B09_SA_Amendment_2_0002.pdf
PDF 644 KB Posted
- Attached to
- Tri-Credit Reporting Services. Federal contract opportunity
- Solicitation number
- 140D0425Q0170
About this file
This document is an Amendment (Amendment 0002) to a Request for Quote (RFQ) for Tri-Credit Reporting Services, solicitation number 140D0425Q0170, issued by the Department of the Interior's Interior Business Center, Acquisition Services Directorate. The amendment serves to respond to contractor questions and update Attachment 1 to clarify that the government will only pay for searches that are required and completed.
The RFQ is set aside for small businesses and seeks a contractor to provide tri-merge credit reporting services for the Human Resources Directorate's Personnel Security Branch. The contract will be a Firm-Fixed-Price purchase order with a base period of one year and four option years, from 06/22/2025 to 06/21/2030. The government anticipates purchasing approximately 1,500 credit report searches per year. The incumbent contractor is Acranet, Inc., with the previous contract (140D7020P0036) not exceeding $50,000 for the base and four options. Credit checks will apply to all federal employees, contractors, current and new hires, including those undergoing position changes or promotions.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140D0425Q0170_Amd_0002.pdf | ||
| B09_SA_Attachment_1_Price_Sheet_Version_2_0002.xlsx | XLSX spreadsheet | |
| Sol_140D0425Q0170_Amd_0001.pdf | ||
| B09_SA_Amendment_1_0001.pdf | ||
| Sol_140D0425Q0170.pdf | ||
| B08_SOL_Attachment_2_EULA_Addendum_2.pdf | ||
| B08_SOL_Full.pdf | ||
| B08_SOL_Attachment_1_Price_Sheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
(x)
140D0425Q0170 x x
1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted ; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGEMENT TO BE
RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR
OFFER. If by virtue of this amendment you desire to change an offer already submitted , such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
x
Herndon VA 20170
D34
Suite 2000A 381 Elden Street Acquisition Services Directorate Interior Business Center, AQD
140D0425Q017003/24/20250002
13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
12. ACCOUNTING AND APPROPRIATION DATA (If required) is not extended.is extended, Items 8 and 15, and returning
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended , by one of the following methods: (a) By completing
The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
FACILITY CODE CODE
10B. DATED (SEE ITEM 13)
10A. MODIFICATION OF CONTRACT/ORDER NO.
9B. DATED (SEE ITEM 11)
9A. AMENDMENT OF SOLICITATION NO.
CODE
8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)
7. ADMINISTERED BY (If other than Item 6)CODE 6. ISSUED BY
PAGE OF PAGES
4. REQUISITION/PURCHASE REQ. NO.3. EFFECTIVE DATE2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO. (If applicable)
1. CONTRACT ID CODE
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
03/24/2025
CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority) appropriation data, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
E. IMPORTANT: Contractor is not is required to sign this document and return __________________ copies to the issuing office.
ORDER NO. IN ITEM 10A.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
The purpose of this amendment 0002 is to:
1. Respond to contractor questions. Included as attachment 3.
2. Update to Attachment 1 to include: The Government will only pay for those searches required/completed.
All other terms and conditions remain unchanged.
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)15A. NAME AND TITLE OF SIGNER (Type or print)
15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 15B. CONTRACTOR/OFFEROR 16C. DATE SIGNED
(Signature of person authorized to sign) (Signature of Contracting Officer)
Christina Lene
STANDARD FORM 30 (REV. 11/2016)
Prescribed by GSA FAR (48 CFR) 53.243
Previous edition unusable
Except as provided herein, all terms and conditions of the document referenced in Item 9 A or 10A, as heretofore changed, remains unchanged and in full force and effect .
RFQ Continuation Sheets
Document No.
RFQ
140D0425Q0170
Tri-Credit reporting Services P a g e | 3
SECTION 1 - Introduction
1.1 General
The Department of the Interior, Interior Business Center, Acquisition Services Directorate, Division 3, Branch 4, on behalf of The Human Directorate (HRD) Resources Security and Drug & Alcohol Testing Services to procure SDATD Tri-Credit Reporting Services.
1.2 Set-Aside Information
This requirement will be competed on the open market through SAM.gov as a Total Small Business (SB) set aside. The Acquisition Services Directorate (AQD) is issuing this competitive Request for Quote (RFQ) to solicit Small Businesses for the purpose of entering into a single Firm-Fixed-Price (FFP) Purchase Order for Tri-Credit Reporting Services. AQD will conduct this acquisition using subparts 13.5 and 12.6 under the Federal Acquisition Regulation (FAR). If you are interested in this acquisition, you may participate by submitting your response in accordance with the requirements and instructions contained herein. AQD will conduct the solicitation and manage the resultant contract administration, as well as payment of invoices.
The Government reserves the right not to make an award.
1.3 Anticipated Award Type
The Government anticipates awarding a Firm-Fixed-Price (FFP) purchase order, issued contract, as a result of this RFQ.
The associated North American Industrial Classification System (NAICS) code for this procurement is NAICS 561450– Credit Services. The Product Service Code (PSC) for this procurement R611 Support- Administrative: Credit Reporting.
SECTION 2 Specifications/Requirement
2.1 CONTRACT FORM
The Human Directorate (HRD) Resources Security and Drug & Alcohol Testing Services to procure SDATD Tri-Credit Reporting Services.
The vendor shall deliver all requested items stated in this solicitation by the delivery date specified in section 2.4 Delivery Instructions.
2.2 SUPPLIES OR SERVICES AND PRICES/COSTS
Item Description Quantity
Document No.
RFQ
140D0425Q0170
Services P a g e | 4
Tri-Credit Reporting services 1500
Searches per year
2.3 PERIOD OF PERFORMANCE AND DELIVERABLES
Award Year POP Start Date POP End Date Base Year 06/22/2025 06/21/2026
Option Year 1 06/22/2026 06/21/2027 Option Year 2 06/22/2027 06/21/2028 Option Year 3 06/22/2028 06/21/2029 Option Year 4 06/22/2029 06/21/2030
2.4 Delivery Instructions:
FOB point for this solicitation is Destination, all shipping and handling cost shall be included in the price of the line items.
Delivery Location.
TBD
The delivery date for all items is no later than 5 days after award. Delivery must be coordinated with IBC/HRD, Contracting Officer Representative (COR) and Delivery Point of Contact (POC).
Both will be identified upon award.
2.5 Contracting Officer Representative (COR):
Performance of work under this contract must be subject to the technical direction of the Contracting Officer's Representative identified above, or a representative designated in writing.
The term "technical direction" includes, without limitation, direction to the contractor that directs or redirects the labor effort, shifts the work between work areas or locations, fills in details and otherwise serves to ensure that tasks outlined in the work statement are accomplished satisfactorily.
1. The Contracting Officer's Representative does not have authority to issue technical direction that constitutes the following:
a. Constitutes a change of assignment or additional work outside the specification(s)/statement of work.
b. Constitutes a change as defined in the clause entitled "Changes”.
c. In any manner causes an increase or decrease in the contract price, or the time required for contract performance.
d. Changes any of the terms, conditions, or specification(s)/work statement of the contract.
Document No.
RFQ
140D0425Q0170
Services P a g e | 5
e. Interferes with the contractor's right to perform under the terms and conditions of the contract; or
f. Directs, supervises, or otherwise controls the actions of the contractor's employees.
2. Technical direction may be oral or in writing. The Contracting Officer's Representative shall confirm oral direction in writing within five workdays, with a copy to the Contracting Officer.
3. The contractor shall proceed promptly with performance resulting from the technical direction issued by the Contracting Officers, Representative. If, in the opinion of the contractor, any direction of the Contracting Officers, Representative, or his/her designee, falls within the limitations in (b-g), above, the contractor shall immediately notify the Contracting Officer no later than the beginning of the next Government workday.
4. Failure of the contractor and the Contracting Officer to agree that technical direction is within the scope of the contract shall be subject to the terms of the clause entitled "Disputes."
COR/Primary Point of Contact:
TBD
2.6 Government Point of Contact:
Christina Lene Contracting Officer Email: Christina_lene@ibc.doi.gov
SECTION 3 – QUOTATION PREPARATION & SUBMISSION INSTRUCTIONS
The Department of Interior, Interior Business Center – Acquisition Service Directorate, is issuing this RFQ to solicit SDATD Tri-Credit Reporting Services. through SAM.gov for the purpose of entering into a Firm-Fixed- Price Purchase Order. This requirement is set aside for Small Business (SB).
Quotes and pricing shall be valid from the time the quote is submitted until awarded which will be no longer than the period of performance start date listed in this solicitation.
3.1 Quotation Preparation Instructions
The following information shall be submitted to be considered for award:
1. Price Quote: Contractor’s price quote shall use the attached spreadsheet and include the unit price for the items quoted, the extended total and the total Purchase Order amount.
2. Specification/Descriptions of all items (Contractor’s format).
3. Provide pricing information to all possible discounts taken into consideration. The price quote shall show the discount provided.
mailto:Christina_lene@ibc.doi.gov
Document No.
RFQ
140D0425Q0170
Services P a g e | 6
4. Shipping and/or handling charges that apply must be included in the price of the line-items.
a) Quoters shall submit a quotation containing the following information:
b) Tax Identification Number (TIN)
c) Unique Entity Identifier (UEI)
d) Complete business mailing address as it appears in the System for Award Management
(SAM) at www.sam.gov
e) Contact name, phone number, and e-mail address.
f) RFQ Number
g) Quotation Number
h) Item Numbers
i) Delivery lead times and delivery date
j) All potential offerors responding to this RFQ are required to verify 508 compliances for all IT products contained in their quote.
Offerors are cautioned that if the Government deems the terms and conditions to be unacceptable, the offeror may be found ineligible for award.
Your quote may be rejected without further consideration for failure to submit any of the information requested in this RFQ.
The potential offeror is required to be registered in the Systems for Award Management (SAM) website as of the date the quote is submitted, which can be accessed at www.sam.gov. The vendor’s SAM registration shall be in active status.
Whether your company is a current or new registrant in the SAM database, your registration must indicate that you are a provider of NAICS 561450, or a NAICS of similar business size, under the Goods– Services section of the registration to be eligible to receive a contract for this solicitation. If the prospective awardee for this request for quotes is not actively registered in the SAM database by close of solicitation, including NAICS 561450, or a NAICS of similar business size, under the Goods – Services section, the government reserves the right to proceed to award to the next otherwise successful.
System updates may lag policy updates. The System for Award Management (SAM) may continue to require entities to complete representations based on provisions that are not included in agency solicitations, including 52.223-22, Public Disclosure of Greenhouse Gas Emissions and Reduction Goals—Representation, and paragraph (t) of 52.212-3, Offeror Representations and Certifications—Commercial Products and Commercial Services. Agencies will not consider or use these representations. Entities are not required to, nor are they able to, update their entity registration to remove these representations in SAM.
All searches shall meet all required capabilities and requirements listed in Section One (1.4) of the Statement of Work (SOW) on pages nine (9) through (11) of this solicitation.
3.2 Submission of Quotations
http://www.sam.gov/ http://www.sam.gov/
Document No.
RFQ
140D0425Q0170
Services P a g e | 7
Quotations shall be submitted via email no later than the date and time specified in Section 3.4 of this RFQ. It is the quoter’s responsibility to ensure/verify that the Government receives its submission on or before this date and time. Quotations received later than this date and time will not be considered.
3.3 Submission of Questions
Questions regarding this RFQ shall be sent via email to the Contract Officer at christina_lene@ibc.doi.gov and Contract Specialist at asa_fred@ibc.doi.gov . Questions shall be submitted no later than 5:00 PM Eastern Time on April 2, 2025.
All questions will be answered via amendment after the question due date expires.
3.4 Quotation Submission Deadline
Quotations shall be submitted via email no later than the date and time specified in Section 3.4 of this RFQ. It is the quoter’s responsibility to ensure/verify that the Government receives its submission on or before this date and time. In accordance with 52.212-1(F), quotations received later than this date and time will be deemed “late”
Quotations shall be submitted no later than 5:00 PM Eastern Time on April 18, 2025.
SECTION 4 EVALUATION FACTORS FOR AWARD
The Government will evaluate the lowest price quote for technical acceptability on a Pass/Fail basis. If the lowest price quote is not acceptable, the Government will evaluate the next lowest price quote (and so forth) until a quote has been determined to be acceptable.
• Technical Acceptability: The government will evaluate the offeror’s technical information to determine if it is technically acceptable. Technically acceptable is defined as the offeror’s ability to meet all the technical requirements identified in the solicitation.
• Price: The government will evaluate the offeror’s price for award purposes by adding the extended price for all Line Items. The Government will evaluate the offer for price reasonableness.
The Government intends to select one contractor for this acquisition. However, the Government reserves the right not to make an award, depending on the quality of the quotes, prices submitted, and the availability of funds.
Rejection of Unreasonable Offers: The Government reserves the right to do price realism.
SECTION 5 - DELIVERY ORDER ADMINISTRATION
mailto:christina mailto:asa_fred@ibc.doi.gov
Document No.
RFQ
140D0425Q0170
Services P a g e | 8
All questions and concerns regarding this effort shall be directed to the Contracting Officer and Contracting Specialist identified below. The following individual will perform contract administration for this delivery order.
Contracting Officer: Christina Lene Christina_lene@ibc.doi.gov
Contract Specialist: Asa Fred asa_fred@ibc.doi.gov
SECTION 6 GENERAL TERMS AND CONDITIONS
6.1 Delivery Order Terms and Conditions
6.2 Delivery Point of Contact (POC)
The delivery POC will be identified upon award.
6.3 508 Compliance
Section 508 of the Rehabilitation Act of 1973 (found at 29 USC 794d) requires access to and use of information by individuals with disabilities. Electronic reports, video footage, and other electronic data are subject to Section 508 guidelines. All IT products available comply with the applicable accessibility standards at 36 CFR 1194, which implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at http://www.section508.gov.
Statement of Work
1.1 OVERVIEW
This is a non-personal service purchase order to provide credit reporting services to the Interior Business Center, Human Resources Directorate. The Government will not exercise any supervision or control over the contract or task order service providers performing the services herein. Such service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government as defined in this Statement of Work (SOW). The Contractor shall perform to the standards herein.
1.2 BACKGROUND
The Interior Business Center’s (IBC) Human Resources Directorate (HRD) has a continued need for credit check services to support its mission. As HRD does not possess the magnitude of manpower and specialized expertise necessary to fully accomplish its objective, this Statement of Work (SOW) outlines the tasks to be performed by the Contractor to assist HRD in meeting the Governments mission objectives.
1.3 OBJECTIVE
mailto:Christina_lene@ibc.doi.gov mailto:quinn_greene@ibc.doi.gov http://www.section508.gov/
Document No.
RFQ
140D0425Q0170
Services P a g e | 9
The Government seeks a vendor to provide a comprehensive product or service that enables HRD, Personnel Security Branch (PSB), to conduct a soft tri-merge credit check on individuals for employment purposes. This report should include name, debtors, amount of credit, amount outstanding, amount overdue, if any.
1.4 DETAILED REQUIREMENTS
The Contractor shall provide reliable and timely access to an online portal the Personnel Security Branch can securely access to pull tri-merge credit reports consolidated into an easy-to-read proprietary format.
The resulting report should include the following requirements.
Applicant Information:
• Full Names
• Aliases
• Date of Birth
• Address
• Partial Social Security Number (last 4 digits)
Credit Summary:
• Total Debtors
• Currently Satisfactory
• Currently Delinquent
• Previously Delinquent
• Collections/Charge Offs
• Indications of Late Payments (30, 60, 90 days)
Financial Summary:
• Payment Details
• Total Balances
• Past Due Amounts
• Utilization of Mortgage
• Installments
• Open Accounts
• Revolving Accounts
• Other Financial Information
• Creditors
• Opening Dates
• Months Reviewed
• Reported Date
• Date of Last Activity (DLA)
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 0
• High Credit
• Balance
• Past Due Amount
• Historical Times Past Due (30, 60, 90 days)
• Type of Account
• Terms
• Present Status
• Remarks
• Public Records
Variations:
• Personal Information Comparison
• Name
• Social Security Number
• Date of Birth
• Aliases
• Address Comparison
• Employment Comparison
• Prior Inquiries: Creditor Inquiry Type, Date, Source
Public Records and Prior Inquiries:
• Highlight accounts that are past due, overdue, in collections, or have charge-offs
• Recorded Tax Issues
• Court-Ordered judgements
• Detailed Account Information (identifies specific account numbers and creditor names, including opening and reporting dates, (and potentially creditor addresses)
• Payment History Patterns
• Total Debt Balances
• Newest and Oldest Trade Accounts
• Details of Inquiries
• Summary of Total Balances:
• Outlines Installment Plans
• Lists Revolving Credit Lines
• Lists High Balances
Additional Requirements:
• Turnaround time from the moment the report is ordered should be immediate
• Credit report must be accessible electronically
• Administrative account for PSB management to add or delete staff
• Two-Factor Authentication login required
• Soft Credit Check
• Confirmation that all three bureaus are reported and included in the single tri-merge report
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 1
Estimated checks per year: 1,500
1.5 PERIOD OF PERFORMANCE
The period of performance shall be for one (1) Base period of four (4) option years. The anticipated performance period will commence upon award of this task order/contract. In addition, FAR Clause 52.217-8, option to extend services (Nov 1999) will be included in the RFQ and resultant Contract.
The Period of Performance reads as follows:
Base Period: 06/22/25-06/21/26 Option Period I: 06/22/26-06/21/27 Option Period II: 06/22/27-06/21/28 Option Period III: 06/22/28-06/21/29 Option Period IIII: 06/22/29-06/21/30
General: This section applies to a Statement of Work The Contractor shall develop and maintain an effective Quality Control Plan (QCP) to ensure services are performed in accordance with this SOW. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor’s QCP is the means by which he/her assures that his/her work complies with the requirement of the task order. After government acceptance of the QCP, the Contractor shall receive the Contract Officer’s (CO) acceptance in writing of any proposed change to the government accepted QCP.
2.1 HOURS OF OPERATION
Work will be performed during normal business hours, Monday-Friday, excluding Federal holidays. Services will be required in support of Federal agencies on as needed basis. No holiday or overtime pay is authorized. Contractor must have sufficient personnel available to support a flexible work schedule.
2.2 GOVERNMENT HOLIDAYS
The following Government holidays are normally observed by Government personnel: New Year’s Day, Martin Luther King's Birthday, Presidential Inauguration Day (metropolitan DC area only), George Washington's Birthday, Memorial Day, Independence Day, Labor Day, Columbus Day, Veteran's Day, Thanksgiving Day, Christmas Day, and any other day designated by Federal Statute, Executive Order, and/or Presidential Proclamation. Or any other kind of administrative leave such as acts of God (i.e., hurricanes, snowstorms, tornadoes, etc.).
Presidential funerals or any other unexpected government closures.
3.1 SECTION 508 COMPLIANCE REQUIREMENTS
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 2
Any/all electronic and information technology procured throughout this effort must meet the applicable accessibility standards at 36 CFR 1194. 3 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at http://www.section508.gov.
3.2 VENDOR TRAINING and TECHNICAL SUPPORT
The Contractor shall provide reliable training, and technical support as requested through an online portal for our staff within the Personnel Security Branch. This will enable them to securely access tri-merge credit reports in a consolidated easy-to-read proprietary format. The training should include online webinars, recorded training sessions, and/or written documentation to accommodate various learning styles and schedules.
3.3 MISCELLELANIOUS
All contractor-generated technical reports, records, files, and other documentation created in the performance of this contract will be considered to be property of the Federal Government. At the end of this contract, the Government may require the contractor to return any and all documentation created in performance of this contract back to the Government of require the contractor to destroy the records.
3.4 DISCLOSURE OF INFORMATION
Information made available to the contractor by the Government for the performance or administration in this effort shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer.
The contractor agrees to assume responsibility for protecting the confidentiality of Government records, which are not public information. Each contractor or employee of the contractor to whom information may be made available or disclosed shall be notified in writing by the contractor that such information may be disclosed only for a purpose and to the extent authorized herein.
3.5 NON-PERSONAL SERVICES
As stated in the Federal Register, Volume 57, No. 190, page 45096, dated September 30, 1992, Policy Letter on Inherently Governmental Functions, no personal services shall be performed under this contract. All work requirements shall flow only from the Project Officer to the Contractor's Senior Project Manager. No Contractor employee shall be directly supervised by the Government. The applicable employee supervisor shall give all individual employee assignments, and daily work direction. If the Contractor believes any Government action or communication has been given that would create a personal services relationship between the Government and any Contractor employee, the Contractor shall promptly notify the Contracting Officer of this communication or action.
The Contractor shall not perform any inherently governmental actions under this contract. No Contractor employee shall hold him or herself out to be a Government employee, agent, or
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 3 representative. No Contractor employee shall state orally or in writing at any time that he or she is acting on behalf of the Federal Government. In all communications with third parties in connection with this contract, Contractor employees shall identify themselves as Contractor employees and specify the name of the company for which they work. In all communications with other Government contractors in connection with this contract, the Contractor employee shall state that he/she has no authority to, in any way, change the contract and that if the other contractor believes this communication to be a direction to change their contract, they should notify the Contracting Officer for that contract and not carry out the direction until a clarification has been issued by the Contracting Officer.
The Contractor shall insure that all of its employees working on this contract are informed of the substance of this article. Nothing in this article shall limit the Government's rights in any way under the other provisions of the contract, including those related to the Government's right to inspect and accept the services to be performed under this contract. The substance of this article shall be included in all subcontracts at any tier.
3.6 GFE GENERAL INFO ON CONTRACT
Contract personnel with elevated access to DOI systems and/or data must use Government Furnished Equipment (GFE) and follow applicable DOI data access requirements in accordance with the systems and/or data being accessed. (See NIST AC-20)
3.7 GFE REQUIREMENT IS FROM AC-20 NIST CONTROL
All sensitive agency information, including Personally Identifiable Information (PII), shall only be processed, housed, transmitted, or stored using DOI controlled and managed computing and network resources.
The contractor agrees that in the event of any actual breach of PII (i.e., loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic) or a reasonable belief that a breach has occurred based on facts and circumstances, it shall as soon as possible, and in no event later than twenty-four (24) hours of discovery, report the breach to the contracting officer, the Contracting Officer's Representative (COR), and the DOI Computer Incident Response Center by phone at 703-648- 5655 or email at DOICIRC@ios.doi.gov. The contractor is responsible for positively verifying that notification is received and acknowledged by at least one of the foregoing Government parties. Notwithstanding anything to the contrary, notification may be delayed to the extent that law enforcement determines that notification may delay or impede its investigation.
The Service Provider shall immediately report all incidents, whether suspected or confirmed, involving potential risks to the confidentiality, integrity, or availability of DOI's information or to the function of provided systems operated on behalf of DOI, to the DOI-CIRC, DOI Contracting Officer and DOI System Owner by phone at 703-648-5655 or email at DOICIRC@Ios.doi.gov. The Service Provider shall report computer security incidents and breaches affecting DOI data/information or to the function of provided systems in accordance with the DOI Enterprise Computer Security Incident Response Plan. The Service Provider shall
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 4 promptly coordinate with the DOI System Owner and DOI-CIRC on all related incident handling, response, containment, eradication, and recovery efforts throughout the incident lifecycle until fully resolved to the satisfaction of the DOI System Owner.
Upon becoming aware of any unlawful access to any DOI data/information stored on the Service Provider's equipment or in the Service Provider's facilities, or unauthorized access to such facilities or equipment resulting in loss, disclosure, or alteration of any DOI data/information (a "Security Incident"), the Service Provider will:
1. Immediately notify the CO and COR's via email with details of the Security Incident.
2. Investigate the Security Incident and provide DOI with detailed information about the
Security Incident.
3. Take reasonable steps to mitigate the effects and to minimize any damage resulting from the Security Incident.
All determinations related to information security incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services will be made by authorized DOI officials at DOI's discretion.
The Contractor and Contractor employees must provide full access and cooperation for all activities determined by DOI to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of information security incidents.
Incident response activities determined to be required by DOI may include but are not limited to, inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the incident and/or liability for any additional response activities.
DOI, at its sole discretion, may obtain the assistance of Federal agencies and/or third-party firms to aid in incident response activities, as needed.
The Contractor is responsible for all costs and related resource allocations required for all subsequent incident response activities determined to be required by DOI, whether incurred by DOI, agents under contract or on assignment to DOI, or by third party firms.
3.8 Data Quality and Data Transmission
The Government acknowledges that the ability of the Contractor to provide accurate information is dependent upon receipt of accurate data from the Government. The Government shall provide current and accurate data necessary for the Contractor to provide the Services. The Government agrees to provide such data to the Contractor in an acceptable format within a mutually agreeable timeframe and to promptly correct and update data. The Government further agrees to test and validate the accuracy of the data on a mutually agreeable frequency using paper-based or electronic data validation reports provided by the Contractor. The parties agree to work together
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 5 to identify and resolve all identified historical and ongoing data errors within two (2) pay periods. The Government agrees that any action required of the Contractor to correct the data for the Government may result in additional fees.
3.9 No Transfer of Intellectual Property
No transfer of intellectual property from one party to the other shall occur under this task order.
Additional Limitations of Liability. Neither party to the Agreement is liable for the other party's legal obligations. Each party to the Agreement shall be responsible for any third-party claims, actions, demands, damages, liabilities, costs, and expenses as a result of any action arising out of or relating to (i) a suit brought against the non-- responsible party relating to employment or termination of employment by the responsible party's own employees or former employees (ii) or the responsible party's own violation of laws or regulations. Nothing in the Agreement (or this Schedule) shall prohibit the non-responsible party from seeking compensation or contribution from the responsible party in the event the non-responsible party is named in any third-party claims, actions, demands, damages, liabilities, costs, and expenses brought against it. Neither the execution of this Schedule or Agreement by the Client nor any other conduct of any representative of the Client relating to this Schedule or Agreement shall be considered a waiver of governmental immunities available to the Client. This paragraph shall survive termination of this Schedule and/or the Agreement.
3.10 Controlled Unclassified Information Data Privacy and Protections
The Contractor shall be responsible for all levels of security for: I) data that is generated by the contractor on behalf of the Government, 2) Government data transmitted by the contractor, and
3) Government data otherwise stored or processed by the contractor, regardless of who owns or controls the underlying systems while that data is under the contractor's control. All Government data, including but not limited to Personal Identifiable Information (PII), Sensitive Security Information (SSI), and Sensitive but Unclassified (SBU), and/or Critical Infrastructure Information (CII), will be protected according to each Government agency's information security policies and mandates which have been provided to Contractor for review and for which Contractor has agreed in writing to comply with.
Upon Government's written request, Contractor shall destroy, purge, or otherwise render inaccessible Government's data from Contractor's production databases. Notwithstanding anything to the contrary, Contractor shall have the right to retain copies of the data for audit purposes, dispute resolution, and to fulfill Contractor's retention requirements. Contractor may also retain Government's data which is stored on encrypted backup media until such media is re-used or destroyed. Contractor shall be required to maintain the security guidelines of this agreement for the period that such data is under control of Contractor.
The contractor shall satisfy requirements to work with and safeguard Sensitive Security Information (SSI), and Personally Identifiable Information (PII). All support personnel must understand and rigorously follow all applicable Government agency's requirements, policies, and procedures for safeguarding SSI and PII for which Contractor has reviewed and have been
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 6 mutually agreed to in writing. Contractor personnel, who are specifically assigned to perform services under this agreement, may be required to complete online training for SSI, Informational Security and Privacy training, if required by the Government agency.
The Contractor, and those operating on its behalf, shall adhere to the requirements of the non-disclosure agreement unless authorized in writing by the Contracting Officer.
The Government will identify IT systems transmitting unclassified/SSI information that will require protection based on a risk assessment as applicable. If encryption is required, the following methods are acceptable for encrypting sensitive information:
• Products Advanced Encryption Standard (AES) algorithms that have been validated under FIPS 140-2
• National Security Agency (NSA) Type 2 or Type 1 encryption
• AES-256-bit encryption
The contractor shall maintain data control according to the applicable Government agency's security level of the data. Data separation will include the use of discretionary access control methods, VPN encryption methods, data aggregation controls, data tagging, media marking, backup actions, logical segregation and data disaster planning and recovery.
The contractor shall comply with all data disposition requirements in accordance with NIST and FISMA standards.
3.11 Security of Systems Handling Personally Identifiable Information and Privacy Incident Response
3.11.1 Definitions
• "Breach" (may be used interchangeably with "Privacy Incident") as used in this clause means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access to Personally Identifiable Information, in usable form whether physical or electronic.
• "Personally Identifiable Information (PII)" as used in this clause means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States.
• Examples of PII include: name, date of birth, mailing address, telephone number, Social
Security Number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), Internet protocol addresses, biometric identifiers (e.g., fingerprints), photographic facial images, or any other unique identifying number or characteristic, and any information
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 7 where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
• Sensitive Personally Identifiable Information (Sensitive PII)" as used in this clause is a subset of Personally Identifiable Information, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
• Complete social security numbers (SSN) and alien registration numbers (A- number) are considered Sensitive PII even if they are not coupled with additional PII. Additional examples include any groupings of information that contains an individual's name or other unique identifier plus one or more of the following elements:
• Driver's license number, passport number, or truncated SSN (such as last 4 digits)
• Date of birth (month, day, and year)
• Citizenship or immigration status
• Financial information such as account numbers or Electronic Funds Transfer
Information
• Medical Information
• System authentication information such as mother's maiden name, account passwords or personal identification numbers (PIN)
• Other PII may be "sensitive" depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII, but it is not sensitive.
• Sensitive PII have higher impact ratings for purposes of privacy incident handling.
3.11.2 SYSTEMS ACCESS
Work to be performed under this contract requires the handling of Sensitive PII. The contractor shall provide the Government high level information regarding its systems, when requested by the Government, as part of its responsibility to ensure compliance with security requirements and shall otherwise reasonably cooperate with the Government in assuring compliance with such requirements.
3.11.3 SYSTEMS SECURITY
In performing its duties related to management, operation, and/or access of systems containing Sensitive PII under this contract, the contractor, its employees, and subcontractors shall comply with applicable security requirements described in NIST and FIPS publication(s). Use of contractor-owned laptops or other media storage devices to process or store PII is prohibited under this contract unless the contractor meets the following requirements:
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 8
• Laptops employ encryption using a NIST Federal Information Processing Standard (FIPS) 140-2 or successor approved product
• The contractor has developed and implemented a process to ensure that security and other applications software are kept current
• Mobile computing devices utilize anti-viral software and a host-based firewall mechanism
• When no longer needed, all removable media and laptop hard drives shall be processed (i.e., sanitized, degaussed, or destroyed) in accordance with contractor security requirements
• The contractor shall maintain an accurate inventory of devices used in the performance of this contract
• Contractor employee annual training and rules of conduct/behavior shall be developed, conducted/issued, and acknowledged by employees in writing
• Training and rules of conduct shall address at minimum
• Authorized and official use
• Prohibition against use of personally owned equipment to process, access, or store
Sensitive PII
• Prohibition against access by unauthorized users and unauthorized use by authorized users; and
3.11.4 PROTECTION OF SENSITIVE PII
Upon Government’s written request, all Sensitive PII obtained under this contract will be disabled for user access from contractor-owned information technology assets until Sensitive PII is destroyed in accordance with the Contractor’s data retention requirements. Contractor may retain archival copies of Sensitive PII for audit and dispute resolution purposes and Contractor may retain copies of Sensitive PII on encrypted back-up media in which such Sensitive PII is co-resident with other employment and income data in accordance with state and/or federal retention requirements Contractor shall remain under its contractual obligation of confidentiality and security to Government during such retention and such obligations shall survive termination of the Agreement. Certification of data removal will be performed by the contractor’s Project Manager and written notification confirming certification will be delivered to the contracting officer within 15 days of destruction of Sensitive PII.
3.11.5 DATA SECURITY
Contractor shall limit access to the data covered by this clause to those employees and subcontractors who require the information in order to perform their official duties under this contract. The contractor, contractor employees, and subcontractors must physically secure Sensitive PII when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss. When Sensitive PII is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed through means that will make the Sensitive PII irretrievable.
Document No.
RFQ
140D0425Q0170
Services P a g e | 1 9
The contractor shall only use Sensitive PII obtained under this contract for purposes of the contract and shall not collect or use such information for any other purpose without the prior written approval of the contracting officer.
3.11.6 BREACH RESPONSE
The contractor agrees that in the event of any actual breach of PII (i.e., loss of control, compromise, unauthorized disclosure, access for an unauthorized purpose, or other unauthorized access, whether physical or electronic) or a reasonable belief that a breach has occurred based on facts and circumstances, it shall as soon as possible, and in no event later than twenty-four (24) hours of discovery, report the breach to the contracting officer, the Contracting Officer’s Representative (COR), and the DOI Computer Incident Response Center by phone at 703-648- 5655 or email at DOICIRC@ios.doi.gov. The contractor is responsible for positively verifying that notification is received and acknowledged by at least one of the foregoing Government parties. Notwithstanding anything to the contrary, notification may be delayed to the extent that law enforcement determines that notification may delay or impede its investigation.
3.11.7 Security Requirements to Contractors
Contractor shall provide in its agreements with subcontractors such written provisions as are sufficient to enable Contractor to comply with the provisions of this Agreement and remains fully responsible for the performance of the subcontractor as if Contractor had itself performed the Services. The terms “contract,” “contractor,” and ‘’Contracting Officer” shall be appropriately modified to preserve the Government’s rights.
3.11.8 EXPRESS WARRANTIES ONLY
Except as expressly noted in this contract, the Contractor makes no other warranties as to the service or the data, express or implied, including any implies warranties of merchantability, and/or fitness for a particular purpose even if Contractor knows of such purpose.
3.11.9 DATA QUALITY AND DATA TRANSMISSION
The Government acknowledges that the ability of the Contractor to provide accurate information is dependent upon receipt of accurate data from the Government. The Government shall provide current and accurate data necessary for the Contractor to provide the Services. The Government agrees to provide such data to the Contractor in an acceptable format within a mutually agreeable timeframe and to promptly correct and update data. The Government further agrees to test and validate the accuracy of the data on a mutually agreeable frequency using paper-based or electronic data validation reports provided by the Contractor. The parties agree to work together to identify and resolve all identified historical and ongoing data errors within two (2) pay periods. The Government agrees that any action required of the Contractor to correct the data for the Government may result in additional fees
Document No.
RFQ
140D0425Q0170
Services P a g e | 2 0
4.1 PERIODIC PROGRESS MEETINGS
The contractor agrees to attend progress meetings. The Contracting Officer or Contracting Officer’s Representative (COR), and other Government personnel, as appropriate, may meet periodically with the Contractor to review the Contractor’s performance. At these meetings, the CO will apprise the Contractor of how the government views the Contractor’s performance and the Contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.
4.2 PHASE IN/OUT PERIOD
To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the Contractor shall have personnel on board, during the 60-day phase in/ phase out periods. During the phase in period, the Contractor shall become familiar with performance requirements in order to commence full performance of services on the start date.
4.3 DELIVERABLES
The Contractor shall submit Interim and Final Deliverables concurrently to the COR once these deliverables have been accepted. The Contractor shall include the contract number (and task order number if appropriate) in the email for each deliverable. The Government may request the Contractor to include specified keywords in the subject line of emails containing deliverables.
Additionally, the Government may request the Contractor to submit Deliverables to an electronic repository as specified by the COR.
End Statement of Work
6.4 Delivery Order Clauses
6.4.1 Clauses Incorporated by Reference
FAR 52.252-2 FAR Clauses Incorporated by Reference (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address (es):
Federal Acquisition Regulation (FAR): www.acquisition/gov/far/ Department of the Interior Acquisition Regulation: https://www.acquisition.gov/diar Health and Human Services Acquisition Regulation: https://www.acquisition.gov/hhsar
Clause Title Date http://www.acquisition/gov/far/ http://www.acquisition.gov/diar https://www.acquisition.gov/hhsar
Document No.
RFQ
140D0425Q0170
Services P a g e | 2 1
FAR 52.203-17 Contractor Employee Whistleblower Rights and
Requirement to Inform Employees of Whistleblower Right
NOV 2023
FAR 52.204-13 System for Award Management Maintenance. OCT 2018 FAR 52.204-18 Commercial and Government Entity Code Maintenance AUG 2020 FAR 52.204-19 Incorporation by Reference of Representations and
Certifications
DEC 2014
FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
NOV 2021
FAR 52.212-4 Contract Terms and Conditions – Commercial Items NOV 2023 FAR 52.232-1 Payments APR 1984 FAR 52.232-18 Availability of Funds APR 1984 FAR 52.232-39 Unenforceability of Unauthorized Obligations JUN 2013 FAR 52.233-1 Disputes MAY 2014
DIAR Clauses Incorporated by Reference
DIAR Clause Title Date DIAR 1452.203-70 Restrictions on Endorsements – Department of the
Interior
JUL 1996
DIAR 1452.201-70 Authorities and delegations. SEP 2011
HHSAR Clauses Incorporated by Reference
HHSAR Clause Title Date HHSAR 352.239-74 Electronic and Information Technology Accessibility DEC 2015
Incorporated by Full Text
52.204-27 Prohibition on a ByteDance Covered Application. (Jun 2023)
Definitions. As used in this clause— Covered application means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited, or an entity owned by ByteDance Limited.
Information technology, as defined in 40 U.S.C. 11101(6)—
(1) Means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use—
(i) Of that equipment; or
(ii) Of that equipment to a significant extent in the performance of a service or the furnishing of a product.
Document No.
RFQ
140D0425Q0170
Services P a g e | 2 2
(2) Includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but
(3) Does not include any equipment acquired by a federal contractor incidental to a federal contract.
(b) Prohibition. Section 102 of Division R of the Consolidated Appropriations Act, 2023 (Pub.
L. 117-328), the No TikTok on Government Devices Act, and its implementing guidance under Office of Management and Budget (OMB) Memorandum M-23-13, dated February 27, 2023, “No TikTok on Government Devices” Implementation Guidance, collectively prohibit the presence or use of a covered application…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .