Attachment 1 - DRAFT PROTECTS II PWS.docx
DOCX document 238 KB Posted
- Attached to
- PROTECTS II Federal contract opportunity
- Solicitation number
- 2032H5-26-Q-000001
About this file
This document is a Draft Performance Work Statement (PWS) for the PROTECTS II Blanket Purchase Agreement (BPA) from the Department of the Treasury. The single-award BPA will provide enterprise-level cybersecurity services from 2025-2035, enabling the Treasury to issue Call Orders across 23 distinct cybersecurity task areas including security risk management, incident response, identity and access management, threat intelligence, DevSecOps, and AI cybersecurity enablement. The BPA is designed to support Treasury's cybersecurity resiliency initiative, comply with federal mandates like FISMA and Executive Order 14028, and align with NIST risk management frameworks.
Key performance details include a 10-year maximum period of performance with annual option periods, a TBD ceiling price, and a modular approach allowing flexible task ordering. The PWS requires comprehensive cybersecurity services spanning governance, risk management, continuous monitoring, secure engineering, workforce development, and critical infrastructure protection. Contractor personnel may work on-site, remotely, or in hybrid arrangements, with security clearance requirements varying by task sensitivity. The government will issue specific Call Orders under the BPA, with each order defining precise scope, deliverables, performance expectations, and pricing arrangements. The solicitation is currently in a Request for Information (RFI) phase, with industry feedback due by 10 June 2025.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 - PROTECTS II RFI Questions Comments.xlsx | XLSX spreadsheet | |
| Attachment 3 - PROTECTS II RFI.docx | DOCX document | |
| Attachment 4 - Draft PROTECTS II Special Notice.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED//FOUO
EXECUTIVE SUMMARY
This Single-Award Blanket Purchase Agreement (BPA) establishes a flexible and streamlined acquisition framework for enterprise-level cybersecurity services under the Department of the Treasury’s Resiliency initiative. Built in accordance with FAR 8.405-3, the BPA provides a mechanism for issuing Call Orders that address evolving cybersecurity needs, enable rapid response to threats, and execution compliance with federal mandates including FISMA, Executive Order 14028, and NIST’s Risk Management Framework. Task areas span governance, risk, and compliance (GRC); continuous monitoring and assessment; identity and access management; incident response; security engineering; and strategic planning. This BPA is designed to maximize agility while maintaining oversight, performance accountability, and alignment with Treasury’s enterprise cybersecurity goals.
Contents
| 1. Agreement Type | 4 | |
| 2. Parties to the Agreement | 4 | |
| 3. Scope of Work | 5 | |
| 4. Period of Performance | 5 | |
| 5. Ceiling Price | 5 | |
| 6. Ordering Procedures | 5 | |
| 7. Performance and Deliverables | 6 | |
| 8. Invoicing | 6 | |
| 10. Point of Contact | 6 | |
| 11. BPA Number | 7 | |
| 12. Modular Performance Work Statement (PWS) | 7 | |
| 12.1 Introduction | 7 | |
| 12.2 Scope of Services | 7 | |
| 12.3 Modular Task Areas | 8 | |
| 12.3.1 | Security Risk Management | 8 |
| 12.3.2 | Governance, Compliance, and Audit Execution | 8 |
| 12.3.3 | Continuous Monitoring (ISCM) | 8 |
| 12.3.4 | Identity, Credential, and Access Management (ICAM) | 8 |
| 12.3.5 | Incident Response and Recovery | 8 |
| 12.3.6 | Security Engineering and Orchestration | 8 |
| 12.3.7 | Threat Intelligence and Analytics | 8 |
| 12.3.8 | GRC Platform Integration and Risk Reporting | 8 |
| 12.3.9 | Workforce Development and Strategic Planning | 8 |
| 12.3.10 | CDM Architecture and Sensor Integration | 8 |
| 12.3.11 | Security Program Planning | 8 |
| 12.3.12 | Risk Quantification and Analytics | 8 |
| 12.3.13 | High Value Asset (HVA) Protection | 9 |
| 12.3.14 | Critical Infrastructure Protection | 9 |
| 12.3.15 | Security Data Aggregation & Analytics | 9 |
| 12.3.16 | DevSecOps & CI/CD Supply Chain Security | 9 |
| 12.3.17 | Security Resilience & Chaos Engineering | 9 |
| 12.3.18 | Enterprise Identity and Systems Integration | 9 |
| 12.3.19 | Cyber Policy and Governance Management | 9 |
| 12.3.20 | Communications Security (COMSEC) Execution | 9 |
| 12.3.21 | Program Management Office Operations | 9 |
| 12.3.22 | AI Cybersecurity Enablement | 9 |
| 12.3.23 | Transition Planning and Execution | 10 |
| 12.4 Deliverables and Reporting | 10 | |
| 12.5 Applicable Laws and Standards | 10 | |
| 12.6 Work Location and Telework Guidelines | 12 | |
| 14.2 Appendix B – Task Area to Call Order Crosswalk | 14 | |
| 14.3 Appendix C – Reporting and Deliverable Templates | 16 | |
| 14.4 Appendix D – Security Clearance and Onboarding Requirements | 17 | |
| 14.5 Appendix E – Invoicing Instructions and IPP Guidance | 19 | |
| 14.6 Appendix F – Policy and Regulatory References | 21 | |
| 14.7 Appendix G – Clause Matrix | 23 | |
| 15. Quality Assurance Surveillance Plan (QASP) | 25 | |
| 16. Quality Control Plan (QCP) | 27 | |
| 17. Contract Data Requirements List (CDRL) | 30 |
1. Agreement Type This Blanket Purchase Agreement (BPA) is a Single-Award BPA established under the authority of Federal Acquisition Regulation (FAR) Part 8-405.3. The BPA enables the Department of the Treasury to acquire a full suite of enterprise cybersecurity technology and services through streamlined ordering procedures. This BPA is not a contract in itself but constitutes a written understanding of the terms under which the Government may issue Call Orders to the Contractor.
All purchases under this BPA shall comply with the terms of this agreement and applicable federal acquisition regulations. Each Call Order issued under this BPA shall be considered a binding contract in accordance with the provisions of FAR Part 8 and the terms outlined herein.
2. Parties to the Agreement This BPA is entered into by and between the:
· Department of the Treasury Office of the Chief Information Officer (OCIO) 1500 Pennsylvania Avenue NW Washington, DC 20220 Acting through an authorized Contracting Officer and
· [Contractor Name] [Contractor Address] [City, State, ZIP] [UEI/CAGE Code] Acting through its authorized representative Both parties agree to the terms and conditions set forth in this BPA and to comply with all applicable laws, regulations, and Treasury-specific requirements. All communications related to this BPA shall be directed through the designated points of contact listed in Section 6 of each individual Call Order.
3. Scope of Work The Contractor shall provide enterprise-wide cybersecurity services to execution the Department of the Treasury’s mission to protect federal information systems, data, and infrastructure. This Blanket Purchase Agreement (BPA) enables the issuance of Call Orders for modular cybersecurity execution aligned with federal standards and evolving threat landscapes.
Work under this BPA may include governance, risk, and compliance (GRC); continuous diagnostics and monitoring; identity and access management; incident response and recovery; security architecture and engineering; threat intelligence; and execution for government-wide cybersecurity initiatives such as DHS CDM and Executive Order 14028.
All work will comply with applicable provisions of the Federal Acquisition Regulation (FAR), the Federal Information Security Modernization Act (FISMA), and guidance issued by the National Institute of Standards and Technology (NIST).
4. Period of Performance The BPA runs from 2025 –2035 (10 years maximum). Task Orders awarded under the BPA can be issued any time prior to BPA expiration.
POP annual periods:
- Base Year: 2025 – 2026
- Option 1: 2026 – 2027
- Option 2: 2027 – 2028
- Option 3: 2028 – 2029
- Option 4: 2029 – 2030
- Option 5: 2030 – 2031
- Option 6: 2031 – 2032
- Option 7: 2032 – 2033
- Option 8: 2033 – 2034
- Option 9: 2034 – 2035
5. Ceiling Price The estimated ceiling value shall not exceed $[TBD].
6. Ordering Procedures All purchases under this BPA shall be made via individually issued Call Orders. Each Call Order must:
· Reference this BPA number in its header
· Define the scope of work clearly, referencing applicable task areas
· Specify deliverables, due dates, and performance expectations
· Establish a period of performance (POP), including start and end dates
· Include firm-fixed pricing, not-to-exceed ceilings, or other pricing arrangements as appropriate Only authorized Government Ordering Officials designated under this BPA may issue Call Orders. Orders may be issued in writing via email or through the designated contract management system. The Contractor shall acknowledge receipt of all Call Orders and begin work in accordance with the terms stated therein.
7. Performance and Deliverables Each Call Order issued under this BPA shall define:
· Specific performance objectives, metrics, and success criteria
· Required deliverables, including format, review cycles, and submission timelines
· Any dependencies, approvals, or Government Furnished Information (GFI) Unless otherwise stated in the Call Order, deliverables shall comply with the standards defined in Section 12.4 of this BPA (Deliverables and Reporting) and be submitted to the points of contact listed in the Call Order. The Contractor is responsible for the timely and accurate submission of all deliverables and for maintaining quality control throughout the performance period.
The Government will assess Contractor performance in accordance with the agreed-upon metrics and may document performance outcomes in CPARS as appropriate.
8. Invoicing Invoices shall be submitted in accordance with the instructions provided in each Call Order and must:
· Include the BPA and Call Order number
· Clearly identify the billing period and any applicable CLINs or deliverables
· Reference the associated deliverable or milestone tied to payment
· Be submitted electronically to the designated Treasury invoicing system (e.g., Invoice Processing Platform (IPP)) The Contractor shall ensure that all invoices are complete, accurate, and submitted in accordance with Treasury Financial Management Policy and FAR 52.212-4(i) (Invoice Instructions). Improper or incomplete invoices may be rejected or returned for correction.
10. Point of Contact Government POC: [Name, Email, Phone] | Contractor POC: [Name, Email, Phone]
11. BPA Number [To be assigned by the Contracting Officer]
12. Modular Performance Work Statement (PWS)
12.1 Introduction
The United States Department of the Treasury is an executive agency responsible for promoting economic prosperity and ensuring the nation’s financial security. Treasury’s activities range from coin and currency production to payment disbursement, revenue collection, and federal debt management.
Resiliency is a Treasury-wide framework that delivers standardized, scalable cybersecurity solutions to Departmental Offices and Bureaus, as well as partner agencies that rely on Treasury for financial management.
12.2 Scope of Services
This BPA covers a comprehensive suite of cybersecurity services designed to improve Treasury’s operational security posture, execution strategic objectives, and ensure continuous compliance with federal cybersecurity mandates.
The Contractor shall deliver execution across the following functional areas:
· Risk identification, analysis, and mitigation using the NIST Risk Management Framework (SP 800-37, 800-30, 800-39)
· POA&M management, risk register updates, and enterprise-level risk dashboards
· Support for system assessments, control testing, and compliance with FISMA and OMB A-130
· Design and implementation of secure architectures, Zero Trust frameworks, and CDM integrations
· Identity proofing, PIV enablement, ICAM modernization, and execution for NIST SP 800-63 guidance
· Incident response planning, playbook execution, threat hunting, and post-event remediation
· Configuration and enhancement of GRC platforms, reporting dashboards, and automated workflows
· Workforce development initiatives mapped to NICE Framework roles and functional gaps Services will be tailored to each Call Order and guided by the Modular PWS task areas outlined in Section 12.3.
12.3 Modular Task Areas
12.3.1 Security Risk Management - Risk categorization, assessments, POA&M tracking, risk dashboards, and audit response execution for enterprise assets, including Filing Season Risk Readiness and Disaster Recovery environments. Enables management of interconnected risk views, upstream/downstream dependencies, and oversight of mission-critical systems. Includes annual oversight process planning, surge execution for emerging risk-related requirements, and alignment with new legislative and executive mandates. (NIST SP 800-30, 800-39, FISMA, EO 14028).
12.3.2 Governance, Compliance, and Audit Execution - FISMA reporting, policy development, audit coordination, compliance (FISMA, OMB A-130).
12.3.3 Continuous Monitoring (ISCM) - Ongoing control assessments, real-time dashboards, ISSO execution (NIST SP 800-137).
12.3.4 Identity, Credential, and Access Management (ICAM) - PIV, MFA, ID proofing, IAL/AAL/FAL requirements (NIST SP 800-63-3).
12.3.5 Incident Response and Recovery - IRP development, exercises, threat detection, forensic execution (NIST SP 800-61r2).
12.3.6 Security Engineering and Orchestration - Zero Trust design, patching automation, secure SDLC (EO 14028, SP 800-160).
12.3.7 Threat Intelligence and Analytics - Threat hunting, IOC analysis, automated reporting and dashboards.
12.3.8 GRC Platform Integration and Risk Reporting - Workflow automation, GRC dashboards, integration of control libraries.
12.3.9 Workforce Development and Strategic Planning - NICE framework alignment, workforce role mapping, planning artifacts.
12.3.10 CDM Architecture and Sensor Integration - CDM implementation, data feed reliability, sensor integration.
12.3.11 Security Program Planning - Strategic program planning, goal alignment, milestone tracking, and performance reporting (OMB A-11, A-130, NIST CSF)
12.3.12 Risk Quantification and Analytics - Quantitative risk modeling, FAIR-based analysis, executive dashboards, and impact-driven prioritization (NIST SP 800-30, FAIR)
12.3.13 High Value Asset (HVA) Protection - HVA identification, DHS reporting, threat modeling, protection planning, and risk register integration (DHS HVA Guidance, OMB M-19-03)
12.3.14 Critical Infrastructure Protection - Identification of mission-critical systems, continuity planning, failover design, and operational resilience (PPD-21, NIST CSF)
12.3.15 Security Data Aggregation & Analytics - Data correlation across CDM, SIEM, asset/vulnerability tools; dashboard development and risk insights (NIST SP 800-137, EO 14028)
12.3.16 DevSecOps & CI/CD Supply Chain Security - Security testing in pipelines, code analysis, dependency scanning, and secure SDLC automation (NIST SP 800-218, EO 14028)
12.3.17 Security Resilience & Chaos Engineering - Resilience validation via controlled disruption, detection testing, and recovery response simulation (NIST SP 800-160v2, EO 14028)
12.3.18 Enterprise Identity and Systems Integration – ICAM lifecycle management, PIV Data Synchronization (PDS), LACS/MFA implementation, GSA MSO coordination, and Zero Trust identity governance (FIPS 201-3, NIST SP 800-63, CDM Phase II)
12.3.19 Cyber Policy and Governance Management – Maintenance of TD P 85-01, SOP drafting, governance workflow facilitation, and alignment with evolving OMB, NIST, and EO 14028 policy requirements (NIST SP 800-53, OMB A-130, EO 14028)
12.3.20 Communications Security (COMSEC) Execution – Cryptographic asset lifecycle management, keying material tracking, NSA/CNSS compliance, SOP development, and inspection readiness (CNSSI 4005, FIPS 140-3, CNSSP No. 1)
12.3.21 Program Management Office Operations – Integrated schedule management, IPT facilitation, risk tracking, executive reporting, document control, and surge PM execution across all BPA Call Orders (PMBOK 7th Ed., GAO Agile Guide, FAR Part 37)
12.3.22 AI Cybersecurity Enablement - AI/ML system risk assessments, secure DevSecOps pipeline integration, model access controls, bias and privacy evaluations, and AI governance policy development in alignment with NIST AI RMF, EO 14110, and OMB M-24-10.
12.3.23 Transition Planning and Execution - Planning and execution of transition-in and transition-out activities, including knowledge transfer, onboarding/offboarding, GFP/system handoff, continuity of operations, and secure data archival, per FAR 42.1204 and DHS IT transition best practices.
12.4 Deliverables and Reporting
The Contractor shall ensure that all deliverables across Call Orders issued under this BPA adhere to standardized formatting, review cycles, and version control requirements. Unless otherwise specified, deliverables shall meet the following criteria:
· Format Requirements:
· Submitted in editable Microsoft Office formats (e.g., Word, Excel, PowerPoint) unless otherwise directed.
· Include document control headers (title, version, date, distribution status).
· Deliverables must include executive summaries, key findings, and actionable recommendations, where applicable.
· Submission and Review Cycle:
· Draft Deliverables: Due in accordance with each Call Order’s schedule and subject to a 10-business day review by the Government.
· Final Deliverables: Incorporate Government feedback and submitted no later than 5 business days following receipt of consolidated comments.
· Recurring Reporting Standards:
· Monthly Performance Reports: Cover activity summaries, milestone tracking, risk updates, and upcoming priorities.
· Quarterly Dashboards: Where applicable, provide performance metrics, compliance scores, and risk posture visualizations.
· Ad Hoc Briefings: Prepared in response to executive inquiries, audits, or federal data calls.
· Knowledge Management:
· All work products and outputs must be archived in the Government-approved knowledge repository, ensuring transparency, version control, and audit readiness.
12.5 Applicable Laws and Standards
The Contractor shall perform all work under this BPA in compliance with applicable federal laws, regulations, executive directives, and technical standards. These include, but are not limited to:
· Contractual and Acquisition Requirements
· Federal Acquisition Regulation
· OMB Circular A-130 – Managing Information as a Strategic Resource
· OMB Circular A-11 – Budget Justification and Capital Planning
· Cybersecurity Laws and Federal Directives
· Federal Information Security Modernization Act (FISMA)
· Executive Order 14028 – Improving the Nation’s Cybersecurity
· Presidential Policy Directive 21 (PPD-21) – Critical Infrastructure Security and Resilience
· OMB M-19-03 – Strengthening High Value Asset Protections
· OMB M-22-09 – Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
· NIST Standards and Guidance
· NIST SP 800-53 – Security and Privacy Controls
· NIST SP 800-37 – Risk Management Framework (RMF)
· NIST SP 800-30 – Risk Assessments
· NIST SP 800-63 – Digital Identity Guidelines
· NIST SP 800-218 – Secure Software Development Framework
· NIST SP 800-137 – ISCM Guidelines
· NIST SP 800-160 Vol. 2 – Cyber Resiliency Engineering
· DHS Binding Operational Directives (BODs) – Including but not limited to BOD 18-02 and future updates
· CDM Program Guidance – Including data feeds, sensor integration, and dashboard alignment
· FIPS 199/200 & 140-3 – Standards for categorization and cryptographic modules
· CNSS Policies & Instructions – Applicable to COMSEC and classified systems (e.g., CNSSI 4005, CNSSP No. 1)
· Treasury-Specific Policies
· TD P 85-01 Volumes I and II – Treasury Cybersecurity Policy
· TD 85 - Treasury Cybersecurity Policy 2025
· Treasury ICAM and COMSEC Handbooks
· Treasury Enterprise Architecture and Strategic Cybersecurity Plans Note: The Contractor is responsible for monitoring changes to these references and ensuring ongoing compliance. Where new directives are issued by OMB, DHS, NIST, or Treasury, the Contractor shall work with the Government to incorporate necessary updates into Call Orders and associated deliverables.
12.6 Work Location and Telework Guidelines
Work performance locations under this Blanket Purchase Agreement (BPA) may include Government sites, contractor facilities, or authorized remote environments. Work modality (e.g., on-site, remote, telework) shall be determined by the Government Point of Contact (POC) assigned to each individual Call Order, based on mission requirements, sensitivity of work, system access needs, and operational posture.
The following guidelines apply:
· On-site Work: May be required for tasks involving classified systems, secure communications, physical equipment handling, or sensitive operational collaboration. The Government may designate specific facilities or work centers for such efforts.
· Remote or Telework: May be authorized at the discretion of the Government POC where the nature of the task permits secure, uninterrupted execution from alternate locations. Contractor personnel must adhere to Treasury telework security protocols, including use of government-furnished equipment (GFE), VPN, endpoint protection, and secure collaboration tools.
· Hybrid Arrangements: Some tasks may involve a hybrid model (e.g., part-time on-site and remote) depending on program needs.
All personnel, regardless of location, shall be expected to attend virtual and/or in-person meetings as required and maintain the same performance expectations and availability as on-site staff.
Work location determinations may be updated over the course of performance at the discretion of the Government.
13. Appendices
13.1 Appendix A – Acronyms and Glossary
| Acronym |
| Definition |
| AAL |
| Authenticator Assurance Level |
| BOD |
| Binding Operational Directive |
| BPA |
| Blanket Purchase Agreement |
| CDM |
| Continuous Diagnostics and Mitigation |
| CISA |
| Cybersecurity and Infrastructure Security Agency |
| CLIN |
| Contract Line Item Number |
| COR |
| Contracting Officer's Representative |
| DHS |
| Department of Homeland Security |
| EO |
| Executive Order |
| ESIM |
| Enterprise Systems and Identity Management |
| FAL |
| Federation Assurance Level |
| FAR |
| Federal Acquisition Regulation |
| FICAM |
| Federal Identity, Credential, and Access Management |
| FISMA |
| Federal Information Security Modernization Act |
| HVA |
| High Value Asset |
| IAL |
| Identity Assurance Level |
| ICAM |
| Identity, Credential, and Access Management |
| IPP |
| Invoice Processing Platform |
| ISCM |
| Information Security Continuous Monitoring |
| LACS |
| Logical Access Control System |
| MFA |
| Multi-Factor Authentication |
| NDA |
| Non-Disclosure Agreement |
| NIST |
| National Institute of Standards and Technology |
| OMB |
| Office of Management and Budget |
| PACS |
| Physical Access Control System |
| PDS |
| PIV Data Synchronization |
| PIV |
| Personal Identity Verification |
| PKI |
| Public Key Infrastructure |
| PMO |
| Program Management Office |
| POA&M |
| Plan of Action and Milestones |
| SAR |
| System Architecture Review |
| SAST/DAST/SCA |
| Static, Dynamic, and Software Composition Analysis |
| SCM |
| Supply Chain Management |
| SIEM |
| Security Information and Event Management |
| SOP |
| Standard Operating Procedure |
| SSO |
| Single Sign-On |
| TIES/TEAS |
| Treasury ICAM Enterprise Services / Treasury Enterprise Account Services |
**Glossary**
- Call Order: A procurement action issued under a BPA that defines scope, deliverables, period of performance, and price.
- High Value Asset (HVA): A system that stores, processes, or transmits information critical to government operations or national interests.
- Zero Trust Architecture: A cybersecurity model that assumes breach and verifies each request as though it originates from an open network.
14.2 Appendix B – Task Area to Call Order Crosswalk
| PWS Task Area |
| Call Order Number |
| Call Order Title |
| 12.3.1 Security Risk Management |
| 001 |
| Security Risk Management Execution |
| 12.3.2 Governance, Compliance, and Audit Execution |
| 002 |
| Governance, Compliance, and Audit Execution |
| 12.3.3 Continuous Monitoring (ISCM) |
| 003 |
| Continuous Monitoring (ISCM) |
| 12.3.4 Identity, Credential, and Access Management (ICAM) |
| 004 |
| ICAM Support |
| 12.3.5 Incident Response and Recovery |
| 005 |
| Incident Response and Recovery |
| 12.3.6 Security Engineering and Orchestration |
| 006 |
| Security Engineering and Orchestration |
| 12.3.7 Threat Intelligence and Analytics |
| 007 |
| Threat Intelligence and Analytics |
| 12.3.8 GRC Platform Integration and Risk Reporting |
| 008 |
| GRC Platform Integration and Risk Reporting |
| 12.3.9 Workforce Development and Strategic Planning |
| 009 |
| Workforce Development and Strategic Planning |
| 12.3.10 CDM Architecture and Sensor Integration |
| 010 |
| CDM Architecture and Sensor Integration |
| 12.3.11 Security Program Planning |
| 011 |
| Security Program Planning |
| 12.3.12 Risk Quantification and Analytics |
| 012 |
| Risk Quantification and Analytics |
| 12.3.13 High Value Asset (HVA) Protection |
| 013 |
| High Value Asset Protection and Program Execution |
| 12.3.14 Critical Infrastructure Protection |
| 014 |
| Critical Infrastructure Protection |
| 12.3.15 Security Data Aggregation & Analytics |
| 015 |
| Security Data Aggregation & Analytics |
| 12.3.16 DevSecOps & CI/CD Supply Chain Security |
| 016 |
| DevSecOps & CI/CD Supply Chain Security |
| 12.3.17 Security Resilience & Chaos Engineering |
| 017 |
| Security Resilience & Chaos Engineering |
| 12.3.18 Enterprise Identity and Systems Integration |
| 018 |
| Enterprise Identity and Systems Integration |
| 12.3.19 Cyber Policy and Governance Management |
| 019 |
| Cyber Policy and Governance Management |
| 12.3.20 Communications Security (COMSEC) Support |
| 020 |
| COMSEC Execution and Maintenance |
| 12.3.21 Program Management Office Operations |
| 021 |
| Program Management Office Operations |
| 12.3.22 AI Cybersecurity Enablement |
| 022 |
| AI Cybersecurity Enablement |
| 12.3.23 Transition Planning and Execution |
| 023 |
| Transition Planning and Execution (In/Out) |
14.3 Appendix C – Reporting and Deliverable Templates
This appendix standardizes the format, content, and review cycle of core reports and deliverables required under the PROTECTS II BPA. These templates promote consistency, enable faster review and approval, and execution compliance with Treasury documentation and knowledge management standards.
C.1 Standard Document Elements All formal deliverables submitted under this BPA shall include:
· Header Information: Title, Version, Date, Deliverable Number, Call Order Number, Distribution Marking
· Executive Summary: Concise overview of purpose, scope, and major findings
· Body Sections: Structured according to content type (e.g., Background, Methodology, Findings, Recommendations)
· Actionable Items: Clear task tracking, risk indicators, or remediation plans (as applicable)
· Annexes/Attachments: Executing data, visuals, or reference materials
C.2 Recurring Report Templates
| Report Type |
| Template Sections |
| Frequency |
| Monthly Performance Report |
| Executive Summary, Activity Summary, Milestones, Risks/Issues, Upcoming Priorities |
| Monthly |
| Quarterly Dashboard |
| Metrics Overview, Risk Posture, Compliance Trends, Scorecards |
| Quarterly |
| Ad Hoc Executive Brief |
| Situational Overview, Impacts, Options, Recommendations |
| As Needed |
| Audit Response Binder |
| Timeline, Request Tracker, Evidence Matrix, Status Summary |
| Per Audit Event |
| Training Progress Report |
| Participants, Completion Rates, Feedback Summary, Next Steps |
| Quarterly |
| Risk Snapshot Report |
| Current Risks, Trending Areas, Interdependencies, Mitigation Actions |
| Weekly (e.g., CO001) |
C.3 Review and Version Control Standards
· Draft Submission Timeline: Per Call Order, typically 10 business days prior to due date
· Review Cycle: Government review period = 10 business days
· Final Submission Timeline: Within 5 business days of receiving consolidated feedback
· Version Control: Each document must include a version log with changes and approval signatures (if required)
C.4 Format Requirements
· File formats: Microsoft Word, Excel, PowerPoint (editable)
· Font: Times New Roman, 12 pt, 1-inch margins, single spacing
· File naming convention: [BPA#]_CO[###]_DeliverableName_V#_Date.docx
· Markings: “UNCLASSIFIED//FOUO” unless otherwise specified
14.4 Appendix D – Security Clearance and Onboarding Requirements
This appendix defines the personnel clearance, background investigation, and onboarding requirements applicable to all contractor personnel executing the PROTECTS BPA. These requirements ensure compliance with federal security regulations and Treasury’s internal personnel security protocols.
D.1 Clearance Requirements by Task Area
| Task Area / Call Order |
| Minimum Clearance Level |
| Justification |
| All Call Orders involving CNSI (Classified National Security Information) |
| Top Secret (TS) |
| Access to sensitive systems/data |
| Most Call Orders involving Treasury internal systems/data |
| Secret |
| Access to SBU/Federal IT systems |
| Non-sensitive execution tasks (e.g., training logistics, admin) |
| Public Trust – Moderate Risk |
| Access to PII, non-CNSI Treasury systems |
Note: The Government will determine the required clearance level based on sensitivity of work outlined in each Call Order.
D.2 Pre-Performance Requirements
· Security Clearance Adjudication: All personnel must hold an active clearance or be in the final stages of adjudication prior to onboarding.
· eQIP Initiation: Contractor companies must initiate background investigations via eQIP in coordination with the Treasury Personnel Security Office.
· SF-85P or SF-86 Forms: Required based on risk level and clearance tier.
D.3 Onboarding Documentation Checklist Each Contractor employee must submit the following (at a minimum):
· Valid government-issued photo ID
· Completed SF-85P or SF-86 (as applicable)
· OF-306 Declaration Form
· Non-Disclosure Agreement (NDA)
· Treasury Rules of Behavior and Cybersecurity Awareness Training Acknowledgment
· Signed Contractor Badge Request Form
· PIV Card Enrollment Appointment Confirmation (if applicable)
D.4 Identity and Access Provisioning
· System Access: Will be granted only after receipt of required clearance documentation and successful onboarding.
· Credentialing: All personnel must possess a valid PIV card or Treasury-approved credential for system/network access.
· Account Termination: Upon task completion or reassignment, all credentials and accesses must be revoked within 24 hours.
D.5 Facility and Badge Requirements
· Facility Access: Access to Treasury facilities (physical) requires valid PIV badge and security training.
· Remote Access: Contractors approved for remote work must use GFE (Government Furnished Equipment) and comply with Treasury VPN and endpoint protection requirements.
14.5 Appendix E – Invoicing Instructions and IPP Guidance
This appendix provides standard invoicing procedures and requires elements for submitting payment requests under the PROTECTS BPA. It aligns with FAR 52.212-4(i), Treasury Financial Manual requirements, and Invoice Processing Platform (IPP) submission protocols.
E.1 General Invoicing Requirements All invoices must be:
· Submitted electronically via the Invoice Processing Platform (IPP) at: https://www.ipp.gov
· Referenced by both BPA number and specific Call Order number
· Matched to deliverables or milestones outlined in the applicable Call Order
· Submitted only by authorized Contractor personnel
E.2 Required Invoice Elements Each invoice shall include the following:
| Field |
| Requirement |
| BPA and Call Order Number |
| Must appear in header of invoice |
| Contractor Name and UEI/CAGE |
| Legal business name and unique identifier |
| Invoice Number and Date |
| Unique sequential number and date of submission |
| Performance Period |
| Billing period start and end dates |
| CLIN(s) or Deliverable(s) |
| Referenced line items or specific deliverables from CDRL/Call Order |
| Labor Hours (if applicable) |
| Hours billed per labor category and rate (for T&M or hybrid CLINs only) |
| Attachments |
| Deliverables or milestone completion documentation, if required for payment release |
| Point of Contact |
| Name, phone, and email for invoicing questions |
E.3 Payment Terms and Timeline
· Net 30 days from the date a proper invoice is received
· Treasury will return improperly prepared invoices for correction
· No interim payments shall be made unless explicitly allowed under the Call Order
E.4 IPP Enrollment & Help
· Enrollment: Contractors must be enrolled in IPP prior to invoice submission
· Assistance: For IPP technical support, contact the IPP Help Desk at:
Email: ipphelpdesk@fiscal.treasury.gov or Call: 1-866-973-3131
E.5 Common Invoice Errors to Avoid
· Omitting the BPA or Call Order number
· Submitting for work not yet performed or outside of POP
· Incorrect or missing CLIN/Deliverable alignment
· Missing documentation where “pay-by-deliverable” terms apply
· Mismatched invoice and IPP header data
14.6 Appendix F – Policy and Regulatory References
This appendix lists the laws, policies, executive directives, memoranda, and technical standards that govern and inform the performance of this BPA. The Contractor shall ensure that all services, deliverables, and personnel comply with the applicable documents below. Updates to any listed references shall be incorporated upon issuance and in consultation with the Government.
1. Federal Acquisition Regulations (FAR)
2. Federal Cybersecurity Laws and Executive Directives
a. Federal Information Security Modernization Act (FISMA) – 44 U.S.C. § 3551 et seq.
b. Executive Order (EO) 14028 – Improving the Nation’s Cybersecurity
c. Presidential Policy Directive 21 (PPD-21) – Critical Infrastructure Security and Resilience
d. Clinger-Cohen Act – IT management and performance requirements
e. Paperwork Reduction Act – Oversight of federal information collections
f. Privacy Act of 1974 – Safeguarding Personally Identifiable Information (PII)
3. Office of Management and Budget (OMB) Circulars and Memoranda
a. OMB Circular A-130 – Managing Information as a Strategic Resource
b. OMB Circular A-11 – Preparation, Submission, and Execution of the Budget
c. OMB Memorandum M-19-03 – Strengthening the Cybersecurity of Federal High Value Assets (HVAs)
d. OMB Memorandum M-22-09 – Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
e. OMB Memorandum M-21-31 – Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents
4. Department of Homeland Security (DHS) Guidance
a. Binding Operational Directive (BOD) 18-02 – Enhance the Protection of Federal HVAs
b. BOD 22-01 – Reducing the Significant Risk of Known Exploited Vulnerabilities
c. BOD 23-01 – Improving Asset Visibility and Vulnerability Detection on Federal Networks
d. Continuous Diagnostics and Mitigation (CDM) Program Guidance – Including sensor architecture, dashboard reporting, and agency integration guidance
5. National Institute of Standards and Technology (NIST) Special Publications
a. NIST SP 800-30 – Guide for Conducting Risk Assessments
b. NIST SP 800-37 – Risk Management Framework (RMF) for Information Systems and Organizations
c. NIST SP 800-39 – Managing Information Security Risk
d. NIST SP 800-53 (Rev. 5) – Security and Privacy Controls for Information Systems and Organizations
e. NIST SP 800-63-3 – Digital Identity Guidelines (IAL/AAL/FAL)
f. NIST SP 800-137 – Information Security Continuous Monitoring (ISCM)
g. NIST SP 800-160 Vol. 1 & 2 – Systems Security Engineering & Cyber Resilience Engineering
h. NIST SP 800-218 – Secure Software Development Framework (SSDF)
i. NIST SP 800-116 – Guidelines for PIV Card Use in Physical Access Control Systems
j. NIST SP 800-207 – Zero Trust Architecture
k. NIST Cybersecurity Framework (CSF) – Framework for Improving Critical Infrastructure Cybersecurity
6. Federal Identity and Cryptographic Standards
a. FIPS 199 – Standards for Security Categorization of Federal Information
b. FIPS 200 – Minimum Security Requirements for Federal Information and Information Systems
c. FIPS 201-3 – Personal Identity Verification (PIV) of Federal Employees and Contractors
d. FIPS 140-3 – Security Requirements for Cryptographic Modules
7. Committee on National Security Systems (CNSS) Policies
a. CNSSP No. 1 – National Policy on COMSEC
b. CNSSI 4005 – Safeguarding and Control of COMSEC Material
c. CNSSI 1253 – Security Categorization and Control Selection for National Security Systems
8. Department of the Treasury-Specific Policies and Standards
a. TD P 85-01 Volume I – Treasury Information Technology Security Policy
b. TD P 85-01 Volume II – Treasury Cybersecurity Control Requirements
c. Treasury Enterprise Cybersecurity Strategy – Strategic goals and implementation roadmap
d. Treasury ICAM Handbook – Identity and credential management standards
e. Treasury COMSEC Standard Operating Procedures
f. Treasury Privacy and Records Management Guidelines
g. TEAS/TIES Operational Documentation – Treasury ICAM Enterprise Services
15. Quality Assurance Surveillance Plan (QASP) For: PROTECTS II– Treasury Enterprise Cybersecurity Technology & Services Applies To: All Call Orders issued under the BPA Prepared By: [Insert CO/COR Name] Date: [Insert Date]
1. Purpose This QASP establishes a systematic approach for monitoring and evaluating contractor performance under the PROTECTS BPA. It ensures that services provided under individual Call Orders meet Treasury’s quality, timeliness, and compliance standards as defined by the Performance Work Statement (PWS), Contract Data Requirements List (CDRL), and specific deliverables.
2. Roles and Responsibilities
| Role |
| Responsibility |
| Contracting Officer (CO) |
| Overall contract authority and oversight |
| COR/Task Monitors |
| Day-to-day surveillance, verification, and acceptance of deliverables |
| Contractor |
| Timely, accurate performance per PWS/Call Order |
3. Surveillance Methods
| Method |
| Description |
| Direct Observation |
| Monitoring real-time execution activities, meetings, or deployments |
| Deliverable Review |
| Evaluation of submitted reports, plans, and dashboards for accuracy/completeness |
| Performance Metrics |
| Review of predefined KPIs tied to each Call Order |
| Interviews/Feedback |
| Surveys or debriefs with stakeholders or system owners |
| Audit Sampling |
| Random sampling of documentation or logs for compliance |
4. Performance Standards & Metrics Performance standards shall be drawn directly from each Call Order’s performance table. Examples:
| Performance Area |
| Standard |
| Acceptable Quality Level (AQL) |
| Method |
| Deliverable Timeliness |
| Reports submitted on or before due date |
| 95% on-time |
| Deliverable Review |
| Dashboard Accuracy |
| Data integrity validated quarterly |
| 98% accuracy |
| Data Sampling |
| Audit Readiness |
| Audit responses submitted within 3 days |
| 100% compliance |
| RFI Tracking |
| Knowledge Management |
| Monthly updates to content repository |
| 90% update rate |
| Content Review |
5. Evaluation Frequency
| Activity |
| Frequency |
| Formal COR Performance Review |
| Quarterly |
| Deliverable Evaluation & Acceptance |
| Per Call Order schedule |
| KPI Dashboard Reporting Review |
| Monthly/Quarterly |
| Lessons Learned / Quality Debrief |
| Annually or End of POP |
6. Incentives and Remedies
· Positive Performance: May result in CPARS rating elevation, public recognition, or expanded tasking
· Unsatisfactory Performance: May result in a Corrective Action Request (CAR), payment withholding, or contract remedies under FAR 52.212-4
7. Documentation and Records All surveillance activities, communications, CARs, and acceptance memos will be documented in the official contract file and tracked via Treasury’s contract management system.
16. Quality Control Plan (QCP) For: PROTECTS II – Treasury Enterprise Cybersecurity Technology & Services Contractor Responsibility Document Applies To: All Call Orders under the BPA Date: [Insert Date]
1. Purpose This Quality Control Plan (QCP) outlines the Contractor’s approach to ensuring consistent, high-quality service delivery across all task areas and Call Orders issued under the PROTECTS BPA. It describes internal processes for quality assurance, issue tracking, personnel oversight, and risk mitigation in alignment with Treasury’s expectations.
2. Quality Control Objectives
· Deliver all products and services in accordance with BPA requirements
· Prevent, identify, and correct deficiencies before Government detection
· Ensure customer satisfaction through proactive performance monitoring
· Maintain compliance with applicable federal regulations, policies, and technical standards
· Promote continuous improvement throughout the contract lifecycle
3. Roles and Responsibilities
| Role |
| Responsibility |
| Program Manager (PM) |
| Oversees QCP implementation, reports to COR, leads risk mitigation actions |
| Quality Manager (QM) |
| Manages quality assurance checks, maintains quality records, facilitates reviews |
| Task Leads |
| Monitor deliverables and activities for assigned task areas |
| Project Staff |
| Follow SOPs, escalate risks, and apply corrective/preventive actions |
4. Internal Quality Review Process
| Step |
| Description |
| Pre-Submission QA Review |
| All deliverables reviewed for formatting, accuracy, completeness before delivery |
| Checklist Verification |
| Deliverables must pass internal checklists aligned to PWS/CDRL criteria |
| Peer Review |
| Technical documents undergo peer validation by SMEs |
| Configuration Control |
| Version control and change tracking applied to all submitted artifacts |
| Lessons Learned Analysis |
| Issues analyzed quarterly to improve repeatability and reduce risk recurrence |
5. Metrics and Quality Thresholds
| Quality Area |
| Metric |
| Threshold |
| On-Time Deliverables |
| % of deliverables submitted by due date |
| ≥ 95% |
| Customer Satisfaction |
| Government survey results or feedback |
| ≥ 90% satisfaction |
| Documentation Quality |
| % of deliverables accepted without rework |
| ≥ 95% |
| CAP Resolution |
| Time to resolve Corrective Action Plans |
| ≤ 30 calendar days |
6. Issue Management
· Nonconformances: Documented in the Contractor’s issue tracking system
· Corrective Actions: Initiated for recurring or serious issues; shared with COR
· Escalation Protocols: PM notifies COR within 24 hours of critical issue discovery
· Root Cause Analysis: Required for any failed or returned deliverables
7. Communication and Reporting
· Monthly Quality Summary Reports: Submitted with Performance Reports to COR
· Quality Dashboard: Tracks open issues, aging trends, and quality performance
· Quarterly Review Meeting: Contractor reviews QCP performance with Government
8. Continuous Improvement Activities
· Perform retrospective reviews at task completion
· Solicit Government feedback and incorporate recommendations
· Update SOPs and training based on issue trends and best practices
· Conduct semiannual quality training for staff
17. Contract Data Requirements List (CDRL) For: PROTECTS – Treasury Enterprise Cybersecurity Technology & Services Applies To: All Call Orders under BPA [Insert BPA Number] Date: [Insert Date]
Instructions:
This CDRL summarizes all required contract deliverables across the BPA. Each entry includes a unique identifier, title, source Call Order, frequency, format, and submission routing. Contractors must adhere to these requirements unless otherwise modified in a specific Call Order.
| CDRL No. |
| Deliverable Title |
| Call Order |
| Frequency |
| Format |
| Recipient(s) |
| CDRL-001 |
| Enterprise Risk Assessment Reports |
| 001 |
| Quarterly |
| Word/PDF |
| COR, Risk Office |
| CDRL-002 |
| POA&M Closure Validation Logs |
| 001 |
| Monthly |
| Excel |
| COR, ISSM |
| CDRL-003 |
| Cybersecurity Policy Package |
| 002 |
| Quarterly |
| Word/PDF |
| COR, Policy Lead |
| CDRL-004 |
| FISMA Compliance Reporting |
| 002 |
| Monthly/Annually |
| Excel/Word |
| COR, FISMA PM |
| CDRL-005 |
| ISCM Dashboards & Metrics Reports |
| 003 |
| Monthly |
| PowerPoint/Excel |
| COR, ISSOs |
| CDRL-006 |
| Secure Code Review Reports |
| 003 |
| As Needed |
| Word |
| COR, AppSec Lead |
| CDRL-007 |
| ICAM System Integration Design |
| 004 |
| As Needed |
| Word/Visio |
| COR, ESIM |
| CDRL-008 |
| MFA Compliance Metrics Dashboard |
| 004 |
| Monthly |
| PowerPoint/Excel |
| COR, ESIM |
| CDRL-009 |
| Incident Response Plan |
| 005 |
| Annually |
| Word/PDF |
| COR, IR Lead |
| CDRL-010 |
| Tabletop Exercise Reports |
| 005 |
| Quarterly |
| Word |
| COR, CISO |
| CDRL-011 |
| Security Architecture Diagrams |
| 006 |
| Per System |
| Visio |
| COR, Engineering Lead |
| CDRL-012 |
| Threat Advisory Bulletins |
| 007 |
| Monthly |
| Word/PDF |
| COR, SOC |
| CDRL-013 |
| IOC Correlation Reports |
| 007 |
| Biweekly |
| Excel |
| COR, Threat Intel Lead |
| CDRL-014 |
| GRC Dashboard Reports |
| 008 |
| Monthly |
| PowerPoint/Excel |
| COR, GRC PM |
| CDRL-015 |
| Cyber Workforce Inventory |
| 009 |
| Annually |
| Excel |
| COR, Workforce Dev Lead |
| CDRL-016 |
| Training Progress Reports |
| 009 |
| Quarterly |
| Excel |
| COR, Training Coordinator |
| CDRL-017 |
| CDM Dashboard Integration Report |
| 010 |
| Quarterly |
| Word/PDF |
| COR, CDM Office |
| CDRL-018 |
| Multi-Year Cybersecurity Program Plan |
| 011 |
| Annually |
| Word |
| COR, CISO |
| CDRL-019 |
| Executive Planning Dashboards |
| 011 |
| Quarterly |
| PowerPoint |
| COR, CIO/CISO |
| CDRL-020 |
| Risk Quantification Framework Guide |
| 012 |
| One-time + Updates |
| Word |
| COR, Risk Analytics Lead |
| CDRL-021 |
| HVA Protection Plan and Architecture Artifacts |
| 013 |
| Per Asset/System |
| Word/Visio |
| COR, HVA Program Lead |
| CDRL-022 |
| COOP and Recovery Plan Documentation |
| 014 |
| Semiannually |
| Word/PDF |
| COR, BCP/COOP Coordinator |
| CDRL-023 |
| Aggregated Cybersecurity Dashboard |
| 015 |
| Monthly |
| PowerPoint/Excel |
| COR, Cyber Ops Lead |
| CDRL-024 |
| CI/CD Security Assessment Report |
| 016 |
| Annually |
| Word/PDF |
| COR, DevSecOps Lead |
| CDRL-025 |
| Security Chaos Engineering Test Plan |
| 017 |
| Quarterly |
| Word |
| COR, Resilience Office |
| CDRL-026 |
| ICAM Roadmap and Execution Strategy |
| 018 |
| Annually |
| Word |
| COR, ESIM |
| CDRL-027 |
| Cyber Policy Governance Framework |
| 019 |
| Annually |
| Word/PDF |
| COR, Governance Lead |
| CDRL-028 |
| COMSEC Key Management SOP |
| 020 |
| Annually |
| Word/PDF |
| COR, COMSEC Custodian |
| CDRL-029 |
| Integrated Master Schedule |
| 021 |
| Monthly |
| MS Project/Excel |
| COR, PMO Lead |
| CDRL-030 |
| AI Risk Assessment Report |
| 022 |
| Quarterly |
| Word/PDF |
| COR, AI Oversight Lead |
| CDRL-031 |
| Transition-In Plan |
| 023 |
| One-time |
| Word/PDF |
| COR, Transition Manager |
| CDRL-032 |
| Handoff Validation Report |
| 023 |
| End of Contract |
| Word/PDF |
| COR, System Owners |
Notes:
· All CDRLs must follow formatting and review cycle requirements outlined in Appendix C.
· CDRL references must appear in invoices when tied to deliverable-based payment milestones.
· Additional ad hoc deliverables may be requested and tracked via BPA Modifications or individual Call Orders.
UNCLASSIFIED//FOUO
pg. 2 image3.png image1.png image2.png
File details come from the government source that posted it. Updated .