MAS - Affinity It LIMITED Liability Company - 47QTCA21D00EE

DOCX document 56 KB

Attached to
Federal Supply Schedule 47QTCA21D00EE Federal contract IDV
Contract number
47QTCA21D00EE
Issued by
GSA Federal Acquisition Service

About this file

This price list provides details on an information technology federal supply schedule contract held by Affinity IT Security Services. The contractor offers professional services and training under SINs 54151S, 611420, and OLM. Key labor categories include Executive Cyber Security Consultant, Cyber Security Consultant III, Cyber Security Consultant II, and Cyber Security Consultant I. Course offerings focus on employee security awareness and securing Java and ASP.NET web applications. The underlying IDV has a contract number 47QTCA21D00EE, was awarded on September 2, 2021 through September 1, 2026 under GSA's Federal Acquisition Service. Pricing is provided for labor categories, courses, and volume discounts with net 30 day payment terms.

Affinity It LIMITED Liability Company (DBA Affinity It Security Services) Pricelist and/or Vendor Terms and Conditions for 47QTCA21D00EE, a Federal Supply Schedule awarded to Affinity It LIMITED Liability Company (DBA Affinity It Security Services), under Multiple Award Schedule (MAS)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

GENERAL SERVICES ADMINISTRATION

Federal Supply Service

Authorized Federal Supply Schedule Price List

On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic delivery order are available through GSA Advantage!®, a menu-driven database system. The INTERNET address GSA Advantage!® is: GSAAdvantage.gov.

Multiple Award Schedule

FSC Group: Information Technology FSC Class: D399 and U012

Contract number: 47QTCA21D00EE

For more information on ordering from Federal Supply Schedules go to the GSA Schedules page at GSA.gov.

Contract period: September 2, 2021, through September 1, 2026

Affinity IT Limited Liability Company dba Affinity IT Security Services 1243 Sussex Turnpike, SUITE 1 Randolph, NJ 07869 800.840.2335 https://affinity-it-security.com/contact-us/

Contract administration source:

Joseph Fisher 973-895-5777 joe@affinity-it.com

Business size: Small Business

Prices Shown Herein are Net (discount deducted)

Price list current as of Modification #PS-0002 effective 2/4/2022

CUSTOMER INFORMATION

1a. Table of awarded special item number(s) with appropriate cross-reference to item descriptions and awarded price(s).

SINs
SIN Title
54151S
Information Technology Professional Services
611420
Information Technology Training
54151HACS
Highly Adaptive Cybersecurity Services (HACS)
OLM
Order-Level Materials (OLM’s)

1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract. This price is the Government price based on a unit of one, exclusive of any quantity/dollar volume, prompt payment, or any other concession affecting price. Those contracts that have unit prices based on the geographic location of the customer, should show the range of the lowest price, and cite the areas to which the prices apply. N/A

1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided. If hourly rates are not applicable, indicate “Not applicable” for this item. See Labor Category Pricing and Labor Category Descriptions

2. Maximum order:

SINs
Maximum Order
54151S
$500,000
611420
$250,000
54151HACS
$500,000
OLM
$250,000

3. Minimum order: $100

4. Geographic coverage (delivery area). Domestic

5. Point(s) of production (city, county, and State or foreign country). Same as company address

6. Discount from list prices or statement of net price. Government Net Prices (discounts already deducted.)

7. Volume discounts. 1.5% for single task orders over $500,000

8. Prompt payment terms. Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions. 1.5% if paid within 15 days: Net 30 days

9. Foreign items (list items by country of origin). Not Applicable

10a. Time of delivery. To Be Determined at the Task Order level

10b. Expedited Delivery. Items available for expedited delivery are noted in this price list. To Be Determined at the Task Order level

10c. Overnight and 2-day delivery. To Be Determined at the Task Order level

10d. Urgent Requirements. To Be Determined at the Task Order level

11. F.O.B. point(s). Destination

12a. Ordering address(es). Same as company address.

12b. Ordering procedures: For supplies and services, the ordering procedures, information on Blanket Purchase Agreements (BPA’s) are found in Federal Acquisition Regulation (FAR) 8.405-3.

13. Payment address(es). Same as company address.

14. Warranty provision. None

15. Export packing charges, if applicable. Not Applicable

16. Terms and conditions of rental, maintenance, and repair (if applicable). Not Applicable

17. Terms and conditions of installation (if applicable). Not Applicable

18a. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable). Not Applicable

18b. Terms and conditions for any other services (if applicable). Not Applicable

19. List of service and distribution points (if applicable). Not Applicable

20. List of participating dealers (if applicable). Not Applicable

21. Preventive maintenance (if applicable). Not Applicable

22a. Special attributes such as environmental attributes (e.g., recycled content, energy efficiency, and/or reduced pollutants). Not Applicable

22b. If applicable, indicate that Section 508 compliance information is available on Electronic and Information Technology (EIT) supplies and services and show where full details can be found (e.g. contractor’s website or other location.) The EIT standards can be found at: www.Section508.gov/.

Not Applicable

23. Data Universal Number System (DUNS) number. 830498684

24. Notification regarding registration in System for Award Management (SAM) database. Contractor registered and active in SAM

Labor Category Pricing

SIN
Labor Category
GSA Price
54151S
Executive Cyber Security Consultant
$229.67
54151S
Cyber Security Consultant III
$190.58
54151S
Cyber Security Consultant II
$141.71
54151S
Cyber Security Consultant I
$117.28
54151HACS
Chief Penetration Testing Officer
$213.10
54151HACS
Penetration Tester III
$188.61
54151HACS
Penetration Tester II
$140.25
54151HACS
Penetration Tester I
$116.07

Service Contract Labor Standards: The Service Contract Labor Standards (SCLS), formerly known as the Service Contract Act (SCA), is applicable to this contract as it applies to the entire Multiple Award Schedule (MAS) and all services provided. While no specific labor categories have been identified as being subject to SCLS/SCA due to exemptions for professional employees (FAR 22.1101, 22.1102 and 29 CRF 541.300), this contract still maintains the provisions and protections for SCLS/SCA eligible labor categories. If and / or when the contractor adds SCLS/SCA labor categories to the contract through the modification process, the contractor must inform the Contracting Officer and establish a SCLS/SCA matrix identifying the GSA labor category titles, the occupational code, SCLS/SCA labor category titles and the applicable WD number. Failure to do so may result in cancellation of the contract.

Labor Category Descriptions

Executive Cyber Security Consultant

Minimum Education: Master’s degree

Minimum Years’ Experience: 25 Years

Functional Responsibilities: Provides consulting services to the management team of a corporation/U.S. government organization and typically works directly with CIOs/CISOs. Designs, customizes, and instructs courses on industry security standards such as NERC-CIP, PCI-DSS, and HIPAA. Leads the process of creating, deploying, and managing cybersecurity technology programs. Provide leadership to their team in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Able to quantify risk by calculating a company’s Exposure Factor, Single Loss Expectancy, and Annualized Rate of Occurrence. Authorized to sign legal documents between Affinity IT and a client which covers the scope of a penetration test, allowed methodology, and other expected deliverables. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Meet with the client to discuss the contents of the Risk and Vulnerability Assessment, answer client questions, and suggest strategies for moving forward. Must have extensive experience with advance cybersecurity concepts and have a master’s degree in a related field (Computer Science, Math, etc.) plus an additional fifteen years of work experience or have at least twenty-five years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.

Cyber Security Consultant III

Minimum Education: Bachelor’s degree

Minimum Years’ Experience: 15 years

Functional Responsibilities: Provide leadership to their team in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Able to quantify risk by calculating a company’s Exposure Factor, Single Loss Expectancy, and Annualized Rate of Occurrence. Authorized to sign legal documents between Affinity IT and a client which covers the scope of a penetration test, allowed methodology, and other expected deliverables. Teach client employees in cybersecurity courses that the company offers. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Meet with the client to discuss the contents of the Risk and Vulnerability Assessment, answer client questions, and suggest strategies for moving forward. Must have extensive experience with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional ten years of work experience or have at least fifteen years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.

Cyber Security Consultant II

Minimum Years’ Experience: 10 years

Functional Responsibilities: Provide support to their team leader in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Able to quantify risk by calculating a company’s Exposure Factor, Single Loss Expectancy, and Annualized Rate of Occurrence. Assist in teaching client employees in cybersecurity courses that the company offers. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Must be familiar with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional five years of work experience or have at least ten years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.

Cyber Security Consultant I

Minimum Years’ Experience: 5 years

Functional Responsibilities:

Provide support to their team leader in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Must be familiar with standard cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) or have at least five years of experience in a related field.

Chief Penetration Testing Officer

Minimum Education: Master’s degree

Minimum Years’ Experience: 25 years

Functional Responsibilities:

Provides leadership, experience, and direction at an organization level. Oversees multiple client projects simultaneously. Ensures all Affinity IT personnel performing penetration testing follow all state and federal laws, ethical hacking procedure, and stay in scope of the work agreed to by Affinity IT and the client. Able to participate within all phases of a penetration test including: Reconnaissance, Scanning and Enumeration, Gaining Access, Escalation of Privileges, Maintaining Access, and Covering Tracks. Authorized to launch simulated attacks and determine when the team should move onto the next phase of a penetration test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment (RVA) composed for the client. Author the Executive Summary included in applicable deliverables. Encrypt and send the RVA to the client via secure methods. Must have extensive experience with advance cybersecurity concepts and have a master’s degree in a related field (Computer Science, Math, etc.) plus an additional fifteen years of work experience or have at least twenty-five years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.

Penetration Tester III

Minimum Education: Bachelor’s degree

Minimum Years’ Experience: 15 years

Functional Responsibilities:

Provide leadership to their team and research known vulnerabilities that are potentially applicable to a penetration test. Able to participate within all phases of a penetration test including: Reconnaissance, Scanning and Enumeration, Gaining Access, Escalation of Privileges, Maintaining Access, and Covering Tracks. Authorized to launch simulated attacks and determine when the team should move onto the next phase of a penetration test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment (RVA) composed for the client. Author the Executive Summary included in applicable deliverables. Encrypt and send the RVA to the client via secure methods. Must have extensive experience with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional ten years of work experience or have at least fifteen years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.

Penetration Tester II

Minimum Education: Bachelor’s degree

Minimum Years’ Experience: 10 years

Functional Responsibilities:

Provide support to their team leader and research known vulnerabilities that are potentially applicable to a penetration test. Able to participate within all phases of a penetration test including: Reconnaissance, Scanning and Enumeration, Gaining Access, Escalation of Privileges, Maintaining Access, and Covering Tracks. Monitor simulated attacks and inform their team leader the results/whether an error occurred that stopped the test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment composed for the client. Must be familiar with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional five years of work experience or have at least ten years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.

Penetration Tester I

Minimum Education: Bachelor’s degree

Minimum Years’ Experience: 5 years

Functional Responsibilities:

Provide support to their team leader and research known vulnerabilities that are potentially applicable to a penetration test. Monitor simulated attacks and inform their team leader the results/whether an error occurred that stopped the test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment composed for the client. Must be familiar with standard cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) or have at least five years of experience in a related field.

Course Pricing (Customer and Contractor Site)

SIN
Course Title
GSA Price
611420
Employee IT Security Awareness
$2,345.09
611420
Securing Java Web Series
$5,743.07
611420
Securing ASP.NET Web Series
$5,743.07

Course Descriptions

Course Title
Course Description
Course Length
Minimum Participants
Maximum Participants
Employee IT Security Awareness
An introductory seminar designed to communicate the essential knowledge your employees need to know to be an IT Security Asset rather than a liability. Available in Classroom or Instructor-led webinar formats, topics are based on each organization’s individual needs.
1 day
1
12
Securing Java Web Series
The design and implementation of secure Web Applications is a huge challenge that requires significant expertise in programming, web application development, and IT Security. This course is designed exclusively for experienced Java developers to empower them to develop secure web applications by illuminating the most common serious vulnerabilities and how to avoid them.
4 days
1
12
Securing ASP.NET Web Series
The design and implementation of secure Web Applications is a huge challenge that requires significant expertise in programming, web application development, and IT Security. This course is designed exclusively for experienced ASP.NET developers to empower them to develop secure web applications by illuminating the most common serious vulnerabilities and how to avoid them.
4 days
1
12

image1.png

File details come from the government source that posted it. Updated .