Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Procurement topic

No spam. Unsubscribe anytime.

Kansas procurement office outlines rules for IT buys, urges earlier security review under SB291

Joint Committee on Information Technology (JCIT) · October 29, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The state's procurement office told legislators it is standardizing how IT purchases are specified, evaluated and awarded, and that the chief information security officer's review mandated by SB291 should occur before solicitations are posted so security requirements are part of the contract specs.

The state's procurement office told the Joint Committee on Information Technology that specifications and staged evaluation remain the best tools to protect competition and public dollars when buying information technology.

Kelly Johnson, chief operating officer for the Office of Procurement and Contracts, told the committee that agencies commonly use three procurement paths: low‑complexity IFBs and RFQs (awarded to the lowest responsive bidder), negotiated RFPs for complex IT projects (technical proposals separated from cost proposals), and prior authorizations for limited exceptions. She said prior authorizations have 15 statutory codes and that any prior authorization exceeding $100,000 must be advertised on OPC's website to allow potential challengers.

"A prior authorization is basically a document that is sent to our office, contains one of 15 different types of codes," Johnson said, describing the way OPC reviews and approves individual exceptions. She told members that prior authorizations lack public competition unless OPC or the director determines a competing offer is substantial, in which case the event must go out to bid.

The office described the RFP process used for most IT procurements in detail: agencies submit technical specifications and deliverables; OPC posts the solicitation; vendors submit a separate technical response (no costs) and a cost proposal; OPC and the agency evaluate technical proposals first; the agency prepares a technical recommendation; only then are cost proposals released and negotiations handled by the Procurement Negotiating Committee.

Johnson said the design—keeping technical and cost proposals separate until technical evaluation is complete—reduces the risk that bidders will be selected on price alone for complex, multi‑phase IT projects.

On SB291, Johnson said the law requires the chief information security officer (CISO) to review IT contracts, and OPC and OITS worked together to require security standards in solicitation specs before they are posted. "The intent was to catch security issues or concerns or deviations before the bid went out," she said, adding that including CSO standards in the spec reduces the need to rely on post‑award corrections.

Committee members asked how vendors get notice of events and whether a state'maintained bidders list blocks new entrants. Johnson explained the SMART registration system: being registered and tagged with product/service merchant codes gives vendors proactive notice of matching solicitations but registration is not required to bid.

Representatives pressed OPC on vendor performance under time‑and‑materials contracts and remedies. Johnson described a graduated enforcement path (informal outreach, formal written notice, notice to cure, termination for cause or convenience) and said OPC is pursuing vendor management tracking software to capture agency satisfaction and vendor performance trends.

On cooperative contracts, Johnson cited NASPO's Dell contract as an example of a national procurement vehicle the state joins by participating addendum. Those cooperative vehicles, she said, often produce better pricing and save state procurement resources.

Why it matters: The committee focused on where security and performance controls are placed in the procurement life cycle. Johnson's brief emphasized putting specific cybersecurity standards into solicitations before posting them (to make them enforceable at award) and improving vendor performance tracking—proposals that affect how future IT acquisitions will be scoped and administered.

What remains open: Committee members asked for the procurement manual link that OPC will distribute and pressed for continued work on vendor performance metrics, more explicit procurement specifications, and clarity about cooperative contract use in high‑risk procurements. No formal actions or votes were taken at the meeting.