Skip to content
OpenDue May 19, 2026

Request for Information (RFI) -- DAST Tool

SOCIAL SECURITY ADMINISTRATION

About this opportunity

The Web Application Security Team (WAST) performs static code scanning of all SSA applications as part of the Office of Information Security�s (OIS) cybersecurity program. This is accomplished with the static application security testing (SAST) tool called Checkmarx and the software composition analysis (SCA) tool called Black Duck. Both of these solutions are white box testing tools that analyze the application�s code as it's being built. WAST is looking to procure a Dynamic Application Security Testing (DAST) solution to better analyze SSA applications, to bolster FISMA metrics, and to satisfy the requirements from multiple external audits and assessments. The DAST tool would scan applications as they are executed to identify exploits that can only be detected from black box testing. Thi...

Finding similar opportunities...