MuleSoft JA Redacted.pdf

PDF 420 KB Posted

Attached to
Mulesoft licenses Federal contract opportunity
Solicitation number
70T03021F7667N084
Issued by
Department of Homeland Security Transportation Security Administration

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION I: Introduction The Transportation Security Administration (TSA), Information Technology (IT) Applications Development Division (ADD) and Contracting & Procurement (C&P) propose to issue a delivery order that restricts the number of sources provided a fair opportunity to be considered (FAR 16.505(b)(2)).

The exception to fair opportunity is based on a class of products to be procured on the basis of a brand-name product. Multiple procurement actions are anticipated to be fulfilled under the authority of this class justification. The initial procurement to be conducted in FY20 will be done using PR number 21-20-200-CIO424 and C&P’s tracking number is JA-2020-03-571

Per FAR 16.505, this acquisition is conducted under a multiple award contract.

SECTION II: Description of Action Being Approved This action is justification and corresponding approval for using a specific brand-name to identify TSA’s requirements for application programming interface (API) integration platform. Specifically, the TSA intends to acquire licenses for the MuleSoft API solution. This justification is prepared on a class basis to identify the on-going requirements for MuleSoft licenses over a 5-year period, from August 25, 2020, through August 24, 2025. The authority of this justification may be used to conduct multiple procurement actions for MuleSoft licenses during that period, up to total ceiling of $13 million. The authority of this justification will expire upon either reaching the end of the authorized period or awarding procurements that reach the ceiling, whichever occurs first.

SECTION III: Description of Supplies or Services The TSA requires a variety of MuleSoft license types. The licenses identified in the table below are the initial types of licenses that will be authorized to be procured on a brand-name basis under the authority of this justification, within the total period of five (5) years and up to the ceiling of $13 million. As additional specific requirements are defined during the authorized period to this justification the TSA may use the authority of this justification to procure additional types of MuleSoft licenses.

Description Part Number

Government Cloud (FedRAMP) Base Subscription 100-1090

Platform Manager and Analytics 100-0008

Program Architect (1 year) Services 100-0047

Flexible Training Credits TCFlex-MS

Additional Two (2) VPC/VPN Pairs 100-0011

(OPTIONAL ITEM) Additional Two (2) Load Balancer 100-0010

(OPTIONAL ITEM) Program Architect (1 year) 100-0047

(OPTIONAL ITEM) Additional Production Cores 100-0003

(OPTIONAL ITEM) Additional Pre-Production Cores 100-0004

SECTION IV: Identification of the Limited Source Consideration Rationale

FAR 16.505 (b)(2)(i)(A) The agency need for the supplies or services is so urgent that providing a fair opportunity would result in unacceptable delays.

FAR 16.505 (b)(2)(i)(B) Only one awardee is capable of providing the supplies or services required at the level of quality required because the supplies or services ordered are unique or highly specialized

Justification for Fair Opportunity Exception Class Brand Name Justification and Approval

MuleSoft Licenses

FAR 16.505 (b)(2)(i)(C) The order must be issued on a sole-source basis in the interest of economy and efficiency because it is a logical follow-on to an order already issued under the contract, provided that all awardees were given a fair opportunity to be considered for the original order

FAR 16.505 (b)(2)(i)(D) It is necessary to place an order to satisfy a minimum guarantee

FAR 16.505 (b)(2)(i)(E) For orders exceeding the simplified acquisition threshold, a statute expressly authorizes that the purchase can be made from a specified source.

SECTION V: Description of Fair Opportunity Exception Rationale

The Applications Development Division (ADD), a division under TSA IT, is responsible for the development, re-platform, integration and maintenance of over 120 applications and various data sources at TSA. ADD’s high priority projects are legacy modernization, interoperability, shared data and services. To meet these demands, ADD researches modern approaches and adopts an application programming interface (API) Centric Enterprise strategy. ADD envisions that effective API oriented development, management, and integration will lay the foundation for TSA digital transformation by enabling it to build an inter-connected applications and data network as an ecosystem, easing the access and interoperation of these applications and data sources anytime, anywhere. This API-Centric Enterprise strategy also enables other key technology strategies such as: Mobile and Internet of Thing (IoT), Microservice architecture, and Federal Data Strategy.

In today’s rapidly evolving environment, risk-based and data-driven decisions rely heavily on the fast, agile delivery and effective use of information to keep America’s transportation system safe. To support this mission, the TSA Information Technology (IT) needs digital transformation to take advantage of new technologies and the power of the cloud. The digital transformation experience from industry has indicated that API and integration play a crucial role in supporting digital transformation and innovation by enabling seamless connectivity between platforms, data, ecosystem business models, agile business processes, and regulations and policies enforcement.

With the current systems in operation, the TSA enterprise has several limitations.

1. Tightly-Coupled Applications: Systems are deployed on multiple technical stacks, with limited thought given to inter-system communications, delineation of enterprise data, or future limitations.

2. Lack Agility: Technology has advanced at a rapid pace and will continue to evolve. Existing technical stacks are utilized in a manner that does not take into consideration the cost of platform migration to lower cost and utilize new capabilities.

3. Information Silo: Individual systems are built to support core organizational needs but are not built to support data and functionality across the TSA enterprise.

4. Lack Clarity of Data Ownership: The ownership of TSA information is not always transparent, leading to a high cost of transition from one vendor or system to another.

The goal of the MuleSoft integration platform is to improve enterprise posture by providing the following benefits.

1. Centralized Integration Platform: A focus on API technical approach serves as a clean demarcation between inter and intra system services, allows for managed system communication, and allows for incremental replacement of services.

2. Authoritative Data Sources: Focus on a clean definition of official TSA data; this definition should serve as a contract between designated data owners and the TSA enterprise on data definition, availability, utilization, and stewardship. The focus should be on care and availability of data to the enterprise for TSA’s benefit.

3. Governance: Standard processes and technology are defined for data and functional availability, security, and API governance, with an emphasis on simplicity and high value reusable interfaces.

4. Data Fidelity: Establishment of a data as a service layer, with associated agreements from the authoritative data sources for feeds, removing issues with specific data store implementations and data ownership. This lowers the barrier for data analytics using TSA enterprise business intelligence tools

TSA requires a full, lifecycle API management and integration platform solution and professional consulting services to support to the implementation of the API platform.

The three most critical requirements for TSA are as follows:

1. Must have Government Cloud offering that is FedRAMP authorized with minimum impact level of Moderate. This is to ensure the product can meet Federal and TSA high security standards, has a FedRAMP approved System Security Plan, speed up Authority to Operate process (ATO), which is usually a lengthy and costly process.

2. Has API Management capabilities to manage the entire API life cycle: design, develop, test, document, publish, deploy, support, version, and retire APIs.

3. Has Enterprise Service Bus (ESB) integration capabilities that enable rapid data and system integration. These capabilities shall be on the same platform and shared the same control plan with the above API management capabilities, to provide a full set of hybrid integration capabilities in a single product.

Each of the critical requirements are required by DHS and TSA policy and guidance.

Requirement 1: Must have Government Cloud offering that is FedRAMP authorized with minimum impact level of Moderate. Per TSA Cloud Strategies 2019 Memo, TSA “adopts a Cloud First strategy for all new IT Services and Cloud Smart strategy for existing applications”.

For security compliance requirements, the memo clearly requires that “TSA cloud solutions must be certified by the Federal Risk and Authorization Management Program (FedRAMP)”. This requirement is further detailed in section G, Federal Risk and Authorization Management Program (FedRAMP), of Information Assurance Requirements for TSA Government Acquisitions policy.

Requirements 2 and 3: Must have API Management capabilities to manage the entire API life cycle and ESB integration capabilities.

Figure 1 illustrates a high-level API-First Technical Approach and ESB integration for current and future projects.

The API and ESB hybrid integration approach above is aligned with the TSA Cloud Strategy 2.0 release, September 2019. In figure above, the key elements include the cloud integration platform with governance and security processes provided within the API lifecycle management support services. The Integration Platform API provides governance and management for the entire API lifecycle in collaboration with security and business owners. Support processes include onboard new APIs, ensure API quality and usability, coordinate release of new version of APIs, report on API usage and metrics and promote enterprise usage. Furthermore, the API and ESB hybrid integration requirements support the implementation of the Federal Data Strategy required at TSA and follow the TSA Information Data Roadmap. Particularly, they support Goal 1 (Governing, Managing, and Protecting Information and Data) and Goal 2 (Promoting efficient and appropriate information and data use). MuleSoft with its modern integration API and ESB capabilities can expose data as asset from anywhere, and enforce the governance and standards from its policy management on a single platform. With MuleSoft Exchange, a shared API repository and standard API documentation, it ensures information and data are identified, organized, and published in ways to promote re-use of authoritative data (Goal 2).

TSA conducted market research to determine products capable of meeting all critical requirements and MuleSoft is only product that has API Management and Enterprise Services Bus (ESB) on a single platform as designed from the beginning (versus through acquisition). This is critical because instead of purchasing multiple elements to develop one system, MuleSoft offers comprehensive integration solution in one product. Other vendors either have only limited capabilities or multiple products with separate control plan. This is because they acquired other capabilities through acquisition, then integrated them to their applications suite. Such applications suite is difficult to use and manage because it was not designed at the beginning.

As such, the result of a single platform for hybrid integration from MuleSoft is cost savings as well as more effective to operate and manage in TSA environment. Furthermore, MuleSoft platform provides many production ready API connectors and integration templates to enable rapid application and data integration with Salesforce. TSA adopted a Cloud-First, SaaS-First strategy by leveraging Salesforce SaaS offering. TSA continues to invest in building a robust Salesforce platform and several TSA offices are turning to Salesforce to re-platform their applications.

MuleSoft compliments and accelerates integration with Salesforce platform which will speed deployment of integration solutions.

A joint program between Enterprise Support and Security Operations, Staffing, Scheduling, Time and Attendance (SSTA), depends on the deployment of the MuleSoft platform. The SSTA architecture is focused on supporting airport operations and the Administrator’s desire to reduce the amount of time spent by TSOs on administrative activities. The MuleSoft API management capabilities are backbone to integrating several applications and systems that support process of staffing airports and paying the front line workforce. Specifically, Mulesoft will enable SSTA to eliminate the need for the front line workforce to manually enter shifts and leave bids data into the time and attendance system across all federalized airports, putting more officers back onto the screening operations to improve wait time for the traveling public.

SECTION VI: Contracting Officer’s Determination that the Order Represents the Best Value Specifying TSA’s requirement for API management platform licenses by using MuleSoft brand name is the best value for meeting requirements because it enables the TSA to meet requirements without incurring a substantial duplication of costs. As noted in section V of this documents, the MuleSoft base platform (Base Subscription + Platform Manager and Analytics) not only includes modern API management capabilities, but also includes ESB capabilities. With ESB capabilities on the same base platform without additional cost, MuleSoft will help TSA to migrate off TIBCO BusinessWorks, an outdated legacy ESB platform. Legacy TIBCO BusinessWorks costs $250K for one-year subscription. MuleSoft base platform costs approximately $266K for one-year subscription. Implementing MuleSoft will eliminate TIBCO software cost and additional savings will be achieved through reducing infrastructure footprint.

MuleSoft Government Cloud is FedRAMP compliant, designed specifically for the US government and authorized government agencies. It includes hundreds of enhancements in access control, auditing, and encryption. It provides continuous security monitoring, threat detection and response, patch and vulnerabilities management. It also includes the System Security Plan, a critical artifact per FISMA requirement to ATO a new system. It is expected that TSA would save approximately 6 months from its ATO process for re-using these security features and save yearly maintenance cost for patch and vulnerabilities management. That is approximately $300K saving for the initial ATO process and $100K a year for the maintenance.

Other savings come from the direct value of re-using available connectors, integration templates and APIs, particularly connectors and templates for Salesforce integration. A growing number of applications are being deployed in Salesforce and they need MuleSoft to integrate with other external applications. Fewer hours will be spent building integration and APIs. Project quality and on-boarding of new developers will be improved. Below is the formula to calculate such benefit:

(Number of APIs to build per project) x (Expected reuse rate) x (Time to build one API) x (FTE Per hour) x (Number of API projects)

Input from a medium size project, such as Global Risk and Analysis Decision Support System (GRADS):

- Number of APIs: 50. Estimated from the current database tables (50 main tables)

- Reuse Rate: 40% is deduced from the current duplicate data points among other applications (e.g., GRADS, LINKs, PARIS, EPMP, KSMS).

Reuse is also from available connectors, integration templates from MuleSoft.

- Time to build one API: 160 hours. Approximately 4 weeks. This includes build, test and deploy.

- FTE per hour: $100. Average FTE cost in a typical application development project at TSA.

- Number of API development projects per year: 10

(50) x (40%) x (160 hours) x ($100) x (10) = $3,200,000

Summary of the Savings:

1. One-time saving from shortening ATO process: $300,000

Annual Saving:

2. TIBCO license subscription: $250,000

3. Security Maintenance: $100,000

4. Saving from reuse: $3,200,000

Total savings for 5 years: $300,000 + 5*(100,000 + 250,000 + 3,200,000) = $18,050,000

For each individual procurement for specific quantities of MuleSoft licenses conducted under the authority of this justification the Contracting Officer will obtain competitive price quotes by soliciting small business re-sellers of MuleSoft licenses under existing IDIQ contract vehicles (such as DHS FirstSource II or NASA SEWP). This price competition amongst resellers will help ensure TSA pays a fair and reasonable price for each procurement for MuleSoft licenses.

Finally, the total estimated ceiling of this justification is calculated on the base if immediate, known requirements and reasonable forecasts of expected requirements over the next five (5) years. IT estimates a need for approximately $1.0M of licenses and support in base year to initiate API deployment in TSA environment. As more applications are deployed to the platform, additional computing capacity (virtual cores) need to be added in all environments. It is estimated that at least 2 Production cores and 4 Pre-Preproduction cores will need to be added every year to support new deployed applications and enhanced applications. Additional technical support is also needed to support more applications and developers onboarding and using the platform. This growth is forecasted in the optional CLINs accordingly.

As a result of this information the Contracting Officer has determined that the procurements covered by this justification represent the best value to TSA for meeting its API integration platform requirements.

SECTION VII: Market Research Description Market research via Internet and Gartner reports were conducted at the beginning to understand the requirements from industry perspective. Those requirements were then complimented with government’s requirements and prioritized for TSA. Products were then reviewed based on their high ranking in Gartner report (Mulesoft, APIGee), FedRAMP authorized (Mulesoft, Dell Boomi), and existence at TSA

(TIBCO).

Color Code Legend

Requirements Fully Met Partial Met Not Met

Requirement

Mulesoft Anypoint

Dell Boomi

APIGee Edge

TIBCO

Mashery

A. API management and Integration Solution Platform Requirements

The platform must have Government Cloud offering that is FedRamp authorized with minimum impact level of Moderate.

1 1 0 0

The platform shall support hybrid and multicloud deployment: control components are in the cloud. Run-time can be deployed on premise or in the cloud.

1 0 0.8 1

The platform shall have API or command line that can support automation of build and policy for environment promotion (development, staging, production).

1 0.7 1 0.8

The platform shall have health and resource consumption monitoring and APIs for these monitoring features so that they can be integrated into TSA existing enterprise monitor tools.

1 1 1 1

The platform shall support high availability solution and up time equals to or greater than 99.95% with a credit policy if uptime is below the threshold. 1 1 1 1

The platform shall provide developer with self-service portal for API discovery, learning, registration, collaboration and management.

1 0.5 0.7 0.7

The platform shall integration with TSA enterprise identity management solution, Okta.

1 1 1 1

The API platform shall enforce authorization policies for access and operation request based on roles, permission sets as well as other external factors such as IP address, geolocation, date and time.

1 0.7 1 0.7

The API platform shall have configurable threat detection solution for content inspection and evaluation of traffic payload for abnormal API consumption.

1 1 1 1

The API platform shall have configurable policy-based data privacy protection to filter or remove specified data from response to prevent them being leaked through an API.

1 0.6 1 1

The API platform shall have configurable traffic management to throttle usage and rate limiting to control API calls volume to improve performance during peak period.

1 0.8 1 1

The API platform shall have configurable traffic management to manage API consumption quotas: capability to throttle or halt subsequent API calls if quota has been reached.

1 1 1 1

The API platform shall have configurable traffic management to Traffic prioritization:

capability to prioritize API traffic based on traffic group or application group (mobile, web), ensure that API calls from those groups are treated with high priority.

0.7 0.7 0.7 0.7

The API platform shall have the ability to perform format translation: capability to translate original data format to more common format, such as JSON, for API consumer.

1 1 1 1

The API platform shall have policy management and tracking capability for authorization tagging to indicate a policy has been applied to a given request for downstream services.

1 1 1 1

The API platform shall enable developers to search APIs that offers service or data for reuse. 1 0.8 1 0.8

The API platform shall have self-service capability so developers publish documentation, test harnesses and sandbox for API, share sample code, libraries and SDKs.

1 0.7 0.8 0.6

The API platform shall support the design phase with an intuitive tool for rapid design and ability to generate API specs in an Open API and RAML standard. 1 0.6 0.9 0.6

The API platform shall support the build phase with visual integration flows and ability to transform and map complex data elements using out of the box features and/or connectors.

1 0.6 0.8 0.6

The API platform shall support the testing phase with automate mock tests at design and runtime, and in CI/CD pipeline. 1 0 0.8 0.7

The API platform shall support the deployment phase with ease of deployment for various scenarios and environments: adding new API to existing service, creating new service from scratch or based on existing data or application resources.

1 1 1 1

The API platform shall support the ability to roll back to earlier versions. 1 0.7 0 1

The API platform shall provide production ready API connectors and integration templates to enable rapid application and data integration with TSA Salesforce government platform.

1 0.5 0.5 0.5

API platform shall provide activity logging of the followings: access, api consumption, performance, error, audit, integration with enterprise monitoring

1 1 1 1

API platform shall provide advanced analytic to include canned reporting, custom reporting, trending reporting, pattern reporting.

1 0.7 0.8 0.7

Enterprise Service Bus (ESB) integration capabilities that enable rapid data and system integration. Provide protocol conversion, data transformation, data security, routing, orchestration, mediation and monitoring. These capabilities shall be on the same platform and shared the same control plan with API capabilities, to provide a full set of hybrid integration capabilities in a single product.

1 0 0 0

ESB shall support advanced asynchronous message queueing (MQ) 1 1 0 1

ESB shall have application connectors/adapters for SaaS and on-premises packaged applications (for example: MS SQL database, Oracle)

1 0.5 0 0.8

ESB shall enable routing of messages and events. 1 0.7 0 0.7

B. API and Integration Professional Consulting Services Requirements

Center of Excellence (COE): Implement a centralized services that facilitates and promotes best practices, collaborations, governance and culture influences for adopting API-led connectivity architecture, development and integration.

1 1 1 1

Total Score 29.7 21.8 21.8 23.9

SECTION VIII: Other Facts Supporting the Fair Opportunity Exception Justification

All facts supporting this justification are identified in the other sections of this document.

SECTION IX: Actions Taken to Remove Barriers to Competition To ensure competition, IT will continually monitor and evaluate its integration approach. In the first two years, when migrating TIBCO BusinessWorks ESB to MuleSoft ESB, IT will re-evaluate ESB integration approach, and consider to replace the ESB-led integration with API-led approach. If that is possible, the ESB requirements can be removed in the future and TSA no longer needs ESB and API capabilities on the same single platform. This will open more competition for other vendors.

IT also expect that more vendors will participate in FedRAMP which will increase the competition. Currently, there are only 2 vendors that are FedRAMP authorized: MuleSoft and Dell Boomi.

As IT consolidates its major development platforms, hosting environment, applications and data sources, IT anticipates its integration needs will change. As other mission needs emerge, IT will re-evaluate its requirements to determine if MuleSoft still best meets TSA integration needs. If there is a better fit available in the marketplace, meets TSA mission and integration needs and is worth the investment, IT will work with its customers to develop new requirements, open more to competition.

SECTION X: Contracting Officer Certification I certify that this information is accurate and complete to the best of my knowledge and belief.

Richard Melrose

Name (Printed) Signature Date SECTION XI: Technical or Requirements Personnel Certification I certify that this requirement meets the Government’s minimum need and that the supporting data, which forms a basis for this justification, is complete and accurate.

Balaji Subramaniam

SECTION XII: Concurrence and Approval

The required levels of concurrence and approval of this Limited Sourced Justification depend on the estimated total value of the procurement. Concurrence and approval must be obtained for that level and each previous level.

Estimated Procurement Value:

$2,000 and greater for Construction $2,500 and greater for Services

$10,000 and greater for Supplies Concurrence:

Program Manager:

Glenn Stoll

Balaji V Subramaniam

Digitally signed by Balaji V Subramaniam Date: 2020.08.27 18:22:46 -04'00'

GLENN A STOLL

Digitally signed by GLENN A

STOLL

Date: 2020.08.28 06:23:39 -04'00'

Acquisition Official Approval:

Contracting Officer:

Richard Melrose

Estimated Procurement Value: Greater than $250,000

Acquisition Official Approval:

Division Director:

Mary F. Hallam Name (Printed) Signature Date

Estimated Procurement Value: Greater than $700,000 Acquisition Official Approval:

TSA Competition Advocate:

Marvin Grubbs

Estimated Procurement Value: Greater than $13,500,000

Head of Contracting Activity:

Estimated Procurement Value: Greater than $68,000,000

DHS Chief Procurement Officer:

RICHARD G

MELROSE

Digitally signed by

RICHARD G MELROSE

Date: 2020.08.28 15:23:54 -04'00'

MARY F HALLAM Digitally signed by MARY F HALLAM Date: 2020.08.28 15:29:01 -04'00'

CHARLES M

GRUBBS

Digitally signed by CHARLES M

GRUBBS

Date: 2020.08.28 15:41:50 -04'00'

File details come from the government source that posted it. Updated .