Loading...
80TECH26RFI0023
Response Deadline
Aug 3, 2026, 11:00 PM(CDT)7 days
Eligibility
Contract Type
Sources Sought
THIS IS NOT A REQUEST FOR PROPOSAL. NO PROPOSALS ARE TO BE SUBMITTED IN RESPONSE TO THIS NOTICE.
This notice is issued by NASA/ITPO to post a Statement of Work to solicit responses from interested parties. This document is for information and planning purposes and to allow industry the opportunity to verify reasonableness and feasibility of the requirement, as well as promote competition.
Fire & Emergency Medical Services Records Management System (FEMSRMS) BASE + 4 Option Years
NASA/ITPO is hereby soliciting information from potential sources for Fire & Emergency Medical Services Records Management System (FEMSRMS) BASE + 4 Option Years
The National Aeronautics and Space Administration (NASA) ITPO seeking capability statements from all interested parties, including all socioeconomic categories of Small Businesses (SB) and Historically Black Colleges and Universities (HBCU)/Minority Institutions (MI) for the purposes of determining the appropriate level of competition and/or small business subcontracting goals for Fire & Emergency Medical Services Records Management System (FEMSRMS) BASE + 4 Option Years. Vendors are encouraged to demonstrate capabilities as a prime, subcontractor and/or teaming partner. The Government reserves the right to consider a Small Business, Small Disadvantaged Business (SDB), HUBZone, Veteran Owned Small Business (VOSB), Service-Disabled Veteran Owned Small Business, and Women-Owned Small Business (WOSB) set-aside based on responses received.
Respondents are requested to provide informed input on realistic and appropriate SB subcontracting and/or participation goals for the specific requirement. This type of feedback supports NASA’s market research and helps ensure the acquisition strategy is aligned with actual industry capability. Industry feedback is requested for:
1.SB Subcontracting goals;
2 Barriers that may limit SB participation, such as certifications, uniquetechnical requirements, security needs, specialized tools, or high-risk performance areas and/or
3.Strategies to increase SB participation, including:
•Breaking requirements into smaller components
•Identifying areas appropriate for subcontracting
•Considering teaming or mentor protégé approaches
This RFI is not to be construed as a commitment by the Government, nor will the Government pay for the information submitted in response. The Government may
2
Rev.: 05/2026
not respond to questions/concerns submitted. The Government will use the information to finalize the RFP as necessary.
All comments or questions must be submitted electronically via email to Kimberly Sandoz Kimberly.r.sandoz@nasa.gov and Cory Rasnic cory.t.rasnic@nasa.gov, no later than 8/03/2026 @ 6:00PM EST. When responding reference RFI # 80TECH26RFI0023.
NASA Clause 1852.215-84, Ombudsman, is applicable. The Center Ombudsman for this acquisition can be found at: https://www.hq.nasa.gov/office/procurement/regs/Procurement-Ombuds-Comp-Advocate-Listing.pdf
If a solicitation is released, then it and any additional documents will be available on Sam.gov. It is the offeror's responsibility to monitor this website for the release of the solicitation and amendments (if any). Potential offerors will be responsible for downloading their own copy of the solicitation and amendments, if any.
The key details are summarized below:
STATEMENT OF WORK (SOW)
1.General Information
Project Title:
Fire & Emergency Medical Services Records Management System (FEMSRMS)
Agency/Organization:
OCIO on behalf of the Office of Protective Services
Requiring Activity:
Procure a Commercial off the Shelf (COTS) Software as a Service (SaaS) solution for Fire and EMS Records Management
Program Office: Office of Protective Services
Date: July 2026
2.Background
The NASA Office of Protective Services (OPS) fire departments require a robust, integrated, and secure Records Management System (RMS) to replace outdated, manual, and fragmented systems. Increasing emergency service demands have amplified risks and inefficiencies associated with spreadsheet-based record keeping, creating operational gaps that jeopardize firefighter safety, mission assurance, and Center readiness. Implementing a comprehensive RMS directly supports OPS’s strategic commitment to safeguarding NASA personnel, infrastructure, and mission-critical operations. To ensure capital project delivery, improve oversight and reporting capabilities, and to mitigate risk, NASA requires a Commercial Off the Shelf (COTS) and Software as a Service (Saas) enterprise-level Fire and EMS solution that aligns with industry standards and is robust, integrated and secure.
3
Rev.: 05/2026
3.Objective
NASA seeks to acquire a Commercial Off the Shelf (COTS) solution for Fire and EMS Records management system along with Professional Services for tailoring and implementation of such a system. The configured COTS solution shall be known as Fire & Emergency Medical Services Records Management System (FEMSRMS)
NASA’s objective with the acquisition of FEMSRMS is to implement and configure a COTS solution that will:
•Replace manual and fragmented fire and EMS Records Management Systems witha modern cloud-based solution that meets NASA OPS and OCIO requirements.
•Enable site consolidation for data sharing.
•Achieve cost savings through efficiencies gained from reducing the number ofsolutions maintained/supported.
The contractor shall provide a cloud-based configured COTS offering, shall meet the technical and operational requirements herein, shall ensure integration with specified information technology (IT) systems and software, and shall operate and maintain FEMSRMS in accordance with industry best practices, Federal Regulations, and NASA guidelines and requirements. The contractor shall provide a solution that is Federal Risk and Authorization Management Program (FedRAMP) High Authorized at the time of contract award. The Government intends to achieve Agency Authority to Operate (ATO), in accordance with NPR 7120.7.
4.Scope
4.1 Functional Standards
4.1.1 The solution must be a COTS product and hosted in a cloud environment.
4.1.2 The FEMSRMS solution must provide the following capabilities:
•Incident reporting & fire documentation: create fire/incident reports andemergency response documentation with FRMS capture, NERIS v1connectivity and an NFIRS legacy crosswalk for reporting.
•ePCR & hospital data exchange: NEMSIS-compliant electronic patientcare reporting that is HIPAA-aware, includes a hospital handoff packet,and supports one-way digital transfer to receiving facilities.
•Integrated authentication & security: PIV-based integrated authenticationfor users.
•CAD ingestion & mobile responder/notifications: vendor-agnostic CADinterface (Central Square compatibility required), mobile respondercapability (notifications, incident access on any device), and offline-capable mobile cache with sync-on-reconnect for intermittent-connectivitysites (e.g., White Sands, Stennis).
•Pre-Incident Planning: Build actionable pre-incident plans for responsepersonnel.
4
Rev.: 05/2026
•Connections to ESRI/ArcGIS for mapping, hydrant and water supplytracking
•Facility inspections, pre-plans, and ITM: mobile inspection and pre-planworkflows with deficiency tracking, Inspect-Test-Maintain (ITM)management, trend/reporting on inspection compliance.
•Personnel scheduling & rostering: centralized personnel records, roster andleave management, qualifications tracking, auto shift-coverage proposals,and automated staffing notifications.
•Training, virtual training & compliance: course catalog, completionrecords, certification-expiry alerts, virtual end-user training, and traininganalytics for compliance with applicable standards (e.g., NFPA, FAA,NASA where required).
•Exposure tracking & health/wellness: per-responder, per-incident exposurehistory, cancer-presumption alignment, and health/wellness documentationand reporting.
•Incident command & on-scene accountability: ICS form set, tacticalworksheets, resource tracking, action-item tracking, and personnelaccountability at incidents.
•Apparatus, equipment, fleet & asset management: asset register forapparatus and equipment, maintenance scheduling, OOS tracking, recallmanagement, inspections, and lifecycle/supply tracking.
•Narcotics & controlled-substance management: DEA-compliant chain-of-custody, witnessed waste, reconciliation, and controlled-substance trackingintegrated with asset/inventory controls.
•Investigations & evidence management: fire cause-and-origindocumentation with customizable investigation forms and full evidencechain-of-custody tracking.
•Events, activities & non-incident records: capture and report dailydepartmental activities and non-incident events.
•Data, analytics & reporting: incident analytics, compliance and inspection-trend reports, and exportable data for downstream use.
•Data migration & test environment: limited/legacy data import capabilityplus a separate non-production test/sandbox environment for training andconfiguration testing.
4.1.3 The solution will provide 2 stations at Kennedy Space Center, 2 stations at Wallops Flight Facility, 1 station at Stennis Space Center, 1 station at Ames Research Center, 1 station at White Sands Test Facility, and one independent non-production test environment. The procurement will be for one initial year
5
Rev.: 05/2026
where configuration, setup and training are included in the initial year. Along with four additional option years where configuration, setup and training are not included. Each year will include annual maintenance for the application and hosting infrastructure.
4.2 Accessibility
4.2.1 Section 508 Compliance. NASA is committed to providing accessible Information and Communication Technology (ICT) to individuals with disabilities, including members of the public and federal employees. The contractor-provided solution shall meet or exceed all requirements of Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d).
4.3 Data Rights and Purchase Authorization
4.3.1 In accordance with FAR 52.227-14 Rights in Data-General (May 2014), the contractor shall provide the Government with unrestricted ownership rights to the project data within the software/program.
4.3.2 IT Purchase Authorization.
4.3.2.1 The contractor shall ensure all IT products and services direct charged to the contract are approved through the NASA OCIO’s Commercial IT Request (CITR) Application. This includes, but is not limited to, Federal Information Technology Acquisition Reform Act (FITARA), Supply Chain Risk Management (SCRM), and IPv6 and 508 compliance. No purchases of commercial IT products or services should be made prior to coordination and approval by the OCIO.
4.3.2.2 This contract shall only be used to purchase software, software maintenance, hardware, or hardware maintenance necessary for the performance of this contract. NASA shall own the license(s) or subscriptions for any software or applications purchased.
4.4 Security Requirements
4.4.1 The contractor COTS solution shall support a secure, multi-factor authentication (MFA) method for Government-consuming end users to access the service and for Government personnel who will perform administrative duties. The contractor shall support integration of the service with multi-factor NASA authentication services including Single Sign On (SSO) and Federal Government Personal Identity Verification (PIV) Card access. A user inside NASA’s firewall shall be able to access the solution without having to provide separate credentials. The contractor provided solution shall support an MFA solution that aligns with all applicable Federal IT security standards and policies. Access controls must comply with the applicable portions of all NASA and Federal IT Security standards and policies listed in Paragraph 5. These policies include session timeouts and inactive user lockouts. The information system/IT solution shall support role-based access controls to distinguish between end users needing access to different levels of data (e.g., end users only needing access to non-sensitive data and end users needing access to sensitive data).
4.4.2 The system shall have a FedRAMP High Authorization package. FEMSRMS shall have an active FedRAMP High Authorization package and shall maintain authorization through the performance period of the contract.
6
Rev.: 05/2026
4.4.3 All work associated with the performance of this contract shall be performed off-site. Access to NASA Center/Sites/Facilities will not be required.
5.Applicable Documents
The contractor shall be subject to all NASA and Federal IT Security standards, policies, and reporting requirements. The contractor shall meet and comply with all NASA IT Security Policies and all applicable NASA and Federal standards and guidelines, and other Government-wide laws and regulations for protection and security of Information Technology. The contractor shall comply with the following policies and regulations:
•Federal Information Security Management Act of 2002 (44 U.S.C. 3541 - 3549)
•Homeland Security Presidential Directive (HSPD)-12: Policy for a CommonIdentification Standard for Federal Employees and Contractors
•Americans with Disabilities Act - Section 508 (29 U.S.C 794d)
•NPD 2800.1, Managing Information Technology
•NPR 2800.2, Information and Communication Technology Accessibility
•NPR 2841.1, Identity, Credential, and Access Management
•NPD 1382.17, NASA Privacy Policy
•NPD 2810.1, NASA Information Security Policy
•NPD 1420.1, NASA Forms Management
•NPD 1440.6, NASA Records Management
•NPD 1490.1, NASA Printing, Duplicating, and Copying Management
•NPR 1382.1, NASA Privacy Procedural Requirements
•NPR 1441.1, NASA Records Management Program Requirements
•NPD 2540.1, Acceptable Use of Government Office Property IncludingInformation Technology
•NPD 2830.1, NASA Enterprise Architecture
•NPR 1040.1, NASA Continuity of Operations (COOP) Planning ProceduralRequirements
•NPR 2810.1, Security of Information and Information Systems
•NPR 2810.7, Controlled Unclassified Information
•NPR 2830.1, NASA Enterprise Architecture Procedures
•NPR 7120.7, NASA Information Technology and Institutional InfrastructureProgram and Project Management Requirements
•The following handbooks relevant to the development, authorization, andmaintenance of NASA information systems. (Current versions as postedon https://cset.nasa.gov/ascs/cspd-handbooks/)
i.ITS-HBK-AASTEP0.v1.0.0 Step 0: Prepare Policy
ii.ITS-HBK-AASTEP1.v1.0.0 Step 1: Categorize Policy
iii.ITS-HBK-AASTEP2.v1.0.0 Step 2: Select Policy
iv.ITS-HBK-AASTEP3.v1.0.0 Step 3: Implement Policy
7
Rev.: 05/2026
v. ITS-HBK-AASTEP4.v1.0.0 Step 4: Assess Policy
vi. ITS-HBK-AASTEP5.v1.0.0 Step 5: Authorize Policy
vii. ITS-HBK-AASTEP6.v1.0.0 Step 6: Monitor Policy
Note: Cybersecurity Handbooks, and standards that apply to specific tasks or requirements are accessible internal only at https://cset.nasa.gov/ascs/cspd-handbooks/ and must be obtained from the Contracting Officer.
6. Contractor Responsibilities
The contractor shall provide all material, equipment, and labor necessary to perform all tasks associated with the licensing, hosting, configuration, testing, integration, data migration, implementation, training, and administration of the contractor provided solution. This shall include, but is not limited to, technical implementation of all system enhancements including beta testing, minor releases, major releases, software updates, and configuration changes.
The Contractor shall:
• Provide qualified personnel.
• Furnish all management, supervision, labor, equipment, and materials unless otherwise specified.
• Maintain project schedules.
• Comply with all applicable federal regulations.
• Protect Government information.
• Coordinate with Government personnel.
• Maintain required licenses and certifications.
7. Place of Performance
All work associated with the performance of this contract shall be performed off-site. Access to NASA Center/Sites/Facilities will not be required.
8. Period of Performance
Base Period:
From: August 2026
To: August 2027
The base year shall include:
• Configuration, setup and training.
• Licenses and limited data import for 7 stations, 7 training sessions.
• 7 operational stations plus one non-production test system.
• Command and investigation licenses for each station including the test system
• One CAD connection license will be included for the KSC station.
• Program service licenses including PMO, HIPPA certification and authentication enablement licenses at all stations
8
Rev.: 05/2026
Each option year shall only include the recurring subscriptions for all stations including the test instance. Setup, data import and web training shall not be included.
Option YEAR 1: August 2027 – August 2028
Option YEAR 2: August 2028 – August 2029
Option YEAR 3: August 2029 – August 2030
Option YEAR 4: August 2030 – August 2031
This synopsis is for information and planning purposes only and is not to be construed as a commitment by the Government nor will the Government pay for information solicited. Respondents will not be notified of the results of the evaluation.
Cory Rasnic
Kimberly Sandoz
NATIONAL AERONAUTICS AND SPACE ADMINISTRATION
NATIONAL AERONAUTICS AND SPACE ADMINISTRATION
NASA IT PROCUREMENT OFFICE
NASA IT PROCUREMENT OFFICE
8800 Greenbelt Road
Greenbelt, MD, 20771
NAICS
Software Publishers
PSC
IT and Telecom - End User as a Service: Help Desk;Tier 1-2,Workspace,Print,Output,Productivity Tools