FreeFree RFPs on Craxy AI — no subscription required

Ready to bid on this RFP?

Sign up free to generate a complete proposal draft instantly — Craxy AI reads the RFP, drafts every section, and matches your past work.

Managed Security Service Provider Services

Concord, New HampshireNew Hampshire, USADue Tuesday, October 13, 2026
Client
Concord, New Hampshire
RFP Number
ITES-10701
Posted
Category
IT Services (Computer Maintenance and Technical Services)
Budget
Looking for Proposal
NAICS
Set-aside
Contact

Description

AI Generated

The agency is seeking managed security service provider (MSSP) services to deliver continuous expert cybersecurity monitoring, incident detection and response, and technical support for its network and ITS infrastructure. The project covers securing a diverse and evolving operational environment that includes centralized data systems and field-deployed devices such as dynamic message signs, CCTV cameras, radar sensors, weather stations, and traffic signal controllers. The scope includes real-time network security monitoring, threat detection, network protection, incident response, vulnerability assessments, and ongoing technical support and coordination. The agency requires 24/7/365 continuous monitoring of its network infrastructure, endpoints, applications, and critical transportation systems. The proposed solution must collect, aggregate, and normalize security logs and events from diverse IT and ITS sources, performing real-time correlation and analysis to detect anomalies and threats. A centralized SIEM platform is required, supporting customizable dashboards and alerts for various stakeholder roles. The solution must monitor and alert on unusual or unauthorized activity related to ITS field device access, configuration changes, or firmware updates, and communicate identified issues verbally and electronically to the Transportation Management Center. The MSSP must detect and prevent known and emerging threats, including malware, ransomware, and phishing attempts. Intrusion detection and prevention capabilities are required, with monitoring of ITS-specific communication protocols. Network segmentation monitoring is essential to ensure the isolation of critical systems, and the solution must leverage up-to-date threat intelligence feeds relevant to government, critical infrastructure, and transportation sectors. The MSSP must also detect and alert on unauthorized access attempts to ITS field devices, attempts at signal manipulation, unauthorized firmware updates, and the presence of malicious code on ITS field devices or associated maintenance tools. Vulnerability management is a key requirement, including regular scanning of network devices, servers, applications, and endpoints. The MSSP must provide prioritized reporting of identified vulnerabilities and offer recommendations and support for remediation and patch management. Specific attention must be paid to identifying and reporting vulnerabilities in ITS roadside equipment, controllers, and central ITS applications, including outdated firmware and insecure configurations. Eligibility rules stipulate that the organization must be onshore (USA Organization Only). Performance of the work will be offsite. All questions must be submitted no later than September 22, 2026. A mandatory pre-bid conference will be held on August 7, 2026. The contract period will be for five years. The proposal due date and time is October 13, 2026, at 3:00 PM ET. The agency is looking for proposals, and responses can be submitted digitally via email or online. The agency requires compliance with NIST Special Publication 800-171 R2 and NIST Special Publication 800-53 Revision 5 Moderate level controls. StateRAMP Ready/Authorized certification is required, with specific timelines for achieving authorization if not already obtained. The agency also requires FedRAMP Authorized or HITRUST certification as alternative options. The MSSP must not use equipment or services on the State of New Hampshire's Prohibited Technologies List or the FCC Covered List. The vendor is responsible for checking parent companies for prohibited entities via SAM.gov. Continuous monitoring and reporting for StateRAMP status are mandatory throughout the contract term.

Source and verification

Original source

Craxy AI summarizes this opportunity from the original listing and available solicitation documents. Confirm submission instructions and amendments with the issuing source before responding.

10 cached source filesDocuments checked

Personalized fit score

Sign up free to see how well this opportunity fits your company — based on your saved profile.

Sign up to see your fit score