HMMS Solicitation 21226.pdf

PDF 1 MB Posted

Attached to
Hazardous Material Management System (HMMS) Software and Sustainment Support Federal contract opportunity
Solicitation number
SP470126R0008
Issued by
Defense Logistics Agency

About this file

This is a Request for Proposal (RFP) solicitation for Hazardous Material Management System (HMMS) Software and Sustainment Support from the Defense Logistics Agency (DLA). The Government seeks a contractor to deliver, deploy, and sustain an enterprise-wide internet-based HMMS software suite supporting the Department of War (DoW) and other federal agencies across approximately 100-150 sites. The contract includes a 12-month base period (March 1, 2026 through February 28, 2027) with four optional 12-month renewal periods. Key system components include inventory management, hazard communication compliance, Safety Data Sheet repositories, hazardous waste disposition tracking, and performance-oriented packaging guidance. The solicitation was issued February 12, 2026, with proposals due February 18, 2026 at 12:00 PM EST. Questions are due February 13, 2026. The acquisition is unrestricted (not set aside) with NAICS code 541519 and a $34 million size standard. The contract emphasizes continuous 24/7 operational support, help desk services (Monday-Friday 6:00 AM to 6:00 PM ET), after-hours critical issue support, and performance metrics including 98% weekly system availability.

The contractor must provide comprehensive project management, configuration management, information assurance support, AI-driven automation capabilities, data management, security compliance, software release management, quality assurance testing, and transition support. Personnel requirements include key positions for Project Manager, Database Administrator III, Software Architect II, and various technical support staff with specific IT-level security clearances (IT-I, IT-II, IT-III). The contractor shall establish service ticket response times based on severity levels, ranging from 2 business hours for critical issues to 130 business days for low-priority items. All invoicing must be submitted electronically through Wide Area Workflow (WAWF), with monthly invoicing authorized. The Government reserves the right to award without discussions and will evaluate offers based on technical approach, level of effort/labor mix, key personnel qualifications, and price. Contractor must comply with numerous DFARS and FAR clauses including cybersecurity requirements, NIST SP 800-171 compliance, DoD 8570.01-M information assurance certifications, and various data rights provisions under DFARS 252.227 series clauses.

View the file

Other files for this federal contract opportunity

Other files attached to Hazardous Material Management System (HMMS) Software and Sustainment Support, newest first.
File Type Posted
HMMS Solicitation 21226.pdf PDF
Attachment 2 - Vendor Pricing Sheet.xlsx XLSX spreadsheet
SP470126R0008 0001.pdf PDF
Attachment 1 TO Personnel Summary Resource Allocation.xlsx XLSX spreadsheet
JA HMMS Software and Support Redacted 21226_Redacted.pdf PDF
Attachment 2 Vendor Pricing Sheet.xlsx XLSX spreadsheet
Attachment 3 Key Personnel Resume Template.docx DOCX document
Question Template.xlsx XLSX spreadsheet
Attachment Z VPAT.doc DOC document
Attachment Y DLA Approved CS CE List - 16 May 2023.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS 1. REQUISITION NUMBER PAGE 1 OF

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

2. CONTRACT NO. 3. AWARD/EFFECTIVE 4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE

DATE DATE

SP4 701-26-R-0008 02/12/2026

a. NAME b. TELEPHONE NUMBER (No collect 8. OFFER DUE DATE/

7. FOR SOLICITATION ► calls) LOCAL TIME INFORMATION CALL: Irvin Farmer Ill

(445) 737-1044 02/18/26@ 12 p�

9. ISSUED BY CODE SP4701 10. THIS ACQUISITON IS

!ZluNRESTRICTED OR OsET ASIDE: % FOR:

DLA Contracting Services Office Philadelphia - DCSO-P

DMALL BUSINESS □ EMERGING SMALL

700 Robbins Ave. BUSINESS

Philadelphia, PA 19111 NAICS: 541519

□ HUBZONE SMALL

BUSINESS

SIZE STANDARD $34 MIL: □ SERVICE-DISABLED VETERAN- □ 8(A)

OWNED SMALL BUSINESS

11. DELIVERY FOR FOB DESTINA- 12. DISCOUNT TERMS 13b. RATING TION UNLESS BLOCK IS D 13a. THIS CONTRACT IS A

MARKED NET30-DAYS RATED ORDER UNDER 14. METHOD OF SOLICITATION

□ SEE SCHEDULE

DPAS (15 CFR 700)

□ RFQ D1FB IZIRFP

1 5. DELIVER TO CODE 16. ADMINISTERED BY CODE I

SEE BLOCK9

17a. '-uNTRAl,;TUR/ CODE I I FACILITY 18a. PAYMENT WILL BE MADE BY CODE I OFFEROR

CODE

TELEPHONE NO.

□ 17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

OFFER BELOW IS CHECKED

7 SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA WARE

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA □ARE ARE NOT ATTACHED

!ill 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _1 __ LJ 29. AWARD OF CONTRACT: REF. OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (Type or print)

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

30c. DATE SIGNED 31 b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED

STANDARD FORM 1449 (REV. 3/2005)

Prescribed by GSA - FAR (48 CFR) 53.212

Hazardous Material Management System (HMMS) Software and Sustainment Support

DEFENSE LOGISTICS AGENCY (DLA)

Request for Proposal (RFP) SP4701-26-R-0008

DLA Contracting Services Office -Philadelphia

700 Robbins Avenue

Philadelphia, PA 19111

OPENING DATE: 02/12/2026

CLOSING DATE: 02/18/2026

Combined Synopsis/Solicitation

(1) Date: February 12, 2026

(2) Contracting Office Address:

DLA Contracting Services Office Philadelphia 700 Robbins Avenue, Building Philadelphia, PA 19111

(3) Proposed Solicitation Number: SP4701-26-R-0008

(4) Questions Due Date: February 13, 2026, at 12:00PM EST

(5) Closing Response Date: February 18, 2026, at 12:00PM EST

(6) Contact Point: Irv Farmer (Irvin.Farmer2@dla.mil; 445-737-1044) / Nyeshia McAllister (Nyeshia.McAllister@dla.mil; 445-737-3233)

(7) Submission: Please email proposals on or before closing response date/time to Irvin.Farmer2@dla.mil and Nyeshia.McAllister@dla.mil

(8) Set Aside: NA

(9) NAICS Code: 541519 mailto:Irvin.Farmer2@dla.mil mailto:Nyeshia.McAllister@dla.mil mailto:Irvin.Farmer2@dla.mil

Section 2: Performance Work Statement

The Defense Logistics Agency (DLA) has been tasked by the Department of War (DoW) to deliver enterprise-wide hazardous material and hazardous waste regulatory capabilities to DoW and other federal agencies. These capabilities include:

• Inventory Management: Tracking from acquisition through ultimate disposal, including manifest control.

• Hazard Communication (HAZCOM): OSHA-compliant handling procedures and Globally Harmonized System (GHS) classification and labeling.

• Safety Data Sheet (SDS) Repository: The DoW SDS repository of record, aligned with Fed Standard 313 (current version).

DoW sites requiring HMMS software and sustainment services must comply with international, federal, state, and local regulations. Each of the roughly 100–150 sites differ by:

• Mission: from small repair shops to full teardown and rebuilding facilities; fighter versus tank maintenance.

• Scale: from sites managing hundreds of line items to sprawling industrial bases tracking millions.

• Capability: from robust IT and chemical-SME support to locations with no dedicated HM/HW expertise.

Key HMMS Components

1. Hazardous Material Management System (HMMS) A unified, web-based solution that centralizes HM/HW inventory, tracking, and reporting across DoW and federal sites. HMMS ingests data from HMIRS, POP, and HWD to deliver real-time visibility into material location, quantities, and lifecycle status—from acquisition through disposal. Its configurable workflows automate issue-point scanning, manifest generation, and compliance checks (OSHA, GHS, DOT), while built-in BI dashboards surface key metrics on usage, expiration, and environmental risk. With role-based access controls and an open API framework, HMMS enables seamless integration with ERP, EDI, and external logistics systems—empowering sites of any size or mission to maintain audit-ready records and meet evolving regulatory mandates.

2. Hazardous Material Information Resource System (HMIRS) A secure, web-based application for managing products and SDS records. A specialized team of engineers, chemists, and scientists enriches manufacturer data with GHS labels, HAZCOM warnings, transportation details, contract and logistics information—ensuring all federal personnel have 24/7 access to critical hazard-communication data. HMIRS is the authoritative source for SDS/MSDS across all U.S. military services and civilian agencies, per DoDI 6050.05.

3. Performance-Oriented Packaging (POP) Provides DoW-tested packaging configurations that meet Department of Transportation (DoT) and UN specifications for non-bulk hazardous materials. It guides DoW employees on applicable modal regulations for shipment.

4. Hazardous Waste Disposition (HWD) A cloud-based portal enabling environmental and contracting personnel worldwide to develop, solicit, award, and administer high-quality hazardous waste disposal contracts. Users can access a global network of disposal vendors, submit documentation electronically, and generate on-demand compliance reports. This system is a Finical Feeder system and complies with Internal Control Over Reporting- Financial Reporting (ICOR-FR) policies and requirements.

5. Hazardous Materials Data Warehouse (HMDW) A strategic platform hosting the Chemical Information Program (CIP) and related applications, with EDI integrations for seamless data exchange between upstream and downstream systems.

Support Approach

Because sites are not identical in mission, structure or requirements, the Performance Work Statement (PWS) offers both a comprehensive support package and à la carte services:

• Core Support Package:

o Technical expertise and tier II/III user support o Integrated business-intelligence tools o Regular site visits and software-release forums o Report writing and web-portal assistance o Security-accreditation support under RMF in Microsoft Azure

• Optional Services:

o Data input and retrieval o On-site or virtual functional assistance o Full hazardous material program support o Custom report-writer and data-export training

SCOPE OF WORK

This contract encompasses the delivery, deployment, sustainment, and enhancement of an Internet-based Hazardous Materials Management System (HMMS) software suite, for multiple DoW and other federal agencies.

Specifically, the contractor shall provide:

• Software Delivery & Sustainment o Install, configure, and maintain HMMS and all associated commercial off-the-shelf (COTS) packages.

o Deliver the HMMS source code unencrypted to DLA for Information Assurance activities and troubleshooting.

o Provide regular upgrades, patches, and system‐integration services.

• Project & Configuration Management o Perform full project management (planning, scheduling, risk management, reporting).

o Manage configuration control, versioning, and release processes in accordance with DoW acquisition regulations.

• User Support & Training o Deliver Tier I–III helpdesk services (global support desk).

o Develop and deliver user training materials and courses covering HMMS, HMIRS, POP, and HWD applications.

o Host user training forums and site-visit support.

• Documentation & Reporting o Produce and maintain System Architecture Documents, user manuals, supporting IA artifacts, and all other required deliverables.

o Provide on-demand (ad hoc) compliance and performance reporting tools.

Personnel Qualifications

All proposed staff should demonstrate relevant environmental and/or systems expertise, that may include:

• Domain & Technical Expertise o Hands-on experience with Hazardous Materials Management Systems and sustainment, and/or a degree or practical experience in environmental sciences (e.g., geology, environmental science).

o In-depth knowledge of HMMS, HMIRS, POP, and HWD OR equivalent experience.

o Familiarity with 29 CFR, 40 CFR, and 49 CFR requirements; MSDS/SDS repository management and reporting OR equivalent experience.

• DoW IT & Acquisition Experience o Participation in DoW ACAT II IT programs: program management, systems engineering, cost analysis, configuration management or equivalent experience.

o Proven track record of DoW IT lifecycle compliance audits against DoW acquisition policies.

• Security & Connectivity o Experience supporting cybersecurity validations and control testing (.

o Expertise in DoW security policy, implementation, and remote-site connectivity.

• Sector Familiarity o Understanding of environmental and logistics operations at NASA, U.S. Coast Guard, Army, Navy, Marine Corps, and DLA facilities.

• Communications Skills o Excellent written and oral communication, with the ability to present technical material to senior military and civilian stakeholders.

This combination of software, data-exchange, project management, and subject-matter expertise ensures that HMMS will meet evolving business requirements and regulatory mandates across all user sites. Equivalent experience is always considered in lieu of preferred qualifications.

TASK REQUIREMENT

The Contractor (referred to as the Vendor) will be required to perform tasks such as the following:

Task 1 PROJECT MANAGEMENT SUPPORT 0004-Program Management Task 2 – CONFIGURATION MANAGEMENT 0004-Program Management Task 3 - INFORMATION ASSURANCE 0003- Operational Phase

Task 4 - REQUIREMENTS FOR AI-DRIVEN AUTOMATION AND SOFTWARE DEVELOPMENT 0002- Development Task 5 - DATA MANAGEMENT and - SYSTEM MONITORING / REPORTING 0002- Development Task 6 - SECURITY AND COMPLIANCE 0003- Operational Phase Task 7 - SOFTWARE RELEASE, MAINTENANCE AND ENHANCEMENTS 0003- Operational Phase Task 8 - TESTING AND QUALITY ASSURANCE (QA) REQUIREMENTS 0003- Operational Phase Task 9 - SUSTAINMENT SUPPORT, DELIVERABLES, DOCUMENTATION AND SCHEDULE 0004-Program Management Task 10- SHARED SERVICES 0004-Program Management Task 11 - ONSITE AND VIRTUAL SUPPORT 0004-Program Management Task 12 Travel and Performance 0004-Program Management Task 13- TRANSITION AND CLOSEOUT SUPPORT **OPTIONAL TASK 0004-Program Management

Task 1 – PROJECT MANAGEMENT SUPPORT

SUBTASK A Contract Kick-Off

The Vendor shall schedule a kick-off meeting with the Government within 7 business days of the award or as agreed upon between the Government and Vendor. The Vendor shall prepare and present an executive overview.

The executive overview will demonstrate the Vendor’s plans to manage scope, schedule, and resources for the contract including how the Vendor plans to integrate/transition in with sustainment (monitoring, existing break/fix, triage, and reporting), and existing project support/upgrades, training. The Vendor shall provide DLA Information Operations (J6) management with a key personnel listing and plans for sustaining/replacing (if required) these personnel. The Vendor shall also meet with J6 stakeholders to discuss expectations and details of contract execution within 30 days of the award.

The Vendor shall present and deliver the Kick-off Meeting Briefing Presentation Material and be prepared to discuss the content of the Project Management Plan (see below), to include the staffing plan, schedule, and how they propose to meet performance metrics identified in this PWS. The Vendor shall produce and distribute Kick-off Meeting Minutes, identifying all the discussion points, agreements, and action items within 2 business days following the meeting.

The Vendor shall include an update from the proposal, related to an updated integration plan, i.e., what, and how does the Vendor integrate into existing operations, sustainment, and current priority list (functional and technical) development/migration/upgrade efforts, and updated staffing plan with “who, when where and why” information.

SUBTASK B Project Management / Project Plan The Vendor shall develop a project plan/schedule to accomplish the requirements of this PWS to include, but not limited to set-up, configuration, and fielding of each environment. Project plans will also be developed for major/minor sustainment activities and specific tasks assigned by the Government within the scope of this PWS.

A high-level Project Plan shall be provided during the Kick-off meeting; it shall then be broken into lower details and provided as part of the Monthly Status Report only when changes to the plan occur.

The Vendor shall prepare a Project Management Plan describing the following:

1) Proposed Management Approach

2) Vendor Organization Structure

3) Staffing Plan by Task and by Role

4) Responsibility Matrix

5) Process Management and Control

6) Standard Operating Procedures (SOPs) for the following:

a. 24/7 Helpdesk with Critical Bug call back support within 2 hours through resolution

b. Problem Notification Reports

c. Software Change Requests

7) Agile Software Release Plans and proposed schedules

8) Weekly Scrum Calls

9) EPIC Plan

10) Sprint Plan

11) Acceptance Tests

12) Delivery Process

13) Cybersecurity Plan to support release scans

14) Training Plan

15) Release Documentation

16) Data Dictionary

17) Entity Relationship Diagram

18) Quality Control Plan (QCP)

19) Risk Management Plan as outlined in the DoDI 5000.02

The Vendor shall provide project management services necessary to:

• Establish project governance

• Develop and implement project plans

• Establish communication and escalation procedures

• Support change control processes

• Monitor, control and report project status, schedule, and report performance

• Conduct regular project reviews

• Ensure quality of deliverables.

• Developing, maintaining, and meeting schedule milestones

• Managing risks

• Identifying, and resolving problems

• Keeping the cognizant HMMS Program Management Office (PMO) informed of status and issues

• Managing the Vendor staff.

Note: project plans, communications, monitoring, status updates and other reports do NOT require service ticket(s). Project Management oversight applies to all tasks and sub-tasks assigned to contract staff in accordance with this PWS. The Vendor’s Project Manager shall have demonstrated leadership experience in a work environment of similar size and complexity as outlined in this solicitation. The Vendor’s Project Manager shall serve as a senior contract official and as such is responsible for all contract staff and their deliverables employed in concert with this PWS.

The COR has the responsibility to monitor the progress of the work of the Vendor personnel assigned to the task.

Additionally, in the absence of other agreements negotiated with respect to the time provided for Government review, standards and actions shall be provided to the COR who will submit to the PM, Deputy PM for inspection.

The Vendor’s project management effort shall continue for the entire term of the contract. The Vendor shall be required to update the contract staffing plan monthly. All documentation shall be compatible with the current DLA Microsoft (MS) Office products unless another format is required and agreed to by the Government and the Vendor.

SUBTASK C Performance/Progress/Status Report The Vendor shall monitor activities and deliverables under this requirement and provide a Status Report (SR) that describes project progress, costs, issues, problems, and status. The SR shall be the Vendor’s method of reporting progress against the Project Management Plan (PMP). The period covered by the SR shall include the activities listed below and other SR reported information not satisfied or closed in previous reporting periods, and any required interfaces, meetings, or other commitments. The Vendor shall provide a status report monitoring quality assurance.

If the bi-weekly Status Reports falls on a Holiday, it will be rescheduled as agreed by the government. The report shall include but not limited to:

1) Program metrics

a. Roadmap

b. Project Updates

i. Activities during reporting period, by task (including on-going activities, new activities, activities completed, and/or other funded tasks, progress to date on all above-mentioned activities.

2) System Releases

a. Status of current and planned HMMS, HMIRS, HWD, POP and HMDW releases

3) Engineering Updates

a. Operating System (OS) EOL/Upgrades

b. Database Upgrades

c. Software EOL/Upgrades

d. Cybersecurity

4) Sustainment support

a. System Availability

i. If the system does not meet the weekly 98% minimum threshold, a report is due to issue and root cause no later than the following bi-weekly meeting.

5) Defects / Production Support Tickets

6) Upcoming Program Related Travel

7) Bi-Weekly Planned Meeting Schedule

8) Risk Register and Identified Issues

9) Personnel changes

10) Government actions required

SUBTASK D Risk/Issue Register The Vendor shall apply the risk management approach and plan to develop and maintain a risk register that documents and tracks Vendor and Government identified project risks and issues. For each risk, the register shall include a description of the risk, a rating (high, moderate, low), a description of the impact should the risk occur, and a mitigation strategy. The initial register shall be provided during the Kick-off meeting and then as part of the bi-weekly Status Report each month. The Vendor shall provide the Risk Register in a Vendor- proposed, Government-approved format to the COR who will submit it to the PM, Deputy PM and/or COTR for review/approval.

SUBTASK E Meetings, Briefing, Presentation Material and Support The Vendor shall prepare briefing materials and represent the HMMS PMO at briefings, meetings, and conference calls with organizations of interest, stakeholders, external and internal systems. This representation shall be at a level that functionally and technically represents the HMMS PMO mission and capabilities.

All Vendor-led briefings and meetings shall be conducted in a professional manner. An authorized Government representative will be present at all briefings, meetings, and conference calls. Read ahead and presentation materials should be delivered to the meeting attendees one business day prior to any meetings, briefings or conference calls as required. If meetings, briefings, or conference calls are scheduled less than one business day in advance, the Vendor shall provide read-ahead and presentation material as soon as practical.

SUBTASK F Monthly Plan of Action and Milestones (POA&M) Report The Vendor shall monitor activities and deliverables under this contract and provide a Monthly POA&M report that lists all POA&M progress, issues, problems, and statuses. This report shall be the Vendor’s method of reporting progress against the ticketing timeline of the NTE table within this contract. The period covered by the POA&M report shall include the previous calendar month’s POA&M activities for all active during the reporting period; any issues, actions or other reported information not satisfied or closed in previous reporting periods; and any required interfaces, meetings or other commitments required for POA&M activities.

The Vendor shall provide a Monthly POA&M Report by the 5th business day of the month to the COR who will submit it to the PM, Deputy PM and/or COTR for review/approval. The Monthly POA&M Report shall include, but not be limited to:

1) Service ticket which has surpassed the NTE table and awaiting POA&M creation.

2) Service ticket tracking number POA&M associated with.

3) POA&M accepted date and Government POC who accepted.

4) POA&M due date.

5) Anticipated activity for the next reporting period.

6) Significant meetings.

SUBTASK G Monthly Service Ticket Report A service ticket is defined as a work unit which may be a single Ticket (TKT), Change (CHG) (normal or break fix or enhancement) or project (PROJ). The Vendor shall use the DLA ticketing system, monitor activities, deliverables and provide a Monthly Service Ticket Report. Service Ticket Reports shall lists all in progress, issues, problems, and statuses. This report shall be the Vendor’s method of reporting progress for service tickets.

The period covered by the Monthly Service Ticket Report shall include the previous calendar month’s service ticket activities for all active and closed service tickets during the reporting period; any issues, actions or other reported information not satisfied or closed in previous reporting periods; and any required interfaces, meetings or other commitments required for service ticket activities.

The Vendor shall provide a Monthly Service Ticket Report for each application (HMMS, HMIRS, POP, HWD, HWDW) 24 hours before the scheduled In Process Review (IPR) held by the PMO team. The Monthly Service Ticket Report shall include, but not be limited to:

1) The total number of service tickets submitted and completed during the month.

a. Completed means that customer acceptance occurred.

2) Service ticket assigned date.

3) Service ticket due date according to the NTE table within this contract.

4) Service ticket progress and status.

5) Service ticket completion date if approved.

6) Service ticket POA&M issuance status (if applicable).

7) Required interfaces, action items or escalations.

The Government shall ensure the Vendors' designated personnel have the required system access to the DLA ticketing system. This includes but is not limited to:

1) Training provided to Vendor by DLA ticketing SME.

2) Grant designated Vendor personnel appropriate access to create, pickup, triage, access, and document any tickets, change requests, incidents or projects within the DLA ticketing system.

3) The Government will work with the Vendor to establish APIs as needed to connect the DLA ticketing system to the Vendors ticketing system for reduction in manual reentry efforts required.

Task 1 Deliverables:

• Deliverable 01-01: Contract Start/Award Integration Plan.

Estimated Time: Initial Kick-off, updated as changes occur.

• Deliverable 01-02: Executive Overview.

Estimated Time: 10 business days after award.

• Deliverable 01-03: Kick-off Meeting.

Estimated Time: Within 7 business days after award, Kick-off meeting minutes due within 2 business days following meeting.

• Deliverable 01-04: Non-Disclosure Agreements (NDAs).

Estimated Time: Within 5 business days of Vendor personnel starting on the contract.

• Deliverable 01-05: Project Management/Project Plan/Schedules/WBS.

Estimated Time: Initial High-Level plan overview and proposed schedule at Kick-off, with final draft plan and schedule submitted for approval within 10 business days following the kick-off, then updated within Monthly Status Report only when changes to the plan or schedule occur.

• Deliverable 01-06: Risk Register with Risk Matrix.

Estimated Time: Draft submitted for approval at Kick-off, then updated monthly within the Monthly Status Report.

• Deliverable 01-07: Integrated Master Schedule (IMS).

Estimated Time: Initial IMS 30 days and based on 75 days after Award and then update in the Monthly Status Report on a quarterly basis.

• Deliverable 01-08: Weekly Touchpoints.

Estimated Time: Meeting summary minutes provided no later than 48 hours after the meeting.

• Deliverable 01-09: Monthly Status Report (MSR).

Estimated Time: 5th business day of every month.

• Deliverable 01-10: Meeting, Briefing, Conference Call Presentation Material.

Estimated Time: Two (2) business days prior to any meetings, briefings, or conference calls.

• Deliverable 01-11: Daily/Weekly Production Support Call Participation (Including Updates and Inputs).

Estimated Time: As requested by the COR.

• Deliverable 01-12: Staffing Plan.

Estimated Time: Follow Deliverable 01-05 as part of the management plan. Initial at Kick-off, then staff changes occur.

• Deliverable 01-13: Analysis/Performance/Progress/Status Reports.

Estimated Time: As changes occur and delivered, and/or as requested by the COR, no less than annually and yearly (at end of contract performance).

• Deliverable 01-14: Monthly Plan of Action and Milestones (POA&M) Report.

• Deliverable 01-15: Monthly Service Ticket Report.

Task 2 – CONFIGURATION MANAGEMENT Configuration Management (CM) and the efficient delivery of software and supporting documentation are essential for maintaining uninterrupted operation and security of all applications and services. These activities shall be performed throughout the life of the contract, with deliveries as specified herein. The Vendor shall be prepared to utilize any Configuration Management tool designated by DLA Information Operations during the contract period.

SUBTASK A Change Management and CM Plan The Vendor shall support and execute robust change management processes. The Vendor shall develop and maintain a Configuration Management (CM) plan that addresses product management and version control for all hardware and software components in accordance with DLA guidance and policies. The CM plan shall ensure the ability to recreate all baseline deliveries from any point in time and must address configuration identification, configuration control, administration, application software, and documentation management.

Tracking and Documentation in alignment with current DLA INFO OPS Configuration Management guidance, the Vendor shall establish procedures for tracking service tickets and software changes. The current guidance will be provided by the Government upon request.

SUBTASK B Objectives of Configuration Management The Configuration Management process shall achieve the following objectives:

1) Identify, define, and control all relevant configuration items.

2) Establish a process for addressing unauthorized changes.

3) Control modifications of all configuration items.

4) Record and report the status of configuration items and modification requests.

5) Ensure the completeness of the configuration items.

6) Control the storage, handling, release, and delivery of the configuration items.

SUBTASK C Specific Vendor Responsibilities:

• Establish and control product attributes and the technical baseline throughout the system lifecycle.

• Identify, document, audit, and control the functional and physical characteristics of the system design;

track changes; and provide an audit trail of design decisions and modifications.

• Provide review and support of Configuration Control Working Group (CCWG) activities and processes.

• Ensure Configuration Management efforts are aligned with the Government CM plan.

SUBTASK D Configuration Control Governance Meetings The Vendor shall assist the Government in preparing for and participating in routine and special Configuration Control governance meetings, including those of the Configuration Control Working Group (CCWG), as required by the governance structure. The Vendor may also be required to attend In Process Reviews (IPRs), meetings with integration/interface representatives from internal and external systems, and special working group sessions as requested by the COR.

2.3.2.5 Task 2 Deliverables:

• Deliverable 02-01: Configuration Management (CM) Plan.

Estimated Time: At the beginning of the period of performance, then midway through the period of performance, and then updated as changes occur.

Task 3 - INFORMATION ASSURANCE SUBTASK A Cybersecurity, Risk Management Framework (RMF) & Artifact Support The Vendor shall provide qualified personnel and maintain ongoing collaboration with the cognizant Program Office and DLA Cybersecurity teams to ensure full compliance with DLA Cybersecurity, RMF, and Artifact requirements in support of obtaining and maintaining Authority to Operate (ATO).

SUBTASK B Standards, Protocols, and Compliance The Vendor shall review, coordinate, and recommend cybersecurity standards and protocols for cost-effective application in alignment with the Department of War’s (DoW) Defense in Depth (DID) strategies. The Vendor shall ensure adherence to all applicable Federal, DoW, and DLA information technology and security requirements, policies, procedures, and standards.

SUBTASK C Security Analysis and Recommendations The Vendor shall perform analysis to validate established security requirements and recommend additional measures as needed. For any detected vulnerabilities, the Vendor shall recommend and implement management, operational, or technical controls—including human procedures, software configuration parameters, and system changes—to mitigate associated risks and support accreditation.

SUBTASK D Technical Compliance and Vulnerability Management The Vendor shall comply with all relevant Security Technical Implementation Guides (STIGs) and support ongoing cybersecurity vulnerability scans, testing, and evaluation. The Vendor shall analyze the results of vulnerability scans, assess STIG compliance, and address any deficiencies identified during internal or external cybersecurity reviews.

SUBTASK E Information Assurance and ATO Support The Vendor shall support Information Assurance (IA) and ATO implementation planning and validation activities.

This includes attending all relevant cybersecurity meetings and providing expert recommendations and guidance for mitigation and remediation efforts.

SUBTASK F Vulnerability Remediation Timelines The Vendor shall remediate vulnerabilities identified through system scans according to the following timelines, unless a variance is approved by the Government:

Vulnerability with exploits available and exploitable from the internet Less than 1 day Critical vulnerability with no known exploits Within 7 days High vulnerability with no known exploits Within 21 days Moderate vulnerability with no known exploits Within 45 days Low vulnerability with no known exploits Within 60 days

a. Items declared Cyber related shall be completed as directed by DoW or DLA J62, these may be out of cycle deliveries with timeframes that DoW mandates. Please reference the Control Correlation Identifier (CCI) Definitions and Implementation Guidance DoDI 8580.1.

SUBTASK G Department of War Architectural Framework (DoWAF) The Vendor shall provide services that assist DLA in complying with the Department of War Architectural Framework (DOWAF). The Vendor shall provide support to assess/validate DoWAF artifacts. The Vendor shall provide support for DoWAF implementation planning and validation. The Vendor shall support conformance with the current DoWAF Architecture Framework version and ensure all documentation is DoWAF compliant.

Task 3 Deliverables:

• Deliverable 03-01: System Scan Remediation Plan

Estimated Time: As requested by the Program Office

• Deliverable 03-02: Cyber Security Artifacts Estimated Time: As changes occur and/or as requested by the Program Office

• Deliverable 06-03: DoWAF Artifacts.

Task 4 - REQUIREMENTS FOR AI-DRIVEN AUTOMATION AND SOFTWARE DEVELOPMENT

The scope and effectiveness of all AI-driven solutions described herein are contingent upon the Vendor’s ability to deploy, integrate, and operate AI tools and resources with the Government-controlled environments. Any limitations in access, compatibility, or authorization for AI technologies within these environments may impact the extent and functionality of the solutions provided.

SUBTASK A Automated Software Testing and Development

The Vendor shall implement automated software testing and development methodologies. This includes utilizing

AI-driven tools for continuous integration, automated code analysis, and quality assurance to enhance software quality and reduce development time.

SUBTASK B AI-Driven System Monitoring and Anomaly Detection The Vendor shall deploy AI-driven system monitoring capable of real-time performance tracking, automated detection of abnormal system behavior, and predictive maintenance. These capabilities shall be used to anticipate and prevent system failures.

SUBTASK C Predictive Maintenance The Vendor shall apply AI algorithms to analyze system data in order to predict maintenance requirements. This approach will optimize maintenance schedules and minimize system downtime.

SUBTASK D Process Automation for Repetitive Tasks The Vendor shall identify repetitive manual tasks and implement process automation solutions. Areas of focus include, but are not limited to, data entry and report generation.

SUBTASK E AI-Powered Data Analysis and Reporting The Vendor shall utilize AI-powered data analysis and reporting tools to extract actionable insights from operational data. Comprehensive reports and visualizations shall be provided in a Government-specified format, in compliance with all applicable data security and privacy regulations. These reports will support data-driven decision-making and performance optimization.

Task 4 Deliverables:

• Deliverable 04-01: AI tool integration plan

• Estimated Time: As tools and solutions are developed and then updated as changes occur.

• Deliverable 04-02: AI software development and testing methodologies

Estimated Time: As tools and solutions are developed and utilized, prior to delivering AI-assisted solutions, and then updated as changes occur.

Task 5 - DATA MANAGEMENT AND SYSTEM MONITORING/REPORTING SUBTASK A Electronic Data Interchanges and/or Data Exchange Support:

The Vendor providing HMMS Software and sustainment support at the time of award, shall have the existing capability to move data electronically, bi-directionally, through eXtensible Markup Language (XML), Defense Logistics management Standards (DLMS) Electronic Data Interchanges (EDI) via Defense Automated Addressing System, Secure File Gateway (SFG), SSH File Transfer Protocol, IBM MQ and other means of data exchange.

The Vendor will design modernization EDI Transactions according to new customer needs, DoW and Industry Standards, and changing DLMS Policy. Refer to section 1.3.8.1 New Project Acceptance Criteria; to determine the process the vendor will follow for new EDI projects and requirements.

Current Electronic Data Interchanges that shall continue to receive sustainment and maintenance are located in the vendor’s HMMS Program Master Interface Reference and referenced below:

1) HMMS Interfaces

• EDI 1.1 - WMS/E2 (Formally DSS) HMMS HM Inventory Interface

• EDI 1.2 - 856S Turn-In Transaction

• EDI 1.3 - 841W Waste Profile Transaction

• EDI 1.4 - 824R Reject/Accept Transaction

• EDI 1.5 - 527R Receipt Acknowledgement Transaction

• EDI 1.6 - HMIRS Interface with Distribution (DLANC)

• EDI 1.7 - FLIS HMMS NSN Information SFG Connection

• EDI 1.8 - GECO – GSA Enhanced Checkout Interface

• EDI 1.9 - Hazardous Materials Usage Interface to HMDW

2) HMIRS Interfaces

• EDI 4.1 - FLIS Item (NSN) Verification Interface

• EDI 4.2 - FLIS CAGE Verification Interface

• EDI 4.3 - LMIA FLIS Interface

• EDI 4.4 - SAIC Delivery Order Interface

• EDI 4.5 - NIIN Subscription Interface

• EDI 4.6 - HMMS SDS Integration and Import Interface

• EDI 4.7 - SDS Outbound Connector Interface

• EDI 4.8 - CHEM/ISP Integration API

3) HWD Interfaces

• EDI 2.1 - 856S Turn-In Transaction

• EDI 2.2 - 841W Waste Profile Transaction

• EDI 2.3 - 824R Accept/Reject Transaction

• EDI 2.4 - 527R Receipt Acknowledgement Transaction

• EDI 2.5 - 14725 HIN Price from eProc Transaction

• EDI 2.6 - 14355 Contract Details from eProc Transaction

• EDI 2.7 - 14724 Request to eProc Transaction

• EDI 2.8 - 14726 Award from eProc Transaction

• EDI 2.9 - 14728 Modification to eProc Transaction

• EDI 2.10 - 861 Payment Authorization Request to eProc Transaction

• EDI 2.11 - 820 Payment Confirmation from eProc Transaction

• EDI 2.12 - 14729 Closeout to eProc Transaction

4) HMDW Interfaces

• EDI 5.1 - SDS Outbound Connector Interface

• EDI 5.2 - Hazardous Materials Usage Interface

• EDI 5.3 - FLIS Item (NSN) Interface

• EDI 5.4 - FLIS CAGE Interface

SUBTASK B Application Administration Support The Vendor shall demonstrate proficiency in application administration, application security, and web administration to effectively operate, maintain, and administer the HMMS, HWD, HMIRS, POP and HMDW applications and services covered under this contract. The Vendor shall support all aspects of installation, implementation, administration, and maintenance for hosting environments, including Continuity of Operations (COOP) as applicable.

SUBTASK C Operations and Maintenance Responsibilities The Vendor shall:

• Monitor and capture performance issues, providing recommendations and plans for Government-approved application upgrades, updates, and enhancements.

• Execute deployment tasks across all environments, including Staging (STAGE), and Production (PROD).

• Troubleshoot and resolve application-related problems, coordinating with system administrators and other stakeholders as necessary.

• Implement Government-approved systems at specified locations, including COOP and backup sites.

• Ensure all mission hardware, software operating systems, and applications remain current by installing required security, upgrade, and functional patches in accordance with the configuration management plan and DoW security policies.

• The Government will perform routine backups and configuration management for all HMMS Portfolio solutions, ensuring that all equipment and software are maintained to keep performance within acceptable tolerances.

SUBTASK D Collaboration and Non-Core Hours Support The Vendor shall anticipate that approximately 5% of work hours may be required during non-core hours. When necessary, the Vendor shall coordinate with external DoW agencies (such as Microsoft) to resolve issues and ensure uninterrupted system operations.

Task 5 Deliverables:

• Deliverable 05-01: HMMS Program Master Interface Reference

• Deliverable 05-02: Monitoring tool deployment documentation

Estimated Time: As requested by the Government

• Deliverable 05-03: Operations & Maintenance Plan

Estimated Time: As requested by the Government and then updated as changes occur.

• Deliverable 05-04: Non-Core Support Procedures

Estimated Time: As requested by the Government and then updated as changes occur.

Task 6 - SECURITY AND COMPLIANCE SUBTASK A Access to Sensitive Information The provisions listed below apply to the Prime Vendor and any sub-Vendors the Prime Vendor may employ during this contract.

This Project is categorized as unclassified.

Vendors are required to comply with the DoD 5220.22-M National Industrial Security Program Operating Manual (NISPOM) in the handling, protection, and safeguarding of classified information in their possession. Security requirements outside the scope of the NISPOM, if required, will be defined in the accompanying DD Form 254.

Personnel security investigations conducted for access to classified information will be conducted by the appropriate DLA Security Team.

SUBTASK B IT Level Investigation Requirements Vendor personnel, who perform work on sensitive IT systems or applications will be required to obtain and maintain the appropriate investigation and adjudication or suitability determination commensurate with the information contained within the application or system. Vendor personnel will be assigned to positions which are designated at one of three levels (IT-I, IT-II, IT-III) based on the actions or tasks to be performed. The Vendor shall assure that individuals assigned to the positions, as determined by the Government, have obtained the proper eligibility as required by DODI 5200.2. The table below defines the labor categories within the contract and the IT-Level position category assigned to each employee. Note that IT-Level position category designation does not imply or convey access to classified information. Instructions for access to classified information, if necessary, will be included on the DD Form 254 attached to this contract.

Labor Category IT-Level Investigation Requirement Refer to PWS Section 2.6.2 IT-I Tier 5 Refer to PWS Section 2.6.2 IT-II Tier 3 Refer to PWS Section 2.6.2 IT-III Tier 1

DLA requires that all Vendor personnel, assigned to this project shall have attained a favorable outcome to the designated IT investigative requirement assigned to each labor classification and be available to initiate work immediately upon delivery order award. IT-Level position categories are designated based on access to government networks and IT systems and may exceed classified access requirements for Hazardous Material Management System (HMMS) Software and Sustainment.

For IT-I, IT–II, and IT-III positions, the required investigation shall be completed, or interim access granted for individuals assigned sensitive duties. The provisions outlined above apply to the prime Vendor and any sub- Vendors the prime Vendor may employ during the course of this contract. In lieu of the correct investigations being completed when contract employees start, a waiver may be submitted if no issues exist within the OPM e- QIP Questionnaire for Public Trust Positions. The Vendor shall have the OPM e-QIP forms filled out, with any other requirements (fingerprints taken and, if required, an OF306), and reviewed by DLA Intelligence before officially hiring any Vendor employee into IT positions. Foreign Nationals are only eligible to perform non-sensitive duties and will not be investigated by the US Government.

DLA retains the right to request the removal of Vendor personnel, regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, clearly conflict with the interest of the Government. The reason for the removal shall be documented in writing by the Contracting Officer. When and if such removal occurs, the Vendor shall, within a two to four-week timeframe, assign qualified personnel to vacancy(s) thus created regardless of whether the individual was in a key- or non-key personnel position. Current personnel security investigations conducted for access to classified information may satisfy investigation requirements for IT-Level position investigations. All other IT- Level position investigations will be performed by the DLA Personnel Security Office.

SUBTASK C DOD 8570.01-M, Information Assurance Workforce Improvement Program The DoD 8570.01-M, Information Assurance Workforce Improvement Program, requires training and certification for IA duties performed. All contract employees performing IA functions shall meet the requirements in accordance with DoW/DLA guidance. Additionally, all contract employees shall be certified in operating systems on any system on which System Administration duties are performed. Proof of certification shall be provided before Privileged access is granted, at time of proposal/resume submission; this includes, but is not limited to, system administration access, network administration access, router/switch access, firewall access, and Intrusion Detection System access. All documentation required for security certification will be maintained by both the Vendor and the Government. All contract employees will have acquired the necessary certification requirements, per DOD 8570.01, throughout the entire period of performance of the contract requirements. These certification requirements are not based on position title; they are based on duties. Refer to Attachment Y:

8570.01-M Certification Matrix; 8570.01-M Approved Baseline Certifications; and Computing Environment Certification List.

The Vendor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. The Vendor shall meet the applicable information assurance certification requirements, including:

DoW-approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01-M; and

Appropriate operating system certification for information assurance technical positions as required by

DoD 8570.01-M.

Upon request by the Government, the Vendor shall provide documentation supporting the information assurance certification status of personnel performing information assurance functions.

Vendor personnel who do not have proper and current certifications shall be denied access to DoW information systems for the purpose of performing information assurance functions.

Reference: http://www.acq.osd.mil/dpap/dars/dfars/html/current/252239.htm.

http://www.acq.osd.mil/dpap/dars/dfars/html/current/252239.htm

SUBTASK E Software The Vendor shall observe all copyright agreements and shall be held liable for any infringement of copyrighted software licensing agreements and shall compensate the appropriate Vendor for each instance of copyright violation. In the interest of protecting Government systems from computer viruses, the Vendor shall not use public domain software, nor shall Vendor personnel download software from public bulletin boards. The Vendor shall use only COTS, Vendor-developed, or Government-furnished software in the performance of this statement of work. The Vendor shall use the Microsoft Office suite of software for the preparation of all documentation required in the delivery order. Should the introduction of a computer virus or malicious destruction of computer software, stored information, or hardware result from the use of public domain software or from software taken from a public bulletin board, the Vendor shall be required to repair the damage at no expense to the Government and without impact on delivery schedules or daily operation.

SUBTASK F Data Use, Disclosure of Information and Handling of Sensitive Information (including Personally Identifiable Information) The Vendor will maintain, transmit, and retain strictest confidence, and prevent unauthorized duplication, use, and disclosure of information. The Vendor will provide information only to employees, Vendors, and sub-Vendors having a need to know such information in the performance of their duties for this project.

Information made available to the Vendor by the Government regarding the performance or administration of this effort shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer. Vendor personnel will be required to sign a non-disclosure statement.

If proprietary information is provided to the Vendor for use in performance or administration of this effort, the Vendor may not use such information for any other purpose except with the written permission of the Contracting Officer. If the Vendor is uncertain about the availability or proposed use

Task 6 Deliverables:

• Deliverable 06-01: Confirmation of compliance and completion of 8570 training

Estimated Time: As requested by the Government.

Task 7 - SOFTWARE RELEASE, MAINTENANCE AND ENHANCEMENTS

SUBTASK A New Project Acceptance Criteria and Process When the Government or an entity acting on behalf of the government wishes to introduce a new project for construction, they will inform the vendor via the Business Requirements process described below. Projects subject this this process are those of a large nature and are not considered regular customer enhancements. Large enhancements are either major changes to the existing application or new functionality, to include Electronic Data Interchanges (EDI).

1. The government will complete a preliminary business requirements document (BRD) that describes the problem statement that needs to be solved. Other supporting information is included in the BRD. The Vendor will work with the Government to provide the BRD template. Changes to the BRD may be authorized given mutual agreement.

2. Upon receipt of the initial BRD, the vendor will engage in preliminary discovery in order to understand the scope of work. The timeline of discovery is subject to complexity and dependencies with external stakeholders.

3. The vendor will then complete the remainder of the BRD exercise and determine the level of effort. The vendor will then generate a Rough Order of Magnitude (ROM).

4. The vendor will deliver the ROM to the Government via electronic mail. The Government may request a virtual meeting to discuss the contents of the ROM, and the vendor will comply.

5. Upon initial acceptance of the ROM, the vendor will work with the Government to determine roadmap placement.

6. Once roadmap placement is agreed upon, the Government will furnish a Performance Work Statement (PWS) to the vendor for review. The vendor shall be provided with seven working days to respond to the PWS with clarifications or recommended changes or additions.

7. The PWS will then endure the Government PWS process and be submitted to the vendor for legal and contract review.

8. Once the PWS process is complete, the development roadmap will be updated and reflected in the next bi-weekly status update.

9. Any changes or additions to the agreed upon project requirements are subject to rescoping and possible roadmap disruption and replacement.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .