SSN NFNC-2026- 0310 PWS H2TNG2.pdf

PDF 4 MB Posted

Attached to
HUD Technology Transformation Next Generation Program Federal contract opportunity
Solicitation number
NFNC20260310
Issued by
Department of Housing and Urban Development

About this file

This is a Performance Work Statement (PWS) for the HUD Technology Transformation Next Generation (H2TNG) contract, dated April 7, 2026, issued by the U.S. Department of Housing and Urban Development Office of Chief Information Officer (OCIO).

The H2TNG is a multiple-award indefinite-delivery/indefinite-quantity (IDIQ) contract vehicle designed to provide comprehensive IT Support Services and Technology Transformation solutions across HUD headquarters, regional and field offices, data centers, and designated locations. The scope encompasses support across eight OCIO functional areas: OCIO front office, Assistance Chief Information Officer Business IT Resource Management (ACIO BIRM), Office of Chief Technology Officer (OCTO), ACIO Customer Relationship & Performance Management (ACIO CRPM), Office of Chief Information Security Office (OCISO), ACIO Office of Infrastructure & Operations (ACIO OIO), Office of the Artificial Intelligence Officer (OAIO), and Office of Digital Business Officer (ODBO). Individual task orders (TOs) may include enterprise performance and risk management, policy development, requirements analysis, program management, standards development, technology refresh, studies and analyses, quality assurance, systems/software engineering, test and evaluation, independent verification and validation, enterprise network support, cybersecurity operations, privacy compliance, records management, customer experience initiatives, training delivery, and IT facility services. The contract covers the full system lifecycle including development/modernization/enhancement, integration and deployment, operations and maintenance, and decommissioning. Contractors must maintain ISO 9001 Quality Management System Certification and CMMI Maturity Level 5 certifications, possess appropriate security clearances, comply with all federal cybersecurity and privacy requirements (including FISMA, NIST standards, and OMB memoranda), undergo personnel background investigations, and submit quarterly reporting on contract performance, Government-furnished equipment, personnel staffing, small business participation, and veterans employment. Services must be delivered nationwide within the United States, U.S. commonwealths, and unincorporated U.S. territories, with travel to HUD locations as required by individual TOs.

View the file

Other files for this federal contract opportunity

Other files attached to HUD Technology Transformation Next Generation Program, newest first.
File Type Posted
NFNC 4-8 H2NG2-2026-0301 Sources Sought Notice.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HUD Technology Transformation Next Generation

Table of Contents

C.1 SCOPE

C.2 APPLICABLE DOCUMENTS

C.3 GENERAL REQUIREMENTS

C.4 TECHNICAL FUNCTIONAL AREAS

C.5 DELIVERABLES

C.6 SECURITY AND PRIVACY

C.7 REPORTING AND MEETING REQUIREMENTS

Performance Work Statement (PWS) for the

DATE: April 7, 2026

United States Department of Housing and Urban Development Office of Chief Information Officer

(US Department of HUD OCIO)

C.1 SCOPE

Under the HUD Technology Transformation Next Generation Performance Work Statement (H2TNG PWS), the Contractor shall deliver comprehensive IT Support Services and Technology Transformation Next Generation (ITSS and 2TNG) solutions across HUD Headquarters (HQ), regional and field offices, data centers, and other designated locations. Support shall span the functional areas of the Office of Chief Information Officer (OCIO), including but not limited to:

OCIO front office

Assistance Chief Information Officer Business IT Resource Management (ACIO BIRM)

Office of Chief Technology Officer (OCTO)

ACIO Customer Relationship & Performance Management (ACIO CRPM)

Office of Chief Information Security Office (OCISO)

ACIO Office of Infrastructure & Operations (ACIO OIO)

Office of the Artificial Intelligence Officer (OAIO)

Office of Digital Business Officer (ODBO)

C.1.1 Scope of Support

Individual TOs (TOs) may include support request for, but are not limited to:

Enterprise performance & risk management, performance management, project health assessments, risk planning, TechStat management, audit response development, communications, OCIO communications and channels, governance, annual strategic planning, customer care committee board, policy management, contract management, adjudication of contracts requesting onsite performance by contractors, acquisition management, acquisition coordination, asset requisition, COR support, administrative management, leadership and employee development and training support, telework/remote work support, reasonable accommodations, timekeeping, travel, space manage, supplies, workforce planning and talent management, financial management, budget execution, budget formulation and capital planning, micro-purchases, spend plan management, customer experience (CX), employee experience (EX), enterprise architecture, capabilities and standards, solution engineering, technical governance, technology strategy, technical solutions, analytics and reporting, cloud applications, custom development, data services, emerging technology, systems/software engineering, software technology demonstration and transitions, test and evaluation (T&E), independent verification & validation (IV&V), acquisition support, acquisition engagement and support, contract management support, budget formulation & capital planning, business need intake for pre-select phase, business need and case/select phase support, budget support, budget management and support, customer engagement, customer centric communication, customer relationship management, FITARA, FITARA request process facilitation, open government, audit and policy response facilitation, program & project management (P/PM), IT asset management, project lifecycle management, governance, risk & compliance, enterprise management framework (EMF), cybersecurity policies and procedures, FISMA CIO Quarterly/Annual Data Calls, plans of action and milestones (POA&Ms) tracking, security assessments, cyber incident response team (CIRT), security operations center (SOC), threat intelligence, Information System Security Officer (ISSO) support, phishing exercises, security awareness and training, security architecture, data loss prevention, Zero Trust Architecture (ZTA), end-to-end lifecycle O&M support for program office systems, accounts & access, data center access management and support, DIAMS administration and support, DIAMS requests, asset management, hardware (H/W) and software (S/W) asset management, audit & reporting compliance, audit support, DHS/CIS BOD Reporting, configuration & release management, patch planning, existing device support, checkout inventory, Headquarters (H/Q) printer support, power outages, printer support, workstation moves, field support, enterprise application support, testing and deployment of new technologies, IT training, H/W, assistive technology (AT) & training resources, IT and operations & maintenance (O&M) support, IT and DME (development, modernization, and enhancement) support, IT and integration and deployment (I&D) support, end user support, network support, telecommunication support, updating outlook distribution lists, data center network security administration, data center network administration, email support, fiber cabling, IP address management, LAN administration, network operation pilots, regional and field office moves, remote access systems support, service desk ticket management, system/performance monitoring, system XID approvals, Tiger Team testing and troubleshooting, VoIP support, Video Teleconferencing (VTC) HQ support, WAN administration Wi-Fi administration, security management, antivirus management, Continuous Diagnostic Monitoring (CDM) administration, Enterprise Mobility Management (EMM), log monitoring and event management, security assessment, security configuration settings management (CSM), vulnerability scanning, system support, data center application support, data center asset and quality management and support, data center cloud management and support, data center database administration, data center mainframe administration, data center middleware administration, data center network administration, data center production control, data center security compliance, data center server administration, event support, IT facilities;

and other solutions encompassing the entire spectrum of IT and IT requirements, to include software and hardware incidental to the solutions.

Contractors shall deliver scalable, secure, compliant, and customer-focused solutions under individual TOs that specify outcomes, service levels, and delivery locations.

C.1.2 IT Product Acquisition

Individual orders may include the acquisition of software and hardware IT products necessary to implement the required solution or capability when such products aren’t readily available through HUD’s existing Blanket Purchase Agreements (BPAs) for hardware, software, and/or cloud services.

The H2TNG multiple award vehicle is not intended to serve solely as a vehicle for purchasing IT products; however, products may be acquired when they are essential to delivering the specified solution or capability.

After delivery, these products will be transitioned to HUD’s Hardware, Software, and

Cloud BPAs for ongoing lifecycle support and replacement.

ITSS, and related IT products, may cover the full system lifecycle.

Contractors must be prepared to provide services and deliverables nationwide, including the United States (U.S.), the U.S. commonwealths, and unincorporated U.S. territories.

C.1.3 Functional Area Requirements

The H2TNG PWS outlines general requirements, while specific requirements will be defined in individual TOs. Functional area requirements, described in Section 4.0 - Technical Function Areas, are not mutually exclusive; many requirements will span multiple areas to deliver a comprehensive, end-to-end lifecycle solution.

For this contract, end-to-end lifecycle refers to all phases of the product lifecycle, including:

Development, Modernization, & Enhancement (DME)

Integration & Deployment (I&D)

Operations & Maintenance (O&M)

Decommissioning and End-of-Life (EOL)

C.2 APPLICABLE DOCUMENTS

The Contractor shall comply with the documents listed below. Additional documents may be listed in individual TOs.

1. 44 U.S.C. § 3554, “Federal Information Security Modernization Act of 2014”

2. 44 U.S.C. 3551-3558, “Cybersecurity Improvements to Agency Information

Systems”

3. 41 U.S.C. § 1321-1328, Federal Acquisition Supply Chain Security Act.

4. Federal Information Processing Standards (FIPS) Publication 140-3, “Security

Requirements for Cryptographic Modules”, April 1, 2022

5. ISO/IEC 19790:2025, Information Security, cybersecurity and privacy protection –

Security requirements for cryptographic modules, Edition 3, 2025.

6. 18 U.S.C. § 278g-3a, Internet of Things Cybersecurity Act.

7. 44 U.S.C. § 3607-3616, FEDRAMP Authorization Act

8. FIPS Pub 199. “Standards for Security Categorization of Federal Information and

Information Systems,” February 2004

9. FIPS Pub 200, “Minimum Security Requirements for Federal Information and

Information Systems,” March 2006

10. FIPS Pub 201-3, “Personal Identity Verification of Federal Employees and

Contractors,” January 24, 2022

11. 10 U.S.C. § 2224, "Defense Information Assurance Program"

12. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

13. Cyber Information Security Agency Binding Operational Directive 22-01 and its successors

14. HUDAR 2452.239-70 (Access to HUD systems) Part of HUD Procurement

Handbook 2210.3, March 31, 2017

15. NIST SP 800-83 Rev 1, Guide to Malware Incident Prevention and Handling for

Desktops and Laptops, July 2013

16. NIST SP 1800-25, Data Integrity: Identifying and Protecting Assets Against

Ransomware and Other Destructive Events, December 2020

17. NIST SP 800-61 Rev 3, Computer Security Incident Handling Guide, April 3, 2025

18. NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems

Organizations, September 2020

19. OMB M-21-31, Improving the Federal Government’s Investigative and Remediation

Capabilities Related to Cybersecurity Incidents

20. OMB Memorandum M-22-09, "Moving the U.S. Government Toward Zero Trust

Cybersecurity Principles

21. OMB M-25-22, "Driving Efficient Acquisition of Artificial Intelligence in

Government

22. OMB M-19-17, "Enabling Mission Delivery through Improved Identity, Credential, and Access Management

23. OMB Memorandum M-19-03, "Strengthening the Cybersecurity of Federal Agencies by Enhancing the High Value Asset Program,"

24. Executive Order 14306, June 6, 2025, "Sustaining Select Efforts to Strengthen the

Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order

14144,"

25. HUD CPO, AS-2315 Cybersecurity and Privacy Requirements (APRIL 2022)

26. HUD Handbook 2400.1 - Information Resources Management (IRM) Policies

27. HUD Handbook 2400.25 - Information Technology Security Policy

28. HUD Handbook 2400.25 - Vulnerability Disclosure Policy

29. HUD Handbook 3150.1 - Breach Notification Policy and Response Plan Rev 1.0

30. HUD Handbook 3250.1 - HUD Business Process Improvement

31. HUD Handbook 3251.1 - Secure Configuration Management Policy

32. HUD Handbook 3252.1 - Software Configuration Management Policy

33. HUD Handbook 3253.1 - Change Management Policy

34. HUD Handbook 3254.1 - Enterprise Patch Management Policy

35. HUD Handbook 3255.1 - Enterprise Architecture Policy

36. HUD Handbook 3256.1 - Information Technology Asset Management Policy

37. HUD Handbook 3260.1 - Enterprise Data Management (EDM) Policy

38. HUD Handbook 3262.1 - Software Acquisition Capability Maturity Model Policy

39. HUD Handbook 300.00.1 - Total Information Quality Management

40. HUD Handbook 3400.1 - HUD Policy for IT Management Framework

41. HUD Handbook 3410.1 - HUD Policy for Information Technology Governance

42. HUD Handbook 3417.1 - Web Application Policy

43. HUD Handbook 3425.1 - HUD Policy for Information Technology Strategic Planning

44. HUD Handbook 3430.1 - HUD Policy for Agile Methodology Rev. 1

45. HUD Handbook 3435.1 - HUD OCIO Risk Management Policy

46. HUD Handbook 3440.1 - HUD OCIO Techstat Policy

47. HUD Handbook 3500.1 - HUD Source Code Policy

48. HUD IT Capital Planning and Investment Control Process Guide, October 2020

49. HUD Handbook 2300.2 - Travel Handbook

50. HUD Handbook 1325.1 - HUD Privacy Handbook Rev. 1.0

51. HUD Handbook 1750.1 - Information and Administrative Security Program

52. HUD Handbook 1751.1 - HUD Controlled Information Program

53. HUD Handbook 2135.1 - Forms Management

54. HUD Handbook 2225.6 - HUD Records Disposition Schedules

55. HUD Handbook 2228.2 - HUD Records & Information Management Handbook

56. HUD Handbook 3230.2 - Physical Security Handbook for HUD Regional and Field Offices

57. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017

58. Office of Management and Budget Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

59. 5 U.S.C. Section 552a, as amended, the Privacy Act of 1974

60. NIST SP 800-66 Rev. 2, “An Introductory Resource Guide for Implementing the

Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” February 2024

61. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. Section § 794d), as amended, January 18, 2017

62. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

63. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-

53 Rev 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

64. Federal Travel Regulation (FTR). 2025 (www.gsa.gov/federaltravelregulation)

65. Common Approach to Federal Enterprise Architecture and the Collaborative Planning

Methodology (CPM), May 2012NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

66. OMB Memorandum M-24-15, Modernizing the Federal Risk and Authorization Management Program, July 25, 2024OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

67. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

68. GSA ICAM Solutions and Shared Services Roadmap (GSA ICAM Solutions and Shared Services Roadmap - IDManagement

69. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

70. FICAM Architecture and Accompanying Playbooks, Version 3.3, June 30, 2023 (FICAM Architecture - IDManagement)NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,” June

71. NIST SP 800-63-4, 800-63A-4, 800-63B-4, 800-63C-4, “Digital Identity Guidelines,” updated August 1,2025

72. NIST SP 800-157 Rev. 1, “Guidelines for Derived PIV Credentials,” November 2024

73. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

74. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC)

Initiative,” September 12, 2019

75. OMB Memorandum M-22-09, Federal Zero Trust Strategy, January 26, 2022

76. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name

System Infrastructure,” August 22, 2008

77. OMB Memorandum M-23-10, DOTGOV Online Trust in Government Act of 2020, February 8, 2023 https://www.gsa.gov/federaltravelregulation https://www.idmanagement.gov/icamsolutions/#:~:text=The%20roadmap%20aligns%20actions%20to,%2Dto%2Dmission%20partner%20interactions.

https://www.idmanagement.gov/icamsolutions/#:~:text=The%20roadmap%20aligns%20actions%20to,%2Dto%2Dmission%20partner%20interactions.

https://www.idmanagement.gov/arch/ https://www.cisa.gov/publication/tic-30-core-guidance-documents

78. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public

Law 110–140), December 19, 2007

79. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

80. Clinger-Cohen Act of 1996, 40 U.S.C. §11101, § 11331, and §11103

81. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

82. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol

Version 6 (IPv6),“ November 19, 2020

83. ANSI/EIA-310, Cabinets, Racks, Panels, and Associated Equipment, December 1st,

84. ANSI/TIA-607-C, Telecommunications Bonding and Grounding (Earthing), November 2015

85. NFPA 70, National Electric Code (NEC), 2026

86. BICSI N3-2020, Bonding and Grounding, January 7, 2020

87. NFPA 17/17A, Dry & Wet Chemical Systems, 2024

88. NFPA 101, Life Safety Code, 2024

89. ASTM E814 & UL 1479, Standard Test Method for Fire Tests of Penetration Firestop

Systems, May 2024

90. ASTM E1966 & UL 2079, Standard Test Method for Fire-Resistive Joint Systems, October 2024

91. NFPA 221, Standard for High Challenging Fire Walls, Fire Walls, and Fire Barrier

Walls, 2024

92. NEC 406.3, Receptacle Rating and Type, 2023

93. NECA/NEMA 105-2024, Standard for Installing Metal Cable Tray Systems, 2024

94. ANSI/TIA-568-E-2020, Commercial Building Telecommunications Cabling

Standards, 2020

95. ANSI/TIA-569, Telecommunication Pathways and Spaces, June 2022

96. ANSI/BICSI N2-3029, Installation of Telecommunications and ICT Cabling, December 2017

97. NEC Article 392, Cable Trays, P/O NFPA 70, 2026

C.3 GENERAL REQUIREMENTS

The Contractor shall provide and/or acquire ITSS and 2TNG solutions in support of the HUD OCIO relevant functional areas, together with any incidental hardware and software required under the individual Task Orders (TOs). Place of Performance

The place of performance will be specified in individual TOs. Work may occur at Government or non-Government sites within the United States, U.S. commonwealths, and unincorporated U.S. territories. Locations may include, but are not limited to, HUD HQ’s, regional and field offices, data centers, and other designated sites as defined in each of the individual TOs.

C.3.1 Travel

Travel to HUD HQ’s, regional and field offices, data centers, and/or other designated locations may be required under the H2TNG multiple award vehicle or individual TOs. Materials, Equipment and Locations

C.3.1.1 Government-Furnished

Government Furnished Property (GFP) – including Government Furnished Material (GFM), Government Furnished Information (GFI), and Government Furnished Equipment (GFE) may be provided and will be identified in individual TOs. Upon receipt, the Contractor shall conduct all necessary examinations, inspections, maintenance, and testing. The Contractor is responsible for reporting inspection results, maintenance actions, losses, and any damage to the Government through HUD’s Software Asset Management (SAM) and/or Hardware Asset Management (HAM) modules, or other required asset management repositories specified in the individual TOs, as well as to the assigned Contracting Officers Representative (COR) and Program/Project Manager (P/PM).

HUD may provide HUD-specific software as required in individual TOs. The Contractor may use HUD-provided software development and test accounts, document repositories, and other resources necessary for development, storage, maintenance, and delivery of products.

Contractors must comply with all HUD security policies and procedures for protecting sensitive data. Refer to Section 6.0 for detailed security requirements.

C.3.1.2 Contractor-Acquired

Upon Government approval, the Contractor shall acquire and/or provide any hardware or software required to fulfill each TO that is not supplied as GFP. The Contractor shall maintain software integrity in accordance with the producer’s licensing agreement until the software is delivered to the Government or otherwise disposed of as directed by the Government. All items delivered must receive prior Government approval and comply with the requirements outlined in the H2TNG PWS. Refer to Section 6.0 for detailed security requirements.

C.3.1.3 Non-Developmental Items and Commercial Processes

Non-Developmental Items (NDI), Commercial-Off-The-Shelf (COTS), and Government-Off- The-Shelf (GOTS) products shall be utilized to the maximum extent possible. The Contractor shall apply federal government – approved and commercially available – federal government approved industry best processes, standards, and technologies wherever feasible.

C.3.1.4 Connectivity

HUD will provide connectivity to HUD-specific systems and network as required for task execution through HUD-approved remote access technology. This remote access will enable connectivity to HUD-specific software and development tools authorized for use on the HUD network. HUD may install equipment at the Contractor’s site to ensure compliance with security requirements. The Contractor must meet all of HUD’s security standards outlined in Section 2.0 and will bear the cost of providing connectivity to HUD data centers, HUD HQ’s, regional, and field offices, and other designated locations as required and specified in individual TOs.

Additional connectivity to HUD systems may be authorized as appropriate within individual TOs.

C.3.1.5 Government and Non-Government Facilities

HUD HQ’s, regional and field offices, data centers, and other designated locations may be made available for the performance of individual TOs. Contractor personnel may also perform at HUD-approved contractor facilities or remote locations if specified in the TO. Contractors may be required to establish operational support at these locations and must comply with all HUD and Federal Assessment and Authorization (A&A) requirements. Specific facilities will be identified in each TO, and the Contractor shall disclose facility details during the Request for Proposal (RFP) process for each TO. All facilities must be approved by HUD and comply with the security and privacy requirements outline in the H2TNG PWS Section 6.0 and the standards specified in Section 2.0. HUD facilities are located within the U.S., U.S. territories, and U.S.

commonwealths.

C.3.1.6 Warranty

Items acquired under individual TOs may require warranty protection. Any applicable commercial warranties shall be transferred to the Government. The type of warranty and extent of coverage will be determined for each TO.

C.3.1.7 Marking, Handling, Storage, Preservation, Packaging, Tracking & Shipping

The Contractor shall establish and maintain procedures, in accordance with the H2TNG PWS Section 2.0 – Applicable Documents for handling, storage, preservation, packaging, marking, tracking, and shipping of all products. These procedures must ensure the protection of product quality and prevent damage, loss, deterioration, degradation, or substitution. The Contractor shall document these procedures and make them available for Government review and approval upon request by the CO, COR, P/PM, or designated representative. Documentation shall include process descriptions, quality control measures, and compliance verification records.

C.3.1.8 Export Control

The Contractor shall comply with all applicable laws and regulations governing export-controlled information and technology. The Contractor shall not use, distribute, transfer, or transmit any technology – including technology incorporated into products, software, or other information except in full compliance with these laws and regulations. Additionally, the Contractor is responsible for planning, obtaining, and maintaining all required export licenses necessary to fulfill the requirements of individual TOs.

C.3.2 Safety and Environmental

Safety and environmental requirements will be specified in individual TOs. The Contractor shall comply with the Office of Federal Sustainability Acquisition and Electronics Stewardship initiatives as outlined in each TO and in accordance with the policies referenced at https://www.sustainability.gov/resources-eo-efo.html.

C.3.3 Enterprise and IT Framework

C.3.3.1 HUD Technical Reference Model

For HUD-specific TOs, the Contractor shall support the HUD Enterprise Management Framework (EMF). In alignment with this framework, the Contractor shall comply with the US Department of HUD Office of Chief Information Officers Technical Reference Model (HUD OCIO TRM) and consider the HUD Enterprise Technology Strategic Plan. The HUD’s OCIO TRM is a key component of the overall Enterprise Architecture (EA), providing a common vocabulary and structure for describing the IT used to develop, operate, and maintain enterprise applications. Additionally, the OCIO TRM – which includes the Standards Profile and Product List – serves as a technology roadmap and a tool for guiding and supporting OCIO initiatives.

The Contractor is responsible for ensuring that all proposed solutions, designs, and implementations adhere to TRM standards and align with HUD’s enterprise architecture principles. Compliance shall be documented and made available for Government review upon request by the CO, COR, IT P/PM, technical point of contact (TPOC), and or subject matter expert (SME).

C.3.3.2 Federal Identity, Credential, And Access Management (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting Homeland Security Presidential Directive-12 (HSPD-12) credentials.

This shall be implemented using HUD’s Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp and HUD Identity and Access Management (IAM) approved enterprise design and integration patterns, All Contractor delivered applications and systems must comply with HUD Identity, Credential, and https://www.sustainability.gov/resources-eo-efo.html.

https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp

Access Management (ICAM) policies and guidelines, the HSPD-12 Program, and align with the Federal Identity, Credential, and Access Management (FICAM) Architecture v3.3 and accompanying playbooks.

Contractor-delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology Special Publication (NIST SP) 800-63-3

– Digital Identity Guidelines. At a minimum, authentication must include Public Key Infrastructure (PKI)-based authentication supporting PIV cards and/or Common Access Card (CAC), as determined by the business needs.

All applications and systems must conform to the Identity and Access Management PIV requirements outlined in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-3. NIST SP 800-217 – Guidelines for Personal Identity Verification (PIV) Federation. Contractor-delivered applications and systems shall be listed on the FIPS 201-3 Approved Product List (APL). If not currently listed, the Contractor is responsible for completing the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support the following capabilities:

Automated provisioning using HUD’s enterprise provisioning service.

Integration with HUD’s authoritative identity source for provisioning identity attributes.

Use of HUD defined unique identifiers (Secure Identifier [SEC ID] / Integrated Control

Number [ICN]).

Support for multiple authenticators per identity and authenticators at every Authenticator

Assurance Level (AAL) appropriate for the solution.

Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

Two-factor authentication (2FA) using HUD Enterprise Design Patterns.

A Security Assertion Markup Language (SAML) implementation for assertion-based authentication; additional assertion methods may be provided if compliant with NIST SP 800-63-3 – Digital Identity Guidelines.

Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if trust-based authentication is used.

Role Based Access Control (RBAC).

Auditing and reporting capabilities.

All FICAM efforts shall comply with all federal government standards, policies, and guidelines specified in Section 2.0 – Applicable Documents; and any new federal government standards, policies, guidelines, and executive orders created within the lifetime of this contract.

The required Assurance Levels for this contract effort are Identity Assurance Level (IAL) 3, Authenticator Assurance Level (AAL) 3, and Federation Assurance Level (FAL) 3.

C.3.3.3 Internet Protocol Version 6 (Ipv6)

The Contractor solution shall fully support Internet Protocol Version 6 (IPv6) in accordance with the Office of Management and Budget (OMB) memorandum issued on November 19, 2020 (OMB M-21-07). Compliance with IPv6 requirements shall follow the USGv6 Program (NIST USGv6 Program), NIST Special Publication (SP) 500-267B Revision 1-USGv6 Profile, and NIST SP 800-119 Guidelines for the Secure Deployment of IPv6.

IPv6 compliance shall be incorporated into all IT infrastructures, application designs as defined under O&M, development activities as defined under O&M, operational systems, sub-systems, and their integrations. All devices must support native IPv6 and dual-stack (IPv6 / IPv4) connectivity without requiring additional memory or resources from the Government, ensuring functionality in mixed environments. Furthermore:

All public/external facing servers and services (e.g., web, email, DNS, ISP services, etc.)

shall support native IPv6 and dual stack (IPv6 / IPv4) operations.

All internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) configurations.

The Contractor shall provide an IPv6 Compliance Plan detailing how these requirements will be met, including timelines, implementation strategies, and risk mitigation measures for each TOs specifying IPv6 requirements. Additionally, the Contractor shall conduct IPv6 functionality and security testing and submit test results to the Government for review and approval prior to deployment of IT systems and services specified within the individual TOs.

C.3.3.4 Trusted Internet Connection (TIC)

The Contractor solution shall comply with the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative”, HUD Directive 6513 “Secure External Connections”, and the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases published by the Cybersecurity & Infrastructure Security Agency (CISA). Any deviations from these requirements must receive prior approval from HUD’s Office of the Chief Information Security Officer (OCISO) and the Assistant Chief Information Officer for the Office of Infrastructure and Operations (ACIO OIO) offices.

C.3.3.5 Standard Computer Configuration

The Contractor’s IT end-user solution developed for use on standard HUD computers shall be fully compatible with and supported on HUD’s standard operating environment, which currently includes Windows 11 (64bit), Microsoft Edge (Chromium based), and Microsoft 365 Apps for Enterprise, as well as any future versions of Windows adopted by HUD during the contract period. Applications delivered to HUD for deployment on Windows 11 workstations shall be delivered as signed .msi packages with switches for silent and unattended installation. Updates shall be delivered as signed .msp files to enable seamless deployment using Microsoft Endpoint Configuration Manager (CM) HUD’s current desktop application deployment tool.

All software code must be signed using a certificate from a HUD-trusted signing authority. The Contractor shall ensure and certify that the solution functions as intended on a standard HUD computer configured with non-admin, standard user rights and hardened according to the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) for the applicable client operating system.

The Contractor shall provide a Compatibility and Deployment Certification Report to the Government for review and approval prior to production deployment for all TOs specifying the execution of this requirement. This report shall include evidence of successful installation, update processes, functionality testing under HUD’s standard configuration, and compliance with all security and configuration requirements for both the current and future Windows versions adopted by HUD.

C.3.3.6 Enterprise Management Framework

The HUD Enterprise Architecture (HEAR) Library provides a comprehensive enterprise-wide view of HUD IT systems, encompassing tools, reports, databases, dashboards, and analytics.

HEAR enables OCIO to monitor system health and performance while delivering intelligent analysis and trending insights that support proactive enterprise system management.

By leveraging real-time information, OCIO can make strategic, operational, and investment decisions that enhance IT service delivery-improving performance, availability, user experience, and reliability across the enterprise.

The contractor shall comply with all HEAR requirements and ensure full integration and alignment with HUD’s enterprise architecture standards. The Contractor must support and maintain HEAR capabilities to enable OCIO’s ability to monitor, analyze, and manage enterprise systems effectively.

HEAR supports a unified enterprise service management model, including release management, configuration management, change management, and incident management, all aligned with industry- standard IT Infrastructure Library (ITIL) service management best practices. The Contractor shall adhere to these ITIL-aligned processes and any additional frameworks specified in individual TOs.

C.3.3.7 Authoritative Data Sources

The HUD Enterprise Architecture Repository (HEAR) is a key component of the overall Enterprise Architecture (EA). IT establishes a common framework for data taxonomy that defines the data architecture used to develop, operate, and maintain enterprise applications.

The Contractor shall comply with the Department’s Authoritative Data Source (ADS) requirement which mandates that HUD systems, services, and processes across the enterprise access HUD data solely through official HUD ADSs where applicable, see below.

Information Classes that compose each ADS are documented in HEAR under the Data & Information domain.

The Contractor shall ensure that all delivered applications and system solutions support the following:

Full integration with HUD’s ADS framework.

Consistent use of official ADSs for all data access and exchange Alignment with HUD’s enterprise data taxonomy and standards specified in Section 2.0-

Applicable Documents.

C.3.3.8 Social Security Number (SSN) Reduction

The Contractor solution shall support the Social Security Number Fraud Prevention Act (SSN FPA) of 2017, which prohibits the inclusion of SSNs on any document sent by mail.

Additionally, the Contractor support shall align with Section 240 of the Consolidated Appropriations Act (CAA) 2018, enacted March 23, 2018, which mandates that HUD discontinue using SSNs as the Primary Identifier in all HUD information systems.

The Contractor shall ensure that:

Any new IT solution eliminates the use of SSNs as the Primary Identifier and replaces them with the Integrated Control Number (ICN) for all individuals in the HUD information systems.

All delivered applications and systems integrate with HUD’s identity management solution to support identity traits, including the use of ICN as the Primary Identifier.

SSN’s may only be used to identify an individual if required to obtain information from a system outside HUD’s jurisdiction, and only when no alternative identifier is available.

C.3.4 Development Methodologies

The Contractor shall support a Service-Oriented Architecture (SOA), a flexible set of design principles applied during system development and integration phases, as specified at the TOs level.

Any SOA-based architecture shall be deployed on a secure, scalable, interoperable, and dynamic platform that provides end-to-end visibility and manageability – from application services through networking components – and supports use across multiple domains.

For HUD-specific TOs, the Contractor shall support HUD efforts in accordance with the following framework and processes:

Visual Innovation Platform (VIP) and Product Lifecycle Management (PLM):

VIP enhances collaboration and decision-making through visual tools (e.g. digital concept boards, etc.).

PLM serves as a central hub for data, connecting engineering, design, manufacturing, and supply chain teams.

VIP and PLM work together to integrate workflows and drive digital transformation:

o VIP connects to PLM, pulling real-time product data to create interactive visual workspaces.

o Teams use VIP’s visual boards to ideate, review, and make decisions, which then updates the central PLM system.

This integration bridges strategic vision (VIP) with operational execution (PLM), accelerating innovation and information technology (IT) maturity.

The Contractor shall perform duties consistent with processes defined in the HUD Process Asset Library (PAL), a centralized digital repository that stores and shares process-related resources (templates, guidelines, policies, checklists, lessons learned, and metrics).

PAL ensures:

Standardized operations and compliance with HUD policies.

Reuse of existing assets to reduce redundancy.

Capturing organizational knowledge and facilitating continuous improvement.

Clear role and responsibilities for HUD and Contractor staff.

The integration of PAL, PLM, and VIP creates a unified system that:

Streamlines development and improves quality.

Links design and capability to HUD’s mission and vision.

Breaks down silos, automates workflows, and ensures smooth data flows across all levels.

For HUD-specific TOs, the Contractor shall follow the HUD PAL, PLM, and VIP processes to ensure compliance with HUD policies, regulations, and quality standards. The Contractor shall use an incremental development methodology such as Agile (e.g. Scrum, Kanban, etc.), unless otherwise specified at the TOs level.

C.3.5 Integrated Product Teams

The Contractor shall, when required by individual TOs, serve as a member of or provide Subject Matter Expertise (SME) to Integrated Product Teams (IPTs), Working IPTs (WIPTs), and/ or Integrated Business Teams (IBTs) within HUD. The Contractor’s specific role(s), responsibilities, and level of participation shall be defined in each TOs. The Contractor shall actively participate in all assigned team activities and provide deliverables, recommendations, and technical input as requested by HUD.

IPTs, WIPTs, and IBTs are cross-functional teams that collaborate to develop strategies and approaches to achieve defined objectives. The Contractor shall support HUD in establishing and executing critical elements across all phases of the program and project lifecycle, including but not limited to:

Acquisition Strategy.

Requirements Development and Management.

Use Case Development.

Risk Management.

Architecture Design.

Performance Engineering.

Capacity Planning.

System and Software Development.

Test and Evaluation.

Sustainment Operations.

The Contractor shall ensure compliance with all HUD policies, standards, and applicable regulations while performing these duties. The Contractor shall provide timely, accurate, and complete documentation and reporting as required by HUD and specified in individual TOs.

C.3.6 Quality Assurance

All Contractors and Subcontractors performing work under individually TOs shall possess the ISO 9001 Quality Management System (QMS) Certification at time of TO award and maintain this certification throughout the TO period of performance if specified within the TO.

Contractors shall comply with ISO 9001:2015 QMS requirements for obtaining and maintaining the ISO 9001 QMS Certification and shall submit a copy of the ISO 9001 QMS Certification with all Request for Proposal (RFP) responses for individual TOs awarded under this contract.

In addition, all Contractors and Subcontractors performing work on individual TOs shall possess the Capability Maturity Model Integration (CMMI) Maturity Level 5 – Optimizing with Capability Level 3 – Defined certification at time of TOs award and maintain this certification throughout the period of performance if specified within the TO. Contractors shall comply with CMMI requirements for obtaining and maintaining certification and shall submit a copy of their the CMMI Maturity Level 5 – Optimizing with Capability Level 3 – Defined certification with all Request for Proposal (RFP) responses for any individual TOs that specify it.

Certain Contractor and Subcontractor personnel may also be required to hold Information Technology Infrastructure Library (ITIL) 4 Certifications at one or more of the following levels:

Level 1 – Foundation, Level 2 – Intermediate/Specialist (i.e. ITIL Managing Professional (MP), ITIL Strategic Leader (SL), and/or Practice Manager), Level 3 - ITIL Expert, and Level 4 – ITIL Master. Certification requirements for Contractor and Subcontractor staff will be identified in TOs labor categories, “key personnel” sections, or within individual TOs awarded under this contract. Contractor and Subcontractors shall submit copies of required ITIL 4 Certifications to the Contracting Officers Representative (COR). All Key Personnel shall submit resumes to the COR for review, ensuring that all names and PII are removed prior to submission. All Key

Personnel submitted as part of the proposal to the multiple-award vehicle or subsequent TOs, if awarded, must be on the contract a minimum of 4 months from the time they receive GFE.

C.3.7 Transition and Orientation Support

The Contractor shall provide transition and orientation services, including the development of a Phase-In/Phase-Out Transition Plan, to ensure continuity of services as specified in the individual TOs. Transition and orientation support may include transferring support services to Government personnel or to another Contractor, as required, to maintain uninterrupted operations.

C.3.8 Government Inspection and Oversight

The Contractor shall cooperate with authorized Government offices in matters related to facilities access, audits, security incident notification, and hosting location requirements. The Contractor and any Subcontractors shall:

a. Provide the CO, Contracting Officers Representative (COR), TOs Program/Project Manager (P/PM), Technical Points of Contact (TPOC), and other designated representatives by the CO, COR, P/PM, and/or TPOC , full and unrestricted physical and remote/logical access to their facilities, installations, operational documentation, databases, and personnel associated with hosting services under this contract and individual TOs. This access shall be granted as necessary to conduct audits, inspections, device scanning using Government-approved tools, investigations, or other reviews to ensure compliance with contractual requirements for IT and information security and to safeguard against threats and hazards to the integrity, availability, and confidentiality of agency information under the Contractor’s or Subcontractor’s control.

b. The Contractor shall fully cooperate with all audits, inspections, investigations, or other reviews conducted by or on behalf of the CO or other authorized Government offices.

Full cooperation includes, but is not limited to, timely disclosure of requested data, information, and records; making Contractor employees available for interviews; and providing prompt access to facilities, systems, data, and personnel as reasonably required to complete the review. All cooperation shall be provided at no additional cost to the Government. The Contractor shall preserve all data, records, logs, and other evidence, reasonably necessary, to conduct a thorough investigation of any computer security incident, as defined in NIST SP 800-61, including incidents that pose an actual or potential threat to the integrity, availability, or confidentiality of agency information or the functionality of information systems operated under this contract. The Contractor shall promptly notify the CO, COR, and P/PM of any computer security or privacy incident in addition to any other notification requirements specified by law or this contract. Federal agency timeframes for reporting incidents to the United State Computer Emergency Readiness Team (US-CERT), as referenced in NIST SP 800-61 Rev. 3, shall serve as a guideline for determining timeliness.

c. Upon request, the Contractor shall provide Government data, information, or records under its control to the CO, COR, P/PM, TPOC, or other authorized Government offices, including the Office of Inspector General (OIG) in support of audits, inspections, investigations, reviews or litigation involving HUD. Requests shall specify a compliance deadline of not less than ten (10) days, and unless otherwise stated in this contract or individual TOs, production shall be at no additional cost to the Government.

d. The Contractor shall include the substance of this section in all subcontracts where Subcontractor employees will have access to agency information or information systems operated under this contract and individual TOs. Furthermore, the Contractor shall ensure that all hosting services and storage of agency data, information, and records under this contract occur within the United States of America.

C.4 TECHNICAL FUNCTIONAL AREAS

Individual TOs may span multiple functional and sub-functional areas. Additional details regarding these areas are provided in subsequent sections to offer greater insight into the complexity and uniqueness of certain potential TOs and contract requirements outlined in this PWS. These requirements are not mutually exclusive and may apply across multiple functional and sub-functional areas.

If the Contractor’s efforts under this contract are of such a nature that they could create a potential organizational conflict of interest (OCI), as defined in Federal Acquisition Regulation (FAR) Subpart 9.5, Contractor personnel may be required to sign a Non-Disclosure Agreement

(NDA).

The following is applicable to all functional areas within the H2TNG multiple-award vehicle.

The Contractor shall perform all relevant services associated with a functional area in alignment with applicable Federal and HUD policies, governance processes, and HUD approved industry frameworks, as specified in individual TOs.

C.4.1 Program Management, Strategy, Enterprise Architecture and Planning

Support

The Contractor shall provide comprehensive Program and Project Management (P/PM) services, including monitoring, analysis, strategic planning, and Enterprise Architecture (EA) support at the enterprise, portfolio, program, and individual project levels.

C.4.1.1 Strategy and Planning

The Contractor shall provide services that facilitate strategic decision-making regarding the organization’s current and future IT structure and program integration. Services shall include, but are not limited to:

Systematic assessment and redesign of key technologies, business processes, activity-based costing, and organizational structures.

Streamlining processes, aligning organizational structures to the way work is conducted and deploying proven supporting technologies where appropriate.

Developing recommendations that contribute to an overarching IT strategy aligned with business goals, objectives, and initiatives, and that leverage innovation to identify new opportunities for success.

Designing measurable objectives and metrics aligned to the overall IT strategy and operations.

C.4.1.2 Compliance

The contractor shall ensure that all recommendations, analyses, supporting documentation and plans shall comply with Federal legislation and be consistent with Federal policies, standards, and guidelines, including but not limited to: the Government Performance and Results Act (GPRA), Clinger-Cohen Act, Federal Activities Inventory Reform (FAIR) Act, and Government Paperwork Elimination Act (GPEA). Where applicable, recommendations shall align with agency policies and enterprise governance standards; and Section 2.0 of this PWS. The Contractor shall monitor and incorporate updates to relevant laws, regulations, and guidance throughout the period of performance, as directed at the Task Order (TO) level.

C.4.1.3 Inherently Governmental Functions

All Contractors and Subcontractors supporting Strategy and Planning efforts shall ensure their staff comply with FAR Subpart 7.5 - Inherently Governmental Functions. The Contractor shall not perform inherently governmental functions and shall immediately report any suspected violations to the contract CO, COR, and P/PM.

C.4.2 Standards, Policy, Procedure and Process Development; and Implementation

Support

The Contractor shall support the development and/or evaluation of new standards, policy directives, operating procedures, processes, and related assessments, including impact analyses associated with implementation.

C.4.2.1 Inherently Governmental Functions

All Contractors and Subcontractors supporting these efforts shall ensure compliance with FAR Subpart 7.5 - Inherently Governmental Functions and shall immediately report suspected violations to the CO, COR, and P/PM.

C.4.3 Requirements Development and Analysis Support

The Contractor shall provide requirements development and analysis support as required by individual TOs. For iterative and agile methodologies, requirements may be identified and/or evolve at any phase of the lifecycle; therefore, requirements definition shall be structured to meet the incremental delivery needs.

Requirements support may include, but is not limited to:

Enterprise analysis.

Business and application architecture.

Business process reengineering.

Feasibility studies.

Requirements planning and management.

Requirements gathering/elicitation.

Use Case development.

Agile requirements methods.

Requirements analysis.

Change management.

Peer reviews.

Solution assessment and validation.

Business process modeling and workflow management.

C.4.3.1 Requirements Packages

The Contractor shall provide requirements package support that may include, but is not limited to:

Assistance in developing Statements of Objectives (SOO), Statements of Work (SOW), Performance Work Statements (PWS), Performance Specifications, Rough Orders of Magnitudes (ROM),…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .