Opportunity

SAM #IT-1

Award Notice: Sole Source Bridge Contract for Cybersecurity and Privacy Program Support Services for FRA

Buyer

693JJ6 FEDERAL RAILROAD ADMIN

Posted

August 04, 2026

Identifier

IT-1

NAICS

541513, 541512

This award notice announces a sole source bridge contract for Cybersecurity and Privacy Program Support Services for the Federal Railroad Administration (FRA). - Sole source bridge contract awarded to Criterion Systems LLC - 12-month period to ensure continuity during DOT's IT consolidation under the Digital Factory model - Services cover all FRA FISMA-reportable systems (12 IT systems: 8 production, 4 under development) - Includes cloud-hosted and on-premises environments - Contractor operates, monitors, and configures DOT and DHS Security Tool Suites within FRA enclave - Tools include Tenable Nessus, BigFix, SCCM, SCOM, DB Protect, Netsparker, Burp Suite, and CSAM repository - Services include Risk Management Framework (RMF) maintenance and Information Security Continuous Monitoring Program (ISCMP) - Senior personnel with advanced cybersecurity credentials (CISSP, CISA, CAP/SSCP, CIPP, CCSK) required - Estimated contract value: $775,027 - No specific product quantities or part numbers; focus is on specialized services - Award ensures uninterrupted cybersecurity and privacy support during DOT's IT reorganization

Description

In strict compliance with GSAR 538.7104-3(b)(ii), this notice is being made publicly available within 14 days after the award of the modification to ensure procedural transparency under GSA’s modernized FSS ordering procedures.  This action is a 12-month sole source award to the incumbent contractor, Criterion, for uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. This bridge extends the period of performance from July 20, 2026 to 07/19/2027.  This contract action is necessitated by the United States Department of Transportation’s (USDOT) reorganization of its Information Technology (IT) function into a digital factory model under the 1DOT reorganization

The FRA requires uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. These services ensure the FRA fully complies with the Federal Information Security Modernization Act (FISMA) of 2014, OMB Circular A-130, and relevant Departmental cybersecurity directives.

The scope of work encompasses comprehensive coverage for all FRA FISMA-reportable systems, requiring the continuous maintenance of the Risk Management Framework (RMF) and the Information Security Continuous Monitoring Program (ISCMP). The architecture currently under administration includes:

Eight (8) production systems (including three hosted in the cloud, seven Moderate Security Impact systems, and five Privacy systems). Four (4) systems under active development, bringing the total technical architecture to twelve (12) IT systems. Environment Composition: Microsoft Dynamics 365 applications, cloud environments (SaaS, PaaS, IaaS), and on-premises datacenters.

The contractor is required to operate, monitor, and configure the DOT and DHS Security Tool Suites utilized within the FRA enclave. This includes specialized engineering and administration of tools such as Tenable Nessus, BigFix, SCCM, SCOM, DB Protect, Netsparker, Burp Suite, and the DOT Cybersecurity Assessment and Management (CSAM) repository. The required services mandate senior key personnel—specifically a Project Manager and Senior Information System Security Specialists—possessing advanced credentials (CISSP, CISA, CAP/SSCP, CIPP, CCSK) and deep, institutionalized knowledge of FRA’s safety-critical infrastructure.

These services are essential for the integration of FRA team under the new Digital Factory model mandated by the FY26 THUD Appropriations Act – passed as section D of the Consolidated Appropriations Act, 2026, Consolidated Appropriations Act, 2026 (P.L. 119-75).

Please see the attached sole source justification.

View original listing