PCI DSS Compliance Technical Support

SOL #: F41999-26-Q-0055Combined Synopsis/Solicitation

Overview

Buyer

DEPT OF DEFENSE
Dept Of The Air Force
FA9000 AF NAF PO
JBSA LACKLAND, TX, 78236-9800, United States

Place of Performance

DWG, TX

NAICS

Computer Systems Design Services (541512)

PSC

Engineering And Technical Services (R425)

Set Aside

No set aside specified

Timeline

1
Posted
Mar 18, 2026
2
Submission Deadline
Apr 30, 2026, 9:00 PM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

The Department of the Air Force's Air Force Services Center (AFSVC) is seeking PCI DSS Compliance Technical Support through a Firm-Fixed Price Request for Quote (RFQ), solicitation number F41999-26-Q-0055. This opportunity aims to establish a proactive, centrally governed security posture, ensure long-term verifiable Payment Card Industry Data Security Standard (PCI DSS) compliance, and empower local personnel for self-sufficient operation within AFSVC's cardholder data environment. Quotes are due by Close of Business on April 30, 2026.

Purpose & Scope

AFSVC, which manages nonappropriated fund (NAF) enterprise Services programs (food, fitness, childcare, lodging, recreation), processes approximately 90% of its transaction revenue via merchant cards. Current practices are not fully PCI DSS compliant, posing security risks. The contractor will provide expert technical support and sustainment across three phases:

  • Phase 1: Conduct a technical gap analysis and develop a solution strategy, including tool recommendations, integration into a reporting framework, cost analysis, and an implementation plan.
  • Phase 2: Support the deployment and integration of security tools and services, validate implemented controls, and remediate identified gaps. AFSVC will procure necessary software, hardware, and licensing, with the contractor responsible for implementation, configuration, and management.
  • Phase 3 (and Option Years): Provide steady-state daily operations and flexible surge support for up to 30 installations, including monitoring, Standard Operating Procedure (SOP) development, 24/7 support, PCI DSS assessment preparation, and knowledge transfer/training. The contractor will provide oversight, analysis, and remediation guidance, with designated government personnel executing privileged actions. Remote work is authorized for the majority of the contract, with the primary place of performance at JBSA Lackland, TX.

Contract Details

  • Contract Type: Firm-Fixed Price (FFP)
  • Duration: One (1) year base period with four (4) one-year options, for a potential total of five (5) years.
  • Funding: Nonappropriated Funds (NAF); Federal Acquisition Regulation (FAR) rules do not apply.
  • Set-Aside: None.
  • Place of Performance: JBSA Lackland, TX, with remote work authorized.
  • Payment: NAF Purchase Card (Visa) within 30 days of invoice and acceptance.

Submission & Evaluation

This is an LPTA (Lowest Price Technically Acceptable) acquisition. Quotes will be evaluated without discussions, so offerors should submit their best terms initially. Evaluation factors include:

  • Factor 1: Contractor Statement of Work (CSOW)/Technical Solution (Acceptable/Unacceptable) – must demonstrate thorough understanding of the Statement of Objectives (SOO).
  • Factor 2: Past Performance (Acceptable/Unacceptable) – requires a minimum of three references for the prime contractor and any subcontractors/teaming partners.
  • Factor 3: Cost/Price – evaluated for realism, balance, and reasonableness. Travel costs are separate from the firm-fixed price. Required submissions include a price quote, technical response to the SOO, confirmation of NAF Standard Clauses acceptance/exceptions, and acceptance/disagreement to Contract Admin Data. Quotes must be valid for a minimum of 180 calendar days.

Key Dates & Contacts

  • Questions Due: NLT 4:00 PM, CST, Tuesday, April 14, 2026.
  • Consolidated Q&A Posted: NLT 4:00 PM, CST, Thursday, April 16, 2026.
  • Quotes Due: Close of Business, Wednesday, April 30, 2026.
  • Primary Contact: Whitney Ward (whitney.ward.1@us.af.mil)
  • Secondary Contact: Valerie Baltimore (valerie.baltimore@us.af.mil)

People

Points of Contact

Files

Files

Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download
Download

Versions

Version 1Viewing
Combined Synopsis/Solicitation
Posted: Mar 18, 2026
PCI DSS Compliance Technical Support | GovScope