Health, Education & Government Government & Public Sector Defense Systems & Programs

Command, Control & Intelligence Systems

Multi-agency, multi-stakeholder programs where procurement, compliance, and mission alignment determine success.

Example organizations in this space: Lockheed Martin Northrop Grumman L3Harris CACI International

This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.

Inside this journey
  1. Pre-Sales

    Qualify and diagnose before investing in formal evaluation and fieldwork.

    1. Acquisition Fit Validation

      Confirm budget profile, decision authority, schedule constraints, and high-level security requirements before full discovery.

      Qualification Questions

      Budget and funding profile

      • So we make the best use of your time: is there an allocated budget range for procurement or integration of this capability? Options: Under $1M, $1M–$5M, $5M–$20M, $20M–$100M, Over $100M, No allocated budget yet, Prefer not to disclose
      • Is the funding single-year, multi-year/incremental, or still TBD? If there are fiscal constraints (e.g., FY deadlines), briefly note them.

      Decision authority and key stakeholders

      • Who is the final decision authority for awarding work like this (role or office, not a person)? Options: Program executive or program manager, Acquisition/Contracting Officer, Milestone/Authorization decision authority, Source selection board or committee, Multiple authorities / not yet determined, Other
      • Who are the other technical or sponsor stakeholders we should include in a discovery conversation (roles only)?

      Schedule and driving milestones

      • What is the target timeline for an initial fielded capability or key milestone that is driving urgency? Options: Within 3 months, 3–6 months, 6–12 months, 12–24 months, No firm date / exploratory
      • What is the primary driver of that timeline (funding FY, operational exercise, accreditation date, threat timeline, or other)?

      High-level security and accreditation posture

      • Which enclave(s) or data classification levels must the solution operate in or interface with? Options: Unclassified/public network, Secret-level enclave, TS/SCI-level enclave, Air-gapped/local enclave, Coalition/allied enclaves with IL requirements, Not sure / needs clarification
      • Are there known accreditation dependencies or artifacts we should be aware of now (existing RMF status, ATO, STIGs, POA&M items)? If known, briefly summarize availability.
    2. Operational Discovery

      Map stakeholders, current architecture, interoperability gaps, cybersecurity posture, and measurable success criteria.

      Discovery Questions

      Set the stage, in one pass

      • Tell me briefly about the mission area this program supports and the top three operational objectives.
      • In the last 12 months, which missions or exercises relied most heavily on your current systems? Options: Persistent ISR, Battle management, Maritime domain awareness, Tactical strike coordination, Space or high-altitude C2, Other
      • How many operator workstations and remote sites must receive fused data in the initial fielding wave? Options: 1-10, 11-50, 51-200, 201+
      • Describe the schedule drivers that cannot slip without causing program-level penalties, for example congressional milestones, test windows, or fielding dates.
      • Who on your team will be the primary program contact and who is the technical lead responsible for cybersecurity accreditation? Options: Program Manager, Deputy PM, Technical Lead, Cybersecurity Lead, Other

      Where the current system falls short

      • If your architecture could not exchange a key sensor feed during a contested operation, what would be the most damaging operational consequence?
      • Which interfaces or gateway types fail most often during your integration tests or exercises? Options: Encrypted gateway to enclave, Multicast sensor distribution, RESTful APIs, Message bus/topic connectors, Proprietary vendor bridge, Other
      • On average, how long does it take to restore a lost feed or reconfigure a connector during an exercise? Options: Under 1 hour, 1-4 hours, 4-24 hours, More than 24 hours
      • When integration failures occur, who is called first and what steps do they typically take to diagnose the issue?
      • Which single unresolved interoperability gap would cause you to stop a pilot or fielding until it is fixed?

