Opportunity
Oregon Buys #S-10700-00017534
Statewide Secure Service Edge solution, implementation, and support for Oregon agencies
Posted
September 30, 2026
Respond By
October 30, 2026
Identifier
S-10700-00017534
NAICS
541519, 541512, 541513
Oregon is seeking a statewide Secure Service Edge (SSE) platform and related implementation and support for state agencies. - Government buyer: State of Oregon, Department of Administrative Services (DAS), State Procurement Services (DAS SPS), on behalf of Enterprise Information Services (EIS) and participating state agencies. - OEMs and named technology vendors: No specific SSE provider or OEM is selected or required. Named examples include Splunk, Microsoft (Microsoft Sentinel, Microsoft Authenticator, Active Directory, Azure AD, Azure, and Microsoft 365), Duo, Okta, Google (Google Workspace and Google Cloud Platform), CrowdStrike, SentinelOne, AWS, Salesforce, Ansible, and Terraform. LDAP is also referenced as an identity integration standard, not a vendor. - Requested solution: A modular statewide SSE offering covering Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), Digital Experience Monitoring (DEM), Remote Browser Isolation (RBI), Firewall as a Service (FWaaS), DNS Security, and SaaS/API Security. - Evaluation quantities: 50,000 users for each of the nine listed SSE components. These quantities support price comparison and do not commit the State to buy that volume. The bid schedule also lists one statewide SSE solution and one each of networking, processing, security, and software. - Related services: Implementation, integration, testing, migration and transition; professional services; maintenance and updates; enterprise and enhanced support; technical account services; and administrator, operations/SOC, agency, and train-the-trainer instruction. Vendors must provide role-based professional-services rates and itemize one-time and recurring costs. - Notable requirements: At least 50,000 concurrent users; 99.99% uptime; 30-minute recovery time objective and 15-minute recovery point objective; latency under 100 ms for 95% of global users; TLS 1.3 or higher with perfect forward secrecy; secure immutable compliance logging, including CJIS and FTI, with SIEM integration; configurable data residency; identity- and device-aware access; and multi-agency tenancy with role-based administration. - Security and accessibility: The solution must meet or exceed NIST SP 800-53 Moderate controls, address Oregon’s restrictions on offshore and foreign services, protect sensitive information, and meet WCAG 2.1 Level AA accessibility requirements. The State also seeks stable APIs, automation support, and documented 24x7 support SLAs.
Description
The State of Oregon Department of Administrative Services, State Procurement Services, on behalf of Enterprise Information Services, is seeking a Secure Service Edge (SSE) solution that meets state technical, security, and operational requirements. The solution is intended to provide unified security policy enforcement, protect sensitive data, and enable secure access to cloud-based and on-premises applications and resources. The RFP anticipates multiple price agreements, with one primary contractor for EIS and EIS-governed agencies; the anticipated initial term is five years with renewal options. Proposals are due October 30, 2026, at 4:00 PM PST.