# Justification and Approval - Vulnerability Disclosure Policy Platform (VDP) Platform

Canonical: https://abierto.us/opportunities/47qfra20q0048

- Solicitation number: 47QFRA20Q0048
- Notice type: Justification
- Status: Awarded to Endyna, Inc.
- Department: General Services Administration
- Agency: Federal Acquisition Service
- Contracting office: GSA FAS Aas Region 6 (47QFHA)
- NAICS: 541519 Other Computer Related Services
- Product or service code: DJ01 Support services focused on supporting security policies/controls, processes, measuring compliance of relevant legal/compliance requirements, to include Section 508, and responding to security breaches. Also provides support for IT Security systems providing Continuous Diagnostics and Mitigation (CDM) for real-time Cyber Security and protection such as vulnerability scanning, managing firewalls, intrusion prevention systems, and security information and event management (SIEM). Includes Disaster Recovery (DR) services to support DR policy, process and means, dedicated failover facilities and perform DR testing.
- Place of performance: Arlington, Virginia
- First posted: July 16, 2026
- Last posted: July 16, 2026
- SAM.gov: https://sam.gov/workspace/contract/opp/9981c687df274f82add5e698356e33d4/view

## Description

The Cybersecurity and Infrastructure Security Agency (CISA) partners with Federal agencies, industry, and other stakeholders to strengthen the security and resilience of the Nation's critical infrastructure and Federal information systems. As part of this mission, CISA supports ongoing efforts to reduce cybersecurity risk by identifying, assessing, and facilitating the remediation of vulnerabilities affecting Federal Civilian Executive Branch (FCEB) systems.

These efforts support the implementation of Binding Operational Directive (BOD) 20-01, which requires FCEB agencies to establish and maintain Vulnerability Disclosure Policies (VDPs) to receive and address vulnerability reports submitted by external security researchers.

This requirement provides CISA and participating FCEB agencies with continued access to a secure, commercially available Software-as-a-Service (SaaS) Vulnerability Disclosure Policy (VDP) platform that enables the centralized submission, validation, routing, tracking, and reporting of cybersecurity vulnerabilities identified in internet-accessible Federal systems.

The platform supports secure collaboration between security researchers and participating agencies, provides configurable reporting and metrics, role-based user management, application programming interface (API) integration capabilities, and optional functionality to support agency-managed bug bounty programs.

The contractor shall configure, operate, secure, and administer the platform; maintain the platform's Authority to Operate (ATO) and support applicable Federal cybersecurity authorization requirements; provide technical support and user onboarding; perform vulnerability triage, validation, routing, and tracking services; generate operational reporting; and support agencies that elect to implement bug bounty programs.

The platform is designed to scale as agency participation changes while ensuring the confidentiality, integrity, and availability of vulnerability information and supporting the Government's continued ability to receive and manage coordinated vulnerability disclosures. This modification extends the period of performance for the existing contract to ensure continuity of the enterprise Vulnerability Disclosure Policy (VDP) platform and associated support services.

The modification continues uninterrupted support for participating Federal Civilian Executive Branch agencies and maintains the Government's capability to receive, triage, track, and manage vulnerability disclosures during the transition period.

## Award on USAspending

- Recipient: Endyna, Inc. (UEI GKWTAHYKMC62)
- Contract: 47QFRA20C0012, definitive contract
- Obligated: $3,627,500.00, current value $20,438,452
- Competition: Full and Open Competition After Exclusion of Sources, 5 offers received
- Link: award number 47QFRA20C0012 equals the contract number; same sub-agency 4732 (high confidence)
- Record: https://www.usaspending.gov/award/CONT_AWD_47QFRA20C0012_4732_-NONE-_-NONE-/


## Publications

- July 16, 2026: Justification. Notice 9981c687df274f82add5e698356e33d4. https://sam.gov/workspace/contract/opp/9981c687df274f82add5e698356e33d4/view

## Points of contact

- Adrienne Davis, adrienne.davis@gsa.gov
- Matthew Schupbach, matthew.schupbach@gsa.gov

---
Source: SAM.gov Contract Opportunities bulk extract and USAspending.gov award data. Confirm deadlines on SAM.gov before responding. Cite https://abierto.us/opportunities/47qfra20q0048.
