PCCS-25-2007 Limited Sources Justification_Redacted.pdf

PDF 127 KB Posted

Attached to
Cybersecurity Training Support Services Federal contract opportunity
Solicitation number
PCCS-25-20007
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This Limited-Sources Justification (LSJ) document details a sole-source task order for the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA). The procurement is for cybersecurity training support services from Edgesource Corporation, valued for a 12-month performance period from September 30, 2025 to September 29, 2026. The required services include delivering synchronous and asynchronous training on Continuous Diagnostic and Mitigation (CDM) Program topics, creating a Cloud Virtual Learning Environment (CVLE) lab, and providing cybersecurity training across various domains including enterprise governance, risk management, incident response, and vulnerability assessments.

The justification emphasizes Edgesource's unique capabilities, noting they are the only vendor capable of immediately providing critical cyber training to federal civilian executive branch (FCEB) end users. The document highlights that changing vendors would cause significant disruption, including potential security processing delays and a gap in statutorily required cybersecurity training. CISA plans to conduct a competitive procurement for a follow-on requirement, with the anticipated solicitation release scheduled for the second quarter of fiscal year 2026, making this limited-source task order a bridge to maintain continuity of essential cybersecurity training services.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Limited-Sources Justification (LSJ): For Order or Blanket Purchasing Agreements (BPA)Exceeding the Simplified Acquisition Threshold (SAT)

PCCS-25-20007

LSJ No: FY-25-00253 3- 1 -

LSJ No.: FY25-00253

This acquisition is conducted under the authority of the Multiple-Award Schedule Program, 41 U.S.C. 152(3), Competitive Procedures, and 40 U.S.C. 501, Services for Executive Agencies.

1. Agency and Contracting Activity. Identification of the agency, contracting activity, and specific identification of the document as a “Limited-Sources Justification.”

The Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), Chief of Contracting Office (COCO) and CISA Cybersecurity Division (CSD) Capacity Building (CB) propose to award a task order pursuant to Federal Acquisition Regulations (FAR) 8.405-6(a), Limiting Sources.”

2. Nature and/or description of the action being approved. Describe the action being approved and include the name and address of the proposed contractor(s).

CISA/COCO intends to limit the number of sources solicited pursuant to FAR 8.405-6(a), for the procurement of cybersecurity training support services to Edgesource Corporation (Edgesource), 909 North Washington Street, Suite 200, Alexandria, VA 22314.

3. Description of Supplies/Services. Describe the supplies or services to be acquired. Provide the estimated total value (including options, if any).

The requirement supports the DHS CISA/CSD/CB/Cyber Training (CT) branch to include major Acquisition efforts like the Continuous Diagnostic and Mitigation (CDM) Program.

To defend against urgent threats and vulnerabilities, CT collaborates with partners to implement training strategies and develop curricula to help cybersecurity staff address current cybersecurity threats. To secure against the ever-evolving cyber threat ecosystem, CT works with key stakeholders to identify, prioritize, and address cybersecurity training gaps.

This requirement is to continue to provide:

a) CDM synchronous and asynchronous training to effectively operate and maintain the

Cloud Virtual Learning Environment (CVLE) system including topics such as using the CDM Dashboard to respond to Federal Directives, Vulnerability and Risk Management within the CDM Dashboard, and using the CDM Agency Dashboard to Respond to Federal Directives- Binding Operational Directive (BOD) 22-01 & BOD 23-01.

b) A CVLE Lab where students can interact directly with a challenge/scenario (simulated) in a virtual environment and, through their actions, experience their own outcome. The lab activities are intended to be self-directed; therefore, they will not be offered in person.

LSJ No: FY-25-00253 3- 2 -

c) Cybersecurity Training Topics - This training targets the broader .gov enterprise and includes synchronous and asynchronous awareness and training topics, such as enterprise governance and risk management perspectives; high value assets; ongoing authorization; identity management; risk management framework; end-of-life software, Industrial Control Systems Cybersecurity and exercises, incident response, ransomware, resilience, digital forensics.

d) Cyber Awareness training and Basic Incident Response Training (BIRT), Ransomware for First Responders, and Vulnerability Management Assessments.

The Government intends to issue the task order to ensure continued operations of the current Cloud Virtual Learning Environment (CVLE) while potentially transitioning to a new Accredited and Authorized Cyber Range. The Government is refining new cloud security and infrastructure requirements to support a future Cyber Range and Virtual Learning Environment. Additionally, CISA’s Office of the Chief Information Officer (OCIO) is conducting ongoing analyses regarding the hosting of commercial cloud solutions similar to the existing CVLE. These new requirements and hosting infrastructure will fundamentally inform the technical scope of a larger training follow-on. Additionally, the new Virtual Learning Environment must go through Accreditation and Authorization (A&A) in order to receive an Authority to Operate (ATO) by DHS OCIO. While the new solution goes through its A&A activity, the current CVLE must be serviced and maintained during the duration of the 12-month performance period. The total cost is as described below:

Performance Period Amount September 30, 2025 – September 29, 2026

4. Authority and supporting rationale.

Authority: FAR 8.405-6(a)(1)(i)(B) Only one source is capable of providing the supplies or services required at the level of quality required because the supplies or services are unique or highly specialized.

Rationale:

Only Edgesource is capable of providing the services required at the level of quality required because the training curriculum development and hands-on lab delivery services ordered are highly specialized and unique. Edgesource provides high-level training, instructional design and delivery services to CISA and the entire Federal Civilian Executive Branch (FCEB) and Critical Infrastructure (CI) partners. This training includes end user instruction and custom hands-on labs for Departments and Agency Information Technology and Cyber Administrators to learn how to use the CDM Dashboard. Edgesource is also currently providing customized Incident Response and Cyber Forensic training and labs for all Federal employees to upskill both entry level and experienced operators. There is no other source capable of immediately delivering the quality required for the Governments immediate short-term needs. For the ongoing effort, Edgesource is uniquely qualified because it maintains the

LSJ No: FY-25-00253 3- 3 -existing virtual learning environment that has achieved an Authority to Operate (ATO) and it possesses critical and requisite technical knowledge and experience delivering training of quality required to meet CISA’s specific needs of various Major Acquisition programs with efficiency and precision. They have qualified staff who continue to maintain cloud/virtual lab infrastructure with the required base knowledge and experience with the programs.

Edgesource can make personnel immediately available for the time required for this effort.

Edgesource has the required number of personnel already in-place and cleared through all DHS/CISA security requirements, and to bring another vendor in for this short period would result in delays due to security processing and on-boarding.

An award to another contractor would require significant development effort to establish a training system and range. Additionally, that training system would require an ATO. This would lead to a significant gap in critical training for operational systems while the new system is being developed and authorized. Extending Edgesource to maintain their current training system while the government competes the new requirements and migrates cloud infrastructure will ensure no gap in services.

Therefore, Edgesource is uniquely qualified to meet the requirement. Their requisite experience and training infrastructure is necessary for ongoing support until the follow-on award. The follow-on task order award was anticipated in the the fourth quarter of fiscal year 2025. However, during procurement planning, the new administration identified a focus of consolidation for contracts and additional time was needed to address changes in the procurement structure and strategy. The anticipated new award will be made in the second quarter of fiscal year FY2026. Without Edgesource’s continued support, CB would assume substantial performance risk with detrimental impact to operations and severely diminish the quality of training services CB and CSD provides to its CI and FCEB partners. Edgesource is the only source that has the resources and experience in place necessary to provide CSD the required services without risking interruption in critical mission capabilities.

Edgesource’s continued support will prevent a lapse in service and disruption to daily operations during the time required to conduct the competitive procurement.

5. Determination by the ordering activity contracting officer that the anticipated order represents the best value consistent with FAR 8.404(d).

The Contracting Officer determined the anticipated prices will be fair and reasonable based on prior acquisition history. Furthermore, the Contracting Officer anticipates the prices will be fair and reasonable consistent with the General Services Administration (GSA) Multiple Award Schedule (MAS) contract held by Edgesource that includes fair and reasonable maximum rates.

6. A description of the market research conducted among schedule holders and the results, or a statement of the reason market research was not conducted.

LSJ No: FY-25-00253 3- 4 -

Market research was conducted from January through June 2025 and revealed that there are sufficient companies with the requisite capabilities and experience that could support the requirement but cannot immediately provide critical cyber and CDM Program training (a statutorily required program) to the number of FCEB end user cohorts. Without Edgesource’s continued training and CVLE support, the federal enterprise will be left with a significant gap in critical cybersecurity positions protecting IT infrastructure across CISA and FCEB.

7. Any other facts supporting the limited-sources justification. Additional facts may be stated in this section. If there are no additional facts, you must state that here.

None.

8. A statement of actions, if any, the agency may take to remove or overcome any barriers that led to restricted consideration (i.e., limited-sources) before any subsequent acquisition for the supplies or services is made.

No other competitive barriers are known at this time, which would lead to restricted consideration before any subsequent acquisition for the supplies of services is made. The Program Office’s market research identified potential sources for the follow-on requirement.

Preparations are underway for the follow-on requirement with an anticipated solicitation release in 2QFY26. This limited source task order is only intended to continue the current services until the competitive procurement is awarded.

9. DHS intends to post this requirement on System for Award Management (SAM.gov) pursuant to FAR 8.405-6(a)(2)(i).

LSJ No: FY-25-00253 3- 5 -

10. Technical/Requirements Personnel Certification.

Pursuant to FAR 8.405-6(c)(2)(x), I certify that this requirement meets the Government’s minimum need and that the supporting data, which form a basis for the Limited-Sources Justification, are accurate and complete.

Technical Representative/COR Date

11. Contracting Officer Certification and/or Approval

Pursuant to FAR 8.405-6(c)(2)(ix), I certify that the Limited-Sources Justification is accurate and complete to the best of my knowledge and belief:

Contracting Officer Date

12. Approval.

Procuring Activity Advocate for Competition or Designee Date

File details come from the government source that posted it. Updated .