This Sources Sought opportunity from Department Of Veterans Affairs was posted on June 25, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.
DA10--Enterprise Vulnerability Management Maintenance and Support (VA-26-00048094)
Contract Overview
Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.
Active Opportunities Like This One
AI Contract Overview
The Department of Veterans Affairs, through its Technology Acquisition Center in Eatontown, New Jersey, issued a Request for Information to assess market capability for Enterprise Vulnerability Management Maintenance and Support under DA10-VA-26-00048094, with the objective of fulfilling requirements for the Cybersecurity Operations Center’s Vulnerability Scanning Services. After evaluating responses, the Government concluded that only Tenable products meet the necessary technical, operational, and compliance standards, leading to a planned solicitation via NASA SEWP under RFQ 36C10B26Q0311 as a Service-Disabled Veteran-Owned Small Business set-aside. The requirement encompasses end-to-end maintenance and support for Tenable’s enterprise vulnerability management suite, including licensed components such as Tenable.sc+ scanners, standard and additional consoles, Tenable.sc Director, Continuous View with LCE renewal, and FedRAMP Moderate cloud agents, all tied to a 1.8 million IP band capacity with 675,000 agent renewals. The contractor must supply all license keys, subscription activations, portal access, and software downloads prior to the commencement of performance or expiration of current coverage, ensuring zero operational gaps in critical areas including AVS, PCI, ATO/SCA, CRD, OIG remediation, emergency scanning, dashboarding, and reporting. Performance must align with the base period from July 1, 2026, to June 30, 2027, with an option year extending through June 30, 2028. All deliverables must comply with Department of Veterans Affairs Technical Reference Model, Section 508 Chapter 2 accessibility standards for electronic content and software, including WCAG 2.0 Level AA, and require submission of a current VPAT or ACR to confirm compliance, with remediation timelines provided if gaps exist. Solutions must operate on native IPv6 and dual-stack networks across all public and internal systems, and any cloud, SaaS, or hosted components must have validated federal authorization status such as FedRAMP, agency ATO, or DoD accreditation. Transition plans for new solutions must include detailed implementation timelines, data migration or recreation steps, integration dependencies, training requirements, licensing assumptions, and rollback strategies to maintain uninterrupted scanning and reporting capabilities. Pricing must be broken down into subscription/software, support, professional services, migration, training, and transition costs, with clear explanation of licensing metrics—such as IPs, endpoints
General Info
Agency
NAICS
Place of Performance
NJSet-Aside
Timeline
Submission Closed
Organization & Contact Information
Full Description
More opportunities from Department Of Veterans Affairs → Technology Acquisition Center Nj (36C10B)
Same awarding agency
Find Active Opportunities Like This
Get AI-powered intelligence on the opportunities still open
Every page of the solicitation package shredded into a compliance breakdown
AI-powered matching based on your capabilities and past performance
Competitor and incumbent history on the requirement
Automated alerts on amendments, Q&A deadlines, and award
Join 650+ contractors already using CLEATUS
