About this file

This is a Statement of Work (Amendment 01) for Systems Engineering and Technical Assistance (SETA) professional support services at the Department of Defense Cyber Crime Center, effective March 31, 2026.

The contract requires the contractor to provide qualified personnel for systems engineering, technical analysis, and program management tasks supporting DC3's cyber investigative, forensic, and training mission. The contractor must staff eight (8) full-time equivalents (FTEs) in the base year, consisting of a minimum of one (1) Senior Cybersecurity Engineer and additional mid-level cybersecurity engineers, plus one (1) Senior Portfolio Manager. Option years OY1, OY2, and RFO 52.217-8 each require five (5) FTEs with at least one (1) Senior Cybersecurity Engineer. All personnel must hold fully adjudicated Top-Secret clearances with SCI eligibility and pass law enforcement records checks. Key Personnel (team lead) must hold a TS/SCI clearance, current CISSP or equivalent certification, a Master's degree in Computer Science/Cybersecurity or Bachelor's degree plus 10+ years of cybersecurity operations experience, 5+ years leading cybersecurity teams in a DoD environment, and experience managing teams of 10+ people and contracts of $10M or more.

Work scope encompasses engineering and technical analysis support, integration and sustainment environment engineering, change and release management, architecture recommendations, studies and assessments, test engineering, process improvement, cyber operations analysis, developmental technical project support (R&D), and technical and enterprise project management. Contractor personnel must work Monday through Friday, 40 hours per week with core duty hours 0800-1600, and may be required to work outside standard hours based on customer needs. Deliverables include weekly activity reports, monthly status reports with financial snapshots, incident reports, meeting minutes, trip reports, a final report due 30 days before contract expiration, specialized technical reports as requested (due within 15 business days), and a quality control plan. The contractor must maintain a stable workforce with no more than 10% employee turnover and no position vacancies exceeding 15 business days. All contractor personnel must comply with security requirements including CMMC Level 2 certification, physical security protocols, access control procedures, identification requirements, and restrictions on weapons and controlled substances. The contractor must report all labor hours to the System for Award Management (SAM) if the contract exceeds $3 million.

View the file

Other files for this federal contract opportunity

Other files attached to DC3 SETA Follow on Systems Engineering and Technical Assistance (SETA) Professional Support Services, newest first.
File Type Posted
Attachment 3 Section L Amendment 03 5-20-2026.pdf PDF
Solicitation FA701426R00010001 Amendment 01.pdf PDF
Attachment 5. Past Performance Amendment 01.pdf PDF
Attachment 8. Questions and Answer Final 01.pdf PDF
Attachment 3. Section L Amendment 01.pdf PDF
Attachment 4. Section M -Amendment 01.pdf PDF
Attachment 7. Responses to Offeror Questions.pdf PDF
Solicitation - FA701426R0001.pdf PDF
Attachment 2. DD254.pdf PDF
Attachment 6. Price Proposal Form.xlsx XLSX spreadsheet
Attachment 1. SOW.pdf PDF
Attachment 3. Section L.pdf PDF
Attachment 4. Section M.pdf PDF
Attachment 5. Past Performance.pdf PDF
Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA7014-26-C-XXXX

STATEMENT OF WORK (Amendment 01)

FOR

SYSTEMS ENGINEERING AND TECHNICAL ASSISTANCE (SETA)

PROFESSIONAL SUPPORT SERVICES

AT

Department of Defense Cyber Crime Center

31 March 2026

Table of Contents

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 General

1.2 Objective

1.3 Non-Personal Services ……..…………………………………………………………….4

1.4 Background ……………..………………………………………………………………..4

1.5 Scope of Work

SECTION II

2.0 LABOR CATEGORY DUTIES

2.1 General Requirements ……………………………………………………………………5

2.2 Knowledge & Experience

2.3 Program Management

2.4 Access and Protect Sensitive and Classified Information

2.5 Labor Category: Senior & Mid-level Cyber Security Engineer

2.6 Labor Category: Senior Portfolio Manager

SECTION III

3.0 DELIVERABLES

SECTION IV

4.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,

INFORMATION, OR SERVICES

SECTION V

5.0 GENERAL INFORMATION

Appendix A: Key Personnel Qualifications Roster

LEFT INTENTIONALLY BLANK

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 General. This Statement of Work (SOW) outlines the requirements for non-personal professional support services to augment the staff of the Department of Defense (DoD) Cyber Crime Center (DC3). The objective is to provide qualified personnel to supplement the government workforce and complete specific, ongoing support tasks.

1.2 Objective: The objective of this contract is to provide qualified specialized technical support to enhance its ability to investigate and prevent criminal and foreign malicious activity, as well as protect Department of the Air Force resources and personnel.

1.3 Non-Personal Services: This is a non-personal services contract the Contractor shall be responsible for all aspects of managing, supervising, and directing its employees. The Government's role is limited to providing technical direction regarding the tasks completed and shall not exercise supervision or control over the contractor's employees.

1.4 Background: The Department of Defense (DoD) Cyber Crime Center (DC3) was unofficially formed in 1998 as an entity under the Department of the Air Force (AF). The initial operational capability brought together the Defense Computer Forensics Laboratory (DCFL) and the Defense Computer Investigations Training Program (DCITP). DC3 is now designated as one of seven Federal Cybersecurity Centers by the National Security Presidential Directive 54/Homeland Security Presidential Directive 23 and a DoD Center of Excellence by DoD Directive (DoDD) 5505.13E. Designated in 2021 as a Field Operating Agency, DC3 is aligned under the Inspector General, Office of the Secretary of the AF.

DC3’s mission is to set the standards in D/MM forensics, develop and deliver specialized cyber investigative training, and serve as a focal point for information sharing on CS matters across the DoD. Also, DC3’s mission is to deliver superior D/MM lab services, cyber technical training, technical solutions development, and cyber analytics for the following DoD mission areas: CS and CIP, LE/CI, document and media exploitation (DOMEX), CT, and safety inquiries.

1.5 Scope of Work: The Contractor shall provide qualified personnel to complete systems engineering, technical analysis, and program management tasks. This includes providing research, development, test & evaluation; program integration; and compliance support, along with technical and programmatic liaison support across DC3 and its partner agencies. The contractor shall provide the required expertise and analysis to produce the deliverables outlined in section 3.0.

SECTION II

2.0 LABOR CATEGORY DUTIES

2.1 General Requirements. The Contractor shall provide qualified personnel to complete the duties outlined in the Labor Categories below. All personnel assigned to this SOW must possess a fully adjudicated Top-Secret clearance, as required for their billet, and pass a law enforcement records check. For TS billets, personnel must be able to obtain and maintain SCI eligibility.

Specific Directorates may levy additional, program-specific, requirements.

2.2 Knowledge & Experience. The Contractor personnel supporting Department of Defense cyber and law enforcement activities must possess sufficient knowledge and experience in the appropriate fields to ensure accurate interpretation of criteria and proper handling of information.

They must understand how to interface and perform technical and programmatic liaison support across DC3 and its partner agencies. The Contractor shall be proficient in conducting technical analyses for trade studies and capability assessments, as well as understanding evaluation tools and support to field demonstrations.

2.3 Program Management. The Contractor shall provide all management, direction, administration, quality control, and leadership for its employees, managed by a Key Personnel (team lead) identified by the Contractor serving as the primary point of contact on-site for the Contracting Officer's Representative (COR) & Government Program Manager. The Key Personnel (team lead) will be included in one of the Senior Cybersecurity Engineer roles included in the eight

(8) FTEs in the base period, and included in the five (5) FTEs in OY1, OY2, and RFO 52.217-8.

2.4 Access and Protect Sensitive and Classified Information. The Contractor shall handle Privacy Act Information (PAI), Controlled Unclassified Information (CUI), and Law Enforcement Sensitive (LES) information in accordance with all applicable laws and regulations. Contractor personnel shall not divulge or release data except to authorized Government personnel with a need-to-know or with written approval from the CO.

2.5 LABOR CATEGORIES:

Contract

Year

Annual

FTEs

Labor Category

Qualifications

Base 7

Senior Cybersecurity Engineer (s)

(one (1) - minimum)

Senior-Level Technical: Requires a Master's degree and ten (10) years of relevant technical experience, or twenty-two (22) years of relevant technical experience, or a Bachelor's degree and eighteen (18) years of relevant technical experience, See Appendix A: Key Personnel Qualification Roster.

Mid-level Cybersecurity

Engineer

Mid-Level Technical: Requires a Bachelor's degree and five (5) years of relevant technical experience, or an

Associate's degree and ten (10) years of relevant technical experience, or fifteen (15) years of relevant technical experience.

Base

Senior Portfolio Manager

Senior-Level Portfolio Manager: Requires a Master's degree and ten (10) years of relevant experience managing complex IT projects within the DoD environment, or twenty-two (22) years of relevant portfolio management experience, or a Bachelor's degree and eighteen (18) years of relevant experience, including at least five (5) years managing IT projects and budgets within the DoD

OY1

Engineer (s)

(one (1) - minimum)

Senior-Level Technical: Requires a Master's degree and ten (10) years of relevant technical experience, or twenty-two (22) years of relevant technical experience, or a Bachelor's degree and eighteen (18) years of relevant technical experience, See Appendix A: Key Personnel Qualification Roster.

Mid-level Cybersecurity

Engineer

Mid-Level Technical: Requires a Bachelor's degree and five (5) years of relevant technical experience, or an

Associate's degree and ten (10) years of relevant

OY2

Engineer (s)

(one (1) - minimum)

Senior-Level Technical: Requires a Master's degree and ten (10) years of relevant technical experience, or twenty-two (22) years of relevant technical experience, or a Bachelor's degree and eighteen (18) years of relevant technical experience, See Appendix A: Key Personnel Qualification Roster.

Mid-level Cybersecurity

Engineer

Mid-Level Technical: Requires a Bachelor's degree and five (5) years of relevant technical experience, or an

Associate's degree and ten (10) years of relevant

RFO

52.217-8

Engineer (s)

(one (1) - minimum)

Senior-Level Technical: Requires a Master's degree and ten (10) years of relevant technical experience, or twenty-two (22) years of relevant technical experience, or a Bachelor's degree and eighteen (18) years of relevant technical experience, See Appendix A: Key Personnel Qualification Roster.

Mid-level Cybersecurity

Engineer

Mid-Level Technical: Requires a Bachelor's degree and five (5) years of relevant technical experience, or an

Associate's degree and ten (10) years of relevant

2.5.1 The Contractor shall complete the following tasks:

2.5.1.1 Engineering and Technical Analysis Support: Contractor shall provide engineering and technical enterprise service support, including, but not limited to, the preparation of feasibility studies, analysis of alternatives, provision of technical services during the construction or installation phase, inspection and evaluation of engineering projects, and related services supporting technology, tools, or capability instantiation. The Contractor shall make use of relevant DoD and AF guidance and Instructions during the execution of these tasks.

2.5.1.2 Integration & Sustainment Environment Engineering: The Contractor shall provide engineering services that include but are not limited to system and technical in-service design, infrastructure (lifecycle refresh, addition, modification and retirement), communications, physical and logical components of services, and supporting software to improve reliability, maintainability, and affordability. Integration & sustainment support includes day-to-day process and system infrastructure operations, Root Cause Analysis (RCA) to eliminate recurring incidents and to minimize the impact of incidents that cannot be prevented, and Problem Management, including the activities required to diagnose the root cause of incidents, determining the resolution to those problems and providing workarounds. Additional tasks include, but are not limited to, production and implementation of technical service management models and appropriate AF documentation, support to technical review process standards and adaptation (e.g. AF Form 1067), and the implementation of prototype agile delivery models to rapidly modernize or update DC3 systems. Contractor efforts will promote collaborative interaction between the DC3 Program Offices, operational sites, other contractors, service providers and Mission Partners. In doing so, the Contractor shall utilize a consistent and time-sensitive approach to the supportability design of mission essential services that are effective and efficient, adhere to DoD and AF requirements, and consider industry best practices.

2.5.1.3 Change Management and Release Management: The Contractor shall provide engineering services that involve but are not limited to the necessary planning and coordination to take a new or changed service, or a service to be decommissioned, through Change Management and Release Management and into the production. Contractors should apply best practices, including applicable DoD system engineering guides, Project Management Professional Book of Knowledge (PMBOK) processes, and SAFE Agile principles for change management, integration, configuration control, and implementation of the Risk Management Framework. Certifications related to the SAFE Agile process, while relevant to this scope of work, are not strictly required of prospective offerors. The ultimate goal is to provide mission-effective engineering and technical support within a continuous integration environment and meeting established process quality performance measures.

2.5.1.4 Architecture: The Contractor shall support and provide recommendations for future architecture modifications including coordinated modernization and execution of AF Cyber Operations and Cyber LE/CI and integration tasks in close association with Mission Partners/Owners. The architecture recommendations should enable implementation of industry-standard and or best architecture practices, as directed by the Government. The contractor shall support update of operational and system views, maintain standards lists and facilitate integration of architecture initiatives across DoD and in close collaboration with other DoD/IC Mission Partners.

2.5.1.5 Studies, Analysis and Assessments: The Contractor shall provide engineering services to develop an efficient and effective methodology for assessing and evaluating solutions during the life cycle of DC3 technical programs. These services include, but are not limited to, assessments and evaluations in support of AF Cyber enterprise systems supporting multi stakeholder environments as well as Cyber-LE/CI specific tools and capabilities. The Contractor shall identify and evaluate current and emerging Government and commercial technologies and procedures that may offer improvements to capabilities and assist in the planning and implementation of technology insertions. Technology solutions and designs shall take into consideration the operational constraints and limitations of the receiving or requiring activity/customer. If applicable, design concepts shall include provisions for continuous technological or workflow improvement to maximize capability improvement available from emerging technological advances in the Government and commercial marketplace (Deliverable 3.7- Specialized Report).

2.5.1.6 Test Engineering: The Contractor shall provide full system life-cycle test engineering capability support for automated test integration, including:

2.5.1.6.1 The Contractor shall have relevant expertise in AF, traditional, Scrum and scaled agile software development techniques, automated test processes in transition to a continuous integration environment leading to DevOps environment.

2.5.1.6.2 The Contractor shall coordinate training in best practices, complete operational and developmental tests and evaluation, verification testing with new/modernized automated test software applications, support technical exchange meetings (TEMs) and participate in quick reaction teams for time critical failure analysis and mishap investigation activities; coordinate risk assessment activities, mitigation and corrective action plans. Contractors must be familiar with the following: [Applicable AF standards for development, test, integration and delivery (i.e. AFSPCI 10-170 RTO&I, eMASS and XACTA docs, etc.)]

2.5.1.7 Process Improvement and Transition Planning: The Contractor shall provide quality assurance for technical services as follows:

2.5.1.7.1 Innovative processes and procedures to ensure operations are optimally effective, efficient and affordable supportable operational capability. Plans shall fully evaluate areas such as, technical resource allocation, enterprise asset management and licensing considerations, how and when various levels of validated Government requirements would be met (Deliverable 3.7- Specialized Report).

2.5.1.7.2 SETA personnel assess and evaluate prototypes and pilots within DC3 assisting to develop transition plans that identify and lead to an initial prototype or pilot demonstrations that rapidly evolve to full system functionality and a supportable operational capability. Plans shall fully evaluate areas such as enterprise technical resource management, asset management and licensing considerations and how and when various levels of validated Government requirements would be met (Deliverable 3.7- Specialized Report).

2.5.1.7.3 Engineering or technical services to correct or improve issues with the goal of maintaining the required effective operations and maintenance performance of the programs, or to provide direct support to the system that is essential to production, sustainment, integration, interoperability, and configuration management.

2.5.1.8 Cyber Operations Analysis: The Contractor shall provide full spectrum intelligence analysis, collections, production support to DC3. This includes but is not limited to the following: The Contractor shall perform intelligence analysis utilizing all-source intelligence data and employing a variety of techniques as can be found in, “Structured Analytic

Techniques for Intelligence Analysis” (Heuer, McPherson), Intelligence Analysis: How to Think in Complex Environments” (Hall), “Intelligence Analysis: A Target-Centric Approach” (Clark), “Analyzing Intelligence: A National Security Practitioners’ Perspectives” (George, Bruce) among others. The Contractor shall identify and document gaps in intelligence data from all source reporting.

2.5.1.8.1 Contractor shall generate, staff and monitor the results of intelligence collection requirements as they are communicated across the intelligence community. The Contractor shall generate on an as needed or more frequent basis a variety of internal intelligence products. These may include “quick looks”, designed to answer relatively superficial or introductory level consumer requirements as well as “deep dives’, involving significantly more involved explanations of highly complex and detailed subject matter.

Periodic updates as they may pertain to specific technologies, project or threats may be also required, depending on the needs of the customer. The Contractor shall provide intelligence analysis that will be used to identify the potential outcomes of tools under development. This will include defining what observable effects may collected by the intelligence community – based on the various technical capabilities and limitations, locations and times those systems may be employed. The Contractor will also provide the customer with identifying additional opportunities for development of tools, in terms of 'branches and sequels' of related vulnerable systems, adversary capabilities and weapons that the original cyber capability could be modified to affect (Deliverable 3.7- Specialized Report).

2.5.1.9 Developmental Technical Project Support (R&D): Contractor shall provide engineering and technical enterprise project development support, including, but not limited to, the development of a holistic approach of multi-domain effects environments in the conduct of R&D activities, Development Test and Evaluation (DT&E) and Operational Test and Evaluations (OT&E), preparation of feasibility COA analysis for tradeoff and risk drivers in development of installation and activities in the conduct of R&D projects, analysis of alternatives, formation and integration of technical requirements for proof of concept demonstrations during development of constructs supporting multi-domain effects. The contractor shall inspect and evaluate engineering projects to meet industry best practices and AF requirements. cyber/radio frequency spectrum effects requirements, and related integration of supporting platform, tools, or capability instantiation to create new capabilities.

The Contractor shall make use of relevant DoD and AF guidance and Instructions during the execution of these tasks.

2.5.1.10 Technical & Enterprise Project Management: The Contractor shall provide program and project management support to ensure the successful planning, execution, and delivery of DC3 technical programs. This support includes a range of tasks, such as schedule development and management, resource assessments, and risk assessments, to ensure that projects are completed on time, within budget, and to the required specifications. The Contractor will develop and maintain project schedules, including milestones, deadlines, and dependencies, and conduct resource assessments to identify and recommend necessary resources, including personnel, materials, and equipment, to support project requirements.

Additionally, the Contractor will identify, assess, and report on risks that could impact project timelines, budgets, or quality, and develop strategies to minimize their impact.

2.6 LABOR CATEGORY: Senior Portfolio Manager

Contract Year

Annual FTE’s

Labor Category

Qualifications

Base 1

Senior

Portfolio Manager

Senior-Level Technical: Requires a Master's degree and ten

(10) years of relevant technical experience, or twenty-two

(22) years of relevant technical experience, or a Bachelor's degree and eighteen (18) years of relevant technical experience

OY1 0

OY2 0

RFO

52.217-8 0

2.6.1 The Contractor shall provide program management services that include but are not limited to:

2.6.1.1 Integrated acquisition/procurement processes, covering all phases of program management – to include the Joint Capabilities Integration and Development Systems (JCIDS); the Planning, Programming, Budgeting, and Execution (PPBE) process; the DoD 5000 series policies and procedures documents; and adherence to Customer policy.

2.6.1.2 The Contractor shall consistently and ethically execute consistent to established DoD policy, while emphasizing sustained effort to identify and report efficiencies to accelerate the delivery of mission-specific capabilities to Sponsor represented end users.

Such efficiencies may be gained through evaluating and recommending new or evolved partnerships; modifying existing processes and/or shaping policy to advance Sponsor objectives. Consistent with Sponsor processes, the Contract shall execute lifecycle program management services spanning all aspects of the assigned program(s) to include but not limited to produce policy traceability analysis; nominate key dependencies; establish and sustain purpose-built cross-functional teams; produce, sustain and resolve plans of action and milestones; characterize, coordinate & report on necessary investments, policy solutions, and integration needs; produce accurate resource, acquisition, procurement training and manpower analysis consistent with Sponsor requirements; participate and inform working groups, data calls and executive leadership decision briefs. Ensuring timely and accurate compliance reporting during all phases of assigned program lifecycle phases.

SECTION III

3.0 DELIVERABLES

3.1 The Contractor shall provide deliverable(s) in a format mutually agreed upon by the Government and the Contractor. The following enumerated deliverables are not expected to change. Due Date intervals are not expected to change but actual dates may need to be revised depending on actual contract start date.

Deliverable

ID# Title Frequency Description

3.1 Weekly

Activity Report

(WAR)

Weekly The WAR is a synopsis of individual activities and progress towards tasks during each week;

consolidated in a team submission. Issues and roadblocks are also identified to create a quicker feedback loop between government and contractor.

3.2 Status Report Monthly -

7th day of the month

The monthly activity report shall include progress toward major milestones, significant accomplishments, and convey areas of risk or concern and mitigating strategies. In addition, the contractor shall include other information as requested by the Government Technical Manager and information which has been directed and/or authorized by the Contracting Officer (CO). The report will include a financial snapshot showing labor and other tools or travel costs incurred for the current period, cumulative costs for the contract period, remaining funds available; include graphics (e.g., line charts) showing actual costs against planned costs and explain all variances exceeding 5%. The monthly status reports shall cover monthly project activities, development results for each task requirement when applicable. The report shall be delivered every 30 days following contract award, by the 7th calendar day of each month for work accomplished the previous month.

3.3 Incident

Reports

Immediately following the incident

Delivered no later than (NLT) 1 hour event:

The contractor shall report mishaps or incidents exceeding $1000 (material and labor) to USAF property entrusted by this contract within one hour during normal day shift hours. All other incidents will be reported as soon as possible, but NLT the next normal working day. Accidents/mishaps shall be reported to the DC3 Project Lead, through the COR.

3.4 Meeting

Minutes

As Required Delivered NLT one (1) day after meeting. The contractor shall provide, and upon USG approval, disseminate meeting minutes for key forums such as Technical Exchange Meeting, Monthly Meetings and In-Progress Reviews.

The meeting minute reports document will be in a format agreed to by the PM/COR.

3.5 Trip Reports NLT five

business days after completion of travel.

The contractor shall submit a brief written report of the visit. Each report shall include, at a minimum, the date and duration of visit; the purpose audience, location of the presentation, and a summary of activities, and any recommendations and/or observations.

3.6 Final Report 30 days

before end of PoP

Shall be delivered NLT one month prior to the end of the Period of Performance (PoP). The contractor shall deliver to the PM/COR a Final Summary report of all activities that captures findings, lessons learned, and best practices, recommendations for future courses of action and all requirements.

3.7 Specialized

Report

As Required Upon government request, the contractor shall produce technical analysis reports on specified topics. Unless otherwise specified, reports are due within 15 business days of the request and shall include an executive summary, methodology, findings, and actionable recommendations. Specialized documentation, data, and reports shall be delivered as specified with respect to project planning, technical diagrams, COA analysis, briefing slides, concepts of operation, or issue white paper.

3.8 Quality

Control Plan

Drafted for Kickoff

Drafted and provided to the Government personnel for project kickoff and refined 60 days after, based on government interaction during and immediately after kickoff.

SECTION IV

4.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,

INFORMATION, OR SERVICES

4.1 Statement of Intent:

While a definitive list of Government Furnished Equipment (GFE) and Government Furnished Information (GFI) has not been finalized at this stage of the proposal, the Government and Contractor acknowledge that specific mission-essential items may be required to fulfill the requirements of the Statement of Work (SOW). The specific GFE/GFI list will be mutually agreed upon and incorporated via a formal contract modification or documented through a Government-approved property management system as requirements mature.

DC3 will maintain accountability and tracking of all furnished materials in accordance with RFO 52.245-1 (Government Property).

SECTION V

5.0 GENERAL INFORMATION

5.1 Scheduling Concerns.

5.1.1 Duty Hours. The Contractor shall have access to Government facility five days per week, Monday through Friday, ten hours a day, except when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings, unless otherwise approved. Contractor personnel are expected to conform to customer agency normal operating hours; however, the Contractor may be required access to Government facility outside of duty hours based on the customer agency’s needs. As a baseline, Contractor personnel shall work 8 hours per day, 40 hours per week. Compensatory time arrangements are permissible for temporary spikes in worktime. Federal Holidays shall be observed in accordance with Office of Personnel Management policy.

• New Year’s Day, January 1st (or as observed)

• Martin Luther King’s Birthday, 3rd Monday in January

• President’s Day, 3rd Monday in February

• Memorial Day, Last Monday in May

• Juneteenth, June 19th (or as observed)

• Independence Day, July 4th (or as observed)

• Labor Day, 1st Monday in September

• Columbus Day, 2nd Monday in October

• Veteran’s Day, November 11th (or as observed)

• Thanksgiving Day, 4th Thursday in November

• Christmas Day, December 25th (or as observed)

5.1.2 Core Duty Hours and Base Shutdown/Inclement Weather. Core duty hours are 0800 - 1600, Monday through Friday (excluding federal holidays), and the DC3 office will be open from 0600

- 1800. The Contractor shall follow guidance of the installation containing their place of performance to determine reporting schedules whether due to a base closure or inclement weather.

5.2 Kickoff Meeting/Orientation Meeting

5.2.1 The Contractor shall schedule and coordinate a Project kick-off Meeting no later than (NLT) five (5) calendar days after contract award via in-person, Microsoft Teams, or Zoom. The meeting will provide an introduction between the Contractor personnel and Government personnel who will be involved with the contract. The meeting will provide the opportunity to discuss technical, management, and logistic issues; travel authorization; communication process between Government and Contractor; and reporting procedures. At a minimum, the attendees shall include key Contractor personnel, key Government representatives, and the COR. The Contractor shall provide a Kick-Off Meeting Agenda (Deliverable 3.7- Specialized Report) that will include, but not be limited to, the following.

• Introduction of personnel

• Overview of project tasks

• Review of organization (complexity)

• Communication Plan/lines of communication overview (between both Contractor and Government)

• Travel notification and processes

• Government-furnished information (GFI) including:

• Technical development data related to existing project activities

• On-going test and evaluation data

• Project performance information

• Additional organization documentation relevant to the execution of contractor activities

• Security requirements (Building access, badges, Common Access Cards (CAC) paperwork)

• Invoice procedures

• Monthly meeting dates

• Reporting Requirements, e.g. Monthly Status Report (MSR)

• POCs

• Roles and Responsibilities

• Prioritization of Contractor activities

• Any initial deliverables

• Quality Control Plan (QCP)

• Additional issues of concern (Leave/back-up support)

5.2.2 The Contractor shall provide a draft copy of the agenda (Deliverable 3.7- Specialized Report) NLT 3 days after contract award for review and approval by the COR prior to finalizing. The Government will provide the Contractor with the number of participants for the kick-off meeting and the Contractor shall provide sufficient copies of the presentation for all present. The Contractor will also provide a Quality Control Plan (Deliverable 3.8), considered a draft document, however the contractor will iterate on the document within 60 days of the Kickoff meeting.

5.2.3 The Kickoff Meeting location will be held onsite at the government facility or virtual and the date and time will be mutually agreed upon by both parties.

5.3 Transition-Out Plan

5.3.1 The Contractor shall provide a Transition-Out Plan (Deliverable 3.7- Specialized Report) NLT than sixty (60) calendar days prior to expiration of the contract. The plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming Contractor (if applicable). In addition, the Contractor will continue to accomplish all tasks as outlined in the contract during this period. The Contractor shall identify how it will coordinate with the incoming Contractor and Government personnel to transfer knowledge regarding the following:

• Project management processes

• Points of contact

• Location of technical and project management documentation

• Status of ongoing technical initiatives

• Transition of key personnel

• Schedules and milestones

• Actions required of the Government

• Coordination of IT related programs, issues

5.3.2 The Contractor shall also establish and maintain effective communication with the incoming Contractor and Government personnel for the period of the transition via weekly status meetings.

5.4 Quality Control.

5.4.1 Quality Assurance. The Government shall rely on the Contractors’ existing quality assurance system as the method to ensure that the requirements of the contract and task completion thresholds are met; however, the Government reserves the right to monitor and evaluate the quality of services provided and compliance with the contract terms and conditions at any time.

5.4.2 Quality Control Plan (QCP) (Deliverable 3.8). The Contractor shall develop and maintain an effective quality control program to ensure services are performed IAW this SOW, applicable laws and regulations, and best commercial practices. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services with special emphasis placed on those services listed in this SOW. The Contractor’s quality control program is the means by which it assures itself that the work complies with the requirement of the contract.

5.5 Emergency Operations/Mission Essential Personnel.

5.5.1. Continuation of Essential Contractor Services During Crisis. All services in this SOW HAVE NOT been defined or designated as essential services for performance during crisis IAW R-DFARS 252.237-7023, “Continuation of Essential Contractor Services.”

5.6 System for Award Management (formerly CMRA)

5.6.1 Service contractor reporting of information is required in the System for Award Management (SAM) when a contract or order – (i) Has a total estimated value, including options, that exceeds $3 million; and (ii) Is for services in the following acquisition portfolio groups;

Logistics management services, Equipment-related services, Knowledge-based services, or Electronic and communications services. Should R-DFARS 204.303-71 be inserted into this contract, the Contractor shall report ALL labor hours (including subcontractor labor hours) required for performance of services provided under this contract via the System for Award Management (SAM) data collection site. The Contractor is required to completely fill in all required data fields at http://www.SAM.gov. Reporting inputs shall be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September. While inputs may be reported anytime during the FY, all data shall be reported not later than 31 October of each calendar year. The Contractor may direct questions to the System for Award Management help desk.

5.6.2 Subcontractor Input in SAM. Prime Contractors are responsible to ensure all subcontractor data is reported. Subcontractors will not be able to enter any data into SAM but will enter their information into a Bulk Loader spreadsheet available from the SAM helpdesk. Subcontractor shall fill in columns A-C then return it to the SAM helpdesk after it's completed, and a technician team will enter the information into SAM.

5.7 Security Instructions

5.7.1 Cybersecurity Maturity Model Certification (CMMC): This contract requires the handling of Controlled Unclassified Information (CUI). The Offeror and all relevant subcontractors must be incompliant with R-DFARS 252.204-7025 and have a CMMC Level 2 (Self); or CMMC Level 2 (C3PAO) as verified by a C3PAO assessment.

5.7.2 Physical Security. The Contractor shall safeguard all Government property, documents and controlled forms provided for Contractor use and adhere to the Government property requirements contained in this contract. At the end of each workday, all Government facilities, equipment, and materials shall be secured by a Government POC. Contractors are not allowed to secure Government facilities, equipment, and materials.

5.7.3 Access Control. The Contractor shall establish and implement methods of ensuring that no building access instruments issued by the Government are lost, misplaced or used by unauthorized persons. Access codes shall not be shared with any person(s) outside the organization. The Contractor shall control access to all Government provided lock combinations to preclude unauthorized entry. The Contractor is not authorized to record lock combinations without written approval by the Government COR. Records with written combinations to authorized secure storage containers, secure storage rooms, or certified vaults, shall be marked and safeguarded at the highest classification level as the classified material maintained inside the approved containers.

Pass and Identification Items. The Contractor shall ensure the pass and identification items required for contract task completion and performance are obtained for employees and non-government owned vehicles.

5.7.4 Retrieving Identification Media. The Contractor shall retrieve all identification media, including vehicle passes, from employees who depart for any reason before the contract expires.

5.7.5 Traffic Laws. The Contractor and its employees shall comply with all base traffic regulations.

5.7.6 Weapons, Firearms, and Ammunition. Contractor employees are prohibited from possessing weapons, firearms, or ammunition, on themselves or within their Contractor-owned vehicle or privately-owned vehicle while on Quantico or any other military facility.

http://www.sam.gov/

5.7.7 Communications Security (COMSEC). Contractors may require access to COMSEC information on Air Force installations. The Contractor shall not require a COMSEC account.

Access shall be controlled by the sponsoring agency. Access to COMSEC material by personnel is restricted to US citizens holding final US Government clearances. Such information is not releasable to personnel holding only reciprocal clearances. If it is determined the Contractor is required to access COMSEC information, the necessary training information and courses shall be provided by the COR. The DD Form 254 shall give further instructions on safeguarding and managing COMSEC material.

5.7.8 Contractor Identification. All Contractor personnel shall wear the Air Force issued Common Access Card and DC3 issued badge at all times when away from their immediate work area to distinguish themselves from Government employees. When conversing with Government personnel during business meetings, over the telephone or via electronic mail, Contractor personnel shall identify themselves as a contractor to avoid situations arising where sensitive topics might be better discussed solely between Government employees. Contractors shall identify themselves on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify their company affiliation. Where practicable, contractors occupying collocated space with their government program customer should identify their workspace area with their name and company affiliation or as a minimum “Contractor” after name.

5.7.9 Drug, Tobacco, and Alcohol Use Policy. The consumption of alcoholic beverages or illegal drugs by contractor personnel, while on duty, is strictly forbidden. Contractor shall immediately remove any employee who is under the influence of alcohol or drugs.

5.8 Travel

5.8.1 Local Travel. Local travel to attend meetings or events may be required at no cost to the Government. Travel within the National Capital Region commuting vicinity is considered a cost of doing business and shall not be separately reimbursed.

5.8.2 CONUS Travel: Prior to travel, the Contractor shall coordinate with, and receive approval from, the COR at least ten (10) business days prior to trip, or as soon as possible based on mission requirements dictate.

5.8.2.1 Contractor shall adhere to policy conditions consistent with the Joint Travel Regulation to encourage team integrity.

5.8.2.2 Contractor may operate GSA-leased vehicles when approved by the US Government Customer.

5.8.3 OCONUS Travel: (e.g., to EUCOM and/or PACOM Area of Responsibility) Prior to travel, the Contractor shall coordinate with, and receive approval from, the COR at least twenty (20) business days prior to trip or as soon as practical. Theater Business Clearances shall be obtained, as necessary, prior to travel.

5.8.3.1 Contractor may operate GSA-leased, or Customer procured vehicles when approved by the US Government Customer.

5.8.3.1.2 Further guidance for Contractor travel can be found at https://www.defensetravel.dod.mil/site/faqctr.cfm.

5.8.4 Trip Reports: Following each trip, the Contractor shall prepare and deliver Trip/After Action Reports to the PM and COR.

5.9 Employee Accountability & Turnover

5.9.1 Staffing of Contractor Personnel. Contractor shall provide a stable workforce, throughout the duration of the contract, by maintaining a 10% or less employee turnover rate. No positions shall remain vacant for more than fifteen (15) business days. The government shall not be billed for positions left vacant over fifteen (15) business days unless the vacancy is due to government delay or otherwise approved by the CO.

5.9.2 List of Employees. The Contractor shall maintain a current listing of employees assigned under this contract. The list shall be password protected and shall include the Employee's Name (Last Name, First Name, Middle Name), DOB, Social Security Number, Email, Phone Number, and level of Security Clearance. The list shall be validated by the company Facility Security Officer (FSO) and provided to the COR and Program Manager. An updated listing shall be provided upon request.

5.9.3 Contractor professionalism. The contractor shall:

• Present a professional appearance and always maintain professional demeanor.

• Conduct their work assignments IAW project schedules.

• Function effectively and efficiently during extended periods of high pressure and stress.

• Function as an integral member of a team of highly trained professionals responsible for the safety and security of USAF personnel and resources.

5.10 Miscellaneous Paragraphs.

5.10.1 Freedom of Information Act (FOIA). All official Government records affected by this contract are subject to the provisions of the FOIA (5 U.S.C. 552/DoD 5400.7-R/AF Supplement).

Any request received by the Contractor for access/release of information from these records to the public (including Government/Contractor employees acting as private citizens), whether oral or in writing, shall be immediately brought to the attention of the CO for forwarding to the OSI FOIA Manager to ensure proper processing and compliance with the Act.

5.10.2 Controlled Unclassified Information (CUI). All DoD CUI must be controlled until authorized for public release in accordance with DoD Instructions (DoDIs) 5230.09, 5230.29, and 5400.04, or DoD Manual (DoDM) 5400.07. These regulations set policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding of CUI material.

5.10.3 Privacy Act. Work on this contract may require that personnel have access to information protected by the Privacy Act. Contractor personnel shall adhere to the Privacy Act, Title 5 of the https://www.defensetravel.dod.mil/site/faqctr.cfm.

U.S. Code, Section 552a and applicable agency rules and regulations when handling such information.

5.10.4 Records. All records created and received by the Contractor in the completion of this contract shall be maintained and readily accessible. Records shall remain the property of the Government.

5.10.5 Safety Concerns. The Contractor is solely responsible for compliance with OSHA standards for the protection of their employees. The Government is not responsible for ensuring that Contractors comply with “personal” safety requirements that do not present the potential to damage Government resources.

5.10.6 Project Policy. The Contractor shall comply with all industry standards. All work shall be done in accordance with all federal, local, and state laws and regulations.

5.10.7 Inherently Governmental Functions. The Contractor shall not perform inherently Governmental functions as defined in the Revolutionary Far Overhaul (RFO) 7.5 in relation to this

SOW.

5.10.8 Ethics. The Contractor shall not employ any person who is an employee of the US Government if employing that person would create a conflict of interest. Additionally, the Contractor shall not employ any person who is an employee of the Department of the Air Force, either military or civilian, unless such person seeks and receives approval according to DoDD 5500-7, Joint Ethics Regulation.

5.10.9 Professional Appearance of Workspace. The Contractor shall keep workspace areas neat and orderly and avoid conditions leading to safety violations.

5.10.10 Non-Personal Services. The Government shall not supervise or task Contractor employees in any manner that generates actions of the nature of personal services, or that creates the perception of personal services. It is the responsibility of the Contractor to manage its employees directly and to guard against any actions that are of the nature of personal services or give the perception of personal services to the Government or to Government personnel. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it is the Contractor’s responsibility to notify the CO immediately. Non-personal Contractor services shall not be used to perform work of a policy/decision making or management nature.

APPENDIX A: KEY PERSONNEL QUALIFICATIONS ROSTER

Key Personnel: For the purposes of this contract, One (1) Key Personnel (Senior Cyber Security Engineer) is required for the base year and for each of the Option Years (OY1 OY2, and RFO 52.217- 8). One (1) Key Personnel is defined as the individual whose specialized expertise and responsibilities are critical to advising stakeholders and the oversight of the successful task completion and performance of work by all other contractor team members. One Key Personnel is required from the team composition, NOT in addition to. The Contractor shall not reassign or replace one (1) Key Personnel without the prior written consent of the Contracting Officer or COR. Any proposed replacement must possess equivalent or superior qualifications and experience. The site lead and one

(1) Key Personnel will be one in the same.

The designated Key Personnel must hold the minimum requirements from below Technical Experience.

Minimum Requirements

Security Clearance Level

Technical Experience

Must possess a Top Secret/SCI clearance.

Must hold a current CISSP or equivalent cybersecurity certification.

Must have a Master's degree in Computer Science, Cybersecurity, or a related field or a Bachelor's degree and 10+ years of experience in cybersecurity operations.

Must have 5+ years of experience leading cybersecurity teams in a DoD environment.

Must have demonstrated experience with incident response, vulnerability management, and threat analysis.

Must have experience managing teams of 10 or more people.

Must have experience managing contracts of $10M or more

TS/SCI

File details come from the government source that posted it. Updated .