{"canonical":"https://abierto.us/opportunities/47qfra20c0012","key":"47QFRA20C0012","url":"https://abierto.us/opportunities/47qfra20c0012","title":"Justification and Approval - Vulnerability Disclosure Policy Platform (VDP) Platform","solicitation_number":"47QFRA20Q0048","notice_type":"u","open":false,"response_deadline":null,"first_posted":"2026-01-12","last_posted":"2026-07-16","department":"GENERAL SERVICES ADMINISTRATION","subagency":"FEDERAL ACQUISITION SERVICE","office":"GSA FAS AAS REGION 6","naics":"541519","psc":"DJ01","set_aside":null,"place_state":"VA","place_county":"51013","place_county_name":"Arlington County","place_city":"5103000","place_city_name":"Arlington","winner":"ENDYNA, INC.","award_amount":null,"publications":[{"notice_id":"d59a92511b5a425780abac8b05d9f368","title":"Notice of Intent to Solicit and Award a Sole-Source Modification for the Vulnerability Disclosure Policy (VDP) Platform","solicitation_number":"47QFRA20C0012","notice_type":"s","base_type":"s","posted":"2026-01-12","posted_at":null,"due_at":"2026-01-26T22:00:00Z","due_date":"2026-01-26","cancelled":null,"archived":null,"archive_date":"2026-01-27","award_number":null,"awardee_name":null,"amount":null,"link_sam":"https://sam.gov/workspace/contract/opp/d59a92511b5a425780abac8b05d9f368/view","enriched":false,"history":[]},{"notice_id":"9981c687df274f82add5e698356e33d4","title":"Justification and Approval - Vulnerability Disclosure Policy Platform (VDP) Platform","solicitation_number":"47QFRA20Q0048","notice_type":"u","base_type":"u","posted":"2026-07-16","posted_at":null,"due_at":null,"due_date":null,"cancelled":null,"archived":null,"archive_date":"2026-08-15","award_number":"47QFRA20C0012","awardee_name":null,"amount":null,"link_sam":"https://sam.gov/workspace/contract/opp/9981c687df274f82add5e698356e33d4/view","enriched":false,"history":[]}],"latest_notice_id":"9981c687df274f82add5e698356e33d4","first_type":"s","notices":[{"dates":{"posted":"2026-01-12","response_deadline":{"raw":"2026-01-26T15:00:00-07:00","utc":"2026-01-26T22:00:00Z","date":"2026-01-26","time":"15:00:00","utc_offset_seconds":-25200}},"links":{"sam":"https://sam.gov/workspace/contract/opp/d59a92511b5a425780abac8b05d9f368/view"},"naics":{"codes":["541519"],"primary":"541519"},"title":"Notice of Intent to Solicit and Award a Sole-Source Modification for the Vulnerability Disclosure Policy (VDP) Platform","agency":{"office":{"name":"FEDERAL ACQUISITION SERVICE"},"subtier":{"code":"4732","name":"FEDERAL ACQUISITION SERVICE"},"department":{"code":"047","name":"GENERAL SERVICES ADMINISTRATION"},"organization_type":"AGENCY"},"status":{"active":false,"archive_date":"2026-01-27","archive_type":"auto_custom"},"contacts":[{"name":"Lila Schmideke","role":"primary","email":"lila.schmideke@gsa.gov"},{"name":"Matthew Schupbach","role":"secondary","email":"matthew.schupbach@gsa.gov"}],"base_type":{"code":"s","label":"Special Notice"},"notice_id":"d59a92511b5a425780abac8b05d9f368","provenance":{"extract":{"url":"https://s3.amazonaws.com/falextracts/Contract%20Opportunities/Archived%20Data/FY2026_archived_opportunities.csv","etag":"\"d9374b90a938e9923d910594731b7b57-106\"","fetched_at":"2026-09-16T16:22:53.920682Z","row_sha256":"041d530fcb50c7468e1075fe2ab2dbb06cd9eac3c1f656e21eed5357b0838d38","last_modified":"2026-09-13T14:50:39Z"},"updated_at":"2026-09-16T16:22:53.920682Z","first_seen_at":"2026-09-16T16:22:53.920682Z"},"description":{"text":"The U.S. General Services Administration, Federal Acquisition Service, hereby publicises its intention to modify an existing open market contract with Endyna, Inc., located at 1345 Lancia Drive, McLean VA, 22102. The anticipated modification will provide the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and partnering Federal Cybersecurity Executive Branch (FCEB) agencies continued access to a secure platform to facilitate the submission, tracking, and reporting of vulnerabilities discovered in information systems. The contractor, EnDyna, configures, operates, and administers the platform; ensures it maintains an Authority to Operate (ATO); provides triage services to ensure the validity, proper routing, and tracking of vulnerability submissions; and facilities a bug bounty incentive payment program for FCEB agencies to reward valid submissions. EnDyna is the only firm currently able to continue to provide the services and maintain the ATO without a break in these critical services. The anticipated sole-source modification will allow the Government adequate time to competitively procure future VDP program requirements and implement a new procurement strategy. Be advised that the aforementioned information is anticipatory in nature and is not binding. A determination by the Government not to compete based upon responses to this notice is solely within the discretion of the Government. This notice is not a request for competitive proposals; however, any firm believing that it can fulfill the requirement of providing these services may be considered on the following competitive procurement. Interested parties may identify their interest and capabilities in response to this notice, and must clearly show the firm's ability to be immediately responsive without compromising the quality, accuracy, and reliability of services provided. The Government will consider all responses.","origin":"extract"},"notice_type":{"code":"s","label":"Special Notice"},"schema_version":1,"solicitation_number":"47QFRA20C0012","place_of_performance":{"zip":"22102","city":{"name":"McLean"},"state":{"code":"VA"},"country":{"code":"USA"}},"product_service_code":"DJ01"},{"award":{"date":"2020-09-25","number":"47QFRA20C0012"},"dates":{"posted":"2026-07-16","award_date":"2020-09-25"},"links":{"sam":"https://sam.gov/workspace/contract/opp/9981c687df274f82add5e698356e33d4/view"},"naics":{"codes":["541519"],"primary":"541519"},"title":"Justification and Approval - Vulnerability Disclosure Policy Platform (VDP) Platform","agency":{"office":{"code":"47QFHA","name":"GSA FAS AAS REGION 6"},"subtier":{"code":"4732","name":"FEDERAL ACQUISITION SERVICE"},"department":{"code":"047","name":"GENERAL SERVICES ADMINISTRATION"},"office_address":{"zip":"64108","city":"KANSAS CITY","state":"MO","country":"USA"},"organization_type":"OFFICE"},"status":{"active":false,"archive_date":"2026-08-15","archive_type":"auto30"},"contacts":[{"name":"Adrienne Davis","role":"primary","email":"adrienne.davis@gsa.gov"},{"name":"Matthew Schupbach","role":"secondary","email":"matthew.schupbach@gsa.gov"}],"base_type":{"code":"u","label":"Justification"},"notice_id":"9981c687df274f82add5e698356e33d4","provenance":{"extract":{"url":"https://s3.amazonaws.com/falextracts/Contract%20Opportunities/Archived%20Data/FY2026_archived_opportunities.csv","etag":"\"d9374b90a938e9923d910594731b7b57-106\"","fetched_at":"2026-09-16T00:55:27.040971Z","row_sha256":"be0e7a1a45c2bd20ab2120cb235475ad089806b65ab0363bb2c3b32154e0b52c","last_modified":"2026-09-13T14:50:39Z"},"updated_at":"2026-09-16T01:23:20.966263Z","first_seen_at":"2026-09-16T00:55:27.040971Z"},"description":{"text":"The Cybersecurity and Infrastructure Security Agency (CISA) partners with Federal agencies, industry, and other stakeholders to strengthen the security and resilience of the Nation's critical infrastructure and Federal information systems. As part of this mission, CISA supports ongoing efforts to reduce cybersecurity risk by identifying, assessing, and facilitating the remediation of vulnerabilities affecting Federal Civilian Executive Branch (FCEB) systems. These efforts support the implementation of Binding Operational Directive (BOD) 20-01, which requires FCEB agencies to establish and maintain Vulnerability Disclosure Policies (VDPs) to receive and address vulnerability reports submitted by external security researchers. This requirement provides CISA and participating FCEB agencies with continued access to a secure, commercially available Software-as-a-Service (SaaS) Vulnerability Disclosure Policy (VDP) platform that enables the centralized submission, validation, routing, tracking, and reporting of cybersecurity vulnerabilities identified in internet-accessible Federal systems. The platform supports secure collaboration between security researchers and participating agencies, provides configurable reporting and metrics, role-based user management, application programming interface (API) integration capabilities, and optional functionality to support agency-managed bug bounty programs. The contractor shall configure, operate, secure, and administer the platform; maintain the platform's Authority to Operate (ATO) and support applicable Federal cybersecurity authorization requirements; provide technical support and user onboarding; perform vulnerability triage, validation, routing, and tracking services; generate operational reporting; and support agencies that elect to implement bug bounty programs. The platform is designed to scale as agency participation changes while ensuring the confidentiality, integrity, and availability of vulnerability information and supporting the Government's continued ability to receive and manage coordinated vulnerability disclosures. This modification extends the period of performance for the existing contract to ensure continuity of the enterprise Vulnerability Disclosure Policy (VDP) platform and associated support services. The modification continues uninterrupted support for participating Federal Civilian Executive Branch agencies and maintains the Government's capability to receive, triage, track, and manage vulnerability disclosures during the transition period.","origin":"extract"},"notice_type":{"code":"u","label":"Justification"},"schema_version":1,"solicitation_number":"47QFRA20Q0048","place_of_performance":{"zip":"22203","city":{"name":"Arlington"},"state":{"code":"VA"},"country":{"code":"USA"}},"product_service_code":"DJ01"}],"due_at":null,"due_date":null,"closes_at":null,"awardable":false,"dept_key":"d-047","dept_name":"GENERAL SERVICES ADMINISTRATION","sub_key":"s-4732","sub_name":"FEDERAL ACQUISITION SERVICE","office_key":"o-47QFHA","office_name":"GSA FAS AAS REGION 6","state":"VA","county":"51013","county_name":"Arlington County","city":"5103000","city_name":"Arlington","country":"USA","winner_key":"GKWTAHYKMC62","amount":null,"linked_awards":2,"cancelled":false,"archived":false,"updated_at":"2026-09-16T21:18:12.857524Z","principal_notice_id":"9981c687df274f82add5e698356e33d4","description":{"text":"The Cybersecurity and Infrastructure Security Agency (CISA) partners with Federal agencies, industry, and other stakeholders to strengthen the security and resilience of the Nation's critical infrastructure and Federal information systems. As part of this mission, CISA supports ongoing efforts to reduce cybersecurity risk by identifying, assessing, and facilitating the remediation of vulnerabilities affecting Federal Civilian Executive Branch (FCEB) systems. These efforts support the implementation of Binding Operational Directive (BOD) 20-01, which requires FCEB agencies to establish and maintain Vulnerability Disclosure Policies (VDPs) to receive and address vulnerability reports submitted by external security researchers. This requirement provides CISA and participating FCEB agencies with continued access to a secure, commercially available Software-as-a-Service (SaaS) Vulnerability Disclosure Policy (VDP) platform that enables the centralized submission, validation, routing, tracking, and reporting of cybersecurity vulnerabilities identified in internet-accessible Federal systems. The platform supports secure collaboration between security researchers and participating agencies, provides configurable reporting and metrics, role-based user management, application programming interface (API) integration capabilities, and optional functionality to support agency-managed bug bounty programs. The contractor shall configure, operate, secure, and administer the platform; maintain the platform's Authority to Operate (ATO) and support applicable Federal cybersecurity authorization requirements; provide technical support and user onboarding; perform vulnerability triage, validation, routing, and tracking services; generate operational reporting; and support agencies that elect to implement bug bounty programs. The platform is designed to scale as agency participation changes while ensuring the confidentiality, integrity, and availability of vulnerability information and supporting the Government's continued ability to receive and manage coordinated vulnerability disclosures. This modification extends the period of performance for the existing contract to ensure continuity of the enterprise Vulnerability Disclosure Policy (VDP) platform and associated support services. The modification continues uninterrupted support for participating Federal Civilian Executive Branch agencies and maintains the Government's capability to receive, triage, track, and manage vulnerability disclosures during the transition period.","html":null,"origin":"extract"},"contacts":[{"name":"Adrienne Davis","role":"primary","email":"adrienne.davis@gsa.gov"},{"name":"Matthew Schupbach","role":"secondary","email":"matthew.schupbach@gsa.gov"}],"place_of_performance":{"zip":"22203","city":{"name":"Arlington"},"state":{"code":"VA"},"country":{"code":"USA"}},"office_address":{"zip":"64108","city":"KANSAS CITY","state":"MO","country":"USA"},"naics_codes":["541519"],"award":{"date":"2020-09-25","number":"47QFRA20C0012"},"attachments":[],"awards":[{"award_key":"CONT_AWD_47QFRA20C0012_4732_-NONE-_-NONE-","permalink":"https://www.usaspending.gov/award/CONT_AWD_47QFRA20C0012_4732_-NONE-_-NONE-/","piid":"47QFRA20C0012","parent_piid":null,"award_type":"DEFINITIVE CONTRACT","vendor_key":"GKWTAHYKMC62","recipient_name":"ENDYNA, INC.","recipient_uei":"GKWTAHYKMC62","recipient_cage":"3UBW9","recipient_city":"MCLEAN","recipient_state":"VA","sub_name":"Federal Acquisition Service","office_name":"GSA FAS AAS REGION 8","office_key":"o-47QFRA","first_action_date":"2024-01-29","last_action_date":"2026-09-10","actions":32,"obligated":"6062139.36","current_total_value":"20438452.16","potential_total_value":"33351282.16","naics":"541519","psc":"D399","extent_competed":"FULL AND OPEN COMPETITION AFTER EXCLUSION OF SOURCES","set_aside":"SMALL BUSINESS SET ASIDE - TOTAL","offers_received":5,"description":"MIGRATED ID08200031 CISA VULNERABILITY DISCLOSURE PLATFORM VDP","method":"piid","confidence":"high","evidence":["award number 47QFRA20C0012 equals the contract number","same sub-agency 4732"],"opportunity_key":null,"opportunity_title":null}],"related":[]}