CISA contemplates whether to hire security software buying help

Gettyimages.com / Fotograzia

The Cybersecurity and Infrastructure Security Agency issued a sources sought notice that describes its desire to bring in a company that can help manage enterprise license and materials purchases.

The Cybersecurity and Infrastructure Security Agency is contemplating whether to hire a contractor to help manage its purchases of cybersecurity software and related tools via a single mechanism.

CISA currently acquires the tools through the Continuous Diagnostics and Mitigation program for protecting civilian government networks and Capacity Building, an arm of the agency that leads federal enterprise cyber governance efforts.

By launching this sources sought notice on Aug. 12, CISA is signaling the start of its evaluation of acquisition approaches that would support roughly $600 million in cyber software purchases per year.

The agency eventually wants that figure to grow to $6 billion per year over the entire contract’s lifecycle, should a contract be created.

CISA is working with the General Services Administration’s Assisted Acquisition Services team to evaluate the market research collected via the request for information. GSA AAS works with other agencies on planning, awarding and managing complex contracts.

In the new notice, CISA describes its desire to bring in a contractor that can aid the agency in managing its enterprise license and materials purchases. The contractor would also work with CISA’s CB team to implement a singular software buying management process and procurement support platforms.

CISA is undertaking this effort as part of its plans to transition away from the CDM program’s current approved product list to a new Cyber Product List and Technical Capability Catalog. The agency describes the latter two initiatives as its baselines for future enterprise cyber software procurements.

The RFI describes the scope of work as covering strategic buying advisory services, acquisition and procurement support, enterprise license management, software asset management, category management, vendor management and procurement analytics. These services would be provided in addition to the cyber tools themselves.

Other requirements include market analysis, historical spend analysis, pricing analysis, procurement strategy development, software category management, enterprise licensing recommendations, and development of cost savings metrics.

Responses to the RFI are due by 5 p.m. ET on Sept. 1.