Synopsis_Solicitation_Document.docx
DOCX document 51 KB Posted
- Attached to
- SAP GSS Support/Maintenance Federal contract opportunity
- Solicitation number
- 2015-N-17233
About this file
Solicitation Document
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
Title of Project: SAP Government Secure Services Support and Maintenance
1. Contracting Officer Representative (COR) Ercila Harrison
2.0 Period of Performance
Base Year: 09/15/2015 – 09/14/2016 Option 1, Year 2: 09/15/2016 – 09/14/2017 Option 2, Year 3: 09/15/2017 – 09/14/2018 Option 3, Year 4: 09/15/2018 – 09/14/2019
3.0 Background and Need
As a result of centralized distribution, CDC now provides vaccine ordering support for over 44,000 health care providers in 64 grantees covering all states and territories of the United States. The legacy systems – VACMAN, NIPVAC and Vaccine Ordering and Forecasting Application (VOFA) – that CDC relies on to support this new operating model use outdated software and hardware that no longer meets the business needs of the federal government. These systems have been modified to adapt them to the current business model, yet there are still significant shortfalls and risks in their ability to support the Vaccine Management Business Improvement Project (VMBIP) vision.
VTrckS, developed in SAP, is a web-based system for provider ordering and automated approvals that will improve operational efficiency and internal controls. It is a SAP based comprehensive IT solution that eliminates current legacy system limitations, provides a scalable platform, and facilitates central administration of vaccine management. VTrckS allows providers to order directly from the Internet, improves internal controls, significantly reduces manual processes, and provides transparency into provider usage patterns improving data analysis capability. This real-time inventory visibility improves preparedness, allows for a greater focus on public health, and reduces time and resources devoted to managing vaccines and funding.
VTrckS is an enterprise-wide ordering supply chain management system integrating vaccine ordering, forecasting, budget management, and contract management that will enable far more effective and efficient management of CDC’s public vaccine programs. Integration of the vaccine business processes will provide a comprehensive, end-to-end, singular view of the program. When fully deployed, VTrckS will serve three levels of users:
1. CDC – approximately 150 people
1. Immunization program offices (grantees) – totaling approximately 800 people located in 64 grantee offices
1. Individual users – approximately 100,000 individual users located in approximately 44,000 vaccine provider locations)
VTrckS was deployed to four pilot grantees on December 13, 2010. Two of the pilot grantees have immunization registries that they use to submit vaccine orders into VTrckS through an interface. The other two grantees and their providers enter vaccination directly into the VTrckS. Release 2.0 of VTrckS has been deployed to the pilot grantees on February 27, 2012. The rollout to the all grantees was completed in May 2013.
4.0 Project Objective
To renew the Enterprise Secure Support, SAP subscriptions and licenses maintenance for VTrckS under current contract 200-2012-52946 (POP’s 09/01/2012 – 09/14/2015).
These items were previously procured under contracts:
1. SAP GSS software, licensed under SAP Public Services Inc. and citing CDC POs 200-2011-40452, (POP 9/1/11 – 8/31/12);
1. 200-2011-41745, (POP 9/1/11 – 8/31/12);
1. 200-2011-40995, (POP 9/1/11 – 8/31/12); and
1. 200-2011- 42414 (POP 1/1/12 – 8/31/12) (previous PO# 34411) which was comprised of:
1. Northrop Grumman Order No. 70772L356C, August 30, 2006 = $900,000
2. Northrop Grumman Order No. 7000076213, September 30, 2008 = $311,063 (CLIN 2 - Loadrunner and Quality Center Software)
3. Northrop Grumman Order No. 7000076213, September 30, 2008 = $68,434 (CLIN 4 - TAO Software)
Complete detail of SAP license information is attached as an appendix to the document.
5.0 Scope of Work
The contract will be a renewal of SAP Secure Enterprise Support and annual software maintenance subscription for current contracts listed in section 4.0: Project Objectives. The contractor shall provide continuous improvement and innovation through software releases and technology updates. Through the use of web portals, the contractor will provide a support backbone which is available through the internet at anytime. The contractor will provide mission critical support for the SAP installations at the CDC. The contractor will through normal SAP business practices provide Early Watch alert information. The contractor will respond to reports of malfunctions and issue with the SAP software in accordance with the SLA agreements under SAP Enterprise Secure Support. The contractor will perform root cause analysis and go-live checks with any releases of VTrckS.
6.0 Technical Requirements
The technical requirements will include SAP Government Secure Enterprise Support and annual software maintenance subscription. Examples of this support include:
Continuous Improvement and Innovation
• New software releases of the licensed Enterprise Support Solutions, as well as tools and procedures for upgrades.
• Support packages - correction packages to reduce the effort of implementing single corrections or changes to existing functionality. Support packages may also contain corrections to adapt existing functionality to changed legal and regulatory requirements.
• Technology updates to support third-party operating systems and databases.
• Available ABAP source code for Software applications and additionally released and supported function modules.
• Software change management processes and tools.
Global Support Backbone
• SAP Service Marketplace - SAP's knowledge database and SAP’s extranet for knowledge transfer on which SAP makes available content and services to licensees and partners of SAP.
