FDIC seeks a software supply chain security solution providing hardened container images, vulnerability management, and compliance artifacts. Proposal due October 9, 2026. Single-award contract. Initial period January 6, 2027 to January 5, 2028, with options through January 5, 2032. Mandatory requirements include FedRAMP Moderate, NIST ****, DISA STIG/CIS benchmarks. Professional services for integration with JFrog. Invoices via IPP. Questions due October 2, 2026.
Proposals must be submitted by 1 p. m. Friday, October 9, 2026. to be considered for this opportunity, offerors shall provide all information required in the rfp, by 1p. m. friday, october 9, 2026.
Payments may be made by check or electronic funds transfer. Invoices submitted via IPP. invoices shall be submitted via the invoice processing platform ipp, a service provided by the u. s. treasurys bureau of the fiscal service.
FDIC accepts the contractor's commercial warranty but does not accept disclaimer of implied warranty. fdic will accept the contractors commercial warranty, but does not accept a disclaimer of the implied warranty that the items delivered hereunder are merchantable and fit for use.
Best value evaluation. offerors that offer these additional capabilities may or may not receive favorable consideration in the best value evaluation, dependent upon their value to the fdic.
Contractor must provide personnel with demonstrated experience in containerization frameworks. the contractor shall provide personnel that has demonstrated experience with containerization framework architectures.
Termination for default is possible if contractor fails to perform. terminate this award for default as provided in ****, termination for default.
Missing required information may be considered non-responsive. any missing volumes or required information in the proposal submission may be considered non responsive.