Attachment 10_CUI_CBII JA_Redacted.pdf
PDF 556 KB Posted
- Attached to
- Cloud Based Internet Isolation Service Federal contract opportunity
- Solicitation number
- HC108426R0005
- Issued by
- Defense Information Systems Agency
About this file
This is a Justification for Other Than Full and Open Competition (OTFAOC) document for a Cloud Based Internet Isolation (CBII) Service procurement by the Defense Information Systems Agency (DISA).
DISA seeks to procure the proprietary Menlo Security Cloud Browser (MSCB) product as a managed service for the Department of War's remote browsing isolation solution. The procurement includes renewal of existing subscription licenses, procurement of new licenses, and incorporation of Menlo Security's HEAT Shield with AI/ML capabilities. The contract will be a firm fixed price (FFP) award issued to an authorized reseller of Menlo Security, Inc., sourced through open-market procedures on SAM.gov, funded with Fiscal Year 2026 Defense Working Capital Funds. The period of performance consists of a one-year base period (April 15, 2026 – April 14, 2027) with four one-year option periods extending through April 14, 2031, plus a 5% surge capability and FAR 52.217-8 pricing through October 14, 2031. The total life cycle runs from April 15, 2026 through October 14, 2031. Current deployment protects approximately 3.05 million DoW users across 70 CBII tenants representing Combatant Commands, Armed Services, and DoW Agencies.
The OTFAOC is justified under 10 U.S.C. 3204(a)(1) and FAR 6.302-1(c) because MSCB is the only solution meeting critical requirements including threat mitigation via remote browsing isolation, secure web sessions with data loss prevention, network optimization, IPv6 support, FedRAMP+ Level 2 compliance, and integration with DISA's DJI security tools. Market research from October 2024 to December 2025 identified 46 RFI responses, with only four potentially capable vendors, all proposing MSCB deployment. Menlo Security, Inc. cannot serve as prime contractor due to lacking a required Secret facility clearance; therefore, the award will go to an authorized reseller from a list of 27 qualified vendors. The justification notes no competing solutions currently exist that meet all government CBII requirements regarding cybersecurity protections, testing capabilities, and cloud environment design. The government commits to continued market research for future competitive actions, anticipating that within approximately five years other remote browsing isolation technologies may mature sufficiently to enable broader competition.
View the file
Other files for this federal contract opportunity
Show all 30
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CBII Service
CUI
Page 1 of 11 Pages
Controlled By: DISA Controlled By: DITCO/PSD/PS8414 CUI Category: PROCURE Distribution/Dissemination Control: FED ONLY POC: Angela Zang, 667-890-0997, disa.scott.ditco.mbx.mobility@mail.mil
CUI
JUSTIFICATION FOR OTHER THAN FULL AND
OPEN COMPETITION (OTFAOC)
Federal Acquisition Regulation (FAR) Part 6 Justification & Approval (J&A), Supporting Procurements under FAR Part 12 and/or FAR Part 15
Purchase Request Number: To be determined (TBD) Contract Number: TBD Procurement Title: Cloud Based Internet Isolation (CBII) Service Estimated Value:
Regulatory Authority: 10 U.S.C. 3204(a)(1) and FAR 6.302-1(c)
J&A Number: JA26-023
Upon the basis of the following justification, I, as Senior Procurement Executive, hereby approve the use of other than full and open competition of the proposed contractual action pursuant to the authority of FAR 6.302-1(c).
1. REQUIRING AGENCY AND CONTRACTING ACTIVITY:
a. Requiring Agency:
Defense Information Systems Agency (DISA) DISA Headquarters 6910 Cooper Avenue Fort Meade, Maryland 20755
b. Contracting Activity:
DISA/Defense Information Technology Contracting Organization (DITCO) PS8414 DITCO-Scott Field Office 2300 East Drive, Building 3600 Scott AFB, Illinois 62225
2. NATURE/DESCRIPTION OF ACTION(S):
a. This procurement is for the proprietary, commercial off-the-shelf (COTS), brand-name Menlo Security, Inc.’s Cloud Browser (MSCB) product, as a Menlo Security, Inc.
reseller-provided managed service, providing the Department of War’s (DoW’s) remote browsing isolation (RBI) solution for CBII. The action includes the renewal of existing subscription licenses, the procurement of new subscription licenses, and the incorporation of Menlo Security, Inc.’s Highly Evasive and Adaptive Threats (HEAT) Shield with Artificial Intelligence/Machine Learning (AI/ML) capabilities to enhance cybersecurity measures.
Page 3 of 11 Pages
CUI
successfully. As of December 2025, around 3.05M users actively rely on MSCB for secure access in the DoD Information Network (DoDIN).
Since 2020, the DoW has leveraged CBII through the MSCB platform under a production Other Transaction Authority (OTA) agreement. Over the past five years, MSCB has continuously evolved to safeguard DoW users from cyber threat actors by proactively engineering defenses against malicious tactics, techniques, and procedures.
Originally hosted on Amazon Web Services, this capability has been further enhanced with the strategic expansion of MSCB to a second cloud environment, the Google Cloud Platform.
This expansion improves system redundancy, optimizes load balancing, and ensures uninterrupted availability of the CBII environment, even during outages. MSCB guarantees continuous, secure web browsing for DoW personnel worldwide.
The CBII Program Management Office (PMO) projects the total user base under OPORD 21- 0006 to range between 3M and 3.2M, with the capacity to scale up to 3.4M users to accommodate surge requirements under an enterprise licensing model. The PMO continues to work with remaining DoW entities to complete their migration efforts, anticipating further growth in the MSCB user base in the coming years.
To defend DoW networks from online threats, the MSCB solution operates within a FedRAMP+ Level 2-compliant unclassified Cloud Service Offering. This environment adheres to rigorous cybersecurity standards while supporting up to 3.4M DoW users worldwide. MSCB provides secure, continuous internet browsing, isolates threats, and optimizes bandwidth usage.
Having already transitioned 3.4M DoW users to the MSCB solution during the CBII production OTA, the focus of this effort is to ensure the system remains operational, scalable, and capable of addressing emerging cybersecurity threats. This includes leveraging Menlo Security, Inc.’s advanced cloud environment, which incorporates cutting-edge AI/ML-driven automated defenses to detect and neutralize sophisticated cyberattacks. These enhancements ensure a robust, reliable solution that protects DoW users from web-based threats while maintaining mission-critical security and operational efficiency.
b. Justification
(1) Minimum government requirements. The MSCB solution requires the following critical capabilities, ensuring the protection of its users, systems, and sensitive information against advanced and persistent cyber threats:
Threat Mitigation: Redirects user browsing activity from local desktops to secure, remote cloud servers, reducing risks to the DoDIN.
Secure and Isolate Web Sessions: Provides authenticated, isolated browsing sessions with data loss prevention features for file uploads, neutralizing attack vectors and preventing data compromise.
Network Optimization: Alleviates bandwidth constraints by offloading internet browsing activity to the cloud, improving overall network performance.
Page 4 of 11 Pages
CUI
Supports Internet Protocol version 6 (IPv6) Traffic: Offers support to both dual stack IPv4/IPv6 traffic and IPv6 to IPv6 only traffic.
Program Support: Provides complete contract oversight and program management, including drafting key documents, regular activity reporting, and developing foundational plans like the Task Order Management Plan, Integrated Master Schedule, and Work Breakdown Structure.
Operational Service Support: Ensures responsive communication and operational stability for all end-users and IT staff. This includes Tier I-III service desk support compliant with the Defense Enterprise Service Management Framework, complete with robust troubleshooting, escalation procedures, and daily tenant maintenance.
User Migration Support: Delivers “white-glove" assistance to over 70 DoW CBII tenants to ensure a seamless migration. This includes access to a dedicated portal with user guides and full support for migration to DoW-approved mobile devices.
Accreditation and Authorization (A&A) Support: Offers expert guidance through all phases of the Risk Management Framework. This includes maintaining standard operating procedures for vulnerability patching, coordinating with A&A teams to resolve security defects, and managing the lifecycle Certification and Accreditation Plan.
Training: Develops and delivers customized training programs for all users, from subscribers to administrators and instructors. Training is available in-person or online and covers all features and functions of the CBII service.
Engineering Support Services: Implements system engineering with the best practices for risk and configuration management, data management, and Test & Evaluation. This service provides for the integration of new technologies, DoD Architecture Framework-compliant design documents, network analysis, and a dedicated test lab to ensure the total cybersecurity posture of the MSCB service.
Secret Facility Clearance Level: The managed service provider will possess a Secret facility clearance, as adjudicated by the Defense Counterintelligence Security Agency, which is a mandatory requirement to serve as the primary contractor.
(2) Proposed brand-name product. The brand-name MSCB capability sits in an Impact Level 2 commercial cloud, providing robust 24x7x365 availability and accessibility for DoW users to access commercial websites while preventing potential malicious source code from touching or infiltrating DoW networks. The MSCB natively supports modern browsers and protects the DoDIN by moving non-mission web browsing off DoW endpoints to a virtual browser in the cloud.
This is achieved by rendering website source code in the Menlo Security, Inc.
isolated cloud platform. Through this process, the MSCB actively declutters DoW networks and load-balances transport, which results in offloading several petabytes of data monthly providing more reliable network access on the DoDIN.
Page 5 of 11 Pages
CUI
Along with the protections provided by browsing isolation, the MSCB solution eliminates the need for third party browser plugins, provides a remote document viewing capability (safe view), and provides granular policy controls to mission partners. For file downloads, MSCB provides initial anti-virus scans, hash checking, and detonation (sandboxing) before passing the file to the full Internet Access Point-DISN Joint Infrastructure (IAP-DJI) security stack for additional inspection with DISA’s advanced security tools. Moreover, MSCB is interoperable with DISA’s advanced DJI security tools to include Web Content Filtering, Enterprise Break & Inspect, Full Content Inspection and the accreditation by DISA’s Risk Management Executive security accessors is also feasible in this deployed state, highlighting the serious cyber protections that MCSB offer.
These existing functions and on-going deployment of MSCB are critical infrastructure points to the first line of defense protecting the DoDIN from potential cyber threats. MSCB has been tested and certified for DoDIN interoperability, cybersecurity, integration, functional and operational requirements, and was implemented as part of previous openly competed OTAs.
Specifically, in the essential CBII categories of System-wide Web Browsing, Cybersecurity Capabilities, Identity Management, Testing, Event Management, Incident Management, Request Fulfillment, IPv6 General, and Special Considerations, the MSCB has proven to meet and exceed requirements.
Other solutions that the CBII PMO analyzed prior to deployment of MSCB through the prototype and production OTA agreements, had requirements that could not meet the aforementioned capabilities and could not be fully deployed in the DISA CBII environment to meet the underlying essential categories. Solutions analyzed during recent market research concluded that no other companies’ products could meet the requirements specifically for one or more of the following reasons:
The proposed solution was not a true CBII capability designed to manage traffic in a cloud environment.
The solution failed to meet required cybersecurity protections.
The response failed to adequately address the CBII testing requirements.
(3) Discussion regarding the necessity of the brand-name solution. MSCB was procured in 2020 and is currently deployed and integrated within the DoDIN.
DISA requires the ability to maintain current systems while meeting future system and network capacity and performance requirements. The CBII solution must be interoperable and compatible with the DJI security stack located at DISA’s ten global IAPs; must comply with DoW mandates for supporting IPv6 network traffic; and must adhere to risk management assessment and authorization requirements. The current capability, MSCB, complies with these requirements.
Per the current market research conducted from October 2024 – December 2025, there are no solutions that meet all the Government’s CBII requirements, nor are there any other capabilities/solutions that are compatible with the existing
Page 6 of 11 Pages
CUI
infrastructure, which is required for the reasons stated below. Moreover, MSCB satisfies vital functional requirements essential to CBII to include system-wide web browsing compatibility, providing cybersecurity capabilities, offering identity management options, testing environments, can interface with DoW mobility gateways, supports event management and incident management, and has the flexibility and scalability with request fulfillment to support an enterprise license structure that will cover up to 3.4M DoW users.
(4) Impact. It was determined that the adoption of a new CBII environment, which excludes or replaces the MSCB, would result in significant disruption to DoW organizations and network operations, and create a significant threat to national security if the DoDIN is left unprotected for any period of time. If the Government were unable to obtain the MSCB subscriptions, MSCB as a managed service, and the addition of HEAT Shield AI, the DoDIN would not maintain security from preventable cyber threats and attacks. Furthermore, the DoDIN and its users would be non-compliant with the OPORD, which intended to reduce these types of targeted attacks. Shifting to a new manufacturer’s brand or cloud browsing service will result in a major disruption to DoW cyber operations and poses a significant threat to national security. Currently, the MSCB protects over 70 CBII tenants, representing United States (U.S.) Combatant Commands, Armed Services, DoW Agencies, and Field Activities. Discontinuing the MSCB and removing the inherent protections afforded by this cloud environment would pose a significant threat to U.S. National Security and compromise the integrity of DoW networks and cyber operations. As a result, the DISA CBII must maintain its existing hosting structure with MSCB.
6. CONTRACT OPPORTUNITIES ANNOUNCEMENT/POTENTIAL SOURCES:
a. In accordance with (IAW) FAR 5.102(a)(6), the Contracting Officer shall make the solicitation and this justification for OTFAOC publicly available to all businesses through the governmentwide point of entry, SAM.gov.
b. As part of market research, the CBII PMO directly asked Menlo Security, Inc. if they could support the CBII requirement. Menlo Security, Inc. stated they can provide the MSCB environment and accompanying services directly to the Government without a third-party integrator. However, in reviewing Menlo Security, Inc.’s Request for Information (RFI) submission, Menlo Security, Inc. does not have the required Secret level facility clearance that is integral to being a prime contract holder for the MSCB award. Additionally, Menlo Security, Inc. provided a list of MSCB authorized resellers.
That list included 27 third-party contractors that are authorized to sell the MSCB to the DoW to support a competitive environment.
7. DETERMINATION OF FAIR AND REASONABLE COST:
a. The Contracting Officer shall determine if the prices offered are fair and reasonable before the award. The complexity and circumstances of this requirement will determine
Page 7 of 11 Pages
CUI
the level of analysis, and the techniques used to determine the proposed price are fair and reasonable. Such methods may include those identified in the following sections:
(1) FAR 15.404-1(b)(2)(i) – Comparison of proposed prices received in response to the solicitation.
(2) FAR 15.404-1(b)(2)(ii) – Comparison of the proposed prices to historical prices paid, whether by the Government or other than the Government, for the same or similar items.
(3) FAR 15.404-1(b)(2)(iv) – Comparison with competitive published price lists, published market prices of commodities, similar indexes, and discount or rebate arrangements.
(4) FAR 15.404-1(b)(2)(v) – Comparison of proposed prices with independent Government cost estimates.
8. MARKET RESEARCH:
a. Market research was conducted from October 2024 to December 2025, by the CBII PMO, DITCO, and DoW participants. Market research consisted of contacting the manufacturer and authorized resellers, releasing an RFI, searching the internet, reviewing catalogs and other contractor literature, holding discussions with industry and government employees, reviewing publications, and conducting research sessions with external information technology research firms.
To help determine the CBII solution, an RFI was released to commercial vendors and integrators that can provide a managed, cloud-based, web browser isolation service that will isolate, contain, and render all non-government websites (.com, .net, etc.) in a secured cloud platform. The RFI was posted to SAM.gov on October 16, 2024, with responses due on November 6, 2024. Forty-six responses were received and evaluated.
Nine of the responses provided enough information for further review and four of those provided sufficient details to indicate they could meet the requirements outlined in the RFI through the deployment of MSCB. All other responses were unable to meet the minimum technical needs. The results of the RFI determined that only MSCB can meet the Government’s CBII requirements. In July 2025, the CBII PMO contacted Menlo Security, Inc. to confirm if they had a Secret Facility Clearance. Since Menlo Security, Inc. did not have a Secret Facility Clearnce, they are not eligible for a direct award. As of December 2025, DISA has successfully migrated 3.05M DoW users to the CBII environment with MSCB. This migration was implemented over 3.5 years and encompassed approximately 70 DoW organizations, which involved extensive coordination, training, testing, organizational collaboration, technical synchronization, and end-user validation. The complexity and scope of replacing the existing MSCB would result in major disruptions to DoW cyber operations, posing a significant threat to national security. Additional market research was conducted through December 2025 confirming the method of procurement. Existing DISA-wide and DoW Multiple-Award
Page 8 of 11 Pages
CUI
Contract Vehicles and Other Government-Wide Acquisition Contracts are not viable options, and the DISA Market Research Repository did not yield any similar acquisition requirements or cloud computing technology comparable to the secure cloud environment being sought or a similar capability that would satisfy the CBII requirements.
This requirement cannot be set aside for a small business or any other socio-economic group because the ostensible subcontract rule, 13 C.F.R. 121.103(h)(3) would apply.
With the required MSCB solution, Menlo Security, Inc., becomes a subcontractor. In addition, subcontracting IAW FAR 52.219-14, Limitations on Subcontracting, cannot be met since a small business would not be providing over 50% of the cost of the requirement.
b. Based on current market research, interoperability and system constraints, it has been determined that only brand-name managed services can fully meet and satisfy the requirement. Only the specific OEM proprietary, brand-name specific MSCB, which is available through authorized resellers, will satisfy the needs and can support the infrastructures currently in place. This requirement is for proprietary products and/or product support, and no competitor functional replacement products exist in the market at this time to meet the Government's needs. The Government will continue to conduct market research to determine if there are changes in the marketplace that would enable future competitive actions; i.e., there are similar products and/or product support in the marketplace that provides the same functionality, the original equipment manufacturer releases ownership rights of the product, or it is economically feasible to procure a new system.
9. ANY OTHER SUPPORTING FACTS:
None.
10. LISTING OF INTERESTED SOURCES:
a. August Schell (a small business)
b. By Light Professional IT Services (a large business)
c. Leidos, Inc. (a large business)
d. Optiv Federal, Inc. (a large business).
11. ACTIONS THE AGENCY MAY TAKE TO REMOVE OR OVERCOME BARRIERS
THAT LED TO THE EXCEPTION TO FULL AND OPEN COMPETITION:
a. Procurement History.
The MSCB platform has demonstrated exponential growth, scaling from 100,000-user prototype OTA agreements in 2018 to a full production OTA agreement in 2020 that serves over three million DoW users. This follow-on recompete to the production OTA agreements highlights the platform's ongoing success and evolution. Additional agreement details listed here:
Page 10 of 11 Pages
CUI
Given the importance of the CBII platform in protecting the DoDIN, the Government will require future demonstrative test pilots or evidence-based success to ensure any non- Menlo Security, Inc. based CBII solution is rigorously tested to validate the efficacy of any stated solution in off-loading network-clogging commercial traffic, protecting against cyber threats in a secured cloud container, and ensuring their environment can manage the services of the DoW enterprise constituting up to as many as 3.6M DoW users, while integrating AI/ML in their cloud solution for early detection of zero-day threats.
The Government anticipates there will be an increase in the number of companies offering RBI technologies, similar to MSCB, that will have matured and may be capable of providing the CBII requirements. As these companies continue to expand their RBI offerings, the Government further believes that a follow-on contract at the conclusion of this contract (i.e. in approximately five years) would be better postured to evaluate and deploy a CBII environment that does not necessarily include MSCB. Such opportunity would allow for wider competition and a potential award for the CBII environment beyond brand-name specific MSCB. The Government will continue to conduct market research to determine if there are changes in the industry that would enable future competitive actions, however, outside of the current MSCB solution that has been utilized by DISA, no other capability to date can meet the mark from a technological and implementation standpoint.
c. Related Prior Awards without the Need for a Brand-Name.
The CBII program has a well-established history of successfully procuring and deploying cloud browser services for MSCB. The prototype OTA was awarded though open competition, and the production OTA was awarded through a bake-off between the two prototype OTA awardees, By Light Professional IT Services, LLC. and Sealing Technologies, Inc. The absence of any challenges to these prior procurements underscores the effectiveness and acceptance of this particular cloud browser solution for our operational needs and supports continued wide-scale deployment.
File details come from the government source that posted it. Updated .