Veterans Affairs - OIT Industry Day - March 27th, 2026

Examples: Zero Trust, "FedRAMP" OR CCaaS, Oracle -"Supercluster", Veteran outcomes -RFI

Keynote

Will the briefing slides be available after the sessions? TY

Yes, the briefing slides are posted on the Virtual Office of Acquisition (VOA) site that was provided to everyone at the end of the event, and on your slides that were posted during and after the event.

Is it possible to get a list of attendees?

Unfortunately, we cannot share other vendors' information because we did not receive or provide a release for all vendors to sign authorizing us to share their information.

Is it possible to get email addresses for the speakers?

Unfortunately, we will not be sharing the email address of our requirement owners; however, you can attend our Office Hours to get information and see them on those calls that will be scheduled through September.

Herman Akins, CEO, Venture Wellness Lab (veteran-owned). What procurement pathways exist for veteran-owned small businesses developing AI tools for VA claims?

VA does not have a single procurement pathway. Businesses are encouraged to monitor SAM.gov for opportunities and actively participate in market research activities, including responding to Requests for Information and Sources Sought notices. These early engagement activities are critical, as they inform acquisition strategies and help VA better understand industry capabilities. Businesses are also encouraged to participate in industry engagement and outreach events to align their solutions with mission needs and position themselves for future opportunities.

As VA modernizes IT, how are you addressing fragmented financial and operational data across systems to improve visibility, decisions, and audit readiness?

Response in progress

All of these RFIs and RFPs will be in SAM, correct?

That is correct. Note, if a particular vehicle is selected and it has its own RFQ/RFP posting tool (e.g., a GSA vehicle), the solicitation will be posted using that vehicle's posting tool.

Kindly provide guidance on accessing and participating in the office hours sessions.

You will go back to the Virtual Office of Acquisition (VOA), select OIT Industry Day, open the Library, and click on Office hours by month. There will be an MS Teams invite with the specific requirements that will be discussed for that specific month.

How do we get in touch / contact with the project stakeholders to identify pain points of current problems?

Through our Office Hours being scheduled on the VOA site, we provided guidance to access and go to the OIT Industry Day documents and click on the months listed to see which requirements will be discussed.

Does VA OSDBU in collaboration with VA OIT plan to resurrect the annual National Veteran Small Business Engagement Conference (NSVBE) this year?

VA continuously evaluates opportunities to engage industry through outreach events. Any future engagements will be communicated through official VA channels as information becomes available.

TAC and OIT did not publish a forecast H2 of last FY or during H1 of this FY which included timing of the RFI for Health DSO.

The intent of this statement/question is unclear; however, the Health DSO effort is included om the Acquisition Gateway Forecast Tool (https://acquisitiongateway.gov/forecast/resources/39707) and the RFI was released on SAM.gov in early February (https://sam.gov/workspace/contract/opp/8282f46a2e864a96b40ff27d16572354/view)

Would the TAC consider reissuing an RFI on HDSO and notifying industry so SMB can view differently based on SAM constraints?

It is unclear as to what SAM constraints exist; however, TAC does not plan to reissue an RFI at this time.

SAM is not easily searchable without having a forecast including contract titles and expected dates. Small business are constrained to search SAM.

Businesses are encouraged to use SAM.gov as the official source for current contracting opportunities. To supplement this, USAspending.gov can be used to conduct market research on historical contract awards, including identifying incumbent contractors, contract values, and patterns of spending. This information can help businesses better understand VA requirements and position their capabilities for future opportunities. Additionally, APEX Accelerators provide training and one-on-one assistance to help businesses navigate Federal procurement systems and develop effective market research and search strategies. VA OSDBU shares select VA business opportunities compiled from SAM.gov through its LinkedIn channel (https://www.linkedin.com/company/vaosdbu) to increase awareness.

Acquisition website: None of the items from industry day were on the Acquisition website. Is there a better way to locate these for SDVOSB?

We are coordinating internally to ensure the information discussed is populated on the GSA Acquisition Gateway tool.

Questions are limited to 33 characters making it difficult to ask meaningful questions.

This is incorrect.

What is VA OIT's overarching AI strategy for IT modernization, and how are contact center capabilities expected to contribute to that vision?

Response in progress

What is VA's priority for small business prime contractor participation across the full modernization portfolio?

VA is committed to providing maximum practicable opportunities for small businesses, including Service-Disabled Veteran-Owned Small Businesses and Veteran-Owned Small Businesses, consistent with statutory requirements under 38 U.S.C. § 8127. This priority is reflected during acquisition planning through market research and industry engagement, where input from Requests for Information (RFIs) and other interactions help shape acquisition strategies, including small business participation. Businesses are strongly encouraged to respond to RFIs and Sources Sought notices, as these responses play a critical role in informing acquisition decisions. Participation levels will vary depending on the nature, scope, and complexity of each requirement.

How is VA measuring Veteran-facing service improvements as an outcome of the broader IT modernization effort?

Response in progress

What is VA's strategy to tap into a wider range of small businesses, including innovative companies outside the SDVOSB community?

VA conducts a range of engagement activities to reach a broad spectrum of small businesses, including industry days, outreach events, conferences, and networking sessions. These engagements are designed to increase awareness of VA requirements, facilitate collaboration between industry and VA stakeholders, and provide businesses with insights into how to be procurement ready. VA also leverages ongoing dialogue with industry through office hours, vendor engagement sessions, and broader forums to share information, gather feedback, and promote transparency in the acquisition process.

Does VA have guidelines for OCI on PMO/Advisory contractors? They bid on contracts they have competitive advantage on: IGCE/staffing /billing/solicitations

OCIs are handled on a case by case basis with the contracting officer and involve coordination with the Office of General Counsel. If there are specific questions around potential OCI on an acquisition, those questions should be directed to the contracting officer.

1. Does the VA/OIT expect to adopt the same DoD CMMC Program Rule ( 32 CFR part 170) and CMMC Acquisition Rule ( 48 CFR) for VA contracts in the future?

Response in progress

IF CMMC requirements are not adopted, will the VA/OIT consider adding points for SDVOSB’s or large/small teams’ points if they are CMMC certified?

Response in progress

Regarding the contract vehicle T4NG, has all the Task Orders been transitioned to T4NG2?

Response in progress

Regarding the Task Orders on the T4NG vehicle, are they going to be recompeted on T4NG2 or could they be switched to another vehicle or GSA MAS?

Response in progress

Would the DLP opportunity be released under other contracting vehicles so that other SDVOSB partners could provide best value? Currently it’s under T4NG

Response in progress

There were several GSA MAS VA RFIs cancelled (RFI1798119) on March 9th. Can you advise why the RFI was cancelled and if it may be reissued at a later date?

Response in progress

Product Delivery Services

Thank you for a transparent overview. Do you intend to keep Health DSO as a single contract or split to allow for focused modernization vs application maint?

The contract strategy is still under deliberation, however the expectation is that it will be part of the same contract.

As VA accelerates digital transformation, how are you ensuring those systems actually improve clinical outcomes, not just delivery speed and performance?

The expectation is that improving clinical experience and outcomes is at the forefront of everything we deliver. Speed and performance are important, but improving clinical outcomes is our focus.

how are you ensuring that what gets deployed remains clinically safe and appropriate in real-world use?”

We employ Key Performance Indicators and expect that teams will deliver clear outcomes that remain clinically safe.

Would the TSS3.0 opportunity would be released with in GSA MAS again ?

OIS should respond

What CRM do you use today? For what purposes? Will that change in the next 2 years?

OIT utilizes multiple CRM soultions. We are constantly reviewing those solutions and are activly analyzing the latest CRM solutions available.

What is your tech stack today? What will that stack look like 2-3 years from now?

Our tech stack varies by product and portfolio, we continue to frequently evaluate this model and will make changes as nessecary.

Appreciate guidance on how to demonstrate CloudLCMS. Our team requests the opportunity to provide a focused demonstration alignment with VA needs.

requesting a meeting?

Where do I find these opportunities?

www.sam.gov

is the VA moving to GSA MASS contract?

recommend OSS respond.

CERTARA hoping to pilot our AI platform in support of your goals. https://www.certara.com/certara-ai/real-world-applications/ Respectfully, William Cahillane

requesting a meeting?

Good afternoon, is there a Supply Chain Risk Management platform included in the SCM Portfolio?

VA is not aware of the platform suggested and would require more information to respond appopriately.

Should we expect any OCI concerns between EDGE and OMEGA? Is it possible that vendors will need to choose between the two? Or is it OK to bid/perform on both?

recommend the TAC respond.

Can you provide updates on the SPRUCE IDIQ, how OIT plans to leverage this contract vehicle, and when we can see more task orders being released in 2026?

SPRUCE is not managed by PDS.

PCT RFI This had a separate and distinct scope difference from the PIVOT RFI. What is the plan with Payer Compliance and Fraud detection with both PCT and Pivot

Response in progress

Will the VA define minimum performance thresholds directly tied to delivered service outcomes?

recommend the TAC respond regarding performance thresholds.

Will the VA accept a phased deployment model vs. requiring full 20,000-seat readiness at initial delivery?

recommend the TAC respond on what is considered acceptable.

Do you have documentation of your current contact center infrastructure, ie, an architectural diagram?

No, I don't believe PDS has a comprehensive document. CCS or the administrations may have them for their respective contact centers.

Is there a preference for your contact center locations?

Response in progress

What KPIs are you experiencing in your environment?

Response in progress

How is VA approaching AI and automation integration across the Product Delivery Service portfolio beyond individual task orders?

Response in progress

Are there enterprise-wide API or interoperability standards being established across PDS product lines to reduce integration complexity?

Response in progress

How is VA balancing technical debt reduction with the need to deliver new capabilities across the health portfolio simultaneously?

Response in progress

Will the VA apply price realism to Task Orders under T4NG2?

recommend the TAC respond.

How will VA balance Zero Trust governance with LCNC and citizen?developer autonomy, measure vendor outcomes beyond SLAs, and integrate AI under FedRAMP/ATO?

DTC to respond.

Office of Information Security

What is VA's current Zero Trust Architecture maturity level across each pillar, and will vendors receive pillar-specific targets to reach optimal by FY2028?

VA’s current ZTA maturity level across each pillar is: Identity – Initial; Devices – Traditional; Networks – Initial; Applications & Workloads – Initial; and Data – Traditional. Vendors will receive pillar specific targets to reach Optimal and will be expected to provide detailed plans on how to achieve outcomes in each of the Pillar / Capability areas.

How is VA planning to address emerging AI-driven cyber threats and evolving executive orders within the ZTA Acceleration requirement?

VA plans to remain agile to future Executive Orders and mandates, and deploy AI detecting capabilities in threat intelligence to combat AI-drive cyber threats such as User Entity Behavior Analytics to detect and respond to anomalous behaviors.

Does VA's DLP coverage gap span endpoint, cloud, and collaboration equally, or is one environment the primary focus for this requirement?

This effort will prioritize closing exfiltration gaps across endpoints, cloud, and collaboration platforms based on risk.

Will enterprise-wide Structured Data Discovery, Analytics, and Labeling (DDAL) be a required baseline deliverable under the DLP effort?

The Structured DDAL is an independent acquisition and initiative focused on identifying and labeling structured data. After discovering and labeling the data, this effort will configure, test and fine-tune enforcement policies for implementation.

How is the VA streamlining the ATO process to keep pace with the speed at which cloud-based and AI-enabled technologies are being introduced?

VA is accelerating its Authorization to Operate (ATO) process by introducing Security Exposure Risk Analysis (SERA) and Authorization through Continuous Evaluation (ACE), which streamline risk reviews, reduce idle time, and enable authorization decisions within 60 days. Deploying a new OIS Intake Portal and Continuous Monitoring Dashboard further unify workflows and provide real‑time system risk visibility to support faster adoption of cloud and AI technologies. Key required evidence to begin SERA includes a Security Assessment Report or external security framework assessment (SOC 2 Type 2, ISO 27001, HiTrust, or NIST 800-171 Self assessment), Architecture / Data Flow Diagrams, Asset Inventory, and credentialed vulnerability scans.

Is the VA moving toward a unified security and compliance framework that will apply consistently across vendors supporting multiple requirements?

Yes, the VA, through its OIT and evolving VAAR regulations, is clearly establishing a unified and consistent security and compliance framework for all vendors. This effort aligns contract clauses, internal directives, and lifecycle risk management to apply across the board, minimizing fragmentation and increasing vendor accountability.

How is the VA preparing its cybersecurity posture to address the risks that come with expanding AI capabilities across the enterprise?

VA is encorporating specific AI security controls into it's Risk Management Framework program including the NIST guidance of NIST SP-800-53 Revision 6.

How will VA measure vendor accountability for enterprise DLP across endpoints, cloud, collaboration tools while aligning with Zero Trust and AI?driven risks?

Vendor accountability can be assessed using a scorecard that reflects actual protection results, such as endpoint coverage, cloud security, policy enforcement for collaboration tools, high-quality identity-based zero trust controls, and the ability to detect AI-related data leaks. Additionally, vendors would be evaluated using defined set metrics for false positive rates, response times, and comprehensive, audit-ready reporting across all systems.

How are you validating that what your DevSecOps pipelines produce is clinically correct, not just technically correct?”

VA's DevSecOps pipelines are strongly aligned with the individual business owners in the Administrations to ensure outputs align with the business owner's expected outcomes, .e.g. clinically correct, by employing strict configuration management practices such as user acceptance testing prior to deployments.

How are you ensuring AI-driven cyber decisions remain safe when they’re technically correct but contextually wrong?

Human‑in‑the‑loop oversight is essential because AI can make cyber decisions that are technically accurate yet unsafe without understanding business context, risk appetite, or operational impact. Keeping humans embedded in the decision chain ensures AI recommendations are validated, contextualized, and aligned with real‑world risk, emerging threats and governance requirements.

How are you ensuring automated risk decisions address root causes without creating downstream operational or clinical risk?

By identifying the true underlying cause of a security event or risk decision required and apply it safely by factoring in the clinical context and criticality of the affected asset, ensuring the right fix is applied in the right place without disrupting patient care. Automation brings the need to also a line with business impacts and those impacts will be considered in decision making. Human in the loop as described in previous question will be leveraged.

How do you ensure DLP actions prevent data loss without disrupting critical clinical workflows?

We prevent DLP actions from disrupting essential clinical and business operations by phasing in controls, validating policies with data owners, and adjusting them to match user workflows. We begin with monitoring, enforce progressively based on risk, and collaborate on an exception process to ensure critical activities continue under supervision.

What is the relationship between VA-mandated cybersecurity requirements and FedRAMP authorization? Does one set of requirements supercede the other?

FedRAMP authorizations—whether through the legacy Rev5 process or the modernized FedRAMP 20x certification—establish a federal baseline for cloud security. However, these authorizations do not replace, override, or supersede VA‑mandated cybersecurity requirements. The VA retains full responsibility under the Federal Information Security Modernization Act (FISMA) to determine and enforce agency‑specific security controls and risk acceptance criteria. As such, all systems handling VA data must meet both FedRAMP requirements and the VA’s own security controls, assessments, and authorization processes.

TSS3.0 covers distinct service areas. Will VA consider multiple awards or small business set-asides for any task areas, or require SB participation plans?

We are currently in the process of gathering and refining requirements for TSS 3.0, and several scope elements are still being defined. As the VA finalizes its needs, we will ensure that all considerations focus on delivering the best overall value to the Department, its mission, and the Veterans we serve.

Will the OIG IT audit/material weakness remediation task area include audit management platforms and POA&M tools, or is it limited to advisory services only?

We are currently in the process of gathering and refining requirements for TSS 3.0 and several scope elements to include tools and technology. The scope will emphasize operational execution over advisory services. We require qualified personnel to deliver hands-on, implementation-focused support. As the VA finalizes its needs, we will ensure that all considerations focus on delivering the best overall value to the Department, its mission, and the Veterans we serve.

Will TSS 3.0 be competed on GSA MAS again or a different vehicle (T4NG, Alliant 2)? Which vehicle should small businesses prioritize for teaming eligibility?

We are currently in the process of gathering and refining requirements for TSS 3.0, and several scope elements are still being defined. As the VA finalizes its needs, we will ensure that all considerations in contract vehicle focus on delivering the best overall value to the Department, its mission, and the Veterans we serve.

What mechanisms does VA provide for small businesses to engage with potential prime contractors on upcoming opportunities?

To reach VA about business opportunities, contact the OIT Vendor Management Office, more information can be found at this link: https://digital.va.gov/general/vendor-management-office-opens-the-door-to-industry-partnerships/. VA provides multiple avenues for engagement with potential prime contractors, including industry events, networking sessions, and targeted outreach engagements. VA OSDBU’s Direct Access Program (https://vetbiz.va.gov/dap/) is one such mechanism that facilitates connections between small businesses and prime contractors, supporting increased visibility and partnership opportunities.

I own B203 LLC, a SDVOB. We install premises cabling & manage electrical, access control, security & FA contractors. Any data center opportunities available?

To reach VA about business opportunities, contact the OIT Vendor Management Office, more information can be found at this link: https://digital.va.gov/general/vendor-management-office-opens-the-door-to-industry-partnerships/

How can I contact someone about a new AI IVR system?

To reach VA about business opportunities, contact the OIT Vendor Management Office, more information can be found at this link: https://digital.va.gov/general/vendor-management-office-opens-the-door-to-industry-partnerships/

Infrastructure Operations

How are your current web services integrating with the VA's z16 mainframes?

Web services are provided external to the VA Mainframes. We do use web services internally to the mainframe so system programmers and developers can access for operational purposes.

What integration tools or platforms are you trying to reduce or replace as a result of cost and complexity?

VA does not have a specific list of tools to reduce or replace. Instead we are looking for experienced vendor partners that have demonstrated the ability to effectively manage large scale IT infrastructure to make recommendations that will result in reduced cost and complexity as part of this acquisition

Does the VA currently have systems integration with the mainframe terminals to support legacy applications?

All applications are accessible and supported with various connection methods including Reflections, TCP/IP and SFTP.

What gaps have you identified with your current IGA solution that are driving this modernization effort? Are you looking to replace your current IGA platform?

VA is modernizing all ICAM services, including IGA. The VA is in the process of replacing a custom-built IGA solution with a modern SaaS platform to provide a true enterprise solution for the agency.

How is VA approaching long-term mainframe planning — is there a modernization or migration roadmap that informs this effort?

Long term mainframe planning is based on customer (application developers) roadmaps and modernization plans so we can scale the mainframes to meet throughput demands

Is VA targeting a specific DCIM tooling platform for ServiceNow integration, or is that architecture still being determined?

VA is currently utilizing Nylte Asset Optimizer (NAO) as the primary DCIM tool.

What is VA's current availability baseline for enterprise data centers, and how close is it to the Tier III 99.98% threshold?

VA’s enterprise data centers are Tier III–capable and currently operate at a 99.9% availability baseline IAW with our customer SLAs.

Where does VA stand today on migrating legacy Oracle Supercluster customers, and what is driving the urgency of that transition?

VA continues to evaluate the best path forward for transitioning legacy Oracle Supercluster workloads, and the timing is influenced by evolving platform support considerations, long term modernization goals including cloud migration opportunities, and the support status of the M8 Platform.

How is VA currently aligning CMOP IT support with VHA, and what coordination challenges is the program experiencing?

VA is actively aligning its Consolidated Mail Outpatient Pharmacy (CMOP) IT support with broader Veterans Health Administration (VHA) priorities to streamline pharmacy operations, enhance patient safety, and improve service delivery for Veterans nationwide. VA is pursuing this alignment by integrating CMOP IT systems with VHA’s electronic health record (EHR) platforms, modernizing legacy applications, and standardizing data and workflows across facilities.

What legacy identity tools are being retired, and how is VA managing the risk of fragmented identity processes during the transition?

VA will deprecate legacy ICAM processes and technologies as they are modernized and looks forward to what industry can provide to assist with effective transition efforts.

How is VA defining a unified onboarding experience across identity stovepipes, and what does that look like for end users today?

VA is looking forward to determining what industry can provide to support a unified customer experience across ICAM services, including provisioning and deprovisioning.

How does Identity Verification play a role in your IGA and PAM processes if at all? Do you intend to bring these solutions into the workflow?

VA is looking forward to hearing from industry on potential ICAM modernization efforts, including identity verification and Identity Governance and Administration.

How is the VA thinking about vendor accountability for outcomes rather than task completion as it structures the new IO contract vehicles?

The primary shift we are making is away from staff augmentation contracts to outcomes based for defined tasks. The intent is to prioritize more automated processes and better overall efficiency while still delivering the highest levels or services.

Is VA developing automation standards for infrastructure operations that vendors should be designing their solutions around today?

No. While VA has automated IT infrastructure management techniques deployed both on-prem and in the cloud, existing approaches should not limit vendor proposals

What's your ICAM strategy for integrating new SaaS and custom apps quickly and reliably as the VA's tech landscape evolves?

VA is looking forward to hearing from industry on potential ICAM modernization efforts, including the deprecation of legacy processes and technologies and how modernized SaaS tools are fully integrated.

How does your IAM/ICAM solution automatically revoke privileged access across all systems (including cloud) when a user's role changes or they leave the VA?

VA is looking forward to hearing from industry on potential ICAM modernization efforts, including joiner-mover-leaver automation, PAM, and RBAC initiatives.

How is the VA defining the long-term boundary between on-premises and cloud-hosted workloads as its hybrid infrastructure strategy matures?

VA has developed a workload placement strategy to better align systems and applications hosting solutions based on objective characteristics of the workloads. This strategy helps bring together other initiatives (data center consolidation, franchise fund expansion, cloud smart, etc.) to improve VA's hosting outcomes

Are you looking to run your IAM/ICAM modernization program as a managed service?

A fully managed service is not envisioned for this space, but VA is looking forward to hearing from industry on its ICAM modernization efforts, including service delivery models.

What additional projects and/or services does the department plans to consolidate beyond IGA rollout and PAM expansion for IAM/ICAM Modernization?

VA is looking forward to hearing from industry on all potential and feasible ICAM modernization efforts, and anticipates ongoing efforts to modernize and replace other legacy ICAM services.

Which organizations within VA will have the leading role in defining requirements, governance, and decision-making for IAM/ICAM Modernization?

To obtain and centralize enterprise IT support services for IAM and ICAM modernization, Infrastructure Operations (IO) will have the leading role in defining requirements, governance, and decision-making for VA’s ICAM program.

How will VA drive vendor accountability for hybrid infrastructure outcomes, automation, cost transparency, resilience while modernizing legacy and cloud ops?

VA will focus on successful management and operations of platforms, servers, containers, storage, etc. over adherence to "how" individual tasks are accomplished.

You spoke of "unifying the process." Is the goal a single, simple access for all VA users (employees, contractors, Veterans) to all entitled resources?

Yes, a simple enterprise process is desired. VA is looking forward to determining what industry can provide to support a unified user experience across ICAM services for both internal and external users, but not necessarily the same for both.

Will Franchise Fund Support Services BPAs (slides 27-32) be released on GSA MAS to allow for the best-in-class innovative solutions and stronger competition?

Yes, GSA MAS is planned to be leveraged for at least some the former Franchise Fund Support Services requirements

Is the Estimated Award Month/Year for the Application Hosting Compute and Storage contract (slide 27) Q1 of FY28, 18 months after the Estimated RFP?

No, the estimated award is Q1FY27

How are you tying infrastructure performance to actual clinical or operational outcomes, not just system metrics?

This is an important goal that has been challenging to address. VA aligns underlying infrastructure to supported business systems and groups systems based on the business outcomes they enable in the for of portfolios and product lines. The intent is to leverage these relationships to build better visibility into how specific infrastructure performance enables actual health, benefits or other business outcomes for VA employees and veterans.

Are you open to presentations from software partners that automate migration + modernization of VMs to/from Cloud or just from the prime services contractors?

VA is open to any approaches that improve efficiency for staff (govt and contractor teams), reduce compute and storage costs (on-prem and in the cloud) so long as the support customer needs and comply with federal security standards

With no incumbent baseline, where does VA OIT expect the initial performance framework to come from, the government, or the vendor during stand-up?

VA expects the vendor to propose an initial performance baseline and work with the government team to refine and improve it during the period of performance

When will the ICAM FFSS Contract be removed from the Application Services FFSS Contract? When will the New ICAM FFSS Contract be published?

The tasks have already been divided from the single PWS into 2 separate documents that will be used for the acquisitions. VA antipcates the ICAM RFP release during Q3 - FY26

When will the updated Application Services FFSS Contract be published?

Q4 - FY26

End User Services

How is VA currently managing SSD and RAM pricing instability, and what impact is that having on endpoint refresh timelines?

VA is closely monitoing the situation and plan to look at all proposals and RFQs on tight turnarounds to be able to lock in price. VA will be looking at leasing/managed service, bulk purchase agreements for set amounts of end points at a time to get pricing that can be honored by industry at time of award.

What is driving the approval-to-delivery delays for endpoints, and how is VA working to improve that process?

Delays are due to ensuring the end points can work in the VA complex enviroment. VA can provide list of approved models so industry can prosoe those models when bidding and also understand they types of models in use at va to ensure that when new models are purposed they are in similar range of modles that typically are approved at va.

How is VA coordinating endpoint refresh timelines with the EHRM rollout to make sure new hardware is in place when clinicians need it?

VA work between OIT and EHRM to ensure that when refreshign the latest endpoints are at the sites and refresh stays in proper alignment with the lifecycle. Once new specs come into play OIT will make decision to rotate out all devices to new specs over time

Is VA considering a managed service approach to endpoint lifecycle management, or will hardware procurement remain largely transactional?

Yes VA is considering managed service but not dimissing transactional/buying outright

How will VA measure vendor accountability for AI?first contact center operations, first?contact resolution, MTTR reduction, and ITSM integration beyond SLAs?

VA Enterprise Service Desk will measure AI efficacy via increased First-Touch Resolution, reducted MTTR, reduced contact volume and increased Customer Satisfaction and very likely additional SLAs still to be developed.

Is CCaaS a New Contract or recompete? The slide said 'New Contract' but listed LMI as the incumbent. If it's a recompete could VA provide the contract number?

VA Contact Center Infrastructure is a re-compete. VA118-16-D-1001

Connectivity and Collaboration

What is your current mean time to repair for network incidents, and what is driving the reliability improvement priority under NEDIIS?

Our current MTTR for medium impact network incidents is about 10 hours, which aligns well within industry expectations. The reliability focus under NEDIIS is driven not by performance gaps but by our commitment to continuous improvement. We’re refining our metrics and measurement practices to better quantify performance and reliability, reduce recurring impacts, and prevent issues before they occur. These metrics also help to trend issues, assess response patterns, and identify opportunities for automation and/or improvements to our processes. Ultimately, we’re focused on operational maturity and continually chasing the next “nine” in overall reliability.

Will CCaaS be set aside for small business (EDWOSB, SDVOSB, HUBZone, 8a), or full and open? Will subcontracting plans be evaluated?

Decisions regarding whether the CCaaS acquisition will be set aside for small business (EDWOSB, SDVOSB, HUBZone, 8(a)) or competed as full and open fall under TAC’s acquisition strategy, not OIT. Similarly, the determination of whether subcontracting plans will be required and evaluated is also a TAC-driven procurement decision. OIT does not make or influence set‑aside determinations or subcontracting plan requirements

Is VA open to CCaaS solutions with FedRAMP authorization levels above Moderate, and how does that factor into evaluation planning?

VA is open to considering CCaaS solutions with FedRAMP authorization levels above Moderate. The specific FedRAMP impact level required will ultimately depend on the solution that is selected and the security needs associated with that approach. Any FedRAMP level requirements — and how they factor into evaluation planning — will be determined as part of TAC’s acquisition strategy. OIT will provide technical and security input, but final evaluation criteria are set by TAC.

Will CCaaS vendors need to demonstrate IRS Pub. 1075 FTI safeguarding capability given Veterans' financial data is processed?

No. CCaaS vendors will not need to demonstrate IRS Pub. 1075 FTI safeguarding capability, because VA’s CCaaS environment does not process Federal Tax Information or Veterans’ financial data subject to those requirements.

Will VA provide an integration inventory — EHRM, CRM, Teams, ServiceNow to help industry understand the CCaaS scope?

Yes. VA will provide an integration inventory — including EHRM, CRM, Microsoft Teams, ServiceNow, and other relevant systems — to help industry understand the scope and integration touchpoints for the CCaaS effort

Is VA considering a combined or unified acquisition approach for CCI and CCaaS given their interdependence as a contact center ecosystem?

Not at this time.

What is VA's small business participation goal across the 21 requirements, and will set-aside intent be shared during the RFI phase?

Decisions regarding VA’s small business participation goals across the 21 requirements — as well as whether any set‑aside intent will be shared during the RFI phase — fall under TAC’s acquisition strategy, not OIT. OIT does not determine small business goals or set‑aside designations.

Is VA considering performance-based outcomes — containment rates, FCR, Veteran satisfaction — as evaluation criteria for CCaaS?

No. VA is not considering performance‑based outcomes such as containment rates, first‑contact resolution, or Veteran satisfaction as evaluation criteria for the CCaaS acquisition. This requirement is focused on licenses, consumables, and TAM support only. Day‑to‑day platform operations and performance management will be handled by VA FTEs, not by the vendor.

Does VA have requirements around platform UI customization and branding consistency across the Veteran-facing contact center?

Potentially yes, however, any required customization work will be performed by VA, with vendor support if required.

How will VA evaluate vendor performance for CCaaS scalability, omnichannel AI features, enterprise integrations, FedRAMP compliance, and User experence outcome?

VA will not evaluate vendors on operational performance outcomes (e.g., UX outcomes, containment rates, FCR, or satisfaction). The CCaaS acquisition is focused on licenses, consumables, and TAM support; VA FTEs will operate and manage day‑to‑day performance of the platform. Evaluation will center on vendor capability and compliance evidence, not outcome metrics