SOS Next Generation Licensing Platform O&M Support
| Agency: | State of Vermont |
|---|---|
| State: | Vermont |
| Type of Government: | State & Local |
| NAICS Category: |
|
| Posted Date: | Aug 19, 2026 |
| Due Date: | Aug 28, 2026 |
| Original Source: | Please Login to View Page |
| Contact information: | Please Login to View Page |
| Bid Documents: | Please Login to View Page |
Description
| TITLE | QUESTIONS DUE | ANSWERS POSTED | DUE DATE | NO POSTING AFTER |
|
SOS Next Generation Licensing Platform O&M Support
Bidder Response Form |
08/14/2026 04:30PM |
Q&A - SOS OPR Next Gen Licensing M&O. (08/19/2026) |
08/28/2026 04:30PM |
|
Attachment Preview
State of Vermont Bidder Response Form
Request for Proposal Name: VTSOS NGLP O&M SUPPORT
Vendor Instructions:
Provide the information requested in this form and submit it to the State of Vermont as part of your Request for Proposal (RFP) response. All answers must be provided within the form unless otherwise specified.
Important: This form must be completed and submitted in response to this RFP for your proposal to be considered valid. The submission must also include the eight (8) additional artifacts requested within this form (denoted by underlined green font).
See the RFP for full instructions for submitting a bid. Bids must be received by the due date and at the location specified on the cover page of the RFP.
Direct any questions you have concerning this form or the RFP to:
Kyle Emerson
State of Vermont
Office of Purchasing & Contracting
E-mail Address:
Part 1: VENDOR PROFILE
Complete the table below.
Provide a brief overview of your company including number of years in business, number of employees, nature of business, and description of clients. Identify any parent corporation and/or subsidiaries.
Is your organization currently or has it previously provided solutions and/or services to any agency or entity of the Vermont State government within the past five years? If so, include a complete list of the State entities, the solutions and/or services provided, and the dates your organization provided the State with these services in the last five years.
Provide a Financial Statement* for your company and label it Attachment #1. This requirement can be filled by:
A current Dun and Bradstreet Report that includes a financial analysis of the firm;
An Annual Report if it contains (at a minimum) a Compiled Income Statement and Balance Sheet verified by a Certified Public Accounting firm; or
Tax returns and financial statements including income statements and balance sheets for the most recent 3 years, and any available credit reports.
A confidentiality statement may be included if this financial information is considered non-public information
*Some types of procurements may require bidders to provide additional or specific financial information. Any such additional requirements will be clearly identified and explained within the RFP and may include supplemental forms in addition to this Bidder Response Form.
Disclose any judgments, pending or expected litigation, or other real potential financial reversals, which might materially affect the viability or stability of your company or indicate below that no such condition is known to exist. A confidentiality statement may be included if this information is considered non-public information
Provide a list of three references similar in size and industry (preferably another governmental entity). References shall be clients, other than the State of Vermont, who have implemented your Solution within the past 48 months.
Part 2: Vendor Proposal/Solution
Provide a description of the operations and maintenance support you are proposing.
Provide a description of the capabilities of the operations and maintenance support you are proposing.
Have you provided operations and maintenance support to government entities? If so, tell us who, when, and how that went?
Provide PowerPoint (minimum of 1 slide and maximum of 10 slides) that provides an Executive level summary of your proposal to the State. Label Attachment #3.
Part 3: system enhancements
The System Enhancements are informational only. A list of these enhancements will be found in Attachment E. This listing of user stories is to provide awareness to potential bidders of the future work. Please do not provide a response to any portion of Attachment E.
Part 4: Non- Functional Requirements
Provide a response to and/or acknowledge compliance with the following NFR's listed under each of the following subsections: 4.1 personnel security program, 4.2 processes, 4.3. hosting, 4.4. application environment, 4.5. portability, 4.6. support, and 4.7. data compliance.
4.1. Personnel Security Program
4.1.1. Provide qualifications and experience of all proposed personnel, including subcontractors. Where applicable, provide any specific knowledge and experience with state and local policies, architecture, and related aspects of the proposed work.
4.1.2. Describe your company's process for background checks and security training for those who will be working on the project.
4.1.3. Provide all work locations and descriptions of physical and logical security requirements, handling of sensitive materials, and emergency and disaster backup provisions. Describe how you will manage various work locations from the perspective of system security. This includes adherence to customer requirements that all work and data storage be maintained in the United States, as applicable.
4.1.4. Describe security training requirements for personnel. Include descriptions of different training for different types of personnel (e.g., system administrators, developers, etc.). Confirm that these same requirements also apply to any subcontractors.
4.1.5. Disclose all countries in which your company operates. Describe the corporate structure and ownership (e.g., publicly traded corporation, privately held partnership, nonprofit). Disclose all board members or any entity with more than 10% ownership in the organization. Also, disclose any ownership in your company by non-U.S. persons or entities, regardless of ownership percentage.
4.1.6. Describe the review process for key personnel that perform critical management and technical functions. Also identify the timing of notification to the customer when a change occurs and the plan for replacing those key personnel.
4.1.7. If subcontractors will be used under this procurement, provide details on each subcontractor and the parts of the project in which they will be involved. The customer shall preapprove all subcontractors. Describe your process for selection and management of subcontractors, including how subcontractors are evaluated on an ongoing basis for meeting security requirements. Describe what information subcontractors will be allowed to access and how you will monitor their activities.
4.2. Processes
4.2.1. Describe your processes for identifying specific cybersecurity risks and mitigating them in the system environment. Be specific and provide specific examples of how this process has been successful in both confirming proper implementation and identifying needed changes. Include lab testing and third-party testing you regularly employ.
4.2.2. Define or provide documentation on incident handling, recovery, and contingency processes, including communication plans, backup procedures, and process for operational data availability. This should also include items such as log and audit, log analysis and assessment, and forensics capabilities.
4.2.3. Define what constitutes an incident and each level of severity. Include procedures for notifying your customer(s) in the event of incidents of each level of severity, to include responsibilities and liability. Also, provide a communications plan for handling an incident.
4.2.4. If you have cybersecurity insurance, provide proof of coverage, and describe any relevant details of the policy.
4.2.5. Provide a contract transition plan for the end of the contract.
4.2.6. Clearly describe expected scope of cybersecurity-related tasks under this contract and who (e.g., contractor, government) is responsible for executing those tasks.
4.2.7. Clearly describe how you intend to monitor service and development processes to ensure adherence to the security requirements of this contract.
4.2.8. Describe how you monitor ongoing security threat changes and respond to evolving threats, including monitoring common vulnerabilities and exposures (CVEs) and any ability to receive and share real-time threat information. Indicate participation in information sharing networks; for example, the Information Technology Information Sharing & Analysis Center (IT-ISAC).
4.2.9. Describe your process for moving data, whether digitally or physically, while maintaining appropriate security protection and data integrity. This includes between organizations such as the proposer and proposed subcontractors, and, to the government, where applicable, during transitions to new systems and technologies.
4.2.10. Describe security requirements that apply to information and communication products and services.
4.2.11. Define specific levels of service for key work activities including performance standards for each service. These should include, but not be limited to:
Expected outcomes for normal security activities.
Include your policies for response time, types of support (e.g., in-person, phone) provided.
Approach to ensuring continuity of mission critical services (e.g., failure restoral, patching and updates, and other relevant service component failures).
4.2.12. Describe trigger points for deploying updates and the approvals needed on both the vendor and customer sides. This response should address vulnerability detection and remediation, patching speeds, and incident response and escalation procedures.
4.2.13. Do you have a standardized system development life cycle management process for information technology? If so, describe your experience in using that life cycle management process for work of the same scope as this engagement and which environment(s) do you currently use (e.g., Azure, Jira, etc.) to manage delivery and high software quality?
4.2.14. Does your software development team follow a secure software development framework (e.g., NIST.SP.800-218)? If so, please describe the secure software development process. If not, are you willing to work with the state on incorporating this framework into your software development process?
4.2.15. Describe the life cycle processes used to manage hardware and software. How will these processes ensure that updates appropriately address security considerations?
4.2.16. Provide a security plan for implementing the security requirements and controls for the product or service. In the absence of the detailed plan, provide an outline of such plan along with examples of security plans for similar products or services provided under similar contracts you have been awarded and successfully implemented. The plan will be finalized in coordination with the customer during the period of performance. If you use a reference standard to develop your security plan, please identify which one.
4.2.17. Clarify whether you have a responsible disclosure policy for vulnerabilities and, if so, include it with your submission.
4.2.18. Describe the scope of responsibilities, assignment/ownership of tasks, and processes and procedures for adhering to security requirements and controls for the product or service.
4.2.19. Describe the security audits and penetration analysis performed on a regular basis. If conducted, provide annual security audit reports conducted by an independent auditor.
4.2.20. Provide examples of prior security testing and evaluation reports, vulnerability assessment reports, and any related reports. Additionally, the customer may require contractors and their suppliers to provide security testing reports and independent audit reports from similar work to this project that details the effectiveness of security controls and demonstrate timely correction of issues.
4.2.21. Provide evidence of certification or registration according to national quality or security standards. Describe your adherence to standardized quality principles, such as through registration as ISO 9001 (general quality) and ISO/IEC 27001 (information security). Both are strongly preferred. If you do not follow a standardized quality principle, provide your documented processes and evidence that you monitor adherence to those processes.
4.2.22. Describe how information sensitivity is categorized and how access to sensitive information is managed and documented for each category, including your ability to create reports and machine-readable data extracts for both private and public dissemination. Clearly designate responsibilities, obligations, and procedures for key aspects of a data governance plan (data owner, data steward, data retention, information sensitivity, etc.).
4.2.23. Demonstrate your understanding of this jurisdiction's data governance policies and practices and propose a data governance approach as part of your submission.
4.3. Hosting
4.3.1. Any hosting provider must provide for back-up and disaster recovery models and plans as needed for the solution
4.3.2. Any hosting provider will abide by ITIL best practices for change requests, incident management, problem management and service desk.
4.4. Application Environment
4.4.1. The vendor must provide for the backup/recover, data retention and disaster recovery of a contracted/hosted application solution. Describe how you will meet this requirement.
4.4.2. The vendor must provide application management and design standards of all technology platforms and environments for the application solution (Development, Staging, Productions, DR, etc.). Describe how you will meet this requirement.
4.4.3. The vendor must engage the State of Vermont using Service Level Agreements for system and application performance, incident reporting and maintenance. Describe how you will meet this requirement.
4.4.4. The State owns any data they enter, migrate, or transmit into the solution and the vendor shall allow the State to pull or copy this data at any time free of charge. Describe how you will meet this requirement.
4.5. Support
4.5.1. Provide a full incident response plan that ensures system availability/recovery in the event of an unforeseen incident including recovery times.
4.5.2. Based on a Service Level Agreement (SLA) per severity levels of support issues, provide State technical support during the business hours of Monday - Friday, 7:45 AM to 4:30 PM, eastern standard time, excluding State Holidays.
4.7 Data Compliance
Vendors and their solutions must adhere to applicable State and Federal standards, policies, and laws based on the type of data that will be stored, accessed, transmitted and/or controlled by the solution. If the "Type of Data" column is checked below, respond "Yes" or "No" in the "Comply" column and provide an explanation on how you comply in the "Vendor's Description of Compliance" column.
4.8 State of Vermont Cybersecurity Standard Update
Bidder shall certify by checking the box below the Solution shall not include, incorporate, rely on, utilize or be supported by any products or services subject to the limitations provided under State of Vermont Cybersecurity Standard Update, which Bidder acknowledges has been provided to it, and is available on-line at the following URL:
Bidder hereby certifies that in connection with the Request for Proposal, none of the applicable products or services will be included in or used to support State systems in a manner prohibited under the Standard.
Part 5: Project Management Approach
Describe the approach you would recommend for project managing during this engagement.
Provide a list of the standard project management deliverables that you would normally produce for this type of engagement.
Describe the experience and qualifications of the Project Manager you would offer as the resource for this engagement. Provide a copy of their resume and label it Attachment #5.
Part 6: TECHNICAL Services
Describe the technical services included in your proposal (e.g., business analysis, configuration, testing, implementation, etc.).
Provide a list of the standard deliverables for the technical services described above.
Provide a description of the roles/services/tasks the State will be expected to cover as part of this engagement. Describe any additional roles/services/tasks that are optional but would be beneficial for the State to provide.
Describe the experience and qualifications of the technical resources proposed for this engagement. Provide their resume(s) and label them Attachment #7.
Part 7: Maintenance and Support Services
Provide answers to the questions below regarding your company's Maintenance and Support Services:
Describe how adherence to your service levels is measured and what remedies you would provide the State when performance doesn't meet the standard?
Part 8: PRICING
The State is looking for two pricing components in your bid, a fixed price for maintenance and operations activities and defined enhancements as mentioned in RFP (items 2.1.1 through 2.1.4), and a rate card for future work not defined in this RFP as described in items 2.1.5 through 2.1.11.
Submit proposed pricing for maintenance and operations below. Insert lines to itemize additional costs. Total each column and provide a total of all columns in the "Total Implementation, plus 5 Year Costs" box on the next page.
Provide pricing information on a rate card for future work.
Describe any assumptions you have made in relation to the above cost and pricing information.
Provide pricing information for any volume discounts that are available based on the number of software licenses purchased or support years purchased.
Part 9: Terms and Conditions
Exceptions to the States standard terms, conditions, and templates is strongly discouraged. Accordingly, exceptions may result in a determination that a bidder's proposal is not in the best interest of the State. However, if a bidder does wish to take exception to the State's terms, conditions, or templates they must indicate those objections in the table below. Add lines to the table below as needed. The State considers contractor documents the bidder wishes to append to the contract as exceptions.
Part 10: CERTIFICATE OF COMPLIANCE/Authorized Company Signature
NON COLLUSION: Bidder hereby certifies that the prices quoted have been arrived at without collusion and that no prior information concerning these prices has been received from or given to a competitive company. If there is sufficient evidence to warrant investigation of the bid/contract process by the Office of the Attorney General, bidder understands that this paragraph might be used as a basis for litigation.
CONTRACT TERMS: Bidder hereby acknowledges that is has read, understands and agrees to the terms of this RFP, including Attachment C: Standard State Contract Provisions, and any other contract attachments included with this RFP.
Worker Classification Compliance Requirement: In accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), the following provisions and requirements apply to Bidder when the amount of its bid exceeds $250,000.00.
Self-Reporting. Bidder hereby self-reports the following information relating to past violations, convictions, suspensions, and any other information related to past performance relative to coding and classification of workers, that occurred in the previous 12 months.
Subcontractor Reporting. Bidder hereby acknowledges and agrees that if it is a successful bidder, prior to execution of any contract resulting from this RFP, Bidder will provide to the State a list of all proposed subcontractors and subcontractors' subcontractors, together with the identity of those subcontractors' workers compensation insurance providers, and additional required or requested information, as applicable, in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), and Bidder will provide any update of such list to the State as additional subcontractors are hired. Bidder further acknowledges and agrees that the failure to submit subcontractor reporting in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54) will constitute non-compliance and may result in cancellation of contract and/or restriction from bidding on future state contracts.
Executive Order 05 - 16: Climate Change Considerations in State Procurements Certification
Bidder certifies to the following (Bidder may attach any desired explanation or substantiation. Please also note that Bidder may be asked to provide documentation for any applicable claims):
Bidder owns, leases or utilizes, for business purposes, space that has received:
Energy Star(R) Certification
LEED(R), Green Globes(R), or Living Buildings ChallengeSM Certification
Other internationally recognized building certification:
____________________________________________________________________________
2. Bidder has received incentives or rebates from an Energy Efficiency Utility or Energy Efficiency Program in the last five years for energy efficient improvements made at bidder's place of business. Please explain:
_____________________________________________________________________________
3. Please Check all that apply:
Bidder can claim on-site renewable power or anaerobic-digester power ("cow-power"). Or bidder consumes renewable electricity through voluntary purchase or offset, provided no such claimed power can be double-claimed by another party.
Bidder uses renewable biomass or bio-fuel for the purposes of thermal (heat) energy at its place of business.
Bidder's heating system has modern, high-efficiency units (boilers, furnaces, stoves, etc.), having reduced emissions of particulate matter and other air pollutants.
Bidder tracks its energy consumption and harmful greenhouse gas emissions. What tool is used to do this? _____________________
Bidder promotes the use of plug-in electric vehicles by providing electric vehicle charging, electric fleet vehicles, preferred parking, designated parking, purchase or lease incentives, etc..
Bidder offers employees an option for a fossil fuel divestment retirement account.
Bidder offers products or services that reduce waste, conserve water, or promote energy efficiency and conservation. Please explain:
____________________________________________________________________________
____________________________________________________________________________
Please list any additional practices that promote clean energy and take action to address climate change:
_____________________________________________________________________________
____________________________________________________________________________
_____________________________________________________________________________
Executive Order 02 - 22: Solidarity with the Ukrainian People
By checking this box, Bidder certifies that none of the goods, products, or materials offered in response to this solicitation are Russian-sourced goods or produced by Russian entities. If Bidder is unable to check the box, it shall indicate in the table below which of the applicable offerings are Russian-sourced goods and/or which are produced by Russian entities. An additional column is provided for any note or comment that you may have. INSTRUCTION: REMOVE THIS SECTION IF FUNDING SOURCE PROHIBITS USE OF THIS LANGUAGE AND/OR WILL IMPACT SOV ELIGIBILITY FOR REIMBURSEMENT (I.E. FHWA).
Certification Regarding Use of Contract Funds for Lobbying. The following provision is applicable to the Contractor for contracts over $100,000.00, and Contractor shall include this clause in all its subcontracts over $100,000.00.
1. The prospective contractor certifies, to the best of his or her knowledge and belief, under the penalties of perjury under the laws of the State of Vermont and the United States that on behalf of the person, firm, association, or corporation he or she represents, that:
a. No Federal appropriated funds have been paid or will be paid, by or on behalf of the undersigned, to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with the awarding of any Federal contract, the making of any Federal grant, the making of any Federal loan, the entering into of any cooperative agreement, and the extension, continuation, renewal, amendment, or modification of any Federal contract, grant, loan, or cooperative agreement.
b. If any funds other than Federal appropriated funds have been paid or will be paid to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with this Federal contract, grant, loan, or cooperative agreement, the undersigned shall complete and submit Standard Form-LLL, "Disclosure Form to Report Lobbying," in accordance with its instructions.
2. This certification is a material representation of fact upon which reliance was placed when this transaction was made or entered into. Submission of this certification is a prerequisite for making or entering into this transaction imposed by 31 U.S.C. 1352. Any person who fails to file the required certification shall be subject to a civil penalty of not less than $10,000 and not more than $100,000 for each such failure.
3. The prospective contractor also agrees that they shall require that the language of this certification be included in all lower tier subcontracts, which exceed $100,000 and that all such recipients shall certify and disclose accordingly.
For your bid to be considered valid, this Bidder Response Form must be signed by a duly authorized representative of the bidder, and submitted as part of the response to the proposal.
I am authorized to submit a proposal to the State of Vermont in response to this RFP on behalf of my organization. The information provided as part of my organization's response is a true and accurate representation of my organization's ability to meet the State of Vermont's business needs as expressed in this RFP.
| Item | Detail |
|---|---|
| Company Name: | [insert the name that you do business under] |
| Physical Address: | [if more than one office - put the address of your head office] |
| Postal Address: | [e.g. P.O Box address] |
| Business Website: | [url address] |
| Type of Entity (Legal Status): | [sole trader/partnership/limited liability company or specify other] |
| Primary Contact: | [name of the person responsible for communicating with the Buyer] |
| Title: | [job title or position] |
| Email Address: | [email] |
| Phone Number: | [landline] |
| Fax Number: | [fax] |
| Reference 1 | Detail |
|---|---|
| Reference Company Name: | [insert the name that you do business under] |
| Company Address: | [address] |
| Type of Industry: | [industry type: e.g., government, telecommunications, etc.] |
| Contact Name: | [if applicable] |
| Contact Phone Number: | [phone] |
| Contact Email Address: | [email] |
| Description of system(s) implemented: | [description] |
| Date of Implementation: | [date] |
| Reference 2 | Detail |
|---|---|
| Reference Company Name: | [insert the name that you do business under] |
| Company Address: | [address] |
| Type of Industry: | [industry type: e.g., government, telecommunications, etc.] |
| Contact Name: | [if applicable] |
| Contact Phone Number: | [phone] |
| Contact Email Address: | [email] |
| Description of system(s) implemented: | [description] |
| Date of Implementation: | [date] |
| Reference 3 | Detail |
|---|---|
| Reference Company Name: | [insert the name that you do business under] |
| Company Address: | [address] |
| Type of Industry: | [industry type: e.g., government, telecommunications, etc.] |
| Contact Name: | [if applicable] |
| Contact Phone Number: | [phone] |
| Contact Email Address: | [email] |
| Description of system(s) implemented: | [description] |
| Date of Implementation: | [date] |
| ID # | Non-Functional Requirement Description | Comply | Vendor's Description of Applicable Security Processes | Audit/Monitor Process |
|---|---|---|---|---|
| S1 | Input validation | |||
| S2 | Output encoding | |||
| S3 | Authentication and password management | |||
| S4 | Session management | |||
| S5 | Access control | |||
| S6 | Cryptographic practices | |||
| S7 | Error handling and logging | |||
| S8 | Data protection from unauthorized use, modification, disclosure or destruction (accidental or intentional). | |||
| S9 | Communication security | |||
| S10 | System configuration | |||
| S11 | Database security | |||
| S12 | File management | |||
| S13 | Memory management | |||
| S14 | Fraud detection | |||
| S15 | General coding practices | |||
| S16 | POA&M management | |||
| S17 | Risk Assessment Practices including but not limited to vulnerability assessment and pen testing | |||
| S18 | Incident response planning and testing | |||
| S19 | System Security Plan delivery |
| Type of Data | Applicable State & Federal Standards, Policies, and Laws | Comply | Vendor's Description of Compliance |
|---|---|---|---|
| Publicly available information | NIST 800-171 | ||
| Confidential Personally Identifiable Information (PII) | State law on Notification of Security Breaches State Law on Social Security Number Protection State law on the Protection of Personal Information National Institute of Standards & Technology: NIST SP 800-53 Revision 4 "Moderate" risk controls Privacy Act of 1974, 5 U.S.C. 552a. | ||
| Payment Card Information | Payment Card Industry Data Security Standard (PCI DSS) v 3.2 | ||
| Federal Tax Information | Internal Revenue Service Tax Information Security Guidelines for Federal, State and Local Agencies: IRS Pub 1075 | ||
| Personal Health Information (PHI) | Health Insurance Portability and Accountability Act of 1996: HIPAA The Health Information Technology for Economic and Clinical Health Act HITECH Code of Federal Regulations 45 CFR 95.621 |
| Type of Data | Applicable State & Federal Standards, Policies, and Laws | Comply | Vendor's Description of Compliance |
|---|---|---|---|
| Affordable Care Act Personally Identifiable Information (PII) | Internal Revenue Service Tax Information Security Guidelines for Federal, State and Local Agencies IRS Pub 1075 Minimum Acceptable Risk Standards for Exchanges MARS-E 2.0 (Scroll down the page) | ||
| Medicaid Information | Medicaid Information Technology Architecture MITA3.0 Code of Federal Regulations 45 CFR 95.621 | ||
| Prescription Information | State law on the Confidentiality of Prescription Information | ||
| Student Education Data | Family Educational Rights and Privacy Act: FERPA | ||
| Personal Information from Motor Vehicle Records | Driver's Privacy Protection Act (Title XXX) ("DPPA") 18 U.S.C. Chapter 123, 2721 - 2725 | ||
| Criminal Records | Criminal Justice Information Security Policy: CJIS | ||
| Other sensitive data | Data that does not fit into the above categories but is sensitive and requires additional protection. |
| Questions | Vendor Response |
|---|---|
| Service: Customer Phone &/or Email Support | Service: Customer Phone &/or Email Support |
| What is the method for contacting technical support? | |
| What are the hours of operation for support? | |
| What is the turnaround time for responses? | |
| What is the escalation process for support issues? | |
| Who comprises the support team and what are their qualifications? | |
| Define your response resolution metrics and how you capture and report them. | |
| Service: Incident/Security Breach Notification and Process | Service: Incident/Security Breach Notification and Process |
| Describe your identification and notification process for security breaches. | |
| Service: Data Management | Service: Data Management |
| Describe how data is stored, retained and backed-up (including frequency). | |
| Service: Hosting | Service: Hosting |
| Describe the hosting service and associated service levels. |
| Questions | Vendor Response |
|---|---|
| Service: Scheduled Maintenance/Downtime | Service: Scheduled Maintenance/Downtime |
| What is the frequency of scheduled maintenance and downtime? | |
| What is the notification process for scheduled maintenance and downtime? | |
| Describe how "maintenance" updates are tested with customers prior to installing them in their live environments. | |
| Service: System Upgrades | Service: System Upgrades |
| Are software upgrades provided as part of the software support contract? | |
| Describe your software upgrade process. | |
| How often are new versions released? | |
| Is documentation and training provided for system upgrades? | |
| Are there additional costs for upgrades and/or new releases? | |
| Describe how and when the State will have an opportunity to test system upgrades/releases prior to live installation. | |
| Describe how the State will validate post installation and how changes will be backed out in the event that a problem is encountered. |
| Questions | Vendor Response |
|---|---|
| Service: Bug Fixes and Minor Enhancements | Service: Bug Fixes and Minor Enhancements |
| Describe the frequency and process for providing, testing, and installing bug fixes and minor enhancements. | |
| Service: Disaster Recovery | Service: Disaster Recovery |
| Describe the disaster recovery services included in this proposal for any non-state hosted services. | |
| What is your standard RPO and RTO? | |
| Describe the plan your company has in place for its own disaster recovery of any sites that may be involved in support of this proposal. |
| Cost Type | One Time (Implementation) | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 |
|---|---|---|---|---|---|---|
| Operations | ||||||
| Support and Maintenance Fees | n/a | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Total Base Costs | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Total Maintenance and Operations | $ 0.00 |
|---|
| Clause Location | Exception | Proposed Verbiage |
|---|---|---|
| [indicate RFP, exhibit, attachment or addendum, section & page number] | [briefly describe your concern about this clause] | [describe your suggested alternative wording for the clause or your solution] |
| [indicate RFP, exhibit, attachment or addendum, section & page number] | [briefly describe your concern about this clause] | [describe your suggested alternative wording for the clause or your solution] |
| [indicate RFP, exhibit, attachment or addendum, section & page number] | [briefly describe your concern about this clause] | [describe your suggested alternative wording for the clause or your solution] |
| Summary of Detailed Information | Date of Notification | Outcome |
|---|---|---|
| Provided Equipment or Product | Note or Comment |
|---|---|
| Signature: | |
|---|---|
| Full name: | |
| Title: | |
| Company: | |
| Date: |
See Also
Request for Bidders Request Date: 6/29/2026 11:55:02 AM Open Date: 6/29/2026 Closing Date:
State Government of Vermont
Due by 1/07/2027
NASPO Emerging Technologies Consulting and Services Request Date: 8/18/2026 3:25:52 PM Open Date:
State Government of Vermont
Due by 10/15/2026
TITLE QUESTIONS DUE ANSWERS POSTED DUE DATE NO POSTING AFTER NASPO Emerging Technologies
State of Vermont
Due by 10/15/2026
TITLE QUESTIONS DUE ANSWERS POSTED DUE DATE NO POSTING AFTER 2026 Retainer Contract
State of Vermont
Due by 10/02/2026