The Virginia Department of Fire Programs (VDFP) has issued an Invitation for Bid (IFB) for IT Audit Services, seeking a qualified contractor to perform comprehensive IT security audits across six software applications. The procurement requires conducting audits in accordance with Commonwealth of Virginia Information Security Audit Standard (SEC502) and Generally Accepted Government Auditing Standards (GAGAS). Specific applications to be audited include an LMS/Training Application, Online Testing Application, Social Media Aggregation Application, Image Management Application, Financial Management Application, and Social Media Archiving Application. The contractor must demonstrate expertise in conducting IT security audits, compliance with COV Information Technology Security standards, and maintain appropriate certifications including a current Quality Assurance/Peer Review report. A mandatory online pre-bid conference was held on January 28, 2025, with sealed bids due on February 20, 2025, at 2:00 PM. The contract period spans from March 1, 2025, through February 28, 2026, with two optional one-year renewal periods, and requires auditing two applications per year. Evaluation will focus on responsiveness to IFB requirements and determining the lowest responsive and responsible bidder. The solicitation is marked as a Micro Set-aside, but non-micro certified vendors are not disqualified from bidding, provided they are registered in eVA, the Commonwealth's electronic procurement system. The procurement includes a significant small business subcontracting component, with a statewide goal of 42% participation from Department of Small Business and Supplier Diversity (DSBSD)-certified small businesses. Vendors must submit a Small Business Subcontracting Plan detailing their approach to meeting this goal. Transaction fees will apply, with 1% fees capped at $500 for certified small businesses and $1,500 for non-certified businesses. The technical environment primarily consists of SaaS applications using Microsoft stack (Windows/SQL) hosted on Azure and AWS, with most applications containing basic sensitive information such as names and addresses. While specific budget ranges are not explicitly stated, the solicitation requires vendors to provide fixed pricing for two applications in the first year. The agency will share Commonwealth RAMP process data and permit observation of SOC reports under a non-disclosure agreement to assist with audit planning.
A Portfolio Platform of GovExec © 2025