2_2_9594CS25Q0061.pdf

PDF 502 KB Posted

Attached to
Remote Monitoring Device Federal contract opportunity
Solicitation number
9594CS25Q0061
Issued by
Court Services and Offender Supervision Agency

About this file

This is a Request for Quote (RFQ) for a Remote Monitoring Device solicitation (9594CS25Q0061) issued by the Court Services and Offender Supervision Agency (CSOSA) for the District of Columbia. The procurement is a Women-Owned Small Business (WOSB) set-aside for a firm-fixed-price purchase order to provide a software solution that enables Community Supervision CSOs to remotely monitor computer and internet activities of offenders under community supervision, with 24/7 data capture across Windows, Mac OS, Android, and iOS devices.

The solicitation covers a base period from September 30, 2025 through September 29, 2026, with four optional one-year extension periods through September 29, 2030. The total contract duration shall not exceed 5 years. The North American Industry Classification System (NAICS) code is 541519 with a small business size standard of $34.0M. Quotes are due by 11:00 AM Eastern Daylight Time 28 calendar days from the solicitation issue date. The government will award to the lowest-priced, technically acceptable quoter based on an evaluation of technical acceptability and price reasonableness, with no trade-offs permitted between price and non-price factors.

View the file

Other files for this federal contract opportunity

Other files attached to Remote Monitoring Device, newest first.
File Type Posted
2_2_Attachment_J-2_Solicitation_Price_Sheet.pdf PDF
2_2_Attachment_J-1_Requirement_Certification.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

WOMEN-OWNED SMALL

BUSINESS (WOSB)

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

1. REQUISITION NUMBER PAGE 1 OF

2. CONTRACT NUMBER 3. AWARD/EFFECTIVE

DATE

4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE

DATE

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME b. TELEPHONE NUMBER (No collect calls)

8. OFFER DUE DATE/

LOCAL TIME

9. ISSUED BY

13b. RATING

14. METHOD OF SOLICITATION

CODE

15. DELIVER TO 16. ADMINISTERED BY CODE

18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/

OFFEROR

CODE

FACILITY

CODE

CODE

TELEPHONE NUMBER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

REQUEST

FOR QUOTE

(RFQ)

INVITATION

FOR BID

(IFB)

REQUEST

FOR

PROPOSAL

(RFP)

SEE ADDENDUM

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH

AND DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND

ON ANY ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS

SPECIFIED

29. AWARD OF CONTRACT: REFERENCE OFFER

DATED . . YOUR OFFER ON SOLICITATION

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA - FAR (48 CFR) 53.212

10. THIS ACQUISITION IS UNRESTRICTED OR

NORTH AMERICAN

INDUSTRY CLASSIFICATION

STANDARD (NAICS):

SIZE STANDARD:

13a. THIS CONTRACT IS A

RATED ORDER UNDER

THE DEFENSE PRIORITIES

AND ALLOCATIONS

SYSTEM - DPAS (15 CFR 700)

SET ASIDE: % FOR:

11. DELIVERY FOR FREE ON

BOARD (FOB) DESTINATION

UNLESS BLOCK IS MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

ARE ARE NOT ATTACHED

ARE ARE NOT ATTACHED

27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4. FAR 52.212-3

AND 52.212-5 ARE ATTACHED. ADDENDA

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

8(A)

ECONOMICALLY

DISADVANTAGED

WOMEN-OWNED SMALL

BUSINESS (EDWOSB)

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

(SDVOSB)

HUBZONE SMALL

BUSINESS

SMALL BUSINESS

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30.

STOCK RECORD (S/R)

STANDARD FORM 1449 (REV. 11/2021) BACK

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE RECEIVED (MM/DD/YYYY) 42d. TOTAL CONTAINERS

40. PAID BY

32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELPHONE NUMBER OF AUTHORZED GOVERNMENT REPRESENTATIVE

32g. EMAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED

CORRECT FOR

PARTIAL FINAL

37. CHECK NUMBER

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER

36. PAYMENT

COMPLETE PARTIAL FINAL

9594CS25Q0061

TABLE OF CONTENTS:

Listing of Incorporated Purchase Requisitions Section B - Supplies or Services and Prices/Costs Section C - Description/Specifications/Work Statement Section D - Packaging and Marking Section E - Inspection and Acceptance Terms Section F - Delivery or Performance Section G - Contract Administration Data Section H - Special Contract Requirements Section I - Contract Clauses Section J - List of Documents, Exhibits, and other Attachments Section K - Representations, Certifications, and Other Statements of Offerors Section L - Instructions, Conditions and Notices to Offerors Section M - Evaluation Factors for Award

Listing of Incorporated Purchase Requisitions

Incorporated Purchase Requisition Numbers:

Section B - Supplies or Services and Prices/Costs

Item Number Base Item Number

Supplies/Services Quantity Unit

0001 Remote Monitoring Device 360 EA Contract Type:Firm Fixed Price

Unit Price Extended Price

Description:

Purchase Requisitions

IDC Type: Not Applicable

Item Number Base Item Number

Supplies/Services Quantity Unit

1001 0001 Remote Monitoring Device 360 EA Contract Type:Firm Fixed Price

Unit Price Extended Price

Description:

