MAS - Gcyber LLC - 47QTCA18D00AG

PDF 389 KB

Attached to
Federal Supply Schedule 47QTCA18D00AG Federal contract IDV
Contract number
47QTCA18D00AG
Issued by
GSA Federal Acquisition Service

About this file

This document outlines a federal supply schedule for information technology professional services and highly adaptive cybersecurity services. The contract was awarded on April 16, 2018 to GCyber, LLC with a potential value of $5,283,830. It has a period of performance from April 16, 2023 through April 15, 2028 with an ultimate end date of April 15, 2038.

The schedule provides labor categories, hourly and fixed rates for IT professional services including applications systems analysts, software engineers, network administrators, and project managers. It also includes rates for highly adaptive cybersecurity services such as risk and vulnerability assessments, penetration testing, incident response, and cyber hunt activities. Offerors must participate in an oral technical evaluation for the cybersecurity special item number and may be placed in subcategories like high value asset assessments.

Gcyber, LLC Pricelist and/or Vendor Terms and Conditions for 47QTCA18D00AG, a Federal Supply Schedule awarded to Gcyber, LLC, under Information Technology Schedule 70 (IT-70)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

www.gcyber.com 1 sales@gcyber.com

GENERAL SERVICES ADMINISTRATION

FEDERAL SUPPLY SERVICE MULTIPLE AWARD SCHEDULE (MAS)

AUTHORIZED FEDERAL SUPPLY SCHEDULE PRICE LIST

On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic delivery order is available through GSA Advantage!, a menu-driven database system. The INTERNET address for GSA Advantage! is http://www.gsaadvantage.gov. Prices Shown Herein are Net (discount deducted).

CONTRACT No. 47QTCA18D00AG

Special Item No. 54151S Information Technology Professional Services Ancillary Supplies and/or Services

54151HACS Penetration Testing Incident Response Cyber Hunt Risk and Vulnerability Assessments High Value Asset Assessments

Order Level Materials (OLM)

For more information on ordering from Federal Supply Schedules click on the FSS Schedules button at fss.gsa.gov http://www.gcyber.com/ mailto:sales@gcyber.com http://www.gsaadvantage.gov/ www.gcyber.com 2 sales@gcyber.com

Contractor GCyber, LLC 1950 Old Gallows Rd, Suite 555 Vienna, VA 22182 571-279-8270 www.gcyber.com

Contractor Point of Contact Brooke Newbern Christakos Director, Business Operations 1950 Old Gallows Rd, Suite 555 Vienna, VA 22182 571-279-8270 bnewbern@gcyber.com bchristakos@gcyber.com

Period of Performance 4/16/2023 – 4/15/2028 (Option 1) Ultimate Contract End Date 4/15/2038

Business Size Small Business

CONTRACTOR INFORMATION

1. Schedule Information

1a. Table of Awarded Special Item Numbers 54151S Information Technology Professional Services

54151HACS Penetration Testing

Incident Response

Cyber Hunt

Risk and Vulnerability Assessments

High Value Asset Assessments

Ancillary Supplies and/or Services

Order Level Materials (OLM)

1b. Lowest Priced Model Number and Price for Each Awarded SIN See Price List

1c. Hourly Rates (Services Only) See Price List

1d. Labor Category Descriptions (Services Only) See Price List

2. Maximum Order Threshold 54151S $500,000

54151HACS $500,000

http://www.gcyber.com/ mailto:bnewbern@gcyber.com mailto:bchristakos@gcyber.com www.gcyber.com 3 sales@gcyber.com

NOTE TO ORDERING ACTIVITIES: If the best value selection places your order over the applicable Maximum Order Threshold, you have an opportunity to obtain a better schedule contract price.

Before placing your order, contact the Contactor for a better price. The Contractor may (1) offer a new price for this requirement, (2) offer the lowest price available under this contract, or (3) decline the order. A delivery order that exceeds the maximum order may be placed under the schedule contract in accordance with FAR 8.404.

3. Minimum Order Threshold $100.00 (all SINs)

4. Geographic Coverage Continental US, Hawaii, Puerto Rico

5. Point(s) of Production Arlington, VA

6. Discount from Best Market Rate GSA Net Prices can be found in Pricing Matrixes (below). Negotiated discounts have been applied and the Industrial Funding Fee has been added.

7. Quantity Discounts None

8. Prompt Payment Terms Net 30. Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions.

9. Government Purchase Cards 9a will be accepted at or below the micro-purchase threshold 9b will not be accepted above the micro-purchase threshold.

10. Foreign Items None

11. Delivery

11a. Time of Delivery Determined at Task Level

11b. Expedited Delivery Determined at Task Level. Items available for expedited delivery are noted in the price list.

11c. Overnight and 2-Day Delivery Determined at Task Level. Schedule Customers can contact the Contractor for rates for overnight and 2-day delivery.

11d. Urgent Requirements www.gcyber.com 4 sales@gcyber.com

Agencies can contact the Contractor’s representative to affect a faster delivery.

Customers are encouraged to contact the Contractor for the purpose of requesting accelerated delivery.

12. FOB Point Destination

13. Ordering

13a. Ordering Address GCyber, LLC 241 18th Street South, Suite 504 Arlington, VA 22202

13b. Ordering Procedures Ordering activities shall use the ordering procedures described in Federal Acquisition Regulation 8.405-3 when placing an order or establishing a BPA for supplies or services.

The ordering procedures, information on Blanket Purchase Agreements, and a sample BPA can be found at the GSA/FSS Schedule Homepage www.fss.gsa.gov/schedules.

14. Payment Address GCyber, LLC 241 18th Street South, Suite 504 Arlington, VA 22202

15. Warranty Provision Standard Commercial

16. Export Packing Charges None

17. Terms and Conditions of Government Purchase Card Acceptance None

18. Terms and Conditions of Rental, Maintenance, and Repaid (if applicable) Not Applicable

19. Terms and Conditions of Installation (if applicable) Not Applicable

20. Terms and Conditions of Repaid Parts Indicating Date of Parts Price Lists and Any Discounts from List Prices (if available) Not Applicable

21a. Terms and Conditions for Any Other Services (if applicable) See Appendix A

21. List of Services and Distribution Points (if applicable) Not Applicable http://www.gcyber.com/ http://www.fss.gsa.gov/schedules www.gcyber.com 5 sales@gcyber.com

22. List of Participating Dealers (if applicable) Not Applicable

23. Preventive Maintenance (if applicable) Not Applicable

24. Special Attributes

24a. Environment Attributes (e.g., recycled content, energy efficiency, and/or reduced pollutants)

Not Applicable

24b. Section 508 Compliance for Electronic and Information Technology (EIT) Compliant. EIT standards can be found at www.Section508.gov.

25. Unique Entity Identifier (UEI) Number

PH6DGRL6EW34

26. Notification Regarding Registration in System for Award Management (SAM) Database The Contractor has an active registration in the System for Award Management (SAM) database.

http://www.gcyber.com/ http://www.section508.gov/ www.gcyber.com A-1 sales@gcyber.com

APPENDIX A

Terms and Conditions Applicable to Information Technology (IT) Professional Services (Special Item Number 54151S, formerly 132-51)

All offerors must follow the evaluation criteria and instructions outlined in the MAS solicitation, including in SCP-FSS-001. The Information Technology Category Attachment outlines additional evaluation criteria, requirements, and information specific to this category only. For a list of required

Schedule templates and attachments, please visit www.gsa.gov/mascategoryrequirements.

1 SCOPE

a. The prices, terms, and conditions stated under Special Item Number 132-51 Information

Technology Professional. Services apply exclusively to IT Professional Services within the scope of this Information Technology Schedule.

b. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.

2 PERFORMANCE INCENTIVES I-FSS-60 Performance Incentives (April 2000)

a. Performance incentives may be agreed upon between the Contractor and the ordering activity on individual fixed price orders or Blanket Purchase Agreements under this contract.

b. The ordering activity must establish a maximum performance incentive price for these services and/or total solutions on individual orders or Blanket Purchase Agreements.

c. Incentives should be designed to relate results achieved by the contractor to specified targets.

To the maximum extent practicable, ordering activities shall consider establishing incentives where performance is critical to the ordering activity’s mission and incentives are likely to motivate the contractor. Incentives shall be based on objectively measurable tasks.

3 ORDER

a. Agencies may use written orders, EDI orders, blanket purchase agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made, and the contract terms and conditions shall continue in effect until the completion of the order.

Orders for tasks which extend beyond the fiscal year for which funds are available shall include

FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.

b. All task orders are subject to the terms and conditions of the contract. In the event of a conflict between a task order and the contract, the contract will take precedence.

4 PERFORMANCE OF SERVICES

www.gcyber.com A-2 sales@gcyber.com

a. The Contractor shall commence the performance of services on the date agreed to by the

Contractor and the ordering activity.

b. The Contractor agrees to render services only during normal working hours unless otherwise agreed to by the Contractor and the ordering activity.

c. The ordering activity should include the criteria for satisfactory completion for each task in the

Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.

Any Contractor travel required in the performance of IT Services must comply with the Federal Travel

Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed.

Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts.

5 STOP-WORK ORDER (FAR 52.242-15) (AUG 1989)

a. The Contracting Officer may, at any time, by written order to the Contractor, require the

Contractor to stop all, or any part, of the work called for by this contract for a period of 90 days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of the work stoppage. Within a period of 90 days after a stop-work is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the Contracting Officer shall either-

i. Cancel the stop-work order; or

ii. Terminate the work covered by the order as provided in the Default, or the Termination for

Convenience of the Government, clause of this contract.

b. If a stop-work order issued under this clause is canceled or the period of the order or any extension thereof expires, the Contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule, contract price, or both, and the contract shall be modified, in writing, accordingly, if-

i. The stop-work order results in an increase in the time required for, or in the Contractor's cost properly allocable to, the performance of any part of this contract; and

ii. The Contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage; provided, that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and act upon the claim submitted at any time before final payment under this contract.

c. If a stop-work order is not canceled and the work covered by the order is terminated for the convenience of the Government, the Contracting Officer shall allow reasonable costs resulting from the stop-work order in arriving at the termination settlement.

www.gcyber.com A-3 sales@gcyber.com

d. If a stop-work order is not canceled and the work covered by the order is terminated for default, the Contracting Officer shall allow, by equitable adjustment or otherwise, reasonable costs resulting from the stop-work order.

6 INSPECTION OF SERVICES

In accordance with FAR 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (MAR

2009) (DEVIATION I - FEB 2007) for Firm-Fixed Price orders and FAR 52.212-4 CONTRACT TERMS AND

CONDITIONS COMMERCIAL ITEMS (MAR 2009) (ALTERNATE I OCT 2008) (DEVIATION I – FEB 2007) applies to Time-and-Materials and Labor-Hour Contracts orders placed under this contract.

7 RESPONSIBILITIES OF THE CONTRACTOR

The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR 52.227-14 (Dec

2007) Rights in Data – General, may apply.

8 RESPONSIBILITIES OF THE ORDERING ACTIVITY

Subject to security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite IT Professional Services.

9 INDEPENDENT CONTRACTOR

All IT Professional Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.

10 ORGANIZATIONAL CONFLICTS OF INTEREST

a. Definitions.

“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.

“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.

An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the

Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.

b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might www.gcyber.com A-4 sales@gcyber.com otherwise exist in situations related to individual orders placed against the schedule contract.

Examples of situations which may require restrictions, are provided at FAR 9.508.

11 INVOICES

The Contractor, upon completion of the work ordered, shall submit invoices for IT Professional Services.

Progress payments may be authorized by the ordering activity on individual orders if appropriate.

Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.

12 PAYMENTS

For firm-fixed price orders the ordering activity shall pay the Contractor, upon submission of proper invoices or vouchers, the prices stipulated in this contract for service rendered and accepted. Progress payments shall be made only when authorized by the order. For time and materials orders, the

Payments under Time and Materials and Labor Hour Contracts at FAR 52.212-4 (MAR 2009) (ALTERNATE

I – OCT 2008) (DEVIATION I – FEB 2007) applies to time and materials orders placed under this contract.

For labor hour orders, the Payment under Time and Materials and Labor Hour Contracts at FAR 52.212-4

(MAR 2009) (ALTERNATE I – OCT 2008) (DEVIATION I – FEB 2007) applies to labor hour orders placed under this contract. 52.216-31(Feb 2007) Time-and-Materials/Labor-Hour Proposal Requirements—

Commercial Item Acquisition. As prescribed in 16.601(e)(3), insert the following provision:

a. The Government contemplates award of a Time-and-Materials or Labor-Hour type of contract resulting from this solicitation.

b. The offeror must specify fixed hourly rates in its offer that include wages, overhead, general and administrative expenses, and profit. The offeror must specify whether the fixed hourly rate for each labor category applies to labor performed by—

i. The offeror.

ii. Subcontractors; and/or

iii. Divisions, subsidiaries, or affiliates of the offeror under common control.

13 RESUMES

Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.

14 INCIDENTAL SUPPORT COSTS

Incidental support costs are available outside the scope of this contract. The costs will be negotiated separately with the ordering activity in accordance with the guidelines set forth in the FAR.

15 APPROVAL OF SUBCONTRACTS

The ordering activity may require that the Contractor receive, from the ordering activity's Contracting

Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.

16 DESCRIPTION OF IT PROFESSIONAL SERVICES AND PRICING

www.gcyber.com A-5 sales@gcyber.com

a. The Contractor shall provide a description of each type of IT Service offered under Special Item

Numbers 132-51 IT Professional Services should be presented in the same manner as the

Contractor sells to its commercial and other ordering activity customers. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles (labor categories) for those individuals who will perform the service should be provided.

b. Pricing for all IT Professional Services shall be in accordance with the Contractor’s customary commercial practices, e.g., hourly rates, monthly rates, term rates, and/or fixed prices, minimum general experience, and minimum education.

www.gcyber.com A-6 sales@gcyber.com

Terms and Conditions Applicable to Highly Adaptive Cybersecurity Services (HACS) (Special Item Number 54151HACS, formerly 132-45)

All offerors must follow the evaluation criteria and instructions outlined in the MAS solicitation, including in SCP-FSS-001. The Information Technology Category Attachment outlines additional evaluation criteria, requirements, and information specific to this category only. For a list of required

Schedule templates and attachments, please visit www.gsa.gov/mascategoryrequirements.

For additional guidance and information for Schedule buyers and sellers, please visit our general guidance page at www.gsa.gov/schedules.

54151HACS Includes a wide range of fields such as the seven-step Risk Management Framework services, information assurance, virus detection, network management, situational awareness and incident response, secure web hosting, and backup, security services, and Security Operations Center

(SOC) services. HACS vendors are cataloged under the 5 subcategories of High Value Asset Assessments:

Risk and Vulnerability Assessments, Cyber Hunt, Incident Response, and Penetration Testing.

NOTE: Subject to Cooperative Purchasing

Instructions:

Additional SIN Description: Includes proactive and reactive cybersecurity services that improve customer enterprise-level security posture. Services to identify and protect a customer's information resources, detect and respond to cybersecurity events or incidents, and recover capabilities or services impaired by any incidents that emerge.

It encompasses a wide range of fields that include, but are not limited to, Risk Management Framework

(RMF) services, information assurance (IA), virus detection, network management, situational awareness and incident response, secure web hosting, and backup and security services.

The seven-step RMF includes preparation, information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. RMF activities may also include Information Security Continuous Monitoring Assessment

(ISCMA), which evaluate organization-wide ISCM implementations, and also Federal Incident Response

Evaluations (FIREs), which assess an organization's incident management functions.

It also includes Security Operations Center (SOC) services. The SOC scope includes services such as:

24x7x365 monitoring and analysis, traffic analysis, incident response and coordination, penetration testing, anti-virus management, intrusion detection and prevention, and information sharing.

1) Specific Instructions for SIN 54151HACS – Highly Adaptive Cybersecurity Services (HACS)

a) Offerors may request to be placed in the following subcategories.

i) High Value Asset (HVA) Assessments include Risk and Vulnerability Assessment (RVA) which assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The www.gcyber.com A-7 sales@gcyber.com services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System

Security Assessment (OSSA), Database Assessment, and Penetration Testing. Security

Architecture Review (SAR) evaluates a subset of the agency s HVA security posture to determine whether the agency has properly architected its cybersecurity solutions and ensures that agency leadership fully understands the risks inherent in the implemented cybersecurity solution. The SAR process utilizes in-person interviews, documentation reviews, and leading practice evaluations of the HVA environment and supporting systems.

SAR provides a holistic analysis of how an HVA’s individual security components integrate and operate, including how data is protected during operations. Systems Security

Engineering (SSE) identifies security vulnerabilities and minimizes or contains risks associated with these vulnerabilities spanning the Systems Development Life Cycle. SSE focuses on but is not limited to the following security areas: perimeter security, network security, endpoint security, application security, physical security, and data security.

ii) Risk and Vulnerability Assessment (RVA) assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless

Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing.

iii) Penetration Testing is security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network.

iv) Incident Response services help organizations impacted by a cybersecurity compromise determine the extent of the incident, remove the adversary from their systems, and restore their networks to a more secure state.

v) Cyber Hunt activities respond to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Cyber Hunts start with the premise that threat actors known to target some organizations in a specific industry or with specific systems are likely to also target other organizations in the same industry or with the same systems.

b) Services offered SIN 54151HACS shall be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:

• Federal Acquisition Regulation (FAR) Part 52.204-21

• OMB Memorandum M-17-12 - Preparing for and Responding to a Breach of Personally

Identifiable Information (PII)

• OMB Memorandum M- 19-03 - Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program

• 2017 Report to the President on Federal IT Modernization

• The Cybersecurity National Action Plan (CNAP)

• NIST SP 800-14 - Generally Accepted Principles and Practices for Securing Information

Technology Systems www.gcyber.com A-8 sales@gcyber.com

• NIST SP 800-27A - Engineering Principles for Information Technology Security (A Baseline for

Achieving Security)

• NIST SP 800-30 - Guide for Conducting Risk Assessments

• NIST SP 800-35 - Guide to Information Technology Security Services

• NIST SP 800-37 - Risk Management Framework for Information Systems and Organizations:

A Systems Life Cycle Approach for Security and Privacy

• NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and

Information System View

• NIST SP 800-44 - Guidelines on Securing Public Web Servers

• NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks

• NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and

Organizations

• NIST SP 800-61 - Computer Security Incident Handling Guide

• NIST SP 800-64 - Security Considerations in the System Development Life Cycle

• NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security

• NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident Response

• NIST SP 800-115 - Technical Guide to Information Security Testing and Assessment

• NIST SP 800-128 - Guide for Security-Focused Configuration Management of Information

Systems

• NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for Federal

Information Systems and Organizations

• NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks (WLANs)

• NIST SP 800-160 - Systems Security Engineering: Considerations for a Multidisciplinary

Approach in the Engineering of Trustworthy Secure Systems

• NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal Information

Systems and Organizations.

c) All professional labor categories under SIN 54151S Information Technology Professional Services may remain there unless the labor categories are specific to SIN 54151HACS

2) Oral Technical Evaluation for SIN 54151HACS - Highly Adaptive Cybersecurity Services (HACS)

a) Unless otherwise specified, the offeror shall participate in an oral technical evaluation that will be conducted by a Technical Evaluation Board (TEB). The oral technical evaluation will be held at the unclassified level and will be scheduled by the TEB. The oral technical evaluation will be used to assess the offeror's capability to successfully perform the services within the scope of each subcategory as set forth in this solicitation, excepting those service components awarded through the submission of the Service Self-Attestation. The Self-Attestation form is available at gsa.gov/hacs.

An offeror may only be awarded SIN 54151HACS upon successful completion of the Highly

Adaptive Cybersecurity Services oral technical evaluation. If the offeror elects to be cataloged under the "Cyber Hunt" and/or "Incident Response" subcategories, additional questions related to those areas will be asked during the HACS Oral Technical Evaluation.

www.gcyber.com A-9 sales@gcyber.com

i) ORAL TECHNICAL EVALUATION CONSTRAINTS: The offeror shall identify up to five key personnel, by name and association with the offeror, who will field questions during the oral technical evaluation. The HACS SIN consists of 5 subcategories. The base HACS Oral

Technical Evaluation consists of questions related to the 3 subcategories of, High Value

Asset Assessments, Risk and Vulnerability Assessments and Penetration Testing. One (1) hour and 40 minutes is allotted for the base HACS Oral Technical Evaluation. The evaluation will be stopped precisely after 1 hour and 40 minutes. Should the offer elect to be considered for the additional subcategories of Incident Response and Cyber Hunt, an additional 10 minutes will be allotted for each of those subcategories. The total base evaluation session is expected to last up to 1 hour and 40 minutes, depending on the number of subcategories the offeror is proposing. The TEB Chairperson will be responsible for ensuring the schedule is met and that

ii) ORAL TECHNICAL EVALUATION SCHEDULING: The TEB will contact the offeror's authorized negotiator or the signatory of the SF 1449 via email to schedule the oral technical evaluation. Evaluation time slots will be assigned on a first-come-first-served basis. The

Government reserves the right to reschedule any offeror's oral technical evaluation at its sole discretion. The oral technical evaluation will be held at facilities designated by the TEB.

The exact location, seating capacity, and any other relevant information will be provided when the evaluations are scheduled. The Government may also make accommodations for vendors to participate in the oral evaluations virtually.

iii) PROHIBITION OF ELECTRONIC RECORDING OF THE ORAL TECHNICAL EVALUATION: The offeror may not record or transmit any of the oral evaluation process. All offeror's electronic devices shall be removed from the room during the evaluation. The offeror is permitted to have a timer in the room during the evaluation, provided by the TEB.

iv) RESUBMISSION RESTRICTIONS FOR UNSUCCESSFUL VENDORS UNDER THIS EVALUATION

FACTOR: The TEB will afford the offeror multiple opportunities to achieve the "pass" criteria under this evaluation factor through "clarification" questioning, during the Oral Technical

Evaluation. Any offeror whom the TEB has found to have not passed under this evaluation factor shall be failed and shall be ineligible to re-submit under the SIN to participate in this evaluation factor for a period of six (6) months following the date of failure.

v) HIGH VALUE ASSET (HVA) ASSESSMENTS SUBCATEGORY PLACEMENT: Any offeror previously awarded all of the following four SINs: 132-45A Penetration Testing, 132-45B Incident

Response, 132-45C Cyber Hunt, and 132-45D Risk and Vulnerability Assessment, shall not be subject to a Highly Adaptive Cybersecurity Services oral technical evaluation, so long as they provide in the modification package to the GSA contracting officer a Service Self-Attestation acknowledging their ability to perform Security Architecture Review (SAR) and Systems

Security Engineering (SSE) services in their entirety. The Self-Attestation form is available at gsa.gov/hacs.

b) Oral Technical Evaluation Procedures: The offeror will be evaluated on their knowledge of the proposed services. The oral technical evaluation will require the offeror to respond to a specific scenario and general questions to assess the offeror's expertise. The competencies, criteria and evaluation minimums for the questions are below: All new offerors and modifications must www.gcyber.com A-10 sales@gcyber.com participate in and PASS the HACS Oral Technical Evaluation. The Oral Technical Evaluation will include, at a minimum, questions on Risk and Vulnerability Assessment (RVA), Security

Architecture Review (SAR), Systems Security Engineering (SSE), and Penetration Testing. At the time of submission, all new offerors and modifications can also elect to be cataloged in one or both of the additional subcategories of Cyber Hunt or Incident Response (IR). Should this election be taken, additional questions related to these subcategories will be included in their

HACS evaluation and these additional subcategory topics must be passed as well.

c) Oral Technical Evaluation Criteria: The offeror's responses to the government's questions during the oral technical evaluation session shall be used to determine whether the offeror has the requisite experience and expertise to perform tasks expected to be performed within the scope of the SIN. The oral technical proposal will be evaluated and rated on a pass/fail basis. The rating definitions provided below will be used for the evaluation of the offeror's responses to questions during the oral evaluation.

www.gcyber.com A-11 sales@gcyber.com

Terms and Conditions Applicable to Ancillary Supplies and/or Services (Special Item Number 54151S, Formerly 132-100)

Ancillary supplies and/or services are support supplies and services which are not within the scope of any ITC SIN, and shall be offered under the ANCILLARY SIN, which is offered under the Miscellaneous large category.

Non-professional labor categories must be incidental to and used solely to support hardware, software and/or professional services, and cannot be purchased separately. Non-professional labor categories shall be offered under the ANCILLARY SIN, which is offered under the Miscellaneous large category.

Energy Star or Electronic Product Environmental Assessment Tool (EPEAT) programs. Commercially available products under this solicitation may be covered by the Energy Star or Electronic Product

Environmental Assessment Tool (EPEAT) programs. For applicable products, offerors are encouraged to offer Energy Star-qualified products and EPEAT-registered products, at the Bronze level or higher. If offerors opt to offer Energy Star or Electronic Product Environmental Assessment Tool (EPEAT) products then they shall identify by model which products offered are Energy Star-qualified and EPEAT-registered, broken out by registration level of bronze, silver, or gold. Visit the Green Procurement Compilation, sftool.gov/greenprocurement for a complete list of products covered by these programs.

Instructions: The work performed under this SIN shall be associated with existing SIN(s) under the contract. Ancillary supplies and/or services shall not be the primary purpose of the work ordered but be an integral part of the total solution offered. Ancillary supplies and/or services may only be ordered in conjunction with or in support of supplies or services purchased under another SIN(s). Offerors may be required to provide additional information to support a determination that their proposed ancillary supplies and/or services are commercially offered in support of one or more SIN(s).

The Miscellaneous Category Attachment outlines additional evaluation criteria, requirements, and information specific to this category only. For a list of required Schedule templates and attachments, please visit www.gsa.gov/mascategoryrequirements

Note: When used in conjunction with a Cooperative Purchasing eligible SIN, this SIN is Cooperative

Purchasing Eligible.

Regulation Number Regulation Title/Comments

52.222-46 EVALUATION OF COMPENSATION FOR PROFESSIONAL EMPLOYEES (FEB 1993)

52.222-48 EXEMPTION FROM APPLICATION OF THE SERVICE CONTRACT LABOR STANDARDS TO

CONTRACTS FOR MAINTENANCE, CALIBRATION, OR REPAIR OF CERTAIN EQUIPMENT

CERTIFICATION (MAY 2014)

52.223-2 AFFIRMATIVE PROCUREMENT OF BIOBASED PRODUCTS UNDER SERVICE AND

CONSTRUCTION CONTRACTS (SEP 2013)

52.228-5 INSURANCE - WORK ON A GOVERNMENT INSTALLATION (JAN 1997)

52.229-1 STATE AND LOCAL TAXES (APR 1984)

52.247-68 REPORT OF SHIPMENT (REPSHIP) (FEB 2006)

52.222-62 PAID SICK LEAVE UNDER EXECUTIVE ORDER 13706 (JAN 2017)

52.222-52 EXEMPTION FROM APPLICATION OF THE SERVICE CONTRACT LABOR STANDARDS TO

CONTRACTS FOR CERTAIN SERVICES - CERTIFICATION (MAY 2014)

http://www.gcyber.com/ http://www.gsa.gov/mascategoryrequirements www.gcyber.com A-12 sales@gcyber.com

52.223-11 OZONE-DEPLETING SUBSTANCES AND HIGH GLOBAL WARMING POTENTIAL

HYDROFLUOROCARBONS (JUN 2016)

52.225-18 PLACE OF MANUFACTURE (AUG 2018)

552.238-105 DELIVERIES BEYOND THE CONTRACTUAL PERIOD - PLACING OF ORDERS (MAY 2019)

552.238-107 TRAFFIC RELEASE (SUPPLIES) (MAY 2019)

552.238-86 DELIVERY SCHEDULE (MAY 2019)

552.238-89 DELIVERIES TO THE U.S. POSTAL SERVICE (MAY 2019)

552.238-90 CHARACTERISTICS OF ELECTRIC CURRENT (MAY 2019)

552.238-91 MARKING AND DOCUMENTATION REQUIREMENTS FOR SHIPPING (MAY 2019)

552.238-92 VENDOR MANAGED INVENTORY (VMI) PROGRAM (MAY 2019)

552.238-93 ORDER ACKNOWLEDGMENT (MAY 2019)

552.238-94 ACCELERATED DELIVERY REQUIREMENTS (MAY 2019)

552.238-95 SEPARATE CHARGE FOR PERFORMANCE ORIENTED PACKAGING (POP) (MAY 2019)

552.238-96 SEPARATE CHARGE FOR DELIVERY WITHIN CONSIGNEE'S PREMISES (MAY 2019)

552.238-111 ENVIRONMENTAL PROTECTION AGENCY REGISTRATION REQUIREMENT (MAY 2019

File details come from the government source that posted it. Updated .