2.04a N0018922Q0070.pdf

PDF 1 MB Posted

Attached to
Training Services in Support of CLP Program Federal contract opportunity
Solicitation number
N0018922Q0070
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This solicitation requests training services in support of the Navy Cyber Defense Operations Command's Continuous Learning Program. Required training includes courses in CompTIA Network+, Cisco CCNA, Certified Penetration Testing, EC-Council Certified Ethical Hacker, Certified Hacking Forensic Investigator, CompTIA Linux+, and CompTIA Security+. Training is to be provided from September 2022 through September 2027 with additional six-month extension options. The solicitation includes details on course schedules, delivery locations, inspection and acceptance terms, and contract administration procedures. Pricing is to be provided using the Schedule of Supplies/Services included in the solicitation document.

View the file

Other files for this federal contract opportunity

Other files attached to Training Services in Support of CLP Program, newest first.
File Type Posted
2.05 J&A Redacted.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUM

(No Collect Calls)

N0018922Q0070

b. TELEPHONE NUMBER

757-443-1449

8. OFFER DUE DATE/LOCAL TIME

01:00 PM 12 Jul 2022

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

07-Jul-2022

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA – FAR (48 CFR) 53.212

(TYPE OR PRINT)

(SIGNATURE OF CONTRACTING OFFICER)

ADDENDA X ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

23.

CODE 10. THIS ACQUISITION IS

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

TELEPHONE NO.

N001899. ISSUED BY

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

FABIOLA A. ORTIZ

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

1 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.X

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

20.

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

. YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

% FOR:SET ASIDE:UNRESTRICTED OR X

SMALL BUSINESS

17a.CONTRACTOR/ CODE FACILITY

OFFEROR CODE

NAVSUP FLC NORFOLK CONTRACTING

NORFOLK OFFICE

ATTN: F. ORTIZ

1968 GILBERT STREET, SUITE 600

NORFOLK VA 23511-3392

18a. PAYMENT WILL BE MADE BY CODE

RATED ORDER UNDER

DPAS (15 CFR 700)

13a. THIS CONTRACT IS A

13b. RATING

CODE15. DELIVER TO CODE N3029A 16. ADMINISTERED BY

12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

14. METHOD OF SOLICITATION

RFQ IFB RFPX

NAVY CYBER DEFENSE OPERATIONS COMMAND

ALLISON FREEMAN

112 LAKE VIEW PARKWAY

SUFFOLK VA 23435-2488

TEL: 757-203-0597 FAX:

FAX:

TEL: 757-443-1449 SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

X 8(A)

HUBZONE SMALL

BUSINESS

SIZE STANDARD:

$12,000,000

NAICS:

611430

X

OFFER DATED

29. AWARD OF CONTRACT: REF.

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

EMAIL:

TEL:

31c. DATE SIGNED

SEE SCHEDULE

SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT

24.22.21.19.

WOMEN-OWNED SMALL BUSINESS (WOSB)

ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

PAGE 2 OF110

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 2/2012) BACK

Prescribed by GSA – FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

SEE SCHEDULE

20.

SCHEDULE OF SUPPLIES/ SERVICES

21.

QUANTITY UNIT

22. 23.

UNIT PRICE

24.

AMOUNT

19.

ITEM NO.

Section SF 1449 - CONTINUATION SHEET

PERFORMANCE WORK STATEMENT

PERFORMANCE WORK STATEMENT

1.0 BACKGROUND

The Navy Cyber Defense Operations Command (NCDOC) Cybersecurity Workforce Program Manager (CSWF- PM) and the N7 Training Department are responsible for administering, managing and facilitating the NCDOC Cybersecurity Workforce Qualification Program (CSWF-QP). The CWSF-QP is NCDOC’s development program designed to develop a highly skilled Department of the Navy Cybersecurity Workforce (CSWF) program. A common understanding of the cyber security concepts, principles and application for each Department of Defense (DOD) category, level and functions to enhance protection and availability of NCDOC information, information systems and networks. The CWSF-QP establishes baseline skills among personnel performing Cyberspace IT or Cybersecurity Workforce (Cyber IT/CSWF), Certification and Accreditation (C&A) and other IA related functions within the NCDOC domain.

NCDOC requires all of its personnel to meet or exceed the CSWF requirements outlined in the SECNAV M 5239.2.

All certifications under the SECNAV M 5239.2 require attaining and reporting Continuing Education Units (CEU);

this is accomplished by attending a minimum of 20 hours of CPE’s annually in the Cyber field according to the mandate of the SECNAV M-5239.2. Most, if not all, of the DON-approved Cyber IT/CSWF certifications have a Continuous learning (CL) requirement in order to remain certified. Certification agencies have various programs to describe their CL program (i.e., Continuous Education, Certification Maintenance Unit, CEU, etc.). The Cyber IT/CSWF member must hold and maintain their certification in accordance with the certification agency’s CL requirements.

NCDOC’s Training Department is responsible for providing the means for training for its personnel’s professional development through a Continuous Learning Program (CLP) that incorporates this type of course availability into its approved annual training budget and plan. Cyber Network Defense (CND) is defined as the actions taken to protect, monitor, analyze, detect and respond to unauthorized activity within DOD information systems and computer networks.

2.0 OBJECTIVE

The objective of this requirement is to provide high quality training services in support of NCDOC’s CND CLP program that will maintain personnel CND proficiency, and provide the necessary technical CPEs for advanced certification maintenance.

3.0 SCOPE

As a part of the CSWF-QP and CND CLP requirements, the training courses that are requested are a vital component to the program curriculum as it hones significant CND competency skills and qualifies personnel as effective members of the NCDOC CND-SP Team. The training program should provide the adult training mode and scheduling flexibility best suited to the adult training needs of NCDOC personnel, in a standard classroom setting when scheduled by NCDOC. As learning is an essential attribute of high-performing individuals and organizations, it is therefore, a critical concept in performance excellence. The course curriculum should all be ANSI and SECNAV M 5239.2 certified courses and built on the Office of Personnel Management (OPM)’s National Initiative for Cybersecurity Education (NICE) Cyber Core Competencies (CCCs): (1) Computer Network Defense, (2 Technology Awareness, (3) Vulnerabilities Assessment, (4) Infrastructure Design, (5) Information Assurance, and

(6) Information Systems/Network Security.

4.0 DEFINITIONS

ANSI – American National Standards Institute CCC- Cyber Core Competency CND – Cyber Network Defense CEU – Continuing Education Units CPE – Continuing Professional Education Credit GIG – Global Information Grid ISSM – Information Systems Security Manager

IAPM – Information Assurance Program Manager CWSF-QP - Cyber Workforce Qualification Program NCDOC – Navy Cyber Defense Operation Command NICE – National Initiative on Cyber Education

5.0 SPECIFIC PERFORMANCE REQUIREMENTS AND TASKS

5.1 – NCDOC Training Account. The NCDOC Training Account should be continuously updated to reflect the training funds invested and be managed by the NCDOC N7 Training Department.

5.1.1 Program Core Curriculum

Core Curriculum should at the minimum consist of the following courses of interest:

A. Certification Courses

a. EC-Councils’ Certified Ethical Hacker (CEH)/Network Forensic Analysis (NFA)

b. CompTIA Security+

c. CompTIA LINUX+

d. CompTIA Network+

e. Cisco Certified Network Associate (CCNA)

f. Computer Hacking Forensic Investigator (CHFI)

g. Certified Penetration Testing Professional (CPENT)

h. EC-Councils’ Certified Ethical Hacker (CEH)

The Government anticipates 6 classes per year with a minimum of 90 students per year. Additional courses shall be available as validated via the N7 Training Department based on individual requirement and the operational necessity.

6.0 DELIVERABLES

1) Training Account

a) The Contractor shall provide on-line secure account registrations for NCDOC Training Department to access and request class vouchers from the Training Account.

b) The Contractor shall inform NCDOC Training Department of courses available and any changes or updates to the curriculums of courses available.

c) The Contractor shall provide the courses to approved participants in traditional scheduled classroom on the dates agreed upon between the Training Department and the Contractor.

2) Command and Control – The contractor shall provide an automated means for controlling courses offered, and limiting the approval of course requested by NCDOC to the designated Training Department person and his/her designated Alternate.

3) The Contractor will inform the Training Department of Courses Requested, Completed, and Exam Status.

PROPOSED COURSE SCHEDULE

The proposed training dates for required courses as outlined in the PWS for the period of September 30, 2022 through September 29, 2023. Yearly schedules shall be provided at option exercise.

CompTIA Network+:

10/31/22 – 11/04/22, 11/28/22 - 12/02/22, 02/28/23 – 03/04/23, 04/11/23 – 04/15/23, 08/22/23 – 08/26/23

Cisco Certified Network Associate (CCNA) Instructor-Led Classroom Instruction with Exam Prep:

01/31/23 – 02/04/23, 03/21/23 – 03/25/23, 06/06/23 – 06/10/23, 08/29/23 – 09/02/23

Certified Penetration Testing Professional (CPENT) Instructor-Led Classroom Instruction with Exam Prep:

11/14/22 – 11/18/23, 01/17/2023 – 01/21/23, 05/31/23 – 06/03/23, 09/06/23 – 09/09/23

EC-Council Certified Ethical Hacker with Network Forensic Analyst (NFA) Combo Course:

12/12/22 – 12/16/22, 01/24/23 – 01/28/23, 02/07/23 – 02/11/23, 03/14/23 – 03/18/23, 05/09/23 – 05/13/23, 06/20/23 – 06/24/23, 08/01/23 – 08/05/23, 09/26/23 – 09/30/23

EC-Council Certified Hacking Forensic Investigator (ChFI) Classroom Instruction with Exam Prep:

01/31/22 – 02/04/23, 02/14/23 – 02/18/23, 05/23/23 – 05/27/23, 08/08/23 – 08/12/23

EC-Council Certified Ethical Hacker (CEH) Classroom Instruction with Exam Prep:

10/17/22 - 10/21/22, 12/05/22 – 12/09/22, 01/31/22 – 02/04/23, 03/07/23 – 03/11/23, 04/04/23 – 04/08/23, 05/02/23 – 05/06/23, 06/20/23 – 06/24/23, 07/25/23 – 07/29/23

CompTIA Linux+ LPI 004 Instructor-Led Classroom Instruction with Exam Prep:

10/03/22 - 10/07/22, 01/10/23 – 01/14/23, 04/18/23 – 04/22/23, 06/20/23 – 06/24/23, 09/26/23 – 09/30/23

CompTIA Security+ 601 Classroom Instruction with Exam Prep:

10/03/22 -10/07/22, 10/24/22 – 10/28/22, 11/14/22 – 11/18/22, 12/19/22 – 12/23/22, 01/03/23 – 01/07/23, 01/24/23 – 01/28/23, 02/14/23 – 02/18/23, 03/07/23 – 03/11/23, 03/28/23 – 04/01/23, 05/16/23 – 05/20/23, 06/06/23 – 06/10/23, 06/27/23 - 07/01/23, 07/25/23 – 07/29/23, 08/01/23 – 08/05/23, 08/15/23 – 08/19/23, 09/12/23 – 09/16/23

7.0 TRAVEL

There will be no travel requirements for this PWS.

8.0 SECURITY

Performance of this task is UNCLASSIFIED. An interaction with the Training account is limited to accessing a secure commercial website through a User account based on the NCDOC Training Department e-mail account.

9.0 Contractor Unclassified Access to Federally Controlled Facilities, Sensitive Information, Information Technology (IT) Systems or Protected Health Information

Executive Order 13467, Reforming Processes Related to Suitability for Government Employee, Fitness for Contractor Employees and Eligibility for Access to Classified National Security Information, Homeland Security Presidential Directive (HSPD)-12, requires government agencies to develop and implement Federal security standards for Federal employees and contractors. The 5 CFR 32 Part 157 in concert with DoD Manual 1000.13, Vol 1, implements the Federal Standards.

APPLICABILITY

This text applies to all DoD sponsored individuals who require CAC eligibility (or login and P/W if acceptable per contract) for: Physical access to DoD facilities or non-DoD facilities on behalf of DoD; Logical access to information systems (whether on site or remotely); or remote access to DoD networks that use only the CAC logon for user authentication, or access to sensitive and protected information. This applies to the Office of the Secretary of Defense (OSD), the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the DoD, the Defense Agencies, the DoD Field Activities and all other organizational entities within the DoD (hereinafter referred to collectively as the "DoD Components").

Each contractor employee providing services at a Navy command under this contract is required to obtain a DoD CAC. Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.

ACCESS TO FEDERAL FACILITIES

Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this clause will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Command's Security Manager (CSM) upon arrival to the command and shall out-process prior to their departure at the completion of the individual's performance under the contract.

START-UP PERIOD

All contractor resource onboarding documents must be submitted via the prime contractor. The prime contractor shall make all necessary preparations to assume full responsibility for productive performance as of the performance start date.

Definition of “productive”:

a. Visit Authorization Request (VAR)

b. Contractor Information Sheet (CIS)

c. FD-258 Fingerprint Card

d. Completed Electronic Investigation (EQIP)

e. All contractor resource(s) must have an active Joint Personnel Adjudication System (JPAS) profile

f. Common Access Card(CAC)

Note (1): Invoicing by the contractor will begin as of the commencement of the performance period of services and no reimbursement will be paid by the government for efforts expended during the start-up period.

Note (2): Foreign Nationals are not allowed access to the functional/system side of Enterprise Resource Planning

(ERP).

12.0 ACCESS TO DOD INFORMATION TECHNOLOGY (IT) SYSTEM

In Accordance With (IAW) Secretary of the Navy (SECNAV) M-5510.30, contractor employees who require access to Department of the Navy (DoN) or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to sensitive information. Sensitive information includes information protected under the Privacy Act, to include PHI. All contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than IT-II.

IT Levels are determined by the requiring activity's Command Information System Security Manager (ISSM)/Information Assurance Manager (IAM).

Contractor employees requiring privileged or IT-I level access, (when specified by the terms of the contract) require a Single Scope Background Investigation (SSBI) or T5 or T5R equivalent investigation, which is a higher level investigation than the National Agency Check (NAC) with Law and Credit (NACLC)/T3/T3R described below. Due to the privileged system access, an investigation suitable for High Risk national security positions is required.

Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance (IA) Technical Level 1, and must be trained and certified on the Operating System (OS) or Computing Environment (CE) they are required to maintain.

Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to IT systems is required for performance of the contractor employee's duties, such employees shall in-process with the Navy CSM and ISSM/IAM manager upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual's performance under the contract. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy IT resources. The decision to authorize access to a government IT system/network is inherently governmental. The contractor supervisor is not authorized to sign the SAAR-N; therefore, the government employee with knowledge of the system/network access required or the Contracting Officers Representative (COR) shall sign the SAAR-N as the supervisor.

The SAAR-N shall be forwarded to the CSM at least thirty (30) days prior to the individual's start date. Failure to provide the required documentation at least thirty (30) days prior to the individual's start date may result in delaying the individual's start date.

When required to maintain access to required IT systems or networks, the contractor shall ensure that all employees requiring access complete annual Cyber Awareness training, and maintain a current requisite background investigation. The contractor's security representative shall contact the CSM for guidance when reinvestigations are required.

INTERIM ACCESS

The CSM may authorize issuance of a DoD CAC and interim access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.

DENIAL OR TERMINATION OF ACCESS

The potential consequences of any requirement under this clause including denial or termination of physical or system access in no way relieves the contractor from the requirement to execute performance under the contract within the timeframes specified in the contract. Contractors shall plan ahead in processing their employees and subcontractor employees. The contractor shall insert this clause in all subcontracts when the subcontractor is permitted to have unclassified access to a federally controlled facility, federally-controlled information system/network and/or to government information, meaning information not authorized for public release.

CONTRACTOR'S SECURITY REPRESENTATIVE

The contractor shall designate an employee to serve as the contractor's security representative. Within three (3) work days after contract award, the contractor shall provide to the requiring activity's Security Manager and the Contracting Officer, in writing, the name, title, address and phone number for the contractor's security representative. The contractor's security representative shall be the primary point of contact on any security matter.

The contractor's security representative shall not be replaced or removed without prior notice to the Contracting Officer and CSM.

BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR

CONTRACTORS ASSIGNED TO NATIONAL SECURITY POSITIONS OR PERFORMING SENSITIVE

DUTIES

Navy security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Contractor employees under this contract are recognized as Non- Critical Sensitive [ADP/IT-II] positions when the contract scope of work require physical access to a federally controlled base, facility or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to contractor employees who access Privacy Act and PHI, provide support associated with fiduciary duties, or perform duties that have been identified as National Security Positions.

At a minimum, each contractor employee must be a US citizen and have a favorably completed NACLC or T3 or T3R equivalent investigation to obtain a favorable determination for assignment to a non-critical sensitive or IT-II position. The investigation consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. Each contractor employee filling a non-critical sensitive or IT-II position is required to complete:

SF-86 Questionnaire for National Security Positions (or equivalent Office of Personnel Management (OPM) investigative product)

Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission

Original Signed Release Statements

Failure to provide the required documentation at least thirty (30) days prior to the individual's start date shall result in delaying the individual's start date. Background investigations shall be reinitiated as required to ensure investigations remain current (not older than ten (10) years) throughout the contract performance period. The contractor's security representative shall contact the CSM for guidance when reinvestigations are required.

Regardless of their duties or IT access requirements ALL contractor employees shall in-process with the CSM upon arrival to the command and shall out-process prior to their departure at the completion of the individual's performance under the contract. Employees requiring IT access shall also check-in and check-out with the Navy command's ISSM/IAM. Completion and approval of a SAAR-N form is required for all individuals accessing Navy IT resources. The SAAR-N shall be forwarded to the Navy CSM at least thirty (30) days prior to the individual's start date. Failure to provide the required documentation at least thirty (30) days prior to the individual's start date shall result in delaying the individual's start date.

The contractor shall ensure that each contract employee requiring access to IT systems or networks complete annual Cyber Awareness training, and maintain a current requisite background investigation. Contractor employees shall accurately complete the required investigative forms prior to submission to the CSM. The CSM will review the submitted documentation for completeness prior to submitting it to the OPM; Potential suitability or security issues identified may render the contractor employee ineligible for the assignment. An unfavorable determination is final (subject to SF-86 appeal procedures) and such a determination does not relieve the contractor from meeting any contractual obligation under the contract. The CSM will forward the required forms to OPM for processing. Once the investigation is complete, the results will be forwarded by OPM to the DoD Central Adjudication Facility (CAF) for a determination.

If the contractor employee already possesses a current favorably adjudicated investigation, the contractor shall submit a VAR via the JPAS or a hard copy VAR directly from the contractor's security representative. Although the contractor will take JPAS owning role over the contractor employee, the Navy command will take JPAS "Servicing" role over the contractor employee during the hiring process and for the duration of assignment under that contract.

The contractor shall include the IT position category per SECNAV M-5510.30 for each employee designated on a VAR. The VAR requires annual renewal for the duration of the employee's performance under the contract.

BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR

CONTRACTORS ASSIGNED TO OR PERFORMING NON-SENSITIVE DUTIES

Contractor employee whose work is unclassified and non-sensitive (e.g., performing certain duties such as lawn maintenance, vendor services, etc...) and who require physical access to publicly accessible areas to perform those duties shall meet the following minimum requirements:

Must be either a U.S. citizen or a U.S. permanent resident with a minimum of 3 years of legal residency in the U.S.

(as required by the Deputy Secretary of Defense DTM 08-006 or its subsequent DoD Instruction (INST)) and

Must have a favorably completed NACI or T1 investigation equivalent including a FBI fingerprint check prior to installation access.

To be considered for a favorable trustworthiness determination, the CSR must submit for all employees each of the following:

SF-85 Questionnaire for Non-Sensitive Positions

Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)

Original Signed Release Statements

The contractor shall ensure each individual employee has a current favorably completed NACI or T1 equivalent investigation, or ensure successful FBI fingerprint results have been gained and investigation has been processed with OPM.

Failure to provide the required documentation at least thirty (30) days prior to the individual's start date may result in delaying the individual's start date.

* Consult with your CSM and ISSM/IAM for local policy when IT-III (non-sensitive) access is required for non- U.S. citizens outside the U.S..*

**Alternative language which may be included as appropriate:

Contractor and all Contractor personnel with access to or responsibility for XXXXXX of this contract shall comply with DoD Directive 8500.1E IA, DoDI 8510.01 Risk Management Framework (RMF) for DoD IT, DoD Directive

5400.11 DoD Privacy Program, DoD 5200.2-R Personnel Security Program and HSPD 12.

X.1 Be CAC ready at the IT Level II prior to reporting for work.

X.2 At minimum, all contractor personnel must possess/maintain a favorable Tier 3 investigation; formerly a NAC with Local Agency Check and Credit Check (NACLC). This requirement is critical in order to access the data base systems within NAVSUP. It is Contracting Companies; responsibility to ensure that 100% of the contractors have the Tier 3 investigation/IT Level II. In addition, interim approval of clearances is not authorized.

X.3 Be citizens of the U.S.

X.4 If at any time, any contractor person requiring a CAC is unable to possess/maintain an adjudicated Tier 3 investigation, the contractor shall immediately notify the NAVSUP COR to coordinate removal of such a person from work under this contract.

X.5 Contractor personnel with access to or responsibility for nonpublic government data under this contract must comply with HSPD-12 Personal Identity Verification (PIV) issuance requirements, known as the CAC for

NAVSUP.

10.0 AUTHORIZED CHANGES ONLY BY THE CONTRACTING OFFICER

(a) Except as specified in paragraph (b) below, no order, statement, or conduct of Government personnel who visit the Contractor's facilities or in any other manner communicate with Contractor personnel during the performance of this contract shall constitute a change under the "Changes" clause of this contract.

(b) The Contractor shall not comply with any order, direction or request of Government personnel unless it is issued in writing and signed by the Contracting Officer, or is pursuant to specific authority otherwise included as a part of this contract.

(c) The Contracting Officer is the only person authorized to approve changes in any of the requirements of this contract and notwithstanding provisions contained elsewhere in this contract, the said authority remains solely with the Contracting Officer. In the event the Contractor effects any change at the direction of any person other than the Contracting Officer, the change will be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in charges incurred as a result thereof. The address and telephone number of the Contracting Officer is:

NAME: Elizabeth Phelps ADDRESS: 1968 Gilbert Street, Suite 600, Norfolk, VA 23511-3392

TELEPHONE: (757)443-1326

NAVSUP FLCN may utilize contractor support through the AbilityOne Program, as needed, to perform contract closeout functions for this acquisition. Information, including business sensitive/confidential or proprietary data, that the offeror provides to the Government or information already in the possession of the Government may be viewed and utilized by the AbilityOne Program support contractor personnel during the course of its contract performance.

The information that may be made available to the support contractor may include, for example, pricing and technical proposals, historical contract, pricing and performance information, Commercial Asset Visibility (CAV) reporting information and similar data/information.

By submission of a proposal in response to this solicitation, the offeror and its subcontractors consent to a release of their business sensitive/confidential or proprietary data to the Government's AbilityOne Program support contractor personnel in order to perform close out services. Prior to the release of any such information to the support contractor, the support contractor will have in place with the Government a Non-Disclosure/Non-Use Agreement in accordance with the terms of the AbilityOne Program support contract.

Offerors may execute their own Non-Disclosure Agreement with the AbilityOne Program (AbilityOne contact information available from the contracting point of contact). The support contractor must provide copies of the executed agreements to the Contracting Officer and the Contracting Officer's Representative (COR) for the support contract; and the offeror/contractor for this acquisition must provide copies of the executed Agreement to the Contracting Officer for this acquisition. If the offeror/contractor seeks such a Non-Disclosure Agreement with the AbilityOne Program support contractor, the Agreement must be executed no later than the date of final delivery under the resulting NAVSUP FLCN contract.

QASP

QUALITY ASSURANCE SURVEILLANCE PLAN (QASP) AND MATRIX

1.0 PURPOSE

This Quality Assurance Surveillance Plan (QASP) is a Government developed and applied document used to make sure that systematic quality assurance methods are used in the administration of the Performance Based Service Contract (PBSC) standards included in this contract. The intent is to ensure that the Contractor performs in accordance with performance metrics set forth in the contract documents, that the Government receives the quality of services called for in the contract and that the Government only pays for the acceptable level of services received.

2.0 AUTHORITY

Authority for issuance of this QASP is provided under FAR 52-212-4(a), Inspection/Acceptance, which provides for inspections and acceptance of the articles, services, and documentation called for in the contract to be accomplished by the Contracting Officer or their duly authorized representative.

3.0 SCOPE

The Contractor, and not the Government, is responsible for management and quality control actions necessary to meet quality standards set forth by the contract. The QASP is put in place to provide Government surveillance oversight of the Contractor’s quality control efforts to assure that they are timely, effective and are delivering the results specified in the contract. The QASP is not a part of the contract nor is it intended to duplicate the Contractor’s Management Plan. The Government may provide the Contractor an information copy of the QASP as an Attachment to the solicitation to support the Contractor’s efforts in developing its plan for maintaining the levels of quality anticipated to be delivered under the terms of the contract.

4.0 RESPONSIBILITIES

The Government resources shall have responsibilities for the implementation of this QASP as follows:

Contracting Officer – The Contracting Officer ensures performance of all necessary actions for effective contracting, ensures compliance with the terms of the contract and safeguards the interests of the United States in the contractual relationship. It is the Contracting Officer that assures the Contractor receives impartial, fair and equitable treatment under the contract. The Contracting Officer is ultimately responsible for the final determination of the adequacy of the Contractor’s performance.

Contracting Officer’s Representative (COR) – An individual designated in writing by the Contracting Officer to act as his authorized representative to assist in administering a contract. The source and authority for the COR is the Contracting Officer. COR limitations are contained in the written letter of appointment.

5.0 METHODS OF QA SURVEILLANCE

The below listed methods of surveillance shall be used in the administration of this QASP. The QASP Matrix describes the methods of surveillance that may be used to monitor the services and deliverables to be provided under the contract.

Customer Feedback – Customer feedback may be obtained either from the results of formal customer satisfaction surveys or from random customer complaints. Customer complaints, to be considered valid, must set forth clearly and in writing the detailed nature of the complaint, must be signed and must be forwarded to the Contractor. The Contractor shall maintain a summary log of all formally received customer complaints as well as a copy of each complaint in a documentation file.

Random Checks/Inspections – Random checks will be conducted to ensure compliance with the Standard Operating Procedures (SOP). The CO or Technical Point of Contact (TPOC) will conduct the random monitoring.

Exam Passing Rates – Checks will be conducted to ensure reasonable passing rates of exams are accomplished. The CO or Technical Point of Contact (TPOC) will conduct the data collection to monitor the passing exam rate.

6.0 IDENTIFIED QA SURVEILLANCE ITEMS

The PBSC items that have been identified for surveillance are identified in the Performance Work Statement (PWS).

1.2.3 Elements of the PWS will be monitored in the QASP for the following positions and based upon the job descriptions as listed in the QASP:

Provide on-line secure account registrations for NCDOC Training Department to access and request class seats utilizing an online account that tracks all spending.

Provide the courses to approved participants in the training modality selected: Online Virtual Classroom, Online On-Demand, or traditional scheduled classroom at a conference setting.

Provide an automated means for controlling courses offered, and limiting the approval of course attendance/seats requested by NCDOC to the designated Training Department person and his/her designated Alternate.

Inform the Training Department of Courses Requested, Completed, Grades of Students, and Exam Status.

N0018922Q0070

QASP Matrix

INCENTIVES/DISINCENTIVES:

The COR makes an annual report on Contractor Performance (CPARS or other annual report). The contractor’s failure to achieve satisfactory performance under the contract, reflected in the COR’s annual report, may result in termination of the contract and may also result in the loss of future Government contracts. Additionally, the contractor’s failure to achieve satisfactory performance under the contract may also result in the non-exercise of available options.

For each item that does not meet acceptable levels, the Government may issue a Contract Discrepancy Report (CDR).

CDRs will be forwarded to the Contracting Officer with a copy sent to the contractor. The contractor must reply in writing within 5 days of receipt identifying how future occurrences of the problem will be prevented. Based upon the contractor’s past performance and plan to solve the problem, the Contracting Officer will determine if any further action will be taken.

CAP FFP

CONTRACT ADMINISTRATION PLAN (CAP)

FOR FIXED PRICE CONTRACTS

In order to expedite the administration of this contract, the following delineation of duties is provided. The names, addresses and phone numbers for these offices or individuals are included elsewhere in the contract award document. The office or individual designated as having responsibility should be contacted for any questions, clarifications, or information regarding the administration function assigned.

1. The Procuring Contract Office (PCO) is responsible for:

a. All pre-award duties such as solicitation, negotiation and award of contracts.

b. Any information or questions during the pre-award stage of the procurement.

c. Freedom of Information inquiries.

d. Changes in contract terms and/or conditions.

e. Post award conference.

2. The Contract Administration Office (CAO) is responsible for matters specified in the FAR 42.302 and DFARS

42.302 except those areas otherwise designated as the responsibility of the Contracting Officer's Representative (COR) or someone else herein.

3. The paying office is responsible for making payment of proper invoices after acceptance is documented.

4. The Contracting Officer's Representative (COR) is responsible for interface with the contractor and performance of duties such as those set forth below. It is emphasized that only the PCO/CAO has the authority to modify the terms of the contract. In no event will any understanding, agreement, modification, change order, or other matter deviating from the terms of the basic contract between the contractor and any other person be effective or binding on the Government. If in the opinion of the contractor an effort outside the scope of the contract is requested, the

Performance Element

Performance Requirement Method of

Surveillance

Frequency

Acceptable Quality Level

(AQL)

Procedures to be taken when performance standards are not met

Resource FTE

Provide online secure account

Provide secure online, secure account for account management

File reviews, periodic inspections, and random observations, and customer complaints

99%

FAR Clause 52.212-4(a) Inspection/Acceptance

Provide courses as selected by NCDOC

Provide courses as scheduled

Periodic inspections, random observations, and customer complaints

99%

Inform NCDOC of course completion and Exam Status

Completion of course

Exam Status

File reviews, periodic inspections, and random observations, and required reports

99%

CTIP Compliance

Compliance with FAR 52.222-50, Combating Trafficking in Persons

Inspection by the COR 100% contractor shall promptly notify the PCO in writing. No action may be taken by the contractor unless the PCO or CAO has issued a contractual change. The COR duties are as follows:

a. Technical Interface

(1) The COR is responsible for all Government technical interface concerning the contractor and furnishing technical instructions to the contractor. These instructions may include: technical advice/recommendations/clarifications of specific details relating to technical aspects of contract requirements;

milestones to be met within the general terms of the contract or specific subtasks of the contract; or, any other interface of a technical nature necessary for the contractor to perform the work specified in the contract. The COR is the point of contact through whom the contractor can relay questions and problems of a technical nature to the PCO.

(2) The COR is prohibited from issuing any instruction which would constitute a contractual change.

The COR shall not instruct the contractor how to perform. If there is any doubt whether technical instructions contemplated fall within the scope of work, contact the PCO for guidance before transmitting the instructions to the contractor.

b. Contract Surveillance

(1) The COR shall monitor the contractor's performance and progress under the contract. In performing contract surveillance duties, the COR should exercise extreme care to ensure that he/she does not cross the line of personal services. The COR must be able to distinguish between surveillance (which is proper and necessary) and supervision (which is not permitted). Surveillance becomes supervision when you go beyond enforcing the terms of the contract. If the contractor is directed to perform the contract services in a specific manner, the line is being crossed. In such a situation, the COR's actions would be equivalent to using the contractor's personnel as if they were government employees and would constitute transforming the contract into one for personal services.

(2) The COR shall monitor contractor performance to see that inefficient or wasteful methods are not being used. If such practices are observed, the COR is responsible for taking reasonable and timely action to alert the contractor and the PCO to the situation.

(3) The COR will take timely action to alert the PCO to any potential performance problems. If performance schedule slippage is detected, the COR should determine the factors causing the delay and report them to the PCO, along with the contractor's proposed actions to eliminate or overcome these factors and recover the slippage. Once a recovery plan has been put in place, the COR is responsible for monitoring the recovery and keeping the PCO advised of progress.

(4) If the Contractor Performance Assessment Reporting System (CPARS) is applicable to the contract you are responsible for completing a Contractor Performance Assessment Report (CPAR) in the CPARS Automated Information System (AIS). The initial CPAR, under an eligible contract, must reflect evaluation of at least 180 days of contractor performance. The completed CPAR, including contractor comments if any, (NOTE: contractors are allowed 30 days to input their comments) should be available in the CPARS AIS for reviewing official (PCO) review no later than 270 days after start of contract performance. Subsequent CPARs covering any contract option periods should be ready at 1-year intervals thereafter.

c. Invoice Review and Approval/Inspection and Acceptance

(1) The COR is responsible for quality assurance of services performed and acceptance of the services or deliverables. The COR shall expeditiously review copies of the contractor's invoices or vouchers, certificate of performance and all other supporting documentation to determine the reasonableness of the billing. In making this determination, the COR must take into consideration all documentary information available and any information developed from personal observations.

(2) The COR must indicate either complete or partial concurrence with the contractor's invoice/voucher by executing the applicable certificate of performance furnished by the contractor. The COR must be cognizant of the invoicing procedures and prompt payment due dates detailed elsewhere in the contract.

(3) The COR will provide the PCO and the CAO with copies of acceptance documents such as Certificates of Performance.

(4) The COR shall work with the Contractor to obtain and execute a final invoice no more than 60 days after completion of contract performance. The COR shall ensure that the invoice is clearly marked as a “Final Invoice.”

d. Contract Modifications. The COR is responsible for developing the statement of work for change orders or modifications and for preparing an independent government cost estimate of the effort described in the proposed statement of work.

e. Administrative Duties

(1) The COR shall take appropriate action on technical correspondence pertaining to the contract and for maintaining files on each contract. This includes all modifications, government cost estimates, contractor invoices/vouchers, certificates of performance, DD 250 forms and contractor's status reports.

(2) The COR shall maintain files on all correspondence relating to contractor performance, whether satisfactory or unsatisfactory, and on trip reports for all government personnel visiting the contractor's place of business for the purpose of discussing the contract.

(3) The COR must take prompt action to provide the PCO with any contractor or technical code request for change, deviation or waiver, along with any supporting analysis or other required documentation.

f. Government Furnished Property. When government property is to be furnished to the contractor, the COR will take the necessary steps to insure that it is furnished in a timely fashion and in proper condition for use. The COR will maintain adequate records to ensure that property furnished is returned and/or that material has been consumed in the performance of work.

g. Security. The COR is responsible for ensuring that any applicable security requirements are strictly adhered to.

h. Standards of Conduct. The COR is responsible for reading and complying with all applicable agency standards of conduct and conflict of interest instructions.

i. Written Report/Contract Completion Statement.

(1) The COR is responsible for timely preparation and submission to the PCO, of a written, annual evaluation of the contractors performance. The report shall be submitted within 30 days prior to the exercise of any contract option and 60 days after contract completion. The report shall include a written statement that services were received in accordance with the Contract terms and that the contract is now available for close-out. The report shall also include a statement as to the use made of any deliverables furnished by the contractor.

(2) If the Contractor Performance Assessment Reporting System (CPARS) is applicable to the contract you are responsible for completing a final Contractor Performance Assessment Report (CPAR) in the CPARS with 30 days of contract completion.

(3) The COR is responsible for providing necessary assistance to the Contracting Officer in performing Contract Close-out in accordance with FAR 4.804, Closeout of Contract Files.

5. The Technical Assistant (TA), if appointed, is responsible for providing routine administration and monitoring assistance to the COR. The TA does not have the authority to provide any technical direction or clarification to the contract. Duties that may be performed by the TA are as follows:

a. Identify contractor deficiencies to the COR.

b. Review contract deliverables, recommend acceptance/rejection, and provide the COR with documentation to support the recommendation.

c. Assist in preparing the final report on contractor performance for the applicable contract in accordance with the format and procedures prescribed by the COR.

d. Identify contract noncompliance with reporting requirements to the COR.

e. Review contractor status and progress reports, identify deficiencies to the COR, and provide the COR with recommendations regarding acceptance, rejection, and/or Government technical clarification requests.

f. Review invoices and provide the COR with recommendations to facilitate COR certification of the invoice.

g. Provide the COR with timely input regarding technical clarifications for the statement of work, possible technical direction to provide the contractor, and recommend corrective actions.

h. Provide detailed written reports of any trip, meeting, or conversation to the COR subsequent to any interface between the TA and contractor.

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 5 Each CompTIA Network+ (001)

FFP

FOB: Destination

PSC CD: U012

NET AMT

0002 4 Each Cisco Certified Network Associate (CCNA)

FFP

Cisco Certified Network Associate (CCNA) Instructor-Led Classroom Instruction with Exam Prep.

0003 6 Each Certified Penetration Testing

FFP

Certified Penetration Testing Professional (CPENT) Instructor-Led Classroom Instruction with Exam Prep.

0004 70 Each EC-Council Certified Ethical Hacker

FFP

EC-Council Certified Ethical Hacker with Network Forensic Analyst (NFA) Combo Course.

0005 5 Each EC-Council Certified Hacking Forensic

FFP

EC-Council Certified Hacking Forensic Investigator (ChFI) Classroom Instruction with Exam Prep.

0006 24 Each EC-Council Certified Ethical Hacker

FFP

EC-Council Certified Ethical Hacker (CEH) Classroom Instruction with Exam Prep.

0007 28 Each CompTIA Linux+

FFP

CompTIA Linux+ LPI 004 Instructor-Led Classroom Instruction with Exam Prep.

0008 30 Each CompTIA Security+

FFP

CompTIA Security+ 601 Classroom Instruction with Exam Prep.

0009 8 Each EC Council Certified Ethical Hacker

FFP

EC Council Certified Ethical Hacker (CEH) exam voucher.

0010 3 Each Cisco CCNA Exam Vouchers

FFP

0011 8 Each CompTIA LX0 (004) Exam Vouchers

FFP

0012 2 Each CompTIA SY0-601 Exam Vouchers

FFP

1001 5 Each OPTION CompTIA Network+ (001)

FFP

1002 4 Each OPTION Cisco Certified Network Associate (CCNA)

FFP

Cisco Certified Network Associate (CCNA) Instructor-Led Classroom Instruction with Exam Prep.

1003 6 Each OPTION Certified Penetration Testing

FFP

Certified Penetration Testing Professional (CPENT) Instructor-Led Classroom Instruction with Exam Prep.

1004 70 Each OPTION EC-Council Certified Ethical Hacker

FFP

EC-Council Certified Ethical Hacker with Network Forensic Analyst (NFA) Combo Course.

1005 5 Each OPTION EC-Council Certified Hacking Forensic

FFP

EC-Council Certified Hacking Forensic Investigator (ChFI) Classroom Instruction with Exam Prep.

1006 24 Each OPTION EC-Council Certified Ethical Hacker

FFP

EC-Council Certified Ethical Hacker (CEH) Classroom Instruction with Exam Prep.

1007 28 Each OPTION CompTIA Linux+

FFP

CompTIA Linux+ LPI 004 Instructor-Led Classroom Instruction with Exam Prep.

1008 30 Each OPTION CompTIA Security+

FFP

CompTIA Security+ 601 Classroom Instruction with Exam Prep.

1009 8 Each OPTION EC Council Certified Ethical Hacker

FFP

EC Council Certified Ethical Hacker (CEH) exam voucher.

1010 3 Each OPTION Cisco CCNA Exam Vouchers

FFP

1011 8 Each OPTION CompTIA LX0 (004) Exam Vouchers

FFP

1012 2 Each OPTION CompTIA SY0-601 Exam Vouchers

FFP

2001 5 Each OPTION CompTIA Network+ (001)

FFP

2002 4 Each OPTION Cisco Certified Network Associate (CCNA)

FFP

Cisco Certified Network Associate (CCNA) Instructor-Led Classroom Instruction with Exam Prep.

2003 6 Each OPTION Certified Penetration Testing

FFP

Certified Penetration Testing Professional (CPENT) Instructor-Led…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .