Notification of Award of Sole Source Bridge Action_Cybersecurity and Privacy Program Support Services
TRANSPORTATION, DEPARTMENT OF › FEDERAL RAILROAD ADMINISTRATION › 693JJ6 FEDERAL RAILROAD ADMIN
No stated response deadline. Posted 2026-08-04.
View on SAM.gov →Official listing
- Posted
- 2026-08-04
- NAICS code
- 541513
- Product/service code
- DA01
- Place of performance
- Washington, DC, 20590, USA
- Award number
- 693JJ621F000026
- Award date
- 2026-07-21
Description
In strict compliance with GSAR 538.7104-3(b)(ii), this notice is being made publicly available within 14 days after the award of the modification to ensure procedural transparency under GSAs modernized FSS ordering procedures. This action is a 12-month sole source award to the incumbent contractor, Criterion, for uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. This bridge extends the period of performance from July 20, 2026 to 07/19/2027. This contract action is necessitated by the United States Department of Transportations (USDOT) reorganization of its Information Technology (IT) function into a digital factory model under the 1DOT reorganization The FRA requires uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. These services ensure the FRA fully complies with the Federal Information Security Modernization Act (FISMA) of 2014, OMB Circular A-130, and relevant Departmental cybersecurity directives. The scope of work encompasses comprehensive coverage for all FRA FISMA-reportable systems, requiring the continuous maintenance of the Risk Management Framework (RMF) and the Information Security Continuous Monitoring Program (ISCMP). The architecture currently under administration includes: Eight (8) production systems (including three hosted in the cloud, seven Moderate Security Impact systems, and five Privacy systems). Four (4) systems under active development, bringing the total technical architecture to twelve (12) IT systems. Environment Composition: Microsoft Dynamics 365 applications, cloud environments (SaaS, PaaS, IaaS), and on-premises datacenters. The contractor is required to operate, monitor, and configure the DOT and DHS Security Tool Suites utilized within the FRA enclave. This includes specialized engineering and administration of tools such as Tenable Nessus, BigFix, SCCM, SCOM, DB Protect, Netsparker, Burp Suite, and the DOT Cybersecurity Assessment and Management (CSAM) repository. The required services mandate senior key personnelspecifically a Project Manager and Senior Information System Security Specialistspossessing advanced credentials (CISSP, CISA, CAP/SSCP, CIPP, CCSK) and deep, institutionalized knowledge of FRAs safety-critical infrastructure. These services are essential for the integration of FRA team under the new Digital Factory model mandated by the FY26 THUD Appropriations Act passed as section D of the Consolidated Appropriations Act, 2026, Consolidated Appropriations Act, 2026 (P.L. 119-75). Please see the attached sole source justification.
Primary contact
Carr, Matthew · [email protected]
Every notice on this board links its official SAM.gov listing — verify details there before responding.
Run federal grants too?
Contract notices are free to browse and are not part of member fit-scoring, alerts, or the Tuesday digest — those cover grants. Members get every federal grant that opens fit-scored to their organization — with an alert when a real match posts.
See grants pricingGet the free Tuesday grants digest
One email a week: the biggest new federal grants and what’s closing soon — the same list for everyone. Contract notices stay on this free board. Unsubscribe any time.
Want contract alerts?
Fit-scored alerts cover grants today; this contracts board is free to browse. If alerts for contract notices would help your team, say so below — enough interest is what gets them built.