About this file

Solicitation Summary: Building 27 Warehouse Security System and Access Controls Upgrade

This is a Service-Disabled Veteran-Owned Small Business (SDVOSB) set-aside Solicitation/Contract/Order for Commercial Products and Commercial Services (SF 1449) issued by the Department of Veterans Affairs, Network Contracting Office 23. The solicitation seeks a single contractor to furnish all labor, materials, equipment, supervision, testing, programming, documentation, training, and incidentals necessary to upgrade the Building 27 Warehouse security system and access controls at VA Central Iowa Health Care System (VACIHCS) in Des Moines, Iowa. The offer due date is July 17, 2026, at 4:00 PM CDT, with an effective/award date of July 6, 2026. The acquisition is a total SDVOSB set-aside using simplified acquisition procedures (SAP) with Lowest Priced Technically Acceptable (LPTA) evaluation. The contract value is estimated at $25 million and will be awarded as a Firm-Fixed-Price contract.

The Performance Work Statement specifies a 30-calendar-day performance period from Notice to Proceed, requiring installation of three Hirsch Scrambleprox card readers, replacement of existing readers, installation of five motion detectors, a complete automatic door operator with relay control and ADA-accessible push button at interior double doors, Hirsch input and relay boards, approximately 470 linear feet of cabling and conduit, firestopping at penetrations, labeling per VA/NECA standards, system integration with existing Hirsch infrastructure, end-user training, and comprehensive documentation. The contractor must comply with strict operational requirements including work hours of 8:00 AM to 3:30 PM CDT Monday through Friday, advance notifications (3-day, 2-day, and 5-day), OSHA safety compliance, VA badging requirements, cybersecurity standards, and coordination with VA Police. All offers must include signed SF 1449, completed price schedules, documentation of technical capability, signed QASP, training certifications, proof of Hirsch System Integrator certification, completed limitations on subcontracting certificate, and Buy American certificate. Payment will be made electronically via the Tungsten Network system, and invoices must be submitted upon completion.

View the file

Other files for this federal contract opportunity

Other files attached to J063--Warehouse security system and access controls upgrade at the CIVAHCS, newest first.
File Type Posted
D.1 WD 2015-4979.pdf PDF
36C26326Q0884_1.docx DOCX document
D.3 QASP_Building27 - V2 revised.pdf PDF
D.2 Attachment A Warehouse Diagram with Door Labels.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

636-26-4-9073-0059

36C26326Q0884 07-06-2026

Joshua Imdacha 3193397017 07-17-2026

16:00 CDT

36C263

DEPARTMENT OF VETERANS AFFAIRS

NETWORK CONTRACTING OFFICE 23

1303 5TH STREET, SUITE 300

CORALVILLE IA 52241

X 100

X

561621

$25 Million

N/A

X

DEPARTMENT OF VETERANS AFFAIRS

VA Central Iowa Health Care System

3600 30TH ST. BLDG 10

DES MOINES IA 50310

NETWORK CONTRACTING OFFICE 23

1303 5TH STREET, SUITE 300

CORALVILLE IA 52241

FMS-VA-2(101)

FINANCIAL SERVICES CENTER

PO BOX 149971

AUSTIN TX 78714-9971

x

See CONTINUATION Page

NCO 23 has a requirement for warehouse security system and access controls upgrade at the CIVAHCS.

See sections B.2 & B.3 for details

This RFQ Is a total SDVOSB set aside

Uses simplified acquisition procedures (SAP) LPTA evaluation see 52.212-2 for details

FOR CONSIDERATION ALL QUESTIONS MUST BE RECEIVED 72 HOURS

BEFORE DATE STIPULATED IN BLOCK 8 OF THE SF1449 FORM.

EMAIL ALL QUESTIONS AND RESPONSES TO JOSHUA.IMDACHA@VA.GOV

SIGN SF1449 AND RETURN ALL PAGES WITH OFFER SUBMISSION

ALL OFFERS SHALL BE SUBMITTED ELECTRONICALLY VIA EMAIL

TO JOSHUA.IMDACHA@VA.GOV

See CONTINUATION Page

636-3660162-9073-854100-2543-636C67XXX-030050190

x X x 1

Joshua Imdacha Contracting Officer

36C26326Q0884

Table of Contents

SECTION A

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 Performance Work Statement (PWS)

B.3 PRICE/COST SCHEDULE

SECTION C - CONTRACT CLAUSES

C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (OCT 2025) (DEVIATION)

C.2 52.222-36 EQUAL OPPORTUNITY FOR WORKERS WITH DISABILITIES (NOV

2025) (DEVIATION)

C.3 52.222-42 STATEMENT OF EQUIVALENT RATES FOR FEDERAL HIRES (MAY

2014)

C.4 52.222-90 ADDRESSING DEI DISCRIMINATION BY FEDERAL CONTRACTORS

(DEVIATION APR 2026)

C.5 52.223-23 SUSTAINABLE PRODUCTS (NOV 2025) (DEVIATION)

C.6 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025)

(DEVIATION)

C.7 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.8 VAAR 852.201-70 CONTRACTING OFFICER'S REPRESENTATIVE (DEC 2022)

C.9 VAAR 852.203-70 COMMERCIAL ADVERTISING (MAY 2018)

C.10 VAAR 852.219-73 VA NOTICE OF TOTAL SET-ASIDE FOR CERTIFIED

SERVICE-DISABLED VETERAN-OWNED SMALL BUSINESSES (JAN 2023)

(DEVIATION)

C.11 VAAR 852.219-75 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING—

CERTIFICATE OF COMPLIANCE FOR SERVICES AND CONSTRUCTION (JAN 2023)

(DEVIATION)

C.12 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS

(NOV 2018)

C.13 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020) . 45

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

D.1 WD 2015-4979

D.2 Attachment A Warehouse Diagram with Door Labels D.3 QASP_Building27 - V2 revised

SECTION E - SOLICITATION PROVISIONS

E.1 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (OCT 2025) (DEVIATION)

E.2 52.216-1 TYPE OF CONTRACT (NOV 2025) (DEVIATION)

E.3 52.240-90 SECURITY PROHIBITIONS AND EXCLUSIONS REPRESENTATIONS

AND CERTIFICATIONS (NOV 2025) (DEVIATION)

E.4 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB

1998)

E.5 VAAR 852.239-75 INFORMATION AND COMMUNICATION TECHNOLOGY

ACCESSIBILITY NOTICE (FEB 2023)

E.6 52.212-2 EVALUATION—COMMERCIAL ITEMS (JAN 1999)

E.7 52.225-2 BUY AMERICAN CERTIFICATE (OCT 2022)

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C263

NETWORK CONTRACTING OFFICE 23

1303 5TH STREET, SUITE 300

CORALVILLE IA 52241

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[x] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or

[] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [x] Upon completion

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

https://www.tungsten-network.com

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO DATE

B.2 Performance Work Statement (PWS) Performance Work Statement (PWS)

Upgrade Building 27 Warehouse Security System and Access Controls VA Central Iowa Health Care System

3600 th St, Des Moines, IA, 50310

1. General Description of Work

1.1. VA Central Iowa Health Care System (VACIHCS) requires a Contractor to furnish all labor, materials, equipment, supervision, testing, programming, documentation, training, and incidentals necessary to upgrade the Building 27 Warehouse security system and access controls.

The Contractor shall remove existing access control devices as specified and install new Hirsch Scrambleprox readers – three in total – at designated entry points. Additionally, the Contractor shall replace existing card readers and install five motion detectors, including four located in Warehouse Room 1002 and one in Corridor C1000, to ensure comprehensive motion detection coverage. A complete automatic door operator with relay control and ADA-accessible push button shall be installed for the interior double doors at Door D, providing secure access and egress functionality. The Contractor shall furnish and install Hirsch input and relay boards, as well as supply and install all associated cabling, conduit, and junction boxes, totaling approximately 470 linear feet. All new devices – including readers, detectors, door operators, and boards – must be fully integrated into the existing Hirsch access control system. The Contractor is also responsible for providing labeling, programming, testing, and all final documentation in compliance with VA security, safety, and IT standards.

1.2. The period of performance for this project is thirty (30) calendar days from the Notice to Proceed (NTP), which includes site investigation, procurement, installation, system integration, testing, end-user training, and close-out documentation.

2. Problem Statement

2.1. The VA Building 27 Warehouse at VACIHCS lacks adequate intrusion detection coverage and updated access controls at multiple entry points. Existing card readers require replacement with compatible Hirsch Scrambleprox models. An interior double door lacks secure access control and ADA egress capability. All system upgrades shall provide reliable reporting of access and alarm events to VA Police and connect to the current Hirsch system in the IT Room.

3. Contract Deliverables Note: Reference to door labelling, approximate locations, and deliverable summaries are available in Attachment A: Warehouse Diagram with Door Labels. This attachment is provided for reference only and does not outline all Performance work statement deliverables. The Contractor is responsible for fully reviewing and complying with all contract deliverables and requirements as detailed in Section 3: Contract Deliverables and Section 4: Contract Equipment Installation Constraints and Requirements of this Performance work statement.

3.1. Card Reader and Access Hardware Deliverable

3.1.1. Remove and replace card reader at Door A (Northwest side, Building 27) with new Scrambleprox reader in a covered mounting box.

3.1.2. Remove and replace exterior card reader at Door C (double doors, northeast exterior, Building 27) with new Scrambleprox reader in a covered mounting box.

3.1.3. Relocate and reinstall card reader from Door A to Door D (double doors, northeast interior, Building 27); install covered mounting box.

3.1.4. Install new Scrambleprox card reader at Door E (southwest exterior, Building 27) in a covered mounting box.

3.2. Automatic Door Operator Deliverable

3.2.1. Install new automatic door operator and relay interface for Door D (interior double doors)

3.2.2. System shall permit entry from hallway into Warehouse (Corridor C1000) via card reader;

exit from warehouse shall be permitted via ADA-accessible push-button installed in Corridor C1000.

3.2.3. Operator must be fully integrated and compatible with existing Hirsch relay output board and physical access security system.

3.3. Motion Detection Deliverable

3.3.1. Install four motion detectors in Warehouse Room 1002 for complete interior motion coverage.

3.3.2. Install one motion detector in Corridor C1000, placed to monitor corridor entry/exit, perpendicular to entry/exit on the east end of Corridor C1002.

3.4. System Integration and Boards Deliverable

3.4.1. Furnish and install all cabling, wiring, conduit, cable trays, and junction boxes required for new devices. Integrate required electrical to the Electrical Room (Room 1017).

3.4.2. Furnish and install Hirsch alarm input boards and relay output boards as needed. Integrate with existing Hirsch panel in IT Room (Room 1019).

3.4.3. All system programming, device enrollment, commissioning, and full event alarm reporting to VA Police.

3.5. Labelling and Documentation Deliverable

3.5.1. The Contractor shall label all cabling, conduit, trays, devices, panels, and junction boxes per

VA/NECA standards.

3.5.2. Deliver closeout submittals including product data, final labelling schedule, and alarm integration documentation to the Contracting Officer Representative in PDF format via email.

3.6. Fire Caulking/Firestopping Deliverable

3.6.1. The Contractor shall provide and install rated fire caulking and/or other approved firestopping material at any location where penetrations are made through a fire-rated barrier, including but not limited to walls, floors, and ceilings. All firestopping shall be performed in accordance with VA, NFPA, and local fire protection codes and shall restore the fire-resistance rating of the barrier.

3.7. End-User Training Deliverable

3.7.1. The Contractor shall provide training to VA warehouse staff and designated personnel on the operation, arming/disarming, and reporting features of the upgraded access control system. Training shall be conducted prior to project acceptance. Designated personnel will be identified by the COR following the Notice to Proceed.

4. Contract Equipment Installation Restraints and Requirements

4.1. Hours of Work on VACIHCS Property Requirement

4.1.1. All work under this contract shall be performed during normal business hours, defined as 8:00 AM to 3:30 PM CST, Monday through Friday, excluding Federal holidays, unless otherwise approved in writing by the Contracting Officer (CO) and Contracting Officer Representative (COR). No work shall be performed on VACIHCS property outside of these hours without advance written authorization from CO and COR.

4.2. Contract Schedule and Station-Level Notification Requirements

4.2.1. The Contractor must submit a detailed project schedule within seven (7) calendar days of the NTP, showing procurement, installation, programming, testing, integration, and documentation milestones.

4.2.2. The Contractor shall notify the Contracting Officer Representative (COR) in writing, via email, at least three (3) calendar days prior to commencing any work within the Building 27 Warehouse space at VACIHCS. Failure to provide timely and proper notification may result in the COR postponing the start of work to their discretion, without incurring any additional costs to the Government for Contractor delays or rescheduling.

4.3. Safety Requirements

4.3.1. Contractor shall designate in writing an OSHA-certified Competent Person (CP) for site safety oversight; provide evidence of OSHA 30-hour Construction Safety training for CP;

OSHA 10-hour training for all other staff within seven (7) calendar days of the Notice to Proceed (NTP).

4.3.2. CP/Superintendent must be present onsite for all work involving contract deliverables, as described in Section 3: Contract Deliverables.

4.3.3. The Contractor is solely responsible for the safety of their own employees, subcontractors, and any personnel under their direction while performing work on VACIHCS property.

This includes compliance with all federal, state, local, and VA safety regulations and standards, and ensuring all required certifications and training are current and in place.

4.3.4. The Contractor shall organize and execute all work associated with the contract deliverables and requirements in full compliance with all applicable VA directives and regulation, as well as all relevant federal, state, and local laws.

4.3.5. The Contractor shall ensure that safe egress and access to the building and all required exits are always maintained during contract activities. Any temporary modifications to access or egress routes must be reviewed and approved by the COR in advance.

4.4. Contractor Personnel Conduct and Site Cleanliness Requirement

4.4.1. Contractor and subcontractor personnel shall always maintain professional conduct and attire while on VA property and shall keep their work areas clean and free of debris. All work areas must be returned to a clean and safe condition at the end of each workday.

4.5. Environmental Protection Requirements

4.5.1. The Contractor shall properly dispose of or recycle removed devices, packaging, and construction debris in compliance with VA and local environmental regulations.

4.6. Utility Outage Documentation and Notification Requirements

4.6.1. If work requires a utility outage affecting building services (such as electrical, IT, fire alarm, or other critical systems), the Contractor shall notify the Contracting Officer Representative (COR) in writing at least five (5) calendar days prior to the required outage.

The Contractor shall not proceed with any work necessitating a utility outage until the COR has reviewed the request and provided the necessary outage memorandum or written approval. All utility interruptions shall be minimized and coordinated to avoid disruption of critical VA operations.

4.7. Security and Badging Requirements

4.7.1. Contractor personnel must obtain and display VA-provided badges at all times while on site.

4.7.2. Contractor is responsible for proper management and return of all badges issued;

lost/unreturned badges may incur replacement charges.

4.7.3. The Contractor is responsible for notifying the COR whenever work within an IT room is required. COR provided escorts may be required while working within this space.

Notification for work within IT spaces shall be communicated from the Contractor to the COR in writing, via email, no later than two (2) calendar days prior to the start of work.

4.8. Coordination with VA Police Requirement

4.8.1. The Contractor shall coordinate all work that may impact facility security operations, alarms, or lock-down procedures with VA Police and the COR at least two (2) calendar days in advance. This includes any work affecting access controls, intrusion detection systems, perimeter security, or emergency communication systems. The Contractor shall comply with directives from VA Police regarding procedures and schedules for such work.

4.9. Contractor Laydown and Staging Space

4.9.1. No formal construction laydown space will be provided by the VA for this contract. The

Contractor is responsible for securing and managing their own storage (if necessary) and staging areas for materials, equipment, and tools. Any temporary staging within VA property shall be communicated in writing, via email within seven (7) calendar days of the Notice to Proceed (NTP). Temporary staging shall not impede facility operations, pedestrian traffic, or emergency egress.

4.10. Submittals Requirement

4.10.1. Contractor shall submit product sheet data, cut sheets, and catalog information for all hardware, cabling, and firestopping materials for VA approval prior to the commencement of work.

4.11. Contractor Provided 1-Year Warranty Requirement

4.11.1. The Contractor shall provide a minimum one-year warranty on workmanship and installed equipment, commencing at final acceptance. Related equipment, shipping, handing, and labor costs for necessary replacements shall be borne by the Contractor.

4.12 Network Connection and Cybersecurity Requirements

4.12.1. Any device, hardware, or software connected to the VA network, including but not limited to access control panels, relay or alarm boards, and operator workstations, must conform to all applicable VA, OIT, and federal cybersecurity directives, standards, and practices.

4.12.2. The Contractor shall not connect any equipment or device to the VA network without prior written approval from the VA Office of Information and Technology (OIT) and the facility Information Security Officer (ISO). The Contractor must schedule and coordinate all network connections and integrations with OIT and the COR in advance.

4.12.3. The Contractor shall ensure factory default credentials are removed, implement strong passwords as specified by VA guidelines, and disable any unnecessary network services or ports on all connected devices.

4.12.4. Any security incident, suspected breach, or unauthorized access to VA systems must be reported immediately to the CO, COR, VA OIT, and the facility ISO in accordance with VA Handbook 6500 and 6500.6.

4.13. Contractor Protection of VACIHCS Property Requirements

4.13.1. The Contractor shall coordinate work to avoid interference with existing fire suppression, lighting, and IT systems.

4.13.2. The Contractor is responsible for repairing or replacing, at no additional cost to the

Government, any existing equipment, infrastructure, or property that is damaged as a result of their work activities. All repairs or replacements shall restore affected items to their original condition or better, to satisfaction of the Government.

5. Performance Work Statement (PWS) Table

Performance Objective Performance Standard Surveillance Method AQL Install all required card readers (Doors A, C, D relocation, and E)

Proper model, covered box, and full functional integration

100% Inspection;

Functional Testing 100%

Install automatic door operator & ADA egress button at Door D

Fully integrated into Hirsch relay output board

Functional/Operational Test 100%

Install 5 motion detectors Proper placement, alarm reporting to VA Police Witness Testing 100%

Install all conduit, cabling, junction boxes (~470 ft)

Installed per VA/NECA/electrical standards

Random & Periodic Inspections

95% workmanship; all deficiencies corrected

Install input and relay boards; integrate to existing Hirsch panel

All events report correctly to VA Police

Functional Testing; COR Inspection 100%

Label all devices, cabling, trays, and panels

Labels per VA/NECA standards 100% Inspection 100%

Submit product data, labeling schedule, integration documentation

Complete and accurate PDF package COR Review 100%

Maintain OSHA-compliant safety staffing

CP onsite; training certifications submitted Document Review 100%

Maintain work hours (0800– 1530, M–F)

Compliance with VA facility requirements Daily Logs 100%

Provide required advance notifications (3-day, 2-day, 5-day)

All notifications delivered on time COR Verification 100%

Obtain OIT/ISO approval before network connection

Approval documented in writing Documentation Review 100%

Maintain clean work area and proper debris disposal

No debris; disposal per VA guidelines Daily Inspection 95% daily / 100% final

Deliver end-user training before acceptance

Complete training with materials provided COR Observation 100%

APPENDIX C — VA INFORMATION AND INFORMATION SYSTEM SECURITY AND

PRIVACY LANGUAGE FOR INCLUSION IN CONTRACTS, AS APPROPRIATE

1.GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.

2.VA INFORMATION CUSTODIAL LANGUAGE.

a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.

b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.

c.VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.

d.VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.

e. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.

f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.

g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.

h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.

I. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about VA information and information systems to the VA CO for response.

k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above-mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response.

l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.

m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.

n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.

o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA. The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.

p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in.

Exceptions to this paragraph will only be granted with the written approval of the VA CO.

3.ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS.

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.

b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.

c.All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP.

Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d);

Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

e. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:

(1)Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.

C-4

(2)Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.

(3)Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.

(4)Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.

(5)Contractor/subcontractor personnel have their authorization to work in the United States revoked.

(6)Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.

f. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

g. Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA.

This property includes (but is not limited to) documents, electronic equipment, keys, and parking passes.

PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.

4.TRAINING.

a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems:

(1)VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) 10176) initially and annually thereafter.

(2)Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and

(3)Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role-based information security training].

b. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.

5.SECURITY INCIDENT INVESTIGATION.

a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.

b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:

(1)The date and time (or approximation of) the Security Incident occurred.

(2)The names of individuals involved (when applicable).

(3)The physical and logical (if applicable) location of the incident.

(4)Why the Security Incident took place (i.e., catalyst for the failure).

(5)The amount of data belonging to VA believed to have been compromised.

(6)The remediation measures the contractor is taking to ensure no future incidents of a similar nature.

c. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.

d.VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.

e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

f. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.

g. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information.

When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.

h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages—Reimbursement for Data Breach Costs.

6.INFORMATION SYSTEM DESIGN AND DEVELOPMENT. – not required per 6500.6 checklist

7.INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE. – not required per 6500.6 checklist

8.SECURITY AND PRIVACY CONTROLS COMPLIANCE TESTING, ASSESSMENT

AND AUDITING. – not required per 6500.6 checklist

9.PRODUCT INTEGRITY, AUTHENTICITY, PROVENANCE, ANTI-COUNTERFEIT

AND ANTI-TAMPERING.

a. The contractor shall comply with Code of Federal Regulations (CFR) Title 15 Part 7, “Securing the Information and Communications Technology and Services (ICTS) Supply Chain”, which prohibits ICTS Transactions from foreign adversaries. ICTS Transactions are defined as any acquisition, importation, transfer, installation, dealing in or use of any information and communications technology or service, including ongoing activities, such as managed services, data transmission, software updates, repairs or the platforming or data hosting of applications for consumer download.

b. When contracting terms require the contractor to procure equipment, the contractor shall purchase or acquire the equipment from an Original Equipment Manufacturer (OEM) or an authorized reseller of the OEM. The contractor shall attest that equipment procured from an OEM or authorized reseller or distributor are authentic. If procurement is unavailable from an OEM or authorized reseller, the contractor shall submit in writing details of the circumstances prohibiting this from happening and procure a product waiver from the VA COR/CO.

c.All contractors shall establish, implement, and provide documentation for risk management practices for supply chain delivery of hardware, software (to include patches) and firmware provided under this agreement. Documentation will include chain of custody practices, inventory management program, information protection practices, integrity management program for sub-supplier provided components, and replacement parts requests. The contractor shall make spare parts available. All contractor(s) shall specify how digital delivery for procured products, including patches, will be validated and monitored to ensure consistent delivery. The contractor shall apply encryption technology to protect procured products throughout the delivery process.

d .If a contractor provides software or patches to VA, the contractor shall publish or provide a hash conforming to the FIPS Security Requirements for Cryptographic Modules (FIPS 140-2 or successor).

e. The contractor shall provide a software bill of materials (SBOM) for procured (to include licensed products) and consist of a list of components and associated metadata which make up the product.

SBOMs must be generated in one of the data formats defined in the National Telecommunications and Information Administration (NTIA) report “The Minimum Elements for a Software Bill of Materials

(SBOM).”

f. Contractors shall use or arrange for the use of trusted channels to ship procured products, such as U.S.

registered mail and/or tamper-evident packaging for physical deliveries.

g. Throughout the delivery process, the contractor shall demonstrate a capability for detecting unauthorized access (tampering).

h. The contractor shall demonstrate chain-of-custody documentation for procured products and require tamper-evident packaging for the delivery of this hardware.

10.VIRUSES, FIRMWARE AND MALWARE. – not required per 6500.6 checklist

11.CRYPTOGRAPHIC REQUIREMENT. – not required per 6500.6 checklist

12.PATCHING GOVERNANCE. – not required per 6500.6 checklist

13.SPECIALIZED DEVICES/SYSTEMS (MEDICAL DEVICES, SPECIAL PURPOSE

SYSTEMS, RESEARCH SCIENTIFIC COMPUTING).

a. Contractor supplies/delivered Medical Devices, Special Purpose Systems-Operational Technology (SPS-OT) and Research Scientific Computing Devices shall comply with all applicable Federal law, regulations, and VA policies. New developments require creation, testing, evaluation, and authorization in compliance with processes specified on the Specialized Device Cybersecurity Department Enterprise Risk Management (SDCD-ERM) Portal, VA Directive 6550, Pre-Procurement Assessment and Implementation of Medical Devices/Systems, VA Handbook 6500, and the VA Information Security Knowledge Service. Deviations from Federal law, regulations, and VA Policy are identified and documented as part of VA Directive 6550 and/or the VA Enterprise Risk Analysis (ERA) processes for Specialized Devices/Systems processes.

b. All contractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500 and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO for governance or resolution.

c. The contractor shall certify to the COR/CO that devices/systems that have completed the VA Enterprise Risk Analysis (ERA) process for Specialized Devices/Systems are fully functional and operate correctly as intended. Devices/systems must follow the VA ERA authorized configuration prior to acquisition and connection to the VA computing environment. If VA determines a new VA ERA needs to be created, the contractor shall provide required technical support to develop the configuration settings. Major changes to a previously approved device/system will require a new ERA.

d. The contractor shall comply with all practices documented by the Food Drug and Administration (FDA) Premarket Submission for Management of Cybersecurity in Medical Devices and Postmarket Management of Cybersecurity in Medical Devices.

e. The contractor shall design devices capable of accepting all applicable security patches with or without the support of the contractor personnel. If patching can only be completed by the contractor, the contractor shall commit the resources needed to patch all applicable devices at all VA locations. If unique patching instructions or packaging is needed, the contractor shall provide the necessary information in conjunction with the validation/testing of the patch. The contractor shall apply security patches within 30 business days of the patch release and have a formal tracking process for any security patches not implemented to include explanation when a device cannot be patched.

f. The contractor shall provide devices able to install and maintain VA-approved antivirus capabilities with the capability to quarantine files and be updated as needed in response to incidents. Alternatively, a

VA-approved whitelisting application may be used when the contractor cannot install an anti-virus / anti-malware application.

g. The contractor shall verify and document all software embedded within the device does not contain any known viruses or malware before delivery to or installation at a VA location.

h. Devices and other equipment or systems containing media (hard drives, optical disks, solid state, and storage via chips/firmware) with VA sensitive information will be returned to the contractor with media removed. When the contract requires return of equipment, the options available to the contractor are the following:

(1)The contractor shall accept the system without the drive, firmware and solid state.

(2)VA’s initial device purchase includes a spare drive or other replacement media which must be installed in place of the original drive at time of turn-in; or

(3)Due to the highly specialized and sometimes proprietary hardware and software associated with the device, if it is not possible for VA to retain the hard drive, firmware, and solid state, then:

(a)The equipment contractor shall have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact.

(b)Any fixed hard drive, Complementary Metal-Oxide-Semiconductor (CMOS), Programmable Read- Only Memory (PROM), solid state and firmware on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be pre-approved and described in the solicitation, contract, or order.

14. DATA CENTER PROVISIONS. – not required per 6500.6 checklist

B.3 PRICE/COST SCHEDULE

ITEM

NUMBER

DESCRIPTION OF

SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

470.00 FT __________________ __________________

Wire/cable labelling (printed sleeves/markers)

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths) PRODUCT/SERVICE CODE: J063 - Maintenance, Repair, and Rebuilding of Equipment - Alarm, Signal, and Security Detection Systems

5.00 EA __________________ __________________

Security Motion Detectors (Bosch/Identiv)

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

2.00 EA __________________ __________________

Securitron M62 Magnetic Lock

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

3.00 EA __________________ __________________

Power supplies for hardware, UL listed with backup

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

2.00 EA __________________ __________________

Patch cords, patch panel accessories

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

Multi-conductor Access/Power Cable (Belden 18/4)

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

1.00 EA __________________ __________________

Miscellanous Hardware (tools, plates, ancillaries)

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

Maglock Power Supply/Relay/Brackets

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

8.00 EA __________________ __________________

Junction/electrical boxes and tamper hardware

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

Hirsch/Identiv Card Reader

PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except Locksmiths)

3.00 EA __________________ __________________

Hirsch Scramblepad…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .