Cybersecurity software · Federal
Software Supply Chain Security Solution
Federal Deposit Insurance Corporation (FDIC)
Issuer and solicitation
- Issuer
- Federal Deposit Insurance Corporation (FDIC) · Independent federal agency
- Reference
- CORHQ-26-R-0394
- Buyer type
- Federal
- Issued
- September 28, 2026 · Newly reviewed October 11. Amendment 0001, posted October 8, extends the original October 9 proposal deadline to October 16.
Scope
Secure and continuously maintain 50 container images, with vulnerability remediation, signed software bills of materials, enterprise authentication/portal and JFROG integration, implementation and specialist support. Includes a Technical Consultant and Security Control Specialist.
Key dates
- Proposal deadline
- October 16, 2026 · 1:00 PM EDT, extended by Amendment 0001
- Questions due
- October 2, 2026 · noon; already passed and not reopened by Amendment 0001
- Issuer expects a Q&A amendment no later than October 14, 2026; review it before submission.
- Initial performance planned January 6, 2027–January 5, 2028.
- No prebid meeting or intent-to-bid cutoff stated in the reviewed packet.
Submission and qualification requirements
- No set-aside; NAICS 513210 and PSC 7A21. SAM registration certification is required; the form permits registration in progress.
- Mission-capability response: 10-page maximum, including vulnerability evidence for the specified Appendix A test images.
- Past performance: three to five relevant contracts from the past five years, two pages maximum per example. Customer questionnaires must reach FDIC directly by the proposal deadline unless the stated CPARS or FDIC-contract exceptions apply; Offerors without a relevant past-performance record receive a neutral rating.
- Complete the pricing workbook and separate Pre-Award Supply Chain Risk Management information. Identify OEM, aftermarket-manufacturer or authorized-supplier status; unacceptable supply-chain risk disqualifies.
- Provide a bank reference and certified/audited financial statements for the current and prior two fiscal years, or an explanation with acceptable alternative evidence. Financial capability is pass/fail.
- Email submission per Section 7.3.1-06, with solicitation number, offeror identity and UEI, signed offer, amendment acknowledgement, Section K certifications and license/support agreements; offer validity at least 120 days.
- Container security-baseline compliance is required, but the packet explicitly does not require the vendor solution to obtain FedRAMP authorization.
- U.S.-made/designated-country end-product restrictions and post-award personnel screening apply; FDIC information cannot be handled outside the U.S. without authorization.
Published budget and contract structure
Published budget: Not stated in reviewed material; proposed price must include applicable travel
- Intended single-award, firm-fixed-price contract.
- One-year initial term plus four annual options through January 5, 2032.
- Remote performance; scope includes software, maintenance, implementation and specialist services.
Sources
In Attachments/Links, use CORHQ-26-R-0394 Updated 10.8.26.pdf, Amendment 0001, the Container Price Schedule and Pre-Award SCRM Info workbook. Check for the expected Q&A amendment before responding.
Sources checked October 11, 2026.
Official current SAM notice, full 71-page updated solicitation and Amendment 0001 reviewed October 11. The October 16 deadline is controlling despite older narrative dates. The packet labels Volume IV inconsistently as Additional Information and SCRM Information; both content requirements remain. A further Q&A amendment is expected by October 14 and must be checked before responding.
Check the official notice for updates.
