Contacts, documents and full notice history are available with a subscription.
Sources Sought Expired 3 notices 2 documents

Vulnerability Disclosure Program Enterprise Management System (VDP EMS) FA701425X000X

Solicitation FA701425X000X Copied Notice ID 4b284fa106f04cb4840675eb4d3cd9bd Copied DEPT OF DEFENSE — FA7014 AFDW PK
SAM.gov
Posted
Jul 03, 2025
Deadline
Jul 10, 2025
Set-aside
None
NAICS
541519
PSC
7A21

Summary

AI-generated · Aug 24, 2025

Enterprise-wide management for Vulnerability Disclosure Programs is being sought. The system must provide an enterprise-grade VDP platform license/subscription for two instances (DoD VDP and DIB VDP) with capabilities for vulnerability submission and management workflows, API integration with the DC3’s Jira-based Vulnerability Report Management Network, mediation support for researcher inquiries, and processes for effective triage and resolution (including CVSS scoring), plus advanced analytics, custom reporting, and a dedicated account team with ongoing support and customer success. Vendors are invited to review the draft Performance Work Statement and provide feedback.

New information includes an amendment extending the response date to 18 July 2025, and Q&A clarifications indicating a preference for a proprietary, crowdsourced VDP platform license (specifically HackerOne, BugCrowd, or SynAck) rather than integrator-only solutions. The Q&A also clarifies logistics responsibilities for distributing DC3 swag (up to about 250 items annually) to researchers, including verifying addresses and handling shipping. This remains a market research/ Sources Sought activity with feedback on the PWS encouraged.

The Department of Defense Cyber Crime Center (DC3) is conducting market research for an enterprise management system to support its Vulnerability Disclosure Program (VDP) and Defense Industrial Base (DIB) VDP. The system shall facilitate collaboration, compliance, and management of the VDPs. Key requirements include: Enterprise-grade VDP platform license/subscription for two instances (DoD VDP and DIB VDP). Vulnerability submission and management workflows. Integration, via API, with DC3's Atlassian Jira-based Vulnerability Report Management Network (VRMN) systems. Mediation support for researcher inquiries. Tools and processes for effective vulnerability triage and resolution (e.g., CVSS scoring). Advanced analytics and custom reporting capabilities. Dedicated account team with customer support and customer success functions. Interested vendors are encouraged to review the attached draft Performance Work Statement (PWS) for detailed requirements and provide feedback on the PWS.

From Sources Sought posted on Jul 03, 2025

The Department of Defense Cyber Crime Center (DC3) is conducting market research for an enterprise management system to support its Vulnerability Disclosure Program (VDP) and Defense Industrial Base (DIB) VDP. The system shall facilitate collaboration, compliance, and management of the VDPs. Key requirements include: Enterprise-grade VDP platform license/subscription for two instances (DoD VDP and DIB VDP). Vulnerability submission and management workflows. Integration, via API, with DC3's Atlassian Jira-based Vulnerability Report Management Network (VRMN) systems. Mediation support for researcher inquiries. Tools and processes for effective vulnerability triage and resolution (e.g., CVSS scoring). Advanced analytics and custom reporting capabilities. Dedicated account team with customer support and customer success functions. Interested vendors are encouraged to review the attached draft Performance Work Statement (PWS) for detailed requirements and provide feedback on the PWS. 7/14/2025 - Amended solicitation to extend response due date to 18 Jul 2025.

From Sources Sought posted on Jul 15, 2025

During the RFI phase of this requirement, two questions were received. The questions and answers are provided below. Please review the Q&A and keep them in mind when the official solicitation is published. This RFI has NOT been extended further. Question 1: Is the Government specifically seeking vendors who can provide a proprietary, crowdsourced VDP platform license (e.g., HackerOne, Bugcrowd), or will you also consider integrators who can deliver compliance, security automation, and Microsoft Sentinel-based triage/reporting workflows in partnership with a platform provider? DC3 is directly seeking a proprietary, crowdsourced VDP platform license; Hackerone, BugCrowd, SynAck. Anything outside of this would impact mission success. Question 2: Can you clarify the 250 crowdsourced vulnerability - bug tag and annual mailings ? Understand the concept here is that we would be responsible for the logistics and shipping of any DC3 provided items used to recognize researchers. This would be in regard to delivering swag (inexpensive tangible goods like stickers, coins, t-shirts) to the researcher community. Specifically, DC3 disseminates swag for things such as hacker of the month or hacker of the year. The vendor will be responsible for distributing the swag on DC3 s behalf (verifying mailing addresses, packaging swag, paying for the shipping, getting the swag to the shipper, etc). End Questions and Answers --------------------------------------------------------------------- The Department of Defense Cyber Crime Center (DC3) is conducting market research for an enterprise management system to support its Vulnerability Disclosure Program (VDP) and Defense Industrial Base (DIB) VDP. The system shall facilitate collaboration, compliance, and management of the VDPs. Key requirements include: Enterprise-grade VDP platform license/subscription for two instances (DoD VDP and DIB VDP). Vulnerability submission and management workflows. Integration, via API, with DC3's Atlassian Jira-based Vulnerability Report Management Network (VRMN) systems. Mediation support for researcher inquiries. Tools and processes for effective vulnerability triage and resolution (e.g., CVSS scoring). Advanced analytics and custom reporting capabilities. Dedicated account team with customer support and customer success functions. Interested vendors are encouraged to review the attached draft Performance Work Statement (PWS) for detailed requirements and provide feedback on the PWS. 7/14/2025 - Amended solicitation to extend response due date to 18 Jul 2025.

From Sources Sought posted on Jul 24, 2025

Notice history

3
  1. Sources Sought Posted Jul 03, 2025
  2. Sources Sought Posted Jul 15, 2025
    • Description: Description was updated
    • Response Deadline: Jul 10, 2025Jul 18, 2025
  3. Sources Sought LATEST Posted Jul 24, 2025
    • Description: Description was updated

Details

Solicitation number FA701425X000X
Notice ID 4b284fa106f04cb4840675eb4d3cd9bd
Notice type Sources Sought
Product / Service (PSC) 7A21
NAICS 541519
Place of performance Linthicum Heights, Maryland
Archive date Jul 25, 2025

Award Information

Not yet awarded

Contacts

primary
Phelicha Silva

Email

secondary
Ryan Amos

Email

Agency

DEPT OF DEFENSE
DEPT OF THE AIR FORCE
AIR FORCE DISTRICT OF WASHINGTON
FA7014 AFDW PK

Place of Performance

Linthicum Heights, Maryland
USA

Dates

Posted Jul 03, 2025 1 year ago
Last Updated Aug 06, 2026 1 day ago
Due Jul 10, 2025 1 year ago