7. PWS Revision 11.21.2022.pdf
PDF 477 KB Posted
- Attached to
- Cryptocurrency Management & Disposal Services Federal contract opportunity
- Solicitation number
- 15M50023QA4400002
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 15M50023QA4400002-0002 - CO Signed.pdf | ||
| 15M50023QA4400002 - 0001.pdf | ||
| 6. Past Performance Data Worksheet.pdf | ||
| 11. DOJ IT Guidance.pdf | ||
| 15M50023QA4400002.pdf | ||
| 5. Offeror Info Page.pdf | ||
| 8. QASP.pdf | ||
| 9. Pricing Schedule-Updated.xlsx | XLSX spreadsheet | |
| 10. Contractor Invoice.xlsx | XLSX spreadsheet | |
| 1. 1449 Continuation.pdf | ||
| 4. Evaluation Factors.pdf | ||
| 2. Additional Clauses.pdf | ||
| 3. Instructions to Offerors.pdf | ||
| 12. CONTRACT DISCREPANCY REPORT.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Source Selection Information—See FAR 2.101 and 3.104
U.S. Marshals Service
Asset Forfeiture Division
Complex Assets Unit
Performance Work Statement for the
Virtual Currency SDVOSB
November 21, 2022
PWS for Virtual Currency SDVOSB Page 1 of 19
For Official Use Only (FOUO)
Table of Contents
1.0 General
2.0 Specific Requirements/Tasks
3.0 Contractor Quality Assurance
4.0 Delivery or Deliverables
5.0 Constraints
6.0 Performance Requirements Matrix
7.0 Meetings
8.0 Required Travel and Other Direct Costs (ODCs)
9.0 Special Instructions
10.0 Government Furnished Property/Equipment/Information
11.0 Glossary of Abbreviations and Acronyms
Note that while, as a matter of policy, some agencies require the government to prepare the PWS, the guidance at FAR 37.602(a) stipulates that “a Performance work statement (PWS) may be prepared by the Government or result from a Statement of objectives (SOO) prepared by the Government where the offeror proposes the PWS.”
https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2037_6.html#wp1074648
PWS for Virtual Currency SDVOSB Page 2 of 19
Performance Work Statement (PWS) for the
Virtual Currency SDVOSB
1.0 General
1.1 Introduction
The United States Marshals Service (USMS), a principal law enforcement agency within the United States Department of Justice (DOJ), is a key component within the Department's Asset Forfeiture Program (AFP). The primary mission of the DOJ AFP is to employ asset forfeiture authority in a way that enhances public safety and security. This is accomplished by dismantling organized crime and removing financial incentives from criminals through the seizure and forfeiture of assets that are either the proceeds of, or were used to facilitate, federal crimes.
To that end, the USMS, in conjunction with the United States Attorney’s Office (USAO) and Investigative Agencies (IA) scrutinize hundreds of virtual currency assets each year.
The Treasury Executive Office for Asset Forfeiture (TEOAF) administers the Treasury Forfeiture Fund (TFF). The TFF is the receipt account for deposit of non-tax forfeitures made pursuant to laws enforced or administered by it participating Treasury and Department of Homeland Security agencies. The Fund was established in 1992 as the successor to what was then the Customs Forfeiture Fund. The TFF participating agencies are:
• Internal Revenue Service Criminal Investigations Division (IRS-CI), U.S. Department of the Treasury;
• U.S. Immigration and Customs Enforcement (ICE), Department of Homeland
Security;
• U.S. Customs and Border Protection (CBP), Department of Homeland Security;
• U.S. Secret Service (USSS), Department of Homeland Security;
• U.S. Coast Guard, Department of Homeland Security.
As the departmental custodians of all seized and forfeited assets, this contract will support the USMS in providing custody, management, and disposal services of virtual currency assets seized and forfeited under the DOJ AFP and TEOAF components or Government agencies with related law enforcement missions.
Orders for this acquisition will be funded from the USMS Asset Forfeiture Fund to support the Department’s Asset Forfeiture Program. However, TEOAF components may fund a portion of this contract, and may issue separate orders approved in advance by the USMS Contracting Officer’s Representative (COR).
PWS for Virtual Currency SDVOSB Page 3 of 19
1.2 Objective
This contract will assist USMS in managing and disposing of virtual currency assets that are held using individual software and not tradeable on most exchanges in a manner that is professional, lawful, and consistent with Department and USMS policy. This contract will also streamline custody, management, and disposal processes for virtual currency assets while allowing for the diversification of the type of virtual currency assets that can be managed and disposed of under the DOJ AFP. USMS has a duty to ensure all services in the contract provide maximum value while minimizing expenses to USMS. USMS expects the Contractor, as its agent, to take prudent action and good faith on the USMS’s behalf with the same duty of care while augmenting our capacity and efficiency regarding the custody, management, and disposal of virtual currency.
The USMS expects to improve its current custodial operations through this contract in several ways. Primarily among these is to ensure the security and accuracy of all virtual currency transactions. To that end, the Contractor shall ensure that a complete and accurate accounting of USMS and TEOAF virtual currency inventory is always maintained and available from the point the Contractor is given custody through disposal.
1.3 Scope of Work
The purpose of this contract is to provide the full range of virtual currency custody, management, and disposal services. This includes but is not limited to such activities as accounting, customer management, audit compliance, managing blockchain forks, wallet creation and management, private encryption key generation and safekeeping, backup and recovery of private encryption key material, airdrops, etc., as well as future actions associated with the virtual currency forfeiture process.
The USMS supports virtual currency seized in field offices in all 50 states and territories of Puerto Rico, U.S. Virgin Islands, Guam, and the Northern Marian Islands. The contract awarded for this PWS is not exclusive and USMS reserves the right to exclude any field office location or asset type anytime from this contract at its sole discretion.
The DOJ AFP seizes and forfeits five different classes of virtual currency.
• Class 1: virtual currency assets that are supported by USMS’s internal wallet and can be liquidated using Coinbase’s exchange platform.
• Class 2: virtual currency assets supported by USMS’s wallet but CANNOT be liquidated using Coinbase’s exchange platform.
• Class 3: virtual currency assets not supported by USMS’s wallet, and/or requires individual software, but can be liquidated using Coinbase’s exchange platform.
• Class 4: virtual currency assets not supported by USMS’s wallet, or requires individual software, and cannot be liquidated using Coinbase’s exchange platform.
• Class 5: virtual currency assets considered anonymity enhanced/privacy coins or unexchangeable due to litigation.
Table 1: Virtual Currency Portfolio Summary below depicts the current virtual currency portfolio that will be transitioned to the Contractor.
PWS for Virtual Currency SDVOSB Page 4 of 19
DOJ IA Custody USMS Custody TEOAF Custody Total
Asset Count
Value Asset Count
Value Asset Count
Value Asset Count
Value
Class 1 123 $6.6 million 38 $3.7 million 0 $0.00 161 $10.3 million
Class 2 18 $237.9k 1 $210k 0 $0.00 19 $447k
Class 3 31 $157k 0 $0 16 $1.0 million 47 $1.1 million
Class 4 28 $243k 15 $460k 12 $10.9 million 55 $11.3 million
TOTAL 200 $7.2 million 54 $4.3 million 28 $11.9 million 282 $24 million
Table 1: Virtual Currency Portfolio Summary
Crypto currency types encountered and not currently listed will be evaluated as encountered and added to the respective classification based on similar criteria upon agreement from the
USMS COR.
1.3.1 Background
The USMS has been self-managing the virtual currency assets seized and forfeited by the DOJ and TEOAF forfeiture programs since 2014. Since then, the number and complexity of virtual currency assets has increased and the need for a contract to provide management, disposal, and industry knowledge is apparent.
The previous acquisition was awarded twice and both times the winning Contractors were deemed other than small business, losing their various protests. This contract is a temporary solution while USMS re-competes the full contract. The scope of virtual currency work may change over the course of the next 18 months while a new contract is bid out.
1.3.2 Type of Contract Contemplated
This contract is a set aside for SDVOSB Indefinite Delivery Indefinite Quantity contract that includes firm fixed price line items. Accordingly, Task Orders will be issued on a Firm Fixed Price basis.
1.3.3 Period of Performance
The period of performance of this contract shall be date of award and continues for 12 calendar months. There is one 6-month option period that may be exercised by the government unilaterally.
1.3.4 Place of Performance
The primary place of performance will be the Contractor’s facilities with occasional visits to the U.S. Marshals Service (USMS) Headquarters at 1215 South Clark Street, Arlington, VA.
1.3.5 Hours of Operation
The Contractor shall generally perform all work between the hours of 8:00 am and 6:00 pm EST, Monday through Friday (except Federal holidays). However, there may be occasions when the
PWS for Virtual Currency SDVOSB Page 5 of 19
Contractor shall be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this PWS.
2.0 Specific Requirements/Tasks
2.1 Custody
Without delay and where technically feasible, the Contractor shall take custody of and provide compliant secure management and disposal services for any type or quantity of virtual currency deemed necessary by the USMS. See The USMS Cryptocurrency Classifications List May 2022 (Appendix A) attached. The Contractor shall provide all aspects of the secure storage and management of virtual currency in its custody from the time of receipt until disposal. TEOAF will require custody as well and will provide a list of currencies upon contract award.
Virtual currencies not supported by the Contractor (with known private keys or mnemonics) at the time of custody will be allowed a period of five (5) business days for custody. All Digital Assets must be backed up in redundant geographically separate logical locations and in a manner that prevents compromise by internal collusion, third-party collusion, remote or local cyber-attacks, physical loss, fire or acts of nature.
The Contractor shall establish an account with Coinbase Prime/Wallet and acquire necessary software wallets to obtain custody of assets quickly and safely. The Contractor must establish an Asset Management Solution that provides real-time tracking of all assets in the Contractor’s custody regardless of location (Coinbase, Ledgers, Software Wallets, etc.).
2.2 Storage
The Contractor shall maintain complete and accurate accounting of USMS and/or TEOAF inventory at all times, while ensuring that USMS and/or TEOAF inventory is never comingled with any other wallets or addresses of different types or owners.
The Contractor shall take prudent steps to prevent the loss of USMS and/or TEOAF inventory including but not limited to theft, human error, system failures, and acts of nature. The Contractor shall hold virtual currency assets in cold storage. Hardware used to store private keys associated with USMS accounts shall not be connected to any local or external networks at any time.
The Contractor will store mostly Class 1-2 cryptocurrencies on the ERC-20 network and Class 3-4 cryptocurrency. Other Class 1-2 currencies will be transferred on a case-by-case basis as needed.
Generally, currencies which the USMS can dispose of through Coinbase will not be transferred to the Contractor unless there are other factors.
2.3 Management
It is impossible to determine which of the assets under investigation will be taken into USMS or TEOAF custody and ultimately referred to the Contractor. However, to realize the increased capacity and efficiencies expected from this contract, the Contractor shall remain capable of taking custody of all types and quantities of virtual currency without limitation, throughout the performance of this contract. This includes both coin and token types of currency. The Contractor will create a case file system to encompass all stages of the asset lifecycle (custody, management, storage, and disposal) which will be shared with the USMS as requested for review. This system must meet the minimum technical specifications for compliance to DOJ/USMS policy for data, PWS for Virtual Currency SDVOSB Page 6 of 19 access, and records management. The technical design of the system must be sufficient to support the four stages of the asset lifecycle. The vendor shall follow the USMS technical lifecycle processes and reporting where possible.
In addition to the managed assets, any technical devices, systems, services, and digital information provided by the Contractor that is used for direct management of USMS information, separate from the managed Cryptocurrency commercial systems, services and assets must meet DOJ and USMS lifecycle compliance requirements.
The Contractor must note if there are any known issues with DOJ or flags with OCIO for technical services and per Appendix B: Security of Information and Information systems DOJ Procurement Guidance Document (PGD) 15-03.
Management of Inventory
The Contractor must establish monitoring processes that notify the Contractor Officer and the COR of any suspicious activities, movement, and/or airdrops. The contractor must notify the Contracting Officer and COR of any breech or unauthorized disclosure of information or assets.
The Contractor is to notify the COR of any reportable activity withing 24 hours of the occurrence.
Management of Forked Currency
On some older assets forks need to be claimed. Within 30 days of the contract award the Contractor will claim the following forks:
Bitcoin Cash (BCH)Bitcoin Gold (BTG)
Bitcoin Satoshi Vision (BSV)
The Contractor will pull the private key from the wallet, account for the forked tokens and airdrops and provide the USG with an updated accounting of these assets to include the new public address. When instructed, the Contractor will dispose of the forked currency.
As a result of forks, the USMS has custody of about a dozen cases with Bitcoin Satoshi Vision (BSV). This forked currency will be transferred to the Contractor for disposal in one wallet.
Additional BSV may require disposal and is noted so below.
Management of Assets on the ECR-20 Network
The Contactor will provide gas/Ether for the transfer of assets that are ERC-20 tokens regardless of their custody location (USMS or Investigating Agency or ultimate destination (USMS or Contractor).
Management of Ethereum Wallets
There are currently two Ethereum wallets that experienced issues during a software update. It is unclear if the private key is incorrect, or the wallet malfunctioned. The Contractor will identify the issue(s) and potentially open the wallet. If the wallet cannot be opened, documentation of efforts taken to unlock or open the wallet will be provided to the USG.
PWS for Virtual Currency SDVOSB Page 7 of 19
Management of Cryptocurrency-Related Hardware
There may be instances where maintenance of cryptocurrency-related hardware (ironkeys, nano ledgers, etc.) may be needed. This may include taking custody of the hardware, recovering files, etc. Dependent on the situation, the Contractor will identify any issues and assist the USG as needed to manage with reportable tracking of the cryptocurrency-hardware.
2.4 Disposal
The Contractor shall dispose of forfeited virtual currency assets in the manner and timeframes specified by the USMS. These methods include but are not limited to:
• Direct exchange from virtual currency into USD where markets exist.
• Exchange into a more liquid form of virtual currency and then exchanged into USD where markets exist.
• Return to Investigating Agency, owner, or other third party.
Disposal of virtual currency will take place subsequent to a court order or other authorizing document. The Contractor shall dispose of the specified asset upon request by the USMS. The Contractor shall make recommendations with regard to the most prudent method of disposal for the amount and/or particular type of virtual currency that is forfeited, however the ultimate decision with regard to disposal method rests solely with the USMS.
2.4.1 Use of Coinbase for Exchanges
The Contractor will use Coinbase (Coinbase Pro and/or Coinbase Prime) where feasible to perform direct exchanges, exchange into a more liquid form of virtual currency.
USMS shall work with the Contractor to determine other safe and economical ways of liquidating virtual currency where Coinbase is not supported.
2.4.2 Standard Disposal via Exchange
Once a virtual currency asset has been approved for disposal, the USMS will notify the Contractor’s PM and specify which asset under custody can be disposed of and provide the written authority to dispose of the asset to the PM. The USMS, at the time of notification, will either request a recommendation by the Contractor or direct the Contractor which method to dispose of the asset. If the directed method chosen by the USMS is determined to not be feasible, the Contractor must provide a written explanation of the mitigating factor and provide an alternative method and explanation of the choice, and any change in pricing.
Standard disposals of all types of virtual currency shall be completed within five (5) business days of notification.
The five-day disposal deadline will be considered complete when all proceeds are in the Treasury Account. This may require approval from the COR to extend the disposal timeframe depending on exchange-based disposal restrictions.
2.4.3 Standard Return to Third Party and/or USMS
PWS for Virtual Currency SDVOSB Page 8 of 19
In instances where the USMS and/or TEOAF must return virtual currency to a third party and/or USMS, the Contractor shall process these requests in a timely and efficient manner. Although the return of virtual currency is considered a type of disposal with regard to the asset itself, the process of doing so is a function of the management requirement NOT the disposal requirement. Therefore, in the event an asset is disposed of in this manner the Contractor shall NOT be entitled to a commission, rather it shall be entitled to its regular monthly management fee only.
The return of assets to a third party shall be completed within ten (10) business days of notification. A return is at the sole discretion of the USMS COR.
2.4.4 Large Return to Third Party
In instances where the USMS and/or TEOAF must return virtual currency to large parties (100 or more), the return of assets shall be completed within twenty (20) business days of notification and receiving all necessary information.
Cases with victims may require returns of currency via a Petition for Remission. These returns may require taking possession of the server on which the currency was seized to process the returns.
The Contractor will:
− Take custody of the various types of cryptocurrency either by transfer or custody of the entire server or exchange account.
− Process returns according to the Petition for Remission.
− Provide the USMS with reporting documents to include blockchain confirmation of the transfer, claimant name, CATS ID, transfer amount, and any other correspondence with the claimants.
− Utilize a platform such as Coinbase Prime that allows for the individual transfers to be set up in advance so that all returns are processed in unison. This is required to eliminate the priority return of currency to any one or several victims.
2.5 Reporting
2.5.1 General Reporting
The Contractor shall provide system access to meet the needs of the USMS. At a minimum access shall include ad hoc reporting capabilities, and the real-time ability check and monitor the assets being held in storage where technically feasible. System shall provide four nines (99.99%) continuous availability throughout the duration of the contract where technically feasible.
In addition, Contractor shall provide the USMS with ad hoc reports.
The contractor shall support export of report data from maintained systems in standard USMS formats.
All written reports provided in electronic format shall have read/write capability using applications that are compatible with USMS workstations as specified by the USMS during the post award conference.
PWS for Virtual Currency SDVOSB Page 9 of 19
2.5.2 Progress Reporting
The Contractor shall provide a monthly progress report to the COR via electronic mail on the first business day following the last day of each month. This report shall include a summary of all work performed, including a reconciliation of the book inventory with the physical inventory, all direct costs by line item, any travel conducted, an assessment of overall progress, projected activity for the following month, and any identified risks, issues, or concerns and plans for their mitigation.
3.0 Contractor Quality Assurance
The Contractor shall submit a proposed QASP for consideration. The draft QASP should include proposed performance standards and “Acceptable Quality Level (AQL), as well as suggested price adjustment or other action.
Please note, the QASP is the internal USMS plan for implementing measurable performance standards for the purposes of monitoring and evaluating the performance of the Contractor.
Therefore, although the USMS will consider alternatives proposed by the Contractor, the final decision on the contents of the QASP rests solely with the USMS.
4.0 Delivery or Deliverables
Timely submission of deliverables and reports is essential to successfully completing this requirement. Schedules for deliverables are specified in Table 2: Deliverables below.
Item Deliverable/Event DUE DIST
1 Post Award Conference Within thirty (30) business days after date of award
Contracting Officer
2 Final Contractor Project Plan Within thirty (30) days of Post Award Conference
Contracting Officer, COR
3 Final Quality Assurance Surveillance Plan
Within thirty (30) days of Post Award Conference
Contracting Officer, COR
4 Business Continuity Plan Within thirty (30) days of Post Award Conference
Contracting Officer, COR
5 Updated Business Continuity Plan Annually Contracting Officer, COR
6 Progress Reports Monthly Contracting Officer, COR
7 Progress Meetings Monthly Contracting Officer, COR
8 Cybersecurity Lifecycle or Breech Notification
Within 24 hours of reportable activity
Contracting officer, COR
Table 2: Deliverables
PWS for Virtual Currency SDVOSB Page 10 of 19
Notice to Contractors:
All information and data related to this project that the Contractor gathers or obtains shall be both protected from unauthorized release and considered the property of the government. The contracting officer will be the sole authorized official to release verbally or in writing, any data, the draft deliverables, the final deliverables, or any other written or printed materials pertaining to this contract.
Press releases, marketing material, or any other printed or electronic documentation related to this project, must not be publicized without the written approval of the USM CO and/or USMS COR.
Contractor will be fined $100,000 if violated, and on the third violation the contract will be terminated.
Unauthorized disclosure of USMS records and technical system breeches must be reported in accordance with appendix B: PGD 15-03 and the USMS security incident reporting procedures and timeframes. The Contractor is responsible for maintaining appropriate access and systems technical controls to ensure protection and compliance.
5.0 Constraints
5.1 Liability
The Contractor shall be liable for any act, omission, negligence, or lack of performance on their part which results in the damage, devaluation, destruction, or loss of any and all physical or virtual property, parts, items or derived portion that the Contractor handles during the performance of this contract. Insurance will be 50% of the commensurate value of the inventory and will be adjusted and reviewed quarterly. The USMS will cover the remaining 50% as the United States Government is self-insured. Bonding is required at the same percentage all times and shall make the USMS whole in the event of any losses. In the event insurance cannot be obtained, the USMS will require an escrow of funds for the duration of the contract.
The Contractor shall be responsible for technical systems under their direct control where unauthorized access and information disclosures occur. The Contractor shall be responsible for taking corrective action consistent with DOJ Data Breach Notification Procedures and as directed by the DOJ and USMS CO, including all costs and expenses associated with such corrective action in accordance with Appendix B DOJ PGD 15-03 DOJ Security Requirements for Procured Technical Solutions and Services, Section VI. Information System Security Breach or Incident (Appendix B). Examples of technical systems under the Contractor’s direct control may include laptop/desktop devices used for managing USMS program information, program reporting services, asset tracking and management services.
5.2 Compliance
5.2.1 External Audits
To the extent deemed necessary by the USMS to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, accuracy, and confidentiality of any non-public USMS data collected and stored by the Contractor, the Contractor shall afford the USMS access to the Contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases at any time during the performance of the contract.
PWS for Virtual Currency SDVOSB Page 11 of 19
Additionally, the Contractor shall remain available to respond and assist the USMS with responding to inquiries by our auditors, both internally and externally. The USMS and/or the Office of the Inspector General (OIG) may periodically contract for the services of an Independent Public Accountant (IPA) to perform a review of the program. The Contractor shall allow and provide as follows:
a. Contractor shall make facility and USMS records accessible to the USMS and or
OIG/IPA upon request.
b. Contractor shall provide ample workspace for USMS and or OIG/IPA during visits.
c. Contractor shall provide onsite representative to assist USMS and or OIG/IPA during visits.
5.2.2 Internal Audits
The CFO Act of 1990 requires an annual audit of the Asset Forfeiture Fund (AFF) annual financial statements. As part of this audit, the Contractor is mandated to conduct a one hundred percent (100%) annual inventory reconciliation for all assets in the custody of the Contractor, including assets which may have become forfeited and/or unblocked based on a Disposition Order but which are still in the custody of the Contractor. The Contractor shall provide their internal audit report to the USMS within five (5) business days of completion. Deficiencies identified by any audit findings shall be cured by the Contractor within twenty (20) business days of such identification or as approved by the
CO.
5.2.3 Information Technology Compliance Audits
The Federal Information Security Management Act (FISMA 2002) and the Federal Information Security Modernization Act (FISMA 2014), defines a framework for security standards and requires all technical services maintain compliance with those standards.
The Department of Justice selects programs, services, and systems annually for FISMA audit review. In addition to FISMA audits, an annual review of compliance controls is conducted by USMS to ensure approval for continuance of a program, service, or systems Authority to Operate. The Contractor shall provide support for any compliance activity review of security standards controls and mitigation as required.
5.3 Information Systems and Services
The Contractor shall provide on-site or remote assistance as required in support of this PWS. All key personnel with systems or services access must be based in the United States, be US Citizens, and must obtain a US government clearance. Per DOJ Security Requirements and in accordance FISMA (Appendix B: DOJ PGD 15-03 DOJ Security Requirements for Procured Technical Solutions and services), the organization and system must follow, develop and maintain technical services to standards to meet the Authority to Operate (ATO) security authorization, DOJ Strong Authentication Policy, and ensure future policies and updates are met throughout the lifecycle for systems and services housing USMS data. The Contractor will ensure
PWS for Virtual Currency SDVOSB Page 12 of 19 all performance and new proposed solutions are compliant with applicable legal, regulatory, Department of Justice (DOJ) and USMS policy requirements to maintain an Authority to Operate (ATO) on all Government-owned information technology systems and services. The Contractor will also ensure performance and new solutions are consistent with Industry and Technology guidance best practices. Any Contractor provided cloud services used for USMS information management delivery shall ensure adherence to the Cloud Service Provider Requirements (Appendix C); and meet DOJ policy outlined in PGD_15_03_Requirements (Appendix B); and meet federal regulatory compliance outlined in USMS Standards and Compliance Requirements (Appendix D).
Reporting related to audit elements shall be provided upon request. Security Certification and Accreditation control validation activities are separately scoped, through a USMS separately maintained for Government-owned services contract. The Contractor shall assist the Government authorized representative, which may be a federal or contractor member of the Cyber Security Branch (CSB), Information System Security Officer (ISSO), with implementation of security controls, Assessment and Authorization (A&A), Authority to test (ATT), Authority to Operate (ATO), vulnerability management, risk mitigation, and maintenance of current Government-owned services. The contractor shall maintain accurate security documentation in DOJ Cyber Security Assessment and Management (CSAM) systems. The Contractor shall develop Plan of Action and Milestones (POA&M) for identified security deficiencies and manage and resolve POA&MS according to Government approved schedule(s). Cyber risk is measured through operational cyber protections and must be embedded in delivery services for architecture, design and delivery of systems, solutions, and services. The Contractor shall provide architectural design documents, diagrams, configuration baselines, reports, patches, system updates, vulnerability mitigation, infrastructure protections, logging, monitoring, alerts, and response in support of specific security related questions, processes, or requested actions as needed and specified by the USMS COR. The Contractor must ensure compliance inclusive of audit support requested by the Cyber Security Branch Audit management team. The standards outlined in Standards and Compliance Requirements (Appendix D), apply to systems, products, and services delivered directly in support of USMS information management performance deliverables by the Contractor, services maintained directly by the Contractor and service designs proposed by the Contractor and may change over the lifecycle of this contract in accordance with DOJ and USMS policy updates. The Contractor is responsible for compliant access of maintained USMS used controls to public cryptocurrency clouds, systems, and services, but not compliance of the commercially owned services themselves.
5.4 Data
The USMS owns the rights to all data/records produced as part of this contract and shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. The Contractor shall not create or maintain any records containing any USMS information that are not specifically tied to or authorized by the contract. Further, disposition and destruction of records is EXPRESSLY PROHIBITED unless authorized by the USMS.
The Contractor shall prevent the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage, or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701.
All information related to this contract created or produced in part or in whole, regardless of type of media, is to be maintained for the duration of the contract, made available upon
PWS for Virtual Currency SDVOSB Page 13 of 19 request, and upon termination of the contract shall be turned over to the USMS. This includes but is not limited to all electronic files, hard copy files, data contained in electronic information systems, databases, etc., and all supporting documentation. The Contractor must deliver sufficient technical documentation with all data deliverables to permit use of the data by the USMS. The contractor shall ensure technical documentation addresses measures taken toward system and services compliance with DOJ/USMS policy.
Any Contractor produced and used algorithms or artificial intelligence code outside commercial off the shelf (COTS) services produced for use in this contract must meet the DOJ and federal
All data at rest shall reside within the contiguous United States, the District of Columbia, and Alaska (CONUS) with a minimum of two geographically separated different and distant geographic locations. Data shall be maintained to ensure high availability. Data at rest and in transit shall be encrypted and protected to Federal Information Security Management Act (FISMA) and USMS standards.
5.5 Continuity of Service
The Contractor shall prepare and submit a Business Continuity Plan (BCP) to the USMS. The BCP shall be due at the post award conference and will be updated on an annual basis. The BCP shall document Contractor plans and procedures to maintain support during an emergency, including natural disasters and acts of terrorism. The BCP, at a minimum, shall include the following:
• A description of the Contractor’s emergency management procedures and policy
• A description of how the Contractor will account for their employees during an emergency
• How the Contractor will communicate with the USMS during emergencies
• A list of primary and alternate Contractor points of contact, each with primary and alternate:
o Telephone Numbers o E-mail addresses
Individual BCPs shall be activated immediately after determining that an emergency has occurred, shall be operational within 24 hours of activation or as directed by the USMS, and shall be sustainable until the emergency situation is resolved and normal conditions are restored or the contract is terminated, whichever comes first. In case of a life-threatening emergency, the COR shall immediately make contact with the Contractor’s Project Manager to ascertain the status of any Contractor personnel who were located in USMS controlled space affected by the emergency. When any disruption of normal, daily operations occurs, the Contractor’s Project Manager and the COR shall promptly open an effective means of communication and verify:
• Key points of contact (USMS and Contractor)
• Temporary work locations (alternate office spaces, telework, virtual offices, etc.)
• Means of communication available under the circumstances (e.g., email, webmail, telephone, FAX, courier, etc.)
PWS for Virtual Currency SDVOSB Page 14 of 19
• Essential Contractor work products expected to be continued, by priority
• Availability of the recovery point objectives (RPO) in the specified recovery time objectives (RTO) for systems, services, and data.
• Cybersecurity status and posture of services.
The USMS and Contractor’s Project Manager shall make use of the resources and tools available to continue contracted functions to the maximum extent possible under emergency circumstances. Contractors shall obtain approval from the Contracting Officer prior to incurring costs over and above those allowed for under the terms of this contract. Regardless of contract type, and of work location, Contractors performing work in support of authorized tasks within the scope of their contract shall charge those hours accurately in accordance with the terms of this contract.
5.6 Key Personnel Contractor Support
Contractor access to systems, services, and privileged information is required under this PWS.
Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with pertinent laws and regulations governing the confidentiality of privileged information and Safeguarding Sensitive But Unclassified (SBU) (For Official Use Only) Information. All key personnel with access to privileged information must be based in the United States, be US Citizens, and must obtain a US government clearance. The Contractor shall sign a non-Disclosure agreement, Corporate Non-Disclosure Agreement (Appendix E). Contract personnel who provide direct support with systems or services access shall sign a non-disclosure agreement, DOJ USMS Non-Disclosure Agreement (Appendix F). Contract personnel that need USMS data and privileged systems access shall be required to complete training annually and to sign a Rules of Behavior, DOJ Rules of Behavior 2021 General Users (Appendix G), and may be required to undergo additional screening. The COR will furnish personnel security application forms to the Contractor as described in Personnel and Property Contractor Compliance Requirements (Appendix H). The initial personnel security form must be submitted for all key personnel as needed. The COR shall notify the Contractor, via email, upon clearance acceptance of contractor personnel, a "Notice to Proceed" to start performance. For purposes of this clause, the Contract award date and effective date are synonymous. The individual Contractor personnel start date(s) shall only begin after approval from the Government, and may start prior to clearance acceptance if authorized by the COR. All Contractors performing work on this contract must sign a DOJ Rules of Behavior General User (Appendix G). If a contractor has elevated access rights, they must also sign a DOJ Rules of Behavior (Privileged User) that will be provided if required.
Contractor access to classified information is not currently required under this PWS. However, the USMS may require all Contractor personnel to have higher clearances at a later date.
Accordingly, at a minimum all Contractor employees provided for this requirement must be eligible for a Secret Clearance.
5.7 Conflicts of Interest
To avoid a conflict of interest, or the appearance of a conflict of interest, the Contractor, Subcontractor (s), associated employees and their immediate family/household members, any
PWS for Virtual Currency SDVOSB Page 15 of 19 entity in which the Contractor has any financial interest; or any agent or representative for such party, are prohibited from bidding on or buying any forfeited property, either directly or indirectly.
If the mere appearance of conflict of interest might arise, the Contractor shall notify the USMS COR immediately.
6.0 Performance Requirements Matrix
The PRM establishes key elements of Contractor performance that represent “mission essential” service requirements, which are identified in the table below in the “Required Service” column, which point to different sections in the PWS. The “Performance Standards” column represents the standard against which Contractor performance will be measured in relation to accomplishment of the corresponding service output. The performance objective or “standard” describes the acceptable level of service by the Contractor for satisfactory performance. The performance standards are the only acceptable levels of service and if these are not met, the Contracting Officer will evoke the negative incentive specified in the Table 3: Performance Requirements Matrix below.
Required Service Performance Standards Incentive
(Negative)
Custody Takes custody within five (5) business days.
Invoice deduction of $500 for each instance.
Storage Accurate and segregated inventory.
Invoice deduction of $500 for each instance.
Project Manager (or designee)
Available within two hours of request between 8 AM EST – 6 PM EST, Monday through Friday. Federal holidays and weekends excluded, using agreed upon contact methods.
Invoice deduction of $500 for each late instance or unavailability.
Standard Disposal Completed within 5 business days
Invoice deduction of $500 for each disposal completed late
Return to Third Party Completed within 5 business days
Invoice deduction of $500 for each disposal completed late
General Compliance within 24 hours of loss or breach, two weeks for remediation plan
Per PGD-1503, Contractor is responsible for damages and costs related to loss. Invoice deduction of $500 for each day remediation plan is late.
General Reporting System Downtime (not including blockchain networks)
Invoice deduction of $500 for each instance
PWS for Virtual Currency SDVOSB Page 16 of 19
Required Service Performance Standards Incentive
(Negative)
Monthly Progress Reports
Reports are complete and submitted within the prescribed timeframes.
Invoice deduction of $500 for each report delivered late
Monthly Progress Meetings
Contractor is fully prepared for meetings and they are conducted within prescribed time period
Invoice deduction of $500 for each late/missed meeting.
External Audits Audits are fully supported ensuring access to data and efficiency of audit process.
Invoice deduction of $500 for each audit conducted late
Internal Audits Audit is conducted fully and within the prescribed timeframes.
Invoice deduction of $500 for each incomplete or late audit.
Continuity of Service Updated BCP is complete and submitted within the prescribed timeframes.
Invoice deduction of $500 for each incomplete or late BCP.
Cybersecurity Lifecycle or Breech Notification
Written and verbal notification within 24 hours of reportable activity
Invoice deduction of $500 for each late notification on all services and required remediation costs per DOJ policy for Contractor systems and services housing USMS information.
Table 3: Performance Requirements Matrix
7.0 Meetings
For all meetings, the Contractor shall be responsible for providing meeting materials, and administrative and facilitation support. Meetings will be conducted at either the USMS Headquarters location at 1215 S. Clark Street, Arlington, VA 22202, or through an alternative method of communication (such as Microsoft Teams), as approved by the USMS CO and/or USMS COR.
7.1 Post-award Kickoff Meeting
Within 14 business days of contract award, the USMS CO and USMS COR will conduct a post-award kickoff meeting at USMS Headquarters at 1215 S. Clark Street, Arlington, VA 22202 (specific date and time to be mutually agreed-upon). The purpose of the meeting is to discuss technical and contracting objectives of this contract and finalize the Contractor’s draft project plan.
7.2 Intermittent Project Status Reviews
At the sole discretion of the USMS COR, intermittent project status reviews may be conducted on an informal basis (by telephone or Microsoft Teams) or in person at USMS Headquarter on an as needed basis as approved by the USMS COR.
7.3 Monthly Project Status Reviews
PWS for Virtual Currency SDVOSB Page 17 of 19
Monthly status meetings to be conducted on the first Wednesday of each month. The Contractor is responsible for reporting the previous month’s activities (including any risks, issues, or concerns, and actual or recommended actions for their mitigation), and projected activities for the following month. At minimum, the Contractor shall review the status and results of Contractor performance with the USMS COR. The monthly meeting may be held via telephone or Microsoft Teams.
7.4 Program Management Review
The USMS COR will conduct quarterly program management reviews at the Contract’s location to review the progress of the program, identify any risks, issues, or concerns, and provide feedback on the Contractor’s progress and performance. The Contractor shall provide written data and verbal presentations as to the financial status, any identified any risks, issues, or concerns (and their mitigation or its plans for their mitigation).
7.5 Technical Services Review
Technical services review meetings as needed for change management activities related to directly provided Contractor systems and services which house USMS information.
Limited review of access and records elements associated with the Commercial Cryptocurrency Services which are part of the managed services delivery and not considered directly attributed USMS owned or operated systems and services. Status reports, meetings, and artifacts related to use of Contractor systems housing USMS management information during the system or service lifecycle for enablement, audit support, changes inclusive of patching and updates, and vulnerability response may be required if requested.
8.0 Required Travel and Other Direct Costs (ODCs)
Contractor travel may be required to support this requirement. The principal place of performance is Arlington, VA. Accordingly, reimbursable travel and per diem for the Contractor’s employees performing work on a regular basis in this area of performance is not authorized. Any changes to this must be approved in advance by the USMS COR.
All travel required by the USMS outside of the local commuting area will be reimbursed to the Contractor in accordance with the Federal Travel Regulation. Where reimbursement is required, the USMS COR must approve Contractor travel in advance.
9.0 Special Instructions
9.1 General
Processes which are fundamental to providing the data critical to achieving USMS goals will change throughout the period of this contract due to advancements in technology, the USMS adoption of new technology, evolving state and federal regulations, and to ensure alignment with organizational and Federal policy. The Contractor shall work in good faith to accommodate such changes as necessary to ensure USMS requirements are met, and to the extent any such changes are necessary to the contract.
https://www.gsa.gov/portal/content/104790
PWS for Virtual Currency SDVOSB Page 18 of 19
The Contractor shall maintain a close and cooperative working relationship with the USMS and make appropriate recommendations. The Contractor shall perform his/her functions in accordance with all applicable Federal, State, and local laws and regulations applicable to the services being provided as well as any policies as specified by the USMS. The Contractor shall obtain and keep current throughout the duration of the contract all licenses, insurance policies, permits, and related documents common within the industry and necessary as established by any regulations to operate this type of business.
The Contractor shall immediately report all emergencies to the COR. Examples include but are not limited to: natural disasters affecting the storage facility, loss of currency, any transfer discrepancy, any compromise in cold storage or security. The Contractor will notify the USMS and/or TEOAF of any data breach or loss of cryptocurrency within 24 hours, and within two weeks, the Contractor must provide a recommended remediation for recovery to ensure future risk mitigation of a similar event.
10.0 Government Furnished Property/Equipment/Information
The Contractor shall provide all materials, supplies, technology, labor, and equipment necessary to meet the requirements of this contract. Government furnished devices shall be maintained in accordance with USMS policy and access to technical services shall follow requirements outlined in Section 5 of this PWS. All technology equipment and access control devices and software provided must be returned at the end of the contract to the COR.
11.0 Glossary of Abbreviations and Acronyms
Acronym/Abbreviation Definition
BCP Business Continuity Plan
CDR Contract Discrepancy Report
CLIN Contract Line Item Number
CO Contracting Officer
CONUS Contiguous United States
COR Contracting Officer’s Representative
FISMA Federal Information Security Management Act
IPA Independent Public Accountant
OIG Office of the Inspector General
POP Period of Performance
PRS Performance Requirements Summary
PWS Performance Work Summary
USMS United States Marshals Service
QASP Quality Assurance Surveillance Plan
PWS for Virtual Currency SDVOSB Page 19 of 19
Table 4: Glossary of Abbreviations and Acronyms
For the purposes of this contract, the forfeiture process consists of the following two primary phases:
Pre-seizure: This phase seeks to identify and address critical title, financial, property management and disposal issues prior to making the decision to proceed with a forfeiture action.
Asset Management: This phase covers the asset life cycle from the point of seizure, to the ultimate disposal of the property and can be further broken down into the following processes:
• Seizure: During this stage the U.S. Marshals Service takes custody of the asset based on a federal court order and serves as the responsible steward of the asset until such time as a forfeiture order has been entered against the asset.
• Forfeiture: The asset has been forfeited to the United States based upon the issuance of a federal court order directing the USMS to sell or otherwise dispose of the asset. The USMS will continue to maintain the asset until such time as its final disposal has been completed.
• Disposal: Pursuant to a federal forfeiture order, the USMS will dispose of the property accordingly.
UNCLASSIFIED // LES
USMS Cryptocurrency Classification List Rev. 10/22
United States Marshals Service Asset Forfeiture Division USMS Cryptocurrency Classification List
The United States Marshals Service (USMS) accepts most virtual currency assets sought for forfeiture by the U.S.
Government, although there are some exceptions. To easily identify what is accepted by USMS, the Asset Forfeiture Division (AFD) has assigned all virtual currency types to one of five classifications.
Note: This list is periodically updated to reflect market changes and should be referenced with each new case.
If you have identified a virtual currency not on this list, please contact USMS to determine which classification type the asset would fall in.
Class 1 Assets are supported by USMS’s wallet and can be liquidated using Coinbase’s exchange platform. These assets are accepted when seized and/or upon forfeiture.
0x (ZRX) Aave (AAVE) Algorand (ALGO) ApeCoin (APE) Augur (REP) Avalanche (AVAX) Band Protocol…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .