MAS - Fortress Government Solutions, LLC - 47QTCA24D006Q

PDF 460 KB

Attached to
Federal Supply Schedule 47QTCA24D006Q Federal contract IDV
Contract number
47QTCA24D006Q
Issued by
GSA Federal Acquisition Service

About this file

This document is a Federal Supply Schedule (FSS) Price List for a contract awarded to Fortress Government Solutions, LLC. The contract covers a variety of IT professional services and software licenses under various Special Item Numbers (SINs) from March 21, 2024 to March 20, 2029.

The price list includes detailed labor categories and descriptions, with awarded hourly rates for each year of the contract period. Key labor categories include system administrators, database administrators, network administrators, data architects, IT analysts, technical architects, subject matter authorities, project managers, programmers, and SCRM IT strategists.

The price list also includes various software products and services related to third party and product risk illumination, such as virtual appliance licenses, data connector services, enterprise support, and risk assessment and monitoring services. Pricing is provided for 12-month durations.

Fortress Government Solutions, LLC Pricelist and/or Vendor Terms and Conditions for 47QTCA24D006Q, a Federal Supply Schedule awarded to Fortress Government Solutions, LLC, under Multiple Award Schedule (MAS)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

GENERAL SERVICES ADMINISTRATION

Federal Acquisition Service

Authorized Federal Supply Schedule FSS Price List

On-line access to contract ordering information, terms and conditions, pricing, and the option to create an electronic delivery order are available through GSA

Advantage!®. The website for GSA Advantage!® is: GSAAdvantage.gov.

Multiple Award Schedule

FSC Group: Information Technology FSC Class: DA01

Contract number: 47QTCA24D006Q

For more information on ordering go to the following website:

https://www.gsa.gov/schedules.

Contract period: Mar 21, 2024 - Mar 20, 2029

Fortress Government Solutions, LLC 250 S Orange Ave, Suite 500

Orlando, FL 32801 Web: fortressinfosec.com

Contract Administrator

Contracts@fortressinfosec.com

Business size: Other than small

Price list current as of contract award

Prices Shown Herein are Net (discount deducted)

CUSTOMER INFORMATION

1a. Table of awarded special item number(s) with appropriate cross-reference to item descriptions and awarded price(s).

SINs Recovery SIN Title

54151S 54151SRC Information Technology Professional Services 54151ECOM 54151ECOMRC Electronic Commerce and Subscription Services 511210 511210RC Software Licenses OLM OLMRC Order-Level Materials (OLM’s)

1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract. This price is the Government price based on a unit of one, exclusive of any quantity/dollar volume, prompt payment, or any other concession affecting price.

Contracts that have unit prices based on the geographic location of the customer, should show the range of the lowest price, and cite the areas to which the prices apply.

FGS-AITPR-OIRI-001 - Third Party Inherent Risk Illumination - $44.35

1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided. If hourly rates are not applicable, indicate “Not applicable” for this item. See Page 4

2. Maximum order:

SINs Maximum Order 54151S $500,000

54151ECOM $500,000

511210 $500,000

OLM $250,000

3. Minimum order: $100

4. Geographic coverage (delivery area). Domestic

5. Point(s) of production (city, county, and State or foreign country).

Fortress Government Solutions, LLC 250 S Orange Ave, Suite 500 Orlando, FL 32801

6. Discount from list prices or statement of net price. Government Net Prices (discounts already deducted.)

7. Quantity discounts. None

8. Prompt payment terms. Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions. Net 30 days

9. Foreign items (list items by country of origin). Not Applicable

10a. Time of delivery. (Contractor insert number of days.) To Be Determined at the Task Order level

10b. Expedited Delivery. Items available for expedited delivery are noted in this price list. To Be Determined at the Task Order level

10c. Overnight and 2-day delivery. To Be Determined at the Task Order level

10d. Urgent Requirements. To Be Determined at the Task Order level

11. F.O.B. point(s). Destination

12a. Ordering address(es).

Fortress Government Solutions, LLC 250 S Orange Ave, Suite 500 Orlando, FL 32801

12b. Ordering procedures: See Federal Acquisition Regulation (FAR) 8.405-3.

13. Payment address(es).

Fortress Government Solutions, LLC 250 S Orange Ave, Suite 500 Orlando, FL 32801

14. Warranty provision. Standard Commercial Warranty Terms & Conditions

15. Export packing charges, if applicable. Not Applicable

16. Terms and conditions of rental, maintenance, and repair (if applicable). Not Applicable

17. Terms and conditions of installation (if applicable). Not Applicable

18a. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable). Not Applicable

18b. Terms and conditions for any other services (if applicable). Not Applicable

19. List of service and distribution points (if applicable). Not Applicable

20. List of participating dealers (if applicable). Not Applicable

21. Preventive maintenance (if applicable). Not Applicable (typical response)

22a. Special attributes such as environmental attributes (e.g., recycled content, energy efficiency, and/or reduced pollutants). Not Applicable

22b. If applicable, indicate that Section 508 compliance information is available on Electronic and Information Technology (EIT) supplies and services and show where full details can be found (e.g.

contractor’s website or other location.) The EIT standards can be found at: www.Section508.gov/.

