Out For Tender › United States › IT services: consulting, software development, Internet and support
USHMM-RFI-2027-MSSP
- Buyer
- USHMM PROCUREMENT DIVISION, United States Holocaust Memorial Museum
- Country
- United States
- Category
- IT services: consulting, software development, Internet and support
- Deadline
- Closes in 28 days (30 Oct 2026 17:00 UTC-4)
- Published
- 1 Oct 2026
- Procedure
- Presolicitation - No Set aside used
Read the official notice and bid → Bidding always happens on the buyer's own portal, never here.
What the buyer is asking for
DISCLAIMER / MARKET RESEARCH NOTICE:This Request for Information (RFI) is issued solely for information gathering and planning purposes. It does not constitute a Request for Proposal (RFP), Invitation for Bid (IFB), or an obligation on the part of the United States Holocaust Memorial Museum (USHMM) to acquire any products or services. Responses to this notice are not offers and cannot be accepted by USHMM to form a binding contract. Responders are solely responsible for all expenses associated with responding to this RFI. The United States Holocaust Memorial Museum (USHMM) is conducting formal market research to evaluate commercial vendor capabilities, industry pricing benchmarks, federal/commercial labor rates, and available contract acquisition vehicles (e.g., GSA MAS SIN 54151HACS, NASA SEWP, CIO-SP3/4, SAM.gov) for re-procuring comprehensive Managed Information Technology (IT) Security, Multi-Cloud/DevSecOps Architecture, Network Engineering, and specialized Managed Security Service Provider (MSSP) operational activities. The primary objective of this market research effort is to evaluate whether competitive commercial marketplace capabilities exist to: Sustain, support, and execute day-to-day operations across USHMM's existing "As-Is" securityinfrastructure without operational disruption or increased organizational risk. Perform rigorous security architecture evaluations, threat modeling, gap analyses, and complianceassessments against industry-best security and privacy standards (NIST SP 800-53 r5, FISMA, PCI DSSv4.2.1, CISA Zero Trust Maturity Model, CSF 2.0). Architect and recommend a modernized, cost-effective "To-Be" security state incorporating ZeroTrust architecture, automated orchestration, tool consolidation, and a Government OwnedContractor Operated (GOCO) Security Operations Center (SOC) framework. Execute a seamless, structured transition lifecycle from the "As-Is" state to the "To-Be" operationalmodel within strict schedule and budget parameters. Pricing Benchmarks & Market Rate Expectations Provide feedback on the commercial feasibility of managing this scope under a Firm-Fixed-Price (FFP)monthly fee structure. Provide fully burdened hourly commercial labor rates or GSA schedule rates in the Washington, DCMetropolitan Area for equivalent labor categories (CISO, Security Architect, DevSecOps Engineer,Security Analyst, Network/System Engineer). Submission Instructions & Response Format Response Deadline: All responses shall be submitted electronically no later than October 30, 2026, at 5:00 PM EDT. Submission Format: Responses must be submitted in PDF or Microsoft Word format, strictly limited to no more than fifteen (15) pages (excluding cover page and labor rate tables). Point of Contact: Submissions and any clarifying technical inquiries must be emailed to Mary Green, USHMM Contracting Officer at magreen@ushmm.org with the subject line "RFI Response - USHMM Managed IT Security & MSSP Services".
Source: SAM · reference 95476727RFI-MSSP · JSON