Experian JA_ 02172021.pdf

PDF 113 KB Posted

Attached to
Remote Identity Proofing (RIDP) Services Federal contract opportunity
Solicitation number
APP210532
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

About this file

This document is a justification for a sole source contract award. The Centers for Medicare and Medicaid Services requires remote identity proofing services from Experian to support its identity management efforts. Experian currently provides customized remote identity proofing services to CMS through a teaming agreement under an existing task order. The justification cites Experian as the only company that can meet CMS' requirements to provide the necessary services within the required timeframe due to its existing customizations and specialized experience supporting CMS applications. The proposed sole source contract would run from February 2021 to October 2025 and include identity proofing, authentication, fraud detection, and professional services supporting over 60 CMS applications.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JUSTIFICATION AND

FOR OTHER THAN FULL AND OPEN

COMPETITION

Acquisition Title: Remote Identity Proofing (RIDP) Services Sole-Source Procurement Agency: CMS Acquisition Year: 2021 Author:

2. Description of Action:

Nature

__X__ New Requirement ____ Follow-On Order ____ Modification of Existing Contract Number

Contract Type __X__ Firm-Fixed Price ____ Time and Materials ____ Cost Plus Fixed Fee (CPFF)

• ____ Term

• ____ Completion

____ Cost Plus Award Fee (CPAF) __X__ Other: __Labor Hour_________

Projected Cost / Price of contract (Base & All Options):

The total estimated value of the proposed sole source action (for modifications only): N/A Funding Source (s): Project Number 000787: OIT- Identity Management (IDM)

____: Basis for Approval (FAR 6.303-1(d)

__X__: Individual Basis

____: Class Basis

Name of Proposed Contractor(s): Experian Information Solutions, Inc.

Street Address: 475 Anton Blvd.

City, State, Zip: Costa Mesa, CA 92626

3. Description of Services or Supplies:

The purpose of this Justification is to procure Remote Identity Proofing (RIDP) subscriptions and professional commercial services. RIDP is the process of confirming the identity of an online user. Typically, people are asked a series of individually tailored questions based on data from credit bureaus and other sources generated automatically by the online system. These questions could only be answered correctly by individuals applying for benefits, reporting changes or otherwise using the service.

The key functionality CMS is procuring includes:

Providing/maintaining Level of Assurance 2 (LOA2) remote Identity Proofing based upon the Risk Management Handbook Volume III Standard 3.1, CMS Authentication Standards or its successor. The Risk Management Handbook may be accessed at:

https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information- Technology/InformationSecurity/Information-Security-Library (scroll down at this link until you see file/document “RMH Vol III Standard 3.1 Authentication” or its successor).

Providing/maintaining Level of Assurance 3 (LOA3) remote Identity Proofing based upon the Risk Management Handbook Volume III Standard 3.1, CMS Authentication Standards or its successor.

Providing/maintaining Experian Precise ID. Approximately 14,300,000 transactions per year.

Providing/maintaining Experian Knowledge IQ (KIQ).

Providing/maintaining Experian (customization added for CMS) Experian Knowledge IQ Select (KIQ-Select).

Providing/maintaining Experian (customization added for CMS) process to link the CMS online proofing and call center proofing sub-codes via Experian’s Fraud Archive Reporting System (FARS) so that when a user fails online proofing, the final outcome is updated based on the call center results.

Actively retaining transaction audit logs and provide auditing capabilities.

Testing services for CMS applications integrating with the Experian RIDP Services.

Presenting to CMS all data set types used in its identity proofing services. CMS shall have the option to restrict usage of any controversial public data sets for identity proofing services if deemed necessary.

Tracking and reporting usage data at the individual application level.

Maintaining Spanish Call Center interpretation services, as customized for CMS, supporting the Experian phone-based identity proofing. Handles roughly 19,000 phone-based calls per year.

Maintaining Limited English Proficiency (LEP) interpretation services, as customized for CMS, supporting the Experian phone-based identity proofing services. Handles roughly 4,000 phone-based calls per year.

o Interpretation services support approximately 202 languages (including but not limited to French, Navajo, Japanese, Arabic, Mandarin Chinese, Russian, Vietnamese, Cantonese, Korean and Portuguese) for CMS users requiring phone proofing.

Providing Experian Professional Services (PS) support to CMS applications integrating with the Experian RIDP services. Estimated at 2,000 labor hours per year.

Supporting CMS and other teams during audits, including but not limited to Security Impact Analyses (SIAs) and Adaptive Control Tests (ACTs).

The services would also require two Experian staff to travel to CMS for four Program Increment (PI) Planning sessions per year.

The anticipated periods of performance are:

Base Year (12 months): 02/04/2021 – 02/03/2022 Option Period 1 (12 months): 02/04/2022 – 02/03/2023 Option Period 2 (12 months): 02/04/2023 – 02/03/2024 Option Period 3 (12 months): 02/04/2024 – 02/03/2025

Option Period 4 (8 months): 02/04/2025 – 10/03/2025 Transition Out to a New Contractor (Optional – 4 months): 10/04/2025 – 02/03/2026

4. Authority and Rationale:

__X___: FAR 6.302-1: Only one responsible source and no other supplies or services will satisfy agency requirements, 41 U.S.C. 253(c)(1)

CMS requires the use of remote identity proofing (RIDP) services provided by Experian’s Precise ID solution, including related Experian Knowledge IQ authentication and scoring, and Professional Services support. As these products and services are only available from one source, CMS intends to procure these products and related services on a sole-source basis from Experian. CMS is procuring these products and services to support CMS’ Identity Management (IDM) efforts, which are currently being supported under the Enterprise Identity Management (EIDM) Operations and Maintenance (O&M) task order being performed by Chags Health Information Technology, LLC (C-HIT). Experian currently provides customized RIDP services to CMS via a teaming agreement with C-HIT under the EIDM O&M task order. The current period of this task order ends on March 7, 2021, at which time CMS will have a newly modernized cloud-based IDM platform that includes Experian Precise ID as the RIDP component. The Health Insurance Marketplace and other critical CMS systems also require uninterrupted RIDP services in order to continue to securely provide their essential services to the millions of CMS customers. This acquisition seeks to procure the RIDP services as a separate contract. Therefore, CMS will need to have the Experian RIDP solution readily available to support the IDM effort.

Federal guidelines mandate that CMS identity proof application system users who are requesting to access certain types of data to a specific level of assurance (LOA) that the person requesting the data is who they say they are. Thus, RIDP services are a key component of how CMS meets these federal mandates and achieves that level of assurance. Remote identity proofing involves two major steps: (1) resolution and (2) validation and verification. During the resolution step, CMS determines which specific identity an applicant is claiming when they first attempt to initiate a transaction, such as enrolling for federal benefits or services, remotely. CMS then electronically compares the applicant’s identifying information with electronic records maintained by Experian -functioning as a consumer reporting agency (CRA) - to determine (or “resolve”) which identity is being claimed. Then, Experian validates and verifies the information a user provides against Experian’s records and may present the user with questions based on that person’s credit profile, called out-of-wallet questions. The out-of-wallet questions and answers, including financial history, are strictly between that user and Experian; CMS does not see or store them. Experian is required by law to securely maintain this data for seven years.

CMS has over 60 applications (each with its own unique user base with varying demographics) utilizing Experian’s Precise ID and Knowledge IQ (KIQ) platforms for RIDP and several using CrossCore (Experian’s integrated digital identity and fraud risk platform). PreciseID is an identity proofing and fraud prevention platform providing resources that enable CMS applications to detect, avoid, and manage fraud activity. Originally, all CMS applications leveraging RIDP connected to PreciseID using an eXtensible Markup Language (XML) Application Programming Interface (API). New CMS applications connecting to Experian RIDP services do so via Experian’s CrossCore platform, which provides access to multiple Experian and non-Experian solutions (backing applications) through a single JavaScript Object Notation (JSON) API. CrossCore combines risk-based authentication, identity proofing, fraud detection, advanced workflow, and reporting capabilities into a single platform offering flexible decisioning orchestration and advanced analytics. PreciseID is just one of the backing applications supported by Experian’s CrossCore. The CrossCore JSON API provides a seamless path for CMS to add other capabilities and applications incorporated into its platform.

Over the last eight or more years, Experian has extensively customized these RIDP services platforms to support the varied requirements of these CMS systems and to work successfully within CMS’ unique ecosystem. These RIDP configurations were developed based on a CMS assessment of the requirements of the risk associated with each application. The customized services implemented to meet CMS’ special requirements include:

Experian Knowledge IQ Select (KIQ-Select):

o KIQ Select is an initiative from Experian that improves the chances of a CMS user getting identity proofed by increasing the pool of questions that can be presented when a user does not have enough information in the usual data sources to provide sufficient questions for the person to pass online proofing. Experian added a new data source for CMS and uses it in this case to provide a new set of questions for the purposes of identity proofing. Experian developed additional logic to access the new data source and changes to the workflow were implemented by Experian to present the new questions to CMS users when these specialized use cases are encountered.

Experian process to link the CMS online proofing and call center proofing sub-codes via Experian’s Fraud Archive Reporting System (FARS) so that when a user fails online proofing the final outcome returned to CMS is updated based on both the online and call center proofing results.

Spanish Call Center: 19,000 phone-based calls per year.

o Call Center support for Spanish speakers requiring phone proofing.

Limited English Proficiency (LEP) interpretation services: 4,000 phone-based calls per year.

o Interpretation services support approximately 202 languages for CMS users requiring phone proofing.

CMS’ customized Experian RIDP solution leverages Experian’s Precise ID platform, which is Kantara certified to provide identity proofing to National Institute of Standards and Testing (NIST) 800-63-2 at both LOA2 and LOA3. The Kantara Identity Assurance Accreditation and Certification Program of Kantara Initiative, Inc. assesses applicants against its strict criteria ensuring, among other things, alignment with the Office of Management and Budget (OMB) Memorandum M-04-04 (E-Authentication Guidance for Federal Agencies) and NIST 800-63 Levels of Assurance. Kantara then grants successful candidates of the program the right to use the Kantara Initiative Mark, a symbol of trustworthy identity and credential management services at specified assurance levels. Experian continues to be an industry leader, building a verified trust layer in Identity Services via a scalable component approach. This allows for innovation and industry partnerships that enable more trusted services, interoperability and efficiency for enterprise identity management solutions. Experian’s Kantara certified Precise ID solution can be configured both with and without the use of knowledge-based verification, and has been enhanced by Experian to support the new NIST 800-63-3 standards.

CMS uses Experian’s Precise ID LOA2 and LOA3 solutions, which include knowledge-based verification via a component known as Knowledge IQ (KIQ). Experian uses KIQ as part of an overall layered authentication strategy that also includes rigorous identity resolution, authoritative records checks on identity and account information, checks of key fraud attributes, and the use of identity risk scores (based on predictive analytics) that go above and beyond that which is required to meet NIST 800-63-2. Using Experian’s knowledge-based verification in such a layered authentication strategy reduces risk beyond use of an equivalent strategy without knowledge-based verification. Experian does not use knowledge-based verification in the context of an LOA2 or LOA3 strategy as the sole determinant to allow a positive authentication result. When knowledge-based verification is used for Identity Assurance Level 2 (IAL2), it is only used when necessary to support the verification of one piece of fair evidence - which is an acceptable use per the NIST guidance. Until such a time as CMS has determined an appropriate transition strategy from NIST 800-63-2 to NIST 800-63-3, an elimination of knowledge-based verification as part of the current layered authentication strategies would only increase the risk associated with RIDP.

The Experian products and related services have proven to be effective tools for increasing confidence in legitimate users of the CMS systems that use these RIDP services, including the Federally Facilitated Marketplace (FFM)/Health Insurance Marketplace. The RIDP strategies of critical CMS Marketplace applications like Secure Login System (SLS) and Data Services Hub (DSH) rely much more heavily on knowledge-based verification, while the Marketplace Enhanced Direct Enrollment (EDE) application, and CMS’ Enterprise Identity Management (EIDM) system, use LOA2, and LOA3 strategies utilizing a much more layered approach. Experian has unique knowledge of, and experience with, the intricacies of the varied CMS systems that rely on the Experian RIDP solution for user identity proofing.

Experian has also tailored and customized their RIDP solution to securely improve the pass rates for specific CMS customers, especially Health Insurance Marketplace users. Currently, each application decision strategy within Experian is customized for CMS to yield the highest pass rates that can be achieved securely, based on the community of users each application serves. As an example, the Health Insurance Marketplace decision strategies are less restrictive and yield the highest pass rates. Management wanted to prioritize pass rates and reduce friction for users shopping for health care.

Switching to a different RIDP services vendor and platform would greatly increase the risk to CMS in terms of the time required for a new vendor to customize their system to provide the RIDP Services Experian now provides to CMS, as well as the time and effort (all unbudgeted for) required for applications using the Experian RIDP Services to ensure their code works with the new solution. Having a new vendor who has to learn CMS’ requirements and change their system to add the customized services Experian is already providing could very well mean that the Transition Out from Experian to this new vendor could stretch out to 12 months or more (unbudgeted for). The cost and schedule risk imposed by having to coordinate and test the change-over to a new vendor, by all the 60+ CMS applications currently utilizing Experian’s RIDP services, is extremely difficult to quantify would require coordination with the business owners and application maintainer teams for each of these systems. In addition, CMS would incur a significant cost burden, increased performance risk and increased schedule risk for a successful implementation of the new modernized IDM solution if all 60+ business applications had to update their systems to accommodate a new product for the required RIDP services.

CMS would need a new RIDP vendor to modify their solution to meet CMS’ varied and specialized identity proofing requirements. CMS has conducted market research, which resulted in a listing of seven (7) potential RIDP service vendors.

Further research indicated that other companies’ similar products are lacking the particular customized features to meet CMS’ needs. CMS also posted a pre-solicitation notice inviting interested vendors to provide a capability statement, proposal or quotation to demonstrate their capability to perform the RIDP requirements. None of the other six (6) potential RIDP service vendors responded to the pre-solicitation notice expressing written interest in the procurement or capability to perform the requirements. Therefore, it is unlikely that a new RIDP vendor would be willing or able to make the required changes to their solution to accommodate CMS’ specialized requirements before the go-live date for the new IDM system.

Experian has already modified their RIDP solution to support CMS, greatly increasing the likelihood that the RIDP services being procured will effectively and efficiently meet CMS’ specialized identity proofing requirements within the timeframe required. This also reduces the risk of encountering a negative user experience for existing customers and users. Experian’s knowledge of CMS’ unique requirements, the customizations Experian has made to their solution over the last eight years to support CMS, and Experian’s robust pathway for transition from NIST 800-63-2 to NIST 800-63-3, make Experian the only vendor offering CMS a proven solution with the least technological, cost, and schedule risk for maintaining the RIDP services relied upon by critical CMS applications. Therefore, Experian is the only responsible source that can provide the required products and services at a level of quality that will satisfy our requirements.

___: FAR 6.302-2: Unusual and compelling urgency, 41 U.S.C.253(c)(2)

___: FAR 6.302-5: Authorized or Required by Statute, 41 U.S.C.253(c)(5) ____: Other (See FAR Subpart 6.3 for additional authority):

5. Bridge Contracts:

N/A - This procurement is not a bridge contract.

6. Actions to Increase Competition:

As required by FAR Subpart 5.2, the CO published a notice of this proposed contract action to the Government wide Point of Entry (GPE) at https://www.fbo.gov (Contract Opportunities) on September 22, 2020. This pre-solicitation notice described the overall scope of the work, along with the key functionality needed to perform the RIDP requirements. The notice also indicated our intent to award a sole-source contract to Experian using non-competitive procedures under the authority of 41 U.S.C. 253 (c)(1) and FAR Subpart 6.302-1: Only one responsible source and no other supplies or services will satisfy agency requirements. However, pursuant to FAR 5.207(c)(16)(ii), the notice stated that all responsible sources may submit a capability statement, proposal or quotation, which shall be considered by the agency. Since this is an acquisition of commercial items, CMS allowed vendors 15 days to respond in writing as to their interest in and capability to perform the requirements. Prior to the closing date of the presolicitation notice, CMS received three inquiries asking for general information about the requirements, such as the anticipated contract length and start date, the scope of the work, and contractor requirements. All of this information was contained in the notice; therefore, the Contracting Officer (CO) and Contract Specialist (CS) responded to these requests and referred these vendors back to the notice for additional details. Prior to the closing date, CMS also received a fourth inquiry asking if this was a follow-on or new requirement. As requested, the CO and CS provided this vendor with identifying information for the current contract and task order, noting that the RIDP services are a piece of that effort. The four vendors that submitted inquiries are listed below in Section 10 and none of these companies provided a capability statement, proposal or quotation in response to the pre-solicitation notice. Prior to the closing date, CMS received no capability statements, proposals or quotations for these requirements from any other source and no other sources expressed interest in response to the notice.

7. Market Research:

The Government Accountability Office (GAO) report “Data Protection: Federal Agencies Need to Strengthen Online Identity Verification Process published May 17, 2019 recommended that the “Administrator of the Centers for Medicare and Medicaid Services should develop a plan with time frames and milestones to discontinue knowledge-based verification” (https://www.gao.gov/products/GAO-19-288). Then the National Institute of Standards and Technology (NIST), in June 2017, published Special Publication 800-63-3 (https://pages.nist.gov/800-63-3/), outlining new identity management standards, which require secure and trusted digital credentials. This new set of guidelines provided technical requirements for federal agencies implementing digital identity services. The digital identity is a unique representation of the physical subject, or individual, in the online world, that is engaged in an online transaction.

NIST’s new credentialing guidelines replaced the previous SP 800-63-2 Level of Assurance (LOA2/3) requirements with NIST SP 800-63; the current guidance no longer uses a single composite assurance level for identification and authentication. The current LOA2 and LOA3 have now morphed into Identification Assurance Level 2 (IAL2), which is much more prescriptive and includes document verification, facial recognition and liveness checks. The foundation of the current RIDP process, Knowledge-based authentication (KBA), has the user answer questions regarding financial or other data which the RIDP Services provider has in their database and uses to make a determination as to whether or not the person answering the questions is who they claim to be. Large-scale data breaches have occurred which exposed a lot of American consumer KBA answers to bad actors. Under the new guidelines, NIST no longer accepts KBA as a method for completing online identity proofing. In the new NIST 800-63-A, IAL2 has moved away from KBA in favor of possession-based methods of authentication. The new NIST requirements also require strong identifiers such as driver’s licenses and passports to be paired with selfies to prevent criminals from using stolen documents to claim another person’s identity online.

The current NIST LOA guidelines offer multiple options to resolve an identity, however when CMS completes the on-going migration to the new IAL standard, the decision strategy will be limited to one option. After reviewing the new NIST requirements, ESSG quickly realized that the proposed RIDP changes in NIST 800-63-A are radical and could significantly affect the way CMS does business. However, the new NIST guidelines do empower an agency to develop a risk based alternative solution in the event that the prescriptive one is not feasible. ESSG/DIMES quickly tasked one of our contractors to do RIDP Market research to determine if solutions are available that conform to these new NIST 800-63-A requirements and GAO recommendations. The primary goal of this market research was to conduct an exhaustive search of the entire RIDP marketplace with a dual emphasis on market leaders and innovative approaches. This research ranked Experian as the #1 provider of RIDP services (out of the 28 RIDP providers surveyed) based on their size, RIDP market share, and level of investment in the RIDP service area. Experian was also listed as one of only two RIDP service providers that demonstrated good financial stability, product strength, NIST 800-63-3 conformance and product vision with regard to their Commercial Off-the-Shelf (COTS) RIDP solutions. The market research resulted in a listing of seven (7) potential RIDP service vendors.

Product Research was then conducted in order to identify products that may be able to actually conform to the new guidelines and address CMS’ unique requirements. This deeper dive into the product offerings of the remaining six (6) most capable product vendors concentrated on gathering information to address IAL2 compliance, pass rates, accuracy for Identity Document (ID) proofing, the technology stack for each product, vendor maturity, user experience and Help Desk support. NIST guidelines empower agencies to develop a risk based alternative solution in the event that the prescriptive one is not feasible and only Experian offered a risk based alternative to the standard and highly prescriptive IAL2 process.

As indicated in Section 6 above, a pre-solicitation notice posted on Contract Opportunities indicated our intent to contract with Experian on a sole-source basis. None of the other six (6) potential RIDP service vendors responded to the pre-solicitation notice expressing written interest in the procurement or capability to perform the requirements.

Overall, the market research has confirmed that Experian is a well-established RIDP services vendor with a robust product offering; it is a market leader and one of the top providers of remote identity verification services in the marketplace today. As previously stated, Experian’s identity proofing solution, PreciseID, is NIST 800-63-3 IAL2-conforming as certified by the Kantara Initiative. The Kantara Identity Assurance Accreditation and Certification Program of the Kantara Initiative Inc.

assesses applicants against its strict criteria ensuring, among other things, alignment with the Office of Management and Budget (OMB) Memorandum M-04-04 (E-Authentication Guidance for Federal Agencies) and NIST 800-63 Levels of Assurance (LOA) and grants successful candidates of the program the right to use the Kantara Initiative Mark, a symbol of trustworthy identity and credential management services at specified Assurance Levels.

Experian offers customizable workflow solutions that can be aligned with both NIST 800-63-3 standards and equivalent risk-based alternatives. Thus, Experian’s identity proofing solution provides a path forward for CMS when the new NIST 800-63 standards are incorporated into the CMS Acceptable Risk Safeguards (ARS). The company’s CrossCore platform offers a comprehensive set of abilities and workflows designed to meet the validation and verification requirements in line with the digital identity proofing standards under the Digital Identity Guidelines. The platform evaluates and validates information provided by those seeking system access by checking and verifying information provided; these checks include issued identity numbers, account numbers, and remotely provided identity documents.

In addition, the CMS Contracting Officer and Contract Specialist reached out to the General Services Administration (GSA) Contracting Officers for both of Experian’s GSA Schedules (GSA Schedule

70 and GSA Schedule 520) on April 21, 2020. After corresponding with the GSA Contracting Officers, the CMS CO determined it would not be feasible for CMS to pursue a procurement for the required Experian RIDP services using a GSA Schedule. CMS requires enhancements that are not currently offered on either of Experian’s GSA schedules. Also, Experian’s GSA Schedules do not have a specific Special Item Number (SIN) for Order-Level Materials (OLMs) and Experian’s enhancements would need to be added as OLMs. The GSA Contracting Officers confirmed without the OLM SIN, CMS could not procure the additional services using a GSA Schedule.

8. Procurement History:

Purchase order or contract number:

Contract #HHSM-500-2007-00020I/Task Order #HHSM-500-T00001 (SAIC/Leidos) Contract #HHSM-500-2017-00015I/Task Order #HHSM-500-T0001 (C-HIT) Was Action Competed? __X_Yes ____ No

Contract #HHSM-500-2007-00020I/Task Order #HHSM-500-T00002 (SAIC/Leidos) Was Action Competed? ___Yes _X__ No

CMS awarded the original task order for RIDP and Multi-Factor Authentication (MFA) services to SAIC/Leidos (HHSM-500-2007-00020I/HHSM-500-T00001) following a competition using CMS’ Enterprise Systems Development (ESD) Indefinite Delivery/Indefinite Quantity (IDIQ) contract vehicle. This task order had a period of performance of 01/31/2012 – 01/30/2017. Under this task order, Experian provided the required RIDP services as a subcontractor to SAIC/Leidos. Due to the time needed to resolve protests of the new CMS Strategic Partners Acquisition Readiness Contract (SPARC) IDIQ contract vehicle (the successor to the ESD contract vehicle), CMS issued a logical follow-on pursuant to FAR 16.505(b)(2)(i)(C) to SAIC/Leidos under Contract #HHSM-500-2007- 00020I/Task Order #HHSM-500-T00002. The period of performance for this logical follow-on was 01/31/2017 – 10/17/2017, with an additional extension issued through 12/31/2017 to allow a transition from SAIC/Leidos to a new contractor. Experian provided the RIDP services as subcontractor under this follow-on task order as well. CMS then conducted a competition under SPARC that combined the RIDP and MFA services with the Operations and Maintenance (O&M) of the Enterprise Identity Management (EIDM) system. CMS awarded this task order (HHSM-500- 2017-00015I/HHSM-500-T0001) to Chags Health Information Technology LLC (C-HIT) with a performance period of 09/08/2017 - 05/17/2022. Although C-HIT holds the task order under which the RIDP services are currently being performed, Experian currently provides the customized RIDP services to CMS via a teaming agreement with C-HIT under this task order.

9. Additional Information to support the justification

A sole source contract to Experian will greatly benefit CMS by allowing continuation of the existing Remote Identity Proofing (RIDP) services. Federal guidelines mandate that CMS identity proof application system users to a certain level of assurance who are requesting access to certain types of data. The Experian RIDP services are a key component of how CMS meets those federal mandates and achieves that level of assurance. Experian has customized its RIDP platforms to support the varied requirements of the CMS systems that currently use the Experian RIDP services, including the Federally Facilitated Marketplace (FFM/Health Insurance Marketplace) and over sixty other CMS systems. It would be very difficult and expensive for all these CMS systems to modify their applications to use a different RIDP service. This costly level of effort could not be completed within the timeframe required to re-compete the providing of these critical services due to the multitude of applications using the RIDP services and the timeframes required for each of these applications to budget for and then push these change requests through the various Change Control Boards and other approvals required (this could easily take a year or more). Each application would then need to schedule and execute the coding changes required. In addition, CMS would most likely need a new Commercial Off-the-Shelf (COTS) RIDP vendor to modify their system to meet CMS’ varied and specialized requirements. There is no way to be sure that a new COTS RIDP vendor would be willing to make changes to their system to accommodate CMS’ specialized requirements;

or that they would be able to do so within the short transition-in period of CMS Information Technology (IT) contracts (typically four months or less). Experian has already modified their RIDP services to support CMS, greatly reducing the risk to CMS that the RIDP product being procured will effectively and efficiently meet CMS’ specialized RIDP requirements.

10. Listing of the sources, if any, that expressed, in writing, an interest in the acquisition.

11. A statement of the actions, if any, the agency may take to remove or overcome any barriers to competition before any subsequent acquisition for the supplies or services required

Once the new IDM platform is operational and stable and all applications currently utilizing the Experian RIDP services have been successfully migrated over to the new IDM platform, then CMS can consider effective ways to eliminate, mitigate or minimize the risks identified above regarding transitioning to a different RIDP service provider. CMS will also continue to perform market research to monitor the capabilities of applicable remote identity proofing tools when conducting future procurements to make maximum practicable attempts to conduct competitive procurements for the RIDP services.

Approvals:

1. Program Office Certification: This is to certify that portions of this justification have been developed by the undersigned program office personnel, including supporting information and/or data verifying the Government’s minimum needs, schedule requirements and other rationale, which form the basis for this justification for other than full and open competition.

Contracting Officer Representative (COR) / Date

Program/Project Manager (P/PM) / Date

Best Value Determination. By my signature below, after review of the relevant documents, I have determined that the order subject to this Justification represents the best value for the Government as set forth in FAR 6.303-2(b)(7), and constitutes a fair and reasonable price. The basis for my determination is as follows:

The Independent Government Cost Estimate (IGCE) was created by the procurement team using both current and historical data regarding required transaction volumes and the types and numbers of labor hour support required. A Statement of Objectives (SOO) will be used to describe the work, which is for the current vendor to continue to provide the existing level of RIDP Services and assist CMS with ensuring these services are flexible and able to support changing government requirements (e.g. NIST 800-63 or its successor). The Technical Evaluation Panel (TEP) will evaluate the Performance Work Statement from Experian using the team’s knowledge of the current contract and transaction costs, as well as of the system and new standards on the horizon. The evaluation methodology to be used will be described in Section L (Instructions, Conditions, and Notices to Offerors or Respondents) of the solicitation.

As certified cost or pricing data will be required for this acquisition, the CO will use cost analysis to evaluate the reasonableness of individual cost elements. The CO will also use price analysis to verify that the overall price offered is fair and reasonable.

2. Contracting Officer Certification: This is to certify that the justification for the proposed acquisition has been reviewed and that to the best of my knowledge and belief, the information and/or data provided to support the rationale and recommendation for approval, is accurate and complete.

Contracting Officer / Date

Edward D. Custer -S Digitally signed by Edward D.

Custer -S Date: 2020.11.04 08:22:05 -05'00'

Jeffrey T. Cernik -S Digitally signed by Jeffrey T. Cernik -S Date: 2020.11.04 08:36:48 -05'00'

Dawn R. Wilkins -S Digitally signed by Dawn R.

Wilkins -S Date: 2020.11.04 08:50:13 -05'00'

3. OAGM Approvals

I hereby confirm the circumstances described above apply and approve the justification for other than full and open competition.

OAGM Division Director / Date

OAGM Group Director / Date

4. Head of Contracting Authority (HCA) Approval I hereby confirm the circumstances described above apply and approve the justification for other than full and open competition.

HCA Name / Date

5. CMS Competition Advocate (CA) Approval I hereby confirm the circumstances described above apply and approve the justification for other than full and open competition.

Name / Date

6. Senior Procurement Executive (SPE) Approval Based on the foregoing justification, I hereby approve the procurement of (state supplies/services being procured) onan other than full and open competition basis pursuant to the authority of (state the full statutory authority and FAR cite and title, consistent with paragraph 4, e.g. 41 U.S.C. 253(c)(1)), as implemented by FAR 6.302-1), subject to the availability of funds, and provided that the services herein described have otherwise been authorized for acquisition.

__________________________N/A_______________________ Name / Date

Andrew Mummert - S

Digitally signed by Andrew Mummert -S Date: 2020.11.04 15:20:16 -05'00'

Lyandra Emmanuel - S

Digitally signed by Lyandra Emmanuel -S Date: 2020.11.05 17:03:02 -05'00'

Derrick L. Heard -S Digitally signed by Derrick L.

Heard -S Date: 2020.11.09 18:30:46 -05'00'

Karen E.

Jackson -S

Digitally signed by Karen E.

Jackson -S Date: 2020.11.13 18:23:05 -05'00'

File details come from the government source that posted it. Updated .