The Crowdsourced Vulnerability Discovery and Disclosure (CVDD) Master Indefinite Delivery/Indefinite Quantity (IDIQ) contract is a cybersecurity-focused procurement vehicle designed to enable the Department of Defense (DoD) to leverage private sector expertise in identifying and resolving potential security vulnerabilities. The contract supports the DoD's objective of enhancing information security through crowdsourced methodology, specifically utilizing commercial firms with extensive experience in administering vulnerability discovery and disclosure activities. The contract allows these firms to host crowdsourced security activities on behalf of the DoD, utilizing platforms and networks of security researchers to systematically identify and report potential system weaknesses. The CVDD contract has primarily been awarded to three prime contractors: HackerOne Inc., Synack, Inc., and Bugcrowd Inc., each delivering task orders typically valued between $200,000 and $550,000 with durations ranging from six to twelve months. Task orders consistently focus on services such as bug bounty programs, vulnerability disclosure, penetration testing, and crowdsourced security assessments, with performance locations primarily in California (San Francisco, Redwood City) and Washington, D.C. Most task orders are competitively awarded without small business set-asides, though one contract to Bugcrowd was designated as a total small business set-aside. The contract supports various DoD components, including the Office of the Secretary of Defense, Defense Advanced Research Projects Agency (DARPA), and the Air Force, with task orders often supporting specific initiatives like the "Hack the Pentagon" program.
Name | Description | Awardee | Potential Value (Click to sort descending) | Award Date (Click to sort descending) | Last Date To Order (Click to sort descending) | Updated At (Click to sort descending) |
|---|---|---|---|---|---|---|
HQ003418D0034 | Bugcrowd Inc. | $34.0m | 9/30/18 | 9/29/21 | 2/23/23 | |
HQ003418D0033 | Synack, Inc. | $34.0m | 9/30/18 | 9/29/21 | 3/16/22 | |
HQ003418D0032 | Hackerone Inc. | $34.0m | 9/30/18 | 6/29/22 | 3/16/22 |
Name | Description | Awardee | Potential Value (Click to sort descending) | Award Date (Click to sort descending) | Completion Date (Click to sort descending) | Updated At (Click to sort descending) |
|---|---|---|---|---|---|---|
Delivery Order HQ003418D0032-HQ003420F0668 | Hackerone Inc. | $441.8k | 9/29/20 | 9/29/21 | 9/27/21 | |
Delivery Order HQ003418D0033-HQ003420F0183 | Synack, Inc. | $295.9k | 4/3/20 | 12/31/20 | 6/4/21 | |
Delivery Order HQ003418D0032-HQ003419F0581 | Hackerone Inc. | $513.0k | 8/30/19 | 10/10/19 | 4/20/20 | |
Delivery Order HQ003418D0033-HQ003418F0672 | Synack, Inc. | $7.5k | 9/27/18 | 9/29/21 | 9/27/18 | |
Delivery Order HQ003418D0033-HQ003420F0667 | Synack, Inc. | $550.0k | 9/30/20 | 4/30/21 | 1/28/21 |
Name | Description | Solicitation Number | Federal Agency | Type | Posted Date (Click to sort descending) |
|---|---|---|---|---|---|
DDS Crowdsourced Vulnerability Discovery & Disclosure Services (CVDD) FA2 | HQ003418R0202 | DOD Washington Headquarters Service | Solicitation 1/2 | 7/13/18, 9:27 AM | |
Crowdsourced Vulnerability Discovery and Disclosure (CVDD) Services | HQ003418R0202 | DOD Washington Headquarters Service | Award Notice 2/2 | 10/23/18, 4:13 PM |
Name | Description | UEI | Primary NAICS | Division | Location | Registration Date (Click to sort descending) | Expiration Date (Click to sort descending) |
|---|---|---|---|---|---|---|---|
| Hackerone Inc. | KGSEGCXA2JN1 | 541519 | Not listed | 44 Montgomery, 44 Montgomery St, San Francisco, CA 94104, USA | 2/4/16 | 4/18/25 | |
| Bugcrowd Inc. | DRCHBQ1G4D38 | 541519 | Not listed | 300 California St Suite 220, San Francisco, CA 94104, USA | 2/17/16 | 7/11/25 | |
| Synack, Inc. | EDRWE6PRKL85 | 541519 | Not listed | 1655 Fort Myer Dr Fl 7 Ste 736, Arlington, VA 22209, USA | 3/25/13 | 5/1/25 |
A Portfolio Platform of GovExec © 2025