TYQ-23A TSC-250 CLS Performance Work Statement v5.pdf

PDF 784 KB Posted

Attached to
Source Selection Solicitation for Follow on TYQ23A and TSC 250 Contractor Logistic Support Federal contract opportunity
Solicitation number
FA8217-25-R-B005
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hill Air Force Base

View the file

Other files for this federal contract opportunity

Other files attached to Source Selection Solicitation for Follow on TYQ23A and TSC 250 Contractor Logistic Support, newest first.
File Type Posted
QA SSS.xlsx XLSX spreadsheet
Section M v6.3.1 Final.pdf PDF
CRC CLS Matrix Follow on.xlsx XLSX spreadsheet
Solicitation TYQ-23A DD254 (2) (signed PJDWF).pdf PDF
Section L v6 Final 30 June (1).pdf PDF
Solicitation - FA821725RB005.pdf PDF
Section M v6.3 Final.pdf PDF
GFPFA821725R5000_22222.pdf PDF
ANTYQ-23A CDRL Package.pdf PDF
PortfolioCLS Matrix.pdf PDF
Addendum Section M page 20 (002).pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement

FOR

AN/TYQ-23A and AN/TSC-250 Sustainment of Tactical Air Operation Module

Solicitation Number: FA821725R5000

Order Number:

Revision: 05

1 Jul 25

Controlled By: Air Force Life Cycle Management Center Controlled By: AFLCMC/C3BYC

CUI Category: OPSEC Distribution/Dissemination Control: FEDCON

POC: Courtney Pace, DAF, 801-586-0202

CUI

Advanced Battle Management System

Division

Program Manager Courtney Pace AFLCMC/C3BYC Contracting Officer Wendy Farley AFLCMC/HBDK/C3BYC

Table of Contents

1. General Information

1.1 Overview:

1.2 Description of Services:

1.3 Background:

1.4 CRC Functions:

1.5 Scope:

1.6 Period of Performance:

1.7 Basic Requirements:

1.8 Small Business Subcontracting Plan:

1.9 50/50 Reporting:

1.10 Labor Reporting:

1.11 Reporting Inputs:

1.12 Uses and Safeguarding of Information:

1.13 User Manuals:

2. Additional General Information:

2.1 Recognized Holiday:

2.2 Hours of Operation:

2.3 Location of Work:

2.4 Contractor Employee:

2.5 Place of Performance:

2.6 ADPE Hardware/Software

3. Health and Safety; Security and Property Damage:

3.1 Worker’s Health and Safety:

3.2 Security Requirements:

3.3 Operations Security (OPSEC):

3.4 Communication Security (COMSEC):

3.5 Security Clearance:

3.6 Security Incident or Violation:

3.7 Access to Government System(s):

3.8 Security of Contractor Systems:

3.9 Common Access Card (CAC):

3.10 Physical Security:

3.11 Government Property Damage:

3.12 Program Protection:

4. Cyber Security

4.1 Cyber Security and Information Assurance (IA):

4.2 Cybersecurity Strategy:

4.3 Cybersecurity Controls:

4.4 Cybersecurity Risk Management:

5. Quality:

5.1 Quality Control (QC):

5.2 Contracting Office Representative (COR):

5.3 Identification of Contractor Employees:

6. Contractor, Freight, and Travel/Transportation:

6.1 Travel Regulations:

6.2 Travel and Other Direct Costs:

6.3 Travel:

6.3.1. Conus Travel:

6.3.2. OCONUS Travel:

6.4 Parts, Material and Supplies Delivery:

6.5 Freight Charges:

7. Contractor Responsibility

7.1 SharePoint Database with Reporting::

7.2 Records/Data:

7.3 Program Management Review (PMRs), Technical Interchange Meeting (TIMs), Staff Assistance Visits:

7.4 CDRL Listing:

8. Government Furnished Property, Equipment, and Services

8.1 Services:

8.2 CLS TYQ-23A/TSC-250GFP Disposition:

9. Contractor Furnished Items and Services:

9.1 Contractor Acquired Property:

10. Work Requirements and Tasks

10.1 Work Requirements:

10.2 Task Requirements & Technical Capabilities:

10.3 Program Management

10.3.2 Bi-Weekly Meetings

10.3.3 Post Award Conference/Periodic Progress Meetings:

10.4 Knowledge, Skills and Abilities/ Qualifications:

10.5 Teleprocessing and Shipping:

10.5.1 Teleprocessing:

10.5.2 Packaging/Packing/Shipping Instructions:

10.6 Telephone Support:

10.7 Government Systems Account:

10.8 Repair and Maintenance Analysis:

10.9 Maintenance Data Collection:

10.9.2 Analysis Reporting:

10.9.3 Tools to Support Field Repair- Help Desk Tool, Report Database, Sharing:

10.9.4 Maintenance Report Content:

10.9.5 Approach to Parts and Maintenance Data Collection:

10.10 System Maintenance:

10.10.2. Component Failure:

10.10.3 Component Repairs:

10.10.4 Depot Repair:

10.10.4.2 Parts Repairs

10.10.4.3 Line Repair Unit (LRU) Repairs

10.10.4.4 Limited Repairs

10.10.5 Field Systems Repairs Requiring Spares from Depot Inventory:

10.10.6 Fielded Systems Repairs Requiring Spares Purchase:

10.11 Spares Supply:

10.11.1 Readiness Spares Package List:

10.11.1 Recommended Pipeline Spares List:

10.11.2 Spares Usage Reporting:

10.11.3 Field Repairs Requiring On-Site Depot Repair:

10.11.4 Software Sustainment:

10.11.4.1 Software Releases:

10.11.4.1 Process for Software Releases:

10.11.4.2 Managing Software Licenses::

10.12 COTS/GOTS Version Updates:

10.13 Trouble Report Fixes (TRs) and Urgent Needs Capability Updates:

10.14 Diminishing Manufacturing Sources and Material Shortages:

10.14.1 Managing DMSMS:

10.14.2 Strategy for Cost Effective Approach to DMSMS/EOL components:

10.14.3 Management of Obsolete Parts:

10.14.4 Process Flow for DMSMS:

10.14.5 Obsolescence Report:

10.15 Technical Refresh Plan:

10.15.4 Operational Safety, Suitability, and Effectiveness (OSS&E):

10.15.5 10.14.5. Preliminary Design Review:

10.15.6 Critical Design Review::

10.15.7 Test Readiness Review

10.15.8 Technical Data Package

10.15.9 Engineering Change Proposals (ECPs):

10.15.10 Request for Variance (RFV):

10.15.11 Specification Change Notices (SCN):

10.15.12 Model Based Systems Engineering

10.15.13 Functional Configuration Audit

10.15.14 Physical Configuration Audit

10.15.15 Interface Control Document

11. Developing new capabilities

12. Testing requirements

13. Training

14. Cybersecurity Management

14.1 SIPRNet:

14.2 Cybersecurity Updates

14.3 RMF Requirements:

14.4 Cybersecurity Test & Evaluation:

15. Demilitarization (DEMIL)

16. Trouble Ticket tracking

17. Transition

18. Reports

18.1 Monthly CDRLs

18.1.1 CDRL A001(DI-MGMT-80368A) – Monthly Technical Status Report (MTSR):

18.1.2 CDRL A002(DI-MGMT-80368A) – Monthly Financial Status Report (MFSR):

18.1.3 CDRL A003(DI-MGMT-80368A) – Trip Reports

18.1.4 CDRL A004(DI-MGMT-80368A) – Spares Usage Reports:

18.1.5 CDRL A011(DI-MGMT-80368A) -- Field Maintenance Report (FMR):

18.2 Delivery Instructions:

19. Item unique Identification

20. Procedures and Warranty Management Responsibilities

20.1 Procedures and Warranty Management Responsibilities

21. Quality Assurance

22. Service Summary:

23. Appendix A: CRC Unit List

Appendix A: AN/TYQ-23A:

Appendix A: AN/TSC-250:

24. Appendix B: MFSR Format

25. Appendix C: Safety Requirement

Contractor’s Guide Safety Appendix

GENERAL SAFETY REQUIREMENTS

26. Appendix D: Air Force Technical Manual Contract Requirements Air Force Technical Manual Contract Requirements (TMCR)

Section 1. Technical Order (TO) Program Requirements – TMSS Linear TMs Section 2. TM TYPE AND DELIVERY REQUIREMENTS Section 3. SPECIFICATION/STANDARD INTERFACE RECORDS (SIRS)

27. Appendix E: Acronym Table

1. General Information

1.1. Overview:

1.1.1. This is a service contract to provide Contract Logistics Support and unscheduled maintenance/repairs on various configurations, technologies, and manufacturers of Tactical Air Operations Module AN/TYQ- 23A and TSC-250 Communication Data Link System (CDLS) and ancillary equipment for the United States Air Force (USAF) and Government Agencies Worldwide. Maintenance of these systems is critical to ensure that the systems will function as designed for operational and mission success. Repairs, including emergency repairs, are required to keep these systems in fully functional condition. All Performance Work Statement (PWS) and contractual discrepancies shall be identified, clarified, and negotiated with the Procurement Contracting Officer (PCO). The PCO is the only individual who can legally bind the Government.

1.1.2. The AN/TYQ-23A is a transportable command, control, and communications facility which provides the equipment and organization necessary to plan, direct, and control tactical air operations, and to perform specified air space management tasks. With the aid of external radars, Identification Friend or Foe with Selective Identification Feature (IFF/SIF) interrogators, power sources, and optional external communications equipment, the OM accomplishes the mission by performing the following functions:

• Detection, identification, and classification of all aircraft and missiles within the sector of responsibility.

• Track management of each aircraft, missile, and ship within the sector of responsibility, as required.

• Data transmission, reception, and forwarding with other agencies.

• Evaluation of the threat potential of enemy aircraft and missiles, and the selection and assignment of weapons to engage hostile threats.

• Engagement control of friendly interceptor aircraft and surface-to-air missiles against enemy threats.

• Control of airspace and air traffic within the sector of responsibility, and performance of designated airspace management tasks.

For the number of AN/TYQ-23A systems and locations, refer to Appendix A.

1.1.3. The AN/TSC-250 CDLS is designed to interface with an AN/TYQ-23A Tactical Air Operations Module. The AN/TSC-250 is a transit case system providing the AN/TYQ-23A with modernized RF Link 16 Datalink capability. The equipment in the MIDS-JTRS Mobile System (MJMS) Rack is the core of this capability. It provides all the power, cooling, and signal interfaces the AN/USQ-190(V)5(C) Radio Set (MIDS-JTRS-CMN4 terminal) requires operating. The MJMS is supported by an Uninterruptable Power Supply (UPS) in a separate transit case. The Ancillary Rack Transit Case contains a managed Ethernet switch that provides a centralized, controlled Ethernet LAN Element for the AN/TSC-250. For the number of AN/TSC-250 systems and locations, refer to Appendix A.

1.2. Description of Services:

1.2.1 The Contractor shall provide all personnel, labor, equipment, supplies, transportation, tools, materials, technical data/manuals, expertise, supervision, and services necessary to perform maintenance as defined in this PWS except for those items provided by base support. The Contractor shall employ a worldwide service organization, trained and experienced in providing Contract Logistics Support, such as but not limited to diagnosis and repair on all covered equipment. The Contractor is ultimately responsible for problem resolution during maintenance activities, i.e., the Contractor shall be responsible for aspects of maintenance activities to include associated hardware and software to ensure fully operational status, troubleshooting/diagnosis, and resolution. The Contractor shall ensure internal coordination and correction of problem resolution with the Government Point-Of-Contact (POC) and Control and Reporting Center (CRC) Program Office (PMO), prior to work performance.

1.2.2. Research, Development, Test and Evaluation (RDT&E 3600 funds) appropriations may be used to finance the following efforts: Research, Development, Test and Evaluation Efforts (including the equipment, material or computer application software developed with RDT&E funds), Development Test and Evaluation (DT&E), and Operational Test and Evaluation (OT&E).

1.2.3. Operation and Maintenance (O&M 3400 funds) appropriations fund expenses such as civilian salaries, travel, minor construction projects, operating military forces, training and education, depot maintenance, stock funds, and base operations support.

1.2.4. Procurement (3080 funds) finances the procurement of direct and indirect ground weapon support equipment, other industrial facilities, equipment modifications, investment-type spares, and first destination transportation. Included in this appropriation is the installation/emplacement of the equipment, production, product improvement, testing, and end item associated technical data and handbooks.

1.3. Background: The CRC is a deployable battle management command and control (BMC2) system employed at the tactical level to support air operations execution across the entire range of operations, from Homeland Security to major combat operations. CRC’s mission is to provide Battlespace Awareness (BA) and tactical BMC2 in an assigned area. CRC Network of systems are tactical C2 element that operates independently or in combination with other tactical, joint, or coalition C2 elements. CRC manages the theater’s integrated air defense system, conducts air surveillance, participates in-theater data link operations, and controls air operations in accordance with the Air Tasking Order (ATO) Airspace Control Order (ACO).

1.4. CRC Functions:

1.4.1. Battle Management Command and Control (BMC2):

The CRC provides the air/ground operations in a decentralized execution mode, by managing, disseminating, and assigning mission tasks defined in appropriate tasking orders.

1.4.2. Weapons Control:

Support and/or coordination of Offensive Counter Air/Defensive Counter Air (OCA/DCA), Air Interdiction (AI), Aerial Reconnaissance (AR), Close Air Support (CAS), Combat Search and Rescue (CSAR), High- Value Airborne Asset (HVAA) protection, Electronic Warfare (EW), Intelligence, Surveillance, and Reconnaissance (ISR), special operations, and the direction of air defense artillery systems.

1.4.3. Surveillance:

Detection, identification, classification, and tracking of airborne/ground objects (sensors detect and provide cueing to engage hostile threats such as manned or unmanned aircraft or cruise missiles).

1.4.4. Combat Identification:

Capability to disseminate timely, accurate, and relevant identification information to weapon system operators to allow engagement of hostile targets and avoid fratricide.

1.4.5. Airspace Management:

Implementation of the Air Tasking Order and Airspace Control Order.

1.4.6. Tactical Data Link (TDL) Management:

Consolidate sensors into the Common Tactical Picture (CTP) for distribution over Tactical Data Link.

1.5 Scope:

1.5.1. The Contractor shall furnish all labor, tools, equipment, technical data/manuals, materials, supplies, parts, Original Equipment Manufacturer (OEM) service bulletins, and services necessary to perform Contractor Logistics Support on TYQ-23A/TSC-250 In Accordance With (IAW) OEM standards (commercial standards if third party is performing service/repair), including software/firmware upgrades.

This support includes but is not limited to: Engineering support, project services, R&M tracking analyses, procurement of spares (Spares Parts Usage Report), depot supply support, depot maintenance support for Hardware/Software (HW/SW), Technical Orders/Manuals (TO/TM), Time Compliant Technical Order’s (TCTOs), Packaging, Handling, Storage and transportation (PHS&T), warranty management, Government Furnished Property (GFP) and any component that compromises the “TYQ-23A/TSC-250 System”, for the USAF and Government Agencies worldwide. This support shall also include Emergency and Preventative Maintenance for any future technologies designed to be implemented in the TYQ-23A/TSC-250. This sustainment effort may substantially increase in cost due to future capability advancements on the TYQ- 23A/TSC-250 and related systems through a bilateral modification. If there is a next-generation or replacement to the TYQ-23A/TSC-250 that is fielded during the POP of this contract, CLS support will continue to be required for the TYQ-23A/TSC-250 program.

1.5.1. The Contractor Logistics Support (CLS) contractor shall provide comprehensive engineering, logistical support, and technical site support for the system. Depot-level maintenance may be conducted either in the field or at the contractor's facility, encompassing testing, parts repair, parts replacement, and shelter maintenance. Additionally, the contractor shall assist in maintaining the Authority to Operate (ATO) and necessary licenses to ensure the system meets a minimum Operational Availability (Ao) standard of 95%.

1.5.2. The CLS contractor shall also perform the role of a Supply Point for Commercial Off-The-Shelf (COTS) products, ensuring the availability and timely delivery of necessary components. Furthermore, the contractor shall provide field support functions, including on-site technical assistance and troubleshooting to maintain system readiness and operational effectiveness.

1.6. Period of Performance: The period of performance of this contract shall have an ordering period of five (5) years After Receipt of Order (ARO).

1.7. Basic Requirements: The Contractor shall maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS for the duration of the period of performance. The Contractor shall maintain the necessary technical expertise to update system cybersecurity and software.

Additionally, the contractor shall implement effective supply chain management practices to ensure an Operational Availability (Ao) of 95% for the AN/TYQ-23A and AN/TSC-250 systems. The Contractor shall comply with all country, federal, installation, state local, industry, and national codes. Certain locations require U.S. Citizenship’s to service and maintain TYQ-23A/TSC-250. All Intelligence Surveillance Reconnaissance (ISR) missions shall be serviced by U.S. Citizens and require constant U.S.

Control for parts utilized.

1.8. Small Business Subcontracting Plan: If the awardee is a large business, the Contractor shall submit a small business subcontracting plan.

1.9. 50/50 Reporting: 50/50 reporting is a requirement for the Department of Defense (DoD) to manage compliance with the Depot Maintenance Statute. The statute requires that 50% of depot maintenance workload be performed organically, and the remaining 50% be performed by contract. The 50/50 reporting requirement applies to a three-year period, including the current fiscal year, the preceding fiscal year, and the ensuing fiscal year. The Contractor shall comply with 50/50 reporting requirements. Submittals due yearly by 15 Oct. (CDRL A026)

10. Labor Reporting: The Contractor shall report contractor labor hours (including subcontractor labor hours) as required for performance of services, specifically meeting the requirements in Federal Acquisition Regulation (FAR) 52.204-14 and 52.204-15, provided under this CLS contract via secure data collection site. All required data fields shall be submitted via www.sam.gov.

1.11. Reporting Inputs: Reporting inputs will be for the labor executed during the period of performance for each Government Fiscal Year (FY), which runs 1 October through 30 September. While inputs may be reported anytime during the FY, all data shall be reported no later than 31 October of each calendar year.

Contractors may direct questions to the Contract Manpower Reporting Application (CMRA) help desk.

1.12. Uses and Safeguarding of Information: Information from secure government web sites is considered proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the Contractor’s name and contract number associated with the data.

1.13. User Manuals: Data for Air Force service requirements must be input at the DoD CMRA Link, http://www.sam.gov, along with user manuals for government personnel and contractors. Data for Air Force service requirements must be input into the DoD CMRA at https://www.ecmra.mil/. Additionally, user manuals and government technical orders for both government personnel and contractors must be provided to ensure proper use and understanding of the system. (CDRL A030)

2. Additional General Information:

2.1. Recognized Holiday: The Contractor may be required to perform service on holidays upon request, including but not limited to:

New Year’s Day Labor Day Birthday of Martin Luther King Jr. Columbus Day President’s Day Veteran’s Day Memorial Day Thanksgiving Day Independence Day Christmas Day Holiday specific to host country Juneteenth

2.2 Hours of Operation: The Contractor shall be responsible for conducting business during core hours of Monday through Friday 8am to 5pm Mountain Standard Time (MST) and a technical support line, except when the Government facility is closed due to local or national emergencies, acts of Nature, acts of War, administrative closings, or similar Government directed facility closings. The Contractor shall not be reimbursed when the Government facility is closed for the above reasons and shall not file a request for equitable adjustment.

2.3. Location of Work: Contractor travel and work may be performed at, but not limited to, all Air Control Squadrons, Major Commands, CRC Program Office, Depots, and Contractor’s Facility. No travel and work shall be performed in a Combat Zone. If the Contractor performs duties outside the United States, the Contractor shall procure Defense Base Act (DBA) Insurance in accordance with FAR 28.305. Contractor shall observe the safety rules IAW Appendix C (as required). Appendix A illustrates primary travel http://www.sam.gov/ http://www.sam.gov/ locations but is not all inclusive.

2.4. Contractor Employee: When hiring personnel, the Contractor shall keep in mind that stability and continuity of the workforce are essential. The Contractor shall not employ persons for work on this contract if such employee is identified to the Contractor by the PCO as a potential threat to the health, safety, security, and/or general well-being to the operational mission of the installation and its population.

Contractor personnel shall meet site access requirements which may require, in some instances, US Citizenship and elevated clearance. Contractor personnel may be required to undergo a background investigation to perform their duties. Contractor personnel shall comply with all regulations for overseas travel.

2.5. Place of Performance: The work pursuant of any contract associated with this PWS shall be performed at various industrialized, non-industrialized, and remote locations worldwide.

2.6. ADPE Hardware/Software: The Contractor shall the Contractor shall have access to and be proficient in the use of computer devices, and in using current Microsoft Office suite, Adobe suite, and other software necessary to meet program support requirements.

3. Health and Safety; Security and Property Damage:

3.1. Worker’s Health and Safety: The Contractor shall comply with all applicable Country, Federal, State, Territorial, and local requirements regarding worker’s health and safety. The Contractor is solely responsible for determining the legal requirements and compliance that apply to their activities. These include but are not limited to all Occupational safety and Health Administration (OSHA) safety rules and regulations, arc flash training, personal protection training and equipment to protect themselves and others from unsafe work conditions. The Contractor shall report any accidents or OSHA violations immediately to the appropriate authorities and within one (1) business day to the PCO and comply with (CDRL A007).

3.2. Security Requirements: The Contractor shall meet personnel, information, system, property, and facility security requirements. The Contractor personnel shall meet site access requirements which may require, in some instances, US Citizenship, i.e., DISS Request. This may include but not limited to vehicle and equipment access requests, Visit Access Request (VAR) submittals, and electronic media device submittals to include mobile telephone, camera devices, etc. The Contractor shall also comply with all Foreign Disclosure Office (FDO) requirements. Contractors’ identification shall be in compliance with the REAL ID act compliant identification. See https://www.dhs.gov/real-id-public-faqs for additional information.

3.3. Operations Security (OPSEC): The purpose of OPSEC is to reduce the vulnerability of USAF Missions to adversary collection and exploitation of critical information. The Contractor shall comply with DoDD 5205.02E, DoDM 5205.02-M and other applicable Government security regulations to protect classified information and/or Controlled Unclassified Information (CUI), Government projects and/or programs.

3.4. Communication Security (COMSEC):

3.4.1. The Contractor shall have an active COMSEC account and use only secure communication methods and equipment to handle, store, and transmit classified materials, information IAW DoD 5200.01 (DoD Information Security Program), and Controlled Unclassified Information (CUI) in accordance with DoD 5220.22-M (National Industrial Security Program Operating Manual) and applicable Air Force directives.

All operations must be conducted in compliance with DoD 5220.22-M and relevant Air Force policies to ensure the protection of sensitive information.

https://www.dhs.gov/real-id-public-faqs

3.5 Security Clearance: The Contractor shall possess a facility clearance IAW the DD Form 254. The Contractor shall ensure personnel have SECRET security clearances for proper accomplishments of contract requirements. Contractor personnel shall obtain clearances IAW the DD Form 254, Department of Defense Contract Security Classification Specification. The Contractor shall inform the CRC Program Management Office (CRC PMO) of all clearance requests. The Contractor shall immediately deny access to classified information and CUI to contractor personnel whose clearances have been suspended or revoked or no longer have a need-to-know.

3.6. Security Incident or Violation: The Contractor shall notify the COR of any potential or actual security incident or violation including potential or actual unauthorized disclosure or compromise of classified information and/or CUI no later than the next business day after the Contractor discovers the incident or violation.

3.7. Access to Government System(s): The Contractor will obtain forms from the COR to gain access to system(s) necessary to perform tasks under the contract. Contractor personnel who require access to unclassified or classified Government systems shall have the appropriate background check or security investigation conducted, as well as the required training prerequisite to obtaining SIPRNet tokens. Access can be revoked or restricted at any time.

3.8. Security of Contractor Systems: The Contractor shall provide security of automated information systems at the Contractor’s facility to preclude potential security incidents or violations including potential unauthorized disclosure or compromise of classified and/or CUI.

3.9. Common Access Card (CAC):

3.9.1. In accordance with AFFARS 5352.242-9001, Common Access Cards (CAC) for Contractor Personnel, all contractor or subcontractor personnel who require access to DoD computer networks and systems, DoD installation entry control or physical access to facilities and buildings to perform tasks under the contract shall obtain a CAC. The Contractor shall provide via an email notification a list of contractor or subcontractor personnel who require a CAC to the COR. The Contractor shall notify the COR of any change to the list and provide an updated list within ten calendar days.

3.9.2. In accordance with AFFARS 5352.242-9001, the Contractor shall report a lost or stolen CAC no later than the next business day. The Contractor shall return CACs within seven working days once contractor personnel no longer require computer network/system access and/or installation access. The Contractor shall return an expired CAC within seven working days after the expiration date.

3.10. Physical Security:

3.10.1. The Contractor shall be responsible for safeguarding all Government equipment, information and property provided for contractor use. The Contractor shall provide protection to Government property to prevent damage during the period which the property is under the control or possession of the Contractor.

3.11. Government Property Damage: The Contractor shall record and report, within one (1) business day, to the CRC Program Manager, PCO and designated Government site POC, all available facts relating to each instance of accidental damage to Government property or injury to either contractor or Government personnel. The Contractor shall not perform any work on the damaged equipment/property until released by an authorized Government representative. If the Government elects to investigate the accident, the Contractor shall cooperate fully and assist the Government personnel until the investigation is completed.

(CDRL A014)

3.12. Program Protection:

3.12.1. The Contractor shall integrate cybersecurity into systems security engineering (as part of systems engineering), program protection, anti-tamper, and design processes. The Contractor shall ensure that the cybersecurity portions of the overall system design are included in system engineering and design documents, test plans, procedures, and reports. The Contractor shall clearly and consistently identify cybersecurity boundaries in program documents and drawings. The Contractor shall ensure that the development environment and processes support cybersecurity implementation. For all cybersecurity testing, regression testing, etc., any procedures deemed unnecessary shall require Government approval prior to omission.

3.12.2. The Contractor’s cybersecurity workforce shall maintain compliance with the cybersecurity contractor training and certification requirements and meet the investigative level requirements established in Enclosure 3 of DoDI 8500.01

4. Cyber Security

4.1. Cyber Security and Information Assurance (IA):

4.1.1. The Contractor shall ensure all facilities, computer and data systems to include technical diagnostic equipment, used to store and process data will implement and maintain administrative, physical, technical, and procedural safeguards and industry best practices at a level sufficient to secure total Data Loss Prevention (DLP) such as cybersecurity, unauthorized access, destruction, use, modification, disclosure and overall vulnerability.

4.1.2. Contractor shall leverage industry expertise, state of the art technology, tactics, techniques, and industry best practices regarding risk management frameworks. Contractor shall develop, validate, and implement cybersecurity mitigation strategies and security controls. Contractor shall implement industry-standard and up-to-date security tools, technologies and procedures including, but not limited to:

• Anti-virus and anti-malware protections

• Intrusion detection

• User accounts (local, system, service, active directory)

• Encryption in compliance with FIPS 140-3

• Physical accountability safeguards

4.2. Cybersecurity Strategy:

4.2.1. The Contractor shall implement the Government-developed Cybersecurity Plan for the system, its subsystems, components, and support systems/equipment IAW DoDI 8510.01.

4.2.2. The Contractor shall adhere to the following definitions for patches and configuration changes for all requirements:

4.2.3 For Minor configuration changes:

• SW/firmware version updates that do not have security implications (including supply chain risk management security implications) but affect security controls associated with the current authorization and security baseline (e.g., releases and/or SW/firmware updates that add functionality, registry or permissions changes, adding additional pre-existing system assets).

• Change to the IS name or other minor administrative type action that requires an ATO authorization update or move within the same physical location (i.e., same building).

• Additional HW/SW with the same configuration computing environment as approved in the existing authorization. For example, adding new servers or network devices with the same configuration or core build as those previously approved and within the same physical location (i.e., same building); noting the new servers or network devices may be the same or similar model as replaced with more powerful computer components (i.e., upgraded processors, more memory) as normally takes place with a cyclical technical HW refresh.

• OS or SW application major version upgrades assuming the upgrade reduces vulnerabilities/misconfigurations. (e.g., upgrading Windows 10 to Windows 11)

• Modification of system ports, protocols, or services (PPS) using Category Assurance List

(CAL)

4.2.4. For moderate configuration changes:

• Adding or removing HW, SW, or other Information Technology (IT) that is not within the same configuration of existing devices, SW, etc.

• Changing the source of software updates or container images. (e.g., using an open-source repository instead of Iron Bank)

• New local system connections (permanent/dedicated or via removable media). Adding an external connection to another system will require the program office to develop an interconnection security agreement (ISA) using ref (f) and routing an Information Systems Security Manager (ISSM) signed Security Impact Analyses (SIA) memo in eMASS for consideration. This may require obtaining the external system’s security authorization package to assess the risk of the new connection. Connections to systems outside the AO boundary may require an Approval to Connect (ATC) from the external system’s Authorizing Official (AO).

• A change in device platform (e.g., Juniper router to Cisco router) or system location (e.g., different building, base, or deploying a type-authorized system to a location not covered by the original authorization).

• Introduction of new technologies not listed above, Ports, Protocols, Services (PPS), HW/SW/services not in the approved ATO baseline, technical capabilities, or functions that enable new missions, enhanced features, or operational environments, requiring the application of new Security Technical Implementation Guides (STIG), scans, and/or other configuration type guides to support a hardened Information System (IS) and environment.

4.2.5. For significant configuration changes:

• Changes to the Information Technology Categorization and Selection Checklist (ITCSC) (e.g., change in applicable overlays, CIA High Water Mark, etc.) Risk Management Framework (RMF Step 1) and/or Control Selection (RMF Step 2).

• Technology refresh encompassing the addition or removal of multiple HW, SW, firmware, processes, or other IT components that are not within the same configuration of existing baseline.

• Any changes to connections to one or more Cross-Domain Solutions (CDS).

• Modification of system PPS Management (PPSM) using non-compliant ports and protocols if the system is connected to the DoDIN. Check https://usaf.dps.mil/teams/IACE/Wiki/Non- Compliant-PPS.aspx for the definition of non-compliant ports and protocols. Some processes may require the AO’s signature. The ports and protocols should match applicable Interface Control Documents (ICD) approved connections.

• Consolidating two or more ATOs for eMASS record reduction efforts where the function and https://usaf.dps.mil/teams/IACE/Wiki/Non-Compliant-PPS.aspx https://usaf.dps.mil/teams/IACE/Wiki/Non-Compliant-PPS.aspx capabilities have not changed and the ATO security baseline for each authorization can be coherently assimilated with each system having like computing environments and risk assessments.

• Changes that result in an adverse security impact (i.e., increased risk) as evaluated by the ISSM and/or SCAR.

4.2.6. The Contractor shall apply cybersecurity requirements to networked assets used to support TYQ-23A (e.g., unclassified test bed, Base Stations, SIPRNet workstations).

4.3. Cybersecurity Controls:

4.3.1. The Contractor shall identify, manage, and verify adherence to cybersecurity requirements in the same manner as all other system requirements.

4.3.2. The Contractor shall implement, per PMO direction, the applicable cybersecurity controls from Committee on National Security Systems Instruction (CNSSI) No. 1253 for the system using the Risk Management Framework (RMF) process, or other DoD approved equivalent process, developed by the program. The Contractor shall update the System Security Plan (SSP) to document the controls as implemented in the system design to include National Institute of Standards and Technology (NIST) SP 800-172. CMMC level 3 requirements are forthcoming, but are not a current requirement. The Contractor shall ensure and document bi-directional traceability between security controls and requirements. (CDRL A021)

4.3.3. The Contractor shall ensure, per PMO direction, that technical data developed for the program address any cybersecurity controls (e.g., administrative, procedural, inherited) or requirements that affect system operation, maintenance, repair, or other support activities. As needed, the Contractor shall develop and update technical documents with new processes to meet these requirements.

4.4. Cybersecurity Risk Management:

4.4.1. The Contractor shall conduct an assessment of the system configuration to identify and quantify cybersecurity risks introduced by the addition of new hardware and software to the system. In the assessment, the Contractor shall include a completed System Security Plan and a quantitative risk assessment supported by an architecture analysis with data flows explaining how the controls, as described in CNSSI No. 1253, are applied to the information, architecture, and underlying hardware and software

(CDRL A021).

4.4.2. The Contractor shall update and provide the following cybersecurity system documents when changes affecting the cybersecurity posture of the CRC system are made (CDRL A021):

• Hardware list

• Software list

• Plan Of Action & Milestones (POA&M)

• Port, Protocol, Services Management (PPSM) list

• Network diagram

• Data flow diagram

4.4.3. The Contractor shall identify and manage cybersecurity risks as part of the overall program risk management process (consisting of cost, schedule, and performance risks). The Contractor shall ensure cyber risk management activities are consistent with guidance provided in Committee on National Security Systems Policy (CNSSP) No. 22 (Cybersecurity Risk Management Policy). (CDRL A021)

4.4.4. The Contractor shall ensure that the cybersecurity risk management activity frequently re-examines threats, exposures, and vulnerabilities to assess changes to system architecture and design. The Contractor shall, as appropriate, recommend changes to cybersecurity controls for the system. The Contractor shall ensure that no documentation conflicts with the program’s cybersecurity strategy and the SSP. (CDRL A021)

5. Quality:

5.1. Quality Control (QC):

5.1.1. The Contractor shall develop a Quality Control Program (QCP) to ensure services are performed IAQ this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor’s QCP must comply with the PWS requirements. The QCP shall be delivered Not Later Than (NTL) 30 calendar days after contract award. Any changes to the QCP shall be submitted to the Procurement Contracting Officer (PCO) within five business days when changes are made after the initial proposal. After acceptance of the QCP, the Contractor shall receive the PCO’s acceptance in writing of any proposed change to his quality control system. Once the QCP is accepted, the QCP shall be implemented NLT 30 calendar days after acceptance. (CDRL A005)

5.1.2. The government shall evaluate the Contractor’s performance IAQ the Quality Assurance Surveillance Plan (QASP). The plan defines how the performance standards shall be applied, the frequency of surveillance, and the minimum acceptable defect rate(s). The Contractor shall develop and maintain a Quality Plan, IAQ Contractor Quality Control, (CDRL A006), to ensure services are performed IAQ commonly accepted OEM practices, Commercial Standards if Third Party is selected, and PWS requirements. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of incomplete maintenance services and provide within 60 calendar days after the contract is awarded. As a minimum, the Contractor shall develop a QC plan that addresses the areas identified in the PWS. The CRC Program Manager shall be the Government liaison in the event of field user complaints.

(CDRL A006)

5.2 Contracting Office Representative (COR): The COR shall be identified in a separate letter. The COR monitors aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: ensure the Contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the Contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor Contractor's performance and notify both the PCO and Contractor of any deficiencies; and coordinate availability of Government furnished property. A letter of designation issued to the COR, a copy of which shall be sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the task order/contract.

5.3. Identification of Contractor Employees: All contract personnel attending meetings, and working in environments, where contractor status is not obvious to third parties are required to identify themselves as such, to avoid the impression they are Government officials. Contract personnel must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. Contractor personnel may be required to obtain and wear identification badges, or other identifying attire, in the performance of this service.

6. Contractor, Freight, and Travel/Transportation:

6.1. Travel Regulations: The Contractor personnel shall comply with all regulations for travel including, but not limited to, compliance with the Department of Defense (DoD) Foreign Clearance Guide (FCG) for travel overseas. The FCG may be accessed at: https://www.fcg.pentagon.mil/. Contractor shall be responsible for submitting all required entries in the various systems including but not limited to, the Travel Tracker (https://iatp.pacom.mil) and the Aircraft and Personnel Automated Clearance System (APACS) (https://apacs.dtic.mil). Instructions can be found within the FCG website.

6.2. Travel and Other Direct Costs:

6.2.1. Travel in support of this effort must be pre-approved by the Contracting Officer Representative (COR) by email. The Contractor shall have Defense Base Act (DBA) coverage for all work performed outside the United States prior to travel start, which will be considered an Other Direct Costs (ODC) and reimbursable to the Contractor. Travel is billed in accordance with Uniformed Travel Determination (UTD)/Civilian Travel Determination (CTD) – revised JTR 01 Jan 2024.

6.2.2. If any United States Government approved ODC is Contractor Acquired Property (CAP), the purchase of CAP shall comply with all appropriate clauses and provide the Administrating Contracting Officer (ACO) requisitioned information and any other information that the ACO requires to issue a contract modification properly identifying the CAP. (CDRL A022)

6.3. Travel:

6.3.1. Conus Travel:

6.3.1.1. CONUS location travel costs shall be IAW the Federal Acquisition Regulation (FAR) 31.205-46.

The Contractor shall minimize Government expense by consolidating Preventative Maintenance services at sites located in the same geographic area, whenever possible. Contractor shall provide a deliverable stating travel costs for each travel effort and identified CONUS locations. This deliverable shall report all travel hours and expenses to include, at minimum, airfare, rental cars, any additional transportation costs, taxes, fees, and lodging to be incurred (while traveling). (CDRL A016)

6.3.1.2. Travel Justification:

Travel must be essential to the performance of the contract and cannot be accomplished through remote communication methods. A written justification must be provided, detailing the purpose of the trip and its relevance to the contract objectives.

• Advance Notice: Travel requests must be submitted at least 30 days in advance of the planned travel dates, unless there are extenuating circumstances that require shorter notice.

• Cost Estimates: Travel requests must include a detailed cost estimate, covering transportation, lodging, meals, and incidental expenses.

• Contractors should use government per diem rates for lodging and meals as a guideline.

• Approval Authority:

• Travel requests must be approved by the contracting officer or designated representative before any travel arrangements are made.

• Documentation and Reporting:

• Contractors must submit a travel report within 10 days of completing the trip, including a summary of activities, outcomes

6.3.2. OCONUS Travel: Overseas and identified OCONUS location travel costs shall be IAW the Federal Acquisition Regulation (FAR) 31.205-46. The Contractor shall minimize Government expense by consolidating Preventative Maintenance services at sites located in the same geographic area, whenever possible. Contractor shall provide a deliverable stating travel costs for each travel effort overseas and identified OCONUS locations. This deliverable shall report all travel hours and expenses to include, at minimum, airfare, rental cars, any additional transportation costs, taxes, fees, and lodging to be incurred (while traveling).

6.4. Parts, Material and Supplies Delivery: Parts, materials, and supplies shall be properly packaged to foster an undamaged delivery. Contractor shall coordinate with the site POC for delivery at a mutually agreed time.

6.5. Freight Charges:

6.5.1. Contractor shall be responsible for freight/delivery charges completed under this contract unless special circumstances are identified by the CRC Program Manager and/or PCO. This includes the use of DoD Transportation Protective Services approved carrier(s) where required. Tracking and shipping numbers shall be provided to the CRC PMO through e-mail for each transaction. This service is invoiced under the Other Direct Costs (ODC).

6.5.2. Special Freight: The U.S. Government has certain missions that require special freight handling, packaging, and delivery requirements for the interests of national security. These requirements may dictate, but are not limited to constant U.S. control, special freight channels/contractors, freight packaging and sealing, freight tracking and escorting. These sites and requirements shall be identified to the Contractor by mission and task order level. Special freight handling/shipping requirements shall be billed Firm Fixed Price (FFP) billed against (CLIN 0006) for these specially identified.

7. Contractor Responsibility

7.1. SharePoint Database with Reporting: The Contractor shall establish (within 180 days of contract award), maintain, and provide access to an internet enabled SharePoint accessible by CRC Program Managers. This database shall include, but not be limited to: FMR POC information for both the site and technician, FMR’s, Spares Inventory Listing, Time Compliance Technical Order (TCTO), Request for Deviation (RFD), CDRL’s, Updated Schedule, Trip Reports, End of Day Reports, Meeting Materials, Trend Analyses, all PM reports, and documentation relating to the TYQ23A/TSC-250 task orders. The Contractor shall permit Government “read only” access to the data contained in the Contractor’s internet enabled SharePoint 24 hours a day, 365 days a year.

7.2. Records/Data: The USG will retain unlimited data rights to all data/material developed under this effort. Data requirements and deliverables are identified in Section 18 (Monthly Technical Status, Monthly Financial Status, Travel Authorization Request (TAR), and Trip Reports).

7.3. Program Management Review (PMRs), Technical Interchange Meeting (TIMs), Staff Assistance Visits:

7.3.1. The Contractor shall participate in Technical Interchange Meetings, Staff Assistance Visits and semi-annual PMRs, with the Government at a mutually agreed location, time, which shall be coordinated through CRC PMO. PMR’s may be held at contractor’s location or a mutually agreed location at the discretion of the CRC Office. The government reserves the right to hold or cancel PMR’s, TIM’s, and Staff Assistance Visits (SAVs). During the reviews the Contractor shall address all issues/concerns with the program. The

Contractor shall develop agendas for the reviews and include topics requested from the government. The topics shall be reviewed and approved by CRC prior.

7.3.2. The Contractor shall also record minutes of reviews and meetings and place documents in SharePoint Database IAW Section 7.1. The Contractor shall provide the minutes within 3 business days after the conclusion of the event. The Contractor shall provide an advance electronic copy of all PMR slides, 5 business days prior to scheduled meeting, to CRC Program Managers. (CDRL A013).

7.4 CDRL Listing:

A001 Technical Status Report DI-MGMT-80368A A002 Financial Status Report DI-MGMT-80368A A003 Trip Report DI-MGMT-80368A A004 Spares Status Report DI-MGMT-80368A A005 Quality Control Program DI-QCIC-81794A A006 Quality Plan DI-QCIC-81794A A007 Workers Health and Safety DI-SAFT-81563 A008 Government Furnished Property DI-MGMT-81893 A011 Field Maintenance Report DI-MGMT-80368A A012 Weekly Conference Call DI-ADMN-81249C/T A013 Program Management Reviews PMRs DI-ADMN-81249C/T A014 Government Property Damage DI-MGMT-82188 A015 Technical Refresh Plan DI-MISC-80508B A016 Trip Authorization Request DI-MISC-80508B A017 Key Personnel DI-MGMT-80368A A018 Failure Summary DI-SESS-80255B A019 Transition Plan DI-SESS-82299 A020 Diminishing Manufacturing Sources and Material DI-MGMT-81899 A021 DoD Risk Management Framework (RMF) Deliverables DI-MGMT-82001A A022 Contractor Acquired Property Report DI-MGMT-80441D A023 Test Plan DI-NDTI-80566A A024 Test Procedures DI-NDTI-80603A A025 Test Report DI-NDTI-80809B A026 50/50 Reporting DI-MGMT-81749B/T A027 Engineering Change Proposals (ECPs) DI-SESS-80639E A029 Engineering Design Data DI-SESS-81000F A030 Technical Order Change Pages DI-TMSS-81723 A031 Design Review Information Package DI-SESS-81757A A033 Request for Variance (RFV) DI-SESS-80640E A034 Specification Change Notices (SCN) DI-SESS-80643E A035 Model Based Systems Engineering DI-SESS-82380 & DI-SESS-82400 A036 Configuration Audit Plans DI-SESS-81646C A037 Configuration Audit Reports DI-SESS-81646C A038 Interface Control Document DI-SESS-81248B

8. Government Furnished Property, Equipment, and Services

8.1. Services: The Contractor shall manage and maintain all Government Furnished Property (GFP), including Government Furnished Information (GFI), Government Furnished Equipment (GFE), and Government Furnished Material (GFM), in its possession in accordance with FAR Part 45. The Contractor shall have sufficient space, with a minimum of 6,200 square feet, to manage the warehousing and receiving of GFP.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .