Zero Trust Encryption RFI
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Department of Veterans Affairs (VA), Office of Information and Technology (OIT), is conducting market research through a Sources Sought / Request for Information (RFI) for Zero Trust Encryption and Post-Quantum Cryptography (PQC) readiness for its enterprise Hardware Security Module (HSM) managed services and lifecycle support. This RFI is a Service-Disabled Veteran-Owned Small Business (SDVOSB) Set-Aside opportunity. The VA seeks industry feedback to inform its acquisition strategy, requirements, and draft Performance Work Statement (PWS). Responses are due June 23, 2026.
Scope of Work
The VA operates a large and complex IT environment, relying on a fleet of 10 production network-attached HSM appliances (8 Luna T-5000, 2 Luna T-2000) across four CONUS data centers. These HSMs provide the cryptographic backbone for VA's PKI, KMS, and critical systems like VistA. The contractor will assume full maintenance and managed service responsibility for this existing equipment.
Key services include:
- HSM Hardware Sustainment and Maintenance: 24x7x365 support, preventive maintenance, firmware/software patching, and lifecycle planning for VA-owned HSM assets.
- HSM Managed Services and Partition Lifecycle Management: 24x7x365 managed services, including partition provisioning, decommissioning, and scaling.
- Post-Quantum Cryptography (PQC) Readiness and Upgrade Services: Transitioning HSM infrastructure to PQC standards (NIST FIPS 203, 204, 205) and managing crypto agility.
- Professional Services and Advisory Support: Technical consulting, market research, and training.
- Transition and Knowledge Transfer: Preparing the government to assume full operation of the HSM environment by contract end.
Contract & Timeline
- Type: Sources Sought / Request for Information (RFI)
- Anticipated Period of Performance: Twelve-month base period with four twelve-month option periods (total not to exceed sixty months).
- Set-Aside: Service-Disabled Veteran-Owned Small Business (SDVOSB)
- Anticipated NAICS Code: 541519 (Other Computer Related Services), with a small business size standard of $34.0 million.
- Response Due: June 23, 2026, at 2:00 PM Eastern Time.
- Published: June 13, 2026.
Submission & Evaluation
This is not a solicitation; no quotes or proposals should be submitted. Responses will inform the VA's acquisition strategy and potential set-aside determinations. Industry feedback is specifically requested on technical approach, salient characteristics, staffing models, planned transition to government operation, acquisition strategy, and pricing.
- Response Limit: Fifteen pages (excluding vendor information table).
- Format: Microsoft Word or Adobe PDF.
- Submission: Via email to Justin B Clark (Justin.Clark2@va.gov) and David A. Long (david.long4@va.gov).
Additional Notes
The RFI includes a draft PWS and a sanitized Attachment A (Government Furnished Property Inventory) detailing the existing HSM fleet. The contract aims to build VA's internal capability for independent HSM environment operation by the end of the period of performance.