IT Audit Services

Solicitation # 85344
Posted 2/11/25, 11:28 AM
No Updates
Due 2/20/25, 2:00 PM
Source
View
Similar Opportunities
The Virginia Department of Health's Office of Licensure and Certification is seeking qualified contractors to provide survey and certification personnel for Long-Term and Acute Care Facilities through Invitation for Bid (IFB #VDH-25-560-0093). The procurement seeks contractors capable of conducting comprehensive facility surveys, including recertification surveys, revisits, complaint investigations, and Life Safety Code surveys for various healthcare facilities such as nursing homes, ICF/IID,...
The Commonwealth of Virginia Department of Forestry is seeking a contractor to perform a comprehensive Statewide Forest Canopy Baseline Assessment across Virginia's 25.5 million acres. This procurement is structured as an Invitation for Bids (IFB) with five primary deliverables: Landcover Analysis, Ecosystem Services Calculations, Heat Index Data, Interactive Online Mapping Application Build, and Per-Year Web Hosting Cost. The project requires advanced geospatial analysis using...
The Virginia State Police (VSP) is soliciting bids for a term contract to provide annual fire extinguisher inspections and related services across multiple VSP locations throughout the state. The procurement seeks a qualified contractor to perform comprehensive fire extinguisher maintenance, including annual inspections, six-year maintenance and recharge, 12-year hydrostatic testing, and repairs for various sizes of ABC fire extinguishers (5lb, 10lb, 20lb) at 10 different facilities such as...
The Virginia Information Technologies Agency (VITA) is conducting a competitive procurement for Information Technology Research Subscription Services through RFP 2024-08, seeking comprehensive IT research and subscription services for the Commonwealth of Virginia and authorized users. The procurement requires vendors to provide online repositories of market research, technology assessments, case studies, strategic planning, and implementation guidance across 25 high-level IT research...
The West Virginia Department of Administration Purchasing Division is seeking a comprehensive Cybersecurity and Privacy Training solution for the West Virginia Office of Technology (WVOT), targeting approximately 25,000 end users across the state government. The Request for Quotation (CRFQ 0231 OOT2500000016) calls for a vendor-managed Learning Management System (LMS) that provides customized security and privacy training, including an integrated phishing simulator. The training must be 30-45...
The Virginia State Police (VSP) has issued an Unsealed Invitation for Bids (UIFB) for Technical Federal Grant Writing Services, seeking a qualified contractor to support the development of competitive federal grant applications. The solicitation, identified by the contract number 156-25-130, aims to procure professional grant writing expertise to enhance the agency's ability to secure federal funding. The selected contractor will be responsible for crafting comprehensive and compelling grant...

The Virginia Department of Fire Programs (VDFP) has issued an Invitation for Bid (IFB) for IT Audit Services, seeking a qualified contractor to perform comprehensive IT security audits across six software applications. The procurement requires conducting audits in accordance with Commonwealth of Virginia Information Security Audit Standard (SEC502) and Generally Accepted Government Auditing Standards (GAGAS). Specific applications to be audited include an LMS/Training Application, Online Testing Application, Social Media Aggregation Application, Image Management Application, Financial Management Application, and Social Media Archiving Application. The contractor must demonstrate expertise in conducting IT security audits, compliance with COV Information Technology Security standards, and maintain appropriate certifications including a current Quality Assurance/Peer Review report. A mandatory online pre-bid conference was held on January 28, 2025, with sealed bids due on February 20, 2025, at 2:00 PM. The contract period spans from March 1, 2025, through February 28, 2026, with two optional one-year renewal periods, and requires auditing two applications per year. Evaluation will focus on responsiveness to IFB requirements and determining the lowest responsive and responsible bidder.

The solicitation is marked as a Micro Set-aside, but non-micro certified vendors are not disqualified from bidding, provided they are registered in eVA, the Commonwealth's electronic procurement system. The procurement includes a significant small business subcontracting component, with a statewide goal of 42% participation from Department of Small Business and Supplier Diversity (DSBSD)-certified small businesses. Vendors must submit a Small Business Subcontracting Plan detailing their approach to meeting this goal. Transaction fees will apply, with 1% fees capped at $500 for certified small businesses and $1,500 for non-certified businesses. The technical environment primarily consists of SaaS applications using Microsoft stack (Windows/SQL) hosted on Azure and AWS, with most applications containing basic sensitive information such as names and addresses. While specific budget ranges are not explicitly stated, the solicitation requires vendors to provide fixed pricing for two applications in the first year. The agency will share Commonwealth RAMP process data and permit observation of SOC reports under a non-disclosure agreement to assist with audit planning.

Generated 2/24/25, 8:08 AM