pdf | 1020KB | 5/16/25 | ||
Attachment C Contractor Security Acknowledgement Form (002).docx | 69KB | Document | 5/16/25 |