• SAP Notes on the SAP Service Marketplace document software errors and contain information on how to remedy, avoid and bypass errors. SAP Notes may contain coding corrections that customers can implement into their SAP system. SAP Notes also documents related issues, customer questions, and recommended solutions (e.g. customizing settings).
• SAP Note Assistant - a tool to install specific corrections and improvements to SAP components.
• SAP Solution Manager Enterprise Edition – as described in Section 2.2
Mission Critical Support Mission Critical Support - Global message handling by SAP for problems related to Enterprise Support Solutions (excluding software to which special support agreements apply), including Service Level Agreements for Initial Reaction Time and Corrective Action. This includes:
• Global 24x7 root cause analysis and escalation procedures for messages not handled under Secure Support (for more information refer to Section 2.1).
• Secure Support – Secure Support elements consisting of Secure remote Connection and Secure Backoffice, Secure Support Advisor, Secure Support Setup, and Secure Continuous Quality Checks as described in Sections 2.3, 2.4, 2.5 and 2.6.
Other Components, Methodologies, Content and Community Participation
• Monitoring components and agents for systems to help optimize available resources with SAP EarlyWatch Alert.
• Collector components for systems to report on the status of the Enterprise Support Solutions.
• Content and supplementary tools designed to help increase efficiency, which may include implementation methodologies and standard procedures, Best Practices, an Implementation Guide (IMG), Business Configuration (BC) Sets and Customizing Monitoring.
• Access to the SAP Service Marketplace, which may include implementation and operations processes and content designed to help reduce costs and risks.
• Participation in SAP's customer and partner community (via SAP Service Marketplace), which provides data about best business practices, service offerings, etc.
2.1. Global Message Handling and Service Level Agreement (SLA). When Licensee reports malfunctions, SAP supports Licensee by providing information on how to remedy, avoid and bypass errors. The main channel for such support will be the support infrastructure provided by SAP. Licensee may send an error message at any time. When Licensee creates an error message, the system automatically collects the most important system data (transaction code, program ID, Support Package level, message number, etc). All persons involved in the message solving process can access the status of the message at any time.
In exceptional cases, Licensee may also contact SAP by telephone. For such contact (and as otherwise provided) SAP requires that License provide remote access as specified in Section 3.2(iii). SAP Enterprise Support is provided exclusively to Licensee’s Customer Center of Expertise.
The following Service Level Agreements (“SLA” or “SLAs”) shall apply to all Licensee support messages that SAP accepts as being Priority 1 and which fulfill the prerequisites specified herein. Such SLAs shall commence in the first full Calendar Quarter following the Effective Date of this Addendum. As used herein, “Calendar Quarter” is the three month period ending on March 31, June 30, September 30 and December 31 respectively of any given calendar year.
Licensee understands and agrees that to the extent the SAP Software contains products and/or software components licensed or resold by SAP from a third party, SAP requires the support of such third party to meet the SLAs. The time frames as specified in the table below shall commence upon receipt of the message.
2.1.1 SLA for Initial Response Times: Priority 1 Support Messages (“Very High”). SAP shall respond to Priority 1 support messages within one (1) hour of SAP’s receipt (twenty-four hours a day, seven days a week) of such Priority 1 support messages. A message is assigned Priority 1 if the problem has very serious consequences for normal business transactions and urgent, business critical work cannot be performed. This is generally caused by the following circumstances: complete system outage, malfunctions of central SAP functions in the Production System, or Top-Issues.
2.1.2 SLA for Corrective Action Response Time for Priority 1 Support Messages: SAP shall provide a solution, work around or action plan for resolution (“Corrective Action”) of Licensee’s Priority 1 support message within four (4) hours of SAP’s receipt (twenty-four hours a day, seven days a week) of such Priority 1 support message (“SLA for Corrective Action”). In the event an action plan is submitted to Licensee as a Corrective Action, such action plan shall include: (i) status of the resolution process; (ii) planned next steps, including identifying responsible SAP resources; (iii) required Licensee actions to support the resolution process; (iv) to the extent possible, due dates for SAP’s actions; and (v) date and time for next status update from SAP. Subsequent status updates shall include a summary of the actions undertaken so far; planned next steps; and date and time for next status update. The SLA for Corrective Action only refers to that part of the processing time when the message is being processed at SAP (“Processing Time”). Processing Time does not include the time when the message is on status “Partner Action”, “Customer Action” or “SAP Proposed Solution”, whereas (a) the status Partner Action means the support message was handed over to a technology or software partner of SAP or a third party vendor of SAP for further processing; (b) the status Customer Action means the support message was handed over to Licensee; and (c) the status SAP Proposed Solution means SAP has provided a Corrective Action as outlined herein. The SLA for Corrective Action shall be deemed met if within four (4) hours of processing time: SAP proposes a solution (status “SAP Proposed Solution”), a workaround or an action plan; or if Licensee agrees to reduce the priority level of the message.
7.0 Reporting Schedule
The contractor will provide reports on system to help optimize the resources used in the CDC SAP system. Examples of these reports include:
1. Early Watch Reports
1. Root Cause Analysis Reports
1. Go-Live Check Reports
The contractor will have at least a monthly touch point call with COR or designated representative to discuss any open service requests.
8.0 Special Considerations
8.1 Where necessary, employees of the contractor will present credentials necessary to receive badges (PIV cards) from the CDC in order to access the VTrckS system.
8.2 Section 508 of the Rehabilitation Act
Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, all electronic and information technology (EIT) products and services developed, acquired, maintained, and/or used under this contract/order must comply with the “Electronic and Information Technology Accessibility Provisions” set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in 36 CFR part 1194. Information about Section 508 provisions is available at http://www.section508.gov/. The complete text of Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/provisions.htm.
The Section 508 standards applicable to this contract/order are identified in the Statement of Work/Specification/Performance Work Statement. The contractor must provide a written Section 508 conformance certification due at the end of each order/contract exceeding $100,000 when the order/contract duration is one year or less. If it is determined by the Government that EIT products and services provided by the Contractor do not conform to the described accessibility in the Product Assessment Template, remediation of the products and/or services to the level of conformance specified in the vendor’s Product Assessment Template will be the responsibility of the Contractor at its own expense In the event of a modification(s) to this contract/order, which adds new EIT products and services or revises the type of, or specifications for, products and services the Contractor is to provide, including EIT deliverables such as electronic documents and reports, the Contracting Officer may require that the contractor submit a completed HHS Section 508 Product Assessment Template to assist the Government in determining that the EIT products and services support Section 508 accessibility requirements. Instructions for documenting accessibility via the HHS Section 508 Product Assessment Template may be found at http://www.hhs.gov/web/508/contracting/index.html.
Prior to the Contracting Officer exercising an option for a subsequent performance period/additional quantity or adding incremental funding for a subsequent performance period under this contract, as applicable, the Contractor must provide a Section 508 Annual Report to the Contracting Officer and Contracting Officer’s Technical Representative (also known as Project Officer or Contracting Officer’s Representative). Unless otherwise directed by the Contracting Officer in writing, the Contractor shall provide the cited report in accordance with the following schedule. Instructions for completing the report are available at: http://www.hhs.gov/web/508/contracting/technology/vendors.html. The Contractor’s failure to submit a timely and properly completed report may jeopardize the Contracting Officer’s exercising an option or adding incremental funding, as applicable.
Schedule for Contractor Submission of Section 508 Annual Report: January 2016; January 2017; January 2018; January 2019. The applicable provisions of this solicitation are: 1194.21, .22, .31, and .41.
8.3 The Paperwork Reduction Act of 1995 (PRA)
Offerors are advised that any activities involving information collections (i.e., surveys, questionnaires, applications, audits, data requests, reporting, recordkeeping and disclosure requirements, etc.) from 10 or more non-Federal entities, including State and local governmental agencies, are subject to the conditions of the PRA. Under the PRA, a Federal agency sponsoring a standardized data collection or directly obtaining standardized or substantially similar information from ten or more persons or entities (other than Federal employees within the scope of their employment) in any 12-month period must obtain advance written approval from the Office of Management and Budget (OMB).” Regardless of form or format (oral, written, or electronically transmitted), responses of opinion or fact requested or required by or for CDC, except those specifically exempted or excluded, are subject to the provisions of the PRA and its implementing regulation, 5 CFR 1320 (Controlling Paperwork Burdens on the Public).”
9.0 Government Furnished Property
Should it become necessary for government equipment to be issued to the contractor, all governmental requirements in the monitoring, maintenance and care of the equipment will be adhered to by the contractor.
10. Deliverables
Deliverables will be in the form of software updates and upgrades, and SAP solution support made available through a web portal online. The software updates and upgrades will be made available as they are released to the public. The deliverables also include early watch reports and exception support; and go-live checks when required for all VTrckS future releases.
SAP Licenses and Government Secure Support Services Renewal
SAP Landscape
1. Northrop PO #70772L356 to SAP Public Services: mySAP software
a. Professional Users, Qty 50 Named Users
b. Limited Professional Users/Managerial Approval roles, Qty 800 Named Users
c. Limited Professional Users/B2B selling role, Qty 74,000 Named Users
d. Developer Users, Qty 5 Named Users
e. SAP XI Base Engine, Qty 10,000 GigaBytes per Month
f. SAP Grants Management (included)
2. Northrop PO #7000076213 to SAP Public Services: CLIN 2-Loadrunner and QC software
a. SAP Loadrunner by HP, Qty 1,000 Virtual Users
b. SAP Quality Center by HP, Qty 6 Testers
3. Northrop PO #7000076213 to SAP Public Services: CLIN 4-TAO
a. SAP Test Acceleration & Optimization (TAO), Qty 6 Testers
SAP Add-on and BOBJ Software
| SAP Quality Center Full Bundle by HP |
| 3 Each |
| SAP Loadrunner by HP: 8 blocks of 250 concurrent users |
| 8 Each |
| SAP Sol Man Adapter for SAP Quality Center - 1 Instance |
| 1 Each |
| SAP Business Objects - Web Intelligence (5 CPUs) |
| 5 Each |
| SAP Net Weaver OpenHub - 1 installation |
| 1 Each |
| SAP BOBJ Knowledge Accelerator for Web Intelligence - 1 Connected System |
| 1 Each |
SAP RWD Software
SAP Productivity Pack by RWD with help Launch Pad & Roadmap Service Pack to include:
1. SAP Productivity Pack for 900 licenses
2. SAP Productivity Pack Adaptor for Sol Man
3. SAP Productivity Pack Launch Pad 900 Licenses
SAP Add-on
| SAP Quality Center by HP Full Bundle |
| 30 Each |
| Testing Accelerator Optimization Used to Accelerate SAP Quality Center |
| 20 Each |
| Professional Users |
| 20 Each |
| Limited Professional Users |
| 200 Each |
Contract No.
SECTION C - CONTRACT CLAUSES
C.1 52.212-5 - Contract Terms and Conditions Required to Implement Statutes or Executive Orders -- Commercial Items (May 2015)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
(1) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Dec 2014)
(2) 52.233-3, Protest After Award (AUG 1996) (31 U.S.C. 3553).
(3) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77, 108-78 (19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the contracting officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
[Contracting Officer check as appropriate.] _X__ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Sept 2006), with Alternate I (Oct 1995) (41 U.S.C. 4704 and 10 U.S.C. 2402).
___ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (Apr 2010) (41 U.S.C. 3509).
___ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (Jun 2010) (Section 1553 of Pub L. 111-5) (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009).
_X__ (4) 52.204-10, Reporting Executive compensation and First-Tier Subcontract Awards (Jul 2013) (Pub. L. 109-282) (31 U.S.C. 6101 note).
___ (5) [Reserved] ___ (6) 52.204-14, Service Contract Reporting Requirements (Jan 2014) (Pub. L. 111-117, section 743 of Div. C).
___ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Jan 2014) (Pub. L. 111-117, section 743 of Div. C).
_X__ (8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment (Aug 2013) (31 U.S.C. 6101 note).
___ (9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Jul 2013) (41 U.S.C. 2313).
___ (10) [Reserved] ___ (11) (i) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Nov 2011) (15 U.S.C. 657a).
___ (ii) Alternate I (Nov 2011) of 52.219-3.
___ (12) (i) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Oct 2011) (if the offeror elects to waive the preference, it shall so indicate in its offer)(15 U.S.C. 657a).
___ (ii) Alternate I (Jan 2011) of 52.219-4.
___ (13) [Reserved] ___ (14) (i) 52.219-6, Notice of Total Small Business Aside (Nov 2011) (15 U.S.C. 644).
___ (ii) Alternate I (Nov 2011).
___ (iii) Alternate II (Nov 2011).
___ (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (June 2003) (15 U.S.C. 644).
___ (ii) Alternate I (Oct 1995) of 52.219-7.
___ (iii) Alternate II (Mar 2004) of 52.219-7.
_X__ (16) 52.219-8, Utilization of Small Business Concerns (Oct 2014) (15 U.S.C. 637(d)(2) and (3)).
___ (17) (i) 52.219-9, Small Business Subcontracting Plan (Oct 2014) (15 U.S.C. 637 (d)(4)).
___ (ii) Alternate I (Oct 2001) of 52.219-9.
___ (iii) Alternate II (Oct 2001) of 52.219-9.
___ (iv) Alternate III (Oct 2014) of 52.219-9.
___ (18) 52.219-13, Notice of Set-Aside of Orders (Nov 2011) (15 U.S.C. 644(r)).
___ (19) 52.219-14, Limitations on Subcontracting (Nov 2011) (15 U.S.C. 637(a)(14)).
___ (20) 52.219-16, Liquidated Damages—Subcontracting Plan (Jan 1999) (15 U.S.C. 637(d)(4)(F)(i)).
___ (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (Nov 2011) (15 U.S.C. 657f).
_X__ (22) 52.219-28, Post Award Small Business Program Rerepresentation (Jul 2013) (15 U.S.C. 632(a)(2)).
___ (23) 52.219-29, Notice of Set-Aside for Economically Disadvantaged Women-Owned Small Business (EDWOSB) Concerns (Jul 2013) (15 U.S.C. 637(m)).
___ (24) 52.219-30, Notice of Set-Aside for Women-Owned Small Business (WOSB) Concerns Eligible Under the WOSB Program (Jul 2013) (15 U.S.C. 637(m)).
_X__ (25) 52.222-3, Convict Labor (June 2003) (E.O. 11755).
___ (26) 52.222-19, Child Labor—Cooperation with Authorities and Remedies (Jan 2014) (E.O. 13126).
_X__ (27) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).
_X__ (28) 52.222-26, Equal Opportunity (Apr 2015) (E.O. 11246).
_X__ (29) 52.222-35, Equal Opportunity for Veterans (Jul 2014) (38 U.S.C. 4212).
_X__ (30) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) (29 U.S.C. 793).
_X__ (31) 52.222-37, Employment Reports on Veterans (Jul 2014) (38 U.S.C. 4212).
_X__ (32) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496).
__X_ (33) (i) 52.222-50, Combating Trafficking in Persons (Mar 2015) (22 U.S.C. chapter 78 and E.O. 13627).
___ (ii) Alternate I (Mar 2015) of 52.222-50, (22 U.S.C. chapter 78 and E.O. 13627).
___ (34) 52.222-54, Employment Eligibility Verification (Aug 2013). (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial items as prescribed in 22.1803.)
___ (35) (i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA-Designated Items (May 2008) (42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
___ (ii) Alternate I (May 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
___ (36) (i) 52.223-13, Acquisition of EPEAT® -Registered Imaging Equipment (Jun 2014) (E.O.s 13423 and 13514 ___ (ii) Alternate I (Jun 2014) of 52.223-13.
___ (37) (i) 52.223-14, Acquisition of EPEAT® -Registered Television (Jun 2014) (E.O.s 13423 and 13514).
___ (ii) Alternate I (Jun 2014) of 52.223-14.
___ (38) 52.223-15, Energy Efficiency in Energy-Consuming Products (Dec 2007) (42 U.S.C. 8259b).
___ (39) (i) 52.223-16, Acquisition of EPEAT® -Registered Personal Computer Products (Jun 2014) (E.O.s 13423 and 13514).
___ (ii) Alternate I (Jun 2014) of 52.223-16.
_X__ (40) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging while Driving (Aug 2011) (E.O. 13513).
_X__ (41) 52.225-1, Buy American--Supplies (May 2014) (41 U.S.C. chapter 83).
___ (42) (i) 52.225-3, Buy American--Free Trade Agreements--Israeli Trade Act (May 2014) (41 U.S.C. chapter 83, 19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, Pub. L. 103-182, 108-77, 108-78, 108-286, 108-302, 109-53, 109-169, 109-283, 110-138, 112-41, 112-42, and 112-43).
___ (ii) Alternate I (May 2014) of 52.225-3.
___ (iii) Alternate II (May 2014) of 52.225-3.
___ (iv) Alternate III (May 2014) of 52.225-3.
___ (43) 52.225-5, Trade Agreements (Nov 2013) (19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note).
_X__ (44) 52.225-13, Restrictions on Certain Foreign Purchases (Jun 2008) (E.O.’s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).
___ (45) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Jul 2013) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).
___ (46) 52.226-4, Notice of Disaster or Emergency Area Set-Aside (Nov 2007) (42 U.S.C. 5150).
___ (47) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (Nov 2007) (42 U.S.C. 5150).
___ (48) 52.232-29, Terms for Financing of Purchases of Commercial Items (Feb 2002) (41 U.S.C. 4505), 10 U.S.C. 2307(f)).
___ (49) 52.232-30, Installment Payments for Commercial Items (Oct 1995) (41 U.S.C. 4505, 10 U.S.C. 2307(f)).
_X__ (50) 52.232-33, Payment by Electronic Funds Transfer— System for Award Management (Jul 2013) (31 U.S.C. 3332).
___ (51) 52.232-34, Payment by Electronic Funds Transfer—Other Than System for Award Management (Jul 2013) (31 U.S.C. 3332).
___ (52) 52.232-36, Payment by Third Party (May 2014) (31 U.S.C. 3332).
___ (53) 52.239-1, Privacy or Security Safeguards (Aug 1996) (5 U.S.C. 552a).
___ (54) (i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (Feb 2006) (46 U.S.C. Appx 1241(b) and 10 U.S.C. 2631).
___ (ii) Alternate I (Apr 2003) of 52.247-64.
(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or executive orders applicable to acquisitions of commercial items:
[Contracting Officer check as appropriate.] ___ (1) 52.222-17, Nondisplacement of Qualified Workers (May 2014) (E.O. 13495) ___ (2) 52.222-41, Service Contract Labor Standards (May 2014) (41 U.S.C. chapter 67.).
___ (3) 52.222-42, Statement of Equivalent Rates for Federal Hires (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).
___ (4) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards -- Price Adjustment (Multiple Year and Option Contracts) (May 2014) (29 U.S.C.206 and 41 U.S.C. chapter 67).
___ (5) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards -- Price Adjustment (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).
___ (6) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment--Requirements (May 2014) (41 U.S.C. chapter 67).
___ (7) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services--Requirements (May 2014) (41 U.S.C. chapter 67).
___ (8) 52.222-55, Minimum Wages Under Executive Order 13658 (Dec 2014) (E.O. 13658).
___ (9) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations. (May 2014) (42 U.S.C. 1792).
___ (10) 52.237-11, Accepting and Dispensing of $1 Coin (Sep 2008) (31 U.S.C. 5112(p)(1)).
(d) Comptroller General Examination of Record The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, and does not contain the clause at 52.215-2, Audit and Records -- Negotiation.
(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor’s directly pertinent records involving transactions related to this contract.
(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR Subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.
(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.
(e)
(1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c) and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial items. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause—
(i) 52.203-13, Contractor Code of Business Ethics and Conduct (Apr 2010) (41 U.S.C. 3509).
(ii) 52.219-8, Utilization of Small Business Concerns (Oct 2014) (15 U.S.C. 637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds $650,000 ($1.5 million for construction of any public facility), the subcontractor must include 52.219-8 in lower tier subcontracts that offer subcontracting opportunities.
(iii) 52.222-17, Nondisplacement of Qualified Workers (May 2014) (E.O. 13495). Flow down required in accordance with paragraph (1) of FAR clause 52.222-17.
(iv) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).
(v) 52.222-26, Equal Opportunity (Apr 2015) (E.O. 11246).
(vi) 52.222-35, Equal Opportunity for Veterans (Jul 2014) (38 U.S.C. 4212).
(vii) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) (29 U.S.C. 793).
(viii) 52.222-37, Employment Reports on Veterans (Jul 2014) (38 U.S.C. 4212).
(ix) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.
(x) 52.222-41, Service Contract Labor Standards (May 2014), (41 U.S.C. chapter 67).
(xi) __X__ (A) 52.222-50, Combating Trafficking in Persons (Mar 2015) (22 U.S.C. chapter 78 and E.O. 13627).
___ (B) Alternate I (Mar 2015) of 52.222-50 (22 U.S.C. chapter 78 E.O. 13627).
(xii) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment--Requirements (May 2014) (41 U.S.C. chapter 67.)
(xiii) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services--Requirements (May 2014) (41 U.S.C. chapter 67)
(xiv) 52.222-54, Employment Eligibility Verification (Aug 2013).
(xv) 52.222-55, Minimum Wages Under Executive Order 13658 (Dec 2014) (E.O. 13658).
(xvi) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Jul 2013) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).
(xvii) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations. (May 2014) (42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.
(xviii) 52.247-64, Preference for Privately-Owned U.S. Flag Commercial Vessels (Feb 2006) (46 U.S.C. Appx 1241(b) and 10 U.S.C. 2631). Flow down required in accordance with paragraph (d) of FAR clause 52.247-64.
(2) While not required, the contractor may include in its subcontracts for commercial items a minimal number of additional clauses necessary to satisfy its contractual obligations.
(End of Clause)
| C.2 | The following FAR Clauses are incorporated by reference*: | |
| FAR Source | ||
| Clause Title and Date |
| 52.204-7 |
| System for Award Management (Jul 2013) |
| 52.212-4 |
| Contract Terms and Conditions -- Commercial Items (May 2015) |
| 52.242-15 |
| Stop-Work Order (Aug. 1989) |
| 52.243-1 |
| Changes -- Fixed Price (Aug 1987) |
| 52.245-1 |
| Government Property (Apr 2012) |
*The full text of the referenced FAR clauses may be accessed electronically at http://farsite.hill.af.mil/vffara.htm
| C.3 | The following HHSAR Clauses are incorporated by reference*: | |
| HHSAR Source | ||
| Clause Title and Date |
| 352.222-70 |
| Contractor Cooperation in Equal Employment Opportunity Investigations (January 2010) |
| 352.227-70 |
| Publications and Publicity (Jan 2006) |
| 352.231-71 |
| Pricing of Adjustments (Jan 2001) |
| 352.242-70 |
| Key Personnel (Jan 2006) |
*The full text of the referenced HHSAR clauses may be accessed electronically at http://farsite.hill.af.mil/vfhhsara.htm
| C.4 | In addition, the selected offeror must comply with the following FAR, HHSAR, and CDC local clauses incorporated here in in full text. |
| C.4.1 | 352.202-1 Definitions (January 2006) |
(a) In accordance with 52.202–1(a)(1), substitute the following as paragraph (a):
‘‘(a) The term ‘‘Secretary’’ or ‘‘Head of the Agency’’ (also called ‘‘Agency Head’’) means the Secretary, Deputy Secretary, or any Assistant Secretary, Administrator or Commissioner of the Department of Health and Human Services; and the term ‘‘his/her duly authorized representative’’ means any person, persons, or board authorized to act for the Secretary.’’
(b) In accordance with 52.202–1(a)(1), add the following paragraph (h):
‘‘(h) The term ‘‘Contracting Officer’s Technical Representative” means the person who monitors the technical aspects of contract performance. The Contracting Officer’s Technical Representative is not authorized to issue any instructions or directions which cause any increase or decrease in the Statement of Work/Performance Work Statement/Specifications which would result in the increase or decrease in the price of this contract, or changes in the delivery schedule or period of performance of this contract. If applicable, the Contracting Officer’s Technical Representative is not authorized to receive or act upon any notification or revised cost estimate provided by the Contractor in accordance with the Limitation of Cost or Limitation of Funds clauses of this contract.’’ C.4.2 HHSAR 352.203-70 Anti Lobbying (Mar 2012) Pursuant to the current HHS annual appropriations act, Public Law 112-74, except for normal and recognized executive-legislative relationships, the Contractor shall not use any HHS contract funds for:
(a) Publicity or propaganda purposes
(b) the preparation, distribution, or use of any kit, pamphlet, booklet, publication, electronic communication, radio, television, or video presentation, designed to support or defeat the enactment of legislation before the Congress or any State or local legislature or legislative body or designed to support or defeat any proposed or pending regulation, administrative action, or order issued by the executive branch of any State or local government itself
(c) Paying the salary or expenses of the Contractor, or agent acting for the Contractor, related to any activity designed to influence the enactment of legislation, appropriations, regulation, administrative action, or Executive order proposed or pending before the Congress or any State government, State legislature or local legislature or legislative body, other than normal and recognized executive-legislative relationships or participation by an agency or officer of a State, local or tribal government in policymaking and administrative processes within the executive branch of that government.
The prohibitions above shall include any activity to advocate or promote any proposed, pending or future Federal, State or local tax increase, or any proposed, pending, or future requirement for, or restriction on, any legal consumer product, including its sale or marketing, including, but not limited to, the advocacy or promotion of gun control.
(end of clause) C.4.3 352.239-70 Standard for Security Configurations (Jan 2010)
(a) The Contractor shall configure its computers that contain HHS data with the applicable Federal Desktop Core Configuration (FDCC) (see http://nvd.nist.gov/fdcc/index.cfm) and ensure that its computers have and maintain the latest operating system patch level and anti-virus software level. (Note: FDCC is applicable to all computing systems using Windows XP™ and Windows Vista™, including desktops and laptops—regardless of function—but not including servers.)
(b) The Contractor shall apply approved security configurations to information technology (IT) that is used to process information on behalf of HHS. The following security configuration requirements apply:
(NOTE: The Contracting Officer shall specify applicable security configuration requirements in solicitations and contracts based on information provided by the Project Officer, who shall consult with the OPDIV/STAFFDIV Chief Information Security Officer.)
(c) The Contractor shall ensure IT applications operated on behalf of HHS are fully functional and operate correctly on systems configured in accordance with the above configuration requirements. The Contractor shall use Security Content Automation Protocol (SCAP)-validated tools with FDCC Scanner capability to ensure its products operate correctly with FDCC configurations and do not alter FDCC settings – see http://scap.nist.gov/validation/. The Contractor shall test applicable product versions with all relevant and current updates and patches installed. The Contractor shall ensure currently supported versions of information technology products meet the latest FDCC major version and subsequent major versions.
(d) The Contractor shall ensure IT applications designed for end users run in the standard user context without requiring elevated administrative privileges.
(e) The Contractor shall ensure hardware and software installation, operation, maintenance, update, and patching will not alter the configuration settings or requirements specified above.
(f) The Contractor shall (1) include Federal Information Processing Standard (FIPS) 201-compliant (see http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf), Homeland Security Presidential Directive 12 (HSPD-12) card readers with the purchase of servers, desktops, and laptops; and (2) comply with FAR Subpart 4.13, Personal Identity Verification.
(g) The Contractor shall ensure that its subcontractors (at all tiers) which perform work under this contract comply with the requirements contained in this clause.
(End of clause) C.4.4 352.239-71 Standard for Encryption Language (Jan 2010)
(a) The Contractor shall use Federal Information Processing Standard (FIPS) 140-2-(PDF) compliant encryption (Security Requirements for Cryptographic Module, as amended) to protect all instances of HHS sensitive information during storage and transmission. (Note: The Government has determined that HHS information under this contract is considered “sensitive” in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems, dated February 2004.)
(b) The Contractor shall verify that the selected encryption product has been validated under the Cryptographic Module Validation Program (see http://csrc.nist.gov/cryptval/) to confirm compliance with FIPS 140-2 (as amended). The Contractor shall provide a written copy of the validation documentation to the Contracting Officer and the Contracting Officer’s Technical Representative.
(c) The Contractor shall use the Key Management Key (see FIPS 201, Chapter 4, as amended) on the HHS personal identification verification (PIV) card; or alternatively, the Contractor shall establish and use a key recovery mechanism to ensure the ability for authorized personnel to decrypt and recover all encrypted information (see http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf). The Contractor shall notify the Contracting Officer and the Contracting Officer’s Technical Representative of personnel authorized to decrypt and recover all encrypted information.
(d) The Contractor shall securely generate and manage encryption keys to prevent unauthorized decryption of information in accordance with FIPS 140-2 (as amended).
(e) The Contractor shall ensure that this standard is incorporated into the Contractor’s property management/control system or establish a separate procedure to account for all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive HHS information.
(f) The Contractor shall ensure that its subcontractors (at all tiers) which perform work under this contract comply with the requirements contained in this clause.
(End of clause) C.4.5 352.239-72 Security Requirements for Federal Information Technology Resources (Jan 2010)
(a) Applicability. This clause applies whether the entire contract or order (hereafter “contract”), or portion thereof, includes information technology resources or services in which the Contractor has physical or logical (electronic) access to, or operates a Department of Health and Human Services (HHS) system containing, information that directly supports HHS’ mission. The term “information technology (IT)”, as used in this clause, includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services) and related resources. This clause does not apply to national security systems as defined in FISMA.
(b) Contractor responsibilities. The Contractor is responsible for the following:
(1) Protecting federal information and federal information systems in order to ensure their—
(i) Integrity, which means guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity;
(ii) Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and.
(iii) Availability, which means ensuring timely and reliable access to and use of information.
(2) Providing security of any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor, regardless of location, on behalf of HHS.
(3) Adopting, and implementing, at a minimum, the policies, procedures, controls, and standards of the HHS Information Security Program to ensure the integrity, confidentiality, and availability of federal information and federal information systems for which the Contractor is responsible under this contract or to which it may otherwise have access under this contract. The HHS Information Security Program is outlined in the HHS Information Security Program Policy, which is available on the HHS Office of the Chief Information Officer’s (OCIO) website.
(c) Contractor security deliverables. In accordance with the timeframes specified, the Contractor shall prepare and submit the following security documents to the Contracting Officer for review, comment, and acceptance:
(1) IT Security Plan (IT-SP) – due within 30 days after contract award. The IT-SP shall be consistent with, and further detail the approach to, IT security contained in the Contractor’s bid or proposal that resulted in the award of this contract. The IT-SP shall describe the processes and procedures that the Contractor will follow to ensure appropriate security of IT resources that are developed, processed, or used under this contract. If the IT-SP only applies to a portion of the contract, the Contractor shall specify those parts of the contract to which the IT-SP applies.
(i) The Contractor’s IT-SP shall comply with applicable federal laws that include, but are not limited to, the Federal Information Security Management Act (FISMA) of 2002 (PDF) (Title III of the E-Government Act of 2002, Public Law 107-347), and the following federal and HHS policies and procedures:
(A) Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources, Appendix III, Security of Federal Automated Information Resources.
(B) National Institute of Standards and Technology (NIST) Special Publication (SP) 800-18 (PDF), Guide for Developing Security Plans for Federal Information Systems, in form and content, and with any pertinent contract Statement of Work/Performance Work Statement (SOW/PWS) requirements. The IT-SP shall identify and document appropriate IT security controls consistent with the sensitivity of the information and the requirements of Federal Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems. The Contractor shall review and update the IT-SP in accordance with NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems and FIPS 200, on an annual basis.
(C) HHS-OCIO Information Systems Security and Privacy Policy.
(ii) After resolution of any comments provided by the Government on the draft IT-SP, the Contracting Officer shall accept the IT-SP and incorporate the Contractor’s final version into the contract for Contractor implementation and maintenance. On an annual basis, the Contractor shall provide to the Contracting Officer verification that the IT-SP remains valid.
(2) IT Risk Assessment (IT-RA) – due within 30 days after contract award. The IT-RA shall be consistent, in form and content, with NIST SP 800-30, Risk Management Guide for Information Technology Systems, and any additions or augmentations described in the HHS-OCIO Information Systems Security and Privacy Policy. After resolution of any comments provided by the Government on the draft IT-RA, the Contracting Officer shall accept the IT-RA and incorporate the Contractor’s final version into the contract for Contractor implementation and maintenance. The Contractor shall update the IT-RA on an annual basis.
(3) FIPS 199 Standards for Security Categorization of Federal Information and Information Systems Assessment (FIPS 199 Assessment) – due within 30 days after contract award. The FIPS 199 Assessment shall be consistent with the cited NIST standard. After resolution of any comments by the Government on the draft FIPS 199 Assessment, the Contracting Officer shall accept the FIPS 199 Assessment and incorporate the Contractor’s final version into the contract.
(4) IT Security Certification and Accreditation (IT-SC&A) – due within 3 months after contract award. The Contractor shall submit written proof to the Contracting Officer that an IT-SC&A was performed for applicable information systems – see paragraph (a) of this clause. The Contractor shall perform the IT-SC&A in accordance with the HHS Chief Information Security Officer’s Certification and Accreditation Checklist; NIST SP 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems; and NIST SP 800-53, Recommended Security Controls for Federal Information Systems. An authorized senior management official shall sign the draft IT-SC&A and provide it to the Contracting Officer for review, comment, and acceptance.
(i) After resolution of any comments provided by the Government on the draft IT-SC&A, the Contracting Officer shall accept the IT-SC&A and incorporate the Contractor’s final version into the contract as a compliance requirement.
(ii) The Contractor shall also perform an annual security control assessment and provide to the Contracting Officer verification that the IT-SC&A remains valid. Evidence of a valid system accreditation includes written results of (A) annual testing of the system contingency plan and (B) the performance of security control testing and evaluation.
(d) Personal identity verification. The Contractor shall identify its employees with access to systems operated by the Contractor for HHS or connected to HHS systems and networks. The Contracting Officer’s Technical Representative (COTR) shall identify, for those identified employees, position sensitivity levels that are commensurate with the responsibilities and risks associated with their assigned positions. The Contractor shall comply with the HSPD-12 requirements contained in “HHS-Controlled Facilities and Information Systems Security” requirements specified in the SOW/PWS of this contract.
(e) Contractor and subcontractor employee…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .