Attachment A RFP 758 2500000347 .pdf

PDF 376 KB Posted

Attached to
IT Peripherals, Components & Services Online Ordering System State and local contract opportunity
Solicitation number
RFP-758-2500000347-1
Issued by
Elliott County, Kentucky

About this file

The document is a Request for Proposal (RFP) 758 2500000347 issued by the Commonwealth of Kentucky's Finance and Administration Cabinet on behalf of the Commonwealth Office of Technology (COT), seeking a Reseller Partner for an Information Technology (IT) Peripherals and Components & Related Services Online Ordering System. The RFP is for a master agreement to provide an online ordering platform for peripherals, components, and related services including audio/visual hardware, installation/de-installation services, and relocation services for all state agencies. The solicitation was released on June 24, 2025, with proposals due by July 24, 2025, at 3:30 PM ET. The initial contract term will be one year, with the possibility of six additional one-year renewals upon mutual agreement.

The online ordering system must be a standalone, secure, and customizable platform that allows agencies to view a catalog of peripherals and components, create downloadable quotes, and place orders directly using a procard. The vendor must be able to resell various branded hardware and provide related services, with specific requirements including Energy Star and EPEAT compliance, Section 508 accessibility, and comprehensive security measures. The evaluation will be based on a total of 2,000 possible points, with 1,000 points for the technical proposal, 500 points for the cost proposal, and potentially 500 points for oral presentations. The Commonwealth reserves the right to negotiate with the top-ranked vendor and may request Best and Final Offers (BAFO).

View the file

Other files for this state and local contract opportunity

Other files attached to IT Peripherals, Components & Services Online Ordering System, newest first.
File Type Posted
ATTACHMENT C Annual Affidavit and Other Affidavits RFP 758 2500000347.docx DOCX document
Final_RFP_758_2500000347_1_SO_FORM.PDF PDF
Attachment B - Cost Proposal Form RFP 758 2500000347.docx DOCX document
Attachment F Mandatory Requirements Checklist RFP 758 2500000347.xlsx XLSX spreadsheet
ATTACHMENT D VENDORS QUESTION FORM RFP 758 2500000347.xlsx XLSX spreadsheet
ATTACHMENT E Personal Information Security & Breach Investigation Act-HB5 RFP 758 2500000347.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT A

Commonwealth of Kentucky

Request for Proposal (RFP) For

INFORMATION TECHNOLOGY (IT)

PERIPHERALS AND COMPONENTS & RELATED SERVICES

ONLINE ORDERING SYSTEM

RFP 758 2500000347

Release Date: June 24,2025

CLOSING DATE AND TIME: July 24, 2025, at 3:30pm ET

Issued by The Finance and Administration Cabinet

On Behalf Of The Commonwealth Office of Technology (COT)

Commonwealth Buyer:

Dianne Lee, KCPM Statewide Procurement Analyst II

COMMONWEALTH OF KENTUCKY

FINANCE AND ADMINISTRATION CABINET

Office of Procurement Services 200 Mero Street, 5th Floor

Frankfort, KY 40622

(502) 782-0799

TABLE OF CONTENTS

Proposal Submission Checklist Section 1 – Summary Section 2 – Introduction Section 3 – Scope of Work Section 4 – Commonwealth Office of Technology Requirements Section 5 – Procurement Requirements and Instructions Section 6 – Proposal Submission Section 7 – Proposal Evaluation Section 8 – Negotiations Section 9 – Contract Requirements Section 10 – Standard Terms and Conditions Section 11 – Attachments

PROPOSAL SUBMISSION CHECKLIST

The vendor MUST include the following with the proposal submission.

If the items highlighted below are not submitted with the proposal submission, the Commonwealth MUST deem the proposal non-responsive and SHALL NOT consider for award.

All other items MUST be submitted prior to award.

� *PROPOSED TECHNICAL SOLUTION

� *PROPOSED COST SOLUTION

� TRANSMITTAL LETTER [see Section 6.7(A)]

� MANDATORY REQUIREMENTS CHECKLIST (see Attachment F)

� REVENUE FORM 10A100 KENTUCKY TAX REGISTRATION APPLICATION

IF APPLICABLE [see Section 6.7 (C)]

� CERTIFICATE OF AUTHORITY- REGISTRATION WITH SECRETARY OF STATE BY

A FOREIGN ENTITY IF APPLICABLE [see Section 6.7 (D)]

� REQUIRED ANNUAL AFFIDAVIT AND OTHER AFFIDAVIT(S) (see Attachment C) https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offer ors%20and%20Contractors.pdf

� Certificate of Insurance [see Section 10.31]

*Please see Attachment E - The Protection of Personal Information Security and Breach Investigation Procedures and Practice Act (KRS 61.931), et seq.

effective January 1, 2015.

https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offerors%20and%20Contractors.pdf https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offerors%20and%20Contractors.pdf https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offerors%20and%20Contractors.pdf

SECTION 1 - RFP SUMMARY

1.1 Estimated Schedule of RFP Activities

The following table presents the anticipated schedule for major activities associated with the RFP distribution, proposal submission, proposal evaluation process, and contract award. The Commonwealth reserves the right at its sole discretion to change the Schedule of Activities, including the associated dates and times.

Anticipated Schedule of Activities

Release of RFP

June 24, 2025

1st Set of Vendors’ Written Questions due by 12:00 PM ET

(SUBMIT QUESTIONS ON ATTACHMENT D-VENDORS’

QUESTION FORM)

July 9, 2025

Commonwealth’s Response to 1st Set of Vendors’ Written Questions

July 11, 2025

2nd Set of Vendors’ Written Questions due by 12:00 PM ET

(SUBMIT QUESTIONS ON ATTACHMENT D-VENDORS’

QUESTION FORM)

July 15, 2025

Commonwealth’s Response to 2nd Set of Vendors’ Written Questions

July 17, 2025

Proposals due by 3:30 PM ET

July 24, 2025

1.2 Issuing Office

The Commonwealth of Kentucky, Finance and Administration Cabinet, Office of Procurement Services, is issuing this RFP on behalf of the Commonwealth Office of Technology (COT). The Finance and Administration Cabinet is the only office authorized to change, modify, amend, alter, or clarify the specifications, terms and conditions of this RFP.

A contract, based on this RFP, may or may not be awarded. Any contract award from this RFP is invalid until properly approved and executed by the Finance and Administration Cabinet.

1.3 Agencies to Be Served

This contract shall be for use by the Commonwealth Office of Technology (COT) on behalf of All-State Agencies. No shipments shall be made except upon receipt by vendor of an official delivery order or a completed online purchase via a procard from the using agency.

Political Subdivisions Under Kentucky Statutes, political subdivisions of this State including cities of all classes, counties, and school districts may participate in All State Agency Master Agreements to the same extent as agencies of the Commonwealth.

SECTION 2 - INTRODUCTION

2.1 Purpose

The purpose of this Request for Proposal (RFP) is to solicit proposals for competitive negotiations pursuant to 200 KAR 5:307. The RFP is issued to award a Master Agreement for an Information Technology (IT) Peripherals and Components & Related Services Online Ordering System that shall include, but is not limited to, Audio Visual Hardware and Services, Installation/De-Installation Services, and Relocation Services.

2.2 Background

The Commonwealth Office of Technology (COT) serves as the Commonwealth’s central information technology agency and provides technology leadership, services and solutions to the Commonwealth’s Executive Branch agencies. COT also provides enterprise governance by establishing IT policies, standards and guidelines.

In the Commonwealth, the management of information technology is a crucial aspect of ensuring efficient government operations and delivering services to the public. Over the last decade, COT has awarded contracts for Peripherals and Components on behalf of all state agencies, as well as for COT, to enable such government operations and the delivery of services.

SECTION 3 – SCOPE OF WORK

PROPOSALS THAT DO NOT MEET MANDATORY REQUIREMENTS WILL BE

DEEMED NON-RESPONSIVE AND WILL NOT BE CONSIDERED. REFER TO

ATTACHMENT F– MANDATORY REQUIREMENTS CHECKLIST.

Mandatory Requirement means a condition set out in the specifications or statement of work that must be met without exception.”

The Commonwealth is seeking a vendor who is a RESELLER PARTNER to provide an Information Technology (IT) Peripherals and Components & Related Services Online Ordering System that shall include, but is not limited to, Audio Visual Hardware and Services, Installation/De-Installation Services, and Relocation Services. The vendor must be able to resell various branded hardware and related services.

3.1 Online Ordering System

A. The vendor shall provide a customizable online ordering system (secure and encrypted). The system shall not be integrated with the Commonwealth’s eProcurement system and shall be provided as a standalone system maintained by the vendor.

Agencies shall have the ability to view an online list or catalog of peripherals and components & services, select what is needed and either (1) create a downloadable online quote to use to place an order via the Commonwealth’s eProcurement system via the Delivery Order process or (2) select and add items to a cart or basket and order directly from the online ordering system using a procard. The intent is for agencies to have the ability to obtain online quotes and order online, thus eliminating phone and/or email quotes from the vendor.

The online ordering system shall, at a minimum, include the following:

1. A list or catalog of the peripherals and components & related services to include a description and/or specifications, unit of measure and unit cost. Images are not required, but desired.

2. The Commonwealth’s name and contract number to identify the site as the Commonwealth’s site

3. The ability to create downloadable online quotes. These quotes shall not include any additional terms and conditions, nor shall they include any travel or travel related expenses. Online quotes shall include, at a minimum, the following:

a. Commonwealth contract number

b. Agency name, contact information, etc. (Quotes shall not simply state “Commonwealth of Kentucky” as the agency name)

c. Hardware name and/or brand (description and/or specifications should be included)

d. Unit of measure

e. Unit cost

f. Total cost

g. For services, a separate line item is required on the quote that shall include, at a minimum, the following:

1. Detailed outline and description of the services

2. Cost with a breakdown of deliverables and/or milestones if appropriate

3. Anticipated start and end dates and/or hourly rates and number of hours for the service if applicable

4. The ability to order directly from the system with a procard

5. Online customer support and/or chat feature

6. Vendor contact information to include name, telephone number and email address

7. The ability to track orders made directly via the online ordering system. All other orders should also be tracked in a method determined by the vendor.

8. The ability to see previous orders made directly via the online ordering system.

9. The ability to obtain information regarding back-orders and/or out-of-stock items

B. The system shall be customized and completed for the Commonwealth no later than ninety (90) calendar days after contract execution with a system testing period to follow. The anticipated contract effective date is December 20, 2025, which will be the go-live date for the system. Thereafter, COT shall conduct periodic compliance checks of the system.

3.2 Peripherals and Components

Peripherals and Components are devices that attach to, work in conjunction with, supported by, update, enhance and/or integrate with computer systems. The devices shall include, but not limited to, wired or wireless input devices, output devices and storage devices such as:

• Bar Code Readers • Computer Carts

• Data Storage/Drives • Digital Cameras

• Digital Signage Displays • Docking Stations

• Graphic Tablets • Headsets

• Keyboards • Memory Upgrades

• Microphones • Computer Mice

• Networking Cards • Projectors

• Interactive Flat Panel Monitors • Badge/ID Card Printers

• Video Walls • Speakers

• Touchpads • UPS/Battery Backups

• Audio/Visual Hardware • Cables (excluding CAT6)

• Toner/Ink Cartridges • Modems

• Scanners • Plotters

• Monitors •Printers/Copiers/Multifunctional Devices

A. No discontinued, refurbished, rebuilt, or remanufactured peripherals or components shall be allowed under this contract unless otherwise approved by COT.

B. Appliance devices are allowed, which are defined as devices that include integrated or embedded software. These devices should be identified as appliances on the list or catalog of items in the description/specifications field and/or the quote.

C. Executive Branch agencies must seek prior approval from COT for all monitor, scanner and printer/copier/multifunctional device purchases.

D. The list or catalog of items must be maintained and updated as necessary to ensure the latest technology is available to the Commonwealth.

3.3 Peripherals and Components Related Services

Services shall include, but are not limited to, audio/visual related services, installation services, de-installation services, relocation services, technical support, and training.

3.4 Out of Scope Items

This contract SHALL NOT include the following unless otherwise approved by

COT:

A. Standalone software or software solutions (appliance devices are allowed per

Section 3.2 (B) above) B. Smart phones/Land phones C. Security cameras D. Desktop, laptop or tablet related devices E. Any hardware or related services deemed outside the scope of this contract by COT or provided via COT Rated Services or Enterprise Services F. Leasing, financing and rental services

3.5 Energy Star, EPEAT, Blue Angel, EcoLogo, Green Guard, Nordic Swan and

TCO Compliance Hardware should be Energy Star, EPEAT, Blue Angel, EcoLogo, Green Guard, Nordic Swan and/or TCO compliant and should be identified as such in the description and/or specifications of the hardware. The vendor may be required to provide verification of such compliance if requested by the Commonwealth.

3.6 Section 508 Compliance

All user interfaces to the solution(s) provided, shall be warranted by the vendor to be compliant with Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) and the World Wide Web Consortium’s (W3C) Web Content Accessibility Guidelines (WCAG) 1.0, conformance level Double-A or greater by ‘go-live’ by code change and/or through the use of Third-Party software and/or hardware at no additional cost to the Commonwealth.

3.7 Quality Assurance

Hardware shall be free from defects in materials and workmanship, except for normal use and care, over the period of the manufacturers' warranties. All components of the hardware shall be OEM components and covered by OEM warranties. Any defective hardware shall be repaired and/or replaced immediately without charge (including freight both ways).

3.8 Warranty

The manufacturer’s most favorable warranty offered to preferred customers shall apply to all hardware. A copy of such warranty shall be furnished to the agency upon delivery of the hardware. The vendor will not be liable under the above warranty for any defects or damages resulting from unforeseeable causes beyond the control and without the fault or negligence of the bidder, such as misuse or neglect by the State, acts of God, fires, floods and hurricanes.

Extended warranty/maintenance options should be offered for newly purchased hardware under this contract as well as for hardware NOT originally purchased under this contract.

3.9 Damaged Hardware Replacement

The vendor must replace, at no cost to the Commonwealth, hardware that is damaged upon delivery to the Commonwealth. The replacement should be received within fifteen (15) calendar days from notification by the Commonwealth.

3.10 Documentation

Original user manuals and/or related documentation shall be furnished to the agency upon delivery of the hardware. Online links are also acceptable.

3.11 Invoices

Invoices should include the same information that is on the agency’s Delivery Order. The invoice shall include the agency’s Delivery Order number and/or the Commonwealth contract number.

The Commonwealth shall not be charged for any travel or travel related expenses.

3.12 Delivery

A. Delivery shall not exceed thirty (30) working days after receipt of order.

Expedited delivery should be an available option to the Commonwealth if needed. When delivery is not made within the thirty (30) working days, one percent (1%) per day may be deducted from the vendor’s invoice for each day the vendor fails to meet the required delivery time.

B. Agencies may accept partial shipments; however, payment shall not be made until the entire order has been delivered and accepted unless otherwise approved by the agency. Payment shall be NET 30 after an accurate invoice has been submitted by the vendor.

3.13 Monthly Reports

Monthly Reports of all sales to the Commonwealth shall be submitted to COT’s Contracting Officer at stephanier.williams@ky.gov on a date negotiated with the awarded vendor. The ability to see such activity within the system in real-time is preferred. Specific contents of such report shall be negotiated.

3.14 Account Manager and Support Staff

A. The vendor shall provide a single dedicated point of contact (and a backup contact) for the Commonwealth account. A toll-free number shall be provided as well as an email address.

mailto:stephanier.williams@ky.gov

B. The account manager or designee shall have the ability to assist with online inquiries concerning the status of orders, delivery information, back-order information, pricing and any other issues.

C. Technical support and sales staff shall be available statewide during normal working hours (8:00 a.m. – 5:00 p.m. Eastern Time and Central Time), five

(5) days a week.

3.15 Cooperation

The vendor shall cooperate and work with:

A. Other Commonwealth vendors if applicable B. Commonwealth and/or COT staff, to include but not limited to, security staff, systems administrators, service desk staff, application development resources, etc.

3.16 Value Added Services

Value added peripherals and components & related services may be added to the contract with the prior approval of COT and the Office of Procurement Services (OPS) Buyer of Record. Upon approval, a formal modification will be made to the contract. No item shall be sold, and no work shall begin until a contract modification is completed and notice provided by the OPS Buyer. These peripherals and components & related services shall be within the scope of the contract.

SECTION 4 – COMMONWEALTH OFFICE OF TECHNOLOGY (COT)

REQUIREMENTS

4.1 Commonwealth Information Technology Policies and Standards

A. The vendor and any subcontractors shall be required to adhere to applicable Commonwealth policies and standards.

B. The Commonwealth posts changes to COT Standards and Policies on its Commonwealth Office of Technology - Home - Commonwealth Office of Technology (Kentucky) website. Vendors and subcontractors shall ensure their solution(s) shall work in concert with all posted changes. Vendors or subcontractors that cannot comply with changes must, within thirty (30) days of the posted change, request written relief with the justification for such relief.

The Commonwealth may: 1) deny the request, 2) approve an exception to the policy/standard, or 3) consider scope changes to the contract to accommodate required changes. Vendors or subcontractors that do not provide the response within the thirty (30) day period shall be required to comply within ninety (90) days of the change.

4.2 Compliance with Kentucky Information Technology Standards (KITS)

A. The Kentucky Information Technology Standards (KITS) reflect a set of principles for information, technology, applications, and organization. These https://technology.ky.gov/Pages/index.aspx https://technology.ky.gov/Pages/index.aspx standards provide guidelines, policies, directional statements and sets of standards for information technology. It defines, for the Commonwealth, functional and information needs so that technology choices can be made based on business objectives and service delivery. The vendor shall stay knowledgeable and shall provide a solution that works in concert with these standards for all related work resulting from this RFP.

https://technology.ky.gov/about-the-agency/Pages/kits.aspx

B. The vendor and any subcontractors may be required to submit a technology roadmap for any offered solution. Additional roadmaps will be submitted upon request of the Commonwealth. If required, the roadmap shall include, but is not limited to, planned, scheduled and projected product lifecycle dates and historical release/patch or maintenance dates for the technology. In addition, any guidance on projected release/revision/patch/maintenance schedules would be preferred.

C. If vendor is proposing or using any type of Artificial Intelligence (AI), please indicate this in the RFP response.

4.3 Compliance with Industry Accepted Reporting Standards Based on Trust Service Principles and Criteria The vendor must employ comprehensive risk and threat management controls based on defined industry standards for service organizations such as ISO AICPA TSP section 100, Trust Services Principles and Criteria. The vendor must annually assert compliance and engage a third-party certification registrar to examine such assertions and controls to provide a Report, such as ISO 9000, ISO 14001, AT101 SOC 2 type 2, on Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, and Privacy, which contains an opinion on whether the operating controls effectively support the assertions. All such reports, including publicly available reports (i.e. AT 101 SOC

3) shall be made available to the Commonwealth for review.

4.4 System Vulnerability and Security Assessments

The Commonwealth reserves the right to conduct, in collaboration with the vendor, non-invasive vulnerability and security assessments of the software and infrastructure used to provide services prior to implementation and periodically thereafter. Upon completion of these assessments, the Commonwealth will communicate any findings to the vendor for action. Any cost relating to the alleviation of the findings will be the responsibility of the vendor. Mitigations will be subject to re-evaluation after completion. In cases where direct mitigation cannot be achieved, the vendor shall communicate this and work closely with the Commonwealth to identify acceptable compensating controls that will reduce risk to an acceptable and agreed upon level. An accredited third-party source may be selected by the vendor to address findings, provided they will acknowledge all cost and provide valid documentation of mitigation strategies in an agreed upon timeframe.

https://technology.ky.gov/about-the-agency/Pages/kits.aspx

4.5 Privacy Assessments

The Commonwealth reserves the right to conduct privacy assessments of the collection, use, maintenance and sharing of Commonwealth data by any vendor services, software, and infrastructure used to provide services prior to implementation and periodically thereafter. Upon completion of this assessment, the Commonwealth will communicate any findings to the vendor for action. Any cost relating to the alleviation of the findings will be the responsibility of the vendor. Mitigations will be subject to re-evaluation after completion. In cases where direct mitigation cannot be achieved, the vendor shall communicate this and work closely with the Commonwealth to identify acceptable compensating controls or privacy practices that will reduce risk to an acceptable and agreed upon level. An accredited third-party source may be selected by the vendor to address findings, provided they will acknowledge all cost and provide valid documentation of mitigation strategies in an agreed upon timeframe.

4.6 Privacy, Confidentiality and Ownership of Information

The Commonwealth is the designated owner of all Commonwealth data and shall approve all access to that data. The vendor shall not have ownership of Commonwealth data at any time. The vendor shall not profit from or share Commonwealth data. The vendor shall be in compliance with privacy policies established by governmental agencies or by state or federal law. Privacy notice statements may be developed and amended from time to time by the Commonwealth and will be appropriately displayed on the Commonwealth portal (Ky.gov). The vendor should provide sufficient security to protect the Commonwealth and COT data in network transit, storage, and cache. All Commonwealth data, including backups and archives, must be maintained at all times within the contiguous United States. All Commonwealth data, classified as sensitive or higher, as defined in Enterprise Standards, must be encrypted in-transit from vendor’s network and at rest while stored on vendor’s laptops or other portable media devices.

4.7 End User Agreements

Any proposed end user agreements shall be in compliance with the contract terms and conditions and shall be read as applicable only to the extent permitted by Kentucky law and no term in violation of the Kentucky law, inclusive of Kentucky Procurement Law, shall be given effect.

Such agreements should be submitted to the agency with the quote and before the order is placed.

4.8 Software Version Requirements, as it relates to appliance devices All commercially supported and Commonwealth approved software components such as Operating system (OS), Database software, Application software, Web Server software, Middle Tier software, and other ancillary software must be kept current. In the event that a patch interferes with the solution, the vendor must present a plan for compliance to the Commonwealth outlining the constraints and an appropriate plan of action to bring the solution in to compliance to allow this patch to be applied in the shortest timeframe possible, not to exceed three (3) months, unless otherwise negotiated with the Commonwealth.

4.9 No Surreptitious Code Warranty

The vendor represents and warrants that no copy of licensed software provided to the Commonwealth contains or will contain any Self-Help Code or any Unauthorized Code as defined below. This warranty is referred to in this contract as the "No Surreptitious Code Warranty”.

As used in this contract, "Self-Help Code" means any back door, time bomb, drop-dead device, or other software routine designed to disable a computer program automatically with the passage of time or under the positive control of a person other than the licensee of the software. Self-Help Code does not include Software routines in a computer program, if any, designed to permit an owner of the computer program (or other person acting by authority of the owner) to obtain access to a licensee's computer system(s) (e.g. remote access) for purposes of maintenance or technical support.

As used in this contract, "Unauthorized Code" means any malware designed to permit unauthorized access to disable, erase, or otherwise harm software, equipment, or data; or to perform any other such actions. The term Unauthorized Code does not include Self-Help Code.

In addition, vendor will use up-to-date commercial virus detection software to detect and remove any viruses from any software prior to delivering it to the Commonwealth.

The vendor shall defend the Commonwealth against any claim and indemnify the Commonwealth against any loss or expense arising out of any breach of the No Surreptitious Code Warranty.

4.10 Network Connection Requirements

A. Vendor shall work with COT to establish any network connections. If a secure site-to-site connection is required, the vendor shall employ a secure site-to-site connection procured by the Agency from COT.

B. Vendor shall, at COT’s discretion, provide appropriate access to enable the Commonwealth to perform additional security measures, such as decryption of the network traffic if required for inspection. If the proposed solution does not have the ability to meet this requirement, the vendor must provide an alternative such as audit reporting of this function.

C. Vendor should provide notifications to the Commonwealth Service Desk for unplanned outages within fifteen (15) minutes.

D. Vendor shall notify COT Change Management, through the Commonwealth Services Desk, a minimum of two (2) business days prior to any planned outage.

E. Vendor, in conjunction with the agency, shall provide a Business Impact Assessment (BIA) to appropriately classify all data before production/go-live.

F. Vendor shall include a Web Application Firewall when application houses any data classified as sensitive or higher as defined in KITS standards.

G. Vendor shall provide Recovery Time Objective (RTO) and Recovery Point Objective (RPO) services. Vendor shall provide those services to achieve those Service Level Agreement (SLA)s.

4.11 OS Requirements

A. Non-On Prem Solutions

1. No Commonwealth data shall be co-mingled with another entity, without the prior approval of the Commonwealth.

2. Vendor shall provide a solution to move data to the Commonwealth, if required by the Commonwealth.

a. At the end of the contract, the vendor shall provide all agency data in a useable standard data format (such as asci, csv, etc.) that can be converted to a subsequent system. The vendor shall cooperate to this end with the agency and/or a vendor of the agency’s choice, in a timely and efficient manner.

b. Vendor shall address the destruction of Commonwealth data as defined in CIO-092 and provide a certification of the complete and permanent deletion the Commonwealth data.

B. Infrastructure as a Service

1. Vendor shall work with the agency and COT to establish all administrative personnel engagements.

2. Vendor shall meet certification requirements for classification of data being stored.

3. Vendor shall, at COT’s request, provide appropriate access to enable the Commonwealth to perform additional security measures in compliance with Commonwealth Enterprise Policies, Standards, and/or any Federal or State requirements.

4. Vendor shall provide an Exit Strategy, to move all data to the Commonwealth Data Center, if required by the Commonwealth.

a. At the end of the contract, the vendor shall provide all agency data in a form that can be converted to any subsequent system of the agency’s choice. The vendor shall cooperate to this end with the vendor of the agency’s choice, in a timely and efficient manner.

4.12 Project Governance

Vendor shall work with the agency and appropriate COT offices, when needed, in the cases of data governance, security aspects, hosting, integration, etc., provided that such work does not expand the scope of the services as described in this RFP absent a corresponding change order agreed to by the parties reflecting such expansion.

4.13 Application and Service Requirements

A. Current Enterprise Applications and Services

1. COT provides a number of Enterprise Shared Services to State agencies.

Vendor shall use published IT Applications and Services provided on KITS for: Enterprise Service Bus, Enterprise Content Management, Data Warehousing, Data Analytics and Reporting, Business Intelligence, Web Services, GIS, unless explicitly approved by COT.

2. Vendor provided dedicated application components (i.e., Application Servers, Databases, etc.) shall comply with KITS or if the technology is not included in KITS, the technology must be accepted by the Commonwealth for inclusion in KITS or granted a written exception to KITS according to COT Information Technology Standards Policy currently

CIO-051.

3. Vendor applications must describe in detail all available features and functionality accessible via APIs.

4. All business applications must support the ability to use modern authentication for authentication and authorization. Modern authentication technologies would include SAML 2.0, WSFED, OAuth, or OpenID Connect.

4.14 Project Management Requirements

The COT Division of Governance and Strategy (COT-DGS) is responsible for overseeing large and complex technology projects throughout the Commonwealth. The vendor shall adhere to Project Management standards and reporting requirements established by COT-DGS, which are posted at https://technology.ky.gov/services-and-support/Pages/About-the-Project- Management-Branch.aspx. These include, but are not limited to, having a documented project schedule, risk management, issue management and reporting project status to the CIO monthly in the format defined by COT-DGS. In addition to the project management standards required by COT-DGS, agency specific requirements may be defined in this RFP.

4.15 Applicable Security Control Framework Compliance

The vendor must have an awareness and understanding of the NIST Special Publication 800-53 Security Control Framework and employ safeguards that meet or exceed the moderate level controls as defined within the standard. The vendor must provide sufficient safeguards to provide reasonable protections around the Commonwealth’s data to ensure that the confidentiality, integrity, and availability is maintained at an appropriate level. These include but are not limited to:

• Access Control

The vendor must employ policy and process that provide for stringent control to limit physical and logical access to systems that house Commonwealth https://technology.ky.gov/services-and-support/Pages/About-the-Project-Management-Branch.aspx https://technology.ky.gov/services-and-support/Pages/About-the-Project-Management-Branch.aspx data, on a need to know basis, provide clear separation of duties, and adheres to least privilege principles.

• Awareness and Training The vendor must provide the appropriate role specific training for staff to ensure that there is awareness and understanding of roles and responsibilities as they relate to the protections around the Commonwealth’s data.

• Audit and Accountability There must be sufficient auditing capability to ensure that actions are tracked and there is individual accountability for all actions taken by vendor staff.

• Configuration Management The vendor must work within established baselines that provide minimal functionality needed to ensure service delivery without exposing unnecessary risk. The vendor must also employ structured change control processes that provide a level of coordination with the client agreed upon in a Service Level Agreement (SLA).

• Contingency Planning The vendor must employ contingent planning policy and procedures that ensure service delivery based on agreed SLA levels while maintaining all Commonwealth data within the continental Unites States.

• Identification and Authorization The vendor must employ appropriate identity and access management policies and procedures to ensure that access is appropriately authorized and managed at a level to ensure that access is provisioned and de-provisioned in a timely and efficient manner.

• Incident Response The vendor must employ policy and procedures to ensure that an appropriate response to all identified security incidents are addressed in a timely manner and are reported to the appropriate parties in an agreed upon SLA timeframe.

The vendor must also ensure that all staff are sufficient trained to ensure that they can identify situations that are classified as security incidents.

• Maintenance The vendor must employ policy and procedures that ensure that all maintenance activities are conducted only by authorized maintenance staff leveraging only authorized maintenance tools.

• Media Protection The vendor must employ policy and procedure to ensure that sufficient protections exist to protect Commonwealth data on all storage media throughout the media lifecycle and maintain documentation from media creation through destruction.

• Physical and Environmental Controls The vendor must employ physical and environmental policies and procedures that ensure that the service and delivery infrastructure are located in a physically secure and environmentally protected environment to ensure the confidentiality, integrity, and availability of Commonwealth data.

• Personnel Security

The vendor must employ policies and procedures to ensure that all staff that have access to systems that house, transmit, or process Commonwealth data have been appropriately vetted and have been through a background check at the time of hire and periodically thereafter.

• System and Communications Protections The vendor must employ physical and logical protection that protect system communications and communication media from unauthorized access and to ensure adequate physical protections from damage.

SECTION 5 – PROCUREMENT REQUIREMENTS AND INSTRUCTIONS

5.1 Procurement Requirements

Procurement requirements are listed under “Procurement Laws, Preference, Regulations and Policies” and “Response to Solicitation” located on the eProcurement Web page at https://finance.ky.gov/eProcurement/Pages/procurement-laws-regulations-and-policies.aspx and https://finance.ky.gov/eProcurement/Pages/doing-business-with-the-commonwealth.aspx respectively. The vendor must comply with all applicable statutes, regulations and policies related to this procurement.

5.2 Access to Solicitation, RFP, and Addenda

The Commonwealth wants each prospective vendor to have full and complete information on which to base a proposal response. Only information presented or referred to in this RFP and any additional written information that is supplied by the Commonwealth Buyer shall be used by vendors in preparing the response.

The solicitation, addenda, and attachments shall be posted to the Kentucky Vendor Self Service link at https://vss.ky.gov

It is not necessary to register to access the solicitation. Unregistered vendors can access solicitations by clicking on public access.

In the event of any conflict or variation between the solicitation or modification as issued by the Commonwealth and the vendor’s response, the version as issued shall prevail.

5.3 RFP Terminology

For the purpose of this RFP, the following terms may be used interchangeably:

o Proposer, Offeror, Contractor, Provider, or Vendor o Commonwealth Buyer, Buyer, Purchaser, or Contract Officer o RFP, Solicitation, or Procurement o Bid, Proposal, or Offer https://finance.ky.gov/eProcurement/Pages/procurement-laws-regulations-and-policies.aspx https://finance.ky.gov/eProcurement/Pages/procurement-laws-regulations-and-policies.aspx https://finance.ky.gov/eProcurement/Pages/doing-business-with-the-commonwealth.aspx https://finance.ky.gov/eProcurement/Pages/doing-business-with-the-commonwealth.aspx https://vss.ky.gov/ o Commonwealth of Kentucky, Commonwealth, or State, Agency, Commonwealth Office of Technology (COT) o Fiscal Year will be defined as the Commonwealth fiscal year: July 1 through June 30 o Biennium will be defined as the Commonwealth biennium: July 1 of each even numbered year through June 30 of the next even numbered year o Requirements that include the words “Shall”, “Will”, “Must” indicate a mandatory requirement o Mandatory Requirement means a condition set out in the specifications or statement of work that must be met without exception.”

5.4 Restrictions on Communications

The Commonwealth Buyer named on the Cover Sheet of this RFP shall be the sole point of contact throughout the procurement process. All communications, oral and written (regular, express, or electronic mail,), concerning this procurement shall be addressed to the Buyer.

For violation of this provision, the Commonwealth shall reserve the right to disqualify the vendors’ proposal response.

5.5 Confidentiality of Contract Terms

The contractor and the Commonwealth agree that all information communicated between them before the effective date of the contract shall be received in strict confidence and shall not be necessarily disclosed by the receiving party, its agents, or employees without prior written consent of the other party. Such material will be kept confidential subject to Commonwealth and Federal public information disclosure laws.

Upon signing of the contract by all parties, terms of the contract become available to the public, pursuant to the provisions of the Kentucky Revised Statutes.

The contractor shall have an appropriate agreement with its subcontractors extending these confidentiality requirements to all subcontractors’ employees.

5.6 Written Questions Regarding this RFP

Vendors are encouraged to submit written questions pursuant to Section 1.1 of this RFP. Written questions shall be submitted to the Commonwealth Buyer via email at Dianne.Lee@ky.gov . Vendors should submit questions on Attachment D Vendors Question Form. No questions shall be accepted after the date(s) listed in Section 1.1 unless the question(s) is considered material to the procurement.

The Commonwealth shall respond to salient questions in writing by issuing an addendum to the solicitation. The addendum shall be posted to the Kentucky Vendor Self Service site.

5.7 Vendor Response and Proprietary Information

mailto:Dianne.Lee@ky.gov

The RFP specifies the format, required information, and general content of proposals submitted in response to the RFP. The Finance and Administration Cabinet will not disclose any portions of the proposals prior to Contract Award to anyone outside the Finance and Administration Cabinet, representatives of the agency for whose benefit the contract is proposed, representatives of the Federal Government, if required, and the members of the evaluation committees. After a contract is awarded in whole or in part, the Commonwealth shall have the right to duplicate, use, or disclose all proposal data submitted by vendors in response to this RFP as a matter of public record.

Although the Commonwealth recognizes the vendor's possible interest in preserving selected data which may be part of a proposal, the Commonwealth must treat such information as provided by the Kentucky Open Records Act, KRS

61.870 et sequitur.

Informational areas which normally might be considered proprietary shall be limited to individual personnel data, customer references, selected financial data, formulae, and financial audits which, if disclosed, would permit an unfair advantage to competitors. If a proposal contains information in these areas that a vendor declares proprietary in nature and not available for public disclosure, the vendor should declare in the Transmittal Letter [see Section 6.7 (A)] the inclusion of proprietary information and shall noticeably label as proprietary each file containing such information. Proprietary information shall be submitted separately and identified as “Proprietary Data”. Proposals containing information declared by the vendor to be proprietary, either in whole or in part, outside the areas listed above may be deemed non-responsive to the RFP and may be rejected.

5.8 Notification of Award of Contract

The procurement process will provide for the evaluation of proposals and selection of the successful proposal in accordance with State law and regulations. KRS Chapter 45A of the Kentucky Model Procurement Code provides the regulatory framework for the procurement of services by State agencies.

All applicable statutes, regulations, policies and requirements shall become a part of an award as well as the Information Technology requirements.

For additional award information, vendors may email the Commonwealth Buyer.

5.9 Protest

Pursuant to KRS 45A.285, the Secretary of the Finance and Administration Cabinet, or his designee, shall have authority to determine protests and other controversies of actual or prospective offerors in connection with the solicitations or selection for award of a contract.

Any actual or prospective offeror or contractor, who is aggrieved in connection with solicitation or selection for award of a contract, may a file protest with the Secretary of the Finance and Administration Cabinet. A protest or notice of other controversy must be filed promptly and in any event within two (2) calendar weeks after such aggrieved person knows or should have known of the facts giving rise thereto. All protests or notices of other controversies must be in writing and shall be addressed and mailed to:

Holly M. Johnson, Secretary

COMMONWEALTH OF KENTUCKY

FINANCE AND ADMINISTRATION CABINET

200 MERO STREET, 5TH FLOOR

FRANKFORT, KY 40622

The Secretary of Finance and Administration Cabinet shall promptly issue a decision in writing. A copy of that decision shall be mailed or otherwise furnished to the aggrieved party and shall state the reasons for the action taken.

The decision by the Secretary of the Finance and Administration Cabinet shall be final and conclusive.

5.10 Vendor Notification – Ineligible for Award

The Commonwealth will not consider or evaluate any proposal submitted by a vendor when the vendor, the vendor’s employees or agents, had any involvement, contribution or participation in the development, preparation or review of this RFP prior to its issuance. The vendors proposal will be deemed ineligible for award.

5.11 Past Vendor Performance

Past vendor performance may be considered in the award of this Contract.

Vendors with a record of poor performance in the last twelve (12) months may be found non-responsible and ineligible for award.

SECTION 6 – PROPOSAL SUBMISSION

6.1 Disposition of Proposals

All proposals become the property of the Commonwealth of Kentucky. The successful proposal shall be incorporated into the resulting contract by reference.

Disposal of unsuccessful proposals shall be at the discretion of the Commonwealth Buyer.

6.2 Rules for Withdrawal of Proposals

Prior to the date specified for receipt of offers, a submitted proposal may be withdrawn by electronic or written notice by submitting a signed written request for its withdrawal to the Commonwealth Buyer.

6.3 Commonwealth’s Right to Use Proposal Ideas

The Commonwealth of Kentucky shall have the right to use all system ideas, or adaptations of those ideas, contained in any proposals received in response to the RFP. Selection or rejection of the proposal will not affect this right.

6.4 Submission of RFP Response

Each qualified offeror shall submit only one (1) proposal. Alternate proposals shall not be allowed. Failure to submit as specified shall result in a non-responsive proposal.

Acknowledgment of Addenda It is the vendor's responsibility to check the web site for any modifications to this solicitation.

Failure to specifically acknowledge addenda with submission will not excuse the vendor from adhering to all changes to the requirements of the solicitation set forth therein nor provide justification for any pricing changes.

6.5 Electronic Proposal Submission

Proposals shall be received by electronic submission in the eProcurement system.

An electronic proposal shall be authorized by the proper agent of the firm by the act of submitting it electronically through the eProcurement system.

Proposal information MUST be completed online. Response must contain all required information for the Solicitation. All bidders MUST be registered in the Commonwealth eProcurement System via the Vendor Self Service System at https://vss.ky.gov

Allow 24 – 48 hours to complete Vendor Registration. Vendors must be logged in to their Vendor Self Service (VSS) account in order to submit a response. Registrations completed the day of bid closing must be completed by the Vendor in the VSS portal. The Customer Resource Center is not able to complete registrations and activate accounts on the same day. Closing dates will not be extended for Vendors not registered by the date/time of the bid closing.

Vendor Self Service Registration Guides are provided at https://vss.ky.gov.

All bidders are cautioned to begin their electronic submission in sufficient time to complete before the closing date and time. Delays due to technical difficulties or document upload impediments shall not be justification for acceptance of a late bid or proposal. Vendor attention to this advisory is encouraged. If you need assistance, please contact the Customer Resource Center (CRC) by email at Finance.CRCGroup@ky.gov or phone 502-564-9641 or toll-free 877-973-HELP (4357).

Proposals shall be submitted in three (3) parts: The Technical Proposal, the Cost Proposal, and Proprietary Information. Each part should consist of one document https://vss.ky.gov/ https://vss.ky.gov/ mailto:Finance.CRCGroup@ky.gov attachment. Do not submit multiple document attachments as Technical, Cost or Proprietary. All files shall be labeled accordingly. Attachments may not exceed

65,000 KB.

Proposals submitted online must be in an “Accepted” status and shall be assigned a date and time stamp from the eProcurement system at the time of final acceptance and formal submission by the vendor. The system will not allow submission of an online proposal after the published date and time for closing.

A proposal may be modified or withdrawn by electronic or written notice ONLY if received prior to the bid closing date and time. An electronic offer may be modified by applying the appropriate electronic signature and following the procedure in the state’s eProcurement signature.

6.6 Format of Response

A. Proposals shall be submitted in three (3) parts: the Technical Proposal, the Cost Proposal, and Proprietary Information. Each part should consist of one document. Do not submit multiple documents as Technical, Cost or Proprietary.

a. The Technical Proposal should be submitted on one (1) document marked Technical (in Microsoft Word, Microsoft Excel or PDF format ONLY). Do not include embedded documents, hyperlinks or hyperlinks to videos. The document should be named in the following manner: Technical – Name of offeror RFP 758 2500000347

b. The Cost Proposal should be submitted on one (1) document marked Cost (in Microsoft Word, Microsoft Excel or PDF format ONLY). Do not include embedded documents, hyperlinks or hyperlinks to videos. The document should be named in the following manner: Cost – Name of offeror RFP 758 2500000347

c. Any Proprietary Information shall be submitted on one (1) document marked Proprietary (in Microsoft Word, Microsoft Excel or PDF format ONLY). Do not include embedded documents, hyperlinks or hyperlinks to videos. The document should be named in the following manner: Proprietary – Name of offeror RFP 758 2500000347

Pricing shall only be provided in the Cost Proposal. DO NOT SUBMIT

ANY PRICING INFORMATION IN THE TECHNICAL PROPOSAL.

All submitted Technical and Cost Proposals shall remain valid for a minimum of six (6) months after the proposal due date.

6.7 Technical Proposal Content

A. Transmittal Letter The transmittal letter shall be on the vendor’s letterhead and signed by an agent authorized to bind the vendor. The transmittal letter should include the following:

i. A statement that deviations are included, if applicable. Proposed deviations must be outlined in the transmittal letter. Any deviation from the provisions of the solicitation must be specifically identified by the vendor in its proposal, which if successful, shall become part of the contract. Such deviations shall not be in conflict with the basic nature of this solicitation. The Commonwealth reserves the right to reject any and/or all deviations in whole or in part.

ii. A statement that, if awarded a contract as a result of this solicitation, the vendor shall comply in full with all requirements of the Kentucky Civil Rights Act, and shall submit all data required by KRS 45.560 to 45.640;

iii. A statement pursuant to KRS 11A.040 that the vendor has not knowingly violated any provisions of the Executive Branch Code of Ethics;

iv. A statement of that the vendor is in compliance with Prohibitions of Certain Conflicts of Interest;

v. A statement of certification in accordance with Federal Acquisition Regulation 52.209-5, Certification Regarding Debarment, Suspension, and Proposed Debarment that to the best of its knowledge and belief, the vendor and/or its principals is (are) not presently debarred, suspended, proposed for debarment, or declared ineligible for the award of contracts by any State or Federal agency.

vi. The name, address, telephone number, and email address of the contact person for this RFP.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .