Opportunity
Iowa State University Ionwave #RFQ-1001476 Addendum 1
Cloud-Hosted PKI and Network Onboarding Solution for Iowa State University
Posted
July 13, 2026
Respond By
August 10, 2026
Identifier
RFQ-1001476 Addendum 1
NAICS
541512, 541513
Iowa State University of Science and Technology (ISU) is seeking a cloud-hosted Public Key Infrastructure (PKI) and network onboarding solution to modernize its network access management. - Government Buyer: - Iowa State University of Science and Technology, Information Technology Services (ITS) - OEMs and Vendors Mentioned: - Cisco (ISE) - Microsoft (Intune, Entra ID, MECM) - Apple (JAMF) - HPE Aruba (ClearPass) - Products/Services Requested: - Cloud-hosted PKI and network onboarding solution (1 unit) - Must support certificate-based 802.1X EAP-TLS authentication for both wired and wireless networks - Coverage for managed devices (via Intune and JAMF), unmanaged university-owned and BYOD devices, and sponsored guests - Integration with Cisco ISE as the sole RADIUS enforcement point (no parallel RADIUS infrastructure allowed) - REST API for ITSM integration - Detailed audit logging - High availability (minimum 99.9% uptime SLA) - SCEP and EST support - Customizable certificate templates - OCSP/CRL endpoints - Entra ID and SAML/OIDC integration - Compliance with WCAG 2.1 AA digital accessibility standards - Self-service onboarding and guest registration - Robust certificate lifecycle management - Implementation and training services - Ongoing technical support services - Unique/Notable Requirements: - Solution must not require a parallel RADIUS infrastructure; Cisco ISE remains the sole enforcement point - Must integrate with Microsoft Intune, JAMF, Entra ID, and provide REST API for ITSM - Accessibility compliance (WCAG 2.1 AA) is mandatory - High availability and detailed audit logging required - Open to qualified vendors able to meet these technical and security requirements
Description
Iowa State University of Science and Technology (ISU) is soliciting proposals for a cloud-hosted Public Key Infrastructure (PKI) and network onboarding solution to replace the university's legacy network registration system. The solution must support certificate-based 802.1X EAP-TLS authentication across wired and wireless infrastructure for managed devices, unmanaged university-owned and BYOD devices, and sponsored guests with self-service onboarding. Cisco ISE will remain the sole RADIUS enforcement point, and the solution must provide a REST API for ITSM integration and detailed audit logging. The solicitation includes requirements for integration with Intune and JAMF, high availability, certificate lifecycle management, and compliance with digital accessibility standards.