Secure Networks
Multi-agency, multi-stakeholder programs where procurement, compliance, and mission alignment determine success.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Pre-Sales
Qualify and diagnose before committing to technical evaluation.
-
Qualification
Confirm budget window, decision authority, timeline, and high-level mission constraints before investing in a full technical evaluation.
Qualification Questions
Mission fit & compliance snapshot
- Which of the following apply to this opportunity? (select all that apply)
- In one or two sentences, what mission outcome must this capability enable and what non negotiable constraint should we know up front?
Budget window
- Is there an allocated budget for this modernization effort? Please select the best range.
Decision authority & stakeholders
- Who has final decision authority for vendor selection and accreditation acceptance?
- Who else should we engage early (list roles or offices, e.g., cybersecurity lead, COMSEC custodian, facilities)?
Timeline & readiness risks
- What is your target live date or the driving deadline for this work?
- What are the top schedule or accreditation risks we should know about (equipment lead times, clearance bottlenecks, authorizing official availability, etc.)?
-
Outcome & Stakeholder Discovery
Map mission objectives, affected enclaves, stakeholders, current topology, and accreditation expectations.
Discovery Questions
Quick context so we start on the same page
- How urgent is this modernization on your timeline?
- When did your team first identify the capability gap that triggered this effort?
- Which mission applications require classified connectivity on day one of deployment?
- Who will be the final authorizing official or signatory for accreditation acceptance in your organization?
- Describe the worst operational impact if connectivity misses your target window.
- Could you prioritize a single enclave for first delivery, and would failing to deliver that enclave stop the program?
When timeline slips, who feels it first
- If your target window slips by 60 days, what operational capability would be most at risk?
- List the concrete mission losses or program delays that would follow a 60-day slip.
- How many users or endpoints operate in each affected classification enclave at peak?
- Who is the first stakeholder your team will escalate to when mission impacts appear?
- What single failure, accreditation rejection, missing COMSEC installation, or equipment lead time, would make you stop the project immediately?
Who sits at the table and what do they need
- Name the stakeholder who can veto accreditation results, and describe what would make them say no.
- Which groups need operational connectivity during the cutover window, and which must be fully validated before cutover?
- To whom does your accreditation office report, and how often do they convene to review milestones?
- Explain how your network engineering branch schedules cleared personnel for COMSEC and Type 1 installations.
- If one stakeholder says no to the proposed accreditation boundary, what immediate change could salvage the program within a week?
What the network looks like under the hood
- Where in your current topology do you routinely see cross-domain handoffs that risk data spillage?
- Describe the encryption device categories and hosting model currently used at each enclave.
- List the key protocols or cross-domain transfer mechanisms that must remain supported during and after migration.
- Estimate peak and sustained bandwidth in Mbps or concurrent flows that must be preserved between enclaves during missions.
- What single integration dependency, such as an API, legacy gateway, or classified circuit, would force a redesign if not available?
Accreditation, acceptance, and evidence
- Rate your confidence that current RMF artifacts will pass the authorizing official's first review.
- Tell me which RMF deliverables you already have and which require creation or update.
- Identify who owns COMSEC provisioning and Type 1 installation scheduling in your organization.
- When do you plan to submit the initial accreditation package relative to procurement and staging?
- Name the accreditation criterion that, if unmet, would force a program stop.
What's getting in the way right now
- Identify the biggest assumption in your plan that is most likely to be wrong.
- Share an example of a recent installation or accreditation review that required rework, what failed, and why.
- Have you experienced vendor engineering resource shortages on recent projects, and what was the downstream schedule impact?
- Estimate the probability that equipment lead times will exceed your procurement window.
- Would a missing cleared site access window force you to delay cutover, and by how long?
The other paths on your table
- Specify the alternatives you are actively vetting and the primary claim each makes.
- For any incumbent or internal option, what would have to be true for you to stay with them instead of changing?
- Has anyone internally proposed solving this without an outside vendor or partner?
- Explain the single advantage the incumbent or another vendor claims that you find credible.
- Would a successful in-house pilot eliminate the need for an outside integrator, and on what timeline?
What must be true before we schedule work
- Pinpoint the single operational constraint that must be resolved before installation can begin.
- Do you have confirmed cleared personnel for Type 1 crypto installation, and how many full time equivalents are allocated?
- Are the physical sites ready for classified equipment installation, including power, rack space, and environmental controls?
- Provide the external systems or third party networks that must be integrated and identify who owns them.
- Could regulatory reviews, legal opinions, or contracting actions realistically extend your timeline past the accreditation deadline?
What success looks like and the next decision points
- Assuming a pilot validates the design, what decision or procurement milestone would allow you to authorize full deployment within seven days?
- Tell me the measurable acceptance criteria the authorizing official will require for go or no go.
- Provide the names and contact points your team will use for cutover authorization and operational escalation.
- Is there a contractual or funding milestone that must be met before you can accept delivery, and what is it?
- Within what timeframe can your team commit to a staged test window for interoperability?
-
-
Technical Evaluation
Validate proposed architecture and interoperability against the buyer's acceptance criteria, including COMSEC handling, cross-domain behaviors, and accreditation evidence.
- desired_state
- current_state
- stakeholders
- gaps
- success_criteria
- decision_readiness
- desired_state
- decision_readiness
- current_state
- success_criteria
- gaps
- stakeholders
- desired_state
- success_criteria
- stakeholders
- gaps
- current_state
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
-
Solution Scope
Define deliverables, accreditation boundaries, responsibilities, equipment staging, and measurable acceptance criteria for architecture, installation, and RMF artifacts.
Scope Configuration
- Procure and Stage Classified Encryption Hardware
- Install and Key Type 1 Cryptographic Devices
- Deploy Cross-Domain Transfer System
- Provision Accredited Key Management Infrastructure
- Configure Multi-Level Network Segmentation and Routing
- Install Classified-Grade Fiber and Switching
- Perform Enclave-to-Enclave Interoperability Testing
- Remediate Encryption Protocol Interoperability Issues
- Manage COMSEC Material and Key Custody
- Deliver RMF Accreditation Artifacts and Evidence Package
- Migrate Classified Services and Cutover
- Decommission Legacy Classified Equipment and Wipe Data
- Provide Cleared Engineers for Onsite Installation
- Operate and Sustain Classified Network Services
Scope Questions
Procure and Stage Classified Encryption Hardware
- Do you have an approved contract vehicle and procurement point of contact for receipt of classified encryption hardware?
- How many encryption chassis and spare units are listed on your bill of materials (BOM) and single-line diagram (SLD)?
- Which staging location will be used for COMSEC handling and zeroizing prior to deployment (for example on-site vault, government staging facility, contractor cleared staging facility)?
- What is the expected procurement lead time for classified hardware against the procurement schedule in weeks as documented in your acquisition timeline?
- Provide the required facility clearance level and Site Access Request (SAR) instructions that delivery and staging agents must meet.
- Will you require chain of custody and Defense Courier Service (DCS) pickup management for sealed COMSEC shipments?
Install and Key Type 1 Cryptographic Devices
- Which cleared personnel and COMSEC account number will act as the local key custodian during Type 1 device installation?
- What is the installation site room identifier and electrical feed one-line that supports Type 1 device power and redundant circuits as shown on the site floorplan?
- Which Type 1 keying plan or keying schedule will be used for initial crypto material injection and documented in the keying checklist?
- What acceptance criteria will confirm Type 1 cryptographic devices are installed, keyed, and operational according to the Type 1 keying plan and the site COMSEC SOP?
- Identify the zeroize and tamper-evidence procedures and the required test cases that must be executed post-installation and captured in the installation checklist.
- Do you require on-site Type 1 key injection by the seller or will a government keying team perform final keying?
Deploy Cross-Domain Transfer System
- Which enclaves and security domains (include classification levels and enclave IDs) will be connected by the cross-domain transfer system as shown in your topology diagram?
- What approved cross-domain policy document or configuration baseline will govern data flows and allowable transfer rules?
- How will you verify cross-domain data flows satisfy approved cross-domain policy during interoperability testing and which cross-domain test cases must pass for acceptance?
- Do you require a cross-domain guard (CDG) configuration audit and a signed Configuration Management Board (CMB) record before cutover?
- Specify the logging and audit retention period for cross-domain transfer records and the SIEM (security information and event management) export endpoint referenced in the integration diagram.
- Are there mandatory accreditation controls or cross-domain accreditation checklists from the authorizing official that the deployment must satisfy?
Provision Accredited Key Management Infrastructure
- What existing Key Management Infrastructure (KMI) entries, certificate authorities, or Hardware Security Module (HSM) serial numbers must be integrated as recorded in your KMI configuration registry?
- Which KMIP (Key Management Interoperability Protocol) endpoints or KMI API endpoints are listed in your integration endpoint inventory for automated key pulls?
- Specify the accreditation level and FedRAMP or agency-specific KMI controls that the KMI must meet as documented in your RMF System Security Plan (SSP).
- Do you require HSM hardware custody transfer procedures and an assets register entry during provisioning?
- Which party will own ongoing key rotation schedules and where should rotation cadence be recorded (for example in the key management SOP or change control log)?
- List the encryption key lifecycles and key sizes required by your accreditation constraints and the RMF control set.
Configure Multi-Level Network Segmentation and Routing
- Which RFC1918 or routed IP address ranges and VLAN IDs per enclave are documented in your network addressing plan and must be implemented?
- What routing protocol and adjacency requirements shown on the topology diagram must be preserved during integration (for example OSPF areas, BGP ASNs, static routes)?
- Which DISA Security Technical Implementation Guide (STIG) checklists or agency hardening baselines must be applied to switching and routing devices per the RMF SSP?
- Do you require microsegmentation policies and an approved policy table documenting allowed east-west flows between enclaves?
- Provide the change control window and blackout periods from your maintenance calendar when routing updates and segmentation changes may occur.
- Which monitoring metrics and NetFlow export endpoints must be configured to validate segmentation and routing per the operations runbook?
Install Classified-Grade Fiber and Switching
- What as-built fiber routes and fiber connector counts are recorded on the fiber as-built drawings that installers must follow?
- Which fiber testing acceptance thresholds documented in the OTDR (optical time-domain reflectometer) report must be met on handover?
- Which switch port mapping spreadsheet or patch panel labeling standard must be used for cabling and rack assignments?
- Do you require bonded grounding and TEMPEST shielding procedures per the facility electrical one-line and facility compliance worksheet?
- Provide the rack elevations, U positions, and power circuit IDs from the rack elevation drawings that installers must follow.
- Are there site restrictions for daytime installation, lockout/tagout (LOTO) steps, or security escort requirements recorded in the Site Access Request (SAR)?
Perform Enclave-to-Enclave Interoperability Testing
- Which interoperability test cases from your interoperability test plan (ITP) must be executed between enclaves, and which test cases are high priority?
- What functional test data sets and sample messages are authorized for cross-enclave testing as recorded in your test data handling SOP?
- Which performance thresholds documented in the service level objectives (for example latency and throughput between enclaves in ms and Mbps) must be met during testing?
- Who will approve the Interoperability Test Results Report and which authorizing official or test official is listed on the test plan?
- Provide the lab or staging harness inventory and simulation endpoints to be used for repeatable interoperability runs.
- Do you require do-not-ship or isolation procedures for test artifacts after interoperability to avoid accidental cross-contamination of enclaves?
Remediate Encryption Protocol Interoperability Issues
- Which encryption protocols and cipher suites are documented in your protocol inventory and must be supported or disabled during remediation?
- What integration logs and packet captures from the failing scenarios in the interoperability test report should be provided to the remediation team?
- Which RMF control failures in the test results require remediation before the POA&M (plan of actions and milestones) can be closed?
- Identify the maximum allowable time to remediate a critical protocol interoperability issue in calendar days to be captured in the POA&M.
- Do you want remediation to include firmware or configuration rollbacks documented in the change control record?
- Provide the escalation path and contact list for unresolved protocol interoperability defects referenced in the defect tracking ticket template.
Manage COMSEC Material and Key Custody
- Who is listed in your COMSEC account as the accountable official and local COMSEC custodian per the COMSEC account record?
- Which COMSEC handling SOP and accountable forms must be used during key receipt and inventory (for example DA Form equivalent or agency inventory sheet)?
- Will you accept the seller maintaining the COMSEC inventory ledger and providing monthly reconciliations, or will you retain ledger custody?
- Specify the storage vault requirements, container types, and accountability chain for zeroizable key material as referenced in your COMSEC vault spec.
- Are emergency zeroize procedures and emergency contact numbers recorded in your COMSEC contingency plan available to installers on-site?
- Provide the schedule for periodic COMSEC reconciliations and the required reconciliation evidence type (signed inventory sheet, photograph, electronic ledger export).
Deliver RMF Accreditation Artifacts and Evidence Package
- Which Risk Management Framework (RMF) artifacts do you require delivered in the accreditation package (for example System Security Plan (SSP), Control Implementation Summary, test result appendices, POA&M)?
- What acceptance criteria and evidence will validate that the RMF artifacts meet the authorizing official's requirements for an Authority to Operate (ATO)?
- Which version of the STIG checklists and baseline scans must be included as evidence with the accreditation package?
- Do you require a redacted copy of evidence for external reviewers and if so which artifacts must be redacted per your classification handling rules?
- Provide the authorizing official contact and required delivery format for the accreditation package (for example signed PDFs, electronic repository upload, thumb drive with COMSEC controls).
Migrate Classified Services and Cutover
- Which classified services (for example authentication services, file shares, voice/crypto endpoints) are in-scope for migration and are listed on the migration inventory spreadsheet?
-
Mutual Commit
Finalize commercial and governance terms, procurement timelines, COMSEC responsibilities, and explicit acceptance criteria tied to accreditation milestones.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Pricing & Payment Schedule
- Purchase Order — Equipment & Materials
- COMSEC Custody & Handling Agreement
- Accreditation Acceptance Criteria & Milestone Schedule
- Governance & Escalation Matrix
- Change Order Agreement
- Termination & Exit Plan
- Procurement & Accreditation Compliance Addendum
-
Deployment
Operationalize rollout with readiness checks, execution, and accreditation validation prior to cutover.
-
Pre-Deployment Readiness
Confirm concrete readiness facts the deployment depends on — site access, cleared personnel, key dates, and accreditation points of contact.
Pre-Deployment Questions
Environment and site access
- List each deployment site and the earliest date the seller will have escorted physical access (site name — earliest access date).
- Production enclave access status (so we can schedule COMSEC installation and cutover):
- Staging space readiness for equipment and cryptographic handling at each site (secured storage and handling procedures in place?):
Data and configuration
- Has the final network topology and accreditation boundary been frozen for deployment? (If yes, we will reference the freeze date in DeploymentConfig.)
- Equipment staging inventory status (so we can confirm kits and avoid procurement delays):
- Cross-domain interfaces and external integration endpoints declared and approved for connection (this determines required interoperability tests):
People and ownership
- Primary on-site deployment lead (name and role) and whether they are cleared to handle COMSEC/custody transfer — provide name and role only.
- Has an Authorizing Official (AO) or designated accrediting official been assigned and committed to review accreditation artifacts during go/no-go?
- Status of cleared technical staff for installation and Type 1 cryptographic actions (who will perform on-site cryptographic work?):
Timing and constraints
- Confirmed target installation start date or earliest possible start date (we will use this to build the deployment timeline):
- Facility blackout windows, mission constraints, travel restrictions, or holiday periods that will block installation at any site (if none, select No blackout windows):
- Outstanding compliance or accreditation gates that must be closed prior to installation (select all that apply):
-
Configuration Details
Capture exact configuration values, cryptographic provisioning requirements, integration endpoints, and staging inventories the deployment team will use.
Configuration Details
Environments & instance names
- Enter the production environment identifier (format: short lowercase alphanumeric, no spaces; default: prod)
Network & addressing (values consumed by device staging)
- Enter the production management VLAN ID for device staging (numeric; default: 4094)
Cryptographic provisioning (exact parameters for keying and custody)
- Select the cryptographic provisioning method the deployment will use (select one)
- Enter the non-secret key identifier/label devices will reference for keying (format: alphanumeric label; do not paste keys)
- Enter the credential owner name who will be the point of contact for keying and integration artifacts (format: Last, First; Organization)
- Select the secure channel that will be used to exchange secrets or key material (the secret itself will not be collected in this form)
Integration endpoints & staging inventory
- Select your identity provider type for device admin authentication (select one)
- Enter the fully-qualified NTP server hostname devices should use (format: ntp.example.mil)
- Number of encryption appliances to stage for initial deployment (numeric)
-
Deployment Execution
Plan and execute installation, Type 1 cryptographic installation, interoperability testing, and RMF artifacts with clear owners and escalation paths.
-
Go‑Live Accreditation Acceptance
Formal go/no-go gate: verify accreditation artifacts, authorizing official sign-off, cross‑domain test results, and operational readiness before cutover.
Checklist items
- Authorizing official written sign-off received for go/no‑go
- Accreditation artifacts package uploaded to shared repository
- Risk acceptance / POA&M acknowledgement obtained
- Cross‑domain interoperability test report accepted
- COMSEC key custody transfer and Type‑1 crypto installation verification completed
- Operational readiness checklist completed and signed
- Rollback plan documented and restore point verified
- Facility Permission to Operate or equivalent authorization received for each affected site
- Cleared personnel and site access confirmed for cutover window
- Final cutover schedule and change authorization signed
- Escalation and incident response contacts acknowledged by parties
-
-
Sustainment & Mission Assurance
Establish recurring success cadence, track RMF maintenance, COMSEC sustainment, and a shared channel for issues and enhancement requests.
Success Reviews
- Go-live Health Check
- First Operational Measurement
- Acceptance Gate - Accreditation Decision
- Quarterly Sustainment Review
- Annual Mission Assurance and RMF Maintenance Review
Issues & Enhancements
- Schedule required COMSEC key rotation or provisioning activities and log completion artifacts.
- Achieve a documented acceptance decision (accept or accept with conditions) recorded against the Solution Scope criteria and signed by the named authorizing official.
- For any condition or failure, finalize a remediation plan with clear evidence requirements and resolution dates.
- Confirm the incumbent system has a decommission or retained-read-only plan with data archive status recorded.
- Publish the formal acceptance record with the named signatory and attach the outcome evidence bundle.
- If acceptance is conditional or failed, produce a remediation plan that lists each criterion, required evidence, and a retest date.
- Execute the incumbent wind-down tasks: archive data, disable active write access, and confirm fallback procedures are retired or documented.
- Trend review for core operational metrics
- Verify that classified network availability (%) remains at or above the target recorded in Solution Scope or document the remediation path if it does not.
- Reduce the count of open accreditation findings and POA&Ms by the agreed quarterly target, and track progress in the next review.
- Confirm COMSEC provisioning and key management activities meet sustainment schedules and record any exceptions.
- Update the POA&M tracker with remediation owners, completion dates, and required retest evidence.
- Re-confirm agreed success criteria and owners
- Publish the quarterly sustainment summary with metric charts and the updated issues/enhancements backlog.
- Accreditation re-certification readiness assessment
- Confirm accreditation re-certification readiness (%) meets the threshold required for the next accreditation cycle or document a remediation roadmap.
- Verify COMSEC key management compliance rate (%) aligns with mandated schedules and remediate any exceptions.
- Set a clear 12-month RMF maintenance calendar with accountable owners and evidence delivery dates.
- Produce the re-certification readiness report listing remaining artifacts, evidence owners, and target delivery dates.
- Update the annual RMF maintenance calendar and publish the quarterly checkpoint dates and required evidence packages.
- Conduct a targeted COMSEC compliance sweep for any items below the compliance threshold and document corrective actions.
- Confirm the deployment completed against the items recorded in Solution Scope and identify any deviations requiring remediation.
- Establish a time-bound remediation plan for all severity 1 and 2 issues to restore agreed operational baselines.
- Confirm monitoring sources and evidence locations for subsequent measurement meetings.
- Publish the cutover validation summary and store evidence artifacts where the project workspace tracks Solution Scope items.
- Produce a remediation plan for all severity 1-2 issues with deadlines and required inputs for resolution.
- Enable access to monitoring feeds and confirm the telemetry collection schedule for the first measurement window.
- Present first data against Solution Scope targets
- Determine whether classified network availability (%) and accreditation findings open count are moving toward the Solution Scope targets and document the gap magnitude.
- Agree a set of corrective actions with resolution dates to bring metrics into compliance by the acceptance gate.
- Identify any external dependencies that threaten the acceptance timeline and record mitigation steps.
- Deliver a remediation and retest schedule for each metric that misses its target, including required evidence types for verification.
- Open tracked tickets for each accreditation finding and assign an expected close date to each ticket.
- Validate that COMSEC provisioning logs show successful cryptographic loading for all Type 1 devices requiring provisioning.
- Restate acceptance criteria from Solution Scope
- RMF maintenance and artifact currency review
- POA&M and accreditation findings burn-down
- Present outcome data against each criterion with evidence
- Diagnose root causes for any gaps
- Deployment and migration validation
- COMSEC inventory and compliance audit
- COMSEC sustainment and key management status
- Agree corrective actions and timelines
- Document pass/fail per criterion and capture signatory decision
- User onboarding and access validation
- Confirm readiness timeline to the acceptance gate
- Year-in-review incidents and lessons learned
- Agree remediation items and resolution timeline
- Early monitoring signals and telemetry review
- Issue channel and enhancement request review
- Agree annual sustainment calendar and checkpoints
- Blockers and open issues triage
- Incumbent system wind-down confirmation
- Agree operational adjustments and next quarter targets
- Agree immediate remediation actions