Resource Pursuit review

Controlled-package access checklist

Prepare the requester, certification, delivery route and receiving environment before asking for a controlled technical package.

Reviewed · Deep Fathom

Wide tables scroll sideways to show all columns.

Use this checklist before requesting controlled drawings or another restricted technical package. For each item, record confirmed, open, not applicable with reason, or not reviewed. A completed worksheet documents your team’s review. It does not grant access.

The checklist

CheckEvidence to recordOwner to identify
Correct packageNotice action, solicitation identifier, attachment and versionPursuit owner
Access instructionExact paragraph and delivery/request routeContracts or capture
Authorized requesterPerson or role the package permits to requestCustodian or named requester
CertificationApplicable JCP or other approval, scope, location and dateCertification owner
Additional conditionAssessment, DEV, NDA or other condition expressly statedResponsible subject expert
Conditional wordingTrigger and whether it is established for this packageContracts or buyer contact
Receiving environmentApproved destination and applicable handling restrictionsSecurity owner
People and disclosureAuthorized users and permitted sharingData owner
Request recordDate, route, response and remaining questionRequester
After-use instructionReturn, retention or destruction condition where statedData owner

The worked access case shows six retained source conditions, the fictional team’s evidence, a limited decision, open questions and an accepted handoff. Use the pursuit review workbook to record your own review. Keep controlled data and personal account credentials out of the workbook.

Select only the conditions that apply

The retained Hellfire RFQ names DD Form 2345 and a Level 2 (Self) check before drawing release. The lifting-cap access paragraph names JCP and secure handling without naming a CMMC status. Warren’s restricted-SAM instructions include a custodian-only request and conditional export-control/DEV language.

Those differences are the reason this worksheet has a source column. Copying the most demanding case into every row can create unnecessary work and still miss the actual buyer’s instructions. Compare the dated cases.

Work an unresolved condition

For the Warren example, record the source as SPRDL1-26-R-0121, pages 11–12, posted August 21, 2026. The custodian-only request is identified. Whether the TDP carries the export-control warning is not established by the retained solicitation. The DEV row therefore remains open, with a question for the contracting office.

Do not mark the whole package inaccessible forever. Do not mark DEV confirmed merely because the paragraph contains the term. A useful checklist preserves the exact uncertainty and the person responsible for resolving it.

Review before and after release

Before requesting, confirm the receiving environment and requester. After release, verify that the files received are the expected package and that the people using them have the appropriate authorization. Access approval and authorization for later disclosure are separate questions.

The receiving controlled technical data guide covers the security handoff. The general bid checklist adds engineering, commercial and submission conditions that this access worksheet does not cover.

If assessment evidence is the remaining work, review the relevant compliance workflow with our team.

Sources Reviewed

Read the governing material.

The checklist is an educational review method, not an agency application form. Sources were reviewed September 7, 2026.