36C10X24Q0204_1.docx

DOCX document 150 KB Posted

Attached to
Hines Badge Readers Federal contract opportunity
Solicitation number
36c10x24Q0204
Issued by
Department of Veterans Affairs Strategic Acquisition Center Frederick

About this file

This document is a solicitation (Solicitation Number: 36C10X24Q0204) issued by the Department of Veterans Affairs (VA) Strategic Acquisition Center Frederick for the removal of 250 existing Verdit PIV badge card readers and installation of 250 HID Signo 40 Badge Readers at the Hines Information Technology Center (HITC).

The key requirements include: the Contractor must provide all necessary labor, tools, material, parts, and supervision; the Contractor's technicians must be trained and certified in the use and operation of HID Badge Readers; the Contractor must be an Enterprise Software House Dealer/Distributor and master technician certified. The anticipated contract period of performance is 11 months. Quotes are due by 12PM EDT on 07-01-2024. The contract will be awarded as a firm-fixed-price contract, and the Government will evaluate quotes to determine if the total proposed price is fair and reasonable. The solicitation includes standard Federal Acquisition Regulation (FAR) clauses.

View the file

Other files for this federal contract opportunity

Other files attached to Hines Badge Readers, newest first.
File Type Posted
36C10X24Q0204_admendment 0001.docx DOCX document
36C10X24Q0204 0001.docx DOCX document
HIYC Badge Readers Replacement SOW-PWS Sections A-B.docx DOCX document
ATTACHMENT B - PAST PERFORMANCE QUESTIONNAIRE.pdf PDF
ATTACHMENT A- PAST PERFORMANCE REFERENCES.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C10X24Q0204

PAGE 1 OF

1. REQUISITION NO.

2. CONTRACT NO.

3. AWARD/EFFECTIVE DATE

4. ORDER NO.

5. SOLICITATION NUMBER

6. SOLICITATION ISSUE DATE

a. NAME

b. TELEPHONE NO. (No Collect Calls)

8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY

CODE

10. THIS ACQUISITION IS

UNRESTRICTED OR

SET ASIDE:

% FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ

IFB

RFP

15. DELIVER TO

CODE

16. ADMINISTERED BY

CODE

17a. CONTRACTOR/OFFEROR

CODE

FACILITY CODE

18a. PAYMENT WILL BE MADE BY

CODE

TELEPHONE NO.

UEI:

EFT:

PHONE:

FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19.

20.

21.

22.

23.

24.

ITEM NO.

SCHEDULE OF SUPPLIES/SERVICES

QUANTITY

UNIT

UNIT PRICE

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________

29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

(REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

36C10X24Q0204 Raelynn White 240-478-1854 07-01-2024

12PM

EDT

36C10X Strategic Acquisition Center - Frederick Department of Veterans Affairs 5202 Presidents Court, Suite 103 Frederick MD 21703 X 561621 $25 Million N/A X Department of Veterans Affairs Office of Information & Technology (OIT) Hines Information Technology Center (HIT 5000 South 5th Avenue, Building 215 Hines IL 60141 36C10X Strategic Acquisition Center - Frederick Department of Veterans Affairs 5202 Presidents Court, Suite 103 Frederick MD 21703

VAFSC

U.S. Department of Veterans Affairs Financial Services Center

PO BOX 149971

see Section B.3 invoicing/payment) Austin TX 78714-8917 1-(877)-489-6135 See CONTINUATION Page The Department of Veterans Affairs (VA), Office of Information & Technology (OIT), IT Operations and Services at Hines Information Technology Center (HITC) has a request to remove 250 existing Verdit PIV badge card readers and install 250 HID Signo 40 Badge Readers at HITC.

Questions due:

Quotes due: See Block 8 above See instructions for submission of quotes in Section E.

See CONTINUATION Page X Table of Contents

SECTION A1
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES1
SECTION B - CONTINUATION OF SF 1449 BLOCKS3
B.1 CONTRACT ADMINISTRATION DATA3
B.2 PERFORMANCE WORK STATEMENT (PWS)5
B.3 PRICE/COST SCHEDULE19
ITEM INFORMATION19
SECTION C - CONTRACT CLAUSES20
C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2023)20
C.2 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV 2018)25
C.3 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)27
C.4 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (FEB 2024)27
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS36
SECTION E - SOLICITATION PROVISIONS37
E.1 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)37
E.2 52.204-29 FEDERAL ACQUISITION SUPPLY CHAIN SECURITY ACT ORDERS—REPRESENTATION AND DISCLOSURES (DEC 2023)39
E.3 52.216-1 TYPE OF CONTRACT (APR 1984)41
E.4 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)41
E.5 INSTRUCTIONS TO OFFERORS41
E.6 FAR 52.212-2 EVALUATION—COMMERCIAL ITEMS (OCT 2014)44
E.7 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (FEB 2024)46

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the POC’s listed after award.

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with 52.232-33, Payment by Electronic Funds Transfer—System For Award Management.

3. INVOICES: Invoices shall be submitted monthly in arrears based upon delivery and acceptance; review and approval of the hours completed by the COR

In accordance with FAR 52.212-4 (g) only proper invoices that contain documentation of services performed will be accepted. Invoices shall include documentation to substantiate the work that was completed during that period for any labor hour line items and shall be in accordance with FAR 52.212-4 (i) Alternate I.

4. CHANGES: Any changes to this PWS and associated tasks shall only be authorized and approved through written correspondence from the Contracting Officer (CO). A copy of each change will be kept in the contract folder along with all other products of the project. Costs incurred by the Contractor through the actions of parties other than the CO shall be borne by the Contractor.

5. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

6. FSC MANDATORY ELECTRONIC INVOICE SUBMISSION: Contractors are required to submit payment requests in electronic form in accordance with the submission instructions below.

TUNGSTEN ELECTRONIC INVOICE SUBMISSION

FSC e-INVOICE PROGRAM THRU AUSTIN PORTAL

FSC MANDATORY ELECTRONIC INVOICE SUBMISSION FOR AUSTIN PAYMENTS

Contractor POC:

Contracting POC:

COR (Contracting Officers Representative):

***All invoices submitted through OB10 to the VA-FSC should mirror vendor’s current submission of Invoice, with the following items required:

· Contract/Task Order Number:

· VA Purchase Order Number:

· Contractor’s Taxpayer ID Number (TIN)

· Contractor’s “Remit Address” information

· Contractor’s contact information: (Personal Name, Email, and Phone)

· Contractor’s VA point of contact information: (Personal Name, Email, and Phone)

· Period of Performance dates (Beginning and Ending)

· All discount information if applicable (Percent and Date Terms)

Vendor Electronic Invoice Submission Methods:

Fax, email and scanned documents are not acceptable forms of submission for payment requests. Electronic form means an automated system transmitting information electronically according to the accepted data transmissions below.

· VA’s Electronic Invoice Presentment and Payment System – The Financial Services Center (FSC) in Austin, TX uses a third-party contractor, Tungsten, to transition vendors from paper to electronic invoice submission. Please go to this website: http://www.tungsten-network.com/US/en/veterans-affairs/ to begin submitting electronic invoices, free of charge.

· A system that conforms to the X12 electronic data interchange (EDI) formats established by the Accredited Standards Center (ASC) chartered by the American National Standards Institute (ANSI). The X12 EDI Web site is http://www.x12.org.

Vendor e-invoice Set-up information:

Please contact Tungsten at the phone number or email address listed below to begin submitting your electronic invoices to the VA Financial Services Center in Austin, TX for payment processing. If you have questions about the payment status of a properly submitted invoice, the e-invoicing program, or Tungsten, please contact the FSC at the phone number or email address listed below.

· Tungsten/OB10 system registration please call 877-752-0900, Option #2

· Tungsten Support call 877-489-6135

· Tungsten e-Invoice email: VA.Registration@tungsten-network.com

· VA TUNGSTEN Number: AAA544240062

· FSC e-Invoice contact information: 1-877-353-9791

· FSC e-Invoice email: vafsccshd@va.gov

· http://www.fsc.va.gov/einvoice.asp

COMMUNICATIONS:

· https://www.federalregister.gov/articles/2012/11/27/2012-28612/va-acquisition-regulation-electronic-submission-of-payment-requests

· http://fcw.com/articles/2012/11/27/va-epayments.aspx?s=fcwdaily

7. ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE

Page 1 of Page 1 of

B.2 PERFORMANCE WORK STATEMENT (PWS)

HITC BADGE READERS REPLACEMENT SOW/PWS

1. INTRODUCTION. The mission of the Department of Veterans Affairs (VA), Office of Information & Technology (OIT), IT Operations and Services at Hines Information Technology Center (HITC) is to provide benefits and services to Veterans of the United States. In meeting these goals, HITC strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to Veterans throughout all the points of the Veterans throughout the United States, in an effective, timely and compassionate manner. VA depends on Information Management / Information Technology (IM/IT) systems to further meet mission goals. The HITC processes data that is considered a lifeline to Veterans and constant availability of that data is crucial. The HITC facilities department is responsible for ensuring the facility provide a safe and secure workplace for its employees, 24 hours a day and seven days a week (24/7).

To accomplish the mission and goals of the VA, OIT, in ensuring a safe and secure workplace, HITC requires the removal of all existing Verdit PIV badge card readers throughout the facility and replace with HID Signo 40 Readers.

2. SCOPE. The Contractor shall provide all necessary labor, tools, material, parts, and supervision to remove 250 existing Verdit PIV badge card readers and install 250 HID Signo 40 Badge Readers at HITC. The Contractor shall employ maintenance personnel/ technicians who are trained and certified in the use and operation of all HID Badge Readers. The Contractor shall be Enterprise Software House Dealer/Distributor and master technician certified. Documentation of each must be provided.

The Contractor shall integrate the new badge readers with current Physical Access Control System (PACS) equipment. Contractor shall coordinate with VA-HITC for old equipment onsite storage or site removal. The Contractor shall ensure after installation completion, to leave the premise in the same condition prior to the installation commencement.

The Contractor shall coordinate all equipment selection and installation with VA-HITC Contracting Officer’s Representative (COR), Project Manager (PM), and other VA-HITC Representative(s) prior to starting project.

The Contractor shall remove old badge readers and install new badge readers in such a way to minimize interruption of VA-HITC service (i.e., only momentary impacts to portions of system).

This is a Firm Fixed Price Contract.

3. PERIOD OF PERFORMANCE (PoP). The anticipated contract PoP shall include a base period of 11-months as follows:

Base: TBD

There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, five (5) are set by date:

New Year’s DayJanuary 1
JuneteenthJune 19
Independence DayJuly 4
Veterans DayNovember 11
Christmas DayDecember 25

If any of the above dates falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if any of the above dates falls on a Sunday, then Monday shall be observed as a holiday.

The other six (6) are set by a day of the week and month:

Martin Luther King's BirthdayThird Monday in January
Washington's BirthdayThird Monday in February
Memorial DayLast Monday in May
Labor DayFirst Monday in September
Columbus DaySecond Monday in October
ThanksgivingFourth Thursday in November

4. PLACE OF PERFORMANCE. Tasks under this PWS must be performed at 5000 South 5th Avenue, Building 215, Hines, Illinois, 60141.

5. TRAVEL. The Government anticipates only local travel to perform the tasks associated with requirement. Local travel within 50 miles will not be reimbursed by the Government.

6. SPECIFIC TASKS AND DELIVERABLES.

6.1 Project Management

6.1.1 Contractor Project Management Plan

The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline, and tools to be used in execution of the contract. The CPMP must take the form of both a narrative and graphic format that displays the schedule, milestones, risks, and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified with the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA PM approved CPMP throughout the POP.

Deliverable:

A. Contractor Project Management Plan

6.1.2 Reporting Requirement.

The Contractor shall provide the COR with Weekly Progress Reports in electronic form in Microsoft Word and Project formats. The report must include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding week.

The Weekly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If the problems have not been completely resolved, the Contractor shall provide and explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Electronic and Information Technology (EIT) deliverables and their current Section 508 conformance status. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.

Deliverable:

B. Weekly Progress Report shall:

1. Provide status of all shipment/delivery of hardware shipped, to include the serial number associated with each piece of equipment; the date of each shipment; the status of each shipment, tracking information, and information relative to Government-receipt of the equipment items at the delivery site.

2. Provide as part of the Weekly Progress Report the Master Delivery Schedule to the COR and PM for coordination purposes.

3. Identify all work completed during the reporting period and work planned for the subsequent reporting period.

4. Identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue.

5. Include an itemized list of all Electronic and Information Technology (EIT) deliverables and their current Section 508 conformance status.

6. Monitor performance against the CPMP and report any deviations.

6.2. Provisioning and Installation of Equipment

The Contractor shall perform all work in accordance with current National Electrical Code (NEC) and all other applicable codes, NFPA 70 (NEC) Code Development, Electrical Code, 2020 (NFPA 70, 2020) | UpCodes, (PDF) NFPA 70, 2023 National Electrical Code | Rey Eduard Q . Umel - Academia.edu. Due to security concerns, serial numbers for existing software and Facility Layouts will be provided upon contract award.

The Contractor shall remove all 250 Verdit PIV badge card readers throughout the facility and replace with HID Signo 40 Readers.

Deliverable:

C. Two Hundred and Fifty (250) HID Signo 40 Badge Readers Wall Switch Contactless Reader. (NOTE: Coordinate with VA-HITC COR on all locations)

6.2.1 Maintenance Support and Equipment Warranty

Upon successful installation of the Badge readers, the Contractor shall provide one-year parts and labor warranty for the complete system. This shall include coverage on all installed equipment.

The Contractor shall maintain 24-hour call service center with a four (4) hours of maximum respond time.

The Badge Reader warranty shall begin when all equipment and documentation are accepted as completed and fully functional.

6.3 Contractor Qualifications

The Contractor shall maintain a current software license and/or license agreement with Lenel OnGuard PACS and HID Global PIV Class.

The Contractor shall be an Enterprise Software House dealer; master technician certifications; domination shall be provided.

The Contractor shall be Lenel OnGuard, HID Global PIV Class certified.

The Contractor’s technicians shall have at a minimum of five (5) years relevant experience working with integrated electronic access control.

The Contractor shall “Test and Validate Equipment” and configurations to assure that the equipment is working properly at each location of the card reader throughout the facility, and that it is properly configured. The contractor must inform the COR if the equipment is not functioning properly, within 30 minutes during the Test and Validation phase. The contractor must certify all equipment and configurations is functioning properly at each location after the “Test and Validation” phase.

The Contractor’s employees and any sub-Contractors’ employees shall be able to pass a criminal history background investigation by the HITC/Austin Information Technology Center (AITC) Security staff and VA Security and Investigation Center (SIC).

The Contractor’s employees and sub-Contractors’ employees shall be legally able to work in the United States.

6.4. General Requirements

6.4.1. Enterprise and IT Framework

6.4.2. VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model VA Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OI&T. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

6.4.3. Federal Identity, Credential, and Access Management (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.ea.oit.va.gov/EAOIT/docs/Oct_2016_Release_Docs/Privacy-and-Security-User-Identity-Authentication-EDP-V1-7_For-Signed.pdf. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500.6 “Contract Security”, and VA IAM enterprise requirements for direct, assertion-based authentication, and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-11-11 can be found at:

https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1.Automated provisioning and are able to use enterprise provisioning service.
2.Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.
3.The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4.Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5.Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6.Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7.Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8.A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9.Authentication/account binding based on trusted Hypertext Transfer Protocol

(HTTP) headers if the solution relies on Trust based authentication.

10.Role Based Access Control.
11.Auditing and reporting capabilities.
12.Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems.

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

6.4.4. Internet Protocol Version 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf) and September 28, 2010 (https://obamawhitehouse.archives.gov/sites/default/file/omb/assets/egov_docs/transition-to-ipv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf), the Technical Infrastructure for USGv6 Adoption (https://www.nist.gov/programs-projects/usgv6-program), and the NIST SP 800 series applicable compliance (https://csrc.nist.gov/publications/sp) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g., web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at: https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

6.4.5. Trusted Internet Connection (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 Trusted Internet Connections Reference Architecture Document Version 2.2 (cisa.gov)

6.4.6. Standard Computer Configuration

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 11 (64bit), Microsoft Edge Explorer 9 and Office 365 ProPlus. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Windows 11. Applications delivered to the VA and intended to be deployed to Windows 11 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the client operating system being used.

6.4.6. Veteran Focused Integration Process (VIP)

The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products.

6.4.7. Process Asset Library (PAL)

The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the Contractor onboarding process consistent with Section 6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf. The main PAL can be accessed at www.va.gov/process.

6.4.8. Authoritative Data Sources

The VA Enterprise Architecture Repository (VEAR) is one component within the overall Enterprise Architecture (EA) that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:

1. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.

3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.

4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.

5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.

6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active-duty military service data. VADIR is the authoritative source foe Qualifying Active-Duty military service in the VA.

7. Delivery Schedule.

Task
Deliverable
Quantity
Delivery Date
Task #: 6.1.1.
Contractor Project Management Plan
One (1) initial report and then monthly report until project completion.
Due 30 days after contract awarded and monthly thereafter as needed
Task # 6.1.2.
Weekly Progress Report
One (1) weekly report. As required.
Due the first day of each week throughout the PoP until project completion.
Task # 6.2.
250 HID Signo 40 Badge Readers
250 HID Signo 40 Badge Readers.
Manufacturer availability
Task #9.2.1.
Contractor Staff Roster
One (1) initial report and updated throughout the PoP
Due three (3) after contract awarded and updated throughout the PoP.

8. Government-Furnished Information, Equipment, and Facilities.

8.1. Confidentiality and Non-Disclosure

The Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations. The Contractor shall not have access to Protected Health Information (PHI) and Electronic Protected Health Information (EPHI) that is subject to protection under the regulations issued by the Department of Health and Human Services, as mandated by the Health Insurance Portability and Accountability Act of 1996 (HIPAA); 45 CFR Parts 160 and 164, Subparts A and E, the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”); and 45 CFR Parts 160 and 164, Subparts A and C, the Security Standard (“Security Rule”). Pursuant to the Privacy and Security Rules, the Contractor shall agree in writing to certain mandatory provisions regarding the use and disclosure of PHI and EPHI.

8.1.1. The Contractor shall have access to some privileged and confidential materials of VA. These printed and electronic documents are for internal use only, are not to be copied or released without permission, and remain the sole property of VA. Some of these materials are protected by the Privacy Act of 1974 (revised by PL 93-5791) and Title 38. Unauthorized disclosure of Privacy Act or Title 38 covered materials is a criminal offense.

8.1.2. The VA Contracting Officer will be the sole authorized official to release in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this contract. The Contractor shall not release any information. Any request for information relating to this contract presented to the Contractor shall be submitted to the VA Contracting Officer for response.

8.1.3. The Contractor personnel recognize that in the performance of this effort, Contractor personnel may receive or have access to sensitive information, including information provided on a proprietary basis by carriers, equipment manufacturers and other private or public entities. Contractor personnel agree to safeguard such information and use the information exclusively in the performance of this contract. Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations as enumerated in this section and elsewhere in this Contract and its subparts and appendices.

8.1.4. The Contractor shall limit access to the minimum number of personnel necessary for contract performance for all information considered sensitive or proprietary in nature. If the Contractor is uncertain of the sensitivity of any information obtained during the performance this contract, the Contractor has a responsibility to ask the VA Contracting Officer.

8.1.5. The Contractor shall train all of their employees involved in the performance of this contract on their roles and responsibilities for proper handling and nondisclosure of sensitive VA or proprietary information. Contractor personnel shall not engage in any other action, venture or employment wherein sensitive information shall be used for the profit of any party other than those furnishing the information. The sensitive information transferred, generated, transmitted, or stored herein is for VA benefit and ownership alone.

8.1.6. The Contractor shall maintain physical security at all facilities housing the activities performed under this contract, including any Contractor facilities according to VA-approved guidelines and directives.

8.1.7. The Contractor shall adhere to the following:

8.1.7.1. The use of “thumb drives” or any other medium for transport of information is expressly prohibited.

8.1.7.2. Controlled access to system and security software and documentation.
8.1.7.3. Recording, monitoring, and control of passwords and privileges.

8.1.7.4. All terminated personnel are denied physical and electronic access to all data, program listings, data processing equipment and systems.

8.1.7.5. VA, as well as any Contractor (or Subcontractor) systems used to support development, provide the capability to cancel immediately all access privileges and authorizations upon employee termination.

8.1.7.6. Contractor PM and VA PM are informed within 24-hours of any employee termination.

8.1.7.7. Acquisition sensitive information shall be marked “Acquisition Sensitive” and shall be handled as “For Official Use Only (FOUO)”.

8.1.7.8. Contractor does not require access to classified data.

8.1.8. Regulatory standard of conduct governs all personnel directly and indirectly involved in procurements. All personnel engaged in procurement and related activities shall conduct business in a manner above reproach and, except as authorized by statute or regulation, with complete impartiality and with preferential treatment for none. The general rule is to strictly avoid any conflict of interest or even the appearance of a conflict of interest in VA/Contractor relationships.

9. Security Requirements.

9.1. Position/Task Risk Designation Level(s)

In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity, and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:

Position Sensitivity and Background Investigation Requirements by Task

Task Number
Tier 1 / Low Risk
Tier 2 / Moderate Risk
Tier 4 / High Risk

9.1.

9.2.

9.2.

The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual shall be working. The submitted Contractor Staff Roster must indicate the required Background Investigation level for each Contractor individual based upon the tasks the Contractor individual shall be working, in accordance with their submitted proposal.

9.2. Contractor Personnel Security Requirements

9.2.1. Contractor Responsibilities:

9.2.1.1. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak, and understand the English language.

9.2.1.2. Within three (3) business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 9.1 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

9.2.1.3. The Contractor shall coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

9.2.1.4. The Contractor shall ensure the following required forms are submitted to the COR within five (5) days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form

9.2.1.5. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).

9.2.1.6. The Contractor employee shall certify and release the e-QIP document, print and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee shall notify the COR within 3 business days that documents were signed via e-QIP).

9.2.1.7. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. If damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.

9.2.1.8. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor shall be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of OPM.

9.2.1.9. The Contractor, when notified of an unfavorably adjudicated background investigation on a contractor’s employee as determined by the Government, must withdraw the employee from consideration in working under the contract.

9.2.1.10. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.

9.2.1.11. Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, always displaying their badges, and returning the identity credentials upon termination of their relationship with VA.

9.2.1.12. The Contractor shall obtain all necessary licenses and/or permits required to perform the work, except for software licenses that need to be procured from a Contractor or vendor in accordance with the requirements documents. The Contractor shall take all reasonable precautions necessary to protect persons and property from injury or damage during the performance of the contract.

Deliverable:

A. Contractor Staff Roster

10. Quality Assurance Surveillance Plan (QASP).

The Government will evaluate the Contractor's performance in accordance with the Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the Government will do to ensure the Contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rates.

Deliverable/ Requirement
Performance

Standard Surveillance Method Outcome

Technical / Quality of Product or Service

1. Demonstrates understanding of requirements.

2. Efficient and effective in meeting requirements

3. Meets technical needs and mission requirements

4. Provides quality services/product

100% inspection. The COR will review each Deliverable for quality/timeliness according to criteria established in this task.
Poor performance may result in issuance of a Contractor Discrepancy Report (CDR). The Contractor’s performance on this TO will be reported to the Contractor Performance Assessment Reporting System (CPARS). The CO and COR will make use of information from CDRs, as well as any additional knowledge and information available to them with respect to the Contractor’s performance, to complete the CPARS.

The Contractor shall be given an opportunity to correct non-conforming services at no cost to the Government if the services are non-conforming or the contract requirement is unacceptable.

Project Milestones and Schedule
1. Established milestones and project dates are met

2. Products completed, reviewed, delivered in accordance with the established schedule

3. Notifies customer in advance of potential problems

100% inspection. The COR will review each Deliverable for quality/timeliness according to criteria established in this task.
The Government will not pay for services that do not conform or do not meet performance standards or have not been properly rendered.
Cost & Staffing
1. Currency of expertise and staffing levels appropriate

2. Personnel possess necessary knowledge, skills, and abilities to perform tasks

100% inspection. The COR will review each Deliverable for quality/timeliness according to criteria established in this task.
The Government will not pay for services that do not conform or do not meet performance standards or have not been properly rendered.
Management
1. Integration and coordination of all activities to execute effort
100% inspection. The COR will review each Deliverable for quality/timeliness according to criteria established in this task.
Poor performance may result in issuance of a Contractor Discrepancy Report (CDR). The Contractor’s performance on this TO will be reported to the Contractor Performance Assessment Reporting System (CPARS). The CO and COR will make use of information from CDRs, as well as any additional knowledge and information available to them with respect to the Contractor’s performance, to complete the CPARS.

The Contractor shall be given an opportunity to correct non-conforming services at no cost to the Government if the services are non-conforming or the contract requirement is unacceptable.

The Contractor’s performance on this contract shall be reported on an annual basis to the Contractor Performance Assessment Reporting System (CPARS). Poor performance may result in issuance of a Contractor Discrepancy Report (CDR). The CO and COR will make use of information from CDRs, as well as any additional knowledge and information available to them with respect to the Contractor’s performance, to complete the CPARS.

The Government will not pay for services that do not conform or do not meet performance standards or have not been properly rendered. The Contractor shall be given an opportunity to correct non-conforming services at no cost to the Government if the services are non-conforming or the contract requirement is unacceptable.

12. Housekeeping.

The Contractor shall keep the job site clean, free from accumulations of waste material or trash. The Contractor shall be responsible for removing all waste material or trash from Government property, as to deter accumulation of debris. All material subject to recycling shall be properly disposed.

13. Non-Personal Services Statement.

Contractor employee(s) performing services shall be controlled, directed and supervised at all times by management personnel of the Contractor. Actions of Contractor employees shall not be interpreted or implemented in any manner that results in any Contractor employee creating or modifying Federal policy, obligating the appropriated funds of the U.S. Government, overseeing the work of Federal employees, providing direct personal services to any Federal employee or otherwise violating the prohibitions set forth in Parts 7.5 and 37.1 of the Federal Acquisition Regulations (FAR).

14. SITE VISIT.

It is strongly suggested and expected that the offeror inspect the campus to be serviced to fully understand the nature of the work and the conditions under which the work is to be performed. In no case shall failure to inspect the campus constitute grounds for a claim after contract award.

14.1 SITE VISIT IS TO BE SCHEDULED WITH THE COR.

B.3 PRICE/COST SCHEDULE

ITEM INFORMATION

ITEM NUMBER
DESCRIPTION OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
250.00
ea
__________________
__________________

HID | Signo 40 Reader, 40NKS-T0-000000, Priority Standard Profile with Pigtail

Contract Period: Base POP Begin: 07-01-2024 POP End: 09-30-2024

GRAND TOTAL
__________________

SECTION C - CONTRACT CLAUSES

C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2023)

(a) Inspection/Acceptance. The Contractor shall only tender for acceptance those items that conform to the requirements of this contract. The Government reserves the right to inspect or test any supplies or services that have been tendered for acceptance. The Government may require repair or replacement of nonconforming supplies or reperformance of nonconforming services at no increase in contract price. If repair/replacement or reperformance will not correct the defects or is not possible, the Government may seek an equitable price reduction or adequate consideration for acceptance of nonconforming supplies or services. The Government must exercise its post-acceptance rights—

(1) Within a reasonable time after the defect was discovered or should have been discovered; and

(2) Before any substantial change occurs in the condition of the item, unless the change is due to the defect in the item.

(b) Assignment. The Contractor or its assignee may assign its rights to receive…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .