Federal solicitation · IT-1 · back to recent
Notification of Award of Sole Source Bridge Action_Cybersecurity and Privacy Program Support Services
TRANSPORTATION, DEPARTMENT OF · NAICS 541513
Solicitation description
In strict compliance with GSAR 538.7104-3(b)(ii), this notice is being made publicly available within 14 days after the award of the modification to ensure procedural transparency under GSAÆs modernized FSS ordering procedures. This action is a 12-month sole source award to the incumbent contractor, Criterion, for uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. This bridge extends the period of performance from July 20, 2026 to 07/19/2027. This contract action is necessitated by the United States Department of TransportationÆs (USDOT) reorganization of its Information Technology (IT) function into a digital factory model under the 1DOT reorganization The FRA requires uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. These services ensure the FRA fully complies with the Federal Information Security Modernization Act (FISMA) of 2014, OMB Circular A-130, and relevant Departmental cybersecurity directives. The scope of work encompasses comprehensive coverage for all FRA FISMA-reportable systems, requiring the continuous maintenance of the Risk Management Framework (RMF) and the Information Security Continuous Monitoring Program (ISCMP). The architecture currently under administration includes: Eight (8) production systems (including three hosted in the cloud, seven Moderate Security Impact systems, and five Privacy systems). Four (4) systems under active development, bringing the total technical architecture to twelve (12) IT systems. Environment Composition: Microsoft Dynamics 365 applications, cloud environments (SaaS, PaaS, IaaS), and on-premises datacenters. The contractor is required to operate, monitor, and configure the DOT and DHS Security Tool Suites utilized within the FRA enclave. This includes specialized engineering and administration of tools such as Tenable Nessus, BigFix, SCCM, SCOM, DB Protect, Netsparker, Burp Suite, and the DOT Cybersecurity Assessment and Management (CSAM) repository. The required services mandate senior key personnelŚspecifically a Project Manager and Senior Information System Security SpecialistsŚpossessing advanced credentials (CISSP, CISA, CAP/SSCP, CIPP, CCSK) and deep, institutionalized knowledge of FRAÆs safety-critical infrastructure. These services are essential for the integration of FRA team under the new Digital Factory model mandated by the FY26 THUD Appropriations Act ¢ passed as section D of the Consolidated Appropriations Act, 2026, Consolidated Appropriations Act, 2026 (P.L. 119-75). Please see the attached sole source justification.
Similar opportunities
Other open SAM.gov opportunities under the same NAICS, prioritizing the same buying agency.
| Title | Agency | Est. value | Basis |
|---|---|---|---|
| CONTRACT AWARD: Aircraft Cabin Research Facility... | TRANSPORTATION, DEPARTMENT OF | $1.7M | same agency naics |
| Elastic Search, Logstash, and Kibana (ELK) Support Services | TRANSPORTATION, DEPARTMENT OF | - | same agency naics |
| Notice of Intent to Single Source to Newton Design, LLC | TRANSPORTATION, DEPARTMENT OF | - | same agency naics |
| AFIMSC IT Support Services | DEPT OF DEFENSE | $62.5M | same naics |
| Maintenance Business System Modernization (MABSM) Bridge Efforts | DEPT OF DEFENSE | $45.7M | same naics |
| Bridge - Technology Support Services | DEPT OF DEFENSE | $9.9M | same naics |
| LSRP 6-month Extension | VETERANS AFFAIRS, DEPARTMENT OF | $1.8M | same naics |
| Middle Georgia State University Facility | DEPT OF DEFENSE | $1.2M | same naics |
Data this profile does NOT cover
- No likely incumbent surfaced; the solicitation number did not prefix-match any award in the FPDSAward window.
- No FPDSAward rows for NAICS 541513 in the trailing 12 months; vendor concentration unavailable.