Specifications include, but are not limited to: The Washington Metropolitan Area Transit Authority (WMATA) requires the services of a qualified contractor to provide a cyber maturity assessment solution. The solution benchmarks WMATA’s target maturity based on risk across 16 cybersecurity capabilities, assess WMATA using industry standards against cybersecurity framework supported practices, deliver a bespoke measured maturity for WMATA and a prioritized risk roadmap to close critical gaps, and develop a strategic plan for building maturity, resilience, and board confidence in line with meeting WMATA’s business objectives . WMATA needs to procure a cyber maturity assessment solution software to benchmark target maturity goals and measure maturity of WMATA’s cybersecurity office using a risk-based assessment approach. The solution will: • Enable a customized risk profile to set quantified capability maturity targets. • Assess across an activity-based architecture of cybersecurity practices that support leading frameworks. • Demonstrate practice gaps, and alignment views to leading frameworks. • Prioritize missing practices for implementation and deliver a plan for improvement. • Deliver a baseline of capability effectiveness, relative maturity, and ability to perform. • Provide easily accessible, transparent, and evidence-based reporting of capability maturity.