IV_11 JOFOC_Form_REDACTED.pdf
PDF 157 KB Posted
- Attached to
- Cybersecurity Training and Certifications Federal contract opportunity
- Solicitation number
- 2032H323N00009
About this file
This document is a Justification for Other than Full and Open Competition (JOFOC) form submitted by the Department of the Treasury's Enterprise Applications Office. The JOFOC requests approval for a sole source award to the SANS Institute for specialized cybersecurity training courses and certifications. The training is needed to develop Treasury's federal cybersecurity workforce and will be provided under an Indefinite Delivery Indefinite Quantity contract with one base year and four option years, from July 2023 through July 2028. SANS Institute will provide over seventy desired cybersecurity courses mapped to the NICE Framework and leading to GIAC certifications, which are unique and not offered by any other provider according to market research. The total estimated contract value is $4,986,189.37. The JOFOC outlines the market research conducted, including requests for information and a sources sought notice, and determines that only SANS Institute can fully meet Treasury's requirement for specialized training courses and certifications.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
IRS Form (Rev. 6/21)
IRSAP 1006.3
JUSTIFICATION FOR OTHER THAN FULL AND OPEN COMPETITION
(JOFOC)
FAR SUBPART 6.3
I recommend the use of other than full and open competition for the acquisition of the following supplies or services. If this acquisition is to be made with only one source or a limited number of sources, negotiations will be conducted with the indicated proposed supplier(s).
1. IDENTIFICATION OF THE AGENCY AND CONTRACTING ACTIVITY:
Agency: Department of the Treasury, Enterprise Applications Office
Contracting Activity: Office of Business Solutions Acquisitions (OBSA), Treasury Operations Branch, Operations Support Section
2. NATURE/DESCRIPTION OF THE ACTION BEING APPROVED:
The purpose of this sole source justification is for the Department of Treasury Enterprise Application offices to obtain approval to award a new requirement under an Indefinite Delivery Indefinite Quantity (IDIQ) Firm Fixed Price (FFP) contract with Escal Institute of Advanced Technologies, Inc. /dba SANS Institute (hereinafter called SANS) for training and certification services. The need date is July 10, 2023. The period of performance will be for one 12-month base period from July 10, 2023 through July 9, 2024, plus four 12-month option periods, expiring July 9, 2028 unless extended in accordance with FAR 52.217-8 Option to Extend Services.
3. DESCRIPTION OF SUPPLIES OR SERVICES:
Treasury (Enterprise Apps) has identified a need to procure specialized cybersecurity training courses and certifications for Treasury-wide use. These courses will help facilitate the development of current federal Enterprise Application Cybersecurity (EAC) employees, future EAC employees, and other Treasury Departmental Offices requiring specialized cybersecurity training and certifications. Therefore, there is a need to establish an Indefinite Delivery Indefinite Quantity (IDIQ) Firm Fixed Price (FFP) contract for specialized cybersecurity training courses & certifications from leading industry provider per Treasury Directive 85-01 (TREASURY DIRECTIVE 85-01 | U.S. Department of the Treasury). These courses will help facilitate the development of current Treasury employees, future Treasury employees, and other DO offices requiring specialized cybersecurity training and certifications. DoD Approved 8570 Baseline Certifications include GIAC Certifications. DoD Approved 8570 Baseline Certifications – DoD Cyber Exchange
4. SHOPPING CART
NUMBER:
23PR-SSP-0027
5. NAME OF PROPOSED SOURCE(S):
The Escal Institute of Advanced Technologies, Inc.
/dba SANS Institute
UEISAM: NA37S3SKQW65
11200 Rockville Pike, Ste 200 North Bethesda MD 20852-3103
6. COST ESTIMATE:
Base Year: $ 609,861.00 Option I: $ 914,267.82 Option 2: $1,111,081.65 Option 3: $1,116,469.35 Option 4: $1,234,509.55 Total: $4,986,189.37 https://home.treasury.gov/about/general-information/orders-and-directives/td85-01 https://public.cyber.mil/wid/cwmp/dod-approved-8570-baseline-certifications/
7. CERTIFICATION OF TECHNICAL OR REQUIREMENTS PERSONNEL
I hereby certify that any supporting information and data provided, which form the basis for this justification, are accurate and complete to the best of my knowledge and belief.
PROGRAM OFFICE (Requiring Activity) (Name & Title)
(Signature)
(Phone No.)
(Date)
8. PROCUREMENT OFFICE CERTIFICATION
This requirement [ ] will / [ X ] will not provide for a bridge contract.
I certify that this submission is accurate and complete to the best of my knowledge and belief. This certification will serve as approval, unless action exceeds $750K.
CONTRACTING OFFICER (Name)
Ramona L. Hanson IRS, Office of Business Solutions Acquisition Treasury Operations Branch
(240)613-9385
Before requesting this procurement, state one statutory authority for this procurement to be conducted under “other than full and open competition” procedures. Provide narrative justification associated with the respective state authority in block number 10.
9. THE COMPETITION IN CONTRACTING ACT OF 1984 (P.L. 98-369)
(place “X” in appropriate box)
XX
41 U.S.C. § 3304(a)(1), FAR 6.302-1– Only one responsible source; or brand name specification
41 U.S.C. § 3304(a)(2), FAR 6.302-2 – Unusual and compelling urgency
41 U.S.C. § 3304(a)(3), FAR 6.302-3 – Industrial mobilization, engineering, developmental, or research capability; or expert services
41 U.S.C. § 3304(a)(4), FAR 6.302-4 – International agreement
41 U.S.C. § 3304(a)(5), FAR 6.302-5 – Authorized or required by statute
41 U.S.C. § 3304(a)(6), FAR 6.302-6 – National Security
41 U.S.C. § 3304(a)(7), FAR 6.302-7 – Public Interest
10. JUSTIFICATION
(add pages if needed)
A. DEMONSTRATION THAT THE PROPOSED CONTRACTOR’S UNIQUE QUALIFICATIONS OR THE
NATURE OF THE ACQUISITION REQUIRES USE OF THE AUTHORITY CITED.
An exhaustive search was conducted by the government via aforementioned market research techniques and determined no other company provides the SANS courses or GIAC certifications, as confirmed by SANS Institute. SANS provided a sole source letter in which they state that they do not allow for authorized resellers or third parties vendors to provide any SANS trainings or GIAC certifications. Market research discovered that vendors could only provide piecemeal substitutes regarding the potential course listing of over seventy desired cybersecurity courses meeting the government’s minimum requirement. Most vendors were only able to offer around 20% crosswalk substitute against the desired SANS courses. Furthermore, vendors did not offer GIAC certifications. Market research determined SANS is the only holistic option available on the marketplace, that offers a complete solution in terms of SANS courses and GIAC certifications.
GIAC certifications are unique certifications by SANS and no other vendor has an equivalent certification (via market research). GIAC certifications are mapped to work roles described in the National Initiative for Cybersecurity Education (NICE) (Workforce Framework for Cybersecurity) Framework. GIAC certifications are also recognized by DoD Approved 8570 Baseline Certifications DoD Approved 8570 Baseline Certifications – DoD Cyber Exchange Over 40 GIAC Certifications are offered with each certification being mapped directly to NICE Framework. GIAC certifications are designed to ensure students can apply their knowledge and skills in real world setting via CyberLive (real world VM environment). CyberLive comment of GIAC Certifications requires a hands-on lab as part of the certification to prove mastery of the subject area.
GIAC is the only vendor to offer CyberLive exams. All GIAC exams are proctored. GIAC provides the assurance of cyber security knowledge and skills available by offering exams that are designed to ensure students can apply their knowledge and skills in a real world setting via CyberLive (real world VM environment) exams. GIAC certifications and exams will directly strengthen Treasury workforce in terms of cybersecurity posture. Ensuring Treasury receives unique and specialized cybersecurity training is imperative especially since recent cybersecurity incidents such as SolarWinds.
GIAC Certifications with CyberLive exam (sample listing)
• GIAC Certified Incident Handler Certification (GCIH)
• GIAC Cloud Forensics Responder (GCFR)
• GIAC Penetration Tester Certification (GPEN)
• GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
• GIAC Web Application Penetration Tester (GWAPT)
• GIAC Security Essentials (GSEC)
• GIAC Certified Intrusion Analyst Certification (GCIA)
• GIAC Certified Forensic Analyst (GCFA)
• GIAC Reverse Engineering Malware Certification (GREM)
• GIAC Network Forensic Analyst (GNFA)
• Global Industrial Cyber Security Professional Certification (GICSP)
• GIAC Certified Forensic Examiner (GCFE)
• GIAC Continuous Monitoring Certification (GMON)
• GIAC Experienced Cyber Security (GX-CS)
• GIAC Experienced Intrusion Analyst (GX-IA)
• GIAC Experienced Incident Handler (GX-IH)
This shall enable Enterprise Apps to support the development of its’ growing federal cybersecurity workforce by procuring highly specialized, industry recognized cybersecurity courses and certifications. SANS Institute’s courses and GIAC certifications justify a sole source acquisition.
B. DESCRIBE THE EFFORTS TAKEN TO ENSURE OFFERS WERE SOLICITED FROM AS MANY
POTENTIAL SOURCES AS IS PRACTICABLE, INCLUDING WHETHER A NOTICE WAS OR WILL BE
PUBLISHED AS REQUIRED BY FAR SUBPART 5.2 AND, IF NOT, WHICH EXCEPTION UNDER FAR
5.202 APPLIES.
A Request for Information (RFIs) was posted to both GSA e-buy (GSA RFQ ID # 1615261) and SAM.gov (2032H323N00009), and closed on April 3 and April 17, 2023, respectively. A total of 27 companies provided a response, including the sole source vendor. Also, in compliance with FAR 5.202, a Notice of Contract Action was posted on May 8, 2023, and closed on May 22, 2023. Five companies responded to the NCA with capability statements. The overall limitation of these companies is that they do not offer a GIAC certification or equivalent, which is a requirement. The provided capability statements also lacked an acceptable crosswalk to ensure all course offerings would be available or listings of courses were limited as compared to the government’s requirement.
C. DETERMINATION THAT THE ANTICIPATED COST TO THE GOVERNMENT WILL BE FAIR AND
REASONABLE.
The contracting officer intends to negotiate a fair and reasonable price with this vendor based upon review of available published pricing rate sheets, request for comparable historical pricing awarded by other government agencies, a comparison to the Independent Government Cost Estimate (IGCE), etc.
D. DESCRIBE THE MARKET RESEARCH THAT WAS CONDUCTED AND THE RESULTS OF THAT
SURVEY. IF ACTIONS WERE TAKEN BY PROCUREMENT PERSONNEL TO SATISFY THIS
REQUIREMENT (SUCH AS A GPE SOURCES SOUGHT SYNOPSIS), PLEASE SPECIFY.
A market review was conducted in reference five companies: Advance Computer Concepts, Bluetech, Gabriel Enterprises Consulting Group LLC, GovSmart, and Patriot Strategies with a focus on their available cybersecurity training, what Enterprise Apps (EA) would be utilized and available certification programs. As a result, EA was unable to locate a vendor who could provide the level of credentialing required by Treasury.
Per the RFI responses, a total of 27 capability packages were received, including one from the proposed sole source vendor. Each capability package was thoroughly reviewed by the program office.
Only SANS can offer GIAC Certifications and GIAC CyberLive exams. The other vendors offered partial crosswalks against the SANS/GIAC offerings; however, the program office strongly believes that the alternative options are not adequate due to piecemeal approach and therefore would leave Treasury vulnerable to future cybersecurity incidents. With exception of the incumbent, it was determined no other company would be able to satisfy the minimum Performance Work Statement (PWS) requirements. Additionally, the sole source vendor confirmed via letter of April 28, 2023, that they do not allow for authorized resellers or third-party vendors to provide the required services under this procurement.
E. DESCRIBE ANY OTHER FACTS TO SUPPORT THE JOFOC.
None
IRSAP 1006.3
F. LIST SOURCES, IF ANY, THAT EXPRESSED, IN WRITING, AN INTEREST IN THE ACQUISITION.
The following sources responded to the posted RFI notices:
99999 Consulting LLC ThunderCat Technology LLC Alliance Micro Solutions, Inc. Ultimate Knowledge Institute BestLink Strategies LLC United Training Career LLC Cloud9 Security Services, Inc. Xtreme Solutions Inc.
Comtech Telecommunications Corp.
Dotwave Solutions Exousia Marketing Group HaloTech Solutions LLC Integrate-Systems, Inc.
Netcom Learning Nfinity LLC Oready LLC Pluralsight LLC PMTS, Inc.
Project Manager USA, Inc.
Rapier Solutions Inc.
RFK Solutionz Corporation RV Global SANS Institute LLC Silkweb Consulting & Development Starweaver Group Inc.
Storsoft Technology Corp.
TASC Management Corp.
G. LIST THE ACTIONS THE BUREAU WILL TAKE TO REMOVE OR OVERCOME ANY BARRIERS TO
PROMOTE THE COMPETITION ON ANY SUBSEQUENT ACQUISITIONS FOR SIMILAR SUPPLIES OR
SERVICES.
Treasury Enterprise Applications office will continue to review the commercial marketplace to determine its’ need as it relates to subsequent acquisitions for similar services, as well as reach back to the sole source vendor to determine if they will allow for authorized resellers or third-party vendors in order to obtain the needed services. The review will also target alternative training certifications in order to promote for future competition of any subsequent requirement.
H. STATEMENT THAT REQUIREMENT DOES NOT RESULT FROM A LACK OF PLANNING OR THE
EXPIRATION OF FUNDS.
This requirement does not result from a lack of planning or expiration of funds.
11. ADDITIONAL APPROVALS
O
VE
R
0, COMPETITION ADVOCATE
(Name & Title)
[ ] APPROVE
[ ] DISAPPROVE
| 41 U.S.C. § 3304(a)(1), FAR 6.302-1– Only one responsible source; or brand name specification |
| 41 U.S.C. § 3304(a)(2), FAR 6.302-2 – Unusual and compelling urgency |
| 41 U.S.C. § 3304(a)(4), FAR 6.302-4 – International agreement |
| 41 U.S.C. § 3304(a)(6), FAR 6.302-6 – National Security |
| 11. ADDITIONAL APPROVALS |
File details come from the government source that posted it. Updated .