RCCA-22-00420 NCP SSJ Redacted_Redacted.pdf
PDF 139 KB Posted
- Attached to
- Contract Award Notice - Micro-Challenges for Cyber Career Pathway Tool Users Federal contract opportunity
- Solicitation number
- 70RCSJ22C00000006
- Issued by
- Not on record
About this file
This document is a sole source justification for a firm fixed price contract awarded to University Enterprises Corporation at California State University, San Bernardino. The Cybersecurity and Infrastructure Security Agency requires specialized expertise to develop micro-challenges for the Nice Challenge Project to support the Cyber Career Pathways Tool on the National Initiative for Cybersecurity Careers and Studies website. The contract value is $102,022.56 for a one year base period from September 30, 2022 to September 29, 2023. Market research found that University Enterprises Corporation is the only organization with access to host and maintain challenges on the existing Nice Challenge Project infrastructure, making it the only source capable of meeting the requirement. No other vendors responded to the notice of intent or synopsis published on SAM.gov.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Award Notice.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sole Source Justification (SSJ) FAR subpart 13.5, including Brand Name
SSJ No.: 1
SSJ No.:
Date: 9/26/2022 PR Number:
Pursuant to the requirements at 41 U.S.C. 1901 as implemented by Federal Acquisition Regulation (FAR) subpart 13.5 and consistent with the content requirements of FAR 6.303-2.
1. Agency and Contracting Activity. Identification of the agency and the contracting activity, and specific identification of the document as a “sole source justification.”
The Department of Homeland Security, Cybersecurity and Infrastructure Security Agency (CISA) Chief of the Contracting Office (COCO) proposes to enter into a purchase order on a basis of other than full and open competition.
2. Nature and/or description of the action being approved.
This Justification and Approval (J&A) supports the action for a firm fixed price (FFP) sole source contract to obtain specialized expertise to assist in developing the Nice Challenge Project (NCP) content and curriculum for colleges, universities, and other higher education institutions from University Enterprises Corporation (UEC) at California State University, San Bernardino (CSUSB), 5500 University Parkway, San Bernardino, CA 92407. This contract will be a 12 month base contract with a total contract value of . Fiscal Year (FY) 2022 Operation and Maintenance (O&M) appropriated funds are available for this effort. The Period of Performance for this requirement is 30 September 2022 through 29 September 2023.
3. Description of Supplies/Services. Describe the supplies or services to be acquired. Provide the estimated total value (including options, if any).
CISA has an immediate need to create a robust pipeline of highly qualified cybersecurity professionals to meet the workforce demands of today and the future. The dangerous shortage of skilled cybersecurity professionals in the United States (U.S.) is a threat to our businesses and puts our cyber and physical infrastructures at risk. Without prompt actions, this shortage of skilled cybersecurity professionals may become a national security threat. It requires tools for students and professionals, whether reskilling or retooling, to explore the knowledge, skills, and tasks of the everyday cybersecurity professional.
The requirement is to develop National Initiative for Cybersecurity Education (NICE) Challenge Project micro-challenges as resources for cybersecurity awareness and career exploration supporting the Cyber Careers Pathway Tool on the National Initiative for Cybersecurity Careers and Studies (NICCS™) website. Content and services include developing cybersecurity critical infrastructure micro-challenges linked to the Cyber Career Pathways Tool, project management, content delivery, and customer service.
SSJ No.: 2
This purchase order will provide specialized expertise to develop Nice Challenge Project (NCP) content and curriculum for the NICCS™ Cyber Careers Pathways Tool. Specific support includes:
(a) Development of micro-challenges using the NICE Cybersecurity Workforce
Framework and the CAE-CD KUs.
(b) Maintenance of the micro-challenge infrastructure, including the underlying learning management system or platform.
(c) Delivering all micro-challenges to CISA for inclusion on the Cyber Career Pathways
Tool. Delivery activities include ensuring all challenges and curriculum map to the NICE Framework, product packaging, and marketing.
(d) Providing program management support and customer service for micro-challenges connected to the NICCS™ website. Customer service includes responding to user inquiries and complaints, providing technical assistance and workshops, and informing users of any planned maintenance or updates.
Period Unit Unit Price Total Base Year 12 mo
4. Identification of the authority.
This action is being taken in accordance with 41 U.S.C. 1901 as implemented by FAR subpart 13.5 Simplified Procedures for Certain Commercial Products and Commercial Services.
5. Demonstration that the proposed contractor’s unique qualifications or the nature of the acquisition requires use of the authority cited.
(a) CISA works closely with our partners at the National Security Agency (NSA) to build the pipeline of qualified cybersecurity professionals entering the workforce through the National Centers of Academic Excellence in Cybersecurity Program. The NCP is one of the resources developed under this partnership and available for free (through current NSA grant funds) to all National Centers of Academic Excellence in Cybersecurity (NCAE-C) designated institutions. One of the key aspects of this project is the development of content and curriculum to be hosted on the current, existing NCP that is available to colleges and universities within the NCAE-C program. UEC is the developer/host of the NCP and is the only organization with the intellectual property rights to update/maintain it. NSA utilizes the NCP to provide for colleges, universities, and other higher education institutions access to the NICE cyber challenges that CISA would provide. Consequently, University Enterprises Corporation (UEC) at California State University, San Bernardino (CSUSB) is the
SSJ No.: 3 only source with the required cyber range and access to the existing NCP capable of performing the work.
(b) CISA reviewed GSA Schedules, Categories for Professional Services Off the Shelf
Training Devices and Training Materials (33318TDTM) and Educational Support Services (611710) to determine whether the contractors listed have an existing cyber range capacity. A cyber range is a controlled, interactive technology environment where cybersecurity professionals can learn how to detect and mitigate cyber-attacks using the same kind of equipment they will have on the job. While several vendors do create cyber curriculum, none have existing cyber ranges, nor do they have access to the existing NCP.
Since no vendor within the GSA Schedule met the requirements, CISA researched academic institutions as they are at the forefront of cyber range curriculum and content development. UEC is the only organization with access to host/maintain the in-house developed NICE Challenge cyber range platform, which is free to all universities and higher educational institutions. Only one (UEC) institution identified in the market research has access to the existing NCP and would be immediately capable of having a contract awarded to them.
(c) CISA’s specific requirement is to support the NCP by developing and maintaining new challenges/curriculum, at no cost, to academia and the wider public. UEC is the only organization with the unique capability of fulfilling the requirement as required because it is the only vendor with the ability to operate/maintain challenges on the NCP. Other vendors do not have the access to operate/maintain the NCP, which prevents them from fulfilling this requirement.
6. Description of efforts made to ensure that offers are solicited from as many potential sources as is practicable.
The Notice of Intent (NOI) RCCA-21-00157 was made in SAM.gov from July 14, 2021 to July 29, 2021, in search for not-for-profit organizations. Unfortunately, no not-for profit vendors responded to the NOI. On September 21st, 2022 the requirement was Synopsised through SAM.gov for two days and closed on 23 September with no responses received.
7. Determination by the contracting officer that the anticipated cost to the Government will be fair and reasonable.
The contracting officer determined issuing the proposed purchase order to UEC for NCP micro-challenges development/support represents the best value and will result in the lowest overall cost, considering price and administrative costs, to meet the Government’s needs.
According to market search, UEC’s labor categories and rates are comparable to GSA rates for similar services. The NCP was created and developed by the faculty and students at CSUSB. Any other vendor would need to purchase the rights to create/add additional
SSJ No.: 4 content and curriculum to the NCP. In addition, the development team at CSUSB maintains the deep technical knowledge of NCP its infrastructure, academic content and curriculum building, including instructional design and scaffolding, as well as pathways for institutional buy in.
8. Description of market research.
In April 2021, CISA initially reviewed GSA Schedules, Categories for Professional Services Off the Shelf Training Devices and Training Materials (33318TDTM) and Educational Support Services (611710) to determine whether the contractors listed has an existing cyber range capacity. While several vendors have created cyber curriculum, none have existing cyber ranges, nor do they have access to the existing NCP. Since no vendor within the GSA Schedule met the requirements, CISA researched academic institutions as they are at the forefront of cyber range curriculum and content development. This research identified a few universities, which did have the necessary cyber ranges to present challenges/curriculum.
However, access to those cyber ranges was limited to students enrolled in the university’s cyber programs. The purpose of the NCP is to offer free and open access to students in all universities and higher learning institutions in order to increase the total number of cyber professionals.
Finally, a Notice of Intent to Sole Source, RCCA-21-00157, was released in SAM.gov from July 14, 2021 to July 29, 2021. Unfortunately, no not-for profit vendors responded to the NOI, and instead four (4) for-profit entities expressed interest in the requirement:
CYBRScore, Wyvern Security, WIN LLC, and DMS International responded. It was determined to proceed with a sole source requirement with an UEC which is a not-for profit organization, and an entity which holds exclusive rights to develop the existing NCP. The Program Office remains in contact with industry.
The program team’s continued market research efforts from interviews and reviews indicate only UEC at CSUSB holds exclusive rights to develop challenges on the existing NCP infrastructure. Access to the currently established NICE Challenge Project (virtual hands-on labs with cybersecurity content and curriculum) is required. Any organization’s cyber range must have the NCP infrastructure to support colleges, universities, and other academic institutions free of cost. Market research concluded GSA’s Federal Supply Schedule vendors do not have the necessary cyber range and/or access to NCP required to do the work.
Additionally, universities who do have cyber ranges do not have access to NCP to provide free cyber range free of charge to all universities and education institutions.
9. Any other facts supporting the justification.
The intent of the requirement for the micro-challenges using the existing NICE Challenge Infrastructure is to make it available to the public free of cost. By utilizing UEC at CSUSB, a not-for profit public university, who holds exclusive rights to develop challenges on the existing NCP infrastructure, CISA is able to support cybersecurity content and curriculum to colleges, universities, and other academic institutions free of cost.
SSJ No.: 5
If the contract is not awarded and services are not acquired, CISA will not be able to expand the Cyber Career Pathways Tool, one of the premier tools on the NICCS™ website, to provide career discovery and exploration to the public. The NICE micro-challenges project is intended to provide career discovery and exploration by allowing the public to complete micro-challenges in NICE cybersecurity workforce roles.
10. A listing of the sources, if any that expressed, in writing, an interest in the acquisition.
A NOI to Sole Source was issued in SAM.gov in July 2021, requesting that parties express their interest in writing to the Contracting Officer. Only four (4) for profit vendors responded: CYBRScore, Wyvern Security, WIN LLC, and DMS International responded. On September 21st, 2022 the requirement was Synopsised through SAM.gov for two days and closed on 23 September with no responses received.
11. A statement of the actions, if any, the agency may take to remove or overcome any barriers to competition before any subsequent acquisition for supplies or services required.
Market research will be conducted for future requirements. Future CISA support to the NCP must be aligned with the NSA’s plans for operation and maintenance of the NCP. NSA and CISA partner to sponsor the NCAE-C program and each allocate funding as available to support the NCP to enhance cybersecurity education.
12. DHS intends to post the requirement pursuant to FAR 13.501(a)(1)(iii) and 6.305(a).
13. Technical/Requirements Personnel Certification. I certify this requirement meets the Government’s minimum need and that the supporting data, which forms a basis for this justification, is complete and accurate.
Technical Representative/COR
Date
14. Contracting Officer Certification
Contracting Officer: Jason Hawkins Date
JASON S
HAWKINS
Digitally signed by JASON S
HAWKINS
Date: 2022.09.26 09:22:06 -04'00'
9/26/22
9/26/22
SSJ No.: 6
15. Approval:
Procuring Activity Advocate for Competition Date
ANTOINETTE CLAY
Digitally signed by ANTOINETTE
CLAY
Date: 2022.09.26 21:52:26 -04'00'
09/26/2022
File details come from the government source that posted it. Updated .