PWS 1 Tabo 2027 OED_CFL.DC3_1.7.26_REV1.pdf

PDF 432 KB Posted

Attached to
RFI Amendment 2: Request for Information DC3 Technical, Analytical, and Business Operations (TABO) Federal contract opportunity
Solicitation number
FA701427DXXXX
Issued by
Department of the Air Force Headquarters District Washington

About this file

This Performance Work Statement (PWS) outlines comprehensive contractor support for the Department of Defense Cyber Crime Center (DC3), specifically the Operations Enablement Directorate (OED) and Cyber Forensics Laboratory (CFL). The contract requires a contractor to provide cyber intelligence analysis, enterprise architecture management, digital forensic operations, evidence handling, media processing, personnel training, knowledge management, external engagement, and full-spectrum program management. The requirements are divided into 17 primary tasks: 10 OED operational tasks, 5 CFL forensic tasks, and a cross-organizational program management task.

Key performance objectives include establishing and maintaining the CADO-IS enterprise architecture, supporting Automated Data Obfuscation operations, managing the Enhanced Sensor System, conducting all-source cyber analysis, handling digital evidence, performing forensic examinations, and providing surge support. The contract requires a highly skilled, TS/SCI-eligible workforce capable of meeting strict deadlines and maintaining compliance with Department of War policies, U.S. Intelligence Community standards, and ISO 17025 accreditation requirements. The period of performance is anticipated to be a 12-month base period with four 12-month option periods, located at 911 Elkridge Landing Road, Linthicum Heights, MD, with performance primarily during normal business hours.

View the file

Other files for this federal contract opportunity

Other files attached to RFI Amendment 2: Request for Information DC3 Technical, Analytical, and Business Operations (TABO), newest first.
File Type Posted
DC3 TABO RFI QA.pdf PDF
PWS 2 Tabo 2027 DCISE_VDP.DC3_1.7.26_REV1.pdf PDF
PWS 5 Tabo 2027 Sec_HR_JA.DC3_1.7.26_REV1.pdf PDF
PWS 3 Tabo 2027 XT.CIO.CS_DC3_1.7.26_REV1.pdf PDF
PWS 4 Tabo 2027 ER_XE.DC3_1.7.26_REV1.pdf PDF
DRAFT PWS 1 Tabo 2027 OED_CFL.DC3.pdf PDF
DRAFT PWS 3 Tabo 2027 XT.CIO.CS_DC3.pdf PDF
DRAFT PWS 5 Tabo 2027 Sec_HR_JA.DC3.pdf PDF
DRAFT PWS 2 Tabo 2027 DCISE_VDP.DC3.pdf PDF
DRAFT PWS 4 Tabo 2027 ER_XE.DC3.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CUI FA7014‐XX-X-XXXX

CUI

PERFORMANCE WORK STATEMENT

FOR

Operations Enablement Directorate (OED) & Cyber Forensic Laboratory (CFL)

AT

Department of Defense Cyber Crime Center (DC3)

23 December 2025

DRAFT

Controlled by: AFDW/PK CUI Categories: PROCURE Distribution/Dissemination Controls:

FEDCON AFTER AWARD

POC: Ulrike U. Powell

Contents

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 GENERAL

1.2 SCOPE

1.3 BACKGROUND

SECTION II

2.0 TASKS

2.1 TASK 1 – COLLECT ANALYZE, DISSEMINATE, OPERATIONALIZE –

INTEGRATED SOLUTION (CADO-IS) OPERATIONS and SUPPORT

2.2 TASK 2 – AUTOMATED DATA OBFUSCATION OPERATIONS and SUPPORT 7

2.3 TASK 3 – ENHANCED SENSOR SYSTEM (ENSITE)

2.4 TASK 4 – OPTIONAL INNOVATION INTEGRATION SUPPORT CONTRACT

LINE-ITEM NUMBER (CLIN)

2.5 TASK 5 – MEDIA SUBMISSION and PRODUCTION SUPPORT

2.6 TASK 6 – ALL SOURCE CYBER ANALYSIS SUPPORT

2.7 TASK 7 – KNOWLEDGE MANAGEMENT SUPPORT

2.9 TASK 9 – REQUIREMENTS and CAPABILITIES ASSESSMENTS

2.10 TASK 10 – OED SURGE SUPPORT

2.12 TASK 12 – DATA IMAGING and EXTRACTION SUPPORT

2.13 TASK 13 – EXAMINATION SUPPORT

2.14 TASK 14 – EVIDENCE CUSTODIAL SUPPORT

2.15 TASK 15 – QUALITY ASSURANCE

2.16 TASK 16 – TRAINING DEVELOPMENT and MENTORING PROGRAM

2.17 TASK 17 – PROGRAM MANAGEMENT

SECTION III

3.0 SERVICE SUMMARY

SECTION IV

4.0 DELIVERABLES

4.1 DELIVERABLES MEDIA

4.2 PLACE(S) OF DELIVERY

4.3 BASIS OF ACCEPTANCE

4.4 DRAFT DELIVERABLES

4.5 WRITTEN ACCEPTANCE/REJECTION BY THE GOVERNMENT

4.6 MARKINGS

4.7 NON-CONFORMING PRODUCTS OR SERVICES

4.8 NOTICE REGARDING LATE DELIVERY/PROBLEM NOTIFICATION REPORT

(PNR) 33

SECTION V

5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,

INFORMATION, OR SERVICES

5.1 GOVERNMENT FURNISHED EQUIPMENT (GFE)

5.2 GOVERNMENT-FURNISHED INFORMATION (GFI)

5.3 FACILITIES ACCESS AND RESOURCE USAGE

5.4 CONTRACTOR FURNISHED ITEMS AND SERVICES

5.5 CONTRACTOR FURNISHED DATA

SECTION VI

6.0 GENERAL INFORMATION

6.1 PERIOD OF PERFORMANCE

6.2 PLACE OF PERFORMANCE

6.3 PERFORMANCE SCHEDULE

6.4 TRAVEL

6.5 QUALITY CONTROL

6.6 EMERGENCY OPERATIONS/MISSION ESSENTIAL PERSONNEL

6.7 SYSTEM FOR AWARD MANAGEMENT (FORMERLY CMRA)

6.8 SECURITY INSTRUCTIONS

6.9 MISCELLANEOUS PARAGRAPHS

SECTION VII

APPENDIX A – SUMMARY OF THE PWS

A1 – Overall Summary

A2 – Summary of Requirements by Task

APPENDIX B – GLOSSARY of KEY TERMS

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 GENERAL

The Department of Defense (DoD) Cyber Crime Center (DC3) Operations Enablement Directorate (OED) is responsible for conducting technical and cyber intelligence analysis leveraging multiple sources of data, unique analytic tools, applications, and capabilities to directly support stakeholder requirements and priorities. The DC3 Cyber Forensics Laboratory (CFL) is responsible performing digital and multimedia (D/MM) forensic examinations, device repair, data extraction, evidence management, and expert testimony in accordance with International Organization for Standardization (ISO) 17025.

This Performance Work Statement (PWS) establishes the requirements for Contractor services in support of the DC3 OED and CFL.

1.2 SCOPE

The purpose of this contract is to provide comprehensive operational, analytical, technical, forensic, and program management support to DC3, specifically OED and CFL. The Contractor shall deliver highly specialized cyber expertise, advanced digital forensic capabilities, innovative technology integration, robust enterprise architecture support, and full-lifecycle program management services to enable DC3’s mission in support of Department of War (DoW), Law Enforcement/Criminal Investigation (LE/CI), and Defense Industrial Base (DIB) cybersecurity, and national-level cyber operations.

The scope of this requirement includes the design, management, and sustainment of enterprise-level systems and architectures; execution of cyber intelligence and analytical production; digital evidence management and processing, imaging, extraction, and examination; rigorous quality assurance and accreditation sustainment; delivery of training and mentoring programs; and facilitation of mission partner engagement and interagency information sharing. The Contractor shall provide all personnel, management, supervision, and expertise necessary to fulfill the tasks and subtasks defined herein, ensuring accuracy, timeliness, compliance, and seamless integration across DC3 directorates.

Performance under this contract requires a highly skilled, TS/SCI-eligible workforce capable of meeting strict deadlines, producing error-free deliverables, and maintaining compliance with DoW policies, USIC standards, and ISO 17025 accreditation requirements. The Contractor shall support dynamic operational environments, respond to surge requirements, and deliver continuous improvements that enhance DC3’s cyber investigative, forensic, and analytical mission effectiveness.

1.3 BACKGROUND

The mission of OED is to amplify the effects of DoW-wide LE/CI investigations and operations, and by extension, the effects of the U.S. Intelligence Community (USIC) at large. To conduct sharply focused technical and cyber intelligence analysis leveraging multiple sources of data, unique analytic tools, applications, and capabilities to directly support stakeholder requirements and priorities.

Support joint operations by managing the development, sustainment, and enhancement of operational support systems. To support DC3’s role as a Federal Cyber Center of Excellence including collaborative analytical and technical exchanges with Subject Matter Experts (SMEs) from LE/CI, Computer Network Defense (CND), USIC, and other cybersecurity (CS) agencies.

The mission of CFL is to conduct a wide variety of examinations across various classification levels on D/MM items submitted to the lab for forensic analysis and to provide expert witness testimony in criminal judicial proceedings as to the relevance of analyzed digital artifacts to those proceedings. It provides malware and forensic analysis of digital data related to criminal, counterintelligence, counterterrorism, counterespionage, and cybersecurity investigations and operations across the DoW and DIB.

SECTION II

2.0 TASKS

The following tasks are in support of this contract:

• Task 1 – Collect, Analyze, Disseminate, Operationalize-Integrated Solution (CADO-IS) Operations and Support

• Task 2 – Automated Data Obfuscation Operations and Support

• Task 3 – Enhanced Sensor System (ENSITE)

• Task 4 – Optional Innovation Integration Support Contract Line-Item Numbers (CLINs)

• Task 5 – Media Submission and Production Support

• Task 6 – All Source Cyber Analysis Support

• Task 7 – Knowledge Management Support

• Task 8 – External Engagement Support

• Task 9 – Requirements and Capabilities Assessment

• Task 10 – OED Surge Support

• Task 11 – CFL Intake Support

• Task 12 – Data Imaging and Extraction Support

• Task 13 – Examination Support

• Task 14 – Evidence Custodial Support

• Task 15 – CFL Quality Assurance

• Task 16 – Training Development and Mentoring Program

• Task 17 – Program Management

Note 1: Tasks 1-10 are OED-specific. Tasks 11-16 are CFL-specific. Task 17 pertains to both OED and CFL.ca

2.1 TASK 1 – COLLECT ANALYZE, DISSEMINATE, OPERATIONALIZE –

INTEGRATED SOLUTION (CADO-IS) OPERATIONS and SUPPORT

2.1.1 SUBTASK 1 – CONFIRGURATION MANAGEMENT

2.1.1.1 The Contractor shall establish, maintain, and evolve the Collect, Analyze, Disseminate, Operationalize-Integrated Solution (CADO-IS) enterprise architecture (EA) to facilitate seamless collaboration among all CADO-IS stakeholders.

2.1.1.2 The Contractor shall develop and maintain comprehensive documentation of the CADO-IS enterprise architecture, adhering to the DoD Architecture Framework (DoDAF) or successor framework. This CADO-IS Enterprise Architecture Report shall be delivered within 30 calendar days of contract award and submitted annually thereafter (Section 4, Deliverable 1).

If CADO-IS Enterprise Architecture is changed within the annual report year, and updated CADO-IS Enterprise Architecture Report shall be submitted within five business days of completion of the change.

2.1.1.3 The Contractor shall implement and maintain comprehensive configuration management (CM) processes to ensure the integrity, traceability, and control of all CADO-IS components, systems, and capabilities. This includes managing configuration items (CIs) developed and managed by Defense Cyber Operations Panel (DCOP) member organizations, Defense Forensic and Cyber Activities (DFCA) subpanel members, and other identified stakeholders. The CM processes must align with industry best practices (e.g., ITIL, ISO 20000) and government regulations.

2.1.1.4 Within fifteen (15) business days of contract award, the Contractor shall develop and deliver a comprehensive CADO-IS Configuration Management Plan (CMP). This CMP shall detail the processes, procedures, and tools used to manage the configuration of all CADO-IS baseline configuration items (CIs) across all participating organizations (Section 4, Deliverable 2).

2.1.2 SUBTASK 2 – COMPREHENSIVE CONFIGURATION MANAGEMENT PLAN

2.1.2.1 The Contractor shall establish and implement a standardized evaluation process for assessing potential new CADO-IS partners and for developing and validating new capabilities from existing partners.

2.2 TASK 2 – AUTOMATED DATA OBFUSCATION OPERATIONS and SUPPORT

2.2.1 SUBTASK 1 – EXPANSION and APPLICATION

2.2.1.1 The Contractor shall actively engage with DC3 mission partners and proactively promote and support the adoption of Automated Data Obfuscation (ADO) capabilities for a wide range of missions, including intelligence, counterintelligence, cyberspace operations, and program protection.

2.2.1.2 The Contractor shall proactively engage with existing DC3 mission partners and actively recruit new partners to expand the ADO user base and maximize its reach and impact.

2.2.1.3 The Contractor shall facilitate the seamless onboarding and records management of new mission partners and provide comprehensive training on ADO capabilities, ensuring they are fully equipped to effectively utilize ADO for their missions.

2.2.2 SUBTASK 2 – OUTREACH and RECRUITMENT

2.2.2.1 The Contractor shall provide comprehensive support to mission partners throughout the ADO utilization lifecycle, from generating obfuscated files for deployment to resolving technical issues and gathering user feedback for continuous improvement. This support shall include Tier 1 and Tier 2 support.

2.2.2.2 The Contractor shall proactively monitor for potential security incidents involving obfuscated files, ensure proper data disposition, provide timely incident response support, and recommend measures to strengthen intelligence collection and network defense capabilities.

2.3 TASK 3 – ENHANCED SENSOR SYSTEM (ENSITE)

2.3.1 SUBTASK 1 – CENTRALIZED COMMUNICATION for SENSOR STAKEHOLDERS

2.3.1.1 The Contractor shall provide comprehensive program management support for the Sensor Program, focusing on customer engagement, architectural alignment, data transfer monitoring, and security oversight.

2.3.1.2 The Contractor shall serve as the primary liaison among Sensor Program stakeholders, OED, and the broader DC3 environment to ensure clear communication and awareness of customer engagement with the Sensor Program.

2.3.2 SUBTASK 2 – UNDERSTANDING SENSOR PROGRAM DATA FLOW

2.3.2.1 The Contractor shall develop and maintain a comprehensive understanding of the architecture pathways and data transfers associated with the Sensor Program to ensure appropriate data and intelligence allocation in accordance with the OED mission, CADO-IS program, and Analytical Group operations.

2.3.2.2 The Contractor shall ensure continuous monitoring and transparency of data and intelligence flow within the Sensor Program to ensure appropriate allocation within CADO-IS.

2.3.3 SUBTASK 3 – SECURE INTEGRATION within the SENSOR PROGRAM

2.3.3.1 The Contractor shall assist with the seamless and secure integration of DIB partners into the DC3 environment for the Sensor program.

2.3.3.2 The Contractor shall contribute to the successful integration of the Sensor Program into the broader enterprise architecture, including developing and implementing CM processes to ensure seamless system and capability integration.

2.4 TASK 4 – OPTIONAL INNOVATION INTEGRATION SUPPORT CONTRACT LINE-

ITEM NUMBER (CLIN)

2.4.1 SUBTASK 1 – INNOVATION ASSESSMENT and INTEGRATION PLANNING

2.4.1.1 The Contractor shall identify and assess scalable opportunities for integrating new technology innovations into DC3. This includes validating other system activities and system engineering requirements to determine potential benefits for DC3 and the broader LE/CI and cyber communities.

2.4.1.2 The Contractor shall conduct thorough evaluations of new technologies, provide detailed assessments of their potential benefits and risks, and develop recommendations for integration into the DC3 environment.

2.4.2 SUBTASK 2 – OPTIONAL SUPPORT for INTEGRATION TESTING

2.4.2.1 The Contractor shall provide operational support with an intelligence collection and reporting skillset to support testing and scaling integrations between active systems and new innovations.

2.5 TASK 5 – MEDIA SUBMISSION and PRODUCTION SUPPORT

2.5.1 SUBTASK 1 – INTAKE and INVESTIGATION

2.5.1.1 The Contractor shall provide comprehensive information management and reporting support, encompassing the coordinated processing of media and malware cases, technical editing and dissemination of published products, and the effective management of Requests for Information (RFIs).

2.5.1.2 The Contractor shall establish and maintain a centralized system for managing RFIs, including tracking requests, coordinating responses with DC3 Directorates, documenting progress, and ensuring timely communication, accountability, and quality control throughout the process.

2.5.1.3 The Contractor shall serve as the primary point of contact for media and malware cases submitted by OED/Analytics Group (AG) partner agencies, ensuring efficient intake, tracking, and communication throughout the investigation process and collaborating to deliver timely and accurate analytical findings Media/Malware Case report (Section 4, Deliverable 3). This report shall be submitted 1 business day after analysis is complete.

2.5.2 SUBTASK 2 – TECHNICAL EDITING and WEB DESIGN

2.5.2.1 The Contractor shall ensure that all published products (e.g., reports, white papers, technical documentation) meet established technical standards, regulatory requirements, and DC3 style guidelines by providing rigorous technical editing to guarantee clarity, accuracy, consistency, and compliance, and facilitating timely and efficient dissemination to relevant stakeholders.

2.5.2.2 The Contractor shall generate and distribute timely and informative Weekly Activity Reports (WARs) and production metrics, providing actionable insights on operational efficiency, resource allocation, performance trends, and areas for improvement to drive informed decision-making (Section 4, Deliverable 4).

2.5.2.3 The Contractor shall design and maintain high-performing OED/AG websites and product templates, leveraging data and user feedback to inform the creation of compelling graphics, interactive charts, and user-friendly interfaces that drive user engagement, improve key metrics, and enhance the overall user experience (Section 4, Deliverable 5). The website will be established 30 days after contract award and updated weekly thereafter.

2.6 TASK 6 – ALL SOURCE CYBER ANALYSIS SUPPORT

2.6.1 SUBTASK 1 – ANALYSIS and PRODUCTION

2.6.1.1 The Contractor shall provide technical and foreign language-enabled all-source analysis in support of law enforcement and counterintelligence investigations and operations.

2.6.1.2 The Contractor shall conduct all-source analytic production, creating intelligence products that describe and assess the activities and capabilities of a broad range of cyber actors, including, but not limited to: military organizations, law enforcement agencies, intelligence services, cybercriminal groups, and hacktivist organizations.

2.6.2 SUBTASK 2 – REPORTING

2.6.2.1 The Contractor shall produce actionable cyber intelligence products that characterize, assess, and document the strategies, techniques, procedures, and capabilities of cyber threat actors in support of OED operations. This analysis will enhance mission partner readiness and success by providing them with timely, relevant, and actionable intelligence on the evolving cyber threat landscape.

2.6.2.2 The Contractor shall produce high-quality intelligence products as required, including, but not limited to:

• Profile Reports (PRF) (Section 4, Deliverable 6)

• Operational Lead Reports (OLR) (Section 4, Deliverable 7)

• Persona Operational Lead Reports (POLR) (Section 4, Deliverable 8)

• All-Source Cyber Intelligence Reports (CIR) (Section 4, Deliverable 9)

• Intelligence Information Reports (IIRs) (Section 4, Deliverable 10)

• All-Source Cyber Intelligence Notes (CIN) (Section 4, Deliverable 11)

• Tailored operational products to meet specific customer needs

A strict quality assurance (QA) process will be implemented to ensure the accuracy, completeness, objectivity, and timeliness of all intelligence products.

2.7 TASK 7 – KNOWLEDGE MANAGEMENT SUPPORT

2.7.1 SUBTASK 1 – PROVIDING INTELLIGENCE EXPERTISE

2.7.1.1 The Contractor shall collaborate with military personnel, USIC analysts, and DC3 mission partners to coordinate intelligence analysis and support planning efforts.

2.7.1.2 The Contractor shall provide intelligence expertise and knowledge to assist in the seamless integration of defense and national intelligence support capabilities, including collection and analytic activities, into operational planning functions and efforts across the DoW.

2.7.2 SUBTASK 2 – MANAGING INFORMATION and ACCESS CONTROLS

2.7.2.1 The Contractor shall securely manage OED/AG-related information on all websites and internal knowledge management systems, enforcing strict access controls and ensuring accuracy, currency, and readily available access for authorized users, while adhering to all applicable security and compliance regulations.

2.7.2.2 The Contractor shall conduct semi-annual reviews and updates of all Standard Operating Procedures (SOPs) to ensure alignment with current policies and procedures, optimize operational efficiency, minimize risk, and reflect best practices.

2.8 TASK 8 – EXTERNAL ENGAGEMENT SUPPORT

2.8.1 SUBTASK 1 – ORGANIZING WORKING GROUPS and EXCHANGES

2.8.1.1 The Contractor shall lead collaborative analytical and technical exchanges and provide on-site liaison support within designated key partner agencies, as directed by the Government PM, to facilitate communication, collaboration, and information sharing.

2.8.1.2 The Contractor shall assist in the organization and hosting of working groups with SMEs to develop Analyst-to-Analyst (A2A) exchanges, facilitating enhanced analytic and operational information-sharing with DC3 mission partners across the Government.

2.8.1.3 The Contractor shall attend relevant workshops and symposiums to identify and develop innovative methodologies and capabilities to enhance DC3’s analytic tradecraft and insights into malicious cyber activity.

2.8.2 SUBTASK 2 – IDENTIFYING and TRACKING PARTICIPATION

2.8.2.1 The Contractor shall proactively identify, cultivate, and track analyst participation in external engagement opportunities, including training programs, conferences, and joint projects.

2.8.2.2 The Contractor shall develop and deliver concise and informative After-Action Reports (AARs) for all collaborative exchanges and major liaison activities, including key findings, lessons learned, and actionable recommendations for improving future engagements (Section 4, Deliverable 12).

2.8.2.3 The Contractor shall develop and maintain accurate, consistent, and up-to-date mission engagement materials (e.g., presentations, brochures, fact sheets) to effectively support outreach and communication efforts (Section 4, Deliverable 13).

2.9 TASK 9 – REQUIREMENTS and CAPABILITIES ASSESSMENTS

2.9.1 SUBTASK 1 – PREPARE and DELIVER ANALYTICAL ASSESSMENT

BRIEFINGS

2.9.1.1 The Contractor shall establish and maintain regular communications with DoW and interagency organizations to assess requirements and identify relevant cyber counterintelligence capabilities.

2.9.1.2 The Contractor shall prepare and deliver clear, concise, and informative briefings to DC3 executive leadership and mission partners on analytical assessments, ensuring that key findings, insights, and recommendations are effectively communicated.

2.9.2 SUBTASK 2 – DEVELOP PRODUCTION METRICS and RECOMMENDATIONS

2.9.2.1 The Contractor shall develop relevant and measurable production metrics, analyze findings, and offer actionable recommendations to the Government for improving compliance with applicable policies, procedures, and regulations.

2.9.2.2 The Contractor shall establish and maintain regular communication channels with key DoW and interagency organizations to solicit feedback, share relevant updates, and document all interactions, ensuring effective collaboration and information sharing.

2.9.2.3 The Contractor shall identify, assess, and document relevant cyber counterintelligence capabilities within DoW and interagency organizations, evaluating their strengths and weaknesses, and sharing assessment findings with relevant stakeholders in accordance with established security protocols (Section 4, Deliverable 14).

2.10 TASK 10 – OED SURGE SUPPORT

2.10.1 SUBTASK 1 – ON DEMAND SUPPORT for CYBER OPERATIONS

2.10.1.1 The Contractor shall provide on-demand surge support to augment the AG capabilities during peak operational periods, increased mission demands, or any situation requiring additional analytical or technical expertise for Government offensive and defensive cyber operations. This includes providing specialized expertise in all-source analysis, threat intelligence, language support, media processing, cyber incident surge support for the DoW or DIB, technical assistance to Government surge teams, and other ad hoc support needed to maximize mission effectiveness.

2.10.1.2 The Contractor shall ensure a rapid and effective response to surge requests, providing qualified personnel to augment Government capabilities as needed.

2.11 TASK 11 – INTAKE SUPPORT

The Contractor shall deliver expert-level forensic support, contributing to the high-quality, efficient, and accurate processing of all intake cases. The lab's robust intrusion, malware analysis and digital forensic analysis capabilities supports DoW LE/CI, and DIB activities and operations.

Intake support consists of the following:

2.11.1 SUBTASK 1 – CASE TRIAGE and INITIAL ASSESSMENT

2.11.1.1 The Contractor shall deliver timely, high-quality customer service, resolving all inbound cases efficiently and accurately within one (1) business day of receipt by CFL.

2.11.2 SUBTASK 2 – EVIDENCE HANDLING and CHAIN OF CUSTODY

ESTABLISHMENT

2.11.2.1 The Contractor shall, within two-hours of receiving customer requests, thoroughly analyze them for conflicts, evidentiary concerns, and procedural impacts; assess required forensic resources and scheduling; and comprehensively document all actions, findings, and requirements following each case.

2.11.3 SUBTASK 3 – INTAKE PROCEDURE EVALUTION and IMPROVEMENT

2.11.3.1 The Contractor shall evaluate intake procedures monthly for efficiency, accuracy, and compliance, and provide recommended improvements in a written report within two- days of the end of each monthly evaluation period.

2.12 TASK 12 – DATA IMAGING and EXTRACTION SUPPORT

The Contractor shall perform imaging and extraction of digital information in compliance with established forensic standards and best practices. Repairs damaged devices and extracts otherwise inaccessible data from them. Data imaging and extraction support projects consist of the following:

2.12.1 SUBTASK 1 – FORENSIC FILE PREPARATION

2.12.1.1 The Contractor shall employ validated forensic tools and techniques to perform imaging and extraction of digital information from all types of media (e.g., hard drives, mobile devices, removable storage), including on-site acquisitions adhering to chain-of-custody protocols when required.

2.12.1.2 The Contractor shall utilize advanced data recovery methods to repair and recover data from damaged or corrupted media, achieving a recovery rate of 80% or higher of accessible data.

2.12.1.3 The Contractor shall develop a comprehensive case report, adhering to established forensic standards and legal requirements, documenting all findings, methodologies, and conclusions from the digital forensics investigation of evidence related to each case (Section 4, Deliverable 15).

2.12.2 SUBTASK 2 – ARCHIVAL SELECTION and VALIDATION

2.12.2.1 The Contractor shall archive all acquired forensic image files using industry-standard best practices to designated, access-controlled storage media requirements, verifying image integrity upon archiving.

2.12.2.2 The Contractor shall, within two-business days of completing the forensic process for each case, methodically document all forensic processes, including tools used, parameters, and deviations from standard procedures, and actively participate in briefings to communicate findings, provide expert testimony, and address technical inquiries following each case (Section 4, Deliverable 16).

2.13 TASK 13 – EXAMINATION SUPPORT

The Contractor shall provide digital forensic and technical expertise, to ensure the effective analysis of digital evidence and its successful utilization in investigations and legal proceedings.

Performs digital forensic examinations, Examination support projects consist of the following:

2.13.1 SUBTASK 1 – DIGITAL MEDIA EXAMINATION and REPORTING

2.13.1.1 The Contractor shall conduct digital forensic examinations and analysis on a variety of digital media, encompassing malware analysis, reverse engineering, and data recovery, adhering to established industry standards and legal requirements.

2.13.1.2 The Contractor shall, within two-business days of completing the analysis, develop in-depth and reliably sourced Digital Forensic Analysis Reports that clearly articulate findings, methodologies, and supporting evidence in a manner suitable for both technical and non-technical audiences (Section 4, Deliverable 17).

2.13.2 SUBTASK 2 – PEER REVIEW ANALYSIS

2.13.2.1 The Contractor shall perform thorough technical peer reviews of forensic analysis reports to ensure accuracy, completeness, consistency, and adherence to established principles and standards.

2.13.3 SUBTASK 3 – WITNESS TESTIMONY PREPARATION

2.13.3.1 The Contractor shall provide expert witness testimony in legal proceedings, effectively communicating complex technical findings to the court based on defensible forensic methodologies and clear, concise explanations, including examinations conducted off-site as required.

2.13.4 SUBTASK 4 – OFF-SITE EXAMINTATION VERIFICATION

2.13.4.1 The Contractor shall conduct specialized D/MM forensic examinations in direct support of the National Digital Exploitation and OSINT Center (NDOC) to assist in their mission-critical activities, adhering to NDOC-specific protocols and reporting requirements.

2.14 TASK 14 – EVIDENCE CUSTODIAL SUPPORT

The Contractor shall provide extensive support for digital evidence management, ensuring its integrity, legal admissibility, and effective utilization within the DC3/CFL environment and provides expert testimony in legal proceedings for DC3 customers. Evidence custodial support projects consist of the following:

2.14.1 SUBTASK 1 – EVIDENCE PROGRAM MAINTENANCE and COMPLIANCE

2.14.1.1 The Contractor shall actively maintain an effective and compliant evidence program, rigorously enforcing established protocols and legal requirements for handling digital evidence.

2.14.1.2 The Contractor shall facilitate the secure and well-documented flow of all digital evidence entering and exiting DC3/CFL, adhering to established intake, transfer, and outtake procedures.

2.14.2 SUBTASK 2 – LEGAL REQUIRMENTS MONITORING and INTEGRATION

2.14.2.1 The Contractor shall maintain the integrity, proper custody, and defensible chain-of-custody documentation for all digital evidence, ensuring its admissibility in legal proceedings and preventing unauthorized access or alteration by accurately recording all handling, storage, and transfer events.

2.14.2.2 The Contractor shall ensure the secure and traceable management of all digital evidence from receipt to disposition, encompassing identification, photography, proper marking, tracking, processing, and accurate recording in CFL's information management program, maintaining data integrity and an organized evidence repository.

2.14.3 SUBTASK 3 – RESOURCE MANAGEMENT

2.14.3.1 The Contractor shall maintain optimal daily staffing levels within the evidence section to ensure the efficient and continuous processing of evidence and a timely response to all internal and external inquiries.

2.15 TASK 15 – QUALITY ASSURANCE

The Contractor shall support DC3/CFL's commitment to quality and accreditation by maintaining, enhancing, and managing the lab's Quality Assurance Program (QAP). CFL is an accredited lab under ISO 17025 by the ANSI National Accreditation Board for its acquisition/extraction and content analysis activities, which are subject to strict quality-control and peer-review procedures. Quality assurance projects consist of the following:

2.15.1 SUBTASK 1 – SUSTAINMENT and ADVANCEMENT

2.15.1.1 The Contractor shall sustain and advance the CFL’s QAP, adhering to ANSI National Accreditation Board 17025 accreditation requirements.

2.15.2 SUBTASK 2 – DOCUMENT CONTROL and REFINEMENT

2.15.2.1 The Contractor shall administer and refine CFL's document control program to maintain accurate, accessible and compliant documentation, ensuring the continued accreditation and credibility of the lab.

2.15.2.2 The Contractor shall securely manage and maintain accurate records of examiner qualifications, education, training, and prior testimony to ensure compliance and support legal defensibility.

2.15.3 SUBTASK 3 – DATA COLLECTION and ANALYSIS

2.15.3.1 The Contractor shall collect, analyze, and report DC3/CFL QAP performance data, including service level agreements, technical review results, and exam delivery metrics, to drive continuous improvement. This Key Performance Indicator Report is due on a monthly basis (Section 4, Deliverable 18).

2.16 TASK 16 – TRAINING DEVELOPMENT and MENTORING PROGRAM

The Contractor shall provide extensive support for the DC3/CFL training program, to ensure a highly skilled and competent workforce. CFL shall work with the DCOP to develop requirements and set standards for digital investigations as new technologies emerge and evolve.

Training development and mentoring program projects consist of the following:

2.16.1 SUBTASK 1 – TRAINING RECORD MANAGEMENT

2.16.1.1 The Contractor shall establish and administer a complete system for tracking and managing training records for all DC3/CFL personnel (e.g., initial qualifications, specialized skills training, and completion of required continuing education).

2.16.2 SUBTASK 2 – CONTINUING EDUCATION PROGRAM DESIGN

2.16.2.1 The Contractor shall design and enforce continuing education requirements for all D/MM examiners, fostering ongoing professional development.

2.16.2.2 The Contractor shall implement enhancements to DC3's examiner mentoring program based on effectiveness evaluations and in accordance with established DC3 SOPs.

2.16.2.3 The Contractor shall lead continuous improvement of the training and mentorship program by thoroughly evaluating its effectiveness, delivering detailed reports, and recommending evidence-based strategies.

2.17 TASK 17 – PROGRAM MANAGEMENT

2.17.1 SUBTASK 1 – PROGRAM OVERSIGHT

2.17.1.1 The Contractor shall provide program management support. This includes the management and oversight of all activities performed by Contractor personnel, including any subcontractors.

2.17.1.2 The Contractor shall identify a PM by name who shall provide management, direction, administration, quality control, and leadership to all Contractor personnel and sub-Contractor personnel.

2.17.2 SUBTASK 2 – PROGRAM MANAGEMENT PLAN (PMP)

2.17.2.1 The Contractor shall provide a PMP that documents all task/subtask requirements performed to satisfy the requirements of this PWS (Section 4, Deliverable 19).

2.17.2.2 The Contractor shall provide the Government with a draft PMP for review, modification, and approval. The final PMP shall incorporate the Government’s changes.

2.17.2.3 The PMP is an evolutionary document that shall be updated as needed to reflect changes and evolving training requirements (Section 4, Deliverable 20).

2.17.2.4 The Contractor shall work from the most current Government approved iteration of the

PMP.

2.17.2.5 The Contractor’s PMP shall, minimally:

• Describe the proposed management approach.

• Describe the Contractor’s SOPs for all tasks.

• Include milestones, tasks, and subtasks required in this contract.

• Describe in detail the Contractor’s approach to risk management under this contract.

• Describe in detail the Contractor’s approach to communications, including processes, procedures, communication approach, and other rules of engagement between the Contractor and the Government.

• Include the current Organizational Chart and the approach to ensuring the Government is in receipt of the most current version of the Organizational Chart.

• Describe in detail the Contractor’s approach to obtaining short-term specialized expertise, when required for surge support.

2.17.3 SUBTASK 3 – RISK MANAGEMENT

2.17.3.1 The Contractor shall develop, implement, and maintain a comprehensive Risk Management Plan (Section 4, Deliverable 21), as part of the overall PMP, for all tasks executed under this PWS.

2.17.3.2 The Contractor’s Risk Management Plan shall include, (minimally):

Identification of risks, and the assessment of risks and their impacts, prioritization, mitigation, and control plans.

Risk tracking, monitoring, and reporting process.

Risk processes including the development of recovery plans in the event risks are realized.

Escalation timelines and procedures for notifying the Government.

2.17.4 SUBTASK 4 – COMMUNICATION and MEETINGS

2.17.4.1 The Contractor shall facilitate Government and Contractor communications; use industry best practices / standards and proven methodologies to track and document requirements and activities to allow for continuous monitoring and evaluation by the Government; and ensure all support and requirements performed are accomplished IAW the contract.

2.17.4.2 The Contractor shall notify the OED and CFL Directors, Deputy Directors or Contracting Officer’s Representative (COR) via a Problem Notification Report (PNR) of any technical, personnel, or general managerial problems encountered throughout the period of performance (POP) (Section 4, Deliverable 22).

2.17.5 SUBTASK 5 – CONDUCT KICKOFF MEETING

2.17.5.1 The Contractor shall schedule, coordinate, and host a Kick-Off Meeting at the location approved by the Government (Section 4, Deliverable 23) within ten (10) business days of award. The meeting shall provide an introduction between the Contractor personnel and Government personnel who will be involved with the PWS. The meeting shall provide the opportunity to discuss technical, management, and security issues, and travel authorization and reporting procedures. At a minimum, the attendees shall include Key Contractor Personnel, representatives from the directorates, COR, relevant Government personnel, and the AFDW/PKA Contracting Officer (CO).

2.17.5.2 The Contractor shall, at least three-business days prior to the Kick-Off Meeting, provide a Kick-Off Meeting Agenda (Section 4, Deliverable 24) for review and approval by the OED and CFL Directors and COR prior to finalizing. The agenda shall include, at a minimum, the following topics/deliverables:

• Points of Contact (POCs) for all parties.

• Personnel discussion (i.e., roles and responsibilities and lines of communication between

Contractor and Government).

• Staffing Plan and status.

• Transition-In Plan and discussion.

• Security discussion and requirements (i.e., building access, badges, Common Access

Cards (CACs), Personal Identity Verification (PIV).

• The Contractor shall provide a Kick-Off Meeting Minutes Report (Section 4, Deliverable

25) documenting the Kick-Off Meeting discussion and capturing any action items.

2.17.6 SUBTASK 6 – MONTHLY STATUS REPORT (MSR)

2.17.6.1 The Contractor shall develop and provide an MSR (Section 4, Deliverable 26). The MSR shall be presented at the Monthly Technical Status Meeting (Section 4, Deliverable 27).

The MSR shall include, minimally, the following:

2.17.6.2 Activities during reporting period, by task (include ongoing activities, new activities, and activities completed, and progress to date on all above-mentioned activities). Each section shall start with a brief description of the task.

2.17.6.3 Problems and corrective actions taken as well as issues or concerns and proposed resolutions.

2.17.6.4 Personnel gains, losses, and status (e.g., out-processing, in-processing, security clearances, etc.). This shall include a copy of the latest Organizational Chart.

2.17.6.5 Government actions required.

2.17.6.6 Schedule execution and forecast reports defined during the Program Baseline Review (show major tasks, milestones, and deliverables; planned and actual start and completion dates for each).

2.17.6.7 Summary of trips taken, conferences attended, etc. (attach Trip Reports to the MSR for reporting period).

2.17.7 SUBTASK 7 – ASSET MANAGEMENT SERVICES

2.17.7.1 The Contractor shall provide shall provide asset management on all GFE provided as a part of the PWS in accordance with DC3 policies and procedures.

2.17.8 SUBTASK 8 – GOVERNMENT REQUIRED TRAINING

The Government will provide the Contractor a list of all required training, with completion dates.

2.17.8.1 The Contractor shall successfully complete and/or attend all training identified by the Government and use the Government’s approved system to take and record this training, primarily on Joint Knowledge Online (JKO).

2.17.8.2 The Contractor shall not directly bill the Government for any Government-required training. The type of training contemplated by this section is joint compliance training typically found in JKO or similar online DoW system.

2.17.9 SUBTASK 9 – KEY PERSONNEL

The following are the minimum personnel who shall be designated as “Key.” The Government does not intend to dictate the composition of the ideal team to perform this contract.

• Program Manager (PM)

• OED Technical Lead

• CFL Intrusions Lead

2.17.9.1 Program Manager: The Contractor shall identify a PM by name to serve as the Government’s primary POC. The PM shall provide overall management and oversight of all activities performed by Contractor personnel, including subcontractors, to satisfy the requirements identified in this PWS. The PM shall facilitate Government and Contractor communications, use industry-best standards and proven methodologies to track and document requirements and activities to allow for continuous monitoring and evaluation by the Government, and ensure all tasks are accomplished IAW this PWS. The PM shall be responsible for the quality and efficiency of the Contractor’s performance and shall assist the Government with all financial and business processes of this PWS, excluding inherently Governmental functions. It is required that the PM has the authority to make decisions for the Contractor’s organization in response to Government issues, concerns, and comments; the authority to commit the prime Contractor’s organization; and to be proactive in alerting the Government to potential contractual or programmatic and resource limitations issues.

2.17.9.1.1 The PM is required to have the following qualifications:

• Top Secret Sensitive Compartmented Information (TS/SCI) clearance eligible.

• Project Management Professional® (PMP) certification.

• Experience within the last ten years managing a project, or program of similar size and complexity to this PWS.

• Experience within the last five years overseeing and determining manpower requirements for projects similar in size and complexity to this PWS, consisting of a diversity of technical skill sets and labor categories.

• Experience within the last five years performing financial and performance monitoring of contracts (e.g., performance metrics).

2.17.9.2 OED Technical Lead: The Contractor shall identify an OED Technical Lead who shall provide management, direction, business operations support, quality control, and leadership of Contractor personnel supporting the OED. The OED Technical Lead shall provide overall leadership and guidance for all Contractor personnel assigned to the OED, including assigning tasks to Contractor personnel, supervising ongoing technical efforts, and managing overall performance of the Contractor team. The OED Technical Lead shall be responsible for the quality and efficiency of the Contractor’s performance and shall assist the Government with all financial and business processes of this PWS, excluding inherently Governmental functions. The OED Technical Lead shall be required to occasionally travel to CONUS and OCONUS locations.

2.17.9.2.1 It is required that the OED Technical Lead has the following qualifications:

• TS/SCI clearance eligible.

• Experience in the last ten years leading technical efforts or supervising teams supporting intelligence analysis requirements.

• Experience in the last ten years supporting the intelligence community or related

Government, industrial, and academic communities in the areas of intelligence collection and policy and intelligence systems and capabilities.

• Experience in the last ten years using principles, concepts, and methodologies of intelligence analysis, including, but not limited to, the use of HUMINT and SIGINT methods.

• Experience in the last ten years developing requirements and methodologies to collect, analyze, manage, and present intelligence in support of cyber investigations and operations.

• Experience in the last ten years writing various analytical reports (e.g., IIRs), serialized intelligence products, and operational cyber threat products).

• Experience in the last ten years for project management experience (e.g., responsible for handling project scope, cost, resources, risk, and schedule).

2.17.9.3 CFL Intrusions Lead: The Contractor shall identify a CFL Intrusions Lead to serve as a project lead and provide oversight of system and network forensic examinations/malware analysis and reverse engineering for a range of evidence items submitted to DC3. This work shall be completed IAW requirements set forth by the Government and Federal law, the UCMJ, CFL Accreditation, SOPs and Intrusions Best Practices to develop evidence and intelligence information. The CFL Intrusions Task Lead shall be responsible for the quality and efficiency of the Contractor’s performance and shall assist the Government with all financial and business processes of the task, excluding inherently governmental functions.

2.17.9.3.1 It is required that the CFL Intrusions Lead has the following qualifications:

• TS/SCI clearance eligible.

• Experience within the last five years leading technical efforts and supervising teams in a forensics lab environment similar to the scope and complexity of this PWS.

• Experience within the last seven years performing D/MM forensics examinations, analysis, and techniques.

• Experience within the last seven years working with MS Windows, Apple/UNIX, and

Linux operating systems related to forensics examinations.

• Experience within the last seven years with forensic network analysis in support of the investigative process.

• Experience within the last seven years analyzing endpoint, Packet Capture (PCAP) data, and other relevant data sources.

• Experience within the last five years utilizing common digital forensic examination tools, including those referenced in the DC3 TOR (e.g., FTK, EnCase, and X-Ways).

2.17.9.4 A key personnel substitution occurs when there is any person who, in an acting capacity, performs the duties of any Key Personnel temporarily (more than 30 consecutive calendar days).

2.17.9.5 The Contractor shall not replace any personnel designated as Key Personnel without the written approval of the OED and CFL Director with concurrence of the CO. Prior to utilizing other than the Key Personnel specified in its proposal in response, the Contractor shall notify the OED and CFL Director, CO, and COR of the existing PWS. This notification shall be no later than ten (10) calendar days in advance of any proposed substitution and shall include justification and labor category of proposed substitution(s) in sufficient detail to permit evaluation of the impact on PWS performance. The Government shall not be billed for positions left vacant over 30 calendar days unless the vacancy is due to Government delay and otherwise approved by the CO.

2.17.9.6 Substitute Key Personnel qualifications shall be equal to, or greater than, those of the Key Personnel substituted. If the OED and CFL, CO, and the COR determine that a proposed substitute Key Personnel is unacceptable, or that the reduction of effort would be so substantial as to impair the successful performance of the work under the contract, the Contractor may be subject to default action as prescribed by FAR 52.249-6 Termination.

2.17.9.7 For the purposes of this contract, all persons supporting this contract shall be considered ‘non-Key Personnel’ unless they are assigned as, or are performing the duties of, a position identified as ‘key’ above.

2.17.10 SUBASK 10 – TRANSITION

2.17.10.1 TRANSITION-IN

This subtask addresses requirements for the entire transition period. Transition-in shall be accomplished using a two-phased transition approach, the Initial Operational Capability (IOC) (Section 4, Deliverable 28) and the Full Operational Capability (FOC) (Section 4, Deliverable 29). Phase 1 of the transition, referred to as IOC at completion, shall be delivered NLT 45 calendar days following contract award and shall represent 50% of OED and CFL essential functions in operation. Phase 2 of the transition, referred to as FOC at completion, shall be delivered NLT 90 calendar days following contract award. This milestone marks Contractor performing 100% of OED and CFL Contractor functions.

Immediately following award, the Contractor shall begin implementing its phased Transition-In Plan (provided as a part of the proposal). The Contractor shall provide a status/progress update of its transition-in activities at the Kick-Off Meeting and weekly updates thereafter. The Contractor shall notify the Government immediately of risks impacting transition.

2.17.10.2 TRANSITION-OUT

The Contractor shall provide transition-out support when required by the Government. The Transition-Out Plan shall facilitate the accomplishment of a seamless transition from the incumbent to incoming Contractor at the expiration of the contract. The Contractor shall provide a Transition-Out Plan within three months of Project Start (PS) (Section 4, Deliverable 30). The Government will work with the Contractor to finalize the Transition-Out Plan. At a minimum, this Transition-Out Plan shall be reviewed monthly and updated as required (Section 4, Deliverable 31).

2.17.10.2.1 In the Transition-Out Plan, the Contractor shall identify how it will coordinate with the incoming Contractor and/or Government personnel to transfer knowledge regarding the following:

• Specifications including equipment, tools, and materials used in support of this contract.

• Point of Contacts (POCs) for licensing agreements etc.

• Actions required of the Government.

• The Contractor shall also establish and maintain effective communication with the incoming Contractor/Government personnel for the period of the transition via weekly status meetings or as often as necessary to ensure a seamless transition-out.

• The Contractor shall implement its Transition-Out Plan NLT one month prior to expiration of the current contract.

SECTION III

3.0 SERVICE SUMMARY

The Contractor service requirements are summarized into performance objectives that relate directly to mission essential items. The performance threshold briefly describes the minimum acceptable levels of service required for each requirement and will be assessed on an “Acceptable” or “Unacceptable” basis. These thresholds are critical to mission success.

Performance Objective PWS Paragraph Performance Threshold Method of

Surveillance

SS – 1

Ensure CADO-IS stakeholder collaboration by establishing, maintaining, and evolving the CADO-IS EA and its DoDAF-adherent documentation, implementing robust CM processes for all CADO-IS components, and establishing a standardized evaluation process for new partners and capabilities to foster continuous improvement and ecosystem expansion.

2.1, 2.1.1, 2.1.2

a) CADO-IS Enterprise Architecture Report 100% free of error

b) 95% of configuration items accurately tracked in CM system

c) Evaluation process documented and implemented within 30 calendar days of contract award

Customer Complaint

100% Surveillance

Document review

SS – 2

Effective utilization of ADO by DC3 mission partners through proactive engagement, recruitment, seamless onboarding, comprehensive training, robust Tier 1 and Tier 2 support throughout the ADO lifecycle, and proactive monitoring for security incidents with ensured proper data disposition.

2.2, 2.2.1, 2.2.2

a) [2] number of ADO adoptions among DC3 mission partners

b) [10] % increase in active ADO users per quarter; [2] new mission partners onboarded per year

c) 100% of new mission partners receive onboarding/training within 5 number of business days of new mission partner approval

d) Tier 1 support response within 24 hours; Tier 2 resolution within 72 business days

e) 100% potential security incidents reported within 24 hours

Periodic Inspections

ADO Usage statistics

Onboarding/ training documentation review

Security incident report review

SS – 3

Ensure effective operation and integration…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .