TPVS 2.0 - Draft PWS v.06042025.docx
DOCX document 767 KB Posted
- Attached to
- Traveler Processing and Vetting Software (TPVS) 2. 0 Federal contract opportunity
- Solicitation number
- RFI20150352
About this file
This Performance Work Statement (PWS) details the U.S. Customs and Border Protection's (CBP) requirements for Traveler Processing and Vetting Software (TPVS) 2.0, a comprehensive suite of mission-critical applications supporting border security and traveler processing. The PWS covers operations and maintenance, technology modernization, development, and enhancements for approximately 55 major applications that process over 3.1 million daily transactions, including advanced passenger information, traveler vetting, entry/exit tracking, and biometric services across air, land, and sea ports of entry.
Key objectives include proactive operations and maintenance, application enhancements and modernization, cloud migration, DevSecOps implementation, and supporting CBP's vision of transforming traveler processing through technologies like biometrics and artificial intelligence. The solicitation emphasizes innovation, collaboration, and developing intuitive capabilities to anticipate emerging threats. The contract will require supporting over 70,000 online users across 20 federal agencies, managing specialized equipment, and maintaining systems that process critical traveler data for national security, with a focus on mobile technologies, human-centered design, and continuous technological advancement.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| TPVS 2.0 - RFI AMD 4 v.07162025.pdf | ||
| TPVS 2.0 - Industry Day Slides Only.pdf | ||
| TPVS 2.0 - Industry Day Slides Only.pdf | ||
| TPVS 2.0 - RFI AMD 3 v.07082025.pdf | ||
| TPVS 2.0 - RFI AMD 2 v.06182025.pdf | ||
| TPVS 2.0 - Amd 1 RFI v.06172025.pdf | ||
| TPVS 2.0 - RFI v.06112025.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Office of Information & Technology
Traveler Processing and Vetting Software (TPVS) 2.0
Application Modernization, Development, Enhancements, Operations & Maintenance, and Specialized Services Requirement
Draft Performance Work Statement (PWS)
June 4, 2025
Document Control Information
| Document Name |
| Performance Work Statement (PWS) |
| Contract Name |
| Traveler Processing and Vetting Software (TPVS) 2.0 |
| Document Version |
| 1.0 |
| Version |
| Date |
| Additions/Modifications |
| 1.0 |
| 3/24/2025 |
| Initial Version |
| 2.0 |
| 6/4/2025 |
| Revised Version |
Table of Contents
| Document Control Information | 2 |
| Performance Work Statement | 7 |
| 1.0 Background | 7 |
| 2.0 Scope | 11 |
| 2.1 Technology Modernization and Cloud Maintenance | 11 |
| 2.2 Operations & Maintenance Services | 11 |
| 2.3 Development and Enhancements | 12 |
| 2.4 Specialized Equipment | 12 |
| 2.5 Project Management and Performance Metrics | 12 |
| 3.0 Applicable Documents | 13 |
| 4.0 Technical Environment | 14 |
| 4.1 Current Environment | 14 |
| 4.2 Future Environment | 14 |
| 4.3 Resiliency and Recovery | 15 |
| 4.4 Mobility and Application Development | 15 |
| 4.5 Analytics | 16 |
| 4.6 Cloud and Infrastructure | 16 |
| 5.0 Operating Environment Requirements | 17 |
| 6.0 Objectives | 18 |
| 6.1 Objective 1: Proactive Operations & Maintenance | 18 |
| 6.2 Objective 2: Enhancements & Modernization | 20 |
| 6.3 Objective 3: New Development and Emerging Technology | 23 |
| 6.4 Objective 4: Specialized Equipment | 23 |
| 6.5 Objective 5: Collaboration | 24 |
| 6.6 Objective 6: Innovation & Thought Leadership | 24 |
| 6.7 Objective 7: Agile Project Management | 25 |
| 6.8 Objective 8: Project Visibility | 26 |
| 7.0 Deliverables and Delivery Schedule | 28 |
| 7.1 Security Plan | 28 |
| 7.2 Transition Plan | 28 |
| 7.3 Weekly Status Reports | 29 |
| 7.4 Contractor Staff Training TO COMPLY WITH CBP REQUIRED TRAINING | 30 |
| 8.0 Government Furnished Equipment and Information | 31 |
| 9.0 Skill Mix | 32 |
| 10.0 Period and Place of Performance and Hours of Operation | 33 |
| 10.1 Period of Performance | 33 |
| 10.2 Place of Performance | 33 |
| 10.3 Hours of Operation | 33 |
| 11.0 Travel | 34 |
| 12.0 Contracting Officer and Contracting Officer’s Representative | 35 |
| Appendix A. Acronyms & Definitions | 37 |
| Table 1. Acronyms & Definitions | 37 |
| PWS Attachment A | 39 |
| Advance Passenger Information System (APIS) | 40 |
| Advance Traveler Information System (ATIS) | 42 |
| ADIS I-94 Service (Create, Update, Delete, Query) | 43 |
| Arrival and Departure Information System (ADIS) | 46 |
| Audit Screen Rendering (ASR) | 48 |
| Biometric Applications | 49 |
| CBP Vetting (CBPV) | 51 |
| Currency and Monetary Instruments Report (CMIR) | 53 |
| Consolidated Secondary Inspection System (CSIS) | 56 |
| Credential Services | 60 |
| Decal and Transponder Online Procurement System (DTOPS) | 61 |
| Device Information Management System (DIMS) | 63 |
| Electronic Advance Passenger Information System (eAPIS) | 65 |
| Electronic Secured Adjudication Forms Environment (e-Safe) | 67 |
| Electronic System for Travel Authorization (ESTA) | 69 |
| Electronic Visa Update System (EVUS) | 72 |
| Encounter Broker Services (EBS) | 74 |
| Enhanced Passenger Processing Service (EPP) | 75 |
| Enterprise Reporting (ER) | 77 |
| Global Entry (GE) – Portals, Mobile and SBE | 82 |
| Guam and the Commonwealth of the Northern Mariana Islands Electronic Travel Authorization (G-CNMI ETA) | 84 |
| I-94 Website | 86 |
| Inspectional Operations Incident Log (IOIL) | 88 |
| Land Border Web Reporting System (LBWRS) | 90 |
| Legacy Land Applications | 92 |
| Lookout Records (LR) | 95 |
| Mitigation Adjustment Tool (M.A.T.) | 97 |
| Mobile Passport Control (MPC) | 98 |
| NCIC/Nlets Services (NNSV) | 100 |
| PSPD Enterprise Architecture Repository (PEAR) | 102 |
| Payment Services | 104 |
| Pleasure Boat Reporting System (PBRS) | 105 |
| Portable Automated Lookout System (PALS) NextGen | 107 |
| Pre-Departure Service Air (PDSA) | 108 |
| Pre-Departure Service Vessel (PDSV) | 110 |
| Primary Inspection Process (PIP) | 112 |
| Primary Query Service (PQS) | 114 |
| Private Aircraft Enforcement System – General Aviation Processing (PAES-GAP) | 116 |
| Protected Person Lookup Service (PPLS) | 118 |
| PSPD Application Response Time (PART) | 120 |
| Replay | 121 |
| Simplified Arrival Air and Sea (SAMN) | 122 |
| Simplified Arrival Pedestrian (SAPN) | 124 |
| Simplified Arrival Vehicle (SAVN) | 126 |
| Spark | 128 |
| TECS Portal (Application) | 130 |
| TECS Portal - Supervisor Approval (SA) | 132 |
| TECS Portal - System Support | 133 |
| TECS Portal - User Profile Processing (UP) | 134 |
| TECS Screening Services (TSSV) | 135 |
| TECS Training | 138 |
| Terms, Acronyms, and Definitions (TAD) | 139 |
| Travel Documents and Encounter Data (TDED) | 140 |
| Travel Document Authentication Service (TDAS) | 142 |
| Trusted Traveler Programs System (TTP) | 144 |
| Trusted Worker Programs (TWP) | 146 |
| Vehicle Primary Application and integration Services (VPAIS) | 147 |
| Vehicle Primary Activity Monitor (VPAM) | 149 |
| Watch List Service (WLS) | 151 |
| PWS Attachment B: current Specialized Equipment & software licenses | 153 |
| pws attachment c: section 508 clauses | 156 |
| 1. Section 508 Requirements | 156 |
| 1.2 Section 508 Deliverables | 158 |
Performance Work Statement
1.0 Background
U.S. Customs and Border Protection (CBP) is a component of the Department of Homeland Security (DHS). The priority mission of CBP is to prevent terrorists and terrorist weapons from entering the United States. This important mission calls for improved security at America's borders and ports of entry as well as for extending the zone of security beyond physical borders so that American borders are the last line of defense, not the first. CBP is also responsible for apprehending individuals attempting to enter the United States illegally; stemming the flow of illegal drugs and other contraband; protecting our agricultural and economic interests from harmful pests and diseases; protecting American businesses from theft of their intellectual property; and regulating and facilitating international trade, collecting import duties, and enforcing U.S. trade laws.
The Office of Information and Technology (OIT) is the information technology component of CBP. OIT’s responsibilities are vast, ranging from designing, delivering and maintaining technology-based capabilities to enterprise architecture and governance. OIT also provides solutions that support CBP inspection and enforcement activities to help CBP officers, agents, and analysts protect our borders and safeguard America. OIT is responsible for enhancing, administering, and maintaining intelligence and targeting systems and related systems that help secure the supply chain and support CBP’s layered defense strategy for international cargo and passengers.
OIT provides application development and continued operational support of traveler and immigration management systems for U. S. Customs and Border Protection. The suite of applications that support traveler and immigration management is called Traveler Processing and Vetting Software (TPVS). TPVS is managed by the Passenger Systems Program Directorate (PSPD) within OIT. Other OIT Offices provide support to systems maintained under TPVS also. The PSPD mission is to deliver and sustain technology solutions to prevent terrorism, and safeguard and expedite legitimate travel into and out of the United States.
PSPD is responsible for developing, managing, and modernizing critical technology systems that facilitate secure and efficient travel across U.S. borders. PSPD oversees a portfolio of innovative solutions that support traveler screening, immigration processing, and border security operations, ensuring seamless coordination between CBP, partner agencies, and the travel industry. By leveraging cutting-edge technology, automation, and data-driven insights, PSPD enhances national security while improving the traveler experience at air, land, and sea ports of entry.
PSPD works to develop and manage the critical technology systems and infrastructure that facilitate secure and efficient traveler processing by supporting CBP’s Office of Field Operations through the delivery of automated screening and traveler processing systems to enhance security and expedite entry. PSPD works with federal, state, and local partners such as the Transportation Security Administration (TSA) and the Department of State (DoS) to develop system integrations that share traveler data and improve risk assessments, helping ensure compliance with immigration, customs, and security policies. PSPD also works hand in hand with airlines, airports, and other travel authorities, deploying biometric entry/exit solutions such as the Advanced Passenger Information System (APIS) and Simplified Arrival, and enhancing operational efficiency and security at air, land, and sea ports. Lastly, PSPD serves the traveling public, facilitating seamless travel using Trusted Traveler Programs, Mobile Passport Control (MPC), and application integration with facial biometric technology, all of which reduce passenger wait times and streamline entry into the US.
By focusing on technological advancement and innovation, automation, and strategic collaboration with trusted partners, the work that PSPD does enhances border security while streamlining traveler processing and immigration, ensuring a safer and more efficient experience for all.
TPVS supports primary and secondary traveler processing at and between U.S. Ports of Entry, public facing applications that facilitate travel, and vetting services across and beyond DHS. TPVS supports a 24X7 mission and handles millions of transactions a day with very quick response times. The CBP mission is very dynamic, and the mission requirements evolve as security threats and technologies emerge.
On a typical day, CBP conducts operations at 328 ports of entry within 20 field offices, and between ports of entry at U.S. Border Patrol sectors. CBP Officers and USBP Agents use applications supported by TPVS every day. Typical transactions processed by TPVS applications include but are not limited to:
Over 3,800,000 Advanced Passenger Information System (APIS) messages processed daily, with over 2,040,000 commercial air traveler records processed daily 348,000 inbound travelers processed daily in the Air and Sea environments 124,000 pedestrians processed daily in the Land environment 247,000 vehicles with 496,000 travelers processed daily in the Land environment
3.1 million transactions daily processed by the Arrival and Departure Information System (ADIS) 110,000 vehicles passing through the Border Patrol Highway Checkpoints Over 1 Million vetting queries conducted per day, supporting CBP and other agencies and DHS components A total of around 151,000 Transponder orders placed annually through Decal and Transponder Online Procurement System (DTOPS), with 560,000 crossings annually 11 Million Electronic System for Travel Authorization (ESTA) applications processed annually 950,000 Electronic Visa Update System (EVUS) applications processed annually 53,853 average daily transactions through Global Entry (GE) portals or GE Mobile 20,764 average daily transactions through Mobile Passport Control 5,000 provisional I-94’s generated daily, with an additional 11,000 created at Land border Ports of Entry daily Support for more than 70,000 online, research, and backend users who represent over 20 Federal agencies Nearly 10 million active Trusted Traveler Programs (TTP) members, with 13,500 new applications received daily
1 Data is from Fiscal year 2024
PSPD has a broad range of stakeholders and users both within and outside of DHS. Figure 1 illustrates major PSPD stakeholders and users.
Figure 1: PSPD Stakeholders and Users
2.0 Scope
The scope of this Performance Work Statement (PWS) is to procure the full range of life cycle services for the CBP PSPD suite of Traveler Processing and Vetting Software (TPVS) applications and related specialized equipment. Attachment A, Software Application Technical Descriptions and Features provides detailed information regarding current applications and services that are in scope. Cloud hosting environments and Software-as-a-Service (SaaS) agreements are under the control of other OIT programs and other contract vehicles for use by applications. The Contractor will be provided Government Furnished Equipment (GFE) operating on CBP networks for TPVS application support services. A common set of development and support tools, including DevSecOps pipeline toolsets, are available to the Contractor for use and maintained by CBP.
Software application services include:
2.1 Technology Modernization and Cloud Maintenance
PSPD requires TPVS application support services that align with CBP OIT’s modernization initiatives, one of which is to migrate to the cloud by 2025. TPVS applications and systems that are already migrated to the cloud should be evaluated for possible refactoring to leverage the latest in cloud technologies and approaches to increase system performance, availability, efficiency, security, and resiliency. Modernizing TPVS applications encompasses several areas, such as application rationalization and consolidation, cost optimization, implementation of Artificial Intelligence and Machine Learning (AI/ML) and Generative AI, and implementation of programmatic or directorate-wide solutions (e.g., shared and common services), among others. To be successful, officers and agents need tailored, intuitive, and advanced capabilities to anticipate and combat emerging threats. CBP’s operational environment requires its technology to be innovative, mobile (where applicable), resilient, available, reliable, and scalable.
2.2 Operations & Maintenance Services
PSPD requires operations and maintenance (O&M) solutions, processes, and procedures necessary to sustain the suite of software applications and related specialized equipment at the highest levels (as defined in this PWS and referenced documents) of security, service and availability consistent with cost, schedule, and performance objectives. This full range of O&M solutions will ensure TPVS applications operate efficiently, effectively and securely, and are available to support CBP mission requirements. Performance objectives and system requirements are subject to Service Level Agreements (SLAs)
2.3 Development and Enhancements
PSPD requires application development, upgrades, updates, modifications and enhancement services with a focus on full DevSecOps integration. Enhancements include changes to existing applications to meet business or technical requirements. Development may include new applications or major changes to existing applications. Changes to existing applications or implementation of new applications are often necessary in response to urgent requests driven by emerging threats or changes in operational requirements.
2.4 Specialized Equipment
PSPD requires a full range of procurement, installation, maintenance, and monitoring, and support services for specialized equipment that supports TPVS applications. The TPVS applications must integrate seamlessly with the specialized equipment.
2.5 Project Management and Performance Metrics
PSPD requires overall project management support services. Project management is to include oversight, control, and direction in team building, communications, time management, quality assurance and quality control, procedure development, risk management, configuration management, cost management, and software integration.
PSPD requires project performance metrics necessary to have visibility into how its application support services are performing in order to effectively manage its application and services portfolio. This information will give PSPDthe ability to baseline, discover trends, identify areas for improvement, and have up-to-date information on the size and scale of all TPVS applications and services.
3.0 Applicable Documents
The following documents represent CBP, DHS and other government agency requirements, policies and guidance for which delivery of TPVS application support services must adhere to:
· CBP IT Strategy 2024 - 2028
· CBP OIT Data Strategy (2022)
· CBP OIT Cloud Strategy (2022)
· CBP OIT Cybersecurity Strategy (2022-2024)
· CBP OIT Agile Governance Framework
· CBP Security Policies and Procedures Handbook
· CBP SELC process
· CBP Section 508 Directive Number 5510-040A
· CBP Technical Reference Model (TRM)
· CBP Enterprise Technical Architecture (ETA)
· CBP CTO IT Technology Roadmap
· Artificial Intelligence (AI) Use at Customs and Border Protection (CBP) Office of Information and Technology (OIT) – Interim Guidance
· DHS Artificial Intelligence (AI) Roadmap (2024)
· DHS Science and Technology Directorate (S&T) Artificial Intelligence & Machine Learning (AI/ML) Strategic Plan (2021)
· DHS Directive 102-01
· DHS/CBP Program Lifecycle Process Guide
· DHS Systems Engineering Life Cycle (SELC)
· Accessibility and Language Services Division Compliance
· DHS Information Security Policy, MD4300.1, Information Technology Systems Security
· DHS MD 4300A, DHS Sensitive Systems Policy and Handbook, CBP Information Systems
· Security Policies and Procedures Handbook HB-1400-05
· All applicable National Institute of Standards and Technology (NIST) Special Publications (800 Series)
· DHS Data Management Policy MD 103-01
· Federal Data Center Consolidation Initiative FDCCI
4.0 Technical Environment
4.1 Current Environment
PSPD performs system activities in a technical environment supported by a broad set of custom architectural components and commercial off-the-shelf (COTS) packages. CBP ensures adequate computing capacity for its current and projected needs to include development, testing and production. This includes associated networking, storage and offsite infrastructure.
TPVS maintains a collection of approximately 55 major applications, sub-systems and services. See Attachment A for detailed information regarding each application and service. These applications and services are largely Java based with some additional common technologies. As of November 2024, 97% of PSPD’s applications were in the CBP cloud (called CACE, CBP Amazon Web Services (AWS) Cloud East), along with 67% of databases and 52% of interfaces. Cloud-based applications are containerized and deployed on AWS Elastic Cloud Compute (EC2) virtual machines on the AWS Elastic Kubernetes Service (EKS) platform. Various cloud services are used for interfaces with AWS’s Active MQ as the primary modernization replacement for IBM MQ. Some applications use AWS’s Managed Streaming for Kafka (MSK). Some other messaging services, such as the AWS Simple Notification Service (SNS), are used in smaller numbers. In the CBP cloud, PSPD data resides on a few different database types, however the predominate (and target) database type is Aurora PostgreSQL. 64% of PSPD databases reside on PostgreSQL.
4.2 Future Environment
CBP’s vision for the future is to transform the way travelers are processed, allowing CBP Officers to focus on purpose, intent, and behavior while maintaining situational awareness, rather than concentrating on administrative procedures and data entry. Increasingly incorporating and leveraging biometrics alongside biographic data is key to realizing the vision. A biometric-based approach allows threats to be identified before travelers arrive to the U.S., effectively extending our borders. The future environment will utilize other OIT and DHS available services to integrate with passenger processing applications to enable photo capture, biometric comparison and biometric vetting capabilities throughout all passenger processing applications. Additionally, CBP’s vision is to transition frontline officers to the extent possible out of static booths to a dynamic and agile operation allowing officers to admit or refer travelers using mobile technology with a single touch point. PSPD’s primary and entry processing systems will need to be updated to meet this future vision for frictionless travel and interface with new biometric technologies identified by CBP. In addition, CBP envisions expanded use of public self-service, web-based, and mobile applications by travelers in all stages of the travel process.
PSPD is also looking to improve the customer experience by implementing human-centered design principles into every user interface (UI). This means taking a fresh look at existing mobile and web applications with the customer’s perspective in mind and making design changes accordingly. Several important web applications will need to be refreshed and modernized.
The backbone of services and applications that process the vast majority of transactions in PSPD is also in need of modernizing. Most services were developed 10+ years ago and are tightly coupled with their respective applications. Some services are also specific to the type of travel modality, e.g., land, air/sea, pedestrian. PSPD is embarking on a large-scale effort to implement a common services architecture with services based on business processes and workflows. These new services will represent how CBP Officers and others in the field actually work and will be common in the sense that multiple applications needing the same service or function can plug into these common services. Upon completion, there will be a much smaller set of common services instead of the multitude of tightly coupled, application-specific services that exists today. Operational efficiencies and reduced costs are expected as a result of this effort.
Artificial Intelligence (AI) is another area with the potential for explosive growth in PSPD over the next five years. PSPD has already identified several AI use cases and initiated some pilots and proofs of concept. More use cases will arise as AI tools, technologies and services become more ingrained and accepted within OIT. CBP’s philosophy with respect to the use of AI in CBP is that it should act as a force multiplier, achieve cost reductions, or achieve operational efficiencies by reducing manual intervention, freeing up CBP Officers and others to focus on more important tasks. AI is not meant to replace human beings in CBP.
PSPD’s future environment is in alignment with CBP’s modernization initiatives. The future of CBP relies on cutting-edge, modern technology to be successful. Officers and agents need tailored, intuitive, and advanced capabilities to anticipate and combat emerging threats. CBP’s operational environment requires its technology to be innovative, mobile, resilient, available, reliable, and scalable. Furthermore, rapid delivery of enabling technologies such as cloud computing, edge computing (data processed where it is generated), automation, and artificial intelligence offer potential leaps of performance and utility. CBP PSPD’s primary modernization goals are:
4.3 Resiliency and Recovery
Identify, prioritize and address challenges within existing mission critical systems to immediately reduce and quickly recover from outages.
4.4 Mobility and Application Development
Leverage the latest trends and technologies in the areas of mobile and web application development, AI/ML and Generative AI, and human-centered design to achieve rapid, continuous, and secure deployment of new capabilities to all platforms, readily providing mission-required functionality to agents and officers in the field.
4.5 Analytics
Support an enterprise-wide data management strategy to make trusted data readily available anytime and anywhere across the enterprise. Look at opportunities to reduce or eliminate duplicated data across OIT and implement approved strategies. Use modern, cloud-based tools and technologies to establish data warehouses / data lakes and extract more meaningful insights from existing data. Note: Data analytic services are outside the scope of TPVS. However, TPVS captures data that is used for analytics.
4.6 Cloud and Infrastructure
Complete cloud migration of any remaining PSPD system components and support other CBP OIT systems and applications in their cloud migration through testing and technical expertise, as needed. Leverage cloud technologies, services and operations to achieve cost savings and reduce redundancies, where feasible. Where appropriate, identify and refactor applications already migrated to the cloud to leverage the latest in cloud technologies and approaches to increase system performance, availability, efficiency, security, and resiliency. This may include opportunities to transition existing cloud applications to a serverless architecture, to increase system performance and reduce the cost of operating in the cloud. Additionally, continue to enhance CBP’s cybersecurity posture in support of both cloud migration and increased edge-device use without impacting system effectiveness.
5.0 Operating Environment Requirements
· PSPD solutions must use DHS/CBP approved products, standards, services, and profiles as reflected by the hardware, software, and infrastructure components of the DHS/CBP Technical Reference Model (TRM). If new hardware, software and infrastructure components are required to develop, test, or implement the program, these products will be coordinated through the CBP Technology Insertion (TI) process. The DHS/CBP TRM will be updated as technology insertions are accomplished.
· PSPD systems must adhere to the CBP enterprise Technical Reference Architecture (TRA). The TRA establishes a consistent, vendor-agnostic, standards-based architecture to be used by CBP in the development of modernized application systems.
· All application O&M, updates, enhancements, upgrades, or modifications within the scope of this PWS apply to the TPVS applications and the corresponding application infrastructure. The platforms on which the TPVS applications operate (National Data Center (NDC) and CACE) are under the control of other OIT programs and other contract vehicles, however TPVS application teams must support infrastructure maintenance to ensure it does not impact the TPVS applications. Software changes are required to continue to properly interface with host platforms and existing physical and software interfaces. As infrastructure and applications are modernized and migrated to and operated in the cloud, the TPVS applications must continue to meet or exceed their system performance (measured in response time, availability, and scalability) prior to the modernization and/or migration effort. TPVS applications must meet or exceed their required security posture while operating in the cloud.
· All proposed enhancements, improvements, modernizations and new capabilities added to systems are subject to review and approval by the Government in accordance with their Configuration Management/Control Plans.
· All systems are subject to Section 508 compliance per CBP Section 508 Directive Number 5510-040A.
· All personnel supporting OIT must have proper DHS/CBP Background Investigation (BI) per the CBP Security Policies and Procedures Handbook.
· All contractor personnel supporting work on this PWS are required to use GFE computers and software hosting facilities. Exceptions must be approved on a case-by-case basis by the COR.
· All TPVS applications and the work in an environment that requires collaboration and cooperation with other government agencies and other contractors supporting OIT and other related programs with common or shared missions and objectives.
6.0 Objectives
The overall objective is to obtain the full range of operations and maintenance support for the suite of TPVS applications and associated specialized equipment as identified in the following objectives.
This includes ensuring TPVS applications and specialized equipment are properly developed, maintained, updated, and enhanced as necessary to support the critical and dynamic mission requirements of CBP. These objectives are all equally important to CBP.
A Quality Assurance Surveillance Plan (QASP) will be created for each individual task order issued against this BPA award. The QASP will include metrics, performance standards and acceptable quality levels for achieving the objectives of the individual task order.
6.1 Objective 1: Proactive Operations & Maintenance
CBP relies upon TPVS applications and services for mission critical primary and secondary traveler processing at and between U.S. Ports of Entry, vetting services across and beyond DHS, and public facing applications used to facilitate travel to the U.S. This objective is to proactively provide all operations and maintenance (O&M) solutions, processes, and procedures necessary to sustain the suite of deployed TPVS applications, services and specialized equipment at their peak efficiency while maintaining an up-to-date security posture, maximizing resiliency, and minimizing issues and/or downtime. Each TPVS application and service has performance, availability, and security requirements. See Attachment A for specific performance availability and security requirements.
PSPD requires a full range of O&M solutions that are necessary to ensure TPVS applications, services and specialized equipment operate efficiently, effectively and securely, and are available to support CBP mission per their individual requirements. PSPD requires proactive preventive and perfective maintenance while minimizing the need for reactive corrective maintenance necessary for resolving service disruptions.
The proactive approach to operations and maintenance of TPVS applications should provide the highest levels of service and availability through a comprehensive maintenance methodology to optimize performance capability, minimize costs, and effectively manage performance risks. Proactive O&M is a centralized capability. Occasional temporary travel may be required to support fielded systems.
Systems Performance Monitoring O&M support includes monitoring the health and performance of production TPVS applications and all associated specialized hardware, troubleshooting software, troubleshooting specialized hardware, fixing software defects, repairing or replacing specialized hardware, as well as designing, creating, testing and implementing software production baseline updates. PSPD requires performance monitoring tool and expertise by the Contractor to consult, configure, develop and operate effective performance monitoring services.
PSPD maintains a real-time, centralized system dashboard capability to monitor the performance, configuration, status and health of all fielded systems. This capability provides the overall health of all operational systems and allows for issues encountered to be discovered and remedied proactively without CBP operational personnel knowledge or involvement. Maintenance actions by the Contractor are to be coordinated with the CBP Level I Help Desk, which is operated by the CBP EIOD Directorate, and with the Field Support Directorate. A centralized systems performance monitoring dashboard for TPVS applications will need to be updated to encompass new capabilities within PSPD.
O&M support will emphasize proactive performance monitoring to identify and resolve performance risks before they impact mission achievement while responding to customer identified performance deficiencies and/or outages. System performance is to be evaluated on a continual basis to ensure there is no degradation to current performance levels as system capabilities and usage continue to grow. Each TPVS application and service has its performance and availability requirements which define its peak efficiency. See Attachment A for specific performance and availability requirements.
Production Monitoring Support PSPD requires a U.S.-based Tier II and III production monitoring support capability with 24x7 telephonic availability and on call maintenance support to respond to corrective maintenance issues working in coordination with the CBP Enterprise Operations Center (EOC) Technology Service Desk and PSPD production monitoring teams. The Contractor will participate in ad hoc production support requests initiated by the TPVS CBP EOC to assist in troubleshooting and resolving issues. The Contractor is responsible for resolving TPVS application and specialized equipment integration issues. When necessary, the Contractor provides support to Infrastructure teams and interfacing TPVS application teams for troubleshooting and resolving issues impacting TPVS applications. Given the mission critical nature of TPVS applications, production issues are expected to be resolved as soon as possible.
Tier II support consist of qualified technical professionals with the ability to effectively troubleshoot, diagnose, and correct or resolve software and hardware problems. Tier II capabilities include the ability to diagnose and correct problems by interpreting system, application, and database log file information.
Tier III support consist of qualified technical professional subject matter experts (SMEs) who can provide software and hardware expertise to a Tier II technician if that assistance is deemed necessary. Tier III SMEs are to have the technical knowledge necessary to assist the Tier II technician on software and hardware issues that are outside of the normal problems.
On-site support in response to a Tier II and / or Tier III issue may require a qualified field maintenance technician to be physically available at the facility to ensure that the issue is resolved in a timely manner. The Government takes the lead for coordination and outreach for maintenance of onsite systems and equipment with the POE Port Director, and the POE Field Technology Officer (FTO) via the OIT Field Support Area Manager to avoid or minimize operational disruptions. If necessary, a Tier III SME may be expected to lend assistance on site, in cases where his/her presence is required. Tier III SMEs are expected to work with site FTOs when necessary.
Development & Integration Testing PSPD requires development and integration testing services to be conducted in an automated manner throughout the software application support process of all TPVS applications, services, and specialized equipment to assist in engineering design and development and to verify that technical performance specifications have been met. Development & Integration testing capabilities shall support the proactive operations & maintenance objective, as well the enhancements & modernization and new development and emerging technology objectives requiring specialized equipment to enhance capabilities of TPVS applications. Automated testing processes following CBP’s DevSecOps approach is a key objective to support agile rapid application development and for improved system quality. Development & integration testing is conducted by the Contractor and includes testing of components, subsystems, preplanned product improvement changes, hardware/software integration, and production qualification testing. It encompasses the use of DevSecOps automated test tools, models, simulations, test beds, and prototypes or full-scale engineering development models of the system. Development & Integration testing services support test-driven development activities.
6.2 Objective 2: Enhancements & Modernization
PSPD requires TPVS application enhancement and modernization services to quickly provide increased functionality in a secure and stable manner.
Enhancements Enhancements are the modification of software applications performed after delivery to production to continue supporting mission requirements in a changing environment. Enhancements address ongoing mission needs for new functionality, collection of additional data, enhancements to existing interfaces, and implementation of new system-to-system interfaces, etc. This effort encompasses system upgrades and improvements, which are generally updates/changes to existing systems and the corresponding infrastructure installation, patching, and management, as applicable. A key enhancement objective is to identify and incorporate software solutions to optimize the performance and operational cost efficiency of the suite of TPVS applications in support of the CBP mission. Additionally, system enhancements and updates may need to be supported rapidly based on priority operational requirements and changing mission needs, without significant impact to other parallel activities.
Enhancements include all phases of the Software Development Life Cycle (SDLC), including planning, requirements definition and analysis, design, development, testing, integration, implementation, production monitoring and support, and retirement to ensure TPVS applications continue enabling users to meet mission goals and objectives.
Any TPVS application upgrades, enhancements or modifications, will be reviewed and approved in accordance with the CBP change management process, and performed and documented in accordance with CBP and DHS Systems Engineering Life Cycle (SELC) tailored for agile development processes and rapid releases.
Modernization TPVS is a large portfolio of mission critical passenger and immigration management systems in all phases of the application life cycle, from legacy systems nearing end-of-life to newly released development. Modernization addresses the migration of legacy to new applications or platforms, including the integration of new and improved functionality. Modernization objectives support CBP’s cloud migration objective by re-engineering applications to benefit from cloud hosting capabilities for rapid provisioning and scaling. This objective is to identify, plan, and implement modernization activities throughout the TPVS application portfolio. Modernization efforts may be major system overhaul projects as well as re-engineering efforts embedded within the everyday enhancement and O&M work. When TPVS applications are touched, changes shall adhere to CBP’s most recent architecture roadmap where possible to incrementally modernize applications.
Modernization also includes improvements to the customer experience by implementing human-centered design principles into every user interface (UI) as well as the use of AI to achieve operational efficiencies and reduce costs.
Cloud Hosting The CBP OIT cloud migration effort is moving all TPVS applications and services out of NDC and to the cloud by 2025. As of May 2025, 100% of PSPD’s applications and more than 80% of PSPD’s databases were in the CBP cloud (CACE). To complete the TPVS cloud migration and ensure continued operations in the cloud, PSPD requires cloud modernization and cloud migration expertise and services for TPVS applications to be hosted in the cloud in a cost-effective, secure, and agile way. In addition to the applications, the remaining TPVS databases and interfaces, as well as any remaining system components, need to be migrated to CACE.
The strategy for cloud-based services and infrastructure should align to the strategy of the Federal Data Center Consolidation Initiative (FDCCI), the objectives of the enterprise service delivery model, the CBP OIT target/cloud architecture, and support the agency’s ability to deliver future sustainable services. This effort will enable OIT to innovate and modernize the way software is built, deployed and managed. The approach will need to successfully enable OIT to quickly, reliably and consistently deliver modernized digital solutions moving forward. Cloud modernization includes building digital solutions based on microservices, implementing API-based modern web frameworks, building TPVS applications that are extensible to mobile and forward-looking industry paradigms, building consistent, standard, reliable and portable environments in the cloud, and defining container strategies and operational models.
DevSecOps All TPVS application support work must adhere to DevSecOps processes and must utilize the CBP CI/CD pipeline toolset. A comprehensive understanding of DevSecOps principles and demonstrable experience in their practical application are essential for successful implementation at CBP.
DevSecOps ensures security is integrated seamlessly throughout the development lifecycle pipeline, making it a transparent and proactive element, not a late-stage gate. Automated testing is a critical objective, alongside a continuously improving security posture. Contractors may propose enhancements to CBP's DevSecOps processes and CI/CD pipeline tools to optimize the software development approach, demonstrating the contractor's ability to contribute to the continuous improvement of CBP's DevSecOps framework, based on their deep understanding and practical experience in development, security, and operations.
Key aspects of our DevSecOps approach:
· Integrated Security: Security is embedded into every phase of the development lifecycle, from design to deployment and beyond.
· Shared Responsibility: Security is a shared responsibility across development, operations, and security teams, fostering a culture of security ownership.
· Automation-First: We prioritize automation to streamline security processes, accelerate delivery, and improve consistency.
· Collaboration & Communication: Effective communication and close collaboration between development, operations, and security teams are fundamental to DevSecOps success.
· Continuous Feedback Loops: Security feedback is continuously gathered and integrated into the development process, enabling rapid iteration and improvement.
· Proactive Risk Management: We proactively identify and mitigate security risks throughout the lifecycle, minimizing potential vulnerabilities and ensuring resilience.
6.3 Objective 3: New Development and Emerging Technology
PSPD requires new development services to quickly develop new TPVS applications based on world events, stakeholder requests, and technological advances, recognizing that OIT has new projects with challenging schedules and often these projects are not on the known horizon of work. New development services include all phases of the SDLC, including planning, requirements definition and analysis, design, development, testing, integration, implementation, and production monitoring and support to ensure TPVS applications enable users to more effectively meet CBP mission goals and objectives and take advantage of the latest advances in technology, including Generative AI to accelerate new development efforts.
These efforts include the full range of software design, Test-Driven Development (TDD), implementation and integration, including planning, requirements definition and analysis, systems design and development, coding and automated testing, production, implementation, integration, and TPVS application maintenance. This effort encompasses new TPVS application development (for web-based, native mobile, and potentially other application platforms) and system modernization projects. New development is to follow CBP’s Agile Framework and DHS SELC procedures tailored for agile development as well as CBP’s DevSecOps processes. CBP currently follows the Scaled Agile Framework (SAFe) model with two-week sprint cycles for all development activities. Travel may be required to ports of entry in support of initial deployments of newly developed functionality.
6.4 Objective 4: Specialized Equipment
PSPD requires the full range of hardware O&M support for specialized equipment to support end-to-end operations of PSPD systems. Specialized equipment services include operations, monitoring, procurement, and installation services for specialized equipment such as portals, jump kits, tablets and iPads, portable systems, accessories, camera systems, biometric capture devices and software, document readers, document authenticators, and telecommunication devices.
Specialized equipment is subject to change over the period of performance based upon new requirements and emerging technologies.
The key to successfully supporting specialized hardware is to ensure that effective monitoring of the equipment is implemented and that logging and tracking of operational issues is performed to proactively identify where the greatest risk of hardware failures exists and allow for predictive maintenance schedules to be developed. When scheduled maintenance is performed, as opposed to reacting to failures, continuity of operations will be maintained, impacts to users minimized, and customer satisfaction increased.
Specialized equipment services include tracking detailed information on PSPD equipment as part of the CBP technology overview plan. Up-to-date information on government hardware is to be maintained, including fielding and maintenance status, warranty, location, Points of Contact responsible for operation and sustainment of the equipment, pertinent help desk tickets and information on service performed.
PSPD requires to improve its ability to predict equipment lifecycles and schedule maintenance in advance of failure and minimize impact to operations. This includes analysis of hard data such as Mean Time between Failure (MTBF) and Mean Time to Repair (MTTR) for each type of hardware to identify trouble prone items and consider remedial actions.
Items of specialized equipment currently include, but are not limited to, the PALS NextGen USB devices, the Global Entry portals, Global Enrollment System jump-kits, camera systems, biometric capture devices, document readers, document authenticators, mobile device such as tablets that can run primary applications and integrate wirelessly with different types of document readers, telecommunications equipment, and removable media. Support includes replacing existing inventory or adding to inventory as directed by the COR.
6.5 Objective 5: Collaboration
PSPD requires a collaborative environment where the Contractor effectively works with other CBP, DHS, other government agencies, and commercial organizations including other contractors. CBP’s mission achievement is dependent on effective collaboration by the many internal and external organizations. PSPD is committed to CBP’s “One OIT” goal with the objective of operating as a single transparent organization with a unified mission focused culture. A highly collaborative environment will foster the sharing of information, resources, best practices, and opportunities to streamline processes across all of OIT.
6.6 Objective 6: Innovation & Thought Leadership
PSPD requires thought leadership on using innovation, new technologies, new methods, new ideas, new efficiencies, etc. to improve PSPD support for the CBP mission. PSPD is looking to instill a culture of innovation into all TPVS application support activities. PSPD provides CBP, DHS, and stakeholder enforcement agencies the data they need, when they need it, to support and accomplish the important mission of protecting travelers, trade, and the homeland. Innovation and constant improvement are paramount to deliver and sustain technology solutions that ensure the safety and security of travelers entering and exiting the United States, while facilitating and streamlining legitimate trade and travel. Innovation is to be continuous and based on the following approach pillars:
· Innovate to reduce cost
· Innovate to improve service/performance/resilience
· Innovate for end-point customer service
· Innovate to improve delivery speed and quality PSPD requires support to identify new, innovative ways of enabling more effective and efficient performance. This objective is to be used as a means for improvement and possible replacement of existing TPVS applications and processes. PSPD requires innovation in, but not limited to, the following areas: surge capacity, increased consistency and value of applications, improved quality, improved user experience, reduced project risks, reduced re-work, reduced implementation and O&M costs. PSPD’s vision is to continue to streamline operations by introducing efficiencies.
PSPD requires an overall architecture support capability to provide Enterprise Architecture guidance, technology roadmap services, technical tool support, and overall innovation support to all TPVS application teams. The architecture support team will work closely with CBP PSPD’s Enterprise Architecture Branch and coordinate with all TPVS application teams.
Innovation and thought leadership are to be infused into all software development, modernization, enhancements and steady state operations activities.
6.7 Objective 7: Agile Project Management
PSPD requires project management services to manage TPVS applications from a holistic perspective understanding the dependencies between all applications and opportunities to work efficiently and effectively across the portfolio. The contractor shall provide management expertise, oversight, control, and direction in team building, communications, time management, quality assurance and quality control, procedure development, risk management, configuration management, cost management, and software integration.
An Agile-based, holistic approach to project management is critical to CBP’s mission as it provides enhanced visibility throughout the lifecycle of a project, enabling the necessary insight into achievement, progress, challenges, goals and next steps. It also enables PSPD to accommodate high priority changes and changes in direction as dictated by the product owners and the user community, in response to new and evolving threats and risks. PSPD is a very agile, nimble organization and new features which comply with the user requirements are often implemented in a very short amount of time. In an Agile organization, project teams deploy functionality incrementally, minimizing the potential for risk impacts, and provide streamlined documentation throughout the phases of a project. The Contractor is expected to do sprint and release planning (i.e. with user stories in Jira), execution, review and demonstration and retrospectives. The Government Product Owner and Contractor will collaborate to determine, prioritize, and document the product backlog for the project, develop definitions of done, ensure daily scrums are conducted, and CBP tools are utilized to document the agile process.
PSPD requires proper staffing and skillset coverage at all times. The Contractor shall have the ability to recruit, hire, and retain CBP-cleared resources with necessary skillsets to effectively address changes in work priorities and staffing, and shall have the ability to effectively upskill and/or augment resources as technologies evolve.
The contractor shall provide project management services which includes transition planning, project planning, scheduling, tracking, and overall financial management.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .