MSD_DRAFT PEFRORMANCE WORK STATEMENT (PWS) MSD MAIDIQ_12 DECEMBER 2024.pdf

PDF 932 KB Posted

Attached to
Request for Information: New Modern Software Delivery Multiple Award IDIQ Federal contract opportunity
Solicitation number
2024DCCOE005
Issued by
Department of the Army Materiel Command Army Contracting Command Aberdeen Proving Ground

About this file

This is a Performance Work Statement (PWS) for the Modern Software Delivery (MSD) Multiple Award Indefinite Delivery Indefinite Quantity (MAIDIQ) contract vehicle, with contract number W9128Z-25-R-XXXX dated December 2024. The PWS outlines requirements for contractors to provide the U.S. Army with rapid software design, development, testing, deployment, and maintenance capabilities for mission-critical applications and systems.

The key objectives include delivering software through multiple pathways (IaaS, PaaS, SaaS, and Managed Services), implementing DevSecOps practices, utilizing human-centered design, leveraging MOSA and UDRA best practices, and conducting rigorous testing and validation. The scope encompasses software development and security operations, modern architectures and platforms, and digital transformations. Contractors must provide configuration and integration of existing software solutions, low-code software development, and custom software development. The PWS includes detailed security requirements, including potential TOP SECRET clearance requirements, and emphasizes contractor responsibilities for personnel management, training, safety protocols, and protection of government information. The document establishes reporting requirements and outlines roles such as Contractor Contract Manager (CCM) and Contractor MSD Board Member for program oversight.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information: New Modern Software Delivery Multiple Award IDIQ, newest first.
File Type Posted
Unplugged-QA_20 December 2024.pdf PDF
RFP 3_Comment Matrix_MSD IDIQ_16 DEC 2024 (1).xlsx XLSX spreadsheet
MSD IDIQ DRAFT RFP_13 DECEMBER 2024.pdf PDF
MSD_DRAFT IDIQ DRAFT RFP_12 DECEMBER 2024.pdf PDF
Attachment 0003_MSD IDIQ Labor Hour Model Worksheet.xlsx XLSX spreadsheet
MSD_DRAFT ORDERING GUIDE_12 DECEMBER 2024.pdf PDF
Attachment 0003_MSD IDIQ Labor Hour Model Worksheet.xlsx XLSX spreadsheet
Comment Matrix_MSD IDIQ_11 OCT 2024.xlsx XLSX spreadsheet
MSD IDIQ DRAFT RFP_11 OCT 2024_CLEAN.pdf PDF
DRAFT Attachment 0001 - Draft PWS_MSD MAIDIQ_11 Oct 24.pdf PDF
DRAFT PWS_MSD IDIQ 16 August.pdf PDF
DRAFT RFP_MSD IDIQ_16 August.pdf PDF
Comment Matrix_MSD IDIQ_16 August.xlsx XLSX spreadsheet
DRAFT LCATS_MSD IDIQ_16 August.pdf PDF
Digital APBI for 10 JUL FINAL FOR RELEASE_v1.pdf PDF
Attachment 2-MSD MA IDIQ Follow Up _RFI Repsonses.xlsx XLSX spreadsheet
Attachment 1-MSD MA IDIQ RFI Repsonses.xlsx XLSX spreadsheet
Modern Software Development- Request for Information.pdf PDF
Attachment 1-MSD MA IDIQ RFI Repsonses.xlsx XLSX spreadsheet
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PEFRORMANCE WORK STATEMENT (PWS)

FOR

MODERN SOFTWARE DELIVERY (MSD)

MULTIPLE AWARD INDEFINITE DELIVERY INDEFINITE QUANTITY (MAIDIQ) CONTRACT

VEHICLE

CONTRACT NUMBER: W9128Z-25-R-XXXX

DECEMBER 2024

1.0 Introduction.

The U.S. Program Executive Office Enterprise’s (PEO Enterprise) mission with support of the Deputy Assistant Secretary of the Army (Data, Engineering, and Software) (DASA (DES)), a subordinate of the Assistant Secretary of the Army (Acquisition, Logistics, and Technology) (ASA(ALT)), and Digital Capability Contracting Center of Excellence (DC3oE), a subordinate of the Army Contracting Command (ACC) is to provide quality, cost effective software capabilities to the Army to meet DoD and Army goals and objectives.

1.1 Mission.

The MSD MAIDIQ is designed to provide the U.S. Army with the ability to rapidly design, develop, test, deploy, and maintain mission critical applications and systems. It aligns with Army Directive (AD) 2024- 02 for Enabling Modern Software for Defense and Acquisition Practices and DoD Modern Software Strategy Memorandum, 2 February 2022. The MSD MAIDIQ enables the Government to build functionality, implement, and extend the capabilities of U.S. Army and to modernize the Army through rapid development and delivery of software capability. This vehicle will have in place mechanisms to sense, respond, and adjust deliveries to increase effectiveness and efficiency throughout the software lifecycle.

The MSD MAIDIQ will follow the guiding principles below:

Driving Effectiveness Outcomes

• Ensure dynamic, agile alignment to Army mission through integrated government technical leadership, utility of the right people and the right tools, and contractual support flexibility.

• Feedback pathways for all stakeholders throughout the delivery lifecycle.

• Metrics-driven focus on value generation through outcomes. Effectiveness over efficiency.

• Clear and transparent communication across mixed roles and delivery teams.

Driving Efficiency Outcomes

• Analysis and reduction of the complexity of and the time spent in all non-capability-developing activities.

• Prioritization of orders focused on agile, pivotal development while restricting superfluous long-term planning and/or sustainment activities.

• Build trusted relationships utilizing the MSD Board to provide feedback and employ efficiency improvements where and when needed.

1.2 Scope

This MAIDIQ is designed to provide a vehicle to award task orders in an efficient manner to support software capability efforts that incorporate but are not limited to the following:

DRAFT

• Software development, security, and operations (DevSecOps, DSO)

• Software delivery using modern architectures, infrastructure, and platforms

• Support digital transformations that apply modern technologies

2. PERFORMANCE SCOPE, REQUIREMENTS, AND OBJECTIVES

The Modern Software Delivery provides a procurement vehicle to continuously modernize the Army through development and delivery of software capability with a contractual commitment to deliver working software code. This vehicle focuses on agile software contracting, programs, and product portfolios use of modern principles Additionally, the directive highlights the importance and relevance to maintain functional and operational advancements of technology across all functional areas or emerging technologies, methodologies, and areas.

2.1 Agile Software Objectives

The delivery of software can take multiple paths, individually delivering one or delivering a mixed architecture of IaaS, PaaS, SaaS, and Managed Services. Activities involved in adapting a software solution include but are not limited to:

a. Use of DevSecOps best practices including Agile Program Management, Repo & Artifact Stores, Automated Security, Automated Testing, CI/CD Orchestration, and Active Monitoring.

b. Continuous software lifecycle evaluation against new requirements, user needs, and/or operational challenges including management of technical debt through agile risk management and developing courses of action to remedy that technical debt.

c. Collaboration with mission partners and original manufactures of existing software, if required, to prioritize and address needs, expectations, and requirements.

d. Use of digital engineering practices including, but not limited to, Model-Based System Engineering (MBSE), model-driven lifecycle management, model-based communication and collaboration, and Lifecycle Product Data Management (LPDM).

e. Use of Human-Centered Design (HCD) including, but not limited to, User Interface Design, Functionality, Information Architecture, Usability, and Content Strategy.

f. Leverage MOSA and UDRA best practices by using extensible APIs and microservices to support seamless interoperability and severability.

g. Conduct rigorous testing and validation to support integration, orchestration, and configuration approaches to meet specified outcomes including all functional, performance, and security requirements.

2.1.1 Configuration and Integration of Software

Contractor shall provide configuration and development against existing Software as a Service (SaaS) or Platform as a Service (PaaS) products and environments to accelerate speed to delivery with a focus on minimizing customizations and using vendor intended configuration practices to reduce technical debt. In limited occurrences, the Government may require Infrastructure as a Service (IaaS) configuration and support requirements. For all hosting pathways, the vendor shall leverage modern practices such as CI/CD, containerization, and Infrastructure as Code (IaC) to automate IaaS deployment and maintenance.

This includes the delivery of Enterprise Resource Planning (ERP), Customer Relationship Management (CRM), Low Code platforms and configurations of Commercial-off-the Shelf (COTS) / Government-off-the-Shelf (GOTS) products and any interstitial or supportive functions of those capabilities.

2.1.2 Low Code Software Solution

The contractor shall provide the ability to adapt or integrate an existing capability to collaboratively develop and meet operational requirements. The contractor shall ensure software remains functional, relevant, and aligned with objectives, goals, and requirements, which may include adapting/integrating, modifying and/or evolving on top of existing software/solution to meet operational requirements, incorporate feedback, integrate with emerging technologies or comply with regulations, standards, and laws. Requirements for adapting software, whether the environment is government or commercial, shall include but not limited to the integration of SaaS, and adapting or integrating developed code/software to meet requirements.

2.1.3 Custom Software Development

Contractors shall provide custom software development that supports the creation and delivery of software that meet Army requirements and are tailored to meet unique expectations, needs, objectives, innovations and operational challenges utilizing the writing of new code. Custom software development may utilize and integrate open-source software. Custom software development activities encapsulate all aspects of DevSecOps and emphasize adaptability, interoperability, scalability, usability and alignment.

2.2 Modern Software Focus Areas

2.2.1 Modern Software Hosting & Operations

Contractors shall focus on integrating software security, modernizing, and automating Software hosting and operations, as applicable to the order level. Use of automation, templating, model development, and containerization as elements of Infrastructure-as-Code (IaC) should be used where applicable. These components ensure robust security, streamline IT infrastructure, automate processes, and optimize DevSecOps lifecycle. Contractors shall provide modern, agile, modular, and secure IT environment(s).

2.2.2 Software Security

Contractors shall implement software security that ensures solutions are designed, developed, deployed, and maintained with robust safeguards to protect against vulnerabilities, unauthorized access and potential threats, risks, and failures. Contractors shall deploy security processes and practices that protect against attacks, as well as comply with Army Cybersecurity standards, policy, regulation and law. Contractors shall implement modern security best practices to include but not limited to:

a. Implement security principles into system architecture(s), such as but not limited to zero-trust design, data encryption, and access controls to ensure compliance with data governance frameworks and privacy laws.

b. Apply secure coding standards and perform automated code scanning for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis.

c. Monitor and manage systems for potential security breaches utilizing real-time analytics and alerts for incident detection and response.

d. Application of the Risk Management Framework and ability to obtain and maintain cATO

2.2.3 Data Mesh Principles

Data from software solutions developed under the MSD contract shall implement the relevant concepts found in the UDRA for the adherence to data mesh principles and apply any future data architectures to achieve the Army’s centricity objectives. When a commercial offering is used vendors shall verify that the data is accessible via open APIs using industry standard protocols and technologies.

2.2.4 Agile Program Management

Agile Program Management activities will span across the base MAIDIQ scope. This includes the management and oversight of all activities performed and delivered by Contractor personnel, including subcontractors, to satisfy the requirements of the order level contract. The Agile Program Management objective is to define, manage, and execute processes and planned activities within cost, schedule, and performance parameters, as defined at the order level.

The Contractor shall adhere to the Agile manifesto and agile principles in support of requirements at the order level to deliver software capability.

3.0 IDIQ Contractor Representation and Reporting Requirements.

Each IDIQ Contract Holder shall identify a representative to serve in the following roles at that IDIQ level. The Government will not separately pay for these positions. No costs for base contract holder representatives shall be billed to the Modern Software Delivery Program Office. Representatives at the IDIQ Contract level will serve as the primary points of communication throughout the ordering period.

Contract Holders may appoint representatives as they see appropriate provided that the individual(s) filling those positions are empowered to speak on behalf of the company. The following positions are identified as representatives at the Base Contract level.

1. Contractor Contract Manager (CCM): Contractor Representative responsible for negotiating contractual matters on behalf of the MSD Contract Holder.

2. Contractor MSD Board Member: Member of the MSD Board of Directors. Responsible for carrying out the duties described at Clause H.7, MSD Board of Directors. MSD MAIDIQ Contract Holders may assign a lead and alternate for the MSD Director position. Responsible for carrying out the following duties:

• Contributes to potential market research activities.

• Discuss potential or future information technology compliance with legislation and regulations

• Discuss software and technology trends and advancements that represent potential cutting and/or business edge gains.

• Contributing member of the IDIQ level MSD Board of Directors collaborative environment.

The Contractor shall ensure that the MAIDIQ PCO has current point-of-contact information for the base contract holder Representative positions. In the event of a change to Contractor representatives, the Contractor shall notify the MAIDIQ PCO and provide all Point of Contact information for the new representative(s) within five (5) calendar days of the change. Failure of Contractor representative(s) to effectively and efficiently perform their duties may be construed as conduct detrimental to contract performance and may result in Off-Ramping (See Section H.7).

3.1 Contract Reports and Deliverables.

All required contractor reports and deliverables shall be defined at the Order level and located in the

QASP.

3.2 Software Metrics

Mission Partners and Government Software teams will regularly review metrics as part of their retrospectives and leverage metrics for continuous improvement, as well as to measure order performance/delivery. The individual order QASP will define the metrics required by each Contractor awardee and include required metrics across all MSD Base Contract Holder. The Government will aggregate a compilation of each individual MSD Contract Holder’s order level metrics to monitor a contractor’s overarching performance via a Software Metric dashboard

3.3 Contractor Manpower Reporting.

If required at the Order level, the contractor shall comply with the Service Contract Reporting Requirements in accordance with FAR 52.204-14. The information required shall be submitted via the internet at www.sam.gov.

4.0 General Requirements

4.1 Task Order Contract Type Flexibility

Orders under this resulting MAIDIQ may include one (1) or hybrid contract types. The contract type(s) determination will be made at the order level.

4.2 Non-Personal Services.

This contract is not a personal services contract in accordance with FAR 37.104. The Government shall neither supervise contractor employees nor control the method by which the contractor performs the required tasks IAW FAR 37.104. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services or give the perception of personal services. If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor’s responsibility to notify the IDIQ Base and Order level Contracting Officer(s) and/or the IDIQ Base and Order level Government Contracting Officer’s Representative (COR) immediately.

4.3 Business Relations.

The contractor shall successfully integrate and coordinate all activity needed to execute the requirement.

The contractor shall manage the timeliness, completeness, and quality of delivery/code. The contractor shall provide corrective action plans, proposal submittals and timely identification of issues. The contractor is expected to establish a history of reasonable and cooperative behavior, effectively manage subcontractors, and award timely subcontracts. The contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.

4.3.1 Order Level Contract Management.

The contractor shall establish clear organizational lines of authority and responsibility to ensure effective management and delivery of requirements at the Order award level.

4.3.2 Order Level Contract Administration.

The contractor shall establish processes and assign appropriate resources to effectively and efficiently deliver the requirement. The contractor shall respond to Government requests for contractual actions within the specified timeline. The contractor shall use the Government Order COR as their single POC between the Government and contractor personnel assigned to Orders awards. The Government Order COR and the corresponding contractor Order POC will meet as necessary to determine and refine technical requirements, products, and timelines.

4.3.3 Personnel Administration.

The contractor shall ensure all training requirements are up to date for all contracted employees during the lifetime of awarded Orders, as applicable and defined within the Order RFP. The contractor shall make necessary travel arrangements for their employees. The contractor shall provide necessary infrastructure to support awarded Order contract(s) when contractors are offsite, as determined within the Order level DD254. The contractor shall provide administrative support to employees in a timely fashion (time keeping, leave processing, pay, emergency needs). In accordance with Federal Acquisition Regulation (FAR) 7.108, the Government does not discourage the Contractor from allowing its employees to telecommute/remote work/telework as determined relevant and applicable within the RFP Order.

http://www.sam.gov/

4.3.3.1 Conduct of Personnel.

Employees of resulting awarded Orders shall comply with standards of conduct IAW FAR 52.203-13 – “Contractor Code of Business Ethics and Conduct”. All contractor personnel shall comply with RFP Order level specified Acceptable Use Policy (AUP) for persons who use computers, if applicable. The contractor shall enforce standards of employee conduct and take disciplinary action, as necessary.

Employees shall not participate in disruptive activities or interfere with Government operations.

4.3.3.2 Removal of Personnel.

The Government may request the removal of any contractor employee for reasons of misconduct, safety, environmental, security, or any other reason if in the best interest of the Government. The Government may request the removal of any contractor employee found to be, or suspected of being, under the influence of alcohol, drugs, or incapacitating agent. The Government may request the contractor to test employees suspected of being under the influence of alcohol, drugs, or incapacitating agent. The removal of a contractor employee from the job site shall not alleviate the contractor of the requirement to provide sufficient personnel to deliver Order level requirements. Replacement of personnel removed under this paragraph shall be provided within ten (10) days of the date of Government’s request for removal.

4.3.3.3 Workspace.

Contractor workspace (office, laboratory, and desk) shall contain a sign signifying the space is occupied by contractor employee(s) to ensure that Federal employees and the public know that they are not Federal employee(s). On-site is defined as Government facilities and Off-site is defined as contractor facilities.

4.3.3.4 Identification of Contractor Personnel.

Contractor personnel shall be required to wear the Government issued contractor identification that distinguishes contract personnel from Government employees. Contractor employees shall identify themselves by name and company affiliation when answering the telephone, presenting briefings, conducting or attending meetings/seminars or any other situations where their contractor status is not obvious.

4.4 Subcontract Management.

The contractor shall be responsible for any subcontract management necessary to deliver order level requirements and shall be responsible and accountable for subcontractor performance. The prime contractor will manage order level work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations. Contractors may add subcontractors to their team after notification and approval from the Order level COR and OCO, and IAW FAR 44.2. Cross teaming arrangements shall be in accordance with (IAW) FAR 9.6.

4.5 Contractor Personnel, Disciplines, and Specialties.

The contractor shall deliver order level requirements based on utilizing qualified personnel with appropriate combinations of education, training, qualifications, certifications and/or experience based on the Order level scope. The contractor shall match personnel skills to the order level scope with a minimum of under/over employment of resources. An RFP Order may define requirements that express a need for labor categories, labor rates, and labor hours to support the successful delivery of Order requirements issued at the order level and shall be the minimum necessary to successfully deliver an end product.

4.5.1 Training.

As required at the Order level, the contractor shall ensure contractor personnel are trained to accomplish the requirements of order level PWS, SOW or SOO. The contractor shall maintain records of all scheduled and completed training, which will be available for periodic inspections by the Government. In addition, copies of training certificates shall be available upon request by the COR as proof of training completion, as required. A lack of required training does not relieve the contractor from ensuring that contractor personnel are otherwise qualified to perform their assigned tasks when they begin employment under Order level contract(s).

The contractor is encouraged to seek opportunities to identify efficiencies in training that will reduce costs to the Government as well as minimize duty hours spent completing training.

The contractor shall pay for training, licensing and certifications, except mandatory training that is provided by the Government. Labor and all associated costs for certificates, training, licenses, meetings and professional development not provided by the Government shall be borne by the contractor.

All travel, training and per diem requirements that are to be reimbursed to the contractor must be approved by the COR within ten (10) workdays prior to commencement of training/travel. Any retraining needed due to contract employee departure will be at the contractor's expense.

4.6 Location and Hours of Work

All locations and hours of work will be determined and provided under each individual Order, as necessary. When work is accomplished at contractor facilities, safeguarding of classified information and security requirements IAW the DoD Contract Security Classification Specification DD Form 254 will be provided at the Order level. Daily commuting time and expenses between the Government site and some other location, such as a home office, shall not be allowable under this contract or any Orders.

4.7 Installation Closures

The contractor may be required to adhere to curtailing operations of the Government which includes any time when the Government is in a non-operational status for events including but not limited to federal holidays, emergency situations, inclement weather, power curtailments, furlough, shutdowns, organization events, executive ordered closures, planned training days, etc. Contractors are expected to adhere to the Government curtailment or closure schedule; however, some contractor employees may be required to work during those periods and/or may be required to report to an alternate work site. The Order COR and/or OCO will notify the contractor of the dates of curtailment and closure. The Contractor shall not invoice for costs in the event of closure or curtailment.

4.8 Federal Holidays

Based on situational awareness and planning purposes, Federal Holidays are identified by the Office of Personnel Management (opm.gov).

4.9 Travel/Temporary Duty (TDY).

All travel requirements (including plans, agenda, itinerary, anticipated costs, trip reasons and dates) shall be pre-approved by the COR (subject to local policy procedures) and is on a strictly cost reimbursable basis (no fee). Costs for travel shall be billed IAW the regulatory implementation of Public Law 99-234 and FAR 31.205-46 Travel Costs (subject to local policy & procedures) and expenses shall be at rates no higher than the substantive provisions of the Joint Travel Regulation (JTR). Contractor travel costs to their normal duty location, whether at the contractor's facility or at the Government’s facilities, will not be authorized and are unallowable. No travel costs shall be invoiced under the Contractor’s base IDIQ contract.

Travel may include multiple locations throughout the CONUS and Outside CONUS (OCONUS).

IAW FAR 31.205-46, invoices for travel shall include documentation for prime and subcontractor costs incurred by contractor personnel on official company business. These costs are subject to the limitations contained in the FAR 31.205-46 subsections. Travel documentation will be included as an attachment to the invoice in Wide Area Work Flow (WAWF). This requirement includes the prime contractor and all subcontractors.

4.10 Conflicts of Interest.

This MAIDIQ contract may include Orders where potential Organizational Conflicts of Interest (OCI) exist as contemplated by FAR subpart 9.5. It is the intention of the parties that the contractor shall not engage in any activity that creates a conflict of interest with the contractors position under this contract, impairs the contractors ability to render unbiased advice and recommendations, or places the contractor in the position of having an unfair competitive advantage as a result of the knowledge, information, and experience gained during the performance of this contract.

Both the Prime Contractor and its Subcontractors have a continuous duty to avoid creating an OCI situation. If a Contractor discovers a potential OCI issue, then they shall report the OCI issue to the Contracting Officer within three (3) working days.

5.0 Special Requirements.

This section describes the special requirements for this effort. The following sub-sections provide details of various considerations on this effort.

5.1 Smoking policy.

The contractor shall comply with AR 600-63 and appropriate DoD policies that establishes policies governing smoking in Government facilities and ranges.

5.2 Government inspections, audits, surveys, and requests for information and technical advice.

IAW FAR 52.246-5, the contractor shall provide and maintain an inspection system acceptable to the Government covering the services under this contract. Complete records of all inspection work performed by the contractor shall be maintained and made available to the Government during contract performance and for as long afterwards as the contract requires. The Government has the right to inspect and test all services called for by the contract, to the extent practicable at all places and times during the term of the contract. The Government shall perform inspections and tests in a manner that will not unduly delay the work. If any of the services performed do not conform with contract requirements, the Government may require the contractor to perform the services again in conformity with contract requirements, for no additional fee. When the defects in services cannot be corrected by re-performance, the Government may (1) require the contractor to take necessary action to ensure that future performance conforms to contract requirements; and (2) reduce any fee payable under the contract to reflect the reduced value of the services performed. If the contractor fails to promptly perform the services again or take the action necessary to ensure future performance in conformity with contract requirements, the Government may (1) by contract or otherwise, perform the services and reduce any fee payable by an amount that is equitable under the circumstances; or (2) terminate the contract for default. “Services,” as used in this clause, includes services performed, workmanship, and material furnished or used in performing services.

5.4 The base contract holders shall respond to all requests for information, to include negative responses, and administrative/technical evolutions regarding the functionality of this MAIDIQ contract. Responses shall be either verbal or written, as specified by the requester. Types of action shall include:

a. Respond to issued Order RFI’s and Order RFP’s;

b. Provide written comments based on review of draft documents;

c. Provide information requested by customers, investigators, inspectors, auditors and members of special teams (both internal and external), and responding to findings of such inquiries;

d. Prepare, execute and deliver requirements IAW Government instructions and directives by the defined due dates;

e. Attend onsite and offsite meetings as required by the Government.

5.6 Defense Department (DD) Form 254.

Overarching security requirements and contractor access to classified information shall be as specified in the base DD Form 254, which will be further identified in the DD Form 254 for each Order, as required.

5.7 Security.

The contractor shall ensure all personnel have an appropriate security clearance at the commencement of an Order. Personnel may require a TOP SECRET level security clearance and be eligible for access to SCI as specified in the individual Orders. Contract Security Classification Specifications are covered in associated DD Form 254. Contractor personnel may require access to some or all of the following categories of classified information: Restricted Data, Formerly Restricted Data, Critical Nuclear Weapon Design Information (CNWDI), Collateral or Sensitive Compartmented Information (SCI) intelligence information, Special Access Program (SAP) information, North Atlantic Treaty Organization (NATO) information, and Controlled Unclassified Information (CUI). Furthermore, contractor personnel may require access to one or more of the Secure Internet Protocol Network (SIPRNET), the Joint Worldwide Intelligence Communication System (JWICS) and special-use PM-provided networks. Work under this contract may require eligibility and access for Communications Security (COMSEC) information and/or a COMSEC account. Contractor personnel may be authorized use of the Defense Courier Service.

Contractor personnel may also be required to courier classified information in accordance with applicable security regulations and guidelines.

5.8 Public Release.

No data, reports, or documents shall be released to other organizations unless authorized in writing by the Contracting Officer, assigned COR through the designated Order Requiring Activity/Customer and applicable public releases offices/procedures. Non-Army programs will be coordinated through proponent’s designated public release procedures. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination. Proposed public releases shall be submitted for approval prior to release.

5.9 Classified/Unclassified Information.

For most activities, controlled unclassified information (CUI) computers shall be used. For selected activities, as denoted in the Order, classified level computers shall be used. Classified data shall only be processed on specifically approved and marked terminals and workstations for the appropriate security level(s). Technical CUI is export controlled and must be marked with the export control warning statement cited in DODD 5230.24 (see AR 380-5).

5.10 Foreign Personnel.

IAW restrictions required by Executive Order 12470, the Arms Export Control Act (Title 22 USC Sec 275), the International Traffic in Arms Regulation (ITAR), or DODD 5230.25, Withholding of Unclassified Technical Data from Public Disclosure, no foreign persons will be permitted to work under this contract or any resulting Order.

5.12 Protection Program Training.

Government provided and required security training includes initial and annual IA, Antiterrorism (AT), OPSEC, Threat Awareness and Reporting Program (TARP) training, Annual Security Awareness Training or training required by DoD operated facilities, and other command mandated training. As determined as the Order level, the appropriate training will be established by the Government and the resulting method of training reporting will be identified to the contractor through the COR prior to the start of training.

5.13 AT Level l Training.

All contractor employees, to include subcontractor employees, requiring access to Army installations, facilities and controlled access areas shall complete AT Level l awareness training within 30 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee to the COR or to the ordering contracting officer, if a COR is not assigned, within 05 calendar days after completion of training by all employees and subcontractor personnel. AT Level l awareness training is available at the following website:

http://jko.jten.mil.

5.14 AT Awareness Training for Contractor Personnel Traveling Overseas.

Additional AT Awareness Training may be required for contractor and subcontractor employees traveling overseas to perform the requirements of this contract, as directed by AR 525-13. Specific AOR training content may be directed by the combatant commander with the unit Anti-Terrorism Office (ATO) being the local POC. The Government will provide supplemental guidance if necessary.

5.15 Access and General Protection/Security Policy and Procedures.

Contractor and all associated subcontractor employees shall provide all information required for background checks to meet installation access requirements to be accomplished by the installation Provost Marshal Office, Director of Emergency Services, or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DoD, HQDA, and/or local policy. Should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.

5.16 Contractors Requiring Common Access Card (CAC).

Before CAC issuance, the contractor employee requires, at a minimum, a favorable adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation IAW Army Directive 2014-

05. The contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks onsite or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical acce s s to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.

Contractors that do not require CAC, but require access to DoD facility or installation: Contractor and all associated subcontractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by Government representative), or, at OCONUS locations, IAW status of forces agreements and other threat regulations.

5.17 iWATCH Training.

The contractor and all associated subcontractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity ATO). This locally developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 calendar days of contract award and within 5 calendar days of new employees commencing performance with the results reported to the CO NLT 30 calendar days after contract award.

http://jko.jten.mil/

5.18 Access to Government Information Systems.

All contractor employees supporting Army systems with access to a Government information system must be registered in the Army Training Certification Tracking System (ATCTS) at commencement of services, and must successfully complete the DoD Cybersecurity Awareness prior to access to the information systems and then annually thereafter. Contractors supporting non-Army systems will comply with proponent’s policies for accessing government information systems.

5.19 OPSEC Standing Operating Procedure (SOP)/Plan.

As determined at the Order level, the contractor shall develop an OPSEC SOP/Plan within 90 calendar days of contract award, to be reviewed and approved by the responsible Government OPSEC officer, per AR 530-1, Operations Security. This plan will include the Government's critical information, where it is located, who is responsible for it, how to protect it and why it needs to be protected. The contractor shall implement OPSEC measures as ordered by the commander. In addition, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1.

5.20 Requirement for OPSEC Training.

Per AR 530-1, Operations Security, the contractor employees must complete Level 1 OPSEC Awareness training. New employees must be trained within 30 calendar days of their reporting for duty and annually thereafter. OPSEC Awareness for Military Members, DoD Employees and Contractors is available at the following website: http://cdsetrain.dtic.mil/opsec/index.htm.

5.21 Cybersecurity/IT Training.

All contractor employees and associated subcontractor employees must complete the DoD Cybersecurity awareness training before issuance of network access and annually thereafter. All contractor employees working cybersecurity/IT functions must comply with DoD and Army training requirements in DODD 8140.01, DODD 8570.01-M, and AR 25-2 within six months of appointment to cybersecurity/IT functions.

5.22 Cybersecurity/IT Certification.

Per DODD 8570.01-M, DFARS 252.239.7001, and AR 25-2, the contractor employees’ cybersecurity/IT functions shall be appropriately certified upon contract award. The baseline certification as stipulated in DODD 8570.01-M must be completed upon contract award.

5.23 Contract Requiring Performance or Delivery in a Foreign Country.

DFARS Clause 252.225-7043, Antiterrorism/Force Protection for Defense Contractors Outside the US.

The clause shall be used in solicitations and contracts that require performance or delivery in a foreign country and will be determined applicable at the Order level. This clause applies to both contingencies and non-contingency support. The key AT requirement is for non-local contractor personnel to comply with theater clearance requirements and allows the combatant commander to exercise oversight to ensure the contractor’s compliance with combatant commander and subordinate task force commander policies and directives.

5.24 Handling or Access to Classified Information.

Contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to Information classified “CONFIDENTIAL,” “SECRET” or “TOP SECRET” and requires contractors to comply with: (1) the Security Agreement (DD Form 441), including the NISPOM (DoD 5220.22-M); (2) any revisions to DoD 5220.22-M, notice of which has been furnished to the contractor. The Government will provide supplemental guidance.

5.25 Threat Awareness and Reporting Program (TARP).

http://cdsetrain.dtic.mil/opsec/index.htm

For all contractors with security clearances. Per AR 381-12 Threat Awareness and Reporting Program (TARP), contractor employees must receive annual TARP training by a CI agent or other trainer as specified in 2-4b of AR 381-12.

5.26 For contractors authorized to accompany the force.

DFARS Clause 252.225-7040, Contractor Personnel Authorized to Accompany U.S. Armed Forces Deployed Outside the United States. The clause shall be used in solicitations and contracts that authorize contractor personnel to accompany US Armed Forces deployed outside the US in contingency operations;

humanitarian or peacekeeping operations; or other military operations or exercises, when designated by the combatant commander. The clause discusses the following AT/OPSEC related topics: required compliance with laws and regulations, pre-deployment requirements, required training (per combatant command guidance), and personnel data required.

5.26 Personnel Security.

Contractor and associated subcontractor employees shall comply with AR 380-67. Foreign travel and contact will be reported. The Government will provide supplemental guidance.

5.27 Reports of Adverse Information.

The contractor shall report to the COR all adverse information on contractor personnel such as security violations, arrests, bankruptcy, and denial, suspension or revocation of security clearances. Employees may be denied access into restricted areas by the ordering Government customer Security Manager based upon the adverse information.

5.28 Handling or Access to CUI or technical CUI.

The contractor shall not disclose or release the content of any Government software, procedures or information provided to the contractor to other than Government authorized persons or activities.

5.29 Privacy Act.

All information obtained, generated, or maintained by the contractor or their subcontractors under this contract will be the property of the U.S. Government and subject to the requirements of the Privacy Act of 1974 as amended and all local, site, DISA, and DoD security regulations.

5.30 Special Access Programs (SAP).

For Orders supporting SAP, the contractor shall ensure that investigative requirements for personnel supporting SAPs are submitted IAW paragraph 5-4, AR 380-381, Special Access Programs. Personnel supporting SAPs shall be subject to random counterintelligence polygraph examinations. Employees who refuse to sign an agreement to undergo a polygraph examination cannot access SAP information.

5.31 Personnel Attestations.

Contractor personnel granted a TOP SECRET clearance or access to SAP information shall make a verbal attestation and execute an Attestation Statement IAW Memorandums from the Secretary of Defense dated February 5, 1999 and the Office of the Assistant Secretary of Defense dated February 9, 1999. Order level Government customer Security personnel will witness the execution of the oral and written attestations and maintain the Attestation Statements for contractor personnel.

5.32 Travel.

As determined at the order level, Contractor personnel may be required to travel to various locations within the CONUS and OCONUS. All contractor personnel traveling OCONUS must possess a valid tourist Passport.

5.33 Relocation.

No relocation costs will be paid by this contract.

5.34 Unescorted access into Restricted Areas.

Unescorted access into restricted areas will be granted to contractor personnel who possess a security clearance or were the subject of a favorably completed National Agency Check (NAC) or a National Agency Check with Local Agency Check and Credit Check (NACLC). Also, unescorted access will be authorized provided a final SECRET clearance has been granted with no more than 24 months of a break in service since the date of the termination of their security clearance and there is no known adverse information. Contractors supporting non-APG contracts will comply with local policies and be addressed in the order.

5.36 Safeguarding Government Information and Property.

The contractor shall be responsible for safeguarding all Government information and property provided for contractor use. The contractor shall safeguard information and material designated as classified, unclassified sensitive, FOUO, OPSEC sensitive, Personally Identifiable information (PII) and Privacy Act Information IAW applicable directives.

5.37 Loss or Possible Compromise of Classified Information.

The contractor shall immediately report the loss or possible compromise of classified information or material to the OCO, COR and the respective Requiring Activity Security Manager.

5.38 Physical Security.

The contractor shall have access as needed to all Government-furnished facilities IAW AR 190-51. The contractor shall develop and implement procedures to ensure that any combinations and/or key locks, metal and electronic keys received from the Government are accountable, controlled, and safeguarded IAW above regulations. Contractors supporting off-site locations shall comply with local policies and be addressed in the Order.

5.39 Visitor Group Security Agreement.

The contractor shall sign a contractor Visitor Group Security Agreement to protect classified information involved in performance under this contract or Orders. The Agreement will outline responsibilities in the following areas: Contractor security supervision; Standard Practice Procedures; access, accountability, storage, and transmission of classified material; marking requirements; security education; personnel security clearances; reports; security checks; security guidance; emergency protection; protection of Government resources; DD Forms 254; periodic security reviews; and other responsibilities, as required.

5.40 Departing Employees.

The contractor, in coordination with the Order COR, shall ensure all contractor employees return photographic security identification badges and CACs/Identification Cards and all permits issued by the Government at the completion of their employment. The return of these items will be completed no later than 24 hours before their departure. In addition to any Order COR contractor departing procedures, the contractor will develop and implement an employment/installation clearance procedure and checklist to ensure that an employee has turned in all badges, Government property, and keys before leaving employment on the installation and access to the Local Area Network (LAN)/email has been cancelled.

This checklist will contain a signature block for the Order Security Office to initial to ensure all contract employees have cleared all aspects of. Security badges will be returned to the respective requiring activity security office to initial to ensure all contract employees have cleared all aspects of employment.

Security badges will be returned to the security office on the employee’s last day of employment with the Government. If departure is after normal business hours, the Order COR will collect the badge on the last day of employment and turn the badge in to security office the next business day. Keys will be returned to the issuing key custodian prior to the employee departing. In addition, contractor personnel briefed on

SCI and SAPs shall contact the requiring activity security office to complete a termination briefing prior to termination of employment. The contractor shall ensure that their departing employee has turned over all files (digitally or paper), records, hand-outs, pictures, drawings, charts, diagrams, notes, briefings, slides or any other related information or material prior to their departure to the Order COR.

5.41 Safety.

Contractor and associated subcontractors shall provide a safe and healthful work environment for their employees as prescribed in FAR 52.236-13, 29 CFR Part 1910, pertinent provisions of AR 385-10, and local regulations, policies, and SOP. They shall safeguard public and Government personnel, property and equipment, and avoid interruption of Government operations. The contractor will report accidents or losses to the OCO as specified in relevant regulations and standards. Whenever the contractor becomes aware of serious or imminent danger to Government, civilian or contractor personnel, the contractor shall take immediate corrective action.

5.42 Government Furnished Property (GFP)/Contractor Acquired Property (CAP).

All Government furnished reference material; information, data, equipment, hardware, and software provided to the contractor for performance under an Order shall remain the property of the U.S.

Government. GFP/CAP will be provided at the Order level, if applicable. Each Order shall specify property accountability requirements to ensure property is controlled, protected, preserved, accounted for and maintained IAW FAR 45 and Army Policy. The Government may provide space onsite if possible at a Government location or off-site Government facilities for contractor personnel including use of the usual items needed to conduct work such as desk, phone, and computer, for the duration of the period of performance and as designated in Orders. However, if no space is available contractor personnel shall perform support at the contractor site. The contractor shall sign a contract modification for all equipment provided by the Government. Rejection of GFP by the contractor shall not relieve the contractor of responsibility in performance of this contract or any Order. The contractor shall not use property provided by the Government for any purpose other than the performance of this contract and/or Orders.

As soon as the GFP is no longer required it shall be promptly turned in. The Order COR will specify the method GFP will be turned in.

Management of GFP and Equipment. All GFP and Contractor Acquired Property (CAP) shall provide a master report IAW CDRLs on Orders. The contractor shall manage GFP IAW Parts 45 and 52 of the FAR and Parts 245 and 252 of the DFARS. The contractor shall be liable for shortages, loss, damages or destruction of Government property IAW the property clauses in Section I of the contract and the Financial Liability Investigation. Within 15 calendar days of discovering the item is missing, damaged or destroyed, the contractor shall appoint a POC who is responsible for initiating the Financial Liability Investigation.

5.43 For any contractor working in a Government facility, the following may be provided by the Government under Orders:

Telephone Service. The Government may provide telephone communication service exclusively for the conduct of official business. The contractor is responsible for charges for long distance telephone calls made or accepted by contractor personnel, which are not for the purpose of conducting official Government business under this contract. Telephone service will be subject to the standard monitoring requirements of the Government telephone network. Government-furnished telephones are subject to security monitoring at all times. Use of these telephones constitutes consent to security monitoring.

Network Access. The Government will provide network access for all Government issued computer systems required for the conduct of official business in the performance of…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .