36C10B23Q0357 Amendment 0001.docx

DOCX document 337 KB Posted

Attached to
R499--EXPENDABLE DATA CLEANSING (VA-23-00068621) Federal contract opportunity
Solicitation number
36C10B23Q0357
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This is a performance work statement for an expendable data cleansing project for the Department of Veterans Affairs. The contractor will provide four phases of services including automated data enhancement, integration and support, proof of concept testing in a simulated VA environment, and optional implementation planning. Phase one involves receiving VA medical supply data and integrating it into a data cleansing solution, then outputting the results to a non-production VA system. Phase two is proof of concept testing in VA's SimLearn simulation center. Optional tasks include phase three monitoring at a VA warehouse or medical center, and phase four development of an enterprise implementation plan. The base period of performance is 12 months with optional tasks extending up to 6 months. The solicitation response deadline is September 21, 2023.

View the file

Other files for this federal contract opportunity

Other files attached to R499--EXPENDABLE DATA CLEANSING (VA-23-00068621), newest first.
File Type Posted
36C10B23Q0357 0001.docx DOCX document
Attachment A - Schedule of Deliverables.docx DOCX document
36C10B23Q0357.docx DOCX document
36C10B23Q0357_2.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C10B23Q0357

PAGE 1 OF

1. REQUISITION NO.

2. CONTRACT NO.

3. AWARD/EFFECTIVE DATE

4. ORDER NO.

5. SOLICITATION NUMBER

6. SOLICITATION ISSUE DATE

a. NAME

b. TELEPHONE NO. (No Collect Calls)

8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY

CODE

10. THIS ACQUISITION IS

UNRESTRICTED OR

SET ASIDE:

% FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ

IFB

RFP

15. DELIVER TO

CODE

16. ADMINISTERED BY

CODE

17a. CONTRACTOR/OFFEROR

CODE

FACILITY CODE

18a. PAYMENT WILL BE MADE BY

CODE

TELEPHONE NO.

UEI:

EFT:

PHONE:

FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19.

20.

21.

22.

23.

24.

ITEM NO.

SCHEDULE OF SUPPLIES/SERVICES

QUANTITY

UNIT

UNIT PRICE

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________

29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

(REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

09-15-2023 Joshua Fitzmaurice 848-377-5122 09-21-2023 15:00

EDT

36C10B Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

X

518210 $40 Million

N/A

See Delivery Schedule

36C10B Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

36C10A Department of Veterans Affairs Technology Acquisition Center Financial Services Center PO Box 149971 Austin TX 78714-8971

See CONTINUATION Page

Expendable Data Cleansing Request for Quote (RFQ).

Points of Contact:

Contracting Officer Wendy Minch Wendy.Minch@va.gov

Contract Specialist Joshua Fitzmaurice Joshua.Fitzmaurice@va.gov

See CONTINUATION Page

Wendy Minch

Table of Contents

SECTION B - CONTINUATION OF SF 1449 BLOCKS4
B.1 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:4
B.2 GOVERNING LAW CLAUSE7
B.3 CONTRACT ADMINISTRATION DATA8
B.4 PRICE SCHEDULE9
B.5 PERFORMANCE WORK STATEMENT12
SECTION C - CONTRACT CLAUSES44
C.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)44
C.2 52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION SYSTEMS (NOV 2021)44
C.3 52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)46
C.4 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (SEP 2023)48
C.5 52.217-7 OPTION FOR INCREASED QUANTITY—SEPARATELY PRICED LINE ITEM (MAR 1989)53
C.6 VAAR 852.201-70 CONTRACTING OFFICER’S REPRESENTATIVE (DEC 2022)53
C.7 VAAR 852.219-70 VA SMALL BUSINESS SUBCONTRACTING PLAN MINIMUM REQUIREMENTS (NOV 2022)53
C.8 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV 2018)54
C.9 VAAR 852.239-76 Information and Communication Technology Accessibility (FEB 2023)55
SECTION D – CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS57
SECTION E – SOLICITATION PROVISIONS58
E.1 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)58
E.2 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)58
E.3 52.204-26 COVERED TELECOMMUNICATIONS EQUIPMENT OR SERVICES—REPRESENTATION (OCT 2020)61
E.4 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018)62
E.5 52.212-1 ADDENDUM to FAR 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL ITEMS63
E.6 52.212-2 Evaluation—Commercial Products and Commercial Services (Nov 2021)67
E.7 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (SEP 2023)68
E.8 52.216-1 TYPE OF CONTRACT (APR 1984)85
E.9 52.233-2 SERVICE OF PROTEST (SEP 2006)85
E.10 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (OCT 2018)86

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:

(1). Definitions.

a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”

b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.

c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.

e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

(2). Software License.

a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.

b) The Government may use the software in a networked environment.

c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).

d) All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.

(3). Software Maintenance and Technical Support.

a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.

b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.

c) Any telephone support provided by Contractor shall be at no additional cost.

d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.cpars.gov).

e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

(4). Disabling Software Code. The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

(5). Manuals and Publications. Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.

B.2 GOVERNING LAW CLAUSE

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.3 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR: TBD

b. GOVERNMENT:Contracting Officer 36C10B
Department of Veterans Affairs
Technology Acquisition Center
23 Christopher Way
Eatontown NJ 07724

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X]
52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[]
52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly[]
b. Semi-Annually[]
c. Other[X] In accordance with B.4 Price Schedule

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

5. ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE
36C10B23Q0357 0001 – Extension of Closing date for RFQ and minor administrative changes highlighted in yellow. SF1449, Pgs. 64, 65, & 67.
9/19/2023

B.4 PRICE SCHEDULE

ITEM NUMBER
DESCRIPTION OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
1.00
LO
______________
________________

PHASE ONE- THE AUTOMATED DATA ENHANCEMENT SOLUTION. (In Accordance with (IAW) Section 5.4 of the Performance Work Statement (PWS).

This Firm Fixed Price (FFP) Contract Line Item Number (CLIN) includes all Program Management tasks IAW Section 5.1, labor, materials, travel and deliverables required for the successful completion of the services detailed in the PWS).

PSC R499

Contract Period: Base 12 Months POP Begin:

POP End:

1.00
LO
______________
________________

PHASE ONE -INTEGRATION AND INTEGRATION SUPPORT

(IAW Section 5.3 of the PWS. This FFP CLIN includes all integration detailed in the PWS).

IT Funding Item

PSC DD01

Contract Period: Base 12 Months

1.00
LO
______________
________________

PHASE TWO – PROOF OF CONCEPT TEST IN VA SIMULATED ENVIRONMENT (IAW Section 5.5 of the PWS. FFP CLIN includes all Program Management tasks IAW Section 5.1, labor, materials, travel and deliverables required for the successful completion of the services detailed in the PWS).

PSC R499

Contract Period: Base 12 Months

1.00
LO
______________
________________

PHASE TWO-INTEGRATION AND INTEGRATION SUPPORT

(IAW Section 5.3 of the PWS. This FFP CLIN includes all includes all integration detailed in the PWS).

IT Funding Item

PSC DD01

Contract Period: Base 12 Months

OPTIONAL TASK 1- This optional task may be exercised IAW FAR 52.217-7 Option for Increase Quantity – Separately Priced Line Item (MAR 1989). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

1.00
LO
______________
________________

PHASE THREE – ELECTRONIC DATA INTERCHANGE MONITORING AT A VA WAREHOUSE AND/OR VA MEDICAL CENTER (OPTIONAL TASK 1) (IAW Section 5.6 of the PWS. This FFP CLIN includes all Program Management tasks IAW Section 5.1, labor, materials, travel and deliverables required for the successful completion of the services detailed in the PWS).

Contract Period: PoP is 6 Months within the Base 12 Months

1.00
LO
______________
________________

PHASE THREE- INTEGRATION AND INTEGRATION SUPPORT (OPTIONAL TASK 1) (IAW Section 5.3 of the PWS. This FFP CLIN includes all integration detailed in the PWS).

IT Funding Item

PSC DD01

Contract Period: PoP is 6 Months within the Base 12 Months

OPTIONAL TASK 2 - This optional task may be exercised IAW FAR 52.217-7 Option for Increase Quantity – Separately Priced Line Item (MAR 1989). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

1.00
LO
______________
________________

PHASE FOUR – IMPLEMENTATION PLAN (OPTIONAL TASK 2) (IAW Section 5.7 of the PWS. This FFP CLIN includes all Program Management tasks IAW Section 5.1, labor, materials, travel and deliverables required for the successful completion of the services detailed in the PWS).

Contract Period: PoP is 3 Months within the Base 12 Months

0008
CONTRACT DELIVERABLES

IAW PWS and Attachment A Contract Deliverables are not separately priced

NSP

BASE REQUIREMENT

SUB TOTAL

GRAND TOTAL(To include Optional Tasks)
________________

B.5 PERFORMANCE WORK STATEMENT

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

VA Logistics Redesign (VALOR) / Enterprise Supply Chain Modernization (ESCM) Policies and Processes Division

Expendable Data Cleansing

Date: 08/23/2023

VA-23-00068621

PWS Version Number: Version 2

Page 1 of

1.0 BACKGROUND

The Office of Veterans Affairs Logistics Redesign (VALOR) is responsible for enterprise level program management for the Department of Veterans Affairs (VA) health care logistics and medical support services management solution and comprehensive efforts in modernizing VA’s supply chain.

VA, through the Veterans Health Administration (VHA) operation of 171 VA Medical Centers (VAMC), integrated outpatient clinics, 772 Community Based Outpatient Clinics (CBOC), and 134 VA Nursing Homes, operates a complex, dynamic medical supply chain across multiple facility types and geographies within VA-specific regulations and policies. The scale of the VA’s operations, the complexity of its supply chain and the fluidity of its IT environment involves a myriad of expendable medical/surgical supply agreements and contract vehicles with thousands of vendors, and diverse commercial-off-the-shelf (COTS) and in-house systems such as Enterprise Resource Planning (ERP), Electronic Health Record (EHR) and other deployed information technology in on-premises and cloud environments.

VA must have the ability to take millions of supply items, that are purchased and will be purchased through contracts and blanket purchase agreements to do the following: 1) cleanse, enrich and match this raw data to the majority of U.S. acute care facilities to mirror industry standards, 2) take in this standardize data into the VA Common Operating Platform automatically on a daily basis; and 3) channel standardize data into a VA Master Supply Catalog on a daily basis for use in VA systems of record; this will allow VA to order, receive, maintain, pay, issue, and turn-in consumable supply items efficiently.

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this PWS, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”

4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004

5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

9. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm

12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm

13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5, 2019

14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017

15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”

17. National Institute of Standards and Technology (NIST) SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021

21. VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021

22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019

23. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010

24. VA Handbook 6500.6, “Contract Security,” March 12, 2010

25. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011

26. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018

27. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

28. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

29. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

30. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

31. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

32. VA Handbook 6510, “VA Identity and Access Management,” January 15, 2016

33. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017

34. VA Directive 6300, “Records and Information Management,” September 21, 2018

35. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010

36. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

37. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

38. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015

39. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014

40. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

41. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

42. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

43. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)

44. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018

45. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020

46. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

47. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile Devices (Draft),” October 2012

48. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981, “Mobile, PIV, and Authentication,” March 2014

49. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

50. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

51. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

52. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

53. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

54. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

55. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

56. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

57. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018

58. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

59. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013

60. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013

61. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

62. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

63. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

64. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

65. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

66. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

67. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),” November 19, 2020

68. Social Security Number (SSN) Fraud Prevention Act of 2017

69. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018

3.0 SCOPE OF WORK

For the Expendable Data Cleansing effort, the Contractor shall provide a proof-of-concept consumable medical supply catalog test in simulated and non-production environments that is organized into four phases. In Phase 1, the Contractor shall receive or integrate publicly available, VA consumable medical/surgical supply item master file data schemas from a VA-server into a data enhancement Software as a Service (SaaS) solution; then take this data and integrate the cleansed data schema outputs into a non-production VA Common Operating Platform (COP). Phase 1 success is defined by automatic daily updates, in a non-production environment, from the VA server to the SaaS solution to the VA COP. In Phase 2, the Contractor shall support a proof-of-concept test in the VA SimLearn Center in Orlando, Florida, which is a non-production environment. This test shall take the resulting Phase 1 master catalog data and then simulate a VA purchase order facility (non-production) using VistA systems. Phase 2 success is defined by VistA orders, receipts and payments through the simulated Electronic Data Interchange (EDI). Optional task for Phase 3, is the continuation of successful phase 1 & phase 2 processes, but in a VA warehouse or medical center (non-production environment). In this phase, the Contractor shall assist the Government with the simulation process at the VA warehouse or medical center (non-production environment). Phase 3 success is defined by a limited series of nonproduction purchase orders being received, paid for, and physically held in non-production for disposition instructions. In an optional task for Phase 4, the Contractor shall provide VA with a plan for the phased implementation of all proven concepts in phases 1, 2 and 3 throughout the enterprise. Phase 4 success is defined by the delivery of the plan in the form of a white paper to inform VA leadership. The Contractor shall provide integration and integration support to Phases 1 through 3 for the test events.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The Period of Performance shall be 12 months from date of award. All tasks at 5.0 through 5.1 and all sub-paragraphs shall be performed in the base and optional tasks, if exercised. Optional tasks can be exercised once within the 12-month base period and Optional Task 1 shall have a period of performance of 6 months and Optional Task 2 shall have a period of performance of 3 months from date of option exercise, if exercised.

Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer).

There are 11 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's DayJanuary 1
JuneteenthJune 19
Independence DayJuly 4
Veterans DayNovember 11
Christmas DayDecember 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's BirthdayThird Monday in January
Washington's BirthdayThird Monday in February
Memorial DayLast Monday in May
Labor DayFirst Monday in September
Columbus DaySecond Monday in October
ThanksgivingFourth Thursday in November

4.2 PLACE OF PERFORMANCE

Tasks under this PWS shall be performed at VA Central Office, Washington, D.C., in VA facilities located in Orlando, Florida, and Denver, Colorado, or a VA facility location within the contiguous 48 United States. Work may be performed virtually and at remote locations with prior concurrence from the Contracting Officer’s Representative (COR).

Tasks under this PWS performed at the Contractor’s facilities shall be identified in the Contractor’s place of performance in their proposal submission.

4.3 TRAVEL

The Government anticipates travel under this effort to perform the tasks associated with the effort, as well as to attend program-related meetings or conferences throughout the PoP. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.

The total estimated number of trips in support of the program related meetings for this effort is eight trips. Anticipated locations include the following, estimated at three days in duration:

1. VA Central Office (VACO), Washington D.C. – Two trips

1. SimLearn Center, Orlando, Florida – Two trips

1. VA facility location TBD within the contiguous 48 United States – Two trips (Optional Task 1)

Travel shall be in accordance with the Federal Travel Regulations and requires advanced concurrence by the COR. Contractor travel within the local commuting area will not be reimbursed.

5.0 SPECIFIC TASKS AND DELIVERABLE

5.1 PROJECT MANAGEMENT

5.1.1 PROJECT MANAGEMENT PLAN

The Contractor shall provide a Project Management Plan (PMP) that details the Contractor’s approach, timeline, and tools to be used in execution of the contract. The PMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks, and resource support. The PMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline PMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA PM approved PMP throughout the PoP.

Deliverable:

A. Project Management Plan

5.1.2 REPORTING REQUIREMENTS

The Contractor shall provide the Contracting Officer Representative (COR) with weekly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding week.

The weekly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Information and Communication Technology (ICT) deliverables and their current Section 508 conformance status. The Contractor shall monitor performance against the PMP and report any deviations. The weekly progress report shall also include updates to the project timeline, action items, updates to action items, flag overdue actions/tasks, and updates to risks and risk remediation actions. It is expected that the Contractor will keep in communication with VA accordingly to ensure alignment between VA and the Contractor so that issues that arise are transparent to both parties to prevent escalation of outstanding issues. Should issues arise, the Contractor shall communicate with the COR to report any potential/known deviation.

Deliverables:

A. Weekly Progress Report

5.1.3 TECHNICAL KICKOFF MEETING

The Contractor shall conduct a technical kickoff meeting within 10 calendar days after contract award. The Contractor shall coordinate the agenda, participants, date, time, and location (can be virtual) with the COR. The Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, risks, and project schedule. The Contractor shall provide the final agenda and technical kickoff presentation to all attendees at least three calendar days prior to the meeting. At the conclusion of the meeting, the Contractor shall update the presentation with a final slide entitled “Summary Report” which shall include notes on any major issues, agreements, or disagreements discussed during the kickoff meeting. The Contractor shall provide meeting minutes and final presentation to all attendees within 10 calendar days after the meeting.

Deliverables:

A. Technical Kickoff Meeting Agenda and Presentation B. Technical Kickoff Meeting Minutes and Final Presentation

5.1.4 INTEGRATED WORKING GROUP MEETINGS

The Contractor shall participate throughout the PoP in the Integrated Working Group (IWG) for the Expendable Data Cleansing in Simulated and Non-Production Environments.

5.2 AUTOMATED DATA ENHANCEMENT PRODUCT

The Contractor shall use its brand name Global Healthcare Exchange SaaS solution or equivalent for automated data enhancement that meets the following salient characteristics. The solution shall be:

1. Completely automated SaaS product and services, regardless of a Source of Supply’s integration capabilities

2. Capable of tracking Electronic Data Interchange (EDI) transmissions for VA purchase orders.

3. 85% or greater involvement with expendable medical supply data cleansing and matching to industry standards for U.S. Acute Care Hospitals.

4. Capable of providing a filter before Purchase Ordering that eliminates the possibility of VA ordering a medical supply item that is on recall, pending a Medical Material Quality Control action, not approved by U.S. Food and Drug Administration (FDA) manufactured, in a non-Trade Agreement Act country, or identified as inferior or unsafe by U.S. oversight agencies such as Joint commission or Occupational Safety and Health Administration (OSHA).

5. Capable of providing automation for integrated and non-integrated expendable medical supply manufacturers, distributors, and resellers.

6. The solution shall demonstrate equal capabilities in dealing with both integrated and non-integrated vendors and a clinical understanding of consumable medical/surgical supply items.

5.3 INTEGRATION AND INTEGRATION SUPPORT

The contractor shall provide integration and integration support across phases 1, 2, and 3 (phase 3 is an optional task). The phase descriptions are identified in the subsequent paragraphs below.

5.4 Phase ONE- Integration of the AUTOMATED data enhancement solution

1. The Contractor shall integrate this automated data enhancement solution into a non-production VA technical environment and data architecture using the following steps identified below.

2. Step 1: The Contractor shall receive or integrate publicly available, VA consumable medical/surgical supply item master file data schemas from the Strategic Technical Evaluation Program (STEP) established by VHA Office of Procurement into a data enhancement Software as a Service (SaaS) solution.

2. Step 2: Cleanse and enrich the item master files to match with 85% or more of the acute care hospital catalog files in the United States.

2. Step 3: Send or integrate the SaaS solution cleansed data schema outputs into a non-production VA Common Operating Platform (COP).

2. The definition of success for this first phase is when the following requirements are satisfied by the Contractor:

a. The Contractor is prepared to automatically receive (either through a push or pull relationship) publicly available consumable medical supply data schemas every 24 hours from a VA hosting server or cloud environment for the purpose of cleansing, enriching, and matching them to the contractor’s global catalog which mirrors item master files for 85% or more of acute care hospitals in the United States;

b. Static file exchanges from VA servers or cloud environments are approved by VA Office of Information and Technology (OIT) in preparation for automated exchanges;

c. The Contractor is prepared to automatically send (either through a push or pull relationship) cleansed, enriched, and matched item master files every 24 hours into a VA Common Operating Platform non-production data lake where the files are harmonized with VA Enterprise and Veteran Information Models;

d. Report as needed daily changes made to supply and equipment item master files from VA or other Federal Agency acquisition raw data after cleansing, enriching, and matching to 85% or greater of U.S. acute care hospitals.

3. The Contractor shall assist the Government in developing a technical architecture and acquisition data pipeline using existing tools within VA and commercial industry to support consumable medical supply spend and other transactional evaluation across VA. The Contractor shall deliver a Solution Architecture and Technical Specifications.

Deliverables:

A. Solution Architecture B. Technical Specifications

5.5 PHASE TWO – proof of concept test in VA Simulated environment The Contractor shall support a proof-of-concept test in a simulated VA environment (currently VA SimLearn Center in Orlando, Florida) to use the resulting Phase 1 catalog, simulate the Electronic Data Interchange (EDI) exchange, and smooth invoicing between suppliers and VA. The Contractor shall support proof of concept testing in the simulated environment to designate resources, utilize VA interfaces to collect, pull, and push data on medical supplies, deliver a test plan, and document test results at the completion of Phase 2. The Contractor shall update the solution architecture and technical specifications for this phase.

Deliverables:

A. Solution Architecture Update – Simulated Environment B. Test Plan – Simulated Environment C. Technical Specifications Update - Simulated Environment D. Test Results – Simulated Environment

5.6 PHASE THREE – Electronic data interchange monitoring at a VA warehouse and/OR VA MEdical center (optional task 1)

If exercised, task 5.2 and all sub-paragraphs shall apply to Phase Three. In Phase 3, the Contractor shall continue successful processes under Phase 1 & Phase 2 at a VA warehouse or medical center (non-production). The contractor shall monitor and assist with a limited series of non-production purchase orders. The Contractor shall support EDI monitoring to smooth VA exchanges between integrated and non-integrated vendors. The Contractor shall provide a readiness review, training plan, materials prior to testing, installation, set-up, training, and troubleshooting support for the test of the integrated automated data enhancement. The Contractor shall coordinate testing with the Government Project Manager and designated resources, deliver a test plan, and document test results at the completion of Phase 3. The Contractor shall provide a document for Project Leader and Business Owner requirements, recommended process changes and lessons learned after the live test is completed. The Contractor shall assist with updating the solution architecture and technical specifications for this phase as follows:

a.Monitor and assist with Master Supply Catalog updates to an authorized ordering and fulfilment system to ensure the system of record’s Item Master Files reflect the GHX or like product global catalog.
b.Monitor and assist with Integrated Financial and Acquisition Management System transactions to help smooth payment discrepancies.
c.Monitor and assist with Financial Services Center (FSC) vendor payments.

Deliverables:

A. Solution Architecture Update – Non-Production Environment Test B. Non-Production Environment Test Plan C. Technical Specifications Update – Non-Production Environment Test D. Document Project Leader and Business Owner Requirements E. Training Plan and Materials F. Non-Production Environment Test Results G. Recommended Process Changes H. Lessons Learned

5.7 Phase four – implementation plan (optional task 2)

If exercised, and Phase Three has been exercised and completed, the Contractor shall provide VA with a plan for the phased implementation of all proven concepts in phases 1, 2 and 3 throughout the enterprise in VA warehouse and medical center production environments. The phased implementation plan shall be provided in a white paper format.

Deliverables:

A. Implementation Plan

6.0 GENERAL REQUIREMENTS

6.1 ENTERPRISE AND IT FRAMEWORK

6.1.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion-based authentication, and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19-17 can be found at: https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-24.pdf, and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and can use enterprise provisioning service.

2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

6.1.4 TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents).

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .