About this file

This is a Request for Information (RFI) from the Department of State's Bureau of Diplomatic Technology seeking information about industry capabilities to provide an integrated suite of COTS software solutions for enterprise desktop virtualization, application virtualization, and secure remote access application delivery platform. The Department requires a solution to support over 300 sites and 275 missions worldwide.

The RFI requires vendors to demonstrate capabilities including: FIPS 140-2/140-3 certification, compliance with CISA BOD 22-01 and EO 14028, DoD Impact Level 6 certification, FedRAMP High certification, Section 508 compliance, and ability to provide 99.999% uptime. Key technical requirements include support for on-premises and hybrid cloud architectures, edge computing capabilities, robust reporting tools, USB redirection support, and secure remote access with SSL VPN and IPsec VPN protocols. Responses are due by February 21, 2025 at 3:00pm ET, with questions due by February 11, 2025. Vendors must provide past performance examples from federal agencies within the last 5 years demonstrating experience with similar scope and complexity. The response must follow specific formatting requirements with page limits of 1 page for Section 1 (Company Information), 18 pages for Section 2 (Functional Requirements), and 5 pages for Section 3 (Past Performance).

View the file

Other files for this federal contract opportunity

Other files attached to ENTERPRISE DESKTOP VIRTUALIZATION, APPLICATION VIRTUALIZATION, AND SECURE REMOTE ACCESS APPLICATION DELIVERY PLATFORM, newest first.
File Type Posted
Attachement 1-C-SCRM Questionnaire.xlsx XLSX spreadsheet
Attachment 2-DOS Secure Software Development Attestation Form.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SENSITIVE BUT UNCLASSIFIED

U.S. DEPARTMENT OF STATE

BUREAU OF DIPLOMATIC TECHNOLOGY (DT)

OFFICE OF INFORMATION TECHNOLOGY ACQUISITIONS (ITA)

REQUEST FOR INFORMATION (RFI)

for

ENTERPRISE DESKTOP VIRTUALIZATION, APPLICATION VIRTUALIZATION, AND

SECURE REMOTE ACCESS APPLICATION DELIVERY PLATFORM

PART 1: REQUEST FOR INFORMATION BACKGROUND AND OBJECTIVES

1.0 PURPOSE

This Request for Information (RFI) is issued as market research to determine industry’s capabilities to provide an integrated suite of commercial-off-the-shelf (COTS) software solutions to include an enterprise-grade, desktop and application virtualization that will support numerous Department missions and business processes.

The Government does not commit to award a contract on the basis of this RFI or reimburse any costs associated with the preparation of responses. This RFI is issued solely for information and planning purposes and does not constitute a solicitation. All information received in response to this RFI that is marked “Proprietary” will be handled accordingly. Responses to the RFI will not be returned. In accordance with FAR 15.201(e), responses to this RFI are not offers and cannot be accepted by the Government to form a binding contract.

Responses to this RFI will assist the Department in determining the potential level of interest, competition adequacy, and technical capabilities of commercial vendors to provide the required products and/or services. The Government does not guarantee any action beyond this RFI.

2.0 BACKGROUND

The Department's mission is to advance the interests of the American people, their safety, and economic prosperity by leading America’s foreign policy through diplomacy, advocacy, and assistance. The mission of the Bureau of Diplomatic Technology (DT) is to rapidly and securely deliver, anytime and anywhere, the knowledge resources and Information Technology (IT) services needed to support the over 300 sites and 275 missions it services worldwide.

DT is seeking input from industry regarding their capability to provide market-leading solutions capable of meeting the full breadth of functional requirements outlined in this RFI. The Department requires access to a platform that is compliant with current Federal security requirements, is easy to use, flexible, scalable, customizable, and configurable to meet specific Department requirements as further detailed below.

3.0 REQUEST FOR INFORMATION OVERVIEW

As further detailed in Section 4, the Department is seeking to identify capable and interested partners able to provide the products and/or services required to meet the full range of functional capabilities outlined in this RFI. Viable partners should have demonstrated experience deploying the solutions and delivering the ongoing support required to maintain, expand, and upgrade the solution over time for an organization of similar size, global scope, and mission complexity as the Department.

Information requested in this RFI includes the following categories:

Company Information (Section 1) - Identification of interested vendors, socio-economic status, and potential acquisition vehicles to inform the Department’s potential acquisition strategy options.

Capability Assessment Against Functional Requirements (Section 2) - Description of vendor’s proposed technical solution and ability to fully meet all stated functional requirements.

Past Experience (Section 3) - Past project example(s) demonstrating vendor’s experience implementing their proposed solution to address the needs of an organization of similar size, global scope, and mission complexity to the Department.

4.0 SUBMISSION INSTRUCTIONS

All written responses should be submitted in Microsoft compatible formats (e.g., Word) or PDF.

Responses must use 12-point font and 1-inch margins, including all text, tables, and graphics. Additional attachments, brochures, or other marketing materials are not requested and will not be considered as part of the response. Response page limit(s) by section are noted below.

• Section 1 - 1 page

• Section 2 - 18 pages

• Section 3 - 5 pages

Please submit all materials to Andrew Rothstein at RothsteinAT@state.gov no later than Thursday, February 21, 2025 at 3:00pm Eastern Time.

The Government will not accept questions after Tuesday, February 11, 2025 at 3:00PM, Eastern Time. Please submit questions to RothsteinAT@state.gov.

The Government will post the questions and responses with sufficient time for contractors to complete their SSN responses.

Please be advised that all submissions become Government property and will not be returned.

UNDER NO CIRCUMSTANCES SHOULD ANY RESPONDENT CONTACT ANY

DEPARTMENT PERSONNEL REGARDING THIS NOTICE.

mailto:RothsteinAT@state.gov mailto:RothsteinAT@state.gov

PART 2: REQUESTED INFORMATION

Respondents are asked to provide the information requested below in accordance with the instructions outlined in Part 1, Section 4.0 above.

Section 1 - Company Information

Please provide the following details regarding your organization:

1. Company name.

2. Company’s point of contact (POC) name.

3. Company’s point of contact (POC) phone number.

4. Company’s point of contact (POC) email address.

5. Company’s URL/web address.

6. Company’s Cage Code.

7. Company’s UEI Number.

8. Company Federal socioeconomic classification(s), if any, based on North American Industry Classification (NAICS) Code that applies to the proposed solution.

9. List GSA schedule, Government wide acquisition contracts (GWACs), or other federal IDIQs or contracts your company holds that are accessible by the Department and where the full proposed solution can be procured, including corresponding schedule number/or contract number.

Section 2 - Functional Requirements Assessment

The Department’s functional requirements for the solution are outlined below.

Respondents are asked to provide a structured response that meets the following format requirements:

a) Response should be structured and annotated to clearly map the detailed description of the proposed solution’s capabilities to the numbered requirements captured in the sections below. Responses should clearly map to the information detailed in the requirements below.

b) Response narrative content should provide sufficient details regarding the proposed solution’s specific technical capabilities to demonstrate that the solution is capable of fully satisfying requirements.

2.1 Mandatory Requirements

The following qualifications and capabilities are mandatory requirements for any potential solutions addressing the needs outlined in this notice. Vendors must assess these requirements carefully, and fully describe their ability to meet them:

a. The solution should provide commercially proven, enterprise-grade consumer-off-the-shelf (COTS) products (no custom-built solutions) with demonstrated experience successfully deploying and operating the solution.

b. The solution should be FIPS 140-2/140-3 (Federal Information Processing Standard) certified. Please specify the extent to which the solution is FIPS 140-2/140-3 certified.

c. The solution should support the Department’s cybersecurity objectives through vendor neutral automation of the systems patching process to comply with the CISA patching Mandate Binding Operational Directive 22- 01 CISA (BOD 22-01) and Presidential Executive Order 14028 for Cybersecurity, Zero Trust and Secure Software Pipeline (White House EO 14028). Provide details regarding solution functionality focused on helping the Department meet these federal directives.

d. The solution should offer a cloud computing platform that is able to support the full spectrum of Intelligence Community security levels having obtained Department of Defense (DoD) Impact Level 6 (IL6) certification for storage and processing of classified information up to the top-secret level.

e. The solution should be compliant with Federal Information Security Modernization Act (FISMA) security standards and have Federal Risk and Authorization Management Program (FedRAMP) certification at the High Impact Level.

f. The solution should be fully compliant with the requirements of Section 508 of the Rehabilitation Act of 1973, as amended, and vendor should be able to provide copies of the VPATs (Voluntary Product Accessibility Template) supporting such compliance.

g. The solution should comply with the Department’s Cybersecurity Supply Chain Risk Management (C-SCRM) policy.

o Please review Attachments 1 & 2 and note whether your company is able to provide the requested information and attestations for your proposed solution.

h. The solution should be able to support on-prem and hybrid architecture, including multi-cloud architectures.

i. The solution should provide robust out of box reporting and data visualization tools for real time reporting, historical reporting, trend analysis that cover areas such as system performance, user activity, system activity, log review, etc.

j. The solution should support the ability to manage and isolate application launches to maximize available system resources.

k. The solution should support edge computing to enable extension of applications to remote or distributed locations while maintaining performance and security. Provide details of the solution’s capabilities in edge computing performance and security.

l. The solution should support the ability to prioritize Quality of Service (QoS) to optimize for voice and video transmissions. The solution should provide details on its capability to manage data traffic and data packets to prioritize high-quality voice and video data over other types of network traffic.

m. The solution should provide USB redirection and peripheral support to virtual desktops.

2.2 Enterprise Desktop Virtualization Solution

The Department requires a commercially proven, enterprise-grade desktop virtualization solution to support a broad range of mission-critical applications and workloads across the Department. Specific requirements include:

a. The solution should ensure stability, reliability, flexibility, and high-performance across various on-premises and cloud environments. Provide details on the solution’s features that enable high performance and reliability across demanding workloads.

b. The solution should offer leading edge security capabilities across both cloud and on-prem environments. Provide details on the solution’s security features and capabilities that differentiate it from alternative solutions.

c. The solution should allow users to access their personal work desktop setup on government furnished equipment (GFE), personal (BYOD), and company owned business owned (COBO) devices from local or remote locations via MFA type solutions such as a One Time Password (e.g., RSA token), PIV Card, etc.

d. Explain whether the solution is compliant with DISA STIGs (Defense Information Systems Agency Security Technical Implementation Guides).

e. Explain if the solution offers automated desktop and application provisioning to accelerate user onboarding and streamline IT administration.

2.3 Enterprise Application Virtualization Solution

The Department requires robust application management capability to support the development, deployment, and management of applications across on-prem, cloud and edge environments.

a. The solution should support cloud-native application development and out-of-the-box integration with robust tools to build, deploy, and scale applications. Provide details of the solution’s capabilities in this area and specific tool sets able to seamlessly integrate with the solution.

b. The solution should enable management of both virtual machines (VMs) and containers on the same platform, allowing legacy applications and containerized applications to run alongside each other. Provide details on the solution’s capabilities to co-localize VMs and containers on a single platform.

c. The solution should support edge computing to enable extension of applications to remote or distributed locations while maintaining performance and security. Provide details of the solution’s capabilities in edge computing performance and security.

d. The solution should offer among its managed service options one or more offerings with FedRAMP High certification. Please elaborate on the solution’s ability to provide FedRAMP High managed service options.

e. The solution should meet National Institute of Standards and Technology (NIST) definitions of Cloud Computing as published in NIST Special Publication 800-145.

2.4 Secure Remote Access Application Delivery

The Department requires a solution that offers advanced load balancing, Secure Sockets Layer Virtual Private Network (SSL VPN) security, and application delivery services to support its complex organizational infrastructure. The Department is exploring potential solutions to optimize our application delivery and enhance security while ensuring high availability and scalability to our remote access solutions.

a. The solution must provide robust remote access capabilities, enabling secure and seamless connectivity for users regardless of their location or device. Explain how it supports a wide range of authentication methods, including domain username and password, RSA tokens, smart cards, and integration with enterprise multi-factor authentication solutions to ensure strong security.

o The remote access feature should provide secure Virtual Private Network (VPN) access, with support for both SSL VPN and Internet Protocol Security (IPsec) VPN protocols, allowing users to securely access corporate resources over public networks.

b. The solution must include features such as application-level tunneling, access control policies, and adaptive security measures to dynamically adjust security requirements based on user behavior, device health, and location. The solution should also ensure high availability and scalability to accommodate varying numbers of remote users while maintaining optimal performance.

c. The solution should offer load balancing, security, and optimization of application delivery. Capable of global and local load balancing, including support for multiple protocols (HTTP, HTTPS, TCP, UDP). Offers multiple sophisticated load balancing algorithms such as round-robin, least connection, and internet protocol (IP) hash to optimize traffic distribution across servers, ensuring high availability and performance.

d. The solution should enhance the performance of our existing enterprise remote access infrastructure by optimizing wide area network (WAN) efficiency, minimizing latency, and improving multimedia delivery, ensuring a seamless and responsive user experience across diverse network conditions.

e. The solution should provide end-to-end visibility into the performance of web applications and services. The solution offers powerful diagnostic tools and performance analytics that help IT teams to proactively manage application delivery, troubleshoot performance bottlenecks, and ensure a smooth end-user experience.

2.5 Reliability and Availability

a. The solution should ensure high availability (99.999% up time) and minimal downtime, ensuring that critical systems always remain operational. Please note the proposed solution’s typical service level agreements (SLAs) and performance metrics for high availability.

b. The solution should be able to support active backups and recovery with minimal or no data loss by committing to rapid recovery time agreements (e.g., committing to service level agreement with the Department for recovery time and recovery point objectives). Please note the proposed solution’s typical SLAs and performance metrics for rapid recovery.

c. The solution should implement disaster recovery solutions to ensure data integrity and availability in the event of system failures or disasters, including regular backups and failover mechanisms.

d. The solution must ensure high availability to maintain continuous service delivery and minimize downtime. It should support active-active and active-passive configurations with automatic failover capabilities, ensuring seamless traffic redirection in the event of hardware failures or network interruptions.

e. Explain how the solution provides real-time health checks and proactive monitoring to detect potential issues before they affect performance, enabling quick recovery.

f. The solution must offer redundancy for key components, including power supplies, network interfaces, and storage, to eliminate single points of failure. It should also be capable of scaling dynamically to accommodate increased traffic without compromising performance, ensuring that the solution remains resilient and reliable under varying load conditions.

2.6 Integration and Interoperability

a. The solution should ensure compatibility with existing systems and software platforms used across the Department’s global enterprise, enabling seamless integration and data exchange.

b. The solution should facilitate secure and efficient data exchange with other federal agencies, internal departments, and external stakeholders, supporting collaborative efforts and information sharing. Provide details on the solution’s capabilities in this area.

c. The solution should offer versatile deployment options, including on-premises, cloud, and hybrid models, with seamless integration into existing infrastructure. Explain how it supports a wide range of deployment configurations such as hardware appliances, virtual appliances, and cloud-based instances, all managed from a unified platform.

o Provide detail of the solution’s flexibility to scale effortlessly across both physical and virtual environments, eliminating the need for separate management tools and ensuring streamlined operations across diverse infrastructures.

2.7 Maintenance and Support

a. The solution should include access to vendor support for ongoing maintenance, updates, and troubleshooting, ensuring that issues can be resolved promptly and effectively. Please describe the support model for your solution and define what support is included with the solution verses support levels that require an additional cost.

b. The solution should provide tools for centralized management, tracking, ordering, renewing, and accounting for licenses and services for streamlining administrative processes and reducing overhead.

c. The solution should provide active monitoring and alerts for usage, storage, and additional attributes that could cause performance or availability issues of databases.

d. The solution should have capabilities that allow for automation of maintenance functions to drive potential cost savings on regular operations and maintenance costs.

e. The solution should offer production support, including phone support, with “US citizen on US soil 24/7 coverage” to support continuity of operations for the Department’s global footprint. Please note whether this level of coverage is included in the base platform at no added cost or is available at an additional cost as a separately priced item.

3.0 PAST PERFORMANCE

The Department is seeking a COTS solution that has a proven track record in the U.S. federal space with demonstrated experience supporting agencies of similar size, global scope, and mission complexity as the Department. Such experience is critical to ensure that the solution has been proven to be secure and reliable under the required IT security, data management, privacy and other federal regulations that govern information technology implementations within the federal environment.

Please provide the following information regarding your experience deploying your solution for federal customers.

3.1 Federal past performance (last five years only)

Please list all federal agencies where you have successfully deployed your solution in the last five years. For each experience noted, in no more than one paragraph, please provide:

a. Agency and organization name.

b. Period of Performance.

c. Solutions provided to the agency.

d. Point of Contact name, email, and phone the Department can contact.

3.2 Past performance description (no more than three projects)

For at least one, but not more than three, of the federal implementations provided in Section 3.1 above, please provide the detailed information requested below to further demonstrate relevant past experience.

a. Dollar value of contract (across full period of performance).

b. Period of performance dates.

c. Schedule, GWAC, or contract used for the requirement.

d. State whether your company was a prime or subcontractor.

e. Customer point of contact (Name, Title, Email, Phone) that the

Department may reach out to for more information.

f. Description of the scope of the work your company performed and its relevance and applicability to demonstrating your solution’s ability to deliver the full set of capabilities outlined in Section 2.

Disclaimer: This RFI Notice is for information gathering purposes only as a means to identify interested and capable sources that can provide a solution that fully meets all requirements outlined in Part 2 of this notice. The information provided in this Notice is subject to change and is not binding on the Government. The Department has not made a commitment to procure any of the items/services discussed, and release of this RFI should not be construed as such a commitment or as authorization to incur cost for which reimbursement would be required or sought.

The Department will not publicly disclose proprietary information obtained as a result of this RFI. To the full extent that it is protected by law and regulations, information identified by a respondent as Proprietary or Confidential will be kept confidential. All submissions become Government property and will not be returned.

File details come from the government source that posted it. Updated .