I. INTRODUCTION This request for information is for market research purposes only in accordance with Federal Acquisition Regulations (FAR) Part 10 procedures. This is not a solicitation, nor does it guarantee a solicitation will be issued. Requests for a solicitation will not receive a response. This is not a request for proposals, and it does not obligate the government in any manner. The mission of the Department of Veterans Affairs (VA), Office of Procurement, Acquisition, and Logistics, Technology Acquisition Center (TAC) is to support our Nation’s Veterans by providing acquisition and logistics solutions for VA. In meeting these goals, TAC is responsible for preparing and executing quality contracts that support the Information Technology (IT) efforts and needs of its customers across VA, which enables our customers to provide best value solutions to Veterans and their families. TAC employees are forward-thinking, smart, and innovative acquisition professionals, with strong technical and leadership competencies. To continue to offer our customers customized and responsive service, maintain nimble operations, and provide expert technical support services, TAC must ensure its workforce continues to enhance and maintain knowledge and awareness across a variety of current and emerging IT technologies and trends. II. GENERAL The Contractor shall provide training on the following topics: Federal Healthcare and Medical Device Cybersecurity Acquisition. Training will be delivered primarily to General Schedule (GS) series 0801 (GS-0801) General Engineering, GS-0854 Computer Engineering professionals as well as Contracting Professionals (GS-1102) who support TAC acquisition and VA business partners in the development, refinement, evaluation, and acquisition of technical requirements for healthcare technologies, medical devices, associated information technology, and related products and services. Training attendees may include, but are not limited to: GS-0801 / 0854 General Engineer / Computer Engineers who support the development of the technical portions of the acquisition packages as well as the technical evaluations. GS-1102 Contract Specialists and Contracting Officers who support, write, and administer acquisition contracts for IT commodity and services in accordance with Federal law, regulation, and policy. GS-0340 Program Managers and GS-1101 General Business and Industry professionals who support Contracting and TAC business partners in management of programs and TAC organizational needs. III. TRAINING REQUIREMENTS The TAC has a requirement for Federal Healthcare and Medical Device Cybersecurity Acquisition training to be delivered to its workforce. Facilitation – All training courses shall be “live,” virtual, instructor led training delivered in real-time and not pre-recorded or self-paced. Schedule – All training shall be delivered in Fiscal Year 2025 between October 1, 2026, through June 30, 2027. No training is permitted during 4th quarter of the Fiscal Year. The Contractor is responsible for coordinating a final training schedule in accordance with the requirements in this notice for approval by the Government within two (2) weeks of the training start date. Course Content – Contractors shall effectively utilize demos, knowledge checks, and hands-on learning activities as appropriate. The training courses shall include up-to-date training material on the latest versions of the latest products. Students should be provided with or have access to view, listen, and/or print all course content. Course content shall be available online to students in video, audio and/or written transcript formats. Changes – The Contractor shall accommodate student changes within 24-hours of the start of any training class session. Changes include student drop-out, student additions, and student switches. It does not include additional students beyond the stated student maximums. Technical Support – The Contractor shall be always available during the course. Section 508 – The training shall meet Section 508 compliance standards IV. TRAINING DELIVERABLES All deliverables shall be in a standardized format. 1. Kick-off Meeting and Course Schedule (Deliverable 1) The Contractor shall conduct a kick-off meeting within one (1) week of contract award with the Government POCs. The Contractor shall coordinate a final course schedule for approval by the Government. The Contractor shall coordinate a final Training Schedule with draft course curriculum in accordance with the requirements of this PWS for approval by the Government. 2. Welcome Letter / Course Curriculum and Training Materials (Deliverable 2) The Contractor shall provide the Course Curriculum and Training Materials to the Government POCs no later than two weeks prior to the scheduled start date of the training course. The Course Curriculum and Training Materials shall include the course agenda, learning objectives, presentation materials, and materials for practical exercises, case studies, and job aids, as applicable. The Contractor shall be responsible for coordinating with the Government point of contract (POC) to release a welcome letter and virtual training invites to all attendees within three (3) days prior to the start of the training. 3. Attendee Roster (Deliverable 3) The Contractor shall take attendance for each training course and provide an attendance sheet to the Government delivery POCs. The attendee roster shall include the name, email, and timestamps of the attendees. Training that is multi-day shall have attendance taken each day. Training course attendance is estimated to be 20- 25 students per class. 4. Certificate of Completion (Deliverable 4) The Contractor shall coordinate with the designated Government POC for Continuous Learning Points (CLPs) approval with all awarded training. Training that extends for a working day (including lunch and breaks) shall be 8 CLPs per full day. The Contractor shall email a certificate of completion to each student within one (1) week of course completion. Certificates of Completion shall include, at a minimum, the name of the training course, training date(s), instructor, Contractor’s name, student’s name, and number of CLPs earned. 5. Feedback Survey (Deliverable 5) The Contractor shall collect training feedback from attendees upon completion of each training course. Feedback shall be provided to the Government delivery POC within three (3) weeks of the training course completion. Feedback information shall be organized and clearly presented. V. TRAINING COURSE The training course shall be “live” virtual instructor led in real time via MS Teams, and meet the requirements identified in this PWS. Contractors shall effectively utilize demos, knowledge checks, and hands-on learning activities as appropriate. The Contractor shall be responsible for coordinating with the Government POCs to release a welcome letter and virtual training invites for attendees. Task 1 – Federal Healthcare and Medical Device Cybersecurity Acquisition Training Course The Contractor shall provide Federal Healthcare and Medical Device Cybersecurity Acquisition training in accordance with Section IV above. The total duration of the training course shall not exceed 24 training hours. For purposes of this requirement, a full business day is equivalent to eight training hours. Training may be delivered as a single course session or divided into multiple training sessions. Individual training sessions may consist of consecutive full or partial business days; however, multiple training sessions are not required to occur consecutively. The specific training schedule, including the number of sessions, session duration, and training dates, shall be coordinated with and approved by the Government. Training shall include practical exercises, demonstrations, knowledge checks, and acquisition-focused case studies, as appropriate. The training shall cover the following areas: VA Healthcare Environment and Medical Technology Fundamentals. Overview of the VA healthcare delivery environment and the role of VA medical centers and other care settings in supporting Veterans. Roles of clinicians, biomedical/clinical engineering personnel, information technology and cybersecurity personnel, PMs, requiring activities, and other stakeholders relevant to technology acquisition. Healthcare technologies and medical devices commonly acquired for or deployed within VA healthcare environments, including connected and network-enabled medical devices, clinical systems, supporting information technology, and associated vendor/manufacturer services 2. Medical Device Architecture, Connectivity, and Integration Medical device and healthcare technology architecture, including connectivity, interfaces, software, firmware, operating systems, cloud or external services, and third-party dependencies. Integration and interoperability with VA networks, enterprise systems, clinical applications, interfaces, Application Programming Interfaces (APIs), and supporting infrastructure. Cybersecurity considerations for data created, received, processed, stored, or transmitted by healthcare technologies 3. Federal Healthcare and Medical Device Cybersecurity Fundamentals Common cybersecurity threats, vulnerabilities, and attack vectors affecting healthcare technologies and connected medical devices. Fundamental security considerations, including authentication and access control, secure configuration, network security and segmentation, encryption and data protection, security logging and monitoring, and remote access. Vulnerability management concepts, including identification, disclosure, remediation, security patching, software and firmware updates, compensating controls, and risks associated with legacy or unsupported technology. Supply chain cybersecurity considerations associated with medical devices and healthcare technologies. 4. Cybersecurity Risk in the Healthcare Environment How cybersecurity risks and failures involving healthcare technologies and medical devices may affect Veteran care, patient safety, clinical operations, protection of sensitive information, system availability, and continuity of VA healthcare services. Technology dependencies and potential operational impacts when cybersecurity vulnerabilities cannot be immediately remediated. Balancing cybersecurity risk with clinical, operational, availability, and patient safety considerations. 5. Healthcare Cybersecurity in the Acquisition Process Identifying key healthcare and medical device cybersecurity considerations during requirements development, acquisition planning, and market research. Understanding how cybersecurity considerations may affect technical requirements, contractor deliverables, proposal evaluations, testing, verification, acceptance, and contract administration. Identifying cybersecurity information and documentation that may be needed from manufacturers or prospective contractors to support technical evaluation and acquisition decisions. Understanding the respective roles of TAC engineers, Contracting Officers, Contract Specialists, requiring activities, and appropriate subject matter experts in addressing healthcare technology cybersecurity considerations. Applying healthcare and medical device cybersecurity considerations to acquisition requirements through practical examples or case studies. 6. Manufacturer and Vendor Cybersecurity Considerations Manufacturer/vendor vulnerability disclosure, remediation, security patching, and software and firmware update processes and responsibilities. Cybersecurity considerations associated with vendor remote access, maintenance, technical support, and ongoing manufacturer support. Cybersecurity documentation and technical artifacts relevant to acquisition and lifecycle support, including software/component transparency and security configuration information. Cybersecurity considerations throughout the technology lifecycle, including deployment, sustainment, vulnerability management, maintenance, end-of-support, end-of-life, obsolescence, and technology refresh. 7. Federal and VA Cybersecurity Requirements and Guidance Overview of Federal and VA cybersecurity requirements, policies, standards, and guidance relevant to healthcare technology and medical device acquisitions. Awareness of applicable NIST, FDA, HHS, and VA cybersecurity requirements and guidance and their relevance to acquisition activities. Understanding the distinction among mandatory requirements, contractual requirements, regulatory requirements, consensus standards, frameworks, and recommended practices. 8. Emerging Topics Trends in healthcare threat intelligence and regulatory direction Training approach : Practical Exercises and Case Studies Use acquisition-focused exercises and case studies involving healthcare technologies and connected medical devices relevant to VA healthcare environments. Exercises shall demonstrate how participants identify cybersecurity considerations, questions for the VA customer/PM, information needed from vendors, and potential impacts on requirements, deliverables, evaluation, and acceptance. Exercises shall demonstrate collaboration between TAC engineering and contracting personnel while maintaining the appropriate responsibilities of each acquisition function. Case studies may include relevant examples from VA, other Federal healthcare organizations, or comparable healthcare delivery environments. Practical Tools and Reference Materials Provide practical checklists, reference materials, or other job aids that TAC personnel can use when reviewing healthcare technology requirements and supporting acquisitions. Materials shall address key cybersecurity considerations across the acquisition and technology lifecycle, including requirement development, market research, solicitation, evaluation, acceptance, sustainment, and end-of-life. VI. DISCLAIMER Responses to this RFI will not be returned. Respondents will not be notified of the Government's evaluation of the information received. Any information or comment resulting from this request that is determined to be useful will be used to help the Government further define their requirement and may be incorporate into the final version of the Product Description. Respondents are advised that the Government is under no obligation to acknowledge receipt of the information received or provide feedback to respondents with respect to any information submitted. This RFI is issued solely for information and planning purposes only and does not constitute a solicitation. All information received in response to this RFI that is marked as proprietary will be handled accordingly. Responses to this RFI are not offers and cannot be accepted by the Government to form a binding contract. Responders are solely responsible for all expenses associated with responding to this RFI. RESPONSES/RFI SUBMISSION Please provide the following information: Detailed Course overview Learning objectives Course content Duration of course Min/Max number of students allowed per course Cost per course – please include the number of students included in the cost of each course. Cost per each additional student. Please answer the following questions and include the requested information as part of your response. Include the following identification information as it pertains to your organization: Company Name Company Unique Entity Identification Number Company Address Company points of contact name, telephone number, and email address Please submit a capability statement describing your company’s abilities to provide the requested training identified in this Request for Information (RFI). The capability statement shall be limited to 10 pages. Please submit the information requested in this RFI by 3:00 p.m. EST on October 21, 2026 , to the Management and Program Analyst, Meryl Czaplinski, Meryl Czaplinski@va.gov. VA reserves the right to not respond to any, all, or select responses or materials submitted.