Attachment 3_Technical Approach Matrix.xlsx

XLSX spreadsheet 24 KB Posted

Attached to
Commercial Testing Services Federal contract opportunity
Solicitation number
HS002122R0021
Issued by
Defense Counterintelligence and Security Agency

About this file

This file contains a technical approach matrix and description of a federal contract opportunity for commercial testing services. The technical approach matrix outlines requirements for a candidate management system, assessment administration services, digital badging, technical support, and program management to support the Department of Defense's security workforce certification program. Key requirements include role-based access, data storage and reporting, data transfer services, customer service, assessment center management, and training for agency staff. The related federal contract opportunity is soliciting proposals for these commercial testing services with an anticipated one year base period of performance and four one-year option periods. Proposals are due by September 30, 2022, and the associated North American Industry Classification System code is 611710 with a $21 million small business size standard and no set-asides. The Defense Counterintelligence and Security Agency is the contracting agency.

View the file

Other files for this federal contract opportunity

Other files attached to Commercial Testing Services, newest first.
File Type Posted
DCSA RFP HS0021R0021 Commercial Testing Services A02.pdf PDF
DCSA RFP_HS0021R0021_Commercial Testing Services_A01.pdf PDF
Attachment 4_Question and Response Template.xlsx XLSX spreadsheet
Attachment 1_CDRL A00001-A00020.pdf PDF
Attachment 4_Q-A Template.xlsx XLSX spreadsheet
Attachment 2_Pricing Workbook.xlsx XLSX spreadsheet
Attachment 5_Small Business Subcontracting Plan.docx DOCX document
DCSA RFP_HS002122R0021_Commercial Testing Services.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sheet1

CUI / Source Selection Information. See FAR 2.101 and 3.104.
Technical Approach Matrix
Offeror Name:
Offeror POC:
Offeror POC Email / Phone Number:
Date:
The instructions for completing matrix are as follows: Offerors shall fill out columns C (yes/no) and D (comments). Offerors are required to respond using the workbook with either a “yes” or “no” answer. Line items that identify specific characteristics and features require a detailed response. Offerors shall provide a detailed description of the specific functionality of the characteristic or feature identified. Where no response is provided, DCSA will assume that the noted feature or capability is not provided by the Offeror. Please do not alter the response matrix's numbering or list of features/capabilities.
PWS ReferenceTaskYes/No
(To be completed by the Offeror)Offeror CommentsOfferor Solution Meets Requirement (To be completed by the Government)Offeror Solution Does Not Meet Requirement

(To be completed by the Government)

5.1Shall provide a platform that provides candidate management, data storage and reporting, system interface capability, digital badging, data transferring, Assessment administration, remote proctoring, and web monitoring.
5.1.1Shall manage and maintain a platform that: Supports the full lifecycle of attaining and maintaining a SPēD certification or credential.
5.1.1Shall manage and maintain a platform that: Maintains an electronic database.
5.1.1Shall manage and maintain a platform that: Manages all certification and credential account activities.
5.1.1Shall manage and maintain a platform that: Manages and maintain digital badging.
5.1.1Shall manage and maintain a platform that: Provides web monitoring service to analyze the potential likelihood of exposures, breaches, intellectual property theft, and other suspicious internet activity that may be of concern to SPēD certification assessments and accreditation standards.
5.1.1Shall manage and maintain a platform that: Facilitates the transfer of data files.
5.1.1Shall manage and maintain a platform that: Facilitates Assessment administration data.
5.1.1Shall manage and maintain a platform that: Provides updates to the candidate certification and credential records.
5.1.1Shall manage and maintain a platform that: Provides a dedicated customer service center to assist candidates with password resets, account issues, system errors, assessment scheduling and rescheduling, and answering frequently asked questions available Monday-Friday, 0800-1630 EST.
5.1.1Shall manage and maintain a platform that: Manages the functions of daily CMS program administration.
5.1.2The platform shall be a web-based or cloud-based application designed to securely manage, track, and store all SPēD certification activities.
5.1.2The platform must include: Candidate demographic information (first name, last name, DoD ID number, address, phone number, email address, government status, job series, rank, grade, owning organization).
5.1.2The platform must include: Obtain and maintain certifications/credentials
5.1.2The platform must include: Maintenance and renewal activities.
5.1.2The platform must include: Digital badging information and issuance.
5.1.2The platform must include: Free and for purchase option to print certification and credential certificates.
5.1.2The platform must include: Provide a login in page for all user roles, which includes DCSA terms of use and retention agreements, password reset, and two-factor authentication.
5.1.2The platform must include: Landing page for candidate demographic information, profile management, certification and credential status review, certification renewal, certification assessment registration and scheduling.
5.1.2The platform must include: DCSA certification renewal auditing capability.
5.1.2The platform must include: Certification, credential, and Assessment administration data reporting capabilities, assessment scheduling, rescheduling, and cancellation capabilities for candidates and administrators.
5.1.2The platform must include: Auto-renewal and manual certification renewal completion capabilities based on certification renewal guidelines.
5.1.2The platform must include: Interact directly to candidates in the form of a government approved series of event-based emails to keep candidates informed of their program status.
5.1.2The platform must include: Real-time transaction refresh capability, provide tracking and status of all candidate profile and certification transactions.
5.1.2The platform must include: Facilitate Assessment registration and enable certification maintenance activities.
5.1.2The platform must include: Automated capability to receive and distribute transferred data files, digital credentials, and update candidate records in the system.
5.1.2The platform must include: Verification functionality to validate candidate information at least every 365 days.
5.1.2The platform must include: Support Microsoft Edge, Mozilla Firefox, Apple Safari, and Google Chrome browsers.
5.1.2The platform must include: Input international addresses and telephone numbers, as many candidates reside outside the continental United States.
5.1.2The platform must include: Reliable operational system, Sunday through Saturday between 12:00 a.m. and 11:59 p.m. ET, with maintenance outages restricted to Saturdays and Sundays.
5.1.2The platform must include: Environment to Assessment program performance and updates.
5.1.2The platform must include: Pilot or Sandbox environment which will allow the government and Contractor to Assessment program performance and updates with no risk to the production environment.
5.1.2The platform must include: Improve products and services as required to meet the contract technical requirements.
5.1.2The platform must include: Provide role-based access to define permissions and grant access for each user and administrative role. These roles include but are not limited to: individual candidates or user access, CDSE Administrators or Program Managers, CDSE auditors, Component Service Representatives (CSRs) access for each owning organization, and Contractor customer support technicians. The CSR, CDSE Administrator or Program Manager, CDSE auditors shall have reporting access. CSR reporting access shall be specific to their owning organization. The Offeror shall establish initial role-based access for CDSE Administrators, CDSE auditors, and CSRs.
5.1.2The platform must include: Manage candidate registration, maintenance, digital badging, reporting, and renewal activities.
5.1.2The platform must include: Provide candidate access to SPēD candidates that require access to create an account, schedule and reschedule assessments, view and download assessment results (to include specific areas of strengths and weaknesses), view certification status, submit reasonable accommodations request, and conduct certification renewal/maintenance activities, such as uploading Professional Development Units (PDUs) for certification renewal. Candidates must have the ability to initiate forms for renewal, appeals, and waiver activities as well as upload/attach documentation to their profile.
5.1.2The platform must include: CDSE Program Managers or assigned System Administrators role based access. The CDSE Program Manager or assigned System Administrator require access to all candidate and administrator certification activities and functions, as well as, CMS modifications and updates to include view and analyze Assessment results, manage assessment item information, review and audit candidate certification renewal activities, manage candidate accounts, access to additional CMS functions and capabilities, create user role-based access accounts, data reporting for all candidates and owning organizations, and approve candidate assessment requests. Program Managers and Administrators shall have the capability to set and adjust the percentage of total candidate records to audit renewal documentation. Program Managers and System Administrators shall be able to set date ranges for auditing candidate records.
5.1.2The platform must include: CDSE Auditor role based access. CDSE Auditors require access to all candidate certification activities. CDSE Auditors also require access to manage all Component Service Representative CSR activities. CDSE Auditors require access to review and audit candidate certification renewal activities manage candidate accounts, view candidate provided documentation, create role-based access for candidates and CSRs, data reporting for all candidates and owning organizations, and approve candidate assessment requests.
5.1.2The platform must include: Component Service Representative (CSR) role based access. CSRs are individuals identified by CDSE, with access to view and manage only candidates assigned to their organizations. CSRs require access to view and manage candidate demographic information, approve or deny candidate assessment requests, view candidate provided documentation, solicit data reporting for candidate certification and Assessment administration, and have the ability to submit incident or trouble tickets on the candidate’s behalf. CSRs will be granted access by the government to view reports only for their owning organization.
5.1.2The platform must include: Data Storage. The CMS shall have the capacity to store all active and inactive candidate information. Data transferred to storage should have assessment item-level data (e.g., assessments delivered, records created, accounts deleted). Data should contain all records pertaining to the SPēD Certification Program,(e.g., candidate information, certification and credential, Assessment administration).
5.1.2The platform must include: Storage capacity shall include standard SPēD certification and credential documents, such as authorization to Assessment, reasonable accommodations, assessment request verification, appeals and waivers verification, renewal form verification documents, candidate provided documentation, and images used for all templates and forms.
5.1.2The platform must include: CMS storage must be capable of storing all relevant candidate and certification/credential data, graphics, and documents for a minimum of 10 years, in accordance with DCSA Manual (DCSAM) 00-04 V2, “10-Year Storage Requirements.”
5.1.2The platform must include: Data backup shall include all certification assessments, candidate assessment results, certification status, and all other candidate record information.
5.1.2The platform must include: In an event affecting candidate data, certification assessments, or information deemed to be PII, Controlled Unclassified Information (CUI), the Contractor shall provide a Service Level Agreement (SLA) to provide a resolution in 72 hours if 100 or fewer users are impacted, and 48 hours if 101 or more users are impacted. The report will be submitted in a Contractor and Government approved format.
5.1.2The platform must include: Ability to log in to the Contractor CMS and obtain electronic reports on all candidate, certification, digital badging activities and functions through a hypertext transfer protocol secure (HTTPS)/Secure Sockets Layer (SSL) connection.
5.1.2The platform must include: Reporting availability for CDSE and CSRs to access Sunday through Saturday, between 12:00 a.m. and 11:59 p.m. ET, with maintenance outages restricted to Saturdays and Sundays.
5.1.2The platform must include: Digital credentialing capabilities for the secure display of learning, certification, and credential accomplishments online.
5.1.2The platform must include: CDSE and CSR role based access to generate reports across all data collected during registration, scheduling, Assessment, digital credentialing issuance, and certification maintenance/renewal process.
5.1.2The platform must include: Data reporting to securely manage, track, and store all SPēD certification activities. Data reporting role based access for Component Service Representatives, CDSE Administrator or Program Manager, and CDSE auditors. System and Assessment administration reporting is pivotal aspect to evaluate program performance.
5.1.2The platform must include: System Interface Capability: The CMS shall have the flexibility to change over time as web data interfaces mature and require updates and upgrades. Currently, data exchange does not require the Contractors CMS to interface directly with the CDSE LMS. Contingent upon the approval of the DCSA Office of the CIO, the Contractors CMS shall have the capability to interface with CDSE’s current LMS to securely transfer candidate certification data files.
5.1.3Data reports. CDSE requires the capability to generate reports with customizable fields and filters across registration, scheduling, Assessment, and certification maintenance/renewal processes.
5.1.3All reports shall have the capability to customize data fields and date ranges to include by not limited to: candidate first name, candidate last name, email address, phone number, user identification number, owning organization, job series, DoD ID, Government status, state, country, date, month, year, quarter, mean assessment score, assessment scheduled, assessment canceled, assessment, rescheduled, assessment no-show, assessment pass, assessment fail, assessment delivered, assessment failed percentage, assessment passed percentage, average exam item incorrect, average exam item skipped, certification program, credential program, assessment center, professional development units earned, assessment item score, assessment item response, assessment time, certification assessment, credential assessment, expiration, renewal, active, inactive, conferral, professional development categories submitted, renewal forms approved, renewal forms denied, renewal forms submitted, digital credentials issued, digital credential accepted, digital credential revoked, certified, active account, inactive account, assessment retakes, assessment location, survey question, NDA response, assessment item response, certification renewal activities, assessment administration response, and assessment attempts.
5.1.3Offeror shall provide the capability for CDSE and CSR users to generate reports across all data collected during registration, scheduling, Assessment, and certification maintenance/renewal processes when a candidate takes action in a contractor-provided system or tool.
5.1.3Each role based access shall be able to generate customizable reports.
5.1.3Component Service representatives shall be able to generate reports only for their owning organization.
5.1.4The Offeror shall have a password-protected file transfer program (e.g., Security File Transfer Protocol (SFTP)) for shared use between assessment developers, Contractors, and DCSA. Secure files will be exported every Thursday NLT 7 a.m. ET for processing, if required.
5.1.5The Offeror shall have a dedicated customer support center open from 8 a.m. through 4:30 p.m. ET, capable of fielding candidate inquires, calls, emails, and chat activity.
5.1.5The customer support center shall provide password reset and Assessment scheduling and rescheduling assistance.
5.1.5The Customer Support Center shall monitor, track email and chat responses and provide monthly customer support center report metrics on frequently asked questions and any incidents that were resolved.
5.1.5The Customer Support Center landing page shall have a system-level custom home page supporting other messaging capabilities within the system (i.e., chat and email links) and shall be able to send event-based emails to inform candidates of status and closing of issue.
5.1.5The Customer Support Center shall have technical support trained to provide a tiered menu of responses to incidents (initial level of assistance), with an 85% initial response within two business days, 95% resolution within four business days.
5.1.5The Customer Support Center shall also have processes when the call requires more in-depth technical support and troubleshooting, with higher support (i.e., understanding of certification activities and policy matrix) and an 85% initial response within two business days and a 95% resolution within four business days, managed by reportable metrics.
5.1.5The Offeror shall have knowledge of SPēD certification program business processes and protocols is required.
5.1.5The Offeror shall provide the Government support to resolve issues regarding the candidate management system.
5.1.6The Offeror shall conform to protective standards outlined in DoD Directive (DODD) 5400.11, “DOD Privacy and Civil Liberties Programs”, DODM 5200.01, “Information Security Program: Protection of Classified Information Vol. 3”, and DODI 5200.48, “Controlled Unclassified Information (CUI)”, concerning handling and protection of PII and information determined to be CUI.
5.1.6The Offeror shall meet minimum FAR standards and clauses for protection of PII and be adaptable over the lifecycle of the contract.
5.1.7The Contractor shall implement assessment administration services for DoD, Federal, and contractor security professionals no later than 60 days after contract award date. This includes secure electronic assessment delivery, assessment data collection, secure transfer of Assessment information, assessment proctoring, and assessment publishing support.
5.1.7The Contractor shall execute government-approved standard operating procedures (SOP) and business rules for all key tasks related to assessment services. The Contractor shall have SOPs and business rules approved by the Government no later than 30 business days after contract award date.
5.1.7All Assessment materials must be secured when not in use.
5.1.7.1The Offeror shall have consistent assessment event procedures and processes approved by the Government. This includes the requirement to have assessment centers available for worldwide assessment based on specific time zones. Seating to accommodate at least 5-20 candidates shall be available for SPēD certification assessments. In addition, a professionally trained and approved Assessment proctor shall be available during assessment operation hours.
5.1.7.1Assessment Centers must comply with facility safety and standards consistent with certification assessment of candidates (e.g., facility cleanliness, furniture comfort, noise reduction, operational assessment equipment, appropriate lighting and heating, local health policies, ventilation and air cooling systems, accommodations for persons with disabilities).
5.1.7.1The Contractor may deliver assessment at Contractor owned and operated or third-party subcontracted Assessment centers. If assessment centers are subcontracted, they must meet Government- and Contractor approved requirements for reliable Assessment of adults, to include accommodations for persons with disabilities.
5.1.7.1The Contractor is responsible for providing all facilities, personnel, software, equipment, tools, materials, supervision, hosting, and other items and services necessary to provide SPēD assessment administration services.
5.1.7.1Assessment services and facilities shall comply with the Web Content Accessibility Guidelines (WCAG). WCAG 2.0 guidelines, published by the Web Accessibility Initiative (WAI) of the World Wide Web Consortium (W3C), are an international standard stricter than the Americans with Disabilities Act (ADA), Section 508. WCAG 2.0 guidelines provide a single shared standard for making web content accessible to disabled users that addresses the needs of individuals, organizations, and governments. Candidates with disabilities requiring assistance beyond what WCAG 2.0 and Section 508 provide will do so via request to the Contractor.
5.1.7.1The Contractor must grant the Government access to conduct periodic inspections and audits at Assessment centers.
5.1.7.2Assessment shall be available no later than five business days after candidate approval and be capable of administering up to two hour and thirty-minute assessments. This includes electronic delivery through remote proctoring and proctored Assessment at Offeror owned and operated or subcontracted Assessment centers Monday through Friday during normal business hours, excluding Federal holidays (see paragraph 1.6.3.3.). Preferred normal business hours are 8:00 a.m. to 4:30 p.m. in the respective time zone. Times may be negotiable based on Assessment center availability, location, and target population.
5.1.7.3Assessment administration services are required at Offeror owned and operated facilities.
5.1.7.3DCSA requires Assessment services in all 50 states (CONUS) and at designated locations outside contiguous United States (OCONUS) commercial facilities and military installations.
5.1.7.3For OCONUS, Assessment is preferred on a military installation. If Assessment cannot occur on a military installation, the Contractor shall provide an alternate Assessment location within 50 miles of the nearest military installation that meets government approved security measures.
5.1.7.4Assessment Centers must meet all physical conditions listed in PWS 5.1.7.4
5.1.7.5Reasonable Accommodations: The Offeror shall have a system for evaluating accommodations meeting the above standards. Accommodations will be approved by the Government and executed by the Offeror-approved SOP. The Offeror shall have reasonable accommodations to include, but no limited to extra time (30 minutes, double assessment time, half assessment time), glucose testing supplies, separate room, bathroom break, reader, recorder, sign language interpreter, and other. The Government CT Program Manager will coordinate necessary Assessment for accommodations with the Offeror Program Manager.
5.1.7.6Contractor Assessment centers shall have defined and consistent protocols for Assessment administrators/proctors in the form of a government approved, Contractor formatted, Assessment Proctoring SOP
5.1.7.6Proctors shall have signed NDAs on file with the Contractor, available for government review upon request.
5.1.7.6The Assessment Proctoring SOP will address proctor behavior and managing incidents at the Assessment center. The SOP shall be provided to the Government 60 days after the contract award date and upon each update.
5.1.7.6Any incident involving a candidate will be tracked and reported as an attachment in the Contractor’s program manager monthly status report, due the 5th calendar day of each month.
5.1.7.6The Contractor shall conduct proctor training, enforce standards, and monitor proctor conduct across Assessment centers.
5.1.7.6The Contractor shall have a defined role specific to the Assessment center environment and conduct at least four random quality assurance (QA) checks each contract year, focusing primarily on those Assessment Centers with a history of complaints and third party (third party-a Assessment center not directly owned-operated by the vendor). These QA checks will be documented and tracked by the Contractor Program Manager and delivered to DCSA in the MSR. Included in the SOP will be detailed documented exam delivery procedures, including chain of custody, storage, and disposal of hard copies of assessments in the event of an accommodation.
5.1.7.6At a minimum (other forms of identification verification can be added over the life of the contract) the proctor will conduct two- credential validation of candidate identification prior to signing the candidate in for Assessment.
5.1.7.6The Contractor shall have the capability to deactivate an Assessment center if there is a breach in assessment security, data, or other any situation reviewable to determine action to temporarily or permanently deactivate an Assessment center. The decision to temporarily or permanently deactivate an Assessment center will be determined by the Contractor.
5.1.7.7The Contractor shall publish assessments provided by the Government and protect Government Furnished Information (GFI) as “CUI,” unless directed otherwise.
5.1.7.7The Contractor shall provide rescore data and confirmation of candidate scoring.
5.1.7.7The Contractor shall have a clearly defined assessment publishing workflow process, including QA reviews and SFTP exchange of assessments for Government review upon request. This SFTP or other secure transfer protocol should be capable of storing and processing assessment reviews.
5.1.7.7There shall only be nine publications per contract year.
5.1.7.7The Government will provide a Question & Assessment Interoperability (QTI) file for current and future certification assessment instruments. The Contractor shall use this QTI file to package the assessment for delivery.
5.1.7.7The Contractor is responsible for providing simulation software to the government for QA checks of the QTI file prior to assessment publishing. Each assessment shall have multiple versions (forms) of the assessment per certification and credential, as requested by DCSA.
5.1.7.7The Contractor shall provide QTI-formatted files back to the Government via SFTP for each published assessment. Assessments can be up to two and a half hours with flexibility built-in to adjust the timing as Assessments change over time and for reasonable accommodations request. A meaningful feedback instrument shall be provided within the system to the candidate and viewable by the government and in accordance with National Commission for Certifying Agency standards.
5.1.7.8The Government expects a minimum of two updates to each certification and credential assessment instrument per year;
5.1.7.8The Contractor shall follow the government approved assessment publishing workflow processes and have the assessment uploaded and available for candidate Assessment within 21 business days after receipt of the QTI file from the Government or its representative.
5.1.7.8The Contractor shall provide an electronic Assessment Publishing Notification (email message) to the government commercial Assessment program manager at least 24 hours prior to the assessment being published and available live to the community.
5.1.7.9Administering Assessments: The Contractor shall be prepared to administer 10,000 assessments to include surge hours during each year of the contract (based on the potential for five additional certifications and/or credentials over the contract life). Currently there are six certification program and three credential program assessments in production. Assessments are either 120 minutes or 150 minutes in duration. However, assessment administration must be flexible to adjust for required changes to assessment length and reasonable accommodations. (Security Fundamentals Professional Certification (SFPC), Security Asset Protection Professional Certification (SAPPC), Security Program Integration Professional Certification (SPIPC), Special Program Security Certification (SPSC), Industrial Security Oversight Certification (ISOC), Physical Security Certification (PSC), Adjudicator Professional Certification (APC), Due Process Adjudicator Professional Credential (DPAPC), and Antiterrorism Credential (ATC))
5.1.10The Contractor is responsible for every aspect of program management based on the Government policies and guidance listed within this PWS.
5.1.11The Contractor shall provide training to CDSE Certification Division personnel related to Assessment administration, candidate management system procedures, reporting, and data transfer services (reports).
5.1.11Training shall be provided virtually, no later than 30 days after the date of award and as needed.
5.1.11There shall be annual refresher training provided by the Contractor.
Government must select either "Offeror Solution Meets Requirement" or "Offeror Solution Does Not Meet Requirement" for each row. In order to considered for award, all rows must be marked as "Offeror Solution Meets Requirement."

File details come from the government source that posted it. Updated .