This document is an amendment to Solicitation No. CORHQ-25-Q-0377, dated September 9, 2025, from the Federal Deposit Insurance Corporation (FDIC) for a renewal requirement. The amendment, effective September 22, 2025, provides government responses to questions received regarding the solicitation. Key responses include confirming the Tenable CID as 77586, clarifying that the requirement is for a renewal, and affirming the necessity of a Tenable Reseller/Partner Agreement, with updated language on SAM.gov. This modification ensures all terms and conditions of the original solicitation remain in effect, with this amendment serving to provide crucial clarifications to potential offerors.
This document is Amendment/Modification 0002 to Solicitation CORHQ-25-Q-0377, issued by the Federal Deposit Insurance Corporation (FDIC) on October 8, 2025. The purpose of this amendment is to update the price schedule, revise Provision 7.3.2-09 General Proposal Instructions and Attachment M-1, and extend the offer due date to October 17, 2025, at noon EST. The solicitation is for Tenable and Rapid7 subscription maintenance for a base year and two one-year option periods, fulfilling FDIC's NIST 800-53 obligations. Offers will be deemed unacceptable if they do not use the specified Price Schedule Workbook, provide Pre-Award SCRM Information, or if the offeror is not an authorized reseller of Tenable and Rapid7. Proposals will be evaluated on a Lowest Price Technically Acceptable (LPTA) basis, requiring compliance with all listed documents, matching part numbers, and proof of authorized reseller status.
This government solicitation from the Federal Deposit Insurance Corporation (FDIC) outlines the requirements for Tenable software subscriptions and maintenance for a base year and two one-year option periods. The software is crucial for the FDIC to meet NIST 800-53 RA-5 and CM-6 standards for host vulnerability detection and baseline compliance, as well as NIST 800-53 CA-8 for vulnerability exploit attempts. The document details the schedule of supplies and services for various Tenable products, including Tenable.sc Console, Tenable Security Center Plus, Metasploit Pro, Nessus Professional, and Premier Support. It specifies delivery to Arlington, VA, and outlines detailed inspection, acceptance, invoicing, and payment procedures, emphasizing electronic fund transfers and strict invoice content requirements. The solicitation also includes critical clauses on post-government employment, commercial supplier agreement terms, off-site processing of FDIC information, basic safeguarding of contractor information systems, and reporting requirements for supply chain events, ensuring compliance, security, and proper contract administration.
The document, NONPUBLIC//FDIC BUSINESS# 7.1.2-03, outlines the Pre-Award Risk Management (SCRM) Information requirements for solicitations, likely within the context of federal government RFPs. It mandates offerors to provide specific details regarding the good/software/service, including solicitation and part numbers, name, model/version, and their status as a manufacturer or supplier. A critical requirement is for offerors to categorize themselves as an Original Equipment Manufacturer (OEM), Aftermarket Manufacturer (AM), or Authorized Supplier, as defined in section 7.1.2-03. Failure to provide this status may lead to ineligibility for award, underscoring the importance of supply chain risk management in the FDIC's procurement process.
The Federal Deposit Insurance Corporation (FDIC) requires subscriptions and maintenance for Tenable and Rapid7 software, critical for meeting NIST 800-53 security controls (RA-5, CM-6, CA-8, CA-8(1), CA-8(2)). This requirement spans a base year (December 21, 2025 – December 20, 2026) and two one-year option periods. The Tenable software provides host vulnerability and baseline compliance detection, while Rapid7 Metasploit assists with vulnerability exploit attempts. The procurement includes various Tenable products such as Tenable.sc Console, Tenable Security Center Plus, Nessus Professional, and Tenable.sc+ for lab use, along with Premier Support. Rapid7's Metasploit Pro User Subscription is also included. The document outlines the price schedules for each period, detailing specific line items, manufacturers, quantities, part numbers, and descriptions of each software component and service, all marked as "NONPUBLIC//FDIC INTERNAL ONLY."
The Federal Deposit Insurance Corporation (FDIC) is seeking a three-year subscription for Tenable and Rapid7 software, encompassing a base year and two one-year option periods. This requirement is crucial for the FDIC to fulfill its obligations under NIST 800-53 RA-5, CM-6, CA-8, CA-8(1), and CA-8(2). The Tenable software provides host vulnerability detection and baseline compliance detection, while Rapid7 Metasploit assists with vulnerability exploit attempts in a controlled and documented manner. The price schedule outlines various subscription and maintenance items for both Tenable and Rapid7 products, including Tenable.sc Console, Tenable Security Center Plus, Metasploit Pro User Subscription, Nessus Professional, Tenable.sc+ for Lab Use, and Premier Support. This procurement aims to ensure the FDIC's continued adherence to essential cybersecurity and risk assessment standards.