| Agency: | State Government of Wisconsin |
|---|---|
| State: | Wisconsin |
| Type of Government: | State & Local |
| NAICS Category: |
|
| Posted Date: | Jun 23, 2026 |
| Due Date: | Jul 14, 2026 |
| Solicitation No: | Request for Information: Secure Access Service Edge (SASE) Solution |
| Original Source: | Please Login to View Page |
| Contact information: | Please Login to View Page |
| Bid Documents: | Please Login to View Page |
| Solicitation Reference #: | Request for Information: Secure Access Service Edge (SASE) Solution | |
| Title: | Request for Information: Secure Access Service Edge (SASE) Solution | |
| Available Date: | 6/23/2026 | |
| Due Date: | 7/14/2026 2:00:00 PM | |
| Are faxed Bids acceptable? | No | |
| Are e-mailed bids acceptable? | No | |
| Bid Synopsis: |
Request for Information Secure Access Service Edge (SASE) Solution Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract. Questions are due on June 30, 2026. Email questions and completed RFI responses to Caleb Hall at caleb.hall@wisc.edu . |
|
| Agency Contact: |
Lori Pulvermacher
|
|
| Documents: |
|
Request for Information
Secure Access Service Edge (SASE) Solution
Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.
Questions concerning this RFI should be directed via email to UW Madison Purchasing Manager Caleb Hall .
RFI Issued Date: June 23, 2026
Questions Due: June 30, 2026
RFI Due Date: July 14, 2026 by 2:00 PM CT
Email questions and completed RFI responses to .
Request for Information (RFI): Secure Access Service Edge (SASE)
Project Title: Enterprise Secure Access Service Edge (SASE) Enablement
Request for Information (RFI): Secure Access Service Edge (SASE)
Project Title: Enterprise Secure Access Service Edge (SASE) Enablement
1. Introduction and Purpose
The University of Wisconsin-Madison is soliciting information regarding an enterprise SASE solution supporting federated governance, Zero Trust, and regulated research environments.
2. Scope of Requirements
The university seeks a cloud-native SASE platform delivering integrated networking and security services across users, devices, and applications.
3. Technical and Functional Requirements
A. Administrative Hierarchy and Federated Management
Describe your support for hierarchical or multi-tenant organizational structures.
Describe how global security policies can be enforced as non-overridable by departmental administrators.
Describe delegated administrative roles, scopes, and RBAC granularity.
Describe policy inheritance, conflict resolution, and override behavior.
Describe how logs, configurations, and analytics are isolated across tenants.
Can different departments define policies without seeing each other's apps?
What usage events increase cost Without explicit admin action?
Are new features automatically licensed when enabled?
How does pricing change with temporary population spikes (students, contractors)?
Are logs, analytics, or retention metered separately?
How are Point of Presence (PoPs) or regions priced over time?
What skill sets are required after deployment?
What changes require vendor support or escalation?
Typical troubleshooting workflows (who looks first?)
Mean time to resolution with vendor involvement?
How does your solution help support unmanaged devices?
On endpoint devices does your solution require an agent install? When the user does not have admin access to install anything, how are those devices handled?
B. Core SASE Capabilities
Identify which SASE capabilities are native, integrated, or roadmap.
Describe Secure Web Gateway (SWG) inspection and policy enforcement.
Describe Firewall-as-a-Service (FWaaS) architecture and policy model.
Describe Zero Trust Network Access (ZTNA) capabilities and app-level access controls.
Describe CASB, DLP, DNS Security, IPS, sandboxing, and SSPM features.
Describe management-pane architecture; number of consoles required, single management plane/policy engine, unified data lake and API support for automation and integration with existing IT tooling.
How are policies tested before deployment?
Are policies ordered, evaluated, or merged, and how is conflict resolved?
C. Networking and Connectivity
Describe native SD-WAN functionality and supported transports.
Describe support for remote users, branch sites, campuses, and data centers.
Describe traffic optimization, QoS, and failover behavior.
Describe integration with existing WAN or network infrastructure.
Research often involves multi-terabyte datasets. Does the SASE PoP architecture throttle high-bandwidth, long-lived flows?
Many lab instruments run on legacy Oss (like Windows XP/7) that cannot host agents. Can the solution provide "micro-segmentation at the edge" for these devices without requiring a local gateway?
D. Identity, Access, and Device Context
Describe supported identity providers and authentication standards.
Describe user provisioning and lifecycle management.
Describe device posture assessment and trust signals.
Describe conditional access logic and continuous risk evaluation.
Describe supported access for unmanaged or BYOD endpoints.
Describe support for IoT/OT, lab devices, research instrument networks and nonhuman identities (machine/NHI) including onboarding, inventory, and access controls.
How does your solution enforce identity-based access for nonhuman identities and how policies differ from human accounts.
How do multiple IdPs or tenants coexist?
Can access policies degrade safely instead of failing open or closed?
Describe your integration with SecureW2.
E. Security Policy Controls
Describe application segmentation and least-privilege enforcement.
Describe session-level controls (clipboard, file transfer, printing).
Describe TLS/SSL inspection and certificate handling.
Describe logging, alerting, and SIEM/SOAR integrations.
Describe protections against lateral movement and insider threats.
How is privileged access treated differently from standard users?
F. Availability, Performance, and Scalability
Describe your global PoP architecture and traffic routing model.
What features are GA today vs. GA only for certain regions or PoPs?
Can performance issues be attributed to your PoP vs. the SaaS provider?
What happens when users are far from the nearest PoP (rural, global research)?
Describe SLAs for availability, latency, and packet loss.
Describe resiliency, redundancy, and disaster recovery capabilities.
How are stale sessions handled during identity outages?
Describe visibility into user experience and application performance.
Describe any scale limits, quotas, or licensing constraints.
What features shown in demos are off by default or require premium licensing?
For third-party collaborators using unmanaged devices, provide typical architectures (RBI, secure browser, reverse proxy) and onboarding/credentialing processes suitable for research and teaching collaborators.
How many policy objects are realistically supported before performance degrades?
What forensic data is not available due to architecture?
Ability to reconstruct full user sessions
Role of Vendor during customer security incidents.
G. Compliance, Data Protection, and Accessibility
Describe support for FERPA, HIPAA, NIST 800-171, CUI, and FedRAMP-aligned use cases.
Describe data inspection, encryption, key management, and residency controls.
Describe secure data deletion, retention, and legal hold capabilities.
Describe WCAG 2.1 / Section 508 accessibility conformance and testing.
Explain log routing, retention, and where inspection/logs/data (including DLP matches and UEBA telemetry) are stored; provide options for logical vs physical data separation and sovereign/private SASE deployments.
Can inspection be selectively disabled per app, user, or data classification?
Where exactly does TLS decryption occur - PoP, region, country?
4. Vendor Questionnaire
A. General Information
Provide an overview of your organization, including history and ownership.
Identify primary technical and contractual contacts.
Provide URLs for product documentation, support, and training.
Describe your experience supporting higher education or regulated research environments.
Provide at least three reference customers similar in size or complexity.
Describe your product roadmap for the next three years and your five-year vision.
Describe your release cycle and customer communication approach.
Describe your cloud platform(s), data center locations, and data residency guarantees.
Describe your patching, maintenance, and SLA model.
What is your incident notification timeline?
Who leads incident response- Vendor, customer, or shared?
Can costs be allocated or broken out by user departments?
Are there minimum commitments or sustained-use discounts?
Are there data egress charges?
B. Accessibility
Does your solution conform to WCAG 2.1 (A/AA) and Section 508 requirements?
Has the solution been tested with assistive technologies? If so, which?
Describe your accessibility testing and QA methodology.
How are accessibility regressions prevented during upgrades?
Describe known accessibility limitations and remediation plans.
Describe how accessibility issues are reported and addressed.
5. Submission Instructions
Send a completed response via email by 2:00 p.m. July 14, 2026, to:
Caleb Hall, Purchasing Manager
UW Madison
caleb.hall@.edu
Include in your response:
Executive summary.
Completed responses to Section 3, including references requested in Section 4.A.5.
Architecture diagrams.
Product roadmap for 2026-2027.
Detailed pricing and licensing, including add-ons and higher education discounts.
6. Anticipated Timeline
The anticipated schedule for this RFI process is as follows:
RFI Issued June 23, 2026
Questions Due June 30, 2026
Information Due by July 14, 2026 2:00PM (CDT)
The University reserves the right to modify this schedule.
7. Questions
Questions regarding this RFI should be submitted via email by June 30, 2026, at 2:00 pm (CDT) to:
Caleb Hall, Purchasing Manager
UW Madison
8. Disclaimer
This Request for Information is issued for informational and planning purposes only. It does not constitute a solicitation for proposals and does not obligate the University to issue a subsequent procurement document or enter into any agreement. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.
The University reserves the right to:
* Modify or cancel this RFI at any time
* Request additional information from respondents
* Conduct interviews with respondents
* Use information received to structure a future procurement process
The University is not responsible for any costs incurred by respondents in preparing responses to this RFI.
With Free Trial, you can:
You will have a full access to bids, website, and receive daily bid report via email and web.
Solicitation Reference #: OO Title: Marketing and Talent Attraction Services - "Onboard to
State Government of Wisconsin
Bid Due: 8/21/2026
Project: RFP 1172-Implementation Support for Enrollment Standards, Student Assignment and Balancing, and Class
Milwaukee Public Schools
Bid Due: 8/18/2026
Project: Countywide Audit Services and Agreed Upon Procedures Ref. #: RFP-2026-001 Type: RFP
Milwaukee County
Bid Due: 8/07/2026
2026-48 Sepak Takrow Sport Court Construction Bids due 7/30/2026 at 2:00pm CT. Bid
City of Eau Claire
Bid Due: 7/30/2026