Attachment 1 - DRAFT ASCEND IDIQ PWS.pdf
PDF 463 KB Posted
- Attached to
- DRAFT - FA873025RB007 - All Domain Common Platform (ADCP) Security Cloud Engineering Network Develpoment (ASCEND) RFI Federal contract opportunity
- Solicitation number
- Not on record
About this file
This Performance Work Statement (PWS) outlines requirements for the All Domain Common Platform (ADCP) Security Cloud Engineering Network Development (ASCEND) Indefinite Delivery/Indefinite Quantity (ID/IQ) contract. The program aims to develop, field, and operate hosting environments for mission-critical warfighting applications supporting the U.S. Air Force, with a focus on operational availability, resilience, and continuous integration of software-intensive capabilities across multiple classification levels. The contract will support Air and Space Operations Center (AOC) enterprise applications and intends to scale to broader operational Command and Control (C2) communities and the Department of the Air Force Battle Network Enterprise.
Key performance objectives include platform architecture and systems engineering, cloud and infrastructure support, platform engineering and operations, security/cybersecurity, and service center management. The contract will have a base period of one year with four potential one-year option periods. Contractor responsibilities include developing cloud-native applications, ensuring 24/7/365 operational support, managing multi-cloud environments, maintaining robust security protocols, and supporting classified work across Impact Levels 4, 5, and 6. The primary performance locations will be Hanscom Air Force Base, Massachusetts, and Langley Air Force Base, Virginia, with potential for remote work and international support.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 - DRAFT Task Order 0001 PWS.pdf | ||
| Exhibit A - Draft CDRLs.pdf | ||
| DRAFT SECTION M ASCEND.pdf | ||
| Attachment 6 - Draft Consent Letter.pdf | ||
| Exhibit B - Draft ASCEND Past Performance Questionnaire.pdf | ||
| DRAFT SECTION L ASCEND.pdf | ||
| Attachment 3 - DRAFT Past Performance Information .pdf | ||
| Attachment 4 -Draft Client Authorization Letter.pdf | ||
| Attachment 7 - Cross Reference Matrix Sample.pdf | ||
| DRAFT Solicitation - FA873025RB007.pdf | ||
| Attachment 5 - Draft Transmittal Letter Draft.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Indefinite Delivery/Indefinite Quantity (ID/IQ) Performance Works Statement (PWS) for
All Domain Common Platform (ADCP) Security Cloud Engineering Network Development
(ASCEND)
Revision 2.0 - 15 January 2025
Prepared by:
Air Force Life Cycle Management Center/Kessel Run (AFLCMC/C3C) 11 Barksdale Street
Building 1614 Hanscom AFB, MA 01731-1700
TABLE OF CONTENTS
1.0 Purpose
2.0 Scope of Mission
3.0 Period and Place of Performance
4.0 Performance Objectives
4.1 Platform Architecture and Systems Engineering
4.2 Cloud, Cloud Edge and Infrastructure support:
4.3 Platform Engineering and Operations
4.4 Security/Cyber Security
4.5 Service Center (Service Integration and Support Management)
5.0 Operating Constraints
5.1 Deliverables
5.2 Surge Capacity
6.0 General Requirements
6.1 Contract Management
6.2 Contract Manager
6.3 Financial Reporting Requirements
6.4 Additional Reporting Requirements
6.5 Phase-In Transition Plan
6.6 Phase-Out Transition Plan
6.7 Sub-Contracting
6.8 Business Relations
6.9 Recognized Holidays
6.10 Risk Management
6.11 Supply Chain Risk Management
6.12 Travel
6.13 Data Management
6.14 Electronic Data Interchange (EDI)
6.15 Government Furnished Equipment (GFE) / Government Furnished Property (GFP) / Government Furnished Information (GFI)
6.16 Contractor Acquired Property (CAP)
6.17 Procurement
6.18 Security Requirements
6.19 Non-Disclosure Agreements
6.20 Passports, Visas, Licenses, and Permits
6.21 Disseminating Scientific and Technical Information (STINFO)
6.22 Associate Contractor Agreements (ACA)
6.23 Data Rights
6.24 Service Delivery Summary (Quality Control)
1.0 PURPOSE:
The purpose of this ID/IQ PWS is to provide the contractor with AFLCMC/C3C’s overarching and enduring requirements for supporting enterprise level cloud activities.
The Government will utilize this document, in conjunction with approved software development roadmaps, and Task Order (TO) specific requirements to emphasize to the contractor the Government’s intent and desired end-state.
2.0 SCOPE OF MISSION:
The ADCP program has the responsibility of developing, fielding, and operating hosting environments for mission critical warfighting applications in support of the U.S. Air Force. These applications need to be operationally available and mission capable 24/7/365 in highly contested environments and resilient against peer advisories in a major theater conflict.
The ADCP program delivers software developer tools, resources and services that enable the development and continuous integration and delivery of software-intensive capabilities to Air Force (AF) and Joint, and Coalition Command and Control (C2) end-users. The ADCP program also provides enterprise services to continuously test, secure, deploy and operate applications to staging and production environments across multiple classification levels. The current primary ADCP user base is the Air and Space Operations Center (AOC) enterprise, and the program intent is to further scale to support the broader operational C2 community and Department of the Air Force (DAF) Battle Network Enterprise.
The Government anticipates continued upscaling of ADCP products, services, and users over the next three to five years. The ADCP user base will increase as modernized ADCP-hosted AOC applications are adopted for operations across more AOCs (from two currently to six or more); the ADCP infrastructure is updated and fully migrated to the cloud as well as to a cloud-connected edge architecture; and ADCP operations centers to provide robust 24/7/365 operational user support, to include but not limited to day-2 support of platform services.
Since ADCP’s production environments support multiple classification levels, the Government anticipates associated increased requirements for cleared personnel, working in classified facilities, on sensitive and classified systems in Impact Levels (IL) 4 and 5, (predominantly Department of Defense (DoD) Secret, IL6) systems, with the requirement to include access to the Joint Worldwide Intelligence Communication System (JWICS) during the course of this contract. Further, the Government has a requirement to host and maintain applications supporting Special Access Programs (SAP) and the sharing of sensitive information with coalition partners such as members of the North Atlantic Treaty Organization (NATO). Specific security requirements will be provided in the TO specific DD Form 254.
3.0 PERIOD AND PLACES OF PERFORMANCE:
The period of performance will be a base period of one (1) year, followed by four (4) option periods of one (1) year duration each. However, it is at the sole discretion of the Government whether to exercise any of the option periods associated with this effort.
The primary places of performance shall be Hanscom Air Force Base, Massachusetts and
Langley Air Force Base, Virginia. However, contractors may be allowed to perform remotely from locations other than the primary places of performance.
It is anticipated that TOs will be issued that require the contractor to have access to and work with classified materials. In those cases where the TO calls for working with classified materials, the Government may provide classified workspaces for the contractor to perform within.
However, when classified Government workspaces are not available, the contractor shall provide their own classified workspaces accredited to the classification level prescribed within the TO DD Form 254 and meeting any associated functional and/or level of service requirements as determined per the applicable TO.
The contractor shall be able to meet the following minimum requirements for classified space available to support ADCP critical mission functions.
- Minimum number of seats 45 (40 seats to be staffed eight (8) hours per day from 0800 – 1600
EST)
- Minimum number of seats supporting 24/7/365 operations
5 (this number is included in the minimum number of seats quantity of 45)
- Minimum network connectivity available at each seat:
- Non-classified Internet Protocol
- Router/Secret Internet Protocol
Router (NIPRNet/SIPRNet) with access to JWICS
- Voice Over IP (VOIP)
- Secure Voice Over IP (SVOIP)
- Minimum Facility Classification Level:
Final Top Secret
- Additional Minimum Requirements: - Existing Special Access Program (SAP) certified physical space capable of supporting IT operations
- Secret open storage or Sensitive Compartmented Information Facility (SCIF) facilities with NIPR/SIPR and JWICS capabilities
NOTE: The minimum number of seats do not all need to be available at one location.
Individual TO(s) may require some classified support to be provided in Outside the Continental United States (OCONUS) locations. In those circumstances, the Governmentwill provide the classified spaces for the contractor to perform in.
Prior to engaging in work outside the primary places of performance, the contractor shall receive approval from the Contracting Officer (CO) and Contracting Officer’s Representative (COR) for those alternate locations.
Additional locations, both within the Continental United States (CONUS) and OCONUS may be added in the future and will be annotated within the specific TO requirements documentation.
4.0 PERFORMANCE OBJECTIVES:
4.1 Platform Architecture and Systems Engineering
● Architecture and Standards:
o The contractor shall provide industry best practices and recommendations pertaining to architecture and engineering standards and facilitate implementation.
o The contractor shall provide architecture guidance pertaining to Government systems including but not limited to cloud design, edge solutions and on-premises/cloud integrations.
o The contractor shall create, aggregate, and update ADCP architecture drawings for all systems in Cameo or other Government approved software. Drawings shall be sourced from multiple tools, systems, and teams.
o The contractor shall ensure all requirements pertaining to architecture drawings in the associated TO(s) are followed. This includes but is not limited to dependency mappings, application or network drawings, cloud account structures, etc.
o The contractor shall develop and/or assist in the development of standards for test strategies, plans and coordination to support all platform engineering and operations.
o The contractor shall ensure development and operational standards are provided and followed as per associated TO(s).
● Cloud and Application Migration:
o The contractor shall discover, analyze, and migrate all on-premises systems to the cloud.
o The contractor shall assist with the migration and refactoring of applications currently on older platforms to the Air Force’s desired cloud platforms as set forth in associated TO(s). (Including but not limited to Broadcom Tanzu to the Hardened Application Platform (Kubernetes)).
o The contractor shall create, organize, and maintain documentation and drawings related to migration efforts.
o The contractor shall provide solutions and implementation for multi-cloud environments as required by the Government and set forth in associated TO(s).
4.2 Cloud, Cloud Edge and Infrastructure support:
4.2.1 The contractor shall provide cloud management, to include but not limited to, manage cloud accounts, Infrastructure as Code (IaC) (e.g. Terraform), Zero Trust, identity access management to IL4/5/6 and Joint Worldwide Intelligence Communication System (JWICS) (Top Secret). The contractor shall have experience with developing, managing, operating and automating pipelines for deployment as well as the developer experience via Identity Management: IAW DoD Identity, Credential, and Access Management (ICAM) strategy.
Additionally, 24/7/365 support of the infrastructure shall be performed by the contractor.
AFLCMC/C3C’s goal is to leverage platform tools and services widely used within the DoD and Department of the Air Force (DAF) for web-based DevSecOps platforms that manage software development, security, and deployment, as well as Identity and Access Management. Whenever possible, solutions from other DAF Battle Network service providers, to include but not limited to Advanced Battle Management System (ABMS), Cloud Based Command and Control (CBC2) and DAF Cloudworks, shall be sourced, used, and supported to ensure consistency, alignment, and enablement of potential merges and/or federations including the support of those efforts.
Prior to the implementation of any platform tools, the contractor shall receive written approval from the Contracting Officer (CO).
The current Cloud Services Provider (CSP) is Amazon Web Services (AWS) and is used in follow-on language, but flexibility to use other CSPs is required for the future. Multiple functional environments are provisioned including test, exercise or training, staging, and production with the goal of environment parity for rapidly deployed cloud-native applications across impact levels and releasabilities (e.g. NOFORN, FVEY, NATO, RELKOREA).
4.2.1 On-Premises Infrastructure
The current ADCP on-premises infrastructure currently owned, operated and maintained by the Government is migrating to cloud environments but may continue to be maintained for the foreseeable future. The Government reserves the decision to re-implement on-premises infrastructure as directed by AFLCMC/C3C and the contractor shall support future development, deployment, maintenance and operations if on-premises infrastructure remains a piece of the DAF Battle Network infrastructure strategy.
4.2.2 Edge Infrastructure
• All environments shall be supportable on the Government’s chosen edge platforms.
Platforms may be provided by other Government partners such as Advanced Battle Management Systems-Digital Infrastructure (ABMS-DI), DAF Cloudworks, or natively developed and deployed by the ADCP program.
• The contractor shall perform integration of tenant applications, such as the Kessel Run All Domain Operations Suite (KRADOS), to edge equipment. The contractor shall work with site networking, security, IT teams for connectivity and proper operation of tenant applications on edge devices.
• The contractor shall work with AFLCMC/C3C and mission partners to enable Denied Disrupted Intermittent and Limited (DDIL) operations on edge equipment.
• The contractor shall work with AFLCMC/C3C and partner data teams to test, validate, and ensure proper synchronization, replication, backup and restoration of data.
4.3 Platform Engineering and Operations
4.3.1 Platform Engineering
• The contractor shall ensure that all environments shall be definitely secure, resilient, scalable, durable, operational and available to withstand ruthless efforts of a peer advisory to disrupt operations. All environments shall be kept in as full feature parity and architecture parity as possible using IL6 as the lowest common denominator and shall meet all requirements set forth in the associated TO(s).
• The contractor shall ensure that all IaC, Continuous Integration/Continuous Delivery (CI/CD) orchestration, security practices and software development practices meet all requirements set forth in the associated TO(s). The contractor shall provide a full path to production to include developer/development tools approved under the continuous Authority to Operate (c-ATO) and fully automated CI/CD pipelines (to meet all requirements necessary for c-ATO from the unclassified development environment to Top Secret environments.
• 100% of code, whether IaC, Big Bang, or other supporting software shall be stored in a code repository, be revisioned, change controlled, and be controlled by AFLCMC/C3C, and visible to its partners, when necessary.
• The contractor shall be responsible for observability, monitoring, and alerting of platforms and applications in all environments, and all applications shall be connected to AFLCMC/C3C managed tools/clusters. Additional requirements for dashboards, data observability, and Security Information and Event Management (SIEM) integration are set forth in the associated TO(s).
• Any vendor-specific Intellectual Property (IP) shall be decoupled from all other code so that any future changes to projects keep any platform, software, or service under the Government’s control.
• In the event that contracts do not continue by either party, there shall be a mechanism for the Government to retain control of the platform, software, or service supporting all Government applications and tools.
• The mechanism to retain control of platform, software, or services supporting all
Government applications and tools shall include training of applicable Government personnel to a level where there is zero disruption to Warfighter applications and operational support.
• Upon request, the contractor will provide the Government with a Portability Plan IAW Contract Data Requirements List (CDRL) A001. Specifically, the Portability plan shall identify, in the form of user instructions, the complete set of processes and procedures that are necessary to extract all of the Government’s data, without restrictions or dependencies, imposed by the contractor.
CDRL A001 Portability Plan / DI-NDTI-80603A
4.3.2 Development and Deployment
• The contractor shall continuously develop, improve, and deploy containerized applications to any Kubernetes environment (unclassified and classified) via integration with the Kessel Run or other AFLMC/C3C tooling release and deployment tools, (e.g.
Release and Deployment Dashboard (RADD)).
• The contractor shall ensure the availability of the tooling required to enable services provided by ADCP (e.g. GitLab, Nexus, Vault, etc.).
• The contractor shall develop, maintain, upgrade release and deployment tools that offer self-service and automation, making it easy for both developers and operators to observe the state of applications across the ADCP or its users and their applications.
• The contractor shall ensure that pipelines are available to perform the building, security scanning, and releasing functions required to enable a CI/CD workflow for conformance with the ATO.
4.3.3 Operations
• The contractor shall provide 24/7/365 operation center supporting: Network/Platform Operations Center (NOC) providing operational support. Operational support includes but is not limited to: Observability, monitoring, alerting of platforms, services and applications in all environments, system/service upgrades or other maintenance. This includes incident response, management, troubleshooting and outage support and resolution with response times in-line with the Government’s incident management process. This location will support classified work with SIPR access and SVOIP and NIPR and VOIP. Additional requirements will be set forth in associated TO(s).
4.3.4 Support
• The contractor shall be responsible for all maintenance, upgrades, updates and support
(hardware and software) in all environments in compliance with ATOs, c-ATO, to include any required credentials and access to Secret and Top-Secret environments.
• The contractor shall provide support for all incidents related to the platform, its infrastructure, services, and/or applications and all support will be 24/7/365 and manned as set forth in associated TO(s).
• The contractor shall facilitate optimization of DevSecOps as appropriate by developing self-service capabilities for ADCP and/or its associated users. This includes but is not limited to configuration, access, playbooks/runbooks. Additional requirements will be set forth in associated TO(s).
• Where applicable, the contractor shall provide services in accordance with Service Level Agreements (SLA) as outlined in associated TO(s).
• A list of SLAs applicable to this PWS and subsequent TO documents, to include monitoring frequency, is as follows. Specific SLA performance metrics to be achieved by the contractor will be provided at the TO level.
Service-Level Agreements
SLA Category SLA Title Monitoring Frequency
Application Support Application Performance
Monthly
Application Support Minor Enhancements Monthly Application Support Defect Management Monthly Application Support Release Deployment Monthly Application Support Success Rate Monthly Application Support Velocity Monthly
Cross-Functional Project Completion- Timeliness
Monthly or Quarterly
Cross-Functional Project Completion- Budget
Monthly or Quarterly
Cross Functional Incident-Priority 1 Restoration (Mission
Critical)
Monthly
Cross Functional Root Cause Analysis Remediation
Monthly
Data Center Disaster Recovery
(DR) – RPO
Monthly
Data Center Security Patch Management
Monthly
Data Center Critical System Stability
Monthly
Data Center Critical System Reliability
Monthly
Data Center Disaster Recovery
(DR) – RTO
Quarterly
Data Center Timeliness – Data Backup
Monthly
Governance % of Tasks Automated
Monthly
Governance Overall Satisfaction with the Services
Provided
Quarterly
IaaS & PaaS Instance Availability (IaaS)
Monthly
IaaS & PaaS Platform Availability (PaaS)
Monthly
IaaS & PaaS Utilization Monthly Network Critical
Segment/Location Stability
Monthly
Network Critical System Reliability
Monthly
Network Guaranteed Mean Time to
Repair/Restore
(MTTR)
Monthly
Network Service Delivery/On- Time Provisioning
Monthly
Network Monitoring Availability
Monthly
Security SIEM Use Case Refresh Rate
Monthly
Security Testing of Vulnerabilities and Penetration Service
Level
Monthly
Security Priority 1 Security Incident Containment
Monthly
Security Priority 1 Security Incident Response
Monthly
Security Threat Notifications Monthly Security Firewall Updates Monthly
Service Desk Account/User Administration-
Change
Monthly
Service Desk Account/User Administration-
Emergency
Monthly
SIAM Critical SLAs Missed Monthly
SIAM KPIs Missed Monthly Software Asset Cloud Instances
Under Management Monthly
• The contractor shall provide a support process that includes but is not limited to a defined tiered support model for platform and supporting services as well as a defined shared responsibility model. (e.g., a detailed accounting of support (to include tier-level)) that is the responsibility of the contractor, the responsibility of AFLCMC/C3C, and responsibility that is shared.)
4.4 Security/Cyber Security
• The contractor shall ensure that all AFLCMC/C3C cyber security policies and requirements are followed and implemented. This includes but is not limited to integrating with AFLCMC/C3C’s Zero Trust requirements and identity aware proxy.
Specific additional requirements to be met are set forth in the associated TO(s).
• Proposed platform and pipeline solutions shall be ATO compliant in order to meet production mission needs. To that end, the platform and pipelines shall not only meet the requirements of an ATO/c-ATO grant but must have an ATO.
• Cloud security vulnerability:
o The contractor shall audit and close security hub findings on all cloud accounts o The contractor shall manage all Plan of Action and Milestones (POAM), create burndown charts tracking progress, remediate findings within the National Institute of Standards and Technology (NIST) guidelines, and provide any supporting documentation for accreditations.
o The contractor shall integrate the assessments and accreditation actions for compliance with the Cloud Cyber Security Engineers o The contractor shall complete the following tasks as directed by the Government:
● Support technical implementation of remediation actions for known security vulnerabilities and system misconfigurations during development and sustainment.
● Work with system administrators, developers, and IT staff to prioritize and plan remediation efforts.
● Evaluate the severity and potential impact of identified vulnerabilities based on industry standards such as Common Vulnerability Scoring System.
● Maintain accurate and up-to-date records of vulnerabilities and their remediation status.
● Track, verify, and document the completion of remediation actions to ensure vulnerabilities are addressed.
● Stay current on latest cybersecurity threats, vulnerabilities, and industry best practices.
● Deliver detailed reports of scan results to the Government, including findings, impacts, and recommended remediation actions.
● Contribute to the development and enhancement of scanning and reporting processes.
● Support monitoring team with incident detection and response
● Support infrastructure team with security engineering solutions
● Be responsible for ensuring that logs from various sources
(Authentication provider, Cyber tools such as CrowdStrike, AWS event logs, etc.) are incorporated into an unclassified and classified
SIEM
4.5 Service Center (Service Integration and Support Management)
• The contractor shall be responsible for stakeholder and relationship management related to customer experience, customer service, ensuring that ADCP products and services are applied and deployed appropriately to meet customer needs.
• The contractor shall utilize ADCP resources in the roles of configuration manager, capacity manager, service desk specialist and others as specified by the associated TO(s) ensuring value creation through IT-enabled services
• The contractor shall be responsible for providing an improved customer experience for the platform and CSP chosen by the Government by supporting employees, developers, and/or application and service teams through the path to production, including but not limited to: documentation, Graphic User Interface (GUI) development, integration assistance, cyber wellness and security hardening, 24/7 support desk capabilities at multiple classification levels, and providing an initial triage point for requests and issues including major and minor incident management.
• The contractor shall ingest and provide recommendations for prioritization of inquiries and issues into ADCP.
• The contractor shall provide continuous testing of both the path to production and the documentation of the path to production to iteratively improve the technical documentation.
• The contractor shall provide additional change & release and incident & problem management as set forth in the TO(s).
5.0 Operating Constraints
5.1 Deliverables
Deliverables are defined as the completion and acceptance according to the “Definition of Done” of the features completed, which are based on the contractor’s Agile Software Development methodology. This methodology defines the repeatable process of providing development outcomes in small iterations which results in the delivery of design, usable software, data, or product, which have little to no inherent defects from the intended implementation. Each outcome shall be defined as Functional Requirements by mutual agreement of the Government and contractor through consistent engagement per Agile Methodology. Functional Requirements shall enforce adherence to the contractor’s Agile Methodology rather than dictate the implementation specifics of a feature. Adherence to the contractor’s Agile Methodology shall result in features that meet the Government’s capability requirements and objectives. Each feature shall document how planning, requirement analysis (user story building), design, coding, testing, quality assurance, and documentation shall all meet the contractor’s “Definition of Done.”
Functional Requirements for each feature, translated into Epics and User Stories shall be used to populate the Product Backlog shall include, but are not limited to:
• Initial application design and implementation
• User research and interviews
• System configuration to support business processes
• Integration for input and output methods
• Workflow design and implementation
• Overall collaboration of applications
• Enhancements, patches, and updates to applications, data, or cloud systems
• Data import of records collected from legacy systems
• Automated testing
• Updating user guides and assessing the impact on existing training material
• User Acceptance Testing
To maintain consistency and quality of products developed and deployed, the contractor shall supply to the Government, when requested, a Software Test Plan (STP), IAW CDRL A002 and Software Test Report (STR), IAW CDRL A003.
CDRL A002 Software Test Plan (STP) / DI-IPSC-81438A CDRL A003 Software Test Report (STR) / DI-IPSC-81440A
5.2 Surge Capacity
The contractor shall have the ability to expand its team quickly to meet an increased demand for services in the event of an emergent requirement or other need per TO(s).
Effective surge capacity requires the coordination of multiple resources to mobilize staff and, in some cases, coordinate with outside resources to fulfill a need. The contractor shall have a surge capacity methodology that discusses a way to diffuse an increased need for personnel within a stated amount of time deemed reasonable by the Government. Any surge capacity issues shall be addressed and/or negotiated through the CO and will be incorporated by TO modification, if needed.
6) GENERAL REQUIREMENTS
6.1 Contract Management
The contractor shall provide all the tools, manpower and support required for successful execution of the contract. The Contractor shall provide recommendations for any additional resources required for successful execution of the contract.
6.2 Contract Manager
The contractor shall have a single point of contact between the Government CO and the contractor to support business relations of each TO. The contractor shall integrate and coordinate all activity required to execute this contract and manage the timeliness, completeness, and quality of problem identification. The contractor shall provide corrective action plans, timely identification of issues, and effective management of subcontractors.
As required by the Government, the Contract Manager shall attend meetings with the Technical Point of Contact (TPOC), Contracting Officer’s Representative (COR) and/or other stakeholders to address any problems or issues that require attention. The meetings may be scheduled regularly or may be ad hoc. The contractor shall provide Meeting Minutes under CDRL A004.
CDRL A004 Meeting Minutes / DI-ADMN-81250C
6.2.1 Program Management
The contractor shall use agile development tools, that will be provided by the Government, to manage the program. The contractor shall propose/recommend innovative collaborative approaches and any additional tools, manpower, and support required for successful execution of the contract. Examples may include, but are not limited to, automated governance and testing methods, virtual engineering support, agile program management processes, and any other support required to ensure mission success. The contractor shall appoint a Program Manager as the single point of contact for the Government COR in support of this effort.
6.2.2 Kick Off and Monthly Meetings
Within fifteen (15) business days of contract award, the contractor shall support a Post Award Conference (PAC) for the Government and team members. The contractor shall introduce team members and staff, and shall present and discuss organizational structure, administrative operations pertinent to this contract, technical approaches and preliminary plans for performing contract tasks, format of reports and quarterly reviews, and a general overview of the overall approach to execute this contract.
The contractor shall support quarterly Program Management Reviews (PMR). These quarterly meetings with the Government shall discuss, at a minimum, the overall cost, schedule, and performance of this effort. The Government reserves the right to increase the frequency of these meetings when deemed necessary.
CDRL A004 Meeting Minutes / DI-ADMN-81250C CDRL A005 Briefing Materials / DI-MGMT-81605 CDRL A006 Meeting Agenda / DI-ADMN-81249C
CDRL A007 Status Report / DI-MGMT-80368
6.3 Financial Reporting Requirements
Based on the TO requirements issued by the Government, the contractor shall submit cost/financial reports in accordance with CDRL A0087 and A009.
CDRL A008 Funds and Man-Hour Expenditure Report / DI-FNCL-80331A CDRL A009 Contract Funds Status Report / DI-MGMT-81468
6.4 Additional Reporting Requirements
Based on the TO requirements issued by the Government, the contractor shall submit technical and programmatic reports in accordance with CDRLs A010, A011, A012, A013. A014, and A015 when applicable.
CDRL A010 Technical Report - Study/Services / DI-MISC-80508B CDRL A011 Product Roadmap / DI-IPSC-82297 CDRL A012 Product Backlog / DI-IPSC-82298 CDRL A013 Integrated Program Management Data and Analysis Report / DI-MGMT- 81861C
6.5 Phase-In Transition Plan
The Government’s intent is to provide a phase-in transition period of (nominally, pending further review) 90 calendar days, at the end of which the Government will require the contractor to be fully operational, to include properly cleared personnel at the appropriate classification levels, operational contractor-provided workspaces, and availability of all required IT systems/connectivity. The contractor’s transition plan shall include:
• Identification, by name, position, and responsibilities, of each team member on the Transition Team.
• A schedule with detailed tasks, milestones, and completion dates for each activity. Status shall be reported at a minimum of 15 calendar day increments.
• Plan for recruitment, hiring, and onboarding of personnel, to include security clearances and system accesses.
• Description of risks, dependencies, and mitigation measures, as appropriate.
• In addition to status reporting, the Contractor shall present an operations readiness review approximately thirty (30) days prior to the projected operational “go live” date, with updates as required to secure Government approval for the final “go live” decision.
CDRL A014 Phase-In Transition Plan / DI-SESS-82299
6.6 Phase-Out Transition Plan
The contractor shall develop a Phase-Out Transition Plan to facilitate the accomplishment of a seamless transition from an incumbent to incoming contractor/Government personnel at the expiration of the final performance period. This plan defines actions needed for an effective transition, to include agreed knowledge capture, transition artifacts, and transfer to ensure programmatic and technical continuity. The contractor shall provide a Phase-Out Transition NLT one hundred eighty (180) business days prior to expiration of the performance period. In the event an option is not exercised, the contractor will provide a Phase-Out Transition plan at the direction of the Government within a reasonable, mutually agreed-upon timeframe. The contractor shall establish and maintain effective communication with the incoming contractor/ Government personnel for the period of the transition via weekly status meetings and other interactions determined necessary by the Government. The contractor shall identify how it will coordinate with the incoming contractor and/or Government personnel to transfer knowledge, including but not limited to, the following:
• Project management processes
• Points of contact
• Location of technical and project management documentation
• Status of ongoing technical initiatives
• Appropriate contractor-to-contractor coordination to ensure a seamless transition
• Transition of key personnel (if applicable)
• Schedule and key milestones for transition
• Actions required of the Government to facilitate transition
CDRL A015 Phase-Out Transition Plan / DI-MGMT-81945A
6.7 Sub-Contracting
The contractor shall be responsible for any subcontract management necessary to integrate work performed on this contract and shall be responsible and accountable for sub-contractor performance.
6.8 Business Relations
The contractor shall have a single interface, which can be the Program Manager, between the Government and contractor personnel to support business relations. The contractor shall integrate and coordinate all activities required to execute this contract and manage the timeliness, completeness, and quality of problem identification. The contractor shall provide corrective action plans, timely identification of issues, and effective management of sub-contractors.
6.9 Recognized Holidays
The Government acknowledges the following Federal Holidays:
• New Year’s Day
• Memorial Day
• Columbus Day
• Martin Luther King Jr.’s Birthday
• Independence Day
• Veteran’s Day
• President’s Day
• Labor Day
• Thanksgiving Day
• Christmas Day
• Juneteenth National Independence Day
The Government acknowledges that, in addition to the days designated as holidays above, the Government observes the following days:
• Any other day designated by Federal Statute
• Any other day designated by President's Proclamation
• Any other day designated by Executive Order
The contractor understands and agrees with the Government that observance of such days by Government personnel shall not otherwise be a reason for an additional period of performance, or entitlement to compensation except as set forth within the contract.
If the contractor believes that an unplanned absence has an impact on the price or period of performance, the contractor shall notify the CO of the changed condition.
6.10 Risk Management
The contractor shall implement a comprehensive risk management program throughout the performance of this contract, adhering to the principles and guidelines set forth in DoDI 8510.01, “Risk Management Framework for DoD Systems,” and the DoD Risk, Issue, and Opportunity (RIO) Management Guide.
The contractor shall utilize its risk management procedures, techniques, controls, and metrics to provide for the early identification of program risks. The contractor shall provide telemetry within ADCP that helps to identify and quantify performance, schedule, and cost risks. The contractor shall be responsible for recommending appropriate risk mitigations. Risks shall be a topic of discussion during the quarterly PMR meetings identified in paragraph 6.2.2.
The contractor shall provide a Risk Management Plan IAW CDRL A016. The contractor’s Risk Management Plan will be used to monitor management, cost and schedule of the contract efforts relative to a system and equipment. This information will provide the Government with risk data for all risks associated with the system/equipment.
CDRL A016 Risk Management Plan / DI-MGMT-81808
The contractor shall provide a Risk Management Status Report IAW CDRL A017. The contractor’s Risk Management Status Report will be used to document the contractor’s progress for: risk identification; risk mitigation planning: risk management plan implementation; and risk tracking. This data will allow the Government to make informed decision.
CDLR A017 Risk Management Status Report / DI-MGMT-81809
6.11 Supply Chain Risk Management (SCRM) Program
The contractor shall implement and maintain a robust SCRM program aligned with industry best practices. The contractor shall implement a supplier performance monitoring program to assess and mitigate risks associated with supplier capabilities and reliability. The contractor shall provide regular reports on supply chain risks and mitigation efforts.
The contractor shall continuously improve its supply chain risk management program based on lessons learned and industry best practices. Further, the contractor shall mitigate acquisition SCRM for new and technical refreshes by using existing department of Air Force and DoD Blanket Purchase Agreements (BPA) outlined in DAFMAN17-1203 and the AFLCMC/C3C Kessel Run Acquisition Directive.
CDRL A018 Supply Chain Risk Management Plan / DI-MGMT-82256
6.12 Travel
The contractor may be required to travel to various locations within CONUS and OCONUS in performance of this contract, with all travel arrangements pre-approved by the CO or COR.
If remote, the contractor shall be required to access and process classified data at an Air Force installation or a SIPR location. Reimbursement costs for this travel type will not be allowable under the contract.
The contractor shall complete a Travel Authorization Request (TAR) prior to all travel. A sample document will be provided upon contract award. The Government may reference Joint Travel Regulations (JTR) as a guide for price reasonableness of travel costs during the travel approval process.
The contractor shall travel using the lowest cost mode transportation commensurate with the mission requirements. When necessary to use air travel, the contractor shall use the tourist class, economy class, or similar accommodations to the extent they are available and commensurate with the mission requirements.
All travel invoiced against this or any subsequent TOs shall be on a cost reimbursement basis to include General and Administrative (G&A) expenses but shall not include the contractor’s fees or any other overhead expenses.
The contractor shall use the Synchronized Pre-deployment and Operational Tracker (SPOT) web-based system, to enter and maintain the data for all Contractor Accompanying Armed Forces (CAAF) and, as designated by USD (AT&L) or the Combatant Commander, non-CAAF supporting U.S. Armed Forces deployed outside the United States. Under this contract, the contractor will be designated as non-CAAF. All contractor personnel traveling to the applicable OCONUS locations shall be responsible for completion of all required training prior to deployment. Refer to DFARS PGI 225.370(b) for any travel to Korea; DFARS PGI 225.370(d) for any travel to Qatar; and the Army in Europe Regulation 715-9 for any travel to Germany.
Within five (5) business days of trip completion, the contractor shall provide a trip report to the COR IAW with CDRL A017.
CDRL A019 Trip/Travel Report / DI-MISC-81943
6.13 Data Management
The contractor shall establish, document, and maintain all data for the program and provide data in accordance with CDRL A018 and A019. The contractor shall use sound data management discipline for developing, acquiring, controlling and delivering all required technical, management, and other data. The contractor shall ensure on-time delivery of data; data quality;
accurate updates/revisions and corrections to data as required; and proper identification.
CDRL A020 Computer Software Product / DI-IPSC-81488 CDRL A021 Computer Software End Item Documentation / DI-IPSC-80590B
6.14 Electronic Data Interchange (EDI)
The contractor shall provide an electronic, secure, on-line access point for delivery of contractor prepared CDRLs to the Government. All CDRL items shall be posted on the contractor’s data delivery access point and available for Government download no later than the delivery date specified by the applicable CDRL item. The contractor shall notify the CDRL item distribution e-mail addresses (via email) when each CDRL item has been posted and is available for Government access/download. The contractor shall follow Government approved open standards for all EDI protocols, files, and formats.
The contractor shall prepare/submit CDRL documentation in electronic formats compatible with Microsoft Office 365 suite of applications, unless a different format is directed for specific CDRL items. Submission times shall be in accordance with the CDRL requirements. This requirement does not preclude contractor delivery of hard copy and/or CD ROM copy CDRL items as required IAW with applicable CDRL instructions.
6.15 Government Furnished Equipment (GFE)/Government Furnished Property (GFP)/Government Furnished Information (GFI)
As required by TO specific requirements, the Government may furnish the contractor with GFE/GFP. Any other items required to perform or meet requirements within this, or any individual TOs, shall be provided by the contractor. The contractor shall comply with GFE and/or GFP guidelines as outlined in DAFMAN 17-1203, DoDi5000.64, DoDi5000.76, and applicable DFARS requirements and DoD Instructions. The contractor shall be responsible for immediately reporting all condition changes associated with the loaned GFE/GFP to the CO, COR, and Government ECO personnel. A GFE/GFP list will be provided with the TO information as applicable.
MAINTENANCE and REPAIR - The contractor shall provide maintenance agreements or service contracts to keep all GFE/GFP operational for the duration of the contract and shall ensure that any long-term maintenance agreements can be transferred to the Government upon completion or termination of the contract.
CDRL A022 Government Property (GP) Inventory Report / DI-MGMT-80441D CDRL A023 Government Furnished Equipment Detail Transaction Status / DI-MGMT- 80377 CDRL A024 Government Furnished Equipment Inventory Report / DI-MGMT-82173
6.16 Contractor Acquired Property (CAP)
In some circumstances the Government may instruct the contractor to purchase or fabricate property for use on the contract, or subsequent TOs, to which the Government will have title.
If the contractor is instructed to purchase or fabricate property for use on the contract, or subsequent TOs, the contractor shall manage the property according to the Government Property clause, or other cited clauses.
Any property acquired or fabricated by the contractor shall be marked with and adhere to an Item Unique Identification (IUID) marking plan that details a comprehensive strategy for marking items requiring unique identification in compliance with this contract and stated clauses.
This plan shall encompass the marking of both items and packaging, covering methodology, encoding, data management, facilities, equipment, registration, quality assurance, and a master schedule.
The plan shall specify marking methods for various items, IUID construction, data elements, label/plate specifications, legacy part handling, and adherence to relevant standards. Furthermore, the plan shall detail quality assurance processes for marking accuracy, reporting, and replacement, as well as data management procedures for registration, repairs, and UII assignment. A master schedule outlining key milestones for plan submission, approval, and marking execution shall be included.
This comprehensive plan ensures accurate and complaint IUID marking, enabling efficient tracking, accountability, and lifecycle management of Government property.
CDLR A025 Item Unique Identification (IUID) Marking Plan / DI-MGMT-81803A
6.17 Procurement
6.17.1. The Contractor shall procure materials, as directed and approved by the Government, to support integration, modification and fielding activities to include software warranties, software licenses, and other articles for the Contractor and Government facilities and enterprise sites.
6.17.2 The Contractor shall ensure full transparency with the Government on software procurements, to include licenses and warranties.
6.17.3. The Contractor shall work with the Government to ensure that all software purchases reduce future transfer liability to the maximum extent possible.
6.17.4. The Contractor shall purchase perpetual software licenses to the maximum extent possible.
6.17.5. The Contractor shall procure all materials in support of the requirements in this PWS in the most cost-effective manner, to include use of Government supply sources, such as the DoD Enterprise Software Initiative (ESI), when they are determined to be the most cost-efficient source.
6.17.6. The Contractor shall submit a Bill of Material (BOM) or a Software Bill of Material (SBOM) to the Government for approval prior to purchases in an approved format.
6.17.7. The Contractor shall provide regular status updates on the procurement to the Government.
At the time of procurement delivery, the Contractor shall provide, at a minimum, the following to the Government:
• Terms of coverage for support, warranty, and license(s)
• Description of services provided by original equipment manufacturer (OEM)
• Shipping tracking information (if applicable)
• Serial numbers (for modular components include serial numbers for all modules/sub-modules) and license key information
• Software product registration information
6.18 Security Requirements
The contractor performing work under this contract shall comply with all applicable security requirements set forth in this document.
The contractor shall deliver the following items on or before the designated due dates:
1. Security Compliance Report – A detailed report on compliance with the security regulations outlined in 32 CFR Part 117, FAR, and DFARS clauses. This report shall be updated quarterly.
CDRL A026 Security Compliance Report / 32 CFR 117
2. Cyber Incident Reports – In the event of a cyber incident or breach affecting covered information, the contractor shall submit an incident report within 48 hours as outlined in
DFARS 252.204-7012.
CDRL A027 Cyber Incident Report / DFARS 252.204-7012
3. System Security Plan (SSP) – The contractor shall provide a comprehensive SSP detailing all cybersecurity controls and measures implemented to safeguard Covered Defense Information and contractor systems in accordance with DFARS 252.204-7012 and FAR 52.204-21.
CDRL A028 Contractor’s System Security Plan / DI-MGMT-82247
4. Cloud Computing Services Evaluation – The contractor shall provide a detailed evaluation and certification that any cloud computing services used under this contract meet the requirements of DFARS 252.239-7010.
CDRL A029 Cloud Computing Services Evaluation / NIST SP 800-145
5. Contractor Responsibilities - The contractor shall ensure all personnel performing work under this contract have the appropriate security clearances and are trained on the safeguarding of Covered Defense Information (CDI) and Controlled Unclassified Information (CUI).
The contractor shall continuously monitor, evaluate, and assess the security of systems used to process, store, or transmit sensitive information, in compliance with the applicable contract clauses.
The contractor shall work closely with the COR to ensure ongoing compliance and report any non-compliance issues promptly.
6.18.1 Security Clearance Requirement
The contractor shall perform these services in compliance with all applicable regulations, including those specified in 32 CFR Part 117 as well as those applicable regulations found with the contract specific Federal Acquisition Regulations (FAR) and Defense Federal Acquisition Regulation Supplement (DFARS).
Within 60 days of the employee's performance on this contract, personnel without a Secret security clearance shall obtain an interim Secret security clearance. All contractor personnel shall be US citizens. In the event a TO requires the need for TS/SCI clearances, contractor personnel shall obtain an interim TS/SCI clearance within 120 days of direction.
6.18.2 DoD Contract Security Classification Specification
A DD Form 254 will be issued in support of this TO. The contractor shall hold a minimum Facility Security Clearance (FCL) of Top-Secret.
6.18.3 Operations Security (OPSEC)
The contractor shall ensure OPSEC is incorporated into the appropriate area of the contract IAW DoD Directive 5205.02E, DoD Operations Security (OPSEC) Program and
AFI 10-701, Air Force OPSEC Program. The contractor shall flow down all OPSEC requirements to sub-contractors that handle Critical Information (CI). CI is defined as specific facts about friendly intentions, capabilities, or activities needed by adversaries to plan and act effectively against friendly mission accomplishment.
6.18.4 Controlled Unclassified Information (CUI)
The contractor shall adhere to the following regulatory requirements: 3.1 32 CFR, Part 117
– Controlled Unclassified Information (CUI) The contractor shall comply with the provisions of 32 CFR, Part 117, which governs the safeguarding of Controlled Unclassified Information (CUI). This includes but is not limited to:
• Properly marking and handling CUI in accordance with applicable regulations.
• Reporting incidents of potential or actual CUI compromise or loss.
• Controlled Unclassified Information (CUI) is any information that law, regulation, or Government wide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.
• The National Archives and Records Administration (NARA) CUI Registry
(http://www.archives.gov/cui/registry/category-list.html) identifies approved CUI categories and subcategories, provides general descriptions for each,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .