Search Contract Opportunities

NAS Cyber Information Security and Operations

ID: 693KA8-26-R-00009 • Type: Sources Sought • Match:  90%
Opportunity Assistant

Hello! Please let me know your questions about this opportunity. I will answer based on the available opportunity documents.

Please sign-in to link federal registration and award history to assistant. Sign in to upload a capability statement or catalogue for your company

Popular Questions:
Generate a draft:
Loading

Description

1. INTRODUCTION

Cybersecurity is a critical component of national security and economic stability with the increasing integration of networked systems, connected devices, and digital platforms across the aviation ecosystem. Cyberspace is a vital domain for the Federal Aviation Administration (FAA). The FAA relies on secure, resilient information systems in cyberspace to fulfill its mission to ensure safe and efficient air travel.

The growing sophistication of cyber threats ranging from nation-state actors to independent malicious groups adversaries poses a significant threat to the FAA's cyberspace infrastructure. They actively target government networks, and some have demonstrated the capability to disrupt and/or compromise elements of the FAA's information environment. As these threats from adversaries evolve, the FAA must strengthen its cybersecurity posture to protect its systems, maintain operational continuity, and safeguard the integrity of the National Airspace System (NAS).

The purpose of this market survey is to (1) gather information about potential vendors and their capabilities and (2) obtain vendors' comments and recommendations regarding draft requirements in accordance with the FAA Acquisition Management System (AMS) Policy 3.2.1.2.1. This announcement is not a Screening Information Request (SIR) or Request for Proposals (RFP). The FAA is not seeking or accepting unsolicited proposals. The FAA will not pay for any information received or cost incurred in preparing the responses to this market survey or associated activities. Therefore, any costs associated with the submission of responses are solely at the interested vendor's expense.

The nature of the competition that will be conducted for this procurement has not been finalized at this time. The FAA will review the responses to this market survey and will make acquisition decisions based on vendor responses and the FAA's needs.

This market survey must not be construed as an obligation on the part of the FAA to acquire these services. Since this is not an SIR or RFP, no results will be issued to the responding firms. No solicitation for these items exists at this time. If a solicitation is issued, it will be announced on the SAM.gov website. It is the vendor's responsibility to monitor the website for release of the solicitation.

The FAA may request that one, some, all, or none of the responders to the market survey provide additional information. No evaluation of vendors will occur based on this additional information, and vendor participation in any informational session is not a promise of future business with the FAA. The FAA reserves the right to have communication with any or none of the respondents. A response to this market survey is not a prerequisite for future procurement consideration.

All information provided in response to this market survey except that which qualifies under an exemption may be subject to release under the Freedom of Information Act (FOIA). Information considered proprietary or confidential must be clearly marked as such and the vendor must provide justification to the FAA of such designation if requested. Any information not identified as proprietary or confidential will be used at the FAA's discretion and may be publicly released without further FOIA disclosure review by the FAA or respondent(s).

Any amendment(s) issued to this announcement will be published on SAM.gov. It is the interested parties' responsibility to visit this website frequently to be informed of any changes to this announcement. Note: the FAR references cited in SAM.gov are not applicable to this market survey as the FAA has its own acquisition policies and guidance contained in AMS.

2. BACKGROUND

The Air Traffic Organization (ATO) has a critical infrastructure and the Cyber Security Strategic Plan advances progress towards a National Airspace System (NAS) where it remains secure and resilient. The plan also provides support for critical and essential services to continue and function under a range of cyber conditions. The NAS cybersecurity capabilities must adapt to changing cyber threats. This includes NAS operations that can withstand and/or rapidly recover from disruptions.

The sustainment of NAS Cyber Operations (NCO), Independent Risk Assessment capabilities, and Information Systems Security (ISS) Assurance is critical to fulfilling the requirements of the Office of Management and Budget's (OMB) for continuous monitoring requirement, as well as complying with Federal Information Security Management Act (FISMA), and Executive Order 13636, Presidential Policy Directive (PPD-21) and the ATO Cyber Security Strategic Plan.

Within the FAA there are three distinct cyber domains: NAS (operational/critical infrastructure), Research and Development, and Mission Support (IT). This Statement of Work (SOW) presents support requirements necessary for the NAS systems that reside both in the NAS Operational domain as well as the Mission Support (MS) domain.

3. DESCRIPTION/SCOPE

The FAA anticipates requirements to support cybersecurity testing, risk assessment and operational security services within the National Airspace System (NAS). These services involve complex operational technology (OT) environment, safety-critical infrastructure, and distributed systems that differ significantly from traditional enterprise IT environments.

The scope is expected to include, but not be limited to:

  • Perform independent risk assessment, penetration testing and vulnerability assessment on NAS systems in accordance with FAA Orders, NIST guidance, and federal cybersecurity requirements.
  • Conduct cybersecurity testing in lab, simulation, and operational environments while ensuring no impact to safety-critical NAS operations.
  • Evaluate cybersecurity controls for operational technology, industrial control systems (ICS), SCADA systems, telecommunications infrastructure, and aviation-specific systems.
  • Support regression testing and validation of remediation actions.
  • Support NAS Cyber Operations (NCO) activities including threat hunting, incident response coordination, and development of Courses of Action.
  • Support Tabletop Exercises and operational cyber response planning.
  • Assess cybersecurity architecture of NAS systems including air-to-ground communications, radar, telecom infrastructure, cloud-integrated NAS systems, and hybrid legacy-modern environments.
  • Evaluate system interdependencies across NAS operational, mission support, and R&D domains.
  • Minimize the impact of cyber security events and incidents in support of availability and restoration requirements for NAS critical and essential services
  • Assess current NAS cybersecurity posture, identify capability gaps and risks, evaluate emerging tools and techniques, and recommend improvements.

4. LOCATION OF WORK

The Place of Performance is at both Contractor and Government facilities, including FAA Headquarters (HQ) Washington D.C., FAA Air Traffic Control System Command Center (ATCSCC), William J Hugues Technical Center (WJHTC), FAA Telecommunication Infrastructure (FTI)/Harris Security Operations Control Center, Mike Maroney Aeronautical Center (MMAC), FAA Security Operations Center (Leesburg, VA), and Contingent Operations Locations.

5. NAICS CODE

The North American Industry Classification System (NAICS) Code for this procurement has not yet been finalized.

6. Submittal Requirements for Market Survey

Interested sources should respond to this RFI/Market Survey by providing a Capability Statement in accordance with the requirements below:

One (1) cover page that includes:

    • Name of the vendor/firm/corporation
    • Available NAICS, Unique Entity Identified (UEI) and CAGE code(s)
    • Business size and socioeconomic status
    • Point of contact (i.e., name, title, telephone, email)
    • FAA eFAST contract number (if available)

The Capabilities Statement (maximum of 5 pages including a cover sheet) should demonstrate

  • A company's capabilities to perform cybersecurity work in NAS, aviation, or safety-critical environments.
  • A company's experience performing the full work of work described in the SOW. The description must demonstrate your capability to perform work of similar size, scope, and complexity.
  • A company's familiarity with FAA cybersecurity orders and NAS architecture.
  • A company's ability to support Independent Risk Assessments and Cybersecurity testing, at locations nationwide, on short notice.
  • A company's ability to identify technologies, areas for development of new technologies, and analyze risks associated with each in order to mitigate vulnerabilities found in each risk assessment.

7. Other (if applicable)

Any proprietary or confidential information contained in the submission must be appropriately marked.

Background
The Federal Aviation Administration (FAA) is focused on enhancing cybersecurity as a critical component of national security and economic stability, particularly within the aviation ecosystem. The FAA's mission is to ensure safe and efficient air travel, which relies on secure information systems in cyberspace. The increasing sophistication of cyber threats from various adversaries necessitates a strengthened cybersecurity posture to protect FAA systems and maintain operational continuity.

This market survey aims to gather information about potential vendors' capabilities and obtain their comments on draft requirements, without seeking unsolicited proposals or incurring costs for responses.

Work Details
The FAA anticipates requirements for cybersecurity testing, risk assessment, and operational security services within the National Airspace System (NAS). Key tasks include:
1. Performing independent risk assessments, penetration testing, and vulnerability assessments on NAS systems per FAA Orders and NIST guidance.
2. Conducting cybersecurity testing in lab, simulation, and operational environments without impacting safety-critical operations.
3. Evaluating cybersecurity controls for operational technology, industrial control systems (ICS), SCADA systems, telecommunications infrastructure, and aviation-specific systems.
4. Supporting regression testing and validation of remediation actions.
5. Assisting NAS Cyber Operations (NCO) activities including threat hunting and incident response coordination.
6. Supporting tabletop exercises and operational cyber response planning.
7. Assessing the cybersecurity architecture of NAS systems including air-to-ground communications and cloud-integrated environments.
8. Evaluating system interdependencies across NAS domains.

Period of Performance
The contract will be performed over a period of one base year with four one-year options.

Place of Performance
Work will be conducted at both Contractor and Government facilities including FAA Headquarters in Washington D.C., FAA Air Traffic Control System Command Center, William J Hugues Technical Center, FAA Telecommunication Infrastructure Security Operations Control Center in Harris, Mike Maroney Aeronautical Center, FAA Security Operations Center in Leesburg, VA, and other contingent operations locations.

Overview

Response Deadline
March 18, 2026, 11:30 p.m. EDT (original: March 18, 2026, 6:00 p.m. EDT) Past Due
Posted
March 11, 2026, 1:34 p.m. EDT (updated: March 13, 2026, 1:00 p.m. EDT)
Set Aside
Small Business (SBA)
Place of Performance
United States
Source

Current SBA Size Standard
$34 Million
Pricing
Multiple Types Common
Est. Level of Competition
Low
Est. Value Range
Experimental
$50,000,000 - $300,000,000 (AI estimate)
Odds of Award
12%
Signs of Shaping
The solicitation is open for 7 days, below average for the FAA Headquarters.
On 3/11/26 FAA Headquarters issued Sources Sought 693KA8-26-R-00009 for NAS Cyber Information Security and Operations due 3/18/26. The opportunity was issued with a Small Business (SBA) set aside with NAICS 541519 (SBA Size Standard $34 Million) and PSC DB02.
Primary Contact
Name
Elizabeth H. Williams   Profile
Phone
None

Secondary Contact

Name
Stacy Roberson   Profile
Phone
None

Documents

Posted documents for Sources Sought 693KA8-26-R-00009

Opportunity Assistant


AI Analysis

AI Generate

Incumbent or Similar Awards

Contracts Similar to Sources Sought 693KA8-26-R-00009

Potential Bidders and Partners

Awardees that have won contracts similar to Sources Sought 693KA8-26-R-00009

Similar Active Opportunities

Open contract opportunities similar to Sources Sought 693KA8-26-R-00009

Experts for NAS Cyber Information Security and Operations

Recommended subject matter experts available for hire

Additional Details

Source Agency Hierarchy
TRANSPORTATION, DEPARTMENT OF > FEDERAL AVIATION ADMINISTRATION > 693JF9 HEADQUARTERS
FPDS Organization Code
6920-00001
Source Organization Code
100179147
Last Updated
April 2, 2026
Last Updated By
elizabeth.h.williams@faa.gov
Archive Date
April 2, 2026