Description
Sources Sought Notice This is a Request for Information Sources Sought Notice only. The purpose of this Sources Sought notice is to identify qualified vendors, obtain market information
on capable sources of supply, industry best practices, and specific input to the information provided for the Department of Veterans Affairs (VA) Office of Information & Technology,
Office of Information Security, Information Security Risk Management requirement for an Enterprise Governance, Risk, and Compliance (GRC) tool solution. This Sources Sought Notice is for
planning purposes only and shall not be considered an Invitation for Bid, Request for Task Execution Plan (TEP), Request for Quotation, or a Request for Proposal. Additionally,
there is no obligation on the part of the Government to acquire any products described in this RFI. Your response to this RFI will be treated only as information for the Government to
consider. You will not be entitled to payment for direct or indirect costs that you incur in responding to this RFI. The Government does not intend to pay for the informationÂ
submitted in response to this RFI. This RFI does not constitute a solicitation for quotes/proposals or the authority to enter negotiations to award a contract. No funds have
been authorized, appropriated, or received for this effort. Interested parties are responsible for adequately marking proprietary, restricted, or competition sensitive informationÂ
contained in their response.  Any Service-Disabled Veteran-owned small businesses (SDVOSBs) or Veteran-owned small businesses (VOSBs) responding to this RFI must include their
intent and ability to meet set-aside requirements for performance of this effort in accordance with the Department of Veterans Affairs (VA) Acquisition Regulation (VAAR) 852.219-73, VA
Notice of Total Set-Aside for Certified SDVOSB or 852.219-74, VA Notice of Total Set-Aside for Certified VOSB; specifically the requirement for at least 50% of the cost of manufacturing
or 50% of the services be performed by yourself and/or other eligible/verified SDVOSB/VOSB concerns; and be listed in the Small Business Administration certification database at the
time of submission. It is requested that all companies interested in participating in this effort please note their interest and provide indication of their respective capabilities to
perform the effort described in the paragraphs below. Any information submitted by respondents to this RFI notice is strictly voluntary. All submissions become Government property and
will not be returned. VA reserves the right to not respond to any, all, or select responses or materials submitted. All requirements identified herein are subject to change at any time.
The North American Industry Classification System (NAICS) code considered for this requirement is 541519, Other Computer Related Services; the small business size standard for this NAICS
is $34 million dollars. REQUIREMENT The Department of Veterans Affairs (VA), Office of Information & Technology Office of Information Security, Information Security Risk Management
The Department of Veterans Affairs (VA) is conducting a market research for an Enterprise Governance, Risk, and Compliance (GRC) tool solution to support the VA in managing security
policies, controls, risks, assessments, and weaknesses through a single platform. HOW TO RESPOND: Respondents are encouraged to respond if they have the capabilities to meet the VA s
requirements. Provide a clear, concise, and complete capability package. Respondents shall submit a capability statement limited to 20 pages (excluding transmittal page) describing your
company s ability to meet the requirements outlined in this RFI and include the following: Provide Company Information: Company Name CAGE/UEI Number under which the company is registered
in SAM.gov. Company Address Point of contact name Telephone number Email address For small business concerns, indicate whether at least 50 percent of the total amount paid by the
Government will be paid to firms that are similarly situated. Company Business Size and Status for NAICS (541519). Brief detailed summary describing your company s technical approach to
meeting the requirements, to include: Identify existing contract vehicle(s) in which you are a current contract holder that can be used to procure the required services (i.e., General
Services Administration Federal Supply Schedule (GSA FSS), Transformation Twenty-One Total Technology Next Generation (T4NG), Government Wide Acquisition Contract, NASA Solution for
Enterprise-Wide Procurement (SEWP) Government-Wide Acquisition Contract (GWAC), etc.). List any existing contracting vehicles you have with the VA that you would recommend for this
requirement. Does the draft Product Description (PD) provide sufficient detail to describe the technical and functional requirements that encompass the requirement? If NO , please provide
your technical and functional comments, recommendations, and or questions on elements of the draft PD that may contribute to a more accurate proposal submission and efficient,
cost-effective effort. Is your company FedRAMP approved or are you currently in the process of obtaining FedRAMP approval? Your company s intent and ability to meet the set aside
requirement in accordance with VAAR 852.219- 73 (JAN 2023) (DEVIATION) and 13 CFR §125.6, which states the contractor will not pay more than 50 percent of the amount paid by the
Government to it to firms that are not SDVOSBs. Your response shall include information as to available personnel and financial resources; number of proposed team members and the PD
requirements planned to be subcontracted, which shall include the prime planned percentage or the number of potential team members that may be used to fulfill the set aside requirement.
If providing a tool with artificial intelligence (AI) or similar capabilities, clearly state the type(s) of model(s) that would be used in your solution. If you are providing a solution
with AI capabilities, please state where the model(s)/data processing would be located (e.g., on prem in VA, specific cloud instance, etc.). Indicate where all GRC data for your solution
would be housed (e.g., on prem in VA, specific cloud instance, etc.). Please provide information on any available contract vehicles in which you participate, that the government could use
to acquire your proposed solution. Provide a recommend the contract type for this solution. Indicate if you are interested and/or able to attend a VA industry day. Respondents are
requested to identify any additional information considered applicable to this RFI. Provide a statement regarding your socioeconomic status (including business type (s)/certifications(s)
such as SDB, 8(a), HUBZone, SDVOSB, WOSB, etc.). If a small business, clearly identify what socioeconomic category you are recommending for this effort. If a small business, are you able
to comply with FAR 52.219-6 and 52.219-14 in execution of this effort? Are you able to comply with subcontracting limitations in 13 CFR 125.6 in execution of this effort? INSTRUCTIONS FOR
SUBMITTING QUESTIONS AND RESPONSES: Do not wait until the last minute to submit your responses. To avoid submission of late responses, we recommend the transmission of your response file
24 hours prior to the required response due date and time. Please be advised that timeliness is determined by the date and time an Offeror s response is received by the Government not
when an Offeror attempted transmission. Offerors are encouraged to review and ensure that sufficient bandwidth is available on their end of the transmission. Questions shall be submitted
electronically to via email to Terricia Lloyd, Terricia.Lloyd@va.gov no later than 10:00 am EST on October 26, 2023. Responses shall be submitted electronically via email to Terricia
Lloyd, Terricia.Lloyd@va.gov no later than 10:00 am EST on October 31, 2023. Information submitted any other method will not be considered. VA will not be able to grant any extensions to
this RFI. The VA reserves the right to not respond to any, all, or select responses or materials submitted. All VA current requirements identified herein are subject to change at any
time. VA appreciates your time and anticipated response.