MAS - Affinity It LIMITED Liability Company - 47QTCA21D00EE
DOCX document 56 KB
- Attached to
- Federal Supply Schedule 47QTCA21D00EE Federal contract IDV
- Contract number
- 47QTCA21D00EE
- Issued by
- GSA Federal Acquisition Service
About this file
This price list provides details on an information technology federal supply schedule contract held by Affinity IT Security Services. The contractor offers professional services and training under SINs 54151S, 611420, and OLM. Key labor categories include Executive Cyber Security Consultant, Cyber Security Consultant III, Cyber Security Consultant II, and Cyber Security Consultant I. Course offerings focus on employee security awareness and securing Java and ASP.NET web applications. The underlying IDV has a contract number 47QTCA21D00EE, was awarded on September 2, 2021 through September 1, 2026 under GSA's Federal Acquisition Service. Pricing is provided for labor categories, courses, and volume discounts with net 30 day payment terms.
Affinity It LIMITED Liability Company (DBA Affinity It Security Services) Pricelist and/or Vendor Terms and Conditions for 47QTCA21D00EE, a Federal Supply Schedule awarded to Affinity It LIMITED Liability Company (DBA Affinity It Security Services), under Multiple Award Schedule (MAS)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
GENERAL SERVICES ADMINISTRATION
Federal Supply Service
Authorized Federal Supply Schedule Price List
On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic delivery order are available through GSA Advantage!®, a menu-driven database system. The INTERNET address GSA Advantage!® is: GSAAdvantage.gov.
Multiple Award Schedule
FSC Group: Information Technology FSC Class: D399 and U012
Contract number: 47QTCA21D00EE
For more information on ordering from Federal Supply Schedules go to the GSA Schedules page at GSA.gov.
Contract period: September 2, 2021, through September 1, 2026
Affinity IT Limited Liability Company dba Affinity IT Security Services 1243 Sussex Turnpike, SUITE 1 Randolph, NJ 07869 800.840.2335 https://affinity-it-security.com/contact-us/
Contract administration source:
Joseph Fisher 973-895-5777 joe@affinity-it.com
Business size: Small Business
Prices Shown Herein are Net (discount deducted)
Price list current as of Modification #PS-0002 effective 2/4/2022
CUSTOMER INFORMATION
1a. Table of awarded special item number(s) with appropriate cross-reference to item descriptions and awarded price(s).
| SINs |
| SIN Title |
| 54151S |
| Information Technology Professional Services |
| 611420 |
| Information Technology Training |
| 54151HACS |
| Highly Adaptive Cybersecurity Services (HACS) |
| OLM |
| Order-Level Materials (OLM’s) |
1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract. This price is the Government price based on a unit of one, exclusive of any quantity/dollar volume, prompt payment, or any other concession affecting price. Those contracts that have unit prices based on the geographic location of the customer, should show the range of the lowest price, and cite the areas to which the prices apply. N/A
1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided. If hourly rates are not applicable, indicate “Not applicable” for this item. See Labor Category Pricing and Labor Category Descriptions
2. Maximum order:
| SINs |
| Maximum Order |
| 54151S |
| $500,000 |
| 611420 |
| $250,000 |
| 54151HACS |
| $500,000 |
| OLM |
| $250,000 |
3. Minimum order: $100
4. Geographic coverage (delivery area). Domestic
5. Point(s) of production (city, county, and State or foreign country). Same as company address
6. Discount from list prices or statement of net price. Government Net Prices (discounts already deducted.)
7. Volume discounts. 1.5% for single task orders over $500,000
8. Prompt payment terms. Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions. 1.5% if paid within 15 days: Net 30 days
9. Foreign items (list items by country of origin). Not Applicable
10a. Time of delivery. To Be Determined at the Task Order level
10b. Expedited Delivery. Items available for expedited delivery are noted in this price list. To Be Determined at the Task Order level
10c. Overnight and 2-day delivery. To Be Determined at the Task Order level
10d. Urgent Requirements. To Be Determined at the Task Order level
11. F.O.B. point(s). Destination
12a. Ordering address(es). Same as company address.
12b. Ordering procedures: For supplies and services, the ordering procedures, information on Blanket Purchase Agreements (BPA’s) are found in Federal Acquisition Regulation (FAR) 8.405-3.
13. Payment address(es). Same as company address.
14. Warranty provision. None
15. Export packing charges, if applicable. Not Applicable
16. Terms and conditions of rental, maintenance, and repair (if applicable). Not Applicable
17. Terms and conditions of installation (if applicable). Not Applicable
18a. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable). Not Applicable
18b. Terms and conditions for any other services (if applicable). Not Applicable
19. List of service and distribution points (if applicable). Not Applicable
20. List of participating dealers (if applicable). Not Applicable
21. Preventive maintenance (if applicable). Not Applicable
22a. Special attributes such as environmental attributes (e.g., recycled content, energy efficiency, and/or reduced pollutants). Not Applicable
22b. If applicable, indicate that Section 508 compliance information is available on Electronic and Information Technology (EIT) supplies and services and show where full details can be found (e.g. contractor’s website or other location.) The EIT standards can be found at: www.Section508.gov/.
Not Applicable
23. Data Universal Number System (DUNS) number. 830498684
24. Notification regarding registration in System for Award Management (SAM) database. Contractor registered and active in SAM
Labor Category Pricing
| SIN |
| Labor Category |
| GSA Price |
| 54151S |
| Executive Cyber Security Consultant |
| $229.67 |
| 54151S |
| Cyber Security Consultant III |
| $190.58 |
| 54151S |
| Cyber Security Consultant II |
| $141.71 |
| 54151S |
| Cyber Security Consultant I |
| $117.28 |
| 54151HACS |
| Chief Penetration Testing Officer |
| $213.10 |
| 54151HACS |
| Penetration Tester III |
| $188.61 |
| 54151HACS |
| Penetration Tester II |
| $140.25 |
| 54151HACS |
| Penetration Tester I |
| $116.07 |
Service Contract Labor Standards: The Service Contract Labor Standards (SCLS), formerly known as the Service Contract Act (SCA), is applicable to this contract as it applies to the entire Multiple Award Schedule (MAS) and all services provided. While no specific labor categories have been identified as being subject to SCLS/SCA due to exemptions for professional employees (FAR 22.1101, 22.1102 and 29 CRF 541.300), this contract still maintains the provisions and protections for SCLS/SCA eligible labor categories. If and / or when the contractor adds SCLS/SCA labor categories to the contract through the modification process, the contractor must inform the Contracting Officer and establish a SCLS/SCA matrix identifying the GSA labor category titles, the occupational code, SCLS/SCA labor category titles and the applicable WD number. Failure to do so may result in cancellation of the contract.
Labor Category Descriptions
Executive Cyber Security Consultant
Minimum Education: Master’s degree
Minimum Years’ Experience: 25 Years
Functional Responsibilities: Provides consulting services to the management team of a corporation/U.S. government organization and typically works directly with CIOs/CISOs. Designs, customizes, and instructs courses on industry security standards such as NERC-CIP, PCI-DSS, and HIPAA. Leads the process of creating, deploying, and managing cybersecurity technology programs. Provide leadership to their team in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Able to quantify risk by calculating a company’s Exposure Factor, Single Loss Expectancy, and Annualized Rate of Occurrence. Authorized to sign legal documents between Affinity IT and a client which covers the scope of a penetration test, allowed methodology, and other expected deliverables. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Meet with the client to discuss the contents of the Risk and Vulnerability Assessment, answer client questions, and suggest strategies for moving forward. Must have extensive experience with advance cybersecurity concepts and have a master’s degree in a related field (Computer Science, Math, etc.) plus an additional fifteen years of work experience or have at least twenty-five years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.
Cyber Security Consultant III
Minimum Education: Bachelor’s degree
Minimum Years’ Experience: 15 years
Functional Responsibilities: Provide leadership to their team in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Able to quantify risk by calculating a company’s Exposure Factor, Single Loss Expectancy, and Annualized Rate of Occurrence. Authorized to sign legal documents between Affinity IT and a client which covers the scope of a penetration test, allowed methodology, and other expected deliverables. Teach client employees in cybersecurity courses that the company offers. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Meet with the client to discuss the contents of the Risk and Vulnerability Assessment, answer client questions, and suggest strategies for moving forward. Must have extensive experience with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional ten years of work experience or have at least fifteen years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.
Cyber Security Consultant II
Minimum Years’ Experience: 10 years
Functional Responsibilities: Provide support to their team leader in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Able to quantify risk by calculating a company’s Exposure Factor, Single Loss Expectancy, and Annualized Rate of Occurrence. Assist in teaching client employees in cybersecurity courses that the company offers. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Must be familiar with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional five years of work experience or have at least ten years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.
Cyber Security Consultant I
Minimum Years’ Experience: 5 years
Functional Responsibilities:
Provide support to their team leader in analyzing a client’s internal network protocols, web-application, and IT-infrastructure for vulnerabilities and exploits. Do Quality Assurance testing when applicable and record any findings. Possess strong verbal and written communication skills to help explain the dangers of relevant malware/misconfigurations and its operating principles to a client. Must be familiar with standard cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) or have at least five years of experience in a related field.
Chief Penetration Testing Officer
Minimum Education: Master’s degree
Minimum Years’ Experience: 25 years
Functional Responsibilities:
Provides leadership, experience, and direction at an organization level. Oversees multiple client projects simultaneously. Ensures all Affinity IT personnel performing penetration testing follow all state and federal laws, ethical hacking procedure, and stay in scope of the work agreed to by Affinity IT and the client. Able to participate within all phases of a penetration test including: Reconnaissance, Scanning and Enumeration, Gaining Access, Escalation of Privileges, Maintaining Access, and Covering Tracks. Authorized to launch simulated attacks and determine when the team should move onto the next phase of a penetration test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment (RVA) composed for the client. Author the Executive Summary included in applicable deliverables. Encrypt and send the RVA to the client via secure methods. Must have extensive experience with advance cybersecurity concepts and have a master’s degree in a related field (Computer Science, Math, etc.) plus an additional fifteen years of work experience or have at least twenty-five years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.
Penetration Tester III
Minimum Education: Bachelor’s degree
Minimum Years’ Experience: 15 years
Functional Responsibilities:
Provide leadership to their team and research known vulnerabilities that are potentially applicable to a penetration test. Able to participate within all phases of a penetration test including: Reconnaissance, Scanning and Enumeration, Gaining Access, Escalation of Privileges, Maintaining Access, and Covering Tracks. Authorized to launch simulated attacks and determine when the team should move onto the next phase of a penetration test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment (RVA) composed for the client. Author the Executive Summary included in applicable deliverables. Encrypt and send the RVA to the client via secure methods. Must have extensive experience with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional ten years of work experience or have at least fifteen years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.
Penetration Tester II
Minimum Education: Bachelor’s degree
Minimum Years’ Experience: 10 years
Functional Responsibilities:
Provide support to their team leader and research known vulnerabilities that are potentially applicable to a penetration test. Able to participate within all phases of a penetration test including: Reconnaissance, Scanning and Enumeration, Gaining Access, Escalation of Privileges, Maintaining Access, and Covering Tracks. Monitor simulated attacks and inform their team leader the results/whether an error occurred that stopped the test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment composed for the client. Must be familiar with advance cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) plus an additional five years of work experience or have at least ten years of work experience in a related field. Must have an EC-Council’s Certified Ethical Hacking certification or higher.
Penetration Tester I
Minimum Education: Bachelor’s degree
Minimum Years’ Experience: 5 years
Functional Responsibilities:
Provide support to their team leader and research known vulnerabilities that are potentially applicable to a penetration test. Monitor simulated attacks and inform their team leader the results/whether an error occurred that stopped the test. Document any vulnerabilities or exposures uncovered during a penetration test along with its applicable CVE ID#, CVSS score, and appropriate remediation actions within the Risk and Vulnerability Assessment composed for the client. Must be familiar with standard cybersecurity concepts and have a bachelor’s degree in a related field (Computer Science, Math, etc.) or have at least five years of experience in a related field.
Course Pricing (Customer and Contractor Site)
| SIN |
| Course Title |
| GSA Price |
| 611420 |
| Employee IT Security Awareness |
| $2,345.09 |
| 611420 |
| Securing Java Web Series |
| $5,743.07 |
| 611420 |
| Securing ASP.NET Web Series |
| $5,743.07 |
Course Descriptions
| Course Title |
| Course Description |
| Course Length |
| Minimum Participants |
| Maximum Participants |
| Employee IT Security Awareness |
| An introductory seminar designed to communicate the essential knowledge your employees need to know to be an IT Security Asset rather than a liability. Available in Classroom or Instructor-led webinar formats, topics are based on each organization’s individual needs. |
| 1 day |
| 1 |
| 12 |
| Securing Java Web Series |
| The design and implementation of secure Web Applications is a huge challenge that requires significant expertise in programming, web application development, and IT Security. This course is designed exclusively for experienced Java developers to empower them to develop secure web applications by illuminating the most common serious vulnerabilities and how to avoid them. |
| 4 days |
| 1 |
| 12 |
| Securing ASP.NET Web Series |
| The design and implementation of secure Web Applications is a huge challenge that requires significant expertise in programming, web application development, and IT Security. This course is designed exclusively for experienced ASP.NET developers to empower them to develop secure web applications by illuminating the most common serious vulnerabilities and how to avoid them. |
| 4 days |
| 1 |
| 12 |
image1.png
File details come from the government source that posted it. Updated .