{
  "schemaVersion": "2.0",
  "schemaName": "govscope.requirements_matrix.customer_v2",
  "caseKey": "opp-b13eeb1c32b14563bee9f39cadf3a7fb",
  "samUrl": "https://sam.gov/opp/b13eeb1c32b14563bee9f39cadf3a7fb",
  "opportunityTitle": "USAC RFP: Penetration Testing as a Service",
  "summary": "This solicitation includes 34 required obligations and 5 attachment-derived requirements.",
  "resolvedDeadlines": null,
  "performancePeriodSchedule": {},
  "performancePeriodExplicitFields": {},
  "verificationChecklist": [],
  "qualityAssessment": {},
  "rows": [
    {
      "rowId": "REQ-SEC-001",
      "matrixSection": "Security / Privacy",
      "requirement": "Contractor must comply with Data Security Laws (FISMA, NIST SP 800-53 Rev 5). Any Cloud Service Offering used must be FedRAMP Authorized at a moderate risk level.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Technical Approach / Security Compliance",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SEC-001",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "PRIVACY AND SECURITY ADDENDUM, 2. SECURITY PROVISIONS",
        "sourcePage": "40",
        "sourceExcerpt": "2.1. Data Security Laws Compliance. Contractor shall comply with the Data Security Laws. For any Contractor IT using a Cloud Service Offering that accesses, stores, or otherwise processes USAC Data, and/or PII, Contractor shall provide documentation and proof of FedRAMP Authorization for use at a moderate risk before any such cloud-based Service may be used.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SEC-002",
      "matrixSection": "Security / Privacy",
      "requirement": "Contractor must notify USAC at incident@USAC.org and Privacy@USAC.org within one (1) hour of becoming aware of an actual or suspected Cybersecurity Incident or Privacy Incident.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": null,
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SEC-002",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "PRIVACY AND SECURITY ADDENDUM, 2.14. Cybersecurity Incidents and Privacy Incidents",
        "sourcePage": "43",
        "sourceExcerpt": "Any Event identified as a Cybersecurity Incident or Privacy Incident requires that USAC be notified at incident@USAC.org and Privacy@USAC.org within one (1) hour of becoming aware of an actual or suspected Cybersecurity Incident or Privacy Incident.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SEC-003",
      "matrixSection": "Security / Privacy",
      "requirement": "Vendor must submit its insider threat program to USAC's Chief Privacy Officer and Chief Information Security Officer within 90 days of the Effective Date of the Contract.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": null,
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SEC-003",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "PRIVACY AND SECURITY ADDENDUM, 2. SECURITY PROVISIONS",
        "sourcePage": "41",
        "sourceExcerpt": "Vendor must submit its insider threat program to USAC's Chief Privacy Officer and Chief Information Security Officer within 90 days of the Effective Date of the Contract.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SEC-004",
      "matrixSection": "Security / Privacy",
      "requirement": "Contractor shall not use, implement, build, or deploy AI tools, services, or code of any type without prior written approval from USAC. Approved AI must include human oversight and cannot be used for autonomous decisions in sensitive areas.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": null,
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SEC-004",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "PRIVACY AND SECURITY ADDENDUM, 3. TECHNOLOGY CONSIDERATIONS",
        "sourcePage": "47",
        "sourceExcerpt": "Contractor shall not use, implement, build, or deploy AI tools, services, or code of any type without prior written approval from USAC. Approved AI must include human oversight and cannot be used for autonomous decisions in sensitive areas.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SEC-005",
      "matrixSection": "Security / Privacy",
      "requirement": "Contractor must maintain ISO 27001 compliance certification and SOC 2 Type II reports for all Contractor IT used in performance of the Services, and provide them to USAC within 10 calendar days of the Effective Date.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": null,
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SEC-005",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "PRIVACY AND SECURITY ADDENDUM, 2.20. Additional Requirements for Services in Contractor IT",
        "sourcePage": "45",
        "sourceExcerpt": "Contractor shall maintain ISO 27001 compliance certification and notify USAC of any changes to its compliance. Contractor shall provide USAC with its ISO 27001 compliance certification within ten (10) calendar days of the Effective Date. • Contractor shall maintain administrative, technical, physical, and procedural information security controls as demonstrated in Service Organization Controls (“SOC”) 2 Type II reports",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-REPORTING-2",
      "matrixSection": "Security / Privacy",
      "requirement": "Email draft details and reproduction steps for critical or high findings to the USAC product manager within one (1) business day.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Critical/high finding alert",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-REPORTING-2",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "1.  One time (within five",
        "sourcePage": "10",
        "sourceExcerpt": "Finding and cover each Significant Alert of Finding reported during the test. 5. Email Alert within one (1) business day of Critical or High finding to USAC project manager.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-REPORTING-5",
      "matrixSection": "Security / Privacy",
      "requirement": "For contracts involving new IT systems or tools, provide a monthly vulnerability report and a risk mitigation plan addressing identified vulnerabilities.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Monthly vulnerability report and risk mitigation plan",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-REPORTING-5",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "18. Notification and Assistance .  Contractor will cooperate with USAC in any litigation and",
        "sourcePage": "45",
        "sourceExcerpt": "Vulnerabilities in the applicable timeframes set forth in such policies. Contractor shall provide a monthly vulnerability report and a risk mitigation plan to address any identified vulnerabilities.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-SECURITY",
      "matrixSection": "Security / Privacy",
      "requirement": "For contracts involving new IT systems or tools, provide a POA&M to address vulnerabilities promptly and prioritize remediation based on severity and risk.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "POA&M",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-SECURITY",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "18. Notification and Assistance .  Contractor will cooperate with USAC in any litigation and",
        "sourcePage": "45",
        "sourceExcerpt": "Officer, and Contractor shall remedy such vulnerabilities as soon as possible. Contractor shall provide USAC a POA&M to address such vulnerabilities promptly and shall prioritize remediation based on the risks implicated by such vulnerabilities. 2.20.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-SECURITY-2",
      "matrixSection": "Security / Privacy",
      "requirement": "For contracts involving new IT systems or tools, report critical and high vulnerabilities promptly to USAC’s Chief Information Officer and Chief Information Security Officer and begin remediation immediately.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Critical/high vulnerability notification workflow",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-SECURITY-2",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "18. Notification and Assistance .  Contractor will cooperate with USAC in any litigation and",
        "sourcePage": "45",
        "sourceExcerpt": "For contracts involving new IT systems or tools, report critical and high vulnerabilities promptly to USAC’s Chief Information Officer and Chief Information Security Officer and begin remediation immediately.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-SECURITY-3",
      "matrixSection": "Security / Privacy",
      "requirement": "For contracts involving new IT systems or tools, respond to USAC information-security questionnaires and related security documentation requests within ten (10) business days or in the timeframe requested by USAC.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Security questionnaires / certifications / training",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-SECURITY-3",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "2. SECURITY PROVISIONS",
        "sourcePage": "40",
        "sourceExcerpt": "Necessary for the parties to perform their obligations under the Data Security Laws; (iii) complete any security questionnaires, IT rules of behavior, certifications, assessments, or workforce training reasonably requested by USAC in a timely manner; and (iv) receive prior written authorization from USAC to access USAC IT Systems from",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-SECURITY-4",
      "matrixSection": "Security / Privacy",
      "requirement": "For contracts involving new IT systems or tools, ensure cloud or COTS offerings can use USAC’s OKTA instance for user authentication and provisioning.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "OKTA-compatible cloud deployment",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-SECURITY-4",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "3. TECHNOLOGY CONSIDERATIONS",
        "sourcePage": "46",
        "sourceExcerpt": "The following requirements: 3.1.1. The Software must be able to utilize USAC’s instance of OKTA’s identity and access management software for user authentication and provisioning. OKTA is a FedRAMP Authorized CSP identity and access management product used by USAC. 3.1.2.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-001",
      "matrixSection": "Submission",
      "requirement": "Proposals must be submitted via email to Procurement@usac.org with a copy to Mustafa.Kamal@usac.org no later than Monday, March 30, 2026, 11:00 AM ET. The subject line must only be 'RFP IT-26-027'.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Email Submission",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-001",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 1. GENERAL, B. PERIOD FOR ACCEPTANCE OF OFFERS",
        "sourcePage": "51",
        "sourceExcerpt": "Be submitted to USAC Procurement Department, no later than Monday, March 30, 2026, 11:00 AM ET (“Proposal Due Date”). • Be submitted in the form of one electronic copy submitted to Procurement@usac.org with copy to Mustafa.Kamal@usac.org. The subject line for all email communication related to this solicitation must only be RFP IT-26-027.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-002",
