RegScale Alternative Sources/Solutions
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Department of the Air Force, through AFLCMC HNCK C3IN, is conducting market research via a Request for Information (RFI) to identify and assess commercially available alternatives to RegScale. This effort supports Platform One (P1) mission requirements for Governance, Risk, and Compliance (GRC) automation. Responses will inform future acquisition strategy decisions. Responses are due May 16, 2026.
Purpose
This RFI aims to evaluate industry capabilities and available solutions that provide comprehensive GRC automation, continuous compliance monitoring, security control management, risk assessment tracking, audit readiness, and authorization support within a government security-compliant environment. The government seeks to identify qualified sources and alternative capabilities to enhance Platform One's DevSecOps ecosystem.
Scope of Interest
The government is particularly interested in solutions capable of supporting:
- Enterprise compliance operations
- Risk Management Framework (RMF) activities
- Continuous Authority to Operate (cATO) sustainment
- Control inheritance management
- Evidence collection automation
- Policy mapping
- Security documentation management
Vendors should address capabilities related to Continuous Controls Monitoring (CCM), automation of evidence collection, support for regulatory frameworks (NIST 800-53, RMF, FedRAMP, CMMC, STIG), policy-as-code, audit trail retention, and integrations with tools like GitLab, Jira, Kubernetes, AWS GovCloud, and ServiceNow.
Key Information Sought
The RFI includes specific questions for vendors covering:
- Technical capabilities (e.g., CCM, automation, supported frameworks, integrations, CATO support, compliance drift detection, RBAC/SSO)
- Implementation timelines and migration support
- Support escalation processes and license delivery
- Pricing models (subscription and implementation)
- Federal or DoD customer examples
- Data ownership, storage, and retention for on-prem environments
Contract & Timeline
- Type: Sources Sought / Request for Information (RFI)
- Set-Aside: None specified (market research stage)
- Response Due: May 16, 2026, 04:00 AM EDT
- Published: May 8, 2026, 05:20 PM EDT
- Agency: DEPT OF THE AIR FORCE / AFLCMC HNCK C3IN
- Place of Performance: San Antonio, TX
Additional Notes
This RFI is for informational purposes only and does not constitute a solicitation, request for proposal, or a commitment by the Government to award a contract. The Government encourages responses from all capable vendors to promote maximum practicable competition.