← Federal Contracting Suite Task Order 3 · Quality & Verification

Test & Verification Strategy

Download Word

The contractor's approach to verifying that BenefitConnect Portal Modernization (Task Order 3 under HSS-IDIQ) meets its PWS requirements before the Government inspects them. This document belongs to Acme Federal Systems; it is not the Government's surveillance instrument. That is the QASP, and the distinction between the two is the first thing this strategy sets out — because on a firm-fixed-price task order, misunderstanding it is expensive.

FFP
Rework is contractor cost
3
CDRL test deliverables
6
QA staff, all onshore
Phased
ATO strategy (D-03)
Zero
508 Level A/AA at go-live

01 Purpose, Scope & Contractual Standing

This strategy governs all verification activity performed by the contractor under Task Order 3: functional testing, Section 508 accessibility verification, security control assessment in support of the ATO, data migration validation, and regression across the Base and Option Periods. It applies to every CDRL deliverable and every release into the Government test environment.

Why this matters commercially

This is a firm-fixed-price task order. Under FFP, the Government pays the agreed price regardless of how much effort the contractor expends. Every rejected CDRL, every rework cycle, and every failed accessibility audit is absorbed by Acme Federal Systems, not billed. First-pass acceptance is therefore not merely a quality aspiration — it is the primary lever protecting task-order margin. That commercial reality shapes this strategy more than any methodology preference.

In scope

Out of scope

02 Relationship to the QASP — Two Documents, Two Parties

These are frequently conflated, and the consequences of conflating them fall entirely on the contractor.

QASPThis Test & Verification Strategy
Whose documentThe Government'sThe contractor's
PurposeHow the COR will surveil contractor performance and what happens when it is unacceptableHow the contractor assures performance is acceptable before it is surveilled
OwnerM. Whitcombe (COR), under A. Reyes (CO)N. Castellano (QA Lead), under C. Tyrrell (Task Order PM)
ContainsPerformance standards, surveillance methods, Acceptable Quality Levels, remediesTest levels, methods, entry/exit criteria, environments, defect handling, evidence production
Consequence of failureWithheld payment, corrective action request, cure noticeRework at contractor cost; CDRL rejection cycle; schedule pressure on gates
The operating principle. Every Acceptable Quality Level in the QASP is a target the contractor must hit. This strategy exists so that no AQL is ever discovered to be missed by the COR — the contractor's own verification finds it first. Section 10 maps each AQL to the internal verification that assures it.

03 Test Artifacts Are Contract Deliverables

Unlike commercial delivery, where test documentation is an internal work product, three test artifacts on this task order are CDRL deliverables with due dates, Data Item Description-referenced acceptance criteria, and formal rejection cycles.

CDRLDeliverableTest relevanceAcceptance risk
A004Section 508 Test PlanDefines how conformance will be verified; must satisfy the Government before testing beginsRejection delays all 508 verification
A006Section 508 / VPAT Compliance Test ReportEvidence of conformance; feeds the independent Government auditDirectly gates go-live under the QASP AQL
A009Data Migration Plan & Validation ReportEvidence that legacy applicant data migrated completely and accuratelyGates migration acceptance; exposed to risk R-02
A005 / A007SSP · ATO PackageSecurity control implementation and assessment evidenceGates the authorization decision (R-01)
Implication for the schedule. The QASP's AQL for CDRL submissions permits no more than one rejection cycle per item. A test report is therefore not "done when testing is done" — it is done when it is written to the DID's acceptance criteria. Report preparation is planned as work in the IMS, not treated as administrative overhead at the end of a test window.

04 Verification Organization

All verification staff are onshore US. No offshore staffing is permitted under this task order due to PII and ATO constraints — a restriction that removes surge capacity and is tracked as risk R-05.

NameRolePeriodVerification responsibility
N. CastellanoQA LeadBase + OptionOwns this strategy, test planning, exit criteria, CDRL test reports
P. ManningQA Automation EngineerBase + OptionRegression automation, CI integration, pipeline gating
N. BeaumontQA Automation EngineerBase onlyAutomation build-out during Base Period delivery
A. ByrneQA Tester (Manual/Regression)Base + OptionFunctional and regression execution
L. SorensonQA Tester (Manual)Base onlyFunctional execution, exploratory testing
M. DelvecchioQA Tester (Manual)Base onlyFunctional execution, migration reconciliation support
P. DuvallSection 508 / Accessibility Compliance LeadBase only508 test plan (A004), conformance verification, VPAT authorship (A006)
T. AbernathyISSO — ATO Package OwnerBase + OptionSecurity control evidence, SSP, POA&M, assessment liaison
D. VasquezSecurity EngineerBase + OptionAPI integration security review (P00011 scope)
Key-person exposure is real and named. Risk R-06 records that Section 508 and ATO knowledge is concentrated in two individuals — P. Duvall and T. Abernathy — and that either's unplanned absence would stall a compliance gate. Both hold Base-only or gate-critical roles. Mitigation is deliberate cross-training of N. Castellano on 508 verification method and of D. Vasquez on ATO evidence assembly, plus written procedure rather than tacit knowledge. This is documented here because a verification strategy that depends on two irreplaceable people is not a strategy.

05 Standards & Framework Alignment

AuthorityApplies toUse on this task order
Section 508 of the Rehabilitation Act (WCAG 2.1 AA via the Revised 508 Standards)All citizen-facing functionalityConformance target; basis of the VPAT and the QASP's zero Level A/AA AQL
NIST SP 800-37 (RMF)Authorization processStructures the security assessment supporting a phased ATO (D-03)
NIST SP 800-53Security & privacy controlsControl selection and assessment evidence in the SSP (A005)
FISMAAgency security obligationWhy the ATO gate exists and cannot be waived by schedule pressure
ISO/IEC/IEEE 29119Test process & documentationMethod basis for test levels, documentation and risk-based approach
FAR / task-order termsAcceptance and remediesGoverns inspection, acceptance, and consequences of nonconformance

06 Test Levels

LevelOwnerScopeAutomation
UnitDevelopers (Marston, Colville, Ibrahim, Petrov)Components and servicesAutomated in CI on every commit
IntegrationQA + K. LindqvistInternal services and the Benefits-Eligibility Verification APIAutomated contract and interface tests
SystemQA (Castellano)End-to-end citizen journeys — eligibility, application, status, notificationPartially automated; exploratory alongside
AccessibilityP. DuvallAll citizen-facing screens and flowsAutomated scanning plus mandatory manual assistive-technology testing
SecurityT. Abernathy / D. VasquezControl implementation, vulnerability scanning, API securityAutomated scanning; manual assessment
Data migrationQA + BA (Okonkwo)Completeness, accuracy, reconciliation of legacy applicant dataAutomated reconciliation; manual sampling
PerformanceS. Vance (DevOps) + QALoad at projected citizen volume, including peak enrollment periodsAutomated load harness
Government acceptanceM. Whitcombe (COR)Inspection against PWS and CDRL acceptance criteriaGovernment-performed

07 Section 508 Accessibility Verification

Accessibility carries the strictest AQL on this task order: zero Level A/AA violations at go-live, verified by an independent Government accessibility audit rather than contractor self-attestation. Decision D-01 settled that explicitly.

What D-01 changes. Because the contractor cannot self-attest, contractor 508 testing has one job: ensure the independent audit finds nothing. A VPAT that reports conformance the auditor then contradicts is worse than no VPAT — it damages credibility with the COR and triggers a CDRL rejection on A006. Contractor testing is therefore deliberately more conservative than the audit is expected to be.

Verification method

StageActivityEvidence
DesignAccessibility requirements embedded in acceptance criteria; design review against WCAG 2.1 AA before buildReviewed designs
BuildAutomated accessibility scanning integrated into CI; violations fail the buildPipeline records
ComponentManual keyboard-only navigation and screen-reader verification per componentComponent checklists
SystemFull assistive-technology testing across complete citizen journeys — screen reader, magnification, keyboard-only, voice controlTest results feeding A006
Pre-auditInternal conformance review against all applicable WCAG criteria; remediation of every finding regardless of severityInternal audit report
Government auditIndependent audit (D-01); contractor supports and remediates findingsAudit result; VPAT (A006) finalized

Automated scanning is treated as a filter, not a verdict. Automated tools reliably detect only a portion of accessibility defects; the criteria that matter most to a benefits applicant — meaningful focus order, comprehensible error recovery, clear form labelling under stress — are found by a human using assistive technology, which is why manual testing is mandatory rather than supplementary.

08 Security Control Assessment & ATO Support

The ATO is the single largest schedule risk on this task order. Risk R-01 — an assessment finding delaying Milestone Gate 1 beyond 14 December 2026 — is rated 9 (High/High), the highest on the register.

Phased authorization approach

Decision D-03 established a phased ATO — interim authorization for lower-risk components rather than holding all functionality behind a single full-ATO gate. Verification is sequenced to serve that: control evidence is assembled per component boundary so that lower-risk components can be assessed and authorized while higher-risk components are still in remediation, rather than the whole portal waiting on its most difficult control.

RMF activityContractor verification roleArtifact
Categorize & select controlsSupport system categorization; confirm control applicability to the system boundarySSP (A005)
ImplementVerify each control is implemented as described — not merely documented as implementedImplementation evidence
AssessPre-assessment self-testing; vulnerability scanning; remediation before formal assessmentScan results, remediation log
AuthorizeSupport the assessment; maintain the POA&M for open findingsATO Package (A007), POA&M
MonitorContinuous scanning and control re-verification through the Option PeriodMonthly evidence
The discipline that protects Gate 1. Security findings are cheapest before formal assessment and most expensive after. Contractor pre-assessment scanning and self-testing run continuously from the start of build, not as a pre-gate scramble — because a POA&M entry raised during the Government assessment costs schedule, while the same finding caught internally costs only a fix.

09 Data Migration Validation

Risk R-02 anticipates that legacy applicant data has inconsistent formatting complicating migration validation. Because the validation report is a CDRL deliverable (A009), migration quality is contractually visible in a way it usually is not.

StageVerificationAcceptance basis
ProfilingQuantify formatting inconsistency, completeness and duplication in legacy applicant recordsFindings inform the migration plan before build
MappingField-level mapping verified against benefits program rules by the BAMapping approved before trial migration
Trial migrationFull dry run into the test environment; defect capture and rerunClean trial run before production migration
ReconciliationRecord counts, control totals, field-level sampling of migrated applicant records100% count reconciliation; sampling within tolerance
Exception handlingUnmigratable records quarantined, reported and traceable — never silently droppedException report reviewed with the COR
Validation reportA009 authored to its DID acceptance criteriaGovernment acceptance, no more than one rejection cycle

A benefits applicant whose record migrates incorrectly may lose access to a payment they depend on. Migration defects on this system are not data-quality inconveniences; they are citizen-impact events, and are treated at the highest severity accordingly.

10 AQL-Aligned Verification Map

Each Acceptable Quality Level in the QASP is mapped to the internal verification that assures it. This table is the operational heart of the strategy: if it holds, the COR's surveillance finds nothing the contractor has not already found and fixed.

QASP performance areaGovernment AQLContractor verification that assures itOwner
CDRL deliverable submissionsNo more than 1 rejection cycle per itemInternal review against the DID's acceptance criteria before submission; QA Lead sign-off on all test-related CDRLsN. Castellano
Section 508 conformanceZero Level A/AA violations at go-liveCI accessibility gating, manual assistive-technology testing, and a conservative internal pre-audit review remediating every findingP. Duvall
Monthly status reportingSubmitted by CDRL due date, no material omissionsStanding report content checklist; QA metrics compiled continuously rather than assembled at month endD. Ferris
System functionality against PWSMeets PWS performance requirementsRequirements traceability from PWS through test case to result; system-level exit criteriaN. Castellano
Security authorizationATO achieved to support Gate 1Continuous pre-assessment scanning; control evidence verified as implemented; POA&M actively managedT. Abernathy

11 Entry & Exit Criteria

StageEntry criteriaExit criteria
System testIntegration complete; environment stable; traceability matrix current100% of PWS-traced critical scenarios passed; no open critical or high defects; performance targets met
508 pre-audit reviewSystem test exit met; automated scans clean; manual component checks completeZero known Level A/AA findings; A006 draft complete
Security assessment supportControls implemented and evidenced; internal scans remediatedAssessment complete; POA&M contains no high-severity open items blocking authorization
Migration production runClean trial migration; reconciliation automated; exception handling verifiedCount reconciliation 100%; sampling within tolerance; A009 accepted
Government acceptanceAll above complete; CDRLs submitted to DID criteriaCOR acceptance recorded on the Deliverable Acceptance Log

12 Defect Management & CDRL Rejection Handling

SeverityDefinitionResponse
CriticalCitizen cannot complete a benefits action; PII exposure; incorrect eligibility outcome; migration data lossImmediate; blocks release absolutely
HighLevel A/AA accessibility violation; major function unusable; security finding requiring POA&MFixed before the applicable gate; blocks release
MediumImpaired function with acceptable workaroundScheduled within the release; disclosed to the COR
LowCosmetic or minor usabilityBacklog

If a CDRL is rejected

13 Test Environments & Data

EnvironmentPurposeData
DevelopmentUnit and component testingSynthetic only
Integration/TestIntegration, system, accessibility, regressionSynthetic and de-identified applicant records
Migration stagingTrial migration and reconciliationDe-identified production-derived legacy data
Security assessmentScanning and control assessmentRepresentative configuration matching production
Government testGovernment inspection and acceptancePer Government direction

14 Automation & Regression

With six QA staff — four of them Base-period only — regression cannot be manual and still fit the Option Period. Automation is a staffing strategy as much as a quality one.

Deliberate sequencing. Four of the six QA staff (Sorenson, Delvecchio, Beaumont, plus 508 Lead Duvall) are Base-period only. Automation coverage must therefore be substantially complete before the Base Period ends, or Option Period regression becomes unaffordable. This is a verification-capacity constraint driven by the staffing profile, and it is why automation build-out is front-loaded rather than incremental.

15 Metrics & Reporting

MetricPurposeTargetReported in
CDRL first-pass acceptance rateDirect proxy for the QASP AQL and for FFP margin100%Monthly Status Report (A008)
PWS requirements traced and testedEvidence of coverage at acceptance100% of critical requirementsGate reviews
Open Level A/AA accessibility findingsLeading indicator for the 508 AQLZero at go-liveMonthly; weekly near gates
Open POA&M items by severityATO readiness (risk R-01)No high-severity blocking itemsMonthly
Automated regression coverageOption Period sustainabilityCritical journeys fully automated by Base Period endMonthly
Defect escape to Government testEffectiveness of internal verificationZero critical; downward trendMonthly

16 Risks to the Verification Approach

RiskEffect on verificationMitigation
R-01 — ATO finding delays Gate 1 (14 Dec 2026)Authorization gate slips; downstream testing compressesContinuous pre-assessment scanning; phased ATO (D-03) so lower-risk components proceed
R-02 — legacy data formatting inconsistencyMigration validation expands; A009 at riskEarly profiling; exception handling designed in; reconciliation automated
R-05 — all-onshore constraint limits surge capacityNo ability to add test capacity quickly if staff attriteAutomation-first regression; cross-training; capacity risk surfaced early to the COR
R-06 — 508/ATO knowledge concentrated in two peopleEither absence stalls a compliance gateDocumented procedure over tacit knowledge; deliberate cross-training (Section 04)
Base-only staffing profileOption Period verification capacity drops sharplyAutomation completed during Base Period; regression suite owned and maintainable by remaining staff
Governing relationship. This strategy is subordinate to the PWS and the Task Order Management Plan, and is written to satisfy the QASP's Acceptable Quality Levels. It is the parent of the Section 508 Test Plan (CDRL A004) and of the verification content within the Data Migration Plan (A009). Changes with cost or schedule impact route through the formal Contract Modification process per decision D-04 — not absorbed within existing CDRL baselines.