| Location: | North Carolina |
|---|---|
| Posted: | Apr 14, 2026 |
| Due: | May 19, 2026 |
| Agency: | State Government of North Carolina |
| Type of Government: | State & Local |
| Category: |
|
| Solicitation No: | Doc2125160203 |
| Publication URL: | To access bid details, please log in. |
| Solicitation Number: | Doc2125160203 |
| Project Title: | Website Development, Hosting and Content Management Services |
| Description: | Website Development, Hosting and Content Management Services |
| Opening Date: | 5/19/2026 2:00 PM |
| Posted Date: | 4/15/2026 |
| Status: | Open |
| Department: | STATE BUREAU OF INVESTIGATION |
|
Solicitation Number
*
Doc2125160203
|
Department
STATE BUREAU OF INVESTIGATION
|
Status Reason
Open
|
|
|
Opening Date
2026-05-19T14:00:00.0000000
|
Posted Date
*
2026-04-14T15:28:33.0000000Z
|
Primary Commodity Code
Internet services
|
|
|
Mandatory Conference/Site Visit
—
—
|
Special Instructions
—
|
Solicitation Type
*
Select RFP IFB RFI
|
|
|
Owner
Boyce Haywood
|
|||
|
Description
Website Development, Hosting and Content Management Services
|
|||
| STATE OF NORTH CAROLINA STATE BUREAU OF INVESTIGATION | REQUEST FOR PROPOSAL NO. 49-250811-BH |
|---|---|
| Contract Name: Website Hosting and Content Management Services | |
| Bid Opening Date: May 19, 2026 | |
| Refer ALL inquiries regarding this RFP to: Name Email Phone Number | Issue Date: April 14,2026 |
| Commodity Code: 432215 | |
| Purchasing Agency: NC State Bureau of Investigation | |
| Requisition No.: RQ250811 |
| OFFEROR: | |||
|---|---|---|---|
| STREET ADDRESS: | P.O. BOX: | ZIP: | |
| CITY, STATE & ZIP: | TELEPHONE NUMBER: | TOLL FREE TEL. NO | |
| NAME & TITLE OF PERSON SIGNING: | FAX NUMBER: | ||
| AUTHORIZED SIGNATURE: | DATE: | E-MAIL: |
STATE OF NORTH CAROLINA REQUEST FOR PROPOSAL NO. 49-250811-BH
Contract Name: Website Hosting and Content
Management Services
STATE BUREAU OF INVESTIGATION
Bid Opening Date: May 19, 2026
Refer ALL inquiries regarding this RFP to: Issue Date: April 14,2026
Commodity Code: 432215
Name
Email Purchasing Agency: NC State Bureau of Investigation
Phone Number Requisition No.: RQ250811
OFFER
The Purchasing Agency solicits offers for Services and/or goods described in this solicitation. All offers and
responses received shall be treated as Offers to contract as defined in 9 NCAC 06A.0102(12).
EXECUTION
In compliance with this Request for Proposal (RFP), and subject to all the conditions herein, the undersigned
offers and agrees to furnish any or all Services or goods upon which prices are offered, at the price(s) offered
herein, within the time specified herein.
Failure to execute/sign offer prior to submittal shall render offer invalid. Late offers are not acceptable.
OFFEROR:
STREET ADDRESS: P.O. BOX: ZIP:
CITY, STATE & ZIP: TELEPHONE NUMBER: TOLL FREE TEL. NO
NAME & TITLE OF PERSON SIGNING: FAX NUMBER:
AUTHORIZED SIGNATURE: DATE: E-MAIL:
Offer valid for one hundred twenty (120) days from date of offer opening unless otherwise stated here: ____
days
ACCEPTANCE OF OFFER
If any or all parts of this offer are accepted, an authorized representative of the NC State Bureau of Investigation
shall affix its signature hereto and any subsequent Request for Best and Final Offer, if issued. Acceptance shall
create a contract having an order of precedence as follows: Best and Final Offers, if any, Special terms and
conditions specific to this RFP, Specifications of the RFP, the Department of Information Technology Terms and
Conditions, and the agreed portion of the awarded Vendor's Offer. A copy of this acceptance will be forwarded to
the awarded Vendor(s).
FOR PURCHASING AGENCY USE ONLY
Offer accepted and contract awarded this date 2026, by
_________________________________(Authorized representative of the NC State Bureau of Investigation.
Website Hosting - NC State Bureau of Investigation - RFP #49-250811
Page 0 of 56
October 9, 2025
Table of Contents
1.0 ANTICIPATED Procurement Schedule ....................................................................................... 3
2.0 Purpose of RFP ........................................................................................................................... 3
2.1 Introduction .............................................................................................................................. 3
2.2 Agency Background ................................................................................................................. 3
2.3 Summary of Problem Statement ............................................................................................. 4
2.4 Contract Term .......................................................................................................................... 5
2.5 Effective Date .......................................................................................................................... 5
2.6 Contract Type .......................................................................................................................... 6
3.0 RFP Requirements and Specifications ........................................................................................ 6
3.1 General Requirements and Specifications ............................................................................... 6
3.2 Security Specifications ............................................................................................................. 7
3.3 Enterprise Specifications ......................................................................................................... 8
3.4 Business and Technical Requirements .................................................................................. 11
3.5 Business and Technical Specifications .................................................................................. 13
4.0 Cost of Vendor's Offer ............................................................................................................... 15
4.1 Offer Costs ............................................................................................................................. 15
5.0 Evaluation ................................................................................................................................. 15
5.1 Source Selection .................................................................................................................... 15
5.2 Evaluation Criteria.................................................................................................................. 15
5.3 Best and Final Offers (BAFO) ................................................................................................ 16
5.4 Possession And Review ........................................................................................................ 16
6.0 Vendor Information and Instructions ......................................................................................... 16
6.1 General Conditions of Offer ................................................................................................... 16
6.2 General Instructions for Vendor ............................................................................................. 18
6.3 Instructions for Offer Submission ........................................................................................... 20
7.0 Other Requirements and Special Terms ................................................................................... 23
7.1 Vendor Utilization Of Workers Outside of U.S. ...................................................................... 23
7.2 Financial Statements ............................................................................................................. 23
7.3 Financial Resources Assessment, Quality Assurance, Performance & Reliability (Reserve) 23
7.4 Vendor's License or Support Agreements ............................................................................. 23
7.5 Resellers (Reserved) ............................................................................................................. 23
7.6 Disclosure Of Litigation .......................................................................................................... 23
7.7 Criminal Conviction ................................................................................................................ 24
7.8 Security and Background Checks .......................................................................................... 24
7.9 Assurances ............................................................................................................................ 24
7.10 Confidentiality of offers .......................................................................................................... 25
7.11 Project Management ............................................................................................................. 25
7.12 Meetings ................................................................................................................................ 26
7.13 Contract Kickoff Meeting ....................................................................................................... 26
Website Hosting - NC State Bureau of Investigation - RFP #49-250811
Page 1 of 56
October 9, 2025
7.14 Recycling and Source Reduction .......................................................................................... 26
7.15 Special Terms and Conditions ............................................................................................... 26
7.16 Agency Terms and Conditions (Reserved) ............................................................................ 26
Attachment A: Definitions .................................................................................................................... 28
Attachment B: Information Technology Terms and Conditions ........................................................... 30
Attachment C: Description of Offeror .................................................................................................. 46
Attachment D: Cost Form ................................................................................................................. 468
Attachment E: Vendor Certification Form ............................................................................................ 50
Attachment F: Location of Workers Utilized by Vendor ...................................................................... 51
Attachment G: References .................................................................................................................. 53
Attachment H: Financial Review Form ................................................................................................ 54
Website Hosting - NC State Bureau of Investigation - RFP #49-250811
Page 2 of 56
October 9, 2025
| Action | Responsibility | Date | ||||||
|---|---|---|---|---|---|---|---|---|
| RFP Issued | Agency | 4/14/26 | ||||||
| Written Questions Deadline | Potential Vendors | 4/28/26 | ||||||
| Agency's Response to Written Questions/ RFP Addendum Issued | Agency | 5/5/26 | ||||||
| Offer Opening Deadline | Vendor(s) | 5/19/26 | ||||||
| Offer Evaluation | Agency | 5/27/26 | ||||||
| Contract Award | Agency | TBD | ||||||
| Protest Deadline | Responding Vendors | 15 days after award |
1.0 ANTICIPATED PROCUREMENT SCHEDULE
The Agency Procurement Agent will make every effort to adhere to the following schedule:
Action Responsibility Date
RFP Issued Agency 4/14/26
Written Questions Deadline Potential Vendors 4/28/26
Agency's Response to Written Questions/ Agency 5/5/26
RFP Addendum Issued
Offer Opening Deadline Vendor(s) 5/19/26
Offer Evaluation Agency 5/27/26
Contract Award Agency TBD
Protest Deadline Responding Vendors 15 days after
award
2.0 PURPOSE OF RFP
2.1 INTRODUCTION
The purpose of this Request for Proposal (RFP) is to is to solicit offers and obtain pricing from qualified
vendors to provide website hosting and content management services for the North Carolina Center for Safer
Schools (CFSS). The CFSS, a division of the North Carolina State Bureau of Investigation (NC SBI),
requires a modern, secure, and accessible web platform to serve as the primary digital hub for school
safety resources, training information, and stakeholder engagement across the State of North Carolina.
The selected vendor shall provide a turnkey solution that includes secure website hosting on industry-
standard content management platforms (WordPress or Drupal), integrated identity and access
management supporting both internal NC SBI users and external contributors, and comprehensive training
for CFSS staff on content management. The solution must comply with NIST 800-53 Moderate security
controls and be capable of handling significant traffic volumes during high-profile events while maintaining
optimal performance and security posture.
2.2 AGENCY BACKGROUND
The North Carolina Center for Safer Schools (CFSS) serves as the central resource for information and
technical assistance on school safety, supporting faculty and staff, law enforcement, youth-serving
community agencies, juvenile justice officials, policymakers, parents/guardians, and students across North
Carolina.
CFSS staff is dedicated to addressing key areas including school climate, discipline, and emergency
preparedness for K-12 schools across North Carolina. The Center offers training, guidance, and technical
assistance upon request to school faculty, staff, and professionals working with children and adolescents,
ensuring they have the tools and knowledge to create safer learning environments.
Key CFSS programs and initiatives include:
* Regional School Safety Specialists (RSSS) Program - Subject matter experts providing
resources and training to public school units across eight designated regions
* Behavioral Threat Assessment and Management (BTAM) - Essential tools, training, and
support for threat assessment
Page 3 of 56
[Title of RFP] - [Agency] [RFP number]
October 9 2025
* Say Something Anonymous Reporting System (SSARS) - Statewide confidential reporting program
* Student Engagement Programs - Including SAVE Clubs, SEED Program, and SHINE Program
* School Safety Grants and SRO Grants - Funding for school safety equipment, crisis services, and
training
* RISE Back to School Safety Summit - Annual training conference for school safety professionals
CFSS recently transitioned to the North Carolina State Bureau of Investigation, strengthening its ability to
collaborate with law enforcement and education leaders in responding to school safety challenges.
2.3 SUMMARY OF PROBLEM STATEMENT
The North Carolina Center for Safer Schools currently lacks a dedicated, fully-functional website to serve as
a comprehensive hub for school safety resources. The existing web presence consists of a single page within
the NC SBI website (www.ncsbi.gov/Services/School-Safety), which does not adequately support the scope
and complexity of CFSS operations, programs, and stakeholder needs.
The current limitations include:
* Lack of dedicated web infrastructure to host comprehensive program information, resources, and
interactive content
* Inability to host dynamic content such as data dashboards, interactive training calendars, and survey
tools
* Reliance on third-party platforms (Google Sheets, Google Forms, YouTube, Whova) for core
functionality that should be integrated into a unified web experience
* No capability for external partners and regional specialists to contribute and maintain content
* Limited ability to scale during high-traffic events such as breaking news stories or incidents affecting
school safety
CFSS requires a secure, modern website that will:
* Serve as the authoritative source for school safety information, resources, and training for North
Carolina stakeholders
* Support multiple content types including documents, videos, embedded dashboards (Power BI),
surveys, and event registrations
* Provide technical training via 4 separate access portals that will be accessed in the following manner:
-Law Enforcement Portal will be accessed via their agency email
-Admin/Teacher/Support Staff Portal will be accessed via their staff email
-Student Portal will be unsecure
-General Public Portal will be unsecure
-Vision for the solution
* High-level functionality expected for each solution release into production environment
* The law enforcement portal and teacher portal will use two factor authentication as mentioned in 3.3.3
* Enable both internal CFSS staff and authorized external contributors to manage and update content
* Meet federal cybersecurity requirements (NIST 800-53 Moderate) to protect against cyberattacks and
defacement
* Provide an accessible, user-friendly experience for all stakeholders including parents, educators,
students, and law enforcement
The following table provides estimated addressable user populations for each of the four secure training
portals. These estimates are based on publicly available data from the NC Department of Public
Page 4 of 56
[Title of RFP] - [Agency] [RFP number]
October 9 2025
| Training Portal | Estimated | Basis for Estimate | ||||||
| Addressable | ||||||||
| Population | ||||||||
| Law Enforcement Portal | 25,000 - 30,000 | Approximately 20,000 full-time local sworn officers (NC Justice | ||||||
| Data Portal, 2022), plus state-level law enforcement agencies | ||||||||
| (SHP, SBI, ALE), school resource officers, and civilian law | ||||||||
| enforcement personnel across approximately 500 agencies | ||||||||
| statewide. | ||||||||
| Admin/Teacher /Support Staff Portal | 190,000 - 210,000 | Approximately 100,000 teachers (NC DPI, 2024-25) plus | ||||||
| teacher assistants, instructional support personnel (75.63% of | ||||||||
| all staff), school-based administrators (3.26%), central office | ||||||||
| administrators (1.7%), and non-professional support staff across | ||||||||
| 115+ LEAs and 200+ charter schools. | ||||||||
| Student Portal | 1,500,000 - 1,700,000 | Approximately 1,538,563 students funded in NC public schools | ||||||
| (NC DPI, 2024-25), plus approximately 146,000 charter school | ||||||||
| students. Portal usage is expected to be concentrated among | ||||||||
| middle and high school students (grades 6-12). Student data | ||||||||
| privacy requirements (FERPA, COPPA) apply. | ||||||||
| General Public Portal | 1,500,000 - 2,000,000 | Based on approximately 1.8 million total K-12 students across | ||||||
| all school types in North Carolina and an estimated 1.5 | ||||||||
| parents/guardians per student household (U.S. Census Bureau, | ||||||||
| 2024). Additional community members, policymakers, and | ||||||||
| youth-serving agency staff may also access this portal. | ||||||||
| Training |
|---|
| Portal |
| Law |
|---|
| Enforcement |
| Portal |
| Admin/Teacher |
|---|
| /Support Staff |
| Portal |
| 190,000 - |
|---|
| 210,000 |
| 1,500,000 - |
|---|
| 1,700,000 |
| General Public |
|---|
| Portal |
| 1,500,000 - |
|---|
| 2,000,000 |
Instruction, NC Department of Justice, NC Justice Data Portal, and the U.S. Census Bureau. Actual
registration and usage rates will vary. Vendors should use these estimates for infrastructure sizing,
capacity planning, and cost proposals.
Training Estimated Basis for Estimate
Portal Addressable
Population
Law 25,000 - 30,000 Approximately 20,000 full-time local sworn officers (NC Justice
Enforcement Data Portal, 2022), plus state-level law enforcement agencies
Portal (SHP, SBI, ALE), school resource officers, and civilian law
enforcement personnel across approximately 500 agencies
statewide.
Admin/Teacher 190,000 - Approximately 100,000 teachers (NC DPI, 2024-25) plus
/Support Staff 210,000 teacher assistants, instructional support personnel (75.63% of
Portal all staff), school-based administrators (3.26%), central office
administrators (1.7%), and non-professional support staff across
115+ LEAs and 200+ charter schools.
Student Portal 1,500,000 - Approximately 1,538,563 students funded in NC public schools
1,700,000 (NC DPI, 2024-25), plus approximately 146,000 charter school
students. Portal usage is expected to be concentrated among
middle and high school students (grades 6-12). Student data
privacy requirements (FERPA, COPPA) apply.
General Public 1,500,000 - Based on approximately 1.8 million total K-12 students across
Portal 2,000,000 all school types in North Carolina and an estimated 1.5
parents/guardians per student household (U.S. Census Bureau,
2024). Additional community members, policymakers, and
youth-serving agency staff may also access this portal.
Note: These figures represent the total addressable population for each portal. Actual registered user
counts will depend on adoption rates, which are expected to grow incrementally over the contract period.
Vendors should describe in their proposals how the solution scales to accommodate growth across all
four portals.
2.4 CONTRACT TERM
A contract awarded pursuant to this RFP shall have an effective date as provided in the Notice of Award.
The term shall be three (3) years and will expire upon the anniversary date of the effective date unless
otherwise stated in the Notice of Award, or unless terminated earlier. The State retains the option to extend
the Agreement for two (2) additional one (1) year periods at its sole discretion.
2.5 EFFECTIVE DATE
This solicitation, including any Exhibits, or any resulting contract or amendment shall not become effective
nor bind the State until the appropriate State purchasing authority/official or Agency official has signed the
document(s), contract or amendment; the effective award date has been completed on the document(s), by
the State purchasing official, and that date has arrived or passed. The State shall not be responsible for
reimbursing the Vendor for goods provided nor Services rendered prior to the appropriate signatures and
Page 5 of 56
[Title of RFP] - [Agency] [RFP number]
October 9 2025
the arrival of the effective date of the Agreement. No contract shall be binding on the State until an
encumbrance of funds has been made for payment of the sums due under the Agreement.
2.6 CONTRACT TYPE
Definite Quantity Contract - This request is for a close-ended contract between the awarded Vendor and the
State to furnish a pre-determined quantity of a good or service during a specified period of time.
3.0 RFP REQUIREMENTS AND SPECIFICATIONS
3.1 GENERAL REQUIREMENTS AND SPECIFICATIONS
3.1.1 REQUIREMENTS
Requirement means, as used herein, a function, feature, or performance that the System must
provide. If the offer cannot meet the requirements, they will not be evaluated.
3.1.2 SPECIFICATIONS
Specification means, as used herein, a detailed description that documents the function and
performance of a system or system component.
The apparent silence of the specifications as to any detail, or the apparent omission of detailed
description concerning any point, shall be regarded as meaning that only the best commercial practice
is to prevail and that only processes, configurations, materials and workmanship of the first quality
may be used. Upon any notice of noncompliance provided by the State, Vendor shall supply proof of
compliance with the specifications. Vendor must provide written notice of its intent to deliver alternate
or substitute Services, products, goods or other Deliverables. Alternate or substitute Services,
products, goods or Deliverables may be accepted or rejected in the sole discretion of the State; and
any such alternates or substitutes must be accompanied by Vendor's certification and evidence
satisfactory to the State that the function, characteristics, performance and endurance will be equal
or superior to the original Deliverables specified.
3.1.3 SITE AND SYSTEM PREPARATION
Vendors shall provide the Purchasing State Agency complete site requirement specifications for the
Deliverables, if any. These specifications shall ensure that the Deliverables to be installed or
implemented shall operate properly and efficiently within the site and system environment. Any
alterations or modification in site preparation, which are directly attributable to incomplete or
erroneous specifications provided by the Vendor and which would involve additional expenses to the
State, shall be made at the expense of the Vendor.
3.1.4 EQUIVALENT ITEMS
Whenever a material, article or piece of equipment is identified in the specification(s) by reference to
a manufacturer's or Vendor's name, trade name, catalog number or similar identifier, it is intended to
establish a standard for determining substantial conformity during evaluation, unless otherwise
specifically stated as a brand specific requirement (no substitute items will be allowed). Any material,
article or piece of equipment of other manufacturers or Vendors shall perform to the standard of the
item named. Equivalent offers must be accompanied by sufficient descriptive literature and/or
specifications to provide for detailed comparison.
3.1.5 ENTERPRISE LICENSING
In offering the best value to the State, Vendors are encouraged to leverage the State's existing
resources and license agreements, which can be viewed here:
https://it.nc.gov/resources/statewide-it-procurement/statewide-it-contracts
Page 6 of 56
[Title of RFP] - [Agency] [RFP number]
October 9 2025
| Control Family | ID | Key Requirements for Website Hosting | ||||||
| Access Control | AC | Multi-factor authentication, role-based access, | ||||||
| session management, least privilege | ||||||||
a) Identify components or products that are needed for your solution that may not be available
with the State's existing license agreement.
b) Identify and explain any components that are missing from the State's existing license
agreement.
c) If the Vendor can provide a more cost effective licensing agreement, please explain in detail
the agreement and how it would benefit the State.
3.2 SECURITY SPECIFICATIONS
3.2.1 SOLUTIONS HOSTED ON STATE INFRASTRUCTURE (RESERVED)
3.2.2 SOLUTIONS NOT HOSTED ON STATE INFRASTRUCTURE
The CFSS Website Hosting Services solution will be required to receive and securely manage data
that is classified as Low Risk (Public) data. However, because the website represents the official
online presence of a state law enforcement agency division, the solution must implement robust
security controls to protect against cyberattacks, defacement, and unauthorized access.
Refer to the North Carolina Statewide Data Classification and Handling Policy for more information
regarding data classification: https://it.nc.gov/document/statewide-data-classification-and-handling-
policy.
To comply with the State's Security Standards and Policies, the Vendor solution must demonstrate
compliance with NIST Special Publication 800-53 Revision 5 security controls at the Moderate
baseline level. This requirement applies to all components of the Vendor-provided solution.
Vendor Readiness Assessment Report: Vendors shall provide a completed Vendor
Readiness
(a) Assessment Report Non-State Hosted Solutions (VRAR) at offer submission. This report is
located at: https://it.nc.gov/documents/vendor-readiness-assessment-report
(b) Independent Third-Party Assessment: Upon request, Vendors shall provide a current
independent third-party assessment report in accordance with the following subparagraphs prior to
contract award. Vendors are encouraged to provide this assessment at the time of offer submission.
* i) Preferred assessments: FedRAMP certification, SOC 2 Type 2, ISO 27001, or
HITRUST (certification
* (ii) Alternative assessments (SOC 2 Type 1) may be submitted with explanation;
preferred assessment required within 365 days of contract effective date
* (iii) IaaS vendor certifications cannot cover SaaS solutions unless explicitly permitted by
written agreement
(c) Additional Security Documentation: Prior to contract award, the State may require additional
security documentation including vulnerability assessment reports and penetration test reports. The
awarded Vendor shall provide such documentation upon request during the contract term.
(d) NIST 800-53 Moderate Control Families: The Vendor must demonstrate implementation of
controls from the following NIST 800-53 control families:
Control Family ID Key Requirements for Website Hosting
Access Control AC Multi-factor authentication, role-based access,
session management, least privilege
Page 7 of 56
[Title of RFP] - [Agency] [RFP number]
October 9 2025
| Audit & | AU | Logging of content changes, user activity | ||||
| Accountability | monitoring, audit log protection | |||||
| Security | CA | Annual security assessments, continuous | ||||
| Assessment | monitoring, penetration testing | |||||
| Configuration | CM | Baseline configurations, change control, | ||||
| Mgmt | software restrictions | |||||
| Contingency | CP | Backup/recovery, disaster recovery, business | ||||
| Planning | continuity | |||||
| Identification & | IA | Unique user identification, authenticator | ||||
| Auth | management, MFA for privileged users | |||||
| Incident | IR | Incident handling, reporting, monitoring, breach | ||||
| Response | notification | |||||
| System & | SC | Encryption in transit (TLS 1.2+), boundary protection, denial of service protection | ||||
| Comms | ||||||
| Protection | ||||||
| System & Info | SI | Malware protection, vulnerability scanning, | ||||
| Integrity | security alerts | |||||
| Encryption in transit (TLS 1.2+), boundary |
|---|
| protection, denial of service protection |
Audit & AU Logging of content changes, user activity
Accountability monitoring, audit log protection
Security CA Annual security assessments, continuous
Assessment monitoring, penetration testing
Configuration CM Baseline configurations, change control,
Mgmt software restrictions
Contingency CP Backup/recovery, disaster recovery, business
Planning continuity
Identification & IA Unique user identification, authenticator
Auth management, MFA for privileged users
Incident IR Incident handling, reporting, monitoring, breach
Response notification
System & SC Encryption in transit (TLS 1.2+), boundary
Comms protection, denial of service protection
Protection
System & Info SI Malware protection, vulnerability scanning,
Integrity security alerts
3.3 ENTERPRISE SPECIFICATIONS
3.3.1 ARCHITECTURE DIAGRAMS
The State utilizes architectural diagrams to better understand the design and technologies of a
proposed solution. Details on these diagrams can be found at the following
link: https://it.nc.gov/resources/statewide-it-procurement/vendor-engagement-resources#Tab-
Architecture-1192
The provision of both Network Architecture and Technology Stack diagrams is a requirement at
offer submission. If they are not supplied at that time, the Vendor's offer will be considered non-
responsive and will not be evaluated.
3.3.2 SOLUTION ROADMAP
Describe the solution roadmap for the proposed CMS platform. Include content on release
strategies for functionality, roadmap for technical architecture, how scalability is planned, and how
customer feedback is collected and incorporated into solution enhancements. The roadmap should
demonstrate the long-term viability of the proposed platform over the five-year potential contract
period.
3.3.3 IDENTITY AND ACCESS MANAGEMENT
The proposed solution must externalize identity and access management. The protocols describing
the State's Identity and Access Management can be found at the following link:
https://it.nc.gov/services/vendor-engagement-resources#Tab-IdentityAccessManagement-1241
Vendor must describe how your solution supports the following authentication requirements:
Page 8 of 56
[Title of RFP] - [Agency] [RFP number]
October 9 2025
* Integration with NC SBI Active Directory / Microsoft Entra ID for internal CFSS staff
authentication (2-3 users)
* Local user accounts with multi-factor authentication (MFA) for external contributors (up to 6
users)
* Role-based access control (RBAC) with granular permissions for content editing, publishing,
and administration
* Support for SAML 2.0 and/or OpenID Connect protocols
Vendor must describe how the solution supports four (4) separate secure training portals with email-
based authentication. Each portal shall restrict access based on the user's email domain and serve
role-appropriate training content including pre-recorded video courses, document-based materials,
and live/scheduled training sessions. The portals are:
* Law Enforcement Portal: Accessible to law enforcement personnel via verified agency
email addresses (e.g., .gov, .us law enforcement domains). Content shall include law
enforcement-specific training, threat assessment protocols, and SRO resources.
* Admin/Teacher/Support Staff Portal: Accessible to school administrators, teachers, and
support staff via verified school district or educational institution staff email addresses.
Content shall include educator-specific training, school safety planning resources, and
behavioral threat assessment materials.
* Student Portal: Accessible to students. Content shall include age-appropriate safety
training, student engagement program resources (SAVE Clubs, SEED, SHINE), and
anonymous reporting information.
* General Public Portal: Accessible to the general public (parents, guardians, community
members). Content shall include general school safety resources, reporting tools, and public
awareness materials.
Vendor must describe the proposed approach for email domain validation, user registration and
provisioning workflow, and how content visibility is managed across portals. The solution must
allow CFSS administrators to flexibly control which training content is visible to each portal
audience on a per-item basis.
3.3.4 INTEGRATION APPROACH
Describe proposed solution capabilities to interoperate with other solutions. The solution must support
embedding of the following external tools and content types:
* Microsoft Power BI dashboards (iframe embedding)
* YouTube video content
* Third-party event registration systems (e.g., Whova, Eventbrite)
* Survey tools and forms
* Google Workspace content (Sheets, Docs, Calendar) where required
3.3.5 DISASTER RECOVERY AND BUSINESS CONTINUITY
Describe the proposed solution capabilities related to the following areas:
Disaster Recovery Plan (DRP): Describe how proposed solution supports Recovery Point
Objectives (RPO) and Recovery Time Objectives (RTO) metrics. The State requires RPO of no more
than 24 hours and RTO of no more than 4 hours.
Page 9 of 56
[Title of RFP] - [Agency] [RFP number]
October 9 2025

With GovernmentContracts, you can:
Follow Multiple Building Fire Exhaust Systems Repairs Active Contract Opportunity Notice ID N4008526R9059
DEPT OF DEFENSE
Bid Due: 8/05/2026
Follow 43d Air Mobility Squadron_ Request for Proposal_FA445226R0012_B753 Kitchen Renovation Active Contract Opportunity
DEPT OF DEFENSE
Bid Due: 8/05/2026
Follow Multiple Base-wide Location Fencing Repairs Active Contract Opportunity Notice ID N4008524R9072 Related
DEPT OF DEFENSE
Bid Due: 8/20/2026
Project: Federal Pipe Video Contracts Ref. #: 269- 2026-235 Department: City Procurement Type:
City of Charlotte
Bid Due: 8/24/2026