Risk Assessment - Sources Sought Announcement

Location: Virginia
Posted: Oct 16, 2025
Due: Oct 23, 2025
Agency: DEPT OF DEFENSE
Type of Government: Federal
Category:
  • D - Automatic Data Processing and Telecommunication Services
Solicitation No: N63285-25-SSA-0017
Publication URL: To access bid details, please log in.
Follow
Risk Assessment - Sources Sought Announcement
Active
Contract Opportunity
Notice ID
N63285-25-SSA-0017
Related Notice
Department/Ind. Agency
DEPT OF DEFENSE
Sub-tier
DEPT OF THE NAVY
Major Command
NAVSUP
Sub Command
NAVSUP OTHER HCA
Sub Command 2
MISC
Office
NCIS QUANTICO VA
Looking for contract opportunity help?

APEX Accelerators are an official government contracting resource for small businesses. Find your local APEX Accelerator (opens in new window) for free government expertise related to contract opportunities.

APEX Accelerators are funded in part through a cooperative agreement with the Department of Defense.

The APEX Accelerators program was formerly known as the Procurement Technical Assistance Program (opens in new window) (PTAP).

General Information
  • Contract Opportunity Type: Sources Sought (Original)
  • Original Published Date: Oct 16, 2025 03:37 pm EDT
  • Original Response Date: Oct 23, 2025 05:00 pm EDT
  • Inactive Policy: 15 days after response date
  • Original Inactive Date: Nov 07, 2025
  • Initiative:
    • None
Classification
  • Original Set Aside: Total Small Business Set-Aside (FAR 19.5)
  • Product Service Code: DA10 - IT AND TELECOM - BUSINESS APPLICATION/APPLICATION DEVELOPMENT SOFTWARE AS A SERVICE
  • NAICS Code:
    • 541519 - Other Computer Related Services
  • Place of Performance:
    Quantico , VA 22134
    USA
Description

This Sources Sought Announcement is intended to identify Risk Assessment platforms capable of of performing the tasks outlined below.



NCIS seeks a Software-as-a-Service (SaaS) platform capable of performing cyber risk assessments for partner entities. The platform must provide integrated cyber supply chain risk management functionality to support ongoing mission requirements.



The required service must:




  • Provide a MITRE-based risk assessment

    • Including a cyber risk technical assessment

    • FAIR (Factor Analysis of Information Risk) analysis

    • External compliance estimate

    • Ransomware Susceptibility Index (RSI).



  • Offer a clear and easily interpretable cyber risk report featuring:

    • Letter-grade ratings with the capability to drill down into the technical details underlying each risk category.



  • Support unlimited NCIS user accounts

  • Enable the continuous monitoring of up to 200 entities.



**Please let us know if you have any recommendations for alternative PSC or NAICS codes.






Attachments/Links
Contact Information
Contracting Office Address
  • 27130 TELEGRAPH ROAD
  • QUANTICO , VA 22134-2253
  • USA
Primary Point of Contact
Secondary Point of Contact
History
  • Oct 16, 2025 03:37 pm EDTSources Sought (Original)
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

...sample employee communications and forms, and conducting a risk analysis specific to the ...

Loudoun County

Bid Due: 6/29/2026

...are detailed in the PWS and include, but are not limited to: Program ...

DEPT OF DEFENSE

Bid Due: 6/11/2026

...the City's Climate Action Plan and Climate Risk and Vulnerability Assessment, the City ...

City of Charlottesville

Bid Due: 6/16/2026

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.