| Location: | North Carolina |
|---|---|
| Posted: | Apr 21, 2026 |
| Due: | May 1, 2026 |
| Agency: | State Government of North Carolina |
| Type of Government: | State & Local |
| Category: |
|
| Solicitation No: | Doc2154121710 |
| Publication URL: | To access bid details, please log in. |
| Solicitation Number: | Doc2154121710 |
| Project Title: | IFB 30-26288-ITD ORDR Internet of Medical Things (IoMT) monitoring solution |
| Description: | The purpose of this Solicitation is to obtain pricing for and procure the ORDR Internet of Medical Things (IoMT) monitoring solution for the NC DHHS Privacy and Security Office. |
| Opening Date: | 5/1/2026 3:00 PM |
| Posted Date: | 4/22/2026 |
| Status: | Open |
| Department: | DEPARTMENT OF HEALTH AND HUMAN SERVICES - DHHS |
|
Solicitation Number
*
Doc2154121710
|
Department
DEPARTMENT OF HEALTH AND HUMAN SERVICES - DHHS
|
Status Reason
Open
|
|
|
Opening Date
2026-05-01T15:00:00.0000000
|
Posted Date
*
2026-04-21T19:30:25.0000000Z
|
Primary Commodity Code
Software maintenance and support
|
|
|
Mandatory Conference/Site Visit
—
—
|
Special Instructions
—
|
Solicitation Type
*
Select RFP IFB RFI
|
|
|
Owner
Angela Childress
|
|||
|
Description
The purpose of this Solicitation is to obtain pricing for and procure the ORDR Internet of Medical Things (IoMT) monitoring solution for the NC DHHS Privacy and Security Office.
|
|||
| STATE OF NORTH CAROLINA DEPARTMENT OF HEALTH AND HUMAN SERVICES Information Technology Division | INVITATION FOR BIDS NO. 30-26288-ITD |
|---|---|
| Offers will be publicly opened: May 1, 2026, promptly at 02:00 PM ET (Attendance is Optional) Microsoft Teams meeting Join: https://teams.microsoft.com/meet/2520713134227?p =2lEUeR6dXfnw8KdRGA Meeting ID: 252 071 313 422 7 Passcode: zs9ZH9MH | |
| Need help? | System reference Dial in by phone +1 984-204-1487,,969773625# United States, Raleigh Find a local number Phone conference ID: 969 773 625# Join on a video conferencing device Tenant key: ncgov@m.webex.com Video ID: 116 518 164 6 More info For organizers: Meeting options | Reset dial-in PIN | |
| Issue Date: April 21, 2026 | |
| Refer ALL inquiries regarding this IFB to: Angela Childress Angela.Childress@dhhs.nc.gov | Commodity Number: 811122 |
| Description: ORDR Internet of Medical Things Monitoring Tools | |
| Using Agency: Privacy and Security Office (PSO) | |
| See page 4 for offer submittal instructions. | Requisition No.: RQ271171 |
STATE OF NORTH CAROLINA INVITATION FOR BIDS NO. 30-26288-ITD
DEPARTMENT OF HEALTH AND HUMAN
Offers will be publicly opened:
SERVICES
May 1, 2026, promptly at 02:00 PM ET
Information Technology Division
(Attendance is Optional)
Microsoft Teams meeting
Join:
https://teams.microsoft.com/meet/2520713134227?p
=2lEUeR6dXfnw8KdRGA
Meeting ID: 252 071 313 422 7
Passcode: zs9ZH9MH
Need help? | System reference
Dial in by phone
+1 984-204-1487,,969773625# United States, Raleigh
Find a local number
Phone conference ID: 969 773 625#
Join on a video conferencing device
Tenant key: ncgov@m.webex.com
Video ID: 116 518 164 6
More info
For organizers: Meeting options | Reset dial-in PIN
Issue Date: April 21, 2026
Refer ALL inquiries regarding this IFB to: Commodity Number: 811122
Angela Childress
Description: ORDR Internet of Medical Things
Angela.Childress@dhhs.nc.gov Monitoring Tools
Using Agency: Privacy and Security Office (PSO)
See page 4 for offer submittal instructions. Requisition No.: RQ271171
OFFER AND ACCEPTANCE
The State seeks offers for the software and software support described in this solicitation. The State's
acceptance of any offer must be demonstrated by execution of the acceptance found below and any subsequent
Request for Best and Final Offer, if issued. Acceptance shall create a contract having an order of precedence
as follows: In cases of conflict between documents comprising the contract, the order of precedence shall be (1)
Best and Final Offers, if any, (2) special terms and conditions specific to this solicitation, (3) specifications, (4)
Department of Information Technology Terms and Conditions of this solicitation, and (5) the agreed portions of
the awarded Vendor's offer. No contract shall be binding on the State until an encumbrance of funds has
been made for payment of the sums due under the contract.
| OFFEROR: | |||
|---|---|---|---|
| STREET ADDRESS: | P.O. BOX: | ZIP: | |
| CITY, STATE & ZIP: | TELEPHONE NUMBER: | TOLL FREE TEL. NO | |
| PRINT NAME & TITLE OF PERSON SIGNING: | FAX NUMBER: | ||
| AUTHORIZED SIGNATURE: | DATE: | E-MAIL: |
IFB Number: 30-26288-ITD
EXECUTION
In compliance with this solicitation and subject to all the conditions herein, the undersigned offers and agrees to
furnish any or all Services or goods upon which prices are offered, at the price(s) offered herein, within the time
specified herein. By executing this offer, I certify that this offer is submitted competitively and without collusion.
Failure to execute/sign offer prior to submittal shall render offer invalid. Late offers are not acceptable.
OFFEROR:
STREET ADDRESS: P.O. BOX: ZIP:
CITY, STATE & ZIP: TELEPHONE NUMBER: TOLL FREE TEL.
NO
PRINT NAME & TITLE OF PERSON SIGNING: FAX NUMBER:
AUTHORIZED SIGNATURE: DATE: E-MAIL:
Offer valid for ninety (90) days from date of offer opening unless otherwise stated here: ____ days
ACCEPTANCE OF OFFER
If any or all parts of this solicitation are accepted, an authorized representative of DHHS shall affix their signature
hereto. A copy of this acceptance will be forwarded to the successful vendor(s).
FOR STATE USE ONLY
Offer accepted and contract awarded _____________________________________, as indicated on attached certification,
by _____________________________________________ (Authorized representative of DHHS).
Page 2 of 29 January 30, 2026
IFB Number: 30-26288-ITD
TABLE OF CONTENTS
1.0 INTENT, USE, DURATION AND SCOPE .............................................................................................. 4
2.0 GENERAL INFORMATION .................................................................................................................... 4
2.1. OFFER SUBMITTAL ............................................................................................................................... 4
2.2. BASIS FOR REJECTION ........................................................................................................................ 5
2.3. LATE OFFERS ....................................................................................................................................... 5
2.4. NON-RESPONSIVE OFFERS ................................................................................................................ 5
2.5. NOTICE TO VENDOR(S) ........................................................................................................................ 5
2.6. E-PROCUREMENT SOLICITATION ....................................................................................................... 5
2.7. DISTRIBUTORS AND RESELLERS ....................................................................................................... 6
2.8. POSSESSION AND REVIEW ................................................................................................................ 6
2.9. BEST AND FINAL OFFERS (BAFO) ...................................................................................................... 6
2.10. AWARD ................................................................................................................................................ 7
2.11. POINTS OF CONTACT ......................................................................................................................... 7
3.0 SPECIFICATIONS ................................................................................................................................. 7
3.1. VENDOR STANDARD AGREEMENT(S) ................................................................................................ 7
3.2. VENDOR UTILIZATION OF WORKERS OUTSIDE U.S. - DISCLOSURE STATEMENT ....................... 7
3.3. E-VERIFY ............................................................................................................................................... 8
3.4 BRAND SPECIFIC PRODUCT ................................................................................................................. 9
3.5. SECURITY SPECIFICATIONS ............................................................................................................... 9
3.6 ENTERPRISE ARCHITECTURE SPECIFICATIONS ............................................................................. 11
3.7 SPECIFICATIONS ................................................................................................................................. 12
3.8. DELIVERY ............................................................................................................................................ 12
3.9. CONTRACT TERM ............................................................................................................................... 13
4.0 FURNISH AND DELIVER .................................................................................................................... 13
5.0 HISTORICALLY UNDERUTILIZED BUSINESSES .............................................................................. 14
6.0 DEPARTMENT OF INFORMATION TECHNOLOGY INSTRUCTIONS TO VENDORS ....................... 15
7.0 GENERAL TERMS AND CONDITIONS APPLICABLE TO SOFTWARE AS A SERVICE (SAAS) ....... 16
Page 3 of 29 January 30, 2026
IFB Number: 30-26288-ITD
1.0 INTENT, USE, DURATION AND SCOPE
The purpose of this Solicitation is to obtain pricing for and procure the ORDR Internet of Medical Things
(IoMT) monitoring solution for the NC DHHS Privacy and Security Office. Goods and Services will be
provided in accordance to the terms and conditions of this Solicitation.
2.0 GENERAL INFORMATION
2.1. OFFER SUBMITTAL
Due Date: Friday, May 1, 2026
Time: Prior to bid opening at 02:00 PM ET
IMPORTANT NOTE: It is the Vendor's sole responsibility to upload their offer to the Ariba
Sourcing Module by the specified time and date of opening. Vendor shall bear the risk for late
electronic submission due to unintended or unanticipated delay, including but not limited to internet
issues, network issues, local power outages, or application issues. Vendor must include all the
pages of this solicitation in their response. Vendor must include the Execution page signed and
dated by an official authorized to bind the Vendor's firm. Failure to return a signed offer shall result
in disqualification.
Attempts to submit a proposal via facsimile (FAX) machine, telephone, email, email
attachments, or in any hardcopy format in response to this Bid SHALL NOT be accepted
and will automatically be deemed Non-Responsive.
a) All File names should start with the Vendor name first, in order to easily determine all the files
to be included as part of the vendor's response. For example, files should be named as follows:
Vendor Name-your file name.
b) File contents SHALL NOT be password protected, the file formats must be in .PDF, .JPEG,
.DOC or .XLS format, and shall be capable of being copied to other sources. Inability by the
State to open the Vendor's files may result in the Vendor's offer(s) being rejected as Non-
Responsive.
c) If the vendor's proposal contains any confidential information (as defined in Attachment B,
Section 2, Paragraph #17), then the vendor must provide one (1) signed, original electronic
offer and one (1) redacted electronic copy.
Questions or issues related to using the Ariba Sourcing Tool itself can be directed to the North
Carolina eProcurement Help Desk at 888-211-7440, Option 2. Help Desk representatives are
available Monday through Friday from 7:30 AM EST to 5:00 PM EST.
Tips for Using the Sourcing Tool
1. Vendors should review available training and confirm that they are able to access the Sourcing
Event, enter responses, and upload files well in advance of the date and time response are due to
allow sufficient time to seek assistance from the North Carolina eProcurement Help Desk.
2. Vendors may submit their responses early to make sure there are no issues and then submit a
revised response any time prior to the response due date and time. The State will only review the
most recent response.
3. Vendors should respond to all relevant sections of the Sourcing Event. Certain questions or
items are required in order to submit a response and are denoted with an asterisk. The Sourcing
Tool will not allow a response to be submitted unless all required items are completed. The
Sourcing Tool will provide error messages to help identify any required information that is missing
when response is submitted.
Page 4 of 29 January 30, 2026
IFB Number: 30-26288-ITD
4. Simply saving your response in the Sourcing Tool is not the same as submitting your response
to the State. Vendors should make sure they complete the submission process and receive a
message that their response was successfully submitted.
5. Only Bids submitted through the Content Section of the Ariba Sourcing Event will be
considered. Bids submitted through the Message Board will not be accepted or considered for
award.
2.2. BASIS FOR REJECTION
Pursuant to 9 NCAC 06B.0401, the State reserves the right to reject any and all offers, in whole or
in part; by deeming the offer unsatisfactory as to quality or quantity, delivery, price or service offered;
non-compliance with the specifications or intent of this solicitation; lack of competitiveness; error(s)
in specifications or indications that revision would be advantageous to the State; cancellation or
other changes in the intended project, or other determination that the proposed requirement is no
longer needed; limitation or lack of available funds; circumstances that prevent determination of the
best offer; or any other determination that rejection would be in the best interest of the State. Vendor
contact regarding this IFB with anyone other than Angela Childress may be grounds for rejection
of said Vendor's offer.
2.3. LATE OFFERS
Regardless of cause, late offers will not be accepted and will automatically be disqualified from
further consideration. It shall be the Vendor's sole risk to ensure submission of offer by the
designated time.
2.4. NON-RESPONSIVE OFFERS
Vendor offers will be deemed non-responsive by the State and will be rejected without further
consideration or evaluation if statements such as the following are included:
* "This offer does not constitute a binding offer",
* "This offer will be valid only if this offer is selected as a finalist or in the competitive range",
* "Vendor does not commit or bind itself to any terms and conditions by this submission",
* "This document and all associated documents are non-binding and shall be used for discussion
purposes only",
* "This offer will not be binding on either party until incorporated in a definitive agreement signed
by authorized representatives of both parties", or
* A statement of similar intent.
2.5. NOTICE TO VENDOR(S)
The State objects to and will not be required to evaluate or consider any additional terms and
conditions not previously agreed to by the State and submitted with an Offeror's response.
This applies to any language appearing in or attached to the document as part of the Offeror's
response. By execution and delivery of this IFB and response(s), the Offeror agrees that any
additional terms and conditions, whether submitted purposely or inadvertently, shall have no
force or effect.
2.6. E-PROCUREMENT SOLICITATION
This is an E-Procurement solicitation. See Paragraph #31 of the attached Department of
Information Technology Terms and Conditions.
a) General information on the E-Procurement service can be found at http://eprocurement.nc.gov/
b) Within two days after notification of award of a contract, vendor must register in NC E-
Procurement @ Your Service at the following web site: https://vendor.ncgov.com/vendor/login
Page 5 of 29 January 30, 2026
| YES | NO |
|---|
IFB Number: 30-26288-ITD
c) As of the IFB submittal date, the Vendor must be current on all E-Procurement fees. If the Vendor
is not current on all E-Procurement fees, the State may disqualify the Vendor from participation
in this IFB.
2.7. DISTRIBUTORS AND RESELLERS
"Resellers" as used herein, refers to businesses that routinely sell or distribute Vendor's Products,
and may include "Distributors", "Value Added Resellers" (VARs), "Original Equipment
Manufacturers" (OEMs), Channel Partners, or such other designations. These businesses must be
approved by the State prior to placement of any orders. Any contract established will be subject to
this solicitation and any resulting Agreement(s), and to the terms and conditions of the State's
competitive bidding process.
The Agency acknowledges that the Reseller has merely purchased the Third-Party Items for resale
or license to the Agency, and that the proprietary and intellectual property rights to the Third-Party
Items are owned by parties other than the Reseller ("Third Parties"). The Agency further
acknowledges that except for the payment to the Reseller for the Third-Party Items, all of its rights
and obligations with respect thereto flow from and to the Third Parties. The Reseller shall provide
the Agency with copies of all documentation and warranties for the Third-Party Items which are
provided to the Reseller. The Reseller shall assign all applicable third-party warranties for
Deliverables to the Agency.
Is the Vendor an authorized ORDR Internet of Medical Things reseller for the products as
listed in Section 4.0 Furnish and Deliver? YES NO
If yes, the State may request an authorized reseller letter. If requested, the Vendor must provide a
copy of the authorized reseller letter from the OEM within seven (7) calendar days of request.
Failure to provide the authorized reseller letter within the stated timeframe may result in rejection of
the bid, at the discretion of the State. Bids from Vendors that are not authorized to resell the
products or services in this IFB may be rejected at the discretion of the State.
2.8. POSSESSION AND REVIEW
During the evaluation period and prior to award, possession of the bids and accompanying
information is limited to personnel of the issuing agency, and to the committee responsible for
participating in the evaluation. Vendors who attempt to gain this privileged information, or to
influence the evaluation process (i.e. assist in evaluation) will be in violation of purchasing rules and
their offer will not be further evaluated or considered.
