2026.04.06_TRAC2ES_Q&A_SAM.gov.xlsx

XLSX spreadsheet 28 KB Posted

Attached to
CSO Call 003 TRANSCOM "Medical" Regulating and Command & Control Evacuation System (TRAC2ES) Federal contract opportunity
Solicitation number
CSOCall_003_TRAC2ES
Issued by
Department of Defense United States Transportation Command

About this file

This is a Questions and Answers document for CSO Call 003 of the TRAC2ES (Transportation Command "Medical" Regulating and Command & Control Evacuation System) federal contract opportunity issued by United States Transportation Command. The Q&A addresses technical, operational, and administrative clarifications for Phase I white paper submissions due April 9, 2026 by 3:00 PM (CT).

The opportunity seeks modernization and enhancement of the existing TRAC2ES system, a web-based aeromedical evacuation command and control application currently deployed in AWS GovCloud. Key requirements include: progressive modernization of the modular architecture (approximately 75% currently modernized); development of a single mobile application supporting both iOS and Android platforms for medical flight crews, aeromedical evacuation liaison teams, and staging facilities; implementation of DevSecOps practices; support for 8,000 concurrent users across global operations; deployment across multiple impact levels (IL2-IL6) in unclassified and classified environments; 24/7 Tier II/III technical support with defined SLAs (15-20 minute recovery for application failures, 1-hour recovery for database failures); and integration with external systems including DEERS, MEIS, OMDS, and ADVANA. The contractor must inherit the existing ATO expiring March 30, 2026, maintain backward compatibility with existing SOAP interfaces, support cloud-agnostic architecture for both AWS and Azure environments, and deliver a minimum viable product within 30 days of award with full transition occurring during a 60-calendar-day transition period prior to the incumbent contract end date of July 31, 2026. The anticipated budget range is $27M-$37M over the full period of performance (10-month base plus four 12-month option periods). Submissions must include a white paper with Rough Order of Magnitude estimates, firm fixed pricing model, prior demonstration and usage evidence, and a non-traditional contractor self-certification statement if applicable. All text must be in Times New Roman 12-point font. The Government anticipates knowledge transfer meetings with stakeholders and will provide access to test environments and external system interfaces in the non-production environment. Large businesses should anticipate providing a Small Business Subcontracting Plan during Phase III if the effort results in a FAR-based contract.

View the file

Other files for this federal contract opportunity

Other files attached to CSO Call 003 TRANSCOM "Medical" Regulating and Command & Control Evacuation System (TRAC2ES), newest first.
File Type Posted
2026.04.09_TRAC2ES_QA_SAM.gov.xlsx XLSX spreadsheet
Atch 2_TDP.docx DOCX document
Atch 1_Governing Guidance and Directives.docx DOCX document
2026.03.09 CSO Call 003_TRAC2ES.docx DOCX document
Atch 3_NDA TDP.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TRAC2ES Q&A

TRANSCOM25CSO001 - USTRANSCOM Information Technology (IT) Enterprise Modernization (ITEM) Solutions.
Transportation Command "Medical" Regulating and Command & Control Evacuation System (TRAC2ES)
Call 0003 - Questions & Answers
Offeror Question/CommentGovernment Response
We request the government to clarify if they require SAFe implementation formally (ARTs, PI Planning).Formal ARTs with all of the ceremonies
We request the Government to clarify what is the current agile maturity level (team-level Scrum vs scaled SAFe).Team-Level Scrum
We request the Government to clarify what tools are currently used for CI/CD (e.g., GitLab, Jenkins, Azure DevOps)GitLab
Does the Government intend for the contractor to (a) enhance and extend existing TRAC2ES web and mobile applications, or (b) develop new applications? Additionally, should the mobile application provide full functional parity with the web-based system, or support a subset of mission-critical capabilities tailored for operational and DIL environments?(A), It is a subset of mission critical capabilities (B), New applications development based on current requirements.
Are there any existing mobile frameworks, development standards, or Government-furnished mobile solutions that the contractor is expected to leverage or align with?The mobile application is expected to work on both iOS and Android. DoD Mobility Unclassified Capability (DMUC) is the current government office but it is transitioning to INTUNE.
We request government to clarify the current state and desired future approach for TRAC2ES mobile capabilities, including whether the intent is to enhance existing mobile applications or develop new ones, and any specific requirements related to offline/DIL functionality, security integration, and platform/device support that would influence the mobile application architecture?Enhance current mobile capability in development. It will be a single application different functions with the following use case: It is envisioned that Mobile initially would be used by Medical Flight Crews, Aeromedical Evacuation Liaison Teams, and Aeromedical Staging Facilities at or near the flight line to provide a real time ITV event of the patients and their attendants by scanning the currently fielded barcode on theTRAC2ES-generated patient ID wristband. Additional functions would be added to expand the user base to support both tactical patient movement in a kinetic environment and CONUS-based DSCA operations. This product is a software-only solution, and the end user would be required to purchase and maintain the hardware required to host the application. DSCA - Defense Support of Civil Authorities - to provide support to domestic civil governments during emergencies, disasters, or planned events.
We request government t confirm whether Tier I support is provided by an existing organization and whether the contractor’s responsibility is limited to Tier II/III support, including escalation handling and resolution?There is not dedicated separate Tier I support in TRAC2ES. TRAC2ES contractor handles all initial calls at Tier II and escalates to Tier III as required.
We request government to provide historical or estimated ticket volumes for Tier II and Tier III support, including average monthly volume, peak demand periods, and incident categories?Tier 2 average is 263 tickets and Tier 3 is 4.5. Majority of Tier 2 actions are Account administration; creating, modifying, etc., the remains are general customer questions. Tier 3 is software related or Business Intelligence reports requests.
What is the expected interaction model between Tier I and Tier II/III support, including escalation workflows, ownership boundaries, and handoff procedures?There is not dedicated separate Tier I support in TRAC2ES. TRAC2ES contractor handles all initial calls at Tier II and escalates to Tier III as required.
What are the required service level agreements (SLAs) and performance metrics (e.g., response time, resolution time, availability) for Tier II/III support?Application A failure: Time to Full Recovery 15-20 Minutes, Downtime Allowed Max 20 Minutes; Database Failure: Time to Full Recovery 1 Hour, Downtime Allowed Max 1 Hour; Availability Zone Failure (very rare): Time to Full Recovery 1 Hour, Downtime Allowed Max 1 Hour; Patch Maintenance: Time to Full Recovery 15-20 Minutes, Downtime Allowed None. Availability listed in CSO Call.
What ticketing and IT service management tools are currently in use (e.g., ServiceNow), and will the contractor be required to use Government-furnished tools or provide their own?ServiceNow for account requests, Jira tickets for cloud service requests. Developer may use own tools for Tier II/III.
We request government to clarify geographic coverage expectations, user distribution, and any requirements for CONUS/OCONUS support for the 24/7/365 service desk?TRAC2ES has users worldwide and distribution varies
We request government to clarify when training activities are expected to begin relative to MVP delivery and production deployment, and whether initial training is required for MVP capabilities or only for fully operational releases?New users are added daily. Training is required for new users and current users will need training for major releases.
What is the anticipated frequency and volume of training sessions (e.g., initial rollout, recurring sessions, and updates aligned with releases)?Training occurs bi-weekly or as needed for deployments for all user types.
We request government to provide an estimate of the number and types of users requiring training (e.g., administrators, operators, field users, analysts), and whether role-based training is required?100 Advanced Users (PMRC-Level). 50-75 Analysts. 2,000 Medical Treatment Facility patient movement clerk users.
We request government to provide the anticipated timeline and phasing for system rollout beyond the 30-day MVP, including any planned incremental releases or deployment waves?The MVP will be defined during the 60-day transition period and will include sustainment of the current TRAC2ES code and any features the Government and contractor agree upon for Sprint and release schedule
Are there preferred training delivery methods or platforms (e.g., LMS, virtual instructor-led, in-person), and will the contractor be required to develop and maintain training environments and materials?No preferred methods but must be accessible to military personnel worldwide
We request government to clarify any preferences or constraints regarding the use of commercial low-code/no-code platforms as part of the solution, and whether such platforms must operate within DoD-approved cloud environments (e.g., AWS GovCloud, Azure Government) and comply with IL2–IL6, RMF, and Zero Trust requirements?The government doesn't have any preferences or constraints. They will have to comply with IL 2-IL 6, RMF, and Zero Trust requirements.
We request government please extend the due date to 04/20/2026 to cover all the areas with a complaint and clear response.The Government extended the date for submission of Phase I submissions to 1 April 2026.
We request the government to clarify if we can use Arial Narrow for writing the technical response.All font/text, no matter the placement, shall be Times New Roman ≥ to 12 pt.
The solicitation mentions that responses should be submitted electronically via email, followed by a separate confirmation email to acknowledge receipt. However, given the sensitive nature of CUI, I would like to confirm whether this is the preferred method for submitting responses containing CUI or if there is an alternative, more secure method that you would recommend. Please let me know if there are any additional security protocols or specific systems, such as the DOD Secure Access File Exchange (SAFE), that should be used for transmitting CUI securely.The Government confirms that responses should be submitted electronically via email as outlined in the solicitation. However, for submissions containing Controlled Unclassified Information (CUI), Offerors are encouraged to use a secure transmission method, such as the DOD Secure Access File Exchange (SAFE), to ensure compliance with security protocols.
Would you provide more detail on the challenges in scalability, performance, cybersecurity, interoperability, and operational efficiency that need to be addressed by new solutions?The main challenge is moving into a DevSecOps environment when it is available in USTRANSCOM and ensuring these areas are addressedwith any new solution.
