Skip to content
GSA7 min readUpdated June 7, 2026

SIN 541990IPS: Data Breach Response and Identity Protection Guide for GSA MAS

A Refresh 32 guide to GSA MAS SIN 541990IPS, Data Breach Response and Identity Protection, including category fit, NAICS/PSC context, max order, TDR/OLM status, and offer preparation notes.

Built for
Contractors mapping offerings, pricing support, catalog files, labor categories, or Add SIN modifications to official GSA MAS scope
By the end
Understand where SIN 541990IPS fits and what evidence to prepare before using it in an offer or modification.
Field guide

When SIN 541990IPS fits

Scope fit
A close-looking SIN can still be wrong if the subcategory, PSC, NAICS, or deliverable story points elsewhere.
Signal
541990IPS Data Breach Response and Identity Protection Services (IPS) include an integrated, total solution to provide identity monitoring and notification of Personally Identifiable Information (PII) and Protected Health Information (PHI); identity theft insurance; identity restoration services; and protection (safeguarding) the confidentiality of PII and PHI. Additional requirements specifically for Identity Protection Services are found in the notes section referenced below.^^^^NOTE 1: Additional Proposal Instructions related to Identity Protection Services (IPS) are found in IPS Requirements Document 1B.^^^^NOTE 2: Any firm offering Identity Protection Services will be required to provide a System Security Plan (SSP) in accordance with the template found in IPS Requirement Document 1C. The firm will also be required to submit a Firm Fixed Price as outlined in IPS Pricing Document 2, unless otherwise defined at the Task Order level (e.g. per product redeemed per the agreed-upon coverage period (month, year, etc.) ) covering ALL services cited in Section I of IPS Requirements Document 1A. If defined otherwise at the Task Order level, it must still be able to be mapped to the awarded Schedule contract pricing. Firms are encouraged to provide separate line item pricing for key services within this total solution SIN that the firm believes could be ordered independently (e.g., credit monitoring, restoration, etc). This will allow the Ordering Agency to obtain only those services needed depending on level of breach. See IPS Pricing Document 2 for pricing tables. ^^^^NOTE 3: Services provided shall be performed in accordance with applicable Federal laws and policies, including the Identity Theft and Assumption Deterrence Act of 1998, as amended by Public Law 105-318, 112 Statute 3007 (Oct. 30, 1998), and implemented by 18 U.S.C. 1028. Firms are required to adhere to all applicable Office of Management and Budget (OMB) policies including OMB Circular A-130, Managing Federal Information as a Strategic Resource, and any updates to OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information.^^^^NOTE 4: The Agency Ordering Guide for Identity Protection Services can be found at https://www.gsa.gov/buying-selling/products-services/professional-services/buy-services/identity-protection-services-ips
Response
Compare the buyer's requirement to the official SIN language before forcing the opportunity into a familiar lane.
Service proof
Service SINs can create labor-category, qualifications, worksite, and rate-support questions.
Signal
The SIN supports service work, labor categories, deliverables, and pricing support.
Response
Prepare labor category descriptions, service narratives, past performance, FCP Services Plus data, and pricing support.
Modification path
Adding a SIN can affect catalog files, service descriptions, pricing support, and buyer-facing records.
Signal
The contractor wants to add this SIN after award or adjust offerings tied to it.
Response
Use the Add SIN and Add Product/Labor Category modification pages to plan scope, price, and evidence changes.
Refresh 32

SIN 541990IPS quick facts

A compact view of the official SIN record from the user's Refresh 32 MAS offerings workbook.

Category
Professional Services
Identity Protection Services
NAICS
541990
NAICS codes associated with the SIN in the workbook.
PSC
R704
Product Service Code mapped to the SIN.
Max order
$1,000,000
Ordering threshold for seeking additional price reductions.
Part 1

What SIN 541990IPS covers

541990IPS Data Breach Response and Identity Protection Services (IPS) include an integrated, total solution to provide identity monitoring and notification of Personally Identifiable Information (PII) and Protected Health Information (PHI); identity theft insurance; identity restoration services; and protection (safeguarding) the confidentiality of PII and PHI. Additional requirements specifically for Identity Protection Services are found in the notes section referenced below.^^^^NOTE 1: Additional Proposal Instructions related to Identity Protection Services (IPS) are found in IPS Requirements Document 1B.^^^^NOTE 2: Any firm offering Identity Protection Services will be required to provide a System Security Plan (SSP) in accordance with the template found in IPS Requirement Document 1C. The firm will also be required to submit a Firm Fixed Price as outlined in IPS Pricing Document 2, unless otherwise defined at the Task Order level (e.g. per product redeemed per the agreed-upon coverage period (month, year, etc.) ) covering ALL services cited in Section I of IPS Requirements Document 1A. If defined otherwise at the Task Order level, it must still be able to be mapped to the awarded Schedule contract pricing. Firms are encouraged to provide separate line item pricing for key services within this total solution SIN that the firm believes could be ordered independently (e.g., credit monitoring, restoration, etc). This will allow the Ordering Agency to obtain only those services needed depending on level of breach. See IPS Pricing Document 2 for pricing tables. ^^^^NOTE 3: Services provided shall be performed in accordance with applicable Federal laws and policies, including the Identity Theft and Assumption Deterrence Act of 1998, as amended by Public Law 105-318, 112 Statute 3007 (Oct. 30, 1998), and implemented by 18 U.S.C. 1028. Firms are required to adhere to all applicable Office of Management and Budget (OMB) policies including OMB Circular A-130, Managing Federal Information as a Strategic Resource, and any updates to OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information.^^^^NOTE 4: The Agency Ordering Guide for Identity Protection Services can be found at https://www.gsa.gov/buying-selling/products-services/professional-services/buy-services/identity-protection-services-ips

The official record maps this SIN to NAICS 541990 and PSC R704. Those codes are not the whole strategy, but they help explain how the offering is categorized for buyers and reviewers.

Part 2

How to prepare the offer story

For service-oriented SINs, keep the service description, labor categories, pricing support, and past-performance examples aligned. A reviewer should be able to see what work is being sold, who performs it, and why the rate story is defensible.

If the SIN is being added through eMod, write down what changes operationally: new scope, new pricing, new files, catalog impact, and who owns maintenance after approval.

Part 3

Buyer and SEO language to keep straight

Use the SIN number, title, category, and subcategory together: SIN 541990IPS - Data Breach Response and Identity Protection - Professional Services - Identity Protection Services. That combination helps a buyer understand the lane quickly and helps the page avoid becoming a vague keyword page.

When writing capability language, explain the actual deliverables and evidence. Do not make the SIN carry the whole message by itself.

Examples

What this looks like in practice

Real-world checkHow to test SIN 541990IPS before building files

Start with the official title and description: Data Breach Response and Identity Protection sits under Professional Services > Identity Protection Services. Then compare your actual commercial offering to that scope, not only to the NAICS code.

If the fit still looks strong, build the proof stack: offering description, pricing support, past performance or product support, and any SIN-specific files the current GSA instructions require.

  • Confirm scope language.
  • Check NAICS and PSC signals.
  • Match the pricing file to the offering type.
  • Keep the support package reviewer-friendly.

Frequently asked questions

Is SIN 541990IPS part of TDR?

The Refresh 32 workbook marks TDR as Y for this SIN. GSA states that TDR became mandatory across MAS SINs with Refresh 31, so contractors should still verify current contract reporting instructions in official GSA sources.

Can order-level materials be used with SIN 541990IPS?

The workbook marks OLM as Y. OLM treatment should always be verified against the current MAS solicitation, mass modifications, and contract-specific instructions.

Should I pick a SIN only because the NAICS matches?

No. NAICS helps, but SIN selection should be based on the actual offering, official SIN description, category/subcategory, pricing files, and buyer acquisition path.