Request for Information- VA Enterprise-level Product Solutions.docx

DOCX document 66 KB Posted

Attached to
DA10-VA Enterprise-level Product Solutions Federal contract opportunity
Solicitation number
36C10B27Q0025
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This is a Request for Information (RFI) issued by the Department of Veterans Affairs Technology Acquisition Center for market research on enterprise-level product solutions. The VA is conducting solution-agnostic market research to evaluate alternative products and solutions across multiple capability areas currently supported by its Microsoft Enterprise Agreement, serving over 540,000 users. This RFI does not constitute a commitment to contract, does not obligate the government, and does not guarantee a follow-on procurement; respondents will not be reimbursed for submission costs, and all submitted information becomes government property.

The RFI seeks information on enterprise solutions spanning 14 key capability areas: productivity and collaboration, identity and access management, unified endpoint management, endpoint operating system licensing, endpoint detection and response, identity threat protection, email and collaboration threat protection, cloud access security broker (CASB), extended detection and response (XDR), data governance and compliance, customer/case management platforms (CRM), enterprise resource planning/supply chain management (ERP), low-code application development and business intelligence, source code management and DevOps platforms, project and portfolio management, diagramming and visualization tools, enterprise technical product support services, professional/implementation services, and cloud infrastructure and platform services. For each capability area, respondents must provide detailed bills of materials with part numbers and pricing; Section 508 compliance details; vendor credibility and scale information; commercial structure and tiered pricing recommendations; lifecycle costs including exit/offboarding and implementation processes; and operational details including SLAs, AI capabilities, integration costs, and cost management tools. Responses are due by October 16, 2026, at 12:00 PM EST to kalil.oneal@va.gov and matthew.newell@va.gov, limited to 10 pages per capability area, and must include company identification information and CAGE number. The VA notes that any follow-on RFP/RFQ may be posted on SAM.gov, does not require existing FedRAMP certification for consideration, and targets Authorization to Operate (ATO) decisions within 60 calendar days of system intake completion.

View the file

Other files for this federal contract opportunity

Other files attached to DA10-VA Enterprise-level Product Solutions, newest first.
File Type Posted
36C10B27Q0025_1.docx DOCX document
Request for Information- Microsoft EA Product Alternatives.docx DOCX document
36C10B27Q0025.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

REQUEST FOR INFORMATION

VA Enterprise-level Product Solutions

Introduction:

This is a Request for Information (RFI) only issued for conducting market research. Accordingly, this RFI constitutes neither a Request for Quote (RFQ), Request for Proposal (RFP), nor a guarantee that one will be issued by the Government in the future; furthermore, it does not commit the Government to contract for any services described herein. The Department of Veterans Affairs (VA) is not, at this time, seeking proposals or quotes, and therefore, will not accept, review, or evaluate unsolicited proposals or quotes received in response hereto. This notice is not to be construed as a commitment on the part of the Government to award a contract, nor does the Government intend to pay for any information submitted because of this request. The Government does not reimburse respondents for any costs associated with submission of the information being requested or reimburse expenses incurred for responses to this RFI. The information provided may be used by VA in developing its acquisition strategy and Performance Work Statement (PWS) or Product Description (PD). Any information submitted by respondents to this RFI is strictly voluntary; however, any information received shall become the property of the Government and will not be returned to the respondent. Interested parties are responsible for adequately marking proprietary, restricted, or competition sensitive information contained in their response. This is a request for information and does not obligate the Government in any way, nor does it commit the Government to any specific course of action. Product information, brochures, part numbers, and/or other description information may be included with the submission.

Requirement:

The Department of Veterans Affairs (VA) is conducting market research into enterprise solutions capable of meeting its functional, security, and interoperability requirements across productivity and collaboration, security and compliance, customer/case management, low-code application development, source code management, reactive product and professional support services, and cloud infrastructure services, currently supporting an enterprise of over 540,000 users.

Our research is being conducted under a solution-agnostic process, through which requirements are evaluated against the marketplace to match the identified need with a solution that is cost-effective and demonstrates enterprise-grade reliability and uptime, independent of incumbent vendor or platform.

Interested vendors are invited to submit information regarding their products' capabilities, compatibility, and ability to meet these requirements at VA's scale.

VA seeks pricing and product information for any solution, regardless of vendor or platform, capable of meeting the requirements described in Table 1 below. This effort does not indicate a decision to move to any specific alternate technology but is intended to inform VA's understanding of available market solutions, costs, and implementation considerations.

