DRAFT Attachment 0001 - Draft PWS_MSD MAIDIQ_11 Oct 24.pdf

PDF 346 KB Posted

Attached to
Request for Information: New Modern Software Delivery Multiple Award IDIQ Federal contract opportunity
Solicitation number
2024DCCOE005
Issued by
Department of the Army Materiel Command Army Contracting Command Aberdeen Proving Ground

About this file

This document is a draft Performance Work Statement (PWS) for a Multiple Award Indefinite Delivery, Indefinite Quantity (MA IDIQ) contract for Modern Software for Defense (MSD). The key objectives are to provide the U.S. Army with quality, cost-effective software capabilities through a pool of vendors able to implement agile methods, modern software development practices, and emerging technologies. The scope includes software development, customization, integration, software-as-a-service, and software security and hosting modernization. The PWS outlines requirements for security clearances, training, government-furnished property, contractor-furnished items, and specific tasks such as agile, software metrics, testing, DevSecOps, human-centered design, data centricity, and digital engineering. The overall goal is to enable the Army to rapidly develop, deliver, and adapt resilient software to achieve a competitive advantage.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information: New Modern Software Delivery Multiple Award IDIQ, newest first.
File Type Posted
Unplugged-QA_20 December 2024.pdf PDF
RFP 3_Comment Matrix_MSD IDIQ_16 DEC 2024 (1).xlsx XLSX spreadsheet
MSD IDIQ DRAFT RFP_13 DECEMBER 2024.pdf PDF
MSD_DRAFT PEFRORMANCE WORK STATEMENT (PWS) MSD MAIDIQ_12 DECEMBER 2024.pdf PDF
MSD_DRAFT IDIQ DRAFT RFP_12 DECEMBER 2024.pdf PDF
Attachment 0003_MSD IDIQ Labor Hour Model Worksheet.xlsx XLSX spreadsheet
MSD_DRAFT ORDERING GUIDE_12 DECEMBER 2024.pdf PDF
Attachment 0003_MSD IDIQ Labor Hour Model Worksheet.xlsx XLSX spreadsheet
MSD IDIQ DRAFT RFP_11 OCT 2024_CLEAN.pdf PDF
Comment Matrix_MSD IDIQ_11 OCT 2024.xlsx XLSX spreadsheet
Comment Matrix_MSD IDIQ_16 August.xlsx XLSX spreadsheet
DRAFT LCATS_MSD IDIQ_16 August.pdf PDF
DRAFT PWS_MSD IDIQ 16 August.pdf PDF
DRAFT RFP_MSD IDIQ_16 August.pdf PDF
Digital APBI for 10 JUL FINAL FOR RELEASE_v1.pdf PDF
Attachment 2-MSD MA IDIQ Follow Up _RFI Repsonses.xlsx XLSX spreadsheet
Attachment 1-MSD MA IDIQ RFI Repsonses.xlsx XLSX spreadsheet
Attachment 1-MSD MA IDIQ RFI Repsonses.xlsx XLSX spreadsheet
Modern Software Development- Request for Information.pdf PDF
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS) 1

Modern Software for Defense (MSD) 3

October 2024 5

PART 1 BACKGROUND 7

1. General: The Multiple Award Indefinite Delivery, Indefinite Quantity (MA IDIQ) for Modern 11 Software for Defense (MSD) is designed to provide a vehicle to award Task Orders and 12 Delivery Orders (TOs/DOs) in a streamlined manner in support of United States Army Modern 13 Software Enablement Requirements. 14

1.1 Description of Services/Introduction: This MA IDIQ is for modern software 16 development services to the Army and its operating agencies to enable the creation of 17 software that will aid in completion of their objectives and supported activities. 18

1.2 Background: 20

This MA IDIQ contract will be utilized for the issuance of TO/DOs for Modern Software 21 Development capacity, achieved via Software Enablement Efforts. For the purposes of this 22 effort Software Enablement is defined as (a) development of a custom software solution; (b) 23 configuration, customization, integration, or modification of a software solution; (c) software as 24 a service enablement; or (d) software security and hosting modernization. 25

1.3 Scope: The Modern Software for Defense (MSD) Contract is designed to provide the 27 U.S. Army with software solutions that comply with the guidelines established in Army Directive 28 AD 2024-02 for Enabling Modern Software Development and Acquisition Practices. The 29 directive highlights the importance for software contracts and programs to use modern 30 principles to include employing agile methods, software metrics, modernized testing, 31 DevSecOps, CI/CD, and future modern software practices as they develop. The scope of this 32 is not limited to only current methods and technologies, but also includes any future emerging 33 technologies with their integral and necessary ancillary MSD components and services as they 34 arise during the entire term of this contract. 35

1.4 Objectives: The objective of this MA IDIQ is enable the delivery of quality, cost effective 37 software capabilities to the Army at the speed necessary to meet Army’s objectives through: 38

1.4.1 Access to a pool of vendors able to “be agile” by implementing the values and principles 40 described in the Agile Manifesto https://agilemanifesto.org. 41

1.4.2 Established labor rate ranges that enable the Army to attract top talent when necessary 43 for program goals and to expedite the ordering process. 44 https://agilemanifesto.org/

1.4.3 Address emerging and new software best practices in both the Federal and Private 46 Industries. 47

1.4.4 Maximize competition at the TO/DO level by releasing contract type agnostic Request for 49 Task/Delivery Order Proposals, when appropriate. In these instances, MSD IDIQ Contract 50 Holders shall propose the most appropriate contract type for their proposed approach. 51

1.5 General Information: 53

1.5.1 Quality Assurance: The Government will evaluate the Contractor’s performance under 55 this contract IAW the Quality Assurance Surveillance Plan (QASP) established in the individual 56 task/delivery orders. This plan is primarily focused on what the Government must do to ensure 57 that the Contractor has performed IAW the performance standards. It defines how the 58 performance standards will be applied, the frequency of surveillance, and the acceptable 59 quality levels (performance thresholds). 60

1.5.2 Recognized Holidays: The following provides information on recognized holidays for the 62 purpose of this PWS. If submittal of any documentation (e.g. deliverables, submittals, etc.) 63 deadlines fall on a holiday, the closest workday prior to the holiday will apply as the deadline 64 for submittal. 65

1.5.3 Place of Performance: The place of performance will be defined at the TO/DO level. 67 .Mission requirements of certain TOs/DOs may require performance at the Government’s 68 facility. Remote work may be authorized to the extent that mission requirements and 69 Contractor policies permit. 70

1.5.4 Hours of Operations: The hours of operation will be defined at the TO/DO level when 72 necessary. 73

1.6 Security Requirements: The following information is provided on security related 75 matters as they concern to this contract. These requirements reflect the maximum 76 requirements for TOs/DOs and further requirements regarding security will be defined within 77 individual TOs/DOs. 78

1.6.1 Security Program: If the TO/DO requires work in a classified environment, then 80 Contractor personnel performing work under this TO/DO must have a SECRET security 81 clearance at time of TO/DO proposal submission and must maintain the level of security 82 required for the life of the TO/DO. The security requirements are IAW with the DoD Contract 83 Security Classification Specification (DD Form 254), which is currently accessible at the 84 following link: http://www.dtic.mil/whs/directives/forms/eforms/dd0254.pdf 85

1.6.2 Personnel Security Clearance Requirements: If the TO/DO states work in a classified 87 environment, then Contractor personnel performing work under this contract must have an 88 active personnel security clearance at the SECRET level in the Defense Information System 89 for Security (DISS) ) at time of the TO/DO proposal submission and must maintain the level of 90 security required for the life of the TO/DO. The security requirements are IAW the DoD 91 http://www.dtic.mil/whs/directives/forms/eforms/dd0254.pdf

Contract Security Classification Specification DD Form 254. The Contractor shall ensure that 92 Contractor employees and subcontractor employees performing services under this contract 93 comply with FAR 52.204-2 Security Requirements when the employee has access to 94 information classified “Confidential,” “Secret,” or “Top Secret.” The Contractor shall ensure the 95 employee complies with the DoD Security Agreement (DD Form 441), and the NISPOM rule at 96 32 Code of Federal Regulation (CFR) Part 117, effective 24 Feb 2021. The NISPOM is the 97 National Industrial Security Program Operating Manual to which contractors must implement 98 and comply. 99

1.6.3 Installation Access: If the TO/DO requires government installation access to U.S. 101 installations, buildings and controlled areas, access is limited to personnel who meet security 102 criteria and are authorized. Failure to submit required information/data and obtain required 103 documentation or clearances will be grounds for denying access to U.S. installations, buildings 104 and controlled areas. The Contractor shall ensure that any subcontractors used in 105 performance of this contract comply with these requirements and that all employees, of both 106 the Contractor and any subcontractor utilized by the Contractor, are made aware of and 107 comply with these requirements. The Contractor shall be aware of and comply with the 108 requirements associated with Installation Access Control. The Government is not liable for any 109 costs associated with performance delays due solely to a firm’s failure to comply with 110 Installation Access Control System (IACS) processing requirements. The Contractor shall 111 return installation passes to the issuing IACS office when the contract is completed or when a 112 Contractor employee no longer requires access. 113

1.6.3.1 Individual Termination or Expiration of Employment: The Contractor shall collect the 115 installation access passes, Government credentials and, if applicable, Government Furnished 116 Property (GFP) the same day employment of an individual has expired or has been terminated 117 and shall return them to the issuing office within one (1) day. 118

1.6.3.2 Contract Termination or Cancellation: Upon termination or cancellation of this TO/DO, 120 the Contractor shall collect all outstanding installation access passes and return them to the 121 issuing office within ten (10) days. 122

1.6.3.3 Common Access Cards (CAC) and CAC Log: When a TO/DO requires it, the 124 Contractor shall provide the following information: Last, First and Middle Names, Social 125 Security Number, date of birth, primary email address (this email address will be used to 126 contact the individual) and any other necessary information required to obtain a CAC or 127 installation access card, to the COR via email within five (5) days after award. The Contractor 128 shall ensure safeguarding of Personally Identifiable Information (PII) and comply with 129 requirements under 1.22.5. 130

1.6.4 Background Checks: Applicable to Continental United States (CONUS) and Outside 132 Continental United States (OCONUS) (includes Alaska and Hawaii) requirements, the 133 requiring activity shall consult with the responsible Security Office and Activity Manager 134 applicable to location(s) associated with this PWS and identify the level of background check, 135 supported by the applicable regulation(s). 136

1.6.4.1 U.S. Citizen: The Requiring Activity (RA) Manager will determine the extent of 138 background checks required. The Contractor employee may begin performance of the contract 139 after receiving a favorable local background check. The Contractor agrees to replace the 140 employee should results of the background check, if required, be unfavorable as determined 141 by the RA Manager. The Contractor’s replacement of the employee with the unfavorable 142 background check shall be within a timeframe provided by the RA Manager. The Contractor 143 shall also replace employees whose background check, during their tenure of employment, 144 renders them with an unfavorable local or stateside background check, as determined by the 145 RA Manager. The Contractor shall forward a copy to the Contracting Officer (KO) via the COR 146 and the RA Manager of each favorable background check within five (5) days of receipt by the 147 Contractor, identifying such with the appropriate contract number. The Contractor shall forward 148 a copy to the KO via the COR and the RA Manager of each unfavorable background check 149 within two (2) days of receipt by the Contractor, identifying such with the appropriate contract 150 number. When the Government awards a non-personal services contract directly to an 151 individual, the failure of the individual to provide a favorable background check would be 152 grounds for termination. 153

1.6.5 Physical Security: The Contractor shall safeguard all Government equipment, 155 information, and property provided for Contractor use. If performing work in a Government 156 facility, at the close of each work period, Government facilities, equipment, and materials shall 157 be secured IAW the Army Physical Security Program (AR 190-13) 158

1.6.6 Operations Security (OPSEC) Requirements: Contractor personnel shall adhere to 160 facility security policies and restrictions. The Contractor shall immediately report suspicious 161 activities to security personnel. 162

1.7 Key Control: Contractor shall establish and implement methods of making sure all keys 164 and/or CAC Cards issued to the Contractor by the Government are not lost or misplaced and 165 are not used by unauthorized persons. NOTE: All references to keys include CAC and key 166 cards. No keys issued to the Contractor by the Government shall be duplicated. The 167 Contractor shall develop procedures covering key control that shall be included in the 168 Contractor’s Security Plan with DI-ADMIN-81373 and the QCP. Such procedures shall include 169 turn-in of any issued keys by personnel who no longer require access to locked areas. The 170 Contractor shall immediately report any incidents of lost or duplicate keys to the KO. The 171 Contractor shall prohibit the use of Government issued keys and/or CAC cards by any persons 172 other than the Contractor’s employees. The Contractor shall prohibit the opening of locked 173 areas by Contractor employees to permit entrance of persons other than Contractor 174 employees engaged in the performance of assigned work in those areas, or personnel 175 authorized entrance by the KO. The Contractor shall establish and implement methods of 176 ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor 177 shall ensure that lock combinations are changed when personnel having access to the 178 combinations no longer have a need to know such combinations. These procedures shall be 179 included in the QCP. (DI-ADMIN-81373) 180

1.8 Post Award Conference/Periodic Progress Meetings: The Contractor shall attend any 182 post award conference convened by the contracting activity or contract administration office 183

IAW FAR Subpart 42.5. The KO, COR, and other Government personnel, as appropriate, may 184 meet periodically with the Contractor to review the Contractor's performance. At these 185 meetings the KO will apprise the Contractor of how the Government views the Contractor's 186 performance and the Contractor shall apprise the Government of problems, if any, being 187 experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings 188 shall be at no additional cost to the Government. (DI-ADMN-81505) 189

1.8.1 The Contractor shall attend, participate in, and furnish input to scheduled and 191 unscheduled meetings, conferences, and briefings that relate to the functions and services 192 herein as required by the Government to provide effective communication and impart 193 necessary information. The Contract Manager or designated representative shall attend 194 meetings as requested by the Government. Meeting attendees shall at times include 195 Contractor managerial, supervisory, and other personnel knowledgeable of the subject matter. 196 Meetings may start or end outside of regular duty hours. 197

1.9 Contracting Officer’s Representative (COR): Refer to Part 2 of this PWS for the 199 definition of a COR. As determined by the KO, a COR will be appointed at the TO/DO Level 200 and identified by letter of designation, a copy of which will be provided to the Contractor by the 201 KO. The designation letter states the responsibilities and limitations of the COR, especially 202 with regard to changes in cost or price, estimates, or changes in delivery dates. The COR is 203 not authorized to change any of the terms and conditions of the resulting order. The COR 204 monitors all technical aspects of the contract and assists in contract administration. The COR 205 is not authorized to obligate the Government. If the work is not written in the contract, the COR 206 is not authorized to request new work. The COR is authorized to perform the following 207 functions: assure that the Contractor performs the technical requirements of the contract; 208 perform inspections necessary in connection with contract performance; maintain written and 209 oral communications with the Contractor concerning technical aspects of the contract; issue 210 written interpretations of technical requirements, including Government drawings, designs, 211 specifications; monitor Contractor's performance and notifies both the KO and Contractor of 212 any deficiencies; coordinate availability of Government property; and coordinate site entry of 213 Contractor personnel. 214

1.10 Identification of Contractor Employees: All Contractor personnel attending meetings, 216 answering Government telephones, and working in other situations where their contractor 217 status is not obvious to third parties must identify themselves, to include proper marking of 218 signature blocks in correspondence, to avoid creating an impression in the minds of members 219 of the public that they are Government officials. The Contractor shall ensure that all documents 220 or reports, produced by Contractors are suitably marked as Contractor products or that 221 Contractor participation is appropriately disclosed. 222

1.11 Contractor Travel: The Contractor may be required to travel to an alternate place of 224 business, CONUS or OCONUS. The Contractor may be authorized travel expenses at rates no 225 higher than the substantive provisions of the Joint Travel Regulation (JTR), IAW FAR Part 226 31.205-46, and the limitation of funds specified in this contract. All travel requires Government 227 approval and authorization within ten (10) days prior to scheduled travel. (DI-ADMN-81308A) 228

1.12 Other Direct Costs (ODCs): Approved Purchasing System means a Contractors 230 purchasing system that has been reviewed and approved IAW FAR Part 44. If a Contractor 231 verifies that they have an Approved Purchasing System, they will be authorized to purchase up 232 to a specified value at the TO/DO level without prior KO approval. Any purchases exceeding 233 the specified dollar value will require Contractor submittal of competitive purchase results to 234 the KO prior to purchase. If a Contractor does not have an approved purchasing system, all 235 Material/Other Direct Costs (ODC) purchases exceeding the micro-purchase threshold as 236 defied at FAR 2.101 shall be evaluated by the COR and KO for fairness and reasonableness 237 and approved prior to purchase. 238 In order for charges to be invoiced, deliverable services must have been performed in direct 240 support of a requirement. There may be occasions when contractor personnel are invited to 241 participate in Government morale and recreational activities, such as holiday parties, golf 242 outings, sports days, and other various events. The Government does not have an 243 employer/employee relationship with contractor employees and therefore is not authorized to 244 grant administrative leave or expend Government resources to compensate contractor 245 employees for hours expended on activities not within scope of the TO/DO. Under these 246 circumstances, contractor employees must comply with individual company policy that is IAW 247 that company’s compensation system. Submission of an invoice for payment of non-billable 248 charges is not authorized and constitutes a false claim, which may lead to criminal sanctions, 249 fines, suspension, and debarment. 250

1.13 Data Rights: Data rights will be negotiated at the TO/DO level and will be governed and 252 subject to the appropriate Federal Acquisition Regulation (FAR) and Defense Federal 253 Acquisition Regulation Supplement (DFARS) provisions and clauses. 254

1.14 Non-Disclosure Requirements: Performance under this Contract may require the 256 Contractor to access data and information proprietary to a government agency, another 257 Government Contractor, or of such nature that its dissemination or use other than as specified 258 in this work statement would be averse to the interests of the Government or others. The 259 Contractor and Contractor personnel shall not divulge, or release data or information 260 developed, or obtained under performance of this PWS, except to authorized Government 261 personnel or upon written approval of the KO. The Contractor shall not use, disclose, or 262 reproduce proprietary data, which bears a restrictive legend, other than as specified in this 263 PWS. All documentation showing individual names or other personal information shall be 264 controlled and protected under the provisions of the Privacy Act of 1974, Public Law 93-579, 5 265 United States Code (U.S.C.) Section 552a. 266

1.15 Protection of Government and Contract Information: Per Public Use Notice of 268 Limitations stated by Defense Imagery Management Operations Center and contained at 269 www.dimoc.mil/resources/limitations/, the Contractor shall not cite any information (e.g., 270 contract information, pictures, locations, etc.) obtained through this contract on any hard copy 271 or digital marketing tools to include its company website. 272

1.16 Non-Disclosure Statements: When the TO/DO requires it the Contractor shall provide 274 signed non-disclosure agreements to the Government no later than seven (7) days prior to 275 http://www.dimoc.mil/resources/limitations/ commencement of work under a TO/DO issued under the contract. Disclosure of information 276 by Contractor personnel may result in removal of Contractor personnel from performance 277 under this contract. 278

1.17 Required Training: The following provides information on training requirements. 280 All Contractor employees, including subcontractors, shall complete Level I OPSEC training 282 within one (1) day of employment under this contract. Verification of the training shall be 283 provided to the COR within one (1) day after completion of the training. OPSEC Level I training 284 is available at https://jkodirect.jten.mil/html/COI.xhtml?course_prefix=EUC&course_number=-285

ECJ6-110-N. 286

1.17.1 Information Security Program (INFOSEC) Training: If applicable, Contractor 288 employees, including subcontractors, shall complete INFOSEC training within one (1) day of 289 employment under this contract. Verification of the training shall be provided to the COR within 290 one (1) day after completion of the training. INFOSEC training is available at 291 https://securityawareness.usalearning.gov/. 292

1.17.2 Information Assurance (IA) Training 294

1.17.2.1 All Contractor employees, including subcontractors, requiring access to Government 296 information systems shall complete the DoD IA Cyber Awareness Training prior to issuance of 297 CAC. Verification of the training shall be provided as part of the request for CAC package. 298

1.17.2.2 All Contractor employees, including subcontractors, working information technology 300 (IT)/IA functions shall comply with DoD and Army training requirements per Information 301 Assurance Training Certification and Workforce Management DoD Directive (DoDD) 8570.01, 302 Information Assurance Workforce Improvement Program DoD 8570.01-M, and Information 303 Assurance AR 25-2 within one (1) day of employment. Training is available at 304 https://public.cyber.mil/training/cyber-awareness-challenge/ . 305

1.17.2.3 All Contractor employees, including subcontractors, performing services under this 307 contract with access to a Government information system must be registered in the Army 308 Training Certification Tracking System (ATCTS). Contractor personnel must complete 309 refresher training every twelve (12) months. Verification of the training shall be provided to the 310 COR within fifteen (15) days prior to expiration of current training. 311

1.19 Government Furnished Property (GFP) and Services: Part 3 of this PWS applies to 313 TOs/DOs requiring GFP . When GFP is issued under a TO/DO, the Contractor shall submit a 314 Property Management Plan to the KO and the Property Administrator via the COR within ten 315

(10) days after date of contract award. (DI-MISC-80508B) 316 https://jkodirect.jten.mil/html/COI.xhtml?course_prefix=EUC&course_number=-ECJ6-110-N https://jkodirect.jten.mil/html/COI.xhtml?course_prefix=EUC&course_number=-ECJ6-110-N https://securityawareness.usalearning.gov/ https://public.cyber.mil/training/cyber-awareness-challenge/

PART 2 DEFINITIONS & ACRONYMS 318

2. Definitions and Acronyms 320

2.1 Definitions: Although not inclusive of every term used within this PWS, the following 322 provides a list of definitions used throughout this PWS and commonly used in the acquisition 323 field. 324 Contracting Officer (KO) – means a person with the authority to enter into, administer, and/or 326 terminate contracts and make related determinations and findings on behalf of the 327 Government. Note: The only individual who can legally bind the Government. 328 Contracting Officer's Representative (COR) – As defined in DFARS 202.101, means an 330 individual designated and authorized in writing by the KO to perform specific technical or 331 administrative functions. DoD Instruction (DoDI) 5000.72, Part II Definitions states the following 332 when defining a COR: “Defined in subpart 202.101 of Reference (f). Any individual delegated 333 responsibilities pursuant to subpart 1.602-2 of Reference (e), regardless of local terminology, 334 must be certified IAW this instruction. For example, local terminology can be COR, KO’s 335 technical representative, technical point of contact (POC), technical representative, alternate 336 COR, administrative COR, assistant COR, line item manager, task order manager, quality 337 assurance personnel, quality assurance evaluator, or COR management.” In addition, Army 338 Regulation 70-13, Chapter 2, paragraph 2-2g, states, in part, the following when providing 339 other surveillance support personnel to assist the COR when needed, “…These other 340 surveillance support personnel may serve as on-site representatives of the COR in 341 performance of actual contract surveillance if they meet all COR requirements and have been 342 appointed by the KO as alternate CORs.” 343 Contractor – means a supplier or vendor awarded a contract to provide specific supplies or 345 service to the Government. The term used in this contract refers to the prime. 346 Contractor-acquired Property - means property acquired, fabricated, or otherwise provided by 348 the Contractor for performing a contract and to which the Government has title. 349 Day – means business day 351 Defective Service – means a service output that does not meet the standard of performance 353 associated with the PWS. 354 Deliverable – means anything that can be physically delivered but may include non-356 manufactured things such as meeting minutes or reports. 357 Government-furnished Property (GFP) – As reflected in FAR 52.245-1, GFP 359 “means property in the possession of, or directly acquired by, the Government and 360 subsequently furnished to the Contractor for performance of a contract. Government-furnished 361 property includes, but is not limited to, spares and property furnished for repair, maintenance, 362 overhaul, or modification. Government-furnished property also includes contractor-acquired 363 property if the contractor-acquired property is a deliverable under a cost contract when 364 accepted by the Government for continued use under the contract. 365 Government Property - means all property owned or leased by the Government. Government 367 property includes both Government-furnished and Contractor-acquired property. Government 368 property includes material, equipment, special tooling, special test equipment, and real 369 property. Government property does not include intellectual property and software. 370 Property Administrator - means an authorized representative of the KO appointed IAW agency 372 procedures, responsible for administering the contract requirements and obligations relating to 373 Government property in the possession of a Contractor. 374 High Level Objective (HLO) – means a key overarching result-based objective for a project 376 necessary to achieve the project’s vision. HLOs are similar to Level 2 in a Work Breakdown 377 Structure. Each HLO may contain several statements to flesh out the areas necessary to meet 378 the objective. 379 Physical Security – means that part of security concerned with physical measures designed to 381 safeguard personnel; to prevent unauthorized access to equipment, installations, material, and 382 documents; and to safeguard against espionage, sabotage, damage, and theft. 383 Quality Assurance – (or Government contract quality assurance) means the various functions, 385 including, inspection, performed by the Government to determine whether a Contractor has 386 fulfilled the contract obligations pertaining to quality and quantity. 387 Quality Assurance Surveillance Plan (QASP) – means the key Government-developed 389 surveillance process document and is applied to Performance-Based Service Contracting 390 (PBSC). The QASP is used for managing Contractor performance assessment by ensuring 391 that systematic quality assurance methods validate that Contractor quality control efforts are 392 timely, effective, and are delivering the results specified in the contract, task order, or delivery 393 order. The QASP directly corresponds to the performance objectives and standards (i.e., 394 quality, quantity, timeliness) specified in the PWS. It provides specific details on how the 395 Government will survey, observe, test, sample, evaluate, and document Contractor 396 performance results to determine if the Contractor has met the required standards for each 397 objective in the PWS. 398 Quality Control – means all necessary measures taken by the Contractor to assure that the 400 quality of an end product or service shall meet contract requirements. 401 Statement – means the specific results-based activities required to satisfy HLOs. A statement 403 contains a result, the context of the statement, and the required action(s). Statements focus on 404 “what” is to be accomplished; however they are not prescriptive in describing “how” the 405 outcome is to be achieved. Each HLO may have several statements to flesh out the areas 406 necessary to meet the objective. Statements are similar to Level 3 in a Work Breakdown 407 Structure. 408

Subcontractor – means one that enters into a contract with a prime Contractor. The 409 Government does not have privity of contract with the subcontractor. 410 Work Day - The number of hours per day the Contractor provides services IAW the contract. 412 Work Week - Monday through Friday, unless otherwise specified. 414

2.2 Acronyms: Although not inclusive of every term used within this PWS, or that may be 416 included in an acquisition, the following provides a list of acronyms commonly used in the 417 acquisition field. 418 ACOR Alternate Contracting Officer's Representative 420 AFARS Army Federal Acquisition Regulation Supplement 421 AOR Area of Responsibility 422 AR Army Regulation 423 AT Anti-terrorism 424 ATCTS Army Training Certification Tracking System 425 CAC Common Access Card 426 CCE Contracting Center of Excellence 427 CFR Code of Federal Regulations 428 CI/CD Continuous Integration Continuous Development (or Deployment) 429 CONUS Continental United States (excludes Alaska and Hawaii) 430 COR Contracting Officer’s Representative 431 DA Department of the Army 432 DD250 Department of Defense Form 250 (Receiving Report) 433 DD254 Department of Defense Contract Security Requirement List 434 DFARS Defense Federal Acquisition Regulation Supplement 435 DMDC Defense Manpower Data Center 436 DoD Department of Defense 437 FAR Federal Acquisition Regulation 438 GFP Government Furnished Property 439 HLO High Level Objective 440 HIPAA Health Insurance Portability and Accountability Act of 1996 441 IA Information Awareness 442 IAC Installation Access Control 443 IACO Installation Access Control Office 444 ID Identification 445 IGCE Independent Government Cost Estimate 446 IT Information Technology 447 JTR Joint Travel Regulation 448 JPAS Joint Personnel Adjudication System 449 KO Contracting Officer 450 OCI Organizational Conflict of Interest 451 OCONUS Outside Continental United States (includes Alaska and Hawaii) 452 ODC Other Direct Costs 453 OPSEC Operations Security 454

PA Property Administrator 455 PII Personally Identifiable Information 456 PIPO Phase In/Phase Out 457 POC Point of Contact 458 PRS Performance Requirements Summary 459 PWS Performance Work Statement 460 QA Quality Assurance 461 QAP Quality Assurance Program 462 QASP Quality Assurance Surveillance Plan 463 QC Quality Control 464 QCP Quality Control Program 465 RA Requiring Activity 466 RCO Regional Contracting Office 467 SIGE Safety and Health Protection Plan 468 TE Technical Exhibit 469 USAG United States Army Garrison 470 UOM Unit of Measure 471

PART 3 GOVERNMENT PROPERTY (GP) AND SERVICES 473

3. Government Property and Services 475

3.1 Services: The Government will provide the contractor with the following items required to 477 perform the work described in this PWS: 478

3.2 Facilities: When required by the TO/DO, the Government will provide the contractor 480 access to the necessary workspace for the contract staff to provide the support outlined in this 481 PWS. These facilities include desk space, telephones, computers, and other items that 482 constitute an office environment. The COR will maintain serial number accountability for all 483 equipment issued to contract personnel. The Contractor shall use reasonable care to avoid 484 damaging existing buildings, equipment, and vegetation on the Government installation. If the 485 Contractor’s failure to use reasonable care causes damage to any of this property, the 486 Contractor shall replace or repair the damage at no expense to the Government as the KO 487 directs. If the Contractor fails or refuses to make such repair or replacement, the Contractor 488 shall be liable for the cost, which may be deducted from the contract price. 489

3.3 Utilities: When required by a TO/DO, the Government will provide utilities within 491 Government facilities for the contractors use in performance of duties outlines in this PWS. 492 The Contractor shall instruct employees in utilities conservation practices. The Contractor shall 493 operate under conditions that preclude the waste of utilities, which include turning off the water 494 faucets or valves, light switches, etc. after using the required amount to accomplish tasks 495 requiring the use of the utilities. 496

3.4 Equipment: When required by the TO/DO, the Government will provide the contractor 498 with access to, and use of office equipment needed to perform the services described in this 499 PWS. Examples of equipment include scanners, fax machines, printers, lights, chairs, desks, 500 computers, and office supplies needed to perform assigned work. When the Government 501 determines a personal digital assistant (e.g., BlackBerry) is required to perform the 502 requirements of the contract, one will be provided by the Government. The contractor shall 503 safeguard any such issued equipment and be responsible for replacement should the 504 equipment be lost or damaged due to negligence on the part of contractor personnel. The 505 contractor shall follow standard GFP guidelines provided in FAR 52.245-1 and clause 252.245-506 7002 507

3.5 Materials: The Government will provide the contractor with the following materials and 509 information: Organizational Standard Operating Procedures (SOPs), administrative policies 510 and procedures (including document templates), and security policies and procedures. 511 The contractor shall return to the Government all GFP, furnished to the contractor for 512 performance of this TO/DO at the end of the TO/DO period of performance IAW FAR 52.245-1. 513 The contractor shall not assume that additional GFE/M/I, not included in this PWS, will be 515 provided by the Government. 516

3.6 Common Access Cards (CAC): The Government will assist the vendor with obtaining 518 CACs via the Trusted Associate Sponsorship System (TASS) (Web site 519 https://www.dmdc.osd.mil/tass/ ). 520 https://www.dmdc.osd.mil/tass/

PART 4 CONTRACTOR FURNISHED ITEMS AND SERVICES 521

4. Contractor Furnished Property and Services 523

4.1 General: The Contractor shall furnish all supplies, equipment, facilities and services 525 required to perform work under the TO/DO that are not listed under Part 3 of this PWS. 526

4.2 Secret Facility Clearance: When required in a TO/DO, the Contractor shall possess and 528 maintain a Secret facility clearance from the Defense Counterintelligence and Security Agency 529 IAW DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM) and 530 AR 380-49, Industrial Security Program. The Contractor’s employees, performing work in 531 support of this contract shall have been granted a Secret from the Defense Industrial Security 532 Clearance Office. The Facility Security Clearance must match the highest security clearance 533 required for personnel. The DoD Contract Security Classification Specification (DD 254) is 534 provided as an attachment in the basic contract. 535

PART 5 SPECIFIC TASKS 537

5.1 Scope of Work Objective 538

The Modern Software Development Contract is designed to provide the U.S. Army with 539 software solutions that comply with the guidelines established in Army Directive AD 2024-02 540 for Enabling Modern Software Development and Acquisition Practices. The directive highlights 541 the importance for software contracts and programs to use modern principles including 542 employing agile methods, software metrics, modernizing testing, DevSecOps, CI/CD, use of 543 digital engineering practices and achieving Data Centricity through adherence to data mesh 544 principles. 545

5.2 Agile 546

Adherence to the Agile manifesto and agile principles have proven to create the best software 547 products and architectures. The agile framework employed by the contract needs to integrate 548 well with the government’s agile implementation. For example, if the government is using 549 Scaled Agile Framework (SAFe) then the awardee of the TO/DO will need to integrate with the 550 government’s SAFe ceremonies and structure for Agile Release Trains. While the exact 551 methods and cycles will continue to evolve over time, as we have seen with the emergence of 552 DevOps taking iterations from weeks to days, the ability for vendors and the government to be 553 agile remains a constant key for successful contracts. Agile frameworks include but are not 554 limited to: 555

• Scaled Agile Framework 556

• Scrum 557

• Kanban 558

• Extreme Programming 559

• Large Scale Scrum 560

Efforts on this contract will require collaboration between the government and contractor to 561 regularly refine the backlog and reach agreement on the definition of done for each of the work 562 elements. 563

5.3 Software Metrics 564

Software Metrics are the measurements of software characteristics to provide insights into the 565 development effort to guide technical and programmatic decision-making, continuous 566 improvement efforts, and remediation of blockers. Software teams will regularly review metrics 567 as part of their retrospectives and leverage metrics for continuous improvement and measuring 568 performance. The MSD IDIQ requires the vendor to collect the metrics in the required section 569 of the ASA(ALT) Software Metrics. 570

Individual TOs/DOs will also include specific metrics. Defined specific metrics will be included 571 in the QASP at the Base and TO/DO levels of this IDIQ. Metrics for individual TOs/DOs will be 572 submitted and aggregated to create metrics dashboards detailing the overarching performance 573 of the contractor across their portfolio of efforts on MSD. 574

5.4 Testing 575

Software testing is a crucial stage of the software lifecycle. Software Solutions on the MSD 576 contract will integrate testing design early in the life cycle and use automated testing to gain 577 confidence in the solution at an acceptable cost and timeline. Proper testing in this manner 578 ensures the contracted software solution delivers secure, quality software that meets the 579 needs of the target audience. Software Solutions on the MSD contract will employ testing 580 types that include but are not limited to: 581

● Automated Testing 582

● Unit Testing 583

● End to end testing 584

● DOT&E 585

● Safety Testing and Certification 586

● Operational Testing 587

● Interoperability Testing 588

● Joint Testing 589

● Functional Testing 590

● Load Testing API Testing 591

● Chaos Testing 592

● Regression Testing 593

5.5 DevSecOps and CI/CD 594

The DevSecOps and Continuous Integration and Continuous Deployment (CI/CD) approach is 595 a software development methodology that emphasizes collaboration, communication, and 596 integration between development, security, and operations teams. This approach aims to 597 shorten the system development life cycle while also improving the quality, security, and 598 predictability of software releases. Under this contract, the Army will require the performance 599 of DevSecOps and CI/CD work that include automation efforts and the implementation of 600 CI/CD pipelines in government-owned or contractor-owned spaces. Automation efforts are a 601 critical component of DevSecOps and CI/CD, as they help to streamline and accelerate the 602 software development and delivery process. DevSecOps and CI/CD efforts may include but 603 are not limited to the following activities: 604

• Automated build, test, and deployment processes 605

• Automated security testing and compliance checks 606

• Implementation of CI/CD pipelines in government-owned or contractor-owned spaces 607

• Configuration management and version control 608

• Creation of Infrastructure as code 609

• Continuous monitoring and logging 610

• Implementation of Continuous Authority to Operate (cATO) processes 611

• Containerization and orchestration 612

• Configuration management and version control 613

• Continuous User Touch Points 614

5.6 Human Centered Design 616

Human Centered Design is an approach to interactive system development that employs 617 techniques such as User Interface/User Experience (UI/UX) to focus on delivering capability 618 that meets the needs of the warfighter and not just the requirements document. The primary 619 focus is on enhancing user satisfaction and usability by improving the accessibility, efficiency, 620 and aesthetics of the product. Intuitive and easy to use software is critical to the successful 621 employment of new technology especially for software that will be used by the warfighter in 622 high stress combat environments. Creation of systems and software employing human 623 centered design principles will engage in a robust discovery phase and continuously refine 624 these designs throughout the lifecycle of the products. Further human centered design may 625 necessitate facilitation of group discussions or white boarding sessions where there may be 626 competing interests, visions and goals for the product to arrive at a common mission essential 627 understanding of the system. Human Centered Design activities and artifacts include but are 628 not limited to: 629

• Creation and employment of: 630 o Personas, 631 o Journey Maps, 632 o Process Maps, 633 o Experience Maps 634

• User Story Generation 635

• Requirements Decomposition 636

• Service Design Blueprints 637

5.7 Data Centricity 639

The Army aims to introduce data mesh principles to flatten and simplify its data architecture, 640 streamline data product sharing across mission partners, and support data-driven decision 641 making at greater speed and scale. To achieve these data strategy goals, the Army has 642 defined the Unified Data Reference Architecture (UDRA) to provide implementation guidance 643 for the creation of data-centric software solutions for the Army. Data from software solutions 644 developed under the MSD contract shall implement the relevant concepts found in the UDRA 645 and future data architectures to achieve the Army’s centricity objectives. . Some of these 646 solutions may include but are not limited to software used for: 647

• Data Pipeline Engineering 648

• Creation of Data Visualization 649

• Data Analytics Design, implementation, validation 650

• Creation of AI integrated workflows 651

• Creation of Data products 652

• Creation of API specifications 653

5.8 Digital Engineering 655

Digital engineering is using and integrating digital models and the underlying data to support 656 the development, test and evaluation, and maintenance of a system. It expands on 657 engineering practices to take full advantage of computation, visualization, and collaboration 658 to enable faster, smarter, data-driven decisions throughout the system life cycle. Proper use 659 of digital engineering digital engineering practices enables faster, higher-quality decision 660 making during design, development, testing, fielding, and maintenance. Disciplined use of 661 digital engineering fosters collaborative digital work environments that allow for concurrent 662 engineering and real-time communication across various locations and disciplines. The intent 663 on this contract is not to perform standalone Digital Engineering activities, but to utilize Digital 664 Engineering activities in concert with software efforts including embedded software that may 665 be part of a larger developmental or acquisition effort. Model Based System/Software 666 Engineering (MBSE) is a key enabling factor for successful software development practices. 667 The Army is standardizing digital engineering practices through use of the Unified 668 Architecture Framework (UAF) and SysML. Key digital engineering products and activities 669 include but are not limited to: 670

• System Architecture 671

• Process Flow Diagrams 672

• Software Architecture Diagrams 673

• Interface Models 674

• Data Models 675

• Requirements Validation 676

• Virtual Prototyping 677

• Digital Thread 678

• Digital Twin 679

• Automated Code or Documentation Generation 680

• Data Architecture 681

• Enterprise Architecture 682

5.9 Software Enablement 683

This Indefinite Delivery, Indefinite Quantity (IDIQ) contract will be utilized for the issuance of 684 TOs/DOs for Modern Software Development, achieved via Software Enablement Efforts that 685 incorporate agile, DevSecOps, CI/CD, testing, HCD, MBSE, and data centric practices where 686 applicable. 687

By nature of the alignment to Modern Software Development Requirements, the IDIQ includes 688 any and all emerging Software Enablement Efforts as they arise to successfully achieve the 689 agency’s mission. Therefore, because technological advances during the term of this IDIQ 690 Contract are inevitable, the scope of this Contract takes into consideration that TO/DO 691 Requirements are permitted to include any future emerging technologies with their integral and 692 necessary ancillary MSD components and services. The scope of the IDIQ Contract includes 693 every conceivable aspect of MSD including but not limited to: 694

5.9.1 Custom Software Development 696

Custom software development is creation of a software solution that addresses bespoke army 698 requirements utilizing the writing of new code. Custom software development may also use 699 and integrate open-source software. It is expected efforts in this task area will incorporate the 700 appropriate agile, CI/CD, DevSecOps, Data, and Digital Engineering practices where 701 appropriate. Custom software development activities encapsulate all aspects of the software 702 development lifecycle including but not limited to: 703

• Requirements Elaboration, Analysis, and Decomposition 705

• Design 706

• Implementation 707

• Test 708

• Delivery 709

• Deployment 710

5.9.2 Adapting a software solution 712

Activities in this task area encompass taking an existing solution, whether government or 714 commercial solutions, including integration of software as a service, and adapting or 715 integrating them to meet Army needs. It is expected efforts in this task area will incorporate the 716 appropriate agile, CI/CD, DevSecOps, data, testing, and Digital Engineering practices to 717 deliver modern so. Activities involved in adapting software solutions include but are not limited 718 to: 719

• Integration 720

• Orchestration 721

• Configuration 722

• Modification of an existing solution 723

• Use of a No-code, low code environment 724

• Creation of an application that augments existing solution 725

Modification of software involves changing the source code of the solution to perform the 728 desired task. Creation of an application that augments an existing solution means execution of 729 code outside of an existing software solution that extends or tailors the functionality of the 730 existing software solution for new tasks and workflows. 731

5.9.3 Software Security 733

Software security are the practices designed to protect solutions from attackers. It is expected 735 efforts in this task area will incorporate the appropriate agile, CI/CD, DevSecOps, testing, data, 736 and Digital Engineering practices where appropriate. This encompasses many activities 737 throughout the software lifecycle including but not limited to: 738

• Application of the Risk Management Framework 739

• Obtaining an ATO or cATO 740

• Software Assurance activities 741

• Penetration Testing 742

• Software Composition Analysis 743

• Use of Intrusion detection and prevention systems 744

• Remediation of Software vulnerabilities 745

• Encryption 746

• Software Patching 747

• Cyber Incident response and management 748

5.9.4 Modernization and Automation of Software Hosting and Operations 750 Software hosting and operations includes activities for deploying, maintaining, and optimizing 752 software applications. Modernization and automation includes scripting, implementation of “-753 as-code” solutions, and the use of emergent technologies such as artificial intelligence to 754 realize efficiencies in tasks and include but are not limited to: 755

• Infrastructure Management 757

• Application Management 758

• Monitoring and Alerting 759

• Incident Management 760

• Deployment and Release Management 761

• Configuration Management 762

• Performance Tuning 763

• Backup and Recovery 764

• Capacity Planning 765

• Documentation and Reporting 766

• Compliance and Auditing 767

• Service Management 768

• Change Management 769

• Cloud Migrations 770

PART 6 APPLICABLE PUBLICATIONS 773

6. Applicable Publications (Current Editions): The following publications, manuals, 775 regulations, etc. are mentioned in this PWS and are listed below. 776

6.1. Department Of Defense Contract Security Classification Specification (DD Form 254). 778

PART 1 BACKGROUND
PART 2 DEFINITIONS & ACRONYMS
PART 3 GOVERNMENT PROPERTY (GP) AND SERVICES
PART 4 CONTRACTOR FURNISHED ITEMS AND SERVICES
PART 5 SPECIFIC TASKS
PART 6 APPLICABLE PUBLICATIONS

File details come from the government source that posted it. Updated .