{
  "acceptanceEvidence": [
    "cross-discipline participation",
    "traceable pathways",
    "independent challenge",
    "owner disposition for every HCE"
  ],
  "acceptanceMatrix": [
    {
      "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
      "assessmentMethod": "cross-discipline review",
      "criterion": "HCE traceability",
      "requiredResult": "Every HCE maps to functions, pathways, controls and owners"
    },
    {
      "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
      "assessmentMethod": "independent challenge",
      "criterion": "Consequence coverage",
      "requiredResult": "Physical, cyber, power, cooling and restoration consequences are represented"
    },
    {
      "acceptanceState": "PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale",
      "assessmentMethod": "artifact inspection",
      "criterion": "No topology publication",
      "requiredResult": "Sensitive facility details remain access-controlled"
    }
  ],
  "bidEvaluationCriteria": [
    "CIE/CCE facilitation experience",
    "cross-discipline engineering capability",
    "high-consequence evidence handling",
    "safe abstraction method",
    "price realism and schedule credibility",
    "data-rights and evidence-delivery terms",
    "subcontractor and supply-chain transparency"
  ],
  "canonicalUrl": "https://xn--mwe.com/procurement/work-packages/cce-workshop/",
  "dataRequirements": [
    "hazard analyses",
    "process and protection diagrams",
    "operating envelopes",
    "maintenance pathways",
    "external service dependencies"
  ],
  "deliverables": [
    "HCE register",
    "critical-function model",
    "consequence pathways",
    "mitigation candidates",
    "unverified-trust register"
  ],
  "dependencies": [
    "WP-K06-01"
  ],
  "evidenceRights": [
    "The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.",
    "Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.",
    "Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.",
    "No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law."
  ],
  "exclusions": [
    "no production exploitation",
    "no publication of real facility topology"
  ],
  "id": "WP-K06-02",
  "inputs": [
    "mission analysis",
    "process diagrams",
    "hazard analysis",
    "asset and dependency inventory"
  ],
  "k07Id": "WP-K07-02",
  "name": "Consequence-driven Cyber-informed Engineering workshop",
  "negativeResultClauses": [
    "A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.",
    "Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.",
    "Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.",
    "The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending."
  ],
  "objective": "Identify high-consequence events, critical functions, system-of-systems pathways, digital dependencies, and engineered-out attack paths.",
  "releaseId": "K12-2026-08-16",
  "slug": "cce-workshop",
  "statementOfWork": {
    "contractorDeliverables": [
      "HCE register",
      "critical-function model",
      "consequence pathways",
      "mitigation candidates",
      "unverified-trust register"
    ],
    "dependencies": [
      "WP-K06-01"
    ],
    "exclusions": [
      "no production exploitation",
      "no publication of real facility topology"
    ],
    "governmentOrOwnerFurnishedInformation": [
      "hazard analyses",
      "process and protection diagrams",
      "operating envelopes",
      "maintenance pathways",
      "external service dependencies"
    ],
    "performanceOutcomes": [
      "high-consequence event register",
      "critical-function model",
      "system-of-systems dependency map",
      "engineered-out consequence-path recommendations"
    ],
    "performanceStandards": [
      "Every HCE maps to functions, pathways, controls and owners",
      "Physical, cyber, power, cooling and restoration consequences are represented",
      "Sensitive facility details remain access-controlled"
    ],
    "periodOfPerformance": "To be defined by the acquiring authority; no duration is inferred by the public pattern.",
    "purpose": "Identify high-consequence events, critical functions, system-of-systems pathways, digital dependencies, and engineered-out attack paths.",
    "qualitySurveillance": [
      "cross-discipline review",
      "independent challenge",
      "artifact inspection"
    ]
  }
}
