Every federal contracting and program management term used across this suite, defined in plain
language with the closest commercial/healthcare PM equivalent where one exists. A companion glossary for
PMBOK/waterfall terminology (as used in the Enrollment & Claims PM Suite) is linked from that suite's
homepage.
Contract Vehicle & Type
FAR Federal Acquisition RegulationThe government's contracting rulebook.Closest to: HIPAA as a compliance framework, but for contracting instead of patient data.
IDIQ Indefinite Delivery/Indefinite QuantityAn umbrella contract vehicle with no fixed total value; individual Task Orders are issued against it over time.Closest to: a master services agreement with SOWs issued underneath it.
Task OrderA specific, funded work assignment issued under an IDIQ. This program is Task Order 3.
FFP Firm-Fixed-PriceA contract type where the government pays an agreed price for defined deliverables regardless of the contractor's actual cost.Closest to: a flat-fee vendor contract — the vendor bears cost-overrun risk internally.
Base PeriodThe initial, guaranteed period of performance on a Task Order — 12 months on this program.
Option PeriodAn additional period of performance the government may (but isn't obligated to) exercise after the Base Period, at pre-priced terms — 6 months on this program.
PWS Performance Work StatementGovernment-written scope document defining the required work.Closest to: a Project Charter, except the client writes it, not the PM.
Prime ContractorThe company holding the direct contract with the government — Acme Federal Systems on this Task Order.
CPARS Contractor Performance Assessment Reporting SystemThe federal system where government past-performance ratings are recorded — a satisfactory CPARS rating is what typically justifies exercising an Option Period.
Government Roles
COR Contracting Officer's RepresentativeGovernment's day-to-day technical/program oversight person.Closest to: an empowered client-side sponsor — but with contract authority you don't usually see commercially.
CO Contracting OfficerThe only government person legally authorized to bind the contract or approve mods.Closest to: Legal being the only one who can sign a change order, not the business sponsor.
Sponsor (Government)The senior government executive with ultimate program accountability on the agency side — separate from the COR's day-to-day oversight role.
ISSO Information System Security OfficerThe role owning a system's ATO package and ongoing security posture.Closest to: a dedicated security lead, but with formal authorization-package ownership.
Deliverables & Schedule
CDRL Contract Data Requirements ListThe numbered, contractual list of every required deliverable, due date, and format.Closest to: a deliverables tracker, but each line item carries contractual weight.
DID Data Item DescriptionThe formatting/content specification a CDRL deliverable must follow — CDRLs say what's due and when; the DID says exactly what it must contain.
QASP Quality Assurance Surveillance PlanGovernment's own plan for how it will inspect and accept contractor deliverables.
IMS Integrated Master ScheduleA formally structured master schedule required in federal format.Closest to: your MS Project plan, with stricter formatting conventions.
POP Period of PerformanceThe contractually defined start and end dates during which work is authorized and funded.
PMP Project Management PlanThe Task Order's foundational planning CDRL — combines what a commercial suite would split across a charter and management plan.
Security & Accessibility
Section 508Federal accessibility compliance requirement for IT systems (screen readers, keyboard navigation, etc.).Closest to: ADA compliance, but IT-specific and federally enforced pre-launch.
VPAT Voluntary Product Accessibility TemplateThe standard documentation format for reporting Section 508 accessibility conformance.
ATO Authority to OperateFormal government approval required before a system can go live in production.Closest to: a HIPAA Security Risk Assessment sign-off, but a hard gate — nothing launches without it.
RMF Risk Management FrameworkThe federal security assessment process that leads to an ATO.
SSP System Security PlanThe core ATO package document describing a system's security controls and how each is implemented.
SCA Security Control AssessmentThe independent third-party test of whether a system's security controls actually work as described in the SSP.
POA&M Plan of Action & MilestonesTracked remediation plan for any security weaknesses found during ATO assessment.
GFE Government Furnished Equipment/EnvironmentInfrastructure, hardware, or environments the government provides rather than the contractor procuring independently — e.g., the GFE hosting environment referenced in this Task Order's VPN/deployment issue log.
FIPS 199The federal standard used to categorize a system's security impact level (Low/Moderate/High) based on the sensitivity of the data it handles — this system is categorized Moderate.
AQL Acceptable Quality LevelThe minimum performance threshold the QASP measures the contractor against for a given deliverable or service area — e.g., "no more than 1 rejection cycle per CDRL item."Closest to: an SLA target, but government-defined and tied to formal remedies.
Contract Modification (Mod)Formal, CO-approved change to a contract's scope, price, or terms.Closest to: change control, but legally binding and CO-signed rather than internally approved.
RAIDDRisks, Assumptions, Issues, Dependencies, Decisions — a single log tracking all five, structured identically to the PM suite's version but populated with federal-specific entries (ATO risk, staffing corrections, mod-driven decisions).
RACIResponsible, Accountable, Consulted, Informed — a responsibility-assignment matrix, extended in this suite to include government-side roles (COR/CO/Sponsor) alongside the contractor delivery team.
CloseoutThe formal end-of-performance process confirming all CDRLs accepted, final costs reconciled, and any undrawn reserve returned.