Jobs Companies EMW, Inc. 2026-0129 Provision OSCAL Architecting Services to NATO HQ CDT (NS) - FRI 11 Sep

Sobre esta vaga de 2026-0129 Provision OSCAL Architecting Services to NATO HQ CDT (NS) - FRI 11 Sep na EMW, Inc.

EMW, Inc. · Presencial · The Hague, South Holland, Netherlands

BIDDING INSTRUCTIONS

1. Bidding Instructions

A) Technical Proposal

Bidders shall submit a proposal clearly providing the following information:

a. CV and attestation of the assigned resource for the project that is/are meeting the requirements as per Section 10 (Specific Expertise Required). The CV shall contain accurate contact details for the reference person for each of the listed professional experiences relevant to this Statement of Work.

b. The Proposal shall contain also, at the minimum, the following statements relevant to the proposed contractor personnel:

Relevant experience in providing architecting services, ideally focusing on Policy-as-Code (PaC) Mapping: list 2 (two) specific projects in the last 3 years that demonstrate the required experience, including details about objective, output, outcome and role exercised.

Relevant experience working in NATO or national committees and working groups (architecting, capability development): list the groups where this experience was gained in the last 3 years, and the type of activity undertaken.

Experience in using architecture modelling tools (e.g. Sparx, System Architect, ARIS): List at least 2 (two) projects / activities where this experience has been demonstrated and provide details of modelling methodology and conventions used.

 

Deadline Date: Friday 11 September 2026

Requirement: Provision of OSCAL Architecting Services to NATO HQ CDT

Location: On-Site, NCIA, The Hague, NLD

Period of Performance: 2026 BASE: As soon as possible but not later than 12 October 2026, through 31 December 2026

Required Security Clearance: NATO SECRET

 

STATEMENT OF WORK

1. OVERALL PROJECT SCOPE

The NATO Communications and Information Agency (NCIA) located in The Hague, The Netherlands, is providing technical support to the NATO HQ Cyber and Digital Transformation (CDT) Division and Supreme Allied Command Transformation (SACT) by moving away from manual point-in-time audits, authorization to operate and security accreditation towards Continuous Governance, Risk and Compliance Auditing leading to Continuous Authorization to Operate (cATO) and Continuous Security Accreditation via EaC (Everything as Code) + Regulatory Operations (RegOps) using NIST OSCAL (Open Security Controls Assessment Language) data models, with the ultimate goal to deploy the RegScale platform as a workload and establish a Minimum Viable Product (MVP) for Continuous Authorization to Operate (cATO).

2. ACTIVITIES AND DELIVERABLES

2.1 Activities (Non-Deliverable)

The Contractor shall perform the following activities in support of the deliverables defined in Section 2.2. These activities are not considered deliverables in themselves.

  • Review the existing SRS, D32/CSRS, NIST/ISO baseline for OSCAL conversion.
  • Identify and document relevant technical triggers from the cloud environment.
  • Review sampled automated evidence to confirm completeness, accuracy and suitability for supporting System Security Plan (SSP) content.
  • Conduct Stakeholder Review Sessions to validate assumptions, mappings, evidence sources, and SSP generation logic.
  • Issue tracking and remediation support.

2.2 Deliverables

D001 – Catalog Digitization

Deliverable D001: Import the organization's SRS (D32/CSRS) or NIST/ISO baseline into OSCAL format.

Acceptance Criteria A001: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

D002 – Policy-as-Code (PaC) Mapping

Deliverable D002: Map technical triggers from cloud to specific OSCAL Control IDs.

Acceptance Criteria A002: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

D003 – Digital SSP Generation

Deliverable D003: Use RegScale to output the first full System Security Plan based on automated evidence.

Acceptance Criteria A003: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

3. KEY PERFORMANCE INDICATORS

The KPIs measure delivery quality, completeness, technical correctness, governance compliance, and business value. Each deliverable has measurable acceptance KPIs directly linked to payment.

D001 – Catalog Digitization KPIs

Catalog conversion completeness: 100% of the agreed SRS (D32/CSRS) or NIST/ISO baseline successfully converted into OSCAL format.

OSCAL validation: 100% of generated OSCAL files pass schema validation without critical errors.

Metadata completeness: 100% of required OSCAL metadata fields completed in accordance with the agreed profile.

Quality and accuracy: ≥98% control mapping accuracy verified through technical review, with no critical defects identified.

Acceptance: Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

D002 – Policy-as-Code (PaC) Mapping KPIs

Control mapping coverage: 100% of agreed technical cloud triggers mapped to the appropriate OSCAL Control IDs.

Mapping traceability: 100% of mappings include documented traceability from technical trigger to OSCAL control.

Mapping accuracy: ≥95% of sampled mappings validated as technically correct during peer review.

Automation readiness: 100% of mappings compatible with the agreed RegScale Policy-as-Code implementation approach.

Acceptance: Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

D003 – Digital SSP Generation KPIs

SSP completeness: 100% of required System Security Plan sections generated using RegScale.

Automated evidence integration: ≥90% of agreed evidence sources automatically incorporated into the generated SSP.

Documentation quality: SSP contains no critical documentation defects requiring regeneration following review.

Successful generation: Digital SSP successfully generated and demonstrated using RegScale.

Acceptance: Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

Generic Performance KPIs

The following Generic Performance KPIs apply across the entire contract and are used as gate criteria before payment.

Timeliness: Deliverables submitted by agreed milestone (Target: ≥95%).

Quality: Deliverables accepted without major rework (Target: ≥90%).

Documentation: Required technical documentation complete (Target: 100%).

Configuration Management: All artifacts version-controlled and traceable (Target: 100%).

Standards Compliance: Deliverables comply with OSCAL and agreed implementation standards (Target: 100%).

Communication: Progress reports submitted on time (Target: 100%).

Risk Management: Risks identified and escalated within agreed timeframe (Target: ≥95%).

4. PAYMENT SCHEDULE

Each milestone payment shall only be released after both the deliverable-specific KPIs and the generic performance KPIs have been achieved.

Scoring Model: Deliverable-specific KPIs are weighted 80%; Generic Contract KPIs are weighted 20%.

This requirement is for the delivery of the products identified in Section 2.2. Payment will be provided based on these deliveries as indicated below.

Milestone Score (%) = (Deliverable KPI Achievement × 80%) + (Generic KPI Achievement × 20%). Payment for each milestone is calculated as: Milestone Payment = Milestone Value × Milestone Score.

Milestone 1 – D001 Catalog Digitization: Payment: 30% Payment Conditions: Approved OSCAL catalogue delivered, validation completed, and all D001 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

Milestone 2 – D002 Policy-as-Code Mapping: Payment: 35% Payment Conditions: Approved Policy-as-Code mapping delivered with complete control mappings and all D002 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

Milestone 3 – D003 Digital SSP Generation: Payment: 35% . Payment Conditions: Digital SSP successfully generated in RegScale, demonstrated, approved, and all D003 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

Schedule of payments: Payment will be made after the Purchaser has accepted a respective deliverable and signed its Delivery Acceptance Sheet (DAS). The contractor shall submit an invoice, with approved DAS attached, to the Purchaser for payment as per the schedule above.

5. SECURITY CLEARANCE

Services included in this SOW require contractor's personnel to be in the possession of a valid NATO SECRET security clearance from the start of contract.

6. PERIOD OF PERFORMANCE

The 2026 BASE services are to be provided for the period starting NLT 12 October 2026 through 31 December 2026.

7. PRACTICAL ARRANGEMENTS

This is a Completion-type contract which requires one consultant with identified skills to complete the service.

Services will be performed on-site at NCIA, The Hague HQ, who is responsible for office space.

8. TRAVEL

This Task Order does not require any scheduled travel.

All travel expenses, including per diem, lodging and associated expenses for travel are included in the price of the bid (NTE), such that the purchaser shall not be invoiced separately for travel.

Extraordinary Travel (Purchaser Directed Travel) may be required to other NATO or non-NATO locations as necessary. In the event of such unforeseen meetings being called, the cost of all travel and subsistence will be addressed through a contract amendment.

Extraordinary Travel expenses will be reimbursed in accordance with Article 5.5 of the AAS+ Framework Contract. Such costs will be set as a separate PO line with a not-to-exceed value to cover and reimburse actual expenses upon submission of all receipts and invoices in line with NCIA processes.

9. CONSTRAINTS

NATO will retain the intellectual property rights for all products developed in relation to this project.

All deliverables, scripts, documentation and required code will be stored as directed by NCIA.

10. SPECIFIC EXPERTISE REQUIRED

[See Requirements]

Requirements

5. SECURITY CLEARANCE

  • Services included in this SOW require contractor's personnel to be in the possession of a valid NATO SECRET security clearance from the start of contract.

10. SPECIFIC EXPERTISE REQUIRED

The services described in this SOW require contractor personnel with experience in Enterprise Architecture and in addressing challenges related to interoperability.

Required:

  • The candidate must have a minimum of a Bachelor's degree from a nationally recognized/certified University in a related discipline and 3 years of related post-degree experience.
  • The candidate must have a minimum of 3 years' experience with NIST/ISO frameworks, JSON/YAML proficiency, and regulatory mapping.
  • The candidate must have a minimum of 3 years' experience with compliance-to-code translation.
  • The candidate must have documented (or demonstrable) experience in process analysis and design techniques.

Desirable Knowledge and Experience:

  • Robust technical knowledge of NATO operations, responsibilities and organization, with specific focus on how NATO achieves technical interoperability on the battlefield.
  • Comprehensive understanding of NATO's Cloud strategies.
  • Knowledge of ITIL, COBIT, or equivalent.
  • Familiarity with current and evolving capabilities and trends in military and civilian communication protocols and standards.

Desirable Competencies:

  • Deciding and Initiating Action: Takes responsibility for actions, projects and people; takes initiative and works under own direction; initiates and generates activity and introduces changes into work processes; makes quick, clear decisions which may include tough choices or considered risks.
  • Adhering to Principles and Values: Upholds ethics and values; demonstrates integrity; promotes and defends equal opportunities, builds diverse teams; encourages organizational and individual responsibility towards the community and the environment.
  • Relating and Networking: Easily establishes good relationships with customers and staff; relates well to people at all levels; builds wide and effective networks of contacts; uses humor appropriately to bring warmth to relationships with others.
  • Formulating Strategies and Concepts: Works strategically to realize organizational goals; sets and develops strategies; identifies, develops positive and compelling visions of the organization's future potential; takes account of a wide range of issues across, and related to, the organization.
  • Achieving Personal Work Goals and Objectives: Accepts and tackles demanding goals with enthusiasm; works hard and puts in longer hours when it is necessary; seeks progression to roles of increased responsibility and influence; identifies own development needs and makes use of developmental or training opportunities.
Pronto para se candidatar à EMW, Inc.?
Candidatar-se à EMW, Inc.

Sobre a EMW, Inc.

EMW provides lifecycle Systems Engineering and Technical Assistance (SETA), Engineering and Installation (E&I), Operations and Maintenance (O&M), Force Protection Technologies and Contractor Recruitment Services across the fields of Defense, Health Information Technology, Cyber Security and Information Assurance, Perimeter Security and Telecommunications Infrastructure worldwide.

Ver todas as vagas na EMW, Inc. →

Vagas semelhantes

EMW, Inc.
C005315 MISP Engineer (NS) - MON 14 Sep
EMW, Inc.
⚡ Candidate-se cedo Mons, Wallonia, Belgium Presencial
● Nova 👁 Vista ✓ Candidatada há 16h
EMW, Inc.
C005306 Microsoft Senior Engineer (NS) - MON 14 Sep
EMW, Inc.
⚡ Candidate-se cedo Mons, Wallonia, Belgium Presencial
● Nova 👁 Vista ✓ Candidatada há 16h
EMW, Inc.
C005302 Cyber Security Incident Responder (NS) - MON 14 Sep
EMW, Inc.
⚡ Candidate-se cedo Mons, Wallonia, Belgium Presencial
● Nova 👁 Vista ✓ Candidatada há 16h
EMW, Inc.
C005305 COMS Senior Engineer (CTS) - MON 14 Sep
EMW, Inc.
⚡ Candidate-se cedo Mons, Wallonia, Belgium Presencial
● Nova 👁 Vista ✓ Candidatada há 16h
EMW, Inc.
C004891 Account Executive (CDT) (NS) - MON 14 Sep
EMW, Inc.
⚡ Candidate-se cedo Brussels, Brussels, Belgium Presencial
● Nova 👁 Vista ✓ Candidatada há 16h
EMW, Inc.
C005307 Technician (User Support) (NS) - FRI 11 Sep
EMW, Inc.
⚡ Candidate-se cedo Mons, Wallonia, Belgium Presencial
● Nova 👁 Vista ✓ Candidatada há 1d
EMW, Inc.
C004799 Infrastructure Engineer (CTS) - FRI 11 Sep RELAUNCH
EMW, Inc.
⚡ Candidate-se cedo The Hague, South Holland, Neth... Presencial
● Nova 👁 Vista ✓ Candidatada há 1d
EMW, Inc.
C005262 Network Technician (Network Automation & Data Entry) (NS) - FRI 11 Sep
EMW, Inc.
⚡ Candidate-se cedo Braine-l'Alleud, Wallonia, Bel... Presencial
● Nova 👁 Vista ✓ Candidatada há 1d
EMW, Inc.
2026-0127 Provision RegOps Engineering to NCIA, SACT and CDT (NS) - FRI 11 Sep
EMW, Inc.
⚡ Candidate-se cedo The Hague, South Holland, Neth... Presencial
● Nova 👁 Vista ✓ Candidatada há 1d

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na EMW, Inc.

Ver todas as vagas na EMW, Inc. →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis