Request for Proposals: Software Systems Modernization

SBCAPCD is soliciting proposals from qualified software development partners to collaborate on the ongoing modernization of its in-house line-of-business software (the Integrated Database System, or IDS). The full Request for Proposals, including scope of work, qualifications, and submission requirements, is available for download below.

Request for Proposals

Key Dates

RFP releasedJuly 1, 2026
Deadline to submit questionsJuly 21, 2026, 5:00 p.m. (Pacific)
Answers & any amendments posted byJuly 24, 2026, 5:00 p.m. (Pacific)
Proposals dueJuly 31, 2026, 5:00 p.m. (Pacific)

How to Submit a Proposal

  • Submit electronically in PDF format to [email protected].
  • Use the email subject line: RFP Response – Software Systems Modernization – [Firm Name].
  • Proposals must be received by the due date above. Late proposals will not be considered.
  • Follow the structure outlined in the Proposal Requirements section of the RFP.

__________________________________________________________________________________________________________________________________________

Questions & Answers

All questions regarding this RFP must be submitted in writing by email to [email protected] no later than July 21, 2026, 5:00 p.m. (Pacific). Questions received after this deadline will not be answered.

Responses to all questions received, together with any amendments to the RFP, will be posted on this page. Questions are published without identifying the firm that submitted them. It is each proposer’s responsibility to check this page for posted responses and amendments before submitting. Only written responses posted here are official and binding; informal or verbal communications do not bind SBCAPCD.

Q1. Is an international team performing the work primarily remotely eligible to respond?

While remote collaboration is expected to be the primary mode of engagement, as stated in Section 8 (Work Location), all partner staff assigned to this project must be located in and perform work from the United States. SBCAPCD will not be contracting with parties outside of the United States at this time. Proposals in which assigned staff would perform work from outside the United States will not be considered.

Q2. Is a joint proposal, consortium, or prime-contractor/subcontractor structure permitted?

Yes. SBCAPCD will consider any team makeup or structure — including a single firm, a joint proposal, a consortium, or a prime-contractor/subcontractor arrangement — provided the proposing team collectively meets the Required Qualifications in Section 9 and all assigned staff comply with the Work Location requirement in Section 8. Proposers electing a multi-party structure should clearly identify the proposing entity, all named delivery partners, and the roles and responsibilities of each within the proposed team.

Q3. May the five representative projects and three client references be satisfied collectively by the proposing team and its named delivery partners?

Yes. The requirement in Section 10.2 for at least five (5) representative projects and at least three (3) client references may be satisfied collectively by the proposing team and its named delivery partners. The projects and references may be drawn from any combination of team members, provided they collectively meet the requirement and reflect a range of project types and client relationships as described in Section 10.2. Proposers should indicate which team member or delivery partner performed each project referenced.

Scope, Applications & Phasing 

Q4. How many applications make up IDS, how many will be modernized in the initial phase, and which application(s) will be included in Phase 1? 

IDS comprises on the order of ten line-of-business Windows Forms applications, which vary considerably in size and complexity. Phase 1 is expected to include one, possibly two, applications, with a current expectation of one. The specific application(s), and any prioritized list, are intentionally left open and will be confirmed collaboratively during discovery, based on where the in-house modernization effort stands when the contract is signed (Section 5, Appendix B). 

Q5. Can SBCAPCD provide sizing information or an application inventory for the anticipated first application? 

For the anticipated first application, general sizing is on the order of 20 or more projects, 40 or more screens, and approximately 250 related stored procedures. (For overall context, the shared database contains 1,000+ tables and 4,500+ stored procedures per Appendix A.) A more detailed inventory — including reports, printable documents, background services, scheduled jobs, approximate code size, and business criticality — will be provided for the in-scope application(s) during discovery. 

Q6. Apart from functional parity, are there measurable modernization objectives? 

Beyond functional parity for core workflows, SBCAPCD’s objectives include a modernized, more usable interface with efficient high-volume data entry; improved maintainability and reduced reliance on knowledge held by a small number of individuals; establishment of an in-process service boundary; and a logging, testing, and diagnostics baseline (Section 3, Appendix B). These are qualitative objectives; SBCAPCD has not established specific quantitative performance targets, and any such measures would be developed collaboratively during discovery. 

Q7. Should the estimate assume migration of all active screens, and is feature parity required for every screen? 

Estimates should assume migration of all active screens for each Phase 1 application. Functional parity for core workflows is the primary focus and a governing Phase 1 exit criterion; during discovery, SBCAPCD and the partner will jointly identify any screens or functions that may be retired, deferred, improved, or excluded, subject to SBCAPCD approval. 

Q8. Can a sample or summary of the prioritized enhancement list be shared? 

A sample enhancement list is not available for distribution at this time. Enhancements to be delivered within the approved scope will be identified and prioritized collaboratively during discovery. 

Q9. Will modernization occur in parallel with ongoing development in the legacy applications, or will the legacy systems be subject to a code freeze? 

Modernization will occur in parallel with continued operation and maintenance of the legacy applications; no code freeze is planned. The legacy applications must remain operational and usable as a fallback throughout Phase 1 (Appendix B), with both generations running side-by-side against the shared database. 

Incumbent Vendor, Award & Future Phases 

Q10. Who is the incumbent vendor, and may they participate in this RFP? 

There is no incumbent vendor. The IDS modernization effort is led by SBCAPCD’s in-house team, and this RFP is intended to expand delivery capacity rather than replace an existing contractor. The question of incumbent participation is therefore not applicable. 

Q11. Will the engagement be awarded to a single vendor, and may a team, consortium, or prime/subcontractor structure propose? 

SBCAPCD anticipates awarding the engagement to a single proposer. That proposer may be a single firm or a team (including a joint proposal, consortium, or prime-contractor/subcontractor arrangement), provided the proposing team collectively meets the Required Qualifications in Section 9 and all assigned staff comply with the Work Location requirement in Section 8. (See also the previously posted responses on team structure and references.) 

Q12. How many modernization phases are anticipated after Phase 1, and will the same vendor continue? 

IDS encompasses many line-of-business applications that will be modernized over successive phases (Section 3.1). More than one additional phase is likely, but the total number and schedule are not fixed and will depend largely on the in-house team’s progress. A partner who demonstrates strong performance, effective collaboration, and quality deliverables would be well-positioned for continued and expanded involvement, subject to applicable procurement requirements. SBCAPCD values continuity and the domain knowledge that comes from a sustained working relationship. 

Existing Technical Environment 

Q13. Has a compatibility study or proof-of-concept been performed for the WinForms/.NET Framework to WinUI 3 / .NET 10 migration, and can findings be shared? 

A staged modernization is already underway in-house, and foundational, cross-cutting infrastructure has been built and validated on the target stack (.NET 10 / WinUI 3, Windows App SDK). This in-house work effectively serves as a proof of concept for the migration approach. A separate formal compatibility study has not been produced as a standalone document. Relevant learnings, conventions, and architectural decisions will be shared with the selected partner at the appropriate stage of the engagement. 

Q14. Can proposers use the first modernized application as the reference for the target architecture and shared components, and will they receive access to conventions, ADRs, and the skill library at discovery? 

The first modernized application serves as the reference pattern for the target architecture, the in-process service boundary, and the shared bug/feature-reporting and in-app help components intended for reuse. As described in Section 4.1, this reference application, along with reusable shared components, architectural decision records, engineering conventions (including service contract, dependency injection, and error-handling/logging conventions), the development skill library, and pull-request/code-review standards, will be made available to the selected partner beginning with discovery. It is not available for review prior to award. 

Q15. What UI control gaps between WinForms and WinUI 3 have been identified, and are solutions standardized in the shared control library? 

Control gaps between the legacy WinForms controls and WinUI 3 — including grid and data-entry scenarios — have been identified through the in-house migration work, and solutions are being standardized through shared UI libraries and engineering conventions intended for reuse across subsequent applications. The specific control choices and patterns will be shared with the selected partner at the appropriate stage of the engagement. 

Q16. What technologies drive reporting and complex regulatory document generation, and will they be modernized? 

Complex regulatory document generation currently relies primarily on Microsoft Office automation (Office interop) to produce letters and formatted documents, and reporting is driven primarily by SQL Server Reporting Services (SSRS) with RDLC report definitions. These capabilities are expected to be carried forward and modernized as part of the in-scope work, with the specific technical approach determined collaboratively during discovery. 

Q17. Are there third-party UI component libraries, COM/ActiveX controls, charting or mapping tools, or specialized hardware peripherals, and will SBCAPCD provide any required licenses? 

Such dependencies are limited across the core IDS applications (Appendix A). No commercial third-party UI control suites or charting/data-visualization suites are used; applications share a common internal control library, and mapping is provided through an externally hosted service (the permitted facilities map at https://map.ourair.org/) rather than an embedded control. There may be minor licensed or third-party components in individual applications, and a limited number of COM/ActiveX and Office interop touchpoints have been noted; these would be handled as targeted migration items. No specialized hardware peripherals are involved. Any such dependencies in the in-scope application(s), and the associated licensing, will be identified and addressed during discovery. 

Q18. Besides the shared SQL Server database and network file shares, what external systems integrate with IDS? 

External integrations are limited. The most notable is the permitted facilities map (https://map.ourair.org/), which is provided by a third party (Monarch). A few other minor integrations exist, but none are significant enough to materially affect the modernization effort. Any integrations relevant to the in-scope application(s) will be confirmed during discovery. 

Q19. What authentication mechanisms are used — is it Active Directory only, or are there integrations beyond Windows Integrated Authentication? 

Authentication is primarily Windows-based (Windows Integrated Authentication). Some applications retain legacy SQL Server authentication for certain permissions. Additional detail can be confirmed during discovery. 

Q20. The database structure and stored-procedure interface are to be preserved. May the partner modify existing stored procedures, add new stored procedures, views, or other schema-additive objects? 

Yes. While the existing database structure and stored-procedure interface are preserved as the shared contract that keeps legacy applications operational, the partner may modify existing stored procedures, create new stored procedures, views, and other schema-additive objects, and make limited schema changes where necessary — under SBCAPCD naming conventions and subject to SBCAPCD review and approval. 

Q21. Do the legacy applications use long-running, UI-bound database transactions requiring refactoring, and how should simultaneous edits of the same record in the legacy and modernized applications behave? 

The legacy applications use UI-bound data-access patterns typical of Windows Forms applications of their era (Appendix A), and the target architecture’s in-process service boundary removes direct UI-to-database access for modernized components. Side-by-side operation of the legacy and modernized applications against the shared database is a Phase 1 requirement (Appendix B). The extent of any refactoring and the specific concurrency behavior for simultaneous edits are application-level design matters that will be assessed and decided collaboratively during discovery; they do not need to be resolved at the proposal stage. 

Q22. Are user manuals available to elaborate on system features and UI complexities? 

Some user-created manuals exist, but they are not comprehensive and are limited to one or two programs. Available documentation will be shared with the selected partner during discovery, and knowledge transfer from SBCAPCD staff is expected to complement written documentation. 

AI-Assisted Development & Tooling 

Q23. Which AI-assisted development tools are used, what governance should partners follow, and are supplementary development tools mandated? 

SBCAPCD currently uses Claude (Anthropic) as part of its AI-assisted development workflow, within the team’s established engineering conventions and with appropriate human review and quality controls (Section 9). Development is done in Visual Studio with Azure DevOps (Section 4, Appendix A). The selected partner is not required to use the same tools and may use comparable AI-assisted development tools of its own choosing, subject to the same review and quality-control expectations; SBCAPCD does not mandate the use of AI-assisted tools where the partner delivers quality work without them. The partner must, however, be comfortable working within a collaborative workflow in which SBCAPCD itself uses AI-assisted development as a standard practice (Section 4.1). SBCAPCD is open to recommendations for supplementary tools that align with and extend its established conventions rather than introduce parallel approaches. 

User Interface & Design 

Q24. Does SBCAPCD have a UI design system, style guide, mockups, or brand guidelines, and will wireframes be provided? 

A formal UI design system and associated conventions are actively under development as part of the ongoing in-house modernization (Section 4.1). SBCAPCD may provide initial UI concepts or mockups as a starting point; the partner is expected to collaborate with SBCAPCD staff and apply UI/UX expertise to arrive at a staff-approved design (Appendix B). Wireframes or mockups may be provided in some cases but are not guaranteed. The relevant conventions and any available design direction will be shared with the selected partner at the appropriate stage of the engagement. 

Testing, Quality Assurance & Deployment 

Q25. What automated test coverage and QA/UAT process is expected for Phase 1, is there a preferred test framework, is a staging/QA environment in scope, and must the partner establish CI/CD? 

For Phase 1, SBCAPCD expects basic automated test coverage for critical business logic in the modernized components, along with structured testing and support for user acceptance testing (Section 9, Appendix B); a specific code-coverage percentage is not mandated. The in-house team has established testing conventions on the modern stack as part of its first modernized application, which will be shared with the selected partner; the overall testing approach and coverage philosophy will be developed collaboratively during discovery. Because formal branching, pull-request, and CI/CD workflows are not yet established (Appendix A), setting up and configuring these Azure DevOps workflows and automated pipelines is expected to be part of the Phase 1 foundational infrastructure. The nightly-refreshed test database is sufficient for much of this testing; where a longer-lived, isolated environment is warranted, SBCAPCD is willing to provision additional environment infrastructure. 

Q26. How are the modernized applications packaged and deployed, and are there workstation deployment constraints or legacy operating system requirements? 

Legacy applications are deployed via ClickOnce to the SBCAPCD intranet (Appendix A). SBCAPCD’s in-house modernized applications use MSIX-based packaging, and the selected partner is expected to work within this approach; any workstation deployment or update constraints will be confirmed collaboratively during discovery. The modernized applications target current, supported versions of Windows on SBCAPCD staff workstations; no legacy Windows operating system support is required. 

Collaboration, Team & Ongoing Support 

Q27. What is the composition of SBCAPCD’s internal team, who will participate, and how much of their time will be available? 

SBCAPCD’s in-house development team consists of two developers, rather than a large, role-differentiated project team. They will collaborate directly with the selected partner on development, code reviews, walkthroughs, and knowledge transfer, supplemented by relevant business staff for testing and user acceptance as needed. SBCAPCD has identified the key staff who will be part of the development team for this engagement, and supporting the selected partner will be a high priority for them throughout Phase 1; a specific time allocation is not being committed in advance, and the collaboration cadence will be established during discovery. SBCAPCD does not prescribe the partner’s team size or composition — a compact, senior team is well suited to the initial phase, with the ability to scale roles as scope is defined; proposers should describe the team structure they consider appropriate. 

Q28. How will ownership boundaries and the division of work be defined, and will the in-house developer(s) continue on the program? 

As described in Section 3.1, the division of work between SBCAPCD’s in-house team and the selected partner will be determined collaboratively and may vary by application and phase. SBCAPCD is not outsourcing ownership of its software; its in-house developers will continue on the program throughout the engagement, and a central objective is to transfer knowledge so staff can independently maintain and extend the modernized system. 

Q29. What are the expectations and timeline for ongoing support and maintenance after implementation? 

This is not a long-term maintenance engagement. As described in Section 3, the intent is a defined-scope, collaborative effort in which the modernized code and its ongoing maintenance are transferred to SBCAPCD staff, who will independently maintain and operate the resulting system. Defined deliverables must be met; long-term support and maintenance beyond knowledge transfer and handoff are not anticipated as part of this engagement. 

Qualifications & Team Size 

Q30. Will substantial experience with WPF, modern .NET, Windows Forms modernization, and enterprise application architecture be considered alongside WinUI 3 experience? 

Yes. WinUI 3 / Windows App SDK experience is valued, but SBCAPCD recognizes it is an emerging framework. As noted in Section 9, experience with WPF or other modern .NET UI frameworks is also relevant, and substantial experience with modern .NET, Windows Forms modernization, and enterprise application architecture will be considered comparable where appropriate. 

Q31. Is there a minimum expected team size, or will proposals be evaluated on capability regardless of firm size, including small firms leveraging AI-assisted development? 

SBCAPCD does not have a minimum expected team size. Proposals will be evaluated on demonstrated capability, relevant experience, and delivery approach per the criteria in Section 11, regardless of firm size. A compact, senior team — or smaller — can be appropriate for this engagement, and the effective use of AI-assisted development with appropriate review and quality controls is consistent with SBCAPCD’s own workflow (Sections 4.1 and 9). 

Q32. For the representative projects and references (Section 10.2), will a mix of public/private-sector work, internal/proprietary systems, and confidential-client engagements (with anonymized descriptions and references under separate confidential cover) be accepted, and may work performed by a firm’s principal be cited? 

Yes, that will suffice. Representative projects may include a mix of public-sector and private-sector engagements, including internal or proprietary line-of-business systems; Section 10.2 asks only that the projects reflect a range of work relevant to this engagement. For confidential engagements, anonymized project descriptions are acceptable provided they include enough detail to evaluate (client type, technologies, scope of services, duration and general scale, and status), and references may be provided under separate confidential cover so long as they include contact information sufficient for SBCAPCD to reach the reference (Section 10.2); SBCAPCD will treat such materials as confidential to the extent permitted by law. Work performed by a firm’s principal may be cited, provided the proposal clearly identifies who performed the work. 

Commercial: Budget, Timeline & Contract 

Q33. Is there an anticipated budget range, not-to-exceed amount, or hours band for the engagement? 

SBCAPCD is not disclosing a budget range, funding allocation, not-to-exceed amount, or hours band at this time. Proposers should provide their rate schedule and pricing per Section 10.4; cost will be evaluated on that basis in combination with the other criteria in Section 11. 

Q34. What pricing/contract model is preferred, should discovery be priced separately, and is a binding not-to-exceed amount required in the proposal? 

At a minimum, proposers should provide their rate schedule and a typical team structure (Sections 10.3–10.4). An illustrative initial-phase cost scenario is welcome and helpful for context, but it is optional and its absence will not count against a proposal. Discovery is expected to be incorporated into the overall Phase 1 engagement and estimate rather than contracted as a separate, standalone engagement. Because the Phase 1 scope is finalized collaboratively during discovery, proposers should provide a planning-level estimate that will be refined after discovery; a firm, binding not-to-exceed amount is not required in the proposal. SBCAPCD has not fixed a pricing model at this time; it will be finalized during contracting. 

Q35. What is the anticipated contract start date, Phase 1 duration, overall contract period, and desired go-live date? 

SBCAPCD is targeting a contract start in the fourth quarter of 2026, subject to the selection and contracting process. The Phase 1 duration, overall contract period, and go-live timing are not fixed in advance; they depend on the scope of the in-scope application(s) and the pace of integration and knowledge transfer, and will be established collaboratively during discovery. 

Q36. Is there a standard SBCAPCD/County contract, and what insurance types and minimum limits (e.g., CGL, professional liability/E&O, cyber, workers’ compensation) will be required? Is a sample agreement available? 

Yes. The engagement will use a standard County of Santa Barbara professional services agreement, including the County’s standard indemnification and insurance requirements for Information and Communications Technology (ICT) professional services. Required coverages include: Commercial General Liability with limits no less than $1,000,000 per occurrence; Automobile Liability of $1,000,000 per accident (not required if no vehicle is operated in performance of the agreement); Workers’ Compensation as required by the State of California, with Employer’s Liability limits of $1,000,000 (not required with written verification of no employees); Cyber Insurance with limits no less than $2,000,000 per occurrence or claim and $2,000,000 aggregate; and Technology Professional Liability (Errors & Omissions) coverage of no less than $2,000,000 per claim (if written on a claims-made basis, the retroactive date must be on or before commencement of services and coverage must remain in force for at least three years following termination of services). Standard County provisions apply, including additional-insured status, primary and non-contributory coverage, notice of cancellation, and waiver of subrogation. No separate bonding or certification requirements have been identified. The complete agreement terms, including the full indemnification and insurance exhibit, will be provided during the contracting process. 

Q37. Will any interviews conducted under Section 11 be available remotely, and what is the anticipated timeline from proposal submission to award? 

Yes — should interviews be conducted as part of the evaluation process, they will be available remotely. SBCAPCD anticipates completing evaluation, selection, and award in the fourth quarter of 2026, subject to the selection and contracting process. 

Submission, Procurement & Contract Administration 

Q38. Will SBCAPCD extend the proposal submission deadline? 

No. Proposals remain due prior to 5:00 p.m. (Pacific) on July 31, 2026, as stated in the RFP (Section 12). 

Q39. Will SBCAPCD relax Section 10.2 to allow fewer representative projects or a longer lookback period? 

SBCAPCD is not amending the requirements of Section 10.2. Proposers that are unable to provide five (5) representative projects completed within the last three (3) years may still submit a proposal with as many qualifying projects as they can provide, and may include additional, older projects for context; however, the completeness of the response against Section 10.2 will be taken into account in the evaluation of Relevant Experience and Qualifications under Section 11. 

Q40. What has SBCAPCD historically spent on IDS development and related consulting, and have external contractors supported IDS in the past five years? 

IDS has been developed and maintained in-house; the most significant recently contracted item is the externally hosted permitted facilities map (https://map.ourair.org/). SBCAPCD’s budget and financial documents are publicly available at https://www.ourair.org/finance/; SBCAPCD is not providing an IDS-specific expenditure breakout as part of this Q&A. 

Q41. Does the U.S.-location requirement in Section 8 apply to all personnel, does it require citizenship or restrict visa classifications, and may offshore resources be used for any phase? 

The requirement applies to partner staff assigned to perform work on this project — personnel who work on the applications or interact with SBCAPCD systems, source code, or data; it is not intended to reach purely administrative functions such as billing. It is a location requirement only: it does not impose a citizenship or immigration-status requirement, and SBCAPCD does not restrict visa classifications; ensuring lawful employment authorization is the contractor’s responsibility. Offshore resources may not be used for any phase or function of the work, including design, development, migration, and support. 

Q42. Are there local, small-business, or diversity preference programs, and do non-local vendors receive equal consideration? 

No such preference programs apply to this solicitation at this time; the applicable requirement is the U.S.-based work requirement in Section 8. All proposers meeting the requirements of the RFP receive equal consideration under the evaluation criteria in Section 11. 

Q43. Is there a maximum subcontracting percentage, and must subcontractors be identified? 

No maximum subcontracting percentage or prime-minimum requirement has been established. Proposers electing a multi-party structure should clearly identify the proposing entity, all named delivery partners, and the roles and responsibilities of each within the proposed team; the proposing team must collectively meet the Required Qualifications in Section 9. 

Q44. How frequently are onsite meetings expected, will travel be reimbursed, and should rates be all-inclusive? 

Onsite meetings are expected to be infrequent — project kickoff, key milestones, or occasional workshops, by mutual agreement (Section 8). Travel and reimbursement terms, if needed, will be addressed during contracting. Proposers should clearly specify what their rates include and state any assumptions or exclusions in their rate schedule and pricing (Section 10.4). 

Q45. What contract vehicle will govern future phases, are renewal or option periods anticipated, and is any minimum volume of work guaranteed? 

The contract structure, including any renewal or option provisions and the vehicle for future phases, has not been established and will be determined at the appropriate time, subject to applicable procurement requirements (Section 3.1). No minimum volume of work, funding, hours, or number of applications is guaranteed. 

Q46. How will invoicing, payment, acceptance schedules, and rate escalation be handled? 

Invoicing, payment, acceptance, and rate terms (including any escalation provisions) will be established during contracting under the County’s standard professional services agreement, informed by the scope defined during discovery and the Phase 1 deliverables and exit criteria in Appendix B. 

Q47. Must key personnel be named with resumes, will proposed staff be interviewed, and are substitutions permitted after award? 

The proposal content requirements are as stated in Section 10; naming key personnel and including resumes is not required, but proposers may include them. SBCAPCD may conduct interviews as part of the evaluation process; should interviews be conducted, they will be available remotely. Personnel substitutions and replacements — including for candidates who become unavailable before project start — are permitted with SBCAPCD’s prior approval and are expected to have equal or higher qualifications. 

Governance, Acceptance & Additional Scope Clarifications 

Q48. Will SBCAPCD entertain proposals that replace IDS workflows with configurable web-based SaaS modules hosted off-premises? 

Not at this time; such an approach is outside the scope of this RFP. Section 5.1 defines the target technology stack (.NET 10 / WinUI 3, Windows App SDK desktop applications preserving the existing on-premises SQL Server database), and SBCAPCD is not outsourcing ownership or hosting of its software (Section 3). Proposals premised on replacing IDS workflows with off-premises SaaS modules would not be responsive to this solicitation. 

Q49. Is the .NET 10 / WinUI 3 (Windows App SDK) target stack mandatory, or may proposers recommend an alternative modern Microsoft UI framework? 

The target stack stated in Section 5.1 is the established direction: it is already in production use by the in-house modernization effort, and foundational shared infrastructure has been built on it. The selected partner is expected to work within this direction rather than propose an alternative stack. 

Q50. What governance model, approval authorities, and change-control process will apply? 

A lightweight, collaborative governance model appropriate to the size of the engagement is anticipated, with approvals resting with SBCAPCD’s designated stakeholders (Appendix B) and day-to-day technical decisions coordinated through the in-house development team. Meeting cadence, reporting, escalation, and specific approval authorities will be established at kickoff. Scope identified during discovery will be refined into a mutually agreed scope and cost before implementation proceeds; changes beyond the agreed scope will be handled through the change and amendment provisions of the contract. 

Q51. Is a post-production warranty or stabilization period required, and what service levels apply to production defects after release? 

The RFP does not define an extended warranty period or formal service-level agreements, and this is not a long-term maintenance engagement; ongoing maintenance transfers to SBCAPCD staff following knowledge transfer and handoff (Section 3). Expectations for stabilization support and defect handling in the period surrounding release will be defined collaboratively during discovery, consistent with the Phase 1 deliverables and exit criteria in Appendix B. 

Q52. What allocation of Phase 1 effort does SBCAPCD expect across assessment, architecture, UI/UX, development, database work, testing, deployment, documentation, and knowledge transfer? 

SBCAPCD has not predetermined an allocation across these activities. Proposers may present the allocation they consider appropriate as part of their proposed approach; the actual distribution will be refined collaboratively during discovery. 

Q53. What test-data strategy will be used, and will the partner receive access to production or only the nightly test copy? 

A production-derived test copy, refreshed nightly from production, will be used for most development and testing (Appendix A); it reflects the production schema and stored procedures. Access to production is possible where necessary, subject to SBCAPCD approval and applicable controls. Any additional test-data arrangements can be determined later depending on the selected partner’s environment and needs, and data handling is subject to the confidentiality and data-handling terms of the contract. 

Q54. Are specific accessibility standards (e.g., WCAG 2.1 AA) required for the modernized applications? 

No formal accessibility standard is mandated at this time; accessibility and usability will be addressed collaboratively during design. 

Q55. What restrictions apply to transmitting SBCAPCD source code, database structures, or other information to cloud-based AI services? 

Any use of AI services involving SBCAPCD source code, database structures, or other information is subject to the confidentiality and data-handling terms of the contract and to the conventions and guidelines shared during onboarding. 

End Users 

Q56. Can SBCAPCD provide an overview of the key user personas/roles, approximate user counts, and role-based access levels? 

A detailed breakdown of user personas and per-role counts is not considered necessary at the proposal stage and will be provided during discovery. SBCAPCD’s user structure is typical for an air district, spanning functions such as permitting/engineering, compliance and enforcement, emission inventory, invoicing, and administration, with role-based access managed within the applications. Detailed personas, user counts, and access levels will be reviewed during discovery.

Security, Access & Data Handling

Q57. Are there background-check, security-clearance, or data-handling requirements for remote, US-based partner staff, what remote access model is anticipated (VPN, virtual desktops, device management), and does the data contain PII?

All partner staff assigned to this project must be located in and perform work from the United States (Section 8). No specific background-check or security-clearance requirements are anticipated at this time; any such requirements would be confirmed during contracting. Access to the Azure DevOps environment, source repositories, and the nightly-refreshed test database will be provisioned through SBCAPCD-managed accounts, most likely via VPN, with the specific mechanisms and any multi-factor requirements confirmed during onboarding. The test and production data may contain personally identifiable and other sensitive regulatory information; partner staff are expected to handle it accordingly under the applicable confidentiality and data-handling terms.

__________________________________________________________________________________________________________________________________________

Communications & Contact

Proposers shall not contact SBCAPCD staff directly regarding this RFP outside of the written Q&A process described above. Unauthorized contact may result in disqualification. (Requests for reasonable accommodation under the ADA are exempt from this restriction.)