Advertisement

DISA issues additional notice to industry for massive migration of combatant commands to DoDNet

Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
(Getty Images)

The Defense Information Systems Agency issued another sources-sought notice Thursday as it prepares to initiate a massive transition of combatant commands from legacy common-use IT services and assets they have been independently operating and maintaining to a single service provider.

The issuance follows the release of a directive from Pentagon Chief Information Officer Kirsten Davies a few months ago calling on DISA, as the designated SSP for the effort, to provide the CIO’s office with a briefing laying out the program’s scope, execution milestones, resource requirements and baseline service delivery model.

Specifically, the agency has been tasked to oversee migrations for all Non-Classified Internet Protocol Router Network (NIPRNet) and classified Secure Internet Protocol Router Network (SIPRNet) common-use IT by the end of fiscal 2028 into a DISA-managed system known as DoDNet.

“This consolidation is essential to advancing enterprise modernization; improving operational efficiency; and ensuring resilient, lethal, and mission-ready network capabilities. The SSP environment ensures CCMDs operate within a zero-trust enabled cybersecurity environment and with a uniform user experience across all commands,” Davies wrote in her memo.

Advertisement

According to the sources-sought notice, there are approximately 231,000 users of legacy environments at approximately 200 sites across the U.S. military’s 11 combatant commands, which include Northern Command, Southern Command, Pacific Command, European Command, Africa Command, Central Command, Space Command, Special Operations Command, Transportation Command, Strategic Command and Cyber Command.

DISA is seeking contractor support for the migration effort.

The agency aims to provide “a single contract with capability for all migration activities from customer contact, discovery effort, migration of networks and endpoints, and to transition to operations,” according to the notice.

Per the notice, a contractor tapped for the effort must have expertise in several capability areas including identity, credential, and access management, zero trust architecture, infrastructure-as-code and automation scripts, migration methodologies, and runbooks.

Officials noted that an effort to migrate Defense Agencies and Field Activities to the DoDNet environment is already underway and that the migration initiative for combatant commands must be executed without hampering those other migrations.

Advertisement

DISA previously issued a sources-sought notice in July with an Aug. 4 response date. In the new notice released a month later, the agency asked companies to provide information about their experience handling “unmanaged environments and parallel baselines,” modernization execution and “velocity,” and training and adoption.

“Provide one or two concrete examples of projects similar in Department of War (DOW) scope and magnitude (approx. 20 locations / 12,000 users) where you successfully executed network and endpoint discovery, migration planning, and execution for an environment you did not currently manage,” officials wrote, using the Trump administration’s preferred name for the Department of Defense. “Specifically, detail your experience migrating to a new baseline in parallel with a physical lifecycle hardware replacement.”

The agency also requested concrete examples from vendors of successfully performing automated migrations from legacy endpoint tools to modernized device management solutions within a DOD environment.

For more insight into how a contractor would bring department personnel up to speed, DISA sought details about companies’ strategies to “deploy an accelerated ramp up in geographically disperse locations,” including the specific “tools, platforms, or methodologies” that they’ve used in previous efforts to “minimize the learning curve and ensure uninterrupted mission readiness for users transitioning to a new integrated endpoint and network service provider.”

Officials gave industry a tight deadline to respond: 3 p.m. EDT on Aug. 28.

Latest Podcasts