The FDA Office of Digital Transformation is planning a consolidated, enterprise-wide Blanket Purchase Agreement for cybersecurity engineering, operations, and AI-enabled services, branded NEXUS — NextGen Cyber Engineering, Operations AI, and Unified Services. FDA issued a sources sought August 18th, 2026, amended it twice, and responses were due on September 3rd, 2026. The RFP has not been released.
The draft Statement of Work is unusually detailed for a market research notice. NEXUS would unify three interdependent cybersecurity domains into a single strategic vehicle:
- Cybersecurity engineering and platform modernization, multi-cloud Trusted Internet Connection engineering, and enterprise platform infrastructure
- Cybersecurity operations and threat management including a 24x7x365 SOC and NOC, endpoint, network, application and data protection, digital forensics, and foreign travel security
- Identity, Credential, and Access Management engineering and operations — layered with AI and automation, Post Quantum Cryptography, and a Zero Trust Identity Hub
One qualifier matters more than any other in this notice: FDA is seeking small businesses holding GSA Multiple Award Schedule contracts. Firms that hold MAS and can document enterprise cybersecurity past performance are the intended audience.
OPPORTUNITY SNAPSHOT
- Opportunity: NEXUS — NextGen Cyber Engineering, Operations AI, and Unified Services
- Agency: Food and Drug Administration, Office of Digital Transformation, Cybersecurity Program
- Estimated RFP Release: TBD
- Vehicle: Enterprise-wide Blanket Purchase Agreement
- Set-Aside: Small business
- NAICS: 54151, Computer Systems Design and Related Services; PSC DA10
- Estimated Value: TBD
- Enterprise Scale: 21,000+ end users, 413 production and pre-production systems, 4 major public-facing applications
- Personnel Security: Public Trust, Moderate Level Tier 2S background investigation
- Place of Performance: Hybrid — North Bethesda and Silver Spring, MD, with approved telework
WHY THIS OPPORTUNITY MATTERS
FDA describes itself as a persistent target for cybercrime and economic espionage, citing the focus is on their trade secrets and intellectual property held inside its enterprise technical infrastructure. The draft SOW names nation-state actors, trusted insiders, and transnational criminal organizations, and points to the SolarWinds compromise and breaches at CMS, CDC, and NIH contractors. What NEXUS needs:
- Zero trust architecture and governance, AI-driven cyber defense and counterintelligence hunt operations, vulnerability and threat management, continuous authorization, ICAM engineering and operations, post-quantum cryptography readiness, and round-the-clock SOC and NOC monitoring, incident response, and reporting
Two features make this more accessible than most federal cyber work. The personnel bar is a Public Trust Moderate Tier 2S background investigation rather than a security clearance, a far shorter hiring runway for a small business. Also, performance is hybrid, anchored in the Maryland suburbs with approved telework rather than full-time onsite. Both meaningfully widen the pool of firms that can realistically staff the work.
Firms preparing for the eventual solicitation should be able to show:
- An active GSA MAS contract with the applicable cybersecurity and IT service SINs
- federal SOC and NOC operations past performance at enterprise scale
- Demonstrated zero trust, cATO, and NIST Cybersecurity Framework implementation
- AI-enabled security tooling experience that survives scrutiny
- ICAM engineering depth (occupies a large share of the draft SOW)
WHO SHOULD CONSIDER THIS OPPORTUNITY
This vehicle is built for small businesses delivering enterprise cybersecurity to federal health customers. Firms with experience in the following should assess their fit now:
- Small businesses holding GSA MAS contracts with cybersecurity and IT service SINs
- Managed security service providers able to staff 24x7x365 SOC and NOC operations
- Zero trust architecture, continuous ATO, and NIST CSF implementation specialists
- ICAM engineering and operations firms
- AI and automation providers applying machine learning, predictive analytics, and autonomous response to security operations
- Post-quantum cryptography and cryptographic modernization specialists
- Firms with HHS or FDA past performance, or current subcontractors seeking a prime position
HOW OST CAN HELP
The market research window has closed, but no solicitation exists yet, which leaves real runway for schedule positioning, teaming, and past performance work. OST supports firms preparing for BPA competitions with:
- Bid/No-Bid assessment: Evaluating fit against the draft SOW, your GSA MAS coverage, and realistic ability to staff 24×7 operations
- Capture planning: Customer engagement and positioning with FDA ODT ahead of the solicitation
- Teaming strategy: Identifying complementary partners via OST’s partnering portal (200+ companies) to close ICAM, AI, and PQC capability gaps
- Past performance strategy: Documenting federal cyber operations past performance mapped to the three NEXUS domains
- Proposal development: Technical approach, staffing, pricing, and compliance for a schedule-based BPA competition
The sources sought window just closed, but NEXUS itself remains ahead of the market: no solicitation has been issued, and FDA’s draft SOW gives an unusually clear picture of what the agency intends to buy. Firms holding a GSA MAS contract that can staff enterprise cyber operations should treat this as an active watch item and prepare now rather than waiting for the RFQ. If this interests you, please book a call with OST Partner and President Bill Schalik via the button below.
Schedule a discussion today.
