ANR FWD Point of Sale Solution

Location: Vermont
Posted: Apr 14, 2026
Due: May 8, 2026
Agency: State of Vermont
Type of Government: State & Local
Category:
  • 70 - General Purpose Information Technology Equipment (including software).
  • D - Automatic Data Processing and Telecommunication Services
Publication URL: To access bid details, please log in.
TITLE QUESTIONS DUE ANSWERS POSTED DUE DATE NO POSTING AFTER
ANR FWD Point of Sale Solution
Bidder Response Form

04/24/2026 04:30PM


05/08/2026 04:30PM

Attachment Preview

State of Vermont Bidder Response Form

Request for Proposal Name: ANR FWD Point of Sale Solution

Vendor Instructions:

Provide the information requested in this form and submit it to the State of Vermont as part of your Request for Proposal (RFP) response. All answers must be provided within the form unless otherwise specified.

Important: This form must be completed and submitted in response to this RFP for your proposal to be considered valid. The submission must also include the eight (8) additional artifacts requested within this form (denoted by underlined green font).

See the RFP for full instructions for submitting a bid. Bids must be received by the due date and at the location specified on the cover page of the RFP.

Direct any questions you have concerning this form or the RFP to:

Kyle Emerson, State Purchasing Agent

State of Vermont

Office of Purchasing & Contracting

E-mail Address:

Part 1: Vendor Profile

Complete the table below.

Provide a brief overview of your company including number of years in business, number of employees, nature of business, and description of clients. Identify any parent corporation and/or subsidiaries.

Is your organization currently or has it previously provided solutions and/or services to any agency or entity of the Vermont State government within the past five years? If so, include a complete list of the State entities, the solutions and/or services provided, and the dates your organization provided the State with these services in the last five years.

Provide a Financial Statement* for your company and label it Attachment #1. This requirement can be filled by:

A current Dun and Bradstreet Report that includes a financial analysis of the firm;

An Annual Report if it contains (at a minimum) a Compiled Income Statement and Balance Sheet verified by a Certified Public Accounting firm; or

Tax returns and financial statements including income statements and balance sheets for the most recent 3 years, and any available credit reports.

A confidentiality statement may be included if this financial information is considered non-public information

*Some types of procurements may require bidders to provide additional or specific financial information. Any such additional requirements will be clearly identified and explained within the RFP and may include supplemental forms in addition to this Bidder Response Form.

Disclose any judgments, pending or expected litigation, or other real potential financial reversals, which might materially affect the viability or stability of your company or indicate below that no such condition is known to exist. A confidentiality statement may be included if this information is considered non-public information

Provide a list of three references similar in size and industry (preferably another governmental entity). References shall be clients, other than the State of Vermont, who have implemented your Solution within the past 48 months.

Part 2: Vendor Proposal/Solution

Provide a description of the technology solution you are proposing.

Provide a description of the capabilities of the technology solution you are proposing.

If specific software is being proposed, provide a description of the:

Standard features and functions of the software:

The software licensing requirements for the solution:

Maximum number of concurrent users:

Give a brief description of the evolution of the system/software solution you are proposing. Include the date of the first installed site and major developments which have occurred (e.g. new versions, new modules, specific features).

List the total number of installations in the last 3 years by the year of installation.

Provide the total number of current users for the proposed system and indicate what version they are using.

Have you implemented the proposed solution for other government entities? If so, tell us who, when, and how that implementation went?

Provide a Road Map that outlines the company's short term and long-term goals for the proposed solution/software and label it Attachment #2. (A confidentiality statement may be included if this information is considered non-public information)

Provide a PowerPoint (minimum of 1 slide and maximum of 10 slides) that provides an Executive level summary of your proposal to the State. Label it Attachment #3.

Describe any infrastructure, equipment, network or hardware required to implement and/or run the solution.

What is your recommended way to host this solution?

Describe how your solution can be integrated to other applications and if you offer a standard-based interface to enable integrations.

Respond to the following questions about the solution being proposed:

Part 3: Functional Requirements

The table below lists the State's Functional Requirements. Indicate the "Availability" for each requirement for your proposed solution. Use the "Vendor Comments" column to provide any additional information or explanations.

A - Feature is available in the core ("out-of-the-box") solution.

D - Feature is currently under development (indicate anticipated date of availability in the Vendor comments column).

C - Feature is not available in the core solution, but can provided with customization.

N - Feature is not available.

Part 4: Non- Functional Requirements

The tables below list the State's Non-Functional Requirements. Indicate if your proposed solution complies in the "Comply" column.

Yes = the solution complies with the stated requirement.

No = the solution does not comply with the stated requirement.

N/A = Not applicable to this offering.

Describe how the requirement is met in the "Vendor Description of Compliance" column.

4.1 Transferability

4.2 Reliability

4.3 Maintainability

4.4 Usability

4.5 Agility

4.6 Performance Efficiency

4.7 Compatibility

Security

4.9 Data Compliance

Vendors and their solutions must adhere to applicable State and Federal standards, policies, and laws based on the type of data that will be stored, accessed, transmitted and/or controlled by the solution. If the "Type of Data" column is checked below, respond "Yes" or "No" in the "Comply" column and provide an explanation on how you comply in the "Vendor's Description of Compliance" column.

4.10 State of Vermont Cybersecurity Standard Update

Bidder shall certify by checking the box below the Solution shall not include, incorporate, rely on, utilize or be supported by any products or services subject to the limitations provided under State of Vermont Cybersecurity Standard Update, which Bidder acknowledges has been provided to it, and is available on-line at the following URL:

Bidder hereby certifies that in connection with the Request for Proposal, none of the applicable products or services will be included in or used to support State systems in a manner prohibited under the Standard.

Part 5: General Administrative Requirements

5.01 Project Management & Planning

PROJ-FEA-GF01

As a State project manager, I want the Contractor to plan, manage, and report project activities using State-approved tools and plans So that the project is executed consistently, collaboratively, and in alignment with State governance standards.

5.02 Human Resources & Staffing Management

PROJ-FEA-GF02

As a State contract manager

I want visibility and oversight of Contractor staffing and personnel

So that the project maintains qualified, available, and accountable resources.

5.03 Contract & Financial Management

PROJ-FEA-GF03

As a State financial administrator

I want Contractor invoicing, subcontractor oversight, and legal responses managed consistently

So that financial compliance, accountability, and transparency are maintained.

5.04 Communications & Documentation Management

PROJ-FEA-GF04

As a State project manager

I want project documentation and communications managed using State standards

So that information is accurate, compliant, and accessible.

5.05 Technical Design & Implementation

PROJ-FEA-GF05

As a State enterprise architect

I want system, interface, and data design documentation maintained and approved

So that technical components are traceable, consistent, and support integrated operations.

5.06 Infrastructure & Hosting Management

PROJ-FEA-GF-06

As a State technical operations lead

I want the Contractor to manage hosting, environments, and infrastructure performance

So that systems operate reliably and meet service level agreements.

5.07 Security & Compliance Management

PROJ-FEA-GF07

As a State security and privacy lead

I want compliant security controls, assessments, and protected environments

So that systems meet Federal and State privacy, audit, and cybersecurity standards.

5.08 Testing & Quality Management

PROJ-FEA-GF08

As a State quality lead

I want quality and testing activities managed under approved standards and plans

So that the system meets performance, compliance, and operational expectations.

5.09 Training & User Support Management

PROJ-FEA-GF09

As a State user support administrator

I want training, user guides, and help desk services delivered using State standards

So that users are supported and enabled throughout system adoption.

5.10 Operations & Maintenance Management

PROJ-FEA-GF10

As a State operations manager

I want maintenance, defect management, release control, and performance monitoring

So that system stability and operational continuity are sustained.

5.11 Business Continuity & Disaster Recovery

PROJ-FEA-GF11

As a State continuity and risk program owner

I want reliable BC/DR/CIR planning, exercises, and recovery capabilities

So that critical operations can resume during incidents or outages.

Part 6: Implementation/Project Management Approach

Describe the approach you would recommend for project managing this engagement.

Provide a list of the standard project management deliverables that you would normally produce for this type of engagement.

Provide a proposed list of project phases, major milestones, and an implementation time-line. Label this Attachment #4.

What types of difficulties have other clients experienced with implementation of the proposed solution?

Describe the experience and qualifications of the Project Manager you would offer as the resource for this engagement. Provide a copy of their resume and label it Attachment #5.

Part 7: Technical Services

Describe the technical services included in your proposal (e.g., business analysis, configuration, testing, implementation, etc.).

Provide a list of the standard deliverables for the technical services described above.

Describe your business analysis approach for the implementation of the Fish and Wildlife Point of Sale solution. Describe your requirements elicitation and documentation processes and deliverables.

How do you manage the process of gathering our business and technical requirements?

What methodology (e.g., workshops, interviews, document analysis) do you use to map our requirements to the COTS product's standard features?

How do you handle requirements that fall outside the COTS application's standard capabilities? What is the formal process for identifying a gap?

What is your standard deliverable/artifact that formally documents the agreed-upon scope (e.g., Requirements Traceability Matrix, Statement of Work)?

What is your formal Gap Analysis process? Who from your team is responsible for leading this activity?

For each identified gap, what is the decision framework used to determine whether it will be solved by:

Configuration (using built-in flexibility)?

Customization (developing new code)?

A process change on the State's end?

What is your policy and process for customizations? Are there limitations (e.g., only via APIs, no changes to core code)? How are these customizations supported and maintained during future product upgrades?

How is the impact of a customization on the overall system performance and stability measured and documented?

Describe how you document and manage other requirements related artifacts like acceptance criteria and business rules.

How do you ensure that the system, as implemented, meets the agreed-upon requirements? How do you associate or link business rules and acceptance criteria to requirements?

What is your approach to User Acceptance Testing (UAT) in relation to the requirements? Do you provide pre-built test cases linked to the requirements?

How do you demonstrate that a custom development or configuration has not negatively impacted other core system functions (regression testing)?

Provide a description of the roles/services/tasks the State will be expected to cover as part of this engagement. Describe any additional roles/services/tasks that are optional, but would be beneficial for the State to provide.

Describe your typical conversion plan to convert data from existing systems to your proposed solution (if applicable).

Describe and attach your typical Implementation Plan (label it Attachment #6), which shall include planning for the transition to maintenance and operations.

Describe the experience and qualifications of the technical resources proposed for this engagement. Provide their resume(s) and label them Attachment #7.

Describe the training that is included in your proposal.

Describe the system, administrator, and/or user documentation that is included in your proposal.

Part 8: Oral Demonstrations, Interviews and Trial Evaluation Period: The State reserves the right to,

Require a Vendor to present an Oral Demonstration of their proposed solution, preferably by the Vendor's Solution Experts and Information Technology staff that will be implementing the solution and respond to interview questions during the demonstration. The demonstration will be stand alone and should include a high-level overview of how the proposed solution meets the State's needs and will be limited to 90 minutes, then 30 minutes available for the State to ask questions about the proposed solution.

Request and be provided a Trial Evaluation (Hands-On Evaluation) Period of the proposed solution by State Evaluators. State Evaluators will have access to Vendor's Sandbox version of the proposed solution for Hands-On Evaluation which will include:

Hands-On Evaluation Setup Meeting prior to beginning of the Evaluation period with Vendor Representative, and State Representatives to review such items as

Account setup and types of roles.

Confirmation of Hands-On Evaluation duration dates.

Vendor Support contact during Hands-On Evaluation.

Setup of Kick-Off meeting with Vendor Representatives and State Evaluators.

Check-In meetings; setup of a minimum of two (2) meetings during Evaluation period.

How Vendor will respond to State questions and evaluation scripts findings (issues).

Pre-Hands-On Evaluation Support to ensure that all Evaluators have successfully logged into the Vendor's Sandbox.

Hands-On Evaluation Duration of Fifteen 15 Business Days.

First day of the Evaluation period, or prior to, a Kick-Off Meeting with Vendor Representatives, and State Evaluators for orientation of Vendor's Sandbox version of the solution.

Minimum of fourteen (14) business days of Hands-On Evaluation of Vendors proposed solution in Vendor's Sandbox.

Minimum of two (2) Check-In Meetings during Evaluation period with State Evaluators and Vendor Representatives to review any issues, blocks, features, and functionality discovered. It is preferred by the State that the first Check-In Meeting be in the first week of the Evaluation period.

All costs associated with oral demonstration, interviews, and Sandbox setup and usage for Hands-On Evaluation will be borne entirely by the Vendor.

Describe how you will make these items possible and what Vendor support will be provided during Hands-On Evaluation period.

Part 9: Maintenance and Support Services

Provide answers to the questions below regarding your company's Maintenance and Support Services:

Describe how adherence to your service levels is measured and what remedies you would provide the State when performance doesn't meet the standard?

Part 10: Pricing

Submit pricing for your proposed solution in the table below. Fill in only the lines that are applicable to your proposal. Insert lines for additional costs, but do not delete or rename any lines in the Table. Total each column and provide a total of all columns in the "Total Implementation, plus 5 Year Costs" box on the next page.

Describe any assumptions you have made in relation to the above cost and pricing information.

Provide pricing information for any volume discounts that are available based on the number of software licenses purchased or support years purchased.

Provide pricing for any Functional Requirements marked as "C" (feature is not available in the core solution, but can be provided with customization).

Part 11: Terms and Conditions

Exceptions to the States standard terms, conditions, and templates is strongly discouraged. Accordingly, exceptions may result in a determination that a bidder's proposal is not in the best interest of the State. However, if a bidder does wish to take exception to the State's terms, conditions, or templates they must indicate those objections in the table below. Add lines to the table below as needed. The State considers contractor documents the bidder wishes to append to the contract as exceptions.

Part 12: Certificate of Compliance/Authorized Company Signature

NON COLLUSION: Bidder hereby certifies that the prices quoted have been arrived at without collusion and that no prior information concerning these prices has been received from or given to a competitive company. If there is sufficient evidence to warrant investigation of the bid/contract process by the Office of the Attorney General, bidder understands that this paragraph might be used as a basis for litigation.

CONTRACT TERMS: Bidder hereby acknowledges that is has read, understands and agrees to the terms of this RFP, including Attachment C: Standard State Contract Provisions, and any other contract attachments included with this RFP.

Worker Classification Compliance Requirement: In accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), the following provisions and requirements apply to Bidder when the amount of its bid exceeds $250,000.00.

Self-Reporting. Bidder hereby self-reports the following information relating to past violations, convictions, suspensions, and any other information related to past performance relative to coding and classification of workers, that occurred in the previous 12 months.

Subcontractor Reporting. Bidder hereby acknowledges and agrees that if it is a successful bidder, prior to execution of any contract resulting from this RFP, Bidder will provide to the State a list of all proposed subcontractors and subcontractors' subcontractors, together with the identity of those subcontractors' workers compensation insurance providers, and additional required or requested information, as applicable, in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), and Bidder will provide any update of such list to the State as additional subcontractors are hired. Bidder further acknowledges and agrees that the failure to submit subcontractor reporting in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54) will constitute non-compliance and may result in cancellation of contract and/or restriction from bidding on future state contracts.

Executive Order 05 - 16: Climate Change Considerations in State Procurements Certification

Bidder certifies to the following (Bidder may attach any desired explanation or substantiation. Please also note that Bidder may be asked to provide documentation for any applicable claims):

Bidder owns, leases or utilizes, for business purposes, space that has received:

Energy Star(R) Certification

LEED(R), Green Globes(R), or Living Buildings ChallengeSM Certification

Other internationally recognized building certification:

____________________________________________________________________________

2. Bidder has received incentives or rebates from an Energy Efficiency Utility or Energy Efficiency Program in the last five years for energy efficient improvements made at bidder's place of business. Please explain:

_____________________________________________________________________________

3. Please Check all that apply:

Bidder can claim on-site renewable power or anaerobic-digester power ("cow-power"). Or bidder consumes renewable electricity through voluntary purchase or offset, provided no such claimed power can be double-claimed by another party.

Bidder uses renewable biomass or bio-fuel for the purposes of thermal (heat) energy at its place of business.

Bidder's heating system has modern, high-efficiency units (boilers, furnaces, stoves, etc.), having reduced emissions of particulate matter and other air pollutants.

Bidder tracks its energy consumption and harmful greenhouse gas emissions. What tool is used to do this? _____________________

Bidder promotes the use of plug-in electric vehicles by providing electric vehicle charging, electric fleet vehicles, preferred parking, designated parking, purchase or lease incentives, etc..

Bidder offers employees an option for a fossil fuel divestment retirement account.

Bidder offers products or services that reduce waste, conserve water, or promote energy efficiency and conservation. Please explain:

____________________________________________________________________________

____________________________________________________________________________

Please list any additional practices that promote clean energy and take action to address climate change:

_____________________________________________________________________________

___________________________________________________________________________ _

_____________________________________________________________________________

Executive Order 02 - 22: Solidarity with the Ukrainian People

By checking this box, Bidder certifies that none of the goods, products, or materials offered in response to this solicitation are Russian-sourced goods or produced by Russian entities. If Bidder is unable to check the box, it shall indicate in the table below which of the applicable offerings are Russian-sourced goods and/or which are produced by Russian entities. An additional column is provided for any note or comment that you may have.

Certification Regarding Use of Contract Funds for Lobbying. The following provision is applicable to the Contractor for contracts over $100,000.00, and Contractor shall include this clause in all its subcontracts over $100,000.00.

1. The prospective contractor certifies, to the best of his or her knowledge and belief, under the penalties of perjury under the laws of the State of Vermont and the United States that on behalf of the person, firm, association, or corporation he or she represents, that:

a. No Federal appropriated funds have been paid or will be paid, by or on behalf of the undersigned, to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with the awarding of any Federal contract, the making of any Federal grant, the making of any Federal loan, the entering into of any cooperative agreement, and the extension, continuation, renewal, amendment, or modification of any Federal contract, grant, loan, or cooperative agreement.

b. If any funds other than Federal appropriated funds have been paid or will be paid to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with this Federal contract, grant, loan, or cooperative agreement, the undersigned shall complete and submit Standard Form-LLL, "Disclosure Form to Report Lobbying," in accordance with its instructions.

2. This certification is a material representation of fact upon which reliance was placed when this transaction was made or entered into. Submission of this certification is a prerequisite for making or entering into this transaction imposed by 31 U.S.C. 1352. Any person who fails to file the required certification shall be subject to a civil penalty of not less than $10,000 and not more than $100,000 for each such failure.

3. The prospective contractor also agrees that they shall require that the language of this certification be included in all lower tier subcontracts, which exceed $100,000 and that all such recipients shall certify and disclose accordingly.

For your bid to be considered valid, this Bidder Response Form must be signed by a duly authorized representative of the bidder, and submitted as part of the response to the proposal.

I am authorized to submit a proposal to the State of Vermont in response to this RFP on behalf of my organization. The information provided as part of my organization's response is a true and accurate representation of my organization's ability to meet the State of Vermont's business needs as expressed in this RFP.

Item Detail
Company Name: [insert the name that you do business under]
Physical Address: [if more than one office - put the address of your head office]
Postal Address: [e.g. P.O Box address]
Business Website: [url address]
Type of Entity (Legal Status): [sole trader/partnership/limited liability company or specify other]
Primary Contact: [name of the person responsible for communicating with the Buyer]
Title: [job title or position]
Email Address: [email]
Phone Number: [landline]
Fax Number: [fax]
Reference 1 Detail
Reference Company Name: [insert the name that you do business under]
Company Address: [address]
Type of Industry: [industry type: e.g., government, telecommunications, etc.]
Contact Name: [if applicable]
Contact Phone Number: [phone]
Contact Email Address: [email]
Description of system(s) implemented: [description]
Date of Implementation: [date]
Reference 2 Detail
Reference Company Name: [insert the name that you do business under]
Company Address: [address]
Type of Industry: [industry type: e.g., government, telecommunications, etc.]
Contact Name: [if applicable]
Contact Phone Number: [phone]
Contact Email Address: [email]
Description of system(s) implemented: [description]
Date of Implementation: [date]
Reference 3 Detail
Reference Company Name: [insert the name that you do business under]
Company Address: [address]
Type of Industry: [industry type: e.g., government, telecommunications, etc.]
Contact Name: [if applicable]
Contact Phone Number: [phone]
Contact Email Address: [email]
Description of system(s) implemented: [description]
Date of Implementation: [date]
Vendor Response/Explanation Vendor Response/Explanation
Question Yes or No
Does the solution use Service Oriented Architecture for integration?
Does the solution use a Rules Engine for business rules?
Does the solution use any Master Data Management?
Does the solution use any Enterprise Content Management software?
Does the solution use any Case Management software?
Does the solution use any Business Intelligence software?
Does the solution use any Database software?
Does the solution use any Business Process Management software?
Is this a browser-based solution and if so, what browsers do you support? (Describe desktop and mobile support.)
Does the solution include an API for integration?
State ID Description Availability Vendor Comments
Manage Permits and Licenses Manage Permits and Licenses Manage Permits and Licenses Manage Permits and Licenses
163 As a Licensing Admin, I want the ability to electronically share a License/Permit with a Customer So that they have immediate access to their current License/Permit.
164 As an FWD Admin, I want the ability to set License Expiration Dates by Type of License, So that variability in Expiration dates is enabled to better serve customers.
413 As a customer, I want to view and print my previous year's license with a "void" watermark, So that I can use the information to get a license out of state.
414 As an admin, I want to be able to indicate a customer has a mobility disability, So that all their future licenses will be noted with an off-road permit designation.
415 As a customer with a mobility disability, I want all my future licenses to have the off-road permit, So that I am able to hunt off the traveled portion of the highway.
430 As an Admin, I want to be able to deactivate a Lifetime license when the payment fails, So that the unpaid Lifetime license is invalid.
462 As an Admin or Agent I want to be able to enter an affidavit for a customer, So that I am able to sell them a license.
538 As an Admin, I want to update letter templates, So that the letter templates reflect our current business needs.
708 As a Customer, I want to be able to purchase a License and or Permit, So that I can hunt and or fish in the state of Vermont.
Messaging to Agent(s) Messaging to Agent(s) Messaging to Agent(s) Messaging to Agent(s)
559 As an Administrator, I want to be able to send Alerts within the Solution So that I am able to communicate high level or time-critical information.
560 As an Administrator, I want to communicate any new policies and laws via alerts So that our Agents and Big Game Reporting Stations have this information before the season starts.
561 As an Agent or Big Game Reporting Station I must be able to dismiss alert(s) So that I don't see them every time I login.
563 As an Agent or Big Game Reporting Station, I must be able to view active and dismissed alerts, So I can keep track of alerts that have been sent.
564 As an Administrator, I want to be able to edit active alerts So I can change the notification as needed.
565 As an Admin, I want to be able to delete active alert(s) So I can remove alerts that are no longer needed.
682 As an Administrator, I want to be able to schedule an Alert to be sent out at a later date and time, So that I can prepare a message before it will be sent.
683 As an Administrator, I want to be able to create reoccurring Alerts, So that I don't have to keep creating the same Alert(s).
554 As an Admin, I want to be able to create and send an Alert to Licensing Agent(s) and or Big Game Reporting Station(s), So that I can communicate effectively.
555 An Agent or Big Game Reporting Station, I want to be able to dismiss my active alerts, So that I can maintain my alerts.
Reports and Analytics Reports and Analytics Reports and Analytics Reports and Analytics
383 As ANR Staff, I want configurable monitoring and notification functions, So stakeholders are alerted to events and conditions.
459 As a FWD Data Analyst, Staff Member I want to run an ad hoc query and export the data So that I am able to analyze the data outside of the Solution
Payment Processing Payment Processing Payment Processing Payment Processing
20 As a Guest, Customer or Admin, I want to purchase multiple items in a single transaction So that I do not have to purchase each item separately.
76 As an Admin, I want to be able to refund a Gift Certificate, So that I am able to manage payments.
161 As a system user, I want to view the total amount due for any combination of License(s), Permit(s), and Lottery Application(s) So I know the total amount due for the purchase
376 As a License Agent, I want to be able to process Customer Payments, So that I am able to sell licenses/permits to a Customer.
377 As an FWD Admin, I want to be able to process Customer Payments, So that a Customer does not need online access to make a payment.
378 As a FWD Admin, I want to be able to assist a Customer who is struggling to complete a purchase online So that I am able to get into their account and advise them on how to complete their transaction.
432 As a Customer, Admin, or Agent I must be able to complete the Residency status So that the list of available license, permit, and lottery SKUs are based on my residency and age.
433 As a Customer, Agent or Admin, If either prior year license history or hunter education certification does not exist in the Customer's license history related to the license or permit being purchased, An affidavit must be completed.
436 As a FWD Admin, I need to have a weekly ACH Process run to transfer the Agent Net Total from each Agent's bank account So that we are able to receive License and Permit fees from Agents.
437 As an FWD Admin, I want an Error Report generated when the weekly ACH withdrawal runs So that I am able to see which Agent payment failed, and the failure reason
438 As an FWD Admin, I want to ensure that an Agent's Negative Balance is maintained in the ACH Process So that I do not have to pay the Agent a refund
439 As a FWD Admin, If a weekly ACH withdrawal from an agent's bank account fails, I want the ACH Process to attempt a second withdrawal So that the ACH withdrawal can be completed
449 As a customer, Admin or Agent, I want to be able to enter a donation amount, So that the donation equals the desired amount.
451 As a Customer, Admin, or Agent, I want to be able to add additional SKUs to any license So that I can print all SKUs on an existing License.
Manage Gift Certificates Manage Gift Certificates Manage Gift Certificates Manage Gift Certificates
23 As a Guest, I want to purchase a Gift Certificate So that I can give it as a gift.
24 As a Customer, I want to purchase or redeem a Gift Certificate from a FWL Office So that I can accomplish the transaction without going online.
25 As a Customer, I want to purchase a Gift Certificate from a FWL Office So that I can accomplish the transaction in person.
26 As an FWD Admin, I want to manage the purchase and redemption of on-line, in-person, emailed, and mailed transactions of Gift Certificates, So that the Certificates can be effectively tracked
69 As an Admin, I want to be able to sell a Gift Certificate(s) to a customer and enter the purchase and payment into the Solution So that a customer is able to purchase a Gift Certificate without online access.
70 As a Customer, I need to apply gift certificate(s) to my purchase So that I can reduce the total amount due.
72 As an Admin, I want to be able to print/reprint a customer's Gift Certificate So that they have proof of their transaction.
73 As an Admin, I want to be able to look up a Gift Certificate by filtering on data points So that I am able to view and edit the Gift Certificate.
74 As an Admin, I want to be able send/resend a Gift Certificate to a Customer, So that I am able to provide customer service.
75 As an Admin, I want to be able to void a Gift Certificate, So that I am able to resolve issues.
77 As an Admin, I want to be able to look up a Gift Certificate by Redemption ID or any other identifier used at the time of purchase, So that I am able to see who redeemed it.
158 As a Customer or Admin, I need to be able to lookup the balance of a Gift Certificate, So that I know if there is a high enough balance to make a purchase
159 As an Admin, I must be able to edit the Gift Certificate format, So that the format can be changed
Interfaces Interfaces Interfaces Interfaces
215 As a FWL staff member, I want to interface with the Kalkomey system, So I can look up a Customer's Hunter Education information.
Game Warden Lookup Game Warden Lookup Game Warden Lookup Game Warden Lookup
105 As a Game Warden and Law enforcement Admin and Licensing Admin, I want to be able to select a Letter, So that I am able to reprint or electronically transmit a letter to a Customer.
87 As a Game Warden, Law Enforcement Admin and Licensing Admin, I want to look up an individual Customer's license data, license history, harvest data, and note field, So that I can access their data.
92 As a Game Warden and Law enforcement Admin and Licensing Admin, I want to look up for an individual Customer by specific data points, So that I am able to review Customer information.
94 As a Game Warden, Law Enforcement Admin and Licensing Admin, I want to view a Customer's list of completed Hunter's Education courses, So that I am aware of their current Hunter's Education status.
95 As a Game Warden and Law enforcement Admin and Licensing Admin, I want to be able to view a customer's red flag status, active points, and the Game Warden(s) who issued the violation(s), So that I have their present status under the current enforcement policy.
96 As a Game Warden and Law enforcement Admin and Licensing Admin, I want to be able to enter notes associated with a Customer profile, So that I can communicate with other wardens working on a case.
97 As a Game Warden, I want to be able to follow a customer, So that I receive a notification when a customer purchases, attempts purchase, adds a harvest record, or when they get red flagged.
101 As a Law Enforcement Admin, Licensing Admin I want to ensure a Customer Profile is created for a person in the Interstate Wildlife Violators Compact (IWVC) file who lacks a Customer Profile, So that FWD laws are enforced consistently with cross-state customers.
103 As a Law Enforcement Admin, Licensing Admin I want to be able to enter a completion date for a Remedial Ethics course, So that a Customer profile reflects a point of compliance.
104 As a Law Enforcement Admin, Licensing Admin I want to be able to select, view, and/or print a letter So that we can notify the customer of their current status.
106 As a Game Warden, I want to receive an alert when a Customer Red Flag has been removed So that I no longer need to continue monitoring the Customer.
390 As a Law Enforcement Admin, Licensing Admin, I want to send a letter to a Vermont Customer who has an IWVC violation in another state, notifying them that they are also Red Flagged in Vermont, So that FWD laws are enforced consistently with cross-state customers.
Marketing Tool Marketing Tool Marketing Tool Marketing Tool
549 As an ANRFWL employee, I want to utilize the CRM system for Data Integrations So that I can integrate various business data like Customer, Agent, Product, Transaction, Event, Certifications, and Marketing data.
550 As an ANRFWL employee, I want to utilize the CRM system for Marketing Automations So that Return on Investment (ROI) tracking is available
551 As an ANRFWL employee, I want to utilize the CRM system for Marketing Automations So that Campaign segmentation is available
552 As an ANRFWL employee, I want to be able to query the CRM system, So that we are able to effectively target specific audiences.
553 As an ANRFWL employee, I want to utilize the CRM system for Marketing Automations So that an email drip campaign is available
562 As an ANRFWL employee, I want to utilize the CRM system for Marketing Automations So that dynamic content capabilities are available
566 As an ANRFWL employee, I want to utilize the CRM system for Marketing Automations So that integrated survey capabilities are available
567 As an ANRFWL employee, I want to geo target Customers, So that I can focus marketing on a specific area
568 As a FWL employee, I want to be able to market our offerings to potential customers "non-license holders", So that FWL can perform outreach by informing customers of options and offers including auto renewals.
693 As an ANRFWL employee, I want to utilize the CRM system for sending SMS texts So that outreach is received via SMS text
Manage Profile Manage Profile Manage Profile Manage Profile
107 As a Law Enforcement Admin, Licensing Admin I want to remove a Customer's Red Flag, So that a Customer's Profile is no longer restricted.
130 As a Customer, I want to create an Individual Profile for myself online, So that I can manage my own data.
134 As a Customer, I want the option to Auto-Renew my License based on business rules So that my License remains current without further action on my part
136 As a Customer I want to have a mandatory password for my Profile, So that I can secure my data.
137 As a Licensing Admin I want to be able to indicate a Customer is Deceased, So that a Deceased Customer's profile is no longer Active.
138 As a Customer, Admin, or Warden I want to be able to view Customer Hunter Education Certification History, So that I know if the legal requirements have been met for permits/licenses.
139 As a Licensing Admin, Enforcement Admin, I want to be able to merge Customer Profiles, So that we have a single unique Customer Profile for each individual.
140 As a Customer, Admin, Game Warden, Biologist I want to be able to look up a bear harvest So that I am able to see data on a bear harvest.
141 As a Customer/Admin/Game Warden/Biologist I want to be able to look up a deer harvest So that I am able to see deer harvest data.
142 As Customer/Admin I want to be able to look up Moose Bonus points So that I am able to view Moose Bonus point data.
143 As a Law Enforcement Admin, Licensing Admin or Warden I want to be able to view Customer History, So that I am aware of prior license, hunter education certification, harvest and infraction history
144 As a Customer or Admin, I want to be able to view or print current License(s)/Permit(s) So that I can provide proof of current or past License(s)/Permit(s).
166 As an FWD Admin, I want the Bear and Deer Tooth Age data to be part of Harvest history, So that access to wildlife data and Customer Harvest data is simplified.
167 As a Customer I want to view how many Moose Bonus Points I have So that I am able to see how many entries I have into the lottery.
181 As License Agent, I want to be able create, view and update a Customer Profile So that I can issue licenses to a customer.
202 As an FWD Admin, I want to be able to edit or update any field within a Customer Profile, So I can fix issues as they arise.
203 As an FWD Admin, I want to be able to reset a Customer's password with a reset email link, So I can help a customer who is having a hard time resetting their own password.
206 As a Licensing Admin, Enforcement Admin, Customer, Game Warden I want to be able to view the Infraction History So that I am able to evaluate if a customer is legally eligible to purchase a License/Permit.
569 As a Customer, I want to create a profile, So that I can purchase a license online.
Manage Lottery Manage Lottery Manage Lottery Manage Lottery
477 As a Customer, I want to be able to apply for the Moose lottery, So that I can attempt to obtain a Moose permit.
632 As an Administrator, I want to be able to run the Moose lotteries electronically, So that the system will randomly select the winners.
650 As an Administrator, I want to draw the Moose Lottery alternates when drawing winners for Moose lottery, So that I do not have to do a second drawing.
655 As an Administrator, I want the system to send out an email to each customer who was drawn as an alternate in the Moose Lottery, So that these customers are aware of their status in the lottery.
656 As an Administrator, I want the system to send out the winner's packet to an alternate that has been selected as a winner, So that alternate customer will be able to complete the winner's packet by the deadline.
638 As an Administrator, I want to be able to edit lottery applications, So I can modify them if needed.
639 As an Administrator, I want to be able to add a note to a lottery applicant's application, So I can keep track of observations and other relevant information related to the applicant's application.
633 As an Administrator, I want to be able to run the Lottery of a Lifetime electronically, So that the system will randomly select the winner.
478 As a Customer, I want to be able to apply for the Antlerless Deer lottery, So that I can enter the lottery for a chance to obtain an Antlerless Deer permit.
482 As a Customer who did not win a lottery, I want to know if I can purchase an Unallocated Antlerless Permit So that I can still participate in the hunting season.
636 As an Administrator, I want to be able to run the Antlerless lotteries electronically, So that the system will randomly select the winners.
476 As a Non-Resident Customer, I want to be able to apply for the Bear Dog lottery, So that I can enter the lottery for a chance to get a Bear Dog permit.
635 As an Administrator, I want to be able to run the Bear Dog lottery electronically, So that the system will randomly select the winners.
479 As a Customer, I want to be able to apply for the Coyote lottery, So that I can attempt to obtain a Coyote Dog Permit.
634 As an Administrator, I want to be able to run the Coyote Dog lottery electronically, So that the system will randomly select the winners.
659 As an Admin, I want to be able to change the number of Coyote Dog Permits available for the current year, So that the number of permit amounts will match statue.
637 As an Administrator, I want the system to automatically calculate and add bonus points as needed for the Moose lottery, So I do not have to calculate them manually.
666 As a Customer, I want to see my accrued bonus points per lottery by year, So that I know how many bonus points I have accumulated.
470 As a Customer, I want to submit my bid by the deadline using the correct form So that I can participate in the auction.
475 As a Customer, I want to ensure my bid meets the minimum bid requirement So that it is considered valid for the auction.
641 As an Administrator, I want to be able upload the completed Moose Auction's Winner's packet, So I can issue the Moose permits electronically.
673 As a Customer, I want to be able to select my preferred payment method, So that I can purchase my Auction entry conveniently.
469 As a lottery winner, I want to receive a winner's packet, So that I can submit the required information by the deadline.
471 As a Customer, I want to know my lottery eligibility status So that I can see if I am eligible to enter into the Moose lotteries.
472 As a Customer, I want to ensure I have a profile, So that I can enter the lotteries.
481 As a Customer, I want to be able to view/reprint my license/permits after I win a lottery to include the updated changes, So that I comply with regulations.
483 As an Admin, I want to be able to turn on and off lotteries as needed based on business rules, So that we have flexibility with running our lotteries.
484 As a Customer, I want to be able to apply for any lottery online, So that it is convenient to apply.
485 As a Customer, I want to be able to apply for any and all lotteries that I am eligible for, So that I am able to secure licenses/permits via the lottery system.
671 As a Customer, I want to be able to select my preferred payment method, So that I can purchase my lottery entry conveniently.
675 As a Customer, I want my lottery application to be prefilled with information from my profile, So that I do not have to type out my information that is already in the system.
Manage Lifetime Licenses Manage Lifetime Licenses Manage Lifetime Licenses Manage Lifetime Licenses
49 As a Vermont Customer at least 66 years of age I want to be able to purchase a Permanent License So that I can obtain an individualized license based on my interests and eligibility.
465 As an FWD Admin and staff member, I want to be able to manage a Customer's Lifetime License Status within the Solution So that I may activate or inactivate a Lifetime License.
468 As an FWD Admin, I want to be able to upgrade a lifetime license (hunting or fishing only) to a lifetime combination license, So that a Customer's lifetime hunting or fishing license is upgraded to a lifetime combination license.
533 As an FWD Admin, I want the Solution to interface with Kalkomey So that a purchased Lifetime License is automatically activated when the certified and required Hunter Education course is completed.
703 As an FWD Admin and staff member, I want to be able to manage a Customer's Lifetime License hunting eligibility within the Solution So that I may activate or inactivate the hunting privilege of a Lifetime License.
Manage Harvest Manage Harvest Manage Harvest Manage Harvest
192 As an FWD Admin, I want to pull Bear Tooth and Deer Tooth history data to prefill a harvest application, So that I do not have to manually enter it.
165 As A Customer, I want to access my Bear and Deer Tooth History So that I am able to see the age of the animal I have harvested.
399 As a Customer, I want to view my harvest history, So that I can keep track of my previous harvests.
400 As a Customer, I want to be able to self-report my harvest, So that I can ensure my harvest records are complete and accurate.
401 As a Law Enforcement Admin, Licensing Admin, Big Game Reporting Station, Wardens, Biologists, I want to be able to record all kinds of harvests on behalf of customers, So that accurate harvest records are maintained.
402 As a Big Game Reporting Station, I want to edit harvest records I have entered, So that I can correct any errors and maintain accurate records.
403 As a Licensing Administrator, I want to be able to enter, edit, and delete any harvest record, So that I can ensure data integrity and accuracy.
404 As a Big Game Reporting Station, I want to be able to view harvest records I have entered, So that I can verify the data I am responsible for.
405 As a Law Enforcement Admin, Licensing Admin, Big Game Station, Biologist and customer, I want to be able to attach a picture of the game animal in the harvest record, So that there is visual confirmation of the harvest.
406 As a Licensing Admin, I want to be able to select which game can be self-reported, So that I can select which species with which seasons can be self-reported as needed.
407 As a System Administrator or any Administrator, I must be able to maintain all business rules, So that as these rules change, I can easily update them to ensure compliance and accuracy.
ID NFR Description Comply Vendor's Description of Compliance
63 Service Providers will agree to continue normal operations activities until completion of Transition-Out Plan activities.
64 Solutions will allow the user to export formatted reports from the system in industry standard formats, e.g., Word, Excel, PDF, and TXT.
66 Solutions will have a defined data migration strategy or process.
67 Solutions will provide tooling to support the Extract-Transform-Load (ETL) process that involves: Extracting data from data sources. Transforming to fit business needs (which can include quality levels). - Loading into the target data store. - Caching: The ability to cache federation results and various subsets of the source data to improve performance in situations where source data volumes are large; therefore, retrieving all data required for integration directly from the source is not feasible.
73 The ability to easily transfer data from one system to another without being required to re-enter data
78 Web services, including APIs, SOA, REST, and SOAP must not compromise end-to-end system security and adherence.
111 Solutions will support access from multiple channels and devices.
142 The solution's interfaces/integrations must continue to operate despite the failure or unavailability of individual technology components, such as an application platform or network connection.
ID NFR Description Comply Vendor's Description of Compliance
146 Solutions will provide the ability to recover from data loss due to end user error and end application error. Recovery includes the following: The ability to recover from data loss: The solutions will be able to restore or recover any data that is lost due to various reasons, such as hardware failure, network outage, human error, or malicious attack. Due to end user error: The solutions will be able to recover from data loss caused by mistakes or errors made by the end users of the solutions, such as deleting or modifying data accidentally or incorrectly. Due to end application error: The solutions will be able to recover from data loss caused by errors or bugs in the end applications that use the solutions, such as crashing, freezing, or corrupting data. (SaaS, PaaS)
151 For PaaS and IaaS solution providers, backup and Recovery Services will include operating system images, configuration files, database, code tree, hardware configurations and virtualization configurations. (PaaS, IaaS)
152 Solution providers must test Backup/Recovery procedures prior to the production launch of the system to validate the procedures and affirm ability to meet recovery requirements.
153 The recovery point objective (RPO) will meet State requirements as defined in the Service Level Agreement.
154 The recovery time objective (RTO) will meet State requirements as defined in the Service Level Agreement.
159 The solution provider is responsible for restoring the normal operation of the Production Environment, which is where the users can access and use the hosted services and data. (SaaS, PaaS, Iaas)
161 The solution provider will conduct an implementation readiness review at least ten days prior to production cutover. (SaaS, PaaS)
162 The solution provider will inform the State when it plans to use regular maintenance periods instead of a different time slot allocated for the State-specific Release Management tasks. (SaaS, PaaS). (SaaS, PaaS)
166 During testing, the solution provider will identify event-thresholds to be used for benchmarking the performance of the solution. (SaaS)
168 Solution provider will monitor critical performance parameters: these can included: CPU usage: the percentage of CPU resources consumed by the software. High CPU usage can affect the responsiveness and speed of the solution. Memory usage: the amount of memory allocated by the software. High memory usage can indicate high resource consumption and affect the performance of the solution Requests per minute and bytes per request: the number of requests received by the software's API per minute and the amount of data handled by each request. Latency and uptime: the delay between a user's action on the software and the response of the software to that action, and the availability of the software to serve requests. Security exposure: the degree to which the software is vulnerable to unauthorized access, modification, or damage. Execution time: the time taken by the software to complete a certain function or task. Throughput: the rate at which the software can process data or transactions.
171 The solution provider will schedule routine planned maintenance activities without disrupting the operational hours. (SaaS, PaaS)
173 In advance of any release or changes the solution provider will produce for the State the following: Change release documentation: that describes the changes made to the solution such as new features, bug fixes, and enhancements. Updated test scripts: instructions or commands that are used to verify the functionality and quality of the solution or system after changes have been made. Training: instructions on how to use the update to the solution will allow the State team to adequately test, verify, and train for support of smooth operation of the State's applications and solutions. (SaaS, PaaS)
174 The solution provider will prepare User Acceptance Testing (UAT) Plan to include, Unit, Integration, SIT, Regression, Stress/Performance. (SaaS, PaaS)
177 The IaaS solution provider will build the State's infrastructure utilizing physical and virtual separation of components. (IaaS)
700 The solution shall support continued point-of-sale operations during temporary loss of internet connectivity, including local transaction capture and secure store-and-forward synchronization once connectivity is restored.
702 The solution shall support reconciliation of offline and online transactions upon restoration of connectivity, including detection and resolution of duplicates, partial submissions, and synchronization conflicts.
ID NFR Description Comply Vendor's Description of Compliance
184 The solution must support automated analysis tools for identifying and reporting on issues such as code quality, security vulnerabilities, and performance bottlenecks.
188 The solution must support automated testing, with clear and well-defined test cases and test data.
189 The solution must have clear and well-defined interfaces and APIs for testing and simulation purposes.
190 The solution must support the use of testing and simulation tools to facilitate unit testing, integration testing, and performance testing.
193 If required for the solution, the network design and network connection configuration, which includes a detailed cabling diagram for network connections between State and Solutions Provider data center locations, will be the responsibility of the Solutions Provider.
195 When proposing changes to the architecture of the solution, the solution provider will generate an updated logical architecture diagram.
198 To maintain the accuracy and integrity of the data, SaaS and PaaS solution providers must perform regular data system refreshes.
199 As part of the Run Book delivered prior to go-live, the Solutions Provider must maintain a logical Architecture Document that outlines the current configuration of all modular components, including third-party applications, in all enAs part of the Run Book delivered prior to go-live, the Solutions Provider will maintain a logical Architecture Document that outlines the current configuration of all modular components, including third-party applications, in all environments.
200 If required for the solution, Solutions Providers will submit to the State as part of their proposal: Specifications for all necessary hardware, software and tools for up to six (6) target environments: 1. Production (PRD), 2. Staging (STG), 3. Development (DEV), 4. Test (TST), 5. Training (TRN), and 6. Disaster Recovery (DR).
209 Solutions will have the capability to track and report usage.
210 Solutions Provider will install and manage required third party software.
214 Solutions Providers will provide a data dictionary and data model to the State.
216 Solutions Providers will provide version control management capability. All changes to Solutions will be reported and approved by the State, and will be maintained in the Solutions Provider's version control management solution, which will be available to the State for review and audit.
219 Solutions will have the ability for an administrator to create and maintain retention schedules as defined by the Vermont State Archives & Records Administration (VSARA).
224 Solutions will automatically calculate transfer and destruction dates (and assign records ready for deletion to the appropriate review process for approval of final deletion) for all records in the retention schedules.
225 Solutions will include a workflow tool to support the records management process.
ID NFR Description Comply Vendor's Description of Compliance
286 Solutions will provide the capability to identify and apply a rule change appropriately to existing cases.
289 Solutions will permit all users (dependent on role-based security and access rights) to have current and up-to-date information regarding a client's information when connected to solutions, given the operational and technical constraints of the data source(s). The data displayed will be time-stamped to reflect the currency of the data.
290 The State of Vermont (SOV) will access applications through a URL entered in a web browser.
291 Solutions will provide access to standardized reporting, ad hoc queries, and data visualization.
294 Solutions will provide the ability to maintain and display the history of each rule change in the rules engine.
296 If a survey engine is required for the solution, survey engine should provide a user-friendly interface, robust features, and customization options to create, distribute, and analyze surveys effectively.
297 Solutions will provide index-based search capabilities.
300 Service Providers will develop a user guide that can be accessed online and printed on demand.
302 Solutions will provide the capability to access the output of the document management system over the Internet and/or Intranet web sites via web services.
304 The solution should conform to the web accessibility guidelines specified by the W3C level 2 accessibility guidelines, ensuring that the application is accessible to users with disabilities. The system should meet the standards outlined in the guidelines to provide an inclusive and user-friendly experience for all users, regardless of their abilities. The application should be designed to accommodate a wide range of assistive technologies and should be tested to ensure compliance with accessibility guidelines
306 Information will be provided to applicants and enrollees in plain language and in a manner that is accessible and timely. Individuals living with disabilities including accessible web sites and the provision of auxiliary aids and services at no cost to the individual in accordance with the Americans with Disabilities Act and sections 504 / 508 of the Rehabilitation Act. Individuals who are limited English proficient through the provision of language services at no cost to the individual, including oral interpretation, written translations. Taglines in non-English languages indicating the availability of language services.
307 Solutions will provide speech and hearing-impaired person with the ability to communicate through a Teletypewriter (TTY) or Telecommunications Display Device (TDD).
308 Solutions will provide the ability for user to create and customize reports, queries, and dashboards.
312 Solutions will generate ad-hoc and standard reports in real time, as well as historical for incoming and outgoing contacts.
314 Solutions will allow for user analytics to be captured and reported.
316 Solutions will provide support for full text search.
321 Solutions will enable central workflow alerts and transactional status. Solutions will centralize pending work items for the user as in a work queue.
322 The system should provide the ability to create, customize and interact with the system and should provide the ability to create, customize and interact with multi-dimensional views and tables, enabling users to explore data and gain insights into complex relationships between various dimensions.
331 Solutions will highlight and flag required and incomplete data fields.
494 If required for the solution, the service provider will assist the State of Vermont (SOV) in preparing their desktops, networks, infrastructure, and applications.
701 The solution shall allow authorized Game Wardens to access relevant licensing, permit, and compliance information on approved mobile or peripheral devices while operating in remote or wilderness environments, including support for intermittent or offline connectivity.
704 When operating with offline or intermittent connectivity, the solution shall clearly indicate data freshness and last synchronization time to the user.
ID NFR Description Comply Vendor's Description of Compliance
382 The solution must test and validate new features and updates before releasing them to the customers using automated tools and processes.
385 The solution must comply with the relevant laws, regulations, standards, and best practices for data security, privacy, accessibility, and ethics.
386 The solution must maintain a consistent and coherent user interface and user experience across different devices, browsers, and platforms.
388 The solution must collaborate with other stakeholders such as developers, testers, customers, users, partners, vendors, etc. using communication and coordination tools and methods.
389 The solution must evolve and improve continuously by applying agile principles and practices such as iterative development, feedback loops, retrospectives, etc.
396 The solution must automate repetitive or tedious tasks such as backups, notifications, reports, etc. by using automation tools and scripts.
ID NFR Description Comply Vendor's Description of Compliance
401 Service provider will collect performance and capacity metrics (including monitoring alerts or incidents) and will conduct analysis of metrics to identify and remedy any possible capacity issues.
411 Server workloads will scale on-demand without shutting down the application to provide continuous scalability.
416 The Relational Database Management System (RDBMS) must have the ability to support advanced configurations for storing data temporarily in a cache. This includes the ability to support caching on the client or application side as well as on the server side. Caching is a technique used to improve the performance of a system by temporarily storing frequently accessed data in a location that is faster to access than the original data source.
421 The solution must scale up or down automatically based on the demand and traffic patterns.
422 The solution must have a monitoring and logging mechanism to track and report the performance metrics and errors.
423 The solution must have a performance testing and tuning mechanism to identify and resolve any performance issues or bottlenecks.
424 The solution must support multiple browsers and devices with different screen sizes and resolutions.
ID NFR Description Comply Vendor's Description of Compliance
436 Solutions will provide the ability for online access by any site connected to the State of Vermont's Network.
441 The Solution must use normalized data formats for all data transformations. Normalized data formats simplify composition, meaning that it is easier to combine data from different sources. This reduces the number of transformations that are needed, which in turn improves compatibility of the system.
446 The solution will provide comprehensive and flexible integration capabilities through secure, standards-based interfaces, including documented APIs, event interfaces, file exchange, and approved adapters where necessary. These capabilities will support integration with external systems, legacy platforms, packaged applications, web services, and structured or semi-structured data sources. Direct database-level connectivity to the solution's production datastore will not be the State's preferred integration method unless explicitly approved for a specific use case.
447 The solution must provide the capability to perform source to destination file integrity checks for exchange data and alert appropriate parties with issues.
455 The solution database will have data replication capabilities to external file formats or other RDBM Systems.
457 The solution database will provide standard data extraction API to allow import and export of data.
459 Solutions will define what is the level and complexity of data transformations required to support the information exchange needs between applications
460 Solutions will define what will be the requirement for software in supporting data integration with the enterprise's customers and suppliers
461 Solutions will adhere to or create common methods and tools for creating, maintaining, and accessing the data shared across the enterprise.
466 Full refreshes will consist of copying the database and full application code from the source environment to the target environment and making the required configuration changes within the database and application of the target environment.
467 Partial refreshes will consist of copying of the database and/or part of the application code from the source environment to the target environment and making the required configuration changes within the database and application of the target environment.
469 Solutions will include data modeling capability that is configurable, customizable, extensible, and upgradable.
471 Data de-duplication and cleansing will be employed on all mastered subject areas.
472 Data de-duplication and cleansing will be employed in all application software to minimize the entry of 'dirty' data into a target environment or other solutions.
479 The software shall support backward compatibility with at least two previous versions of the software, ensuring that users can upgrade without losing any important data or functionality.
480 The software shall maintain data integrity when transitioning from older versions to newer versions, ensuring that users can access their previous data without any errors or inconsistencies.
484 The software shall be designed with flexibility to accommodate future changes and updates, ensuring that future versions of the software will be able to function correctly without significant modification.
485 The software shall support easy data migration from the current version to future versions of the software, ensuring that users can upgrade without losing any important data or functionality
486 The software shall provide stable APIs (Application Programming Interfaces) that are compatible with future versions of the software, ensuring that any third-party integrations or plugins continue to function correctly.
487 The software shall be designed with scalability in mind, ensuring that future versions of the software can handle increased workload or data volumes without performance degradation.
490 The software shall provide a high level of configurability, allowing users to customize the software to meet their specific needs and preferences.
495 Data transformations will be to and from normalized formats. Normalized data formats facilitate composition and reduce the number of transformations that will be created and maintained. A canonical data representation that spans the enterprise will be used but is not required. A federated approach to data normalization is required.
501 Solution will define the requirement for all software to support data integration with other systems
507 Database data exports will contain all data from the State of Vermont (SOV)'s production database(s) or the subset of data specified in the data export request.
619 If the application records any information also collected by Okta (e.g., First Name, Last Name, Email required; Alternative Email, Phone, or DOB) then the application must source and update that data from Okta at each login unless directed otherwise by the Agency. The application must also provide an endpoint to receive real-time user profile updates should the state decide to push such data to the application.
625 Salesforce applications must use established state protocol for the Salesforce and Okta integration, including use of OIDC auth providers and the State's common handler code.
ID NFR Description Comply Vendor's Description of Compliance
428 Data center facilities must be located within the United States to comply with jurisdictional regulations.
515 Solutions handling Federal Tax Information (FTI) or other sensitive data must comply with FedRamp standards to ensure data security and regulatory compliance.
516 Access to the environment via the State of Vermont internal network must be controlled by a firewall that validates communications based on recognized protocols and approved source/destination IP address ranges.
517 Applications accessible from the public internet must be deployed on dedicated Demilitarized Zone (DMZ) servers managed by the Contractor to ensure security and isolation from internal networks.
518 Contractor personnel must be authorized by the provider for network and system access across all environments to maintain security and control.
523 The Contractor must maintain an isolated support network separate from its intranet, including firewall, VPN, intrusion detection, authentication, reporting, and DNS services, as the standard method for personnel to connect to the environment.
526 The Contractor must manage access control to its data centers and the environment, limiting access to State of Vermont's network connections to authorized personnel only.
529 Intrusion Detection Systems (IDS) must provide continuous surveillance to intercept and respond to security events, with alerts forwarded to the hosting service provider's IT security and service desk for review and response.
530 Secure Socket Layer (SSL) must be deployed for all web-based applications hosted by the Contractor, especially those accessible via the internet or secure networks like hardware VPNs, ensuring secure data transmission.
531 The Contractor must deploy non-Secure Socket Layer (SSL) applications privately, accessible only through secure network connections and not exposed to the public internet, with State of Vermont connections to non-internet applications using SSL and secure network connections.
532 Secure Socket Layer (SSL) -enabled web applications accessed by the State of Vermont (SOV) via the public internet must be deployed internally by the Contractor over SOV's network, with the hosting provider procuring and maintaining SSL certificates on behalf of the SOV.
533 The Contractor must utilize VPN devices in a site-to-site (network-to-network) configuration, leveraging either the public internet or dedicated links for secure data transmission.
534 Internet Protocol Security (IPsec) must be implemented within the VPN strategy to secure data using tunneling and encryption (168-bit Triple DES or AES256) for data privacy.
535 Standard network connectivity between the Contractor and the State of Vermont must be established through a hardware VPN provided by the hosting service provider.
538 Access to logs must be restricted to authorized personnel based on need-to-know and least privilege principles, with log files protected using SHA1 cryptographic hash sums and monitored, and logs accessible via intranet systems relocated daily to non-intranet systems.
539 Access control policies and procedures must govern resource access within the State of Vermont environment, including physical servers, files, directories, services, database tables, and network protocols.
540 Least Privilege and Separation of Duties (SOD) principles must be applied to all solutions, ensuring user permissions and system functionality align with specific roles based on access needs.
541 New deployments within Contractor data centers must undergo security technical reviews by a cross-organization team, including dedicated security experts, and technologies or tools not meeting security policies or standards must not be deployed.
542 Security and compliance standards for deployment environments must remain consistent whether in production or non-production settings.
543 All permanent or contract employees handling data must complete data privacy awareness and corporate ethics training, including understanding data privacy, recognizing risks related to personal data, understanding their data responsibilities, and reporting privacy violations.
546 Server instances within deployment environments must be isolated via firewalls based on their application role.
547 Remote access for Contractor employees and subcontractors must require IPsec or SSL-encrypted VPN connections from non-hosting service provider locations to access the network.
549 Access provisioning must be centralized and based on job roles, requiring management approval to ensure appropriate access levels are maintained.
550 Access to operating systems must require secure login procedures with unique user IDs and strong passwords to protect system integrity.
551 Root passwords for hosts and facilities must be changed every 30 days to enhance security and prevent unauthorized access.
553 Employees must maintain confidentiality of state data by signing confidentiality agreements and complying with company policies on the protection of confidential information.
554 Network controls must protect and control State of Vermont data during transmission, ensuring all connected devices comply with security standards and policies.
555 Designated personnel must handle removable digital media according to defined procedures, with media securely transported, logged, and vaulted by a third-party service provider under contractual obligations to comply with hosting provider-defined media protection terms.
556 Intrusion Detection Systems (IDS) must provide continuous surveillance to intercept and respond to security events, ensuring timely detection and mitigation of threats.
557 State of Vermont data must not be stored on removable drives or mediums unless encrypted to safeguard sensitive information.
558 Strict restrictions must be maintained over the distribution of media containing state health information, complying with information protection, media sanitization, privacy, and records retention policies.
561 Database passwords must be changed every 180 days to ensure ongoing security and prevent unauthorized access. Data integrity during transmission must be protected using strong encryption protocols such as TLS/SSL or IPsec, along with hashed Message Authentication Codes (HMAC-SHA-1) on VPN networks.
562 The Contractor must implement a Security Information and Event Management (SIEM) system to correlate and alert on security events from Intrusion Detection Systems (IDS), firewall logs, and network flow events, with monitoring conducted 24/7 throughout the year.
564 Third-party anti-virus and anti-spam products must scan all State of Vermont and employee emails and attachments traversing Contractor data centers, with the email infrastructure enforcing TLS encryption for both inbound and outbound emails.
565 Server operating systems must be hardened by eliminating unnecessary services, accounts, and network access rights to enhance security and reduce vulnerabilities.
566 The Contractor must evaluate and respond promptly to incidents of unauthorized access or handling of State of Vermont (SOV) data, collaborating with relevant teams and law enforcement to restore the confidentiality, integrity, and availability of SOV's environment.
571 Solution administrators must have the capability to create, manage, and assign user accounts with role-based access, including configurations for user groups, locations, and organizational hierarchy.
573 The solution must provide transaction tracking and log consolidation capabilities across the application's data tier to facilitate comprehensive monitoring and analysis.
574 The solution must maintain records of all data additions, changes, and deletions, which must be searchable by user/client ID, date/time, location, and other relevant details to ensure traceability and accountability.
575 Audit records must be protected from unauthorized modifications and require formal approval for any changes to maintain integrity and compliance.
579 The solution must utilize Single Sign-On (SSO) components for authentication and authorization to streamline user access and enhance security.
581 The solution must support the protection of Personally Identifiable Information (PII) through encryption or de-identification techniques to safeguard sensitive data.
582 The Contractor must certify code against OWASP Application Development Security Standards and mitigate risks outlined in CWE/SANS Top 25 Most Dangerous Software Errors.
616 When user requests to log in, or requests an authenticated page, they shall be redirected to the State's central login widget (currently at my.vermont.gov) in order to ensure that the user is challenged with State-approved authenticators in a State-approved user experience.
617 Authentication of external users will be handled with a SAML or OIDC connection with the State's Okta tenants in DEV, TEST and PROD environments. Internal users shall be authenticated with a SAML or OIDC connection to Entra. The State's preference is to have separate URLs for internal and external authentication. If the application can only facilitate a single auth provider but requires access for both internal and external users, Okta shall be established as the auth provider and will route internal users to Entra. If app functionality depends on internal or external status, the application must have a means to discern such states from OIDC claims, SAML attributes or other reliable method approved by the State.
618 With respect to user attributes required for the application use but not collected from general Okta registration, the Contractor shall ensure portions of the application are secured from users with incomplete profiles. The Contractor may request from ADS that Okta profile enrollment policies are used to capture app specific profile data with Okta, but ADS may decline to store such data within Okta for any internal reason.
620 Contractor shall make the application session length configurable and set in accordance with agency requirements.
621 Contractor shall ensure that all logout triggers, which are to be provided to all authenticated external users, are effective at terminating both the app session and the Okta SSO session.
622 For agencies requiring identity proofing, the application must redirect users with insufficient proofing confirmed on their OIDC claims or SAML attributes, to the state's remote proofing solution at id.vermont.gov or other proofing solution as directed by the State.
623 The application must have an efficient means of provisioning new users while adhering to principles of least privileged access. Unless another method is approved by the State, this should be accomplished by allowing any user login to the application but preventing use of any functionality as directed by the State until after an internal administrator has approved the user for elevated access. An administrator should be able to approve a user for access before or after their initial login.
624 If the application maintains its own user records, it must rely on the Okta alphanumeric unique guide for the subject, also known as a 'sub'. If a connection with an unknown Okta user is initially made with the Okta username (which is the user's email), the sub must then be used to maintain the connection going forward so as to prevent disruptions in application access if the user changes their email in Okta.
626 The system must support integration with the State of Vermont's identity providers (Entra for internal users and Okta for external such as providers) using SAML 2.0 or OpenID Connect, and otherwise in accordance with state protocol.
703 The solution shall support controlled access from approved mobile or peripheral devices, including the ability to revoke or disable access for lost, compromised, or decommissioned devices.
16222 The Contractor must ensure that the solution achieves compliance with applicable State and Federal regulations and standards as outlined in the National Institute of Standards and Technology (NIST) Publication 800-53, current revision, upon Operational Go-Live. Compliance must be verified through an independent third-party production security controls assessment. The Contractor must ensure an independent third-party production security controls assessment is conducted at least annually, at no additional cost to the State, and performed by a State-approved third party that has no financial or controlling relationship with the Contractor. The Contractor must be responsible for implementing modifications to maintain compliance with applicable State and Federal regulations and standards as outlined in the National Institute of Standards and Technology (NIST) Publication 800-53, current revision, including the application of compensating controls to address any identified gaps. The Contractor must provide documented results of the independent third-party production security controls assessment and develop corrective action plans for any deficiencies identified during the assessment. The Contractor must ensure all modifications necessary to maintain compliance with applicable State and Federal regulations and standards as outlined in the National Institute of Standards and Technology (NIST) Publication 800-53, current revision, are executed in accordance with the terms and conditions of the Contract.
16224 The Contractor must ensure the System Security Plan facilitates the development and submission of a Statement on Standards for Attestation Engagements (SSAE) 18, Service Organization Control (SOC) 2 Type II Compliance Report from hosting providers. The Contractor must ensure the System Security Plan supports the development and maintenance of organizational information security policies to ensure comprehensive protection of data. The Contractor must ensure the System Security Plan includes a Privacy Impact Analysis that identifies data elements of the system exposing Vermont beneficiaries to potential privacy threats and outlines system controls to mitigate risks of private data disclosure. The Contractor must ensure the System Security Plan establishes a security event notification process, event evaluation and escalation procedures, and security event response procedures to ensure timely and effective handling of security incidents. The Contractor must ensure the System Security Plan provides a complete network diagram detailing servers, printers, workstations, firewalls, intrusion prevention systems, network security device internet connections, and any other network-connected devices. The Contractor must ensure the System Security Plan includes firewall security standards and diagrams, showing sufficient detail of data flows in and out of security boundaries, including VPNs, subnets, ports, and protocols. The Contractor must ensure the System Security Plan includes a detailed strategy for system log collection and monitoring to ensure ongoing oversight and security. The Contractor must ensure the System Security Plan includes an antivirus deployment and maintenance plan to protect against malware and other security threats. The Contractor must ensure the System Security Plan incorporates a software maintenance strategy, including updates for operating systems and third-party software, to ensure systems remain secure and functional. The Contractor must attest that criminal background checks are completed and passed by all employees before they are granted access to State data. The Contractor must ensure the System Security Plan includes procedures to limit access to information to individuals who need it for their job functions, ensuring access is restricted to the minimum necessary information. The Contractor must ensure the System Security Plan describes how the physical safety of data under its control is protected using appropriate devices and methods, such as alarm systems, locked files, guards, or other devices to prevent loss or unauthorized access. The Contractor must ensure the System Security Plan includes procedures to prevent unauthorized use of passwords, access logs, badges, or other methods designed to prevent loss or unauthorized access to electronically or mechanically held data. The Contractor must agree to comply with Health Insurance Portability and Accountability Act (HIPAA) Privacy Rules as a Business Associate of the State, ensuring adherence to federal regulations.
16225 The Contractor must ensure that the System Security Plan complies with State and Federal laws, rules, regulations, standards, and guidelines to include the following: * NIST Publication 800-53 current revision * Federal Information Processing Standard (FIPS) 200 * The American Recovery and Reinvestment Act (ARRA) * Title XIX of the Social Security Act * Health Insurance Portability and Accountability Act of 1996 (HIPAA) * Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009
16226 The Contractor must ensure the system(s) maintains compliance with current and future security, privacy, accessibility, and certification laws (State and Federal), regulations, policies, and guidelines relevant to system security, confidentiality, integrity, availability, and safeguarding of information. Where any of these overlap, the Contractor must ensure that the system(s) must always strive to attain the more stringent policy. The Contractor retains responsibility for all modifications to the system(s) to maintain compliance according to the terms and conditions of the resulting Contract.
16238 The Contractor must maintain a Security Breach Response Team available 24 hours a day, 7 days a week, and within 5 minutes of notification of an incident to respond to security violations and breaches (physical and electronic). This includes communications to a defined list of personnel at the State tied to the State's Continuity of Operations/Disaster Recovery. State staff must be informed of response plan, including specific steps and time frames for resolution.
16241 The Contractor must provide a State-approved, 508-compliant user-centered designed and intuitive interface for Security Administrators to grant, track, manage, and revoke access for individuals. System must also provide auditing capabilities for approved audit resources.
16245 The Contractor must ensure all systems undergo Industry Standard security testing (e.g., penetration, physical security, web application, social engineering, and vulnerability tests) minimally on an annual basis, as mutually agreed upon between the Contractor and the State, when there has been a significant infrastructure change or resulting from Federal requirements. This security testing must be conducted at no cost to the State and by a State-approved third party that maintains no financial or controlling relationship with the Contractor. Additionally, the Contractor must provide documented testing results and generate corrective action plans for any deficiencies identified as well as be responsible for modifications to remain compliant based on the terms and conditions of the Contract.
16247 The Contractor must design and execute security testing to prevent unauthorized access to the system (intrusion detection and vulnerability testing) on a quarterly basis and provide a report of all findings to the State within 10 business days. Any issues identified and reported to the State are to be resolved according to their respective SLA.
32586 The Contractor must ensure State of Vermont (SOV) data is not stored, transmitted to, or accessed from outside the United States except as authorized in writing by SOV.
Type of Data Applicable State & Federal Standards, Policies, and Laws Comply Vendor's Description of Compliance
Publicly available information NIST 800-171
Confidential Personally Identifiable Information (PII) State law on Notification of Security Breaches State Law on Social Security Number Protection State law on the Protection of Personal Information National Institute of Standards & Technology: NIST SP 800-53 Revision 4 "Moderate" risk controls Privacy Act of 1974, 5 U.S.C. 552a.
Payment Card Information Payment Card Industry Data Security Standard (PCI DSS) v 3.2
Federal Tax Information Internal Revenue Service Tax Information Security Guidelines for Federal, State and Local Agencies: IRS Pub 1075
Personal Health Information (PHI) Health Insurance Portability and Accountability Act of 1996: HIPAA The Health Information Technology for Economic and Clinical Health Act HITECH Code of Federal Regulations 45 CFR 95.621
Type of Data Applicable State & Federal Standards, Policies, and Laws Comply Vendor's Description of Compliance
Affordable Care Act Personally Identifiable Information (PII) Internal Revenue Service Tax Information Security Guidelines for Federal, State and Local Agencies IRS Pub 1075 Minimum Acceptable Risk Standards for Exchanges MARS-E 2.0 (Scroll down the page)
Medicaid Information Medicaid Information Technology Architecture MITA3.0 Code of Federal Regulations 45 CFR 95.621
Prescription Information State law on the Confidentiality of Prescription Information
Student Education Data Family Educational Rights and Privacy Act: FERPA
Personal Information from Motor Vehicle Records Driver's Privacy Protection Act (Title XXX) ("DPPA") 18 U.S.C. Chapter 123, 2721 - 2725
Criminal Records Criminal Justice Information Security Policy: CJIS
Other sensitive data Data that does not fit into the above categories but is sensitive and requires additional protection.
Other: describe [List what's applicable or delete this line.]
ID Description Comply Vendor's Description of Compliance
GR-00001 The Contractor must follow project management methodologies as directed by the State that are consistent with the Project Management Institute's (PMI) Project Management Body of Knowledge (PMBOK) Guide v7 and Agile project management.
GR-00002 The Contractor must use the State-managed SharePoint Online Project Management Repository in accordance with State standards and expectations.
GR-00003 The Contractor must complete the activities specified in the Enterprise Project Management Office (EPMO) Project Lifecycle as published on the EPMO public-facing website.
GR-00004 The Contractor must provide, on a weekly basis, a current project schedule in Microsoft Project format (v2013 or later).
GR-00005 The Contractor must maintain a decision log, risk log, and issue log (in State-approved tools), updated at least weekly, with clear owners and due dates.
GR-00006 The Contractor must actively collaborate with all State-approved Contractors and Subcontractors, sharing information, designs, and schedules necessary to achieve an integrated solution.
GR-00007 The Contractor must participate in State-facilitated cross-vendor forums, and align to shared standards, environments, calendars, and schedules as directed by the State.
GR-00008 If an inter-vendor conflict cannot be resolved collaboratively within five business days, the Contractor must escalate the issue to the State no later than one business day thereafter.
GR-00009 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Business Analysis Plan.
GR-00010 The Contractor must follow business analysis methodologies that are consistent with the International Institute for Business Analysis (IIBA) Guide to Business Analysis Body of Knowledge (BABOK) v3.
GR-00011 The Contractor must collaborate with the State to elicit user stories and requirements at sufficient detail to ensure the solution meets the needs of the State.
GR-00012 The Contractor must maintain and manage all requirements, user stories, and business rules in the State's Azure DevOps (ADO) tenet per the direction of the State.
GR-00013 The Contractor must develop and keep current a State-approved Risk Management Plan.
GR-00014 The Contractor must develop and keep current a State-approved Implementation Plan that outlines the approach for the design, development, and implementation of all technology and services in accordance with the solution scope.
GR-00015 The Contractor must, upon Contract execution, participate in the project Steering Committee, which will govern and steer the project.
GR-00016 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Change Management Plan.
GR-00017 The Contractor must collaborate with all State-approved Contractors and Subcontractors under the direction of the State Change Control Board to manage change within a multi-Contractor, integrated systems solution as it relates to any system- or non-system-based changes, modifications, or maintenance activities, efforts, tasks, or projects
GR-00018 The Contractor must identify the impact of data source changes to all solution components and capabilities, so that the changes may be verified to be in accordance with the approved Change Management Plan.
GR-00019 The Contractor must monitor and inform the State of industry changes that may have an impact on business processes or on systems covered by the Contract, so that the State can prepare for and implement any necessary updates and stay aligned with industry changes and best practices.
GR-00020 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Scope Management Plan.
GR-00021 The Contractor must develop a State-approved Project Kickoff Deck.
GR-00022 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Schedule Management Plan.
GR-00023 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Deliverables Matrix.
ID Description Comply Vendor's Description of Compliance
GR-00024 The Contractor must keep current, on the State's SharePoint site, a Personnel Table of all Contractor staff and Subcontractor staff associated with the project. The Personnel Table must provide: (a) Full name (b) Business phone number (c) Business email address (d) Project role (e) Project responsibilities.
GR-00025 The Contractor must develop and keep current a State-approved Organizational Chart of all Contractor and Subcontractor personnel working on the project.
GR-00026 The Contractor must provide the State with resumes for Contractor and Subcontractor staff working on the project.
GR-00027 The Contractor must ensure vacant positions supporting this Contract are filled within 60 calendar days of date of vacancy or obtain written approval by the State for extended vacancies.
GR-00028 The Contractor must provide the State 20 business days or more advance notice of any plans to change, hire, or reassign personnel supporting this Contract.
GR-00029 The Contractor must notify the State within one business day of the replacement, reassignment, resignation, or termination of any personnel directly supporting this Contract.
GR-00030 The Contractor must replace or reassign personnel supporting this Contract for cause (i.e., where the State can demonstrate a reason) at the State's request. The State shall report to Contractor any concerns regarding Contractor Personnel that may lead the State to make such a request with sufficient detail and time for Contractor to take corrective measures.
GR-00031 The Contractor must conduct an initial criminal background check/investigation on all new hires supporting this Contract as well as conduct follow-up criminal investigations every two years, if requested, for all staff supporting this Contract. The costs for the initial criminal background check must be the responsibility of the Contractor.
GR-00032 The Contractor's staffing solution may include staff located both within the United States as well as outside the United States.
GR-00033 The Contractor must ensure that all licensed Contractor staff maintain current licensure required for their role on the project, with no State or Federal sanctions.
GR-00034 The Contractor must cross train its staff to prevent loss of knowledge and expertise when staff leave, as well as to minimize negative impacts to project timelines due to resource availability.
GR-00035 The Contractor must keep current a State-approved process for immediate removal, with just cause or reason, physical and remote access to systems and facilities for Contractor or Subcontractor employees deemed unfit to continue employment.
GR-00036 The Contractor must develop and keep current a State-approved Resource Management Plan.
GR-00037 The Contractor must bear the costs of changes, hires, or reassignment of Contractor personnel.
GR-00038 The Contractor must develop and apply onboarding and training processes for new staff and turnover in staff.
ID Description Comply Vendor's Description of Compliance
GR-00039 The Contractor must develop and keep current a State-approved process for all invoicing activities.
GR-00040 The Contractor must correct and reissue invoices within 10 business days of State notification.
GR-00041 The Contractor must make all Subcontractor agreements available to the State upon request.
GR-00042 The Contractor must be responsible/accountable for all subcontracted work assigned, including responsibility for enforcement and oversight of subcontractors and their compliance with all State and Federal contractual terms/provisions as included within this Contract.
GR-00043 For any Subcontract, the Contractor must identify a designated Subcontractor contact who is accessible to the State.
GR-00044 The Contractor must provide, at no cost to the State, information and data as requested by the State to fulfill requests for litigation, subpoenas, open record requests, or other legal actions.
GR-00045 Upon State request, the Contractor must provide staff and resources to assist the State with preparing and reviewing materials planned to be shared at forum(s), such as national organizations and conferences, on efforts related to this Contract.
ID Description Comply Vendor's Description of Compliance
GR-00046 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Communication Management Plan.
GR-00047 The Contractor must notify the State of all legislative, executive level, and media inquiries with respect to this project and forward any such inquiries to the State within one business day of the Contractor's awareness of said inquiry.
GR-00048 The Contractor must not respond to legislative, executive level, or media inquiries regarding the project unless directed by the State, except where required by law.
GR-00049 The Contractor must ensure all communications conform to State of Vermont brand standards as issued by the Chief Marketing Office.
GR-00050 The Contractor must ensure that the Contractor's own name, logo, or any reference to the Contractor are not included in any public-facing communications with respect to this project, unless approved by the State.
GR-00051 The Contractor must develop and keep current a State-approved Deliverables Management Plan.
GR-00052 The Contractor must update and maintain all Project Deliverables on a mutually agreed upon cadence as approved by the State.
GR-00053 The Contractor must prepare, update, revise, and submit to the State for approval all operational, systems, or reporting based documentation (in all original forms/media) as they relate to system changes, maintenance, or modification work requests.
GR-00054 The Contractor must create and maintain all system and technical documentation for the solution.
GR-00055 System and technical documentation must utilize State-approved language, diagrams, and structure.
GR-00056 The Contractor must utilize the State-approved Project Management Repository as well as any other State-required document repository to maintain system related business, technical, and operational documentation.
GR-00057 The Contractor must ensure all documentation is readily available online and electronically maintained, retained, archived, and restored as required by all document and data retention laws, including any applicable litigation hold.
GR-00058 The Contractor must ensure all documentation is prepared and accessible using current State standard/approved software packages.
GR-00059 All project documentation must be reviewed and approved by the State prior to publication.
GR-00060 The Contractor must provide new, routinely maintained, and updated documentation for all contracted functions in accordance with the State-approved documentation development, maintenance, and quality review process.
GR-00061 The Contractor must maintain a documentation standard that aligns with the standards and templates set forth by the State and other contracted Contractors and utilize the approved standard throughout the life of the Contract.
GR-00062 The Contractor must revise any required documentation deliverable if requested to do so by the State.
GR-00063 The Contractor must maintain complete and detailed records of all Contractor-facilitated meetings with the State related to the Contract, software development lifecycle documents, presentations, project artifacts, and any other interaction and post and maintain these artifacts in the Project Management Repository within five business days of the meeting or interaction.
GR-00064 The Contractor must secure State approval prior to any representation or presentation of documentation related to this project, including any local, State, national conferences, or other public or private forums.
ID Description Comply Vendor's Description of Compliance
GR-00065 The Contractor must develop and keep current a State-approved Business Design/System Design Document.
GR-00066 The Contractor must create and keep current documentation of all operational, system, and technical processes as they relate to the solution.
GR-00072 All user interfaces must comply with the most recent version of Section 508 Standards and WCAG Level A and AA Success Criteria.
ID Description Comply Vendor's Description of Compliance
GR-00073 The Contractor must implement, host (or arrange for third-party hosting), operate, maintain, and manage all infrastructure, including all hardware, software, middleware, and licenses necessary for successful operation of all systems and services under the Contract.
GR-00074 The Contractor must be solely responsible for the end-to-end oversight and management of all environments during implementation and transition, such that performance metrics and service level agreements are met.
GR-00075 The Contractor must retain the responsibility and costs for providing network connectivity and access to all systems and data under their scope to all State-authorized stakeholders.
GR-00076 The Contractor must retain all responsibility and costs for all software, hardware, and infrastructure Maintenance and Operations necessary to fulfill their obligations of this Contract.
GR-00078 The Contractor must provide the base infrastructure and optimization of all systems under the scope of this Contract to meet required application-specific uptime/response time requirements related to performance requirements, deliverable due dates, and Service Level Agreements.
GR-00079 The Contractor must provide reporting of all infrastructure optimizations annually, or after any major system change, to meet or exceed performance requirements or as requested by the State.
GR-00080 The Contractor must document and maintain State-approved application specific response time requirements, measurements, and reporting.
GR-00081 The Contractor must continuously monitor, track, and report monthly to the State infrastructure space and storage trends over the term of the Contract.
GR-00082 The Contractor must notify the State and present the upgrade/replacement plan within 20 business days of awareness of a software or infrastructure upgrade notice received from a software/infrastructure contractor, unless the change is categorized as an Emergency Upgrade, in which case notification must be given five days prior to the upgrade date.
GR-00083 The Contractor must implement each approved upgrade/replacement plan for all software and infrastructure upgrades in accordance with a State-approved schedule.
GR-00084 The Contractor must provide the tools and infrastructure to support required access to all systems and data under their scope to all State-authorized stakeholders.
ID Description Comply Vendor's Description of Compliance
GR-00085 The Contractor must develop and keep current a State-approved System Security Plan.
GR-00086 The Contractor must meet the applicable State and Federal privacy and security standards in the hosting and support of all infrastructure, including but not limited to the Payment Card Industry Data Security Standard (PCI-DSS) requirements for the protection, storage, transmission, and processing of cardholder data maintained within the solution.
GR-00087 The Contractor must provide secure access as applicable and appropriate to the development and test environments to a subset of authorized users. Authorization must be by each environment and conform to the security protocols used by the State.
GR-00088 The Contractor must ensure development and test environments have sufficient security controls in place to prevent unauthorized access.
GR-00089 The Contractor must ensure that test environments, aligned with State standards and approval, mask critical and sensitive data as required for distribution. This includes data classified as Protected Health Information (PHI) and Personally Identifiable Information (PII).
GR-00090 The Contractor must ensure that test environments must adhere to the same level of security compliance for such data as required in a production environment, unless authorized otherwise in writing by the State.
GR-00092 The Contractor must, throughout all phases of this Contract, adhere to 42 CFR 434.6(a)(5), which allows evaluation by Federal Partners through inspection or other means, of the quality, appropriateness, and timeliness of services performed under this Contract.
GR-00093 The Contractor must provide an independent, third-party security and privacy controls assessment report that covers compliance with NIST SP 800-171 and/or NIST SP 800-53 standards and all relevant controls in the Payment Card Industry Data Security Standard (PCI-DSS) and the Open Web Application Security Project Top 10.
ID Description Comply Vendor's Description of Compliance
GR-00094 The Contractor must develop and keep current a State-approved Quality Management Plan that is consistent with ISO 9001:2015, Quality Management System (QMS), Total Quality Management (TQM), SSAE18 SOC 2 Type 2, and Continuous Quality Improvement principles and standards.
GR-00095 The Contractor must collaborate with the State and all State-identified Contractors/partners to achieve and maintain quality system and operational services in accordance with State-approved performance metrics and benchmarks.
GR-00097 The Contractor must lead, coordinate, and be responsible for all project quality assurance management, documentation quality assurance, and quality assurance testing meetings as requested and required under the Quality Management Plan and/or by the State.
GR-00099 The Contractor must provide adequate and dedicated staff to implement, monitor, and address all quality assurance and improvement activities required under the Quality Management Plan.
GR-00100 The Contractor must take a proactive role in identifying and addressing quality control issues within the solution in the effort to meet or exceed performance benchmarks/metrics for the State.
GR-00101 The Contractor must develop and keep current a State-approved Test Management Plan.
GR-00102 The Contractor must collaborate with other project Contractors to ensure the Test Management Plan establishes test frameworks and test objectives, supporting all Contractors and partners involved in the solution.
GR-00103 The Test Management Plan must comply with ISO/IEC/IEEE 29119-3:2021 standards.
GR-00105 The Contractor must provide secure access as applicable and appropriate to the development and test environments to a subset of authorized users.
GR-00106 The Contractor must ensure development and test environments enable access to appropriate devices and resources required to connect to the State environment.
GR-00107 The Contractor must implement a User Acceptance Test (UAT) environment so there is a dedicated environment for user acceptance testing activities.
GR-00108 The solution must adhere to established and mutually agreed-upon standards, procedures, and protocols for data loading into non-production environments.
GR-00109 The Contractor must develop, for each system change, a State-approved suite of test cases that includes the test scope, approach, and tools, and is used to complete testing and provide the documented test results to the State.
GR-00110 The Contractor must provide resources to assist, complete, and submit results, in a State-approved format, of all comprehensive system(s) tests as documented in the State-approved Test Management Plan.
GR-00111 The Contractor must provide sufficient time and resources for all testing performed by the Contractor, and to support testing done by entities other than the Contractor.
GR-00112 The Contractor must ensure that all draft deliverables meet the State's minimum expectations for grammar, spelling, formatting, and overall quality, with revisions made at no additional cost and without impacting the project schedule.
ID Description Comply Vendor's Description of Compliance
GR-00113 The Contractor must develop and keep current a State-approved User Training Plan.
GR-00114 The Contractor must develop and keep current a searchable, web-based State-approved User Guide.
GR-00115 The User Guide must be used as part of the basis for user training, unless otherwise specified by the State.
GR-00116 The Contractor must develop and keep current training materials in compliance with Americans with Disabilities Act of 1990 (ADA) standards. Any identified changes to training materials to comply with this requirement must be addressed at no cost to the State.
GR-00117 The Contractor must provide training to the State, its agents, and Successor Contractor(s).
GR-00118 The Contractor must develop and keep current a State-approved Help Desk Plan.
GR-00119 The Contractor must maintain a State-approved help desk support function that enables users to submit requests through a web portal during State business days, 7 a.m. ET to 7 p.m. ET.
GR-00120 The Contractor must maintain a State-approved help desk support function that enables users to submit requests by phone during State business days, 7 a.m. ET to 7 p.m. ET.
GR-00121 The Contractor must provide technical assistance as needed to assist users in researching problems, reviewing production outputs, and understanding report formats.
ID Description Comply Vendor's Description of Compliance
GR-00122 The Contractor must develop and keep current a State-approved System Maintenance Support Plan.
GR-00124 The Contractor must perform and complete all work necessary to correct and resolve each defect identified in the solution.
GR-00125 The Contractor must utilize Microsoft Azure DevOps, the State-approved online Defect Management tool, for the identification, impact assessment, definition, traceability, verification, and reporting of all defects and resolutions.
GR-00126 The Contractor must conduct development walk-throughs as appropriate to demonstrate to the State that all functions have been completely and accurately planned, developed, and unit tested.
GR-00127 The Contractor must, in coordination with the State, maintain a comprehensive lessons-learned repository in the State's SharePoint site that is a knowledge base of all lessons learned.
GR-00128 The Contractor must detect, log, notify, and respond appropriately to errors and exceptions in both system and data processing.
GR-00129 The Contractor must collaborate with the source system Contractor to resolve bad or otherwise corrupt data in accordance with the data quality review process timelines.
GR-00130 The Contractor must maintain a data quality review process for the identification and resolution of corrupt or bad data.
GR-00131 The Contractor must develop and keep current a State-approved Release Management Plan.
GR-00132 The Contractor must have the ability to selectively move modifications on a release schedule with State approval, with the flexibility to selectively back out system changes prior to a release (last minute) without significant resources or impact (point in time restore).
GR-00133 The Contractor must implement improvements, changes, or enhancements following a State-approved approach that must enable all other environments to update and mirror the ""new"" production functionality.
GR-00134 The Contractor must provide, as part of the Release Management Plan, a Network Design and Monitoring Plan for an optimally performing computing and data transporting environment.
GR-00136 The Contractor must maintain, as part of the Release Management Plan, change management metadata regarding all system application release and operational performance and behavior.
GR-00137 The Contractor must provide a quarterly Configuration Management Summary report providing a high-level overview of any changes to the system baseline configuration and operational usage.
GR-00138 The Contractor must document and maintain State-approved standard maintenance windows for system maintenance and downtime that are coordinated across solutions and minimize stakeholder disruption.
GR-00141 The Contractor must notify affected State stakeholders of scheduled and emergency maintenance windows and system outages.
ID Description Comply Vendor's Description of Compliance
GR-00147 The Contractor must develop and keep current a State-approved Business Continuity, Cyber Incident Response, and Disaster Recovery (BC/DR/CIR) Plan.
GR-00148 The Contractor must ensure the Business Continuity/Disaster Recovery/Cyber Incident Response Plan: (a) provides a framework for reconstructing vital operations to ensure the safety of employees (b) provides for the resumption of time sensitive operations and services in the event of an emergency (c) provides for initial and ongoing notification procedures (d) complies with all NIST CP-2, NIST 800-61, and IR-8, NIST-800-53 standards (e) complies with the latest version of ARC-AMPE standards.
GR-00149 The Contractor must ensure the Business Continuity/Disaster Recovery/Cyber Incident Response Plan's operational and system functions, including systems and operations under the scope of Subcontractors, adhere to Health Insurance Portability and Accountability Act and National Institute of Standards and Technology standards.
GR-00150 The Contractor must provide an up-to-date copy of the Business Continuity/Disaster Recovery/Cyber Incident Response Plan in a secure, highly accessible, centralized online location and at an offsite location approved by the State.
GR-00151 The Contractor must submit the Business Continuity, Cyber Incident Response, and Disaster Recovery Plan annually or more frequently as directed by the State, such as after a major system change that materially affects the plan.
GR-00152 The Contractor must perform annual Business Continuity, Disaster Recovery, and Cyber Incident Response exercises, including pre-go-live activities.
GR-00153 Business Continuity (BC), Disaster Recovery (DR), and Cyber Incident Response (CIR) exercises must include activities selected from the BC/DR/CIR Plans to verify the viability of each plan in accordance with NIST CP-4 and IR-8 standards.
GR-00154 The Contractor must perform Business Continuity, Disaster Recovery, and Cyber Incident Response exercises after major system changes as required by the State.
GR-00155 The Contractor must document all Business Continuity, Disaster Recovery, and Cyber Incident Response activities and report to the State instances where appropriately trained personnel were unable to complete the necessary recovery procedures.
GR-00156 The Contractor must adjust contingency and training plans to correct deficiencies identified through Business Continuity, Disaster Recovery, and Cyber Incident Response exercises and present updates to the State for approval.
GR-00157 The Contractor must provide annual test reports to the State within 10 business days of exercise, Business Continuity (BC)/Disaster Recovery (DR) and Cyber Incident Response (CIR) Plan reports within one business day of incident, and BC/DR/CIR Plan updates within one business day of identified deficiency.
GR-00158 The Contractor must evaluate systems and business processes in collaboration with the State for criticality and necessity to determine appropriate return to operations time frames during development of both the initial and ongoing Business Continuity/Disaster Recovery/Cyber Incident Response Plans.
GR-00159 The Contractor must update key personnel contact information as it relates to the Business Continuity/Disaster Recovery/Cyber Incident Response Plans within one business day of notification of the change.
GR-00160 The Contractor must implement a State-approved alert process to handle system-related issues, including notifying State-identified contacts in accordance with the Business Continuity/Disaster Recovery/Cyber Incident Response Plans.
GR-00161 In coordination with the State, the Contractor must provide training to Contractor staff and State-identified stakeholders on the execution of the Business Continuity/Disaster Recovery/Cyber Incident Response Plans a minimum of 20 business days prior to implementation of the Contractor's module components, with the implementation of major changes, and annually thereafter.
GR-00162 The Contractor must review any new applicable Contractor provided business processes, including systems and operations under the scope of Subcontractors, for impact on mission critical functionality and update Business Continuity/Disaster Recovery/Cyber Incident Response Plans prior to new business process implementation.
GR-00164 The Contractor must provide for backup capabilities at a geographically separate remote site(s) from the Contractor's primary site(s) in accordance with the standards set forth in the Business Continuity/Disaster Recovery/Cyber Incident Response Plans. System and data backup and recovery points must be mutually agreed upon between the Contractor and the State.
GR-00165 The Contractor must provide a backup and recovery/failover system(s) in compliance with State and Federal rules and regulations to ensure full backup.
GR-00166 Backup and Recovery Services must be in place for Production Environment and Non-Production Environments.
GR-00167 The solution must ensure that all backups are immutable (unchangeable).
Questions Vendor Response
Service: Customer Phone &/or Email Support Service: Customer Phone &/or Email Support
What is the method for contacting technical support?
What are the hours of operation for support?
What is the turnaround time for responses?
What is the escalation process for support issues?
Who comprises the support team and what are their qualifications?
Define your response resolution metrics and how you capture and report them.
Service: Incident/Security Breach Notification and Process Service: Incident/Security Breach Notification and Process
Describe your identification and notification process for security breaches.
Service: Data Management Service: Data Management
Describe how data is stored, retained and backed up (including frequency).
Service: Hosting Service: Hosting
Describe the hosting service and associated service levels.
Questions Vendor Response
Service: Scheduled Maintenance/Downtime Service: Scheduled Maintenance/Downtime
What is the frequency of scheduled maintenance and downtime?
What is the notification process for scheduled maintenance and downtime?
Describe how "maintenance" updates are tested with customers prior to installing them in their live environments.
Service: System Upgrades Service: System Upgrades
Are software upgrades provided as part of the software support contract?
Describe your software upgrade process.
How often are new versions released?
Is documentation and training provided for system upgrades?
Are there additional costs for upgrades and/or new releases?
Describe how and when the State will have an opportunity to test system upgrades/releases prior to live installation.
Describe how the State will validate post installation and how changes will be backed out in the event that a problem is encountered.
Service: Bug Fixes and Minor Enhancements Service: Bug Fixes and Minor Enhancements
Describe the frequency and process for providing, testing, and installing bug fixes and minor enhancements.
Service: Disaster Recovery Service: Disaster Recovery
Describe the disaster recovery services included in this proposal for any non-state hosted services.
What is your standard RPO and RTO?
Describe the plan your company has in place for its own disaster recovery of any sites that may be involved in support of this proposal.
Cost Type One Time (Implementation) Year 1 Year 2 Year 3 Year 4 Year 5
Software
Enterprise Application: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Maintenance &/or License Fee Add-Ons $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Subscription cost $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Storage Limitations and/or Additional Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Database Software: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Middleware Tools: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Operating System Software: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Upgrade Costs for Later Years $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Support and Maintenance Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Implementation Services
Project Management $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Requirements $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Design (Architect Solution) $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Development (Build, Configure or Aggregate)/Testing $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
System Testing $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Defect Removal $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Implement/Deploy or Integrate $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Quality Management $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Cost Type One Time (Implementation) Year 1 Year 2 Year 3 Year 4 Year 5
Implementation Services Continued
Training $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Telecom $0.00
Bandwidth $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Hardware $0.00
Computing Hardware $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Storage and Backup Hardware $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Network Hardware $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Facilities/Data Center $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Hosting $0.00
Hosting Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Total Base Costs $0.00
Total Implementation plus Five Year Costs $ 0.00
Clause Location Exception Proposed Verbiage
[indicate RFP, exhibit, attachment or addendum, section & page number] [briefly describe your concern about this clause] [describe your suggested alternative wording for the clause or your solution]
[indicate RFP, exhibit, attachment or addendum, section & page number] [briefly describe your concern about this clause] [describe your suggested alternative wording for the clause or your solution]
[indicate RFP, exhibit, attachment or addendum, section & page number] [briefly describe your concern about this clause] [describe your suggested alternative wording for the clause or your solution]
Summary of Detailed Information Date of Notification Outcome
Provided Equipment or Product Note or Comment
Signature:
Full name:
Title:
Company:
Date:
This is the opportunity summary page. It provides an overview of this opportunity and a preview of the attached documentation.
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

Reading ER P23-1 (404) Request Date: 7/29/2026 1:05:25 PM Open Date: Closing Date:

State Government of Vermont

Bid Due: 8/21/2026

Williston Road Stormwater Structures Request Date: 7/29/2026 8:42:48 AM Open Date: Closing Date:

State Government of Vermont

Bid Due: 8/27/2026

Follow Dental and Audiology Coordinator for the Vermont Army National Guard Active Contract

DEPT OF DEFENSE

Bid Due: 8/23/2026

Roadway Line Striping and Markings Request Date: 7/24/2026 2:23:32 PM Open Date: Closing

State Government of Vermont

Bid Due: 8/19/2026

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.