Request for Information: Automated Cryptographic Discovery and Inventory (ACDI) Tool
Overview
Buyer
Place of Performance
NAICS
PSC
Set Aside
Original Source
Timeline
Qualification Details
Fit reasons
- NAICS alignment with historical contract wins in similar service areas.
- Scope strongly matches core technical capabilities and delivery model.
Risks
- Past performance thresholds may require one additional teaming partner.
- Potential clarification needed on staffing minimums before bid/no-bid.
Next steps
Validate eligibility requirements, assign capture owner, and schedule partner outreach to confirm teaming strategy before submission planning.
Quick Summary
The U.S. Department of Health and Human Services (HHS), Office of the Chief Information Officer (OCIO), Office of Information Security (OIS), has issued a Request for Information (RFI) for Automated Cryptographic Discovery and Inventory (ACDI) Tool solutions. This RFI is for market research and planning purposes only, seeking information on commercial or commercially available ACDI solutions to support enterprise cryptographic discovery and inventory management, and to gather feedback on the Statement of Objectives (SOO). Responses are due June 5, 2026, at 12:00 PM ET.
Purpose & Context
HHS aims to procure an ACDI capability to address the growing threat from quantum computing to existing cryptographic systems and to support its transition to Post-Quantum Cryptography (PQC), aligning with federal mandates (NSM-10, OMB M-23-02). This effort is part of a broader government strategy, as outlined by CISA, for migrating to automated PQC discovery and inventory tools across Federal Civilian Executive Branch (FCEB) agencies.
Scope of Interest (from SOO)
HHS is interested in solutions that provide:
- Automated Discovery: Identify cryptographic implementations across on-premises, cloud, applications, networks, and data-at-rest environments using active scanning and passive monitoring.
- Cryptographic Identification: Pinpoint algorithms (symmetric, asymmetric, hash), protocols, certificates, key lengths, and hybrid cryptography instances.
- Inventory Management: Maintain a centralized repository with system details, tagging, deduplication, and historical tracking.
- Risk Assessment & Prioritization: Identify deprecated, weak, non-compliant, or quantum-vulnerable cryptography, providing contextual risk analysis and supporting remediation prioritization.
- Continuous Monitoring & Reporting: Offer continuous or periodic discovery, detect changes, alert on new assets, and provide comprehensive dashboards and reports on inventory, vulnerabilities, and compliance.
- Technical Requirements: Solutions should support scalable architecture, distributed scanning, agent-based and agentless discovery, integration with enterprise systems (CMDB, SIEM), role-based access control (RBAC), Single Sign-On (SSO), and have a path to ATO/FedRAMP High authorization.
Contract Details (Anticipated)
While this is an RFI, the Statement of Objectives indicates an anticipated Firm-Fixed-Price (FFP) contract with a 12-month base period and four (4) 12-month option years.
- Set-Aside: None specified.
Submission & Deadlines
- Questions Due: June 1, 2026, at 12:00 PM ET. Submit in writing via email to Jordan Neal (jordan.neal@hhs.gov) and Julie Rodriguez (julie.rodriguez@hhs.gov).
- Responses Due: June 5, 2026, at 12:00 PM ET. Submit a capability statement or white paper via email to Jordan Neal (jordan.neal@hhs.gov) and Julie Rodriguez (julie.rodriguez@hhs.gov).
- Submission Format: Include the solicitation number and company name in the email subject line. Clearly mark any proprietary information.
Additional Notes
This RFI is for planning and market research only and does not commit the Government to issue a solicitation or award a contract. All information submitted is voluntary.