← Federal Suite 02 · Planning & Compliance

Requirements Traceability Matrix

Download Word

This matrix traces every requirement this Task Order is obliged to meet — from the paragraph of the PWS that states it, through the CDRL data item that evidences it, to the verification that proves it and the surveillance the Government uses to grade it. The Test & Verification Strategy promises “requirements traceability from PWS through test case to result” as the contractor verification behind the System functionality against PWS AQL. This is that traceability.

Generated, not maintained by hand. This matrix is produced by a script that reads the PWS, the CDRL, the Contract Modification Log, the QASP and the Test & Verification Strategy and fails loudly if any identifier it emits does not resolve in those documents. A hand-kept RTM decays quietly: the source moves, the matrix does not, and it goes on asserting coverage it no longer has. A generated one can only be wrong if its sources are wrong — and then it is wrong visibly, in the same place the sources are.

Why a federal RTM is not a commercial one

On a commercial program the requirements document and the specification are both written by the delivery organisation, so the trace links are already in the text — the spec cites the requirement it satisfies. None of that holds here.

PWS paragraphGovernment-issued requirement, or a requirement added by executed modification
CDRL data itemThe deliverable that carries the evidence, against its DID
Contractor verificationTest level, 508 stage, RMF activity or migration stage
Government surveillanceQASP method and AQL — run by the COR, not the contractor
COR acceptanceFormal acceptance recorded in the Deliverable Acceptance Log

The requirements baseline is the PWS as modified

The Task Order has been modified 11 times. 4 of those modifications were scope additions, and between them they added 5 requirements that appear nowhere in the PWS as awarded. Any matrix that traces only the awarded PWS is tracing a superseded baseline — and would report full coverage while ignoring 4 funded scope additions worth $4,138,000.

ModTitleTypeCost impactRequirements added
P00004Add Multi-Factor Authentication to Citizen Portal LoginScope Addition (Security)+$45,000M-P00004.1
P00006Add Automated Accessibility Regression TestingScope Addition (Section 508)+$18,000M-P00006.1
P00008Add Disaster Recovery / COOP TestingScope Addition+$35,000M-P00008.1
P00011Add Mobile-Responsive Redesign & Benefits-Eligibility Verification API IntegrationScope Addition+$4,040,000M-P00011.1, M-P00011.2

The remaining seven modifications adjusted schedule, price, or administration without changing what the system must do, so they add no requirement to this baseline.

Coverage

35
Requirements in the current baseline
30
From the PWS as awarded
5
Added by executed modification
24
Trace to a data item
25
Have a contractor verification
24
Sit under a surveillance area
ClassReqsData itemVerificationSurveillanceWhat the class covers
PERF Performance / Capability7477What the delivered system must do.
CMPL Compliance1212129Externally imposed standards the Task Order must satisfy.
DELV Deliverable4444Obligations about the CDRL data items themselves.
MGMT Contract Management9424Period, price, place, and administration of the Task Order.
GFP Government-Furnished3000Obligations on FOPBA, not on the contractor.

The low numbers are the point, not a defect. Contract-management requirements — period of performance, price ceiling, place of performance, FAR incorporation — are not verified by test, and it would be dishonest to claim a test case against them; they are administered by the Contracting Officer and evidenced in the Task Order Budget and the Contract Modification Log. Government-furnished obligations are not the contractor's to verify at all. A matrix that showed 100 % across every column would be a matrix that had stopped distinguishing between requirement types.

The matrix — PWS as awarded

PWS §2 · Scope of Work 6 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 2.1
PERF
Replatform the citizen-facing benefits application portal to a modern, accessible web application, covering account creation, benefits application intake, status tracking, and secure document upload
The delivered system is not itself a CDRL data item — see gap G-01.
No data item Unit Integration System Government acceptance QASP — System functionality against PWS
PWS 2.2
CMPL
Achieve and document Section 508 accessibility conformance (WCAG 2.1 AA-aligned), independently audited rather than self-attested
Decision D-01 removed contractor self-attestation; the Government audit is the verdict.
A004 A006 Accessibility Pre-audit Government audit QASP — Section 508 conformance
Zero Level A/AA violations at go-live
PWS 2.3
CMPL
Obtain Authority to Operate (ATO) under the Risk Management Framework prior to production cutover, including a System Security Plan, Security Assessment Report, and Plan of Action and Milestones (POA&M)
Decision D-03 phases the authorization; risk R-01 is scored against this requirement.
A005 A007 Security Assess Authorize QASP — Security authorization
PWS 2.4
PERF
Migrate existing applicant data and in-flight applications from the legacy platform without service interruption to any applicant mid-process
Risk R-02 anticipates legacy formatting inconsistency here.
A009 Data migration Reconciliation Exception handling PWS 9.4 — Data migration completed with no service interruption to in-flight applicants
Zero applicant-impacting incidents during cutover
PWS 2.5
MGMT
Provide a 6-month Option Period of post-launch stabilization support, including continuous ATO monitoring and defect-fix sustainment, exercisable at FOPBA's discretion based on Base Period performance
Option Period exercised early via Mod P00010 (02 Jul 2026), on a FAR 17.207 determination driven by FY2026 appropriations timing rather than by the Base Period performance trigger this paragraph states — assumption A-02 records that the stated trigger did not operate. Traceability is unaffected: the requirement is still owed in full.
A007 A008 Monitor Performance QASP — System availability (post-launch)
99.5% monthly uptime
PWS 2.6
DELV
Deliver all contract data items per the CDRL on the schedule specified, with each deliverable formally accepted (not merely submitted) by the COR before it is considered complete
Acceptance, not submission, discharges the obligation.
All 10 data items CDRL deliverable submissions QASP — CDRL deliverable submissions
No more than 1 rejection cycle per item

PWS §3 · Period of Performance 2 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 3.1
MGMT
Base Period — 12 months — portal build, ATO authorization, data migration, and production cutover
Baseline schedule is a data item; the period itself is a contract term.
A002 Not test-verified QASP — Monthly status reporting
Submitted by CDRL due date, no material omissions
PWS 3.2
MGMT
Option Period — 1 × 6-month option — post-launch stabilization support, exercised via Mod P00010
Exercised by CO action (Mod P00010), not automatic extension.
A002 Not test-verified QASP — Monthly status reporting
Submitted by CDRL due date, no material omissions

PWS §4 · Deliverables (CDRL Summary) 1 requirement

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 4.1
DELV
All deliverables are enumerated with due dates, formats, and acceptance criteria in the Contract Data Requirements List — 10 line items in total, spanning the Project Management Plan (A001), Integrated Master Schedule (A002), Section 508 Test Plan and Report (A004/A006), System Security Plan and ATO package (A005/A007), Monthly Status Reports (A008), the data migration validation report (A009), and final closeout certification (A010). Each is formally accepted by the COR, not merely submitted — a distinction that matters because a submitted-but-rejected deliverable does not satisfy the contract, and re-submission timelines are tracked against the original due date, not reset by the rejection.
Re-submission runs against the original due date.
All 10 data items CDRL deliverable submissions PWS 9.1 — CDRL deliverables submitted on or before the due date specified
98% on-time submission rate

PWS §5 · Success Criteria & Performance Standards 5 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 5.1
PERF
ATO granted and production cutover completed within the Base Period, with zero unplanned service interruption for applicants with in-flight applications
Gates Milestone Gate 1 (14 Dec 2026).
A007 A009 Authorize Reconciliation PWS 9.4 — Data migration completed with no service interruption to in-flight applicants
Zero applicant-impacting incidents during cutover
PWS 5.2
CMPL
Independent Section 508 audit finds full conformance (or all findings remediated) prior to go-live A006 Pre-audit Government audit QASP — Section 508 conformance
Zero Level A/AA violations at go-live
PWS 5.3
DELV
All 10 CDRL line items accepted by the COR, none rejected more than once
The AQL is "no more than 1 rejection cycle per item".
All 10 data items CDRL deliverable submissions QASP — CDRL deliverable submissions
No more than 1 rejection cycle per item
PWS 5.4
MGMT
QASP surveillance metrics remain within acceptable range across the period of performance (see the QASP for the specific surveillance methods and metrics) A008 Monthly status reporting QASP — Monthly status reporting
Submitted by CDRL due date, no material omissions
PWS 5.5
MGMT
Total Task Order cost remains within the Firm-Fixed-Price baseline plus any Contracting-Officer-approved modifications — no unapproved cost growth
Verified against the Task Order Budget and Contract Modification Log, not by test.
No data item Not test-verified No surveillance area

PWS §6 · Constraints & Assumptions 2 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 6.1
CMPL
all delivery-team personnel handling applicant PII or supporting the ATO/RMF security authorization must be U.S. persons performing work onshore — no offshore staffing is permitted on this Task Order, unlike the Agile suite's commercial program.
Restated at PWS 7.1 and PWS 10.4 — see gap G-04.
A005 Security No surveillance area
PWS 6.2
MGMT
The Firm-Fixed-Price structure means Acme Federal Systems bears internal cost-overrun risk; FOPBA's exposure is limited to the negotiated price plus approved modifications.
FFP risk allocation; a contract term, not a verifiable behaviour.
No data item Not test-verified No surveillance area

PWS §7 · Place of Performance 2 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 7.1
CMPL
Primarily remote/contractor-site performance. All personnel handling applicant PII or ATO/RMF-scoped work must be U.S. persons performing work from within the United States (see Constraints, Section 6) — this is an onshore-location requirement, not a requirement to work from a specific government facility.
Restatement of PWS 6.1.
A005 Security No surveillance area
PWS 7.2
MGMT
Up to 4 on-site visits to FOPBA headquarters per Base Period are anticipated for Milestone Gate reviews, ATO briefings to the Agency Authorizing Official, and kickoff/closeout meetings; travel for these visits is priced into the Task Order rather than billed as a separate travel line item.
Travel priced into the Task Order; tracked administratively.
No data item Not test-verified No surveillance area

PWS §8 · Government Furnished Property & Information (GFP/GFI) 3 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 8.1
GFP
Legacy System Read Access — FOPBA provides contractor read access to the legacy benefits portal database and application server logs for migration planning and validation (RAIDD Log, Assumption A-01)
FOPBA obligation. Assumption A-01; Mod P00002 extended the window when it slipped.
No data item Not test-verified No surveillance area
PWS 8.2
GFP
GFE Network / VPN — FOPBA-managed VPN connectivity into the government furnished environment (GFE) for deployment and testing against non-production instances
FOPBA obligation. Assumption A-04; issue I-05 records GFE VPN latency against it.
No data item Not test-verified No surveillance area
PWS 8.3
GFP
Existing Eligibility Rules Documentation — FOPBA-maintained business rules documentation for benefit eligibility logic, provided as reference — the contractor does not alter eligibility rules (see Scope, Section 2)
FOPBA obligation. No RAIDD entry — see gap G-05.
No data item Not test-verified No surveillance area

PWS §9 · Performance Requirements Summary Matrix 4 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 9.1
DELV
CDRL deliverables submitted on or before the due date specified All 10 data items CDRL deliverable submissions PWS 9.1 — CDRL deliverables submitted on or before the due date specified
98% on-time submission rate
PWS 9.2
CMPL
Section 508 / WCAG 2.1 AA conformance on all delivered UI components A006 Accessibility System Government audit PWS 9.2 — Section 508 / WCAG 2.1 AA conformance on all delivered UI components
Zero unremediated Level A/AA failures at CDRL A006 acceptance
PWS 9.3
CMPL
Zero unauthorized applicant PII disclosure incidents
Zero tolerance — no sampling; continuous monitoring.
A005 A007 Security PWS 9.3 — Zero unauthorized applicant PII disclosure incidents
Zero tolerance
PWS 9.4
PERF
Data migration completed with no service interruption to in-flight applicants A009 Data migration Reconciliation PWS 9.4 — Data migration completed with no service interruption to in-flight applicants
Zero applicant-impacting incidents during cutover

PWS §10 · Applicable Federal Requirements 5 requirements

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
PWS 10.1
MGMT
Federal Acquisition Regulation (FAR) clauses incorporated by reference in the Task Order
Administered by the CO; incorporated by reference.
No data item Not test-verified No surveillance area
PWS 10.2
CMPL
Section 508 of the Rehabilitation Act — accessibility conformance A004 A006 Accessibility QASP — Section 508 conformance
Zero Level A/AA violations at go-live
PWS 10.3
CMPL
Risk Management Framework (RMF) — security authorization prior to go-live (ATO) A005 A007 Assess Authorize QASP — Security authorization
PWS 10.4
CMPL
All delivery-team personnel handling applicant PII or supporting the ATO/RMF security authorization must be U.S. persons performing work onshore — no offshore staffing is permitted on this Task Order
Restatement of PWS 6.1.
A005 Security No surveillance area
PWS 10.5
MGMT
HSS-IDIQ labor category schedule — every billed role must map to a pre-negotiated labor category and rate ceiling on the underlying IDIQ contract, verified during the labor-category audit that produced Mod P00009
Verified by the labor-category audit that produced Mod P00009.
No data item Not test-verified No surveillance area

The matrix — requirements added by modification

These five requirements are as binding as anything in the PWS and are funded at $4,138,000 of the $4,154,000 net modification value. None of them appears in the PWS document.

RequirementStatementData itemContractor verificationGovernment surveillance & AQL
M-P00004.1
CMPL
Multi-Factor Authentication on the citizen-facing portal login flow, per the post-award OMB identity-assurance memo.
Changes the authentication control set described in the SSP; the A005 data item was not amended.
A005 A007 Security Integration PWS 9.3 — Zero unauthorized applicant PII disclosure incidents
Zero tolerance
M-P00006.1
CMPL
Automated accessibility regression testing executed on every release, alongside manual VPAT testing.
Adds a method the A004 Test Plan must describe; A004 was submitted before this mod was executed.
A004 A006 Accessibility Build QASP — Section 508 conformance
Zero Level A/AA violations at go-live
M-P00008.1
PERF
Disaster Recovery / COOP failover to a secondary region within FOPBA's required recovery time objective, demonstrated by test.
No data item records the DR test result — see gap G-03.
No data item Performance QASP — System availability (post-launch)
99.5% monthly uptime
M-P00011.1
PERF
Mobile-responsive front-end redesign of the citizen-facing portal, which was desktop-only as awarded.
FOPBA's 508 program office raised this as an accessibility gap, so it lands inside the strictest AQL on the Task Order.
A004 A006 Accessibility System QASP — Section 508 conformance
Zero Level A/AA violations at go-live
M-P00011.2
PERF
Real-time integration to the agency Benefits-Eligibility Verification API, replacing a manual caseworker lookup.
Named explicitly in the Test Strategy integration level; no data item — see gap G-01.
No data item Integration Security QASP — System functionality against PWS

Data items and what they carry

The reverse view: for each CDRL line item, which requirements depend on it. A data item with many requirements behind it is a concentration of risk — a single rejection cycle on A006 puts every accessibility requirement on the Task Order into remediation at once.

CDRLTitleDIDDueAccepting authorityRequirements tracedStatus
A001Project Management PlanDI-MGMT-81438Task Order + 30 daysCORAccepted
A002Integrated Master Schedule (IMS)DI-MGMT-81650Task Order + 30 daysCOR3.1, 3.2Accepted
A003Risk Management Plan (RAIDD Log baseline)DI-MGMT-81808Task Order + 30 daysCORAccepted
A004Section 508 Test PlanDI-MISC-80508Task Order + 60 daysCOR10.2, 2.2, M-P00006.1, M-P00011.1Accepted
A005System Security Plan (SSP)DI-MGMT-82045Task Order + 90 daysISSO / COR10.3, 10.4, 2.3, 6.1, 7.1, 9.3, M-P00004.1Accepted
A006Section 508 / VPAT Compliance Test ReportDI-MISC-80784Task Order + 180 daysCOR10.2, 2.2, 5.2, 9.2, M-P00006.1, M-P00011.1Pending
A007Authority to Operate (ATO) PackageDI-MGMT-82046Task Order + 210 daysAgency Authorizing Official (AO)10.3, 2.3, 2.5, 5.1, 9.3, M-P00004.1Pending
A008Monthly Status ReportDI-MGMT-803685th of each monthCOR2.5, 5.4Recurring — current
A009Data Migration Plan & Validation ReportDI-MISC-81234Task Order + 150 daysCOR2.4, 5.1, 9.4Under COR Review
A010Task Order Closeout ReportDI-MGMT-80467End of Period of PerformanceCOR / COPending

Status reflects the current reporting position, Base Period Month 5 of 18 (16 Oct 2026). Five data items are accepted (A001, A002, A003, A004, A005), A009 is submitted and under COR review, A008 is recurring and current, and the remainder are not yet due.

Open traceability gaps

Building this matrix surfaced five gaps. They are recorded here with an owner and a date rather than quietly closed, because a traceability matrix that reports no gaps is usually a matrix that was written to report no gaps.

G-01

No data item evidences the delivered system itself

PWS 2.1 is the core capability requirement of this Task Order, and the two capability requirements added by Mod P00011 sit alongside it. None of them trace to a CDRL. All ten data items are management or compliance documents; there is no system acceptance test report. Acceptance of the working portal therefore rests on COR inspection against PWS prose, with no DID-defined acceptance criteria to inspect against.

Why it matters. PWS 5.3 makes "all 10 CDRL line items accepted" a success criterion. A Task Order could satisfy that criterion in full while the portal itself has never been formally accepted against written criteria.

ActionPropose a system acceptance test report data item at the next modification, or agree written system acceptance criteria with the COR and record them in the Deliverable Acceptance Log.
OwnerC. Tyrrell
ByBefore system test entry
G-02

The CDRL was never amended for post-award scope

Four executed modifications added requirements after award. The CDRL still carries exactly the ten line items it carried at award. A004 and A006 must now cover mobile-responsive components and automated regression testing; A005 and A007 must now cover multi-factor authentication. No DID was amended and no due date moved.

Why it matters. The contractor is verifying against a wider requirements baseline than the data items describe. A COR reviewing A006 against its original DID could accept a report that does not cover mobile at all.

ActionRaise a modification amending the A004, A005, A006 and A007 data item descriptions to name the added scope.
OwnerC. Tyrrell / A. Reyes (CO)
ByBefore CDRL A006 submission
G-03

The DR/COOP test has no deliverable and no acceptance path

Mod P00008 added a Disaster Recovery / COOP failover test against FOPBA's recovery time objective. The Test & Verification Strategy has a performance level that can execute it, but no CDRL receives the result and no QASP surveillance area names it.

Why it matters. A funded requirement with no acceptance path is a requirement the Government cannot confirm was met, and the contractor cannot prove it delivered.

ActionAttach the DR test result to the A007 continuous-monitoring evidence, or add it as a numbered attachment to A008.
OwnerT. Abernathy (ISSO)
ByBefore Option Period start
G-04

One constraint is stated three times

The onshore / U.S.-persons constraint appears at PWS 6.1, is restated at PWS 7.1, and appears again at PWS 10.4. All three are traced here as one requirement with two restatements.

Why it matters. Low as written, but a future modification that changes staffing terms must update three paragraphs. Changing one and missing the others leaves the PWS self-contradictory.

ActionNote the restatement in the requirements baseline so any staffing modification touches all three paragraphs.
OwnerD. Ferris (Deputy PM)
ByStanding
G-05

One Government-furnished obligation has no RAIDD entry

PWS 8.1 is covered by assumption A-01 and PWS 8.2 by assumption A-04 and issue I-05. PWS 8.3 — FOPBA-maintained eligibility rules documentation — has neither. Mod P00002 is the precedent: a Government-furnished obligation slipped and cost fifteen days.

Why it matters. Contractor traceability for a Government obligation terminates in a dependency, not a verification. Without a RAIDD entry there is nothing tracking whether the obligation was met.

ActionOpen a dependency entry against PWS 8.3 in the RAIDD Log.
OwnerJ. Okonkwo
ByNext RAIDD review

How this matrix is kept true

It is regenerated, not edited. The generator reads the PWS anchors, the CDRL records, the Contract Modification Log, the QASP surveillance table and the Test & Verification Strategy tables, and aborts before writing if a requirement in the trace map is missing from the PWS, a PWS paragraph is missing from the trace map, a CDRL identifier does not exist, a verification method is not one the Test Strategy actually defines, a surveillance area is not one the QASP actually lists, or an owner is not on the Resource Plan roster.

That last set of checks is the useful part. A matrix whose validation cannot fail is decoration. Regenerating this one after any change to the PWS, the CDRL, or an executed modification is what keeps it a control rather than a record of what was once true.

Generated 16 Oct 2026 from task-order-pws.html, cdrl-detail.html, cdrl.html, contract-mod-detail.html, qasp.html, test-strategy.html and resource-plan.html · 35 requirements · 10 data items · all identifiers resolved.

Related

Performance Work Statement · CDRL · CDRL Detail · Contract Modification Log · QASP · Test & Verification Strategy · Deliverable Acceptance Log · RAIDD Log