Sources Sought Notice FOHC102822F0929.docx
DOCX document 58 KB Posted
- Attached to
- Cybersecurity Management Services Federal contract opportunity
- Solicitation number
- 832573449
- Issued by
- Defense Information Systems Agency
About this file
This Sources Sought Notice is issued by the Defense Information Systems Agency (DISA) to identify small businesses capable of providing Cybersecurity Management Services for the J-9 Hosting and Compute (J-9 HaC) Cybersecurity Division. The anticipated contract is a firm-fixed price, one-year base contract with three one-year option periods, beginning October 1, 2026, with performance locations in Oklahoma City, OK; Mechanicsburg, PA; Montgomery, AL; San Antonio, TX; and Ogden, UT. The current incumbent is Cinteot, Inc., a small business.
The contract requires comprehensive cybersecurity capabilities, including vulnerability scanning, threat detection and monitoring, security compliance support for DoD Risk Management Framework (RMF) and FISMA, incident response, and network defense. Eligible businesses must be small businesses (including Small Disadvantaged Businesses, 8(a), Service-Disabled Veteran-Owned, HUBZone, and Woman-Owned Small Businesses) with experience in cybersecurity across classified and unclassified networks. Respondents must have a Secret facility clearance and submit a five-page capabilities statement by September 24, 2025, to specified DISA email contacts. The NAICS code is 541512 with a $34M size standard.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 832573449 Recompete FO HC102822F0929_CLEAN.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOURCES SOUGHT NOTICE
832573449
The Defense Information Systems Agency (DISA) is seeking sources for Cybersecurity Management Services, an acquisition for J-9 Hosting and Compute (J-9 HaC) Cybersecurity Division.
CONTRACTING OFFICE ADDRESS: DISA/ Defense Information Technology Contracting Organization (DITCO) - Scott, 2300 East Drive, Scott Air Force Base, Illinois, 62225-5406
INTRODUCTION:
This is a SOURCES SOUGHT NOTICE to determine the availability and technical capability of small businesses (include the following subsets, Small Disadvantaged Businesses, Certified 8(a), Service-Disabled Veteran-Owned Small Businesses, Historically Underutilized Business Zone Small Businesses (HUBZone), and Woman Owned Small Businesses (WOSB)) to provide the required products and/or services.
The J-9 HaC Cybersecurity Division oversees the security posture of all information technology (IT) assets that receive, process, store, display, or transmit Department of Defense (DoD) information that is managed by J-9 HaC. This IT will be acquired, configured, operated, maintained, and disposed of consistent with applicable DoD cybersecurity policies, standards, and architectures. These programs include program services, network program services, mission partner engagement, internal program services, Defense Information Systems Network programs, and communication security.
The DISA Cybersecurity Division is seeking information for potential sources to support Cybersecurity Management Services, which includes training; audits; review, creation, and execution of policies, orders, and guidance; vulnerability scanning, detection, and analysis; compliance monitoring, reporting, and mitigation; and cybersecurity systems management and automation configuration, change, and account management for J-9 HaC managed information systems.
The anticipated period of performance is a one-year base with three one-year option periods beginning October 1, 2026.
The anticipated places of performance are Oklahoma City, OK; Mechanicsburg, PA; Montgomery, AL; San Antonio, TX; and Ogden, UT.
DISCLAIMER:
THIS SOURCES SOUGHT NOTICE IS FOR INFORMATIONAL PURPOSES ONLY. THIS IS NOT A REQUEST FOR PROPOSAL. IT DOES NOT CONSTITUTE A SOLICITATION AND SHALL NOT BE CONSTRUED AS A COMMITMENT BY THE GOVERNMENT. RESPONSES IN ANY FORM ARE NOT OFFERS AND THE GOVERNMENT IS UNDER NO OBLIGATION TO AWARD A CONTRACT AS A RESULT OF THIS NOTICE. NO FUNDS ARE AVAILABLE TO PAY FOR PREPARATION OF RESPONSES TO THIS NOTICE. ANY INFORMATION SUBMITTED BY RESPONDENTS IS STRICTLY VOLUNTARY.
CONTRACT/PROGRAM BACKGROUND:
Contract Number: 47QTCA18D00K3 / HC102822F0929 Contract Type: Firm-Fixed Price Incumbent and their size: Cinteot, Inc. – Small Business Method of previous acquisition: HUBZone Set Aside on General Services Administration Multiple Award Schedule (formerly IT Schedule 70) Period of performance: One-year base and three one-year options (October 1, 2022- September 30, 2026)
The cybersecurity services include application administration, support for Commercial-Off-The-Shelf and Government-Off-The-Shelf tools, incident response, network defense, security posture validation, and vulnerability analysis. Work accomplished under this task order includes cybersecurity support in Non-classified Internet Protocol Router Network, Secret Internet Protocol Router Network, and isolated environments.
REQUIRED CAPABILITIES:
1) J-9 HaC Cybersecurity Division supports endpoint management and vulnerability analysis and protections, scans, remediation and automation support. Please describe your experience in supporting cybersecurity vulnerability scanning & detection, maintaining operational security, and supporting DoD audits, for both unclassified and classified networks in accordance with DoD regulations, guidelines, and orders. (SOW Reference Section 6; Task Areas 1 and 2).
2) J-9 HaC Cybersecurity Division provide automation and monitoring, analyzing, and reporting security threats both internally and externally to protect our IT environments from threats or security incidents and remediate any discrepancies that are found through the proper DoD guidance and regulations. Please describe your experience monitoring, analyzing, reporting, and improving cyber security posture throughout the entire lifecycle of managed information systems with all available tools/cyber systems. This includes ensuring insider/external threats and incidents are appropriately detected, monitored, and remediated per DoD Guidance and regulations. (SOW Reference Section 6; Task Areas 1 and 9).
3) J-9 HaC Cybersecurity Division continually monitor each IT environment through DISA approved scanning and vulnerability tools to monitor, analyze, evaluate and report any deficiencies across all applications, databases, operating systems and other network platforms to assist in the cybersecurity compliance. J-9 HaC Cybersecurity Division supports developing, analyzing, maintaining, monitoring and reporting security compliance to support DoD Risk Management Framework (RMF) and Federal Information Security Management Act (FISMA) requirements. Please describe your experience and ability in developing and utilizing/managing cyber systems to include: tools, applications, databases, and other software/network platforms; developing, analyzing, maintaining, monitoring and completing RMF and FISMA requirements. (SOW Reference Section 6; Task Area 3).
4) J-9 HaC Cybersecurity Division supports, reviews, and submits recommendations for improvements in efficiencies and effectiveness for cybersecurity activities, processes, and documentation. J-9 HaC Cybersecurity Division team members also obtain the appropriate DoD-approved 8140 certifications. Please describe your experience in providing a comprehensive management approach for the appropriate mix of skilled/qualified labor categories, hours/schedules/shifts, and certifications (i.e. DoDD 8140.01). (SOW Reference Section 6; Task Area 9).
SPECIAL REQUIREMENTS
Final Secret Clearance required for personnel.
Facility Clearance Required: Secret Clearance. Within your response, please state your current facility clearance level.
SOURCES SOUGHT:
The North American Industry Classification System Code (NAICS) for this requirement is 541512, with the corresponding size standard of $34M.
In order to make a determination for a small business set-aside, two or more qualified and capable small businesses must submit responses that demonstrate their qualifications. Responses must demonstrate the company’s ability to perform in accordance with FAR clause 52.219-14, Limitations on Subcontracting.
To assist DISA in determining the level of participation by small business in any subsequent procurement that may result from this Sources Sought Notice, provide information regarding any plans to use joint ventures (JVs) or partnering. Please outline the company's areas of expertise and those of any proposed JV/partner who combined can meet the specific requirements contained in this notice.
SUBMISSION DETAILS:
Responses should include:
1) Business name and address;
2) Name of company representative and their business title;
3) Small Business Socio-economic status (if small);
4) CAGE Code;
5) Prime contract vehicles; to include ENCORE III, SETI, NIH CIO-SP4, NASA SEWP V, General Service Administration (GSA): OASIS, ALLIANT II, VETS II, STARS III, MAS (including applicable SIN(s), groups or pools), or any other Government Agency contract vehicle that allows for decentralized ordering. (This information is for market research only and businesses with a valid cage that lack prime contract vehicles are still encouraged to respond to this notice.)
Businesses who wish to respond must send a response via email NLT 2:00PM Central Time (CT) on September 24, 2025 to Ms. Carly A. Youngless at carly.a.youngless.civ@mail.mil and Mr. Kenric L. Phillips at kenric.l.phillips.civ@mail.mil. Interested businesses should submit a brief capabilities statement package addressing the specific questions above (no more than five pages) demonstrating the ability to perform the services listed under Required Capabilities.
Proprietary information and trade secrets, if any, must be clearly marked on all materials. All information received that is marked Proprietary will be handled accordingly. All submissions become Government property and will not be returned. All government and contractor personnel reviewing submitted responses will have signed non-disclosure agreements and understand their responsibility for proper use and protection from unauthorized disclosure of proprietary information as pursuant to 41 USC 423. The Government shall not be held liable for any damages incurred if proprietary information is not properly identified.
For information on DISA’s requirements, you can find current information on our home page: www.disa.mil – that includes current forecast and the current acquisition strategies. If there is no information regarding the requirement you may be inquiring about, then there is no additional publicly available information. Please continue to review www.disa.mil.
Page 2 of 4 Pages
File details come from the government source that posted it. Updated .