2.2.1.i DR-4827 NC Direct Lease SOW100 Unit_123124 Rev 1.pdf
PDF 330 KB Posted
- Attached to
- Amendment 0005 Direct Lease (DR4827NC) Federal contract opportunity
- Solicitation number
- 70FBR425Q00000050
- Issued by
- Federal Emergency Management Agency
About this file
This is a Statement of Work (SOW) for FEMA's Direct Lease program under disaster declaration DR-4827-NC, requiring Property Management Companies and Housing Solutions vendors to provide furnished, turnkey residential properties for temporary housing assistance following severe storms, flooding, straight-line winds, and tornadoes that occurred in September 2024.
The contractor must provide 1-4 bedroom furnished properties located within 30-60 minutes commute from damaged dwellings, with monthly rental rates specified by county in the included Fair Market Rent table. Properties must be currently vacant, comply with federal/state/local occupancy standards, and include basic furnishings like beds, dining sets, appliances, and living room furniture. The period of performance is 12 months with one 2-month option period. Key requirements include property inspections, matching eligible applicants with units, executing lease agreements, coordinating move-ins, maintaining properties, and handling emergency repairs within 6 hours and non-emergency repairs within 3 days. The contractor must implement security measures to protect personally identifiable information (PII) and complete required security/privacy training within 30 days of contract award.
View the file
Other files for this federal contract opportunity
Show all 26
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DR-4827-NC
STATEMENT OF WORK
DIRECT LEASE
DR-4827-NC
SEVERE STORMS, FLOODING,
STRAIGHT-LINED WINDS, AND
TORNADOES
PURPOSE:
The Department of Homeland Security (DHS) Federal Emergency Management Agency (FEMA) has a requirement for Direct Lease Contractors/Property Managers (PM), Housing Solutions Vendors and/or Property Owners (PO). FEMA Direct Lease is a form of housing assistance to lease existing rental units for the purpose of providing temporary housing to eligible applicants who are displaced due to the presidentially declared major disaster designated FEMA DR-4827- NC as a result of Severe Storms, flooding, straight-line winds, and tornadoes for September 28, 2024. Note: the term Contractor will be used to refer to Contractor/Property Managers/Housing Solutions Vendors/Property Owners from this point on.
SCOPE:
The Property Management Company shall provide a portfolio of furnished, turnkey 1-, 2-, 3-, and 4-bedroom properties located within a thirty (30) – to sixty (60)-minute commute from the damaged dwelling, ensuring that these properties do not place an undue hardship on qualified disaster applicants. This should include existing residential properties advertised for lease (e.g., corporate apartments, vacation rentals, and second homes), vacant residential properties that are listed for sale (single family and multiple occupancy), and bank owned properties (e.g., foreclosures) or any other type of residential property that meets the criteria of a Direct Lease property as accepted by FEMA and the standards identified in this Statement of Work.
Contractor shall provide FEMA with regular progress reports related to their property inventory.
Contractor and FEMA shall evaluate each property to ensure the property is safe, sanitary, secure, and functional. Safe means secure from disaster-caused hazards or threats to occupants. Sanitary means free of disaster-caused health hazards. Functional means an item or home capable of being used for its intended purpose.
The following items and services are to be performed by the Contractor for the Direct Lease Program:
1. Identify Properties. Contractor shall only rent existing turnkey residential properties.
a. Contractor may only lease properties that are currently vacant and the property owner must certify in writing that they are not terminating an existing lease for the sole purpose of listing their unit for FEMA Direct Lease.
b. Contractor may only lease properties that comply with federal, state, and local occupancy standards, to provide complete and independent living facilities for one or more persons, including permanent provisions for living, sleeping, cooking, and sanitation. All utilities, appliances, and any furnishings provided by the property must be safe and functional.
i. Contractor shall prioritize properties that include accessibility features or can easily be conformed to accessible requirements; and are in proximity to accessible public transportation, as well as wrap around services.
c. The monthly cost per unit may not exceed the amounts established in Figure 1 below, unless an increase is approved by the Contracting Officer (CO).
i. The Government will establish a contract line item for one (1) month security deposit not-to-exceed one (1) month rent. The security deposit is a cost reimbursable contract line item and will not be disbursed at the signing of the contract. The security deposit will be held by the Government in the event any damages (other than normal wear and tear) occur and will be invoiced based on the actual costs of damages verified between the Government and the Contractor. All damages above the cost of monthly rent shall be the responsibility of the contractor and or applicant upon confirmation of the cause of damage.
ii. Damages-Security Deposit must be approved by CO prior to submission of invoice. Contractor must submit request for damages/security deposits within 14-days of Move-Out Inspection (MOI). Documentation including repair costs and time stamp photo documentation must be submitted with request.
d. Contractor shall implement and update a tracking spreadsheet for approved properties throughout the Direct Lease process. The tracking system must be approved by the COR prior to implementation. An example is provided at Attachment 2, Direct Lease Property Tracking Sheet.
Figure 1 - Maximum Monthly Rent FY2025 Fair Market Rent (FMR) Documentation 1
County 1 BED 2 BEDS 3 BEDS 4 BEDS
Alexander $851 $1,046 $1,334 $1,567 Alleghany $772 $947 $1,141 $1,424
Ashe $717 $930 $1,228 $1,233 Avery $803 $1,054 $1,270 $1,584
Buncombe $1,347 $1,512 $1,944 $2,566 Burke $851 $1,046 $1,334 $1,567
Caldwell $851 $1,046 $1,334 $1,567 Catawba $851 $1,046 $1,334 $1,567
Clay $921 $1,020 $1,357 $1,533 Cleveland $709 $930 $1,303 $1,397
Gaston $1,647 $1,824 $2,250 $2,852 Haywood $1,105 $1,223 $1,473 $1,736 Henderson $1,347 $1,512 $1,944 $2,566
Jackson $868 $961 $1,269 $1,274 Lincoln $1,058 $1,171 $1,623 $1,731 Macon $894 $1,022 $1,231 $1,426
Madison $1,347 $1,512 $1,944 $2,566
McDowell $836 $930 $1,172 $1,243 Mecklenburg $1,647 $1,824 $2,250 $2,852
Mitchell $709 $930 $1,161 $1,233 Polk $841 $1,046 $1,335 $1,757
Rutherford $807 $930 $1,255 $1,442 Swain $762 $930 $1,303 $1,398
Transylvania $877 $1,150 $1,386 $1,729 Watauga $1,004 $1,274 $1,555 $2,139 Wilkes $807 $930 $1,244 $1,386 Yancey $709 $930 $1,228 $1,233
2. Property Inspections. Contractor/FEMA shall inspect each property to ensure compliance with Housing and Urban Development’s (HUD) Housing Quality Standards (HQS) and with Federal, State, and local occupancy standards prior to executing lease agreements with housing applicants. Each inspection will also verify property owner’s capability to provide all property management services, including building maintenance.
3. Contacting Applicants. FEMA will identify eligible applicants for the Direct Lease program and provide the following applicant information to Contractor: applicant name, co-applicant names (if applicable), damage dwelling address, mailing address, phone numbers and email addresses.
4. Matching Applicants. Once units are reported as available, FEMA will initiate contact to the applicant within one (1) day and coordinate with the applicant to match the Direct Lease unit that fits the needs of the applicant. FEMA will also inform each applicant of the next steps towards their placement in a Direct Lease Unit, such as having background checks for properties that require it.
a. Contractor shall notify FEMA, within one (1) day, in each instance regarding an applicant being denied due to adverse information in their background check.
5. Execute Lease Agreements. The Contractor shall complete and execute lease agreements with FEMA’s applicants through completion of the following documents within three (3) business days of completion. The Contractor shall provide the Contracting Officer Representative (COR) with the following documentation:
a. Exhibit 1 of this document, the Direct Lease Occupant Lease Agreement
b. Exhibit 7 of this document, the Direct Lease Addendum
c. Provide a copy of the lease agreement between the Contractor and the property owner.
6. Move-in of Applicants. Contractor and FEMA will be responsible for the move-in process for applicants into Direct Lease units. Contractor and DHS-FEMA shall conduct a walkthrough of the temporary housing unit with the applicant and ensure all necessary paperwork is completed prior to completing a move-in. Within three (3) business days of completion, Contractor shall prepare and provide the COR with the following documentation:
a. A copy of the inspection record confirming the property complies with Federal, State, and local occupancy standards; HUD (Exhibit 3). The completed HUD inspection checklist shall be submitted prior to award. Pictures of the unit, including all rooms and furnishings, shall be included in the inspection record.
b. A copy of the Direct Lease Contract Terms and Conditions (Exhibit 2) that was completed in executing the lease agreement and specifies the monthly rent rates.
c. A copy of the Direct Lease Occupant Lease Agreement (Exhibit 1)
d. A copy of the Direct Lease Addendum (Exhibit 7)
e. A copy of the Temporary Housing Agreement (Exhibit 4).
7. Lease Agreement Payments. FEMA shall make rental payments to Contractor in accordance with the rental or lease agreements for each property that is awarded under the contract.
8. Terminate Lease Agreements. FEMA will be responsible for any termination of assistance to applicants. Contractor shall be responsible for eviction of applicants whose assistance has been terminated by FEMA. FEMA may terminate the lease for the housing unit by providing Contractor with a written thirty (30) calendar day Termination Notice.
9. Utilities. The Government is not responsible for utilities, unless utilities are included in the monthly rental fee and do not exceed the established monthly rental rates established in Figure 1. Applicants are responsible for obtaining their own utility accounts.
10. Maintenance and Other Services. All maintenance and services such as trash pickup, parking, lawn care, pest control, building maintenance, and storm preparations shall be the responsibility of the Contractor.
a. Emergency Repairs are repairs that resolve or mitigate the immediate threat or imminent danger to the health, safety, or security of the Unit Occupant and the Unit/property, such as heating, ventilation, and air conditioning (HVAC), water, electricity, and elevators not working properly. The COR shall be contacted within two (2) hours and work shall be initiated and completed within six (6) hours of work order receipt.
Contractor shall place applicant(s) in alternative housing, if necessary, if repairs are not completed within six (6) hours.
b. A complete emergency maintenance repair is defined as the imminent threat to life or property and is either completely repaired or temporarily repaired so that a permanent repair can be completed as regular maintenance.
c. In the event of a death in the Unit, the Contractor shall properly clean the Unit prior to another applicant being placed in the Unit, such as the proper biohazard clean up. The Contractor is responsible for securing the applicant’s personal belongings prior to the cleaning.
d. All Non-Emergency Repairs are repairs that are not an immediate threat or imminent danger to the health, safety, or security of the Unit Occupant and the Unit/property. The COR shall be contacted within one (1) day and work shall be initiated and completed within three (3) days of work order receipt.
e. The Contractor shall submit a status report monthly which includes all maintenance issues with pictures included.
11. Access and Functional Needs. A provision allowing Contractor to make, at FEMA’s expense, reasonable modifications, or improvements to the property to provide a reasonable accommodation for an eligible applicant with a disability or other access or functional needs.
All modifications or improvements will be coordinated with the COR and CO for FEMA approval prior to execution or incurrence of costs. All costs above $3,000 must be approved by the CO.
INSPECTION
Properties are subject to inspection by FEMA and other applicable Government agencies.
Contractor shall participate by responding to all requests for information and inspection or review findings by regulatory agencies. Contractor shall allow FEMA, or an entity or organization approved by FEMA, to conduct inspections of rental units, as required, to ensure an acceptable level of services and acceptable conditions of housing as determined by FEMA.
FEMA will share findings of the inspection with Contractor (See Exhibit 3).
FURNISHED PROPERTY / TURNKEY IS DEFINED.
Unit Item Inventory Requirements. The Contractor shall do an inventory of each item they may want to file a replacement or damage claim on in a Unit at move out. No later than 30 calendar days after the scheduled FEMA move out inspection date, the Contractor shall submit any claims for damages and/or replacement of items above normal wear and tear. For Direct Lease units, the normal wear and tear period is for the one-year base period. Additional option periods beyond the one-year base period, shall only be accepted for destroyed items and shall not cover items listed in the living kit (one time purchase items). Any claims made for damages shall be submitted with pictures of damages and receipts of payment to a third party.
Prior to the move in of the FEMA applicant, the Contractor shall submit a completed Vendor Required Unit Furnishing list of each item in the unit and provide the estimated replacement cost for the item. Reference Vendor Required Unit Furnishing List (Attachment 10). At a minimum, the following items are required in each unit for the number of bedrooms per unit/household composition.
Items not listed on Vendor Required Unit Furnishing List will not be reimbursable.
1. At least 1 bed per bedroom (full size or larger)
2. At least 1 nightstand
3. One (1) dresser or built in or portable closet/wardrobe with hanger rod and shelves
4. Curtains or Blinds or Shades for each window
5. Dining table with at least 4 chairs
6. Refrigerator
7. Cook top stove
8. Microwave
9. Water heater
10. One (1) Sofa
11. One (1) end table and 1 coffee table
12. One (1) or more AC Unit(s) suitable to adequately cool the entire unit
13. Weather Radio
14. Living Kit (suitable for size of unit but minimum of 4 dining place settings – plates, bowls, cups, and glasses; 4 place settings silverware – fork, spoon, and knife; Cooking
Pots and Pans with lids; Cooking utensils; Bed-in-a-bag; 6-piece towel set; mattress cover, and all Safety equipment required by code/HUD housing standards i.e., Fire extinguisher, Smoke/Carbon Monoxide Detectors etc. The living kit is not reimbursable for a missing item claim or for damages.
PLACE OF PERFORMANCE
Within thirty (30) minutes to up to sixty (60) minutes commuting distance from the damaged dwelling, and that do not place an undue hardship on qualified disaster applicants. The Government may adjust this requirement as needed, but not outside the State of North Carolina.
PERIOD OF PERFORMANCE
The period of performance (POP): Base Period: 12-months, with one (1) 2-month Option Periods (if needed).
POINTS OF CONTACTS:
CONTRACTING OFFICER(S):
Name: Victor Hinojosa Name: Janice Joseph
CONTRACTING OFFICER REPRESENTATIVE(S):
Name: Alicia Wynn Name: Maureeke Milligan Greenidge Name: Corey Perro
FEMA PROGRAM MANAGER
Name: Ina Chan
APPLICABLE ATTACHMENTS:
1. Direct Lease Property Tracking Sheet
2. Direct Lease Property Inspection Checklist (HUD)
3. Direct Lease Contract Terms and Conditions
4. Direct Lease Occupant Lease Agreement Template
5. Direct Lease-Lease Addendum
6. Temporary Housing Agreement
7. FEMA Decision to Terminate DTHA Notice
8. Rental Resource FMR Rates
9. Pricing Schedule
10. Vendor Required Unit Furnishing List
Information Sharing
To accomplish the task personally identifiable information (PII) will be disclosed for placement of the survivors. PII data elements: Disaster Survivor’s Name
Need to Know The contractor will limit access to the PII provided by FEMA under this contract only to the contractor’s authorized personnel having a need to know the information to accomplish the tasks outlined in this contract.
Prohibition on Computer Matching The contractor shall ensure no computer matching, as that term is defined in 5 U.S.C. § 552a(o), will occur for the purpose of establishing or verifying eligibility or compliance as it relates to cash or in-kind assistance or payments under federal benefit programs.
Return or Destruction of Data when no longer needed If at any time during the term of this contract any part of FEMA PII, in any form, that the contractor obtains from FEMA ceases to be required by the contractor for the performance of the contract, or upon termination of the contract, whichever occurs first, the contractor shall, within fourteen (14) days thereafter, promptly notify FEMA and securely return PII to FEMA, or, at FEMA’s written request destroy, un-install and/or remove all copies of such PII in the contractor’s possession or control, and certify in writing to FEMA that such tasks have been completed.
SECURITY LANGUAGE
Personnel may require access to information up to the sensitive but unclassified, for official use only (FOUO) levels. Contractor must ensure contractor employees receive a favorably adjudicated suitability prior to entry on duty (EOD). All individuals will be U.S. citizens. The contractor shall follow the standards established within DHS and FEMA policy.
Unauthorized Disclosure of Classified or Unclassified Information:
Contractors and Subcontractors who are working on this contract shall receive Unauthorized Disclosure of Classified or Unclassified Information training.
Access to the training can be obtained at: Unauthorized Disclosure of Classified Information and Controlled Unclassified Information (usalearning.gov)
Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
OPSEC Training:
Contractors and Subcontractors who are working on this contract shall receive the Operations Security (OPSEC) Awareness Brief.
Access to the briefing can be obtained at OPSEC Awareness for Military Members, DOD Employees and Contractors (usalearning.gov)
Send the certificate of completion to the FEMA Contracting Officer Representative no later than 30 calendar days after awarded contract. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
Insider Threat Training:
Insider Threat training for Contractors can be found at: Insider Threat Awareness (usalearning.gov)
Certificate of training is required for all cleared contractor employees who are working with classified or unclassified information. All certificates must be sent to the assigned FEMA Contracting Officer Representative, before the Contractor or Subcontractor is granted access to classified or unclassified information but no later than 30 calendar days after awarded contract. All cleared contractor personnel are required to recertify Insider Threat https://securityawareness.usalearning.gov/disclosure/index.html https://securityawareness.usalearning.gov/disclosure/index.html https://securityawareness.usalearning.gov/opsec/index.htm https://securityawareness.usalearning.gov/opsec/index.htm https://securityawareness.usalearning.gov/itawareness/index.htm training annually thereafter. New employees entering the contract must receive the briefing within ten (10) business days of joining the contract.
For Official Use Only (FOUO) Information:
In accordance with DHS Management Directive 11042.1 contractors, consultants and others to whom access is granted will abide by 11042.1; DHS policy regarding the identification and safeguarding of sensitive but unclassified information originated within DHS. It also applies to other sensitive but unclassified information received by DHS from other government and non-governmental activities.
The contractor will:
1. Be aware of and comply with the safeguarding requirements for “For Official Use Only” (FOUO) information as outlined in this directive.
2. Participate in formal classroom or computer-based training sessions presented to communicate the requirements for safeguarding FOUO and other sensitive but unclassified information.
3. Be aware that divulging information without proper authority could result in administrative or disciplinary action.
Contractors and Consultants shall execute a DHS Form 11000-6, Sensitive but Unclassified Information Non Disclosure Agreement (NDA), as a condition of access to such information. Other individuals not assigned to or contractually obligated to DHS, but to whom access to information will be granted, may be requested to execute an NDA as determined by the applicable program manager. Execution of the NDA shall be effective upon date of the DHS Policy and not applied retroactively.
Background Investigations:
All contractor personnel who require access to DHS or FEMA information systems, routine access to DHS or FEMA facilities, or access to sensitive information, including but not limited to Personally Identifiable Information (PII), shall be subject to a full background investigation commensurate with the level of the risk associated with the job function or work being performed. FEMA’s Personnel Security Division (PSD) will determine the risk designation for each contractor position by comparing the functions and duties of the position against those of a same or similar federal position, applying the same standard for evaluating the associated potential for impact on the integrity and efficiency of federal service.
Low Risk without Information System Access:
Contractor personnel occupying positions or performing functions with a Low Risk designation and who do not require access to DHS or FEMA information systems may undergo a Tier 1 investigation with a credit check and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
(also reference Facility Access).
Low Risk with Information System Access:
Contractor personnel occupying positions or performing functions with a Low Risk designation and who require access to DHS or FEMA information systems shall undergo a Tier 2 Suitability Background Investigation (T2) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
Moderate Risk:
Contractor personnel occupying positions or performing functions with a Moderate Risk designation shall undergo a Tier 2 Suitability Background Investigation (T2) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
High Risk:
Contractor personnel occupying positions or performing functions with a High-Risk designation shall undergo a Tier 4 Suitability Background Investigation (T4) and must receive a favorable adjudication thereof from FEMA PSD prior to performing work under this contract.
Background Investigation Process:
To initiate the request to process contractor personnel, the Contractor shall provide the FEMA Contracting Officer’s Representative (COR) with all required information and comply with all necessary instructions to complete Section II of the FEMA Form 11000-25, “Contract Fitness/Security Screening Request.” The FEMA COR shall ensure that all other applicable sections of the FEMA Form 11000-25 are complete prior to submitting the form to FEMA PSD for processing. The Contractor shall also provide the FEMA COR with completed OF 306, “Declaration for Federal Employment,” forms for all contractor personnel.
Contractor personnel who already have a favorably adjudicated background investigation, may be eligible to perform work under this contract without further processing by FEMA PSD if:
the investigation was completed within the last five years, it meets or exceeds the minimum requirement for the position they will occupy or functions they will perform on this contract, the contractor personnel have not had a break in employment since the prior favorable adjudication, and, FEMA PSD has verified the investigation and confirmed that no new derogatory information has been disclosed which may require a reinvestigation.
FEMA PSD will notify the COR of the names of the contractor personnel eligible to work based on prior, favorable adjudication. The COR will, in turn, notify the Contractor of the names of the favorably adjudicated contractor personnel, at which time the favorably adjudicated contractor personnel will be eligible to begin work under this contract.
For those contractor personnel who do not have an acceptable, prior, favorable adjudication or who otherwise require reinvestigation, FEMA PSD will issue an electronic notification via email directly to the contractor applicant/personnel that contains the following documents, which are incorporated into this contract by reference, along with a link to the National Background Investigation Services (NBIS) e-Application (eAPP) online system and instructions for submitting the necessary information:
Standard Form 85P, “Questionnaire for Public Trust Positions”
Optional Form 306, “Declaration for Federal Employment”
SF 87, “Fingerprint Card” (2 copies)
DHS Form 11000-6, “Non-Disclosure Agreement”
DHS Form 11000-9, “Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act”
FEMA PSD will only accept complete packages consisting of all of the above document and Standard Form 85P, which must be completed electronically through the National Background Investigation Services (NBIS) e- Application (eAPP) online system. The Contractor is responsible for ensuring that all contractor personnel timely and properly submit all required background information.
Once contractor personnel have properly submitted the complete package of all required background information, FEMA’s Personnel Security Division, at its sole discretion, may grant contractor personnel temporary eligibility to perform work under this contract prior to completion of the full background investigation if the Personnel Security Division’s initial review of the contractor personnel’s background information reveals no issues of concern. In such cases, FEMA’s Personnel Security Division will provide notice of such temporary eligibility to the COR who will then notify the Prime Contractor, at which time the identified contractor personnel will be temporarily eligible to begin work under this contract. Neither the Prime Contractor nor the contractor personnel has any right to such a grant of temporary eligibility. The grant of such temporary eligibility shall not be considered as assurance that the contactor personnel will remain eligible to perform work under this contract upon completion of and final adjudication of the full background investigation.
Upon favorable adjudication of the full background investigation, FEMA’s Personnel Security Division will update the contractor personnel’s security file and take no further action. In any instance where the final adjudication results in an unfavorable determination FEMA’s Personnel Security Division will notify the contractor personnel directly, in writing, of the decision and will provide the COR with the name(s) of the contractor personnel whose adjudication was unfavorable. The COR will then forward that information to the Contractor. Contractor personnel who receive an unfavorable adjudication shall be ineligible to perform work under this contract. Unfavorable adjudications are final and not subject to review or appeal.
Continued Eligibility and Reinvestigation:
Eligibility determinations based on a Low Risk T1, Moderate Risk T2S or High Risk T4 are valid for five years from the date that the investigation was completed and closed. Contractor personnel required to undergo a background investigation to perform work under this contract shall be ineligible to perform work under this contract upon the expiration the background investigation unless and until the contractor personnel have undergone a reinvestigation and FEMA’s Personnel Security Division has renewed their eligibility to perform work under this contract.
Exclusion by Contracting Officer:
The Contracting Officer, independent of FEMA’s Personnel Security Division, may direct the Contractor be excluded from working on this contract. Any contractor found or deemed to be unfit or whose continued employment on the contract is deemed contrary to the public interest or inconsistent with the best interest of the agency may be removed.
Facility Access:
The Contractor shall comply with FEMA Directive 121-1 “FEMA Personal Identity Verification Guidance,” FEMA Directive 121-3 “Facility Access,” and FEMA Manual 121-3-1 “FEMA Credentialing Access Manual,” to arrange for contractor personnel’s access to FEMA facilities, which includes, but is not limited to, arrangements to obtain any necessary identity badges for contractor personnel.
Contractor personnel working within any FEMA facility who do not require access to DHS or FEMA IT systems and do not qualify for a PIV Card may be issued a Facility Access Card (FAC). FACs cannot exceed 180 days;
all contractors requiring access greater than 180 days will need to qualify for and receive a PIV card before being allowed facility access beyond 180 days.
Contractor personnel shall not receive a FAC until they have submitted a SF 87, “Fingerprint Card,” and an OF306, Declaration for Federal Employment, and receive approval from FEMA PSD. Contractor personnel using a FAC for access to FEMA facilities must be escorted in Critical Infrastructure areas (i.e., server rooms, weapons rooms, mechanical rooms, etc.) at all times.
FEMA may deny facility access to any contractor personnel whom FEMA’s Office of the Chief Security Officer has determined to be a potential security threat.
Separation of Contract:
The Contractor shall notify the FEMA COR of all terminations/resignations within five calendar days of occurrence. The Contractor must account for all forms of Government-provided identification issued to contractor employees under a contract (i.e., the PIV cards or other similar badges) must return such identification to FEMA as soon as any of the following occurs:
• When no longer needed for contract performance.
• Upon completion of a contractor employee’s employment.
• Upon contract completion or termination.
If an identification card or building pass is not available to be returned, the Contractor shall submit a report to the FEMA COR, referencing the pass or card number, name of the individual to whom it was issued, and the last known location and disposition of the pass or card.
The Contractor or contractor personnel’s failure to return all DHS- or FEMA-issued identification cards and building passes upon expiration, upon the contractor personnel’s removal from the contract, or upon demand by DHS or FEMA may subject the contractor personnel and the Contractor to civil and criminal liability.
RECORDS MANAGEMENT OBLIGATIONS
A. Applicability
This clause applies to all Contractors whose employees create work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.
B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law, or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.
The term Federal record:
• includes FEMA records;
• does not include personal materials;
• applies to records created, received, or maintained by Contractors pursuant to their FEMA contract; and
• may include deliverables and documentation associated with deliverables.
C. Requirements
1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C.
552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.
3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for
Government use or created, while performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
4. FEMA and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of FEMA or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to FEMA. The agency must report promptly to NARA in accordance with 36 CFR 1230.
5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records, or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the SOW. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records, and/or equipment is properly protected.
The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to FEMA control, or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the SOW.
Destruction of records is EXPRESSLY PROHIBITED unless in accordance with
Paragraph (4).
6. The Contractor is required to obtain the Contracting Officer’s approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any subcontractor) is required to abide by Government and FEMA guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.
7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with FEMA policy.
8. The Contractor shall not create or maintain any records containing any nonpublic FEMA information that are not specifically tied to or authorized by the contract.
9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.
10. FEMA owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which FEMA shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.
SAFEGUARDING OF CONTROLLED UNCLASSIFIED INFORMATION (JULY 2023)
(a) Definitions. As used in this clause— Adequate Security means security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls. Controlled Unclassified Information (CUI) is any information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government (other than classified information) that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. This definition includes the following CUI categories and subcategories of information:
(1) Chemical-terrorism Vulnerability Information (CVI) as defined in 6 CFR part 27, “Chemical Facility Anti-Terrorism Standards,” and as further described in supplementary guidance issued by an authorized official of the Department of Homeland Security (including the Revised Procedural Manual “Safeguarding Information Designated as Chemical-Terrorism Vulnerability Information” dated September 2008);
(2) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (title XXII, subtitle B of the Homeland Security Act of 2002 as amended through Pub. L. 116– 283), PCII’s implementing regulations (6 CFR part 29), the PCII Program Procedures Manual, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security, the PCII Program Manager, or a PCII Program Manager Designee;
(3) Sensitive Security Information (SSI) as defined in 49 CFR part 1520, “Protection of Sensitive Security Information,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or designee), including Department of Homeland Security MD 11056.1, “Sensitive Security Information (SSI)” and, within the Transportation Security Administration, TSA MD 2810.1, “SSI Program”;
(4) Homeland Security Agreement Information means information the Department of Homeland Security receives pursuant to an agreement with State, local, Tribal, territorial, or private sector partners that is required to be protected by that agreement.
The Department receives this information in furtherance of the missions of the Department, including, but not limited to, support of the Fusion Center Initiative and activities for cyber information sharing consistent with the Cybersecurity Information Sharing Act of 2015;
(5) Homeland Security Enforcement Information means unclassified information of a sensitive nature lawfully created, possessed, or transmitted by the Department of Homeland Security in furtherance of its immigration, customs, and other civil and criminal enforcement missions, the unauthorized disclosure of which could adversely impact the mission of the Department;
(6) International Agreement Information means information the Department of Homeland Security receives that is required to be protected by an information sharing agreement or arrangement with a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization;
(7) Information Systems Vulnerability Information (ISVI) means:
(i) Department of Homeland Security information technology (IT) systems data revealing infrastructure used for servers, desktops, and networks; applications name, version, and release; switching, router, and gateway information; interconnections and access methods; and mission or business use/need.
Examples of ISVI are systems inventories and enterprise architecture models. Information pertaining to national security systems and eligible for classification under Executive Order 13526 will be classified as appropriate; and/or
(ii) Information regarding developing or current technology, the release of which could hinder the objectives of the Department, compromise a technological advantage or countermeasure, cause a denial of service, or provide an adversary with sufficient information to clone, counterfeit, or circumvent a process or system;
(8) Operations Security Information means Department of Homeland Security information that could be collected, analyzed, and exploited by a foreign adversary to identify intentions, capabilities, operations, and vulnerabilities that threaten operational security for the missions of the Department;
(9) Personnel Security Information means information that could result in physical risk to Department of Homeland Security personnel or other individuals whom the Department is responsible for protecting;
(10) Physical Security Information means reviews or reports illustrating or disclosing facility infrastructure or security vulnerabilities related to the protection of Federal buildings, grounds, or property. For example, threat assessments, system security plans, contingency plans, risk management plans, business impact analysis studies, and certification and accreditation documentation;
(11) Privacy Information includes both Personally Identifiable Information (PII) and Sensitive Personally Identifiable Information (SPII). PII refers to information that can be used to distinguish or trace an individual’s identity, either alone, or when combined with other information that is linked or linkable to a specific individual; and SPII is a subset of PII that if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
To determine whether information is PII, the DHS will perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. In performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available, in any medium or from any source, that would make it possible to identify an individual. Certain data elements are particularly sensitive and may alone present an increased risk of harm to the individual.
i. Examples of stand-alone PII that are particularly sensitive include: Social Security numbers (SSNs), driver’s license or State identification numbers, Alien Registration Numbers (A-numbers), financial account numbers, and biometric identifiers.
ii. Multiple pieces of information may present an increased risk of harm to the individual when combined, posing an increased risk of harm to the individual. SPII may also consist of any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:
A. Truncated SSN (such as last 4 digits);
B. Date of birth (month, day, and year);
C. Citizenship or immigration status;
D. Ethnic or religious affiliation;
E. Sexual orientation;
F. Criminal history;
G. Medical information; and H. System authentication information, such as mother’s birth name, account passwords, or personal identification numbers (PINs).
i. Other PII that may present an increased risk of harm to the individual depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. The context includes the purpose for which the PII was collected, maintained, and used. This assessment is critical because the same information in different contexts can reveal additional information about the impacted individual. Federal information means information created, collected, processed, maintained, disseminated, disclosed, or disposed of by or for the Federal Government, in any medium or form. Federal information system means an information system used or operated by an agency or by a Contractor of an agency or by another organization on behalf of an agency. Handling means any use of controlled unclassified information, including but not limited to marking, safeguarding, transporting, disseminating, re-using, storing, capturing, and disposing of the information. Incident means an occurrence that—
(1) Actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or
(2) Constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Information Resources means information and related resources, such as personnel, equipment, funds, and information technology. Information Security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide—
(1) Integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;
(2) Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and
(3) Availability, which means ensuring timely and reliable access to and use of information. Information System means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
(b) Handling of Controlled Unclassified Information.
(1) Contractors and subcontractors must provide adequate security to protect CUI from unauthorized access and disclosure. Adequate security includes compliance with DHS policies and procedures in effect at the time of contract award. These policies and procedures are accessible at https://www.dhs.gov/dhs-security-and-training-requirements-contractors.
(2) The Contractor shall not use or redistribute any CUI handled, collected, processed, stored, or transmitted by the Contractor except as specified in the contract.
(3) The Contractor shall not maintain SPII in its invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions. It is acceptable to maintain in these systems the names, titles, and contact information for the Contracting Officer’s Representative (COR) or other government personnel associated with the administration of the contract, as needed.
(4) Any government data provided, developed, or obtained under the contract, or otherwise under the control of the Contractor, shall not become part of the bankruptcy estate in the event a Contractor and/or subcontractor enters bankruptcy proceedings.
(c) Incident Reporting Requirements.
(1) Contractors and subcontractors shall report all known or suspected incidents to the Component Security Operations Center (SOC) in accordance with Attachment F, Incident Response, to DHS Policy Directive 4300A Information Technology System Security Program, Sensitive Systems. If the Component SOC is not available, the Contractor shall report to the DHS Enterprise SOC. Contact information for the DHS Enterprise SOC is accessible at https://www.dhs.gov/dhs-personnel-security-info-reference-materials. Subcontractors are required to notify the prime Contractor that it has reported a known or suspected incident to the Department. Lower tier subcontractors are required to likewise notify their higher tier subcontractor, until the prime contractor is reached. The Contractor shall also notify the Contracting Officer and COR using the contact information identified in the contract. If the report is made by phone, or the email address for the Contracting Officer or COR is not immediately available, the Contractor shall contact the Contracting Officer and COR immediately after reporting to the Component or DHS Enterprise SOC.
(2) All known or suspected incidents involving PII or SPII shall be reported within 1 hour of discovery. All other incidents shall be reported within 8 hours of discovery.
(3) CUI transmitted via email shall be protected by encryption or transmitted within secure communications systems. CUI shall be transmitted using a FIPS 140-2/140-3 Security Requirements for Cryptographic Modules validated cryptographic module identified on https://csrc.nist.gov/Projects/cryptographic-module-validation-program/validated-modules. When this is impractical or unavailable, for Federal information systems only, CUI may be transmitted over regular email channels. When using regular email channels, Contractors and subcontractors shall not include any CUI in the subject or body of any email. The CUI shall be included as a password-protected attachment with the password provided under separate cover, including as a separate email. Recipients of CUI information will comply with any email restrictions imposed by the originator.
https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-personnel-security-info-reference-materials https://www.dhs.gov/dhs-personnel-security-info-reference-materials https://csrc.nist.gov/Projects/cryptographic-module-validation-program/validated-modules
(4) An incident shall not, by itself, be interpreted as evidence that the Contractor or Subcontractor has failed to provide adequate information security safeguards for CUI or has otherwise failed to meet the requirements of the contract.
(5) If an incident involves…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .