4-MIDA RFP for Managed IT Services CMMC Level 2 Compliance (1).pdf

PDF 2 MB Posted

Attached to
NS26-85 Military Installation Development Authority - Managed IT Services & CMMC Level 2 Compliance State and local contract opportunity
Solicitation number
NS26-85
Issued by
Utah

About this file

This is a Request for Proposals (RFP) issued by the Military Installation Development Authority (MIDA), an independent Utah state government entity, seeking qualified managed service providers to deliver comprehensive IT support, cybersecurity management, and technical advisory services. The solicitation requires offerors to provide managed IT services including help desk support, device management, cloud-based software administration, endpoint security and response, backup and disaster recovery, and incident response capabilities, with the primary focus on achieving and maintaining Cybersecurity Maturity Model Certification (CMMC) Level 2 compliance. MIDA operates with approximately 20 remote-based users across Utah utilizing exclusively cloud-based software with approximately 15 company-owned laptops and 15 multifunction printers; currently does not process classified information but stores sensitive data including employee personally identifiable information (PII), vendor banking information, and certain sales tax records. A mandatory pre-proposal meeting is scheduled for February 19, 2026 at 10:00 am Mountain Standard Time (MST), with a Non-Disclosure Acknowledgement due by February 17, 2026 at 5:00 pm (MST), questions due by February 26, 2026 at 5:00 pm (MST), and proposals due electronically via the Utah Public Procurement Place (U3P) by March 5, 2026 at 5:00 pm (MST). The anticipated contract term is three (3) years, with interviews estimated for March 13, 2026.

The cost proposal must provide the estimated total cost across the three-year contract term calculated as one-time project costs plus monthly operational costs multiplied by 36 months, with all pricing fully loaded to include labor, travel, overhead, and administrative fees. One-time project costs must be itemized separately for transition and implementation (MDM deployment, current environment documentation, and .gov domain migration) and CMMC Level 2 compliance (policy documentation, technical remediation, and support for one C3PAO assessment). Monthly costs must be provided as either a fixed flat rate or per-user/per-device fee and exclude one-time implementation costs; offerors should assume 20 users and devices, 15 help desk tickets monthly, and four onboarding/offboarding events annually. Minimum requirements for proposal qualification include certification that support operations comply with NIST SP 800-171 standards and demonstration of minimum five (5) years of managed IT services experience. Evaluation criteria weighted at 30 percent for plan and approach, 20 percent for experience and references, 10 percent for key personnel and qualifications, 10 percent for interviews, and 30 percent for cost; proposals must achieve a minimum technical score of 75 percent to advance to the interview phase. Joint proposals with one subcontractor are permitted, provided both the lead offeror and partner meet secure support operations requirements and at least one entity meets the five-year managed IT services experience requirement. MIDA has set a target objective of achieving CMMC Level 2 compliance readiness within four (4) months of contract execution, though alternative timelines may be proposed with justification.

View the file

Other files for this state and local contract opportunity

Other files attached to NS26-85 Military Installation Development Authority - Managed IT Services & CMMC Level 2 Compliance, newest first.
File Type Posted
3-Appendix C - Standard Terms and Conditions for Goods and Services.pdf PDF
2-Appendix B - Claim of Business Confidentiality.pdf PDF
1-Appendix A - Non-Disclosure Acknowledgement.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Military Installation Development Authority (MIDA)

Request for Proposals for Managed Information Technology Services & CMMC Level 2 Compliance

RFP Schedule

Non-Disclosure Acknowledgement Due February 17, 2026 at 5:00 pm (MST)

Mandatory Pre-Proposal Meeting February 19, 2026 at 10:00 am (MST)

Questions Due February 26, 2026 at 5:00 pm (MST)

Proposal Submission Deadline March 5, 2026 at 5:00 pm (MST)

Interviews with Evaluation Committee (Estimated)

March 13, 2026

MIDA RFP for Managed Information Technology Services & CMMC Level 2 Compliance

Table of Contents Section 1: Introduction

1.1. Purpose of RFP

1.2. Joint Proposals Permitted

1.3. Introduction to MIDA

1.4. MIDA’s Current IT System

Section 2: Scope of Work

2.1. Overview of Services Provided

2.2. CMMC Level 2 Compliance

2.2.1. Subject Matter Expert and Compliance Architect

2.2.2. Gap Analysis & Roadmap

2.2.3. Documentation

2.2.4. CMMC Assessment Liaison

2.2.5. Target Timeline for CMMC Level 2 Compliance Readiness

2.3. General Managed IT Services

2.3.1. General IT Management and Help Desk

2.3.2. Device Management

2.3.3. Cloud-Based Software Administration

2.3.4. Endpoint Security & Response

2.3.5. Backup and Recovery

2.3.6. Incident Response & Utah Government Data Privacy Act Compliance

2.3.7. Website Security and .gov Domain Transition

2.3.8. Target Timeline for Managed IT Services

2.4. Exceptions to this Scope of Work

Section 3: Minimum Requirements

3.1. Minimum Requirements

3.1.1. Secure Support Operations

3.1.2. Managed IT Services Experience

Section 4: Proposal Requirements

4.1. Technical Proposal Requirements

4.1.1. Minimum Requirements

4.1.2. Plan and Approach

4.1.3. Experience and References

4.1.4. Key Personnel and Qualifications

4.2. Cost Proposal Requirements

4.2.1. One-Time Project Costs

4.2.2. Monthly Costs

4.2.3. Firm Pricing and Negotiation

Section 5: Solicitation Period and Submission Instructions

5.1. Mandatory Pre-Proposal Meeting

5.2. Non-Disclosure Acknowledgement Required

5.3. Question and Answer Period

5.4. Addenda

5.5. Proposal Submission Instructions

5.6. Interviews

5.6.1. Schedule and Logistics

5.6.2. Rules of Conduct

Section 6: Evaluation, Scoring, and Award

6.1. Minimum Requirements

6.2. Evaluation Criteria

6.3. Technical Proposal Scoring

6.4. Interview Scoring

6.5. Cost Proposal Scoring

6.6. Award and Notice

Section 7: Other Information

7.1. Cost of Proposals

7.2. Protest Procedures

7.3. Government Records Access and Management Act (GRAMA)

7.4. Reservation of Rights

7.5. Examination of Proposal Documents and Federal Requirements

7.6. Written Agreement Required and Proposed Alterations

Appendix A: Non-Disclosure Acknowledgement Appendix B: Claim of Business Confidentiality Appendix C: Standard Terms and Conditions for Goods and Services

Section 1: Introduction

1.1. Purpose of RFP

The Military Installation Development Authority (“MIDA”) is seeking proposals from qualified managed service providers (each, an “Offeror”) to deliver comprehensive IT support, cybersecurity management, and technical advisory services. The Offeror will be responsible for maintaining secure, reliable, and compliant information systems that support MIDA’s workforce and mission.

The scope of services includes help desk support, cybersecurity monitoring and incident response, system maintenance, and backup and disaster recovery. Additionally, the selected Offeror will provide ongoing advisory support to ensure MIDA continually meets evolving cybersecurity and privacy standards.

The Offeror must possess demonstrated experience supporting organizations – preferably government entities similar in size as MIDA – in cloud-native environments. Crucially, the Offeror must have the capability to implement and maintain systems that are compliant with Level 2 of the Cybersecurity Maturity Model Certification (“CMMC Level 2”).

This request for proposals (“RFP”) seeks to identify the Offeror that presents the best overall value to MIDA. The anticipated length of the resulting contract will be three (3) years.

1.2. Joint Proposals Permitted

MIDA permits Offerors to partner with one subcontractor to meet the Scope of Work, which encompasses both standard managed IT services and CMMC Level 2 compliance. However, such proposals must comply with the requirements for joint proposals outlined in Section 3, Minimum Requirements, and Section 4, Proposal Requirements. Regardless of the partnership structure, the proposal must identify a single point of contact as the “Lead Offeror” (referred to throughout this RFP as the “Offeror”) and identify any subcontracting firm as the “Partner.”

1.3. Introduction to MIDA

MIDA is an independent state government entity established by the Utah Legislature in 2007 that is responsible for facilitating the development of economic development projects that support military installations and missions in Utah. MIDA works in partnership with the U.S. military, state and local governments, and private developers to deliver public infrastructure, services, and amenities that serve both military personnel and the general public.

MIDA is a small organization and exclusively uses cloud-based software for its operations. Its employees and contractors work remotely and are based in Utah. As a result, MIDA seeks to implement IT service and security that is practical and appropriate for a small, remote workforce. MIDA does not wish to unnecessarily increase system complexity or introduce solutions that exceed its operational needs.

Instead, MIDA seeks a partner who can guide the organization to compliance using efficient approaches that leverage existing tools and software whenever feasible.

1.4. MIDA’s Current IT System

MIDA exclusively uses off-the-shelf cloud software for its operations. It does not own or operate physical servers, on-premise data centers, or a central office network. The following information is provided to assist Offerors in preparing their proposals:

1. User Count: Approximately 20 total users.

2. Workstations: Approximately 15 MIDA-owned laptops and 15 MIDA-owned multifunction (or all-in-one) printers . MIDA issues Microsoft, Lenovo (Microsoft OS), and Apple laptops. Almost all Microsoft workstations run Windows 11. MIDA will provide a current, comprehensive list of MIDA-owned hardware to the selected Offeror.

3. Hardware lifecycle: Laptops are generally replaced every 4-5 years. Printers and other hardware (e.g., keyboards, monitors) are replaced on an as-needed basis.

4. Mobile devices: MIDA does not issue cell phones or tablets for its users.

5. Website: MIDA’s website is managed and hosted by a contracted marketing firm.

6. Controlled Unclassified Information: MIDA currently does not store documents that are federally designated as Confidential, Secret, Top Secret, or subject to International Traffic in Arms Regulations (“ITAR”). MIDA estimates that only three (3) users need access to controlled unclassified information (“CUI”) through its IT systems.

7. Sensitive Data: MIDA stores and collects the following Personally Identifiable Information (“PII”) or private records:

● Names and basic contact details (e.g., email address, address) for digital newsletter distribution and property management purposes. (MIDA contracts with a third party for property management; it does not process or store rental agreements or renters’ financial information);

● Banking information of vendors and contractors for routine Automated Clearing House (“ACH”) processing;

● Documents that contain Social Security numbers, dates of birth, document numbers (e.g., passport or driver license number) of employees for the purposes of payroll processing, benefit certification, and employment eligibility verification; and

● Certain sales tax records of businesses.

Unless otherwise noted above, MIDA does not store or collect the following data:

● PII from general members of the public;

● Personal Health Information (“PHI”);

● Credit card information;

● Surveillance footage; or

● Biometric data.

MIDA will provide additional information about its IT infrastructure, security protocols, and the data it stores and collects during a virtual, mandatory pre-proposal meeting held on February 19, 2026 at 10:00 am Mountain Standard Time (“MST”). Refer to Section 5.1. for more information about registering and attending this meeting.

Section 2: Scope of Work

2.1. Overview of Services Provided

The Offeror shall serve as MIDA’s managed service provider (“MSP”) to support MIDA’s remote workforce and operations. The primary objective is to maintain a secure, reliable IT system that maintains compliance with CMMC Level 2 requirements while being flexible enough to support daily business functions.

MIDA anticipates a primarily remote service delivery model; however, the Offeror must coordinate directly with MIDA operations staff for any tasks requiring physical intervention (e.g., hardware deployment, on-site troubleshooting). The Offeror is expected to provide clear instructions and guidance to MIDA staff when remote resolution is not possible. Under critical circumstances, such as a substantial security breach, deploying personnel may be required.

Offerors should propose solutions that are proportionate to MIDA’s small size and lean operational model, avoiding unnecessary network or infrastructure expansion unless it is absolutely required to meet compliance. Proposals that offer scope-limiting solutions, such as a CUI enclave, to reduce the compliance burden are highly desirable.

2.2. CMMC Level 2 Compliance

2.2.1. Subject Matter Expert and Compliance Architect

The Offeror shall act as the subject matter expert and architect for CMMC Level 2 compliance.

While this Scope of Work outlines MIDA’s general needs, MIDA relies on the Offeror’s expertise to prescribe the specific technical configurations, policies, hardware, and software required to achieve and maintain compliance.

Unless otherwise specified in Section 2.4., Exceptions to this Scope of Work, the Offeror must provide a complete turnkey solution for CMMC Level 2 compliance. MIDA will not define the technical roadmap.

It is the sole responsibility of the Offeror to interpret and understand CMMC Level 2 requirements and define the technical scope required to achieve them.

2.2.2. Gap Analysis & Roadmap

Upon contract award, the Offeror must conduct a comprehensive gap analysis against CMMC Level 2 requirements, which includes, but may not be limited to:

1. Provide a detailed roadmap estimating the time and resources required to close identified gaps.

2. Collaborate with MIDA to propose specific remediation steps for any non-compliant assets or workflows.

3. Create a responsibility matrix.

2.2.3. Documentation

The Offeror is responsible for developing and maintaining the documentation required for CMMC Level 2 certification, which includes, but may not be limited to:

1. Creating and updating the System Security Plan (“SSP”).

2. Creating the Plan of Action and Milestones (“POA&M”) and tracking and remediating known vulnerabilities.

3. Drafting administrative policies and standard operating procedures, in consultation with MIDA, that align with federal requirements.

2.2.4. CMMC Assessment Liaison

The Offeror shall serve as the primary point of contact for any Certified Third-Party Assessor Organization (“C3PAO”) engaged by MIDA for a CMMC Level 2 assessment.

2.2.5. Target Timeline for CMMC Level 2 Compliance Readiness

MIDA has established a target objective to achieve CMMC Level 2 compliance and a Level 2 self-attestation in the Procurement Integrated Enterprise Environment (“PIEE”) within four (4) months of the contract effective date. MIDA believes this timeline is feasible given its small organizational size, highly motivated operations staff, cloud-native environment, and desire for scope-limiting solutions, such as a CUI enclave.

If the Offeror determines that a four (4) month timeline is infeasible, it may propose an alternative timeline. However, the Offeror must provide a clear justification for the extended duration, detailing specific technical or administrative constraints.

2.3. General Managed IT Services

This section encompasses the day-to-day operational support, maintenance, and incident response required to support MIDA’s operations and staff. While these services focus on general operations, they must be aligned with MIDA’s broader security goals.

2.3.1. General IT Management and Help Desk

1. Serve as MIDA’s primary IT service provider and offer help desk and technical support. Although historical volume is low (average of five (5) inquiries per month), MIDA would require a high-availability support model.

a. Provide help desk and technical support during U.S. Mountain Time business hours

(Monday - Friday, 9:00 am - 5:00 pm) for routine requests.

b. Provide 24x7x365 availability for critical incidences, such as security breaches.

2.3.2. Device Management

1. Implement Mobile Device Management (“MDM”) capabilities to MIDA-owned devices to configure the devices, enforce security policies, and deploy software updates and patches.

2. Restrict local administrator privileges on MIDA-owned devices. The Offeror shall assume administrative control, ensuring that end-user accounts under “Least Privilege” access, while providing a fast process for legitimate elevation requests.

3. Maintain the ability to remotely “wipe” MIDA-owned devices that are reassigned, lost, or compromised.

4. The Offeror shall act as the primary procurement agent for all MIDA IT hardware. This includes hardware specification, order fulfillment, initial setup, and direct-to-user shipping.

2.3.3. Cloud-Based Software Administration

1. Administer licenses, users, permissions, security settings, and other pertinent settings for cloud-based software (e.g., Google Workspace, Microsoft Office Applications, Dropbox).

2. Monitor cloud software for unusual sign-ins, privilege escalation requests, and unauthorized applications. Conduct and report quarterly reviews on security settings.

3. Assist MIDA in onboarding new staff members and offboarding departing staff members. Ensure the immediate removal of access and the preservation of data for departing staff members.

MIDA estimates three (3) onboarding or offboarding events per year.

2.3.4. Endpoint Security & Response

1. Maintain and monitor Endpoint Detection and Response (“EDR”) solutions on all MIDA-owned hardware assets. The Offeror may propose and implement new EDR solutions if current tools are insufficient for CMMC Level 2 compliance.

2. Provide 24x7x365 monitoring for malicious activity and quarantine threats immediately.

2.3.5. Backup and Recovery

1. Implement and manage a backup and disaster recovery solution for all cloud-based file repositories (e.g., Dropbox, Google Drive) and email accounts (Gmail). The solution must ensure full recoverability in the event of ransomware, malware, data corruption, or accidental deletion.

2. Perform quarterly tests on the recoverability of emails, files, and other data to validate backup and recovery ability and report the results to MIDA.

3. Assist MIDA with developing an incident response and business continuity plan tailored to MIDA’s cloud-based environment and remote workforce. This may include, but is not limited to, procedures to restore service, communications during incidents, and failover options.

2.3.6. Incident Response & Utah Government Data Privacy Act Compliance

1. Immediately notify MIDA of any security breaches and lead the technical response to the incident, including containment, eradication of threats, and recovery of affected systems.

a. In extreme circumstances where remote remediation is ineffective or insufficient (e.g., total loss of remote access), the Offeror must be capable of deploying personnel to MIDA’s central location in Kaysville, Utah within 48 hours to assist with recovery.

2. Assist MIDA in complying with the Utah Governmental Data Privacy Act (“GDPA”) by providing technical support and reporting in the event of a security incident. This includes, but is not limited to:

a. Immediately notifying MIDA upon discovery of a breach. If a data breach affects 500 or more individuals, the Offeror shall assist MIDA in notifying the Utah Cyber Center and the Attorney General’s Office within the statutory five (5) day window.

b. Creating and submitting a detailed internal incident report documenting the nature and scope of the breach.

c. Assisting MIDA with the technical identification of affected individuals to facilitate required notifications under the GDPA.

d. Providing consultation and data regarding MIDA’s technical security posture to support the completion of MIDA’s annual privacy report.

2.3.7. Website Security and .gov Domain Transition

1. Assist MIDA and its contracted marketing firm to implement or maintain security requirements for MIDA’s website, midaut.org.

2. Lead the technical migration of MIDA’s domain of .org to .gov. This may include, but is not limited to:

a. Managing the complex transition of all email addresses, DNS records, and cloud service identities (e.g., Microsoft 365 / Google Workspace usernames) to the new domain.

b. Updating all single sign-on integrations and third-party software configurations to reflect the domain change, ensuring zero downtime for operations.

c. Implementing permanent redirects to ensure traffic and emails sent to the old .org domain are seamlessly routed to the new .gov addresses.

2.3.8. Target Timeline for Managed IT Services

To ensure a smooth onboarding process, MIDA has established the following target timelines for the assumption of duties and implementation of tools outlined in Section 2.3., General Managed IT Services:

1. The Offeror shall provide help desk support immediately upon contract execution.

2. The Offeror shall assume management of and/or implement all solutions regarding

MDM, EDR, backup and recovery, cloud license administration, and website security within four (4) months of the contract effective date.

3. The migration to a .gov domain is considered a lower priority and should be completed within six (6) months of the contract effective date.

CMMC Level 2 compliance is the highest priority of this RFP and an ensuing contract. In the event of any conflict between requirements listed in this Scope of Work, the requirements of CMMC Level 2 should take precedence.

MIDA recognizes that technical dependencies may dictate a more efficient order of operations (e.g., completing the .gov transition prior to CMMC Level 2 readiness). Offerors are encouraged to propose alternative timelines if their technical approach warrants a different schedule to maximize efficiency.

2.4. Exceptions to this Scope of Work

The Offeror is not responsible for the direct execution of administrative and physical security controls that are inherently internal to MIDA’s operations. However, MIDA retains the option to consult with the Offeror for recommendations and best practices regarding the following areas:

1. Personnel Security and Awareness: MIDA will manage the screening of its personnel and the delivery of security awareness training.

2. Physical Security and Facility Management: MIDA is responsible for the physical protection, monitoring, and access control of its central storage facility (e.g., visitor logs, escorting, and physical access devices).

3. Physical Media Protection: MIDA will handle the physical marking, storage, and transport of CUI media (paper or digital). However, the Offeror remains responsible for the technical sanitization/wiping of media prior to disposal.

4. Publicly Accessible Systems: Management and control of CUI on any MIDA-hosted public-facing platforms (e.g., midaut.org).

Offeror is not responsible for arranging or contracting the services of a C3PAO for a CMMC Level 2 assessment. However, the Offeror may provide technical guidance to assist MIDA during the C3PAO selection or procurement process if requested.

Section 3: Minimum Requirements

3.1. Minimum Requirements

To be considered for evaluation, the Proposal must meet ALL of the minimum requirements listed below.

For joint proposals, the requirements may be satisfied by the Lead Offeror, the Partner, or both, as specified in the “Joint Proposal” note in each section.

Failure to meet any of these criteria will result in the immediate disqualification of the proposal.

3.1.1. Secure Support Operations

The Offeror must certify that its support operations — specifically the personnel and devices authorized to access, view, troubleshoot, or manage systems processing or storing MIDA’s CUI — operate in full compliance with NIST SP 800-171 standards.

Joint Proposal: In a joint proposal, BOTH the Lead Offeror and Partner must meet these requirements. Proposals must explicitly identify that both firms meet this requirement.

3.1.2. Managed IT Services Experience

The Offeror must certify that it has provided managed IT services for a minimum of five (5) years immediately preceding the date of its proposal submission.

Joint Proposal: This requirement may be satisfied by either the Lead Offeror OR the Partner. The proposal must explicitly identify which firm (Lead Offerer, Partner, or both) satisfies this requirement.

Section 4: Proposal Requirements

An Offeror must submit two (2) separate files as part of its proposal: a technical proposal and a cost proposal. The requirements for the technical proposal are outlined in Section 4.1., and the requirements for the cost proposal can be found in Section 4.2.

4.1. Technical Proposal Requirements

The Offeror shall provide the information below as part of its technical proposal. The Offeror is prohibited from providing any cost information or data in this part of the proposal.

4.1.1. Minimum Requirements

The Offeror must certify and provide information to demonstrate that it meets ALL minimum requirements in its proposal. Failure to meet or address ANY of these requirements will result in the immediate disqualification of the proposal.

1. A statement that certifies the Offeror meets the minimum requirements outlined in

Section 3.1.1., Secure Support Operations.

2. A statement that certifies the Offeror meets the minimum requirement outlined in Section 3.1.2., Managed IT Services Experience.

4.1.2. Plan and Approach

This section of the proposal should describe how the Offeror intends to deliver the services outlined in the Scope of Work. Generic marketing materials are strongly discouraged.

Specifically, the technical approach should include the following:

1. Joint Proposal Division of Duties: If submitting a joint proposal, the Offeror must provide a detailed breakdown of responsibilities, clearly identifying which company (Lead Offeror or Partner) will be responsible for each component of the Scope of Work.

2. CMMC Strategy: Detailed Strategy and estimated timeline for compliance with CMMC

Level 2 standards. MIDA prefers strategies that are cloud-based, reduce scope, isolate CUI with the use of an enclave, and create the least burden on the organization and its staff. Offerors are not required to factor a C3PAO assessment in its timeline.

3. Help Desk Support:

a. A table defining response times and resolution targets for Tier 1, Tier 2, and

Tier 3 support.

b. Standard operating hours and days for routine support inquiries and the availability for critical incidents, such as a security breach.

c. Staffing levels of help desk technicians.

d. Physical location of the help desk technicians and their proximity to Level 2 and Level 3 engineers.

e. Description of the help desk’s ability to provide service via phone, email, support portal, and/or online ticketing system.

4. Device Management: A description of the proposed MDM and EDR solutions and how it would be deployed to existing devices. Provide any information on the Offeror’s capabilities to procure, set up, and ship hardware to MIDA staff.

5. .gov Transition Plan: A detailed technical project plan and timeline for the .gov domain transition. This must include the Offeror’s strategy for maintaining email continuity (email routing), updating single sign-on identities, and ensuring zero downtime for MIDA operations.

6. Incident Response: A description of the Offeror’s incident response protocol. This must also include how the Offeror can support in meeting the five (5) day notification requirement under the GDPA, including its process for data forensics and identifying affected individuals.

7. Backup & Recovery: A description of the Offeror’s proposed backup and recovery solution, including the frequency of automated backups. It is encouraged to provide an example of a test report that would be provided to MIDA for restoration tests.

8. Proposed Software and Hardware: A list of all new software and hardware proposed to meet the Scope of Work. Generic terms (e.g., “we will implement an industry-standard file backup software”) are strongly discouraged. Offerors may also propose alternative solutions to MIDA’s existing cloud-based software but must give a justification.

4.1.3. Experience and References

1. Company Overview: A brief overview of the Offeror’s company (and the Partner’s company, if submitting a joint proposal), including the following information for each company:

a. Company name;

b. Company address;

c. Website URL;

d. Estimated number of employees;

e. Estimated number of help desk/service desk staff;

f. Estimated number of Level 2 and Level 3 engineering staff;

g. Number of years the company has operated as an IT managed service provider;

h. Estimated number of customers;

i. 2025 revenue; and

j. Projected 2026 revenue.

2. References: Provide three (3) references for clients, preferably those similar in size or scope as MIDA and/or clients who have obtained CMMC Level 2 compliance with the assistance of the Offeror.

a. If submitting a joint proposal, the three (3) references should collectively demonstrate the experience of the entire team. It is strongly recommended that the Offeror include at least one (1) reference for the Partner if the Partner is responsible for a material portion of the Scope of Work.

b. Each reference should include the following information:

i. Company Name;

ii. Contact Person;

iii. Address;

iv. Phone number;

v. Email address; and

vi. Brief description of the services Offeror (or Partner) provided.

MIDA reserves the right to contact references to verify the quality of service and type(s) of services provided by the Offeror.

4.1.4. Key Personnel and Qualifications

1. The Offeror must provide professional biographies and/or resumes for the key personnel who will be directly responsible for the strategic execution of MIDA’s account.

At a minimum, this should include:

a. Executive / Account Manager: the primary point of contact for contract management and high-level escalation.

b. CMMC Lead: the individual responsible for the CMMC Level 2 implementation.

c. Technical Lead: the individual overseeing the managed IT services and .gov domain transition.

2. Requirements for key personnel:

a. Resumes should highlight experience in federal cybersecurity compliance

(NIST 800-171/CMMC) and/or public sector IT support.

b. If the Offeror is submitting a joint proposal, the proposal must explicitly state which company employs each individual.

c. By listing these individuals, Offeror commits that they will be assigned to the

MIDA account for the duration of the initial implementation phase.

d. Professional biographies or resumes for general help desk or support staff are not required.

4.2. Cost Proposal Requirements

The Offeror must submit a cost proposal that provides the estimated TOTAL COST of the contract throughout its three (3) year term. The total cost should be calculated like so:

Total Cost = One-Time Project Costs + (Monthly Cost x 36)

All pricing provided must be fully loaded and inclusive of all labor, travel, overhead, administrative fees, and any other expenses required to complete the Scope of Work. Offerors are not expected to include costs for extraordinary, unpredictable events (e.g., “force majeure” events, catastrophic security breaches not attributable to Offeror’s negligence or failure to maintain security standards).

Section 4.2.1. below outlines the information that should be included in the One-Time Project Cost, and Section 4.2.2. provides the information that must be included in the Monthly Costs.

4.2.1. One-Time Project Costs

The Offeror must provide a separate total fixed cost for each of the following two projects:

1. Transition & Implementation

a. Deployment of management tools (e.g., MDM) to existing devices, documentation of the current environment, and initial administrative setup.

b. The technical labor required to migrate MIDA to the .gov domain, including email routing updates and single sign-on reconfiguration.

2. CMMC Level 2 Compliance

a. Creation of policy documentation and the technical remediation required to bring MIDA into compliance as outlined in Section 2.2.

b. The estimated cost and labor hours necessary to serve as the point of contact for one (1) CMMC Level 2 assessment by a C3PAO. (This cost covers the Offeror’s labor to support the audit. The actual fees charged by a C3PAO for the assessment should be excluded from the cost proposal, as MIDA would pay the fee to the C3PAO directly.)-

For each of the two projects listed above, the Offeror must provide a detailed breakdown including:

1. The specific job titles performing the work (e.g., Project Manager, Senior Engineer).

2. The hourly billable rate for each labor category.

3. The estimated number of hours estimated for each labor category to complete the specific project.

4. The calculated total (Hours x Rate).

5. The itemized costs of any one-time purchases of new software or hardware necessary to achieve CMMC Level 2 compliance or to implement MDM, EDR, etc. Offerors should not include the cost of hardware for future MIDA staff (e.g., new hire laptops).

