What this opportunity is
The Department of Defense is seeking information about potential contractors for the Army Enterprise Identity, Credential, and Access Management (E-ICAM) Services Delivery Contract. This non-set-aside procurement is suitable for businesses with expertise in computer systems design and related services (NAICS 541519). The notice type is a Sources Sought, indicating that interested parties should track the solicitation for updates rather than submit a bid immediately. The contract will be performed in Virginia, and the services will involve the continuous delivery and modernization of the Army's ICAM platform, including operation, maintenance, and Tier 3 helpdesk support.
Analysis by Mindy, grounded in the SAM.gov notice.
Description
Performance Work Statement (PWS) for
Army Enterprise Identity, Credential and Access Management (E-ICAM) Delivery Contract
FOR
Army Capability Program Executive (CPE) Command and Control Information Network (C2IN)
DATE: 03 March 2026
VERISON: Army E-ICAM Delivery v1
Controlled by: Department of Army Controlled by: CPE C2INEO EISCUI Category(ies): Procurement and Acquisition Distribution: FEDCONPOC: David Thompson
Section 1 – General
1. Description of services
The Contractor shall provide all non-personal services, supervision, and resources necessary to perform the continuous delivery and modernization of the Army's enterprise Identity, Credential, and Access Management (ICAM) platform, as defined in this Performance Work Statement (PWS). These services encompass the continuous operation, maintenance, and Tier 3 helpdesk support for existing capabilities, including the Army Master Identity Directory (AMID), Army Enterprise Identity Provider (IdP), Identity Governance and Administration (IGA), Privileged Access Management (PAM), and auditing services across all classification levels. Concurrently, the contractor will incrementally develop, deliver, and integrate modernized ICAM capabilities using an agile methodology to incorporate Zero Trust principles, automate account provisioning and access controls, and improve identity governance. This effort requires a Site Reliability Engineering (SRE) model that utilizes a continuous delivery pipeline that ensures proactive security patching and automated capability enhancements without disrupting mission operations.
The contractor shall replace manual 'break-fix' routines with automated, self-healing infrastructure that comply with Zero Trust concepts and ensure Army Unified Network ICAM capabilities never stagnate; adaptations are deployed in hours, not months. The Army E-ICAM services must guarantee critical access capabilities remain highly available to the warfighter, while seamlessly integrating continuous security and feature updates. These comprehensive services are designed to improve the Army's cybersecurity posture, drive IT efficiencies by eliminating redundant systems, and ensure compliance with Federal, DoD, and Army mandates.
1.2. Background
The Department of the Army operates a suite of enterprise Identity, Credential, and Access Management (ICAM) capabilities that are foundational to securing the Army’s network and data. This existing infrastructure, while operational, requires significant flexible modernization to align with current Department of Defense (DoD) and Army cybersecurity strategies, including the transition to a Zero Trust Architecture. This initiative is driven by the urgent need to enhance security, improve IT efficiency by consolidating disparate systems, and ensure compliance with federal mandates and audit requirements.
This modernization effort is a critical enterprise-wide initiative that impacts and requires coordination across a broad spectrum of Army organizations. The contractor's performance will be integral to meeting the complex requirements of these varied stakeholders as the Army evolves its ICAM platform to provide a more robust, centralized, and automated solution for managing digital identities and access control.
1.3. Scope
Base Requirements: The scope of this Performance Work Statement (PWS) encompasses the full lifecycle of services required to sustain and modernize the Army's enterprise Identity, Credential, and Access Management (ICAM) platform. This includes continuing to deliver all current ICAM capabilities while simultaneously developing and integrating modernized solutions using an agile framework. A critical component of this scope is providing direct support for audit compliance, including the remediation of findings from financial and cybersecurity audits. The contractor shall provide all necessary program management, systems engineering, and technical support to enhance the platform in alignment with Zero Trust principles, automate controls to address audit requirements, and integrate Army applications into the enterprise and tactical operating environments to improve the Army's overall cybersecurity posture and IT efficiency.
Optional Surge Capability: The Government, at its sole discretion, may require the contractor to provide agile based surge support beyond the level of effort defined for the base requirements. This optional capability provides for increased support for any task area within this PWS in response to unforeseen requirements, new mandates, or changes in schedule. All surge support shall be ordered by the Contracting Officer in accordance with the terms of the contract."
1.4. Place of performance
The contractor can perform work at a remote location that can support the mission requirements in accordance with DoD and Army regulations, including access to NIPRNet, SIPRNet, Top Secret (if applicable) and Sensitive Compartmented Information (SCI) known as the Joint Worldwide Intelligence Communications System (JWICS) and commercial cloud services. The government will also provide on-site access at Fort Belvoir, VA.
1.5. Travel requirements will be dependent on the contractor's proposed solution. It is anticipated that travel outside of the National Capital Region will be required at least five times per year. The specific details regarding locations, dates, and the number of participants is to be determined and proposed by the contractor.
1.6. FEDERAL HOLIDAYS.
Non-Performance Days: The contractor is not required to perform services on the federal holidays listed below. The U.S. Government observes the following days as holidays:
New Year's Day (January 1st)
Martin Luther King, Jr.'s Birthday (Third Monday in January)
Washington's Birthday / Presidents' Day (Third Monday in February)
Memorial Day (Last Monday in May)
Juneteenth National Independence Day (June 19th)
Independence Day (July 4th)
Labor Day (F…
Source: SAM.gov, as posted. Verify the current solicitation before responding.