Request for Information (RFI) -- DAST Tool
| Agency: | SOCIAL SECURITY ADMINISTRATION |
|---|---|
| State: | Federal |
| Type of Government: | Federal |
| Posted Date: | May 5, 2026 |
| Due Date: | May 19, 2026 |
| Solicitation No: | 28321326RI0000019 |
| Original Source: | Please Login to View Page |
| Contact information: | Please Login to View Page |
| Bid Documents: | Please Login to View Page |
Description
APEX Accelerators are an official government contracting resource for small businesses. Find your local APEX Accelerator (opens in new window) for free government expertise related to contract opportunities.
APEX Accelerators are funded in part through a cooperative agreement with the Department of Defense.
The APEX Accelerators program was formerly known as the Procurement Technical Assistance Program (opens in new window) (PTAP).
- Contract Opportunity Type: Solicitation (Original)
- Original Published Date: May 05, 2026 03:16 pm EDT
- Original Date Offers Due: May 19, 2026 02:00 pm EDT
- Inactive Policy: 15 days after date offers due
- Original Inactive Date: Jun 03, 2026
-
Initiative:
- None
- Original Set Aside:
- Product Service Code: 7A21 - IT AND TELECOM - BUSINESS APPLICATION SOFTWARE (PERPETUAL LICENSE SOFTWARE)
-
NAICS Code:
- 513210 - Software Publishers
-
Place of Performance:
The Web Application Security Team (WAST) performs static code scanning of all SSA applications as part of the Office of Information Security’s (OIS) cybersecurity program. This is accomplished with the static application security testing (SAST) tool called Checkmarx and the software composition analysis (SCA) tool called Black Duck. Both of these solutions are white box testing tools that analyze the application’s code as it's being built. WAST is looking to procure a Dynamic Application Security Testing (DAST) solution to better analyze SSA applications, to bolster FISMA metrics, and to satisfy the requirements from multiple external audits and assessments. The DAST tool would scan applications as they are executed to identify exploits that can only be detected from black box testing. This funding is required immediately to better support the workload of multiple federal mandates and to provide black box testing early in the development lifecycle to stop exploits before they go to Production and potentially cause a security breach. This will also support a new requirement to perform penetration testing on all Tier 1 applications and all information systems going through the Authority to Operate (ATO) process.
- 1540 ROBERT M. BAIL BUILDING 6401 SECURITY BLVD 21235
- BALTIMORE , MD 21235
- USA
- Keelin McGrath
- keelin.mcgrath@ssa.gov
- May 05, 2026 03:16 pm EDTSolicitation (Original)
See Also
Follow Simview Simulation Renewal Active Contract Opportunity Notice ID N6893626Q5192 Related Notice Department/Ind.
DEPT OF DEFENSE
Due by 9/28/2026
Follow ScriptPro Upgrade and Maintenance Active Contract Opportunity Notice ID 26-SOL-IHS1524457 Related Notice
HEALTH AND HUMAN SERVICES, DEPARTMENT OF
Due by 9/21/2026
Follow Commercial Solutions Opening for Data and Analytics for Maritime Domain Awareness Active
DEPT OF DEFENSE
Due by 1/07/2027
Follow CMPro Software and Support Active Contract Opportunity Notice ID N0016726Q1161 Related Notice
DEPT OF DEFENSE
Due by 9/23/2026