RFQ & Procurement August 12, 2026 9 min read By Rajadurai R — Founder, 14 years plant-head experience

How to Share an RFQ with a 3D Model Securely: A Procurement Engineer's Guide

Sharing an RFQ with a 3D model securely means delivering geometry, drawings, and specifications to shortlisted suppliers through access-controlled, time-limited links — not email attachments — so that only authorised vendors can open the file, every download is logged, and access expires automatically after the quoting window closes. Done correctly, it protects intellectual property while giving suppliers everything they need to return an accurate quote.

A machined aerospace bracket. A precision-welded sub-frame. A custom hydraulic manifold. Every one of these parts starts its supply-chain life as a 3D model floating in someone's email outbox — attached to a message that will be forwarded, downloaded to personal laptops, and possibly handed to three other shops the buyer never approved. Most procurement teams treat file security as a legal formality. They sign an NDA, attach the STEP, hit send, and move on. The consequences surface months later when a competitor quotes an eerily similar geometry, or when an audit reveals that six unauthorised parties accessed the file.

What Is Really at Stake When You Email a CAD File

A 3D model is not just geometry. It encodes your wall thicknesses, feature relationships, material allowances, and sometimes embedded metadata from the originating CAD system — enough for a determined party to reverse-engineer your product. Once an email attachment leaves your outbox, you have zero visibility into who opens it, copies it, or forwards it. The NDA you signed is a legal remedy after the fact; it does not prevent the breach.

Beyond IP, there is a quoting accuracy problem. Suppliers quoting from incomplete or outdated files return quotes that are useless for comparison. If Supplier A quotes Rev B and Supplier B quotes Rev C, you are comparing apples to engine blocks. A controlled, versioned RFQ package eliminates that confusion entirely.

The financial exposure is real too. Engineering design represents 20–30% of a product's total lifecycle cost according to research published by NIST on the cost of poor quality data. Leaking that design data early collapses the competitive advantage that justified the R&D spend in the first place.

Step-by-Step: How to Share an RFQ with a 3D Model Securely

This process is structured around four phases: prepare the package, control access, distribute with auditability, and compare quotes. Each phase has specific actions that close the most common security gaps.

Phase 1 — Prepare the RFQ Package Correctly

  1. Convert to neutral format. Export geometry as STEP (AP214 or AP242) or IGES. Never send native SLDPRT, Catia CATPart, or Parasolid files unless the supplier has a documented need and your legal team has cleared it. Native files carry parametric history — suppliers only need dumb solid geometry to quote.
  2. Strip embedded metadata. Most CAD systems write author name, company, and revision history into file properties. Use your CAD export settings or a batch metadata cleaner to remove fields you did not intend to share. Check STEP file headers in a text editor — the first 20 lines expose originating software and username by default.
  3. Prepare the 2D drawing as a locked PDF. The drawing must carry all tolerance and GD&T information per ASME Y14.5-2018 or ISO 1101, including general tolerances declared under ISO 2768 class (e.g., ISO 2768-m for medium). The 3D model shows shape; the drawing governs the contract.
  4. Define the RFQ scope document. This plain-language document must state: revision level, material grade (e.g., IS 2062 Gr E250A for structural steel, AMS 5596 for Inconel 625 sheet, or 6061-T6 aluminium), surface finish (Ra value in µm or µin), heat treatment, plating or coating, quantity tiers, delivery location, and INCO term. Suppliers who have to guess any of these return quotes with large contingency markups — or simply decline to quote.
  5. Bundle into a single, clearly named archive. File naming convention: [PartNumber]_[RevLevel]_RFQ_[IssueDate].zip. Example: HYD-MFD-0042_RevC_RFQ_2026-07-15.zip. This naming survives download and email forwarding and tells every recipient exactly which revision they are looking at.

Phase 2 — Set Up Access Controls Before You Share Anything

  1. Choose a signed-URL delivery method — not cloud drive. Google Drive and Dropbox links are persistent by default, re-shareable, and tied to the recipient's account with minimal audit depth. A signed URL embeds an expiry timestamp and optionally a password. When the quoting window closes, the URL is cryptographically dead — no administrative action needed.
  2. Set the shortest viable expiry. Match expiry to your quoting timeline plus two working days buffer. A 14-day RFQ window warrants a 16-day expiry. Leaving links open indefinitely because "we might need to follow up" is the single most common access-control failure in manufacturing procurement.
  3. Assign one unique link per supplier. This is non-negotiable for auditability. If the same link goes to five suppliers and the file appears in an unexpected location six months later, you cannot trace the source. Unique links mean every download event is attributed to a named vendor.
  4. Add password protection as a second factor. Communicate the password through a separate channel — a phone call or a different messaging platform — never in the same email as the link. This simple two-channel approach stops link-forwarding breaches cold, because the recipient needs both credentials.
  5. Record the NDA status before generating any link. Your access control log should have a column: NDA signed (Y/N), NDA date, NDA expiry. Do not issue a link to a supplier without a confirmed NDA on file. This is basic but routinely skipped under quoting deadline pressure.

Phase 3 — Distribute and Monitor with an Audit Trail

  1. Send the invitation — not the file. The invitation email contains: the signed URL, the quoting deadline, the scope document (or a link to it), contact details for technical queries, and the quote submission format. The 3D model and drawing are only accessible after the supplier authenticates through the link.
  2. Monitor access events in real time. A proper audit trail logs: timestamp of access, IP address, user agent (browser/OS), number of downloads, and any failed authentication attempts. Review this log at least once during the quoting window. If a supplier has not opened the package three days before deadline, a proactive chase call saves a missed quote.
  3. Version-lock the package. If an engineering change occurs mid-RFQ, do not silently update the existing link. Issue a new package, revoke the old link, notify all suppliers of the revision, and document the change in your procurement record. Mixing revisions across suppliers invalidates quote comparisons and can create contractual disputes later.
  4. Acknowledge receipt from each supplier. A simple confirmation — "We have received your quote for Part HYD-MFD-0042 Rev C" — closes the loop and confirms the supplier quoted the correct revision. This takes 30 seconds and prevents a painful mismatch at Purchase Order stage.

Phase 4 — Collect and Compare Quotes

  1. Standardise the quote submission format. Give suppliers a template with fixed rows: unit price by quantity tier, tooling cost (one-time), lead time (weeks), material source/certificate availability, process capability statement (Cpk ≥ 1.33 is standard for critical dimensions per AIAG SPC guidelines), and payment terms. Unstructured quotes are impossible to compare fairly.
  2. Build a comparison matrix before quotes arrive. Pre-populate columns with your evaluation criteria and weighting: price (40%), lead time (20%), quality credentials (ISO 9001/AS9100 certification status — 20%), past performance (10%), and geographic risk (10%). Weights are illustrative — adjust for your commodity and supply risk profile.
  3. Cross-check quoted material against your specification. A supplier quoting IS 2062 Gr E250B when you specified Gr E350 may look cheaper but will fail mechanical requirements. Verify material grade, heat, and lot traceability requirements explicitly before awarding.
  4. Document the award decision. Record why you selected or rejected each supplier, referencing the comparison matrix scores. This documentation is required evidence for ISO 9001:2015 clause 8.4 (external provider control) and ISO 9001:2015 audit purposes.

RFQ Package Contents: At a Glance

Item Format Purpose Common Mistake
3D geometry STEP AP214/AP242 Shape reference for programming and fixturing Sending native CAD with parametric history
2D drawing PDF (locked) Contractual tolerance and GD&T reference Omitting general tolerance standard (ISO 2768)
Scope document PDF or structured form Material, finish, qty, INCO, deadline Verbal agreements not committed to writing
Quote template XLSX or structured form Standardises supplier response for fair comparison Accepting unstructured email quotes
NDA reference Confirmation number or date Legal access prerequisite Issuing links before NDA is confirmed signed

Common Mistakes That Expose IP and Ruin Quote Comparisons

Mistake 1 — Using email attachments as the primary delivery method. Email is inherently uncontrolled. There is no expiry, no audit trail, and no revocation mechanism. If you send a STEP file as an attachment today, that file sits in the supplier's inbox, potentially forever, regardless of what your NDA says.

Mistake 2 — Sharing the same link with all suppliers. This is equivalent to handing the same key to ten people and then being surprised when you cannot tell who copied it. Unique links per supplier is the minimum viable audit requirement.

Mistake 3 — Setting no expiry or a very long one. A link that expires in 90 days for a 14-day quoting exercise leaves a 76-day window of unnecessary exposure. Set expiry to quoting deadline plus two working days and no longer.

Mistake 4 — Omitting the 2D drawing and sharing only the 3D model. A 3D model without a drawing is geometrically suggestive but legally ambiguous. Tolerances on a model — even those embedded as PMI — do not carry the same contractual weight as a signed drawing. Always include both.

Mistake 5 — Updating the 3D model without issuing a new revision. Overwriting the file at the same URL mid-RFQ means some suppliers quote the old geometry, others quote the new one. The quotes are incomparable and the procurement record is invalid. Every geometry change requires a new revision, a new link, and a formal reissue notification.

Mistake 6 — Skipping the quote submission template. When suppliers return quotes in their own format, comparing them requires manual interpretation. A price buried in a narrative paragraph is easy to miss. Structured templates remove ambiguity and speed up the comparison step dramatically.

For context on how ballooned drawings feed directly into a well-structured RFQ package, see the guide on RFQ to Vendor Workflow: Send Drawings Securely and the explainer on STEP File BOM Export for generating accurate material and part lists from your 3D assembly.

How CadNexa Helps

CadNexa's Secure RFQ System is built specifically for this workflow. Drawings and 3D models are shared with vendors via signed URLs that carry password protection, a configurable expiry date, and a full audit trail — every access event is logged against the vendor. Suppliers submit quotes directly through the platform, and the buyer compares and awards from a single dashboard. There is no emailing of attachments, no version confusion, and no manual audit log to maintain. The 3D Viewer inside the same platform lets suppliers inspect the STEP geometry in-browser without downloading proprietary software — which means you control the viewing environment, not the supplier's desktop. Try the Secure RFQ System at cadnexa.com/app.html and run your next RFQ without a single email attachment.

If your workflow also involves ballooning drawings before issuing the RFQ — which it should, to give suppliers a clear inspection reference — the guide to ballooning a PDF drawing online covers that step in detail.

Frequently Asked Questions

What is the safest way to send a 3D model to a supplier for quoting?

Use a signed URL with password protection and a short expiry window rather than email attachments. This limits access to named suppliers, prevents forwarding, and creates an audit trail of every download. Communicate the password through a separate channel — phone or a different messaging platform — never in the same email as the link.

Should I send the native CAD file or a neutral format like STEP for an RFQ?

Send STEP or IGES for geometry and a PDF drawing for 2D tolerances. Native formats such as SLDPRT or Parasolid expose design intent and parametric history that suppliers do not need to quote. That is unnecessary IP exposure and a legal risk if the supplier reverse-engineers your feature relationships.

How do I prevent a supplier from sharing my 3D model with a competitor?

Combine an NDA, a short-lived signed URL, and an audit trail. Once the URL expires, the file is inaccessible regardless of whether the link was forwarded. Each supplier gets a unique link, so any leak can be traced back to a specific vendor — a strong deterrent in itself.

What file formats should I include in a manufacturing RFQ package?

At minimum: STEP or IGES for 3D geometry, a locked PDF drawing with all tolerances and GD&T per ASME Y14.5-2018 or ISO 1101, a material specification (e.g., IS 2062 Gr E250A, AMS 5596, or 6061-T6), surface finish Ra values, treatment or coating requirements, quantity tiers, and annual volume if applicable.

Is a signed URL the same as a shared cloud drive link?

No. A shared drive link from Google Drive or Dropbox is persistent, often re-shareable, and has shallow audit depth. A signed URL embeds an expiry timestamp and, optionally, a password. Access is revoked automatically when the URL expires, and every access event is logged — neither of which is true of a standard cloud share link.

Conclusion

Secure CAD file sharing for RFQ is not an IT concern — it is a procurement discipline. The steps are straightforward: prepare a neutral-format package with a locked drawing and a complete scope document, deliver via unique signed URLs with password protection and a tight expiry, monitor access through an audit trail, and collect quotes in a standardised format that makes comparison objective. The tools to do this exist and are not expensive. The cost of not doing it — leaked geometry, invalid quote comparisons, and a failed ISO 9001 clause 8.4 audit — is considerably higher.

Try CadNexa's Secure RFQ System free — 14 days, no card required. Share your next 3D model RFQ via signed URL, collect structured supplier quotes, and compare bids in one place. Start your free trial at cadnexa.com/app.html →