      "matrixSection": "Submission",
      "requirement": "Proposals must be presented in four separate volumes (Corporate Information, Technical Capability, Past Performance, Price). Each volume must be submitted in PDF format as a separate attachment to a single email. Times New Roman 12-point font is required (minimum 9-point for diagrams/tables).",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Four PDF Volumes",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-002",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 4. PROPOSAL FORMAT & E. Presentation and Page Limitations",
        "sourcePage": "52",
        "sourceExcerpt": "Proposals shall be presented in four separate volumes: 1. Volume 1 – Corporate Information 2. Volume 2 – Technical Capability 3. Volume 3 – Past Performance 4. Volume 4 – Price Each volume of the proposal should be submitted in PDF format as a separate attachment to a single email Proposals must be prepared using Times New Roman font.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-003",
      "matrixSection": "Submission",
      "requirement": "Each volume must contain a cover page including: Org name, contact name, contact info, Unique Entity ID, date of submittal, a statement verifying the proposal is valid for 120 days, and the signature of a duly authorized representative.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Cover Pages",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-003",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 5. PROPOSAL COVER PAGE",
        "sourcePage": "53",
        "sourceExcerpt": "Each volume must contain a cover page including: Org name, contact name, contact info, Unique Entity ID, date of submittal, a statement verifying the proposal is valid for 120 days, and the signature of a duly authorized representative.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-004",
      "matrixSection": "Submission",
      "requirement": "Volume 1 must not exceed 4 pages and must include the Cover Page, Executive Summary (no pricing info), Confidentiality and Information Security statement, and Conflict of Interest statement.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Volume 1",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-004",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 6. PROPOSAL CONTENT & E. Presentation and Page Limitations",
        "sourcePage": "53",
        "sourceExcerpt": "Volume 1 must not exceed 4 pages and must include the Cover Page, Executive Summary (no pricing info), Confidentiality and Information Security statement, and Conflict of Interest statement.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-005",
      "matrixSection": "Submission",
      "requirement": "Volume 2 must not exceed 12 pages (excluding Attachment A - Resumes). It must include the Cover Page, Technical Approach, Capabilities, and Key Personnel details.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Volume 2",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-005",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 6. PROPOSAL CONTENT & E. Presentation and Page Limitations",
        "sourcePage": "54",
        "sourceExcerpt": "Volume 2 must not exceed 12 pages (excluding Attachment A - Resumes). It must include the Cover Page, Technical Approach, Capabilities, and Key Personnel details.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-006",
      "matrixSection": "Submission",
      "requirement": "Volume 3 must not exceed 5 pages. It must include a Cover Page, description of recent experience, and a list of 2 to 3 current or recently completed contracts (no older than 3 years) for similar services. Each project overview shall not exceed 1 page.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Volume 3",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-006",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 6. PROPOSAL CONTENT & E. Presentation and Page Limitations",
        "sourcePage": "55",
        "sourceExcerpt": "Volume 3 must not exceed 5 pages. It must include a Cover Page, description of recent experience, and a list of 2 to 3 current or recently completed contracts (no older than 3 years) for similar services. Each project overview shall not exceed 1 page.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-007",
      "matrixSection": "Submission",
      "requirement": "Volume 4 must not exceed 4 pages. It must include a Cover Page and completed pricing information in Attachment 1 – Bid Sheet. The proposed price must be fully loaded.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Volume 4",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-007",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 6. PROPOSAL CONTENT & E. Presentation and Page Limitations",
        "sourcePage": "56",
        "sourceExcerpt": "Volume 4 must not exceed 4 pages. It must include a Cover Page and completed pricing information in Attachment 1 – Bid Sheet. The proposed price must be fully loaded.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-008",
      "matrixSection": "Submission",
      "requirement": "The Offeror's submission must include a statement certifying that the USAC Standard Terms and Conditions set forth in the RFP have been reviewed by the Offeror's office of general counsel (or equivalent legal representative).",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Certification Statement",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-008",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 1. GENERAL, A. CONTRACT TERMS AND CONDITIONS",
        "sourcePage": "51",
        "sourceExcerpt": "Offeror’s submission must include a statement certifying that the USAC Standard Terms and Conditions set forth in this RFP have been reviewed by Offeror’s office of general counsel (or equivalent legal representative).",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-009",
      "matrixSection": "Submission",
      "requirement": "Any deviations from, or exceptions to, the requirements in the RFP must be clearly identified in a separate Attachment to the proposal titled 'Exceptions to RFP Terms'.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Exceptions to RFP Terms Attachment",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-009",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 1. GENERAL, A. CONTRACT TERMS AND CONDITIONS",
        "sourcePage": "51",
        "sourceExcerpt": "Offeror’s proposal may identify deviations from, or revisions, exceptions or additional terms (collectively “exceptions”) to the RFP, but only if such exceptions are clearly identified in a separate Attachment to the proposal, “Exceptions to RFP Terms.”",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-SUB-010",
      "matrixSection": "Submission",
      "requirement": "The RFP is subject to the terms of the Confidentiality Agreement (Attachment 2) which must be executed by the Offeror and submitted along with any proposal. It may be submitted in PDF format as a separate attachment and does not count towards page limits.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Executed Confidentiality Agreement",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-SUB-010",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION A: About Us, 3. CONFIDENTIALITY",
        "sourcePage": "4",
        "sourceExcerpt": "The RFP is subject to the terms of the Confidentiality Agreement (Attachment 2) which must be executed by the Offeror and submitted along with any proposal. It may be submitted in PDF format as a separate attachment and does not count towards page limits.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-DEL-001",
      "matrixSection": "Deliverables",
      "requirement": "Contractor must perform penetration testing on 16 to 20 USAC mission systems at least annually in pre-production environments. Testing includes Ethical Hacking, Web Application, and Application Code testing.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Technical Approach",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-DEL-001",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION B: STATEMENT OF WORK, 5. SCOPE OF WORK AND DELIVERABLES",
        "sourcePage": "7",
        "sourceExcerpt": "Contractor must perform penetration testing on 16 to 20 USAC mission systems at least annually in pre-production environments. Testing includes Ethical Hacking, Web Application, and Application Code testing.",
        "citationQuality": "Section-level citation"
      }
    },
    {
      "rowId": "REQ-DEL-002",
      "matrixSection": "Deliverables",
      "requirement": "Contractor shall offer optional services to conduct three corporate-level social engineering campaigns annually, including Phishing, Vishing, Smishing, and AI emulation.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Technical Approach",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-DEL-002",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION B: STATEMENT OF WORK, 5. SCOPE OF WORK AND DELIVERABLES",
        "sourcePage": "9",
        "sourceExcerpt": "Contractor shall offer optional services to conduct three corporate-level social engineering campaigns annually, including Phishing, Vishing, Smishing, and AI emulation.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-DEL-003",
      "matrixSection": "Deliverables",
      "requirement": "Contractor shall offer optional physical testing for Wi-Fi networks and physical access at USAC's HQ location annually.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Technical Approach",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-DEL-003",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION B: STATEMENT OF WORK, 5. SCOPE OF WORK AND DELIVERABLES",
        "sourcePage": "9",
        "sourceExcerpt": "C. Physical Environment Testing (Optional) i. Wi-Fi testing of USAC’s Corporate (secure) and Guest (insecure) Wi-Fi networks at USAC’s HQ ii.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-DEL-004",
      "matrixSection": "Deliverables",
      "requirement": "Contractor must provide specific deliverables according to the schedule in Section B.5.C, including Kickoff Meeting, Onboarding Plan, Core System Pen Test Plans/Reports, Significant Alerts of Findings, Weekly/Monthly Status Reports, and a Transition Out Plan.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": null,
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-DEL-004",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION B: STATEMENT OF WORK, 5. SCOPE OF WORK AND DELIVERABLES, C. Deliverables",
        "sourcePage": "9",
        "sourceExcerpt": "Contractor must provide specific deliverables according to the schedule in Section B.5.C, including Kickoff Meeting, Onboarding Plan, Core System Pen Test Plans/Reports, Significant Alerts of Findings, Weekly/Monthly Status Reports, and a Transition Out Plan.",
        "citationQuality": "Section-level citation"
      }
    },
    {
      "rowId": "AUTO-DELIVERABLE",
      "matrixSection": "Deliverables",
      "requirement": "Hold the contract kickoff meeting within five (5) business days of contract award.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Kickoff meeting and technical planning",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-DELIVERABLE",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "1.  One time (within five",
        "sourcePage": "10",
        "sourceExcerpt": "IT-26-027 | Request for Proposals (RFP) Page 10 of 11 Available for Public Use 1. One time (within five (5) business days of Contract award) Kickoff Meeting Official kick-off of Contract to introduce teams, Contractor approach, and coordinate technical planning for test execution. 2.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-DELIVERABLE-2",
      "matrixSection": "Deliverables",
      "requirement": "For each system tested, submit a draft penetration test plan ten (10) business days before test kickoff and a final plan five (5) business days before test kickoff.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Draft and final penetration test plan for each system",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-DELIVERABLE-2",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "1.  One time (within five",
        "sourcePage": "10",
        "sourceExcerpt": "Contractor personnel, test accounts, tools, and coordination of support by USAC teams. 3. One draft Plan (ten (10) business days before test kickoff) and one final Plan (five (5) business days before test kickoff) for each system tested for up to twenty (20) systems.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-REPORTING",
      "matrixSection": "Deliverables",
      "requirement": "For each system tested, provide a draft report at the conclusion of the test and a final report within ten (10) business days after the test concludes.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Draft and final penetration test report for each system",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-REPORTING",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "1.  One time (within five",
        "sourcePage": "10",
        "sourceExcerpt": "Responsible for coordination for access and readiness to commence testing on schedule. 4. One draft Report at conclusion of each test and one final Report (ten (10) business days after conclusion of test) ) for each system tested for up to twenty (20) systems.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-REPORTING-3",
      "matrixSection": "Deliverables",
      "requirement": "If optional social engineering tests are performed, publish the annual social engineering assessment report with outcomes, key risks, and next-year recommendations.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Social engineering assessment report",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-REPORTING-3",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Deliverables",
        "sourcePage": "9",
        "sourceExcerpt": "Urrent fraud scenarios and security threats known or prescient. iv. Contractor will publish a Social Engineering Assessment Report annually after all tests are completed with recommendations for Social Engineering testing in the coming year along with outcomes and key risks identified by the tests. c.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-REPORTING-4",
      "matrixSection": "Deliverables",
      "requirement": "If optional physical environment testing is performed, publish a report with findings and recommendations for improvement.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Physical environment penetration test report",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-REPORTING-4",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "9.  Once annually, fifteen",
        "sourcePage": "11",
        "sourceExcerpt": "Testing for USAC’s HQ location. 10. Once annually, fifteen (15) days after the test (OPTIONAL) Physical Environment Penetration Test Report Contractor will publish outcome of the Physical Environment Penetration Test in a report with recommendations for improvement. 11.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-PRC-001",
      "matrixSection": "Pricing",
      "requirement": "Pricing must be submitted using Attachment 1 - Bid Sheet. The proposed price must be a fully loaded firm fixed price including wages, overhead, G&A, taxes, and profit. Travel expenses are not reimbursable.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Attachment 1 - Bid Sheet",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-PRC-001",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION E: INSTRUCTIONS AND EVALUATION CRITERIA, 6. PROPOSAL CONTENT, D. Price Proposal (Volume 4)",
        "sourcePage": "56",
        "sourceExcerpt": "Pricing must be submitted using Attachment 1 - Bid Sheet. The proposed price must be a fully loaded firm fixed price including wages, overhead, G&A, taxes, and profit. Travel expenses are not reimbursable.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-PRICING",
      "matrixSection": "Pricing",
      "requirement": "Price the bid sheet by daily rate for the base year and all four option years.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Attachment 1 – Bid Sheet",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3259",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3259?requirement=AUTO-PRICING",
        "sourceDocumentName": "RFP-IT-26-027-Attachment-1-Bid-Sheet.xlsx",
        "sourceSection": "Attachment 1 - Bid Sheet | | | | | | | |",
        "sourcePage": null,
        "sourceExcerpt": "Price the bid sheet by daily rate for the base year and all four option years.",
        "citationQuality": "Section-level citation"
      }
    },
    {
      "rowId": "AUTO-PRICING-2",
      "matrixSection": "Pricing",
      "requirement": "Provide pricing for small, medium, and large system-test sizes in Attachment 1 – Bid Sheet.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Attachment 1 – Bid Sheet",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3259",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3259?requirement=AUTO-PRICING-2",
        "sourceDocumentName": "RFP-IT-26-027-Attachment-1-Bid-Sheet.xlsx",
        "sourceSection": "Attachment 1 - Bid Sheet | | | | | | | |",
        "sourcePage": null,
        "sourceExcerpt": "| | | | | Base Year | Option Year 1 | Option Year 2 | Option Year 3 | Option Year 4 | 1 | Small (Low) | 5 | | | | | | 2 | Medium (Moderate) | 7 | | | | | | 3 | Large (High) | 4 | | | | | | Core System Tests Sub-Total | | | | | | | | Social Engineering Testing (Optional) | | | | | | | | Physical Environment Testing (Optional) | | | | | |",
        "citationQuality": "Section-level citation"
      }
    },
    {
      "rowId": "AUTO-PRICING-3",
      "matrixSection": "Pricing",
      "requirement": "Include optional pricing line items for social engineering testing and physical environment testing in Attachment 1 – Bid Sheet.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Optional pricing line items",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3259",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3259?requirement=AUTO-PRICING-3",
        "sourceDocumentName": "RFP-IT-26-027-Attachment-1-Bid-Sheet.xlsx",
        "sourceSection": "Attachment 1 - Bid Sheet | | | | | | | |",
        "sourcePage": null,
        "sourceExcerpt": "7 | | | | | | 3 | Large (High) | 4 | | | | | | Core System Tests Sub-Total | | | | | | | | Social Engineering Testing (Optional) | | | | | | | | Physical Environment Testing (Optional) | | | | | | | | Optional Tests Sub-Total | | | | | | | | Grand Total | | | | | | | | Other (describe) | | | | | | | | Total NTE Price | | | | | | | |",
        "citationQuality": "Section-level citation"
      }
    },
    {
      "rowId": "AUTO-PRICING-4",
      "matrixSection": "Pricing",
      "requirement": "Complete Attachment 1 – Bid Sheet with company name, authorized representative, signature, title, and date.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Signed Attachment 1 – Bid Sheet",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3259",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3259?requirement=AUTO-PRICING-4",
        "sourceDocumentName": "RFP-IT-26-027-Attachment-1-Bid-Sheet.xlsx",
        "sourceSection": "Attachment 1 - Bid Sheet | | | | | | | |",
        "sourcePage": null,
        "sourceExcerpt": "| | | | | Company Name: ________________________________________________ | | | | | | | | Authorized Representative: _______________________________________ | | | | | | | | Signature:______________________________________________________ | | | | | | | | Print Name:____________________________________________________ | | | | | | | |",
        "citationQuality": "Section-level citation"
      }
    },
    {
      "rowId": "AUTO-PRICING-5",
      "matrixSection": "Pricing",
      "requirement": "USAC encourages offerors to propose alternative pricing they normally provide for Penetration Testing as a Service.",
      "obligation": "CONDITIONAL",
      "obligationLabel": "If Applicable",
      "criticality": "low",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Alternative PTaaS pricing",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-PRICING-5",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "1. A cover page, as outlined above.",
        "sourcePage": "56",
        "sourceExcerpt": "In Attachment 1 – Bid Sheet. As noted on the bid sheet, USAC requests offerors to propose alternative pricing that they normally provide relative to their approach for providing Penetration Testing as a Service.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-EVALUATION",
      "matrixSection": "Evaluation",
      "requirement": "USAC will evaluate offers based on Technical, Past Performance, and Price factors.",
      "obligation": "INFORMATIONAL",
      "obligationLabel": "Reference",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Proposal response aligned to stated evaluation factors",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-EVALUATION",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "3. Price Evaluation:",
        "sourcePage": "58",
        "sourceExcerpt": "Proposals (RFP) Page 58 of 59 Available for Public Use Experience and past performance information will be evaluated to assess the risks associated with Offeror’s performance of this effort, considering the relevance, how recent the project is (no older than three (3) years from the date of the solicitation), and quality of Offeror’s",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-EVALUATION-2",
      "matrixSection": "Evaluation",
      "requirement": "USAC will evaluate whether proposed pricing is realistic and reasonable, and unrealistic or unreasonable pricing will not be considered for award.",
      "obligation": "INFORMATIONAL",
      "obligationLabel": "Reference",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Realistic and reasonable pricing",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-EVALUATION-2",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "3. Price Evaluation:",
        "sourcePage": "58",
        "sourceExcerpt": "Total prices of Offerors when making the award, USAC will also evaluate whether the proposed prices are realistic (i.e., reasonably sufficient to perform the requirements) and reasonable. Proposals containing prices that are determined to be unrealistic or unreasonable will not be considered for award. 8.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-EVALUATION-3",
      "matrixSection": "Evaluation",
      "requirement": "USAC intends to make award on a best-value basis considering Technical, Past Performance, and Price.",
      "obligation": "INFORMATIONAL",
      "obligationLabel": "Reference",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Proposal aligned to best-value evaluation basis",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-EVALUATION-3",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "2. Page Limitation",
        "sourcePage": "57",
        "sourceExcerpt": "Solicitation to the responsible Offeror whose offer conforming to the solicitation will be most advantageous to USAC, price and other factors considered. The following factors shall be used to evaluate offers and select the awardee – Technical, Past Performance, and Price. 7.1.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-EVALUATION-4",
      "matrixSection": "Evaluation",
      "requirement": "Address the Technical subfactors of Technical Approach, Capabilities, and Key Personnel in the technical proposal.",
      "obligation": "INFORMATIONAL",
      "obligationLabel": "Reference",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Technical volume aligned to subfactors",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-EVALUATION-4",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "2. Page Limitation",
        "sourcePage": "57",
        "sourceExcerpt": "1. Technical: The technical sub-factors listed below in descending order of importance: a. Technical Approach b. Capabilities c. Key Personnel 7.2. Experience and Past Performance: [[PAGE 58]] Universal Service Administrative Co.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-EVALUATION-5",
      "matrixSection": "Evaluation",
      "requirement": "Do not exceed the volume page limits; proposals exceeding the page count may be considered technically unacceptable and may receive no further consideration.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Compliant page-limited proposal",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-EVALUATION-5",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "2. Page Limitation",
        "sourcePage": "57",
        "sourceExcerpt": "Five (5) pages. d. Volume 4 – Price; may not exceed four (4) pages. Any proposals received exceeding the page count will be considered technically unacceptable and may not receive further consideration. 7.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-STAFF-001",
      "matrixSection": "Key Personnel / Staffing",
      "requirement": "The Contractor's team must be staffed with a Contract Engagement Manager. The Offeror shall propose additional Key Personnel such as engineers, consultants, and/or IT lead. Resumes for all Key Personnel must be submitted as Attachment A, no longer than 2 pages per resume.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Resumes (Attachment A)",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-STAFF-001",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION B: STATEMENT OF WORK, 6. KEY PERSONNEL & SECTION E: 6. PROPOSAL CONTENT",
        "sourcePage": "12",
        "sourceExcerpt": "The Contractor's team must be staffed with a Contract Engagement Manager. The Offeror shall propose additional Key Personnel such as engineers, consultants, and/or IT lead. Resumes for all Key Personnel must be submitted as Attachment A, no longer than 2 pages per resume.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "REQ-STAFF-002",
      "matrixSection": "Key Personnel / Staffing",
      "requirement": "Contractor Staff are required to be in the USAC office at least 2 days per week. Contractors required to report in person must reserve workspaces in advance using USAC's hoteling system.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": null,
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=REQ-STAFF-002",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "SECTION B: STATEMENT OF WORK, 4. PLACE OF PERFORMANCE",
        "sourcePage": "5",
        "sourceExcerpt": "Presently, USAC has a hybrid work approach requiring Contractor Staff (as defined in Section C.1.G) to be in the USAC office at least 2 days per week. Contractors that are required to report in person must reserve their workspaces in designated areas in advance using USAC’s hoteling system.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-STAFFING",
      "matrixSection": "Key Personnel / Staffing",
      "requirement": "Conduct background checks on contractor staff and provide evidence of those checks to USAC upon request.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Background-check evidence",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-STAFFING",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Key Personnel / Staffing",
        "sourcePage": "25",
        "sourceExcerpt": "Negligent, or that constitute a breach of the Visitor Form and/or the Contract. Contractor shall conduct background checks on Contractor Staff and provide evidence of the background checks to USAC upon request. 20. KEY PERSONNEL USAC may specify which Contractor employees are Key Personnel under the Contract.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-KEY_PERSONNEL",
      "matrixSection": "Key Personnel / Staffing",
      "requirement": "Keep key personnel in their assigned roles for the contract term and obtain USAC’s prior written approval before changing, removing, or reducing their time commitment.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Key personnel continuity / substitution plan",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-KEY_PERSONNEL",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Key Personnel / Staffing",
        "sourcePage": "25",
        "sourceExcerpt": "Or a part of the Contract if Contractor changes the position, role, or time commitment of Key Personnel, or removes Key Personnel from the Contract, without USAC’s prior written approval.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-DELIVERABLE-3",
      "matrixSection": "Contractual / Admin",
      "requirement": "Submit the transition-out plan no later than sixty (60) days before the end of the contract period of performance, including knowledge transfer and offboarding steps.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Transition-out plan",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-DELIVERABLE-3",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Contractual / Admin",
        "sourcePage": "11",
        "sourceExcerpt": "Submit the transition-out plan no later than sixty (60) days before the end of the contract period of performance, including knowledge transfer and offboarding steps.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-CONTRACTUAL",
      "matrixSection": "Contractual / Admin",
      "requirement": "Contractor staff attending USAC headquarters must complete the USAC Visitor Form and wear a badge while on premises.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "USAC Visitor Form",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-CONTRACTUAL",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Contractual / Admin",
        "sourcePage": "6",
        "sourceExcerpt": "Headquarters for meetings or to conduct audits, Contractor Staff will be considered as visitors. All visitors are required to complete USAC's Visitor Form, and wear a badge while on premises. The Kick-Off Meeting and all in -person meetings will be held at USAC Headquarters or other reasonable locations designated by USAC.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-CONTRACTUAL-2",
      "matrixSection": "Contractual / Admin",
      "requirement": "Avoid material exceptions to the RFP; material or unacceptable exceptions may render the proposal technically unacceptable or ineligible for award.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Exceptions attachment or compliant terms",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-CONTRACTUAL-2",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Contractual / Admin",
        "sourcePage": "51",
        "sourceExcerpt": "In a separate Attachment to the proposal, “Exceptions to RFP Terms.” Proposals that include material exceptions to the RFP may be considered unacceptable and render Offeror ineligible for award unless the Offeror withdraws or modifies any unacceptable exceptions prior to USAC’s selection of the successful Offeror for award.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-ELIGIBILITY",
      "matrixSection": "Contractual / Admin",
      "requirement": "Maintain an active SAM.gov registration and not be excluded from government contracting for responsibility determination.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "medium",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Active SAM.gov registration",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-ELIGIBILITY",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Contractual / Admin",
        "sourcePage": "58",
        "sourceExcerpt": "Contracting, as listed on the excluded parties list in https://www.sam.gov, and 6. Offeror has an active registration in https://www.sam.gov. [[PAGE 59]] Universal Service Administrative Co.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-QUESTION_DEADLINE",
      "matrixSection": "Schedule",
      "requirement": "Submit questions by Monday, March 9, 2026, by 11:00 AM ET.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": null,
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-QUESTION_DEADLINE",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Schedule",
        "sourcePage": "1",
        "sourceExcerpt": "Proposal (“RF P”) Solicitation Number: IT-26-027 Solicitation Issue Date: Tuesday, March 3, 2026 Question Due Date: Monday, March 9, 2026, by 11:00 AM ET Q&A Response Due Date: Friday, March 13, 2026 Proposal Due Date: Monday, March 30, 2026, by 11:00 AM ET CONTRACT TO BE ISSUED BY: Universal Service Administrative Co.",
        "citationQuality": "Exact page citation"
      }
    },
    {
      "rowId": "AUTO-DUE_DATE",
      "matrixSection": "Schedule",
      "requirement": "Submit the proposal by March 30, 2026.",
      "obligation": "MANDATORY",
      "obligationLabel": "Required",
      "criticality": "high",
      "lifecycle": null,
      "applicability": {},
      "evidenceArtifacts": [],
      "whatToPrepare": "Complete proposal submission",
      "sourceBasis": null,
      "rowConfidence": {},
      "validationFlags": [],
      "evidenceLinks": [],
      "evidence": {
        "sourceDocumentId": "doc_3258",
        "sourceDocumentHref": "https://capture.govscope.io/cases/opp-b13eeb1c32b14563bee9f39cadf3a7fb/sources/doc_3258?requirement=AUTO-DUE_DATE",
        "sourceDocumentName": "RFP-IT-26-027-Penetration-Testing-as-a-Service.pdf",
        "sourceSection": "Schedule",
        "sourcePage": "1",
        "sourceExcerpt": "Date: Monday, March 9, 2026, by 11:00 AM ET Q&A Response Due Date: Friday, March 13, 2026 Proposal Due Date: Monday, March 30, 2026, by 11:00 AM ET CONTRACT TO BE ISSUED BY: Universal Service Administrative Co.",
        "citationQuality": "Exact page citation"
      }
    }
  ]
}