DOCUMENT
D -- Enterprise PKI Certificate Solution - Entrust Licenses & Maintenance - Attachment
- Notice Date
- 12/2/2016
- Notice Type
- Attachment
- NAICS
- 541519
— Other Computer Related Services
- Contracting Office
- Department of Veterans Affairs;Technology Acquisition Center;23 Christopher Way;Eatontown NJ 07724
- ZIP Code
- 07724
- Solicitation Number
- VA11817Q1753
- Archive Date
- 3/10/2017
- Point of Contact
- Amy Schmalzigan
- Small Business Set-Aside
- N/A
- Award Number
- NNG15SD19B VA118-17-F-1764
- Award Date
- 12/1/2016
- Awardee
- ALVAREZ & ASSOCIATES, LLC;8251 GREENSBORO DR STE 230;TYSONS CORNER;VA;22102
- Award Amount
- $943,000.00
- Description
- On December 1, 2016, the Technology Acquisition Center awarded Delivery Order VA118-17-F-1764 under the terms and conditions of National Aeronautics and Space Administration (NASA) Solutions for Enterprise-Wide Procurement (SEWP) V contract NNG15SD19B with Alvarez & Associates (Alvarez), located at 8251 Greensboro Drive Suite 230, Tysons Corner, VA 22102. Alvarez will be providing Entrust certificate subscription licenses and software maintenance. The period of performance shall be December 5, 2016 through December 4, 2017, plus two 12-month option periods, if exercised, the total order value of $1,803,000.00. JUSTIFICATION FOR AN EXCEPTION TO FAIR OPPORTUNITY 1. Contracting Activity: Department of Veterans Affairs (VA) Office of Acquisition Operations Technology Acquisition Center 23 Christopher Way Eatontown, NJ 07724 2. Description of Action: This proposed action is for a firm-fixed-price delivery order issued under the National Aeronautics and Space Administration (NASA) Solutions for Enterprise-Wide Procurement (SEWP) V Government-Wide Acquisition Contract (GWAC) for the renewal of brand name Entrust certificate subscription licenses and software maintenance. 3. Description of the Supplies or Services: For several years, VA suffered from various migration issues with its escrowed Public Key Infrastructure (PKI) encryption certificates. Specifically, VA experienced issues maintaining several contracts with different vendors to provide migration services, and in that, VA experienced significant problems executing the migration of escrowed encryption certificates, to include failures to migrate escrowed encryption certificates. To address the PKI encryption and migration issues, VA determined it was in its best interest to enter into an Interagency Transaction with the Department of Treasury (Treasury) in accordance with applicable regulations and procedures. The current Interagency Transaction with Treasury, effective July 2016, provides PKI services for VA in support of a Shared Service Provider (SSP). As an SSP for PKI services, the Treasury s Bureau of the Public Debt (BPD) provides PKI support services to VA. For about four years, VA has held agreements with BPD to install, operate, and maintain a PKI enrollment server which provides VA with the ability to issue web and device based PKI and encryption certificates to users across VA enterprise. VA, Office of Information and Technology, Service Delivery and Engineering, Enterprise Systems Engineering, Core Infrastructure Services has a requirement to renew 550,000 brand name Entrust Entelligence Security Provider User Client Access Licenses (CALs) to include software maintenance, 500,000 Entelligence Security Provider for Devices User Identity CALs to include software maintenance, and 400,000 Web Certificates (no maintenance) to support the Interagency Transaction. These subscription licenses allow VA a limited web based PKI administration platform for the issuance and management of end entity certificates within VA enterprise. The required certificate authority administration software subscriptions include capabilities for auto enrollment, user management and user registration and enrollment server for the web management of encryption certificates. VA must renew these licenses in order for BPD as a SSP to provide PKI services for VA. The Contractor shall also provide software maintenance to include 24 hours per day, 7 days per week technical phone support, software patches, bug fixes, and version upgrades. The period of performance shall be December 5, 2016 through December 4, 2017, plus two 12-month option periods, if exercised. 4. Statutory Authority: The statutory authority permitting this exception to fair opportunity is 41 U.S.C. 4106(c)(2) as implemented by Federal Acquisition Regulation (FAR) 16.505(b)(2)(i)(B), entitled Only one awardee is capable of providing the supplies or services required at the level of quality required because the supplies or services ordered are unique or highly specialized. 5. Rationale Supporting Use of Authority Cited Above: Based on market research, as described in section eight of this justification, it was determined that limited competition is viable among authorized resellers of the required brand name Entrust certificate subscription licenses and software maintenance. VA has a critical need to continue the existing license subscription with Entrust. Entrust is the current software that the BPD uses for its entire customer base, which includes VA. VA utilizes BPD as a SSP for its PKI services and Entrust is the only software that is interoperable and compatible with the existing BPD Entrust SM8 software currently installed in BPD s PKI management environment. BPD currently utilizes Entrust SM8 software and VA needs to communicate with that software and can only use Entrust certificate subscription licenses due to the proprietary code that only allows Entrust certificates to be issued from the Entrust software that BPD hosts. Any other product, other than Entrust, would not communicate and work with the existing BPD Entrust SM8 software. VA requires Entrust certificate subscription licenses for continued operational availability. Maintenance is required for software updates and patches to VA s current Entrust software. These updates and patches provide new feature sets, address program errors in prior software versions, and provide security enhancements. Only Entrust, through an authorized reseller, can provide the necessary software upgrades and patches because of the propriety source code required to develop and implement software updates. Since the software is proprietary, a legal restriction is placed on access to the software code that is required in order to develop upgrades and patches to the software. Without this access it is impossible for another source to modify the software code as necessary to provide the required patches and upgrades. No other source other than an Entrust authorized reseller can provide the required maintenance support requirements described herein, such as assistance via phone and email, as well as all software upgrades and patches. Failure to renew the existing Entrust certificate license subscriptions will cause PKI services in VA (email encryption/Personal Identity Verification (PIV) card issuance/Secure websites) to be invalidated because the Entrust licenses are the only ones that are interoperable with the current system. This will cause integration for other Veteran Focused Integration Program (VIP) deliverable items, such as PIV card management system (CMS) activities that support Homeland Security Presidential Directive-12 (HSPD-12) and Office of Management and Budget (OMB) mandates for PIV cards to be severely disrupted. The services that will cease to function will leave VA without a PKI provider. Failure to procure Entrust PKI software licenses will cause systems that use security certificates and encryption to go offline, resulting in outages that will cause access failures to VA IT systems to include medical systems, which will cause patient safety incidents. 6. Efforts to Obtain Competition: Market research was conducted, details of which are in section eight of this justification. This effort did not yield any additional sources that can meet the Government s requirements. It was determined, however, that limited competition is viable among authorized resellers for the required Entrust software license subscription and maintenance renewals. In accordance with FAR 5.301 and 16.505(b)(2)(ii)(D), the award notice for this action will be synopsized and this justification will be made publicly available on the Federal Business Opportunities Page within 14 days of award of the order. Additionally, in accordance with FAR 16.505(a)(4)(iii)(A)(2), this justification will be provided with the Request for Quote to NASA SEWP V GWAC holders. 7. Actions to Increase Competition: The Government will continue to conduct market research to ascertain if there are changes in the market place that would enable future actions to be competed. VA technical Subject Matter Experts regularly review industry trade publications and conduct internet research to ascertain if any other software is available to meet the requirements described herein. 8. Market Research: The Government s technical experts conducted market research in August of 2016 by reviewing similar software products to ascertain if these items could meet VA s requirements. Specifically, the Government s technical experts conducted web-based research from Verisign, Inc., Verizon Communications, Symantec Corporation, and SafeNet, Inc. as other PKI providers. VA reviewed each of the possible sources product information and it was determined that only Entrust meets VA s requirements. All other PKI providers use a different PKI vendor suite that is incompatible with the current BPD environment consisting of Entrust SM8 software. Furthermore, no other vendor, including those reviewed by the technical experts, has the capability of issuing software patches, bugs, fixes, and version upgrades for Entrust certificate subscription licenses necessary to support the existing VA requirement. Based on the above, only Entrust certificate subscription licenses and software maintenance meet all of the Government s requirements. Additional market research was conducted in October 2016 by utilizing the NASA SEWP Provider Lookup tool to determine whether the brand name Entrust certificate subscription licenses and software maintenance are available from NASA SEWP V GWAC holders. It was determined that there are several resellers of the brand name Entrust certificate subscription licenses and software maintenance that hold current GWACs such that limited competition is anticipated. 9. Other Facts: None
- Web Link
-
FBO.gov Permalink
(https://www.fbo.gov/notices/b2187c37803730b2eb4d55d95ce026af)
- Document(s)
- Attachment
- File Name: NNG15SD19B VA118-17-F-1764 NNG15SD19B VA118-17-F-1764_1.docx (https://www.vendorportal.ecms.va.gov/FBODocumentServer/DocumentServer.aspx?DocumentId=3138631&FileName=NNG15SD19B-085.docx)
- Link: https://www.vendorportal.ecms.va.gov/FBODocumentServer/DocumentServer.aspx?DocumentId=3138631&FileName=NNG15SD19B-085.docx
- Note: If links are broken, refer to Point of Contact above or contact the FBO Help Desk at 877-472-3779.
- File Name: NNG15SD19B VA118-17-F-1764 NNG15SD19B VA118-17-F-1764_1.docx (https://www.vendorportal.ecms.va.gov/FBODocumentServer/DocumentServer.aspx?DocumentId=3138631&FileName=NNG15SD19B-085.docx)
- Record
- SN04342013-W 20161204/161202234414-b2187c37803730b2eb4d55d95ce026af (fbodaily.com)
- Source
-
FedBizOpps Link to This Notice
(may not be valid after Archive Date)
| FSG Index | This Issue's Index | Today's FBO Daily Index Page |