Penetration Testing Contracts & Bids
Penetration testing and ethical hacking services simulating cyberattacks to identify vulnerabilities in networks, web applications, and systems, including red team assessments, vulnerability scanning, security audits, and compliance testing using tools such as Metasploit, Burp Suite, Nessus, and Kali Linux.
72 open Penetration testing opportunities right now — 12 federal, 60 state & local.
Paste your website — we'll show the open government contracts that fit your business.
Free · no signup · we read your homepage once. We don't store your email.
Create a free account and we’ll email you when new Penetration testing opportunities are posted — scored against your business so you only see the ones that fit.
Penetration testing contract activity
A current snapshot based on 50 of 72 open listings shown on this page. Counts update with the directory.
- Municipal (RSS feeds)16
- BidNet (local govts)9
- Federal (SAM.gov)8
- Colombia (SECOP II)5
- EU (TED — Tenders Electronic Daily)2
- Other10
Deadline outlook
- Next 30 days
- 35
- Later
- 8
- Open / rolling
- 7
Most represented buyers
- Colombia (SECOP II)5
- DEPT OF DEFENSE / DEPT OF THE ARMY3
- Iselin, NJ3
- New Orleans, LA3
- Other36
36 of the listings shown were posted in the last 30 days. Municipal (RSS feeds) contributes the largest share (16). Colombia (SECOP II) is the most represented buyer in this snapshot.
- State/localITES-11058 - USA (New Orleans, Louisiana) - Cybersecurity Assessment and Penetration Testing Services - Deadline November 3,2026New Orleans, LA · due Nov 3, 2026
(1) Vendor needs to provide cybersecurity assessment and penetration testing services to the government authority located in New Orleans, LA.– Provide solutions to address growing cybersecurity needs.– Identify and mitigate vulnerabilities that may expose to risks such as data exposure, breach of confidential information, or negative impact to functionality or performance of applications.– Vulnerability assessment with penetration test.– Post–remediation vulnerability assessment.– 12 months…
More - State/localITES-11047 - USA (New Orleans, Louisiana) - Cybersecurity Assessment and Penetration Testing Services - Deadline November 3,2026New Orleans, LA · due Nov 3, 2026
(1) Vendor needs to provide cybersecurity assessment and penetration testing services to the government authority located in New Orleans, LA.– Vulnerability Assessment – to validate host configurations and produce a list of known vulnerabilities existing on in–scope systems. The testing includes manual validation of vulnerabilities to reduce false positives.– The types of vulnerabilities typically detected by this testing include:• Microsoft Windows, Linux and Unix operating system…
More - State/localETHICAL HACKING (Manifestación de interés (Menor Cuantía)) (Presentación de oferta)Colombia (SECOP II) · due Oct 13, 2026
Prestar el servicio de realización de pruebas de intrusión y penetración internas, mediante análisis de vulnerabilidades y hacking ético sobre la infraestructura tecnológica y los servicios asociados a la CRC.
More - State/localETHICAL HACKINGColombia (SECOP II) · due Oct 13, 2026
Prestar el servicio de realización de pruebas de intrusión y penetración internas, mediante análisis de vulnerabilidades y hacking ético sobre la infraestructura tecnológica y los servicios asociados a la CRC.
More - State/localITES-11131 - USA (Nebraska) - Corporate and Physical Penetration Test Services - Deadline October 27,2026RFPMart: It Services Computer Maintenance & Technical Services · due Oct 27, 2026
(1) Vendor needs to provide corporate and physical penetration test services to the government authority located in Nebraska.– Perform a comprehensive penetration testing assessment of agency external and internal information technology environment, web applications, systems, and physical infrastructure.– Demonstrate a proven track record of successfully conducting enterprise penetration testing engagements and maintaining expertise in current cybersecurity threats, attack methodologies, and…
More - State/localETHICAL HACKING (Manifestación de interés (Menor Cuantía))Colombia (SECOP II) · due Oct 13, 2026
Prestar el servicio de realización de pruebas de intrusión y penetración internas, mediante análisis de vulnerabilidades y hacking ético sobre la infraestructura tecnológica y los servicios asociados a la CRC.
More - State/localPROVISION OF A VULNERABILITY ASSESSMENT AND PENETRATION TESTZimbabwe (PRAZ e-GP) · due Nov 2, 2026
PROVISION OF A VULNERABILITY ASSESSMENT AND PENETRATION TEST (1 Each)
More - State/localCybersecurity Assessment & Penetration TestingNew Orleans Regional Transit Authority, LA · due Nov 3, 2026
The New Orleans RTA has requested that a Cybersecurity Vendor (CV) provide solutions to address growing Cybersecurity needs. This Scope of Work (SOW) outlines deliverables requested of the CV. The CV services will seek to identify and mitigate vulnerabilities that may expose the New Orleans RTA to risks such as data exposure, breach of confidential information, or negative impact to functionality or performance of applications. The solution by the CV can be a first step in understanding and…
More - State/localITES-11117 - USA (Farmington Hills, Michigan) - Network Security and Penetration Testing Services - Deadline October 28,2026Farmington Hills, MI · due Oct 28, 2026
(1) Vendor needs to provide network security and penetration testing services to the government authority located in Farmington Hills, MI.– Provide qualified cybersecurity professionals with demonstrated experience performing penetration testing for governmental, municipal, educational, healthcare, or similarly complex organizations. – Perform all testing in accordance with applicable laws, regulations, industry standards, and generally accepted cybersecurity practices.– Obtain written…
More - State/localFinland – Computer audit and testing services – TietoturvatestauspalvelutFinland
HUS-yhtymä (jäljempänä myös tilaaja tai hankintayksikkö) pyytää tarjouksia tietoturvatestauspalveluista tämän tarjouspyynnön ja sen liitteiden ehtojen mukaisesti. Tietoturvatestauksessa käytetään pääsääntöisesti määrämuotoista tietoturvamallia. Testaus noudattaa tarvittavia ja yleisesti hyväksyttyjä viitekehyksiä ja standardeja kuten CC (Common Criteria for Information Technology Security Evaluation), OWASP (Open Web Application Security Project) mukaan lukien OWASP ASVS ja OWASP LLM, WASC…
More - State/localITES-11047 - USA (New Orleans, Louisiana) - Cybersecurity Assessment and Penetration Testing Services - INFO ONLY, RFP NOT INCLUDED - Deadline October 16,2026New Orleans, LA · due Oct 16, 2026
(1) Vendor needs to provide cybersecurity assessment and penetration testing services to the government authority located in New Orleans, LA.(2) All question must be submitted no later than October 8, 2026.(3) This is a brief information, Main RFP Document is not available on our website.
More - State/localPhishing and Security Awareness TrainingAlberta (APC) · due Oct 20, 2026
This NRFP is an invitation to submit proposals for the provision of Phishing and Security Awareness Training application (on-premise, SaaS or hosted) licensing and support services directly from OEM providers and certified Value Added Resellers, as further detailed in Appendix B – The Deliverables. Proponents must be able to provide solutions for both Phishing and Security Awareness Training; proposals for only one component will not be accepted.
More - State/localITES-11103 - USA (Linden, New Jersey) - Cybersecurity Consulting Services - Deadline November 6,2026Linden, NJ · due Nov 6, 2026
(1) Vendor needs to provide cybersecurity consulting services to the government authority located in Linden, NJ. – Provide cybersecurity training, support and strategic vision.– A response time of less than one hour is required for critical failures 24/7/365.– Security Posture Assessment & Reporting: The offeror's personnel will continuously assess the agency’s overall cybersecurity health, producing monthly and quarterly reports for agency leadership that include risk scores, identified gaps,…
More - State/localPenetration Testing and Cybersecurity AssessmentScotland (Public Contracts Scotland) · due Oct 16, 2026
Services of a cybersecurity partner to conduct comprehensive penetration testing and security assessment engagement across Cairn Housing Association's digital infrastructure, applications and operational processes, in support of our information security programme and its obligations under regulatory frameworks including GDPR, ISO27001, PCI DSS, NIS and Cyber Essentials Plus
More - State/localTI - 44-20 Contratar la prestación del servicio integral de seguridad informática y de la información; orientado al análisis de vulnerabilidades y la ejecución de pruebas de hacking éticoColombia (SECOP II) · due Oct 21, 2026
TI - 44-20 Contratar la prestación del servicio integral de seguridad informática y de la información, orientado al análisis de vulnerabilidades y la ejecución de pruebas de hacking ético sobre la infraestructura tecnológica de la Auditoría General de la República, con el fin de identificar, evaluar y mitigar riesgos que puedan afectar la disponibilidad, integridad y confidencialidad de la información institucional.
More - State/localINSU-6583 - USA (Iselin, New Jersey) - Cybersecurity Consultant Services - Deadline November 6,2026Iselin, NJ · due Nov 6, 2026
Vendor needs to provide cybersecurity consultant services to the government authority located in Iselin, NJ.1. Cyber insurance assessments:– This overview identifies the risk areas and security gaps each municipality faces. A cyber insurance risk assessment considers not just technology but also organization protocols and daily employee procedures that may create a security risk.2. Gap analysis and risk treatment plan:– A gap analysis is a process that compares actual performance or results…
More - State/localCSE-24839 - USA (Iselin, New Jersey) - Cyber Risk Consultant Services - Deadline November 6,2026Iselin, NJ · due Nov 6, 2026
(1) Vendor needs to provide cyber risk consultant services to the government authority located in Iselin, NJ.– Cyber Insurance Assessments –This overview identifies the risk areas and security gaps each municipality faces.– Gap Analysis & Risk Treatment Plan – A gap analysis is a process that compares actual performance or results with what was expected or desired– Cyber Risk Consultant will provide each municipality with a written report of compliance with the insurance carrier and/or Fund…
More - State/localITES-10977 - USA (Maryland) - GLOBAL - IT Systems Cybersecurity Audit and Systems Integration Review Service - Deadline October 16,2026RFPMart: It Services Computer Maintenance & Technical Services · due Oct 16, 2026
(1) Vendor needs to provide IT systems cybersecurity audit and systems integration review service to the government authority located in Maryland. • Assess enterprise IT network, systems, and data environment to identify material cybersecurity risks, control gaps, and remediation priorities in alignment with recognized industry practices.• APIs and API connections• EDI integrations or external data exchange mechanisms• Third–party software applications (installed or cloud–based)• Integration…
More - State/localCSE-24845 - USA (Iselin, New Jersey) - Cybersecurity Consultant Services - Deadline November 6,2026Iselin, NJ · due Nov 6, 2026
(1) Vendor needs to provide cybersecurity consultant services to the government authority located in Iselin, NJ.– Cyber Insurance Assessments –This overview identifies the risk areas and security gaps each municipality faces. A cyber insurance risk assessment considers not just technology but also organization protocols and daily employee procedures that may create a security risk.– Gap Analysis & Risk Treatment Plan – A gap analysis is a process that compares actual performance or results…
More - State/localITES-11087 - USA (Ogdensburg, New York) - Cybersecurity Risk Assessment Services - Deadline November 20,2026Ogdensburg, NY · due Nov 20, 2026
(1) Vendor needs to provide cybersecurity risk assessment services of the city’s water system and wastewater system to the government authority located in Ogdensburg, NY.– Project Initiation and Data Collection• Gather information on existing information technology (IT) and operational technology (OT)/industrial control system (ICS) architecture, including SCADA, remote telemetry, and any internet–facing or remotely accessible systems, for both the water and wastewater system.– Current…
More - State/localSW-120465 - USA (Maryland) - Novee Pen Testing Subscription Services - Deadline November 16,2026RFPMart: Software System & Application · due Nov 16, 2026
(1) Vendor needs to provide novee pen testing subscription services.– NS AI Pen Testing Platform Continuous Web App Assessment for 1 – 5 Web Apps (2) A pre–bid meeting will be held on October 27, 2026.(3) The contract period will be for one year.
More - State/localITES-11114 - USA (Washington, DC) - GLOBAL - Technology Focused Projects Research, Design, Development, and Deployment Service - Deadline November 23,2026RFPMart: It Services Computer Maintenance & Technical Services · due Nov 23, 2026
(1) Vendor needs to provide technology focused projects research, design, development, and deployment service to the government authority located in Washington, DC. • Web Hosting: Migration and onboarding support• Secure web hosting.• Secure hosting, monitoring, and resiliency of websites during special events• Censorship events and network shutdowns response: Providing alternative applications for communications and internet access during shutdowns and censorship events.• Analysis of Internet…
More - State/localAnálisis y gestión de VulnerabilidadesColombia (SECOP II) · due Oct 13, 2026
Prestar el servicio de Análisis y gestión de Vulnerabilidades sobre la infraestructura tecnológica de la Entidad en modalidad SaaS, mediante la identificación, evaluación, priorización, seguimiento y validación de vulnerabilidades de seguridad de la información, con el fin de fortalecer la postura de ciberseguridad y reducir los riesgos asociados a la exposición de los activos tecnológicos, con el fin de dar continuidad al proceso.
More - State/localBid Extension: Virtual Chief Information Security Officer (vCISO) ServicesNew York City · due Oct 21, 2026
The New York City Police Pension Fund is seeking proposals from qualified and experienced firms to provide Virtual Chief Information Security Officer (vCISO) services. The selected firm will support the Fund in enhancing and maturing its cybersecurity program; strengthening cybersecurity governance, oversight, and accountability; improving cybersecurity risk visibility through metrics, reporting, and dashboards; enhancing incident preparedness, response, and recovery capabilities; and aligning…
More - State/localNorway – IT services: consulting, software development, Internet and support – Security Culture ProgrammeNorway
Statsforvalterens fellestjenester would like to receive offers for tools/implementation of phishing tests. In order to enable employees internally and at the state administration offices (approximately 2,900 employees in total) to identify fraudulent emails, awareness/training regarding fraudulent emails is desired.
More - State/localITES-11034 - USA (San Francisco, California) - Cybersecurity IAM and PAM, and Active Directory Resources Services - Deadline October 20,2026San Francisco, CA · due Oct 20, 2026
(1) Vendor needs to provide cybersecurity IAM and PAM, and active directory resources such as architecture, remediation, defense, endpoint security, hardening, identifying vulnerability points, installation of cyber security tools, etc. In addition to, Microsoft Active Directory, Microsoft Entra ID, Identity and Access Management (“IAM”), Identity Governance and Administration, Privileged Access Management (“PAM”), Multi–Factor Authentication, Single Sign–On, identity verification and…
More - State/localITES-10746 - USA (Pennsylvania) - Digital Development Services - Deadline June 2,2030RFPMart: Pennsylvania · due Jun 2, 2030
Vendor needs to provide digital development services to the government authority located in Pennsylvania.1. Digital service discovery:– Includes, but is not limited to, the performance of initial research and analysis activities required to identify and define user needs and system requirements for digital service projects. Services include stakeholder interviews, user research, competitive analysis, persona identification, business process mapping, and initial prototyping to outline feasible…
More - FederalDA01--Enterprise Cybersecurity Program Audit Support (VA-26-00036760)VETERANS AFFAIRS, DEPARTMENT OF / VETERANS AFFAIRS, DEPARTMENT OF
The acquisition strategy for Enterprise Cybersecurity Program Audit Support is still being determined, and answers to any technical questions asked are still being formulated.
More - State/localCSE-24850 - USA (Dahlgren, Virginia) - RFI for Cyber Support Services - Deadline November 16,2026Dahlgren, VA · due Nov 16, 2026
Vendor needs to provide cyber support services to the government authority located in Dahlgren, VA.• The contractor shall provide cybersecurity system engineering, hardware, firmware, and software support for various programs and networks to include developmental, testing, and operational environments.• The contractor shall work with project managers to develop the scope and schedule of cybersecurity efforts; incorporate costs of cybersecurity integration into budgets and schedules; and report…
More - State/localCyber Security Services 3United Kingdom (Contracts Finder) · due Feb 11, 2029
Crown Commercial Service (CCS) set up a dynamic purchasing system for a period of 60 months and has invited bidders to request to participate for the Cyber Security Services 3 DPS. This DPS provides central government departments and the wider public sector with the opportunity to procure cyber services from a range of suppliers. The DPS filters are for certification, services, standards and experience. Appointed suppliers will be invited by customers (buyers) to submit tenders for relevant…
More - FederalISP Cyber Range (JFHQ-C) Assessment EventDEPT OF DEFENSE / DEPT OF THE ARMY · due Oct 14, 2026
The Cyber Fusion Innovation Center (CFIC), in collaboration with Army Cyber Command (ARCYBER) and the Army Cyber Technology and Innovation Center (ArCTIC), invites qualified industry partners to submit proposals for the development of a high?fidelity Internet Service Provider (ISP) Cyber Range. This Assessment Event release describes the problem set, desired capabilities, and evaluation approach for solutions that can support Joint Force Headquarters?Cyber (JFHQ?C) (A)’s mission to provide…
More - FederalCPE ST3 Digital Enterprise Engineering Environment (DE3) “Army Training Verse”— Industry DayDEPT OF DEFENSE / DEPT OF THE ARMY
Host: Capability Program Executive Simulation, Training, Test & Threat (CPE ST3) When: 10 March 2026, 1100-1200 Physical Location: Central Florida Tech Grove, 12809 Science Drive, Orlando, FL 32826 Virtual MS Teams Live: https://events.dod.teams.microsoft.us/event/eda60444-c7f3-452d-b09f-938dff5cc716@fae6d70f-954b-4811-92b6-0530d6f84c43 Purpose: Capability Program Executive Simulation, Training, Test and Threat (CPE ST3) pleased to invite you to tech industry day on 10 March that includes…
More - Federal552 SEAPORT NXG 1DEPT OF DEFENSE / DEPT OF THE NAVY · due Oct 13, 2026
This Market Survey is issued for the purpose of assessing Small Business capabilities. Small Business firms having the capabilities to perform the tasking described in this MS are encouraged to respond. Market Survey for Services Procurements United States International Partner Variant NMT WAMS MAT and GBS Systems Engineering Test and Evaluation (Cybersecurity Engineering) REFERENCE NUMBER 552 SEAPORT NXG 1 LARGE BUSINESSES DO NOT NEED TO RESPOND TO THIS NOTICE Opportunity is only for Seaport…
More - FederalUSACE Enterprise-Wide Trident ServicesDEPT OF DEFENSE / DEPT OF THE ARMY · due Oct 13, 2026
USACE Enterprise-Wide Emergency Management Services (Blue Sky and Gray Sky)
More - FederalEnterprise Level Engineering and Systems Analysis Support (ELESAS)DEPT OF DEFENSE / DEFENSE INFORMATION SYSTEMS AGENCY (DISA) · due Oct 14, 2026
This is a SOURCES SOUGHT NOTICE to determine the availability and technical capability of small businesses and large businesses (including the following subsets: Small Disadvantaged Businesses, Certified 8(a), Service-Disabled Veteran-Owned Small Businesses, HUBZone Small Businesses and Woman-Owned Small Businesses) to provide the required products and/or services. The DISA Enterprise Engineering Directorate (DISA OE) is seeking capabilities from potential sources for engineering support for…
More - FederalDesign Basis Threat (DBT) and Target Sets SecurityNUCLEAR REGULATORY COMMISSION / NUCLEAR REGULATORY COMMISSION · due Oct 12, 2026
The purpose of this solicitation is to obtain technical assistance services from a contractor to assist and support the NRC staff to: (1) review of submittals related to Flow-Induced Vibration (FIV) analysis and testing (2) update NRC guidance related to FIV analysis and testing (3) prepare knowledge management training related to FIV analysis and testing
More - FederalUpdate for the Pre-Solicitation Notice GPO Production Environment Track and Trace PlatformUNITED STATES GOVERNMENT PUBLISHING OFFICE / UNITED STATES GOVERNMENT PUBLISHING OFFICE · due Dec 31, 2026
This is an update for the Pre-Solicitation Notice GPO Production Environment Track and Trace Platform, 040ADV-26-R-0024.
More - State/local
- State/local
- State/local
- State/local
- State/local
- State/local
- State/localŚwiadczenie usług polegających na przeprowadzeniu testów bezpieczeństwa aplikacji internetowychPoland (e-Zamówienia) · due Oct 16, 2026
- State/local
- State/local
- State/localSERVICIO DE PRUEBAS DE PENETRACIÓN A LA RED INTERNA RED EXTERNA RED EXTERNA APLICATIVOS WEB APLS ANÁLISIS DE CÓDIGO ESTÁTICO DE LA PGREl Salvador (COMPRASAL) · due Oct 13, 2026
- State/local
- State/local
- State/local
Frequently asked
72 open Penetration testing opportunities are posted right now — 12 federal and 60 state & local — updated daily.
GovBidAlerts matches open federal (SAM.gov), state, and local solicitations to the Penetration testing category with AI, so you can browse Penetration testing bids and RFPs across every level of government in one place.
Federal award history by NAICS code
Federal buyers file Penetration testing under these industry codes. Each code page shows who has won that work, which agencies buy it, and typical award sizes.