Command, Control & Intelligence Systems
Multi-agency, multi-stakeholder programs where procurement, compliance, and mission alignment determine success.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Pre-Sales
Qualify and diagnose before investing in formal evaluation and fieldwork.
-
Acquisition Fit Validation
Confirm budget profile, decision authority, schedule constraints, and high-level security requirements before full discovery.
Qualification Questions
Budget and funding profile
- So we make the best use of your time: is there an allocated budget range for procurement or integration of this capability?
- Is the funding single-year, multi-year/incremental, or still TBD? If there are fiscal constraints (e.g., FY deadlines), briefly note them.
Decision authority and key stakeholders
- Who is the final decision authority for awarding work like this (role or office, not a person)?
- Who are the other technical or sponsor stakeholders we should include in a discovery conversation (roles only)?
Schedule and driving milestones
- What is the target timeline for an initial fielded capability or key milestone that is driving urgency?
- What is the primary driver of that timeline (funding FY, operational exercise, accreditation date, threat timeline, or other)?
High-level security and accreditation posture
- Which enclave(s) or data classification levels must the solution operate in or interface with?
- Are there known accreditation dependencies or artifacts we should be aware of now (existing RMF status, ATO, STIGs, POA&M items)? If known, briefly summarize availability.
-
Operational Discovery
Map stakeholders, current architecture, interoperability gaps, cybersecurity posture, and measurable success criteria.
Discovery Questions
Set the stage, in one pass
- Tell me briefly about the mission area this program supports and the top three operational objectives.
- In the last 12 months, which missions or exercises relied most heavily on your current systems?
- How many operator workstations and remote sites must receive fused data in the initial fielding wave?
- Describe the schedule drivers that cannot slip without causing program-level penalties, for example congressional milestones, test windows, or fielding dates.
- Who on your team will be the primary program contact and who is the technical lead responsible for cybersecurity accreditation?
Where the current system falls short
- If your architecture could not exchange a key sensor feed during a contested operation, what would be the most damaging operational consequence?
- Which interfaces or gateway types fail most often during your integration tests or exercises?
- On average, how long does it take to restore a lost feed or reconfigure a connector during an exercise?
- When integration failures occur, who is called first and what steps do they typically take to diagnose the issue?
- Which single unresolved interoperability gap would cause you to stop a pilot or fielding until it is fixed?
The human map that matters
- Name the organization or individual who holds the Authority to Operate decision, and describe what would cause them to withhold approval.
- Walk me through who must approve enclave connections, cross-domain transfers, and physical site access, and how those approvals typically flow.
- List the operational user roles, their typical shift patterns, and which roles must see the common operating picture in real time.
- How many external partners or coalition nodes require federated access, and do any of those partners require on-the-fly data transformation before sharing?
- If a key stakeholder group refuses the proposed operational concept, how likely is the program to proceed without them?
Data and interfaces, not promises
- Walk me through the three critical data feeds your program depends on, and for each name the owner, data format, and refresh rate.
- Describe the classification level for each feed and how data is moved between classification domains in your current process.
- Are APIs available for your key systems, who maintains them, and do you have published schemas or test sandboxes?
- Estimate the percentage of incoming data that requires normalization or enrichment before it can be fused into the common operating picture.
- Should a critical feed owner deny access or require six months to negotiate release, would that pause your acceptance criteria or can you proceed with mitigations?
Cybersecurity posture, accreditation, and deadlines
- In your target network enclave, what is the current accreditation status and what specific steps remain to obtain an Authority to Operate?
- Identify the RMF control families that are currently open and name the office or role responsible for each remediation action.
- Count the cybersecurity assessments your system failed in the last three years and summarize the root causes.
- List the fixed security testing windows or authority-imposed dates that would constrain delivery and cannot be moved.
- Should vendor-supplied artifacts be unavailable, can your team produce equivalent artifacts in time to meet the accreditation schedule?
Budget, procurement path, and decision gates
- Tell me which procurement vehicle and contracting office will handle this award, and whether pre-existing IDIQ slots are available to use.
- On a scale, how firm is the funding profile for this fiscal year and how much is earmarked versus discretionary?
- Who controls funding execution and what approval steps are required to move funds across budget lines if a schedule slip requires it?
- Assuming the pilot meets acceptance, which internal approvals would remain before award, and which of those could be fast tracked?
- Is there a non negotiable budget cap or milestone payment that, if unmet, would prevent award?
Competitive landscape and the DIY option
- Provide the alternative approaches you are actively evaluating, by category: incumbent vendor, other vendors, internal development, and note one strength of each.
- Explain what conditions would have to be true for you to keep the incumbent or pursue an internal build instead of bringing in an external integrator.
- Has anyone on your team proposed solving this in house, and if so who is leading that effort and what budget or timeline have they proposed?
- What single advantage would lead you to choose the incumbent or an internal build over contracting with a new integrator?
Acceptance criteria and measurable success
- Outline the single metric that, if met in a pilot, would make you sign an agreement that same week.
- Specify the numerical thresholds for integration latency in milliseconds, percentage data fusion accuracy, and the maturity level you require for security controls.
- Provide the methods you will use to measure operational impact on mission tempo and decision cycles during the pilot, and name who will validate those results.
- Given a pilot that exceeds performance targets but reveals classification transfer risks, would you proceed to award or pause to mitigate those risks?
Implementation practicalities and site constraints
- Identify any physical site constraints, network enclave types, or access restrictions that would prevent deployment at a planned location.
- Name who owns the on site network switches and whether they permit installation of required gateway or inspection hardware.
- Estimate the number of cleared engineer hours per week your team can commit for factory acceptance, integration, and on site testing.
- Are there export control, foreign disclosure, or coalition caveats that would block certain software modules from running at your site?
- Where physical access is limited to a single two week window, can you meet the deployment plan or would that force a schedule re baseline?
Next steps, risks, and the decisive path
- Given all discovery items resolved, what is the earliest date you would be willing to enter into a pilot agreement?
- Specify the top program risks from this conversation that would cause you to delay award by more than one quarter.
- Confirm the roles or named offices that must sign off on pilot scope and acceptance criteria to keep the timeline intact.
- What would you need from the seller in the next two weeks to remove the top three schedule blockers?
- Pick one action you could commit to this month that would most accelerate award, for example unlocking a dataset, approving a test window, or issuing a letter of intent.
-
-
Solution Experience
Translate operational needs into validated scenarios showing how the platform delivers a common operating picture and meets accreditation milestones.
Solution Experience
- Solution Experience Session
- Confirm the current state and its cost to your program
- You confirm the demonstrated scenario removes the manual reconciliation you described and shortens the decision timeline.
- Produce a tailored scenario replay file and a one-page accreditation evidence map that ties the demonstrated workflow to RMF controls and milestone impacts.
- You confirm the shown accreditation artifacts map to your RMF/ATO checkpoints and that the timeline impact is acceptable for your milestone needs.
- Run the validated mission scenario end-to-end
- Provide the current list of sensor endpoints, data formats, enclave types, and the acceptance criteria you will use for the technical evaluation.
- Show accreditation evidence mapping and milestone impact
- You agree to a concrete scope and acceptance criteria for the follow-up technical evaluation.
- Define the decision owners and signoff points for the scoped evaluation and confirm target dates for evidence delivery.
- Validate the fit with a direct confirmation
- Agree next technical evaluation scope and deliverables
- Solution Experience Session
- Solution Experience Deck
- Solution Brief — Common Operating Picture & Accreditation
- meeting
- slides
- document
-
Solution Scope
Define system modules, interfaces, responsibilities, test criteria, deployment sites, and cybersecurity accreditation deliverables.
Scope Configuration
- Ruggedized Operator Workstation Fielding
- Secure Communications Gateway Installation
- Sensor Interface and Feed Onboarding
- Real-Time Data Correlation Engine Deployment
- Common Operating Picture Visualization Deployment
- Role-Based Access Control Configuration (DISA‑Compliant)
- Factory Integration and System Build
- Site Rack Integration and Power/Cooling Installation
- Operational Test and Live Exercise Execution
- RMF Authorization Artifacts and ATO Support
- STIG Baseline Implementation and Network Hardening
- Field Spares, Logistics, and Depot Transition Kit
- Operator Training and SOP Handover
Scope Questions
Ruggedized Operator Workstation Fielding
- Do you require workstations certified for the intended enclave types (for example NIPR, SIPR, coalition enclaves)?
- How many operator seats will be fielded per site for the ruggedized workstation?
- Specify the environmental or ruggedization ratings required (for example MIL-STD-810, IP65, operating temperature range).
- Do you require local disk encryption and FIPS 140 validated cryptographic modules on the workstations?
- Describe required peripheral certifications and imaging process, for example headset/TACCOM interoperability, certified drivers, and boot-image provisioning flow.
Secure Communications Gateway Installation
- Which enclave boundaries and network labels will each gateway terminate (for example NIPR, SIPR, coalition enclaves)?
- How many concurrent encrypted tunnels or sessions should each gateway support at peak?
- Specify required crypto profiles and key management method (for example PKI with CAC/PIV, hardware security module backing).
- Are existing boundary devices and firewall rule sets required to interoperate with the gateway?
- Are site single-line diagrams (SLD) or network diagrams available to inform placement, power, and rack-space assessments?
Sensor Interface and Feed Onboarding
- List the sensor types and protocols to be onboarded and their expected feed formats (for example GMTI, EO/IR, ADS-B, Link-16, AIS and whether feeds are JSON, XML, binary, or socket stream).
- Estimate the number of distinct sensor feeds that will be integrated at initial fielding per site.
- Will any sensor feeds require protocol translation or adapters (for example Link-16 gateway, ADS-B to IP translator)?
- Provide the latency and update-rate SLAs required for each critical feed (for example <1s, <5s, <1 minute) and note per-feed priorities.
- What sample data extract, schema, or test vectors will you provide for onboarding validation (for example recorded packets, IKD messages, or time-stamped track dumps)?
Real-Time Data Correlation Engine Deployment
- Estimate the sustained number of simultaneous tracks or fused objects the correlation engine must handle.
- What target data-fusion accuracy or acceptable false positive/negative thresholds must the engine meet for mission-critical tracks?
- Is a fixed processing-latency guarantee required for correlation (for example maximum processing latency in milliseconds)?
- Which downstream integration endpoints must the engine publish to (for example map clients, message bus topics, REST API endpoints)?
- Provide the performance test scenarios and workload profiles you expect during system-level validation, for example sustained track density, feed loss injection, and recovery time objectives.
Common Operating Picture Visualization Deployment
- List required map layers, coordinate reference systems, and geospatial standards to support (for example WGS84, required symbology sets, overlays for classification).
- Indicate the number of concurrent operator displays and the target refresh rates the visualization must support.
- Is accreditation milestone alignment required for visualization components (for example accredited rendering of classified overlays tied to ATO steps)?
- Describe the user workflows and scenario steps to validate during demonstration, for example track-to-COP mapping, target nomination, and collaborative share flows.
- Identify the acceptance evidence that will validate COP visualization readiness (for example end-to-end scenario replay logs, timestamped track-to-map alignment reports, operator sign-off).
Role-Based Access Control Configuration (DISA‑Compliant)
- Indicate the number of distinct operator roles and templates required, including administrators, auditors, and mission users.
- List required authentication methods (for example CAC/PIV, PKI, multi-factor authentication) to be supported for each role.
- Specify audit log retention and formats required by your accreditation (for example 90 days, 1 year, syslog format).
- Do you require STIG-hardened role profiles and strict separation-of-duties enforcement as part of role configuration?
- Identify privileged account management requirements such as just-in-time elevation, session recording, or break-glass procedures.
Factory Integration and System Build
- How many unique system-build configurations require factory integration and Factory Acceptance Testing prior to shipment?
- Specify the Factory Acceptance Testing (FAT) test cases you expect, for example end-to-end data flow with simulated sensors, image load, and performance thresholds.
- Do you require hardware serialization, DoD-compliant asset tagging, and labeling for each unit?
- Provide the factory documentation deliverables required such as build books, wiring diagrams, master images, and configuration baselines.
- Are there depot turn-in, packaging, or transport constraints to meet (for example MIL-STD packing, pallet dimensions, customs documentation)?
Site Rack Integration and Power/Cooling Installation
- How many racks and total rack units will be installed per site and can you provide the single-line diagram (SLD) for power feeds?
- Do sites require redundant power feeds, UPS capacity, or generator tie-ins for the rack population?
- Specify cooling capacity requirements for the rack population in BTU/hr or tons and any ambient temperature constraints.
- Are there site access or clearance requirements for installation personnel (for example badge levels or escort requirements)?
- Identify grounding, bonding, and EMI/EMC requirements for rack installation (for example MIL-STD-464 or equivalent constraints).
Operational Test and Live Exercise Execution
- Which operational scenarios and mission threads must be exercised during live test (for example ISR cue-to-action, multi-domain track handoff)?
- How many distributed sites or coalition participants must be exercised simultaneously during the live exercise?
- Provide the objective measures and thresholds for test success, for example maximum data-fusion latency, track continuity percentage, and acceptable packet loss.
- Do you require cyber-incident injects, red-team interoperability tests, or simulated sensor failures to be included in the exercise?
- What evidence will you accept to sign off live-exercise success (for example signed test reports, bit-for-bit replay logs, observer checklists)?
RMF Authorization Artifacts and ATO Support
- Which accreditation boundary and specific artifacts do you require in the ATO package such as the System Security Plan (SSP), Plan of Actions and Milestones (POA&M), and Security Assessment Report (SAR)?
- Do you require support for producing vulnerability scan baselines, STIG checklists, and automated compliance evidence?
- Specify the evidence and artifacts required for Authority to Operate such as signed SSP, POA&M entries with remediation owners, and continuous monitoring plan items.
- Are there existing continuous monitoring or SIEM feeds that must be integrated into the accreditation package?
- Provide your target ATO timeline and note any upstream or joint ATO dependencies on other systems.
STIG Baseline Implementation and Network Hardening
- Which operating systems and device classes must have STIG baselines applied (for example Linux variants, Windows Server, network appliances)?
- Do you have an existing STIG compliance baseline and remediation backlog we should ingest?
- Specify the acceptable deviation or waiver process for items that cannot comply with a STIG, for example documented risk acceptance versus POA&M entry.
- Are network segmentation and micro-segmentation policies required to be enforced as part of the hardening work?
- Identify the patching cadence and vulnerability management SLA you require for the hardened baseline.
Field Spares, Logistics, and Depot Transition Kit
- How many field-spare kits are required per site and which components must each kit include (for example spare blades, power supplies, network modules)?
- Do you require depot-level technical manuals, maintenance checklists, and line-replaceable unit (LRU) lists as part of the transition kit?
- Specify transport, customs, or export-control considerations for overseas transfer and handover of spares.
- Are there known part obsolescence or lifecycle constraints we should account for in the depot kit (for example end-of-life windows)?
- Provide the on-site Mean Time To Repair (MTTR) target and spare-part replenishment SLA required.
-
Solution Evaluation
Run a scoped technical evaluation against agreed acceptance criteria — integration tests, data fusion fidelity, and security controls — to validate performance and accreditation feasibility.
- desired_state
- stakeholders
- gaps
- success_criteria
- current_state
- decision_readiness
- decision_readiness
- desired_state
- current_state
- success_criteria
- gaps
- stakeholders
- gaps
- success_criteria
- current_state
- stakeholders
- desired_state
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
-
Mutual Commit
Finalize contractual terms, performance milestones, ATO dependencies, and program governance required for award and execution.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Program Governance Charter
- Authority to Operate (ATO) Dependencies Addendum
- Security and Accreditation Plan
- Acceptance Test & Evaluation Plan (T&E)
- Payment & Pricing Schedule
- Change Order Agreement
- Subcontracting and Supply Chain Security Addendum
- Data Rights & Software License Agreement
- Program Risk Register and Acceptance
- Procurement & Security Rider (DoD/RMF/CMMC) - conditional
-
Deployment
Operationalize rollout with readiness checks, execution, and outcome validation.
-
Pre-Deployment Readiness
Confirm owners, network environments, enclave types, access permissions, and required artifacts for accreditation and fielding.
Pre-Deployment Questions
Environment and site access
- Which target environments will this deployment touch? (select all that apply — used to plan network, enclave, and gateway tasks)
- For each environment selected, provide the named network owner or point of contact (name, role, org) who can approve connectivity, firewall, and gateway changes.
- Are gateway/integration endpoint owners and their maintenance windows confirmed for all selected environments? (so we can schedule integration and cutover)
Data and configuration
- Who is the source-of-truth owner for operational data (name, role, dataset/category) and will they sign the data-mapping/transfer approval?
- Which of the following accreditation and deployment artifacts are already available for the system or site? (select all that apply — we will reference these to plan evidence collection)
People and ownership
- Who is the designated deployment owner responsible for schedule, coordination, and final site acceptance? (name, role, primary contact)
- List the named approval authorities for accreditation evidence and ATO decisions (e.g., Authorizing Official, ISSO, CISO) and indicate whether each will accept remote evidence review.
- Are cleared seller personnel authorized for on-site access and badge sponsorship at each site? (select the option that matches current status)
Timing and constraints
- Are there fixed blackout windows, mission-critical dates, or fiscal constraints that will limit installation or testing at any site? (if yes, we'll request date ranges in the free-response field)
- Target date for first site fielding or production cutover (enter a date or 'TBD') — this locks schedule milestones and ATO dependencies.
-
Configuration Details
Lock exact configuration values, gateway interfaces, encryption profiles, operator roles, and integration endpoints the deployment will use.
Configuration Details
Configuration Snapshot — core identifiers the build will lock
- Enter the exact deployment environment name the orchestration will use (format: single token, no spaces). Default: production
- Environment type (select one). Default: Production
- Primary deployment region for this build (select one). Default: CONUS
Network & Gateway Interfaces — exact interfaces and endpoints the platform will bind to
- Primary gateway interface type that will carry platform traffic (select one)
- Primary gateway endpoint the platform will route to (enter FQDN or IPv4/IPv6 address; format: hostname.domain or 10.0.0.1)
- Network segmentation / enclave type this deployment will reside in (select one)
Encryption & Security — profiles and compliance flags the deployment enforces
- Data-in-transit encryption profile to lock (select one). Default: TLS1.3-AES256-GCM
- Is FIPS-140 validated cryptography required for this deployment? Default: Yes
Identity & Operator Roles — exact role and authentication source names the platform will create/use
- Primary identity provider (IdP) type for operator authentication (select one). Default: SAML-based IdP
- Primary operator role name to create in the platform (enter exact identifier; example: OPERATOR_VIEWER). This exact string will be used in role mappings.
-
Deployment Execution
Execute systems integration, factory acceptance, site installation, operational testing, and schedule milestones with named owners and escalation paths.
-
Go-Live Acceptance
Formal acceptance gate to verify functional tests, cybersecurity accreditation evidence, and operational readiness signatures before declaring fielding complete.
Checklist items
- Receive signed functional test acceptance
- Verify integration and regression test artifacts are complete
- Obtain formal cybersecurity authorization evidence
- Confirm POA&M and risk-acceptance for outstanding findings
- Validate rollback and recovery plan execution
- Obtain per-deployment-site operational readiness sign-off
- Verify site safety and energization clearance
- Receive final programmatic acceptance sign-off
- Handover operations runbook, monitoring, and escalation artifacts
- Confirm operator training and competency attestations
- Issue go-live acceptance certificate and archive evidence
-
-
Sustainment & Success
Monitor mission outcomes, track issues and enhancement requests, and run recurring reviews to ensure operational performance and accreditation continuity.
Success Reviews
- Go-Live Health Check (Week 1-4)
- First Measurement Review (Week 4-10)
- 90-Day Sustainment Ratification and Accreditation Continuity (Day ~90)
- Quarterly Operational Review
- Annual Mission Outcomes Review
Issues & Enhancements
- Publish the prioritized backlog with target delivery windows and test criteria for each item retained for implementation.
- Close or create remediation tickets for all outstanding critical accreditation findings with target completion dates.
- Schedule the quarterly operational review dates for the next 12 months.
- Verify accreditation artifacts remain current and schedule any required evidence refreshes.
- Trend review for uptime and operator proficiency
- Confirm system uptime on the accredited enclave and operator proficiency rate meet sustainment thresholds or have remediation plans in place.
- Agree priority and resolution timeline for the top persistent issues and backlog items affecting mission outcomes.
- Re-confirm success criteria and owner map
- Create resolution plans for the top 5 persistent issues with measurable success criteria.
- Schedule accreditation artifact refresh tasks aligned to the documented evidence cadence.
- Year-to-date mission outcomes
- Confirm whether the platform met its year-one mission targets for mission task completion rate and mean sensor-to-decision latency as recorded in Solution Evaluation.
- Document accreditation continuity over the year and identify any major audit exposures requiring action.
- Agree a set of operational adjustments and test schedules to be executed in the next 12 months.
- Publish the annual outcomes report including metric trends, accreditation summary, and the agreed operational adjustments.
- Open implementation tasks for agreed operational adjustments with completion targets for the next quarter.
- Compile a consolidated list of enhancements resolved in the past 12 months and lessons learned for program records.
- Deployment deliverables validated against the artifacts recorded in Solution Evaluation and any critical gaps identified.
- Incumbent system wind-down posture confirmed (decommission or retain-read-only) and data migration/archive status documented.
- Immediate remediation actions and owners recorded with target dates for next check-in.
- Publish the deployment validation summary and incumbent wind-down checklist for asynchronous confirmation.
- Create and prioritize remediation tickets for all high-severity blockers with resolution target dates.
- Circulate operator onboarding issues and schedule targeted training or configuration adjustments as required.
- Present first-period outcomes vs targets
- Confirm whether the measured data fusion correlation accuracy rate and mean sensor-to-decision latency meet the targets recorded in Solution Evaluation or require remediation.
- Agree a concrete remediation plan with target dates to close the top 3 measured gaps.
- Ensure open accreditation findings count is reduced or has committed resolution dates that preserve ATO continuity.
- Produce a remediation task list for each failed metric with specific technical actions and completion dates.
- Deliver updated telemetry dashboards that isolate the root-cause indicators for each metric shortfall.
- Publish a time-boxed plan to resolve open accreditation findings with referenced evidence artifacts.
- Restate sustainment and accreditation criteria
- Sustainment plan and accreditation continuity approach formally ratified for ongoing operations without re-running the deployment acceptance decision.
- All critical accreditation or operational blockers are closed or assigned with committed resolution dates.
- A named sustainment review cadence is established for the next 12 months.
- Publish the ratified sustainment plan and accreditation evidence schedule with the ratification record.
- Deployment and migration validation
- Persistent issues and ticket burn-down
- Accreditation continuity and audit summary
- Present 90-day operational and security metrics
- Root cause diagnosis for gaps
- Accreditation and security findings review
- Enhancement requests and backlog hygiene
- Close or reassign critical remediations
- Open enhancements resolved and outstanding
- Early adoption and usage signals
- Incumbent system wind-down status
- Lessons learned and operational adjustments
- Accreditation evidence currency check
- Agree corrective actions and schedule
- Sustainment plan ratification and sign-off ceremony
- Blockers and immediate remediation plan