We would like to request clarification regarding the inclusion of a Rough Order of Magnitude (ROM) estimate for Phase I. The original CSO indicates that the ROM should be included within the White Paper; however, the language in the specific Call Order appears to treat the ROM as a separate deliverable. Could you please confirm whether the ROM is required to be incorporated into the White Paper submission, or if it may be submitted as a standalone document?The Government confirms that the Rough Order of Magnitude (ROM)should be included within the White Paper submission, as outlined in the original CSO.
Are offeror’s required to “hard delete” or purge the TDP documents within the company environment after the CSO is delivered, or after down-selects are made in future phases?Offerors are expected to handle the TDP in accordance with the Non-Disclosure Agreement (NDA)and any additional security requirements outlined in the CSO.
The CSO states the Government has previously obtained rights in technical data and software. Does the Government hold unlimited rights, Government Purpose Rights (GPR), or limited rights in the current TRAC2ES codebase and database design? Specifically, will the winning contractor receive the complete current source code repository, database schemas, and deployment artifacts with sufficient rights to modify and extend them?Unlimited rights. Winning contractor will receive all code.
The Security-Focused Configuration Plan references eMASS# 263 with a Moderate-High-High (C-I-A) categorization. Will the contractor inherit the existing ATO and eMASS package, or is the Government expecting a new ATO under a re-architected system boundary? If inherited, what is the current ATO expiration date and the status of open POA&Ms?Contractor will inherit existing ATO(s) for Unclassified and Classified if completed prior to contract start. Current ATO expires 30 March, new ATO date is unknown at this time but should be 18 months.
The OMDS ICD (v1.1, January 2025) describes a recently implemented interface replacing the legacy TMDS connection. The MEIS ICD documents both read and write-back capabilities with mission-level data. Are there any planned changes, version updates, or deprecation timelines for the DEERS, MEIS, OMDS, or ADVANA interfaces within the 2026-2031 period of performance that the contractor should account for?No planned changes are not known.
The ICDs document SOAP/SSL interfaces for DEERS, MEIS, ADVANA, and OMDS. The CSO calls for an API-first architecture with real-time data exchange. Does the Government expect the contractor to re-engineer all existing SOAP interfaces to RESTful or gRPC APIs, or maintain backward compatibility with existing SOAP endpoints while building new API-first interfaces in parallel? Are the external system owners (DMDC for DEERS, AMC for MEIS, ADVANA team, JOMIS for OMDS) prepared to accept new interface protocols?These interfaces do not need to be re-engineered.
The CSO calls for migration to a cloud-agnostic environment supporting both AWS and Azure at IL2-6. TRAC2ES currently operates exclusively in AWS GovCloud. Does the Government have an existing Azure IL5/IL6 authorization or environment provisioned, or will the contractor be expected to establish the Azure authorization boundary from scratch? Is the intent for simultaneous multi-cloud deployment, or a primary/secondary failover model?USTANSCOM currently uses AWSGovCloud, future environments will be selected by USTRANSCOM.
Has USTRANSCOM selected a cloud service provider for IL5/IL6, or is the selection of a cloud service provider expected to be part of the contractor's proposed solution?USTANSCOM currently uses AWSGovCloud, future environments will be selected by USTRANSCOM.
Regarding the mobile platform, could the Government please clarify whether the solution will be Government Furnished Equipment (GFE) only or Bring Your Own Device (BYOD)? Additionally, will the mobile application be required to support iOS, Android, or both? What subset of TRAC2ES functionality must be mobile-accessible?It will be a single application different functions with the following use case: It is envisioned that Mobile initially would be used by Medical Flight Crews, Aeromedical Evacuation Liaison Teams, and Aeromedical Staging Facilities at or near the flight line to provide a real time ITV event of the patients and their attendants by scanning the currently fielded barcode on theTRAC2ES-generated patient ID wristband. Additional functions would be added to expand the user base to support both tactical patient movement in a kinetic environment and CONUS-based DSCA operations. This product is a software-only solution, and the end user would be required to purchase and maintain the hardware required to host the application. DSCA - Defense Support of Civil Authorities - to provide support to domestic civil governments during emergencies, disasters, or planned events. Android and iOS
The Topology (v5.0.0, January 2026) shows React servers (items 5-6), a Python server (item 11), and a Podman server (item 12) that are not described in the SSDD (v2.32, May 2025). Could the Government please describe what functionality runs on these servers, and what percentage of the application is modernized versus legacy Tomcat/Java?The React Server (RCT) EC2 instances host the frontend content for the modernized portion of the TRAC2ES application. The primary software process is Apache 2.4, and its sole job is to host the static content that comprises the React application. The PYT instance hosts various Python services used by the application. The primary software process is Python. The running services are: estimated-arrival-service, geojson-server, and sync-service. The Podman Server contain the Apache Superset application. The TRAC2ES program is approximately 75% modernized.
Can the Government please clarify what the current peak concurrent user count is? The CSO targets 8,000, but no baseline is documented.8,000 is the required scalability for concurrent users
Can the Government provide an overview of the current technology stack for TRAC2ES, including primary programming languages, frameworks, and database technologies in use?TRAC2ES current architecture is web-based application hosted in the USTC-U AWS Gov Cloud environment including a primary and alternate site mirrored in two availability zones (AZ) such that at any time there is an active and a warm-standby site. A legacy replication tool [SRO Data-Xtend] is used to keep the databases synchronized across AZs. Patching and deployments are typically performed by patching or deploying to the standby site, verifying the site internally, and then performing a “fail-over” where the sites’ roles are reversed. TRAC2ES utilizes various AWS services include Elastic Load Balancers, Amazon Elastic Compute Cloud (EC2) Amazon Machine Images (AMI) leveraging Red Hat Linux 8.9, Windows 2016 OS, Redis Elastic Cache, Oracle Database 19c, Oracle 12c Fusion Middleware, Apache Http Server, Apache Tomcat.
Is the TRAC2ES_Topology_20260224_5.0.0 document the final, approved version (i.e., no longer “CUI until finalized”), and does it represent the as-is system topology we should treat as authoritative for the current configuration?5.0.0 is the current approved topology and authoritative for the current configuration
Can you provide technical details on the amounts of compute, storage and network throughput that are required by the currently fielded version of TRAC2ES?Monthly average usage: Compute: 30,991.085 hours, Storage: 26,328 GB-months, Throughput: 515.2743 units
In what regions of the world must TRAC2ES be available in IL-6 environments? If these differ from the unclassified environments (IL-2 through IL-5), please advise.TRAC2ES is required worldwide
Does USTRANSCOM already have providers of services that can be leveraged as part of its Zero Trust Architecture for TRAC2ES? For example, Mobile Device Management (MDM) providers with which we could integrate and leverage their services?TRANSCOM in process of developing DevSecOps environment and any ZT providers are unknown at this time.
What is the intended platform for the needed mobile application? Is it intended to be used on Apple iOS devices, Android devices, both, or something else?Both Android and iOS
Could the Government please clarify what constitutes an acceptable Minimum Viable Product (MVP) within 30 days of award?The MVP will be defined during the 60 calendar day transition period and will include sustainment of the current TRAC2ES code and any features the Government and contractor agree upon for Sprint and release schedule
We would like to request clarification on file naming conventions and required submission files. Specifically, should the quad chart be combined with the five-slide (plus title-slide) PowerPoint into a single document? If so, is there any flexibility regarding the 10 MB PowerPoint file size limit? The provided quad chart template already exceeds 2 MB.The Government confirms that the Quad Chartshould be included as the first content slide within the PowerPoint briefing, combined into a single .pptx document along with the title slide and five content slides. Regarding the 10 MB file size limit, Offerors should make every effort to compress images and graphics to remain within the limit.
Page 14 of the CSO states that offerors must provide: (g) Non-Traditional Contractor Self-certification Statement. Does this mean only non-traditional contractors can offer as a prime?No. The Government is seeking white papers from both non-traditional and traditional contractors. Non-traditional contractors should include a statement certifying themselves as such and traditional contractors may respond to (g) as N/A or with a statement that they do not qualify as non-traditional.
Requirements reference multi-cloud and SECRET deployment, while current environments are AWS-based with future SIPR provisioning. Please clarify whether execution is required in both AWS and Azure or if a cloud-agnostic, portable architecture satisfies requirements. Additionally, confirm whether SECRET deployment is required at award or a future-state objective, including any clearance prerequisites.Architecture will be cloud agnostic and a SECRET deployment will be required.
TRAC2ES documentation indicates that classified (SIPRNET) capabilities are planned but not fully provisioned. What are the Government’s expectations for deployment sequencing, data synchronization, and release management between UNCLASSIFIED and future SECRET enclaves?Releases for both Unclassified and Classified environments will be simultaneous.
Where can we find Attachment 1: Phase I – Documentation Submission Requirements?Submission requirements are included on SAM.gov - See Notice ID: TRANSCOM25CSO001
Given strict enclave separation, what are the Government’s expectations for CI/CD pipeline execution, artifact management, and promotion workflows across UNCLASSIFIED and SECRET environments?There isn't a CDES solution currently; the current solution is to transfer via air gapped disc players. Development will be done on NIPR.
Publicly available contractual transactions show that Booz Allen received 1.1M for “TRAC2ES ADD ADDITIONAL MODERNIZATION” in February of last year. Does the TDP include the government-owned IP developed work products developed for this effort?The TDP does not call out the functional modernization explicitly but the modernization efforts have been completed or will be completed prior to end to the current contract and the documents in the TDP updated to reflect the modernization.
Can the Government provide additional insight into the current architectural state of TRAC2ES (e.g., monolithic vs modular) and the expected balance between refactoring, replatforming, and full modernization?TRAC2ES is modular and is undergoing some refactorization and modernization and will be replatforming once DevSecOps environment is available. Reference Executive Order 14028
The PWS mentions mobile applications (plural) – how many different mobile applications will need to be developed and how each one will be used (e.g., primary use case)?It will be a single application different functions with the following use case: It is envisioned that Mobile initially would be used by Medical Flight Crews, Aeromedical Evacuation Liaison Teams, and Aeromedical Staging Facilities at or near the flight line to provide a real time ITV event of the patients and their attendants by scanning the currently fielded barcode on theTRAC2ES-generated patient ID wristband. Additional functions would be added to expand the user base to support both tactical patient movement in a kinetic environment and CONUS-based DSCA operations. This product is a software-only solution, and the end user would be required to purchase and maintain the hardware required to host the application. DSCA - Defense Support of Civil Authorities - to provide support to domestic civil governments during emergencies, disasters, or planned events.
TRAC2ES documentation indicates current deployment within AWS GovCloud. Should offerors assume modernization within this environment, and are there existing constraints or dependencies that must be maintained to support continuity of operations across TC-UGC and TC-CGC/SIPR?Yes, modernization is in the AWS GovCloud; there are currently no constraints
From the Government’s perspective, what are the highest-risk areas in TRAC2ES modernization (e.g., legacy architecture, cybersecurity compliance, integration, or operational continuity) that offerors should prioritize in Phase I responses?Operational continuity and preparation to move to DevSecOps environment
Can you please clarify what is meant by “HIPAA compliant as a Business Associate?”See DOD Instruction 6025.18, page 6, G.2. Definitions and DoD Manual 6015.18, page 95, G.2. Definitions
Will development and test environments provide access to external system interfaces (e.g., DEERS, MEIS, OMDS, ADVANA) to support integration testing for MVP delivery?Yes, in Non-Prod environment
What minimum capabilities are expected to be included in the initial MVP deployment within 30 days of award?The MVP will be defined during the 60 calendar day transition period and will include sustainment of the current TRAC2ES code and any features the Government and contractor agree upon for Sprint and release schedule
What is the personnel security clearance requirement for this effort?Secret
What TRAC2ES capabilities or data elements are expected to operate at IL6 versus IL5 or below?IL-6 capabilities and data elements will be the same as IL-5 with the exception of no external interfaces.
Will the Government require a full IL6 deployment of TRAC2ES or only specific modules operating in a classified enclave?Full deployment without external interfaces
Does USTRANSCOM anticipate a need for Cross Domain Solutions to support data exchange between classified and unclassified TRAC2ES environments? If so, are there existing CDS capabilities already approved for TRAC2ES-related systems?A CDS is required and being developed by USTRANSCOM. DVD read/write devices are currently in use for transfer between NIPR and SIPR.
Should the mobile TRAC2ES capability support classified operational environments, or is it expected to remain an unclassified capability?It will support both Unclassified and Classified environments
May the Government grant offerors an extension on the white paper due date?An extension to the due date is under consideration, and any official decision will be announced on SAM.gov.
Please provide the average number of help desk incidents escalated to the Tier 2/3 team by month, categorized by type, assigned to the incumbent team for resolution.Tier 2 average is 263 tickets and Tier 3 is 4.5. Majority of Tier 2 actions are Account administration; creating, modifying, etc., the remains are general customer questions. Tier 3 is software related or Business Intelligence reports requests.
Is Disaster Recovery in scope for the proposed solution? If so, what are the government's IT policies and SLAs for Disaster Recovery?Disaster Recovery is in the scope of the current solution. The SLA has not been developed yet.
Can you provide the Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for the Production and if applicable to the Non-Production Environments?Application A failure: Time to Full Recovery 15-20 Minutes, Downtime Allowed Max 20 Minutes; Database Failure: Time to Full Recovery 1 Hour, Downtime Allowed Max 1 Hour; Availability Zone Failure (very rare): Time to Full Recovery 1 Hour, Downtime Allowed Max 1 Hour; Patch Maintenance: Time to Full Recovery 15-20 Minutes, Downtime Allowed None
What is the Average Monthly/Annual growth (TB or %) for database storage data?The average monthly usage of storage data is 26.3287 TB. The annual growth remained steady
Is the government's expectation that a full transition of support services from the incumbent contractor will be completed within 30 days of award, or will the government provide a transition timeline for full assumption of service operations that is different than the 30 day deadline for deploying an MVP?There will be a 60 calendar day transition period prior to the end of the current contract of 31 Jul 26. All support services are expected to start with the new contract on 1 Aug 26. The MVP will be defined during the 60 calendar day transition period and will include sustainment of the current TRAC2ES code and any features the Government and contractor agree upon for Sprint and release schedule
Regarding the requirement to deploy a minimum viable product as soon as 30 days after award, please confirm if the contractor is allowed to perform software development in a contractor-owned environment designed to match the technical and security specifications of the government's environment based on the information provided in the TDP documents (e.g., AWS GovCloud with same IL).Yes
Is a TRAC2ES mobile app currently deployed? If so, what TRAC2ES functionality does the mobile app provide?No, not deployed. It will be a single application different functions with the following use case: It is envisioned that Mobile initially would be used by Medical Flight Crews, Aeromedical Evacuation Liaison Teams, and Aeromedical Staging Facilities at or near the flight line to provide a real time ITV event of the patients and their attendants by scanning the currently fielded barcode on theTRAC2ES-generated patient ID wristband. Additional functions would be added to expand the user base to support both tactical patient movement in a kinetic environment and CONUS-based DSCA operations. This product is a software-only solution, and the end user would be required to purchase and maintain the hardware required to host the application. DSCA - Defense Support of Civil Authorities - to provide support to domestic civil governments during emergencies, disasters, or planned events.
Will the support staff have the ability to connect to the application through a remote desktop or government furnished laptop?GFE will be provided
Can the government provide anticipated release management activities (e.g., number of major/minor/ad hoc releases) in a year in the new contract?Sprints will be between 1-4 weeks, agreed upon by the government and contractor. Number of releases will be based on agreed Sprint schedule. Each Sprint should be planned to include a release.
CSO Call 003 requests that the White Paper include “Prior Demonstration and Usage,” including evidence of capability in relevant or representative environments. However, TRANSCOM25CSO001 states that corporate or personnel qualifications and past experience should not be included unless specifically requested in the CSO Call.The Government confirms that Offerors may include concise examples demonstrating successful operational deployment or testing of similar capabilities within the White Paper to address the “Prior Demonstration and Usage”requirement, as specifically requested in CSO Call 003.
Since Call 003 appears to specifically request demonstration of prior usage, please confirm that offerors may include concise examples demonstrating successful operational deployment or testing of similar capabilities within the White Paper to address the “Prior Demonstration and Usage” requirement.Confirming offerors should provide evidence demonstrating capability in relevant and/or representative environments and show experience in successfully fielding solutions into operations. White papers should annotate to what extent specifications and attributes included in the White Paper have been verified (e.g., usage in commercial environments, testing within academia, etc.).
Will the MVP after the down select be built on a Government technology stack in an existing IL2, IL4 or IL5 GovCloud? Or will vendors build and use their own environment to demonstrate the MVP? If using a GovCloud environment, will additional time above the 30-day MVP delivery be allowed for onboarding selected vendors?The MVP will be defined during the 60 calendar day transition period and will include sustainment of the current TRAC2ES code and any features the Government and contractor agree upon for Sprint and release schedule. The vendor will use their own environment to develop.
I have a question regarding the CMMC requirement listed in the solicitation. It states that the contractor must have CMMC Level 2. Could you please clarify whether subcontractors are also required to have a CMMC Level 2 self-assessment, or if this requirement applies only to the prime contractor?DFARS 252.204-7020 applies to both prime contractors and subcontractors if they handle CUI. Prime contractors must flow down the clause to subcontractors, and subcontractors must conduct their own Basic Assessment and submit results to SPRS.
You are requesting a Firm fixed pricing model but no template for this submission was attached. Can you please provide the required template for this? Or can you confirm what you would like to see in this model?The Government has not provided a specific template for the firm fixed pricing model. Offerors should include a clear and detailed Rough Order of Magnitude (ROM)in their submission, outlining projected costs for the full period of performance (base and option periods).
Should Offerors assume that the selected contract structure will support the anticipated five-year period of performance described in the AoI?Yes
Should Offerors assume that demonstration of existing operational capability will be viewed more favorably than conceptual approaches?The Government will evaluate all proposed solutions based on their ability to meet the objectives outlined in the TRAC2ES AoI, considering both existing operational capabilities and conceptual approaches.
Does the Government anticipate evaluating the maturity of the proposed technology or platform as part of Phase I evaluation?The Government will evaluate the maturity of the proposed technology as presented in the provided documentation.
For integration with enterprise systems such as DEERS, MEIS, OMDS, and ADVANA Pegasus, should Offerors assume the availability of existing enterprise APIs and integration services?Yes
Is the intent of this attribute to be operational decision support or technical/back-end optimization, or both?It can be either or both
How does USTRANSCOM define a “deployable MVP within 30 days” across UNCLASSIFIED and SECRET environments? Should offerors assume deployment in both enclaves within that timeframe, and what constitutes Government acceptance for MVP delivery?USTRANSCOM is seeking solutions that are sufficiently mature and capable of being executed or operationally transitioned within 30 days of award to improve upon existing capabilities. While the term "Minimum Viable Product" is used, the emphasis is on the solution's readiness to deliver operational value within the specified timeframe, rather than a prototype or initial iteration.

Offerors are encouraged to propose solutions that can be rapidly implemented and scaled to meet USTRANSCOM's needs.

Due to the diverse nature of the AoI solution attributes, can you please clarify the scope of what you would expect to see in an MVP that could be deployed as soon as 30 days after award?The MVP will be defined during the 60 calendar day transition period and will include sustainment of the current TRAC2ES code and any features the Government and contractor agree upon for Sprint and release schedule.
For the requirement of a minimum viable product as soon as 30 days post-award, will the Government provide early access to test environments or data sets (e.g., simulated UNCLASSIFIED/SECRET instances) to the awardee, or is this expected to be built solely from the TDP?The Government anticipates up to a 60 day transition period based on the successful offeror's techncial approach.
The AoI indicates that solutions may be expected to deliver a Minimum Viable Product within 30 days of award. Could the Government clarify which operational capabilities would define the MVP milestone?The MVP will be defined during the 60-day transition period and will include sustainment of the current TRAC2ES code and any features the Government and contractor agree upon for Sprint and release schedule.
For mobile and DIL operations, what user roles, operational scenarios, and device/MDM constraints should offerors assume, and is mobile capability considered a core requirement for MVP delivery or a phased enhancement?Mobile may or may not be a core capability for the MVP based on status of fielding in the current contract. Decision will be coordinated during the contract transition period.
Can the Government provide a breakdown of the approximately 8,000 users by role/user type and rough geographic distribution?250 Advanced Users (PMRC-Level) / 300 Command and Control Analysts / 2,000 flight medical crews / 5,000 patient movement clerks for global operations. No specific breakdown of distribution butthree Theater Patient Movement Centers are setup for the America (NORTHCOM and SOUTHCOM), Pacific (INDO-PACOM), and Europe (EUCOM, CENTCOM, Africa).
What level of functionality is expected to be supported in a disconnected or low-connectivity environment? Specifically, which core features must remain available to users when operating offline?Prepare draft and store documents for all functions and submit and receive when connected.
Should Offerors assume pricing for hosting, licenses, cloud services, and infrastructure should be included within the ROM estimate?Yes
The CSO identifies an anticipated program budget range of $27M–$37M. Is this range intended as a planning estimate or an expected pricing range for the overall program?The identified program budget range of $27M–$37Mis intended as a planning estimate for the anticipated scope of the program. It provides a general framework for budgeting purposes and reflects the government’s expectations for the program’s overall funding.
Would ROM estimates outside the stated budget range be considered acceptable if supported by a technically sound solution?Yes, ROM (Rough Order of Magnitude) estimates outside the stated budget range may be considered acceptable if they are supported by a technically sound, innovative, and value-driven solution that aligns with the program's objectives and requirements. Offerors are encouraged to provide detailed justifications for any estimates outside the range, demonstrating how their approach delivers superior value, efficiency, or capability to the government. However, offerors should also remain mindful of the government’s anticipated budget constraints when developing their proposals.
Should the ROM include sustainment and operational support activities across the anticipated contract period?Yes
The Phase I submission instructions request a Rough Order of Magnitude (ROM). Should the ROM represent the estimated cost for the full potential period of performance or the cost associated with initial capability delivery?The ROM requested in the Phase I submission should represent the estimated cost for the full potential period of performance, including the 10-month base period and four 12-month option periods, as outlined in the TRAC2ES CSO Call 003.
Please clarify whether large businesses will be required to provide a Small Business Plan during later phases of TRAC2ES, even if not required in the Phase 1 submission.While a Small Business Subcontracting Planis not required during Phase I, large businesses should anticipate the need to provide one during later phases (e.g., Phase III) if the effort results in a FAR-based contract and meets the applicable thresholds. Offerors are encouraged to proactively consider small business participation in their proposed solutions to align with the Government’s objectives.
Section 3.4 states that TRAC2ES “does not rely on the use of Java Applets.” However, figure 4-2 states, “…subsystems shown are implemented in Java” and para 4.1.1.3 states there is, “…developmental Java code…”. Can the Government please confirm that the statements in Section 3.4 are not correct?No Java Applets are used in the TRAC2ES application.
Does performance of this effort require a facility clearance at the Secret or Top Secret level?Secret
Should Offerors assume that the proposed solution must achieve Authority to Operate (ATO) as part of the initial deployment?TRAC2ES has an ATO, solutions will be incorporated into the existing application
Does the Government expect solutions to support operations across all listed impact levels (IL2–IL6) at initial deployment, or should Offerors assume a phased capability approach?Continued use of existing components initially across all Impact Levels. If different solutions offer better performace and cost effectiveness, then they can be incorporated into subsequent planning and Sprint schedules.
Please clarify if you are looking for a new system to replace TRAC2ES or if you are looking for a solution that enhances the existing TRAC2ES system with these AoI solution attributes?The solution will be to enhance the existing TRAC2ES system with the AOI solution attributes. Some re-architecting of the existing TRAC2ES system will be required as the application will be migrated to a DevSecOps environment being developed in USTRANSCOM.
Should Offerors assume continued use of existing TRAC2ES components during modernization efforts?Yes, continued use of existing components initially. If different modernization solutions offer better performace and cost effectiveness, then they can be incorporated into subsiquent planning and Sprint schedules.
Does the Government anticipate a progressive modernization of the current TRAC2ES system, or the development of a fully modernized replacement platform?Progressive modernization
Discrepancies exist between AoI, TDP, and current technical documentation, impacting architecture and staffing. Please confirm the authoritative list of required external interfaces, identifying which are mandatory at award, planned additions, or planned retirements.Refer to TRAC2ES_Topology_20260224_5.0.0
Does the TDP include sufficient details on current system pain points, user feedback, or historical defect logs to allow non-incumbent offerors to propose equivalent innovations? If not, can additional anonymized data be released to level the information asymmetry?No. The TDP does not include system pain points, user feedback, or historical defect logs.
What is the planned transition period from the current incumbent contract (ending around May 31, 2026) to the new awardee? Will the Government provide a transition plan or support (e.g., knowledge transfer sessions) to mitigate any advantages from the incumbent's institutional knowledge?The Government anticipates extending the current contract through 31 Jul 2026. The Government anticipates up to a 60 day transition period based on the successful offeror's techncial approach. The Government anticipates knowledge transfer meetings stakeholders.
What is the required mobile device management (MDM)/security stack and authorization boundary assumptions?Architecture will be cloud agnostic and a SECRET deployment will be required.
Phase I requires pricing despite a multi-faceted, evolving scope. Please clarify whether the firm-fixed-price model should cover the full five-year scope or if phased pricing (e.g., transition, sustainment, modernization, optional capabilities) is acceptable.The pricing model should provide the Government with an understanding of how the offeror's solution would be priced. There are no Government directed requirements.
Under Phase 1 Submission requirements, #3 mentions a firm fixed pricing model. Does the government want that as part of the ROM section in the white paper or a separate document?The firm fixed pricing model should be included within the ROM section of the white paper rather than as a separate document. Offerors should ensure the ROM provides a clear representation of the projected costs for the proposed solution, aligned with the Government’s requirements.
The system currently depends on several licensed COTS tools despite modernization goals. Please identify priority COTS products for reduction or elimination and confirm whether interim sustainment during transition is acceptable under a phased modernization approach.Oracle Identity Management is being replaced with the E-ICAM solution, along with the Windows Server EC2 instances that hosts them. Oracle databases will be migrated to AWS RDS Oracle databases.
The requirement includes both AI-enabled development and operational analytics across sensitive data environments. Please define required AI/ML use cases and constraints related to hosting, model location, training data, retention, and use of PHI/PII/CUI/classified data.There are approved AI/ML tools that can be used on specific Impact Level environments for development. There are no use cases at this time for operational analytics.
The AoI specifies 24/7 Tier II/III support, while current operations include a separate Tier I function. Please clarify the Tier I/II/III service desk boundaries, including whether Tier I remains external, what ITSM platform will be provided, and required response/resolution metrics by severity.There is not dedicated separate Tier I support in TRAC2ES. TRAC2ES contractor handles all initial calls at Tier II and escalates to Tier III as required. ServiceNow is the ITSM. Respond to escalated production support issues that cause work stopage or operational problems with the system and ensure the Production system operates without interuption to functional users. Servertiy 1 issues shall be acknowledged to Tier III within 15 minutes and the the Government within 4 business hours and resolution provided withing 1 business day. Severtity 2 and 3 issues shall be acknowledged to Tier III within 1 hour and to the Government within 1 business day and resolution provided within 5 business days. Software defects that result in a work stoppage or impact to business operations shall result in an unplanned softwarre Hotfix. Application A failure: Time to Full Recovery 15-20 Minutes, Downtime Allowed Max 20 Minutes; Database Failure: Time to Full Recovery 1 Hour, Downtime Allowed Max 1 Hour; Availability Zone Failure (very rare): Time to Full Recovery 1 Hour, Downtime Allowed Max 1 Hour; Patch Maintenance: Time to Full Recovery 15-20 Minutes, Downtime Allowed None.
Please define how the 99.3% availability requirement will be measured (scope, time basis, inclusion/exclusion of planned outages or partial system impacts).Availability is measured monthly by dividing the time (minutes) that the system was available by the total minutes within the month. This will include scheduled downtime.
Current operations include 24/7 support and established processes; prior materials referenced a 45-business-day transition. Please confirm whether a formal transition period will be provided, including expected duration, incumbent knowledge-transfer support, and Government-furnished assets available at transition start (e.g., code repositories, pipelines, ALM/ITSM tools, cloud environments, test data, runbooks, licenses).The Government anticipates up to a 60 day transition period based on the successful offeror's techncial approach. The Government anticipates knowledge transfer meetings with stakeholders.

File details come from the government source that posted it. Updated .