Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, August 19 at 2:00 PM EDT

Register Free →

7B22--614-26-3-560-0221 - IVX Omnicell Workflows Equipment

Active
36C24926Q0348Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The Department of Veterans Affairs, through Network Contracting Office 9, is seeking information from potential vendors capable of supplying an Automated Sterile Compounding Workflow Solution for the Memphis VA Medical Center. The requirement is for five integrated systems designed to be deployed within laminar airflow hoods and biological safety cabinets to automate the compounding of sterile intravenous medications, ensuring compliance with USP 797 and USP 800 standards while reducing human error and improving patient safety. Each system must provide an ISO Class 5 environment, support closed-system transfer devices, feature integrated barcode and image recognition, gravimetric verification, camera-based documentation, remote pharmacist verification, automated labeling, and alerts for accuracy failures. The solution must maintain detailed tracking of medications, lot numbers, and expiration dates for recalls, interface with VA’s VistA and Simplifi797 software via HL7, operate within existing physical spaces, and support 24/7 remote and onsite technical support with a minimum 99% uptime. All equipment must be compatible with VA’s security protocols and IT infrastructure, including FIPS 140-2 encryption, TLS configurations, and VA-approved antivirus and patch management systems. The solicitation is a sources sought notice, not a request for proposals or quotes, and responses must include company details, SAM EUI, NAICS 339112 size status, capability statements, and disclosures regarding certifications such as SDVOSB, VOSB, 8(a), or women-owned status. Vendors must identify any related companies owned by the same principals with overlapping NAICS codes and disclose intent to form a joint venture. The government anticipates awarding a single one-year lease with four option years under FAR 12 and 15. Installation must be completed by January 2026 at the Memphis VAMC, with full technical support, remote access via secure VPN, and adherence to all VA information security mandates including NIST 800-52, NIST 800-88 sanitization, FIPS 199/200 categorization, and compliance with VA Handbook 6500 and the Privacy Act. Contractors must ensure no VA data is stored on returned or decommissioned equipment and must provide SBOMs, patch management plans, cryptographic validation, and supply chain integrity documentation. All responses must be submitted by email to daymeion.brantley@va.gov by August 12, 2026,

General Info

VA seeks automated sterile compounding systems with USP 797/800 compliance, HL7 integration, 24/7 support, and strict security for Memphis VAMC by Jan 2026.

Agency

Department Of Veterans Affairs → 249-NETWORK Contract Office 9 (36C249)View Agency

NAICS

339112 - Surgical and Medical Instrument ManufacturingView NAICS

Place of Performance

VA Memphis Healthcare System Lt. Col Luke Weathers, Jr. VAMC, Memphis, TN, 38105

Set-Aside

NONE

Documents

(1)

36C24926Q0348.docx

DOCX

AI Contract Breakdown

Uniform Contract Format

What is UCF?

Uniform Contract Format (UCF) uses AI to break down any contract into standardized sections—scope, pricing, deliverables, and evaluation criteria.

Timeline

PhaseSources Sought
Posted

Sources Sought

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Veterans Affairs → 249-NETWORK Contract Office 9 (36C249)
Contacts1 person available
OfficeMURFREESBORO, TN, 37129, USA
Organization / Agency
Department Of Veterans Affairs → 249-NETWORK Contract Office 9 (36C249)
View Agency Profile
Office AddressMURFREESBORO, TN, 37129, USA
Contacts
Daymeion BrantleyContract Specialist

Full Description

Show more
Page 4 of 25 Page 1 of This is not a request for quotes; the Government is seeking information for market research purposes only. VA Network Contracting Office (NCO) 9 is seeking sources interested and capable of providing the items as described in the attached Product Description.
The North American Industry Classification System (NAICS) is 339112 The Service Code (PSC) is 6515 - Medical and Surgical Instruments, Equipment, And Supplies
Responses to this notice shall include company/individual name, size status for the above reference NAICS code, a service capability statement, SAM Entity Unique Identifier (EUI), address, point of contact, and examples of similar facilities to which similar items have been provided.
Contractors must provide information on whether they are certified SDVOSB, VOSB, Hub zone, 8(a), women-owned concern. If standard company brochures will be provided as a response to this Source Sought ensure that additional information tailored to this notice is included. This is not a solicitation for quotes. If a solicitation is issued, it will be announced on the Contract Opportunities website https: respond to that solicitation announcement separately from the response to this announcement.
Contractors must be registered in System for Award Management (SAM), see internet site: https://www.sam.gov for information about registration.
Identify any other companies owned (wholly or in-part) by the owners of this business who provide goods or services that are registered under the same or a related NAICS code with the Center for Veterans Enterprise (CVE); Provide the certification type (SDVOSB/VOSB), Federal Identification Number, and state of incorporation for each.
Do you plan on responding to a solicitation for this requirement with a Joint Venture utilizing multiple owned companies as majority or non-majority owner?
If you are in GSA, please provide schedule and contract number.
Responses to this notice must be submitted via email to daymeion.brantley@va.gov. No telephone inquiries will be accepted.
DISCLAIMER This Sources Sought is issued solely for information and planning purposes only and does not constitute a solicitation. All information received in response to this Sources Sought that is marked as proprietary will be handled accordingly. Responses to this notice are not offers and cannot be accepted by the Government to form a binding contract. Responders are solely responsible for all expenses associated with responding to this Sources Sought.
Veterans Affairs, NCO-9, is seeking information for vendors interested and capable of providing the service below:
STATEMENT OF WORK
Automated Sterile Compounding Workflow Solution
BACKGROUND: The Memphis VA Medical Center s (VAMC) Pharmacy Service manually compounds sterile non-hazardous and hazardous intravenous (IV) compounds for patient administration. Pharmacy Service currently follows USP 797 standards. However, USP 800 standards have been published and must be implemented by December 2019. In addition, new USP 797 guidelines are projected to be published by June 2020. To remain compliant with these USP standards as well as look at new opportunities to prevent medication errors, the Pharmacy Service is looking at automation to help improve patient safety by reducing medication errors and ensure all documentation is obtained for compounded products as required by new standards. OBJECTIVE: To install sterile compounding workflow solutions that can be placed inside laminar airflow hoods and biological safety cabinets to improve patient safety and reduce potential medication errors when manual compounding is required. SCOPE OF WORK SCOPE OF WORK: Vendor shall provide five IV workflow solutions for laminar airflow hoods and biological safety cabinets. Vendor shall furnish all accessories, parts and expertise necessary to provide shared maintenance of all equipment at the Memphis VAMC. Equipment Requirements Provides an ISO Class 5 environment and/or can be used within an ISO Class 5 environment Can be used in a negative pressure environment Compatible with closed-system transfer devices Uses integrated barcode scanning for verification of ingredients Uses image recognition for verification of ingredients Uses gravimetric verification Uses cameras to visually document compounding of sterile IV medications Allows for remote pharmacist verification Provides compounding instructions for pharmacy technicians when manual compounding is required Print labels for compounded items Alert to destroy items that do not meet accuracy verification Maintains photo documentation of all compounded items Tracks all medications, lot numbers and expiration dates for items used in compounded medications for recall purposes Flexibility with use of different manufacturers and supplies during times of medication/supply shortages Small footprint that can be used in current spaces Ability to interface with VA software (VistA) via HL7 interface Ability to interface with Simplifi797® software Customized reporting system Ability to log into the automation with username and unique PIN Customer support with remote virtual private network (VPN) ability and onsite repairs available 24 hours per day/7 days per week SCHEDULE: Installation estimated to be completed by January 2026.
TERM OF CONTRACT AND PRICING: The VA anticipates the award of a single contract for a one-year lease with four option years. The solicitation will be conducted in accordance with FAR 12 and 15.
HOURS OF OPERATION: Not applicable.
MAINTENANCE AND TECHNICAL SUPPORT: Provide maintenance on all contractor-provided equipment and installed systems. Contractor shall make provisions for the proper maintenance and functioning of associated equipment, facilities and fixtures as may reasonably be required by pharmacists to perform services hereunder. Provide after-hours support for problems with call-pack periods not to exceed 30 minutes from the placement of a call for assistance
PLANNING AND INSTALLATION: Contractor shall develop a project implementation strategy with Memphis VAMC to include the preparation of buildings, establishing telecommunications etc. if necessary The service provider should utilize a point-to-point VPN between themselves and Memphis VAMC, if necessary, to dial into the system for diagnostic or upgrading purposes. All security requirements need to be met. Contractors should provide a system that maintains a minimum of 99% up time performance rate. Failure to provide this may result in a possible contract termination. Contractor shall provide hardware necessary to connect remotely to Memphis VAMC to be utilized at the contractor site. Contractor shall provide facsimile, telephone, computer/laptops, networking and other telecommunication equipment to be utilized at the contractor facility. Contractor shall provide all supplies, services, maintenance, repairs and upgrades required at contractor facility to provide services as described above. Contractor s equipment, hardware, software and supplies shall be compatible with the VA s software and hardware used during performance of this contract, including critical patches and antivirus updates. Contractor shall provide proof of installation of critical patches and/or antivirus updates to the VA upon request. Contractor s network and security system shall be compatible with the VA s network and security system. Contractor shall use any VA furnished items in conjunction with, and exclusively for, performance under this contract. APPENDIX C VA INFORMATION AND INFORMATION SYSTEM SECURITY AND PRIVACY LANGUAGE FOR INCLUSION IN CONTRACTS, AS APPROPRIATE NOTE: Any sections (1-14) which DO NOT apply should not be included in the Statement of Work (SOW), Performance Work Statement (PWS), Product Description (PD) or contract. GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter contract ) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data General. VA information will not be co-mingled with any other data on the contractor s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.
The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies. The contractor shall not make copies of VA information except as specifically authorized and necessary to fulfil the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.
The contractor s firewall and web services security controls, as applicable, shall meet or exceed VA s minimum requirements. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer to all requests for demands for production of or inquiries about VA information and information systems to the VA CO for response. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the abovementioned information, the contractor shall immediately refer to such court order or other requests to the VA CO for response.
Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that are used to store, process, or access VA information that cannot be destroyed shall be returned to VA. The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of VA CO. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM). All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following: Contractor/subcontractor personnel no longer have a need for access to VA information or VA information systems.
Contractor/subcontractor personnel are terminated, suspended, or otherwise have their work on a VA project discontinued for any reason. Contractors believe their own personnel or subcontractor personnel may pose a threat to their company s working environment or to any company owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data. Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record. Contractor/subcontractor personnel have their authorization to work in the United States revoked. Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal. Contractors/subcontractors who no longer require VA access will return VA issued property to VA. This property includes (but is not limited to) documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO. TRAINING. This entire section applies to all acquisitions which include section 3. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems: VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) 10176) initially and annually thereafter. Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document i.e., any role-based information security training]. The contractor shall provide the COR/CO with a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any Information Security and Privacy language. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO with the incident number received from the ESD. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following: The date and time (or approximation of) the Security Incident occurred. The names of individuals involved (when applicable). The physical and logical (if applicable) location of the incident. Why did the Security Incident take place (i.e., catalyst for the failure). The amount of data belonging to VA was believed to have been compromised. The remediation measures the contractor is taking to ensure no future incidents of a similar nature. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal violations associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages Reimbursement for Data Breach Costs. INFORMATION SYSTEM DESIGN AND DEVELOPMENT. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (to include the subcomponents of each) designed or developed for or on behalf of VA by any non-VA entity. Information systems designed or developed on behalf of VA at non-VA facilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards for the protection of electronic Protected Health Information (PHI), outlined in 45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems and FIPS 200, Minimum Security Requirements for Federal Information Systems. Baseline security controls shall be implemented commensurate with the FIPS 199 system security categorization (reference VA Handbook 6500 and VA Trusted Internet Connections (TIC) Architecture). Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA Assessment and Authorization (A&A) processes in VA Handbook 6500 and VA Information Security Knowledge Service to obtain Authority to Operate (ATO). VA Directive 6517, Risk Management Framework for Cloud Computing Services, provides security and privacy requirements for cloud environments. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500, VA Handbook 6517, Risk Management Framework for Cloud Computing Services and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution. Contractors shall comply with FAR 39.1, specifically the prohibitions referenced. The contractor (including producers and resellers) shall comply with Office of Management and Budget (OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M22-18 (September 14, 2022). The term software includes firmware, operating systems, applications and application services (e.g., cloud-based software), as well as products containing software. The contractor shall provide a self-attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program (FedRAMP) Third Party Assessor Organization (3PAO) or one approved by the agency will be acceptable in lieu of a software producer's self-attestation. The contractor shall ensure all delivered applications, systems and information systems are compliant with Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity management requirements as set forth in OMB M-19-17, M-05-24, FIPS 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors (or its successor), M-21-31 and supporting NIST guidance. This applies to Commercial Off-The-Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations. The contractor shall ensure all contractors delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity Guidelines, for direct, assertion-based authentication and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common Access Card (CAC), as determined by the business need and compliance with VA Information Security Knowledge Service specifications. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operate correctly as intended on systems in compliance with VA baselines prior to acceptance or connection into an authorized VA computing environment. If the Defense Information Systems Agency (DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requires the population of operating systems and applications includes all listed on the NIST National Checklist Program Checklist Repository. The standard installation, operation, maintenance, updating and patching of software shall not alter the configuration settings from VA approved baseline configuration. Software developed for VA must be compatible with VA enterprise installer services and install to the default program files directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on VA systems. Applications designed for normal end users will run in the standard user context without elevated system administration privileges. The contractor-delivered solutions shall reside on VA approved operating systems. Exceptions to this will only be granted with the written approval of the COR/CO. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development life cycle outlined in NIST 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, VA Directive and Handbook 6500, and VA Handbook 6517. The Contractor shall comply with the Privacy Act of1974 (the Act), FAR 52.2242 Privacy Act, and VA rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish a VA function. The contractor shall ensure the security of all procured or developed information systems, systems, major applications, minor applications, enclaves and platform information technologies, including their subcomponents (hereinafter referred to as Information Systems ) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems. When the contractor is responsible for operations or maintenance of the systems, the contractor shall apply the security fixes within the timeframe specified by the associated controls on the VA Information Security Knowledge Service. When security fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the contractor shall provide written notice to the VA COR/CO that the patch has been validated as not affecting the Systems within 10 business days. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (cloud and non-cloud) hosted, operated, maintained, or used on behalf of VA at non-VA facilities. The contractor shall comply with all Federal laws, regulations, and VA policies for Information systems (cloud and non-cloud) that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities. Security controls for collecting, processing, transmitting, and storing of VA sensitive information, must be in place. The controls will be tested by VA or a VA sanctioned 3PAO and approved by VA prior to hosting, operation, maintenance or use of the information system or systems by or on behalf of VA. This includes conducting compliance risk assessments, security architecture analysis, routine vulnerability scanning, system patching, changing management procedures and the completion of an acceptable contingency plan for each system. The contractor s security control procedures shall be the same as procedures used to secure VA-operated information systems. Outsourcing (contractor facility, equipment, or staff) of systems or network operations, telecommunications services or other managed services require Assessment and Authorization (A&A) of the contractor s systems in accordance with VA Handbook 6500 as specified in VA Information Security Knowledge Service. Major changes to the A&A package may require reviewing and updating all the documentation associated with the change. The contractor s cloud computing systems shall comply with FedRAMP and VA Directive 6517 requirements. The contractor shall return all electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) to non-VA leased or non-VA owned IT equipment used to store, process, or access VA information to VA in accordance with A&A package requirements. This applies when the contract is terminated or completed and prior to disposal of media. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Information Security Knowledge Service requirements and NIST 800-88. The contractor shall send a self-certification that the data destruction requirements above have been met to the COR/CO within 30 business days of termination of the contract. All external internet connections to VA network involving VA information must be in accordance with VA Trusted Internet Connection (TIC) Reference Architecture and VA Directive and Handbook 6513, Secure External Connections and reviewed and approved by VA prior to implementation. Government-owned contractor-operated systems, third party or business partner networks require a Memorandum of Understanding (MOU) and Interconnection Security Agreements (ISA). Contractor procedures shall be subject to periodic, announced, or unannounced assessments by VA officials, the OIG or a 3PAO. The physical security aspects associated with contractor activities are also subject to such assessments. The contractor shall report, in writing, any deficiencies noted during the above assessment to the VA COR/CO. The contractor shall use VA s defined processes to document planned remedial actions that address identified deficiencies in information security policies, procedures, and practices. The contractor shall correct security deficiencies within the timeframes specified in the VA Information Security Knowledge Service. All major information system changes which occur in the production environment shall be reviewed by the VA to determine the impact on privacy and security of the system. Based on the review results, updates to the Authority to Operate (ATO) documentation and parameters may be required to remain in compliance with VA Handbook 6500 and VA Information Security Knowledge Service requirements. The contractor shall conduct an annual privacy and security self-assessment on all information systems and outsourced services as required. Copies of the assessment shall be provided to the COR/CO. The VA/Government reserves the right to conduct assessments using government personnel or a third party if deemed necessary. The contractor shall correct or mitigate any weaknesses discovered during the assessment. VA prohibits the installation and use of personally owned or contractor-owned equipment or software on VA information systems. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW, PWS, PD or contract. All security controls required for government furnished equipment must be utilized in VA approved Other Equipment (OE). Configuration changes to the contractor OE must be funded by the owner of the equipment. All remote systems must use VA-approved antivirus software and a personal (host-based or enclave based) firewall with a VA-approved configuration. The contractor shall ensure software on OE is kept current with all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-virus software and the firewall on the non-VA owned OE. Approved contractor OE will be subject to technical inspection at any time. The contractor shall notify the COR/CO within one hour of disclosure or successful exploits of any vulnerability which can compromise the confidentiality, integrity, or availability of the information systems. The system or effected component(s) needs(s) to be isolated from the network. A forensic analysis needs to be conducted jointly with VA. Such issues will be remediated as quickly as practicable, but in no event longer than the timeframe specified by VA Information Security Knowledge Service. If sensitive personal information is compromised reference VA Handbook 6500.2 and Section 5, Security Incident Investigation. For cases wherein the contractor discovers material defects or vulnerabilities impacting products and services they provide to VA, the contractor shall develop and implement policies and procedures for disclosure to VA, as well as remediation. The contractor shall, within 30 business days of discovery, document a summary of these vulnerabilities or defects. The documentation will include a description of the potential impact of each vulnerability and material defect, compensating security controls, mitigations, recommended corrective actions, FboNotice cause analysis and/or workarounds (i.e., monitoring). Should there exist any backdoors in the products or services they provide to VA (referring to methods for bypassing computer authentication), the contractor shall provide the VA CO/CO written assurance they have permanently remediated these backdoors. All other vulnerabilities, including those discovered through routine scans or other assessments, will be remediated based on risk, in accordance with the remediation timelines specified by the VA Information Security Knowledge Service and/or the applicable timeframe mandated by Cybersecurity & Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 2201 and BOD 19-02 for Internet-accessible systems. Exceptions to this paragraph will only be granted with the approval of the COR/CO. SECURITY AND PRIVACY CONTROLS COMPLIANCE TESTING, ASSESSMENT AND AUDITING. This entire section applies whenever section 6 or 7 is included. Should VA request it, the contractor shall provide a copy of their (corporation s, sole proprietorship s, partnership s, limited liability company (LLC), or other business structure entity s) policies, procedures, evidence and independent report summaries related to specified cybersecurity frameworks (International Organization for Standardization (ISO), NIST Cybersecurity Framework (CSF), etc.). VA or its third-party/partner designee (if applicable) are further entitled to perform their own audits and security/penetration tests of the contractor s IT or systems and controls, to ascertain whether the contractor is complying with the information security, network or system requirements mandated in the agreement between VA and the contractor. Any audits or tests of the contractor or third-party designees/partner VA elects to carry out will commence within 30 business days of VA notification. Such audits, tests and assessments may include the following: (a): security/penetration tests which both sides agree will not unduly impact contractor operations; (b): interviews with pertinent stakeholders and practitioners; (c): document review; and (d): technical inspections of networks and systems the contractor uses to destroy, maintain, receive, retain, or use VA information. As part of these audits, tests and assessments, the contractor shall provide all information requested by VA. This information includes, but is not limited to, the following: equipment lists, network or infrastructure diagrams, relevant policy documents, system logs or details on information systems accessing, transporting, or processing VA data. The contractor and at its own expense, shall comply with any recommendations resulting from VA audits, inspections and tests. VA further retains the right to view any related security reports the contractor has generated as part of its own security assessment. The contractor shall also notify VA of the existence of any such security reports or other related assessments, upon completion and validation. VA appointed auditors or other government agency partners may be granted access to such documentation on a need-to-know basis and coordinated through the COR/CO. The contractor shall comply with recommendations which result from these regulatory assessments on the part of VA regulators and associated government agency partners. PRODUCT INTEGRITY, AUTHENTICITY, PROVENANCE, ANTI-COUNTERFEIT AND ANTI-TAMPERING. This entire section applies when the acquisition involves any product (application, hardware, or software) or when section 6 or 7 is included.
The contractor shall comply with Code of Federal Regulations (CFR) Title 15 Part 7, Securing the Information and Communications Technology and Services (ICTS) Supply Chain , which prohibits ICTS Transactions from foreign adversaries. ICTS Transactions are defined as any acquisition, importation, transfer, installation, dealing in or use of any information and communications technology or service, including ongoing activities, such as managed services, data transmission, software updates, repairs or the platforming or data hosting of applications for consumer download. When contracting terms require the contractor to procure equipment, the contractor shall purchase or acquire the equipment from an Original Equipment Manufacturer (OEM) or an authorized reseller of the OEM. The contractor shall attest that equipment procured from an OEM or authorized reseller or distributor is authentic. If procurement is unavailable from an OEM or authorized reseller, the contractor shall submit in writing details of the circumstances prohibiting this from happening and procure a product waiver from VA COR/CO. All contractors shall establish, implement, and provide documentation for risk management practices for supply chain delivery of hardware, software (to include patches) and firmware provided under this agreement. Documentation will include chain of custody practices, inventory management program, information protection practices, integrity management program for sub-supplier provided components, and replacement parts requests. The contractor shall make spare parts available. All contractors(s) shall specify how digital delivery for procured products, including patches, will be validated and monitored to ensure consistent delivery. The contractor shall apply encryption technology to protect procured products throughout the delivery process. If a contractor provides software or patches to VA, the contractor shall publish or provide a hash conforming to the FIPS Security Requirements for Cryptographic Modules (FIPS 140-2 or successor). The contractor shall provide a software bill of materials (SBOM) for procured (to include licensed products) and consist of a list of components and associated metadata which make up the product. SBOMs must be generated in one of the data formats defined in the National Telecommunications and Information Administration (NTIA) report The Minimum Elements for a Software Bill of Materials (SBOM). Contractors shall use or arrange for the use of trusted channels to ship procured products, such as U.S. registered mail and/or tamper-evident packaging for physical deliveries. Throughout the delivery process, the contractor shall demonstrate a capability for detecting unauthorized access (tampering). The contractor shall demonstrate chain-of-custody documentation for procured products and require tamper-evident packaging for the delivery of this hardware. VIRUSES, FIRMWARE AND MALWARE. This entire section applies when the acquisition involves any product (application, hardware, or software) or when section 6 or 7 is included. The contractor shall execute due diligence to ensure all software provided and patches, including third-party patches, are free of viruses and/or malware before releasing them to or installing them on VA information systems. The contractor warrants it has no knowledge of and did not insert, any malicious virus and/or malware code into any software or patches provided to VA which could potentially harm or disrupt VA information systems. The contractor shall use due diligence, if supplying third-party software or patches, to ensure the third-party has not inserted any malicious code and/or virus which could damage or disrupt VA information systems. The contractor shall provide or arrange for the provision of technical justification as to why any false positive hit has taken place to ensure their code s supply chain has not been compromised. Justification may be required, but is not limited to when install files, scripts, firmware, or other contractor-delivered software solutions (including third-party install files, scripts, firmware, or other software) are flagged as malicious, infected, or suspicious by an anti-virus vendor. The contractor shall not upload (intentionally or negligently) any virus, worm, malware or any harmful or malicious content, component and/or corrupted data/source code (hereinafter virus or other malware ) onto VA computer and information systems and/or networks. If introduced (and this clause is violated), upon written request from the VA CO, the contractor shall: Take all necessary actions to correct the incident, to include all assistance to VA to eliminate the virus or other malware throughout VA s information networks, computer systems and information systems; and Use commercially reasonable efforts to restore operational efficiency and remediate damage due to data loss or data integrity damage, if the virus or other malware causes a loss of operational efficiency, data loss, or damage to data integrity. CRYPTOGRAPHIC REQUIREMENT. This entire section applies whenever the acquisition includes section 6 or 7 is included. The contractor shall document how the cryptographic system supporting the contractor s products and/or services protect the confidentiality, data integrity, authentication and non-repudiation of devices and data flows in the underlying system. The contractor shall use only approved cryptographic methods as defined in FIPS 140-2 (or its successor) and NIST 800-52 standards when enabling encryption on its products. The contractor shall provide or arrange for the provision of an automated remote key-establishment method which protects the confidentiality and integrity of the cryptographic keys. The contractor shall ensure emergency re-keying of all devices can be remotely performed within 30 business days. The contractor shall provide or arrange for the provision of a method for updating cryptographic primitives or algorithms. PATCHING GOVERNANCE. This entire section applies whenever the acquisition includes section 7 is included a. The contractor shall provide documentation detailing patch management, vulnerability management, mitigation and update processes (to include third-party) prior to the connection of electronic devices, assets or equipment to VA s assets. This documentation will include information regarding the following: The resources and technical capabilities to sustain the program or process (e.g., how the integrity of a patch is validated by VA); and The approach and capability to remediate newly reported zero-day vulnerabilities for contractor products. The contractor shall verify and provide documentation that all procured products (including third-party applications, hardware, software, operating systems, and firmware) have appropriate updates and patches installed prior to delivery to VA. The contractor shall provide or arrange the provision of appropriate software and firmware updates to remediate newly discovered vulnerabilities or weaknesses for their products and services within 30 days of discovery. Updates to remediate critical or emergent vulnerabilities will be provided within seven business days of discovery. If updates cannot be made available by contractor within these time periods, the contractor shall submit mitigations, methods of exploit detection and/or workarounds to the COR/CO prior to the above deadlines. The contractor shall provide or arrange for the provision of appropriate hardware, software and/or firmware updates, when those products, including open-source software, are provided to the VA, to remediate newly discovered vulnerabilities or weaknesses. Remediations of products or services provided to the VA s system environment must be provided within 30 business days of availability from the original supplier and/or patching source. Updates to remediate critical vulnerabilities applicable to the Contractor s use of the third-party product in its system environment will be provided within seven business days of availability from the original supplier and/or patching source. If applicable third-party updates cannot be integrated, tested and made available by Contractor within these time periods, mitigations and/or workarounds will be provided to the COR/CO before the above deadlines. SPECIALIZED DEVICES/SYSTEMS (MEDICAL DEVICES, SPECIAL PURPOSE SYSTEMS, RESEARCH SCIENTIFIC COMPUTING). This entire section applies when the acquisition includes one or more Medical Device, Special Purpose System or Research Scientific Computing Device. If appropriate, ensure selected clauses from section 6 or 7 and 8 through 12 are included. Contractor supplies/delivered Medical Devices, Special Purpose Systems Operational Technology (SPS-OT) and Research Scientific Computing Devices shall comply with all applicable Federal law, regulations, and VA policies. New developments require creation, testing, evaluation, and authorization in compliance with processes specified on the Specialized Device Cybersecurity Department Enterprise Risk Management (SDCD-ERM) Portal, VA Directive 6550, Pre-Procurement Assessment and Implementation of Medical Devices/Systems, VA Handbook 6500, and the VA Information Security Knowledge Service. Deviations from Federal law, regulations, and VA Policy are identified and documented as part of VA Directive 6550 and/or the VA Enterprise Risk Analysis (ERA) processes for Specialized Devices/Systems processes. All contractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500 and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO for governance or resolution. The contractor shall certify to the COR/CO that devices/systems that have completed the VA Enterprise Risk Analysis (ERA) process for Specialized Devices/Systems are fully functional and operate correctly as intended. Devices/systems must follow the VA ERA authorized configuration prior to acquisition and connection to the VA computing environment. If VA determines a new VA ERA that needs to be created, the contractor shall provide required technical support to develop the configuration settings. Major changes to a previously approved device/system will require a new ERA. The contractor shall comply with all practices documented by the Food Drug and Administration (FDA) Premarket Submission for Management of Cybersecurity in Medical Devices and Post market Management of Cybersecurity in Medical Devices. The contractor shall design devices capable of accepting all applicable security patches with or without the support of the contractor personnel. If patching can only be completed by the contractor, the contractor shall commit the resources needed to patch all applicable devices at all VA locations. If unique patching instructions or packaging are needed, the contractor shall provide the necessary information in conjunction with the validation/testing of the patch. The contractor shall apply security patches within 30 business days of the patch release and have a formal tracking process for any security patches not implemented to include explanation when a device cannot be patched. The contractor shall provide devices able to install and maintain VA-approved antivirus capabilities with the capability to quarantine files and be updated as needed in response to incidents. Alternatively, a VA-approved whitelisting application may be used when the contractor cannot install an anti-virus / antimalware application. The contractor shall verify and document all software embedded within the device which does not contain any known viruses or malware before delivery to our installation at a VA location. Devices and other equipment or systems containing media (hard drives, optical disks, solid state, and storage via chips/firmware) with VA sensitive information will be returned to the contractor with media removed. When the contract requires return of equipment, the options available to the contractor are the following: The contractor shall accept the system without the drive, firmware and solid state. VA s initial device purchase includes a spare drive or other replacement medium which must be installed in place of the original drive at time of turn in; or Due to the highly specialized and sometimes proprietary hardware and software associated with the device, if it is not possible for VA to retain the hard drive, firmware, and solid state, then: The equipment contractor shall have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact. Any fixed hard drive, Complementary Metal-Oxide-Semiconductor (CMOS), Programmable Read-Only Memory (PROM), solid state and firmware on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be pre-approved and described in the solicitation, contract, or order. DATA CENTER PROVISIONS. This entire section applies whenever the acquisition requires an interconnection to/from the VA network to/from a non-VA location. The contractor shall ensure the VA network is accessed in accordance with VA Directive 6500 and IAM security processes specified in the VA Information Security Knowledge Service. The contractor shall ensure network infrastructure and data availability in accordance with VA information system business continuity procedures specified in the VA Information Security Knowledge Service. The contractor shall ensure any connections to the internet or other external networks for information systems occur through managed interfaces utilizing VA approved boundary protection devices (e.g., internet proxies, gateways, routers, firewalls, guards or encrypted tunnels). The contractor shall encrypt all traffic across the segment of the Wide Area Network (WAN) it manages and no unencrypted Out of Band (OOB) Internet Protocol (IP) traffic will traverse the network. The contractor shall ensure tunnel endpoints are routable addresses at each VA operating site. The contractor shall secure access from Local Area Networks (LANs) at co-located sites in accordance with VA TIC Reference Architecture, VA Directive and Handbook 6513, and MOU/ISA process specified in the VA Information Security Knowledge Service. DELIVERY LOCATIONS AND HOURS OF OPERATION: Facility Address City State ZIP Lt. Col Luke Weathers, Jr. VAMC
116 N. Pauline Avenue Memphis TN 38105
Hours of operation will be 8:00am 4:00pm Monday through Friday except on federal government holidays. FEDERAL GOVERNMENT HOLIDAYS New Year's Day January 1st Martin Luther King's Birthday Third Monday in January President's Day Third Monday in February Memorial Day Last Monday in May Juneteenth Independence Day June 19th Independence Day July 4th Labor Day First Monday in September Columbus Day Second Monday in October Veterans Day November 11th Thanksgiving Day Fourth Thursday in November Christmas Day December 25th *If these holidays fall on a Saturday or Sunday, the contractor should contact the facility to determine on which day (Friday or Monday) they will be observed. PROGRAM POINT OF CONTACT (POC) and/or CONTRACTING OFFICER REPRESENTATIVE (COR): The COR for the acquisition is Sylvia Flowers and may be reached at 901-523-8990 ext. 17217 or sylvia.flowers@va.gov.

Similar Contracts

Same NAICS industry code

NAICS: 339112
New
Federal
Optical Fabrication Equipment
Solicitation # W81K0026QA262
The Medical Readiness Contracting Office – West is seeking information from potential suppliers capable of providing specialized Optical Fabrication Lab equipment for the Optical Fabrication Lab at Brooke Army Medical Center in San Antonio, Texas. The equipment must fully support the existing Satisloh North America Fabrication System and meet exact technical criteria including the use of non-alloy components for lens blocking, UV-curing to reduce cooling time, automatic adjustment of prism angle and blocking chuck axis, polishing on alloy-free blocks, a no-touch lens cleaning process, separation of blocks and adhesive from lenses, and dual-sided drying to make lenses inspection-ready. Submissions must be tailored specifically to these brand-name requirements and cannot be general capability statements. Responses are voluntary and for informational purposes only and do not constitute a solicitation or commitment by the government. All submissions must be submitted electronically in PDF or MS Word format, not exceeding ten single-sided pages with no less than 10-point font, and must include the company name, point of contact, phone number, email, Unique Entity ID, CAGE code, small business status type and certifications, and a statement confirming the applicable NAICS code 339112. The requirement is eligible for set-asides for small businesses under the 1,000-employee size standard, and responses must be received by August 11, 2026, at 3:00 PM. Questions must be submitted in writing to the designated contracting points of contact, referencing solicitation number W81K00-26-Q-A262, and no verbal inquiries will be accepted. No funding is available to cover response preparation costs.
W40M MRC0 West

POSTED

about 8 hours ago

DEADLINE

in 4 days
View Details
NAICS: 339112
New
Federal
6515--LEAD-LINED PET UNIT DOSE CABINET "BRAND NAME ONLY" OEM LETTER FROM THE MANUFACTURER IS REQUIRED. IF NO OEM LETTER VENDOR WILL BE CONSIDERED NON-RESPONSIVE.
Solicitation # 36C24526Q0752
The U.S. Department of Veterans Affairs is conducting market research through a Request for Information to identify qualified suppliers for a Brand Name Only requirement for a Lead-Lined PET Unit Dose Cabinet and associated radiation shielding equipment, including an L-Block Shield, Lead Brick Cave, and specialized PET sharps containers with lead shielding. All responses must include an authorized distributor letter from the original equipment manufacturer, as failure to provide this will result in immediate disqualification. Respondents are required to complete the Buy American Certificate (FAR 52.225-2), provide full answers to all 14 specified questions, and submit detailed information including their SAM registration, Unique Entity ID, company size status, manufacturer part numbers, warranty terms, and point of contact details. Pricing must be submitted for market research purposes only, and all items must be delivered within 60 days of contract award to the VA warehouse in Martinsburg, WV, during standard business hours Monday through Friday, excluding federal holidays and weekends. The Government intends to award a Firm-Fixed Price contract based solely on price evaluation, with no consideration for technical factors beyond compliance with mandatory requirements. Vendors must be actively registered in the System for Award Management (SAM) and, if claiming SDVOSB or VOSB status, must be verified on the SBA’s certification website. Responses are strictly voluntary, non-binding, and not considered offers under federal acquisition regulations; the Government reserves the right to reject any or all submissions without obligation. Submissions must be sent via email to the designated point of contact by the deadline of August 12, 2026, at 12:00 PM EST, and no telephone responses will be accepted. Information provided may be used to determine acquisition strategy, assess vendor capability, and decide whether to proceed with a formal solicitation, but no contract award is guaranteed.
245-NETWORK Contract Office 5 (36C245)

POSTED

about 8 hours ago

DEADLINE

in 5 days
View Details
NAICS: 339112
New
Federal
6515--Waterloo Health Isolation Carts with IV Poles - BRAND NAME ONLY- SMALL BUSINESS SET-ASIDE
Solicitation # 36C24126Q0711
This contract is a Brand Name-only small business set-aside solicitation issued by the Department of Veterans Affairs Network Contracting Office 1 for the procurement of 14 Tall Aluminum Unicarts with light gray shells, yellow drawer fronts, three 6-inch drawers, one 9-inch drawer, a pull-out shelf, and 5-inch casters, along with 14 corresponding IV Pole Accessories, all manufactured to the specific Waterloo Medical product specifications. The equipment is intended to replace end-of-life isolation carts in the Medical Surgical Unit, ICU, and PACU at the White River Junction VA Medical Center to enhance clinical care for veterans. The contract requires the supplier to deliver new, state-of-the-art, non-refurbished units, install them on-site, perform technical service checks, dispose of all packaging and trash, and provide user and service manuals along with an on-station in-service training. Delivery must be made to White River Junction, Vermont, using a box truck; no dock, liftgate, or inside delivery beyond warehouse access is required. The solicitation is a combined synopsis and RFQ with no separate written document, and all responses must be emailed to the designated point of contact by the deadline of August 14, 2026, at 12:00 PM EST. Only verified small businesses in active SAM.gov registration are eligible to respond, with a strict pass/fail requirement for small business status under the NAICS code 339112, which has a size standard of 1,000 employees. Proposals must include the Unique Entity Identifier, complete FAR 52.212-3 representations and certifications, pricing, warranty terms, delivery lead time, and an acknowledgment of full compliance with all terms or specific exceptions. The award will be made based on lowest price among compliant, qualified small business vendors, with no weightings assigned to other factors. The contractor must comply with extensive data rights and records management clauses, including unlimited government ownership of all deliverables and prohibitions against unauthorized use or dissemination of protected information under the Privacy Act or Freedom of Information Act. A minimum one-year manufacturer warranty from the date of installation is required. All equipment must meet current VA, TJC, and VHA directives for infection prevention and facility standardization. Submitting vendors must confirm SAM registration, include all required documentation, and agree to the solicitation’s terms without modification unless explicitly stated with rationale.
241-NETWORK Contract Office 01 (36C241)

POSTED

about 8 hours ago

DEADLINE

in 7 days
View Details
NAICS: 339112
New
Federal
Supply of IntelliVue FMX-4 Fetal/Neonatal Monitoring SystemsThe contract involves the delivery of four Philips IntelliVue FMX-4 fetal and neonatal monitoring systems designed to meet clinical standards for maternal and newborn care, with full compliance with electronic health record systems and integration into the Philips ecosystem to ensure seamless data flow and interoperability. The equipment must support continuous monitoring capabilities for both fetal and neonatal patients, adhering to all technical and regulatory specifications required for deployment in healthcare environments. This is a subcontract classified as a Service-Disabled Veteran-Owned Small Business set-aside under FAR 19.14, specifically targeting SDVOSB firms to promote veteran-owned business participation in federal contracting. The NAICS code 339112 confirms the industrial classification as Medical Equipment and Supplies Manufacturing. The solicitation was posted on August 6, 2026, with a response deadline of August 10, 2026, and the place of performance is specified as Tucson, Arizona, with a ZIP code of 85723-0002. The contracting authority is the Department of Veterans Affairs through the 262-NETWORK Contract Office 22 (36C262), indicating the systems will be deployed within VA healthcare facilities. The requirement emphasizes vendor capability to deliver fully configured, tested, and compliant systems ready for clinical use, with integration support to ensure compatibility with existing hospital infrastructure and data protocols. No point of contact details are provided in the public data, but the opportunity is accessible via the SAM.gov portal for eligible bidders.
262-NETWORK Contract Office 22 (36C262)

POSTED

1 day ago

DEADLINE

in 3 days
View Details

More opportunities from Department Of Veterans Affairs → 249-NETWORK Contract Office 9 (36C249)

Same awarding agency

NAICS: 721110
New
Federal
James H. Quillen Hoptel Services
Solicitation # 36C24926R0070
The U.S. Department of Veterans Affairs is seeking hotel and motel services under contract number 36C24926R0070 to provide temporary lodging for veterans and staff near the James H. Quillen VA Medical Center in Mountain Home, Tennessee. The contract requires the availability of 1 to 15 or more rooms per night, with the exact number fluctuating daily based on operational needs throughout the month. All accommodations must be located within a six-mile radius of the medical center’s address at the corner of Lamont and Veterans Way. This solicitation is designated as a Small Business Set Aside, totaling the entirety of the contract opportunity for small businesses, and is classified under NAICS code 721110 for accommodations. The solicitation, posted on August 7, 2026, has a response deadline of August 31, 2026, at 7:00 PM Eastern Time, and is managed by the 249-NETWORK Contract Office 9 located in Murfreesboro, Tennessee. Primary point of contact is Harry R. Grambo III, reachable at 423-905-5043 or Harry.Gramboiii@va.gov, with Lori Ellis serving as the secondary contact at 615-225-5507 or Lori.Ellis2@va.gov. The contract will be awarded through the SAM.gov platform, and vendors must ensure full compliance with the specified location requirements and volume flexibility to meet VA lodging demands effectively and consistently.
Hotels (except Casino Hotels) and Motels

POSTED

about 8 hours ago

DEADLINE

in 24 days
View Details
NAICS: 339113
New
Federal
Supply of DCI Series 5 Track Mount Operatory LightsThe contract seeks the procurement of 13 DCI Edge Series 5 Track Mount Operatory Lights, model LT5000, or an equivalent product that meets or exceeds the manufacturer’s specifications and key performance characteristics. The equipment is intended for use at a facility located in Mountain Home, Tennessee, with delivery and installation requirements aligned with operational standards for medical lighting systems. This procurement is issued as a subcontract under a Service-Disabled Veteran-Owned Small Business (SDVOSB) set-aside, adhering to FAR 19.14, ensuring priority consideration for businesses owned and controlled by service-disabled veterans. The North American Industry Classification System (NAICS) code 339113 applies, classifying this as a medical equipment and supplies manufacturing contract. The solicitation was posted on August 5, 2026, with a response deadline of August 18, 2026, at 3:00 PM Eastern Time. The contracting office is the 249-NETWORK Contract Office 9 (36C249), operating under the Department of Veterans Affairs. All submissions must demonstrate strict compliance with product specifications, including performance, durability, and installation requirements, with no deviations permitted without prior approval. The contract does not specify a point of contact, and bidders are expected to rely on the official SAM.gov portal for all tender-related communications and documentation.
Surgical Appliance and Supplies Manufacturing

POSTED

2 days ago

DEADLINE

in 11 days
View Details