4.2.2. Monthly Costs

The Offeror must provide a monthly cost for the ongoing operational support and maintenance components of the services outlined in Section 2.3 throughout the three (3) year term.

This monthly cost must exclude any one-time implementation, migration, remediation, or initial setup costs mentioned in Section 4.2.1. The Offeror must clarify if this is a fixed monthly fee (flat rate) or a per-user/per-device fee.

This portion of the cost proposal must also include itemized costs for new software and hardware that would be paid on a monthly or cyclical basis. The Offeror should not include the cost of software or licenses that MIDA currently owns and pays for directly unless the Offeror proposes to become the reseller for those licenses. If the Offeror proposes to become the reseller, the proposal should only include value-added reseller fees or markups, not the base cost of the licenses.

Offerors can make the following assumptions when calculating this cost:

1. Users: 20 users / 20 devices.

2. General Help Desk Support: 15 tickets per month.

3. User and Device Management: Estimated four (4) onboarding/offboarding events per year.

4.2.3. Firm Pricing and Negotiation

Pricing provided in the Cost Proposal shall be considered firm and fixed. By submitting a proposal, the Offeror agrees that their proposed pricing shall remain valid throughout the evaluation period and until a contract is fully executed. In the event that MIDA elects to negotiate with an Offeror as permitted in Section 7.4., the Offeror agrees that the pricing submitted in the original proposal shall serve as a ceiling for all costs and may not be increased during the negotiation process unless MIDA requests a material change to the Scope of Work that warrants a price adjustment.

Section 5: Solicitation Period and Submission Instructions

5.1. Mandatory Pre-Proposal Meeting

A mandatory pre-proposal meeting will be held virtually via Zoom on February 19, 2026 at 10:00 am (MST). During the meeting, MIDA staff will provide a detailed overview of its current IT and security infrastructure and goals. This will be followed by a Q&A session.

Offerors must register for the Zoom meeting in advance using this link:

https://us06web.zoom.us/webinar/register/WN_l3KgKgt0TheI1YGJZ-Xz4w

Proposals from Offerors who do not attend this mandatory meeting will be deemed non-responsive and will not be evaluated.

5.2. Non-Disclosure Acknowledgement Required

Due to the sensitive nature of the security details that will be discussed at the pre-proposal meeting, attendance is restricted to Offerors who have executed a Non-Disclosure Acknowledgement (“NDA”). The NDA can be obtained in Exhibit A of this document or on the solicitation’s page on the Utah Public Procurement Place (“U3P”).

The NDA should be received by kyoung@midaut.org no later than February 17, 2026 at 5:00 pm (MST) to ensure MIDA staff have sufficient time to verify the completeness of the document and admit the Offeror to the virtual meeting.

Please note: the February 17, 2026 5:00 pm (MST) NDA deadline is requested for administrative processing and is not a criterion for proposal disqualification. However, Offerors who submit an NDA after this deadline (or an incomplete NDA) risk a significant delay in being admitted to the virtual meeting or being denied entry to the meeting. Any Offeror who fails to submit a completed NDA prior to the start of the meeting will be denied entry.

5.3. Question and Answer Period

All questions regarding this solicitation must be emailed to and received by Kara Young at kyoung@midaut.org on or before February 26, 2026 at 5:00 pm (MST). Please do not post questions regarding this RFP to U3P, as questions may suggest or identify sensitive security information.

To ensure the security of the information provided, responses to questions will be emailed only to individuals who have completed the required NDA. Consequently, no answers will be released prior to February 17, 2026 at 5:00 pm (MST) (the NDA submission deadline).

https://us06web.zoom.us/webinar/register/WN_l3KgKgt0TheI1YGJZ-Xz4w

Note: it is the responsibility of the Offeror to ensure their email information on the NDA is correct and legible, check their email regularly, and verify their email security settings permit the receipt of emails from a midaut.org domain email address. MIDA is not responsible for questions or answers lost to spam filters.

5.4. Addenda

MIDA may issue addenda to this RFP to clarify requirements, provide additional information, or modify the RFP. Addenda will be posted on the U3P website and emailed to individuals who have completed an NDA. It is the sole responsibility of an Offeror to regularly monitor the U3P website and check their email accounts.

5.5. Proposal Submission Instructions

All proposals must be submitted electronically via the Utah Public Procurement Place (“U3P”) on or before March 5, 2026 at 5:00 pm (MST). Any proposal received after such time will be deemed non-responsive. It is the sole responsibility of the Offeror to ensure that its proposal is submitted to and received by U3P by the deadline specified above.

Offerors must submit two (2) separate electronic files for each proposal: one technical proposal file and one cost proposal file.

For instructions on how to submit a proposal, please visit the U3P help center here:

https://purchasing.utah.gov/training/for-vendors-training/.

5.6. Interviews

Following an evaluation of written technical proposals, MIDA will invite a selection of the Offerors to participate in an interview.

5.6.1. Schedule and Logistics

1. Interviews will be tentatively scheduled for March 13, 2026. This date is subject to change based on the availability of the evaluation committee members and the number of proposals received.

2. Kara Young, kyoung@midaut.org, will contact invited Offerors to determine an interview time and provide a Zoom meeting link.

3. Interviews will last approximately 30 minutes. Offerors must prepare a 10-15 opening presentation, which will be followed by a Q&A with the evaluation committee. Offerors are strongly encouraged to include the Executive/Account Manager, CMMC Lead, and Technical Lead who would be assigned to MIDA’s account.

MIDA RFP for Managed Information Technology Services & CMMC Level 2 Compliance https://purchasing.utah.gov/training/for-vendors-training/

5.6.2. Rules of Conduct

1. To maintain the integrity of the evaluation process, Offerors and evaluation committee members are strictly prohibited from discussing or revealing cost or pricing information during the presentation.

2. The purpose of the session is to allow the Offeror to clarify or correct information, provide additional context, and answer the evaluation committee’s questions. Offerors may not modify the scope of their original proposal.

Section 6: Evaluation, Scoring, and Award

6.1. Minimum Requirements

The Offeror must certify and provide evidence that it meets all of the minimum requirements outlined in Section 3. If an Offeror does not meet all of these minimum requirements, its proposal will be immediately disqualified, and it will not be evaluated further.

6.2. Evaluation Criteria

The evaluation committee will evaluate proposals that meet the minimum requirements using the following weighted criteria:

Evaluation Criterion Weight Max. Points Possible

Plan and Approach 30% 150

Experience and References 20% 100

Key Personnel and Qualifications 10% 50

Interviews 10% 50

Cost 30% 150

6.3. Technical Proposal Scoring

Each evaluator will assign a score from zero (0) to five (5) for each technical criterion:

● 5 = Excellent. The proposal addresses and exceeds all of the requirements and criteria.

● 4 = Good. The proposal addresses all requirements and criteria and in some respects exceeds them.

● 3 = Satisfactory. The proposal addresses all requirements and criteria in a minimum satisfactory manner.

● 2 = Unsatisfactory. The proposal addresses the requirements and criteria in an unsatisfactory manner.

● 1 = Poor. The proposal inadequately addresses the requirements and criteria or cannot be assessed due to incomplete information.

● 0 = Fail. The proposal fails to address the requirements and criteria or cannot be assessed due to missing information.

The evaluators’ scores will be averaged to produce a single average score for each criterion. That average score will then be divided by the highest possible score and then multiplied by the number of possible points, like so:

Points Awarded = (Average Weighted Score / Highest Possible Score) x Possible Points

6.4. Interview Scoring

Following the evaluation of the Technical Proposals, MIDA will establish a shortlist of Offerors to proceed with the interview phase. To be invited for an interview, an Offeror must achieve a minimum technical score of 75% of the total available technical points (225 points out of 300).

The interview provides an opportunity for Offerors to clarify their proposals and for MIDA to evaluate the team’s expertise. Each evaluator will assign a score from zero (0) to five (5) for the interview based on the rubric defined in Section 6.3. The points will be calculated using the same “Points Awarded” formula used for the technical proposal scoring.

6.5. Cost Proposal Scoring

Cost proposals will be evaluated based on the estimated total contract cost. Cost points will be awarded based on the following formula:

Cost Score = Maximum Cost Points x (Lowest Proposed Cost / Offeror’s Proposed Cost)

MIDA reserves the right to conduct a cost realism analysis and to adjust an Offeror’s score or deem a proposal non-compliant based on the findings. This analysis may include, but is not limited to:

1. Review of estimated labor hours. MIDA will review the estimated labor hours for the transition and implementation of managed IT services and CMMC Level 2 compliance. If an Offeror’s proposed hours are deemed unrealistically low for the scope, MIDA may conclude that the Offeror lacks a clear understanding of the project’s requirements and deduct points accordingly.

2. Review of itemized costs. MIDA will verify that all deliverables described in the technical proposal are accounted for in the cost proposal. If the Offeror fails to include costs for items outlined in its technical approach, such as new software or required hardware or the transition to a .gov domain, MIDA may deem the proposal non-compliant.

6.6. Award and Notice

MIDA intends to award a contract resulting from this RFP to the highest scoring responsive and responsible Offeror meeting the stated RFP requirements.

If an Offeror is awarded for a contract, the notice of award will be posted on U3P, and the selected Offeror will be contacted directly to begin the contracting and negotiation process. Offerors may also request a copy of the notice of award by emailing Kara Young at kyoung@midaut.org.

Section 7: Other Information

7.1. Cost of Proposals

MIDA is not liable for any costs incurred by Offerors in the preparation, presentation, or negotiation of proposals submitted in response to this RFP. All such costs shall be borne by the respective Offeror.

7.2. Protest Procedures

Any actual Offeror who is aggrieved in connection with the solicitation or award of a contract under this RFP may file a protest by submitting a written protest via email to Kara Young at kyoung@midaut.org.

The written protest must include the following:

● The protesting party’s name, mailing address, daytime telephone number, the signature of the protesting party or their attorney, and the date the protest is signed.

● A statement of relief sought, a statement of facts, and a recitation of reasons and legal authority in support of the protest sufficient to allow for an appropriate review.

The protest must be submitted prior to the proposal due date, unless the protestor was unaware of the facts giving rise to the protest. In such cases, the protest must be submitted within five (5) business days of the notice of award being posted on U3P.

The Purchasing Agent will review the protest and issue a written determination. This determination shall be considered final.

7.3. Government Records Access and Management Act (GRAMA)

Records related to this procurement are subject to the Utah Government Records Access and Management Act (“GRAMA”). Offerors may submit a written claim of business confidentiality in accordance with Utah Code § 63G-2-309. A sample form may be found in Exhibit B of this document.

7.4. Reservation of Rights

MIDA reserves the right, among other things to:

1. Reject any or all proposals;

2. Award all or part of the work described in this RFP;

3. Waive irregularities or informalities;

4. Request clarification of a proposal;

5. Conduct interviews with one or more Offerors;

6. Adjust the minimum scoring threshold for interview invitations to ensure a sufficient competitive range;

7. Limit the number of Offerors it invited to interview based on natural breaks in scoring or administrative efficiency;

8. Invite additional Offerors to interview if it is determined to be in the best interest of the project, regardless of the initial percentage threshold;

9. Cancel interviews with one or more Offerors;

10. Contact provided references;

11. Terminate the RFP process at any time;

12. Select an Offerer based solely on written submissions;

13. Re-advertise the RFP;

14. Modify the RFP with written notice;

15. Negotiate with an Offeror prior to a final award;

16. Contact the references provided in proposals to verify the quality and types of services provided by the Offeror;

17. View the Offeror’s provided website URL to verify proposal and company information;

18. Contract with multiple Offerors; and

19. Accept any proposal or proposals deemed to be in the best interests of MIDA.

7.5. Examination of Proposal Documents and Federal Requirements

The submission of a proposal shall constitute an acknowledgement upon which MIDA may rely that the Offeror has thoroughly examined and is familiar with the RFP and has reviewed all applicable statutes, regulations, ordinances, and federal regulations and standards related to the services to be provided.

Failure or neglect to examine such documents, legal requirements or standards shall not relieve the Offeror of its obligations. No modification of the Offeror’s obligations will be permitted based on a lack of knowledge or misunderstanding of this RFP or applicable requirements.

7.6. Written Agreement Required and Proposed Alterations

The selected Offeror(s) must be willing to enter into a written agreement with MIDA and agree to all terms and conditions set forth in this RFP, including Appendix C: Standard Terms and Conditions.

If an Offeror wishes to request alterations to the RFP or the Standard Terms and Conditions, the alterations must be specifically identified in the proposal with reasonable alternatives presented. Any such exceptions must be submitted as a separate document and labeled “Requested Alterations.”

Offerors are advised of the following:

1. Only those alterations identified in the “Requested Alterations” document will be available for discussion or negotiation.

2. MIDA may reject a proposal as non-responsive if the Offeror submits a large number of exceptions or exceptions that are in fundamental conflict with the requirements of the RFP.

3. MIDA is not bound by the terms of the RFP or any proposal until a written agreement is fully executed. Any activity taken on by the Offeror prior to full execution is done at the Offeror’s sole risk.

Appendix A: Non-Disclosure Acknowledgement

This Non-Disclosure Acknowledgement (“Acknowledgement”), is agreed to as of the date of Offeror’s signature below (“Effective Date”) as a condition of Offeror’s participation in the Request for Proposals for Managed Information Technology Services and CMMC Level 2 Compliance (the “RFP”).

Offeror acknowledges that MIDA may provide Offeror with access to protected records as defined by Utah Code §63G-2-305, and/or with certain confidential information related to MIDA’s security of property, record keeping systems, and information technology (“IT”) infrastructure and security under the terms of conditions of this Acknowledgement. These records and information shall be collectively referred to as “Confidential Information”.

MIDA hereto agrees to disclose and Offeror hereto acknowledges and agrees to receive Confidential Information as applicable in a manner consistent with the following provisions:

1. Confidential Information

The Offeror anticipates that Confidential Information may be disclosed and received during the RFP process. Confidential Information is defined as: any information provided by MIDA to Offeror in connection with the RFP, except for documents, addenda, and information publicly posted on the RFP’s solicitation page on the Utah Public Procurement Place (“U3P”) website. Confidential Information includes, but is not limited to, protected records as defined by Utah Code §63G-2-305 and MIDA’s IT infrastructure and security protocols.

Offeror acknowledges and agrees that it will maintain the secrecy and confidentiality of all Confidential Information and agrees to use Confidential Information only for the purpose of responding to the RFP.

Offeror agrees to use measures to protect the secrecy and confidentiality of Confidential Information that are no less than reasonable under the circumstances, and will neither use nor disclose Confidential Information to anyone other than those who need to know Confidential Information for the purpose of responding to the RFP. Offeror agrees that it will be responsible for any breach of this Acknowledgement by any of its employees, agents, authorized representatives or permitted assignees or subcontractors.

Without prior written consent from MIDA, Offeror will not: (i) disclose to any person or entity the substance or import of the Confidential Information; (ii) use any Confidential Information to access or obtain additional information outside the purpose contemplated by this Acknowledgement; (iii) duplicate, distribute or otherwise reproduce Confidential Information in any way. Offeror will not remove a designation of confidentiality from any item or material containing Confidential Information.

Confidential Information does not include information that is: (i) is or becomes generally known and available to the public other than as a result of any breach by Offeror of this Acknowledgement; (ii) is subsequently learned from a third party who is under no obligation of confidentiality with respect to such information; (iii) was known by Offeror under no obligation of confidentiality prior to disclosure by MIDA hereunder; or (iv) was generated independently by Offeror without reference to MIDA’s information.

2. Ownership of Confidential Information

Unless otherwise specified in writing, all Confidential Information remains the sole and exclusive property of MIDA. Upon Offeror’s submission of a response to the RFP or MIDA’s request or within thirty

(30) days from the awarding of one or more contracts in response to the RFP, whichever comes first, Offeror agrees to promptly, and at its own expense: (i) redeliver to MIDA all copies of Confidential Information in Offeror’s possession, whether such information is in written, electronic, digital, or other form or format; (ii) destroy any and all analyses, compilations, studies, or other documents in any form or format that were prepared by or for the use of Offeror which contain or reflect any information; and

(iii) if requested, certify such destruction to MIDA in writing by an authorized officer of the Offeror who supervised such destruction.

3. Breach of Confidentiality

Offeror acknowledges and agrees that the remedy at law for any breach of confidentiality is inadequate and that, in addition to monetary damages, including but not limited to special, incidental, consequential or punitive damages, and any other available relief at law, whether based in contract, tort or otherwise, MIDA will be entitled to specific performance, injunctive relief or any other equitable remedy without the need to: (i) prove actual damages; and/or (ii) post any bond or other security deposit in connection with such remedy.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .