Question Template- ANSWERS-Specialized OSINT Tools IDIQ.xlsx
XLSX spreadsheet 57 KB Posted
- Attached to
- Specialized OSINT Tools IDIQ Federal contract opportunity
- Solicitation number
- RFP-002132
About this file
This is a Questions and Answers document for the FBI's Specialized OSINT Tools IDIQ (Indefinite Delivery/Indefinite Quantity) contract solicitation. The document addresses vendor inquiries regarding submission requirements, technical specifications, pricing, security standards, and evaluation criteria across 11 Contract Line Item Numbers (CLINs) covering specialized open-source intelligence capabilities.
The solicitation is a small business set-aside under NAICS code 513210 (Software Publishers) with a $47 million size standard, seeking Software-as-a-Service (SaaS) OSINT tools delivered through multi-tenant cloud environments. Award will be limited to up to two contractors per CLIN. Vendors must submit separate, complete proposals for each CLIN they pursue, including a 9-page Technical Approach (Volume 2) and Pricing (Volume 3) per CLIN, with pricing conforming to the Government's prescribed per-license format that includes all support, training, and helpdesk services. CLINs cover Financial/Banking Information, Deep and Dark Web, Terrorism-Related Information, Historical Internet Data, Identity Records, Property and Land Records, Image Information, and Video Information. The Government requires FedRAMP Moderate-level security or comparable security posture, Section 508 compliance or documented progress toward compliance, and mandatory CAI (Commercially Available Information) questionnaire completion. Helpdesk support must provide acknowledgment within 5 minutes of contact and operate 24/7, with 99.9% system uptime expected (excluding scheduled maintenance, which requires 30 days' notice). The Government does not require existing tools to be modified or new tools built, will not accept alternative pricing models outside the prescribed template, and will not extend proposal deadlines. Task orders under the IDIQ will be competed among all awardees under the applicable CLIN in accordance with FAR 16.505.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP-002132-Specialized Tools V5.pdf | ||
| RFP-002132-Specialized Tools-6-5.pdf | ||
| SOW- Specialized OSINT Tools IDIQ.pdf | ||
| Pricing Template- Specialized OSINT Tools.xlsx | XLSX spreadsheet | |
| 15F06726R0000026-Terms and Conditions-updated 5-29-2026.pdf | ||
| RFP-002132-Specialized Tools-4-16.pdf | ||
| RFP-Specialized OSINT Tools IDIQ.pdf | ||
| SOW- Specialized OSINT Tools IDIQ.pdf | ||
| Pricing Template - Specialized OSINT Tools IDIQ.xlsx | XLSX spreadsheet | |
| 15F06726R0000026-Terms and Conditions.pdf | ||
| Pricing Template - Specialized OSINT Tools IDIQ.xlsx | XLSX spreadsheet | |
| RFP-Specialized OSINT Tools IDIQ.pdf | ||
| CAI Questions-Specialized OSINT Tools.pdf | ||
| SOW- Specialized OSINT Tools IDIQ.pdf | ||
| Question Template- Specialized OSINT Tools IDIQ.xlsx | XLSX spreadsheet |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1
| CLIN | QUESTION | ANSWER |
| All | The NAICS code listed on it is unique and one we do not have. Any chance we can use a common one? | The applicable NAICS code for this solicitation is 513210 (Software Publishers), and all offerors must qualify under that code to be eligible for award. |
| 2 | Are there areas where better tools are needed? | The solicitation reflects the Government’s requirements/needs. Offerors should respond to the stated needs as written. |
| 7 | Are there areas where better tools are needed? | The solicitation reflects the Government’s requirements/needs. Offerors should respond to the stated needs as written. |
| All-NAICs | The solicitation identifies NAICS 513210 (Software Publishers) with inclusion of FAR 52.219-1, which applies a 500-employee size standard for nonmanufacturers contingent upon an approved Nonmanufacturer Rule (NMR) waiver. Will the Government confirm whether an NMR waiver has already been obtained from the SBA for this requirement, or if there is an intention to secure such a waiver prior to contract award? |
If an NMR waiver is not currently in place, we recommend consideration of issuing this requirement under NASA Solutions for Enterprise-Wide Procurement (SEWP V), which maintains an established class waiver for the Nonmanufacturer Rule. Utilizing SEWP V would eliminate the need for the FBI to pursue a separate SBA waiver, thereby reducing procurement risk, avoiding potential delays, and ensuring compliance with small business regulations without additional administrative burden.
Further, transitioning this requirement to SEWP V would enable the FBI to take advantage of the contract’s Strategic Marketplace and Blanket Purchase Agreement (BPA) capabilities. Through a Strategic Marketplace construct, the FBI could define a curated catalog of pre-approved OSINT software tools and associated services aligned to mission requirements, applying standardized filters such as security compliance, vendor authorization, and technical specifications. Establishing a BPA against this Marketplace would provide a streamlined ordering mechanism for recurring and evolving OSINT needs, enabling rapid tasking, reduced procurement lead times, and improved cost efficiency through aggregated demand.
| This approach would also support continuous competition among qualified SEWP contract holders, facilitate faster onboarding of emerging OSINT technologies, and provide enhanced visibility, reporting, and governance across tool usage. Collectively, leveraging SEWP V would provide a more agile, compliant, and scalable acquisition strategy for specialized OSINT capabilities while minimizing administrative overhead and regulatory complexity. | A waiver is not required as this is for SaaS and therefore the NMR does not apply. | ||
| 0001 Financial / banking information | Are only existing tools being requested, or will you also accept tools we can build out for you? | Existing tools are requested, not tools to be built | |
| 0001 Financial / banking information | Do you only require the products or will we be able to offer an SME to assist with requests? | The Government is looking for a SaaS tool and a helpdesk representative, which could be a SME, to assist with requests. | |
| 0002 Deep and Dark Web | Are only existing tools being requested, or will you also accept tools we can build out for you? | Existing tools are requested, not tools to be built | |
| 0002 Deep and Dark Web | Do you only require the products or will we be able to offer an SME to assist with requests? | The Government is looking for a SaaS tool and a helpdesk representative, which could be a SME, to assist with requests. | |
| 0003 Digital Assets information | Are only existing tools being requested, or will you also accept tools we can build out for you? | Existing tools are requested, not tools to be built | |
| 0003 Digital Assets information | Do you only require the products or will we be able to offer an SME to assist with requests? | The Government is looking for a SaaS tool and a helpdesk representative, which could be a SME, to assist with requests. | |
| 0008 Terrorism related information | Are only existing tools being requested, or will you also accept tools we can build out for you? | Existing tools are requested, not tools to be built | |
| 0008 Terrorism related information | Do you only require the products or will we be able to offer an SME to assist with requests? | The Government is looking for a SaaS tool and a helpdesk representative, which could be a SME, to assist with requests. | |
| 0007 Historical internet data | Are only existing tools being requested, or will you also accept tools we can build out for you? | Existing tools are requested, not tools to be built | |
| 0007 Historical internet data | Do you only require the products or will we be able to offer an SME to assist with requests? | The Government is looking for a SaaS tool and a helpdesk representative, which could be a SME, to assist with requests. | |
| All CLINs, RFP 5.3 Volume 2, Technical Approach | RFP states "Each proposal must list the product number, product description, quantity, and period of performance, for each year requested, including base and option years." It is our understanding that the required PoP is a base year, four (4) 12-month option periods, and 6-month extension. Is the Offeror being asked to acknowledge this PoP in our Technical Approach? Please clarify what must be included to be compliant. | Yes, acknowledge POP in the Technical Approach | |
| All CLINs, RFP 5.3 Volume 2, Technical Approach | RFP states "Each proposal must list the product number, product description, quantity, and period of performance, for each year requested, including base and option years." It is our understanding that the desired quantities are listed in Tiers 1-4. Is the Offeror being asked to acknowledge these tiers in our Technical Approach? Please clarify what must be included to be compliant. | Tiers do not need restated in the Technical Approach | |
| All CLINs, RFP 6.0 Basis of Award | In order to properly align with the applicable size standard (small), we request clarification on the Government’s determination regarding the use of the IT Value Added Reseller (VAR) exception under NAICS 541519. Specifically, could the Government provide its estimated breakdown of contract value between: Product/tool licensing or subscriptions; and Value-added services (e.g., integration, support, training)? Based on our understanding of the requirement, the scope appears to be primarily focused on the provision of OSINT tools/licenses. | The Government is not using the IT Value Added Reseller (ITVAR) exception. This solicitation is issued under NAICS 513210 (Software Publishers), which covers SaaS‑based software delivered as a service. The reference to ‘small business resellers’ reflects that offerors may be authorized partners or distributors of SaaS OSINT platforms. Because this is not an ITVAR or supply‑based requirement, the Government will not be providing a percentage breakdown between licensing and services. | |
| All CLINs, 5.3, Volume 2, Technical Approach | We request confirmation of the anticipated Period of Performance (PoP) start date, including any expected transition or phase-in period. This information is important to ensure accurate proposal planning, staffing, and cost estimation. | The Government has not established a specific Period of Performance start date for this requirement. At this stage, offerors are only required to ensure their quotes remain valid for 120 days, as stated in the RFP. A POP date will be finalized at the time of award. | |
| Proposal Document | In the 5.0 SUBMITTAL INSTRUCTIONS, Point (5), is single line-spacing acceptable? | Yes | |
| Proposal Document | If we include images are they counted towards page count? | Images are counted in the nine pages of Volume II - Factor 1 - Technical Approach. | |
| Proposal Document | If we include images are captions in the same, 12-point Times font? | Captions can be a smaller font, but need to be readable. | |
| Proposal Document | If we are submitting against more than one CLIN, is there one proposal (Volume 1, Volume 2, Volume 3) per CLIN? | Full proposals and Volumes must be submitted for each CLIN, with each proposal focusing on the specific requirements of that CLIN. Each CLIN is evaluated separately. Contractors can submit proposals for any CLIN which they meet the requirement. | |
| General Query | What specific domains are required? | ||
| o | Surface web only? | ||
| o | Social media (which platforms)? | ||
| o | Deep web forums? | ||
| o | Dark web marketplaces, TOR sites, leak sites? | The domains are listed in the requirements for each CLIN. | |
| General Query | Which CLIN categories are in scope? | ||
| o | Identity, terrorism, dark web, financial, etc. | The Offeror should provide a submission for each CLIN that they feel they can meet the requirements of. | |
| Data Volume and Ingestion Rate | How much data needs to be ingested daily? | The amount of data to be ingested depends greatly on the CLIN and the Offeror's capability. We invite the Offeror to share what volume of data they are able to provide for a given CLIN. | |
| Data Volume and Ingestion Rate | Is this: | ||
| o | Continuous streaming ingestion | ||
| o | Periodic batch ingestion | There is no specific timeliness requirement in the SOW for data being updated, but the more current the better. We invite the Offeror to share what timeliness of ingestion they are able to provide. | |
| Data Volume and Ingestion Rate | What is the expected data growth rate over time? | There is no way to estimate data growth rate, but useful information will naturally see an increase in demand over time. | |
| Data Volume and Ingestion Rate | Are there spikes in volume (events, crises, investigations)? | Spikes can occur depending on needs of the Bureau, yes. | |
| All CLIN | Are there specific geographies or languages required? | Geographic needs may include anywhere in the United States and Territories, including Puerto Rico, US Virgin Islands, Guam, and Saipan, also foreign countries. For languages, no specific ones are specified but large and common languages are preferred. | |
| All CLIN | Are there specific threat types being prioritized? | ||
| o | Terrorism | ||
| o | Cybercrime | ||
| o | Fraud | ||
| o | Human trafficking | Each CLIN is a separate topic, and each one will be looked at individually. We do not specify a Human Trafficking, Cyber, or Fraud CLIN. | |
| All CLIN | Do you need broad discovery or targeted monitoring? | Both. The requirements assume starting with broad discovery, though many of the CLINs ask for detailed information about a search target. | |
| All CLIN | How many queries per user per day? | It is impossible to estimate the number of queries per day; it will depend on the CLIN, the tool, the number of licenses purchased, and any exigent circumtances that might be occurring. | |
| All CLIN | Are queries: | ||
| o | Simple keyword searches | ||
| o | Complex boolean queries | ||
| o | Entity-based (identity pivoting) | We invite the Offeror to share what types of queries they are able to provide for a given CLIN. | |
| All CLIN | Do queries require: | ||
| o | Cross-source correlation | ||
| o | Historical back-searching | Cross-source correlation involves analysis, and some requirements speak to the analysis need. Also, some CLINs ask for historical data to be provided. | |
| All CLIN | What is the average query depth? | ||
| o | Single search vs multi-hop pivoting | We invite the Offeror to share what query depth they are able to provide for a given CLIN. | |
| All CLIN | How many persistent (standing) queries will be running? | See response, line 33. | |
| All CLIN | How frequently should they execute? | ||
| o | Real-time / streaming | ||
| o | Every few minutes | ||
| o | Daily | See response, line 27. | |
| All CLIN | How many subjects or cases are being continuously monitored? | See response, line 33. | |
| All CLIN | What is the expected alert volume per day? | See response, line 33. There is no specified alerting requirement in the SOW. | |
| All CLIN | How much historical data access is required? | ||
| o | Real-time only | ||
| o | 30 days | ||
| o | 1 year | Historical data is required for several CLINs on this RFQ, and CLIN 6 specifically asks for Historical Internet data. We invite the Offeror to share what date range of historical data they are able to provide for that and other CLINs. | |
| All CLIN | Are Multi-year historical archives required | There is no requirement stating multi-year archives are needed, but we invite the Offeror to share if they have access to such data. | |
| All CLIN | Do analysts need to: | ||
| o | Re-query historical datasets? | ||
| o | Perform retroactive analysis? | There are a number of scenarios where the FBI may need to look at historical data to respond to a question or line of inquiry, to delve into a subject's past, or otherwise for assistance in an investigation. | |
| All CLIN | How many concurrent users? | See response, line 33. | |
| All CLIN | What type of users: | ||
| o | Heavy analysts | ||
| o | Occasional users | There are various use cases and several position descriptions in the Bureau that may use these tools; some analysts, some occasional users. | |
| All CLIN | Average session duration | It is impossible to estimate the average session duration; it will depend on the CLIN, the tool, the number of licenses purchased, and any exigent circumtances that might be occurring. | |
| All CLIN | Queries per session | See response, line 33. | |
| All CLIN | Will data be: | ||
| o | Exported frequently? | ||
| o | Integrated into other systems? | There is no direct integration of data from the Offeror's system to FBI systems; we ask the Offeror to provide information about how data can be exported if needed. | |
| All CLIN | What formats are required? As etc. is listed as an export option | Formats required include those mentioned, and we ask the Offeror to share information about others they might provide. | |
| All CLIN | Are there APIs pulling data continuously? | There are no requirements for APIs in the SOW. | |
| All CLIN | Is there cross-agency sharing? | Cross agency sharing is possible but not common. | |
| CLIN 2: Deep/Dark Web | What specific domains are required? | ||
| o | Deep web forums? | ||
| o | Dark web marketplaces, TOR sites, leak sites | The required datasets for the Deep/Dark Web CLIN (CLIN 2) are specified. We invite the Offeror to share which of the Deep/Dark websites they can provide. | |
| CLIN 8: Terrorism related information | Will Avatars be required for searching of data where private channels are used. | Avatars are not called out in the requiements. We invite the Offeror to share if such aides are provided and how this would be beneficial to the Government. | |
| CLIN 9: Image Information | Will searches include multimedia content such as images and video, or be limited to text? | Both Images and Video data are called out in the requirements; depending on the CLIN, text-only data is not sufficient. | |
| CLIN 9: Image Information | Will multimedia content need to be indexed and searchable alongside text-based data? | OCR in images and videos is called out in various CLINs. Searchable images and videos are much more useful to the Government. | |
| CLIN 10: Video information | Will searches include multimedia content such as images and video, or be limited to text? | See response, line 54. | |
| CLIN 10: Video information | Will multimedia content need to be indexed and searchable alongside text-based data? | See response, line 55. | |
| CLIN 11: Identity Records | Will Avatars be required for searching of data where private channels are used. | See response, line 53. | |
| CLIN 12: Property and land records | Are satellite maps required to visualize the co-ordinates from data source | Satellite maps are not called out in the requirements. We invite the Offeror to share if such data are provided and how this would be beneficial to the Government. | |
| CLIN 12: Property and land records | Is OCR required to view legacy records | OCR is called out several times in the requirements; legacy records are much more useful if they are text-searchable. | |
| All CLIN | Is there a criteria for what’s periods of data is considered critical vs important vs good to have? Meaning, is the recent 3 month data more critical vs past year important vs last 2 years? | See response, line 41. | |
| All CLIN | How many entity profiles, across all sections, does the FBI plan to utilize | It is impossible to estimate the number of entity profiles; it will depend on the CLIN, the tool, the number of licenses purchased, and any exigent circumtances that might be occurring. | |
| All CLIN | After queries are made, across any or all sections of CLIN, does the user like to store all query results/data sets? | Retention of data may be useful in some circumstances; however, there is a policy limit to how long the system(s) can store the data, so any retention should allow for deletion when needed. | |
| All CLIN | What would be the data sets/query results retention time in the system? | Generally, data may not be retained longer than 120 days. | |
| All CLIN | Would there be a critical list of identifiers and metadata required for indexing? While we can index any amount of identifiers and associated metadata, the system parameters rapidly increase. That affects the sizing of the system | Indexing as understood in the FBI is not a requirement for this acquisition. | |
| All CLIN | Will analysts require coverage of social messaging platforms (e.g., WhatsApp public channels, Telegram public groups, Discord communities)? | Yes, any social media messaging platform that has Publicly Available Information. | |
| General Queries | Will analysts require coverage of blogs and long-form web content? | Yes, any coverage of blogs and long-form web content that has Publicly Available Information. | |
| General Queries | Will analysts require broadcast news and media transcript ingestion (TV, radio, closed caption feeds)? | Yes, any coverage of broadcast news and media transcript ingestion that has Publicly Available Information. | |
| General Queries | Will searches include multimedia content such as images and video, or be limited to text? | See response, line 54. | |
| General Queries | Do analysts require document summarization capabilities across large text datasets? | Artifical Intelligence capabilities are preferred but not required for most of the CLINs, with some exceptions such as NLP found in Machine Translation tools. We invite the Offeror to share how much AI they can provide in their system. | |
| General Queries | Should summarization be applied automatically or on-demand by analysts? | Artifical Intelligence capabilities are preferred but not required for most of the CLINs, with some exceptions such as NLP found in Machine Translation tools. We invite the Offeror to share how much AI they can provide in their system. | |
| All CLIN | Which is the perfered option for deployment Cloud, on-prem, or hybrid? | This RFP is for a SaaS. | |
| All CLIN | Will the system be deployed Multi-tenant vs single-tenant? | Multi-tenant is preferable to single-tenant. | |
| All CLIN | Any special security controls required? Such as dual factor authentication | The requirements for System Security are listed under each CLIN. | |
| All CLIN | What is the acceptable latency for: | ||
| o | Search results | ||
| o | Alerts | See response, line 40. See also response, line 27. | |
| All CLIN | Is this: | ||
| o | Analyst-driven investigation | ||
| o | Time-sensitive threat detection | The data will be needed for various questions and investigations in the FBI. Analysts may be involved, as will other FBI personnel. Current data is requested, including threats, but it is only 1 purpose for using these tools. | |
| All CLIN | Will data be: | ||
| o | Exported frequently? | ||
| o | Integrated into other systems? | There is no direct integration of data from the Offeror's system to FBI systems; we ask the Offeror to provide information about how data can be exported if necessary. | |
| All CLIN | Are there APIs pulling data continuously? | Duplicate to line 50. | |
| All CLIN | How quickly must alerts be delivered? | ||
| o | Real-time | ||
| o | Near real-time | ||
| o | Scheduled | See response, line 40. See also response, line 27. | |
| All CLIN | How many alerts per day are expected? | No alerts are required in the SOW. That said, it is impossible to estimate the number of queries per day; it will depend on the CLIN, the tool, the number of licenses purchased, and any exigent circumtances that might be occurring. | |
| All CLIN | Are alerts: | ||
| o | Simple keyword matches | ||
| o | Complex behavioral triggers | ||
| o | Do alerts trigger downstream workflows? | Alerts as such are not required per the SOW. That said, specific keyword matches are the first search returns expected. We invite the Offeror to share if they are capable of providing more complex returns such as behavioral triggers. Responses to searches may result in further analysis in the tool, if the tool has analysis capability. | |
| All CLIN | Are alerts limited to the user interface | See response, line 40. | |
| All CLIN | Are alerts are required to be sent via email or other methods | See response, line 40. | |
| All CLIN | How much AI processing is required? | ||
| o | Basic NLP vs advanced modeling | Artifical Intelligence capabilities are only preferred but not required for most of the CLINs, with some exceptions such as NLP found in Machine Translation tools. We invite the Offeror to share how much AI they can provide in their system. | |
| All CLIN | Are you analyzing: | ||
| o | Text only | ||
| o | Audio/video/image | See response, line 54. | |
| All CLIN | Do you require: | ||
| o | Real-time AI processing | ||
| o | Batch processing | We invite the Offeror to provide information on what their tool can offer. | |
| All CLIN | What percentage of data is being analyzed vs just stored? | It is impossible to estimate the number of downloads vs. reviews of the returned data; it will depend on the CLIN, the tool, the number of licenses purchased, and any exigent circumtances that might be occurring. Storage is not a requirement but it may be useful; the Offeror can inform the FBI if that is a capability they can provide. | |
| All CLIN | Do you require identity resolution / entity correlation? | In accordance with all legal requirements, the Contractor must provide the ability to identify, analyze, and correlate current and historical information to "digital identities and footprints" and connect them to real people, and vice versa. | |
| All CLIN | Do you require credential datasets (breach data)? | For the Deep/ Dark Web CLIN (CLIN 2), breach data is not required, but suggested. | |
| All CLIN | Do you require: | ||
| o | Geo-inference | ||
| o | Translation | ||
| o | Transcription (audio/video) | Each of these are called out specifically in the requirements document. | |
| All CLIN | Are you enriching data with: | ||
| o | Commercial identity datasets | ||
| o | Risk scoring | ||
| o | Behavioral analytics | The FBI is not enriching the data, though it may export the data if it is found to be useful for investigations and casework. | |
| Overall - Volume 2 | Technical Approach – does the government expect a 9 page tech response for each of the CLINs of interest? Or, is it one technical approach of 9 pages for all CLINs in total? | See response, Line 23. | |
| Overall All CLINs | Are the analytics services to be included in the unit price per license for each CLIN, or should it be broken out separately? | The FBI is seeking 1 single license price for an evaluable cost. It must include all support and capabilities of the system. | |
| Overall All CLINs | Are the training and help desk support to be included in the unit price per license, or should it be broken out separately? | It must be included. | |
| Overall All CLINs | How many live virtual training sessions are expected under each CLIN? | The number of trainings depends on number of licenses on task orders. Any task order, including those with just 1 license, must provide virtual live training. | |
| ALL | Given that some vendors provide integrated SaaS platforms that span multiple CLIN capability areas, does the Government prefer pricing to be submitted separately for each CLIN, or is it acceptable to propose a single enterprise license price that covers multiple CLINs with a clear mapping of capabilities | Separate pricing for each CLIN is required for evaluation. | |
| ALL | Can a single proposed solution be evaluated and awarded under multiple CLINs if it meets the requirements of each, or is the Government expecting distinct solutions per CLIN? | See results, line 23. | |
| ALL | If pricing is required at the CLIN level, does the Government have a preferred methodology for allocating pricing across CLINs for solutions that provide overlapping or integrated capabilities? | Each CLIN will be evaluated individually, even if the offeror can provide services under more than one CLIN. | |
| ALL | For solutions that inherently bundle multiple data types and analytical capabilities within a single license, should offerors include all included capabilities within a primary CLIN, or distribute them across multiple CLINs? | See response, Line 23. | |
| ALL | How does the Government intend to evaluate pricing at the task order level for vendors whose solutions span multiple CLINs under a single license model? | Each CLIN will be evaluated individually, with the basis for each evaluation of price is the single-license price. | |
| ALL | Is the Government expecting offerors to propose against a single CLIN where they are strongest, or to propose against all applicable CLINs where their solution meets requirements? | See response, Line 23. | |
| ALL | Please clarify whether FedRAMP Moderate certification/authorization is required for this procurement or whether the reference to FedRAMP Moderate, 256-bit encryption, and other security measures is illustrative only. If FedRAMP is not strictly required, please identify the minimum security posture and compliance standards that an offeror's system must meet to be considered acceptable to the FBI. | The Contractor must ensure their website and system maintain a robust security posture to safeguard usernames, passwords, and FBI usage and search terms. The Government must be provided the security posture of the Contractor's system to safeguard the user data in the system. FedRAMP Moderate level is preferred, but a security posture that is comparable is acceptable. | |
| The RFP states that offerors must identify which CLIN(s) their specialized tool fits into, and the Government may choose up to two tools for each CLIN. Would the Government consider proposals that rely on formal company partnerships or teaming arrangements to satisfy multiple CLIN requirements under a single submission, where each proposed partner is responsible for the applicable CLIN-specific capabilities? If so, please clarify whether the Government has a preferred structure for presenting those arrangements in order to reduce administrative burden on both the Government and the offeror. | No. Each CLIN requires its own separate proposal and set of volumes. Offerors may use partners or teaming arrangements, but each CLIN must still be submitted as a separate proposal with its own CLIN‑specific content | ||
| Pricing | OSINT tools consume some of their data from providers that charge for consumption of that data. To keep user license pricing as low as possible, we are considering moving to a data consumption token model similar to AWS, Microsoft, Google and many computing and AI based providers. This type of model will benefit the customer by allowing more access to high value data sources but only pay for them as used/needed to support government requirements. Will the government accept a pricing model that is a license for the tool that includes a base amount of tokens for data consumption with the ability to top up on tokens when they are depleted? | No, pricing and licensing structure must comply with the SOW RFP, and Pricing Template | |
| CLIN 8: Terrorism related information, 508 Compliance | If the contractor is in the process of becoming 508 compliant and is planning on being compliant in the next 6-9 months, is that acceptable to the government? | The Contractor must ensure their system is 508 Compliant or working towards 508 Compliance. A Scorecard is not required in the submission, but must be provided annually if awarded a contract. | |
| CLIN 8: Terrorism related information, System Security | Will ISO 27001:2022 certification be an adequate security measure to safeguard user data? | The Contractor must ensure their website and system maintain a robust security posture to safeguard usernames, passwords, and FBI usage and search terms. The Government must be provided the security posture of the Contractor's system to safeguard the user data in the system. FedRAMP Moderate level is preferred, but a security posture that is comparable is acceptable. | |
| CLIN 8: Terrorism related information, System Security | Do you require a security certification, like FedRAMP moderate, in order to be considered for award? | No. The Contractor must ensure their website and system maintain a robust security posture to safeguard usernames, passwords, and FBI usage and search terms. The Government must be provided the security posture of the Contractor's system to safeguard the user data in the system. FedRAMP Moderate level is preferred, but a security posture that is comparable is acceptable. | |
| CLIN 8: Terrorism related information, System Security | The SOW repeats the same system-security requirements (e.g., SaaS architecture, FedRAMP-like security posture, DOJ-02/05/07 considerations) within each CLIN description. Can the Government confirm that all contract-level security requirements apply uniformly to all CLINs and that there are no CLIN-specific variations in required security controls? | Correct, for each CLIN the system Security requirements are the same. | |
| CLIN 8: Terrorism related information | What criteria will you use to define a "user-friendly GUI?" | The Contractor must provide a coherent, organized, and intuitive Graphic User Interface (GUI) that is easily navigated by non-technical users. The GUI must not be cluttered or confusing and must be able to be understood without needing extensive training. | |
| CLIN 8: Terrorism related information | The SOW states that company/system requirements must both "provide Software as a Service (SaaS)" and "provide notice of planned upgrades and modifications to the system...this notification must be provided 30 days prior to implementation." SaaS companies service more than one government customer with the same software, while a noted advantage of SaaS products is the speed and adoption of upgrades. Will the FBI have a waiver procoess for this 30-day notification requirement? | The 30-day requirement is for major pre-planned upgrades that may require extra user training as well as review by attorneys to ensure the Privacy and Civil Liberties are not enfringed (such as use of a new AI functionality). However, a waiver could be accepted in exigent circumstances where 30 days notice cannot be made. | |
| CLIN 8: Terrorism related information | Will the FBI provide a DD Form 254 or equivalent for selected companies in order to obtain security clearances to support the DI customer? | No, no security clearance will be necessary or requested by the FBI for this IDIQ contract. | |
| CLIN 2, 3, 5, 6, 7, 8, 9, 11, 12 | Your list several SOW capabilities as either required or preferred for geospatial and geo-inference tooling that's referenced across multiple CLINs. Can you please provide a CLIN specific to this requirement? | Geospatial and Geo-Inference requirements may apply differently for different CLINs. No CLIN has geo as a specific focus. | |
| CLIN 1-12 | You make statements throughout the SOW requiring a non-technical user focussed UI that are referenced across multiple CLINs. “The Contractor must provide a coherent, organized, and intuitive Graphic User Interface (GUI) that is easily navigated by non-technical users.” Can you please provide a CLIN specific to this requirement? FBI mission stakeholders would no doubt find value in a consistent UI across all CLIN data requests. | No, the only GUI requirements are stated under each CLIN in the SOW. | |
| 7 | How do you envision users will query the system's data holdings while ensuring appropriate classification requirements are met (for example, if there are any high-side selectors in the search terms)? If there are high-side selectors, do you envision this as a need the system would address, or that the FBI will declassify search terms before entering them into the system? | The data searches for these CAI/PAI tools will not exceed the UNCLASSIFIED FOUO and/or LES level. | |
| 10 | How do you envision users will query the system's data holdings while ensuring appropriate classification requirements are met (for example, if there are any high-side selectors in the search terms)? If there are high-side selectors, do you envision this as a need the system would address, or that the FBI will declassify search terms before entering them into the system? | Repeat; see response, line 114. | |
| 7 | The Office of the Director of National Intelligence has released guidance on accessing, collecting, and processing Commercially Available Information, which includes applying "appropriate safeguards that are tailored to the sensitivity of the information...These safeguards shall reflect consideration of any newly available privacy enhancing methods or technologies and must ensure CAI is properly secured, handled appropriately, and subject to appropriate auditing, retention, destruction, and oversight requirements." Although not explicitly called out in the RFP, will these safeguards be considered as part of the responses to this CLIN? | The FBI follows all ODNI and DOJ CAI mandates and each tool accepted as viable for the contract will have to pass CAI screening before the FBI can use it. A separate CAI questionnaire must be completed by every Offeror, which is the start of the CAI process. This questionnaire does not count against the 9 page limit. | |
| 10 | The Office of the Director of National Intelligence has released guidance on accessing, collecting, and processing Commercially Available Information, which includes applying "appropriate safeguards that are tailored to the sensitivity of the information...These safeguards shall reflect consideration of any newly available privacy enhancing methods or technologies and must ensure CAI is properly secured, handled appropriately, and subject to appropriate auditing, retention, destruction, and oversight requirements." Although not explicitly called out in the RFP, will these safeguards be considered as part of the responses to this CLIN? | Repeat; see response, line 116 | |
| ALL | Given that some vendors provide integrated SaaS platforms that span multiple CLIN capability areas, does the Government prefer pricing to be submitted separately for each CLIN, or is it acceptable to propose a single enterprise license price that covers multiple CLINs with a clear mapping of capabilities? | Each CLIN must stand on its own with its own task order, billing, usage and license pricing. | |
| ALL | Can a single proposed solution be evaluated and awarded under multiple CLINs if it meets the requirements of each, or is the Government expecting distinct solutions per CLIN? | Full proposals and Volumes must be submitted for each CLIN. Each CLIN is evaluated separately. Contractors can submit proposals for any CLIN which they meet the requirement | |
| ALL | If pricing is required at the CLIN level, does the Government have a preferred methodology for allocating pricing across CLINs for solutions that provide overlapping or integrated capabilities? | See response, line 118. | |
| ALL | For solutions that inherently bundle multiple data types and analytical capabilities within a single license, should offerors include all included capabilities within a primary CLIN, or distribute them across multiple CLINs? | Full proposals and Volumes must be submitted for each CLIN. Each CLIN is evaluated separately. | |
| ALL | How does the Government intend to evaluate pricing at the task order level for vendors whose solutions span multiple CLINs under a single license model? | See response, line 118. | |
| ALL | Can the Government clarify the intended relationship between the Open-Source Intelligence (OSINT) Alerting Tool RFQ (issued 1/23/26) procurement and this, Specialized OSINT Tools IDIQ (issued 3/20/26)? Are these solutions expected to be complementary, or do they represent overlapping capabilities? | There may be some overlappting capabilities, but these are separate contracts with separate capabilities, clients, and benefits. | |
| ALL | Is the Government expecting offerors to propose against a single CLIN where they are strongest, or to propose against all applicable CLINs where their solution meets requirements? | Offerors can submit a proposal for each CLIN where their solution meets the requirements | |
| ALL | Please clarify whether FedRAMP Moderate certification/authorization is required for this procurement or whether the reference to FedRAMP Moderate, 256-bit encryption, and other security measures is illustrative only. If FedRAMP is not strictly required, please identify the minimum security posture and compliance standards that an offeror's system must meet to be considered acceptable to the FBI? | The Government must be provided the security posture of the Contractor's system to safeguard the user data in the system. FedRAMP Moderate level is preferred, but a security posture that is comparable is acceptable. | |
| The RFP states that offerors must identify which CLIN(s) their specialized tool fits into, and the Government may choose up to two tools for each CLIN. Would the Government consider proposals that rely on formal company partnerships or teaming arrangements to satisfy multiple CLIN requirements under a single submission, where each proposed partner is responsible for the applicable CLIN-specific capabilities? If so, please clarify whether the Government has a preferred structure for presenting those arrangements in order to reduce administrative burden on both the Government and the offeror. | No. Each CLIN requires its own separate proposal and set of volumes. Offerors may use partners or teaming arrangements, but each CLIN must still be submitted as a separate proposal with its own CLIN‑specific content | ||
| CLIN 2 and CLIN 11 | Does the Government distinguish between traditional OSINT 'scrapers' (which monitor public forums) and 'Recapture' technologies that provide telemetry directly from malware-infected devices (infostealer logs)? Given that infostealer logs provide real-time access to session cookies, browser-stored credentials, and autofill data not available on the surface or dark web, will the Government evaluate this as a distinct technical advantage under CLIN 2 and CLIN 11? | The FBI is not seeking this level of cyber data pulled from session cookies, browser-stored credentials, etc. If an Offeror can provide it, the FBI invites the Offeror to describe their capability and how that would be useful within a particular CLIN. | |
| CLIN 3 and CLIN 5 | For requirements involving Digital Assets and International Business, does the Government seek the ability to link PII to financial 'digital exhaust'‚ such as exfiltrated bank account selectors, credit card numbers, or API keys for payment platforms‚ recovered from compromised endpoints? Will tools providing this level of financial attribution be scored higher in technical merit? | Yes to linking. Technical merit is evaluated by confidence in the submitter's 9-page response. | |
| Section L / PRA | If a proposed tool functions as a search-and-recapture engine that allows investigators to query pre-existing stolen data without the tool itself storing or hosting new Government-acquired PII, how does this 'non-storage' architecture impact the mandatory FedRAMP control baseline for the Product Risk Assessment (PRA)? Does the Government acknowledge the reduced data liability of this architecture? | If an Offeror has the ability to search and recapture data in the manner described, the Offeror can describe that in their submission. In any case, the system provided to FBI users must be FEDRAMP (or equivalent) protected. | |
| Section L | Given the 'non-storage' nature of certain specialized tools, will the Government accept a SOC 2 Type II attestation as a sufficient security baseline for the initial award, provided the tool does not ingest, process, or store sensitive FBI-generated data? | No. The issue lies with the fact that the system must have FBI user accounts, and as such, names and/or emails of FBI personnel will be held in the system. Futhermore, search criteria may be FOUO or LES, which can be considered senstive FBI data. | |
| General / Volume 2 | Given the 9-page limit for Volume 2 (Technical Approach), if a bidder proposes a best-of-breed solution set where a single high-fidelity dataset or tool satisfies the requirements of multiple CLINs (e.g., CLINs 2, 3, 5, and 11) simultaneously, may the bidder submit a consolidated technical description that maps that capability across all applicable CLINs to ensure a thorough response while remaining within the page constraints?" | Each CLIN requires its own separate proposal and set of volumes. CLINs are evaluated independently, and a full 9‑page technical approach is allowed for each CLIN. | |
| N/A - Administrative (RFP Section 5.1 Proposal Organization) | Are the page limitations inclusive of any cover pages or table of contents? | No. Table of Contents and a cover page are not counted in the 9 pages. | |
| N/A - Administrative | Does the government require completion of any representations and certifications outside of those completed in SAM.gov? | No | |
| RFP Document - Section 6. Basis of Award | This section states the Government intends to issue a Multiple-Award IDIQ to small business authorized resellers of Specialized OSINT Tools. Is the authorized reseller status a requirement for response? | No. Offerors do not need to be an authorized reseller at the time they submit a proposal, but they must be authorized by the SaaS publisher before award. The Government may request proof of authorization during evaluations to ensure the offeror can legally provide the proposed tool. The intent of the language is simply to ensure that the prime contractor is a small business under NAICS 513210 and is able to legally provide the SaaS OSINT tools they propose. | |
| RFP Section 5.0, Submittal Instructions | Can an offeror propose multiple OEM solutions across different CLINs within a single response, or is the submission limited to one OEM per overall proposal? | Offerors must submit only one proposal per CLIN. Each proposal must identify a single OEM. Each CLIN must have its own complete proposals and Volumes. | |
| RFP Section 5.0, Submittal Instructions | If a submission is limited to one OEM per overall proposal, may an offeror submit multiple proposals? | No. Offerors may submit only one proposal per CLIN. Each proposal must identify a single OEM. | |
| 0004, 0005, 0011 | If an offeror’s solution aligns with and is proposed under multiple CLIN categories, does the Government expect pricing to be replicated separately under each applicable CLIN? If a respondent has a solution that crosses multiple CLINs, will that be taken into account in the total price evaluation? | Yes, full proposals and Volumes must be submitted for each CLIN. Each CLIN and its pricing is evaluated separately. | |
| Section 5.0 Submittal Instructions | Will the Government allow each Volume to include a cover page and table of contents that do not count against page limitations? | Yes | |
| Section 7.0 Rating Methodology | The RFP instructions Section 7 Rating and Methodology, provides a breakdown of the technical approach ratings. The highest rating is "High Confidence" which is classified as "The Government has high confidence that the Contractor understands the requirement, proposes a sound approach, and will be successful in meeting minimum requirements with little to no Government intervention." Given that this is a commercial SaaS procurement, vendors claiming that their solutions will provide the Government high confidence is quite ambiguous. Will the Government please provide additional guidance as to what qualifies as criteria that would drive higher confidence for understanding of requirements? For example, does the Government desire Contractors to provide benefits and/ or strengths to help quantify confidence levels for the evaluators? | The confidence ratings in Section 7 are standard Government evaluation terminology and reflect the evaluators’ level of confidence in the offeror’s ability to meet the requirements. Vendors may demonstrate their understanding and approach by clearly addressing the requirements in the SOW and by identifying any benefits, strengths, or unique aspects of their proposed solution. The Government will not provide additional criteria beyond what is stated in the solicitation. | |
| Section 5.0 Submittal Instructions | Section 5.0 of the RFP provides submission instructions that indicates that Factor 1 - Technical Approach volumes cannot exceed 9 pages. However, if vendors intend to bid on multiple CLINS they must include a list of product descriptions along with how their proposed products meet or exceed the SOW for each of the CLINS, which would make it difficult to respond to multiple CLINS given the tight page constraints. Theoretically if a vendor wishes to bid on all 12 CLINS this would require a vendor to address all of the requirements in merely 9 pages. Will the Government please consider increasing the page maximum to 15 pages? | It is 9 pages for each technical proposal. Each CLIN requires its own technical proposal. | |
| 0001, 0003, 0004, 0011 | Please confirm the applicable NAICS code and corresponding size standard for this solicitation and for each CLIN, if different by CLIN. | NAICS 513210 (Software Publishers), with a $47 million small business size standard, is the applicable NAICS code for this solicitation. This NAICS code applies to the entire requirement and to all CLINs. The Government is not assigning different NAICS codes by CLIN. | |
| 0001, 0003, 0004, 0011 | Please confirm that a small business offeror may propose as an authorized reseller / prime contractor with a subcontracted OEM or platform provider, provided the offeror remains the contractual interface with the Government and otherwise meets solicitation requirements. | Yes. Confirmed | |
| 0001, 0003, 0004, 0011 | Please confirm whether any limitations on subcontracting apply to this procurement and, if so, how the Government intends to classify performance for purposes of that requirement. | Yes. Limitations on subcontracting apply to this small‑business set‑aside. Compliance will be based on the solicitation’s primary NAICS code. | |
| 0001, 0003, 0004, 0011 | The updated solicitation states that base pricing is for one (1) license/user. Please confirm whether this should be interpreted strictly as one named user seat, or whether a commercial enterprise subscription may be mapped into the pricing template using a consistent license/user construct across base and tiered pricing. | The base pricing requirement of one (1) license/user must be interpreted in accordance with the pricing and licensing structure outlined in the SOW, RFP, and the provided pricing template. Offerors must conform to this structure. Commercial enterprise or usage‑based models may be translated into the Government’s required format, but the construct must remain consistent with the solicitation’s prescribed one‑license per user basis. Offerors must follow the pricing and licensing structure in the SOW, RFP, and pricing template. | |
| 0001, 0003, 0004, 0011 | If a commercial offering is normally sold as an enterprise subscription, market package, or usage-based subscription rather than per-seat licensing, may the offeror map that commercial model into the Government’s pricing template using an equivalent license/user construct? If so, does the Government have a preferred approach? | The base pricing requirement of one (1) license/user must be interpreted in accordance with the pricing and licensing structure outlined in the SOW, RFP, and the provided pricing template. Offerors must conform to this structure. Commercial enterprise or usage‑based models may be translated into the Government’s required format, but the construct must remain consistent with the solicitation’s prescribed one‑license per user basis. Offerors must follow the pricing and licensing structure in the SOW, RFP, and pricing template. | |
| 0001, 0003, 0004, 0011 | The SOW requires SaaS available through the internet with no software downloaded, installed, or integrated into FBI computers. Would a browser-accessed dedicated tenant or dedicated hosted environment for Government use satisfy this requirement, provided no FBI endpoint software is required? | No. The FBI prefers multi-tenant environments. | |
| 0001, 0003, 0004, 0011 | If the proposed tool/solution is hosted in a cloud environment that is already FedRAMP certified at the moderate impact level, such as AWS or Azure Government, would that satisfy the FBI’s security requirements for purposes of ATO review, or does the application layer itself also need to be FedRAMP certified? | Yes | |
| 0001, 0003, 0004, 0011 | Please clarify what security documentation the Government expects with proposal submission to demonstrate system security posture, such as architecture diagrams, data flow diagrams, encryption details, incident response summaries, SSP, SAR, or other artifacts. | The Government must be provided the security posture of the Contractor's system to safeguard the user data in the system. For submission, a description will suffice, diagrams would not need to be included. | |
| 0001, 0003, 0004, 0011 | Please clarify whether the Government requires all privileged administrative, maintenance, and support access to contractor environments containing FBI information to be performed only by U.S. persons located in the United States. | Yes, all persons working on the system with any access to searches, usernames and accounts, or other FBI-specific information must be US Persons located in the US. | |
| 0001, 0003, 0004, 0011 | Please clarify whether CAI, AI evaluation, PTA, and any required PIA reviews must be completed prior to IDIQ award, prior to task order issuance, or prior to operational use. | Theses processes must be done prior to operational use. | |
| 0001, 0003, 0004, 0011 | Please clarify whether a specific contract vehicle will be used in the IDIQ to purchase approved CLIN products such as NASA SEWP V or ITES-SW2. If not, please describe how products will be purchased. | This solicitation is creating an Multiple Award IDIQ. Task Orders will be placed via the resulting IDIQ. |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .