Global Hardware-Request for Information.pdf
PDF 244 KB Posted
- Attached to
- Global Hardware Federal contract opportunity
- Solicitation number
- 19AQMM25B0123
About this file
This is a Request for Information (RFI) issued by the Department of State's Bureau of Diplomatic Technology (DT) seeking information about industry capabilities to provide commercial-off-the-shelf (COTS) hardware solutions for servers and storage to be deployed globally across hundreds of sites. The RFI covers four main hardware configurations: overseas prebuilt half-racks with Oracle RAC servers, domestic prebuilt full racks with hypervisor servers, datacenter converged hardware, and datacenter storage solutions ranging from 184TB to 2PB.
The required solutions must include silicon root of trust, NIST-certified cryptographic modules, U.S. government country of origin compliance, and 99.9999% high availability design. Vendors must provide 24/7 support with 24-hour replacement shipping, maintain a Top Secret Facility Clearance, and demonstrate past performance with federal agencies of similar size and scope. Responses are due by March 5, 2025 at 3:00 PM EST, with questions due by February 26, 2025. The RFI requires detailed responses across three sections: company information (1 page), functional requirements assessment (80 pages), and past performance (5 pages). This is for market research only and does not constitute a commitment to award.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions and Responses-Global Hardware-19AQMM25B0123-5 Pages.docx | DOCX document | |
| Attachment 2-DOS Secure Software Development Attestation Form.pdf | ||
| Attachement 1-C-SCRM Questionnaire.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SENSITIVE BUT UNCLASSIFIED
U.S. DEPARTMENT OF STATE
BUREAU OF DIPLOMATIC TECHNOLOGY (DT)
OFFICE OF INFORMATION TECHNOLOGY ACQUISITIONS (ITA)
REQUEST FOR INFORMATION (RFI)
for
GLOBAL HIGH AVAILABILITY SERVER AND STORAGE HARDWARE SOLUTIONS
PART 1: REQUEST FOR INFORMATION BACKGROUND AND OBJECTIVES
1.1 PURPOSE
This Request for Information (RFI) is issued as market research to determine industry’s capabilities to provide proven commercial-off-the-shelf (COTS) hardware solutions capable of delivering industry leading server and storage capabilities to be deployed globally to hundreds of sites. The solutions must provide a commercially proven platform with transferrable components to meet specific Department of State (“Department”) requirements and use cases. The solutions must also provide leading edge capability in the return merchandise authorization (RMA) process, only include hardware that implements cryptographic modules already certified by the National Institute of Standards and Technology (NIST) Cryptographic Module Validation Program, have silicon root of trust, and meet United States Government country of origin requirements.
Solution submittals must be backable by prepurchase proof of concept builds that may be evaluated by Department personnel at vendor facilities.
Additional specific capability requirements are enumerated in Part 2 below.
The Government does not commit to award a contract on the basis of this RFI or reimburse any costs associated with the preparation of responses. This RFI is issued solely for information and planning purposes and does not constitute a solicitation. All information received in response to this RFI that is marked “Proprietary” will be handled accordingly. Responses to the RFI will not be returned. In accordance with FAR 15.201(e), responses to this RFI are not offers and cannot be accepted by the Government to form a binding contract.
Responses to this RFI will assist the Department in determining the potential level of interest, competition adequacy, and technical capabilities of commercial vendors to provide the required products and/or services. The Government does not guarantee any action beyond this RFI.
1.2 BACKGROUND
The Department’s mission is to advance the interests of the American people, their safety, and economic prosperity by leading America’s foreign policy through diplomacy, advocacy, and assistance. The mission of the Bureau of Diplomatic Technology (DT) is to rapidly and securely deliver, anytime and anywhere, the knowledge resources and Information Technology (IT) services needed to support the over 300 sites and 275 missions it services worldwide. The mission of the Bureau of Consular Affairs (CA) is to protect the lives and serve the interests of U.S. citizens abroad, keep our country safe, and help foreign nationals connect with the U.S. by issuing visas to qualified visitors, workers, and immigrants.
Across the globe, we serve our fellow citizens during some of their most important moments and help U.S. citizens connect with the world by issuing millions of U.S. passports each year.
CA, with DT’s support, is seeking input from industry regarding their capability to provide market-leading solutions capable of meeting the full breadth of functional requirements outlined in this RFI. The Department requires access to a hardware solution that is compliant with current federal and Department security requirements, is easy to use, as well as a solution that is flexible, scalable, customizable, and configurable to meet specific Department hardware requirements as further detailed below.
1.3 RFI OVERVIEW
As further detailed in Part 2, the Department is seeking to identify capable and interested partners able to provide the products and/or services required to meet the full range of functional capabilities outlined in this RFI. Viable partners should have demonstrated experience deploying hardware solutions and delivering the ongoing support required to maintain, expand, and upgrade the solution over time for an organization of similar size, global scope, and mission complexity to the Department within the federal market.
Information requested in this RFI includes the following categories:
• Company Information (Section 1) – Identification of interested vendors, socio-economic status, and potential acquisition vehicles to inform the Department’s potential acquisition strategy options.
• Capability Assessment Against Functional Requirements (Section 2) – Description of vendor’s proposed technical solutions and ability to fully meet all stated functional requirements.
• Past Experience (Section 3) – Past project example(s) demonstrating vendor’s experience implementing their proposed solutions in the federal environment to address the needs of an organization of similar size, global scope, and mission complexity to the Department.
1.4 SUBMISSION INSTRUCTIONS
All written responses should be submitted in Microsoft compatible formats (e.g., Word) or PDF.
Responses must use 12-point font and 1-inch margins, including all text, tables, and graphics. Additional attachments such as data sheets providing additional technical details for proposed solutions may also be provided, if necessary, in addition to the page limits stated below. General brochures or other marketing materials not directly relevant to the stated requirements are not requested and will not be considered as part of the response. Response page limit(s) by section are noted below.
• Section 1 – 1 page
• Section 2 – 80 pages
• Section 3 – 5 pages
Please submit all materials to Andrew Rothstein at RothsteinAT@state.gov by Wednesday, March 5 #, 2025 at 3:00pm, Eastern Standard Time.
The Government will not accept questions after Wednesday, February 26, 2025 at 3:00 PM, Eastern Standard Time. Please submit questions to RothsteinAT@state.gov.
The Government will post the questions and responses on GSA E-buy with sufficient time for vendors to complete their RFI responses.
Please be advised that all submissions become Government property and will not be returned.
PART 2: REQUESTED INFORMATION
Vendors are asked to provide the information requested below in accordance with the instructions outlined in 1.4 above.
2.1 – COMPANY INFORMATION
Please provide the following details regarding your organization:
a. Company name
b. Company point of contact (POC) name
c. Company POC phone number
d. Company POC email address
e. Company URL/web address
f. Company Cage Code
g. Company UEI Number
h. Company business size in terms of revenue and number of employees
i. Company federal socioeconomic classification(s), if any, based on North American Industry Classification (NAICS) Code that applies to the proposed solution.
j. List GSA schedule, Government wide acquisition contracts (GWACs), or other federal IDIQs or contracts the vendor holds that are accessible by the Department and where the full proposed solution can be procured, including corresponding schedule number or contract number.
2.2 – FUNCTIONAL REQUIREMENTS ASSESSMENT
The Department’s functional requirements for the solution are outlined below.
Vendors are asked to provide a structured response that meets the following format requirements:
a) Response must be structured and annotated to clearly map the detailed description of the proposed solution’s capabilities to the numbered requirements captured in Section 2.2.1 – Section 2.2.5 below. Responses should clearly map to the information stated in the listed requirements below.
b) Response narrative content should provide sufficient details regarding the proposed solution’s specific technical capabilities to demonstrate that the solution is capable of fully satisfying stated requirements.
2.2.1 Mandatory Qualifications
The following qualifications and capabilities are mandatory requirements for any potential solutions addressing the needs outlined in this notice. Vendors must assess these requirements carefully and fully describe their ability to meet them.
Key requirements are as follows:
a. Solutions should be based on a commercially proven, industry-leading original equipment manufacturer (OEM) integrated hardware platform.
The Department is seeking only hardware solutions that have been successfully deployed at other federal agencies similar in size and global scope to the Department.
b. Solution submittal should include a complete parts breakdown list.
Component parts listing should align to datasheet at the level of serviceable or orderable parts. Examples of components include, but are not limited to, chassis, CPU, GPU, network card, memory, disk, power supply, blank, and cable.
c. Solution submittals should be backable by prepurchase proof of concept builds that may be evaluated by Department personnel at vendor facilities.
d. Solution submittal should identify functionality that requires licensing that is not covered in base purchase, if any.
e. Solution hardware should maintain commercial sale for the next three to five years.
f. Solution software and firmware should be supported for the next five years.
g. Vendor should direct ship and warranty all original hardware for no less than four years and should ship replacements within 24 hours of request for all components.
h. Vendor should provide direct support using a self-service support website and call center so that hardware technicians can initiate hardware replacements and service requests without delay 24 hours a day, 7 days a week.
i. Department tier 3 personnel should be able to open a service request immediately and directly.
ii. Department tier 3 personnel should be able to initiate warranty replacement and track delivery of replacement hardware.
iii. Vendor should acknowledge and agree that for overseas post requirements (Section 2.2.2) received hardware cannot be returned to vendor and only in limited and unique circumstances will vendor personnel be able to access equipment for which warranty replacements are requested.
iv. For domestic requirements (all other requirement sections), Vendor should acknowledge and agree that no storage components may be returned to vendor (“keep your drive support”) during the warranty service/replacement process.
i. All hardware should provide silicon root of trust and other security controls including Unified Extensible Firmware Interface (UEFI) secure boot or equivalence.
j. All hardware should meet United States Government country of origin requirements.
k. All hardware should support automated system recovery during a system failure.
l. All hardware should not require a warranty/service contract to download update packages or update firmware.
m. Manufacturers should maintain an up-to-date software/firmware repository and notify customers of discovered vulnerabilities. Notification should be provided immediately when software is added to the repository.
n. Submittals should provide Common Criteria Certification information for all components.
o. Hardware and software should include only components that are Federal Information Processing Standard (FIPS) Publication 140-3 certified, and submittal should include certification numbers for cryptographic modules for all hardware and software encryption components.
p. Select server hardware should be certified for Oracle Enterprise Linux (OEL) 8 and later, VMware ESXI 8 and later, or Microsoft Windows Server 2019 and later.
q. Software should support centralized management for a minimum of 2,000 devices, support management of hardware from multiple OEMs, and include details on power usage.
r. Software should integrate with third party systems for user account management such as CyberArk, Microsoft Active Directory, and Okta or support protocols such as Lightweight Directory Access Protocol (LDAP), Remote Authentication Dial-In User Service (RADIUS), Security Assertion Markup Language (SAML), and Open Authorization (OAuth).
s. Software should integrate with third party Secure Sockets Layer (SSL) certificate authority for certificate signing as well as import and export of certificates.
t. Software should integrate with third party monitoring via common protocols such as Simple Network Management Protocol (SNMP) and system logging protocol (Syslog).
u. Hardware for Sections 2.2.2 and 2.2.3 should be assembled before delivery.
The first unit should be made available for inspection by Department personnel before delivery.
v. Vendor should attest to being able to meet the following facility and personnel security requirements:
i. Currently holds an active Top Secret Facility Clearance (FCL)
ii. Capable of providing personnel cleared at the Secret level for all personnel handling Department software assets
iii. Capable of providing personnel able to achieve a Moderate Risk
Public Trust (MRPT) or higher clearance for all other personnel supporting the infrastructure refresh
w. The vendor should describe its ability to keep its software and product supply chains secure in accordance with NIST SP 800-35.
x. The vendor Solution should comply with the Department’s Cybersecurity Supply Chain Risk Management (C-SCRM) policy.
i. Please review Attachments 1 & 2 and state in your response whether your company is able to provide the requested information and attestations for your proposed solution.
2.2.2 Overseas Units - Complete Prebuilt Half-Rack
The Department requires a prebuilt hardware solution that can be shipped to any country worldwide with a bare minimum of onsite setup. General solution make up is a top of rack switch, Keyboard Video Mouse (KVM) console, dual node Oracle Real Application Clusters (RAC) servers with directly connected storage array network, a single backup server, and redundant (uninterruptible power supply) UPS.
a. Pre-imaged media should be boxed as a separate shipment from rack shipment.
b. Pre-imaged media should be labeled for onsite technician reinstallation.
c. All cables and ports should be labeled for visual aid to assist onsite technician during trouble shooting.
d. Rack switch should be pre-configured with a backup management connection to one of the servers.
e. Rack should be crated, tamper resistant, include proper handling indicators, and use heat treated pallets (for customs entry).
f. Current build Oracle RAC Servers include the following components and specifications. The vendor should propose a solution meeting these requirements, but must also be capable of providing future model upgrades as market capabilities and the Department’s requirements evolve for core components:
i. OEL 8 and 9 certifications
ii. Dual Port 1GbE LOM (1 per server)
iii. Dual Port 10GbE BASE-T Adapter (1 per server)
iv. Quad Port 10GbE Base-T Adapter (1 per server)
v. Dual, Hot Plug, Power Supply (1+1) Redundant 1400W (1 per server)
vi. CPU Intel Xeon Gold 6426Y (2 per server)
vii. Memory 32GB type RDIMM (8 per server)
viii. Disk 1.6TB type SSD SAS (14 per server)
ix. Support remote management
x. Support Redundant Array of Independent Drives (RAID) - various
RAID 10 disk groups will be utilized
g. The current build for the Backup Server includes the following components and specifications. The Vendor should propose a solution meeting these requirements, but must also be capable of providing future model upgrades as market capabilities and the Department requirements evolve for the core components:
i. VMware ESXI 7 certification
ii. Dual Port 1GbE LOM (1 per server)
iii. Dual Port 10GbE BASE-T Adapter (1 per server)
iv. Quad Port 10GbE Base-T Adapter (1 per server)
v. Dual, Hot Plug, Power Supply (1+1) Redundant 1400W (1 per server)
vi. CPU Intel Xeon Gold 6426Y (2 per server)
vii. Memory 32GB type RDIMM (8 per server)
viii. Disk 1.6TB type SSD SAS (16 per server)
ix. Support remote management
x. Support Redundant Array of Independent Drives (RAID) - various
RAID 10 disk groups will be utilized
h. The current build for the Storage Server includes the following components and specifications. The vendor should propose a solution meeting these requirements, but must also be capable of providing future model upgrades as market capabilities and the Department’s requirements evolve for core components:
i. 12Gb SAS 8 Port Dual Controller
ii. Disk 1.6TB type SSD SAS (16 per server)
iii. Support remote management
iv. Support RAID - various RAID 10 disk groups will be utilized
2.2.3 Domestic Prebuilt Full Rack
The Department requires a prebuilt hardware solution that can be shipped to any city in the United States with a minimum of onsite setup. General solution make up is top of rack switches, Keyboard Video Mouse (KVM) console, six hypervisor servers with directly connected storage array network (SAN) with three SAN devices, a single backup server, and single UPS.
a. Pre-imaged media should be labeled for onsite technician reinstallation.
b. All cables and ports should be labeled for visual aid to assist onsite technician during trouble shooting.
c. Rack switch should be pre-configured with a backup management connection to one of the servers.
d. Rack should be crated, tamper resistant, include proper handling indicators.
e. The current build for the Large Site includes the following components and specifications. The vendor should propose a solution meeting these requirements, but must also be capable of providing future model upgrades as market capabilities and the Department requirements evolve for core components:
i. Microsoft Standard Query Language (SQL) Server
ii. Five node cluster, 12 total rack units
iii. 16 cores per node | 96 cores per cluster
iv. Dual, Hot Plug, Power Supply (1+1) Dual 1100W 100-240V AC
v. Single Silver 6444Y @ 3.6GHz 16C
vi. Memory 512GB (8x 64GB DIMMS) per node 3072GB per cluster
vii. Three x 800GB SSD Cache Drives
viii. 15 x 7.68TB SSD
ix. Four x 25GbE SFP28 Ports Per Node
x. Support remote management
xi. Five Years ProSupport Four-Hour Mission Critical
xii. Storage will have 258.1TB Usable Capacity
xiii. Six vSAN Enterprise licenses
f. The current build for the Small/Medium Site includes the following components and specifications. The vendor should propose a solution meeting these requirements, but must also be capable of providing future model upgrades as market capabilities and the Department requirements evolve for core components:
i. MS SQL Server
ii. Five node cluster, 10 total rack units
iii. 16 cores per node | 80 cores per cluster
iv. Dual, Hot Plug, Power Supply (1+1) Dual 1100W 100-240V AC
v. Single Silver 6444Y @ 3.6GHz 16C
vi. Memory 512GB (8x 64GB DIMMS) per node 3072GB per cluster
vii. 2 x 800GB SSD Cache Drives
viii. 6 x 7.68TB SSD
ix. 4 x 25GbE SFP28 Ports Per Node
x. Support remote management
xi. 5 Years ProSupport 4 Hour Mission Critical
xii. Storage will have 80.9TB Usable Capacity
xiii. 5 vSAN Enterprise licenses
g. The current build for the Backup server includes the following components and specifications. The vendor should propose a solution meeting these requirements, but must also be capable of providing future model upgrades as market capabilities and the Department requirements evolve for core components:
i. One x Intel Xeon Gold 5416S 2G, 16C/32T
ii. 128 GB memory
iii. Six x 192TB SAS SSD
iv. BOSS card with 2 x 480GB M.2
v. Five Years ProSupport Four-Hour Mission Critical
2.2.4 Datacenter Converged Hardware
The Department requires an industry leading converged hardware solution with flexible network, compute, memory, and storage capability. Solution should align with multi-location 2N+1 concept architecture and integrate with alternate site processing, disaster recovery, and continuity of operations requirements.
High level characteristics include:
a. VMware-certified
b. 99.9999% high availability design
c. 10, 25, 100 Gigabit Ethernet (GbE) networking
d. Multiple 32/64 Bg dual port fibre
e. Minium 1600 GB cache
f. Minimum 8192 GB memory
g. Minium 50 TB SAS storage
h. RAID 6 capable
i. Support data-at-rest encryption
j. Minimize power consumption and weight
2.2.5 Datacenter Storage Area Network and Network Attached Storage
The Department requires an industry leading storage hardware solution. Solution should align with multi-location 2N+1 concept architecture and integrate with alternate site processing, disaster recovery, and continuity of operations requirements:
a. 184 TB to 2 PB storage
b. RAID 6 capable
c. 99.9999% high availability design
d. Dual hot swapable controller
e. Support Fibre Channel (FC), Internet Small Computer Storage Interface
(iSCSI) (optical or BaseT), Serial Attached SCCIs (SAS)
f. Support data-at-rest encryption
g. Compatible with VMware, Windows, and Linux hosts
h. Minimize power consumption and weight
2.3 PAST PERFORMANCE
The Department is seeking a solution that has a proven track record in the U.S.
federal space with demonstrated experience supporting federal agencies of similar size, global scope, and mission complexity to the Department. Such experience is critical to ensuring the solution has been proven to be secure and reliable under the required IT security, data management, privacy, and other federal regulations that govern both domestic and overseas information technology implementations within the federal environment.
Please provide the following information regarding your experience deploying your solution for federal customers.
a. Please list all federal agencies where you have successfully deployed your solution in the last five years. For each experience noted, in no more than one paragraph, please provide:
i. Agency and organization name.
ii. Period of Performance.
iii. Solutions provided to the agency.
iv. Point of Contact Name, email and phone that the Department can contact regarding this experience.
b. For at least one, but not more than three, of the federal implementations provided in bullet a above, please provide the additional detailed information requested below to further demonstrate your relevant past experience.
i. Dollar value of contract (across full period of performance).
ii. Period of performance dates.
iii. Schedule, GWAC, or contract used for the requirement.
iv. State whether your company was a prime or subcontractor.
v. Customer point of contact (Name, Title, Email, Phone) that the
Department may reach out to for more information.
vi. Description of the scope of the work your company performed and its relevance and applicability to demonstrating your solution’s ability to deliver the full set of capabilities outlined in Part 2.
Disclaimer: This RFI is for information gathering purposes only as a means to identify interested and capable sources that can provide a solution that fully meets all requirements outlined in Part 2 of this request. The information provided in this notice is subject to change and is not binding on the Government.
The Department has not made a commitment to procure any of the items/services discussed, and release of this RFI should not be construed as such a commitment or as authorization to incur cost for which reimbursement would be required or sought.
The Department will not publicly disclose proprietary information obtained as a result of this RFI. To the full extent that it is protected by law and regulations, information identified by a vendor as Proprietary or Confidential will be kept confidential. All submissions become Government property and will not be returned.
File details come from the government source that posted it. Updated .