Opportunity
CanadaBuys #20261288
FCAC enterprise cybersecurity assessment and NIST CSF 2.0 reporting
Posted
October 06, 2026
Respond By
October 22, 2026
Identifier
20261288
NAICS
541512, 541519
The Financial Consumer Agency of Canada (FCAC) is seeking an independent firm to assess its enterprise cybersecurity posture and deliver two distinct reports. - Government buyer: Financial Consumer Agency of Canada (FCAC/ACFC). The named contact is Pavlo Kyryakov; no sub-agency or office is specified. - Requested service: An enterprise-wide cybersecurity assessment, with an estimated level of effort of 164 days. - Assess IT security controls using ITSG-33 Annex 3A and a harmonized threat-and-risk assessment methodology. - Collect evidence; analyze control gaps and residual risks; and recommend prioritized remediation. - Deliver a detailed, evidence-based internal report for management and a separate, high-level report based on NIST Cybersecurity Framework (CSF) 2.0 for senior leadership or broader communication. - The broader report must not disclose sensitive vulnerabilities, system-specific weaknesses, or protected information. - Named prospective suppliers: Accenture Inc.; ADGA Group Consultants Inc.; CGI Information Systems and Management Consultants Inc.; Deloitte Inc.; Ernst & Young LLP; Gartner Canada Co.; IBM Canada Limited/IBM Canada Limitée; IPSS Inc.; KPMG LLP; OPTIV Canada Federal Inc.; T-REX Solutions LLC; TEKsystems Global Services Corp.; The Bell Telephone Company of Canada or Bell Canada/La Compagnie de Téléphone Bell du Canada ou Bell Canada; TPG Technology Consulting Ltd.; and TRM Technologies Inc. - Notable requirements: The assessment must be independent and evidence-based. Reliability security clearance is required for the organization and its personnel. No products, OEMs, part numbers, or product quantities are specified.
Description
The Financial Consumer Agency of Canada requires an experienced, independent cybersecurity firm to assess its enterprise-wide cybersecurity posture. The work includes an evidence-based internal assessment of IT security controls using ITSG-33 Annex 3A and a harmonized threat and risk assessment methodology, with gap analysis, residual risk determination, and prioritized remediation planning. The contractor must also produce a separate NIST Cybersecurity Framework 2.0 report presenting a high-level maturity narrative suitable for external communication without disclosing sensitive vulnerabilities or protected information. The estimated level of effort is 164 days, with work from contract award through March 31, 2027; bidding is limited to specified Tier 1 SBIPS Supply Arrangement holders qualified in the Security Management stream for the National Capital Region.