15A00026Q00000045-0002.pdf

PDF 196 KB Posted

Attached to
Albuquerque Vehicle Storage and Parking Federal contract opportunity
Solicitation number
15A00026Q00000045
Issued by
Department of Justice Bureau of Alcohol Tobacco Firearms and Explosives

About this file

This document is Amendment 0002 to a federal solicitation (15A00026Q00000045) issued by the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), a component of the Department of Justice (DOJ).

The amendment extends the solicitation closing date to May 26, 2026 at 12:00 PM Eastern Time and incorporates questions and answers. The underlying solicitation seeks commercial rent services for specialty and oversized vehicle storage and parking in Albuquerque, with a NAICS code of 812930 (Parking Lots and Garages). The contract structure includes a 12-month base period (06/01/2026–03/31/2027) and four unexercised one-year option periods extending through 03/31/2031. Award will be made on a Lowest Price Technically Acceptable (LPTA) basis, with offerors required to submit technical acceptability and pricing information in separate volumes. The technical proposal may not exceed five pages and must demonstrate compliance with the Statement of Work. Pricing must align with five contract line item numbers (CLINs) covering the base year and four option years. This is a small business set-aside with firm fixed pricing. Offerors must register in the System for Award Management (SAM) and comply with numerous FAR clauses and DOJ-specific security, privacy, and compliance requirements, including electronic invoicing through the Treasury's Invoice Processing Platform, whistleblower protections, and extensive information security controls. Questions were due May 20, 2026 at 3:00 PM ET, with quotes due May 26, 2026 at 12:00 PM ET.

View the file

Other files for this federal contract opportunity

Other files attached to Albuquerque Vehicle Storage and Parking, newest first.
File Type Posted
Questions and Answer.pdf PDF
15A00026Q00000045-0001.pdf PDF
Albuquerque FO SOW 20260515.pdf PDF
Albuquerque FO SOW.pdf PDF
15A00026Q00000045.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

15A00026Q00000045/0002 Page 1 of 28

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

1. CONTRACT ID CODE PAGE OF PAGES

1 28

2. AMENDMENT/MODIFICATION NUMBER

3. EFFECTIVE DATE 4. REQUISITION/PURCHASE REQUISITION NUMBER 5. PROJECT NUMBER (If applicable)

15A000CODE

ATF - ACQUSITIONS MANAGEMENT

DIVISION

Brandon Hodnett

99 NEW YORK AVE. NE

WASHINGTON, DC 20226

(O) 2026487612

(F) 2026489654 Brandon.Hodnett@ATF.gov

6. ISSUED BY CODE7. ADMINISTERED BY (If other than Item 6)

9A. AMENDMENT OF SOLICITATION NUMBER

15A00026Q00000045

CODE FACILITY CODE

8. NAME AND ADDRESS OF CONTRACTOR (Number, street, country, state and ZIP Code) (X)

X 9B. DATED (SEE ITEM 11)

05/14/2026

10A. MODIFICATION OF CONTRACT/ORDER

NUMBER

10B. DATED (SEE ITEM 13)

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

X XThe above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers is extended, is not extended.

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods: (a) By completing items 8 and 15, and returning __1__copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

12. ACCOUNTING AND APPROPRIATION DATA (If required)

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.

IT MODIFIES THE CONTRACT/ORDER NUMBER AS DESCRIBED IN ITEM 14.

CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT

ORDER NUMBER IN ITEM 10A.

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority)

E. IMPORTANT: Contractor is not, is required to sign this document and return _______ copies to the issuing office.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

The purpose of this modification is to extend the solicitation closing date to Tuesday, May 26, 2026 at 12pm eastern. This modification will incorporate questions and answers attachment.

