Atttch 1_SSN_Enterprise Cybersecurity Spt Srvs_DCSA_CYBERSSN_25.pdf

PDF 124 KB Posted

Attached to
DCSA Enterprise Cybersecurity Support Services Federal contract opportunity
Solicitation number
DCSA_CYBERSSN_25
Issued by
Defense Counterintelligence and Security Agency

About this file

This Sources Sought Notice is for the Defense Counterintelligence and Security Agency (DCSA) seeking Enterprise Cybersecurity Support Services from Certified 8(a) vendors. The contract requires comprehensive cybersecurity support across multiple functional areas, including Cyber Data Management, Cybersecurity Engineering, Cyber Compliance Support, Cyber Defense Operations, Cloud Security Engineering, and Project Management. The services will support up to 15,000 personnel and encompass information systems at all classification levels, involving tasks such as Assessment and Authorization, risk management, technical analysis, PKI support, cybersecurity compliance, publication support, and emergent technology integration.

Key requirements include maintaining IT infrastructure, supporting the Enterprise Data Management Program, establishing a Cybersecurity, Compliance and Risk Management program, supporting the Cyber Defense Operations Security Operations Center, and providing advanced technology support in areas like zero-trust networking, supply chain risk management, and AI-enabled security solutions. The Sources Sought Notice is specifically targeting Certified 8(a) vendors, with responses due by 5:00 PM EST on 20 May 2025, to be submitted via email to the Contract Specialist and Contracting Officer. This market research effort is preliminary and does not constitute a formal solicitation.

View the file

Other files for this federal contract opportunity

Other files attached to DCSA Enterprise Cybersecurity Support Services, newest first.
File Type Posted
PRIOR POST INFO - DCSA_CYBERSSN_25.pdf PDF
DCSA_CYBERSSN_25 QNAs.pdf PDF
SSN_Enterprise Cybersecurity Spt Srvs_DCSA_CYBERSSN_25.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sources Sought Notice Defense Counterintelligence and Security Agency

Enterprise Cybersecurity Support Services

ATTACHMENT 1 - TASKS

1. Basic Services: The Contractor shall provide Enterprise Cybersecurity Support Services for all systems operating at all classification levels and includes: Cyber Data Management, Cybersecurity Engineering, Cybersecurity Support, Cyber Compliance Support, Cyber Publication Services, Cyber Defense Operations, Cloud Security Engineering, System Lifecycle Risk Management – Change & Configuration Management, and Project/Program Management for the contract. These functional areas are applied providing support for Information Systems (IS) general enclaves, major applications, minor applications, cloud environments, and IT analyses of hardware and software products annually, overall supporting up to 15,000 personnel.

2. Information Systems Engineering (ISSE) Program Support: DCSA requires ISSE support in order to maintain IT infrastructure, applications, and any new development projects ensuring the security efficacy of networks. The Government will provide an established workflow in which the Contractor shall support in line with the deliverables and timeline.

As such, technical analysis, research, evaluation, and technical guidelines shall be performed in order to accomplish the below.

3. Cybersecurity Support Services of Major Programs: The Contractor shall provide cybersecurity support services to include Assessment and Authorization (A&A), cloud initiatives, risk management, product analysis, facility inspections/site assessments (locations hosting information systems, worksites for classified production or storage, support regional directorates as requested), circuit action support.

4. Cyber Compliance and Public Key Infrastructure (PKI) Support: The Contractor shall provide support for the PKI Program Management Office (PKI-PMO) that provides oversight to the agency’s PKI program, Data Transfer Program, and Media Destruction Program.

5. Cyber Compliance Support Services IAW DoD 8570.01-M/8140: The Contractor shall support all cybersecurity compliance, review all user account requests, and cyber training compliancy on average of 15,000 accounts per year, Federal Information Security Modernization Act (FISMA) reporting, account auditing, overall agency compliance and reporting of Cyber Workforce Improvement program.

6. Cyber Publication Support Services: DCSA requires cybersecurity publications support in order to maintain and support current and future cyber organizational operations. As such, various technical documents, procedures, and cyber written artifacts are to be performed in order to accomplish the needed support. The Government will provide an established workflow in which the Contractor shall support in line with the tasks below.

7. Data Management Support Services: The Contractor shall provide data management services in support of the Enterprise Data Management (EDM) Program.

8. System Lifecycle Risk Management – Cybersecurity, Compliance and Risk Management (CCRM): The Contractor shall establish a mature DCSA enterprise CCRM program and ensure that all its components are consistent of a specific product or system’s attributes.

Additionally, ensure components are developed, maintained, and executed for change and configuration management operations within DCSA IT, cloud, capabilities, and enclave environments enterprise wide.

9. The Cyber Defense Operations (CDO) / Computer Network Defense Support Services:

The Contractor shall maintain and support the EC3-SOC, following all DoD published guidance including but not limited to Directives, Instructions, Manuals and DCSA CCRM, CDO SOC CONOPS that support the CDO program at DCSA.

10. Emergent Technology Support:

The contractor shall provide program level cybersecurity/engineering services in support of zero-trust, networking, supply chain risk management, technology assessments, Cloud and AI-enabled security solutions, identification and integration of innovative, breakthrough technologies to protect DCSA networks, web servers, and endpoints. The contractor shall provide Risk Management Framework (RMF) support for steps 0-3 and 6 and advise the Information System Security Manager (ISSM) in terms of impact to confidentiality, integrity, and availability of systems based on security control implementation, mitigation strategies and compliance.

File details come from the government source that posted it. Updated .