See More RFPs

Application Security Testing Platform

Overview


Cybersecurity & Data Privacy
Sacramento, California, United StatesPosted: July 8th, 2026Deadline: July 29th, 2026

Settle Signals


Market intelligence for public sector sales teams

RFP Hunter shows what is open. Settle shows what is forming.

Settle pieces together buyer signals, budgets, contract activity, and the sources your team already monitors. See why an opportunity fits and what to do before the RFP posts.

Learn more about Settle

SUMMARY


A California-based solicitation seeks an application security testing platform with integrated SAST, DAST, SCA, and AI-assisted remediation capabilities. The solution must support CI/CD integration, secure authentication, flexible deployment models, and training for agency users.

KEY REQUIREMENTS


TIMELINE


Release Project Date: July 7th, 2026

Pre-Bid Meeting (Mandatory): July 8th, 2026

Question Submission Deadline: July 15th, 2026

Addendum Issued (if necessary): July 24th, 2026

Submission Deadline: July 29th, 2026

Award Contract: August 3rd, 2026

QUESTION DEADLINE


July 15th, 2026

CONTACTS


Primary procurement contact — name, title, email, and phone

Additional decision-makers and their departments

Issuing Agency


County Of Sacramento

Organization overview and procurement intelligence available on paid plans.
See Issuer Research

DESCRIPTION


The issuing organization is seeking a vendor to provide an Application Security Testing (AST) platform that supports secure software development across multiple programming languages and development environments. The requested solution must include integrated capabilities for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and AI-assisted remediation to help identify, prioritize, and remediate vulnerabilities throughout the software development lifecycle.

The platform should integrate with modern source code management systems and CI/CD pipelines, including GitHub, GitLab, Azure DevOps, Bitbucket, and other systems used by agency development teams. It must also support enterprise authentication features such as single sign-on and role-based access control, provide deployment options approved by the agency such as cloud, on-premises, or hybrid, and include dashboards for audit, compliance, and operational security reporting. The solution should support both developer-centric and application-centric licensing models, with clear definitions for usage limits, concurrency constraints, and entitlements.

Vendors are also expected to provide developer-friendly reporting, vulnerability history tracking, severity scoring, findings triage, and AI-assisted remediation guidance such as patch recommendations and code-fix suggestions. Where applicable, the solution should have FedRAMP Moderate or GovRAMP authorization. In addition to the platform itself, the selected vendor must provide onboarding, administrator training, developer enablement sessions, and on-demand learning resources. Questions are due by July 15, 2026, and a mandatory pre-bid meeting will be held on July 8, 2026.

Similar RFPs


Frequently asked questions


When is the submission deadline?
Submissions are due July 29, 2026. Questions must be submitted by July 15, 2026.
Who issued this RFP?
It was issued by County Of Sacramento. The work is located in Sacramento, California, United States.
Who is a good fit for this opportunity?
  • Cybersecurity software vendor specializing in application security testing platforms
  • Proven experience delivering integrated SAST, DAST, and SCA solutions
  • Capability to support enterprise CI/CD and source control integrations
  • Experience serving government or regulated-sector clients
  • FedRAMP Moderate or GovRAMP authorized offering where applicable
  • Strong training, onboarding, and developer enablement services
  • Flexible deployment support across cloud, on-premises, and hybrid environments
  • Expertise in SSO, role-based access control, and compliance reporting

Analysis generated by Settle AI from the source RFP.

RFP Hunter shows what is open. Settle shows what is forming.

Settle pieces together buyer signals, budgets, contract activity, and the sources your team already monitors. See why an opportunity fits and what to do before the RFP posts.

See how Settle works