Vulnerability Disclosure Program Enterprise Management System (VDP EMS)

Location: Maryland
Posted: Jul 24, 2025
Due: Jul 18, 2025
Agency: DEPT OF DEFENSE
Type of Government: Federal
Category:
Solicitation No: FA701425X000X
Publication URL: To access bid details, please log in.
Follow
Vulnerability Disclosure Program Enterprise Management System (VDP EMS)
Active
Contract Opportunity
Notice ID
FA701425X000X
Related Notice
Department/Ind. Agency
DEPT OF DEFENSE
Sub-tier
DEPT OF THE AIR FORCE
Major Command
AIR FORCE DISTRICT OF WASHINGTON
Office
FA7014 AFDW PK
Looking for contract opportunity help?

APEX Accelerators are an official government contracting resource for small businesses. Find your local APEX Accelerator (opens in new window) for free government expertise related to contract opportunities.

APEX Accelerators are funded in part through a cooperative agreement with the Department of Defense.

The APEX Accelerators program was formerly known as the Procurement Technical Assistance Program (opens in new window) (PTAP).

General Information View Changes
  • Contract Opportunity Type: Sources Sought (Updated)
  • Updated Published Date: Jul 24, 2025 09:40 am EDT
  • Original Published Date: Jul 03, 2025 07:55 am EDT
  • Updated Response Date: Jul 18, 2025 02:00 pm EDT
  • Original Response Date: Jul 10, 2025 02:00 pm EDT
  • Inactive Policy: 15 days after response date
  • Updated Inactive Date: Aug 02, 2025
  • Original Inactive Date: Jul 25, 2025
  • Initiative:
    • None
Classification
  • Original Set Aside:
  • Product Service Code: 7A21 - IT AND TELECOM - BUSINESS APPLICATION SOFTWARE (PERPETUAL LICENSE SOFTWARE)
  • NAICS Code:
    • 541519 - Other Computer Related Services
  • Place of Performance:
    Linthicum Heights , MD
    USA
Description View Changes

During the RFI phase of this requirement, two questions were received. The questions and answers are provided below. Please review the Q&A and keep them in mind when the official solicitation is published. This RFI has NOT been extended further.





Question 1: Is the Government specifically seeking vendors who can provide a proprietary, crowdsourced VDP platform license (e.g., HackerOne, Bugcrowd), or will you also consider integrators who can deliver compliance, security automation, and Microsoft Sentinel-based triage/reporting workflows in partnership with a platform provider?





DC3 is directly seeking a proprietary, crowdsourced VDP platform license; Hackerone, BugCrowd, SynAck. Anything outside of this would impact mission success.





Question 2: Can you clarify the “250 crowdsourced vulnerability - bug tag and annual mailings”? Understand the concept here is that we would be responsible for the logistics and shipping of any DC3 provided items used to recognize researchers.





This would be in regard to delivering “swag” (inexpensive tangible goods like stickers, coins, t-shirts) to the researcher community. Specifically, DC3 disseminates “swag” for things such as “hacker of the month” or “hacker of the year.” The vendor will be responsible for distributing the “swag” on DC3’s behalf (verifying mailing addresses, packaging swag, paying for the shipping, getting the swag to the shipper, etc).



End Questions and Answers



---------------------------------------------------------------------





The Department of Defense Cyber Crime Center (DC3) is conducting market research for an enterprise management system to support its Vulnerability Disclosure Program (VDP) and Defense Industrial Base (DIB) VDP. The system shall facilitate collaboration, compliance, and management of the VDPs. Key requirements include:




  • Enterprise-grade VDP platform license/subscription for two instances (DoD VDP and DIB VDP).

  • Vulnerability submission and management workflows.

  • Integration, via API, with DC3's Atlassian Jira-based Vulnerability Report Management Network (VRMN) systems.

  • Mediation support for researcher inquiries.

  • Tools and processes for effective vulnerability triage and resolution (e.g., CVSS scoring).

  • Advanced analytics and custom reporting capabilities.

  • Dedicated account team with customer support and customer success functions.



Interested vendors are encouraged to review the attached draft Performance Work Statement (PWS) for detailed requirements and provide feedback on the PWS.



7/14/2025 - Amended solicitation to extend response due date to 18 Jul 2025.


Attachments/Links
Contact Information
Contracting Office Address
  • ADMIN ONLY NO REQTN CP 240 612 2997 1500 W PERIMETER RD STE 5750
  • ANDREWS AFB , MD 20762-6604
  • USA
Primary Point of Contact
Secondary Point of Contact
History

Related Document

Jul 3, 2025[Sources Sought (Original)] Vulnerability Disclosure Program Enterprise Management System (VDP EMS)
Jul 15, 2025[Sources Sought (Updated)] Vulnerability Disclosure Program Enterprise Management System (VDP EMS)
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL
* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.