Cloud Based Internet Isolation Service
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Defense Information Systems Agency (DISA), on behalf of the Department of War (DoW), is soliciting proposals for a Cloud Based Internet Isolation (CBII) Service. This requirement is for a proprietary, commercial off-the-shelf, brand-name Menlo Security, Inc.’s Cloud Browser product, delivered as a managed service. The service will enhance cybersecurity measures by renewing existing and procuring new subscription licenses, and incorporating Menlo Security's HEAT Shield with AI/ML capabilities. Proposals are due March 23, 2026, at 3 PM CST.
Scope of Work
The managed service will provide secure, cloud-based internet isolation for up to 3.4 million DoW users, ensuring safe web access and mitigating cyber threats. Key services include delivering, deploying, and sustaining a FedRAMP+ Level 2 compliant solution, program support, tiered service desk infrastructure, engineering, migration support, user training, and Accreditation & Authorization (A&A) support. Capabilities encompass destination-based whitelisting/blacklisting, web content filtering, malware scanning, Data Loss Prevention (DLP), and web isolation within a secure container. Personnel must possess a Final Secret clearance.
Contract & Timeline
- Type: Firm Fixed Price (FFP) for managed services; Cost-Reimbursable for travel. Invoicing will be monthly in arrears based on actual usage (averaging 2.0-2.1 million active users).
- Duration: One-year base ordering period (April 15, 2026 - April 14, 2027) and four one-year option periods, totaling up to five years. A 6-month extension for evaluation is included per FAR 52.217-8.
- Set-Aside: Unrestricted. A Justification for Other Than Full and Open Competition (J&A) specifies the brand-name Menlo Security, Inc.'s MSCB product and states it cannot be set aside for small businesses.
- NAICS: 541519, Size Standard: $34,000,000.
- Proposal Due: March 23, 2026, at 3 PM CST.
- Questions Due: March 11, 2026, at 3 PM CST (now passed).
- Published: March 12, 2026.
Evaluation
Award will be made to the responsible offeror whose proposal represents the overall best value using a Lowest Price Technically Acceptable (LPTA) evaluation process.
Special Requirements
Contractors must comply with Cybersecurity Maturity Model Certification (CMMC) Level 2. While CMMC Level 2 (Self) is acceptable at award, C3PAO compliance is required by the first option year. The solution must integrate with DISN Joint Infrastructure (DJI) security stack and support DoW PKI/PIV authentication.