Solicitations
› DEPT OF DEFENSE
› NAICS 541611
Develop and sustain CASTLE KEEP in Army commercial cloud solutions
DEPT OF DEFENSE · Solicitation W56KGY26CKRFI0001 · NAICS 541611 · No Set aside used · Responses due 22 September 2026
Solicitation details
| Solicitation number | W56KGY26CKRFI0001 |
|---|
| Notice ID | 8c6dfbf8edc14fb0b3511fce4f72556a |
|---|
| Agency | DEPT OF DEFENSE |
|---|
| Sub-tier | DEPT OF THE ARMY |
|---|
| Contracting office | W6QK ACC-APG |
|---|
| NAICS code | 541611 |
|---|
| Product / service code (PSC) | DJ01 |
|---|
| Set-aside | No Set aside used |
|---|
| Notice type | Sources Sought |
|---|
| Posted | 09 September 2026 |
|---|
| Response deadline | 22 September 2026 |
|---|
| Place of performance | Washington, DC, USA |
|---|
Description
RFI Pursuant to Revolutionary Federal Acquisition Regulation Overhaul RFO FAR 15.101(c) DISCLAIMER This is a Request for Information (RFI) issued in accordance with RFO FAR 15.101(c). The Government does not intend to award a contract on the basis of this RFI or otherwise pay for the information requested. Responses to this RFI will be treated as information only and shall not be construed as a proposal. This is not a Request for Proposal (RFP), nor does it constitute a solicitation and shall not be construed as a commitment by the Government. Responses in any form are not offers and the Government is under no obligation to award a contract from this announcement. No funds will be made available to pay for the preparation of responses to this announcement. Any information submitted to this notice is strictly voluntary and will not be returned. Not responding to this notice does not preclude participation in future solicitations. If a solicitation is released, it will not be synopsized on the government-wide point of entry due to national security. Only vendors meeting the security requirements will be provided with additional information pertaining to this requirement. INTENT Background: HQDA G-2. CASTLE KEEP is a customer-facing portal that provides automated workflow services and Sensitive Compartmented Army SCI program reporting, metrics, analysis, and information sharing within the Army SCI community in accordance with DoDM 5105.21 requirements. This is non-personal services contract to provide Software Development and Software Sustainment Support of the Department of Army (DA) SSO s CASTLE KEEP. The Army Contracting Command Aberdeen Proving Ground (ACC-APG) is issuing this RFI to conduct market research. The intent of the RFI is to identify parties having an interest in bidding on and the resources to support solicitations for G2 s CASTLE KEEP s sustainable solution for the SSO/SSR community to develop and sustain CASTLE KEEP in Army Commercial Cloud Solutions Provider (AC2SP). The Government retains ownership to software and application tools; upon completion this contract all information will be turned over to the U.S. Government and is U.S. Government property. The identified questions are to encourage competition and exchanges of information. Any voluntary response received will be reviewed to assist the Government in arriving at the most suitable approach. The Government is seeking responses to this RFI that describes vendors existing capabilities. Small Business Participation: This RFI is issued on an unrestricted basis (Full and Open) to maximize industry responses. The Government highly encourages submissions from all business sizes and socioeconomic categories (e.g., Small Business, SDVOSB, 8(a), WOSB, HUBZone). Infrastructure Assessment: Vendor shall simulate the realistic threat exploitation techniques within the legacy, existing, and emerging software system's cybersecurity in the mission context of the representative operating environment. Vendor shall apply the cybersecurity testing process with blue teams of Government and Vendor equivalent organizations and red teams of the certified Government and Vendor equivalent organizations during Developmental/Operational Test & Evaluation (D/O T&E).The Blue team assesses the operational network vulnerability with findings for the independent technical review of the network security posture and implements the mitigation techniques for integration into the community security solution to increase the cybersecurity readiness posture. The Blue teams evaluate the security threats/risks in the operating environment and study the network environment and its current state of security readiness. The Red teams simulate the potential adversary's exploitation capabilities against an enterprise's security posture to enhance the enterprise IA/Cybersecurity via demonstration of the impacts of the successful attacks and the needed countermeasure by the blue teams in the operational environment. Cyber Integration: Vendor shall coordinate with Government Agencies and industry partners to support interoperability and integration of other capabilities, maintain adequate certified personnel to meet requirements, and provide qualified staff for CASTLE KEEP software development and sustainment. Vendor shall lease workspace with NIPRNet and JWICS access to support three to four personnel. Multi-level Security: Vendor personnel performing work under this action must have an active Top Secret (TS) security clearance with eligibility for obtaining Sensitive Compartmented Information (SCI) (SI, TK, G, and HCS security clearance IAW DoD 5200.1-R at the time of award and must maintain the level of security required for the life of a contract. This action will require TSI/SCI, but future work related to this action may require a TS/SCI with Counterintelligence Polygraph (TS/SCI w/CI Poly) clearance. The security requirements are IAW the attached DD Form 254, Security Classification Specification. Personnel must perform within the security limitations of AR 381-10, USSID 18, and other security regulations. Any vendor personnel that will need access to SIPRNet terminals will require a TS/SCI clearance because all SIPRNet terminals are in Sensitive Compartmented Information Facility (SCIFs) Security Boundary Clarification: The vendor shall understand and apply all applicable security classification guidance. Users should notify the originator if information indicates a need to update the guidance. Classification determinations remain the responsibility of the Government Contracting Agency (GCA). The Contract Security Classification Specification (DD254) is required for performance on a classified contract. Infrastructure for Cyber Operations: The vendor shall leverage infrastructure as code such as terraform or related for deployments and cloud management. Cyber-Network Architecture: develop, maintain, and update documentation which includes Standard Operating Procedures, System Architecture Guides, Entity Relationship Diagram (ERD), Install Guides, and Department of Defense Architectural Framework (DoDAF) diagrams for all related system and hardware configurations adhering to organizational templated and policies quarterly. The vendor shall leverage cross-domain solutions for implementation for tempest hardening and significant equipment installations. The vendor shall not implement solutions that have licenses or incur additional costs without written approval from the Government stakeholders, COR, and ACOR. Post-RFI Events: Following the evaluation of RFI responses, the Government anticipates hosting an Industry Day to facilitate open exchanges of information and provide further program details. A separate announcement containing registration, scheduling, and security clearance instructions for the Industry Day will be published on SAM.gov. The feasibility of conducting associated physical site visits is currently under evaluation and will be announced at a later date, if applicable. SUBMISSION INSTRUCTIONS Vendors may only submit one (1) submission per CAGE code. Interested sources are requested to submit a response of no more than fifteen (5) pages, written in Times New Roman font of 12-point size or larger. Responses must be in either Microsoft Word or character recognized and searchable Adobe Portable Document Format (PDF). If your company has different business sectors which hold different CAGE codes, each sector may submit a response. In addition, each CAGE code must provide separate facility clearance documentation. If teaming, use the Prime Vendor's CAGE code in the response. Submission of proprietary and other sensitive information must be marked and identified with disposition instructions. The Government shall not be liable or suffer any consequential damage for any improperly identified proprietary information. Proprietary information will be safeguarded in accordance with the applicable Government regulations and requirements. The information provided and received in response to this announcement is subject to the conditions set forth in RFO FAR 15.101(c). RFI responses and any questions shall be submitted via email to the following: Questions and responses may be sent using either of the following methods: Emailed to: ricardo.a.rivera50.civ@army.mil and cesar.m.mencia.civ@army.mil Sent via DOD Secure Access File Exchange (SAFE) (https://safe.apps.mil) to: ricardo.a.rivera50.civ@army.mil and cesar.m.mencia.civ@army.mil DO NOT SEND CLASSIFIED INFORMATION. All submissions and attachments to this RFI must be UNCLASSIFIED or Controlled Unclassified Information (CUI). The subject line of all emails sent in response to this RFI shall be " W56KGY26CKRFI0001". All emails shall identify respondents organization, point(s) of contact, and classification/caveats. Responses to this request shall be submitted via email and must be received no later than 12:00 pm, ET, 22 September 2026. The…
Go deeper on this solicitation
FedSift reads the full solicitation package — every attachment — and pre-extracts
the compliance matrix, evaluation factors, key risks, win themes and
deal-breakers, each with a verbatim quote and the exact PDF page it came from. It
scores the opportunity against your company profile, tells you whether to bid as
prime or sub, and ranks teaming partners who could close your gaps.
Open the AI analysis in FedSift →
Free forever plan — no credit card.
Browse solicitations without an account; sign in for AI analysis and matching.
Other open solicitations in NAICS 541611
- Community Reentry NetworkJUSTICE, DEPARTMENT OF · Due 14 September 2026
- R499--Insurance Entry and Verification Services - CPAC [VA-26-00073096]VETERANS AFFAIRS, DEPARTMENT OF · Due 14 September 2026
- Human Performance Optimization (HPO) ModelDEPT OF DEFENSE · Due 14 September 2026
- Intent to Sole Source - Gartner for Executive Leaders (v2) Guided Individual Access License SubscriptionTREASURY, DEPARTMENT OF THE · Due 15 September 2026
- FHWA Transportation Data Collection, Data Method Development, Data Processing, and Information ExtractionTRANSPORTATION, DEPARTMENT OF · Due 15 September 2026
- Outplacement ServicesENERGY, DEPARTMENT OF · Due 15 September 2026
- Professional consulting services to conduct a comprehensive law enforcement-focused assessment of hydrocarbon theft, diversion, and…STATE, DEPARTMENT OF · Due 16 September 2026
- R408--Acquisition Support ServicesVETERANS AFFAIRS, DEPARTMENT OF · Due 17 September 2026
All NAICS 541611 solicitations →
More from DEPT OF DEFENSE
All DEPT OF DEFENSE solicitations →
Source: this notice on SAM.gov.
FedSift republishes public federal procurement data and is not affiliated with
the U.S. Government. Always confirm dates and requirements against SAM.gov
before responding.