36C10X21R0001-amendment 1.docx
DOCX document 199 KB Posted
- Attached to
- FAC-C-DS Federal contract opportunity
- Solicitation number
- 36C10X21R0001
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Q A Amendment 1.docx | DOCX document | |
| 36C10X21R0001-amendment 1.docx | DOCX document | |
| Atch2 IDIQ Pricing Amendment 1.docx | DOCX document | |
| Atch 1 TO PWS.docx | DOCX document | |
| Atch2 IDIQ Pricing.docx | DOCX document | |
| Atch3 TO Pricing.docx | DOCX document | |
| 36C10X21R0001 Final.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
36C10X21R0001
1. REQUISITION NO.
2. CONTRACT NO.
3. AWARD/EFFECTIVE DATE
4. ORDER NO.
5. SOLICITATION NUMBER
6. SOLICITATION ISSUE DATE
a. NAME
b. TELEPHONE NO. (No Collect Calls)
8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY
CODE
10. THIS ACQUISITION IS
UNRESTRICTED OR
SET ASIDE:
% FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ
IFB
RFP
15. DELIVER TO
CODE
16. ADMINISTERED BY
CODE
17a. CONTRACTOR/OFFEROR
CODE
FACILITY CODE
18a. PAYMENT WILL BE MADE BY
CODE
TELEPHONE NO.
DUNS:
DUNS+4:
PHONE:
FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19.
20.
21.
22.
23.
24.
ITEM NO.
SCHEDULE OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA
26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA
ARE
ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
ARE
ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________
29. AWARD OF CONTRACT: REF. ___________________________________ OFFER
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
DATED ________________________________. YOUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
(REV. 2/2012)
PREVIOUS EDITION IS NOT USABLE
Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
36C10X21R0001 10-15-2020 Justin Cole 240.215.1751 10-28-2020
2 PM
36C10X Strategic Acquisition Center - Frederick Department of Veterans Affairs
5202 Presidents Court, Suite 103 Frederick MD 21703
X
611430 $12 Million
N/A
36C10X Strategic Acquisition Center - Frederick Department of Veterans Affairs
5202 Presidents Court, Suite 103 Frederick MD 21703
VAFSC
U.S. Department of Veterans Affairs Financial Services Center
PO BOX 149971
(see Section B.3 invoicing/payment) Austin TX 78714-8917 1-(877)-489-6135
See CONTINUATION Page FAC-C-DS Certifications
Period of Performance is from December 1, 2020 to November, 30
2025.
$0.00
See CONTINUATION Page x
Table of Contents
| SECTION A | 1 |
| A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS | 1 |
| SECTION B - CONTINUATION OF SF 1449 BLOCKS | 3 |
| B.1 CONTRACT ADMINISTRATION DATA | 3 |
| B.2 PERFORMANCE WORK STATEMENT | 4 |
| 8.2.1 FAC-C-DS TRAINING COURSE MATERIAL | 7 |
| 8.2.2 FAC-C-DS TRAINING SUPPORT | 7 |
| B.3 PRICE/COST SCHEDULE | 23 |
| ITEM INFORMATION | 23 |
| SECTION C - CONTRACT CLAUSES | 24 |
| C.1 SUPPLEMENTAL INSURANCE REQUIREMENTS | 24 |
| C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL ITEMS (JUN 2020) | 25 |
| C.3 52.216-18 ORDERING (OCT 1995) | 30 |
| C.4 52.216-19 ORDER LIMITATIONS (OCT 1995) | 30 |
| C.5 52.216-22 INDEFINITE QUANTITY (OCT 1995) | 30 |
| C.6 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999) | 31 |
| C.7 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000) | 31 |
| C.8 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998) | 31 |
| C.9 VAAR 852.219-75 SUBCONTRACTING COMMITMENTS MONITORING AND COMPLIANCE (JUL 2018) | 32 |
| C.10 VAAR 852.212-70 PROVISIONS AND CLAUSES APPLICABLE TO VA ACQUISITION OF COMMERCIAL ITEMS (APR 2020) | 32 |
| SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS | 34 |
| SECTION E - SOLICITATION PROVISIONS | 35 |
| E.1 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (DEC 2019) | 36 |
| E.2 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018) | 37 |
| E.3 52.212-2 EVALUATION—COMMERCIAL ITEMS (OCT 2014) | 38 |
| E.4 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL ITEMS (OCT 2018) | 39 |
| E.5 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL ITEMS (JUN 2020) | 42 |
| E.6 52.216-1 TYPE OF CONTRACT (APR 1984) | 54 |
| E.7 52.233-2 SERVICE OF PROTEST (SEP 2006) | 54 |
| E.8 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998) | 55 |
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR:
b. GOVERNMENT: Contracting Officer 36C10X Strategic Acquisition Center - Frederick Department of Veterans Affairs Roxana Cepeda 5202 Presidents Court, Suite 103 Frederick MD 21703
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
| [X] |
| 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or |
| [] |
| 52.232-36, Payment by Third Party |
3. INVOICES: Invoices shall be submitted in arrears:
| a. Quarterly | [] |
| b. Semi-Annually | [] |
| c. Other | [] |
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.
U.S. Department of Veterans Affairs Financial Services Center
PO BOX 149971
(see Section B.3 invoicing/payment) Austin TX 78714-8917 ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
| AMENDMENT NO |
| DATE |
B.2 PERFORMANCE WORK STATEMENT
Title: Technology Acquisition Center Federal Acquisition Certification in Contracting Core-Plus Specialization in Digital Services Training Program
1. BACKGROUND
The mission of the Department of Veterans Affairs (VA), Office of Procurement, Acquisition, and Logistics, Technology Acquisition Center (TAC) is to support our Nation’s Veterans by providing acquisition and logistics solutions for VA. In meeting these goals, TAC is responsible for preparing and executing quality contracts that support the Information Technology (IT) efforts and needs of its customers across VA, which enables our customers to provide best value solutions to Veterans and their families. TAC has a large population of General Schedule series 1102’s (GS-1102’s) that are responsible for these IT procurements, all of whom either have obtained Federal Acquisition Certification in Contracting (FAC-C) or are working toward obtaining FAC-C certification.
On May 18, 2018, the Office of Federal Procurement Policy (OFPP) launched the new digital services certification program (FAC-C-DS) with the goal of creating a digital IT acquisition professional (DITAP) community. This new specialization aligns with the President’s Management Agenda in the areas of modernizing the government’s IT, improving the efficiency and effectiveness of our services, and developing a 21st century workforce. A common component of these strategies is delivering data, information, and transactional services across multiple platforms to transform how citizens interact with their government. To develop this new generation of digital services, the workforce must learn and apply new skills. Buying digital services is not a skill that is gained through the FAC-C curriculum, thereby necessitating a specialized and immersive training and development program called the DITAP, which leads to the FAC-C-DS. This specialization meets an urgent need for digital services expertise and will be part of a larger effort to raise the overall competency of the acquisition workforce in acquiring IT solutions. In order to understand how to craft acquisitions to procure digital services, the TAC GS-1102 workforce has a need for the training required to obtain their FAC-C-DS certification.
2. SCOPE OF WORK
TAC requires the training necessary to obtain FAC-C-DS certification for its GS-1102 workforce. The Contractor shall provide all labor, materials, transportation, and other incidentals necessary to develop and provide the instructor guided education, in the area of FAC-C-DS described, focused on enhancing the skills and understanding, to a diverse GS-1102 workforce. Students shall get 80 Continuous Learning Points (CLPs) resulting from the training. The training program curriculum shall be validated by OFPP and U.S. Digital Service.
3. CONTRACT TYPE
The government anticipates the award of a firm-fixed price IDIQ contract with cost reimbursement for travel.
3.1 MINIMUM/MAXIMUM CONTRACT AMOUNT
The guaranteed minimum amount under this contract will be satisfied by either 1) the award of any singular task order contained in this solicitation or 2) the obligation of funds in the amount of $5,000. The maximum contract amount is $2,000,000.00 for the life of the contract. If the Government’s requirements for services set forth in the solicitation do not result in task orders in the amount described as the “maximum,” it shall not constitute the basis for an equitable adjustment under this contract.
4. PERIOD OF PERFORMANCE
The anticipated period of performance is for a period of 60 months (5) years.
Any work shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).
There are 10 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
| New Year's Day | January 1 | |
| Independence Day | July 4 | |
| Veterans Day | November 11 | |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January | ||
| Washington's Birthday | Third Monday in February | ||
| Memorial Day | Last Monday in May | ||
| Labor Day | First Monday in September | ||
| Columbus Day | Second Monday in October | ||
| Thanksgiving | Fourth Thursday in November |
5. PLACE OF PERFORMANCE
The tasks under this Performance Work Statement (PWS) shall be performed both virtually and face to face at the TAC offices in Eatontown, NJ, as discussed in Section 7 below.
6. DELIVERABLES
| Deliverable # |
| Title/Description |
| Due Date |
| Format |
| 11.2.1 |
| Contractor Staff Roster |
| Due business 3 days after contract award and updated throughout the Period of Performance on an annual basis or at the delivery of each task order. |
| Electronic |
* Curriculum based upon an open source learning management system, allowing students to interact, and featuring self-directed, guided, and applied learning, classroom instruction, case studies, guest speakers, and hands-on skills building through a live digital assignment structured similar to the following:
· Nine days of classroom instruction consisting of three separate, three-day face to face sessions*
· Fifteen hours of virtual instructor led training
· Twelve hours per week of asynchronous, self-paced material
For each cohort, curriculum provided shall include course detail outline, course pre-work, classroom materials, and course evaluations/feedback forms.
7. TRAVEL
The Government anticipates travel under this effort. Travel must be pre-approved in writing by the Contracting Officer’s Representative (COR) and in accordance with Federal Travel Regulations (FTR). Each Contractor invoice shall include copies of all receipts that support the travel costs claimed in the invoice. Local travel within a 50-mile radius from the contractor’s facility is considered the cost of doing business and will not be reimbursed. This includes travel, subsistence, and associated labor charges for travel time. Travel performed for personal convenience and daily travel to and from work at the Contractor’s facility will not be reimbursed. Travel, subsistence, and associated labor charges for travel time for travel beyond a 50-mile radius of the Contractor’s facility are authorized for reimbursement on a case-by-case basis and must be pre-approved by the COR and must be planned and executed according to Federal Travel Regulations. General and Administrative expenses will not be reimbursed.
The FTR can be referenced at:
http://www.gsa.gov/portal/ext/public/site/FTR/file/FTRTOC.html/category/21865/hostUri/portal
8. TASK STATEMENT
Tasks performed shall be of a non-personal nature. VA organizations will not provide supervision of Contractor personnel. Contractor personnel shall at no time allow an employer-employee relationship to develop with VA organizations or their staff. VA organizations will refrain from any activities that create the appearance of such a relationship.
Contractors shall not perform inherently governmental functions including decision-making, supervision of Government employees, supervision of other contractors on other contracts, and activities that create the appearance of performing such functions.
8.1 REPORTING REQUIREMENTS
The Contractor shall provide the COR with Monthly Progress Reports in electronic form in Microsoft Word or Microsoft Excel. The report shall include detailed instructions/explanations for each required task or data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Month.
The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The Contractor shall monitor performance against the previous month’s approved Monthly Progress Report and report any deviations. It is expected that the Contractor shall maintain communication with VA accordingly so that any arising issues are transparent to both parties to prevent escalation of outstanding issues.
8.2 FAC-C-DS CERTIFICATION COURSE
The Contractor shall provide the OFPP and U.S. Digital Service validated DITAP certification course for the TAC GS-1102 workforce.
The Contractor shall provide an immersive, six-month training program as required under DITAP in order for the TAC GS-1102 workforce to obtain their FAC-C-DS certification. The curriculum shall be based upon an open source learning management system, allowing students to interact, and shall feature self-directed, guided and applied learning, classroom instruction, case studies, guest speakers, and hands-on skills building through a live digital assignment, all of which the Contractor shall be responsible to provide.
This Contractor shall ensure each cohort is provided up to 25 students and lasting approximately 6 months. For each cohort, the Contractor shall provide a validated training program, consisting of, at a minimum, the following:
· Nine days of classroom instruction consisting of three separate, three-day face to face sessions*
· Fifteen hours of virtual instructor led training
· Twelve hours per week of asynchronous, self-paced material
· Participants receive up to 80 continuous learning points (CLPs)
The Contractor shall ensure the program incorporates the most current resources, tools, and best practices in digital service acquisition, including:
· Methods to acquire and monitor contracts for services such as human-centered design, Agile development methodology, DevSecOps, cloud, and X-as-a-service
· How to use and apply metrics and incentives appropriately
· Techniques to create a culture of innovation and lead customers to the best solutions
*The Contractor shall travel to the TAC office in Eatontown, NJ, in order to provide the face to face classroom instruction required for each of the cohorts. In the event of potential COVID-19 restrictions, the Contractor shall provide virtual classroom sessions in place of the required face-to-face classroom sessions.
8.2.1 FAC-C-DS TRAINING COURSE MATERIAL
The Contractor shall provide, for each participant in each cohort, a Training Material Set which includes hard copy and electronic copies of such items as course hand-outs, instruction manuals, briefing slides, group activities, lecture notes, case studies, application exercises, and group presentations. All material shall be provided to the training participants at the start of the training, except for video, audio or other software-based demonstration or exercise material which may not be available to provide.
8.2.2 FAC-C-DS TRAINING SUPPORT
The Contractor shall maintain course rosters for each cohort and record training completions, indicating attendance for each participant. The rosters shall include the cohort number, the names of all the employees in attendance, the dates training was conducted, and the course/class title. Employees will sign in at the beginning of the course day and again after any lunch break (if applicable). The Contractor shall annotate absent periods greater than one hour for any participant on the course roster.
The Contractor shall provide a Course Evaluation Form to be filled out by each participant and returned to the Contractor, for submission to the COR at the end of each cohort.
At the course completion, the Contractor shall report each student’s attendance into a Course Roster and Training Completion Record. The Contractor shall submit the record to the COR. The Contractor shall provide a Course Completion Certificate for each student with their name, dates of course (cohort), and number of CLPs to the VA COR.
9. OTHER DIRECT COSTS
Not Applicable
10. GOVERNMENT- FURNISHED EQUIPMENT/ MATERIALS/ FACILITIES/ INFORMATION
The Government will provide training space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.
The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact. The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.
11. SECURITY AND PRIVACY REQUIREMENTS
11.1 POSITION/TASK RISK DESIGNATION LEVEL(S)
| Position Sensitivity |
| Background Investigation (in accordance with Department of Veterans Affairs 0710 Handbook, “Personnel Suitability and Security Program,” Appendix A) |
| Low / Tier 1 |
| Tier 1 / National Agency Check with Written Inquiries (NACI) A Tier 1/NACI is conducted by Office of Personnel Management (OPM) and covers a 5-year period. It consists of a review of records contained in the OPM Security Investigations Index (SII) and the Department of Defense (DOD) Defense Central Investigations Index (DCII), Federal Bureau of Investigation (FBI) name check, FBI fingerprint check, and written inquiries to previous employers and references listed on the application for employment. In VA it is used for Non-sensitive or Low Risk positions. |
| Moderate / Tier 2 |
| Tier 2 / Moderate Background Investigation (MBI) A Tier 2/MBI is conducted by OPM and covers a 5-year period. It consists of a review of National Agency Check (NAC) records [OPM SII, DOD DCII), FBI name check, and a FBI fingerprint check], a credit report covering a period of five years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, law enforcement check; and a verification of the educational degree. |
| High / Tier 4 |
| Tier 4 / Background Investigation (BI) A Tier 4/BI is conducted by OPM and covers a 10-year period. It consists of a review of NAC records [OPM SII, DOD DCII, FBI name check, and a FBI fingerprint check report], a credit report covering a period of 10 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, spouse, neighbors, supervisor, co-workers; court records, law enforcement check, and a verification of the educational degree. |
In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity, and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:
Position Sensitivity and Background Investigation Requirements by Task
| Task Number |
| Tier1 / Low Risk |
| Tier 2 / Moderate Risk |
| Tier 4 / High Risk |
| 8.1 |
| |X| |
| |_| |
| |_| |
| 8.2 |
| |X| |
| |_| |
| |_| |
The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.
11.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
11.2.1 Contractor Responsibilities:
1. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak, and understand the English language.
A. Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the Proposed Action Letter template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 7 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within one day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with Federal Information Processing Standard (FIPS) 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.
1. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph D.4. below) when getting fingerprints taken.
C. The Contractor shall ensure the following required forms are submitted to the COR within five days after contract award:
1) Optional Form 306
2) Self-Certification of Continuous Service
3) VA Form 0710
4) Completed SIC Fingerprint Request Form
D. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents – Standard Form (SF)85, SF85P, or SF 86) utilizing the OPM Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the SIC.
E. The Contractor employee shall certify and release the e-QIP document, print, and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within three business days of receipt of the e-QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within three business days that documents were signed via e-QIP).
1. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.
1. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational Personal Identity Verification (PIV) credential for PIV only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of OPM.
1. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.
I. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.
J. Identity Credential Holders must follow all Homeland Security Presidential Directive-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with VA.
Deliverable:
A. Contractor Staff Roster
11.2.3 Physical Security and Safety Requirements
The Contractor and their personnel shall follow all VA policies, standard operating procedures, applicable laws, and regulations while on VA property. Violations of VA regulations and policies may result in citation and disciplinary measures for persons violating the law.
a. The Contractor and their personnel shall wear visible identification at all times while they are on the premises.
b. VA does not provide parking spaces at the work site; the Contractor must obtain parking at the work site if needed. It is the responsibility of the Contractor to park in the appropriate designated parking areas. VA will not invalidate or make reimbursement for parking violations of the Contractor under any conditions.
c. Smoking is prohibited inside/outside any building other than the designated smoking areas.
d. Possession of weapons is prohibited.
e. The Contractor shall obtain all necessary licenses and/or permits required to perform the work, with the exception of software licenses that need to be procured from a Contractor or vendor in accordance with the requirements document. The Contractor shall take all reasonable precautions necessary to protect persons and property from injury or damage during the performance of this contract.
11.2.4 Confidentiality and Non-Disclosure
0. The Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations.
0. The VA CO will be the sole authorized official to release in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this contract. The Contractor shall release no information. Any request for information relating to this contract presented to the Contractor shall be submitted to the VA CO for response.
0. Contractor personnel recognize that in the performance of this effort, Contractor personnel may receive or have access to sensitive information, including information provided on a proprietary basis by carriers, equipment manufacturers and other private or public entities. Contractor personnel agree to safeguard such information and use the information exclusively in the performance of this contract. Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations as enumerated in this section and elsewhere in this Contract and its subparts and appendices.
0. Contractor shall limit access to the minimum number of personnel necessary for contract performance for all information considered sensitive or proprietary in nature. If the Contractor is uncertain of the sensitivity of any information obtained during the performance this contract, the Contractor has a responsibility to ask the VA CO.
0. Contractor shall train all of their employees involved in the performance of this contract on their roles and responsibilities for proper handling and nondisclosure of sensitive VA or proprietary information. Contractor personnel shall not engage in any other action, venture or employment wherein sensitive information shall be used for the profit of any party other than those furnishing the information. The sensitive information transferred, generated, transmitted, or stored herein is for VA benefit and ownership alone.
0. Contractor shall maintain physical security at all facilities housing the activities performed under this contract, including any Contractor facilities according to VA-approved guidelines and directives. The Contractor shall ensure that security procedures are defined and enforced to ensure all personnel who are provided access to patient data must comply with published procedures to protect the privacy and confidentiality of such information as required by VA.
0. Contractor must adhere to the following:
1) The use of “thumb drives” or any other medium for transport of information is expressly prohibited.
2) Controlled access to system and security software and documentation.
3) Recording, monitoring, and control of passwords and privileges.
4) All terminated personnel are denied physical and electronic access to all data, program listings, data processing equipment and systems.
5) VA, as well as any Contractor (or Subcontractor) systems used to support development, provide the capability to cancel immediately all access privileges and authorizations upon employee termination.
6) Contractor PM and VA PM are informed within 24 hours of any employee termination.
7) Acquisition sensitive information shall be marked "Acquisition Sensitive" and shall be handled as "For Official Use Only (FOUO)".
8) Contractor does not require access to classified data.
0. Regulatory standard of conduct governs all personnel directly and indirectly involved in procurements. All personnel engaged in procurement and related activities shall conduct business in a manner above reproach and, except as authorized by statute or regulation, with complete impartiality and with preferential treatment for none. The general rule is to strictly avoid any conflict of interest or even the appearance of a conflict of interest in VA/Contractor relationships.
0. VA Form 0752, Confidentiality of Sensitive Information Non-Disclosure Agreement, shall be completed by all Contractor employees working on this contract, and shall be provided to the CO before any work is performed. In the case that Contractor personnel are replaced in the future, their replacements shall complete VA Form 0752 prior to beginning work.
11.2.5 NOTICE OF THE FEDERAL ACCESSIBILITY LAW AFFECTING ALL INFORMATION AND COMMUNICATION TECHNOLOGY (ICT) PROCUREMENTS (SECTION 508) On January 18, 2017, the Architectural and Transportation Barriers Compliance Board (Access Board) revised and updated, in a single rulemaking, standards for electronic and information technology developed, procured, maintained, or used by Federal agencies covered by Section 508 of the Rehabilitation Act of 1973, as well as our guidelines for telecommunications equipment and customer premises equipment covered by Section 255 of the Communications Act of 1934. The revisions and updates to the Section 508-based standards and Section 255-based guidelines are intended to ensure that information and communication technology (ICT) covered by the respective statutes is accessible to and usable by individuals with disabilities.
The Section 508 standards established by the Access Board are incorporated into, and made part of all VA orders, solicitations and purchase orders developed to procure ICT. These standards are found in their entirety at: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines. A printed copy of the standards will be supplied upon request.
Federal agencies must comply with the updated Section 508 Standards beginning on January 18, 2018. The Final Rule as published in the Federal Register is available from the Access Board: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule.
The Contractor shall comply with “508 Chapter 2: Scoping Requirements” for all electronic ICT and content delivered under this contract. Specifically, as appropriate for the technology and its functionality, the Contractor shall comply with the technical standards marked here:
| |X| | E205 Electronic Content – (Accessibility Standard -WCAG 2.0 Level A and AA Guidelines) |
| |X| | E204 Functional Performance Criteria |
| |_| | E206 Hardware Requirements |
| |X| | E207 Software Requirements |
| |X| | E208 Support Documentation and Services Requirements |
11.2.5.2 Compatibility with Assistive Technology
The standards do not require installation of specific accessibility-related software or attachment of an assistive technology device. Section 508 requires that ICT be compatible with such software and devices so that ICT can be accessible to and usable by individuals using assistive technology, including but not limited to screen readers, screen magnifiers, and speech recognition software.
11.2.5.3 Acceptance and Acceptance Testing
Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.
The Government reserves the right to test for Section 508 Compliance before delivery. The Contractor shall be able to demonstrate Section 508 Compliance upon Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.
The Government reserves the right to test for Section 508 Compliance before delivery. The Contractor shall be able to demonstrate Section 508 Compliance upon delivery.
11.2.6 INFORMATION TECHNOLOGY USING ENERGY-EFFICIENT PRODUCTS
The Contractor shall comply with Sections 524 and Sections 525 of the Energy Independence and Security Act of 2007; Section 104 of the Energy Policy Act of 2005; Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015; Executive Order 13221, “Energy-Efficient Standby Power Devices,” dated August 2, 2001; and the Federal Acquisition Regulation (FAR) to provide ENERGY STAR®, Federal Energy Management Program (FEMP) designated, low standby power, and Electronic Product Environmental Assessment Tool (EPEAT) registered products in providing information technology products and/or services.
The Contractor shall ensure that information technology products are procured and/or services are performed with products that meet and/or exceed ENERGY STAR, FEMP designated, low standby power, and EPEAT guidelines. The Contractor shall provide/use products that earn the ENERGY STAR label and meet the ENERGY STAR specifications for energy efficiency. Specifically, the Contractor shall:
1. Provide/use ENERGY STAR products, as specified at www.energystar.gov/products (contains complete product specifications and updated lists of qualifying products).
2. Provide/use the purchasing specifications listed for FEMP designated products at https://www4.eere.energy.gov/femp/requirements/laws_and_requirements/energy_star_and_femp_designated_products_procurement_requirements . The Contractor shall use the low standby power products specified at http://energy.gov/eere/femp/low-standby-power-products.
3. Provide/use EPEAT registered products as specified at www.epeat.net. At a minimum, the Contractor shall acquire EPEAT® Bronze registered products. EPEAT registered products are required to meet the technical specifications of ENERGY STAR, but are not automatically on the ENERGY STAR qualified product lists. The Contractor shall ensure that applicable products are on both the EPEAT Registry and ENERGY STAR Qualified Product Lists.
4. The Contractor shall use these products to the maximum extent possible without jeopardizing the intended end use or detracting from the overall quality delivered to the end user.
The following is a list of information technology products for which ENERGY STAR, FEMP designated, low standby power, and EPEAT registered products are available:
1. Computer Desktops, Laptops, Notebooks, Displays, Monitors, Integrated Desktop Computers, Workstation Desktops, Thin Clients, Disk Drives
2. Imaging Equipment (Printers, Copiers, Multi-Function Devices, Scanners, Fax Machines, Digital Duplicators, Mailing Machines)
3. Televisions, Multimedia Projectors
This list is continually evolving, and as a result is not all-inclusive.
11.3 APPLICABLE VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE (per VA HANDBOOK 6500.6, APPENDIX C, MARCH 12, 2010)
11.3.1 GENERAL
Contractors, Contractor personnel, Subcontractors, and Subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
11.3.2 ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A Contractor/Subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, Subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
b. All Contractors, Subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for Contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service. Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates (e.g. Business Associate Agreement, Section 3G), the Contractor/Subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
e. The Contractor or Subcontractor must notify the CO immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the Contractor or Subcontractor’s employ. The CO must also be notified immediately by the Contractor or Subcontractor prior to an unfriendly termination.
11.3.3 VA INFORMATION CUSTODIAL LANGUAGE
a. Information made available to the Contractor or Subcontractor by VA for the performance or administration of this contract or information developed by the Contractor/Subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of VA. This clause expressly limits the Contractor/Subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
b. VA information should not be co-mingled, if possible, with any other data on the Contractors/Subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the Contractor must ensure that VA information is returned to VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of Contractor and Subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
c. Prior to termination or completion of this contract, Contractor/Subcontractor must not destroy information received from VA, or gathered/created by the Contractor in the course of performing this contract without prior written approval by VA. Any data destruction done on behalf of VA by a Contractor/Subcontractor must be done in accordance with National Archives and Records Administration requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the Contractor that the data destruction requirements above have been met must be sent to the VA CO within 30 days of termination of the contract.
d. The Contractor/Subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations, and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
e. The Contractor/Subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on Contractor/Subcontractor electronic storage media for restoration in case any electronic equipment or data used by the Contractor/Subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
f. If VA determines that the Contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the Contractor or third party or terminate the contract for default or terminate for cause under FAR Part 12.
g. The Contractor/Subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
h. The Contractor/Subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA minimum requirements. VA Configuration Guidelines are available upon request.
i. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the Contractor/Subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA prior written approval. The Contractor/Subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA CO for response.
j. Notwithstanding the provision above, the Contractor/Subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the Contractor/Subcontractor is in receipt of a court order or other requests for the above-mentioned information, that Contractor/Subcontractor shall immediately refer such court orders or other requests to the VA CO for response.
k. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require Assessment and Authorization (A&A) or a Memorandum of Understanding-Interconnection Service Agreement for system interconnection, the Contractor/Subcontractor must complete a Contractor Security Control Assessment on a yearly basis and provide it to the COR.
11.3.4 SECURITY INCIDENT INVESTIGATION
a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The Contractor/Subcontractor shall immediately notify the COR and simultaneously, the designated Information Security Officer and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the Contractor/Subcontractor has access.
b. To the extent known by the Contractor/Subcontractor, the Contractor/Subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the Contractor/Subcontractor considers relevant.
c. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.
d. In instances of theft or break-in or other criminal activity, the Contractor/Subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA Office of Inspector General and Security and Law Enforcement. The Contractor, its employees, and its Subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The Contractor/Subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
12.3.5 LIQUIDATED DAMAGES FOR DATA BREACH
a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information (SPI). If so, the Contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the Contractor/Subcontractor processes or maintains under this contract. However, it is the policy of VA to forgo collection of liquidated damages in the event the contractor provides payment of actual damages in an amount determined to be adequate by the agency.
b. The Contractor/Subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .