Health, Education & Government Government & Public Sector Defense Systems & Programs

Secure Networks

Multi-agency, multi-stakeholder programs where procurement, compliance, and mission alignment determine success.

Example organizations in this space: General Dynamics IT SAIC Leidos BAE Systems

This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.

Inside this journey
  1. Pre-Sales

    Qualify and diagnose before committing to technical evaluation.

    1. Qualification

      Confirm budget window, decision authority, timeline, and high-level mission constraints before investing in a full technical evaluation.

      Qualification Questions

      Mission fit & compliance snapshot

      • Which of the following apply to this opportunity? (select all that apply) Options: No classified or COMSEC work, Sensitive but Unclassified only (SBU), Classified enclave required (Secret/Top Secret), COMSEC or Type 1 cryptographic handling required, Cross‑domain transfers required between enclaves, Accreditation required (RMF/ATO) as part of the program, Unsure — need to confirm
      • In one or two sentences, what mission outcome must this capability enable and what non negotiable constraint should we know up front?

      Budget window

      • Is there an allocated budget for this modernization effort? Please select the best range. Options: No allocated budget yet, Under $500,000, $500,000 to $2,000,000, $2,000,000 to $5,000,000, $5,000,000 to $20,000,000, Over $20,000,000 (above typical scope), Prefer not to say

      Decision authority & stakeholders

      • Who has final decision authority for vendor selection and accreditation acceptance? Options: Director level or Authorizing Official (single executive), Program Manager with director sign off, Procurement/Contracting office holds final approval, Multiple stakeholders must sign off (cross functional), Unsure / need to confirm
      • Who else should we engage early (list roles or offices, e.g., cybersecurity lead, COMSEC custodian, facilities)?

      Timeline & readiness risks

      • What is your target live date or the driving deadline for this work? Options: Within 4 weeks, 1 to 3 months, 3 to 6 months, 6 to 12 months, No firm date / exploratory
      • What are the top schedule or accreditation risks we should know about (equipment lead times, clearance bottlenecks, authorizing official availability, etc.)?
    2. Outcome & Stakeholder Discovery

      Map mission objectives, affected enclaves, stakeholders, current topology, and accreditation expectations.

      Discovery Questions

      Quick context so we start on the same page

      • How urgent is this modernization on your timeline? Options: Less than 3 months, 3 to 6 months, 6 to 12 months, More than 12 months, No firm deadline yet
      • When did your team first identify the capability gap that triggered this effort? Options: Within the last month, 1 to 3 months ago, 3 to 6 months ago, More than 6 months ago, Still being defined
      • Which mission applications require classified connectivity on day one of deployment? Options: Intelligence dissemination, Video teleconference / VTC, Sensor and ISR feeds, Command and control, Logistics and sustainment systems, Other
      • Who will be the final authorizing official or signatory for accreditation acceptance in your organization? Options: Authorizing Official (AO), Designated Accreditation Official, Director of Enterprise Services / CIO, Program Manager, Not yet identified
      • Describe the worst operational impact if connectivity misses your target window.
      • Could you prioritize a single enclave for first delivery, and would failing to deliver that enclave stop the program? Options: Yes, one enclave is critical and failure stops program, Yes, one enclave is preferred but not program-stopping, No, no single enclave is critical, Undecided

      When timeline slips, who feels it first

      • If your target window slips by 60 days, what operational capability would be most at risk? Options: Real-time intelligence sharing, Operational VTC, Sensor data ingestion, Mission command availability, Other
      • List the concrete mission losses or program delays that would follow a 60-day slip.
      • How many users or endpoints operate in each affected classification enclave at peak? Options: Fewer than 100, 100 to 499, 500 to 2,000, More than 2,000, Unknown / variable
      • Who is the first stakeholder your team will escalate to when mission impacts appear? Options: Program Manager, Director of Enterprise Services / CIO, J6/G6 communications officer, Network Engineering Branch Chief, Other
      • What single failure, accreditation rejection, missing COMSEC installation, or equipment lead time, would make you stop the project immediately? Options: Accreditation rejection by AO, No cleared personnel for COMSEC tasks, Equipment lead-time exceeds window, Funding or contract milestone failure, Other

      Who sits at the table and what do they need

      • Name the stakeholder who can veto accreditation results, and describe what would make them say no.
      • Which groups need operational connectivity during the cutover window, and which must be fully validated before cutover? Options: Mission operations, INTEL consumers, Admin and logging, Partner enclave bridges, Other
      • To whom does your accreditation office report, and how often do they convene to review milestones? Options: Weekly, Biweekly, Monthly, Ad hoc, Not yet scheduled
      • Explain how your network engineering branch schedules cleared personnel for COMSEC and Type 1 installations.
      • If one stakeholder says no to the proposed accreditation boundary, what immediate change could salvage the program within a week? Options: Reduce scope to single enclave, Staged acceptance by enclave, Temporary compensating control, Escalate to AO for exception, Other

      What the network looks like under the hood

      • Where in your current topology do you routinely see cross-domain handoffs that risk data spillage? Options: Cross-domain guard between enclaves, Gateway services for partners, Border routing nodes, Legacy mediation appliances, Not sure / need review
      • Describe the encryption device categories and hosting model currently used at each enclave.
      • List the key protocols or cross-domain transfer mechanisms that must remain supported during and after migration.
      • Estimate peak and sustained bandwidth in Mbps or concurrent flows that must be preserved between enclaves during missions. Options: Less than 100 Mbps, 100 to 500 Mbps, 500 Mbps to 2 Gbps, More than 2 Gbps, Unknown / requires measurement
      • What single integration dependency, such as an API, legacy gateway, or classified circuit, would force a redesign if not available? Options: Legacy cross-domain gateway, Classified trunk circuit, External partner API, Key certificate / KMI access, Other

      Accreditation, acceptance, and evidence

      • Rate your confidence that current RMF artifacts will pass the authorizing official's first review. Options: 5, very confident, 4, mostly confident, 3, uncertain, 2, unlikely, 1, not confident at all
      • Tell me which RMF deliverables you already have and which require creation or update. Options: System Security Plan (SSP), Plan of Actions and Milestones (POA&M), Risk Assessment, Interconnection Security Agreement, Continuous Monitoring Strategy, Other
      • Identify who owns COMSEC provisioning and Type 1 installation scheduling in your organization. Options: COMSEC office, Program manager, Network engineering branch, Contracting officer representative, Not assigned
      • When do you plan to submit the initial accreditation package relative to procurement and staging? Options: Before procurement, During staging, After installation, Not yet planned
      • Name the accreditation criterion that, if unmet, would force a program stop. Options: AO rejects residual risk, COMSEC handling not certified, Unresolved cross-domain spill risk, Type 1 crypto not installed, Other

      What's getting in the way right now

      • Identify the biggest assumption in your plan that is most likely to be wrong.
      • Share an example of a recent installation or accreditation review that required rework, what failed, and why.
      • Have you experienced vendor engineering resource shortages on recent projects, and what was the downstream schedule impact? Options: Yes, major impact, Yes, moderate impact, Minor impact, No shortages experienced, Unknown
      • Estimate the probability that equipment lead times will exceed your procurement window. Options: Less than 10 percent, 10 to 30 percent, 30 to 60 percent, More than 60 percent, Unknown
      • Would a missing cleared site access window force you to delay cutover, and by how long? Options: Yes, delay by 1 to 2 months, Yes, delay by 2 to 4 months, Yes, longer than 4 months, No, we can work around it, Unsure

      The other paths on your table

      • Specify the alternatives you are actively vetting and the primary claim each makes. Options: Incumbent contractor, Internal delivery by staff, Prime integrator lacking COMSEC capability, Do nothing / delay, Other vendor or integrator
      • For any incumbent or internal option, what would have to be true for you to stay with them instead of changing?
      • Has anyone internally proposed solving this without an outside vendor or partner? Options: Yes, fully internal, Yes, with minimal contractor support, No internal proposal, Under discussion
      • Explain the single advantage the incumbent or another vendor claims that you find credible.
      • Would a successful in-house pilot eliminate the need for an outside integrator, and on what timeline? Options: Yes, within 3 months, Yes, within 3 to 6 months, Not likely, Unsure

      What must be true before we schedule work

      • Pinpoint the single operational constraint that must be resolved before installation can begin.
      • Do you have confirmed cleared personnel for Type 1 crypto installation, and how many full time equivalents are allocated? Options: Yes, dedicated FTEs available, Yes, available but schedule constrained, No, must be provided by contractor, Unknown
      • Are the physical sites ready for classified equipment installation, including power, rack space, and environmental controls? Options: Fully ready, Mostly ready with minor tasks, Major site work required, Unknown
      • Provide the external systems or third party networks that must be integrated and identify who owns them.
      • Could regulatory reviews, legal opinions, or contracting actions realistically extend your timeline past the accreditation deadline? Options: Yes, likely, Possible but manageable, No, cleared, Unsure

      What success looks like and the next decision points

      • Assuming a pilot validates the design, what decision or procurement milestone would allow you to authorize full deployment within seven days?
      • Tell me the measurable acceptance criteria the authorizing official will require for go or no go. Options: No data spill observed in cross domain tests, Signed accreditation artifacts from AO, COMSEC installed and validated, Interoperability tests passed for all enclaves, Other
      • Provide the names and contact points your team will use for cutover authorization and operational escalation.
      • Is there a contractual or funding milestone that must be met before you can accept delivery, and what is it? Options: Specific funding obligation date, Contract option exercised, Letter of Authorization from AO, No single milestone, Other
      • Within what timeframe can your team commit to a staged test window for interoperability? Options: Within 2 weeks, 2 to 4 weeks, 1 to 2 months, More than 2 months, Not ready to schedule
  2. Technical Evaluation

    Validate proposed architecture and interoperability against the buyer's acceptance criteria, including COMSEC handling, cross-domain behaviors, and accreditation evidence.

    • desired_state
    • current_state
    • stakeholders
    • gaps
    • success_criteria
    • decision_readiness
    • desired_state
    • decision_readiness
    • current_state
    • success_criteria
    • gaps
    • stakeholders
    • desired_state
    • success_criteria
    • stakeholders
    • gaps
    • current_state
    • decision_readiness
    • decision_readiness
    • decision_readiness
    • decision_readiness
    • decision_readiness
  3. Solution Scope

    Define deliverables, accreditation boundaries, responsibilities, equipment staging, and measurable acceptance criteria for architecture, installation, and RMF artifacts.

    Scope Configuration

    • Procure and Stage Classified Encryption Hardware
    • Install and Key Type 1 Cryptographic Devices
    • Deploy Cross-Domain Transfer System
    • Provision Accredited Key Management Infrastructure
    • Configure Multi-Level Network Segmentation and Routing
    • Install Classified-Grade Fiber and Switching
    • Perform Enclave-to-Enclave Interoperability Testing
    • Remediate Encryption Protocol Interoperability Issues
    • Manage COMSEC Material and Key Custody
    • Deliver RMF Accreditation Artifacts and Evidence Package
    • Migrate Classified Services and Cutover
    • Decommission Legacy Classified Equipment and Wipe Data
    • Provide Cleared Engineers for Onsite Installation
    • Operate and Sustain Classified Network Services

    Scope Questions

    Procure and Stage Classified Encryption Hardware

    • Do you have an approved contract vehicle and procurement point of contact for receipt of classified encryption hardware? Options: Yes, No
    • How many encryption chassis and spare units are listed on your bill of materials (BOM) and single-line diagram (SLD)? Options: 1-2, 3-5, 6-10, More than 10
    • Which staging location will be used for COMSEC handling and zeroizing prior to deployment (for example on-site vault, government staging facility, contractor cleared staging facility)? Options: On-site secured room, Government staging facility, Contractor cleared staging facility, Other
    • What is the expected procurement lead time for classified hardware against the procurement schedule in weeks as documented in your acquisition timeline? Options: Less than 4 weeks, 4-8 weeks, More than 8 weeks
    • Provide the required facility clearance level and Site Access Request (SAR) instructions that delivery and staging agents must meet.
    • Will you require chain of custody and Defense Courier Service (DCS) pickup management for sealed COMSEC shipments? Options: Yes, No

    Install and Key Type 1 Cryptographic Devices

    • Which cleared personnel and COMSEC account number will act as the local key custodian during Type 1 device installation?
    • What is the installation site room identifier and electrical feed one-line that supports Type 1 device power and redundant circuits as shown on the site floorplan?
    • Which Type 1 keying plan or keying schedule will be used for initial crypto material injection and documented in the keying checklist? Options: Government-provided keying schedule, Customer keying schedule to be provided, Use seller keying schedule under KMI plan
    • What acceptance criteria will confirm Type 1 cryptographic devices are installed, keyed, and operational according to the Type 1 keying plan and the site COMSEC SOP?
    • Identify the zeroize and tamper-evidence procedures and the required test cases that must be executed post-installation and captured in the installation checklist.
    • Do you require on-site Type 1 key injection by the seller or will a government keying team perform final keying? Options: Seller performs injection, Government performs injection, Hybrid (seller staging, government final)

    Deploy Cross-Domain Transfer System

    • Which enclaves and security domains (include classification levels and enclave IDs) will be connected by the cross-domain transfer system as shown in your topology diagram?
    • What approved cross-domain policy document or configuration baseline will govern data flows and allowable transfer rules? Options: Customer cross-domain policy provided, Use seller recommended policy baseline, Need joint development of policy
    • How will you verify cross-domain data flows satisfy approved cross-domain policy during interoperability testing and which cross-domain test cases must pass for acceptance?
    • Do you require a cross-domain guard (CDG) configuration audit and a signed Configuration Management Board (CMB) record before cutover? Options: Yes, No
    • Specify the logging and audit retention period for cross-domain transfer records and the SIEM (security information and event management) export endpoint referenced in the integration diagram. Options: 90 days, 180 days, 365 days, Custom retention
    • Are there mandatory accreditation controls or cross-domain accreditation checklists from the authorizing official that the deployment must satisfy? Options: Yes, provided, Yes, to be provided, No

    Provision Accredited Key Management Infrastructure

    • What existing Key Management Infrastructure (KMI) entries, certificate authorities, or Hardware Security Module (HSM) serial numbers must be integrated as recorded in your KMI configuration registry?
    • Which KMIP (Key Management Interoperability Protocol) endpoints or KMI API endpoints are listed in your integration endpoint inventory for automated key pulls? Options: KMIP endpoint, Proprietary KMI API, Manual keying only
    • Specify the accreditation level and FedRAMP or agency-specific KMI controls that the KMI must meet as documented in your RMF System Security Plan (SSP).
    • Do you require HSM hardware custody transfer procedures and an assets register entry during provisioning? Options: Yes, No
    • Which party will own ongoing key rotation schedules and where should rotation cadence be recorded (for example in the key management SOP or change control log)? Options: We will own rotation schedule, You will provide rotation schedule, Shared responsibility
    • List the encryption key lifecycles and key sizes required by your accreditation constraints and the RMF control set.

    Configure Multi-Level Network Segmentation and Routing

    • Which RFC1918 or routed IP address ranges and VLAN IDs per enclave are documented in your network addressing plan and must be implemented?
    • What routing protocol and adjacency requirements shown on the topology diagram must be preserved during integration (for example OSPF areas, BGP ASNs, static routes)? Options: OSPF, BGP, Static, Other
    • Which DISA Security Technical Implementation Guide (STIG) checklists or agency hardening baselines must be applied to switching and routing devices per the RMF SSP? Options: Apply agency STIGs, Apply baseline provided by customer, Apply seller recommended STIGs
    • Do you require microsegmentation policies and an approved policy table documenting allowed east-west flows between enclaves? Options: Yes, No
    • Provide the change control window and blackout periods from your maintenance calendar when routing updates and segmentation changes may occur.
    • Which monitoring metrics and NetFlow export endpoints must be configured to validate segmentation and routing per the operations runbook?

    Install Classified-Grade Fiber and Switching

    • What as-built fiber routes and fiber connector counts are recorded on the fiber as-built drawings that installers must follow?
    • Which fiber testing acceptance thresholds documented in the OTDR (optical time-domain reflectometer) report must be met on handover? Options: Standard agency thresholds, Stricter than agency thresholds, Custom thresholds to be provided
    • Which switch port mapping spreadsheet or patch panel labeling standard must be used for cabling and rack assignments?
    • Do you require bonded grounding and TEMPEST shielding procedures per the facility electrical one-line and facility compliance worksheet? Options: Yes, No
    • Provide the rack elevations, U positions, and power circuit IDs from the rack elevation drawings that installers must follow.
    • Are there site restrictions for daytime installation, lockout/tagout (LOTO) steps, or security escort requirements recorded in the Site Access Request (SAR)? Options: Yes, No

    Perform Enclave-to-Enclave Interoperability Testing

    • Which interoperability test cases from your interoperability test plan (ITP) must be executed between enclaves, and which test cases are high priority?
    • What functional test data sets and sample messages are authorized for cross-enclave testing as recorded in your test data handling SOP? Options: Sanitized production data, Synthetic test data, Customer-provided sanitized sets
    • Which performance thresholds documented in the service level objectives (for example latency and throughput between enclaves in ms and Mbps) must be met during testing? Options: Latency < 50 ms, Throughput > 100 Mbps, Custom thresholds
    • Who will approve the Interoperability Test Results Report and which authorizing official or test official is listed on the test plan?
    • Provide the lab or staging harness inventory and simulation endpoints to be used for repeatable interoperability runs.
    • Do you require do-not-ship or isolation procedures for test artifacts after interoperability to avoid accidental cross-contamination of enclaves? Options: Yes, No

    Remediate Encryption Protocol Interoperability Issues

    • Which encryption protocols and cipher suites are documented in your protocol inventory and must be supported or disabled during remediation? Options: AES-GCM, Suite B, Legacy suites require remediation, Custom list
    • What integration logs and packet captures from the failing scenarios in the interoperability test report should be provided to the remediation team?
    • Which RMF control failures in the test results require remediation before the POA&M (plan of actions and milestones) can be closed?
    • Identify the maximum allowable time to remediate a critical protocol interoperability issue in calendar days to be captured in the POA&M. Options: 7 days, 14 days, 30 days, Custom timeline
    • Do you want remediation to include firmware or configuration rollbacks documented in the change control record? Options: Yes, No
    • Provide the escalation path and contact list for unresolved protocol interoperability defects referenced in the defect tracking ticket template.

    Manage COMSEC Material and Key Custody

    • Who is listed in your COMSEC account as the accountable official and local COMSEC custodian per the COMSEC account record?
    • Which COMSEC handling SOP and accountable forms must be used during key receipt and inventory (for example DA Form equivalent or agency inventory sheet)?
    • Will you accept the seller maintaining the COMSEC inventory ledger and providing monthly reconciliations, or will you retain ledger custody? Options: Seller maintains ledger, Buyer retains ledger, Shared process with joint reconciliation
    • Specify the storage vault requirements, container types, and accountability chain for zeroizable key material as referenced in your COMSEC vault spec.
    • Are emergency zeroize procedures and emergency contact numbers recorded in your COMSEC contingency plan available to installers on-site? Options: Yes, No
    • Provide the schedule for periodic COMSEC reconciliations and the required reconciliation evidence type (signed inventory sheet, photograph, electronic ledger export). Options: Signed inventory sheet, Photograph, Electronic ledger export, Other

    Deliver RMF Accreditation Artifacts and Evidence Package

    • Which Risk Management Framework (RMF) artifacts do you require delivered in the accreditation package (for example System Security Plan (SSP), Control Implementation Summary, test result appendices, POA&M)? Options: SSP, Control Implementation Summary, Test results appendices, POA&M, All of the above
    • What acceptance criteria and evidence will validate that the RMF artifacts meet the authorizing official's requirements for an Authority to Operate (ATO)?
    • Which version of the STIG checklists and baseline scans must be included as evidence with the accreditation package? Options: Current agency STIGs, STIGs provided by buyer, Seller baseline with customer approval
    • Do you require a redacted copy of evidence for external reviewers and if so which artifacts must be redacted per your classification handling rules? Options: Yes, redacted copy required, No redacted copy required
    • Provide the authorizing official contact and required delivery format for the accreditation package (for example signed PDFs, electronic repository upload, thumb drive with COMSEC controls). Options: Signed PDFs, Repository upload, Encrypted thumb drive, Other

    Migrate Classified Services and Cutover

    • Which classified services (for example authentication services, file shares, voice/crypto endpoints) are in-scope for migration and are listed on the migration inventory spreadsheet?
  4. Mutual Commit

    Finalize commercial and governance terms, procurement timelines, COMSEC responsibilities, and explicit acceptance criteria tied to accreditation milestones.

    Agreement Modules

    • Master Services Agreement (MSA)
    • Statement of Work (SOW)
    • Pricing & Payment Schedule
    • Purchase Order — Equipment & Materials
    • COMSEC Custody & Handling Agreement
    • Accreditation Acceptance Criteria & Milestone Schedule
    • Governance & Escalation Matrix
    • Change Order Agreement
    • Termination & Exit Plan
    • Procurement & Accreditation Compliance Addendum
  5. Deployment

    Operationalize rollout with readiness checks, execution, and accreditation validation prior to cutover.

    1. Pre-Deployment Readiness

      Confirm concrete readiness facts the deployment depends on — site access, cleared personnel, key dates, and accreditation points of contact.

      Pre-Deployment Questions

      Environment and site access

      • List each deployment site and the earliest date the seller will have escorted physical access (site name — earliest access date).
      • Production enclave access status (so we can schedule COMSEC installation and cutover): Options: Available now, Available on a specific date (we will capture date in DeploymentConfig), Restricted — access requires additional approvals, Not yet scheduled
      • Staging space readiness for equipment and cryptographic handling at each site (secured storage and handling procedures in place?): Options: Yes — secured staging ready at all sites, Partial — secured staging ready at some sites, No — staging not available and must be provided

      Data and configuration

      • Has the final network topology and accreditation boundary been frozen for deployment? (If yes, we will reference the freeze date in DeploymentConfig.) Options: Yes — frozen, No — still being finalized, Frozen for selected enclaves only
      • Equipment staging inventory status (so we can confirm kits and avoid procurement delays): Options: Complete and kit-assigned for all sites, Partial — some items pending, No — equipment not staged
      • Cross-domain interfaces and external integration endpoints declared and approved for connection (this determines required interoperability tests): Options: All declared and approved, Declared but pending approvals, Not declared / not applicable

      People and ownership

      • Primary on-site deployment lead (name and role) and whether they are cleared to handle COMSEC/custody transfer — provide name and role only.
      • Has an Authorizing Official (AO) or designated accrediting official been assigned and committed to review accreditation artifacts during go/no-go? Options: Yes — AO assigned and available, AO assigned but limited availability, No — AO not yet assigned
      • Status of cleared technical staff for installation and Type 1 cryptographic actions (who will perform on-site cryptographic work?): Options: Seller NSA-certified engineers scheduled and cleared for site access, Seller scheduled but requires buyer sponsorship for access, Buyer-cleared staff will perform installation, No cleared staff scheduled

      Timing and constraints

      • Confirmed target installation start date or earliest possible start date (we will use this to build the deployment timeline):
      • Facility blackout windows, mission constraints, travel restrictions, or holiday periods that will block installation at any site (if none, select No blackout windows): Options: No blackout windows, Yes — blackout windows exist (provide dates per site in response)
      • Outstanding compliance or accreditation gates that must be closed prior to installation (select all that apply): Options: COMSEC custody transfer pending, Interim ATO or waiver required, Facility security clearances pending, Background checks / personnel clearances pending, None — all gates cleared
    2. Configuration Details

      Capture exact configuration values, cryptographic provisioning requirements, integration endpoints, and staging inventories the deployment team will use.

      Configuration Details

      Environments & instance names

      • Enter the production environment identifier (format: short lowercase alphanumeric, no spaces; default: prod)

      Network & addressing (values consumed by device staging)

      • Enter the production management VLAN ID for device staging (numeric; default: 4094)

      Cryptographic provisioning (exact parameters for keying and custody)

      • Select the cryptographic provisioning method the deployment will use (select one) Options: Type-1 provisioning via buyer COMSEC custodian, HSM-backed key load (buyer-controlled HSM), HSM-backed key load (seller-controlled HSM), Manual key label with physical COMSEC courier
      • Enter the non-secret key identifier/label devices will reference for keying (format: alphanumeric label; do not paste keys)
      • Enter the credential owner name who will be the point of contact for keying and integration artifacts (format: Last, First; Organization)
      • Select the secure channel that will be used to exchange secrets or key material (the secret itself will not be collected in this form) Options: Your secrets manager (buyer-controlled), Your secrets manager (seller-coordinated), Defense-approved COMSEC custody channel / physical courier (buyer custodian), Seller-managed COMSEC custodian (pre-arranged), Other — will coordinate at deployment kickoff

      Integration endpoints & staging inventory

      • Select your identity provider type for device admin authentication (select one) Options: SAML-based IdP, OIDC-based IdP, LDAP directory (bind DN), Local accounts only
      • Enter the fully-qualified NTP server hostname devices should use (format: ntp.example.mil)
      • Number of encryption appliances to stage for initial deployment (numeric)
    3. Deployment Execution

      Plan and execute installation, Type 1 cryptographic installation, interoperability testing, and RMF artifacts with clear owners and escalation paths.

    4. Go‑Live Accreditation Acceptance

      Formal go/no-go gate: verify accreditation artifacts, authorizing official sign-off, cross‑domain test results, and operational readiness before cutover.

      Checklist items

      • Authorizing official written sign-off received for go/no‑go
      • Accreditation artifacts package uploaded to shared repository
      • Risk acceptance / POA&M acknowledgement obtained
      • Cross‑domain interoperability test report accepted
      • COMSEC key custody transfer and Type‑1 crypto installation verification completed
      • Operational readiness checklist completed and signed
      • Rollback plan documented and restore point verified
      • Facility Permission to Operate or equivalent authorization received for each affected site
      • Cleared personnel and site access confirmed for cutover window
      • Final cutover schedule and change authorization signed
      • Escalation and incident response contacts acknowledged by parties
  6. Sustainment & Mission Assurance

    Establish recurring success cadence, track RMF maintenance, COMSEC sustainment, and a shared channel for issues and enhancement requests.

    Success Reviews

    • Go-live Health Check
    • First Operational Measurement
    • Acceptance Gate - Accreditation Decision
    • Quarterly Sustainment Review
    • Annual Mission Assurance and RMF Maintenance Review

    Issues & Enhancements

    • Schedule required COMSEC key rotation or provisioning activities and log completion artifacts.
    • Achieve a documented acceptance decision (accept or accept with conditions) recorded against the Solution Scope criteria and signed by the named authorizing official.
    • For any condition or failure, finalize a remediation plan with clear evidence requirements and resolution dates.
    • Confirm the incumbent system has a decommission or retained-read-only plan with data archive status recorded.
    • Publish the formal acceptance record with the named signatory and attach the outcome evidence bundle.
    • If acceptance is conditional or failed, produce a remediation plan that lists each criterion, required evidence, and a retest date.
    • Execute the incumbent wind-down tasks: archive data, disable active write access, and confirm fallback procedures are retired or documented.
    • Trend review for core operational metrics
    • Verify that classified network availability (%) remains at or above the target recorded in Solution Scope or document the remediation path if it does not.
    • Reduce the count of open accreditation findings and POA&Ms by the agreed quarterly target, and track progress in the next review.
    • Confirm COMSEC provisioning and key management activities meet sustainment schedules and record any exceptions.
    • Update the POA&M tracker with remediation owners, completion dates, and required retest evidence.
    • Re-confirm agreed success criteria and owners
    • Publish the quarterly sustainment summary with metric charts and the updated issues/enhancements backlog.
    • Accreditation re-certification readiness assessment
    • Confirm accreditation re-certification readiness (%) meets the threshold required for the next accreditation cycle or document a remediation roadmap.
    • Verify COMSEC key management compliance rate (%) aligns with mandated schedules and remediate any exceptions.
    • Set a clear 12-month RMF maintenance calendar with accountable owners and evidence delivery dates.
    • Produce the re-certification readiness report listing remaining artifacts, evidence owners, and target delivery dates.
    • Update the annual RMF maintenance calendar and publish the quarterly checkpoint dates and required evidence packages.
    • Conduct a targeted COMSEC compliance sweep for any items below the compliance threshold and document corrective actions.
    • Confirm the deployment completed against the items recorded in Solution Scope and identify any deviations requiring remediation.
    • Establish a time-bound remediation plan for all severity 1 and 2 issues to restore agreed operational baselines.
    • Confirm monitoring sources and evidence locations for subsequent measurement meetings.
    • Publish the cutover validation summary and store evidence artifacts where the project workspace tracks Solution Scope items.
    • Produce a remediation plan for all severity 1-2 issues with deadlines and required inputs for resolution.
    • Enable access to monitoring feeds and confirm the telemetry collection schedule for the first measurement window.
    • Present first data against Solution Scope targets
    • Determine whether classified network availability (%) and accreditation findings open count are moving toward the Solution Scope targets and document the gap magnitude.
    • Agree a set of corrective actions with resolution dates to bring metrics into compliance by the acceptance gate.
    • Identify any external dependencies that threaten the acceptance timeline and record mitigation steps.
    • Deliver a remediation and retest schedule for each metric that misses its target, including required evidence types for verification.
    • Open tracked tickets for each accreditation finding and assign an expected close date to each ticket.
    • Validate that COMSEC provisioning logs show successful cryptographic loading for all Type 1 devices requiring provisioning.
    • Restate acceptance criteria from Solution Scope
    • RMF maintenance and artifact currency review
    • POA&M and accreditation findings burn-down
    • Present outcome data against each criterion with evidence
    • Diagnose root causes for any gaps
    • Deployment and migration validation
    • COMSEC inventory and compliance audit
    • COMSEC sustainment and key management status
    • Agree corrective actions and timelines
    • Document pass/fail per criterion and capture signatory decision
    • User onboarding and access validation
    • Confirm readiness timeline to the acceptance gate
    • Year-in-review incidents and lessons learned
    • Agree remediation items and resolution timeline
    • Early monitoring signals and telemetry review
    • Issue channel and enhancement request review
    • Agree annual sustainment calendar and checkpoints
    • Blockers and open issues triage
    • Incumbent system wind-down confirmation
    • Agree operational adjustments and next quarter targets
    • Agree immediate remediation actions
First-Party AI

1-2 minutes please — Your AI agent is working

First-Party AI™ can make mistakes. Always check important information.