EFO SP4709-23-F-0077 P00009_Redacted.pdf

PDF 285 KB Posted

Attached to
DLA Cybersecurity Web-App Vulnerability Management Federal contract opportunity
Solicitation number
SP4709-23-F-0077_P00009
Issued by
Defense Logistics Agency

About this file

This document is a Justification for an Exception to Fair Opportunity for a sole source modification to an existing task order with IP-Plus Consulting Inc. under the J6 Enterprise Technology Services (JETS) Indefinite-Delivery Indefinite-Quantity (IDIQ) contract. The modification seeks to increase cybersecurity engineering support for the Defense Logistics Agency's (DLA) Research & Development (R&D) program, specifically for J68 Research and Development and J61 Cybersecurity.

The modification will provide a dedicated Information Systems Security Engineer (ISSE) to support Small Business Innovation Research (SBIR) projects, evaluating cybersecurity risks, ensuring compliance with policies, and supporting the development of artificial intelligence and operational technology initiatives. The total estimated dollar value for this scope increase is $405,054.78, with a performance period from May 15, 2025 to September 20, 2026. The justification emphasizes the contractor's unique capabilities, extensive expertise, and current integration with DLA systems, arguing that introducing a new vendor would incur additional costs and risks to the government's critical cybersecurity efforts.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Controlled by: DLA DCSO – Philadelphia (DCSO-P) CUI Category: General Procurement and Acquisition / Source Selection Information see FAR 2.101 & 3.104 Distribution/Dissemination Controls: FED ONLY

Controlled Unclassified Information (CUI) Source Selection Sensitive Information - See FAR 2.101 & 3.104

DEFENSE LOGISTICS AGENCY

DLA CONTRACTING SERVICES OFFICE - PHILADELPHIA

700 ROBBINS AVENUE, PHILADELPHIA, PA 19111-5092

JUSTIFICATION FOR AN EXCEPTION TO FAIR

OPPORTUNITY (FAR 16.505(b)(2))

Upon the basis of the following justification, I hereby approve the issuance of the contractual action described below using an exception to fair opportunity, pursuant to the authority cited herein.

1. IDENTIFICATION OF AGENCY AND CONTRACTING ACTIVITY:

Requiring Activity:

DLA Information Operations (J614C) 8725 John J. Kingman Rd Fort Belvoir, VA 22060

Contracting Activity:

DLA Contracting Service Office-Philadelphia 700 Robbins Avenue Philadelphia, PA 19111-5092

2. NATURE AND DESCRIPTION OF THE ACTION BEING APPROVED:

Pursuant to FAR 16.505(b)(2), the action being approved is an exception to fair opportunity. This justification authorizes the use of other than full and open competition to increase the CONUS Information Assurance Support Task 2 Information Assurance Support for the Enterprise under the existing Task Order for J6 Enterprise Technology Services (JETS) IDIQ. Task Order No.

SP4709-23-F-0077 was awarded on a competitive basis to IP-Plus Consulting Inc. with a performance period of October 01, 2023, expiring September 30, 2026. The task order includes two 12-month option periods. The Task Order was placed against IP-Plus Consulting Inc. J6 Enterprise Technology Services (JETS) Indefinite-Delivery Indefinite-Quantity (IDIQ) contract, SP4709-17-D-0048. The increased scope for DLA Cybersecurity J614C Vulnerability Management services is detailed in Section 3 below.

3. A DESCRIPTION OF THE SUPPLIES OR SERVICES REQUIRED TO

MEET THE AGENCY’S NEEDS/ESTIMATED DOLLAR AMOUNT:

DLA Research & Development (R&D) at the Defense Logistics Agency at Fort Belvoir is seeking to increase support to DLA Cybersecurity Vulnerability Management Task 2- Information Assurance Support for the Enterprise. The increase in R&D for information technology, cloud services and operational technology requires an appropriate cybersecurity engineer to support the program office with adequate cybersecurity skillsets while evaluating emerging technology that will support cybersecurity resiliency efforts in future programs for the agency. As a result, DLA requires the expertise of a contractor to provide cybersecurity support to the R&D program management office located at Ft Belvoir, VA.

The contractor will play a critical role in providing cybersecurity engineering support to the DLA HQ Ft. Belvoir R&D program office, evaluating, documenting, and improving the cybersecurity posture of DLA activities; ensure compliance with DOD and DLA cybersecurity policies; and to design and evaluate risk to provide appropriate recommendations to the Program Manager and R&D directorate. The cybersecurity engineer will design, review, and evaluate the risk to remediate or mitigate cybersecurity vulnerabilities for information and operational technology systems before they can be exploited. All risk base evaluations will follow DLA, DoD, NIST, and all other U.S. Government policies.

J68 Research and Development (R&D) is seeking a dedicated Information Systems Security Engineer (ISSE) in J61 Cybersecurity to support multiple ongoing Small Business Innovation Research (SBIR) projects. J61 Cybersecurity does not currently have the staff to provide a dedicated ISSE to this effort, but the role is critical to ensuring our systems are securely designed and developed with strong cybersecurity resilience. The ISSE will be responsible for providing critical guidance to J68 on security best practices and ensuring compliance with relevant policies.

Specifically, the ISSE will provide guidance on security architecture requirements, system hardening, risk mitigation, cybersecurity best practices, and compliance with DoD policies and cybersecurity frameworks for the various projects.

This work directly supports national cybersecurity initiatives outlined in Executive Order 14028 and memo M-24-14, which prioritize public-private sector collaboration. Our Applied Research & Testing Emerging Technologies (ARTET) program provides the technological foundation for rapidly adopting innovative technologies for our warfighters and they are committed to building cybersecurity into every stage of development.

The ISSE contractor will play a vital role in securing these critical R&D efforts by ensuring the secure and compliant operation of the ARTET multi-cloud environment while providing security engineering guidance to the R&D team for the various SBIR projects.

J68 requires a contracted resource for the upcoming SBIR phase III project beginning in May 2025 better addresses the need for consistency in managing the functional areas. This contractor currently supports all of J6, and this additional effort will be an increased resource requirement that will require additional manpower due to the following:

The recent increase in operational tempo has highlighted IP-Plus's unique capabilities in research and development at this crucial time. This heightened activity has expanded the scope of tasks to include program evaluations of artificial intelligence (AI) as well as the development of an integrated operational technology zero-trust environment. The rationale for selecting this contractor is grounded in their advanced data analytics capabilities, which facilitate the extraction, transformation, and loading of several specialized datasets pertinent to both non-critical and critical platforms. This initiative aims to address EX Order 14028 by supporting both IT and operational technology enclaves and securing their respective boundaries. The team is composed of highly qualified professionals who possess industry-recognized certifications, including CCIE, CCNA, CCNP, CCDP, CISSP, CSSP, ISSEP, ISSAP, RMP, JNCIE, CEH, PMP, among others.

This extensive expertise enables the delivery of superior service quality and assures clients of the exceptional qualifications of the personnel involved.

Introducing a separate vendor would require additional integration costs and efforts, present schedule and performance risks, and jeopardize the Government’s ability to deliver immediate enhanced site-specific support to J6 R&D.

5. A DETERMINATION BY THE CONTRACTING OFFICER THAT THE

ANTICIPATED COST TO THE GOVERNMENT WILL BE FAIR AND REASONABLE:

As the Contracting Officer, I hereby determine that the anticipated cost to the Government will be fair and reasonable. The proposal will be analyzed in accordance with FAR 15.404-1 procedures.

It is anticipated that the Government will use various price analysis techniques including, but not limited to (1) Comparison with competitive price lists in accordance with FAR 15.404-1(b)(2)(iv);

(2) Comparison with Independent Government Cost Estimate (FAR 15.404-1(b)(2)(v)); and/or (3) Comparison of proposed prices obtained through market research for the same or similar items in order to obtain a fair and reasonable price in accordance with FAR 15.404-1(b)(2)(vi).

6. ANY OTHER FACTS SUPPORTING THE JUSTIFICATION:

N/A.

7. A STATEMENT OF THE ACTIONS, IF ANY, THE AGENCY MAY TAKE TO

REMOVE OR OVERCOME ANY BARRIERS THAT LED TO THE EXCEPTION TO

FAIR OPPORUNITY BEFORE ANY SUBSEQUENT ACQUISITION FOR THE

SUPPLIES OR SERVICES IS MADE:

The DLA Cybersecurity Web/App Vulnerability Management task order was solicited as a competitive acquisition under the JETS contract vehicle. The circumstances leading to the need for this modification were unforeseen prior to solicitation and award. At the time of the base award, support for J68 R&D was underestimated as the organization was not actively using cyber engineering support, but through the course of contract performance, the organization was identified as requiring the otherwise unused support, further increasing the manpower requirement beyond the known scope of the base award.

This sole source action is required before a new DLA Cybersecurity Web/App Vulnerability Management is awarded to oversee the delivery of critical operational support to the J68 R&D and ensure continuity of services and meet the needs of the DLA customers. To that end, the Government anticipates competing the follow-on to the current task order with the known increase to cybersecurity requirements before all available options expire on January 2, 2027.

8. CERTIFICATIONS.

Requirements Certification: I hereby certify that the support data provided for which I am responsible and which form a basis for this justification are complete and accurate.

DATE

Technical Certification: I hereby certify that the support data provided for which I am responsible and which form a basis for this justification are complete and accurate.

Contracting Certification: I hereby certify that this justification is accurate and complete to the best of my knowledge and belief. In accordance with FAR 16.505(b)(2)(ii)(C)(2), I have determined that FAR 16.505(b)(2)(i)(B) applies and I approve this justification.

File details come from the government source that posted it. Updated .