# SAM #95476727RFI-MSSP

USHMM Market Research for Managed Security, Multi-Cloud, DevSecOps, Network Engineering, and MSSP Services

**Buyer:** USHMM Procurement Division
**Posted:** October 01, 2026
**Respond By:** October 30, 2026
**Identifier:** 95476727RFI-MSSP
**NAICS:** 541512, 541519

The United States Holocaust Memorial Museum is exploring a potential re-procurement of managed security and related IT services.
- **Government buyer:** United States Holocaust Memorial Museum (USHMM), Procurement Division.
- **OEMs and vendors:** No OEMs, vendors, or incumbent providers are named.
- **Requested services:**
  - Operate and sustain USHMM’s existing security infrastructure, including security architecture evaluations, threat modeling, gap analyses, and compliance assessments.
  - Provide multi-cloud and DevSecOps architecture, network engineering, and managed security service provider (MSSP) operations.
  - Recommend a modernized security environment incorporating Zero Trust, automated orchestration, and security-tool consolidation.
  - Support a Government Owned Contractor Operated Security Operations Center model and transition to the recommended operating approach.
- **Standards and frameworks:** NIST SP 800-53 Rev. 5, FISMA, PCI DSS v4.2.1, the CISA Zero Trust Maturity Model, and CSF 2.0.
- **Pricing information sought:** Feedback on a monthly Firm-Fixed-Price approach and fully burdened Washington, DC-area labor rates for CISO, Security Architect, DevSecOps Engineer, Security Analyst, and Network/System Engineer roles.
- **Products and quantities:** No specific products, part numbers, or quantities are identified.

### Description

<p>DISCLAIMER / MARKET RESEARCH NOTICE:This Request for Information (RFI) is issued solely for information gathering and planning purposes. It does not constitute a Request for Proposal (RFP), Invitation for Bid (IFB), or an obligation on the part of the United States Holocaust Memorial Museum (USHMM) to acquire any products or services. Responses to this notice are not offers and cannot be accepted by USHMM to form a binding contract. Responders are solely responsible for all expenses associated with responding to this RFI.</p>

<p>The United States Holocaust Memorial Museum (USHMM) is conducting formal market research to evaluate commercial vendor capabilities, industry pricing benchmarks, federal/commercial labor rates, and available contract acquisition vehicles (e.g., GSA MAS SIN 54151HACS, NASA SEWP, CIO-SP3/4, SAM.gov) for re-procuring comprehensive Managed Information Technology (IT) Security, Multi-Cloud/DevSecOps Architecture, Network Engineering, and specialized Managed Security Service Provider (MSSP) operational activities. The primary objective of this market research effort is to evaluate whether competitive commercial marketplace capabilities exist to:</p>

<ul>
	<li>Sustain, support, and execute day-to-day operations across USHMM&#39;s existing &quot;As-Is&quot; securityinfrastructure without operational disruption or increased organizational risk.</li>
	<li>Perform rigorous security architecture evaluations, threat modeling, gap analyses, and complianceassessments against industry-best security and privacy standards (NIST SP 800-53 r5, FISMA, PCI DSSv4.2.1, CISA Zero Trust Maturity Model, CSF 2.0).</li>
	<li>Architect and recommend a modernized, cost-effective &quot;To-Be&quot; security state incorporating ZeroTrust architecture, automated orchestration, tool consolidation, and a Government OwnedContractor Operated (GOCO) Security Operations Center (SOC) framework.</li>
	<li>Execute a seamless, structured transition lifecycle from the &quot;As-Is&quot; state to the &quot;To-Be&quot; operationalmodel within strict schedule and budget parameters.</li>
</ul>

<p>Pricing Benchmarks &amp; Market Rate Expectations</p>

<ul>
	<li>Provide feedback on the commercial feasibility of managing this scope under a Firm-Fixed-Price (FFP)monthly fee structure.</li>
	<li>Provide fully burdened hourly commercial labor rates or GSA schedule rates in the Washington, DCMetropolitan Area for equivalent labor categories (CISO, Security Architect, DevSecOps Engineer,Security Analyst, Network/System Engineer).</li>
</ul>

<p>Submission Instructions &amp; Response Format</p>

<ul>
	<li>Response Deadline: All responses shall be submitted electronically no later than October 30, 2026, at 5:00 PM EDT.</li>
	<li>Submission Format: Responses must be submitted in PDF or Microsoft Word format, strictly limited to no more than fifteen (15) pages (excluding cover page and labor rate tables).</li>
	<li>Point of Contact: Submissions and any clarifying technical inquiries must be emailed to Mary Green, USHMM Contracting Officer at magreen@ushmm.org with the subject line &quot;RFI Response - USHMM Managed IT Security &amp; MSSP Services&quot;.</li>
</ul>

[View original listing](https://sam.gov/opp/1a583f243fa744f3a70c2f7df3758df1/view)
