FedSift

SolicitationsTRANSPORTATION, DEPARTMENT OFNAICS 541513

Notification of Award of Sole Source Bridge Action_Cybersecurity and Privacy Program Support Services

TRANSPORTATION, DEPARTMENT OF · Solicitation IT-1 · NAICS 541513 · Unrestricted (full and open)

Solicitation details

Solicitation numberIT-1
Notice IDb7aabe4acf78443aa7b1baf04b0837ac
AgencyTRANSPORTATION, DEPARTMENT OF
Sub-tierFEDERAL RAILROAD ADMINISTRATION
Contracting office693JJ6 FEDERAL RAILROAD ADMIN
NAICS code541513
Product / service code (PSC)DA01
Set-asideUnrestricted (full and open)
Notice typeJustification
Posted04 August 2026
Response deadlineNot stated
Place of performanceWashington, DC, USA

Description

In strict compliance with GSAR 538.7104-3(b)(ii), this notice is being made publicly available within 14 days after the award of the modification to ensure procedural transparency under GSA s modernized FSS ordering procedures. This action is a 12-month sole source award to the incumbent contractor, Criterion, for uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. This bridge extends the period of performance from July 20, 2026 to 07/19/2027. This contract action is necessitated by the United States Department of Transportation s (USDOT) reorganization of its Information Technology (IT) function into a digital factory model under the 1DOT reorganization The FRA requires uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. These services ensure the FRA fully complies with the Federal Information Security Modernization Act (FISMA) of 2014, OMB Circular A-130, and relevant Departmental cybersecurity directives. The scope of work encompasses comprehensive coverage for all FRA FISMA-reportable systems, requiring the continuous maintenance of the Risk Management Framework (RMF) and the Information Security Continuous Monitoring Program (ISCMP). The architecture currently under administration includes: Eight (8) production systems (including three hosted in the cloud, seven Moderate Security Impact systems, and five Privacy systems). Four (4) systems under active development, bringing the total technical architecture to twelve (12) IT systems. Environment Composition: Microsoft Dynamics 365 applications, cloud environments (SaaS, PaaS, IaaS), and on-premises datacenters. The contractor is required to operate, monitor, and configure the DOT and DHS Security Tool Suites utilized within the FRA enclave. This includes specialized engineering and administration of tools such as Tenable Nessus, BigFix, SCCM, SCOM, DB Protect, Netsparker, Burp Suite, and the DOT Cybersecurity Assessment and Management (CSAM) repository. The required services mandate senior key personnel specifically a Project Manager and Senior Information System Security Specialists possessing advanced credentials (CISSP, CISA, CAP/SSCP, CIPP, CCSK) and deep, institutionalized knowledge of FRA s safety-critical infrastructure. These services are essential for the integration of FRA team under the new Digital Factory model mandated by the FY26 THUD Appropriations Act passed as section D of the Consolidated Appropriations Act, 2026, Consolidated Appropriations Act, 2026 (P.L. 119-75). Please see the attached sole source justification.

Go deeper on this solicitation

FedSift reads the full solicitation package — every attachment — and pre-extracts the compliance matrix, evaluation factors, key risks, win themes and deal-breakers, each with a verbatim quote and the exact PDF page it came from. It scores the opportunity against your company profile, tells you whether to bid as prime or sub, and ranks teaming partners who could close your gaps.

Open the AI analysis in FedSift →

Free forever plan — no credit card. Browse solicitations without an account; sign in for AI analysis and matching.

Other open solicitations in NAICS 541513

All NAICS 541513 solicitations →

More from TRANSPORTATION, DEPARTMENT OF

All TRANSPORTATION, DEPARTMENT OF solicitations →

Source: this notice on SAM.gov. FedSift republishes public federal procurement data and is not affiliated with the U.S. Government. Always confirm dates and requirements against SAM.gov before responding.