Cyber Technology Services

SOL #: 70RCSJ26RFI000001Sources Sought

Overview

Buyer

Homeland Security
Office Of Procurement Operations
CISA CONTRACTING ACTIVITY
Washington, DC, 20528, United States

Place of Performance

Arlington, VA

NAICS

Other Computer Related Services (541519)

PSC

Support Services For Activities Involved With Application Development And Support To Include Analysis, Design, Development, Coding, Testing, And Release Packaging, As Well As Support Of Off The Shelf Business Applications. (DA01)

Set Aside

No set aside specified

Timeline

1
Posted
May 22, 2026
2
Response Deadline
Jun 19, 2026, 8:00 PM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

The Department of Homeland Security (DHS), specifically the Cybersecurity and Infrastructure Security Agency (CISA), is conducting market research through a Request for Information (RFI) for Cyber Technology Services (CTS). This RFI seeks to identify qualified companies capable of supporting CISA's Cybersecurity Division (CSD) Threat Hunting Sub-Division. Responses are due by June 19, 2026, at 4:00 p.m. EST.

Purpose & Background

This RFI is for market research purposes only and is not a solicitation. CISA aims to gather information from industry to refine the scope, technical approach, contract type, potential contract vehicles, and acquisition method for the CTS requirement. The primary goal of the CTS effort is to detect malicious cyber activity, proactively hunt for threats, and respond to cyber incidents targeting U.S. infrastructure to mitigate national risk.

Scope of Work

The contractor will provide a comprehensive range of services over an anticipated five-year period (one base year and four option years). Key task areas include:

  • Program Management
  • IT Architecture, Technology, and Innovation Services
  • IT Engineering, Development Operations, and Services (emphasizing DevSecOps and Agile methodologies)
  • Data Management & Analytics
  • IT Sustainment, Operations and Maintenance (O&M) Services
  • IT Security Operations Services
  • Laboratory Support Services
  • IT Service Desk, Asset Management & Logistical Support

Performance will occur at various government and contractor locations, including Arlington, VA; Bluemont, VA; Washington, DC; Pensacola, FL; Idaho Falls, ID; and Richland, WA. Contractor personnel may require DHS Suitability/Public Trust, Secret, Top Secret (TS), or Top Secret/Sensitive Compartmented Information (TS/SCI) clearances.

Contract Details

  • Opportunity Type: Sources Sought / Request for Information (RFI)
  • NAICS Code: 541519 – Other Computer Related Services (Small Business Size Standard: $34M)
  • Product Service Code: DA01 - Support Services For Activities Involved With Application Development And Support
  • Set-Aside: Not a formal set-aside; market research to inform future acquisition strategy.

Response Requirements

Respondents should submit a capabilities statement (maximum 10 pages) demonstrating their ability to perform all or at least four of the listed task areas. Submissions should highlight experience in large-scale cybersecurity engineering, DevSecOps, 24x7x365 SOC operations, and threat-hunting. Companies must also provide their size, socio-economic status, and information on potential subcontracting or teaming arrangements. Responses to nine specific questions regarding processes, project management, IT systems delivery, data governance, past performance, contract type recommendations, innovative practices, and key personnel qualifications are also required.

Submission Information

  • Deadline: June 19, 2026, 4:00 p.m. EST
  • Format: Electronically in Microsoft Word or PDF, with a cover page including company details (name, POC, SAM.GOV UEI, CAGE code, Business Type, NAICS Code, size standard).
  • Email: hannah.moussa@cisa.dhs.gov and jennifer.burbage@cisa.dhs.gov

Additional Notes

The accompanying Quality Assurance Surveillance Plan (QASP) provides insight into how the government will measure and evaluate contractor performance, detailing specific standards, metrics, and oversight approaches.

People

Points of Contact

Files

Files

Download
Download
Download

Versions

Version 1Viewing
Sources Sought
Posted: May 22, 2026
Cyber Technology Services | GovScope