NTSB Responses to Questions_RFI.pdf
PDF 197 KB Posted
- Attached to
- Incident Management Software Federal contract opportunity
- Solicitation number
- PUR250022
- Issued by
- National Transportation Safety Board
About this file
This is a Q&A document containing 62 questions and NTSB responses related to RFI PUR250022 for Incident Management Software. The incumbent provider is Grey Wall Software LLC (VEOCI.com), whose contract expires May 19, 2025. NTSB plans to release an RFP in time to award a new contract by that date.
Key requirements include: FedRAMP Moderate authorization (required within 12 months), support for 250 simultaneous internal users, mobile app compatibility for Apple/Android, offline data capture capabilities, integration with O365 Exchange Online for email notifications, and REST API integration with in-house applications. The system must handle approximately 1,200 intake forms, 700-1,000 emails, and 100 SMS messages monthly. The solution should provide role-based access control, support external portal access for approximately 100 users, include mapping capabilities, and maintain 99.9% uptime. Training is needed for 15-20 staff members, with either virtual or onsite options acceptable. NTSB will not consider direct 8(a) or WOSB awards, opting instead for open competition to ensure best value.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI_Incident Mgmt System_FINAL.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 1 of 11
NTSB Responses to Questions Received in Response to RFI PUR250022 Incident Management Software
February 14, 2025
1. We would like to request a two-week extension to the RFI submission date for this project in order to assist us in providing the best possible response.
NTSB Response: The NTSB will extend the RFI to ensure interested parties have adequate time to review responses to questions.
2. Does NTSB have an expected schedule for a following procurement process such as an RFP?
NTSB Response: The NTSB anticipates releasing an RFP in time to award a new contract by May 19, 2025.
3. Does NTSB have an expected project start date?
NTSB Response: The current NTSB contract for Incident Management Software will expire on May 19, 2025.
4. What is NTSB’s expected project completion date / system go live?
NTSB Response: The go live date will need to be NLT three months after the award date.
5. Please indicate if there are any special business registration, licensing, or permit processes required to do business with NTSB other than registration on Sam.gov.
NTSB Response: The NTSB does not have any special business registration, licensing, or permitting requirements.
6. The RFI states the solution needs to support a minimum 250 users. Could you please clarify, is this the minimum number of user accounts, or 250 users logged in to the software at the same time (concurrent users)? If the day-to-day user concurrent user count is different from that expected during an emergency, it would be helpful to know both numbers.
NTSB Response: The system needs to allow for a minimum of 250 simultaneous users.
7. To assist vendors in providing an approximate cost for their solution, how many users does NTSB foresee the vendor needing to train in the following categories: End-User, NTSB Administrators, Train-the-Trainer?
NTSB Response: Approximately 15-20 staff (watch officer and train the trainer)
8. To assist vendors in providing an approximate cost for their solution, please indicate whether NTSB prefers onsite instructor-led training at NTSB’s locations or virtual training?
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 2 of 11
NTSB Response: Either is acceptable.
9. For vendors willing to obtain FedRAMP authorization within 24 months of contract award, is NTSB willing to sponsor the vendor for ATO?
NTSB Response: Yes, NTSB will be able to sponsor the awarded vendor if they don’t currently hold a FedRAMP Authorization. Furthermore, the awarded vendor will incur all costs related to the FedRamp Authorization.
10. Is NTSB willing to accept a vendor that has obtained FedRAMP Low authorization if they supply NIST 800-53 security control enhancements equivalent to meeting the Moderate controls?
NTSB Response: NTSB data needs requires the application to have and maintain a FedRAMP authorization level of Moderate.
11. Is NTSB already using a FedRAMP Moderate compliant version of ESRI ArcGIS or ArcGIS Online for GIS mapping? If not, will the vendor need to provide the necessary ArcGIS Online key or ArcGIS Enterprise licensing at the Moderate control level?
NTSB Response: NTSB does not have have ESRI Licenses and the vendor should add to the overall cost of their proposed solution.
12. Is the vendor expected to provide email servers for email notification, or will NTSB supply their own? If the vendor is to provide the email service, must they also be within the FedRAMP environment?
NTSB Response: NTSB has O365 Exchange Online and as long as the proposed solution could be integrated with our email services, you don’t have stand up your own email service.
13. Is NTSB interested in Streaming Video capabilities for integrating web-based video feeds, CC-TV, drone video, security cameras, roadway cameras, or other IP-based video services into the IMS/CMS application?
NTSB Response: No.
14. Is NTSB interested in Real-time asset tracking of equipment or personnel deployed to the field desired?
NTSB Response: No.
15. Is NTSB interested in the IMS/CMS application also providing Resource Requests and Fulfillment capabilities?
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 3 of 11
NTSB Response: No.
16. Is NTSB interested in the IMS/CMS application also providing features to support mutual aid missions with other agencies?
NTSB Response: No.
17. Currently, does NTSB have an IMS/CMS system in place? If so, is NTSB able to disclose the current product or vendor?
NTSB Response: The incumbent provider of Incident Management Software to NTSB is Grey Wall Software LLC dba VEOCI.com.
18. Currently, does NTSB have an alerting / notification system in place? If so, is NTSB able to disclose the current product or vendor? Will vendors be expected to integrate with an existing alerting system to provide email/SMS/Phone notifications or is the vendor expected to provide or replace this functionality with its own product?
NTSB Response: The Veoci IMS provides SMS alerting.
19. Do you require estimated pricing to be submitted with responses to this RFI? If so, which section should this information be included in?
NTSB Response: Rough Order of Magnitude pricing is not required but will be appreciated.
20. Regarding various requirements in the Statement of Work, several areas imply need for external users (including "portal access to outside organizations" and "instant messaging capability between internal/external entities"). Can the government provide examples and/or quantify the potential scope of use for these groups? Would these be in addition to the required 250 simultaneous users?
NTSB Response: The NTSB currently uses the system during accident investigation launches to send instant messages to our Travel Agent Services contractor.
21. Does NTSB have an existing IMS or CMS that they are using? If so, what is it?
NTSB Response: The incumbent provider of Incident Management Software to NTSB is Grey Wall Software LLC dba VEOCI.com. There is no incumbent CMS.
22. If the NTSB does not have an existing IMS or CMS, how does NTSB currently receive and/or manage incidents, accidents, and events?
NTSB Response: See above.
23. Is there an incumbent?
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 4 of 11
NTSB Response: The incumbent provider of Incident Management Software to NTSB is Grey Wall Software LLC dba VEOCI.com.
24. Is there a timeframe for posting the RFP? Will it be this fiscal year?
NTSB Response: The NTSB anticipates releasing an RFP in time to award a new contract by May 19, 2025.
25. Will NTSB require source data to be migrated from source systems into the new IMS and CMS? If so, what are those source systems?
NTSB Response: Source data must be migrated from the incumbent IMS, Veoci.
26. On page 2, under "Statement of Work," it reads "The software shall be able to interface with the NTSB’s current emergency notification system to send SMS text, email messages, and voicemail messages to an individual or Outlook Active Directory group simultaneously through multiple types of devices (Android or Apple devices, email, and voicemail)." Does this imply that the government intends to continue to use the current emergency notification system and the requirement is simply for the new software to interface with the current emergency notification system?
NTSB Response: The proposed solution shall have the capability to process information for mission/tasking, situation reporting, significant events, and incident action planning create and send SMS text, email messages, and voicemail messages to an individual, groups, and external entities.
27. On page 3, under "Statement of Work," it reads "24/7 tech support available by telephone." Is this for all levels of support — even non-critical?
NTSB Response: Critical issues only.
28. On page 4, under "Statement of Work," it reads "Software shall have a mobile application that will work on Apple or Android OS." Does the government require offline access to the application?
NTSB Response: Online only.
29. How many total users would need access to the system?
NTSB Response: 250
30. Unified SaaS Platform: Could you elaborate on how you plan to leverage a FedRAMP-authorized multi-tenant SaaS platform for Incident Management and Case Management (CMS)?
Specifically, are there any advantages or concerns you foresee with a unified platform approach that allows real-time data sharing and collaboration among internal and external stakeholders?
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 5 of 11
NTSB Response: We don’t have any concerns with real-time data sharing among internal users. However, we anticipate that external users will be granted access to information that is deemed appropriate for the public at any given stage. Therefore, it is critical that the proposed solution shall distinguish between internal and external stakeholders. Any proposed solution shall the capability to implement Role Based Access.
31. Customizability: For ongoing changes—such as adding new fields, creating custom dashboards, or updating business process workflows—how important is it that your chosen solution allows these updates without extensive custom code or vendor reliance?
NTSB Response: Our intent is to minimize customization as much as possible. However, any customization of the proposed solution shall adhere to the platform guardrails to avoid incompatibility with future upgrades.
32. Scalability Needs: The RFI mentions up to 250 simultaneous users. Could you clarify if you foresee future scalability needs—e.g., adding state/local responders, partner agencies, or additional internal staff? How important is it that the system can expand seamlessly without performance degradation or major re-architecture?
NTSB Response: To be addressed in the solicitation.
33. Collaborative Features: Beyond SMS and email, do you envision leveraging collaborative features such as quick group messaging, AI-driven chat summaries, or automated call bridging?
How important is it to have these functionalities already built into the platform versus relying on multiple third-party add-ons?
NTSB Response: Ideally, it would be beneficial to have Agentive AI capabilities built into the platform.
34. FedRAMP Authorization: Would NTSB prefer a solution that already has a Moderate (or higher) FedRAMP authorization, or would you consider an “in-progress” vendor that commits to completing FedRAMP certification within the specified 24-month window? Could you detail how critical an existing FedRAMP authorization is to your decision?
NTSB Response: The NTSB may prefer that the solution has already received a Moderate or higher FedRAMP authorization. This will be addressed in any resulting solicitation.
GSA has clarified in its guidance that vendors and agencies have 12 months to complete FedRAMP certification.
35. Additional Security Requirements: Are there any additional security or compliance requirements beyond FedRAMP Moderate that vendors should address, mainly for multi-agency collaboration scenarios?
NTSB Response: No
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 6 of 11
36. Role-Based Permissions: The RFI states the need for tight user-based and event-based access controls. Do you foresee a requirement for multiple permission levels (e.g., read-only vs.
full-edit vs. limited-edit) across various teams or external agencies? How do you expect to manage these role-based permissions dynamically over time?
NTSB Response: See response for Question #30. Internal stakeholder’s role-based permission could be assigned based on user personas/roles dynamically.
37. Integration Needs: Could you provide more details on the types of data exchanges or integrations expected with external entities or in-house applications? How critical is a mature REST or Open API capability for seamlessly connecting to third-party services, especially during large-scale, multi-agency incidents?
NTSB Response: Any proposed solution shall have the capability to pull and push information from many in-house developed Line of Business Application as well as interfacing with other third-party vendor services. A mature API is critical.
38. In-House Applications: The RFI mentions integration with an in-house application via REST APIs. Can you clarify which in-house systems or applications require integration and what types of data or functionality need to be exchanged?
NTSB Response: SAFTI: The System for Analysis of Federal Transportation Investigations (SAFTI) is an enterprise line of business application that encompasses the workflow and case management of an NTSB investigation across all modal offices and consolidates and standardizes processes and data.
We have public, partners and internal APIs. Their structure formats are JSON or XML.
39. Auditing and Reporting: You mention strict auditing capabilities (e.g., who made changes, timestamps, data lineage). In addition to that, are there specific compliance or policy-driven reporting formats you anticipate needing out of the box? How important is built-in compliance reporting to your selection?
NTSB Response: Built-in compliance reporting is a key factor in our decision-making process as it directly impacts our operational efficiency and risk management. Therefore, solutions that offer robust, built-in compliance reporting will be given higher consideration.
40. Offline and Low-Connectivity Scenarios: In addition to a mobile app, does the NTSB anticipate any offline or low-connectivity scenarios during field investigations? If so, what capabilities would be essential (e.g., forms, data capture, notes) to sync once connectivity is restored?
NTSB Response: Yes. Low connectivity to no connectivity is very comment in accident sites.
The capability to capture data such as pictures, notes, intake forms to later upload would be very beneficial.
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 7 of 11
41. Mobile Functionality: The RFI mentions mobile app compatibility for both Apple and Android devices. Are there specific features (e.g., mapping, notifications) that are considered critical for mobile use?
NTSB Response: Notification, records/intake forms
42. Self-Service Portals: For the TDA Case Management component, how critical is it to have a self-service portal (e.g., for family members or external agencies) that ties seamlessly into your internal workflows? Are you envisioning real-time updates, submission of additional information, and automated notifications for these external users?
NTSB Response: A self-service portal that integrates seamlessly with our internal workflows is indispensable. It not only streamlines our operations but also enhances communication and transparency with external users, which is fundamental to the success of our case management efforts.
43. Case Calendar Features: Can you provide more detail on how the calendar feature will be used in the CMS? For example, do you anticipate recurring events, group notifications, or specific integrations with external calendar systems (e.g., Microsoft Outlook)?
NTSB Response: A calendar feature in the CMS will be a vital tool for managing our schedules, tasks, and resources. Recurring events, group notifications, and integration with external calendar systems like Microsoft Outlook are among the key functionalities we anticipate. These features will enhance our ability to stay organized, improve communication, and streamline our workflows.
44. Implementation Timeline: Could you clarify your target timeframe for full operational readiness once a vendor is selected? How do you see your staff collaborating with the implementation team for configuration, training, and support, especially for advanced features like analytics or omnichannel communication?
NTSB Response: Throughout this process, collaboration between our staff and the implementation team will be key. Regular check-ins, progress updates, and open lines of communication will ensure that the project stays on track and any challenges are addressed promptly. By working closely together, we aim to achieve full operational readiness within the target timeframe and fully leverage the advanced features of the new system.
45. Training Requirements: What level of user training do you envision for this solution, especially considering the varied functionalities (e.g., messaging, auditing, reporting)? Would you prefer on-site, virtual, or hybrid training models?
NTSB Response: We anticipate a hybrid training model to ensure that all users, regardless of their role or location, receive the necessary training to effectively use the system.
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 8 of 11
46. Support Services: In addition to phone support, are you open to or need specialized “white-glove” services—like dedicated success managers, proactive system health monitoring, or advanced administration—to ensure the solution remains fully operational and meets evolving requirements?
NTSB Response: Yes, as long as “white glove” services are not cost prohibited. However, our vendor POC and COR will need to ensure that the solution not only remains fully operational but also continues to evolve to meet our changing needs.
47. Expanded Notification Channels: The RFI specifies SMS, email, and voicemail notifications. Are there any additional channels you might need (e.g., push notifications, in-app alerts)?
NTSB Response: Our expectation is that if the vendor proposes a mobile app as part of their solution, a push notification and in app-alert should part of it.
48. Family Member Notifications: For TDA case management, are there specific scenarios or use cases where family member notifications are critical? Could you elaborate on how these notifications are expected to function (e.g., templates, automated responses)?
NTSB Response: Yes, there are specific scenarios in TDA (Temporary Disability Assistance) case management where family member notifications are critical. Notifications triggers could be the result of updates of case status within the investigation, safety reports and/or recommendation. Effective communication with family members can play a vital role in ensuring the well-being and support of individuals receiving assistance.
49. System Performance Metrics: How does the NTSB plan to measure the success of the implemented system? Are there specific performance benchmarks or usage metrics that vendors should consider?
NTSB Response:
Here are a few examples:
Error Rates: Monitoring the frequency of errors or issues reported by users. We aim to minimize error rates to less than 1% of all transactions or operations.
Automation Success: The percentage of tasks successfully automated by the system, reducing the need for manual intervention. We aim for at least 50% automation of routine tasks.
Uptime and Availability: We expect the system to maintain a high level of uptime and availability, ideally 99.9% or higher, to ensure continuous access and reliability for our users.
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 9 of 11
Flexibility and Customization: Measuring the ease with which the system can be customized and adapted to meet evolving requirements. This includes the ability to integrate with other systems and implement new features.
Data Security and Compliance: Ensuring the system meets all security and compliance requirements, including data protection regulations and industry standards. Regular security audits and compliance checks will be conducted.
50. Dashboard and Analytics: Could you elaborate on the type of dashboards and analytics capabilities you require? Are there specific metrics, KPIs, or visualizations you need to track and display?
NTSB Response: NTSB requires robust dashboards and analytics capabilities that provide comprehensive insights into system performance, user activity, and case management processes.
51. We are eligible for direct award under FAR 6.302-5 for 8(a) or 19.1506 for (WOSB), would the Government be open engaging our firm direct?
NTSB Response: The anticipates competing this requirement to ensure that it obtains the best value solution.
52. Is this a new requirement or contract renewal?
NTSB Response: The current NTSB contract for Incident Management Software will expire on May 19, 2025.
53. If renewal, what is current contract number?
NTSB Response: The current contract number is 9531BM20D0001.
54. When will the RFP be released?
NTSB Response: The NTSB anticipates releasing an RFP in time to award a new contract by May 19, 2025.
55. Scope of Work: “The software shall be able to interface with the NTSB’s current emergency notification system to send SMS text, email messages, and voicemail messages to an individual or Outlook Active Directory group simultaneously through multiple types of devices (Android or Apple devices, email, and voicemail).”
Can you provide additional information on the current system used for emergency notifications?
What is the volume of notifications sent out via SMS? via email? and voicemail?
NTSB Response: Average monthly intake is approximately 1,200 intake forms, 700-1,000 emails and approximately 100 SMS.
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 10 of 11
56. Scope of Work: “The software shall be able to function for a minimum of 250 users simultaneously. ”
Of the 250 users, can you provide a breakdown of the roles of these users and what functions they will need access to?
Are these 250 users all internal NTSB users?
NTSB Response: All are internal NTSB users.
57. “Ability to map locations and addresses in the system.”
Can you provide more detail on what actions you will need to take from maps? Are there a set of users who needs access to maps in the field to map locations and addresses?
NTSB Response: GEO map all employees residence location in the event of disaster, security event or proximity to an NTSB investigation site.
58. “Upon entry of a case in the system, automatically create a calendar reminder, eleven months after the date of the accident, prompting the case manager to reach out to the IIC for a one-year investigative update.”
Does this requirement need to integrate with an existing calendaring tool NTSB is using?
NTSB Response: Our hope is that the proposed solution has calendaring capabilities built in.
59. “Ability to collaborate and share data with outside entities to include other emergency response agencies and/or public health departments in real-time.”
Can you provide a rough estimate of the number of external users that will need collaboration and data access?
NTSB Response: Approximately 100, depending on the event.
60. “Chatroom instant messaging capability Between internal and external entities”
How many internal users will need instant messaging capabilities?
How many external users will need instant messaging capabilities?
NTSB Response: Internal. TDA will require approximately 10 users. The ROC will require approximately 15 users.
61. “Ability to allow the NTSB to provide portal access to outside originations who are not operating the same software/solution.”
How many users will need portal access?
NTSB Responses, RFI PUR250022 – Incident Management Software, Page 11 of 11
NTSB Response: Approximately 100.
62.“The CMS shall be able to integrate with in-house developed applications using REST APIs and or OPEN APIs” Please list the systems/applications/datasources that the CMS system would need to integrate with, and the underlying technology (i.e. .NET application, Java-based app, SQL database, Postgres database, SaaS application, legacy application, etc.)
NTSB Response: We have a number of full stack application and integration to this application will be done via REST APIs. We don’t anticipate a direct connection to the backend database will be needed.
File details come from the government source that posted it. Updated .