Amendment 0001.pdf

PDF 527 KB Posted

Attached to
FCI Englewood - Upgrade Health Services Elevator Federal contract opportunity
Solicitation number
15BBNF26Q00000048
Issued by
Department of Justice Bureau of Prisons Field Acquisition Office

About this file

This is an Amendment of Solicitation (Amendment 0001) for a federal construction contract issued by the Federal Bureau of Prisons Field Acquisition Office. The solicitation number is 15BBNF26Q00000048 for the "Upgrade Health Services Elevator" project at FCI Englewood in Littleton, Colorado (Project 26Z4AL6). The amendment extends the solicitation closing date to Friday, May 8, 2026, at 12:00 PM Mountain Time, and adds three substantive items: clause DOJ-02 Contractor Privacy Requirements (JAN 2022), clause FAO-0023 Progress Payments for Construction, and incorporates photos and meeting minutes from the pre-bid conference held on April 15, 2026.

The project magnitude is between $100,000 and $250,000. Key contractual terms include a 336-calendar-day completion period with liquidated damages of $992.01 per calendar day for delays, Davis-Bacon Act wage compliance (Decision CO20260023), and a bid bond requirement of at least 20 percent of the bid price (not to exceed $3 million). Work hours within the secure facility perimeter are limited to 7:00 AM to 3:30 PM Monday through Friday, excluding weekends and federal holidays. Contractors must be registered in SAM with NAICS code 238290. The Contracting Officer's Representative (COR) is Mr. Joshua White, Engineering Technician at FCI Englewood. Offerors must submit STANDARD FORM 1442 (pages 1, 2, 4, and 36-37), a commodity/services schedule, a bid guarantee, past performance documentation (FAO-0021 Business Management Questionnaire), and acknowledge all amendments. Progress payments are made monthly based on work accomplished meeting quality standards, with contractor certification required. The facility is a secure correctional institution with strict security protocols, including security clearances for contractor personnel, restrictions on inmate contact, tool accountability requirements, and prohibitions on firearms, weapons, drugs, and alcohol on federal property.

View the file

Other files for this federal contract opportunity

Other files attached to FCI Englewood - Upgrade Health Services Elevator, newest first.
File Type Posted
Amendment 0004.pdf PDF
Amendment 0003.pdf PDF
Amendment 0002 Attachement - Questions and Answers.pdf PDF
Amendment 0002.pdf PDF
Amendment 0001 - Attachment 1 Photos.pdf PDF
Amendment 0001 - Attachment 3 Photos.pdf PDF
Amendment 0001 - Attachment 2 Photos.pdf PDF
Amendment 0001 - Attachment 4 Photos.pdf PDF
Wage Determination.pdf PDF
Bid Bond.pdf PDF
1 - Criminal History Check Form.pdf PDF
15BBNF26Q00000048.pdf PDF
1 - Instructions to Offerors.pdf PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

15BBNF26Q00000048/0001 Page 1 of 78

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

1. CONTRACT ID CODE PAGE OF PAGES

1 78

2. AMENDMENT/MODIFICATION NUMBER

3. EFFECTIVE DATE 4. REQUISITION/PURCHASE REQUISITION NUMBER

15B40326PR000180

5. PROJECT NUMBER (If applicable)

15BFAOCODE

Federal Bureau of Prisons Field Acquisition Office U.S. Armed Forces Reserve Complex 346 Marine Forces Drive Grand Prairie TX, 75051

6. ISSUED BY CODE7. ADMINISTERED BY (If other than Item 6)

9A. AMENDMENT OF SOLICITATION NUMBER

15BBNF26Q00000048

CODE FACILITY CODE

8. NAME AND ADDRESS OF CONTRACTOR (Number, street, country, state and ZIP Code) (X)

X 9B. DATED (SEE ITEM 11)

04/01/2026

10A. MODIFICATION OF CONTRACT/ORDER

NUMBER

10B. DATED (SEE ITEM 13)

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

X XThe above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers is extended, is not extended.

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods: (a) By completing items 8 and 15, and returning __1__copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

12. ACCOUNTING AND APPROPRIATION DATA (If required)

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.

IT MODIFIES THE CONTRACT/ORDER NUMBER AS DESCRIBED IN ITEM 14.

CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT

ORDER NUMBER IN ITEM 10A.

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority)

E. IMPORTANT: Contractor is not, is required to sign this document and return _______ copies to the issuing office.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

Amendment 0001 is hereby issued to incorporate the following changes:

1. Extend the solicitation opening - offers are now due on Friday, May 8th

2. To add clause DOJ-02 Contractor Privacy Requirements (JAN 2022)

3. To add clause FAO-0023 Progress Payments for Construction

4. Incorporate photos and meeting minutes from the site visit held on April 15.

THIS AMENDMENT EXTENDS THE SOLICITATION CLOSING DATE/TIME TO: 05/08/2026 - 12:00 MT US/Mountain

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER (Type or print) 16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)

Lucas Bonner Contracting Officer

(Signature of person authorized to sign)

15B. CONTRACTOR/OFFEROR 15C. DATE SIGNED

By (Signature of Contracting Officer)

16B. UNITED STATES OF AMERICA 16C. DATE SIGNED

Previous edition unusable STANDARD FORM 30 (REV. 11/2016) Prescribed by GSA FAR (48 CFR) 53.243

4/21/2026 26Z4AL6

PRE-BID CONFERENCE MEETING MINUTES

15BBNF26Q00000048 – UPGRADE HEALTH SERVICES ELEVATOR

FCI ENGLEWOOD - PROJECT 26Z4AL6

1 | P a g e

DATE: Wednesday, April 15, 2026, at 9:00 AM MDT Place: FCI Englewood, 9595 W. Quincy Ave., Littleton, CO, 80123

CONTRACTING OFFICER:

I. INTRODUCTIONS:

Round table introduction of all attendees.

II. PURPOSE OF MEETING:

Indicate the purpose of this meeting is to familiarize the contractor with the unique circumstances and requirements surrounding a correctional setting. This meeting is also to explain the solicitation, as issued, and not to furnish additional information.

State - nothing said here shall be interpreted as a change to the solicitation without the issuance of a formal amendment through Luke Bonner, Contracting Officer.

III. MINUTES:

Advised minutes will be recorded and distributed via the System for Award Management (SAM) database at www.sam.gov.

IV. SITE VISIT INFORMATION:

Walk to selected site for Upgrade Health Services Elevator immediately following the meeting.

V. TIME FRAMES AND LOCATION FOR SUBMISSION OF BIDS:

State the deadline for submission of offers for this project is Friday, April 29, 2026, by 12:00 PM MDT.

lbonner@bop.gov.

VI. GENERAL TOPICS:

The following submission/completion items will be addressed:

1. From the solicitation, each offeror SHALL complete and submit the following forms, clauses, and statements with his/her bid. Failure to do so may cause your bid to be considered as non-responsive:

• STANDARD FORM 1442 Pages 1, 2, 4, and 36-37: Please include DUNS number and Tax ID# and e-mail address where indicated in block 10 and complete blocks 14-20c. If your company has a “doing business as” name reflected in you SAM registration, include this name as well in Block 14. Ensure the address typed in block 14 matches the address in your SAM registration.

http://www.sam.gov/

2 | P a g e

• COMMODITY OR SERVICES SCHEDULE (PAGE 4): Complete the Unit Price (JB = job) and Amount blocks (these amounts will be the same). Note: The amounts listed in this section should be the same as the amount listed in block 17 of the SF-1442.

• BID GUARANTEE: See FAO-0001 Bonds. A bid bond must be submitted with your solicitation. The penal sum of the bond must be at least 20% of the bid price, not to exceed $3 million, whichever is less. A blank bid bond was included in the solicitation. The bid bond must be from a Government approved surety. A list of approved sureties can be located on the Department of Treasury, Bureau of the Fiscal Service website.

• PAST PERFORMANCE SUBMISSION: Please complete FAO-0021 Business Management Questionnaire on Pages 36-37 of the solicitation.

• REPRESENTATIONS AND CERTIFICATIONS: All contractors submitting a bid must be registered in the System for Award Management (SAM) at www.sam.gov with the North American Industry Classification Standard code (NAICS) 238290 which is applicable to this acquisition.

• AMENDMENTS: Amendments (if any) must be acknowledged and submitted with the bid by one of the methods as described in item eleven of the Standard Form 30.

2. Other general items to be addressed:

• DAVIS BACON ACT: This contract is subject to the Davis Bacon Act Wage Decision

CO20260023 is applicable for this area. All applicable workers must be paid according to the terms of the wage decision.

• MAGNITUDE: The magnitude of the project is between $100,000.00 and $250,000.00.

• LICENSING AND PERMITS: All required licensing and permits are required to be obtained by the contractor who receives contract award.

• WORK HOURS: Work hours within the secure perimeter shall be between 7:00 am and 3:30 pm

Monday through Friday excluding weekends and federal holidays.

• COR: The Contracting Officer’s Representative (COR) is Mr. Joshua White, Engineering Technician at FCI Englewood.

• PERIOD OF PERFORMANCE: The completion period is 336 calendar days.

• LIQUIDATED DAMAGES: Liquidated damages for this project are in the amount of $992.01 per calendar day of delay after scheduled completion.

• PRE-CONSTRUCTION CONFERENCE: A Pre-Construction conference is required after the contract is awarded and will be scheduled accordingly.

• PROGRESS SCHEDULE: A copy of the progress schedule is to be provided to the Contracting

3 | P a g e

Officer and Contract Monitor as soon as possible. Each time the progress schedule is changed, it must be provided to both the Contracting Officer and COR. It is suggested an updated document be provided by the Prime Contractor at the mandatory monthly progress meeting.

• PAYMENT REQUESTS: Application for payments are to be submitted on AIA G702(Continuation) or the contractors own form as long as the information is similar to the G702. Contactors can get these forms from the following website www.aiabookstore.com

• TIME EXTENSIONS: Time extensions for inclement weather will not be granted unless the weather is unusually severe and abnormal in comparison to prior years.

• QUESTIONS: Oral questions asked at Site Visit of a technical nature are not acceptable due to the possibility of misunderstanding or misinterpretation. All questions shall be sent in WORD FORMAT to LUKE BONNER, CONTRACTING OFFICER via email, LBONNER@BOP.GOV. In order to provide sufficient response time prior to the bid due date, the Government has establishing that questions be submitted no later than Friday, April 17, 2026 at 11:00 AM, MDT.

• STORAGE OF MATERIALS: Storage of materials will be coordinated with the COR.

• ACCESS TO SITE/PARKING OF VEHICLES: Parking will be provided for employee vehicles and contractor work vehicles.

• CONTRACTOR TEMPORARY OFFICE: No temporary office space will be provided.

• INSPECTIONS: "Punch List" items generated by inspections will be corrected and discrepancy items re-inspected and approved before contract closure takes place. Should any work be covered without proper notification, the contractor shall uncover that work for inspection at his own expense.

SAFETY MANAGER, R. Lee:

3. SAFETY POINTS:

• The contractor is responsible for providing required protective gear to all contractor workers, should it be required. Contractor will ensure that all workers have proper safety gear at all times.

• Contractor is responsible for the prevention of accidents on the project site and has spill kit onsite and containment procedures. OSHA requirements will be adhered to.

• The Contractor will have a Safety Representative on site at all times during the completion of this project.

• Proper storage of any chemicals in lay down yard with SDS present.

http://www.aiabookstore.com/

4 | P a g e

• The institution design consists of a multistory structure equipped with elevators and architecturally connected housing units. The building is equipped with a fire suppression sprinkler system which restricts the spread of fire and is conducive to fire containment.

• Prior to any burning, cutting, grinding, or welding inside the facility, the detail supervisor will inspect the area to determine the fire hazards, safety precautions, or special equipment required to perform the job safely.

• The detail supervisor will submit the completed a provided Hot Work Permit to the Facility Manager or designee for review. After the permit is reviewed, the Facility Manager or designee will forward the permit to the Safety Administrator or designee for approval. The permit will be valid for a single day not to exceed the approved time of work.

• Establish and maintain a "Fire Watch" in the area during at least thirty minutes following the completion of hot work operations and until the work supervisor inspects the area and is satisfied that there is no fire in the area and no residue present that could cause a fire to develop.

CAPTAIN, A. Gonzalez:

4. SECURITY

• ADVERSE WEATHER: Whenever adverse weather conditions or other institution emergency contingencies are in effect, contract workers will not be permitted passage into the secure institution. Should emergency conditions be implemented while contract workers are inside the secure perimeter, they will be required to secure their tools, remove vehicles and equipment, and leave the institution grounds until the emergency situation has been resolved.

Depending upon the nature of the emergency, this normally will not affect any construction outside of the secure perimeter. Contractor is reminded that fog days will be treated like rain days. The performance period of 336 days will allow adequate time to complete the job, and no consideration will be allowed for normal rain days and normal fog days. The normal rain, snow or fog days will be based on the average over the last ten (10) years for the local community.

• SECURITY CLEARANCES: Contract workers are subject to security investigative procedures.

Please refer to the contract for details. Please refer to Pages 8 and 9 of the solicitation.

• EMPLOYEE IDENTIFICATION: Contractor personnel working on project site must bring valid photo identification to the institution each day. The identification will be surrendered upon entry to, and returned upon exit from institution property.

• TOOL ACCOUNTABILITY: Strict accountability and control of all contractor tools and hazardous materials must be maintained at all times. All contractor tools to be used inside the secure perimeter must be inventoried and accounted for at the conclusion of the work day Contractor tools may not be stored on-site overnight. The contractor should provide for enough time at the conclusion of the work day for the return and accounting of all tools issued during the

5 | P a g e work day. Lost or missing tools must be reported to the COR the Captain immediately.

• ILLEGAL ITEMS ON FEDERAL PROPERTY: Firearms, ammunition, knives, other weapons, drugs, narcotics, and alcoholic beverages are not permitted inside/outside the secure perimeter or anywhere else on Federal property at any time. This includes the private vehicles of contract workers. Violators will be subject to criminal prosecution. All persons, vehicles, and equipment are subject to search by institution authorities at any time.

• NO CONTACT WITH INMATES: Contract workers are not to have any contact with inmates at any time. No photographs may be taken of inmates.

• CONTRACTOR EMPLOYEE WORK DRESS: Green or orange‐colored clothing is not allowed, as inmates wear these colors.

• PHOTOGRAPHS: The institution’s Facilities Department maintains a digital camera that will be utilized by FBOP staff to document the project work. The Contractor may request copies of these photos and may request that photos be taken for specific conditions. Cellular telephones equipped with photographic capabilities are prohibited on project construction site.

VII. ADDITIONAL DISCUSSION:

R. Bond and R. Thomas took photos in the absence of J. White. Captain will provide further information regarding communication via short wave radios or a dedicated landline for the construction crews.

Meeting minutes recorded by:

Gianluca Sicolo, Contract Specialist FCI Englewood

NOTICE:

MEETING MINUTES ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY. THEY ARE NOT

INTENDED TO CHANGE ANY SPECIFICATIONS, TERMS OR CONDITIONS OF THE

SOLICITATION. ANY AND ALL CHANGES TO THE SOLICITATION SHALL BE ISSUED IN

SUBSEQUENT AMENDMENTS ISSUED BY THE CONTRACTING OFFICER ON A STANDARD

FORM 30 (SF-30).

15BBNF26Q00000048 - UPGRADE HEAL TH SERVICES ELEVATOR

FCI ENGLEWOOD - PROJECT 2624AL6

Name

Wednesday, April 15, 2026 9:00 AM Sign-In Sheet

Organization f ,' y-Jf. e,,o_(A fv\o J.s LLL

Bop

Email/Phone

111Jk @fk ef evJ-trr , t-o#\..

9 2,5 -S ~ 3 - S 61 _9

61Page

01 •. n ?PS be.§-; r-s {vleeJ;" f q : 20 So,fe:l-l f"\C<-nc-.:1er ~ {ves 136 e.P

Cav,sf !MS e<bouf t,vc.lk!e Tc,.,l/,1es; J,- ];,Side

'f l\of\e # ) Poss\\,le. v~e. of. per14- U-ovSe.. pkonc.

S ;4'e, v,'s,'--t- fse_Jr'-1\.,S'

FAO-0023 Payments under Fixed-Price Construction Contracts

(a) Payment of price. The Government shall pay the Contractor the contract price as provided in this contract.

(b) Progress payments. The Government shall make progress payments monthly as the work proceeds, or at more frequent intervals as determined by the Contracting Officer, on estimates of work accomplished which meets the standards of quality established under the contract, as approved by the Contracting Officer.

(1) The Contractor’s request for progress payments shall include the following substantiation:

(i) An itemization of the amounts requested, related to the various elements of work required by the contract covered by the payment requested.

(ii) A listing of the amount included for work performed by each subcontractor under the contract.

(iii) A listing of the total amount of each subcontract under the contract.

(iv) A listing of the amounts previously paid to each such subcontractor under the contract.

(v) Additional supporting data in a form and detail required by the Contracting Officer.

(2) In the preparation of estimates, the Contracting Officer may authorize material delivered on the site and preparatory work done to be taken into consideration. Material delivered to the Contractor at locations other than the site also may be taken into consideration if-

(i) Consideration is specifically authorized by this contract; and

(ii) The Contractor furnishes satisfactory evidence that it has acquired title to such material and that the material will be used to perform this contract.

(c) Contractor certification. Along with each request for progress payments, the Contractor shall furnish the following certification, or payment shall not be made: (However, if the Contractor elects to delete paragraph (c)(4) from the certification, the certification is still acceptable.)

I hereby certify, to the best of my knowledge and belief, that-

(1) The amounts requested are only for performance in accordance with the specifications, terms, and conditions of the contract;

(2) All payments due to subcontractors and suppliers from previous payments received under the contract have been made, and timely payments will be made from the proceeds of the payment covered by this certification, in accordance with subcontract agreements and the requirements of Chapter 39 of Title 31, United States Code;

(3) This request for progress payments does not include any amounts which the prime contractor intends to withhold or retain from a subcontractor or supplier in accordance with the terms and conditions of the subcontract; and

(4) This certification is not to be construed as final acceptance of a subcontractor’s performance.

__________________________________________________ (Name) __________________________________________________ (Title) __________________________________________________ (Date)

(d) Refund of unearned amounts. If the Contractor, after making a certified request for progress payments, discovers that a portion or all of such request constitutes a payment for performance by the Contractor that fails to conform to the specifications, terms, and conditions of this contract (hereinafter referred to as the "unearned amount"), the Contractor shall-

(1) Notify the Contracting Officer of such performance deficiency; and

(2) Be obligated to pay the Government an amount (computed by the Contracting Officer in the manner provided in paragraph (j) of this clause) equal to interest on the unearned amount from the 8th day after the date of receipt of the unearned amount until-

(i) The date the Contractor notifies the Contracting Officer that the performance deficiency has been corrected; or

(ii) The date the Contractor reduces the amount of any subsequent certified request for progress payments by an amount equal to the unearned amount.

(e) Retainage. If the Contracting Officer finds that satisfactory progress was achieved during any period for which a progress payment is to be made, the Contracting Officer shall authorize payment to be made in full. However, if satisfactory progress has not been made, the Contracting Officer may retain a maximum of 10 percent of the amount of the payment until satisfactory progress is achieved. When the work is substantially complete, the Contracting Officer may retain from previously withheld funds and future progress payments that amount the Contracting Officer considers adequate for protection of the Government and shall release to the Contractor all the remaining withheld funds. Also, on completion and acceptance of each separate building, public work, or other division of the contract, for which the price is stated separately in the contract, payment shall be made for the completed work without retention of a percentage.

(f) Title, liability, and reservation of rights. All material and work covered by progress payments made shall, at the time of payment, become the sole property of the Government, but this shall not be construed as-

(1) Relieving the Contractor from the sole responsibility for all material and work upon which payments have been made or the restoration of any damaged work; or

(2) Waiving the right of the Government to require the fulfillment of all of the terms of the contract.

(g) Reimbursement for bond premiums. In making these progress payments, the Government shall, upon request, reimburse the Contractor for the amount of premiums paid for performance and payment bonds (including coinsurance and reinsurance agreements, when applicable) after the Contractor has furnished evidence of full payment to the surety. The retainage provisions in paragraph (e) of this clause shall not apply to that portion of progress payments attributable to bond premiums.

(h) Final payment. The Government shall pay the amount due the Contractor under this contract after-

(1) Completion and acceptance of all work;

(2) Presentation of a properly executed voucher; and

(3) Presentation of release of all claims against the Government arising by virtue of this contract, other than claims, in stated amounts, that the Contractor has specifically excepted from the operation of the release. A release may also be required of the assignee if the Contractor’s claim to amounts payable under this contract has been assigned under the Assignment of Claims Act of1940 ( 31 U.S.C.3727 and 41 U.S.C. 6305).

(i) Limitation because of undefinitized work. Notwithstanding any provision of this contract, progress payments shall not exceed 80 percent on work accomplished on undefinitized contract actions. A "contract action" is any action resulting in a contract, as defined in FAR subpart 2.1, including contract modifications for additional supplies or services, but not including contract modifications that are within the scope and under the terms of the contract, such as contract modifications issued pursuant to the Changes clause, or funding and other administrative changes.

(j) Interest computation on unearned amounts. In accordance with 31 U.S.C. 3903(c)(1), the amount payable under paragraph (d)(2) of this clause shall be-

(1) Computed at the rate of average bond equivalent rates of 91-day Treasury bills auctioned at the most recent auction of such bills prior to the date the Contractor receives the unearned amount; and

(2) Deducted from the next available payment to the Contractor.

http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title31-section3727&num=0&edition=prelim http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title41-section6305&num=0&edition=prelim http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title31-section3903(c)(1)&num=0&edition=prelim

DOJ-02 Contractor Privacy Requirements (JAN 2022)

A. Limiting Access to Privacy Act and Other Sensitive Information

(1) Privacy Act Information

In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984),if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974,the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System(FDsys) available at http://www.gpo.gov/fdsys/.

SORNs may be updated at any time.

(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment

Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.

(3) Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

(4) Separation Checklist for Contractor Employees

The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.

In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).

Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.

B. Privacy Training, Safeguarding, and Remediation

(1) Required Security and Privacy Training for Contractors

The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj.The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of

Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of

DOJ-OPCL-CS-0005.

The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.

(2) Safeguarding PII Requirements

Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.

(3) Non-Disclosure Agreement Requirement

Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:

(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and

(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.

The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.

(4) Prohibition on Use of PII in Vendor Billing and Administrative Records

The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.

(5) Reporting Actual or Suspected Data Breach

Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or

(2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.

(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting andResponse Procedures for a Breach of Personally Identifiable Information.

(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate;

the COR; and the Contracting Officer within one (1)hour of the initial discovery.

(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov,202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:

(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6] Date, time, and location of the incident.

(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.

(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]

(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.

(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]

(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.

(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.

(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.

(6) Victim Remediation

At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach. The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.

C. Government Records Training, Ownership, and Management

(1) Records Management Training and Compliance

(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR. This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.

(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.

(2) Records Creation, Ownership, and Disposition

(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information. The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32,the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.

(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.

D. Data Privacy and Oversight

(1) Restrictions on Testing or Training Using Real Data Containing PII

The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.

(2) Requirements for Contractor IT Systems Hosting Government Data

The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.

(3) Requirement to Support Privacy Compliance

(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCLwebsite (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.

(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion. The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB CircularA-130.

[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual orby some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).

[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.”

OMB Circular A-130, at App. II-2.

[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.

[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”

[5] https://www.justice.gov/file/4336/download

[6] As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used;

extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.

[7] As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.

[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.

[9] As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.

[10] In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of information) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.

(End of Clause)

File details come from the government source that posted it. Updated .