FA830726RB019 - SBOM Vulnerability Scanning RFI
Sources Sought from DEPT OF THE AIR FORCE • DEPT OF DEFENSE. Place of performance: TX. Response deadline: Feb 19, 2026. Industry: NAICS 541519 • PSC 7A20.
Market snapshot
Awarded-market signal for NAICS 541519 (last 12 months), benchmarked to sector 54.
Related hubs & trends
Navigate the lattice: hubs for browsing, trends for pricing signals.
Point of Contact
Agency & Office
More in NAICS 541519
Description
This Request for Information (RFI) is issued in accordance with the Federal Acquisition Regulation (FAR) clause 52.215-3 (Request for Information or Solicitation for Planning Purposes - Oct 1997) and is published to obtain information for use by the Air Force Lifecycle Management Center (AFLCMC), Cryptologic and Cyber Systems Division (CCSD), Joint Base San Antonio - Lackland, Texas, for market research and planning purposes only.
THIS RFI IS NOT A REQUEST FOR PROPOSAL, INVITATION FOR BID, OR AN ANNOUNCEMENT OF A SOLICITATION; IT IS ONLY INTENDED FOR INFORMATION OR PLANNING PURPOSES. There is no bid package or solicitation document associated with this announcement. Response to this RFI is strictly voluntary and will not affect any potential offeror's ability to submit an offer if a solicitation is released. Any requests for a solicitation package will be disregarded. The government does not intend to award a contract on the basis of this RFI or otherwise pay for the information solicited. No entitlement to payment of direct or indirect costs or charges by the government will arise as a result of preparing submissions in response to this RFI and the government's use of such information. Submittals will not be returned to the sender. Respondents to this RFI may be asked to provide additional information/details based on their initial submittals.
GENERAL SCOPE
The government is seeking sources who can provide software licenses with capabilities that meet the requirements of the attached “Draft” Statement of Work (SOW) for Software Bill of Materials (SBOM) Generation & Vulnerability Analysis Solution. All feedback and information received may be used to determine the appropriate acquisition strategy.
PERFORMANCE REQUIREMENTS
The contractor shall:
Provide a base one-year software license plus four (4) One-Year Option Periods.
PRODUCT
The proposed product must be a commercial license that meets the requirements of the Draft Statement of Work attached herein.
DELIVERY
Period of Performance:
Base: 1 Aug 2026 -31 July 2027
Option Year 1: 1 Aug 2027 -31 July 2028
Option Year 2: 1 Aug 2028 -31 July 2029
Option Year 3: 1 Aug 2029 -31 July 2030
Option Year 4: 1 Aug 2030 -31 July 2031
The government requests White Paper responses:
- Company information to include UEI, CAGE Code, Contract Vehicles, POC
- Potential software solution(s) that could meet the government requirements
- Brief Narrative of how software solutions meets the requirements.
- Limit responses to 2 pages, 1-inch margins, 12-point Times New Roman font.
- Submit responses to aflcmc.hncx.p1licensemanagement@us.af.mil & aflcmc.hnckp.platformonectr@us.af.mil by February 20, 2026.
Files
Files size/type shown when available.
BidPulsar Analysis
A practical, capture-style breakdown of fit, requirements, risks, and next steps.
The Department of the Air Force is seeking sources through a Request for Information (RFI) for software licenses related to Software Bill of Materials (SBOM) Vulnerability Scanning. This initiative, under solicitation number FA830726RB019, requests responses by February 19, 2026, to inform future acquisition strategies. It is essential for participating companies to provide capabilities that meet the attached Draft Statement of Work (SOW).
The buyer aims to gather market insights and capabilities for software solutions that can generate Software Bills of Materials and perform vulnerability analysis, in order to develop future procurement strategies for a software licensing contract.
- Review Draft Statement of Work for software requirements.
- Assess current software solutions that meet SBOM generation and vulnerability scanning requirements.
- Prepare a White Paper response including company information and software details.
- Company information including UEI and CAGE Code.
- Overview of relevant contract vehicles.
- Description of potential software solutions.
- Brief narrative on how the solutions meet requirements.
Source coverage notes
Some notices publish limited source detail. Confirm these points before final bid/no-bid decisions.
- No details on specific features required in the SOW outside of SBOM and vulnerability analysis specifics.
FAQ
How do I use the Market Snapshot?
It summarizes awarded-contract behavior for the opportunity’s NAICS and sector, including a recent pricing band (P10–P90), momentum, and composition. Use it as context, not a guarantee.
Is the data live?
The signal updates as new awarded notices enter the system. Always validate the official award and solicitation details on SAM.gov.
What do P10 and P90 mean?
P10 is the 10th percentile award size and P90 is the 90th percentile. Together they describe the typical spread of award values.