FINAL RFQ 36C10B24Q0418.docx

DOCX document 259 KB Posted

Attached to
7A21--PI Planning Federal contract opportunity
Solicitation number
36C10B24Q0418
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This is a request for quotation (RFQ) issued by the Department of Veterans Affairs (VA) Technology Acquisition Center for Scaled Agile, Inc.'s piplanning.io or equivalent planning interval (PI) planning software and associated technical support services. The VA is seeking 150 licenses of the PI planning software and related installation, configuration, communications, and technical support services. This is a small business set-aside under NAICS code 541511, with a period of performance of 12 months and an optional 12-month extension. Key details include a required response by July 2, 2024 at 4:00 PM EDT, a fixed-price payment structure, and specific performance requirements such as providing a project management plan, reporting, kickoff meeting, change management, technical documentation, and optional tasks for transition support, cybersecurity assessments, and additional licensing. The VA has identified a Contracting Officer, Contract Specialist, and Contracting Officer's Representative as points of contact.

View the file

Other files for this federal contract opportunity

Other files attached to 7A21--PI Planning, newest first.
File Type Posted
36C10B24Q0418_4.docx DOCX document
Continuation Page 2.docx DOCX document
Continuation Page.docx DOCX document
36C10B24Q0418_3.docx DOCX document
36C10B24Q0418_1.docx DOCX document
Redacted JA.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C10B24Q0418

1. REQUISITION NO.

2. CONTRACT NO.

3. AWARD/EFFECTIVE DATE

4. ORDER NO.

5. SOLICITATION NUMBER

6. SOLICITATION ISSUE DATE

a. NAME

b. TELEPHONE NO. (No Collect Calls)

8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY

CODE

10. THIS ACQUISITION IS

UNRESTRICTED OR

SET ASIDE:

% FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ

IFB

RFP

15. DELIVER TO

CODE

16. ADMINISTERED BY

CODE

17a. CONTRACTOR/OFFEROR

CODE

FACILITY CODE

18a. PAYMENT WILL BE MADE BY

CODE

TELEPHONE NO.

UEI:

EFT:

PHONE:

FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19.

20.

21.

22.

23.

24.

ITEM NO.

SCHEDULE OF SUPPLIES/SERVICES

QUANTITY

UNIT

UNIT PRICE

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________

29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

(REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

06-26-2024 Jessica Martin 848-377-5336 07-02-2024

4:00 PM

EDT

Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

X

Y 541511 $34 Million

N/A

See Delivery Schedule See Delivery Schedule See Delivery Schedule

Eatontown NJ 07724

Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

Department of Veterans Affairs Technology Acquisition Center Financial Services Center PO Box 149971 Austin TX 78714-8971

See CONTINUATION Page This procurement is a Small Business Set-Aside The period of performance shall consist of:

07/12/24-07/11/2025 w/ one 12-month option period

Points of Contacts:

CO: Matthew Newell; Matthew.Newell@va.gov CS: Jessica Martin; Jessica.Martin10@va.gov

See CONTINUATION Page

Matthew Newell

Page 1 of

Table of Contents

SECTION B - CONTINUATION OF SF 1449 BLOCKS4
B.1 GOVERNING LAW4
B.2 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:5
B.3 CONTRACT ADMINISTRATION DATA8
B.3 PRICE SCHEDULE9
B.4 PERFORMANCE WORK STATEMENT13
1.0BACKGROUND14
2.0APPLICABLE DOCUMENTS14
3.0SCOPE OF WORK17
3.1ORDER TYPE18
4.0PERFORMANCE DETAILS18
4.1PERFORMANCE PERIOD18
4.2PLACE OF PERFORMANCE18
4.3TRAVEL OR SPECIAL REQUIREMENTS18
4.4GOVERNMENT FURNISHED PROPERTY18
4.5SECURITY AND PRIVACY18
4.5.1POSITION/TASK RISK DESIGNATION LEVEL(S)19
5.0SPECIFIC TASKS AND DELIVERABLES19
5.1PROJECT MANAGEMENT20
5.1.1CONTRACTOR PROJECT MANAGEMENT PLAN20
5.1.2REPORTING REQUIREMENTS20
5.1.3TECHNICAL KICKOFF MEETING21
5.1.4CHANGE ENABLEMENT, RELEASE AND MANAGEMENT21
5.2APPLICATION SUPPORT22
5.2.1LICENSES23
5.3TECHNICAL DOCUMENTATION24
5.4TRANSITION SUPPORT (OPTIONAL TASK ONE)24
5.5CYBER SECURITY (OPTIONAL TASK TWO)25
5.5.1SECURITY ASSESSMENT AND ACCREDITATION25
5.6Licensing (Optional Task Three)29
5.6.1150 Licenses29
5.6.2150 Licenses29
6.0GENERAL REQUIREMENTS29
6.1PERFORMANCE METRICS29
6.1.1VA TECHNICAL REFERENCE MODEL30
6.1.2FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)30
6.1.3INTERNET PROTOCOL VERSION 6 (IPV6)32
6.1.4TRUSTED INTERNET CONNECTION (TIC)32
6.1.5STANDARD COMPUTER CONFIGURATION32
6.1.6VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT (PLM)33
6.1.7PROCESS ASSET LIBRARY (PAL)33
6.1.8AUTHORITATIVE DATA SOURCES33
6.1.9SOCIAL SECURITY NUMBER (SSN) REDUCTION34
6.2SECTION 508 – INFORMATION AND COMMUNICATION TECHNOLOGY (ICT) STANDARDS35
6.2.1COMPATIBILITY WITH ASSISTIVE TECHNOLOGY36
6.2.2ACCEPTANCE AND ACCEPTANCE TESTING36
SECTION C - CONTRACT CLAUSES37
C.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)37
C.6 52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION SYSTEMS (NOV 2021)38
C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (FEB 2024)40
C.3 52.217-7 OPTION FOR INCREASED QUANTITY—SEPARATELY PRICED LINE ITEM (MAR 1989)49
C.4 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)49
C.5 852.219-75 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING - CERTIFICATE OF COMPLIANCE FOR SERVICES AND CONSTRUCTION50
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS52
SECTION E - SOLICITATION PROVISIONS53
E.8 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)53
E.2 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)54
E.4 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (FEB 2024)57
E.5 52.216-1 TYPE OF CONTRACT (APR 1984)77
E.6 52.233-2 SERVICE OF PROTEST (SEP 2006)77
E.6 PROPOSAL SUBMISSION INSTRUCTIONS77
E.7 BASIS FOR AWARD79

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 GOVERNING LAW

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this Clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this Clause shall prevail. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ). 28 U.S.C. § 516. At the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be affected by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.2 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:

1. Definitions.

1. Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”

1. Licensor. The term “licensor” shall mean the contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “contractor” is the party identified in Block 17a on the SF1449. If the contractor is a reseller and not the Licensor, the contractor remains responsible for performance under this order.

1. Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

1. Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.

1. Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

1. Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

1. Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

1. Software License

1. Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software

1. The Government may use the software in a networked environment.

1. Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).

1. All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.

1. Software Maintenance and Technical Support

(a)If the Government desires to continue software maintenance and support beyond the period of performance identified in this contract or order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received the contractor is neither authorized nor permitted to renew any of the previously furnished services.
(b)The contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.
(c)Any telephone support provided by contractor shall be at no additional cost.
(d)The contractor shall provide all maintenance services in a timely manner in accordance with the contractor’s customary practice or as defined in the Performance Work Statement/Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the contractor (e.g., www.ppirs.gov).
(e)If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

1. Disabling Software Code. The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

1. Manuals and Publications. Upon Government request, the contractor shall furnish the most current version of the user manual and publications for all products/services provided under this contract or order at no cost.

B.3 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C10B Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X]
52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[]
52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly[]
b. Semi-Annually[]
c. Other[X] In accordance with Section B.3 Price Schedule

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE

B.3 PRICE SCHEDULE

Base Period Period of Performance shall be for 12 months from TBD

CLIN

Description Quantity

Unit

Unit Price

Total Price

0001
Project Management- Contractor Project Management Plan, Reporting Requirements, Technical Kickoff Meeting, and Change Enablement, Release, Management

In accordance with (IAW) 5.1, 5.1.1, 5.1.2, 5.1.3, 5.1.4 of Performance Work Statement)

12
MO
NSP
NSP
0001AA
Contractor Project Management Plan IAW PWS Section 5.1.1

Due 30 days after contract and updated monthly thereafter.

12
MO
NSP
NSP
0001AB
Product Status Report IAW PWS Section 5.1.2

Due via dashboard, accessible real-time

12
MO
NSP
NSP
0001AC
Change Enablement, Release, Management IAW PWS Section 5.1.4

System Configuration Management Plan

Due 30 days after receipt of contract and updated monthly thereafter

12
MO
NSP
NSP
0002
Application Support- installation, configuration, communications, application, and technical support for PI Planning application IAW PWS Section 5.2
12
MO
$
$
0002AA
Root Cause Analysis Report IAW PWS Section 5.2

Due within 5 business days following a reported issue

12
MO
NSP
NSP
0003
Licenses-150 Scaled Agile, Inc’s ® piplanning.io IAW PWS Section 5.2.1, 5.2.1.1

Due at contract award

1
EA
$
$
0004
Technical Documentation IAW PWS Section 5.3

The cost of this CLIN shall be included and allocated in CLIN 0002

12
MO
NSP
NSP
0004AA
Physical/logical diagrams IAW PWS 5.3

Diagrams shall be delivered thirty (30) days after receipt of contract and updated as per environment changes, thereafter

1
LO
NSP
NSP
0004AB
Administrative Account Records IAW PWS Section 5.3

Due 30 days within a change to the system

1
LO
NSP
NSP
0004AC
Deployment and Installation, Back-out, and Rollback Plan IAW PWS Section 5.3

Due every 180 days after receipt of contract or within 30 days of a change

1
LO
NSP
NSP
0004AD
Test Plan IAW PWS Section 5.3

Due 14 days after a change to Production which requires an update to the Test Plan

1
LO
NSP
NSP
0004AE
Test Scripts IAW PWS Section 5.3

Due one week prior to Production release

1
LO
NSP
NSP
0004AF
Test Reports IAW PWS Section 5.3

Due the day of release to Production

1
LO
NSP
NSP

BASE PERIOD TOTAL:

Option Period One This option may be exercised in accordance with FAR 52.217-9, Option to Extend the Term of the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence immediately after expiration of the base year.

CLIN

Quantity

1001
Project Management- Contractor Project Management Plan, Reporting Requirements, Technical Kickoff Meeting, and Change Enablement, Release, Management

In accordance with (IAW) 5.1, 5.1.1, 5.1.2, 5.1.3, 5.1.4 of Performance Work Statement)

12
MO
NSP
NSP
1001AA
Contractor Project Management Plan IAW PWS Section 5.1.1

Due 30 days after contract and updated monthly thereafter.

12
MO
NSP
NSP
1001AB
Product Status Report IAW PWS Section 5.1.2

Due via dashboard, accessible real-time

12
MO
NSP
NSP
1001AC
Change Enablement, Release, Management IAW PWS Section 5.1.4

System Configuration Management Plan

Due 30 days after receipt of contract and updated monthly thereafter

12
MO
NSP
NSP
1002
Application Support- installation, configuration, communications, application, and technical support for PI Planning application IAW PWS Section 5.2
12
MO
$
$
1002AA
Root Cause Analysis Report IAW PWS Section 5.2

Due within 5 business days following a reported issue

12
MO
NSP
NSP
1003
Licenses-150 Scaled Agile, Inc’s ® piplanning.io IAW PWS Section 5.2.1, 5.2.1.1

Due at contract award

1
EA
$
$
1004
Technical Documentation IAW PWS Section 5.3

The cost of this CLIN shall be included and allocated in CLIN 0002

12
MO
NSP
NSP
1004AA
Physical/logical diagrams IAW PWS 5.3

Diagrams shall be delivered thirty (30) days after receipt of contract and updated as per environment changes, thereafter

1
LO
NSP
NSP
1004AB
Administrative Account Records IAW PWS Section 5.3

Due 30 days within a change to the system

1
LO
NSP
NSP
1004AC
Deployment and Installation, Back-out, and Rollback Plan IAW PWS Section 5.3

Due every 180 days after receipt of contract or within 30 days of a change

1
LO
NSP
NSP
1004AD
Test Plan IAW PWS Section 5.3

Due 14 days after a change to Production which requires an update to the Test Plan

1
LO
NSP
NSP
1004AE
Test Scripts IAW PWS Section 5.3

Due one week prior to Production release

1
LO
NSP
NSP
1004AF
Test Reports IAW PWS Section 5.3

Due the day of release to Production

1
LO
NSP
NSP

OPTION PERIOD ONE TOTAL:

Optional Tasks This option may be exercised in accordance with FAR 52.217-7, Option for increased quantity, separately priced line item any time during the period of performance. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

CLIN

Quantity

0005
Transition Support (Optional Task One)- If exercised, the Contractor shall provide a Transition Plan for 60 days of outgoing transition support for transitioning work from the current order to a follow-on order or Government entity IAW PWS Section 5.4
12
MO
$
$
0006
Cyber Security (Optional Task Two)-Security Assessment and Accreditation IAW PWS Section 5.5, 5.5.1
12
MO
$
$
0007
Licensing (Optional Task Three)- Licensing Block One, Licensing Block Two IAW PWS Section 5.6
12
MO
$
$
Base Period Total
$
Option Period One Total
$
Optional Task Total
$
TOTAL VALUE
$

B.4 PERFORMANCE WORK STATEMENT

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Office of Information and Technology (OIT) Compliance, Risk and Remediation (CRR)

Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning Software and Support Date: June 16, 2024

VA-24-00073347

Task Order PWS Version Number: 1.0

1.0 BACKGROUND

The Department of Veterans Affairs (VA), Office of Information & Technology (OIT), Technical Solutions strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.

The VA Office of Compliance, Risk and Remediation (CRR), has a requirement for Scaled Agile, Inc’s ® piplanning.io or equivalent Planning Interval (PI) planning application for use in Scaled Agile Framework (SAFe). PI Planning is a cadence-based event that aligns all the teams on the Agile Release Train (ART) to a shared mission and vision. PI Planning has a standard agenda that includes a presentation of business context and vision, followed by team planning breakouts – where the teams create their Iteration plans and objectives for the upcoming PI. A successful PI Planning event delivers two primary outputs – committed PI objectives and a program board.

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”

4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004

5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

9. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm

12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm

13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5, 2019

14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017

15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”

17. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021

21. VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021

22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019

23. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010

24. VA Handbook 6500.6, “Contract Security,” March 12, 2010

25. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011

26. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018

27. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

28. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

29. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

30. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

31. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

32. VA Handbook 6510, “VA Identity and Access Management,” January 15, 2016

33. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017

34. VA Directive 6300, “Records and Information Management,” September 21, 2018

35. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010

36. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

37. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

38. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015

39. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014

40. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

41. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

42. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

43. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)

44. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018

45. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020

46. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

47. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile Devices (Draft),” October 2012

48. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981, “Mobile, PIV, and Authentication,” March 2014

49. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

50. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

51. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

52. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

53. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

54. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

55. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

56. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

57. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018

58. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

59. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013

60. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013

61. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

62. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

63. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

64. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

65. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

66. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

67. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),” November 19, 2020

68. Social Security Number (SSN) Fraud Prevention Act of 2017

69. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018

3.0 SCOPE OF WORK

The Contractor shall provide technical application support services, installation, configuration, troubleshooting, and user administration to the OIT Technical Solutions team. The Contractor shall provide virtual system/server support for containerized applications and their virtual environments in test, development, sandbox, and production platform environments. The Contractor shall provide vulnerability remediation in the virtual environment, and all other support services provided in this PWS within the PoP.

The solution within this TO is hosted in the VA Enterprise Cloud (VAEC) VA Platform One (VAPO) environment and shall be maintained in the current state of operations.

All documentation created by the Contractor shall use OIT approved templates.

3.1 ORDER TYPE

The effort shall be proposed on a Firm Fixed Price (FFP) basis.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The PoP shall be 12 months from date of award, with one 12-month option period. The overall Period of Performance shall not exceed 24 months.

4.2 PLACE OF PERFORMANCE

Efforts under this contract shall be performed at Contractor facilities. The Contractor shall identify the Contractor’s place of performance, including all remote employees, in their Task Execution Plan submission.

4.3 TRAVEL OR SPECIAL REQUIREMENTS

There is no expected travel with this effort.

4.4 GOVERNMENT FURNISHED PROPERTY

The Government shall furnish the below GFE:

· Personal Identification Verification (PIV) cards

· Cloud capacity in and connectivity to the VA Enterprise Cloud (VAEC) environments.

· VA Enterprise Cloud Operational Tools (VAECOT) comprised of a suite of COTS cloud management tools as identified in the VAEC Technical Reference Guide.

· Enterprise Development Environment (EDE) and Tools as identified in the VAEC Technical Reference Guide.

4.5 SECURITY AND PRIVACY

Specific contract requirements are as follows,

j. The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system). Such issues shall be remediated as quickly as is practical, but in no event longer than ___2__days from the date the exploitation is discovered. The vendor shall prioritize the remediation based on the severity of the exploitation.

k. When the Security Fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the vendor shall provide written notice to VA that the patch has been validated as not affecting the Systems within 10 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within __5___ days or the next available planned outage.

4.5.1 POSITION/TASK RISK DESIGNATION LEVEL(S)

The PDT Tool is located at the following US Office of Personnel Management Website: https://www.opm.gov/investigations/suitability-executive-agent/position-designation-tool/) In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity, and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:

Position Sensitivity and Background Investigation Requirements by Task

Task Number
Tier1 / Low Risk
Tier 2 / Moderate Risk
Tier 4 / High Risk
5.1
|X|
|_|
|_|
5.2
|_|
|X|
|_|
5.3
|X|
|_|
|_|
5.4
|X|
|_|
|_|
5.5
|X|
|_|
|_|

The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

5.0 SPECIFIC TASKS AND DELIVERABLES

VA requires the purchase of Scaled Agile Inc.’s (SAI) piplanning.io or equivalent. This application includes 150 licenses, premium level on-premises support, installation services and end user support services. Installation services include configuration and installation of Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application to a production level. To a production level refers to the best practice of test, development, sandbox, and production environments located in the VAEC. These services also include integration with an Application Lifecycle Management (ALM) tool (e.g., Jira®). End user support services consists of live support available during business hours to all users of the product. The Contractor shall provide dedicated premium level on-premises support with coverage available between 6:00am – 7:00pm Eastern Time.

5.1 PROJECT MANAGEMENT

5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN

The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline, and tools to be used in execution of this TO effort. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks, and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA Program Manager (PM) approved CPMP throughout the PoP.

Deliverable:

A. Contractor Project Management Plan

5.1.2 REPORTING REQUIREMENTS

The Contractor shall produce an electronic Product Status Reports available real-time. These reports will be auto generated to a dashboard from existing data sources, including:

· From the VA customer service request system (e.g., ServiceNow®)

· Server monitoring tools (e.g., Dynatrace®).

The Product Status Report shall, at a minimum, include the following data elements, which shall be retrieved from multiple different data sources and aggregated to produce the reports:

a. Status of all customer service, problem, user support and incident reporting (ServiceNow data).

b. Status of all user accounts requests (ServiceNow data).

c. Status of all approved change orders to the hardware and application platform (ServiceNow change management data).

d. Status of all issues and risks (Product risk registry).

The Contractor shall use the VA-authorized tools (e.g., Jira, GitHub, or similar) and products in scope of this contract and server reports to collect and report the data to be reported in this PWS. This report will not be the only means of communication between the Contractor, COR, and the VA PM. The Contractor shall continuously monitor performance and report any deviation from the CPMP or previous Product Status Reports to the COR and VA PM during routine, regular communications.

Deliverable:

A. Product Status Report

5.1.3 TECHNICAL KICKOFF MEETING

A technical kickoff meeting shall be held within 10 days after contract award. The Contractor shall coordinate the date, time, and location (can be virtual) with the Contracting Officer (CO), as the Post-Award Conference Chairperson, the VA PM, as the Co-Chairperson, the Contract Specialist (CS), and the COR. The Contractor shall provide a draft agenda to the CO and VA PM at least five (5) calendar days prior to the meeting. Upon Government approval of a final agenda, the Contractor shall distribute to all meeting attendees.

During the kickoff-meeting, the Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, and project schedule for each effort via a Microsoft Office PowerPoint presentation. At the conclusion of the meeting, the Contractor shall update the presentation with a final slide entitled “Summary Report” which shall include notes on any major issues, agreements, or disagreements discussed during the kickoff meeting and the following statement “As the Post-Award Conference Chairperson, I have reviewed the entirety of this presentation and assert that it is an accurate representation and summary of the discussions held during the Technical Kickoff Meeting for Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application support contract.

The Contractor shall submit the final updated presentation to the CO for review and signature within three (3) calendar days after the meeting. The Contractor shall also work with the CS, the Government’s designated note taker, to prepare and distribute the meeting minutes of the kickoff meeting to the CO, COR, and all attendees within three (3) calendar days after the meeting. The Contractor shall obtain concurrence from the CS on the content of the meeting minutes prior to distribution of the document.

5.1.4 CHANGE ENABLEMENT, RELEASE AND MANAGEMENT

The Contractor shall be responsible for compliance with VA Directive 6004, Configuration, Change, and Release Management Programs, which provides department-wide standards established in accordance with Federal Information Security Management Act (FISMA) (P.L. 107-347, Title III of the E-Government Act), December 2002, related VA Directive and Handbook 6500, Information Security Program, and Office of Information Technology (OIT) Authorization Requirements Standard Operating Procedures (SOP).

The Contractor shall work with Information System Owner (ISO) to meet ATO requirements which includes completion of a System Configuration Management Plan (SCMP). In addition to complying with VA Directive 6004, the Contractor shall comply with Configuration Management System (CMS) Discovery and Service Mapping requirements, which includes, but is not limited to; providing associated system design documents or appropriate contacts for system design and technical information necessary to conduct discovery and mapping activities. Provisions must be made between the responsible vendor and VA Product team on coordination of all system changes. Release Change Requests are required to be submitted in the VA authorized Change Control system, ServiceNow.

References:

VA Directive 6004, Configuration, Change and Release Management Programs VA Directive and Handbook 6500, Information Security Program

Deliverables:

A. System Configuration Management Plan

5.2 APPLICATION SUPPORT

The Contractor shall provide installation, configuration, communications, application, and technical support for Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application. A dedicated contractor Account Manager shall respond to urgent inquiries within four hours from the time of notification. All other inquiries shall be addressed the next business day. The methods of communication shall include Slack®, phone, and Teams®.

The Contractor shall provide technical product support and if unable to resolve the contractor is responsible for escalation to the vendor for remediation. During PI events issues must be resolved within two hours; issues that cannot be resolved by the contractor within this timeframe shall be escalated to the vendor. Upon successful resolution the contractor shall provide root cause analysis of issues escalated to the vendor within three business days of event.

The Contractor shall provide the equivalent to senior level DevSecOps Engineer, with a minimum of nine years’ experience, to meet the required level of effort in support of version upgrades, integrations, and deployments within the VA ecosystem.

The Contractor shall provide full application lifecycle support, including continuous sustainment (patching) and technical support (patching, upgrades) for VA’s implementation of Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application.

The Contractor shall provide project updates in VA approved tools (e.g., ServiceNow, Jira). The resources shall provide support including, but not limited to remediation of scan results, custom script deployments, and/or any technical change within the vendor’s control that will enable successful Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application implementation.

The Contractor shall perform product integration and testing for the application. Testing shall include 508-compliance, connectivity, load, functional, and integration following industry best practices. The Contractor shall create test plans, test scripts, and test reports.

The Contractor shall perform data migration as required.

Deliverables:

A. Root Cause Analysis Report

5.2.1 LICENSES

The Contractor shall provide 150 Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning software application licenses.

SALIENT CHARACTERISTICS

• whiteboard capability with colored sticky notes for different teams.

• Graphical User Interface (GUI) must be intuitive.

• able to handle up to 600 concurrent users either onsite or in distributed teams.

• must support a “big picture” Kanban board to virtually “walk the walls.”

• must have backup/recovery features.

• must have an enterprise licensing model.

• must support several iterations of varying durations.

• must be able to support identification of the team to attend the event.

• must have the ability to create breakout room sessions.

• must have the ability to read other team boards without additional permissions.

• must allow for role-based permissions.

• must offer an integrated program risk board.

• must provide visual representation of tasks to meet feature delivery.

• must allow for creation of milestones.

• must be able to map out dependencies between teams.

• must be able to synchronize in real-time.

• must be able to be agnostic when connecting to Application Lifecycle Management (ALM)/Software-as-a-Service (SaaS) tools.

• must offer bi-directional communication with ALM and desktop applications.

• must have the ability to schedule timed breakout sessions and breaks.

• must offer both anonymous and name capture for voting/polling features.

• must allow touch screen functionality.

• must allow mobile app functionality.

• must support online availability of all documents and material for PI planning events.

• must take into consideration user bandwidth required to run the application.

Deliverable:

A. Licenses

5.3 TECHNICAL DOCUMENTATION

The Contractor shall coordinate with VA to identify needs for creation, editing, review, and promulgation of Physical/Logical Diagrams, Administrative Account Records, Deployment, and Installation, Back-out, and Rollback Plan, Test Plan, Test Scripts, Test Reports, end user communications and technical documentation, as needed. All new versions of products may require the Contractor to create/update documentation.

Deliverables:

A. Physical/logical diagrams B. Administrative account records C. Deployment and Installation, Back-out, and Rollback Plan D. Test Plan E. Test Scripts F. Test Reports

5.4 TRANSITION SUPPORT (OPTIONAL TASK ONE)

If exercised, the Contractor shall provide a Transition Plan for 60 days of outgoing transition support for transitioning work from the current contract to a follow-on contract or Government entity. This transition may be to a Government entity or to another Contractor. In accordance with the Government-approved Transition Plan, the Contractor shall execute the Transition Plan and assist the Government in implementing a complete transition from this contract to a new support provider. This shall include formal coordination with Government staff and successor staff and management. It shall also include delivery of copies of all artifacts delivered under this contract, as well as existing policies and procedures, and delivery of baseline metrics and statistics. This Transition Plan shall, at a minimum, include the following:

1. Coordination with Government representatives.

2. Review, evaluation, and transition of current support services.

3. Transition of historic data to new Contractor system.

4. Transition of application accounts.

5. Transfer of hardware and software warranties, maintenance agreements and licenses.

6. Update and transfer of all necessary business and/or technical documentation.

7. Orientation phase and program to introduce Government and Contractor personnel, programs, and users to the Contractor's team, tools, methodologies, and business processes.

8. Disposition of Contractor purchased Government owned assets,

9. Transfer of Government Furnished Equipment (GFE) and Government Furnished Information, and GFE inventory management assistance.

10. Turn-in of all Government keys, ID/access cards, and security codes.

If exercised, the PoP for the optional task may extend 60 days beyond the PoP in which it is exercised. During this period, the Contractor shall provide for continuity of services to include technical resources required to provide continued help desk functionality, database management and virtual system/server support for the series of application servers, database servers, web servers, virtual environments in the testing, training, staging and production platform environments. The Contractor shall work collaboratively with the incoming Contractor staff or Government personnel to minimize interruption to on-going program operations.

Deliverable:

A. Transition Plan

5.5 CYBER SECURITY (OPTIONAL TASK TWO)

5.5.1 SECURITY ASSESSMENT AND ACCREDITATION

All systems and applications supporting Federal government agencies shall follow National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) Special Publication (SP) 800-37 as the standard for Assessment and Authorization (A&A) process before being put into production, and every five (5) years thereafter. Risk assessments must be performed in accordance with NIST SP 800-30, NIST SP 800-53 and as described in the VA Information Security Knowledge Service. The risk factors described in NIST SP 800-30 and NIST SP 800-53 will be used across VA Administrations and Staff Offices to ensure ease of sharing risk information.

If exercised in Option period one, the Contractor shall maintain VA ATO authorization for the Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application. This includes supporting any of the associated environments prior to the expiration of any current ATO periods in effect for these products. Specific activities are to include, at a minimum, security certifications, or comprehensive assessments of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly. This effort includes all activities associated with obtaining a new ATO period for these applications and environments.

The Contractor shall develop and maintain all A&A documentation and requirements for upload, registration, and execution within the VA-approved Governance Risk and Compliance (GRC) tool for Scaled Agile, Inc’s ® piplanning.io or equivalent PI Planning application.

Custom developed and Government Off the Shelf (GOTS)/Commercial Off the Shelf (COTS) VA applications are required to obtain an ATO. For any ATO effort, the Contractor shall follow the Risk Management Framework (RMF) Lifecycle. The Contractor shall initiate the ATO process within 30 calendar days of the exercising of this TO. Products in the VAEC require a continuous ATO process.

The Contractor shall provide applicable documentation and coordinate with data center partners to ensure consistency with ATO requirements for certification authorization to ensure the supported applications/systems meet VA information security policies and standards to facilitate the successful completion of the A&A process and maintain its ATO.

The Contractor shall:

1. Support VA Information Security Officers and the Office of Cyber Security Control Assessment team as detailed in VA Directive and Handbook 6500 Information Security Program, VA Handbook 6500.3 Certification and Accreditation of VA Information Systems.

2. Conduct cybersecurity software code quality testing and validation of all software code and provide certified scan reports validating the required code quality.

3. Conduct and participate in vulnerability scans and tests as detailed in National Institute of Standards and Technology (NIST) Special Publication (SP)…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .