# New York State Contract Reporter #2139496

Managed cybersecurity GRC and vCISO program management for Nassau Community College

**Posted:** September 30, 2026
**Respond By:** October 27, 2026
**Identifier:** 2139496
**NAICS:** 541512, 541611, 541519

Nassau Community College is seeking a hands-on partner to manage and strengthen its cybersecurity governance, risk, and compliance program.
- Buyer
  - Nassau Community College, part of the State University of New York system; Procurement Office.
  - The provider will work under the direction of the Associate Vice President of Information Technology Services.
- Requested service
  - One managed Governance, Risk, Compliance, and Cybersecurity Program Management service, including virtual Chief Information Security Officer (vCISO) leadership and active program coordination.
  - Work includes cybersecurity strategy and maturity roadmaps; risk assessments, risk registers, POA&M and remediation tracking; compliance and audit support; enterprise technology and application inventory; policy and procedure management; business continuity and disaster recovery planning; vendor risk management; vulnerability and security assessments; incident response readiness and support; governance committee facilitation; and executive and Board reporting.
  - The provider must do more than offer recommendations: it is expected to coordinate execution, maintain program documentation and a centralized system of record, and drive measurable cybersecurity maturity improvements.
  - The scope includes an annual NIST CSF 2.0 assessment and a baseline review and program transition during the first six months.
- OEMs and vendors
  - No product manufacturers, OEMs, resellers, or prospective service vendors are named. NIST CSF 2.0 is a framework, not a vendor or product.
- Contract term
  - One initial year, with up to four additional one-year extensions by mutual consent; annual fixed fees are requested for up to five years.
- Products and quantities
  - No equipment, software products, or product part numbers are specified. The service is listed as one engagement; no separate quantities are provided for its component activities.

### Description

Nassau Community College is seeking a qualified cybersecurity services partner to provide comprehensive Governance, Risk, Compliance (GRC), and Cybersecurity Program Management Services. The selected firm will provide virtual Chief Information Security Officer services and active program management, working as an extension of the College’s Information Technology organization. Work includes planning, coordination, documentation, facilitation, risk and compliance management, governance support, execution oversight, stakeholder coordination, and tracking remediation to improve cybersecurity maturity. Proposals are due October 27, 2026, at 12:00 PM.

[View original listing](https://www.nyscr.ny.gov/Ads/Search)
