The State of Marylandâs Department of General Services is seeking qualified vendors to provide advanced cybersecurity and privacy services statewide. The solicitation is divided into three functional areasâGovernance, Architecture/Engineering/Implementation, and Protection/Defenseâallowing firms to bid on only one area. Work includes developing policies, GRC programs, risk assessments, secure architecture design (ZeroâTrust, DevSecOps), tool implementation (SIEM, IAM, endpoint protection), cloud security, SOC staffing, threat hunting, incident response, and related deliverables. The contract will be awarded to a vendor that demonstrates strong technical expertise, relevant experience, and compliance with minorityâbusiness participation goals (15% MBE, 3% VSBE). Proposals must be submitted in a doubleâenvelope format (technical and financial) via eMMA by September 18, 2026.
⢠Three separate functional areas; bidders may respond to only one.
⢠Required deliverables: governance frameworks, design documents, security configurations, SOC reports, threat intel briefs, etc.
⢠Mandatory doubleâenvelope submission (technical first, financial second).
⢠MBE/VSBE participation goals: 15%/3% respectively.
⢠Oral presentations may be required (date TBD).
⢠Questions due by August 17, 2026; proposals due September 18, 2026.