| Location: | North Carolina |
|---|---|
| Posted: | Jun 4, 2026 |
| Due: | Jun 25, 2026 |
| Agency: | State Government of North Carolina |
| Type of Government: | State & Local |
| Category: |
|
| Solicitation No: | 68-68-SOCC0626 |
| Publication URL: | To access bid details, please log in. |
| Solicitation Number: | 68-68-SOCC0626 |
| Project Title: | PBS North Carolina Call Center |
| Description: | Call agent staffing services |
| Opening Date: | 6/25/2026 10:00 AM |
| Posted Date: | 6/5/2026 |
| Status: | Open |
| Department: | UNC - SYSTEM OFFICE |
|
Solicitation Number
*
68-68-SOCC0626
|
Department
UNC - SYSTEM OFFICE
|
Status Reason
Open
|
|
|
Opening Date
2026-06-25T10:00:00.0000000
|
Posted Date
*
2026-06-04T20:45:38.0000000Z
|
Primary Commodity Code
Local and long distance telephone communications
|
|
|
Mandatory Conference/Site Visit
—
—
|
Special Instructions
—
|
Solicitation Type
*
Select RFP IFB RFI
|
|
|
Owner
Robert Myers
|
|||
|
Description
Call agent staffing services
|
|||
| STATE OF NORTH CAROLINA UNIVERSITY OF NORTH CAROLINA PBS NC | REQUEST FOR PROPOSAL NO. |
|---|---|
| Bid Opening Date: June 25, 2026 | |
| Refer ALL inquiries regarding this RFP to: Bob Myers rbmyers@northcarolina.edu 68-SOCC0626 Questions | Issue Date: June 4, 2026 |
| Commodity Code: 83111507 | |
| Purchasing Agency: University of North Carolina | |
| Requisition No.: |
| OFFEROR: | |||
|---|---|---|---|
| STREET ADDRESS: | P.O. BOX: | ZIP: | |
| CITY, STATE & ZIP: | TELEPHONE NUMBER: | TOLL FREE TEL. NO | |
| NAME & TITLE OF PERSON SIGNING: | FAX NUMBER: | ||
| AUTHORIZED SIGNATURE: | DATE: | E-MAIL: |
STATE OF NORTH CAROLINA REQUEST FOR PROPOSAL NO.
UNIVERSITY OF NORTH CAROLINA
PBS NC
Bid Opening Date: June 25, 2026
Issue Date: June 4, 2026
Refer ALL inquiries regarding this RFP to:
Bob Myers Commodity Code: 83111507
rbmyers@northcarolina.edu
Purchasing Agency: University of North Carolina
68-SOCC0626 Questions
Requisition No.:
OFFER
The Purchasing Agency solicits offers for Services and/or goods described in this solicitation. All offers and
responses received shall be treated as Offers to contract as defined in 9 NCAC 06A.0102(12).
EXECUTION
In compliance with this Request for Proposal (RFP), and subject to all the conditions herein, the undersigned
offers and agrees to furnish any or all Services or goods upon which prices are offered, at the price(s) offered
herein, within the time specified herein.
Failure to execute/sign offer prior to submittal shall render offer invalid. Late offers are not acceptable.
OFFEROR:
STREET ADDRESS: P.O. BOX: ZIP:
CITY, STATE & ZIP: TELEPHONE NUMBER: TOLL FREE TEL. NO
NAME & TITLE OF PERSON SIGNING: FAX NUMBER:
AUTHORIZED SIGNATURE: DATE: E-MAIL:
Offer valid for one hundred twenty (120) days from date of offer opening unless otherwise stated here: ____
days
ACCEPTANCE OF OFFER
If any or all parts of this offer are accepted, an authorized representative of the University of North Carolina shall
affix its signature hereto and any subsequent Request for Best and Final Offer, if issued. Acceptance shall create
a contract having an order of precedence as follows: Best and Final Offers, if any, Special terms and conditions
specific to this RFP, Specifications of the RFP, the Department of Information Technology Terms and Conditions,
and the agreed portion of the awarded Vendor's Offer. A copy of this acceptance will be forwarded to the awarded
Vendor(s).
