ICE IT shop looks to build ‘agentic software factory’

ICE has issued an RFI for an "agentic software factory" to expand the STELLA platform using AI agents for large parts of the software lifecycle; vendors must offer AI application development, workforce training, continuous monitoring, and technology evaluation services, and responses are due…

Cabrillo Club

Cabrillo Club

Editorial Team · September 30, 2026 · 4 min read

Share:LinkedInX

Cabrillo Club Insights

ICE IT shop looks to build ‘agentic software factory’

Overview

ICE (Immigration and Customs Enforcement) has issued an RFI seeking an "agentic software factory" that uses AI agents to perform substantial portions of the software development lifecycle and will expand the agency’s STELLA platform. The RFI requests vendor support across AI application development, workforce training, continuous monitoring, and technology evaluation services, and responses are due October 16, 2024. ICE is explicitly asking for ways to distinguish genuine vendor capabilities from generative-AI-produced proposals, so proposers must prepare proof of provenance and human-in-the-loop controls. This opportunity affects IT Services and AI-focused firms with relevant NAICS capabilities and touches compliance surfaces listed for the event (NIST 800-171 (NIST Special Publication 800-171), FedRAMP (Federal Risk and Authorization Management Program)). Action is needed now to assemble capability evidence, map compliance posture, and prepare bid materials that demonstrate accountable, auditable development and oversight practices. See the Winning Federal Contracts Guide (/insights/winning-federal-contracts) for capture basics.

Immediate Actions (This Week)

  • [ ] Monitor for the official solicitation and any updates to the RFI on SAM.gov (System for Award Management) and ICE procurement pages; calendar the response due date (October 16, 2024) and set internal milestones.
  • [ ] Assemble an evidence pack that demonstrates real-world, human-supervised software development: code repositories, commit histories, CI/CD logs, human approval gates, test artifacts, and past performance narratives showing AI augmentation vs. full automation.
  • [ ] Inventory internal capabilities against the event’s scope (AI application development, workforce training, continuous monitoring, technology evaluation) and tag relevant staff, past projects, and training curriculum; map those to the listed NAICS in the event tags for capture planning.

Short-Term Actions (30 Days)

  • [ ] Draft a capability summary and technical approach outline that highlights mechanisms to differentiate human-led work from AI-generated output (provenance logging, human review processes, red-team evaluation, reproducible build artifacts).
  • [ ] Perform a focused compliance gap check against the named regimes (NIST 800-171 and FedRAMP) to identify immediate remediation actions and documentation you will cite in the RFI response.

Long-Term Actions (90+ Days)

  • [ ] Build or refine automated evidence pipelines and provenance controls in your development lifecycle so future proposals can produce audit-ready artifacts proving human oversight and traceability.
  • [ ] Develop a workforce training and sustainment program tailored to agency needs (role-based upskilling for AI-augmented development, documented instructor-led and hands-on modules) and capture measurable outcomes to include in proposals.

Compliance Checklist

  • [ ] NIST 800-171: Identify applicable control families, produce a System Security Plan (SSP) and Plan of Action and Milestones (POA&M) for any gaps, and prepare to describe how controlled unclassified information (CUI (Controlled Unclassified Information)) will be protected during AI development and continuous monitoring.
  • [ ] FedRAMP: If offering cloud-hosted AI capabilities or managed platforms for ICE/STELLA expansion, document your cloud hosting posture and FedRAMP-relevant controls; prepare evidence of authorization or a migration/authorization plan if FedRAMP impact is indicated.

Resources

  • NIST SP 800-171 (NIST Special Publication 800-171) text and resources: https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
  • FedRAMP program: https://www.fedramp.gov
  • ICE home page (agency procurement and policy pages to monitor): https://www.ice.gov
  • DHS (Department of Homeland Security) home page (policy and guidance landing): https://www.dhs.gov

Related reading: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) | CUI-Safe CRM Guide (/insights/cui-safe-crm-guide)

How Cabrillo Club Automates This

Cabrillo Signals War Room — Already detected this event and delivered this briefing within minutes. For subscribers, War Room continuously monitors federal sources for ICE and DHS procurement activity, RFI/RFP amendments, and policy shifts related to STELLA and AI initiatives. It will push immediate alerts for amendment notices, sources-sought updates, or changes to the October 16, 2024 schedule so your capture team never misses a deadline.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Signals Match Engine — Automatically re-scores your opportunity pipeline when events like this shift priorities. Match Engine updates opportunity scores, keyword relevance, and agency alignment in real time based on the RFI’s emphasis (AI agents, workforce training, continuous monitoring). Use the rescored pipeline to prioritize proposals and identify which existing bids should be reworked to highlight provenance and human-in-the-loop controls.

Cabrillo Signals Intelligence Hub — Tracks the affected agencies, the STELLA vehicle, and NAICS codes associated with this event. Configure saved searches to alert you when follow-on solicitations, sources-sought notices, or award actions related to this RFI are posted on SAM.gov. Intelligence Hub also centralizes the event tags and your evidence artifacts so capture teams have a single source of truth.

Proposal Studio (Proposal OS) — Generates first-draft technical approaches, compliance matrices, and capability statements tailored to this RFI using your past performance and win-theme library. Proposal Studio can auto-populate sections that describe provenance controls, human oversight processes, and training curricula, and it supports rapid iterations so you can produce an auditable draft for internal review ahead of the RFI deadline.

Proposal Studio Workflow Tracker — Triggers a 9-gate capture workflow for this opportunity (opportunity intake, bid/no-bid, solutioning, compliance review, pricing, approvals, submission, debrief capture, lessons learned). The Workflow Tracker routes compliance reviews to your contracts and legal teams, tracks required artifacts for NIST 800-171 and FedRAMP, and produces an audit-ready documentation package that demonstrates how your proposal differentiates genuine capabilities from AI-generated claims.

Call to action: Use the Cabrillo suite to automate monitoring, evidence collection, and rapid proposal assembly for this ICE RFI — contact your Cabrillo account lead to enable these features and map them to your capture plan.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.