See More RFPs

Cyber Third-Party Risk Management Services

Overview


Cybersecurity & Data Privacy
New Mexico, United StatesPosted: September 16, 2026Deadline: October 16, 2026

Settle Signals


Market intelligence for public sector sales teams

RFP Hunter shows what is open. Settle shows what is forming.

Settle pieces together buyer signals, budgets, contract activity, and the sources your team already monitors. See why an opportunity fits and what to do before the RFP posts.

Learn more about Settle

SUMMARY


A New Mexico government authority seeks a vendor to develop and deliver a scalable cyber third-party risk management program and toolset for participating local entities. Work includes risk governance, vendor assessment and monitoring, cybersecurity requirements, training, legal evaluation, and template ordinances.

KEY REQUIREMENTS


CONTRACT DURATION


6 months

TIMELINE


Request for Quote Issuance: September 14th, 2026

Questions Due: September 25th, 2025

Questions and Answers Posted: October 2nd, 2026

Quote Submission Deadline: October 16th, 2026

Evaluation and Selection: October 19th, 2026 – November 20th, 2026

QUESTION DEADLINE


September 25, 2025

CONTACTS


Primary procurement contact — name, title, email, and phone

Additional decision-makers and their departments

Issuing Agency


New Mexico Office Of Cybersecurity

Organization overview and procurement intelligence available on paid plans.
See Issuer Research

DESCRIPTION


The government authority in New Mexico is seeking a vendor to design, develop, and deliver a scalable, multi-tenant cyber third-party risk management framework, program, and toolset for entities participating in state grants. Participating local entities may include higher education institutions, county governments, municipalities, and tribal governments with varying levels of cybersecurity maturity.

The engagement is expected to address cybersecurity governance and planning, risk assessments, vulnerability and attack surface management, cybersecurity training, and workforce development planning. The program will standardize how local entities discover, tier, assess, contract with, and continuously monitor third-party vendors, resellers, software providers, and managed service providers in order to reduce systemic supply-chain cybersecurity risk.

The vendor will also evaluate existing legal and contractual provisions, recommend baseline cybersecurity requirements aligned with nationally recognized cybersecurity frameworks, and develop one or more template ordinances that participating entities may adopt to establish legal authority for a third-party risk management program.

Similar RFPs


Frequently asked questions


When is the submission deadline?
Submissions are due October 16, 2026. Questions must be submitted by September 25, 2025.
Who issued this RFP?
It was issued by New Mexico Office Of Cybersecurity. The work is located in New Mexico, United States.
Who is a good fit for this opportunity?
  • Cybersecurity consultancy with third-party risk management expertise
  • Experience designing scalable, multi-tenant cybersecurity programs and toolsets
  • Familiarity with higher education, local government, tribal government, or grant-funded entities
  • Expertise in supply-chain security, vendor assessments, vulnerability management, and attack surface management
  • Knowledge of nationally recognized cybersecurity frameworks and public-sector legal requirements
  • Proven ability to deliver cybersecurity training and workforce development planning

Analysis generated by Settle AI from the source RFP.

RFP Hunter shows what is open. Settle shows what is forming.

Settle pieces together buyer signals, budgets, contract activity, and the sources your team already monitors. See why an opportunity fits and what to do before the RFP posts.

See how Settle works