Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 2 at 2:00 PM EDT

Register Free →

This Solicitation opportunity from Ohio was posted on July 30, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.

Gambling Blocking Services

Closed
SRC0000040376State & Local

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

The contract seeks providers of gambling blocking services to support mental health interventions for individuals affected by problem gambling, specifically within the state of Ohio. It is issued by the Casino Control Commission under solicitation number SRC0000040376, with a response deadline of August 7, 2026. The services must be delivered to residents of Ohio and are intended to help curb gambling behavior through technological and behavioral blocking mechanisms. This initiative falls under state-level public health efforts, with no specific set-aside provisions or NAICS code listed, indicating a broad eligibility for qualified vendors. The contract is posted on Ohio’s state procurement portal, and all submissions must comply with the requirements outlined through the provided UI link, though no direct point of contact information is provided in the posting.

General Info

Ohio seeks gambling blocking services for residents to support mental health interventions by August 7, 2026.

Agency

Ohio → Casino Control CommissionView Agency

NAICS

713290 - Other Gambling IndustriesView NAICS

Place of Performance

OH, USA

Set-Aside

NONE

Documents

(4)

Appendix_2_Contractor_Information_Form.pdf

PDF

Gambling_Blocking_Services_RFP_Updated.pdf

PDF

Appendix_3_Contractor_Redaction_Justification_Form.pdf

PDF

Appendix_1_Executive_Order_2019-12D.pdf

PDF

AI Contract Breakdown

Uniform Contract Format

What is UCF?

Uniform Contract Format (UCF) uses AI to break down any contract into standardized sections—scope, pricing, deliverables, and evaluation criteria.

Timeline

PhaseClosed
Posted

Solicitation

Response Deadline

Deadline has passed

Submission Closed

Find active opportunities like this

Start your free trial to discover similar active contracts, track opportunities, and build proposals with AI assistance.

Organization & Contact Information

Show more
AgencyOhio → Casino Control Commission
ContactsNo contacts available
OfficeN/A
Organization / Agency
Ohio → Casino Control Commission
View Agency Profile
Office AddressN/A
ContactsNo contact information available

Full Description

Show more
The Ohio Casino Control Commission is aware of the continued issues that some vendors have experienced while attempting to submit questions through the “Inquiry” portion of Ohio Buys. The Commission is working with its partners at Ohio Buys to resolve this issue and ensure it is functioning properly, but due to the deadlines for both the submission of inquiries we have established a temporary solution. Please email your inquiry, or questions, to BlockingServiceRFP@casinocontrol.ohio.gov and our team will promptly review and post both the question(s) and answer(s) in Ohio Buys so that they are available to the inquiring vendor and the public.Thank you!
Please see attached documents for scope of work
Mental health interventions or procedures
Inquiries Inquiry 93436 | Question 1: Anti-Bypass Resistance and Third-Party Support MechanismsPart Two, Section IV asks for "reliable, tamper-resistant blocking controls." Is there a minimum standard or third-party certification the Commission expects for anti-bypass resistance, or will this be evaluated qualitatively through the vendor's own testing documentation? Separately, does the Commission consider mechanisms that involve a trusted third party, such as a family member or support contact receiving notification of an attempted bypass, to be a valued or expected component of "tamper-resistant blocking controls" and "recovery-oriented" functionality? If so, should this be addressed under Capability and Functionality, or under a separate deliverable category? Question 2: Organizational Capacity for Newer VendorsGiven the emphasis on "organizational capacity" and "3 years of similar projects" (Part Three, II.A.b), how would the Commission evaluate a newer vendor with a strong pilot or proof-of-concept but no prior state government contract? Is a phased or trial engagement a realistic path for smaller vendors? Question 3: Media Strategy Development Cost Line ItemThe cost proposal template requests a "Media strategy development cost" line item (Part Three, II.B). For a purely technical blocking service with no public awareness campaign component, should this be listed as $0, or is a media or outreach component expected as part of the deliverable? Question 4: Demographic Reporting vs. PrivacyPart Two, Section IV requires on-demand reporting including "user demographic information," while Evaluation Criterion II weighs "privacy protections for service user information" at 20 points. For a solution architected to collect no personal or demographic data beyond connection location (IP-based), how should a vendor address the demographic reporting requirement? Would location-based aggregate data alone satisfy this requirement, or does the Commission expect additional demographic fields such as age or gender to be collected at sign-up? Question 5: Vendors Based in the European UnionAppendix 1 (Executive Order 2019-12D) requires disclosure of the location(s) where services are performed and where State data is accessed, tested, maintained, or stored. Our solution is architected so that no user or State data is stored on any server: all blocking configuration and activity data remains local to the participant's device. The only data processed off-device consists of anonymized, aggregated product-usage analytics, processed through a U.S.-based analytics provider (Amplitude). Given this architecture, would it be acceptable under the Executive Order for a vendor to operate and provide support from the European Union, or does the Executive Order require the vendor's operational location itself (development, support) to be within the United States regardless of where data is or isn't stored? | Answer: Question 1: Anti-Bypass Resistance and Third-Party Support MechanismsPart Two, Section IV asks for "reliable, tamper-resistant blocking controls." Is there a minimum standard or third-party certification the Commission expects for anti-bypass resistance, or will this be evaluated qualitatively through the vendor's own testing documentation? Separately, does the Commission consider mechanisms that involve a trusted third party, such as a family member or support contact receiving notification of an attempted bypass, to be a valued or expected component of "tamper-resistant blocking controls" and "recovery-oriented" functionality? If so, should this be addressed under Capability and Functionality, or under a separate deliverable category?ANSWER: The Commission does not have specific minimum standards or third-party certification requirements for anti-bypass resistance, unless provided in the RFP. Evaluations will be conducted qualitatively through testing documentation. The Commission is open to consideration of the functionalities provided in this question. A vendor should include all functionalities which it deems appropriate in its response and is responsive to the RFP. The Commission will leave it to the discretion of the proposer as to where it should appear in response to the RFP.Question 2: Organizational Capacity for Newer VendorsGiven the emphasis on "organizational capacity" and "3 years of similar projects" (Part Three, II.A.b), how would the Commission evaluate a newer vendor with a strong pilot or proof-of-concept but no prior state government contract? Is a phased or trial engagement a realistic path for smaller vendors?ANSWER: The Commission will evaluate vendor responses consistent with the terms specified in the RFP, including the weights given to each category. Therefore, a vendor with a strong proof of concept may still be considered for final award, depending on how it scores generally and relative to other proposals. The consideration of a phased or trial engagement cannot be addressed at this time as it is outside the scope of this RFP.Question 3: Media Strategy Development Cost Line ItemThe cost proposal template requests a "Media strategy development cost" line item (Part Three, II.B). For a purely technical blocking service with no public awareness campaign component, should this be listed as $0, or is a media or outreach component expected as part of the deliverable?ANSWER: A proposer should list actual or projected costs associated with a public awareness campaign. If no such campaign exists, then $0 would be appropriateQuestion 4: Demographic Reporting vs. PrivacyPart Two, Section IV requires on-demand reporting including "user demographic information," while Evaluation Criterion II weighs "privacy protections for service user information" at 20 points. For a solution architected to collect no personal or demographic data beyond connection location (IP-based), how should a vendor address the demographic reporting requirement? Would location-based aggregate data alone satisfy this requirement, or does the Commission expect additional demographic fields such as age or gender to be collected at sign-up?ANSWER: The Commission collects user demographic information for the purposes of monitoring the efficiency and efficacy of its program services. Therefore, vendors should submit in their RFP the information that they collect from end users who sign up for the service. The Commission will evaluate proposals consistent with its data collection needs.Question 5: Vendors Based in the European UnionAppendix 1 (Executive Order 2019-12D) requires disclosure of the location(s) where services are performed and where State data is accessed, tested, maintained, or stored. Our solution is architected so that no user or State data is stored on any server: all blocking configuration and activity data remains local to the participant's device. The only data processed off-device consists of anonymized, aggregated product-usage analytics, processed through a U.S.-based analytics provider (Amplitude). Given this architecture, would it be acceptable under the Executive Order for a vendor to operate and provide support from the European Union, or does the Executive Order require the vendor's operational location itself (development, support) to be within the United States regardless of where data is or isn't stored?ANSWER: Executive Order 2019-12d applies to data and services that are performed outside the United States. Any foreign company or American company which offers services provided hereunder and outside the United States will need to apply for a waiver for Executive Order 2019-12d through the Department of Administrative Services, which the Commission will facilitate. Assuming a waiver is granted, a vendor’s operational location need not be in the United States. | Answered: 7/29/2026 Inquiry 93618 | Part Two, Section IV requires quarterly reports demonstrating the number of participant licenses used. Does the Commission have an anticipated or maximum number of participant licenses for the contract term, a target enrollment figure, or historical utilization from comparable programs that Proposers should use as the basis for pricing? | Answer: Answers to Multiple Questions1. Anticipated license volume. Part Two, Section IV requires quarterly reports demonstrating the number of licenses used. Does the Commission have an anticipated, target, or maximum number of participant licenses for the contract term that Proposers should use as a basis for pricing? ANSWER: The Commission has no anticipated, target, or maximum number of participant licenses for the term. Historically, the Commission anticipates having around 35-40 users sign up for these services per month. These numbers are not, however, guaranteed.2. Distribution channels. How does the Commission anticipate making the service available to Ohio residents — direct publication, referral through treatment providers and prevention staff, helpline referral, or other channels? This affects how enrollment access is structured and reported.ANSWER: The Commission provides awareness of the program through direct publication, referral through treatment providers and prevention staff, a helpline referral and other state agencies. The Commission reserves the right to identify and implement additional avenues to publicize the service during the term of the contract.3. Block duration. Part Two, Section IV requires participants to configure "duration periods" during sign up. Would a participant-selected commitment period, enforced as a mandatory delay on any request to weaken or remove protections rather than as a fixed term that expires, satisfy this requirement?ANSWER: Any configuration of duration periods should be addressed in the response to the RFP, including any flexibility in the level of blocking services. 4. Residency verification. Is the Contractor required to verify that participants are Ohio residents, or is participant self-attestation of Ohio residency sufficient?ANSWER: There is no requirement that the Contractor verify that participants are Ohio residents. However, the Commission expects a vendor to identify and report a user’s location. 5. Secure Commission access. Deliverable 2 requires ensuring authorized personnel have secure access to the service for monitoring and reporting. Does the Commission expect a web-based reporting portal, scheduled report delivery, or both?ANSWER: The Commission expects regular reports, and a vendor should provide the mechanics of how this will be accomplished in its response to the RFP.6. Payment structure. Part Five, Section II states the services contract will specify the payment structure. Does the Commission have a preferred invoicing cadence that Proposers should reflect in the budget milestone timeline required under Part Three, Section II.B?ANSWER: The Commission does not have a specific payment structure requirement. This will be set forth in any final contract with prevailing vendors. 7. Contract term. Is there any option to extend or renew beyond June 30, 2028, and should Proposers price only the initial term?ANSWER: The Commission may consider an extension following the conclusion of the term.8. Multiple awards. Part Five, Section III states the Commission intends to award one or more contracts. Would the Commission consider awards to more than one vendor offering complementary approaches to the same program?ANSWER: The Commission has the discretion, but not the requirement, to award contracts to multiple vendors. | Answered: 8/3/2026 Inquiry 93627 | See attached list | Answer: 1) Our first question relates to the OhioBuys terms and conditions, specifically the following section:"VI. PERFORMANCE AND COMPLIANCE D. CUSTOM DELIVERABLES. All custom work done by the Contractor and covered by this Contract, including any software modifications, and documentation, will belong to the State with all rights, title, and interest in all intellectual property that comes into existence through the Contractor's work under this Contract being assigned to the State. Additionally, the Contractor waives any shop rights, author rights, and similar retained interests in any such custom developed materials. The Contractor must provide the State with all assistance reasonably needed to vest such rights of ownership in the State. However, the Contractor will retain ownership of all tools, methods, techniques, standards, and other development procedures, as well as generic and preexisting shells, subroutines, and similar material incorporated in any custom Deliverable ("Pre-existing Materials"). The Contractor grants the State a worldwide, non-exclusive, royalty-free, perpetual license to use, modify, and otherwise distribute all Pre-existing Materials that are incorporated in any custom- developed Deliverable, including distribution to third parties as required by funding mandates. The Contractor may not include in any custom Deliverable any intellectual property unless such has been created under this Contract or qualifies as Pre-existing Material. If the Contractor wants to incorporate any Pre-existing Materials in a custom Deliverable, the Contractor must disclose that desire to the State and obtain written approval from the State for doing so in advance. On the request of the Contractor, the State will incorporate any proprietary notice that Contractor may reasonably want for any Pre-existing Materials included in a custom Deliverable in all copies the State makes of that Deliverable. Subject to the limitations and obligations of the State with respect to Pre-existing Materials, the State may make all custom Deliverables available to the general public without any proprietary notices of any kind."- Standard_T_C_3-31-25.pdfWe raised similar concerns with the Massachusetts Gaming Commission, during our successful tender to them to deliver blocking software for the state of Massachusetts where similar requirements were built in and subsequently adjusted. Supplier is an international service. We are keen to cooperate with the Casino Control Commission to deliver necessary support to Ohioans, but any tools of features developed are provided to ALL of our users, not simply users in Ohio. We cannot give ownership of Supplier, or any of the work we undertake to update/improve the service during the period of the contract to the State of Ohio.We are happy to grant ownership to the State of any cooperatively created content, copy or signposting. But we cannot give ownership of the Supplier app, or any features or updates made to the app during the period of the contract, to the State.We need to ensure that expectation around ownership of the service are clear before moving forwards?ANSWER: The Commission intends for this to be a service provided to the Commission; it is not necessarily a custom work. Please include this exception to the Standard Terms & Conditions if you deem it necessary.2) Our second question again relates to the OhioBuys terms of use, specifically:"All Contract Data at rest in systems supporting the Contractor’s services must reside within the contiguous United States with a minimum of two data center facilities at two different and distant geographic locations, ensuring physical and environmental protection controls are implemented as defined in State IT Security Policy 2100-15, and be handled in accordance with the requirements of these Terms at all Contractor locations. All Contract Data that is not classified as public by the State must be encrypted at rest and while in transit utilizing industry standards that meet Federal Information Processing Standards (FIPS) validated algorithms and comply with State IT Security Policy IT-14, Data Encryption and Securing Confidential Data."- Standard_T_C_3-31-25.pdfThis again is another issue that came up when we were submitting our successful tender to the Massachusetts Gaming Commission, and indeed has come up in other forms with each of the other international regulatory agencies that we've worked with officially to deliver blocking software support for their populations. Supplier is an international service that supports users all over the world. We are very cost effective, but part of the reason for that is that no one country or state is paying for the entirety of the service. They each contribute to the a small amount to the overall costs of the operation. We have a single set of servers, and a Content Distribution Network (CDN) that creates pseudo-servers in over 300 locations around the world.During the application process each authority, understandably, looks to build in data protection requirements that would geolocate information about users in their population to their jurisdiction. This creates an impossible tension for Supplier. Where each regulator we support insists on servers being located locally, this forces a dynamic where Supplier would have to create independent services for each jurisdiction, duplicating the expense of our organisation's server needs, and requiring a custom version of the app to be coded and distributed that would explicitly point that jurisdiction's users to that jurisdiction's servers. This duplication of workload would drive the cost of delivering support up by several times what we would ordinarily quote.As a registration free service, Supplier holds very little personal information on our users. The only time that we have contact information for our users is where they reach out to us for technical support, necessitating an email address for response. Our servers are currently located in the UK, a jurisdiction with a very robust data protection framework. And prior to any contract with the State of Ohio, Supplier has already been supporting large numbers of Ohioans for nearly a decade with zero data protection issues.We need clarification from the Casino Control Commission regarding whether our current delivery model is acceptable, or whether additional infrastructure would be required, so that we can appropriately cost our application?ANSWER: The Commission cannot speak to the adequacy of a vendor’s delivery model or Contract Data to be collected. Please indicate any concerns in the response to the vendor’s internal controls and delivery mode, and the Commission will review. If necessary, a vendor may provide alternate line item and cost proposals.3) Referring to document Gambling_Blocking_Services_RFP_Updated.pdf, we would direct the Casino Control Commission's attention to the following requirement:"Provide on-demand reporting of the following information, at a minimum: Sign up information Date and Time Location Block duration and content" Supplier is a registration free service, that prioritize user anonymity. There are significant benefits to this approach, including substantially higher user uptake, but this does limit the information that we gather. While we can provide substantive reporting data via anonymised, aggregate data from various analytics platforms - as we do when producing reports for other regulatory agencies - user specific data like sign-up information etc is not something we can provide.Before proceeding, we need to understand if this is a requirement that the Casino Control Commission can adjust to the registration free model that Supplier provides?ANSWER: The Commission will consider all proposals which meet the minimum requirements as set forth in the RFP. The Commission will score all responses with the metrics set forth therein. The Commission emphasizes that it needs certain user data in order to measure the efficacy of its programming. | Answered: 8/3/2026 Inquiry 93631 | See attached list | Answer: 1. My first question relates to Executive Order 2019-12D. All of our data for US users is stored, accessed, and processed from US servers. It may be temporarily and ephemerally transferred to a different location for purposes of support or account management for example. I would like to request a waiver on this basis if possible?ANSWER: The Commission will work to prepare the appropriate waivers for each vendor if they are awarded a contract. The Department of Administrative Services must provide final approval of any waiver submitted as part of this solicitation.2. Appendix 2 contractor information requests the number of minorities in our employment. However, I can't find how the state defines a minority.ANSWER: For the purposes of the State’s Minority Business Enterprise program, minorities are defines as: blacks or African Americans, Hispanics or Latinos, Native Americans, or Asians. Please refer to R.C. 122.71.3. We're uncertain how to use the technical and financial questionnaire Excel sheets. We created our proposal in separate documents, what should we include in each field? Do we simply transpose our answers to each of the RFP questions into the fields in the Excel sheet? Or is my copy of the excel sheet missing data?ANSWER: Please address all technical and financial questions in your response to the RFP. There are no additional requirements found in the RFP technical and financial portions which require the use of the Excel spreadsheets. | Answered: 8/3/2026