Zero Trust Encryption RFI

Project ID: 36C10B26Q0474 FederalOpportunitiesSources Sought
Overview
AgencyVISN 16: South Central VA Health Care Network
Deadline06/23/26
Posted06/13/26
Estimated Value$1,500,000 - $5,000,000 (AI estimate)
Set AsideSDVOSBC
NAICS541519 - Other Computer Related Services
PSC7G21 - IT And Telecom - Network: Digital Network Products (Hardware And Perpetual License Software)
LocationEatontown, NJ 07724 United States
Description
Primary Latest Change

VA Office of Information and Technology, Infrastructure Operations operates one of the largest and most complex information technology environments in the federal government, spanning on-premises data centers, private cloud infrastructure, and public cloud services delivered through the VA Enterprise Cloud (VAEC). At the cryptographic foundation of that environment sits VA's enterprise Hardware Security Module (HSM) fleet, which provides the cryptographic backbone for VA's Public Key Infrastructure (PKI), Key Management Services (KMS), digital certificate operations, and cryptographic processing for a broad portfolio of clinical and administrative systems, including the Veterans Health Information Systems and Technology Architecture (VistA) and VAEC-hosted workloads. The Government-furnished fleet consists of ten production network-attached HSM appliances, eight Luna Network HSM T-5000 and two Luna Network HSM T-2000, at firmware version 7.11, deployed across four geographically distributed CONUS gateway data centers, together with partition capacity licenses, HSM administration kits, and backup HSM components. The fleet is described at the gateway and metropolitan-area level in the attached sanitized Attachment A; system identifiers, serial numbers, and facility street addresses will be provided with the solicitation. The Contractor would assume full maintenance and managed-service responsibility for this equipment in its as-found configuration upon completion of transition-in. VA is executing an enterprise Zero Trust modernization program consistent with its Critical Security Controls. Under that program, all HSM operations, including key lifecycle management, partition management, PKI operations, and cryptographic services for VA endpoints and applications, are core components of VA's Zero Trust encryption posture. In August 2024, the National Institute of Standards and Technology (NIST) finalized its first post-quantum cryptographic standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), making post-quantum cryptography (PQC) readiness a mandatory enterprise requirement for all HSM infrastructure. The Government is seeking industry feedback on technical approach, the salient characteristics, the staffing and key personnel model, the planned transition to Government operation, acquisition strategy, and pricing to inform its procurement planning.

Summary (Newest Update)

Background The VA Office of Information and Technology, Infrastructure Operations manages a vast and intricate IT environment within the federal government, encompassing on-premises data centers, private cloud infrastructure, and public cloud services via the VA Enterprise Cloud (VAEC). Central to this environment is the VA's enterprise Hardware Security Module (HSM) fleet, which underpins the Public Key Infrastructure (PKI), Key Management Services (KMS), digital certificate operations, and cryptographic processing for various clinical and administrative systems. The fleet includes ten production network-attached HSM appliances: eight Luna Network HSM T-5000 and two Luna Network HSM T-2000, all at firmware version 7.11, distributed across four CONUS gateway data centers. The contract aims to support the VA's Zero Trust modernization program aligned with Critical Security Controls and mandates readiness for post-quantum cryptography (PQC) as per NIST standards. Work Details The Contractor will provide comprehensive managed services, hardware sustainment, lifecycle support, professional services, and PQC upgrade capabilities for the VA's enterprise HSM infrastructure. Key tasks include: 1. Project Management 2. HSM Hardware Sustainment and Maintenance 3. HSM Managed Services and Partition Lifecycle Management 4. Post-Quantum Cryptography Readiness and Upgrade Services 5. Professional Services, Market Research, and Advisory Support 6. Transition-Out to Government Operation All solutions must comply with defined Salient Characteristics including: - FIPS 140-3 Level 3 validation for cryptographic modules. - Tamper-resistant enclosure with automatic zeroization upon intrusion. - In-field firmware upgradeable to NIST-standardized PQC algorithms without hardware replacement. - Support for multi-tenancy with isolated cryptographic partitions. - Minimum 99.9% availability across the managed HSM fleet. Period of Performance The anticipated period of performance is a twelve-month base period with four twelve-month option periods, totaling up to sixty months. Place of Performance Services will be performed across the VA's national footprint of data centers and gateway locations. Bidder Requirements Bidders must meet the Service Disabled Veteran Owned Small Business Set-Aside (SDVOSBC) status. Additionally, they must ensure compliance with all relevant standards including FIPS 140-3 for cryptographic modules and demonstrate capability in providing managed services that align with VA's Zero Trust Critical Security Controls.

Contacts
Contact nameJustin B Clark
Contact emailjustin.clark2@va.gov
Contact phoneNone
Secondary contact nameDavid A. Long
Secondary contact emaildavid.long4@va.gov
Secondary contact phoneNone
Same Region Opportunities