Justification
Notification of Award of Sole Source Bridge Action_Cybersecurity and Privacy Program Support Services
IT-1
Federal Railroad Administration, 693JJ6 Federal Railroad Admin. Computer Facilities Management Services.
Awarded
$2,188,049.95 obligated so far on USAspending, July 21, 2026, contract 693JJ621F000026
Description
As published on SAM.gov.
In strict compliance with GSAR 538.7104-3(b)(ii), this notice is being made publicly available within 14 days after the award of the modification to ensure procedural transparency under GSA’s modernized FSS ordering procedures. This action is a 12-month sole source award to the incumbent contractor, Criterion, for uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. This bridge extends the period of performance from July 20, 2026 to 07/19/2027.
This contract action is necessitated by the United States Department of Transportation’s (USDOT) reorganization of its Information Technology (IT) function into a digital factory model under the 1DOT reorganization The FRA requires uninterrupted, highly specialized Cybersecurity and Privacy Program Support Services. These services ensure the FRA fully complies with the Federal Information Security Modernization Act (FISMA) of 2014, OMB Circular A-130, and relevant Departmental cybersecurity directives.
The scope of work encompasses comprehensive coverage for all FRA FISMA-reportable systems, requiring the continuous maintenance of the Risk Management Framework (RMF) and the Information Security Continuous Monitoring Program (ISCMP). The architecture currently under administration includes:
Eight (8) production systems (including three hosted in the cloud, seven Moderate Security Impact systems, and five Privacy systems). Four (4) systems under active development, bringing the total technical architecture to twelve (12) IT systems.
Environment Composition: Microsoft Dynamics 365 applications, cloud environments (SaaS, PaaS, IaaS), and on-premises datacenters. The contractor is required to operate, monitor, and configure the DOT and DHS Security Tool Suites utilized within the FRA enclave. This includes specialized engineering and administration of tools such as Tenable Nessus, BigFix, SCCM, SCOM, DB Protect, Netsparker, Burp Suite, and the DOT Cybersecurity Assessment and Management (CSAM) repository.
The required services mandate senior key personnel—specifically a Project Manager and Senior Information System Security Specialists—possessing advanced credentials (CISSP, CISA, CAP/SSCP, CIPP, CCSK) and deep, institutionalized knowledge of FRA’s safety-critical infrastructure.
These services are essential for the integration of FRA team under the new Digital Factory model mandated by the FY26 THUD Appropriations Act – passed as section D of the Consolidated Appropriations Act, 2026, Consolidated Appropriations Act, 2026 (P.L. 119-75). Please see the attached sole source justification.
The contract, on USAspending
Federal procurement data the awarding office reported to FPDS, matched to this solicitation by its number.
- Recipient
- Criterion Systems, L.L.C.
- UEI
- MPGNDNHHWM33
- CAGE
- 8AEP0
- Vendor location
- Vienna, VA
- Contract
- 693JJ621F000026 under 693JJ320A000011, bpa call
- Obligated
- $2,188,049.95, current value $4,202,752
- Actions
- 6 between July 17, 2024 and August 30, 2026
- Competition
- Full and Open Competition, 3 offers received
- Described as
- IT Security Services for FRA - Modification Is Issued to Exercise Option Year 3.
- Match
- award number 693JJ621F000026 equals the contract number; same awarding office 693JJ6 (high confidence)
- Record
- USAspending award page
Publications
Every notice SAM.gov issued under this solicitation number, oldest first. Each is a separate record on SAM.
Points of contact
- Carr, Matthewmatthew.carr@dot.gov