Vulnerability Disclosure Program Enterprise Management System (VDP EMS)
| Agency: | DEPT OF DEFENSE |
|---|---|
| State: | Maryland |
| Type of Government: | Federal |
| NAICS Category: |
|
| Posted Date: | Jul 24, 2025 |
| Due Date: | Jul 18, 2025 |
| Solicitation No: | FA701425X000X |
| Original Source: | Please Login to View Page |
| Contact information: | Please Login to View Page |
| Bid Documents: | Please Login to View Page |
Description
APEX Accelerators are an official government contracting resource for small businesses. Find your local APEX Accelerator (opens in new window) for free government expertise related to contract opportunities.
APEX Accelerators are funded in part through a cooperative agreement with the Department of Defense.
The APEX Accelerators program was formerly known as the Procurement Technical Assistance Program (opens in new window) (PTAP).
- Contract Opportunity Type: Sources Sought (Updated)
- Updated Published Date: Jul 24, 2025 09:40 am EDT
- Original Published Date: Jul 03, 2025 07:55 am EDT
- Updated Response Date: Jul 18, 2025 02:00 pm EDT
- Original Response Date: Jul 10, 2025 02:00 pm EDT
- Inactive Policy: 15 days after response date
- Updated Inactive Date: Aug 02, 2025
- Original Inactive Date: Jul 25, 2025
-
Initiative:
- None
- Original Set Aside:
- Product Service Code: 7A21 - IT AND TELECOM - BUSINESS APPLICATION SOFTWARE (PERPETUAL LICENSE SOFTWARE)
-
NAICS Code:
- 541519 - Other Computer Related Services
-
Place of Performance:
Linthicum Heights , MDUSA
During the RFI phase of this requirement, two questions were received. The questions and answers are provided below. Please review the Q&A and keep them in mind when the official solicitation is published. This RFI has NOT been extended further.
Question 1: Is the Government specifically seeking vendors who can provide a proprietary, crowdsourced VDP platform license (e.g., HackerOne, Bugcrowd), or will you also consider integrators who can deliver compliance, security automation, and Microsoft Sentinel-based triage/reporting workflows in partnership with a platform provider?
DC3 is directly seeking a proprietary, crowdsourced VDP platform license; Hackerone, BugCrowd, SynAck. Anything outside of this would impact mission success.
Question 2: Can you clarify the “250 crowdsourced vulnerability - bug tag and annual mailings”? Understand the concept here is that we would be responsible for the logistics and shipping of any DC3 provided items used to recognize researchers.
This would be in regard to delivering “swag” (inexpensive tangible goods like stickers, coins, t-shirts) to the researcher community. Specifically, DC3 disseminates “swag” for things such as “hacker of the month” or “hacker of the year.” The vendor will be responsible for distributing the “swag” on DC3’s behalf (verifying mailing addresses, packaging swag, paying for the shipping, getting the swag to the shipper, etc).
End Questions and Answers
---------------------------------------------------------------------
The Department of Defense Cyber Crime Center (DC3) is conducting market research for an enterprise management system to support its Vulnerability Disclosure Program (VDP) and Defense Industrial Base (DIB) VDP. The system shall facilitate collaboration, compliance, and management of the VDPs. Key requirements include:
- Enterprise-grade VDP platform license/subscription for two instances (DoD VDP and DIB VDP).
- Vulnerability submission and management workflows.
- Integration, via API, with DC3's Atlassian Jira-based Vulnerability Report Management Network (VRMN) systems.
- Mediation support for researcher inquiries.
- Tools and processes for effective vulnerability triage and resolution (e.g., CVSS scoring).
- Advanced analytics and custom reporting capabilities.
- Dedicated account team with customer support and customer success functions.
Interested vendors are encouraged to review the attached draft Performance Work Statement (PWS) for detailed requirements and provide feedback on the PWS.
7/14/2025 - Amended solicitation to extend response due date to 18 Jul 2025.
- ADMIN ONLY NO REQTN CP 240 612 2997 1500 W PERIMETER RD STE 5750
- ANDREWS AFB , MD 20762-6604
- USA
- Phelicha Silva
- phelicha.silva@us.af.mil
- Ryan Amos
- ryan.amos.5.ctr@us.af.mil
- Jul 24, 2025 09:40 am EDTSources Sought (Updated)
- Jul 15, 2025 03:19 pm EDT Sources Sought (Updated)
- Jul 03, 2025 07:55 am EDT Sources Sought (Original)
Related Document
| Jul 3, 2025 | [Sources Sought (Original)] Vulnerability Disclosure Program Enterprise Management System (VDP EMS) |
| Jul 15, 2025 | [Sources Sought (Updated)] Vulnerability Disclosure Program Enterprise Management System (VDP EMS) |
See Also
Follow Packaged Food Ingredient Monitoring Active Contract Opportunity Notice ID 75F40126Q00344 Related Notice
HEALTH AND HUMAN SERVICES, DEPARTMENT OF
Due by 9/16/2026
Follow Maintenance and Support Agreement for NIH Hazardous Waste Management Tracking Information Software
HEALTH AND HUMAN SERVICES, DEPARTMENT OF
Due by 9/28/2026
Follow Notice of Intent - Sole Source - Rockwell Automation (Rexel) Active Contract
DEPT OF DEFENSE
Due by 9/21/2026
Follow SRD License Key System Active Contract Opportunity Notice ID 1333ND26QNB640575 Related Notice
COMMERCE, DEPARTMENT OF
Due by 9/15/2026