Attachment 1 - DRAFT PROTECTS II PWS.docx

DOCX document 238 KB Posted

Attached to
PROTECTS II Federal contract opportunity
Solicitation number
2032H5-26-Q-000001
Issued by
Department of the Treasury Internal Revenue Service

About this file

This document is a Draft Performance Work Statement (PWS) for the PROTECTS II Blanket Purchase Agreement (BPA) from the Department of the Treasury. The single-award BPA will provide enterprise-level cybersecurity services from 2025-2035, enabling the Treasury to issue Call Orders across 23 distinct cybersecurity task areas including security risk management, incident response, identity and access management, threat intelligence, DevSecOps, and AI cybersecurity enablement. The BPA is designed to support Treasury's cybersecurity resiliency initiative, comply with federal mandates like FISMA and Executive Order 14028, and align with NIST risk management frameworks.

Key performance details include a 10-year maximum period of performance with annual option periods, a TBD ceiling price, and a modular approach allowing flexible task ordering. The PWS requires comprehensive cybersecurity services spanning governance, risk management, continuous monitoring, secure engineering, workforce development, and critical infrastructure protection. Contractor personnel may work on-site, remotely, or in hybrid arrangements, with security clearance requirements varying by task sensitivity. The government will issue specific Call Orders under the BPA, with each order defining precise scope, deliverables, performance expectations, and pricing arrangements. The solicitation is currently in a Request for Information (RFI) phase, with industry feedback due by 10 June 2025.

View the file

Other files for this federal contract opportunity

Other files attached to PROTECTS II, newest first.
File Type Posted
Attachment 2 - PROTECTS II RFI Questions Comments.xlsx XLSX spreadsheet
Attachment 3 - PROTECTS II RFI.docx DOCX document
Attachment 4 - Draft PROTECTS II Special Notice.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNCLASSIFIED//FOUO

EXECUTIVE SUMMARY

This Single-Award Blanket Purchase Agreement (BPA) establishes a flexible and streamlined acquisition framework for enterprise-level cybersecurity services under the Department of the Treasury’s Resiliency initiative. Built in accordance with FAR 8.405-3, the BPA provides a mechanism for issuing Call Orders that address evolving cybersecurity needs, enable rapid response to threats, and execution compliance with federal mandates including FISMA, Executive Order 14028, and NIST’s Risk Management Framework. Task areas span governance, risk, and compliance (GRC); continuous monitoring and assessment; identity and access management; incident response; security engineering; and strategic planning. This BPA is designed to maximize agility while maintaining oversight, performance accountability, and alignment with Treasury’s enterprise cybersecurity goals.

Contents

1. Agreement Type4
2. Parties to the Agreement4
3. Scope of Work5
4. Period of Performance5
5. Ceiling Price5
6. Ordering Procedures5
7. Performance and Deliverables6
8. Invoicing6
10. Point of Contact6
11. BPA Number7
12. Modular Performance Work Statement (PWS)7
12.1 Introduction7
12.2 Scope of Services7
12.3 Modular Task Areas8
12.3.1Security Risk Management8
12.3.2Governance, Compliance, and Audit Execution8
12.3.3Continuous Monitoring (ISCM)8
12.3.4Identity, Credential, and Access Management (ICAM)8
12.3.5Incident Response and Recovery8
12.3.6Security Engineering and Orchestration8
12.3.7Threat Intelligence and Analytics8
12.3.8GRC Platform Integration and Risk Reporting8
12.3.9Workforce Development and Strategic Planning8
12.3.10CDM Architecture and Sensor Integration8
12.3.11Security Program Planning8
12.3.12Risk Quantification and Analytics8
12.3.13High Value Asset (HVA) Protection9
12.3.14Critical Infrastructure Protection9
12.3.15Security Data Aggregation & Analytics9
12.3.16DevSecOps & CI/CD Supply Chain Security9
12.3.17Security Resilience & Chaos Engineering9
12.3.18Enterprise Identity and Systems Integration9
12.3.19Cyber Policy and Governance Management9
12.3.20Communications Security (COMSEC) Execution9
12.3.21Program Management Office Operations9
12.3.22AI Cybersecurity Enablement9
12.3.23Transition Planning and Execution10
12.4 Deliverables and Reporting10
12.5 Applicable Laws and Standards10
12.6 Work Location and Telework Guidelines12
14.2 Appendix B – Task Area to Call Order Crosswalk14
14.3 Appendix C – Reporting and Deliverable Templates16
14.4 Appendix D – Security Clearance and Onboarding Requirements17
14.5 Appendix E – Invoicing Instructions and IPP Guidance19
14.6 Appendix F – Policy and Regulatory References21
14.7 Appendix G – Clause Matrix23
15. Quality Assurance Surveillance Plan (QASP)25
16. Quality Control Plan (QCP)27
17. Contract Data Requirements List (CDRL)30

1. Agreement Type This Blanket Purchase Agreement (BPA) is a Single-Award BPA established under the authority of Federal Acquisition Regulation (FAR) Part 8-405.3. The BPA enables the Department of the Treasury to acquire a full suite of enterprise cybersecurity technology and services through streamlined ordering procedures. This BPA is not a contract in itself but constitutes a written understanding of the terms under which the Government may issue Call Orders to the Contractor.

All purchases under this BPA shall comply with the terms of this agreement and applicable federal acquisition regulations. Each Call Order issued under this BPA shall be considered a binding contract in accordance with the provisions of FAR Part 8 and the terms outlined herein.

2. Parties to the Agreement This BPA is entered into by and between the:

· Department of the Treasury Office of the Chief Information Officer (OCIO) 1500 Pennsylvania Avenue NW Washington, DC 20220 Acting through an authorized Contracting Officer and

· [Contractor Name] [Contractor Address] [City, State, ZIP] [UEI/CAGE Code] Acting through its authorized representative Both parties agree to the terms and conditions set forth in this BPA and to comply with all applicable laws, regulations, and Treasury-specific requirements. All communications related to this BPA shall be directed through the designated points of contact listed in Section 6 of each individual Call Order.

3. Scope of Work The Contractor shall provide enterprise-wide cybersecurity services to execution the Department of the Treasury’s mission to protect federal information systems, data, and infrastructure. This Blanket Purchase Agreement (BPA) enables the issuance of Call Orders for modular cybersecurity execution aligned with federal standards and evolving threat landscapes.

Work under this BPA may include governance, risk, and compliance (GRC); continuous diagnostics and monitoring; identity and access management; incident response and recovery; security architecture and engineering; threat intelligence; and execution for government-wide cybersecurity initiatives such as DHS CDM and Executive Order 14028.

All work will comply with applicable provisions of the Federal Acquisition Regulation (FAR), the Federal Information Security Modernization Act (FISMA), and guidance issued by the National Institute of Standards and Technology (NIST).

4. Period of Performance The BPA runs from 2025 –2035 (10 years maximum). Task Orders awarded under the BPA can be issued any time prior to BPA expiration.

POP annual periods:

- Base Year: 2025 – 2026

- Option 1: 2026 – 2027

- Option 2: 2027 – 2028

- Option 3: 2028 – 2029

- Option 4: 2029 – 2030

- Option 5: 2030 – 2031

- Option 6: 2031 – 2032

- Option 7: 2032 – 2033

- Option 8: 2033 – 2034

- Option 9: 2034 – 2035

5. Ceiling Price The estimated ceiling value shall not exceed $[TBD].

6. Ordering Procedures All purchases under this BPA shall be made via individually issued Call Orders. Each Call Order must:

· Reference this BPA number in its header

· Define the scope of work clearly, referencing applicable task areas

· Specify deliverables, due dates, and performance expectations

· Establish a period of performance (POP), including start and end dates

· Include firm-fixed pricing, not-to-exceed ceilings, or other pricing arrangements as appropriate Only authorized Government Ordering Officials designated under this BPA may issue Call Orders. Orders may be issued in writing via email or through the designated contract management system. The Contractor shall acknowledge receipt of all Call Orders and begin work in accordance with the terms stated therein.

7. Performance and Deliverables Each Call Order issued under this BPA shall define:

· Specific performance objectives, metrics, and success criteria

· Required deliverables, including format, review cycles, and submission timelines

· Any dependencies, approvals, or Government Furnished Information (GFI) Unless otherwise stated in the Call Order, deliverables shall comply with the standards defined in Section 12.4 of this BPA (Deliverables and Reporting) and be submitted to the points of contact listed in the Call Order. The Contractor is responsible for the timely and accurate submission of all deliverables and for maintaining quality control throughout the performance period.

The Government will assess Contractor performance in accordance with the agreed-upon metrics and may document performance outcomes in CPARS as appropriate.

8. Invoicing Invoices shall be submitted in accordance with the instructions provided in each Call Order and must:

· Include the BPA and Call Order number

· Clearly identify the billing period and any applicable CLINs or deliverables

· Reference the associated deliverable or milestone tied to payment

· Be submitted electronically to the designated Treasury invoicing system (e.g., Invoice Processing Platform (IPP)) The Contractor shall ensure that all invoices are complete, accurate, and submitted in accordance with Treasury Financial Management Policy and FAR 52.212-4(i) (Invoice Instructions). Improper or incomplete invoices may be rejected or returned for correction.

10. Point of Contact Government POC: [Name, Email, Phone] | Contractor POC: [Name, Email, Phone]

11. BPA Number [To be assigned by the Contracting Officer]

12. Modular Performance Work Statement (PWS)

12.1 Introduction

The United States Department of the Treasury is an executive agency responsible for promoting economic prosperity and ensuring the nation’s financial security. Treasury’s activities range from coin and currency production to payment disbursement, revenue collection, and federal debt management.

Resiliency is a Treasury-wide framework that delivers standardized, scalable cybersecurity solutions to Departmental Offices and Bureaus, as well as partner agencies that rely on Treasury for financial management.

12.2 Scope of Services

This BPA covers a comprehensive suite of cybersecurity services designed to improve Treasury’s operational security posture, execution strategic objectives, and ensure continuous compliance with federal cybersecurity mandates.

The Contractor shall deliver execution across the following functional areas:

· Risk identification, analysis, and mitigation using the NIST Risk Management Framework (SP 800-37, 800-30, 800-39)

· POA&M management, risk register updates, and enterprise-level risk dashboards

· Support for system assessments, control testing, and compliance with FISMA and OMB A-130

· Design and implementation of secure architectures, Zero Trust frameworks, and CDM integrations

· Identity proofing, PIV enablement, ICAM modernization, and execution for NIST SP 800-63 guidance

· Incident response planning, playbook execution, threat hunting, and post-event remediation

· Configuration and enhancement of GRC platforms, reporting dashboards, and automated workflows

· Workforce development initiatives mapped to NICE Framework roles and functional gaps Services will be tailored to each Call Order and guided by the Modular PWS task areas outlined in Section 12.3.

12.3 Modular Task Areas

12.3.1 Security Risk Management - Risk categorization, assessments, POA&M tracking, risk dashboards, and audit response execution for enterprise assets, including Filing Season Risk Readiness and Disaster Recovery environments. Enables management of interconnected risk views, upstream/downstream dependencies, and oversight of mission-critical systems. Includes annual oversight process planning, surge execution for emerging risk-related requirements, and alignment with new legislative and executive mandates. (NIST SP 800-30, 800-39, FISMA, EO 14028).

12.3.2 Governance, Compliance, and Audit Execution - FISMA reporting, policy development, audit coordination, compliance (FISMA, OMB A-130).

12.3.3 Continuous Monitoring (ISCM) - Ongoing control assessments, real-time dashboards, ISSO execution (NIST SP 800-137).

12.3.4 Identity, Credential, and Access Management (ICAM) - PIV, MFA, ID proofing, IAL/AAL/FAL requirements (NIST SP 800-63-3).

12.3.5 Incident Response and Recovery - IRP development, exercises, threat detection, forensic execution (NIST SP 800-61r2).

12.3.6 Security Engineering and Orchestration - Zero Trust design, patching automation, secure SDLC (EO 14028, SP 800-160).

12.3.7 Threat Intelligence and Analytics - Threat hunting, IOC analysis, automated reporting and dashboards.

12.3.8 GRC Platform Integration and Risk Reporting - Workflow automation, GRC dashboards, integration of control libraries.

12.3.9 Workforce Development and Strategic Planning - NICE framework alignment, workforce role mapping, planning artifacts.

12.3.10 CDM Architecture and Sensor Integration - CDM implementation, data feed reliability, sensor integration.

12.3.11 Security Program Planning - Strategic program planning, goal alignment, milestone tracking, and performance reporting (OMB A-11, A-130, NIST CSF)

12.3.12 Risk Quantification and Analytics - Quantitative risk modeling, FAIR-based analysis, executive dashboards, and impact-driven prioritization (NIST SP 800-30, FAIR)

12.3.13 High Value Asset (HVA) Protection - HVA identification, DHS reporting, threat modeling, protection planning, and risk register integration (DHS HVA Guidance, OMB M-19-03)

12.3.14 Critical Infrastructure Protection - Identification of mission-critical systems, continuity planning, failover design, and operational resilience (PPD-21, NIST CSF)

12.3.15 Security Data Aggregation & Analytics - Data correlation across CDM, SIEM, asset/vulnerability tools; dashboard development and risk insights (NIST SP 800-137, EO 14028)

12.3.16 DevSecOps & CI/CD Supply Chain Security - Security testing in pipelines, code analysis, dependency scanning, and secure SDLC automation (NIST SP 800-218, EO 14028)

12.3.17 Security Resilience & Chaos Engineering - Resilience validation via controlled disruption, detection testing, and recovery response simulation (NIST SP 800-160v2, EO 14028)

12.3.18 Enterprise Identity and Systems Integration – ICAM lifecycle management, PIV Data Synchronization (PDS), LACS/MFA implementation, GSA MSO coordination, and Zero Trust identity governance (FIPS 201-3, NIST SP 800-63, CDM Phase II)

12.3.19 Cyber Policy and Governance Management – Maintenance of TD P 85-01, SOP drafting, governance workflow facilitation, and alignment with evolving OMB, NIST, and EO 14028 policy requirements (NIST SP 800-53, OMB A-130, EO 14028)

12.3.20 Communications Security (COMSEC) Execution – Cryptographic asset lifecycle management, keying material tracking, NSA/CNSS compliance, SOP development, and inspection readiness (CNSSI 4005, FIPS 140-3, CNSSP No. 1)

12.3.21 Program Management Office Operations – Integrated schedule management, IPT facilitation, risk tracking, executive reporting, document control, and surge PM execution across all BPA Call Orders (PMBOK 7th Ed., GAO Agile Guide, FAR Part 37)

12.3.22 AI Cybersecurity Enablement - AI/ML system risk assessments, secure DevSecOps pipeline integration, model access controls, bias and privacy evaluations, and AI governance policy development in alignment with NIST AI RMF, EO 14110, and OMB M-24-10.

12.3.23 Transition Planning and Execution - Planning and execution of transition-in and transition-out activities, including knowledge transfer, onboarding/offboarding, GFP/system handoff, continuity of operations, and secure data archival, per FAR 42.1204 and DHS IT transition best practices.

12.4 Deliverables and Reporting

The Contractor shall ensure that all deliverables across Call Orders issued under this BPA adhere to standardized formatting, review cycles, and version control requirements. Unless otherwise specified, deliverables shall meet the following criteria:

· Format Requirements:

· Submitted in editable Microsoft Office formats (e.g., Word, Excel, PowerPoint) unless otherwise directed.

· Include document control headers (title, version, date, distribution status).

· Deliverables must include executive summaries, key findings, and actionable recommendations, where applicable.

· Submission and Review Cycle:

· Draft Deliverables: Due in accordance with each Call Order’s schedule and subject to a 10-business day review by the Government.

· Final Deliverables: Incorporate Government feedback and submitted no later than 5 business days following receipt of consolidated comments.

· Recurring Reporting Standards:

· Monthly Performance Reports: Cover activity summaries, milestone tracking, risk updates, and upcoming priorities.

· Quarterly Dashboards: Where applicable, provide performance metrics, compliance scores, and risk posture visualizations.

· Ad Hoc Briefings: Prepared in response to executive inquiries, audits, or federal data calls.

· Knowledge Management:

· All work products and outputs must be archived in the Government-approved knowledge repository, ensuring transparency, version control, and audit readiness.

12.5 Applicable Laws and Standards

The Contractor shall perform all work under this BPA in compliance with applicable federal laws, regulations, executive directives, and technical standards. These include, but are not limited to:

· Contractual and Acquisition Requirements

· Federal Acquisition Regulation

· OMB Circular A-130 – Managing Information as a Strategic Resource

· OMB Circular A-11 – Budget Justification and Capital Planning

· Cybersecurity Laws and Federal Directives

· Federal Information Security Modernization Act (FISMA)

· Executive Order 14028 – Improving the Nation’s Cybersecurity

· Presidential Policy Directive 21 (PPD-21) – Critical Infrastructure Security and Resilience

· OMB M-19-03 – Strengthening High Value Asset Protections

· OMB M-22-09 – Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

· NIST Standards and Guidance

· NIST SP 800-53 – Security and Privacy Controls

· NIST SP 800-37 – Risk Management Framework (RMF)

· NIST SP 800-30 – Risk Assessments

· NIST SP 800-63 – Digital Identity Guidelines

· NIST SP 800-218 – Secure Software Development Framework

· NIST SP 800-137 – ISCM Guidelines

· NIST SP 800-160 Vol. 2 – Cyber Resiliency Engineering

· DHS Binding Operational Directives (BODs) – Including but not limited to BOD 18-02 and future updates

· CDM Program Guidance – Including data feeds, sensor integration, and dashboard alignment

· FIPS 199/200 & 140-3 – Standards for categorization and cryptographic modules

· CNSS Policies & Instructions – Applicable to COMSEC and classified systems (e.g., CNSSI 4005, CNSSP No. 1)

· Treasury-Specific Policies

· TD P 85-01 Volumes I and II – Treasury Cybersecurity Policy

· TD 85 - Treasury Cybersecurity Policy 2025

· Treasury ICAM and COMSEC Handbooks

· Treasury Enterprise Architecture and Strategic Cybersecurity Plans Note: The Contractor is responsible for monitoring changes to these references and ensuring ongoing compliance. Where new directives are issued by OMB, DHS, NIST, or Treasury, the Contractor shall work with the Government to incorporate necessary updates into Call Orders and associated deliverables.

12.6 Work Location and Telework Guidelines

Work performance locations under this Blanket Purchase Agreement (BPA) may include Government sites, contractor facilities, or authorized remote environments. Work modality (e.g., on-site, remote, telework) shall be determined by the Government Point of Contact (POC) assigned to each individual Call Order, based on mission requirements, sensitivity of work, system access needs, and operational posture.

The following guidelines apply:

· On-site Work: May be required for tasks involving classified systems, secure communications, physical equipment handling, or sensitive operational collaboration. The Government may designate specific facilities or work centers for such efforts.

· Remote or Telework: May be authorized at the discretion of the Government POC where the nature of the task permits secure, uninterrupted execution from alternate locations. Contractor personnel must adhere to Treasury telework security protocols, including use of government-furnished equipment (GFE), VPN, endpoint protection, and secure collaboration tools.

· Hybrid Arrangements: Some tasks may involve a hybrid model (e.g., part-time on-site and remote) depending on program needs.

All personnel, regardless of location, shall be expected to attend virtual and/or in-person meetings as required and maintain the same performance expectations and availability as on-site staff.

Work location determinations may be updated over the course of performance at the discretion of the Government.

13. Appendices

13.1 Appendix A – Acronyms and Glossary

Acronym
Definition
AAL
Authenticator Assurance Level
BOD
Binding Operational Directive
BPA
Blanket Purchase Agreement
CDM
Continuous Diagnostics and Mitigation
CISA
Cybersecurity and Infrastructure Security Agency
CLIN
Contract Line Item Number
COR
Contracting Officer's Representative
DHS
Department of Homeland Security
EO
Executive Order
ESIM
Enterprise Systems and Identity Management
FAL
Federation Assurance Level
FAR
Federal Acquisition Regulation
FICAM
Federal Identity, Credential, and Access Management
FISMA
Federal Information Security Modernization Act
HVA
High Value Asset
IAL
Identity Assurance Level
ICAM
Identity, Credential, and Access Management
IPP
Invoice Processing Platform
ISCM
Information Security Continuous Monitoring
LACS
Logical Access Control System
MFA
Multi-Factor Authentication
NDA
Non-Disclosure Agreement
NIST
National Institute of Standards and Technology
OMB
Office of Management and Budget
PACS
Physical Access Control System
PDS
PIV Data Synchronization
PIV
Personal Identity Verification
PKI
Public Key Infrastructure
PMO
Program Management Office
POA&M
Plan of Action and Milestones
SAR
System Architecture Review
SAST/DAST/SCA
Static, Dynamic, and Software Composition Analysis
SCM
Supply Chain Management
SIEM
Security Information and Event Management
SOP
Standard Operating Procedure
SSO
Single Sign-On
TIES/TEAS
Treasury ICAM Enterprise Services / Treasury Enterprise Account Services

**Glossary**

- Call Order: A procurement action issued under a BPA that defines scope, deliverables, period of performance, and price.

- High Value Asset (HVA): A system that stores, processes, or transmits information critical to government operations or national interests.

- Zero Trust Architecture: A cybersecurity model that assumes breach and verifies each request as though it originates from an open network.

14.2 Appendix B – Task Area to Call Order Crosswalk

PWS Task Area
Call Order Number
Call Order Title
12.3.1 Security Risk Management
001
Security Risk Management Execution
12.3.2 Governance, Compliance, and Audit Execution
002
Governance, Compliance, and Audit Execution
12.3.3 Continuous Monitoring (ISCM)
003
Continuous Monitoring (ISCM)
12.3.4 Identity, Credential, and Access Management (ICAM)
004
ICAM Support
12.3.5 Incident Response and Recovery
005
Incident Response and Recovery
12.3.6 Security Engineering and Orchestration
006
Security Engineering and Orchestration
12.3.7 Threat Intelligence and Analytics
007
Threat Intelligence and Analytics
12.3.8 GRC Platform Integration and Risk Reporting
008
GRC Platform Integration and Risk Reporting
12.3.9 Workforce Development and Strategic Planning
009
Workforce Development and Strategic Planning
12.3.10 CDM Architecture and Sensor Integration
010
CDM Architecture and Sensor Integration
12.3.11 Security Program Planning
011
Security Program Planning
12.3.12 Risk Quantification and Analytics
012
Risk Quantification and Analytics
12.3.13 High Value Asset (HVA) Protection
013
High Value Asset Protection and Program Execution
12.3.14 Critical Infrastructure Protection
014
Critical Infrastructure Protection
12.3.15 Security Data Aggregation & Analytics
015
Security Data Aggregation & Analytics
12.3.16 DevSecOps & CI/CD Supply Chain Security
016
DevSecOps & CI/CD Supply Chain Security
12.3.17 Security Resilience & Chaos Engineering
017
Security Resilience & Chaos Engineering
12.3.18 Enterprise Identity and Systems Integration
018
Enterprise Identity and Systems Integration
12.3.19 Cyber Policy and Governance Management
019
Cyber Policy and Governance Management
12.3.20 Communications Security (COMSEC) Support
020
COMSEC Execution and Maintenance
12.3.21 Program Management Office Operations
021
Program Management Office Operations
12.3.22 AI Cybersecurity Enablement
022
AI Cybersecurity Enablement
12.3.23 Transition Planning and Execution
023
Transition Planning and Execution (In/Out)

14.3 Appendix C – Reporting and Deliverable Templates

This appendix standardizes the format, content, and review cycle of core reports and deliverables required under the PROTECTS II BPA. These templates promote consistency, enable faster review and approval, and execution compliance with Treasury documentation and knowledge management standards.

C.1 Standard Document Elements All formal deliverables submitted under this BPA shall include:

· Header Information: Title, Version, Date, Deliverable Number, Call Order Number, Distribution Marking

· Executive Summary: Concise overview of purpose, scope, and major findings

· Body Sections: Structured according to content type (e.g., Background, Methodology, Findings, Recommendations)

· Actionable Items: Clear task tracking, risk indicators, or remediation plans (as applicable)

· Annexes/Attachments: Executing data, visuals, or reference materials

C.2 Recurring Report Templates

Report Type
Template Sections
Frequency
Monthly Performance Report
Executive Summary, Activity Summary, Milestones, Risks/Issues, Upcoming Priorities
Monthly
Quarterly Dashboard
Metrics Overview, Risk Posture, Compliance Trends, Scorecards
Quarterly
Ad Hoc Executive Brief
Situational Overview, Impacts, Options, Recommendations
As Needed
Audit Response Binder
Timeline, Request Tracker, Evidence Matrix, Status Summary
Per Audit Event
Training Progress Report
Participants, Completion Rates, Feedback Summary, Next Steps
Quarterly
Risk Snapshot Report
Current Risks, Trending Areas, Interdependencies, Mitigation Actions
Weekly (e.g., CO001)

C.3 Review and Version Control Standards

· Draft Submission Timeline: Per Call Order, typically 10 business days prior to due date

· Review Cycle: Government review period = 10 business days

· Final Submission Timeline: Within 5 business days of receiving consolidated feedback

· Version Control: Each document must include a version log with changes and approval signatures (if required)

C.4 Format Requirements

· File formats: Microsoft Word, Excel, PowerPoint (editable)

· Font: Times New Roman, 12 pt, 1-inch margins, single spacing

· File naming convention: [BPA#]_CO[###]_DeliverableName_V#_Date.docx

· Markings: “UNCLASSIFIED//FOUO” unless otherwise specified

14.4 Appendix D – Security Clearance and Onboarding Requirements

This appendix defines the personnel clearance, background investigation, and onboarding requirements applicable to all contractor personnel executing the PROTECTS BPA. These requirements ensure compliance with federal security regulations and Treasury’s internal personnel security protocols.

D.1 Clearance Requirements by Task Area

Task Area / Call Order
Minimum Clearance Level
Justification
All Call Orders involving CNSI (Classified National Security Information)
Top Secret (TS)
Access to sensitive systems/data
Most Call Orders involving Treasury internal systems/data
Secret
Access to SBU/Federal IT systems
Non-sensitive execution tasks (e.g., training logistics, admin)
Public Trust – Moderate Risk
Access to PII, non-CNSI Treasury systems

Note: The Government will determine the required clearance level based on sensitivity of work outlined in each Call Order.

D.2 Pre-Performance Requirements

· Security Clearance Adjudication: All personnel must hold an active clearance or be in the final stages of adjudication prior to onboarding.

· eQIP Initiation: Contractor companies must initiate background investigations via eQIP in coordination with the Treasury Personnel Security Office.

· SF-85P or SF-86 Forms: Required based on risk level and clearance tier.

D.3 Onboarding Documentation Checklist Each Contractor employee must submit the following (at a minimum):

· Valid government-issued photo ID

· Completed SF-85P or SF-86 (as applicable)

· OF-306 Declaration Form

· Non-Disclosure Agreement (NDA)

· Treasury Rules of Behavior and Cybersecurity Awareness Training Acknowledgment

· Signed Contractor Badge Request Form

· PIV Card Enrollment Appointment Confirmation (if applicable)

D.4 Identity and Access Provisioning

· System Access: Will be granted only after receipt of required clearance documentation and successful onboarding.

· Credentialing: All personnel must possess a valid PIV card or Treasury-approved credential for system/network access.

· Account Termination: Upon task completion or reassignment, all credentials and accesses must be revoked within 24 hours.

D.5 Facility and Badge Requirements

· Facility Access: Access to Treasury facilities (physical) requires valid PIV badge and security training.

· Remote Access: Contractors approved for remote work must use GFE (Government Furnished Equipment) and comply with Treasury VPN and endpoint protection requirements.

14.5 Appendix E – Invoicing Instructions and IPP Guidance

This appendix provides standard invoicing procedures and requires elements for submitting payment requests under the PROTECTS BPA. It aligns with FAR 52.212-4(i), Treasury Financial Manual requirements, and Invoice Processing Platform (IPP) submission protocols.

E.1 General Invoicing Requirements All invoices must be:

· Submitted electronically via the Invoice Processing Platform (IPP) at: https://www.ipp.gov

· Referenced by both BPA number and specific Call Order number

· Matched to deliverables or milestones outlined in the applicable Call Order

· Submitted only by authorized Contractor personnel

E.2 Required Invoice Elements Each invoice shall include the following:

Field
Requirement
BPA and Call Order Number
Must appear in header of invoice
Contractor Name and UEI/CAGE
Legal business name and unique identifier
Invoice Number and Date
Unique sequential number and date of submission
Performance Period
Billing period start and end dates
CLIN(s) or Deliverable(s)
Referenced line items or specific deliverables from CDRL/Call Order
Labor Hours (if applicable)
Hours billed per labor category and rate (for T&M or hybrid CLINs only)
Attachments
Deliverables or milestone completion documentation, if required for payment release
Point of Contact
Name, phone, and email for invoicing questions

E.3 Payment Terms and Timeline

· Net 30 days from the date a proper invoice is received

· Treasury will return improperly prepared invoices for correction

· No interim payments shall be made unless explicitly allowed under the Call Order

E.4 IPP Enrollment & Help

· Enrollment: Contractors must be enrolled in IPP prior to invoice submission

· Assistance: For IPP technical support, contact the IPP Help Desk at:

Email: ipphelpdesk@fiscal.treasury.gov or Call: 1-866-973-3131

E.5 Common Invoice Errors to Avoid

· Omitting the BPA or Call Order number

· Submitting for work not yet performed or outside of POP

· Incorrect or missing CLIN/Deliverable alignment

· Missing documentation where “pay-by-deliverable” terms apply

· Mismatched invoice and IPP header data

14.6 Appendix F – Policy and Regulatory References

This appendix lists the laws, policies, executive directives, memoranda, and technical standards that govern and inform the performance of this BPA. The Contractor shall ensure that all services, deliverables, and personnel comply with the applicable documents below. Updates to any listed references shall be incorporated upon issuance and in consultation with the Government.

1. Federal Acquisition Regulations (FAR)

2. Federal Cybersecurity Laws and Executive Directives

a. Federal Information Security Modernization Act (FISMA) – 44 U.S.C. § 3551 et seq.

b. Executive Order (EO) 14028 – Improving the Nation’s Cybersecurity

c. Presidential Policy Directive 21 (PPD-21) – Critical Infrastructure Security and Resilience

d. Clinger-Cohen Act – IT management and performance requirements

e. Paperwork Reduction Act – Oversight of federal information collections

f. Privacy Act of 1974 – Safeguarding Personally Identifiable Information (PII)

3. Office of Management and Budget (OMB) Circulars and Memoranda

a. OMB Circular A-130 – Managing Information as a Strategic Resource

b. OMB Circular A-11 – Preparation, Submission, and Execution of the Budget

c. OMB Memorandum M-19-03 – Strengthening the Cybersecurity of Federal High Value Assets (HVAs)

d. OMB Memorandum M-22-09 – Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

e. OMB Memorandum M-21-31 – Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents

4. Department of Homeland Security (DHS) Guidance

a. Binding Operational Directive (BOD) 18-02 – Enhance the Protection of Federal HVAs

b. BOD 22-01 – Reducing the Significant Risk of Known Exploited Vulnerabilities

c. BOD 23-01 – Improving Asset Visibility and Vulnerability Detection on Federal Networks

d. Continuous Diagnostics and Mitigation (CDM) Program Guidance – Including sensor architecture, dashboard reporting, and agency integration guidance

5. National Institute of Standards and Technology (NIST) Special Publications

a. NIST SP 800-30 – Guide for Conducting Risk Assessments

b. NIST SP 800-37 – Risk Management Framework (RMF) for Information Systems and Organizations

c. NIST SP 800-39 – Managing Information Security Risk

d. NIST SP 800-53 (Rev. 5) – Security and Privacy Controls for Information Systems and Organizations

e. NIST SP 800-63-3 – Digital Identity Guidelines (IAL/AAL/FAL)

f. NIST SP 800-137 – Information Security Continuous Monitoring (ISCM)

g. NIST SP 800-160 Vol. 1 & 2 – Systems Security Engineering & Cyber Resilience Engineering

h. NIST SP 800-218 – Secure Software Development Framework (SSDF)

i. NIST SP 800-116 – Guidelines for PIV Card Use in Physical Access Control Systems

j. NIST SP 800-207 – Zero Trust Architecture

k. NIST Cybersecurity Framework (CSF) – Framework for Improving Critical Infrastructure Cybersecurity

6. Federal Identity and Cryptographic Standards

a. FIPS 199 – Standards for Security Categorization of Federal Information

b. FIPS 200 – Minimum Security Requirements for Federal Information and Information Systems

c. FIPS 201-3 – Personal Identity Verification (PIV) of Federal Employees and Contractors

d. FIPS 140-3 – Security Requirements for Cryptographic Modules

7. Committee on National Security Systems (CNSS) Policies

a. CNSSP No. 1 – National Policy on COMSEC

b. CNSSI 4005 – Safeguarding and Control of COMSEC Material

c. CNSSI 1253 – Security Categorization and Control Selection for National Security Systems

8. Department of the Treasury-Specific Policies and Standards

a. TD P 85-01 Volume I – Treasury Information Technology Security Policy

b. TD P 85-01 Volume II – Treasury Cybersecurity Control Requirements

c. Treasury Enterprise Cybersecurity Strategy – Strategic goals and implementation roadmap

d. Treasury ICAM Handbook – Identity and credential management standards

e. Treasury COMSEC Standard Operating Procedures

f. Treasury Privacy and Records Management Guidelines

g. TEAS/TIES Operational Documentation – Treasury ICAM Enterprise Services

15. Quality Assurance Surveillance Plan (QASP) For: PROTECTS II– Treasury Enterprise Cybersecurity Technology & Services Applies To: All Call Orders issued under the BPA Prepared By: [Insert CO/COR Name] Date: [Insert Date]

1. Purpose This QASP establishes a systematic approach for monitoring and evaluating contractor performance under the PROTECTS BPA. It ensures that services provided under individual Call Orders meet Treasury’s quality, timeliness, and compliance standards as defined by the Performance Work Statement (PWS), Contract Data Requirements List (CDRL), and specific deliverables.

2. Roles and Responsibilities

Role
Responsibility
Contracting Officer (CO)
Overall contract authority and oversight
COR/Task Monitors
Day-to-day surveillance, verification, and acceptance of deliverables
Contractor
Timely, accurate performance per PWS/Call Order

3. Surveillance Methods

Method
Description
Direct Observation
Monitoring real-time execution activities, meetings, or deployments
Deliverable Review
Evaluation of submitted reports, plans, and dashboards for accuracy/completeness
Performance Metrics
Review of predefined KPIs tied to each Call Order
Interviews/Feedback
Surveys or debriefs with stakeholders or system owners
Audit Sampling
Random sampling of documentation or logs for compliance

4. Performance Standards & Metrics Performance standards shall be drawn directly from each Call Order’s performance table. Examples:

Performance Area
Standard
Acceptable Quality Level (AQL)
Method
Deliverable Timeliness
Reports submitted on or before due date
95% on-time
Deliverable Review
Dashboard Accuracy
Data integrity validated quarterly
98% accuracy
Data Sampling
Audit Readiness
Audit responses submitted within 3 days
100% compliance
RFI Tracking
Knowledge Management
Monthly updates to content repository
90% update rate
Content Review

5. Evaluation Frequency

Activity
Frequency
Formal COR Performance Review
Quarterly
Deliverable Evaluation & Acceptance
Per Call Order schedule
KPI Dashboard Reporting Review
Monthly/Quarterly
Lessons Learned / Quality Debrief
Annually or End of POP

6. Incentives and Remedies

· Positive Performance: May result in CPARS rating elevation, public recognition, or expanded tasking

· Unsatisfactory Performance: May result in a Corrective Action Request (CAR), payment withholding, or contract remedies under FAR 52.212-4

7. Documentation and Records All surveillance activities, communications, CARs, and acceptance memos will be documented in the official contract file and tracked via Treasury’s contract management system.

16. Quality Control Plan (QCP) For: PROTECTS II – Treasury Enterprise Cybersecurity Technology & Services Contractor Responsibility Document Applies To: All Call Orders under the BPA Date: [Insert Date]

1. Purpose This Quality Control Plan (QCP) outlines the Contractor’s approach to ensuring consistent, high-quality service delivery across all task areas and Call Orders issued under the PROTECTS BPA. It describes internal processes for quality assurance, issue tracking, personnel oversight, and risk mitigation in alignment with Treasury’s expectations.

2. Quality Control Objectives

· Deliver all products and services in accordance with BPA requirements

· Prevent, identify, and correct deficiencies before Government detection

· Ensure customer satisfaction through proactive performance monitoring

· Maintain compliance with applicable federal regulations, policies, and technical standards

· Promote continuous improvement throughout the contract lifecycle

3. Roles and Responsibilities

Role
Responsibility
Program Manager (PM)
Oversees QCP implementation, reports to COR, leads risk mitigation actions
Quality Manager (QM)
Manages quality assurance checks, maintains quality records, facilitates reviews
Task Leads
Monitor deliverables and activities for assigned task areas
Project Staff
Follow SOPs, escalate risks, and apply corrective/preventive actions

4. Internal Quality Review Process

Step
Description
Pre-Submission QA Review
All deliverables reviewed for formatting, accuracy, completeness before delivery
Checklist Verification
Deliverables must pass internal checklists aligned to PWS/CDRL criteria
Peer Review
Technical documents undergo peer validation by SMEs
Configuration Control
Version control and change tracking applied to all submitted artifacts
Lessons Learned Analysis
Issues analyzed quarterly to improve repeatability and reduce risk recurrence

5. Metrics and Quality Thresholds

Quality Area
Metric
Threshold
On-Time Deliverables
% of deliverables submitted by due date
≥ 95%
Customer Satisfaction
Government survey results or feedback
≥ 90% satisfaction
Documentation Quality
% of deliverables accepted without rework
≥ 95%
CAP Resolution
Time to resolve Corrective Action Plans
≤ 30 calendar days

6. Issue Management

· Nonconformances: Documented in the Contractor’s issue tracking system

· Corrective Actions: Initiated for recurring or serious issues; shared with COR

· Escalation Protocols: PM notifies COR within 24 hours of critical issue discovery

· Root Cause Analysis: Required for any failed or returned deliverables

7. Communication and Reporting

· Monthly Quality Summary Reports: Submitted with Performance Reports to COR

· Quality Dashboard: Tracks open issues, aging trends, and quality performance

· Quarterly Review Meeting: Contractor reviews QCP performance with Government

8. Continuous Improvement Activities

· Perform retrospective reviews at task completion

· Solicit Government feedback and incorporate recommendations

· Update SOPs and training based on issue trends and best practices

· Conduct semiannual quality training for staff

17. Contract Data Requirements List (CDRL) For: PROTECTS – Treasury Enterprise Cybersecurity Technology & Services Applies To: All Call Orders under BPA [Insert BPA Number] Date: [Insert Date]

Instructions:

This CDRL summarizes all required contract deliverables across the BPA. Each entry includes a unique identifier, title, source Call Order, frequency, format, and submission routing. Contractors must adhere to these requirements unless otherwise modified in a specific Call Order.

CDRL No.
Deliverable Title
Call Order
Frequency
Format
Recipient(s)
CDRL-001
Enterprise Risk Assessment Reports
001
Quarterly
Word/PDF
COR, Risk Office
CDRL-002
POA&M Closure Validation Logs
001
Monthly
Excel
COR, ISSM
CDRL-003
Cybersecurity Policy Package
002
Quarterly
Word/PDF
COR, Policy Lead
CDRL-004
FISMA Compliance Reporting
002
Monthly/Annually
Excel/Word
COR, FISMA PM
CDRL-005
ISCM Dashboards & Metrics Reports
003
Monthly
PowerPoint/Excel
COR, ISSOs
CDRL-006
Secure Code Review Reports
003
As Needed
Word
COR, AppSec Lead
CDRL-007
ICAM System Integration Design
004
As Needed
Word/Visio
COR, ESIM
CDRL-008
MFA Compliance Metrics Dashboard
004
Monthly
PowerPoint/Excel
COR, ESIM
CDRL-009
Incident Response Plan
005
Annually
Word/PDF
COR, IR Lead
CDRL-010
Tabletop Exercise Reports
005
Quarterly
Word
COR, CISO
CDRL-011
Security Architecture Diagrams
006
Per System
Visio
COR, Engineering Lead
CDRL-012
Threat Advisory Bulletins
007
Monthly
Word/PDF
COR, SOC
CDRL-013
IOC Correlation Reports
007
Biweekly
Excel
COR, Threat Intel Lead
CDRL-014
GRC Dashboard Reports
008
Monthly
PowerPoint/Excel
COR, GRC PM
CDRL-015
Cyber Workforce Inventory
009
Annually
Excel
COR, Workforce Dev Lead
CDRL-016
Training Progress Reports
009
Quarterly
Excel
COR, Training Coordinator
CDRL-017
CDM Dashboard Integration Report
010
Quarterly
Word/PDF
COR, CDM Office
CDRL-018
Multi-Year Cybersecurity Program Plan
011
Annually
Word
COR, CISO
CDRL-019
Executive Planning Dashboards
011
Quarterly
PowerPoint
COR, CIO/CISO
CDRL-020
Risk Quantification Framework Guide
012
One-time + Updates
Word
COR, Risk Analytics Lead
CDRL-021
HVA Protection Plan and Architecture Artifacts
013
Per Asset/System
Word/Visio
COR, HVA Program Lead
CDRL-022
COOP and Recovery Plan Documentation
014
Semiannually
Word/PDF
COR, BCP/COOP Coordinator
CDRL-023
Aggregated Cybersecurity Dashboard
015
Monthly
PowerPoint/Excel
COR, Cyber Ops Lead
CDRL-024
CI/CD Security Assessment Report
016
Annually
Word/PDF
COR, DevSecOps Lead
CDRL-025
Security Chaos Engineering Test Plan
017
Quarterly
Word
COR, Resilience Office
CDRL-026
ICAM Roadmap and Execution Strategy
018
Annually
Word
COR, ESIM
CDRL-027
Cyber Policy Governance Framework
019
Annually
Word/PDF
COR, Governance Lead
CDRL-028
COMSEC Key Management SOP
020
Annually
Word/PDF
COR, COMSEC Custodian
CDRL-029
Integrated Master Schedule
021
Monthly
MS Project/Excel
COR, PMO Lead
CDRL-030
AI Risk Assessment Report
022
Quarterly
Word/PDF
COR, AI Oversight Lead
CDRL-031
Transition-In Plan
023
One-time
Word/PDF
COR, Transition Manager
CDRL-032
Handoff Validation Report
023
End of Contract
Word/PDF
COR, System Owners

Notes:

· All CDRLs must follow formatting and review cycle requirements outlined in Appendix C.

· CDRL references must appear in invoices when tied to deliverable-based payment milestones.

· Additional ad hoc deliverables may be requested and tracked via BPA Modifications or individual Call Orders.

UNCLASSIFIED//FOUO

pg. 2 image3.png image1.png image2.png

File details come from the government source that posted it. Updated .