Sobre esta vaga de 2026-0119 Consultancy Support for CIS Security (NS) - THU 20 Aug na EMW, Inc.
BIDDING INSTRUCTIONS
1. Technical Proposal
In submitting their bids, Bidders shall provide a proposal clearly providing the following information:
a) Proposed approach to address the required scope of work.
Minimum Requirements:
The proposal shall include:
- A clear description of the approach to deliver the full Scope of Work, covering the required GWSW support activities, including: refinement of the NCIA CIS Security Governance Process; alignment with NCIA policies, notices and directives; gap analysis of CIS security roles and responsibilities; update of RACI matrix and development/refinement of Terms of Reference; support to internal and external communication plans.
- A defined delivery methodology (e.g. iterative / Agile approach) aligned with the SOW.
- A milestone plan consistent with the required timeline (2 months).
- Clear linkage between: refinement of the NCIA CIS Security Governance Process; alignment with NCIA policies, notices and directives; gap analysis of CIS security roles and responsibilities; update of RACI matrix and development/refinement of Terms of Reference; support to internal and external communication plans.
Non-Compliance Conditions
The proposal shall be deemed non-compliant if:
- The proposed approach is missing or incomplete.
- The proposed approach does not cover all phases of the SOW.
- The proposed milestone plan is absent or inconsistent with the required delivery structure.
b) Experience of assigned resources.
Minimum Requirements:
The proposal shall demonstrate that the assigned resources collectively have relevant and proven experience directly aligned with the scope of this SOW, including:
- Governance processes in the context of CIS Security.
- Development, refinement, or assessment of security governance roles and responsibilities, including: RACI matrices; Terms of Reference; stakeholder accountability models; governance decision making structures.
- Gap analysis in relation to security governance, including: assessment of existing roles and responsibilities; identification of overlaps, gaps and accountability issues; development of practical recommendations for improvement.
- Development of large and complex communication strategies and communication plans, including: internal stakeholder communication; external stakeholder communication; communication of governance changes; support of organizational change and stakeholder engagement.
- Experience with CIS systems, including military and/or civilian CIS environments.
- Experience with CIS-related international, commercial, or industrial standards.
- Experience in Service Design and Management.
- Knowledge and experience of NATO and/or NCIA environments.
- Preparation of governance documentation, reports, recommendations, and implementation guidance suitable for stakeholder use, including: governance process description; reports and recommendations; RACI matrices; Terms of Reference; GAP analyses; implementation roadmap or action plan; communication plans.
- Possession of NATO SECRET security clearance.
Non-Compliance Conditions
The proposal shall be deemed non-compliant if:
- The proposed team does not demonstrate direct experience in the following areas: CIS security governance; development or refinement of roles and responsibilities, RACI matrices and Terms of Reference; development of communication strategies and communication plans; gap analysis of governance roles, responsibilities and stakeholder accountability.
- Experience is generic, for example limited to general IT governance, standard project management, or advisory work, and is not aligned with the specific scope of this SOW.
- Proposed resources do not meet the minimum seniority expectations or lack relevant experience for their assigned roles.
- The proposal does not demonstrate practical implementation experience (i.e., only advisory or conceptual experience is provided) in delivering governance-related outputs, including RACI matrices, Terms of Reference, communication plans, gap analyses, recommendations or implementation guidance.
- The proposed resource does not hold the required NATO SECRET security clearance.
c) Project Implementation Plan
Minimum Requirements
The proposal shall include a high-level project implementation plan clearly aligned with the scope of this SOW and demonstrating a feasible approach to deliver all required outputs within the required period of performance, covering:
- A structured work plan across all required deliverables, including: Project Kick-off and Requirements Analysis; refinement of the NCIA CIS Security Governance Process; alignment with applicable NATO/NCIA policies, notices and directives; Gap Analysis of CIS security roles and responsibilities; update of the RACI matrix; development or refinement of Terms of Reference; refinement of internal and external Communication Plans; preparation, review, and finalization of all required deliverables.
- A schedule aligned with the required period of performance and milestone dates, including: 15 September 2026 – Project Kick-off and Requirements Analysis; 15 October 2026 – Governance Process refinement and alignment; 15 October 2026 – Gap Analysis – Roles and Responsibilities; 15 November 2026 – Communication Plan.
- Definition of key tasks and deliverables, clearly linked to: SOW objectives; required support activities; applicable KPIs; acceptance criteria; expected review and approval points.
- Identification of key risks and mitigation approaches, including: dependency on NCIA inputs and documentation; stakeholder availability; alignment with NATO/NCIA policies and directives; delivery within the required 2 months' timeframe.
- A reporting and governance approach, including: interaction with the NCIA Task Lead and Point of Contact; milestone reporting by email; incorporation of NCIA feedback; tracking of actions, decisions, risks and issues; peer review of deliverables.
- Clear definition of roles and responsibilities, including responsibility for: governance analysis; gap analysis; RACI matrices; Terms of Reference; communication planning; documentation and report drafting; quality assurance; coordination with NCIA stakeholders.
Non-Compliance Conditions
The proposal shall be deemed non-compliant if:
- The implementation plan does not cover all required deliverables and support activities in the SOW.
- The implementation plan is not aligned with the required period of performance or specific milestone dates.
- Key elements such as tasks, deliverables, milestones, dependencies, risks, mitigation measures, reporting arrangements, or roles and responsibilities are missing or insufficiently described.
- The plan does not demonstrate a feasible approach to delivering both governance refinement activities and communication plan development within the required timeframe.
d) CVs of Assigned Resources
Minimum Requirements
The proposal shall include CVs for all assigned resources, which shall:
- Clearly identify for each resource: assigned role within the project; years of relevant experience; key qualifications and certifications; security clearance level, including confirmation of NATO SECRET clearance where required.
- Demonstrate direct experience aligned with the scope of this SOW, including where applicable: CIS security governance; governance process refinement; gap analysis of roles and responsibilities; development or refinement of RACI matrices; development or refinement of Terms of Reference; communication strategy and communication plan development; CIS systems; Service Design and Management; NATO and/or NCIA experience or comparable environments.
- Demonstrate at least 10 years' relevant experience for the proposed Senior Manager profile.
- Provide evidence of hands-on experience or involvement in relevant activities, including: governance documentation; stakeholder engagement; policy/directive alignment; development of recommendations and implementation guidance.
- Ensure consistency between proposed roles and demonstrated experience.
Non-Compliance Conditions
The proposal shall be deemed non-compliant if:
- CVs are missing for key roles.
- CVs do not demonstrate relevant experience aligned with the SOW scope.
- The proposed Senior Manager does not demonstrate the required 10+ years' relevant experience.
- Proposed resources are assigned to roles inconsistent with their experience.
- The required NATO SECRET security clearance is not demonstrated.
- Experience is purely generic or advisory, without evidence of implementation or delivery.
e) Compliance Matrix
Minimum Requirements
The proposal shall include a compliance matrix that:
- Maps all requirements from: the Scope of Work; the Deliverables, KPIs and Schedule; the Acceptance Criteria; the Required Competencies section; the Security Clearance; the Practical Arrangements sections.
- Clearly indicates for each requirement: how the requirement is addressed; reference to the relevant section(s) of the proposal.
- Demonstrates full coverage of the SOW scope, including: governance process refinement; gap analysis of CIS security roles and responsibilities; RACI matrix; Terms of Reference development/refinement; internal and external communication plan refinement; milestone reporting and progress communication; deliverable review and acceptance.
- Clearly identifies any assumptions or limitations, where applicable.
Non-Compliance Conditions
The proposal shall be deemed non-compliant if:
- The compliance matrix is missing.
- Requirements are not fully mapped, traceable or clearly addressed.
- References to the proposal are incomplete, inaccurate or inconsistent.
- The matrix does not demonstrate coverage of the full scope of work.
Deadline Date: Thursday 20 August 2026
Requirement: Consultancy Support for CIS Security
Location: 70% On-site in Brussels, Belgium; 30% Off-site
Period of Performance: As soon as possible, but not later than 15 September 2026, until 4 December 2026.
Required Security Clearance: NATO SECRET
STATEMENT OF WORK
1. BACKGROUND
The CIS Planning and Implementation Authority (CISPIA) is a role defined in the context of NATO's Security Policy as being responsible to design and implement Communication and Information Systems (CISs), its functionalities, and the required security measures.
CISPIA is responsible to design and implement the corresponding CIS, its functionalities, and the required security measures. For NATO CIS, this shall be accomplished also through the definition and use of security architectures, which will determine how security requirements can be implemented, following a risk-based approach, to meet both security and mission requirements, and associated funding arrangements, in line with extant NATO Security Policy and supporting directives.
As part of the Get Well – Stay Well Project (GWSW), NCIA enhances its continuous visibility into the security posture of its systems and provides objective evidence that NCIA is compliant with the established security policies.
The NCIA is seeking subject matter experts (SMEs) to enhance the CIS security in support of the GWSW mission.
2. OBJECTIVES
Under the direction / guidance of the local NCIA Point of Contact, the objectives of the service are:
- Deliver SME expertise and recommendations in support of the GWSW project.
- Strengthen the communication strategy and governance framework in support of the GWSW project.
- Support NCIA's alignment with applicable NATO and NCIA security policies, directives and governance requirements.
3. SCOPE OF WORK
3.1 Scope Overview
The Contractor is to provide support services to the GWSW Project, by developing gap analyses and enhancement of governance processes. The NCIA GWSW project team will furnish the contractor with all relevant documentation such as the drafted communication strategy and initial communication plan, the Roles and Responsibilities and the developed governance processes, as well as with all relevant directives and documentation.
The scope of this contract covers the following activities/deliverables:
- Support in the refinement of the NCIA CIS Security Governance Process in alignment with applicable NATO/NCIA policies, notices and directives.
- Gap analysis: Roles and Responsibilities of the CIS security functions, including monitoring and updating Roles and Responsibilities and the RACI Matrix, and developing Terms of Reference.
- Supporting the development of internal and external communication plans.
NCIA staff will provide oversight and inputs that shall be taken into account in the conduct of the service but which shall not waive the contractor's responsibility for the deliverables.
The contractor will be responsible for managing their own working time in order to meet the agreed deliverables by their respective due dates.
4. DELIVERABLES AND PAYMENT MILESTONES
This section thoroughly describes the deliverables and payment milestones. All deliverables are to be peer reviewed within their delivery cycle. Input and guidance will be provided by NCIA in written form and/or during the targeted review meetings.
During the period of performance, a Delivery Acceptance Sheet (DAS) shall be provided to the Purchaser for each scheduled delivery, as identified in Section 4.1. The Purchaser will confirm acceptance by signing the DAS.
The following deliverables are expected from the service on this Statement of Work:
4.1 Deliverables, Key Performance Indicators and Schedule
The contractor shall undertake the necessary research and evaluation to provide the following deliverables by their respective due dates.
Deliverable 1: Project Kick-off and Requirements Analysis: Kick-off meeting minutes including the analysis of the project requirements and activities that shall be performed during the period of performance, an initial roadmap and review of milestones.
KPIs: KPI 1.0: 100% analysis of the project requirements completed. KPI 1.1: 100% initial roadmap and review of milestones completed.
Due Date: 15 September 2026
Payment Milestone: M1 – 15% of total awarded value
Deliverable 2: Governance Process Refinement and Alignment: Review and refine governance processes, align these with applicable NCIA policies, notices and directives, and update the supporting documentation.
KPIs: KPI 2.1: 100% of in-scope governance processes reviewed and required refinements addressed and documented. KPI 2.2: 100% alignment with AN 24.002 confirmed through a completed gap analysis and matrix. KPI 2.3: 100% updated governance documentation delivered on time and accepted by GWSW management.
Due Date: 15 October 2026
Payment Milestone: M2 – 35% of total awarded value
Deliverable 3: Gap Analysis – Roles & Responsibilities: Assess and refine roles and responsibilities against applicable NATO security directives and applicable NCIA policies, notices and directives.
KPIs: KPI 3.1: 100% gap analysis completed against applicable NATO Security Directives and AN 24.002. KPI 3.2: 100% of roles and responsibilities for the functions reviewed and updated (RACI matrix and Terms of Reference developed/refined). KPI 3.3: 100% of gaps identified and recommendations delivered.
Due Date: 15 October 2026
Payment Milestone: M3 – 25% of total awarded value
Deliverable 4: Communication Plan: Refine the communication approach, stakeholders, channels and implementation roadmap.
KPIs: KPI 4.1: 100% comprehensive communications plan refined and accepted by NCIA. KPI 4.2: 100% of communication objectives, key stakeholders, and channels (internal and external to NCIA but within NATO) and implementation roadmap prepared. KPI 4.3: 100% refinement of the communication approach, stakeholders, channels and implementation roadmap.
Due Date: 15 November 2026
Payment Milestone: M4 – 25% of total awarded value
5. ACCEPTANCE CRITERIA
The deliverables provided to NCIA must be compliant with the following success criteria:
- All deliverables must demonstrably meet the specific KPI requirements outlined in Section 4.
- All deliverables shall be complete, technically accurate, and aligned with the requirements, objectives and scope defined under Sections 2 and 3 (KPIs 1–4).
- Strategy documents, governance artefacts, gap analyses, and implementation recommendations shall provide sufficient detail to support implementation by NCIA and shall include references to applicable NATO/NCIA policies and directives (KPIs 1–4).
- All findings, recommendations, technical solutions and implementation proposals shall be supported by appropriate findings, analyses, references, etc. (KPIs 1–4).
- All documents, diagrams, process maps, RACI matrices, and other artefacts shall be delivered in editable electronic formats approved by NCIA to enable future maintenance and reuse (KPIs 1–4).
- All deliverables, including but not limited to reports, analyses, strategies, governance artefacts, process models, diagrams, templates, documentation and any other work products developed under this Statement of Work, together with all associated intellectual property rights, shall vest in and become the property of NCIA upon acceptance and payment of the respective deliverable. NCIA shall have the unrestricted right to use, reuse, reproduce, modify and further develop such deliverables without requiring any additional consent or royalty fees to the Contractor.
- All deliverables shall be original work prepared by qualified personnel. AI-generated content shall not be accepted unless its use has been explicitly approved in writing by the NCIA project team prior to its development. Where such approval has been granted, the Contractor shall remain fully responsible for the accuracy, completeness and quality of the deliverables.
- Final acceptance of each deliverable shall be subject to NCIA review and documented through the signature of the corresponding Delivery Acceptance Sheet (DAS).
6. COORDINATION AND REPORTING
The contractor shall report to the NCIA Task Lead.
For each milestone, the contractor must report the outcome of his/her work during the period of performance. The format of this report shall be an email to the NCIA Point of Contact briefly mentioning the work performed and the development achievements during the milestone.
Acceptance of each delivery completion will be documented in a Delivery Acceptance Sheet.
7. PERIOD OF PERFORMANCE
This task order will be active immediately after signing of the contract by both parties.
The BASE period of performance is to start ASAP but not later than 1 September 2026 and will end on 4 December 2026. In case of delays, the performance period can be extended provided NCIA's agreement.
8. SECURITY CLEARANCE
The work will be conducted at the NATO UNCLASSIFIED level. It is mandatory for the Contractor to be in possession of a security clearance of NATO SECRET in order to enable access to relevant documentation and access to NATO facilities.
9. CONSTRAINTS
All the documentation provided under this Statement of Work will be based on NCIA templates or as agreed with the project Point of Contact.
10. PRACTICAL ARRANGEMENTS
10.1 Place of Performance
The Contractor's personnel are expected to provide services in Brussels, Belgium at a rate of 70% onsite and 30% offsite.
In the event of offsite work, the contractor will be required to work within a NATO country, following the rules and regulations applicable for the operations of NATO CIS.
10.2 Travel
Travel to other NATO sites, i.e. The Hague, is expected at a 20% rate.
10.3 Contractor Furnished Services
The Contractor shall furnish everything required to perform the contract except for the items specified and covered under NCIA Furnished Property and Services below.
10.4 NCIA Furnished Property and Services
Access to relevant classified networks and environments will be provided by NCIA.
Access to the survey tool/platform will be provided by NCIA.
If options are exercised, NCIA will facilitate the provision of a test environment.
NCIA will equip the contractor with an NR IT (laptop).
11. REQUIRED COMPETENCIES
[See Requirements]
Requirements
11. REQUIRED COMPETENCIES
Required
- The proposed Senior Manager must have 10+ years of knowledge and experience in large and complex Communication Strategies.
- The proposed Senior Manager must have 10+ years of experience and knowledge in governance processes in the context of CIS Security.
- The proposed Senior Manager must have solid experience of 10+ years in gap analyses in the context of roles and responsibilities of key stakeholders.
- The proposed Senior Manager must have experience and knowledge of CIS-related international, commercial, and industrial standards.
- The proposed Senior Manager must have experience with CIS systems (military and/or civilian).
- The proposed Senior Manager must have experience in Service Design and Management.
- The proposed Senior Manager must have knowledge and experience working with NATO and/or NCIA.
- Personal Security Clearance at NATO SECRET level is required. Bidders are encouraged to propose only candidates' profiles that are already cleared at the level required.