Attachment_4_-Q&A_AMA_3Oct2019.pdf
PDF 296 KB Posted
- Attached to
- Software DevSecOps Services Blanket Purchase Agreement Federal contract opportunity
- Solicitation number
- fa8307-19-R-0133
About this file
AMA Q&As
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ASK ME ANYTHING (AMA) QUESTIONS / RESPONSES
FA8307-19-R-0133, 0134, & 0135
DevSecOps Initiative AMA Session 4 October 2019
QUESTIONS RESPONSES
1. Is it permissible for a contractor to submit a response as a prime and submit a response on another team as a subcontractor?
If yes, what happens if the vendor on both teams win?
Yes, however prime BPA holders can only hold one BPA per requirement. However, they can participate as a subcontractor/teaming partner.
If both vendors receive a BPA, they will need to determine their rules of engagement internally within their respective companies: i.e. mitigations/firewalls.
2. Unclassified source code is often marked FOUO, requiring we lock down source code repositories with at least username/password and SSL security. To allow evaluators access while still protecting source code, will the government please provide an email address to allow us to provide evaluators with access to the links provided in the Portfolio Review volume?
Please submit to the below email address:
AFLCMC.HNCP.LEVELUP@us.af.mil
Please do not submit any other quote information to this address. All quote submissions must be sent to the Contract Specialist and Contracting Officer identified in the RFQ.
3. Will the Government confirm that pricing information is NOT required to be provided as part of any of the 3 BPAs?
Confirmed. Please refer to Amendment 3 posted to FBO on 2 October 2019.
4. What volume is weighed heavier? Or are all weighted the same?
If referring to the evaluation criteria, technical is more important.
5. Will the Government confirm that OEM part numbers/SKUs are not required to be provided as part of any of the 3 BPAs?
Confirmed.
6. As a small business with Government contracts, none of our customers are currently working DevSecOps. At best, they are starting to discuss DevOps (but don't fully understand it). How can we best share and prove our skills in DevSecOps if we don't have any contracts requiring it so far?
It is at the discretion of the vendor to provide comparable technical content (from Government or non-Government work) describing how they can fulfill the technical requirements of this solicitation.
7. Can we submit a Data Assertion Rights Doc with our Portfolio?
Please note, we are not requesting data assertion rights as part of the Portfolio review, which has page limitations. There are opportunities to submit data assertion rights at the call level when the requirement is further defined.
8. How would the contracting office prefer exceptions to clauses be noted?
Exceptions to clauses can be sent with Volume I and will not count against the page limitations.
mailto:AFLCMC.HNCP.LEVELUP@us.af.mil
9. Will the government accept proposals from a team (Prime-Subcontractor) for the multiple CSPs, or does the Government ask for the Prime to be able to support multiple CSPs?
Government will accept proposals from a team.
However, the Government’s determination which offerors to enter into BPAs with will depend upon which offerors’ technical narratives and portfolios and/or source code repositories indicate they are most capable of satisfying the Government’s requirements. How those offerors chose to demonstrate that, whether as a single entity, a partnership, joint venture, or prime – subcontractor relationship is at the discretion of those offerors.
10. Unclassified source code is often marked FOUO, requiring we lock down source code repositories with at least username/password and SSL security. To allow evaluators access while still protecting source code, will the government please provide an email address to allow us to provide evaluators with access to the links provided in the Portfolio Review volume?
Please submit to the below email address:
AFLCMC.HNCP.LEVELUP@us.af.mil
Please do not submit any other quote information to this address. All quote submissions must be sent to the Contract Specialist and Contracting Officer identified in the RFQ.
11. Is there a page limit for Portfolio? Vol III? Yes. However, please note the page limit has been extended to 10 pages.
12. FA8307-19-R-0135: Please confirm that amendment 3 has removed the requirement for price proposal and discount level. And now, government is asking for 2pages of administrative and one page of management review as a response.
Yes, please refer to Amendment 3 posted to FBO on 2 October 2019.
13. Can we propose alternative tools in addition to those requested in the Licensing BPA
Yes, the Government will consider suggested alternative tools but has the discretion to choose.
The current License listing will be updated regularly as new technologies are identified.
14. I believe it’s been asked before...can we submit the response to the RFQ with teammates.
Yes. However, the Government’s determination which offerors to enter into BPAs with will depend upon which offerors’ technical narratives and portfolios and/or source code repositories indicate they are most capable of satisfying the Government’s requirements. How those offerors chose to demonstrate that, whether as a single entity, a partnership, joint venture, or prime – subcontractor relationship is at the discretion of those offerors.
15. What is the email id to which we can send github invites for the portfolio reviews?
Please submit to the below email address:
AFLCMC.HNCP.LEVELUP@us.af.mil
Please do not submit any other quote information to this address. All quote submissions must be sent to the Contract Specialist and Contracting Officer identified in the RFQ.
16. Can a respondent propose to only one area of focus on the BPA, e.g. could a contractor propose to only the cybersecurity team support?
Offerors who meet all the requirements of the BPA RFQ are eligible for a BPA. It is at the discretion of the vendor to submit a quote that best meets all the requirements of the solicitation.
17. Amendment 3 says Attachment 6 has been removed, but the Q&A says it is required. Please confirm if Attachment 6 needs to be submitted with the proposal
Attachment 6 was incorporated into the sample solicitations. Please note that Attachment 6 was incorporated into the 1449. While the 1449 does not need to be submitted with the quote, Offerors are required to submit all applicable provision/clauses IAW RFQ requirements.
18. Can the Government share an estimate of how many call orders it expects to release under this BPA annually? We do not have an estimate at this time. Please note this initiative is to support program offices across the DoD.
19. In the file “FA830719R0133_-_SW_DEVSECOPS.pdf”, are we required to complete and return the 32 page Section K (pg 97) with our proposal submission?
Yes, please note that Attachment 6 was incorporated into the 1449. While the 1449 does not need to be submitted with the quote, Offerors are required to submit all applicable provision/clauses IAW the RFQ requirements.
20. Will the Government allow graphics to be in Arial font, per industry standard?
Yes; embedded graphics are not considered written text.
21. Attachment 1, Section 1I(3) states, "Offerors shall provide a management overview that demonstrates partnerships with certified/authorized resellers and/or partner networks as it relates to this effort." Please can you clarify what types of partnerships this entails?
Partnerships entail a good working relationships with other vendors, such as being an authorized or certified reseller of the partners’ products.
22. Cloud Services BPA Question:
Regarding the submission of the Pricing Sheet as shown in Attachment 3, would a statement of a blanket discount approach that can be applied to all cloud services in each CSP’s service catalog be acceptable as a response in lieu of providing line item pricing reflecting the same discounts?
Price has been removed. Please refer to Amendment 3 posted to FBO on 2 October 2019.
23. Cloud Services BPA Question:
Is the Air Force seeking pricing for AWS cloud platform services in this BPA? Is the Air Force seeking pricing for Microsoft Azure cloud platform services?
Multiple cloud services are being requested, however, pricing is not being requested. Pricing will be requested at the call level. Refer to Amendment 3 regarding Price.
24. Cloud Services BPA Question:
Is the Air Force seeking pricing solely for government public cloud regions provided by AWS and Microsoft that support up to IL 5 workloads or are they also interested in having access to commercial cloud regions that do not provide this compliance for dev/test and other purposes?
Price has been removed. Please refer to Amendment 3 posted to FBO on 2 October 2019.
25. Cloud Services BPA Question:
Is there a forecast of the estimated annual cloud spend (years 1, 2, 3, 4, 5) under this BPA?
At this time there is not a projected forecast.
26. Cloud Services BPA Question:
Is there an estimated allocation of the projected annual spend by cloud provider (AWS vs. Microsoft Azure)?
At this time there is not an estimated allocation for cloud services
27. Cloud Services BPA Question:
Is the Air Force seeking pricing for network connectivity to public clouds in this BPA?
Price has been removed. Please refer to Amendment 3 posted to FBO on 2 October 2019.
28. Cloud Services BPA Question:
Is the Air Force seeking pricing for cloud service provider support plans in this BPA?
Price has been removed. Please refer to Amendment 3 posted to FBO on 2 October 2019.
29. Does the Government have a preference (or different weights) for past performances vs source code repositories in the Portfolio?
Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another, and there is no preference for different variations in the portfolio review.
30. Will companies be required to certify as small at the task order level or the BPA level? That is to say if a company is onboarded as small, but graduates to large, will they be able to compete as small for the life of the
BPA?
If a company graduates from the small business program, they should coordinate with the Small Business Administration to understand what “graduating” entails. As a reminder, these BPA’s are open to both Small and Large business.
31. Is it possible for a single contractor to receive a Cloud, Services and Tool BPA?
Yes
32. Is it permissible for a contractor to submit a response as a prime and submit a response on another team as a subcontractor for the same BPA?
Yes
33. Will you be posting Q&A from this session? Yes
34. Cloud Service BPA Question:
Attachment 1, Section 1I(1) states, "Offerors shall provide a cover letter with their quote to include current points of contact (Contract Manager and Program Manager) that is authorized to obligate your firm, mailing address, current e-mail address and phone number." Are the POCs and contact information necessary for all members of Offeror's team or only the Prime Contractor?
Offerors shall submit contact information for the prime with whoever has authority to submit/sign on behalf of the company.
35. The description of the amendment on 10/2 states "The following are also being provided: Solicitation - This is not a formal solicitation". Please confirm whether these 3 BPAs are issued as Requests for Proposals or Requests for Information.
The BPAs are being issued as Request for Quotes –
(RFQ).
36. Cloud Service BPA Question:
For selecting the Cloud Service Providers (CSP); IS Government interested to receive a response for the CSPs that are certified at only DoD IL2, or IL2 and IL4? Or, is the government only interested in CSPs that are certified at the DoD Impact Level 5 (IL5)?
Multiple Impact Levels will be considered for this acquisition.
37. When referencing Volume III: Portfolio Review on Page 4 of Attachment 1, the solicitation states, "Offerors shall provide a portfolio and/or source code repository with links to demonstrate a technical understanding of DevSecOps engineering, software development, cybersecurity and/or IT support and operations. Offerors may provide information for several Government or commercial clients that they consider most relevant in demonstrating their ability to perform the proposed effort." Is there a minimum or maximum number of projects that Offerors should submit to meet this requirement?
Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another, and there is no preference for different variations in the portfolio review. It is at the discretion of the vendor to submit a proposal that best meets the requirements of the solicitation, and to decide what should be submitted to best highlight the company’s skills.
38. Attachment 1, Instructions to Offerors: Page 8 paragraph 3 states, "Although past performance may not be used as an evaluation factor, the information obtained from other sources available to the Government such as the Past Performance Information Retrieval System (PPIRS) will be used as part of the responsibility determination made IAW FAR 9.104-1." However, we are required to include a Portfolio Review volumes that highlights past work through code repositories. Is Factor 2 not considered past performance? If not, what format should our Portfolio Review volume take?
Past performance is not an evaluation factor and Factor 2 is not considered traditional past performance. The Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
39. Will demonstrated ability to support TS/SCI affect evaluation?
Ability to support TS/SCI is not an evaluation factor;
however, it will affect a company’s ability to propose at the call level if such work is required to be at the TS/SCI level.
40. It's not clear to me what the Govt. is looking for in the proposal for a "source code repository with links." Could you please explain exactly what this means?
Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
41. BPA#2 - SW Pipeline - how did the government determine with solutions were included as part of the bid submission? What will the process be for new technology to be added? Are there hard requirements (e.g. ATO) in order for a SW solution to be considered and added?
New technology will be evaluated at call level. Yes, there are requirements that the Government will determine at the call level.
42. Simplified acquisition threshold: Does that mean all task orders will be $7 million and below?
No
43. Where is the sample proposal just mentioned housed? There was no mention of a sample proposal. There was a comment that a sample solicitation was posted to FBO via Amendment 3. Also note, the slides and video content will be posted on FedBizOps.
44. the slide is not advancing, is that by design? Slides were controlled by the speaker on zoom. All slides will be posted on FedBizOps.
45. Attachment 5, titled "BPA_Guide_SW_DevSecOps" references the following attachments:
Attachment A: Scope of Work
Attachment B: Price List
Attachment C: Ordering Procedures
Attachment D: On-Ramping & Off-Ramping Procedures
Attachment E: Sample DD Form 254
Attachment F: Key Personnel
Attachment G Labor Categories
While the provided Attachments E F, and G correspond to those stated above, no attachments A, B, or C were provided. Can the Government confirm whether the above-mentioned Attachment A corresponds to the provided "Attachment_2_-_SOO_SW_DevSecOps" and whether the above-mentioned Attachment B corresponds to the provided "Attachment_3_-_Pricing_Sheet"? Can the Government also clarify where "Attachment C:
Ordering Procedures" can be found?
Please refer to Amendment 3 posted to FBO on 2 October 2019.
46. For the DevSecOps BPA. Will you be requesting pricing after the proposals are submitted at a later time?
Yes. pricing will be requested at the call level, for each call.
47. The answers to the last LevelUP Q&A contained this exchange: "112. Q: Based on RFQ requirements, please confirm that during the BPA proposal evaluations, the Government is evaluating prime contractor capabilities only. A: Confirmed." There is no reference to this limitation in the RFQ. Please update the RFQ to reflect the limitation on using subcontractor capabilities.
The Government’s determination which offerors to enter into BPAs with will depend upon which offerors’ technical narratives and portfolios and/or source code repositories indicate they are most capable of satisfying the Government’s requirements.
How those offerors chose to demonstrate that, whether as a single entity, a partnership, joint venture, or prime – subcontractor relationship is at the discretion of those offerors.
48. The answers to the last LevelUP Q&A contained this exchange: "112. Q: Based on RFQ requirements, please confirm that during the BPA proposal evaluations, the Government is evaluating prime contractor capabilities only. A: Confirmed." What capabilities are being referenced here, and does this refer to the entire response or just one section?
The Government’s determination which offerors to enter into BPAs with will depend upon which offerors’ technical narratives and portfolios and/or source code repositories indicate they are most capable of satisfying the Government’s requirements.
How those offerors chose to demonstrate that, whether as a single entity, a partnership, joint venture, or prime – subcontractor relationship is at the discretion of those offerors.
Capabilities being evaluated are those listed in the
ITO.
49. FA8307-19-R-0133: Is there a min or max on projects/contracts that must be submitted for the portfolio evaluation?
There is no min or max. The Offeror has discretion to submit what is necessary to accurately depict technical understanding.
50. Are offerors required to name key or representative personnel at the BPA level, or is this only done at the order level?
This will be at the call level.
51. Cloud Services: shall we submit all our questions asked here via email? if so, when is the deadline for question submission?
No. A transcript of the AMA was provided. All questions and answers are being provided. Reminder
– The Government is not accepting any additional questions.
52. Is it possible to share the slides after the conf-call?
thanks
Slides will be posted to FBO. Please note that the Government is clarifying slide 7 – Example 1 BPA Call (Under SAT). Example 1 BPA Call should reflect under (Under $7M). Also, price lists will not be reviewed prior to issuance of a call RFQ.
53. Will the Government consider pay-as-you-go software as a service (SaaS)for DevSecOps or are there specific licensed software tools the Government wishes to run on cloud infrastructure?
At this time, the Government is not seeking SaaS.
54. Cloud Service question: Since IL 6 cannot be purchased through authorized reseller, is AF allowing the cloud service provider such as AWS and Azure to bid and receive a BPA award?
These BPAs are open to all small and large businesses who can fulfill the requirements of the RFQs.
55. Question on Q&A response. The response to question 112 indicated that only prime offeror capabilities are evaluated. How are the capabilities of teams evaluated or are team capabilities not considered?
The Government’s determination which offerors to enter into BPAs with will depend upon which offerors’ technical narratives and portfolios and/or source code repositories indicate they are most capable of satisfying the Government’s requirements.
How those offerors chose to demonstrate that, whether as a single entity, a partnership, joint venture, or prime – subcontractor relationship is at the discretion of those offerors.
56. The Volume III should be in PDF format (the Q&A, No, please submit project details and experience in a PDF. ) with links to different resources?
The portfolio review can be in PDF or Microsoft Office format. The information can be conveyed via numerous methods including but not limited to include source code repositories, links to demonstrations, and screenshots.
57. Can you elaborate on what types of portfolio or repository software you would like to review? Is your preference to evaluate general software applications or only software and configuration related directly to DevSecOps pipelines?
Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
58. Since contractors won't be responsible for managing the end to end solution for the CI/CD pipeline, how is LevelUP currently managing their pipeline (ie what software is currently in use) and where are you currently storing your code?
Gitlab CI or Jenkins and it is all done declaratively.
59. Is the Example 1 consistent with Q&A that was provided in mod 3? I thought calls would go to all BPAs (unless set aside) not 3 companies as listed on the slide.
Please note that the Government is clarifying slide 7 – Calls will vary. Calls under the thresholds identified in the FAR Part 13 Simplified Acquisition Procedures (SAP) will be competed amongst a minimum of 3 vendors up to $7M; however, the Government reserves the right to compete amongst all vendors at its discretion. Over the SAP thresholds ($7M) will be competed against all BPA holders. Small Business set-asides can also be done at the call level. This response supersedes the response previously provided with Amendment 3.
60. How many Small business set aside awards will be given?
There is not a set number of small business set asides. This will be determined be determined at the call level. This acquisition is open to both small and large business. Note that the Government reserves the right to award one (1) or more small business, small business team or joint venture if qualified and eligible for a BPA award. If the Government chooses to exercise this right and two or more small businesses/teams/joint ventures are determined qualified and eligible for a BPA, the Government will consider small disadvantaged business status in its selection for award.
61. How will the government review the Pricing Lists from all 15 BPA vendors before issuing the Call RFQ if we are no longer submitting pricing as part of the BPA proposal?
Pricing will be evaluated at the call level. The call RFQ will outline the pricing requirements and how price will be evaluated.
62. Will there be a percentage of BPA calls set-aside to smalls?
Currently, there is not a set number of small business set asides. This will be determined be determined at the call level.
63. Cloud Services: please confirm that for this BPA there is no Sample task order provided.
Confirmed, there are no sample “orders” provided.
64. DevSecOps question: We have our own DevSecOps pipeline, and we want to onboard your pipeline as a stage/production by bringing in our package/containers (with licenses). Is this possible?
Yes, this is possible. They can bring containers and licensing on, but it must go through the container hardening process.
65. Volume IV/Factor 3: price is now removed...can you please confirm that only 10 pages now accepted across Volumes 1 (Administrative), Volume II (technical capability) and Volume III (Portfolio Review)?
All page limits remain the same except for the portfolio review which has been increased to 10 pages.
66. Is it the expectation that large contractors bid on all call orders except those that are designated as Small Business
Calls will vary. Calls under the thresholds identified in the FAR Part 13 Simplified Acquisition Procedures (SAP) will be competed amongst a minimum of 3 vendors up to $7M; however, the Government reserves the right to compete amongst all vendors at its discretion. Over the SAP thresholds ($7M) will be competed against all BPA holders. Small Business set-asides can also be done at the call level.
67. Under Solicitation Number: FA8307-19-R-0134:
DevSecOps Tools, Pipeline & Platform Integration & Licensing Blanket Purchase Agreement – Should DevSecOps security solutions be considered for inclusion under this BPA – Including quotes for software that secures workloads and repositories
The list of licenses is a “living document” that will be continuously updated as new technologies emerge, the Government reserves the right to “add-to or take-away” from this list at their discretion.
68. The response to question 90 stated the rates are required for various sites. Please confirm whether pricing is required or not in the RFQ response.
Confirming. Price was removed with Amendment 3.
Question 90 should have reflected the following:
Please note that Price has been removed from the evaluation criteria. Determination of price fair and reasonableness will be determined at the call level.
69. for the Tools BPA pricing Attachment_3_- _Pipeline_Pricing_Sheet - what is the unit we are required for pricing FFP software licenses
Pricing was removed with Amendment 3.
70. Since Air Force is soliciting 3 separate BPAs, is it possible for the answers to all questions be separated for the 3 BPAs?
Questions and answers received prior to the 27 September 2019 deadline were separated for each of the BPA RFQs. However, the AMA sessions are a consolidated list of question and answers.
71. Can awardees name authorized agents to their contract?
Authorized agents must be able to obligate the firm they are representing.
72. Should the volumes be submitted as separate documents or one consolidated document?
Please submit volumes in separate PDFs.
73. Would the Government consider Client POCs to request Source Code Repository access in lieu of Source Code Repository Links since these are bound by client access approvals?
If source code repositories are not available to be provided directly to the Government as part of the proposal, there are several other methods to provide insight into the technical capabilities, such as links to demonstrations, screenshots of web applications, and detailed technical write-ups.
74. How will the Government evaluate/measure “strong technical understanding” in comparison to “good technical understanding” in Factor 2?
Quotes will be subjectively and consistently evaluated by the technical evaluation team IAW the instructions to Offerors.
75. What is meant by “validate response from the proposal” from the comment just mentioned?
The event is a continuation of the evaluation for DevSecOps Services BPA. Companies will need to orally demonstrate/validate their technical capability and portfolio review based on the evaluation criteria stated in the RFQ.
76. Our portfolio is classified. Is that acceptable? Also, our code falls in that category as well.
The Government will not be accepting classified proposals. The portfolio review is not limited to traditional past performance, intending to allow companies to propose with no DoD experience.
Please provide an unclassified version or write up, if possible or commercial experience.
77. Thank you. would it be helpful to note them in spreadsheet form? and do you require a rationale for each?
This question is incomplete. Please refer to all questions and answers provided to date.
78. For the DecSecOps BPA. Recommend you add labor categories for program management, project management, quality assurance, etc - so that if customers have large modernization efforts - they can get a company leadership team to manage the call and not just technical talent.
The labor categories are not all inclusive. The Government reserves the right to update as needed, throughout the life of the BPA. Any changes will be incorporated via modification to the BPA.
79. Is there going to be any considerations for HUBZONE companies?
There is not a set number of small business set asides. This will be determined be determined at the call level. This acquisition is open to both small and large business. Note that the Government reserves the right to award one (1) or more small business, small business team or joint venture if qualified and eligible for a BPA award. If the Government chooses to exercise this right and two or more small businesses/teams/joint ventures are determined qualified and eligible for a BPA, the Government will consider small disadvantaged business status in its selection for award.
80. For the Tools BPA, with the removal of the price section - does a respondent simply list the technologies/products they plan to support? Is a letter of authorization required as part of the response?
The tools included in the updated list are for informational purposes. Specific tools will be identified at the call level at which time a LoA will be coordinated/requested. Note only authorized Government resellers/agents will be eligible for a
BPA.
81. What is the government's intent for the source code repositories if we provide links to those? Are you intending to run the software, are you systematically evaluating the source code or something else?
Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
82. CLoud BPAQuestion 14 (Oct 2 Q&A) - the answer is "Evaluation criteria has been updated."
Criteria will be updated and provided via amendment.
83. In the ITO requirements, does co-location refer to positioning of our staff in Government facilities?”
Performance locations will be determined at the call level and may be at a Government facility or a contractor facility, as determined in each call. The RFQ requests the offeror to demonstrate the ability to co-locate in either Government and/or contractor facilities.
84. How will the team mates portfolios be evaluated as part of the bid?
The Government’s determination which offerors to enter into BPAs with will depend upon which offerors’ technical narratives and portfolios and/or source code repositories indicate they are most capable of satisfying the Government’s requirements.
How those offerors chose to demonstrate that, whether as a single entity, a partnership, joint
85. For the Event Day for the DevSecOps BPA, Is the proposal "justification" one-on-one with the Government?
Yes, the continuation of the technical evaluation will be one-on-one with a designated Government evaluation team.
86. Where is that sample CLIN structure? Included with the 1449.
87. Will the Government allow an 11x17 graphic be counted as a single page?
The use of 11 X 17 fold out should be limited to the items described in the ITO and will not be counted against the page count.
88. If we have existing integrated pipeline solutions will the government consider those if they have already achieved FedRAMP ready status?
No
89. What "proof" does the government expect companies to demonstrate at the onboarding event that they can do the proposed work?
The event is a continuation of the evaluation for DevSecOps Services BPA. Companies will need to orally demonstrate/validate their technical capability and portfolio review based on the evaluation criteria stated in the BPA.
90. Please clarify past performance requirements Past Performance is not an evaluation factor. The Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another. A portfolio provides an in-depth look at your business and prior projects. This portfolio gives the Government an idea of your company’s strengths, the experience of your staff and what working with you looks like. The visuals and text you include are key to the content and can put you ahead of your competition.
91. Cloud Services: please confirm that the sample pricing is the file called FA830719R0135? And we do not need to submit it as part of our submissions?
Pricing was removed with Amendment 3. The sample solicitation was provided to give Offerors insight to how an award will be structured to include the CLIN structure, provisions and clauses, attachments. While the 1449 does not need to be submitted with the quote, Offerors are required to submit all applicable provision/clauses requirements.
92. Will the LevelUP staff be facilitating the Business Process Reengineering (BPR), training, and cultural shift for current Government programs and staffs? This shift has been the primary challenge to the vendors with programs that are identified as Agile or DevSecOps?
These BPAs are not for enablement. The SOOs outline the scope of work required. With that said, the DevSecOps BPA can be used to acquire talent to support training.
93. Can you clarify your definition of portfolio? Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another. A portfolio provides an in-depth look at your business and prior projects. This portfolio gives the Government an idea of your company’s strengths, the experience of your staff and what working with you looks like. The visuals and text you include are key to the content and can put you ahead of your competition.
94. Will the government consider the capabilities of a subcontractor in their evaluation of the Technical and Portfolio sections, or will only the capabilities of the prime be considered in the evaluation.
The Government’s determination which offerors to enter into BPAs with will depend upon which offerors’ technical narratives and portfolios and/or source code repositories indicate they are most capable of satisfying the Government’s requirements.
How those offerors chose to demonstrate that, whether as a single entity, a partnership, joint
95. Since price is no longer being requested for all BPAs, is the Pricing Pipeline Attachment 3 Document no longer relevant?
Correct, Price is no longer a part of the evaluation.
Therefore, Attachment 3 does not need to be submitted with your quote.
96. So to clarify the Pricing volumes are no longer required for any of the 3 BPAs? just the administrative, management and technical as currently listed?
Correct
97. When will the government provide full answers to all questions asked in this meeting?
4 October 2019
98. If a company for the Licensing BPA has not yet completed the process to get into the USAF's Container CI/CD pipeline but will be in NOV 2019, can we still submit to the Licensing BPA due in OCT 2019?
There is no requirement of being in the “USAF’s Container CI/CD pipeline”.
99. Will the Government allow Arial Narrow for Tables and graphics?
Please refer to the ITO regarding submission requirements.
100. So to Prime this effort I can submit with a partner for a complete proposal.
It is the Offerors discretion on how they intend to submit their quotes. Offerors can team or submit alone.
101. BPA#1 - Services - do you have to be able to cover every LCAT identified in the requirement in order to be considered - or can you simply cover a subset and still be considered for award?
Offerors shall submit quotes IAW the RFQ. Companies must determine whether or not they can fulfill the requirements of the RFQ. BPAs will only be issued to those vendors who can fulfill the requirement as stated in the RFQ.
102. For the DevSecOps BPA. Recommend you have offerors include their facility clearance level as part of the Vol 2 Technical capability. Otherwise you risk awarding all 15 awards to companies with no facility clearances - and therefore will have a number of calls - to which none of the BPA awarded offers may propose.
Noted. The Government understands the facility clearance requirements.
103. What licenses are specifically required to run in your pipeline. For example, Fortify, Twistlock, SonarQube, Concourse, Anchore, etc. Also is there a requirement for specific OSs such as redhat? Is vendor responsible for acquiring these licenses?
The list of licenses is a “living document” that will be continuously updated as new technologies emerge, the Government reserves the right to “add-to or take-away” from this list at their discretion. Licenses will be determined at the call level.
104. Are remote workers allowed? or only in office workers?
Location of work will be determined at the call level.
105.
Cloud BPA
a. Question 14 (Oct 2 Q&A), the answer was "Evaluation criteria has been updated."
b. In reviewing the new criteria, it still does not specify that a CSP can directly offer their own product without the use of a partner. It still implies that the offeror MUST be associated in a partner channel. How can a FedRAMP CSP offer their own IaaS/PaaS product and be properly evaluated.
c. There are several FedRAMP CSP's that offer directly and do not have a partner network nor participate in offering competing products
a. Criteria will be updated to not exclude CSPs.
b. CSPs are not excluded.
c. Noted
106. Is CMMI-DEV desirable Not requested.
107. How would we submit Patented technology (source code, design docs) for the portfolio and still protect our
IP?
An Offerors’s quote is marked as proprietary and will be treated as such by the evaluation team.
108. I know you took out pricing but would you like an overview of vendors cloud capabilities available in IL5 and
IL6?
Not required
109. How do you plan on protecting source code that is made available via Github?
An Offerors’s quote is marked as proprietary and will be treated as such by the evaluation team.
110. Please define "Portfolio". Is it past performance or is it example code?
Past performance is not an evaluation factor. The Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
111. You stated clearance will be determined at the call order level does that mean you will sponsor companies who don't have an FCL?
Yes
112. Read your slide that said call orders over the SAT will be competed. Since these BPAs are under FAR Part 13, will there be any ceiling established for each call order (not referring to the $95M ceiling at the BPA level)
There is not a ceiling limit for this BPA. The dollar limit on individual calls will be in accordance with thresholds identified in FAR Part 13 - Simplified Acquisition Procedures and/or any approved agency supplements or deviations to same.
113. Where will the transcript be located? The recorded AMA has been uploaded to FedBizOps.
114. My company is already registered in SAM. Do we need to register again specifically for this opportunity?
No, however, ensure your SAM registration is still active.
115. Cloud Service: should the bidding company be part of Air Force CI/CD list?
No, this is not a requirement.
116. In the previous Q&A they said they would evaluate that your code does what it is supposed to do. How is this evaluated without the Government having a full understanding of requirements and test cases.
Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
117. Can we submit source code for internal projects we have worked on?
Yes. Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
118. Will new mentor / protege partnerships be considered at the call level?
Yes, however, mentor/protégé partnerships must be made prior to any response to a call RFQ.
Joint ventures must be registered and active in the System for Award Management (SAM) by 1 November 2019. Joint ventures can be formed when two or more companies join together to act as a potential prime contractor.
Forming a separate entity is different than a traditional prime contractor/subcontractor arrangement. Prime contractors must be registered in SAM no later than 1 November 19 to be eligible for award.
119. Please confirm that a narrative describing our support on current and past development contracts will meet the requirements of the portfolio review
Confirmed.
120. Based on a question posted in this thread - has the requirement for Past Performance changed? Previously, past performance citations were not being requested -only technical write ups based on the page limitations provided.
Requirement has not changed. Past performance is not an evaluation factor. Traditional past performance is not being requested. Instead, the Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
121. Is the focus of BPA2 primarily centered around procurement of licenses and licensed tools or is integration of these tools into the DevSecOps pipelines also a significant portion of this BPA?
Licenses and tools and the support needed to manage.
122. Any naming convention to the GitHub repository that we need to follow?\
No
123. Does the source code have to fit within the 3-page limit for Vol. III?
Page limit has been extended to 10 pages. Links may be used to access source code versus content.
124. For Cloud Services is it required to offer both IL5 and/or IL6?
Multiple Impact Levels are required.
125. For the DevSecOps BPA. What is the SAT level to which calls will be competed with 3 holders and the level for all holders.
Calls will vary. Calls under the thresholds identified in the FAR Part 13 Simplified Acquisition Procedures (SAP) will be competed amongst a minimum of 3 vendors up to $7M; however, the Government reserves the right to compete amongst all vendors at its discretion. Over the SAP thresholds ($7M) will be competed against all BPA holders. Small Business set-asides can also be done at the call level.
126. How is the program funded? NIP/MIP? AFPOM To be determine as requirements are identified.
However, multiple sources of funding will be used.
127. Which BPA could potentially impact the Air Force the most and why?
All BPAs equally impact the Air Force.
128. Should all proposals attempt to be comprehensive in nature and attempt to cover as many of the statement of objectives as possible or will more focused proposals that target specific items in the statement of objectives be considered at value.
It is at the discretion of the Offeror to provide comparable technical content (from Government or non-Government work) describing how they can fulfill the technical requirements of this solicitation.
129. In regards to the Cloud Services BPA, Are you looking for just colocation hardware and cloud utilization coverage or are you also looking for all services required to establish a secure access point that involves the development of a security stack, i.e labor?
Yes, but at this time, the resources will be in the cloud, the on-premise will be for securing and sustaining end-points
130. What are the links for the portfolio supposed to link to and how does that work within a PDF document?
If links are provided, they are to access source code repositories, demos, etc and can be provided as a hyperlink in the PDF.
131. If your submission is based on a collection of partners supporting the requirements, if an invitation is provided, will the government accept a collaborative presentation for the 13 November event?
Yes
132. To confirm BPA 1 is more around bid for talent...BPA2 is around access to licensing. We'd need two submissions or can we combine?
Separate submissions for each BPA are required.
133. Is the expectation that the offeror should have a fully executed NDA prior to RFP submission with the A&AS contractor?
Fully executed NDAs must be completed with MITRE and submitted with your quote.
134. You are looking for rates below the SAT to determine 3 bidders to ask for quotes, but if we aren't submitting pricing then what rates are you looking at? Rates from our GSA Schedule?
Please note that the Government is clarifying slide 7 – Example 1 BPA Call (Under SAT). Example 1 BPA Call should reflect under (Under $7M). Also, price lists will not be reviewed prior to issuance of a call RFQ.
135.
1. Is the Air Force seeking pricing for AWS cloud platform services in this BPA? Is the Air Force seeking pricing for Microsoft Azure cloud platform services?
2. Is the Air Force seeking pricing solely for government public cloud regions provided by AWS and Microsoft that support up to IL 5 workloads or are they also interested in having access to commercial cloud regions that do not provide this compliance for dev/test and other purposes?
3.Is there a forecast of the estimated annual cloud spend (years 1, 2, 3, 4, 5) under this BPA?
4. Is there an estimated allocation of the projected annual spend by cloud provider (AWS vs. Microsoft Azure)?
5. Is the Air Force seeking pricing for network connectivity to public clouds in this BPA?
6. Is the Air Force seeking pricing for cloud service provider support plans in this BPA?
7. Regarding the submission of the Pricing Sheet as shown in Attachment 3, would a statement of a blanket discount approach that can be applied to all cloud services in each CSP’s service cat
1. Price was removed with Amendment 3.
2. Price was removed with Amendment 3.
3. There is currently no forecast of estimated annual cloud spend.
4. There is currently no allocation of the projected annual spend.
5. Price was removed with Amendment 3.
6. Price was removed with Amendment 3.
7. Price was removed with Amendment 3.
136. I thought that facility security clearance is only confidential, secret and top secret
Your comment has been noted. Note security requirements will be identified at the call level.
137. Is there a page limit on Portfolio submission? Yes, it has been updated to 10 pages.
138. SCI applies to personnel Your comment has been noted. Note security requirements will be identified at the call level.
139. Ref Technically Capable... and past performance ... is this list of past and current support?... do you need names and scope of support...
Past performance is not an evaluation criteria. The Government is evaluating company’s technical understanding of DevSecOps, software development, cybersecurity, and/or IT support and operations. That technical understanding can be conveyed via various methods to include source code repositories, links to demonstrations, screenshots of web applications, and detailed technical write-ups, all of which can determine technical understanding. These various methods are not weighted against one another.
140. What was due 10.17 in the last slide? Quotes are due by 1200 CDT on 17 October 2019.
141. Will waivers be required to use the DevSecOps BPA for software licenses over the mandatory use DoD ESI
BPA?
The Government will not be seeking a waiver for those items currently offered via ESI. ESI is a mandatory vehicle and items available on ESI will not be procured via the BPA.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.