Purchase Requisitions

Option: 2 Option Time Date: 9/30/26 Option Time Duration: 364 Option Time Units: Days IDC Type: Not Applicable

Item Number Base Item Number

Supplies/Services Quantity Unit

2001 0001 Remote Monitoring Device 360 EA Contract Type:Firm Fixed Price

Unit Price Extended Price

Description:

Purchase Requisitions

Option: 1 Option Time Date: 9/30/27 Option Time Duration: 365 Option Time Units: Days IDC Type: Not Applicable

Item Number Base Item Number

Supplies/Services Quantity Unit

3001 0001 Remote Monitoring Device 360 EA Contract Type:Firm Fixed Price

Unit Price Extended Price

Description:

Purchase Requisitions

Option: 3 Option Time Date: 9/30/28 Option Time Duration: 364 Option Time Units: Days IDC Type: Not Applicable

Item Number Base Item Number

Supplies/Services Quantity Unit

4001 0001 Remote Monitoring Device 360 EA Contract Type:Firm Fixed Price

Unit Price Extended Price

Description:

Purchase Requisitions

Option: 4 Option Time Date: 9/30/29 Option Time Duration: 364 Option Time Units: Days IDC Type: Not Applicable

B.1 Type of Contract. Remote Monitoring Device is a Firm Fixed price Purchase Order; The Contractor shall provide all services required for the above contract line items (CLINs). In accordance with Section C Statement of Work.

B.3 North American Industry Classification System (NAICS) and Small Business Size Standard. The NAICS Code for this Purchase Order is 541519 Other Computer Related Services. The Small Business Size Standard is $34.0M.

Section C - Description/Specifications/Work Statement

C.1 Agency Background.

The Court Services and Offender Supervision Agency (CSOSA) for the District of Columbia is a Federal Executive Branch Agency, created by Congress in 1997 to perform the offender supervision function for D.C. Code offenders. It does so in coordination with the Superior Court of the District of Columbia and the U.S. Parole Commission. CSOSA's mission is effectively supervise adults under our jurisdiction to enhance public safety, reduce recidivism, support the fair administration of justice, and promote accountability, and inclusion and success through the implementation of evidence-based practices in close collaboration with our criminal justice and the community. CSOSA is committed to achieving our strategic goals and enhancing public safety. CSOSA continues to develop, implement, and analyze effective evidence-based offender supervision programs and techniques to reduce recidivism among our offender population.

C.2 Scope.

CSOSA requires a contractor to provide a software solution and related services that enables Community Supervision CSOs (CSO's) to monitor remotely the computer and internet activities of offenders under community supervision. Remote monitoring enables CSOs to monitor an offender's computer or internet use continuously from a distance, 24 hours a day, 7 days a week.

The contractor shall provide all equipment, software, and associated support required to successfully perform the requirements defined in this statement of work.

The contractor's solution shall provide the following services:

C.2.1 Data Capture - 24 hours a day, seven (7) days a week data capture of offender's computer and internet usage and activities on Windows, Mac OS, Android, and iOS devices.

C.2.2 Remote Access via Dedicated Interface - The contractor shall provide CSOs 24 hours a day, seven (7) days a week remote access to the dedicated interface through which the solution's features and reports are accessible.

C.2.3 Physical and/or Remote Installation and Removal of Hardware and/or Software - The solution shall be able to be installed and uninstalled by CSO or contractor.

C.2.4 Technical Support - On-call 24 hours a day, seven (7) days a week technical support.

C.2.5 Training – The contractor shall provide training to the CSO staff on the installation, use, and maintenance of the monitoring solution. This should include training to ensure CSOs meet the minimum standard in usage of the solution.

C.2.5 Technology Refreshment - The contractor shall provide a technological refresh at any time during the period of performance, should a technological advancement occur that would enhance the contractor's ability to perform data capture and management.

C.2.7 Application Programming Interface (API). The Contractor shall provide a Representational State Transfer (REST) Application Programming Interface (API) affording CSOSA the opportunity to fetch records relevant to its use of the Contractor's Case Management System (CMS) on demand over a secured Hypertext Transport Protocol (HTTPS) connection.

C.2.8 Security – The contractor's solution shall possess a security infrastructure that meets requirements to prevent unauthorized individuals from gaining access to offender data.

C.2.9 Storage of Captured Data – The contractor shall ensure all captured data is stored in a secure environment that meets data storage requirements specified in Section H.11.

C.3 Requirements.

C.3.1 Data Capture. The Contractor's solution shall capture:

A. Computer Use – Collect all use of monitored computer/device, i.e. program/application uses, login/logout, file creation/access/modification.

B. Internet Browser Activity – Collect all internet browser activity captured by Uniform Resource Locator (URL) and designated by browser used with data and time accessed.

C. Communication Activity – Capture email, chat/IM, video communication. (Screen captures may satisfy the minimum requirement. Full text or HTML of all chat/IM, email, or any other web-based chat communications exceeds the minimum requirements).

D. Program and Application Activity – Capture use of programs and application by data and time accessed.

E. File Transfer Activity – Capture files sent/received by computer device.

F. File Activity - Capture files created/modified/accessed activity by the computer device.

G. External Media, Human Interface Device(s) and/or Peripheral(s) Device Activity – Capture external (non-resident) media device access such as USB flash drives, network-connected hard drives/storage, wireless hard drives, and any other media storage device not resident to the monitored device to include cloud storage.

H. Screen Capture – The solution shall permit for the ability to capture screen activity (screen shot) of the monitored devices, and shall be configurable based on identified keyword, application/program usage, or time intervals.

I. Application/Program/Website blocking – The solution shall permit for the ability to configure and block identified application(s), program(s), and website(s) from being used or accessed on the monitored device.

J. Data Review – The solution shall provide the review of all flagged data collected for validity based on case profile(s).

K. Image Analysis – The solution shall review all images, screenshots, and videos collected by the solution for validity based on case profile(s).

L. Alerts and Reports – The solution shall provide immediate alert notification(s), as well as time set interval reports, based on identified risk(s) such as keyword(s) or application(s) by email, text, or telephone contact.

M. Keystroke Activity – The solution shall capture user keystroke activity.

C.3.2 Remote Access via Dedicated Interface. The Contractor's solution shall provide users a dedicated interface through which remote access to the solution's features and reports is achieved.

A. All access shall be web based and accessible by web browser by traditional and mobile computer devices, without the use of any third-party software interface.

B. The contractor shall maintain and provide login ID and temporary passwords for all CSOs upon request. The interface shall allow CSOs to create unique login and passwords upon creation of an account.

C. The interface shall provide the CSOs the ability to view, print, download, and enter/modify offender information.

D. The interface shall allow the CSO to enroll defendants/offenders with offender profile information, choose specific monitoring protocols, restrictions, exclusions from monitoring, and delineate key alerts, suspicious activity notifications, and innocuous activities; and other tasks as noted in C.3.1 Task 1- Data Capture.

E. Upon CSO enrollment of a offender into the contractor's solution, the contractor's solution shall confirm enrollment with the CSO.

F. The interface shall provide multiple (hierarchical) levels of access, up to an enterprise level of access that enables the COR to view all users and connected devices, active and inactive, searchable by install and uninstall dates.

G. The interface shall provide for the management and configuration of persons under supervision "case" on an individual case level as well as group.

H. The contractor's solution shall possess the capability to capture each CSO's access and utilization of the solution;

provide offender enrollment, removal, and modification capability; key alert summary reports; and other customized reports as designated by the COR.

I. The interface shall provide the ability to create, customize, configure, and assign case type profile(s) to a case(s) and group(s).

J. The interface shall provide the ability to create, customize, configure, and assign individual and group keywords of interest to be noted in data collection to individual cases and groups.

K. The interface shall provide the ability to create, customize, configure, and assign individual and group application(s)/program(s) of interest to be noted in the data collection to individual cases and groups.

L. The interface shall provide the ability to create, customize, configure, and assign reports for individual cases and group.

M. The interface shall provide reports on:

1. The number of devices installed and active the present day or within a searchable date range.

2. The number of devices that failed to connect for three (3) days.

3. The number of devices that failed to connect for seven (7) days.

N. The interface shall provide the ability create, customize, and configure immediate notification based on identified risk such as keyword(s) or application(s) by email, text, or telephone contact.

O. The interface shall provide CSOs the ability to access all collected data, as well as the ability to filter and sort in various ways to produce the desired data for review.

C.3.3 Physical Installation and Removal of Software.

A. The solution shall have the ability to be installed and uninstalled by a CSO as well as the contractor by scheduled appointment.

B. The offeror shall provide a solution for physical installation and removal of hardware and/or software to accomplish the following objectives for this task as follows:

1. The contractor shall provide all necessary equipment and software required to install and remove the monitoring solution software.

2. The monitoring solution shall be installable by both the contractor, by service appointment, and CSO without the aid of contractor.

3. The contractor shall provide all required training, notes, or other details for installation.

4. The solution shall notify the assigned CSO of installation completion.

5. The contactor's solution shall facilitate the installation of monitoring software no more than three (3) business days after enrollment when a request for contractor installation is submitted.

C.3.4 Technical Support. The offeror shall provide a solution for technical support to accomplish the following objectives for this task as follows:

A. The contractor shall aid and inform CSOs regarding all functions of the contractor's solution.

B. The contractor shall provide contact information for technical assistance to all CSOs, including after hours and on-call procedures.

C. The contractor shall provide CSOs with digital copies of captured and stored data documents and data retrieval and preparation, if needed.

D. The contractor shall address and provide detailed response for all assistance requests in a reasonable time frame.

C.3.5 Training.

A. Training shall be available and provided to all CSOs using the solution.

B. The contractor shall develop training for the installation and removal of the monitoring solution.

C. The contractor shall provide training for the overall use of the dedicated interface.

D. The contractor shall provide training on the overall functionality of the contractor's solution.

E. Within thirty (30) calendar days contract award, the contractor shall provide to the COR a training program, to include content and materials, for training CSOs on the installation and implementation of the contractor's solution.

F. Training may be in the form of web-based modules, in-person presentations, video, or other formats as approved by the

COR.

G. The contractor may provide up to six web-based training sessions per period of performance on technology refreshes, new features, or best practices for using the solution.

H. The Contractor shall provide a copy of any web-based training sessions to the COR in a SCROM file format, or a file convertible to a SCROM file format, that can be posted on the agency's Learning Management System.

C.3.6 Technology Refresh.

A. The contractor shall provide a technological refresh on any identified services or abilities noted in this contract at any time during the period of performance, should a technological advancement occur that would enhance the contractor's ability to perform data capture and management.

B. The offeror shall provide a solution for technology refresh to accomplish the following objectives for this task as follows:

1. The contractor shall coordinate with the COR on scheduled releases because of implementation of new technology and associated training within 30 days of the release.

2. The Contractor shall provide written notification in writing via email, text, or alert via dedicated interface at least 24 hours in advance of any scheduled service outages.

3. CSOSA reserves the right to modify its stated requirements per platform to take advantage of emerging technologies and enhanced capabilities to allow for optimal monitoring.

4. The contractor shall only provide software that is the most recent generation and supported by the manufacturer. Any replacement, new or upgraded software specifications and delivery information shall be submitted, in writing, to the COR and approved by the CO.

5. The contractor shall immediately (no greater than 24 hours) to take documented measures to correct all failures and deficiencies resulting from software or services acquired under contract. During this time, the contractor shall provide the COR documentation related to the timeframe for full resolution. The contractor shall provide replacement software and/or hardware as needed.

6. Throughout the life of the contract, the contractor shall provide the most recent generation of reliable software, hardware, and support services to mitigate the risk of obsolescence of existing technology.

7. The contractor shall provide up-to-date monitoring to include the ability to monitor new operating systems (OS) releases within a maximum of six (6) months from release of OS developer's kit or a maximum of 90 days from market launch (whichever is sooner).

C.3.7 Application Programming Interface (API).The Contractor shall provide a Representational State Transfer (REST) Application Programming Interface (API) affording CSOSA the opportunity to fetch records relevant to its use of the Contractor's Case Management System (CMS) on demand over a secured Hypertext Transport Protocol (HTTPS) connection.

The API shall:

A. Support changes (i.e., insert/update/delete operations) performed against the Contractor's CMS.

B. Be accessible to authorized CSOSA staff within thirty days of task order award.

C. Accept JavaScript Object Notation (JSON) blocks as requests.

D. Return JSON blocks as responses.

E. Include endpoints for retrieving system user records identifying and characterizing CSOSA users and vendor agents who have inserted/updated/deleted records related to CSOSA personnel, CSOSA team configurations, offender records, device type, device installation and uninstallation dates, invoice periods, line items, unit costs, and billable unit counts sufficient to support invoicing and CSOSA audits.

C.3.8 Data Security. The contractor's solution shall possess a security infrastructure (meeting requirements described in Section H) to prevent unauthorized individuals from gaining access to offender data.

A. The contractor shall implement procedures necessary to ensure the immediate detection of data breaches and unscheduled service outages.

B. The contractor shall be required to prevent and remedy data breaches and unscheduled service outages, and to provide the Contracting CSO (CO) and COR with all necessary information and cooperation in this area.

C. The contractor shall notify the COR in writing, as soon as reasonably possible but no later than 24 hours, of any security or data breaches, as well as unscheduled disruptions in service. The COR may request more information from the contractor for investigatory purposes.

D. The contractor shall provide written report(s) within five (5) calendar days to the CO and COR documenting the above listed event(s), efforts to remedy the event and steps to prevent a re-occurrence of the problem for review and acceptance by CSOSA. This also includes provisions for training, contractor staff, monitoring, incident reporting, and other physical and logical access security controls and safeguards.

E. In the event of a security or data breach the contractor shall notify law enforcement and cooperate with any investigation efforts.

F. In the event of an unscheduled service outage occurrence that is not a failure of the solution but rather an attack from the outside such as a Denial Of Service Attack (DOS), the contractor shall again notify law enforcement and comply with any investigation efforts.

G. Should a breach occur, the contractor is required to take all reasonable and necessary steps and precautions to enable the CO and COR to satisfy its data breach reporting duties under applicable law, regulation, and/or policy.

H. The contractor shall have a reputable independent service conduct an annual security evaluation of the solution and provide a written report to the CO and COR.

C.3.9 Post-Award Meetings. The Contractor shall participate in a post-award meeting scheduled by the COR to review the purchase order goals and objectives. This post-award meeting will take place no later than 10 days following the purchase order award.

C.3.10 Contractor Quality Assurance Protocol (QAP). The Contractor shall develop, and provide to the CO within 10 days of purchase order award, a QAP that identifies what actions, processes, procedures, inspections, reviews, and responsibility assignments the Contractor will utilize to ensure that the Contractor's performance complies with all of the requirements of this purchase order. The CO shall have ten business days to review the QAP and provide requested or required changes to the Contractor. The Contractor will then have five business days to incorporate the CO's required/requested changes and return a final QAP to the CO. The Contractor's QAP shall be reviewed and updated as required, but no less than annually.

C.3.11 Inspections, Compliance and Audit. CSOSA through the CO, COR, or other CSOSA components shall conduct inspections and audits (hereafter "audit") to verify the personnel, operations, programs and the related non-financial books, records, accounts and information (including electronic data) of Contractor, comply with the provisions of this purchase order, or to assess the efficacy of any goods or services delivered pursuant to this purchase order. Contractor and its personnel shall cooperate fully with all audits.

Section D - Packaging and Marking

Section E - Inspection and Acceptance Terms

E.1 Inspection will be in accordance with FAR 52.212-4(a) and E.2 below.

E.2 Inspection and acceptance of services to be furnished will be performed by the Contracting Officer's Representative (COR). The Government will conduct any inspection and tests deemed reasonably necessary to ensure the all services provided conform will all requirements identified in Section C. Services and/or deliverables, which upon inspection, are found not to be in conformance with Section C, shall be promptly rejected by the COR. A written notice of such rejection will be provided to the Contractor. Any notice of rejection requires the Contractor to re-perform any rejected services within the timeframe established by the COR.

Section F - Delivery or Performance

Line Item: 0001 Period Of Performance Start Date Period Of Performance End Date Period Of Performance Address

9/30/25 9/29/26

Line Item: 1001 Period Of Performance Start Date Period Of Performance End Date Period Of Performance Address

9/30/26 9/29/27

Line Item: 2001 Period Of Performance Start Date Period Of Performance End Date Period Of Performance Address

9/30/27 9/29/28

Line Item: 3001 Period Of Performance Start Date Period Of Performance End Date Period Of Performance Address

9/30/28 9/29/29

Line Item: 4001 Period Of Performance Start Date Period Of Performance End Date Period Of Performance Address

9/30/29 9/29/30

F.1 Period of Performance. The period of performance for this Purchase Order is as follows:

Base Period – September 30, 2025 through September 29, 2026;

Option Period 1 – September 30, 2026 through September 29, 2027;

Option Period 2 – September 30, 2027 through September 29, 2028;

Option Period 3 – September 30, 2028 through September 29, 2029; and

Option Period 4 – September 30, 2029 through September 29, 2030.

F.2 Place of Performance. The work shall be performed at the Contractor's location.

F.3 Hours of Operation. CSOSA normal hours of operation are five days per week. From 7:00 AM ET to 5:00 PM ET.

F.4 Observance of Legal Holidays.

F.4.1 CSOSA personnel observe the following holidays:

New Year's Day

Martin Luther King's Birthday

President's Day

Memorial Day

Juneteenth Day

Independence Day

Labor Day

Columbus Day

Veterans' Day

Thanksgiving Day

Christmas Day

F.4.2 If a holiday falls on Sunday, the following Monday will be observed as the legal holiday.

F.4.3 When a holiday falls on a Saturday, the preceding Friday is observed as a legal holiday by U.S. Government agencies.

F.4.4 In addition to the days designated as holidays, the Government observes the following days:

(1) Any other day designated by Federal Statute

(2) Any other day designated by Executive Order

(3) Any other day designated by the President's Proclamation

F.4.5 It is understood and agreed between the Government and the Contractor that observance of such days by Government personnel shall not otherwise be a reason for an additional period of performance, or entitlement of compensation except as set forth within this Purchase Order.

F.5 Deviations. An advance written agreement from the Contracting Officer must be received by the Contractor for deviations to delivery or performance requirements under this Purchase Order.

F.6 Travel. No travel reimbursement is allowed under this Purchase Order.

F.7 Deliverables. The deliverables under this Purchase Order shall be provided in accordance with all the requirements identified in Section C as follows:

Deliverable Frequency Due Date

Section C.3.2.M - Report of the # of Devices that failed to connect for three (3) days

Daily By 8:00 AM (eastern)

Section C.3.2.M - Report of the # of Devices that failed to connect for seven (7) days

Daily By 8:00 AM (eastern)

Section C.3.3.5 - Installation of monitoring software As necessary No more than three (3) business days after enrollment when a request for contractor installation is submitted.

Section C.3.4.B - Contact information for technical support to include after hours and on-call procedures.

As necessary 10 calendar days after contract award and within 24 hours if contact information changes

Section C.3.4.C - Digital copies of captured and stored data documents and data retrieval and preparation.

As necessary As soon as reasonably possible but no later than 24 hours

Section C.3.4.D - Written detailed response for all assistance requests.

As necessary As soon as reasonably possible but no later than 24 hours

Section C.3.5.E - Written training program, to include content Once 30 calendar days of contract

Deliverable Frequency Due Date and materials, for training CSOs on the installation and implementation of the contractor's solution.

award

Section C.3.5.F - Provide web-based training for CSOs using the solution.

Monthly Scheduled anytime during month

Section C.3.5.G – Provide copy of web-based training in SCORM file format (or compatible) file.

As necessary Up to 6 times per period of performance

Section C.3.6 - Provide software that is the most recent generation and supported by the manufacturer. Any replacement, new or upgraded software specifications and delivery information shall be submitted, in writing for approval prior to release.

As necessary At time of contract award and replacement, new, or upgraded software within six (6) months from release of OS developers kit or a maximum of 90 calendar days from market launch (whichever is sooner).

Section C.3.6.B.2 - Notification in writing of any scheduled service outages

As necessary No less than 24 hours prior to scheduled service

Section C.3.6.B.4 - Documented measures and timeframes for full resolution to correct all failures and deficiencies resulting from software or services acquired by CSOSA. The contractor shall provide replacement software and/or hardware as needed.

As necessary No greater than 24 hours

C.3.8.D - Notification in writing of any security or data breaches, as well as unscheduled disruptions in service.

As necessary As soon as reasonably possible but no later than 24 hours

Section C.3.8.C - Notification in writing of any unscheduled service outages

As necessary As soon as reasonably possible but no later than 24 hours

Section C.3.8.D - Written report(s) documenting the security or data breach as well as unscheduled disruptions in service , efforts to remedy the event and steps to prevent a re-occurrence of the problem for review and acceptance by CSOSA. This also includes provisions for training, contractor staff, monitoring, incident reporting, and other physical and logical access security controls and safeguards.

As necessary Within five (5) calendar days of security or data breach as well as unscheduled disruptions in service.

Section C.3.8.E - Notification to law enforcement and cooperation with investigating offices in the event of a security or data breach.

As necessary As soon as reasonably possible but no later than 24 hours

Section C.3.8.F - Notification to law enforcement and comply with any investigation efforts in the event of an unscheduled service outage occurrence that is not a failure of the solution but rather an attack from the outside such as a Denial Of Service Attack (DOS).

As necessary As soon as reasonably possible but no later than 24 hours

Section C.3.8.G - Assist the CO and COR to satisfy its data breach reporting duties under applicable law, regulation, and/or policy should a breach occur.

As necessary As soon as reasonably possible but no later than 24 hours

Section C.3.8.H - Written report from a reputable independent service that conducted an annual security evaluation of the solution.

Annually 30 calendar days after each year of contract performance

F.8 Notice of Contractor Delays. In the event the Contractor encounters, or anticipates encountering, difficulty in meeting performance requirements, or in complying with the Purchase Order delivery schedule or completion date, or whether the Contractor has knowledge that any actual or potential situation is delaying, or threatens to delay, timely performance, the Contractor shall immediately, within one (1) business day, notify the Contracting Officer and the COR, in writing, giving pertinent details; provided, however, that this notification shall be informational only in character, and that this provision shall not be construed as a waiver by CSOSA of any delivery schedule or date, or any rights or remedies provided by law or under this Purchase Order.

F.9 FAR 52.242-14 Suspension of Work (Apr 1984)

(a) The Contracting Officer may order the Contractor, in writing, to suspend, delay, or interrupt all or any part of the work of this contract for the period of time that the Contracting Officer determines appropriate for the convenience of the Government.

(b) If the performance of all or any part of the work is, for an unreasonable period of time, suspended, delayed, or interrupted (1)by an act of the Contracting Officer in the administration of this contract, or (2)by the Contracting Officer's failure to act within the time specified in this contract (or within a reasonable time if not specified), an adjustment shall be made for any increase in the cost of performance of this contract (excluding profit) necessarily caused by the unreasonable suspension, delay, or interruption, and the contract modified in writing accordingly. However, no adjustment shall be made under this clause for any suspension, delay, or interruption to the extent that performance would have been so suspended, delayed, or interrupted by any other cause, including the fault or negligence of the Contractor, or for which an equitable adjustment is provided for or excluded under any other term or condition of this contract.

(c) A claim under this clause shall not be allowed- (1) For any costs incurred more than 20 days before the Contractor shall have notified the Contracting Officer in writing of the act or failure to act involved (but this requirement shall not apply as to a claim resulting from a suspension order); And (2) Unless the claim, in an amount stated, is asserted in writing as soon as practicable after the termination of the suspension, delay, or interruption, but not later than the date of final payment under the contract.

(End of clause)

Section G - Contract Administration Data

Requesting Office Address

CSP 800 N CAP

800 N. CAPITOL STREET, NW

Washington DC 20002 Phone: Fax:

Contact Details:

COR Office Address

CSP 800 N CAP

800 N. CAPITOL STREET, NW

Washington DC 20002 Phone: Fax:

Contact Details:

Issuing Office Address

Fax:

CSP 800 N CAP

800 N. CAPITOL STREET, NW

Washington DC 20002 Phone:

(202) 220-5621 Contact Details:

Lee, Colin Colin.Lee@csosa.gov

Payment Office Address CSOSA OFM Payment 800 N. Capitol Street, NW Washington DC 20002 Phone: Fax:

Contact Details:

WHITE, ROLANDA

Rolanda.White@csosa.gov

G.1 Contracting Officer's Representative.

G.1.1 The Contracting Officer's Representative (COR) for this Purchase Order is:

Danielle Speed Court Services and Offender Supervision Agency (CSOSA)

800 North Capitol Street, NW

Washington, DC 20002-4260

Telephone Number: 202-585-7767 Email Address: Danielle.Speed@csosa.gov

G.1.2 The COR is responsible for the technical aspects of the Purchase Orderand serves as the liaison with the Contractor.

The COR is responsible for the final inspection and acceptance of all work performed and such other responsibilities as may be specified in this Purchase Order.

G.1.3 The COR is not authorized to make any commitments or otherwise obligate the Government or authorize any changes which affect the Purchase Order price, terms, or conditions. Any Contractor request for changes shall be referred to the Contracting Officer directly or through the COR. No such changes shall be made without the express written prior authorization of the Contacting Officer.

G.2 Contracting Officer.

G.2.1 The Contracting Officer (CO) is the only person authorized to approve changes to any of the terms and conditions of this purchase order. In the event the Contractor effects any changes at the direction of any person other than the CO, the changes will be considered to have been made without authority and no adjustment will be made in the purchase order price to cover any increase in costs incurred as a result thereof. The CO shall be the only individual authorized to accept nonconforming work, waive any requirement of the purchase order, or to modify any term or condition of this purchase order. The CO is the only individual who can legally obligate Government funds. No cost chargeable to the proposed purchase order can be incurred before receipt of a fully executed contract, which includes any subsequent purchase order modifications or other specific written authorization from the CO.

G.2.2 The Contractor shall not comply with any order, direction, or request of Government personnel unless it is issued in writing and signed by the CO, or is pursuant to specific authority otherwise included as a part of this purchase order. No order, statement, or conduct of Government personnel, other than the CO, who visit the Contractor's facilities or in any other manner communicate with Contractor personnel during the performance of this purchase order, shall constitute a change under the terms for changes included in FAR 52.212-4 of this purchase order.

G.2.3 The procuring and administering Contracting Officer for this Purchase Order is:

Valerie Wallace

Office of Procurement

Court Services and Offender Supervision Agency (CSOSA)

800 North Capitol Street, NW

Washington, DC 20002-4260

Phone: 202-585-7448

Email Address: Valerie.Wallace@csosa.gov

G.3 Electronic Invoicing and Payment Requirements – Invoice Processing Platform

G.3.1 Payment requests must be submitted electronically through the U.S. Department of Treasury's Invoice Processing Platform (IPP) system using the "Bill to Agency" of Interior Business Center – FMD.

G.3.2 Definitions.

G.3.2.1 "Contract" as used throughout this clause means the type of contract identified in Section B.1 above.

G.3.2.2 "Payment request" means a bill, voucher, invoice or request for contract financing payment with associated supporting documentation.

G.3.3 To constitute a proper invoice, the payment request must comply with the requirements identified in the applicable Prompt Payment clause included in the contract or the clause GSAR 552.212-4, Contract Terms and Conditions – Commercial Items, included in commercial item contracts.

G.3.4 IPP Registration. The IPP website address is: https://www.ipp.gov.The Contractor must use the IPP website to register, access, and use IPP for submitting requests for payment. The Contractor Government Business Point of Contact (as listed in SAM) will receive enrollment instructions via email from the Federal Reserve normally within 3-5 business days of the contract award date. Assistance with enrollment may be obtained by contacting the IPP Production Helpdesk via email at IPPCustomerSupport@fiscal.treasury.gov or by phone at (866) 973-3131.

G.3.5 Payment Request/Invoice Submission.

G.3.5.1 Invoices shall be submitted in IPP with a unique invoice number and on a timely basis upon acceptance and delivery of items delivered under any awarded delivery order. Invoices shall not include items delivered from more than one awarded delivery order.

G.3.5.2 The payment request/invoice submission must identify the specific Contract Line Item Number (CLIN) for which the Contractor is seeking payment under the contract.

G.3.5.3 In addition to providing the information required by IPP, the Contractor shall include in IPP as an attachment(s) to the specific payment request the following:

1. Contractor Tax Identification Number;

2. Contractor Mailing Address;

3. Contractor Phone Number;

4. Date of Invoice;

5. Contractor Invoice Number (unique);

6. CSOSA Contract / Purchase Order Number;

7. CSOSA Contract Line Item Number (CLIN) or item number;

8. Description, price, quantity, deliverables.

G.3.6 CSOSA is bound by the Prompt Payment Act (5 CFR Part 1315) to reimburse Contractors on the 30th calendar day after a proper and valid invoice is officially received by the Agency.

G.3.6.1 Invoices submitted in IPP to incorrect CLINs and/or without required or valid attachment information are not considered proper.

G.3.6.2 Improper or invalid IPP invoices shall be disputed / rejected by CSOSA in their entirety. If the invoice is disputed / rejected by CSOSA, the Contracting Officer or COR appointed to the contract will notify the Contractor in writing of the dispute within seven (7) days of the CSOSA invoice official receipt date (the received date stamped on the invoice by OFM). CSOSA's written dispute / rejection notification will identify the specific invoice items and amounts being disputed, reason the items or amounts are disputed, a reference to the specific terms of the contract which supports the government's dispute and a request for an immediate explanation and / or corrected invoice. In addition, the invoice will be rejected by CSOSA in IPP. The Contractor shall re-submit corrected invoices in IPP, with required attachments, using a new, unique invoice number.

G.3.6.3 Properly disputed invoice amounts are not subject to late payment interest computations during the period of dispute.

Per FAR Part 32 the Contracting Officer has the final authority to approve payment of an invoice.

G.3.7 The Contractor should review IPP to determine the current status of a submitted invoice. Contractor inquiries concerning an invoice payment may be made to the CSOSA Office of Financial Management (OFM) thirty (30) calendar days after a proper invoice has been submitted. The Contractor may make payment inquires to by calling OFM, Ms. Rolanda White, at 202-220-5464 or emailing OFM at Rolanda.White@csosa.gov.

Section H - Special Contract Requirements mailto:IPPCustomerSupport@fiscal.treasury.gov mailto:Rolanda.White@csosa.gov

H.1 CSOSA Contractor Information Security Requirements

H.1.1 The Contractor shall meet and comply with Federal laws, Executive Orders, directives, policies, regulations, standards, and guidance, as amended and extended, for the protection of the information system and information during processing, while in storage, and during transmission. The Contractor shall be required to comply with, at a minimum:

a. Federal Information Security Modernization Act of 2014 (FISMA)

b. Office of Management and Budget (OMB) Circular and Memoranda (e.g. Circular A-130)

c. U.S. Department of Homeland Security Directives (e.g. US-CERT and HSPD-12)

d. National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) and Special

Publication (SP) 800 Series (e.g. FIPS 200, FIPS 199, FIPS 140-2, SP 800-18, SP 800-37, SP 800-53A, SP 800-60)

H.1.2 The Federal Information Security Modernization Act of 2014 (FISMA), requires the head of each agency to provide information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information. It requires those measures to be in place for information collected or maintained by or on behalf of the agency; and information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.

H.1.2.1 The law defines the term "information security" to mean protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide:

a. Integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;

b. Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and

c. Availability, which means ensuring timely and reliable access to and use of information.

H.1.2.2 The Contractor shall provide and implement security controls, as selected by CSOSA, to meet the security requirements for a Moderate impact level system as defined in NIST SP 800-53 (as amended), Security and Privacy Controls for Federal Information Systems and Organizations.

H.1.2.3 Executive departments and agencies procuring commercial and non-commercial cloud services, or systems provided or managed by other departments or agencies, contractors, or other sources shall comply with FISMA requirements. The Federal Risk and Authorization Management Program (Fed RAMP) is a government-wide program that provides a standardized approach to FISMA compliance as it applies to cloud-based computing services. It oversees and standardizes how to do security assessments, authorizations, and continuous monitoring for cloud products and services. Fed RAMP requirements apply to all cloud deployment models (e.g., Public Clouds, Community Clouds, Private Clouds, Hybrid Clouds);

and all cloud service models (e.g., Infrastructure as a Service, Platform as a Service, Software as a Service) as defined by the National Institute of Standards and Technology (NIST).

H.2 Security Assessment and Authorization, and Continuous Monitoring. The Contractor shall apply the appropriate set of baseline security controls as required in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 (as amended), Security and Privacy Controls for Federal Information Systems and Organizations.

H.2.1 The Contractor shall be responsible for the cost of preparing the Security Authorization Package using NIST SP 800-37 (as amended) Guide for Applying the Risk Management Framework to Federal Information Systems (using Fed RAMP templates, where available) and maintainingcompliance.

H.2.2 The Contractor shall be able to maintain a security management continuous monitoring environment thatmeets or exceeds the Continuous Monitoring requirements in SP 800-37, AppendixG.

H.3 Requirements for Externally Hosted Services and Applications.Since the Contractor's CMS is external to CSOSA the following requirements also apply:

H.3.1 CSOSA reserves the right to perform Penetration Testing. If CSOSA exercises this right, the Contractor shall allow Government employees (or designated third parties) to conduct Security Assessment activities to include control reviews in accordance with Fed RAMP requirements. Review activities include but are not limited to scanning operating systems , web applications, wireless scanning; network device scanning to include routers, switches, and firewall, and IDS/IPS; databases and other applicable systems, including general support structure, that support the processing, transportation, storage, or security of Government information for vulnerabilities.

H.3.2 Identified gaps between required Security Controls and the Contractor's implementation as documented in the System Security Plan (SSP) shall be tracked by the Contractor for mitigation in a Plan of Action and Milestones (POA&M) document.

H.3.3 The Contractor is responsible for mitigating all security risks found during security assessment and accreditation and continuous monitoring activities. All high-risk vulnerabilities shall be mitigated within 30 days and all moderate risk vulnerabilities shall be mitigated within 90 days from the date vulnerabilities are formally identified.

H.3.4 The Contractor shall provide access to the Federal Government, or their designee acting as their agent, when requested, in order to verify compliance. CSOSA reserves the right to conduct onsite inspections. The Contractor shall make appropriate personnel available for interviews and provide all necessary documentation during this review.

H.3.5 CSOSA has the right to perform manual or automated audits, scans, reviews, or other inspections of the Contractor's Information Technology (IT) environment being used to provide or facilitate services for CSOSA. In accordance with the Federal Acquisitions Regulations (FAR) clause 52.239-1, the Contractor shall be responsible for the following security safeguards:

H.3.6 The Contractor shall not publish or disclose in any manner, without the CO's written consent, the details of any safeguards either designed or developed by the Contractor under this purchase order or otherwise provided by CSOSA.

H.3.7 To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor shall afford CSOSA access to the Contractor's facilities, installations, technical capabilities, operations, documentation, records, and databases within 72 hours. The program of inspection shall include, but is not limited to:

a. Authenticated and unauthenticated operating system/network vulnerability scans;

b. Authenticated and unauthenticated web application vulnerability scans;

c. Authenticated and unauthenticated database application vulnerability scans; and

d. Automated scans can be performed by Government personnel, or agents acting on behalf of CSOSA, using Government operated equipment, and Government specifiedtools.

H.3.8 If new or unanticipated threats or hazards are discovered by either CSOSA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

H.3.9 If the Contractor chooses to run its own automated scans or audits, results from these scans may, at CSOSA's discretion, be accepted in lieu of Government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by CSOSA. In addition, the results of Contractor-conducted scans shall be provided, in full, to

CSOSA.

H.3.10 CSOSA may choose to cancel for convenience the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .