What this opportunity is
The Department of Defense's Defense Microelectronics Activity (DMEA) is seeking a Women-Owned Small Business (WOSB) to provide professional, technical, and system integration services for its enterprise-wide risk management and risk management and internal control program. This acquisition is open to certified WOSBs and will be awarded without discussions, so offerors should submit their best terms initially. The contract requires access to Controlled Unclassified Information (CUI) and adherence to specific security guidelines, but does not require a facility or personnel security clearance.
Analysis by Mindy, grounded in the SAM.gov notice.
Description
PERFORMANCE WORK STATEMENT (PWS)
DMEA 26-6F3
25 June 2026
Contract Officer Representative: , DMEA/DAG
1.0 SCOPE:
1.1 TITLE: DMEA Enterprise Program Support
1.2 APPLICABILITY: Defense Microelectronics Activity (DMEA)
1.3 BACKGROUND: DMEA Directors Action Group (DAG) is tasked with maintaining an enterprise-wide risk
management (ERM) and risk management and internal control (RMIC) program, enabling DMEA to remain in
compliance with DoDI 5010.40 internal control over reporting – operations requirements and to better accomplish
its mission. The enterprise program shall continue the development and documentation of DMEA's enterprise
mission and support processes, including but not limited to information technology and networking systems, human
capital, organization, records retention and disposition, in a defined control framework, which satisfies
requirements. This Enterprise Program is the risk and control identification, assessment, and remediation process
enabling DMEA to successfully analyze, and manage critical business processes to more effectively and efficiently
execute DMEA's mission.
DMEA’s enterprise program will simplify DMEA’s compliance with various standards and programs, such as
quality management system standards (ISO 9001), the testing and calibration laboratories standard (ISO 17025),
discipline-specific compliance standards, and risk management and internal controls (RMIC) program to which
DMEA must comply.
1.4 PURPOSE: To acquire services to maintain, assess, and remediate enterprise risk management and internal
controls at DMEA based on DMEA’s existing business processes and infrastructure.
2.0 REFERENCED GOVERNMENT PROVIDED RESOURCES:
2.1 GOVERNMENT DOCUMENTS:
Document No. Date Title
DoDI 5010.40 Latest Enterprise Risk Management and Risk Management & Internal Control
Program Instruction
[no number] Latest DoW OMB A-123 Implementation Handbook – Guide to Reporting
Requirements for A-123
[no number] Latest Fraud Risk Management Strategy and Guidance
DMEA Policy 5010.40 Latest Risk Management and Internal Control Program
100143 Latest DMEA Quality Management System Manual (ISO 9001)
DMEA OP 5015.02 Latest DoD Records Management Program
SEGIT ISO 17025-2017(E) Latest SEGIT Quality Management System Manual
2.2 OTHER DOCUMENTS:
Document No. Date Title
ISO 9001:2015 2015-09 Quality Management Systems – Requirements
ISO/IEC 17025:2017 2018-03 General Requirements for the Competence of Testing and Calibration Laboratories
ISO 19011:2018 2018-07 Guidelines for Auditing Management Systems
2.3 GOVERNMENT FURNISHED EQUIPMENT:
Nomenclature Part Number Date Available
Laptop TBD ARO
-- 1 of 9 --
2.4 GOVERNMENT FURNISHED INFORMATION:
Nomenclature Date Date Available
DMEA Information Technology Process Support Data Most Recent ARO
RMIC Program Documentation Most Recent ARO
ISO 9001 Documentation Most Recent ARO
ISO 17025 Documentation Most Recent ARO
2.5 GOVERNMENT FURNISHED FACILITIES/ACCESS:
Facility/Access Date
DMEA Complex, 4234 54th Street, McClellan, CA; Building 1 (620), 2, and 600. ARO
Access to non-classified or open storage rooms in Building 1 (620), 2, and 600:
Resources required: (1) Work area to include personal computer and all required
software to perform PWS tasks. (2) Virtual access to systems to include local area
network (e-mail and internet access). (3) Photo identification with personal identity
verification, such as Common Access Card.
ARO
3.0 REQUIREMENTS:
3.1 GENERAL REQUIREMENTS:
3.1.1 RESERVED
3.2 ENTERPRISE PROGRAM REQUIREMENTS:
3.2.1 PROGRAM MANAGEMENT: The contractor shall perform computer system integration, administrative,
technical, financial management, during this effort and shall communicate monthly on the status of their effort
towards achieving the PWS objectives, including all technical activities and efforts, problems/deficiencies, impacts,
and recommended solutions. The contractor shall create a detailed project plan to be included with the monthly
status report.
(A001-Monthly Status Reports)
(A002-Detailed Project Plan)
3.2.2 TECHNICAL INTERCHANGE MEETINGS (TIMs): The contractor shall conduct TIMs as necessary in the
performance of this task. The TIM with the contractor shall be scheduled when there is need for technical
interchange between the government and the contractor. The content of the meeting can include discussion of any
information that has impact upon the task activities, including documentation contents or format.
(A003-TIMs Meeting Minutes)
3.2.3 TRAVEL: Travel may be required during the conduct of this PWS. Negotiated travel shall be approved upon
task award. Additional travel shall be authorized only upon written approval of the PCO. The contractor shall
provide a report following all travel to include objectives achieved and action items.
(A004-Trip Report)
3.3 TASK REQUIREMENTS:
3.3.1 SYSTEM INTEGRATION: The contractor shall provide fusion of information technology (IT) with, process
architectures, metric systems, and compliance requirements to optimize performance and efficiency across the
enterprise. System architecture should maximize the availability of process and control information through IT
applications to provide on-going (continual) monitoring of process health and effectiveness of controls. Systems
should minimize effort required to provide necessary control test information that supports the annual DMEA A-123
Statement of Assurance.
-- 2 of 9 --
3.3.2 CONTROL TESTING AND AUDITING: The contractor shall work with the various process owners to
develop test plans to ensure that all controls are tested and analyzed for effectiveness. The contractor shall work with
the various process owners to follow all test plans and determine if the controls are adequate or not.
(A005-Test Plans)
(A006-Test Results)
3.3.3 DEFICIENCY ASSESSMENT AND CORRECTIVE & PREVENTIVE ACTION REPORTS: The contractor
shall work with the various process owners to assess any deficiencies discovered in the c…
Source: SAM.gov, as posted. Verify the current solicitation before responding.