3-DD254_16Jun2025Ch2.signedpdf.pdf
PDF 424 KB Posted
- Attached to
- Elevator Maintenance Services Federal contract opportunity
- Solicitation number
- SP4705-25-Q-2025
- Issued by
- Defense Logistics Agency
About this file
The DD Form 254 is a Department of Defense Contract Security Classification Specification for an elevator maintenance and services contract at the DLA Headquarters Complex. The document specifies a Secret-level facility security clearance is required, with the contract solicitation number SP4705-25-S-XXXX and a due date of August 1, 2025. The contract involves performing services within Pod 10's secured space, including cyber security-related systems such as elevator control and monitors.
Key security requirements include contractor employees potentially being in areas with visible and audible information, operations security (OPSEC) requirements, and handling of Controlled Unclassified Information (CUI). The contract will be administered by the Defense Logistics Agency (DLA) at 8725 John J. Kingman Road, Fort Belvoir, VA, with the Contracting Officer's Representative (COR) being Andrea Terrell. Public release requests must be routed through DLA Public Affairs Office via the COR, and the contract includes additional security requirements beyond standard National Industrial Security Program (NISP) guidelines.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SF30 Amendment 00002.pdf | ||
| SF30 Amendment 0001 - Site Visit Updated Information 1.pdf | ||
| DLA HQ DBIDS Pre-Enrollment MEMO.pdf | ||
| SP4705-25-Q-2025_DD254 Contract Continuation Pages JUN 2025.pdf | ||
| AD-HOC CLIN Work Procedures.pdf | ||
| Pricing Schedule.xlsx | XLSX spreadsheet | |
| Combined Synopsis-Solicitation Instructions to Quoters.pdf | ||
| DLA HQ Elevator Maintenance Services PWS.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in): CUI
PREVIOUS EDITION IS OBSOLETE. Page 1 of 3DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED
(See Instructions)
Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
None (See instructions)
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER
SP4705-25-S-XXXX
DUE DATE (YYYYMMDD)
20250801
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor) Add Row Remove Last Row Delete All Rows
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
8. ACTUAL PERFORMANCE (Click button to add more locations.) Add Row Remove Last Row Delete All Rows
a. LOCATION(S) (For actual performance, see instructions.)
Defense Logistics Agency 8725 John J. Kingman Road Fort Belvoir VA 22060-6221
b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
This contract is for Elevator Maintenance and Services at the DLA Headquarters Complex.
PREVIOUS EDITION IS OBSOLETE. Page 2 of 3DD FORM 254, APR 2018
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.) h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
Within Pod 10 secured space and systems such as Elevator Control and Monitors etc. (Cyber security).
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDI 5200.48, only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
Contractor employees may be in areas where information is visible and or audible.
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
DLA/DP
Route Public Release requests to Public Affairs Office Via COR
Public Release Authority:
DLA Public Affairs Office
13. SECURITY GUIDANCE Add Signature Remove Last Signature Delete All Signatures
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
Reference Item 6:
Reference Item 8.a.
Reference 10k.
Reference 11e.
Reference Item 11.j:
Reference Item 11.m:
Reference Item 12:
PREVIOUS EDITION IS OBSOLETE. Page 3 of 3DD FORM 254, APR 2018
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form) Show Attachment Bar
NAME & TITLE OF REVIEWING OFFICIAL
Candy Best Industrial Security Program Manager
SIGNATURE
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
See Reference Items: 10j; 11j; 11l.
