The contractor's approach to verifying that BenefitConnect Portal Modernization (Task Order 3 under HSS-IDIQ) meets its PWS requirements before the Government inspects them. This document belongs to Acme Federal Systems; it is not the Government's surveillance instrument. That is the QASP, and the distinction between the two is the first thing this strategy sets out — because on a firm-fixed-price task order, misunderstanding it is expensive.
FFP
Rework is contractor cost
Phased
ATO strategy (D-03)
Zero
508 Level A/AA at go-live
01 Purpose, Scope & Contractual Standing
This strategy governs all verification activity performed by the contractor under Task Order 3: functional testing, Section 508 accessibility verification, security control assessment in support of the ATO, data migration validation, and regression across the Base and Option Periods. It applies to every CDRL deliverable and every release into the Government test environment.
Why this matters commercially
This is a firm-fixed-price task order. Under FFP, the Government pays the agreed price regardless of how much effort the contractor expends. Every rejected CDRL, every rework cycle, and every failed accessibility audit is absorbed by Acme Federal Systems, not billed. First-pass acceptance is therefore not merely a quality aspiration — it is the primary lever protecting task-order margin. That commercial reality shapes this strategy more than any methodology preference.
In scope
- The citizen-facing BenefitConnect portal, its mobile-responsive redesign, and the Benefits-Eligibility Verification API integration added under modification P00011.
- Legacy applicant data migration and its validation (CDRL A009).
- Section 508 conformance verification ahead of independent Government audit (CDRLs A004, A006).
- Security control implementation evidence supporting the ATO package (CDRLs A005, A007).
Out of scope
- Government-performed surveillance, inspection and acceptance — governed by the QASP.
- The independent Government accessibility audit itself (decision D-01) — the contractor prepares for it and remediates against it, but does not perform it.
- Testing of Government-furnished systems beyond the defined interfaces.
02 Relationship to the QASP — Two Documents, Two Parties
These are frequently conflated, and the consequences of conflating them fall entirely on the contractor.
| QASP | This Test & Verification Strategy |
| Whose document | The Government's | The contractor's |
| Purpose | How the COR will surveil contractor performance and what happens when it is unacceptable | How the contractor assures performance is acceptable before it is surveilled |
| Owner | M. Whitcombe (COR), under A. Reyes (CO) | N. Castellano (QA Lead), under C. Tyrrell (Task Order PM) |
| Contains | Performance standards, surveillance methods, Acceptable Quality Levels, remedies | Test levels, methods, entry/exit criteria, environments, defect handling, evidence production |
| Consequence of failure | Withheld payment, corrective action request, cure notice | Rework at contractor cost; CDRL rejection cycle; schedule pressure on gates |
The operating principle. Every Acceptable Quality Level in the QASP is a target the contractor must hit. This strategy exists so that no AQL is ever discovered to be missed by the COR — the contractor's own verification finds it first. Section 10 maps each AQL to the internal verification that assures it.
03 Test Artifacts Are Contract Deliverables
Unlike commercial delivery, where test documentation is an internal work product, three test artifacts on this task order are CDRL deliverables with due dates, Data Item Description-referenced acceptance criteria, and formal rejection cycles.
| CDRL | Deliverable | Test relevance | Acceptance risk |
| A004 | Section 508 Test Plan | Defines how conformance will be verified; must satisfy the Government before testing begins | Rejection delays all 508 verification |
| A006 | Section 508 / VPAT Compliance Test Report | Evidence of conformance; feeds the independent Government audit | Directly gates go-live under the QASP AQL |
| A009 | Data Migration Plan & Validation Report | Evidence that legacy applicant data migrated completely and accurately | Gates migration acceptance; exposed to risk R-02 |
| A005 / A007 | SSP · ATO Package | Security control implementation and assessment evidence | Gates the authorization decision (R-01) |
Implication for the schedule. The QASP's AQL for CDRL submissions permits no more than one rejection cycle per item. A test report is therefore not "done when testing is done" — it is done when it is written to the DID's acceptance criteria. Report preparation is planned as work in the
IMS, not treated as administrative overhead at the end of a test window.
04 Verification Organization
All verification staff are onshore US. No offshore staffing is permitted under this task order due to PII and ATO constraints — a restriction that removes surge capacity and is tracked as risk R-05.
| Name | Role | Period | Verification responsibility |
| N. Castellano | QA Lead | Base + Option | Owns this strategy, test planning, exit criteria, CDRL test reports |
| P. Manning | QA Automation Engineer | Base + Option | Regression automation, CI integration, pipeline gating |
| N. Beaumont | QA Automation Engineer | Base only | Automation build-out during Base Period delivery |
| A. Byrne | QA Tester (Manual/Regression) | Base + Option | Functional and regression execution |
| L. Sorenson | QA Tester (Manual) | Base only | Functional execution, exploratory testing |
| M. Delvecchio | QA Tester (Manual) | Base only | Functional execution, migration reconciliation support |
| P. Duvall | Section 508 / Accessibility Compliance Lead | Base only | 508 test plan (A004), conformance verification, VPAT authorship (A006) |
| T. Abernathy | ISSO — ATO Package Owner | Base + Option | Security control evidence, SSP, POA&M, assessment liaison |
| D. Vasquez | Security Engineer | Base + Option | API integration security review (P00011 scope) |
Key-person exposure is real and named. Risk R-06 records that Section 508 and ATO knowledge is concentrated in two individuals — P. Duvall and T. Abernathy — and that either's unplanned absence would stall a compliance gate. Both hold Base-only or gate-critical roles. Mitigation is deliberate cross-training of N. Castellano on 508 verification method and of D. Vasquez on ATO evidence assembly, plus written procedure rather than tacit knowledge. This is documented here because a verification strategy that depends on two irreplaceable people is not a strategy.
05 Standards & Framework Alignment
| Authority | Applies to | Use on this task order |
| Section 508 of the Rehabilitation Act (WCAG 2.1 AA via the Revised 508 Standards) | All citizen-facing functionality | Conformance target; basis of the VPAT and the QASP's zero Level A/AA AQL |
| NIST SP 800-37 (RMF) | Authorization process | Structures the security assessment supporting a phased ATO (D-03) |
| NIST SP 800-53 | Security & privacy controls | Control selection and assessment evidence in the SSP (A005) |
| FISMA | Agency security obligation | Why the ATO gate exists and cannot be waived by schedule pressure |
| ISO/IEC/IEEE 29119 | Test process & documentation | Method basis for test levels, documentation and risk-based approach |
| FAR / task-order terms | Acceptance and remedies | Governs inspection, acceptance, and consequences of nonconformance |
06 Test Levels
| Level | Owner | Scope | Automation |
| Unit | Developers (Marston, Colville, Ibrahim, Petrov) | Components and services | Automated in CI on every commit |
| Integration | QA + K. Lindqvist | Internal services and the Benefits-Eligibility Verification API | Automated contract and interface tests |
| System | QA (Castellano) | End-to-end citizen journeys — eligibility, application, status, notification | Partially automated; exploratory alongside |
| Accessibility | P. Duvall | All citizen-facing screens and flows | Automated scanning plus mandatory manual assistive-technology testing |
| Security | T. Abernathy / D. Vasquez | Control implementation, vulnerability scanning, API security | Automated scanning; manual assessment |
| Data migration | QA + BA (Okonkwo) | Completeness, accuracy, reconciliation of legacy applicant data | Automated reconciliation; manual sampling |
| Performance | S. Vance (DevOps) + QA | Load at projected citizen volume, including peak enrollment periods | Automated load harness |
| Government acceptance | M. Whitcombe (COR) | Inspection against PWS and CDRL acceptance criteria | Government-performed |
07 Section 508 Accessibility Verification
Accessibility carries the strictest AQL on this task order: zero Level A/AA violations at go-live, verified by an independent Government accessibility audit rather than contractor self-attestation. Decision D-01 settled that explicitly.
What D-01 changes. Because the contractor cannot self-attest, contractor 508 testing has one job: ensure the independent audit finds nothing. A VPAT that reports conformance the auditor then contradicts is worse than no VPAT — it damages credibility with the COR and triggers a CDRL rejection on A006. Contractor testing is therefore deliberately more conservative than the audit is expected to be.
Verification method
| Stage | Activity | Evidence |
| Design | Accessibility requirements embedded in acceptance criteria; design review against WCAG 2.1 AA before build | Reviewed designs |
| Build | Automated accessibility scanning integrated into CI; violations fail the build | Pipeline records |
| Component | Manual keyboard-only navigation and screen-reader verification per component | Component checklists |
| System | Full assistive-technology testing across complete citizen journeys — screen reader, magnification, keyboard-only, voice control | Test results feeding A006 |
| Pre-audit | Internal conformance review against all applicable WCAG criteria; remediation of every finding regardless of severity | Internal audit report |
| Government audit | Independent audit (D-01); contractor supports and remediates findings | Audit result; VPAT (A006) finalized |
Automated scanning is treated as a filter, not a verdict. Automated tools reliably detect only a portion of accessibility defects; the criteria that matter most to a benefits applicant — meaningful focus order, comprehensible error recovery, clear form labelling under stress — are found by a human using assistive technology, which is why manual testing is mandatory rather than supplementary.
08 Security Control Assessment & ATO Support
The ATO is the single largest schedule risk on this task order. Risk R-01 — an assessment finding delaying Milestone Gate 1 beyond 14 December 2026 — is rated 9 (High/High), the highest on the register.
Phased authorization approach
Decision D-03 established a phased ATO — interim authorization for lower-risk components rather than holding all functionality behind a single full-ATO gate. Verification is sequenced to serve that: control evidence is assembled per component boundary so that lower-risk components can be assessed and authorized while higher-risk components are still in remediation, rather than the whole portal waiting on its most difficult control.
| RMF activity | Contractor verification role | Artifact |
| Categorize & select controls | Support system categorization; confirm control applicability to the system boundary | SSP (A005) |
| Implement | Verify each control is implemented as described — not merely documented as implemented | Implementation evidence |
| Assess | Pre-assessment self-testing; vulnerability scanning; remediation before formal assessment | Scan results, remediation log |
| Authorize | Support the assessment; maintain the POA&M for open findings | ATO Package (A007), POA&M |
| Monitor | Continuous scanning and control re-verification through the Option Period | Monthly evidence |
The discipline that protects Gate 1. Security findings are cheapest before formal assessment and most expensive after. Contractor pre-assessment scanning and self-testing run continuously from the start of build, not as a pre-gate scramble — because a POA&M entry raised during the Government assessment costs schedule, while the same finding caught internally costs only a fix.
09 Data Migration Validation
Risk R-02 anticipates that legacy applicant data has inconsistent formatting complicating migration validation. Because the validation report is a CDRL deliverable (A009), migration quality is contractually visible in a way it usually is not.
| Stage | Verification | Acceptance basis |
| Profiling | Quantify formatting inconsistency, completeness and duplication in legacy applicant records | Findings inform the migration plan before build |
| Mapping | Field-level mapping verified against benefits program rules by the BA | Mapping approved before trial migration |
| Trial migration | Full dry run into the test environment; defect capture and rerun | Clean trial run before production migration |
| Reconciliation | Record counts, control totals, field-level sampling of migrated applicant records | 100% count reconciliation; sampling within tolerance |
| Exception handling | Unmigratable records quarantined, reported and traceable — never silently dropped | Exception report reviewed with the COR |
| Validation report | A009 authored to its DID acceptance criteria | Government acceptance, no more than one rejection cycle |
A benefits applicant whose record migrates incorrectly may lose access to a payment they depend on. Migration defects on this system are not data-quality inconveniences; they are citizen-impact events, and are treated at the highest severity accordingly.
10 AQL-Aligned Verification Map
Each Acceptable Quality Level in the QASP is mapped to the internal verification that assures it. This table is the operational heart of the strategy: if it holds, the COR's surveillance finds nothing the contractor has not already found and fixed.
| QASP performance area | Government AQL | Contractor verification that assures it | Owner |
| CDRL deliverable submissions | No more than 1 rejection cycle per item | Internal review against the DID's acceptance criteria before submission; QA Lead sign-off on all test-related CDRLs | N. Castellano |
| Section 508 conformance | Zero Level A/AA violations at go-live | CI accessibility gating, manual assistive-technology testing, and a conservative internal pre-audit review remediating every finding | P. Duvall |
| Monthly status reporting | Submitted by CDRL due date, no material omissions | Standing report content checklist; QA metrics compiled continuously rather than assembled at month end | D. Ferris |
| System functionality against PWS | Meets PWS performance requirements | Requirements traceability from PWS through test case to result; system-level exit criteria | N. Castellano |
| Security authorization | ATO achieved to support Gate 1 | Continuous pre-assessment scanning; control evidence verified as implemented; POA&M actively managed | T. Abernathy |
11 Entry & Exit Criteria
| Stage | Entry criteria | Exit criteria |
| System test | Integration complete; environment stable; traceability matrix current | 100% of PWS-traced critical scenarios passed; no open critical or high defects; performance targets met |
| 508 pre-audit review | System test exit met; automated scans clean; manual component checks complete | Zero known Level A/AA findings; A006 draft complete |
| Security assessment support | Controls implemented and evidenced; internal scans remediated | Assessment complete; POA&M contains no high-severity open items blocking authorization |
| Migration production run | Clean trial migration; reconciliation automated; exception handling verified | Count reconciliation 100%; sampling within tolerance; A009 accepted |
| Government acceptance | All above complete; CDRLs submitted to DID criteria | COR acceptance recorded on the Deliverable Acceptance Log |
12 Defect Management & CDRL Rejection Handling
| Severity | Definition | Response |
| Critical | Citizen cannot complete a benefits action; PII exposure; incorrect eligibility outcome; migration data loss | Immediate; blocks release absolutely |
| High | Level A/AA accessibility violation; major function unusable; security finding requiring POA&M | Fixed before the applicable gate; blocks release |
| Medium | Impaired function with acceptable workaround | Scheduled within the release; disclosed to the COR |
| Low | Cosmetic or minor usability | Backlog |
If a CDRL is rejected
- Rejection is logged and root-caused within two business days — the QASP permits only one rejection cycle before the AQL is missed.
- Correction addresses the specific DID criterion cited, and the same criterion is added to the pre-submission checklist for every subsequent CDRL.
- A second rejection on the same item is escalated by the Task Order PM to the COR proactively, with a corrective action plan, rather than waiting for a cure notice.
13 Test Environments & Data
| Environment | Purpose | Data |
| Development | Unit and component testing | Synthetic only |
| Integration/Test | Integration, system, accessibility, regression | Synthetic and de-identified applicant records |
| Migration staging | Trial migration and reconciliation | De-identified production-derived legacy data |
| Security assessment | Scanning and control assessment | Representative configuration matching production |
| Government test | Government inspection and acceptance | Per Government direction |
- PII never leaves the authorized boundary. All access is onshore US, consistent with the task-order staffing constraint.
- De-identified data retains realistic shape — inconsistent legacy formatting is preserved deliberately, because that inconsistency (risk R-02) is precisely what migration testing must exercise.
14 Automation & Regression
With six QA staff — four of them Base-period only — regression cannot be manual and still fit the Option Period. Automation is a staffing strategy as much as a quality one.
- CI gating: unit tests, static analysis, dependency and vulnerability scanning, and automated accessibility scanning all run per commit; failures block merge.
- Regression suite covering all PWS-traced critical citizen journeys, built during the Base Period while automation staffing is at full strength, so the Option Period can be sustained by a smaller team.
- Continuous security scanning through the Option Period, supporting RMF continuous monitoring obligations.
- Traceability maintained automatically from PWS requirement to test case to result, so the requirements traceability matrix is a live artifact rather than a document rebuilt before each gate.
Deliberate sequencing. Four of the six QA staff (Sorenson, Delvecchio, Beaumont, plus 508 Lead Duvall) are Base-period only. Automation coverage must therefore be substantially complete before the Base Period ends, or Option Period regression becomes unaffordable. This is a verification-capacity constraint driven by the staffing profile, and it is why automation build-out is front-loaded rather than incremental.
15 Metrics & Reporting
| Metric | Purpose | Target | Reported in |
| CDRL first-pass acceptance rate | Direct proxy for the QASP AQL and for FFP margin | 100% | Monthly Status Report (A008) |
| PWS requirements traced and tested | Evidence of coverage at acceptance | 100% of critical requirements | Gate reviews |
| Open Level A/AA accessibility findings | Leading indicator for the 508 AQL | Zero at go-live | Monthly; weekly near gates |
| Open POA&M items by severity | ATO readiness (risk R-01) | No high-severity blocking items | Monthly |
| Automated regression coverage | Option Period sustainability | Critical journeys fully automated by Base Period end | Monthly |
| Defect escape to Government test | Effectiveness of internal verification | Zero critical; downward trend | Monthly |
16 Risks to the Verification Approach
| Risk | Effect on verification | Mitigation |
| R-01 — ATO finding delays Gate 1 (14 Dec 2026) | Authorization gate slips; downstream testing compresses | Continuous pre-assessment scanning; phased ATO (D-03) so lower-risk components proceed |
| R-02 — legacy data formatting inconsistency | Migration validation expands; A009 at risk | Early profiling; exception handling designed in; reconciliation automated |
| R-05 — all-onshore constraint limits surge capacity | No ability to add test capacity quickly if staff attrite | Automation-first regression; cross-training; capacity risk surfaced early to the COR |
| R-06 — 508/ATO knowledge concentrated in two people | Either absence stalls a compliance gate | Documented procedure over tacit knowledge; deliberate cross-training (Section 04) |
| Base-only staffing profile | Option Period verification capacity drops sharply | Automation completed during Base Period; regression suite owned and maintainable by remaining staff |
Governing relationship. This strategy is subordinate to the
PWS and the
Task Order Management Plan, and is written to satisfy the
QASP's Acceptable Quality Levels. It is the parent of the Section 508 Test Plan (CDRL A004) and of the verification content within the Data Migration Plan (A009). Changes with cost or schedule impact route through the formal Contract Modification process per decision
D-04 — not absorbed within existing CDRL baselines.