Request for Information: Secure Access Service Edge (SASE) Solution

Location: Wisconsin
Posted: Jun 23, 2026
Due: Jul 14, 2026
Agency: State Government of Wisconsin
Type of Government: State & Local
Category:
  • R - Professional, Administrative and Management Support Services
Solicitation No: Request for Information: Secure Access Service Edge (SASE) Solution
Publication URL: To access bid details, please log in.
Solicitation Reference #: Request for Information: Secure Access Service Edge (SASE) Solution
Title: Request for Information: Secure Access Service Edge (SASE) Solution
Available Date: 6/23/2026
Due Date: 7/14/2026 2:00:00 PM
Are faxed Bids acceptable? No
Are e-mailed bids acceptable? No
Bid Synopsis:

Request for Information

Secure Access Service Edge (SASE) Solution

Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned.  Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

Questions are due on June 30, 2026.

Email questions and completed RFI responses to Caleb Hall at caleb.hall@wisc.edu .

Agency Contact: Lori Pulvermacher

Documents:
RFI-SASE
6/23/2026
NIGP Codes
Code Description
20811 Application Software, Microcomputer
20836 Data Processing Software, Microcomputer
92005 Application, Infrastructure, Hosting and Cloud Computing Services
92014 Applications Software (For Minicomputer Systems)
92045 Software Maintenance/Support
Revision History

Attachment Preview

Request for Information

Secure Access Service Edge (SASE) Solution

Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

Questions concerning this RFI should be directed via email to UW Madison Purchasing Manager Caleb Hall .

RFI Issued Date: June 23, 2026

Questions Due: June 30, 2026

RFI Due Date: July 14, 2026 by 2:00 PM CT

Email questions and completed RFI responses to .

Request for Information (RFI): Secure Access Service Edge (SASE)

Project Title: Enterprise Secure Access Service Edge (SASE) Enablement

Request for Information (RFI): Secure Access Service Edge (SASE)

Project Title: Enterprise Secure Access Service Edge (SASE) Enablement

1. Introduction and Purpose

The University of Wisconsin-Madison is soliciting information regarding an enterprise SASE solution supporting federated governance, Zero Trust, and regulated research environments.

2. Scope of Requirements

The university seeks a cloud-native SASE platform delivering integrated networking and security services across users, devices, and applications.

3. Technical and Functional Requirements

A. Administrative Hierarchy and Federated Management

Describe your support for hierarchical or multi-tenant organizational structures.

Describe how global security policies can be enforced as non-overridable by departmental administrators.

Describe delegated administrative roles, scopes, and RBAC granularity.

Describe policy inheritance, conflict resolution, and override behavior.

Describe how logs, configurations, and analytics are isolated across tenants.

Can different departments define policies without seeing each other's apps?

What usage events increase cost Without explicit admin action?

Are new features automatically licensed when enabled?

How does pricing change with temporary population spikes (students, contractors)?

Are logs, analytics, or retention metered separately?

How are Point of Presence (PoPs) or regions priced over time?

What skill sets are required after deployment?

What changes require vendor support or escalation?

Typical troubleshooting workflows (who looks first?)

Mean time to resolution with vendor involvement?

How does your solution help support unmanaged devices?

On endpoint devices does your solution require an agent install? When the user does not have admin access to install anything, how are those devices handled?

B. Core SASE Capabilities

Identify which SASE capabilities are native, integrated, or roadmap.

Describe Secure Web Gateway (SWG) inspection and policy enforcement.

Describe Firewall-as-a-Service (FWaaS) architecture and policy model.

Describe Zero Trust Network Access (ZTNA) capabilities and app-level access controls.

Describe CASB, DLP, DNS Security, IPS, sandboxing, and SSPM features.

Describe management-pane architecture; number of consoles required, single management plane/policy engine, unified data lake and API support for automation and integration with existing IT tooling.

How are policies tested before deployment?

Are policies ordered, evaluated, or merged, and how is conflict resolved?

C. Networking and Connectivity

Describe native SD-WAN functionality and supported transports.

Describe support for remote users, branch sites, campuses, and data centers.

Describe traffic optimization, QoS, and failover behavior.

Describe integration with existing WAN or network infrastructure.

Research often involves multi-terabyte datasets. Does the SASE PoP architecture throttle high-bandwidth, long-lived flows?

Many lab instruments run on legacy Oss (like Windows XP/7) that cannot host agents. Can the solution provide "micro-segmentation at the edge" for these devices without requiring a local gateway?

D. Identity, Access, and Device Context

Describe supported identity providers and authentication standards.

Describe user provisioning and lifecycle management.

Describe device posture assessment and trust signals.

Describe conditional access logic and continuous risk evaluation.

Describe supported access for unmanaged or BYOD endpoints.

Describe support for IoT/OT, lab devices, research instrument networks and nonhuman identities (machine/NHI) including onboarding, inventory, and access controls.

How does your solution enforce identity-based access for nonhuman identities and how policies differ from human accounts.

How do multiple IdPs or tenants coexist?

Can access policies degrade safely instead of failing open or closed?

Describe your integration with SecureW2.

E. Security Policy Controls

Describe application segmentation and least-privilege enforcement.

Describe session-level controls (clipboard, file transfer, printing).

Describe TLS/SSL inspection and certificate handling.

Describe logging, alerting, and SIEM/SOAR integrations.

Describe protections against lateral movement and insider threats.

How is privileged access treated differently from standard users?

F. Availability, Performance, and Scalability

Describe your global PoP architecture and traffic routing model.

What features are GA today vs. GA only for certain regions or PoPs?

Can performance issues be attributed to your PoP vs. the SaaS provider?

What happens when users are far from the nearest PoP (rural, global research)?

Describe SLAs for availability, latency, and packet loss.

Describe resiliency, redundancy, and disaster recovery capabilities.

How are stale sessions handled during identity outages?

Describe visibility into user experience and application performance.

Describe any scale limits, quotas, or licensing constraints.

What features shown in demos are off by default or require premium licensing?

For third-party collaborators using unmanaged devices, provide typical architectures (RBI, secure browser, reverse proxy) and onboarding/credentialing processes suitable for research and teaching collaborators.

How many policy objects are realistically supported before performance degrades?

What forensic data is not available due to architecture?

Ability to reconstruct full user sessions

Role of Vendor during customer security incidents.

G. Compliance, Data Protection, and Accessibility

Describe support for FERPA, HIPAA, NIST 800-171, CUI, and FedRAMP-aligned use cases.

Describe data inspection, encryption, key management, and residency controls.

Describe secure data deletion, retention, and legal hold capabilities.

Describe WCAG 2.1 / Section 508 accessibility conformance and testing.

Explain log routing, retention, and where inspection/logs/data (including DLP matches and UEBA telemetry) are stored; provide options for logical vs physical data separation and sovereign/private SASE deployments.

Can inspection be selectively disabled per app, user, or data classification?

Where exactly does TLS decryption occur - PoP, region, country?

4. Vendor Questionnaire

A. General Information

Provide an overview of your organization, including history and ownership.

Identify primary technical and contractual contacts.

Provide URLs for product documentation, support, and training.

Describe your experience supporting higher education or regulated research environments.

Provide at least three reference customers similar in size or complexity.

Describe your product roadmap for the next three years and your five-year vision.

Describe your release cycle and customer communication approach.

Describe your cloud platform(s), data center locations, and data residency guarantees.

Describe your patching, maintenance, and SLA model.

What is your incident notification timeline?

Who leads incident response- Vendor, customer, or shared?

Can costs be allocated or broken out by user departments?

Are there minimum commitments or sustained-use discounts?

Are there data egress charges?

B. Accessibility

Does your solution conform to WCAG 2.1 (A/AA) and Section 508 requirements?

Has the solution been tested with assistive technologies? If so, which?

Describe your accessibility testing and QA methodology.

How are accessibility regressions prevented during upgrades?

Describe known accessibility limitations and remediation plans.

Describe how accessibility issues are reported and addressed.

5. Submission Instructions

Send a completed response via email by 2:00 p.m. July 14, 2026, to:

Caleb Hall, Purchasing Manager

UW Madison

caleb.hall@.edu

Include in your response:

Executive summary.

Completed responses to Section 3, including references requested in Section 4.A.5.

Architecture diagrams.

Product roadmap for 2026-2027.

Detailed pricing and licensing, including add-ons and higher education discounts.

6. Anticipated Timeline

The anticipated schedule for this RFI process is as follows:

RFI Issued June 23, 2026

Questions Due June 30, 2026

Information Due by July 14, 2026 2:00PM (CDT)

The University reserves the right to modify this schedule.

7. Questions

Questions regarding this RFI should be submitted via email by June 30, 2026, at 2:00 pm (CDT) to:

Caleb Hall, Purchasing Manager

UW Madison

8. Disclaimer

This Request for Information is issued for informational and planning purposes only. It does not constitute a solicitation for proposals and does not obligate the University to issue a subsequent procurement document or enter into any agreement. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

The University reserves the right to:

* Modify or cancel this RFI at any time

* Request additional information from respondents

* Conduct interviews with respondents

* Use information received to structure a future procurement process

The University is not responsible for any costs incurred by respondents in preparing responses to this RFI.

This is the opportunity summary page. It provides an overview of this opportunity and a preview of the attached documentation.
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL
* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.