Cloud Based Internet Isolation Service
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Defense Information Systems Agency (DISA), under the Department of Defense, is soliciting proposals for a Cloud Based Internet Isolation (CBII) Service (RFP HC108426R0005). This opportunity seeks a managed service provider for a proprietary, brand-name Menlo Security, Inc. Cloud Browser solution to support up to 3.4 million Department of War (DoW) users. Proposals are due March 30, 2026, by 12:00 PM CST.
Scope of Work
The requirement is to maintain and enhance a secure, cloud-based internet isolation managed service. This includes:
- Delivering and sustaining a FedRAMP+ Level 2 compliant Cloud Service Offering (CSO) engineered by Menlo Security, Inc.
- Providing internet traffic isolation, threat mitigation, and Data Loss Prevention (DLP).
- Offering operational service support through a tiered service desk.
- Supporting Accreditation & Authorization (A&A) activities under the Risk Management Framework (RMF).
- Managing user migration, sustainment, training, and engineering support services.
- Incorporating Menlo Security, Inc.'s Highly Evasive and Adaptive Threats (HEAT) Shield with AI/ML capabilities.
Contract Details
- Type: Firm Fixed Price (FFP) contract.
- Period of Performance: A one-year base ordering period (April 15, 2026 - April 14, 2027) and four one-year option periods, totaling up to five years.
- Set-Aside: Unrestricted. This is a brand-name specific procurement for Menlo Security, Inc.'s MSCB product, justified due to its critical role since 2020 and lack of suitable alternatives. It cannot be set aside for small businesses.
- Pricing Model: Monthly invoicing will be based on 3.2 million DoW users, not actual usage. Usage-based pricing has been removed. Surge support will be provided at proposed and fair/reasonable rates.
Key Requirements
- Personnel must possess a Final Secret clearance.
- Compliance with FedRAMP+ Level 2 and CMMC Level 2 is mandatory (Self-assessment at award, C3PAO by first option year).
- Interoperability with DISN Joint Infrastructure (DJI) security stack and support for IPv6.
- All data must reside on servers located in the United States.
Submission & Evaluation
- Proposal Due: March 30, 2026, by 12:00 PM CST.
- Additional Questions Due: March 26, 2026, at 10:00 AM CST.
- Evaluation: Award will be made using a Lowest Price Technically Acceptable (LPTA) process.
- Instructions: Previously submitted proposals must be resubmitted in their entirety. Volume II (Technical/Management Approach) file size limit is 20MB, accepting PowerPoint or PDF. Cover pages, table of contents, and summary slides are excluded from page limits.
Additional Notes
This solicitation is for a critical national security service, leveraging an existing, proven solution.