Q_A from Draft RFP.pdf

PDF 126 KB Posted

Attached to
Cyber TRIDENT Federal contract opportunity
Solicitation number
W900KK-20-R-0001
Issued by
Department of the Army Materiel Command Contracting Command Orlando Contracting Center

About this file

This document provides questions and answers related to a draft request for proposal (RFP) for the Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (TRIDENT) contract. The TRIDENT contract will provide acquisition lifecycle support for the Army's Platform for Cyber Experimentation and Training (PCTE) program of record, continuing development of the platform and integration of third-party vendor capabilities. Key details include that the TRIDENT contractor will be responsible for integration and maintenance of the PCTE platform and products, applying acquisition best practices, and supporting external interoperability initiatives. Questions cover areas such as the current agile development processes, integration pipeline documentation, requirements for maintenance of research computing systems, event support needs, and onboarding of additional third-party vendors. The document indicates the RFP will require pricing of tasks orders for eight years and include small business participation targets.

View the file

Other files for this federal contract opportunity

Other files attached to Cyber TRIDENT, newest first.
File Type Posted
Slides - Industry Day - Pre-Solicitation Briefing Slides Contracts - 4-30-20.pptx PPTX presentation
TO 0001-Order-SOW-CDRLs.pdf PDF
TO 0002-Order-SOW-CDRLs.pdf PDF
DO 0003-Order-SOW-CDRLs.pdf PDF
RFP - W900KK-20-R-0001 DRAFT 30 Apr 2020 Updated.pdf PDF
SOW - DO 3 CYBER TRIDENT DO 3 SOW - 29 Apr 2020 Updated.pdf PDF
SOW - TO 1 CYBER TRIDENT TO 1 SOW - 29 Apr 2020 Updated.pdf PDF
Attach 17 - Proposal Cost Price Workbook 4-30-20 Updated.xls XLS spreadsheet
SOW - TO 2 CYBER TRIDENT TO 2 SOW - 29 Apr 2020 Updated.pdf PDF
CDRL_Base_SOW.pdf PDF
Attach 18 - Past Perf Questionnaire - Cyber TRIDENT - 4-15-20 Updated.docx DOCX document
Attach 1 - SOW - Base CYBER TRIDENT Base SOW - 29 Apr 2020 Updated.pdf PDF
Attach 4 - RCS Price List - 4-24-20 Updated.docx DOCX document
Consolidated Industry Questions 1-200 4-30-2020 Posted (2).pdf PDF
Consolidated Industry Questions 1-200 4-30-2020 Posted.pdf PDF
Consolidated Industry Questions-Answer 1-74.pdf PDF
Q-As -Cyber TRIDENT W900KK-20-R-0001 27 Mar 2020.pdf PDF
Instructions for Obtaining Distribution D Document - 13 Mar 2020.pdf PDF
Distribution Agreement - Cyber TRIDENT Solicitation -Final 13 Mar 2020.pdf PDF
List of Attachments - 13 Mar 2020.pdf PDF
Attach 19 - Q-A Spreadsheet-12 Mar 2020.xlsx XLSX spreadsheet
00 Solicitation Attachment List.pdf PDF
Attach 18 - Past Perf Questionaire - Cyber TRIDENT.docx DOCX document
Statement of Work - DO 1 - Infrastructure and Maintenance.pdf PDF
Attach 14 - PCTE DD254.pdf PDF
Instructions to Obtain Distribution D Documents.docx DOCX document
Attach 16 - SF1408 - Pre-Award Suvey of Prospective Contractor Acctg System.pdf PDF
Attach 5 Small Business Participation Proposal Form.DOCX DOCX document
Attach 1 - Statement of Work - Basic Contract - Cyber TRIDENT.pdf PDF
Attach 2 -Contract Labor Rates.docx DOCX document
Attach 15 - Pre-Award Survey of Prospective Contractor Acctg System Checklist.pdf PDF
RFP - W900KK-20-R-0001 DRAFT 10 Mar 2020.pdf PDF
Statement of Work - DO 2 - Integraton Factory.pdf PDF
Statement of Work -DO 3 - Platform Capability Production.pdf PDF
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Question # Subject &/or SOW Reference Questions Gov't Answer

PCTE L and M v11 - Technical Management, Pg 1, Section 1.1.1.A, Agile Development Operations (DevOps)

Please describe the current process.

Platform Development Kit details current process.

Provide specific questions on any of the current process documentation. Furthermore, the PCTE Industry Day on 11 Jun 2019, the program office covered on slides 6-11 & 14-15 our agile development processes, construct, and tooling as well.

PCTE L and M v11 - Technical Management, Pg 1, Section 1.1.1.A.1, Agile Development Operations (DevOps)

Please describe current velocity and quantity of incomplete tasks (user story under-delivery).

Providing our metrics will not help you recommend a process or technique to improve our velocity. The offeror is recommended to provide innovation in which the integration factory, CI/CD pipeline, and agile DevOps processes can scale and be more robust than primary Gov't led integration activities currently - as opposed to strictly measuring on velocity.

PCTE L and M v11 - Technical Management, Pg 1, Section 1.2.A.4, Infrastructure / Platform Operations

The scope associated with this criteria includes the deployment of platform training applications. Is the actual tooling and processes associated with deploying exercise-specific emulated networks to the platform part of the TRIDENT scope, or is it capability provided by 3rd party applications.

This sub-element was removed from Section L and M to minimize complexity associated with criteria. As part of execution of DO1-2-3, it is expected prospective bidders are to integrate capabilities within a multi-vendor environment. To verify the agile integration in an incremental and iterative fashion, the ability to test across the plan-prepare-execute-assess training lifecycle of components delivered by multiple vendors is critical.

This is further reinforced with DO2 providing an 3rd party orchestration role. Any software integration challenges would need to be mediated amongst the Government, TRIDENT, and 3rd party applications - but would require overall lead effort by TRIDENT in the collaboration via the integration factory and CI/CD processes.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 6, Section 3.2, Operations

How is system availability (Ao, e.g., 95%) for a "high quality, persistent user experience" determined? Will the Government provide this metric? Is the requirement " The contractor shall manage PCTE platform operations to ensure a system availability (Ao) of 95% for a high quality, persistent user experience".

95% system availability in discussion internally for calculation. Final number will come with Draft RFP. With PCTE capabilities being provided by multiple vendor, it is expected that TRIDENT bidders would have full cognizance over platform infrastructure layers across hardware, software virtualization/middleware, and core enterprise services. The system is expected to maintain this availability number even through basic troubleshooting steps provided and maintained by the vendor (to include those provided by 3rd parties).

Attachment 19 - Q&A Form - Cyber TRIDENT Solicitation - Consolidated List of Questions

CYBER TRIDENT DO 1 SOW v8 -11-25-20, Pg 6, 3.2.1, PCTE Maintenance and Support

Will the Government provided PDK (or a bidder's library) be updated to contain complete RCS Infrastructure (Hardware and Software)to include model numbers, actual quantities, spares, etc. in order to provide the offeror with enough information to provide a Fixed-Price bid?

Yes, planning to provide HW/SW List

CYBER TRIDENT DO 1 SOW v8 -11-25-21, Pg 7, Section 3.2.2, PCTE Maintenance and Support

Will the Government provide a roll-out schedule for the RCS deployments or will the offeror just assume all RCS are active on Day 1 of the contract.

For the purpose of DO 1, the assumption should be made all RCS are active on day one.

CYBER TRIDENT DO 1 SOW v8 -11-25-21, Pg 7, Section 3.2.2, PCTE Maintenance and Support

Are there six or seven RCS Locations, there is a discrepancy between the Base SOW (Vicksburg) and DO 1 which has six and does not include Vicksburg. How many nodes will there be at each location?

Will provide updated RCS information for clarity at Draft RFP. At present there is anticipated to be 7 RCS (1 DevRCS and 6 production nodes - of which are at multiple, separate classification levels).

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 6, Section 3.2, PCTE Maintenance and Support Are MOAs currently in place? Will the Government initially establish these agreements?

Yes, MOAs in place and/or Government will do initial establishment. Government has lead on MOAs, and contractor in assist role.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 6, Section 3.2.1, PCTE Maintenance and Support

Can the Government define the performance requirements for the RCS so the offeror can define the required performance tests?

The Government is assembling a number of RCS related documents to be provided as part of the bidders library.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 7, Section 3.2.2, Infrastructure Tier 3 Technical Support

Is the trouble ticket application that is accessible from the PCTE platform GOTS or is it to be provided by the TRIDENT contractor?

As part of the Cyber Innovation Challenge (CIC) 3, a Technical Operations Dashboard was awarded that provided JIRA Service Desk for ticketing from users, and the DI2E instance of JIRA provides ticketing for the development team. Both applications are intended to stay in place after TRIDENT, but the offeror may propose alternatives that may be beneficial to the Government.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 7, Section 3.2.2, Infrastructure Tier 3 Technical Support Does the Tier 3 Contractor Technical Support route Tier 3 tickets to the CIC Vendors?

Tier 2 internal PM help desk routes to Tier 3 and CIC vendors as per slide 19 of the Industry Day slides from

I/ITSEC 2019.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, PG 14, Section, 3.4.1, Maintenance Support

In this context, are vendors outside the set of 3rd party vendors performing under the CICs or other contracts, or are CIC COTS providers included in this requirement?

