Continuous Monitoring Analytical Tool Set (CMATS) Development and Sustainment

SOL #: 832674365Sources Sought

Overview

Buyer

DEPT OF DEFENSE
Defense Information Systems Agency (Disa)
IT CONTRACTING DIVISION - PL83
SCOTT AFB, IL, 62225-5406, United States

Place of Performance

St James, MD

NAICS

Other Computer Related Services (541519)

PSC

No PSC code specified

Set Aside

Total Small Business Set-Aside (FAR 19.5) (SBA)

Timeline

1
Posted
Apr 9, 2026
2
Response Deadline
Apr 23, 2026, 7:00 PM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

The Defense Information Systems Agency (DISA) is conducting a Sources Sought to identify qualified small businesses for the Continuous Monitoring Analytical Tool Set (CMATS) Development and Sustainment. This effort focuses on modernizing, developing, and sustaining the CMATS portfolio, including migrating applications to a Joint Warfighter Cloud Capability (JWCC) Azure Cloud environment. This is a Total Small Business Set-Aside. Responses are due April 23, 2026.

Purpose & Scope

DISA seeks to gather information on industry capabilities for the continued development, sustainment, support, and modernization of the CMATS portfolio. The objective is to ensure robust endpoint attribution tag management, policy management, and continuous monitoring across the Department of Defense (DoD). The scope includes:

  • Core CMATS Portfolio: Development, sustainment, modernization, and integration of existing capabilities like Continuous Monitoring Risk Scoring (CMRS), Cyber Operational Attribute Management System (COAMS), Enterprise User Management (EUM), and Information Assurance Vulnerability Management (IAVM).
  • New Capabilities: Development and integration of new functionalities.
  • Cloud Modernization: Migrating the CMATS platform to a JWCC Azure Cloud environment.
  • Data Analytics & Visualization: Enhancing data analytics, developing new data sources, and improving visualization.
  • Endpoint Attribution: Development and sustainment of tools such as Device Attribution Tagging Tool (DATT) and Central Attribution Management Portal (CAMP).
  • Support Services: Requirements analysis, prototyping, custom code, cybersecurity analysis, COTS/OSS/GOTS integration, QA, testing, deployment, documentation, help desk, and lab administration. Four concurrent development teams are anticipated, focusing on CMRS, EUM & COAMS, IAVM, and DATT/CAMP.

Anticipated Contract Details

  • Type: Sources Sought (for market research, not an RFP)
  • Anticipated Period of Performance: Base period from July 01, 2027 – June 30, 2028, with four option periods extending through June 30, 2032.
  • Place of Performance: Primarily contractor facility, with some work at DISA HQ, Fort Meade, MD.
  • Set-Aside: Total Small Business Set-Aside (FAR 19.5).
  • NAICS Code: 541519 (Computer Systems Design Services), with a size standard of $34M.

Key Requirements & Capabilities

Respondents should demonstrate experience in:

  • Software Development Lifecycle: Agile methodologies, requirements capture, testing, configuration management, and deployment.
  • Cloud Migration: Migrating legacy Microsoft systems to cloud environments, specifically to JWCC Azure.
  • Team Management: Managing up to five software development teams.
  • Data Integration & Analytics: Ingesting, normalizing, processing, and providing consumable results from various data sources, and building/maintaining analytics from changing datasets.
  • Security: All personnel must be U.S. citizens with a Secret security clearance, and the contractor facility must have a Secret Facility Clearance. Adherence to RMF, NIST SP 800-53, STIGs, and CMMC (level to be specified) is required.
  • Agile Development: Strict adherence to Agile SCRUM.

Background & Incumbents

This is a new requirement, though portions are currently performed under existing contracts:

  • Continuous Monitoring Risk Scoring Development and Sustainment: HC1028-23-F-0003 (Incumbent: Foxhole Technology, Small Business)
  • Secure Configuration Management Development and Operations: HC1028-22-F-0276 (Incumbent: Superlative Technologies, Small Business)
  • Device Attribute Tagging Tool (DATT) Maintenance and Implementation Support: HC1028-25-F-0166 (Incumbent: Booz Allen Hamilton, Large Business)

Submission Details

  • Deadline: April 23, 2026, at 7:00 PM ET (19:00:00Z).
  • Submission: Email a brief capabilities statement (maximum 7 pages) to carly.a.youngless.civ@mail.mil and kenric.l.phillips.civ@mail.mil.
  • Content: Address required capabilities, business name/address, representative name/title, socio-economic status, CAGE Code, and prime contract vehicles. Demonstrate ability to comply with FAR clause 52.219-14, Limitations on Subcontracting.
  • Disclaimer: This is for informational purposes only and does not constitute a solicitation. The government is not obligated to award a contract, and no funds are available for response preparation.

People

Points of Contact

Carly YounglessPRIMARY
Kenric PhillipsSECONDARY

Files

Files

Download
Download

Versions

Version 1Viewing
Sources Sought
Posted: Apr 9, 2026
Continuous Monitoring Analytical Tool Set (CMATS) Development and Sustainment | GovScope