Task Order Charter
| Task Order PM | C. Tyrrell |
| Program Sponsor (FOPBA) | R. Osei |
| Contracting Officer's Rep. (COR) | M. Whitcombe |
| Contracting Officer (CO) | A. Reyes |
| Contract Vehicle | Health Systems Support IDIQ (HSS-IDIQ) |
| Contract Type | Firm-Fixed-Price (FFP) |
| Period of Performance | Base 12 months + Option 6 months |
| Authorized Price (at award) | $3,550,000 |
| Charter Date | April 20, 2026 |
| Version | 1.0 |
1. Charter Authorization & Document Purpose
This Task Order Charter authorizes execution of Task Order 3 — BenefitConnect Portal Modernization — under the Health Systems Support IDIQ vehicle, and designates C. Tyrrell as Task Order PM with the authority defined in §13. It is the contractor's internal authorizing document; it does not create, alter or supersede any contractual obligation, all of which flow from the Performance Work Statement and the executed Task Order itself.
That distinction is the first thing this charter has to get right. On a commercial program the charter can define scope. Here it cannot: the requirements baseline is Government-issued and Government-owned. The contractor may interpret the PWS, plan against it, and price it — but may not reword a single requirement. This charter therefore authorizes the contractor's response to a baseline set elsewhere, and every scope statement below is a reading of the PWS rather than an independent definition.
This charter records the Task Order as awarded. It states the award-date price and the award-date team, and it is not re-issued as modifications are executed. Current contract value, current staffing and current status live in the Task Order Budget, the Resource Plan and the Dashboard. Where a figure here differs from those artifacts, the difference is the modification history — recorded in the Contract Modification Log — not an inconsistency.
2. Business Case & Strategic Context
FOPBA's legacy benefits enrollment portal runs on an unsupported COTS platform that cannot meet current Section 508 accessibility standards or federal Authority to Operate (ATO) security requirements without significant remediation. Manual accessibility workarounds and compensating security controls have accumulated cost and risk that the agency can no longer sustain under normal operations funding.
This Task Order authorizes Acme Federal Systems, under the HSS-IDIQ contract vehicle, to modernize the BenefitConnect portal: legacy data migration, a Section 508/WCAG-conformant rebuild of the citizen-facing enrollment experience, and a full ATO package to authorize the modernized system for production use.
The business case is that a conformant, ATO'd platform eliminates the compensating-control cost burden, reduces the agency's accessibility-complaint exposure, and positions FOPBA to meet growing enrollment volume without a parallel increase in manual processing staff. As with any end-of-support modernization, the decision facing the agency is not whether to invest but at what level: the incumbent platform's support horizon removes "continue as-is" from the option set, and the Cost-Benefit Analysis evaluates the chosen scope against that constrained set rather than against a do-nothing baseline that does not exist.
3. Contract Structure & Type
The Task Order is Firm-Fixed-Price, issued under the HSS-IDIQ vehicle, with a 12-month Base Period and a 6-month Option Period exercisable at FOPBA's discretion. The contract type is not an administrative detail — it determines who carries performance risk, and therefore how this program must be managed.
- Cost growth is the contractor's risk, not the Government's. Under FFP, rework, inefficiency and internal overrun are absorbed by Acme Federal Systems at no additional cost to FOPBA. Quality failures are therefore financial events for the contractor, which is why the verification approach in the Test & Verification Strategy is built to catch defects early rather than at acceptance.
- Scope changes require a bilateral modification. There is no mechanism for absorbing "small" additional scope informally; new work is priced and executed through the modification process (decision D-04) or it does not happen.
- Acceptance, not completion, discharges the obligation. A deliverable submitted is not a deliverable accepted; the Government's acceptance decision is what closes a CDRL line item, and a rejected submission does not reset its due date.
- The Option Period is the Government's to exercise. Its exercise depends on Base Period performance, which makes CPARS-relevant performance a contractual outcome rather than a reputational one.
4. Task Order Objectives & Success Criteria
| Objective | Measurable success criterion |
|---|---|
| Accessibility conformance | Full Section 508 / WCAG 2.1 AA conformance on the modernized portal prior to Milestone Gate 1, independently verified rather than self-attested |
| Security authorization | ATO obtained with zero open Critical/High findings at the Milestone Gate 1 review |
| Data migration integrity | Legacy applicant/enrollment data migrated with full field-level validation prior to cutover |
| Contract performance | Completion within the approved Firm-Fixed-Price value and Period of Performance, reconciled to $0 variance on the baseline |
| Past-performance rating | CPARS rating of Satisfactory or better, sufficient to justify Option Period exercise |
5. Scope
5.1 In Scope
- Legacy applicant/enrollment data migration and validation.
- Section 508/WCAG-conformant rebuild of the citizen-facing portal.
- Full ATO package: System Security Plan, Security Control Assessment, POA&M process, and supporting CDRLs.
- Cloud hosting/infrastructure setup, including disaster recovery / COOP testing.
- Multi-factor authentication and identity-assurance controls per current OMB guidance.
5.2 Out of Scope
- Any FOPBA system outside the BenefitConnect enrollment portal.
- Ongoing operations and maintenance beyond the Option Period, absent a separate follow-on Task Order.
- Policy or eligibility-rules changes not directly required by the platform modernization.
Under a fixed price, the out-of-scope list is a financial control as much as a planning one. Every item absorbed without a modification is delivered at the contractor's expense, so the boundary stated here is what the modification process in §20 is there to defend.
6. High-Level Requirements
- The modernized portal must achieve full Section 508/WCAG 2.1 AA conformance, independently verified by a government auditor rather than contractor self-attestation.
- The system must pass a Security Control Assessment and obtain ATO prior to production Go-Live.
- All Task Order staffing must be onshore (US-based) given the system's handling of applicant PII.
- Legacy data migration must be validated at the field level prior to cutover, with documented cleansing rules for any formatting inconsistencies found.
These restate the PWS at charter level. The full requirement set, its paragraph numbering, and the evidence that each requirement is verified and surveilled are carried in the Requirements Traceability Matrix.
7. Summary Milestone Schedule
| Milestone | Target date |
|---|---|
| Task Order Kickoff | May 18, 2026 |
| PMP + IMS Baseline (CDRL A001/A002) | Jun 17, 2026 |
| Section 508 Test Plan (CDRL A004) | Jul 17, 2026 |
| System Security Plan (CDRL A005) | Aug 16, 2026 |
| Section 508 / VPAT Testing (CDRL A006) | Nov 14, 2026 |
| ATO Milestone Gate (CDRL A007) | Dec 14, 2026 |
| Production Go-Live | Jan 13, 2027 |
| Option Period Start (exercised early by Mod P00010, Jul 2, 2026) | May 18, 2027 |
| Task Order Closeout | Nov 9, 2027 |
Milestone dates are CDRL-anchored: most are expressed contractually as "Task Order + N days" rather than as calendar commitments, so the dates above are the calendar expression of contractual intervals. The authoritative sequencing is maintained in the Integrated Master Schedule (CDRL A002).
8. Contract Data Requirements List (CDRL)
Ten data items are deliverable under this Task Order. They are the contractual currency of performance: the Government evaluates the Task Order substantially through what is submitted, reviewed and accepted here, and acceptance of each is recorded in the Deliverable Acceptance Log.
| CDRL | Data item |
|---|---|
| A001 | Project Management Plan |
| A002 | Integrated Master Schedule (IMS) |
| A003 | Risk Management Plan (RAIDD Log baseline) |
| A004 | Section 508 Test Plan |
| A005 | System Security Plan (SSP) |
| A006 | Section 508 / VPAT Compliance Test Report |
| A007 | Authority to Operate (ATO) Package |
| A008 | Monthly Status Report |
| A009 | Data Migration Plan & Validation Report |
| A010 | Task Order Closeout Report |
Due dates, formats and acceptance authorities are carried in the CDRL. Note that A008 is recurring rather than one-time, and that acceptance authority is split — the COR accepts most items while the ISSO holds authority over the security artifacts.
9. Budget Authorization
The following Firm-Fixed-Price value is authorized at award:
| Category | Authorized amount |
|---|---|
| Labor — delivery team (13 named resources at award) | $3,070,000 |
| Independent Section 508 audit | $85,000 |
| Third-party Security Control Assessment (SCA) & identity assurance (MFA) | $110,000 |
| Cloud hosting / infrastructure | $225,000 |
| Data migration tooling | $60,000 |
| TOTAL AUTHORIZED FIRM-FIXED PRICE (BASELINE) | $3,550,000 |
This is the original baseline authorized at Charter approval. See the Task Order Budget for the current, mod-adjusted value ($7,704,000 after 11 approved modifications). The growth between the two figures is not overrun — under FFP an overrun would be absorbed by the contractor, not added to the price. It is additional authorized scope, each increment priced and executed through a bilateral modification and traceable in the Contract Modification Log. Reading the two figures as baseline-versus-actual would misread the contract type.
10. Government-Furnished Property & Dependencies
Certain work cannot begin until the Government furnishes what only the Government holds. The controlling item is legacy system read access: assumption A-01 records that FOPBA will provide it within 15 days of Task Order start, and migration planning and validation depend on it.
Government-furnished dependencies invert the usual accountability. For contractor obligations, Acme Federal Systems is answerable for performance; for GFP, the obligation sits with FOPBA, and the contractor's duty is to be ready to use the property and to document any delay in receiving it. Late furnishing is a Government-caused impact, visible as such rather than silently absorbed into a fixed price. Dependencies of this kind are tracked in the RAIDD Log and governed alongside the external relationships in the Vendor & Subcontractor Management Plan.
11. Organization & Resourcing
The Task Order is authorized at award with a 13-person named delivery team, priced in the labor line in §9. Current staffing is larger — the modifications recorded in §9 added scope and the people to perform it — and the current roster is carried in the Resource Plan, with reporting lines in the Org Chart and accountabilities in the RACI.
One resourcing constraint is absolute: all Task Order personnel must be U.S. persons performing work onshore. No offshore staffing is permitted at any point, including during the Option Period and regardless of severity or surge need. This is a data-sovereignty requirement driven by applicant PII, not a cost preference, and it means the program's only surge lever is onshore capacity.
12. Governance & Decision Rights
Federal governance runs on two tracks that must not be conflated — the contractual track and the programmatic one:
| Role | Authority |
|---|---|
| Contracting Officer (CO) | The only authority that can change price, scope or period of performance. All modifications are executed by the CO; no other party can commit the Government. |
| Contracting Officer's Representative (COR) | Technical direction within the existing scope; acceptance of most CDRL deliverables; surveillance under the QASP. |
| Information System Security Officer (ISSO) | Authority over the security artifacts and the ATO path. |
| Program Sponsor (FOPBA) | Agency-side programmatic priority and escalation. |
| Task Order PM (contractor) | Delivery management within the authorized baseline — see §13. |
The distinction that most often causes trouble on federal work is between technical direction and a change. Direction from the COR that stays inside the existing scope is executable; direction that adds scope is a constructive change and must be routed to the CO before it is performed. The full governance model is carried in Program Governance.
13. Task Order PM Authority & Limitations
C. Tyrrell is authorized to apply organizational resources to Task Order activities, manage the approved budget within the Firm-Fixed-Price baseline, and approve task-level schedule adjustments that do not affect a CDRL due date or a Milestone Gate.
Changes to scope, price, or a CDRL-mandated deliverable require a formal Contract Modification approved by the Contracting Officer. No verbal or informal scope change is recognized under this Task Order — a direction that would change scope is escalated to the CO rather than accommodated, however reasonable it appears and whoever gives it.
14. Key Stakeholders
| Name | Role |
|---|---|
| R. Osei | Program Sponsor, FOPBA |
| M. Whitcombe | Contracting Officer's Representative (COR) |
| A. Reyes | Contracting Officer (CO) |
| T. Abernathy | Information System Security Officer (ISSO) |
| D. Ferris | Deputy Task Order PM |
| C. Tyrrell | Task Order PM |
Communication cadence, reporting routes and escalation paths are defined in the Communications Plan.
15. Regulatory & Compliance Framework
- Section 508 / WCAG 2.1 AA. Accessibility conformance is a contractual deliverable (CDRL A004/A006) verified by an independent Government auditor, not a design aspiration. Evidence is carried in the Section 508 / VPAT report.
- FISMA / RMF and the ATO. The system may not operate in production without an Authority to Operate. The SSP, Security Control Assessment and POA&M process are deliverables (A005, A007), and the ATO Package is the artifact that authorizes operation.
- Applicant PII and onshore performance. Handling of applicant personally identifiable information drives the U.S.-persons/onshore constraint in §11, which flows down to any party touching the data.
- FAR-governed contract administration. Modifications, option exercise and acceptance follow FAR-based process; the authority boundaries in §12 derive from it.
16. Quality Assurance & Government Surveillance
Quality on this Task Order is assessed twice, independently. The contractor verifies its own work through the Test & Verification Strategy; the Government separately surveils performance through the Quality Assurance Surveillance Plan, which defines a surveillance method and frequency for every performance standard and Acceptable Quality Level in the PWS.
The two are deliberately not merged. A deliverable can pass contractor verification and still fail Government surveillance, and it is the Government's assessment that determines acceptance and, ultimately, the CPARS rating that conditions Option Period exercise. Planning as though internal quality gates are the real gate is the characteristic federal delivery mistake this structure is designed to prevent.
17. High-Level Risks
Risks recorded at charter approval, maintained with scoring, owners and responses in the RAIDD Log:
| Ref | Risk |
|---|---|
| R-01 | ATO assessment could surface a security finding that delays Milestone Gate 1 beyond Dec 14, 2026 (highest-rated risk at Charter approval) |
| — | Legacy applicant data has known formatting inconsistencies that could complicate migration validation |
| — | The all-onshore staffing requirement limits surge capacity if a resource attrites mid-Option-Period, with no offshore substitution permitted regardless of severity |
| — | Contract modification growth over the Task Order's life could mask underlying scope creep if not actively tracked against the original PWS baseline |
The last of these proved prescient rather than theoretical: eleven modifications were executed against this Task Order, and the discipline that keeps that from becoming uncontrolled growth is precisely the baseline-versus-current separation this charter maintains in §9.
18. Assumptions
- A-01 — FOPBA will provide legacy system read access within 15 days of Task Order start.
- A-02 — The Option Period will be exercised based on satisfactory Base Period performance (CPARS rating of Satisfactory or better).
- No additional offshore staffing will be authorized at any point during the Option Period, consistent with the PII/ATO onshore-only requirement.
- FOPBA's existing network and security infrastructure is sufficient to support the modernized portal without a separate agency capital investment.
Assumptions are stated here as they stood at charter approval. Their current status — including any that did not hold as written — is maintained in the RAIDD Log, which is the live record; this charter is not amended when an assumption changes.
19. Constraints
- Fixed price. Delivery must complete within the authorized FFP value; internal overrun is absorbed by the contractor.
- Onshore-only performance. No offshore staffing at any point, for any reason.
- ATO as a hard gate. Production operation is not permitted without authorization, so security cannot be traded for schedule.
- Government-owned requirements baseline. The contractor cannot reword, descope or reinterpret a PWS requirement unilaterally.
- CDRL-driven cadence. Deliverable due dates are contractual intervals; a missed submission is a contractual event, not an internal slip.
20. Contract Modifications & Change Control
Decision D-04 establishes the program's change posture: route all scope changes through the formal Contract Modification process rather than absorbing them. Under a fixed price, absorbing scope is not generosity — it is unpriced work that erodes margin and, worse, sets a precedent that the boundary is negotiable.
Each modification is proposed, priced, negotiated and executed bilaterally by the Contracting Officer, then recorded in the Contract Modification Log with its rationale and value. That record is what allows the difference between the $3,550,000 award baseline and the current contract value to be explained line by line rather than merely observed — which is exactly the control the fourth risk in §17 calls for.
21. Document Control & Related Documents
This charter is version 1.0, dated April 20, 2026. It is superseded only by a re-issued charter; contractual changes are made by modification and recorded in the Contract Modification Log, not by amending this document.
- Performance Work Statement — the Government-issued requirements baseline
- Task Order Management Plan (CDRL A001) and Integrated Master Schedule (CDRL A002)
- CDRL and Deliverable Acceptance Log
- QASP and Test & Verification Strategy
- Requirements Traceability Matrix
- Task Order Budget, Resource Plan, Contract Modification Log
- RAIDD Log, Program Governance, Communications Plan
- Cost-Benefit Analysis, Benefits Realization Plan, Total Cost of Ownership
22. Approval
This charter authorizes the Task Order PM to proceed with planning and execution of the BenefitConnect Portal Modernization Task Order as described above, within the authority defined in §13.