Notice of Intent to Solicit and Award a Sole-Source Modification for the Vulnerability Disclosure Policy (VDP) Platform

Location: Virginia
Posted: Jan 12, 2026
Due: Jan 26, 2026
Agency: GENERAL SERVICES ADMINISTRATION
Type of Government: Federal
Category:
  • D - Automatic Data Processing and Telecommunication Services
Solicitation No: 47QFRA20C0012
Publication URL: To access bid details, please log in.
Follow
Notice of Intent to Solicit and Award a Sole-Source Modification for the Vulnerability Disclosure Policy (VDP) Platform
Active
Contract Opportunity
Notice ID
47QFRA20C0012
Related Notice
Department/Ind. Agency
GENERAL SERVICES ADMINISTRATION
Sub-tier
FEDERAL ACQUISITION SERVICE
General Information
  • Contract Opportunity Type: Special Notice (Original)
  • Original Published Date: Jan 12, 2026 02:07 pm MST
  • Original Response Date: Jan 26, 2026 03:00 pm MST
  • Inactive Policy: Manual
  • Original Inactive Date: Jan 27, 2026
  • Initiative:
    • None
Classification
  • Original Set Aside: No Set aside used
  • Product Service Code: DJ01 - IT AND TELECOM - SECURITY AND COMPLIANCE SUPPORT SERVICES (LABOR)
  • NAICS Code:
    • 541519 - Other Computer Related Services
  • Place of Performance:
    McLean , VA 22102
    USA
Description

The U.S. General Services Administration, Federal Acquisition Service, hereby publicises its intention to modify an existing open market contract with Endyna, Inc., located at 1345 Lancia Drive, McLean VA, 22102. The anticipated modification will provide the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and partnering Federal Cybersecurity Executive Branch (FCEB) agencies continued access to a secure platform to facilitate the submission, tracking, and reporting of vulnerabilities discovered in information systems. The contractor, EnDyna, configures, operates, and administers the platform; ensures it maintains an Authority to Operate (ATO); provides triage services to ensure the validity, proper routing, and tracking of vulnerability submissions; and facilities a bug bounty incentive payment program for FCEB agencies to reward valid submissions. EnDyna is the only firm currently able to continue to provide the services and maintain the ATO without a break in these critical services. The anticipated sole-source modification will allow the Government adequate time to competitively procure future VDP program requirements and implement a new procurement strategy.



Be advised that the aforementioned information is anticipatory in nature and is not binding. A determination by the Government not to compete based upon responses to this notice is solely within the discretion of the Government. This notice is not a request for competitive proposals; however, any firm believing that it can fulfill the requirement of providing these services may be considered on the following competitive procurement. Interested parties may identify their interest and capabilities in response to this notice, and must clearly show the firm's ability to be immediately responsive without compromising the quality, accuracy, and reliability of services provided. The Government will consider all responses.




Attachments/Links
Contact Information
Primary Point of Contact
Secondary Point of Contact
History
  • Jan 12, 2026 02:07 pm MSTSpecial Notice (Original)
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

...Regional Stormwater Vulnerability Assessment Status: Open RFP 119549-2 West Piedmont Planning... for a ...

State Government of Virginia

Bid Due: 7/03/2026

...Regional Stormwater Vulnerability Assessment Status: Open RFP 119549 West Piedmont Planning... for a ...

State Government of Virginia

Bid Due: 7/03/2026

...vulnerabilities. Solution must have autonomous syncing capability and be able to execute functions ...

DEPT OF DEFENSE

Bid Due: 6/08/2026

...vulnerabilities. Solution must have autonomous syncing capability and be able to execute functions ...

DEPT OF DEFENSE

Bid Due: 6/08/2026

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.