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item
13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
a. GCA NAME
DLA DCSO
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)
SP4705
c. ADDRESS (Include ZIP Code) 8725 John J. Kingman Road Fort Belvoir VA 22060
d. POC NAME
Odemaris Dekle
e. POC TELEPHONE (Include Area Code)
+1 (445) 737-5019
f. EMAIL ADDRESS (See Instructions) odemaris.dekle@dla.mil
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)
Andrea Terrell
b. TITLE
Facility Systems Operations Specialist (COR)
c. ADDRESS (Include ZIP Code) 8725 John J. Kingman Road Fort Belvoir VA 22060
d. AAC OF THE CONTRACTING OFFICE (See Instructions)
SP4705
e. CAGE CODE OF THE PRIME CONTRACTOR
(See Instructions.)
f. TELEPHONE (Include Area Code)
+1 (571) 767-2724
g. EMAIL ADDRESS (See Instructions)
h. SIGNATURE
i. DATE SIGNED (See Instructions)
20250624
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
a. CONTRACTOR
b. SUBCONTRACTOR
c. COGNIZANT SECURITY OFFICE FOR PRIME AND
SUBCONTRACTOR
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY
ADMINISTRATION
e. ADMINISTRATIVE CONTRACTING OFFICER
f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
DLA Industrial Security
SECURITY GUIDANCE (BLOCK 13) CONTINUATION PAGES
FOR CONTRACT #: SP4705-25-S-XXXX
Per the DD Form 441, Department of Defense Security Agreement, Section VI, signed by the United States Government through the Defense Counterintelligence and Security Agency (DCSA) and the Contractor, the government is not obligated to provide funds and shall not be liable for any security costs or claims of the Contractor arising out of the DD Form 441 Agreement, its instructions, or the requirements identified in the 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM), and its changes/revisions.
The DD 254 will be housed within the NISP Contract Classification System (NCCS) through the life of the contract. The Contractor shall be registered within NCCS at time of award to gain access to the DD 254. It is incumbent upon the Contractor to ensure that the necessary security paperwork is submitted in sufficient time to enable each individual to be cleared prior to beginning work on this contract. In the event that the NCCS is superseded by another System of Record, the same requirements apply.
The Contractor is required to flow-down all applicable requirements of the DD Form 254 to its Subcontractor(s).
Reporting Requirements:
The Contractor shall provide the following to the DLA Major Subordinate Command (MSC) or Regional Activity (RA) Industrial Security Manager (contact information listed in block 13 of page two of the DD Form 254):
• Courtesy copy the DLA HQ Industrial Security Program Office on any security incident report (initial and final) sent to the DCSA involving the loss, compromise, or suspected compromise of classified information. The Contractor shall provide a copy to the DLA within the same reporting timeframe as is required by the DCSA.
• Courtesy copy the DLA HQ Industrial Security Program Office on any report involving a cyber-intrusion of DLA program information sent to the Federal Bureau of Investigation and the DCSA per NISPOM, 32 CFR 117.8 and Industrial Security Letter (ISL) 2021-02.
• Provide a copy of any DCSA letter that indicates a less than satisfactory security rating and/or that negatively impacts the Facility Clearance Level (FCL) of the company within 48-hours of receipt.
• Provide electronic copies of Subcontractor DD Form 254s issued by the Prime and the Subcontractor. The Prime Contractor shall act as the focal point for collecting their Subcontractor’s DD Form 254s and the Prime is responsible for forwarding these DD Form 254s to the DLA HQ Industrial Security Program Office.
• DLA HQ Industrial Security Program Office:
Defense Logistics Agency ATTN: DI / Industrial Security Program Manager 8725 John J. Kingman Road Fort Belvoir, VA 22060-6221 Phone: (571) 767-0926 Email: DLAIndustrialSecurity@dla.mil mailto:DLAIndustrialSecurity@dla.mil
Block 13 Continuation Pages for Contract #: SP4705-25-S-XXXX
Subcontractor Classified Access Approvals:
The Prime Contractor and Subcontractor are authorized to flow access to and/or dissemination of classified information to the level specified in Block 1a to their Subcontractors. Dissemination is only authorized and applicable for information safeguarded at the Contractor’s facility. The Contractor shall provide the appropriate accesses to its Subcontractors as required per NISPOM, 32 CFR 117.15. The Prime Contractor and Subcontractor must verify Facility Clearance, Safeguarding Capability and Access Authorizations prior to the dissemination of classified information. Certain accesses require GCA approval prior to subcontracting and are specified herein, if applicable.
Pre-Award Access
This section concerns the release of classified information to the contractor prior to the award of a DLA classified contract. DLA classified information may only be released to the Contractor for submission preparation purposes following verification of the Contractor’s facility clearance and safeguarding. The DD Form 254 shall act as security guidance for the safeguarding of program-related classified information at the Contractor facility. The DCSA maintains security cognizance of classified information stored at a contractor facility. However, the following stipulations apply:
• IAW 32 CFR Part 117.15(e)(6) NISPOM, Contractors shall ensure full written accounting and control over all DLA classified information provided to the Contractor by DLA or created as copies by the Contractor.
• IAW 32 CFR Part 117.15(h)(1)(2) NISPOM, distribution of DLA classified information shall only be made to those cleared Contractor personnel working on the Contractor’s response to the request for information, unless otherwise authorized by the Program Manager
(PM).
• IAW 32 CFR Part 117.15(h)(6) NISPOM, for purposes of this submission request, further distribution of DLA classified information shall only be authorized by the DLA PM overseeing this request for information.
• IAW 32 CFR Part 117.15(i)(k) NISPOM, all classified information provided for use in submission preparation shall be returned to DLA or destroyed.
Reference Item 6: Issuance of this DD Form 254 does not alone permit access to classified information by the contractor identified in Block 6. Access to classified information is contingent upon a Facility Clearance (FCL), active and in good standing, favorably adjudicated by the DCSA. A DD Form 254 issued to a contractor not in possession of a FCL may be used by the government contracting activity as justification to initiate the FCL sponsorship process. The contractor is only permitted to work on unclassified portions of the contract pending the issuance of a favorable FCL.
Reference Item 8.a. (continued) Government Locations:
Classified performance will occur at various DLA and/or government locations as directed by the contract via the Performance Work Statement, Statement of Work, or Statement of Objectives or other agreement. The Contractor shall abide by the host government security requirements per 32 CFR Part 117.24 NISPOM. The cognizant security office at the performance location is DLA or the host installation.
Reference Item 10.j: See Controlled Unclassified Information (CUI) Supplement. The Contractor is required to provide the supplement to all uncleared Subcontractors requiring access to CUI information.
Reference Item 10.k: The Contractor is required to install Elevator Control and Monitors which require installing program and software. The Contractor shall execute the installation task per the Statement of Work/Performance Work Statement/Statement of Objectives.
Reference Item 11.e: The contractor will be performing services only on this contract and will not be expected to produce deliverable items. The contractor will be required to provide services in secure Government facilities and may come into contact with Classified or Controlled Unclassified Information (CUI). Actual knowledge, generation, or production of classified information is not required for the performance of this contract. Cleared personnel are required to perform this service because access to classified information cannot be precluded by escorting personnel due to a high risk of aural or visual access to classified information. This access cannot be properly mitigated through other reasonable physical security measures.
Reference Item 11.j:
1. The Contractor is required to apply Operations Security (OPSEC) to enhance protection of classified and unclassified critical information pursuant to DoD Directive 5205.02, “DoD OPSEC Program; DoD 5205.02-M, “OPSEC Program Manual;” National Security Decision Directive Number 298, “National Operations Security Program;” DLA Instruction 3606-01, “Operations Security (OPSEC) Program,” October 3, 2018; DLA Manual 3606.01, “Operations Security (OPSEC) Program,” October 10, 2018; and supplementary instructions. Service OPSEC guidance may also apply if the contracted activity is performed in a Service-level operational environment. Contractors are required to complete OPSEC refresher training on an annual basis and provide timely and appropriate responses to Agency OPSEC Managers, when necessary. The preferred training for DLA contractors can be found online: https://icontent-hcm04.ns2.apps.mil/icontent/CUSTOM/DLAHCM04P/NoCompat/SEC-ASCA/.
2. The contractor will accomplish the following minimum requirements in support of the DLA OPSEC Program. Protect those items of critical information, applicable to operations. Items of critical information are those facts, which individually, or in the aggregate, reveal sensitive details about the mission, operation, etc., and thus require protection from adversarial collection or exploitation. A copy of the GCA’s Critical Information List should be furnished to the https://icontent-hcm04.ns2.apps.mil/icontent/CUSTOM/DLAHCM04P/NoCompat/SEC-ASCA/ https://icontent-hcm04.ns2.apps.mil/icontent/CUSTOM/DLAHCM04P/NoCompat/SEC-ASCA/ contractor upon issuance of the DD Form 254.
3. Include OPSEC as part of its ongoing security awareness program and take all required OPSEC training provided by DLA.
4. Protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of operations performed by the contractor in support of the mission.
Reference Item 11.l:
Contractor’s Unclassified Automated Information System (AIS):
1. The Contractor shall safeguard and protect CUI provided by or generated for the Government (other than public information) that transits or resides on any non-Government information technology system IAW the procedures in DoDI 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems,” June 6, 2012, Enclosure 3 and NIST SP 800- 171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” June 2015. Information shall be protected from unauthorized access, disclosure, incident or compromise by extending the safeguarding requirements and procedures in DFARS clause 252.204-7012, Safeguarding of Covered Defense Information and Cyber Incident Reporting. The NIST SP 800-171 security controls specified in 252.204-7012 were extended to include Controlled Unclassified Information (CUI) information which resides on, or transits through the contractor’s (prime and all sub-contractors) unclassified information technology systems.
2. The contractor shall ensure that all persons accessing CUI meet the Tier 1 investigative requirements and must have lawful government purpose to access DLA unclassified AIS.
3. The “Controlled Unclassified Information Supplement” provides additional guidance for the handling, marking, transmission, reproduction, safeguarding, and disposition of CUI.
4. DLA reserves the right to conduct compliance inspections of Contractor unclassified information systems and other repositories for the protection of CUI.
Reference Item 12: The Prime Contractor shall forward all requests for public release authorization through the Contracting Officer or designated representative to the listed DLA program office. Per 32 CFR Part 117.15(h)(8) NISPOM, the Contractor shall include all necessary information to assist with the decision of the DLA program office. The Prime Contractor shall act as the focal point for all Subcontractor requests for public release. A lack of response from the DLA program office does not constitute as public release authorization. The Prime Contractor shall not release information to the public prior to receiving written authorization from the DLA program office (this requirement includes any information system that provides public access).
CONTROLLED UNCLASSIFIED INFORMATION SUPPLEMENT
1. Definitions.
a. Controlled Unclassified Information (CUI) Information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information.
b. Dual Citizenship. A dual citizen is a citizen of two nations. For the purposes of this document, an individual must have taken an action to obtain or retain dual citizenship.
Citizenship gained as a result of birth to non-U.S. parents or by birth in a foreign country to U.S.
parents thus entitling the individual to become a citizen of another nation does not meet the criteria of this document unless the individual has taken action to claim and to retain such citizenship. 
c. National of the United States. Title 8, U.S.C. Section 1101(a)(22), defines a National of the U.S. as:
(1) A citizen of the United States, or,
(2) A person who, but not a citizen of the U.S., owes permanent allegiance to the U.S.
NOTE: 8 U.S.C. Section 1401, paragraphs (a) through (g), lists categories of persons born in and outside the U.S. or its possessions that may qualify as Nationals and Citizens of the U.S. This subsection should be consulted when doubt exists as to whether a person can qualify as a National of the U.S.
d. U.S. Person. Any form of business enterprise or entity organized, chartered, or incorporated under the laws of the United States or its possessions and trust territories and any person who is a citizen or national (see National of the United States) of the United States, or permanent resident of the United States under the Immigration and Nationality Act.
2. Access.
a. No person may have access to information designated as CUI unless that person has been determined to have a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose. The final responsibility for determining whether an individual has a valid need for access to information designated as CUI rests with the individual who has authorized possession, knowledge, or control of the information, not with the prospective recipient.
b. e. When CUI is to be provided to or generated by DoD contractors, the controls and protective measures to be applied shall be described in the pertinent contract documents (e.g., contract clause; statement of work; or DD Form 254, “Department of Defense Contract Security Classification Specification”). Solicitations and contracts shall use a non-disclosure of information clause that prohibits release of unclassified information to the public without approval of the contracting activity (e.g., clause 252.204-7000 of the Defense Federal Acquisition Regulation Supplement). The clause shall also be made applicable to subcontractors.
c. ALL DoD unclassified information MUST BE REVIEWED AND APPROVED FOR RELEASE through standard DoD Component processes before it is provided to the public (including via posting to publicly accessible websites) in accordance with DoDD 5230.09, Clearance of DoD Information for Public Release, and other applicable regulations. Unclassified information previously approved for release to the public may be shared with any foreign government or organization.
d. Release or disclosure of CUI to foreign governments or international organizations shall be in accordance with DoDD 5230.20, Visits and Assignments of Foreign Nationals, DLAI 5230.01, Foreign Visit and Foreign Disclosure Program, and other policy and procedures that may be established by the USD(P) and the Defense Logistics Agency.
e. Some CUI is export-controlled information which may additionally be protected by law, Executive order, regulation, or contract. DoD officials must pay particular attention to export control regulations and to access restrictions on each type of CUI to ensure compliance with export requirements, especially when non-U.S. citizens are assigned to or visit their organizations.
f. Release or disclosure of CUI to non-U.S. citizens employed by the Department of Defense is permitted, provided access is within the scope of their assigned duties; access would further the execution of a lawful and authorized DoD mission or purpose and would not be detrimental to the interests of the Department of Defense or the U.S. Government; there are no contract restrictions prohibiting access; and the access complies with the requirements of export control regulations, as applicable. In such cases, the non-U.S. citizen shall execute a nondisclosure agreement approved by appropriate DoD Component authorities.
g. CUI may be identified in security classification guides to ensure the information receives appropriate protection. If the security classification guide is subsequently cancelled, a separate memorandum or other guidance document may be issued to identify the declassified information, if any, that qualifies as CUI as well as any CUI previously cited in the guide.
h. For unauthorized disclosures of CUI, no formal security inquiry or investigation is required.
However, the contractor must notify DLA of any incidents pertaining to unauthorized disclosures of CUI and appropriate management action shall be taken to fix responsibility for unauthorized disclosure of CUI whenever feasible or required by other guidance, and appropriate disciplinary action shall be taken against those responsible.
i. Non-Sensitive Positions. Non-sensitive positions associated with CUI are found at Contractor facilities processing such information on their (Contractor's) unclassified computer systems. All unclassified computer systems will be protected in accordance with DFARS 252.204-7012, Safeguarding of Covered Defense Information and Cyber Incident Reporting and
NIST SP 800-171, with access to CUI conducted in accordance with applicable policy.
Personnel nominated to occupy nonsensitive designated positions must have at least a favorably reviewed Tier 1 investigation. The Contractor shall contact DLA Office of Personnel Security at DIPERSECOperations@dla.mil, and provide the requested information. DLA Office of Personnel Security will assist the Contractor complete the necessary paperwork and fingerprints.
3. Identification Markings. CUI shall be marked in accordance with DoDI 5200.48.
4. Handling. Storage of CUI outside of Contractor facilities (i.e. residence, telework facility, hotel, etc.) shall be in a locked room, drawer, filing cabinet, briefcase, or other storage device, to prevent the access to the material by unauthorized individuals. Continuous storage of CUI outside of a Contractor facility shall not exceed 30 days unless government approval is granted.
5. Transmission/Dissemination/Reproduction.
a. Subject to compliance with official distribution statements, CUI markings (e.g., Export Control, Proprietary Data) and/or Non-Disclosure Agreements which may apply to individual items in question; authorized Contractors, consultants and grantees may transmit/disseminate CUI information to each other, other DoD Contractors and DoD officials who have an authorized, lawful government purpose in connection with any DoD authorized contract, solicitation, program or activity. The government Procuring Contracting Officer (PCO) will confirm with the Contracting Officer's Representative or Task Order Monitor authorized, lawful government purpose when required. Contractors shall employ Public Key Infrastructure (PKI) and Public Key (PK) enabling technologies for the electronic transmission of CUI. The following general guidelines apply:
(1) In accordance with DoD Instruction 5200.48, “Controlled Unclassified Information,” external electronic data transmissions of CUI shall be only over secure communications means approved for transmission of such information.
(2) Encryption of e-mail to satisfy this requirement shall be in accordance with DoD Instruction 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems,” June 6, 2012, being accomplished by use of DoD approved Public Key Infrastructure Certification or by the company’s participation in the “Federal Bridge.”
b. Failure of the Contractor to encrypt CUI introduces significant risks to the DLA mission.
It is essential for the Contractor to understand that mitigation options that are available. The Contractor must understand that failure to encrypt CUI carries with it certain risks to the mission.
These risks can be mitigated with the thoughtful application of processes, procedures, and technology. Some of the available mitigation tools include:
(1) Approved DoD PKI/CAC hardware token certificates or DoD trusted software certificates for encrypting data in transport.
(2) Industry best practice of Virtual Private Network (VPN) Internet Protocol Security mailto:DIPERSECOperations@dla.mil
(IPSEC) for intra-organization transport.
(3) Industry best practice of Secure Sockets Layer Portal Web Services for document sharing and storage.
(4) Approved DoD standard solutions for encrypting data at rest.
(5) Approved DoD E-Collaboration services via DLA Portal or Defense Information Systems Agency (DISA) Network Centric Enterprise Services (NCES).
(6) Any FIPS 140-2 validated encryption [e.g., IPSEC, Secure Socket Layer/Transport Layer Security (SSL/TLS), Secure/Multipurpose Internet Mail Extensions
(S/MIME)].
(7) Procure and employ Secure Telephone Equipment (STE).
(8) Procure and employ secure facsimile (FAX) capability.
(9) Utilize secure VTC capabilities.
(10) Hand-carry CUI.
(11) Utilize mailing through U.S. Postal Service.
(12) Utilize overnight express mail services.
c. The NIST SP 800-171 identifies the baseline CUI system security requirements for industry established by Part 2002 of Title 32, CFR. Additionally, Section 252.204-7012 of the DFARS specifies a waiver process for defense contractors in accordance with NIST SP 800-171 for contractor IT or networks. Additional information can be found in DoDI 5200.48, Controlled Unclassified Information.
d. Reproduction of CUI may be accomplished on unclassified copiers within designated government or Contractor reproduction areas.
6. Storage. During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel (e.g., not reading, discussing, or leaving CUI information unattended where unauthorized personnel are present). After working hours, CUI information may be stored in unlocked containers, desks, or cabinets if contract building security is provided. If such building security is not provided or is deemed inadequate, the information shall be stored in locked desks, file cabinets, bookcases, locked rooms, etc.
7. Disposition.
a. When no longer required, CUI shall be returned to the DLA office that provided the information or destroyed by any of the following means:
a. Burning (Use of burn bags and an authorized burn facility)
b. Cross-cut shredding (Shredders must be listed on the NSA Evaluated Products
List)
c. Any method approved for the destruction of classified material.
b. Removal of the CUI status can only be accomplished by the government originator. The DLA COR shall review and/or coordinate with proper authority the removal of CUI status for information in support of contract activity.
SECURITY GUIDANCE (BLOCK 13) CONTINUATION PAGES FOR CONTRACT #: SP4705-25-S-XXXX
Reporting Requirements:
Subcontractor Classified Access Approvals:
Pre-Award Access
Reference Item 8.a. (continued) Government Locations:
Reference Item 11.j:
Reference Item 11.m:
CONTROLLED UNCLASSIFIED INFORMATION SUPPLEMENT
PREVIOUS EDITION IS OBSOLETE.
Page of
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
June 30, 2025 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification"
| CurrentPage: |
| PageCount: |
| Select classification from drop-down list.: CUI |
| SerialNum: |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Select for "original.": 0 |
| Select for "original.": 1 |
| Enter prime contract number.: |
| Select for "revised.": 0 |
| Select for "revised.": 0 |
| Enter subcontract number.: |
| Select for "final.": 1 |
| Select for "final.": 0 |
| Enter solicitation or other number.: SP4705-25-S-XXXX |
| Enter due date in format YYYYMMDD.: 20250801 |
| Enter date in format YYYYMMDD.: |
| Enter revision number.: |
| Enter date in format YYYYMMDD.: |
| Enter final specification.: |
| Enter date in format YYYYMMDD.: |
| Select for "no.": 1 |
| Select for "no.": 1 |
| Select for "no.": 0 |
| Select for "no.": 1 |
| Select for "yes.": 0 |
| Select for "yes.": 0 |
| Select for "yes.": 1 |
| Select for "yes.": 0 |
| Enter preceding contract number.: |
| Enter contractor's request date in format YYYYMMDD.: |
| Enter period.: |
| Enter typed name of certifying official (last, first, middle initial).: Andrea Terrell |
| Enter CAGE code of the prime contractor.: |
| Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: |
| Select to add row to locations.: |
| Select to remove last row from locations.: |
| Select to delete all signatures.: |
| Enter location(s).: Defense Logistics Agency |
8725 John J. Kingman Road Fort Belvoir VA 22060-6221
| Enter general unclassified description of this procurement.: This contract is for Elevator Maintenance and Services at the DLA Headquarters Complex. |
| Select for "a. CONTRACTOR.": 0 |
| Select for "a. CONTRACTOR.": 0 |
| Select for "a. CONTRACTOR.": 1 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "f. OTHER AS NECESSARY.": 0 |
| Select for "f. OTHER AS NECESSARY.": 1 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "b. SUBCONTRACTOR.": 0 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0 |
| Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0 |
| Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 0 |
| Select for "h. REQUIRE A COMSEC ACCOUNT.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "i. HAVE A TEMPEST REQUIREMENT.": 0 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 0 |
| Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 0 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1 |
| Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 0 |
| Enter infomration for "other.": Within Pod 10 secured space and systems such as Elevator Control and Monitors etc. (Cyber security). |
| Enter infomration for "other.": Contractor employees may be in areas where information is visible and or audible. |
| Enter infomration for "other.": DLA Industrial Security |
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 1 |
| Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 1 |
| Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1 |
| Select for "m.OTHER.": 1 |
| Select for "direct.": 0 |
| Select for ": 1 |
| Enter specification for "through".: DLA/DP |
Route Public Release requests to Public Affairs Office Via COR
| Enter public release authority.: DLA Public Affairs Office |
| Select to add signature.: |
| Select to remove last signature.: |
| text: Reference Item 6: |
Reference Item 8.a.
Reference 10k.
Reference 11e.
Reference Item 11.j:
Reference Item 11.m:
Reference Item 12:
| Click on this button to attach a file(s).: |
| rep: Candy Best |
Industrial Security Program Manager
| Enter signature.: |
| Explain and identify specific areas and government activity responsible for inspections.: See Reference Items: 10j; 11j; 11l. |
| Enter GCA name.: DLA DCSO |
| Enter AAC of the contracting office.: SP4705 |
| Enter AAC of the contracting office.: SP4705 |
| Enter address (include zip code).: 8725 John J. Kingman Road |
Fort Belvoir VA 22060 Enter address (include zip code).: 8725 John J. Kingman Road Fort Belvoir VA 22060
| Enter POC name.: Odemaris Dekle |
| Enter telephone number (include area code).: 4457375019 |
| Enter telephone number (include area code).: 5717672724 |
| Enter email address.: odemaris.dekle@dla.mil |
| Enter title.: Facility Systems Operations Specialist (COR) |
| Enter the date signed in format YYYYMMDD.: 20250624 |
File details come from the government source that posted it. Updated .