DA10--Trellix Brand Name or Equal Compact Disc (CD) / Digital Versatile Disc (DVD) Enterprise Encryption Software VA-26- 00046223
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Department of Veterans Affairs (VA) is conducting a Request for Information (RFI) for Trellix Brand Name or Equal Compact Disc (CD) / Digital Versatile Disc (DVD) Enterprise Encryption Software. This RFI is for planning purposes to gather market capabilities for an enterprise-wide encryption solution. Responses are due by March 17, 2026, at 10:00 AM EST.
Purpose
This RFI serves as market research to inform the VA's acquisition strategy and refine the Product Description (PD) for replacing its current Trellix software used for encrypting removable media. This is not a solicitation, and the Government is not obligated to acquire any products or services described.
Scope of Work
The VA seeks a "Brand Name or Equal" software solution that meets or exceeds specified requirements for CD/DVD encryption. Key technical requirements include:
- Encryption Standards: FIPS 140-3 compliant encryption for data-in-motion and data-at-rest by September 2026.
- Operating System Support: Must support Windows 11 Professional.
- Management & Deployment: Centrally managed, with agents deployable via BigFix or Configuration Manager (CM). Updates pushed from the server.
- User Interface & Reporting: Web-based management console with a user-friendly query/reporting tool, capable of exporting reports in multiple formats (DOC, PDF, XML).
- Integration: API-driven integration with Security Information and Event Management (SIEM) tools and Microsoft Active Directory (AD).
- Compliance: Adherence to VA Critical Security Controls, SSN Reduction Act, IPv6 requirements, and Section 508 standards.
Contract Details (Anticipated)
The anticipated period of performance is one 12-month base period (May 15, 2026 - May 14, 2027), with four potential 12-month option periods. The requirement includes 24/7/365 technical support and potential optional tasks for professional services and additional subscriptions.
Set-Aside
Responses to this RFI will inform future set-aside decisions. The VA has a strong interest in Service-Disabled Veteran-Owned Small Businesses (SDVOSBs) and Veteran-Owned Small Businesses (VOSBs). Small businesses should detail their intent and ability to meet set-aside requirements in accordance with VAAR 852.219-10 and 13 CFR §125.6, including available personnel, financial resources, and proposed subcontracting plans.
Submission Requirements
Interested contractors must submit a capability statement (maximum 10 pages, no marketing materials) summarizing their ability to meet the draft PD requirements. Submissions must include:
- Company Name, Address, Point of Contact, Phone, Fax, Email, Business Size and Status, VOSB/SDVOSB VIP verification, NAICS code(s), Socioeconomic data, and DUNS Number.
- An assessment of whether the draft PD provides sufficient detail, and if not, technical comments/recommendations. Responses must be emailed to Julia Renna, Contract Specialist, at Julia.Renna@va.gov by March 17, 2026, 10:00 AM EST. The subject line should be "RFI 36C10B26Q0254 - CD/DVD Enterprise Encryption Software". The email file size shall not exceed 5 MB, and proprietary information should be marked accordingly.
Additional Notes
This RFI is for planning purposes only and does not constitute a solicitation. No funds have been authorized for this effort, and the Government will not pay for information submitted. Technical questions may be included in the response but should not be directed to the customer.