← Active opportunities
Sources Sought

DOJ Software as a Service (SaaS) log management / Security Information and Event Management (SIEM) solution

JUSTICE, DEPARTMENT OF · OFFICES, BOARDS AND DIVISIONS · OFFICE OF ACQUISITION MANAGEMENT

Amended
Response deadlineSep 5, 2026
PostedAug 27, 2026
Archive dateSep 19, 2026
SolicitationDOJRFI-1
Notice ID5127cae408464a2aaac8319b22ae91ce
Notice typeSources Sought
Set-aside
Place of performanceWashington, DC
Public-source intelligence

Source-backed opportunity brief

7 citations · 5 sources

Contract Vehicles and Commercial Availability Identify any existing Government contract vehicles through which the required software licenses and/or services are available, including, as applicable, GSA Multiple Award Schedule (MAS), Government-Wide Acquisition Contracts (GWACs), Indefinite-Delivery/Indefinite-Quantity (IDIQ) contracts, agency-specific contract vehicles, or other Government-wide or agency contract vehicles.

Scope

Scope: Generic and Solution-Specific Objectives and Tasks • The Vendor shall provide a configurable log management / SIEM solution that meets DOJ’s operational and M-26-14 requirements, detailed below. • The Vendor shall provide professional services to provide insight into the solution management, recommendations, and consulting on the migration on the DOJ’s current, on-prem solution to the Vendor’s Software as a Service (SaaS) solution. • The offered single-vendor solution provided must be a cloud-based SaaS service, and it is required to have a categorization of High FedRAMP Authorization to Operate (ATO). • Given the sensitive nature of the data, encryption of data at rest and in transit is required to meet Department and Federal data encryption policies and requirements. • The Vendor shall provide technical documentation for the configuration and general support for the system. • The Vendor shall offer single-vendor solution training courses necessary for administration and management of the service/solution. • The Vendor provides user friendly task and workflow automation in support of implementing automation of security operations.

Deliverables

Search Performance • The vendor log management system search performance must be capable of searching through millions of structured (indexed) and unstructured (raw) log messages in less than a minute without impacting other scheduled searches or user experience. o Deliver fast search and analytics performance, including real-time alerts. • The vendor shall provide a query performance service level agreement.

Evaluation

Accreditation / Security — RTM ID SEC-003 Question 21: "The vendor shall describe how the proposed SaaS SIEM solution aligns with FedRAMP 20x initiative…" Can DOJ identify the specific FedRAMP 20x objectives, success criteria, or evaluation factors that will be used to assess vendor responses to this requirement?

Extracted from the official notice and archived solicitation files. Confirm controlling requirements in the source documents.

Official notice text

See attached RFI document.

What changed

Aug 27, 2026 · 3 fields changed
Response deadline2026-08-29T03:59:00+00:002026-09-05T03:59:00+00:00
Archive date2026-09-122026-09-19
Documents12

Notice history

Attachments

Select a filename to open the source file. If a saved copy is not available yet, FedRoster will continue to the official notice.