Cybersecurity consulting · State agency
Third-Party Risk Management Project (RFQ)
State of New Mexico, Office of Cybersecurity (OCS)
Issuer and solicitation
- Issuer
- State of New Mexico, Office of Cybersecurity (OCS) · State cybersecurity office within the Department of Information Technology
- Buyer type
- State agency
- Issued
- September 14, 2026
Scope
Consulting on third-party risk for public entities: cybersecurity standards, vendor assessments, legal and procurement gaps, and model ordinances and contract clauses. This is not a software procurement.
Key dates
- Proposal deadline
- October 16, 2026 · time not stated
- Questions due
- September 25, 2026 (closed); answers posted October 2, 2026
- OCS said it would answer several open questions by October 7, 2026
- Evaluation and selection October 19 – November 20, 2026
Submission and qualification requirements
- Quotes over USD 60,000 require a current New Mexico statewide price agreement, GSA or NASPO contract.
- At least three references from similar projects through the issuer's online questionnaire.
- Required federal forms.
- Quotes are emailed to OCS.
Published budget and contract structure
Published budget: Not stated in reviewed material
- Six-month term.
- Time-and-materials pricing with a strict not-to-exceed amount; the contractor assumes under-budgeting risk and commits to complete the scope.
Sources
- Official RFQ (opens in new tab)↗
- Official questions and answers (October 2, 2026) (opens in new tab)↗
Sources checked October 6, 2026.
The RFQ and October 2 Q&A were reviewed. Several scope answers were deferred to October 7 and remain unresolved in the reviewed material.
Check the official notice for updates.
