DA01--NBEKRSS (VA-26-00031146) Professional Service - Network Based Encryption Key Recovery Storage Solution
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Department of Veterans Affairs (VA) is conducting market research through a Request for Information (RFI) for Professional Service - Network Based Encryption Key Recovery Storage Solution (NBEKRSS). This RFI is for planning purposes only and is not a solicitation. The VA is seeking information on potential providers for software maintenance and support of its existing NBEKRSS solution, and assessing the market for new entrants and capabilities. Responses are due by March 23, 2026.
Purpose & Scope
The VA is contemplating a requirement to renew software maintenance and support for its deployed NBEKRSS solution, which is critical for the VA's Public Key Infrastructure (PKI) ecosystem. The system supports secure key recovery, high-volume S/MIME decryption for investigations, cybersecurity operations, and litigation discovery. The scope includes maintaining a solution that integrates with VA's existing PKI services, directories, and Hardware Security Modules (HSMs).
Key requirements for the NBEKRSS solution include:
- PKI Compatibility: Full interoperability with U.S. Treasury SSP PKI (VACA1 and VACA2) and integration with VA enterprise directory services.
- On-Premises Operation: All components must operate within VA facilities on VA-owned infrastructure.
- Cryptographic Requirements: Use FIPS-validated cryptographic modules (FIPS 140-3 or 140-2) and support modern TLS configurations (TLS 1.2/1.3).
- Key Recovery & Decryption: Secure ingestion, cataloging, and recovery of VA user encryption private keys, achieving ≥95% successful decryption on eligible items, and sustaining ≥50,000 email items/hour.
- HSM Integration: Compatibility with VA’s Luna T5000 HSMs and PED-based key controls.
- Support Services: 24/7/365 support from U.S.-based personnel, including software/firmware updates, patches, hotfixes, and technical support.
- Compliance: Must comply with Section 508, VA Technical Reference Model (TRM), Zero Trust controls, and IPv6 requirements.
- The requirement is described as a "Brand Name or Equal" for the current Zeva DecryptNaBox solution, requiring support for a minimum of 3.5 million encryption keys.
Contract & Timeline
- Type: Request for Information (RFI) / Sources Sought
- NAICS Code: 541519 (Computer Systems Design Services) with a $34 million size standard.
- Set-Aside: None specified.
- Anticipated Period of Performance: 12-month base period with four subsequent 12-month option periods.
- Response Due: March 23, 2026, 16:00 Eastern Time.
- Published: March 16, 2026.
Submission Requirements
Interested vendors must submit a response (limited to 15 pages, no marketing materials) via email to Dennis.Simms@va.gov and Michael.Weckesser@va.gov, with "Network-based Encryption Key Recovery Storage System" in the subject line. The email file size shall not exceed 5 MB. Responses should include:
- Company information (Name, Address, POC, Phone, Email, CAGE Code, UEI, Business Size/Status, NAICS, Socioeconomic Data, existing Contractual Vehicles).
- A summary of capabilities addressing the draft Product Description (PD) in areas such as Company Qualifications/Product Overview, Federal PKI/Security Compliance, Licensing Model, Release Management & Patching, and Technical Support Model.
- Specific examples or references for Corporate Service Line experience.
- Confirmation on whether the draft PD provides sufficient detail, and if not, technical comments/recommendations.
Additional Notes
This RFI is for market research only and does not obligate the Government to acquire any products or services. No funds have been authorized or appropriated for this effort. Proprietary information should be clearly marked.