Description
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Office of Information & Technology (OIT)
Product Delivery Service (PDS)
Unified Discovery and Disclosure (UDD) Platform
Date: July 14, 2026
<VA-27-00004607>
PWS Version Number: 0.5
Contents
1.0 BACKGROUND 4
2.0 APPLICABLE DOCUMENTS 4
3.0 SCOPE OF WORK 8
3.1 IN-SCOPE WORKSTREAMS 9
3.2 SCALE (INDICATIVE, NOT BINDING) 9
3.3 GEOGRAPHIC SCOPE AND AVAILABILITY 9
3.4 OBJECTIVES AND DESIRED OUTCOMES 9
4.0 PERFORMANCE DETAILS 9
4.1 PERFORMANCE PERIOD 9
4.2 PLACE OF PERFORMANCE 10
4.3 TRAVEL 10
5.0 SPECIFIC TASKS AND DELIVERABLES 10
5.1 PROJECT MANAGEMENT 10
5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN 10
5.1.2 REPORTING REQUIREMENTS 11
5.2 CAPABILITY AREAS FOR MARKET RESEARCH 11
5.3 PLATFORM AND ARCHITECTURE 12
5.4 LEGAL HOLD AND PRESERVATION 12
5.5 IDENTIFICATION AND COLLECTION 12
5.6 PROCESSING AND INDEXING 12
5.7 SEARCH, ANALYTICS, AND TECHNOLOGY-ASSISTED REVIEW 12
5.8 REVIEW, CODING, AND QUALITY CONTROL 12
5.9 AUDIO, VIDEO, AND IMAGERY 13
5.10 AI-ASSISTED REDACTION AND AI GOVERNANCE 13
5.11 PRODUCTION 13
5.12 FOIA CASE MANAGEMENT 13
5.13 FOIA REPORTING AND PUBLIC POSTING 14
5.14 EDISCOVERY CASE MANAGEMENT 14
5.15 REPORTING, DASHBOARDS, AND BUSINESS INTELLIGENCE 14
5.16 MICROSOFT 365 INTEGRATION AND OTHER INTEGRATIONS 14
5.17 OPEN API 14
5.18 MOBILE AND ACCESSIBILITY 14
5.19 SECURITY, PRIVACY, AND COMPLIANCE (HIGH LEVEL) 15
5.20 IMPLEMENTATION AND DATA MIGRATION 15
5.21 TRAINING AND ORGANIZATIONAL CHANGE MANAGEMENT 15
5.22 SUSTAINMENT AND MANAGED SERVICES 15
5.23 TRANSITION (PHASE-IN AND PHASE-OUT) 15
6.0 GENERAL REQUIREMENTS 16
6.1 ENTERPRISE AND IT FRAMEWORK 16
6.1.1 VA TECHNICAL REFERENCE MODEL 16
6.1.2 ZERO TRUST – VA CRITICAL SECURITY CONTROLS 16
6.1.3 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM) 16
6.1.4 INTERNET PROTOCOL VERSION 6 (IPv6) 18
6.1.5 TRUSTED INTERNET CONNECTION (TIC) 18
6.1.6 STANDARD COMPUTER CONFIGURATION 18
6.1.7 VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT (PLM) 19
6.1.8 PROCESS ASSET LIBRARY (PAL) 20
6.1.9 AUTHORITATIVE DATA SOURCES 20
6.1.10 SOCIAL SECURITY NUMBER (SSN) REDUCTION 21
6.1.11 SOFTWARE AND LICENSING REQUIREMENTS 21
6.1.12 GENERATIVE ARTIFICIAL INTELLIGENCE REQUIREMENTS 22
6.1.12.1 AI SYSTEM/LLM DEVELOPMENT AND OPERATION DOCUMENTATION REQUIREMENTS 23
6.1.12.2 MONITORING, REPORTING, AND CORRECTIVE ACTION 25
6.1.12.3 AI MODEL UPDATES AND CHANGE DISCLOSURES 25
6.2 SECURITY AND PRIVACY REQUIREMENTS 26
6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S) 26
6.2.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS 27
6.3 METHOD AND DISTRIBUTION OF DELIVERABLES 29
6.4 PERFORMANCE METRICS 29
6.5 FACILITY/RESOURCE PROVISIONS 30
6.6 GOVERNMENT FURNISHED PROPERTY 31
6.7 SHIPMENT OF HARDWARE OR EQUIPMENT 31
ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED 33
ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/ PRIVACY LANGUAGE 39
BACKGROUND
VA, Office of Information and Technology (OIT), Office of General Counsel (OGC), with business stakeholders including the FOIA Service (Compliance, Risk, and Remediation) and OGC eDiscovery under the Secretary of VA, Congressional, Legal Affairs (SCLA) product line currently operates two separate enterprise applications; Freedom of Information Act (FOIA) and Privacy Act case management (eFOIA) and eDiscovery and litigation review. These systems do not share a common evidentiary corpus, a chain of custody, a redaction engine, a legal hold registry, an audit log, or a user interface. The eFOIA system supports FOIA and Privacy Act request intake, processing, redaction, response, public posting, appeals processing and tracking and reporting, while the eDiscovery system supports litigation and administrative discovery across the matter lifecycle.
This separation drives duplicative collection and storage of the same VA records, inconsistent legal hold and redaction practices, and inconsistent service levels across components. VA seeks a single, integrated, FedRAMP-authorized cloud platform that performs both eDiscovery and eFOIA work end to end on the same corpus, with a single chain of custody, redaction engine, audit log, and user interface, while preserving role-based separation across matter types and components.
APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
“Federal Information Security Modernization Act of 2014”
Federal Information Processing Standards (FIPS) Publication 140-3, “Security Requirements for Cryptographic Modules”, March 22, 2019
FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004
FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006
FIPS Pub 201-3, “Personal Identity Verification of Federal Employees and Contractors,” January 2022
10 U.S.C. § 2224, "Defense Information Assurance Program", as amended
5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
Public Law 109-461 (P.L. 109-461), Veterans Benefits, Health Care, and Information Technology Act of 2006, as amended, Title IX, Information Security Matters
42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”, as amended
VA Directive 0710, “Personnel Vetting Program,” September 8, 2025, https://www.va.gov/vapubs/index.cfm
VA Handbook 0710, “Personnel Vetting Program,” September 8, 2025, https://www.va.gov/vapubs/index.cfm
VA Directive 6102, “Internet/Intranet Services,” August 5, 2019
36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” as amended
Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”, as amended
NIST SP 800-66 Rev. 2, “Implementi…
Source: SAM.gov, as posted. Verify the current solicitation before responding.