RegScale Alternative Sources/Solutions

SOL #: RFI_HNC_Regscale_FA830726RB028Sources Sought

Overview

Buyer

DEPT OF DEFENSE
Dept Of The Air Force
FA8307 AFLCMC HNCK C3IN
SAN ANTONIO, TX, 78243-7007, United States

Place of Performance

San Antonio, TX

NAICS

Software Publishers (513210)

PSC

No PSC code specified

Set Aside

No set aside specified

Timeline

1
Posted
May 8, 2026
2
Response Deadline
May 16, 2026, 4:00 AM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

The Department of the Air Force, through AFLCMC HNCK C3IN, is conducting market research via a Request for Information (RFI) to identify and assess commercially available alternatives to RegScale. This effort supports Platform One (P1) mission requirements for Governance, Risk, and Compliance (GRC) automation. Responses will inform future acquisition strategy decisions. Responses are due May 16, 2026.

Purpose

This RFI aims to evaluate industry capabilities and available solutions that provide comprehensive GRC automation, continuous compliance monitoring, security control management, risk assessment tracking, audit readiness, and authorization support within a government security-compliant environment. The government seeks to identify qualified sources and alternative capabilities to enhance Platform One's DevSecOps ecosystem.

Scope of Interest

The government is particularly interested in solutions capable of supporting:

  • Enterprise compliance operations
  • Risk Management Framework (RMF) activities
  • Continuous Authority to Operate (cATO) sustainment
  • Control inheritance management
  • Evidence collection automation
  • Policy mapping
  • Security documentation management

Vendors should address capabilities related to Continuous Controls Monitoring (CCM), automation of evidence collection, support for regulatory frameworks (NIST 800-53, RMF, FedRAMP, CMMC, STIG), policy-as-code, audit trail retention, and integrations with tools like GitLab, Jira, Kubernetes, AWS GovCloud, and ServiceNow.

Key Information Sought

The RFI includes specific questions for vendors covering:

  • Technical capabilities (e.g., CCM, automation, supported frameworks, integrations, CATO support, compliance drift detection, RBAC/SSO)
  • Implementation timelines and migration support
  • Support escalation processes and license delivery
  • Pricing models (subscription and implementation)
  • Federal or DoD customer examples
  • Data ownership, storage, and retention for on-prem environments

Contract & Timeline

  • Type: Sources Sought / Request for Information (RFI)
  • Set-Aside: None specified (market research stage)
  • Response Due: May 16, 2026, 04:00 AM EDT
  • Published: May 8, 2026, 05:20 PM EDT
  • Agency: DEPT OF THE AIR FORCE / AFLCMC HNCK C3IN
  • Place of Performance: San Antonio, TX

Additional Notes

This RFI is for informational purposes only and does not constitute a solicitation, request for proposal, or a commitment by the Government to award a contract. The Government encourages responses from all capable vendors to promote maximum practicable competition.

People

Points of Contact

Platform One License Management TeamPRIMARY
Mr. David GarciaSECONDARY

Files

Files

Download
Download

Versions

Version 1Viewing
Sources Sought
Posted: May 8, 2026
RegScale Alternative Sources/Solutions | GovScope