16-3955 bop award rfq.pdf
PDF 2 MB Posted
- Attached to
- REQUEST FOR QUOTE FOR PLAQUES AND WOOD BOXES Federal contract opportunity
- Solicitation number
- SV0235-26
About this file
This is a Request for Quotation (RFQ) issued by UNICOR Federal Prison Industries, Inc. for commercial items under Solicitation Number SVC235-26. The solicitation was issued on August 20, 2026, with an offer due date of August 24, 2026, at 12:00 PM EST. The contract is a 100% Small Business Set Aside with NAICS code 459999 (All other Miscellaneous Retailers) and a size standard of 11.5 million dollars. The contracting officer is Tiffani Balestrini, reachable at 570-547-1990. Delivery is required to UNICOR's Sign Factory in Cumberland, Maryland, with desired delivery of 14 days or sooner after purchase order issuance.
The solicitation seeks four line items of commercial products: 1,520 units of Piano Fin R-Wood Plaque (PLO0018), 970 units of Rosewood Piano Finish Box 12.25" (PLO0029), 1,590 units of Florentine Plate Gold/Black (PLO0001GLD2), and 890 units of Florentine Plaque Plate (PLO0001GLD5). All items are to be quoted in US dollars with unit pricing and extended amounts. Award evaluation will be based on ability to meet specifications (consistency with current products), delivery lead time, and price. The government anticipates a single award but reserves the right to make multiple awards for partial quantities if in the government's best interest. Payment will be made to UNICOR Federal Prison Industries' Central Accounts Payable at PO Box 11849, Lexington, Kentucky 40578-1849. The solicitation incorporates extensive DOJ security requirements, including data protection, cloud computing restrictions, LLM compliance with Unbiased AI Principles, and supply chain risk management obligations applicable to contractors and subcontractors.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Page 1 of 22ORDER NUMBER:
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
1. REQUISITION NUMBER PAGE 1 OF
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE
DATE
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME b. TELEPHONE NUMBER (No collect calls)
8. OFFER DUE DATE/
LOCAL TIME
9. ISSUED BY
13b. RATING
14. METHOD OF SOLICITATION
CODE
15. DELIVER TO 16. ADMINISTERED BY CODE
18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/
OFFEROR
CODE
FACILITY
CODE
CODE
TELEPHONE NO.
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
RFQ IFB RFP
SEE ADDENDUM
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
29. AWARD OF CONTRACT: REF. OFFER
DATED . . YOUR OFFER ON SOLICITATION
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR
30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED
31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
10. THIS ACQUISITION IS UNRESTRICTED OR
NAICS:
SIZE STANDARD:
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
SET ASIDE: % FOR:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
ARE ARE NOT ATTACHED
ARE ARE NOT ATTACHED
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
Coll. No.
8 (A)
EDWOSB
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SMALL BUSINESS
UEI
Document Number
Page 2 of 22ORDER NUMBER:
Page 3 of 22ORDER NUMBER:
Page 4 of 22ORDER NUMBER:
SECTION B
SUPPLIES OR SERVICES AND PRICES/COSTS
Item No. SUPPLIES OR SERVICE Quantity U/M UNIT PRICE AMOUNT IN US$ Delivery Date
Page 5 of 22ORDER NUMBER:
Page 6 of 22ORDER NUMBER:
Page 7 of 22ORDER NUMBER:
Page 8 of 22ORDER NUMBER:
Page 9 of 22ORDER NUMBER:
Page 10 of 22ORDER NUMBER:
Page 11 of 22ORDER NUMBER:
Page 12 of 22ORDER NUMBER:
Page 13 of 22ORDER NUMBER:
Page 14 of 22ORDER NUMBER:
Page 15 of 22ORDER NUMBER:
Page 16 of 22ORDER NUMBER:
Page 17 of 22ORDER NUMBER:
Page 18 of 22ORDER NUMBER:
Page 19 of 22ORDER NUMBER:
Page 20 of 22ORDER NUMBER:
Page 21 of 22ORDER NUMBER:
Page 22 of 22ORDER NUMBER:
Page of
ORDER NUMBER:
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
1. REQUISITION NUMBER
PAGE 1 OF
2. CONTRACT NO.
3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER
5. SOLICITATION NUMBER
6. SOLICITATION ISSUE
DATE
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
b. TELEPHONE NUMBER (No collect calls)
8. OFFER DUE DATE/
LOCAL TIME
9. ISSUED BY
13b. RATING
14. METHOD OF SOLICITATION
CODE
15. DELIVER TO
16. ADMINISTERED BY
CODE
18a. PAYMENT WILL BE MADE BY
CODE
17a. CONTRACTOR/
OFFEROR
CODE
FACILITY
CODE
CODE
TELEPHONE NO.
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
RFQ
IFB
RFP
SEE ADDENDUM
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA
26. TOTAL AWARD AMOUNT (For Govt. Use Only)
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
29. AWARD OF CONTRACT: REF. OFFER
DATED . . YOUR OFFER ON SOLICITATION
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
10. THIS ACQUISITION IS
UNRESTRICTED OR
NAICS:
SIZE STANDARD:
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
SET ASIDE:
% FOR:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
ARE
ARE NOT ATTACHED
ARE
ARE NOT ATTACHED
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA 27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA \\iaimain\apps1\Pam_Ward\Logos\Pointer.jpg Right Arrow Pointing to Call the Contact Point for this Solicitation/Contract/Order 8 (A)
EDWOSB
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
SMALL BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SMALL BUSINESS
SMALL BUSINESS
Page of
UEI
Document Number Printing C:\FORMFLOW\FORMS\SF\S1449_3.FRP BarbMWilliams
SECTION B
SUPPLIES OR SERVICES AND PRICES/COSTS
Item No. SUPPLIES OR SERVICE Quantity U/M UNIT PRICE AMOUNT IN US$ Delivery Date
| LV_TITLE: Request for Quotation |
| CurrentSheet: |
| SheetCount: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: 1600003955 |
| 1. REQUISITION NUMBER: |
| PAGE 1 OF: |
| 2. CONTRACT NUMBER: |
| 4. ORDER NUMBER: |
| 5. SOLICITATION NUMBER: SV0235-26 |
| 31b. NAME OF CONTRACTING OFFICER (Type or print): Tiffani Balestrini |
| 31b. NAME OF CONTRACTING OFFICER (Type or print): Tiffani Balestrini |
| 7. FOR SOLICITATION INFORMATION CALL: b. TELEPHONE NUMBER (No collect calls): 570-547-1990 |
| 7. FOR SOLICITATION INFORMATION CALL: b. TELEPHONE NUMBER (No collect calls): 570-547-1990 |
| 15. DELIVER TO CODE: CUM1 |
| 15. DELIVER TO CODE: CUM1 |
| % For : 100 |
| 12. DISCOUNT TERMS: |
| 13b. RATING: |
| 15. DELIVER TO: |
| 17a. CONTRACTOR/ OFFEROR CODE: 391014499 |
| 17a. CONTRACTOR/ OFFEROR CODE: 391014499 |
| 17a. CONTRACTOR/ OFFEROR CODE: 391014499 |
| 17a. CONTRACTOR/ OFFEROR: UNDETERMINED SOURCE |
NA BLANK
WASHINGTON DC 20534
| 17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER: |
| 18a. PAYMENT WILL BE MADE BY: |
| 19. ITEM NUMBER. Line 1 of 8.: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: See Section B |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 19. ITEM NUMBER. Line 2 of 8.: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 19. ITEM NUMBER. Line 3 of 8.: |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 19. ITEM NUMBER. Line 4 of 8.: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: SV0235-26 |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: SV0235-26 |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 19. ITEM NUMBER. Line 5 of 8.: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 19. ITEM NUMBER. Line 6 of 8.: |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 19. ITEM NUMBER. Line 7 of 8.: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 19. ITEM NUMBER. Line 8 of 8.: |
| 20. SCHEDULE OF SUPPLIES/ SERVICES: |
| 21. QUANTITY: |
| 22. UNIT: |
| 23. UNIT PRICE: |
| 25. ACCOUNTING AND APPROPRIATION DATA: |
| 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY |
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED. INITIALS :
| 29. AWARD OF CONTRACT: REFERENCE OFFER: |
| DATE. YOUR OFFER ON SOLICITATION |
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS.:
| 30b. NAME OF SIGNER (Type or print): |
| 30b. TITLE OF SIGNER (Type or print): |
| 10. THIS ACQUISITION IS UNRESTRICTED: 0 |
| 10. THIS ACQUISITION IS SET ASIDE:: 1 |
| 11. DELIVERY FOR FOB DESTINATION UNLESS BLOCK IS MARKED SEE SCHEDULE: X |
| 13a. THIS CONTRACT IS A RATED ORDER UNDER DPAS (15 CFR 700): 0 |
| 14. METHOD OF SOLICITATION RFQ: 1 |
| 10. THIS ACQUISITION IS NAICS:: 459999 |
| 14. METHOD OF SOLICITATION IFB: |
| 14. METHOD OF SOLICITATION RFP: 0 |
| 18a. PAYMENT WILL BE MADE BY CODE: |
| 17a. CONTRACTOR/ OFFEROR TELEPHONE NUMBER: |
| 27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA: 0 |
| 29. AWARD OF CONTRACT : |
| 27a. ARE ATTACHED: 0 |
| 29. AWARD OF CONTRACT DATE Enter 2 digit month, 2 digit day and 4 digit year.: |
| 30c. DATE SIGNED. Enter 2 digit month, 2 digit day and 4 digit year.: |
| 6. SOLICITATION ISSUE DATE. Enter 2 digit month, 2 digit day and 4 digit year.: 2026-08-20 |
| 8. OFFER DUE DATE Enter 2 digit month, 2 digit day and 4 digit year.: 2026-08-24 |
| 8. OFFER LOCAL TIME: 12:00 pm est |
| 9. ISSUED BY: CUMBERLAND SIGN |
14601 BURBRIDGE RD SE
CUMBERLAND MD 21502-8724
| 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK IS CHECKED SEE ADDENDUM: |
| 26. TOTAL AWARD AMOUNT (FOR GOVT. USE ONLY): 0.00 |
| 26. TOTAL AWARD AMOUNT (FOR GOVT. USE ONLY): 0.00 |
| 26. TOTAL AWARD AMOUNT (FOR GOVT. USE ONLY): 0.00 |
| 26. TOTAL AWARD AMOUNT (FOR GOVT. USE ONLY): 0.00 |
| 26. TOTAL AWARD AMOUNT (FOR GOVT. USE ONLY): 0.00 |
| 17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN |
OFFER :
| 31A. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) : |
| 10. THIS ACQUISITION IS SERVICE-DISABLED VETERAN-OWNED SMALL BUSINESS: 0 |
| 10. THIS ACQUISITION IS HUBZONE SMALL BUSINESS: 0 |
| 27a. ARE ATTACHED: |
| 6. SOLICITATION ISSUE DATE. Enter 2 digit month, 2 digit day and 4 digit year.: 2026-08-20 |
| 10. THIS ACQUISITION IS SERVICE-DISABLED VETERAN-OWNED SMALL BUSINESS: 0 |
| 10. THIS ACQUISITION IS HUBZONE SMALL BUSINESS: 1 |
| 10. THIS ACQUISITION IS HUBZONE SMALL BUSINESS: 0 |
| 10. THIS ACQUISITION IS HUBZONE SMALL BUSINESS: 0 |
| 23. UNIT PRICE: |
| 23. UNIT PRICE: |
| 23. UNIT PRICE: |
| 23. UNIT PRICE: |
| 23. UNIT PRICE: |
| 23. UNIT PRICE: |
| 23. UNIT PRICE: |
| 23. UNIT PRICE: |
| 27a. ARE ATTACHED: 0 |
| 10. THIS ACQUISITION IS NAICS:: 12 M Ann Receip |
| 17a. CONTRACTOR/ OFFEROR TELEPHONE NUMBER: |
| LV_TERMS_OF_DELIV: Terms: |
| INCO1: |
| INCO2: |
| LV_TARGET_VALUE_CHAR: |
| TDLINE: #PNA912-9"X12" PIANO FIN. R.WOOD PLAQUE |
| TDLINE: Vendor: # 620482752 -JDS Industries |
| TDLINE: #GBX03,ROSEWOOD-PIANO-FINISH-BOX-12.25" |
| TDLINE: #FL3-710-7"X10"-FLORENTINE-PLATE-GLD/BLK |
| TDLINE: Vendor: # 620482752 |
| TDLINE: FL3-68;6"X8"-FLORENTINE-PLAQUE-PLATE |
| TDLINE: TERMS OF DELIVERY ARE F.O.B. DESTINATION TO: |
| TDLINE: UNICOR, Federal Prison Industries, Inc. |
| TDLINE: UNICOR Sign Factory |
| TDLINE: 14601 Burbridge Rd. S.E. |
| TDLINE: Cumberland, MD 21504 |
| TDLINE: Request for Quote is being issued as a Firm Fixed Price, Definite |
| TDLINE: Quantity/Definite Delivery Quote for Commercial Items. |
| TDLINE: This RFQ is being issued as a 100% Small Business Set Aside. |
| TDLINE: NAICS code is 459999 All other Misc. Retailers. |
| TDLINE: Size Standard is 11.5M |
| TDLINE: It is anticipated this will be a single award, however the Government |
| TDLINE: reserves the right to make multiple award if it is in the best interest |
| TDLINE: of the Government. |
| TDLINE: For a list, description and total estimated quantities of all items, |
| TDLINE: refer to Section B. |
| TDLINE: UNICOR's desired delivery is 14 days or sooner after issuance of |
| TDLINE: purchase order. Please state your lead time for delivery to Cumberland |
| TDLINE: MD. If you can provide less than the requested quantities please |
| TDLINE: provide the quantity you are able to provide immediately and the lead |
| TDLINE: time on the balance of the requested amount. |
| TDLINE: All offers need to provide the following information to be considered |
| TDLINE: for award: |
| TDLINE: 1. Active Registration on sam.gov |
| TDLINE: SAM UNIQUE ENTITY NUMBER:____ _______________________ |
| TDLINE: 2. Company information: |
| TDLINE: VENDOR'S POINT OF CONTACT: __ _____________________ |
| TDLINE: VENDOR'S TELEPHONE & FAX NUMBER: _________________ |
| TDLINE: VENDOR'S EMAIL ADDRESS: __ _________ |
| TDLINE: 3.,,VENDOR'S BUSINESS SIZE (i.e. SMALL, LARGE, ETC.): __ _____ |
| TDLINE: 4.,,Country of Origin of products offered:________________ |
| TDLINE: 5.,,Pricing on all items |
| TDLINE: 6.,,Picture of product offered to ensure consistency with current |
| TDLINE: products used by UNICOR, if different than requested part numbers. |
| TDLINE: Closing date and time is Monday August 24, 2026 at 12:00 noon EST. |
| TDLINE: PART I: INFORMATION |
| TDLINE: This is a contract for commercial items prepared in accordance with the |
| TDLINE: format in FAR Part The RFQ number is SVC235-26. |
| TDLINE: NOTICE TO GOVERNMENT WHEN CONTRACTOR(S) DELAYS: |
| TDLINE: In the event the contractor(s) encounter difficulty in meeting |
| TDLINE: performance requirements, or when there is an anticipated difficulty in |
| TDLINE: complying with the delivery terms or completion dates, or whenever the |
| TDLINE: contractor has knowledge that any actual or potential situation is |
| TDLINE: delaying or threatens to delay the timely delivery/performance of this |
| TDLINE: contract, the contractor must immediately notify the Field |
| TDLINE: Administrative Contracting Officers at UNICOR (Cumberland) or in writing |
| TDLINE: giving pertinent details. This information will not be construed as a |
| TDLINE: waiver by the Government of the required delivery schedule, or the |
| TDLINE: Governments rights to impose consideration against delinquencies or |
| TDLINE: other remedies provided by this contract. |
| TDLINE: Future requirements for these or similar items from this or other UNICOR |
| TDLINE: factories may be added to the resulting contract if considered to fall |
| TDLINE: within the scope of work and the price is determined to be fair and |
| TDLINE: reasonable. |
| TDLINE: INVOICES ARE TO BE MAILED TO: |
| TDLINE: UNICOR, Federal Prison Industries |
| TDLINE: Central Accounts Payable |
| TDLINE: P.O. Box 11849 |
| TDLINE: Lexington, KY 40578-1849 |
| TDLINE: ATTN: Chief of Vendor Services |
| TDLINE: PH: 1-800-827-3168 |
| TDLINE: Or Preferred method is Email - |
| TDLINE: INVOICES ARE TO BE EMAILED TO: |
| TDLINE: Accounts.payable@usdoj.gov |
| TDLINE: Award Evaluation Criteria: |
| TDLINE: Award will be based on the following criteria: |
| TDLINE: 1.,,Ability to meet specification (based on consistency with products |
| TDLINE: currently in use by UNICOR) |
| TDLINE: 2.,,Delivery Lead Time |
| TDLINE: 3. ,,Price |
| TDLINE: Award (single or multiple for partial quantities) will be made by best |
| TDLINE: value determination based on the criteria listed above. |
| TDLINE: #PNA912-9"X12" PIANO FIN. R.WOOD PLAQUE |
| TDLINE: Vendor: # 620482752 -JDS Industries |
| TDLINE: #GBX03,ROSEWOOD-PIANO-FINISH-BOX-12.25" |
| TDLINE: #FL3-710-7"X10"-FLORENTINE-PLATE-GLD/BLK |
| TDLINE: Vendor: # 620482752 |
| TDLINE: FL3-68;6"X8"-FLORENTINE-PLAQUE-PLATE |
| TDLINE: Provision: |
| TDLINE: 52.212-1,,INSTRUCTIONS TO OFFERORS,, |
| TDLINE: 52.212-2,,EVALUATION,, |
| TDLINE: 52.203-18,,Prohibition on Contracting with Entities that |
| TDLINE: Require Certain Internal Confidentiality |
| TDLINE: Agreements or Statements-Representation,, |
| TDLINE: 52.204-7 ,,System for Award Management—Registration,, |
| TDLINE: 52.222-18,,Certification Regarding Knowledge of Child Labor |
| TDLINE: for Listed End Products,, |
| TDLINE: 52.225-2,,Buy American Certificate,, |
| TDLINE: 52.240-90,,Security Prohibitions and Exclusions |
| TDLINE: Representations and Certifications,, |
| TDLINE: Clauses |
| TDLINE: 52.212-4,,Terms and Conditions - Commercial Products,, |
| TDLINE: 52.203-17,,Contractor Employee Whistleblower Rights,, |
| TDLINE: 52.203-19,,Prohibition on Requiring Certain Internal |
| TDLINE: Confidentiality Agreements or Statements,, |
| TDLINE: 52.209-6,,Protecting the Government’s Interest When |
| TDLINE: Subcontracting with Contractors Debarred<(>,<)> |
| TDLINE: Suspended, or Proposed for Debarment,, |
| TDLINE: 52.209-10,,Prohibition on Contracting with Inverted |
| TDLINE: Domestic Corporations,, |
| TDLINE: 52.219-6,,Notice of total Small Business Set Aside,, |
| TDLINE: 52.219-33,,Nonmanufacturers rule,, |
| TDLINE: 52.222-3,,Convict Labor,, |
| TDLINE: 52.222-19,,Child labor-cooperation with authorities and |
| TDLINE: Remedies,, |
| TDLINE: 52.222-36,,Equal Opportunity for Workers with Disabilities,, |
| TDLINE: 52.222-50,,Combating Trafficking in Persons,, |
| TDLINE: 52.222-54,,Employement Eligibiltiy Verification,, |
| TDLINE: 52.222-90,,Addressing DEI Discrimiation by Federal |
| TDLINE: Contractors,, |
| TDLINE: 52.225-1,,Buy American-Supplies,, |
| TDLINE: 52.225-1 WITH ALT 1,,BUY AMERICAN SUPPLIES WITH ALTERNATE 1,, |
| TDLINE: 52.225-3,,Buy American-Free Trade Agreements-Israeli |
| TDLINE: Trade Act.,, |
| TDLINE: 52.226-8,, Encouraging Contractor Policies to Ban Text Messaging While |
| TDLINE: Driving.,, |
| TDLINE: 52.232-40,,Providing Accelerated Payments to Small |
| TDLINE: Business Subcontractors.,, |
| TDLINE: 52.233-4,,Applicable Law for Breach of Contract Claim.,, |
| TDLINE: 52.240-91,,Security Prohibitions and Exclusions.,, |
| TDLINE: 52.244-6,,Subcontracts for Commercial Products and |
| TDLINE: Commercial Services.,, |
| TDLINE: DOJ-05 Security of Department Information and Systems (OCT 2023) |
| TDLINE: Applicability to Contractors and Subcontractors Section 2839.102 of the |
| TDLINE: Justice Acquisition Regulation (JAR), (48 C.F.R. § 2839.102), applies to |
| TDLINE: this contract. Accordingly, all contractors are obligated to comply with |
| TDLINE: all applicable DOJ security policies, directives, or guidance documents, |
| TDLINE: including the security requirements in the provisions in this contract |
| TDLINE: clause. This contract clause applies to all contractors and |
| TDLINE: subcontractors, including cloud service providers (“CSPs”), and |
| TDLINE: personnel of the contractors and subcontractors (hereinafter |
| TDLINE: collectively, “Contractor”) that may access, collect, store, process, |
| TDLINE: maintain, use, share, retrieve, disseminate, transmit, or dispose of DOJ |
| TDLINE: Information. The security requirements set forth herein are in addition |
| TDLINE: to those required by the Federal Acquisition Regulation (“FAR”), and any |
| TDLINE: other applicable laws, mandates, contract clauses, DOJ policies, |
| TDLINE: directives or guidance documents and Executive Orders pertaining to the |
| TDLINE: development and operation of Information Systems and/or the protection |
| TDLINE: of Government Information. This clause does not alter or diminish any |
| TDLINE: existing rights, obligations, or liability under any other civil and/or |
| TDLINE: criminal law, rule, regulation, or mandate. II. General Definitions The |
| TDLINE: following general definitions apply to this clause. Specific definitions |
| TDLINE: also apply as set forth in other paragraphs. A. Authorization to Operate |
| TDLINE: (“ATO”), as defined in National Institute of Standards and Technology |
| TDLINE: (“NIST”) Special Publication (“SP”) 800-37 Revision 2, is the official |
| TDLINE: management decision given by a senior Federal official or officials to |
| TDLINE: authorize operation of an information system and to explicitly accept |
| TDLINE: the risk to agency operations (including mission, functions, image, or |
| TDLINE: reputation), agency assets, individuals, other organizations, and the |
| TDLINE: Nation based on the implementation of an agreed-upon set of security and |
| TDLINE: privacy controls. B. Cloud Computing, as defined in DOJ Order 0904 |
| TDLINE: Cybersecurity Program, is a model for enabling ubiquitous, convenient, |
| TDLINE: on-demand network access to a shared pool of configurable computing |
| TDLINE: resources (e.g., networks, servers, storage, applications, and services) |
| TDLINE: that can be rapidly provisioned and released with minimal management |
| TDLINE: effort or service provider interaction. This cloud model is composed of |
| TDLINE: five essential characteristics, three service models, and four |
| TDLINE: deployment models in accordance with NIST SP 800-145. U.S. Department of |
| TDLINE: Justice Departmental Provisions and Clauses C. Covered Contract is any |
| TDLINE: contract, order or other agreement under which the contractor, or a |
| TDLINE: subcontractor at any tier, including a cloud service provider, may |
| TDLINE: access, collect, store, process, maintain, use, share, retrieve, |
| TDLINE: disseminate, transmit, or dispose of DOJ Information (as defined below) |
| TDLINE: in the course of providing a product or service to the Department, with |
| TDLINE: the exception of acquisitions under the micro-purchase threshold. D. |
| TDLINE: Covered Information System means any information system used for, |
| TDLINE: involved with, or allowing, the processing, storing, or transmitting of |
| TDLINE: DOJ Information under a Covered Contract. E. Data means recorded |
| TDLINE: information, regardless of form or the media on which it may be |
| TDLINE: recorded. The term includes technical data, computer software, and |
| TDLINE: personally identifiable information (PII) (defined below). The term does |
| TDLINE: not include information incidental to contract administration, such as |
| TDLINE: financial, administrative, cost or pricing, or management information. |
| TDLINE: F. DOJ Information, as defined in DOJ Order 0904, means any Information |
| TDLINE: that is owned, produced, controlled, protected by, or otherwise within |
| TDLINE: the custody or responsibility of the DOJ, including, without limitation, |
| TDLINE: information related to DOJ programs or personnel. It includes, without |
| TDLINE: limitation, Information (1) provided by or generated for the DOJ, (2) |
| TDLINE: managed or acquired by the Contractor for the DOJ in connection with the |
| TDLINE: performance of the contract, and/or (3) acquired to perform the |
| TDLINE: contract. G. Information, as defined in DOJ Order 0904, is any |
| TDLINE: communication or representation of knowledge such as facts, data, or |
| TDLINE: opinions, in any form or medium, including textual, numerical, graphic, |
| TDLINE: cartographic, narrative, or audiovisual. This includes any communication |
| TDLINE: or representation of knowledge in an electronic format that allows it to |
| TDLINE: be stored, retrieved, or transmitted. H. Information System, means a |
| TDLINE: discrete set of information resources organized for the collection, |
| TDLINE: processing, maintenance, use, sharing, dissemination, or disposition of |
| TDLINE: information (44 U.S.C. 3502(8)). I. Personally Identifiable Information |
| TDLINE: (“PII”), as defined in the FAR 24.101, means information that can be |
| TDLINE: used to distinguish or trace an individual's identity, either alone or |
| TDLINE: when combined with other information that is linked or linkable to a |
| TDLINE: specific individual. It includes but is not limited to common data |
| TDLINE: elements such as names, addresses, dates of birth, and places of |
| TDLINE: employment, to identity documents, Social Security numbers or other |
| TDLINE: government-issued identifiers, precise location information, medical |
| TDLINE: history, and biometric records. This definition covers all PII that is |
| TDLINE: created by or becomes available to the contractor, including its |
| TDLINE: employees, subcontractors, or affiliates, as a result of performing |
| TDLINE: under this contract. PII, as supplementally defined in DOJ Order 0904, |
| TDLINE: also includes information about an individual maintained by an agency, |
| TDLINE: including, but not limited to, information related to education, |
| TDLINE: financial transactions, medical history, and criminal or employment |
| TDLINE: history and information, which can be used to distinguish or trace an |
| TDLINE: individual’s identity. U.S. Department of Justice Departmental |
| TDLINE: Provisions and Clauses J. Private Cloud, as defined in NIST SP 800-145, |
| TDLINE: is the deployment model for cloud infrastructure provisioned for |
| TDLINE: exclusive use by a single organization comprising multiple consumers |
| TDLINE: (e.g., business units). It may be owned, managed, and operated by the |
| TDLINE: organization, a third party, or some combination of them, and it may |
| TDLINE: exist on or off premises. K. Security Breach means any security incident |
| TDLINE: (as defined below) that directly relates to the loss of control, |
| TDLINE: compromise, exfiltration, manipulation, unauthorized disclosure, |
| TDLINE: unauthorized acquisition, unauthorized exposure or unauthorized access |
| TDLINE: or any similar occurrence of any Covered Information System or any DOJ |
| TDLINE: Information or any PII accessed by, retrievable from, processed by, |
| TDLINE: stored on, or transmitted within, to or from any such system. This |
| TDLINE: includes incidents where (1) a person other than an authorized user |
| TDLINE: accesses or potentially accesses PII or DOJ Information or (2) an |
| TDLINE: authorized user accesses or potentially accesses PII or DOJ Information |
| TDLINE: for an unauthorized purpose. a. Potential Security Breach (hereinafter, |
| TDLINE: “Potential Breach”) means any suspected, but unconfirmed security breach |
| TDLINE: (as defined above). b. Confirmed Security Breach (hereinafter, |
| TDLINE: “Confirmed Breach”) means any confirmed security breach (as defined |
| TDLINE: above). L. Security Incident means any occurrence that (1) may actually |
| TDLINE: or imminently jeopardize, without lawful authority, the availability, |
| TDLINE: integrity, authentication, confidentiality, or nonrepudiation of DOJ |
| TDLINE: Information or a Covered Information System; or (2) may constitute a |
| TDLINE: violation or imminent threat of violation of law, security policies, |
| TDLINE: security procedures, or acceptable use policies. a. Potential Security |
| TDLINE: Incident means any suspected, but unconfirmed security incident (as |
| TDLINE: defined above). b. Confirmed Security Incident means any confirmed |
| TDLINE: security incident (as defined above). M. Vulnerability, as defined in |
| TDLINE: DOJ Vulnerability Management Plan, and the OCIO Information Security |
| TDLINE: Management Procedure, means a weakness or flaw discovered in the design |
| TDLINE: of a system that, when exploited, may result in a loss of |
| TDLINE: confidentially, integrity, or availability of DOJ Information or an |
| TDLINE: Information System. III. Confidentiality and Non-Disclosure of DOJ |
| TDLINE: Information A. Preliminary and final contract deliverables and all |
| TDLINE: associated working papers and material generated by the Contractor |
| TDLINE: developed using DOJ Information, product, source code, and/or methods of |
| TDLINE: operations, are the property of the U.S. Government and must be |
| TDLINE: submitted to the Contracting Officer (“CO”) or the CO’s Representative |
| TDLINE: (“COR”) at the conclusion of the contract. The U.S. Government has |
| TDLINE: unlimited data rights to all such deliverables and associated working |
| TDLINE: papers and materials in accordance with FAR 52.227-14 (Rights in |
| TDLINE: Data-General). The Contractor will define a method of monitoring the |
| TDLINE: development activity to include any activity associated with DOJ |
| TDLINE: Information, product, source code, and methods of operations. The data |
| TDLINE: rights and development details shall be defined within the Contract. |
| TDLINE: U.S. Department of Justice Departmental Provisions and Clauses If the |
| TDLINE: Contractor intends to utilize its existing data, for which it has a |
| TDLINE: patent or copyright, to develop a contract deliverable, it is incumbent |
| TDLINE: upon the Contractor to negotiate with the CO the proper FAR Part 27 |
| TDLINE: clauses in the contract to protect its existing data. B. Pursuant to FAR |
| TDLINE: 52.227-14(d)(2), all documents and data produced in the performance of |
| TDLINE: this contract containing DOJ Information, product code, source code, |
| TDLINE: and/or methods of operations are the property of the U.S. Government |
| TDLINE: and, without the prior written permission of the CO, the Contractor |
| TDLINE: shall neither reproduce nor release such information to any third-party |
| TDLINE: at any time, including during performance or following expiration and/or |
| TDLINE: termination of the contract. C. Any DOJ Information made available to |
| TDLINE: the Contractor under this contract shall be used only for the purpose of |
| TDLINE: performance of this contract and shall not be divulged or made known in |
| TDLINE: any manner to any persons except as may be necessary in the performance |
| TDLINE: of this contract. In performance of this contract, the Contractor |
| TDLINE: assumes responsibility for the protection of the confidentiality of all |
| TDLINE: DOJ Information processed, stored, or transmitted by the Contractor. The |
| TDLINE: Contractor shall comply with information security responsibilities and |
| TDLINE: duties throughout the contract and after expiration/termination as |
| TDLINE: appropriate per contract close-out activities. When requested by the CO |
| TDLINE: (typically no more than annually), the Contractor shall provide a report |
| TDLINE: to the CO identifying, to the best of the Contractor’s knowledge and |
| TDLINE: belief, the type, amount, and level of sensitivity of the DOJ |
| TDLINE: Information processed, stored, or transmitted under the Contract, |
| TDLINE: including an estimate of the number of individuals for whom PII has been |
| TDLINE: processed, stored or transmitted under the Contract and whether such |
| TDLINE: information includes social security numbers (in whole or in part). IV. |
| TDLINE: Compliance with Information Technology Security Policies, Procedures and |
| TDLINE: Requirements A. For all Covered Information Systems, in addition to any |
| TDLINE: other applicable requirements, as set forth in Part I, the Contractor |
| TDLINE: shall comply with the security requirements of the Federal Information |
| TDLINE: Security Modernization Act of 2014 (“FISMA”), Privacy Act of 1974, E |
| TDLINE: Government Act of 2002, National Institute of Standards and Technology |
| TDLINE: (“NIST”) Special Publications (“SP”), including NIST SP 800-37, 800-53, |
| TDLINE: and 800-60 Volumes I and II, Federal Information Processing Standards |
| TDLINE: (“FIPS”) Publications 140-2, 199, and 200, Federal Risk and |
| TDLINE: Authorization Management Program (“FedRAMP”), DOJ IT Security Standards |
| TDLINE: as amended, and OMB Memoranda relating to the security of information |
| TDLINE: and/or Federal Information Systems. B. In addition, for all Covered |
| TDLINE: Information Systems, the Contractor shall comply with the following |
| TDLINE: requirements, which are listed here only to highlight certain specific |
| TDLINE: applicable requirements from one of the sources identified in the first |
| TDLINE: paragraph of this Section. This is not an exhaustive list of all such |
| TDLINE: requirements with which the Contractor is obligated to comply, and the |
| TDLINE: omission of a requirement from this list should not be construed as |
| TDLINE: negating the materiality of that requirement. These requirements and |
| TDLINE: those in the authorities in the prior paragraph should be read together. |
| TDLINE: 1. Limiting access to DOJ Information and Covered Information Systems to |
| TDLINE: authorized users and to transactions and functions that authorized users |
| TDLINE: are permitted to exercise. U.S. Department of Justice Departmental |
| TDLINE: Provisions and Clauses 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. Providing |
| TDLINE: security awareness training at least annually to all Contractor |
| TDLINE: employees and contractors involved with the Covered Contract. Such |
| TDLINE: training shall include, but not be limited to, recognizing and reporting |
| TDLINE: potential indicators of insider threats to users and managers of DOJ |
| TDLINE: Information and Covered Information Systems. Creating, protecting, and |
| TDLINE: retaining, in accordance with applicable requirements but in any event |
| TDLINE: at least until the expiration of the contract, Covered Information |
| TDLINE: System audit records, reports, and supporting documentation to enable |
| TDLINE: reviewing, monitoring, analysis, investigation, reconstruction, and |
| TDLINE: reporting of unlawful, unauthorized, or inappropriate activity related |
| TDLINE: to such Covered Information Systems and/or DOJ Information. Maintaining |
| TDLINE: authorizations to operate any Covered Information System. Performing |
| TDLINE: continuous monitoring on all Covered Information Systems, to include but |
| TDLINE: not be limited to, collecting, reviewing, and analyzing appropriate logs |
| TDLINE: and timely investigating security alerts and potential security |
| TDLINE: incidents. Establishing and maintaining baseline configurations and |
| TDLINE: current inventories of Covered Information Systems, including hardware, |
| TDLINE: software, firmware, and documentation, throughout the Information System |
| TDLINE: Development Lifecycle, and establishing and enforcing security |
| TDLINE: configuration settings for IT products employed in Covered Information |
| TDLINE: Systems. Ensuring appropriate contingency planning has been performed, |
| TDLINE: including DOJ Information and Covered Information System backups. |
| TDLINE: Identifying Covered Information System users, processes acting on behalf |
| TDLINE: of users, or devices, and authenticating and verifying the identities of |
| TDLINE: such users, processes, or devices, using multifactor authentication or |
| TDLINE: HSPD-12 compliant authentication methods as defined by NIST 800-63-3, |
| TDLINE: Digital Identity Guidelines or current revision. Establishing and |
| TDLINE: maintaining an operational incident handling capability for Covered |
| TDLINE: Information Systems that includes adequate and timely development, |
| TDLINE: logging, detection, analysis, containment, recovery, and user response |
| TDLINE: activities, and tracking, documenting, and timely reporting incidents to |
| TDLINE: appropriate officials and authorities within the Contractor’s |
| TDLINE: organization and the DOJ. Performing periodic and timely maintenance on |
| TDLINE: Covered Information Systems, and providing effective controls on tools, |
| TDLINE: techniques, mechanisms, and personnel used to conduct such maintenance. |
| TDLINE: Protecting Covered Information System media containing DOJ Information, |
| TDLINE: including paper, digital and electronic media, and DOJ assets under |
| TDLINE: Contractor control; protecting them from environmental impacts, access, |
| TDLINE: and equipment positioning requirements defined; limiting access to DOJ |
| TDLINE: Information to authorized users; and sanitizing or destroying Covered |
| TDLINE: Information System media containing DOJ Information before disposal, |
| TDLINE: release or reuse of such media. Limiting physical access to Covered |
| TDLINE: Information Systems, equipment, and physical facilities housing such |
| TDLINE: Covered Information Systems to authorized personnel according to DOJ 03. |
| TDLINE: U.S. Department of Justice Departmental Provisions and Clauses 13. 14. |
| TDLINE: 15. 16. 17. 18. 19. 20. 21. 22. 23. Screening individuals prior to |
| TDLINE: authorizing access to Covered Information Systems to ensure compliance |
| TDLINE: with DOJ Security standards including personnel background checks. |
| TDLINE: Continuously assessing the risk to DOJ Information in Covered |
| TDLINE: Information Systems, including scanning and remediating vulnerabilities, |
| TDLINE: or implementing appropriate mitigation in accordance with DOJ policy, |
| TDLINE: and ensuring the timely removal of assets no longer supported by the |
| TDLINE: Contractor. Continuously monitoring the application of security controls |
| TDLINE: of Covered Information Systems, assessing the efficacy of such controls, |
| TDLINE: and developing and implementing plans of action designed to correct |
| TDLINE: deficiencies and eliminate or reduce vulnerabilities in such Covered |
| TDLINE: Information Systems. Monitoring, controlling, and protecting information |
| TDLINE: transmitted or received by Covered Information Systems at the external |
| TDLINE: boundaries and key internal boundaries of such Covered Information |
| TDLINE: Systems, and employing architectural designs, software development |
| TDLINE: techniques, and systems engineering principles that promote effective |
| TDLINE: security. Identifying, reporting, and correcting Covered Information |
| TDLINE: System security flaws in a timely manner, providing protection from |
| TDLINE: malicious code at appropriate locations, monitoring security alerts and |
| TDLINE: advisories and taking appropriate and timely action in response. |
| TDLINE: Ensuring return of Government Furnished Equipment (“GFE”) and/or PIV |
| TDLINE: card assets within 10 business days of notification for end of use |
| TDLINE: (contract end, staff change, etc.). Complying with rights in data (FAR |
| TDLINE: 52.227-14) as to the development, management, and protection of DOJ |
| TDLINE: Information. Reporting on risks or known issues impacting DOJ Services |
| TDLINE: (staffing, hardware, process, changes, etc.) through the Contractor’s CO |
| TDLINE: or COR, DOJ Service Owner (“SO”), and Government Technical Manager |
| TDLINE: (“GTM”) including risk mitigation activities. Reporting through the |
| TDLINE: Contractor’s CO or COR on any projected or planned changes in corporate |
| TDLINE: ownership, covered information system design, and/or any technical |
| TDLINE: changes that could impact the confidentiality, integrity or availability |
| TDLINE: of DOJ Information, data, or systems. Changes to system design must be |
| TDLINE: updated through the authorization process per NIST SP 800-37 Revision 2, |
| TDLINE: Step 6 (‘Continuous Monitoring”) or current NIST revision. When, as part |
| TDLINE: of operating within the DOJ environment, the Contractor’s covered |
| TDLINE: information system is subject to review, audit, or assessment by third |
| TDLINE: parties, facilitating DOJ access to information system resources, |
| TDLINE: facilities, personnel, and documentation in a timely manner as required |
| TDLINE: by the auditors. Should a third-party organization conduct a review of |
| TDLINE: any Covered Information System, the Contractor must provide a copy of |
| TDLINE: the report to DOJ, through the CO and COR. Completing an attestation |
| TDLINE: that meets OMB Memorandum M-22-18 for software procurements following |
| TDLINE: the template attestation form developed by NIST. The attestation form |
| TDLINE: must be returned to the CO and COR for sharing with the component Chief |
| TDLINE: Information Officer (CIO). U.S. Department of Justice Departmental |
| TDLINE: Provisions and Clauses 24. C. Reporting on outages impacting DOJ |
| TDLINE: Services through the Contractor’s CO, COR, and DOJ Service Owner (SO) to |
| TDLINE: include event and mitigation details. The Contractor shall not process, |
| TDLINE: store, or transmit DOJ Information using a Covered Information System |
| TDLINE: without first obtaining an ATO for each Covered Information System. The |
| TDLINE: ATO shall be signed by the Authorizing Official for the DOJ component |
| TDLINE: responsible for maintaining the security, confidentiality, integrity, |
| TDLINE: and availability of the DOJ Information under this contract. (For Cloud |
| TDLINE: Computing Systems, see Section V, below.) D. The Contractor shall ensure |
| TDLINE: compliance with DOJ-03 (Personnel Security Requirements for Contractor |
| TDLINE: Employees) as to all Covered Information Systems. E. When requested by |
| TDLINE: the DOJ CO or COR as described below, the Contractor shall provide DOJ, |
| TDLINE: including the Office of Inspector General (“OIG”) and Federal law |
| TDLINE: enforcement components, (1) access to any and all information and |
| TDLINE: records, including electronic information, regarding a Covered |
| TDLINE: Information System, and (2) physical access to the Contractor’s |
| TDLINE: facilities, installations, systems, operations, documents, records, and |
| TDLINE: databases. Such access may include independent validation testing of |
| TDLINE: controls, system penetration testing, and FISMA data reviews by DOJ or |
| TDLINE: agents acting on behalf of DOJ, and such access shall be provided within |
| TDLINE: 72 hours of the request. Additionally, the Contractor shall cooperate |
| TDLINE: with DOJ’s efforts to ensure, maintain, and safeguard the security, |
| TDLINE: confidentiality, integrity, and availability of DOJ Information. F. The |
| TDLINE: use of Contractor-owned laptops or other portable digital or electronic |
| TDLINE: media to process or store DOJ Information covered by this clause or |
| TDLINE: access a Covered Information System is prohibited unless the CO approves |
| TDLINE: it in writing after the Contractor has provided a letter certifying |
| TDLINE: compliance with the following requirements. For any requirements which |
| TDLINE: include the use or storage of PII, the Senior Component Official for |
| TDLINE: Privacy must also approve. Any additional requirements set forth for the |
| TDLINE: use or storage of PII under DOJ-02, Contractor Privacy Requirements, are |
| TDLINE: in addition to, not superseded by, the requirements set forth here. 1. |
| TDLINE: 2. 3. 4. 5. Media must be encrypted using a NIST FIPS 140-2 approved |
| TDLINE: product. The Contractor must develop and implement a process to ensure |
| TDLINE: that security and other applications software is kept up to date. Where |
| TDLINE: applicable, media must utilize antivirus software and a host-based |
| TDLINE: firewall mechanism. The Contractor must log all computer-readable data |
| TDLINE: extracts from databases holding DOJ Information and verify that each |
| TDLINE: extract including such data has been erased within 90 days of extraction |
| TDLINE: or that its use is still required. All DOJ Information should be treated |
| TDLINE: by the Contractor as sensitive information unless specifically |
| TDLINE: designated as non-sensitive by the DOJ. A Rules of Behavior (ROB) form |
| TDLINE: must be signed and acknowledged annually by users. These rules must |
| TDLINE: address, at a minimum, authorized, and official use, prohibition against |
| TDLINE: unauthorized users and use, and the protection of DOJ Information. The |
| TDLINE: form also must notify the users that they have no reasonable expectation |
| TDLINE: of privacy regarding any communications transmitted through or data |
| TDLINE: stored on Contractor-owned laptops or other portable digital or |
| TDLINE: electronic media. U.S. Department of Justice Departmental Provisions and |
| TDLINE: Clauses 6. G. Cybersecurity Awareness Training (CSAT) shall be provided |
| TDLINE: annually by Contractor for all users of Covered Information System. This |
| TDLINE: training must be submitted to, and approved by, the CO or COR in advance |
| TDLINE: of being provided to users. Users must complete and acknowledge having |
| TDLINE: received CSAT each year. At a minimum, CSAT provided by contractors must |
| TDLINE: include: a. Insider Threat Detection and Reporting – Importance of |
| TDLINE: detecting, methodologies, indicators, and reporting b. Privacy Awareness |
| TDLINE: – Privacy Act and PII c. General Cybersecurity – Information security, |
| TDLINE: trends in advance persistent threats, social engineering/phishing, |
| TDLINE: appropriate use, mobile devices, remote access, basic security best |
| TDLINE: practices Contractors shall not store DOJ information on |
| TDLINE: Contractor-owned removable IT (e.g., media such as a thumb drive or |
| TDLINE: external hard drive) unless expressly authorized in writing by the DOJ |
| TDLINE: CO or COR in the performance of their contract. H. When no longer |
| TDLINE: needed, all media must be processed (sanitized, degaussed, or destroyed) |
| TDLINE: in accordance with NIST SP 900-88, Guidelines for Media Sanitization. I. |
| TDLINE: The Contractor must keep an accurate inventory of digital or electronic |
| TDLINE: media used in the performance of DOJ contracts. J. The Contractor must |
| TDLINE: remove all DOJ Information from Contractor media and return all such |
| TDLINE: information to the DOJ within 10 days of the expiration or termination |
| TDLINE: of the contract, unless otherwise extended by the CO, or waived (in part |
| TDLINE: or whole) by the CO, and all such information shall be returned in a |
| TDLINE: format and form acceptable to DOJ. The Contractor shall provide a |
| TDLINE: written certification certifying the removal and return of all such |
| TDLINE: information to the CO within 10 business days of the removal and return |
| TDLINE: of all DOJ Information. K. DOJ, at its discretion, may suspend the |
| TDLINE: Contractor’s access to any DOJ Information, or terminate the contract, |
| TDLINE: when DOJ suspects that the Contractor has failed to comply with any |
| TDLINE: security requirement, or in the event of an Information System Security |
| TDLINE: Incident or Security Breach (see definitions above), where the |
| TDLINE: Department determines that either event gives cause for such action. The |
| TDLINE: suspension of access to DOJ Information may last until such time as DOJ, |
| TDLINE: in its sole discretion, determines that the situation giving rise to |
| TDLINE: such action has been corrected or no longer exists. Any termination |
| TDLINE: action taken because of the Contractor’s suspected failure to comply |
| TDLINE: with any security requirement will be conducted in accordance with the |
| TDLINE: applicable termination clause governing the awarded contract. The |
| TDLINE: Contractor understands that any suspension or termination in accordance |
| TDLINE: with this provision shall be at no cost to DOJ, and that upon request by |
| TDLINE: the CO, the Contractor must immediately return all DOJ Information to |
| TDLINE: DOJ, as well as any media upon which DOJ Information resides, at the |
| TDLINE: Contractor’s expense. The Contractor must comply with FAR 52.227-14 |
| TDLINE: (Rights in Data), FAR 52.245-1 (Government Property), DOJ 2400.3A |
| TDLINE: Chapter 1 (component property procedures), and FAR 4.804-5(a)(6) |
| TDLINE: (Procedures for closing out contract files). V. Cloud Computing U.S. |
| TDLINE: Department of Justice Departmental Provisions and Clauses A. B. C. D. E. |
| TDLINE: The Contractor may not utilize the Cloud system of any Cloud Service |
| TDLINE: Provider (CSP) unless: 1. 2. All of the following has occurred: (a) the |
| TDLINE: Cloud system and CSP have been evaluated by a Third Party Assessing |
| TDLINE: Organization (“3PAO”) certified under FedRAMP; (b) the Cloud system |
| TDLINE: received FedRAMP authorization; (c) the Contractor has provided the most |
| TDLINE: current System Security Plan (“SSP”) and Security Assessment Report |
| TDLINE: (“SAR”) to the DOJ CO for consideration, and provides any subsequent |
| TDLINE: SSPs and SARs within 30 days of issuance; and, (d) the Authorizing |
| TDLINE: Official for the DOJ component responsible for maintaining the security |
| TDLINE: confidentiality, integrity, and availability of the DOJ Information |
| TDLINE: under the Covered Contract has issued an ATO; or, In cases where the CSP |
| TDLINE: or its offering is not FedRAMP authorized, the COR approves utilization |
| TDLINE: of the Cloud System after the CSP has worked with the authorizing |
| TDLINE: official, the DOJ OCIO, and the FedRAMP Program Management Office to |
| TDLINE: determine that the CSP is likely to seek and receive Agency/FedRAMP |
| TDLINE: authorization within 1 year, or DOJ has authorized use as a Private |
| TDLINE: Cloud or Contractor Owned, Contractor Operated system. The Contractor |
| TDLINE: must ensure that the CSP allows DOJ to access and retrieve any DOJ |
| TDLINE: Information processed, stored, or transmitted in a Cloud system under |
| TDLINE: this Contract within a reasonable time of any such request, but in no |
| TDLINE: event less than 48 hours from the request. To ensure that the DOJ can |
| TDLINE: fully and appropriately search and retrieve DOJ Information from the |
| TDLINE: Cloud system, access shall include any schemas, meta-data, and other |
| TDLINE: associated data artifacts. The Contractor must ensure that the CSP |
| TDLINE: provides access and information to support and enable DOJ’s cloud |
| TDLINE: security posture management, to include the current inventory of |
| TDLINE: security management configuration data for services and information to |
| TDLINE: confirm the Contractor has been monitoring accounts for compliance with |
| TDLINE: security requirements. The DOJ Justice Security Operations Center (JSOC) |
| TDLINE: must be able to access logs and events to investigate potential security |
| TDLINE: breaches and perform security posture assessments associated with the |
| TDLINE: Security Audit Identity Credential Access Management (ICAM) policies. |
| TDLINE: The Contractor must ensure that the CSP provides evidence of annual |
| TDLINE: recertification of privileged user access management. A Supply Chain |
| TDLINE: Risk Management (SCRM) review is mandatory for specified acquisitions in |
| TDLINE: accordance with established process in EO 14028 and NIST SP 800 161, |
| TDLINE: Cybersecurity Supply Chain Risk Management Practices for Systems and |
| TDLINE: Organizations, or superseding document. All vendor products and |
| TDLINE: solutions to be used on DOJ national security systems, enterprise-wide |
| TDLINE: systems, or new FIPS-199 High and Moderate systems for the purpose of |
| TDLINE: accessing, collecting, storing, processing, maintaining, using, sharing, |
| TDLINE: retrieving, disseminating, transmitting, or U.S. Department of Justice |
| TDLINE: Departmental Provisions and Clauses disposing of DOJ Information must be |
| TDLINE: submitted to DOJ OCIO for a Supply Chain Risk Management review prior to |
| TDLINE: contract award or ATO signature. Changes in corporate ownership or |
| TDLINE: structure shall be reported to the CO for referral to SCRM. The |
| TDLINE: Contractor shall notify the CO of any confirmed Supply Chain compromise |
| TDLINE: affecting the Contractor’s products or services within 1 hour of |
| TDLINE: discovery. _____ The following SCRM requirements for acquisition of |
| TDLINE: systems, hardware, or software which will be used in systems that are |
| TDLINE: mission critical or process sensitive data apply to this award. (CO |
| TDLINE: check as appropriate in coordination with the Program Manager and/or |
| TDLINE: System Owner) 1. 2. 3. The Contractor shall develop and deliver a SCRM |
| TDLINE: Plan. The SCRM Plan shall meet the format described in NIST SP 800-161, |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .