SP 90468: Network Access Control System (Virtual Appliance)

Agency: City of Chicago Housing Authority
State: Illinois
Type of Government: State & Local
NAICS Category:
  • 238210 - Electrical Contractors and Other Wiring Installation Contractors
  • 541512 - Computer Systems Design Services
  • 541519 - Other Computer Related Services
  • 561621 - Security Systems Services (except Locksmiths)
Posted Date: Sep 8, 2026
Due Date: Sep 11, 2026
Original Source: Please Login to View Page
Contact information: Please Login to View Page
Bid Documents: Please Login to View Page

Description

SP 90468: Network Access Control System (Virtual Appliance)

Attachment Preview

PROJECT TITLE ITS 90468_Network Access Control System (Virtual Appliance)
REQUESTING DEPARTMENT / DIVISION Procurement & Contracts / Information Technology
REQUEST ISSUED 8/31/2026
QUOTE DUE DATE AND TIME 9/11/2026 at 1:00 PM CT
PERFORMANCE PERIOD 3 YEAR BASE TERM
Initial and Option Periods (if applicable)
PROJECTED CONTRACT START DATE 10/1/2026
CONTACT PERSON NAME/EMAIL Frederica Juste - FJuste@thecha.org

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
SMALL PURCHASE REQUEST FORM
PART 1 - REQUESTOR AND SCOPE OF SERVICES INFORMATION
PROJECT TITLE ITS 90468_Network Access Control System (Virtual
Appliance)
REQUESTING DEPARTMENT / DIVISION Procurement & Contracts / Information Technology
REQUEST ISSUED 8/31/2026
QUOTE DUE DATE AND TIME 9/11/2026 at 1:00 PM CT
PERFORMANCE PERIOD 3 YEAR BASE TERM
Initial and Option Periods (if applicable)
PROJECTED CONTRACT START DATE 10/1/2026
CONTACT PERSON NAME/EMAIL Frederica Juste - FJuste@thecha.org
PART 2 - SCOPE OF WORK
The Chicago Housing Authority (CHA) is seeking qualified vendors to provide, implement, configure, and
support installation, configuration, and initial enforcement of FortiNAC or an equivalent Network Access
Control system (NAC) across over 275 sites, supporting up to 11,000 various device/endpoint access. The
system shall improve inconsistent device onboarding, visibility across wired and wireless environments,
and heightened exposure to network security threats, restrict unauthorized devices, and ensure that only
trusted users/devices can access the CHA network.
Infrastructure shall meet all CHA's IT cybersecurity requirements & expectations, including protections
against unauthorized access, phishing, and data breaches. The platform shall be scalable to accommodate
infrastructure upgrades, future organizational growth, as well as contractors, board members, and
external partners, as needed.
Along with the execution of this quote form, please provide a three (3) page supplemental in pdf format
indicating your firm's capacity to provide services including a written narrative with the understanding of
project goals and objectives, as described in the scope of work below. The proposed software should
maintain a high rating, preferably 4.0 out of 5 stars, on the Gartner Peer Insights (GPI) platform. The GPI is
a fully vetted, enterprise-focused, vendor-agnostic online review and ratings platform specifically built for
enterprise software, hardware, and technology services. The NAC system rating must be within the
Network Access Control (NAC) market category and based on a minimum of 20 verified customer reviews.
The product must feature strong ecosystem integration capabilities and robust compliance features.
It must also feature an ecosystem where we can later buy optional switches and firewalls from that same
vendor to integrate natively with the NAC. This will move our architecture beyond standalone network
access control into a unified security environment.
All responding vendors will be required to provide a 30-40-minute demonstration conducting proof of
concept for the platform's capabilities and core functionality.

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
Key Deliverables for Virtual only NAC (No Hardware required):
* FortiNAC-MX-VM Manager or equivalent centralized management virtual
appliance
* FortiNAC-CAX-VM Primary or equivalent main control application and server
appliance
* FortiNAC-CAX-VM Secondary or equivalent main control application and server
appliance for redundancies & high availability
* Scalable for future organizational upgrades but integrates with CHA's current
infrastructure without additional purchase:
Microsoft Active Directory on premises
o
Microsoft Entra ID/Azure AD
o
Microsoft Intune / MDM
o
Email servers for notifications
o
ITSM: Ticket creation on NAC events (e.g., quarantine) in FreshService or
o
equivalent
SIEM: SolarWinds SEM (Security Event Manager) or equivalent
o
* Configuration of high availability (HA)
* Guest/unknown device onboarding portal & Device profiling + custom profiling
rules
* Network discovery and visibility
* NAC access policy development (VLANs, tags, compliance checks)
* Successful Pilot enforcement for specified locations and tuning including
document & knowledge transfers upon project closeout.
* Go live support (remote & onsite) at Headquarters (Chicago, IL 60605) and 300
active remote sites
Microsoft Windows 10 support.
o
Microsoft Windows 11 support.
o
Apple macOS support.
o
Network neutral vendor support.
o
NAC System features shall include, but are not limited to:
System Roles & Entities -Segmentation Strategy
* Admin Roles: IT Security, Network, Systems engineering, Help desk
* User Roles: Corporate user, contractor, guest, device
* Device groups: Managed workstation endpoints, BYOD, IoT devices, cameras,
workstations, servers and Wi-Fi endpoints
* Enforcement: VLAN/DACL (Dynamic Access Control List) /SGT (Security Group Tag) per
user role; Authenticated users and non-authenticated users.

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
Minimum Capabilities & Core Functionality:
* Preferred Wired & Wireless 802.1X with EAP-TLS. Capable use of active network scanning
and SNMP traps to discover and profile devices that cannot support standard 802.1X
agents, such as older cameras and other older devices
* MAB (Mac Authentication Bypass) for non-802.1X devices (printers, cameras, OT
controllers)
* Dynamic Authorization: VLAN assignment, Downloadable ACLs (DACL) or Security Group
Tags (SGT)/labels
* Discovery & Device Profiling: Using DHCP, LLDP, SNMP, traffic patterns; custom profiling
for OT/IoT
* Posture Assessment: Anti-virus, OS patch level, BitLocker encryption, firewall status;
integration with Intune/MDM
* Logging & SIEM: Syslog/API to SolarWinds SEM (Security Event Manager) dashboards for
authentication failures & anomalous device behavior
* Guest Access: Captive portal, self-registration, sponsor approval & High Availability:
Redundant NAC nodes, RADIUS survivability
* Change & Audit: Role-based admin access, change history, exportable configurations.
Support but not require RADIUS and be able to use SNMP and/or SSH for FULL NAC
control and visibility
* Dissolvable agent with ability to check Windows, macOS, and Linux user devices for
Security Policy Compliance before granting access. If the user is compliant, it must self-
remove, otherwise it stays on the device for remediation, checking for updates, etc.
without requiring admin rights and need for user or IT intervention.
* Support a broad set of profiling methods including Location, Vendor OUI, HTTP/HTTPS, IP
Range, SNMP, SSH, TCP, Telnet, UDP, WinRM, WMI Profile, DHCP Fingerprinting,
Persistent Agent, Active NMAP OS detection database, Passive OS analyzing of network
traffic, ONVIF, and Network Traffic
Technical Support Requirements: timely and reliable technical assistance throughout initial
implementation phase and ongoing business operations.
The following criteria for support shall include:
* 24x7 support for critical high impact incidents with a 1-hour initial response or Next Business
Day response time for standard low impact requests
* Defined response and escalation times
* access to experienced NAC engineers
* assistance with integrations and upgrades
* proactive notification of vulnerabilities, product updates and root cause analysis for
significant issues.
The vendor should also provide clear documentation, training resources, and identify any support
limitations or services that require additional fees.
CHA current network infrastructure supports RADIUS, VLAN enforcement, and discovery. Following final
award and kick-off, as a pre-requisite, CHA shall provide all necessary network information (IP addresses,
credentials, diagrams), complete prerequisite checklists, make required network configuration changes on
switches/APs/firewalls, and provide staff during enforcement testing. CHA shall approve any schedules
and change windows with the selected vendor prior to implementation.

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
Development, Configuration, and Implementation Phases:
Phase 1 Setup & Initial Configuration
* Deploy Manager, Primary, and Secondary appliances
* Apply certificates
* Integrate AD and email servers
* Configure HA and validate failover
* Run network discovery, Risks or blockers
* Prepare endpoint agent packages
* Phase summary + status report including blocks, risks, or limitations
Phase 2 Endpoint Classification & Profiling
* Create profiling rules
* Enable agent-based device scanning
* Integrate Intune for device context
* Review classification results
* Phase summary + status report including blocks, risks, or limitations
* CHA Review of accomplishments, outstanding tasks, and next steps
Phase 3 Policy Development
* Build access policies (VLAN assignments, tags)
* Build compliance policies (audit-only with notifications)
* Configure guest onboarding portal
* Enable system log forwarding to SIEM
* Validate policies
* Phase summary + status report, including blocks, risks, or limitations
* CHA Review of accomplishments, outstanding tasks, and next steps
Phase 4 Pilot Enforcement
* Enable NAC enforcement on selected Pilot Switches and Pilot SSIDs
* Access & compliance policies tested successfully
* Review of alerts, events, and help desk procedures
* Go-live assistance at HQ + 2 Remote Sites
* Phase summary + status report including blocks, risks, or limitations
* CHA Review of accomplishments, outstanding tasks, and next steps
Phase 5 Post-Go-Live Optimization
* Policy tuning and refinements
* Device profiling operational and accurate for major device groups
* Knowledge transfer to IT staff
* Final configuration summary + closeout report including blocks, risks, or limitations
* CHA Review of accomplishments, outstanding tasks, and next steps
All phases shall be completed within 15 calendar days. This includes 12 calendar days with service during
normal business hours (8:00 AM - 5:00 PM CT) and 3 calendar days with service outside of normal business
hours. All days are full-day blocks, and any unused days shall be used for post-project support within the first
year of the 3-year base term.
Prior to commencement, an itemized and detailed project timeline shall be created and submitted to CHA for
final approval.

CHA ITEM DESCRIPTION OR SUGGESTED SYSTEM NAME/SKU SERVICE DESCRIPTION *Estimated Annual Quantities BASE
3 YEAR TERM
LINE ITEM
TOTAL
Suggested Professional Services - Implementation, Integration, & Configuration Per Day Charge Normal Business Hours (8:00 AM CT - 5:00 PM CT) PART NAME/SKU# ________________________________ ________________________________ ________________________________ ________________________________ Engineering services that install, configure, integrate, and operate across all CHA sites. Covers profiling setup, NAC policy development, onboarding rules, segmentation, and pilot testing. Comment any addt'l details: ________________________________ ________________________________ ________________________________ ________________________________ 12 Per Day Charge: _$_________ *Base Year 1 Only* (Total 12 Days) _$_____________
FortiNAC Resource Service Per Day Charge for Normal Business Hours (8:00 AM CT - 5:00 PM CT) PART/SKU #FP-10-PS001-830-01-01 Engineering services that install, configure, integrate, and operate across all CHA sites. Covers profiling setup, NAC policy development, onboarding rules, segmentation, and pilot testing. 12 Per Day Charge: _$_________ *Base Year 1 Only* (Total 12 Days) _$_____________
Suggested Professional Services - Implementation, Integration, & Configuration Per Day Charge Overtime Hours (5:00 PM CT - 6:00 AM CT) PART NAME/SKU# ________________________________ ________________________________ ________________________________ ________________________________ Engineering services that install, configure, integrate, and operate across all CHA sites. Covers profiling setup, NAC policy development, onboarding rules, segmentation, and pilot testing. Comment any addt'l details: ________________________________ ________________________________ ________________________________ ________________________________ 3 Per Day Charge: _$_________ *Base Year 1 Only* (Total 3 Days) _$_____________
FortiNAC Resource Service Per Day Charge Overtime Hours (5:00 PM CT - 6:00 AM CT) PART/SKU #FP-10-PS001-830-01-01 Engineering services that install, configure, integrate, and operate across all CHA sites. Covers profiling setup, NAC policy development, onboarding rules, segmentation, and pilot testing. 3 Per Day Charge: _$_________ *Base Year 1 Only* (Total 3 Days) _$_____________
Suggested NAC Control/ Application Virtual Server System NAME & SKU: ________________________________ ________________________________ ________________________________ ________________________________ Provides device visibility, automated access control, and policy enforcement across CHA's entire network. Enables identification of all connected devices and blocks unauthorized network access. Comment any addt'l details: ________________________________ ________________________________ ________________________________ ________________________________ 1 $_____________
*Estimated
Annual
Quantities
CHA ITEM DESCRIPTION OR
SUGGESTED SYSTEM
NAME/SKU

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
*Pricing can be submitted for the FortiNAC system or an equivalent NAC that covers all specifications above*
*Estimated BASE
CHA ITEM DESCRIPTION OR
Annual 3 YEAR TERM
SUGGESTED SYSTEM SERVICE DESCRIPTION
Quantities LINE ITEM
NAME/SKU
TOTAL
Suggested Professional Services -
Engineering services that install, configure,
Implementation, Integration, &
integrate, and operate across all CHA sites. Per Day Charge:
Configuration
Covers profiling setup, NAC policy development, _$_________
Per Day Charge
onboarding rules, segmentation, and pilot
Normal Business Hours
testing.
(8:00 AM CT - 5:00 PM CT) 12
Comment any addt'l details: *Base Year 1 Only*
PART NAME/SKU#
________________________________ (Total 12 Days)
________________________________
________________________________
________________________________
________________________________ _$_____________
________________________________
________________________________
________________________________
Per Day Charge:
_$_________
FortiNAC Resource Service Engineering services that install, configure,
Per Day Charge for Normal Business integrate, and operate across all CHA sites.
Hours (8:00 AM CT - 5:00 PM CT) Covers profiling setup, NAC policy development, 12
*Base Year 1 Only*
PART/SKU onboarding rules, segmentation, and pilot
(Total 12 Days)
#FP-10-PS001-830-01-01 testing.
_$_____________
Suggested Professional Services -
Engineering services that install, configure,
Implementation, Integration, & Per Day Charge:
integrate, and operate across all CHA sites.
Configuration _$_________
Covers profiling setup, NAC policy development,
Per Day Charge
onboarding rules, segmentation, and pilot
Overtime Hours
testing.
(5:00 PM CT - 6:00 AM CT) 3 *Base Year 1 Only*
Comment any addt'l details:
PART NAME/SKU# (Total 3 Days)
________________________________
________________________________
________________________________
________________________________ _$_____________
________________________________
________________________________
________________________________
________________________________
Per Day Charge:
FortiNAC Resource Service _$_________
Engineering services that install, configure,
Per Day Charge
integrate, and operate across all CHA sites.
Overtime Hours
Covers profiling setup, NAC policy development, 3
(5:00 PM CT - 6:00 AM CT) *Base Year 1 Only*
onboarding rules, segmentation, and pilot
PART/SKU (Total 3 Days)
testing.
#FP-10-PS001-830-01-01
_$_____________
Provides device visibility, automated access
Suggested NAC control, and policy enforcement across CHA's
Control/ Application Virtual Server entire network. Enables identification of all
System connected devices and blocks unauthorized
NAME & SKU: network access.
1 $_____________
________________________________ Comment any addt'l details:
________________________________ ________________________________
________________________________ ________________________________
________________________________ ________________________________
________________________________

FortiNAC Control and Application Extended next-gen VM Server PART/SKU #FNC-CAX-VM Provides device visibility, automated access control, and policy enforcement across CHA's entire network. Enables identification of all connected devices and blocks unauthorized network access. 1 $_____________
Suggested NAC Virtual Manager System NAME & SKU: ________________________________ ________________________________ ________________________________ ________________________________ Centralized management console used to administer all components. Supports multi-site oversight, reporting, policy configuration, and unified visibility. Comment any addt'l details: ________________________________ ________________________________ ________________________________ ________________________________ 1 $_____________
FortiNAC Manager Extended next-gen VM Server (Vmware or Hyper-V) PART/SKU #FNC-MX-VM Centralized management console used to administer all FortiNAC components. Supports multi-site oversight, reporting, policy configuration, and unified visibility. 1 $_____________
Suggested License Subscription and Qualifying Tier 11,000 concurrent endpoint devices NAME & SKU: ________________________________ ________________________________ ________________________________ ________________________________ Enables Support CHA's footprint of IoT, workstations, cameras, contractor devices, and guest devices. Provides profiling/endpoint visibility, dynamic VLAN steering, and compliance enforcement, Advanced Network Access Controls and automated provisioning for users, guests, and devices Comment any addt'l details: ________________________________ ________________________________ ________________________________ ________________________________ 11,000 Fee Per License: $_____________ Total Cost: $_____________
FortiNAC-Subscription PLUS License for concurrent endpoint devices. PART/SKU# #FC7-10-FNAC1-213-01-36 (10,000 licenses) #FC6-10-FNAC1-213-01-36 (1,000 licenses) Enables FortiNAC support of CHA's footprint of IoT, workstations, cameras, contractor devices, and guest devices. Provides profiling/endpoint visibility, dynamic VLAN steering, and compliance enforcement, Advanced Network Access Controls and automated provisioning for users, guests, and devices 11,000 Fee Per License: $_____________ Total Cost: $_____________
Suggested VM Technical Support Service and Qualifying Tier NAME & SKU: ________________________________ ________________________________ ________________________________ ________________________________ Provides support, updates, patches, and technical assistance for the Suggested Virtual Manager to ensure system reliability, security, and platform stability. Comment any addt'l details: ________________________________ ________________________________ ________________________________ ________________________________ 1 $_____________
FortiNAC Manager Extended VM FortiCare Premium Support PART/SKU #FC-10-FNVXM-248-02-36 Provides support, updates, patches, and technical assistance for the FortiNAC Manager VM to ensure system reliability, security, and platform stability. 1 $_____________

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
Provides device visibility, automated access
FortiNAC Control and Application
control, and policy enforcement across CHA's
Extended next-gen VM Server
entire network. Enables identification of all 1 $_____________
PART/SKU
connected devices and blocks unauthorized
#FNC-CAX-VM
network access.
Centralized management console used to
Suggested NAC Virtual Manager administer all components. Supports multi-site
System oversight, reporting, policy configuration, and
NAME & SKU: unified visibility.
________________________________ Comment any addt'l details: 1 $_____________
________________________________ ________________________________
________________________________ ________________________________
________________________________ ________________________________
________________________________
FortiNAC Manager Extended next-gen
Centralized management console used to
VM Server
administer all FortiNAC components. Supports
(Vmware or Hyper-V) 1 $_____________
multi-site oversight, reporting, policy
PART/SKU
configuration, and unified visibility.
#FNC-MX-VM
Enables Support CHA's footprint of IoT,
workstations, cameras, contractor devices, and
Suggested License Subscription and
guest devices. Provides profiling/endpoint
Qualifying Tier Fee Per License:
visibility, dynamic VLAN steering, and
11,000 concurrent endpoint devices
compliance enforcement, Advanced Network
NAME & SKU: $_____________
Access Controls and automated provisioning for
________________________________ 11,000
users, guests, and devices
________________________________ Total Cost:
Comment any addt'l details:
________________________________
________________________________
________________________________ $_____________
________________________________
________________________________
________________________________
FortiNAC-Subscription PLUS License
Enables FortiNAC support of CHA's footprint of Fee Per License:
for concurrent endpoint devices.
IoT, workstations, cameras, contractor devices,
PART/SKU#
and guest devices. Provides profiling/endpoint $_____________
#FC7-10-FNAC1-213-01-36
visibility, dynamic VLAN steering, and 11,000
(10,000 licenses)
compliance enforcement, Advanced Network Total Cost:
Access Controls and automated provisioning for
#FC6-10-FNAC1-213-01-36
users, guests, and devices $_____________
(1,000 licenses)
Provides support, updates, patches, and
Suggested VM Technical Support technical assistance for the Suggested Virtual
Service and Qualifying Tier Manager to ensure system reliability, security,
NAME & SKU: and platform stability.
________________________________ Comment any addt'l details: 1 $_____________
________________________________ ________________________________
________________________________ ________________________________
________________________________ ________________________________
________________________________
Provides support, updates, patches, and
FortiNAC Manager Extended VM
technical assistance for the FortiNAC Manager
FortiCare Premium Support
VM to ensure system reliability, security, and 1 $_____________
PART/SKU
platform stability.
#FC-10-FNVXM-248-02-36

Suggested Control/Application VM Technical Support Service and Qualifying Tier NAME & SKU: ________________________________ ________________________________ ________________________________ ________________________________ Ensures ongoing support and critical updates for the primary enforcement engine, maintaining accurate device discovery and security posture assessments. Comment any addt'l details: ________________________________ ________________________________ ________________________________ ________________________________ 1 $_____________
FortiNAC Control and Application Extended-VM FortiCare Premium Support PART/SKU #FC-10-FNVXA-248-02-36 Ensures ongoing support and critical updates for the primary enforcement engine, maintaining accurate device discovery and security posture assessments. 1 $_____________
3 Year $_____________
Contract
Aggregate
Total
DATE
CORPORATE AUTHORIZED
REPRESENTATIVE
CORPORATE OFFICIAL E -MAIL
ADDRESS
COMPANY PHONE NUMBER
COMPANY ADDRESS
CORPORATE AUTHORIZED
REPRESENTATIVE SIGNATURE

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
Ensures ongoing support and critical updates for
Suggested Control/Application VM
the primary enforcement engine, maintaining
Technical Support Service and
accurate device discovery and security posture
Qualifying Tier
assessments.
NAME & SKU:
Comment any addt'l details: 1 $_____________
________________________________
________________________________
________________________________
________________________________
________________________________
________________________________
________________________________
________________________________
FortiNAC Control and Application Ensures ongoing support and critical updates for
Extended-VM the primary enforcement engine, maintaining
FortiCare Premium Support accurate device discovery and security posture 1 $_____________
PART/SKU assessments.
#FC-10-FNVXA-248-02-36
3 Year
Contract
$_____________
Aggregate
Total
*CHA reserves the right to increase or delete any scheduled items, and/or increase or reduce the quantity of any
scheduled item as deemed necessary, to waive informalities and technicalities, and to make other changes and
modifications consistent with CHA's policies, and the laws and regulations governing HUD programs.
All Quote Responses Must Be Typed & Signed by an Authorized Representative from the Respondent's company.
PART 3 - VENDOR INFORMATION
_______________________
(ADD CORPORATE NAME ATTACHED TO FEDERAL TAX ID NUMBER ABOVE) has thoroughly read all pages
of ITS 90468_Network Access Control System (Virtual Appliance) Software and all associated addenda (if
applicable) and can provide the services as described at the offer submitted on this Quote Form.
CONTACT INFORMATION FOR CORPORATE OFFICIAL AUTHORIZED TO BIND RESPONDENT
DATE
CORPORATE AUTHORIZED
REPRESENTATIVE
CORPORATE OFFICIAL E -MAIL
ADDRESS
COMPANY PHONE NUMBER
COMPANY ADDRESS
CORPORATE AUTHORIZED
REPRESENTATIVE SIGNATURE
The successful Respondent(s) will be required to submit mandatory CHA forms and affidavits within five (5) days
of notice of award found at https://www.thecha.org/contracting-opportunities/forms-and-documents.

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
The mandatory forms will be requested from the successful respondents prior to contract award. Forms
should be completed, signed, and notarized where required or marked "not applicable" where
appropriate. The mandatory forms are:
* Utilization Plan**
* Compliance Certification Form
* Contractors Affidavit
* Economic Disclosure Statement Form
* HUD-50071 - Certification of Payments to Influence Federal Transactions
* HUD 5369-A Representations, Certifications and Other Statements of Bidders
* Required Insurance Certificate (see below Insurance Requirements)
Failure by the Respondent to provide such information within the allotted time will
render the Respondent ineligible for award.
CHA may reject any or all quotes. Action to reject all quotes shall be taken only for unreasonably high
prices, error in the solicitation, cessation of need, unavailability of funds, failure to secure adequate
competition, or any other reason deemed appropriate by CHA.
Insurance Requirements
Prior to the commencement of this Agreement, the Vendor shall procure and maintain at all times during
the term of this Agreement insurance against claims for bodily injury or property damage which may
arise from or in connection with services performed under this Agreement and from the negligent acts,
omissions and errors of the Vendor, its officers, agents, representatives or employees. The insurance
carriers used must be authorized to conduct business in the State of Illinois and shall have an A.M. Best
rating of not less than A: VII.
Contractor's insurance policies shall contain no exclusions for work performed under the Agreement for
Chicago Housing Authority or Low-Income Housing exposure. Policies must waive subrogation or any
other right of recovery Contractor or its insurer(s) may have against CHA because of payments made for
injuries or damages arising out of your ongoing operations of "your work" done under a contract with
CHA.
Minimum Coverage and Limit Requirements
1. Commercial General Liability: General Liability Insurance on an occurrence basis with limits not less than
$1,000,000 per occurrence with an aggregate of not less than $2,000,000 covering bodily injury and
property damage. This coverage shall also include, but not be limited to, contractual liability, products
and completed operations, personal and advertising injury.
2. Workers' Compensation and Employer's Liability: Coverage must be in accordance with the laws of the
State of Illinois and include a waiver of subrogation in favor of Chicago Housing Authority.
Coverage A - Statutory Limits
Coverage B - Employers Liability - $500,000 bodily injury or disease each accident; each
employee
3. Auto Liability: Required when any vehicles (owned, hired and/or non-owned) are used in connection
with the Services to be performed, coverage limits of not less than $1,000,000 per occurrence combined
single limit for Bodily Injury and Property Damage.
4. Professional Liability: Coverage is required when services are performed by licensed professionals
and/or Scope involves performing any financial, auditing, consulting, design, engineering, surveying,
testing, or other professional services. Professional Liability insurance appropriate to the Contractor's

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
profession shall provide coverage for the acts, errors, or omissions with a limit of not less than $1,000,000
per claim or occurrence. When policies are renewed or replaced, the policy retroactive date must
coincide with, or precede, the start of Services under the Agreement. A claims-made policy which is not
renewed or replaced must have an extended reporting period of two (2) years following termination of
Agreement.
5. Technology Errors & Omissions (including Cyber Liability): Required when Vendor/Consultant provides
technology services or technology products under this Agreement, insurance appropriate to the
professional services being performed shall provide coverage for the acts, errors, or omissions of
Vendor/Consultant with a limit of not less than $1,000,000 per occurrence or claim and $2,000,000 in
aggregate. Coverage shall be sufficiently broad to respond to the duties and obligations as is undertaken
by the Vendor in this agreement and shall include, but not be limited to, claims involving security breach,
system failure, data recovery, business interruption, cyber extortion, social engineering, infringement of
intellectual property, including but not limited to infringement of copyright, trademark, trade dress,
invasion of privacy violations, information theft, damage to or destruction of electronic information,
release of private information, and alteration of electronic information. The policy shall provide coverage
for breach response costs, regulatory fines and penalties as well as credit monitoring expenses.
Related Insurance Requirements
The Certificate of Insurance evidencing the minimum coverages required herein shall be in force on the
Effective Date of the Contract and continuously throughout the duration. The required documentation
must be received prior to the commencement of work under this Agreement.
It is understood and agreed to by the parties hereto that Chicago Housing Authority and others listed
below shall be included as Additional Insureds on Vendor's liability policies, with the exception of
Professional Liability and Employer's Liability and such insurance is primary to and will not seek
contribution from any insurance, deductibles, self-insured retentions and/or self-insured programs
available to Chicago Housing Authority.
Certificate Holder: Chicago Housing Authority
60 E Van Buren
Chicago, IL 60605
Additional Insureds: Collectively referred to as the "Additional Insureds" shall include Chicago
Housing Authority, Chicago Housing Administration, LLC; and/or other
Partnership, Limited Liability Company as established by CHA; its respective
commissioners, board members, officers, directors, agents, property
management firms, agents, employees, invitees and visitors.
Primary Coverage: For any claims related to this Agreement, the Vendor's insurance coverage shall
be the primary policy. The Vendor expressly understands and agrees that any
insurance or self-insurance programs maintained by the CHA shall apply in
excess of and shall not contribute with insurance provided by the Vendor.
Prior to the issuing of the Notice to Proceed by the CHA, the Vendor shall submit a Certificate of Insurance
via PINS Advantage Certificate Tracking System, evidencing compliance with the insurance requirements
set forth above. You will receive an email with instructions for the submission of your insurance. Copies
of the endorsement(s) adding the CHA to Vendor's policy as an additional insured are required upon
request. Updated Certificates of Insurance are required for policies which renew during the term of this
Agreement or extensions thereof. Under no circumstances shall the Vendor allow any required coverage
to lapse, cancel or non-renew throughout the duration of the Agreement or extensions thereof.

CHA ITS SP 90468_Network Access Control System (Virtual Appliance) (2026)
At the CHA's option, non-compliance will result in (1) all payments due the Vendor being withheld until
the Vendor has complied with the Agreement; or (2) the Vendor will be assessed Five Hundred Dollars
($500.00) for every day of non-compliance; or (3) the Vendor will be immediately removed from the
premises and the Agreement will be terminated for default. The receipt of any certificates does not
constitute agreement by the CHA that the insurance requirements in the Agreement have been fully met
or that the insurance policies indicated on the certificate comply with all Agreement requirements. The
insurance policies shall provide for thirty (30) days prior written notice to be given to the CHA in the
event coverage is substantially changed, canceled or non-renewed.
The Authority in no way warrants that the minimum limits contained herein are sufficient to protect the
Authority from liabilities that might arise out of the performance of the work under this Agreement by
the Vendor or its Subcontractors. The Vendor shall assess its own risks and, if it deems appropriate and/or
prudent, maintain higher limits and/or broader coverages. If the Vendor maintains broader coverage
and/or higher limits than the minimum requirements above, CHA and Additional Insured require and
shall be entitled to same. The Vendor is not relieved of any liability or other obligations assumed or
pursuant to the contract by reason of its failure to obtain or maintain sufficient insurance.
The Vendor shall require all subcontractors to carry the insurance required and adhere to the same
requirements and conditions as outlined above.
The Vendor expressly understands and agrees that any insurance or self-insurance programs maintained
by the CHA shall apply in excess of and will not contribute with insurance provided by the Vendor and/or
any of its subcontractors.
PART 4 - ADMINISTRATIVE TERMS AND CONDITIONS
* Required CHA Vendor Registration
In order to do business with CHA, Respondent must be a registered vendor prior to submitting a
response. If Respondent has already registered with CHA, the Respondent's (Vendor) profile must
be up to date. Respondent is responsible for contacting their local authorities to ensure that
Respondent has complied with all laws and is authorized and/or licensed to do business in the
Territory. All applicable fees associated therewith are the responsibility of Respondent now or
hereafter in effect during the contract. Respondent and its employees, agents and subcontractors
shall also comply with all Federal, State and local laws regarding business permits and licenses that
may be required to carry out the services performed under the contract.
* Acceptance Period
All Respondents submitting a quote must agree to honor the terms and conditions contained herein for
a period of one hundred twenty (120) days.
* Quote Signature
The person signing the Quote Form must be a person authorized to bind the Respondent
contractually. Unsigned offers will be rejected. Unsigned offers cannot be signed after the quote
has been received.
* Ownership of Documents
All work products generated, prepared, assembled and provided to CHA pursuant to this RFQ
become the property of CHA upon receipt. Work products include but are not limited to reports,
memoranda, data, survey responses, presentations, and other materials of any nature, or
information related to any of the foregoing, which are or were generated in connection with the
scope of services described in the contract. Respondents shall not copyright, or cause to be
copyrighted, any portion of any document submitted to CHA as a result of this SP.

This page summarizes the opportunity, including an overview and a preview of the attached documents.
Get Government Bids Like This by Email Receive daily bid alerts that match your keywords, business categories, and target regions.

See Also

Cisco Network Gear Start Date: 08/19/2026 9:07 AM Close Date: 09/14/2026 2:00 PM

Streamwood village

Due by 9/14/2026

Bid Solicitation # 27-466MIL-PROCU-B-53983 Bid Solicitation # 27-466MIL-PROCU-B-53983 Organization Name MIL - Military

State Government of Illinois

Due by 9/16/2026

Cisco Network Gear Start Date: 08/19/2026 Close Date: 09/14/2026 2:00 PM The Village

Streamwood village

Due by 9/14/2026

Bid Solicitation # 27-448DOIT-TELEC-B-53872 Bid Solicitation # 27-448DOIT-TELEC-B-53872 Organization Name DoIT - Department

State Government of Illinois

Due by 9/17/2026

* Disclaimer: This website provides information about bids, requests for proposals (RFPs), or requests for qualifications (RFQs) for convenience only and does not serve as an official public notice. Individuals who wish to respond to or inquire about bids, RFPs, or RFQs should contact the relevant government department directly.