The Atlanta Regional Commission (ARC) is seeking proposals for a comprehensive network security audit and vulnerability assessment. The selected service provider will be responsible for assessing the maturity of ARC's information security program and providing actionable guidance to improve security posture and operational efficiency. Key deliverables include a findings document, a risk analysis, and a security roadmap. The engagement also involves conducting disaster recovery drills and tabletop exercises. Proposals are due by April 27, 2026. Vendors must submit questions by April 6, 2026. The maximum contract value is $45,**** will be evaluated based on technical approach, qualifications, experience, reasonableness of fee, client references, and proposed cost.
The bid notice states that proposals are due by Monday, April 27, 2026, by 5:00 p. m. EST. The vulnerability assessment and risk assessment activities should be completed within 30 days, and disaster recovery drills and tabletop exercises should be completed by the end of the calendar year.
The bid notice states that progress payments will be made monthly, with ARC paying or rejecting properly submitted invoices within 45 days of receipt. Final payment will be made upon ARC's determination that all contractual requirements have been fulfilled.
The bid notice states that written proposals will be evaluated based on the following weighted criteria: Technical approach (35%), Demonstrated qualifications and experience (30%), Reasonableness of proposed fee and expenses (20%), Client references and letters of support (10%), and Proposed cost (5%).
The bid notice states that the service provider must have at least one certified information systems auditor (CISA) or equivalent certification holder assigned to the project. Equivalent certifications include, but are not limited to, CISSP, CISM, CEH, or OSCP. Proposals must also include the legal name of the firm, point of contact information, qualifications and technical competence, description of relevant project experience with at least three client references, listing of key project personnel and their qualifications, a detailed description of the proposed technical approach, and a proposed cost breakdown.
The bid notice states that sample reports representative of the deliverables described in this RFP must be included with the proposal.
The bid notice states that the deadline for questions is Monday, April 6, 2026, by 5:00 p. m. EST.
The bid notice states that the maximum contract value shall not exceed $45,****.