The University of Pittsburgh is seeking a qualified vendor to provide a fullyâmanaged Single SignâOn (SSO) infrastructure based on Shibboleth IdP, supporting both SAML 2.0 and OpenID Connect (OIDC) protocols. The contract will run for three years, with a 30âday cancellation right, and requires a hosted SaaS option (with an optional Managed Private Cloud deployment). The provider must deliver 99.97 % monthly uptime, rapid incident response, comprehensive auditâlog access, monthly reporting, and compliance documentation (SOC 2 Type II or equivalent). Key deliverables include migration from the existing IdP, ongoing maintenance, MFA integration, and a selfâservice portal for SP/RP onboarding.
⢠Provide a highâavailability, cloudâhosted Shibboleth IdP supporting SAML 2.0 and OIDC with PKCE, JWKS rotation, and attribute mapping.
⢠Offer 24Ă7Ă365 support with defined SLA response times (P1 within 15â30 min, P2 within 1â2 h) and a 99.97 % uptime guarantee.
⢠Submit an itemized pricing proposal covering subscription fees, DR, perâintegration charges, consulting, and optional privateâcloud deployment.
⢠Deliver migration plan, auditâlog access, monthly reports, and maintain compliance with NIST, ISO 27001, and SOC 2 Type II standards.