SLED Opportunity · NEW MEXICO · CITY OF SANTA FE, NM

    Santa Fe Reginal Airport Security Auditing and Record Keeping

    Issued by City of Santa Fe, NM
    cityRFPCity of Santa Fe, NMSol. 289219
    Closed
    STATUS
    Closed
    due Aug 4, 2026
    PUBLISHED
    Jul 31, 2026
    Posting date
    JURISDICTION
    City of
    city
    NAICS CODE
    541512
    AI-classified industry

    AI Summary

    Santa Fe Regional Airport seeks a TSA-compliant security record keeping and auditing system to centralize and secure airport security data, ensure regulatory compliance, and support operational efficiency with advanced audit and reporting capabilities.

    Opportunity details

    Solicitation No.
    289219
    Type / RFx
    RFP
    Status
    open
    Level
    city
    Published Date
    July 31, 2026
    Due Date
    August 4, 2026
    NAICS Code
    541512AI guide
    Agency
    City of Santa Fe, NM

    Description

    The Airport Security Record Keeping and Auditing System shall provide a secure, centralized, and auditable platform for the collection, management, retention, retrieval, and reporting of airport security records required to support compliance with Transportation Security Administration (TSA) regulations, Airport Security Program (ASP) requirements, and applicable federal standards. The system shall support security operations by maintaining accurate records for personnel, credentials, access control activities, inspections, incidents, investigations, training, equipment maintenance, regulatory compliance activities, and corrective actions. All records shall be managed throughout their lifecycle in accordance with applicable TSA record retention requirements and organizational policies. The solution shall provide comprehensive audit capabilities by maintaining immutable audit logs that capture all user activities, authentication events, data creation, modification, deletion, approvals, electronic signatures, report generation, and administrative changes. Audit records shall include user identification, timestamps synchronized to an authoritative time source, originating device or workstation information where applicable, and a detailed description of the action performed. The system shall enforce role-based access control (RBAC), least-privilege principles, multi-factor authentication (MFA), encryption of data at rest and in transit, and protection of Sensitive Security Information (SSI) in accordance with 49 CFR Part 1520. Access to security records shall be limited to authorized personnel based upon operational responsibilities and security clearance. The system shall provide configurable workflows supporting security inspections, access authorization approvals, incident investigations, corrective action tracking, compliance verification, and internal and external audit activities. Automated notifications, escalation workflows, and management dashboards shall assist airport security personnel in maintaining continuous regulatory compliance. The solution shall generate standardized and ad hoc reports supporting TSA inspections, Airport Security Program compliance reviews, internal audits, executive oversight, and incident response activities. Reports shall provide complete traceability while preserving the integrity and confidentiality of Sensitive Security Information. By implementing a comprehensive record management and auditing capability, the airport will improve operational accountability, strengthen regulatory compliance, reduce administrative burden, support security investigations, enhance organizational resilience, and provide demonstrable evidence of compliance during TSA inspections and regulatory audits.

    Project Details

    • Department: Airport
    • Department Head: Jimmy Gunn (Airport Director)

    Addenda

    • Addendum #1 (released 2026-07-31T21:04:25.171Z) —

      Please use the See What Changed link to view all the changes made by this addendum.

    Evaluation Criteria

    • Important Instructions for Electronic Submittals

      The Santa Fe Regional Airport is accepting electronic bid submissions. Bidders shall create a FREE account with OpenGov Procurement by signing up at https://procurement.opengov.com/signup. Once you have completed account registration, browse back to this page, click on "Draft Response", and follow the instructions to submit the electronic bid.

    • Award

      The City reserves the right to make an award in the manner deemed most advantageous to the City and in the public interest. Specifically, the City may:

      • Award to one or more vendors;

      • Award based on quotes as submitted;

      • Award portions of one or more quotes;

      • Select items or services from multiple quotes to create a combined award;

      • Clarify or confirm elements of a quote prior to award;

      • Reject any or all quotes;

      • Cancel or re-issue all or portions of this request if it is in the City’s best interest to do so;

      • Make no award under this request for quotes.

      Award will be made to the responsible vendor(s) whose quote(s) are determined to be the most advantageous to the City, considering price, responsiveness, and compliance with the any requirements. The lowest-priced quote may not necessarily result in an award.

      Vendors shall not commence work until a Purchase Order is issued by the City.

    • TSA-Compliant Airport Security Record Keeping and Auditing System

      1. Purpose

      The purpose of this is to design, develop, configure, test, deploy, and maintain an Airport Security Record Keeping and Auditing System that supports airport security operations while ensuring compliance with Transportation Security Administration (TSA) regulations, Airport Security Program (ASP) requirements, applicable FAA guidance, Department of Homeland Security (DHS) cybersecurity principles, and organizational governance policies.

      2. Project Objectives

      The contractor shall provide a secure enterprise solution capable of:

      • Centralizing all airport security records.
      • Supporting TSA regulatory compliance.
      • Providing complete audit traceability.
      • Protecting Sensitive Security Information (SSI).
      • Improving operational efficiency.
      • Reducing manual recordkeeping.
      • Supporting TSA inspections and regulatory audits.
      • Integrating with existing airport security systems.
      • Providing executive-level reporting and analytics.

      3. Functional Scope

      The system shall support management of:

      Personnel Records

      • Security employee records
      • Security officer certifications
      • Badge holder information
      • Security clearances
      • Employment verification
      • Credential expiration
      • Annual reviews
      • Training history

      Access Control Records

      • Badge issuance
      • Badge activation
      • Badge suspension
      • Badge revocation
      • Visitor credentials
      • Temporary badges
      • Escort authorizations
      • Access level assignments

      Security Incident Management

      • Incident reporting
      • Security violations
      • Unauthorized access events
      • Lost or stolen credentials
      • Suspicious activity reports
      • Law enforcement referrals
      • Corrective actions
      • Incident closure documentation

      Inspection Management

      Support documentation for:

      • TSA inspections
      • Internal audits
      • Compliance reviews
      • Vulnerability assessments
      • Security surveys
      • Self-inspections
      • Corrective action plans
      • Follow-up inspections

      Training Management

      Maintain records for:

      • Initial training
      • Recurrent TSA training
      • Emergency response training
      • Security awareness
      • Insider threat training
      • Cybersecurity awareness
      • Practical exercises
      • Certifications

      Equipment Management

      Track:

      • Security camera maintenance
      • Access control devices
      • Explosive detection equipment
      • Security screening assets
      • Communications equipment
      • Calibration records
      • Preventive maintenance
      • Service history

      4. Audit and Accountability

      The system shall maintain immutable audit logs capturing:

      • User logins
      • Authentication failures
      • Record creation
      • Record modification
      • Record deletion
      • Report generation
      • Administrative actions
      • Configuration changes
      • Workflow approvals
      • Electronic signatures
      • Data exports
      • Security alerts

      5. Security Requirements

      The system shall implement:

      • Role-Based Access Control (RBAC)
      • Multi-Factor Authentication (MFA)
      • Encryption at rest
      • Encryption in transit
      • Least privilege access
      • Comprehensive audit logging
      • Secure backup procedures

      6. Compliance Requirements

      The solution shall support compliance with:

      • TSA regulations (49 CFR Parts 1520, 1540, 1542, and 1544, as applicable)
      • Airport Security Program (ASP) requirements
      • DHS cybersecurity guidance
      • FAA guidance applicable to airport operators
      • Applicable records retention policies
      • Organizational information governance policies

      7. Reporting

      The system shall provide configurable reports including:

      • Badge status reports
      • Expiring credentials
      • Training compliance
      • Incident statistics
      • Audit findings
      • Inspection history
      • Corrective action status
      • Security trend analysis
      • User activity reports
      • Executive dashboards

      Reports shall support PDF and Microsoft Excel export.

      8. Integration Requirements

      The solution shall integrate, where authorized and applicable, with:

      • Physical Access Control Systems (PACS)
      • Identity and Credential Management Systems
      • Video Management Systems (VMS)

      9. Data Management

      The contractor shall provide:

      • Automated backups
      • Version control
      • Record retention management
      • Secure archival
      • Data restoration
      • Search and indexing
      • Metadata management
      • Electronic document management

      10. 40 Hours of On-Call Services as needed at the Airports approval

    Submission Requirements

    • Respondent Submittals (without Cost) (required)

      Please Upload your COMPLETE response, including any and all required forms listed in the solicitation and the corresponding attachments.

      (Do not upload cost information in here)

    • Separate Cost Proposal (required)

      Confirm that your fee proposal is not attached in your Proposal and is attached separately here.

    • I certify that I have read, understood and agree to the terms in this solicitation, and that I am authorized to submit this response on behalf of my company. (required)
    • Pricing (required)
      • Choose Option 1 when you have set line items, for example:
        • This is a quote for goods or commodities.
        • This is a public works bid, with a pricing table that can be uploaded into OpenGov Procurement from an Excel spreadsheet.
        • Seeking services for hourly rate schedules.
      • Choose Option 2 when you need vendors to provide you with the line items. 

    Key dates

    1. July 31, 2026Published
    2. August 4, 2026Responses Due

    AI classification tags

    Frequently asked questions

    SLED stands for State, Local, and Education. These are solicitations issued by state governments, counties, cities, school districts, utilities, and higher education institutions — as opposed to federal agencies.

    SamSearch Platform

    Stop searching. Start winning.

    AI-powered intelligence for the right opportunities, the right leads, and the right time.