Vendors are any third party company or Govt organization that is needed to be interfaced with to ensure full operations of the platform.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg (N/A), Section 3, Multiple

Since these documents do not typically apply to Agile/DevOps programs will these CDRLs be deleted or allowed to be tailored/replaced by the offerors based on their proposed solution?

The program office is relooking each of the CDRLs.

However, we intend to tailor traditional CDRLs to be updated to fit the Agile nature of PCTE. The program office is not looking to develop a SSS, SRS, CRS centric requirement trace but to align them within a agile approach that could include decomposition and alignment of program office requirements to agile backlog, epics, user stories and themes evolved over time. Further review by the Government will better elaborate this.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 6, Section 3.2.1, Capability Development, Integration, Delivery and Sustainment

Since these events do not typically apply to Agile/DevOps programs will these events be deleted or allowed to be tailored/replaced by the offerors based on their proposed solution?

The offeror may recommend tailoring or removal of these events in their proposed solution. No traditional SETR reviews are not anticipated but agile reviews corresponding to them are requested to be offered for substitution.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 7, Section 3.2.2, Integration Factory

Does the offeror make its recommendations against the information solely contained in the PDK, or are recommendations to consider current prototype activities and capabilities?

The current integration factory development environment is documented in the PDK. We have asked for innovations in Section L&M for the current status documented in the PDK. Additional information has also been furnished within the PCTE Jun 2019 Industry Day and I/ITSEC Presentations published.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 25, Section 3.6.2, Developmental Testing

Do these exist today? Do we have to create from scratch? Does a current RTM/RVTM exist today? Will the bidder's library contain the current prototype RVTM, test reports, test artifacts, test logs, etc.?

Regarding T&E, an RTM is available linking requirements to capabilities to test cases. The RTM will need to be modified and managed by the TRIDENT vendor upon contract award. The RTM, Test reports and artifacts will be made available in the bidders library.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 26, Section 3.6.4, Defect Management and Resolution

Any effective failure analysis effort seems to have dependency on 3rd Party Software, and 3rd Party processes, in order to identify potential root causes and resolutions. Do CIC vendors have the requirements to support this activity, or will their software, development processes, architecture artifacts, etc. be provided in the bidder's library?

CIC vendors have the requirement to support bugs and defects, and currently this activity is supported in the Government managed JIRA ticketing system. As part of leading DO2 efforts, it is expected TRIDENT bidder would be leading the orchestration and collaboration of this multi-vendor integration factory and managing the allocation, tracking, and satisfactory resolution of defects provided by 3rd party vendors.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 8, Section 3.2.3, Integration

Reword or remove the contractor's responsibility to ensure these updates, to read that the contractor can report status on the updates to documentation.

Yes, we will reword in the SOW with the below:

The contractor shall integrate 3rd party vendor contributions into an overall PCTE integration package to include documentation.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 13, Section 3.2.3.8, Configuration Management (CM)

Does this requirement apply to new platform capability developed under the TRIDENT contract or apply to existing potential Configuration Items? Does this requirement apply to 3rd Party provided applications and products?

Yes, applies to 3rd party provided applications and products. The core crux of DO2 is an integration factory that needs to track, orchestrate, integrate, and deliver capabilities via a mature CI/CD process - a cornerstone of that is robust CM processes and tools that reflect the total capabilities that amount to the final PCTE platform, development tooling, lab configuration and other items necessary to routinely and rapidly produce "shippable products" out of the integration factory.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 16, Section 3.4.1, Security Engineering

Remove requirement for a separate cyber security teams and let the offeror propose how cybersecurity activates are performed.

Acknowledged, and will take under consideration.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 23, Section 3.5, Training

Does this requirement apply to 3rd party training applications, and if so, will 3rd party vendors provide that training content, or will the offeror provide a solution to obtain this critical input?

Yes, applies to 3rd party provided applications and products. Vendors will provide training data and information, and offeror will package into a releasable training product.

CYBER TRIDENT DO 3 SOW v10 -11-25-19, Pg 6, Section 3.2.6, Requirements

The scope of this section seems to heavily utilize terminology of a traditional DoD 5000 waterfall program. Will these requirements be removed based on the Agile/DevOps requirements elsewhere in the SOWs, or can the offeror tailor this approach in their offering?

Offeror can tailor in their approach/proposal. See line item 13 for similar response.

CYBER TRIDENT DO 3 SOW v10 -11-25-19, Pg 7, Section 3.2.7, Architecture

Can the external stakeholder be provided, and are they funded by the Cyber TRIDENT contract? Can the definition of "External" be clarified - is this outside of the contractor's program staff, within its parent company and partners, or is completely external to those entities? Can "each iteration of PCTE" be clarified since it indicates how often this event occurs?

Currently that would include core program office, TCM, and USCC identified representatives. Currently the program office holds architecture working groups with representatives from PM and vendors with gov't holding final approval.

CYBER TRIDENT DO 3 SOW v10 -11-25-19, Pg 9, Section 3.2.13, Metrics

Will the definitions of these metric areas be provided by the Government or left to the offerors to develop their own definitions which may vary significantly. Are these items to be provided by a DID/CDRL?

Will be left to offerors.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 6, Section 3.2.1, PCTE Maintenance and Support

Given that software patches and updates from vendors can be released at random times (with some possibly being critical), how do we bound this and provide a firm bid for uncertain future tasking?

Software patching and updating is a routine task across all DoD programs with periodic and recurring patch cycles developed and executed by the contractor with Government oversight. The possibility of a critical, out of cycle patch will happen and should be planned for based on the offeror's experience with critical COTS patching (i.e.: Microsoft updates, etc)

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 6, 3.3.1, Event and Exercise Support

Will the Government provide how many events will take place, their duration, how many users will attend, or how taxing they will be on the system in order for the offeror to bid this effort?

The contractor should estimate attending one event per quarter. The number of users, and taxing on the system are not relevant as the event will be executed by another organization.

CYBER TRIDENT DO 2 SOW v9 -11-25-19, Pg 9, Section 3.2.3.1, Third Party Onboarding and Orchestration

Given that we don't know (right now) how many future CICs there will be or the number of future CIC vendors, how can we bid onboarding and orchestrating an arbitrary amount of third party vendors?

The current vendor pool as denoted on slide 13 of the PCTE Tech State of the Union slides held on 11 JUN 2019 show the current vendors that will be analogous in size and scale to the number moving forward while factoring in vendor turnover.

CYBER TRIDENT Base SOW v20 -11-25-19, Pg 11, Section 3.1.9.1, Transition In (Initial Operations) Please clarify all components that are expected to be tested as part of transition-in.

Base SOW will be updated as part of Draft RFP to show all elements that will need to included in the Contractor's Transition In Test plan.

CYBER TRIDENT Base SOW v20 -11-25-19, Pg 29, Section 3.6.1, Maintenance Support

Please clarify this support is limited to platform infrastructure and does not include Training Applications developed by 3rd Party providers.

Base SOW is not priced effort, and therefore is only in place for future scope. Support services is broad in nature and not bound to only platform infrastructure.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 14, Section, 3.4.1, Maintenance Support

Please clarify this support is limited to platform infrastructure and does not include Training Applications developed by 3rd Party providers.

CIC vendor product maintenance is not included however maintenance on enterprise COTS products is included (i.e.: Windows updates, Red Hat updates, etc)

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 15, Section 3.4.2, Property Accountability and Management

Please specify and quantify supplies. Or is the requirement for the Contractor to ensure 100% accountability for Government property to be transferred to the Contractor(e.g. GFP maintenance parts).

Contractor will be responsible for 100% accountability of all equipment, not just GFP. Complete list will be available shortly.

CYBER TRIDENT DO 1 SOW v8 -11-25-19, Pg 15, Section 3.4.3, Supply Management

PEO STRI Organizational and installation supplies is confusing. Is the requirement "The contractor shall establish and maintain an automated supply system that accounts for Government property to be transferred to the Contractor(e.g. GFP maintenance parts).

Will clarify. The intention is the contractor will have responsibility for PCTE property accountability of all PCTE equipment, not just GFP.

CYBER TRIDENT DO 3 SOW v10 -11-25-19, Pg 2, Section 3.1.3, Schedule

We are not familiar with the current Government agile scrum process. Is the requirement? The contractor shall plan, execute and deliver contributions within their implementation of an agile scrum processes implemented within Delivery Order 2.

See Platform Development Kit (PDK) for all necessary information on Government agile scrum process. This process will be the starting point for the offeror, however, the Government will be open to proposed improvements and changes based on the offeror's feedback to innovate the process.

CYBER TRIDENT DO 3 SOW v10 -11-25-19, Pg 16, Section 3.4.1, Licensing and Warranty Management

Please clarify - Is this requirement restricted to vender platform licenses managed by the Contractor and excludes CIC application licenses acquired by the Government?

The vendor shall be the single point contact regarding education and training of licensed COTS and GOTS hardware / software. The vendor shall be the coordinator for new equipment training and new software training to include all initial purchases, fielding and sustainment of education / training with regards to major revisions / versions changes. This includes COTS, GOTS and proprietary hardware or software.

35 Cyber TRIDENT DO 2 Section 3.6.1 CI/CD Testing

"The contractor shall maintain and enhance the current implementation of the CI/CD pipelines documented in the PCTE PDK as directed by the Government team." - In the interest of improving the efficiency and collaboration of the entire SDLC, would the government be open to migrating their CI/CD pipelines to a new platform? Also, we only saw that CI/CD was called out, does the government expect to maintain other tools/processes for source code management or issue tracking for example?

As stated in Section L Technical/Management Approach factor, the Government is looking for innovative, mature and robust means to establish an integration factory of which CI/CD is core. The Government intends to evaluate offeror solutions on these fronts and would be open to understanding alternative tooling as long as it aligns to commercial best practices, industry trends, and modern tooling to rapidly deliver platform capabilities on-demand. The PCTE strategy is to maximize utilization of COTS components and with that model we do not expect to do much customer software development or coding.

See PDK for current tools used by PCTE.

36 Cyber TRIDENT DO 2

We saw that SAST was called out in Security Requirements in draft of SOW for DO 2, but didn't see any mention of DAST, dependency scanning, container scanning or license compliance checks. Are those also required?

The program office is looking for a CI/CD process that implements variety of automated checks, tests, and compliance gates of which cybersecurity is one such lane (others include regression, scalability, loading, new feature, API contract testing, etc). It is expected SAST will be of limited value to the program office due to the nature of heavy COTS components for which we don’t own the source code for. There will be instances of open source capabilities integrated into the platform to enable integration such as RabbitMQ, OpenShift, API Gateway, NGINX, and Infrastructure as Code scripts for which source is available but which is integrated into the platform.

How many users does PCTE expect to be involved in the total development process:

developers, program management, security/IA, infrastructure

The program office expects at least 100-120 personnel responsible for development activities across Government lanes, vendors, COTS providers, and end users (as part of the DevOps integration).

Would the government be open to using a single platform that supported the entire DevSecOps lifecycle as opposed to using multiple point solutions that only address pieces of the Software Development lifecycle?

IAW Section L, the Government would be willing to consider the merits of any offeror’s DevSecOps process and the innovation that it bring forth. The Government is highly seeking robust, mature and commercial best practices to establish this integration factory utilizing DevOps, CI/CD and agile processes as the core tenets for its integration factory.

30% Small business target During prior industry engagements and FBO postings, potential offerors were told that the small business target would be 30%, but not including CLINs for licensing (estimate 40% of the PCTE mission funding that will be applied to TRIDENT). This seems to have changed in the DRFP, as there is no specific language except for the 30% on a yearly basis. Please clarify whether the small business target will be based on all CLINS, or if the licensing ones will be excluded. The Government is adding the language to Section G3 removing CLIN 0004, Software Licensing from the calculation of the small business participation percentage and amount.

Classification of major subs (RFP L.2.0 - page 88) The current classification of major subcontractors is any company expected to have a 30

To clarify, the major subcontractor definition is only for defining the proposal information required for the past performance and cost/price factor. The solicitation only requires cost information and past performance on major subcontractors that comprise 30% or more of the effort.

However, there is not a goal or requirement for major subcontractors to be 30% of more of the contract as long as they are still meeting the SB participation goal requirements. The SB participation requirement can be met in various ways, such as multiple SB subcontractors equating to a total of 30%. In this example there could be no major subcontractors. The Government is providing this clarification and will not be changing the definition to the major subcontractor.

RCS Availability (RFP L2.0 Factor 2) On both the RFP and SOW (TO1) the requirement for 95% availability for the RCS is included. Please clarify whether this is "Per RCS," "Overall," or "Per RCS classification level."

The 95% availability requirement is per RCS. DO 1 SOW, Section 3.1.2 has been updated to reflect this clarification.

RCS Availability (RFP L2.0 Factor 2) How will the government measure the level of availability? For example, if the system is functional but externally provided DoDIN network services are down, does that count against the availability?

No, there are a number of factors that would not count against the availability time. Please review SOW Section

3.2.1 on TO 0001 which provide what is not included in the availability times.

Transition in and SCIF Pricing (Cost volume and RFP L.2.0 Factor 2 v. and vi.

Referencing the following RFP Cost Volume paragraphs:

v. Transition of Incoming Contractor (FFP CLIN 0012 of Basic): The offeror shall propose a price for requirements IAW base SOW, Para 3.1.9.1 and 3.1.9.2 in the cost/price volume for completing all the transition-in activities of the contractor’s proposed transition plan and a price for providing a Sensitive Compartmented Information Facility.

Completion of Transition In Activities, 1 each, $___________________.

vi. Sensitive Compartmented Information Facility (SCIF) (FFP CLIN 0013 of Basic):

The offeror shall propose a FFP price for providing a SCIF IAW base SOW, Para 3.1.9.2 in the cost/price volume.

Sensitive Compartmented Information Facility, 1 each, $____________.

a. Both of these say to include prices for the SCIF - need clarification on what the difference is between the two

b. What are we actually pricing for the SCIF? Square footage? Actual build and accreditation costs?

a) Item v and vi have been corrected with item v. being only for the transition in activities and vi being only for the set up of the SCIF. B). Pricing for CLIN 0013 is for completion of activities required to provide the use of a SCIF IAW Base SOW 3.1.9.2. Section 3.1.9.2 states the specification of the SCIF and facilities to be provided by the contractor.

RFP L.1.5 (Transition Plan) Should Base SOW paragraph 3.1.9.2 (SCIF) also be referenced here?

Concur with change. Will update as needed.

RFP L.1.4 (Third Party Integration and Coordination) References TO 0002, SOW-2020-011, Section 3.1.3.2, But this paragraph doesn't exist Correct. References are being corrected to read:

References TO 0002, SOW-2020-011, Section 3.1. and 3.2

TO1 LNOs Will a daily workplace facility be provided for all LNOs at the RCS locations listed in the SOW, or does the contractor need to provide an office location at each site? The LNO requirements were removed from TO 0001.

This may be a future requirement as it is in the scope of the Base SOW.

Base SOW 3.4.5 (SOC) Will PdM CRT provide any office space, equipment, tools, or cybersecurity personnel to work within the SOC? If so, please provide information on each of those items, including product names, versions, how many Government personnel will be provided and what are the anticipated titles/skillsets.

This may be a future requirement because it is scope within the Base SOW, however not a current requirement as part of DO 1-3.

Base SOW 3.4.5 (SOC) What are the anticipated operating hours of the SOC? (24/7, 8/7, 8/5) This may be a future requirement because it is scope within the Base SOW, however not a current requirement as part of DO 1-3.

Base SOW 3.4.5 (SOC) Will individual SOC capabilities be required for each classification level of the PCTE RCS systems? This may be a future requirement because it is scope within the Base SOW, however not a current requirement as part of DO 1-3.

Base SOW 3.4.5 (SOC) Will the TRIDENT Contractor be responsible for obtaining an the initial RMF Accreditation for the SOC, or will this be inherited? This may be a future requirement because it is scope within the Base SOW, however not a current requirement as part of DO 1-3.

Base SOW 3.4.5 (SOC) Does the government have plans to accredit the SOC as a Cybersecurity Service Provider (CSP) under DoDi 8530.01? This may be a future requirement because it is scope within the Base SOW, however not a current requirement as part of DO 1-3.

Section L.5.5 Accounting System Compliance it indicates that “offeror shall provide documentation from DCMA with status of their accounting system, to include approval of the offeror’s Cost Accounting System. If status of accounting system letter is more than a year old and the offeror has a more current DCAA audit report completed commenting on the status of their accounting system, a copy of the report shall be submitted with the proposal. ”

Is it a correction assumption that an offeror will be deemed compliant and meet this requirement by providing their approval letter even though the letter is dated in 2012 as long as no new additional communication indicating the system is not approved has been received? If not, please clarify what is required when the approval is more than a year old. Sec L5.5 has been modified to require offeror's with an approved accounting system from DCAA over one year must complete the Pre-Award Survey of Perspective Contractor Accounting System Checklist (attachment 15) and certify that there has been no changes to their accounting system since the approval. If there has been changes than a the offeror's accounting system must be reviewed and approved.

53 Past Performance Questionnaire

Given that the intention of the CIC was to provided piloting; please confirm that the Cyber Innovation Challenges (CIC) activity listed in the Past Performance Questionnaire is for informational purposes only. We request that this activity not be considered in any rating of relevancy in order to provide the full advantage to the entire field of respondents.

The Government will consider past performance references in accordance with the definition and criteria stated in Section L and M of the RFP, to include past performance on CICs if the performance meets the definition of relevancy and is within the recency criteria.

54 Proposal Instructions L.2.0

For purposes of the RFP, the Government is defining "major subcontractors" as subcontractor who provides at least 30% of the proposed total price/cost (excluding the Offeror’s profit/fee), for the contract. DFARS (Defense Federal Acquisition Regulation Supplement 209.571-1) defines a major subcontractor as 10% and/or $55M. Please consider revising the RFP language to match 10% and/or $55M, as this will benefit the Government as Prime Contractors can build the necessary best to market teams without unnecessary restrictions. The 30% requirement becomes unattainable with the small business percentage also at 30%. Together that precludes a prime from having more than one large business on the team thus greatly limiting the capabilities that could be provided.

To clarify, the major subcontractor definition is only for defining the proposal information required for the past performance and cost/price factor. The solicitation only requires cost information and past performance on major subcontractors that comprise 30% or more of the effort.

However, there is not a goal or requirement for major subcontractors to be 30% or more of the contract other than for meeting the SB participation goal requirements.

The SB participation requirement can be met in various ways, such as multiple SB subcontractors equating to a total of 30%. In this example there could be no major subcontractors. In response to your request, the Government is reducing the definition for major subcontractor in Section L.2.0 Proposal Instruction from 30% to 20% of the proposed total cost/price (excluding the Offeror's profit/fee).

55 L.2.2.2 Video Presentation

Can the Government please provide the existing process referenced on Page 89 "existing Government led Agile process" and again on Page 93 so that all vendors can have access to the referenced documents/processes?

See Platform Development Kit (PDK) for all necessary information on Government agile scrum process.

RFP; page 11 CLIN 1006 Should CLIN 1006 be designated as CPFF to maintain consistency with the other periods of performance? CLINs 0006 and 0007 have been changed to match their corresponding CLINs (1006, 1007, 2006 and 2007)

RFP; page 12 CLIN 1007 Should CLIN 1007 be designated as FFP to maintain consistency with the other periods of performance? CLINs 0006 and 0007 have been changed to match their corresponding CLINs (1006, 1007, 2006 and 2007)

58 RFP; page 17 CLIN 2007 CLIN 2007 has CPFF and FFP designations. Please confirm that this should be FFP. CLIN 2007 has been corrected to CPFF.

RFP; page 18 CLIN 2009 Please confirm that CLIN 2009 pertains to Contract Year 8.

CLIN 2009 has been corrected to Contract Year 8.

RFP; page 21; Section B1.1 Please clarify what is envisioned in the sentence "The Government may place unilateral delivery orders at the stated FFPs during the ordering period."

This terms allows the Government to place orders within the ordering period at the contract price for the CLINs 0001, 0002, 0003, 0012, 0013 and Attachments 003 and

004. Given the prices are already established at the award of the basic contract, no negotiations are required, thus unilateral orders will be issued IAW the price and delivery schedule on the basic contract for those CLINs and the parts list attachments.

RFP; page 21; Section B1.2 Please confirm if there is any material difference between a "delivery order" and a "task order".

Delivery Order means an order for supplies placed against an established contract and a task order means an order for services placed against an established contract.

RFP; page 29; CLIN 0012 Please confirm that CLIN 0012 should end on 31-May-2021 or if it will extend 14 months?

The ordering period for CLIN 0012 has been extended from 31 May 2021 to 30 Sep 2021. Please note the SCIF requirement description has been removed from this CLIN as the SCIF requirement is in CLIN 0013.

RFP; page 30; CLIN 2007 Please confirm that CLIN 2007 should end on 24-Mar-2029 or if it should end on 31-

Mar-2029? CLIN 2007 has been corrected to end on 31 Mar 2029

RFP; page 87; L2.0

Will the Government please share the price reasonableness range with Industry? If not, will the Government share how they will determine if a vendor is within the range of price reasonableness? Please describe the competitive range within the Price Evaluation process starting on Page 116.

1) The Government does not have price reasonable range information. 2) The Government's determination of price reasonableness will be IAW FAR 15.404-1 and will perform various techniques as described in Section M such as price analysis and cost analysis. Section M, Part B, M.2.0, Items 5-7 will be changed from price reasonableness to price analysis. 3) If discussions are necessary, then the KO must make a competitive range determination considering the initial evaluations for all factors from all the offerors to identify the most highly rated proposals which have a reasonable chance of being selected for award. The competitive range determination is a qualitive judgment based on the factual content of the proposals, and it must carefully consider both technical merit/performance and price.

Therefore, the KO will not make a determination considering the cost/price evaluation factor only to identify the most highly rated proposals.

RFP; page 96, a (also pages 104, 105, 108, 119) Please clarify whether the use of "principal" subcontractor is the same as a "major" subcontractor discussed on page 88.

Corrected principal subcontractor to major subcontractor throughout Sections L and M.

RFP; page 99; i. Please clarify how many years TO2 should be priced. The text in the first sentence says submit price for five years but in the last sentence it includes hours for all 8 years. TO 0002 should be priced for 8 years.

RFP; page 100; ii.

Please clarify how many years DO3 should be priced. The text in the first sentence says submit price for five years but in the last sentence it says "shall be priced for the base year and all option years ".

DO 0003 should be priced for 8 years. This error was also corrected in Section L.2.0.c.ii.B

RFP page 116; section 2.1 Please clarify whether Task Order 1 will be subject to the most Probable Cost adjustments since it is FFP and the sentence refers to CPFF DO/TOs.

TO 0001 will not be subject to a most probable cost adjustment. Correction is made to Section M, Part B, Item M.2.1 for TO 0001.

69 RFP Page 99

RFP Page 99 states that a FPRA takes precedence over a FPRR. Please confirm that this is to be interpreted that the Government is requesting Offerors to provide a FPRA if they have one, otherwise the FPRR should be provided. And that this does not imply an advantage to Offerors with a FPRA over those without and FPRA. Offerors are not in full control of the issuance of the FPRA.

For the purpose of substantiating rates and cost, an FPRA takes precedence over a FPRR only if available. If an FPRA is not available, the offeror shall submit their highest available level of substantiating information in the order of preference stated in Section L. The information preference does not imply an advantage to offerors without a FPRA.

RFP page 113; Relative Order of Importance

Page 113 of the RFP states that all non-cost factors when combined are approximately equal to the cost factor. FAR 15.101-1 provides the Government broad discretion to determine if the non-cost factors should be significantly more important, equal or less than the cost factors. We recommend the best value trade-off be revised such that the non-cost factors are significantly more important than the cost factors. This would maximize the Government's discretion to award to the Offeror whose proposal offers the greatest overall value to include cost. If the cost and non-cost factors are equal then an Offeror with a significantly lower price and a lower scoring technical proposal would be selected for award thus creating a defacto LPTA evaluation. To clarify we are not suggesting the Government ignore price, rather we recommend the Government maximize the flexibility provided by the best value tradeoff process.

Your suggestion has been considered and at this time, there are no changes to the relative order of importance to the solicitation.

71 Section H

One of the primary costs involved in delivering an end-to-end service is the cost of purchasing third-party hardware / software. Additional cost savings would be achieved for the Government if the Government agrees that "the Prime Contractor is purchasing the third-party hardware / software as an agent of the Government only and is a pass-through/ resale directly to the Government. Thus, the Prime Contractor would not be responsible for the physical asset other than to procure it on behalf of the government."

To clarify, the Prime Contractor is still responsible for the configuration and O&M services associated with the use of the Government Owned hardware / software to deliver the end-to-end service. Does the Government agree with this statement? Could the Government insert this language into the RFP, perhaps in Section H?

The Government does not have a requirement for a third-party hardware/software agent for the Cyber TRIDENT requirements, therefore we will not be inserting the suggested language into the RFP.

72 DO2 CLIN Structure

Can the Government please clarify the intent associated with a flat level of effort over eight years for DO2? DO2 is designed to handle requirements, services, and deliverables that would typically follow more of a bell curve rather than a straight line. Is the Government simply contracting for a specific capacity or is there an alignment with our proposed solution? We recommend the Government remove the Fixed LOE clause and ask Contractors propose their anticipated level of effort.

1) The Gov't's intent associated with the consistent estimated (78K+) hours for each year is to provide offerors an expected level of effort for completing the various tasking for this term type order. 2) The Gov't is contracting for a specified level of effort for a stated time period employing the contractor's proposed solutions to the various requirements. The Gov't considered your recommendation, and will continue with use of the LOE clause stated in Section H1.

73 DO2 CLIN Structure

Where a fixed level of effort is required we recommend use of a FFP-LOE contract type rather than CPFF, thus shifting the risk associated with the cost of labor to the contractor rather than Government.

The level of effort is only a general estimate of hours for factory integration support. Due to the unknown aspect of this requirement, the Government incorporated the level of effort clause stated in H1, allowing the Government a proportional reduction to the fee amount based on the actual hours incurred from the hours estimated on the order. This reduction will protect the Government in situations where the actual hours incurred are significantly less than originally estimated. This CLIN's quantity of work, complexity of the task, as well as, the contractor's solution have a direct effect of the number of hours needed to support this effort. Given the quantity of work and exact tasking going to be assigned is unknown and can only be generally estimated, the Level of Effort Clause incorporated under H1 is necessary to protect the Government's interest.

74 DO2 CLIN Structure

CLINs assigned to DO2 such as CLIN 0010 – Support Services (CPFF) and CLIN 0011 (FFP) provide the flexibility to procure either under CPFF or FFP cost structures. Such flexibility is in the best interest of the Government given the uncertainty precisely forecasting the user load for support services in Contract Years 3 – 8. We recommend the Government adopt a mix of CPFF and FFP on a year-by-year basis for DO2.

Specifically, use CPFF in the first two years when the learning curve is steep and FFP in the later years, reducing the risk to the Government. This blended CPFF/FFP bid would be based on the responder’s estimated user and system loads in the out-years.

The user and system load forecast should be documented in the responder's Basis of Estimate (BOE) documentation provided in the Pricing Volume. We also recommend the RFP include a clause to allow rebaselining prior to the start of any Option Year based on the actual user and system loads from the prior years.

The ability to switch from CPFF to FFP in the outyears is available as currently structure as the outyears are options and do not have to be exercised. If at the time of option, the Government feels there is sufficient information available and the requirement is well defined, then the options will not be exercised and a new order will be issued based on the information available.

File details come from the government source that posted it. Updated .