Description
This is a combined synopsis/solicitation for commercial products or commercial services. Proposals are being requested and a written solicitation, with the redacted Justification For An Exception To Fair Opportunity, is attached. This requirement is issued as a 100% total small business set-aside. The Department of Veterans Affairs (VA), Office of Information & Technology (OIT), Office of the Chief Technology Officer (OCTO) has a requirement for the renewal of the Brand Name ID.me Identity and Access Management (IAM) Credential Service Provider (CSP) Software-as-a-Service (SaaS) solution which includes an annual Credential Brokers license, maintenance support and help desk assistance. VA, OIT, OCTO requires the ID.me CSP SaaS solution to support new and renewal user proofing subscriptions, which allow individuals to prove their identities and establish credentials for the purposes of secure authentication into external VA systems, such as VA.gov, the VA Health and Benefits mobile app, VA s Enterprise Service Desk, and more. VA requires a CSP that can be used by anyone who needs to interact with VA s external digital tools, including Veterans and beneficiaries, family members, dependents, and caregivers that live in the United States or abroad; VA employees and Contractors; and other professionals interacting with VA in an official capacity. To support all users, VA requires a CSP that allows users having difficulty completing identity verification remotely to transfer to a human-assisted process with a person who can act as a trusted referee, which the National Institute of Standards (NIST) defines as a person or organization that can vouch for the identity of the end user. VA also requires a CSP that meets Federal identity standards set by NIST at the following levels: 800-63-2 Level of Assurance (LOA) 1, 2, and 3; NIST 800-63-3 Identity Assurance Level (IAL) 1, 2; and Authenticator Assurance Level (AAL) 1, 2, and 3. In addition, VA requires a CSP that is compliant with the Office of Management and Budget Memo 19-17, which requires federal agencies to use NIST 800-63 compliant credentials that are federally or commercially shared, and with Executive Orders 14249, 14247, and 14271, which prioritize fraud reduction and usage of commercially available solutions. Also, VA requires a CSP that can verify users internationally. Finally, VA requires a CSP that is interoperable with its current infrastructure, including VA s Single Sign-On external (SSOe) technical stack, the VA.gov platform, the VA Health and Benefits Mobile platform, the VA Lighthouse Application Programming Interface (API) and the My HealtheVet (MHV) platform. For ID.me, VA requires renewal of the yearly Credential Broker license, which allows up to 125 million Multi-Factor Authentication (MFA) events in the Base Period and in each Option Period, as well as maintenance support and help desk support. The Broker License will provide Veterans with publicly available customer support, inc…
Classification
Contracting Office
Contacts
Attachments (3)