Skip to content
BidBenchmark
Sources Sought

RFI - DCSA Personnel Security Alert Management (PSAM) Platform

DEFENSE CI AND SECURITY AGENCY · Quantico, Virginia

Response status

Historical record

Sep 22, 2026, 5:00 PM UTC

This notice is no longer open.

Posted
Sep 14, 2026
Archive date
Oct 7, 2026
SAM status
Active
This is a preserved solicitation record. The response window is closed because the published deadline passed.

Answer-first brief

What the source record says

  • DEFENSE CI AND SECURITY AGENCY published this sources sought.
  • The place of performance is Quantico, Virginia.

Procurement identity

Notice ID
8ff0acae872847959a2c12f284e24ecb
Solicitation
DCSAPSAMRFI2026001
Base type
Sources Sought
Version
1 of 1

Solicitation facts

Structured fields from the current SAM notice version. A dash means the source did not publish a value.

Notice type
Sources Sought
Solicitation number
DCSAPSAMRFI2026001
NAICS
—
PSC
—
Set-aside
—
Set-aside code
—
Posted
Sep 14, 2026
Responses due
Sep 22, 2026, 5:00 PM UTC
Archive date
Oct 7, 2026
Archive type
auto15
Base type
Sources Sought
Organization type
OFFICE
Benchmark category
—
Category confidence
—
Category source
—
Last seen
Oct 2, 2026

Buyer and place

Office hierarchy and place of performance as published.

Department
DEPT OF DEFENSE
Department code
—
Subagency
DEFENSE COUNTERINTELLIGENCE AND SECURITY AGENCY (DCSA)
Subagency code
—
Office
DEFENSE CI AND SECURITY AGENCY
Organization path
—
Organization path codes
—
Office address
QUANTICO, VA, 22134, USA
Place of performance
Quantico, Virginia
City code
—
State
Virginia
State code
VA
Postal code
—
Country
—

Points of contact

Contact details from the current notice version.

Notice description

Source text reproduced without an AI summary.

REQUEST FOR INFORMATION (RFI) Personnel Security Alert Management (PSAM) Platform Defense Counterintelligence and Security Agency (DCSA) RFI Reference: DCSA-PSAM-RFI-2026-001 Response Instructions: Due Date: September 22, 2026 @ 1:00pm ET Vendors shall fill out the attached questionnaire and submit it via email to Lindsay Weindruch: lindsay.a.weindruch.civ@mail.mil Disclaimer: This RFI is for informational and planning purposes only. It is not a Request for Proposal, does not commit the Government to any award, and responses are not offers the Government can accept to form a contract. The Government will not pay for information submitted. Do not include classified information in responses; proprietary information will be protected to the extent permitted by law. 1. Purpose DCSA seeks information from Security Information Event Management (SIEM) and Security Operations Center (SOC) platform vendors on commercial capabilities that can support personnel-security operations through cybersecurity event correlation, alert triage, risk-based prioritization, and workflow automation. DCSA is particularly interested in solutions that can identify, correlate, prioritize, and route cybersecurity alerts and incidents associated with members of the trusted workforce for appropriate personnel-security review. 2. Problem Statement DCSA's Continuous Vetting (CV) program faces high daily detection volumes from many sources, much of it low-value noise. Alerts which are drawn from dozens of criminal, financial, terrorism-screening, foreign-contact, foreign-travel, and public-record data sources are still worked largely first-in-first-out rather than by risk, so high-consequence alerts can wait behind routine, low-risk items and case queues have grown faster than staffing. While CV has made progress in detecting potential risk indicators far faster than legacy periodic-reinvestigation models, it is still triaging risk with case-management approaches built for a lower-volume era. 3. Desired Capability DCSA seeks a solution that will incorporate the following capabilities: Ingests and normalizes 40+ structured and unstructured data sources�including APIs, databases, PDFs, and open-source information�into a unified alert stream. Correlates alerts to individual subjects using privacy-preserving tokenization, enabling cross-source analysis without unnecessary exposure of personal data. Applies explainable AI/ML risk scoring aligned with federal adjudicative guidelines�such as financial considerations, criminal conduct, and foreign influence�rather than generic threat categories. Analyst-facing outputs must provide clear rationale (for example, LIME, SHAP, or an equivalent method). Automates low-value alert handling through configurable business rules that suppress duplicates, auto-clear qualifying low-risk alerts, and reduce false positives. Routes alerts through tiered, human-in-the-loop workflows for validation, investigation, and adjudication. The system must prioritize alerts by assessed risk�not age�and immediately escalate critical or high-risk alerts. Supports continuous improvement by feeding adjudicator outcomes back into the rules engine and AI/ML models, subject to appropriate oversight and validation. Integrates with�not replaces�authoritative case-management systems of record through documented, open-standard APIs, including OpenAPI 3.1 and REST. The capability must generate upstream triage signals rather than create a parallel case-management silo. Provides leadership and operational dashboards showing key performance measures, including time to detect, time to respond, false-positive rate, and backlog by priority, with near-real-time visibility into detection, response, and workload status. Avoids vendor lock-in. Proprietary data formats or closed APIs are disqualifying. Can operate in controlled IL5 and classified IL6 environments appropriate for intelligence-derived derogatory information and consistent with Department of War cross-domain security requirements.

Comparable award range

Historical award values for work matched by the fixed rubric—not an estimate of this opportunity.

No past awards scored highly enough to form a comparable range.

Comparable awards

The match score is decomposed so each comparison can be challenged.

No comparable awards are attached to this notice.

Record provenance

Field-level lineage for the current opportunity version.

FieldSourceSource as ofParserTransform
agency_nameSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
archive_dateSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
archive_typeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
base_typeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
city_nameSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
contactsSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
country_codeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
descriptionSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
notice_idSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
notice_typeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
office_citySAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
office_country_codeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
office_nameSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
office_postal_codeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
office_state_codeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
organization_typeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
posted_dateSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
response_deadlineSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
sam_urlSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
solicitation_numberSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
state_codeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
subagency_nameSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
titleSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3
upstream_activeSAM.gov Contract OpportunitiesSep 16, 2026sam_opportunity_snapshot@2026.08.32026.08.3

Sources and method

Figures on this page are computed from public federal award records. Numbers are never estimated or generated; where a figure is withheld, the reason is stated rather than filled in.

  1. 1Notice fields come from the SAM.gov contract opportunities record last seen Oct 2, 2026. SAM.gov remains authoritative.

Note 1 covers the solicitation record. No synthetic FAQ or inferred solicitation value is published.

RFI - DCSA Personnel Security Alert Management (PSAM) Platform — federal contract opportunity · BidBenchmark