Request for Information: Secure Access Service Edge (SASE) Solution

Agency: State Government of Wisconsin
State: Wisconsin
Type of Government: State & Local
NAICS Category:
  • 541511 - Custom Computer Programming Services
  • 541512 - Computer Systems Design Services
  • 541519 - Other Computer Related Services
Posted Date: Jun 23, 2026
Due Date: Jul 14, 2026
Solicitation No: Request for Information: Secure Access Service Edge (SASE) Solution
Original Source: Please Login to View Page
Contact information: Please Login to View Page
Bid Documents: Please Login to View Page
Solicitation Reference #: Request for Information: Secure Access Service Edge (SASE) Solution
Title: Request for Information: Secure Access Service Edge (SASE) Solution
Available Date: 6/23/2026
Due Date: 7/14/2026 2:00:00 PM
Are faxed Bids acceptable? No
Are e-mailed bids acceptable? No
Bid Synopsis:

Request for Information

Secure Access Service Edge (SASE) Solution

Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned.  Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

Questions are due on June 30, 2026.

Email questions and completed RFI responses to Caleb Hall at caleb.hall@wisc.edu .

Agency Contact: Lori Pulvermacher

Documents:
RFI-SASE
6/23/2026
NIGP Codes
Code Description
20811 Application Software, Microcomputer
20836 Data Processing Software, Microcomputer
92005 Application, Infrastructure, Hosting and Cloud Computing Services
92014 Applications Software (For Minicomputer Systems)
92045 Software Maintenance/Support
Revision History

Attachment Preview

Request for Information

Secure Access Service Edge (SASE) Solution

Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

Questions concerning this RFI should be directed via email to UW Madison Purchasing Manager Caleb Hall .

RFI Issued Date: June 23, 2026

Questions Due: June 30, 2026

RFI Due Date: July 14, 2026 by 2:00 PM CT

Email questions and completed RFI responses to .

Request for Information (RFI): Secure Access Service Edge (SASE)

Project Title: Enterprise Secure Access Service Edge (SASE) Enablement

Request for Information (RFI): Secure Access Service Edge (SASE)

Project Title: Enterprise Secure Access Service Edge (SASE) Enablement

1. Introduction and Purpose

The University of Wisconsin-Madison is soliciting information regarding an enterprise SASE solution supporting federated governance, Zero Trust, and regulated research environments.

2. Scope of Requirements

The university seeks a cloud-native SASE platform delivering integrated networking and security services across users, devices, and applications.

3. Technical and Functional Requirements

A. Administrative Hierarchy and Federated Management

Describe your support for hierarchical or multi-tenant organizational structures.

Describe how global security policies can be enforced as non-overridable by departmental administrators.

Describe delegated administrative roles, scopes, and RBAC granularity.

Describe policy inheritance, conflict resolution, and override behavior.

Describe how logs, configurations, and analytics are isolated across tenants.

Can different departments define policies without seeing each other's apps?

What usage events increase cost Without explicit admin action?

Are new features automatically licensed when enabled?

How does pricing change with temporary population spikes (students, contractors)?

Are logs, analytics, or retention metered separately?

How are Point of Presence (PoPs) or regions priced over time?

What skill sets are required after deployment?

What changes require vendor support or escalation?

Typical troubleshooting workflows (who looks first?)

Mean time to resolution with vendor involvement?

How does your solution help support unmanaged devices?

On endpoint devices does your solution require an agent install? When the user does not have admin access to install anything, how are those devices handled?

B. Core SASE Capabilities

Identify which SASE capabilities are native, integrated, or roadmap.

Describe Secure Web Gateway (SWG) inspection and policy enforcement.

Describe Firewall-as-a-Service (FWaaS) architecture and policy model.

Describe Zero Trust Network Access (ZTNA) capabilities and app-level access controls.

Describe CASB, DLP, DNS Security, IPS, sandboxing, and SSPM features.

Describe management-pane architecture; number of consoles required, single management plane/policy engine, unified data lake and API support for automation and integration with existing IT tooling.

How are policies tested before deployment?

Are policies ordered, evaluated, or merged, and how is conflict resolved?

C. Networking and Connectivity

Describe native SD-WAN functionality and supported transports.

Describe support for remote users, branch sites, campuses, and data centers.

Describe traffic optimization, QoS, and failover behavior.

Describe integration with existing WAN or network infrastructure.

Research often involves multi-terabyte datasets. Does the SASE PoP architecture throttle high-bandwidth, long-lived flows?

Many lab instruments run on legacy Oss (like Windows XP/7) that cannot host agents. Can the solution provide "micro-segmentation at the edge" for these devices without requiring a local gateway?

D. Identity, Access, and Device Context

Describe supported identity providers and authentication standards.

Describe user provisioning and lifecycle management.

Describe device posture assessment and trust signals.

Describe conditional access logic and continuous risk evaluation.

Describe supported access for unmanaged or BYOD endpoints.

Describe support for IoT/OT, lab devices, research instrument networks and nonhuman identities (machine/NHI) including onboarding, inventory, and access controls.

How does your solution enforce identity-based access for nonhuman identities and how policies differ from human accounts.

How do multiple IdPs or tenants coexist?

Can access policies degrade safely instead of failing open or closed?

Describe your integration with SecureW2.

E. Security Policy Controls

Describe application segmentation and least-privilege enforcement.

Describe session-level controls (clipboard, file transfer, printing).

Describe TLS/SSL inspection and certificate handling.

Describe logging, alerting, and SIEM/SOAR integrations.

Describe protections against lateral movement and insider threats.

How is privileged access treated differently from standard users?

F. Availability, Performance, and Scalability

Describe your global PoP architecture and traffic routing model.

What features are GA today vs. GA only for certain regions or PoPs?

Can performance issues be attributed to your PoP vs. the SaaS provider?

What happens when users are far from the nearest PoP (rural, global research)?

Describe SLAs for availability, latency, and packet loss.

Describe resiliency, redundancy, and disaster recovery capabilities.

How are stale sessions handled during identity outages?

Describe visibility into user experience and application performance.

Describe any scale limits, quotas, or licensing constraints.

What features shown in demos are off by default or require premium licensing?

For third-party collaborators using unmanaged devices, provide typical architectures (RBI, secure browser, reverse proxy) and onboarding/credentialing processes suitable for research and teaching collaborators.

How many policy objects are realistically supported before performance degrades?

What forensic data is not available due to architecture?

Ability to reconstruct full user sessions

Role of Vendor during customer security incidents.

G. Compliance, Data Protection, and Accessibility

Describe support for FERPA, HIPAA, NIST 800-171, CUI, and FedRAMP-aligned use cases.

Describe data inspection, encryption, key management, and residency controls.

Describe secure data deletion, retention, and legal hold capabilities.

Describe WCAG 2.1 / Section 508 accessibility conformance and testing.

Explain log routing, retention, and where inspection/logs/data (including DLP matches and UEBA telemetry) are stored; provide options for logical vs physical data separation and sovereign/private SASE deployments.

Can inspection be selectively disabled per app, user, or data classification?

Where exactly does TLS decryption occur - PoP, region, country?

4. Vendor Questionnaire

A. General Information

Provide an overview of your organization, including history and ownership.

Identify primary technical and contractual contacts.

Provide URLs for product documentation, support, and training.

Describe your experience supporting higher education or regulated research environments.

Provide at least three reference customers similar in size or complexity.

Describe your product roadmap for the next three years and your five-year vision.

Describe your release cycle and customer communication approach.

Describe your cloud platform(s), data center locations, and data residency guarantees.

Describe your patching, maintenance, and SLA model.

What is your incident notification timeline?

Who leads incident response- Vendor, customer, or shared?

Can costs be allocated or broken out by user departments?

Are there minimum commitments or sustained-use discounts?

Are there data egress charges?

B. Accessibility

Does your solution conform to WCAG 2.1 (A/AA) and Section 508 requirements?

Has the solution been tested with assistive technologies? If so, which?

Describe your accessibility testing and QA methodology.

How are accessibility regressions prevented during upgrades?

Describe known accessibility limitations and remediation plans.

Describe how accessibility issues are reported and addressed.

5. Submission Instructions

Send a completed response via email by 2:00 p.m. July 14, 2026, to:

Caleb Hall, Purchasing Manager

UW Madison

caleb.hall@.edu

Include in your response:

Executive summary.

Completed responses to Section 3, including references requested in Section 4.A.5.

Architecture diagrams.

Product roadmap for 2026-2027.

Detailed pricing and licensing, including add-ons and higher education discounts.

6. Anticipated Timeline

The anticipated schedule for this RFI process is as follows:

RFI Issued June 23, 2026

Questions Due June 30, 2026

Information Due by July 14, 2026 2:00PM (CDT)

The University reserves the right to modify this schedule.

7. Questions

Questions regarding this RFI should be submitted via email by June 30, 2026, at 2:00 pm (CDT) to:

Caleb Hall, Purchasing Manager

UW Madison

8. Disclaimer

This Request for Information is issued for informational and planning purposes only. It does not constitute a solicitation for proposals and does not obligate the University to issue a subsequent procurement document or enter into any agreement. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

The University reserves the right to:

* Modify or cancel this RFI at any time

* Request additional information from respondents

* Conduct interviews with respondents

* Use information received to structure a future procurement process

The University is not responsible for any costs incurred by respondents in preparing responses to this RFI.

This page summarizes the opportunity, including an overview and a preview of the attached documents.
* Disclaimer: This website provides information about bids, requests for proposals (RFPs), or requests for qualifications (RFQs) for convenience only and does not serve as an official public notice. Individuals who wish to respond to or inquire about bids, RFPs, or RFQs should contact the relevant government department directly.

Sign-up for a Free Trial, Government Bid Alerts

With Free Trial, you can:

You will have a full access to bids, website, and receive daily bid report via email and web.

Try One Week FREE Now

See Also

Solicitation Reference #: OO Title: Marketing and Talent Attraction Services - "Onboard to

State Government of Wisconsin

Bid Due: 8/21/2026

Project: RFP 1172-Implementation Support for Enrollment Standards, Student Assignment and Balancing, and Class

Milwaukee Public Schools

Bid Due: 8/18/2026

Project: Countywide Audit Services and Agreed Upon Procedures Ref. #: RFP-2026-001 Type: RFP

Milwaukee County

Bid Due: 8/07/2026

2026-48 Sepak Takrow Sport Court Construction Bids due 7/30/2026 at 2:00pm CT. Bid

City of Eau Claire

Bid Due: 7/30/2026