[
  {
    "acceptanceEvidence": [
      "named approvers",
      "signed scope",
      "resolved ownership",
      "expiry and review dates",
      "open-question register"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "document review and owner attestation",
        "criterion": "Authority completeness",
        "requiredResult": "Every action class has a named competent authority or an explicit UNAVAILABLE state"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "traceability replay",
        "criterion": "Scope precision",
        "requiredResult": "Assets, effects, locations, time window and exclusions are bounded"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "graph propagation test",
        "criterion": "Negative result preservation",
        "requiredResult": "Unresolved authority remains visible and blocks downstream readiness"
      }
    ],
    "bidEvaluationCriteria": [
      "demonstrated authority-analysis method",
      "ability to preserve unresolved conclusions",
      "conflict-of-interest disclosure",
      "evidence-delivery and data-rights plan",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "controlling authority instruments",
      "asset and service ownership records",
      "jurisdiction facts",
      "mission-essential function list",
      "stakeholder and escalation contacts"
    ],
    "deliverables": [
      "mission thread",
      "authority matrix",
      "allowed-action matrix",
      "prohibited-outcome register",
      "decision and escalation map"
    ],
    "dependencies": [],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no self-generated authority",
      "no target package",
      "no legal opinion without retained counsel"
    ],
    "id": "WP-K06-01",
    "inputs": [
      "mission statement",
      "authority instruments",
      "asset ownership",
      "stakeholder map",
      "jurisdiction facts"
    ],
    "k07Id": "WP-K07-01",
    "name": "Mission and authority analysis",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Define the protected mission, competent authorities, asset scope, allowed actions, prohibited outcomes, decision rights, deconfliction, and evidence obligations before technology selection.",
    "slug": "mission-analysis",
    "statementOfWork": {
      "contractorDeliverables": [
        "mission thread",
        "authority matrix",
        "allowed-action matrix",
        "prohibited-outcome register",
        "decision and escalation map"
      ],
      "dependencies": [],
      "exclusions": [
        "no self-generated authority",
        "no target package",
        "no legal opinion without retained counsel"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "controlling authority instruments",
        "asset and service ownership records",
        "jurisdiction facts",
        "mission-essential function list",
        "stakeholder and escalation contacts"
      ],
      "performanceOutcomes": [
        "approved mission boundary",
        "competent-authority register",
        "prohibited-outcome and deconfliction baseline",
        "decision-expiry and review schedule"
      ],
      "performanceStandards": [
        "Every action class has a named competent authority or an explicit UNAVAILABLE state",
        "Assets, effects, locations, time window and exclusions are bounded",
        "Unresolved authority remains visible and blocks downstream readiness"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Define the protected mission, competent authorities, asset scope, allowed actions, prohibited outcomes, decision rights, deconfliction, and evidence obligations before technology selection.",
      "qualitySurveillance": [
        "document review and owner attestation",
        "traceability replay",
        "graph propagation test"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "cross-discipline participation",
      "traceable pathways",
      "independent challenge",
      "owner disposition for every HCE"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "cross-discipline review",
        "criterion": "HCE traceability",
        "requiredResult": "Every HCE maps to functions, pathways, controls and owners"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "independent challenge",
        "criterion": "Consequence coverage",
        "requiredResult": "Physical, cyber, power, cooling and restoration consequences are represented"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "artifact inspection",
        "criterion": "No topology publication",
        "requiredResult": "Sensitive facility details remain access-controlled"
      }
    ],
    "bidEvaluationCriteria": [
      "CIE/CCE facilitation experience",
      "cross-discipline engineering capability",
      "high-consequence evidence handling",
      "safe abstraction method",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "hazard analyses",
      "process and protection diagrams",
      "operating envelopes",
      "maintenance pathways",
      "external service dependencies"
    ],
    "deliverables": [
      "HCE register",
      "critical-function model",
      "consequence pathways",
      "mitigation candidates",
      "unverified-trust register"
    ],
    "dependencies": [
      "WP-K06-01"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no production exploitation",
      "no publication of real facility topology"
    ],
    "id": "WP-K06-02",
    "inputs": [
      "mission analysis",
      "process diagrams",
      "hazard analysis",
      "asset and dependency inventory"
    ],
    "k07Id": "WP-K07-02",
    "name": "Consequence-driven Cyber-informed Engineering workshop",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Identify high-consequence events, critical functions, system-of-systems pathways, digital dependencies, and engineered-out attack paths.",
    "slug": "cce-workshop",
    "statementOfWork": {
      "contractorDeliverables": [
        "HCE register",
        "critical-function model",
        "consequence pathways",
        "mitigation candidates",
        "unverified-trust register"
      ],
      "dependencies": [
        "WP-K06-01"
      ],
      "exclusions": [
        "no production exploitation",
        "no publication of real facility topology"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "hazard analyses",
        "process and protection diagrams",
        "operating envelopes",
        "maintenance pathways",
        "external service dependencies"
      ],
      "performanceOutcomes": [
        "high-consequence event register",
        "critical-function model",
        "system-of-systems dependency map",
        "engineered-out consequence-path recommendations"
      ],
      "performanceStandards": [
        "Every HCE maps to functions, pathways, controls and owners",
        "Physical, cyber, power, cooling and restoration consequences are represented",
        "Sensitive facility details remain access-controlled"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Identify high-consequence events, critical functions, system-of-systems pathways, digital dependencies, and engineered-out attack paths.",
      "qualitySurveillance": [
        "cross-discipline review",
        "independent challenge",
        "artifact inspection"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "source artifacts",
      "versioned diagrams",
      "finding reproducibility",
      "owner and due date"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "finding replay",
        "criterion": "Reproducibility",
        "requiredResult": "Every finding cites a versioned source artifact"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "coverage matrix",
        "criterion": "Boundary coverage",
        "requiredResult": "IT, OT, power, cooling, physical, timing, model and recovery planes are assessed"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "activity log review",
        "criterion": "No uncontrolled scanning",
        "requiredResult": "Fragile OT is not actively scanned without site approval"
      }
    ],
    "bidEvaluationCriteria": [
      "cyber-physical architecture depth",
      "OT-safe assessment method",
      "evidence provenance tooling",
      "independence from product resale incentives",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "logical and physical diagrams",
      "configuration baselines",
      "identity and key architecture",
      "power and cooling controls",
      "OT and timing interfaces"
    ],
    "deliverables": [
      "architecture findings",
      "trust-zone model",
      "critical-interface register",
      "defeater register",
      "remediation roadmap"
    ],
    "dependencies": [
      "WP-K06-01",
      "WP-K06-02"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no certification claim",
      "no uncontrolled active scanning of fragile OT"
    ],
    "id": "WP-K06-03",
    "inputs": [
      "CCE outputs",
      "logical and physical architecture",
      "configuration baselines",
      "trust relationships"
    ],
    "k07Id": "WP-K07-03",
    "name": "Cyber-physical architecture assessment",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Assess separation, identity, management planes, OT, power, cooling, timing, physical sensing, autonomy, evidence, and recovery against the consequence model.",
    "slug": "architecture-assessment",
    "statementOfWork": {
      "contractorDeliverables": [
        "architecture findings",
        "trust-zone model",
        "critical-interface register",
        "defeater register",
        "remediation roadmap"
      ],
      "dependencies": [
        "WP-K06-01",
        "WP-K06-02"
      ],
      "exclusions": [
        "no certification claim",
        "no uncontrolled active scanning of fragile OT"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "logical and physical diagrams",
        "configuration baselines",
        "identity and key architecture",
        "power and cooling controls",
        "OT and timing interfaces"
      ],
      "performanceOutcomes": [
        "versioned architecture baseline",
        "trust and management-plane analysis",
        "defeater and common-cause register",
        "prioritized remediation roadmap"
      ],
      "performanceStandards": [
        "Every finding cites a versioned source artifact",
        "IT, OT, power, cooling, physical, timing, model and recovery planes are assessed",
        "Fragile OT is not actively scanned without site approval"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Assess separation, identity, management planes, OT, power, cooling, timing, physical sensing, autonomy, evidence, and recovery against the consequence model.",
      "qualitySurveillance": [
        "finding replay",
        "coverage matrix",
        "activity log review"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "exact source references",
      "scope owner approval",
      "gaps and compensating measures",
      "review cadence"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "mapping validation",
        "criterion": "Applicability explicit",
        "requiredResult": "Every control is exact, partial, informative, conflicting, superseded, not applicable or unresolved"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "citation replay",
        "criterion": "Source precision",
        "requiredResult": "Mappings cite exact current source sections"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "language audit",
        "criterion": "No certification leap",
        "requiredResult": "Control selection is not represented as compliance"
      }
    ],
    "bidEvaluationCriteria": [
      "framework interpretation competence",
      "source-currentness process",
      "ability to document non-applicability",
      "control-neutral architecture",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "applicable authority and contract scope",
      "facility pattern and site facts",
      "source requirements",
      "architecture findings",
      "risk and license conditions"
    ],
    "deliverables": [
      "tailored control baseline",
      "mapping-quality register",
      "not-applicable decisions",
      "conflict and supersession log",
      "implementation evidence plan"
    ],
    "dependencies": [
      "WP-K06-03"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no compliance certificate",
      "no silent inheritance of framework scope"
    ],
    "id": "WP-K06-04",
    "inputs": [
      "architecture findings",
      "facility profile",
      "source requirements",
      "license and contract scope"
    ],
    "k07Id": "WP-K07-04",
    "name": "Control tailoring and applicability determination",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Select, modify, reject, or defer controls with explicit mapping quality, applicability evidence, and unresolved gaps.",
    "slug": "control-tailoring",
    "statementOfWork": {
      "contractorDeliverables": [
        "tailored control baseline",
        "mapping-quality register",
        "not-applicable decisions",
        "conflict and supersession log",
        "implementation evidence plan"
      ],
      "dependencies": [
        "WP-K06-03"
      ],
      "exclusions": [
        "no compliance certificate",
        "no silent inheritance of framework scope"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "applicable authority and contract scope",
        "facility pattern and site facts",
        "source requirements",
        "architecture findings",
        "risk and license conditions"
      ],
      "performanceOutcomes": [
        "site-specific control baseline",
        "applicability and mapping-quality decisions",
        "compensating-measure register",
        "implementation and evidence plan"
      ],
      "performanceStandards": [
        "Every control is exact, partial, informative, conflicting, superseded, not applicable or unresolved",
        "Mappings cite exact current source sections",
        "Control selection is not represented as compliance"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Select, modify, reject, or defer controls with explicit mapping quality, applicability evidence, and unresolved gaps.",
      "qualitySurveillance": [
        "mapping validation",
        "citation replay",
        "language audit"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "isolation test",
      "effects-disabled substitutes",
      "scenario traceability",
      "independent stop test",
      "clean reset"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "independent network and artifact inspection",
        "criterion": "Isolation",
        "requiredResult": "No production route, credential or uncontrolled effect path exists"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "schema validation",
        "criterion": "Traceability",
        "requiredResult": "Every scenario maps to claims, controls and expected evidence"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "repeatable reset exercise",
        "criterion": "Reset",
        "requiredResult": "Known-good state and cleanup are demonstrated"
      }
    ],
    "bidEvaluationCriteria": [
      "high-consequence range experience",
      "fault-injection safety",
      "digital-twin trust model",
      "non-actionable public reporting",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "assurance claims",
      "hazards and safety envelope",
      "system models",
      "control baseline",
      "approved synthetic or sanitized data"
    ],
    "deliverables": [
      "range architecture",
      "scenario set",
      "fault-injection plan",
      "stop authority",
      "reset and artifact-removal procedure"
    ],
    "dependencies": [
      "WP-K06-02",
      "WP-K06-04"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no public exploit chain",
      "no unauthorized target",
      "no destructive production test"
    ],
    "id": "WP-K06-05",
    "inputs": [
      "assurance claims",
      "tailored controls",
      "hazards",
      "system models",
      "safety envelope"
    ],
    "k07Id": "WP-K07-05",
    "name": "Evaluation-range design",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Design an isolated, effects-bounded range or digital twin that can test claims without exposing production systems or reusable attack procedures.",
    "slug": "range-design",
    "statementOfWork": {
      "contractorDeliverables": [
        "range architecture",
        "scenario set",
        "fault-injection plan",
        "stop authority",
        "reset and artifact-removal procedure"
      ],
      "dependencies": [
        "WP-K06-02",
        "WP-K06-04"
      ],
      "exclusions": [
        "no public exploit chain",
        "no unauthorized target",
        "no destructive production test"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "assurance claims",
        "hazards and safety envelope",
        "system models",
        "control baseline",
        "approved synthetic or sanitized data"
      ],
      "performanceOutcomes": [
        "isolated evaluation architecture",
        "effects-bounded scenario suite",
        "stop and reset mechanism",
        "artifact-removal and evidence-preservation procedure"
      ],
      "performanceStandards": [
        "No production route, credential or uncontrolled effect path exists",
        "Every scenario maps to claims, controls and expected evidence",
        "Known-good state and cleanup are demonstrated"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Design an isolated, effects-bounded range or digital twin that can test claims without exposing production systems or reusable attack procedures.",
      "qualitySurveillance": [
        "independent network and artifact inspection",
        "schema validation",
        "repeatable reset exercise"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "reproducible evaluations",
      "frozen artifacts",
      "independent challenge",
      "bounded failure behavior"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "hash and lineage replay",
        "criterion": "Provenance",
        "requiredResult": "Model, data, code and evaluation artifacts are versioned and linked"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "policy enforcement test",
        "criterion": "Bounded authority",
        "requiredResult": "Tool and actuator permissions are explicit and testable"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "fault-injection exercise",
        "criterion": "Failure behavior",
        "requiredResult": "Fallback and rollback operate under declared uncertainty"
      }
    ],
    "bidEvaluationCriteria": [
      "model-system assurance depth",
      "adversarial evaluation method",
      "secure evidence handling",
      "vendor-independent test design",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "model inventory and hashes",
      "training/evaluation data lineage",
      "tool interfaces",
      "system prompts and policies under controlled access",
      "runtime telemetry and incident history"
    ],
    "deliverables": [
      "model assurance case",
      "adversarial evaluation summary",
      "tool-authority matrix",
      "drift and rollback plan",
      "unresolved model risks"
    ],
    "dependencies": [
      "WP-K06-04",
      "WP-K06-05"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no claim that benchmark success proves field judgment",
      "no unrestricted tool use"
    ],
    "id": "WP-K06-06",
    "inputs": [
      "model inventory",
      "training and evaluation records",
      "tool policy",
      "agent architecture",
      "safety constraints"
    ],
    "k07Id": "WP-K07-06",
    "name": "Model and autonomous-agent assurance",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Evaluate model provenance, data lineage, adversarial robustness, tool authority, memory boundaries, drift, fallback, and runtime constraints.",
    "slug": "model-assurance",
    "statementOfWork": {
      "contractorDeliverables": [
        "model assurance case",
        "adversarial evaluation summary",
        "tool-authority matrix",
        "drift and rollback plan",
        "unresolved model risks"
      ],
      "dependencies": [
        "WP-K06-04",
        "WP-K06-05"
      ],
      "exclusions": [
        "no claim that benchmark success proves field judgment",
        "no unrestricted tool use"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "model inventory and hashes",
        "training/evaluation data lineage",
        "tool interfaces",
        "system prompts and policies under controlled access",
        "runtime telemetry and incident history"
      ],
      "performanceOutcomes": [
        "model and data provenance baseline",
        "tool-authority and memory-boundary matrix",
        "adversarial robustness evidence",
        "drift, rollback and fallback plan"
      ],
      "performanceStandards": [
        "Model, data, code and evaluation artifacts are versioned and linked",
        "Tool and actuator permissions are explicit and testable",
        "Fallback and rollback operate under declared uncertainty"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Evaluate model provenance, data lineage, adversarial robustness, tool authority, memory boundaries, drift, fallback, and runtime constraints.",
      "qualitySurveillance": [
        "hash and lineage replay",
        "policy enforcement test",
        "fault-injection exercise"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "measured RTO/RPO",
      "clean-room proof",
      "independent observation",
      "defect closure plan"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "timed exercise",
        "criterion": "Measured restoration",
        "requiredResult": "RTO/RPO and safety objectives are directly observed"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "independent verification",
        "criterion": "Clean state",
        "requiredResult": "Recovered artifacts match approved hashes and compromise checks"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "readiness graph test",
        "criterion": "Negative result",
        "requiredResult": "Missed objectives remain recorded and propagate"
      }
    ],
    "bidEvaluationCriteria": [
      "recovery exercise leadership",
      "forensic continuity",
      "power/cooling/OT restoration experience",
      "negative-result discipline",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "RTO/RPO objectives",
      "known-good artifacts",
      "backup and key inventories",
      "dependency restoration order",
      "incident command and evidence rules"
    ],
    "deliverables": [
      "exercise plan",
      "restoration chronology",
      "evidence-preservation record",
      "reinfection checks",
      "lessons and corrective actions"
    ],
    "dependencies": [
      "WP-K06-05",
      "WP-K06-06"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no tabletop-only claim of operational recovery",
      "no destruction of production evidence"
    ],
    "id": "WP-K06-07",
    "inputs": [
      "recovery objectives",
      "known-good artifacts",
      "backup inventory",
      "incident command",
      "range environment"
    ],
    "k07Id": "WP-K07-07",
    "name": "Critical-function recovery exercise",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Demonstrate clean restoration of minimum viable mission and safe functions under isolated, degraded, and compromise-assumed conditions.",
    "slug": "recovery-exercise",
    "statementOfWork": {
      "contractorDeliverables": [
        "exercise plan",
        "restoration chronology",
        "evidence-preservation record",
        "reinfection checks",
        "lessons and corrective actions"
      ],
      "dependencies": [
        "WP-K06-05",
        "WP-K06-06"
      ],
      "exclusions": [
        "no tabletop-only claim of operational recovery",
        "no destruction of production evidence"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "RTO/RPO objectives",
        "known-good artifacts",
        "backup and key inventories",
        "dependency restoration order",
        "incident command and evidence rules"
      ],
      "performanceOutcomes": [
        "measured minimum-viable mission restoration",
        "clean-room recovery evidence",
        "reinfection and integrity checks",
        "corrective-action register"
      ],
      "performanceStandards": [
        "RTO/RPO and safety objectives are directly observed",
        "Recovered artifacts match approved hashes and compromise checks",
        "Missed objectives remain recorded and propagate"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Demonstrate clean restoration of minimum viable mission and safe functions under isolated, degraded, and compromise-assumed conditions.",
      "qualitySurveillance": [
        "timed exercise",
        "independent verification",
        "readiness graph test"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "complete graph validation",
      "checksums",
      "signature validation where supplied",
      "stale-evidence propagation",
      "owner sign-off"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "graph validation",
        "criterion": "Completeness",
        "requiredResult": "Every mandatory dependency resolves or is visibly unavailable"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "manifest replay",
        "criterion": "Integrity",
        "requiredResult": "Every artifact has a digest and provenance record"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "independent audit",
        "criterion": "No suppression",
        "requiredResult": "Negative, disputed and superseded evidence remains accessible"
      }
    ],
    "bidEvaluationCriteria": [
      "evidence architecture",
      "machine-readable delivery",
      "signature and custody controls",
      "correction and supersession workflow",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "all approved work-package artifacts",
      "source snapshots",
      "test evidence",
      "exceptions and incidents",
      "authority and acceptance records"
    ],
    "deliverables": [
      "machine-readable assurance graph",
      "human assurance report",
      "evidence manifest",
      "defeater status",
      "readiness recommendation"
    ],
    "dependencies": [
      "WP-K06-01",
      "WP-K06-02",
      "WP-K06-03",
      "WP-K06-04",
      "WP-K06-05",
      "WP-K06-06",
      "WP-K06-07"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no suppression of negative evidence",
      "no conversion of unavailable evidence into pass"
    ],
    "id": "WP-K06-08",
    "inputs": [
      "all prior work-package artifacts",
      "source snapshots",
      "test results",
      "exceptions",
      "authority records"
    ],
    "k07Id": "WP-K07-08",
    "name": "Assurance evidence package",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Assemble claim-to-control-to-test-to-evidence traceability, provenance, currentness, signatures, limitations, defects, and decision receipts.",
    "slug": "evidence-package",
    "statementOfWork": {
      "contractorDeliverables": [
        "machine-readable assurance graph",
        "human assurance report",
        "evidence manifest",
        "defeater status",
        "readiness recommendation"
      ],
      "dependencies": [
        "WP-K06-01",
        "WP-K06-02",
        "WP-K06-03",
        "WP-K06-04",
        "WP-K06-05",
        "WP-K06-06",
        "WP-K06-07"
      ],
      "exclusions": [
        "no suppression of negative evidence",
        "no conversion of unavailable evidence into pass"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "all approved work-package artifacts",
        "source snapshots",
        "test evidence",
        "exceptions and incidents",
        "authority and acceptance records"
      ],
      "performanceOutcomes": [
        "complete claim-control-test-evidence graph",
        "signed or checksummed evidence manifest",
        "defeater and stale-state report",
        "decision-ready human and machine reports"
      ],
      "performanceStandards": [
        "Every mandatory dependency resolves or is visibly unavailable",
        "Every artifact has a digest and provenance record",
        "Negative, disputed and superseded evidence remains accessible"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Assemble claim-to-control-to-test-to-evidence traceability, provenance, currentness, signatures, limitations, defects, and decision receipts.",
      "qualitySurveillance": [
        "graph validation",
        "manifest replay",
        "independent audit"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "organizational independence",
      "repeatable methods",
      "signed findings",
      "disagreement preservation"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "organizational review",
        "criterion": "Independence",
        "requiredResult": "Verifier has no delivery-team decision conflict"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "technical replay",
        "criterion": "Replay",
        "requiredResult": "Selected claims and evidence can be independently reproduced"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "record audit",
        "criterion": "Disagreement preservation",
        "requiredResult": "Unresolved disputes remain in final record"
      }
    ],
    "bidEvaluationCriteria": [
      "independence",
      "replay capability",
      "high-consequence domain expertise",
      "willingness to issue adverse findings",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "complete evidence package",
      "approved range access",
      "acceptance criteria",
      "source and mapping records",
      "organizational independence disclosures"
    ],
    "deliverables": [
      "independent findings",
      "replay results",
      "mapping disputes",
      "residual-risk statement",
      "verification decision"
    ],
    "dependencies": [
      "WP-K06-08"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "no self-verification represented as independent",
      "no regulator impersonation"
    ],
    "id": "WP-K06-09",
    "inputs": [
      "evidence package",
      "access to approved range",
      "source records",
      "decision criteria"
    ],
    "k07Id": "WP-K07-09",
    "name": "Independent verification",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "Challenge the assurance argument, replay evidence, test mappings, inspect defeaters, and record disagreements without inheriting the delivery team's conclusions.",
    "slug": "independent-verification",
    "statementOfWork": {
      "contractorDeliverables": [
        "independent findings",
        "replay results",
        "mapping disputes",
        "residual-risk statement",
        "verification decision"
      ],
      "dependencies": [
        "WP-K06-08"
      ],
      "exclusions": [
        "no self-verification represented as independent",
        "no regulator impersonation"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "complete evidence package",
        "approved range access",
        "acceptance criteria",
        "source and mapping records",
        "organizational independence disclosures"
      ],
      "performanceOutcomes": [
        "independent replay results",
        "mapping and evidence disputes",
        "residual-risk statement",
        "signed verification decision with limitations"
      ],
      "performanceStandards": [
        "Verifier has no delivery-team decision conflict",
        "Selected claims and evidence can be independently reproduced",
        "Unresolved disputes remain in final record"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "Challenge the assurance argument, replay evidence, test mappings, inspect defeaters, and record disagreements without inheriting the delivery team's conclusions.",
      "qualitySurveillance": [
        "organizational review",
        "technical replay",
        "record audit"
      ]
    }
  },
  {
    "acceptanceEvidence": [
      "exact host observations",
      "timestamps",
      "body and artifact hashes",
      "authority to observe",
      "owner disposition"
    ],
    "acceptanceMatrix": [
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "authorization check",
        "criterion": "Owner confirmation",
        "requiredResult": "Observation does not begin before deployment confirmation"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "hash and response replay",
        "criterion": "Exact comparison",
        "requiredResult": "Deployed artifacts and configuration are compared to approved manifest"
      },
      {
        "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
        "assessmentMethod": "evidence review",
        "criterion": "Operation boundary",
        "requiredResult": "Page availability is not treated as protected-system operation"
      }
    ],
    "bidEvaluationCriteria": [
      "live verification discipline",
      "safe observation methods",
      "configuration-drift analysis",
      "clear separation of reachability from operation",
      "price realism and schedule credibility",
      "data-rights and evidence-delivery terms",
      "subcontractor and supply-chain transparency"
    ],
    "dataRequirements": [
      "owner deployment confirmation",
      "deployed manifest",
      "authorized observation scope",
      "service identity and rollback owner",
      "incident and change records"
    ],
    "deliverables": [
      "deployed-manifest comparison",
      "live observation record",
      "drift and incident findings",
      "operational-state recommendation",
      "next review date"
    ],
    "dependencies": [
      "WP-K06-08",
      "WP-K06-09"
    ],
    "evidenceRights": [
      "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
      "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
      "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
      "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
    ],
    "exclusions": [
      "not performed without owner confirmation",
      "page availability is not protected-system operation"
    ],
    "id": "WP-K06-10",
    "inputs": [
      "deployment confirmation",
      "deployed manifest",
      "authorized observation scope",
      "rollback owner"
    ],
    "k07Id": "WP-K07-10",
    "name": "Post-deployment observation",
    "negativeResultClauses": [
      "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
      "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
      "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
      "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
    ],
    "objective": "After owner-confirmed deployment, observe actual configuration, reachability, headers, service identity, operating evidence, incidents, drift, and recovery readiness against the approved manifest.",
    "slug": "post-deployment-observation",
    "statementOfWork": {
      "contractorDeliverables": [
        "deployed-manifest comparison",
        "live observation record",
        "drift and incident findings",
        "operational-state recommendation",
        "next review date"
      ],
      "dependencies": [
        "WP-K06-08",
        "WP-K06-09"
      ],
      "exclusions": [
        "not performed without owner confirmation",
        "page availability is not protected-system operation"
      ],
      "governmentOrOwnerFurnishedInformation": [
        "owner deployment confirmation",
        "deployed manifest",
        "authorized observation scope",
        "service identity and rollback owner",
        "incident and change records"
      ],
      "performanceOutcomes": [
        "deployed-manifest comparison",
        "live configuration and service observation",
        "drift, incident and operating-state recommendation",
        "next-review trigger"
      ],
      "performanceStandards": [
        "Observation does not begin before deployment confirmation",
        "Deployed artifacts and configuration are compared to approved manifest",
        "Page availability is not treated as protected-system operation"
      ],
      "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
      "purpose": "After owner-confirmed deployment, observe actual configuration, reachability, headers, service identity, operating evidence, incidents, drift, and recovery readiness against the approved manifest.",
      "qualitySurveillance": [
        "authorization check",
        "hash and response replay",
        "evidence review"
      ]
    }
  }
]
