Search Contract Opportunities

Cybersecurity Compliance and Risk Management   3

ID: HQ085822R0009 • Type: Solicitation
Opportunity Assistant

Hello! Please let me know your questions about this opportunity. I will answer based on the available opportunity documents.

Please sign-in to link federal registration and award history to assistant. Sign in to upload a capability statement or catalogue for your company

Some suggestions:
Please summarize the work to be completed under this opportunity
Do the documents mention an incumbent contractor?
Does this contract have any security clearance requirements?
I'd like to anonymously submit a question to the procurement officer(s)
Loading

Description

Posted: Oct. 7, 2022, 1:15 p.m. EDT

October 7, 2022 - Response to Questions: Provided as an attachment, in the PIEE Solicitation System, is our response to additional questions submitted in regards to this solicitation. Please visit PIEE for all documents associated with this solicitation.

September 16, 2022 - Response to Questions: Provided as an attachment, in the PIEE Solicitation System, is our response to additional questions submitted in regards to this solicitation. Please visit PIEE for all documents associated with this solicitation.

September 2, 2022, Amendment 0002, HQ0858-22-R-0009: The MDA is issuing this amendment to update the proposal due date to 5:00 pm central time on October 18, 2022; update NAICS Code from 541519 to 541330; incorporate an updated Attachment J-01 TEAMS-Next CCRM SOW; incorporate Attachment J-18 Mission Essential Functions; incorporate an updated Attachment L-05 TEAMS-Next CCRM EPW; incorporate an updated Section L; provide responses to industry questions.

August 30, 2022, ANNOUNCEMENT - MDA is in the process of amending this RFP. The new RFP due date will be in October 2022.

ANNOUNCEMENT: MDA will be releasing an amendment in the future regarding HQ0858-22-R-0009, TEAMS-Next CCRM. This amendment will update the NAICS code to 541330. In addition, an extension to the submission date will be provided, the Statement of Work (SOW) will have minor changes, and a new Excel Pricing Worksheet (EPW) will be provided. As we review the questions submitted by potential offerors additional documents may be updated. Please note MDA has been notified that the processing of a JCP Certification number (required to gain access to the restricted library) may take upwards of 45 days. We recommend that you register for this number through DLA as soon as possible. (https://www.dla.mil/HQ/LogisticsOperations/Services/JCP/)

August 5, 2022, Amendment 0001, HQ0858-22-R-0009: The MDA is issuing an amendment to update the proposal due date to 5:00 pm central time on September 6, 2022; update the Set Aside Code to Women-Owned Small Business (WOSB) Program Set-Aside; update Section L - Instructions, Conditions, and Notices to Offerors, page 4, to reflect the updated proposal due date; upload HQ085822R0009_Redacted_CDRLs_Combined; upload HQ085822R0009_TN-CCRM Amd 0001 08.05.22; Upload HQ085822R0009_TN-CCRM Conformed Amd 0001 08.05.22; and remove HQ085822R0009_Atch_J_08_DD254__RFI__Signed and HQ085822R0009_Atch_J_08_DD254_SCI_Supp. Industry is reminded to refer to page 2 of the solicitation for the set aside designation. August 4, 2022, Solicitation Notice HQ0858-22-R-0009 TEAMS-Next Cybersecurity Compliance and Risk Management Solicitation The Missile Defense Agency (MDA) is issuing this solicitation to procure Cybersecurity Compliance and Risk Management advisory and assistance services to support MDA and the Office of Chief Information Officer. The Cybersecurity Compliance and Risk Management requirement consists of conducting numerous cybersecurity test and risk assessment services across all MDA information systems (Business, Mission Support, and Warfighter), their connections and associated test events in support of Agency Security Control Assessors (SCA). The requirement includes the development, implementation, sustainment, and execution of Agency Risk Management Framework (RMF) functions and processes to include: cybersecurity controls validation, software assurance, cybersecurity risk assessment, cybersecurity training; and providing fee-for-service management and event scheduling support. The cybersecurity controls validation requirement involves performing technical and non-technical evaluation of: 1) information systems authorized or to-be authorized by the MDA Authorizing Official; 2) internal and external MDA information systems connections; and 3) classified sites connecting to MDA information systems. The software assurance requirement involves: 1) assessing internal and external Commercial-Off-The-Shelf (COTS) and Government-Off-The-Shelf (GOTS) software code analysis (static, dynamic); results and risk assessment reports for all major software builds/updates of the Operational Capacity Baseline of the MDS and information systems authorized or to-be authorized by the MDA Authorizing Official; 2) assessing Program(s) compliance with Agency software development, test, and cyber requirements; and 3) conducting static and dynamic code reviews on MDA-developed software. The cybersecurity risk assessment requirement involves the RMF control and system-level assessments of: 1) all major hardware and software updates of the Operational Capacity Baseline of the MDS; 2) all MDA flight and ground test event architectures; 3) information systems authorized or to-be authorized by the MDA Authorizing Official; 4) internal and external MDA information systems connections, 5) classified sites connecting to MDA information systems; 6) cybersecurity test results from official Development and Test Evaluations (DT and E) of MDA developed acquisition systems; 7) cybersecurity test results from official Operational and Test Evaluations (OT and E) of MDA developed acquisition systems; and 8) internal and external COTS and GOTS software vulnerability reports or analysis. The cybersecurity training requirement involves: 1) organizing and developing curriculum for Agency-level cybersecurity workforce training, education, and leadership development; and 2) provide management support in tracking Agency-wide cybersecurity certifications and training requirements. Activities also include the development, implementation, and execution of a fee-for-service catalog, five-year master test plan, project schedule, and program-specific metrics to orchestrate and communicate all activities described above. The Government requires proposal submissions be conducted via the Procurement Integrated Enterprise Environment (PIEE) Solicitation Module, https://piee.eb.mil. The proposal shall be received prior to 5:00 pm central time on September 6, 2022. Late submissions will not be accepted. To initiate the proposal submission through PIEE, the Offeror must register as a proposal manager. Training on the solicitation module is available for proposal managers through PIEE. Subcontractors who have proprietary data and do not want to submit this data to the prime must submit it through PIEE. The subcontractors will register as a proposal manager, and create a separate proposal submission from their prime. Documents submitted by the subcontractor directly to the Government must have the prime contractors team name and RFP number on the first page of the document. Any questions about the solicitation must be emailed to: TN-CYBERCOMP@mda.mil and Ms. Rebecca Froelich at rebecca.froelich@mda.mil. The PIEE help desk can be reached Monday - Friday, 06:30 ? 24:00 EST at phone: 866-618-5988, Email: disa.global.servicedesk.mbx.eb-ticket-requests@mail.mil or fax: 801-605-7453. Approved for Public Release 22-MDA-11219 (28 July 22) *Visit 'https://piee.eb.mil/sol/xhtml/unauth/search/oppMgmtLink.xhtml?solNo=HQ085822R0009' to obtain more details.*

Posted: Sept. 16, 2022, 8:23 a.m. EDT
Posted: Sept. 2, 2022, 11:12 a.m. EDT
Posted: Aug. 30, 2022, 2:41 p.m. EDT
Posted: Aug. 19, 2022, 9:13 a.m. EDT
Posted: Aug. 5, 2022, 4:36 p.m. EDT
Posted: Aug. 4, 2022, 5:41 p.m. EDT

Overview

Response Deadline
Oct. 18, 2022, 6:00 p.m. EDT (original: Sept. 5, 2022, 6:00 p.m. EDT) Past Due
Posted
Aug. 4, 2022, 5:41 p.m. EDT (updated: Oct. 7, 2022, 1:15 p.m. EDT)
Set Aside
Women-Owned Small Business (WOSB)
Place of Performance
Not Provided
Source
SAM

Current SBA Size Standard
$25.5 Million
Pricing
Likely Cost Plus
Signs of Shaping
82% of obligations for similar contracts within the Missile Defense Agency were awarded full & open.
On 8/4/22 Missile Defense Agency issued Solicitation HQ085822R0009 for Cybersecurity Compliance and Risk Management due 10/18/22. The opportunity was issued with a Women-Owned Small Business (WOSB) set aside with NAICS 541330 (SBA Size Standard $25.5 Million) and PSC R425.
Primary Contact
Name
Rebecca Froelich   Profile
Phone
(250) 450-4616

Documents

Posted documents for Solicitation HQ085822R0009

Question & Answer

The AI Q&A Assistant has moved to the bottom right of the page

Opportunity Lifecycle

Procurement notices related to Solicitation HQ085822R0009

Award Notifications

Agency published notification of awards for Solicitation HQ085822R0009

Contract Awards

Prime contracts awarded through Solicitation HQ085822R0009

Incumbent or Similar Awards

Potential Bidders and Partners

Awardees that have won contracts similar to Solicitation HQ085822R0009

Similar Active Opportunities

Open contract opportunities similar to Solicitation HQ085822R0009

Additional Details

Source Agency Hierarchy
DEPT OF DEFENSE > MISSILE DEFENSE AGENCY (MDA) > MISSILE DEFENSE AGENCY (MDA)
FPDS Organization Code
97JC-HQ0858
Source Organization Code
500045673
Last Updated
Oct. 18, 2023
Last Updated By
rebecca.froelich@mda.mil
Archive Date
Oct. 18, 2023