VA desires identification of enterprise proven alternate products which meet the functional requirements described in Table 1 and that have been demonstrated to operate at a similar level of size, scope, and complexity to VA’s current environment.

Per VA policy (Memorandum V14895023, July 28, 2026), this RFI does not require respondents’ alternatives to hold existing FedRAMP certification to be considered. VA's security and authorization requirements are based on NIST SP 800-53 Revision 5, VA Directive 6500, and VA Handbook 6500.6 Appendix C, and any awarded solution must complete VA's Authorization to Operate (ATO) process prior to operating in VA's production environment. Any FedRAMP references elsewhere in this document describe VA's current environment only and are not intended as a qualification requirement for respondents. For reference, in the event a follow-on procurement were pursued, VA targets an ATO decision within 60 calendar days of a system meeting intake requirements, consistent with VA's accelerated authorization process; this timeline reflects a service level target only and does not guarantee a favorable authorization outcome Responses:

For this RFI, VA has identified key capability areas currently supported under its Microsoft Enterprise Agreement and provided current-state descriptions and functional requirements for each. Any reference to interoperability with the organization’s productivity suites references VA's current Microsoft environment or a to-be-selected alternative, and vendors should describe integration via open standards. Respondents may provide responses for anyone, multiple, or all key capability area(s). These capability areas, with their respective current state descriptions, are described below:

Table 1: Requirements Matrix

Key Capability Area
Current State (Reference Only)
Functional/Technical Requirements
Productivity & Collaboration
VA currently operates over 540,000 user subscriptions for its enterprise productivity and collaboration tool, spanning workstations, laptops, and tablets, plus 16 on-premise mail servers
• Productivity applications: Office productivity applications (word processing, spreadsheet, presentation, email client) licensed per user, as a coherent interoperating set.

• Multi-device use: Each licensed user shall be able to access and use the full set of core productivity applications (word processing, spreadsheet, presentation, email client) across their personal complement of desktop, laptop, tablet, and smartphone devices, a user can work their complement of devices at reasonable cost, with centralized, cloud-based license and device management. Vendors shall describe their licensing model for multi-device use, including any per-device install rights, per-session limits, or managed-device thresholds inherent to their platform, and how license entitlements are tracked across a user's devices.

• Government-authorized cloud environment: Solution shall operate in a segregated, US-only data residency environment with access restricted to screened US personnel, consistent with NIST SP 800-53 Rev 5 controls and VA Directive 6500, and capable of supporting VA's ATO process.

• Core collaboration services: Cloud-based email, document/file collaboration and storage, and team messaging/video conferencing, licensed per user.

• Mailbox capacity: Enterprise-grade mailbox size with auto-expanding archive; email access via web, desktop, and mobile clients.

• Cloud storage: Aggregate cloud storage per user (personal plus allocated shared/team storage, in whatever split the vendor's model supports), with ability to request increased quotas. Specific storage model capacity and individual versus shared allocations may vary.

• Built-in threat protection: Anti-phishing, malicious link and attachment protection integrated into or interoperable with the email/collaboration platform.

• Data protection: US-only data storage at rest with strong encryption in transit (e.g., TLS/IPsec) using FIPS-validated cipher suites.

• Accessibility: Published Accessibility Conformance Reports (ACRs/VPATs) addressing Section 508, WCAG, and EN 301 549.

• Interoperability: Describe integration with commonly used identity/access management and endpoint management solutions, including support for open standards (e.g., SAML, OIDC, SCIM).

• AI and analytics capabilities: Describe any embedded AI, predictive analytics, automation, or decision-support capabilities within the platform's workflows. Indicate whether each is included in the base license or is an additional/consumption-based cost, and how pricing scales with usage

Identity & Access Management
VA currently provides identity and access management as part of its 540,000+ user productivity environment.
• Core IAM: Single sign-on, multifactor authentication, conditional/risk-based access policies, and dynamic group management aligned to Zero Trust principles.

• Directory integration: Support for federation with on-premises directory services and other identity providers via open standards (SAML, OIDC, SCIM).

• Lifecycle management: Automated user provisioning/deprovisioning, access certification, and privileged access management.

• Government-authorized cloud environment: US-only data residency, screened US personnel, NIST SP 800-53 Rev 5 alignment, and support for VA's ATO process.

• Interoperability: Describe integration with commonly used productivity/collaboration platforms and endpoint management solutions, independent of vendor.

Unified Endpoint Management
VA currently provides unified endpoint management as part of its 540,000+ user productivity environment, across Windows, iOS, Android, and macOS devices.
• Device enrollment & compliance: Enrollment, compliance policy enforcement, configuration management, automated provisioning, and application deployment across desktop and mobile operating systems (Windows, iOS, Android, macOS, and Linux where applicable).

• Mixed-OS support: Ability to manage a heterogeneous device fleet independent of a single productivity suite or OS vendor.

• Reporting & compliance: Fleet-wide compliance reporting and integration with identity/conditional access policies.

• Interoperability: Describe integration with commonly used identity providers and endpoint operating systems , independent of vendor.

Endpoint Operating System Licensing
VA currently licenses an enterprise-level endpoint, graphical operating system spanning workstations, laptops, and tablets.
• Endpoint operating system for existing VA hardware: An enterprise-grade endpoint operating system capable of running on VA's existing installed base of workstations, laptops, and tablets, licensed independently of hardware. Vendors shall describe available licensing models (e.g., per-device perpetual, per-user subscription, or hybrid) and enterprise agreement structures suitable for a 540,000+ user environment.

• Hardware dependencies (if any): If the proposed operating system cannot run on VA's existing endpoint hardware and requires the purchase of new or specific devices, the vendor shall clearly state this and provide the associated device acquisition costs separately, so that total cost of ownership reflects any hardware refresh required by the proposed solution.

• If your offer does not have a general-purpose desktop operating system, describe how your broader solution set (in other lots) operates on and integrates with commonly deployed federal endpoint operating systems (Windows, macOS, ChromeOS, Linux), including device management/security integrations relevant to a mixed-OS environment.

Endpoint Detection and Response
VA currently provides endpoint detection and response as part of its 540,000+ user productivity environment
• Threat detection: Identifies malicious activity and compromises across endpoints

• Automated investigation and remediation: Investigates threats and executes automatic containment/remediation actions

• Vulnerability management: Asset inventory, risk-based prioritization, and secure configuration assessment

• Multi-platform coverage: Windows, macOS, Linux, Android, iOS

• Extended device support: Servers and IoT/OT devices

• IoT-specific security monitoring: Dedicated monitoring for IoT/OT device environments

Identity Threat Protection
VA currently provides identity threat protection as part of its 540,000+ user productivity environment
• Compromise detection: Detects compromised identities and unauthorized account access

• Lateral movement analysis: Tracks attacker progression and lateral movement through the network

• On-premises integration: Integrates with VA's on-premise directory services (e.g., Active Directory)

• Risk-based conditional access: Dynamic access policies based on real-time identity risk scoring

• Third-party governance: Controls and audits OAuth and third-party application access

Email and Collaboration Threat Protection
VA currently provides email and collaboration threat protection as part of its 540,000+ user productivity environment
• Anti-phishing protection: Detects and blocks phishing attempts

• Malicious link/attachment protection: Real-time scanning and blocking of malicious content

• Business Email Compromise (BEC) response: Automated detection and response to BEC attacks

• Collaboration platform protection: Extends protection to Teams, SharePoint, and file-sharing platforms

• Automated response: Quarantine and remediation actions executed automatically

Cloud Access Security Broker (CASB)
VA currently provides cloud access security as part of its 540,000+ user productivity environment
• SaaS application discovery: Identifies sanctioned and unsanctioned cloud applications in use

• Posture management: Assesses security configuration and compliance posture of cloud applications

• Threat detection and response: Monitors and responds to suspicious activity within cloud applications

• Exposure management: Identifies and reports on data exposure and security gaps

• Usage control: Enforces security policies on cloud application access and user behavior

Cross-Cutting Capabilities
Extended Detection and Response (XDR)
• Cross-domain correlation: Aggregates security signals from endpoints, identities, email, SaaS applications, and cloud workloads

• Automated response: Executes coordinated threat response actions across all capability areas

• Threat hunting: Advanced investigation and proactive threat hunting across domains

• Unified visibility: Signals from these domains are correlated, whether natively or via integration with third-party tools via open APIs/SIEM.

Data Governance & Compliance
VA provides data governance and compliance functionality as part of its 540,000+ user environment.
• Data security posture management: Visibility into data risk, oversharing, and sensitive information exposure across the environment.

• Data loss prevention (DLP): Policy-based prevention of sensitive data leakage across email, file storage, collaboration platforms, and endpoint devices.

• Information/data classification and protection: Automated or manual classification, labeling, and encryption of sensitive data across applications and cloud services.

• Insider risk management: Detection and investigation of data theft, unauthorized data movement, or insider misuse.

• eDiscovery: Advanced tools for legal review, internal investigations, litigation holds, and analytics.

• Audit logging: Extended-retention audit logs (up to 10 years) suitable for forensic investigation and regulatory requirements.

• Data lifecycle management: Retention, deletion, archiving, and defensible disposition of records.

• Compliance risk assessment: Regulatory control mapping, risk scoring, and compliance reporting tools.

• Communications compliance monitoring: Scanning of internal communications for harassment, threats, sensitive data sharing, and policy violations.

Customer / Case Management Platform (CRM)
VA owns and operates client licenses supporting case management, customer service, and sales functions.
• Unified CRM capability: A single, integrated customer relationship and case/service management platform delivered by one vendor, spanning case/service management, customer service, and sales functions. VA seeks one coherent CRM ecosystem for this area and is not seeking to assemble it from separately sourced point products.

• Modular deployment: Ability to purchase and deploy discrete functional modules (e.g., case/service management, customer service, sales) individually or together, based on organizational need, within the single vendor's platform.

• Cloud-based architecture: Secure, high-availability, scalable SaaS delivery with continuous updates.

• Embedded AI/analytics: Predictive insights, automation, and decision-support capability integrated into case/customer workflows. Vendors shall describe whether these are included in the base license or priced separately.

• Low-code/no-code extensibility: Ability to build custom workflows and applications without extensive custom coding, and to integrate with the organization's broader automation/workflow platform.

• Interoperability: Describe integration with the organization's productivity suite, identity/access management, and — where relevant — with a separately sourced ERP/supply chain platform (see separate capability area).

• AI and analytics capabilities: Describe any embedded AI, predictive analytics, automation, or decision-support capabilities within the platform's workflows. Indicate whether each is included in the base license or is an additional/consumption-based cost, and how pricing scales with usage.

Capability Area: Enterprise Resource Planning / Supply Chain Management (ERP)
VA operates supply chain management functions as part of its current enterprise environment.
• Core ERP/supply chain capability: Enterprise resource planning functionality supporting supply chain management, including inventory, procurement, and related logistics/operations functions at enterprise scale.

• Modular deployment: Ability to acquire and deploy discrete ERP/supply chain modules individually or together, based on organizational need.

• Cloud-based architecture: Secure, high-availability, scalable SaaS delivery with continuous updates.

• Embedded AI/analytics: Predictive insights, automation, and decision support integrated into supply chain and operational workflows. Vendors shall describe whether these are included in the base license or priced separately.

• Low-code/no-code extensibility: Ability to configure and extend workflows without extensive custom coding.

• Interoperability: Describe integration with the organization's productivity suite, identity/access management, and — where relevant — with a separately sourced CRM/case management platform (see separate capability area). Open standards and documented APIs for cross-platform data exchange shall be described.

• AI and analytics capabilities: Describe any embedded AI, predictive analytics, automation, or decision-support capabilities within the platform's workflows. Indicate whether each is included in the base license or is an additional/consumption-based cost, and how pricing scales with usage.

Low-Code Application Development, Workflow Automation & Business Intelligence Platform
VA owns and operates over 22,000 per-user and 17,000 per-app low-code application licenses, plus premium Business intelligence subscriptions supporting over 3,000 workspaces.
• Cloud & Compliance: US-based government-authorized cloud delivery; US-only data residency; screened US personnel; demonstrated ability to meet NIST SP 800-53 Rev 5 control requirements and support VA's Authorization to Operate (ATO) process consistent with VA Directive 6500 and VA Handbook 6500.6 Appendix C.

• Security & Governance: Enterprise identity integration, role-based access control (RBAC), data loss prevention (DLP) policies, audit logging, and application lifecycle management (ALM) supporting a governed Center of Excellence (CoE) operating model.

• Accessibility: Section 508 conformance, with a documented roadmap for any gaps.

• Interoperability: Native integration with the organization's productivity suite (file storage, messaging, spreadsheet/document tools) and approved data connectors (e.g., SQL databases, data warehouses, CRM/ERP platforms).

• Low-code application development: Support for both visual/canvas-based and data-model-driven application development; accessible via browser, mobile, and messaging-platform embedding; support for standard and premium data connectors; development/test/production lifecycle management; flexible licensing models (per-user, per-app, or consumption-based) with documented API and storage limits.

• Workflow and process automation: Cloud-based workflow automation and robotic process automation (RPA), including both attended and unattended automation; on-premises gateway connectivity; documented throughput limits; audit trails.

• Business intelligence and reporting: Interactive dashboards, self-service analytics, data modeling, scheduled data refresh, and enterprise-scale distribution; premium/scalable capacity tiers with workspace governance, row-level security, and support for large data models; government-cloud tenant distribution.

• Low-code web portal capability: Support for both authenticated and anonymous public-facing sites, government-cloud data residency, and Section 508-aligned site management tools.

• Shared enterprise data platform: A common data platform with documented database/file/log storage capacity, usage/chargeback rules, auditing, row-level security, and data integration pipelines.

• Scale & References: Evidence of successful deployment at VA-like scale (500,000+ users, thousands of solutions) and pricing structures suitable for large-scale, multi-year enterprise procurement.

Source Code Management & DevOps Platform
VA currently owns over 13,000 enterprise source-code-hosting subscriptions, including over 5,700 advanced security add-on subscriptions.
• Version control hosting: Cloud-based hosting of Git (or equivalent distributed version control) repositories with built-in collaboration tools for code review, issue discussion, and project management.

• Branching and code review workflows: Support for independent parallel development branches and structured pull/merge-request-based code review prior to merging changes.

• Integrated issue tracking and project management: Native tools for tracking tasks, bugs, and features alongside source code.

CI/CD automation: Continuous integration/continuous deployment automation and DevOps workflow tooling — either native to the platform or through tightly integrated, first-class pipeline capability — including autoscaling/scalable build runners and configurable security controls.

• AI-assisted development: Integrated AI coding assistance available directly within the platform and across common IDEs.

• Enterprise identity and access management: Single sign-on, automated user provisioning (e.g., SCIM), and role-based access control for centralized governance at scale.

• Advanced security scanning: Code scanning and secret-scanning capability, available as a licensed add-on or bundled.

• IDE and toolchain integration: Deep integration with commonly used development environments (e.g., Visual Studio Code, IntelliJ, Eclipse), supporting both web-based and desktop-based development.

• Deployment model: Vendors shall describe their available deployment model(s) - fully managed cloud service, self-managed/on-premises, or both — and how each option supports organizational data control, residency, and compliance needs. VA does not require any single deployment model; describe what you offer

• Audit streaming and compliance reporting: Enterprise identity management, audit log streaming, and compliance reporting capability for governance visibility.

• Extensibility: Marketplace of third-party integrations/apps and public APIs/webhooks to connect with deployment platforms, ticketing systems, and other enterprise tools.

• AI-assisted development: Describe any integrated AI coding-assistance capabilities available within the platform and across common IDEs, including whether they are included in the base license or licensed separately, and how pricing scales per user or by usage.

Project & Portfolio Management Platform
VA owns and operates over 2,000 per-user project and portfolio management licenses, and a small number of on-premises server-based license.
• Core project portfolio management: Centralized web-based interface for managing projects, resources, schedules, and portfolios, with an optional desktop/authoring client for schedule creation and publishing.

• Advanced task scheduling: Task dependency management (including lead/lag time), automated critical-path calculation, and historical tracking of schedule changes.

• Resource, cost, and portfolio management: Enterprise resource pooling with capacity planning, cost tracking, budgeting, timesheet approval workflows, and portfolio-level rollup reporting.

• Automated scheduling engine: Automated schedule calculation and resource management, deployable as a standalone application or connected to a hosted/cloud service.

• Multiple project views: Support for grid, board, timeline/Gantt, and chart-based visualizations, including a dedicated resource-assignment view.

• Governance and workflow: Configurable stage-gate/approval workflows, demand intake processes, custom fields/views, and reporting access to underlying project data.

• Integration: Ability to operate standalone or integrate with the organization's document management/collaboration platform and broader productivity suite (email, chat, video, co-authoring) for unified task/project tracking.

• Licensing transparency: Full disclosure of licensing model, including server-based and any user/client/authoring license types; vendors shall not assume any existing licenses are held and shall name, quantify, and price all required licenses.

Diagramming & Visualization Tool
VA owns and operates over 6,000 per-user diagramming and visualization licenses.
• Core functionality: Diagramming and vector graphics application supporting flowcharts, organizational charts, floor plans, and technical drawings.

• Automatic updates and cloud storage: Automatic delivery of feature/security updates for the subscription term, plus minimum 2 GB per-user cloud storage for file retention and sharing.

• Data export and automation integration: Ability to export diagrams to common document/presentation formats, trigger workflow/ Robotic Process Automation (RPA) automation, and generate diagrams from external data sources (e.g., spreadsheets).

• Real-time co-authoring: Simultaneous multi-user editing of the same diagram file, with integration to common productivity-suite data sources.

• Government-authorized cloud environment: Cloud service offering authorized for use by US Federal, State, Local, and Tribal government agencies and their contractors.

• Template/shape library: Extensive built-in and third-party-extensible library of templates, shapes, and stencils, with support for hyperlinking within diagram objects.

Enterprise Technical Product Support Services
VA currently provides product support services across its 540,000+ user enterprise environment
• Enterprise-wide reactive support: 24x7 problem resolution across the full deployed technology spectrum (productivity, security, identity, cloud infrastructure, data platform, developer tools) supporting a 540,000+ user enterprise, including root cause analyses.

• Severity-based response commitments: Defined initial response and escalation timelines tied to incident severity, with documented service level agreements.

• Proactive services: Advisory support, health assessments, architecture reviews, and knowledge transfer to reduce recurring incidents.

• Dedicated technical account management: Named point(s) of contact coordinating support delivery, escalation, and reporting at enterprise scale.

• Screened/cleared US-based personnel: Support delivered by appropriately screened personnel consistent with government cloud and data-handling requirements.

• Escalation to product engineering: Ability to escalate complex or product-defect issues directly to the vendor's engineering organization.

Professional/Implementation Services
VA currently utilizes professional support services for planning, implementation, and optimization of its deployed technology environment.
• Planning and implementation support: Architectural design, testing, configuration, operational support, knowledge transfer, and new-product implementation services.

• Location: Services shall be provided within the Continental United States (CONUS); remote delivery is acceptable, but in-person/on-site work may be required as determined by VA.

• End-to-end managed support: Ability to provide complete managed support across the full deployed technology spectrum, focused on VA business priorities and optimal performance of VA's technology investments.

• Operational continuity: Demonstrated ability to support day-to-day problem resolution, performance enhancement, disaster recovery, and configuration management, with a focus on knowledge transfer and continuity of service.

Cloud Infrastructure & Platform Services
VA uses cloud services (as defined in NIST SP 800-145) across both public and government community cloud (high-security) environments. There are currently over 100 cloud services in use and authorized under applicable federal cloud authorization processes in VA's enterprise cloud environment.
• NIST SP 800-145-compliant service models: Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and serverless computing offerings.

• Security & authorization: Ability to meet NIST SP 800-53 Rev 5 control requirements and support VA's Authorization to Operate (ATO) process.

• Enterprise-scale landing zones: Pre-configured, governed environments for large-scale workload deployment.

• Automated Data and security operations capability: Native or integrated data platform services, and security information and event management (SIEM)/extended detection and response (XDR) capability.

• Data and AI/ML services: Describe available native or integrated data platform and AI/ML services. Indicate licensing/consumption model and how costs scale with usage.

• Zero Trust alignment: Architecture and controls consistent with Zero Trust security principles.

• Resilience: Multi-region redundancy and disaster recovery capability.

• Cost management: Tooling to track, forecast, and manage cloud consumption costs.

• Interoperability: Integration capability with the organization's productivity suite, low-code platform, and CRM/ERP platform capabilities described above.

• Scale: Demonstrated ability to support 100+ concurrent cloud services at VA-like enterprise scale, with detailed SLAs, cost-tracking tools, and migration strategy documentation across all technical domains.

Any product or technology identified in response to this RFI must meet all the functional/technical requirements identified in Table 1 above for the applicable capability area. VA's current environment for these capability areas is built on Microsoft’s ecosystem, as noted in the table, and this context is provided for market research purposes as individual alternative solutions may require interoperability with remaining ecosystem products.

Please submit a response to each question below, using the Requirements Matrix identified in Table 1.

Questions per Key Technical Domain:

Technical/Functional:

1. Provide a detailed Bill of Materials (BOM) that includes part numbers, quantities and a description of all products required to fulfill the functional/technical requirements for the key capability area in the form of a quote that includes pricing per part number. In addition, to support VA's should-cost analysis, provide a high-level breakdown of the cost drivers underlying your pricing (e.g., infrastructure, labor/support, licensing structure), to the extent releasable.

2. Provide details on each products’ compliance with Section 508 of the Rehabilitation Act of 1973. If less than 100%, estimate date when product will be fully compliant.

3. Vendors shall describe whether CI/CD is delivered as a built-in capability or via integrated components and shall identify any separately licensed products required to deliver the described automation.

Vendor Credibility & Scale:

4. Is your company currently providing similar products or services to any government agency or other non-government customers? If you are unable or unwilling to share your customers' identity, please address whether your company offers the same or similar services, commercially (outside the federal government).Where possible, identify the largest deployment (by user count) of this solution currently in production, and whether that deployment is comparable in scale, complexity, or regulatory environment to VA's.

Commercial Structure:

5. Provide recommendations on available tiered pricing discounts, if available, for the products proposed, based on the estimated quantities identified for each key capability area. Please identify any alternative licensing models available for your solution (e.g., suites of products, user-based licensing, consumption-based, pay as you go). Please also indicate how your proposed pricing compares to other federal or large enterprise (10,000+ seat) engagements, where disclosure is possible

Lifecycle Cost:

6. Describe your standard exit/offboarding process, including data extraction format, timeline, and any associated costs, should VA elect to transition away from your solution at contract end or termination?

7. Describe your standard onboarding and implementation process for a deployment at VA's scale (540,000+ users), including typical phases, timeline from contract award to full production availability, required VA resource/staffing commitments, and any associated implementation or professional services costs not already reflected in the BOM/quote provided in response to Question 1.

8. Describe the change management and end-user training resources, materials, or services you provide (or make available through partners) to support adoption at enterprise scale, including whether these are included in the base license/quote or represent an additional cost, and any data on adoption timelines or user proficiency outcomes from comparable deployments.

Ongoing Operations:

9. What contractual or service level agreements (SLAs) do you offer for service outage or degradation processing/equitable price adjustments, when SaaS elements become unavailable or degraded beyond agreed upon levels. VA seeks to understand how “user minutes” of service are calculated along the published service SLAs and the procedures, with timelines associated with adjustments. Please also provide your platform's actual uptime performance (e.g., trailing 12-month availability) against your published SLA target(s).

10. Provide details on what Artificial Intelligence (AI) capabilities are available for each alternate product, as well as how they are licensed/priced (e.g., subscription costs, additional consumption costs, etc), including specific SKU and pricing information, if available. Indicate whether these capabilities are included in the base license or represent an additional/variable cost as usage scales.

11. Provide details on any associated costs or additional products (e.g., third-party) which may be required to operate the alternate product(s) with VA's existing enterprise environment (including Microsoft's product suite). Separately, estimate the one-time costs associated with migrating from VA's current solution to your proposed alternative (e.g., data migration, integration rework, parallel-run/transition period).

12. Provide information on available tools to effectively track, manage, and understand cloud costs or other consumption-based costs across the identified products including any capability to forecast cost impact prior to scaling usage.

Close:

13. Provide feedback on the functional/technical requirements identified. Specifically, any additional that should be included or any that may be too restrictive. Please also identify any requirements above that may create long-term vendor lock-in or limit VA's ability to migrate away from your solution in the future.

Please submit a response to each question below regarding your company. Responses should be no longer than 10 pages per capabilities areas.

Include the following identification information:

1) Name of Company

2) Address

3) Point of Contact

4) Phone Number

5) Fax Number

6) Email address

7) CAGE Number

Responses are due no later than Friday October 16, 2026, at 12 PM EST via email to both kalil.oneal@va.gov and matthew.newell@va.gov. Mark your response as “Proprietary Information” if the information is considered business sensitive.

Post RFI Phase Based on market research results, an RFP/RFQ may be made available on Contracting Opportunities found at SAM.gov. It is the responsibility of interested parties to regularly monitor the SAM.gov for updates. The government will not provide hard copies of the solicitation once issued. Interested parties are responsible for monitoring the website and downloading the solicitation, its attachments, and any amendments from the internet site identified above when/if issued. All information regarding the procurement is provided herein, and no additional information shall be provided at this time.

File details come from the government source that posted it. Updated .