VA-26-00050029 User and Entity Behavior Analytics (UEBA) Solution

SOL #: VA-26-00050029Sources Sought

Overview

Buyer

Veterans Affairs
Veterans Affairs, Department Of
TECHNOLOGY ACQUISITION CENTER NJ (36C10B)
EATONTOWN, NJ, 07724, United States

Place of Performance

Apple Springs, TX

NAICS

Other Computer Related Services (541519)

PSC

Security And Compliance Support Delivered As A Service, By Subscription, Or Service Contract. Includes Support Of Security Policies/Controls, Processes, Measuring Compliance Of Relevant Legal/Compliance Requirements, To Include Section 508, And Responding To Security Breaches. Also Provides Support For It Security Systems Providing Continuous Diagnostics And Mitigation (Cdm) For Real Time Cyber Security And Protection Such As Vulnerability Scanning, Managing Firewalls, Intrusion Prevention Systems, And Security Information And Event Management (Siem). Includes Disaster Recovery (Dr) Services To Support Dr Policy, Process And Means, Dedicated Failover Facilities And Perform Dr Testing. (DJ10)

Set Aside

No set aside specified

Timeline

1
Posted
Mar 5, 2026
2
Last Updated
Mar 10, 2026
3
Response Deadline
Mar 12, 2026, 4:59 PM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

The Department of Veterans Affairs (VA) is conducting market research via a Sources Sought notice for a User and Entity Behavior Analytics (UEBA) Solution. This RFI aims to identify potential sources capable of providing a host-based UEBA solution and comprehensive support services to the VA's Office of Information Security. Responses are due March 13, 2026, at 12:00 PM CST.

Purpose

This notice is for information and planning purposes only and does not constitute a Request for Quote (RFQ), Invitation for Bid (IFB), or Request for Proposal (RFP). The VA is seeking to gather information from potential sources for a UEBA solution, with an anticipated NAICS code of 541519. The VA anticipates awarding a Firm-Fixed Price contract to a single responsive, responsible contractor based on future solicitation.

Scope of Work (UEBA Solution)

The anticipated scope involves providing a Host-Based UEBA solution, including hardware, maintenance, software licenses, installation, and ongoing support. This encompasses project management, technical services, implementation, and maintenance to enhance cybersecurity by analyzing user, account, and host behaviors for anomaly detection. The solution must support IPv6, Zero Trust Architecture, and integrate with existing VA security platforms (Splunk, SOAR, EDR, SIEM, IDPS). Performance standards include technical quality, meeting project milestones, cost efficiency, and reporting metrics such as time to detect, investigate, and mitigate, along with false positive/negative rates.

Contract & Timeline

  • Type: Sources Sought / Market Research
  • Anticipated Contract Type: Firm-Fixed Price
  • NAICS Code: 541519
  • Set-Aside: None specified (market research)
  • Anticipated Period of Performance: One 12-month base period and two 12-month option periods (total 36 months), including seven optional tasks.
  • Response Due: March 13, 2026, 12:00 PM CST
  • Published: March 6, 2026

Information Requested from Responders

Interested parties should submit the following via email to Marcela.Clark2@va.gov:

  • Firm Name, Point of Contact (Name, Phone, Email)
  • Unique Entity ID (UEI) and CAGE Code
  • Small Business Status (including certifications like SDB, 8(a), HUBZone, SDVOSB, WOSB)
  • Authorized Reseller Letter (if applicable)
  • Identified tool/solution being offered
  • FedRamp certification level (or ability to obtain) and projected timeframe

Additional Notes

The RFI document also includes a detailed Product Description for a separate "Validation Authority and OCSP Responder Services Solution." However, the primary purpose of this Sources Sought notice is to gather information for the UEBA solution. Compliance with numerous federal and VA security directives, including FISMA, NIST, and VA Handbook 6500 series, is required for the UEBA solution.

People

Points of Contact

Marcela ClarkPRIMARY

Files

Files

Download
Download

Versions

Version 4
Sources Sought
Posted: Mar 10, 2026
View
Version 3Viewing
Sources Sought
Posted: Mar 6, 2026
Version 2
Sources Sought
Posted: Mar 6, 2026
View
Version 1
Sources Sought
Posted: Mar 5, 2026
View
VA-26-00050029 User and Entity Behavior Analytics (UEBA) Solution | GovScope