Response to Offeror Questions document.pdf

PDF 313 KB Posted

Attached to
Dakota State University-SecureSD Secure Email Solution State and local contract opportunity
Solicitation number
25RFP-DSU-25003
Issued by
Kingsbury County, South Dakota

About this file

This document is a Questions and Answers (Q&A) file for the SecureSD Cybersecurity for Municipalities and Counties Request for Proposal (RFP #: DSU-25003-SecureSD), issued by Dakota State University. The RFP seeks to establish a pool of qualified contractors to provide a secure email solution for South Dakota's local government entities, including cities, counties, and municipalities. The solution requires Microsoft 365 Government Community Cloud (GCC) with a minimum G3 license and Microsoft Defender for Office 365 Plan 2, focusing on enhancing cybersecurity infrastructure. The proposal submissions are due by June 30, 2025, with an anticipated award date of August 1, 2025, and a contract period running through April 30, 2028. The RFP is not mandatory, and entities can voluntarily participate in the program.

The project is funded through the 2024 Senate Bill 187, which appropriated $7 million from the general fund to the South Dakota Attorney General's Office's Consumer Protection division. The exact number of participating entities is unknown, but there are 66 counties and approximately 309 cities in South Dakota. The solution will provide full desktop versions of Office applications, collaboration services, spam protection, ongoing simulated phishing campaigns, multi-factor authentication, and end-to-end encryption, all hosted in US-based government community cloud data centers at no initial cost to the entities. Vendors are encouraged to propose optional third-party security solutions, and the final contract will be negotiated based on individual entity needs. After the initial contract period, participating entities may become responsible for continuing the service costs.

View the file

Other files for this state and local contract opportunity

Other files attached to Dakota State University-SecureSD Secure Email Solution, newest first.
File Type Posted
RFP Document.pdf PDF
RFP Document.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SecureSD: Cybersecurity for Municipalities and Counties

RFP #: DSU-25003-SecureSD

Questions and Answers

820 N Washington Ave Madison SD 57042 Page 1 605-295-0821 | https://madlabs.dsu.edu/securesd/ | SecureSD@dsu.edu

Questions are in bold and those submitted by Offerors are verbatim (including any misspelling or grammar errors) as received and the answers follow the questions.

Q. How will this project impact those entities that already have their own domain and secured email solution? Will it be required that they switch to this solution, or is it just going to be offered as another option? Thanks.

A. They will not be required to switch to this solution. While the Secure Email Solution service will be a government level secured email system, complete with Office365 applications (including collaboration services

<Teams, OneDrive, SharePoint, etc.), spam protection, ongoing simulated phishing campaigns, multi-factor authentication, end-to-end encryption, (and more), all inside US (only) based government community cloud data centers and delivered at no cost, it remains as a voluntary decision of the entity. If you are an IT Vendor with existing local government clients, it may behoove you to submit a proposal for this RFP to migrate them to the government cloud and improve their cybersecurity posture to a government level.

Q. Most counties have the understanding that they should improve their email security. The problem is they get nervous about funding being pulled in the future or not having any say in future changes.

A. The #1 thing we hear from IT Vendors (and the Entities – both cities & counties) is that we’d like to improve cybersecurity but we don't want to pay for it. The continuing funding is always an unknown and uncertainty especially to those who don’t like any risk at all. It is actually how we’ve designed this Email RFP, to mitigate that risk somewhat. The entities establish a relationship with the selected IT Vendor, and the costs should be reasonable as they should have multiple clients, able to automate a lot of the work, etc.

The entities will have a lot of say in future changes. Again, it is how we have designed the RFP to be individualized per entity. If they don’t like the IT Vendor or their service, they can discuss their needs with them or simply change to another IT Vendor in the pool of qualified vendors awarded the RFP.

Per the “get nervous about funding being pulled in the future” we’ve heard it said … “we’d take a Michael

Jordan for 3 years over doing nothing to improve the team.” Enhancing cybersecurity is ongoing and to have this government level of cybersecurity utilizing this funding is a great kickstart and provides time to prepare future budgets if needed.

Q. Just to clarify, do you want Sealed USB delivered to you again or is electronic submission via email sufficient?

A. Email submissions are not accepted and will be rejected. (RFP Section 1.6.2) We need one physical copy mailed to us – these should/must have the wet signatures (prefer blue ink) on them. Also, ensure the cost proposal is in a separately sealed envelope. Included in these post office mailing(s) would be the USB drive with one electronic copy of your proposal (or cost proposal in the separate envelope), any attachments, and ensure they are in the requested formats outlined in the RFP.

https://madlabs.dsu.edu/securesd/

820 N Washington Ave Madison SD 57042 Page 2

Q. I have an entity that is currently looking to migrate from ISP hosted POP/IMAP mail to a 365 solution. If RFP decisions aren’t going to be made until 8/1, at what point can the entities start receiving covered services? This entity is hoping to get something established soon, but if waiting means that all costs will be covered they may opt for that.

A. We would recommend the entity wait before making a decision. Remember the SecureSD Secure Email

Solution will be a government level secured email system, complete with Office365 applications (including collaboration services (Teams, OneDrive, SharePoint, etc.), spam protection, ongoing simulated phishing campaigns, multi-factor authentication, end-to-end encryption, (and more), all inside US (only) based government community cloud data centers.

We think obtaining that level of cybersecurity [ As you mention - at no cost through the funding of SecureSD ] would be worth the wait.

Specific to your question. We may have some entities on the system by the end of August, certainly in

September, and throughout the fall months and then continue over the length of the program. If the entity lets us know ahead of time we can make sure they are at the top of the list and we can be prepared for them.

Q. Would our Endpoint Security be a fit here and if so whom would we contact for next steps?

A. Endpoint Security alone would be outside of this Secure Email Solution RFP. By itself it would be a separate solution our local government entities would need to consider individually. We do encourage and will accept the offeror’s experience in determining any additional, optional services or solutions beyond the requirements of this RFP.

Q. Do you have an idea of how many entities our company will be working with?

A. The exact number of entities per awardee is unknown. We are establishing a pool of qualified state-approved contractors. The entities (city/county/municipality), in collaboration with SecureSD, will then select the IT

Vendor/Contractor that would work best for their specific needs. There are 66 counties and approximately 309 cities across South Dakota.

Per RFP Section 8.1: This RFP is intended to create a pool of contractors to select from. There is no guarantee that any offeror selected through this process will be invited to enter into contract with the State. Any individual contract entered into will contain a negotiated scope of work which may include all or any portion of the scope of work described herein.

Q. Are documentation/procedures/policies unique between entities, or are there central requirements that all must adhered to?

A. We require cybersecurity baselines, and best practices, along with adherence to local entity policies such as archiving and retention. If it is in the interest of the state and enhances cybersecurity, SecureSD may work with the awardees and collaboratively have central requirements, configurations, or settings.

820 N Washington Ave Madison SD 57042 Page 3

SecureSD will have common documentation/reporting requirements that all contractors must adhere to so we can aggregate the data into state/system wide reports.

Q. The Schedule of Activities doesn’t mention when questions are due, only RFP Explanation Meeting and Responses to Offeror’s Questions. Can you please confirm when questions are due to the State?

A. Questions can be submitted up and until the day before 07/01/2025. So a due date would be 6/30/25 and

07/01/25 is the day we will post all questions to the state’s official RFP portal at the Central Bid Exchange:

https://sourcing.esmsolutions.com/postingboard/entities/3444a404-3818-494f-84c5-2a850acd7779.

Note: You may submit your questions multiple times if you think of something while reviewing the RFP and working on your proposal. We do not want to hold up the progress on your proposal.

Q. Is the RFP Explanation Meeting mandatory?

A. No, it is not mandatory.

Q. What MS Office subscription will an entity need if they sign up for the new email platform?

A. Included with the licensing for the SecureSD’s Secure Email Solution will be full desktop versions of Office applications (Word, Excel, PowerPoint, Outlook, OneNote, Publisher, Access for PC only). It also includes the web versions of these apps. Also included will be all the core collaboration services: Exchange Online (for email), SharePoint Online, OneDrive for Business, Microsoft Teams, etc. Note Section 3.0.A in the RFP outlines the licensing requirements as:

• Procure & deploy required licensing:

o Avoid duplicate purchases of any licenses.

▪ Work with participating entities to balance any existing Microsoft licensing so SecureSD can append onto the expiration of existing licenses.

o Collaborate as needed with SecureSD on required licensing.

Q. Should ongoing phishing training be included?

A. Yes. Continued cybersecurity testing/training is valuable in keeping the human firewall updated and informed.

Per RFP Section 3.0.C

Create simulated phishing campaigns with link-based, attachment-based, and credential-based threats.

Q. Any preference for after-hours support? Is it weighted in any way?

A. All proposal evaluation criteria are listed in Section 6.0 of the RFP. We do not have an exact item for after-hours support. However, each evaluation criteria (Section 6.4) will be scored based on the proposals and are weighted as the state deems necessary to get the best pool of qualified contractors.

https://sourcing.esmsolutions.com/postingboard/entities/3444a404-3818-494f-84c5-2a850acd7779

820 N Washington Ave Madison SD 57042 Page 4

Q. Could South Dakota please confirm whether this is a new initiative or an existing engagement?

A. This specific project is a new initiative as part of the SecureSD program. (https://madlabs.dsu.edu/securesd/)

Q. Could South Dakota provide an estimated budget or a Not-to-Exceed (NTE) amount for this contract?

A. This project is one part of the SecureSD program. The SecureSD program if funded through the 2024 Senate

Bill 187 (https://sdlegislature.gov/Session/Bill/24622) which appropriated $7 million from the general fund to the South Dakota Attorney General’s Office, specifically Consumer Protection. These funds are dedicated to enhancing cybersecurity infrastructure and technology to safeguard the IT assets of local governments within South Dakota. Dakota State University is collaborating with Consumer Protection to develop and implement this program.

Q. Could South Dakota please provide the anticipated project timeline, including key milestones and the overall expected duration of the engagement?

A. Per the RFP Timeline Anticipated Award Decision/Contract Negotiation is 08/01/2025. We plan to have contractors start working as soon as possible.

RFP Section 1.1: The proposed contract will be in force until 4/30/28. After which, if no additional state funding is available, the participating entities will be responsible for the costs beyond the contract period and the successful offeror will be responsible for working out the continuity of the services.

Q. Could South Dakota please clarify whether it intends to award this RFP to a single vendor or multiple vendors? If multiple awards are anticipated, could South Dakota specify the expected number of vendors to be selected?

A. Please review RFP Section 1.1 and other sections for more details. It is not feasible to determine how many IT

Vendors may submit proposals. The number of selected contractors will be determined by what is in the best interest of the State of South Dakota.

RFP Section 8.1: This RFP is intended to create a pool of contractors to select from. There is no guarantee that any offeror selected through this process will be invited to enter into contract with the State. Any individual contract entered into will contain a negotiated scope of work which may include all or any portion of the scope of work described herein.

Q. How many entities are expected to participate initially, and what is the estimated total number of end-users over the life of the contract?

A. The exact number of entities per awardee is unknown. We are establishing a pool of qualified state-approved contractors. The entities (city/county/municipality), in collaboration with SecureSD, will then select the IT

Vendor/Contractor that would work best for their specific needs. There are 66 counties and approximately 309 cities across South Dakota.

Per RFP Section 8.1: This RFP is intended to create a pool of contractors to select from. There is no guarantee that any offeror selected through this process will be invited to enter into contract with the State. Any individual https://madlabs.dsu.edu/securesd/ https://sdlegislature.gov/Session/Bill/24622

820 N Washington Ave Madison SD 57042 Page 5 contract entered into will contain a negotiated scope of work which may include all or any portion of the scope

Q. Will each participating entity require its own Microsoft 365 GCC tenant, or is multi-tenant or shared tenant architecture allowed in specific cases

A. RFP Section 3.0.A.

Configure a Microsoft 365 Government Community Cloud (GCC) tenant for each entity.

Q. Are there existing Microsoft 365 or Exchange licenses in use by any of the entities? If yes, can you provide a breakdown by license type (e.g., G1, G3, G5, etc.)?

A. RFP Section 3.0.A:

• Procure & deploy required licensing:

o Avoid duplicate purchases of any licenses.

▪ Work with participating entities to balance any existing Microsoft licensing so SecureSD can append onto the expiration of existing licenses.

o Collaborate as needed with SecureSD on required licensing.

Q. How many of the participating entities are expected to require migration from legacy systems (e.g., Gmail, Yahoo, on-prem Exchange)?

A. The exact number of entities per awardee is unknown, therefore we can not determine how many. It is not a requirement to migrate from legacy systems. It is up to the contractor and the entity to determine the best method going forward. Some entities may start with a clean mailbox going forward, while other will want to transfer some or all of their legacy email.

