RFI Revised - CISA IDIQ_02-28-2025 .pdf
PDF 379 KB Posted
- Attached to
- CISA Indefinite Delivery Indefinite Quantity Contract Federal contract opportunity
- Solicitation number
- 47QFRA25K0003
About this file
This is a Request for Information (RFI) issued by GSA Federal Acquisition Service (FAS) Assisted Acquisition Services (AAS) on behalf of the Cybersecurity and Infrastructure Security Agency (CISA) to conduct market research for a potential multiple-award IDIQ contract valued at $18-20 billion over a 10-year period (5-year base with 5-year option). The RFI seeks industry input on two areas: (1) the potential acquisition structure for functional alignment of DEFEND requirements and (2) feedback on Cyber Training requirements.
The proposed IDIQ would encompass five Service Areas: (1) Cyber/IT Project Management Support, (2) Requirements Management, (3) Capability Implementation, (4) Operations, Sustainment and Ancillary Support, and (5) Solution Development, plus one Product Area for cybersecurity products and tools. Initial task orders are expected to include Requirements and Implementation Roadmap Management for CDM, Strategic Cybersecurity Acquisition and Buying Support, and various implementation task orders for IDAM, EDR, mobile, cloud services, and IoT. Responses are due by 11 a.m. ET on March 7, 2025. The government is using NAICS code 541512 (Computer Systems Design) and anticipates SA5 and PA1 having potential for direct small business participation. Respondents must complete corporate overview information, prior experience examples, and address specific questions about capabilities and approach within a 19-page limit.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Question and Answer Document 02-28-2025.pdf | ||
| Attachment 1 - CISA IDIQ - PWS as of 2-13-2025.pdf | ||
| Attachment 2 - RFI for Cyber Training Program 02-13-2025.pdf | ||
| Attachment 3 - Capacity Building Training Program Capabilities and Requirements.pdf | ||
| RFI - CISA IDIQ_47QFRA25K0003_02-13-2025 .pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
GENERAL SERVICES ADMINISTRATION (GSA)
ASSISTED ACQUISITION SERVICES (AAS) REQUEST FOR INFORMATION (RFI)
I. Introduction
General Services Administration (GSA) Federal Acquisition Service (FAS) Assisted Acquisition Services (AAS) is releasing this Request for Information (RFI) on behalf of Cybersecurity and Infrastructure Security Agency (CISA). The purpose of this RFI is to assist the Government in conducting market research and receiving information and valuable input from industry. The information will be multi-focused and two fold for (1) the potential acquisition structure provided in this RFI (see Attachment 1) for a multiple award vehicle highlighted in this introduction for the functional alignment of the DEFEND requirements as covered in the 2024 industry day and (2) feedback distinctly for the Cyber Training requirement which could be included as part of the multiple award vehicle (see Attachment 2 and 3). The acquisition structure would include scope for the RFIs currently identified as “Deployment Services (DS)” (47QFRA23K0012) and potentially “Strategic Cybersecurity Acquisition and Buying Services (SCABS)” (47QFRA24K0005) and Operational Services discussed during the 2024 Industry Day. Additionally, this RFI will assist the Government in conducting market research focused on identifying industry partners that have the ability to meet the objectives in the attached updated draft requirement. That is, the objectives and tasking associated with the draft IDIQ PWS (see Attachment 1) and the attached Training RFI (see Attachment 2) and Cyber Training Draft Requirements Document (see Attachment 3). This information will be used for market research only. The Government is not obligated to release a future solicitation.
This RFI does NOT constitute a Request for Proposal and is not to be construed as a commitment, implied or otherwise, by the Government that a procurement action will be issued.
Response to this notice is not a request to be added to a bidders list or to receive a copy of a solicitation. No entitlement to payment of direct or indirect costs or charges by the Government will arise as a result of the submission of the requested information. No reimbursement will be made for any costs associated with providing information in response to this announcement and any follow up information requests. Responses to this RFI may be considered in the future determination of an appropriate acquisition strategy for the program. The Government may not respond to any specific questions or comments submitted in response to this RFI or information provided as a result of this request. Any information submitted by respondents as a result of this notice is strictly voluntary.
II. Background
The Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is the Nation’s risk advisor, working with partners to defend against today’s threats and collaborating to build more secure and resilient infrastructure for the future. In this role, CISA builds the Nation’s capacity to defend against cyber-attacks. Through a variety of large-scale programs, the Agency works to provide cybersecurity tools, incident response capabilities, and assessment services to safeguard the Federal Civilian Executive Branch (FCEB) ‘.gov’ systems and systems that support national critical functions. Critical Infrastructure Sectors | CISA
In 2QFY24, the government hosted an industry day where CISA/Capacity Building (CB) outlined its intent to transition its existing Dashboard and DEFEND Task Orders to more functionally aligned contracts. These functions included but were not limited to capability deployment, operations and operational services, solutions development and cybersecurity commercial tool buying. Following the industry day, the government released an RFI for Deployment Services associated with the implementation and deployment of technologies and solutions. After reviewing RFI responses and internally analyzing various approaches to accommodate all government objectives, CISA and GSA are exploring the feasibility and potential of a Capacity Building Indefinite Delivery/Indefinite Quantity (IDIQ) or other multiple award strategy. The intent is for programs, like CDM, to leverage the broad service areas associated with the vehicle to satisfy dynamic needs of CISA and the FCEB.
III. Functional Areas
Objectives:
The government anticipates the Contractor to support increases in organizational capacity, improvements in IT flexibility, and an overall reduction of redundant infrastructure and commodity services, while strengthening the overall security of participating organization’s environments. Solutions must meet the needs of the stakeholders and, as applicable, align with all CISA/CB’s programmatic goals.
Implementations shall be scalable and rooted in enterprise-wide collaboration, accountability and transparency. Technical planning, development and operational support services must align with organizational strategies and objectives. In all cases, participating contractors will be required to provide expert guidance and high-level support services to account for security policy compliance and awareness of security threats.
Participating Contractors will help set customer expectations and shall respond to the needs of customers with agile, flexible, service delivery, meeting or exceeding established standards of timeliness and responsiveness with cost-effective solutions. The customer experience and relevant customer inputs in the design, development, and roll out of any new product, service, or business process is a critical tenet in all engagements.
This approach also aims to implement an efficient procurement management process with the https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors capability to support a significant cyber software (SW) procurement footprint. Specifically, if deemed appropriate, the IDIQ aims at resolving a number of challenges associated with IT/Cyber procurements at this scale, such as:
● Shelfware – CDM structured enterprise agreements provide advantageous pricing, but often lack in flexibility that lead to “shelfware” as agencies continually evolve and are not always ready to deploy the tools once available despite saying otherwise.
● Transferability – Agencies often require different product sets or a variety of SKUs even within a product family. When attempting to mitigate shelfware, CISA often looks to promote transferability among participating Agencies to maximize their investments. This is often met with resistance from the Original Equipment Manufacturers (i.e., OEMs or product manufacturers).
● Outyear Pricing – While OEMs and Value Add Resellers help Capacity Building achieve significant cost savings at the initial transaction, outyear price escalation and/or product and SKU re-packaging erodes (or even washes out) discount percentages.
● Disjointed buying approaches – Large federated organizations are often not aligned when executing SW and cyber tool transactions. Components within an Agency frequently make just in time procurements to meet a narrow need or to fill a license renewal gap. These are often not aligned to more strategic procurements made by large scale Agency programs which would benefit from sequencing and tracking these targeted just in time buys.
Structure:
The potential approach outlined below will encompass a substantial part of the Cybersecurity and Information and Communications Technology (ICT) acquisition by and for CB and the broader Agency. This approach would offer support across five (5) Service Areas (SA):
● SA 1: Cyber/IT Project Management Support
● SA 2: Requirements Management
● SA 3: Capability Implementation
● SA 4: Operations, Sustainment and Ancillary Support
● SA 5: Solution Development
This potential multiple award strategy could also include a Product Area (PA) with access to cybersecurity and IT product areas for procurement (hardware (HW), SW, cloud infrastructure, security tools, etc.)
● PA 1: Cybersecurity Products and Tools
Each of these areas represents a general category of services or cyber product/tool aligned to capabilities. This structure is provided to broadly define the scope of potential service areas where Task Orders may be issued under this approach (See Attachment 1 – Draft PWS). This approach will include a flexible ordering mechanism that any entity within CB and the broader agency or their FCEB partners may use to create a customized Task Order to fulfill their requirements, regardless of the area in which those requirements are grouped in the overarching Scope of Work.
SA 1 scope focuses directly on the management of individual Task Order contractual activities and the overarching project objectives of specific engagements. There will also be general administrative management tasking.
SA 2 scope focuses on assisting Government project and program management offices in managing the execution of CB capability implementations at FCEB partner organizations. This will require a comprehensive requirements management process that analyzes and prioritizes department and Agency requests with CB program objectives and available resources.
SA 3 scope focuses on capability implementations for CDM and other large-scale programs. This includes conducting technical planning for implementations and direct support to Federal Departments and Agencies to configure, deploy and test technologies and solutions.
SA 4 scope focuses on operations, cyber program operational services, sustainment and consultative services. This includes O&S services for solutions deployed as part of this strategy and existing systems or solutions operating in the Federal enterprise. SA 4 also includes consultative procurement support to Capacity Building to enable Cyber technology logistics and purchasing.
SA 5 scope is focused on solution and SW development services. This area includes SecDevOps.
PA 1 is solely focused on offering categorical cybersecurity products, SW and tools associated with broad technology and capability areas. This PA is intended to serve as a strict procurement sleeve enabling organizations to fill product/tool gaps or to supplement various SA task orders.
The Government is still deliberating on specific Contractor Pool alignment for the SA/PAs. The Government anticipates that the contractor pool for SA5 and PA1 could encompass direct small business participation.
Potential initial Task Orders:
- Requirements and Implementation roadmap Management for CDM
- Strategic Cybersecurity Acquisition and Buying Support
- Implementation Task Orders for:
o Identity and Access Management (IDAM) o Endpoint Detection and Response (EDR) o Mobile implementation and configuration o Cloud Services and Cloud Management o Internet of Things (IoT)
- Cybersecurity Training Program Support Services
IV. Government Estimate The Government currently estimates the total amount of this requirement to be in the range of $18-20 Billion over a ten-year period (five-year base ordering period and a five-year optional ordering period) including all potential orders.
V. Questionnaires
RFI Response Content:
Complete the questionnaire as outlined below:
a. All responses must be submitted electronically by email only to David Shamburger at david.shamburger@gsa.gov, Emily Rankin at emily.rankin@gsa.gov, Aaron Maddox at aaron.maddox@gsa.gov and Diana Zoppi at diana.zoppi@gsa.gov. Use the attached questionnaire to provide the requested information.
b. All responses shall maintain one-inch margins, 12-point Times New Roman font, and are single spaced. Smaller font is allowed for tables.
c. Table 1: Corporate Overview shall be no longer than 2 pages in length. Please indicate what service/product area/s your company is interested in. Also distinctly indicate interest in the attached Training RFI as one of the potential initial orders.
d. Table 2: Prior and Current Corporate Experience shall be no longer than 6 pages in length (2 pages for each example of Corporate Experience). Corporate Experience should be performed by the respondent as a Prime Contractor. If submitting Corporate Experience as a subcontractor, please provide additional information to give the Government confidence on the ability to perform as a prime for this requirement. Do not resubmit corporate experience if you already provided it as part of the RFIs referenced above.
Corporate Experience can be given for the main requirement areas (Attachment 1) or the Training requirements (Attachment 2 and 3) or a mix of both but is limited to 3 overall.
e. Corporate Capabilities and Approaches shall be no longer than 3 pages and is further limited below.
f. Government RFI question responses shall be no longer than 5 pages.
g. Responses to the Training RFI (Attachment 2) shall be no longer than 3 pages be sure to include answers to questions specific to the Training RFI.
h. All information submitted shall be UNCLASSIFIED.
i. Responses shall be submitted no later than 11 a.m. Eastern Time on March 7, 2025.
j. Send questions to the POCs listed above.
To provide clarity for the page limits above, bullet c - 2 pages, bullet d - 6 pages, bullet e - 3 pages, bullet f - 5 pages, bullet g - 3 pages. Total pages allowed maximum: 19 pages.
mailto:david.shamburger@gsa.gov mailto:emily.rankin@gsa.gov mailto:aaron.maddox@gsa.gov mailto:diana.zoppi@gsa.gov
RFI Response Questions:
1. Please provide feedback on the attached requirement document (Attachment 1) and the different areas that are contained within it. Please indicate whether you have responded to previously posted RFIs referenced above for DS or SCABS. Even if you have responded previously, please still fill out the Corporate Overview from Table 1 below. If you have responded previously and provided sufficient Corporate Experience and Capability related to these requirements no response is necessary for Table 2 and Corporate Capabilities and Approaches. If you have additional information that you need to provide since that response, please provide an updated response for Table 2 and Corporate Capabilities and Approaches.
2. The Government is using the primary NAICS code of 541512 Computer Systems Design.
What other NAICS codes would be good to include for these requirements?
3. Please provide feedback on the approach provided in this RFI. Be specific and detail any pros, cons or any challenges and benefits that are anticipated.
4. Would integrated or combined SA pools be achievable or would the Government benefit from expertise distinct to any service areas?
5. The government requires direct procurement consulting support (i.e., what was previously referred to as SCABS). This scope is included in Service Area 4. Is this an optimal approach from an efficiency and/or business perspective? That is, should SCABS services be its own Service Area and target a certain segment of industry?
6. What labor categories or work roles would align best to the Service Areas?
7. From your experience under other vehicles, what aspects of ordering procedures are beneficial and/or provide details of any challenges that have been experienced in participation on multiple award vehicles?
8. Based on the nature of the work and the supported agencies, the Government anticipates non-commercial aspects of these requirements. Please weigh in on the challenges surrounding commercial services in different requirement areas and where commercial services or products would be appropriate or possible.
9. The Government considers SA 5 and PA 1 to have potential for direct small business support.
Any small business response to SA 1 - 4 is requested to help shape the Government approach, any responses should take into account the magnitude and staffing challenges of these requirements. Any small businesses that have interest in SA 1 - 4 should provide substantial detail that would give confidence to the Government in the ability to support those requirements. An additional 2 pages are provided to small businesses to provide this detail for SA 1 - 4.
10. Would additional industry engagement be helpful and would you be interested in participating in an industry day or due diligence sessions?
Table 1: Corporate Overview
Question Answer Name of Company Name of Business Unit Responding to the RFI (if applicable)
DUNS Number Commercial and Government Entity (CAGE) Code Corporate Address Total Number of Full Time Employees Website URL Indicate what Service/Product Area or Areas your company is interested in.
Small Business under North American Industry Classification System (NAICS) Code 541512 Computer Systems Design.
□ YES
□ NO
Type of Small Business, if applicable (e.g., Woman- Owned, Service-Disabled Veteran Owned, 8(a), HUBZone)
Do you have a cost accounting system deemed adequate by a cognizant audit agency? (e.g., Defense Contract Audit Agency (DCAA))
□ YES
□ NO
Do you have an approved Purchasing System? □ YES
□ NO
One Point of Contact (POC) (Enter name, phone number, and email address)
Name:
Phone #:
Email:
Please identify which, if any, of the formal accreditations or certifications listed below are held by your firm (do not include any self-certifications):
International Organization for Standardization (ISO) 9001 Quality Management System (QMS)
□ YES
□ NO
ISO 20000-1 Information technology Service Management System (ITSMS)
□ YES
□ NO
ISO/International Electrotechnical Commission (IEC) 27001 Information Security Management Systems (ISMS)
□ YES
□ NO
Other, please specify □ How does your company integrate commercially available offerings to meet the needs of the stated mission requirements?
Table 2: Prior and Current Corporate Experience Please respond to the following inquiries (Note: If your company is divided into separate business units, responses shall be based upon the Corporate Experience of the business unit responding to the RFI):
Please complete the following table for prior Corporate Experiences performed in the last five years in which the contractor (ideally serving as prime contractor) provided or currently provides services similar in size, complexity, and scope to the stated requirements and technical environment as listed in Sections III and IV. Use individual task order values for the table below, not the overall Indefinite Delivery Indefinite Quantity (IDIQ) or Blanket Purchase Agreement (BPA) ceiling value the task order may have been awarded from.
Question Answer Contract Vehicle/Contract Number Contract/Project Name Value at Award Value at Completion/Current Value
Contract Type: check the type that represents the largest ($) for this contract
□ Time-and-Materials (T&M)/Labor-Hour (LH)
□ Firm-Fixed-Price (FFP)
□ Cost-Plus-Incentive-Fee (CPIF)
□ Cost-Plus-Award-Fee (CPAF)
Client Department or Agency Project Description Client POC, Name, E-mail, Phone Percentage of Services Sub-contracted
Number of Users Average Monthly Service Contact Volume
Amount of Tools/Other Direct Costs (ODCs) Procured for Life of Task Order
Corporate Capabilities and Approaches
a. Describe your corporate capabilities as they relate to the holistic and integrated
Functional Areas listed above. Please include which contract types these experiences were with (limited to 1 page).
b. Describe your company/business unit’s experience, if any, with providing innovative solutions in terms of technology, process, or automation to drive operational service delivery efficiencies (cost and performance) without disrupting current operations, leveraging investment through savings in automation, and integrated delivery (limited to 1 page).
c. Describe your company/business unit’s capability, experience, and methodology for properly staffing with the same size, scope, and complexity as referenced in Section II above. Additionally, please provide the methodology used to provide cleared personnel so as not to burden cleared Government and contractor resources with escort duty (limited to 1 page).
| I. Introduction |
| II. Background |
| III. Functional Areas |
| IV. Government Estimate |
| V. Questionnaires |
| Table 2: Prior and Current Corporate Experience |
| Corporate Capabilities and Approaches |
File details come from the government source that posted it. Updated .