      The human map that matters

      • Name the organization or individual who holds the Authority to Operate decision, and describe what would cause them to withhold approval.
      • Walk me through who must approve enclave connections, cross-domain transfers, and physical site access, and how those approvals typically flow.
      • List the operational user roles, their typical shift patterns, and which roles must see the common operating picture in real time. Options: Tactical Operators, Mission Commanders, Intelligence Analysts, Signal/Network Ops, Maintenance/Logistics, Other
      • How many external partners or coalition nodes require federated access, and do any of those partners require on-the-fly data transformation before sharing? Options: None, 1-2 partners, 3-5 partners, 6+ partners
      • If a key stakeholder group refuses the proposed operational concept, how likely is the program to proceed without them? Options: Proceed as planned, Proceed with reduced scope, Pause and renegotiate, Cancel

      Data and interfaces, not promises

      • Walk me through the three critical data feeds your program depends on, and for each name the owner, data format, and refresh rate.
      • Describe the classification level for each feed and how data is moved between classification domains in your current process. Options: Unclassified, Secret, Top Secret, Mixed levels
      • Are APIs available for your key systems, who maintains them, and do you have published schemas or test sandboxes? Options: APIs with schemas and sandbox, APIs without schemas, No APIs but file exchanges, Proprietary interfaces only
      • Estimate the percentage of incoming data that requires normalization or enrichment before it can be fused into the common operating picture. Options: 0-10%, 11-33%, 34-66%, 67-100%
      • Should a critical feed owner deny access or require six months to negotiate release, would that pause your acceptance criteria or can you proceed with mitigations? Options: Pause acceptance, Proceed with mitigations, Use synthetic/test feeds, Unknown

      Cybersecurity posture, accreditation, and deadlines

      • In your target network enclave, what is the current accreditation status and what specific steps remain to obtain an Authority to Operate? Options: Already ATO, ATO in progress, Initial authorization pending, No work started
      • Identify the RMF control families that are currently open and name the office or role responsible for each remediation action.
      • Count the cybersecurity assessments your system failed in the last three years and summarize the root causes. Options: 0, 1, 2-3, 4+
      • List the fixed security testing windows or authority-imposed dates that would constrain delivery and cannot be moved.
      • Should vendor-supplied artifacts be unavailable, can your team produce equivalent artifacts in time to meet the accreditation schedule? Options: Yes we can produce, No we cannot, Partial capability, Need vendor support

      Budget, procurement path, and decision gates

      • Tell me which procurement vehicle and contracting office will handle this award, and whether pre-existing IDIQ slots are available to use. Options: DoD contract vehicle, Agency IDIQ, New RFP required, Other
      • On a scale, how firm is the funding profile for this fiscal year and how much is earmarked versus discretionary? Options: Fully funded and earmarked, Mostly funded with some discretionary, Contingent on reprogramming, Not funded
      • Who controls funding execution and what approval steps are required to move funds across budget lines if a schedule slip requires it?
      • Assuming the pilot meets acceptance, which internal approvals would remain before award, and which of those could be fast tracked?
      • Is there a non negotiable budget cap or milestone payment that, if unmet, would prevent award? Options: Yes, cap exists, No cap, Depends on program office, Unknown

      Competitive landscape and the DIY option

      • Provide the alternative approaches you are actively evaluating, by category: incumbent vendor, other vendors, internal development, and note one strength of each.
      • Explain what conditions would have to be true for you to keep the incumbent or pursue an internal build instead of bringing in an external integrator.
      • Has anyone on your team proposed solving this in house, and if so who is leading that effort and what budget or timeline have they proposed? Options: No internal proposal, Internal proposal exists, Incumbent seeking extension, Other
      • What single advantage would lead you to choose the incumbent or an internal build over contracting with a new integrator?

      Acceptance criteria and measurable success

      • Outline the single metric that, if met in a pilot, would make you sign an agreement that same week.
      • Specify the numerical thresholds for integration latency in milliseconds, percentage data fusion accuracy, and the maturity level you require for security controls.
      • Provide the methods you will use to measure operational impact on mission tempo and decision cycles during the pilot, and name who will validate those results.
      • Given a pilot that exceeds performance targets but reveals classification transfer risks, would you proceed to award or pause to mitigate those risks? Options: Proceed to award, Pause for mitigation, Proceed with restrictions, Undecided

      Implementation practicalities and site constraints

      • Identify any physical site constraints, network enclave types, or access restrictions that would prevent deployment at a planned location.
      • Name who owns the on site network switches and whether they permit installation of required gateway or inspection hardware. Options: Prime contractor, Government network owner, Host unit, Other
      • Estimate the number of cleared engineer hours per week your team can commit for factory acceptance, integration, and on site testing. Options: 0-40 hours, 41-120 hours, 121-240 hours, 240+ hours
      • Are there export control, foreign disclosure, or coalition caveats that would block certain software modules from running at your site? Options: Yes, multiple caveats, Yes, limited, No, Unknown
      • Where physical access is limited to a single two week window, can you meet the deployment plan or would that force a schedule re baseline? Options: Meet plan, Force re baseline, Partial deployment possible, Unknown

      Next steps, risks, and the decisive path

      • Given all discovery items resolved, what is the earliest date you would be willing to enter into a pilot agreement? Options: Immediately, Within 30 days, Within 90 days, Later than 90 days
      • Specify the top program risks from this conversation that would cause you to delay award by more than one quarter.
      • Confirm the roles or named offices that must sign off on pilot scope and acceptance criteria to keep the timeline intact.
      • What would you need from the seller in the next two weeks to remove the top three schedule blockers?
      • Pick one action you could commit to this month that would most accelerate award, for example unlocking a dataset, approving a test window, or issuing a letter of intent. Options: Unlock dataset access, Approve a two week test window, Assign cleared engineer support, Issue a letter of intent, Other
  2. Solution Experience

    Translate operational needs into validated scenarios showing how the platform delivers a common operating picture and meets accreditation milestones.

    Solution Experience

    • Solution Experience Session
    • Confirm the current state and its cost to your program
    • You confirm the demonstrated scenario removes the manual reconciliation you described and shortens the decision timeline.
    • Produce a tailored scenario replay file and a one-page accreditation evidence map that ties the demonstrated workflow to RMF controls and milestone impacts.
    • You confirm the shown accreditation artifacts map to your RMF/ATO checkpoints and that the timeline impact is acceptable for your milestone needs.
    • Run the validated mission scenario end-to-end
    • Provide the current list of sensor endpoints, data formats, enclave types, and the acceptance criteria you will use for the technical evaluation.
    • Show accreditation evidence mapping and milestone impact
    • You agree to a concrete scope and acceptance criteria for the follow-up technical evaluation.
    • Define the decision owners and signoff points for the scoped evaluation and confirm target dates for evidence delivery.
    • Validate the fit with a direct confirmation
    • Agree next technical evaluation scope and deliverables
    • Solution Experience Session
    • Solution Experience Deck
    • Solution Brief — Common Operating Picture & Accreditation
    • meeting
    • slides
    • document
  3. Solution Scope

    Define system modules, interfaces, responsibilities, test criteria, deployment sites, and cybersecurity accreditation deliverables.

    Scope Configuration

    • Ruggedized Operator Workstation Fielding
    • Secure Communications Gateway Installation
    • Sensor Interface and Feed Onboarding
    • Real-Time Data Correlation Engine Deployment
    • Common Operating Picture Visualization Deployment
    • Role-Based Access Control Configuration (DISA‑Compliant)
    • Factory Integration and System Build
    • Site Rack Integration and Power/Cooling Installation
    • Operational Test and Live Exercise Execution
    • RMF Authorization Artifacts and ATO Support
    • STIG Baseline Implementation and Network Hardening
    • Field Spares, Logistics, and Depot Transition Kit
    • Operator Training and SOP Handover

    Scope Questions

    Ruggedized Operator Workstation Fielding

    • Do you require workstations certified for the intended enclave types (for example NIPR, SIPR, coalition enclaves)? Options: NIPR, SIPR, Both, Other
    • How many operator seats will be fielded per site for the ruggedized workstation? Options: 1-4, 5-10, 11-24, 25+
    • Specify the environmental or ruggedization ratings required (for example MIL-STD-810, IP65, operating temperature range). Options: MIL-STD-810, IP65, IP67, Custom/Other
    • Do you require local disk encryption and FIPS 140 validated cryptographic modules on the workstations? Options: Yes, No
    • Describe required peripheral certifications and imaging process, for example headset/TACCOM interoperability, certified drivers, and boot-image provisioning flow.

    Secure Communications Gateway Installation

    • Which enclave boundaries and network labels will each gateway terminate (for example NIPR, SIPR, coalition enclaves)? Options: NIPR, SIPR, Coalition/Allied, Other
    • How many concurrent encrypted tunnels or sessions should each gateway support at peak? Options: <100, 100-500, 500-2000, 2000+
    • Specify required crypto profiles and key management method (for example PKI with CAC/PIV, hardware security module backing). Options: PKI (CAC/PIV), HSM-backed PKI, Pre-shared keys, Other
    • Are existing boundary devices and firewall rule sets required to interoperate with the gateway? Options: Yes, No
    • Are site single-line diagrams (SLD) or network diagrams available to inform placement, power, and rack-space assessments? Options: Yes, No

    Sensor Interface and Feed Onboarding

    • List the sensor types and protocols to be onboarded and their expected feed formats (for example GMTI, EO/IR, ADS-B, Link-16, AIS and whether feeds are JSON, XML, binary, or socket stream).
    • Estimate the number of distinct sensor feeds that will be integrated at initial fielding per site. Options: 1-5, 6-15, 16-50, 51+
    • Will any sensor feeds require protocol translation or adapters (for example Link-16 gateway, ADS-B to IP translator)? Options: Yes, No
    • Provide the latency and update-rate SLAs required for each critical feed (for example <1s, <5s, <1 minute) and note per-feed priorities. Options: <1s, <5s, <1min, Custom
    • What sample data extract, schema, or test vectors will you provide for onboarding validation (for example recorded packets, IKD messages, or time-stamped track dumps)?

    Real-Time Data Correlation Engine Deployment

    • Estimate the sustained number of simultaneous tracks or fused objects the correlation engine must handle. Options: <1,000, 1,000-10,000, 10,000-100,000, 100,000+
    • What target data-fusion accuracy or acceptable false positive/negative thresholds must the engine meet for mission-critical tracks? Options: >99%, 95-99%, 90-95%, Custom
    • Is a fixed processing-latency guarantee required for correlation (for example maximum processing latency in milliseconds)? Options: Yes, No
    • Which downstream integration endpoints must the engine publish to (for example map clients, message bus topics, REST API endpoints)?
    • Provide the performance test scenarios and workload profiles you expect during system-level validation, for example sustained track density, feed loss injection, and recovery time objectives.

    Common Operating Picture Visualization Deployment

    • List required map layers, coordinate reference systems, and geospatial standards to support (for example WGS84, required symbology sets, overlays for classification).
    • Indicate the number of concurrent operator displays and the target refresh rates the visualization must support. Options: 1-4, 5-10, 11-25, 26+
    • Is accreditation milestone alignment required for visualization components (for example accredited rendering of classified overlays tied to ATO steps)? Options: Yes, No
    • Describe the user workflows and scenario steps to validate during demonstration, for example track-to-COP mapping, target nomination, and collaborative share flows.
    • Identify the acceptance evidence that will validate COP visualization readiness (for example end-to-end scenario replay logs, timestamped track-to-map alignment reports, operator sign-off).

    Role-Based Access Control Configuration (DISA‑Compliant)

    • Indicate the number of distinct operator roles and templates required, including administrators, auditors, and mission users. Options: 1-3, 4-7, 8-15, 16+
    • List required authentication methods (for example CAC/PIV, PKI, multi-factor authentication) to be supported for each role. Options: CAC/PIV, PKI without CAC, Username/MFA, Other
    • Specify audit log retention and formats required by your accreditation (for example 90 days, 1 year, syslog format). Options: 90 days, 1 year, Custom
    • Do you require STIG-hardened role profiles and strict separation-of-duties enforcement as part of role configuration? Options: Yes, No
    • Identify privileged account management requirements such as just-in-time elevation, session recording, or break-glass procedures.

    Factory Integration and System Build

    • How many unique system-build configurations require factory integration and Factory Acceptance Testing prior to shipment? Options: 1, 2-3, 4+
    • Specify the Factory Acceptance Testing (FAT) test cases you expect, for example end-to-end data flow with simulated sensors, image load, and performance thresholds.
    • Do you require hardware serialization, DoD-compliant asset tagging, and labeling for each unit? Options: Yes, No
    • Provide the factory documentation deliverables required such as build books, wiring diagrams, master images, and configuration baselines.
    • Are there depot turn-in, packaging, or transport constraints to meet (for example MIL-STD packing, pallet dimensions, customs documentation)? Options: Yes, No

    Site Rack Integration and Power/Cooling Installation

    • How many racks and total rack units will be installed per site and can you provide the single-line diagram (SLD) for power feeds?
    • Do sites require redundant power feeds, UPS capacity, or generator tie-ins for the rack population? Options: Redundant feeds, Standard single feed, Generator tie-in only, Other
    • Specify cooling capacity requirements for the rack population in BTU/hr or tons and any ambient temperature constraints.
    • Are there site access or clearance requirements for installation personnel (for example badge levels or escort requirements)? Options: Yes, No
    • Identify grounding, bonding, and EMI/EMC requirements for rack installation (for example MIL-STD-464 or equivalent constraints).

    Operational Test and Live Exercise Execution

    • Which operational scenarios and mission threads must be exercised during live test (for example ISR cue-to-action, multi-domain track handoff)?
    • How many distributed sites or coalition participants must be exercised simultaneously during the live exercise? Options: Single site, 2-3 sites, 4-10 sites, 10+
    • Provide the objective measures and thresholds for test success, for example maximum data-fusion latency, track continuity percentage, and acceptable packet loss.
    • Do you require cyber-incident injects, red-team interoperability tests, or simulated sensor failures to be included in the exercise? Options: Yes, No
    • What evidence will you accept to sign off live-exercise success (for example signed test reports, bit-for-bit replay logs, observer checklists)?

    RMF Authorization Artifacts and ATO Support

    • Which accreditation boundary and specific artifacts do you require in the ATO package such as the System Security Plan (SSP), Plan of Actions and Milestones (POA&M), and Security Assessment Report (SAR)?
    • Do you require support for producing vulnerability scan baselines, STIG checklists, and automated compliance evidence? Options: Yes, No
    • Specify the evidence and artifacts required for Authority to Operate such as signed SSP, POA&M entries with remediation owners, and continuous monitoring plan items.
    • Are there existing continuous monitoring or SIEM feeds that must be integrated into the accreditation package? Options: Yes, No
    • Provide your target ATO timeline and note any upstream or joint ATO dependencies on other systems. Options: <3 months, 3-6 months, 6-12 months, 12+ months

    STIG Baseline Implementation and Network Hardening

    • Which operating systems and device classes must have STIG baselines applied (for example Linux variants, Windows Server, network appliances)?
    • Do you have an existing STIG compliance baseline and remediation backlog we should ingest? Options: Yes, No
    • Specify the acceptable deviation or waiver process for items that cannot comply with a STIG, for example documented risk acceptance versus POA&M entry. Options: Formal waiver required, POA&M entry acceptable, Other
    • Are network segmentation and micro-segmentation policies required to be enforced as part of the hardening work? Options: Yes, No
    • Identify the patching cadence and vulnerability management SLA you require for the hardened baseline. Options: Weekly, Monthly, Quarterly, Other

    Field Spares, Logistics, and Depot Transition Kit

    • How many field-spare kits are required per site and which components must each kit include (for example spare blades, power supplies, network modules)? Options: 1, 2, 3+
    • Do you require depot-level technical manuals, maintenance checklists, and line-replaceable unit (LRU) lists as part of the transition kit? Options: Yes, No
    • Specify transport, customs, or export-control considerations for overseas transfer and handover of spares.
    • Are there known part obsolescence or lifecycle constraints we should account for in the depot kit (for example end-of-life windows)? Options: Yes, No
    • Provide the on-site Mean Time To Repair (MTTR) target and spare-part replenishment SLA required. Options: <4 hours, 4-24 hours, 24-72 hours, 72+ hours
  4. Solution Evaluation

    Run a scoped technical evaluation against agreed acceptance criteria — integration tests, data fusion fidelity, and security controls — to validate performance and accreditation feasibility.

    • desired_state
    • stakeholders
    • gaps
    • success_criteria
    • current_state
    • decision_readiness
    • decision_readiness
    • desired_state
    • current_state
    • success_criteria
    • gaps
    • stakeholders
    • gaps
    • success_criteria
    • current_state
    • stakeholders
    • desired_state
    • decision_readiness
    • decision_readiness
    • decision_readiness
    • decision_readiness
    • decision_readiness
  5. Mutual Commit

    Finalize contractual terms, performance milestones, ATO dependencies, and program governance required for award and execution.

    Agreement Modules

    • Master Services Agreement (MSA)
    • Statement of Work (SOW)
    • Program Governance Charter
    • Authority to Operate (ATO) Dependencies Addendum
    • Security and Accreditation Plan
    • Acceptance Test & Evaluation Plan (T&E)
    • Payment & Pricing Schedule
    • Change Order Agreement
    • Subcontracting and Supply Chain Security Addendum
    • Data Rights & Software License Agreement
    • Program Risk Register and Acceptance
    • Procurement & Security Rider (DoD/RMF/CMMC) - conditional
  6. Deployment

    Operationalize rollout with readiness checks, execution, and outcome validation.

    1. Pre-Deployment Readiness

      Confirm owners, network environments, enclave types, access permissions, and required artifacts for accreditation and fielding.

      Pre-Deployment Questions

      Environment and site access

      • Which target environments will this deployment touch? (select all that apply — used to plan network, enclave, and gateway tasks) Options: Production classified enclave, Production unclassified enclave, Staging / integration enclave, Test / lab enclave, Edge / disconnected enclave, Government cloud region, Contractor-hosted enclave, Other (specify in next field)
      • For each environment selected, provide the named network owner or point of contact (name, role, org) who can approve connectivity, firewall, and gateway changes.
      • Are gateway/integration endpoint owners and their maintenance windows confirmed for all selected environments? (so we can schedule integration and cutover) Options: Yes — all owners and windows confirmed, Partial — some owners/windows pending, No — owners/windows not confirmed

      Data and configuration

      • Who is the source-of-truth owner for operational data (name, role, dataset/category) and will they sign the data-mapping/transfer approval?
      • Which of the following accreditation and deployment artifacts are already available for the system or site? (select all that apply — we will reference these to plan evidence collection) Options: System Security Plan (SSP), Interconnection Security Agreement (ISA) / ISM documentation, Plan of Actions & Milestones (POA&M), Security Assessment Report / Test results, Factory Acceptance Test (FAT) / Site Acceptance Test (SAT) plans, Network and interface diagrams, Operator account / RBAC provisioning template, ATO / provisional authority letter, None of the above, Other (specify)

      People and ownership

      • Who is the designated deployment owner responsible for schedule, coordination, and final site acceptance? (name, role, primary contact)
      • List the named approval authorities for accreditation evidence and ATO decisions (e.g., Authorizing Official, ISSO, CISO) and indicate whether each will accept remote evidence review.
      • Are cleared seller personnel authorized for on-site access and badge sponsorship at each site? (select the option that matches current status) Options: Yes — on-site access and badge sponsorship approved, Yes — on-site access approved, badge sponsorship pending, No — only remote access authorized, No — on-site access prohibited

      Timing and constraints

      • Are there fixed blackout windows, mission-critical dates, or fiscal constraints that will limit installation or testing at any site? (if yes, we'll request date ranges in the free-response field) Options: No, Yes — dates will be provided in the next field
      • Target date for first site fielding or production cutover (enter a date or 'TBD') — this locks schedule milestones and ATO dependencies.
    2. Configuration Details

      Lock exact configuration values, gateway interfaces, encryption profiles, operator roles, and integration endpoints the deployment will use.

      Configuration Details

      Configuration Snapshot — core identifiers the build will lock

      • Enter the exact deployment environment name the orchestration will use (format: single token, no spaces). Default: production
      • Environment type (select one). Default: Production Options: Production, Staging, Development, Test, Continuous Integration
      • Primary deployment region for this build (select one). Default: CONUS Options: CONUS, OCONUS, Classified enclave (secret/high classification), Edge/Forward-deployed, Multi-region

      Network & Gateway Interfaces — exact interfaces and endpoints the platform will bind to

      • Primary gateway interface type that will carry platform traffic (select one) Options: Physical Ethernet (802.3), Routed IP over tactical radio, MPLS VPN, Dedicated fiber, Satellite link (e.g., GEO/LEO), Secure cellular (LTE/5G), Other
      • Primary gateway endpoint the platform will route to (enter FQDN or IPv4/IPv6 address; format: hostname.domain or 10.0.0.1)
      • Network segmentation / enclave type this deployment will reside in (select one) Options: Unclassified, Sensitive-but-unclassified, Secret/classified enclave, Cross-domain gateway required, Air-gapped

      Encryption & Security — profiles and compliance flags the deployment enforces

      • Data-in-transit encryption profile to lock (select one). Default: TLS1.3-AES256-GCM Options: TLS1.3-AES256-GCM (default), TLS1.2-AES256-GCM, IPsec/IKEv2-AES256, AES256-GCM (platform-managed tunnel), Custom profile (provide canonical name to your security owner separate from this sheet)
      • Is FIPS-140 validated cryptography required for this deployment? Default: Yes Options: Yes, No

      Identity & Operator Roles — exact role and authentication source names the platform will create/use

      • Primary identity provider (IdP) type for operator authentication (select one). Default: SAML-based IdP Options: SAML-based IdP, OIDC-based IdP, LDAP-only, Local platform accounts (no external IdP), None (manual operator provisioning)
      • Primary operator role name to create in the platform (enter exact identifier; example: OPERATOR_VIEWER). This exact string will be used in role mappings.
    3. Deployment Execution

      Execute systems integration, factory acceptance, site installation, operational testing, and schedule milestones with named owners and escalation paths.

    4. Go-Live Acceptance

      Formal acceptance gate to verify functional tests, cybersecurity accreditation evidence, and operational readiness signatures before declaring fielding complete.

      Checklist items

      • Receive signed functional test acceptance
      • Verify integration and regression test artifacts are complete
      • Obtain formal cybersecurity authorization evidence
      • Confirm POA&M and risk-acceptance for outstanding findings
      • Validate rollback and recovery plan execution
      • Obtain per-deployment-site operational readiness sign-off
      • Verify site safety and energization clearance
      • Receive final programmatic acceptance sign-off
      • Handover operations runbook, monitoring, and escalation artifacts
      • Confirm operator training and competency attestations
      • Issue go-live acceptance certificate and archive evidence
  7. Sustainment & Success

    Monitor mission outcomes, track issues and enhancement requests, and run recurring reviews to ensure operational performance and accreditation continuity.

    Success Reviews

    • Go-Live Health Check (Week 1-4)
    • First Measurement Review (Week 4-10)
    • 90-Day Sustainment Ratification and Accreditation Continuity (Day ~90)
    • Quarterly Operational Review
    • Annual Mission Outcomes Review

    Issues & Enhancements

    • Publish the prioritized backlog with target delivery windows and test criteria for each item retained for implementation.
    • Close or create remediation tickets for all outstanding critical accreditation findings with target completion dates.
    • Schedule the quarterly operational review dates for the next 12 months.
    • Verify accreditation artifacts remain current and schedule any required evidence refreshes.
    • Trend review for uptime and operator proficiency
    • Confirm system uptime on the accredited enclave and operator proficiency rate meet sustainment thresholds or have remediation plans in place.
    • Agree priority and resolution timeline for the top persistent issues and backlog items affecting mission outcomes.
    • Re-confirm success criteria and owner map
    • Create resolution plans for the top 5 persistent issues with measurable success criteria.
    • Schedule accreditation artifact refresh tasks aligned to the documented evidence cadence.
    • Year-to-date mission outcomes
    • Confirm whether the platform met its year-one mission targets for mission task completion rate and mean sensor-to-decision latency as recorded in Solution Evaluation.
    • Document accreditation continuity over the year and identify any major audit exposures requiring action.
    • Agree a set of operational adjustments and test schedules to be executed in the next 12 months.
    • Publish the annual outcomes report including metric trends, accreditation summary, and the agreed operational adjustments.
    • Open implementation tasks for agreed operational adjustments with completion targets for the next quarter.
    • Compile a consolidated list of enhancements resolved in the past 12 months and lessons learned for program records.
    • Deployment deliverables validated against the artifacts recorded in Solution Evaluation and any critical gaps identified.
    • Incumbent system wind-down posture confirmed (decommission or retain-read-only) and data migration/archive status documented.
    • Immediate remediation actions and owners recorded with target dates for next check-in.
    • Publish the deployment validation summary and incumbent wind-down checklist for asynchronous confirmation.
    • Create and prioritize remediation tickets for all high-severity blockers with resolution target dates.
    • Circulate operator onboarding issues and schedule targeted training or configuration adjustments as required.
    • Present first-period outcomes vs targets
    • Confirm whether the measured data fusion correlation accuracy rate and mean sensor-to-decision latency meet the targets recorded in Solution Evaluation or require remediation.
    • Agree a concrete remediation plan with target dates to close the top 3 measured gaps.
    • Ensure open accreditation findings count is reduced or has committed resolution dates that preserve ATO continuity.
    • Produce a remediation task list for each failed metric with specific technical actions and completion dates.
    • Deliver updated telemetry dashboards that isolate the root-cause indicators for each metric shortfall.
    • Publish a time-boxed plan to resolve open accreditation findings with referenced evidence artifacts.
    • Restate sustainment and accreditation criteria
    • Sustainment plan and accreditation continuity approach formally ratified for ongoing operations without re-running the deployment acceptance decision.
    • All critical accreditation or operational blockers are closed or assigned with committed resolution dates.
    • A named sustainment review cadence is established for the next 12 months.
    • Publish the ratified sustainment plan and accreditation evidence schedule with the ratification record.
    • Deployment and migration validation
    • Persistent issues and ticket burn-down
    • Accreditation continuity and audit summary
    • Present 90-day operational and security metrics
    • Root cause diagnosis for gaps
    • Accreditation and security findings review
    • Enhancement requests and backlog hygiene
    • Close or reassign critical remediations
    • Open enhancements resolved and outstanding
    • Early adoption and usage signals
    • Incumbent system wind-down status
    • Lessons learned and operational adjustments
    • Accreditation evidence currency check
    • Agree corrective actions and schedule
    • Sustainment plan ratification and sign-off ceremony
    • Blockers and immediate remediation plan
First-Party AI

1-2 minutes please — Your AI agent is working

First-Party AI™ can make mistakes. Always check important information.