2.2.1 70FBR626Q00000006.pdf

PDF 364 KB Posted

Attached to
NMJRO Janitorial Service Federal contract opportunity
Solicitation number
70FBR626Q00000006
Issued by
Federal Emergency Management Agency

About this file

Solicitation Summary

This is a Request for Quote (RFQ) for janitorial services issued by the Federal Emergency Management Agency (FEMA) Region VI in support of the New Mexico Joint Recovery Office (NMJRO). The solicitation number is 70FBR626Q00000006, issued on 03/26/2026, with quotations due by 10:00 a.m. Central Time on 04/10/2026. The contracting officer is Michael Bonds (202-257-8893; michael.bonds@fema.dhs.gov), and the solicitation incorporates FAR provisions 52.212-1, 52.212-4, and 52.212-5.

The janitorial services are required for the NMJRO facility located at 1712 St. Michaels Drive, Santa Fe, New Mexico 87505, covering a building area of 94,829 square feet. The base contract period is three months, with two option periods (three months and two months respectively) for a potential total of eight months. The Government estimates the total value for the base period at $27,600.00 to $28,000.00, with an eight-month total estimated value between $73,700.00 and $74,700.00. This is a Total Small Business Set-Aside under NAICS code 561720 (Janitorial Services) with a $22.0 million size standard, with local area preference given to firms in disaster-declared counties (Lincoln, Dona Ana, Otero, and Mescalero Reservation) under the Stafford Act, where a 10 percent price evaluation factor applies to non-local offerors. Award will be made on a firm-fixed-price basis to the offeror providing the best value considering price, technical merit, and prior experience. Offerors must submit three professional references and demonstrate understanding of the Statement of Work, including equipment specifications, staff supervision plans, quality assurance processes, and supply management procedures. Service Contract Labor Standards apply per wage determination 2015-5449 (Revision 27; 12/03/2025).

View the file

Other files for this federal contract opportunity

Other files attached to NMJRO Janitorial Service, newest first.
File Type Posted
Questions and Answers.docx DOCX document
Statement of Work Janitorial Services Contract..pdf PDF
2.2.1 Disaster Area Representation - Solicitation 70FBR625Q00000019.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

WOMEN-OWNED SMALL

BUSINESS (WOSB)

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

1. REQUISITION NUMBER PAGE 1 OF

2. CONTRACT NUMBER 3.AWARD/EFFECTIVE

DATE

4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE

DATE

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME b. TELEPHONE NUMBER (No collect calls)

8. OFFER DUE DATE/

LOCAL TIME

9. ISSUED BY

13b. RATING

14. METHOD OF SOLICITATION

CODE

15. DELIVER TO 16. ADMINISTERED BY CODE

18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/

OFFEROR

CODE

FACILITY

CODE

CODE

TELEPHONE NUMBER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

REQUEST

FOR QUOTE

(RFQ)

INVITATION

FOR BID

(IFB)

REQUEST

FOR

PROPOSAL

(RFP)

SEE ADDENDUM

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN 29. AWARD OF CONTRACT: REFERENCE

. YOUR OFFER ON SOLICITATION

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA - FAR (48 CFR) 53.212

10. THIS ACQUISITION IS UNRESTRICTED OR

NORTH AMERICAN

INDUSTRY CLASSIFICATION

STANDARD (NAICS):

SIZE STANDARD:

13a. THIS CONTRACT IS A

RATED ORDER UNDER

THE DEFENSE PRIORITIES

AND ALLOCATIONS

SYSTEM - DPAS (15 CFR 700)

SET ASIDE: % FOR:

11. DELIVERY FOR FREE ON

BOARD (FOB) DESTINATION

UNLESS BLOCK IS MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

ARE ARE NOT ATTACHED

ARE ARE NOT ATTACHED

27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4.

FAR 52.212-3 AND 52.212-5 ARE ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED.

8(A)

ECONOMICALLY

DISADVANTAGED

WOMEN-OWNED SMALL

BUSINESS (EDWOSB)

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

(SDVOSB)

HUBZONE SMALL

BUSINESS

SMALL BUSINESS

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30.

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH

AND DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND

ON ANY ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS

SPECIFIED

DATED.

OFFER

ADDENDA

ADDENDA

70FBR626Q00000006

FEMA REGION 06

DHSFEMA

REGION VI 800 NORTH LOOP 288

DENTON TX 76209-3606

FEMA REGION 06

DHSFEMA

REGION VI 800 NORTH LOOP 288

DENTON TX 76209-3606

04/10/2026 1000 CT

Michael Bonds 202-257-8893

70FBR6 100.00

70FBR6

Michael Bonds

561720

$22

03/26/2026

The purpose of this solicitation is to request a quotation for janitorial services in support of NMJRO. This is a combined synopsis/solicitation for commercial services prepared in accordance Revolutionary FAR

Continued...

STOCK RECORD (S/R)

STANDARD FORM 1449 (REV. 11/2021) BACK

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE RECEIVED (MM/DD/YYYY) 42d. TOTAL CONTAINERS

40. PAID BY

32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32g. EMAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED

CORRECT FOR

PARTIAL FINAL

37. CHECK NUMBER

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER

36. PAYMENT

COMPLETE PARTIAL FINAL

ACCEPTED,

Overhaul, FAR overhaul, Part 12. This announcement constitutes the only solicitation.

Offers are being requested and a separate written solicitation will not be issued. The

Federal Emergency Management Agency intends to award one purchase order on a firm-fixed-price basis.

Site visits are requested by appointment only.

To request a site visit, email Mark Macanas at mark.macanas@fema.dhs.gov. The deadline to request a site visit is 12:00 p.m. Central

Time, April 3, 2026.

Questions can be submitted to michael.bonds@fema.dhs.gov. The deadline for questions is 12:00 p.m. Central Time, April 3, 2026. Answers will be posted no later than

12:00 p.m. Central Time, April 6, 2026.

Quotations are due 10:00 a.m. Central Time, April 10, 2026.

Basis of award: Award will be made to the acceptable offer determined to represent the best value to the Federal Emergency Management

Agency, which will be based on consideration of the offer’s technical, prior experience and price. A quotation is acceptable if it conforms to all material requirements of the request for

CONTINUATION SHEET

REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGES

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C)

NSN 7540-01-152-8067

quotation, otherwise it is unacceptable.

Evaluation: The Government will perform a comparative evaluation (comparing offers to each other) to select the offeror that is best suited and provides the best value, considering the evaluation factors below.

Price

Technical

Prior experience

Once the Government determines the offeror that represents the best value to the Federal

Emergency Management Agency, (i.e. the apparent awardee), the Government reserves the right to communicate with only that offeror to address remaining issues, if necessary, and finalize a purchase order with the offeror. These issues may include technical and price. If the parties cannot successfully address and remedy any remaining issues, as determined pertinent at the sole discretion of the Government, the

Government reserves the right to communicate with the next offeror based on the evaluation to address and remedy any remaining issues.

Offerors are invited to identify innovative cost-saving measures, such as process efficiencies, alternative materials, or optimized service schedules, that reduce total cost of ownership over the contract term.

Offerors are encouraged to propose their most competitive pricing, including any available volume discounts, prompt payment discounts for early payments, or cost-saving alternatives that maintain or enhance quality.

Location of service:

NMJRO (New Mexico Joint Recovery Office) located at 1712 St. Michaels Dr., Santa Fe, NM.

87505.

The building area is 94,829 sq. ft.

Wage determination: 2015-5449; Revision 27;

Date of revision: 12/03/2025

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C)

The Government estimates that the total value of the Janitorial Services for eight (8) months

(base period and all option periods) is between

$73,700.00 and $ $74,700.00. The Government anticipates that the total value of the

Janitorial Services for three (3) month base period only is between $27,600.00 and

$28,000.00.

Financial Responsibility

Statement of Contractor Assurance

By submitting this offer, the offeror certifies that, at the time of submission, they have adequate financial resources to perform the contract; they have the capability to comply with the required or proposed delivery or performance schedule; and otherwise meet or exceed the general standards required by FAR

9.104-1. Furthermore, by submitting this offer, the offeror also certifies that any partners or subcontractors meet or exceed the general standards required by FAR 9.104-1, and the offeror has commitments from their partners and subcontractors to deliver all commodities/services proposed.

The offeror shall disclose any filings for bankruptcy, fines levied by governmental agencies, or legal proceeding against any participating organization, employees, corporate officer, or entity that might have a material effect on the proposer’s ability to implement the proposed project, as required by

FAR [52.209-5 or 52.212-3(h)*], Certification

Regarding Responsibility Matters.

Instructions for Submitting Contractor

Assurance Information**

The offeror shall disclose any filings for bankruptcy, fines levied by governmental agencies, or legal proceeding against any participating organization, employees, corporate officer, or entity that might have a material effect on the proposer’s ability to implement the proposed project, as required by

FAR [52.209-5 or 52.212-3(h)*], Certification

Regarding Responsibility Matters.

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C)

Instructions for Submitting Contractor

Assurance Information**

The offeror shall submit information supporting this certification to the CO at the time proposals are due. This submission will only be reviewed by the CO in making a determination of responsibility. This information will not be reviewed as part of a technical evaluation and will not count against page limits for technical proposals.

At a minimum, offerors shall include: 1) the offeror’s delivery plans, including, but not limited to, any agreements and/or arrangements with suppliers, providing as much detail necessary to explain how the statement of work will be accomplished within this working relationship; 2) a description of the offeror’s ability to adequately meet the financial demands of the requirement, including current relationships with lending and/or financial institutions or equity sources which have demonstrated interest in providing financing for the proposed project; and 3) at the offerors discretion, any additional information the offeror believes supports the above certification and will assist the CO in making the determination of responsibility for the offeror and its subcontractors.

*52.212-3(h) applies to acquisitions over the

Simplified Acquisition Threshold ($250,000).

** This request for information is only included for disaster solicitations because FAR

9.105-1 Obtaining Information, states that information should generally be obtained after receipt of offers and “shall ordinarily be limited to information concerning – (i) the low bidder; or (ii) those offerors in range for award.”

Contract Announcement, Press Release

Advertisements, Publicizing Awards, and News

Releases All press releases or announcements about agency programs, projects, and contract awards need to be cleared by the FEMA CO. Under

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C) no circumstances shall the Contractor, or anyone acting on behalf of the Contractor, refer to the supplies, services, or equipment furnished pursuant to the provisions of this contract in any publicity news release or commercial advertising without first obtaining explicit written consent to do so from the CO.

The Contractor agrees not to refer to awards in commercial advertising in such a manner as to state or imply that the product or service provided is endorsed or preferred by the

Federal Government or considered to be superior to other products or services.

Option to Extend Services Addendum. Evaluation of options will not obligate the Government to exercise the option(s).

Except when it is determined in accordance with

FAR 17.206(b) not to be in the Government’s best interests, the Government will evaluate offers or quotations for award purposes by adding the total price for all options to the total price for the basic requirement to determine the total evaluated price. This includes options under FAR 52.217-8, Option to

Extend Services, which applies to this solicitation. Evaluation of options will not obligate the Government to exercise the option(s). The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. To account for the option periods possible under FAR

52.217-8 (maximum of six months), the

Government will evaluate the option to extend services by adding six months of the offeror’s final option period price to the offeror’s total price. This amount will be the total evaluated price. The Government may choose to exercise the Option to Extend Services at the end of any performance period (base or option periods).

Prices for the base and option periods, including the 6-month option available under

FAR 52.217-8, will be evaluated to ensure that they are fair and reasonable for performance of the requirements established in the

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C) solicitation and as proposed in the technical submission. The price for the effort associated with FAR 52.217-8 will not be included in the total awarded value at contract award. If, at the end of the contract’s/order’s period of performance (the end of the base period or any option period) and within the time period established in the clause, the Government chooses to exercise this option, the pricing will be pursuant to the rates specified in the contract for the preceding performance period.

This effort is solicited as a Small Business set-aside, with preference being given to local firms within the declared counties of New

Mexico (Lincoln, Dona Ana, Otero and Mescalero

Reservation) in accordance with the Robert T.

Stafford and Local Community Recovery Act of

2006 under NAICS code 561720 – Janitorial. The

Small Business Size Standard in millions of dollars is $22.0M. Per FAR 26.202, Local Area

Preference, preference shall be given, to the extent feasible and practicable, to local firms. This effort will consider SB offerors, with preference given to those businesses primarily in areas affected by Wildfires and

Straight-line Winds as declared by

Presidential

Disaster Declaration DR-4886 in the state of

New Mexico (see Attachment - Disaster

Declaration Map).

(e) The Stafford Act – Local Area Evaluation

Preference

(1) Offers will be evaluated by adding a factor of 10 percent to the price of all offers, except for offers who reside or primarily do business in the disaster or emergency area. The factor of 10 percent shall be applied on a line-item basis or to any group of items on which award may be made. Other evaluation factors described in the solicitation shall be applied before application of the factor. When the two highest rated offerors are a local business concern and a non-local business concern, and the evaluated offer of the local business concern is equal to the evaluated offer of the non-local business concern after

NAME OF OFFEROR OR CONTRACTOR

SUPPLIES/SERVICES

(B)

UNIT

(D)

UNIT PRICE

(E)

AMOUNT

(F)

OPTIONAL FORM 336 (4-86)

Sponsored by GSA FAR (48 CFR) 53.110

ITEM NO.

(A)

QUANTITY

(C) considering the price evaluation preference, award will be made to the local business concern.

(2) Local Area Offerors: If an offeror fails to comply with local area criterion or the contracting officer determines the offeror does not meet the criteria that it resides or primarily does business in the disaster or emergency area, then its offer will not be evaluated by adding a factor of 10 percent to its price.

0001 3 MOJanitorial Services. See Statement of Work

Product/Service Code: S201

Product/Service Description: HOUSEKEEPING-

CUSTODIAL JANITORIAL

1001 3 MOOPTION PERIOD 1: Janitorial Services. See

Statement of Work

(Option Line Item)

Date Option to be Exercised

Product/Service Code: S201

Product/Service Description: HOUSEKEEPING-

CUSTODIAL JANITORIAL

2001 2 MOOPTION PERIOD 2: Janitorial Services. See

Statement of Work

(Option Line Item)

Date Option to be Exercised

Product/Service Code: S201

Product/Service Description: HOUSEKEEPING-

CUSTODIAL JANITORIAL

A - Solicitation/Contract Form B - Supplies or Services/Prices C - Description/Specifications D - Packaging and Marking E - Inspection and Acceptance F - Deliveries or Performance G - Contract Administration Data H - Special Contract Requirements I - Contract Clauses J - List of Documents, Exhibits and Other Attachments K - Representations, Certifications, and Other Statements of Bidders L - Instructions, Conditions, and Notices to Bidders M - Evaluation Factors for Award

A - Solicitation/Contract Form

Contractor Employee Access (NOV 2025) - Alternate II (NOV 2025)

Contractor Employee Access (NOV 2025)

52.212-1 Instructions to Offerors-Commercial Products and Commercial Services. (SEP 2023) (Deviation AUG 2025)

52.212-2 Evaluation-Commercial Products and Commercial Services. (NOV 2021) (Deviation AUG 2025)

(a) Evaluation factors. The Government will award a contract resulting from this solicitation to the responsible Offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors will be used to evaluate offers:

1. Price. Offerors shall provide competitive pricing for the base and option periods.

2. Technical. Quotations shall demonstrate an understanding of the statement of work. Quotations shall explain:

a. The equipment to be used.

b. A plan to supervise staff.

c. A plan to monitor and maintain quality of work.

d. How supplies will be managed and replenished.

3. Prior Experience. Offerors shall submit the name, number and/or email of three (3) professional references for the same or similar services.

Evaluation factors other than price when combined are approximately equal to price.

(b) Options (if applicable). The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. The evaluation of options does not obligate the Government to exercise the option(s).

(c) Notice of award. A written notice of award or acceptance of an offer furnished to the successful Offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer's specified expiration time, the Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.

(End of provision)

52.212-4 Terms and Conditions-Commercial Products and Commercial Services. (NOV 2023) (Deviation AUG 2025)

52.212-5 Reserved

52.223-23 Sustainable Products and Services. (MAY 2024) (Deviation OCT 2025)

B - Supplies or Services/Prices

C - Description/Specifications

D - Packaging and Marking

E - Inspection and Acceptance

F - Deliveries or Performance

G - Contract Administration Data

INVOICE APPROVAL

INVOICE APPROVAL (JUN 2014)

The following FEMA individual (in addition to the Contracting Officer) is hereby delegated authority to accept goods and services and to review and approve invoices for this contract:

Authorized Invoice Approver

Name: Mark Macanas

Title: Facilities Manager

Phone: 256-419-4948

Email: mark.macanas@fema.dhs.gov

IDENTIFICATION OF GOVERNMENT OFFICIALS

IDENTIFICATION OF GOVERNMENT OFFICIALS (AUG 2014)

The Government Officials assigned to this contract are as follows:

Administrative Contracting Officer:

Name: Michael Bonds

Phone: 202-257-8893

Email: michael.bonds@fema.dhs.gov

Fax: none

Contract Specialist:

Name: Michael Bonds

Phone: 202-257-8893

Email: michael.bonds@fema.dhs.gov

Fax: None

Contracting Officer’s Representative:

Name: Mark Macanas

Phone: 256-419-4948

Email: mark.macanas@fema.dhs.gov

Fax: None

BILLING INSTRUCTIONS

BILLING INSTRUCTIONS (JUN 2014)

Contractors will use Standard Form 1034 (Public Voucher for Purchases and Services Other Than Personal) located at http://www.gsa.gov/portal/forms/type/SF when submitting a payment request. A payment request means any invoice or request for contract financing payment requesting reimbursement for supplies or services rendered. The Contractor shall not be paid more frequently than on a monthly basis.

Contractors must submit vouchers electronically in pdf format to the FEMA Finance Center at FEMA- Finance-Vendor-Payments@fema.dhs.gov. A copy of the voucher must be submitted electronically to the contracting officer identified within this contract. The submission of vouchers electronically will reduce correspondence and other causes for delay to a minimum and will facilitate prompt payment to the Contractor. Paper vouchers mailed to the finance center will not be processed for payment. If the Contractor is unable to submit a payment request in electronic form, the contractor shall submit the payment request using a method mutually agreed to by the Contractor, the Contracting Officer, and the payment office.

H - Special Contract Requirements

Safeguarding of Sensitive Information (MAR 2015)

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as

“Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause—

“Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available— in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of

Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an

Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the

Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the

Homeland Security Act, Public Law 107296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal

Regulations, Part 29) as amended, the applicable PCII Procedures

Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland

Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of

Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant

Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements.

Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)

Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of

Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But

Unclassified (for Official Use Only) Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable

Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland

Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security

Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html

(10) National Institute of Standards and Technology (NIST) Special

Publication 800-53 Security and Privacy Controls for Federal Information

Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on

Contractor personnel security requirements are set forth in various

Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only)

Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE

ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS

4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources. The DHS

Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland

Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-

Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative

(COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the

Headquarters or Component CIO, or designee, in consultation with the

Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the

Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A

(Version 11.0, April 30, 2014), or any successor publication, DHS 4300A

Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements

Traceability Matrix and Government security documentation templates.

SA documentation consists of the following: Security Plan, Contingency

Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and

Authorization to Operate Letter. Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection

Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the

Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and

Privacy Controls for Federal Information Systems and Organizations. The

Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii) Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA. The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy

Impact Assessment (PIA) and/or Privacy Act System of Records Notice

(SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the

PIAin a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and

SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the

Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the

ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process. The

Contractor shall update its SA package by one of the following methods:

(1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or

Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the

Contracting Officer and COR, contact the Headquarters or Component

CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal

Year 2014 DHS Information Security Performance Plan, or successor publication. The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for

Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of

Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the

Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements.

Annual and quarterly data collection will be coordinated by the

Government. Contractors shall provide the COR with requested information within three (3) business days of receipt of the request.

Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance

Plan, or successor publication. The Contractor shall provide the

Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements.

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center

(SOC) within one hour of discovery in accordance with 4300A Sensitive

Systems Handbook Incident Response and Reporting requirements.

When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or

Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the

Contracting Officer’s email address is not immediately available, the

Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The

Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive Systems Handbook

Incident Response and Reporting, Contractors shall also provide as many of the following data elements that are available at the time the incident is reported, with any remaining data elements provided within 24 hours of submission of the initial incident report:

(i) Data Universal Numbering System (DUNS);

(ii) Contract numbers affected unless all contracts by the company are affected;

(iii) Facility CAGE code if the location of the event is different than the prime contractor location;

(iv) Point of contact (POC) if different than the POC recorded in the

System for Award Management (address, position, telephone, email);

(v) Contracting Officer POC (address, telephone, email);

(vi) Contract clearance level;

(vii) Name of subcontractor and CAGE code if this was an incident on a subcontractor network;

(viii) Government programs, platforms or systems involved;

(ix) Location(s) of incident;

(x) Date and time the incident was discovered;

(xi) Server names where sensitive information resided at the time of the incident, both at the Contractor and subcontractor level;

(xii) Description of the Government PII and/or SPII contained within the system;

(xiii) Number of people potentially affected and the estimate or actual number of records exposed and/or contained within the system; and

(xiv) Any additional information relevant to the incident.

(g) Sensitive Information Incident Response Requirements.

(1) All determinations related to sensitive information incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) will be made in writing by the Contracting Officer in consultation with the Headquarters or

Component CIO and Headquarters or Component Privacy Officer.

(2) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(3) Incident response activities determined to be required by the

Government may include, but are not limited to, the following:

(i) Inspections,

(ii) Investigations,

(iii) Forensic reviews, and

(iv) Data analyses and processing.

(4) The Government, at its sole discretion, may obtain the assistance from other Federal agencies and/or third-party firms to aid in incident response activities.

(h) Additional PII and/or SPII Notification Requirements.

(1) The Contractor shall have in place procedures and the capability to notify any individual whose PII resided in the Contractor IT system at the time of the sensitive information incident not later than 5 business days after being directed to notify individuals, unless otherwise approved by the Contracting Officer. The method and content of any notification by the

Contractor shall be coordinated with, and subject to prior written approval by the ContractingOfficer, in consultation with the Headquarters or

Component Privacy Officer, utilizing the DHS Privacy Incident Handling

Guidance. The Contractor shall not proceed with notification unless the

Contracting Officer, in consultation with the Headquarters or Component

Privacy Officer, has determined in writing that notification is appropriate.

(2) Subject to Government analysis of the incident and the terms of its instructions to the Contractor regarding any resulting notification, the notification method may consist of letters to affected individuals sent by first class mail, electronic means, or general public notice, as approved by the Government. Notification may require the Contractor’s use of address verification and/or address location services. At a minimum, the notification shall include:

(i) A brief description of the incident;

(ii) A description of the types of PII and SPII involved;

(iii) A statement as to whether the PII or SPII was encrypted or protected by other means;

(iv) Steps individuals may take to protect themselves;

(v) What the Contractor and/or the Government are doing to investigate the incident, to mitigate the incident, and to protect against any future incidents; and

(vi) Information identifying who individuals may contact for additional information.

(i) Credit Monitoring Requirements. In the event that a sensitive information incident involves PII or SPII, the Contractor may be required to, as directed by the Contracting Officer:

(1) Provide notification to affected individuals as described above; and/or

(2) Provide credit monitoring services to individuals whose data was under the control of the Contractor or resided in the Contractor IT system at the time of the sensitive information incident for a period beginning the date of the incident and extending not less than 18 months from the date the individual is notified. Credit monitoring services shall be provided from a company with which the Contractor has no affiliation. At a minimum, credit monitoring services shall include:

(i) Triple credit bureau monitoring;

(ii) Daily customer service;

(iii) Alerts provided to the individual for changes and fraud; and

(iv) Assistance to the individual with enrollment in the services and the use of fraud alerts; and/or

(3) Establish a dedicated call center. Call center services shall include:

(i) A dedicated telephone number to contact customer service within a fixed period;

(ii) Information necessary for registrants/enrollees to access credit reports and credit scores;

(iii) Weekly reports on call center volume, issue escalation (i.e., those calls that cannot be handled by call center staff and must be resolved by call center management or DHS, as appropriate), and other key metrics;

(iv) Escalation of calls that cannot be handled by call center staff to call center management or DHS, as appropriate;

(v) Customized FAQs, approved in writing by the Contracting Officer in coordination with the Headquarters or Component Chief Privacy Officer;

and

(vi) Information for registrants to contact customer service representatives and fraud resolution representatives for credit monitoring assistance.

(j) Certification of Sanitization of Government and Government-Activity-

Related Files and Information. As part of contract closeout, the

Contractor shall submit the certification to the COR and the Contracting

Officer following the template provided in NIST Special Publication 800-

88 Guidelines for Media Sanitization.

(End of clause)

I - Contract Clauses

AI Language

The Contractor will not use or deploy the use of Artificial Intelligence, as defined by 15 U.S.C. 9401(3), unless expressly authorized by the Contracting Officer.

The term 'artificial intelligence' means a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations or decisions influencing real or virtual environments.

Artificial intelligence systems use machine and human-based inputs to –

(A) perceive real and virtual environments;

(B) abstract such perceptions into models through analysis in an automated manner; and

(C) use model inference to formulate options for information or action.

52.204-9 Personal Identity Verification of Contractor Personnel. (JAN 2011)

52.204-19 Incorporation by Reference of Representations and Certifications. (DEC 2014)

52.217-8 Option To Extend Services. (NOV 1999)

The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 2 days..

(End of clause)

52.217-9 Option To Extend the Term of the Contract. (MAR 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 1 days; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 2 days before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 8 months.

(End of clause)

52.219-6 Notice of Total Small Business Set-Aside. (NOV 2020) (Deviation OCT 2025)

52.222-41 Service Contract Labor Standards. (AUG 2018)

52.222-50 Combating Trafficking in Persons. (OCT 2025) (Deviation OCT 2025)

52.223-3 Hazardous Material Identification and Safety Data. (FEB 2021) (Deviation OCT 2025)

52.224-1 Privacy Act Notification. (APR 1984)

52.225-1 Buy American-Supplies (OCT 2022) (Deviation OCT 2025)

52.226-7 Drug-Free Workplace. (MAY 2024)

52.226-8 Encouraging Contractor Policies To Ban Text Messaging While Driving. (MAY 2024)

52.232-25 Prompt Payment. (JAN 2017)

52.232-33 Payment by Electronic Funds Transfer - System for Award Management. (OCT 2018)

52.233-3 Protest after Award. (AUG 1996) (Deviation AUG 2025)

52.233-4 Applicable Law for Breach of Contract Claim. (OCT 2004) (Deviation AUG 2025)

52.244-6 Subcontracts for Commercial Products and Commercial Services. (OCT 2025) (Deviation

SEP 2025)

52.246-25 Limitation of Liability - Services. (FEB 1997)

52.252-2 Clauses Incorporated by Reference. (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .