Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 2 at 2:00 PM EDT

Register Free →

STAMP Out: Improving Software Security with Open Source Static Analysis Tools

Active
70RSAT19R00000036Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The Department of Homeland Security’s Science and Technology Directorate (DHS S&T) intends to award a sole source contract to GrammaTech, Inc. to continue work on the Static Tool Analysis Modernization Project (STAMP), which focuses on advancing software assurance through improved static analysis tools. GrammaTech was previously selected from a competitive Broad Agency Announcement and remained the sole performer after a down-select process. The new contract is necessary because the previous contract was an assisted acquisition handled by the Department of Health and Human Services (HHS), which can no longer support the requirement. The research under the new contract will build upon prior STAMP work, avoiding duplication of effort, and aims to enhance tool performance, increase coverage of software weaknesses, improve integration with DevOps environments, and reduce false positives and false negatives in software analysis. The project addresses the critical need to improve cybersecurity for vital national infrastructure increasingly reliant on complex and open-source software. STAMP’s goal is to develop state-of-the-art testing, evaluation, and modernization methodologies for static analysis tools, benefiting the Software Assurance Marketplace (SWAMP). GrammaTech is uniquely qualified due to its deep expertise in software analysis, understanding of the software security lifecycle, experience with NIST’s SAMATE program, and proven capabilities in developing test cases, performing white-box and black-box testing, and creating unified software assurance methodologies. The contract will involve R&D, technical writing, web portal design, and application of machine learning techniques, with primary work performed at GrammaTech’s facilities in Ithaca, NY, and certain DHS-designated government sites. The contract period includes a 12-month base and a six-month option, and the government is not using any multi-award or GSA schedules for this acquisition.

General Info

Sole source contract to GrammaTech for advancing static analysis tools under DHS STAMP project.

Agency

Department Of Homeland Security → Contract Administration Svcs DivisionView Agency

NAICS

541715 - Research and Development in the Physical, Engineering, and Life Sciences (except Nanotechnology and Biotechnology)View NAICS

Place of Performance

GrammaTech Inc. 531 Etsy Street, ITHACA, NY, 14850, USA

Set-Aside

NONE

Documents

(0)

No documents available

AI Contract Breakdown

Uniform Contract Format

No contract breakdown available.

Cannot generate Contract Breakdown because no documents were found from this contract's source.

Timeline

PhasePresolicitation
Posted

Presolicitation

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Homeland Security → Contract Administration Svcs Division
Contacts2 people available
OfficeWASHINGTON, DC, 20528, USA
Organization / Agency
Department Of Homeland Security → Contract Administration Svcs Division
View Agency Profile
Office AddressWASHINGTON, DC, 20528, USA
Contacts
Jennifer K. KoonsContract Specialist
Carolyn Lethert

Full Description

Show more
This is a synopsis of a Department of Homeland Security (DHS) Science and Technology Directorate (S&T) requirement to be solicited on a sole source basis to: GrammaTech, Inc. 531 Etsy Street Ithaca, NY 14850 This is a noncompetitive action under FAR 6.302-1. Based on DHS S&T's market research and in-depth knowledge of the software assurance static analysis tools landscape GrammaTech is the best qualified company to execute this research. S&T awarded a contract to GrammaTech under a full and open Broad Agency Announcement which provided a group of contractors capable of doing this work. S&T selected two companies from this group to begin the Static Tool Analysis Modernizatoin Project (STAMP), with the intent of down selecting to the performer that best executed the project objectives. GrammaTech remained as a performer after this down select. The GrammaTech contract was awarded as an assisted acquisition by the Department of Health and Human Services (HHS). However, HHS is no longer able to service this requirement and DHS S&T still has the requirement. The work GrammaTech still has left under the HHS contract will not be done unless DHS awards a new contract to GrammaTech. The research proposed for the base and option periods builds substantially on work already completed under the STAMP project. It would be a significant duplication of effort and investment for the Government to select another performer through full and open competition and have them repeat work already completed by GrammaTech. The Government anticipates awarding a stand-alone contract as a result of the solicitation. The Government is not utilizing a General Services Administration Schedule or any sort of Government-wide or multiple-award contract to issue an order. The primary place of performance will be at GrammaTech facilities and certain Government facilities designated by DHS S&T. The period of performance will include a 12-month base and one 6-month option period. No response to this synopsis is requested. All responsible sources may submit a capability statement, proposal, or quotation, which shall be considered by the agency. The following is a summary of the requirement: DHS is committed to using cutting-edge technologies and scientific talent in its quest to make America safer. The DHS S&T is tasked with researching and organizing the scientific, engineering, and technological resources of the United States and leveraging these existing resources into technological tools to help protect the homeland. One element of the DHS S&T research and development portfolio is Cyber Security research and more specifically, software assurance. The nation's critical infrastructure (e.g., energy, transportation, financial services) and society are extensively and increasingly controlled by software. However, weaknesses in software expose vulnerabilities that put these critical infrastructure resources at risk. As of October 2017, the National Vulnerability Database (NVD) reported more than 12,000 vulnerabilities in the calendar year. That's nearly double the number reported in 2015 and 2016. This risk is compounded by software size and complexity and the growing reliance on reusable software code and open-source software in organizations. The current state-of-the-art software assurance tools have not kept pace with modern software. The complexity and size of software make it more difficult for software analysis tools to perform. Oftentimes these tools have difficulty tracking data flows through complex and large software systems, to the point that software analysis tools oversimplify and make assumptions about software code that is inaccurate. The goal of STAMP is to modernize a list of candidate software analysis tools to improve tool performance and coverage, to seamlessly integrate and support continuous integration and DevOps operational environments and provide more accurate analysis of results by reducing false-positives and provide more visibility into false-negatives that often leave residual risks. STAMP is designed to create new techniques that advance the state-of-the-art capabilities found in software analysis tools and will help address the risks posed by the increasing use of software. STAMP will improve the testing and evaluation of static analysis tools, with a focus towards improving deployment and understanding as well as expanding weakness coverage and strength of tools for use in the Software Assurance Marketplace (SWAMP). In addition, GrammaTech Inc. will develop and implement a repeatable methodology for testing, evaluation, and modernizing existing open-source static analysis tools. To perform this work, the contractor will need to have the following minimum capabilities: - Deep understanding of the current state of static analysis tools, including the shortcomings of the various tool vendors, the challenges facing software security implementers as they consider acquiring software assurance tools - In depth knowledge of the software security life cycle and how it must be integrated into the software development work flow - Deep corporate experience in software analysis and flaw-finding capability, particularly as applied in a research and development environment - Understanding of and previous experience working with the National Institute of Standards and Technology, specifically their Software Assurance Metrics And Tool Evaluation (SAMATE) program - Previously demonstrated experience developing realistic test cases, at scale, based on real open source code - Previously demonstrated experience performing both white box and black box testing of static analysis tools - Previously demonstrated experience in developing a unified methodology for software assurance testing, including consideration of the following: test-case generation, target development languages and existing tools, assessment, tool development, evaluation, and deployment. The contractor will also need to have personnel to conduct research and development, do technical writing and editing, web portal design, incorporating machine learning and other data science techniques into software testing and perform program management tasks and reporting.

Similar Contracts

Same NAICS industry code

NAICS: 541715
New
Federal
Federal Protective Service (FPS) Network Scanning Tool
Solicitation # 70RSAT26RFI000028
The Department of Homeland Security Science and Technology Directorate, through the Homeland Security Advanced Research Projects Agency, is conducting market research to develop a portable, agentless network scanning tool for the Federal Protective Service. The objective is to create a solution capable of real-time discovery and inventory of Information Technology, Internet of Things, and Operational Technology assets, specifically for use in environments lacking centralized monitoring. The selected contractor will be responsible for the design, development, testing, and delivery of the tool, including a user interface, comprehensive documentation, and training materials. The tool must integrate with existing inventory and reporting systems and comply with federal cybersecurity standards such as FISMA and NIST. The project is estimated at a total cost of 2,000,000 dollars with a performance period of twelve months from the date of award. While the tool must be durable and portable, the government has clarified that a ruggedized transport case is sufficient for the electronic components, and individual components do not require independent ruggedization. This effort is currently in the Request for Information stage under NAICS code 541715 to identify qualified sources and evaluate technical capabilities, including the use of Best-in-Class vehicles. Access to sensitive or classified information is not required for the execution of this statement of work.
Sci Technology Acq Division

POSTED

about 17 hours ago

DEADLINE

in about 16 hours
View Details
NAICS: 541715
New
Federal
Stryker Family of Vehicles Commercial Solutions Opening
Solicitation # W912CH-26-S-0010
The Commercial Solutions Opening (CSO) under solicitation W912CH-26-S-0010, issued by the Army Contracting Command – Detroit Arsenal for the Program Manager Stryker Brigade Combat Team, is designed to accelerate the acquisition of innovative commercial technologies to modernize the Stryker Family of Vehicles. This CSO remains open until May 7, 2031, but companies cannot submit proposals directly in response to this announcement; instead, they must monitor SAM.gov for individual Areas of Interest (AoIs), which serve as the only authorized portals for proposal submissions. Each AoI will define specific needs, deadlines, and delivery requirements, with proposals evaluated under a streamlined, multi-phase process: submission of a Solution Brief, optional presentation or pitch, and finally, a full Commercial Solution Proposal. Proposals must be submitted in two separate volumes—Technical and Price—with the Technical Volume capped at 20 pages and the Solution Brief limited to either five pages or fifteen slides. All submissions must be unclassified, in Word or PDF format, and submitted exclusively through the active AoI posting on SAM.gov. Awards under this CSO may take the form of FAR Part 12 Fixed-Price contracts or Other Transaction Authority (OTA) agreements under 10 U.S.C. 4022, with no reimbursement for proposal development costs. The evaluation is non-LPTA and based on a trade-off approach considering eight factors in descending order of importance: solution relevance, technical merit, innovation level, technical risk, cost risk, schedule risk, company viability, and intellectual property/data rights risk. Offerors must have a valid Unique Entity ID and be registered in SAM.gov, and must submit a Warranties and Representations form to establish eligibility. While no socioeconomic certifications are required, foreign-owned entities must be able to obtain necessary security clearances to access prescribed information. Payment will be processed through WAWF, and the contracting officer contacts are Marta Furman and Taylor Ferguson. The Government may negotiate follow-on production contracts without competition after successful prototype development, and no formal contract value or line-item pricing is specified in this solicitation, as pricing and scope are defined per AoI. The place of performance and delivery terms vary by AoI, with Michigan's Detroit Arsenal area serving as the contracting office location.
Department Of The Army

POSTED

about 17 hours ago

DEADLINE

in over 4 years
View Details
NAICS: 541715
New
Federal
Army Advanced Manufacturing (AdvM) Commercial Solutions Opening (CSO)
Solicitation # W9124P26SC001
The Army Advanced Manufacturing (AdvM) Commercial Solutions Opening (CSO), identified by solicitation number W9124P26SC001, is an ongoing, open solicitation managed by the Army Contracting Command – Redstone Arsenal to identify and acquire innovative commercial technologies that enhance manufacturing, maintenance, and sustainment capabilities across the Army’s Organic Industrial Base and at the tactical edge. This initiative leverages flexible acquisition authorities including 10 U.S.C. § 3458, § 4022, DFARS RFO 212.70, and the Employee Stock Ownership Pilot Program to support rapid prototyping and fielding of advanced manufacturing solutions in areas such as additive manufacturing, digital twins, Industrial Internet of Things, cybersecurity integration, and process qualification. Proposals are submitted through a two-phase process: Phase 1 requires a one-page Quad Chart and a five-page White Paper formatted in 12-point Times New Roman, single-spaced, with one-inch margins, submitted via email to the designated mailbox. While the CSO remains continuously open, specific Calls for Solutions will have defined deadlines, and only commercially available solutions meeting the defined Areas of Interest are considered. The Government retains the right to issue amendments, which will be highlighted in yellow for transparency, and does not guarantee that any Request for Information will lead to a follow-on opportunity. Award decisions are based on a best-value trade-off process, evaluating technical merit and relevance first, followed by innovation and uniqueness, company viability—including corporate experience, personnel qualifications, and data rights identification—and price and affordability. Non-cost factors collectively carry significantly more weight than cost, making this a non-LPTA process. All awards will be made as Firm-Fixed-Price contracts under DFARS RFO 212.7002(b), with potential award instruments including IDIQ contracts, Other Transaction Agreements, or direct purchase orders. Offerors must be registered in SAM.gov and hold an active Unique Entity ID, but no socioeconomic set-asides or size status certifications are mandated. Submission costs are not reimbursable, and proposals must comply with DFARS data rights clauses, particularly regarding intellectual property and technical data disclosure. Performance will be centered at Redstone Arsenal, Alabama, with operational delivery targeted to the OIB and tactical locations. No packaging, marking, or inspection standards are specified beyond the requirement that proposed solutions must demonstrate validated prototypes, qualified manufacturing processes, or commercialized technologies aligned with Army modernization priorities. The Government conducts all evaluation
W6QK Acc-Rsa

POSTED

about 17 hours ago

DEADLINE

N/A
View Details
NAICS: 541715
New
Federal
ARMY OPEN SOLICITATION (AOS)
Solicitation # W9128Z-25-S-A002
The Army Open Solicitation (AOS), identified by solicitation number W9128Z-25-S-A002, is an indefinite, open solicitation issued by the U.S. Army Contracting Command – Aberdeen Proving Ground to rapidly acquire innovative commercial technologies and research-driven solutions across all Army mission areas. Designed to revitalizing the industrial base and enhancing Warfighter lethality, the solicitation leverages a flexible acquisition framework under multiple FAR, DFARS, and U.S. Code authorities, including Other Transactions, Commercial Solutions Opening, and prototype authorities. It supports both Active Capability Gap submissions and periodic Calls for Solutions, with responses evaluated based on technical merit, feasibility, schedule, price estimation, viability, and desirability using a trade-off approach rather than lowest price technically acceptable. The solicitation remains open indefinitely until canceled, with recent amendments through March 2026 expanding and clarifying Army Example Areas, refining submission procedures, and updating contracting information including Active Capability Gap mailboxes. All submissions must adhere to strict formatting requirements, including a single PDF submission not exceeding five pages or fifteen slides, with mandatory inclusion of an executive summary, company information, and rough order of magnitude cost and schedule estimates. Offerors must be registered in SAM, use WAWF for invoicing, and comply with stringent data storage and security requirements, including U.S.-only data hosting and full organizational conflict of interest disclosures. The solicitation encourages participation from small businesses, nontraditional defense contractors, and nonprofit research institutions, with specific certifications required through the Affirmation of Business Status Certification. Performance may occur at government facilities including Aberdeen Proving Ground and other CONUS/OCONUS locations as directed, with award timing anticipated in fiscal year 2026, and support expected through 2032. No fixed contract value is provided, as pricing is determined through competitive evaluation of commercial proposals under the solicitation's open-ended structure.
W6QK Acc-Apg Contr Ctr

POSTED

about 17 hours ago

DEADLINE

N/A
View Details
NAICS: 541715
New
Federal
Broad Agency Announcement _ TRMC _ TE-ST _ W900KK-22-R-0012
Solicitation # W900KK-22-R-0012
The Broad Agency Announcement W900KK-22-R-0012 is a long-term solicitation active through March 14, 2037, aimed at advancing Research, Development, Test and Evaluation (RDT&E) technologies to enhance the Department of Defense’s Test and Evaluation/Science and Technology (T&E/S&T) capabilities. It targets Technology Readiness Levels (TRLs) 3–6, focusing on innovations that will make T&E processes higher quality, more cost-effective, and faster across Developmental, Operational, and Live-Fire Testing domains. The program actively seeks novel, high-risk, high-payoff solutions that are too unconventional for current DoD adoption, prioritizing technical merit and mission relevance over cost. Proposals must align with specific Opportunity Notices detailing technical areas such as high-G centrifuges for IMU testing, requiring precision engineering, sustainability planning, and compliance with advanced performance metrics. Submission requires a multi-volume technical and cost proposal adhering to strict formatting, page limits, and naming conventions, with all documents delivered electronically to designated officials by the deadline. Key attachments include signed data rights, intellectual property assertions, cost worksheets, and project quad charts, all subject to Controlled Unclassified Information (CUI), export control, and Limited Dissemination markings. Evaluation prioritizes scientific and technical merit equally with mission relevance, followed by cost realism, using a trade-off process rather than Lowest Price Technically Acceptable. Contractors must comply with rigorous security protocols including Facility Clearance Levels, NISPOM standards, antiterrorism training, and organizational conflict of interest disclosures, particularly when providing prior advising services to TRMC. All work must be performed under strict data rights agreements, with the government expecting unlimited rights to developed IP unless explicitly restricted, and prohibits public dissemination of results without approval under ITAR or CUI regulations. Performance is structured in phased milestones with defined exit criteria and deliverables including prototypes, software with source code, and system documentation, all subject to Government inspection and acceptance via DD Form 250 at designated facilities, with no FOB terms specified. Submission is governed by a clear chain of contact, administrative requirements, and adherence to federal acquisition guidelines, but no contract value, funding ceiling, or payment details are provided in the solicitation.
W6QK Acc-Apg-Orlando

POSTED

about 17 hours ago

DEADLINE

in over 3 years
View Details