# 2026-0128 Cloud Digital Trust (NS) - FRI 11 Sep

**Company:** [EMW, Inc.](http://jobs.workable.com/companies/rxTcVwBJTwXzUuxD5bzFUW.md)
**Location:** The Hague, Netherlands
**Workplace:** on site
**Employment type:** Contract
**Department:** AAS

[Apply for this job](http://jobs.workable.com/view/8c98a6f7-ebc0-4dcc-abe1-818d07e5ba83)

## Description

**BIDDING INSTRUCTIONS**

**1\. Bidding Instructions**

**A) Technical Proposal**

Bidders shall submit a proposal clearly providing the following information:

a. CV and attestation of the assigned resource for the project that is/are meeting the requirements as per Section 10 (Specific Expertise Required). The CV shall contain accurate contact details for the reference person for each of the listed professional experiences relevant to this Statement of Work.

b. The Proposal shall contain also, at the minimum, the following statements relevant to the proposed contractor personnel:

Relevant experience in providing Strategic influence, Change Management, Budgeting, Risk Communication. Responsible for ROI and C-Suite alignment, ideally focusing on operationalizing GRC tools: list 2 (two) specific projects in the last 3 years that demonstrate the required experience, including details about objective, output, outcome and role exercised.

Relevant experience working in NATO or national committees and working groups (engineering, capability development): list the groups where this experience was gained in the last 3 years, and the type of activity undertaken.

**Deadline Date:** Friday 11 September 2026

**Requirement:** Cloud Digital Trust

**Location:** On-Site, NCIA, The Hague, NLD

**Period of Performance:** 2026 BASE: As soon as possible but not later than 12 October 2026, through 31 December 2026

**Required Security Clearance:** NATO SECRET

**STATEMENT OF WORK**

**1\. OVERALL PROJECT SCOPE**

The NATO Communications and Information Agency (NCIA) located in The Hague, The Netherlands, is providing technical support to the NATO HQ Cyber and Digital Transformation (CDT) Division and Supreme Allied Command Transformation (SACT) by moving away from manual point-in-time audits, authorization to operate and security accreditation towards Continuous Governance, Risk and Compliance Auditing leading to Continuous Authorization to Operate (cATO) and Continuous Security Accreditation via EaC (Everything as Code) + Regulatory Operations (RegOps) using NIST OSCAL (Open Security Controls Assessment Language) data models, with the ultimate goal to deploy the RegScale platform as a workload and establish a Minimum Viable Product (MVP) for Continuous Authorization to Operate (cATO).

**2\. ACTIVITIES AND DELIVERABLES**

**2.1 Activities (Non-Deliverable)**

The Contractor shall perform the following activities in support of the deliverables defined in Section 2.2. These activities are not considered deliverables in themselves.

-   Facilitate stakeholder discussion to confirm the pilot scope, target environment, priority SaaS application, success criteria, and key risk areas.
-   Coordinate with Cloud, compliance, audit and business stakeholders to agree on roles and responsibilities, dependencies, and decision points of the pilot.
-   Review whether automated evidence from cloud and/or SaaS is complete, reliable, traceable, and suitable.
-   Mapping “digital evidence” to relevant controls, audit requirements and assurance expectations.
-   Review dashboard content to ensure it accurately reflects live risk posture, control status and compliance.
-   Prepare C-suite demo flow to explain live dashboard, key insights and business value.
-   Conduct Stakeholder Review Sessions to validate assumptions, mappings, etc.
-   Issue tracking and remediation support.

**2.2 Deliverables**

**D001 – Pilot Scope and Governance Baseline (document)**

**Deliverable D001:** a signed-off Pilot Definition Document containing: the named pilot environment (specific Azure Landing Zone or SaaS application); quantified success criteria for the pilot (e.g. number of controls under continuous monitoring, evidence refresh frequency, target reduction in manual audit effort); a RACI covering cloud, compliance, audit and business stakeholders; the selected control framework baseline to be expressed in OSCAL; and a risk and dependency register with owners.

**Acceptance Criteria A001:** Document approved in writing by the NCIA PM.

**D002 – Digital Evidence Assessment and Audit Readiness Report (document plus mapping artifact)**

**Deliverable D002:** a control-to-evidence mapping matrix covering 100% of the controls in the agreed pilot baseline, identifying for each control the automated evidence source, collection method, and traceability path, delivered in OSCAL-compatible format where feasible; an assessment of each evidence source against completeness, reliability, traceability and suitability; a gap and remediation log with prioritised actions; and a written internal audit validation memo confirming which controls the digital evidence satisfies and which require compensating manual evidence.

**Acceptance Criteria A002:** Mapping matrix covers the full pilot baseline; approved in writing by the NCIA PM.

**D003 – Executive Demo Package and Scaling Recommendation (working demo plus documents)**

**Deliverable D003:** a configured Live Trust Dashboard in the pilot environment showing real-time control status, risk posture and compliance state for the pilot scope; the executive briefing deck and demo script used for the Board presentation; a one-page business value summary quantifying audit effort saved and risk visibility gained; and a recommendation report describing the path from pilot to cATO MVP on RegScale, including resourcing, licensing and dependency assumptions.

**Acceptance Criteria A003:** Demo delivered to the Board or delegated executive audience; all artifacts handed over and stored as directed by NCIA per Section 9.

**3\. KEY PERFORMANCE INDICATORS**

The KPIs measure delivery quality, completeness, technical correctness, governance compliance, and business value. Each deliverable has measurable acceptance KPIs directly linked to payment.

**D001 – Pilot Scope and Governance Baseline KPIs**

**Governance documentation completeness:** 100% of mandatory sections (pilot definition, success criteria, RACI, OSCAL baseline, risk & dependency register) delivered and accepted without missing mandatory content.

**Stakeholder approval:** Written approval by NCIA PM with no more than one consolidated review cycle required.

**Timeliness:** Delivered within the agreed contractual milestone date.

**Traceability:** 100% of identified risks and dependencies assigned to named owners and linked to pilot objectives.

**D002 – Digital Evidence Assessment and Audit Readiness Report KPIs**

**Control coverage:** 100% of agreed pilot controls mapped to digital evidence sources.

**Evidence quality assessment:** 100% of evidence sources assessed against completeness, reliability, traceability and suitability.

**Gap identification:** 100% of identified evidence gaps documented with prioritised remediation actions.

**Audit readiness:** Internal audit validation memo accepted confirming automated versus manual evidence coverage.

**OSCAL compatibility:** ≥95% of control mappings delivered in OSCAL-compatible format where technically feasible.

**D003 – Executive Demo Package and Scaling Recommendation KPIs**

**Dashboard functionality:** Live Trust Dashboard demonstrates 100% of agreed pilot controls, compliance status and risk posture during executive demonstration.

**Executive package completeness:** Executive briefing, demo script, business value summary and scaling recommendation delivered and accepted.

**Business value quantification:** Business value summary includes quantified estimates for audit effort reduction, compliance visibility and operational benefits.

**Knowledge transfer:** 100% of deliverables, configurations and supporting documentation handed over and stored in NCIA-designated repository.

**Executive demonstration:** Successful demonstration completed to Board or delegated executive audience with no critical demonstration failures.

**Generic Performance KPIs**

The following Generic Performance KPIs apply across the entire contract and are used as gate criteria before payment.

**Timeliness:** Deliverables submitted on schedule (Target: ≥95%).

**Quality:** Deliverables accepted without major rework (Target: ≥90%).

**Documentation:** Mandatory documentation complete (Target: 100%).

**Governance:** Activities traceable and documented (Target: 100%).

**Communication:** Progress reporting submitted on time (Target: 100%).

**Risk Management:** Risks escalated within agreed timeframe (Target: ≥95%).

**4\. PAYMENT SCHEDULE**

Each milestone payment shall only be released after both the deliverable-specific KPIs and the generic performance KPIs have been achieved.

**Scoring Model:** Deliverable-specific KPIs are weighted 80%; Generic Contract KPIs are weighted 20%.

Milestone Score (%) = (Deliverable KPI Achievement × 80%) + (Generic KPI Achievement × 20%). Payment for each milestone is calculated as: Milestone Payment = Milestone Value × Milestone Score.

**Milestone 1 – D001 Pilot Scope and Governance Baseline:** Payment: 30% Payment Conditions: Written acceptance of the Pilot Definition Document by the NCIA PM and achievement of all D001 KPIs. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

**Milestone 2 – D002 Digital Evidence Assessment and Audit Readiness Report:** Payment: 40% Payment Conditions: Acceptance of the evidence mapping package, audit readiness report and achievement of all D002 KPIs. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

**Milestone 3 – D003 Executive Demo Package and Scaling Recommendation:** Payment: 30% Payment Conditions: Successful executive demonstration, handover of all artifacts and achievement of all D003 KPIs. Payment Milestone: After deliverable completion and signed Delivery Acceptance Sheet (DAS).

Schedule of payments: Payment will be made after the Purchaser has accepted a respective deliverable and signed its Delivery Acceptance Sheet (DAS). The contractor shall submit an invoice, with approved DAS attached, to the Purchaser for payment as per the schedule above.

**5\. SECURITY CLEARANCE**

Services included in this SOW require contractor's personnel to be in the possession of a valid NATO SECRET security clearance from the start of contract.

**6\. PERIOD OF PERFORMANCE**

The 2026 BASE services are to be provided for the period starting NLT 12 October 2026 through 31 December 2026.

**7\. PRACTICAL ARRANGEMENTS**

This is a Completion-type contract which requires one consultant with identified skills to complete the service.

Services will be performed on-site at NCIA, The Hague, who is responsible for office space.

**8\. TRAVEL**

This Task Order does not require any scheduled travel.

All travel expenses, including per diem, lodging and associated expenses for travel are included in the price of the bid (NTE), such that the purchaser shall not be invoiced separately for travel.

Extraordinary Travel (Purchaser Directed Travel) may be required to other NATO or non-NATO locations as necessary. In the event of such unforeseen meetings being called, the cost of all travel and subsistence will be addressed through a contract amendment.

Extraordinary Travel expenses will be reimbursed in accordance with Article 5.5 of the AAS+ Framework Contract. Such costs will be set as a separate PO line with a not-to-exceed value to cover and reimburse actual expenses upon submission of all receipts and invoices in line with NCIA processes.

**9\. CONSTRAINTS**

NATO will retain the intellectual property rights for all products developed in relation to this project.

All deliverables, scripts, documentation and required code will be stored as directed by NCIA.

**10\. SPECIFIC EXPERTISE REQUIRED**

\[See Requirements\]

## Requirements

**5\. SECURITY CLEARANCE**

-   Services included in this SOW require contractor's personnel to be in the possession of a valid NATO SECRET security clearance from the start of contract.

**10\. SPECIFIC EXPERTISE REQUIRED**

The services described in this SOW require contractor personnel with experience in Enterprise Architecture and in addressing challenges related to interoperability.

**Required:**

-   The candidate must have a minimum of a Bachelor's degree from a nationally recognized/certified University in a related discipline and 3 years of related post-degree experience.
-   The candidate must have a minimum of 3 years' experience in Leadership.
-   The candidate must have a minimum of 3 years' experience in Communication.
-   The candidate must have a minimum of 3 years' experience in Strategy.
-   The candidate must have a minimum of 3 years' experience in Risk Management.
-   The candidate must have a minimum of 3 years' experience in Audit standards.
-   The candidate must have a minimum of 3 years' experience in Storytelling and ROI Analysis.
-   The candidate must have documented (or demonstrable) experience in process analysis and design techniques.

**Desirable Knowledge and Experience:**

-   Robust technical knowledge of NATO operations, responsibilities and organization, with specific focus on how NATO achieves technical interoperability on the battlefield.
-   Comprehensive understanding of NATO's Cloud strategies.
-   Knowledge of ITIL, COBIT, or equivalent.
-   Familiarity with current and evolving capabilities and trends in military and civilian communication protocols and standards.

**Desirable Competencies:**

-   **Deciding and Initiating Action:** Takes responsibility for actions, projects and people; takes initiative and works under own direction; initiates and generates activity and introduces changes into work processes; makes quick, clear decisions which may include tough choices or considered risks.
-   **Adhering to Principles and Values:** Upholds ethics and values; demonstrates integrity; promotes and defends equal opportunities, builds diverse teams; encourages organizational and individual responsibility towards the community and the environment.
-   **Relating and Networking:** Easily establishes good relationships with customers and staff; relates well to people at all levels; builds wide and effective networks of contacts; uses humor appropriately to bring warmth to relationships with others.
-   **Formulating Strategies and Concepts:** Works strategically to realize organizational goals; sets and develops strategies; identifies, develops positive and compelling visions of the organization's future potential; takes account of a wide range of issues across, and related to, the organization.
-   **Achieving Personal Work Goals and Objectives:** Accepts and tackles demanding goals with enthusiasm; works hard and puts in longer hours when it is necessary; seeks progression to roles of increased responsibility and influence; identifies own development needs and makes use of developmental or training opportunities.
