50310224R0009_corrected.pdf

PDF 486 KB Posted

Attached to
13F List Services Federal contract opportunity
Solicitation number
50310224R0009
Issued by
Securities and Exchange Commission

About this file

This document is a Request for Proposal (RFP) for 13F List Services, a quarterly list of public securities that complies with Section 13(f) of the Securities Exchange Act of 1934. The objective is for the contractor to provide services to the Securities and Exchange Commission (SEC) to compile and deliver the 13F List.

The RFP outlines the scope of the 13F List, the format and data sources required, and the contractor's responsibilities, including delivering the 13F List within 1-2 business days before the end of each calendar quarter and providing an annual certification on the data compilation process. Proposals are due by 5:00 PM EST on June 14, 2024, and award will be made to the responsible offeror whose proposal represents the best value to the government, considering technical approach, management approach, past performance, and price. The contract has a one-year base period and four one-year option periods.

View the file

Other files for this federal contract opportunity

Other files attached to 13F List Services, newest first.
File Type Posted
50310224R0009_24MAY2024.pdf PDF
Questions and Answers 50310224R0009.pdf PDF
Att 4_13F List.txt TXT text file
Att 3_13F_Report.pdf PDF
Att 2_ NDA Contractor Personnel.pdf PDF
50310224R0009.pdf PDF
Att 1_NDA Contractor Entity.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

50310224R0009

SOLICITATION, OFFER AND AWARD

4. TYPE OF SOLICITATION2. CONTRACT NUMBER 3. SOLICITATION NUMBER

7. ISSUED BY CODE 8. ADDRESS OFFER TO (If other than Item 7)

ORDER UNDER DPAS (15 CFR 700)

6. REQUISITION/PURCHASE NUMBER

NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".

NEGOTIATED (RFP)

SEALED BID (IFB)

5. DATE ISSUED

1. THIS CONTRACT IS A RATED RATING PAGE OF PAGES

1 35

C. E-MAIL ADDRESS

EXT.NUMBERAREA CODE

B. TELEPHONE (NO COLLECT CALLS)A. NAME

10. FOR

INFORMATION

CALL:

CAUTION: LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.

(Date)(Hour) local timeuntildepository located in copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if hand carried, in the

SOLICITATION

9. Sealed offers in original and

PART IV - REPRESENTATIONS AND INSTRUCTIONS

OTHER STATEMENTS OF OFFERORS

EVALUATION FACTORS FOR AWARD

INSTRS., CONDS., AND NOTICES TO OFFERORS

REPRESENTATIONS, CERTIFICATIONS AND

LIST OF ATTACHMENTS

CONTRACT CLAUSES

PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.

I

J

K

L

M SPECIAL CONTRACT REQUIREMENTS

CONTRACT ADMINISTRATION DATA

DELIVERIES OR PERFORMANCE

INSPECTION AND ACCEPTANCE

PACKAGING AND MARKING

DESCRIPTION/SPECS./WORK STATEMENT

SUPPLIES OR SERVICES AND PRICES/COSTS

SOLICITATION/CONTRACT FORM

PART II - CONTRACT CLAUSESPART I - THE SCHEDULE

H

G

F

E

D

C

B

A

SEC. DESCRIPTION PAGE(S) (X) DESCRIPTION SEC. (X)

11. TABLE OF CONTENTS

18. OFFER DATE17. SIGNATURE

SUCH ADDRESS IN SCHEDULE.

IS DIFFERENT FROM ABOVE - ENTER

15C. CHECK IF REMITTANCE ADDRESS

EXT.NUMBERAREA CODE

15B. TELEPHONE NUMBER

(Type or print)AND

ADDRESS

OF

OFFEROR

CODE FACILITY

16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN OFFER15A. NAME

DATEAMENDMENT NO.DATEAMENDMENT NO.

and related documents numbered and dated):

amendments to the SOLICITATION for offerors

(The offeror acknowledges receipt of

14. ACKNOWLEDGEMENT OF AMENDMENTS

CALENDAR DAYS (%)30 CALENDAR DAYS (%)20 CALENDAR DAYS (%)10 CALENDAR DAYS (%)

(See Section I, Clause No. 52.232.8)

13. DISCOUNT FOR PROMPT PAYMENT

designated point(s), within the time specified in the schedule.

by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

OFFER (Must be fully completed by offeror)

IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.

28. AWARD DATE

(Signature of Contracting Officer)

27. UNITED STATES OF AMERICA

25. PAYMENT WILL BE MADE BY

26. NAME OF CONTRACTING OFFICER (Type or print)

CODE 24. ADMINISTERED BY (If other than Item 7)

ITEM

(4 copies unless otherwise specified)

23. SUBMIT INVOICES TO ADDRESS SHOWN IN

41 U.S.C. 253 (c) ( 10 U.S.C. 2304 (c) (

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

21. ACCOUNTING AND APPROPRIATION20. AMOUNT19. ACCEPTED AS TO ITEMS NUMBERED

AWARD (To be completed by government)

CODE

05/15/2024 X

SEC-OA - 03

SECURITIES AND EXCHANGE COMMISSION

OFFICE OF ACQUISITIONS

MISSION AND OPERATIONS SUPPORT BRANCH

100 F STREET NE

MAIL STOP 4226

WASHINGTON DC 20549

1700 ES 06/14/2024

KATHLEEN FERTE 202

fertek@sec.gov

551-6946

X

X

X

X

X

X

X

X

X

X

X

X

X

PAGE(S)

KATHLEEN FERTE

AUTHORIZED FOR LOCAL REPRODUCTION

Previous edition is unusable

STANDARD FORM 33 (Rev. 9-97)

Prescribed by GSA - FAR (48 CFR) 53.214(c)

12. In compliance with the above, the undersigned agrees, if this offer is accepted within _____0_________ calendar days (60 calendar days unless a different period is inserted

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

NAME OF OFFEROR OR CONTRACTOR

2 35

CONTINUATION SHEET

REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF

50310224R0009

(A) (B) (C) (D) (E) (F)

To procure a list of all equity securities to be reported pursuant to Section 13(f) of the

Securities Exchange Act of 1934, Rule 13F-1(c).

Period of Performance: 09/01/2024 to 08/31/2025

00001 Base Period: The Contractor shall provide the services necessary to provide the 13F List in accordance with Section C, Statement of Work.

00002 Option Period One: The Contractor shall provide the services necessary to provide the 13F List in accordance with Section C, Statement of Work.

(Option Line Item)

Period of Performance: 09/01/2025 to 08/31/2026

00003 Option Period Two: The Contractor shall provide the services necessary to provide the 13F List in accordance with Section C, Statement of Work.

(Option Line Item)

Period of Performance: 09/01/2026 to 08/31/2027

00004 Option Period Three: The Contractor shall provide the services necessary to provide the 13F List in accordance with Section C, Statement of Work.

(Option Line Item)

Period of Performance: 09/01/2027 to 08/31/2028

00005 Option Period Three: The Contractor shall provide the services necessary to provide the 13F List in accordance with Section C, Statement of Work.

(Option Line Item)

Period of Performance: 09/01/2028 to 08/31/2029

OPTIONAL FORM 336 (4-86)

Sponsored by GSA

FAR (48 CFR) 53.110

NSN 7540-01-152-8067

RFP 50310224R0009

SECTION C – DESCRIPTION/SPECIFICATIONS

C-1. Introduction:

The Securities and Exchange Commission (SEC) is an independent federal agency charged with primary responsibility for enforcing the federal securities laws and regulating the securities industry, the nation’s stock and options exchanges, and other electronic securities markets in the United States. With its headquarters located in Washington, D.C., the agency’s functional responsibilities are organized into 5 Divisions and 16 Offices. The approximately 4,000 staff members are located in the Washington, D.C. area and 11 Regional Offices throughout the country.

C-2. Background:

In 1975, Congress passed Section 13(f) of the Securities Exchange Act of 1934 (the “Act”) in order to increase the public availability of information regarding the securities holdings of institutional investors. Congress believed that this institutional disclosure program would increase investor confidence in the integrity of the United States securities markets. Under Section 13(f), the Securities and Exchange Commission (“SEC”) has adopted Rule 13f-1 under the Act and Form 13F.

Rule 13f-1 requires an institutional investment manager to file electronically through the Electronic Database Gathering, Analysis, and Retrieval (EDGAR) system a report on Form 13F with the SEC, if: (1) the manager exercises investment discretion with respect to accounts holding certain equity securities, as defined in Rule 13f-1(c); and (2) the aggregate fair market value on the last trading day of any month of any calendar year of such equity securities is at least $100,000,000. Such filings must be made within 45 days after the last day of such calendar year and within 45 days after the last day of each of the first three calendar quarters of the subsequent calendar year.

Pursuant to Section 13(f)(4) of the Act1, the SEC is required to make available to the public a list of all equity securities to be reported pursuant to Section 13(f), i.e., the “section 13(f) securities” that are defined in Rule 13f-1(c). Such list must be updated no less frequently than such reports are required to be filed with the SEC.

C-3. Objective:

The SEC’s objective of this Contract is to allow the SEC to make public quarterly a report consisting of a list of securities which complies with the requirements of Section 13(f) and Rule 13f-1 to be used by institutional investment managers in the preparation and filing of Form 13F with the SEC (such list, the “13F List”).

C-4. Scope of the 13F List:

Contractor shall provide services to the SEC in order to compile a 13F List which shall consist of the following:

A. The securities on each 13F List shall include (1) all securities that are “section

13(f) securities” within the meaning of Rule 13f-1(c) under the Act, and (2) such other securities as the SEC or its staff determine are to be included on the 13F List consistent with the requirements, policies and purposes of Section 13(f) of the Act and Rule 13f-1 thereunder.

B. With respect to each security on the 13F List, the list shall include:

1) Name of the issuer of the security;

2) Description of the title and class of the security issued (presented in a manner to be mutually agreed by the SEC and Contractor); and

3) Committee on Uniform Securities Identification Procedures (“CUSIP”) number of such security, if applicable.1

C. The securities on the 13F List should be organized alphabetically by name of the issuer. In the case of any security with listed options, such security shall be listed before any such options and an asterisk may be placed next to such security’s name in order to indicate that it has one or more listed options.

D. In order to reflect securities that are added or deleted from the 13F List each quarter, revisions that have been made to the 13F List may be indicated in a column titled “STATUS.” The word “ADDED” may be included in this status column opposite the name of a particular security in order to indicate that such security has been included as a “13(f) security” in such 13F List since the date on which the most recent calendar quarter has ended (i.e., the end date of the calendar quarter to which the last published 13F List pertains). The word “DELETED” may be included in this status column opposite the name of a particular security in order to indicate that such security has ceased to be a “13(f) security” since the date on which the most recent calendar quarter has ended.

E. Each 13F List must be current as of the calendar end date of the calendar quarter to which such 13F List relates. Quarters in a year as follows:

Date Ranges Quarter Name

01/01/YYYY - 03/31/YYYY Q1

04/01/YYYY - 06/30/YYYY Q2

07/01/YYYY - 09/30/YYYY Q3

10/01/YYYY - 12/31/YYYY Q4

Example of year and next year: Year – 2024 and Next year - 2025

1 In order to comply with Section 13(f) (and Form 13F as adopted by the Commission under this section), the securities information on the 13F List is required to include CUSIP numbers. Therefore, under current legal requirements, an alternative unique securities identifier may not be substituted.

F. Upon the SEC’s request, Contractor shall provide a glossary of any abbreviations contained in the 13F List.

C-5. Format of Each 13F List:

Each 13F List shall be submitted to the SEC in an electronic format acceptable to the SEC and accessible by the SEC staff. This electronic delivery shall be submitted both in textual (*.txt) and non-textual (*.pdf) format through well-known File Transfer Protocol (FTP) to the designated SEC business unit and that is consistent with the requirements, policies and purposes of Section 13(f) of the Act and Rule 13f-1 thereunder. The 13F list data in the .pdf format must exactly match with the data format currently published in the sec.gov (https://www.sec.gov/files/investment/13flist2023q3.pdf). SEC will not be able to provide character spacing in each record of the 13F list. It is the vendor responsibility to extract the formatting (character spacing in each record) from the currently published .pdf file. A sample .txt and .pdf file can be given to the potential vendors if needed. The SEC reserves the right to convert each 13F List into another format for publication, including for any continued posting of the 13F List on the SEC’s website. The SEC also preserves the right to publish either or both formatted data file(s) (*.pdf and *.txt) wherever and whenever it thinks fit.

C-6. Data Sources Required to Compile the 13F List:

Contractor shall have all the proper controls and processes in place for the services required to produce the 13F List accurately and completely. Contractor is responsible for obtaining all the necessary data to create each 13F List (the “13F List Data”). The 13F List Data required includes, but is not limited to, access to CUSIP data for all of the securities to be included on each 13F List, including CUSIP numbers and standard descriptions.2 Contractor is solely responsible for acquiring and maintaining sufficient rights to the 13F List Data, including any required licenses or permissions.

C-7. Annual Certification by Contractor:

No less than annually, Contractor shall provide the SEC with a written certification that describes the data compilation steps involved in the services required to produce each 13F List and the quality assurance measures it takes with respect to such services (e.g., Independent Verification and Validation (IV&V), edit checks, statistical sampling and/or change reports with respect to internal processes used to prepare the 13F List).

C-8. SEC Contact Person(s) for Data, Technical or Transmission Issues:

In case of any data, technical or transmission issues that arise in the course of Contractor’s preparation or delivery of a 13F List, Contractor should contact the COR and Alt-COR for this Contract.

C-9. Use of Information:

2 CUSIP numbers and standard descriptions currently are maintained by Standard & Poor’s CUSIP Service Bureau, a division of The McGraw-Hill Companies, Inc., on behalf of the American Bankers Association.

Contractor shall not release the 13F List to any party other than the SEC prior to publication (or other public dissemination, as appropriate) of such 13F List by the SEC. Contractor’s work to compile the 13F List should be in a controlled environment to ensure that the work product to be delivered is kept non-public prior to delivery of the 13F List to the SEC each calendar quarter and prior to publication of such calendar quarter’s 13F List by the SEC. The SEC recognizes that the 13F List is not confidential or non-public. Nevertheless, because Section 13(f)(4) of the Act and Rule 13f-1(c) thereunder require the SEC to make the 13F List publicly available, access to the 13F List must be timely and equitable per 44 U.S.C. § 3506. Accordingly, no person other than the SEC and Contractor may be permitted access to the 13F List, or the compiled data contained therein (e.g., preliminary or interim drafts or versions), prior to the contemporaneous quarterly publication (or other public dissemination, as appropriate) of such 13F List by the SEC in accordance with the requirements of the Act and the rules promulgated thereunder.

Notwithstanding the above, this section does not preclude Contractor from using CUSIP data contained in a 13F List for other non-Form 13F purposes related to its business needs and/or operations.

C-10. Future 13F List Changes or Enhancements:

The parties recognize that the 13F List implements federal law and regulatory policies that may periodically change and that such changes may result in updates to the requirements of the 13F List in order to reflect such law and policies. (This includes current and future federal law and guidance pertaining to security in federal information systems.) It is also expected that, from time to time, the SEC will recommend enhancements to the 13F List, including enhancements to maintain compatibility with the SEC’s other systems (e.g., EDGAR), to keep the 13F List technologically up-to-date or improve the presentation of the information provided to the public in the 13F List. Such recommendations should be governed by the Changes clause of this Contract. Therefore, Contractor agrees that it will make all reasonable efforts to make the changes or enhancements to the 13F List requested by the SEC or its staff.

SECTION D – PACKAGING AND MARKING

SEC 2001.00 SHIPPING INSTRUCTIONS (JANUARY 2022)

Preservation, packaging, packing, and marking of all deliverables must conform to normal commercial packing standards to assure safe delivery at destination. All deliveries are F.O.B.

Destination. The Contractor shall include the SEC contract number on all packing slips that accompany items shipped to the SEC.

SECTION E – INSPECTION AND ACCEPTANCE

See Section I for applicable Federal Acquisition Regulation Clause(s).

SECTION F – DELIVERIES OR PERFORMANCE

F.1 PLACE OF DELIVERY - F.O.B. DESTINATION

The deliverables to be furnished under this contract shall be delivered to the following address:

U.S. Securities and Exchange Commission 100 F Street NE Washington DC 20549 Attn:

Phone Number: 202-551- E-mail:

F.2 DELIVERABLES

The Contractor shall submit all deliverables required under the contract to the SEC. Contractor shall be responsible for the quality of the data (13F list) in terms of data integrity, validity and veracity before submitting the data to the SEC. The SEC shall not be responsible for verifying the accuracy of the data received from the contractor. All deliverables shall be formatted by the contractor and prepared in a non-textual (imaged) PDF format. The SEC will review all deliverables for formatting conformance only and will provide a list of formatting corrections to the Contractor within 20 business days. If the SEC does not provide the Contractor with a list of formatting corrections within 20 business days, the 13F List shall be considered to be accepted by the SEC. If additional formatting corrections to a 13F List are required after acceptance of such 13F List by the SEC, then the SEC shall provide a list of such formatting corrections to be included to Contractor as soon as practicable.

The Contractor shall on an ongoing basis conduct IV&V of the data provided to the SEC so that the integrity, veracity, and validity of the data remain intact. After publishing the data, if the SEC receives feedback(s) from the 13F list data consumers in regard to the data in question, the SEC will compile all public comments along with its own (if any) and will send them to the Contractor for correction or justification. The Contractor shall re-deliver the corrected list as per the deliverable schedule and shall exercise due diligence to make sure the same or similar error(s) does not happen in the subsequent deliverables.

The deliverables specified in the table below are required and shall be delivered electronically to an SEC identified point of contact, the Contracting Officer’s Representative (COR) and the Alternate Contracting Officer’s Representative (ALT-COR).

F.3 SEC 4003.01 SCHEDULE OF DELIVERABLES (JANUARY 2022)

SOW Task Deliverables Schedule Distribution C-4, C-5, C-

13F List Within 1-2 business days before the end date of each calendar quarter

COR/Alt-

COR/SEC

Identified POC

C-4, C-5, C-

Corrected 13F List

Within 3 business days after the SEC's list of corrections is received by Contractor

COR/Alt-

COR/SEC

Identified POC

C-7 Certification At least annually, no less than sixty calendar days before the end of the performance period of the contract

COR/Alt-

COR/SEC

Identified POC

F.4 PERIOD OF PERFORMANCE

The Period of Performance for this contract shall be from Date of Award through one year. The contract has four one-year options. At the end of the base year, if exercised, the first option will begin. If all options are exercised, the period of performance will not exceed a total of five years.

If exercised, the period of performance for each successive option will begin the day after expiration of the previous period. Exercise of any option requires a contract modification signed by the SEC Contracting Officer.

SECTION G – CONTRACT ADMINISTRATION DATA

G.1 5003.05 SUBMISSION OF INVOICES - DELPHI EINVOICING SYSTEM

(JANUARY 2022)

a. The Securities and Exchange Commission (SEC) will only accept electronic invoices submitted through the Delphi eInvoicing system on a monthly basis.

b. Payment system registration. All persons accessing the Delphi eInvoicing web-portal will be required to have their own unique user Delphi eInvoicing ID and password and be credentialed through login.gov.

(1) Electronic authentication. See www.login.gov for instructions. Click on the following link for instructions on establishing a login.gov account: https://login.gov/help/creating-an-account/how-do-i-create-an-account-with-logingov/.

(2) To create a login.gov account, the user will need a valid email address and a working phone number. The user will create a password and then login.gov will reply with an email confirming the email address.

(3) In order to set up a new user account or make changes to existing vendor Delphi eInvoice users who will submit invoices through the eInvoicing web-portal for payment and tracking purposes, notify iSupplier@sec.gov and include the contract/order number, the user's full name, valid email address (group mailboxes are not recommended), and current phone number of all vendor users. Vendor users will be notified via e-mail when the account is created. The vendor user will be provided detailed instructions for logging into their Delphi eInvoicing account.

(4) Training on Delphi. To facilitate use of DELPHI, comprehensive user information is available at http://einvoice.esc.gov

(5) Account Management. Vendors are responsible to contact the Delphi Help Desk when their firm's points of contacts will no longer be submitting invoices so they can be http://www.login.gov/ https://login.gov/help/creating-an-account/how-do-i-create-an-account-with-logingov/ https://login.gov/help/creating-an-account/how-do-i-create-an-account-with-logingov/ mailto:iSupplier@sec.gov http://einvoice.esc.gov/ removed from the system. Instructions for contacting the Delphi Help Desk can be found at http://einvoice.esc.gov

c. Contractors are cautioned against submitting an invoice prior to goods and services being received/accepted. Invoices submitted prematurely may be rejected. Software license maintenance and subscriptions may be invoiced at the beginning of the contract period of performance.

d. The SEC's Delphi eInvoicing system is managed by the Enterprise Services Center (ESC). In order to receive payment and in accordance with the Prompt Payment Act, all invoices submitted as attachments in the Delphi eInvoicing web-portal shall contain the following:

(1) Company logo or letterhead

(2) Company name and payment address

(3) Company Point of Contact (POC) for the invoice with phone and e-mail

(4) Invoice number and invoice date

(5) Billing period

(6) SEC Contract number

(7) Task/Delivery Order number (if applicable)

(8) SEC Contracting Officer's Representative (COR name)

(9) Amount billed (by CLIN), current and cumulative

(10) Total amount billed this period

(11) Cumulative total billed to date

(12) Brief Description of Services Performed - General description only

e. If the contract includes allowances for travel, all invoices which include charges pertaining to travel expenses will catalog a breakdown of reimbursable expenses with the appropriate receipts to substantiate the travel expenses.

G.2 SEC 5004.00 APPOINTMENT OF CONTRACTING OFFICER’S

REPRESENTATIVE (COR) (JANUARY 2022)

a. A Securities and Exchange Commission COR has been designated for administration and information relating to this contract. The SEC may also assign one or more Alternate CORs for this contract. The COR may not re-delegate his or her authority; only the CO has this authority. A COR Appointment Letter (and ACOR Appointment Letter if applicable) detailing the designations will be e-mailed to the contractor.

b. The COR will manage the contract in coordination with the CO and within the terms of the contract. The COR’s responsibilities include reviewing invoices and charges by the Contractor, informing the CO of areas where exceptions are taken, and accepting or rejecting invoices in the SEC’s financial system. The COR shall be the primary point of contact responsible for communicating administrative guidance for on-boarding and off-boarding of Contractor Personnel, mandatory trainings, government closures, and other events as necessary. Unless otherwise specified in this contract, inspection and acceptance of supplies and/or services to be furnished under this contract will be performed by the COR.

http://einvoice.esc.gov/

c. Only the CO has the authority to change the terms and conditions of this contract. The COR may request a contract modification, but the CO will make the final determination. The COR may not agree to or issue a change to the contract terms and conditions. In the event the Contractor effects changes to the contract at the direction of any person other than the CO, the changes will be considered to have been made without any authority and no adjustments will be made to the contract.

SECTION H – SPECIAL CONTRACT REQUIREMENTS

H.1 SEC 6001.00 SEC NON-DISCLOSURE REQUIREMENTS AND AGREEMENTS

(AUGUST 2022)

a. Required non-disclosure agreements are attached and must be completed and returned to the Contracting Officer before starting work under this contract.

b. Provisions of the SEC Regulation Concerning Conduct of Members and Employees and

Former Members and Employees of the Commission expressly prohibit unauthorized disclosure and improper use of confidential or non-public information or documents. See 17 C.F .R. § 200.7353(b)(1) & (b)(2). The Contractor, and its employees, agents, subcontractors, and subcontractor personnel who will have access to confidential or non-public information or documents in the performance of the contract, agree to be bound by the provisions of Sections 200.735-3(b)(1) and 200.735-3(b)(2) of the SEC's Regulation Concerning Conduct and the terms set forth in the attached non-disclosure agreements (Attachments 1& 2). For purposes of this clause, “confidential or non-public information,” is defined as information generated by or in the possession of the SEC that is commercially valuable, trade secret, market sensitive, proprietary, related to an SEC enforcement or examination matter, subject to privilege, protected by the Privacy Act (5 U.S.C. § 552a), or otherwise deemed confidential or non-public by an SEC division director or office head, and is not otherwise available to the public.

c. An officer or executive authorized to bind the Contractor shall execute the non-disclosure agreement (Attachment 1) on behalf of the Contractor and return it to the Contracting Officer prior to the Contractor commencing work on the contract. The Contractor shall submit to the Contracting Officer a list of its employees, agents, and subcontractors that will be authorized access to SEC information by virtue of performing the requirements set forth in this contract. Each person identified on the list shall then sign the non-disclosure agreement on behalf of themselves (Attachment 2) and submit it to the Contracting Officer before commencing work on the contract.

d. The Contractor shall also ensure that all of its employees, agents, and subcontractors assigned to perform the requirements set forth in this contract adhere to the terms of the non-disclosure agreement, protecting all confidential or non-public information, and to not divulge to any unauthorized person. Assignment of staff who has not executed the non-disclosure agreement or failure to adhere to this statement shall result in action by the Contracting Officer, as deemed appropriate. Violation of this clause or the attached non-disclosure agreements by the Contractor, its employees, agents, subcontractors, or subcontractor personnel may result in default of the contract and/or civil suits and/or criminal prosecution.

H.2 SEC 6001.01 RESTRICTIONS ON USE, DISCLOSURE, AND DUPLICATION OF

CONFIDENTIAL AND NON-PUBLIC INFORMATION (JANUARY 2022)

Confidential or non-public information, for purposes of this clause, includes but is not limited to, all financial, statistical, personnel and/or technical data which is furnished, produced, generated, or otherwise available to the Contractor, during the performance of this contract. Unless otherwise specified, confidential or non-public information shall not be used for purposes other than performance of work under this contract without the prior written consent of the Contracting Officer. The Contractor and its employees, agents, subcontractors, and subcontractor personnel are restricted from duplicating or disclosing confidential or non-public information, in whole or in part, outside the Securities and Exchange Commission (SEC) for purposes other than fulfillment of the requirements set forth in this contract. Any presentation of any confidential or non-public information, or any reports or material derived from confidential or non-public information shall be subject to review of the Contracting Officer prior to publication or dissemination. Any questions about whether information is confidential or non-public shall be referred to the Contracting Officer prior to use disclosure or duplication.

H.3 SEC 6004.00 APPROVAL OF SUBCONTRACTS (JANUARY 2022)

The Contractor shall not enter into a contractual agreement with any party to furnish any of the work or services under this contract/agreement without the written approval of the Contracting Officer. This provision shall not be interpreted as requiring the approval of contracts for employment between the contractor and personnel assigned for services thereunder.

H.4 SEC 6002.00 TYPE OF CONTRACT (JANUARY 2022)

This is a Firm Fixed Price type contract.

H.5 SEC 6006.00 CONFLICTS OF INTEREST (JANUARY 2022)

(a) General

Subpart 9.5 of the Federal Acquisition Regulation (FAR) 48 C.F.R. 9.5, prescribes responsibilities, general rules, and procedures for identifying, evaluating, and resolving organization conflicts of interest.

(b) Purpose The purpose of this SEC Instruction (SECI) is to avoid, neutralize, or otherwise mitigate organizational conflicts of interest which might exist related to a Contractor’s performance of work required by this contract. Such conflicts may arise in situations including, but not limited to:

(1) A Contractor’s participation as an offeror, or representative of an offeror, in a procurement in which it has provided assistance in the preparation of the Government’s requirements and specifications;

(2) A Contractor providing advisory assistance to the Government for a procurement in which the Contractor, or a firm which the Contractor represents, is an actual or potential offeror; and

(3) A Contractor’s participation as an offeror, or representative of an offeror, in a procurement where the Contractor has obtained confidential or proprietary information relating to competing offers as a result of the Contractor’s work on prior contracts.

(c) Definition

For the purposes of this SECI, the term “Contractor” means: the Contractor; any of the Contractor’s parents, affiliates, or other entities in which the Contractor or such parents or affiliates have a financial interest; successors in interest to the Contractor or any of its parents or affiliates; proposed consultants or subcontractors at any tier; and employees thereof.

(d) Restrictions The Contractor agrees:

(1) To remain ineligible to participate in any capacity (including participating as a prime contractor, subcontractor, or as the representative of another party) in offers, contracts, or subcontracts (whether solicited or unsolicited) that directly relate to the Contractor’s performance of work under this contract.

(2) To execute, prior to beginning work on a contract, such Confidentiality Agreements, Non-Disclosure Agreements, or other documents which the Contracting Officer may, in their sole discretion, require in order to protect the proprietary nature or confidentiality of information provided by the Government or otherwise received by the Contractor in connection with its work under this contract.

(3) As otherwise provided in this contract, not to accept any compensation or any other form of payment from a broker, potential lessor, or any source other than the Government for services rendered under this contract, and to employ aggressive strategies to minimize the Government’s lease costs where the Contractor would be entitled by common business practice to receive a real estate commission or any form of payment from a broker, potential lessor, or other party, for work performed under this contract.

(4) To immediately notify the Contracting Officer of any offer of compensation, other form of payment, or thing of value, made by a broker, potential lessor, or any source other than the Government to the Contractor related to services rendered under this Contract, regardless of whether such offer was made during Contractor’s performance of work under a given contract or subsequent to Contractor’s completion of work under such contract.

(5) Prior to the acceptance of a contract, request to immediately notify the Contracting

Officer of any potential conflict of interest which would prevent or limit the Contractor’s ability to perform the work required under the contract.

(6) To immediately notify the Contracting Officer of any conflict of interest discovered during the Contractor’s performance of work pursuant to a Government contract;

provided that the Contracting Officer shall have the right to impose such restrictions as they deem appropriate on Contractor’s performance based on the existence of such a conflict or, if the Contracting Officer determines that such restrictions would not adequately address the conflict of interest at issue, to terminate the Contractor’s performance of work under the contract at no cost to the Government.

(7) As otherwise provided in this contract, that if the Contractor declines to accept a task order request and subsequently participates (either directly or as a representative of another party) in a Government procurement action that was the subject of the task order request, then the fee which the Contractor would have been entitled to receive for such task order work or the fee actually paid by the Government for the task order’s performance by another contractor, whichever is greater, shall be applied toward the Contractor’s minimum order guarantee.

(8) That in the event that the Contractor knowingly withholds the existence of a conflict of interest from the Government, that the Contracting Officer may terminate this contract at no cost to the Government and any minimum guarantee(s) otherwise applicable to the Contractor will be forfeited; provided, that the foregoing shall be in addition to all other remedies and causes of action which the Government may have against the Contractor, including the suspension and/or debarment of the Contractor.

(9) To include this Conflict of Interest SEC Instruction, including this subparagraph, in all of the Contractor’s subcontracts at all tiers (appropriately modified to preserve the Government’s rights hereunder) which involve the performance of work by subcontractors in support of this contract.

(10) That, in addition to the remedies enumerated above, the Government may terminate this contract for cause in the event of the Contractor’s breach of any of the above restrictions.

H.6 SEC 6007.00 COMPLIANCE WITH REGULATIONS (JANUARY 2022)

a. The Contractor shall comply with all statutes, regulations, directives, instructions, and references applicable to the conduct of this acquisition as imposed by the Federal Government and the SEC, including, without limitation, those specified or referred to in this contract.

b. The Contractor and its employees performing work on-site at SEC facilities shall become acquainted with and shall comply with the rules and regulations of the SEC’s facilities, including, but not limited to security, controlled access, personnel clearances, and conduct with respect to health and safety at the site, regardless of whether or not title to the facility is vested in the SEC.

H.7 SEC 6012.02 SEC SECTION 508 REQUIREMENTS (JANUARY 2022)

a. Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, all Information and Communication Technology (ICT) products and services developed, acquired, maintained, and/or used under this contract/order must comply with the Information and Communication Technology Accessibility Provisions set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in FAR 39.203(a). The complete text of Section 508 Final Provisions can be accessed at Section 508 Law.

b. All ICT products must comply with the following requirements. Descriptions of the requirements are viewable at the link Section 508 Standards.

c. Offerors that fail to demonstrate compliance with the above requirements, may be eliminated from further consideration for award.

d. The offeror shall indicate for each line item in the schedule whether each product or service is compliant or non-compliant with the accessibility requirements at 36 CFR 1194 using a Voluntary Product Accessibility Template (VPAT 2.4). Further, the solicitation response must indicate where full details of compliance can be found (e.g., vendor’s website or other exact location).

e. Offerors to this solicitation must provide any additional detailed information necessary for determining applicable Section 508 standards conformance. If an offeror claims its products and/or services, including ICT deliverables such as electronic documents, web content or electronic reports, meet applicable Section 508 standards, and it is later determined by the Government – i.e., after award of a contract/order, that products and/or services delivered do not conform to the described accessibility, remediation of the products and/or services to the level of conformance specified in the contract will be the responsibility of the offeror at its expense.

H.8 SEC 6013.01 FEDERAL REQUIREMENTS, SECURITY, AND ACCESSIBILITY

FOR INFORMATION SYSTEMS (JANUARY 2022)

a. Information Systems Authorization to Operate (ATO): Information systems containing Securities and Exchange Commission (SEC) data or operated on behalf of the SEC are required to have an authorization to operate, based on National Institutes of Standards and Technology (NIST) Special Publication (SP) 800-37, Revision 2, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach. The security assessment entails a review of minimum https://www.govinfo.gov/content/pkg/USCODE-2011-title29/html/USCODE-2011-title29-chap16-subchapV-sec794d.htm https://www.access-board.gov/ https://www.access-board.gov/ https://www.acquisition.gov/content/39203-applicability https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/corrections-to-the-ict-final-rule https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.itic.org/policy/accessibility/vpat security controls, documented in NIST SP 800-53, Revision 5 (and subsequent revisions as finalized by NIST); documentation of a system security plan, based on NIST SP 800- 18 updated, Rev. 1; and remediation of weaknesses that are documented in a plan of action and milestone (POA&M) document, as required by Office of Management and Budget (OMB) Memorandum 02-01. The ATO will also have to cover any alternate processing facilities or a subcontractor handling SEC information or operating systems on behalf of the SEC.

b. Additional Federal governance includes but is not limited to the following:

1. Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d) for system accessibility requirements.

2. Office of Management and Budget (OMB) Circular A-11, Revised, “Preparation, Submission and Execution of the Budget” (December 2020)

3. OMB Circular A-130, Revised, “Managing Information as a Strategic

Resource” (July 2016)

4. OMB Federal Enterprise Architecture Program Management Office (FEAPMO)

Reference Models and Circular A-11 Guidance. www.feapmo.gov.

5. Privacy Act of 1974, Public Law 93-579 (5 U.S.C. 552a), as amended

6. The E-Government Act of 2002, Public Law 107-347

7. OMB Memorandum M-15-01, Fiscal Year 2014-2015 Guidance on Improving Federal Information Security and Privacy Management Practices, October 3, 2014 (and subsequent updates by OMB)

8. OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002, September 30, 2003

9. OMB Memorandum M-10-22, Guidance for Online Use of Web Measurement and Customization Technologies

10. OMB Federal Risk and Authorization Management Program (FedRAMP) Policy Memo, December 8, 2011

11. Federal Information Processing Standard (FIPS) Publication (PUB) 201, Personal Identity Verification (PIV) of Federal Employees and Contractors, September 2013

12. FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006

13. FIPS PUB 197, Advanced Encryption Standard, November 2001

14. FIPS PUB 140-3, Security Requirements for Cryptographic Modules, March 2019

15. National Institute for Standards and Technology (NIST), Special Publication (SP) 800-

122, Guide for Protecting the Confidentiality of Personally Identifiable Information (PII), April 2010

16. NIST SP 800-37, Revision 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, December 2018

17. NIST SP 800-115, Technical Guide to Information Security Testing and Assessment Sept 2008

18. NIST SP 800-100, Information Security Handbook: A Guide for Managers, Oct 2006

19. NIST SP 800-95, Guide to Secure Web Services, Aug 2007

20. NIST SP 800-92, Guide to Computer Security Log Management, Sep 2006

21. NIST SP 800-88, Revision 1, Guidelines for Media Sanitization, December

22. NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide, August

23. NIST SP 800-53 Rev. 5, Security and Privacy Controls for Federal Information Systems and Organizations, September 2020

24. NIST SP 800-53A, Revision 4, Guide for Assessing the Security Controls in Federal Information Systems, December 2014

25. NIST SP 800-44 Version 2, Guidelines on Securing Public Web Servers, Sep

26. NIST SP 800-30, Revision 1, Guide for Conducting Risk Assessments, September 2012

27. NIST SP 800-34, Revision 1, Contingency Planning Guide for Federal Information Systems, May 2010

28. NIST SP 800-18, Revision 1, Guide for Developing Security Plans for Federal Information Systems, February 2006

29. NIST SP 800-70, Revision 4, National Checklist Program for IT Products: Guidelines for Checklist Users and Developers, February 2018

30. NIST SP 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations, September 2011

31. NIST SP 800-137A, Assessing Information Security Continuous Monitoring Programs;

Developing and ISCM Program Assessment, May 2020

c. Encryption Specifications:

1. All encryption modules in the requirement must be FIPS 140-3 certified level 2.

2. All built-in encryption modules are subject to verification by technical support provided by the contractor or as otherwise directed by the COR.

3. Unless the Contractor is using SEC provided devices, all contractor provided mobile devices including, but not limited to laptops, mobile phones, and tablets, must be encrypted with a full-disk (or full-system) encryption capability.

4. All data written to removable media must be encrypted using the SEC’s enterprise removable media encryption capability.

5. All systems and applications must only support Hypertext Transfer Protocol Secure (HTTPS). All Internet-facing systems must also implement HTTP Strict Transport Security (HSTS). Deprecated encryption methods (such as SSLv2 and SSLv3) and encryption ciphers (such as 3DES and RC4) shall not be supported.

d. Cloud-Based Assessment: Any cloud-based components that are not otherwise exempt pursuant to SEC Cloud Service and FedRAMP policy shall be assessed in accordance with FedRAMP requirements and must have already received a provisional authorization from either the Joint Authorization Board or another U.S. Federal Executive Branch Agency. Additional Federal requirements for cloud computing are documented in NIST SPs 800-144, 800-145 and 800-146, and in SEC Instruction 6022.00.

e. Security Issue Review: The Contractor shall remediate problems identified during any security testing activities. All significant issues (typically those rated as HIGH and often those rated as MEDIUM) should be resolved before the system is allowed to go into production and handle SEC information. The Contractor shall resolve security audit-related Plan of Action and Milestones (POA&M) items within a reasonable timeframe, based on risk guidance from the designated authorizing official. The Contractor shall document the resolution and provide supporting evidence of changes. The Contractor shall schedule a conference meeting with the Contracting Officer’s Representative (COR), Office of Information Technology (OIT) Security Group staff, and relevant SEC staff to review the state of the POA&M resolutions. The Contractor shall provide the SEC with the number and description of resolved POA&M items identified in the security review along with supporting evidence. SEC’s OIT Security Group may choose to perform additional technical testing to validate resolution.

f. Dedicated Security Personnel Specifications: All system development, maintenance, and support contracts must include an appropriate number of qualified information security personnel to be provided by the Contractor as defined below. These individuals will ensure secure development methodologies are followed and assist the SEC Security Operations Center (SOC) in proactive monitoring of exploits against SEC information systems.

g. All applicable contracts must have at least one dedicated security resource, but Contractors may augment the skills and abilities of security personnel with additional Contractor Personnel.

h. Security personnel must:

1. Prepare written documents and communicate with both business and technical stakeholders;

2. Have experience in and understand security architecture for web applications and infrastructure, and have experience and working knowledge of Security Assessment and Authorization (SA&A) activities in accordance with standards from NIST;

3. Have expertise and experience in performing continuous monitoring activities for systems to include monitoring for security threats, performing access reviews, reviewing and developing mitigations for vulnerability assessment reports, and proposing enhancements for systems security;

4. Have experience supporting security operations centers (or similar capabilities) in systems reviews and potential incident investigations; and

5. Obtain and maintain knowledge of the security architecture and the business purpose of systems under his/her purview.

i. Security Assessment: OIT Security Team with the support of the Contractor Security Personnel performs Security Assessment and Authorization (SA&A) for a product to be deployed. This process is designed to allow the SEC to identify any risks associated with the system and either mitigate them or formally accept any residual risk. This requirement is based on the NIST SP 800 series of documents and includes:

1. Enumeration - activity aimed at identifying devices and components and cross-referencing with provided inventory lists;

2. Vulnerability Scanning - performs network-based vulnerability assessment of customer’s servers, workstations, and any other network device or appliance in scope. The assessment will identify vulnerabilities associated with network services, operating systems, and devices that are un-patched or have out-of-date software security patches;

3. Penetration Testing - attempts to exploit weaknesses identified from vulnerability scanning to verify legitimate findings, eliminate false-positives, and determine the extent of the vulnerability and potential remediation steps that may be taken; and

4. Functional Testing - Perform specific tests, examinations, and inspections against NIST SP 800-53 controls not tested by the other activities.

j. The Contractor shall provide the Security Team with: (1) a system demonstration; (2) test user IDs; (3) Access to the system; (4) System Security Plan (SSP); (5) additional documents as required under the NIST SP 800 series to support Security Assessment & Authorization activities including third party assessments for certain projects/requirements as described in the section below. The Contractor shall provide ongoing support to update the required SA&A documentation. The OIT Security Team provides the test reports. Any cloud-based components will have to be assessed in accordance with FedRAMP and must have already received a provisional authorization from either the Joint Authorization Board or another U.S. Federal Executive Branch Agency. Additional Federal requirements for cloud computing are documented in NIST SPs 800-144, 800-145 and 800-146, and in SEC Instruction 6022.00.

k. Contractor-provided SA&A for all system development or solutions development projects for contractor-operated systems and solutions:

1. For all Contractor-operated systems or solutions (including Cloud-based systems), the Contractor must obtain from an organization (3PAO) a third party accredited security assessment compliant with standards from NIST (e.g., SP 800-115 Technical Guide to Information Security Testing and Assessment) to verify that security controls are implemented and operating as intended.

2. The assessment is subject to review and approval by the SEC.

l. Documentation Updates: The Contractor shall maintain and update system specifications and/or documentation, including system inventory, to reflect changes made during maintenance or update. The Contractor shall maintain system documentation to reflect the configuration of software releases and commercial off-the shelf (COTS) products. The Contractor shall maintain documents and specifications in compliance with standards for formatting and content and produce standardized documentation, i.e., User Guides, Requirements Documents, On-line Help, Standard Operating Procedures (SOP), system specifications, audit documentation practices and procedures, and other documentation.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .