FBI Image Capturing RFI: Which NARA FADGI Requirement Is Named
Date: August 30, 2026 · Author: Dmitrii Zatona
In July 2026 the FBI’s Information Management Division posted market research for a platform to capture and process the Bureau’s paper records — scanning, recognition, metadata, workflow, at a stated hundred thousand images on an average day. Across the ten-page attachment’s dozens of capability bullets, the notice description, and thirty-two answered questions, FADGI is the only image-quality standard named (driver interfaces — TWAIN, WIA, ISIS — appear in the scanner-compatibility bullets) — and the operative phrase appears once, in the PDF: the system “must be able to handle the capturing and processing of textual documents and photographs, meeting the temporary and permanent NARA FADGI digitization requirements.” No resolution figure appears in any of the three documents; neither does bit depth, color mode, JPEG 2000, PDF/A, or a star level. The whole image-quality axis of the requirement rests on that one phrase — and the phrase names a compound object whose two halves behave very differently. For permanent records the parameters were chosen years ago, by regulation rather than by this notice, and they arrive with a scope gate the notice itself never mentions. For temporary records the phrase admits at least three readings, leading to three different normative objects, and no reviewed document says which was meant. What follows lays out what it takes for “meeting NARA FADGI requirements” to become a checkable object, and which links the documents fill. A market-research notice is entitled to leave choices open; the interest is in what each unmade choice involves.
1. What was published
The notice is FBI-IMD-IC , “RFI for FBI Image Capturing,” posted to SAM.gov on July 9, 2026 by the FBI’s Finance and Facilities Division, Procurement Section. SAM classifies it as a Sources Sought notice; the attached ten-page document titles itself a Request for Information and cites FAR 15.201(e) in its own disclaimer. The requiring organization named in the description is the Department of Justice, Federal Bureau of Investigation, Information Management Division (IMD), Technology Innovation Section (TIS). The recorded place of performance is a city only: Winchester.
Three versions exist in the SAM record: the July 9 original (responses due July 20), a July 14 revision adding the thirty-two-question Q&A workbook, and a July 16 revision extending the deadline to July 27. The notice auto-archived on August 11, 2026; its related field is empty and it carries no award data. The record carries no NAICS code, product service code, or set-aside — checked against a control notice on the same endpoint, so a property of this record, not the interface. The point of contact is Brandon James, bmjames@fbi.gov, listed as “Contracting Point of Contact” on the PDF’s last page — a procurement-section contact, not a program contact, and nothing below treats him as one.
Two pieces of primary background, connected to the notice no further than the documents connect them. The FBI’s FY 2027 Budget Request to Congress (March 2026) describes the Central Records Complex in Winchester, Virginia as a 256,000-square-foot facility with “the capacity to house approximately 1.7 billion pages of records,” whose robotic system “manages more than 361,000 records storage bins.” And Sentinel — named in the Q&A (Q3) as “FBI’s Enterprise-level case management system,” the downstream consumer the captured documents and metadata are expected to reach — was announced as deployed to all employees on July 1, 2012 by the FBI’s National Press Office .
Liveness, as a bounded fact about public records: as of August 29, 2026 no follow-on solicitation or related notice appears in SAM.gov public search (queries run: FBI-IMD, image capturing, image capture document processing, Captiva; active-only image capture FBI returns nothing). That negation is bounded by what SAM public search covers — a next step may proceed through channels this corpus does not capture. This is recently closed market research; the timing of any next-step solicitation is not public.
Method note: this is the seventh teardown in a series (1 : does a named primitive exist; 2 : which assurance tier; 3 : where the platform boundary sits; 4 : which operational choices a traceability sentence leaves open; 5 : who chooses the policy under which evidence composes; 6 : what anchors a biconditional guarantee). The test here is conditional: under the third reading below, the temporary half becomes second-article-shaped — levels exist, none selected — so what is particular is that the published text does not settle which referent was named at all. The fourth article examined a different notice from the same Bureau division; nothing below reuses its analysis.
2. What the requirement says
The document sets its own register in the introduction: “The description below outlines preliminary requirements envisioned for the Image Capture Suite and Document Processing Modernization project.” Its disclaimer states that responses are not offers and that the Government is under no obligation to award anything. The capability text that follows is organized into groups, each a list of short bullets:
| Group (PDF section) | What it enumerates |
|---|---|
| User Interface | Intuitive design; real-time previews for “immediate quality assessment of scanned images” |
| Scanner Compatibility | Eight named scanner models; TWAIN, WIA and ISIS drivers; per-document-type profiles |
| Database Management | ”Any common database type”; exportable history; live batch tracking |
| Batch Scanning | Minimal manual intervention; barcode/blank-page separation; batch-level indexing; page reordering |
| Recognition Services | Multilingual OCR; font-agnostic recognition; zonal extraction; ICR and handwritten text recognition; AI/ML classification; automated sensitive-data detection |
| Image Capture and Quality Control | Automated quality checks; manual flag-and-replace QC; enhancement parameters; simultaneous FADGI and non-FADGI workflows |
| Metadata and Indexing | OCR-driven extraction; “uniform metadata schemas”; immediate correction |
| File Management and Export | Naming “aligned with agency standards”; export to “all common image formats (pdf, tiff, jpg, png, etc.)”; content-based output segregation |
| Security, Performance, Workflow, Analytics, Cloud | Secret-enclave operation; audit logging; encryption; monitoring; configurable workflows; reporting; optional cloud and hybrid features |
Four passages carry the weight of this analysis. The first is the only place an image-quality standard is named (PDF p. 4, verbatim, with the bullet’s own title):
“Flexible Digitization Platform Supporting Simultaneous FADGI and NonFADGI Workflows: The system must be able to handle the capturing and processing of textual documents and photographs, meeting the temporary and permanent NARA FADGI digitization requirements and simultaneously running a non-NARA FADGI workflow”
The second, two bullets above it in the same group:
“Automated Quality Checks: Alerts and corrections for blurred, skewed, or incomplete captures.”
Its neighbours extend the same idea: “Manual and automated flagging options to identify and replace low-quality images during the QC process,” and enhancement tools “to adjust brightness, contrast, noise reduction, de-speckling, blank page detection, cropping, and other image clean up features.”
The third is the metadata bullet — “Consistent Schema Application: Uniform metadata schemas for efficient organization” — which names no schema. Asked whether schemas would be standardized across the enterprise or maintained per business area (Q7), the later FBI Q&A answers: “We are striving for FADGI compliance which requires us to capture various descriptive, technical, and administrative metadata associated with the record being digitized.” The metadata question is routed back to the same single reference.
The fourth carries the only “shall” among the capability bullets — elsewhere in those bullets obligations are phrased as “must” or “should” (the PDF’s submission instructions use “shall” separately):
“Automated Sensitive Data Detection: The system shall utilize Artificial Intelligence and Machine Learning to identify potentially classified or sensitive information, replacing or supplementing basic regular expression (regex) ‘dirty word’ searches with context-aware analysis to improve accuracy and reduce manual review.”
The Q&A fills in what that capability is meant to recognize — classification levels, dissemination controls, compartments, CUI categories and PII, “displayed in banner lines, portion markings, and classification blocks” (Q28) — and what its output is: “Advisory flags. All AI-detected sensitive data would undergo human review.” (Q29). Asked whether acceptance thresholds would be set, the Q&A answers that they have not been: “Performance thresholds have not yet been established and may be defined during requirements refinement and acceptance testing.” (Q30).
One more fact about the corpus, bounded and load-bearing. A case-insensitive search of all three documents — the SAM description, the full text of the ten-page PDF, and every cell of the Q&A workbook — finds zero occurrences of: dpi, ppi, pixels, bit depth, bitonal, grayscale, compression, lossless, sRGB, color mode; JPEG, JPEG 2000, JP2, PDF/A, or TIFF as a standard reference (the string “tiff” appears once, lowercase, in the informal export list); EBTS, ANSI/NIST-ITL, FISWG, NIST standalone; FIPS, RMF, ATO, NIST 800-53, CJIS, Section 508; METS, Dublin Core, EXIF, XMP; provenance, chain of custody, integrity, retention, disposition, records schedule, hash, checksum, verify, verification. “FADGI” appears in one PDF bullet and one Q&A answer, with no star level and no edition. Every quantitative image-quality parameter the requirement would need is therefore inherited, if at all, through that single phrase.
3. What it takes for “meeting NARA FADGI requirements” to be checkable
The chain below is this article’s organizing abstraction, marked (I); no reviewed document draws it. Six links, filled by different authorities, make the sentence testable.
- The record’s category — temporary or permanent, which the applicable records schedule determines, not the capture platform (unscheduled records are treated as permanent pending an approved schedule, per NARA’s published FAQ; whether any are in this workload is not established by the reviewed documents).
- The applicable normative object — which regulation or guideline actually governs that category.
- The scope gate — whether the material and the capture method fall inside that object’s coverage.
- The parameters — resolution, bit depth, color, tone, sharpening, noise, formats, metadata elements.
- The assessment method — what is measured, on what, how often, against which target and tolerance.
- Who attests — who asserts conformance, and who, if anyone, checks the assertion.
The permanent branch. Here the chain is filled in, and mostly not by the notice. 36 CFR part 1236, Subpart E — “Digitizing Permanent Federal Records,” final rule at 88 FR 28410 , effective June 5, 2023 — does not incorporate FADGI as a moving reference. It transcribes a fixed parameter set into the Code of Federal Regulations and says where the numbers came from: § 1236.50(b) states that “The performance parameters are based on FADGI three-star aim points and tolerance ranges,” and § 1236.41 identifies the Technical Guidelines as the basis of the part’s technical parameters, “which equate to the FADGI three-star level.” Link 4 is therefore closed by regulation, not by the notice or a vendor: Table 1, for modern textual paper, fixes resolution at ≥ 294 ppi, bit depth at 8 or 16, sharpening below 1.1 max modulation, and further measured parameters with tolerances; Table 2 raises resolution to ≥ 392 ppi for photographic prints and fine-detail paper. § 1236.48 enumerates formats per material: TIFF 6.0, JPEG 2000 Part 1 and PNG 1.2 for both tables, PDF/A for paper records only (Table 1) — it is absent from Table 2 for photographic prints — with no transcoding and no upsampling anywhere in the workflow; § 1236.54 enumerates mandatory metadata elements in the regulation’s own vocabulary.
Link 5 is closed to a range: device-level, target-based QA — a reference target captured “at the beginning of each workday,” auto-correction settings that may cause non-conformance turned off during evaluation (§ 1236.46(c)) — by FADGI’s Digital Image Conformance Evaluation method or a documented alternative (§ 1236.46(b)); plus bounded per-file checking — 100 % of files for openability, format, compression and recorded attributes, visual inspection of a sample (§ 1236.46(d)), a 1 % corrective threshold (§ 1236.46(e)).
Link 6 is often assumed to work otherwise, so it is worth stating plainly: no external certifier appears anywhere in the reviewed corpus — the guidelines and the regulation. The FADGI Technical Guidelines, Third Edition (May 2023) treat conformance as a property of a digitizing program — parameters, documented workflows, conformance evaluation, trained staff — and state in § 2.3 that validating or recommending targets and software “is beyond the scope of our mission.” Conformance is a self-assertion about one’s own program, validated under the regulation by agency staff independent of the QC staff (§ 1236.56), with NARA free to review the documentation.
Link 3 is where the notice and the regulation part company. Subpart E covers permanent paper records and photographic prints digitized by reflective techniques; transmissive originals — negatives, transparencies, microfilm, radiographs — and dynamic media are expressly outside it, with agencies directed to contact NARA (§ 1236.40). The RFI does not state that gate — its object statement, “textual documents and photographs,” specifies neither medium nor capture technique — and the Q&A describes a heterogeneous workload: mostly textual images, but “often intermingled with photographs, receipts, books, newspapers, magazines, pamphlets, brochures, maps, blueprints, oversized material” (Q5). What remains open on this branch is narrow but real: material-class assignment between the two parameter tables, DICE versus a documented alternative, and the sampling plan — the ten-or-ten-percent default, or an agency-documented statistically valid plan.
The temporary branch. Here the chain forks, and the fork is the subject of this article. One gate conditions the first two readings: Subpart D carries its own applicability condition — its standards apply when an agency digitizes temporary records “in order to use the digitized records in place of the source records” (§ 1236.30(a)). The RFI does not state whether digitized temporary records would replace their sources, and no reviewed document resolves that either; every statement below about Subpart D’s standards is conditional on that use — and where the gate is met, § 1236.30(a) also requires managing the digitized records under Subparts A through C, a records-management layer separate from the five digitization standards below. The gate does not touch the third reading: a voluntary FADGI-class requirement for temporary records neither depends on nor is resolved by § 1236.30(a).
Read literally. The subpart governing digitizing temporary records is Subpart D — final rule at 84 FR 14265, effective May 10, 2019, amended at 89 FR 46803 , effective August 28, 2024. Its standards are quoted in full, because their completeness is the point:
“When digitizing temporary records, agencies must meet the following standards: (a) Capture all information contained in the source records; (b) Include all the pages or parts from the source records; (c) Ensure the agency can use the digitized records for all the purposes the source records serve, including the ability to attest to transactions and activities; (d) Protect against unauthorized deletions, additions, or alterations to the digitized versions; and (e) Ensure the agency can locate, retrieve, access, and use the digitized versions for the records’ entire retention period.”
Five functional digitization standards — conditional, per the gate above, on the digitized records being used in place of the sources, and sitting alongside the Subpart A–C management duties the gate also attaches: completeness, page-level completeness, fitness for purpose, protection against alteration, retrievability for the retention period. As codified through the CFR annual edition of July 1, 2025, Subpart D contains no reference to FADGI, no star level, no resolution figure, no format list, no metadata schema, and no quantitative image parameter of any kind; validation is agency-required and documented — the agency “may establish its own validation process or use a third-party process” — with NARA free to review it (§ 1236.34). Read against that text, “temporary NARA FADGI digitization requirements” names an object that does not exist, and the marked outcome of this reading is null. NARA’s FAQ on the subpart runs in the same direction: it “does not recommend that agencies use the digitization standards for permanent as a default for all temporary records.”
Read as shorthand. The phrase distributes across its halves — NARA’s requirements for temporary records (Subpart D) plus the FADGI-derived requirements for permanent ones (Subpart E) — and is then a compact way to say “both regimes.” What follows for a builder is that the two workflows the same platform must run are specified in different currencies: one quantitative, parameterized and method-bearing; one functional and agency-defined. The FADGI parameters still do not reach the temporary side.
Read as intent. An agency may exceed Subpart D — no reviewed text forbids applying FADGI-class imaging to temporary records, and an organization running one pipeline over mixed holdings has an operational reason to want a single quality regime. On this reading the parameters exist and the sentence is deliberate. What is then unmade is what the permanent branch has closed: the star level (FADGI defines four, “does not recommend digitization to less than a three-star level when possible,” and cautions against four-star “for all but the most sophisticated imaging programs”), the material class among the fifteen the Third Edition defines, and the assessment method.
Three readings, three different objects, and the published documents do not choose. No reviewed regulation or guideline defines FADGI requirements for temporary records, and no reviewed document — notice description, RFI PDF, or Q&A — resolves which interpretation was intended. The null belongs to the literal reading only, as its marked outcome; it is not a finding about what the FBI meant, and this article draws none.
4. Four gaps
4.1 The referent itself is unresolved
This gap sits a step earlier than most: a respondent has to pick which of the three readings to build around, and the pick changes the engineering answer: under the literal reading the temporary workflow needs, where Subpart D applies at all (its § 1236.30(a) gate — digitized records used in place of the sources, which also attaches Subpart A–C management duties), a documented validation process (the agency’s own or a third party’s) and nothing quantitative about image quality; under the shorthand reading, the same, alongside a Subpart E pipeline for permanent records; under the intent reading, FADGI-class capture on both, with a star level and material classes still to be selected. Those are different equipment profiles, different QC regimes, and different unit economics at a hundred thousand images a day. The Q&A had the opportunity to settle it — the metadata question (Q7) was answered by invoking FADGI compliance generally, and one question (Q23) used the phrase “FADGI validation” — and no answer in the workbook names a subpart, a star level, or an edition.
4.2 The boundary of “automated quality checks” is not set
“Alerts and corrections for blurred, skewed, or incomplete captures” names its subject plainly: the RFI asks for automated detection of those three defects on production images. The three defects do not stand equally against the permanent regime’s own checks, and the split matters. For completeness, § 1236.46(f)(2) already prescribes automated and visual verification that 100 % of the source’s informational content was captured; for skew, § 1236.46(d)(3)(v) prescribes a visual check that images are not skewed — both conditional on the permanent branch. What neither provision supplies, and the RFI does not set, is what an automated production-image detector would need: a metric for any of the three defects, a threshold, a checking frequency — nor does the RFI say how its capability relates to the per-file attribute checks (openability, format, compression, recorded attributes) that § 1236.46(d) requires for 100 % of files, a provision that prescribes coverage, not automation.
The shelf standardizes the first thing thoroughly and the second not at all. ISO 19264-1:2021 analyzes imaging-system quality from a single capture of a specified test target; DICE works the same way; FADGI’s own image-level check is sampled visual inspection. The bounded statement: in the reviewed corpus — FADGI Third Edition (May 2023), 36 CFR part 1236 through the July 1, 2025 edition, ISO 19264-1:2021 — quality is standardized at device-and-target level, plus 100 % file-attribute checking, prescribed completeness verification, and sampled human inspection (skew among its visual criteria); an automated method for scoring an arbitrary production image against any of the three defects, without a target in frame, is not among them. The RFI asks for automated alerts and corrections, and for that automation the corpus offers no standard method or threshold to inherit.
4.3 “Corrections” have no stated bound — and the shelf’s bounds are of two different kinds
The same bullet asks for corrections; the enhancement bullet next to it asks for brightness, contrast, noise reduction, de-speckling, blank-page detection and cropping. No passage in the RFI, the description, or the Q&A limits how far a captured image may be altered before it is stored. The reviewed shelf does place limits, and they differ in status — a distinction that matters to anyone writing an acceptance test:
- Regulatory requirements (36 CFR part 1236, Subpart E): sharpening capped at < 1.1 max modulation in both parameter tables (§ 1236.50); no transcoding and no upsampling anywhere in the workflow (§ 1236.48(c)(3)); auto-correction settings that may cause non-conformance turned off during target evaluation, with production settings matching the evaluated configuration (§ 1236.46(c)); processing must not alter or delete embedded technical metadata (§ 1236.54(b)(4)); visual QC rejects over-sharpening, clipping, and images that are “improperly cropped … flipped, inverted, or skewed” (§ 1236.46(d)).
- Guideline recommendations (FADGI Third Edition, May 2023): “We recommend the entire object be scanned, without cropping. A small border should be visible around the entire document or photographic image” (§ 6.3) — a recommendation, not a prohibition; “Do not rely on ‘auto correct’ features” (§ 6.2); rotation correction expressly allowed (§ 2.4.12); and, where both are kept, the uncorrected file is the archival master.
Read together: the shelf’s bounds exist, and they are of two kinds — numbered requirements in the regulation, recommendations in the guidelines (which also allow minor post-capture adjustments, § 6.1, and require failed records to be corrected or re-digitized, § 1236.46(e)). The RFI asks for corrections and enhancements and states no bound of either kind for them; which kind a platform would be expected to enforce is a choice the documents leave open.
4.4 The capability list’s one “shall” has no yardstick
The sensitive-data detection bullet is the only “shall” among the capability bullets, and its acceptance criteria are stated to be undefined: thresholds “have not yet been established and may be defined during requirements refinement and acceptance testing” (Q30). That is a reasonable position for market research. The engineering observation is about what a contract would have to invent if it wanted them. In the corpus reviewed here — 36 CFR part 1236 through July 1, 2025; FADGI Third Edition (May 2023); NIST AI 100-1 (AI RMF 1.0, January 2023); NIST SP 800-122 (April 2010) — no federal standard sets quantitative performance thresholds for automated detection of sensitive information or PII in digitized records. AI 100-1 is a voluntary framework whose Measure function directs organizations to select their own metrics and acceptable risk levels, with no numeric detection threshold for any application; SP 800-122 defines PII and confidentiality impact levels and states no detection-accuracy requirement. The regulation requires recording Privacy Act and FOIA-based restrictions as metadata inherited from the source records (§ 1236.54(c)(2)) and prescribes no method for finding such content. Any threshold here would need to be defined in subsequent requirements or acceptance criteria — Q30 states they may be defined during requirements refinement and acceptance testing.
The adjacent capability has the same shape: asked for required minimum OCR/ICR/HTR accuracy levels, the Q&A names ten languages and no figure (Q27). Nothing in the corpus supplies one — FADGI § 6.7 leaves the “specified accuracy level” and its measurement to the implementer; § 1236.40(e) makes OCR optional for the permanent subpart; and in the corpus searched (that regulation, that guideline, the ISO catalogue, NIST publications) no current federal regulation or international standard defines a normative measurement method or minimum value for OCR, ICR or HTR accuracy. The systematic U.S. benchmark record is thirty years old (NISTIR 4990 , 1993).
5. Scale
The notice’s own numbers first. Asked for daily volumes, the Q&A answers “100,000 images daily (average) / 500,000 images daily (peak)” (Q4, repeated in Q25). Deployment: the DocLab plus two remote secured locations and 100 concurrent users (Q25). The fleet runs to roughly a hundred devices across eight models — some 80 Ricoh fi-7700, plus IBML, Opex Falcon+, Epson and Contex units (Q16, Q25). A quarter to a half of the documents carry handwriting, “often intermingled with typed text” (Q6); current OCR covers “over 70 languages” (Q27).
The facility context, sourced in Section 1: capacity for approximately 1.7 billion pages at the Central Records Complex, per the FBI’s FY 2027 Budget Request (March 2026). One policy date sits behind federal digitization programs generally: OMB and NARA’s M-23-07 (December 23, 2022) states that “Starting on July 1, 2024, agencies will be required to digitize permanent records created in analog formats before transfer to NARA,” after M-19-21 (June 28, 2019) set the original end date for NARA’s acceptance of paper. The same budget document records, in an unrelated part of the Bureau’s records work, a FOIPA workload of “almost 11,000 pending requests … totaling over 10 million pages awaiting processing” — published FBI context only; the RFI does not connect itself to FOIPA, and neither does this article.
One comparison has to be refused explicitly, because it is the natural one to reach for. Subpart E’s visual sampling rule — a minimum of ten records or 10 % of each batch, whichever is larger — cannot be set against the 500,000-images-per-day peak to yield a workload figure. The units differ (records per batch versus images per day), neither the batch size nor the image-to-record ratio is published in any reviewed document, and the regulation independently permits a statistically valid sampling plan in place of the default. Any number produced by combining them would be an artifact of the assumptions, not a fact about the program.
For calibration on what visual checking costs and finds, one peer-reviewed measurement was located in this review, and it measures a different program: Chapman and Leonard’s study of 100 %-visual QC in large-scale digitization of archival manuscripts (Library Hi Tech 31(3), 2013 ) reports “one error was discovered for every 223 scans reviewed (0.4 percent of scans)” and “one critical error was found for every 700 scans (0.1 percent),” with 15 % of project time spent on quality control. A 2013 academic-library figure, not a measurement of this environment. No publication located in this search reports automated-QA failure rates at production volumes of the order the RFI states.
6. The record
What follows is the dated public record around this notice, in three groups that the documents themselves do not connect. The notice’s related field is empty; the award records name products and dates and say nothing about the origin of any requirement. No causal statement is made below, and none is available from these sources.
The mandates and the regulations. M-19-21, June 28, 2019. Subpart D of 36 CFR part 1236, final rule 84 FR 14265, effective May 10, 2019, amended by direct final rule 89 FR 46803, effective August 28, 2024. M-23-07, December 23, 2022. Subpart E, final rule 88 FR 28410, effective June 5, 2023, and applicable retroactively per its preamble “to digitized permanent records that have not been transferred to the National Archives.” FADGI Technical Guidelines Third Edition, May 2023.
The notice family. SAM search on FBI-IMD returns five notices, all inactive as of August 29, 2026. Three are recent Sources Sought notices from the same requiring organization: FBI-IMD-ECM , “FBI Enterprise Content Manager Solution,” April 16, 2025; FBI-IMD-RT , “IMD Redaction Tool,” December 3, 2025; and this one, July 2026. The ECM description opens in near-identical language — the same division and section “conducting market research, seeking available sources to provide an innovative enterprise content management solution … seamless integration into the existing FBI environment.” None of the three is linked in SAM to a posted solicitation. Listing them is a statement about SAM records, not about a program.
The award record. FPDS data via USAspending, awarding sub-tier the FBI, retrieved August 29, 2026; the office prefix 15F067 matches the contracting office that issued the RFI. Twelve awards mention Captiva across FY2016–FY2026 — among them 15F06722F0002009 ($1,160,427.14, “PURCHASE OF NEW CAPTIVA LICENSES FOR THE CRC,” 2022–2024) and 15F06726F0000184 (“CAPTIVA RENEWAL,” to January 9, 2027) — alongside 15F06724F0000117 (“OPENTEXT MAINTENANCE,” $1,890,000.00, to December 29, 2026). Nineteen mention IBML, including 15F06725P0000744 (”…IBML 8300/8400 SCANNERS,” to February 12, 2027) and 15F06724P0001307 (”…THREE IBML IT6 SCANNERS FOR DOCLAB”). One Opex award appears: 15F06724F0002139 (“PURCHASE OF TWO OPEX FALCON SCANNERS,” $192,995.36). Ricoh/Fujitsu appears as fi-series scanner maintenance (15F06724P0001309; 15F06724F0001669, to 2027).
The dated record shows those mandates, those notices, and those awards. No reviewed document connects them to each other. Two limits on the award figures: FPDS keyword search is not exhaustive, so no total for the capture environment is computed or quoted here, and the horizons above are what the award records state, not a statement about what will be renewed.
7. Who would build it
What is requested. The RFI is addressed to manufacturers “with a documented proven history of successful integration of Image Capture and Document Processing applications on classified networks”; a reseller, integrator or prime may respond jointly with the manufacturer (Q22). Responses: at most eight pages. A potential Industry Day requires a Facility Clearance up to Top Secret, a GSA Schedule or NASA SEWP prime contract, active SAM registration, no debarments, U.S. ownership — with a “Show Me, Don’t Tell Me” demonstration approach and “customer provided data samples.”
The deployment constraints are firm: the system “must operate within a secret enclave without direct access to the internet”; cloud functionality “must support hybrid architectures and must not require direct internet connectivity from classified networks”; and the Q&A adds that the solution “must function completely within the Secret environment without requiring external cloud-based AI services,” with cloud or hybrid features permitted as optional enhancements that “must not impact the solution’s core capabilities if unavailable” (Q19). One place where the RFI and its Q&A read differently is shown here with both texts rather than resolved. The PDF’s submission instructions state: “The proposed software must also hold FedRAMP High certification to ensure compliance with federal security standards.” The later FBI Q&A states: “The FedRAMP High requirement applies only to cloud-hosted components and services. Software deployed exclusively within the on-premises classified enclave is not required to hold FedRAMP High authorization.” (Q21). Both are FBI-authored texts on the same notice; the second is the later clarification, and this article characterizes their relationship no further.
What is documented. The environment the platform would enter is heterogeneous, in the FBI’s own description: “OpenText Captiva Suite (ScanPlus, Completion, RescanPlus) Opex Software (CertainScan, Edit, Transform, and Monitor), Ricoh (PaperStream Capture), IBML Capture Suite, and custom-coded applications” (Q15). Whether that environment is replaced or joined is explicitly open — asked whether the FBI seeks to replace all current applications with one platform or to have the proposed solution coexist with selected existing systems, the Q&A answers “Either” (Q24), and the same answer is given to whether the FBI wants an integrated solution with third-party components or everything from one manufacturer (Q23). No claim of consolidation is made here, because the notice makes none.
The award record backs those product names at different granularities, and the difference matters. For Captiva, the evidence is at exact-product level: award descriptions naming Captiva licences and Captiva maintenance, one tied to the CRC. For IBML, it is software and hardware maintenance on named scanner series, one award naming the DocLab. For Opex, the documented award is for scanners — “PURCHASE OF TWO OPEX FALCON SCANNERS” — not for the CertainScan software suite the Q&A names. For Ricoh, the awards are scanner maintenance on fi-series models; PaperStream Capture appears in one 2016 line item bundled with a scanner purchase. The named software stack is therefore not, as a whole, documented by award chains at product granularity: some of it is, and some is visible only as the hardware it runs on.
What is unproven. Everything about transition. No reviewed document states what would be migrated, in what order, or on what schedule; no total contract value for the capture environment is computed here. Which vendors responded, and what any of them proposed, appears in no reviewed public record as of August 29, 2026.
8. What does not exist as a standard
The survey below states, for each reviewed document, what it fixes and what it does not, bounded to the version accessed on August 29, 2026.
| Document (version, date) | Fixes | Does not fix (bounded to this version) |
|---|---|---|
| 36 CFR 1236 Subpart E (88 FR 28410, eff. 2023-06-05; CFR ed. 2025-07-01) | Star level (three-star aim points, § 1236.50(b)); parameter tables; formats per material — PDF/A for paper only, Table 1 (§ 1236.48); metadata elements (§ 1236.54); QC regime and corrective threshold (§ 1236.46); independent validation (§ 1236.56) | Coverage beyond reflective digitization of permanent paper and photographic prints (§ 1236.40); material-class assignment; choice of targets and analysis software; sampling plan beyond the default |
| 36 CFR 1236 Subpart D (84 FR 14265, eff. 2019-05-10; am. 89 FR 46803, eff. 2024-08-28) | Five functional standards (§ 1236.32) and required, documented validation — own or third-party process (§ 1236.34) — applicable when digitized records are used in place of the sources (§ 1236.30(a)) | Any FADGI reference, star level, resolution, format list, metadata schema, or quantitative image parameter — none appears in the subpart |
| FADGI Technical Guidelines, 3rd ed. (May 2023) | Four star levels; fifteen material classes; the measured parameters; the four components of a conformant program (§ 2.2) | Any certification or accreditation program; any external assessor; any endorsement of targets or software (§ 2.3); any targetless per-production-image conformance metric |
| ISO 19264-1:2021 | Imaging-system quality analysis from one capture of a specified target; three levels to which FADGI’s stars nominally correspond | Assessment of production images without a target; continuous monitoring semantics |
| Conformance evaluation of the DICE class (tools page ) | Target-plus-software measurement, named in the regulation with a documented-alternative clause (§ 1236.46(b)) | A conformance authority: the regulation names a method, not a body that issues findings |
| 36 CFR § 1236.54 metadata elements | A mandatory element set — administrative, descriptive, embedded technical — plus CSV transfer and a documented label mapping | Alignment to any named external schema; FADGI ch. 8 declines to specify an element set at all |
| NIST AI 100-1 (AI RMF 1.0, January 2023) | A voluntary risk-management framework; Govern/Map/Measure/Manage | Any numeric detection threshold; metric selection is delegated to the organization |
| NIST SP 800-122 (April 2010) | PII definitions and confidentiality impact levels | Any detection-accuracy requirement |
Four bounded negations, with their corpus stated. In the documents reviewed here — 36 CFR part 1236, both subparts, through the CFR annual edition of July 1, 2025; the FADGI Technical Guidelines Third Edition (May 2023); NARA’s published FAQ on digitizing temporary records; ISO 19264-1:2021; NIST AI 100-1 and SP 800-122 — (1) no regulation or guideline defines FADGI digitization requirements for temporary federal records, and no document of the notice itself resolves which of the three readings in Section 3 was intended; (2) no standard defines an automated, targetless metric, threshold, or checking frequency for scoring an arbitrary production image against blur, skew, or incompleteness — what is standardized is device-and-target measurement, 100 % checking of file attributes, prescribed completeness verification (§ 1236.46(f)(2)) and visual skew inspection (§ 1236.46(d)(3)(v)) on the permanent branch, and sampled human inspection; (3) no federal standard sets quantitative thresholds for automated detection of sensitive information or PII, and none defines a measurement method or minimum value for OCR, ICR or HTR accuracy; (4) no external certifier of FADGI conformance appears anywhere in that corpus — conformance is asserted by the digitizing organization, validated by agency staff independent of the QC staff, and reviewable by NARA.
What the shelf does hold is worth stating as plainly as the gaps: for permanent paper records digitized reflectively, an agency does not have to design an image-quality regime — parameters, formats, metadata elements, inspection coverage and corrective threshold are written into the CFR, with the assessment method named. The unmade choices in this notice sit on the other side of the phrase: which records the requirement is about, and which of three referents the temporary half names. I work on verifiable evidence chains and provenance records in an adjacent area, and that work is separate from this analysis.
The bullet is one line in a document that labels its own requirements preliminary, and market research is supposed to leave choices open. What is unusual is the level at which the openness sits: most underspecified requirements name an object and leave its parameters unselected; this one names a compound object whose permanent half arrives with parameters already selected by regulation, and whose temporary half resolves three different ways depending on a reading no published text fixes. A respondent has to decide which requirement was named before deciding how to meet it. The record, as it archived on August 11, 2026, leaves that decision where it found it.
If you are building a response to this document and the provenance or attestation piece has to be designed and built, that is contract work I take on.