THIS AMENDMENT EXTENDS THE SOLICITATION CLOSING DATE/TIME TO: 05/26/2026 - 12:00 ET US/Eastern

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER (Type or print) 16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)

Brandon C Hodnett

(Signature of person authorized to sign)

15B. CONTRACTOR/OFFEROR 15C. DATE SIGNED

By (Signature of Contracting Officer)

16B. UNITED STATES OF AMERICA 16C. DATE SIGNED

Previous edition unusable STANDARD FORM 30 (REV. 11/2016) Prescribed by GSA FAR (48 CFR) 53.243

15A00026Q00000045/0002 Page 2 of 28

Table of Contents

Section Description Page Number

Solicitation/Contract Form 1 Commodity or Services Schedule 2 Contract Clauses

52.203-17 Contractor Employee Whistleblower Rights (Nov 2023) 52.204-7 (DEV) System for Award Management-Registration (Nov 2024) (DEVIATION NOV 2025) 52.212-4 (DEV) Terms and Conditions-Commercial Products and Commercial Services (Nov

2023) (DEVIATION NOV 2025)

52.232-39 Unenforceability of Unauthorized Obligations (Jun 2013) 52.232-40 Providing Accelerated Payments to Small Business Subcontractors (Mar 2023) 52.217-8 Option to Extend Services (Nov 1999) 52.217-9 Option to Extend the Term of the Contract (Mar 2000) 52.222-90 Addressing DEI Discrimination by Federal Contractors (APR 2026) ATF-14 Electronic Invoicing & Release of Residual Funds (DECEMBER 2025) ATF-17 Notice to the Government of Delays (APRIL 2025) ATF-19 Authority to Obligate the Government (APRIL 2025) ATF-21 All Items To Become The Property Of The Government (APRIL 2025) ATF-22 Confidentiality of Information and Disclosure (APRIL 2025) ATF-50 Limitations on Subcontracting Under Small Business Set-Asides (APRIL 2025) DOJ-01 Whistleblower Information Distribution (Oct 2021) DOJ-02 Contractor Privacy Requirements (JAN 2022) DOJ-05 Security of Department Information and Systems (APR 2026) 52.212-5 Alt I Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial Products and Commercial Services (Mar 2026) - Alternate I (Feb 2000)

3 List of Attachments 4 Solicitation Provisions

15A00026Q00000045/0002 Page 3 of 28

Section 1 - Commodity or Services Schedule

Albuquerque Vehicle Storage and Parking

Firm Fixed Price

SCHEDULE OF SUPPLIES/SERVICES

CONTINUATION SHEET

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 Commercial rent for Specialty and Oversized Vehicle Storage.

PSC: X1LZ

Line Period of Performance: 06/01/2026 - 03/31/2027

Base Period

Previous :

Change: 0

Current : 12

MO $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

1001 Commercial rent for Specialty and Oversized Vehicle Storage.

PSC: X1LZ

Line Period of Performance: 04/01/2027 - 03/31/2028

Unexercised Option 1

Previous :

Change: 0

Current : 12

MO $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

2001 Commercial rent for Specialty and Oversized Vehicle Storage.

PSC: X1LZ

Line Period of Performance: 04/01/2028 - 03/31/2029

Unexercised Option 2

Previous :

Change: 0

Current : 12

MO $________ $_________________

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

3001 Commercial rent for Specialty and Oversized Vehicle Storage.

PSC: X1LZ

Line Period of Performance: 04/01/2029 - 03/31/2030

Unexercised Option 3

Previous :

MO $________ $_________________

15A00026Q00000045/0002 Page 4 of 28

Change: 0

Current : 12

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

4001 Commercial rent for Specialty and Oversized Vehicle Storage.

PSC: X1LZ

Line Period of Performance: 04/01/2030 - 03/31/2031

Unexercised Option 4

Previous :

Change: 0

Current : 12

MO $________ $_________________

Section 2 - Contract Clauses

A.1 ADDENDUM TO FAR 52.212-4, Terms and Conditions-Commercial Products and Commercial Services (Nov

2023) (DEVIATION NOV 2025)

The terms and conditions for the following clauses are hereby incorporated into this solicitation and resulting contract as an addendum to FAR clause 52.212-4.

Clauses By Reference

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov

Clause Title Fill-ins (if applicable)

52.203-17 Contractor Employee Whistleblower Rights (Nov 2023)

52.204-7 (DEV) System for Award Management-Registration (Nov 2024)

(DEVIATION NOV 2025)

52.212-4 (DEV) Terms and Conditions-Commercial Products and

Commercial Services (Nov 2023) (DEVIATION NOV

2025)

52.232-39 Unenforceability of Unauthorized Obligations (Jun 2013)

52.232-40 Providing Accelerated Payments to Small Business

Subcontractors (Mar 2023)

52.217-8 Option to Extend Services (Nov 1999)

15A00026Q00000045/0002 Page 5 of 28

Clauses By Full Text

52.217-9 Option to Extend the Term of the Contract (Mar 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 30 [insert the period of time within which the Contracting Officer may exercise the option]; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 30 days [60 days unless a different number of days is inserted] before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 66 (months) (years).

(End of clause)

52.222-90 Addressing DEI Discrimination by Federal Contractors (APR 2026)

(a) Definitions. As used in this clause— Program participation means membership or participation in, or access or admission to: training, mentoring, or leadership development programs; educational opportunities; clubs; associations; or similar opportunities that are sponsored or established by the contractor or subcontractor.

Racially discriminatory diversity, equity, and inclusion (DEI) activities means disparate treatment based on race or ethnicity in the recruitment, employment (e.g., hiring, promotions), contracting (e.g., vendor agreements), program participation, or allocation or deployment of an entity's resources.

(b) In connection with the performance of work under this contract, the Contractor agrees as follows:

(1) The Contractor will not engage in any racially discriminatory DEI activities;

(2) The Contractor will furnish all information and reports, including providing access to books, records, and accounts, as required by the Contracting Officer, for purposes of ascertaining compliance with this clause;

(3) In the event of the Contractor's or a subcontractor's noncompliance with this clause, this contract may be canceled, terminated, or suspended in whole or in part, and the Contractor or subcontractor may be declared ineligible for further Government contracts;

(4) The Contractor will report any subcontractor's known or reasonably knowable conduct that may violate this clause to the Contracting Officer and take any appropriate remedial actions directed by the Contracting Officer;

and

(5) The Contractor will inform the Contracting Officer if a subcontractor sues the Contractor and the suit puts at issue, in any way, the validity of this clause.

(6) The Contractor recognizes that compliance with the requirements of this clause are material to the Government's payment decisions for purposes of 31 U.S.C. 3729(b)(4).

(c) The Contractor must include the substance of this clause, including this paragraph (c), in subcontracts at any tier, including those for commercial products and commercial services, except those where the place of delivery or performance is outside the United States.

(End of clause)

ATF-14 Electronic Invoicing & Release of Residual Funds (DECEMBER 2025)

15A00026Q00000045/0002 Page 6 of 28

(a) The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) requires contractors to submit invoices electronically through the United States’ Department of the Treasury's Invoice Processing Platform (IPP) – www.IPP.gov. Invoicing electronically saves time, money, and physical storage space for both the Government and the contractor.

(b) After the Department of Justice/ATF enrolls the Contractor in IPP, the Contractor’s Electronic Business (EB) POC per the System for Award System (www.SAM.gov) will receive a link. The Contractor’s EB POC, hereafter Administrator, must use that link to log into IPP, using an existing or new account. The Contractor Administrator and/or the Users that person adds will gain access to IPP’s Collector module (upon login) where they can view actions, submit invoices and access payment information. For assistance with IPP, contact its Customer Support Desk via email, IPPCustomerSupport@Fiscal.Treasury.gov, or phone, 866.973.3131.

(c) Each invoice must be a proper invoice in accordance with the Federal Acquisition Regulation (FAR) subpart 32.905(b) and comply with IPP’s requirements. If contractors submit an invoice with multiple contract-line-item numbers (CLINs) or line numbers for a particular contract-/purchasing-vehicle number, the contractor must clearly identify the specific amounts and activity applicable to each line. Additionally, the contractor must clearly label the final invoice as "Final."

(d) ATF may closeout residual funds without a modification when the total value of the obligation does not exceed the simplified-acquisition threshold AND the total does not exceed $1,000.

(End of Clause)

ATF-17 Notice to the Government of Delays (APRIL 2025)

In the event the Contractor: 1) encounters difficulty in meeting performance requirements; 2) anticipates difficulty in complying with the contract-delivery schedule or completion date; or 3) has knowledge that any actual or potential situation is delaying or threatens to delay the timely performance of the contract, the Contractor shall immediately notify the Contracting Officer and the CO's Representative(s), in writing, giving pertinent details. However, this notice shall not be construed as a waiver by the Government of any required contractual-delivery schedule or date or any rights or remedies provided by law or under this contract; instead, this notice shall be information only in character.

(End of Clause)

ATF-19 Authority to Obligate the Government (APRIL 2025)

The Contracting Officer (CO) is the only individual who can legally commit or obligate the Government to the expenditure of public funds. No cost chargeable to the contract can be incurred before receipt of a fully signed and awarded contract unless specific authorization from the CO is provided.

(End of Clause)

ATF-21 All Items To Become The Property Of The Government (APRIL 2025)

Title to all source data and materials furnished by the Government, together with all related plans, designs, reports, materials, programs, and documentation submitted by the Contractor in performance of the contract and all other items pertaining to the Contractor's work and services to be performed under orders pursuant to this solicitation and contract shall become and remain the sole property of the Government upon contract completion. The Government will have the full right to use these materials and data for its purpose without further compensation or approval on the part of the Contractor. The Government shall have access to and the right to make copies of the above-mentioned items. All proprietary information, programs, etc. shall be indicated as such in the Contractor's proposal. The identification of information, programs, etc. as proprietary or confidential is subject to investigation and proof, as outlined in FAR clause 52.227-14, upon request by the Government. The Contractor is advised that information may be subject to release upon request pursuant to the Freedom of Information Act (5 U.S.C. 552).

(End of Clause)

ATF-22 Confidentiality of Information and Disclosure (APRIL 2025)

(a) The Contractor agrees, in the performance of this contract, to keep all information contained in source documents or other media furnished by the Government in the strictest confidence. The Contractor also agrees not to publish or

15A00026Q00000045/0002 Page 7 of 28 otherwise divulge such information in whole or in part, in any manner or form, nor to authorize or permit others to do so, taking such reasonable measures as are necessary to restrict access to such information while in the Contractor's possession, to those employees needing such information to perform the work provided herein, e.g., on a need-to-know basis. There shall be no dissemination or publication, except within and between the Contractor and any subcontractors, of information developed under this contract or contained in the reports to be furnished pursuant to this contract without prior written approval from the Contracting Officer (CO). No news release (including photographs and films, public announcements, denial, or confirmation of same) on any part of the subject matter of this contract or any phase of any program hereunder shall be made without the prior written approval of the CO. The Contractor is prohibited from releasing to any source, other than the sponsoring activity, any interim, draft, and final reports or information pertaining to services performed under this contract until report approval or official review has been obtained.

(b) The Contractor agrees to immediately notify in writing the CO if the Contractor determines or has reason to suspect a breach of this clause. The Contractor agrees to insert the substance of this clause in any consultant agreement or subcontract hereunder.

1. Confidential information, as used in this clause, means:

i. information or data of a personal nature;

ii. proprietary information about an individual;

iii. information or data submitted by or about an institution or organization; or

iv. information or data pertaining to a law enforcement investigation or operation.

2. In addition to the types of confidential information described in (1) above, information which requires special consideration regarding the timing of its disclosure such as draft budget and strategic plans, studies or research, audits, etc. are also considered to be confidential information.

3. The CO and the Contractor may identify elsewhere in this contract specific information and/or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential. Similarly, the CO and the Contractor may identify such confidential information from time to time during the performance of the contract. Any disagreement as to what constitutes confidential information will be settled pursuant to the Disputes clause.

4. If it is established that information to be utilized under this contract is subject to the Privacy Act, the Contractor will follow the rules and procedures of the disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

5. Confidential information, as defined above, shall not be disclosed without the prior written consent of the CO, and the individual(s), institution(s), or organization(s) affected. Confidential information, as defined in above shall not be disclosed without the prior written consent of the Bureau of Alcohol, Tobacco, Firearms & Explosives (ATF).

6. Whenever the Contractor is uncertain regarding the proper handling of material under the contract, or if the material in question is subject to the Privacy Act or is confidential information subject to the information contained in this clause, the Contractor shall obtain a written determination from the CO prior to any release, disclosure, dissemination, or publication.

ATF-50 Limitations on Subcontracting Under Small Business Set-Asides (APRIL 2025)

(a) In conjunction with the requirements of FAR 52.219-14, Limitations on Subcontracting, contractors shall certify the level of subcontracting proposed, prior to award of any portion of the contract set-aside or partially set-aside for a small business or 8(a) participant. Contractors shall also certify the level of subcontracting actually achieved prior to the CO exercising any option period.

(Offerors shall indicate "N/A" for lines that are Not Applicable.)

1. Services (except construction). The contractor's proposed percentage of the cost of contract performance incurred for personnel shall be expended for employees of concern: [% for Services or N/A] (must be at least 50% or N/A).

2. Supplies (other than procurement from a non-manufacturer of such supplies). Contractor's proposed work to be performed as a percentage of the cost of manufacturing the supplies, not including the cost of materials: [% for Supplies or N/A] (must be at least 50% or N/A).

3. General construction. Offeror's proposed work to be performed as a percentage of the cost of the contract, not including the cost of materials, with its own employees: [% for GEN Construction or N/A] (must be at least 15% or N/A).

15A00026Q00000045/0002 Page 8 of 28

4. Construction by special trade contractors. Offeror's proposed work to be performed as a percentage of the cost of the contract, not including the cost of materials, with its own employees: [% for Construction or N/A] (must be at least 25% or N/A).

DOJ-01 Whistleblower Information Distribution (Oct 2021)

Within 30 days of contract award, the contractor and its subcontractors must distribute the “Whistleblower Information for Employees of DOJ Contractors, Subcontractors, Grantees, or Sub-Grantees or Personal Services Contractors” (“Whistleblower Information”) document to their employees performing work in support of the products and services delivered under this contract (https://oig.justice.gov/sites/default/files/2020-04/NDAA-brochure.pdf). By agreeing to the terms and conditions of this contract, the prime contractor acknowledges receipt of this requirement, in accordance with 41 U.S.C. § 4712 and FAR

3.906 & 52.203-17, and commits to distribution. Within 45 days of award, the contractor must provide confirmation to the contracting officer verifying that it has distributed the whistleblower information as required.

(End of Clause)

DOJ-02 Contractor Privacy Requirements (JAN 2022)

A. Limiting Access to Privacy Act and Other Sensitive Information

(1) Privacy Act Information

In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.

(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment

Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.

(3) Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

(4) Separation Checklist for Contractor Employees

The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally

15A00026Q00000045/0002 Page 9 of 28 identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.

In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).

Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.

B. Privacy Training, Safeguarding, and Remediation

(1) Required Security and Privacy Training for Contractors

The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj.

The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.

The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.

(2) Safeguarding PII Requirements

Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.

(3) Non-Disclosure Agreement Requirement

Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:

(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and

(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.

15A00026Q00000045/0002 Page 10 of 28

The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.

(4) Prohibition on Use of PII in Vendor Billing and Administrative Records

The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.

(5) Reporting Actual or Suspected Data Breach

Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose.

The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.

(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting and Response Procedures for a Breach of Personally Identifiable Information.

(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and the Contracting Officer within one (1) hour of the initial discovery.

(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:

(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6] Date, time, and location of the incident.

(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.

(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]

(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.

(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]

(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.

(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.

(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.

(6) Victim Remediation

At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim

15A00026Q00000045/0002 Page 11 of 28 remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach.

The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.

C. Government Records Training, Ownership, and Management

(1) Records Management Training and Compliance

(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR.

This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.

(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.

(2) Records Creation, Ownership, and Disposition

(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information.

The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.

(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.

D. Data Privacy and Oversight

(1) Restrictions on Testing or Training Using Real Data Containing PII

The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.

(2) Requirements for Contractor IT Systems Hosting Government Data

15A00026Q00000045/0002 Page 12 of 28

The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.

(3) Requirement to Support Privacy Compliance

(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.

(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion.

The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.

[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).

[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.

[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.

[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”

[5] https://www.justice.gov/file/4336/download [6] As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used; extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.

[7] As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.

15A00026Q00000045/0002 Page 13 of 28

[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.

[9] As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.

[10] In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of information) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.

(End of Clause)

DOJ-05 Security of Department Information and Systems (APR 2026)

I. Applicability to Contractors and Subcontractors Section 2839.102 of the Justice Acquisition Regulation (JAR), (48 C.F.R. § 2839.102), applies to this contract.

Accordingly, all contractors are obligated to comply with all applicable DOJ security policies, directives, or guidance documents, including the security requirements in the provisions in this contract clause. This contract clause applies to all contractors and subcontractors, including cloud service providers (“CSPs”), and personnel of the contractors and subcontractors (hereinafter collectively, “Contractor”) that may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information. The security requirements set forth herein are in addition to those required by the Federal Acquisition Regulation (“FAR”), and any other applicable laws, mandates, contract clauses, DOJ policies, directives or guidance documents and Executive Orders pertaining to the development and operation of Information Systems and/or the protection of Government Information. This clause does not alter or diminish any existing rights, obligations, or liability under any other civil and/or criminal law, rule, regulation, or mandate.

II. General Definitions The following general definitions apply to this clause. Specific definitions also apply as set forth in other paragraphs.

A. Authorization to Operate (“ATO”), as defined in National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-37 Revision 2, is the official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls.

B. Cloud Computing, as defined in DOJ Order 0904 Cybersecurity Program, is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics, three service models, and four deployment models in accordance with NIST SP 800-145.

C. Covered Contract is any contract, order or other agreement under which the contractor, or a subcontractor at any tier, including a cloud service provider, may access, collect, store, process, maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ Information (as defined below) in the course of providing a product or service to the Department, with the exception of acquisitions under the micro-purchase threshold.

D. Covered Information System means any information system used for, involved with, or allowing, the processing, storing, or transmitting of DOJ Information under a Covered Contract.

E. Data means recorded information, regardless of form or the media on which it may be recorded. The term includes technical data, computer software, and personally identifiable information (PII) (defined below). The term

15A00026Q00000045/0002 Page 14 of 28 does not include information incidental to contract administration, such as financial, administrative, cost or pricing, or management information.

F. DOJ Information, as defined in DOJ Order 0904, means any Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility of the DOJ, including, without limitation, information related to DOJ programs or personnel. It includes, without limitation, Information (1) provided by or generated for the DOJ, (2) managed or acquired by the Contractor for the DOJ in connection with the performance of the contract, and/or (3) acquired to perform the contract.

G. Information, as defined in DOJ Order 0904, is any communication or representation of knowledge such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audiovisual. This includes any communication or representation of knowledge in an electronic format that allows it to be stored, retrieved, or transmitted.

H. Information System, means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502(8)).

I. Personally Identifiable Information (“PII”), as defined in the FAR 24.101, means information that can be used to distinguish or trace an individual's identity, either alone or when combined with…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .