Solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS)

Closed Solicitation Posted

This opportunity was awarded. See the award notice from , or the latest solicitation from .

Solicitation number
70RTAC22R00000010
Agency
Office of Procurement Operations Department of Homeland Security
Responses due
Set-aside
No set-aside

Opportunity facts

NAICS code
541519 Other Computer Related Services
PSC
DJ01 It And Telecom - Security And Compliance Support Services (Labor)

Notice details come from SAM.gov. Updated .

About this opportunity

The Department of Homeland Security seeks proposals for crowdsourced vulnerability assessment services to identify security issues within DHS systems through the Hack DHS program. Vendors must provide a vulnerability disclosure platform and maintain an active security researcher community of over 1,000 members to conduct assessments. Proposals will be evaluated on technical approach, past performance, and pricing, with awards as fixed price IDIQ contracts for an one year base period and four optional one year extensions. Phase 1 proposals are due by June 27, 2022.

The solicitation does not include any set-aside designations. The primary NAICS code is 541511 and PSC code is D302. There is no mention of incumbent or current contractors. The cumulative contract ceiling is $43 million to be awarded across a minimum of three to maximum of four contracts. Services will involve up to six time boxed challenges and two continuous assessments annually. Place of performance will be within the United States to comply with DHS data security requirements.

Notice text

3 versions

Update #3 · Latest ·

___

07.27.2022

Dear Industry Partners, 

The above-referenced Request for Proposal (RFP) has been cancelled due to requirements changes and DHS plans to issue a new RFP within the next month. Please continue to check SAM.gov for future updates concerning this requirement.

Thank you. 

___

06.22.2022

Dear Industry Partners,

The Department of Homeland Security (DHS) is issuing Amendment 0001 to the Hack DHS CVAS solicitation. This amendment 1) extends the proposal deadline for Phase 1 to June 27, 2022 at 12pm ET; 2) provides responses to vendor questions on the final Request for Proposal (RFP); 3) updates RFP to reflect the updated proposal deadline for Phase 1; and 4) provides the updated RFP Attachment J.2 Performance Work Statement (PWS).

Solicitation Amendment Changes:

Changes have been made to the following sections of the solicitation:

  • RFP Cover Page - Combined Synopsis/Solicitation Notice (page 1), Item (9)
  • RFP Section L, Instructions, Conditions, and Notices to Offerors or Respondents
    • Subsections L.2 (page 64) and L.4 (page 65)
  • RFP Attachment J.2 - PWS
    • Subsections 2.0 (page 6) and 2.2.4 (page 8)

Changes are highlighted in yellow.

Solicitation Amendment Documents:

The following documents are included as part of this solicitation amendment:

  • Amendment 0001_RFP 70RTAC22R00000010_Responses to Vendor Questions on Final RFP
  • Amendment 0001_RFP 70RTAC22R00000010
  • Amendment 0001_RFP 70RTAC22R00000010_SF30
  • Amendment 0001_RFP Attachment_J.2 - PWS

___

06.09.2022

This is a final solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS). Please see the attached documents for more information. 

Attachments: 

Responses to Vendor Questions on DRAFT RFP

RFP 70RTAC22R00000010

RFP 70RTAC22R00000010 J.1 - SF1449

RFP 70RTAC22R00000010 J.2 - PWS

RFP 70RTAC22R00000010 J.3 - Cert of IDIQ VDDP Platform Compliance

RFP 70RTAC22R00000010 J.4 - Cert of Active Researcher Community

RFP 70RTAC22R00000010 J.5 - Cert of HSAR 3052.204-70 and Data Req

RFP 70RTAC22R00000010 J.6 - Past Performance Questionnaire

RFP 70RTAC22R00000010 J.7 - Pricing Template

Update #2 ·

___

06.22.2022

Dear Industry Partners,

The Department of Homeland Security (DHS) is issuing Amendment 0001 to the Hack DHS CVAS solicitation. This amendment 1) extends the proposal deadline for Phase 1 to June 27, 2022 at 12pm ET; 2) provides responses to vendor questions on the final Request for Proposal (RFP); 3) updates RFP to reflect the updated proposal deadline for Phase 1; and 4) provides the updated RFP Attachment J.2 Performance Work Statement (PWS).

Solicitation Amendment Changes:

Changes have been made to the following sections of the solicitation:

  • RFP Cover Page - Combined Synopsis/Solicitation Notice (page 1), Item (9)
  • RFP Section L, Instructions, Conditions, and Notices to Offerors or Respondents
    • Subsections L.2 (page 64) and L.4 (page 65)
  • RFP Attachment J.2 - PWS
    • Subsections 2.0 (page 6) and 2.2.4 (page 8)

Changes are highlighted in yellow.

Solicitation Amendment Documents:

The following documents are included as part of this solicitation amendment:

  • Amendment 0001_RFP 70RTAC22R00000010_Responses to Vendor Questions on Final RFP
  • Amendment 0001_RFP 70RTAC22R00000010
  • Amendment 0001_RFP 70RTAC22R00000010_SF30
  • Amendment 0001_RFP Attachment_J.2 - PWS

___

06.09.2022

This is a final solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS). Please see the attached documents for more information. 

Attachments: 

Responses to Vendor Questions on DRAFT RFP

RFP 70RTAC22R00000010

RFP 70RTAC22R00000010 J.1 - SF1449

RFP 70RTAC22R00000010 J.2 - PWS

RFP 70RTAC22R00000010 J.3 - Cert of IDIQ VDDP Platform Compliance

RFP 70RTAC22R00000010 J.4 - Cert of Active Researcher Community

RFP 70RTAC22R00000010 J.5 - Cert of HSAR 3052.204-70 and Data Req

RFP 70RTAC22R00000010 J.6 - Past Performance Questionnaire

RFP 70RTAC22R00000010 J.7 - Pricing Template

Update #1 ·

___

This is a final solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS). Please see the attached documents for more information. 

Attachments: 

Responses to Vendor Questions on DRAFT RFP

RFP 70RTAC22R00000010

RFP 70RTAC22R00000010 J.1 - SF1449

RFP 70RTAC22R00000010 J.2 - PWS

RFP 70RTAC22R00000010 J.3 - Cert of IDIQ VDDP Platform Compliance

RFP 70RTAC22R00000010 J.4 - Cert of Active Researcher Community

RFP 70RTAC22R00000010 J.5 - Cert of HSAR 3052.204-70 and Data Req

RFP 70RTAC22R00000010 J.6 - Past Performance Questionnaire

RFP 70RTAC22R00000010 J.7 - Pricing Template

Attachments

Show all 13

Notice history

Notices posted for this opportunity, newest first
Notice Type Posted
Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Award Award Notice
Solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Latest solicitation Solicitation
Solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) This notice Solicitation
DRAFT Solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Pre-Solicitation
Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Original Pre-Solicitation

On GovTribe

Work this opportunity on GovTribe

  • Track it in your pipeline
  • Find teaming partners
  • Similar opportunities
  • Ask GovTribe AI about this opportunity