Active Solicitation · SOCIAL SECURITY ADMINISTRATION

    REQUEST FOR INFORMATION (RFI) -- DAST TOOL

    SOCIAL SECURITY ADMINISTRATION
    Sol. 28321326RI0000019SolicitationBALTIMORE, MD
    Open · 6d remaining
    DAYS TO CLOSE
    6
    closes May 19, 2026
    POSTED
    May 5, 2026
    Publication date
    NAICS CODE
    513210
    Primary industry classification
    PSC CODE
    7A21
    Product & service classification

    AI Summary

    The Social Security Administration is seeking information on a Dynamic Application Security Testing (DAST) tool to enhance its cybersecurity measures. This tool will support the analysis of applications during execution, fulfilling federal mandates and improving security protocols. Interested vendors should respond to this RFI by the specified deadline.

    Contract details

    Solicitation No.
    28321326RI0000019
    Notice Type
    Solicitation
    Posted Date
    May 5, 2026
    Response Deadline
    May 19, 2026
    NAICS Code
    513210AI guide
    PSC / Class Code
    7A21
    Primary Contact
    Keelin McGrath
    State
    MD
    ZIP Code
    21235
    AI Product/Service
    product

    Description

    The Web Application Security Team (WAST) performs static code scanning of all SSA applications as part of the Office of Information Security’s (OIS) cybersecurity program. This is accomplished with the static application security testing (SAST) tool called Checkmarx and the software composition analysis (SCA) tool called Black Duck. Both of these solutions are white box testing tools that analyze the application’s code as it's being built. WAST is looking to procure a Dynamic Application Security Testing (DAST) solution to better analyze SSA applications, to bolster FISMA metrics, and to satisfy the requirements from multiple external audits and assessments. The DAST tool would scan applications as they are executed to identify exploits that can only be detected from black box testing. This funding is required immediately to better support the workload of multiple federal mandates and to provide black box testing early in the development lifecycle to stop exploits before they go to Production and potentially cause a security breach. This will also support a new requirement to perform penetration testing on all Tier 1 applications and all information systems going through the Authority to Operate (ATO) process.

    Key dates

    1. May 5, 2026Posted Date
    2. May 19, 2026Proposals / Responses Due

    AI search tags

    Frequently asked questions

    REQUEST FOR INFORMATION (RFI) -- DAST TOOL is a federal acquisition solicitation issued by SOCIAL SECURITY ADMINISTRATION. Review the full description, attachments, and submission requirements on SamSearch before the response deadline.

    SamSearch Platform

    Stop searching. Start winning.

    AI-powered intelligence for the right opportunities, the right leads, and the right time.