7. PWS Revision 11.21.2022.pdf

PDF 477 KB Posted

Attached to
Cryptocurrency Management & Disposal Services Federal contract opportunity
Solicitation number
15M50023QA4400002
Issued by
Department of Justice US Marshals Service

View the file

Other files for this federal contract opportunity

Other files attached to Cryptocurrency Management & Disposal Services, newest first.
File Type Posted
15M50023QA4400002-0002 - CO Signed.pdf PDF
15M50023QA4400002 - 0001.pdf PDF
6. Past Performance Data Worksheet.pdf PDF
11. DOJ IT Guidance.pdf PDF
15M50023QA4400002.pdf PDF
5. Offeror Info Page.pdf PDF
8. QASP.pdf PDF
9. Pricing Schedule-Updated.xlsx XLSX spreadsheet
10. Contractor Invoice.xlsx XLSX spreadsheet
1. 1449 Continuation.pdf PDF
4. Evaluation Factors.pdf PDF
2. Additional Clauses.pdf PDF
3. Instructions to Offerors.pdf PDF
12. CONTRACT DISCREPANCY REPORT.pdf PDF
Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Source Selection Information—See FAR 2.101 and 3.104

U.S. Marshals Service

Asset Forfeiture Division

Complex Assets Unit

Performance Work Statement for the

Virtual Currency SDVOSB

November 21, 2022

PWS for Virtual Currency SDVOSB Page 1 of 19

For Official Use Only (FOUO)

Table of Contents

1.0 General

2.0 Specific Requirements/Tasks

3.0 Contractor Quality Assurance

4.0 Delivery or Deliverables

5.0 Constraints

6.0 Performance Requirements Matrix

7.0 Meetings

8.0 Required Travel and Other Direct Costs (ODCs)

9.0 Special Instructions

10.0 Government Furnished Property/Equipment/Information

11.0 Glossary of Abbreviations and Acronyms

Note that while, as a matter of policy, some agencies require the government to prepare the PWS, the guidance at FAR 37.602(a) stipulates that “a Performance work statement (PWS) may be prepared by the Government or result from a Statement of objectives (SOO) prepared by the Government where the offeror proposes the PWS.”

https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2037_6.html#wp1074648

PWS for Virtual Currency SDVOSB Page 2 of 19

Performance Work Statement (PWS) for the

Virtual Currency SDVOSB

1.0 General

1.1 Introduction

The United States Marshals Service (USMS), a principal law enforcement agency within the United States Department of Justice (DOJ), is a key component within the Department's Asset Forfeiture Program (AFP). The primary mission of the DOJ AFP is to employ asset forfeiture authority in a way that enhances public safety and security. This is accomplished by dismantling organized crime and removing financial incentives from criminals through the seizure and forfeiture of assets that are either the proceeds of, or were used to facilitate, federal crimes.

To that end, the USMS, in conjunction with the United States Attorney’s Office (USAO) and Investigative Agencies (IA) scrutinize hundreds of virtual currency assets each year.

The Treasury Executive Office for Asset Forfeiture (TEOAF) administers the Treasury Forfeiture Fund (TFF). The TFF is the receipt account for deposit of non-tax forfeitures made pursuant to laws enforced or administered by it participating Treasury and Department of Homeland Security agencies. The Fund was established in 1992 as the successor to what was then the Customs Forfeiture Fund. The TFF participating agencies are:

• Internal Revenue Service Criminal Investigations Division (IRS-CI), U.S. Department of the Treasury;

• U.S. Immigration and Customs Enforcement (ICE), Department of Homeland

Security;

• U.S. Customs and Border Protection (CBP), Department of Homeland Security;

• U.S. Secret Service (USSS), Department of Homeland Security;

• U.S. Coast Guard, Department of Homeland Security.

As the departmental custodians of all seized and forfeited assets, this contract will support the USMS in providing custody, management, and disposal services of virtual currency assets seized and forfeited under the DOJ AFP and TEOAF components or Government agencies with related law enforcement missions.

Orders for this acquisition will be funded from the USMS Asset Forfeiture Fund to support the Department’s Asset Forfeiture Program. However, TEOAF components may fund a portion of this contract, and may issue separate orders approved in advance by the USMS Contracting Officer’s Representative (COR).

PWS for Virtual Currency SDVOSB Page 3 of 19

1.2 Objective

This contract will assist USMS in managing and disposing of virtual currency assets that are held using individual software and not tradeable on most exchanges in a manner that is professional, lawful, and consistent with Department and USMS policy. This contract will also streamline custody, management, and disposal processes for virtual currency assets while allowing for the diversification of the type of virtual currency assets that can be managed and disposed of under the DOJ AFP. USMS has a duty to ensure all services in the contract provide maximum value while minimizing expenses to USMS. USMS expects the Contractor, as its agent, to take prudent action and good faith on the USMS’s behalf with the same duty of care while augmenting our capacity and efficiency regarding the custody, management, and disposal of virtual currency.

The USMS expects to improve its current custodial operations through this contract in several ways. Primarily among these is to ensure the security and accuracy of all virtual currency transactions. To that end, the Contractor shall ensure that a complete and accurate accounting of USMS and TEOAF virtual currency inventory is always maintained and available from the point the Contractor is given custody through disposal.

