Supply Chain Illumination RFI

SOL #: FBI-OCIO-SCRMSources Sought

Overview

Buyer

Justice
Federal Bureau Of Investigation
FBI-JEH
WASHINGTON, DC, 20535, United States

Place of Performance

Clarksburg, WV

NAICS

No NAICS code specified

PSC

No PSC code specified

Set Aside

No set aside specified

Timeline

1
Posted
Mar 24, 2026
2
Last Updated
Apr 24, 2026
3
Response Deadline
May 6, 2026, 7:00 PM

Qualification Details

Fit reasons
  • NAICS alignment with historical contract wins in similar service areas.
  • Scope strongly matches core technical capabilities and delivery model.
Risks
  • Past performance thresholds may require one additional teaming partner.
  • Potential clarification needed on staffing minimums before bid/no-bid.
Next steps

Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.

Quick Summary

The Federal Bureau of Investigation (FBI), under the Department of Justice, has issued a Request for Information (RFI) for Supply Chain Illumination capabilities. This RFI seeks industry input on commercially available technologies and services to establish an enterprise Supply Chain Risk Management (SCRM) capability. The goal is to illuminate information and communication technology (ICT) products, software, and services, providing detailed insights into threats, risks, and vulnerabilities within their supply chains. This is for informational and planning purposes only and does not constitute a solicitation.

Scope of Interest

The FBI is interested in solutions that can:

  • Provide continuous monitoring of product/entity risk levels and associated factors.
  • Perform in-depth due diligence for initial risk assessment and mitigation planning.
  • Generate automatic alerts for changes in risk ratings or status (near real-time, max 24-hour latency for data updates).
  • Offer automated management, tasking features, customizable visualizations, and data exports.
  • Group products, vendors, or entities for easy access and coordination.
  • Map supply chains at least three tiers upstream, including structured product/vendor registries and relationship mapping.
  • Break down Software Bills of Materials (SBOMs) and offer micro component traceability (at least three layers back for hardware).
  • Track shipping/transport records and identify financial, operational, cyber, governance, third-party, and trade risks.
  • Include Application Programming Interfaces (APIs) and be FedRAMP High approved (FedRAMP Moderate is acceptable for unclassified networks; SaaS is the preferred deployment model).
  • Risk scoring methodologies must align with NIST 800-161 and FIPS 199, with customization capabilities preferred.

Deployment & Data Handling

Solutions should operate without ingesting FBI asset inventory into vendor-hosted environments. FBI-derived or enriched data is restricted from being stored outside government-controlled infrastructure. Alternative deployment models (government-controlled, on-premises, enclave-based) are acceptable if not connected to the secret enclave. The initial deployment is for 15-20 users, monitoring approximately 500 vendors, on the unclassified network only.

Submission Details

  • Type: Request for Information (RFI)
  • Set-Aside: Not applicable, as this is an RFI.
  • Submissions Due: May 6, 2026, 3:00 PM ET
  • Questions Due: April 17, 2026, Noon ET (answers posted by April 24, 2026)
  • Format: UNCLASSIFIED, Microsoft Word/Excel/PowerPoint or PDF, not exceeding 20 pages.
  • Email Submissions to: bmjames@fbi.gov and hlwilliams@fbi.gov, with subject "RFI- Supply Chain Illumination."

Additional Notes

Responses are voluntary, and no funds are available for preparation. The FBI may request demonstrations based on RFI responses. Solutions must be maintainable within FBI control and operate independently of completed inventories, without requiring data entry into systems outside FBI networks or secured government clouds.

People

Points of Contact

Brandon JamesPRIMARY

Files

Files

Download
Download

Versions

Version 2Viewing
Sources Sought
Posted: Apr 24, 2026
Version 1
Sources Sought
Posted: Mar 24, 2026
View