Application Security Testing (AST) Platform

Agency: Sacramento County
State: California
Type of Government: State & Local
NAICS Category:
  • 541511 - Custom Computer Programming Services
  • 541512 - Computer Systems Design Services
  • 541519 - Other Computer Related Services
Posted Date: Jul 15, 2026
Due Date: Aug 7, 2026
Solicitation No: 2026-RFB-0064
Original Source: Please Login to View Page
Contact information: Please Login to View Page
Bid Documents: Please Login to View Page

Description


Project ID: 2026-RFB-0064

Title: Application Security Testing (AST) Platform

Addenda: 1

Release Date: 7/7/2026

Due Date: 8/7/2026

Follow
Application Security Testing (AST) Platform
Last updated by Addendum #1 on Jul 16, 2026 7:40 AM See what changed
Request for Bid
DGS: CAPSD - Procurement
20429 , 20882 , 20888 , 20889 , 20890 ... show all
Project ID: 2026-RFB-0064
Release Date: Tuesday, July 7, 2026
· Due Date: Friday, August 7, 2026 5:00pm
Posted Tuesday, July 7, 2026 10:48am
All dates & times in Pacific Time
Draft Response Events RSVP No Bid22 days, 22 hours, 38 minutes


Post Information

Posted At:Tue, Jul 7, 2026 10:48 AM
Sealed Bid Process:Yes (Bids Sealed / Pricing Sealed)
Private Bid:No
Overview


Summary

The Sacramento County Contract & Purchasing Services Division is releasing a Request for Bid (RFB) on behalf of the Department of Technology to procure an Application Security Testing (AST) platform capable of supporting secure software development across multiple programming languages and development environments. The solution must provide integrated capabilities for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and AI‑assisted remediation to identify, prioritize, and remediate vulnerabilities throughout the development lifecycle. The platform should offer seamless integration with modern source‑code management systems and CI/CD pipelines, support enterprise authentication (including SSO), and include licensing models appropriate for developer‑centric or application‑centric usage. Preference will be given to solutions with FedRAMP or GOVRAMP authorization and robust reporting suitable for audit, compliance, and operational security functions.



Background

Sacramento County has adopted the NIST Cyber-Security framework and strives to align its practices with those described in the moderate controls of NIST 800-53. Sacramento County is made up of numerous departments and critical services, some of which must comply with external regulatory requirements, including PCI, IRS Pub 1075, HIPAA, CJIS, and other requirements related to critical infrastructure.

Sacramento County continually strives to align its practices with the NIST Cyber-Security framework and looks to procure an Application Security Testing platform to help us improve our overall application security practices.



Timeline

Release Project Date:
July 7, 2026
Pre-Bid Meeting (Non-Mandatory):
July 8, 2026, 11:00am
Microsoft Team Meeting
(916) 245-8966 - Conference ID:878 889 367#
Meeting ID: 270 918 541 750 28
Passcode: Kc3mQ3p8
Question Submission Deadline:
July 24, 2026, 5:00pm
Addendum Issued (if necessary):
July 31, 2026, 5:00pm
Submission Deadline:
August 7, 2026, 5:00pm
Award Contract:
August 14, 2026
Get Government Bids Like This by Email Receive daily bid alerts that match your keywords, business categories, and target regions.

See Also

DPW | As-Needed AV, Telecom, & Security Svcs 2027 Format : Sell |

City and County of San Francisco

Due by 11/02/2026

Project ID: 260560 Title: Invitation for Bids (IFB) for Annual Renewal of Microsoft

Orange County Transportation Authority

Due by 10/08/2026

Opportunity ID 231518 Organization City of Los Angeles Department Personnel Stage Open Contact

City of Los Angeles

Due by 9/21/2026

Project ID: 260545 Title: AvePoint Cloud Backup for Microsoft Cloud Subscription Renewal Addenda:

Orange County Transportation Authority

Due by 9/29/2026

* Disclaimer: This website provides information about bids, requests for proposals (RFPs), or requests for qualifications (RFQs) for convenience only and does not serve as an official public notice. Individuals who wish to respond to or inquire about bids, RFPs, or RFQs should contact the relevant government department directly.