DRAFT PWS 2 Tabo 2027 DCISE_VDP.DC3.pdf

PDF 378 KB Posted

Attached to
RFI Amendment 2: Request for Information DC3 Technical, Analytical, and Business Operations (TABO) Federal contract opportunity
Solicitation number
FA701427DXXXX
Issued by
Department of the Air Force Headquarters District Washington

About this file

This Performance Work Statement (PWS) details a contract for the Department of Cyber Crime Center (DC3) Vulnerability Disclosure Program (VDP) and Defense Industrial Base Collaborative Information Sharing Environment (DCISE). The contract aims to enhance cybersecurity for the Department of War (DoW) and Defense Industrial Base (DIB) through comprehensive vulnerability management and threat analysis services.

The contract covers 12 key tasks divided into three main areas: Tasks 1-5 support the Vulnerability Disclosure Program, Tasks 6-11 focus on DCISE functions, and Task 12 covers program management. Critical requirements include managing the entire lifecycle of vulnerability reports, identifying and engaging system owners, conducting detailed vulnerability analysis, facilitating communication between researchers and DoW components, developing cyber threat intelligence, creating mitigation strategies, and maintaining the DCISE operational environment. The period of performance is anticipated to be a 12-month base period with four 12-month option periods, located at 911 Elkridge Landing Road, Linthicum Heights, MD. Key personnel include a Program Manager and DCISE Technical Lead, both requiring Top Secret/Sensitive Compartmented Information (TS/SCI) clearance eligibility.

View the file

Other files for this federal contract opportunity

Other files attached to RFI Amendment 2: Request for Information DC3 Technical, Analytical, and Business Operations (TABO), newest first.
File Type Posted
DC3 TABO RFI QA.pdf PDF
PWS 1 Tabo 2027 OED_CFL.DC3_1.7.26_REV1.pdf PDF
PWS 3 Tabo 2027 XT.CIO.CS_DC3_1.7.26_REV1.pdf PDF
PWS 4 Tabo 2027 ER_XE.DC3_1.7.26_REV1.pdf PDF
PWS 2 Tabo 2027 DCISE_VDP.DC3_1.7.26_REV1.pdf PDF
PWS 5 Tabo 2027 Sec_HR_JA.DC3_1.7.26_REV1.pdf PDF
DRAFT PWS 1 Tabo 2027 OED_CFL.DC3.pdf PDF
DRAFT PWS 3 Tabo 2027 XT.CIO.CS_DC3.pdf PDF
DRAFT PWS 5 Tabo 2027 Sec_HR_JA.DC3.pdf PDF
DRAFT PWS 4 Tabo 2027 ER_XE.DC3.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CUI FA7014‐XX-X-XXXX

CUI

PERFORMANCE WORK STATEMENT

FOR

Vulnerability Disclosure Program (VDP) Defense Industrial Base Collaborative Sharing Environment (DCISE)

AT

Department of Defense Cyber Crime Center (DC3)

23 December 2025

DRAFT

Controlled by: AFDW/PK CUI Categories: PROCURE Distribution/Dissemination Controls:

FEDCON AFTER AWARD

POC: Ulrike Powell

Contents

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 GENERAL

1.2 SCOPE

1.3 BACKGROUND

SECTION II

2.0 TASKS

2.1 TASK 1 – REPORT INTAKE, VALIDATION and TRIAGE

2.2 TASK 2 – IDENTIFY and ENGAGE SYSTEM OWNERS

2.3 TASK 3 – REPORT ANALYSIS

2.4 TASK 4 – INTEGRATION, DISSEMINATION and COMMUNICATION

2.5 TASK 5 – MITIGATION, REPORTING and ANALYSIS

2.6 TASK 6 – INCIDENT and THREAT RESPONSE

2.7 TASK 7 – REPORT and PRODUCT GENERATION

2.8 TASK 8 – DATA MANAGEMENT REQUIREMENTS

2.9 TASK 9 – PROGRAM MANAGEMENT and PROCESS IMPROVEMENT

2.10 TASK 10 – OUTREACH ENGAGEMENT and COMMUNICATION

2.11 TASK 11 – TECHNOLOGY and SERVICES MANAGEMENT

2.12 TASK 12 – PROGRAM MANAGEMENT

SECTION III

3.0 SERVICE SUMMARY

SECTION IV

4.0 DELIVERABLES

4.1 DELIVERABLES MEDIA

4.2 PLACE(S) OF DELIVERY

4.3 BASIS OF ACCEPTANCE

4.4 DRAFT DELIVERABLES

4.5 WRITTEN ACCEPTANCE/REJECTION BY THE GOVERNMENT

4.6 MARKINGS

4.7 NON-CONFORMING PRODUCTS OR SERVICES

4.8 NOTICE REGARDING LATE DELIVERY/PROBLEM NOTIFICATION REPORT

(PNR) 27

SECTION V

5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,

INFORMATION, OR SERVICES

5.1 GOVERNMENT FURNISHED EQUIPMENT (GFE)

5.2 GOVERNMENT-FURNISHED INFORMATION (GFI)

5.3 FACILITIES ACCESS AND RESOURCE USAGE

5.4 CONTRACTOR FURNISHED ITEMS AND SERVICES

5.5 CONTRACTOR FURNISHED DATA

SECTION VI

6.0 GENERAL INFORMATION

6.1 PERIOD OF PERFORMANCE

6.2 PLACE OF PERFORMANCE

6.3 PERFORMANCE SCHEDULE

6.4 TRAVEL

6.5 QUALITY CONTROL

6.6 EMERGENCY OPERATIONS/MISSION ESSENTIAL PERSONNEL

6.7 SYSTEM FOR AWARD MANAGEMENT (FORMERLY CMRA)

6.8 SECURITY INSTRUCTIONS

6.9 MISCELLANEOUS PARAGRAPHS

SECTION VII

APPENDIX A – SUMMARY OF THE PWS

A1 – Overall Summary

A2 – Summary of Requirements by Task

APPENDIX B – GLOSSARY of KEY TERMS

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 GENERAL

The Department of Defense (DoD) Cyber Crime Center (DC3) Vulnerability Disclosure Program (VDP) Directorate is responsible for the authorization of private-sector Cybersecurity (CS) researchers called White-Hat Hackers to scan publicly accessible Department of War (DoW) information systems for vulnerabilities. The DC3 Defense Industrial Base Collaborative Information Sharing Environment (DCISE) Directorate is responsible for assisting Defense Industrial Base (DIB) companies to safeguard DoW content and intellectual property residing on or transiting their unclassified networks. This Performance Work Statement (PWS) establishes the requirements for Contractor services in support of the DC3 VDP and DCISE Directorates.

1.2 SCOPE

The Contractor shall furnish all personnel and services to perform the work to provide vulnerability disclosure services at the DC3 Buildings located at 911 Elkridge Landing Road, Linthicum Heights, MD 21090 and 1306 Concourse Drive, Linthicum Heights, MD 21090.

Contractor performance shall be in accordance with this PWS. The Contractor shall provide highly qualified personnel to support DC3 VDP Directorate operations. The Contractor shall provide support to the DC3 VDP Directorate by executing the following tasks in support of this contract.

The scope of this requirement includes execution of cyber intelligence and analytical production;

delivery of training and mentoring programs; and facilitation of mission partner engagement and interagency information sharing. The Contractor shall provide all personnel, management, supervision, tools, facilities, and expertise necessary to fulfill the tasks and subtasks defined herein, ensuring accuracy, timeliness, compliance, and seamless integration across DC3 directorates.

Performance under this contract requires a highly skilled, TS/SCI-eligible workforce capable of meeting strict deadlines, producing error-free deliverables, and maintaining compliance with DoW policies and intelligence community standards. The Contractor shall support dynamic operational environments and deliver continuous improvements that enhance DC3’s cyber and analytical mission effectiveness.

1.3 BACKGROUND

The DC3 VDP directorate supports DC3’s role as approved by the Secretary of War (SoW) to improve the defense of the DoD Information Network (DoDIN). The mission of the DC3 VDP Directorate is to ensure that identified vulnerability reports are delivered to the system owner and remediation personnel as quickly as possible.

The DC3 DCISE directorate serves as the focal point for all DIB cyber incident reporting affecting unclassified networks and providing awareness across the Government of cybersecurity threats and trends that impact the DIB. The mission of DCISE is to protect DoW information on DIB unclassified networks by fostering a collaborative information sharing environment and delivering DIB-focused cybersecurity services and resources.

SECTION II

2.0 TASKS

The following tasks are in support of this contract:

• Task 1 – Report Intake, Validation and Triage

• Task 2 – Identify and Engage System Owners

• Task 3 – Report Analysis

• Task 4 – Integration, Dissemination and Communication

• Task 5 – Mitigation, Reporting and Analysis

• Task 6 – Incident and Threat Analysis

• Task 7 – Report and Product Generation

• Task 8 – Data Management Requirements

• Task 9 – Program Management and Process Improvement

• Task 10 – Outreach Engagement and Communication

• Task 11 – Technology and Services Management

• Task 12 – Program Management

Note 1: Tasks 1-5 are VDP specific. Tasks 6-11 are DCISE specific. Task 12 pertains to both VDP and DCISE.

2.1 TASK 1 – REPORT INTAKE, VALIDATION and TRIAGE

This task covers the complete lifecycle of vulnerability reports received through the DoW and Defense Industrial Base (DIB) Vulnerability Disclosure Programs (VDP), from initial intake to final disposition and closure. The Contractor shall triage, assess, validate, and synchronize reports across different networks, ensuring vulnerabilities are properly addressed and tracked.

2.1.1 SUBTASK 1 – INTAKE and TRIAGE

2.1.1.1 The Contractor shall establish and maintain designated channels for receiving vulnerability reports from researchers for both DoW VDP and Defense Industrial Base (DIB)

VDP.

2.1.1.2 The Contractor shall log each incoming report into a central tracking system within twenty-four (24) hours of receipt (Section 4, Deliverable 1).

2.1.2 SUBTASK 2 – ASSESSMENT and VALIDATION

2.1.2.1 The Contractor shall verify the scope, impact, and exploitability of each reported vulnerability.

2.1.2.2 The Contractor shall assign a priority level (e.g., Critical, High, Medium, Low) to each report based on its combined impact and exploitability, according to a documented prioritization matrix as provided by the Government.

2.1.2.3 The Contractor shall conduct technical analysis to verify the existence and exploitability of each reported vulnerability, using appropriate tools and techniques (e.g., vulnerability scanners, manual testing).

2.1.2.4 The Contractor shall develop, maintain and execute a rotating list of DoW assets for vulnerability testing.

2.1.2.5 The Contractor shall conduct vulnerability assessments based on target lists and record outputs from assessments in standardized VDP assessment templates.

2.1.3 SUBTASK 3 – DISPOSITION and RECOMMENDATION

2.1.3.1 The Contractor shall identify reports that lack sufficient information for validation or require clarification.

2.1.3.2 The Contractor shall draft and submit a clear and concise communication to the researcher detailing the specific deficiencies and required information within one (1) business day of identification.

2.1.3.3 The Contractor shall, within one (1) business day of completion of the initial assessment, recommend a disposition (e.g., closure, further investigation) and document the rationale in the VDP report (Section 4, Deliverable 2).

2.1.4 SUBTASK 4 – REMEDIATION and CLOSURE

2.1.4.1 The Contractor shall obtain an approved Plan of Action & Milestones (POA&M) from the system owner that outlines the planned remediation activities and timelines.

2.1.4.2 The Contractor shall document the system owner's acceptance of risk or approval of the POA&M in the VDP report.

2.1.4.3 The Contractor shall close the VDP report in the tracking system with the appropriate disposition code (e.g., Accepted Risk, Approved POA&M, Informative, Referred, Unvalidated).

2.1.5 SUBTASK 5 - NIPRNET and SIPRNET SYNCHRONIZATION

2.1.5.1 The Contractor shall establish and maintain a secure and automated process for synchronizing vulnerability reports between NIPRNET, SIPRNET, and DIB Vulnerability Report Management Network (VRMN) instances.

2.1.5.2 The Contractor shall synchronize reports between NIPRNET and SIPRNET instances twice daily at specified intervals (e.g., 0800 and 1600 ET).

2.1.5.3 The Contractor shall verify synchronization completion, resolve issues, and document the process and any encountered issues.

2.1.5.4 The Contractor shall maintain the VDP VRMN System to include VRMN NIPR, SIPR and DIB VRMN.

2.1.5.5 The Contractor shall provide continuous development of VRMN to include VRMN NIPR, SIPR and DIB VRMN.

2.2 TASK 2 – IDENTIFY and ENGAGE SYSTEM OWNERS

This task focuses on identifying and engaging system owners responsible for systems and applications with vulnerabilities reported through the VDP. The Contractor shall utilize various methods, including reviewing the Demilitarized Zone (DMZ) Whitelist, leveraging Open-Source Intelligence (OSINT), and contacting system owners directly to ensure they are aware of reported vulnerabilities.

2.2.1 SUBTASK 1 – VULNERABILITY-DRIVEN WHITELIST OWNER IDENTIFICATION

2.2.1.1 The Contractor shall review the current DoW Demilitarized Zone (DMZ) Whitelist to determine owners of systems with vulnerabilities identified by VDP reporting for both DoW VDP and DIB VDP.

2.2.1.2 The Contractor shall identify systems and applications accessible through the DMZ Whitelist and provide this information to the DoD Cyber Defense Command (DCDC) and the Defense Information Systems Agency (DISA).

2.2.2 SUBTASK 2 – NON-DMZ SYSTEM DISCOVERY and OWNER OUTREACH

2.2.2.1 The Contractor shall use available information to identify systems and applications not accessible through the DMZ and contact their system owners.

2.2.2.2 The Contractor shall utilize Open-Source Intelligence (OSINT) techniques to discover potential system owners and contact information.

2.2.3 SUBTASK 3 – SYSTEM OWNER IDENTIFICATION VIA OPEN-SOURCE

INTELLIGENCE

2.2.3.1 The Contractor shall maintain a list of DoW-managed websites and web applications not registered on the DoD Information Network (DoDIN), including the website/application name, uniform resource locator (URL), purpose, and system owner contact information.

2.2.3.2 The Contractor shall validate the system owner information for a sample of systems already listed on the DMZ Whitelist to ensure accuracy and completeness. The sample size will be mutually agreed upon between the Contractor and the government.

2.3 TASK 3 – REPORT ANALYSIS

This task involves the detailed analysis of validated vulnerability reports to classify vulnerabilities impacting DoW systems and applications and map them to relevant governance frameworks. The Contractor shall identify applicable Security Technical Implementation Guides (STIGs), Risk Management Framework (RMF) controls, and industry/vendor best practices to guide remediation efforts.

2.3.1 SUBTASK 1 – TRIAGE and CLASSIFY VULNERABILITIES

2.3.1.1 The Contractor shall review validated VDP reports to identify and categorize reported vulnerabilities impacting DoW systems and applications for both DoW VDP and DIB VDP.

2.3.1.2 The Contractor shall map identified vulnerabilities to DoW CS governance frameworks, policies, and procedures.

2.3.2 SUBTASK 2 – DETERMINE RELEVANT GUIDES and CONTROLS

2.3.2.1 The Contractor shall identify the specific Security Technical Implementation Guides (STIGs) and/or Risk Management Framework (RMF) security controls that are relevant to the reported vulnerability. The Contractor shall document the rationale for the identified STIGs and RMF controls.

2.3.2.2 The Contractor shall identify industry best practices for mitigating the reported vulnerability. This includes researching and documenting widely accepted security practices and recommendations for addressing the specific type of vulnerability.

2.3.2.3 The Contractor shall identify vendor-specific best practices for mitigating the reported vulnerability. This includes consulting vendor documentation, security advisories, and support resources to determine recommended mitigation steps.

2.4 TASK 4 – INTEGRATION, DISSEMINATION and COMMUNICATION

This task focuses on the timely integration and dissemination of vulnerability reports to relevant stakeholders. The Contractor shall transmit complete VDP report packages and facilitate effective communication between vulnerability researchers and other DoW components to support efficient vulnerability resolution.

2.4.1 SUBTASK 1 – TRANSMIT VULERNABILITY REPORTS

2.4.1.1 The Contractor shall assign all VDP reports containing validated vulnerabilities to the DCDC for both DoW VDP and DIB VDP.

2.4.1.2 The Contractor shall transmit a complete VDP Report Package to DCDC via the VRMN on a monthly reporting schedule, ensuring delivery to all Defense Industrial Base Cybersecurity Organization (DIBCO) Participants.

2.4.2 SUBTASK 2 – FACILITATE COMMUNICATION and RESOLUTION

2.4.2.1 The Contractor shall maintain appropriate and timely communication with Vulnerability Researchers, DCDC, and relevant DoW components, as needed for the overall VDP process.

2.4.2.2 The Contractor shall ensure all inquiries, updates, and communications related to VDP reports and vulnerability remediation are promptly and properly coordinated and addressed according to established protocols.

2.5 TASK 5 – MITIGATION, REPORTING and ANALYSIS

This task centers on validating vulnerability mitigation efforts, managing the status of VDP reports, and generating comprehensive reports on assessment results. The Contractor shall assess system owner actions, close resolved reports, return unmitigated reports, and produce recurring reports and documentation to share lessons learned and recommendations.

2.5.1 SUBTASK 1 – MANAGE REPORT STATUS and CLOSURE

2.5.1.1 The Contractor shall assess system owner actions to validate vulnerability mitigation efforts.

2.5.1.2 For vulnerabilities successfully mitigated, the Contractor shall mark VDP reports as "Resolved," recommend closure, and close the reports notifying the Vulnerability Researcher.

2.5.1.3 For unmitigated vulnerabilities, the Contractor shall recommend and return reports to DCDC via VRMN, confirming receipt.

2.5.1.4 The Contractor shall close VDP Reports with accepted risk/POA&M and notify the Vulnerability Researcher.

2.5.2 SUBTASK 2 – PRODUCE RECURRING REPORTS and ASSESSMENT RESULTS

2.5.2.1 The Contractor shall develop, collect, aggregate, and analyze information from After- Action Assessments.

2.5.2.2 The Contractor shall follow up on missing/incomplete After-Action Assessments through DCDC via VRMN and confirm receipt of completed assessments from DCDC.

2.5.2.3 The Contractor shall publish monthly and annual reports, lessons learned documentation, case studies, and whitepapers (as appropriate) documenting assessment results and recommendations.

2.6 TASK 6 – INCIDENT and THREAT RESPONSE

This task involves analyzing cyber threats and vulnerabilities, developing tailored mitigation strategies for the DIB, and responding to security incidents. The Contractor shall collect and analyze threat intelligence, facilitate analyst exchanges, and perform malware analysis to document lessons learned and enhance incident response capabilities.

2.6.1 SUBTASK 1 – ANALYZE and TRIAGE CYBER REPORTING

2.6.1.1 The Contractor shall collect and analyze cyber threat intelligence from various sources;

identify and document Indicators of Compromise (IOCs); assess network vulnerabilities and exploits, and provide documented threat intelligence collection, prioritization criteria, and vulnerability assessment reports.

2.6.2 SUBTASK 2 – PROVIDE CYBER THREAT ANALYSIS in SUPPORT of the DEFENSE

INDUSTRIAL BASE (DIB)

2.6.2.1 The Contractor shall develop and provide tailored mitigation and remediation strategies for identified cyber threats to DIB participants; facilitate regular analyst-to-analyst exchanges with DIB participants and produce meeting minutes, shared threat intelligence reports, and actionable mitigation plans.

2.6.3 SUBTASK 3 – CONDUCT COMPREHENSIVE THREAT ANALYSIS and INCIDENT

RESPONSE

2.6.3.1 The Contractor shall perform malware analysis, data fusion, and continuous network monitoring; execute incident response procedures and document lessons learned and produce malware analysis reports, data fusion reports, incident response reports, and documented lessons learned from incidents.

2.7 TASK 7 – REPORT and PRODUCT GENERATION

This task involves the creation and dissemination of detailed reports and cyber products to inform the Government and DIB community about threats, vulnerabilities, and intrusion trends.

The Contractor shall also process mandatory reports to ensure continuous compliance with regulations and provide timely information to stakeholders.

2.7.1 SUBTASK 1 – DEVELOP DETAILED REPORTS on CYBER THREATS

2.7.1.1 The Contractor shall continuously research and analyze cyber threats, vulnerabilities, and intrusion trends, delivering quarterly reports no later than 10 business days after quarter end detailing findings, mitigation strategies, and recommendations to ensure a proactive cybersecurity posture (Section 4, Deliverable 3).

2.7.2 SUBTASK 2 – PRODUCE CYBER PRODUCTS for GOVERNMENT and DIB

COMMUNITY

2.7.2.1 The Contractor shall create and disseminate time-sensitive security information to the Government and DIB community, including alerts and advisories; disseminate products providing overviews of significant vulnerabilities and malware intrusion trends and provide security alerts, advisories, vulnerability reports, and malware reports.

2.7.3 SUBTASK 3 – PROCESS MANDATORY REPORTS

2.7.3.1 The Contractor shall maintain continuous DFARS compliance by identifying reporting requirements, establishing data collection processes, and generating and submitting accurate, compliant reports as required by all applicable DFARS clauses, with documented requirements and reports available for government review on a quarterly basis, and submitted no later than 10 business days after quarter end (Section 4, Deliverable 4).

2.8 TASK 8 – DATA MANAGEMENT REQUIREMENTS

This task focuses on maintaining the DCISE operational environment, enabling data-driven decision-making, and proactively securing the DCISE IT environment at DoW Impact Level 4.

The Contractor shall manage the DCISE suite of tools, deliver interactive dashboards, and implement a comprehensive knowledge management strategy to support secure operations.

2.8.1 SUBTASK 1 – MAINTAIN DCISE OPERATIONAL ENVIRONMENT

2.8.1.1 The Contractor shall maintain the DCISE operational environment, including managing the DCISE Suite of tools, optimizing directorate communications, and integrating new technologies.

2.8.2 SUBTASK 2 – ENABLE DATA-DRIVEN DECISION MAKING and SECURE

OPERATIONS

2.8.2.1 The Contractor shall enable data-driven decision-making and secure operations by delivering interactive DCISE dashboards, managing DIB partner data, streamlining the Request for Information (RFI) process, and implementing a comprehensive knowledge management strategy.

2.8.3 SUBTASK 3 – SECURE DCISE IT ENVIRONMENT at DoW

2.8.3.1 The Contractor shall proactively secure DCISE's IT environment at DoW Impact Level 4, ensuring diligent records management and system optimization.

2.9 TASK 9 – PROGRAM MANAGEMENT and PROCESS IMPROVEMENT

This task involves managing DCISE's programs to optimize performance and meet regulations, assisting with Capability Maturity Model Integration (CMMI) compliance, and providing integrated strategic support and program management services. The Contractor shall drive special projects, develop metrics, and optimize records management to enhance DCISE's overall effectiveness.

2.9.1 SUBTASK 1 – MANAGE DCISE PROGRAMS for OPTIMIZATION and

COMPLIANCE

2.9.1.1 The Contractor shall manage DCISE’s programs through strategic alignment and pilot programs to optimize performance and meet regulations, including analysis of cybersecurity processes for DIB Partners.

2.9.2 SUBTASK 2 – CAPABILITY MATURITY MODEL INTEGRATION COMPLIANCE

ASSISTANCE

2.9.2.1 The Contractor shall assist with Capability Maturity Model Integration for Services Level (CMMI-SVC) 3 compliance, including driving special projects, developing metrics, presenting findings, and offering recommendations.

2.9.3 SUBTASK 3 – INTEGRATED STRATEGIC SUPPORT and PROGRAM

MANAGEMENT

2.9.3.1 The Contractor shall provide integrated strategic support and program management services to DCISE, encompassing strategic plan updates, pilot program execution, and records management optimization.

2.10 TASK 10 – OUTREACH ENGAGEMENT and COMMUNICATION

This task focuses on cultivating strong relationships with DIB partners and DC3 mission partners, facilitating clear and consistent communication across all channels, and managing stakeholder engagement. The Contractor shall organize events, provide briefings, support working groups, and develop engaging content to enhance collaboration and threat mitigation awareness.

2.10.1 SUBTASK 1 – DIB PARTNER COLLABORATION and DC3 MISSION PARTNER

COORDINATION

2.10.1.1 The Contractor shall collaborate with DIB Partners on provisioning services and capabilities and coordinate threat analysis and support to planning with DC3 mission partners and produce documentation of collaborative efforts, coordination plans, and agreed-upon processes.

2.10.2 SUBTASK 2 – ANALYTICAL ASSESSMENT BRIEFINGS

2.10.2.1 The Contractor shall brief DC3 leadership and mission partners on analytical assessments and provide presentation materials, briefing schedules, and follow-up documentation.

2.10.3 SUBTASK 3 – WORKING GROUP SUPPORT

2.10.3.1 The Contractor shall assist in the organization and hosting of working groups with Subject Matter Experts to develop Alerts, Warnings, Advisories, TIPPERs, and other threat-based analyses and provide working group agendas, meeting minutes, and threat analysis products.

2.10.4 SUBTASK 4 – THREAT MIGITATION AWARENESS

2.10.4.1 The Contractor shall attend workshops and symposiums, at the request of the Government, to stay abreast of threat mitigation resources and provide trip reports, summaries of key takeaways, and relevant information on new threat mitigation resources.

2.10.5 SUBTASK 5 – DIB PARTNER and STAKEHOLDER ENGAGEMENT

MANAGEMENT

2.10.5.1 The Contractor shall lead and manage DIB partner and key stakeholder engagement, serving as the primary point of contact, organizing and executing events, and developing and disseminating engaging content across multiple channels and provide contact lists, event plans, marketing and engagement content, and reports on partner engagement metrics.

2.11 TASK 11 – TECHNOLOGY and SERVICES MANAGEMENT

This task focuses on ensuring the reliable operation and maintenance of DCISE's technology infrastructure and services, providing cyber threat expertise, and implementing cybersecurity partner pilot programs. The Contractor shall assist in developing communication strategies, identifying technology recommendations, and providing evolving solutions to enhance information sharing within the DIB Partnership.

2.11.1 SUBTASK 1 – CYBER THREAT EXPERTISE for TECHNICAL ANALYSIS

2.11.1.1 The Contractor shall provide cyber threat expertise and knowledge to assist in the development of aggregate data from DIB Partner incident reports to produce technical analysis products and presentations and provide analysis of DIB partner information and provide threat analysis products and presentations, and summaries of available mitigation strategies.

2.11.2 SUBTASK 2 – COMMUNICATION STRATEGY and TECHNOLOGY

RECOMMENDATIONS

2.11.2.1 The Contractor shall assist with research and identify the most effective ways to communicate with the DIB Partnership, allowing for informed recommendations for technologies that can best support rapid cyber threat information sharing between DoW and the DIB Partnership and provide documented communication strategies and justified technology recommendations for enhanced information sharing.

2.11.3 SUBTASK 3 – CYBERSECURITY PARTNER PILOT PROGRAM

IMPLEMENTATION

2.11.3.1 The Contractor shall develop and implement pilots to DIB Cybersecurity Partners and encompass a wide range of cybersecurity concepts, technologies, and processes and provide evolving solutions based on the ever-changing cybersecurity environment and the diverse composition of the DIB Partnership and provide pilot program plans, reports on pilot program outcomes, and evolving solutions for the DIB community.

2.12 TASK 12 – PROGRAM MANAGEMENT

2.12.1 SUBTASK 1 – PROGRAM OVERSIGHT

2.12.1.1 The Contractor shall provide program management support. This includes the management and oversight of all activities performed by Contractor personnel, including any subcontractors.

2.12.1.2 The Contractor shall identify a PM by name who shall provide management, direction, administration, quality control, and leadership to all Contractor personnel and sub-Contractor personnel.

2.12.2 SUBTASK 2 – PROGRAM MANAGEMENT PLAN (PMP)

2.12.2.1 The Contractor shall provide a PMP that documents all task/subtask requirements performed to satisfy the requirements of this PWS (Section 4, Deliverable 5).

2.12.2.2 The Contractor shall provide the Government with a draft PMP for review, modification, and approval. The final PMP shall incorporate the Government’s changes.

2.12.2.3 The PMP is an evolutionary document that shall be updated as needed to reflect changes and evolving training requirements (Section 4, Deliverable 6).

2.12.2.4 The Contractor shall work from the most current Government approved iteration of the

PMP.

2.12.2.5 The Contractor’s PMP shall, minimally:

• Describe the proposed management approach.

• Describe the Contractor’s SOPs for all tasks.

• Include milestones, tasks, and subtasks required in this contract.

• Describe in detail the Contractor’s approach to risk management under this contract.

• Describe in detail the Contractor’s approach to communications, including processes, procedures, communication approach, and other rules of engagement between the Contractor and the Government.

• Include the current Organizational Chart and the approach to ensuring the Government is in receipt of the most current version of the Organizational Chart.

Describe in detail the Contractor’s approach to obtaining short-term specialized expertise, when required for surge support.

2.12.3 SUBTASK 3 – RISK MANAGEMENT

2.12.3.1 The Contractor shall develop, implement, and maintain a comprehensive Risk Management Plan (Section 4, Deliverable 7), as part of the overall PMP, for all tasks executed under this PWS.

2.12.3.2 The Contractor’s Risk Management Plan shall include, (minimally):

• Identification of risks, and the assessment of risks and their impacts, prioritization, mitigation, and control plans.

• Risk tracking, monitoring, and reporting process.

• Risk processes including the development of recovery plans in the event risks are realized.

• Escalation timelines and procedures for notifying the Government.

2.12.4 SUBTASK 4 – COMMUNICATION and MEETINGS

2.12.4.1 The Contractor shall facilitate Government and Contractor communications; use industry best practices / standards and proven methodologies to track and document requirements and activities to allow for continuous monitoring and evaluation by the Government; and ensure all support and requirements performed are accomplished IAW the contract.

2.12.4.2 The Contractor shall notify the VDP and DCISE Directors, Deputy Directors or Contracting Officer’s Representative (COR) via a Problem Notification Report (PNR) of any technical, personnel, or general managerial problems encountered throughout the period of performance (POP) (Section 4, Deliverable 8).

2.12.5 SUBTASK 5 – CONDUCT KICKOFF MEETING

2.12.5.1 The Contractor shall schedule, coordinate, and host a Kick-Off Meeting at the location approved by the Government (Section 4, Deliverable 9) within ten (10) business days of award.

The meeting shall provide an introduction between the Contractor personnel and Government personnel who will be involved with the PWS. The meeting shall provide the opportunity to discuss technical, management, and security issues, and travel authorization and reporting procedures. At a minimum, the attendees shall include Key Contractor Personnel, representatives from the directorates, COR, relevant Government personnel, and the AFDW/PKA Contracting Officer (CO).

2.12.5.2 The Contractor shall, at least three-business days prior to the Kick-Off Meeting, provide a Kick-Off Meeting Agenda (Section 4, Deliverable 10) for review and approval by the VDP and DCISE Directors and COR prior to finalizing. The agenda shall include, at a minimum, the following topics/deliverables:

• Points of Contact (POCs) for all parties.

• Personnel discussion (i.e., roles and responsibilities and lines of communication between Contractor and Government).

• Staffing Plan and status.

• Transition-In Plan and discussion. This must include an update on the plan to relocate to the Contractor facility and classrooms.

• Security discussion and requirements (i.e., building access, badges, Common

Access Cards (CACs), Personal Identity Verification (PIV).

• The Contractor shall provide a Kick-Off Meeting Minutes Report (Section 4, Deliverable 11) documenting the Kick-Off Meeting discussion and capturing any action items.

2.12.6 SUBTASK 6 – MONTHLY STATUS REPORT (MSR)

2.12.6.1 The Contractor shall develop and provide an MSR (Section 4, Deliverable 12). The MSR shall be presented at the Monthly Technical Status Meeting (Section 4, Deliverable 13).

The MSR shall include, minimally, the following:

2.12.6.2 Activities during reporting period, by task (include ongoing activities, new activities, and activities completed, and progress to date on all above-mentioned activities). Each section shall start with a brief description of the task.

2.12.6.3 Problems and corrective actions taken as well as issues or concerns and proposed resolutions.

2.12.6.4 Personnel gains, losses, and status (e.g., out-processing, in-processing, security clearances, etc.). This shall include a copy of the latest Organizational Chart.

2.12.6.5 Government actions required.

2.12.6.6 Schedule execution and forecast reports defined during the Program Baseline Review (show major tasks, milestones, and deliverables; planned and actual start and completion dates for each).

2.12.6.7 Summary of trips taken, conferences attended, etc. (attach Trip Reports to the MSR for reporting period).

2.12.7 SUBTASK 7 – ASSET MANAGEMENT SERVICES

2.12.7.1 The Contractor shall provide shall provide asset management on all GFE provided as a part of the PWS in accordance with DC3 policies and procedures.

2.12.8 SUBTASK 8 – GOVERNMENT REQUIRED TRAINING

The Government will provide the Contractor a list of all required training, with completion dates.

2.12.8.2 The Contractor shall successfully complete and/or attend all training identified by the Government and use the Government’s approved system to take and record this training, primarily on Joint Knowledge Online (JKO).

2.12.8.3 The Contractor shall not directly bill the Government for any Government-required training. The type of training contemplated by this section is joint compliance training typically found in JKO or similar online DoW system.

2.12.9 SUBTASK 9 – KEY PERSONNEL

The following are the minimum personnel who shall be designated as “Key.” The Government does not intend to dictate the composition of the ideal team to perform this contract.

• Program Manager (PM)

• DCISE Technical Lead

2.12.9.1 Program Manager: The Contractor shall identify a PM by name to serve as the Government’s primary POC. The PM shall provide overall management and oversight of all activities performed by Contractor personnel, including subcontractors, to satisfy the requirements identified in this PWS. The PM shall facilitate Government and Contractor communications, use industry-best standards and proven methodologies to track and document requirements and activities to allow for continuous monitoring and evaluation by the Government, and ensure all tasks are accomplished IAW this PWS. The PM shall be responsible for the quality and efficiency of the Contractor’s performance and shall assist the Government with all financial and business processes of this PWS, excluding inherently Governmental functions. It is required that the PM has the authority to make decisions for the Contractor’s organization in response to Government issues, concerns, and comments; the authority to commit the prime Contractor’s organization; and to be proactive in alerting the Government to potential contractual or programmatic and resource limitations issues.

2.12.9.1.1 The PM is required to have the following qualifications:

• Top Secret Sensitive Compartmented Information (TS/SCI) clearance eligible.

• Project Management Professional® (PMP) certification.

• Experience within the last ten years managing a project, or program of similar size and complexity to this PWS.

• Experience within the last five years overseeing and determining manpower requirements for projects similar in size and complexity to this PWS, consisting of a diversity of technical skill sets and labor categories.

• Experience within the last five years performing financial and performance monitoring of contracts (e.g., performance metrics).

2.12.9.2 DCISE Technical Lead: The Contractor shall identify a DC3/DCISE Technical Task Lead to serve as a project lead to provide technical oversight and guidance on the DCISE tasks IAW the PWS. The DC3/DCISE Technical Task Lead shall serve as a Contractor representative for the DCISE executive leadership. The DC3/DCISE Technical Task Lead shall be responsible for the quality and efficiency of the Contractor’s performance and shall assist the Government with all financial and business processes of the task, excluding inherently governmental functions.

2.17.9.2.1 It is required that the DCISE Technical Lead has the following qualifications:

• Top Secret Sensitive Compartmented Information (TS/SCI) clearance eligible.

• Experience in the last ten years leading technical efforts supporting intelligence analysis requirements in all-source cyber analysis and reporting.

• Experience in the last ten years supervising teams supporting intelligence analysis requirements in all-source cyber analysis and reporting.

• Experience in the last ten years with scanning tools (i.e., VirusTotal) to conduct suspicious file scanning, and performing queries, pivoting on indicators, and malware analysis on characteristics (Message-Digest Algorithm 5 (MD5), Secure Hash Algorithm 1 (SHA1), file size, file name, file paths, etc.).

Experience in the last ten years with intelligence analysis processes, including Open-Source Intelligence (OSINT) and closed-source intelligence gathering, source verification, data fusion, link analysis, and threat actor knowledge.

• Experience in the last ten years conducting malware and network analysis, identifying protocols, persistence mechanisms, encoding techniques, and encryption and how they are used by Advanced Persistent Threat (APT) threat actors.

2.12.9.3 A key personnel substitution occurs when there is any person who, in an acting capacity, performs the duties of any Key Personnel temporarily (more than 30 consecutive calendar days).

2.12.9.4 The Contractor shall not replace any personnel designated as Key Personnel without the written approval of the VDP and DCISE Director with concurrence of the CO. Prior to utilizing other than the Key Personnel specified in its proposal in response, the Contractor shall notify the VDP and DCISE Director, CO, and COR of the existing PWS. This notification shall be no later than ten (10) calendar days in advance of any proposed substitution and shall include justification and labor category of proposed substitution(s) in sufficient detail to permit evaluation of the impact on PWS performance. The Government shall not be billed for positions left vacant over 30 calendar days unless the vacancy is due to Government delay and otherwise approved by the CO.

2.12.9.5 Substitute Key Personnel qualifications shall be equal to, or greater than, those of the Key Personnel substituted. If the VDP and DCISE Director, CO, and the COR determine that a proposed substitute Key Personnel is unacceptable, or that the reduction of effort would be so substantial as to impair the successful performance of the work under the contract, the Contractor may be subject to default action as prescribed by FAR 52.249-6 Termination.

2.12.9.6 For the purposes of this contract, all persons supporting this contract shall be considered ‘non-Key Personnel’ unless they are assigned as, or are performing the duties of, a position identified as ‘key’ above.

2.12.10 SUBASK 10 – TRANSITION

2.12.10.1 TRANSITION-IN

This subtask addresses requirements for the entire transition period to include the initial, seamless transition from the incumbent operations to the Contractor’s proposed facility.

Transition-in shall be accomplished using a two-phased transition approach, the Initial Operational Capability (IOC) (Section 4, Deliverable 14) and the Full Operational Capability (FOC) (Section 4, Deliverable 15). Phase 1 of the transition, referred to as IOC at completion, shall be delivered NLT 45 calendar days following contract award and shall represent 50% of VDP and DCISE essential functions in operation. Phase 2 of the transition, referred to as FOC at completion, shall be delivered NLT 90 calendar days following contract award. This milestone marks Contractor performing 100% of VDP and DCISE Contractor functions.

Immediately following award, the Contractor shall begin implementing its phased Transition-In Plan (provided as a part of the proposal). The Contractor shall provide a status/progress update of its transition-in activities at the Kick-Off Meeting and weekly updates thereafter. The Contractor shall notify the Government immediately of risks impacting transition.

2.12.10.2 TRANSITION-OUT

The Contractor shall provide transition-out support when required by the Government. The Transition-Out Plan shall facilitate the accomplishment of a seamless transition from the incumbent to incoming Contractor at the expiration of the contract. The Contractor shall provide a Transition-Out Plan within three months of Project Start (PS) (Section 4, Deliverable 16). The Government will work with the Contractor to finalize the Transition-Out Plan. At a minimum, this Transition-Out Plan shall be reviewed monthly and updated as required (Section 4, Deliverable 17).

2.12.10.2.1 In the Transition-Out Plan, the Contractor shall identify how it will coordinate with the incoming Contractor and/or Government personnel to transfer knowledge regarding the following:

• Identify risks and impacts of moving from the current Contractor facility to a new facility and mitigations to prevent the loss of classroom training services.

• Classroom configuration specifications including equipment, tools, and materials used in support of courses.

• Point of Contacts (POCs) for licensing agreements etc.

• Actions required of the Government.

• The Contractor shall also establish and maintain effective communication with the incoming Contractor/Government personnel for the period of the transition via weekly status meetings or as often as necessary to ensure a seamless transition-out.

• The Contractor shall implement its Transition-Out Plan NLT one month prior to expiration of the current contract.

SECTION III

3.0 SERVICE SUMMARY

The Contractor service requirements are summarized into performance objectives that relate directly to mission essential items. The performance threshold briefly describes the minimum acceptable levels of service required for each requirement and will be assessed on an “Acceptable” or “Unacceptable” basis. These thresholds are critical to mission success.

Performance Objective PWS Paragraph Performance Threshold Method of

Surveillance

SS – 1

Establish and maintain effective channels for receiving and logging vulnerability reports, thoroughly assess and validate reported vulnerabilities, efficiently manage reports, and maintain a secure and automated process for synchronizing vulnerability reports.

2.1, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5

a) 99% uptime of reporting channels

b) 95% of reports acknowledged within two (2) hours

c) 100% of reports logged

d) 85% or more of reporting vulnerabilities validated

Customer Complaint

100% Surveillance

Audit

SS – 2

Accurately identify system owners of systems with vulnerabilities, effectively discover and contact system owners of systems and applications not accessible through the DMZ, and maintain a current list of unregistered DoW-managed websites/applications.

2.2, 2.2.1, 2.2.2, 2.2.3

a) 98% accuracy in identifying system owners

b) Twenty-four (24) hours or less to attempt initial contact of detected vulnerability

100% Surveillance

Audit

SS – 3

Accurately triage and classify reported vulnerabilities, identify and document specific STIGs, RMF controls, industry best practices, and vendor-specific recommendations for mitigating reported vulnerabilities.

2.3, 2.3.1, 2.3.2

a) 95% mitigation guidance provided

b) Eight (8) hours or less to document critical vulnerabilities

Periodic Surveillance

Peer Review

SS – 4 2.4, 2.4.1,

2.4.2

a) 99% transmission rate

Paragraph Performance Threshold Method of

Surveillance Accurately and reliably transmit all validated vulnerability reports to the DCDC and maintain timely and effective communication with Vulnerability Researchers to facilitate report resolution.

b) 100% receipt acknowledgement

Periodic Surveillance

Audit

SS – 5

Effectively manage the status and closure of vulnerability reports, publish comprehensive reports and documentation summarizing assessment results, lessons learned, and recommendations.

2.5, 2.5.1, 2.5.2

a) 100% scheduled reports submitted

b) 4.0 rating on stakeholder satisfaction

Customer Complaint

Periodic Surveillance

Audit

SS – 6

Analyze and respond to cyber incidents, minimizing the impact on critical systems and protecting sensitive data.

2.6, 2.6.1, 2.6.2, 2.6.3

a) 90% of reported cyber incidents are triaged and assigned to an analyst within 2 hours of initial notification

100%

Audit

SS – 7

Provide timely, accurate, and actionable intelligence on cyber threats to the government and DIB community, supporting informed decision-making and proactive security measures.

2.7, 2.7.1, 2.7.2, 2.7.3

a) 100% of mandatory DFARS reports are submitted within the required timeframe, with zero rejected reports due to errors or omissions

Customer Complaint

100%

SS – 8

Ensure the availability, integrity, and security of DCISE data, enabling data-driven decision-making and secure operations across the organization.

2.8, 2.8.1, 2.8.2, 2.8.3

a) 99.9% DCISE dashboards are available during normal business hours

100%

SS – 9

Effectively manage DCISE programs, optimize performance, and ensure compliance with relevant

2.9, 2.9.1, 2.9.2, 2.9.3

a) Two (2) pilot programs per year executed, with documented cost savings or efficiency improvements resulting from each pilot

Customer Complaint

100%

Paragraph Performance Threshold Method of

Surveillance regulations and standards, fostering a culture of continuous improvement.

SS – 10

Cultivate strong relationships with DIB partners and key stakeholders, facilitating clear and consistent communication to promote cybersecurity awareness and collaboration.

2.10, 2.10.1, 2.10.2, 2.10.3, 2.10.4, 2.10.5

a) 80% satisfaction rating from DIB partners and key stakeholders

Customer Complaint

100%

SS – 11

Ensure the reliable operation and maintenance of DCISE's technology infrastructure and services, providing a secure and efficient environment for mission execution.

2.11, 2.11.1, 2.11.2, 2.11.3

a) 95% of identified cybersecurity vulnerabilities are addressed within the timeframe

100%

SS-12

Provide comprehensive program management support, including reporting, risk management, and communication with government stakeholders.

2.12, 2.12.1, 2.12.2, 2.12.3, 2.12.4, 2.12.5, 2.12.6, 2.12.7, 2.12.8, 2.12.9, 2.12.10

a) 100% of oversight meetings conducted as scheduled.

b) 100% PMP updates delivered within 7 business days of changes.

c) 100% compliance with risk management strategies.

d) Conduct regular meetings with government personnel unless otherwise cancelled by the government.

e) 100% of MSRs submitted on time.

f) 100% compliance with Key Personnel qualifications.

100% Inspection

SECTION IV

4.0 DELIVERABLES

The Contractor shall provide deliverable(s) in a format mutually agreed upon by the Government and the Contractor.

The following enumerated deliverables are not expected to change. Due Date intervals are not expected to change but actual dates may need to be revised depending on actual contract start date.

DEL.

MILESTONE/DELIVERABLE PWS

REF

DATE OF COMPLETION

DELIVERY

1 Intake Report 2.1.1.2 Within twenty-four (24) hours of receipt

2 Vulnerability Report 2.1.3.3 Within one (1) business day of completion of the initial assessment 3 Quarterly Cyber Activity Report 2.7.1.1 No later than 10 business day after quarter end 4 Quarterly DFARS Report 2.7.3.1 No later than 10 business day after quarter end 5 Program Management Plan (PMP) 2.12.2.1 Draft Due NLT 30 business days following contract award/Final Due 10 business days after receipt of Government comments

6 Program Management Plan Updates 2.12.2.3 Annually minimum or as project changes occur

7 Risk Management Plan (RMP) 2.12.3.1 Delivered IAW PMP 8 Problem Notification Report 2.12.4.2 As required 9 Kick-Off Meeting 2.12.5.1 Within 10 business days of contract award 10 Kick-Off Meeting Agenda 2.12.5.2 NLT 3 business days prior to

Kick-Off Meeting 11 Kick-Off Meeting Minutes Report 2.12.5.2 NLT 3 business days following Kick-Off Meeting 12 Monthly Status Report 2.12.6.1 Monthly, 30 calendar days after contract award 13 Monthly Technical Status Meetings 2.12.6.1 Monthly, at minimum 14 Transition IOC 2.12.10.1 NLT 45 calendar days after contract award 15 Transition FOC 2.12.10.1 NLT 90 calendar days after contract award 16 Transition-Out Plan 2.12.10.2 Draft within three months of

PS/Final due 10 calendar

DEL.

MILESTONE/DELIVERABLE PWS

REF

DATE OF COMPLETION

DELIVERY

days after receipt of Government comments

17 Transition-Out Plan Updates 2.12.10.2 As required 18 Trip Reports 6.4.1.3 When request for travel is submitted

4.1 DELIVERABLES MEDIA

The Contractor shall deliver all electronic versions by electronic mail (email) and removable electronic media, as well as placing in the DCISE/VDP-designated repository. The following are the required electronic formats, whose versions must be compatible with the latest, commonly available version on the market.

Text MS Word Spreadsheets MS Excel Briefings MS PowerPoint Drawings MS Visio Schedules MS Excel (Preferred); MS Project Brochures and Reports Adobe Creative Cloud and Adobe PDF

4.2 PLACE(S) OF DELIVERY

Unclassified copies of all deliverables shall be delivered to the CO, COR, and DCISE.VDP Director. The name, address, and contact information of these individuals will be provided at award.

4.3 BASIS OF ACCEPTANCE

The basis for acceptance shall be compliance with the requirements set forth in the contract and relevant terms and conditions of the contract. Deliverable items rejected shall be corrected in accordance with the applicable clauses.

The Government requires a period NTE 15 business days after receipt of final deliverable items for inspection and acceptance or rejection. Final acceptance will occur when all discrepancies, errors, or other deficiencies identified in writing by the Government have been resolved, through documentation updates, program correction, or other mutually agreeable methods.

Reports, documents, and narrative-type deliverables will be accepted when all discrepancies, errors, or other deficiencies identified in writing by the Government have been corrected.

If the draft deliverable is adequate, the Government may accept the draft and provide comments for incorporation into the final version.

All of the Government’s comments on deliverables shall either be incorporated in the succeeding version of the deliverable, or the Contractor shall explain to the Government’s satisfaction why such comments should not be incorporated.

If the Government finds that a draft or final deliverable contains spelling errors, grammatical errors, or improper format, or otherwise does not conform to the quality assurance requirements stated within this contract, the document may be rejected without further review and returned to the Contractor for correction and resubmission. If the Contractor requires additional Government guidance to produce an acceptable draft, the Contractor shall arrange a meeting with the COR.

Additional acceptance criteria:

4.4 DRAFT DELIVERABLES

The Government will provide written acceptance, comments, and/or change requests, if any, within 15 business days from Government receipt of the draft deliverable. Upon receipt of the Government comments, the Contractor shall have ten business days to incorporate the Government’s comments and/or change requests and to resubmit the deliverable in its final form.

4.5 WRITTEN ACCEPTANCE/REJECTION BY THE GOVERNMENT

The CO or COR will provide written notification of acceptance or rejection (Section 4) of all final deliverables within 15 business days. All notifications of rejection will be accompanied with an explanation of the specific deficiencies causing the rejection.

4.6 MARKINGS

The Contractor shall mark all deliverables listed in the above table to…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .