Cybersecurity Assessments and Services
ID: BPM052516
• State: Maryland
Opportunity Assistant
Loading
Description
Background
The Maryland Department of General Services (DGS OSP), on behalf of the Maryland Department of Information Technology (DoIT), is issuing this Request for Proposals (RFP) to procure cybersecurity assessment services. This initiative aims to fulfill Maryland law requirements mandating regular cybersecurity assessments for Executive Branch agencies. It supports DoIT's mission to safeguard digital assets and ensure resilient government operations.
Work Details
The Contractor will conduct approximately ninety (90) cybersecurity assessments over a 24-month period, determining each unit's overall security posture and maturity. Assessments will utilize the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) as the standard measurement framework. The Contractor is responsible for scoping each assessment, conducting interviews, assessing documentation, rating maturity levels, and presenting findings and recommendations.
Deliverables include an Evaluation Standards Guide for consistent scoring, real-time reporting dashboards compatible with the State’s Governance, Risk, and Compliance (GRC) platform, and integration of historical assessment data into reporting deliverables. The Contractor must also develop a comprehensive Quality Assurance process to ensure high-quality deliverables.
Period of Performance
The contract duration is two (2) base years with one (1) option period of two (2) years.
Place of Performance
The primary place of performance is the Contractor’s location and possibly at various locations throughout the State of Maryland.
Bidder Requirements
An overall Minority Business Enterprise (MBE) subcontract participation goal of 15% has been established for this procurement. Additionally, there is a Veteran-Owned Small Business Enterprise (VSBE) participation goal of 3%. Offerors must demonstrate knowledge of NIST-based cybersecurity assessments and prior experience conducting similar assessments.
The Maryland Department of General Services (DGS OSP), on behalf of the Maryland Department of Information Technology (DoIT), is issuing this Request for Proposals (RFP) to procure cybersecurity assessment services. This initiative aims to fulfill Maryland law requirements mandating regular cybersecurity assessments for Executive Branch agencies. It supports DoIT's mission to safeguard digital assets and ensure resilient government operations.
Work Details
The Contractor will conduct approximately ninety (90) cybersecurity assessments over a 24-month period, determining each unit's overall security posture and maturity. Assessments will utilize the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) as the standard measurement framework. The Contractor is responsible for scoping each assessment, conducting interviews, assessing documentation, rating maturity levels, and presenting findings and recommendations.
Deliverables include an Evaluation Standards Guide for consistent scoring, real-time reporting dashboards compatible with the State’s Governance, Risk, and Compliance (GRC) platform, and integration of historical assessment data into reporting deliverables. The Contractor must also develop a comprehensive Quality Assurance process to ensure high-quality deliverables.
Period of Performance
The contract duration is two (2) base years with one (1) option period of two (2) years.
Place of Performance
The primary place of performance is the Contractor’s location and possibly at various locations throughout the State of Maryland.
Bidder Requirements
An overall Minority Business Enterprise (MBE) subcontract participation goal of 15% has been established for this procurement. Additionally, there is a Veteran-Owned Small Business Enterprise (VSBE) participation goal of 3%. Offerors must demonstrate knowledge of NIST-based cybersecurity assessments and prior experience conducting similar assessments.
Overview
Opportunity Type
RFP: Double Envelope Proposal
Opportunity ID
BPM052516
Version
1
Response Deadline
Jan. 15, 2026
Past Due
Date Posted
Sept. 30, 2025
Source
Est. Value Range
Experimental
$5,000,000 - $15,000,000
(AI estimate)
Agency Distribution
High
On 9/30/25 State of Maryland Government in Maryland issued RFP: Double Envelope Proposal Cybersecurity Assessments and Services with ID BPM052516 due 1/15/26.
Contacts
Documents
Posted documents for Cybersecurity Assessments and Services
Opportunity Assistant
AI Analysis
AI Generate
Classifications
Opportunity Classification
Actuarial consulting services
Additional Details
Lot #
1
Round #
2