02.02.01 Attachment 01 Solicitation 70FBR426Q00000038 08.26.26.pdf

PDF 22 MB Posted

Attached to
70FBR426Q00000038 Armed Level II Security Guard DR-4930 Federal contract opportunity
Solicitation number
70FBR426Q00000038
Issued by
Federal Emergency Management Agency

About this file

This is a Solicitation/Contract/Order for Commercial Products and Commercial Services issued by the Federal Emergency Management Agency (FEMA), Region 04, for Level II Armed Protective Security Officers in support of Presidentially declared Disaster 4930-MS.

The solicitation is designated as a local area small business set-aside per FAR 26.202-3(a) for Mississippi counties of Covington, George, Greene, Hancock, Harrison, Pearl River, Stone, and Wayne. The contract will be a Firm-Fixed-Unit-Price (FFUP) arrangement. The primary requirement is 8,180 labor hours for Level II Armed Guard Services per the Performance Work Statement, with branch office operations in Hattiesburg, MS 39401. Requirements include 3-5 guards providing 24-hour armed security service and 1 guard per Disaster Recovery Center site, with operations Monday-Friday 7:30 AM to 6:30 PM and Saturday 7:30 AM to 2:30 PM. One option (Item 1001) for 5,520 labor hours extends performance from December 17, 2026 to March 16, 2027. The requisition number is 1600 ES with a contract value of $29,000,000. The contact for solicitation information is Leah Rogers (561-612). Evaluation factors include Technical and Management Approach (Factor 1), Past Performance (Factor 2), and Price (Factor 3). The solicitation incorporates multiple federal clauses addressing contractor employee access, safeguarding of controlled unclassified information, privacy requirements, background investigations, facility access, and service contract labor standards with applicable wage determinations for Mississippi counties. Contractors must comply with DHS security requirements, IT security awareness training, OPSEC training, insider threat training, and background investigation protocols based on risk designation levels.

View the file

Other files for this federal contract opportunity

Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

WOMEN-OWNED SMALL

BUSINESS (WOSB)

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

1. REQUISITION NUMBER PAGE 1 OF

2. CONTRACT NUMBER 3.AWARD/EFFECTIVE

DATE

4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE

DATE

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME b. TELEPHONE NUMBER (No collect calls)

8. OFFER DUE DATE/

LOCAL TIME

9. ISSUED BY

13b. RATING

14. METHOD OF SOLICITATION

CODE

15. DELIVER TO 16. ADMINISTERED BY CODE

18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/

OFFEROR

CODE

FACILITY

CODE

CODE

TELEPHONE NUMBER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

REQUEST

FOR QUOTE

(RFQ)

INVITATION

FOR BID

(IFB)

REQUEST

FOR

PROPOSAL

(RFP)

SEE ADDENDUM

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN 29. AWARD OF CONTRACT: REFERENCE

. YOUR OFFER ON SOLICITATION

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA - FAR (48 CFR) 53.212

10. THIS ACQUISITION IS UNRESTRICTED OR

NORTH AMERICAN

INDUSTRY CLASSIFICATION

STANDARD (NAICS):

SIZE STANDARD:

13a. THIS CONTRACT IS A

RATED ORDER UNDER

THE DEFENSE PRIORITIES

AND ALLOCATIONS

SYSTEM - DPAS (15 CFR 700)

SET ASIDE: % FOR:

11. DELIVERY FOR FREE ON

BOARD (FOB) DESTINATION

UNLESS BLOCK IS MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

ARE ARE NOT ATTACHED

ARE ARE NOT ATTACHED

27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4.

FAR 52.212-3 AND 52.212-5 ARE ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED.

8(A)

ECONOMICALLY

DISADVANTAGED

WOMEN-OWNED SMALL

BUSINESS (EDWOSB)

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

(SDVOSB)

HUBZONE SMALL

BUSINESS

SMALL BUSINESS

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30.

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH

AND DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND

ON ANY ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS

SPECIFIED

DATED.

OFFER

ADDENDA

ADDENDA

70FBR426Q00000038

VARIOUS LOCATIONS

FEMA REGION 04

FEDERAL EMERGENCY MANAGEMENT AGENCY

ADMINISTRATIVE SERVICESCONTRACTING

3005 CHAMBLEE TUCKER ROAD

ATLANTA GA 30341

1600 ES Leah Rogers

70FBR4

561612

$29

000000

The purpose of this solicitation is to request a quote for Level II Armed Protective Security

Officers (PSOs) in support of Presidentially declared Disaster 4930-MS. Requirement details are listed in the Performance Work Statement.

Continued...

STOCK RECORD (S/R)

STANDARD FORM 1449 (REV. 11/2021) BACK

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE RECEIVED (MM/DD/YYYY) 42d. TOTAL CONTAINERS

40. PAID BY

32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32g. EMAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED

CORRECT FOR

PARTIAL FINAL

37. CHECK NUMBER

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER

36. PAYMENT

COMPLETE PARTIAL FINAL

ACCEPTED,

This acquisition will be a local area small business set-aside per FAR 26.202-3(a) for the

Mississippi counties of Covington, George, Greene, Hancock, Harrison, Pear River, Stone, and Wayne.

This solicitation will result in a

Firm-Fixed-Unit-Price contract. A firm-fixed-unit-price (FFUP) contract establishes a fixed-price(s) for supplies or services but does not establish the quantity, except for a guaranteed minimum and a ceiling.

Volume discounts and equitable adjustments to the unit price based on actual usage do not render the contract other than a firm-fixed-unit-price contract.

* To ensure timely and equitable evaluation of an offer, contractors are encouraged to read the entire solicitation and attachments to provide all requested information and documentation as failure to submit any of the requested information will be considered incomplete and ineligible for review. Offerors must clearly label and identify each required section response.

0001 8180 LHLevel II Armed Guard Services per Performance

Work Statement

Continued...

CONTINUATION SHEET

REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGES

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C)

NSN 7540-01-152-8067

70FBR426Q00000038

Minimum Labor Hours 0

Maximum Labor Hours 8180

Branch Office:

Hattiesburg, MS 39401

Required Guards: 3-5 guards

24-hour armed security service

Disaster Recovery Center (DRC) Counties:

Covington, Wayne, Greene, George, Stone, Harrison, Pearl River, and Hancock.

Required Guards: 1 guard will be required at each DRC Site. Requirements may change

Monday-Friday: 7:30 AM - 6:30 PM

Saturday: 7:30 - 2:30 PM

Product/Service Code: R430

Product/Service Description: SUPPORT-

PROFESSIONAL: PHYSICAL SECURITY AND BADGING

Period of Performance: 09/17/2026 to

12/16/2026

1001 5520 LHOption One - Level II Armed Guard Services per

Statement of Work

Minimum Labor Hours 0

Maximum Labor Hours 5520

Branch Office:

Hattiesburg, MS 39401

Required Guards: 3-5 guards

24-hour armed security service

Product/Service Code: R430

Product/Service Description: SUPPORT-

PROFESSIONAL: PHYSICAL SECURITY AND BADGING

Period of Performance: 12/17/2026 to

03/16/2027

A - Solicitation/Contract Form B - Supplies or Services/Prices C - Description/Specifications D - Packaging and Marking E - Inspection and Acceptance F - Deliveries or Performance G - Contract Administration Data H - Special Contract Requirements I - Contract Clauses J - List of Documents, Exhibits and Other Attachments K - Representations, Certifications, and Other Statements of Bidders L - Instructions, Conditions, and Notices to Bidders M - Evaluation Factors for Award

A - Solicitation/Contract Form

B - Supplies or Services/Prices

C - Description/Specifications

I - Contract Clauses

52.224-2 Privacy Act. (APR 1984)

52.224-3 Privacy Training. (JAN 2017)

3052.212-70 Contract terms and conditions applicable to DHS acquisition of commercial items.

(JUL 2023)

The Contractor agrees to comply with any provision or clause that is incorporated herein by reference to implement agency policy applicable to acquisition of commercial items or components. The provision or clause in effect based on the applicable regulation cited on the date the solicitation is issued applies unless otherwise stated herein. The following provisions and clauses are incorporated by reference: (The Contracting Officer should either check the provisions and clauses that apply or delete the provisions and clauses that do not apply from the list. The Contracting Officer may add the date of the provision or clause if desired for clarity.)

(a) Provisions.

[ ] 3052.216-70 Evaluation of Offers Subject to An Economic Price Adjustment Clause.

[ ] 3052.219-72 Evaluation of Prime Contractor Participation in the DHS Mentor Protégé Program.

[ ] 3052.247-70 F.o.B. Origin Information.

[ ] Alternate I

[ ] Alternate II

[ ] 3052.247-71 F.o.B. Origin Only.

[ ] 3052.247-72 F.o.B. Destination Only.

(b) Clauses.

[ ] 3052.203-70 Instructions for Contractor Disclosure of Violations.

[X] 3052.204-71 Contractor Employee Access.

[X] Alternate I

[X] Alternate II

[X] 3052.204-72 Safeguarding of Controlled Unclassified Information.

[X] Alternate I

[ ] 3052.204-73 Notification and Credit Monitoring Requirements for Personally Identifiable Information Incidents.

[ ] 3052.205-70 Advertisement, Publicizing Awards, and Releases.

[ ] Alternate I

[ ] 3052.209-72 Organizational Conflicts of Interest.

[ ] 3052.209-73 Limitation on Future Contracting.

[ ] 3052.215-70 Key Personnel or Facilities.

[ ] 3052.216-71 Determination of Award Fee.

[ ] 3052.216-72 Performance Evaluation Plan.

[ ] 3052.216-73 Distribution of Award Fee.

[ ] 3052.217-91 Performance. (USCG)

[ ] 3052.217-92 Inspection and Manner of Doing Work. (USCG)

[ ] 3052.217-93 Subcontracts. (USCG)

[ ] 3052.217-94 Lay Days. (USCG)

[ ] 3052.217-95 Liability and Insurance. (USCG)

[ ] 3052.217-96 Title. (USCG)

[ ] 3052.217-97 Discharge of Liens. (USCG)

[ ] 3052.217-98 Delays. (USCG)

[ ] 3052.217-99 Department of Labor Safety and Health Regulations for Ship Repair.

(USCG)

[ ] 3052.217-100 Guarantee. (USCG)

[ ] 3052.219-71 DHS Mentor Protégé Program.

[ ] 3052.228-70 Insurance.

[ ] 3052.228-90 Notification of Miller Act Payment Bond Protection. (USCG)

[ ] 3052.228-91 Loss of or Damage to Leased Aircraft. (USCG)

[ ] 3052.228-92 Fair Market Value of Aircraft. (USCG)

[ ] 3052.228-93 Risk and Indemnities. (USCG)

[ ] 3052.236-70 Special Provisions for Work at Operating Airports.

[ ] 3052.242-72 Contracting Officer's Representative.

[ ]HSAR 3052.249-90 Contract Termination (USCG).

(End of clause)

NARA RECORDS MANAGEMENT LANGUAGE FOR CONTRACTS

The following standard items relate to records generated in executing the contract and should be included in a typical Electronic Information Systems (EIS) procurement contract:

1. Citations to pertinent laws, codes and regulations such as 44 U.S.C chapters 21, 29, 31 and 33; Freedom of Information Act (5 U.S.C. 552); Privacy Act (5 U.S.C. 552a); 36 CFR Part 1222 and Part 1228.

2. Contractor shall treat all deliverables under the contract as the property of the U.S. Government for which the Government Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest.

3. Contractor shall not create or maintain any records that are not specifically tied to or authorized by the contract using Government IT equipment and/or Government records.

4. Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected by the Freedom of Information Act.

5. Contractor shall not create or maintain any records containing any Government Agency records that are not specifically tied to or authorized by the contract.

6. The Government Agency owns the rights to all data/records produced as part of this contract.

7. The Government Agency owns the rights to all electronic information (electronic data, electronic information systems, electronic databases, etc.) and all supporting documentation created as part of this contract. Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

8. Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format (paper, electronic, etc.) or mode of transmission (e-mail, fax, etc.) or state of completion (draft, final, etc.).

9. No disposition of documents will be allowed without the prior written consent of the Contracting Officer. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the agency records schedules.

10. Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, this contract. The Contractor (and any sub-contractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

52.202-1 Definitions. (JUN 2020)

52.203-5 Covenant Against Contingent Fees. (MAY 2014)

52.203-7 Anti-Kickback Procedures. (JUN 2020)

52.203-13 Contractor Code of Business Ethics and Conduct. (NOV 2021)

52.203-17 Contractor Employee Whistleblower Rights. (NOV 2023)

52.204-9 Personal Identity Verification of Contractor Personnel. (JAN 2011)

52.204-13 System for Award Management-Maintenance. (OCT 2018) (Deviation AUG 2025)

52.204-19 Incorporation by Reference of Representations and Certifications. (DEC 2014)

52.212-4 Terms and Conditions-Commercial Products and Commercial Services. (NOV 2023) (Deviation AUG 2025)

52.217-6 Option for Increased Quantity. (MAR 1989)

The Government may increase the quantity of supplies called for in the Schedule at the unit price specified.

The Contracting Officer may exercise the option by written notice to the Contractor within 2 days. Delivery of the added items shall continue at the same rate as the like items called for under the contract, unless the parties otherwise agree.

(End of clause)

52.217-8 Option To Extend Services. (NOV 1999)

The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 7 days .

(End of clause)

52.217-9 Option To Extend the Term of the Contract. (MAR 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 7 days ; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 7 days before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 12 months.

(End of clause)

52.219-6 Notice of Total Small Business Set-Aside. (NOV 2020) (Deviation OCT 2025)

52.222-3 Convict Labor. (JUN 2003) (Deviation Effective Date)

52.222-15 Certification of Eligibility. (MAY 2014)

52.222-36 Equal Opportunity for Workers with Disabilities. (JUN 2020) (Deviation OCT 2025)

(a) Equal opportunity clause. The Contractor must abide by the requirements of the equal opportunity clause at 41 CFR 60-741.5(a), as of March 24, 2014. This clause prohibits discrimination against qualified individuals on the basis of disability, and requires affirmative action by the Contractor to employ and advance in employment qualified individuals with disabilities.

(b) Subcontracts. The Contractor must include the terms of this clause in every subcontract or purchase order in excess of the threshold specified in Federal Acquisition Regulation (FAR) 22.1401-2(a)(1) on the date of subcontract award, unless exempted by rules, regulations, or orders of the Secretary, so that such provisions will be binding upon each subcontractor or vendor. The Contractor must act as specified by the Director, Office of Federal Contract Compliance Programs of the U.S. Department of Labor, to enforce the terms, including action for noncompliance. Such necessary changes in language may be made as shall be appropriate to identify properly the parties and their undertakings.

(End of clause)

52.222-40 Notification of Employee Rights Under the National Labor Relations Act. (DEC 2010) (Deviation Effective Date)

52.222-41 Service Contract Labor Standards. (AUG 2018) (Deviation Effective Date)

52.222-44 Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment.

(MAY 2014) (Deviation Effective Date)

52.222-50 Combating Trafficking in Persons. (OCT 2025) (Deviation Effective Date)

52.226-3 Disaster or Emergency Area Representation. (NOV 2007)

(a) Set-aside area. The area covered in this contract is: Mississippi Declared counties of Covington, Wayne, Greene, George, Stone, Harrison, Pearl River, and Hancock

(b) Representations. The offeror represents that it ___ does ___ does not reside or primarily do business in the set-aside area.

(c) An offeror is considered to be residing or primarily doing business in the set-aside area if, during the last twelve months-

(1) The offeror had its main operating office in the area; and

(2) That office generated at least half of the offeror's gross revenues and employed at least half of the offeror's permanent employees.

(d) If the offeror does not meet the criteria in paragraph (c) of this provision, factors to be considered in determining whether an offeror resides or primarily does business in the set-aside area include-

(1) Physical location(s) of the offeror's permanent office(s) and date any office in the set-aside area(s) was established;

(2) Current state licenses;

(3) Record of past work in the set-aside area(s) (e.g., how much and for how long);

(4) Contractual history the offeror has had with subcontractors and/or suppliers in the set-aside area;

(5) Percentage of the offeror's gross revenues attributable to work performed in the set-aside area;

(6) Number of permanent employees the offeror employs in the set-aside area;

(7) Membership in local and state organizations in the set-aside area; and

(8) Other evidence that establishes the offeror resides or primarily does business in the set-aside area. For example, sole proprietorships may submit utility bills and bank statements.

(e) If the offeror represents it resides or primarily does business in the set-aside area, the offeror shall furnish documentation to support its representation if requested by the Contracting Officer.

The solicitation may require the offeror to submit with its offer documentation to support the representation.

(End of provision)

52.226-4 Notice of Disaster or Emergency Area Set-Aside. (NOV 2007)

(a) Set-aside area. Offers are solicited only from businesses residing or primarily doing business in The Mississippi Declared counties of Covington, Wayne, Greene, George, Stone, Pearl River, Harrison, and Hancock Offers received from other businesses shall not be considered.

(b) This set-aside is in addition to any small business set-aside contained in this contract.

(End of clause)

52.226-5 Restrictions on Subcontracting Outside Disaster or Emergency Area. (NOV 2007)

52.226-7 Drug-Free Workplace. (MAY 2024)

52.226-8 Encouraging Contractor Policies To Ban Text Messaging While Driving. (MAY 2024)

52.227-14 Rights in Data-General. (MAY 2014)

52.232-23 Assignment of Claims. (MAY 2014)

52.232-39 Unenforceability of Unauthorized Obligations. (JUN 2013)

52.232-40 Providing Accelerated Payments to Small Business Subcontractors. (MAR 2023)

52.233-3 Protest after Award. (AUG 1996) (Deviation AUG 2025)

52.233-4 Applicable Law for Breach of Contract Claim. (OCT 2004) (Deviation AUG 2025)

J - List of Documents, Exhibits and Other Attachments

Attachment Number Title Date

Wage Determinations

K - Representations, Certifications, and Other Statements of Bidders

L - Instructions, Conditions, and Notices to Bidders

52.212-1 Instructions to Offerors-Commercial Products and Commercial Services. (SEP 2023) (Deviation AUG 2025)

M - Evaluation Factors for Award

52.212-2 Evaluation-Commercial Products and Commercial Services. (NOV 2021) (Deviation AUG 2025)

(a) Evaluation factors. The Government will award a contract resulting from this solicitation to the responsible Offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors will be used to evaluate offers:

Factor 1: Technical and Management Approach Factor 2: Past Performance Factor 3: Price

(b) Options (if applicable). The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. The evaluation of options does not obligate the Government to exercise the option(s).

(c) Notice of award. A written notice of award or acceptance of an offer furnished to the successful Offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer's specified expiration time, the Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.

(End of provision)

14. 508 INFORMATION TECHNOLOGY CLAUSE

Test for Accessibility | Section508.gov https://www.dhs.gov/compliance-test-processes

DHS 508 Tool: https://www.dhs.gov/xlibrary/oast/DART/

Note: The 508 IT clause is generated from the DHS 508 Tool on an ad hoc basis.

The 508 IT clause generated from the DHS 508 Tool is inserted into the PWS or SOO or PWS.

Accessibility Requirements (Section 508)

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-

220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology (EIT), they must ensure that it is accessible to people with disabilities.

Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.

All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable EIT accessibility standards have been identified:

Section 508 Applicable EIT Accessibility Standards

36 CFR 1194.21 Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to GOTS and

COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.

36 CFR 1194.22 Web-based Intranet and Internet Information and Applications, applies to all Web based deliverables, including documentation and reports procured or developed under this work statement. When any

Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous

JavaScript and XML (AJAX) then 1194.21 Software standards also apply to fulfill functional performance criteria.

36 CFR 1194.23 Telecommunications Products, applies to all telecommunications products including end-user interfaces such as telephones and non-end-user interfaces such as switches, circuits, etc. that are procured, developed or used by the Federal Government.

36 CFR 1194.26 Desktop and Portable Computers, applies to all desktop and portable computers, including but not limited to laptops and personal data assistants (PDA) that are procured or developed under this work statement.

https://www.section508.gov/test/ http://www.dhs.gov/xlibrary/oast/DART/

36 CFR 1194.31 Functional Performance Criteria, applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.

36 CFR 1194.41 Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required 1194.31 Functional

Performance Criteria, they shall comply with the technical standard associated with Web based Intranet and

Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.

Section 508 Applicable Exceptions

Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COTR and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply: 36

CFR 1194.3(b) Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.

Section 508 Compliance Requirements

36 CFR 1194.2(b) (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meet some but not all of the standards, the agency must procure the product that best meets the standards. When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires authorization from the DHS Office of Accessible

Systems and Technology (OAST) in accordance with DHS MD 4010.2.

All tasks for testing of functional and/or technical requirements must include specific testing for Section 508 compliance and must use DHS Office of Accessible Systems and Technology approved testing methods and tools. For information about approved testing methods and tools send an email to accessibility@dhs.gov.

15. DHS ENTERPRISE ARCHITECTURE COMPLIANCE

All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the Contractor shall comply with the following Homeland Security

Enterprise Architecture (HLS EA) requirements:

(a) All developed solutions and requirements shall be compliant with the HLS/FEMA EA.

(b) All IT hardware and/or software shall be compliant with the HLS/FEMA EA Technical Reference Model

(TRM) Standards and Products Profile.

(c) Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.

mailto:accessibility@dhs.gov

(d) Development of data assets, information exchanges and data standards will comply with the DHS Data

Management Policy MD 103-01[1] and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

(e) Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS

Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be

IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile (National Institute of

Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

INFORMATION SHARING

To accomplish the tasks outlined in this contract, FEMA will provide the contractor with access to limited PII consistent with security procedures in the Electronic Security System (ESS), including Personal Identity Verification

(PIV) card information and facility visitor names. The contractor will not have direct access to ESS.

The information sharing outlined in this contract is authorized by the following System of Records Notice(s) and

Routine Use(s):

• DHS/ALL-023 Department of Homeland Security Personnel Security Management, October 13, 2020, 85 FR

64511, Routine Use H.

• DHS/ALL-024 Department of Homeland Security Facility and Perimeter Access Control and Visitor

Management, February 3, 2010, 75 FR 5609, Routine Use F.

• DHS/ALL-025 Law Enforcement Authority in Support of the Protection of Property Owned, Occupied, or

Secured by the Department of Homeland Security System of Records, June 14, 2017, 82 FR 27274, Routine

Use F.

• DHS/ALL-026 Department of Homeland Security Personal Identity Verification Management System, June

25, 2009, 74 FR 30301, Routine Use F.

The information sharing outlined in this contract is authorized by the following Privacy Impact Assessments:

• DHS/FEMA/PIA-051 FEMA Physical Access Control Systems (PACS)

Need to Know

The contractor will limit access to the PII provided by FEMA under this contract only to the contractor’s authorized personnel who need to know the information to accomplish the tasks outlined in this contract.

Prohibition on Computer Matching

The contractor shall ensure no computer matching, as that term is defined in 5 U.S.C. § 552a(o), will occur for the purpose of establishing or verifying eligibility or compliance as it relates to cash or in-kind assistance or payments under federal benefit programs.

Return or Destruction of Data when no longer needed

If at any time during the term of this contract any part of FEMA PII, in any form, that the contractor obtains from

FEMA ceases to be required by the contractor for the performance of the contract, or upon termination of the contract, whichever occurs first, the contractor shall, within fourteen (14) days thereafter, promptly notify FEMA and securely return PII to FEMA, or, at FEMA’s written request destroy, un-install and/or remove all copies of such PII in the contractor’s possession or control, and certify in writing to FEMA that such tasks have been completed.

Clauses

1) HSAR 3052.204-72 Safeguarding of Controlled Unclassified Information (July 2023)

2) Special Clause Information Technology Security Awareness Training

3) HSAR 3052.204-71 Contractor Employee Access

4) HSAR 3052.204-73 HSAR 3052.204-73 Notification and Credit Monitoring Requirements for Personally

Identifiable Information Incidents

5) 52.204-9 Personal Identity Verification Of Contractor Personnel (JAN 2011)

6) 52.224-1 Privacy Act Notification (APR 1984)

7) FAR 52.224-3 Privacy Training – Alternate I (see FAR Class Deviation 17-03, Revision 1)

HSAR 3052.240-72 SAFEGUARDING OF CONTROLLED UNCLASSIFIED INFORMATION

(HSAR DEVIATION 25-12) (Effective November 3, 2025)

(a) Definitions. As used in this clause— http://www.federalregister.gov/documents/2020/10/13/2020-22536/privacy-act-of-1974-system-of-records http://www.gpo.gov/fdsys/pkg/FR-2010-02-03/html/2010-2206.htm http://www.gpo.gov/fdsys/pkg/FR-2010-02-03/html/2010-2206.htm https://www.federalregister.gov/documents/2017/06/14/2017-12262/privacy-act-of-1974-system-of-records https://www.federalregister.gov/documents/2017/06/14/2017-12262/privacy-act-of-1974-system-of-records

Adequate Security means security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls.

Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or

Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:

(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical Facility

Anti-Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual “Safeguarding

Information Designated as Chemical-Terrorism Vulnerability Information” dated September 2008);

(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information

Act of 2002 (title XXII, subtitle B of the Homeland Security Act of 2002 as amended through Pub. L.

116–283), PCII’s implementing regulations (6 CFR part 29), the PCII Program Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of

Homeland Security, the PCII Program Manager, or a PCII Program Manager Designee;

(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive Security

Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation

Security Administration or designee), including Department of Homeland Security MD 11056.1, “Sensitive

Security Information (SSI)” and, within the Transportation Security Administration, TSA MD 2810.1, “SSI

Program”;

(4) Homeland Security Agreement Information means information the Department of Homeland Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement. The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion Center Initiative and activities for cyber information sharing consistent with the Cybersecurity Information Sharing Act of 2015;

(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;

(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;

(7) Information Systems Vulnerability Information (ISVI) means:

(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release;

switching, router, and gateway information; interconnections and access methods; and mission or business use/need. Examples of ISVI are systems inventories and enterprise architecture models.

Information pertaining to national security systems and eligible for classification under Executive

Order 13526 will be classified as appropriate; and/or

(ii) Information regarding developing or current technology, the release of which could hinder the objectives of the Department, compromise a technological advantage or countermeasure, cause a denial of service, or provide an adversary with sufficient information to clone, counterfeit, or circumvent a process or system;

(8) Operations Security Information means Department of Homeland Security information that could be collected, analyzed, and exploited by a foreign adversary to identify intentions, capabilities, operations, and vulnerabilities that threaten operational security for the missions of the Department;

(9) Personnel Security Information means information that could result in physical risk to Department of

Homeland Security personnel or other individuals whom the Department is responsible for protecting;

(10) Physical Security Information means reviews or reports illustrating or disclosing facility infrastructure or security vulnerabilities related to the protection of Federal buildings, grounds, or property.

For example, threat assessments, system security plans, contingency plans, risk management plans, business impact analysis studies, and certification and accreditation documentation;

(11) Privacy Information includes both Personally Identifiable Information (PII) and Sensitive Personally

Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual’s identity, either alone, or when combined with other information that is linked or linkable to a specific individual; and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. To determine whether information is PII, DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual. Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.

(i) Examples of stand-alone PII that are particularly sensitive include: Social Security numbers (SSNs), driver’s license or State identification numbers, Alien Registration Numbers (A-numbers), financial account numbers, and biometric identifiers.

(ii) Multiple pieces of information may present an increased risk of harm to the individual when combined, posing an increased risk of harm to the individual. SPII may also consist of any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:

(A) Truncated SSN (such as last 4 digits);

(B) Date of birth (month, day, and year);

(C) Citizenship or immigration status;

(D) Ethnic or religious affiliation;

(E) Sexual orientation;

(F) Criminal history;

(G) Medical information; and

(H) System authentication information, such as mother’s birth name, account passwords, or personal identification numbers (PINs).

(iii) Other PII that may present an increased risk of harm to the individual depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. The context includes the purpose for which the PII was collected, maintained, and used. This assessment is critical because the same information in different contexts can reveal additional information about the impacted individual.

Federal information means information created, collected, processed, maintained, disseminated, disclosed, or disposed of by or for the Federal Government, in any medium or form.

Federal information system means an information system used or operated by an agency or by a Contractor of an agency or by another organization on behalf of an agency.

Handling means any use of controlled unclassified information, including but not limited to marking, safeguarding, transporting, disseminating, re-using, storing, capturing, and disposing of the information.

Incident means an occurrence that—

(1) Actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or

(2) Constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

Information Resources means information and related resources, such as personnel, equipment, funds, and information technology.

Information Security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide—

(1) Integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;

(2) Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and

(3) Availability, which means ensuring timely and reliable access to and use of information.

Information System means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

(b) Handling of Controlled Unclassified Information.

(1) Contractors and subcontractors must provide adequate security to protect CUI from unauthorized access and disclosure. Adequate security includes compliance with DHS policies and procedures in effect at the time of contract award. These policies and procedures are accessible at https://www.dhs.gov/dhs-security-and-training-requirements-contractors.

(2) The Contractor shall not use or redistribute any CUI handled, collected, processed, stored, or transmitted by the Contractor except as specified in the contract.

(3) The Contractor shall not maintain SPII in its invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions. It is acceptable to maintain in these systems the names, titles, and contact information for the Contracting Officer’s Representative (COR) or other government personnel associated with the administration of the contract, as needed.

(4) Any government data provided, developed, or obtained under the contract, or otherwise under the https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors control of the Contractor, shall not become part of the bankruptcy estate in the event a Contractor and/or subcontractor enters bankruptcy proceedings.

(c) Incident Reporting Requirements.

(1) Contractors and subcontractors shall report all known or suspected incidents to the Component Security

Operations Center (SOC) in accordance with Attachment F, Incident Response, to DHS Policy Directive

4300A Information Technology System Security Program, Sensitive Systems. If the Component SOC is not available, the Contractor shall report to the DHS Enterprise SOC. Contact information for the DHS

Enterprise SOC is accessible at https://www.dhs.gov/dhs-security-and-training- requirements-contractors.

Subcontractors are required to notify the prime Contractor that it has reported a known or suspected incident to the Department. Lower tier subcontractors are required to likewise notify their higher tier subcontractor, until the prime contractor is reached. The Contractor shall also notify the Contracting Officer and COR using the contact information identified in the contract. If the report is made by phone, or the email address for the Contracting Officer or COR is not immediately available, the Contractor shall contact the Contracting

Officer and COR immediately after reporting to the Component or DHS Enterprise SOC.

(2) All known or suspected incidents involving PII or SPII shall be reported within 1 hour of discovery. All other incidents shall be reported within 8 hours of discovery.

(3) CUI transmitted via email shall be protected by encryption or transmitted within secure communications systems. CUI shall be transmitted using a FIPS 140-2/140-3 Security Requirements for Cryptographic

Modules validated cryptographic module identified on https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules. When this is impractical or unavailable, for Federal information systems only, CUI may be transmitted over regular email channels. When using regular email channels, Contractors and subcontractors shall not include any CUI in the subject or body of any email. The CUI shall be included as a password-protected attachment with the password provided under separate cover, including as a separate email. Recipients of CUI information will comply with any email restrictions imposed by the originator.

(4) An incident shall not, by itself, be interpreted as evidence that the Contractor or Subcontractor has failed to provide adequate information security safeguards for CUI or has otherwise failed to meet the requirements of the contract.

(5) If an incident involves PII or SPII, in addition to the incident reporting guidelines in Attachment F, Incident Response, to DHS Policy Directive 4300A Information Technology System Security Program, Sensitive Systems, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Unique Entity Identifier (UEI);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime Contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the System for Award

Management (address, position, telephone, and email);

(v) Contracting Officer POC (address, telephone, and email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms, or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules

(xi) Server names where CUI resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the government PII or SPII contained within the system; and

(xiii) Any additional information relevant to the incident.

(d) Incident Response Requirements.

(1) All determinations by the Department related to incidents, including response activities, will be made in writing by the Contracting Officer.

(2) The Contractor shall provide full access and cooperation for all activities determined by the

Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of incidents.

(3) Incident response activities determined to be required by the Government may include, but are not limited to, the following:

(i) Inspections;

(ii) Investigations;

(iii) Forensic reviews;

(iv) Data analyses and processing; and

(v) Revocation of the Authority to Operate (ATO), if applicable.

(4) The Contractor shall immediately preserve and protect images of known affected information systems and all available monitoring/packet capture data. The monitoring/packet capture data shall be retained for at least 180 days from submission of the incident report to allow DHS to request the media or decline interest.

(5) The Government, at its sole discretion, may obtain assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

(e) Certificate of Sanitization of Government and Government-Activity-Related Files and Information. Upon the conclusion of the contract by expiration, termination, cancellation, or as otherwise indicated in the contract, the

Contractor shall return all CUI to DHS and/or destroy it physically and/or logically as identified in the contract unless the contract states that return and/or destruction of CUI is not required. Destruction shall conform to the guidelines for media sanitization contained in NIST SP 800–88, Guidelines for Media Sanitization. The Contractor shall certify and confirm the sanitization of all government and government-activity related files and information.

The Contractor shall submit the certification to the COR and Contracting Officer following the template provided in

NIST SP 800–88, Guidelines for Media Sanitization, Appendix G.

(f) Other Reporting Requirements. Incident reporting required by this clause in no way rescinds the Contractor’s responsibility…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .