DJ01--Zero Trust Application Realtime Protection (ZARP) (VA-25-00093376) 36C10B25Q0429
Summary
AI-generated · Aug 25, 2025Protect enterprise web applications, APIs, and related workloads with a turnkey Zero Trust Application Runtime Protection (ZARP) solution that covers VA’s hybrid environment (on‑premises, cloud, and VA cloud assets). The solution should provide end-to-end runtime protection for web apps, APIs, and backend services through Web Application and API Security (WAAS) and Cloud Workload Protection Platform (CWPP) capabilities, and support host-based, containerized, and serverless workloads across monolithic and microservice architectures. It must enforce runtime policy at Layer 7 for both external and internal traffic (North‑South and East‑West within a subnet/host), be compatible with FedRAMP Moderate or High, and integrate with SIEM/SOAR (Splunk acceptable), IAM, vulnerability management, and CI/CD tooling. The delivery must be turnkey, including implementation, documentation, training, and 24/7 monitoring/incident response, and support the Authority to Operate process. A Palo Alto Prisma Cloud Enterprise Edition or equivalent is preferred, with alternative solutions considered only if they clearly meet or exceed functionality, maturity, and federal standards.
New information from follow-up Q&A clarifies that the exact inventory of VA applications and workload counts will be provided to the selected vendor during post-award discovery; Splunk-only SIEM integration is sufficient, with on-prem, cloud, and hybrid Splunk ingestion supported. The solution must include WAAS and CWPP modules and be capable of Runtime Application Self-Protection (RASP). Network segmentation is addressed by separate VA controls; the RFI seeks a ROM, pricing structure, and contract approach, with the final contract vehicle to be determined based on responses. There is no existing ZARP solution today, and detailed workload/location counts and deployment specifics will be disclosed after award during onboarding.
DESCRIPTION Department of Veterans Affairs Request for Information (RFI) Zero Trust Application Runtime Protection (ZARP) This is a Request for Information (RFI) only. Do not submit a quote. This RFI is for planning purposes only and shall not be considered a Request for Quotation. Additionally, there is no obligation on the part of the Government to acquire any products or services described in this RFI. Your response to this RFI will be treated only as information for the Government to consider. You will not be entitled to payment for direct or indirect costs that you incur in responding to this RFI. This request does not constitute a solicitation for quotes or the authority to enter into negotiations to award a task order. No funds have been authorized, appropriated or received for this effort. The information provided may be used by the Department of Veterans Affairs (VA) in developing its acquisition strategy. Interested parties are responsible for adequately marking proprietary, restricted or competition sensitive information contained in their response. The Government does not intend to pay for the information submitted in response to this RFI. The Government requests Industry to review and provide commentary on the Governments requirement detailed below. The Government intends to review RFI responses to exchange information and improve industry s understanding of the Government requirement and the Government s understanding of industry capabilities. This will allow potential offerors to judge whether or how they can satisfy the Government s requirements and enhance the Government s ability to obtain quality supplies and services. SUBMITTAL INFORMATION: All responsible sources may submit a response in accordance with the below information. As part of your market research response, please provide a (10-page limit) submission detailing a solution that meets or exceeds the Government s requirement detailed below. Interested vendors shall provide constructive comments and/or feedback regarding the following elements of the proposed procurement: Proposed contract type: Firm Fixed Price Schedule: Base Year plus four (4) option years Industry to suggest a Contract Line-Item Number (CLIN)/Price Structure and deliverables. Industry to provide a Rough Order of Magnitude (ROM) to include level of effort, associated labor categories and estimated pricing Feasibility of the requirement, including performance requirements Industry to provide part numbers (if applicable). Any other industry concerns, comments, or questions Interested Vendors shall provide the following information in the initial paragraph of the submission: Name of Company Address Point of Contact Phone Number Email address Company Business Size and Status under the following North American Industry Classification System (NAICS) Code: 541519 Other Computer Related Services with a Size Standard of $34 Million. Existing Contractual Vehicles (GWAC, FSS, MAC, SEWP) to include the contract and schedule numbers. Socioeconomic data (For Veteran-Owned Small Business (VOSB) and Service-Disabled Veteran-Owned Small Business (SDVOSB)s, proof of verification in Small Business Administration (SBA) Veteran Small Business Certification (VetCert)) Indicate whether you can comply with the limitations on subcontracting at VA Acquisition Regulation (VAAR) 852.219-73, VA Notice of Total Set-Aside for Certified Service-Disabled Veteran-Owned Small Businesses or VAAR 852.219-74 VA Notice of Total Set-Aside for Certified Veteran-Owned Small Businesses System for Award Management Unique Identity Identification Number While not required, artifacts supporting your submission may be submitted to better demonstrate the above. The artifacts can be in addition to the page limit. There are no specific submission requirements other than the page limit, but the Government requests that it not be inundated with marketing materials or peripheral content, and that the submission be readable. CONTRACTOR RESPONSE: All Contractors shall submit via email to Michael Berberich, Contract Specialist at michael.berberich@va.gov and Contracting Officer Jason King at jason.king6@va.gov. Any/all questions from industry must be submitted by close of business (COB) on 7/11/25. The Government intends to have all questions answered and posted by COB on 7/14/25. Final responses are due no later than 12:00 PM ET, July 16, 2025. GOVERNMENT REQUIREMENT: Introduction / Background: The Department of Veterans Affairs (VA) is conducting market research to identify capable vendors that can deliver a comprehensive, turnkey solution for application and API runtime protection across VA's enterprise environments. This initiative, titled Zero Trust Application Runtime Protection (ZARP), supports the agency's cybersecurity modernization goals under Executive Order 14028 and the VA's Zero Trust Architecture Strategy. The ZARP initiative is focused on runtime protection for web applications, APIs, and associated workloads. It will prioritize VA mission critical systems to include support for both externally facing and non-web-based services. Purpose of this RFI This RFI seeks industry feedback and solution concepts from qualified vendors. The Government intends to use responses to: Validate technical feasibility and market availability Refine its acquisition strategy Determine industry capacity to meet ZARP objectives Identify best practices and potential innovations Scope of the ZARP Solution This solution must be delivered as a total turnkey implementation, meaning the contractor shall be responsible for all components and phases of delivery without reliance on VA-led development or integration efforts. The VA seeks a commercial off the shelf (COTS) solution that provides end-to-end protection for web applications, APIs, and critical backend services across VA s hybrid environments. VA is interested in Palo Alto s Prisma Cloud Enterprise Edition or similar. Vendors are encouraged to propose alternative or equivalent solutions if they can clearly demonstrate equal or superior functionality, integration maturity, and compliance with federal standards. Salient Characteristics Respondents should confirm their solution supports or addresses the following key characteristics: Turnkey Delivery Model Implementation and integration Solution process design and configuration Documentation and training Operational support (including 24/7 monitoring and incident response) Supporting the Authority to Operate (ATO) process Runtime Protection Scope Coverage of cloud-native, web-facing and non-web workloads (e.g., internal APIs, headless services) Support for host-based, container, and serverless applications Support for monolithic, microservice, containerized, and serverless architectures Capable of protecting on-prem or VA Enterprise Cloud (VAEC) environments Platform Capabilities Web Application and API Security (WAAS) Cloud Workload Protection Platform (CWPP) Compute Defender or equivalent functionality Runtime policy enforcement, threat detection, and virtual patching Compliance FedRAMP-authorized (Moderate or High) for SaaS Applicable legislation (e.g. FISMA, NIST 800-53 and CISA directives) Tool Integration Support SIEM (Splunk, Elastic) SOAR platforms Identity and Access Management systems Vulnerability Management and CI/CD pipelines Measurable Outcomes Reduction in successful exploits and faster Mean time to detect (MTTD) / Mean time to respond (MTTR) Capable of achieving a true-positive detection rate of at least 98% and cross-over error rate of no more than 2%, as measured against independent OWASP Benchmarks or equivalent tests Requested Information from Respondents Vendors are encouraged to provide the following: A description of their proposed solution, including people processes and technologies A response matrix mapping their solution to each of the salient characteristics Details of past performance with similar enterprise security deployments, especially within federal environments Licensing models and scalability options Key differentiators or innovations Any anticipated deployment challenges and mitigation strategies Any recommended additions, corrections, or clarifications to the scope or requirements described in this RFI
From Sources Sought posted on Jul 08, 2025QUESTION: Can you list the number of applications and break out how they are hosted? Interested in the number of container nodes, VMs, Serverless functions, etc. ANSWER: VA does not publish its application inventory at the market-research (RFI) stage. The exact number of applications and their hosting breakdown across on-premises data centers, VA Enterprise Cloud (AWS GovCloud US & Azure Government), and other environments will be provided to the selected vendor during post-award discovery and onboarding. QUESTION: Could the Government clarify whether Elastic SIEM integration is a requirement or if Splunk-only integration would be sufficient? ANSWER: Splunk-only Integration is sufficient QUESTION: Are there specific Splunk configurations or deployment models (cloud, on-premises, or hybrid) that the solution must support? ANSWER: The ZARP solution must cleanly support on-prem, cloud, and hybrid Splunk ingestion. QUESTION: Do you require SPUNK pricing in the ROM? ANSWER: No QUESTION: SOAR Platforms (Swimlane): Are there particular Swimlane integrations or workflows that the solution should accommodate to align with VA s current SOAR environment? ANSWER: At this stage we are not releasing VA-specific Swimlane playbooks or connector details. QUESTION: Which IAM systems are deployed within VA (e.g., Microsoft Azure AD, Okta, Ping Identity), and are there specific protocols (SAML, OAuth, OpenID Connect) required for integration? ANSWER: The VA uses multiple IAM services in a hybrid on-prem / cloud environment. More details will be furnished to the selected vendor during post-award discovery and onboarding. QUESTION: Given the use of Tenable for vulnerability management, are there specific integration requirements or use cases VA expects? Additionally, could VA identify CI/CD platforms in use (e.g., Jenkins, GitLab, Azure DevOps) that the solution should integrate with? ANSWER: VA uses several CI/CD pipelines. Pipeline details are sensitive and will be shared only with the awardee under post-award security procedures. QUESTION: To provide a meaningful Rough Order of Magnitude (ROM) for the ZARP RFI, could the government provide approximate counts of workloads (VMs, containers, serverless functions) and anticipated data ingestion volumes for SIEM/SOAR integration? ANSWER: The requested information is not available QUESTION: Please clarify which Prisma Cloud modules (e.g., WAAS, CWPP, CSPM) VA expects vendors to include. ANSWER: WAAS & CWPP QUESTION: For scoping the number of VA workloads, how many on-premise container hosts will the solution need to support? ANSWER: The requested information is not available QUESTION: For scoping the number of VA workloads, how many K8 worker nodes will the solution need to support? ANSWER: The requested information is not available QUESTION: For scoping the number of VA workloads, how many serverless containers (AWS-Fargate / Azure ACI) will the solution need to support? ANSWER: The requested information is not available QUESTION: Can the VA confirm the solution must be capable of Runtime Application Self Protection (RASP)? ANSWER: Yes, the solutions must be capable of Runtime Application Self Protection QUESTION: Will the proposed zero trust solution require traffic visibility and enforcement aspects of ZTS Zero Trust Segmentation (or micro-segmentation), or will it be primarily based on North-South subnet-based enforcement? ANSWER: This RFI covers runtime-application and workload protection (ZARP). Network-level Zero Trust Segmentation (micro-segmentation) is handled by separate VA controls. The solution must inspect and enforce at Layer 7 for both North-South traffic (ingress/egress) and East-West traffic that remains within a subnet or host. Detailed integration points with VA s ZTS environment will be defined during post-award discovery. QUESTION: What is the scope of number of locations, workloads, applications as part of this solicitation or any other details you can provide that would be helpful for vendors? ANSWER: This information is not available QUESTION: Is the request for this new solution replacing existing technology and what is the existing solution today? ANSWER: There is no existing solution QUESTION: Is the VA using any segmentation solutions today within this environment and what is the technology being used? ANSWER: The specific vendors, products, and policy schemas are considered sensitive architecture details and will be disclosed only to the awardee under post-award security procedures. QUESTION: What GWACs is the VA currently considering for this procurement? Is GSA VETS 2 being considered? ANSWER: To be determined. The contract vehicle will be determined based on the responses received from the RFI. Please provide any existing contract vehicles per RFI Submittal Information paragraph 3(g).
From Sources Sought posted on Jul 14, 2025Department of Veterans Affairs Request for Information (RFI) Zero Trust Application Runtime Protection (ZARP) This is a RFI Loopback only. DO NOT SUBMIT A QUOTE OR A RESPONSE. This notice is posted as an amendment to the original RFI issued on 7/8/2025, for the purpose of informing industry of the outcome of the subject requirement. No response is required or requested; this posting is a notice to industry only. The solicitation for the subject requirement was released on NASA SEWP under 36C10B25Q0516 as an SDVOSB set-aside on 8/21/2025.
From Sources Sought posted on Sep 16, 2025Notice history
3-
-
Sources Sought LATEST Posted Sep 16, 2025View changes (3)
- Description: Description was updated
- Response Deadline: Jul 16, 2025 → Sep 30, 2025
- Set-Aside: None → Service-Disabled Veteran-Owned Small Business Set Aside
Details
Award Information
Contacts
Contract Specialist