Penetration Testing Government Contracts, Bids & RFPs
Penetration testing and ethical hacking services simulating cyberattacks to identify vulnerabilities in networks, web applications, and systems, including red team assessments, vulnerability scanning, security audits, and compliance testing using tools such as Metasploit, Burp Suite, Nessus, and Kali Linux.
65 open Penetration testing opportunities right now — 5 federal, 60 state & local.
Paste your website — we'll show the open government contracts that fit your business.
Free · no signup · we read your homepage once. We don't store your email.
Create a free account and we’ll email you when new Penetration testing opportunities are posted — scored against your business so you only see the ones that fit.
Penetration testing contract activity
A current snapshot based on 50 of 65 open listings shown on this page. Counts update with the directory.
- Municipal (RSS feeds)22
- BidNet (local govts)15
- EU (TED — Tenders Electronic Daily)3
- Federal (SAM.gov)3
- Latvia (IUB)2
- Other5
Deadline outlook
- Next 30 days
- 39
- Later
- 4
- Open / rolling
- 7
Most represented buyers
- RFPMart: It Services Computer Maintenance & Technical Services8
- California4
- Latvia (IUB)2
- Tennessee2
- Other34
38 of the listings shown were posted in the last 30 days. Municipal (RSS feeds) contributes the largest share (22). RFPMart: It Services Computer Maintenance & Technical Services is the most represented buyer in this snapshot.
- State/localSweden – IT services: consulting, software development, Internet and support – IT-konsulter för penetrationstester och säkerhetsgranskningarSweden · due Sep 17, 2026
Löf avser att upphandla IT-konsulter för penetrationstester och säkerhetsgranskningar. Löfs behov omfattar resurser enligt nedan: En (1) IT-säkerhetsspecialist för penetrationstester och säkerhetsgranskningar av egenutvecklade system och applikationer. En (1) IT-säkerhetsspecialist för penetrationstester och säkerhetsgranskningar av IT-infrastruktur ur ett kontinuitets/säkerhetsperspektiv. Välkomna att lämna anbud! Vänliga hälsningar Löf
More - State/localFinland – Computer audit and testing services – TietoturvatestauspalvelutFinland
HUS-yhtymä (jäljempänä myös tilaaja tai hankintayksikkö) pyytää tarjouksia tietoturvatestauspalveluista tämän tarjouspyynnön ja sen liitteiden ehtojen mukaisesti. Tietoturvatestauksessa käytetään pääsääntöisesti määrämuotoista tietoturvamallia. Testaus noudattaa tarvittavia ja yleisesti hyväksyttyjä viitekehyksiä ja standardeja kuten CC (Common Criteria for Information Technology Security Evaluation), OWASP (Open Web Application Security Project) mukaan lukien OWASP ASVS ja OWASP LLM, WASC…
More - State/localNET-16930 - USA (Monument, Colorado) - Network Environment Penetration Testing and Security Assessment Services - Deadline September 9,2026Monument, CO · due Sep 9, 2026
(1) Vendor needs to provide network environment penetration testing and security assessment services to the government authority located in Monument, CO. – Cybersecurity firms to provide baseline network penetration testing and security assessment services.– The engagement will include limited external and internal network testing, active directory and identity security review, microsoft 365/Entra id configuration review, and a focused review of systems supporting the police department.– The…
More - State/localCSE-24389 - USA (New York, New York) - Virtual Chief Information Security Officer (vCISO) Services - Deadline September 17,2026New York, NY · due Sep 17, 2026
(1) Vendor needs to provide virtual chief information security officer (vciso) services will support the Fund in enhancing and maturing its cybersecurity program; strengthening cybersecurity governance, oversight, and accountability; improving cybersecurity risk visibility through metrics, reporting, and dashboards; enhancing incident preparedness, response, and recovery capabilities; and aligning cybersecurity practices to the government authority located in New York, NY.• Strengthen…
More - State/localITES-10765 - Ireland - Cyber Security Consultancy and Technical Services - Deadline August 27,2026RFPMart: It Services Computer Maintenance & Technical Services · due Aug 27, 2026
(1) Vendor needs to provide cyber security consultancy and technical services include to implementing risk analysis frameworks, incident handling processes, business continuity and disaster recovery plans, AI system security reviews (artificial intelligence), SAAS security reviews (Software as a Service) and supply chain security measures as well tabletop exercises and pen test reviews.– A comprehensive program addressing areas such governance, business continuity, risk management, operational…
More - State/localITES-10814 - Ireland - Cyber Security Consultancy Services - Deadline August 28,2026RFPMart: It Services Computer Maintenance & Technical Services · due Aug 28, 2026
(1) Vendor needs to provide cyber security consultancy services.– Development of the inspection methodology, risk assessment approach, maturity assessment and inspection related templates.– Seeking pragmatic, proportionate and streamlined approach to cyber security inspections.– Cyber security inspection methodology.– Develop a documented risk–based approach for selecting which entities to inspect and when.– Maturity assessment.– Approach to maintaining confidentiality, integrity, and…
More - State/localNET-17004 - USA (Frankfort, Kentucky) - Network Security Software, Hardware, and Services - Deadline September 17,2026Frankfort, KY · due Sep 17, 2026
(1) Vendor needs to provide network security software, hardware, and services to the government authority located in Frankfort, KY.1. Firewall Management: Implementing and managing firewalls like Checkpoint, Fortinet, and Palo Alto.2. Rule Base Analysis: Analyzing firewall rules to assess how changes impact effectiveness, efficiency, compliance, and risk (such as Algosec).3. Web Gateways: Implementing URL caching and filtering solutions (such as Forcepoint Secure Web Gateway).4. Endpoint…
More - State/localITES-10720 - USA (Montpelier, Vermont) - Information Technology (IT) Services - Deadline September 2,2026Montpelier, VT · due Sep 2, 2026
(1) Vendor needs to provide information technology (IT) services to the government authority located in Montpelier, VT. – Provide strategies and solutions to defend hardware and software IT and telecommunications resources against adversaries such as viruses, worms and hackers for operating systems and applications, penetration testing and related IT security activities.– Analyze customer and citizen demand for IT–enabled services– Business analyst and project management services.– Online…
More - State/localINSU-6351 - USA (McAllen, Texas) - Cybersecurity Liability Insurance Services - Deadline September 4,2026McAllen, TX · due Sep 4, 2026
(1) Vendor needs to provide cybersecurity liability insurance services to the government authority located in McAllen, TX– Cybersecurity Insurance Services shall include:– Annual cybersecurity audit and external vulnerability scan – independent, third–party annual cybersecurity audit and external vulnerability scan to validate the efficacy of the district's internal vulnerability management systems and provide an external risk posture report for underwriting purposes– Loss Mitigation and…
More - State/localITES-10797 - Ireland - IT Support and Network Security Services - Deadline September 8,2026RFPMart: It Services Computer Maintenance & Technical Services · due Sep 8, 2026
(1) Vendor needs to provide IT support and network security services to the government authority located in Ireland.• 24 / 7 Managed Detection and Response service• Reactive Support and annual health check of existing HRI Firewalls• Security consultancy and advisory services• Security Penetration testing services• Option to supply of other security services(2) All questions must be submitted no later than September 1, 2026.(3) The contract period will be for four years.
More - State/localSW-118085 - USA (Illinois) - Security Awareness and Phishing Simulation Platform - Deadline August 28,2026RFPMart: Illinois · due Aug 28, 2026
(1) Vendor needs to provide security awareness and phishing simulation platform. • AI–Generated Phishing Scenarios: Ability of the platform to use integrated Large Language Models (LLMs) to dynamically generate highly realistic, contextual spear–phishing templates tailored to specific departments or user risk profiles.• Automated Campaigns: Support for automated, randomized “drip“ phishing campaigns to ensure employees do not receive the same tests at the exact same time.• Customization:…
More - State/localITES-10748 - USA (Washington, DC) - Global Cybercrime and Cryptocurrency Assessment and Intelligence Gathering Service - Deadline August 31,2026RFPMart: It Services Computer Maintenance & Technical Services · due Aug 31, 2026
(1) Vendor needs to provide global cybercrime and cryptocurrency assessment and intelligence gathering service to the government authority located in Washington, DC. • Addressing cybercrime and cyber–enabled crimes. Projects should focus on combating cyber intrusions, online fraud, online–facilitated drug trafficking, digital piracy, and the criminal misuse of cryptocurrency and virtual assets.• Establish comprehensive baseline understanding of online fraud harming Americans through…
More - State/localAI-1185 - USA (Maryland) - NextGen Cyber Engineering, Operations AI, and Unified Services - Deadline August 31,2026RFPMart: Artificial Intelligence & Machine Learning · due Aug 31, 2026
(1) Vendor needs to provide NextGen cyber engineering, operations AI, and unified services. • Integrated cybersecurity engineering, cybersecurity operations and threat management, identity, credential, and access management (ICAM), artificial intelligence and automation–enabled capabilities.• Provide engineering, administration, and sustainment support for the FDA Cybersecurity Platform, including Security Information and Event Management (SIEM) and associated tools, AI–enhanced analytics,…
More - State/localVirtual Chief Information Security Officer (vCISO) ServicesNew York City · due Sep 17, 2026
The New York City Police Pension Fund is seeking proposals from qualified and experienced firms to provide Virtual Chief Information Security Officer (vCISO) services. The selected firm will support the Fund in enhancing and maturing its cybersecurity program; strengthening cybersecurity governance, oversight, and accountability; improving cybersecurity risk visibility through metrics, reporting, and dashboards; enhancing incident preparedness, response, and recovery capabilities; and aligning…
More - State/localCzechia – Statutory audit services – Auditní a poradenské služby v oblasti kybernetické bezpečnostiCzechia · due Sep 18, 2026
Předmětem veřejné zakázky je vypracování komplexního auditu kybernetické bezpečnosti informačních systémů, síťové infrastruktury, serverové infrastruktury, tenantu Microsoft 365 a bezpečnostní dokumentace Zadavatele, příprava implementačního plánu opatření. Požadovaný rozsah auditu je blíže popsán v příloze č. 1 závazného návrhu smlouvy, která je přílohou č. 1 zadávací dokumentace. Dále je předmětem veřejné zakázky poskytování následných poradenských služeb v oblasti kybernetické bezpečnosti…
More - State/localITES-10784 - USA (Maryland) - Statewide Cybersecurity Resources Services - Deadline September 18,2026RFPMart: It Services Computer Maintenance & Technical Services · due Sep 18, 2026
(1) Vendor needs to provide statewide cybersecurity resources services to the government authority located in MD.– Provide secure highly skilled professionals and teams capable of delivering advanced cybersecurity and privacy services across multiple domains, including governance, risk management, and compliance.– Strengthen their cybersecurity posture, mitigate risks, and ensure compliance with federal and state regulations.– Oversight and governance:– provide implementing robust risk…
More - State/localITES-10746 - USA (Pennsylvania) - Digital Development Services - Deadline June 2,2030RFPMart: Pennsylvania · due Jun 2, 2030
Vendor needs to provide digital development services to the government authority located in Pennsylvania.1. Digital service discovery:– Includes, but is not limited to, the performance of initial research and analysis activities required to identify and define user needs and system requirements for digital service projects. Services include stakeholder interviews, user research, competitive analysis, persona identification, business process mapping, and initial prototyping to outline feasible…
More - FederalDA01--Enterprise Cybersecurity Program Audit Support (VA-26-00036760)VETERANS AFFAIRS, DEPARTMENT OF / VETERANS AFFAIRS, DEPARTMENT OF
The acquisition strategy for Enterprise Cybersecurity Program Audit Support is still being determined, and answers to any technical questions asked are still being formulated.
More - State/localITES-10749 - USA (Anchorage, Alaska) - Cybercrimes Program Enforcement Services - Deadline August 28,2026Anchorage, AK · due Aug 28, 2026
(1) Vendor needs to provide cybercrimes program enforcement services to strengthen the investigation and prosecution of cybercrimes against individuals in rural and remote communities to the government authority located in Anchorage, AK.– Expand statewide investigative capacity– Increase local digital investigation capability– Improve victim–centered investigations and offender accountability– Strengthen statewide collaboration and technical assistance(2) All question must be submitted no…
More - State/localCyber Security Services 3United Kingdom (Contracts Finder) · due Feb 11, 2029
Crown Commercial Service (CCS) set up a dynamic purchasing system for a period of 60 months and has invited bidders to request to participate for the Cyber Security Services 3 DPS. This DPS provides central government departments and the wider public sector with the opportunity to procure cyber services from a range of suppliers. The DPS filters are for certification, services, standards and experience. Appointed suppliers will be invited by customers (buyers) to submit tenders for relevant…
More - State/localSW-117656 - USA (Michigan) - Cloud-Based Active Assailant Threat Detection Platform - Deadline August 27,2026RFPMart: Michigan · due Aug 27, 2026
(1) Vendor needs to provide cloud–based active assailant threat detection platform.– A secure, cloud–based Software–as–a–Service (SaaS) platform that continuously analyzes publicly available online information to identify behavioral indicators associated with potential targeted violence and other threats to public safety. – Include software licensing, secure cloud hosting, implementation, configuration, onboarding, administrator and end–user training, technical support, ongoing maintenance,…
More - State/localITES-10871 - USA (East Wenatchee, Washington) - Managed IT and Cybersecurity Services - Deadline September 1,2026East Wenatchee, WA · due Sep 1, 2026
(1) Vendor needs to provide managed IT and cybersecurity services to the government authority located in East Wenatchee, WA. – Provide comprehensive managed IT services and cybersecurity to support district operations.– Capable of delivering secure, reliable, and scalable IT services that support public health operations, regulatory requirements, and continuity of services.– Cybersecurity Services:• Managed Detection and Response (MDR).• Identity Threat Detection and Response (ITDR), including…
More - State/localSW-117561 - USA (New Jersey) - Cyber Security Awareness and Training Platform - INFO ONLY, RFP NOT INCLUDED - Deadline August 28,2026RFPMart: Software System & Application · due Aug 28, 2026
(1) Vendor needs to provide cyber security awareness and training platform.– An AI–enabled, customizable cybersecurity awareness and training platform that supports continuous human risk reduction beyond compliance–based training.– Provide a technology platform to enable cyber security awareness and training.(2) This is a brief information; Main RFP Document is not available on our website.
More - State/localSW-117561 - USA (New Jersey) - Cyber Security Awareness and Training Platform - INFO ONLY, RFP NOT INCLUDED - Deadline August 28,2026RFPMart: New Jersey · due Aug 28, 2026
(1) Vendor needs to provide cyber security awareness and training platform.– An AI–enabled, customizable cybersecurity awareness and training platform that supports continuous human risk reduction beyond compliance–based training.– Provide a technology platform to enable cyber security awareness and training.(2) This is a brief information; Main RFP Document is not available on our website.
More - State/localITES-10832 - USA (Washington, DC) - IT Infrastructure Service - Deadline September 4,2026RFPMart: It Services Computer Maintenance & Technical Services · due Sep 4, 2026
– Vendor needs to provide IT infrastructure service to the government authority located in city. – services and achieve measurable results, including system availability, data integrity, automated workflow functionality, compliance with applicable IT governance and security standards, operational reliability, end–to–end technical performance, and continuous improvement. – System availability and operational continuity, compliance with cybersecurity standards and policies, timely remediation of…
More - State/localITES-10787 - USA (California) - Senior IT Manager Services - Deadline September 1,2026RFPMart: It Services Computer Maintenance & Technical Services · due Sep 1, 2026
(1) Vendor needs to provide senior IT manager services.1. Systems and help desk management:– Administrate the M365 environment, including Active Directory, Defender, SharePoint, Intune and exchange.– Oversee and supervise all IT help desk and facilities (technology related) support requests across multiple offices; ensure accuracy and timeliness of responses.– Consult on and develop trainings for staff to build out the staff website.– Create content for the IT section of the staff website,…
More - State/localUS-FED-00000390354 - Sources Sought C5ISRT NEXT GENERATION CYBERSECURITY AND INFORMATION ASSURANCE - Deadline August 25,2026RFPMart: It Services Computer Maintenance & Technical Services · due Aug 25, 2026
C5ISRT NEXT GENERATION CYBERSECURITY AND INFORMATION ASSURANCEThe Naval Surface Warfare Center, Panama City Division (NSWC PCD) is soliciting capability statements from potential qualified sources to provide comprehensive full–lifecycle cybersecurity for the C5ISRT Division. The C5ISRT Division, is responsible for the cybersecurity of a large and diverse portfolio of mission–critical systems. This portfolio supports a wide range of stakeholders, including OPNAV N95, PMW 130, PMW 150, PMW 160,…
More - State/localSW-117825 - USA (Oklahoma) - Managed Email Security Solution - Deadline August 28,2026RFPMart: Oklahoma · due Aug 28, 2026
(1) Vendor needs to provide managed email security solution.– Solution should deliver both technology and managed services to protect users, prevent compromise, and improve the organization's overall email security posture.– Protect against malware, ransomware, and malicious attachments.– Improve visibility into email threats and attack trends.– Provides meaningful threat intelligence and visibility.– Proposed solution must include the following capabilities:• Email Threat Detection• Email…
More - FederalCyber Future Capability Directorate RFIDEPT OF DEFENSE / DEPT OF THE ARMY · due Sep 4, 2026
Title: Cyber Future Capability Directorate seeks solutions to solve challenges with Electromagnetic Warfare in Support of Army 2030-2040 requirements Department/Agency: Department of War Sub Agency: Department of Army Major Command: T2COM Sub Command: Cyber FCD, Ft Gordon, GA Office: Science and Technology Branch, Experimentation Division Classification: Unclassified Description: THIS IS A REQUEST FOR INFORMATION (RFI) ONLY. This RFI is issued solely for information and planning purposes – it…
More - FederalDA01--Enterprise Cybersecurity Program Audit Support (VA-26-00036760)VETERANS AFFAIRS, DEPARTMENT OF / VETERANS AFFAIRS, DEPARTMENT OF
Enterprise Cybersecurity Program Audit Support is intended to be solicited and released as an SDVOSB set-aside on GSA MAS IT PS SIN 54151S, anticipated for release in the early June timeframe. Additionally, this modification to the previous notice is being issued to provide responses to the technical questions submitted.
More - State/localNETWORK ENVIRONMENT PENETRATION TESTING AND SECURITY ASSESSMENT SERVICESColorado · due Sep 9, 2026
- State/local
- State/local
- State/localOrganizational Continuity and Resiliency Portfolio (OCRP) Limited Penetration Test EngagementWashington · due Aug 31, 2026
- State/local
- State/local
- State/local
- State/local
- State/local
- State/local
- State/local
- State/localThreat Detection, Screening & Emergency Response SolutionsEqualis Group / Region 10 ESC, TX · due Sep 4, 2026
- State/local
- State/local
- State/local
- State/local
- State/local
- State/local
- State/local
- State/local
Frequently asked
65 open Penetration testing opportunities are posted right now — 5 federal and 60 state & local — updated daily.
GovBidAlerts matches open federal (SAM.gov), state, and local solicitations to the Penetration testing category with AI, so you can browse Penetration testing bids and RFPs across every level of government in one place.