RFQ 36C10A25Q0071.pdf
PDF 788 KB Posted
- Attached to
- DA01--Gimmal Physical Software Annual Maintenance and Technical Support Federal contract opportunity
- Solicitation number
- 36C10A25Q0071
About this file
This Request for Quotation (RFQ) 36C10A25Q0071 is for Gimmal Physical Software Annual Maintenance and Technical Support from the Department of Veterans Affairs Technology Acquisition Center. The solicitation seeks a contractor to provide annual maintenance, technical support, patches, bug fixes, and updates for VA's existing Gimmal Physical Software perpetual license, with a base period from August 15, 2025 to August 14, 2026 and three optional 12-month extension periods through August 14, 2029. The contract includes up to 40 hours of programmer labor per performance period for VA-requested custom enhancements, with a government not-to-exceed ceiling that increases slightly each option year (starting at $10,000 in the base period).
The solicitation is unrestricted and has a NAICS code of 541519 with a size standard of $34 million. Key contract requirements include providing software updates via download, offering unlimited technical support during normal business hours (Monday-Friday, 8:00 AM to 5:00 PM CST), and meeting specific response time requirements for technical support issues ranging from one hour for production site outages to one week for general information requests. The contractor must also provide email notifications of software updates and incident documentation, and comply with various VA cybersecurity, accessibility, and information technology standards.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| JA_Redacted.pdf | ||
| 36C10A25Q0071.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 1. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. UEI: EFT:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
36C10A25Q0071 7/29/2025
Brianna Feaster 848-377-5084 8/5/2025
8AM EDT
36C10A Department of Veterans Affairs Technology Acquisition Center Procurement Service G 23 Christopher Way Eatontown NJ 07724
541519
$34M
N/A
X
See Schedule
36C10A
Department of Veterans Affairs Technology Acquisition Center Procurement Service G
Department of Veteran Affairs Financial Services Center P.O. Box 149971 Austin TX 78714-8971 See website at http://www.fsc.va.gov/einvoice.asp
(877) 353-9791
See CONTINUATION Page
Project Title: Gimmal Physical Software Annual Maintenance and Technical Support
See Section B.1 – Schedule of Supplies/Services
See Continuation Pages
See CONTINUATION Page
X X
LORI L. WALKER
Request for Quotation: 36C10A25Q0071
SECTION B - CONTINUATION OF SF 1449 BLOCKSB
B.1 SCHEDULE OF SUPPLIES AND SERVICES
19.
ITEM #
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22. UNIT 23. UNIT
PRICE
24. AMOUNT
Gimmal Physical Software Annual Maintenance and Technical Support - All services shall be in accordance with (IAW) the Performance Work Statement (PWS) as set forth in Section B.4 of this solicitation.
Inspection/Acceptance: Destination
Product Service Code (PSC): DA01 - For all Contract Line Item Numbers (CLIN) unless otherwise noted.
Delivery Address/Point of Contact:
To be provided at award.
Base Period
Period of Performance: August 15, 2025 – August 14, 2026
ARM: TBD
Integrated Financial and Acquisition Management System (iFAMS) Obligation Number:
To be determined (TBD)
0001 Annual Maintenance and
Technical Support for Gimmal Physical Software
The Contractor shall provide patches, bug fixes, updates and enhancements released during the period of performance to support VA’s existing Brand Name Gimmal Physical Software perpetual license and technical support in accordance with the PWS.
1 Each
(EA) $________ $________
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22. UNIT 23. UNIT
PRICE
24. AMOUNT
0002 Programmer Labor
NTE 40 hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs.
Invoicing shall be in accordance with FAR 52.212-4 Alternate I, “Contract Terms and Conditions-Commercial Items”.
Government Not to Exceed Ceiling:
$10,000.00 + Fixed Handling Rate % = NTE Ceiling $________ (Inclusive of Government NTE ceiling + Fixed Handling Rate)
1 Lot (LT) $_______ $_______
0003 Deliverables:
1 EA NSP NSP
0003AA Email notification to VA PM and VA COR as software updates and patches are released.
1 EA NSP NSP
0003AB Email documentation for each VA reported incident in accordance with response times shown in PWS Section 4.1 until resolved.
1 EA NSP NSP
TOTAL BASE PERIOD: $
Option Period One
Period of Performance: August 15, 2026 – August 14, 2027
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22. UNIT 23. UNIT
PRICE
24. AMOUNT
1001 Annual Maintenance and
Physical Software
The Contractor shall provide patches, bug fixes, updates and enhancements released during the period of performance to support VA’s existing Brand Name Gimmal Physical Software perpetual license
1002 Programmer Labor
NTE 40 hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs.
Invoicing shall be in accordance with FAR 52.212-4 Alternate I, “Contract Terms and Conditions-Commercial Items”.
Government Not to Exceed Ceiling:
$10,700.00 + Fixed Handling Rate % = NTE Ceiling $________
1003 Deliverable:
1 EA NSP NSP
1003AA Email notification to VA PM and VA
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22. UNIT 23. UNIT
PRICE
24. AMOUNT
1003AB Email documentation for each VA reported incident in accordance with response times shown in PWS Section 4.1 until resolved.
1 EA NSP NSP
TOTAL OPTION PERIOD ONE: $
Option Period Two
Period of Performance: August 15, 2027 – August 14, 2028
2001 Annual Maintenance and
Physical Software
The Contractor shall provide patches, bug fixes, updates and enhancements released during the period of performance to support VA’s existing Brand Name Gimmal Physical Software perpetual license
2002 Programmer Labor
NTE 40 hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs.
Invoicing shall be in accordance with FAR 52.212-4 Alternate I, “Contract Terms and Conditions-Commercial Items”.
Government Not to Exceed Ceiling:
$11,449.00 + Fixed Handling Rate %
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22. UNIT 23. UNIT
PRICE
24. AMOUNT
= NTE Ceiling $________
2003 Deliverable:
2003AA Email notification to VA PM and VA
2003AB Email documentation for each VA reported incident in accordance with response times shown in PWS Section 4.1 until resolved.
1 EA NSP NSP
TOTAL OPTION PERIOD TWO: $
Option Period Three
Period of Performance: August 15, 2028 – August 14, 2029
3001 Description
Annual Maintenance and
Physical Software
The Contractor shall provide patches, bug fixes, updates and enhancements released during the period of performance to support VA’s existing Brand Name Gimmal Physical Software perpetual license
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22. UNIT 23. UNIT
PRICE
24. AMOUNT
3002 Programmer Labor
NTE 40 hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs.
Invoicing shall be in accordance with FAR 52.212-4 Alternate I, “Contract Terms and Conditions-Commercial Items”.
Government Not to Exceed Ceiling:
$12,250.64.00 + Fixed Handling Rate % = NTE Ceiling $________
3003 Deliverable:
1 EA NSP NSP
3003AA Email notification to VA PM and VA
3003AB Email documentation for each VA reported incident in accordance with response times shown in PWS Section 4.1 until resolved.
1 EA NSP NSP
TOTAL OPTION PERIOD THREE: $
TOTAL ORDER VALUE, INCLUSIVE OF OPTIONS: $___________
Governing Law (continuation of Schedule of Supplies and Services above):
Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S.
Department of Justice (DOJ in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.
SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:
(1) Definitions.
a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”
b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.
c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.
d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.
e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.
f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.
g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).
(2) Software License.
a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.
b) The Government may use the software in a networked environment.
c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).
d) All limitations of software usage are expressly stated in the Schedule of
Supplies/Services and the Performance Work Statement/Product Description.
(3) Software Maintenance and Technical Support.
a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.
b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.
c) Any telephone support provided by Contractor shall be at no additional cost.
d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work
Statement or Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.cpars.gov).
e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.
(4) Disabling Software Code.
The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software.
Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.
(5) Manuals and Publications.
Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.
B.2 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR: See Block 17a.
b. GOVERNMENT: Contracting Officer 36C10A
Department of Veterans Affairs Technology Acquisition Center – Procurement Service G http://www.cpars.gov/
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[] 52.232-36, Payment by Third Party
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly []
b. Semi-Annually []
c. Other [X] Delivery, Inspection and Acceptance
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.
See website at:
http://www.fsc.va.gov/einvoice.asp
ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
AMENDMENT NO DATE
B.3 ACCOUNTING AND APPROPRIATION DATA
Funds in the amount of $TBD are obligated in iFAMS Obligation Number TBD to pay for Services (PSC DA10) on CLIN 0001-0002. Each invoice should reference the iFAMS Obligation Number TBD and associated CLINs/SLINs.
http://www.fsc.va.gov/einvoice.asp
B.4 PERFORMANCE WORK STATEMENT
Performance Work Statement
DEPARTMENT OF VETERANS AFFAIRS
Financial Services Center Records Center & Vault (RCV)
Gimmal Physical Software Annual Maintenance and Technical Support
Date: July 23, 2025
VA-25-00069791
PWS Version Number: 1.0
1.0 DESCRIPTION OF SERVICES
The VA Records Center and Vault (RCV) has a requirement to renew annual support for Gimmal Physical Software Annual Maintenance and Technical Support currently in VA’s production environment. The software tracks the warehouse locations for 1.8 million boxes of records, the box and folder retrievals made by approximately 1,000 VHA employee/contractor users, and stores electronic documents (eDocs) in PDF format associated with box disposition. Movement of boxes and files is captured using untethered android hand-held scanners with data transfer completed via USB connection since the RCV’s subterranean warehouse is without Wi-Fi capabilities.
The platform is VA-Intranet/Cloud based. Contractor support for the VA’s Gimmal Physical perpetual license with eDocs, PortableConnect and billing features includes access to all patches, bug fixes, updates and enhancements released during the performance period, and unlimited telephone technical support during normal hours of operation: Monday through Friday, 8:00 AM to 5:00 PM, Central Standard Time, excluding Federal holidays. Contractor updates/enhancements shall be made available for download via Gimmal’s website, or other VA-approved transfer method.
2.0 APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. “Federal Information Security Modernization Act of 2014”
2. Federal Information Processing Standards (FIPS) Publication 140-3, “Security Requirements for Cryptographic Modules”, March 22, 2019
3. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004
4. FIPS Pub 200, “Minimum Security Requirements for Federal Information and
Information Systems,” March 2006
5. FIPS Pub 201-3, “Personal Identity Verification of Federal Employees and
Contractors,” January 2022
6. 10 U.S.C. § 2224, "Defense Information Assurance Program", as amended
7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
8. Public Law 109-461 (P.L. 109-461), Veterans Benefits, Health Care, and
Information Technology Act of 2006, as amended, Title IX, Information Security Matters
9. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”, as amended
10. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm
11. VA Handbook 0710, Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm
12. VA Directive 6102, “Internet/Intranet Services,” August 5, 2019 https://www.va.gov/vapubs/index.cfm https://www.va.gov/vapubs/index.cfm
13. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” as amended
14. OMB Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
15. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended
16. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
17. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021 (see VA
NOTICE 24-18, dated September 27, 2024, “Update to VA Directive 6500 Cybersecurity Program”, and VA Notice 25-07, dated 3/18/25, “Amending VA Directive 6500 to incorporate M-24-15”)
18. VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021 (see VA Notice 25-01, dated October 15, 2024, “Update to VA Handbook 6500 Risk Management Framework for VA Information Systems VA Information Security Program”, and VA Notice 25-06, dated 3/18/25, “Amending VA Directive 6500 to incorporate M-24-15”)
19. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” June 30, 2023
20. VA Handbook 6500.6, “Contract Security,” March 12, 2010 (see VA Notice 24-12, dated April 22, 2024, “Update to VA Handbook 6500.6, Contract Security, Appendix C VA Information and Information System Security/Privacy Language For Inclusion Into Contracts, As Appropriate”)
21. VA Handbook 6500.8, “Information System Contingency Planning,” March 25, 2025
22. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018
23. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017
24. OIT Process Asset Library (PAL), OIT Process Asset Library.
25. One VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
26. VA Directive 6508, “Implementation of Privacy Threshold Analysis and VA
Privacy Impact Assessment,” October 15, 2014
27. VA Directive 6510, “VA Identity, Credential and Access Management,”
September 3, 2024
28. VA Handbook 6510, “VA Identity, Credential and Access Management,”
September 27, 2024
29. VA Directive and Handbook 6513, “Secure External Connections,” October
12, 2017
30. VA Directive 6300, “Records and Information Management,” September 21,
31. VA Handbook, 6300.1, “Records Management Procedures,” March 24, 2010
32. NIST SP 800-37 Rev 2, “Risk Management Framework for Information
Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018 https://digital.va.gov/process-asset-library/ https://www.va.gov/trm/TRMHomePage.aspx
33. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)
34. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015
35. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-
12) Program,” March 24, 2014
36. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005
37. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019
38. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008
39. Federal Identity, Credential, and Access Management (FICAM) Architecture, June 20, 2023 (FICAM Architecture (idmanagement.gov))
40. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,” June 2018
41. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020
42. Draft NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December
43. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514
44. IAM Identity Management Business Requirements Guidance document, May 2013, (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
45. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896
46. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents
47. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019
48. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008
49. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
50. “Veteran Focused Integration Process (VIP) Guide 4.0,” March 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
51. VA Memorandum “Proper Use of Email and Other Messaging Services,”
January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
52. “Product Line Management Transformation Playbook” version 3.1, August 2023, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946 https://www.idmanagement.gov/arch/#:%7E:text=FICAM%20is%20the%20federal%20government%E2%80%99s%20enterprise%20approach%20to,identity%20processes%2C%20practices%2C%20policies%2C%20and%20information%20security%20disciplines.
https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://www.cisa.gov/publication/tic-30-core-guidance-documents https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946
53. NIST SP 500-267B Revision 1, ”USGv6 Profile,” November 2020
54. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol
Version 6 (IPv6),“ November 19, 2020
55. Social Security Number (SSN) Fraud Prevention Act of 2017
56. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23,
57. C.F.R Title 15 Part 7, “Securing the Information and Communications
Technology and Services (ICTS) Supply Chain”, as amended
58. Executive Order 14028, “Executive Order on Improving the Nation's
Cybersecurity,” May 12, 2021, https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/
59. OMB Memorandum M-22-09, “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles”, January 26, 2022, https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf.
60. NIST SP 800-52 Revision 2, “Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations
61. OMB M-22-18, “Enhancing the Security of the Software Supply Chain through Secure Software Development Practices,” September 14, 2022
62. OMB M-23-16, “Update to Memorandum M-22-18,” June 9, 2023
63. OMB M-21-31, “Improving the Federal Government’s Investigative and
Remediation Capabilities Related to Cybersecurity Incidents,” August 27,
64. NIST SP 800-88 Revision 1 “Guidelines for Media Sanitization,” December
65. VA Memorandum, “VA Security Controls”, January 17, 2025, https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010
3.0 PERFORMANCE DETAILS
3.1 PERFORMANCE PERIOD
The period of performance is 12 months from August 15, 2025 through August 14, 2026 and includes three 12-month option periods:
Description Quantity Base Period – Annual Support for Gimmal Physical Records Management Software Period of Performance: August 15, 2025 – August 14, 1 Each
Option Period One (1) – Annual Support for Gimmal Physical Records Management Software Period of Performance: August 15, 2026 – August 14, https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/ https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/ https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/ https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010
3.2 PLACE OF PERFORMANCE
All contractor support shall be provided by telephone or VA approved virtual method such as MS Teams, during regular business hours Monday through Friday, 8:00 AM to 5:00 PM Central Standard Time (CST), excluding federal holidays.
4.0 SPECIFIC TASKS AND DELIVERABLES
The Contractor shall provide the following:
All patches, bug fixes, updates and enhancements released during the performance period. Availability is via download from the official Gimmal website, or other VA pre-approved transfer method.
Unlimited technical support via telephone or VA-approved virtual method such as MS Teams during normal business hours: Monday through Friday, 8:00 AM to 5:00 PM, Central Standard Time (CST) excluding federal holidays.
Minimum acceptable initial response & update frequency timeframes to VA written requests for technical support from Financial Services Center (FSC) system application managers, the VA Project Manager (PM) or VA Contracting Officer’s Representative (COR) are:
• Production site is down: One (1) hour and daily
• Production is severely impacted: Four (4) hours and daily
• Production is minimally Impacted: One (1) day and weekly
• General requests for information or enhancements: One (1) week and weekly
Up to forty (40) optional contractor programmer hours during each performance period for VA-requested custom enhancements to support the unique operational needs of the RCV (e.g., reports, forms, barcode label formats, etc.). If utilized, the VA will provide
Option Period Two (2) – Annual Support for Gimmal Physical Records Management Software Period of Performance: August 15, 2027 – August 14, Option Period Three (3) – Annual Support for Gimmal Physical Records Management Software Period of Performance: August 15, 2028 – August 14, contractor a written request outlining required output(s)/outcome(s). Contractor response shall include a brief description and labor hour estimate to satisfy the request with anticipated delivery timeframe. The VA Project Manager and VA COR will confirm acceptance in writing to proceed. Contractor’s delivery method and technical support for custom projects shall mirror those for routine enhancements outlined in the first two paragraphs this PWS section 4.0 Specific Tasks and Deliverables.
Description Quantity Base Period – Not to Exceed (NTE)Forty (40) hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs.
Period of Performance: August 15, 2025 – August 14, 40 Hours
Option Period One (1) – NTE Forty (40) hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs. Period of Performance: August 15, 2026 – August 14, 2027
40 Hours
Option Period Two (2) – NTE Forty (40) hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs.
Period of Performance: August 15, 2027 – August 14, 40 Hours
Option Period Three (3) – NTE Forty (40) hours programmer labor for VA-requested enhancements to support unique agency/facility operational needs.
Period of Performance: August 15, 2028 – August 14, 40 Hours
4.1 REPORTING REQUIREMENTS
Contractor shall notify VA Program Manager (PM) and VA COR (COR) in writing as new Gimmal Physical software application patches/system updates are published for download.
Contractor shall provide written response to VA system application managers, the VA PM and/or VA COR to requests for technical assistance and general inquiries as follows until reported issues are resolved:
• Production site is down: One (1) hour and daily
• Production is severely impacted: Four (4) hours and daily
• Production is minimally Impacted: One (1) day and weekly
• General requests for information or enhancements: One (1) week and weekly
Deliverable(s):
A. Email notification to VA PM and VA COR as software updates and patches are released.
B. Email documentation for each VA reported incident in accordance with response times shown in PWS Section 4.1 until resolved.
5.0 GENERAL REQUIREMENTS
5.1 ENTERPRISE AND IT FRAMEWORK
5.1.1 VA TECHNICAL REFERENCE MODEL
The Contractor shall comply with the VA OIT Technical Reference Model (VA TRM).
Compliance with the VA TRM is achieved by using only technologies and standards that are listed as approved for use in the VA TRM. The Contractor shall provide all necessary information requested by VA to ensure TRM approval is obtained prior to use on VA’s network.
5.1.2 ZERO TRUST – VA CRITICAL SECURITY CONTROLS
VA has established minimum mandatory security requirements and requires that any network connected software system or service must meet the VA Critical Security Controls as outlined in the VA Memorandum, “VA Security Controls”, https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010. VA Critical Security Controls identify the minimum mandatory requirements that must be implemented across all VA enterprise infrastructure, cloud computing environments, information systems, networks, and specialized devices (medical devices/systems, special-purpose systems, and research scientific computing devices) that process, store, and/or transmit VA data. Effective July 1, 2025, the Contractor shall implement these VA Critical Security Controls, within any network connected software system or service prior to being authorized for use in the VA. This functional requirement is not negotiable, and Plan of Action & Milestones (POAM) will not be accepted in the event these controls cannot be implemented for new systems. Critical Security Controls are intended to increase VA’s security posture and provide security and privacy risk visibility into the VA network and is not a new requirement. The Contractor’s failure to maintain these VA Critical Controls after implementation will result in VA discontinuing the use of the system.
5.1.3 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Architecture (EA), and VA Identity and Access Management (IAM) approved Enterprise Technology Guidelines (ETG). The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in Executive Order 14028, VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010 https://www.ea.oit.va.gov/ https://www.ea.oit.va.gov/ https://digital.va.gov/office-of-information-and-technology/reference-library/enterprise-technology-guidelines/ https://digital.va.gov/office-of-information-and-technology/reference-library/enterprise-technology-guidelines/
Presidential Directive 12 (HSPD-12) Program, CISA Binding Operational Directive 23- 01, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the ETGs. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, M-22-09, and NIST Federal Information Processing Standard (FIPS) 201-3. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable Technology Guideline as outlined in VA ETGs.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
https://bidenwhitehouse.archives.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2005/m05-24.pdf https://bidenwhitehouse.archives.gov/wp-content/uploads/2019/05/M-19-17.pdf https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/01/M-22-09.pdf
12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
5.1.4 INTERNET PROTOCOL VERSION 6 (IPV6)
The Contractor solution shall support IPv6-Only based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). Which defines IPv6-only as the state of an operational system or service when IPv4 protocol functions (addressing, packet forwarding) are not in use. The NIST USGv6 profile defines technical requirements for a product to be capable of operating in IPv6-Only environments. IPv6-Only technology, in accordance with the USGv6 Program ((https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices, applications, and systems shall support all applicable functionality on native IPv6-Only as well as dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g., web, email, DNS, ISP services, etc.) shall support native IPv6-Only and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall support using native IPv6-Only and dual stack (IPv6 / IPv4) for all functionality and operations.
5.1.5 TRUSTED INTERNET CONNECTION (TIC)
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents).
5.1.6 STANDARD COMPUTER CONFIGURATION
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, Windows 10 (64bit) and Windows 11, Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1 https://doi.org/10.6028/NIST.SP.500-267Br1 https://doi.org/10.6028/NIST.SP.800-119 https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf https://www.cisa.gov/publication/tic-30-core-guidance-documents and or Windows 11 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.
5.1.7 VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE
MANAGEMENT (PLM)
The Contractor shall support VA efforts IAW the Veteran-Focused Integration Process (VIP) Guide and Product Line Management (PLM) Playbook. The major focus of VIP is on Enterprise Oversight, Governance, reporting, and establishing practices that focus on outcomes and continuously delivering sustainable IT capabilities to benefit the Veteran. PLM is a framework that focuses on delivering functional products that provide the highest priority work to customers while delivering simplified, reliable, and practical solutions to the business, medical staff, and our Veterans. The VIP Guide is a companion guide to the PLM Transformation Playbook and can be found at:
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 and the PLM Transformation Playbook can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946. VIP and PLM are the authoritative processes that IT projects must follow to ensure development and delivery of IT products.
The VIP Guide provides guidance for transitioning from project-centric to product-centric delivery. The VIP guide applies to all OIT Office of Management and Budget (OMB) reportable products that are required to collect and report costs, schedules, risks, and other valuable information in VA PARS (whether products are procured or developed by VA) and any VA Information Technology project effort in Software Product Management (SPM) and Infrastructure Operations (IO), or their successors, that touch the VA network regardless of IT organizational alignment (whether it spends government funding from VA's Congressional IT Appropriation or any other appropriation).
The PLM Transformation Playbook details how OIT leadership expects Product Lines (PLs) to implement PLM, DevOps, and Lean-Agile principles, methods, practices, and techniques through levels of maturity. The PLM Transformation Playbook applies to all Information Technology (IT) products aligned to PLs in the Software Product Management, Infrastructure Operations and Product Engineering organizations within the OIT organization.
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946
Others outside the referenced groups or organizations may use the VIP Guide and PLM Transformation Playbook for situational awareness as needed.
5.1.8 PROCESS ASSET LIBRARY (PAL)
The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The Process Asset Library (PAL) includes a spectrum of OIT functions and activities, such as project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. OIT utilizes PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section 6.2.2 and can be found at process_CONB_ext.docx (live.com). The main PAL can be accessed at www.va.gov/process.
5.1.9 AUTHORITATIVE DATA SOURCES
The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:
1. Interfacing with VA’s Master Person Index (MPI) (formerly the Master Veteran Index (MVI)) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.
3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.
4. Interfacing with HR Smart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HR Smart is the authoritative source for VA personnel information data.
https://view.officeapps.live.com/op/view.aspx?src=https%3A%2F%2Fdigital.va.gov%2Fprocess-asset-library%2Fwp-content%2Fuploads%2Fsites%2F16%2F2024%2F04%2Fprocess_CONB_ext.docx&wdOrigin=BROWSELINK http://www.va.gov/process
5. Interfacing with VA Profile to access personal contact information, if the solution relies on VA Veteran personal contact information data. VA Profile is the authoritative source for VA Veteran Personal Contact Data.
6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for qualifying active duty military service in VA.
7. Interfacing with VA Systems Inventory (VASI) to access VA systems information, if the solution relies on VA system information. VASI is the authoritative source for VA Information Technology systems.
8. Interfacing with Enterprise Mission Assurance Support Service (eMASS) to access the Authority to Operate (ATO) status of all VA Information Systems.
eMASS contains the official Authority to Operate (ATO) status of all VA Information Systems.
5.1.10 SOCIAL SECURITY NUMBER (SSN) REDUCTION
The Contractor solution shall support the Social Security Number (SSN) Fraud Prevention Act (FPA) of 2017 which prohibits the inclusion of SSNs on any document sent by mail. The Contractor support shall also be performed in accordance with Section 240 of the Consolidated Appropriations Act (CAA) 2018, enacted March 23, 2018, which mandates VA to discontinue using SSNs to identify individuals in all VA information systems as the Primary Identifier. The Contractor shall ensure that any new IT solution discontinues the use of SSN as the Primary Identifier to replace the SSN with the ICN in all VA information systems for all individuals.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .