FedSift

SolicitationsGENERAL SERVICES ADMINISTRATIONNAICS 541519

Justification and Approval - Vulnerability Disclosure Policy Platform (VDP) Platform

GENERAL SERVICES ADMINISTRATION · Solicitation 47QFRA20Q0048 · NAICS 541519 · Unrestricted (full and open)

Solicitation details

Solicitation number47QFRA20Q0048
Notice ID9981c687df274f82add5e698356e33d4
AgencyGENERAL SERVICES ADMINISTRATION
Sub-tierFEDERAL ACQUISITION SERVICE
Contracting officeGSA FAS AAS REGION 6
NAICS code541519
Product / service code (PSC)DJ01
Set-asideUnrestricted (full and open)
Notice typeJustification
Posted16 July 2026
Response deadlineNot stated
Place of performanceArlington, VA, USA

Description

The Cybersecurity and Infrastructure Security Agency (CISA) partners with Federal agencies, industry, and other stakeholders to strengthen the security and resilience of the Nation's critical infrastructure and Federal information systems. As part of this mission, CISA supports ongoing efforts to reduce cybersecurity risk by identifying, assessing, and facilitating the remediation of vulnerabilities affecting Federal Civilian Executive Branch (FCEB) systems. These efforts support the implementation of Binding Operational Directive (BOD) 20-01, which requires FCEB agencies to establish and maintain Vulnerability Disclosure Policies (VDPs) to receive and address vulnerability reports submitted by external security researchers. This requirement provides CISA and participating FCEB agencies with continued access to a secure, commercially available Software-as-a-Service (SaaS) Vulnerability Disclosure Policy (VDP) platform that enables the centralized submission, validation, routing, tracking, and reporting of cybersecurity vulnerabilities identified in internet-accessible Federal systems. The platform supports secure collaboration between security researchers and participating agencies, provides configurable reporting and metrics, role-based user management, application programming interface (API) integration capabilities, and optional functionality to support agency-managed bug bounty programs. The contractor shall configure, operate, secure, and administer the platform; maintain the platform's Authority to Operate (ATO) and support applicable Federal cybersecurity authorization requirements; provide technical support and user onboarding; perform vulnerability triage, validation, routing, and tracking services; generate operational reporting; and support agencies that elect to implement bug bounty programs. The platform is designed to scale as agency participation changes while ensuring the confidentiality, integrity, and availability of vulnerability information and supporting the Government's continued ability to receive and manage coordinated vulnerability disclosures. This modification extends the period of performance for the existing contract to ensure continuity of the enterprise Vulnerability Disclosure Policy (VDP) platform and associated support services. The modification continues uninterrupted support for participating Federal Civilian Executive Branch agencies and maintains the Government's capability to receive, triage, track, and manage vulnerability disclosures during the transition period.

Go deeper on this solicitation

FedSift reads the full solicitation package — every attachment — and pre-extracts the compliance matrix, evaluation factors, key risks, win themes and deal-breakers, each with a verbatim quote and the exact PDF page it came from. It scores the opportunity against your company profile, tells you whether to bid as prime or sub, and ranks teaming partners who could close your gaps.

Open the AI analysis in FedSift →

Free forever plan — no credit card. Browse solicitations without an account; sign in for AI analysis and matching.

Other open solicitations in NAICS 541519

All NAICS 541519 solicitations →

More from GENERAL SERVICES ADMINISTRATION

All GENERAL SERVICES ADMINISTRATION solicitations →

Source: this notice on SAM.gov. FedSift republishes public federal procurement data and is not affiliated with the U.S. Government. Always confirm dates and requirements against SAM.gov before responding.