Sbips Professional Cyber Security Evaluation Services
Public summary
Generated or condensed from imported source text. Verify before bidding.
This is a selective federal procurement from the Financial Consumer Agency of Canada (FCAC) for an independent enterprise-level cybersecurity assessment. The work would involve reviewing FCAC’s security controls using ITSG-33 Annex 3A and a harmonized threat and risk assessment method, collecting evidence, identifying gaps and residual risks, and creating a prioritized remediation plan. The supplier must also produce a separate, executive-level report based on the NIST Cybersecurity Framework 2.0 that could be shared more broadly without exposing sensitive technical weaknesses. The requirement is for approximately 164 days of work, expected to run from contract award to March 31, 2027, in the National Capital Region/Ottawa area. A DOS–Reliability corporate security clearance and Reliability-level resource security are identified as minimum requirements. One contract is planned.Important eligibility limitation: this solicitation is only open to the 15 Tier 1 SBIPS Supply Arrangement holders listed in the notice for the Security Management stream and the National Capital Region. FCAC states that it will not add other suppliers to this procurement. Businesses not on that list appear unable to bid directly on this opportunity, although they may wish to explore permitted teaming or subcontracting options independently and verify the rules with the contracting authority. The closing date is October 22, 2026, at 2:00 p.m. Ottawa time. The RFP documents are being sent directly by FCAC to the invited supply arrangement holders; Canada Buys is not responsible for distributing them. Review the official notice and obtain the complete RFP before making any bid or eligibility decision. Bid Maple is not affiliated with the Government of Canada.Official notice: https://canadabuys.canada.ca/sites/default/files/webform/tender_notice/108919/npp_20261288.pdf
Requirement preview
A profile unlocks the full bid checklist and match explanation.
- This is a selective tender open only to SBIPS Supply Arrangement holders qualified under Tier 1 for the Security Management stream in the National Capital Region.
- The NPP identifies 15 eligible suppliers and states that no additional suppliers will be added to this solicitation. The listed supplier roster should be checked to confirm eligibility before pursuing the opportunity.
- The requirement is for one contract with an anticipated contract period from contract award to March 31, 2027.
- The anticipated start date is October 29, 2026, and the estimated level of effort is 164 days.
Source description preview
Imported source text may contain formatting from the original notice.
NOTICE OF PROPOSED PROCUREMENT (NPP) For Solution-Based Informatics Professional Services (SBIPS).GSIN: D302A Informatics Professional Services Reference Number: 20261288Solicitation Number: 20261288Organization Name: The Financial Consumer Agency of Canada (FCAC)Solicitation Date: 2026-10-06Closing Date: 2026-10-22, 2:00 PM Ottawa Time Anticipated Start Date: 2026-10-29Estimated Delivery Date: 2027-03-31Estimate Level of Effort: 164 day Contract Duration: The contract period will be from the date of contract to 2027-03-31.Solicitation Method: Competitive Applicable Trade Agreements: World Trade Organization Agreement on Government Procurement (WTO-AGP), the Canada-Chile Free Trade Agreement (CCFTA), the Canada-Peru Free Trade Agreement (CPFTA), the Canada-Colombia Free Trade Agreement (CColFTA), the Canada-Panama Free Trade Agreement (CPanFTA), the Canada-Honduras Free-Trade Agreement, the Canada-European Union Comprehensive Economic and Trade Agreement (CETA), the Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP), the Canadian Free Trade Agreement (CFTA), the Canada-Ukraine Free Trade Agreement (CUFTA), the Agreement on Trade Continuity between Canada and the United Kingdom of Great Britain and Northern Ireland and the Canada-Korea Free Trade Agreement (CKFTA). Comprehensive Land Claim Agreement Applies: No Number of Contracts: 1 Requirement Details Tendering Procedure: Selective Tendering This requirement is open only to those SBIPS Supply Arrangement Holders who qualified under Tier 1 for services in the National Capital Region for the following stream(s): Security Management 1. Accenture Inc.; 2. ADGA Group Consultants Inc.; 3. CGI Information Systems and Management Consultants Inc.; 4. Deloitte Inc.; 5. Ernst & Young LLP.; 6. Gartner Canada Co.; 7. IBM Canada Limited/IBM Canada Limitée.; 8. IPSS Inc.; 9. KPMG LLP.; 10. OPTIV Canada Federal Inc.; 11. T-REX Solutions LLC.; 12. TEKsystems Global Services Corp.; 13. The Bell Telephone Company of Canada or Bell Canada/La Compagnie de Téléphone Bell du Canada ou Bell Canada.; 14. TPG Technology Consulting Ltd.; 15. TRM Technologies Inc. *** Financial Consumer Agency of Canada (FCAC) thanks you for your interest in our procurement process. The RFP will only be open to the fifteen (15) suppliers listed on the NPP and we will not be adding any additional suppliers to this solicitation. FCAC has met the mandatory requirements under the PSPC SBIPS SA and we are confident that we will be receiving a sufficient number of proposals to make this a truly competitive process. With our current staffing limitations, we cannot invite additional proponents without creating undo process or inefficiencies within our procurement system. FCAC thanks you again for your interest and going forward we will keep your firm in mind for our future requirements.Description of Work: The Financial Consumer Agency of Canada requires the services of an experienced, reputable, and independent third-party cybersecurity firm to conduct an enterprise-level assessment of FCAC’s cybersecurity posture. The assessment shall include an internal evaluation of FCAC’s information technology security controls using ITSG-33 Annex 3A and a harmonized threat and risk assessment methodology, supported by evidence collection, gap analysis, residual risk determination, and prioritized remediation planning. The assessment shall also include a separate National Institute of Standards and Technology Cybersecurity Framework 2.0 report to present FCAC’s cybersecurity posture in a broader, executive-level and externally consumable manner. The internal report shall be detailed, evidence-based, and suitable for management decision-making, while the external report shall provide a high-level maturity narrative suitable for publication or broader stakeholder communication, without disclosing sensitive technical vulnerabilities, system-specific weaknesses, or protected information.Security Requirement: Common PS SRCL # 6 applies Minimum Corporate Security Required: DOS – Reliability Minimum Resource Security Required: Reliability Contract Authority Name: Pavlo Kyryakov Phone Number: (613)-290-2003Email Address: [email protected] Inquiries Inquiries regarding this RFP requirement must be submitted to the Contracting Authority named above. Request for Proposal (RFP) documents will be e-mailed directly from the Contracting Authority to the Qualified Supply Arrangement Holders who are being invited to bid on this requirement. BIDDERS ARE ADVISED THAT “CANADABUYS.CANADA.CA” IS NOT RESPONSIBLE FOR THE DISTRIBUTION OF SOLICITATION DOCUMENTS. The Crown retains the right to negotiate with any supplier on any procurement. Documents may be submitted in either official language.NOTE: Solution-Based Informatics Professional Services (SBIPS) Method of Supply is refreshed three (3) times per year. If you wish to find out how you can be a “Qualified SA Holder”, please contact [email protected] .
Turn this listing into a bid decision.
Build a company profile to unlock match scoring, explanations, checklist next steps, saved opportunity tracking, and alerts.
