A17_JA_-_SSJ_-_Vanguard_zAssure_RFO_12_102(a)_Redacted_1.pdf

PDF 345 KB Posted

Attached to
Vanguard z/Assure Single Source Determination Federal contract opportunity
Solicitation number
140D0426Q0687
Issued by
Department of the Interior Departmental Offices Interior Business Center

About this file

This is a Single Source Determination document for a commercial product acquisition under the Simplified Acquisition Threshold (SAT), issued by the U.S. Department of the Interior's Interior Business Center (IBC) on behalf of the Office of the Chief Information Officer (OCIO).

The Department of the Interior seeks to acquire Vanguard zAssure Resource Access Control Facility (RCAF) licenses from Vanguard Integrity Professionals, Inc., located at 6625 S Eastern Avenue, Suite 100, Las Vegas, Nevada 89119-3930 (Point of Contact: Barbara Reeves, 877.794.0014 x 307). The acquisition covers a base period of twelve (12) months with two (2) optional twelve-month renewal periods under a Firm-Fixed-Price (FFP) contract structure. The Independent Government Estimate (IGE) pricing is redacted in the document. The requirement is set aside as a Women Owned Small Business (WOSB) procurement under NAICS 513210 (Software Publishers). The planned acquisition includes mainframe software licensing, annual support, maintenance, and updated software versioning services to support DOI's Federal Personnel and Payroll System (FPPS) vulnerability management and cybersecurity defenses.

The Contracting Officer has determined that only one source is reasonably available based on brand-name requirements. The justification centers on Vanguard's unique qualifications: proof-of-concept (POC) testing evaluated multiple commercially available code scanning products, and only z/Assure demonstrated the combined capability to detect vulnerabilities in DOI's z/OS mainframe environment while producing high-level reports that non-IT professionals can readily understand and act upon. Competitive alternatives produced overly technical reports requiring expert interpretation, preventing timely remediation. Market research included searches of the internet, NASA SEWP, and GSA IT Schedules, with Vanguard confirming it has no authorized resellers for these proprietary licenses. DOI commits to periodic reassessment of alternative solutions for future requirements. The document was signed by Contracting Officer Matthew Mosellen on July 6, 2026, and concurred by Program Manager/COR Catherine Beach on July 7, 2026.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

3. Identification of the single source to be solicited.

Vanguard Integrity Professionals, Inc.

6625 S Eastern AVE

STE 100

Las Vegas, Nevada 89119-3930

POC: Barbara Reeves

877.794.0014 x 307

702.794.0014 x 307 barbara.reeves@go2vanguard.com

4. Basis for Single Source Determination.

The Contracting Officer has determined that only one source reasonably available.

Brand-name requirement � The particular brand name is essential to the requirement and market research indicates similar products do not meet or cannot be modified to meet agency needs. If the justification is to cover only the portion of the buy which is brand name, then it should so state; the approval level requirements will then only apply to that portion.

5. Detailed Rationale.

Vanguard possesses unique qualifications required for this acquisition, which provides mainframe software licensing, annual support, maintenance and updated software versioning services for its proprietary RCAF license(s).

Market research has indicated that there are limited products available within the commercial marketplace that offer the specific level of code scanning and automation needed for an assessment of DOI�s z/OS environment. A proof of concept (POC) test was conducted using multiple, similar commercially available products, assessing functionality and reporting capabilities. Amongst these products was z/Assure from Vanguard. From the results of the POC testing, only z/Assure was found to be able to provide the combined detection of the desired weaknesses/vulnerability within DOI�s system with the necessary high-level reports needed for IBC management to accurately, succinctly, and easily convey the vulnerability results.

The POC test scans conducted using zAssure�s were found to be capable of detecting the desired weaknesses/vulnerability present within DOI�s mainframe operating system environment which hosts the Federal Personnel and Payroll System (FPPS) application.

This is of significant value to DOI as once the weaknesses/vulnerability are detected, they can be remedied prior to being exploited by a malicious actor. More specifically, as FPPS is responsible for coordinating payroll functions to employees across DOI, a disruptive cyber attack could not only halt payment to DOI employees, but also expose personally identifiable and financial information of DOI employees. Thus, the security of the FPPS system is of the utmost importance.

In addition to the detection capabilities of zAssure, the high-level reports produced as a result of scan(s) by zAssure were found to be of a higher quality than other, similar products. Specifically, the zAssure high-level reports were found to accurately, succinctly, and easily convey the vulnerability results in a manner that non-IT professional were capable of easily understanding and digesting. This then allows DOI to take quicker action as to any detected weaknesses/vulnerability found, as less time is spent interpreting the zAssure scan results compared to the results of other scanning tools.

Other scanning tools were found to capable of detecting the desired weaknesses/vulnerability present within DOI�s system, but product results reports that were considered highly technical in nature. As such, cybersecurity laymen are unlikely to be able to easily read/understand/comprehend results reports in a timely manner and without expert assistance. As such, they are not of the quality that would allow DOI to remedy any detected weaknesses/vulnerability in a timely manner.

The Vanguard software licenses sought under this requirement are commercial in nature. The purchase of commercial, off-the-shelf licenses is in alignment with Executive Order 14271: Ensuring Commercial, Cost- Effective Solutions in Federal Contracts where the Government is purchasing a commercial, off the- shelf solution with minimal modification/configuration, as opposed to pursuing �highly specialized� or �custom-developed� solutions.

For future requirements, DOI OCIO will reassess whether solutions other than Vanguard software products can be utilized. If solutions other than Vanguard products are available without creating significant detriment to the Government, future requirements will be competed. If Vanguard remains the only viable solution, similar brand name procurements may be awarded.

6. Market Research.

Market research included a search of the internet, NASA SEWP, and GSA IT Schedules; however, no other solution was found acceptable for immediate use.

Additionally, Vanguard confirmed via email that it has no authorized resellers for the Vanguard zAssure RACF license(s) and support sought under this requirement.

Vanguard also confirmed via email that the Vanguard zAssure RACF license(s) are proprietary in nature and sold commercially.

Market research is periodically conducted by DOI to assess the availability of alternate sources for its requirements. DOI will continue to seek and test other sources for suitability and determine if the other potential solutions can adequately meet the Government�s needs. To date, Vanguard is the only vendor that has provided a solution that can meet OCIO�s present needs.

File details come from the government source that posted it. Updated .