Crowdsourced Vulnerability Discovery and Disclosure (CVDD)

Award Date 9/30/2018
Last Date To Order 9/28/2021
Shared Ceiling $34M
Contract Type
Master IDIQ
Predecessor
Not listed
Successors

The Crowdsourced Vulnerability Discovery and Disclosure (CVDD) Master Indefinite Delivery/Indefinite Quantity (IDIQ) contract is a cybersecurity-focused procurement vehicle designed to enable the Department of Defense (DoD) to leverage private sector expertise in identifying and resolving potential security vulnerabilities. The contract supports the DoD's objective of enhancing information security through crowdsourced methodology, specifically utilizing commercial firms with extensive experience in administering vulnerability discovery and disclosure activities. The contract allows these firms to host crowdsourced security activities on behalf of the DoD, utilizing platforms and networks of security researchers to systematically identify and report potential system weaknesses.

The CVDD contract has primarily been awarded to three prime contractors: HackerOne Inc., Synack, Inc., and Bugcrowd Inc., each delivering task orders typically valued between $200,000 and $550,000 with durations ranging from six to twelve months. Task orders consistently focus on services such as bug bounty programs, vulnerability disclosure, penetration testing, and crowdsourced security assessments, with performance locations primarily in California (San Francisco, Redwood City) and Washington, D.C. Most task orders are competitively awarded without small business set-asides, though one contract to Bugcrowd was designated as a total small business set-aside. The contract supports various DoD components, including the Office of the Secretary of Defense, Defense Advanced Research Projects Agency (DARPA), and the Air Force, with task orders often supporting specific initiatives like the "Hack the Pentagon" program.

Generated 1/16/25, 12:26 AM