# 2026-0127 Provision RegOps Engineering to NCIA, SACT and CDT (NS) - FRI 11 Sep

**Company:** [EMW, Inc.](http://jobs.workable.com/companies/rxTcVwBJTwXzUuxD5bzFUW.md)
**Location:** The Hague, Netherlands
**Workplace:** on site
**Employment type:** Contract
**Department:** AAS

[Apply for this job](http://jobs.workable.com/view/80dc2c2e-eeba-42e6-ba89-1491a1433910)

## Description

**BIDDING INSTRUCTIONS**

**A) Technical Proposal**

Bidders shall submit a proposal clearly providing the following information:

a. CV and attestation of the assigned resource for the project that is/are meeting the requirements as per Section 10 (Specific Expertise Required). The CV shall contain accurate contact details for the reference person for each of the listed professional experiences relevant to this Statement of Work.

b. The Proposal shall contain also, at the minimum, the following statements relevant to the proposed contractor personnel:

Relevant experience in providing Regulatory Operations (RegOps) Engineering services, ideally focusing on operationalizing GRC tools: list 2 (two) specific projects in the last 3 years that demonstrate the required experience, including details about objective, output, outcome and role exercised.

Relevant experience working in NATO or national committees and working groups (engineering, capability development): list the groups where this experience was gained in the last 3 years, and the type of activity undertaken.

Experience in using requisite tools, e.g. K8s, Docker, SQL etc.: List at least one project / activity where this experience has been demonstrated and provide details.

**Deadline Date:** Friday 11 September 2026

**Requirement:** Provision of RegOps Engineering to NCIA, SACT and CDT

**Location:** On-Site, NCIA, The Hague, NLD

**Period of Performance:** 2026 BASE: As soon as possible but not later than 12 October 2026, through 31 December 2026

**Required Security Clearance:** NATO SECRET

**STATEMENT OF WORK**

**1\. OVERALL PROJECT SCOPE**

The NATO Communications and Information Agency (NCIA) located in The Hague, The Netherlands, is providing technical support to the NATO HQ Cyber and Digital Transformation (CDT) Division and Supreme Allied Command Transformation (SACT) by moving away from manual point-in-time audits, authorization to operate and security accreditation towards Continuous Governance, Risk and Compliance Auditing leading to Continuous Authorization to Operate (cATO) and Continuous Security Accreditation via EaC (Everything as Code) + Regulatory Operations (RegOps) using NIST OSCAL (Open Security Controls Assessment Language) data models, with the ultimate goal to deploy the RegScale platform as a workload and establish a Minimum Viable Product (MVP) for Continuous Authorization to Operate (cATO).

**2\. ACTIVITIES AND DELIVERABLES**

**2.1 Activities (Non-Deliverable)**

The Contractor shall perform the following activities in support of the deliverables defined in Section 2.2. These activities are not considered deliverables in themselves.

Review the target Kubernetes/PaaS environment and prepare deployment, DB, API gateway, networking and configuration.

Configure and test Entra ID/Azure AD or IAM integration, including role mappings, automated user onboarding and access controls.

Set up and validate integrations with Azure Policy, AWS Security Hub, M365 and Purview to ingest compliance, telemetry and SaaS inventory data.

Verify that imported compliance data, telemetry, control statuses and evidence are correctly received, normalized and mapped within RegScale.

Run controlled test changes to confirm that event-driven updates are detected and reflected accurately in RegScale.

Configure and test automated workflows so that failed controls generate Jira or Azure DevOps tickets.

Conduct Stakeholder Review Sessions to validate assumptions, mappings, etc.

Issue tracking and remediation support.

**2.2 Deliverables**

**D001 – Workload Deployment**

**Deliverable D001:** Deploy RegScale containers into internal PaaS (K8s); configure SQL DB and API Gateway.

**Acceptance Criteria A001:** Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

**D002 – Identity Integration**

**Deliverable D002:** Connect RegScale to Entra ID (Azure AD) or IAM for automated RBAC and user onboarding.

**Acceptance Criteria A002:** Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

**D003 – Cloud Connector Setup**

**Deliverable D003:** Configure API integration with Azure Policy / AWS Security Hub to pull live compliance data.

**Acceptance Criteria A003:** Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

**D004 – SaaS Inventory Sync**

**Deliverable D004:** Onboard M365/Purview telemetry to monitor data sovereignty/sharing settings.

**Acceptance Criteria A004:** Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

**D005 – Initial Drift Detection**

**Deliverable D005:** Test 'event-driven' updates (manually trigger changes to verify platform response).

**Acceptance Criteria A005:** Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

**D006 – POAM Automation**

**Deliverable D006:** Set up automated workflows for 'failed' controls to trigger Jira/DevOps tickets.

**Acceptance Criteria A006:** Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.

**3\. KEY PERFORMANCE INDICATORS (KPI)**

The KPIs measure delivery quality, completeness, technical correctness, governance compliance, and business value. Each deliverable has measurable acceptance KPIs directly linked to payment.

**D001 – Workload Deployment KPIs**

**Platform deployment success:** 100% of RegScale containers successfully deployed into the agreed Kubernetes (K8s) environment with all required services operational.

**Infrastructure configuration:** SQL database, API Gateway and supporting platform services configured and operational with no critical defects.

**Deployment validation:** Successful deployment validation completed with all critical test cases passed (100%).

**Documentation completeness:** Deployment guide, architecture diagram and configuration documentation completed and approved.

**Acceptance:** Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

**D002 – Identity Integration KPIs**

**Identity integration success:** 100% successful integration with Entra ID (Azure AD) or designated IAM platform.

**RBAC implementation:** 100% of agreed user roles and permissions configured and validated.

**Automated onboarding:** ≥95% successful automated provisioning of test users without manual intervention.

**Authentication testing:** 100% of authentication and authorization test scenarios successfully completed.

**Acceptance:** Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

**D003 – Cloud Connector Setup KPIs**

**Connector deployment:** 100% of agreed Azure Policy and/or AWS Security Hub connectors successfully configured.

**Compliance data ingestion:** ≥95% of expected compliance data successfully imported into RegScale.

**Data refresh reliability:** Automated synchronization completes successfully during agreed test cycles with ≥99% successful execution.

**Traceability:** 100% of imported compliance findings linked to corresponding controls.

**Acceptance:** Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

**D004 – SaaS Inventory Sync KPIs**

**Telemetry integration:** 100% successful integration of agreed Microsoft 365/Purview telemetry sources.

**Inventory completeness:** ≥95% of agreed SaaS assets successfully synchronized into RegScale.

**Data quality:** ≥98% synchronization accuracy verified during validation testing.

**Monitoring readiness:** Data sovereignty and sharing settings successfully displayed for all agreed monitored services.

**Acceptance:** Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

**D005 – Initial Drift Detection KPIs**

**Event detection:** 100% of agreed test configuration changes detected by RegScale.

**Detection latency:** Event-driven updates reflected within the agreed response time (e.g. ≤5 minutes or agreed SLA).

**Alert generation:** 100% of drift events generate the expected compliance status update.

**Test completion:** All planned drift detection scenarios executed successfully with documented results.

**Acceptance:** Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

**D006 – POAM Automation KPIs**

**Workflow automation:** 100% of failed control events automatically generate Jira/Azure DevOps work items.

**Workflow accuracy:** ≥95% of automatically created tickets contain complete and correct metadata.

**End-to-end validation:** 100% of workflow scenarios successfully tested from control failure through ticket creation.

**Documentation:** Automation workflow documentation and operational guidance completed and approved.

**Acceptance:** Written approval by the NCIA PM in coordination with the CDT Project Sponsor or designated authority.

**Generic Performance KPIs**

The following Generic Performance KPIs apply across the entire contract and are used as gate criteria before payment.

**Timeliness:** Deliverables submitted according to approved schedule (Target: ≥95%).

**Quality:** Deliverables accepted without major rework (Target: ≥90%).

**Technical Compliance:** Solution complies with approved architecture, security standards and implementation guidelines (Target: 100%).

**Configuration Management:** All configurations version controlled and documented (Target: 100%).

**Documentation:** Technical documentation complete and up to date (Target: 100%).

**Issue Resolution:** Critical implementation defects resolved before milestone acceptance (Target: 100%).

**Communication:** Progress reporting submitted on time (Target: 100%).

**4\. PAYMENT SCHEDULE**

Each milestone payment shall only be released after both the deliverable-specific KPIs and the generic performance KPIs have been achieved.

**Scoring Model:** Deliverable-specific KPIs are weighted 80%; Generic Contract KPIs are weighted 20%.

Milestone Score (%) = (Deliverable KPI Achievement × 80%) + (Generic KPI Achievement × 20%). Payment for each milestone is calculated as: Milestone Payment = Milestone Value × Milestone Score.

**Milestone 1 – D001 Workload Deployment:** Payment: 30% . Payment Conditions: RegScale platform successfully deployed on Kubernetes, infrastructure operational, documentation completed and D001 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

**Milestone 2 – D002 Identity Integration:** Payment: 15% . Payment Conditions: Entra ID/IAM integration completed, RBAC validated and D002 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

**Milestone 3 – D003 Cloud Connector Setup:** Payment: 15%. Payment Conditions: Cloud connectors operational, compliance data successfully ingested and D003 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

**Milestone 4 – D004 SaaS Inventory Sync:** Payment: 15% .Payment Conditions: SaaS telemetry synchronized, monitoring operational and D004 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

**Milestone 5 – D005 Initial Drift Detection:** Payment: 10% Payment Conditions: Drift detection successfully demonstrated and D005 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

**Milestone 6 – D006 POAM Automation:** Payment: 15% Payment Conditions: Automated remediation workflow demonstrated, documentation completed and D006 KPIs achieved. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

Schedule of payments: Payment will be made after the Purchaser has accepted a respective deliverable and signed its Delivery Acceptance Sheet (DAS). The contractor shall submit an invoice, with approved DAS attached, to the Purchaser for payment as per the schedule above.

**5\. SECURITY CLEARANCE**

Services included in this SOW require contractor's personnel to be in the possession of a valid NATO SECRET security clearance from the start of contract.

**6\. PERIOD OF PERFORMANCE**

The 2026 BASE services are to be provided for the period starting NLT 12 October 2026 through 31 December 2026.

**7\. PRACTICAL ARRANGEMENTS**

This is a Completion-type contract which requires one consultant with identified skills to complete the service.

Services will be performed on-site at NCIA, The Hague, who is responsible for office space.

**8\. TRAVEL**

This Task Order does not require any scheduled travel.

All travel expenses, including per diem, lodging and associated expenses for travel are included in the price of the bid (NTE), such that the purchaser shall not be invoiced separately for travel.

Extraordinary Travel (Purchaser Directed Travel) may be required to other NATO or non-NATO locations as necessary. In the event of such unforeseen meetings being called, the cost of all travel and subsistence will be addressed through a contract amendment.

Extraordinary Travel expenses will be reimbursed in accordance with Article 5.5 of the AAS+ Framework Contract. Such costs will be set as a separate PO line with a not-to-exceed value to cover and reimburse actual expenses upon submission of all receipts and invoices in line with NCIA processes.

**9\. CONSTRAINTS**

NATO will retain the intellectual property rights for all products developed in relation to this project.

All deliverables, scripts, documentation and required code will be stored as directed by NCIA.

**10\. SPECIFIC EXPERTISE REQUIRED**

\[See Requirements\]

## Requirements

**5\. SECURITY CLEARANCE**

-   Services included in this SOW require contractor's personnel to be in the possession of a valid NATO SECRET security clearance from the start of contract.

**10\. SPECIFIC EXPERTISE REQUIRED**

The services described in this SOW require contractor personnel with experience in Enterprise Architecture and in addressing challenges related to interoperability.

**Required:**

-   The candidate must have a minimum of a Bachelor's degree from a nationally recognized/certified University in a related discipline and 3 years of related post-degree experience.
-   The candidate must have a minimum of 3 years' experience with Kubernetes, API Integration (REST), Python/Scripting, and CI/CD pipelines.
-   The candidate must have a minimum of 3 years' experience drafting technical data flows.
-   The candidate must have a minimum of 3 years' experience with Webhooks and Jira/ServiceNow APIs.
-   The candidate must have a minimum of 3 years' experience with M365 Graph API and Security Center.
-   The candidate must have a minimum of 3 years' experience with red-teaming compliance.
-   The candidate must have a minimum of 3 years' experience with PowerShell, Cloud APIs, and JSON.
-   The candidate must have a minimum of 3 years' experience with OAuth2, OIDC, and Identity Management.
-   The candidate must have documented (or demonstrable) experience in process analysis and design techniques.

**Desirable Knowledge and Experience:**

-   Robust technical knowledge of NATO operations, responsibilities and organization, with specific focus on how NATO achieves technical interoperability on the battlefield.
-   Comprehensive understanding of NATO's Cloud strategies.
-   Knowledge of ITIL, COBIT, or equivalent.
-   Familiarity with current and evolving capabilities and trends in military and civilian communication protocols and standards.

**Desirable Competencies:**

-   **Deciding and Initiating Action:** Takes responsibility for actions, projects and people; takes initiative and works under own direction; initiates and generates activity and introduces changes into work processes; makes quick, clear decisions which may include tough choices or considered risks.
-   **Adhering to Principles and Values:** Upholds ethics and values; demonstrates integrity; promotes and defends equal opportunities, builds diverse teams; encourages organizational and individual responsibility towards the community and the environment.
-   **Relating and Networking:** Easily establishes good relationships with customers and staff; relates well to people at all levels; builds wide and effective networks of contacts; uses humor appropriately to bring warmth to relationships with others.
-   **Formulating Strategies and Concepts:** Works strategically to realize organizational goals; sets and develops strategies; identifies, develops positive and compelling visions of the organization's future potential; takes account of a wide range of issues across, and related to, the organization.
-   **Achieving Personal Work Goals and Objectives:** Accepts and tackles demanding goals with enthusiasm; works hard and puts in longer hours when it is necessary; seeks progression to roles of increased responsibility and influence; identifies own development needs and makes use of developmental or training opportunities.
