This matrix traces every requirement this Task Order is obliged to meet — from the paragraph of the PWS that states it, through the CDRL data item that evidences it, to the verification that proves it and the surveillance the Government uses to grade it. The Test & Verification Strategy promises “requirements traceability from PWS through test case to result” as the contractor verification behind the System functionality against PWS AQL. This is that traceability.
Why a federal RTM is not a commercial one
On a commercial program the requirements document and the specification are both written by the delivery organisation, so the trace links are already in the text — the spec cites the requirement it satisfies. None of that holds here.
- The baseline is Government-issued and Government-owned. The PWS was written by FOPBA. The contractor cannot add, reword, or reinterpret a requirement; changing one takes a Contract Modification signed by the Contracting Officer.
- The PWS contains no trace links, because the Government had no reason to put them there. Constructing traceability is therefore the contractor's own act of interpretation — and that interpretation is precisely what gets tested when the COR inspects a deliverable.
- Verification has two independent columns. The contractor verifies; the Government surveils. These are different parties running different processes with different evidence, and the contractor does not control the second one. A requirement can be fully verified internally and still fail surveillance.
- Traceability terminates in acceptance, not completion. Under a Firm-Fixed-Price task order a deliverable that was submitted but rejected has not satisfied anything, and re-submission runs against the original due date rather than resetting it.
The requirements baseline is the PWS as modified
The Task Order has been modified 11 times. 4 of those modifications were scope additions, and between them they added 5 requirements that appear nowhere in the PWS as awarded. Any matrix that traces only the awarded PWS is tracing a superseded baseline — and would report full coverage while ignoring 4 funded scope additions worth $4,138,000.
| Mod | Title | Type | Cost impact | Requirements added |
|---|---|---|---|---|
| P00004 | Add Multi-Factor Authentication to Citizen Portal Login | Scope Addition (Security) | +$45,000 | M-P00004.1 |
| P00006 | Add Automated Accessibility Regression Testing | Scope Addition (Section 508) | +$18,000 | M-P00006.1 |
| P00008 | Add Disaster Recovery / COOP Testing | Scope Addition | +$35,000 | M-P00008.1 |
| P00011 | Add Mobile-Responsive Redesign & Benefits-Eligibility Verification API Integration | Scope Addition | +$4,040,000 | M-P00011.1, M-P00011.2 |
The remaining seven modifications adjusted schedule, price, or administration without changing what the system must do, so they add no requirement to this baseline.
Coverage
| Class | Reqs | Data item | Verification | Surveillance | What the class covers |
|---|---|---|---|---|---|
| PERF Performance / Capability | 7 | 4 | 7 | 7 | What the delivered system must do. |
| CMPL Compliance | 12 | 12 | 12 | 9 | Externally imposed standards the Task Order must satisfy. |
| DELV Deliverable | 4 | 4 | 4 | 4 | Obligations about the CDRL data items themselves. |
| MGMT Contract Management | 9 | 4 | 2 | 4 | Period, price, place, and administration of the Task Order. |
| GFP Government-Furnished | 3 | 0 | 0 | 0 | Obligations on FOPBA, not on the contractor. |
The low numbers are the point, not a defect. Contract-management requirements — period of performance, price ceiling, place of performance, FAR incorporation — are not verified by test, and it would be dishonest to claim a test case against them; they are administered by the Contracting Officer and evidenced in the Task Order Budget and the Contract Modification Log. Government-furnished obligations are not the contractor's to verify at all. A matrix that showed 100 % across every column would be a matrix that had stopped distinguishing between requirement types.
The matrix — PWS as awarded
PWS §2 · Scope of Work 6 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 2.1 PERF |
Replatform the citizen-facing benefits application portal to a modern, accessible web application, covering account creation, benefits application intake, status tracking, and secure document upload The delivered system is not itself a CDRL data item — see gap G-01. |
No data item | Unit Integration System Government acceptance | QASP — System functionality against PWS |
| PWS 2.2 CMPL |
Achieve and document Section 508 accessibility conformance (WCAG 2.1 AA-aligned), independently audited rather than self-attested Decision D-01 removed contractor self-attestation; the Government audit is the verdict. |
A004 A006 | Accessibility Pre-audit Government audit | QASP — Section 508 conformance Zero Level A/AA violations at go-live |
| PWS 2.3 CMPL |
Obtain Authority to Operate (ATO) under the Risk Management Framework prior to production cutover, including a System Security Plan, Security Assessment Report, and Plan of Action and Milestones (POA&M) Decision D-03 phases the authorization; risk R-01 is scored against this requirement. |
A005 A007 | Security Assess Authorize | QASP — Security authorization |
| PWS 2.4 PERF |
Migrate existing applicant data and in-flight applications from the legacy platform without service interruption to any applicant mid-process Risk R-02 anticipates legacy formatting inconsistency here. |
A009 | Data migration Reconciliation Exception handling | PWS 9.4 — Data migration completed with no service interruption to in-flight applicants Zero applicant-impacting incidents during cutover |
| PWS 2.5 MGMT |
Provide a 6-month Option Period of post-launch stabilization support, including continuous ATO monitoring and defect-fix sustainment, exercisable at FOPBA's discretion based on Base Period performance Option Period exercised early via Mod P00010 (02 Jul 2026), on a FAR 17.207 determination driven by FY2026 appropriations timing rather than by the Base Period performance trigger this paragraph states — assumption A-02 records that the stated trigger did not operate. Traceability is unaffected: the requirement is still owed in full. |
A007 A008 | Monitor Performance | QASP — System availability (post-launch) 99.5% monthly uptime |
| PWS 2.6 DELV |
Deliver all contract data items per the CDRL on the schedule specified, with each deliverable formally accepted (not merely submitted) by the COR before it is considered complete Acceptance, not submission, discharges the obligation. |
All 10 data items | CDRL deliverable submissions | QASP — CDRL deliverable submissions No more than 1 rejection cycle per item |
PWS §3 · Period of Performance 2 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 3.1 MGMT |
Base Period — 12 months — portal build, ATO authorization, data migration, and production cutover Baseline schedule is a data item; the period itself is a contract term. |
A002 | Not test-verified | QASP — Monthly status reporting Submitted by CDRL due date, no material omissions |
| PWS 3.2 MGMT |
Option Period — 1 × 6-month option — post-launch stabilization support, exercised via Mod P00010 Exercised by CO action (Mod P00010), not automatic extension. |
A002 | Not test-verified | QASP — Monthly status reporting Submitted by CDRL due date, no material omissions |
PWS §4 · Deliverables (CDRL Summary) 1 requirement
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 4.1 DELV |
All deliverables are enumerated with due dates, formats, and acceptance criteria in the Contract Data Requirements List — 10 line items in total, spanning the Project Management Plan (A001), Integrated Master Schedule (A002), Section 508 Test Plan and Report (A004/A006), System Security Plan and ATO package (A005/A007), Monthly Status Reports (A008), the data migration validation report (A009), and final closeout certification (A010). Each is formally accepted by the COR, not merely submitted — a distinction that matters because a submitted-but-rejected deliverable does not satisfy the contract, and re-submission timelines are tracked against the original due date, not reset by the rejection. Re-submission runs against the original due date. |
All 10 data items | CDRL deliverable submissions | PWS 9.1 — CDRL deliverables submitted on or before the due date specified 98% on-time submission rate |
PWS §5 · Success Criteria & Performance Standards 5 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 5.1 PERF |
ATO granted and production cutover completed within the Base Period, with zero unplanned service interruption for applicants with in-flight applications Gates Milestone Gate 1 (14 Dec 2026). |
A007 A009 | Authorize Reconciliation | PWS 9.4 — Data migration completed with no service interruption to in-flight applicants Zero applicant-impacting incidents during cutover |
| PWS 5.2 CMPL |
Independent Section 508 audit finds full conformance (or all findings remediated) prior to go-live | A006 | Pre-audit Government audit | QASP — Section 508 conformance Zero Level A/AA violations at go-live |
| PWS 5.3 DELV |
All 10 CDRL line items accepted by the COR, none rejected more than once The AQL is "no more than 1 rejection cycle per item". |
All 10 data items | CDRL deliverable submissions | QASP — CDRL deliverable submissions No more than 1 rejection cycle per item |
| PWS 5.4 MGMT |
QASP surveillance metrics remain within acceptable range across the period of performance (see the QASP for the specific surveillance methods and metrics) | A008 | Monthly status reporting | QASP — Monthly status reporting Submitted by CDRL due date, no material omissions |
| PWS 5.5 MGMT |
Total Task Order cost remains within the Firm-Fixed-Price baseline plus any Contracting-Officer-approved modifications — no unapproved cost growth Verified against the Task Order Budget and Contract Modification Log, not by test. |
No data item | Not test-verified | No surveillance area |
PWS §6 · Constraints & Assumptions 2 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 6.1 CMPL |
all delivery-team personnel handling applicant PII or supporting the ATO/RMF security authorization must be U.S. persons performing work onshore — no offshore staffing is permitted on this Task Order, unlike the Agile suite's commercial program. Restated at PWS 7.1 and PWS 10.4 — see gap G-04. |
A005 | Security | No surveillance area |
| PWS 6.2 MGMT |
The Firm-Fixed-Price structure means Acme Federal Systems bears internal cost-overrun risk; FOPBA's exposure is limited to the negotiated price plus approved modifications. FFP risk allocation; a contract term, not a verifiable behaviour. |
No data item | Not test-verified | No surveillance area |
PWS §7 · Place of Performance 2 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 7.1 CMPL |
Primarily remote/contractor-site performance. All personnel handling applicant PII or ATO/RMF-scoped work must be U.S. persons performing work from within the United States (see Constraints, Section 6) — this is an onshore-location requirement, not a requirement to work from a specific government facility. Restatement of PWS 6.1. |
A005 | Security | No surveillance area |
| PWS 7.2 MGMT |
Up to 4 on-site visits to FOPBA headquarters per Base Period are anticipated for Milestone Gate reviews, ATO briefings to the Agency Authorizing Official, and kickoff/closeout meetings; travel for these visits is priced into the Task Order rather than billed as a separate travel line item. Travel priced into the Task Order; tracked administratively. |
No data item | Not test-verified | No surveillance area |
PWS §8 · Government Furnished Property & Information (GFP/GFI) 3 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 8.1 GFP |
Legacy System Read Access — FOPBA provides contractor read access to the legacy benefits portal database and application server logs for migration planning and validation (RAIDD Log, Assumption A-01) FOPBA obligation. Assumption A-01; Mod P00002 extended the window when it slipped. |
No data item | Not test-verified | No surveillance area |
| PWS 8.2 GFP |
GFE Network / VPN — FOPBA-managed VPN connectivity into the government furnished environment (GFE) for deployment and testing against non-production instances FOPBA obligation. Assumption A-04; issue I-05 records GFE VPN latency against it. |
No data item | Not test-verified | No surveillance area |
| PWS 8.3 GFP |
Existing Eligibility Rules Documentation — FOPBA-maintained business rules documentation for benefit eligibility logic, provided as reference — the contractor does not alter eligibility rules (see Scope, Section 2) FOPBA obligation. No RAIDD entry — see gap G-05. |
No data item | Not test-verified | No surveillance area |
PWS §9 · Performance Requirements Summary Matrix 4 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 9.1 DELV |
CDRL deliverables submitted on or before the due date specified | All 10 data items | CDRL deliverable submissions | PWS 9.1 — CDRL deliverables submitted on or before the due date specified 98% on-time submission rate |
| PWS 9.2 CMPL |
Section 508 / WCAG 2.1 AA conformance on all delivered UI components | A006 | Accessibility System Government audit | PWS 9.2 — Section 508 / WCAG 2.1 AA conformance on all delivered UI components Zero unremediated Level A/AA failures at CDRL A006 acceptance |
| PWS 9.3 CMPL |
Zero unauthorized applicant PII disclosure incidents Zero tolerance — no sampling; continuous monitoring. |
A005 A007 | Security | PWS 9.3 — Zero unauthorized applicant PII disclosure incidents Zero tolerance |
| PWS 9.4 PERF |
Data migration completed with no service interruption to in-flight applicants | A009 | Data migration Reconciliation | PWS 9.4 — Data migration completed with no service interruption to in-flight applicants Zero applicant-impacting incidents during cutover |
PWS §10 · Applicable Federal Requirements 5 requirements
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| PWS 10.1 MGMT |
Federal Acquisition Regulation (FAR) clauses incorporated by reference in the Task Order Administered by the CO; incorporated by reference. |
No data item | Not test-verified | No surveillance area |
| PWS 10.2 CMPL |
Section 508 of the Rehabilitation Act — accessibility conformance | A004 A006 | Accessibility | QASP — Section 508 conformance Zero Level A/AA violations at go-live |
| PWS 10.3 CMPL |
Risk Management Framework (RMF) — security authorization prior to go-live (ATO) | A005 A007 | Assess Authorize | QASP — Security authorization |
| PWS 10.4 CMPL |
All delivery-team personnel handling applicant PII or supporting the ATO/RMF security authorization must be U.S. persons performing work onshore — no offshore staffing is permitted on this Task Order Restatement of PWS 6.1. |
A005 | Security | No surveillance area |
| PWS 10.5 MGMT |
HSS-IDIQ labor category schedule — every billed role must map to a pre-negotiated labor category and rate ceiling on the underlying IDIQ contract, verified during the labor-category audit that produced Mod P00009 Verified by the labor-category audit that produced Mod P00009. |
No data item | Not test-verified | No surveillance area |
The matrix — requirements added by modification
These five requirements are as binding as anything in the PWS and are funded at $4,138,000 of the $4,154,000 net modification value. None of them appears in the PWS document.
| Requirement | Statement | Data item | Contractor verification | Government surveillance & AQL |
|---|---|---|---|---|
| M-P00004.1 CMPL |
Multi-Factor Authentication on the citizen-facing portal login flow, per the post-award OMB identity-assurance memo. Changes the authentication control set described in the SSP; the A005 data item was not amended. |
A005 A007 | Security Integration | PWS 9.3 — Zero unauthorized applicant PII disclosure incidents Zero tolerance |
| M-P00006.1 CMPL |
Automated accessibility regression testing executed on every release, alongside manual VPAT testing. Adds a method the A004 Test Plan must describe; A004 was submitted before this mod was executed. |
A004 A006 | Accessibility Build | QASP — Section 508 conformance Zero Level A/AA violations at go-live |
| M-P00008.1 PERF |
Disaster Recovery / COOP failover to a secondary region within FOPBA's required recovery time objective, demonstrated by test. No data item records the DR test result — see gap G-03. |
No data item | Performance | QASP — System availability (post-launch) 99.5% monthly uptime |
| M-P00011.1 PERF |
Mobile-responsive front-end redesign of the citizen-facing portal, which was desktop-only as awarded. FOPBA's 508 program office raised this as an accessibility gap, so it lands inside the strictest AQL on the Task Order. |
A004 A006 | Accessibility System | QASP — Section 508 conformance Zero Level A/AA violations at go-live |
| M-P00011.2 PERF |
Real-time integration to the agency Benefits-Eligibility Verification API, replacing a manual caseworker lookup. Named explicitly in the Test Strategy integration level; no data item — see gap G-01. |
No data item | Integration Security | QASP — System functionality against PWS |
Data items and what they carry
The reverse view: for each CDRL line item, which requirements depend on it. A data item with many requirements behind it is a concentration of risk — a single rejection cycle on A006 puts every accessibility requirement on the Task Order into remediation at once.
| CDRL | Title | DID | Due | Accepting authority | Requirements traced | Status |
|---|---|---|---|---|---|---|
| A001 | Project Management Plan | DI-MGMT-81438 | Task Order + 30 days | COR | — | Accepted |
| A002 | Integrated Master Schedule (IMS) | DI-MGMT-81650 | Task Order + 30 days | COR | 3.1, 3.2 | Accepted |
| A003 | Risk Management Plan (RAIDD Log baseline) | DI-MGMT-81808 | Task Order + 30 days | COR | — | Accepted |
| A004 | Section 508 Test Plan | DI-MISC-80508 | Task Order + 60 days | COR | 10.2, 2.2, M-P00006.1, M-P00011.1 | Accepted |
| A005 | System Security Plan (SSP) | DI-MGMT-82045 | Task Order + 90 days | ISSO / COR | 10.3, 10.4, 2.3, 6.1, 7.1, 9.3, M-P00004.1 | Accepted |
| A006 | Section 508 / VPAT Compliance Test Report | DI-MISC-80784 | Task Order + 180 days | COR | 10.2, 2.2, 5.2, 9.2, M-P00006.1, M-P00011.1 | Pending |
| A007 | Authority to Operate (ATO) Package | DI-MGMT-82046 | Task Order + 210 days | Agency Authorizing Official (AO) | 10.3, 2.3, 2.5, 5.1, 9.3, M-P00004.1 | Pending |
| A008 | Monthly Status Report | DI-MGMT-80368 | 5th of each month | COR | 2.5, 5.4 | Recurring — current |
| A009 | Data Migration Plan & Validation Report | DI-MISC-81234 | Task Order + 150 days | COR | 2.4, 5.1, 9.4 | Under COR Review |
| A010 | Task Order Closeout Report | DI-MGMT-80467 | End of Period of Performance | COR / CO | — | Pending |
Status reflects the current reporting position, Base Period Month 5 of 18 (16 Oct 2026). Five data items are accepted (A001, A002, A003, A004, A005), A009 is submitted and under COR review, A008 is recurring and current, and the remainder are not yet due.
Open traceability gaps
Building this matrix surfaced five gaps. They are recorded here with an owner and a date rather than quietly closed, because a traceability matrix that reports no gaps is usually a matrix that was written to report no gaps.
No data item evidences the delivered system itself
PWS 2.1 is the core capability requirement of this Task Order, and the two capability requirements added by Mod P00011 sit alongside it. None of them trace to a CDRL. All ten data items are management or compliance documents; there is no system acceptance test report. Acceptance of the working portal therefore rests on COR inspection against PWS prose, with no DID-defined acceptance criteria to inspect against.
Why it matters. PWS 5.3 makes "all 10 CDRL line items accepted" a success criterion. A Task Order could satisfy that criterion in full while the portal itself has never been formally accepted against written criteria.
The CDRL was never amended for post-award scope
Four executed modifications added requirements after award. The CDRL still carries exactly the ten line items it carried at award. A004 and A006 must now cover mobile-responsive components and automated regression testing; A005 and A007 must now cover multi-factor authentication. No DID was amended and no due date moved.
Why it matters. The contractor is verifying against a wider requirements baseline than the data items describe. A COR reviewing A006 against its original DID could accept a report that does not cover mobile at all.
The DR/COOP test has no deliverable and no acceptance path
Mod P00008 added a Disaster Recovery / COOP failover test against FOPBA's recovery time objective. The Test & Verification Strategy has a performance level that can execute it, but no CDRL receives the result and no QASP surveillance area names it.
Why it matters. A funded requirement with no acceptance path is a requirement the Government cannot confirm was met, and the contractor cannot prove it delivered.
One constraint is stated three times
The onshore / U.S.-persons constraint appears at PWS 6.1, is restated at PWS 7.1, and appears again at PWS 10.4. All three are traced here as one requirement with two restatements.
Why it matters. Low as written, but a future modification that changes staffing terms must update three paragraphs. Changing one and missing the others leaves the PWS self-contradictory.
One Government-furnished obligation has no RAIDD entry
PWS 8.1 is covered by assumption A-01 and PWS 8.2 by assumption A-04 and issue I-05. PWS 8.3 — FOPBA-maintained eligibility rules documentation — has neither. Mod P00002 is the precedent: a Government-furnished obligation slipped and cost fifteen days.
Why it matters. Contractor traceability for a Government obligation terminates in a dependency, not a verification. Without a RAIDD entry there is nothing tracking whether the obligation was met.
How this matrix is kept true
It is regenerated, not edited. The generator reads the PWS anchors, the CDRL records, the Contract Modification Log, the QASP surveillance table and the Test & Verification Strategy tables, and aborts before writing if a requirement in the trace map is missing from the PWS, a PWS paragraph is missing from the trace map, a CDRL identifier does not exist, a verification method is not one the Test Strategy actually defines, a surveillance area is not one the QASP actually lists, or an owner is not on the Resource Plan roster.
That last set of checks is the useful part. A matrix whose validation cannot fail is decoration. Regenerating this one after any change to the PWS, the CDRL, or an executed modification is what keeps it a control rather than a record of what was once true.