FOR PURCHASING AGENCY USE ONLY
Offer accepted and contract awarded this date, , as indicated on attached certification,
by (Authorized representative of the University of North Carolina).
Version May 4, 2026
Table of Contents
1.0 Anticipated Procurement Schedule ............................................................................................. 3
2.0 Purpose of RFP ........................................................................................................................... 3
2.1 Introduction ............................................................................................................................. 3
2.2 Agency Background ................................................................................................................ 3
2.3 Summary of Problem Statement ............................................................................................. 3
2.4 Contract Term ......................................................................................................................... 4
2.5 Effective Date ......................................................................................................................... 4
2.6 Contract Type ......................................................................................................................... 4
3.0 RFP requirements and Specifications ......................................................................................... 4
3.1 General requirements and Specifications ............................................................................... 4
3.2 Security Specifications ............................................................................................................ 5
3.3 Enterprise Specifications ........................................................................................................ 6
3.3.1 Architecture Diagrams ............................................................................................................ 6
3.3.2 Solution Roadmap .................................................................................................................. 6
3.3.3 Identity and Access Management........................................................................................... 7
3.3.4 Integration Approach .............................................................................................................. 7
3.3.5 Disaster Recovery and Busienss Continuity ........................................................................... 7
3.3.6 Data Migration ........................................................................................................................ 7
3.3.7 Application Management ........................................................................................................ 7
3.3.8 Accesibility .............................................................................................................................. 7
3.4 Business and Technical Requirements ................................................................................... 8
3.5 Business and Technical Specifications ................................................................................. 10
4.0 Cost of Vendor's Offer ............................................................................................................... 11
4.1 Offer Costs ........................................................................................................................... 11
4.2 Payment Schedule ................................................................................................................ 11
5.0 Evaluation ................................................................................................................................. 11
5.1 Source Selection................................................................................................................... 11
5.2 Evaluation Criteria ................................................................................................................ 11
5.3 Best and Final Offers (BAFO) ............................................................................................... 12
5.4 Possession and Review ........................................................................................................ 12
6.0 Vendor Information and Instructions ......................................................................................... 12
6.1 General Conditions of Offer .................................................................................................. 12
6.2 General Instructions for Vendors .......................................................................................... 13
6.3 Instructions for Offer Submission .......................................................................................... 15
7.0 Other Requirements and Special Terms ................................................................................... 18
7.1 Vendor Utilization Of Workers Outside of U.S. ..................................................................... 18
7.2 Financial Statements ............................................................................................................ 18
7.3 Financial Resources Assessment, Quality Assurance, Performance and Reliability ............ 18
7.4 Vendor's License or Support Agreements ............................................................................ 18
7.5 Resellers ............................................................................................................................... 19
7.6 Disclosure of Litigation .......................................................................................................... 19
7.7 Criminal Conviction ............................................................................................................... 19
Version May 4, 2026
7.8 Security and Background Checks ......................................................................................... 19
7.9 Assurances ........................................................................................................................... 19
7.10 Confidentiality of offers ......................................................................................................... 19
7.11 Project Management ............................................................................................................ 20
7.12 Meetings ............................................................................................................................... 20
7.13 Recycling and Source Reduction ......................................................................................... 20
7.14 Special Terms and Conditions .............................................................................................. 20
7.15 Agency Terms and Conditions ............................................................................................. 20
Attachment A: Definitions .................................................................................................................... 21
Attachment B: Department of Information Technology Terms and Conditions.................................... 23
Attachment C: Description of Offeror .................................................................................................. 39
Attachment D: Cost Form ................................................................................................................... 41
Attachment E: Vendor Certification Form ............................................................................................ 42
Attachment F: Location of Workers Utilized by Vendor - Disclosure Statement .................................. 43
Attachment G: References .................................................................................................................. 45
Attachment H: Financial Review Form ................................................................................................ 46
Version May 4, 2026
| Action | Responsibility | Date | ||||||
|---|---|---|---|---|---|---|---|---|
| RFP Issued | Agency | 6/4/2026 | ||||||
| Written Questions Deadline | Potential Vendors | 6/12/2026 at noon EDT | ||||||
| Agency's Response to Written Questions/ RFP Addendum Issued | Agency | 6/17/2026 | ||||||
| Offer Opening Deadline | Vendor(s) | 6/25/2026 at 10:00 a.m. EDT | ||||||
| Contract Award | Agency | TBD | ||||||
| Protest Deadline | Responding Vendors | 15 days after award |
1.0 ANTICIPATED PROCUREMENT SCHEDULE
The Agency Procurement Agent will make every effort to adhere to the following schedule:
Action Responsibility Date
RFP Issued Agency 6/4/2026
Written Questions Deadline Potential Vendors 6/12/2026 at
noon EDT
Agency's Response to Written Questions/ Agency 6/17/2026
RFP Addendum Issued
Offer Opening Deadline Vendor(s) 6/25/2026 at
10:00 a.m. EDT
Contract Award Agency TBD
Protest Deadline Responding Vendors 15 days after
award
2.0 PURPOSE OF RFP
2.1 INTRODUCTION
The purpose of this RFP is to solicit Offers for call agent staffing services. PBS North Carolina is requesting
proposals for an external call center agency to provide call agent staffing for the organization Monday-Friday,
9:00am-5:00pm ET. The call center agency will be responsible for answering and fielding all phone calls as
well as responding to voicemails to PBS North Carolina from its nearly 105,000 members and many more
viewers that watch its free public broadcasting. The donations from the members of PBS North Carolina
constitute the majority of the organization's annual budget, necessitating the need for the highest level of
customer service for these donors.
2.2 AGENCY BACKGROUND
PBS NC is North Carolina's only statewide public media network PBS NC's 12 stations provide all 100
counties with four full time, unique broadcast program channels. PBS NC's strategic priorities focus on
service and engagement within our communities and developing an operating plan that promotes long-term
sustainability.
2.3 SUMMARY OF PROBLEM STATEMENT
Call agents should be able to answer phone calls, log account changes with the PBS North Carolina CRM,
take new donations, cancel donations, and provide answers to questions pertaining to either the mission or
programming of PBS North Carolina or its streaming app, Passport. Call agents must be able to work out of
Blackbaud's Raisers Edge NXT, Blackbaud's Luminate Online, and MVault, a PBS system used to manage
Passport access.
External call center must maintain sufficient data-security measures for all call agents (in-person and/or
remote) and must annually provide a current PCI DSS Attestation of Compliance for Service Providers, under
PCI DSS v4.0(x) or the then-current version, covering the services proposed for PBS NC, including applicable
telephony, call recording, CRM/ticketing, payment-processing, remote-agent, and subcontractor
environments.
Page 3 of 46
May 4, 2026
Additionally, if able, PBS North Carolina would like to know availability to provide 24-hour call agent staffing
for a pledge line with the sole purpose of taking new donations, documenting requested premium gifts, and
taking request notes to provide for the 9:00am-5:00pm call team for data entry.
Reporting on calls answered, calls missed, response rate per agent, tickets resolved, and other relevant metrics
must be provided on a weekly basis, presented by daily results. Recordings of call agents, masking all PII,
must be provided upon request to ensure quality control. The external call center must not store payment-card
data, CVV/CVC, sensitive authentication data, or payment information in recordings, transcripts, voicemails,
tickets, notes, or quality-assurance tools. The external call center shall not record any portion of conversations
whereby PII or payment-card data is shared by PBS donors.
2.4 CONTRACT TERM
A contract awarded pursuant to this RFP shall have an effective date as provided in the Notice of Award.
The term shall be one (1) year, and will expire upon the anniversary date of the effective date unless
otherwise stated in the Notice of Award, or unless terminated earlier. The State retains the option to extend
the Agreement for two (2) two-year periods at its sole discretion.
2.5 EFFECTIVE DATE
This solicitation, including any Exhibits, or any resulting contract or amendment shall not become effective
nor bind the State until the appropriate State purchasing authority/official or Agency official has signed the
document(s), contract or amendment; the effective award date has been completed on the document(s), by
the State purchasing official, and that date has arrived or passed. The State shall not be responsible for
reimbursing the Vendor for goods provided nor Services rendered prior to the appropriate signatures and the
arrival of the effective date of the Agreement. No contract shall be binding on the State until an encumbrance
of funds has been made for payment of the sums due under the Agreement.
2.6 CONTRACT TYPE
Definite Quantity Contract - This request is for a close-ended contract between the awarded Vendor and the
State to furnish a pre-determined quantity of a good or service during a specified period of time.
The State reserves the right to make partial, progressive or multiple awards where it is advantageous to
award separately by items; where more than one supplier is needed to provide the contemplated
specifications as to quantity, quality, delivery, service, geographical areas; or where other factors are
deemed to be necessary or proper to the purchase in question.
3.0 RFP REQUIREMENTS AND SPECIFICATIONS
3.1 GENERAL REQUIREMENTS AND SPECIFICATIONS
3.1.1 REQUIREMENTS
Requirement means, as used herein, a function, feature, or performance that the System must
provide. If the offer can not meet the requirements, they will not be evaluated.
3.1.2 SPECIFICATIONS
Specification means, as used herein, a detailed description that documents the function and
performance of a system or system component.
The apparent silence of the specifications as to any detail, or the apparent omission of detailed
description concerning any point, shall be regarded as meaning that only the best commercial practice
is to prevail and that only processes, configurations, materials and workmanship of the first quality
may be used. Upon any notice of noncompliance provided by the State, Vendor shall supply proof of
Page 4 of 46
May 4, 2026
compliance with the specifications. Vendor must provide written notice of its intent to deliver alternate
or substitute Services, products, goods or other Deliverables. Alternate or substitute Services,
products, goods or Deliverables may be accepted or rejected in the sole discretion of the State; and
any such alternates or substitutes must be accompanied by Vendor's certification and evidence
satisfactory to the State that the function, characteristics, performance and endurance will be equal
or superior to the original Deliverables specified.
3.1.3 SITE AND SYSTEM PREPARATION
Vendors shall provide the Purchasing State Agency complete site requirement specifications for the
Deliverables, if any. These specifications shall ensure that the Deliverables to be installed or
implemented shall operate properly and efficiently within the site and system environment. Any
alterations or modification in site preparation, which are directly attributable to incomplete or
erroneous specifications provided by the Vendor and which would involve additional expenses to the
State, shall be made at the expense of the Vendor.
3.1.4 EQUIVALENT ITEMS
Whenever a material, article or piece of equipment is identified in the specification(s) by reference to
a manufacturer's or Vendor's name, trade name, catalog number or similar identifier, it is intended to
establish a standard for determining substantial conformity during evaluation, unless otherwise
specifically stated as a brand specific requirement (no substitute items will be allowed). Any material,
article or piece of equipment of other manufacturers or Vendors shall perform to the standard of the
item named. Equivalent offers must be accompanied by sufficient descriptive literature and/or
specifications to provide for detailed comparison.
3.1.5 ENTERPRISE LICENSING
a) Reserved.
3.2 SECURITY SPECIFICATIONS
3.2.1 SOLUTIONS HOSTED ON STATE INFRASTRUCTURE
Reserved.
3.2.2 SOLUTIONS NOT HOSTED ON STATE INFRASTRUCTURE
The Agency (named on page one (1)) has designated this solicitation to receive and securely manage
data that is classified as:
Agency has selected:
Restricted - Restricted data represents the highest risk to the State, State Agencies, and
constituents if it is disclosed or compromised. This information is likely to be regulated by State
or Federal law, and access to it is restricted to a limited audience (e.g., State and Federal Tax
Information [FTI], Payment Card data, Protected Health Information [PHI], Criminal Justice
Information [CJI], Social Security Administration provided information, etc.)
Confidential - Includes information that is limited to a small audience with a need-to-know or
legitimate business case (e.g., State employee personnel records, trade secrets, student records,
sensitive public security information, etc.). If exposed to unauthorized parties, data from this
category will cause high impact consequences such as regulatory fines, inability to recruit talent,
loss of confidence, and/or damage to vendor relationships. This is not a complete list and is
subject to legislative changes.
Internal - This is information typically used within the agency and not for public sharing. Most
documents are classified as Internal within the organization, and most State employees would
have access. This type of data, if exposed to unauthorized parties, would have a very limited
impact on an agency's reputation, compliance requirements or ability to achieve strategic goals.
Page 5 of 46
May 4, 2026
Internally classified data does not contain direct identifiers. Often, the effects of the loss of data
can be recognized in very subtle ways and may not lead to clear negative consequences causing
confusion due to lack of context or minor reputational harm.
Public - Data that is open to public inspection according to state and federal law, or readily
available through public sources.
Refer to the North Carolina Statewide Data Classification and Handling policy for more information
regarding data classification. The policy is located at the following website:
https://it.nc.gov/document/statewide-data-classification-and-handling-policy.
To comply with the State's Security Standards and Policies, State agencies are required to perform
annual security/risk assessments on their information systems using NIST 800-53 controls.
This requirement additionally applies to all Vendor-provided, agency-managed Infrastructure as a
Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) solutions which will
handle data classified as Internal, Confidential, or Restricted.
(a) To comply with the State's Security Standards and Policies, cloud products
are required to comply with applicable FedRAMP or GovRAMP security requirements,
including but not limited to, continuous monitoring, incident response, and data classification
as outlined in GovRAMP documentation.
(b) To streamline and standardize this requirement the State has adopted GovRAMP which is
a Risk and Authorization Management Program that provides a standardized approach to
security assessment, authorization, and continuous monitoring for cloud products and
services. GovRAMP's security verification model is based on NIST 800-53 Rev. 5 (or
current).
(c) Additional Security Documentation. Prior to contract award, the State may in its discretion
require the Vendor to provide additional security documentation, including but not limited to,
vulnerability assessment reports and penetration test reports. The awarded Vendor shall provide
additional security documentation upon request by the State during the term of the contract.
Refer to: https://it.nc.gov/documents/statewide-glossary-information-technology-terms for
descriptions of the Application Criticality categories.
Refer to: http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf for descriptions of NIST
system confidentiality, integrity, and availability categories.
3.3 ENTERPRISE SPECIFICATIONS
3.3.1 ARCHITECTURE DIAGRAMS
The two diagrams are Network Architecture and Technology Stack. The State utilizes architectural
diagrams to better understand the design and technologies of a proposed solution. Details on these
diagrams can be found at the following link: https://it.nc.gov/resources/statewide-it-
procurement/vendor-engagement-resources#Tab-Architecture-1192
The provision of these two diagrams is a requirement at offer submission. If they are not supplied
at that time, the Vendor's offer will be considered non-responsive and will not be evaluated.
There may be additional architectural diagrams requested of the vendor after contract award. This
will be communicated to the vendor by the agency as needed during the project.
3.3.2 SOLUTION ROADMAP
Reserved.
Page 6 of 46
May 4, 2026
3.3.3 IDENTITY AND ACCESS MANAGEMENT
Reserved.
3.3.4 INTEGRATION APPROACH
Describe proposed solution capabilities to interoperate with other solutions. Identify the standards
supported, integrations platforms, adaptors, APIs, and the like.
3.3.5 DISASTER RECOVERY AND BUSINESS CONTINUITY
Describe the proposed solution capabilities related to the following areas:
Disaster Recovery Plan (DRP) - describe how proposed solution supports Recovery Point Objectives
(RPO) and Recovery Time Objectives (RTO) metrics.
System Backup - describe backup plan capabilities.
Disaster Recovery Testing - describe the frequency and test procedures for end-to-end disaster
recovery testing. Business Continuity Plan (BCP) - describe capabilities proposed solution can
provide in support of agency's continuity of operations and incident responses.
3.3.6 DATA MIGRATION
Describe approaches available for data conversion and/or data migration to load current data into
proposed solution.
3.3.7 APPLICATION MANAGEMENT
Describe how the proposed solution monitors and reports the metrics on system performance.
Describe how the proposed solution manages user administration.
Describe the audit capabilities of proposed solution related to management of the application.
3.3.8 ACCESSIBILITY
Describe how the proposed solution complies with industry accessibility standards.
Provide product documentation that demonstrates how the proposed solution is digitally accessible
or if not fully accessible, provide the roadmap with timeline for remediation.
Standards include:
* State of North Carolina Digital Accessibility & Usability Standard
* W3C Web Accessibility Initiative - Web Content Accessibility Guidelines (WCAG) 2.1:
https://www.w3.org/TR/WCAG21/
* Section 508: https://www.section508.gov/
* Voluntary Product Accessibility Template (VPAT(R)):
https://www.itic.org/policy/accessibility/vpat
ENTERPRISE, SERVICES, AND STANDARDS
Vendors should refer to the Vendor Resources Page for information on North Carolina Department
of Information Technology regarding architecture, security, strategy, data, digital, identity and access
management and other general information on doing business with state IT process.
The Vendor Resources Page found at the following link: https://it.nc.gov/vendor-engagement-
resources. This site provides vendors with statewide information and links referenced throughout the
RFP document. Agencies may request additional information.
Page 7 of 46
May 4, 2026
3.4 BUSINESS AND TECHNICAL REQUIREMENTS
3.4.1
PBS North Carolina is seeking an external call center agency to provide call agent staffing for the
organization Monday-Friday, 9:00am-5:00pm ET. The call center agency will be responsible for
answering and fielding all phone calls as well as responding to voicemails to PBS North Carolina from
its nearly 105,000 members and many more viewers that watch its free public broadcasting.
Call agents must be able to work out of Blackbaud's Raisers Edge NXT, Blackbaud's Luminate
Online, and MVault, a PBS system used to manage Passport access.
All call agents must be able to provide the following functions within the systems:
* Account changes such as changes to name, preferred salutation, physical mailing address, email
address(es), phone number(s), and communication preferences
* Documenting premium gifts needed
* Cancellation of recurring donations
* Processing of new donations, including if a donor would like a new card or bank account on file,
upgrade their donation, or downgrade their donation
* Passport Status look up
* Passport Award
* Passport Membership extensions
* Data entry from pledge line
* Documentation of all changes with action logs and notes within the systems
* Receipting
Additionally, call agents should be able to provide answers to questions pertaining to either the
mission or programming of PBS North Carolina or its streaming app, Passport.
The external call center must maintain sufficient data-security measures for all call agents and must
annually provide a current PCI DSS Attestation of Compliance for Service Providers, under PCI DSS
v4.0.1 or the then-current version, covering the services proposed for PBS NC, including applicable
telephony, call recording, CRM/ticketing, payment-processing, remote-agent, and subcontractor
environments. PBS North Carolina will need one point of contact as the account representative that
will meet with PBS North Carolina Development management twice a month to discuss current
metrics and any relevant organizational or programming updates for PBS North Carolina for call
center agents. Reporting on calls answered, calls missed, response rate per agent, tickets resolved,
and other relevant metrics must be provided on a weekly basis, presented by daily results. Recordings
of call agents, masking all donor PII, must be provided upon request to ensure quality control. The
external call center must not store payment-card data, CVV/CVC, sensitive authentication data, or
payment information in recordings, transcripts, voicemails, tickets, notes, or quality-assurance tools.
Service Provider Security Acknowledgment. Vendor shall provide a written acknowledgment,
incorporated into the Agreement, that Vendor is responsible for the security of account data,
cardholder data, and sensitive authentication data that Vendor possesses or otherwise stores,
processes, or transmits on behalf of PBS NC, or to the extent Vendor could affect the security of PBS
NC cardholder data, sensitive authentication data, or cardholder data environment.
Telephone Payment and Recording Controls. Vendor shall describe the end-to-end payment-card
handling process for all donor payments, including agent scripts, call routing, IVR or payment-
application use, CRM entry, call recording, voicemail handling, ticketing, and quality-assurance
review. Vendor shall use technical controls such as secure IVR or payment capture, pause-and-
resume recording, DTMF masking or suppression, tokenization, secure payment links, or equivalent
controls to prevent payment-card data from being exposed to or retained in non-payment systems,
and shall provide evidence of the effectiveness of these controls upon request.
Page 8 of 46
May 4, 2026
Compliance Monitoring and Reporting. Vendor shall provide updated PCI DSS compliance evidence
at least annually and within ten (10) business days after PBS NC written request. Vendor shall notify
PBS NC within five (5) business days of any material change in PCI DSS compliance status, lapse
or expiration of an AOC, material change in PCI DSS scope, failure of a required PCI DSS control,
change in payment-card processing flow, or change in any subcontractor that stores, processes,
transmits, or could affect payment-card data. Vendor failure to maintain applicable PCI DSS
compliance or to provide required evidence shall constitute a material breach of the Agreement.
PCI DSS Responsibility Matrix. Vendor shall provide and maintain a PCI DSS v4.0.1 or then-current
responsibility matrix identifying each applicable PCI DSS requirement and sub-requirement and
stating whether it is Vendor responsibility, PBS NC responsibility, or a shared responsibility. For
shared responsibilities, Vendor shall describe the specific actions required of each party, the relevant
systems or processes, and the evidence available to demonstrate compliance. Vendor shall update
the responsibility matrix within thirty (30) calendar days of any material change to services, systems,
subcontractors, compliance status, or payment-card handling processes.
Subcontractors and Nested Service Providers. Vendor shall not add or materially change
subcontractors, affiliates, platforms, cloud providers, payment processors, IVR providers, call-
recording providers, workforce-management tools, ticketing systems, or other third parties that store,
process, transmit, access, or could affect PBS NC donor data or payment-card data without prior
written notice to PBS NC and any required approval under the Agreement. Vendor shall ensure
approved subcontractors are contractually bound to security, confidentiality, incident-response, audit,
and PCI DSS obligations at least as protective as those imposed on Vendor. Vendor remains fully
responsible for subcontractor performance and compliance.
Payment-Card and Donor-Data Incident Response. Vendor shall notify PBS NC without undue delay
and no later than twenty-four (24) hours after discovering any suspected or confirmed unauthorized
access to, disclosure of, compromise of, loss of, or inability to account for PBS NC donor data,
account data, cardholder data, sensitive authentication data, payment systems, call recordings,
voicemails, CRM records, or systems that could affect the security of such data. Vendor shall
immediately contain the incident, preserve relevant logs and evidence, cooperate with PBS NC and
its designated representatives, support payment-brand and acquirer requirements, and provide
information reasonably necessary for PBS NC to meet legal, contractual, regulatory, and PCI DSS
obligations. Vendor shall not make public statements regarding the incident without PBS NC prior
written approval except as required by law.
Access Control and Security Audit Evidence. Vendor shall use unique user IDs, least-privilege
access, strong authentication, multi-factor authentication where supported or required, secure
password and session controls, timely removal of access upon role change or separation, and
periodic access reviews for all personnel accessing PBS NC systems, donor data, payment systems,
call recordings, or related tools. Upon reasonable request, Vendor shall provide documentation
sufficient to verify compliance with security, privacy, and PCI DSS obligations, including policies,
training records, access-review records, vulnerability-management summaries, penetration-test
executive summaries, incident-response test results, PCI DSS evidence, AOCs, responsibility
matrices, and relevant subcontractor attestations.
Additionally, PBS North Carolina would like to know availability to provide 24-hour call agent staffing
for a pledge line with the sole purpose of taking new donations, documenting requested premium
gifts, and taking request notes to provide for the 9:00am-5:00pm call team for data entry.
Page 9 of 46
May 4, 2026

With GovernmentContracts, you can:
Follow Multiple Building Fire Exhaust Systems Repairs Active Contract Opportunity Notice ID N4008526R9059
DEPT OF DEFENSE
Bid Due: 8/05/2026
Follow 43d Air Mobility Squadron_ Request for Proposal_FA445226R0012_B753 Kitchen Renovation Active Contract Opportunity
DEPT OF DEFENSE
Bid Due: 8/05/2026
Follow Multiple Base-wide Location Fencing Repairs Active Contract Opportunity Notice ID N4008524R9072 Related
DEPT OF DEFENSE
Bid Due: 8/20/2026
Project: Federal Pipe Video Contracts Ref. #: 269- 2026-235 Department: City Procurement Type:
City of Charlotte
Bid Due: 8/24/2026