Search Contract Opportunities

Automated Penetration Test Vulnerability Platform Request for Information (RFI)

ID: 70T03025_RFI_SIVM • Type: Sources Sought • Match:  100%
Opportunity Assistant

Hello! Please let me know your questions about this opportunity. I will answer based on the available opportunity documents.

Please sign-in to link federal registration and award history to assistant. Sign in to upload a capability statement or catalogue for your company

Some suggestions:
Please summarize the work to be completed under this opportunity
Draft a sources sought response template for this opportunity
Do the documents mention an incumbent contractor?
Does this contract have any security clearance requirements?
I'd like to anonymously submit a question to the procurement officer(s)
Loading

Description

Please see Attached Request for Information (RFI) for The Transportation Security Administration (TSA) Automated Penetration Test Vulnerability Platform requirement. For any comments, questions, or concerns, please look at the "Contact Information" tab for Email and/or Number. Thank you for the time.

Background
The Transportation Security Administration (TSA) is seeking to enhance its capabilities in airport environments through the acquisition of a commercial off-the-shelf (COTS) Automated Penetration Test Vulnerability Platform. This initiative aims to improve TSA's ability to conduct vulnerability testing, develop security solutions, and implement effective measures in response to emerging threats. The agency is interested in gathering information from potential business sources, including various types of small businesses, to inform its acquisition decisions.

Work Details
The platform must provide the following capabilities:
- Screening Efficiency: Enable seamless security asset information sharing, utilize non-intrusive inspection technology, interface with airport security sensors and scanning machines, perform mission-critical analysis, conduct testing and evaluation of systems and algorithms, draft potential scenarios/simulations for real-life situations, and include a swab sampling assessment tool.

- Technical Requirements: A standalone, hardened laptop platform with a customized operating system is required. It must host an integrated security assessment framework capable of performing comprehensive evaluations across operating systems, databases, web applications, and network appliances. All functionality must be self-contained without reliance on external infrastructure. The system should support integration with commercial and open-source assessment tools such as Nessus for OS vulnerability testing, Burp Suite for web application testing, AppDetective Pro for database testing, and Nipper Studio for network device testing.

- Comprehensive Automation: The platform should automate complex logic pathing for thorough assessment results from various security solutions and conduct detailed assessments on both IT and Operational Technology (OT) environments.

- Assessment Techniques: Support asset discovery, vulnerability assessment, exploitation techniques, ransomware simulation, data breach exposure analysis, and Open-Source Intelligence (OSINT) gathering. Automated penetration testing capabilities are also required.

- Specific Assessment Capabilities: Conduct credentialed assessments automatically and discover vendor-specific vulnerabilities related to airport screening lane equipment.

- Advanced Reporting: Generate detailed reports with risk-based guidance for remediation of findings.

- Performance Flexibility: Support deployment on air-gapped laptops or in cloud environments without disrupting live TSA operations.

- Support Package: Assistance with tool configuration and operation is necessary; support should be available via phone, email, or web-based portal during business hours.

Place of Performance
The geographic location for performance is not explicitly stated but pertains to TSA operations at airport environments.

Overview

Response Deadline
July 8, 2025, 6:00 p.m. EDT Past Due
Posted
June 18, 2025, 6:10 p.m. EDT
Set Aside
None
PSC
None
Place of Performance
Springfield, VA 22151 United States
Source

Current SBA Size Standard
$40 Million
Pricing
Likely Fixed Price
Est. Level of Competition
Low
Odds of Award
15%
On 6/18/25 Transportation Security Administration issued Sources Sought 70T03025_RFI_SIVM for Automated Penetration Test Vulnerability Platform Request for Information (RFI) due 7/8/25. The opportunity was issued full & open with NAICS 518210.
Primary Contact
Name
Rohan Martin   Profile
Phone
(540) 359-1564

Secondary Contact

Name
Michele Reeves   Profile
Phone
(609) 813-3371

Documents

Posted documents for Sources Sought 70T03025_RFI_SIVM

Question & Answer

The AI Q&A Assistant has moved to the bottom right of the page

Incumbent or Similar Awards

Contracts Similar to Sources Sought 70T03025_RFI_SIVM

Potential Bidders and Partners

Awardees that have won contracts similar to Sources Sought 70T03025_RFI_SIVM

Similar Active Opportunities

Open contract opportunities similar to Sources Sought 70T03025_RFI_SIVM

Additional Details

Source Agency Hierarchy
HOMELAND SECURITY, DEPARTMENT OF > TRANSPORTATION SECURITY ADMINISTRATION > ENTERPRISE INFORMATION TECHNOLOGY
FPDS Organization Code
7013-70T030
Source Organization Code
500000090
Last Updated
July 23, 2025
Last Updated By
rohan.martin@tsa.dhs.gov
Archive Date
July 23, 2025