The Department of Veterans Affairs (VA) Technology Acquisition Center has issued a Sources Sought Notice (Solicitation Number 36C10B26Q0097) for an Audit and Change Monitoring Solution. This notice, released from Eatontown, NJ, seeks responses by December 19, 2025, at 4 PM Eastern Time. The product service code is 7A21 and the NAICS code is 541519. Interested parties are directed to refer to the attached
This Request for Information (RFI) seeks to gather information for planning purposes regarding an Audit and Change Monitoring Solution. This RFI is not a solicitation or a commitment to award a contract. The government is conducting market research to identify vendors capable of providing enterprise-grade audit and change monitoring solutions. The NAICS codes being considered are 541519 (150 employees) and 513210 ($47 million), with an encouragement for small businesses. Responses, limited to five pages, must include company details, capability to meet requirements, past performance, technology refresh considerations, software support, cloud/hybrid integration options, additional recommendations, and a Rough Order of Magnitude (ROM) pricing for a 12-month base period with four 12-month option periods. Responses are due by 4:00 p.m. EDT on December 19, 2025, and should be submitted to Elena.Juliano@va.gov and ioannis.vardouniotis@va.gov with “Audit and Change Monitoring Solution” in the subject line.
The Department of Veterans Affairs (VA) is seeking an experienced partner for an enterprise-level Audit and Change Monitoring Solution. This Request for Information (RFI) aims to identify vendors capable of deploying, operating, and managing a robust system to monitor and audit changes across diverse IT environments, including identity and access management, file systems, databases, and cloud services. The solution must provide real-time detection and alerting, centralized audit logging, enhanced visibility, seamless integration with existing VA security frameworks, and proactive risk mitigation. Key capabilities include tracking administrator behavior in Active Directory and Entra ID, auditing various systems, supporting compliance with FISMA, HIPAA, and NIST, and integrating with incident response workflows. The partner will provide full lifecycle support, ensuring 99.9% platform availability and continuous monitoring, documentation, and communication, with support covering business hours, after-hours, weekends, and federal holidays. Deliverables include monthly reports on ticket resolution, audit efficiency, compliance, uptime, and security incidents, among others.