REQUEST FOR PROPOSALS
Varonis SaaS Data Security Platform Implementation and Support Services
RFP #: 25-11-3922SB
PROPOSAL DUE DATE: 3:00 p.m. MDST December 1, 2025
CONTACT PERSON:
Alex Largie, Network Manager
Phone: 928-871-6018 / 6520
Email: alexl@navajo-nsn.gov
DELIVER TO:
Department of Information Technology
P.O. Box 5970
Tribal Hill Drive, Building No. W008-076
Window Rock, AZ 86515
Attn: Alex Largie
SECTION I
A. ISSUING OFFICE: This Request for Proposal (RFP) is issued by the Navajo Nation Department
of Information Technology (NNDIT), Division of General Services, Navajo Nation, P.O. Box 5970,
Window Rock, Arizona. The contact person for this RFP is Alex Largie, Network Manager, NNDIT.
B. PURPOSE: This RFP provides prospective respondents with sufficient information to prepare
and submit proposals for consideration.
C. SCOPE: This RFP contains the instructions governing the proposal to be submitted and the
material to be included therein; mandatory requirements that must be met to be eligible for
consideration; and other requirements to be met by each proposal.
D. PROCUREMENT OF RFP: This procurement shall be conducted in accordance with all
applicable Navajo Nation laws and regulations including the Navajo Business Opportunity Act
https://www.navajoeconomy.org All applicable rules, regulations, and laws shall also be
followed. Prospective Vendors shall familiarize themselves with Navajo Nation Procurement
Rules and Regulations (BFD-192-03) prior to submitting responses to this RFP, and may
download a copy of the regulations from the Office of the Controller website at any time up to
the Deadline for Proposals from the following link: Purchasing Section (nnooc.org)
E. SCHEDULE OF ACTIVITIES:
Advertisement Date: November 17, 2025
Proposal Due Date: December 1, 2025
Inquiry Deadline: November 26, 2025
Evaluation Period: Week of November 8, 2025
F. INQUIRIES: Prospective respondents shall make written questions concerning this RFP to
obtain clarification of requirements through e-mail to Mr. Alex Largie, Network Manager, NNDIT
at alexl@navajo-nsn.gov No inquiries will be accepted after the inquiry deadline listed in section
E.
** Inquiry Deadline: Wednesday, November 26, 2025 at 12:00PM MST **
G. ADDENDUM OR SUPPLEMENT TO THIS REQUEST: In the event that it becomes necessary to
revise any part of this RFP, an addendum will be issued.
H. PROPOSAL SUBMISSION: Proposal must be received on or before 3:00 p.m., December 01,
2025 (MDST). The address is indicated on the cover sheet of the RFP e-mail proposals. Late
proposals will not be accepted. (No exceptions will be made)
I. NUMBER OF COPIES: Five sets of the proposal must be delivered. The proposal should be
clearly marked with the project name- “Varonis SaaS Data Security Platform Implementation
and Support Services BID NO. 25-11-3922SB” and the name and address of the firm submitting
the proposal. Proposals not clearly marked will not be accepted. (No exceptions will be made)
J. REJECTION OF PROPOSALS: NNDIT reserves the right to reject any and all proposals. This RFP
may be canceled at any time and all proposals may be rejected in whole or in part when the
NNDIT Department Director determines it is in the best interest of the Navajo Nation.
K. PROPRIETARY INFORMATION:
Any restriction on the use of data contained within any proposals must be clearly stated in the
proposal itself. Proprietary information submitted in response to this RFP will be handled in
accordance with applicable purchasing procedures. Each and every page of the proprietary
material must be labeled or identified with the word “proprietary”.
L. RESPONSE MATERIAL OWNERSHIP:
All material submitted regarding this RFP shall become the property of The Navajo Nation and
will not be returned to the respondent. Responses received will be retained by NNDIT and may
be reviewed by any person after final selection has been made, subject to paragraph I above.
NNDIT has the right to use any or all system ideas presented in reply to this RFP, subject to
limitations in paragraph I above. Disqualification or non-selection of a respondent or proposal
does not eliminate this right.
M. INCURRING COSTS: NNDIT is not liable for any cost by the respondents prior to issuance of a
contract.
N. ACCEPTANCE TIME: NNDIT intends to make a vendor selection within four (10) working days
after the closing date for receipt of proposals.
O. SUFFICIENT APPROPRIATION: A contract awarded as a result of this RFP is contingent upon
the availability of funds. A contract may be terminated or reduced in scope if sufficient funds do
not exist. Sending a written notice to the Vendor shall effect such termination or reduction in
scope. The NNDIT Department Director decision to terminate or reduce the scope due to
insufficient appropriations shall be accepted as final by the Vendor.
P. JOINT PROPOSALS: Nothing in this RFP shall be construed to prohibit vendors from entering
into a consortium for the purpose of offering a proposal in response to this RFP. Parties to a
consortium will not be permitted independent, individual proposals in response to this RFP
Q. EVALUATION PROCEDURES AND CRITERIA:
1. An evaluation team will judge the proposals received in accordance with the general criteria
used herein. Respondents should be prepared to provide any additional information the team
feels necessary for the fair evaluation of proposals.
2. Failure of a respondent to provide any information requested in the RFP may result in
disqualification of the proposal. All proposals must be endorsed with the signature of a
responsible official having the authority to bind the respondent to the execution of a contract.
3. The sole objective of the review team will be to select the respondent who is most responsive
to the needs of NNDIT. The specifications in this RFP represent the minimum performance
necessary for a response. On the basis of the evaluation criteria established in this RFP, the
review team will select and recommend the respondent who best meets this objective. If there
is only one responsive bid, the NNDIT Department Director may elect to evaluate RFP solely.
4. Each bid must be accompanied by a letter of transmittal. The letter of transmittal must:
1. Provide Statements of Qualifications.
2. Identify the name of the person responding to the RFP.
3. Identify the name, title, and telephone numbers of person authorized to negotiate on
behalf of the organization.
4. Identify the names, and telephone numbers of person to be contacted for
clarification.
5. Navajo Preference, Certificate of Eligibility issued by the Navajo Business Regulatory
Department.
6. Required insurance documents, i.e., Certificate of Liability Insurance
7. Completed and signed W-9 Form
8. Completed and Signed Navajo Nation Certification Regarding Debarment and
Suspension
9. Subcontractors List, if any.
10.Explicitly indicate acceptance of the conditions governing this procurement;
11.Be signed by the person responding to the RFP; and
12.Acknowledge receipt of any and all amendments to the RFP.
5. Evaluation Criteria: The following criteria will be used by an ad-hoc committee in the
selection process for contract award. Vendors and proposals will be evaluated to determine the
best opportunity for NNDIT.
• Priority Vendor Certification – 10 pts
A. Priority One Vendor (10 points)
B. Priority Two Vendor (5 points)
C. Non-Priority Vendor (0 points)
• Letter of Transmittal and Qualifications – 25 pts
• Technical Proposal and Scope Alignment – 30 pts
• Cost Proposal and Value – 20 pts
• Managed Detection and Response Capability (MDDR) – 10 pts
• Data Sovereignty and Knowledge Transfer Plan – 5 pts
Total: 100 pts
R. STANDARD CONTRACT: The Navajo Nation reserves the right to incorporate standard
contract provision into any contract negotiations as a result of a proposal submitted in response
to the RFP.
S. TAX: All appropriate taxes should be included in the cost of services including the Navajo
Sales Tax. All work performed within the territorial jurisdiction of the Navajo Nation is subject to
the Navajo Sales Tax of 6% (24 N.N.C. Section 601 et. seq.).
T. TERM: The term of this contract will be for a period of 3 years from the date of award.
U. SOVEREIGNTY: The Navajo Nation will not relinquish any of its sovereignty rights.
V. COMPLIANCE WITH LAWS AND REGULATIONS: The successful Vendor shall comply with all
Federal, Tribal, State, and Local laws, regulations and Navajo Nation rules and policies pertaining
to work under its charge, and shall, at its expense, procure any permits that may be required.
W. INDEMNIFICATION: To the fullest extent permitted by law, or as otherwise defined in the
Contract, the successful Vendor shall indemnify and hold harmless the Navajo Nation and its
officials, employees and agents from and against all claims, liens or demands that result in
losses, liabilities, defense costs and expenses (including but not limited to attorney’s fees and
costs of litigation) arising out of the term, conditions and performance under the contract. The
Vendor further agrees to indemnify and hold harmless the Navajo Nation, its agents, or
employees, against claims or liability arising from or based upon the violation of any federal,
state, county, city, or other applicable laws, bylaws, ordinances, or regulations by the Vendor, its
agents, associates, or employees.
The indemnification provided above shall obligate the Vendor to defend at its own expense or
to provide for such defense, at the Navajo Nation’s option, of any and all claims of liability and
all suits and actions of every name and description that may be brought against the Navajo
Nation which may result from the operations and activities under any Contract resulting from
this RFP.
The award of this Contract to the Vendor shall obligate the Vendor to comply with the foregoing
indemnity provision.
SECTION II – SCOPE OF WORK
The Navajo Nation Department of Information Technology (NNDIT) seeks a qualified vendor to
implement and support the Varonis SaaS Data Security Platform. This initiative will enhance the
Nation’s cybersecurity posture through automated data discovery, classification, permissions
management, and real-time threat detection.
This implementation will strengthen the Navajo Nation’s data sovereignty and cybersecurity
framework by protecting sensitive, cultural, and operational data assets. All data collected,
stored, or analyzed under this contract shall remain within environments approved by NNDIT
and in compliance with Navajo Nation data sovereignty policies.
The Navajo Nation anticipates deployment of approximately 3,000 cloud-based SaaS
security licenses in support of a fully Microsoft 365 environment. The proposed solution
must provide a SaaS-only configuration with no dependency on on-premises
infrastructure. If connectors are needed for optional sources, the solution must support
lightweight deployment without requiring local hardware.
The proposed solution must include the following minimum capabilities:
• Enterprise-grade Microsoft 365 protection across SharePoint Online, OneDrive,
Teams, Entra ID, Exchange Online, and Copilot.
This is the opportunity summary page. It provides an overview of this opportunity and a preview of the attached documentation.