Opportunity
SAM #SS-75F40126Q00333
FDA Sources Sought: NextGen Cybersecurity Engineering, Operations, AI, and Unified Services BPA
Buyer
FDA Office of the Associate General Counsel for Administrative Law
Posted
August 06, 2026
Respond By
August 31, 2026
Identifier
SS-75F40126Q00333
NAICS
5415, 541512, 541330, 541715
This opportunity is a sources sought notice from the U.S. Food and Drug Administration (FDA) seeking small businesses on the GSA MAS Schedule for advanced, integrated cybersecurity services to modernize and protect FDA's digital infrastructure. - Scope of Work: - Comprehensive cybersecurity engineering, operations, and modernization services for FDA's enterprise, including on-premises and cloud environments - Support for Zero Trust cybersecurity framework and AI-driven capabilities - Services include: - Cybersecurity engineering and platform modernization - Security Operations Center (SOC) and Network Operations Center (NOC) 24x7x365 monitoring and response - Threat management, vulnerability management, and digital forensics - Identity, Credential, and Access Management (ICAM) with AI enablement - Artificial Intelligence (AI) and automation for compliance, threat detection, and orchestration - Post Quantum Cryptography (PQC) transition and support - Secure cloud connectivity and Trusted Internet Connection (TIC) engineering - Cyber AI defense, counterintelligence, and proactive threat hunting - Workforce support, analytics, and training - Implementation of a vendor-neutral Zero Trust Identity Hub - Requirements: - Alignment with federal cybersecurity standards (NIST, CISA Zero Trust, OMB, DHS) - AI-enabled compliance monitoring, automated control validation, and continuous authorization (cATO) - No specific OEMs, part numbers, or product quantities are listed - Set aside for small businesses; market research phase (not a solicitation) - Potential Commercial Opportunities: - BPA for multi-year, enterprise-wide cybersecurity services - Opportunities for vendors specializing in AI/ML, Zero Trust, cloud security, and post-quantum cryptography - **No named OEMs or incumbent vendors; open to qualified small businesses on GSA MAS Schedules 54151S and 54151HACS
Description
The U.S. Food and Drug Administration (FDA) is issuing this source sought notice as a means of conducting market research, pursuant to FAR Part 10 Market Research, to align all engineering activities to applicable Federal cybersecurity standards and guidance, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), CISA Zero Trust Maturity Model, and other relevant OMB and DHS directives, while leveraging Artificial Intelligence (AI)-enabled compliance monitoring, automated control validation, and continuous authorization (cATO) capabilities to ensure ongoing alignment and rapid adaptation to evolving federal requirements.
Support the design, integration, and evolution of a scalable, resilient, and interoperable cybersecurity architecture aligned to a defense-in-depth strategy, AI-driven architecture optimization, intelligent workload distribution, automated resilience testing, and predictive risk modeling to enhance system performance, security posture, and operational agility.
This is a SOURCES SOUGHT ONLY, not a Request for Quote (RFQ) and does not commit the Government to award a contract now or in the future. The purpose of this Sources Sought is to identify SMALL BUSINESSES on GSA MAS Schedule with the capabilities to provide the services stated herein.
See attachment for complete information for this sources sought.