The Fleet Logistics Center Norfolk seeks qualified sources for a two-week, on-site cybersecurity assessment of the United States Naval Academy's (USNA) unclassified educational environment. This Sources Sought Notice is for planning purposes only, anticipating a single-award, Firm-Fixed-Price (FFP) contract under NAICS code 541519. The assessment will mirror the Department of War’s CORA Team methodology to identify security vulnerabilities and risks, with detailed specifications outlined in an attached Statement of Work. This is not a solicitation; the government will not award a contract from this announcement or pay for submitted information. Interested parties must email capability statements and/or estimates by December 9, 2025, to Ms. Jordan Walton, including company, CAGE Code, SAM registration, business size, and existing government contract vehicle information if applicable. All communications must be in writing; telephone requests will not be honored.
This Statement of Work (SOW) outlines a two-week mock Cyber Operational Readiness Assessment (CORA) for the United States Naval Academy's (USNA) unclassified educational environment. The assessment, modeled after the Department of War's CORA Team, aims to identify security vulnerabilities, ensure compliance with DISA STIGs/SRGs and DoW orders, and provide actionable remediation recommendations. The scope includes boundary/DMZ systems, select internal web sites, servers, virtual environments, wireless networks, databases, firewalls, IDS/IPS, and key network switches. It also involves a documentation review of security policies and plans. Excluded are guest wired and wireless networks. The methodology incorporates vulnerability scanning using USNA's ACAS, configuration audits, and policy reviews. The project timeline spans two weeks for discovery, assessment, validation, and analysis, followed by a reporting phase, with the final report delivery within 30 business days. The sole deliverable is a comprehensive CORA Assessment Report, including an executive summary, detailed findings with risk ratings, actionable recommendations, and a presentation. Responsibilities are divided, with the assessor executing inspection activities and maintaining confidentiality, while USNA provides necessary access, credentials, and ensures system operational readiness.