The FDIC is seeking a single‑award, firm‑fixed‑price contract to provide a comprehensive Software Supply Chain Security Solution. The contractor must deliver hardened, FedRAMP‑moderate compliant container images, continuous vulnerability monitoring, SBOMs, provenance documentation, and an enterprise‑grade management portal with AD/Azure Entra ID integration. Professional services are required for integration with the FDIC’s JFROG pipeline, security‑control support, and training. The base period runs from 6 Jan 2027 to 5 Jan 2028 with four optional one‑year extensions through Jan 2032. Proposals are due 1 p.m. Oct 9 2026; questions must be submitted by 12 p.m. Oct 2 2026. Evaluation will be best‑value, emphasizing mandatory technical requirements, professional services, and price.
• Provide a catalog of secure, hardened container images (multi‑arch, minimal base)
• Continuous daily vulnerability scanning, 48‑hour zero‑day patching, SLA‑based CVE remediation (7‑14‑30 days)
• Deliver SBOMs, signed attestations, and provenance metadata (SPDX/CycloneDX)
• Management portal with SSO (AD/Azure Entra), RBAC, CLI/API access, notifications, and JFROG integration
• Professional services: technical integration, security‑control specialist, training, and pilot support
• Licensing for up to 50 images, optional extended‑life support, self‑service custom image builds
• Option periods for additional years of image supply and maintenance