25QE037_PWS_DRAFT_031225.pdf
PDF 1 MB Posted
- Attached to
- Cybersecurity Pathway Courseware, Credentialing, and Support Federal contract opportunity
- Solicitation number
- HE125425QE037
- Issued by
- Department of Defense Education Activity
About this file
This Draft Performance Work Statement (PWS) details the Department of Defense Education Activity's (DoDEA) requirements for a Cybersecurity Pathway program for high school students. The solicitation seeks a contractor to provide digital instructional resources, instructor training/certification, industry-aligned student certifications, and ongoing technical support for three cybersecurity courses: Computer Service & Support, Networking Fundamentals, and Introduction to Cybersecurity. The program aims to expose students to real-world cybersecurity topics and prepare them for entry-level industry certifications.
DoDEA plans to award a firm-fixed-price, indefinite delivery/indefinite quantity (IDIQ) contract for a 5-year base period and one option year, targeting 10 existing cybersecurity programs with potential expansion to other high schools and the DoDEA Virtual High School. The contract will cover comprehensive courseware on a single modular learning platform, virtual professional learning for teachers, certification test vouchers, and technical support. The solicitation is planned as a 100% Small Business Set-Aside, with an anticipated solicitation posting date of 04/04/2025 and an award date of 09/03/2025. The program will support approximately 67,000 military and civilian dependents across 161 schools in the Americas, Europe, Middle East, and Pacific regions.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
Department of Defense Education Activity
4800 Mark Center Drive
Alexandria, VA 22350
DRAFT
24 Jan 25 1
Cybersecurity Pathway Courseware, Credentialing, and Support
1. General Information and Scope of Work
1.1 Agency
1.1.1 For school year (SY) 2024-25, the Department of Defense Education Activity (DoDEA) will provide
PK-12 instruction in 161 schools to over 67,000 dependents of military and civilian employees. DoDEA's curriculum, resources and student achievement scores on standardized assessments compare favorably to those of high-performing US public school systems.
1.1.2 Student enrollment is based primarily on deployment of military troops worldwide. In the Americas, DoDEA operates 50 schools located in seven states, Puerto Rico, and Cuba. In Europe and the Middle
East, DoDEA operates 64 schools located in Germany, England, Netherlands, Belgium, Spain, Turkey, Bahrain, and Italy. In the Pacific, DoDEA operates 46 schools located in Korea, Japan (mainland and Okinawa), and Guam. DoDEA also operates a fully accredited virtual high school with teaching hubs in the Americas, Europe, and Pacific.
1.1.3 DoDEA schools have many grade configurations. Forty of our 160 brick-and-mortar schools have grades 9-12, and they serve approximately 12,975 high school students.
1.1.4 DoDEA has adopted College and Career Ready Standards (CCRS) in mathematics, literacy, the arts, social studies, and science, which are rigorous, research-based, and reflect the knowledge, skills and dispositions students need for success in college and/or careers and are aligned with the Common
Core State Standards (CCSS), National Core Art Standards (NCAS), Next Generation Science
Standards (NGSS), College, Career, and Civic Life (C3) Framework for Social Studies State Standards, and Society for Health and Physical Education Standards (SHAPE AMERICA). DoDEA has also adopted both the International Society for Technology in Education (ISTE) Standards for Students, Collaborative for Academic, Social, and Emotional Learning (CASEL) framework.
1.2 Background
1.2.1 DoDEA has offered IT infrastructure and support training programs for secondary students in
DoDEA high schools since 2002. Students and teachers report that the program helps students improve their information technology (IT) skills, understand industry requirements, and determine whether or not they want to choose IT as their career field.
1.2.2 This highly technical curriculum requires teachers to have ongoing technical assistance and support throughout the school year. Also, the progress of these programs needs to be monitored to ensure that they comply with the latest industry standards.
1.2.3 Since at least 2010, DoDEA’s cybersecurity pathway has been based on the Cisco platform. There are now many other competing training platforms available. DoDEA is establishing a new cyber-security pathway to introduce high school students to cloud computing, networking, and enterprise solutions, using one platform.
1.3 Scope of Work
1.3.1 DoDEA requires access to digital instructional resources, instructor training/certification, industry aligned student certifications and ongoing technical support for this program to include the monitoring of quality assurance and performance in conformance with current industry standards. The professional learning component includes virtual training for both new teacher training, certified teachers, and selected above-school level subject-matter experts. Although numbers may vary slightly in the option years, DoDEA currently has ten cybersecurity programs systemwide and is looking to expand to other DoDEA high schools and the DoDEA Virtual High School.
1.3.2 DoDEA expects to make one award for a firm-fixed price (FFP), indefinite delivery/indefinite quantity
(IDIQ) contract for a 5-year base period and a one-year option period.
1.3.3 The table below shows course names and estimated enrollment and schools offering by course for each year of the period of performance:
24 Jan 25 2
Categories
Computer Service and Support
Networking
Fundamentals
Introduction to
Cybersecurity
Students Schools* Students Schools * Students Schools *
Base Year 1 90 5 ---** 8 110 6
Base Year 2 120 8 120 8 160 8
Base Year 3 160 12 160 12 210 12
Base Year 4 200 16 200 16 260 16
Base Year 5 240 20 240 20 310 20
Option Year 1 275 23 275 23 350 23
* DoDEA estimates one teacher per school. ** Teacher training occurs.
2 Requirements
Cybersecurity Pathway Resources and Support: The Contractor shall provide students and staff with courseware for three courses on one platform, related credentialing opportunities, asynchronous professional learning, and technical support.
Supporting Tasks: The tasks below are to help the Contractor gain a better understanding of the requirements to successfully meet the objective. They are not all inclusive, so the Contractor is expected to develop the total solution to meet all the requirements in accordance with a performance-based approach.
1.1 Task 1, Courseware—The Contractor shall provide three comprehensive, one-year courses for DoDEA’s cybersecurity pathway that align with current industry certifications for both teachers and students while utilizing a single modular learning platform (“platform”). The three courses are Computer Service & Support, Networking
Fundamentals, and Introduction to Cybersecurity. The goal is to expose students to real-world cybersecurity topics while preparing them to become entry-level industry ready as proven by proof of industry certification.
Students will be given an opportunity to practice types of questions administered to become comfortable with industry testing platform. Product training shall provide an overview of the software and resources as well as site navigate.
1.1.1 Each course shall include, at a minimum, the following:
1) Customizable content in a variety of instructional formats to accommodate face-to-face, virtual, and hybrid teaching.
2) Content aligned to a related industry credential, per Task 3.
3) Modular instruction adaptable for usage on various devices and platforms.
4) Virtual simulations and/or video lessons to demonstrate cybersecurity topics and scenarios. See
Task 2 regarding related hardware.
5) Instructional practices for teachers to foster student mastery of industry skills.
6) Up-to-date regulatory information as applicable, pertaining to the cybersecurity industry.
7) Variety of hands-on skill building activities to strengthen knowledge of real-world industry topics and concepts.
8) Assessments (such as pretests, knowledge checks and unit tests) to determine student strengths and weaknesses for industry-aligned credentials, standards and objectives.
9) Practice tests for industry certification exams, if applicable.
10) Enabling teachers and students to monitor mastery of core skills and objectives.
1.1.2 Provide a list of components required for each lesson to include necessary and optional equipment and consumables. Note: If applicable, provide the option to purchase supplemental student instructional kits for various learning formats.
1.2 Task 2, Hardware/Software/Consumables (if applicable): The Contractor shall provide a list of hardware and software required for each course to include virtual simulations. Clearly distinguish necessary and optional hardware, software, and consumables. Include the option for DoDEA to purchase the hardware, software and consumables directly from the Contractor. Provide industry-standard warranties for each piece of hardware.
Note: In today’s modern training environment, much of the training may be accomplished through use of
Cyber-Ranges or other virtualization solutions. If this type of access is required as part of the proposed solution, include the licensing and access costs in the price proposal.
24 Jan 25 3
1.3 Task 3, Virtual Professional Learning (PL)—For each course, the Contractor shall provide asynchronous webinars and/or digital modules. The latter shall be SCORM®-compliant, per PWS 3.10. The Contractor shall:
1.3.1 School Administrator PL: Provide one approximately 30-minute asynchronous webinar and/or digital module providing an overview of the modules and course materials as well as instructional best practices in the base year. In the event product updates are issued during the term of the contract, additional PL shall be provided to ensure stakeholder awareness. The Contractor shall also provide a digital 1-2-page observation checklist for each course to help administrators evaluate teacher/ program effectiveness.
▪ School administrators need to understand the program.
▪ This one PL shall cover all three courses.
1.3.2 Educational Technologist PL: Provide one approximately 60-minute webinar or digital module for education technologists and selected support personnel. In the event product updates are issued during the term of the contract, additional materials shall be provided to ensure stakeholder awareness.
Note: Education technologists need to support teachers in program delivery and in implementing instructional best practices.
1.3.3 Classroom Teacher PL: In Base Year 1, provide four sessions lasting approximately two hours each—an estimated eight total hours. In Base Years 2-4, provide one session lasting approximately one hour each to address changes in the courseware/best practices. Topics will be determined by
DoDEA in consultation with the Contractor post-award and will likely include such topics as (1) using provided courseware solutions to prepare for industry exams, (2) best teaching practices for each course, and (3) best practices in preparing students for the industry credentialing exams.
1.3.4 All Professional Learning—The Contractor shall:
1.3.4.1 Present a dry run of the PL to selected DoDEA staff at least 30 calendar days before the expected release date. Finalize each PL based on written feedback from the contracting officer’s representative (COR). Note: The exact schedule for these requirements will be determined by DoDEA in consultation with the Contractor post-award.
1.3.4.2 Post each PL on DoDEA’s learning management system (LMS, Schoology).
2.4 Task 4, Credentialing—The Contractor shall provide nationally recognized certification test vouchers. The digital certification tests shall be administered in DoDEA schools using local proctors and include the following features:
2.4.1 Be scored and reported to DoDEA within one business day of the test taker completing the exam.
2.4.2 Include a pre-test option for all test takers with each voucher.
2.4.3 Include at least one post-test retake opportunities for all test takers with each voucher.
2.4.4 Ensure certification test vouchers are valid for at least one year from date of payment.
2.4.5 Distribute purchased vouchers electronically to the designated DoDEA point of contact.
2.4.6 Reports: Provide data produced or stored by the Contractor’s platform in connection with DoDEA
(including internally generated data such as usage data) in addition to any other web-based reporting platforms/tools/exports data that the Contractor maintains. Ensure DoDEA’s data are:
1) Exportable via a programmatically accessible interface (e.g., API, SFTP, and/or mirrored database) for automated import back into DoDEA’s data systems.
2) Returnable in a data-friendly format (e.g., CSV, SQL dump, JSON, XML).
3) Updated either in real-time or at minimum once per semester after testing is complete.
2.5 General Requirements—The Contractor shall:
2.5.1 Technical Support: Provide industry-standard technical support for its digital resources for the life of the contract via telephone or email within one business day from the initial contact to include but not limited to assisting with service problems, product setup, upgrades, and troubleshooting.
2.5.2 Technical Requirements for Digital Resources—The Contractor shall:
2.5.2.1 Provide digital resources designed to run in DoDEA’s learning management system (LMS, Schoology), which operates within our virtual learning environment (VLE).
2.5.2.2 Deliver digital resources in one of the following formats:
1) Integrated via DoDEA’s LMS to the digital resources hosted by the Contractor.
2) Hosted externally by the Contractor but accessible via DoDEA’s LMS to the digital assignments and assessments imported, hosted, and maintained in the LMS.
24 Jan 25 4
2.5.2.3 Ensure the course content meets the following specifications:
1) Conforms to IMS Learning Global Consortium (IMS) content packaging specifications.
2) Uses imported content, if required, conforming to IMS content packaging specifications.
3) Uses code that does not disable LMS features when digital resources are accessed.
4) Requires single—not multiple—authentications to access content via DoDEA’s LMS.
5) Incorporates, where applicable, assessments that are IMS Test and Question Interoperability
(QTI)-conformant.
6) Uses content-hosted externally that conforms to any of the existing versions of IMS
Learning Tools Interoperability (LTI), per www.imsglobal.org.
2.5.2.4 Provide teacher and student access to the Contractor’s digital resources through a single sign-on platform that uses one username and password to access what is needed, specifically, via DoDEA’s identity, rostering, and management platform (currently, ClassLink).
2.5.3 Third-Party Programs, Software, and Applications: Ensure its own and its subcontractors’ (third-party) programs, software, and applications meet—at a minimum—the same technical requirements as the
Contractor must meet, such as single sign on (SSO) and Federal Risk and Authorization Management
Program (FedRAMP) Level 2, etc. On a case-by-case basis, DoDEA may honor requests to waive the
FedRAMP Level 2 requirement. For more information, see Technical Exhibit #1, 1.1.7.
2.5.4 Delivery of Print and Digital Resources—The Contractor shall:
2.5.4.1 Deliver digital materials with instructions detailing how the resources can be accessed by teachers, students, and above-school-level educators.
2.5.4.2 Ship all print/physical materials to the Americas by commercial carrier or USPS and to
Europe and the Pacific only by commercial carrier. Delivery orders use door-to-door addresses.
Provide, upon shipment of materials, a digital shipment notification that includes the following:
▪ Contract number and delivery order number
▪ Contract line item number (CLIN) indicating materials and quantities being shipped
▪ Destination and date of shipment
▪ Shipping carrier name and the tracking number of each shipment
▪ Estimated date of arrival of shipment and, if applicable, shipping slip
2.5.5 Meetings: Attend virtual meetings at no additional cost to the Government and provide the medium through which each meeting occurs, record each meeting’s minutes. Submit the draft minutes to the
COR within two business days of the event and finalize the minutes two business days after receipt of written feedback from the COR. Note: Costs associated with attending any face-to-face meetings shall be handled/paid for as stated in the contract.
2.5.5.1 Post-Award Conference: Participate in a video- or teleconference with the COR five business days after award IAW FAR Subpart 42.5.
2.5.5.2 IT Meeting: Convene a video- or teleconference with DoDEA Information Technology staff ten business days after award, per Technical Exhibit #1.
2.5.5.3 Other Post-Award Meetings: Meet with the Contracting Officer (KO), COR, and/or other
Agency personnel, as appropriate, to review Contractor performance, as required by DoDEA.
The KO may discuss the Agency’s view of Contractor performance, and the Contractor shall apprise the Agency of any problems being experienced. The Contractor shall take appropriate action to resolve any outstanding issues the Agency raises.
2.6 Performance Standards and Acceptable Quality Levels
2.6.1 Performance Standard: Tasks shall be completed by the required completion date.
2.6.2 Acceptable Quality Level: See PWS 7, Performance Requirement Summary (PRS).
3 Constraints
3.1 Place of Performance: Work shall be performed at the Contractor’s facilities.
3.2 Privacy—The Contractor shall:
3.2.1 User Accounts: Require, wherever applicable, that individual accounts possess unique usernames and passwords that do not require personally identifiable information (PII) to access online content, i.e., first & last name and any other unique personal information.
3.2.2 Contractor Personnel:
24 Jan 25 5
▪ Ensure personnel assigned to this contract take proper precautions to protect information from disclosure. Collect and/or store all agency-owned or agency-controlled PII in accordance with the relevant requirements of the Privacy Act, 5 U.S.C, which may be found at the following URL:
http://www.archives.gov/about/laws/privacy-act-1974.html.
▪ All Contractor personnel that have access or may potentially have access to DoDEA data in any form shall be US citizens, including any third-party penetration (PEN)/security testers.
3.2.3 Privacy Training: Ensure Contractor staff who have access to DoDEA’s student, teacher and/or staff personally identifiable information successfully complete the DoD Privacy Act/Personally Identifiable
Information (PA/PII) training before gaining access to the data and yearly thereafter. Provide copies of the certificates of completion to the COR which can be audited at any time by the Chief Information
Security Officer (CISO) or his/her designee.
3.2.4 Privacy Verification: Provide the COR written verification of compliance to the Privacy requirements
(listed above) 120 calendar days prior to the expiration of each year’s contract option period or annually, as required. Note: After reviewing the Contractor’s verification, DoDEA reserves the right to ask for further verification data in order for DoDEA to comply with DoD’s evolving privacy mandates.
3.3 Liaison and Alternate Liaison—The Contractor shall:
3.3.1 Provide a liaison and alternate liaison to be responsible for the performance of work. Their names shall be designated in writing to the Contracting Officer. They shall have full authority to act for the
Contractor on all contract matters relating to the daily operation of this contract. Each shall have at least one year of experience working in a similar role.
3.3.2 Notify the COR in writing regarding any change in either the liaison’s role ten business days in advance of the change If the liaison or liaison alternate is changed post-award, the replacement shall meet or exceed the qualifications and experience of the person assigned upon contract award.
3.4 Holidays and Hours of Operation
3.4.1 The liaison or alternate liaison shall be available during the hours of 9AM to 3PM Eastern Standard
Time (EST), except for Federal holidays and Federal government closures/shutdowns. The following list shows recognized Federal holidays: New Year’s Day, Martin Luther King Jr.’s Birthday, Presidents
Day, Memorial Day, Juneteenth National Independence Day, Independence Day, Labor Day, Columbus
Day, Veterans Day, Thanksgiving Day, and Christmas Day.
3.4.2 Although there are different time zones within Europe and the Pacific and different hours for specific schools throughout DoDEA, the normal business hours for the regions roughly correspond to the following: Americas, 0700-1500 EST; Europe, 1300-2100 EST; and Pacific, 2000-0400 EST. there are different time zones within Europe and the Pacific and different hours for specific schools throughout DoDEA, the normal business hours for the regions roughly correspond to the following:
Americas, 0700-1500 EST; Europe, 0200-1000 EST; and Pacific, 2000-0400 EST.
3.5 Availability: The Contractor shall make all resources available for the life of the contract.
3.6 Copyright Dates: The Contractor shall keep content/courseware current and updated regularly throughout the period of performance, as demonstrated by maintenance of an updated content copyright not to exceed one school year from its current date. For example, an eBook published in January 2023 would be acceptable for the 2022-23 school year and also the 2023-24 school year. It would not, however, be considered current for the 2024-25 school year.
3.7 Anti-Bias, Diversity, and Inclusion: The Contractor shall provide resources free of age, racial, color, national origin, disabling conditions, sexual, gender, religious, and ethnic bias and present balanced coverage of multi-cultural contributions and representation, where appropriate.
3.8 Section 508 Compliance—The Contractor shall:
3.8.1 Background: Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires Federal agencies that develop, procure, maintain, or use information and communication technology (ICT) to endure they are accessible to people with disabilities.
Federal employees and members of the public who have disabilities must have access to and use of information/data that is comparable to people without disabilities.
24 Jan 25 6
3.8.2 Requirement: Ensure that products, platforms, and services delivered as part of this work statement that are ICT or contain ICT conform to the Revised 508 Standards, 36 C.F.R. § 1194.1 & Apps.
A, C & D which are located at the following URL: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines.
3.8.3 ARS: See the attached ICT Accessibility Requirements Statement (ARS). All functional performance criteria apply when using an alternative design or technology that achieves substantially equivalent or greater accessibility and usability by individuals with disabilities, than would be provided by conformance to one or more of the requirements in Chapters 4-6 of the Revised 508 Standards or when Chapters
4-6 do not address one or more functions of ICT. Note the guidance in the table below:
Applicable
Requirements Directions
Software Features and Components
Applies to all WCAG Level AA Success Criteria, 502 Interoperability with
Assistive Technology, and 503 Applications.
Hardware Features and Components All requirements apply.
Support Services and
Documentation All requirements apply.
Outputs/Deliverables Ensures that outputs/deliverables do not adversely affect accessibility features of the existing EIT technologies.
3.9 Optical Character Resolution (OCR): The Contractor shall provide, upon request, two digital OCR copies of print materials in one or more of the following five formats: Digital Accessible Information System/National
Instructional Materials; Accessibility Standard (NIMAS) with cascading style sheet; HyperText Markup
Language (HTML); Portable Document Format (PDF, unlocked, embedded fonts, single page); and Rich Text
Format (RTF)/Word document.
3.10 Sharable Content Object Reference Model® (SCORM®) Compliance: Provide digital modules, if included among the proposed/required resources, that are SCORM®-compliant. Note: The Department of Defense
Instruction (DoDI) 1322.26 mandates that modules comply with the latest possible version of SCORM®, per https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/132226_dodi_2017.pdf?ver=2017-
10-05-073235-400.
3.11 Data & Data Rights: All data developed from any work awarded under this contract is and shall remain the property of the Government. The Contractor shall ensure that digital rights to all visual materials embedded in the resources will be given so that DoDEA for DoDEA’s internal use only may use resources without incurring copyright costs or infringing on copyright laws. All data developed from any work awarded under this contract is and shall remain the property of the Government.
3.12 Organizational Conflict of Interest (OCI): The Contractor (including any subcontractor) personnel performing work under this contract may receive, have access to, or participate in the development of, proprietary or
Privacy Act information (e.g., personal information, education, etc.) may create a current or subsequent OCI as defined in FAR Subpart 9.5. Whenever the Contractor becomes aware that such access or participation may result in actual or potential OCI, the Contractor shall (1) immediately notify the Contracting Officer
(KO) in writing and (2) promptly submit a plan to the KO to avoid or mitigate any such OCI. Note: The KO will unilaterally determine if the Contractor’s plan is acceptable. If the KO determines the plan cannot satisfactorily avoid or mitigate an OCI, s/he may implement other remedies to include prohibiting the Contractor’s further participation in contracted requirements.
4 Government-Furnished Information / Resources
None
24 Jan 25 7
5 Contract Deliverables
Milestone/Deliverable Word
Excel
Digital
Copies
PWS
Planned
Frequency
Courseware Yes Yes 2.1 Ongoing access after receipt of initial delivery order
Hardware (if applicable) Yes Yes 2.2
After receipt of delivery orders, hardware/consumables delivered to US sites in 30 business days and to overseas sites in 45 business days. Software access three business days after receipt of a delivery order.
Virtual Professional
Learning Yes Yes 2.3
Dry Runs: Scheduled post-award approximately 30 business days after award.
Finals: Completed five business days after receipt of written feedback from DoDEA to include posting on
DoDEA’s LMS.
Credentialing Yes Yes 2.4 Scheduled post-award
Technical Support Yes Yes 2.5.1 Ongoing after receipt of initial delivery order
Privacy Training Yes Yes 3.2.3 Three days after receipt of a written request
Privacy Verification Yes Yes 3.2.4 120 calendar days prior to the end of each contract year
6 Acronyms and Definitions
PA/PII Privacy Act/Personally Identifiable Information
SCORM® Shareable Content Object Reference Model®
Contract Line Item Number (CLIN): Basic structural element in a procurement instrument describing and organizing the required product or service for pricing, delivery, inspection, acceptance, invoicing, and payment.
The use of the term “line item” includes “subcontract line number”, (SLIN), as applicable.
Contracting Officer (KO) : Only individual with expressed authority to obligate (bind) the Government by means of entering, administering, and terminating contracts within the limits of the authority delegated via a KO’s warrant.
Contracting Officer’s Representative (COR): Qualified and trained Government employee, nominated by the requiring activity (RA) and appointed in writing by a KO primarily to perform specific technical or administrative functions on a specific contract(s); serves as the ‘eyes and ears’ of a KO to assure the Government’s best interests are protected via the terms and conditions of the contract(s) appointed. COR’s do not have authority to obligate
(i.e., bind) the Government.
Contractor: Supplier or vendor contracted to provide specific supplies or services to the Government. The term herein refers to the prime.
Deliverable: Usually physically delivered items but may include such items as digital documents/reports.
Performance Work Statement (PWS): Statement of work for performance-based acquisitions describing the required results in clear, specific, and objective terms with measurable outcomes.
7 Performance Requirement Summary
Performance
Objective
Performance
Standard Acceptable Quality Level Inspection Method
Task 1, Courseware, PWS 2.1
PWS-
compliant
Courseware available 24/7/365 except for scheduled downtimes and no more than one unscheduled down day per semester.
COR inspection and stakeholder feedback
Task 2, Hardware /
Software, PWS 2.2
PWS-
compliant
No more than five precent of orders are delivered late. No more than five percent of ordered resources are damaged or defective.
COR inspection and stakeholder feedback
Task 3, Virtual
Professional Learning, PWS 2.3
PWS-
compliant
No more than one of the PL presentations is completed late, per the schedule finalized post-award.
COR inspection and stakeholder feedback
24 Jan 25 8
Performance
Objective
Performance
Standard Acceptable Quality Level Inspection Method
Task 4, Credentialing
PWS 2.4
PWS-
compliant
No more than one test per year shall need to be rescheduled due to Contractor issues.
COR inspection and stakeholder feedback
Technical Support
PWS 2.5.1
PWS-
compliant
Acknowledge receipt of request within two hours. Resolve 90% of requests in one business day. Resolve remaining 10% in five business days.
COR inspection and stakeholder feedback
Privacy Training
PWS 3.2.3
PWS-
compliant
No more than one certificate per year sent to the COR more than three business days from the date of the COR’s request for it.
COR inspection
Privacy Verification
PWS 3.2.4
PWS-
compliant
Submitted 120 calendar days prior to the end of each contract year.
COR inspection
Technical Exhibit #1 - TECHNICAL REQUIREMENTS
The Contractor shall comply with the applicable technical requirements detailed below.
1.1 Software and Cloud Security Requirements—The Contractor shall:
1.1.1 Ensure all online resources, cloud-based services and instructional software meet Department of Defense
(DoD) and DoDEA cybersecurity requirements as defined below. Note: Software, cloud services and associated websites are rigorously tested to ensure no security risks are posed to DoDEA infrastructure and its users.
1.1.2 Complete the Cloud Services questionnaire that was submitted as part of the proposal submission and provide copies of and/or access to any software listed in the proposed solution.
1.1.3 Ensure on-premises software support post-installation integration of the necessary Security Technical
Implementation Guides (STIG) for applicable systems and applications, including Microsoft Windows
11, Microsoft Windows Server 2016, Windows Server 2019, Microsoft Windows IIS, Apache, Oracle databases, and Microsoft SQL Server databases. Note: The application to obtain the STIG Viewer is found at https://public.cyber.mil/stigs/srg-stig-tools/, and the STIGs themselves may be downloaded from https://public.cyber.mil/stigs/downloads/.
1.1.4 Ensure its content accessible from the web is compatible with the following browser platforms: Google
Chrome, and Edge. Ensure that any applicable STIGs are implemented.
1.1.5 Ensure on-premises software, which is subject to static and dynamic analysis testing, imposes no risk to
DoDEA systems, users and/or data. Note: DoDEA assesses software products to ensure compatibility with existing system configurations and software, testing may also include reverse engineering analysis.
1.1.6 Provide a plan of actions and milestones (POA&M) to mitigate any cybersecurity findings resulting from non-compliant and/or vulnerable components in 30 calendar days of written notification from DoDEA.
1.1.7 Be able to meet Federal Risk and Authorization Management Program (FedRAMP) Level 2 standards for all proposed software/digital resources and ensure that any third-party resources that are part of its proposed solution also meet the FedRAMP Level 2 standard. For more information on FedRAMP, see the following URL: www.fedramp.gov. Participate, if required, in interviews and deep system architecture inspections.
▪ Per DoD policy for cloud-based services, DoDEA conducts a supplemental series of validations, which closely mirror the FedRAMP Internet Cloud vetting processes. Contractor participation/ cooperation is normally required to complete this process.
▪ On a case-by-case basis, DoDEA may honor requests to waive the FedRAMP Level 2 requirement.
1.2 System Requirements—The Contractor shall:
1.2.1 Provide, per Section 1.1 (above), any software installed and/or accessed in or by a DoDEA system, network whether stand-alone or web-based, is compatible with the standards cited herein.
24 Jan 25 9
1.2.2 Provide minimum desktop/server system technical specifications, reference architectures, networking specifications and diagrams, and applicable systems configuration documentation for the proposed solution.
1.2.3 Provide software that is compatible with the following minimum baseline:
Specifications Minimum
Memory 4 GB
Hard Drive 100 GB
Processor Intel® Core™ i5-8365U Processor 8th Generation (up to 4.1GHz, 6MB cache) equivalent or better (Must show benchmark/passmark scores)
Video Graphics Integrated Intel HD Graphics 620 (1920x1080) equivalent or better
Operating System Windows 11
Browser Environment Chrome, Edge, Edge Chromium
1.2.4 Provide software that is completely functional on a standard DoDEA desktop without the need or requirement for administrative-level user rights and/or permissions or the requirement to use or insert external media to execute the software.
1.2.5 Provide software that does not require modifications to folder permissions while executing.
1.2.6 Provide, if applicable, software packages that support unattended installation methods used by enterprise software packaging and deployment systems.
▪ DoDEA currently distributes software packages via Microsoft’s System Center Configuration Manager
(SCCM) and Microsoft Intune.
▪ All older 16-bit software are automatically denied.
1.3 Data Management Requirements—The Contractor shall:
1.3.1 Provide a mechanism for batch administration and automation of routine data management tasks via flat file import, or representational state transfer (REST) based web service application programming interfaces
(APIs). The mechanism shall provision and manage data objects within the Contractor’s system, including but not limited to organizational structures, student accounts, staff accounts, courses, and class rosters.
1.3.2 Provide all necessary documentation and assets to facilitate batch administration and automation of routine data management tasks, including but not limited to roster template files (i.e., comma separated value templates); data element/field definitions documentation; data interchange formats and schemas (XML/
JSON); and/or data dictionaries for the purpose of mapping organizational student information system
(SIS) data to the Contractor’s required input formats.
1.3.3 Provide a single point of contact to support DoDEA in performing the required data integration activities within the Contractor’s system.
1.3.4 Configure DoDEA enterprise within its system and/or databases as the appropriate organizational entity
(i.e., region, district, school) upon a request in writing from the contracting officer’s representative (COR).
Note: DoDEA’s organization hierarchy consists of the following: one system, three regions, nine districts, 62 communities, and 161 schools, including the K-12 virtual school programs.
1.3.5 Participate in a technical meeting with DoDEA within ten business days after award for the purposes of preparing for onboarding of new services and initial configuration of administrator-level accounts.
1.3.6 Ensure the transfer of any Sensitive, Confidential data including but not limited to PII data be transferred in a secure means meeting any requirements set by DoDEA’s Chief Information Security Officer (CISO).
1.4 DoDEA Software License Keys: The Contractor shall provide (1) license keys and electronic downloads for software required under this Contract to the COR and (2) software directly to DoDEA schools, districts, or regions only if explicitly required to do so in the contract or in writing by the COR.
1.5 Cybersecurity Supporting Elements/Requirements and Scalability—The Contractor shall:
1.5.1 Comply with the same Federal law and DoD policies and guidance to which DoDEA is subject that include but are not limited to the cybersecurity requirements defined in the following documents:
▪ DoD Directive (DoDD) 8500.01E, Information Assurance, be found at the following URL:
https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf.
▪ DoD Security Technical Implementation Guidance (STIG), which may be found at the following
URL: https://public.cyber.mil/stigs/downloads/.
24 Jan 25 10
▪ DoD Risk Management Framework (DODRMF) per DoD Instruction 8510.01, which may be found at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001p.pdf?ver=2019-02-
26-101520-3004.5.2.
1.5.2 Provide security patches/upgrades to include third-party applications in response to public-released security vulnerabilities associated with its software solution. Provide a POA&M for any security vulnerabilities within five business days of discovery. Software upgrades/patches shall be included in the licensing cost and be performed at the least disruptive times as determined by DoDEA in writing. Note: Any exception to this requirement must be approved in advance and in writing by DoDEA’s Chief Information Officer
(CIO) or designated official.
1.5.3 Protect DoDEA data against all cyberattacks, notifying DoDEA within 72 hours of an identified and confirmed breach/intrusion.
1.5.4 Perform security incident investigations upon identification of an event or at the request of DoDEA.
1.5.5 Address all information assurance vulnerability messages (IAVM) in the defined timelines to include IA vulnerability alerts (IAVA), IA vulnerability bulletins (IAVB), and technical advisories (TA).
1.5.6 User passwords must not be readable by anyone having access to the system.
1.5.7 Ensure any portion of its solution that involves Internet access by DoDEA students complies with the relevant requirements of the Children's Internet Protection Act, Public Law 106-554, § 1(a)(4) [Div. B, Title XVII, § 1701], Dec. 21, 2000, 114 Stat. 2763, 2763A-335. All Contractor personnel that have access or may potentially have access to DoDEA data in any form shall be US citizens. Note: If its solution does not involve Internet access by DoDEA students, please ensure the following are included:
1) Maintaining system security IAW the latest versions of the (1) DoD Cloud Computing Security
Requirements Guide, (2) Family Educational Rights and Privacy Act (FERPA), and (3) Protection of Pupil Rights Amendment (PPRA).
2) Providing a solution robust enough to serve the needs of a large community of learners dispersed across the world using a variety of bandwidths and scalable to meet future growth, both in terms of instruction and the number of users.
3) Ensuring Contractor staff who have access to DoDEA’s student, teacher and/or staff personally identifiable information take the DoD Privacy Act/Personally Identifiable Information (PA and PPI/PII) training before gaining access to the data and yearly thereafter. Provide copies of the certificates to the COR which can be audited at any time by the CISO or his/her designee.
1.6 Program and System Integration—The Contractor’s solution shall:
1.6.1 Provide Single Sign-On (SSO) Capabilities / Platform which (1) integrates with an Industry Standard SSO login solution. (ClassLink, Google, Azure, etc.); (2) supports Oauth 2.0, Security Assertions Markup
Language (SAML) for integration with Azure, or Google; and (3) authenticates using Azure Active Directory
(AD) or Google AD. Authenticates using Azure Active Directory (AD) or Google AD.
1.6.2. Support industry-standard data rostering standards via ClassLink and standard data formats such as
OneRoster.
1.6.3. Ensure that data storage, handling, and security meet the following minimum standards:
1) DoDEA’s information and data shall be secured in data center located in the United States.
2) The system, including its server(s) and network devices, shall be in an environmentally controlled and secure facility under controlled circumstances (e.g., using authorized personnel access lists, ID cards, entry logs, etc.).
3) All Contractor personnel that have access or may potentially have access to DoDEA data in any form shall be US citizens, including any third-party penetration (PEN)/security testers.
4) All data transit shall be secured with Transport Layer Security (TLS) encryption.
5) All data at rest shall be secured with Advanced Encryption Standard (AES)-256 encryption.
1.6.4 Ensure that data integration includes the following:
1) Automated industry standard form of data integration using Representational State Transfer Application
Program Interface (RESTful API), Learning Tools Interoperability (LTI), or Secure File Transfer
Protocol (SFTP) data sets (ClassLink, OneRoster, etc.).
2) Encryption of DoDEA’s data at rest to include unique encryption keys for each customer on systems hosting multiple customers.
3) Notification of DoDEA in writing within 72 hours of any changes made to corporate policies for data protection.
4) Use of only masked student data in a non-production environment.
24 Jan 25 11
5) Integration scheduling that meets DoDEA’s required timeframes.
6) Provision of fully automated data uploads per Agency schedule(s) and Agency requirements.
7) Support of SFTP capabilities using a single set of login credentials.
8) Provision of a single data set of DoDEA information. Note: The Contractor’s solution shall support
DoDEA at all levels: school, community, district, region, and HQ.
9) Maintenance of a backup and restore plan for DoDEA data in the event of a disaster.
10) Provision of detailed feedback of what caused errors if an integration transmission results in errors.
1.6.5 System Features—The system shall:
1) Allow user accounts to be created automatically based on a file provided by DoDEA either nightly or on another pre-determined scheduled feed.
2) Allow DoDEA to be able to choose the format of user login identification, e.g., an email address, and be able to create manual accounts, if needed.
3) Require the user—for manually created accounts—to reset the password on the user’s initial login or, upon request, a password reset.
File details come from the government source that posted it. Updated .