The Cybersecurity Supply Chain Risk Management (C-SCRM) Questionnaire is a critical document for vendors engaging with government entities, particularly in the context of federal RFPs, grants, and state/local RFPs. Its primary purpose is to assess a vendor's cybersecurity posture and their ability to manage supply chain risks. The questionnaire is divided into three sections: Contact Information, Vendor Risk Management Plan, and Physical and Personnel Security. Vendors are required to provide details about their company's primary point of contact and then address questions related to their organization's strategies for identifying and mapping supply chain threats, implementing written SCRM requirements with key suppliers, and verifying compliance through contractual terms. Additionally, the questionnaire delves into physical and personnel security, inquiring about policies for background checks, procedures to prevent tampering of ICT equipment, and literacy training for recognizing insider threats. Adherence to NIST SP 800-53 references is also indicated for various items. The instructions emphasize that the offering entity, or its managing partner in the case of a joint venture, must complete the questionnaire, and the government may request documentation to validate responses.
The US Embassy in Ljubljana, Slovenia, requires contractors to certify compliance with Section 889(a)(1)(B) of the National Defense Authorization Act (NDAA), which prohibits the use of covered telecommunications equipment or services from entities like Huawei, ZTE, Hytera, Hangzhou, and Dahua. Contractors must disclose if they use such equipment, provide details, and confirm willingness to remove it by 2022 and provide a detailed list. The document also includes FAR clauses 52.204-24 and 52.204-26, outlining prohibitions on procuring or using covered telecommunications equipment and services, and requiring offerors to make representations regarding their use of such equipment. Contractors must check the System for Award Management (SAM) for excluded parties and provide detailed disclosures if they use or will provide covered equipment or services to the Government.
The U.S. Embassy in Ljubljana, Slovenia, issued Request for Quotations (RFQ) number 19S16026Q0003 for mobile telephone services. The contract, commencing March 1, 2026, for one year with a one-year option, requires the contractor to provide comprehensive mobile services for 117 lines, including voice and data packages, international calling/roaming, SMS/MMS, voicemail, and 24-hour customer service. Key requirements include high network quality, provision of SIM/eSIM cards, and detailed monthly billing. Proposals are due by January 12, 2026, 10:00 AM local time, and must be submitted electronically to LjubljanaQuotes@state.gov in specified formats (MS-Word, MS-Excel, or Adobe Acrobat) with a file size limit of 30MB. Quoters must also complete and submit SF-1449, pricing, representations and certifications, a Cybersecurity Supply Chain Risk Management (C-SCRM) Questionnaire, and a Contractor Certification for NDAA Covered Telecommunications Equipment. The U.S. Government intends to award a contract based on comparative evaluation, not solely on low price. Registration in the SAM database is highly encouraged.