The Contractor shall deliver:
•
“As-is” Minimum Viable Architecture (MVA) for the NATO Intelligence Systems Architecture focusing on Applications and Technology.
•
“To-be” MVA for the NATO Intelligence Systems Architecture focusing on Applications and Technology.
•
Gap analysis with high level roadmap.
The “as-is” architecture will include a selected set of current NIE applications, and technologies.
The main deliverable is the “as-is” architecture report that shall cover the following areas:
Description: Brief overview of the goals and objectives, stakeholders, architecture views and scope.
KPIs: 100% coverage of goals, objectives, scope, stakeholders and required architecture views.
Acceptance Evidence: Approved scope checklist, traceability links, review record and editable source.
Accept When: Decision-focused summary is complete, consistent with the package and approved by the Purchaser PM and Lead Architect.
Current Architecture Overview
Description: High-level description of the current NIE architecture / NISA.
KPIs: KPI 1 — 100% of in-scope domains, boundaries, external actors, key dependencies and integration points represented against the baseline inventory. KPI 2 — 100% of overview views reviewed by designated domain SMEs; 0 unresolved Critical or Major modelling inaccuracies.
Acceptance Evidence: Context/dependency views, inventory reconciliation and SME validation log.
Accept When: Views describe the current state, agree with domain models and contain no unapproved future-state content.
Description: List of stakeholders and their roles and responsibilities.
KPIs: KPI 1 — 100% of identified stakeholder groups have role, responsibility, interest and required architecture input/output recorded. KPI 2 — 100% of key architecture activities have exactly one Accountable party and at least one Responsible party; 0 RACI gaps or duplicate accountability.
Acceptance Evidence: Stakeholder register, RACI and stakeholder review record.
Accept When: Named functions are current, responsibilities are unambiguous and the designated governance authority approves the RACI.
Description: Description of existing applications, their software components, interfaces, related standards, and dependencies between the applications.
KPIs: KPI 1 — 100% of in-scope applications, components, interfaces, standards and dependencies modelled; at least 95% of mandatory attributes complete. KPI 2 — 100% of critical interfaces record source, target, protocol, exchanged information and security/trust dependency; 0 orphan critical applications.
Acceptance Evidence: Application catalogue, interface matrix, diagrams, model export and reconciliation report.
Accept When: Catalogue and models are mutually consistent, traceable to inventory and approved by application/integration SMEs.
Description: Description of the infrastructure services, networks and connectivity, platform services, middleware as they are relevant for the deployment and hosting of the applications.
KPIs: KPI 1 — 100% of relevant infrastructure, network/connectivity, hosting, platform and middleware services documented and linked to deployed applications. KPI 2 — 100% of critical hosting/network paths validated; at least 95% of mandatory technical attributes complete; 0 unresolved Critical or Major inaccuracies.
Acceptance Evidence: Deployment, network and service views; configuration/source references; SME validation log.
Accept When: Models reflect the current technical state and reconcile application deployment with platforms, zones and connectivity.
Pain Points and Limitations
Description: Identified issues, bottlenecks, risks, and gaps in the current architecture.
KPIs: 100% of identified pain points are recorded with description, affected capability/system/process, severity, impact, owner, source, and proposed disposition.
Acceptance Evidence: Pain point register, gap analysis, risk/issues log, stakeholder interview records, incident/problem reports, operational feedback, architecture assessment findings, technical debt register, and traceability matrix.
Accept When: Pain points are complete, evidence-based, prioritised, traceable to the current architecture, and agreed by relevant SMEs and stakeholders; all Critical and Major items have an approved mitigation, target-state response, or formal risk acceptance.
Description: International and/or existing NATO standards; adherence status.
KPIs: KPI 1 — 100% of applicable compliance obligations and architecture standards identified, assigned to architecture areas, and traced to controls, requirements, or design decisions. KPI 2 — 100% of deviations, waivers, or non-compliances documented with justification, risk impact, owner, and approval status.
Acceptance Evidence: Compliance matrix, standards applicability assessment, waiver/deviation register, requirements traceability matrix, and review/approval records.
Accept When: Compliance position is clear, traceable, approved by the relevant authority, and all mandatory standards are either satisfied or formally waived.
Description: Diagrams, glossary, references, and supporting documents.
KPIs: KPI 1 — 100% of referenced diagrams, models, terms, acronyms, standards, and source documents included or linked. KPI 2 — 100% of architecture diagrams have title, version, owner, date, classification/handling marking where applicable, and source reference.
Acceptance Evidence: Diagram pack, glossary, acronym list, reference list, assumptions/constraints log, model exports, document control record, and repository links.
Accept When: Supporting material is complete, controlled, versioned, accessible to authorised stakeholders, and consistent with the main architecture document.
In addition, the Contractor is expected to deliver the architecture models that shall include all information about Application Architecture, Business Architecture, Technical Architecture, and Data/Information Architecture, based on the details defined in the metamodel to be further provided upon onboarding.
In order to deliver the architecture detailed above, the Contractor is expected to:
•
Conduct around 20 interviews with relevant stakeholders regarding NIE projects and programmes detailed by the CTO project team.
•
Support the architecture and roadmap development as prescribed in this Statement of Work.
•
Provide architecture expertise to support the report generation.
The “to-be” architecture shall be based upon existing and future NIE systems/applications. The “to-be” architecture shall:
•
Simplify, harmonize the “as-is” architecture: consolidate technology choices, identify common components and optimize their reuse.
•
Reduce Operation & Maintenance support.
•
Be data-centric, considering data as a first class concept and avoiding locking data into specific applications/systems, aligned with NATO’s Data Centric Reference Architecture.
•
Be a resilient architecture with open design for the future.
•
Optimize data flow, considering data transfer spanning different security domains, networks, and the internet/cloud.
•
Enable interoperability, including interoperability with the nations and in a federated environment.
•
Implement Zero Trust Policy: enforce identity checks, least privileged access, data integrity, provenance, and strict guard policies.
•
Comply with NATO STANAGs when available, and open standards otherwise, avoiding vendor lock-in.
•
Ensure applications are cloud-native to the extent possible, i.e. embrace a cloud-optimized design using cloud services and principles such as portability, resiliency, and scalability, and ensure readiness for migration to the cloud.
•
Maximize use of available platform, infrastructure and AI services.
The main deliverable is the “to-be” architecture and the generated report shall address the following areas:
Description: Overview of the future architecture vision and objectives.
KPIs: 100% coverage of goals, objectives, scope, stakeholders and required architecture views.
Acceptance Evidence: Approved scope checklist, traceability links, review record and editable source.
Accept When: Decision-focused summary is complete, consistent with the package and approved by the Purchaser PM and Lead Architect.
Future Architecture Overview
Description: High-level description of the future system architecture; identify new components, and components from the as-is architecture that can be reused or need to be modified.
KPIs: KPI 1 — 100% of in-scope domains, boundaries, external actors, key dependencies and integration points represented against the baseline inventory. KPI 2 — 100% of overview views reviewed by designated domain SMEs; 0 unresolved Critical or Major modelling inaccuracies.
Acceptance Evidence: Context/dependency views, inventory reconciliation and SME validation log.
Accept When: Views describe the current state, agree with domain models and contain no unapproved future-state content.
Target Stakeholders and Roles
Description: List of target stakeholders including future users, associated locations, and their expected roles.
KPIs: KPI 1 — 100% of identified stakeholder groups have role, responsibility, interest and required architecture input/output recorded. KPI 2 — 100% of key architecture activities have exactly one Accountable party and at least one Responsible party; 0 RACI gaps or duplicate accountability.
Acceptance Evidence: Stakeholder register, RACI and stakeholder review record.
Accept When: Named functions are current, responsibilities are unambiguous and the designated governance authority approves the RACI.
Description: High-level description of planned applications, their functions, interfaces, and dependencies.
KPIs: KPI 1 — 100% of in-scope applications, components, interfaces, standards and dependencies modelled; at least 95% of mandatory attributes complete. KPI 2 — 100% of critical interfaces record source, target, protocol, exchanged information and security/trust dependency; 0 orphan critical applications.
Acceptance Evidence: Application catalogue, interface matrix, diagrams, model export and reconciliation report.
Accept When: Catalogue and models are mutually consistent, traceable to inventory and approved by application/integration SMEs.
Description: Target application technology.
KPIs: KPI 1 — 100% of relevant infrastructure, network/connectivity, hosting, platform and middleware services documented and linked to deployed applications. KPI 2 — 100% of critical hosting/network paths validated; at least 95% of mandatory technical attributes complete; 0 unresolved Critical or Major inaccuracies.
Acceptance Evidence: Deployment, network and service views; configuration/source references; SME validation log.
Accept When: Models reflect the current technical state and reconcile application deployment with platforms, zones and connectivity.
Description: Planned security controls, risk mitigations, and compliance.
KPIs: KPI 1 — 100% of in-scope systems, applications, interfaces, data flows, and hosting zones mapped to applicable security controls and trust boundaries. KPI 2 — 100% of identified Critical and High risks have an approved mitigation, acceptance, transfer, or treatment plan; 0 unresolved Critical security gaps.
Acceptance Evidence: Security architecture views, risk register, control traceability matrix, threat model, data classification mapping, security requirements, and security SME review record.
Accept When: Security controls and risk treatments are complete, traceable to requirements and standards, and approved by the Security Authority or designated security governance body.
Description: Future integration methods, APIs, middleware, and interoperability.
KPIs: KPI 1 — 100% of internal and external integration points documented with source, target, protocol, data exchanged, frequency, ownership, security classification, and error-handling approach. KPI 2 — 100% of critical integrations mapped to approved integration patterns, standards, and interoperability requirements.
Acceptance Evidence: Interface control documents, API catalogue, integration matrix, sequence/data-flow diagrams, interoperability assessment, and SME validation log.
Accept When: Integration architecture is complete, technically feasible, aligned with approved standards, and approved by integration, application, and security SMEs.
Description: Future compliance requirements and alignment strategy.
KPIs: KPI 1 — 100% of applicable compliance obligations and architecture standards identified, assigned to architecture areas, and traced to controls, requirements, or design decisions. KPI 2 — 100% of deviations, waivers, or non-compliances documented with justification, risk impact, owner, and approval status.
Acceptance Evidence: Compliance matrix, standards applicability assessment, waiver/deviation register, requirements traceability matrix, and review/approval records.
Accept When: Compliance position is clear, traceable, approved by the relevant authority, and all mandatory standards are either satisfied or formally waived.
Description: Diagrams, glossary, references, and supporting documents.
KPIs: KPI 1 — 100% of referenced diagrams, models, terms, acronyms, standards, and source documents included or linked. KPI 2 — 100% of architecture diagrams have title, version, owner, date, classification/handling marking where applicable, and source reference.
Acceptance Evidence: Diagram pack, glossary, acronym list, reference list, assumptions/constraints log, model exports, document control record, and repository links.
Accept When: Supporting material is complete, controlled, versioned, accessible to authorised stakeholders, and consistent with the main architecture document.
3.4 Implementation Roadmap
The main deliverable is the implementation roadmap that aims at identifying the transition from the “as-is” architecture to the “to-be” architecture. The implementation roadmap shall enable the ability to deliver faster, identifying quick wins as well as long-term strategies. The implementation roadmap shall address the following areas:
Description: Compare as-is and to-be to highlight what needs to change.
KPIs: KPI 1 — 100% of in-scope as-is and to-be architecture elements are compared and assigned a gap status: unchanged, reused, modified, replaced, retired, or new. KPI 2 — 100% of identified gaps have documented impact, priority, owner, target resolution approach, and traceability to requirements, pain points, risks, or target architecture objectives.
Acceptance Evidence: Gap register, as-is/to-be comparison matrix, capability heat-map, application/technology disposition matrix, traceability matrix, and SME review record.
Accept When: Gaps are complete, prioritised, evidence-based, traceable to both baseline and target architecture, and agreed by relevant SMEs and governance authority.
Description: Group related changes into programmes/projects.
KPIs: KPI 1 — 100% of approved gaps and target-state changes are mapped to at least one initiative, project, work package, or explicit no-action decision. KPI 2 — 100% of initiatives include objective, scope, expected outcome, owner, impacted domains, estimated effort, indicative cost, benefits, dependencies, risks, and target phase.
Acceptance Evidence: Initiative register, programme/project mapping, work package descriptions, benefits map, gap-to-initiative traceability matrix, and governance review record.
Accept When: Initiatives are complete, non-overlapping, traceable to architecture gaps and objectives, and approved by the portfolio/programme governance authority.
Description: Identify dependencies on external projects.
KPIs: KPI 1 — 100% of initiatives and roadmap phases have dependencies identified, classified, and assigned an owner. KPI 2 — 100% of Critical and Major dependencies include impact, required date, delivery owner, mitigation or contingency, and monitoring status.
Acceptance Evidence: Dependency register, integrated master schedule, project interface agreements, external project mapping, RAID log, supplier/third-party inputs, and governance records.
Accept When: Dependencies are complete, validated with dependency owners, reflected in the roadmap schedule, and actively managed through an agreed governance mechanism.
Description: Prioritize based on value, feasibility, and dependencies. Define clear phases or waves for implementation, identifying quick wins (low effort, high impact), foundational work (e.g., data governance, cloud infrastructure) and major transformations (new core system, process re-engineering). Provide milestones and timeline.
KPIs: KPI 1 — 100% of initiatives are assigned to a roadmap phase/wave with sequencing rationale, priority, dependency alignment, and expected outcome. KPI 2 — Each phase identifies quick wins, foundational activities, major transformation activities where applicable, entry/exit criteria, and measurable benefits.
Acceptance Evidence: Phased roadmap, prioritisation matrix, value/feasibility assessment, dependency mapping, benefit realisation plan, sequencing rationale, and governance review record.
Accept When: Roadmap phases are realistic, prioritised, dependency-aware, benefit-led, and approved by architecture and delivery governance stakeholders.
Description: Gantt chart or timeline view of key activities; milestones for each work stream or phase.
KPIs: KPI 1 — 100% of roadmap phases and initiatives have start/end windows, key milestones, decision gates, dependencies, and accountable owners recorded. KPI 2 — 100% of milestones have measurable completion criteria, planned date, owner, dependency linkage, and status.
Acceptance Evidence: Gantt chart, integrated roadmap timeline, milestone register, workstream plan, dependency schedule, baseline schedule, and approval record.
Accept When: Timeline is complete, internally consistent, dependency-aware, agreed by delivery owners, and baselined under the relevant programme or portfolio governance process.
Description: Identify top risks and mitigation plans.
KPIs: KPI 1 — 100% of roadmap initiatives and phases are assessed for key implementation, technical, security, operational, schedule, cost, and organisational risks. KPI 2 — 100% of High and Critical risks have owner, likelihood, impact, mitigation, contingency, due date, residual risk rating, and escalation path.
Acceptance Evidence: Risk register, RAID log, mitigation plans, security/accreditation risk inputs, dependency risk assessment, issue logs, and risk review records.
Accept When: Risks are complete, prioritised, actively owned, linked to roadmap items, and all High/Critical risks have approved mitigations, contingency plans, or formal acceptance.
Description: Diagrams, glossary, references, and supporting documents.
KPIs: KPI 1 — 100% of referenced diagrams, registers, matrices, models, schedules, terms, acronyms, standards, and source documents are included or linked. KPI 2 — 100% of supporting artefacts have title, version, owner, date, classification/handling marking where applicable, and source reference.
Acceptance Evidence: Diagram pack, glossary, acronym list, reference list, assumptions and constraints log, model exports, roadmap source files, document control record, and repository links.
Accept When: Supporting material is complete, controlled, versioned, accessible to authorised stakeholders, and consistent with the roadmap document.