Back to search
SAM.govNotice f90f169b8bcd44558f993129a0838b84

6540--Zeiss Callisto Eye System | 595

Country
United States
Published
November 14, 2025
Deadline
November 20, 2025

Description

{"description":"\n\n\n\n\n\nTHIS IS NOT A SOLICITATION ANNOUNCEMENT. THIS IS A REQUEST FOR INFORMATION ONLY.\nThis Request for Information (RFI) is intended for information and planning purposes only at this time; and shall not be construed as a solicitation or as an obligation on the part of the Department of Veterans Affairs. Because this is a Request for Information announcement, no evaluation letters and/or results will be issued to the respondents. \nThe Department of Veterans Affairs, Network Contracting Office (NCO) 4, Lebanon VA Medical Center is looking for sources offering an Intraoperative Digital Guidance System for Cataract Surgery. The brand name for reference is Zeiss Callisto. If unable to provide the referenced brand name, then please provide the model closest to that product; an American-Made version is preferable. The referenced products are as follows: \nIntegrated Carrier Arm on Opmi Lumera 700 Floor Stand\nPart Number 000000-2403-804-50UCCEOF Quantity 1\n\nIdis - Integrated Data Injection System\nPart Number 000000-2403-804-30UCIDIS Quantity 1\n\nV3.7 Basic -> Markerless Uc\nPart Number 000000-2243-464-01UCMLIC Quantity 1\n\nSw+Hw Upgrade: V3.7.2 + Pc Ii \nSw+Hw Upgrade: AnyPrevious Sw Version -> Sw V3.7.2 And Panel Pc I ->Panel Pc Ii\nPart Number 000000-2243-464-01UV372H Quantity 1\n\nForum-Dicom Interface License to Czm Instrument\nPart Number 000000-2244-886-40FCZDIC Quantity 1\n\nMeditec, Inc. \\F\\ Upgrade Kit: Ethernet for Lumera 700\\F\\\nPart Number 000000-2403-804-50UCETHN Quantity 1\n\nInstallation and Training\nPart Number 266002-1150-893 Quantity: 24 hours of training, onsite setup / installation\n\nThe information identified above is intended to be descriptive, not restrictive, and to indicate the quality of the supplies/services that will be satisfactory. It is the responsibility of the interested source to demonstrate to the government that the interested parties can provide the supplies/services that fulfill the required specifications mentioned above. \nSecurity Language:\n\n1. GENERAL. This entire section applies to all acquisitions requiring any Information\nSecurity and Privacy language. Contractors, contractor personnel, subcontractors\nand subcontractor personnel will be subject to the same federal laws, regulations,\nstandards, VA directives and handbooks, as VA personnel regarding information\nand information system security and privacy.\n\n2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all\nacquisitions requiring any Information Security and Privacy language.\na. The Government shall receive unlimited rights to data/intellectual property\nfirst produced and delivered in the performance of this contract or order\n(hereinafter contract ) unless expressly stated otherwise in this contract. This\nincludes all rights to source code and all documentation created in support\nthereof. The primary clause used to define Government and Contractor data\nrights is FAR 52.227-14 Rights in Data General. The primary clause used to\ndefine computer software license (not data/intellectual property first produced\nunder this contractor or order) is FAR 52.227-19, Commercial Computer\nSoftware License.\nb. Information made available to the contractor by VA for the performance or\nadministration of this contract will be used only for the purposes specified in\nthe service agreement, SOW, PWS, PD, and/or contract. The contractor shall\nnot use VA information in any other manner without prior written approval\nfrom a VA Contracting Officer (CO). The primary clause used to define\nGovernment and Contractor data rights is FAR 52.227-14 Rights in Data \nGeneral.\nc. VA information will not be co-mingled with any other data on the contractor s\ninformation systems or media storage systems. The contractor shall ensure\ncompliance with Federal and VA requirements related to data protection, data\nencryption, physical data segregation, logical data segregation, classification\nrequirements and media sanitization.\nd. VA reserves the right to conduct scheduled or unscheduled audits,\nassessments, or investigations of contractor Information Technology (IT)\nresources to ensure information security is compliant with Federal and VA\nrequirements. The contractor shall provide all necessary access to records\n(including electronic and documentary materials related to the contracts and\nsubcontracts) and support (including access to contractor and subcontractor\nstaff associated with the contract) to VA, VA's Office Inspector General (OIG),\nand/or Government Accountability Office (GAO) staff during periodic control\nassessments, audits, or investigations.\ne. The contractor may only use VA information within the terms of the contract\nand applicable Federal law, regulations, and VA policies. If new Federal\ninformation security laws, regulations or VA policies become applicable after\nexecution of the contract, the parties agree to negotiate contract modification\nand adjustment necessary to implement the new laws, regulations, and/or\npolicies.\nf. The contractor shall not make copies of VA information except as specifically\nauthorized and necessary to perform the terms of the contract. If copies are\nmade for restoration purposes, after the restoration is complete, the copies shall\nbe destroyed in accordance with VA Directive 6500, VA Cybersecurity Program\nand VA Information Security Knowledge Service.\ng. If a Veterans Health Administration (VHA) contract is terminated for default or\ncause with a business associate, the related local Business Associate Agreement\n(BAA) shall also be terminated and actions taken in accordance with VHA\nDirective 1605.05, Business Associate Agreements. If there is an executed\nnational BAA associated with the contract, VA will determine what actions are\nappropriate and notify the contactor.\nh. The contractor shall store and transmit VA sensitive information in an\nencrypted form, using VA-approved encryption tools which are, at a minimum,\nFederal Information Processing Standards (FIPS) 140-2, Security Requirements\nfor Cryptographic Modules (or its successor) validated and in conformance\nwith VA Information Security Knowledge Service requirements. The contractor\nshall transmit VA sensitive information using VA approved Transport Layer\nSecurity (TLS) configured with FIPS based cipher suites in conformance with National\nInstitute of Standards and Technology (NIST) 800-52, Guidelines for the\nSelection, Configuration and Use of Transport Layer Security (TLS)\nImplementations.\ni. The contractor s firewall and web services security controls, as applicable, shall\nmeet or exceed VA s minimum requirements.\nj. Except for uses and disclosures of VA information authorized by this contract\nfor performance of the contract, the contractor may use and disclose VA\ninformation only in two situations: (i) in response to a qualifying order of a\ncourt of competent jurisdiction after notification to VA CO (ii) with written\napproval from the VA CO. The contractor shall refer all requests for, demands\nfor production of or inquiries about, VA information and information systems\nto the VA CO for response.\nk. Notwithstanding the provision above, the contractor shall not release VA\nrecords protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality\nassurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain\nmedical records pertaining to drug addiction, sickle cell anemia, alcoholism or\nalcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the\ncontractor is in receipt of a court order or other requests for the\nabovementioned information, the contractor shall immediately refer such court\norder or other requests to the VA CO for response.\nl. Information made available to the contractor by VA for the performance or\nadministration of this contract or information developed by the contractor in\nperformance or administration of the contract will be protected and secured in\naccordance with VA Directive 6500 and Identity and Access Management\n(IAM) Security processes specified in the VA Information Security Knowledge\nService.\nm. Any data destruction done on behalf of VA by a contractor shall be done in\naccordance with National Archives and Records Administration (NARA)\nrequirements as outlined in VA Directive 6300, Records and Information\nManagement, VA Handbook 6300.1, Records Management Procedures, and\napplicable VA Records Control Schedules.\nn. The contractor shall provide its plan for destruction of all VA data in its\npossession according to VA Directive 6500 and NIST 800-88, Guidelines for\nMedia Sanitization prior to termination or completion of this contract. If\ndirected by the COR/CO, the contractor shall return all Federal Records to VA\nfor disposition.\no. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or\noptical discs that is used to store, process, or access VA information that cannot\nbe destroyed shall be returned to VA. The contractor shall hold the appropriate\nmaterial until otherwise directed by the Contracting Officer s Representative\n(COR) or CO. Items shall be returned securely via VA-approved methods. VA\nsensitive information must be transmitted utilizing VA-approved encryption\ntools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If\nmailed, the contractor shall send via a trackable method (USPS, UPS, FedEx,\netc.) and immediately provide the COR/CO with the tracking information. Self-certification\nby the contractor that the data destruction requirements above\nhave been met shall be sent to the COR/CO within 30 business days of\ntermination of the contract.\np. All electronic storage media (hard drives, optical disks, CDs, back-up tapes,\netc.) used to store, process or access VA information will not be returned to the\ncontractor at the end of lease, loan, or trade-in. Exceptions to this paragraph\nwill only be granted with the written approval of the VA CO.\n\n3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This\nsection applies when any person requires access to information made available to\nthe contractor by VA for the performance or administration of this contract or\ninformation developed by the contractor in performance or administration of the\ncontract.\na. A contractor/subcontractor shall request logical (technical) or physical access to\nVA information and VA information systems for their employees and\nsubcontractors only to the extent necessary to perform the services specified in\nthe solicitation or contract. This includes indirect entities, both affiliate of\ncontractor/subcontractor and agent of contractor/subcontractor.\nb. Contractors and subcontractors shall sign the VA Information Security Rule of\nBehavior (ROB) before access is provided to VA information and information\nsystems (see Section 4, Training, below). The ROB contains the minimum user\ncompliance requirements and does not supersede any policies of VA facilities\nor other agency components which provide higher levels of protection to VA s\ninformation or information systems. Users who require privileged access shall\ncomplete the VA elevated privilege access request processes before privileged\naccess is granted.\nc. All contractors and subcontractors working with VA information are subject to\nthe same security investigative and clearance requirements as those of VA\nappointees or employees who have access to the same types of information. The\nlevel and process of background security investigations for contractors shall be\nin accordance with VA Directive and Handbook 0710, Personnel Suitability and\nSecurity Program. The Office of Human Resources and\nAdministration/Operations, Security and Preparedness (HRA/OSP) is\nresponsible for these policies and procedures. Contract personnel who require\naccess to classified information or information systems shall have an\nappropriate security clearance. Verification of a Security Clearance shall be\nprocessed through the Special Security Officer located in HRA/OSP.\nContractors shall conform to all requirements stated in the National Industrial\nSecurity Program Operating Manual (NISPOM).\nd. All contractors and subcontractors shall comply with conditions specified in\nVAAR 852.204-71(d); Contractor operations required to be in United States.\nAll contractors and subcontractors working with VA information must be\npermanently located within a jurisdiction subject to the law of the United States\nor its Territories to the maximum extent feasible. If services are proposed to be\nperformed abroad the contractor must state where all non-U.S. services are\nprovided. The contractor shall deliver to VA a detailed plan specifically\naddressing communications, personnel control, data protection and potential\nlegal issues. The plan shall be approved by the COR/CO in writing prior to\naccess being granted.\ne. The contractor shall notify the COR/CO in writing immediately (no later than\n24 hours) after personnel separation or occurrence of other causes. Causes may\ninclude the following:\n(1) Contractor/subcontractor personnel no longer has a need for access to VA\ninformation or VA information systems.\n(2) Contractor/subcontractor personnel are terminated, suspended, or\notherwise has their work on a VA project discontinued for any reason.\n(3) Contractor believes their own personnel or subcontractor personnel may\npose a threat to their company s working environment or to any company\nowned property. This includes contractor-owned assets, buildings,\nconfidential data, customers, employees, networks, systems, trade secrets\nand/or VA data.\n(4) Any previously undisclosed changes to contractor/subcontractor\nbackground history are brought to light, including but not limited to\nchanges to background investigation or employee record.\n(5) Contractor/subcontractor personnel have their authorization to work in\nthe United States revoked.\n(6) Agreement by which contractor provides products and services to VA has\neither been fulfilled or terminated, such that VA can cut off electronic\nand/or physical access for contractor personnel.\nf. In such cases of contract fulfillment, termination, or other causes; the contractor\nshall take the necessary measures to immediately revoke access to VA network,\nproperty, information, and information systems (logical and physical) by\ncontractor/subcontractor personnel. These measures include (but are not\nlimited to): removing and then securing Personal Identity Verification (PIV)\nbadges and PIV Interoperable (PIV-I) access badges, VA-issued photo badges,\ncredentials for VA facilities and devices, VA-issued laptops, and authentication\ntokens. Contractors shall notify the appropriate VA COR/CO immediately to\ninitiate access removal.\ng. Contractors/subcontractors who no longer require VA accesses will return VA\nissued property to VA. This property includes (but is not limited to):\ndocuments, electronic equipment, keys, and parking passes. PIV and PIV-I\naccess badges shall be returned to the nearest VA PIV Badge Issuance Office.\nOnce they have had access to VA information, information systems, networks\nand VA property in their possessions removed, contractors shall notify the\nappropriate VA COR/CO.\n\n4. TRAINING. This entire section applies to all acquisitions which include section 3.\na. All contractors and subcontractors requiring access to VA information and VA\ninformation systems shall successfully complete the following before being\ngranted access to VA information and its systems:\n(1) VA Privacy and Information Security Awareness and Rules of Behavior\ncourse (Talent Management System (TMS) #10176) initially and annually\nthereafter.\n(2) Sign and acknowledge (electronically through TMS #10176)\nunderstanding of and responsibilities for compliance with the\nOrganizational Rules of Behavior, relating to access to VA information\nand information systems initially and annually thereafter; and\n(3) Successfully complete any additional cyber security or privacy training, as\nrequired for VA personnel with equivalent information system or\ninformation access [to be defined by the VA program official and\nprovided to the VA CO for inclusion in the solicitation document i.e.,\nany role based information security training].\nb. The contractor shall provide to the COR/CO a copy of the training certificates\nand certification of signing the Organizational Rules of Behavior for each\napplicable employee within five days of the initiation of the contract and\nannually thereafter, as required.\nc. Failure to complete the mandatory annual training is grounds for suspension or\ntermination of all physical or electronic access privileges and removal from\nwork on the contract until such time as the required training is complete.\n\n5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all\nacquisitions requiring any Information Security and Privacy language.\na. The contractor, subcontractor, their employees, or business associates shall\nimmediately (within one hour) report suspected security / privacy incidents to\nthe VA OIT s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY:\n711). The ESD is OIT s 24/7/365 single point of contact for IT-related issues.\nAfter reporting to the ESD, the contractor, subcontractor, their employees, or\nbusiness associates shall, within one hour, provide the COR/CO the incident\nnumber received from the ESD.\nb. To the extent known by the contractor/subcontractor, the contractor/\nsubcontractor's notice to VA shall identify the information involved and the\ncircumstances surrounding the incident, including the following:\n(1) The date and time (or approximation of) the Security Incident occurred.\n(2) The names of individuals involved (when applicable).\n(3) The physical and logical (if applicable) location of the incident.\n(4) Why the Security Incident took place (i.e., catalyst for the failure).\n(5) The amount of data belonging to VA believed to have been compromised.\n(6) The remediation measures the contractor is taking to ensure no future\nincidents of a similar nature.\nc. After the contractor has provided the initial detailed incident summary to VA,\nthey will continue to provide written updates on any new and relevant\ncircumstances or facts they discover. The contractor, subcontractor, and their\nemployes shall fully cooperate with VA or third-party entity performing an\nindependent risk analysis on behalf of VA. Failure to cooperate may be deemed\na material breach and grounds for contract termination.\nd. VA IT contractors shall follow VA Handbook 6500, Risk Management\nFramework for VA Information Systems VA Information Security Program,\nand VA Information Security Knowledge Service guidance for implementing\nan Incident Response Plan or integrating with an existing VA implementation.\ne. In instances of theft or break-in or other criminal activity, the\ncontractor/subcontractor must concurrently report the incident to the\nappropriate law enforcement entity (or entities) of jurisdiction, including the\nVA OIG, and the VA Office of Security and Law Enforcement. The contractor,\nits employees, and its subcontractors and their employees shall cooperate with\nVA and any law enforcement authority responsible for the investigation and\nprosecution of any possible criminal law violation(s) associated with any\nincident. The contractor/subcontractor shall cooperate with VA in any civil\nlitigation to recover VA information, obtain monetary or other compensation\nfrom a third party for damages arising from any incident, or obtain injunctive\nrelief against any third party arising from, or related to, the incident.\nf. The contractor shall comply with VA Handbook 6500.2, Management of\nBreaches Involving Sensitive Personal Information, which establishes the\nbreach management policies and assigns responsibilities for the oversight,\nmanagement and reporting procedures associated with managing of breaches.\ng. With respect to unsecured Protected Health Information (PHI), the contractor is\ndeemed to have discovered a data breach when the contractor knew or should\nhave known of breach of such information. When a business associate is part of\nVHA contract, notification to the covered entity (VHA) shall be made in\naccordance with the executed BAA.\nh. If the contractor or any of its agents fails to protect VA sensitive personal\ninformation or otherwise engages in conduct which results in a data breach\ninvolving any VA sensitive personal information the contractor/subcontractor\nprocesses or maintains under the contract; the contractor shall pay liquidated\ndamages to the VA as set forth in clause 852.211-76, Liquidated Damages \nReimbursement for Data Breach Costs.\n\n7. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE.\nThis entire section applies to information systems, systems, major applications,\nminor applications, enclaves, and platform information technologies (cloud and\nnoncloud) hosted, operated, maintained, or used on behalf of VA at non-VA\nfacilities.\na. The contractor shall comply with all Federal laws, regulations, and VA policies\nfor Information systems (cloud and non-cloud) that are hosted, operated,\nmaintained, or used on behalf of VA at non-VA facilities. Security controls for\ncollecting, processing, transmitting, and storing of VA sensitive information,\nmust be in place. The controls will be tested by VA or a VA sanctioned 3PAO\nand approved by VA prior to hosting, operation, maintenance or use of the\ninformation system or systems by or on behalf of VA. This includes conducting\ncompliance risk assessments, security architecture analysis, routine\nvulnerability scanning, system patching, change management procedures and\nthe completion of an acceptable contingency plan for each system. The\ncontractor s security control procedures shall be the same as procedures used to\nsecure VA-operated information systems.\nb. Outsourcing (contractor facility, equipment, or staff) of systems or network\noperations, telecommunications services or other managed services require\nAssessment and Authorization (A&A) of the contractor s systems in accordance\nwith VA Handbook 6500 as specified in VA Information Security Knowledge\nService. Major changes to the A&A package may require reviewing and\nupdating all the documentation associated with the change. The contractor s\ncloud computing systems shall comply with FedRAMP and VA Directive 6517\nrequirements.\nc. The contractor shall return all electronic storage media (hard drives, optical\ndisks, CDs, back-up tapes, etc.) on non-VA leased or non-VA owned IT\nequipment used to store, process or access VA information to VA in accordance\nwith A&A package requirements. This applies when the contract is terminated\nor completed and prior to disposal of media. The contractor shall provide its\nplan for destruction of all VA data in its possession according to VA\nInformation Security Knowledge Service requirements and NIST 800-88. The\ncontractor shall send a self-certification that the data destruction requirements\nabove have been met to the COR/CO within 30 business days of termination of\nthe contract.\nd. All external internet connections to VA network involving VA information\nmust be in accordance with VA Trusted Internet Connection (TIC) Reference\nArchitecture and VA Directive and Handbook 6513, Secure External\nConnections and reviewed and approved by VA prior to implementation.\nGovernment-owned contractor-operated systems, third party or business\npartner networks require a Memorandum of Understanding (MOU) and\nInterconnection Security Agreements (ISA).\ne. Contractor procedures shall be subject to periodic, announced, or unannounced\nassessments by VA officials, the OIG or a 3PAO. The physical security aspects\nassociated with contractor activities are also subject to such assessments. The\ncontractor shall report, in writing, any deficiencies noted during the above\nassessment to the VA COR/CO. The contractor shall use VA s defined\nprocesses to document planned remedial actions that address identified\ndeficiencies in information security policies, procedures, and practices. The\ncontractor shall correct security deficiencies within the timeframes specified in\nthe VA Information Security Knowledge Service.\nf. All major information system changes which occur in the production\nenvironment shall be reviewed by the VA to determine the impact on privacy\nand security of the system. Based on the review results, updates to the\nAuthority to Operate (ATO) documentation and parameters may be required to\nremain in compliance with VA Handbook 6500 and VA Information Security\nKnowledge Service requirements.\ng. The contractor shall conduct an annual privacy and security self-assessment on\nall information systems and outsourced services as required. Copies of the\nassessment shall be provided to the COR/CO. The VA/Government reserves\nthe right to conduct assessment using government personnel or a third-party if\ndeemed necessary. The contractor shall correct or mitigate any weaknesses\ndiscovered during the assessment.\nh. VA prohibits the installation and use of personally owned or contractor-owned\nequipment or software on VA information systems. If non-VA owned\nequipment must be used to fulfill the requirements of a contract, it must be\nstated in the service agreement, SOW, PWS, PD or contract. All security\ncontrols required for government furnished equipment must be utilized in VA\napproved Other Equipment (OE). Configuration changes to the contractor OE,\nmust be funded by the owner of the equipment. All remote systems must use a\nVA-approved antivirus software and a personal (host-based or enclave based)\nfirewall with a VA-approved configuration. The contractor shall ensure\nsoftware on OE is kept current with all critical updates and patches. Owners of\napproved OE are responsible for providing and maintaining the anti-virus\nsoftware and the firewall on the non-VA owned OE. Approved contractor OE\nwill be subject to technical inspection at any time.\ni. The contractor shall notify the COR/CO within one hour of disclosure or\nsuccessful exploits of any vulnerability which can compromise the\nconfidentiality, integrity, or availability of the information systems. The system\nor effected component(s) need(s) to be isolated from the network. A forensic\nanalysis needs to be conducted jointly with VA. Such issues will be remediated\nas quickly as practicable, but in no event longer than the timeframe specified by\nVA Information Security Knowledge Service. If sensitive personal information\nis compromised reference VA Handbook 6500.2 and Section 5, Security Incident\nInvestigation.\nj. For cases wherein the contractor discovers material defects or vulnerabilities\nimpacting products and services they provide to VA, the contractor shall\ndevelop and implement policies and procedures for disclosure to VA, as well as\nremediation. The contractor shall, within 30 business days of discovery,\ndocument a summary of these vulnerabilities or defects. The documentation\nwill include a description of the potential impact of each vulnerability and\nmaterial defect, compensating security controls, mitigations, recommended\ncorrective actions, FboNotice cause analysis and/or workarounds (i.e., monitoring).\nShould there exist any backdoors in the products or services they provide to\nVA (referring to methods for bypassing computer authentication), the\ncontractor shall provide the VA CO/CO written assurance they have\npermanently remediated these backdoors.\nk. All other vulnerabilities, including those discovered through routine scans or\nother assessments, will be remediated based on risk, in accordance with the\nremediation timelines specified by the VA Information Security Knowledge\nService and/or the applicable timeframe mandated by Cybersecurity &\nInfrastructure Security Agency (CISA) Binding Operational Directive (BOD)\n2201 and BOD 19-02 for Internet-accessible systems. Exceptions to this\nparagraph will only be granted with the approval of the COR/CO.\n\n8. SECURITY AND PRIVACY CONTROLS COMPLIANCE TESTING, ASSESSMENT\nAND AUDITING. This entire section applies whenever section 6 or 7 is included.\na. Should VA request it, the contractor shall provide a copy of their (corporation s,\nsole proprietorship s, partnership s, limited liability company (LLC), or other\nbusiness structure entity s) policies, procedures, evidence and independent\nreport summaries related to specified cybersecurity frameworks (International\nOrganization for Standardization (ISO), NIST Cybersecurity Framework (CSF),\netc.). VA or its third-party/partner designee (if applicable) are further entitled\nto perform their own audits and security/penetration tests of the contractor s\nIT or systems and controls, to ascertain whether the contractor is complying\nwith the information security, network or system requirements mandated in\nthe agreement between VA and the contractor.\nb. Any audits or tests of the contractor or third-party designees/partner VA elects\nto carry out will commence within 30 business days of VA notification. Such\naudits, tests and assessments may include the following: (a):\nsecurity/penetration tests which both sides agree will not unduly impact\ncontractor operations; (b): interviews with pertinent stakeholders and\npractitioners; (c): document review; and (d): technical inspections of networks\nand systems the contractor uses to destroy, maintain, receive, retain, or use VA\ninformation.\nc. As part of these audits, tests and assessments, the contractor shall provide all\ninformation requested by VA. This information includes, but is not limited to,\nthe following: equipment lists, network or infrastructure diagrams, relevant\npolicy documents, system logs or details on information systems accessing,\ntransporting, or processing VA data.\nd. The contractor and at its own expense shall comply with any recommendations\nresulting from VA audits, inspections and tests. VA further retains the right to\nview any related security reports the contractor has generated as part of its own\nsecurity assessment. The contractor shall also notify VA of the existence of any\nsuch security reports or other related assessments, upon completion and\nvalidation.\ne. VA appointed auditors or other government agency partners may be granted\naccess to such documentation on a need-to-know basis and coordinated\nthrough the COR/CO. The contractor shall comply with recommendations\nwhich result from these regulatory assessments on the part of VA regulators\nand associated government agency partners.\n\n9. PRODUCT INTEGRITY, AUTHENTICITY, PROVENANCE, ANTI-COUNTERFEIT\nAND ANTI-TAMPERING. This entire section applies when the acquisition involves\nany product (application, hardware, or software) or when section 6 or 7 is included.\na. The contractor shall comply with Code of Federal Regulations (CFR) Title 15\nPart 7, Securing the Information and Communications Technology and\nServices (ICTS) Supply Chain , which prohibits ICTS Transactions from foreign\nadversaries. ICTS Transactions are defined as any acquisition, importation,\ntransfer, installation, dealing in or use of any information and communications\ntechnology or service, including ongoing activities, such as managed services,\ndata transmission, software updates, repairs or the platforming or data hosting\nof applications for consumer download.\nb. When contracting terms require the contractor to procure equipment, the\ncontractor shall purchase or acquire the equipment from an Original\nEquipment Manufacturer (OEM) or an authorized reseller of the OEM. The\ncontractor shall attest that equipment procured from an OEM or authorized\nreseller or distributor are authentic. If procurement is unavailable from an OEM\nor authorized reseller, the contractor shall submit in writing details of the\ncircumstances prohibiting this from happening and procure a product waiver\nfrom the VA COR/CO.\nc. All contractors shall establish, implement, and provide documentation for risk\nmanagement practices for supply chain delivery of hardware, software (to\ninclude patches) and firmware provided under this agreement. Documentation\nwill include chain of custody practices, inventory management program,\ninformation protection practices, integrity management program for sub supplier\nprovided components, and replacement parts requests. The contractor\nshall make spare parts available. All contractor(s) shall specify how digital\ndelivery for procured products, including patches, will be validated and\nmonitored to ensure consistent delivery. The contractor shall apply encryption\ntechnology to protect procured products throughout the delivery process.\nd. If a contractor provides software or patches to VA, the contractor shall publish\nor provide a hash conforming to the FIPS Security Requirements for\nCryptographic Modules (FIPS 140-2 or successor).\ne. The contractor shall provide a software bill of materials (SBOM) for procured\n(to include licensed products) and consist of a list of components and\nassociated metadata which make up the product. SBOMs must be generated in\none of the data formats defined in the National Telecommunications and\nInformation Administration (NTIA) report The Minimum Elements for a\nSoftware Bill of Materials (SBOM). \nf. Contractors shall use or arrange for the use of trusted channels to ship procured\nproducts, such as U.S. registered mail and/or tamper-evident packaging for\nphysical deliveries.\ng. Throughout the delivery process, the contractor shall demonstrate a capability\nfor detecting unauthorized access (tampering).\nh. The contractor shall demonstrate chain-of-custody documentation for procured\nproducts and require tamper-evident packaging for the delivery of this\nhardware.\n\n10. VIRUSES, FIRMWARE AND MALWARE. This entire section applies when the\nacquisition involves any product (application, hardware, or software) or when\nsection 6 or 7 is included.\na. The contractor shall execute due diligence to ensure all provided software and\npatches, including third-party patches, are free of viruses and/or malware\nbefore releasing them to or installing them on VA information systems.\nb. The contractor warrants it has no knowledge of and did not insert, any\nmalicious virus and/or malware code into any software or patches provided to\nVA which could potentially harm or disrupt VA information systems. The\ncontractor shall use due diligence if supplying third-party software or patches,\nto ensure the third party has not inserted any malicious code and/or virus\nwhich could damage or disrupt VA information systems.\nc. The contractor shall provide or arrange for the provision of technical\njustification as to why any false positive hit has taken place to ensure their\ncode s supply chain has not been compromised. Justification may be required,\nbut is not limited to, when install files, scripts, firmware, or other contractor delivered software solutions (including third-party install files, scripts,\nfirmware, or other software) are flagged as malicious, infected, or suspicious by\nan anti-virus vendor.\nd. The contractor shall not upload (intentionally or negligently) any virus, worm,\nmalware or any harmful or malicious content, component and/or corrupted\ndata/source code (hereinafter virus or other malware ) onto VA computer\nand information systems and/or networks. If introduced (and this clause is\nviolated), upon written request from the VA CO, the contractor shall:\n(1) Take all necessary action to correct the incident, to include any and all\nassistance to VA to eliminate the virus or other malware throughout VA s\ninformation networks, computer systems and information systems; and\n(2) Use commercially reasonable efforts to restore operational efficiency and\nremediate damages due to data loss or data integrity damage, if the virus\nor other malware causes a loss of operational efficiency, data loss, or\ndamage to data integrity\n.\n11. CRYPTOGRAPHIC REQUIREMENT. This entire section applies whenever the\nacquisition includes section 6 or 7 is included.\na. The contractor shall document how the cryptographic system supports the\ncontractor s products and/or services protect the confidentiality, data integrity,\nauthentication and non-repudiation of devices and data flows in the underlying\nsystem.\nb. The contractor shall use only approved cryptographic methods as defined in\nFIPS 140-2 (or its successor) and NIST 800-52 standards when enabling\nencryption on its products.\nc. The contractor shall provide or arrange for the provision of an automated\nremote key-establishment method which protects the confidentiality and\nintegrity of the cryptographic keys.\nd. The contractor shall ensure emergency re-keying of all devices can be remotely\nperformed within 30 business days.\ne. The contractor shall provide or arrange for the provision of a method for\nupdating cryptographic primitives or algorithms.\n\n12. PATCHING GOVERNANCE. This entire section applies whenever the acquisition\nincludes section 7 is included\na. The contractor shall provide documentation detailing the patch management,\nvulnerability management, mitigation and update processes (to include third\nparty) prior to the connection of electronic devices, assets or equipment to VA s\nassets. This documentation will include information regarding the follow:\n(1) The resources and technical capabilities to sustain the program or process\n(e.g., how the integrity of a patch is validated by VA); and\n(2) The approach and capability to remediate newly reported zero-day\nvulnerabilities for contractor products.\nb. The contractor shall verify and provide documentation on all procured products\n(including third-party applications, hardware, software, operating systems, and\nfirmware) have appropriate updates and patches installed prior to delivery to\nVA.\nc. The contractor shall provide or arrange the provision of appropriate software\nand firmware updates to remediate newly discovered vulnerabilities or\nweaknesses for their products and services within 30 days of discovery.\nUpdates to remediate critical or emergent vulnerabilities will be provided\nwithin seven business days of discovery. If updates cannot be made available\nby contractor within these time periods, the contractor shall submit mitigations,\nmethods of exploit detection and/or workarounds to the COR/CO prior to the\nabove deadlines.\nd. The contractor shall provide or arrange for the provision of appropriate\nhardware, software and/or firmware updates, when those products, including\nopen-source software, are provided to the VA, to remediate newly discovered\nvulnerabilities or weaknesses. Remediations of products or services provided to\nthe VA s system environment must be provided within 30 business days of\navailability from the original supplier and/or patching source. Updates to\nremediate critical vulnerabilities applicable to the Contractor s use of the third\nparty product in its system environment will be provided within seven\nbusiness days of availability from the original supplier and/or patching source.\nIf applicable third-party updates cannot be integrated, tested and made\navailable by Contractor within these time periods, mitigations and/or\nworkarounds will be provided to the COR/CO before the above deadlines.\n\n\n\nResponses to this RFI should include:\n\nCompany name\nAddress\nPoint of contact\nPhone number\nPoint of contact e-mail\nContractor s Unique Entity ID (SAM) number\nNAICS: 334510\nSize standard: 1250 Employees\nCapability Statement\n\nThis RFI will be conducted in accordance with Federal Acquisition Regulation (FAR) Part 12. \nTelephone responses will not be accepted. Responses must be received via e-mail to Adriane.Perretti@va.gov no later, 10:00 AM Eastern Standard Time (EST) on 11/20/2025, with 36C24426Q0040 in the subject line. This notice will help the VA in determining available potential sources only. Do not contact VA Medical Center staff regarding this requirement, as they are not authorized to discuss this matter related to this procurement action.\nAll firms responding to this Request for Information are advised that their response is not a request for proposal, therefore proposals will not be considered for a contract award. \nIf a solicitation is issued, information will be posted on the www.sam.gov web site for all qualified interested parties. Interested parties must respond to the solicitation to be considered for award. This notice does not commit the government to contract for any supplies or services. The government will not pay for any information or administrative cost incurred in response to this Request for Information.\nDISCLAIMER \nThis RFI is issued solely for information and planning purposes only and does not constitute a solicitation. All information received in response to this RFI that is marked as proprietary will be handled accordingly. Responses to this notice are not offers and cannot be accepted by the Government to form a binding contract. Responders are solely responsible for all expenses associated with responding to this RFI.\n\n"} Solicitation Number: 36C24426Q0040 Type: Presolicitation Base Type: Presolicitation NAICS: 334510 Classification Code: 6540 Response Deadline: 2025-11-20T10:00:00-05:00 Office Address: PITTSBURGH, PA Place of Performance: Lebanon, PA, 17042-7529 POC: Adriane Perretti, adriane.perretti@va.gov, 330-883-3336 {"description":"\n\n\n\n\n\nTHIS IS NOT A SOLICITATION ANNOUNCEMENT. THIS IS A REQUEST FOR INFORMATION ONLY.\nThis Request for Information (RFI) is intended for information and planning purposes only at this time; and shall not be construed as a solicitation or as an obligation on the part of the Department of Veterans Affairs. Because this is a Request for Information announcement, no evaluation letters and/or results will be issued to the respondents. \nThe Department of Veterans Affairs, Network Contracting Office (NCO) 4, Lebanon VA Medical Center is looking for sources offering an Intraoperative Digital Guidance System for Cataract Surgery. The brand name for reference is Zeiss Callisto. If unable to provide the referenced brand name, then please provide the model closest to that product; an American-Made version is preferable. The referenced products are as follows: \nIntegrated Carrier Arm on Opmi Lumera 700 Floor Stand\nPart Number 000000-2403-804-50UCCEOF Quantity 1\n\nIdis - Integrated Data Injection System\nPart Number 000000-2403-804-30UCIDIS Quantity 1\n\nV3.7 Basic -> Markerless Uc\nPart Number 000000-2243-464-01UCMLIC Quantity 1\n\nSw+Hw Upgrade: V3.7.2 + Pc Ii \nSw+Hw Upgrade: AnyPrevious Sw Version -> Sw V3.7.2 And Panel Pc I ->Panel Pc Ii\nPart Number 000000-2243-464-01UV372H Quantity 1\n\nForum-Dicom Interface License to Czm Instrument\nPart Number 000000-2244-886-40FCZDIC Quantity 1\n\nMeditec, Inc. \\F\\ Upgrade Kit: Ethernet for Lumera 700\\F\\\nPart Number 000000-2403-804-50UCETHN Quantity 1\n\nInstallation and Training\nPart Number 266002-1150-893 Quantity: 24 hours of training, onsite setup / installation\n\nThe information identified above is intended to be descriptive, not restrictive, and to indicate the quality of the supplies/services that will be satisfactory. It is the responsibility of the interested source to demonstrate to the government that the interested parties can provide the supplies/services that fulfill the required specifications mentioned above. \nSecurity Language:\n\n1. GENERAL. This entire section applies to all acquisitions requiring any Information\nSecurity and Privacy language. Contractors, contractor personnel, subcontractors\nand subcontractor personnel will be subject to the same federal laws, regulations,\nstandards, VA directives and handbooks, as VA personnel regarding information\nand information system security and privacy.\n\n2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all\nacquisitions requiring any Information Security and Privacy language.\na. The Government shall receive unlimited rights to data/intellectual property\nfirst produced and delivered in the performance of this contract or order\n(hereinafter contract ) unless expressly stated otherwise in this contract. This\nincludes all rights to source code and all documentation created in support\nthereof. The primary clause used to define Government and Contractor data\nrights is FAR 52.227-14 Rights in Data General. The primary clause used to\ndefine computer software license (not data/intellectual property first produced\nunder this contractor or order) is FAR 52.227-19, Commercial Computer\nSoftware License.\nb. Information made available to the contractor by VA for the performance or\nadministration of this contract will be used only for the purposes specified in\nthe service agreement, SOW, PWS, PD, and/or contract. The contractor shall\nnot use VA information in any other manner without prior written approval\nfrom a VA Contracting Officer (CO). The primary clause used to define\nGovernment and Contractor data rights is FAR 52.227-14 Rights in Data \nGeneral.\nc. VA information will not be co-mingled with any other data on the contractor s\ninformation systems or media storage systems. The contractor shall ensure\ncompliance with Federal and VA requirements related to data protection, data\nencryption, physical data segregation, logical data segregation, classification\nrequirements and media sanitization.\nd. VA reserves the right to conduct scheduled or unscheduled audits,\nassessments, or investigations of contractor Information Technology (IT)\nresources to ensure information security is compliant with Federal and VA\nrequirements. The contractor shall provide all necessary access to records\n(including electronic and documentary materials related to the contracts and\nsubcontracts) and support (including access to contractor and subcontractor\nstaff associated with the contract) to VA, VA's Office Inspector General (OIG),\nand/or Government Accountability Office (GAO) staff during periodic control\nassessments, audits, or investigations.\ne. The contractor may only use VA information within the terms of the contract\nand applicable Federal law, regulations, and VA policies. If new Federal\ninformation security laws, regulations or VA policies become applicable after\nexecution of the contract, the parties agree to negotiate contract modification\nand adjustment necessary to implement the new laws, regulations, and/or\npolicies.\nf. The contractor shall not make copies of VA information except as specifically\nauthorized and necessary to perform the terms of the contract. If copies are\nmade for restoration purposes, after the restoration is complete, the copies shall\nbe destroyed in accordance with VA Directive 6500, VA Cybersecurity Program\nand VA Information Security Knowledge Service.\ng. If a Veterans Health Administration (VHA) contract is terminated for default or\ncause with a business associate, the related local Business Associate Agreement\n(BAA) shall also be terminated and actions taken in accordance with VHA\nDirective 1605.05, Business Associate Agreements. If there is an executed\nnational BAA associated with the contract, VA will determine what actions are\nappropriate and notify the contactor.\nh. The contractor shall store and transmit VA sensitive information in an\nencrypted form, using VA-approved encryption tools which are, at a minimum,\nFederal Information Processing Standards (FIPS) 140-2, Security Requirements\nfor Cryptographic Modules (or its successor) validated and in conformance\nwith VA Information Security Knowledge Service requirements. The contractor\nshall transmit VA sensitive information using VA approved Transport Layer\nSecurity (TLS) configured with FIPS based cipher suites in conformance with National\nInstitute of Standards and Technology (NIST) 800-52, Guidelines for the\nSelection, Configuration and Use of Transport Layer Security (TLS)\nImplementations.\ni. The contractor s firewall and web services security controls, as applicable, shall\nmeet or exceed VA s minimum requirements.\nj. Except for uses and disclosures of VA information authorized by this contract\nfor performance of the contract, the contractor may use and disclose VA\ninformation only in two situations: (i) in response to a qualifying order of a\ncourt of competent jurisdiction after notification to VA CO (ii) with written\napproval from the VA CO. The contractor shall refer all requests for, demands\nfor production of or inquiries about, VA information and information systems\nto the VA CO for response.\nk. Notwithstanding the provision above, the contractor shall not release VA\nrecords protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality\nassurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain\nmedical records pertaining to drug addiction, sickle cell anemia, alcoholism or\nalcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the\ncontractor is in receipt of a court order or other requests for the\nabovementioned information, the contractor shall immediately refer such court\norder or other requests to the VA CO for response.\nl. Information made available to the contractor by VA for the performance or\nadministration of this contract or information developed by the contractor in\nperformance or administration of the contract will be protected and secured in\naccordance with VA Directive 6500 and Identity and Access Management\n(IAM) Security processes specified in the VA Information Security Knowledge\nService.\nm. Any data destruction done on behalf of VA by a contractor shall be done in\naccordance with National Archives and Records Administration (NARA)\nrequirements as outlined in VA Directive 6300, Records and Information\nManagement, VA Handbook 6300.1, Records Management Procedures, and\napplicable VA Records Control Schedules.\nn. The contractor shall provide its plan for destruction of all VA data in its\npossession according to VA Directive 6500 and NIST 800-88, Guidelines for\nMedia Sanitization prior to termination or completion of this contract. If\ndirected by the COR/CO, the contractor shall return all Federal Records to VA\nfor disposition.\no. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or\noptical discs that is used to store, process, or access VA information that cannot\nbe destroyed shall be returned to VA. The contractor shall hold the appropriate\nmaterial until otherwise directed by the Contracting Officer s Representative\n(COR) or CO. Items shall be returned securely via VA-approved methods. VA\nsensitive information must be transmitted utilizing VA-approved encryption\ntools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If\nmailed, the contractor shall send via a trackable method (USPS, UPS, FedEx,\netc.) and immediately provide the COR/CO with the tracking information. Self-certification\nby the contractor that the data destruction requirements above\nhave been met shall be sent to the COR/CO within 30 business days of\ntermination of the contract.\np. All electronic storage media (hard drives, optical disks, CDs, back-up tapes,\netc.) used to store, process or access VA information will not be returned to the\ncontractor at the end of lease, loan, or trade-in. Exceptions to this paragraph\nwill only be granted with the written approval of the VA CO.\n\n3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This\nsection applies when any person requires access to information made available to\nthe contractor by VA for the performance or administration of this contract or\ninformation developed by the contractor in performance or administration of the\ncontract.\na. A contractor/subcontractor shall request logical (technical) or physical access to\nVA information and VA information systems for their employees and\nsubcontractors only to the extent necessary to perform the services specified in\nthe solicitation or contract. This includes indirect entities, both affiliate of\ncontractor/subcontractor and agent of contractor/subcontractor.\nb. Contractors and subcontractors shall sign the VA Information Security Rule of\nBehavior (ROB) before access is provided to VA information and information\nsystems (see Section 4, Training, below). The ROB contains the minimum user\ncompliance requirements and does not supersede any policies of VA facilities\nor other agency components which provide higher levels of protection to VA s\ninformation or information systems. Users who require privileged access shall\ncomplete the VA elevated privilege access request processes before privileged\naccess is granted.\nc. All contractors and subcontractors working with VA information are subject to\nthe same security investigative and clearance requirements as those of VA\nappointees or employees who have access to the same types of information. The\nlevel and process of background security investigations for contractors shall be\nin accordance with VA Directive and Handbook 0710, Personnel Suitability and\nSecurity Program. The Office of Human Resources and\nAdministration/Operations, Security and Preparedness (HRA/OSP) is\nresponsible for these policies and procedures. Contract personnel who require\naccess to classified information or information systems shall have an\nappropriate security clearance. Verification of a Security Clearance shall be\nprocessed through the Special Security Officer located in HRA/OSP.\nContractors shall conform to all requirements stated in the National Industrial\nSecurity Program Operating Manual (NISPOM).\nd. All contractors and subcontractors shall comply with conditions specified in\nVAAR 852.204-71(d); Contractor operations required to be in United States.\nAll contractors and subcontractors working with VA information must be\npermanently located within a jurisdiction subject to the law of the United States\nor its Territories to the maximum extent feasible. If services are proposed to be\nperformed abroad the contractor must state where all non-U.S. services are\nprovided. The contractor shall deliver to VA a detailed plan specifically\naddressing communications, personnel control, data protection and potential\nlegal issues. The plan shall be approved by the COR/CO in writing prior to\naccess being granted.\ne. The contractor shall notify the COR/CO in writing immediately (no later than\n24 hours) after personnel separation or occurrence of other causes. Causes may\ninclude the following:\n(1) Contractor/subcontractor personnel no longer has a need for access to VA\ninformation or VA information systems.\n(2) Contractor/subcontractor personnel are terminated, suspended, or\notherwise has their work on a VA project discontinued for any reason.\n(3) Contractor believes their own personnel or subcontractor personnel may\npose a threat to their company s working environment or to any company\nowned property. This includes contractor-owned assets, buildings,\nconfidential data, customers, employees, networks, systems, trade secrets\nand/or VA data.\n(4) Any previously undisclosed changes to contractor/subcontractor\nbackground history are brought to light, including but not limited to\nchanges to background investigation or employee record.\n(5) Contractor/subcontractor personnel have their authorization to work in\nthe United States revoked.\n(6) Agreement by which contractor provides products and services to VA has\neither been fulfilled or terminated, such that VA can cut off electronic\nand/or physical access for contractor personnel.\nf. In such cases of contract fulfillment, termination, or other causes; the contractor\nshall take the necessary measures to immediately revoke access to VA network,\nproperty, information, and information systems (logical and physical) by\ncontractor/subcontractor personnel. These measures include (but are not\nlimited to): removing and then securing Personal Identity Verification (PIV)\nbadges and PIV Interoperable (PIV-I) access badges, VA-issued photo badges,\ncredentials for VA facilities and devices, VA-issued laptops, and authentication\ntokens. Contractors shall notify the appropriate VA COR/CO immediately to\ninitiate access removal.\ng. Contractors/subcontractors who no longer require VA accesses will return VA\nissued property to VA. This property includes (but is not limited to):\ndocuments, electronic equipment, keys, and parking passes. PIV and PIV-I\naccess badges shall be returned to the nearest VA PIV Badge Issuance Office.\nOnce they have had access to VA information, information systems, networks\nand VA property in their possessions removed, contractors shall notify the\nappropriate VA COR/CO.\n\n4. TRAINING. This entire section applies to all acquisitions which include section 3.\na. All contractors and subcontractors requiring access to VA information and VA\ninformation systems shall successfully complete the following before being\ngranted access to VA information and its systems:\n(1) VA Privacy and Information Security Awareness and Rules of Behavior\ncourse (Talent Management System (TMS) #10176) initially and annually\nthereafter.\n(2) Sign and acknowledge (electronically through TMS #10176)\nunderstanding of and responsibilities for compliance with the\nOrganizational Rules of Behavior, relating to access to VA information\nand information systems initially and annually thereafter; and\n(3) Successfully complete any additional cyber security or privacy training, as\nrequired for VA personnel with equivalent information system or\ninformation access [to be defined by the VA program official and\nprovided to the VA CO for inclusion in the solicitation document i.e.,\nany role based information security training].\nb. The contractor shall provide to the COR/CO a copy of the training certificates\nand certification of signing the Organizational Rules of Behavior for each\napplicable employee within five days of the initiation of the contract and\nannually thereafter, as required.\nc. Failure to complete the mandatory annual training is grounds for suspension or\ntermination of all physical or electronic access privileges and removal from\nwork on the contract until such time as the required training is complete.\n\n5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all\nacquisitions requiring any Information Security and Privacy language.\na. The contractor, subcontractor, their employees, or business associates shall\nimmediately (within one hour) report suspected security / privacy incidents to\nthe VA OIT s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY:\n711). The ESD is OIT s 24/7/365 single point of contact for IT-related issues.\nAfter reporting to the ESD, the contractor, subcontractor, their employees, or\nbusiness associates shall, within one hour, provide the COR/CO the incident\nnumber received from the ESD.\nb. To the extent known by the contractor/subcontractor, the contractor/\nsubcontractor's notice to VA shall identify the information involved and the\ncircumstances surrounding the incident, including the following:\n(1) The date and time (or approximation of) the Security Incident occurred.\n(2) The names of individuals involved (when applicable).\n(3) The physical and logical (if applicable) location of the incident.\n(4) Why the Security Incident took place (i.e., catalyst for the failure).\n(5) The amount of data belonging to VA believed to have been compromised.\n(6) The remediation measures the contractor is taking to ensure no future\nincidents of a similar nature.\nc. After the contractor has provided the initial detailed incident summary to VA,\nthey will continue to provide written updates on any new and relevant\ncircumstances or facts they discover. The contractor, subcontractor, and their\nemployes shall fully cooperate with VA or third-party entity performing an\nindependent risk analysis on behalf of VA. Failure to cooperate may be deemed\na material breach and grounds for contract termination.\nd. VA IT contractors shall follow VA Handbook 6500, Risk Management\nFramework for VA Information Systems VA Information Security Program,\nand VA Information Security Knowledge Service guidance for implementing\nan Incident Response Plan or integrating with an existing VA implementation.\ne. In instances of theft or break-in or other criminal activity, the\ncontractor/subcontractor must concurrently report the incident to the\nappropriate law enforcement entity (or entities) of jurisdiction, including the\nVA OIG, and the VA Office of Security and Law Enforcement. The contractor,\nits employees, and its subcontractors and their employees shall cooperate with\nVA and any law enforcement authority responsible for the investigation and\nprosecution of any possible criminal law violation(s) associated with any\nincident. The contractor/subcontractor shall cooperate with VA in any civil\nlitigation to recover VA information, obtain monetary or other compensation\nfrom a third party for damages arising from any incident, or obtain injunctive\nrelief against any third party arising from, or related to, the incident.\nf. The contractor shall comply with VA Handbook 6500.2, Management of\nBreaches Involving Sensitive Personal Information, which establishes the\nbreach management policies and assigns responsibilities for the oversight,\nmanagement and reporting procedures associated with managing of breaches.\ng. With respect to unsecured Protected Health Information (PHI), the contractor is\ndeemed to have discovered a data breach when the contractor knew or should\nhave known of breach of such information. When a business associate is part of\nVHA contract, notification to the covered entity (VHA) shall be made in\naccordance with the executed BAA.\nh. If the contractor or any of its agents fails to protect VA sensitive personal\ninformation or otherwise engages in conduct which results in a data breach\ninvolving any VA sensitive personal information the contractor/subcontractor\nprocesses or maintains under the contract; the contractor shall pay liquidated\ndamages to the VA as set forth in clause 852.211-76, Liquidated Damages \nReimbursement for Data Breach Costs.\n\n7. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE.\nThis entire section applies to information systems, systems, major applications,\nminor applications, enclaves, and platform information technologies (cloud and\nnoncloud) hosted, operated, maintained, or used on behalf of VA at non-VA\nfacilities.\na. The contractor shall comply with all Federal laws, regulations, and VA policies\nfor Information systems (cloud and non-cloud) that are hosted, operated,\nmaintained, or used on behalf of VA at non-VA facilities. Security controls for\ncollecting, processing, transmitting, and storing of VA sensitive information,\nmust be in place. The controls will be tested by VA or a VA sanctioned 3PAO\nand approved by VA prior to hosting, operation, maintenance or use of the\ninformation system or systems by or on behalf of VA. This includes conducting\ncompliance risk assessments, security architecture analysis, routine\nvulnerability scanning, system patching, change management procedures and\nthe completion of an acceptable contingency plan for each system. The\ncontractor s security control procedures shall be the same as procedures used to\nsecure VA-operated information systems.\nb. Outsourcing (contractor facility, equipment, or staff) of systems or network\noperations, telecommunications services or other managed services require\nAssessment and Authorization (A&A) of the contractor s systems in accordance\nwith VA Handbook 6500 as specified in VA Information Security Knowledge\nService. Major changes to the A&A package may require reviewing and\nupdating all the documentation associated with the change. The contractor s\ncloud computing systems shall comply with FedRAMP and VA Directive 6517\nrequirements.\nc. The contractor shall return all electronic storage media (hard drives, optical\ndisks, CDs, back-up tapes, etc.) on non-VA leased or non-VA owned IT\nequipment used to store, process or access VA information to VA in accordance\nwith A&A package requirements. This applies when the contract is terminated\nor completed and prior to disposal of media. The contractor shall provide its\nplan for destruction of all VA data in its possession according to VA\nInformation Security Knowledge Service requirements and NIST 800-88. The\ncontractor shall send a self-certification that the data destruction requirements\nabove have been met to the COR/CO within 30 business days of termination of\nthe contract.\nd. All external internet connections to VA network involving VA information\nmust be in accordance with VA Trusted Internet Connection (TIC) Reference\nArchitecture and VA Directive and Handbook 6513, Secure External\nConnections and reviewed and approved by VA prior to implementation.\nGovernment-owned contractor-operated systems, third party or business\npartner networks require a Memorandum of Understanding (MOU) and\nInterconnection Security Agreements (ISA).\ne. Contractor procedures shall be subject to periodic, announced, or unannounced\nassessments by VA officials, the OIG or a 3PAO. The physical security aspects\nassociated with contractor activities are also subject to such assessments. The\ncontractor shall report, in writing, any deficiencies noted during the above\nassessment to the VA COR/CO. The contractor shall use VA s defined\nprocesses to document planned remedial actions that address identified\ndeficiencies in information security policies, procedures, and practices. The\ncontractor shall correct security deficiencies within the timeframes specified in\nthe VA Information Security Knowledge Service.\nf. All major information system changes which occur in the production\nenvironment shall be reviewed by the VA to determine the impact on privacy\nand security of the system. Based on the review results, updates to the\nAuthority to Operate (ATO) documentation and parameters may be required to\nremain in compliance with VA Handbook 6500 and VA Information Security\nKnowledge Service requirements.\ng. The contractor shall conduct an annual privacy and security self-assessment on\nall information systems and outsourced services as required. Copies of the\nassessment shall be provided to the COR/CO. The VA/Government reserves\nthe right to conduct assessment using government personnel or a third-party if\ndeemed necessary. The contractor shall correct or mitigate any weaknesses\ndiscovered during the assessment.\nh. VA prohibits the installation and use of personally owned or contractor-owned\nequipment or software on VA information systems. If non-VA owned\nequipment must be used to fulfill the requirements of a contract, it must be\nstated in the service agreement, SOW, PWS, PD or contract. All security\ncontrols required for government furnished equipment must be utilized in VA\napproved Other Equipment (OE). Configuration changes to the contractor OE,\nmust be funded by the owner of the equipment. All remote systems must use a\nVA-approved antivirus software and a personal (host-based or enclave based)\nfirewall with a VA-approved configuration. The contractor shall ensure\nsoftware on OE is kept current with all critical updates and patches. Owners of\napproved OE are responsible for providing and maintaining the anti-virus\nsoftware and the firewall on the non-VA owned OE. Approved contractor OE\nwill be subject to technical inspection at any time.\ni. The contractor shall notify the COR/CO within one hour of disclosure or\nsuccessful exploits of any vulnerability which can compromise the\nconfidentiality, integrity, or availability of the information systems. The system\nor effected component(s) need(s) to be isolated from the network. A forensic\nanalysis needs to be conducted jointly with VA. Such issues will be remediated\nas quickly as practicable, but in no event longer than the timeframe specified by\nVA Information Security Knowledge Service. If sensitive personal information\nis compromised reference VA Handbook 6500.2 and Section 5, Security Incident\nInvestigation.\nj. For cases wherein the contractor discovers material defects or vulnerabilities\nimpacting products and services they provide to VA, the contractor shall\ndevelop and implement policies and procedures for disclosure to VA, as well as\nremediation. The contractor shall, within 30 business days of discovery,\ndocument a summary of these vulnerabilities or defects. The documentation\nwill include a description of the potential impact of each vulnerability and\nmaterial defect, compensating security controls, mitigations, recommended\ncorrective actions, FboNotice cause analysis and/or workarounds (i.e., monitoring).\nShould there exist any backdoors in the products or services they provide to\nVA (referring to methods for bypassing computer authentication), the\ncontractor shall provide the VA CO/CO written assurance they have\npermanently remediated these backdoors.\nk. All other vulnerabilities, including those discovered through routine scans or\nother assessments, will be remediated based on risk, in accordance with the\nremediation timelines specified by the VA Information Security Knowledge\nService and/or the applicable timeframe mandated by Cybersecurity &\nInfrastructure Security Agency (CISA) Binding Operational Directive (BOD)\n2201 and BOD 19-02 for Internet-accessible systems. Exceptions to this\nparagraph will only be granted with the approval of the COR/CO.\n\n8. SECURITY AND PRIVACY CONTROLS COMPLIANCE TESTING, ASSESSMENT\nAND AUDITING. This entire section applies whenever section 6 or 7 is included.\na. Should VA request it, the contractor shall provide a copy of their (corporation s,\nsole proprietorship s, partnership s, limited liability company (LLC), or other\nbusiness structure entity s) policies, procedures, evidence and independent\nreport summaries related to specified cybersecurity frameworks (International\nOrganization for Standardization (ISO), NIST Cybersecurity Framework (CSF),\netc.). VA or its third-party/partner designee (if applicable) are further entitled\nto perform their own audits and security/penetration tests of the contractor s\nIT or systems and controls, to ascertain whether the contractor is complying\nwith the information security, network or system requirements mandated in\nthe agreement between VA and the contractor.\nb. Any audits or tests of the contractor or third-party designees/partner VA elects\nto carry out will commence within 30 business days of VA notification. Such\naudits, tests and assessments may include the following: (a):\nsecurity/penetration tests which both sides agree will not unduly impact\ncontractor operations; (b): interviews with pertinent stakeholders and\npractitioners; (c): document review; and (d): technical inspections of networks\nand systems the contractor uses to destroy, maintain, receive, retain, or use VA\ninformation.\nc. As part of these audits, tests and assessments, the contractor shall provide all\ninformation requested by VA. This information includes, but is not limited to,\nthe following: equipment lists, network or infrastructure diagrams, relevant\npolicy documents, system logs or details on information systems accessing,\ntransporting, or processing VA data.\nd. The contractor and at its own expense shall comply with any recommendations\nresulting from VA audits, inspections and tests. VA further retains the right to\nview any related security reports the contractor has generated as part of its own\nsecurity assessment. The contractor shall also notify VA of the existence of any\nsuch security reports or other related assessments, upon completion and\nvalidation.\ne. VA appointed auditors or other government agency partners may be granted\naccess to such documentation on a need-to-know basis and coordinated\nthrough the COR/CO. The contractor shall comply with recommendations\nwhich result from these regulatory assessments on the part of VA regulators\nand associated government agency partners.\n\n9. PRODUCT INTEGRITY, AUTHENTICITY, PROVENANCE, ANTI-COUNTERFEIT\nAND ANTI-TAMPERING. This entire section applies when the acquisition involves\nany product (application, hardware, or software) or when section 6 or 7 is included.\na. The contractor shall comply with Code of Federal Regulations (CFR) Title 15\nPart 7, Securing the Information and Communications Technology and\nServices (ICTS) Supply Chain , which prohibits ICTS Transactions from foreign\nadversaries. ICTS Transactions are defined as any acquisition, importation,\ntransfer, installation, dealing in or use of any information and communications\ntechnology or service, including ongoing activities, such as managed services,\ndata transmission, software updates, repairs or the platforming or data hosting\nof applications for consumer download.\nb. When contracting terms require the contractor to procure equipment, the\ncontractor shall purchase or acquire the equipment from an Original\nEquipment Manufacturer (OEM) or an authorized reseller of the OEM. The\ncontractor shall attest that equipment procured from an OEM or authorized\nreseller or distributor are authentic. If procurement is unavailable from an OEM\nor authorized reseller, the contractor shall submit in writing details of the\ncircumstances prohibiting this from happening and procure a product waiver\nfrom the VA COR/CO.\nc. All contractors shall establish, implement, and provide documentation for risk\nmanagement practices for supply chain delivery of hardware, software (to\ninclude patches) and firmware provided under this agreement. Documentation\nwill include chain of custody practices, inventory management program,\ninformation protection practices, integrity management program for sub supplier\nprovided components, and replacement parts requests. The contractor\nshall make spare parts available. All contractor(s) shall specify how digital\ndelivery for procured products, including patches, will be validated and\nmonitored to ensure consistent delivery. The contractor shall apply encryption\ntechnology to protect procured products throughout the delivery process.\nd. If a contractor provides software or patches to VA, the contractor shall publish\nor provide a hash conforming to the FIPS Security Requirements for\nCryptographic Modules (FIPS 140-2 or successor).\ne. The contractor shall provide a software bill of materials (SBOM) for procured\n(to include licensed products) and consist of a list of components and\nassociated metadata which make up the product. SBOMs must be generated in\none of the data formats defined in the National Telecommunications and\nInformation Administration (NTIA) report The Minimum Elements for a\nSoftware Bill of Materials (SBOM). \nf. Contractors shall use or arrange for the use of trusted channels to ship procured\nproducts, such as U.S. registered mail and/or tamper-evident packaging for\nphysical deliveries.\ng. Throughout the delivery process, the contractor shall demonstrate a capability\nfor detecting unauthorized access (tampering).\nh. The contractor shall demonstrate chain-of-custody documentation for procured\nproducts and require tamper-evident packaging for the delivery of this\nhardware.\n\n10. VIRUSES, FIRMWARE AND MALWARE. This entire section applies when the\nacquisition involves any product (application, hardware, or software) or when\nsection 6 or 7 is included.\na. The contractor shall execute due diligence to ensure all provided software and\npatches, including third-party patches, are free of viruses and/or malware\nbefore releasing them to or installing them on VA information systems.\nb. The contractor warrants it has no knowledge of and did not insert, any\nmalicious virus and/or malware code into any software or patches provided to\nVA which could potentially harm or disrupt VA information systems. The\ncontractor shall use due diligence if supplying third-party software or patches,\nto ensure the third party has not inserted any malicious code and/or virus\nwhich could damage or disrupt VA information systems.\nc. The contractor shall provide or arrange for the provision of technical\njustification as to why any false positive hit has taken place to ensure their\ncode s supply chain has not been compromised. Justification may be required,\nbut is not limited to, when install files, scripts, firmware, or other contractor delivered software solutions (including third-party install files, scripts,\nfirmware, or other software) are flagged as malicious, infected, or suspicious by\nan anti-virus vendor.\nd. The contractor shall not upload (intentionally or negligently) any virus, worm,\nmalware or any harmful or malicious content, component and/or corrupted\ndata/source code (hereinafter virus or other malware ) onto VA computer\nand information systems and/or networks. If introduced (and this clause is\nviolated), upon written request from the VA CO, the contractor shall:\n(1) Take all necessary action to correct the incident, to include any and all\nassistance to VA to eliminate the virus or other malware throughout VA s\ninformation networks, computer systems and information systems; and\n(2) Use commercially reasonable efforts to restore operational efficiency and\nremediate damages due to data loss or data integrity damage, if the virus\nor other malware causes a loss of operational efficiency, data loss, or\ndamage to data integrity\n.\n11. CRYPTOGRAPHIC REQUIREMENT. This entire section applies whenever the\nacquisition includes section 6 or 7 is included.\na. The contractor shall document how the cryptographic system supports the\ncontractor s products and/or services protect the confidentiality, data integrity,\nauthentication and non-repudiation of devices and data flows in the underlying\nsystem.\nb. The contractor shall use only approved cryptographic methods as defined in\nFIPS 140-2 (or its successor) and NIST 800-52 standards when enabling\nencryption on its products.\nc. The contractor shall provide or arrange for the provision of an automated\nremote key-establishment method which protects the confidentiality and\nintegrity of the cryptographic keys.\nd. The contractor shall ensure emergency re-keying of all devices can be remotely\nperformed within 30 business days.\ne. The contractor shall provide or arrange for the provision of a method for\nupdating cryptographic primitives or algorithms.\n\n12. PATCHING GOVERNANCE. This entire section applies whenever the acquisition\nincludes section 7 is included\na. The contractor shall provide documentation detailing the patch management,\nvulnerability management, mitigation and update processes (to include third\nparty) prior to the connection of electronic devices, assets or equipment to VA s\nassets. This documentation will include information regarding the follow:\n(1) The resources and technical capabilities to sustain the program or process\n(e.g., how the integrity of a patch is validated by VA); and\n(2) The approach and capability to remediate newly reported zero-day\nvulnerabilities for contractor products.\nb. The contractor shall verify and provide documentation on all procured products\n(including third-party applications, hardware, software, operating systems, and\nfirmware) have appropriate updates and patches installed prior to delivery to\nVA.\nc. The contractor shall provide or arrange the provision of appropriate software\nand firmware updates to remediate newly discovered vulnerabilities or\nweaknesses for their products and services within 30 days of discovery.\nUpdates to remediate critical or emergent vulnerabilities will be provided\nwithin seven business days of discovery. If updates cannot be made available\nby contractor within these time periods, the contractor shall submit mitigations,\nmethods of exploit detection and/or workarounds to the COR/CO prior to the\nabove deadlines.\nd. The contractor shall provide or arrange for the provision of appropriate\nhardware, software and/or firmware updates, when those products, including\nopen-source software, are provided to the VA, to remediate newly discovered\nvulnerabilities or weaknesses. Remediations of products or services provided to\nthe VA s system environment must be provided within 30 business days of\navailability from the original supplier and/or patching source. Updates to\nremediate critical vulnerabilities applicable to the Contractor s use of the third\nparty product in its system environment will be provided within seven\nbusiness days of availability from the original supplier and/or patching source.\nIf applicable third-party updates cannot be integrated, tested and made\navailable by Contractor within these time periods, mitigations and/or\nworkarounds will be provided to the COR/CO before the above deadlines.\n\n\n\nResponses to this RFI should include:\n\nCompany name\nAddress\nPoint of contact\nPhone number\nPoint of contact e-mail\nContractor s Unique Entity ID (SAM) number\nNAICS: 334510\nSize standard: 1250 Employees\nCapability Statement\n\nThis RFI will be conducted in accordance with Federal Acquisition Regulation (FAR) Part 12. \nTelephone responses will not be accepted. Responses must be received via e-mail to Adriane.Perretti@va.gov no later, 10:00 AM Eastern Standard Time (EST) on 11/20/2025, with 36C24426Q0040 in the subject line. This notice will help the VA in determining available potential sources only. Do not contact VA Medical Center staff regarding this requirement, as they are not authorized to discuss this matter related to this procurement action.\nAll firms responding to this Request for Information are advised that their response is not a request for proposal, therefore proposals will not be considered for a contract award. \nIf a solicitation is issued, information will be posted on the www.sam.gov web site for all qualified interested parties. Interested parties must respond to the solicitation to be considered for award. This notice does not commit the government to contract for any supplies or services. The government will not pay for any information or administrative cost incurred in response to this Request for Information.\nDISCLAIMER \nThis RFI is issued solely for information and planning purposes only and does not constitute a solicitation. All information received in response to this RFI that is marked as proprietary will be handled accordingly. Responses to this notice are not offers and cannot be accepted by the Government to form a binding contract. Responders are solely responsible for all expenses associated with responding to this RFI.\n\n"}

Open original notice

Get tenders like this in one daily alert

Use this notice as context when Tenqual drafts your search scope and fit criteria.

Create free alert
6540--Zeiss Callisto Eye System | 595 tender | Tenqual