DRAFT PERFORMANCE WORK STATEMENT SUPPLY CHAIN-INDUSTRIAL RISK ( Feb 23).pdf

PDF 231 KB Posted

Attached to
Sources Sought for Supply Chain and Industrial Analysis Federal contract opportunity
Solicitation number
W911NF-23-S-0001
Issued by
Department of the Army Materiel Command Army Contracting Command Aberdeen Proving Ground

About this file

This performance work statement outlines supply chain and industrial risk analysis services required by the U.S. Army Futures Command. The contractor shall catalogue non-traditional Army contractors, conduct risk assessments of companies' supply chains and industries, and provide mapping and monitoring tools. Specific requirements include mapping contractors' supply chains to third tier suppliers; assessing financial, operational, legal, cyber, and other risks; advising on data strategy and knowledge management; and maintaining a risk dashboard. The contractor must have security clearance and safeguard all classified information. The contract is firm-fixed-price with a one-year base period and four one-year options. The response deadline for this sources sought notice is March 15, 2023.

View the file

Other files for this federal contract opportunity

Other files attached to Sources Sought for Supply Chain and Industrial Analysis, newest first.
File Type Posted
DRAFT PERFORMANCE WORK STATEMENT SUPPLY CHAIN-INDUSTRIAL RISK ( Feb 23).pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

FOR

SUPPLY CHAIN & INDUSTRIAL RISK ANALYSIS

ACQUISITION AND SYSTEMS HEADQUARTERS, AUSTIN, TX

Prepared by

U.S. Army Futures Command, Acquisition and Systems (A&S)

210 West 7th Street, Austin, Texas 78701

TABLE OF CONTENTS

1.0 Introduction…………………….………….…………………………..…………….……………………….….…………….……….3

1.1 Background.…………………..……………………………………………….….….…….……….……….……….3

1.2 Scope …………….……………………………………………………………………….....………..….…….……...3

1.3 Performance Objectives.…………………………………………..………………..….….……….….…….…3

2.0 Applicable Documents……………..…………………….…………….…………….………..……..….……….…………….…4

3.0 Program Management Tasks and Deliverables ….…………………………………..………….….….…………..…4

3.1 Kick-off Meeting………..………………………………………………….………...……….…..…………

3.2 Continuous Monitoring and Reporting ……………………………..…………….….………………….4

3.3 Monthly Status Report (MSR)……………………………………………..…………….….………………..5

3.4 Project Management ……....………………...…….….……………………..………….…..……………….9

3.5 Program Management ……....…………………………..……...…….….…………….…..………………..9

3.6 Quarterly Status Report (QSR)……………………..……...…….….…………….……...………………..9

3.7 Summary of Contract Deliverables ……....………………...…….….…………….…..……………….10

4.0 Security Guidance/Requirements…….…………….………………………..……….…..………….…………….………10

5.0 General Information……..……………………………….………………………………….………………..….………………..11

5.1 Place of Performance / Hours of Operations…………….……………………….….……………….11

5.2 Travel Requirements…….…………….…………………………….……………………….….…….………..12

5.3 Section 508 Compliance …….………….………………………….……………………….….……….…….12

1.0 INTRODUCTION

1.1 Background

Risks exist in the business space that challenges Army innovation and competitiveness. The U.S Army Futures Command (AFC) is responsible for twenty percent of the Army’s annual Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) portfolios totaling $300 million, Additionally, AFC executes other contracting efforts in support of the Army Modernization Priorities. Globalization, competition, and connected economies add complexity of understanding non-traditional contractor’s strengths, weakness, dependencies, and undisclosed partnerships. This ultimately adds challenges to the Army’s ability to innovate and provide capability at speed. The competitive business environment and the COVID-19 Pandemic has negatively impacted small businesses, exposing them to increased corporate risk and partnerships that threaten their effectiveness in innovating for the Army. Risk exists at the strategic and operational levels that could degrade innovation and readiness for the Army. AFC’s Acquisition and Systems (A&S) Directorate will manage the command’s Supply Chain and Industrial Risk analysis ability to catalogue non-traditional contractors and maintain situational awareness of overall risk to AFC.

1.2 Scope

The Performance Work Statement (PWS) outlines the Supply Chain and Industrial Risk analysis requirements that the Contractor will provide to AFC leadership located at HQ, AFC in Austin, TX. The service shall encompass methods to evaluate risk and address complex and challenging Supply Chain and Industrial Risk problems of non-traditional contractors awarded to Army Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) in support of AFC efforts. The contractor will use open-source tools and methods to follow current activity and historical trends and forecast risk in various areas such as industrial risk, supply chain risk, technology protection, adversarial capital, cyber security, foreign ownership, and foreign influence. The Contractor will provide findings to A&S leadership for assessment and considerations prior to awarding of contract and post award. The government anticipates awarding a firm-fixed price contract with a base year plus four option years.

1.3 Performance Objectives

• Catalogue all non-traditional contractors that are currently awarded a contract and/or intend to compete for AFC/Army SBIR and (STTR) contracts. A&S anticipates awarding roughly 50-70 contracts annually.

• Conduct analysis on companies or sectors of interest outside of SBIR/STTR companies as directed by A&S leadership.

• Conduct regular supply chain and industrial analysis that identifies contractors that possess risk.

• Identify contracting risk that will inform A&S leadership in making informed decisions regarding the SBIR program.

• Assess, analyze, and define metrics for measuring technical risk (including Financial, Legal and Regulatory, Foreign Influence, Reputational and Operational risk relating to supply chain) manufacturing, industry, material risk, and the workforce that will most impact AFC SBIR/STTR modernization efforts.

• Analyze domestic end products used in SBIR/STTR contracts, determine extent to which contractors buy supplies acquired for use in the United States.

o Develop analysis on the impacts of transport and how this impacts parts, backorders, mission impaired capabilities, and insights not currently realized based on the demand.

o Compare, contrast, and rank all supply indicators against each other and provide a risk analysis rating.

• Safeguard all classified and sensitive information as specified in security requirements section or contract terms.

• Build a risk-focused common operating picture (COP) that captures risk assessments for analyzed companies. Apply clearly defined metrics/findings to assist A&S leadership with final risk mitigation determination on the company seeking a SBIR/STTR award.

2.0 APPLICABLE DOCUMENTS

The contractor shall use this PWS to execute their tasks during the term of this contract.

3.0 PROGRAM MANAGEMENT TASKS AND DELIVERABLES

3.1 Kick-Off Meeting

The Government will schedule and coordinate a Kick-Off Meeting no later than ten (10) days after contract award. The meeting shall be virtually or at the location approved by the Government. The meeting shall provide an introduction between the contractor and Government personnel who shall be involved with the contract. The meeting shall provide the opportunity to discuss technical, management, and security issues. The contractor shall provide a Kick-Off Meeting Agenda and Kick-Off Meeting Presentation that shall include, but not be limited to, the following:

• Introduction of team members

• Overview of project tasks

• POCs (Contractor and Government)

• Communication Plan/Lines of communication overview (both contractor and Government)

• Security requirements/issues

• Sensitivity and protection of information

• Deliverable schedule

Data generated under this task shall be delivered in accordance with the following Contract Data Requirement List (CDRL):

CDRL A001 Kick-Off Meeting Agenda and Presentation

3.2 Continuous Monitoring and Reporting:

The contractor shall conduct continuous monitoring of the companies provided by the government.

The contractor shall provide continuous monitoring via the contractor’s propriety software for the respective supplies and companies that are mapped and analyzed per Section 3.3.1 and 3.3.2. This service will allow the contractor to update the data near-real time, display with the updated data of the supply chain and industrial risks and provide alerts to stakeholders when a significant change happens that would impact the original risk assessment or mapping.

Data generated under this task shall be delivered in accordance with the following CDRL:

CDRL A002 Continuous Monitoring and Reporting

3.3 Monthly Status Report (MSR)

The contractor shall provide a Monthly Status Report. This report shall provide significant activities, accomplishments, program/schedule status, current problems/issues, and funding status.

Data generated under this task shall be delivered in accordance with the following CDRL:

CDRL A003 Monthly Status Report

3.3.1. Eco-System Mappings

The contractor shall provide mapping reports for the respective Supply Chain and Industrial Risk for companies to at least the 3rd tier. The mapping report shall be produced via the contractor’s propriety software and shall show how suppliers are mapped both vertically and horizontally. The contractor shall maintain the mapping reports throughout the period of performance of this effort.

The contractor shall provide the mapping reports NLT 30 Days upon request from the government.

The Eco-System Mapping and reporting will be included as a sub-section under the of the monthly status report.

Data generated under this task shall be delivered in accordance with the following CDRL:

CDRL A004 Eco-System Mapping and Reporting

3.3.2. Supply Chain & Industrial Chain Risk Assessment

The contract shall provide a high-level risk analysis report, comprised of a minimum of the supplier ownership history and manufacturing locations within the last ten (10) years, corporate leadership, suppliers and customers, investors, technical information (including quality assurance, production information, and innovation), security and legal issues including cybersecurity and insider threat risk, market information (competitors, revenue, and financial health. One of the purposes of this high-level risk analysis report is to identify those suppliers that require a more detailed risk assessment.

Data generated under this task shall include the information in sections 3.3.2.1. & 3.3.2.2 below and will be delivered in accordance with the following CDRL:

CDRL A005 Supply Chain & Industrial Chain Risk Assessment

3.3.2.1. Industrial Risk Analysis Support

The contractor shall assign an individual with expertise in Industrial Risk Analysis. This individual shall function as the lead risk analysis analyst for all non-traditional industry related engagements, data, and information. Risk Analysis Analyst functions include:

a. The contractor shall conduct risk assessment reviews of non-traditional contractor’s pre-award or awarded AFC/Army SBIR and STTR contracts.

b. The contractor shall create a risk assessment framework or identify a process to conduct risk assessments identifying early warning factors exposing potential risks to AFC/A&S equities doing business with non-traditional contractors. The contractor will determine the degree of risk and advise A&S leadership of any information concerning subversive activities and propose recommendations to A&S leadership.

c. The contractor shall conduct Due Diligence reviews (of key stakeholders) for risks/threats to the AFC SBIR/STTR program and report possible vulnerabilities to the COR or A&S leadership.

d. The contractor shall evaluate and recommend innovative solutions to conduct risk analysis checks, ensure sound processes and procedures produce results and minimize risk to the AFC SIBR/STTR program.

e. The contractor shall submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the Government’s plan.

f. The contractor shall coordinate with AFC for additional support, or security subject matter expertise in those risk areas not adequately provided.

3.3.2.2. Supply Chain Risk Analysis Support

The contractor shall assign an individual with expertise in Supply Chain Risk Analysis. This individual shall function as the lead risk analysis analyst for all non-traditional industry related engagements, data, and information.

a. The contractor shall conduct reviews and assess current DoD and Army established organizational processes that utilize commercial and organic tools for SCRM that continuously monitor companies, mitigate risk, and executes issue resolution.

b. The contractor shall assess and recommend mitigation strategies of identified issues, monitor the data, and communicate to COR and Leadership when issues are found.

c. The contractor shall provide COR and leadership a comprehensive overview and recommended course of action to implement the forthcoming comprehensive DoD SBIR/ STTR due diligence and SCRM policy/guidance.

d. The contractor shall assess threats to the supply chain and how to make classified/CUI info/threat assessments available to COR and AFC leadership.

e. The contractor shall catalogue & track and optimize the use of data to improve mission and business effectiveness.

f. The contractor shall advise on Data Strategy and Management.

g. The contractor shall advise on how to integrate SBIR/STTR contract Performance Measures and

Reporting into future vendor selection or decision-making efforts.

h. The contractor shall advise on Knowledge Management procedures which could potentially optimize sharing relevant AFC SBIR/STTR program or process data with DoD efforts.

3.3.3. Platform Mapping Tools

For the companies provided to the contractor, the contractor shall rapidly map networks of all vendors relationships, based upon open-source databases of contracts, bills of lading, news reports, public release statements, digital signatures, publicly published software product requirements, public data on software dependencies, annual reports, etc. identify current suppliers and collect data deemed relevant to the government such as capabilities, conduct risk, third-party vendors, ownership, and financial and operational health.

The contract shall use tools to shall collect data on company financials, demographics (employees, locations, leadership), etc. and discover known and unknown potentially problematic relationships within vendor networks.

The solution will be able to classify both public and private companies across multiple jurisdictions according to multiple industry classifications. The solution shall seamlessly integrate data on private sector operations with known federal government contracting performance through automated data pipeline or factory development methodology.

The contractor and solution shall enable Government-wide Information Sharing. Government users must be able to share data and analysis internally with other Government stakeholders to maximize information sharing and awareness of supply chain and industrial risks and vulnerabilities, included in the license.

The contractor shall provide persistent updates and monitoring of supply chain/market/industrial base illuminations as needed; specifically, the ability to monitor unstructured open web content.

The contractor shall leverage technical capability that integrates international open-source data sources and perform entity resolution and risk analysis, translating multiple languages and delivering content in a consumable fashion for supply chain illumination.

The contractor shall be able to provide concise summaries and visualizations of data to enable decision making via dynamic dashboards and reports.

The contractor shall provide access to a web-based data analytics platform for the performance of due diligence analysis, risk identification and reporting, and continuous monitoring.

The contractor shall provide performance-based services to formulate and implement an effective risk analysis index for AFC Leadership.

The government expects that this risk analysis tool will assess, score and monitor the following risks and, as necessary, provide separate discreet scores for the following risks from overall risk ratings:

• Foreign Ownership, Control, or Influence (FOCI): concerns to include foreign operating locations, servers in foreign countries, foreign revenue concentration and foreign personnel.

• Financial Risks: Financial delinquency, outstanding debt, degree of foreign funding, a history of poor financial performance, financial resilience.

• Operational Risks: Labor issues, health and safety problems, certification lapses, physical threats, lawsuits, governance flags, poor supplier relationships, operating in foreign countries, or close operational relationships with foreign suppliers or entities.

• Legal Risks: Matters where the product, vendor or entity is a party to a civil litigation or criminal Matter.

• Cyber Risks: Breaches, leaks, backdoors, hacks, or other cybersecurity events that have created vulnerabilities for entities or their partners in the past or currently; known cybersecurity vulnerabilities of products.

• Third-Party Risk: Identify white label products, embedded open-source software (OSS) and dependency, hardware risks, associate third party component with parent companies and affiliates, tier 2 and tier 3 supply chain risk.

• Environmental, Social, and Governance Risk: Identify Lack of certification or poor performance for complying with regulations or internal risk management mitigation; environmental controversies; Diversity, Equity & Inclusion; safe labor practices, modern slavery; human rights

• Personnel Risk: Identification of personnel risks of key employees that can influence the supply chain security.

• Trade Risk: Material contracts including contracts with foreign influence are identified, exposure to blocked or adversarial entities, export control issues, etc.

Data generated under this task shall be delivered in accordance with the following CDRL:

CDRL A006 Platform Mapping Tools

3.4 Project Management

In performance under this contract, the contractor shall use only fully trained, experienced and technically proficient personnel who understands corporate risk analysis related to non-traditional contractor business elements.

a. Training of contractor personnel shall be performed by the contractor at their expense to include training or replacement or newly hired personnel or for the purpose of keeping the contractor personnel abreast of state-of-the-art practices.

b. The contractor shall provide a single primary point-of-contact who shall be responsible for management of all risk activities.

c. The contractor shall enter into written agreements with all non-traditional companies whose proprietary data the contractor shall have access to, that shall protect such data from unauthorized use or disclosure if it remains proprietary. The contractor shall protect this data and other documents which were disclosed, directly or indirectly, in the performance of this contract with the same caution that a reasonably prudent contractor would use to safeguard highly valuable property. The contractor shall not distribute reports, data or information of any nature arising from its performance under this contract except as high-risk data to AFC/A&S leadership on a need-to-know basis, or as directed by the KO or his representative.

d. The contractor shall protect all data from unauthorized use or disclosure in accordance with the SBIR Data Rights provisions in section 8(b) of the SBIR/STTR Policy Directive.

3.5 Program Management

The contractor shall be responsible for providing the necessary management support for the total accountability of funds expended in support of this contract as follows:

a. All work products developed under this contract shall be reviewed and approved by the COR or designated government representative.

b. All purchases (Other Direct Costs (ODCs) and materials), travel and overtime must be approved, in writing subject to authority delegated in writing by the KO.

c. The contractor shall provide a Monthly Status Report. This report shall provide significant activities, accomplishments, program/schedule status, current problems/issues, and funding status.

3.6 Quarterly Status Report (QSR)

The contractor shall develop a Quarterly Status Report (QSR) using Microsoft (MS) Office Suite applications and be provided via electronic mail (email) to the Contracting Officer’s Representative (COR) and Technical Point of Contact (TPOC). The QSR shall briefly summarize, by task area, the management and technical progress to date under the contract, as well as provide the current information indicated below. The Government will be provided at a minimum the following information:

a. Activities during the 12-month period of performance, by task and subtask to include: On-going activities, new activities, activities completed, deliverables submitted for that period, and progress to date on all the above-mentioned activities. Each section shall begin with a brief description of the task.

b. Schedule of tasks completed and remaining tasks

c. Government actions required (deliverables awaiting Government approval, etc.).

d. The contractor shall provide the QSR NLT 10 days after the end of each quarter.

Data generated under this task shall be delivered in accordance with the following CDRL:

CDRL A007 Quarterly Status Report.

3.7 Summary of Contract Deliverables:

Deliverable PWS Ref. CDRL Delivery Date

Kick-Off Meeting Agenda and Presentation 3.1 A001 No Later than (NLT) 10 days after contract award

Continuous Monitoring Reporting 3.3 A002 Third Business Day of Each Month

Monthly Status Report 3.3 A003 Monthly: NLT 5 days at the end of each month

Eco-System Mappings 3.3.1. A004 NLT 30 Days after request from the government

Supply Chain & Industrial Chain Risk Assessment 3.3.2. A005 Monthly: NLT 5 days at the end of each month

Platform Mapping Tools 3.3.3 A006 Monthly: NLT 5 days at the end of each month

Quarterly Status Report 3.6 A007 NLT 10 days after each quarter

4.0. SECURITY GUIDANCE/REQUIREMENTS

For contracts that require handling or access to classified information. The contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires contractors to comply with— (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M); (2) any revisions to DOD 5220.22-M, notice of which has been furnished to the contractor.

The contractor shall receive, record, track, coordinate, process, and disseminate all request for release of classified information within HQ AFC A&S or DOIS.

The contractor shall ensure all disclosures or releases of classified information are IAW National Disclosure Policy 1 (NDP-1).

The contractor shall ensure all disclosures or releases of classified information occur in a Government-to-Government forum. At no time is the contractor to disseminate classified information to the foreign entity or partner.

The contractor shall maintain awareness and ensure local security programs to include Information Security, Personnel Security, Industrial Security, OPSEC, and Intelligence Facility Physical Security are adequate to protect classified and sensitive but unclassified information in accordance with the HQ AFC protection benchmarks.

Contractor personnel performing on this PWS shall meet and provide requirements to obtain at least a SECRET clearance; and complete the on-line Operation Security Training, an annual requirement at https://securityawareness.usalearning.gov/opsec/index.htm.

Contractor personnel shall have appropriate clearances prior to contract award unless otherwise approved in writing by the Contracting Officer (KO).

The Contractor shall register and request security clearances through the National Industrial Security Program Central Access Information Security System (NCAISS) (https://www.dss.mil/is/ncaiss/).

The work being performed on this effort will be at the UNCLASSIFIED level and will remain

UNCLASSIFIED.

In the event the government deemed that work would need to be conducted at the CLASSIFIED level, the KO will provide the contract with at least 45 days of advance notice.

If the government requires the contractor to perform CLASSIFIED work, the government will exercise the optional clin in support of this classified work.

The Contractor must possess or be able to obtain a facility security clearance at the level of [Secret] at the time of contract award.

All information furnished by the government to conduct the analysis in accordance with this SOW, and all results and reports are not to be shared with any entities or persons, other than Government members of the AFC Team.

5.0 GENERAL INFORMATION

5.1. Place Of Performance / Hours of Operations

The primary place of performance will be at the Contractor’s facility between the core hours of 0900- 1700 hrs., Monday through Friday, excluding federal holidays. In no case shall overtime be authorized to compensate for shortcomings or not meeting the contractor’s performance in this PWS. Overtime, however, will be authorized with prior coordination and approval from the COR.

https://securityawareness.usalearning.gov/opsec/index.htm https://www.dss.mil/is/ncaiss/

The contractor is not required to perform services on holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings.

Federal Holidays are:

• New Year’s Day

• Dr. Martin Luther King’s Birthday

• Presidents Day

• Memorial Day

• Juneteenth

• Independence Day

• Labor Day

• Columbus Day

• Veteran’s Day

• Thanksgiving Day

• Christmas Day

5.2. Travel Requirements

To perform tasks under this PWS, the contractor may be required to travel to work sites, sometimes upon short notice, away from the primary sites at contractor’s location. The COR or government representative must authorize travel in advance. Travel will be in accordance with the Federal Travel Regulation.

5.3. Section 508 Compliance

All Electronic and Information Technology (EIT) products and services proposed shall fully comply with Section 508 of the Rehabilitation Act of 1973, per the 1998 Amendments, 29 United States Code (U.S.C.) 794d, and 36 Code of Federal Regulations (CFR) 1194. The contractor shall identify all EIT products and services proposed, identify the technical standards applicable to all products and services proposed, and state the degree of compliance with the applicable standards. Additionally, the contractor must clearly indicate where the information pertaining to Section 508 compliance can be found (e.g., vendor’s website or other exact web page location). The contractor shall ensure that the list is easily accessible by typical users beginning at Time of Award (TOA) and shall inform the COR and TPOC of the information location.

File details come from the government source that posted it. Updated .