Supply Chain Illumination RFI
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The Federal Bureau of Investigation (FBI), under the Department of Justice, has issued a Request for Information (RFI) for Supply Chain Illumination capabilities. This RFI seeks industry input on commercially available technologies and services to establish an enterprise Supply Chain Risk Management (SCRM) capability. The goal is to illuminate information and communication technology (ICT) products, software, and services, providing detailed insights into threats, risks, and vulnerabilities within their supply chains. This is for informational and planning purposes only and does not constitute a solicitation.
Scope of Interest
The FBI is interested in solutions that can:
- Provide continuous monitoring of product/entity risk levels and associated factors.
- Perform in-depth due diligence for initial risk assessment and mitigation planning.
- Generate automatic alerts for changes in risk ratings or status (near real-time, max 24-hour latency for data updates).
- Offer automated management, tasking features, customizable visualizations, and data exports.
- Group products, vendors, or entities for easy access and coordination.
- Map supply chains at least three tiers upstream, including structured product/vendor registries and relationship mapping.
- Break down Software Bills of Materials (SBOMs) and offer micro component traceability (at least three layers back for hardware).
- Track shipping/transport records and identify financial, operational, cyber, governance, third-party, and trade risks.
- Include Application Programming Interfaces (APIs) and be FedRAMP High approved (FedRAMP Moderate is acceptable for unclassified networks; SaaS is the preferred deployment model).
- Risk scoring methodologies must align with NIST 800-161 and FIPS 199, with customization capabilities preferred.
Deployment & Data Handling
Solutions should operate without ingesting FBI asset inventory into vendor-hosted environments. FBI-derived or enriched data is restricted from being stored outside government-controlled infrastructure. Alternative deployment models (government-controlled, on-premises, enclave-based) are acceptable if not connected to the secret enclave. The initial deployment is for 15-20 users, monitoring approximately 500 vendors, on the unclassified network only.
Submission Details
- Type: Request for Information (RFI)
- Set-Aside: Not applicable, as this is an RFI.
- Submissions Due: May 6, 2026, 3:00 PM ET
- Questions Due: April 17, 2026, Noon ET (answers posted by April 24, 2026)
- Format: UNCLASSIFIED, Microsoft Word/Excel/PowerPoint or PDF, not exceeding 20 pages.
- Email Submissions to: bmjames@fbi.gov and hlwilliams@fbi.gov, with subject "RFI- Supply Chain Illumination."
Additional Notes
Responses are voluntary, and no funds are available for preparation. The FBI may request demonstrations based on RFI responses. Solutions must be maintainable within FBI control and operate independently of completed inventories, without requiring data entry into systems outside FBI networks or secured government clouds.