RFP: Section 3.0.B Implementation & Onboarding

• Migration/Transition of existing entities email to new system.

o Utilize best efforts to transfer existing email.

o If tools exist to easily migrate old/past/existing email/contacts we will accept funding it.

o If tools do not exist, and it will take many (mutually agreed between contractor and SecureSD) hours we will not fund that.

Q. Is there a preferred migration tool (e.g., BitTitan, Quest) the state would like the vendor to use, or is that up to the vendor to propose?

A. An Offeror can propose any tool they plan to use as part of their RFP submission.

Q. What is the expected level of email migration support—full mailbox and calendar migration, or only current inbox items?

A. It is up to the contractor and the entity to determine the best method going forward. Some entities may start with a clean mailbox going forward, while other will want to transfer some or all of their legacy email.

RFP: Section 3.0.B Implementation & Onboarding

• Migration/Transition of existing entities email to new system.

o Utilize best efforts to transfer existing email.

820 N Washington Ave Madison SD 57042 Page 6 o If tools exist to easily migrate old/past/existing email/contacts we will accept funding it.

o If tools do not exist, and it will take many (mutually agreed between contractor and SecureSD) hours we will not fund that.

Q. Will SecureSD provide a unified onboarding schedule for all entities, or will each one be handled separately with its own timeline and onboarding plan?

A. The entities will be onboarded case-by-case according to the requirements of the SecureSD program and preparedness mutually agreed upon by the entity, contractor and the state.

Q. What level of support is expected—business hours only, or 24/7 coverage, especially for law enforcement and emergency departments?

A. We have asked the offerors to provide this information in their proposals. This will help the entities select the contractor that best fits their needs.

RFP Section 3.0.C. Monitoring, Management, and Ongoing Support

• Ongoing end-user support.

o Support Services:

▪ Helpdesk availability with tiered escalation.

▪ Provide the hours support services are available.

▪ Provide your plan for after-hours support.

▪ What is the waiting time for assistance?

Q. Are there minimum response time SLAs or escalation timelines expected for support (e.g., critical issues resolved within 1 hour)?

A. We have asked the offerors to provide this information in their proposals. This will help the entities select the contractor that best fits their needs.

RFP Section 3.0.C. Monitoring, Management, and Ongoing Support

• Ongoing end-user support.

o Support Services:

▪ Helpdesk availability with tiered escalation.

▪ Provide the hours support services are available.

▪ Provide your plan for after-hours support.

▪ What is the waiting time for assistance?

Q. What KPIs or metrics are required in the monthly/annual reports e.g., number of blocked phishing attempts, email volume, user MFA adoption rates, etc.?

A. These will be mutually determined between the state and the contractor.

RFP Section 3.0.C.

• Monitoring/Reporting/Deliverables: (To Entity and the State) o Email Policy Configuration Documentation per municipality.

o Meaningful activity reports:

▪ Monthly, annual, ad-hoc. covering multiple KPI’s as mutually determined.

• Based on what is available by the state and the contractor.

o All monitoring/reporting will be aggregated and granular to the individual entity

820 N Washington Ave Madison SD 57042 Page 7

▪ I.e. Total email volume (malicious, safe, spam, etc.), phishing attempts, quarantined messages, simulated phishing reports, any incident response, number of threats mitigated based on specific threats.

Q. What is the estimated budget for the contract?

A. This project is one part of the SecureSD program (https://madlabs.dsu.edu/securesd/). The SecureSD program is funded through the 2024 Senate Bill 187 (https://sdlegislature.gov/Session/Bill/24622) which appropriated $7 million from the general fund to the South Dakota Attorney General’s Office, specifically

Consumer Protection. These funds are dedicated to enhancing cybersecurity infrastructure and technology to safeguard the IT assets of local governments within South Dakota. Dakota State University is collaborating with Consumer Protection to develop and implement this program.

Q. Will submitting one copy of the proposal in either hardcopy or softcopy format be sufficient, or is the submission of both hardcopy and softcopy versions required?

A. Per the RFP both are required. Please review RFP Section 1.6.2 and follow the directions precisely as stated to avoid being disqualified.

Q. Is there any possibility for an extension to the proposal submission deadline, should vendors require additional time to prepare a comprehensive response?

A. No.

Q. Beyond the Microsoft 365 GCC and Defender for Office 365 Plan 2 requirements, are there any specific independent or third-party solutions (e.g., secure email gateways, archiving platforms, advanced threat protection tools) that the state or participating entities are looking to include or evaluate as part of this initiative?

A. RFP Section 3.0.D: Optional Services/Solutions.

Knowing the expertise of the industry and keeping pace with the changing threat landscape, we would entertain optional solutions or add-ons beyond the requirements. Be sure to separate these expenses from the requirements, unless they are included and noted in the overall cost.

Q. Do you require Microsoft 365 Government Community Cloud (GCC) licensing, or is Microsoft 365 GCC High required for this project?

A. Per RFP Section 3.0.A

The Secure Email Solution will be built using the minimum of a Microsoft 365 G3 license.

The offeror may propose anything above this minimum in their submission provided it covers all requirements of the RFP.

Q. The RFP mentions a minimum of Microsoft 365 G3 licenses with added security via Microsoft Defender for Office

365 Plan 2. Since G3 does not include Defender Plan 2 by default, should vendors plan to purchase Defender Plan 2 as a separate add-on, or would alternative bundled licenses (e.g., Microsoft 365 G5 ) that include Defender Plan 2 be acceptable?

https://madlabs.dsu.edu/securesd/ https://sdlegislature.gov/Session/Bill/24622

820 N Washington Ave Madison SD 57042 Page 8

A. Yes, G5 licenses will be acceptable as long as your proposal contains all the requirements (Per the RFP) and the costs are all associated with exactly what is in the technical solution proposed.

Q. Is it correct to understand that the requested email solution should include licensing, deployment, and management of Microsoft 365 (including security features like Defender for Office 365 Plan 2)? Or are you also seeking or open to independent third-party email security solutions (such as Check Point, Proofpoint, Mimecast, etc.)

in addition to or instead of Microsoft-native tools?

A. Yes, the solution will need to include all requirements in the RFP, specifically Section 3.0 Scope of Work. The other third-party solutions can be included in your proposal. Review RFP Section 3.0.D Optional

Services/Solutions for more details on how to add that to your proposal.

Can you provide an estimated total number of Microsoft 365 licenses or user seats that will be required across all participating entities, both initially and over the life of the contract?

A. The exact number of entities per awardee is unknown, therefore, the number of licenses is also unknown.

We are establishing a pool of qualified state-approved contractors. The entities (city/county/municipality), in collaboration with SecureSD, will then select the IT Vendor/Contractor that would work best for their specific needs. There are 66 counties and approximately 309 cities across South Dakota.

Per RFP Section 8.1: This RFP is intended to create a pool of contractors to select from. There is no guarantee that any offeror selected through this process will be invited to enter into contract with the State. Any individual contract entered into will contain a negotiated scope of work which may include all or any portion of the scope

820 N Washington Ave Madison SD 57042 Page 9

General RFP Proposal Format Questions:

Q. Just to clarify, do you want Sealed USB delivered to you again or is electronic submission via email sufficient?

A. Email submissions are not accepted and will be rejected. (RFP Section 1.6.2) We need one physical copy mailed to us – these should/must have the wet signatures (prefer blue ink) on them. Also, ensure the cost proposal is in a separate sealed envelope. Included in these post office mailing(s) would be the USB drive with one electronic copy of your proposal (or cost proposal in the separate envelope), any attachments, and ensure they are in the requested formats outlined in the RFP.

Q. Is it acceptable to send the printed copies and a USB flash drive containing the same document in both Word and

PDF format in the same envelope?

A. Yes.

Q. Should cost proposals be submitted as paper copies and one electronic copy on a USB drive (same as the technical proposal), but in a separate sealed envelope?

A. Yes, correct. Per the RFP (Section 1.6.2) the cost proposal must be submitted in a separate sealed envelope and labeled “Cost Proposal.”

Q. Can you please clarify that we will need to submit two totally separate sealed envelopes, containing the following:

Envelope 1: Technical proposal (everything but cost proposal)

• paper copies of technical proposal

• USB drive containing Word and PDF files of technical proposal

Envelope 2: Cost proposal(s), which contains info requested in Section 7.0 of the RFP.

• paper copies of cost proposal

• USB drive containing Word and PDF file of cost proposal

A. Yes, this is correct. If needed, your USB drive may also contain other common/standard file formats of attachments such as .jpg images, Excel files for cost proposal(s), etc.

Q. No signature is required on Appendix A at this time, correct?

A. Yes, correct. Appendix A is an example of what the contract will be. If the offeror has any questions, exceptions, or additions concerning Appendix A, they are expected to document the questions/exceptions in their proposal.

File details come from the government source that posted it. Updated .