U.S. Department of Defense
Active

Cyber Security Engineering and Risk Management Framework Support Services

U.S. Department of Defense
Updated May 22, 2026 · 04:14 UTC
schedule
Offers due in 2 days
info
This is a Sources Sought notice.

The agency is gauging market interest. No bid is being requested yet — submitting a capabilities statement may put you on the radar for the eventual solicitation.

The Army needs a certified 8(a) small business to provide cybersecurity engineering and risk management framework support services.

Key Details

  • What exactly do they need? Cybersecurity engineering and risk management framework support services, including personnel, equipment, and supplies.
  • What is the timeline? The notice doesn't say.

Who can apply

  • Must be 8(a) certified (a small-business program for socially or economically disadvantaged owners)
  • Has a CISSP certification and at least 5 years of experience managing RMF lifecycle reporting
  • Has Security+ or CASP/SecurityX certification and at least 3 years of experience supporting RMF lifecycle reporting

If you're interested, do this first

  • Check that your 8(a) certification is still active in SAM.gov
  • Write a 1-page summary of similar work you've done before
  • Email the contracting officer to RSVP for the site visit

Primary point of contact

Email
pasqulita.n.jackson.civ@army.mil

Get the daily digest by email.

A summary of every new set-aside opportunity, in your inbox by 9:00 a.m. Eastern. Free, no spam, unsubscribe anytime.