After award of contract the complete bid file will be available to any interested persons with the
exception of trade secrets, test information or similar proprietary information as provided by statute
and rule. Any proprietary or confidential information which conforms to exclusions from public
records as provided by N.C.G.S. 132-1.2 must be clearly marked as such in the offer when
submitted.
2.9. BEST AND FINAL OFFERS (BAFO)
The State may establish a competitive range based upon evaluations of offers, and request BAFOs
from the Vendor(s) within this range, e.g. "Finalist Vendor(s)". If negotiations or subsequent offers
are solicited, the Vendor(s) shall provide BAFO(s) in response. Failure to deliver a BAFO when
requested shall disqualify the non-responsive Vendor from further consideration. The State will
evaluate BAFO(s), oral presentations, and product demonstrations as part of the Vendors'
respective offers to determine the final rankings.
Page 6 of 29 January 30, 2026
| Vendor Contractual Point of Contact | Vendor Technical Point of Contact |
|---|---|
| Name of Vendor: Street: City, State, Zip: Attn: Email: | Name of Vendor: Street: City, State, Zip: Attn: Email: |
IFB Number: 30-26288-ITD
2.10. AWARD
It is the general intent to award this contract to one (1) Vendor. As provided by statute, award will
be based on Best Value Analysis, Lowest Price Technically Acceptable Source Selection Method
in accordance with 09 NCAC 06B. 0302 Information Technology Procurement.
2.11. POINTS OF CONTACT
Contact by the Offeror with the persons shown below for contractual and technical matters related
to this IFB is only permitted if expressly agreed to by the purchasing lead named on page 5, or upon
award of contract:
For Vendor completion:
Vendor Contractual Point of Contact Vendor Technical Point of Contact
Name of Vendor: Name of Vendor:
Street: Street:
City, State, Zip: City, State, Zip:
Attn: Attn:
Email: Email:
3.0 SPECIFICATIONS
3.1. VENDOR STANDARD AGREEMENT(S)
The terms and conditions of Vendor's standard license, maintenance or other agreement(s)
applicable to Software and other Products acquired under this Agreement may apply to the extent
such terms and conditions do not materially change the terms and conditions of this Agreement. In
the event of any conflict between the terms and conditions of this Agreement and the Vendor's
standard agreement(s), the terms and conditions of this Agreement relating to audit and records,
jurisdiction, choice of law, the State's electronic procurement application of law or administrative
rules, the remedy for intellectual property infringement and the exclusive remedies and limitation of
liability in the Terms and Conditions herein shall apply in all cases and supersede any provisions
contained in Vendor's relevant standard agreement or any other agreement. The State shall not be
obligated under any standard license and/or maintenance or other Vendor agreement(s) to indemnify
or hold harmless the Vendor, its licensors, successors or assigns; nor arbitrate any dispute, nor pay
late fees, legal fees or other similar costs.
A license agreement for the ORDR Internet of Medical Things monitoring solution by and between
ORDR, Inc. and DHHS may be applicable to this IFB. A fully executed copy of the updated license
agreement shall be incorporated by reference and attached to the final version of this IFB via a Best
and Final Offer - BAFO.
3.2. VENDOR UTILIZATION OF WORKERS OUTSIDE U.S. - DISCLOSURE STATEMENT
In accordance with the Statewide Information Security Manual (SISM), the State restricts the
location of information systems that receive, process, store, or transmit State and Federal data to
the United States which includes the following areas: US States, US Territories, US Embassies,
and US Military installations (stateside or overseas). This restriction applies to the Vendor and to
any subcontractors engaged to provide Services under this Agreement or with access to State Data.
Page 7 of 29 January 30, 2026
| YES | NO |
|---|
| YES | NO |
|---|
| YES | NO |
|---|
IFB Number: 30-26288-ITD
The Vendor must ensure that its subcontractor agreements contain the same restrictions and will
be responsible for monitoring and enforcing subcontractor compliance at all times.
Pursuant to N.C.G.S. 143B-1361(b), the Vendor must complete and return this Disclosure
Statement Attachment F with its solicitation response. The Vendor may attach additional pages to
its response if needed. The State of North Carolina will evaluate Disclosure Statement Attachments
for additional risks, costs, and other factors associated with its service prior to making an award for
any such Vendor's offer. The Vendor must provide the following information in its bid response:
Vendor to complete a.-e. in their offer:
a. The location of work performed under a state contract by the Vendor, any subcontractors,
employees, or other persons performing the contract and whether any of this work will be
performed outside the United States.
Vendor to enter text here to answer this disclosure question:
b. The corporate structure and location of corporate employees and activities of the Vendor, its
affiliates or any other subcontractors.
Vendor to enter text here to answer this disclosure question:
c. Vendor agrees to provide notice of the relocation of the Vendor, employees of the Vendor,
subcontractors of the Vendor, or other persons performing Services under a state contract
outside of the United States in the event such relocation occurs during the contract term.
Does Vendor agree to provide notice as defined above? YES NO
d. Vendor agrees that any Vendor or subcontractor providing call or contact center Services to
the State of North Carolina shall disclose to inbound callers the location from which the call or
contact center Services are being provided.
Does Vendor agree to provide disclosure as defined above? YES NO
e. Will any work under this contract be performed outside the United States? YES NO
The use of resources or workers located outside the United States is a critical security exception
that must be escalated to the State Chief Information Officer for review pursuant to N.C.G.S. 143B-
1376(c) and 143B-1320(c). These critical security exceptions are approved only in rare and
extenuating circumstances. Vendor should account for this when preparing its response.
______________________________________________________________________________
3.3. E-VERIFY
Pursuant to N.C.G.S. 143B-1350(k), the State shall not enter into a contract unless the awarded
Vendor and each of its subcontractors comply with the E-Verify requirements of N.C.G.S. Chapter
64, Article 2. Vendors are directed to review the foregoing laws. Any awarded Vendor must submit
a certification of compliance with E-Verify to the awarding agency, and on a periodic basis thereafter
as may be required by the State.
Page 8 of 29 January 30, 2026
IFB Number: 30-26288-ITD
3.4 BRAND SPECIFIC PRODUCT
Manufacturer(s) name and product descriptions used in this solicitation are product specific. The
items offered in response to this solicitation must be the manufacturer and type specified. Failure to
comply with this requirement will result in rejection of offer.
3.5. SECURITY SPECIFICATIONS
3.5.1 SOLUTIONS NOT HOSTED ON STATE INFRASTRUCTURE
The Agency (named on page one (1)) has designated this solicitation to receive and securely manage
data that is classified as:
Agency has selected:
Restricted - Restricted data represents the highest risk to the State, State Agencies, and
constituents if it is disclosed or compromised. This information is likely to be regulated by State
or Federal law, and access to it is restricted to a limited audience (e.g., State and Federal Tax
Information [FTI], Payment Card data, Protected Health Information [PHI], Criminal Justice
Information [CJI], Social Security Administration provided information, etc.)
Confidential - Includes information that is limited to a small audience with a need-to-know or
legitimate business case (e.g., State employee personnel records, trade secrets, student records,
sensitive public security information, etc.). If exposed to unauthorized parties, data from this
category will cause high impact consequences such as regulatory fines, inability to recruit talent,
loss of confidence, and/or damage to vendor relationships. This is not a complete list and is
subject to legislative changes.
Internal - This is information typically used within the agency and not for public sharing. Most
documents are classified as Internal within the organization, and most State employees would
have access. This type of data, if exposed to unauthorized parties, would have a very limited
impact on an agency's reputation, compliance requirements or ability to achieve strategic goals.
Internally classified data does not contain direct identifiers. Often, the effects of the loss of data
can be recognized in very subtle ways and may not lead to clear negative consequences causing
confusion due to lack of context or minor reputational harm.
Public - Data that is open to public inspection according to state and federal law, or readily
available through public sources.
Refer to the North Carolina Statewide Data Classification and Handling policy for more information
regarding data classification. The policy is located at the following website:
https://it.nc.gov/document/statewide-data-classification-and-handling-policy.
To comply with the State's Security Standards and Policies, State agencies are required to perform
annual security/risk assessments on their information systems using NIST 800-53 controls.
This requirement additionally applies to all Vendor-provided, agency-managed Infrastructure as a
Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) solutions which will
handle data classified as Internal, Confidential, or Restricted.
For Vendor Completion:
(a) To comply with the State's Security Standards and Policies, cloud products
are required to comply with applicable FedRAMP or GovRAMP security requirements,
Page 9 of 29 January 30, 2026
IFB Number: 30-26288-ITD
including but not limited to, continuous monitoring, incident response, and data classification
as outlined in GovRAMP documentation.
(b) To streamline and standardize this requirement the State has adopted GovRAMP which is
a Risk and Authorization Management Program that provides a standardized approach to
security assessment, authorization, and continuous monitoring for cloud products and
services. GovRAMP's security verification model is based on NIST 800-53 Rev. 5 (or
current).
(c) (NCDIT to determine required GovRAMP verified status for each solicitation based on data
classification type as defined in the North Carolina Statewide Information Security Manual
and North Carolina Statewide Data Classification and Handling
Policy.) The required GovRAMP verified status will depend on the sensitivity of the data and
processes supported by the solution as defined in the Statewide Data Classification and
Handling Policy.
(d) For purposes of this solicitation, in accordance with the North Carolina Department of
Information Technology Statewide Information Security Manual, a GovRAMP verified status
of [X] is required. At offer submission, if the protected system does not currently hold a
validated GovRAMP status, the Vendor will be required to provide their GovRAMP Security
Snapshot Score and upon request, the complete Snapshot Matrix. If awarded the contract,
Vendor shall have an interim period from the effective date of the contract to
achieve the verified GovRAMP status outlined above. The interim time periods for each
data classification that requires a verified status are further described below. The Vendor
shall provision access to the State to their continuous monitoring packages at a [standard]
or [elevated] access level within fourteen (14) days of contract award, and seven (7) days
of any subsequent GovRAMP status changes. If a non-disclosure agreement (NDA) is
required by the Vendor, a copy of the NDA must be uploaded with the response and
executed by the Vendor and the State at the time of contract award.
a. Public - For third-party cloud services where the highest category of information to be
processed is Public data, the Vendor must submit an updated score for the product
annually throughout the contract duration that meets or exceeds the original score at
time of contract award. Products with GovRAMP Core, Ready, Authorized or
Provisionally Authorized statuses or FedRAMP Rev. 5 authorization also satisfy the
security requirement.
b. Internal - For third-party cloud services where the highest category of information to
be processed is Internal data, the Vendor must either achieve the status of GovRAMP
Core prior to award, or agree to achieve GovRAMP Core status within an interim time
period, no later than twelve (12) months from the effective date of the contract.
c. Confidential - For third-party cloud services where the highest category of information
to be processed is Confidential data, the Vendor must either achieve a status of
GovRAMP Ready, or agree to achieve GovRAMP Ready status no later than fifteen
(15) months from the effective date of the contract.
d. Restricted - For third-party cloud services where the highest category of information to
be processed is Restricted Data, the Vendor must either achieve a status of GovRAMP
Authorized, or agree to achieve GovRAMP Authorized status no later than twenty-one
(21) months from the effective date of the contract.
Upon contract award, Vendor's who submitted a GovRAMP Security Snapshot Score will be
required to enroll in the GovRAMP Progressing Snapshot program prior to any data being
transferred, stored or processed. The Vendor must complete their first Progressing
Snapshot within ninety (90) days of award, with the expectation that progress will be made
on a quarterly basis and access to progress reports must be provisioned to the State.
Page 10 of 29 January 30, 2026

With GovernmentContracts, you can:
...Follow 14 WS Climate Software Active Contract Opportunity Notice ID FA4600-26-14WS Related Notice... ...
DEPT OF DEFENSE
Bid Due: 8/18/2026
...Solicitation Number: Doc2332844055 Project Title: 30-26362-OOC Everlaw software subscription... and support Description: Everlaw ...
State Government of North Carolina
Bid Due: 8/17/2026
...Follow Notice of Intent to Sole Source: Federal Mastercam Software License Active Contract... ...
DEPT OF DEFENSE
Bid Due: 8/16/2026
...Follow Maintenance and repair, replacement parts, and software upgrades/updates for the Omnicell... source ...
DEPT OF DEFENSE
Bid Due: 8/13/2026