The vendor is required to provide cybersecurity maturity model certification (CMMC) security and compliance professional services for include:
1. Architecture changes, compliance documentation & monitoring solution
• Design and implement a dedicated and secure, cloud-based, enclave architecture in compliance with CMMC requirements and for processing controlled unclassified information (CUI) or federal contract information (FCI).
• Ability to extend the secure enclave boundary to district on premises infrastructure and ensure seamless integration with the cloud-based enclave while maintaining CMMC compliance.
• Provide technical engineering professional services to support microsoft azure government environments.
• Assist in securely migrating data into the secure enclave from non-compliant systems.
• Assist with ensuring that on-premises and cloud environments are fully integrated, with secure communication channels established between them.
• Provide confirmation that in-scope, district SaaS applications such as microsoft office 365 GCC high, can be integrated and supported within the enclave. additional applications to be determined.
• Develop detailed, accurate and CMMC-compliant system security plans (SSPS), policies, and procedures.
• Provide regular compliance reports and dashboards to track the status of CMMC control implementation on an ongoing basis.
• Assist in building a security monitoring solution to enhance district’s threat detection, response, and compliance capabilities.
• The proposed solution should support the ingestion and analysis of diverse log sources.
• Offer scalable solutions for future CMMC compliance.
2. Certification process
• Assist with the formal CMMC audit process by engaging a certified third-party assessor organization (c3pao) to conduct an audit of the organization's cybersecurity practices.
3. Ongoing monitoring & compliance
• Provide ongoing monitoring and auditing services to ensure the enclave remains CMMC compliant.
• Plan for future periodic assessments as required by CMMC to ensure that all compliance activities remain up-to-date and effective in safeguarding CUI.
• Compliance services include compliance management, monitoring, reporting per agency requirements, audit management.
- Contract Period/Term: 2 years
- Virtual Information Meeting Date: May 07, 2025
- Questions/Inquires Deadline: May 15, 2025