Application Security Testing (AST) Platform

Location: California
Posted: Jul 15, 2026
Due: Aug 7, 2026
Agency: Sacramento County
Type of Government: State & Local
Category:
  • 70 - General Purpose Information Technology Equipment (including software).
  • D - Automatic Data Processing and Telecommunication Services
Solicitation No: 2026-RFB-0064
Publication URL: To access bid details, please log in.


Project ID: 2026-RFB-0064

Title: Application Security Testing (AST) Platform

Addenda: 1

Release Date: 7/7/2026

Due Date: 8/7/2026

Follow
Application Security Testing (AST) Platform
Last updated by Addendum #1 on Jul 16, 2026 7:40 AM See what changed
Request for Bid
DGS: CAPSD - Procurement
20429 , 20882 , 20888 , 20889 , 20890 ... show all
Project ID: 2026-RFB-0064
Release Date: Tuesday, July 7, 2026
· Due Date: Friday, August 7, 2026 5:00pm
Posted Tuesday, July 7, 2026 10:48am
All dates & times in Pacific Time
Draft Response Events RSVP No Bid22 days, 22 hours, 38 minutes


Post Information

Posted At:Tue, Jul 7, 2026 10:48 AM
Sealed Bid Process:Yes (Bids Sealed / Pricing Sealed)
Private Bid:No
Overview


Summary

The Sacramento County Contract & Purchasing Services Division is releasing a Request for Bid (RFB) on behalf of the Department of Technology to procure an Application Security Testing (AST) platform capable of supporting secure software development across multiple programming languages and development environments. The solution must provide integrated capabilities for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and AI‑assisted remediation to identify, prioritize, and remediate vulnerabilities throughout the development lifecycle. The platform should offer seamless integration with modern source‑code management systems and CI/CD pipelines, support enterprise authentication (including SSO), and include licensing models appropriate for developer‑centric or application‑centric usage. Preference will be given to solutions with FedRAMP or GOVRAMP authorization and robust reporting suitable for audit, compliance, and operational security functions.



Background

Sacramento County has adopted the NIST Cyber-Security framework and strives to align its practices with those described in the moderate controls of NIST 800-53. Sacramento County is made up of numerous departments and critical services, some of which must comply with external regulatory requirements, including PCI, IRS Pub 1075, HIPAA, CJIS, and other requirements related to critical infrastructure.

Sacramento County continually strives to align its practices with the NIST Cyber-Security framework and looks to procure an Application Security Testing platform to help us improve our overall application security practices.



Timeline

Release Project Date:
July 7, 2026
Pre-Bid Meeting (Non-Mandatory):
July 8, 2026, 11:00am
Microsoft Team Meeting
(916) 245-8966 - Conference ID:878 889 367#
Meeting ID: 270 918 541 750 28
Passcode: Kc3mQ3p8
Question Submission Deadline:
July 24, 2026, 5:00pm
Addendum Issued (if necessary):
July 31, 2026, 5:00pm
Submission Deadline:
August 7, 2026, 5:00pm
Award Contract:
August 14, 2026
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

...and Management Development Training Educational Services 541511: Custom Computer Programming Services... Professional, Scientific, ...

City of Los Angeles

Bid Due: 9/21/2026

...in bidding opportunities for the procurement of cyber assets, equipment, software, or services... ...

City of Los Angeles

Bid Due: 1/01/2030

...SOFTWARE AS A SERVICE NAICS Code: 541511 - Custom Computer Programming Services Place ...

DEPT OF DEFENSE

Bid Due: 8/26/2026

...of cyber assets, equipment, software, or services supporting the Bulk Electric System. Additional... ...

City of Los Angeles

Bid Due: 1/02/2030

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.