Opportunity
SAM #80TECH26RFI0023
NASA RFI for Fire & Emergency Medical Services Records Management System (FEMSRMS) SaaS Solution
Buyer
NASA Glenn IT Procurement Office
Posted
July 27, 2026
Respond By
August 03, 2026
Identifier
80TECH26RFI0023
NAICS
541512, 513210
NASA is seeking industry input for a planned procurement of a cloud-based Fire & Emergency Medical Services Records Management System (FEMSRMS) SaaS solution. - Government Buyer: - National Aeronautics and Space Administration (NASA) - NASA IT Procurement Office (ITPO) on behalf of the Office of Protective Services (OPS) - OEMs and Vendors: - No specific OEMs or vendors are named in the notice - Products/Services Requested: - Commercial Off the Shelf (COTS) Software as a Service (SaaS) solution for fire and EMS records management - Cloud-based, FedRAMP High Authorized system - Features required: - Incident reporting - Electronic Patient Care Reporting (ePCR) - Computer-Aided Dispatch (CAD) integration - Personnel scheduling - Asset management - Narcotics tracking - Additional fire and EMS records management capabilities - Configuration, setup, training, and annual maintenance - Support for seven operational stations and one non-production test environment - Unique or Notable Requirements: - Solution must be FedRAMP High Authorized - Must comply with Section 508 accessibility and NASA/Federal IT security standards - NASA requires unrestricted data rights - All work performed off-site - Contractor responsible for implementation, integration, and ongoing support - Base year plus four option years for annual subscription and maintenance
Description
THIS IS NOT A REQUEST FOR PROPOSAL. NO PROPOSALS ARE TO BE SUBMITTED IN RESPONSE TO THIS NOTICE. This notice is issued by NASA/ITPO to post a Statement of Work to solicit responses from interested parties. This document is for information and planning purposes and to allow industry the opportunity to verify reasonableness and feasibility of the requirement, as well as promote competition. Fire & Emergency Medical Services Records Management System (FEMSRMS) BASE + 4 Option Years NASA/ITPO is hereby soliciting information from potential sources for Fire & Emergency Medical Services Records Management System (FEMSRMS) BASE + 4 Option Years The National Aeronautics and Space Administration (NASA) ITPO seeking capability statements from all interested parties, including all socioeconomic categories of Small Businesses (SB) and Historically Black Colleges and Universities (HBCU)/Minority Institutions (MI) for the purposes of determining the appropriate level of competition and/or small business subcontracting goals for FEMSRMS. Vendors are encouraged to demonstrate capabilities as a prime, subcontractor and/or teaming partner. The Government reserves the right to consider a Small Business, Small Disadvantaged Business (SDB), HUBZone, Veteran Owned Small Business (VOSB), Service-Disabled Veteran Owned Small Business, and Women-Owned Small Business (WOSB) set-aside based on responses received. Respondents are requested to provide informed input on realistic and appropriate SB subcontracting and/or participation goals for the specific requirement. This type of feedback supports NASA’s market research and helps ensure the acquisition strategy is aligned with industry capability. Industry feedback is requested for: SB Subcontracting goals; Barriers that may limit SB participation, such as certifications, unique technical requirements, security needs, specialized tools, or high-risk performance areas; and Strategies to increase SB participation, including: Breaking requirements into smaller components Identifying areas appropriate for subcontracting Considering teaming or mentor protégé approaches This RFI is not to be construed as a commitment by the Government, nor will the Government pay for the information submitted in response. The Government may not respond to questions/concerns submitted. The Government will use the information to finalize the RFP as necessary. All comments or questions must be submitted electronically via email to Kimberly Sandoz Kimberly.r.sandoz@nasa.gov and Cory Rasnic cory.t.rasnic@nasa.gov, no later than 8/03/2026 @ 6:00PM EST. When responding reference RFI # 80TECH26RFI0023. NASA Clause 1852.215-84, Ombudsman, is applicable. The Center Ombudsman for this acquisition can be found at: https://www.hq.nasa.gov/office/procurement/regs/Procurement-Ombuds-Comp-Advocate-Listing.pdf If a solicitation is released, then it and any additional documents will be available on Sam.gov. It is the offeror's responsibility to monitor this website for the release of the solicitation and amendments (if any). Potential offerors will be responsible for downloading their own copy of the solicitation and amendments, if any. The key details are summarized below: STATEMENT OF WORK (SOW) 1. General Information Project Title:Fire & Emergency Medical Services Records Management System (FEMSRMS) Agency/Organization:OCIO on behalf of the Office of Protective Services Requiring Activity:Procure a Commercial off the Shelf (COTS) Software as a Service (SaaS) solution for Fire and EMS Records Management Program Office: Office of Protective Services Date: July 2026 2. Background The NASA Office of Protective Services (OPS) fire departments require a robust, integrated, and secure Records Management System (RMS) to replace outdated, manual, and fragmented systems. Increasing emergency service demands have amplified risks and inefficiencies associated with spreadsheet-based record keeping, creating operational gaps that jeopardize firefighter safety, mission assurance, and Center readiness. Implementing a comprehensive RMS directly supports OPS’s strategic commitment to safeguarding NASA personnel, infrastructure, and mission-critical operations. To ensure capital project delivery, improve oversight and reporting capabilities, and to mitigate risk, NASA requires a Commercial Off the Shelf (COTS) and Software as a Service (SaaS) enterprise-level Fire and EMS solution that aligns with industry standards and is robust, integrated, and secure. 3. Objective NASA seeks to acquire a Commercial Off the Shelf (COTS) solution for Fire and EMS Records management system along with Professional Services for tailoring and implementation of such a system. The configured COTS solution shall be known as Fire & Emergency Medical Services Records Management System (FEMSRMS) NASA’s objective with the acquisition of FEMSRMS is to implement and configure a COTS solution that will: Replace manual and fragmented fire and EMS Records Management Systems with a modern cloud-based solution that meets NASA OPS and OCIO requirements. Enable site consolidation for data sharing. Achieve cost savings through efficiencies gained from reducing the number of solutions maintained/supported. The contractor shall provide a cloud-based configured COTS offering, shall meet the technical and operational requirements herein, shall ensure integration with specified information technology (IT) systems and software, and shall operate and maintain FEMSRMS in accordance with industry best practices, Federal Regulations, and NASA guidelines and requirements. The contractor shall provide a solution that is Federal Risk and Authorization Management Program (FedRAMP) High Authorized at the time of contract award. The Government intends to achieve Agency Authority to Operate (ATO), in accordance with NPR 7120.7. 4. Scope 4.1 Functional Standards 4.1.1 The solution must be a COTS product and hosted in a cloud environment. 4.1.2 The FEMSRMS solution must provide the following capabilities: Incident reporting & fire documentation: create fire/incident reports and emergency response documentation with FRMS capture, NERIS v1 connectivity, and an NFIRS legacy crosswalk for reporting. ePCR & hospital data exchange: NEMSIS-compliant electronic patient care reporting that is HIPAA-aware, includes a hospital handoff packet, and supports one-way digital transfer to receiving facilities. Integrated authentication & security: PIV-based integrated authentication for users. CAD ingestion & mobile responder/notifications: vendor-agnostic CAD interface (Central Square compatibility required), mobile responder capability (notifications, incident access on any device), and offline-capable mobile cache with sync-on-reconnect for sites with intermittent connectivity (e.g., White Sands, Stennis). Pre-Incident Planning: Build actionable pre-incident plans for response personnel. Connections to ESRI/ArcGIS for mapping, hydrant and water supply tracking Facility inspections, pre-plans, and ITM: mobile inspection and pre-plan workflows with deficiency tracking, Inspect-Test-Maintain (ITM) management, trend/reporting on inspection compliance. Personnel scheduling & rostering: centralized personnel records, roster and leave management, qualifications tracking, auto shift-coverage proposals, and automated staffing notifications. Training, virtual training & compliance: course catalog, completion records, certification-expiry alerts, virtual end-user training, and training analytics for compliance with standards (e.g., NFPA, FAA, NASA). Exposure tracking & health/wellness: per-responder, per-incident exposure history, cancer-presumption alignment, and health/wellness documentation and reporting. Incident command & on-scene accountability: ICS form set, tactical worksheets, resource tracking, action-item tracking, and personnel accountability at incidents. Apparatus, equipment, fleet & asset management: asset register, maintenance scheduling, OOS tracking, recall management, inspections, and lifecycle/supply tracking. Narcotics & controlled-substance management: DEA-compliant chain-of-custody, witnessed waste, reconciliation, and controlled-substance tracking integrated with asset/inventory controls. Investigations & evidence management: fire cause-and-origin documentation with customizable investigation forms and full evidence chain-of-custody tracking. Events, activities & non-incident records: capture and report daily departmental activities and non-incident events. Data, analytics & reporting: incident analytics, compliance and inspection-trend reports, and exportable data for downstream use. Data migration & test environment: limited/legacy data import capability plus a separate non-production test/sandbox environment for training and configuration testing. 4.1.3 The solution will provide 2 stations at Kennedy Space Center, 2 stations at Wallops Flight Facility, 1 station at Stennis Space Center, 1 station at Ames Research Center, 1 station at White Sands Test Facility, and one independent non-production test environment. The procurement will be for one initial year where configuration, setup, and training are included in the initial year. Along with four additional option years where configuration, setup, and training are not included. Each year will include annual maintenance for the application and hosting infrastructure. 4.2 Accessibility 4.2.1 Section 508 Compliance. NASA is committed to providing accessible Information and Communication Technology (ICT) to individuals with disabilities, including members of the public and federal employees. The contractor-provided solution shall meet or exceed all requirements of Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d). 4.3 Data Rights and Purchase Authorization 4.3.1 In accordance with FAR 52.227-14 Rights in Data-General (May 2014), the contractor shall provide the Government with unrestricted ownership rights to the project data within the software/program. 4.3.2 IT Purchase Authorization. 4.3.2.1 The contractor shall ensure all IT products and services direct charged to the contract are approved through the NASA OCIO’s Commercial IT Request (CITR) Application. This includes, but is not limited to, Federal Information Technology Acquisition Reform Act (FITARA), Supply Chain Risk Management (SCRM), and IPv6 and 508 compliance. No purchases of commercial IT products or services should be made prior to coordination and approval by the OCIO. 4.3.2.2 This contract shall only be used to purchase software, software maintenance, hardware, or hardware maintenance necessary for the performance of this contract. NASA shall own the license(s) or subscriptions for any software or applications purchased. 4.4 Security Requirements 4.4.1 The contractor COTS solution shall support a secure, multi-factor authentication (MFA) method for Government-consuming end users to access the service and for Government personnel who will perform administrative duties. The contractor shall support integration of the service with multi-factor NASA authentication services including Single Sign-On (SSO) and Federal Government Personal Identity Verification (PIV) Card access. A user inside NASA’s firewall shall be able to access the solution without having to provide separate credentials. The contractor-provided solution shall support an MFA solution that aligns with all applicable Federal IT security standards and policies. Access controls must comply with the applicable portions of all NASA and Federal IT Security standards and policies listed in Paragraph 5. These policies include session timeouts and inactive user lockouts. The information system/IT solution shall support role-based access controls to distinguish between end users needing access to different levels of data (e.g., end users only needing access to non-sensitive data and end users needing access to sensitive data). 4.4.2 The system shall have a FedRAMP High Authorization package. FEMSRMS shall have an active FedRAMP High Authorization package and shall maintain authorization through the performance period of the contract. 4.4.3 All work associated with the performance of this contract shall be performed off-site. Access to NASA Center/Sites/Facilities will not be required. 5. Applicable Documents The contractor shall be subject to all NASA and Federal IT Security standards, policies, and reporting requirements. The contractor shall meet and comply with all NASA IT Security Policies and all applicable NASA and Federal standards and guidelines, and other Government-wide laws and regulations for protection and security of Information Technology. The contractor shall comply with the following policies and regulations: Federal Information Security Management Act of 2002 (44 U.S.C. 3541 - 3549) Homeland Security Presidential Directive (HSPD)-12: Policy for a Common Identification Standard for Federal Employees and Contractors Americans with Disabilities Act - Section 508 (29 U.S.C 794d) NPD 2800.1, Managing Information Technology NPR 2800.2, Information and Communication Technology Accessibility NPR 2841.1, Identity, Credential, and Access Management NPD 1382.17, NASA Privacy Policy NPD 2810.1, NASA Information Security Policy NPD 1420.1, NASA Forms Management NPD 1440.6, NASA Records Management NPD 1490.1, NASA Printing, Duplicating, and Copying Management NPR 1382.1, NASA Privacy Procedural Requirements NPR 1441.1, NASA Records Management Program Requirements NPD 2540.1, Acceptable Use of Government Office Property Including Information Technology NPD 2830.1, NASA Enterprise Architecture NPR 1040.1, NASA Continuity of Operations (COOP) Planning Procedural Requirements NPR 2810.1, Security of Information and Information Systems NPR 2810.7, Controlled Unclassified Information NPR 2830.1, NASA Enterprise Architecture Procedures NPR 7120.7, NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements and the following handbooks relevant to the development, authorization, and maintenance of NASA information systems (current versions as posted on https://cset.nasa.gov/ascs/cspd-handbooks/): ITS-HBK-AASTEP0.v1.0.0 Step 0: Prepare Policy ITS-HBK-AASTEP1.v1.0.0 Step 1: Categorize Policy ITS-HBK-AASTEP2.v1.0.0 Step 2: Select Policy ITS-HBK-AASTEP3.v1.0.0 Step 3: Implement Policy ITS-HBK-AASTEP4.v1.0.0 Step 4: Assess Policy ITS-HBK-AASTEP5.v1.0.0 Step 5: Authorize Policy ITS-HBK-AASTEP6.v1.0.0 Step 6: Monitor Policy Note: Cybersecurity Handbooks, and standards that apply to specific tasks or requirements are accessible internal only at https://cset.nasa.gov/ascs/cspd-handbooks/ and must be obtained from the Contracting Officer. 6. Contractor Responsibilities The contractor shall provide all material, equipment, and labor necessary to perform all tasks associated with the licensing, hosting, configuration, testing, integration, data migration, implementation, training, and administration of the contractor-provided solution. This shall include, but is not limited to, technical implementation of all system enhancements including beta testing, minor releases, major releases, software updates, and configuration changes. The Contractor shall: Provide qualified personnel. Furnish all management, supervision, labor, equipment, and materials unless otherwise specified. Maintain project schedules. Comply with all applicable federal regulations. Protect Government information. Coordinate with Government personnel. Maintain required licenses and certifications. 7. Place of Performance All work associated with the performance of this contract shall be performed off-site. Access to NASA Center/Sites/Facilities will not be required. 8. Period of Performance Base Period:From: August 2026To: August 2027 The base year shall include: Configuration, setup and training. Licenses and limited data import for 7 stations, 7 training sessions. 7 operational stations plus one non-production test system. Command and investigation licenses for each station including the test system One CAD connection license will be included for the KSC station. Program service licenses including PMO, HIPAA certification, and authentication enablement licenses at all stations Each option year shall only include the recurring subscriptions for all stations including the test instance. Setup, data import, and web training shall not be included. Option YEAR 1: August 2027 – August 2028Option YEAR 2: August 2028 – August 2029Option YEAR 3: August 2029 – August 2030Option YEAR 4: August 2030 – August 2031 This synopsis is for information and planning purposes only and is not to be construed as a commitment by the Government nor will the Government pay for information solicited. Respondents will not be notified of the results of the evaluation.