The Defense Information Systems Agency posted a sources-sought notice on June 16, 2026, for the Army Endpoint Security Event Management System, a consolidated cybersecurity recompete carrying an estimated ceiling of $850 million over a two-year base period and eight one-year option periods. The solicitation targets a globally distributed environment spanning Army enterprise and tactical networks, multiple Regional Cyber Centers, and installations both inside and outside the continental United States. Incumbent Everforth ECS, formerly ECS Federal, holds the larger portion of the current work through an Alliant 2 task order, with a second piece held under a separate IDIQ by another contractor — both expiring in 2027. Everforth ECS has accumulated approximately $275 million in task order volume on the program since 2022, with the larger Alliant 2 task order running through September 2027.

Background

The Army Endpoint Security Event Management System supports two major Army organizations: Project Manager Command and Control Infrastructure and the Network Enterprise Technology Command. Together, these commands manage the Army's sprawling enterprise and tactical IT networks, requiring continuous visibility into endpoint health, threat detection, and response across a force that operates globally and in contested communication environments where connectivity is never guaranteed.

DISA is handling the acquisition on the Army's behalf, a common arrangement for enterprise IT programs that benefit from DISA's cybersecurity acquisition expertise and existing contract vehicles. The agency's broad portfolio of endpoint security programs across the department gives it institutional knowledge that the Army leverages when recompeting work of this complexity and scale. DISA has run similar large-scale endpoint programs for other components of the department, making it the natural home for an acquisition of this size and technical specificity.

What distinguishes this recompete from its predecessor is scope consolidation. DISA is combining two previously separate contracts into a single procurement for the first time, centralizing endpoint security management under one awardee. The move reflects a broader federal trend toward vendor consolidation in cybersecurity programs — fewer integration seams, clearer accountability, and reduced licensing overhead across a massive, heterogeneous network environment spanning both garrison and tactical nodes. A single contractor managing the unified stack can also more effectively enforce consistent Zero Trust policy controls across all Army endpoints, which the current split-contract model complicates.

Everforth ECS won the original larger task order under the Alliant 2 governmentwide acquisition contract managed by the General Services Administration. Alliant 2 is a preferred vehicle for large IDIQ IT services competitions, and the recompete may again use a similar multiple-award vehicle or move to a standalone solicitation depending on final acquisition strategy decisions DISA makes after evaluating sources-sought responses.

Key Details

The primary place of performance is the Global Cyber Center at Fort Huachuca, Arizona, home to the Army's Network Enterprise Technology Command and a key hub for Army enterprise cybersecurity operations. Program oversight is managed out of Aberdeen Proving Ground, Maryland, with support across four Regional Cyber Centers in the United States and overseas. Contractors must hold a Top Secret Facility Clearance, with personnel requiring Secret-level clearances at minimum — requirements that narrow the competitive field to firms already embedded in the defense IT sector.

The technical stack specified in the sources-sought notice reflects current enterprise cybersecurity practice: Microsoft Defender for Endpoint and Elastic Defend for host-based protection, Elastic Stack for security information and event management, Forescout for network access control and device visibility, and a government Azure cloud environment. Additional components include Kubernetes, Apache Kafka, and Cribl as part of a hybrid-cloud unified SIEM capability. The Zero Trust architecture requirement — with default-deny application controls — aligns with the Army's published Zero Trust strategy and the broader federal mandate that followed the 2021 executive order on improving national cybersecurity.

The $850 million ceiling covers the full 10-year potential performance period, consisting of two base years plus eight one-year option periods. IDIQ ceilings represent maximum ordering authority, not guaranteed spending — actual obligated amounts depend on task orders issued during the performance period. For context, Everforth ECS has accumulated approximately $275 million in task order volume on the program since 2022, suggesting annual run rates in the $65 million to $75 million range. The new ceiling is sized to accommodate scope growth as the Army expands its endpoint visibility requirements and strengthens Zero Trust enforcement across a larger number of managed devices.

Responses to the request for information were due June 29, 2026, at 12:30 p.m. Eastern time. The sources-sought notice is a market research step and does not constitute a formal solicitation — DISA uses the responses to gauge industry interest, identify qualified performers, and inform acquisition strategy decisions such as set-aside type and contract vehicle selection before releasing a formal Request for Proposals. The contract is expected to begin performance in March 2027.

What It Means for Contractors

  • Respond to the RFI to shape the acquisition strategy. Sources-sought responses directly influence DISA's set-aside determination, vehicle selection, and technical requirements. Firms with relevant Alliant 2 task order experience managing large-scale endpoint security environments should make the case for their qualifications before the June 29 deadline.
  • Demonstrate Zero Trust and multi-tool integration experience. The notice specifically calls out Microsoft Defender for Endpoint, Elastic Stack, Elastic Defend, Forescout, Azure, Kubernetes, Apache Kafka, and Cribl — contractors whose past performance covers this stack in a similarly scaled DoD environment will have a competitive advantage. Firms that have implemented default-deny application controls in a DoD context should highlight that work explicitly.
  • Prepare for an Alliant 2 or follow-on GWAC competition. Given that the incumbent holds the larger work via an Alliant 2 task order, DISA may issue the recompete on Alliant 2 or a successor vehicle. Firms not currently on Alliant 2 should monitor whether DISA opts for a standalone solicitation, which would open the competition more broadly.
  • Account for the consolidated scope in teaming plans. The single-contract structure means one awardee manages the full endpoint security stack across the Army's enterprise and tactical networks. Teaming arrangements that cover managed detection and response, network access control, cloud security operations, and Zero Trust policy enforcement are likely more competitive than narrow point-solution bids.
  • Set SAM.gov alerts for the formal RFP release. The sources-sought is the first public signal; the formal solicitation will post on SAM.gov. Firms should configure alerts for DISA and Network Enterprise Technology Command solicitations covering cybersecurity managed services to avoid missing the RFP release window.

Sources