# 2026-0113 DCIS Cyber Boundary Protection Level 3 Support (CTS) - FRI 4 Sep

**Company:** [EMW, Inc.](http://jobs.workable.com/companies/rxTcVwBJTwXzUuxD5bzFUW.md)
**Location:** Brunssum, Netherlands
**Workplace:** on site
**Employment type:** Contract
**Department:** AAS

[Apply for this job](http://jobs.workable.com/view/340eb573-c607-4d89-986e-c65967e2a9aa)

## Description

**BIDDING INSTRUCTIONS**

**1.1 Bidding Options**

All companies may bid for this Statement of Work by proposing personnel to deliver the scope of work outlined in Section 3 (Scope of Work) and who meet the required qualifications outlined in the Requirements section. The Contractor shall provide a qualified personnel profile to deliver the services described in this Statement of Work. The profile must meet all mandatory technical, professional, and soft-skill requirements. The personnel shall ensure continuous service coverage, operational resilience, and the ability to support both routine and on-call activities across all NMI functional locations.

**1.2 Technical Proposal**

Bidders shall include in the Technical Proposal the CVs of the proposed Contractor personnel, clearly indicating relevant experience that demonstrates compliance with the required qualifications.

Bidders shall include in the Technical Proposal a compliance matrix for each proposed profile, demonstrating how the Contractor personnel meet all required qualifications, supported by evidence from their professional experience.

**1.3 Technical Compliance**

Each bid will be assessed for technical compliance in accordance with Section 1.2, Technical Proposal.

**Deadline Date:** Friday 04 September 2026

**Requirement:** DCIS Cyber Boundary Protection Level 3 Support

**Location:** NCIA Mons, Belgium (100% onsite)

**Period of Performance:** Commencing 15 September 2026 (tentative), for an initial period of two (2) months from the effective start date. NCIA reserves the right to extend the period of performance for such additional period(s) as may be required, subject to business needs, the availability of funding, and written notification to the Contractor.

**Required Security Clearance:** COSMIC TOP SECRET

**1\. INTRODUCTION**

The NATO Integrated Mission Services Centre (NIMSC) is responsible for the coordination, planning, and delivery of engineering and operational support capabilities across Mobile CIS Infrastructure, including Deployable CIS Services (DCIS), Dispersible Systems, Highly Mobile Systems, SATCOM, and Wireless Communications. To ensure the sustained availability, performance, and resilience of these mission-critical capabilities, NIMSC requires structured, continuous Operations and Maintenance (O&M) support aligned with NATO governance, service management processes, and operational priorities.

Through this Statement of Work (SoW), the NIMSC seeks industry support to deliver comprehensive technical, operational, and service-governance activities for the NATO Mission Iraq (NMI) Deployable Communication and Information System (CIS). The objective is to ensure implementation of a new CIS system, an uninterrupted service delivery, effective incident and change management, accurate and auditable reporting, and continuous service improvement across all NMI functional locations. The Contractor, through the selected personnel, will provide technical support, system documentation management, service reporting, and participation in on-call and operational coordination activities, ensuring that NMI CIS capabilities are fully operational, secure, and aligned with NATO standards.

**2\. INTENDED BUSINESS OUTCOME**

The intended business outcome of this Statement of Work is to support the successful delivery of Deployable CIS Services (DCIS) kits by providing the technical expertise required to configure, integrate, validate, and prepare the Boundary Protection infrastructure for operational deployment.

Specifically, the main objectives are:

-   Configure operationally ready DCIS kits by ensuring that all assigned Boundary Protection components are configured, integrated, and validated in accordance with approved technical designs, security requirements, and NCIA standards.
-   Ensure consistent and high-quality implementation through the application of standardized configuration practices, rigorous testing, and comprehensive technical documentation.
-   Support timely project delivery by executing assigned activities in accordance with the agreed project schedule, coordinating effectively with NCIA personnel and other delivery teams, and proactively managing technical dependencies and risks.
-   Facilitate successful system integration by ensuring interoperability between the Boundary Protection components, network infrastructure, Core Services, and supporting management systems within each DCIS kit.
-   Enable efficient acceptance and deployment readiness by supporting User Acceptance Testing (UAT), resolving identified technical issues, and delivering complete and accurate technical documentation.
-   Maintain governance and compliance by performing all activities in accordance with NCIA processes, security policies, configuration management procedures, and project governance requirements, ensuring full traceability and auditability throughout the delivery lifecycle.

The successful execution of this Statement of Work will result in securely configured, fully integrated, tested, and deployment-ready DCIS kits containing the required Boundary Protection components that meet the required technical, operational, and security standards and are ready for transition into operational use.

**3\. SCOPE OF WORK**

The scope covers the configuration, integration, deployment support, and operational readiness of NMI NATO DCIS Boundary Protection Services and architecture, including the configuration, validation, and deployment of Boundary Protection components. The Contractor shall provide services in a continuous, structured, and highly secure manner, ensuring alignment with approved technical designs, operational priorities, service levels, security classification boundaries, and NATO governance processes. The services shall be delivered through the assignment of one (1) qualified personnel as set out in the Requirements section.

The assigned personnel shall perform the activities defined herein and contribute to the achievement of the agreed service levels, performance targets, and successful delivery of Deployable CIS Services (DCIS) kits. This includes the following activities:

-   Boundary Protection configuration: Executing the end-to-end configuration of Boundary Protection components in accordance with approved technical designs, security requirements, and NCIA standards.
-   Boundary Protection integration: Integrating and validating Boundary Protection components to ensure interoperability with the network infrastructure, Core Services, and supporting management systems.
-   Deployment support: Supporting the deployment, configuration, validation, and operational readiness of Boundary Protection components within DCIS kits.
-   Management tool integration: Configuring and verifying Boundary Protection components within the applicable centralized management and monitoring tools.
-   System documentation management: Supporting the maintenance and updating of technical documentation to reflect changes, configurations, operational procedures, and implemented solutions.
-   User Acceptance Testing (UAT) and Troubleshooting: Providing technical support during UAT, including fault diagnosis, troubleshooting, and resolution of Boundary Protection-related issues.

The Contractor shall ensure that the assigned personnel possess the required qualifications and experience.

The Contractor shall ensure that the assigned personnel perform the tasks in accordance with NATO processes and procedures.

The Contractor shall ensure that the assigned personnel maintain continuity and quality of service delivery.

All activities shall be performed in accordance with NCIA processes and procedures, ensuring compliance, traceability, and auditability.

**3.1 Service Reporting**

The Contractor shall establish, maintain, and operate a structured reporting framework to provide NCIA with full visibility of service performance, operational status, service availability, risks, and compliance with the requirements of this Statement of Work (SoW).

**3.1.1 Reporting Requirements**

The Contractor shall provide the reports described below.

**3.1.1.1 Weekly Progress Report**

The Contractor shall submit a Weekly Progress Report every week, summarising the progress of the services performed during the reporting period. The report shall include, as a minimum: activities completed during the reporting period; activities planned for the next reporting period; progress against the agreed service activities and contractual milestones; status of assigned service requests, incidents, changes, and maintenance activities; configuration, maintenance, support, and operational activities completed; and outstanding actions, dependencies, risks, and service issues.

**3.1.1.2 Monthly Service Performance Report**

The Contractor shall submit a Monthly Service Performance Report no later than the fifth (5th) working day following the end of each reporting period. The report shall include, as a minimum:

**Service Performance:** Summary of services delivered during the reporting period; service availability across all supported service domains; and major incidents and outages, including impact assessment.

**Operational Activities:** Activities completed during the reporting period; planned activities for the next reporting period; incident, change, release, and maintenance activities performed; and outstanding actions and dependencies.

**Service Configuration and Maintenance:** Status of configuration and maintenance activities; validation of implemented configurations; operational status of supported systems and services; and deviations from approved technical designs or operational procedures.

**Testing and Validation:** Backup and restore validation activities performed; configuration validation results; defects identified; troubleshooting and corrective actions completed; and outstanding issues affecting service availability or operational readiness.

**Documentation Status:** Status of technical documentation updates; and confirmation that implemented configurations, operational changes, and procedures have been incorporated into the system documentation.

**Risks and Issues:** Technical issues affecting service delivery; service risks and operational issues; dependencies on other contractor teams or NCIA stakeholders; mitigation actions; and escalation items requiring NCIA decisions.

**Deliverables and Milestones:** Deliverables completed during the reporting period; deliverables submitted for acceptance, where applicable; milestones achieved; planned milestone completions; and activities requiring NCIA review or acceptance.

**KPI Performance:** KPI measurements and supporting evidence; identification of KPI breaches; corrective actions for KPI underperformance; and calculation of applicable Service Credits.

The Monthly Service Performance Report shall serve as the basis for service performance assessment and payment validation.

**3.1.1.3 Ad Hoc Reports**

The Contractor shall provide ad hoc reports upon request by NCIA or following significant service issues, major incidents, operational risks, or other events requiring management attention.

**3.1.2 Reporting Obligations**

Reports shall be submitted electronically using NCIA-approved templates or formats and in accordance with the reporting schedule defined in this SoW. All reports shall be accurate, complete, traceable, and auditable, and shall be supported by information recorded in NCIA-approved systems and tools, where applicable.

The Contractor shall participate in project, technical, operational, and service review meetings as requested by NCIA and provide additional verbal or written status updates upon request.

NCIA reserves the right to request clarification or supporting evidence for any reported information and to require corrective actions where reporting deficiencies or discrepancies are identified.

**3.2 Service Governance Model**

The Contractor shall establish and maintain an effective governance structure to ensure the successful planning, coordination, monitoring, operation, and delivery of the services defined in this Statement of Work (SoW). The governance structure shall facilitate effective communication, timely decision-making, risk management, and coordination with NCIA and other stakeholders.

**3.2.1 Service Governance**

The governance structure shall include the following levels:

**Operational Coordination:** Day-to-day coordination of operational activities, incident management, change and release activities, maintenance, service requests, issue resolution, dependency management, operational planning, and coordination of upcoming activities. Frequency: Weekly (or as required).

**Service Review (Performance Management):** Review of service performance, KPI achievement, service availability, operational activities, service reporting, risks, mitigation actions, corrective and preventive actions, and overall service delivery. Frequency: Monthly.

**Technical Review:** Review of technical issues, planned configuration activities, design changes, implementation progress, operational risks, and technical solutions related to Boundary Protection components. Frequency: As required.

**Acceptance Review:** Review of completed deliverables, User Acceptance Testing (UAT) results, technical documentation, outstanding defects, and readiness for acceptance of DCIS kits. Frequency: Prior to each acceptance milestone.

The Contractor shall participate in governance activities including, but not limited to: operational and technical coordination meetings; service review meetings; incident and problem review meetings; change and release review meetings; risk and issue review meetings; technical review meetings; project status meetings, where applicable; and ad hoc meetings requested by NCIA.

The Contractor shall cooperate with NCIA and other contractors to ensure the successful integration, configuration, testing, validation, and delivery of the Boundary Protection components within the complete DCIS solution.

**3.2.2 Escalation**

The Contractor shall establish and maintain effective communication with NCIA throughout the execution of the services. The Contractor shall promptly notify NCIA of any issue, risk, dependency, or event that may adversely affect the delivery schedule, quality of the services, technical compliance, or successful completion of the activities defined in this SoW.

Issues shall be escalated without undue delay where: milestones or delivery dates are at risk; technical issues cannot be resolved within the Contractor's area of responsibility; dependencies on NCIA, other contractors, or third parties may impact service delivery; resource constraints or unforeseen events may affect the delivery of the services; or decisions or guidance from NCIA are required to maintain progress.

**3.3 Continuous Service Improvement**

The Contractor shall identify opportunities for service optimisation and efficiency improvements; propose and track corrective and preventive actions; and monitor trends and recurring issues to drive long-term improvements.

All improvement actions shall be documented; reviewed during governance meetings; and tracked to completion.

**3.4 Security Clearance**

Performance of the services requires a valid NATO COSMIC TOP SECRET.

The Contractor shall ensure that all the Contractor staff or anyone working under the remit of the Contractor requiring recurring access to on-site locations for the delivery of the services under this SoW, have a valid NATO Personal Security Clearance at least to the NATO COSMIC TOP SECRET level.

**3.5 Working Provisions**

**3.5.1 Place of Performance**

The primary place of performance shall be the premises of NCIA in Mons, Belgium.

**3.5.2 Hours of Performance**

The services shall be performed during normal working hours, as follows: Monday to Thursday, 08:30-17:30 (CET); Friday, 08:30-15:30 (CET).

Where required for operational reasons, the Contractor shall perform night work in support of the services. Such activities shall be planned and agreed in advance with NCIA. All night work shall be included within the Contractor's price and shall not be subject to additional reimbursement.

**3.5.3 NCIA-Furnished Property and Services**

NCIA shall provide access to necessary tools, data, and NATO networks, subject to applicable Agency policies, security authorisation, and coordination requirements.

**3.5.4 Travel Requirements**

The Contractor shall be prepared to undertake travel that may include, but is not limited to, NCIA Europe locations. An estimated average of one (1) trip per month is anticipated and will not exceed 5 days; however, this estimate is indicative only and shall not constitute a commitment. The cost of such travel, including all associated travel and subsistence expenses, shall be included in the Contractor's price and shall not be subject to separate reimbursement.

Extraordinary Travel, defined as travel requirements that involve destinations other than those identified above, shall be subject to prior written approval by NCIA. The cost of such travel and associated subsistence shall be reimbursed in accordance with Article 5.5 of the AAS+ Framework Contract based on actual expenses and in line with NCIA processes. Such costs may be established via a contract amendment and through a separate Purchase Order line.

All travel arrangements shall be the responsibility of the Contractor.

**4\. SERVICE PERFORMANCE**

The performance of each assigned personnel shall be measured against the Key Performance Indicators (KPI) defined in this Section. Performance shall be measured through the following indicators: KPI 1 - On-Time Delivery, ensuring that contractual milestones and deliverables are completed in accordance with the agreed implementation schedule; KPI 2 - Configuration Acceptance Rate, ensuring that configured DCIS kits meet the agreed technical requirements and are accepted by NCIA without requiring significant rework; KPI 3 - UAT Success Rate, ensuring that configured DCIS kits successfully pass User Acceptance Testing (UAT) and are ready for operational deployment; and KPI 4 - Reporting Timeliness, ensuring that all required reports are submitted within the agreed timelines and are complete, accurate, and suitable for performance assessment.

All KPI thresholds, performance monitoring, and associated Service Credits shall be applied as defined in this Section and linked to the reporting and payment mechanism.

**4.1 KPI Measurement**

The performance of the assigned personnel shall be measured as follows:

**KPI 1 - On-Time Delivery:** Compliant (Met): At least ninety-five percent (95%) of contractual milestones and deliverables due during the reporting period are completed by the agreed due date. Non-Compliant (Not Met): Less than ninety-five percent (95%) are completed on time. Frequency: Monthly.

**KPI 2 - Configuration Acceptance Rate:** Compliant (Met): At least ninety-five percent (95%) of configured DCIS kits or deliverables submitted during the reporting period are accepted by NCIA without requiring significant rework. Non-Compliant (Not Met): Less than ninety-five percent (95%) meet this requirement. Frequency: Monthly.

**KPI 3 - UAT Success Rate:** Compliant (Met): At least ninety-five percent (95%) of DCIS kits submitted for User Acceptance Testing successfully pass UAT on the first submission. Non-Compliant (Not Met): Less than ninety-five percent (95%) achieve first-time acceptance. Frequency: Monthly.

**KPI 4 - Reporting Timeliness:** Compliant (Met): All reports required under this SoW are submitted within the agreed timelines and are complete and suitable for performance assessment. Non-Compliant (Not Met): Any required report is submitted late or is incomplete. Frequency: Monthly.

**4.2 Service Credits**

**4.2.1 KPI Weighting**

Each KPI shall contribute to the overall service performance as follows:

**KPI 1 - On-Time Delivery:** 5%

**KPI 2 - Configuration Acceptance Rate:** 3.5%

**KPI 3 - UAT Success Rate:** 3.5%

**KPI 4 - Reporting Timeliness:** 3%

**4.2.2 Calculation of Service Credits**

Where a KPI is determined to be Non-Compliant (Not Met) in accordance with Section 4.1, the corresponding percentage specified in Section 4.2.1 shall be applied as a service credit.

Service credits shall be calculated on a monthly basis as follows: Total Service Credit (%) = Sum of the percentages assigned to each KPI that is Not Met. The monetary value of the service credit shall be: Service Credit Value = Total Service Credit (%) x Monthly Service Fee.

Service credits shall be calculated based on validated KPI results; be documented in the Service Performance Report; be reviewed and confirmed during service review meetings; and be deducted from the corresponding invoice.

**4.2.3 Cap on Service Credits**

The total service credits applied in any reporting period shall not exceed ten percent (10%) of the applicable monthly service fee.

**4.2.4 Audit and Verification**

The Contractor shall ensure that all KPI measurements and service credit calculations are accurate, transparent, and auditable.

NCIA reserves the right to verify KPI results; request supporting evidence; and challenge any calculation deemed incorrect.

**5\. PAYMENT**

**5.1 Monthly Service Fee**

The work carried under this Statement of Work shall be delivered on the basis of a Monthly Service Fee. Such Monthly Service Fee shall cover all costs associated with the delivery of the services, including personnel, night work, management, tools, overheads, and travel as defined in this SoW.

The Monthly Service Fee is structured as follows:

**Monthly Fixed Fee:** Equal to eighty-five percent (85%) of the Monthly Service Fee and payable upon NCIA's acceptance of the services delivered during the applicable reporting period in accordance with Section 5.1.1.

**Monthly Performance-Based Fee:** Equal to fifteen percent (15%) of the Monthly Service Fee and payable upon NCIA's acceptance of the services delivered during the applicable reporting period in accordance with Section 5.1.1, subject to performance assessment against the applicable KPIs defined in Section 4.1 and shall be adjusted through the application of Service Credits in accordance with Section 4.2.2.

**5.1.1 Acceptance of Services**

Payment shall be subject to NCIA's acceptance of the services delivered during the applicable reporting period. Acceptance shall be based on confirmation that: the services have been performed in accordance with the requirements of this Statement of Work; the Monthly Service Performance Report and supporting documentation have been submitted and validated by NCIA; deliverables completed during the reporting period have been accepted by NCIA, where formal acceptance is required; any identified deficiencies affecting the invoiced services have been resolved or are subject to a remediation plan agreed by NCIA; and the applicable KPI results and Service Credits have been validated.

Acceptance of the services for invoicing purposes shall not constitute acceptance of incomplete, defective, or non-compliant work, nor relieve the Contractor of its obligations under this Statement of Work.

**5.1.2 Invoicing**

The Contractor shall submit invoices on a monthly basis in arrears. Each invoice shall correspond to the services delivered during the relevant calendar month; include the applicable monthly fees; clearly identify any applicable service credits in accordance with Section 4.2; and be supported by the Service Performance Acceptance Report for the same period.

**5.1.3 Period of Performance**

This Statement of Work is expected to commence 15 September 2026 (tentative), for an initial period of two (2) months from the effective start date.

The Period of Performance may be extended by NCIA, at its sole discretion, subject to business needs, the availability of funding, and written notification to the Contractor. The Monthly Service Fee shall continue to apply throughout any extension of the Period of Performance and shall be pro-rated where an extension covers less than one calendar month. Where the Period of Performance extends into a subsequent calendar year, the Monthly Service Fee applicable from the beginning of that calendar year shall be adjusted by applying the Price Adjustment Formula (PAF) in accordance with Article 6.5 of the Special Provisions under Framework Agreement CO-115786-AAS+.

**6\. REPLACEMENT**

Any replacement of the personnel assigned shall be subject to prior written approval by NCIA and shall meet or exceed the qualifications, experience, and security requirements defined for the respective profile. In the event that assigned personnel become unavailable during the Period of Performance, the personnel shall propose a suitable replacement personnel and ensure seamless continuity of the services at no additional cost, including the provision of appropriate knowledge transfer.

**7\. TRANSITION OUT**

The conclusion of the Period of Performance shall include the transfer of all relevant documentation, data, work products, system configurations, and operational procedures necessary to maintain continuity of service delivery. The Contractor shall also provide reasonable support to NCIA and, where applicable, to any follow-on contractor, including clarification of activities and assistance in mitigating disruption.

All transition activities shall be completed within a timeframe agreed with NCIA and in accordance with NCIA instructions. All applicable NCIA Terms and Conditions shall apply.

**8\. QUALIFICATIONS**

\[See Requirements\]

## Requirements

**3.4 SECURITY CLEARANCE**

-   The Contractor shall ensure that all the Contractor staff or anyone working under the remit of the Contractor requiring recurring access to on-site locations for the delivery of the services under this SoW, have a valid NATO Personal Security Clearance at least to the NATO COSMIC TOP SECRET level.

**8\. QUALIFICATIONS**

**Required Technical Qualifications and Experience**

-   A minimum of three (3) years of relevant professional experience in firewall administration and network security.
-   Holds a PaloAlto Networks Certified Network Security Engineer (PCNSE) certification, or an equivalent qualification.
-   Holds a CompTIA Security+ certification (pre-2020: Code SY0-601; post-2020: Code SY0-701).
-   In-depth knowledge of PaloAlto firewall configuration, management, and troubleshooting.
-   Understanding of networking protocols and security principles.
-   In-depth knowledge of network infrastructure and architecture.
-   Experience with security policy design and implementation.
-   In-depth knowledge of VPN technologies and configurations.
-   In-depth knowledge of scripting and automation skills.

**Desirable Technical Qualifications and Experience**

-   Holds a PaloAlto Networks Certified Network Security Administrator (PCNSA) certification, with at least three (3) years of experience.
-   Holds a Certified Information Systems Security Professional (CISSP) certification, with at least three (3) years of experience.
-   Holds a Cisco Certified Network Associate (CCNA) certification (Code 200-301), with at least three (3) years of experience.

**Professional Competencies**

-   The ability to listen, speak, read, and write in English to or above NATO SLP 3333 (good/minimum professional), in accordance with STANAG 6001.
-   Proven English language ability to communicate effectively, both orally and in writing, including the ability to deliver clear briefings and articulate complex technical matters.
-   Strong interpersonal skills, with the ability to work effectively in multinational and multidisciplinary environments.
-   The ability to work autonomously with minimal supervision, while contributing effectively as part of a team.
-   Strong analytical and problem-solving capabilities, with a results-oriented approach.
-   Demonstrated ability to interact with users, stakeholders, and technical teams in a professional and collaborative manner.
-   A high level of motivation, adaptability, and professional integrity.
-   In-depth practical understanding of NATO command structures, roles, and organisational context.
-   In-depth practical knowledge of NATO Enterprise Architecture and DCIS services, covering OSI Layers 1-7.
