36C25525Q0568.docx

DOCX document 36 KB Posted

Attached to
J063--Annual Maintenance Service - Security and CCTV Systems Federal contract opportunity
Solicitation number
36C25525Q0568
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 15

About this file

This document is a Special Notice and Performance Work Statement (PWS) for an annual maintenance service contract for security and CCTV systems at the Department of Veterans Affairs Kansas City Medical Center. The Department of Veterans Affairs, VISN 15 Contracting Office intends to award a sole source contract to Siemens Industry Inc. for comprehensive security system maintenance, with an Indefinite Delivery Indefinite Quantity (IDIQ) structure spanning five 12-month ordering periods from January 2026 to December 2030.

The contract requires an on-site technician 5 days per week, providing full maintenance and repairs for C-CURE 9000 security and CCTV systems across multiple VA facilities. Specific services include annual maintenance, software updates, emergent and non-emergent repairs, license renewals, and correcting system deficiencies. The scope covers physical access control devices, intrusion systems, video surveillance equipment, emergency call boxes, and network infrastructure. Key deliverables for each ordering period include on-site labor, system license renewals, corrective maintenance, and specific improvement projects such as camera installations, server replacements, and PACS upgrades. The solicitation number is 36C25525Q0568, with a response deadline of October 06, 2025, at 16:30 PM CST.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SUBJECT*

Annual Maintenance Service - Security and CCTV Systems

GENERAL INFORMATION

CONTRACTING OFFICE’S ZIP CODE*
66048
SOLICITATION NUMBER*
36C25525Q0568
RESPONSE DATE/TIME/ZONE
09-30-2025 16:30 CENTRAL TIME, CHICAGO, USA
ARCHIVE
15 DAYS AFTER THE RESPONSE DATE
RECOVERY ACT FUNDS
N
PRODUCT SERVICE CODE*
J063
NAICS CODE*
561210
CONTRACTING OFFICE ADDRESS
Department of Veterans Affairs

Network Contracting Office (NCO) 15 3450 S 4th Street Trafficway

Leavenworth KS 66048

POINT OF CONTACT*

Contract Specialist Laura Ferguson Laura.Ferguson@va.gov 913.758.9924

ADDITIONAL INFORMATION

AGENCY’S URL
https://www.va.gov/
URL DESCRIPTION
VA Homepage
AGENCY CONTACT’S EMAIL ADDRESS
Laura.Ferguson@va.gov
EMAIL DESCRIPTION
Contract Specialist

DESCRIPTION

The Department of Veterans Affairs, VISN 15 Contracting Office intends to award a sole source contract under the authority of 41 U.S.C 1901 – FAR Part 13.106-1 (b) (2); Soliciting from a Single Source because they are unique services available from only one source – Siemens Industry Inc. at 8066 Flint St, Lenexa, KS 66214 will onsite labor (5 days each week during the contract year), all system license renewals and upgrade projects to current systems..

The place of performance is for the Department of Veterans Affairs Kansas City Medical Center located at 4801 East Linwood Blvd., MO 64128.

The NAICS code for these items is 561210 (Facilities Support Services). This action will result in a Firm-Fixed Price Indefinite Delivery Indefinite Quantity (IDIQ) contract with five 12-month (one year) ordering periods.

This notice of intent is not a request for quotations; interested parties may express their interest by providing a capabilities statement NLT October 06 at 16:30 PM CST. The capabilities statement must provide clear and unambiguous evidence to substantiate the capability of the party to provide the required services. A determination not to compete this proposed contract upon responses to this notice is solely within the discretion of the Government. Verbal responses are not acceptable and will not be considered.

POTENTIAL SOURCES SHALL PROVIDE THE FOLLOWING INFORMATION IN THE RESPONSE:

1) Company name, address, phone number, primary contact(s), e-mail address, NAICS code(s), business size (i.e. small/large), and UEI Number.

2) Statement of Capability that demonstrates the ability to provide the item in accordance with the attached Statement of Work (SOW) and past performance in providing this type of service.

Include examples of prior completed Government contracts, references, and other related information.

This notice is to assist NCO 15 in determining SOURCES ONLY. This announcement is not a request for proposals or quotations. The Government is not committed to awarding a contract pursuant to this announcement. The Government will not pay for any costs incurred in the preparation or submission of information in response to this announcement.

When responding to this announcement, respondents should refer to Announcement 36C25525Q0568 Notice of Intent. If after October 06, 2025, if no viable responses have been received in response to this announcement, Department of Veterans Affairs shall negotiate solely with Siemens Industry Inc.

This notice of intent to award a sole source contract is not a request for competitive quotes.

There will be no solicitation available for competitive quotes. Phone calls will not be accepted.

The point of contact for this action is Contracting Officer, Laura Ferguson who can be reached at: Laura.Ferguson@va.gov .The VISN 15 Contracting Office address is: VA Heartland Network 15, Network Business Office, Contracting Office, 3450 South. 4th Street, Leavenworth, KS 66048.

Special Notice Special Notice

*= Required Field
Special Notice

Special Notice

STATEMENT WORK STATEMENT

ANNUAL MAINTENANCE SERVICE C-CURE 9000 SECURITY AND CCTV SYSTEMS

Part 1

General Information

1. GENERAL: This is a non-personal services contract to provide full maintenance and repairs for the Security and CCTV systems installed at the Kansas City, VA Medical Center, located at 4801 East Linwood Blvd., Kansas City, MO 64128. The services will also be required at the Honor Annex and all Community Based Outpatient Clinics (CBOC). The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government. All services provided under this proposal will meet manufacturers' performance and technical specifications, Federal Regulations, FCC certification and other specifications that may apply such as National Electric Code (NEC), Life Safety Code (LSC), Joint Commission on Accreditation of Healthcare Organizations (JCAHO), and VA Regulations.

1.1 Description of Services/Introduction: The Contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and nonpersonal services necessary to perform Maintenance of the C-CURE Security and CCTV Systems and to correct FIPS deficiencies as defined in this Performance Work Statement (PWS). The Contractor shall perform to the standards in this contract.

1.2 Background: The Medical Center has a C-CURE 9000 security and CCTV systems that uses a combination of operating hardware and software that was engineered specifically for the Medical Center. The systems have multiple FIPS deficiencies that need to be corrected and/or repaired.

1.3 Objectives: To have a properly functioning and reliable, security and CCTV system that is for the safety and security of the occupants of the medical center.

1.4 Scope: Contractor will provide all tools, materials, labor, and supervision to perform annual maintenance of the security and CCTV systems for all buildings at the Kansas City VA Medical Center, 4801 East Linwood Boulevard, Kansas City, MO 64128. The contractor will provide a qualified and certified security system technician, to be onsite, Monday thru Friday during each week of the contract year. Copies of the security system certifications for the prime contractor and any of the technicians that will be working on the premises, will be given to the contract COR, within 10 business days of contract award. Required services also include license renewals for all the systems as well as upgrades to the systems from local projects. Any repairs, additions or software upgrades to the proprietary Siemens scramble pads security interface can only be done by Siemens. See SERVICE RESPONSE for response times for the scramble pad repairs. Full maintenance includes emergent and non-emergent repairs; routine weekly preventative maintenance that includes the cleaning of cameras, testing of cameras, servers, PIN Pads, and scramble pads. Contractor will provide all replacement parts, hardware and software updates and licenses to the security and CCTV systems installed as outlined in this Scope. All parts used during maintenance will be new, OEM replacement parts that are designed for the model and type of device they replace. Contractor will provide all labor, tools, supplies, test equipment and other incidentals necessary to maintain or restore the C-CURE 9000 and Genetec Video equipment to operating specifications that meet or exceed the manufacturers' specifications. Due to the critical need for fully operational security and CCTV systems, the contractor will maintain an ample supply of devices and other supplies that are on station to minimize downtime. Contractor will be required to diagnose and repair systems deficiencies throughout the facility with minimal assistance from VA staff. Thorough knowledge of the layout of the Medical Center that includes the security and CCTV systems is critical in repairing problems in a timely manner. Contractor will correct existing PACS (Physical Access Control System) and FIPS (Federal Information Processing Standards) deficiencies throughout the Medical Center buildings. This will include the replacement or new installation of cameras for exterior doors and underneath the solar panels. Correcting deficiencies also requires installing PIV (Personal Identity Verification) card readers at doorways. At times, security deficiencies are identified during safety and security inspections or surveys. When security deficiencies are identified by the VA or by the contractor, the VA will request a proposal and a Statement of Work, from the contractor to correct the deficiencies. Security Items and components that will be maintained under this contract:

Physical Access Control (PACS) devices:

• Card readers

• Card reader interfaces

• Door controllers, power supplies, and back-up batteries

• Scramble Keypads

• Scramble Keypad Interface

• Door position switches, electronic locks, electrified panic hardware, and maglocks

• Request to exit devices

• Physical Access Control system programming

• PIV Card Verification devices

• PIV Card registration workstations, operating systems, software, and licenses

• Physical Access Control workstations, operating systems, software, and licenses

• Physical Access Control servers, operating systems, software, and licenses

• Physical Access Control UPS

• Touchscreen Video Intercom set w/door release

Intrusion Systems:

• Door position switches

• Motion detectors

• Glass breakage detectors

• Arm / disarm stations

• Alarm sounders

• Power supplies / back-up batteries

Video Surveillance:

• Indoor and outdoor cameras including mounting hardware and wiring

• Video surveillance system programming

• Video surveillance workstations, operating systems, software, and licenses

• Video surveillance servers and storage, operating systems, software, and licenses

• Video surveillance UPS

Emergency Call Boxes, aka; Distress Stations:

• Outdoor emergency call boxes

• Outdoor bus call boxes

• Electrified Panic hardware

Network for Physical Access Control, Video Surveillance, and outdoor call boxes:

• Network switches and routers

• Network switch UPS

• Network interconnections (fiber optic cable, copper cable, etc.).

Requested Services include:

Annual maintenance Software updates Emergent and non-emergent services.

Correcting all deficiencies observed during inspections.

Service Response:

A Contract representative shall be located on site at the Kansas City VA (KCVA) Medical Center during duty hours of Monday – Friday (8:00AM- 5:00PM) to address any issues that may arise with the security system. During non-duty hours, weekends & holidays, Contractor will provide a central number for emergency contact. A Contractor technician will respond within 2 hours of the placing of the call by the Government to address the issue and initiate repairs. Contractor will respond on the premises of the Kansas City VA Medical Center, Honor Annex, Community Based Outpatient Clinic (CBOC) and Fisher House within 2 hours for critical responses and 8 hours for non-critical areas when required for onsite service call as requested by the VA Police.

In each contract year, the Contractor shall accomplish (Contract Deliverables):

Ordering Period I

• On site labor & system license renewals

• On-Site Technician 5 days per week

• Corrective Maintenance & Repairs

• Warranties on service completed prior contract year

• Correct Deficiencies:

o Install Freedom and Valor building cameras o Replace old servers and install new updated servers in the Main Hospital o Install Main building cameras o Install Transitional Residence Housing cameras and PACS o Building 2 Police o Honor Annex Parking Cameras

Ordering Period II

• On site labor & system license renewals

• On-Site Technician 5 days per week

• Corrective Maintenance & Repairs Selected Projects to be completed

• Warranties on service completed prior contract year

Ordering Period III

• On site labor & system license renewals

• On-Site Technician 5 days per week

• Corrective Maintenance & Repairs

• Warranties on service completed prior contract year

• Correct Deficiencies:

Selected Projects to be completed

Ordering Period IV

• On site labor & system license renewals

• On-Site Technician 5 days per week • Corrective Maintenance & Repairs

• Warranties on service completed prior contract year

• Correct Deficiencies:

Selected Projects to be completed

Ordering Period V

• On site labor & system license renewals

• On-Site Technician 5 days per week

• Corrective Maintenance & Repairs Selected Projects to be completed

• Warranties on service completed prior contract year

Ordering Period I: 01/01/2026 – 12/31/2026 Ordering Period II: 01/01/2027 – 12/31/2027 Ordering Period III: 01/01/2028 – 12/31/2028 Ordering Period IV: 01/01/2029 – 12/31/2029 Ordering Period V: 01/01/2030 – 12/31/2030

VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY language FOR Inclusion into CONTRACTS AS Of June 2023:

1. GENERAL

Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

1. ACCESS to VA INFORMATION AND VA INFORMATION SYSTEMS

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

b. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

2. VA INFORMATION CUSTODIAL Language

a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

b. If VA determines that the contractor has violated any of the information confidentiality, privacy, security, and other provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

3. SECURITY INCIDENT INVESTIGATION

a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

c. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

d. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.

e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

4. LIQUIDATED DAMAGES FOR DATA BREACH

a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

b. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.

c. Each risk analysis shall address all relevant information concerning the data breach, including the following:

(1) Nature of the event (loss, theft, unauthorized access);

(2) Description of the event, including:

(a) date of occurrence;

(b) data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;

(3) Number of individuals affected or potentially affected;

(4) Names of individuals or groups affected or potentially affected;

(5) Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;

(6) Amount of time the data has been out of VA control;

(7) The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);

(8) Known misuses of data containing sensitive personal information, if any;

(9) Assessment of the potential harm to the affected individuals;

(10) Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate; and

(11) Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.

f. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $__37.50__ per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

(1) Notification;

(2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

(3) Data breach analysis;

(4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;

(5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

(6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.

5. TRAINING

a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

(1) Successfully complete the appropriate VA privacy training and annually complete required privacy training (See below training); and

(2) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access

g. The contractor shall provide to the contracting officer and/or the COTR a copy of the training certificates for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

h. Failure to complete the mandatory annual training, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

7. ADDITIONAL Requirements

a. The COR is responsible for coordinating with the Police prior to contractor arrival to identify the names of contractor personnel so that Police can ensure sufficient number of contractor badges are available for issuance prior to beginning work. COR is also responsible for signing out and signing in temporary contractor badges.

b. The COR is also responsible for maintaining copies of signed Privacy training for all contractors according to RCS 10-1.

c. Any work performed outside of official VA business hours after hours will require escorts.

d. Escort duties for un-cleared contractors are strictly limited to government officials, specifically VA employees. At no time are contractors allowed to escort other contractors.

File details come from the government source that posted it. Updated .