1.3 Scope of Work

The purpose of this contract is to provide the full range of virtual currency custody, management, and disposal services. This includes but is not limited to such activities as accounting, customer management, audit compliance, managing blockchain forks, wallet creation and management, private encryption key generation and safekeeping, backup and recovery of private encryption key material, airdrops, etc., as well as future actions associated with the virtual currency forfeiture process.

The USMS supports virtual currency seized in field offices in all 50 states and territories of Puerto Rico, U.S. Virgin Islands, Guam, and the Northern Marian Islands. The contract awarded for this PWS is not exclusive and USMS reserves the right to exclude any field office location or asset type anytime from this contract at its sole discretion.

The DOJ AFP seizes and forfeits five different classes of virtual currency.

• Class 1: virtual currency assets that are supported by USMS’s internal wallet and can be liquidated using Coinbase’s exchange platform.

• Class 2: virtual currency assets supported by USMS’s wallet but CANNOT be liquidated using Coinbase’s exchange platform.

• Class 3: virtual currency assets not supported by USMS’s wallet, and/or requires individual software, but can be liquidated using Coinbase’s exchange platform.

• Class 4: virtual currency assets not supported by USMS’s wallet, or requires individual software, and cannot be liquidated using Coinbase’s exchange platform.

• Class 5: virtual currency assets considered anonymity enhanced/privacy coins or unexchangeable due to litigation.

Table 1: Virtual Currency Portfolio Summary below depicts the current virtual currency portfolio that will be transitioned to the Contractor.

PWS for Virtual Currency SDVOSB Page 4 of 19

DOJ IA Custody USMS Custody TEOAF Custody Total

Asset Count

Value Asset Count

Value Asset Count

Value Asset Count

Value

Class 1 123 $6.6 million 38 $3.7 million 0 $0.00 161 $10.3 million

Class 2 18 $237.9k 1 $210k 0 $0.00 19 $447k

Class 3 31 $157k 0 $0 16 $1.0 million 47 $1.1 million

Class 4 28 $243k 15 $460k 12 $10.9 million 55 $11.3 million

TOTAL 200 $7.2 million 54 $4.3 million 28 $11.9 million 282 $24 million

Table 1: Virtual Currency Portfolio Summary

Crypto currency types encountered and not currently listed will be evaluated as encountered and added to the respective classification based on similar criteria upon agreement from the

USMS COR.

1.3.1 Background

The USMS has been self-managing the virtual currency assets seized and forfeited by the DOJ and TEOAF forfeiture programs since 2014. Since then, the number and complexity of virtual currency assets has increased and the need for a contract to provide management, disposal, and industry knowledge is apparent.

The previous acquisition was awarded twice and both times the winning Contractors were deemed other than small business, losing their various protests. This contract is a temporary solution while USMS re-competes the full contract. The scope of virtual currency work may change over the course of the next 18 months while a new contract is bid out.

1.3.2 Type of Contract Contemplated

This contract is a set aside for SDVOSB Indefinite Delivery Indefinite Quantity contract that includes firm fixed price line items. Accordingly, Task Orders will be issued on a Firm Fixed Price basis.

1.3.3 Period of Performance

The period of performance of this contract shall be date of award and continues for 12 calendar months. There is one 6-month option period that may be exercised by the government unilaterally.

1.3.4 Place of Performance

The primary place of performance will be the Contractor’s facilities with occasional visits to the U.S. Marshals Service (USMS) Headquarters at 1215 South Clark Street, Arlington, VA.

1.3.5 Hours of Operation

The Contractor shall generally perform all work between the hours of 8:00 am and 6:00 pm EST, Monday through Friday (except Federal holidays). However, there may be occasions when the

PWS for Virtual Currency SDVOSB Page 5 of 19

Contractor shall be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this PWS.

2.0 Specific Requirements/Tasks

2.1 Custody

Without delay and where technically feasible, the Contractor shall take custody of and provide compliant secure management and disposal services for any type or quantity of virtual currency deemed necessary by the USMS. See The USMS Cryptocurrency Classifications List May 2022 (Appendix A) attached. The Contractor shall provide all aspects of the secure storage and management of virtual currency in its custody from the time of receipt until disposal. TEOAF will require custody as well and will provide a list of currencies upon contract award.

Virtual currencies not supported by the Contractor (with known private keys or mnemonics) at the time of custody will be allowed a period of five (5) business days for custody. All Digital Assets must be backed up in redundant geographically separate logical locations and in a manner that prevents compromise by internal collusion, third-party collusion, remote or local cyber-attacks, physical loss, fire or acts of nature.

The Contractor shall establish an account with Coinbase Prime/Wallet and acquire necessary software wallets to obtain custody of assets quickly and safely. The Contractor must establish an Asset Management Solution that provides real-time tracking of all assets in the Contractor’s custody regardless of location (Coinbase, Ledgers, Software Wallets, etc.).

2.2 Storage

The Contractor shall maintain complete and accurate accounting of USMS and/or TEOAF inventory at all times, while ensuring that USMS and/or TEOAF inventory is never comingled with any other wallets or addresses of different types or owners.

The Contractor shall take prudent steps to prevent the loss of USMS and/or TEOAF inventory including but not limited to theft, human error, system failures, and acts of nature. The Contractor shall hold virtual currency assets in cold storage. Hardware used to store private keys associated with USMS accounts shall not be connected to any local or external networks at any time.

The Contractor will store mostly Class 1-2 cryptocurrencies on the ERC-20 network and Class 3-4 cryptocurrency. Other Class 1-2 currencies will be transferred on a case-by-case basis as needed.

Generally, currencies which the USMS can dispose of through Coinbase will not be transferred to the Contractor unless there are other factors.

2.3 Management

It is impossible to determine which of the assets under investigation will be taken into USMS or TEOAF custody and ultimately referred to the Contractor. However, to realize the increased capacity and efficiencies expected from this contract, the Contractor shall remain capable of taking custody of all types and quantities of virtual currency without limitation, throughout the performance of this contract. This includes both coin and token types of currency. The Contractor will create a case file system to encompass all stages of the asset lifecycle (custody, management, storage, and disposal) which will be shared with the USMS as requested for review. This system must meet the minimum technical specifications for compliance to DOJ/USMS policy for data, PWS for Virtual Currency SDVOSB Page 6 of 19 access, and records management. The technical design of the system must be sufficient to support the four stages of the asset lifecycle. The vendor shall follow the USMS technical lifecycle processes and reporting where possible.

In addition to the managed assets, any technical devices, systems, services, and digital information provided by the Contractor that is used for direct management of USMS information, separate from the managed Cryptocurrency commercial systems, services and assets must meet DOJ and USMS lifecycle compliance requirements.

The Contractor must note if there are any known issues with DOJ or flags with OCIO for technical services and per Appendix B: Security of Information and Information systems DOJ Procurement Guidance Document (PGD) 15-03.

Management of Inventory

The Contractor must establish monitoring processes that notify the Contractor Officer and the COR of any suspicious activities, movement, and/or airdrops. The contractor must notify the Contracting Officer and COR of any breech or unauthorized disclosure of information or assets.

The Contractor is to notify the COR of any reportable activity withing 24 hours of the occurrence.

Management of Forked Currency

On some older assets forks need to be claimed. Within 30 days of the contract award the Contractor will claim the following forks:

Bitcoin Cash (BCH)Bitcoin Gold (BTG)

Bitcoin Satoshi Vision (BSV)

The Contractor will pull the private key from the wallet, account for the forked tokens and airdrops and provide the USG with an updated accounting of these assets to include the new public address. When instructed, the Contractor will dispose of the forked currency.

As a result of forks, the USMS has custody of about a dozen cases with Bitcoin Satoshi Vision (BSV). This forked currency will be transferred to the Contractor for disposal in one wallet.

Additional BSV may require disposal and is noted so below.

Management of Assets on the ECR-20 Network

The Contactor will provide gas/Ether for the transfer of assets that are ERC-20 tokens regardless of their custody location (USMS or Investigating Agency or ultimate destination (USMS or Contractor).

Management of Ethereum Wallets

There are currently two Ethereum wallets that experienced issues during a software update. It is unclear if the private key is incorrect, or the wallet malfunctioned. The Contractor will identify the issue(s) and potentially open the wallet. If the wallet cannot be opened, documentation of efforts taken to unlock or open the wallet will be provided to the USG.

PWS for Virtual Currency SDVOSB Page 7 of 19

Management of Cryptocurrency-Related Hardware

There may be instances where maintenance of cryptocurrency-related hardware (ironkeys, nano ledgers, etc.) may be needed. This may include taking custody of the hardware, recovering files, etc. Dependent on the situation, the Contractor will identify any issues and assist the USG as needed to manage with reportable tracking of the cryptocurrency-hardware.

2.4 Disposal

The Contractor shall dispose of forfeited virtual currency assets in the manner and timeframes specified by the USMS. These methods include but are not limited to:

• Direct exchange from virtual currency into USD where markets exist.

• Exchange into a more liquid form of virtual currency and then exchanged into USD where markets exist.

• Return to Investigating Agency, owner, or other third party.

Disposal of virtual currency will take place subsequent to a court order or other authorizing document. The Contractor shall dispose of the specified asset upon request by the USMS. The Contractor shall make recommendations with regard to the most prudent method of disposal for the amount and/or particular type of virtual currency that is forfeited, however the ultimate decision with regard to disposal method rests solely with the USMS.

2.4.1 Use of Coinbase for Exchanges

The Contractor will use Coinbase (Coinbase Pro and/or Coinbase Prime) where feasible to perform direct exchanges, exchange into a more liquid form of virtual currency.

USMS shall work with the Contractor to determine other safe and economical ways of liquidating virtual currency where Coinbase is not supported.

2.4.2 Standard Disposal via Exchange

Once a virtual currency asset has been approved for disposal, the USMS will notify the Contractor’s PM and specify which asset under custody can be disposed of and provide the written authority to dispose of the asset to the PM. The USMS, at the time of notification, will either request a recommendation by the Contractor or direct the Contractor which method to dispose of the asset. If the directed method chosen by the USMS is determined to not be feasible, the Contractor must provide a written explanation of the mitigating factor and provide an alternative method and explanation of the choice, and any change in pricing.

Standard disposals of all types of virtual currency shall be completed within five (5) business days of notification.

The five-day disposal deadline will be considered complete when all proceeds are in the Treasury Account. This may require approval from the COR to extend the disposal timeframe depending on exchange-based disposal restrictions.

2.4.3 Standard Return to Third Party and/or USMS

PWS for Virtual Currency SDVOSB Page 8 of 19

In instances where the USMS and/or TEOAF must return virtual currency to a third party and/or USMS, the Contractor shall process these requests in a timely and efficient manner. Although the return of virtual currency is considered a type of disposal with regard to the asset itself, the process of doing so is a function of the management requirement NOT the disposal requirement. Therefore, in the event an asset is disposed of in this manner the Contractor shall NOT be entitled to a commission, rather it shall be entitled to its regular monthly management fee only.

The return of assets to a third party shall be completed within ten (10) business days of notification. A return is at the sole discretion of the USMS COR.

2.4.4 Large Return to Third Party

In instances where the USMS and/or TEOAF must return virtual currency to large parties (100 or more), the return of assets shall be completed within twenty (20) business days of notification and receiving all necessary information.

Cases with victims may require returns of currency via a Petition for Remission. These returns may require taking possession of the server on which the currency was seized to process the returns.

The Contractor will:

− Take custody of the various types of cryptocurrency either by transfer or custody of the entire server or exchange account.

− Process returns according to the Petition for Remission.

− Provide the USMS with reporting documents to include blockchain confirmation of the transfer, claimant name, CATS ID, transfer amount, and any other correspondence with the claimants.

− Utilize a platform such as Coinbase Prime that allows for the individual transfers to be set up in advance so that all returns are processed in unison. This is required to eliminate the priority return of currency to any one or several victims.

2.5 Reporting

2.5.1 General Reporting

The Contractor shall provide system access to meet the needs of the USMS. At a minimum access shall include ad hoc reporting capabilities, and the real-time ability check and monitor the assets being held in storage where technically feasible. System shall provide four nines (99.99%) continuous availability throughout the duration of the contract where technically feasible.

In addition, Contractor shall provide the USMS with ad hoc reports.

The contractor shall support export of report data from maintained systems in standard USMS formats.

All written reports provided in electronic format shall have read/write capability using applications that are compatible with USMS workstations as specified by the USMS during the post award conference.

PWS for Virtual Currency SDVOSB Page 9 of 19

2.5.2 Progress Reporting

The Contractor shall provide a monthly progress report to the COR via electronic mail on the first business day following the last day of each month. This report shall include a summary of all work performed, including a reconciliation of the book inventory with the physical inventory, all direct costs by line item, any travel conducted, an assessment of overall progress, projected activity for the following month, and any identified risks, issues, or concerns and plans for their mitigation.

3.0 Contractor Quality Assurance

The Contractor shall submit a proposed QASP for consideration. The draft QASP should include proposed performance standards and “Acceptable Quality Level (AQL), as well as suggested price adjustment or other action.

Please note, the QASP is the internal USMS plan for implementing measurable performance standards for the purposes of monitoring and evaluating the performance of the Contractor.

Therefore, although the USMS will consider alternatives proposed by the Contractor, the final decision on the contents of the QASP rests solely with the USMS.

4.0 Delivery or Deliverables

Timely submission of deliverables and reports is essential to successfully completing this requirement. Schedules for deliverables are specified in Table 2: Deliverables below.

Item Deliverable/Event DUE DIST

1 Post Award Conference Within thirty (30) business days after date of award

Contracting Officer

2 Final Contractor Project Plan Within thirty (30) days of Post Award Conference

Contracting Officer, COR

3 Final Quality Assurance Surveillance Plan

Within thirty (30) days of Post Award Conference

Contracting Officer, COR

4 Business Continuity Plan Within thirty (30) days of Post Award Conference

Contracting Officer, COR

5 Updated Business Continuity Plan Annually Contracting Officer, COR

6 Progress Reports Monthly Contracting Officer, COR

7 Progress Meetings Monthly Contracting Officer, COR

8 Cybersecurity Lifecycle or Breech Notification

Within 24 hours of reportable activity

Contracting officer, COR

Table 2: Deliverables

PWS for Virtual Currency SDVOSB Page 10 of 19

Notice to Contractors:

All information and data related to this project that the Contractor gathers or obtains shall be both protected from unauthorized release and considered the property of the government. The contracting officer will be the sole authorized official to release verbally or in writing, any data, the draft deliverables, the final deliverables, or any other written or printed materials pertaining to this contract.

Press releases, marketing material, or any other printed or electronic documentation related to this project, must not be publicized without the written approval of the USM CO and/or USMS COR.

Contractor will be fined $100,000 if violated, and on the third violation the contract will be terminated.

Unauthorized disclosure of USMS records and technical system breeches must be reported in accordance with appendix B: PGD 15-03 and the USMS security incident reporting procedures and timeframes. The Contractor is responsible for maintaining appropriate access and systems technical controls to ensure protection and compliance.

5.0 Constraints

5.1 Liability

The Contractor shall be liable for any act, omission, negligence, or lack of performance on their part which results in the damage, devaluation, destruction, or loss of any and all physical or virtual property, parts, items or derived portion that the Contractor handles during the performance of this contract. Insurance will be 50% of the commensurate value of the inventory and will be adjusted and reviewed quarterly. The USMS will cover the remaining 50% as the United States Government is self-insured. Bonding is required at the same percentage all times and shall make the USMS whole in the event of any losses. In the event insurance cannot be obtained, the USMS will require an escrow of funds for the duration of the contract.

The Contractor shall be responsible for technical systems under their direct control where unauthorized access and information disclosures occur. The Contractor shall be responsible for taking corrective action consistent with DOJ Data Breach Notification Procedures and as directed by the DOJ and USMS CO, including all costs and expenses associated with such corrective action in accordance with Appendix B DOJ PGD 15-03 DOJ Security Requirements for Procured Technical Solutions and Services, Section VI. Information System Security Breach or Incident (Appendix B). Examples of technical systems under the Contractor’s direct control may include laptop/desktop devices used for managing USMS program information, program reporting services, asset tracking and management services.

5.2 Compliance

5.2.1 External Audits

To the extent deemed necessary by the USMS to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, accuracy, and confidentiality of any non-public USMS data collected and stored by the Contractor, the Contractor shall afford the USMS access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases at any time during the performance of the contract.

PWS for Virtual Currency SDVOSB Page 11 of 19

Additionally, the Contractor shall remain available to respond and assist the USMS with responding to inquiries by our auditors, both internally and externally. The USMS and/or the Office of the Inspector General (OIG) may periodically contract for the services of an Independent Public Accountant (IPA) to perform a review of the program. The Contractor shall allow and provide as follows:

a. Contractor shall make facility and USMS records accessible to the USMS and or

OIG/IPA upon request.

b. Contractor shall provide ample workspace for USMS and or OIG/IPA during visits.

c. Contractor shall provide onsite representative to assist USMS and or OIG/IPA during visits.

5.2.2 Internal Audits

The CFO Act of 1990 requires an annual audit of the Asset Forfeiture Fund (AFF) annual financial statements. As part of this audit, the Contractor is mandated to conduct a one hundred percent (100%) annual inventory reconciliation for all assets in the custody of the Contractor, including assets which may have become forfeited and/or unblocked based on a Disposition Order but which are still in the custody of the Contractor. The Contractor shall provide their internal audit report to the USMS within five (5) business days of completion. Deficiencies identified by any audit findings shall be cured by the Contractor within twenty (20) business days of such identification or as approved by the

CO.

5.2.3 Information Technology Compliance Audits

The Federal Information Security Management Act (FISMA 2002) and the Federal Information Security Modernization Act (FISMA 2014), defines a framework for security standards and requires all technical services maintain compliance with those standards.

The Department of Justice selects programs, services, and systems annually for FISMA audit review. In addition to FISMA audits, an annual review of compliance controls is conducted by USMS to ensure approval for continuance of a program, service, or systems Authority to Operate. The Contractor shall provide support for any compliance activity review of security standards controls and mitigation as required.

5.3 Information Systems and Services

The Contractor shall provide on-site or remote assistance as required in support of this PWS. All key personnel with systems or services access must be based in the United States, be US Citizens, and must obtain a US government clearance. Per DOJ Security Requirements and in accordance FISMA (Appendix B: DOJ PGD 15-03 DOJ Security Requirements for Procured Technical Solutions and services), the organization and system must follow, develop and maintain technical services to standards to meet the Authority to Operate (ATO) security authorization, DOJ Strong Authentication Policy, and ensure future policies and updates are met throughout the lifecycle for systems and services housing USMS data. The Contractor will ensure

PWS for Virtual Currency SDVOSB Page 12 of 19 all performance and new proposed solutions are compliant with applicable legal, regulatory, Department of Justice (DOJ) and USMS policy requirements to maintain an Authority to Operate (ATO) on all Government-owned information technology systems and services. The Contractor will also ensure performance and new solutions are consistent with Industry and Technology guidance best practices. Any Contractor provided cloud services used for USMS information management delivery shall ensure adherence to the Cloud Service Provider Requirements (Appendix C); and meet DOJ policy outlined in PGD_15_03_Requirements (Appendix B); and meet federal regulatory compliance outlined in USMS Standards and Compliance Requirements (Appendix D).

Reporting related to audit elements shall be provided upon request. Security Certification and Accreditation control validation activities are separately scoped, through a USMS separately maintained for Government-owned services contract. The Contractor shall assist the Government authorized representative, which may be a federal or contractor member of the Cyber Security Branch (CSB), Information System Security Officer (ISSO), with implementation of security controls, Assessment and Authorization (A&A), Authority to test (ATT), Authority to Operate (ATO), vulnerability management, risk mitigation, and maintenance of current Government-owned services. The contractor shall maintain accurate security documentation in DOJ Cyber Security Assessment and Management (CSAM) systems. The Contractor shall develop Plan of Action and Milestones (POA&M) for identified security deficiencies and manage and resolve POA&MS according to Government approved schedule(s). Cyber risk is measured through operational cyber protections and must be embedded in delivery services for architecture, design and delivery of systems, solutions, and services. The Contractor shall provide architectural design documents, diagrams, configuration baselines, reports, patches, system updates, vulnerability mitigation, infrastructure protections, logging, monitoring, alerts, and response in support of specific security related questions, processes, or requested actions as needed and specified by the USMS COR. The Contractor must ensure compliance inclusive of audit support requested by the Cyber Security Branch Audit management team. The standards outlined in Standards and Compliance Requirements (Appendix D), apply to systems, products, and services delivered directly in support of USMS information management performance deliverables by the Contractor, services maintained directly by the Contractor and service designs proposed by the Contractor and may change over the lifecycle of this contract in accordance with DOJ and USMS policy updates. The Contractor is responsible for compliant access of maintained USMS used controls to public cryptocurrency clouds, systems, and services, but not compliance of the commercially owned services themselves.

5.4 Data

The USMS owns the rights to all data/records produced as part of this contract and shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. The Contractor shall not create or maintain any records containing any USMS information that are not specifically tied to or authorized by the contract. Further, disposition and destruction of records is EXPRESSLY PROHIBITED unless authorized by the USMS.

The Contractor shall prevent the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage, or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701.

All information related to this contract created or produced in part or in whole, regardless of type of media, is to be maintained for the duration of the contract, made available upon

PWS for Virtual Currency SDVOSB Page 13 of 19 request, and upon termination of the contract shall be turned over to the USMS. This includes but is not limited to all electronic files, hard copy files, data contained in electronic information systems, databases, etc., and all supporting documentation. The Contractor must deliver sufficient technical documentation with all data deliverables to permit use of the data by the USMS. The contractor shall ensure technical documentation addresses measures taken toward system and services compliance with DOJ/USMS policy.

Any Contractor produced and used algorithms or artificial intelligence code outside commercial off the shelf (COTS) services produced for use in this contract must meet the DOJ and federal

All data at rest shall reside within the contiguous United States, the District of Columbia, and Alaska (CONUS) with a minimum of two geographically separated different and distant geographic locations. Data shall be maintained to ensure high availability. Data at rest and in transit shall be encrypted and protected to Federal Information Security Management Act (FISMA) and USMS standards.

5.5 Continuity of Service

The Contractor shall prepare and submit a Business Continuity Plan (BCP) to the USMS. The BCP shall be due at the post award conference and will be updated on an annual basis. The BCP shall document Contractor plans and procedures to maintain support during an emergency, including natural disasters and acts of terrorism. The BCP, at a minimum, shall include the following:

• A description of the Contractor’s emergency management procedures and policy

• A description of how the Contractor will account for their employees during an emergency

• How the Contractor will communicate with the USMS during emergencies

• A list of primary and alternate Contractor points of contact, each with primary and alternate:

o Telephone Numbers o E-mail addresses

Individual BCPs shall be activated immediately after determining that an emergency has occurred, shall be operational within 24 hours of activation or as directed by the USMS, and shall be sustainable until the emergency situation is resolved and normal conditions are restored or the contract is terminated, whichever comes first. In case of a life-threatening emergency, the COR shall immediately make contact with the Contractor’s Project Manager to ascertain the status of any Contractor personnel who were located in USMS controlled space affected by the emergency. When any disruption of normal, daily operations occurs, the Contractor’s Project Manager and the COR shall promptly open an effective means of communication and verify:

• Key points of contact (USMS and Contractor)

• Temporary work locations (alternate office spaces, telework, virtual offices, etc.)

• Means of communication available under the circumstances (e.g., email, webmail, telephone, FAX, courier, etc.)

PWS for Virtual Currency SDVOSB Page 14 of 19

• Essential Contractor work products expected to be continued, by priority

• Availability of the recovery point objectives (RPO) in the specified recovery time objectives (RTO) for systems, services, and data.

• Cybersecurity status and posture of services.

The USMS and Contractor’s Project Manager shall make use of the resources and tools available to continue contracted functions to the maximum extent possible under emergency circumstances. Contractors shall obtain approval from the Contracting Officer prior to incurring costs over and above those allowed for under the terms of this contract. Regardless of contract type, and of work location, Contractors performing work in support of authorized tasks within the scope of their contract shall charge those hours accurately in accordance with the terms of this contract.

5.6 Key Personnel Contractor Support

Contractor access to systems, services, and privileged information is required under this PWS.

Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with pertinent laws and regulations governing the confidentiality of privileged information and Safeguarding Sensitive But Unclassified (SBU) (For Official Use Only) Information. All key personnel with access to privileged information must be based in the United States, be US Citizens, and must obtain a US government clearance. The Contractor shall sign a non-Disclosure agreement, Corporate Non-Disclosure Agreement (Appendix E). Contract personnel who provide direct support with systems or services access shall sign a non-disclosure agreement, DOJ USMS Non-Disclosure Agreement (Appendix F). Contract personnel that need USMS data and privileged systems access shall be required to complete training annually and to sign a Rules of Behavior, DOJ Rules of Behavior 2021 General Users (Appendix G), and may be required to undergo additional screening. The COR will furnish personnel security application forms to the Contractor as described in Personnel and Property Contractor Compliance Requirements (Appendix H). The initial personnel security form must be submitted for all key personnel as needed. The COR shall notify the Contractor, via email, upon clearance acceptance of contractor personnel, a "Notice to Proceed" to start performance. For purposes of this clause, the Contract award date and effective date are synonymous. The individual Contractor personnel start date(s) shall only begin after approval from the Government, and may start prior to clearance acceptance if authorized by the COR. All Contractors performing work on this contract must sign a DOJ Rules of Behavior General User (Appendix G). If a contractor has elevated access rights, they must also sign a DOJ Rules of Behavior (Privileged User) that will be provided if required.

Contractor access to classified information is not currently required under this PWS. However, the USMS may require all Contractor personnel to have higher clearances at a later date.

Accordingly, at a minimum all Contractor employees provided for this requirement must be eligible for a Secret Clearance.

5.7 Conflicts of Interest

To avoid a conflict of interest, or the appearance of a conflict of interest, the Contractor, Subcontractor (s), associated employees and their immediate family/household members, any

PWS for Virtual Currency SDVOSB Page 15 of 19 entity in which the Contractor has any financial interest; or any agent or representative for such party, are prohibited from bidding on or buying any forfeited property, either directly or indirectly.

If the mere appearance of conflict of interest might arise, the Contractor shall notify the USMS COR immediately.

6.0 Performance Requirements Matrix

The PRM establishes key elements of Contractor performance that represent “mission essential” service requirements, which are identified in the table below in the “Required Service” column, which point to different sections in the PWS. The “Performance Standards” column represents the standard against which Contractor performance will be measured in relation to accomplishment of the corresponding service output. The performance objective or “standard” describes the acceptable level of service by the Contractor for satisfactory performance. The performance standards are the only acceptable levels of service and if these are not met, the Contracting Officer will evoke the negative incentive specified in the Table 3: Performance Requirements Matrix below.

Required Service Performance Standards Incentive

(Negative)

Custody Takes custody within five (5) business days.

Invoice deduction of $500 for each instance.

Storage Accurate and segregated inventory.

Invoice deduction of $500 for each instance.

Project Manager (or designee)

Available within two hours of request between 8 AM EST – 6 PM EST, Monday through Friday. Federal holidays and weekends excluded, using agreed upon contact methods.

Invoice deduction of $500 for each late instance or unavailability.

Standard Disposal Completed within 5 business days

Invoice deduction of $500 for each disposal completed late

Return to Third Party Completed within 5 business days

Invoice deduction of $500 for each disposal completed late

General Compliance within 24 hours of loss or breach, two weeks for remediation plan

Per PGD-1503, Contractor is responsible for damages and costs related to loss. Invoice deduction of $500 for each day remediation plan is late.

General Reporting System Downtime (not including blockchain networks)

Invoice deduction of $500 for each instance

PWS for Virtual Currency SDVOSB Page 16 of 19

Required Service Performance Standards Incentive

(Negative)

Monthly Progress Reports

Reports are complete and submitted within the prescribed timeframes.

Invoice deduction of $500 for each report delivered late

Monthly Progress Meetings

Contractor is fully prepared for meetings and they are conducted within prescribed time period

Invoice deduction of $500 for each late/missed meeting.

External Audits Audits are fully supported ensuring access to data and efficiency of audit process.

Invoice deduction of $500 for each audit conducted late

Internal Audits Audit is conducted fully and within the prescribed timeframes.

Invoice deduction of $500 for each incomplete or late audit.

Continuity of Service Updated BCP is complete and submitted within the prescribed timeframes.

Invoice deduction of $500 for each incomplete or late BCP.

Cybersecurity Lifecycle or Breech Notification

Written and verbal notification within 24 hours of reportable activity

Invoice deduction of $500 for each late notification on all services and required remediation costs per DOJ policy for Contractor systems and services housing USMS information.

Table 3: Performance Requirements Matrix

7.0 Meetings

For all meetings, the Contractor shall be responsible for providing meeting materials, and administrative and facilitation support. Meetings will be conducted at either the USMS Headquarters location at 1215 S. Clark Street, Arlington, VA 22202, or through an alternative method of communication (such as Microsoft Teams), as approved by the USMS CO and/or USMS COR.

7.1 Post-award Kickoff Meeting

Within 14 business days of contract award, the USMS CO and USMS COR will conduct a post-award kickoff meeting at USMS Headquarters at 1215 S. Clark Street, Arlington, VA 22202 (specific date and time to be mutually agreed-upon). The purpose of the meeting is to discuss technical and contracting objectives of this contract and finalize the Contractor’s draft project plan.

7.2 Intermittent Project Status Reviews

At the sole discretion of the USMS COR, intermittent project status reviews may be conducted on an informal basis (by telephone or Microsoft Teams) or in person at USMS Headquarter on an as needed basis as approved by the USMS COR.

7.3 Monthly Project Status Reviews

PWS for Virtual Currency SDVOSB Page 17 of 19

Monthly status meetings to be conducted on the first Wednesday of each month. The Contractor is responsible for reporting the previous month’s activities (including any risks, issues, or concerns, and actual or recommended actions for their mitigation), and projected activities for the following month. At minimum, the Contractor shall review the status and results of Contractor performance with the USMS COR. The monthly meeting may be held via telephone or Microsoft Teams.

7.4 Program Management Review

The USMS COR will conduct quarterly program management reviews at the Contract’s location to review the progress of the program, identify any risks, issues, or concerns, and provide feedback on the Contractor’s progress and performance. The Contractor shall provide written data and verbal presentations as to the financial status, any identified any risks, issues, or concerns (and their mitigation or its plans for their mitigation).

7.5 Technical Services Review

Technical services review meetings as needed for change management activities related to directly provided Contractor systems and services which house USMS information.

Limited review of access and records elements associated with the Commercial Cryptocurrency Services which are part of the managed services delivery and not considered directly attributed USMS owned or operated systems and services. Status reports, meetings, and artifacts related to use of Contractor systems housing USMS management information during the system or service lifecycle for enablement, audit support, changes inclusive of patching and updates, and vulnerability response may be required if requested.

8.0 Required Travel and Other Direct Costs (ODCs)

Contractor travel may be required to support this requirement. The principal place of performance is Arlington, VA. Accordingly, reimbursable travel and per diem for the Contractor’s employees performing work on a regular basis in this area of performance is not authorized. Any changes to this must be approved in advance by the USMS COR.

All travel required by the USMS outside of the local commuting area will be reimbursed to the Contractor in accordance with the Federal Travel Regulation. Where reimbursement is required, the USMS COR must approve Contractor travel in advance.

9.0 Special Instructions

9.1 General

Processes which are fundamental to providing the data critical to achieving USMS goals will change throughout the period of this contract due to advancements in technology, the USMS adoption of new technology, evolving state and federal regulations, and to ensure alignment with organizational and Federal policy. The Contractor shall work in good faith to accommodate such changes as necessary to ensure USMS requirements are met, and to the extent any such changes are necessary to the contract.

https://www.gsa.gov/portal/content/104790

PWS for Virtual Currency SDVOSB Page 18 of 19

The Contractor shall maintain a close and cooperative working relationship with the USMS and make appropriate recommendations. The Contractor shall perform his/her functions in accordance with all applicable Federal, State, and local laws and regulations applicable to the services being provided as well as any policies as specified by the USMS. The Contractor shall obtain and keep current throughout the duration of the contract all licenses, insurance policies, permits, and related documents common within the industry and necessary as established by any regulations to operate this type of business.

The Contractor shall immediately report all emergencies to the COR. Examples include but are not limited to: natural disasters affecting the storage facility, loss of currency, any transfer discrepancy, any compromise in cold storage or security. The Contractor will notify the USMS and/or TEOAF of any data breach or loss of cryptocurrency within 24 hours, and within two weeks, the Contractor must provide a recommended remediation for recovery to ensure future risk mitigation of a similar event.

10.0 Government Furnished Property/Equipment/Information

The Contractor shall provide all materials, supplies, technology, labor, and equipment necessary to meet the requirements of this contract. Government furnished devices shall be maintained in accordance with USMS policy and access to technical services shall follow requirements outlined in Section 5 of this PWS. All technology equipment and access control devices and software provided must be returned at the end of the contract to the COR.

11.0 Glossary of Abbreviations and Acronyms

Acronym/Abbreviation Definition

BCP Business Continuity Plan

CDR Contract Discrepancy Report

CLIN Contract Line Item Number

CO Contracting Officer

CONUS Contiguous United States

COR Contracting Officer’s Representative

FISMA Federal Information Security Management Act

IPA Independent Public Accountant

OIG Office of the Inspector General

POP Period of Performance

PRS Performance Requirements Summary

PWS Performance Work Summary

USMS United States Marshals Service

QASP Quality Assurance Surveillance Plan

PWS for Virtual Currency SDVOSB Page 19 of 19

Table 4: Glossary of Abbreviations and Acronyms

For the purposes of this contract, the forfeiture process consists of the following two primary phases:

Pre-seizure: This phase seeks to identify and address critical title, financial, property management and disposal issues prior to making the decision to proceed with a forfeiture action.

Asset Management: This phase covers the asset life cycle from the point of seizure, to the ultimate disposal of the property and can be further broken down into the following processes:

• Seizure: During this stage the U.S. Marshals Service takes custody of the asset based on a federal court order and serves as the responsible steward of the asset until such time as a forfeiture order has been entered against the asset.

• Forfeiture: The asset has been forfeited to the United States based upon the issuance of a federal court order directing the USMS to sell or otherwise dispose of the asset. The USMS will continue to maintain the asset until such time as its final disposal has been completed.

• Disposal: Pursuant to a federal forfeiture order, the USMS will dispose of the property accordingly.

UNCLASSIFIED // LES

USMS Cryptocurrency Classification List Rev. 10/22

United States Marshals Service Asset Forfeiture Division USMS Cryptocurrency Classification List

The United States Marshals Service (USMS) accepts most virtual currency assets sought for forfeiture by the U.S.

Government, although there are some exceptions. To easily identify what is accepted by USMS, the Asset Forfeiture Division (AFD) has assigned all virtual currency types to one of five classifications.

Note: This list is periodically updated to reflect market changes and should be referenced with each new case.

If you have identified a virtual currency not on this list, please contact USMS to determine which classification type the asset would fall in.

Class 1 Assets are supported by USMS’s wallet and can be liquidated using Coinbase’s exchange platform. These assets are accepted when seized and/or upon forfeiture.

0x (ZRX) Aave (AAVE) Algorand (ALGO) ApeCoin (APE) Augur (REP) Avalanche (AVAX) Band Protocol…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .