Cybersecurity and Infrastructure Security Agency procurement forecast

Contracts the Cybersecurity and Infrastructure Security Agency plans to buy, from its published acquisition forecast. Forecasts come out months before a solicitation is posted on SAM.gov, so this is the time to introduce your business and ask how Cybersecurity and Infrastructure Security Agency plans to buy the work.

Planned buys listed
23
Award expected within 6 months
11
Set aside for small business
15
Updated
Oct 10, 2026

Upcoming Cybersecurity and Infrastructure Security Agency contracts, soonest award first

23 listed

  • ENTERPRISE TECHNOLOGY RESEARCH AND SUPPORT SERVICES (ETRSS)

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Nov 27, 2026
    Solicitation expected
    Nov 1, 2026
    Estimated value
    $2M to $5M
    Set-aside
    Not decided yet
    NAICS
    511210
    Description

    The Office of the Chief Technology Officer is seeking support services to support CISA’s enterprise technology research and support service covering information technology, computer software and hardware, and communications resources. These services will provide CISA government officials with enterprise level licensed access to an assigned service delivery team, periodic reviews, a facilitated team workshop, access to research advisors and events, leadership development research, best practices…

  • Critical Infrastructure Security and Resilience

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Dec 22, 2026
    Solicitation expected
    Oct 20, 2026
    Estimated value
    $20M to $50M
    Set-aside
    8(a)
    NAICS
    541611 Administrative Management and General Management Consulting Services
    Description

    The contractor will provide CISA's Infrastructure Security Division (ISD) with analysis and support for Defense Critical Infrastructure projects through a collaborative approach that applies all-hazards and threat-based analysis. It identifies security and resilience gaps within associated infrastructure and recommends courses of action to mitigate those gaps. It delivers analytical findings and actionable recommendations that enable infrastructure owners and operators to mitigate or reduce ris…

  • CISA Cybersecurity Operations Support Services (COSS)

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Jan 2, 2027
    Solicitation expected
    Oct 31, 2026
    Estimated value
    Over $100M
    Set-aside
    No set-aside
    NAICS
    541330 Engineering Services
    Description

    The Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), Office of the Chief Information Officer (OCIO), and the Defensive Cybersecurity Operations (DCO) Subdivision the responsibility to monitor and protect CISA systems from unauthorized access, misconfiguration or disruption of services from internal and external threats. CISA will acquire expert IT Security services for CISA’s DCO mission. This includes leveraging expertise in Security Operations Ce…

  • Property Inventory and Audit Remediation

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Jan 15, 2027
    Solicitation expected
    Nov 13, 2026
    Estimated value
    $20M to $50M
    Set-aside
    Small business
    NAICS
    541219 Other Accounting Services
    Description

    This procurement supports the Cybersecurity and Infrastructure Security Agency (CISA) Chief Operations Support and Chief Financial Officer. Office of the Chief Financial Officer (OCFO) is responsible for ensuring property is properly accounted for in CISA’s financial statements and for the timely and accurate financial reporting of transactions across multiple non-integrated systems, specifically Federal Financial Management System (FFMS) (financial ledger), PRISM (acquisition), Sunflower Asset…

  • Terrorism and Targeted Violence Risk Mitigation

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Jan 19, 2027
    Solicitation expected
    Oct 19, 2026
    Estimated value
    $20M to $50M
    Set-aside
    8(a)
    NAICS
    541611 Administrative Management and General Management Consulting Services
    Description

    Perform research, product development, in person and virtual training development and delivery, analytical support, private and public sector communication and outreach, compliance tracking, and risk management relating to active assailant prevention and response, small-unmanned aircraft systems (sUAS) cybersecurity and counter unmanned aircraft system (C-UAS), insider threat mitigation, and other threat-specific and general security expertise.

  • Tier 5 Background Investigation Support

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Feb 10, 2027
    Solicitation expected
    Jan 11, 2027
    Estimated value
    $1M to $2M
    Set-aside
    No set-aside
    NAICS
    561611 Investigation and Personal Background Check Services
    Description

    The Cybersecurity and Infrastructure Security Agency (CISA), Office of the Chief Security Officer (OCSO), requires contractor support to conduct non-personal services related to personnel security processing for federal employees, contractors, and other vetted partners. The contractor shall provide all personnel, materials, and services necessary to execute personnel security actions, including Entry-on-Duty (EOD) processing, fitness determinations, suitability adjudications, and eligibility ev…

  • Sensitive Compartmented Information Facilities (SCIF) Special Security Representative (SSR)

    Cybersecurity and Infrastructure Security Agency

    Award expected
    Mar 8, 2027
    Solicitation expected
    Jan 4, 2027
    Estimated value
    $10M to $20M
    Set-aside
    Small business
    NAICS
    561612 Security Guards and Patrol Services
    Description

    Office of the Chief Security Officer (OCSO) requires Sensitive Compartmented Information Facilities (SCIF) support services to manage and maintain the security, accreditation, and compliance of Cybersecurity and Infrastructure Security Agency (CISA) SCIFs in the National Capital Region (NCR), Mount Weather, Florida and Kansas City. The contract provides specialized security personnel to ensure the protection of classified information by overseeing access control, personnel clearance validation,…

  • Foreign Investment Risk Analysis

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Mar 19, 2027
    Solicitation expected
    Feb 5, 2027
    Estimated value
    $2M to $5M
    Set-aside
    8(a)
    NAICS
    541512 Computer Systems Design Services
    Description

    Provide CISA National Risk Management Center's (NRMC’s) Foreign Investment Risk Branch (FIRB) with cybersecurity and technology risk analysis and advisory and national security consulting related, in part, to the Committee on Foreign Investment in the United States (CFIUS) and the Committee for the Assessment of Foreign Participation in the U.S. Telecommunications Services Sector [informally known as Team Telecom (TT)]. Objective: This requirement is to provide the requisite tools, services, sk…

  • Integrated Cybersecurity Assessments and Hygiene Support Services

    Cybersecurity and Infrastructure Security Agency

    Award expected
    Mar 30, 2027
    Solicitation expected
    Jan 30, 2027
    Estimated value
    Over $100M
    Set-aside
    No set-aside
    NAICS
    541519 Other Computer Related Services
    Description

    **Although this is listed as a follow-on to 70RCSJ26FR0000007, additional scope has been added. This requirement will be more than just a follow-on.** The Integrated Cybersecurity Assessments and Hygiene Support Services requirement establishes a unified, scalable, and modernized mission support vehicle for the Cybersecurity and Infrastructure Security Agency’s (CISA) Vulnerability Management (VM) Sub-Division. This consolidated contract enables end-to-end delivery of technical assessments, ope…

  • Program Management Support for Financial Systems Modernization

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Mar 31, 2027
    Solicitation expected
    Jan 29, 2027
    Estimated value
    $10M to $20M
    Set-aside
    Small business
    NAICS
    541219 Other Accounting Services
    Description

    The DHS Office of the Chief Financial Officer (OCFO) established the Financial Systems Modernization (FSM) program to oversee Component FSM efforts. The foundational tenets for the FSM programs are: • Increased business process standardization across Components through efforts to define a common set of financial management business processes and then ensuring Component business process re-engineering and modernization efforts reflect the DHS process standard. • Implement standard financial data…

  • Planning & Readiness Support

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Apr 9, 2027
    Solicitation expected
    Mar 19, 2027
    Estimated value
    $5M to $10M
    Set-aside
    Small business
    NAICS
    541611 Administrative Management and General Management Consulting Services
    Description

    The contractor shall provide CISA Integrated Operations Division (IOD) with support to Operational Planning (OP) and Operational Readiness and Continuity (ORC) functions integral to the effective execution of CISA mission areas. The services associated would include development and refinement of operational plans; readiness assessments, continuity exercises and plan, exercising/verification of plans; and the creation of professional graphic images which enhances planning, exercise, COOP, and op…

  • Priority Services End to End Integration

    Cybersecurity and Infrastructure Security Agency

    Award expected
    Jun 1, 2027
    Solicitation expected
    Apr 1, 2027
    Estimated value
    $5M to $10M
    Set-aside
    8(a)
    NAICS
    541512 Computer Systems Design Services
    Description

    The contractor shall provide the CISA Emergency Communications Division (ECD) with the integration of Local Exchange Carriers (LECs) into the Government Emergency Telecommunications Service (GETS) and Wireless Priority Service (WPS) network, participate with standards-making bodies to ensure that the requirements of CISA and their constituencies are represented, and manage the service center which will enroll GETS/WPS subscribers and maintain their accounts. Work will be performed at the contra…

  • Dun & Bradstreet (D&B) Hoovers and Data Block license subscriptions

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Jun 7, 2027
    Solicitation expected
    Mar 30, 2027
    Estimated value
    $500K to $1M
    Set-aside
    Small business
    NAICS
    513210 Software Publishers
    Description

    The Office of the Chief Information Officer has a requirement to obtain Dun & Bradstreet (D&B) Hoovers and D&B Data Block license subscriptions, enabling secure access to comprehensive contact and organizational information across global industry groups classified by the North American Industry Classification System. These resources will facilitate targeted engagement and requirements trend analysis, leveraging authoritative third-party data via government-furnished equipment to enhance product…

  • Business Analysis Services

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Jun 29, 2027
    Solicitation expected
    Nov 18, 2026
    Estimated value
    $5M to $10M
    Set-aside
    8(a)
    NAICS
    541611 Administrative Management and General Management Consulting Services
    Description

    Integrated Operations Division (IOD) requires on-demand information management, data analysis, business intelligence, and business analysis services for Cybersecurity and Infrastructure Security Agency (CISA)/IOD. IT support includes content and records management, SharePoint development, data visualizations, business process improvement, and requirements analysis across all IOD’s sub-divisions and regions. Automates tracking and visibility of information essential to fiscal stewardship and com…

  • Google Workspace Enterprise Plus

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 1, 2027
    Solicitation expected
    Jul 1, 2027
    Estimated value
    $2M to $5M
    Set-aside
    HUBZone
    NAICS
    541519 Other Computer Related Services
    Description

    This procurement, supporting the Office of the Chief Information Officer (OCIO), is for the use of Google Workspace Enterprise Plus Apps to support CISA’s IT Operations performance functions. The Enterprise Plus apps are a cloud-based browser with built-in controls that provide encryption and verification which enables work from anywhere and eliminates the need for VPNs. The apps have the ability to operate on a global scale while protecting information from phishing, malware, ransomware, and s…

  • Real Property Asset Management System (RPAMS)

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 1, 2027
    Solicitation expected
    Jun 28, 2027
    Estimated value
    $2M to $5M
    Set-aside
    Service-disabled veteran-owned
    NAICS
    541511 Custom Computer Programming Services
    Description

    The Office of the Chief Information Officer is seeking software platform and an Integrated Workplace Management System (IWMS) tool that are a single-source, scalable, cloud-based solution to assist with overall agency services and responsibilities, such as, strategic space planning, operation and maintenance of building/facilities, move management, strategic planning, workplace service requests, lease administration, and management of real property, assets, risks, sustainability, and other supp…

  • National Initiative for Cybersecuirty Careers and Studies (NICCS) Website Support

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 1, 2027
    Solicitation expected
    May 1, 2027
    Estimated value
    $5M to $10M
    Set-aside
    8(a)
    NAICS
    541512 Computer Systems Design Services
    Description

    The Office of the Chief Information Officer (OCIO) is seeking contractor support to provide online resources for cybersecurity career, education, and training information.

  • Cyber Technology Services (CTS)

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 15, 2027
    Solicitation expected
    May 1, 2027
    Estimated value
    Over $100M
    Set-aside
    No set-aside
    NAICS
    541519 Other Computer Related Services
    Description

    Assist the Cybersecurity Division (CSD), Office of Threat Hunting, with Technology Services necessary for Information Technology Architecture, Information Technology Development Operations, Information Technology Security Operations, and Operations and Maintenance (O&M) services to support incident response and proactive hunting missions. The Technology Services contract provides the support necessary to carry out the day-to-day operations and sustainment of Government operational networks, tec…

  • Cyber Grant Support and Program Development (SLTT)

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 15, 2027
    Solicitation expected
    Aug 16, 2027
    Estimated value
    $2M to $5M
    Set-aside
    8(a)
    NAICS
    541611 Administrative Management and General Management Consulting Services
    Description

    The Cyber Grant Support Services contract helps the Integrated Operations Division (IOD) coordinate and improve the State and Local Cybersecurity Grant Program and Tribal Cybersecurity Grant Program across CISA Regions, CISA Headquarters, Mission Enabling Offices, and FEMA. The services and support include but are not limited to providing updates on grant operations and technical assistance plans, collects lessons learned and best practices, tracks return on investment data, supports program mo…

  • Supply Chain Risk Assessment Support Services

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 17, 2027
    Solicitation expected
    Jul 16, 2027
    Estimated value
    $20M to $50M
    Set-aside
    No set-aside
    NAICS
    541690 Other Scientific and Technical Consulting Services
    Description

    This potential requirement will support the National Risk Management Center (NRMC) in its efforts to more effectively communicate certain identified supply chain risks posed by entities, hardware, software, services and as more holistic framing of critical elements are defined across national critical functions (NCFs).

  • FY27 EOY IT Equipment Buy

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 21, 2027
    Solicitation expected
    Sep 1, 2027
    Estimated value
    $10M to $20M
    Set-aside
    Small business
    NAICS
    541519 Other Computer Related Services
    Description

    This procurement, supporting the Cybersecurity and Infrastructure Security Agency (CISA), Office of the Chief Information Officer (OCIO), is for the acquisition of Information Technology (IT) equipment and peripheral necessary to replace outdated equipment, sustain, and enhance CISA’s IT operations performance functions. The requirement encompasses the delivery of brand-name or equal equipment that meets or exceeds all technical specifications identified in the Statement of Requirements (SOR). …

  • Recruitment Platform

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Sep 24, 2027
    Solicitation expected
    Jul 9, 2027
    Estimated value
    $2M to $5M
    Set-aside
    Not decided yet
    NAICS
    511210
    Description

    NOTE: This requirement is a follow-on to P2026074335; which is scheduled for award 9/25/26. The incumbent contractor is TBD at this time. The Cybersecurity and Infrastructure Security Agency (CISA), Office of the Chief Human Capital Officer (OCHCO), manages strategic recruitment and workforce planning, which are crucial for sustaining a highly skilled personnel base as the agency expands. To overcome recruitment challenges, OCHCO intends to implement a career network platform, facilitating conn…

  • CONSOLIDATED HIRING OPERATIONS AND PERSONNEL SERVICES III (CHOPS III)

    Cybersecurity and Infrastructure Security Agency · Virginia

    Award expected
    Nov 1, 2027
    Solicitation expected
    Jun 25, 2027
    Estimated value
    $50M to $100M
    Set-aside
    Not decided yet
    NAICS
    541612 Human Resources Consulting Services
    Description

    Provide the CISA Office of the Chief Human Capital Officer (OCHCO) with Human Resource Management support services for the CHOPS III program by utilizing advanced human resources expertise. The contract includes comprehensive functional support across the following areas: P/PM support; Talent Acquisition and Workforce Planning; HR Policy and Accountability; Pay and Compensation; Recruitment; HRIT; and Data Analytics.

What Cybersecurity and Infrastructure Security Agency plans to buy

NAICS codes on Cybersecurity and Infrastructure Security Agency's upcoming forecast entries:

CodeIndustryPlanned
541611Administrative Management and General Management Consulting Services5
541519Other Computer Related Services4
541512Computer Systems Design Services3
5112102
541219Other Accounting Services2
513210Software Publishers1
541330Engineering Services1
541511Custom Computer Programming Services1
541612Human Resources Consulting Services1
541690Other Scientific and Technical Consulting Services1
561611Investigation and Personal Background Check Services1
561612Security Guards and Patrol Services1

Frequently asked questions

What is an agency procurement forecast?

A procurement (or acquisition) forecast is an agency's list of contracts it plans to buy in the coming months, published before the solicitation is posted on SAM.gov. Agencies publish them so small businesses can prepare. Each entry usually gives the work, the NAICS code, an estimated value range, the expected solicitation or award quarter and whether it may be set aside.

How should a small business use a forecast?

Pick the planned buys in your NAICS codes, then introduce your business to the agency's small business specialist or program office with a short email and your capability statement. Ask how they plan to buy it: set-aside, contract vehicle and timing. Then watch SAM.gov for a sources sought notice or draft solicitation, which often comes first. Contacting Cybersecurity and Infrastructure Security Agency early, while the requirement is still being planned, is when you can still influence a set-aside decision.

How accurate are forecast dates and values?

They are estimates. Dates shown as a quarter or fiscal year are the agency's own (the federal fiscal year starts October 1, so Q1 FY2027 is October to December 2026). Values are ranges. Buys slip, change set-aside or are dropped, and some are never posted. Treat a forecast as an early signal, not a promise.

Where does this forecast data come from?

From the agencies' own public forecast sites: GSA's Acquisition Gateway forecast tool (which carries the forecasts of many departments), the Department of Homeland Security's Acquisition Planning Forecast System, and the Department of Energy and NASA acquisition forecasts. FedReady checks them every day. Agencies that aren't listed publish their forecasts elsewhere; Acquisition.gov links to each one.

Keep going

Forecast data from DHS Acquisition Planning Forecast System, public U.S. government information, as of Oct 10, 2026. Forecasts are plans, not promises: dates, values and set-asides change. FedReady is an independent company, not affiliated with the Cybersecurity and Infrastructure Security Agency, SAM.gov or any government agency.