RFI_51556_Event_management_Sotware.pdf
PDF 224 KB Posted
- Attached to
- Event Management Software -UPDATED State and local contract opportunity
- Solicitation number
- RFI 40100-51553
- Issued by
- Davidson County, Tennessee
About this file
The Tennessee Department of Transportation (TDOT) has issued a Request for Information (RFI) # 40100-51553 for an event management software solution to support two annual events: the Regional Equipment Operator's Safety and Training Conference (ROADEO) and the Tennessee Drone and Advanced Air Mobility Symposium. The RFI seeks a flexible, cutting-edge event platform similar to Cvent's conference management software, with an annual access license to enhance TDOT's event planning, marketing, and management processes. The RFI was issued on August 11, 2025, with key dates including a questions deadline of August 18, 2025, questions/answers posting on August 25, 2025, and a response deadline of September 8, 2025.
The software must provide comprehensive features including event registration and marketing, public-facing website management, mobile apps and onsite solutions, speaker and content management, and exhibitor and sponsor management. Key requirements include real-time registration, branded online experiences, payment processing, mobile check-in, agenda creation, speaker submission tools, and analytics reporting. The events typically attract approximately 900 attendees, with around 450 attendees per event. Respondents must comply with strict information technology security requirements, including housing all state data in the continental United States, maintaining SOC 2 Type 2 examination reports, performing annual penetration tests, and adhering to the state's enterprise information security policies.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_2.pdf | ||
| RFI_51556_Event_management_Sotware.pdf | ||
| Amendment_1_Event_Management_Software_RFI_40100-51553.pdf | ||
| RFI_51556_Event_management_Sotware.pdf | ||
| Amendment_1_Event_Management_Software_RFI_40100-51553.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATE OF TENNESSEE
DEPARTMENT OF TRANSPORTATION
REQUEST FOR INFORMATION
FOR
EVENT MANAGEMENT SOFTWARE
RFI # 40100-51553
August 11, 2025
1. STATEMENT OF PURPOSE:
The State of Tennessee, Department of Transportation ("TDOT" or "State") issues this Request for Information ("RFI") to understand marketplace for obtaining information that could assist the State in the development of a future solicitation for an event software management system or application and assess the ability of the event software management companies to meet State security requirements of a future solicitation and contract. We appreciate your input and participation in this process.
BACKGROUND:
The Tennessee Department of Transportation (TDOT) oversees transportation across Tennessee.
Its responsibilities encompass various transportation modes, including roadways, aviation, public transit, waterways, and railroads. Established in 1915 as the Tennessee Department of Highways and Public Works, the agency was renamed to its current title in 1972.
TDOT's core mission is to ensure a safe and reliable transportation system for people, goods, and services, thereby supporting economic prosperity in the state. Since 1998, TDOT has consistently ranked among the top five agencies nationwide for the quality of highway infrastructure.
TDOT's headquarters is in downtown Nashville, and the department operates four regional offices in Chattanooga, Jackson, Knoxville, and Nashville.
In support of its mission, vision, and values, TDOT organizes and helps organize several local, regional, and national conferences.
TDOT's primary objective, as outlined in this Request for Information Statement of Purpose above, is to assess event management software companies or publishers' capabilities and ability to meet State security requirements of a future solicitation to support two important annual events: the Regional Equipment Operator's Safety and Training Conference, commonly referred to as the "ROADEO," and the Tennessee Drone and Advanced Air Mobility Symposium.
To facilitate this initiative, TDOT seeks a flexible and cutting-edge software management company to provide an annual access license to a cutting-edge event platform similar to Cvent’s conference management software, which we have used in the past, to enhance TDOT's planning, marketing, and management efforts for both conferences by streamlining processes and improving the overall experience for potential attendees, resulting in a well-organized event.
The required features must include the following:
a. Event Registration & Marketing:
i. Collect real-time event registrations through branded online experiences.
ii. Send reminders.
iii. Create event agendas.
iv. Develop registration websites.
v. Implement marketing initiatives.
vi. Provide payment processing.
vii. Integrate with CRM systems.
viii. Multiple registration types with differentiated pricing (e.g., Gov/Edu, Non-Gov, Exhibitor, Sponsor).
ix. Support for promotional codes, bundled packages, and combination options.
x. Statement of non-refundable, non-transferable policy settings.
xi. Scheduled and segmented email campaigns.
xii. Registration reminders and personalized confirmations.
Embedded QR codes or mobile app download links in communication.
b. Public-Facing Website Management:
i. Ability to build and maintain a branded public-facing event website that supports homepage with rotating banners and dynamic content.
ii. Themed landing pages: About, Agenda, Hotel, Sponsors, Exhibitors, Speakers, Contact Us.
iii. Countdown clock widget capability.
iv. Embedded or linked registration functionality.
v. Graphic and media embedding (PDF sponsorship forms, images, speaker headshots, etc.).
vi. Linkage to external booking/reservation systems (e.g., hotel blocks).
c. Mobile Apps & Onsite Solutions:
i. Enhance accessibility with a mobile event app.
ii. Provide a seamless check-in and badging experience. Check-in via QR or NFC and onsite badge printing.
iii. Include appointment tools (e.g., attendee-to-attendee scheduling, or exhibitor meetings)
iv. Speaker, sponsor, and exhibitor directories.
v. In-app messaging and notifications.
d. Speaker & Content Management:
i. Gather content effortlessly and solicit submissions.
ii. Collaborate with speakers and sync easily into the event agenda.
iii. Provide customized submission forms.
iv. Maintain a review portal for submission scoring.
v. Automate acceptance and rejection processes.
vi. Maintain a centralized file/resource upload area for confirmed speakers.
vii. Speaker profile management (photo, name, title/org, bio).
viii. Agenda builder with filters (by date, track, session type).
Speaker-to-session linking and public agenda publishing.
e. Exhibitor & Sponsor Management:
i. Ensure exhibitors receive value by helping them streamline and automate tasks and communications.
ii. Create an exhibitor portal.
iii. Offer task management and reporting features.
iv. Maintain an event calendar and scheduling tools.
v. Facilitate staff registration.
vi. Capture and access leads.
vii. Online sponsor and exhibitor sign-up capability.
viii. Tiered sponsorship structure integration with custom benefits.
ix. Graphic upload (logos) and promotional material hosting.
x. Real-time exhibitor space availability tracking (e.g., 15 spots only).
f. Analytics and Reporting:
i. Real-time dashboards showing registration numbers by type.
ii. Session attendance tracking.
iii. Sponsor/exhibitor engagement metrics.
iv. Exportable reports for all data points.
This comprehensive approach will contribute to the success of TDOT's events, which, on average, attract approximately 900 attendees, with around 450 attendees at each event.
COMMUNICATIONS:
1.1. Please submit your response to this RFI to:
Kenny Weaver, Procurement and Contracts Division Tennessee Department of Transportation James K Polk Building, 5th Floor 505 Deadrick St, Nashville, TN 37243 TDOT.RFP@tn.gov
1.2. Please feel free to contact the Tennessee Department of Transportation with any questions regarding this RFI. The main point of contact will be:
Kenny Weaver, Procurement and Contracts Division Tennessee Department of Transportation James K Polk Building, 5th Floor 505 Deadrick St, Nashville, TN 37243 TDOT.RFP@tn.gov
1.3. Please reference RFI # 40100-51553 with all communications to this RFI
2. RFI SCHEDULE OF EVENTS:
EVENT
TIME
(Central Time Zone)
DATE
(all dates are State business days)
1. RFI Issued August 11, 2025
2. RFI Questions Deadline 4:00 p.m. August 18, 2025
3. RFI Questions/Answers Posted 4:00 p.m. August 25, 2025
4. RFI Response Deadline 4:00 p.m. September 8, 2025 mailto:TDOT.RFP@tn.gov mailto:TDOT.RFP@tn.gov
3. GENERAL INFORMATION:
3.1. Responding to this RFI is a prerequisite for responding to any future solicitations related to this project. Responses to this RFI will not create any contract rights and responses to this RFI will become property of the State.
3.1.1. All Respondents will be required to provide a signed written response from their legal counsel, or Chief Executive Officer, either confirming Respondent’s ability or describing Respondent’s inability to comply with the requirements set forth in Attachment A.
3.1.2. The specific Recovery Time Objective (RTO) and Recovery Point Objective (RPO) periods referenced in the Information Technology Security Requirements clause of Attachment A will be negotiated and determined between the vendor and the State for the particular contract based on the priority of the service.
3.2. The information gathered during this RFI is part of an ongoing procurement. In order to prevent an unfair advantage among potential respondents, the RFI responses will not be available until after the completion of evaluation of any responses, proposals, or bids resulting from a Request for Qualifications, Request for Proposals, Invitation to Bid or other procurement methods. In the event that the state chooses not to go further in the procurement process and responses are never evaluated, the responses to the procurement including the responses to the RFI, will be considered confidential by the State.
3.3. The State will not pay for any costs associated with responding to this RFI.
4. INFORMATIONAL FORMS:
The State is requesting the following information from all interested parties. Attachment A are being provided as information only for the Respondent to provide an informed response . Please provide the following information:
RFI # 40100-51553
TECHNICAL INFORMATIONAL FORM
1. RESPONDENT LEGAL ENTITY NAME:
2. RESPONDENT CONTACT PERSON:
Name, Title:
Address:
Phone Number:
Email:
3. Provide a description of Respondent experience with providing event software management applications, specifically for government transportation departments, including the proposed solution and how it assisted another government entity with a similar need. If the Respondent is not the service vendor, please clarify the nature of the Respondent relationship with the vendor.
4. Provide an overview of the capabilities of the Respondent’s proposed conference management solutions based on the statement of purpose and background sections.
5. Provide a brief overview describing the pre and pos implementation services Respondent provides. Include information regarding customizing the service and how long implementation will take, if applicable.
6. If Contractor cannot meet the following requirement specified in Attachment A, “The Contractor shall ensure that all State Data is housed in the continental United States, inclusive of backup data. All State data must remain in the United States, regardless of whether the data is processed, stored, in-transit, or at rest. Access to State data shall be limited to US-based (onshore) resources only”, provide the name of the host country(ies) where any data may be processed or stored, in-transit, or at rest.
7. Provide a signed written response from their legal counsel, or Chief Executive Officer, either confirming Respondent’s ability or describing Respondent’s inability to comply with the requirements set forth in Attachment A.
COST INFORMATIONAL FORM
1. Describe what pricing units you typically utilize for similar services or goods (e.g., per hour, each, etc.:
2. Describe the typical price range for similar services or goods
ADDITIONAL CONSIDERATIONS
1. Please provide input on alternative approaches or additional things to consider that might benefit the State:
ATTACHMENT A
NOTABLE TERMS AND CONDITION REQUIREMENTS
(This is not representative of all State Terms and Conditions, but reflects ones that the State requires acknowledgement of respondents ability, or inability, to comply for inclusion in a future procurement for services referenced in this RFI.)
Comptroller Audit Requirements
Comptroller Audit Requirements.
When requested by the State or the Comptroller of the Treasury, the Contractor must provide the State or the Comptroller of the Treasury with a detailed written description of the Contractor’s information technology control environment, including a description of general controls and application controls. The Contractor must also assist the State or the Comptroller of the Treasury with obtaining a detailed written description of the information technology control environment for any third or fourth parties, or Subcontractors, used by the Contractor to process State data and/or provide services under this Contract.
Contractor will maintain and cause its Subcontractors to maintain a complete audit trail of all transactions and activities in connection with this Contract, including all information technology logging and scanning conducted within the Contractor’s and Subcontractor’s information technology control environment. Upon reasonable notice and at any reasonable time, the Contractor grants the State or the Comptroller of the Treasury with the right to audit the Contractor’s information technology control environment, including general controls and application controls. The audit may include testing the general and application controls within the Contractor’s information technology control environment and may also include testing general and application controls for any third or fourth parties, or Subcontractors, used by the Contractor to process State data and/or provide services under this Contract. The audit may include the Contractor’s and Subcontractor’s compliance with the State’s Enterprise Information Security Policy and all applicable requirements, laws, regulations, or policies.
Upon reasonable notice and at any reasonable time, the Contractor and Subcontractor(s) agree to allow the State, the Comptroller of the Treasury, or their duly appointed representatives to perform information technology control audits of the Contractor and all Subcontractors used by the Contractor. Contractor will provide to the State, the Comptroller of the Treasury, or their duly appointed representatives access to Contractor and Subcontractor(s) personnel for the purpose of performing the information technology control audit. The audit may include interviews with technical and management personnel, physical or virtual inspection of controls, and review of paper or electronic documentation.
The Contractor must have a process for correcting control deficiencies that were identified in the State’s or Comptroller of the Treasury’s information technology audit. For any audit issues identified, the Contractor and Subcontractor(s) shall submit a corrective action plan to the State or the Comptroller of the Treasury which addresses the actions taken, or to be taken, and the anticipated completion date in response to each of the audit issues and related recommendations of the State or the Comptroller of the Treasury. The corrective action plan shall be provided to the State or the Comptroller of the Treasury upon request f rom the State or Comptroller of the Treasury and within 30 days f rom the issuance of the audit report or communication of the audit issues and recommendations. Upon request f rom the State or Comptroller of the Treasury, the Contractor and Subcontractor(s) shall provide documentation and evidence that the audit issues were corrected.
Each party shall bear its own expenses incurred while conducting the information technology controls audit.
Information Technology Security Requirements (State Data, Audit, and Other Requirements).
a. The Contractor shall protect State Data as follows:
(1) The Contractor shall ensure that all State Data is housed in the continental United States, inclusive of backup data. All State data must remain in the United States, regardless of whether the data is processed, stored, in-transit, or at rest. Access to State data shall be limited to US-based (onshore) resources only.
All system and application administration must be performed in the continental United States.
Configuration or development of software and code is permitted outside of the United States. However, software applications designed, developed, manufactured, or supplied by persons owned or controlled by, or subject to the jurisdiction or direction of, a foreign adversary, which the U.S. Secretary of Commerce acting pursuant to 15 CFR 7 has defined to include the People’s Republic of China, among others are prohibited. Any testing of code outside of the United States must use fake data. A copy of production data may not be transmitted or used outside the United States.
(2) The Contractor shall encrypt Confidential State Data at rest and in transit using the current version of Federal Information Processing Standard (“FIPS”) 140-2 or 140-3 (or current applicable version) validated encryption technologies. The State shall control all access to encryption keys. The Contractor shall provide installation and maintenance support at no cost to the State.
(3) The Contractor and any Subcontractor used by the Contractor to host State data, including data center vendors, shall be subject to an annual engagement by a licensed CPA f irm in accordance with the standards of the American Institute of Certified Public Accountants (“AICPA”) for a System and Organization Controls for service organizations (“SOC”) 2 Type 2 examination. The scope of the SOC 2 Type 2 examination engagement must include the Security, Availability, Confidentiality, and Processing Integrity Trust Services Criteria. In addition, the Contractor services that are part of this Contract, including any processing or storage services, must be included in the scope of the SOC 2 Type 2 examination engagement(s).
(4) The Contractor must annually review its SOC 2 Type 2 examination reports. Within 30 days of receipt of the examination report, or upon request f rom the State or the Comptroller of the Treasury, the Contractor must provide the State or the Comptroller of the Treasury a non-redacted copy of the Contractor’s SOC 2 Type 2 examination report(s). The Contractor must review the annual SOC 2 Type 2 examination reports for each of its Subcontractors and must also assist the State or Comptroller of the Treasury with obtaining a non-redacted copy of any SOC examination reports for each of its Subcontractors, including data centers used by the Contractor to host or process State data.
If the Contractor’s SOC 2 Type 2 examination report includes a modified opinion, meaning that the opinion is qualified, adverse, or disclaimed, the Contractor must share the SOC report and the Contractor’s plan to address the modified opinion with the State or the Comptroller of the Treasury within 30 days of the Contractor’s receipt of the SOC report or upon request from the State or the Comptroller of the Treasury. If any Subcontractor(s) SOC 2 Type 2 examination report includes a modified opinion, the Contractor must assist the State or Comptroller of the Treasury with obtaining the Subcontractor(s) SOC report and the Subcontractor(s) plan to address the modified opinion.
The Contractor must have a process for correcting control deficiencies that were identified in the SOC 2 Type 2 examination, including follow-up documentation providing evidence of such corrections. Within 30 days of receipt of the examination report, or upon request from the State or the
Comptroller of the Treasury, the Contractor must provide the State or the Comptroller of the Treasury with a corrective action plan and evidence of correcting the control deficiencies. The Contractor must require each of its Subcontractors, including data centers used by the Contractor to host State data, to have a process for correcting control deficiencies identified in their SOC examination reports and must assist the State or Comptroller of the Treasury with obtaining a corrective action plan and obtaining evidence of correcting control deficiencies identified in Subcontractor(s) SOC reports.
No additional funding shall be allocated for these examinations as they are included in the Maximum Liability of this Contract.
(5) The Contractor must annually perform Penetration Tests and Vulnerability Assessments against its Processing Environment per the NIST 800-115 definition. “Processing Environment” shall mean the combination of software and hardware on which the Application runs.
“Application” shall mean the computer code that supports and accomplishes the State’s requirements as set forth in this Contract. “Penetration Tests” shall be in the form of attacks on the Contractor’s computer system, with the purpose of discovering security weaknesses which have the potential to gain access to the Processing Environment’s features and data. The “Vulnerability Assessment” shall be designed and executed to define, identify, and classify the security holes (vulnerabilities) in the Processing Environment. The Contractor shall allow the
State, at its option, to perform Penetration Tests and Vulnerability Assessments on the Processing Environment. The Contractor shall provide a letter of attestation on its processing environment that penetration tests and vulnerability assessments has been performed on an annual basis and taken corrective action to evaluate and address any findings.
In the event of an unauthorized disclosure or unauthorized access to State data, the State Strategic Technology Solutions (STS) Security Incident Response Team (SIRT) must be notified and engaged by calling the State Customer Care Center (CCC) at 615-741-1001. Any such event must be reported by the Contractor within twenty-four (24) hours after the unauthorized disclosure has come to the attention of the Contractor.
(6) If a breach has been confirmed a fully un-modified third-party forensics report must be supplied to the State and through the STS SIRT. This report must include indicators of compromise (IOCs) as well as plan of actions for remediation and restoration. Contractor shall take all necessary measures to halt any further Unauthorized Disclosures.
(7) Upon State request, the Contractor shall provide a copy of all Confidential State Data it holds.
The Contractor shall provide such data on media and in a format determined by the State
(8) Upon termination of the Contract and in consultation with the State, the Contractor shall destroy, and ensure all subcontractors shall destroy, all Confidential State Data it holds (including any copies such as backups) in accordance with the current version of National Institute of Standards and Technology (“NIST”) Special Publication 800-88. The Contractor shall provide a written confirmation of destruction to the State within ten (10) business days after destruction.
b. Minimum Requirements
(1) The Contractor and all data centers used by the Contractor to host State data, including those of all Subcontractors, must comply with the State’s Enterprise Information Security Policies as amended periodically. The State’s Enterprise Information Security Policies document is found at the following URL:
https://www.tn.gov/finance/strategic-technology-solutions/strategic-technology-solutions/sts-security-policies.html.
(2) The Contractor agrees to maintain the Application so that it will run on a current, manufacturer-supported Operating System. “Operating System” shall mean the software that supports a computer's basic functions, such as scheduling tasks, executing applications, and controlling peripherals.
(3) If the Application requires middleware or database software, Contractor shall maintain middleware and database software versions that are always fully compatible with current versions of the Operating System and Application to ensure that security vulnerabilities are not introduced.
(4) In the event of drive/media failure, if the drive/media is replaced, it remains with the State https://www.tn.gov/finance/strategic-technology-solutions/strategic-technology-solutions/sts-security-policies.html https://www.tn.gov/finance/strategic-technology-solutions/strategic-technology-solutions/sts-security-policies.html https://www.tn.gov/finance/strategic-technology-solutions/strategic-technology-solutions/sts-security-policies.html and it is the State’s responsibility to destroy the drive/media, or the Contractor shall provide written confirmation of the sanitization/destruction of data according to NIST 800-88.
c. Business Continuity Requirements. The Contractor shall maintain s et(s) of documents, instructions, and procedures which enable the Contractor to respond to accidents, disasters, emergencies, or threats without any stoppage or hindrance in its key operations (“Business Continuity Requirements”). Business Continuity Requirements shall include:
(1) “Disaster Recovery Capabilities” refer to the actions the Contractor takes to meet the Recovery
Point and Recovery Time Objectives defined below. Disaster Recovery Capabilities shall meet the following objectives:
i. Recovery Point Objective (“RPO”). The RPO is defined as the maximum targeted period in which data might be lost f rom an IT service due to a major incident
Eight (8) Hour
ii. Recovery Time Objective (“RTO”). The RTO is defined as the targeted duration of time and a service level within which a business process must be restored after a disaster (or disruption) in order to avoid unacceptable consequences associated with a break in business continuity:
Sixteen (16) hours
(2) The Contractor and the Subcontractor(s) shall maintain a documented Disaster Recovery plan and shall share this document with the State when requested. The Contractor and the Subcontractor(s) shall perform at least one Disaster Recovery Test every three hundred sixty - f ive
(365) days. A “Disaster Recovery Test” shall mean the process of verifying the success of the restoration procedures that are executed after a critical IT failure or disruption occurs. The Disaster Recovery Test shall use actual State Data Sets that mirror production data, and success shall be defined as the Contractor verifying that the Contractor can meet the State’s RPO and RTO requirements. A “Data Set” is defined as a collection of related sets of information that is composed of separate elements but can be manipulated as a unit by a computer. The Contractor shall provide written confirmation to the State after each Disaster Recovery Test that its Disaster Recovery Capabilities meet the RPO and RTO requirements.
File details come from the government source that posted it. Updated .