Attachment_4_-Q&A_AMA_25Sep2019.pdf

PDF 201 KB Posted

Attached to
Software DevSecOps Services Blanket Purchase Agreement Federal contract opportunity
Solicitation number
fa8307-19-R-0133
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hanscom Air Force Base

About this file

AMA Q&As

View the file

Other files for this federal contract opportunity

Other files attached to Software DevSecOps Services Blanket Purchase Agreement, newest first.
File Type Posted
Amendment_5_-_SW_DevSecOps_(133).pdf PDF
BOA_RFQ_Cover_Letter_-_SW_DevSecOps_9Oct19.pdf PDF
FA830719R0133.pdf PDF
Attachment_1_-_ITO_SW_DevSecOps_9Oct19.pdf PDF
Revised_Provisions_and_Clauses_-_DevSecOps.docx DOCX document
LevelUP_AMA_03Oct19.pdf PDF
Attachment_4_-Q&A_AMA_3Oct2019.pdf PDF
LevelUP_AMA_25Sep19.pdf PDF
BPA_RFQ_Cover_Letter_-_SW_DevSecOps_clean.pdf PDF
Amendment_3_-_SW_DevSecOps_(133).pdf PDF
FA830719R0133_-_SW_DEVSECOPS.pdf PDF
Attachment_1_-_ITO_SW_DevSecOps_tracked.pdf PDF
Attachment_1_-_ITO_SW_DevSecOps_clean.pdf PDF
Attachment_4_-_Q&A_DevSecOps.pdf PDF
BPA_Guide_SW_DevSecOps_v2_tracked.pdf PDF
BPA_RFQ_Cover_Letter_-_SW_DevSecOps_tracked.pdf PDF
AMA_QA_Report_(9.25.19).pdf PDF
Attachment_E_-_Sample_DD254.pdf PDF
Attachment_G_-_Labor_Category_LevelUP.pdf PDF
Attachment_1_-_ITO_SW_DevSecOps.pdf PDF
Attachment_4_-_Q&A_Template.docx DOCX document
Attachment_2_-_SOO_SW_DevSecOps.pdf PDF
Attachment_F_-_Key_Personnel_Information.pdf PDF
Attachment_3_-_Pricing_Sheet.xlsx XLSX spreadsheet
Attachment_D_-_On_Off_Ramp_Procedures.pdf PDF
Attachment_5_-_BPA_Guide_SW_DevSecOps.pdf PDF
Attachment_6_-Provisions_and_Clauses_-_SW_DevSecOps.pdf PDF
BPA_RFQ_Cover_Letter_-_SW_DevSecOps.pdf PDF
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ASK ME ANYTHING (AMA) QUESTIONS / RESPONSES

FA8307-19-R-0133, 0134, & 0135

DevSecOps Initiative AMA Session 2 October 2019

QUESTIONS RESPONSES

1. Shall rate build-up be based on Government or Contractor site?

Vendors have the discretion to propose for a high and average locality rate. Location will be determined at the call level, work may or may not be at a Government or Contractor site depending on the requirement.

Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

2. What city and state location shall the rate build-up be based upon?

Vendors have the discretion to propose for a high and average locality rate. Work is not limited to one city and state location.

Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

3. Are there labor category requirements and/or descriptions for Levels 1, 2, and 3?

Level 1 is considered entry level, Level 2 is moderate experience, Level 3 is a senior/expert level. NOTE:

Requirements for labor category descriptions are arbitrary to the talent we are seeking.

4. Is labor category Level 3 the more senior/expert level?

Requirements for labor category descriptions are arbitrary to the talent we are seeking.

5. Will Task Order potentially require higher level security clearances than outlined in Attachment G "able to obtain secret"?

Potentially, yes. Work will range from Unclassified to

TS/SCI.

6. Please confirm Attachment 3 is Attachment B. Confirmed, however, please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

7. Please confirm Attachment 3/Attachment B can be manipulated to be compliant with contractor's estimating structure/disclosed estimating practices.

Confirmed, however, please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

8. Please clarify whether the customer is expecting the contractor to establish 1 set of rates at the BPA level to apply to FFP and T&M/LH call orders or if two separately priced ratecards should be priced.

Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

9. Can all volumes be combined into a single PDF file for submission?

No, please submit PDFs separately.

10. In relation to Factor 2: Portfolio Review, will the Government accept links to DI2E project spaces where the Government may need to obtain access to a given project in order to view associated data and details?

No, please submit project details and experience in a

PDF.

11. Can you expand what your are looking for in Volume, Portfolio Review? Is it a traditional past performance write-up? The source code we develop for DoD is at a classification that does not permit access via a web portal.

The Government will not be accepting classified proposals. The portfolio review is not limited to traditional past performance, intending to allow companies to propose with no DoD experience.

Please provide an unclassified version or write up, if possible or commercial experience.

12. Please clarify it is the Government’s intent that all bidders submit the worksheet only, and that bidders are not requested to submit any associated narrative and/or justification for the proposed rates in order to demonstrate fair and reasonable pricing.

Please refer to the Instructions to Offerors/Basis of Award attached to the associated BPA you intend to submit a Quote to. Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

13. DevSecOps Question: Is the solicitation a brand new contract or is this a new contract to continue support of an existing contract whose period of performance is ending? If this is to establish a new contract due to a period of performance ending, would the existing vendor be eligible to compete for the new contract?

There are three separate Blanket Purchase Agreements for new requirements. These are not follow-ons to existing contracts.

14. "Cloud Services Blanket Purchase Agreement Solicitation Number: FA8307-19-R-0135

RE Factor 1 – Management review

“Portfolio indicates numerous and strong partnerships with certified/authorized reseller and/or partner networks. Positive aspects of the portfolio outweigh any negative aspects.”

This leaves out CSP’s who directly offer cloud services.

This implies that only FedRAMP/DISA Cloud services are available vis a partnership with CSP’s, which is not true.

There are several FedRAMP Authorized IaaS/PaaS CSP’s with a JAB P-ATO Moderate and DISA IL 2/4 who directly offers services to the Government without the use of resellers.

How can a direct seller CSP who sells directly be compliant with factor 1 when it is mandated that you must be a partner"

Evaluation criteria has been updated.

15. "Software DevSecOps Services BPA:

a. Shall rate build-up be based on Government or Contractor site?

b. What city and state location shall the rate build-up be based upon?

c. Are there labor category requirements and/or descriptions for Levels 1, 2, and 3?

d. Is labor category Level 3 the more senior/expert level?

e. Will Task Order potentially require higher level security clearances than outlined in Attachment G ""able to obtain secret""?

f. Please confirm Attachment 3 is Attachment B

g. Please confirm Attachment 3/Attachment B can be manipulated to be compliant with contractor's estimating structure/disclosed estimating practices

h. Please clarify whether the customer is expecting the contractor to establish 1 set of rates at the BPA level to apply to FFP and T&M/LH call orders or if two separately priced ratecards should be priced.

j. Can all volumes be combined into a single PDF file for submission?"

a/b. Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

c. Level 1 is considered entry level, Level 2 is moderate experience, Level 3 is a senior/expert level.

NOTE: Requirements for labor category descriptions are arbitrary to the talent we are seeking.

d. Level 3 is a senior/expert level.

e. Potentially, yes. Work will range from Unclassified to TS/SCI.

f-h. Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

i. Please submit volumes in separate files attached to your Quote.

16.

a. In relation to Factor 2: Portfolio Review, will the Government accept links to DI2E project spaces where the Government may need to obtain access to a given project in order to view associated data and details?

b. Will this contract support AFLCMC/HNCP’s Cyber Enterprise Services (CES) contract requirements at the conclusion of the CES contract’s period of performance of 20 Feb 2021?

a. No, please submit project details and experience in a PDF.

b. At this time, the follow-on acquisition strategy has not been determined for the Cyber Enterprise Services IDIQ.

17.

a. Cloud Services BPA: 1. Attachment 1 - ITO_for_Cloud:

Will the government consider providing an architecture example to use for the basis of estimate in order to provide a price that is evaluated using “comparison of proposed prices received in the response to the RFQ”?

b. Attachment 1 - ITO_for_Cloud: Will the government provide the methodology of the “price analysis” used to determine price reasonableness and completeness.

c. Attachment 1 - ITO_for_Cloud: “Volume I:

Administrative” per 3. Evaluation Factors is not being evaluated. Part of the 2-page requirement is the opportunity to provide “a statement that the company understands the requirements specified and will meet the performance standards and requirements”. The remaining requirements (cover letter with their quote, POC and contact info and the statement of exceptions, if any and the validity of 120-day quote) will not require space of two pages. Will the government consider changing the Volume I: Administration” page count to 1, move the compa"

a. No. Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

b. Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

c. Page counts will remain as listed.

18. DevSecOps BPA: Do you want Volumes 1-3 submitted as a single document or separate documents? Please submit the volumes in separate attachments.

19.

Attachment_1_-ITO_SW_DevSecOps in Section 2, Basis for Award, states “Offerors who receive a Highly Capable Technical rating, a higher than Acceptable Portfolio Review rating, and their prices are determined fair and reasonable will be invited to the BPA Event Day tentatively scheduled for 13 November 2019 as a continuation of the technical evaluation.” It is unclear how the Government will consistently determine that proposed labor rates are fair and reasonable as Attachment_G_-_Labor_Category_LevelUP does not provide education and experience requirements for each labor category. This will result in bidders using their own interpretation of each labor category. The rates proposed will be fair and reasonable to the offeror but may not be fair and reasonable to the Government who may have a different interpretation of the education and experience required for each labor category. Will the Government consider revising Attachment G to include education and experience requirements?

Labor category descriptions are written to ensure we do not restrict talent based on educational/experience requirements.

Please note that Price has been removed from the

20. How does the contracting office plan to manage audit rights for orders under these BPAs?

Management of audit rights is an internal Government process; therefore, we will not be providing any details in this forum.

21. Are there plans to run Jenkins as a container -- inside Kubernetes?

All technical requirements will be expressed in the individual call.

22. Cloud Services BPA -

The list of applications includes MSBuild. MSBuild is an application that is part of Visual Studio. Does the government require pricing for Visual Studio as this is not an application that can be purchased as a standalone product?

The pricing and availability of Cloud Services is dynamic in nature. Cloud Service Providers continually add new services and modify existing services. How will these changes be handled under this BPA?

MSBuild: MSBuild can run without Visual Studio. It is available here: https://github.com/microsoft/msbuild

It is available free of charge under the MIT License:

https://github.com/microsoft/msbuild/blob/master/L

ICENSE

BPAs will have a tech refresh on an annual basis to reflect changing and emerging technologies.

Please note that Price has been removed from the

23. There is a requirement Bidding vendors will need to prove that their company can process data securely at the second-highest security level for Defense Department systems, impact level five. Does this mean we have to have developed a system in the cloud that is rated level five?

No, the Government will specify what the security classification and specific impact level will be at the time of the call.

24.

a. How will using these BPAs fit in the "order of preference" compared to the priority given to DoD ESI contracts?

b. Thanks for the follow-up. I believe ESI provides "related services" (i.e., related to SW or HW), so do you mean integration and other support services?

a. Question was addressed live, but to expand further, licenses and services (together) are not provided on ESI

b. Yes, contractors will need to provide pipeline & platform integration and licensing to support a wide collection of software and programming tools. Please note: agencies will still need to adhere to any mandatory sources.

https://github.com/microsoft/msbuild https://github.com/microsoft/msbuild/blob/master/LICENSE https://github.com/microsoft/msbuild/blob/master/LICENSE

25. SW-DevSecOps - For resource planning purposes, can you provide insight into the November 13 event date (ahead of the additional information planned for Nov 1)?

What type of personnel should we plan to make available?

The Government is currently working logistics and format. Details regarding Event Day will be provided to attendees as soon as available but no later than 1 November 2019. However, offerors should prepare for a Q&A regarding the technical capabilities cited in their quote.

Invited vendors will need to bring personnel capable of validating their technical capability and portfolio review submissions through an oral presentation. If awarded a BPA, the vendor needs to ensure they bring someone with the authority to sign on behalf of their company.

26. SW-DevSecOps - Volume III Portfolio Reviews - Can you clarify what “offeror may provide information for several Government or commercial clients…”? Is this past performance, descriptive examples, code examples? –

The vendor has the discretion to provide any past performance/examples they deem appropriate and relative.

27. Are companies that are foreign owned, but fully FOCI-compliant (per the foreign ownership control regulations), eligible to be a prime on a LevelUP BPA?

Please note that some Calls placed under this BPA will require contractor access to proscribed information, i.e., Top Secret, Sensitive Compartmented Information, Special Access Program, Communication Security, and Restricted Data. As a result, any prospective Offeror that has foreign ownership, control or influence (FOCI) as defined in National Industrial Security Program Operating Manual, Chapter 2, Section 3, will need to make that known to the Government Contracting Officer with the submission of its quote. In addition, to be found responsible and eligible for award by the Government Contracting Officer, that prospective Offeror will also need to provide proof it has put in place security measures to negate or mitigate FOCI. The Government will verify this status during evaluations.

Please note this also applies to subcontractors and teaming partners.

28. DevSecOps BPA - Attachment_1_-ITO_SW_DevSecOps in Section 2, Basis of Award, states: “Note that the BPA Event Day is a continuation of the technical evaluation and attendance is mandatory in order to receive a BPA.

Award determination will be contingent on the results of the BPA Event Day.” What are the expectations for the bidders participation in BPA Event Day, i.e. are bidders just required to attend, or are there additional evaluation criteria which will be based upon an oral presentation?

The Government is currently working logistics and format. Details regarding Event Day will be provided to attendees as soon as available but no later than 1 November 2019. However, offerors should prepare for a Q&A regarding the technical capabilities cited in their quote.

There is no additional evaluation criteria, this will be an extension of the stated evaluation criteria. Invited vendors will need to validate their technical capability and portfolio review submissions through an oral presentation.

29. Can vendors submit quotes for a subset of the skillsets listed in the BAA (the case for small businesses that do not have all the skillsets/job descriptions that are required in the BAA?) or are small businesses recommended to go through a prime?

Offerors shall submit quotes IAW the RFQ, Instructions to Offeror/Basis of Award. Companies must determine whether or not they can fulfill the requirements of the RFQ. BPAs will only be issued to those vendors who can fulfill the requirement as stated in the RFQ.

30. SW-DevSecOps - Volume III Portfolio Reviews - How should we interpret the page limitation (3 pages) for the portfolio review? Is this a description of content that includes links to source or other DevSecOps components?

The Government does not intend to research links to sources of content, please provide a description of portfolio review. Links may be used to access source code versus content.

31. DevSecOps BPA - If the Government is not looking for bidders to provide links to publically available Web Sites, will you update the BPA to clarify this evaluation factor? If the Government is requesting bidders include links to publically available Web Sites, essentially providing infinite page count for Factor 2. This infinite expansion of page count may make it difficult to assess all bidders fairly and may extend the Government’s acquisition timeline.

Will the Government please update Factor 2 such that only material provided within the allocated page count is evaluated?

The Government does not intend to research links to sources of content, please provide a description of portfolio review. Links may be used to access source code versus content.

32. SW-DevSecOps - Volume III Portfolio Reviews - We assume the repository is set up specifically for 1:1 sharing for this acquisition (i.e. access provided to government by invitation, not an existing public repository?)

Correct

33. Will any of these BPAs entail supporting workforce and organizational development and transformation to support benefits realization of these new DevSecOps capabilities? Are these services factored into these three BPAs as well?

Yes, these services will be factored into these BPAs and is incorporated into the Labor Categories in the Software DevSecOps Services BPA.

34.

a. Will this work be done in a common development environment (I.E. GovCloud and/or C2S) - or is there also an on-prem requirement? If so - OpenStack? VMWare?

b. For the software development factories/labs that are expected to be supported - is there any information on platform (cloud native and containerized - or is there transition work that will be happening?) Is there a requirement to migrate existing development shops to Agile and CI/CD, or will the development teams be Agile-focused and bought in to the CI/CD and DevSecOps methodologies?

c. Are development labs and pipelines intended to be universal - one pipeline, one path to production - or is the intent to support multiple mission partners and sites with varying infrastructure requirements?

d. Is the intent that CATO be provided by adherence to the DevSecOps process (similar to SpaceCAMP), or by virtue of being built into a common, accredited platform and infrastructure?

a. This work will be done in both on-prem and a common development environment.

b. There will be multiple platforms for this effort. The determination of work type will be determined at the call level.

c. This effort will support multiple efforts and will be determined at the call level.

d. CATO governance and requirements will be handled by the Government and adherence to any specific CATO guidelines will be determined at the call level.

35. What is the government's intent with any source code repositories that are supplied? How do you assess code quality?

Government’s intent is to review code quality and ensure the code does what it’s supposed to.

36. Are you looking for DevSecOps capabilities for end to chain of Command for artifacts generated deployed and the Configuration, Change and incident management for these artifacts (content trust)?

Any capabilities that adds value or increases/enhances security to the DevSecOps CI/CD Pipeline (guardrails and processes) are welcome.

37. SW-DevSecOps - Volume II Technical capability - Can the government provide additional guidance on the various site locations and provide additional definition of co-location (i.e. is staff located on government site or at offeror site nearby?)

Site locations will vary based on user requirements.

Vendors have the discretion to propose for a high and average locality rate. Location will be determined at the call level, work may or may not be at a Government or Contractor site depending on the requirement.

Please note that Price has been removed from the

38. Will you only be looking at security tools native to the CSP's or will 3rd party vendors be looked at to provide additional security controls?

Not limited to only security tools native to CSPs. All capabilities must have the ability to be hosted in our own environments.

39. How many awards does the government anticipate to make to small businesses?

The Government anticipates awarding to both small and large businesses. Note that the Government reserves the right to award one (1) or more small business, small business team or joint venture if qualified and eligible for a BPA award. If the Government chooses to exercise this right and two or more small businesses/teams/joint ventures are determined qualified and eligible for a BPA, the Government will consider small disadvantaged business status in its selection for award.

40. Can small business joint ventures submit? Yes

41. Pipeline BPA - Attachment_3_Pipeline_Pricing_Sheet:

Only one Labor category is provided. What is the government’s anticipated use of labor on this BPA vs.

actual license purchases? Will be awardees be allowed to provide value add labor to provide thought leadership to guide the USAF in broader aspects of this critical capability?

Part of the labor is to manage and support the integration of new or existing capabilities. Software DevSecOps Services BPA includes labor categories to support additional requirements.

Please note that Price has been removed from the

42. Ref BPA 2 - Pricing Template - Worksheet for Container/Licenses listing different example DSOP tools -can you provide explanation and/or a sample illustration on product pricing for this work sheet?

Please reference the solicitation for pricing sheet.

The vendor has discretion to provide their best determination for proposing. These tools are not specifically for DSOP but anticipated for multiple efforts. The number and mix of licenses will be determined at each individual call.

Please note that Price has been removed from the

43. In order to level the playing field between offerors, will the government please provide labor category descriptions (including requirements for education and years of experience) for each labor category included in Attachment 3, Pricing Sheet? - relevant for Software DevSecOps BPA

Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

Labor category descriptions are written to ensure we do not restrict talent based on educational/experience requirements.

44. Regarding Cloud Services BPA

As a follow up to a previous question...

What is the format and page limit for submitting technical capability?

Please refer to the Instructions to Offerors/Basis of Award for Cloud Services attached to the RFQ for page limitations to the corresponding Volume.

45. For the Software DevSecOps Services BPA, should a company price all of the developer roles identified in the Pricing Sheet or just the roles that reflect their company strengths? Is it ok to only apply for some of the Labor Category roles.

IAW with the RFQ, offerors shall be able to fulfill all requirements identified in the RFQ. Please note that Price has been removed from the evaluation criteria.

Determination of price fair and reasonableness will be determined at the call level.

46. What levels of support are vendors expected to provide through the help desk? (L1-L3)

The levels of support will be determined at the call level depending on the magnitude of the requirement.

47. What is the pricing evaluation process and criteria for both the BPA and the Task Orders?

Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

In regards to the individual Calls, the pricing evaluation process and criteria will be determined and provided in the Call RFQ.

48. If a contractor receives an award for the Services BPA, is that contractor eligible to also receive an award for the Cloud or Tool BPA?

Each BPA is an individual requirement. Offerors are eligible to submit quotes to all three BPAs and receive a single BPA under each.

49. Many of the tools offer a wide range of licensing options based on levels of services (e.g, Standard, Professional, Enterprise), number of users, remote access, managed services, SaaS access and/or features desired.

Can the government clarify specific software products, number of users, and licensing model desired? - Relevant to the Pipeline & Platform Integration and Licensing Services BPA

Please note that Price has been removed from the

50. DevSecOps BPA

a. Is there currently an incumbent in this role or is it a new position?

b. If an incumbent is in place, would the DoD prefer to keep them in place for this new award?

c. If an incumbent in in place, would we be able to speak to them so we could include them in our response?

d. Can you provide guidance on the labor category they are currently working under?"

a-d. This is a new requirement. Therefore, there are no incumbents.

51. You would expect source code or mostly links to our capabilities and demos?

It is at the discretion of the vendor to propose a narrative that clearly meets the requirements. The Government does not intend to research links to sources of content, please provide a description of portfolio review. Links may be used to access source code versus content.

52.

a. Will there be a small business track?

b. Do you require bidders to have prime past performance?

c. Are you accepting CTAs and JVs?"

a. The Government intends to award a mix of small and large businesses. There is not a set small business track. However, the Government intends to do small business set-asides at the Call level, at its discretion.

b. The Government will be evaluating a Portfolio Review (Factor 2). The portfolio review is not limited to traditional past performance and does not require bidders to have prime past performance, intending to allow companies to propose with no DoD experience.

Note - Past performance is not being utilized as an evaluation factor. However, the information obtained from other sources such as PPIRs available to the Government will be used as part of the responsibility determination IAW FAR 9.104-1.

c. Yes

53. Are you looking for DevSecOps capabilities for end to end Chain of Command for artifacts generated deployed?

Is there a recommended platform for Configuration, Change and incident management for the artifacts (content trust)?

Any capabilities that adds value or increases/enhances security to the DevSecOps CI/CD Pipeline (guardrails and processes) are welcome.

54. Software DevSecOps

On the bottom of page 2 of the SOO it mentions “Support a 24 hour operations and/or business hour (0830-1630) help desk”. If conducted during business hours, would this need to be EST, CST, or MST?

The location will be determined at the call level. Time zone is dependent on location.

55. Cloud BPA - Attachment_5_- _BPA_Guide_for_Cloud_Services states: “This BPA will leverage various contract types to include Time & Materials/Labor Hour and Firm-Fixed price.” Is it the Government’s intent that labor will be purchased form this BPA?

This will be determined at the call level. However, all labor categories will be based off of the DevSecOps Services BPA.

56. Cloud BPA - The Government is requesting 11 year pricing; however cloud service providers and their offerings will evolve over this period. What provisions does the BPA have allowing BPA holders to update their rate card (rates and items) as the cloud landscape evolves?

Please note that Price has been removed from the

57. As it relates to teaming partners, can vendors submit as a prime contractor and also support other small business as subcontractor?

Yes, however, please note that vendors can only hold one BPA under each requirement.

58. What is the expected range of award size and length at the task order level?

This will be determined at the BPA Call level.

59. All 3 BPAs - Will the Government consider providing a representative call order for this BPA? A representative call order allows bidders to clearly understand the commitment being made to the AF as a BPA participant.

This ensures all bidders understand the level of support required to participate in the BPA meeting the Government’s expected 10 day turnaround for call order proposals. Providing the representative call order is also advantageous to the Government as bidders not willing to make the required commitment to the AF will not burden the Government with evaluation of a BPA proposal.

The Government will not provide a representative call order as the calls have the potential to significantly vary from call to call.

Level of support required will be detailed in the ordering guide.

60. Regarding "BPA 3" (Cloud Service Provider-focused), Will the Government please clarify if the products and services must be on GSA Schedule? In other words, are offers restricted to companies that have Letters of Supply (LOS) from the associated cloud service providers?

Industry suggests that such a restriction will limit competition, as the major cloud service providers undoubtedly anticipated for use under this contract have very limited LOS programs.

This is a stand-alone BPA and not associated with a GSA Schedule or any other contract vehicle.

61. You need to decide the FCL requirement at the BPA level, or awardees may not be able to bid at the Call Level

- Software DevSecOps requires up to TS/SCI (see your draft DD254). If you award to companies that do not hold an FCL, then they will not be able to hold or process security clearances.

Minimum FCL requirements are Unclassified, maximum are TS/SCI. The determination of which classification level will be made at the call level. The “sample” DD254 was only a draft and will be provided at the call level.

62. DevSecOps - Attachment_G_- _Labor_Category_LevelUP contains the labor categories one would expect to use when staffing DevSecOps teams.

However, labor categories do not exist for leadership positions such as Scrum Master and Product Manager.

Based on this observation it is unclear who provides these leadership roles. Does the Government intend to perform these leadership activities with this BPA primarily serving as staff augmentation to Government led teams, i.e. does the Government anticipate letting call orders for support staff (FTEs) or for the design, development, deployment, or maintenance of a complete product or service?

The Government Product Manager will provide this function.

63. CSEngineering: The question about source code being shared in the Portfolio volume is important for those of us who are already doing DevSecOps, but exclusively in the classified community. We wouldn’t score “highly” if it is a requirement to share the source code. And thus, would not bid on the BPA.

The Government is not accepting classified proposals.

Please provide an unclassified version or narrative describing your source code and or previous application/capabilities. Portfolio volume is only one of the evaluation factors and if selected, the onboarding event would be the opportunity to validate your abilities.

64. For all BPAs: Does the Gov't anticipate providing a forecast pipeline of calls to facilitate planning activity?

Once the BPA is awarded and requirements are identified, the Government may consider forecasting calls for planning purposes.

65. Relevant to Software DevSecOps and Pipeline/Platform BPAs - On page 2 in Section F.B of Attachment 1 ITO, the Government states “If an Offeror chooses to obtain an NDA, to facilitate that process the Government is providing Abacus Technology Corporation, MITRE, and P3I, Inc. points of contact, with address, to whom Offerors should submit both their and any subcontractor NDAs for signature:” however it appears that the points of contact are missing after the colon.

Please provide the POCs, with address, for Abacus, MITRE, and P3I referenced so that we (and our subcontractors) may obtain an NDA with them.

Note - Only MITRE will be supporting this effort.

POC for MITRE:

Michael Leonard michael.leonard.11.ctr@us.af.mil Comm: 210-977-4329

MITRE: 210-675-9640

66. SW DevSecOps - it is not clear from DD254 provided as attachment E - is facility clearance required at the time of BPA response submission? if so at what level?

Minimum FCL requirements are Unclassified, maximum are TS/SCI. The determination of which classification level will be made at the call level. The “sample” DD254 was only a draft and will be provided at the call level.

67. All BPAs - Can teaming occur after an award on a BPA? Yes, however the teaming arrangement must be in place prior to issuance of a call RFQ.

mailto:michael.leonard.11.ctr@us.af.mil

68. For R-0135 Cloud Services please provide the labor categories that are expected.

This will be determined at the call level. However, all labor categories will be based off of the DevSecOps Services BPA.

69. Will you provide Labor category qualifications (yrs of experience and education requirements)

Labor category descriptions are written to ensure we do not restrict talent based on educational/experience requirements.

70. How will the Government ensure that Small Businesses with strong capabilities have a fair opportunity at winning a BPA if there are several Large Businesses with extensive experience and past performance that are also bidding? We understand there not set number of Large and Small Business awards, but, would the Government consider establishing a number of ratio of awards to Small Businesses to even the playing field?

The Government is committed to promoting Small Business participation. Small businesses with strong capabilities will have the same opportunity to receive a BPA as a large. Note that The Government reserves the right to award one (1) or more small business, small business team or joint venture if qualified and eligible for a BPA award. If the Government chooses to exercise this right and two or more small businesses/teams/joint ventures are determined qualified and eligible for a BPA, the Government will consider small disadvantaged business status in its selection for award.

72. Can government customers apply SBIR funding to purchase software off the BPA?

Yes, as long as the BPA is within scope of the SBIR effort. Note - 3400, 3600, and 3080 are the types of funding that can be used with the calls.

73. DevSecOps BPA: The majority of our DevSecOps portfolio has been under DHS. All these apps are internal applications (hosted on DHS's AWS enclave) that are only accessible from DHS networks with proper credentials.

Are you only evaluating public accessible work? or is there a method to evaluate work hosted in private government enclaves?

The Government will not be accepting classified proposals. The portfolio review is not limited to traditional past performance, intending to allow companies to propose with no DoD experience.

Please provide an unclassified version or write up, if possible or commercial experience.

74. The ITO states that NDAs must be submitted "within seven work days after the date of this RFQ". Please confirm that these are due within seven work days of proposal submission. If not, will the Government extend the due date for these NDAs through October 4, 2019?

NDAs shall be submitted with the quote.

75. For all BPAs: You indicated you would be revising the pricing templates. Since you also indicated that work may be performed at either Gov't or Contractor locations, will the pricing template include both On-site and Off-site rate tables?

Please note that Price has been removed from the

76. You did not answer the question concerning applications written for the Government, CI/CD pipelines written for the Government - we can not provide access to or source code for the proposal. How do you propose we provide you access?

Please provide an unclassified version or write up, if possible or commercial experience.

77. How many minimum code repository are required as

PP?

There is no minimum code repository required.

Contractors should determine the number of code repositories that will demonstrate their ability to meet the criteria listed in the ITO.

78. Do we need a secure facility as a requirement for responding?

Minimum FCL requirements are Unclassified, maximum are TS/SCI. The determination of which classification level will be made at the call level. The “sample” DD254 is only a draft.

79. Not sure you understand the question on source code and pipelines. We do not own the source code or pipelines. They are Government owned. If is a question of releasability outside the Government owner and not classification.

Please provide an unclassified version or write up, if possible or commercial experience.

80. All BPAs -Will each of these questions be recorded for each of us to review after this call?

Yes. The AMA transcript and Q&As have been posted to FBO.

81. If a small business graduates after onboarding, will they be considered a small business on the BPA or will they no longer be a small business?

They will be considered a small business.

82. Would you consider extending the deadline for submission, since revised pricing template and answer to questions won't occur until next Wednesday?

The Government’s schedule does not allow for an extension. However, please note that the quote due date has changed to 17 October 2019.

83. According to the provided documents titled Attachment D On_Off_Ramp_Procedures.pdf, Item (c) “ (c) Any Contractor that meets the eligibility requirements set forth in the new solicitation may submit a proposal in response to the solicitation; however, existing BPA Contractors may not hold more than one BPA at any time”

a. Does this mean that a company may submit a proposal for each of the BPAs (FA8307-19-R-0135, FA8307-19-R-0134, FA8307-19-R-0133), however only a single BPA will be awarded to the company under only one of the above mentioned BPAs?

b. Does this mean that if a company already has a BPA (i.e. NETCENTS 2 BPA) then that company will only be able to hold a single BPA and will either be denied award under the above mentioned BPA RFQs or will have to cancel the company’s current (i.e. NETCENTS 2) BPA to accept the award of one of the above mentioned BPAs?

c. Does this mean a company can submit a proposal for each of the BPAs and may only hold a single BPA under each of the FA8307-19-R-0135, FA8307-19-R-

0134, FA8307-19-R-0133?

a. A company may submit a quote for each BPA and may receive a BPA under each of the RFQs.

Companies can only hold one BPA per RFQ.

b. These are stand-alone BPAs, therefore no BPAs outside of these RFQs apply.

c. Yes

84. Since the Government indicated an amendment would be forthcoming, would the Government consider extending the deadline?

The Government’s schedule does not allow for an extension. However, please note that the quote due date has changed to 17 October 2019.

85. Would the Government allow rates to be discounted per call order?

Yes. Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

86. Can the Government please provide point of contacts for the Non-Disclosure Agreements?

Note - Only MITRE will be supporting this effort.

POC for MITRE:

Michael Leonard michael.leonard.11.ctr@us.af.mil Comm: 210-977-4329

MITRE: 210-675-9640

mailto:michael.leonard.11.ctr@us.af.mil

87. It is our experience that Agile and DevSecOps are very effective methods to keep pace with advancing technology, evolving user needs and deploying capabilities to the cloud in a rapid manner. These methods are most potent when the product line/chain, user needs and use cases are well defined. This approach delineates a range of functionality that informs the development pipeline regarding not only appropriate tools and capabilities, but standards, interfaces and operational expectations. It is our position that these activities are critical to successful valid development/deployment outcomes. As we reviewed each of the three BPAs, it isn’t clear which BPA covers this type of critical development. Is it in BPA one or spread across all three relevant to each type of work contained in each BPA?

Spread across all three relevant to each type of work contained in each BPA.

For better understanding of what these BPAs will support/enable, please read the “DoD Enterprise DevSecOps Reference Design” Document:

https://dodcio.defense.gov/Portals/0/Documents/Do D%20Enterprise%20DevSecOps%20Reference%20Des ign%20v1.0_Public%20Release.pdf?ver=2019-09-26- 115824-583

Multiple agile methodologies will be utilized, the method for individual requirements will be established at the call level.

The scope for DevSecOps BPA will be updated to reflect agile training for DevSecOps

88. What is the required software warranty requirement for the FFP elements identified in the pricing sheet?

Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

89. What is the required services workmanship warranty associated with any T&M management services in the pricing sheet?

Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.

90. Does the Government intend to provide any FAR/DFAR flow-down clauses or terms and conditions for which this BPA will be governed after award and can this information be provided now?

Information was provided with the RFQ under Attachment 6 – Provisions and Clauses. However, please note that all applicable provisions and clauses are included in the sample solicitation.

91. Does the Government anticipate service contract labor standards (SCLS) will be applicable to this order?

The Government does not anticipate that SCLS is applicable, however, this will be determined at the call level.

https://dodcio.defense.gov/Portals/0/Documents/DoD%20Enterprise%20DevSecOps%20Reference%20Design%20v1.0_Public%20Release.pdf?ver=2019-09-26-115824-583 https://dodcio.defense.gov/Portals/0/Documents/DoD%20Enterprise%20DevSecOps%20Reference%20Design%20v1.0_Public%20Release.pdf?ver=2019-09-26-115824-583 https://dodcio.defense.gov/Portals/0/Documents/DoD%20Enterprise%20DevSecOps%20Reference%20Design%20v1.0_Public%20Release.pdf?ver=2019-09-26-115824-583 https://dodcio.defense.gov/Portals/0/Documents/DoD%20Enterprise%20DevSecOps%20Reference%20Design%20v1.0_Public%20Release.pdf?ver=2019-09-26-115824-583

File details come from the government source that posted it.