Identity services engine servers

Closed Solicitation Posted

Solicitation number
FA448425Q0053
Agency
Air Mobility Command Air Force, Department of Defense
Responses due
Set-aside
Total Small Business

Opportunity facts

NAICS code
334210 Telephone Apparatus Manufacturing
PSC
5810 Communications Security Equipment And Components
Place of performance
Joint Base MDL, New Jersey 08641, United States
Points of contact

Notice details come from SAM.gov. Updated .

About this opportunity

The Department of the Air Force Air Mobility Command is procuring two Identity Services Engine (ISE) servers and supporting equipment to support lifecycle operations for the Air Force Information Network (AFIN) at Joint Base McGuire-Dix-Lakehurst. The contractor must provide specific Cisco equipment including servers, RAID controllers, power supplies, network interface cards, and associated accessories, all of which must be 2GIT compliant, Trade Agreements Act compliant, and explicitly not manufactured in China. Key requirements include ensuring Security Technical Implementation Guides (STIG) compliance, adhering to Privacy Act of 1974 requirements, and having personnel with DoD Directive 8570 Information Assurance Technical Level II certification with appropriate Cisco certifications. The government intends to use a Lowest Price Technically Acceptable (LPTA) evaluation methodology for this firm-fixed-price contract. The original response deadline was September 15, 2025, but has been amended multiple times, with the current due date being September 15, 2025 at 10:00 PM EST.

This solicitation is set aside for Total Small Business under NAICS code 334210 with a size standard of 1,250 employees, and the original solicitation documents also indicated it was designated for Women-Owned Small Business (WOSB). The contract requires delivery of all specified equipment within 45 days of contract award, with performance taking place at Joint Base McGuire-Dix-Lakehurst in New Jersey. The procurement involves multiple quantities of server components ranging from 2 to 12 units per item type across various stock numbers. While no specific contract value is disclosed in the solicitation documents, the scope encompasses comprehensive server infrastructure equipment designed to increase network reliability and sustainability. The government expects to award a single contract without discussions, and all offers must remain valid for 90 calendar days from the submission deadline.

Notice text

3 versions

Update #3 · Latest ·

AMMENDMENT: 

SITE VISIT CANCELLED

NEW DUE DATE 15 SEP 2025 AT 10:00pm EST

NEW SOW UPLOADED

General

The 87 CS Operations Flight (SCO) mission is to manage and maintain the Air Force Information Network (AFIN) and supporting cyber transport devices. This Statement of Work (SOW) addresses the need to procure two ISE servers.

Scope of Work

The contractor will be required to equip and furnish two ISE servers and all supporting equipment as listed in Section 5. Deliverables section.

Objectives

  • Supports life cycle support for Joint Base McGuire-Dix-Lakehurst AFIN. 
  • Increases reliability and sustainability of the base network.

Contractor Responsibilities

The selected contractor shall:

    1. Provide equipment listed in Deliverables Section 5 (See attached SOW)
    2. Comply with the Privacy Act of 1974, and shall comply with all applicable safeguarding and handling requirements associated with Privacy Act information
    3. Inform the POC and the Contracting Specialist/Officer in writing of any Contractor or Government caused delivery delays.

Deliverables

Please see attached SOW

Equipment Requirements

AFIN Identity Service Engine replacement servers and all equipment listed in Section 5. Deliverables must be:

  • 2GIT compliant
  • TAA compliant and explicitly NOT manufactured in China
  • All equipment delivered must match serial numbers and quantities of equipment listed in Deliverables Section 5.
Update #2 ·

AMMENDMENT: 

SITE VISIT CANCELLED

NEW DUE DATE 10 SEP 2025 AT 12:00pm EST

Scope of Work

The contractor will be required to equip and furnish two ISE servers and all supporting equipment as listed in Deliverables section.

Objectives

  • Supports life cycle support for Joint Base McGuire-Dix-Lakehurst AFIN. 
  • Increases reliability and sustainability of the base network.

Contractor Responsibilities

The selected contractor shall:

  1. Ensure STIG Compliance: Security Technical Implementation Guides (STIGs) set rigorous security standards for government and military networks. As STIG requirements are updated to address new vulnerabilities and threats, legacy Cisco ISE appliances may become non-compliant due to outdated firmware, unsupported configurations, or limited security patch availability. Upgrading to a newer appliance ensures adherence to the latest STIG requirements, safeguarding network integrity and security posture.
  2. Comply with the Privacy Act of 1974, and shall comply with all applicable safeguarding and handling requirements associated with Privacy Act information
  3. Ensure all personnel working on any Government network at minimum holds an active DoD Directive 8570 Information Assurance Technical (IAT) Level II certification and must present these credentials to the Government upon request.
  4. IAT Level II must include an appropriate equipment certification – in the case of this installation, an appropriate Cisco certification is required.
  5. Inform the POC and the Contracting Specialist/Officer in writing of any Contractor or Government caused Project delays.
  6. Conduct a kickoff meeting within the first two weeks of the start of period of performance.
  7. Participate in pre-install site survey(s) throughout the duration of the project in an effort to know the location and times of the switch installations.

Deliverables

Contractor shall document each ISE server appliance being provided as well as supporting equipment. 

NOTE:  Please reference 7. Information Assurance Requirements.

Equipment Requirements

AFIN Identity Service Engine replacement servers:

  • C9606R-48Y24C-BN-A TAA (Catalyst 9600 6-slot, 1xSup, 2xLC, 3x2KW AC, DNA-A LIC) x4
  • CAB-CONSOLE-RJ45 (Console Cable 6ft with RJ45 and DB9F) x4
  • C9600-SUP-1/2 (Cisco Catalyst 9600 Series Redundant Supervisor 1 Module) x4
  • C9600-DNA-A-3Y (Cisco Catalyst 9600 EDNA Advantage 3 Year License) x4
  • C9500-48Y4C-A TAA (Catalyst 9500 48-port x 1/10/25G + 4-port 40/100G, Advantage) x20
  • C9K-PWR-650WAC-R/2 (650W AC Config 4 Power Supply front to back cooling) x20
  • C9500-DNA-A-3Y (Cisco Catalyst 9500 DNA Advantage 3 Year License) x20
  • QSFP-100G-ZR4-S= (100GBASE QSFP Transceiver, 80KM reach over SMF, Duplex LC) x4
  • QSFP-100G-CU1M= (100GBASE-CR4 Passive Copper Cable, 1m) x24
  • QSFP-100G-LR4-S= (100GBASE LR4 QSFP Transceiver, LC, 10km over SMF) x28
  • SFP-10G-LR-S= (10GBASE-LR SFP Module, Enterprise-Class) x80
  • C9600-LC-48YL++= TAA (Cisco Catalyst 9600 Series 48-Port 25GE/10GE/1GE TAA) x1
  • SNS-3715-K9 CISCO SYSTEMS (Small Secure Network Server for ISE Applications) x2
  • SNS-HD600G10K12NM6 CISCO SYSTEMS (600GB 12G SAS 10K RPM SFF HDD) x2
  • SNS-PSU1-1200W CISCO SYSTEMS (1200W Titanium power supply for C-Series Servers) x2
  • CAB-9K12A-NA CISCO SYSTEMS (Power Cord, 125VAC 13A NEMA 5-15 Plug, North America) x2
  • SNS-CPU-I4310 CISCO SYSTEMS (Intel 4310 2.1GHz/120W 12C/18MB DDR4 2667MHz) x2
  • SNS-MR-X16G1RW CISCO SYSTEMS (16GB RDIMM SRx4 3200 (8Gb)) x4
  • SNS-TPM-002C CISCO SYSTEMS (TPM 2.0, TCG, FIPS140-2, CC EAL4+ Certified, for M6 servers) x2
  • SW-37X5-ISE-K9 CISCO SYSTEMS (Cisco ISE Software Load on SNS-36x5-K9 appliance) x2
  • SNS-RAID-220M6 CISCO SYSTEMS (Cisco 12G SAS RAID Controller w/4GB FBWC (16 Drv) w/1U Brkt) x2
  • SNS-PSU-M5BLK CISCO SYSTEMS (Power Supply Blanking Panel for SNS-3700 servers) x2
  • SNS-PCIE-IQ10GF CISCO SYSTEMS (Intel X710 quad-port 10G SFP+ NIC) x2
  • SNS-3755-K9 CISCO SYSTEMS (Medium Secure Network Server for ISE Applications) x2
  • SNS-HD600G10K12NM6 CISCO SYSTEMS (600GB 12G SAS 10K RPM SFF HDD) x8
  • SNS-PSU1-1200W CISCO SYSTEMS (1200W Titanium power supply for C-Series Servers) x4
  • CAB-9K12A-NA CISCO SYSTEMS (Power Cord, 125VAC 13A NEMA 5-15 Plug, North America) x4
  • SNS-CPU-I4316 CISCO SYSTEMS (Intel 4316 2.3GHz/150W 20C/30MB DDR4 2667MHz) x2
  • SNS-MR-X16G1RW CISCO SYSTEMS (16GB RDIMM SRx4 3200 (8Gb)) x12
  • SNS-TPM-002C CISCO SYSTEMS (TPM 2.0, TCG, FIPS140-2, CC EAL4+ Certified, for M6 servers) x2
  • SW-37X5-ISE-K9 CISCO SYSTEMS (Cisco ISE Software Load on SNS-36x5-K9 appliance) x2
  • SNS-RAID-220M6 CISCO SYSTEMS (Cisco 12G SAS RAID Controller w/4GB FBWC (16 Drv) w/1U Brkt) x2
  • SNS-PCIE-IQ10GF CISCO SYSTEMS (Intel X710 quad-port 10G SFP+ NIC) x2

Information Assurance Requirements

The contractor shall provide a network diagram or as-built for each building. The diagram will consist of the type and number of network switches and patch panels, also their locations.

The contractor shall provide, at completion, all product manuals, guides, and an IP address table with topology for the installed equipment.

TRAINING: 

No training should be required for the installed switches. If training is required, coordination will be done through the 87 CS/FUOPS.

Information Assurance Support Requirements

The contractor shall incorporate all applicable technical, procedural, and system documentation associated with federal, Department of Defense (DoD), and Air Force information assurance (IA) policy and requirements for systems that transmit and manage sensitive but unclassified (SBU) data traffic.

The contractor shall also provide support to the following IA requirements:

  • The Information System installed should be able to pass directed network scans and appropriate STIGs.
    • Provide a design of the proposed system.
    • Provide list of equipment Serial Numbers, Model Numbers, IP Addresses, and OS versions used and how system is connected.
    • Provide contact for management of information system being utilized.
    • Provide maintenance plan for system.
    • Topology (see sample topology below).

IA Certification Support

The contractor shall provide system administration, access, and engineering support to the 87 CS who will then coordinate with the IA certification team during the IA certification activities after acceptance test and prior to system burn-in. IAW AFMAN 17-1303 Cybersecurity Workforce Improvement Program meet the minimum 8570 Baseline requirement for Certification. DoDM 8570 currently moving to 8140 Cyberspace Workforce Qualification and Management Program.

Information Assurance System Requirements

The new equipment shall provide the additional features to support the IA requirements:

    • Include and support all IA activities necessary to meet DoD and Air Force IA requirements.

Information Assurance References

The new system shall comply with the following DoD policy documents or latest versions (https://public.cyber.mil/stigs/) provides the latest version of the following DoD documents and STIGs):

    • DoD Directive 5000.1, The Defense Acquisition System (ref (a), (j), and (k)).
    • Department of Defense Directive (DoDD 8500.1, Information Assurance (IA).
    • Department of Defense Instruction (DoDI 8500.2, Information Assurance (IA) Implementation.
    • 10 U.S.C.  Section 2224, Defense Information Assurance Program.
    • Office of Management and Budget Circular A-130, Appendix III, Management of Federal Information Resources.
    • AFI 33-202V1, Network and Computer Security.
    • Network Infrastructure STIG.
Update #1 ·

Scope of Work

The contractor will be required to equip and furnish two ISE servers and all supporting equipment as listed in Deliverables section.

Objectives

  • Supports life cycle support for Joint Base McGuire-Dix-Lakehurst AFIN. 
  • Increases reliability and sustainability of the base network.

Contractor Responsibilities

The selected contractor shall:

  1. Ensure STIG Compliance: Security Technical Implementation Guides (STIGs) set rigorous security standards for government and military networks. As STIG requirements are updated to address new vulnerabilities and threats, legacy Cisco ISE appliances may become non-compliant due to outdated firmware, unsupported configurations, or limited security patch availability. Upgrading to a newer appliance ensures adherence to the latest STIG requirements, safeguarding network integrity and security posture.
  2. Comply with the Privacy Act of 1974, and shall comply with all applicable safeguarding and handling requirements associated with Privacy Act information
  3. Ensure all personnel working on any Government network at minimum holds an active DoD Directive 8570 Information Assurance Technical (IAT) Level II certification and must present these credentials to the Government upon request.
  4. IAT Level II must include an appropriate equipment certification – in the case of this installation, an appropriate Cisco certification is required.
  5. Inform the POC and the Contracting Specialist/Officer in writing of any Contractor or Government caused Project delays.
  6. Conduct a kickoff meeting within the first two weeks of the start of period of performance.
  7. Participate in pre-install site survey(s) throughout the duration of the project in an effort to know the location and times of the switch installations.

Deliverables

Contractor shall document each ISE server appliance being provided as well as supporting equipment. 

NOTE:  Please reference 7. Information Assurance Requirements.

Equipment Requirements

AFIN Identity Service Engine replacement servers:

  • C9606R-48Y24C-BN-A TAA (Catalyst 9600 6-slot, 1xSup, 2xLC, 3x2KW AC, DNA-A LIC) x4
  • CAB-CONSOLE-RJ45 (Console Cable 6ft with RJ45 and DB9F) x4
  • C9600-SUP-1/2 (Cisco Catalyst 9600 Series Redundant Supervisor 1 Module) x4
  • C9600-DNA-A-3Y (Cisco Catalyst 9600 EDNA Advantage 3 Year License) x4
  • C9500-48Y4C-A TAA (Catalyst 9500 48-port x 1/10/25G + 4-port 40/100G, Advantage) x20
  • C9K-PWR-650WAC-R/2 (650W AC Config 4 Power Supply front to back cooling) x20
  • C9500-DNA-A-3Y (Cisco Catalyst 9500 DNA Advantage 3 Year License) x20
  • QSFP-100G-ZR4-S= (100GBASE QSFP Transceiver, 80KM reach over SMF, Duplex LC) x4
  • QSFP-100G-CU1M= (100GBASE-CR4 Passive Copper Cable, 1m) x24
  • QSFP-100G-LR4-S= (100GBASE LR4 QSFP Transceiver, LC, 10km over SMF) x28
  • SFP-10G-LR-S= (10GBASE-LR SFP Module, Enterprise-Class) x80
  • C9600-LC-48YL++= TAA (Cisco Catalyst 9600 Series 48-Port 25GE/10GE/1GE TAA) x1
  • SNS-3715-K9 CISCO SYSTEMS (Small Secure Network Server for ISE Applications) x2
  • SNS-HD600G10K12NM6 CISCO SYSTEMS (600GB 12G SAS 10K RPM SFF HDD) x2
  • SNS-PSU1-1200W CISCO SYSTEMS (1200W Titanium power supply for C-Series Servers) x2
  • CAB-9K12A-NA CISCO SYSTEMS (Power Cord, 125VAC 13A NEMA 5-15 Plug, North America) x2
  • SNS-CPU-I4310 CISCO SYSTEMS (Intel 4310 2.1GHz/120W 12C/18MB DDR4 2667MHz) x2
  • SNS-MR-X16G1RW CISCO SYSTEMS (16GB RDIMM SRx4 3200 (8Gb)) x4
  • SNS-TPM-002C CISCO SYSTEMS (TPM 2.0, TCG, FIPS140-2, CC EAL4+ Certified, for M6 servers) x2
  • SW-37X5-ISE-K9 CISCO SYSTEMS (Cisco ISE Software Load on SNS-36x5-K9 appliance) x2
  • SNS-RAID-220M6 CISCO SYSTEMS (Cisco 12G SAS RAID Controller w/4GB FBWC (16 Drv) w/1U Brkt) x2
  • SNS-PSU-M5BLK CISCO SYSTEMS (Power Supply Blanking Panel for SNS-3700 servers) x2
  • SNS-PCIE-IQ10GF CISCO SYSTEMS (Intel X710 quad-port 10G SFP+ NIC) x2
  • SNS-3755-K9 CISCO SYSTEMS (Medium Secure Network Server for ISE Applications) x2
  • SNS-HD600G10K12NM6 CISCO SYSTEMS (600GB 12G SAS 10K RPM SFF HDD) x8
  • SNS-PSU1-1200W CISCO SYSTEMS (1200W Titanium power supply for C-Series Servers) x4
  • CAB-9K12A-NA CISCO SYSTEMS (Power Cord, 125VAC 13A NEMA 5-15 Plug, North America) x4
  • SNS-CPU-I4316 CISCO SYSTEMS (Intel 4316 2.3GHz/150W 20C/30MB DDR4 2667MHz) x2
  • SNS-MR-X16G1RW CISCO SYSTEMS (16GB RDIMM SRx4 3200 (8Gb)) x12
  • SNS-TPM-002C CISCO SYSTEMS (TPM 2.0, TCG, FIPS140-2, CC EAL4+ Certified, for M6 servers) x2
  • SW-37X5-ISE-K9 CISCO SYSTEMS (Cisco ISE Software Load on SNS-36x5-K9 appliance) x2
  • SNS-RAID-220M6 CISCO SYSTEMS (Cisco 12G SAS RAID Controller w/4GB FBWC (16 Drv) w/1U Brkt) x2
  • SNS-PCIE-IQ10GF CISCO SYSTEMS (Intel X710 quad-port 10G SFP+ NIC) x2

Information Assurance Requirements

The contractor shall provide a network diagram or as-built for each building. The diagram will consist of the type and number of network switches and patch panels, also their locations.

The contractor shall provide, at completion, all product manuals, guides, and an IP address table with topology for the installed equipment.

TRAINING: 

No training should be required for the installed switches. If training is required, coordination will be done through the 87 CS/FUOPS.

Information Assurance Support Requirements

The contractor shall incorporate all applicable technical, procedural, and system documentation associated with federal, Department of Defense (DoD), and Air Force information assurance (IA) policy and requirements for systems that transmit and manage sensitive but unclassified (SBU) data traffic.

The contractor shall also provide support to the following IA requirements:

  • The Information System installed should be able to pass directed network scans and appropriate STIGs.
    • Provide a design of the proposed system.
    • Provide list of equipment Serial Numbers, Model Numbers, IP Addresses, and OS versions used and how system is connected.
    • Provide contact for management of information system being utilized.
    • Provide maintenance plan for system.
    • Topology (see sample topology below).

IA Certification Support

The contractor shall provide system administration, access, and engineering support to the 87 CS who will then coordinate with the IA certification team during the IA certification activities after acceptance test and prior to system burn-in. IAW AFMAN 17-1303 Cybersecurity Workforce Improvement Program meet the minimum 8570 Baseline requirement for Certification. DoDM 8570 currently moving to 8140 Cyberspace Workforce Qualification and Management Program.

Information Assurance System Requirements

The new equipment shall provide the additional features to support the IA requirements:

    • Include and support all IA activities necessary to meet DoD and Air Force IA requirements.

Information Assurance References

The new system shall comply with the following DoD policy documents or latest versions (https://public.cyber.mil/stigs/) provides the latest version of the following DoD documents and STIGs):

    • DoD Directive 5000.1, The Defense Acquisition System (ref (a), (j), and (k)).
    • Department of Defense Directive (DoDD 8500.1, Information Assurance (IA).
    • Department of Defense Instruction (DoDI 8500.2, Information Assurance (IA) Implementation.
    • 10 U.S.C.  Section 2224, Defense Information Assurance Program.
    • Office of Management and Budget Circular A-130, Appendix III, Management of Federal Information Resources.
    • AFI 33-202V1, Network and Computer Security.
    • Network Infrastructure STIG.

Attachments

Files attached to this notice, newest first
File Type Posted
ISE Server SOW_10Sep2025.pdf PDF
Solicitation Amendment FA448425Q00530002 SF 30.pdf PDF
ISE Questions and Answers.pdf PDF
ISE Questions and Answers.docx DOCX document
Solicitation Amendment FA448425Q00530001 SF 30.pdf PDF
Solicitation - FA448425Q0053.pdf PDF
Anti-terror Guide.pdf PDF
SFS Appendix.pdf PDF
Anti-terror trifold.pdf PDF
Medical Statement.docx DOCX document
ISE Server SOW updated.pdf PDF
Show all 11

On GovTribe

Work this opportunity on GovTribe

  • Track it in your pipeline
  • Find teaming partners
  • Similar opportunities
  • Ask GovTribe AI about this opportunity