Q and A PCI DSS Consultant.pdf

PDF 403 KB Posted

Attached to
Payment Card Industry Data Security Standard (PCI DSS) Advisory Consultant Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of the Air Force Air Education and Training Command

About this file

This is a Questions and Answers (Q&A) document containing 110 questions and responses regarding a Request for Information (RFI) for PCI DSS Advisory Consultant services for the Air Force Services Center (AFSVC).

The Q&A clarifies that AFSVC is seeking advisory consulting services to help achieve PCI DSS compliance across 104 installations by end of FY26. Key details include: this is a nonappropriated fund procurement that does not follow FAR or recognize set-asides; the scope involves providing guidance for 2200+ point-of-sale systems; no travel is required as work will be done remotely; US citizenship is preferred but security clearance is not required; the timeline includes 8 months for developing strategy and execution plans; AFSVC currently has Level 2 merchant compliance but needs to achieve Level 1; they use one primary merchant processor; Windows OS is used; and training will be delivered virtually. The budget and pricing strategy have not been determined as this is currently in the market research phase. A dedicated PCI Compliance Team will meet 1-2 times weekly with the selected vendor, using Microsoft Office tools for communication and reporting. The Q&A indicates AFSVC is open to recommendations for tools and solutions but is primarily seeking advisory expertise rather than direct implementation services.

View the file

Other files for this federal contract opportunity

Other files attached to Payment Card Industry Data Security Standard (PCI DSS) Advisory Consultant, newest first.
File Type Posted
Attachment 1 Verizon Gap Analysis.pdf PDF
SOO - PCI Advisory Consultant 7 Feb 2025.pdf PDF
SOO - PCI Advisory Consultant 7 Feb 2025.docx DOCX document
SOO - PCI Advisory Consultant 7 Feb 2025.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 1 of 18

Payment Card Industry Data Security Standard (PCI DSS) Advisory Consultant

Request for Information (RFI)

Questions and Answers (Q & A)

No. Question Answer

1 Can you confirm whether this requirement is eligible for sole-source contracting under the 8(a) program?

Nonappropriated Fund (NAF) procurement does not follow the Federal Acquisition Regulations (FAR). We do not recognize set-asides. Contractors that meet the Contractor Qualifications outlined in the Statement of Objectives (SOO) will be considered.

2 Are there any specific compliance requirements or certifications that the consulting company must meet besides those listed in DOD MANUAL 8140.03 to qualify for this opportunity?

No specific certifications. Expertise required per SOO, Section 2 (2.1.1 - 2.1.3).

3 Would the government open to a team of businesses responding to the opportunity?

Yes. However, the prime contractor must manage their subcontractors. The prime contractor and subcontractors must meet the Contractor Qualifications outlined in the SOO paragraph 4.2.

4 How does the government prioritize the different aspects of the project, such as PCI DSS compliance, risk mitigation, and business process optimization?

All aspects related to attaining compliance are top priority, with those to sustain compliance and optimize processes secondary. Prefer to design compliance attainment approach with sustainment and optimization in mind.

5 What key evaluation criteria will be used to assess potential vendors for this opportunity?

Technical Solution, Past Performance, and Price.

6 Are the past performance requirements flexible, particularly for contractors with

Experience in the hospitality and entertainment industry is our preference. However, we are flexible if you have experience in the PCI DSS

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 2 of 18 substantial PCI DSS compliance experience but not specifically in the hospitality sector?

industry that shows you are able to meet our requirements. Please see paragraph 4.2 of the SOO for Contractor Qualifications.

7 How does the Air Force Services Center prioritize industry experience over specific NAICS code alignment when evaluating potential contractors for this project?

Experience in the hospitality and entertainment industry is our preference. However, we are flexible if you have experience in the PCI DSS industry that shows you are able to meet our requirements. Please see paragraph 4.2 of the SOO for Contractor Qualifications.

8 What is the anticipated timeline for the project, from the award to full implementation?

We do not have a timeline. We are currently conducting Market Research.

9 What are the government's expectations regarding ongoing support and sustainment of the PCI compliance program after initial implementation?

Air Force Services Center (AFSVC) is conducting Market Research at this stage and looking for expertise and advisory consulting guidance and recommendations, rather than ongoing support.

10 How will the government measure the success and sustainability of the compliance program?

Closing all third-party identified prioritized gaps and reducing installation risk scores are the primary success measures.

AFSVC is conducting Market Research at this stage looking for advisory consulting guidance to get compliant; this would include guidance on processes to sustain compliance.

11 Is the government open to receiving feedback and recommendations on the SOO to refine the final solicitation requirements?

Yes

12 How will the government incorporate industry best practices and insights into the final solicitation?

AFSVC would like to see several examples of how each vendor has used their expertise and influence to make recommendations that, once implemented, were successful in driving compliance for their clients.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 3 of 18

13 Can you provide guidance on this project's budget constraints or cost considerations?

We have not developed a budget or pricing strategy. We are currently conducting Market Research.

14 How does the government plan to assess the cost-effectiveness of the proposed solutions?

We are seeking industry input to help us assess the cost effectiveness of moving forward with this requirement.

15 Will there be opportunities for industry engagement or pre-solicitation conferences to discuss the project further?

We have not determined what, if any, pre-solicitation activities are required. We are currently conducting Market Research.

16 Based on the statement of "Currently, there are 2200+ disparate POS systems in operation, along with gaps in network infrastructure and business processes, leading to fragmented efforts to achieve PCI DSS compliance." Does AFSVC believe there is sufficient commitment to making the changes necessary the environment - specifically do you have budgetary commitments to make the required changes to people, process, and technology and then performing the necessary compliance assessments?

We are committed to resolving all identified issues. We have not developed a budget or pricing strategy. We are currently conducting Market Research.

17 The SOO (Section 6.7) references security clearances, but the narrative in that section only references security certifications - does the vendor need to have cleared personnel available for the PCI DSS effort? (Section 6.6.1 states

Security clearance is not required as classified information is not in scope. However, a background check will be required.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 4 of 18 highest classification level is Unclassified)

18 The SOO states multiple disparate solutions in use, can you describe the central AFSVC central authority/division that is capable of setting and enforcing a standard across the full ecosystem?

The new PCI Office was stood up in FY25 to develop a more centrally managed approach and works directly with Command leadership to decide and implement as leadership deems appropriate. Policy changes will be made to better enforce PCI accountability at the installation level.

19 Regarding the "Unknown number" of payment channels and cardholder data environments - does the AFSVC maintain a merchant id inventory?

Yes, merchant and terminal ID inventory is maintained within the Treasury Management Division at AFSVC.

20 Section 3.1.2.6 references Penetration Testing. Will the vendor need to perform penetration testing, or review penetration testing results? If it is performing the testing, the scope (e.g., number of IPs, networks, devices etc.) will need to be defined, or left as cost-plus. Historically does AFSVC centrally control this testing, or is it handled on a site-by-site basis?

AFSVCs is looking for advisory consulting guidance and recommendations (advisory analysis and scoping) to include solution options, software, vendors, etc.

Per Section 3.1.2. of the SOO “PCI Scoping:

Identifying areas where AFSVC’s current security controls and processes do not meet the requirements of the PCI DSS. The Contractor shall provide a PCI QSA advisory analysis and scoping of all AFSVC payment channels…”

21 Section 4.3.2 references impact Major Commands/Field Commands - are the AFSVC locations controlled or funded by the commands? Mainly we are asking if the solutions recommended by the consultant and adopted by AFSVC will be subject to secondary decision or

There are funding distinctions between Appropriated and non-Appropriated funds.

Certain revenue generating items fall under the Installation level funding requirements (non- Appropriated) rather than the AFSVC headquarters (Appropriated) funding. AFSVC command is in the process of decisioning around central management and funding options and impacts.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 5 of 18 funding process outside the control of AFSVC.

22 Given the global nature of the

AFSVC footprint, is the use of qualified non-U.S. companies and personnel under the guidance of a QSA acceptable?

AFSVC is conducting Market Research at this stage.

23 Given the number of unknowns in the scope of the effort, does AFSVC anticipate a time and materials contract? The level of effort could vary widely based on the ongoing assessment efforts.

We cannot determine the acquisition strategy until after we have examined all the market research collected. We are seeking advice from industry on how to execute this requirement.

24 Is the 8-month remediation timeline (mentioned in 3.1.2.4) realistic given the scope of 104 locations and 2200+ POS systems?

AFSVC is requesting the vendor to identify and prioritize the AFSVC key work areas that must be addressed and provide solutions and resource requirements for the solution to be implemented.

The eight-month timeframe is referring to the strategy and execution plan development.

25 How will the phased implementation approach align with the 3-year maximum contract period?

AFSVC has identified a two-year journey toward achieving 100% compliance across all installations.

26 What are the specific metrics for measuring success in each phase?

AFSVC will be assessing metrics such as Installation Risk scores based on infrastructure readiness, training and process implementation to determine compliance attainment and identify roadblocks. The Advisory Consultant will help inform and guide the actions and approaches necessary to improve compliance measures.

27 What is the actual number of payment channels across locations?

AFSVC is working with a vendor to conduct site surveys to attain a comprehensive inventory to include payment channels by end of FY25.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 6 of 18

28 What is the full inventory of disparate network cardholder data environments?

AFSVC is working with a vendor to conduct site surveys to attain a comprehensive inventory by end of FY25.

29 How will integration with existing DoD security infrastructure be handled?

Integration with DoD security infrastructure should be unnecessary as the installation level revenue generating activities are independent.

30 How will geographic challenges be addressed for the 104 worldwide locations?

We have vendors visiting the installations for site survey, secure network installations and point-of-sale system hardware upgrades, so the Advisory Consultant will consume their reports and make recommendations working virtually and in partnership with the AFSVC PCI Cell.

31 What is the required staffing level for QSAs across different regions?

stage, looking for Advisory consulting guidance and recommendations. AFSVC will utilize a centralized repository of all required data for assessments, negating need for travel to all regions.

32 How will training be delivered across multiple time zones and locations?

Training will be conducted virtually via webinars and computer-based training at multiple timeframes to accommodate all time zones.

33 Section 6.5: Need complete information about conflicts of interest disclosure requirements

AFSVC is currently conducting market research.

34 Section 6.7.2: Clarification on the exact scope of "Limited Privileged Access" research.

35 Section 3.1.2.8: Are 21 days sufficient for the PCI DSS Discovery report given the scope?

3.1.2.8 of the SOO states:

The Contractor shall present a written report to the COR within 21 days of completing the PCI DSS Discovery which contains:

A short and graphical executive summary aimed at senior management. The executive summary contains a statement of the project

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 7 of 18 scope, non-technical descriptions of vulnerabilities, along with those findings’ inherent business risk. It also provides a comparison of the AFSVC’s security posture with that of other organizations of similar size and business objectives.

The ask is 21 days after completing the discovery. Flexibility can be granted as deemed necessary.

36 What is the genesis of the action to perform this PCI assessment and compliance initiative at this time?

stage looking for advisory consulting guidance based on Verizon gap assessment prioritized approach.

Who at AFSVC is responsible for PCI compliance internally?

Currently PCI Compliance responsibility falls on IT but has been elevated to a central PCI Compliance team reporting up through Director of Staff to develop a centrally managed strategy. All installations are accountable for ensuring they comply with guidelines set forth by this team.

38 How many banks are involved with AFSVC PCI transactions both domestically and internationally?

AFSVC has one Merchant for all card transactions across all locations.

39 Are the Merchant IDs managed by one resource? If not, how many resources manage the Merchant IDS?

AFSVC Merchant IDs are managed by the Treasury Management Division partnering with one Merchant for all card transactions across all locations.

40 Is AFSVC able to identify where all credit card transactions settle? Specifically, we would be interested in engaging with someone from treasury or a financial controller role that can account for credit card transactions coming in as part of the engagement.

AFSVC Treasury Management Division tracks all credit card transactions.

41 What, if any, PCI assessment, remediation, and/or compliance

Once elevated to Level 1 Merchant, AFSVC conducted a Third-Party Gap Assessment and received a prioritized approach to compliance.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 8 of 18 initiative has AFSVC performed previously?

The initial remediation was to ensure all business activities were using Chip and PIN card readers and completing all required training. The current focus is on updating the network security and ensuring POS hardware software lifecycles are being maintained by the installations.

42 Is there a minimum baseline security standard that can be referenced which all networks and systems should operate within?

AFSVC Merchant IDs are managed by the Treasury Management Division

43 Does AFSVC have a list of all vendors that store, process, or transmit cardholder data on behalf of AFSVC?

AFSVC has an inventory of business activities and their associated merchant and terminal IDs

44 Can the Government clarify the audience for training?

The audience would be the installation level IT teams and Resource Managers, with other roles added as deemed necessary.

45 Can the Government please clarify: Are the 2200 mentioned lines of business are redundant to the 2200 disparate POS systems in operation? Or rather, are there multiple POS systems supporting a subset of lines of business?

There are multiple POS systems supporting a subset of business operations. Multiple lines of businesses utilize a POS and many of the same POS systems are subset to the business program areas (i.e. Food and Beverage, AF Lodging, Child and Youth, etc.) Most business activities operate one point of sale system with multiple terminals.

46 Can the Government confirm integrated tools in use today? Is the Government seeking audit compliance tooling, vulnerability scanning, and/or access control management?

research focused specifically on advisory consulting guidance based on industry best practices with tool recommendations. AFSVC is working with vendors for the related tools but open to new solutions as deemed necessary and feasible.

47 Does the Government have an inventory analysis of POS systems in use?

AFSVC does have an inventory for the primary POS systems, associated terminals and merchant IDs.

48 Has the Government completed PCI compliance certification to verify adherence to PCI DSS in the past?

AFSVC was compliant at a Merchant Level 2 but has not attained Merchant Level 1 Compliance to date.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 9 of 18

1.2.1. The AFSVC merchant card processing

operations are currently non-compliant with the PCI DSS for a Level 1 Merchant. The compliance effort encompasses a comprehensive review of networks, hardware, software, policies, and procedures associated with merchant card processing.

49 Can the Government confirm there are 104 installations in

Yes, 104 installations are in scope.

50 Does the Government anticipate physical travel to the 104 installations will be required to discover POS systems in use and supporting processes?

Travel will not be necessary for the Advisory consulting scope.

51 Does the government anticipate coordination with vendor POS teams as part of the POS system analysis?

Coordination will be with and through the AFSVC PCI Compliance team for the Advisory consulting role.

52 Does the Government have Policies, Procedures and Standards in place today?

There are various DODI and AFMAN policies with PCI DSS related guidance. AFSVC is revising and strengthening the policy verbiage, accountability and enforcement processes.

53 When was the last time the government performed a risk assessment for PCI?

A third-party assessment was conducted by Verizon September 2022.

54 Does the Government have a data or map that shows current state? Or any view of current state status?

Each installation level IT has varying levels of data and network mapping. Central guidance, training and support is being developed.

55 How many vendors does the Government have in scope for PCI compliance?

AFSVC is currently conducting market research focused specifically on advisory consulting guidance based on industry best practices.

56 How many OS types does the Government have? Does the

AFSVC typically runs Windows OS, both virtual and physical.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 10 of 18

Government run virtual or Physical?

57 How many applications does the Government support from OS?

AFSVC currently two identified payment applications in scope for PCI DSS Compliance.

Vendor assessment currently underway.

58 How many databases platforms does the Government have in your environment?

AFSVC currently has five POS systems in scope for PCI DSS Compliance. Vendor assessment currently underway.

59 Does the Government have an intended timeline for specific deliverables? Given the three year PoP, we understand some will be recurring; however, would benefit from understanding the most near term priorities.

Yes, The PCI Compliance Team has a two-year timeline across all People, Policy, Process, Financial, and Technology workstreams, with Technology being the critical path.

60 Does the Government want the vendor to work directly with Merchants on account setup or is the preference that we provide the toolkit for the Government to facilitate that correspondence?

consulting guidance based on industry best practices.

61 Does the Government anticipate that the vendor is directly delivering on technology (meaning, provide developers to support additional configuration) or are you looking for PCI expertise to help with improvements and provide recommendations?

AFSVC is looking for PCI Consulting expertise to help with improvements and provide recommendations.

Per RFI Section 2 Final Outcome.

The consultant will deliver strategies, tools, and frameworks to help AFSVC in developing an effective and robust enterprise PCI compliance program to achieve and maintain PCI DSS compliance, mitigate risks associated with payment card processing, and enhance overall business system processes affecting cybersecurity. The consultant will provide ongoing support throughout the implementation phase and ensure readiness for subsequent assessments.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 11 of 18

62 The RFI mentions an "unknown number of payment channels" and "unknown number of disparate network cardholder data environments." Will AFSVC provide an initial inventory, or are we expected to conduct a full discovery?

AFSVC has a partial inventory and are working with another vendor to ensure full inventory is documented and maintained.

63 Regarding the ‘8-month timeline for remediation activities’.

Would this be considered a strict deadline, or can recommendations include phased implementation plans extending beyond this timeframe?

Per paragraph 3.1.2.4 of the SOO, Security Control Implementation and Remediation:

Assisting with the implementation and remediation of non-compliant security controls and processes to meet the requirements of the PCI DSS. The Contractor shall identify and prioritize the AFSVC key work areas that must be addressed and provide solutions and manpower resources to complete remediation requirements within 8 months.

AFSVC is looking for a strategy, prioritized approach and execution plan to include resourcing estimates to accomplish the objective within an 8-month timeline.

64 Is there a specific timeframe / deadline (within the maximum 3-year period stated) for achieving PCI compliance?

AFSVC is targeting end of FY26 to attain 100% PCI Compliance.

65 Is there a requirement for consultants to be US citizens?

Yes, that is preferred.

66 Is International security clearance equivalence recognized? (for example – Five Eyes)

Security clearance not required.

67 Can we use contracted resources to conduct the assessments?

Yes. However, the prime contractor must manage their subcontractors. The prime contractor and subcontractors must meet the paragraph 4.2.

68 What contract type are you contemplating for the requirement? How will the

We cannot determine the acquisition strategy until after we have examined all the market research collected. The Air Force and the

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 12 of 18

USAF ensure that the selected contractor can meet both the deliverables and milestones within the proposed period of performance (PoP)?

awarded contractor will work together to keep track of the deliverables and milestones within the period of performance.

69 How will the contract type address the need for flexibility in adapting to potential changes in the scope or timeline, especially given the diverse and geographically separate

We cannot determine the acquisition strategy until after we have examined all of the market research collected. We are seeking advice from industry on how to execute this requirement.

70 What performance metrics will be put in place to assess contractor effectiveness in meeting the PCI DSS compliance (evaluations and assessments) requirements and ensuring security across all business operations?

AFSVC will be assessing metrics such as Installation Risk scores based on infrastructure readiness, training and process implementation to determine compliance attainment and identify roadblocks. The Advisory Consultant will help inform and guide the actions and approaches necessary to improve compliance measures.

71 How will the contractor's performance be evaluated in relation to their ability to provide timely and actionable recommendations for system improvements and risk mitigation?

The Air Force and the awarded contractor will work together to keep track of the deliverables and milestones within the period of performance.

72 What specific measures will be taken in the contract to ensure accountability for the contractor’s role in developing and executing the compliance and business process strategies/tactics?

The Air Force and the awarded contractor will work together to keep track of the deliverables and milestones within the period of performance.

73 How will the contractor’s ability to maintain ongoing support and alignment with AFSVC’s PCI DSS compliance objectives be ensured throughout the life of the contract?

The AFSVC PCI Compliance Team will work closely with the vendor to ensure the appropriate level of support is provided.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 13 of 18

74 How will the contract strategy address the potential need for post-implementation support, particularly in terms of training and ongoing maintenance of PCI DSS compliance across all consulting guidance based on industry best practices. Training and sustainment best practice recommendations would be part of the advisory guidance and planning process.

75 What steps will be taken to incorporate a collaborative working relationship between AFSVC and the contractor to ensure constant transparency and communication on compliance efforts and challenges?

According to 3.2.1.1 of the SOO, Acceptance Criteria, Weekly/Monthly status reports/meetings will be held to discuss details as outlined. The PCI Compliance team will work closely with the vendor consultants.

76 What mechanisms will be used to manage contract modifications or extensions should unforeseen issues arise, particularly in addressing compliance gaps across the 2200+ lines of business and 104

There will be coordination between the Contracting Officer, the Contracting Officer’s Representative, and the awarded contractor.

Additionally, see paragraph 5.2 Schedule of the

SOO.

77 Is there an interest in a Small Business set-aside (prime contract) in any socio-economic classification or credentials (i.e.

SDVOSB, 8a, or HUBZone)? If not, is the Other Than Small (OTS) Prime Contractor required to meet small business subcontracting goals with such a definitive set of requirements/deliverables?

NAF procurement does not follow the Federal Acquisition Regulations. We do not recognize set-asides. Contractors that meet the will be considered.

78 Is AFSVC procuring these services organically (Definitively or IDIQ pool) or is there consideration for procurement alternatives like GSA Schedules or GWACs (i.e.

Alliant 2, CIO SP3, CIO SP3

We cannot determine the acquisition strategy until after we have examined all the market research collected. We are seeking advice from industry on how to execute this requirement.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 14 of 18

Small Business, SEWP 4, and

VETS 2).

79 Reference SOO Section I, 1.1:

Please AFSVC further elaborate on non-compliance findings and provide greater summary-level or specific details on those shortcomings?

See Attachment 1 Verizon Gap Analysis.

80 Can AFSVC provide any current network diagrams/processes that illustrate the current payment environment and set-up across the bases, is there any consistency amount them?

Network diagrams are specific to each installation. AFSVC has a vendor reconfiguring/installing network and will collaborate to ensure revised network diagrams are delivered.

81 Is the current payment process centered solely around Point of Sale/Card Present transactions or are other channels included in this SOO– such as online payments or other?

Primarily Point of Sale/Card Present transactions are the primary focus, but online payments could be in scope as deemed necessary.

82 Has the program office at AFSVC open to modernizing the enterprise, consolidating this work into a more uniform enterprise-level system, or migrating to a new payment solution altogether to reduce/eliminate the current disparate systems and unnecessary costs?

consulting guidance based on industry best practices. AFSVC is open to recommendations with proven compliance results for similar industry.

83 Can AFSVC share a list the current provider(s) used for merchant processing?

AFSVC uses one primary Merchant Card Processor through various payment gateways.

84 Can you please describe the current process to procure Point of Sale hardware?

POS Hardware is procured through the AFSVC Merchant Process overseen by the Treasury Management Division.

85 Does the current AFSVC payments program require cardholder to pay a convenience

USAF pays those fees.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 15 of 18 fee for card payments or does the USAF pay those fees on behalf of the cardholders?

86 Can AFSVC list the types/models of Point-of-Sale terminals deployed in the current system of payments?

Yes, AFSVC has an inventory of merchant and terminal IDs along with model information.

Is 52.22-6 Trade Agreements Act (TAA) compliance expected for POS hardware deployments for the USAF? [If not, this may be a USAF security consideration for consideration as part of the PCI assessment and future modernization work and implementations].

Yes.

Are there incumbent contractors currently performing similar work? If so, can their performance be shared?

Aspects of the compliance initiative are underway by other vendors. Knowledge sharing and lessons learned will be leveraged for the advisory consultant onboarding.

88 What is the level of government personnel engagement during the project?

We have a dedicated team that will meet as often as needed, at least 1-2 times weekly.

89 Are there preferred tools or frameworks the government expects for compliance and reporting?

AFSVC is currently using specific software;

advisory guidance and recommendation is in scope of this RFI.

90 Will travel to all 104 locations be required, or will remote evaluations suffice?

Remote evaluations will suffice. Physical site assessments have been conducted/are underway.

91 What metrics or KPIs will be used to measure the success of this project?

Success will be measured by reducing the Installation Risk score, comprised of Increasing PCI awareness through installation level POCs, training and governance accountability along with Infrastructure readiness, comprised of enterprise network, end-of-life POS

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 16 of 18 maintenance and lifecycle management, and scanning and penetration testing in place.

92 Are there any upcoming updates to PCI DSS requirements that should be anticipated during the contract period?

The PCI Security Standards Council periodically releases new versions of the PCI DSS standard, introducing new or updated requirements. The advisory guidance requested will remain geared toward the overall standard with adjustments to focus as needed.

93 What is the budget ceiling for this contract, if any?

We have not developed a budget or pricing strategy. We are currently conducting Market Research.

94 What specific outcomes would you consider a success for this initiative?

Summarized in Section 2.1 of the SOO, Final Outcome:

The consultant will deliver strategies, tools, and frameworks to help AFSVC in developing an effective and robust enterprise PCI compliance program to achieve and maintain PCI DSS compliance, mitigate risks associated with payment card processing, and enhance overall business system processes affecting cybersecurity. The consultant will provide ongoing support throughout the implementation phase and ensure readiness for subsequent assessments.

95 How does PCI DSS compliance align with your strategic objectives?

Attaining PCI DSS compliance is a top Priority for AFSVC and IMSC Command aligned to strategic objectives around Strengthening Airmen & Families.

96 Are there any constraints or risks that the decision-making team is particularly concerned about?

Time is the biggest constraint; goal is expediency to attain compliance to reduce the risk of a breach

97 Is there an expectation for the contractor to propose new technologies or stick with proven solutions?

As stated in the SOO, paragraph 2.0 Problem Statement:

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 17 of 18

The deliverable will also include a comprehensive suite of integrated tools and strategies that ensure full PCI DSS compliance while improving the overall security and efficiency of payment processing across business operations and geographically separated locations, protecting payment card data and streamlining related processes.

Strategic pillars (not an exhaustive list):

2.1.3 Commercial expertise to recommend

turnkey compliance solution suite, including tools, technologies, and processes that ensure adherence to PCI DSS standards

98 How critical is training and employee awareness to the overall compliance strategy?

These are key components to the holistic approach AFSVC is implementing.

99 Are there internal milestones or deadlines that the contractor must be aware of?

AFSVC is targeting end of FY2026 to attain 100% PCI Compliance

100 What is the long-term vision for payment card data security within AFSVC?

Long-term vision is to sustain PCI DSS compliance across all installations through comprehensive processes, education and innovation through compliance catalog with suite of options that are approved for use, tracked and maintained by the business activities (business units/installations)

101 What are the most significant challenges you foresee during implementation?

The most significant challenges are expected to be the pace of network installation and POS upgrades across all 104 installations.

102 How is the current level of PCI DSS compliance being measured across locations?

AFSVC has been deemed a Merchant Level 1 by the Merchant Processor, therefore all installations have to achieve 100% compliance.

AFSVC is assessing risk by installation based on the 2022 Verizon gap assessment.

103 Are there existing systems or tools that the contractor must integrate with?

No integrations at this point. Guidance and assistance will be provided if necessary.

PCI DSS Advisory Consultant Questions and Answers 25 Feb 2025 Page 18 of 18

104 How involved will the program team be in facilitating access to resources and data?

AFSVC has a dedicated PCI Compliance Team that will facilitate vendor access.

105 What are the preferred communication and reporting mechanisms for the program team?

Weekly meetings leveraging MS office suite – Teams, Project, PowerPoint, Excel, Word, etc.

106 Are there specific locations or lines of business with higher risk profiles?

The installations in foreign countries, geographically separated units (satellite locations separated from the main base), those with remote recreation areas, those with high transaction volume.

107 How will conflicts or bottlenecks between stakeholders be resolved?

Courses of action will be developed and presented to command leadership for decisioning.

108 What level of customization is expected in training materials and templates?

Some level of Air Force customization will be required, but prefer structured consistent templates across all installations

109 What mechanisms are currently in place for ongoing compliance monitoring?

AFSVC is working with a vendor to conduct scans and penetration tests and develop remediation plans

110 Are there plans for scaling or expanding the PCI compliance framework beyond the current

There are no plans at this time.

We sincerely thank you for your questions. We look forward to receiving your comments to assist us in developing the SOO and our pricing strategy. Thank you.

File details come from the government source that posted it. Updated .