NATO Business Opportunity: Web Asset Security Assessment Grey Box Web Penetration Testing

Location: Federal
Posted: Jan 22, 2025
Due: Feb 6, 2025
Agency: COMMERCE, DEPARTMENT OF
Type of Government: Federal
Category:
  • 70 - General Purpose Information Technology Equipment (including software).
Solicitation No: RFQ-CO-424225-PEN
Publication URL: To access bid details, please log in.
Follow
NATO Business Opportunity: Web Asset Security Assessment Grey Box Web Penetration Testing
Active
Contract Opportunity
Notice ID
RFQ-CO-424225-PEN
Related Notice
Department/Ind. Agency
COMMERCE, DEPARTMENT OF
Sub-tier
BUREAU OF INDUSTRY AND SECURITY
General Information
  • Contract Opportunity Type: Special Notice (Original)
  • Original Published Date: Jan 22, 2025 09:09 am EST
  • Original Response Date: Feb 06, 2025 05:00 pm EST
  • Inactive Policy: Manual
  • Original Inactive Date: Feb 12, 2025
  • Initiative:
Classification
  • Original Set Aside:
  • Product Service Code:
  • NAICS Code:
    • 541519 - Other Computer Related Services
  • Place of Performance:
    BEL
Description

The NATO Communications and Information Agency (NCIA) intends to issue a Request for Quotation (RFQ) for Web Asset Security Assessment Grey Box Web Penetration Testing.



Potential U.S. prime contractors must 1) maintain a professionally active facility (office, factory, laboratory, etc.) within the United States, 2) be pre-approved for participation in NATO International Competitive Bidding (ICB), 3) be issued a Declaration of Eligibility (DOE) by the Department of Commerce (DOC), and 4) register with the NCI Agency’s eProcurement tool, Neo: https://www.ncia.nato.int/business/procurement/neo-eprocurement



In addition, contractor personnel will be required to work unescorted in Class II Security areas. Therefore, access can only be permitted to cleared individuals. Only companies maintaining the appropriate personnel clearances will be able to perform the resulting contract.



The reference for the RFQ is RFQ-CO-424225-PEN and all correspondence concerning the RFQ should include this reference.



SUMMARY OF REQUIREMENTS



Please note that these requirements are being refined and will be included in further details as part of the RFQ.



Project Objective



To assess the security vulnerabilities and risks associated with NATO web assets. The security audit will be conducted using a greybox approach and following OWASP Application Security Verification Standard.



Scope of Work



1. Conduct manual penetration testing following a grey box approach for i) web assets exposed to the internet and ii) web assets not exposed to the internet.

2. Assess the security vulnerabilities and risks associated with the web assets.

3. Provide recommendations to mitigate the identified risks.



Period of Performance



A nine month basic period, followed by two 12-month optional periods. The basic period is anticipated to start in April 2025 and end on 31 December 2025. This timeline represents the anticipated duration of the project, and adjustments may be made as per the requirements of the solicitation process and subsequent contractual agreement



BECOMING ELIGIBLE TO BID



NATO ICB requires that the U.S. Government issue a DOE for potential U.S. prime contractors interested in this project. Before the U.S. Government can do so, however, the U.S. Government must approve the U.S. firm for participation in NATO ICB. U.S. firms are approved for NATO ICB on a facility-by-facility basis.



The U.S. NATO ICB application is a one-time application. The application requires supporting documentation in the form of 1) a company resume or capability statement indicating contracts completed as a prime contractor and 2) an annual report or set of financial documents indicating compilation, review, or audit by an independent CPA.



U.S. firms can download a copy of the U.S. NATO ICB application from the following website:



https://www.bis.doc.gov/index.php/other-areas/strategic-industries-and-economic-security-sies/nato-related-business-opportunities



DOC is the U.S. Government agency that approves NATO ICB applications. Please submit to the email address provided your application and supporting documentation (as attachments). If your firm is interested in a specific NATO ICB project at this time, please also include the following in the TEXT of your email:



- the title and/or solicitation number of the project

- the name/phone/email of the company employee who should receive the bid documents



After approval of your one-time NATO ICB application, DOC will then know to follow up by issuing a DOE for the project. DOC will transmit the DOE to the NATO contracting agency.



IMPORTANT DATES:



Request a DOE (and, for firms new to NATO ICB, submit the completed one-time NATO ICB application): 06 February 2025



NCIA distributes the RFQ (planned): 14 February 2025



Bid closing (anticipated): 28 February 2025



Contract Award (estimated): 01 April 2025


Attachments/Links
Contact Information
Primary Point of Contact
Secondary Point of Contact


History
  • Jan 22, 2025 09:09 am ESTSpecial Notice (Original)
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

...to more effective terminal ballistics. Enhanced Barrier Penetration: The increased velocity and kinetic..., ...

DEPT OF DEFENSE

Bid Due: 6/08/2026

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.