02 Scope of Work.pdf

PDF 2 MB Posted

Attached to
Enterprise Wide Workplace Federal contract opportunity
Solicitation number
47PF0025R0022
Issued by
General Services Administration Public Buildings Service Region 5

About this file

This is a Statement of Work (SOW) for GSA's Enterprise-Wide Workplace initiative seeking to implement a scalable marketplace solution to optimize its real estate portfolio across 59 buildings (6.8M square feet, 48K users). The solution must include a Workplace Management System for space allocations and reporting, a Federal Workspace Exchange for sharing underutilized office assets, integration with GSA enterprise identity systems using SCIM and SAML/OpenID Connect, and access to pre-negotiated commercial flexible office space.

The contractor must be a small business with proven expertise in real estate portfolio management and SaaS platform integration, and must either be FedRAMP authorized or achieve GSA LiSaaS authorization within four weeks of award. Key implementation milestones include a 3-day configuration period, 3-day user base identification, 2-day administrator training, and system launch by March 31, 2025, followed by one year of performance monitoring. The SOW details extensive security requirements including LiSaaS/FedRAMP compliance, personnel security protocols, and data protection standards. Additional phases may expand the solution to San Francisco (89 buildings, 6.3M sq ft, 38K users) and Dallas (108 buildings, 6.2M sq ft, 75K users), with options for WiFi services, turnkey services, occupancy sensors, and concierge services.

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Wide Workplace, newest first.
File Type Posted
A02_Proposal Submittal and Method of Award.pdf PDF
A02_LiSaaS-Solution-Profile.docx DOCX document
A02_FIPS-PUB-199-Security-Categorization.docx DOCX document
A02_Amendment 02.pdf PDF
A02_Option Clauses.pdf PDF
A02_RFP Questions_Responses.pdf PDF
A02_LiSaaS-Attestation-Letter.docx DOCX document
A02_LiSaaS-Low-Risk-ATO-Letter.docx DOCX document
A02_LiSaaS-Solution-Review-Checklist.xlsx XLSX spreadsheet
00 Amendment 01.pdf PDF
03 Rev Proposal Submittal and Award Evaluation.pdf PDF
02 Rev SOW 250305.pdf PDF
05 Rev SF1449 47PF0025R0022.pdf PDF
00a Amendment 01 attachment.pdf PDF
01 Rev RFP Cover Page.pdf PDF
04 Rev Commercial Clauses Provisions.pdf PDF
06 Rev Appendix A PRICE SHEET.pdf PDF
01 RFP Cover Page.pdf PDF
03 Proposal Submittal and Award Evaluation.pdf PDF
05 SF1449 47PF0025R0022.pdf PDF
04 Commercial Clauses Provisions.pdf PDF
06 Acquisition Appendix A - PRICE SHEET - final 3-4-25.pdf PDF
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1. Project Overview The General Services Administration (GSA) is seeking to implement an enterprise-wide, scalable marketplace solution to optimize its real estate portfolio and streamline the management of federal office space. The marketplace will empower GSA and its federal agency customers to efficiently share and manage existing office assets while providing seamless access to flexible office space on an as-needed basis. This initiative will align with GSA’s mission to reduce spending, optimize office space, and enhance workforce productivity.

2. Contractor Qualifications Given the high-profile nature of this project and the accelerated timeline, the contractor must be a small business with proven expertise in managing government and private sector real estate portfolios that meet the identified requirements. The selected firm must have experience executing large-scale, high-impact projects with a focus on real estate optimization, flexible office space management, and Software as a Service (SaaS) platform integration. Additionally, the firm must offer a ready-to-deploy solution, as the project schedule does not allow for full development from the ground up. The firm is required to either be already FedRAMP authorized or be able to achieve GSA LiSaaS authorization within the first four weeks of contract award.

3. SOW Deliverables and Responsibilities – Pilot Phas e The contractor shall be responsible for providing the following key scalable deliverables and responsibilities for 59 buildings (leased and government owned), 6.8M square feet and approximately 48K users:

● Workplace Management System:

An administrative engine to assist federal employees with space allocations and reporting, specifically for those who have access to office space in GSA-managed buildings. This includes:

⮚ Managing space allocations across federal agencies

⮚ Generating real-time reporting on space utilization and employee engagement

⮚ Enabling budget controls and spend management

⮚ Ensuring secure access for federal employees based on their roles

● Federal Workspace Exchange:

A secure marketplace for sharing underutilized federal office assets across agencies, ensuring optimal space utilization. Note: Floor plans will not be loaded into the system in this phase, but the ability to do so at a later phase is required.

● Integration with GSA enterprise identity and access management Systems:

The solution should integrate with GSA’s enterprise identity and access management systems, using System for Cross-domain Identity Management (SCIM) and Security Assertion markup Language ( SAML) or OpenID Connect integrations, to manage user access and provide seamless authentication (e.g., Single Sign On) for federal employees.

● Flexible Office Space Access:

Access to a network of commercial flexible office space, with pre-negotiated agreements that comply with government policies.

1 | Page

● AI-Driven Portfolio Management and Cost Optimization:

The solution will incorporate advanced AI analytics to assist GSA in optimizing office space utilization, reducing costs, and making data-driven decisions to manage real estate effectively.

Vendor must adhere to the GSAAIdiective .

● Develop Success Criteria:

In coordination with the COR and CO, create pilot success factors to evaluate at the conclusion of the base performance period.

● Post-Launch Performance Monitoring:

Continuous monitoring and reporting of workspace usage, cost savings, and user satisfaction after the system launch to ensure ongoing optimization.

● All deliverables shall be completed for post-launch performance monitoring within 30 days.

The monitoring will take place for one year for the base year .

● Price Proposal Requirements Pilot Phase:

o Base Year Pricing : Provide a detailed price proposal for all required services for the initial base year .

This ensures transparency in pricing for the base year while allowing flexibility for future expansion.

4. Key Milestones and Timeline

Milestone Timeline Resolution of Configuration Specifications 3 working days Identification of Federal Employee User Base 3 working days Administrator Training 2 working days Launch Communications Development 3 working days Federal Office Asset Onboarding 3 working days

System-Wide Launch March 31, 2025

Post-Launch Mission Performance Monitoring Ongoing, starting from March 31, 2025, one year of monitoring

5. Implementation Approach (Pilot) The implementation of this project will follow the timeline and phases outlined in the table above. The contractor will manage all aspects of configuration, user onboarding, training, and the system launch.

Key phases include:

● Step 1: Resolution of Configuration Specifications Identification and finalization of configuration requirements, including system specifications, access controls, and reporting structures.

● Step 2: Identification of Federal Employee User Base Defining user roles, access permissions, and group structures for federal employees.

● Step 3: Administrator Training Training federal administrators to use the platform for managing workspace allocations, reporting, and user permissions.

2 | Page https://www.gsa.gov/directives-library/use-of-artificial-intelligence-at-gsa

● Step 4: Launch Communications Development Preparation of internal communications and training materials for federal employees to ensure a smooth transition to the new platform.

● Step 5: Federal Office Asset Onboarding Cataloging and integrating available federal office spaces into the marketplace for sharing and optimization.

● Step 6: System-Wide Launch Full deployment and go-live of the system, making it available for federal employees across all agencies.

● Step 7: Post-Launch Mission Performance Monitoring Ongoing monitoring of platform performance, utilization rates, cost savings, and user satisfaction to ensure continuous optimization of the real estate portfolio. Calibrate system by utilizing data points captured and provided by GSA/federal agencies such as: employee daily check-in, occupancy sensors, badge swipes, and other intel to assess occupancy and vacancy levels .

● Step 8: Reporting Provide access to real time data and create customized executive summaries for GSA and customer(s).

6. SOW Deliverables and Responsibilities – Phase II

Price Proposal Requirements for Phase II Options:

● Option 1a: Pricing Year 2 for original scope Chicago (March 2026) :

Pricing for an additional option year 2 beyond the base year for Chicago, IL.

● Option 1b: Pricing Year 3

Pricing for an additional option year 3 for Chicago, IL.

● Option 2: San Francisco, California

Pricing for approximately 89 buildings, 6.3M square feet and 38K users including monitoring for one year. The government may choose to substitute city locations.

● Option 2a: Pricing Year 2 Pricing for an additional option year 2 for San Francisco, CA.

● Option 2b: Pricing Year 3 Pricing for an additional option year 3 for San Francisco, CA.

● Option 3: Dallas, Texas Pricing for 108 buildings, 6.2 M square feet and 75K users including monitoring for one year. The government may choose to substitute city locations.

● Option 3a: Pricing Year 2 Pricing for an additional option year 2 for Dallas, TX.

● Option 3b: Pricing Year 3 Pricing for an additional option year 3 for Dallas, TX.

Provide a detailed licensing model in terms of cost, recurring basis, support included with each license and how licensing is determined (ie: user, location, number of buildings, number of reservable spaces, etc) WiFi Services in Select Buildings:

In subsequent phases, the government may modify the contract to request the contractor be responsible for installing and integrating WiFi services in designated buildings. This includes assessing

3 | Page existing infrastructure, planning for secure, high-performance connectivity, and executing the installation process.

● Note: Pricing for WiFi services is not required at this time.

Turnkey Services in Select Buildings:

In subsequent phases, the government may modify the contract to request the contractor will be responsible for full turnkey services, inclusive of office furnishings, installing and integrating WiFi services, and other office amenities in designated buildings. This includes assessing existing space and addressing future state needs, inclusive of any permits required, installation/reconfiguration/removal of furniture, move services, infrastructure, planning for secure, high-performance connectivity, and executing the installation process.

● Note: Pricing for Turnkey Services is not required at this time.

Occupancy Sensors in Select Buildings:

Option 4: Occupancy Sensor Pricing:

Estimated option pricing for the occupancy sensor system 500,000 square-foot.

The consultant will deploy an occupancy sensor system at designated locations (to be determined) to capture anonymous, real-time, and historical occupancy data. This system will enable GSA to track foot traffic, monitor space usage, and analyze utilization patterns to optimize workspace allocation.

Installation & System Deployment:

● Conduct site surveys to determine optimal sensor placement.

● Perform professional installation and calibration of occupancy sensors.

● Validate data accuracy and system functionality.

System Activation & Data Access:

● Activate the occupancy monitoring system post-installation.

● Provide secure access to occupancy data through a customer portal (web-based dashboard) and

● API integration for seamless connectivity with GSA analytics tools.

● Ensure compliance with federal data security and privacy standards.

Data Collection & Reporting:

● Capture real-time and historical occupancy data, including traffic counts (entries/exits), dwell time analysis (time spent in specific areas), and utilization rates/peak usage periods.

● Provide monthly reports summarizing space utilization insights.

Technical Support & Account Management:

● Assign a dedicated account management team to support GSA.

● Provide technical assistance for troubleshooting and system integration.

● Conduct training sessions for GSA staff on data access and reporting.

Concierge Services:

The contractor shall offer both virtual and on-site concierge services to enhance user support and operational efficiency. These services will assist with facility navigation, scheduling, workspace reservations, and troubleshooting connectivity or facility-related issues.

Option 5: Concierge Services:

The contractor shall provide pricing estimates for:

o Virtual and/or on-site concierge management services (per person) for a one-year term

4 | Page

If the pilot phase is successful and GSA elects to proceed with additional phases, the Contractor shall commence the process to obtain FedRAMP authorized security documentation within one year of the Notice to Proceed (NTP).

7. Security and Compliance The contractor will work with GSA to ensure the solution meets all necessary security and compliance requirements, including achieving FedRAMP authorization for secure government-wide adoption. The solution must adhere to all federal cybersecurity standards, ensuring the platform is safe and secure for use across the federal workforce.

7.1 Low Impact Software as a Service (LiSaaS) - IT Security and Privacy Requirements To be considered for award, the contractor must comply with GSA IT’s LiSaaS review process. The successful vendor will need to ensure any SaaS provided under this contract meets GSA security and privacy requirements prior to invoicing the government for services received under this contract. This includes working with GSA to ensure the SaaS passes the current LiSaaS authorization process, as outlined in GSA IT Security Procedural Guide 16-75: Low Impact Software as a Service (LiSaaS) Solutions Authorization Process.

7.1.1 Assessment of the System (LiSaaS)

The contractor shall provide evidence in support of meeting the requirements for the review activities stated in GSA IT Security Procedural Guide 16-75: Low Impact Software as a Service (LiSaaS) Solutions Authorization Process, and as summarized below. As stated in the guide items (3)-(7) in the list below, may be satisfied by a letter of attestation submitted by the Office of the Chief Security Officer ISSO Support Division (IST) Information System Security Officer (ISSO) or Information System Security Manager (ISSM), based on a demonstration and review of artifacts.

Templates as referenced below will be provided to the contractor, as applicable.

1. Completion of the LiSaaS Solution Profile Template. This profile provides a summary of the service function and purpose provided by the LiSaaS solution. It includes the who, what, when, where, and how of the solution, including the following information and capabilities, as applicable. Instructions are contained in the template.

2. Completion of a LiSaaS Solution Review Checklist Template (including supporting artifacts) with the ISSO. The LiSaaS checklist will go into specific detail regarding the actual GSA implementation of the LiSaaS.

3. Document how system and security parameters deferred to customers are implemented.

Do not use the vendor-supplied defaults for system passwords and other security parameters. GSA security policies and best practices should be used to the greatest extent possible.

5 | Page

4. Submit latest web application vulnerability scan results (e.g., Invicti, NetSparker, Acunetix, Burp Suite Pro, etc.).

5. Submit latest operating system (OS) vulnerability scan results (e.g., Tenable Nessus, Qualys, nCircle, McAfee Vulnerability Manager, etc.). Reference NIST SP 800-53 control RA-05 – Vulnerability Monitoring and Scanning.

a. Vendors that are Payment Card Industry Data Security Standard ( PCI DSS ) compliant or have the TrustedSite Certification or TrustGuard Seal may provide the results of their latest PCI DSS Compliant, McAfee TrustedSite or TrustGuard quarterly scan.

b. Vendors that do not meet the PCI DSS, McAfee, or TrustGuard standards listed, must provide their most recent OS vulnerability scan results.

6. Document an acceptable flaw remediation process. Vendors must be able to identify and remediate information system flaws in a timely manner (i.e., the process must describe how often scans are completed and how vulnerabilities are remediated). Reference NIST 800-53 Control SI-2: Flaw Remediation.

7. Results of one of the following audits/certifications:

a. Service Organization Control (SOC) 2/Statements on Standards for Attestation

Engagements (SSAE) 18

b. SysTrust/WebTrust

c. ISO/IEC 27001

d. PCI DSS

Note: Although the basic requirement is for the SSAE/SOC 2 audit report or one of the vendor certifications; the GSA AO and the CISO will take a holistic view of the application based on all of the documentation presented to determine the overall risk of the application as well as any residual risks that may need to be accepted when considering the application for use. If the documentation presented does not provide an adequate understanding of the systems security posture and/or is deemed insufficient to make a risk determination; additional information will be required.

7.1.2 Authorization of the System (LiSaaS)

The LiSaaS solutions must not have any Critical/Very High or High vulnerabilities identified in their scans before an ATO can be granted.

The ATO package must include documentation and validation of the requirements identified above, and consists of:

6 | Page https://www.pcisecuritystandards.org/document_library https://www.trustedsite.com/ https://www.trust-guard.com/ https://us.aicpa.org/interestareas/frc/assuranceadvisoryservices/cpas https://us.aicpa.org/interestareas/frc/assuranceadvisoryservices/cpas https://www.cpacanada.ca/en/business-and-accounting-resources/audit-and-assurance/overview-of-webtrust-services https://www.iso.org/standard/54534.html https://www.pcisecuritystandards.org/

● LiSaaS Solution Profile

● LiSaaS Checklist

● FIPS 199 Security Categorization

● Latest vulnerability scan results (e.g., web, OS, container), as applicable

● LiSaaS Attestation Letter, if applicable

● LiSaaS ATO Letter

The authorization process supports an ATO valid for:

● No more than one year if the application is determined to be Low Risk based on the evidence provided.

● Up to three years if the application is determined to be a commodity ancillary service that presents Very Low/Negligible Risk based on the evidence provided.

If not already FedRAMP authorized, any application granted a one-year ATO must obtain a FedRAMP tailored authorization (at a minimum) within one year of its ATO. If, within three months of receiving its one-year ATO, progress towards a FedRAMP Tailored authorization has not been observed, GSA will start to cease engagement with the vendor and pursue alternative solutions. For detailed requirements of FedRAMP Tailored Li-SaaS, download the FedRAMP Tailored Authorization Toolkit available on the FedRAMP Baselines webpage . Without a LiSaaS approval, GSA will not be able to use the software for the base year of the contract, and without FedRAMP approval, GSA will be unable to use the product for the option years of the contract.

The contractor’s agreement to the LiSaaS and FedRAMP requirements are required. If the contractor does not agree, no contract award will be made.

The authorization process supports an ATO valid for:

● No more than one year if the application is determined to be Low Risk based on the evidence provided.

● Up to three years if the application is determined to be a commodity ancillary service that presents Very Low/Negligible Risk based on the evidence provided.

If not already FedRAMP authorized, any application granted a one-year ATO must obtain a FedRAMP tailored authorization (at a minimum) within one year of its ATO. If, within three months of receiving its one-year ATO, progress towards a FedRAMP Tailored authorization has not been observed, GSA will start to cease engagement with the vendor and pursue alternative solutions. For detailed requirements of FedRAMP Tailored Li-SaaS, download the FedRAMP Tailored Authorization Toolkit available on the FedRAMP Baselines webpage . Without a LiSaaS approval, GSA will not be able to use the software for

7 | Page https://www.fedramp.gov/baselines/ https://www.fedramp.gov/baselines/ the base year of the contract, and without FedRAMP approval, GSA will be unable to use the product for the option years of the contract.

The contractor’s agreement to the LiSaaS and FedRAMP requirements are required. If the contractor does not agree, no contract award will be made.

7.1.3 Inability to Maintain LiSaaS ATO Requirements

If at any time, the vendor is either unwilling or unable to meet any of the LiSaaS ATO process requirements as specified in GSA IT Security Procedural Guide 16-75: Low Impact Software as a Service (LiSaaS), GSA may choose to cancel the contract and terminate any outstanding orders.

The vendor shall report if its audit report/certification renews or expires and if any of the other required activities cannot be supported.

7.2 Cloud Information Systems – IT Security and Privacy Requirements Cloud computing products and services (such as Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Software-as-a-Service (SaaS)) that create, collect, process, store, or maintain Federal information on behalf of GSA are required to be FedRAMP authorized. FedRAMP provides for a standardized, reusable approach to security assessments and authorizations for cloud computing products and services to ensure the security of Federal information.

The contractor shall implement the controls contained within the FedRAMP Cloud Computing Security Requirements Baseline and FedRAMP Continuous Monitoring Requirements for Low impact systems (as defined in FIPS PUB 199). These documents define requirements for compliance to meet minimum Federal information security and privacy requirements for Low impact systems. The FedRAMP baseline controls are based on NIST Special Publication 800-53, Revision 5, “Security and Privacy Controls for Information Systems and Organizations,” and includes a set of additional controls for use within systems providing cloud services to the federal government.

The contractor shall generally, substantially, and in good faith follow FedRAMP guidelines and Security guidance. The FedRAMP program overview document FedRAMP CSP Authorization Playbook , available on the FedRAMP.gov website, details program requirements; the Documents and Templates section on the FedRAMP website provides a detailed and comprehensive list of all current documents and templates necessary to facilitate a FedRAMP authorization. In situations where there are no FedRAMP or GSA procedural guides, the contractor shall use generally accepted industry best practices for IT security.

GSA may choose to cancel the contract and terminate any outstanding orders if the contractor has its FedRAMP authorization revoked and the deficiencies are greater than GSA risk tolerance thresholds.

7.2.1 Assessment and Authorization

7.2.2 Assessment of the System

8 | Page https://www.fedramp.gov/assets/resources/documents/CSP_Authorization_Playbook.pdf https://www.fedramp.gov/documents-templates/

● If the Cloud Service Provider (CSP) SaaS or PaaS is FedRAMP authorized (i.e., listed as FedRAMP authorized on the FedRAMP Marketplace website), GSA will leverage the CSP’s FedRAMP Assessment and Authorization package to document and assess the Customer Responsibility Matrix (CRM) controls for which GSA has responsibility for the agency’s instance of the CSP’s SaaS or PaaS offering. The CSP shall support GSA’s Leveraged FedRAMP assessment and authorization process of CRM controls as specified in CIO-IT Security-06-30: Managing Enterprise Cybersecurity Risk, as necessary.

● If the CSP SaaS or PaaS offering is NOT already FedRAMP authorized, the contractor shall comply with FedRAMP requirements as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement. The Level of Effort for the Assessment and Authorization (A&A) is based on the System’s FIPS PUB 199 impact level and applicable A&A documentation requirements. The contractor shall create, maintain, and update FedRAMP required documentation, as applicable per categorization type, using FedRAMP requirements and templates, which are available at FedRAMP.gov; and the following GSA required supplemental documents to capture additional system details, as applicable. This list could include but is not limited to the following:

⮚ Expanded ports protocols and services template

⮚ Expanded data sensitivity template

⮚ External services template

● Alternative Implementation / Risk Acceptance Template

● GSA container guidance document

● GSA mobile application guidance document

● Secure Configuration Template (SCP), an expanded CIS/CRM document

● Information systems must be assessed by an accredited FedRAMP Third Party Assessment Organization (3PAO) initially and whenever there is a significant change to the system’s security posture in accordance with the FedRAMP Continuous Monitoring Plan.

● The Government reserves the right to perform Security Assessment and Penetration Testing (of its instance). If the Government exercises this right, the contractor shall allow Government employees (or designated third parties) to conduct Security Assessment and Penetration Testing activities to include control reviews in accordance with FedRAMP requirements. Penetration shall be supported by mutually agreed upon Rules of Engagement (RoE). Review activities include but are not limited to manual penetration testing; automated scanning of operating systems, web applications; wireless scanning; network device scanning to include routers, switches, and firewall, and IDS/IPS; databases and other applicable systems, including general support structure, that create, collect, process, store, or maintain of Government information for vulnerabilities.

● The contractor shall provide access to the Federal Government, or their designee acting as their agent, when requested, in order to verify compliance with the requirements for an Information Technology security program. The Government reserves the right to conduct on-site inspections.

The contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review.

● Physical Access Considerations – If the CSP is operated within an IaaS that is FedRAMP authorized (e.g., Amazon Web Services); physical access to the physical datacenter environment

9 | Page will be governed by the terms of access allowed by the underlying infrastructure provider as defined in the FedRAMP A&A authorization package.

● Identified gaps between required FedRAMP Security Control Baselines and Continuous Monitoring controls and the contractor's implementation as documented in the Security Assessment Report shall be tracked by the contractor for mitigation in a Plan of Action and Milestones (POA&M) document. Depending on the severity of the gaps, the Government may require them to be remediated before a GSA authorization is issued.

● The contractor is responsible for mitigating all security risks found during A&A and continuous monitoring activities. Vulnerabilities must be mitigated as follows:

⮚ 14 days for CISA Known Exploited Vulnerabilities (KEV)

● 15 days for Critical vulnerabilities for Internet-accessible systems or services

● 30 days for Critical and High vulnerabilities

● 90 days for Moderate vulnerabilities

● 180 days for Low vulnerabilities

● The Government will determine the risk rating of vulnerabilities

7.2.3 Authorization of the System

● FedRAMP Authorized CSP Offerings. If the CSP SaaS or PaaS is already FedRAMP authorized (i.e., listed as FedRAMP authorized on the FedRAMP Marketplace website), GSA will leverage the CSP’s FedRAMP Assessment and Authorization package and GSA’s assessment of the customer responsibility matrix (CRM) controls to issue a GSA leveraged ATO for the agency’s instance of the CSP’s SaaS or PaaS offering. The CSP shall support GSA’s Leveraged FedRAMP authorization process as specified in CIO-IT Security-06-30: Managing Enterprise Cybersecurity Risk, as necessary.

● Not FedRAMP Authorized CSP Offerings. If the CSP SaaS or PaaS offering is NOT already FedRAMP authorized and is required to be FedRAMP authorized consistent with the scope of FedRAMP as identified in M-24-15, “Modernizing the Federal Risk and Authorization

● Management Program (FedRAMP),” it shall:

⮚ Operate on a CSP IaaS environment that is FedRAMP authorized; AND

⮚ Be listed on the FedRAMP Marketplace as either “FedRAMP Ready” or “In Process”; AND provide GSA a copy of the system FedRAMP Readiness Assessment Report (RAR), completed by an A2LA.org approved FedRAMP 3PAO, following the FedRAMP Readiness Assessment Guidelines, within two weeks of contract award. The FedRAMP Readiness Assessment Review demonstrates the CSPs overall readiness for FedRAMP authorization and whether it has a viable path to achieve a FedRAMP authorization within one (1) year of the contract award. If the CSP does not provide a FedRAMP Readiness Assessment as prescribed or the assessment demonstrates a significant gap in capabilities that will preclude achievement of a FedRAMP authorization within 1 year of the contract award, then, GSA will terminate the contract; OR

⮚ If the CSP is not already listed as “FedRAMP Ready” or “In-Process” on the FedRAMP Marketplace, OR the CSP does not have a RAR, they shall develop and deliver one within

10 | Page

90 days of contract award for a Tailored/Low system or 180 days for a Moderate/High system. The FedRAMP RAR shall be completed by an A2LA.org approved FedRAMP 3PAO, following the FedRAMP Readiness Assessment Guidelines.

⮚ All applicable FedRAMP controls for the appropriate FedRAMP baseline ( Tailored-LiSaaS, Low) must be implemented aligned to the FedRAMP control parameters and implementation guidance, as applicable. The table below identifies the essential FedRAMP security controls. The CSP shall make the proposed system and security architecture of the information system available to the Security Engineering Division, in the Office of the Chief Information Security Officer for review and approval before commencement of system build (architecture, infrastructure, and code [as applicable]) and/or the start of A&A activities.

FedRAMP Security Controls Table Control ID Control Title FedRAMP Baseline AC-02 Account Management H, M, T, L AC-03 Access Enforcement H, M, T, L AC-17 Remote Access H, M, T, L AU-02 Audit Events H, M, T, L AU-03 Content of Audit Records H, M, T, L AU-06 Audit Record Review, Analysis, and Reporting H, M, T, L

AU-06(03) Correlate Audit Record Repositories

H, M

CM-02 Baseline Configuration H, M, T, L CM-06 Configuration Settings H, M, T, L CP-07 Alternative Processing

Site M, H

CP-08 Telecom Services M, H IA-02(01) Identification and

Authentication (Organizational Users) | Network Access to Privileged Accounts

H, M, T, L

IA-02(2) Identification and Authentication (Organizational Users) | Network Access to Non-Privileged Accounts

H, M, T, L

IA-02(12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials

H, M, T, L

11 | Page

IA-07 Cryptographic Module Authentication

H, M, T, L

IA-11 Re-Authentication H, M, T, L IA-12 Identity Proofing H, M PL-08 Information Security

Architecture H, M, T, L

RA-03(01) Risk Assessment / Supply Chain Risk Assessment

H, M, T, L

RA-05 Vulnerability Scanning H, M, T, L RA-05(05) Vulnerability Monitoring and Scanning | Privileged Access

H, M

RA-08 Privacy Impact Assessments

N/A (required by GSA)

SA-09 External System Services H, M, T, L SA-11(01) Static Code Analysis H, M SC-02 Separation of System and

User Functionality H, M

SC-07 Boundary Protection H, M, T, L SC-07(08) Boundary Protection |

Route Traffic To Authenticated Proxy Servers

H, M

SC-07(10) Boundary Protection / Prevention Exfiltration

H

SC-08/SC-08(

01)

Transmission Confidentiality and Integrity / Cryptographic Protection

H, M, T, L

SC-10 Network Disconnect H, M SC-12 Cryptographic Key

Establishment and Management

H, M, T, L

SC-13 Cryptographic Protection H, M, T, L SC-17 Public Key Infrastructure

Certificates H, M

SC-28(01) Protection of Information at Rest | Cryptographic Protection

H, M, T, L

SI-02 Flaw Remediation H, M, T, L SI-04(18) Analyze Traffic and

Convert Exfiltration H, M

12 | Page

SI-07(02) Software, Firmware, and Information Integrity | Automated Notifications of Integrity Violations

H

SI-10 Information Input Validation

H, M

SR-02 Supply Chain Risk Management Plan

H, M, T, L

⮚ If requirements a-d, as defined above, are met, the CSP will have one (1) year from LiSaaS issuance to achieve FedRAMP authorization. During this transitional period, GSA may issue an agency specific authorization (i.e., not FedRAMP) not to exceed eighteen months or the discretion of the contracting officer (to allow the CSP to achieve FedRAMP compliance) leveraging either:

● an existing ATO with another Federal Department/Agency (D/A) (with supporting A&A Package) OR

● a new ATO based on the A&A processes described in GSA IT Security Procedural Guide 06-30: Managing Enterprise Cybersecurity Risk including:

● GSA LiSaaS ATO (For Low Impact) - For the LiSaaS authorization process the CSP shall, in collaboration with GSA, complete a LiSaaS solution profile and checklist, provide the most recent vulnerability scans for the solution and provide documentation on how flaws/vulnerabilities are remediated.

● The CSP shall commit to supporting the effort required for an agency specific authorization. The CSP shall make available any existing assessment and authorization package for GSA review and provide necessary documentation and access to facilitate the completion of the appropriate GSA A&A process (i.e., LiSaaS). If a FedRAMP authorization is not obtained within one (1) year of contract award, OR the assessment of the CSP offering demonstrates a significant gap in capabilities that will preclude achievement of a FedRAMP authorization then GSA will not be able to use the offering and shall terminate the contract. After achieving FedRAMP authorization, the CSP shall support efforts for GSA to issue a Leveraged FedRAMP authorization as described in Item 1 above, FedRAMP Authorized CSP Offerings.

7.2.4 Reporting and Continuous Monitoring

● If the CSP SaaS or PaaS is FedRAMP authorized:

⮚ Maintenance of the FedRAMP Authorization will be through continuous monitoring and periodic audit of the operational controls within a contractor’s system, environment, and processes to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment.

Through continuous monitoring, security controls and supporting deliverables are

13 | Page updated in agreement with FedRAMP guidelines and submitted to the Connect.gov Portal or repository designated by the FedRAMP program.

⮚ The submitted deliverables (or lack thereof) provide a current understanding of the security state and risk posture of the information systems. The deliverables will allow the Federal Departments/Agencies leveraging the services providers’ cloud offering to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur. Contractors will be required to provide updated deliverables and automated data feeds as defined in the FedRAMP Continuous Monitoring Plan.

● If the CSP SaaS or PaaS offering is NOT already FedRAMP authorized, the contractor shall provide continuous monitoring deliverables in support of a one (1) year conditional authorization until FedRAMP authorization is achieved at which time the contractor will follow the FedRAMP process. Deliverables to be provided during this conditional authorization shall include:

⮚ Quarterly, provide the most recent Web Application and Operating System vulnerability scan reports. GSA’s control parameter for RA-05, Vulnerability Monitoring and Scanning, specifies the following type and frequency of scans; weekly authenticated scans of operating systems (OS)-including databases, monthly unauthenticated scans of web applications, annual authenticated scans of web applications (deliverable shall include raw results and findings shall be included in the POA&M document);

⮚ Quarterly, provide POA&M updates in accordance with requirements and the schedule set forth in GSA CIO IT Security Procedural Guide 09-44: Plan of Action and Milestones

(POA&M).

⮚ Annually, provide A&A Package updates including the System Security Plan, Contingency Plan, Business Impact Analysis, Configuration Management Plan, Contingency Plan Test Report, and Annual FISMA Assessment.

● Upon achievement of FedRAMP authorization, GSA will accept the FedRAMP A&A and continuous monitoring documentation made available on the Connect.gov Portal or a repository designated by the FedRAMP program in agreement with FedRAMP guidelines to satisfy the continuous monitoring requirement.

7.3 Personnel Security Requirements

Contractor shall furnish documentation reflecting favorable adjudication of background investigations for all personnel (including subcontractors) supporting the system. Contractors shall comply with GSA Order CIO 2100.1, “GSA Information Technology (IT) Security Policy,” and GSA Order ADM 2181.1, “Homeland Security Presidential Directive-12, Personal Identity Verification and Credentialing Policy, and Background Investigations for Contractor Employees.” GSA separates the risk levels for personnel working on Federal computer systems as follows:

● A favorable initial fitness/suitability determination must be granted, and a Tier 1 or higher background investigation initiated before access to the GSA network or any GSA IT system. There shall be no waivers to this requirement for GSA network and IT system access for GSA employees or contractors.

14 | Page

● A favorable initial fitness/suitability determination must be granted, and a Tier 2 or higher background investigation initiated before access to PII/CUI is granted. The authority and access shall be determined by the appropriate GSA Supervisor (for GSA employees) or CO (for contract personnel), Data Owner, and the System's AO. Each System's AO, with the request of the GSA Supervisor, Data Owner, or CO, shall evaluate the risks associated with each such request.

● A favorable suitability determination must be completed at a Tier 2 or higher background investigation before privileged access to the GSA network or IT systems is granted. A waiver may be requested in order to maintain GSA business operations; however, such requests should be used judiciously and not incur unnecessary risks to GSA.

If final adjudication of a background investigation is unfavorable, GSA network and IT system access must be revoked, and any GFE, including the GSA PIV card, must be retrieved and returned to OMA.

GSA shall sponsor the investigation when deemed necessary. No access shall be given to government computer information systems and government sensitive information without a background investigation being verified or in process. If results of background investigation are not acceptable, then access shall be terminated.

The Contractor shall provide a report of separated staff on a monthly basis, beginning 60 days after execution of the option period.

7.4 Sensitive Information Storage

Controlled Unclassified Information (CUI), data, and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment will be returned to Government control, destroyed, or held until otherwise directed. Destruction of items shall be accomplished by following NIST Special Publication 800-88, Revision 1, “Guidelines for Media Sanitization.” The destruction, purging or clearing of media specific to the CSP will be recorded and supplied upon request of the Government.

7.5 Protection of Information

The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The contractor shall also protect all Government data, equipment, etc. by treating the information in accordance with its FISMA system categorization.

All information about the systems gathered or created under this contract should be considered as CUI information. If contractor personnel must remove any information from the primary work area that is included in the ATO boundary, they should protect it to the same FedRAMP requirements. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.

7.6 Unrestricted Rights to Data

The government will retain unrestricted rights to government data. The ordering activity retains ownership of any user created/loaded data and applications hosted on vendor’s infrastructure, as well as maintains the right to request full copies of these at any time.

7.7 Personally Identifiable Information

15 | Page

Personally identifiable information (PII) is not in the scope of this acquisition and PII is not expected to be stored in the vendor's cloud solution. The vendor shall prepare a Privacy Threshold Assessment (PTA) to either document PII is not in scope, or determine which categories of information will be stored, processed, or transmitted by the system. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.

PII (should it come into scope) will require the following guidelines be adhered to.

● The vendor’s information system must be authorized at least at the FIPS PUB 199 Moderate level.

● For any system that collects, maintains, or disseminates PII, a PIA must be completed by the contractor and provided to the GSA Privacy Office for review along with the other authorization to operate (ATO) documents.

● If the system retrieves information using PII, the Privacy Act applies and it must have a system of records notice (SORN) published in the Federal Register.

● If PII is collected from individuals by the system, a Privacy Act Statement (i.e., Privacy Notice) must be provided to users prior to their use of the application on what data is being collected and why, as well as the authority for the collection and the impact of not providing some or all of

it. The Privacy Act Statement must be available to the individual directly on the form used to collect the information. Providing a link back to the Statement from the form is acceptable.

7.8 Data Availability

The data must be available to the Government upon request within one business day or within the timeframe negotiated with the Contractor and shall not be used for any other purpose other than that specified herein. The contractor shall provide requested data at no additional cost to the government.

7.9 Data Release

Any information made available to the Contractor by the Government shall be used only for the purpose of carrying out the provisions of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of the contract. In performance of this contract, the Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its subcontractors shall be under the supervision of the Contractor or the Contractor’s responsible employees. Each officer or employee of the Contractor or any of its subcontractors to whom any Government record may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such officer or employee can be used only for that purpose and to the extent authorized herein. Further disclosure of any such information, by any means, for a purpose or to an extent unauthorized herein, may subject the offender to criminal sanctions imposed by 18 U.S.C. §§ 1030.

Contractor will not disclose Customer Data to any government or third party or access or use Customer Data; except in each case as necessary to maintain the Cloud Services or to provide the Cloud Services to Customer in accordance with this contract, or as necessary to comply with the law or a valid and binding order of a governmental or regulatory body (such as a subpoena or court order). Unless it would be in violation of a court order or other legal requirement, the Contractor will give the Government reasonable notice of any such legal requirement or order, to allow the Government to seek a protective order or other appropriate remedy.

7.10 Data Ownership

16 | Page https://www.gsa.gov/reference/gsa-privacy-program/rules-and-policies-protecting-pii-privacy-act

All Government data collected in the system is the property of the Federal Government. All data collected by the system shall be provided by the Contractor (system provider) as requested during the contract period and at the completion of the contract period.

Confidentiality and Nondisclosure Personnel working on any of the described tasks, may at Government request, be required to sign formal non-disclosure and/or conflict of interest agreements to guarantee the protection and integrity of Government information and documents.

Additionally, any information made available to the Contractor by the Government shall be used only for the purpose of carrying out the provisions of this contract and shall not be divulged or made known in any manner to any persons except as may be necessary in the performance of the contract. In performance of this contract, the Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its subcontractors shall be under the supervision of the Contractor or the Contractor’s responsible employees. Each officer or employee of the Contractor or any of its subcontractors to whom any Government record may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such officer or employee can be used only for that purpose and to the extent authorized herein. Further disclosure of any such information, by any means, for a purpose or to an extent unauthorized herein, may subject the offender to criminal sanctions imposed by 18 U.S.C. §§ 1030.

7.11 GSA Non-Disclosure Agreement

Each individual contractor/subcontractor employee who performs work on this contract is required to sign an Employee NDA. The Contractor shall submit to the COR a completed confidentiality and NDA for each individual contractor/subcontractor.

The Contractor and all contractor/subcontractor employees may have access to sensitive data, proprietary, or confidential business information of other companies or the Government in the course of performing official duties on this contract. The term “proprietary information” means any information considered so valuable by its owners that it is held in secret by them and their licensees and is not available to the public.

All information that is (1) obtained related to or derived from this contract, and (2) results from or derived from any actual tasks assigned to contractor employees while participating on this contract is considered proprietary.

The Contractor and all contractor/subcontractor employees will not use vendor proprietary information except as necessary to perform this contract and shall agree not to disclose such information to third parties, including any employee of the contractor/subcontractor who has not executed this NDA, or use such information in any manner inconsistent with the purpose for which it was obtained. Anyone failing to comply with the agreement may be subject to disciplinary action or termination of employment by the contractor/subcontractor, and possible administrative, civil, or criminal penalties.

Note: GSA’s Office of the General Counsel (OGC) is available to coordinate on defining NDA requirements. Upon request, GSA OGC can advise on NDA development.

7.12 Additional Stipulations:

● If the CSP SaaS or PaaS is FedRAMP authorized security documentation will be marked in accordance with FedRAMP guidelines.

● If the CSP SaaS or PaaS offering is NOT already FedRAMP authorized security documentation will be marked as follows:

17 | Page

⮚ PTAs, PIAs, and self-attestation letters will not be marked.

⮚ CP, BIA, and CP Test Reports will be marked CUI//EMGT.

⮚ All other security documentation will be marked CUI//ISVI.

⮚ Documents will be marked in bold text on the top of all pages. Spelling out of acronyms is not required.

⮚ The cover page of each CUI document must contain the following statement on the lower left of the page. Controlled by: General Services Administration OCISO ISP Division: ispcompliance@gsa.gov .

⮚ External transmission/dissemination of CUI to or from a Government system must be encrypted. A FIPS PUB 140-3/140-2 validated encryption module must be used to encrypt the CUI data.

Note: NIST has issued FIPS 140-3 and no longer accepts FIPS 140-2 modules for validation. However, previously validated 140-2 modules will be accepted through September 22, 2026. For additional information see the NIST Cryptographic Module Validation Program Validated Modules.

● The Contractor shall provide software self-attestation letter(s) regarding conformity to NIST guidance on secure software development as required by OMB M-23-16, “Update to Memorandum M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices.”

⮚ Attestation must be provided as part of an acquisition, upon contract award, and upon major version upgrades as specified in OMB M-23-16, GSA MV-2023-02 Supplements 1-2, and self-attestation letter templates provided by GSA.

⮚ Any gaps in meeting the software development practices required by the attestation form that cannot be attested to, the Contractor must provide mitigating practices in place (if any) and provide a POA&M to monitor any gaps and their resolution.

● The contractor shall cooperate in good faith in defining an NDA that other third parties must sign when acting as the Federal government’s agent. Note: GSA’s Office of the General Counsel (OGC) is available to coordinate on defining NDA requirements. Upon request, GSA OGC can advise on NDA development.

● The contractor shall comply with any additional FedRAMP privacy requirements. The Government has the right to perform manual or automated audits, scans, reviews, or other inspections of the vendor’s IT environment being used to provide or facilitate services for the Government. The Contractor shall be responsible for the following privacy and security safeguards:

⮚ The Contractor shall not publish or disclose in any manner, without the Contracting Officer’s written consent, the details of any safeguards either designed or developed by the Contractor under this contract or otherwise provided by the Government. Exception - Disclosure to a Consumer Agency for purposes of A&A verification or to the Connect.gov portal. To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor shall afford the Government access to the Contractor’s facilities, installations, 18 | Page mailto:ispcompliance@gsa.gov https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Validated-Modules technical capabilities, operations, documentation, records, and databases within 72 hours of the request. Access to support incident investigations, shall be provided as soon as possible but not longer than 72 hours after request.

⮚ Physical Access Considerations – If the SaaS provider is…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .