SSN_Enterprise Cybersecurity Spt Srvs_DCSA_CYBERSSN_25.pdf

PDF 240 KB Posted

Attached to
DCSA Enterprise Cybersecurity Support Services Federal contract opportunity
Solicitation number
DCSA_CYBERSSN_25
Issued by
Defense Counterintelligence and Security Agency

About this file

This is a Sources Sought Notice issued by the Defense Counterintelligence and Security Agency (DCSA) for market research to determine the availability and technical capabilities of Certified 8(a) companies to provide Enterprise Cybersecurity Support Services. The notice seeks vendors who can support DCSA's cybersecurity mission, with a focus on services including developing cybersecurity plans, assisting with Authorization & Assessment processes, implementing cybersecurity frameworks, conducting product analysis, managing media destruction, reviewing workforce improvement programs, using cyber threat detection tools, and supporting enterprise security operations.

Interested 8(a) vendors must submit a 15-page capabilities statement by May 20, 2025, at 5:00 PM EST to Sherrita Muse and Kelsie Kautz via email. The capabilities statement should detail the firm's experience with cybersecurity support services for a DoD customer, including past performance within the last 3-5 years, contract details, personnel capabilities, and experience with specific software products like Axonius, CyberArk PAM, Splunk Cloud, and others. The place of performance is in the National Capital Region, and an active Top Secret Facility Clearance is required. The NAICS code is 541513 (Computer Facilities Management Services) with a business size standard of $37.0M.

View the file

Other files for this federal contract opportunity

Other files attached to DCSA Enterprise Cybersecurity Support Services, newest first.
File Type Posted
PRIOR POST INFO - DCSA_CYBERSSN_25.pdf PDF
DCSA_CYBERSSN_25 QNAs.pdf PDF
Atttch 1_SSN_Enterprise Cybersecurity Spt Srvs_DCSA_CYBERSSN_25.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sources Sought Notice Defense Counterintelligence and Security Agency

Enterprise Cybersecurity Support Services

Background This is a Sources Sought Notice issued by the Defense Counterintelligence and Security Agency (DCSA) for Market Research purposes only to determine the availability and technical capability of Certified 8(a) companies to provide Enterprise Cybersecurity Support Services. As permitted by Federal Acquisition Regulation (FAR) 10 “Market Research”, and FAR 15.201(e), responses to this notice are not offers and cannot be accepted by the U.S.

Government to form a binding contract. Not responding to this Notice does not preclude participation in any future RFP or RFQ. All responses to this request become the property of the Federal Government and will not be returned.

DCSA is an agency of the Department of Defense (DoD), headquartered in Quantico, Virginia, providing security services to the DoD, Military Components, Executive Branch Departments and Agencies, and approximately 10,000 cleared Contractor facilities under the direction, authority and control of the Under Secretary of Defense for Intelligence and Security. The DCSA Office of the Chief Information Officer (OCIO) provides automated information systems and telecommunications in support of this mission. The mission of protecting information and information systems within DCSA and industry partners is an ongoing endeavor. Adversaries continue to present a persistent threat taking advantage of new forms of intrusion, malware, and data exfiltration. By using new technology advances and adjusting focus on potential vulnerabilities, DCSA can strengthen cybersecurity activity and defensive cyber operations.

DCSA is seeking information from Certified 8(a) vendors ONLY regarding capabilities to provide Enterprise Cybersecurity Support Services in support of the DCSA OCIO mission.

Sources Sought Details This Sources Sought Notice is issued solely for informational and planning purposes – it does not constitute a RFP or a promise to issue a RFP in the future. This Notice does not commit the Government to contract for any supply or service whatsoever. Further, DCSA is not at this time seeking proposals and will not accept unsolicited proposals.

Responders are advised that the U.S. Government will not pay for any information or administrative costs incurred in response to this Notice; all costs associated with responding will be solely at the interested Vendor’s expense.

Proposed NAICS and PSC The NAICS code contemplated for this requirement is 541513 – Computer Facilities Management Services. This particular NAICS code has a Business Size Standard of $37.0M.

The PSC contemplated for this requirement is DJ01 – IT and Telecom – Security and Compliance Support Services (Labor).

Objective/Scope The overall objective of this potential requirement is to provide comprehensive cybersecurity support to the current enterprise and programs, and transformational cybersecurity support for the future DCSA organizational enterprise. Listed below are the functions necessary to carry out this objective:

• Provide knowledge-based support to help DCSA continue developing cybersecurity for the Agency, to include cloud environments;

• Provide knowledge-based support to help DCSA in the continued cybersecurity integration of the Enterprise Data Management (EDM) for the Agency;

• Provide assistance with the DCSA Authorization & Assessment (A&A) process to ensure the Risk Management Framework is implemented on DCSA systems;

• Provide assistance with DCSA systems to ensure the cybersecurity framework is implemented for identifying, protecting, detecting, responding to, and recovering from cyber threats & vulnerabilities;

• Conduct approved product analysis, to recommend products being considered for inclusion on the DCSA networks ensuring they are properly and uniformly analyzed for compliance with DoD and DCSA security requirements and best practices;

• Provide support with issuance and technical assistance with Non-Classified Internet Protocol Router Network (NIPRNet), Secret Internet Protocol Router Network (SIPRNet) and Joint Worldwide Intelligence Communications System (JWICS) tokens and Unclassified – Top Secret media destruction of various types of media and guidance to DCSA personnel;

• Review Cyber Workforce Improvement program reports/artifacts to ensure validation of requirements to obtain/maintain network access;

• Provide and perform incident response, forensics, threat hunt, and cyber operations test and evaluation for the Agency;

• Use Tools to detect, analyze, counter, and mitigate cyber threats and vulnerabilities; as well as to maximize user accessibility and functionality;

• Provide configuration and change management practices to establish and maintain consistency of a product or system’s attributes with its requirements and evolving technical baseline over its life;

• Ensure supply chain risk management is supported from a risk-based approach by conducing assessments. Provide support for securely onboarding and off-boarding personnel.

The DCSA-enterprise cybersecurity mission encompasses the cybersecurity systems engineering, secure systems integration, cybersecurity, oversight activities of its data management, and related cybersecurity technology efforts. The types of contractor-provided enterprise cybersecurity support services may include:

• Cyber Data Management

• Cybersecurity Engineering

• Cloud Security Engineering

• Cybersecurity Risk Management

• System Lifecycle Risk Management – Change and Configuration Management

• Cyber Defense Operations

• Cyber Compliance Support

• Cyber Publication Services

Place of Performance For informational purposes, the place of performance for this notice consists of the National Capital Region (NCR) to include Quantico, Virginia and Hanover, Maryland.

Security Requirement This potential effort requires an active Top Secret Facility Clearance.

8(a) Partnerships and Joint Ventures For interested 8(a) Joint Ventures (JV), the firm shall indicate if the 8(a) JV itself or the individual partner(s) to the 8(a) JV hold the required security clearance.

Task Elements Interested 8(a) vendors submitting capability responses to this Notice should address their performance experience and capability related to the service requirement Tasks Elements (listed in Attachment 1). Interested parties should NOT submit marketing materials; but rather, speak directly and specifically to the required capabilities and services, in the Task Elements of Attachment 1.

Submission Requirements Interested 8(a) vendors should submit a response to include a capabilities statement covering experience, staffing and technical capabilities. The capabilities statement should address the Task Elements identified in Attachment 1. For each of the Task Elements, demonstrate how the firm’s recent past performance (within 3-5 years) is relevant to the Task Elements listed, including the dollar value, period of performance, size and scope of the vendor’s prior contracts.

Capability statements should not exceed 15 pages, using Times New Roman 12-inch font on 8.5 x 11 paper. Respondents must submit documents in Word or PDF format. Zipped files and/or telephone requests will NOT be accepted/honored.

Vendors must demonstrate their ability to comply with the requirements in this Sources Sought Notice in order to be considered capable of satisfying the Government’s requirement.

All correspondence must include the subject line: “DCSA_CYBERSSN_25 (Vendor name)”

Confidentiality Proprietary information and trade secrets, if any, must be clearly marked on all materials. All information received that is marked “Proprietary” will be handled accordingly. Please be advised that all submissions become Government property and will not be returned. All Government and Contractor personnel reviewing responses will have signed non-disclosure agreements and understand their responsibility for proper use and protection from unauthorized disclosure of proprietary information as described 41 USC 423. The Government shall not be held liable for any damages incurred if proprietary information is not properly identified.

The Government reserves the right to use any information provided by respondents for any purpose deemed necessary and legally appropriate, including using technical information provided by respondents in any resultant solicitation. Responses to this Notice will not be returned.

Submission Instructions Interested 8(a) Participants having the capability to provide Enterprise Cybersecurity Support Services shall submit responses no later than 20 May 2025 at 5:00 PM EST. Capability statements/responses shall be submitted to the following contacts only, with Subject Line:

DCSA_CYBERSSN_25 (Vendor name) Contract Specialist: Sherrita Muse, at sherrita.d.muse.civ@mail.mil, Contracting Officer: Kelsie Kautz, at kelsie.kautz.civ@mail.mil

No hard copy submissions will be accepted. Submissions to any contact other than the one listed above will not be considered. Submissions after this date may not be considered. Cover letters and extraneous materials (marketing, brochures, etc.) will not be considered.

No questions or phone calls will be accepted concerning this Sources Sought Notice. All firms responding to this Sources Sought Notice are advised that the Government may not provide or acknowledge receipt of the information received, provide feedback to firms with respect to any information submitted, or provide any follow-up information well after the deadline of this sources sought notice. DCSA will respond to questions at its discretion. The Government will not respond to further questions regarding the anticipated date of solicitation release.

Capability Statements To facilitate a timely and comprehensive review of all submitted responses, firms should respond using the format requested in this Notice. Any deviation from this format may lead to the rejection of the response.

mailto:sherrita.d.muse.civ@mail.mil mailto:kelsie.kautz.civ@mail.mil

Please provide the following information for your firm and for any teaming or joint venture partners:

***PLEASE ADDRESS THE FOLLOWING ELEMENTS WITHIN YOUR CAPABILITY

STATEMENT***

Responses shall include the following information, at a minimum:

1. General Information:

a. Entity Information

i. Company/Institute Name, address, point of contact name, telephone, and email address.

ii. CAGE Code and Unique Entity Identifier (UEI).

iii. Company/Institute Website.

iv. A statement as to whether your company/institute is domestically or foreign owned (if foreign, please indicate the country ownership).

v. A declaration of the company’s facility clearance level. If a required clearance impacts your ability to support this requirement, please indicate and explain how.

b. Business Type

Business size and classification (e.g., large, small, small-disadvantaged, SBA Certified 8(a), HUBZone, service-disabled veteran-owned) based on NAICS:

541513 – Computer Facilities Management Services.

c. Contract Vehicles

Indicate any existing contracting vehicles a future DCSA contract award may be placed against.

d. NAICS and PCS Code Recommendations

Provide confirmation if the existing codes are sufficient, or recommend new codes.

e. Teaming Arrangements

If applicable, potential proposed teaming arrangements to include business size and classification of prime and subcontractors.

f. Similar Efforts

Identify contracts your company has been awarded under NAICS: 541513 – Computer Facilities Management Services. Additional information on NAICS codes can be found at www.sba.gov http://www.sba.gov/

2. Technical Capability:

a. Provide a brief synopsis to support the firm’s ability to perform all of the Task Elements identified in Attachment 1. Identify each task element and provide information to support the firm’s experience, staffing and overall ability to perform the technical area.

b. Evidence of experience and past performance should include contracts/task orders from the past three to five (3-5) years similar in scope to this requirement. Specify whether the work was performed by the firm as the Prime or a Subcontractor.

c. Examples must include contract numbers, project titles, dollar amounts, periods of performance, and Government points of contact (telephone numbers or email addresses)

d. Documented information to support the firm’s ability to provide the personnel required for this effort in a timely fashion who are United States citizens and have the ability to work within 100 miles of the National Capital Region (NCR).

e. Provide any data on previous contracts/task orders on personnel retention.

f. Briefly summarize what experience that your company has with providing comprehensive, enterprise level cybersecurity support services and performing the following functions for a DoD customer:

• Developing cybersecurity plans/procedures for information systems, to include cloud environments

• Assisting with Authorization & Assessment (A&A) in accordance with (IAW)

Department of Defense Instruction (DoDI) 8510, Risk Management Framework

• Ensuring cybersecurity framework is implemented for identifying, protecting, detecting, responding to, and recovering from cyber threats & vulnerabilities, IAW DoDI 8530

• Conducting approved product analysis to ensure uniformity with DoD security requirements

• Media destruction of various types of media devices

• Review Cyber Workforce Improvement program reports/artifacts to ensure validation of requirements to obtain/maintain network access IAW DoD-M 8570 and DoDI 8140

• Using Tools to detect, analyze, counter, and mitigate cyber threats and vulnerabilities

• Providing configuration and change management practices

• Ensuring supply chain risk management is supported from a risk-based approach

• Supporting implementation of Zero Trust to systems and devices IAW DoD

Zero Trust Reference Architecture

• Providing support, identification and integration of innovative/breakthrough technologies (Artificial Intelligence enabled solutions)

• Providing Support for the Enterprise Security Operations Centers

• Providing incident response, forensics, and threat hunt services.

• Supporting Pen Testing Services (Red team/Blue team)

• Performing cybersecurity integration of the Enterprise Data Management

• Developing cybersecurity dashboards for transparency and accountability

g. Provide a summary of experience using any of the following software products:

• Axonius

• Cellebrite

• Cobalt Strike

• CyberArk PAM

• Mandiant

• FireEye

• ForeScout

• HBSS Trelix (ESS)

• Magnet Axiom

• Rapid 7

• Splunk Cloud

• ACAS

• CrowdStrike

• eMASS

• Microsoft Power Apps / SharePoint

h. A summary of experience managing the following:

• PKI, Change Management, and Media Destruction program

• Cybersecurity validations

• Security Operations Center (SOC), as well as conducting penetration and forensics investigations

• Cyber risk assessments

• Preparing for cybersecurity audits

• Cyber workforce compliance

Vendor Follow-on Meetings

DCSA representatives may or may not choose to meet with potential vendors. Such meetings would only be intended to obtain further clarification of potential capability to meet future or existing requirements.

Summary

This information is being requested to identify potential sources that can provide support pertaining to the subject requirement. The information provided in the Sources Sought is subject to change and is not binding on the Government. DCSA has not made a commitment to procure any of the items discussed, and release of this Sources Sought should not be construed as such a commitment or as authorization to incur costs for which reimbursement would be required or sought. All submissions become Government property and will not be returned.

File details come from the government source that posted it. Updated .