RFI: External Attack Surface Module (EASM)
The Social Security Administration (SSA) has issued a Request for Information (RFI) for an External Attack Surface Module (EASM), seeking to identify potential software solutions in the cybersecurity domain. This solicitation targets software publishers with capabilities in developing comprehensive attack surface management tools, with a specific focus on external digital security monitoring. The RFI was posted on February 12, 2025, with responses due by February 25, 2025, indicating a relatively short response window for interested vendors. The procurement falls under the NAICS category 513210 for Software Publishers and the PSC category 7A21 for IT and Telecom Business Application Software. The agency appears to be seeking a perpetual license software solution that can provide advanced external threat detection and vulnerability assessment capabilities.
The solicitation does not indicate a specific set-aside designation, suggesting the opportunity is open to a broad range of potential contractors. No incumbent contractor information is explicitly provided in the notice. While specific award values or budget ranges are not detailed, the procurement suggests a sophisticated cybersecurity software solution targeting enterprise-level attack surface management. The contract is classified as a civilian agency procurement, implying the software will be used within SSA's internal IT infrastructure. The technical requirements likely include comprehensive scanning, risk assessment, and continuous monitoring capabilities for external digital assets. Vendors interested in responding should carefully review the full RFI documentation and prepare detailed technical proposals that demonstrate their solution's ability to meet the SSA's complex cybersecurity needs.
28321325RI0000021 Social Security Administration
Solicitation 1/1
2/12/25, 3:53 PM CONFERENCE REGISTRATION SYSTEM
The National Institute of Standards and Technology (NIST) is conducting a sources sought notice for a Software-as-a-Service (SaaS) browser-based Conference Registration System. The agency seeks a commercial-off-the-shelf (COTS) or custom developed solution that can efficiently manage event registration, payments, attendee tracking, and integrate with existing NIST systems while meeting federal security requirements. Key contract requirements include robust registration and payment processing capabilities, attendee management features, system integration, communication tools, and multi-tier administrative access. The system must comply with federal IT security standards, including obtaining an Assessment and Authorization (A&A) at the moderate FISMA level or FedRAMP certification. Respondents must submit a capabilities statement, narrative evidence of system capabilities, a product portal URL, previous experience description, and other supporting documentation by March 6, 2025, with responses limited to 15 pages.
This sources sought notice is set aside for small businesses, specifically targeting 8(a), service-disabled veteran-owned, HUBZone, small disadvantaged, and women-owned small businesses under NAICS code 513210 with a size standard of $47.0M. While no specific award value is mentioned, the system must support unlimited events, registrations, and licenses without additional per-event costs. Critical technical requirements include two-factor authentication compatible with Personal Identity Verification (PIV) cards, Section 508 compliance, PAY.GOV payment integration, and the ability to handle personally identifiable information (PII) securely. Respondents must demonstrate current System for Award Management (SAM) registration and provide evidence of federal security authorizations. The notice emphasizes that this is a market research effort and does not guarantee a contract award, with NIST reserving the right to use the submitted information for planning purposes.
NIST-PAO-25-SS01 Department of Commerce National Institute of Standards and Technology
Pre-Solicitation 1/1
2/20/25, 11:41 AM USDA-ITSD-NIFA - CuadraSTAR - Software License & Maintenance Support Renewal
The U.S. Department of Agriculture's National Institute of Food and Agriculture (NIFA) is seeking to renew its Cuadra STAR software licenses and maintenance support through a sole source procurement with Cuadra Associates, Inc. The contract involves a text management and information retrieval system with database management capabilities, requiring a 20-user license for software maintenance, upgrade services, and technical support. The procurement will utilize Federal Acquisition Regulation (FAR) 13.106-1(b)(1)(i), which allows sole source contracting when only one source is reasonably available. Vendors interested in challenging the sole source determination must submit substantiating documentation within five calendar days of the notice's publication, specifically by January 2, 2025. The government will evaluate any responses to determine whether to open the procurement to competitive bidding, though they retain full discretion in this decision.
The contract opportunity is set aside for total small business participation under NAICS code 513210 (Software Publishers) and Product Service Code 7A21 for business application software. The base period of performance is scheduled from February 1, 2025, through January 31, 2026, with an anticipated award date of January 26, 2025. Cuadra Associates is positioned as the sole source provider due to being the original equipment manufacturer with proprietary rights to the STAR software. Market research conducted through SAM.gov, GSA MAS, and NASA SEWP confirmed no alternative vendors can provide the required software capabilities. The procurement involves a comprehensive software license renewal that includes database definition management, global change functions, web-based interfaces, and technical support services for the USDA's information management needs.
1232SA25Q0011 Department of Agriculture Agricultural Research Service
Pre-Solicitation 2/2
12/27/24, 11:58 AM Joint Enterprise License Agreement (JELA) to fulfill a requirement for Palo Alto Products and Services
The Defense Information Systems Agency (DISA) is seeking sources for a new Joint Enterprise License Agreement (JELA) to fulfill a requirement for Palo Alto Products and Services.
CONTRACTING OFFICE ADDRESS:
DISA/Defense Information Technology Contracting Organization (DITCO)
2300 East Drive, Building 3600
Scott AFB, IL 62225-5406
INTRODUCTION:
This is a SOURCES SOUGHT NOTICE to determine the availability and technical capability of small and large businesses (including the following subsets: Small Disadvantaged Businesses, Certified 8(a), Service-Disabled Veteran-Owned Small Businesses, HUBZone Small Businesses and Woman-Owned Small Businesses) to provide the required products and/or services.
On January 24, 2022, the Government awarded an Other Transaction Authority (OTA) contracting vehicle for the Thunderdome Zero Trust Solution to Booz Allen Hamilton, Inc.
The objective of the OTA was to implement key Zero Trust concepts on an existing network. Specifically, the Government intended to design, develop, and demonstrate the operational utility of Secure Access Service Edge (SASE) and Customer Edge Security Stacks at the Defense Information System Network customer points of presence, along with scalable Application Security Stacks deployed in front of one or more application workloads.
DISA announced a successful completion of the Thunderdome Prototype OTA, a zero-trust security model that leverages commercial technologies. DISA's Thunderdome prototype successfully proved that commercial technologies could improve both security and network performance in an existing enterprise environment. DISA’s Thunderdome solution provides a comprehensive Zero Trust Architecture with several integrated, but distinct components whose independent adoption will drive growth uniquely across the solution. The licenses required to deploy and operate DISA’s Thunderdome solution are largely the same for the Non-classified Internet Protocol (IP) Router Network (NIPRNet) and Secure Internet Protocol Router Network (SIPRNet) implementations. Both implementations will have the same solution components and therefore the same licensing requirements, though each will have unique scale and growth patterns. SASE licensing will only be applicable to the NIPRNet implementation.
The DISA JELA Program Management Office is seeking information from potential sources for Palo Alto Products and Services. The specific area of focus are the resources that offer commercial licenses in the functional areas of Public/Private/Hybrid Cloud Security, Container Security, Secure Remote Access, Internet Landscape Intelligence, and Security Operations Center (SOC) Operational Tools. These products must be able to integrate into the existing infrastructure. The information gathered will be in support of the development of a Department of Defense (DoD) JELA. The DoD-wide JELA is a contracting vehicle that will be used to procure the required products in support of the functional areas stated above.
The anticipated Period of Performance is January 29, 2024 – January 29, 2029
The anticipated Place of Performance is the Continental United States (CONUS) and outside the (CONUS)
DISCLAIMER:
THIS SOURCES SOUGHT ANNOUNCEMENT IS FOR INFORMATIONAL PURPOSES ONLY. THIS IS NOT A REQUEST FOR PROPOSAL. IT DOES NOT CONSTITUTE A SOLICITATION AND SHALL NOT BE CONSTRUED AS A COMMITMENT BY THE GOVERNMENT. RESPONSES IN ANY FORM ARE NOT OFFERS AND THE GOVERNMENT IS UNDER NO OBLIGATION TO AWARD A CONTRACT AS A RESULT OF THIS ANNOUNCEMENT. NO FUNDS ARE AVAILABLE TO PAY FOR PREPARATION OF RESPONSES TO THIS ANNOUNCEMENT. ANY INFORMATION SUBMITTED BY RESPONDENTS TO THIS SOURCES SOUGHT ANNOUNCEMENT IS STRICTLY VOLUNTARY.
CONTRACT/PROGRAM BACKGROUND: N/A
REQUIRED CAPABILITIES:
The DoD has a need for a license agreement that can support the implementation of a zero-trust approach that can integrate within the existing infrastructure to outpace cyberthreats. This effort will provide DoD with access to numerous products and services that will provide an offering to meet our core defensive cyber operations capabilities. The DoD further requires the Palo Alto Software-as-a-Service (SaaS) solution that has a minimum of DoD Impact Level 5 (IL5) certification as defined within the DoD’s Cloud Security Requirement Guide (SRG).
Once implemented DoD Agencies and Military Departments (MILDEPs) (all of the MILDEPS and agencies will be known as “Agencies” in the remainder of the document) will potentially utilize the same toolset reducing redundancy, lowering tool costs, and enabling the organization to operate more effectively. This will enable the Agencies to leverage the various products that are prevalent within the DoD directed by policies, organized, and structured in processes, and supporting procedures towards the goal to design, plan, deliver, operate, and control Information Technology.
Describe and provide an example of your company’s experience supporting the three areas of requirements below utilizing the products and services listed in Attachment 1.
Tab 1. A comprehensive suite of security services to effectively predict, prevent, detect, and automatically respond to security and compliance risks without creating friction for users, developers, and security and network administrators.
Tab 2. Software firewalls protect private and public cloud deployments with segmentation and threat prevention, secure Kubernetes environments, and protect deployments with network security delivered as a managed cloud service.
Tab 3. A portfolio of services to assist with the implementation of next-generation firewall for prevention and detection of cyber threats to millions of customers globally by offering a comprehensive portfolio with visibility, trusted intelligence, automation, and flexibility to help organizations advance securely across clouds, networks, and mobile devices with a modernized, future-proof security framework and can integrate within a network. Remote IT asset management must be provided to facilitate recording, tracking, and monitoring assets covered under this agreement.
Additionally, please describe and provide an example of tracking all software licenses via an asset management tool.
SPECIAL REQUIREMENTS
Must be able to provide a Palo Alto SaaS solution that has a minimum requirement of DoD IL5 certification as defined within the DoD’s Cloud SRG.
Must have Top Secret Facility Clearance. Provide your current Facility Clearance level.
SOURCES SOUGHT:
The North American Industry Classification System Code (NAICS) for this requirement is 513210 with the corresponding size standard of $47M.
In order to make a determination for a small business set-aside, two or more qualified and capable small businesses must submit responses that demonstrate their qualifications. Responses must demonstrate the company’s ability to perform in accordance with the Limitations on Subcontracting clause (FAR 52.219-14).
To assist DISA in deciding the level of participation by small business in any subsequent procurement that may result from this Sources Sought, you are also encouraged to provide information regarding your plans to use joint venturing (JV) or partnering. Please outline the company's areas of expertise and those of any proposed JV/partner who combined can meet the specific requirements contained in this notice.
SUBMISSION DETAILS:
Responses should include:
Business name and address.
Name of company representative and their business title.
Type of Small Business.
CAGE Code.
Prime contract vehicles; to include ENCORE III, SETI, NIH CIO-SP4, NASA SEWP V, General Service Administration (GSA): OASIS, ALLIANT II, VETS II, STARS III, MAS (including applicable SIN(s), groups, or pools), or any other Government Agency contract vehicle that allows for decentralized ordering. (This information is for market research only and businesses with a valid cage that lack prime contract vehicles are still encouraged to respond to this notice.)
Businesses who wish to respond must send responses via email NLT 9:00 AM Eastern Daylight Time (EDT) on June 26, 2023 to carmelynanne.bryan.civ@mail.mil and carene.v.simon.civ@mail.mil. Interested businesses should submit a brief capabilities statement package addressing the specific questions (no more than five pages) and demonstrating ability to perform the services listed under Required Capabilities.
Proprietary information and trade secrets, if any, must be clearly marked on all materials. All information received that is marked Proprietary will be handled accordingly. Please be advised that all submissions become Government property and will not be returned. All government and contractor personnel reviewing submitted responses will have signed non-disclosure agreements and understand their responsibility for proper use and protection from unauthorized disclosure of proprietary information as described 41 USC 423. The Government shall not be held liable for any damages incurred if proprietary information is not properly identified.
842366609 Defense Information Systems Agency
Pre-Solicitation 1/1
6/12/23, 8:23 AM GENGS VBS Software
The Department of the Army Materiel Command Contracting Command Redstone Arsenal (ACC Redstone) has published a Special Notice for a sole source acquisition of GENGS VBS4 software and associated licenses. This is being done in accordance with Federal Acquisition Regulation (FAR) 6.302-1, as the Government has determined that the VBS4 and VBS Blue Image Generator products provide the best feature set to meet the simulator requirements for the Technology Development Directorate of the Combat Capabilities Development Command, Aviation and Missile Center.
The purpose of this Special Notice is to inform interested parties of the Government's intent to award a sole source contract to Bohemia Interactive Simulations for the required VBS4 software and licenses, with an estimated value of $232,974. Interested parties may submit capability statements, proposals, or quotations within 7 days of the publication of this notice, which the Government will consider. However, this is not a request for competitive quotes, and the decision to compete the proposed contract is at the sole discretion of the Government. The required hardware and software components, as well as the need for an Embedded Trainer to support a Gray Eagle simulation, are also outlined in the accompanying Purchase Description.
W9124P24Q7872 Department of the Army Materiel Command Contracting Command Redstone Arsenal
Special Notice 1/1
7/10/24, 10:18 AM