Attachment 1 - C-SCRM Questionnaire.xlsx
XLSX spreadsheet 169 KB Posted
- Attached to
- Software License Subscriptions Renewal and Support Services Federal contract opportunity
- Solicitation number
- 19TH2026Q0064
- Issued by
- Department of State US Embassy Bangkok
About this file
This is a Cybersecurity Supply Chain Risk Management (C-SCRM) Questionnaire template designed to collect vendor compliance information for the solicitation 19TH2026Q0064 (Software License Subscriptions Renewal and Support Services) issued by the Department of State US Embassy Bangkok.
The questionnaire requires vendors to complete three sections: Section 1 requests contact information including company name, primary point-of-contact name, job title, phone number, and email address; Section 2 addresses vendor risk management practices, requiring yes/no responses regarding identification of supply chain threats, mapping of key suppliers to threats, written SCRM requirements in supplier contracts, and verification of supplier compliance with SCRM requirements; Section 3 covers physical and personnel security practices, including background check policies for employees, procedures to prevent tampering of ICT equipment in supply chain inventory, and insider threat literacy training programs. The template references NIST SP 800-53 security control standards for each questionnaire item and includes scoring mechanisms for tracking responses. Offerors are advised that the Government may request supporting documentation to validate responses. This questionnaire is mandatory for vendors responding to the RFQ with quotations due by August 11, 2026 at 12:00 PM Bangkok local time, and vendors must be registered in the System for Award Management (SAM) database prior to submission.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| QA_19TH2026Q0064_Software License Subscriptions Renewal and Support Services.pdf | ||
| RFQ no. 19TH2026Q0064 Software Licenses Subscriptions Renewal and Support Services.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
C-SCRM Questionnaire
| CYBERSECURITY SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE |
| Instructions: |
- This worksheet shall be completed by the vendor responsible for submitting the offer. References to "organization" refer to the offering entity. If the offering entity is a joint venture (JV), the response may come from either the JV or from the JV managing partner.
- Provide the requested inputs in the gray shaded lines of the template under column D, Vendor Response, for all Items Numbers for Sections 1-3. Offerors are advised that the Government may request documentation from the Offerors to validate the responses provided.
| SECTION 1 - CONTACT INFORMATION | |||
| ITEM NO. | ITEM DESCRIPTION | VENDOR RESPONSE | |
| 1.1 | Enter the name of your company. | ||
| 1.2 | Enter the name of the primary Point-Of-Contact (POC) for your company that the Government may contact to discuss the vendor inputs on this questionnaire. | ||
| 1.3 | Enter the job title of the primary POC. | ||
| 1.4 | Enter the phone number of the primary POC in the following format: (555) 555-5555 | ||
| 1.5 | Enter the e-mail address of the primary POC. | ||
| SECTION 2 VENDOR RISK MANAGEMENT PLAN | |||
| ITEM NO. | ITEM DESCRIPTION | VENDOR RESPONSE | NIST SP 800-53 Reference |
| 2.1 | Does your organization identify its key supply chain threats? (Note: if you do not have suppliers, answer "Yes") | IR-8, SR-7 | |
| 2.2 | Does your organization map key suppliers to your supply chain threats? (Note: if you do not have suppliers, answer "Yes") | IR-8, SR-7 | |
| 2.3 | Does your organization have written SCRM requirements in contracts with your key suppliers? (Note: if you do not have suppliers, answer "Yes") | SA-4 | |
| 2.4 | Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions? (Note: if you do not have suppliers, answer "Yes") | SR-6 | |
| SECTION 3 PHYSICAL AND PERSONNEL SECURITY | |||
| ITEM NO. | ITEM DESCRIPTION | VENDOR RESPONSE | NIST SP 800-53 Reference |
| 3.1 | Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates? | PE-2, PE-3 |
PS-3
3.2 Does your organization have procedures in place to prevent tampering of Information and Communications Technology (ICT) equipment stored as supply chain inventory? SR-9
AC-1
3.3 Do you provide literacy training on recognizing and reporting potential indicators of insider threat? AT-2(2)
&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED
Data (HIDE)
| Status | Score | Status | Not Reviewed | Yes | No | Not Applicable | Alternative | Total |
| ERROR:#REF! | ERROR:#REF! | Counts | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! |
| Pct | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! |
&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED
Counts Not Reviewed Yes No Not Applicable Alternative 0 0 0 0 0
DL (HIDE)
| GWACS | Pool | Implementation Status | Answer |
| Alliant/ Alliant 2 | Small Business (SB) Pool | Satisfied | Yes |
| Alliant SB | HUBZone SB (HUBZone) Pool | Partially Satisfied | No |
| 8(a) STARS II | Women Owned SB (WOSB) Pool | Not Satisfied | |
| VETS/ VETS2 | Other | Not Applicable | |
| TBD | |||
| Not Reviewed |
&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED
File details come from the government source that posted it. Updated .