Not Applicable

23. Unique Entity Identifier (UEI) number. GEHFKM8C1DT3

24. Notification regarding registration in System for Award Management (SAM) database. Contractor registered and active in SAM

Awarded Outyear Pricing – SIN 54151S Year 1 Year 2 Year 3 Year 4 Year 5

Labor Category GSA Rate GSA Rate GSA Rate GSA Rate GSA Rate

System Administrator 1 $121.54 $126.41 $131.47 $136.73 $142.20

System Administrator 2 $160.43 $166.85 $173.52 $180.46 $187.68

System Administrator 3 $184.74 $192.12 $199.81 $207.80 $216.11

Database Administrator 1 $121.54 $126.41 $131.47 $136.73 $142.20

Database Administrator 2 $170.16 $176.97 $184.05 $191.42 $199.07

Database Administrator 3 $194.46 $202.24 $210.33 $218.74 $227.49

Network Administrator $194.46 $202.24 $210.33 $218.74 $227.49

Data Architect $218.77 $227.53 $236.62 $246.09 $255.93

IT Analyst 1 $121.54 $126.41 $131.47 $136.73 $142.20

IT Analyst 2 $170.16 $176.97 $184.05 $191.42 $199.07

IT Analyst 3 $194.46 $202.24 $210.33 $218.74 $227.49

Technical Architect 1 $218.77 $227.53 $236.62 $246.09 $255.93

Technical Architect 2 $267.39 $278.09 $289.21 $300.78 $312.81

Subject Matter Authority (SMA) 1 $243.07 $252.80 $262.91 $273.43 $284.37

Subject Matter Authority (SMA) 2 $309.45 $321.83 $334.71 $348.10 $362.03

Subject Matter Authority (SMA) 3 $353.25 $367.38 $382.07 $397.35 $413.24

IT Operations Manager $218.77 $227.53 $236.62 $246.09 $255.93

Task Manager $218.77 $227.53 $236.62 $246.09 $255.93

Project Manager $291.69 $303.36 $315.49 $328.10 $341.23

Senior Program Manager $381.86 $397.14 $413.03 $429.55 $446.73

Quality Assurance Specialist $145.84 $151.68 $157.74 $164.05 $170.61

Programmer 1 $97.23 $101.12 $105.16 $109.36 $113.73

Programmer 2 $145.84 $151.68 $157.74 $164.05 $170.61

Programmer 3 $218.77 $227.53 $236.62 $246.09 $255.93

SCRM IT Strategist 1 $194.46 $202.24 $210.33 $218.74 $227.49

SCRM IT Strategist 2 $291.69 $303.36 $315.49 $328.10 $341.23

SCRM IT Strategist 3 $381.86 $397.14 $413.03 $429.55 $446.73

Training Specialist $145.84 $151.68 $157.74 $164.05 $170.61

Awarded Labor Categories / Services - 54151S

Labor Category/Service Title Labor Category/Service Description

Minimum Education

Min.

Exp.

System Administrator 1

A System Administrator 1 manages and maintains the IT technical infrastructure that supports vendor and product initiatives. They ensure that IT systems are configured correctly and are operating effectively, and they troubleshoot technical IT issues as they arise.

They also provide technical support to other IT team members and stakeholders.

Bachelors 0

System Administrator 2

A System Administrator 2 has advanced technical IT expertise and is responsible for managing and maintaining complex technical IT systems that support vendor and product initiatives.

They work with other technology professionals to identify and address technical challenges and ensure that IT systems are resilient and scalable.

Bachelors 3

System Administrator 3

A System Administrator 3 is a senior-level technical expert who provides strategic direction and leadership for the design, implementation, and maintenance of the technical infrastructure that supports vendor and product initiatives. They ensure that systems are secure, efficient, and effective, and they provide technical guidance to other team members and stakeholders.

Bachelors 6

Database Administrator 1

A Database Administrator 1 manages and maintains the databases that support vendor and product initiatives. They ensure that databases are configured correctly, backed up regularly, and operating effectively, and they troubleshoot database issues as they arise. They also provide technical support to other team members and stakeholders.

Bachelors 0

Database Administrator 2

A Database Administrator 2 has advanced technical expertise and is responsible for managing and maintaining complex databases that support vendor and product initiatives. They work with other technology professionals to identify and address technical challenges and ensure that databases are resilient and scalable.

Bachelors 3

Database Administrator 3

A Database Administrator 3 is a senior-level technical expert who provides strategic direction and leadership for the design, implementation, and maintenance of the databases that support vendor and product initiatives. They ensure that databases are secure, efficient, and effective, and they provide technical guidance to other team members and stakeholders.

Bachelors 6

Network Administrator

A Network Administrator manages and maintains the network infrastructure that supports vendor and product initiatives. They ensure that networks are secure, efficient, and effective, and they troubleshoot network issues as they arise. They also provide technical support to other team members and stakeholders.

Bachelors 6

Data Architect

A Data Architect designs and manages the data architecture that supports vendor and product initiatives. They work with other technology professionals to ensure that data is organized and stored securely, and that it can be easily accessed and analyzed to support decision-making. They also ensure that data is properly backed up and can be recovered in the event of an attack or other disaster.

Bachelors 6

Minimum Education

Min.

Exp.

IT Analyst 1

A IT Analyst 1 is responsible for monitoring and analyzing vendor and product risks. They use a range of IT tools (i.e. Fortress Platform) and techniques to identify and assess potential risks, and they work with other technology/IT professionals to develop and implement strategies to mitigate those risks.

Bachelors 0

IT Analyst 2

A IT Analyst 2 has advanced technical expertise and is responsible for analyzing complex vendor and product risks. They work with other technology/IT professionals to develop and implement strategies to mitigate risks and respond to risks. They also provide technical guidance to other IT team members and stakeholders.

Bachelors 3

IT Analyst 3

A IT Analyst 3 is a senior-level technical expert who provides strategic direction and leadership for the analysis and mitigation of vendor and product risks as may be compiled from the use of IT tools (i.e. Fortress Platform). They work with other technology/IT professionals to develop and implement comprehensive strategies to protect against threats and ensure the security of data and systems.

Bachelors 6

Technical Architect 1

A Technical Architect 1 designs and implements technical solutions to support vendor and product risk initiatives. They work with other technology professionals to ensure that the technical infrastructure is secure, efficient, and effective. They also provide technical guidance to other team members and stakeholders.

Bachelors 6

Technical Architect 2

A Technical Architect 2 has advanced technical expertise and provides strategic direction for the development and implementation of vendor and product risk solutions. They work with other technology professionals to identify and address complex technical challenges and ensure that the technical infrastructure is resilient and adaptable to changing risks.

Bachelors 9

Subject Matter Authority

(SMA) 1

Provides technical expertise and guidance on vendor and product risks. Assists in the development and implementation of security policies and procedures.

Bachelors 3

Subject Matter Authority

(SMA) 2

Serves as a technical expert on vendor and product risks and develops recommendations for risk mitigation. Collaborates with other security teams to ensure security posture is maintained.

Bachelors 6

Subject Matter Authority

(SMA) 3

Oversees the development and implementation of vendor and product policies and procedures. Provides guidance and direction to lower level SMAs.

Bachelors 9

IT Operations Manager

A IT Operations Manager oversees the day-to-day operations of a vendor and product IT team. They are responsible for managing IT team members, setting priorities and goals, and ensuring that vendor and product IT initiatives are aligned with the overall goals and objectives of the organization. They also oversee the development and implementation of IT policies and procedures.

Bachelors 6

Minimum Education

Min.

Exp.

Task Manager

A Task Manager is responsible for leading and managing teams of vendor and product risk IT professionals to complete specific tasks or projects. They work with other managers and executives to set goals and ensure that project deliverables are completed on time, within budget, and to the required level of quality.

Bachelors 6

Project Manager Manages vendor and product risk IT projects from initiation to closure. Develops project plans and schedules, manages project resources, and communicates project status to stakeholders.

Bachelors 9

Senior Program Manager Oversees multiple vendor and product IT technology programs and initiatives. Develops and implements technology strategy and provides guidance and direction to program managers.

Bachelors 12

Quality Assurance Specialist

A Quality Assurance Specialist ensures that vendor and product risk initiatives meet the required level of quality. They develop and implement testing and validation procedures to identify and address any quality issues, and they work with other technology/IT professionals to ensure that all deliverables meet the required standards.

Bachelors 3

Programmer 1

A Programmer 1 develops and implements software solutions to support vendor and product risk initiatives. They work with other technology professionals to identify requirements, design solutions, write code, and test and deploy software.

Bachelors 0

Programmer 2

A Programmer 2 has advanced technical expertise and is responsible for developing and implementing complex software solutions that support vendor and product risk initiatives. They work with other technology professionals to identify requirements, design solutions, write code, and test and deploy software.

Bachelors 3

Programmer 3

A Programmer 3 is a senior-level technical expert who provides strategic direction and leadership for the development and implementation of software solutions that support vendor and product risk initiatives. They ensure that software is secure, efficient, and effective, and they provide technical guidance to other team members and stakeholders.

Bachelors 6

SCRM IT Strategist 1

A SCRM Strategist 1 is responsible for developing and implementing strategies to assess and mitigate vendor and product risks throughout the customer. They work with other technology/IT professionals to identify potential risks and vulnerabilities through use of IT tools I.e.. Fortress Platform), and they develop and implement strategies to mitigate those risks.

Bachelors 3

Minimum Education

Min.

Exp.

SCRM IT Strategist 2

A SCRM Strategist 2 has advanced technical expertise and is responsible for developing and implementing comprehensive strategies to assess and mitigate complex vendor and product risks throughout the customer. They work with other technology/IT professionals to identify potential risks and vulnerabilities through use of IT tools I.e.. Fortress Platform), and they develop and implement strategies to mitigate those risks.

Bachelors 6

SCRM IT Strategist 3

A SCRM Strategist 3 is a senior-level technical expert who provides strategic direction and leadership for the development and implementation of comprehensive strategies to assess and mitigate vendor and product risks throughout the customer. They work with other technology/IT professionals to identify potential risks and vulnerabilities through use of IT tools I.e.. Fortress Platform), and they develop and implement strategies to mitigate those risks.

Bachelors 9

Training Specialist

A Training Specialist develops and delivers training programs to help employees and other stakeholders understand and implement vendor and product best practices. They work with other technology professionals to identify training needs and develop materials and courses to address those needs.

Bachelors 3

Service Contract Labor Standards: The Service Contract Labor Standards (SCLS), formerly known as the Service Contract Act (SCA), is applicable to this contract as it applies to the entire Multiple Award Schedule (MAS) and all services provided. While no specific labor categories have been identified as being subject to SCLS/SCA due to exemptions for professional employees (FAR 22.1101, 22.1102 and 29 CRF 541.300), this contract still maintains the provisions and protections for SCLS/SCA eligible labor categories. If and / or when the contractor adds SCLS/SCA labor categories to the contract through the modification process, the contractor must inform the Contracting Officer and establish a SCLS/SCA matrix identifying the GSA labor category titles, the occupational code, SCLS/SCA labor category titles and the applicable WD number. Failure to do so may result in cancellation of the contract.

Awarded Products

SIN MFR PART NO PRODUCT NAME PRODUCT DESCRIPTION UOI

Awarded

GSA Price

511210

FGS-TPPRI-VA-

COR-001

Third Party and Product Risk Illumination Virtual Appliance - Single Core License

Third Party and Product Risk Illumination Virtual Appliance - Single Core License - The Third Party and Product Risk Illumination Virtual Appliance (TPPRI-VA) provides the foundation for risk management workflows.

This includes workflows, internal/external collaboration, assessment, questionnaires, dashboards, audit logging, role & attribute-based access controls, user management, navigation customization, approval flows, configurable user interface, white labeled interface, risk register, automation, event notification, third party, product, system, component, and API modules. The TPPRI-VA is licensed on a per-Core basis.

A “Core” is a unit of capacity licensed for the transactional requirements of a single department, program office, or similar organizationally structured team.

Each Core includes licenses for up to 10 Standard User IDs and 100 Lite User IDs. Cores may be extended by purchasing additional user licenses up to 50 Standard User IDs and 500 Lite User IDs; beyond this, additional Cores must be purchased. User IDs are customer and tenant-specific, including and limited to the department, program office, or similar organizationally structured team for which the Core is licensed to, and are assigned to individual users – account sharing is not permitted.

Fortress or deactivated User IDs do not count towards licenses limits.

Each Core includes a single TPPRI-VA tenant, which provides high data segregation capabilities for departmental data. Cores are installed by default in a Fortress multi-tenant SaaS environment; additional hosting options are available.

Standard User IDs grant comprehensive system access and are designed for users managing workflows.

Lite User IDs are tailored for stakeholders needing limited system interaction. They exclude administrative settings, system settings, rule configurations, notification configurations, campaigns, dashboard configurations, and assessment management (e.g., sending/reviewing). Lite User IDs can access dashboards, reports, input forms, and internal questionnaires.

Fortress will provide reporting on Core utilization and advise when limits are being approached.

Two modules are included in this SKU: Third-Party Risk Management Module and Third Party and Product Security Module.

The Third-Party Risk Management Module includes functionality for third party tiering, third party assessments, portal for unlimited external third party users (this “Third Party Portal” allows third parties to respond to questionnaires and findings, upload evidence, and communicate securely), questionnaire builder, dashboards, audit logging, role and attribute-based access control, configurable navigation, approvals, findings risk register, automated events, and event notifications.

The Third Party and Product Security Module provides the capability to browse products and order Software Bill of Materials (SBOMs) on them. It allows for the review

EA $186,125.29

and management of risks including vulnerabilities, dependencies, integrity, licensing, and foreign presence identified in software components. The module also offers visualization tools and dashboards for interpreting these findings. Extending its functionalities, the module includes options to order Hardware Bill of Materials (HBOMs) and manage findings from counterfeit, obsolescence, non-conformance, modified components, last-time-buy, not-recommended-for-new-designs, foreign presence, and banned entities.

Pricing is for a 12-month duration per applicable terms and conditions.

511210

FGS-TPPRI-VA-

COR-MAINT-001

Third Party and Product Risk Illumination Virtual Appliance - Single Core License - Maintenance

Third Party and Product Risk Illumination Virtual Appliance - Single Core License - Maintenance - Maintenance is included for the TPPRI-VA with Standard Support. Standard Support provides resources (technical support or engineering) to establish or restore substantial conformity with designed functionality. Support requests will be managed through the Support Portal (also known as the Fortress Helpdesk) in accordance with performance-level agreements (PLAs) defined in the contract.

Fortress will determine when it will be most effective to develop a new fix. Examples include (i) where a production system has gone down, (ii) or has experienced degraded performance, (iii) significant security vulnerabilities have been identified, or (iv) other significant software defects. For other types of issues, Fortress will typically either provide an existing fix or may provide solution delivery through a regularly scheduled software version upgrade.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $37,225.06

511210

FGS-TPPRI-VA-

DC-001

VPRI-VA Data Connector - Build & Integration

TPPRI-VA Data Connector - Build & Integration - One system data connector build and related integration service within the Third Party and Product Risk Illumination Virtual Appliance. Includes a 2-way (push and pull) data connection.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $84,937.03

511210

FGS-TPPRI-VA-

DC-MAINT-001

VPRI-VA Data Connector - Maintenance

TPPRI-VA Data Connector - Maintenance - Technical support and software maintenance and upgrades for the TPPRI-VA Data Connector.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $16,986.60

511210

FGS-PS-ENTSPT-

Enterprise Support

Enterprise Support - Enterprise support provides an upgrade to the standard platform maintenance and support. Enterprise support includes up to 200 hours per year in support of the following activities:

1. Highest level of service-level agreements with 4-hour response times (Phone and Email Support).

2. Dedicated professional services manager contact.

3. Dashboard and report development and support.

4. Resource availability to join customer internal meetings.

5. Platform workflow Configuration Management requests.

6. Customized onboarding and training.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $42,821.16

511210

FGS-AITPR-OIRI-

Third Party Inherent Risk Illumination

Third Party Inherent Risk Illumination - Automatically tier large vendor populations, identifying quickly which vendors should be prioritized for monitoring and assessments based on inherent risk. Web crawlers, scanners, API’s, and machine learning identify company service classifications and risk factors. Business rules and artificial intelligence further attribute risk across ten

(10) categories - system access, data access, physical access, hosted services, financial, fourth party, offshore operations, reputation, strategic/single/sole source, and geolocation footprint. Results are scored and summarized in reports and dashboards. Pricing is for a 12-month duration per applicable terms and conditions.

EA $44.35

54151E

COM

FGS-AITPR-OORI-

OSINT Third Party Risk Illumination

OSINT Third Party Risk Illumination - Over 40 procedures utilize open and closed source intelligence to identify risks, mapped back to CMMC and NIST, across risk management, security, negative news, compliance, sentiment, financial, privacy, and fourth party categories.

All findings are documented with traceable evidence.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $5,428.42

54151E

COM

FGS-TPRM-

VTPCQ-10-001

Validated Third Party Controls Questionnaire

Validated Third Party Controls Questionnaire - A controls questionnaire is submitted to a third party to complete;

Fortress then performs a validation of the responses versus the supplied evidence. A report aggregates the findings and related information from the assessment and third party record in the Fortress Platform. This includes up to three outreach attempts over a 45-day period for a single attestation. Pricing is for a 12-month duration per applicable terms and conditions.

EA $4,435.26

54151E

COM

FGS-TPRM-

TPFRA-001

Third Party Findings Resolution Assistance

Third Party Findings Resolution Assistance - Fortress reaches out to third parties to address findings from identified risks with resolution details, timelines, and evidence of resolution and also assists Client personnel with resolving the finding in accordance with agreed-upon procedures. Resolution may involve a third party remediation, an internal mitigation, or an internal risk acceptance. Internal resolution activities are limited to three interactions. Third party outreach will be limited to three attempts per report. Pricing is for a 12-month duration per applicable terms and conditions.

EA $4,435.26

54151E

COM

FGS-AITPR-OCRI-

Third Party Control Risk Illumination

Third Party Control Risk Illumination - Includes automated risk illumination for a given third party, revealing application security, security protocol health, domain configuration, geolocation, and patching cadence risks.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $55.37

54151E

COM

FGS-AITPR-

OCRM-001

Third Party Control Risk Monitoring

Third Party Control Risk Monitoring - Includes annual subscription for automated risk illumination for a given third party, revealing application security, security protocol health, domain configuration, internet protocol reputation, geolocation, and patching cadence risks.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $198.66

54151E

COM

FGS-AITPR-OFPI-

Third Party Foreign Presence Illumination

Third Party Foreign Presence Illumination - Includes analyst-curated results for identifying foreign locations categorized by physical locations; headquarters location;

mergers & acquisitions headquarters locations for target, buyer, and seller; IP address locations; corporate family headquarters locations; manufacturing locations; and locations of foreign owners. Pricing is for a 12-month duration per applicable terms and conditions.

EA $546.70

54151E

COM

FGS-AITPR-

OFPM-001

Third Party Foreign Presence Monitoring

Third Party Foreign Presence Monitoring - Includes continuous monitoring with analyst curated results for identifying foreign locations categorized by physical locations; headquarters location; mergers & acquisitions headquarters locations for target, buyer, and seller; IP address locations; corporate family headquarters locations; manufacturing locations; and locations of foreign owners. Pricing is for a 12-month duration per applicable terms and conditions.

EA $1,241.81

54151E

COM

FGS-VM-VA-MGD-

VDR-ASET-

UT20K-001

Virtual Appliance with Managed VDR

- Monthly Scanning

- Per Asset - Up to 20,000 Assets

Virtual Appliance with Managed VDR - Monthly Scanning

- Per Asset - Up to 20,000 Assets - Fortress provides a managed service for vulnerability detection and response (VDR), ensuring compliance with the vulnerability management (VM) process for a single asset (i.e., priced per asset) up to 20,000 assets. The process is described below.

Discover: Fortress is responsible for accurate data collection from various sources like scanners, sensors, data feeds, network tools, and databases. This data is integrated and reconciled with the VM process.

Enrich: The service involves ensuring data completeness and engaging stakeholders to address data gaps. This includes gathering information for business impact analysis, resolving duplicate assets, and correlating data across various elements.

Prioritize: Fortress enforces policies through system rules for issue prioritization. This includes grouping issues by responsible party, solution types, and environment.

Prioritization criteria include asset criticality, frequency of vulnerabilities, specific named vulnerabilities, and compliance with time-bound SLAs.

Assess: For assets of highest criticality, Fortress checks the relevance of proposed solutions against existing controls, aiming to optimize communication and remediation efforts.

Act: The service involves developing action plans and assigning them to the correct application or asset owners.

Fortress manages rules for owner determination, adaptable to factors like department, asset class, or network location. The service includes communication of findings and progress tracking, which can be integrated with external systems. Fortress does not implement fixes directly.

Verify: Fortress conducts rescans to confirm the effectiveness of fixes and the resolution of issues. Any discrepancies are addressed in collaboration with stakeholders.

This includes a single asset license to the Vulnerability Management Virtual Appliance (VM-VA) which is a risk management platform that supports the workflows for the vulnerability management lifecycle across discovery, enrichment, prioritization, assessment, action, and verification steps.

This includes workflows, internal/external collaboration, assessment, questionnaires, dashboards, audit logging, role & attribute-based access controls, user management, navigation customization, approval flows, configurable user interface, white labeled interface, risk register, automation, event notification, supplier, product, system, component, action plans, ticketing, and API modules.

System concepts include assets (devices, servers, virtual machines, cloud instances, etc.), software, software versions, software components, application and system owners, vulnerabilities, threats, solutions, controls, assessments, action plans, tickets.

The VM-VA is licensed by number of assets. Pricing is for a 12-month duration per applicable terms and conditions.

per applicable terms and conditions.

EA $107.51

511210

FGS-AIPR-FIAM-

File Integrity Assurance Monitoring

File Integrity Assurance Monitoring - Includes validating the authenticity and integrity of all patches and updates for a given product. Authenticity checks include checking the supplier for known breaches, appropriate encryption delivery, updated security certificate and DNS checks.

Integrity checks include reviewing code signage, malware analysis and, in some cases, sandbox and firmware analysis. Pricing is for a 12-month duration per applicable terms and conditions.

EA $830.41

4151EC

OM

FGS-AIPR-OPRI-

OSINT Product Risk Illumination

OSINT Product Risk Illumination - Risk illumination is provided for product vulnerability history, vulnerability notice procedures, patching cadence, and 65 product security controls are validated based on publicly-available information such as product guides and web searches.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $4,100.25

511210

FGS-PRM-SBOM-

VVFA-MFGB-001

SBOM - Validated Vulnerability and FOCI Analysis - Manufacturer Provided BOM

Software Bill of Materials - Vulnerability and Foreign Ownership, Control, and Influence Analysis - Manufacturer Provided BOM - Vulnerability and foreign influence analysis of manufacturer-provided software bill of materials. Risk illumination is provided for product vulnerability history, vulnerability notice procedures, and patching cadence. Foreign influence is identified on all identified fourth parties. Bill of materials must be provided to Fortress. Pricing is for a 12-month duration per applicable terms and conditions.

EA $11,072.07

511210

FGS-PRM-HBOM-

VVFA-MFGB-001

HBOM - Validated Vulnerability and FOCI Analysis - Manufacturer Provided BOM

Hardware Bill of Materials - Vulnerability and Foreign Ownership, Control, or Influence Analysis - Manufacturer Provided BOM - Vulnerability and foreign influence analysis of manufacturer-provided hardware bill of materials. Risk illumination is provided for counterfeit, obsolescence, non-conformance, modified components, last-time-buy, not-recommended-for-new-designs, foreign presence, and relations to banned entities. Foreign influence is identified on all identified fourth parties. Bill of materials must be provided to Fortress. Pricing is for a 12-month duration per applicable terms and conditions.

EA $11,072.07

511210

FGS-PRM-

HSBOM-VVFA-

MFGB-001

H/SBOM -

Validated Vulnerability and FOCI Analysis - Manufacturer Provided BOM

Hardware and Software Bill of Materials - Vulnerability and Foreign Ownership, Control, and Influence Analysis - Manufacturer Provided BOM - Vulnerability and foreign influence analysis of manufacturer-provided hardware and software bill of materials.

Software risk illumination is provided for product vulnerability history, vulnerability notice procedures, and patching cadence. Foreign influence is identified on all identified fourth parties.

Hardware risk illumination is provided for counterfeit, obsolescence, non-conformance, modified components, last-time-buy, not-recommended-for-new-designs, foreign presence, and relations to banned entities.

Bill of materials must be provided to Fortress.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $16,608.10

511210

FGS-AIPR-SBOM-

NFM-001

SBOM - New File Monitoring

Software Bill of Materials - New File Monitoring - Continuous analysis of a product's web location to identify when new versions are released, download the new version, and attempt to generate an SBOM from a binary analysis of the new software. SKU does not include the analysis. Pricing is for a 12-month duration per applicable terms and conditions.

EA $802.07

54151E

COM

FGS-AIPR-SBOM-

RI-001

SBOM - SBOM

Risk Illumination

Software Bill of Materials - Risk Illumination – Analysis includes vulnerability, dependency, integrity, malware, and licensing risks for a single software version. Includes a one-time automated attempt to create an SBOM when Fortress is able to retrieve the respective software (additional SKU is available for continuous monitoring).

Pricing is for a 12-month duration per applicable terms and conditions.

EA $534.71

54151E

COM

FGS-TPRM-

SSDFTPAC-001

SSDF Third Party Attestation Campaign

Secure Software Development Framework Third Party Attestation Campaign - Fortress initiates an outreach to up to 100 third parties in a batch process known as a campaign. The objective is for third parties to complete a questionnaire or upload artifacts related to secure software development. A maximum of three reminders will be sent, and the campaign's duration is limited to 45 days. Includes campaign configuration, third party follow-up (reminders) configuration, dashboard creation for campaign, and recommendations for campaign enhancements. Pricing is for a 12-month duration per applicable terms and conditions.

EA $49,672.54

54151E

COM

FGS-TPRM-

SBOMCOL-001

Software Bill of Materials - Third Party SBOM Collection

Software Bill of Materials - Third Party SBOM Collection - This includes up to three outreach attempts over a 45-day period for a single SBOM. Client shall supply third party contact information. Fortress will offer to third party a meeting, not to exceed 30 minutes, to explain and orchestrate the collection process (e.g., where and how to upload the SBOM). Client must have a Fortress Platform license for this SKU. Pricing is for a 12-month duration per applicable terms and conditions.

EA $1,108.82

54151E

COM

FGS-AIMTP-LTE-

AI Monitoring - Third Party - Lite

AI Monitoring - Third Party - Lite - Includes annual subscription for automated impact & likelihood risk illumination for a given organization.

Impact risk is scored across ten (10) categories - system access, data access, physical access, hosted services, financial, fourth party, offshore operations, reputation, strategic/single/sole source, and geographical footprint.

Likelihood risk is scored across six (6) categories - (1) technology and security, (2) foreign ownership, control, or influence (FOCI), (3) product quality and design, (4) compliance, (5) financial, and (6) manufacturing & supply.

Pricing is for a 12-month duration per applicable terms and conditions.

EA $113.37

54151E

COM

FGS-AIMTP-STD-

AI Monitoring - Third Party - Standard

AI Monitoring - Third Party - Standard - Includes annual subscription for automated impact & likelihood risk illumination for a given organization. Risk indicators include those in the AI Vendor Monitoring - Third Party - Lite plus additional risks.

Over 40 additional checks are performed to address comprehensive vendor and product risk illumination. Risk categories include (1) technology and security, (2) foreign ownership, control, or influence (FOCI), (3) product quality and design, (4) compliance, (5) financial, (6) manufacturing & supply, (7) political & regulatory, (8) transportation & distribution, (9) economic, (10) environment, (11) human capital, and (12) infrastructure.

Each check queries multiple public and private data sources which provide coverage to over a hundred subcategories of risk within the identified 12 categories listed above. Pricing is for a 12-month duration per applicable terms and conditions.

EA $566.85

54151E

COM

FGS-AIMTP-

PREM-001

AI Monitoring - Third Party - Premium

AI Monitoring - Third Party - Premium - Provides the data and reporting from the AI Vendor Monitoring - Third Party

- Standard SKU and includes a validation of all findings and categories by a Fortress third-party risk management analyst. Pricing is for a 12-month duration per applicable terms and conditions.

EA $1,700.55

4866-4106-4719.1 4864-8581-3885.1

APPENDIX A

FORTRESS GOVERNMENT SOLUTIONS

END USER LICENSE AGREEMENT

This End User License Agreement (“Agreement”) by and between Fortress Government Solutions LLC (“Fortress”, “FGS”) and the Ordering Activity under GSA Schedule contracts identified in the Order ( “Client”) sets forth the terms and conditions applicable to the license of Fortress software, subscriptions and data.

1. Definitions.

a. “Client Software” means the software provided by Fortress for installation locally, or via any online interface, by Client.

b. “Content” means any data or content that is provided or uploaded by Client for transmission, storage, integration, import, display, distribution, or use in or through the Products.

c. “Data” means recorded information of any kind regardless of the form or method of recording that is hosted or provided by Fortress through the Client Software or otherwise under the Order.

d. “Documentation” means the user manual, published specifications, online guides, and other materials describing the operation and functionality of the Products made generally available by Fortress to its customers, as updated from time-to-time by Fortress.

e. “Order” means the order through which Client obtains a license or access right to certain Fortress commercial computer software products or contracts for certain services from Fortress.

f. “Product(s)” means the Client Software, Data, and Software specified in the Order.

g. “Software” means the Fortress proprietary commercial computer software, models, and algorithms, and any helpers, extensions, plug-ins, and add-ons, in any format, specified in the Order (and any related purchase orders, statements of work, or amendments, which are incorporated by reference herein) or provided in connection with this Agreement, any third-party software incorporated therein or in the Client Software, and any improvements, modifications, derivative works, patches, Updates, and upgrades thereto that Fortress provides in its discretion to Client hereunder.

h. “Updates” means Product changes that Fortress in its discretion implements in the

4864-8581-3885.1 generally available Products specified in the Order. Updates do not include platform capabilities, configurations, or modules not specified in the Order that Fortress makes available for an additional charge.

2. Term and Termination.

a Term. This Agreement shall begin and remain effective for the period of time specified in the Order (“Term”) either (i) in perpetuity if the Order specifies a perpetual license, or

(ii) for the number months or years set forth in the Order if the Order specifies a term licenses, unless otherwise terminated as provided herein.

b Client Termination for Convenience. During the Term, this Agreement may be terminated by Client for convenience in accordance with the Federal Acquisition Regulation (“FAR”) termination for convenience clause in FAR 52.212-4(l).

c Default. When the End User is an instrumentality of the U.S., recourse against the United States for any alleged breach of this Agreement must be brought as a dispute under the contract Disputes Clause (Contract Disputes Act). During any dispute under the Disputes Clause, FGS shall proceed diligently with performance of this Agreement, pending final resolution of any request for relief, claim, appeal, or action arising under the Agreement, and comply with any decision of the Contracting Officer. The right of the non-defaulting party to terminate this Agreement under this Section is in addition to all other rights that are available to it under this Agreement, at law, or in equity.

d Disposition of Software on Termination. Upon the expiration or termination of this Agreement for any reason, the license and all other rights granted to Client hereunder shall immediately cease, and Client shall: (i) uninstall and return the Products to Fortress together with all reproductions and modifications of the Products and all copies of any Documentation, notes, and other materials respecting the Products; (ii) purge all copies of the Products or any portion thereof from any computer storage device or medium on which Client has placed or has permitted others to place the Products, including copies of the Products made for archival and backup purposes; and (iii) provide Fortress a written certification that Client has complied with all of its obligations under this Section.

e Return of Content. Upon expiration or termination of this Agreement for any reason, Fortress will promptly make all Content available to Client for electronic retrieval for a period of ninety (90) days following the effective date of termination or expiration

3. Limited License to Software. Subject to Client’s compliance with this Agreement, Fortress grants to each Client individually a non-transferable, non-assignable, non-exclusive, limited license without any right to sublicense or share with Client-related entities during the Term to install, execute, and use the Software in object code format solely for Client’s internal purposes as specified in the Order and in accordance with the Documentation (this “Software License”).

This Software License is not fungible and shall not be reallocated or expanded by Client for any purpose not specified in the Order. This Software License may not be shared with or among separate governmental departments or agencies unless otherwise specified in the Order. Client

4864-8581-3885.1 acknowledges and agrees that Fortress may use certain embedded technological and software controls to enforce any applicable restrictions on this Software License.

4. Limited License to Data. Subject to Client’s compliance with this Agreement, Fortress grants to each Client individually a non-transferable, non-assignable, non-exclusive, limited license without any right to sublicense or share with Client-related entities during the Term to use the Data solely for Client’s internal purposes as specified in the Order and in accordance with the Documentation (this “Data License” and together with the Software License, the “Licenses”). This Data License may not be shared with or among separate governmental departments or agencies unless otherwise specified in the Order. This Data License is not fungible and shall not be reallocated or expanded by Client for any purpose not specified in the Order. Client and Client’s contractors, employees, or others given access to Data may not use the Data for any purpose other than Client’s internal business purposes as specified in the Order nor share any Data externally in any form, including but not limited to, disclosing excerpts or portions of any Data in any externally shared documentation, marketing materials, reports, or any other externally distributed materials.

Ownership of Intellectual Property. Client acknowledges and agrees that notwithstanding anything to the contrary in the Order, the Software, Data, Products, Updates, Documentation, any other related documents, materials, or information provided by Fortress or developed by Fortress under the Order, and any and all ideas, processes, techniques, designs, architecture, and “know-how” embodying the foregoing (the “Materials”), are and shall remain the sole and exclusive property of Fortress, and all right, title and interest in and to the Materials shall remain with Fortress including any intellectual property rights or rights in any trademark, copyright, or patent of the foregoing (“Fortress Intellectual Property”). No ownership rights in the Materials or Fortress Intellectual Property are being conveyed to Client under this Agreement.

Nothing in this or any other agreement or in the course of dealing between Fortress and Client shall be construed to grant to Client any ownership right, title or interest in or license to any of the Fortress Intellectual Property, title to which at all times will vest exclusively in Fortress. This is not a “work made for hire” agreement, as that term is defined in Section 101 of Title 17 of the United States Code. Except for the express Licenses granted herein, Fortress does not grant any other licenses, whether express or implied, to any Fortress software, services, technology, or intellectual property. Client will preserve the Products from any liens, encumbrances, and claims of any individual or entity. Client shall maintain and not remove, obscure, or alter any intellectual property notices, trademarks, logos, tradenames, or other identifiers or notices that appear on any Products or Documentation or any other materials, software, data, or Fortress Intellectual Property.

Client will not use any Fortress Intellectual Property or Confidential Information to contest the validity of any of Fortress’s intellectual property rights, and any such use of the foregoing will constitute a material, non-curable breach of this Agreement. The provisions of this section shall survive expiration or termination of this Agreement for any reason. Nothing herein shall restrict the ability of Fortress to use and disclose the Materials and the Fortress Intellectual Property in any manner and for any reason, provided for U.S. Government contracts, such use and disclosure complies with applicable law including, without limitation, export controls laws and restrictive markings included on Content provided by the Client. Fortress reserves the right to modify the Products for any reason, without notice and without liability to Client or any Authorized User, to comply with applicable law and Fortress further reserves the right to otherwise modify and update

5.

4864-8581-3885.1 the Products from time to time in its discretion, provided Fortress does not materially reduce the functionality of the Products as set forth in the Documentation during the Term.

6. Restrictions on Use of Fortress Intellectual Property. Client shall not, and shall not allow any third party to infringe upon the Fortress Intellectual Property. Client shall require Authorized Users to agree to the terms of this Agreement, and shall be responsible for ensuring Authorized Users’ compliance with this Agreement. Client shall not, and shall not allow any Authorized User or third party to (i) decompile, disassemble, scan, reverse engineer, modify, translate, or attempt to discover any source code, underlying ideas, algorithms, trade secrets, or other data of any Products (except to the extent applicable law expressly prohibits such a restriction); (ii) distribute, rent, sell, provide, lease, lend, use for timesharing or service bureau purposes, or otherwise use or allow others to use a Product for the benefit of any third party; (iii) list or otherwise display, copy, or reuse any code of any Product; (iv) copy any Products or components thereof, except where Client is hosting is specified then Client may make a reasonable number of copies of the Software as well as Documentation solely for backup, archival or disaster recovery purposes in compliance with the Software License; (v) develop any improvement, modification, or derivative work of the Products or include a portion thereof in any equipment or item; (vi) allow the transfer, transmission, public communication, export, or re-export of any Fortress Intellectual Property or any portion thereof; (vii) conduct performance, benchmark, or other testing or technical evaluations of the Products without prior written consent from Fortress;

(viii) gain or attempt to gain unauthorized access to the Products, or any element thereof, or…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .