70RDAD21R00000001 Final Solicitation RFP.pdf

PDF 1 MB Posted

Attached to
Cybersecurity Compensation System Support Services Federal contract opportunity
Solicitation number
70RDAD21R00000001
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This solicitation requests proposals for cybersecurity compensation system support services. The Department of Homeland Security seeks a contractor to assist with designing, operating, and analyzing its new Cybersecurity Compensation System, which will be part of the Cybersecurity Talent Management System. The support services include ongoing assessments of the system design, market analysis, cost modeling, and operation of salary structures and incentive programs. Proposals are due by March 22, 2021, and the base period of performance is one year with four optional one-year extensions. The solicitation is full and open and will result in a single-award time and materials contract. The contractor must have experience with cybersecurity compensation programs and a strong understanding of the cybersecurity labor market.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity Compensation System Support Services, newest first.
File Type Posted
Question and Answers to Solicitation.xlsx XLSX spreadsheet
70RDAD21R00000001 Amendment 0001 to RFP.pdf PDF
Pre Proposal Conference Recording.mp4 MP4 file
70RDAD21R00000001 Attachment 1 Labor Categories and Qualifications.pdf PDF
70RDAD21R00000001 Attachment 2 Pricing Table.xlsx XLSX spreadsheet
70RDAD21R00000001 Attachment 3 Non-Disclosure Agreement.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUMIS CHECKED

CODE 18a. PAYMENT WILL BE MADE BY

CODE

FACILITYCODE

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

OFFEROR

DHS/OPO/DEPT.OPS

245 Murray Lane SW, #0115 Dept. Operations Acquisition Div.

Office of Procurement Operations U.S. Dept. of Homeland Security

CODE 16. ADMINISTERED BYCODE

X

X

541612

SIZE STANDARD:

% FOR:SET ASIDE:UNRESTRICTED OR70RDAD

RFPIFB

10. THIS ACQUISITION ISCODE

RFQ

14. METHOD OF SOLICITATION

13b. RATING

NAICS:

SMALL BUSINESS

03/22/2021 1200 ES

03/16/2021

202-447-5667Daniel Weingarten (No collect calls)

INFORMATION CALL:

FOR SOLICITATION 8. OFFER DUE DATE/LOCAL TIMEb. TELEPHONE NUMBER a. NAME

4. ORDER NUMBER3. AWARD/ 6. SOLICITATION

70RDAD21R00000001

5. SOLICITATION NUMBER

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS 1. REQUISITION NUMBER PAGE OF

1 77 RUHC-21-CS003OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

Washington DC 20528-0115

TELEPHONE NO.

17a. CONTRACTOR/

15. DELIVER TO

Washington DC 20528 245 Murray Lane SW, Mailstop 0115 Dept. Operations Acquisition Div.

Office of Procurement Operations U.S. Dept. of Homeland Security

9. ISSUED BY

7.

2. CONTRACT NO.

EFFECTIVE DATE

$16.50

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW

ISSUE DATE

DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

11.

SEE SCHEDULEX

12. DISCOUNT TERMS

THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13a.

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

8(A)

DEPT OPS ACQ DIV(70RDAD)

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

24.

AMOUNT

23.

UNIT PRICE

22.

UNIT

21.

QUANTITY

20.

SCHEDULE OF SUPPLIES/SERVICES

19.

ITEM NO.

The intent of this solicitation is to acquire Cybersecurity Talent Management System (CTMS) Compensation Analysis Support Services.

0001 Task 1 - Design Period of Performance: 04/29/2021 to 04/28/2022

0002 Task 2 - Analysis (Option Line Item) Continued ...

(Use Reverse and/or Attach Additional Sheets as Necessary)

HEREIN, IS ACCEPTED AS TO ITEMS:

XX

DATED

Phorsha R. Peel

. YOUR OFFER ON SOLICITATION (BLOCK 5),

INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER

ARE

ARE

31c. DATE SIGNED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (Type or print)

ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL

SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

26. TOTAL AWARD AMOUNT (For Govt. Use Only)

OFFER

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA - FAR (48 CFR) 53.212

ARE NOT ATTACHED.

ARE NOT ATTACHED.

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

30b. NAME AND TITLE OF SIGNER (Type or print)

30a. SIGNATURE OF OFFEROR/CONTRACTOR

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

25. ACCOUNTING AND APPROPRIATION DATA

29. AWARD OF CONTRACT:

REF.

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32c. DATE 32b. SIGNATURE OF AUTHORIZED GOVERNMENT REPRESENTATIVE

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

40. PAID BY39. S/R VOUCHER NUMBER38. S/R ACCOUNT NUMBER

37. CHECK NUMBER

FINALPARTIAL

36. PAYMENT

FINALPARTIAL

35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER33. SHIP NUMBER

COMPLETE

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

42d. TOTAL CONTAINERS42c. DATE REC'D (YY/MM/DD)

42b. RECEIVED AT (Location)

42a. RECEIVED BY (Print)

41c. DATE41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

STANDARD FORM 1449 (REV. 2/2012) BACK

24.

AMOUNT

23.

UNIT PRICE

22.

UNIT

21.

QUANTITY

20.

SCHEDULE OF SUPPLIES/SERVICES

19.

ITEM NO.

Period of Performance: 04/29/2021 to 04/28/2022

0003 Task 3 - Operation

(Option Line Item)

Period of Performance: 04/29/2021 to 04/28/2022

0004 Task 4 - Surge

(Option Line Item)

Period of Performance: 04/29/2021 to 04/28/2022

0005 Other Direct Cost

Period of Performance: 04/29/2021 to 04/28/2022

1001 Task 1 - Design Option Year 1

(Option Line Item)

Period of Performance: 04/29/2022 to 04/28/2023

1002 Task 2 - Analysis Option Year 1

(Option Line Item)

Period of Performance: 04/29/2022 to 04/28/2023

1003 Task 3 - Operation Option Year 1

(Option Line Item)

Period of Performance: 04/29/2022 to 04/28/2023

1004 Task 4 - Surge Option Year 1

(Option Line Item)

Period of Performance: 04/29/2022 to 04/28/2023

Continued ...

32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT REPRESENTATIVE

77 2 of

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

NAME OF OFFEROR OR CONTRACTOR

3 77

CONTINUATION SHEET

REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF

(A) (B) (C) (D) (E) (F)

70RDAD21R00000001

1005 Other Direct Cost Option Year 1

(Option Line Item)

Period of Performance: 04/29/2022 to 04/28/2023

2001 Task 1 - Design Option Year 2

(Option Line Item)

Period of Performance: 04/29/2023 to 04/28/2024

2002 Task 2 - Analysis Option Year 2

(Option Line Item)

Period of Performance: 04/29/2023 to 04/28/2024

2003 Task 3 - Operation Option Year 2

(Option Line Item)

Period of Performance: 04/29/2023 to 04/28/2024

2004 Task 4 - Surge Option Year 2

(Option Line Item)

Period of Performance: 04/29/2023 to 03/31/2024

2005 Other Direct Cost Option Year 2

(Option Line Item)

Period of Performance: 04/29/2023 to 04/28/2024

3001 Task 1 - Design Option Year 3

(Option Line Item)

Period of Performance: 04/29/2024 to 04/28/2025

3002 Task 2 - Analysis Option Year 3

(Option Line Item)

Period of Performance: 04/29/2024 to 04/28/2025

3003 Task 3 - Operation Option Year 3

(Option Line Item)

Period of Performance: 04/29/2024 to 04/28/2025

3004 Task 4 - Surge Option Year 3

(Option Line Item)

Period of Performance: 04/29/2024 to 04/28/2025

3005 Other Direct Cost Option Year 3

(Option Line Item)

Period of Performance: 04/29/2024 to 04/28/2025

Continued ...

NSN 7540-01-152-8067 OPTIONAL FORM 336 (4-86)

Sponsored by GSA

FAR (48 CFR) 53.110

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

NAME OF OFFEROR OR CONTRACTOR

4 77

CONTINUATION SHEET

REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF

(A) (B) (C) (D) (E) (F)

70RDAD21R00000001

4001 Task 1 - Design Option Year 4

(Option Line Item)

Period of Performance: 04/29/2025 to 04/28/2026

4002 Task 2 - Analysis Option Year 4

(Option Line Item)

Period of Performance: 04/29/2025 to 04/28/2026

4003 Task 3 - Operation Option Year 4

(Option Line Item)

Period of Performance: 04/29/2025 to 04/28/2026

4004 Task 4 - Surge Option Year 4

(Option Line Item)

Period of Performance: 04/29/2025 to 04/28/2026

4005 Other Direct Cost Option Year 4

(Option Line Item)

Period of Performance: 04/29/2025 to 04/28/2026

NSN 7540-01-152-8067 OPTIONAL FORM 336 (4-86)

Sponsored by GSA

FAR (48 CFR) 53.110

FEDERAL ACQUISITION REGULATION (FAR) Subpart 12.6

COMBINED SYNOPSIS/SOLICITATION NOTICE

In accordance with (IAW) Federal Acquisition Regulation (FAR) subpart 12.603, Streamlined Solicitation for Commercial Items, Combined Synopsis/Solicitation Procedures, shall be utilized in support of the subject solicitation. As such the following synopsis information as required by FAR subpart 5.207 Preparation and transmittal of synopses is hereby provided to include detail required by aforementioned FAR subpart 12.603.

(1) Action Code: Not Applicable

(2) Date: March 16, 2021

(3) Year: 2021

(4) Contracting Office ZIP Code: 20528-0115

(5) Product or Service Code: R431

(6) Contracting Office Address: U.S. Dept. of Homeland Security Office of Procurement Operations 245 Murray Lane, SW, Mailstop 0115 Washington DC 20528-0115

(7) Subject: Department of Homeland Security (DHS), Cybersecurity Compensation System Support Services

(8) Proposed Solicitation Number: 70RDAD21R00000001

(9) Closing Response Date: Phase I Proposal – March 22, 2021

(10) Contact Point or Contracting Officer: Daniel Weingarten Email: Daniel.Weingarten@hq.dhs.gov

Phorsha Peel Email: Phorsha.Peel@hq.dhs.gov

(11) Contract Award and Solicitation Number: Solicitation Number: 70RDAD21R00000001 Award Number: TBD mailto:Daniel.Weingarten@hq.dhs.gov mailto:Phorsha.Peel@hq.dhs.gov

(12) Line Item Number: A schedule of supplies and services is represented within the solicitation document reference Section B, to include solicitation Attachment 2, Pricing Schedule Template.

(14) Contract Award Date: TBD

(15) Contractor: TBD

(16) Description: This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in FAR subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation is hereby issued as a part of this notice.

Solicitation 70RDAD21R00000001 is issued as a Request for Proposal (RFP) where provisions 52.212-1, , 52.212-3, 52.212-4, and 52.212-5 applies.

Award will be made on a best value/tradeoff basis as described in Section M of the RFP.

(17) Place of Contract Performance: Section F

(18) Set-aside Status: Full and Open

SECTION A: SOLICITATION/CONTRACT FORM

See solicitation Standard Form 1449

SECTION B – SUPPLIES OR SERVICE/PRICE OR COST

1 AWARD TYPE

The Government intends to award a Time and Materials type single award contract.

2 GENERAL DESCRIPTION

This Department of Homeland Security (DHS), Cybersecurity Compensation System Support Services acquisition is a single award contract. The objective of this contract is to assist DHS with the design and ongoing operation of a Cybersecurity Compensation System, which will be one key element of the Department’s new Cybersecurity Talent Management System (CTMS) (note: CTMS is a Federal civilian personnel system—not an information technology system.

Similarly, the Cybersecurity Compensation System is not an information technology system; it is a set of business rules, processes, and policies for administering compensation). The Strategic Cybersecurity Compensation System should enable DHS to offer sufficiently competitive compensation to recruit and retain required cybersecurity talent, while remaining responsive to changes in the cybersecurity labor/talent market and the cybersecurity work necessary to execute the DHS mission. The Cybersecurity Compensation System should balance internal and external equity, while integrating leading compensation methods, including those proven effective in cybersecurity-focused organizations and those reflecting a focus on skills/competencies/capabilities.

SECTION C: DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK

1 BACKGROUND

The DHS Office of the Chief Human Capital Officer (OCHCO) leads a cross-Component effort to implement a new cybersecurity-focused Federal civilian personnel system, the Cybersecurity Talent Management System (CTMS), as authorized by the Border Patrol Agent Pay Reform Act of 2014 (P.L. 113-277), which added a new section (codified at 6 U.S.C. § 658) to the Homeland Security Act of 2002. The Secretary’s authority allows for a variety of talent management changes, including alternative methods for describing jobs, conducting hiring, and compensating employees.

In designing CTMS, DHS has revisited some of the foundational theories and structures that underlie how the Federal Government has managed talent for a decade. In order to modernize the civil service for cybersecurity work, DHS has specifically revisited the following aspects of compensation: traditional Federal position classification, multi-field salary structures, tenure-based salary progression, and occupation-focused compensation flexibilities. In completing the design of CTMS and preparing for launch, DHS is pursuing new compensation practices to enhance the Department’s capacity to compete for top cybersecurity talent in a competitive market.

The objective of this contract is to assist DHS with the design and ongoing operation of a Cybersecurity Compensation System, which will be one key element of the Department’s new CTMS (note: CTMS is a Federal civilian personnel system—not an information technology system. Similarly, the Cybersecurity Compensation System is not an information technology system; it is a set of business rules, processes, and policies for administering compensation). The Strategic Cybersecurity Compensation System should enable DHS to offer sufficiently competitive compensation to recruit and retain required cybersecurity talent, while remaining responsive to changes in the cybersecurity labor/talent market and the cybersecurity work necessary to execute the DHS mission. The Cybersecurity Compensation System should balance internal and external equity, while integrating leading compensation methods, including those proven effective in cybersecurity-focused organizations and those reflecting a focus on skills/competencies/capabilities.

2 SCOPE

Contractor support is needed for ongoing design and operation of the Cybersecurity Compensation System based on existing DHS work, including some completed with the support of a prior contractor. Existing work includes proposed designs for: a national broadband salary structure, including geographic differentials/supplements, and a streamlined menu of recruitment and retention incentives, including cash bonuses, time-off, and student loan repayments. Support for the Cybersecurity Compensation System will include: Design, Analysis, Operation, and Surge.

The contractor shall perform the task identified as “MANDATORY” on a continual basis upon award. If the need arises, the contractor shall perform the tasks identified as “OPTIONAL.”. If the need arises, the contractor shall perform Task Four – Surge, which is to enable DHS to increase the number of support staff and/or adjust the level of expertise provided across other tasks to address unexpected circumstances.

3 SPECIFIC REQUIREMENT/TASKS

3.1 TASK ONE: Design (MANDATORY):

1. Review and remain knowledgeable of the latest versions of foundational documentation related to CTMS and the Cybersecurity Compensation System, including: CTMS regulations, Government-wide compensation regulations that apply under CTMS, CTMS policies, and CTMS standard operating procedures (SOPs).

2. Produce ongoing assessments of the design and current state of the Cybersecurity Compensation System, including information about cybersecurity compensation best practices and options for enhancing System operation and effectiveness. Each assessment should be scoped with DHS to clarify format (e.g., issue paper, draft policy language, executive summary, slide deck, chart/graph, action plan); to ensure appropriate specialized expertise is available to assist (in some cases, there may be a need for multiple contractor experts with specific specializations/professional experiences to provide input); and to define focus areas to be comprehensively covered. Such focus areas may include:

a. Work/job value hierarchy (or architecture of work);

b. National salary structure(s), including geographic differentials, informed by market analysis (note: structures(s) cover all career levels and multiple cybersecurity specializations, including those associated with increasingly deep technical expertise in specific competencies and increasingly deep cybersecurity management/leadership expertise);

c. Objective, competency-focused salary setting processes using cybersecurity technical and professional/leadership competencies as well as other compensable factors;

d. Processes for managing salary progression based on performance/impact on the DHS cybersecurity mission, including through competency enhancement;

e. Cash bonuses and other recruitment and retention incentives provided based on eligibility criteria and amount/frequency limitations;

f. Relationship to market of specific aspects of the Cybersecurity Compensation System based on specific sources of data, such as particular compensation surveys; and

g. Composition and strength of total reward offering, including benefits, at all career and expertise levels, from the entry-level through the national expert or executive level.

3.2 TASK TWO. Analysis (OPTIONAL):

1. Assist with identifying, obtaining, and using a compensation data analysis platform(s)/solution(s) to compile, maintain, and report compensation data, including that obtained from or prepared for compensation surveys. If necessary, highlight potential costs, licenses, or subscriptions for review and decision by DHS, including contractor purchase through other direct costs. Effort could include identifying and using existing contactor platform(s)/solution(s) as best approach to complete work.

2. Assist with identifying, obtaining, and analyzing relevant compensation survey data. If necessary, highlight potential costs, licenses, or subscriptions for review and decision by DHS, including contractor purchase through other direct costs. Effort could include identifying and using existing contactor data sources/data gathering methods as best approach to complete work.

3. Prepare DHS compensation data to enable participation in compensation surveys. Such assistance may include - facilitating job matching, compiling and sanitizing data, and monitoring deadlines and associated project schedules.

4. At least annually, produce a comprehensive analysis of the state of the cybersecurity labor/talent market to include - trend summaries; straightforward comparisons of current

CTMS employee compensation to compensation in the market; and issues to be addressed by potential Cybersecurity Compensation System design adjustments.

5. Assist in refining current compensation cost models, including estimation factors and projections in future years, to increase accuracy and utility for DHS in estimating and planning for employee compensation under CTMS.

3.3 TASK THREE. Operation (OPTIONAL):

1. Assist with maintenance and planning associated with salary structures and recruitment and retention incentives, including cash bonuses. Specific assistance will include;

a. Supporting annual salary planning, including through analysis of projected budget for salary increases based on merit (defined in terms of performance/mission impact, including competency enhancement, under CTMS), development of merit increase matrices, management of salary progression, and interaction with review boards and calibration panels;

b. Supporting annual cash bonus planning, including through analysis of projected budget for recognition awards (based primarily on performance/mission impact, including competency enhancement, under CTMS), development of templates and tools to assist with the allocation and calculation of awards to ensure distribution based on differentiated performance/mission impact, and interaction with review boards and calibration panels;

c. Developing and maintaining compensation training and communication materials, including, guidance, tools, and templates for managers and other leadership stakeholders as well as employees to understand annual and ad hoc compensation processes and provide required input; and

d. Preparing reports on employees and groups of employees assessing competitiveness of compensation against the market and presenting data related to Cybersecurity Compensation System performance metrics defined with DHS.

2. Assist with ongoing operation of salary structures and recruitment and retention incentives, including cash bonuses. Specific assistance will include:

a. Developing and maintaining guidance, including templates, decision trees, matrices, and calculators, to support compensation decisions affecting individuals or groups of individuals;

b. Assisting with and recommending modifications to salary setting, salary adjustment, and retention and recruitment incentive request/approval processes;

c. Preparing compensation packages for review/approval;

d. Developing and maintaining compensation communication and negotiation procedures, including guidance for explaining compensation package strength to applicants, employees, hiring officials, managers, and other leadership stakeholders;

and

e. Preparing reports on employees and groups of employees assessing current compensation in relationship to any applicable laws, regulations, policies, and SOPs, including compensation limitations or caps under the Cybersecurity Compensation System.

3.4 TASK FOUR. Surge Support (Optional):

If the need arises, output associated with other Tasks would be expanded under Task Four to address unexpected increases in workload volume or complexity. The Tasks would be performed as identified above with an expectation of either more detailed or complex work products, an increase in the volume or rapidity of work product production, or both. If exercised, the support under the Task Four Optional CLIN will be expanded incrementally—and as needed, up to the ceiling level—by bringing on additional contractor staff to perform the work.”

3.5 Other Direct Costs

Other direct costs will be set as Not to Exceed $130,000 for the base year, $140,000 per each option year to include compensation surveys, compensation management software (e.g., PayFactors, Payscale, MarketPay), and Compensation Allocation tools (e.g., Curo).

4 CONTRACTOR PERSONNEL

4.1 Qualified Personnel

The Contractor shall provide qualified personnel to perform all requirements specified in this RFP. Please refer to Attachment 1 - Labor Categories and Qualifications.

4.2 Continuity of Support

The Contractor shall ensure that the contractually required level of support for this requirement is maintained at all times. The Contractor shall ensure that all contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor shall provide e-mail notification to the Contracting Officer’s Representative (COR) prior to employee absence. Otherwise, the Contractor shall provide a fully qualified replacement.

4.3 Key Personnel

Before replacing any individual designated as Key by the Government, the Contractor shall notify the Contracting Officer no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes shall possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor shall not replace Key Contractor personnel without approval from the Contracting Officer. The following Contractor personnel are designated as Key for this requirement:

1. Project Manager

2. Lead Compensation - Subject Matter Expert

3. Lead Compensation Consultant

4.4 Project Manager

The Contractor shall identify a Project Manager (PM) to provide centralized administration and management. The PM is required to correspond and meet with the DHS OCHCO Program Manager and COR as necessary. The PM is responsible for hands-on project management and coordination of day-to-day support across tasks. The PM shall also be available to participate in ad hoc meetings throughout the term of the contract.

The Contractor shall provide a Project Manager who shall be responsible for all Contractor work performed under this SOW. The PM shall be a single point of contact for the Contracting Officer and the COR. The name of the PM shall be provided to the Government as part of the Contractor's proposal. The PM is further designated as Key by the Government. During any absence of the PM, only one alternate shall have full authority to act for the Contractor on all matters relating to work performed under this contract. Any alternate(s) who shall act for the Contractor in the absence of the PM shall be as qualified as the PM. The PM and all designated alternates shall be able to read, write, speak and understand English. Additionally, the Contractor shall not replace the PM without prior approval from the Contracting Officer.

4.5 Lead Compensation Subject Matter Expert

The Contractor shall identify a Lead Compensation Subject Matter Expert (SME) to provide centralized strategic vision and technical leadership across all Tasks. The Lead Compensation SME shall provide significant technical experience, including thought leadership. The Lead Compensation SME must have experience designing compensation programs for IT/cybersecurity professionals as well as a strong understanding of the current leading compensation practices for cybersecurity professionals. The name of the Lead Compensation SME shall be provided to the Government as part of the Contractor's proposal.

4.6 Lead Compensation Consultant

The Contractor shall identify a Lead Compensation Consultant to provide day-to-day compensation analysis and input across Tasks, as well as collaborating with DHS to address to ad hoc requests and challenges. The Lead Compensation Consultant shall have in-depth client experience, preferably with organizations focused on IT/cybersecurity. The Lead Compensation Consultant shall possess strong technical compensation skills and project management skills.

Additionally, the Lead Compensation Consultant should be an expert in market-based pay/compensation and have a strong understanding of cybersecurity roles and the labor market for cybersecurity professionals. The name of the Lead Compensation Consultant shall be provided to the Government as part of the Contractor's proposal.

4.7 Replacement of Key Personnel

Before replacing any individual designated as Key by the Government, the Contractor must notify the Contracting Officer no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes must possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor must not replace Key Contractor personnel without approval by the Contracting Officer.

4.8 Key Personnel Availability

All Key Personnel shall be available to the COR via telephone between the hours of 8:00 a.m.

and 5:00 p.m. ET, Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 2 hours of notification.

The Project Manager shall be available to engage in on-site ad hoc meetings as required with a 24-hour notification within the Washington D.C. Metro area.

4.9 Employee Identification

Contractor Employees Visiting Government Facilities Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not apparent and display all identification and visitor badges in plain view above the waist at all times.

Contractor Employees Working On-Site at Government Facilities Contractor employees working on-site at Government facilities shall wear a Government issued identification badge. All Contractor employees shall identify themselves as Contractors when their status is not apparent (in meetings, when answering Government telephones, in e-mail messages, etc.) and display the Government issued badge in plain view above the waist at all times.

4.10 Employee Conduct

Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Project Manager shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.

4.11 Removing Employees for Misconduct or Security Reasons

The Government may, at its sole discretion (via the Contracting Officer), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons.

Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.

5 OTHER APPLICABLE CONDITIONS

5.1 General Report Requirements

The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations (Windows 7 and Microsoft Office 2010 Applications).

5.2 Protection of Information

Contractor access to information protected under the Privacy Act is required under this RFP.

Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation.

Review and certify understanding of provided DHS policies and guidelines governing the handling of sensitive information, including personally identifiable information (PII), ethical conduct, use and communication of DHS branded materials, and proper identification of relationship to DHS in applicant and stakeholder interactions.

5.3 Data Stored/Processed at Contractor Site

Unless otherwise directed by DHS, any storage of data must be contained within the resources allocated by the Contractor to support DHS and may not be shared with other commercial or government clients.

The Contractor remote access connection to DHS networks may be terminated for unauthorized use, at the sole discretion of DHS.

5.4 Sensitive But Unclassified (SBU) Data Privacy and Protection

The Contractor must satisfy requirements to work with and safeguard Sensitive Security Information (SSI), and Personally Identifiable Information (PII). All support personnel must understand and rigorously follow DHS and DHS requirements, policies, and procedures for safeguarding SSI and PII. Contractor personnel will be required to complete online training for SSI and Informational Security, which take one hour each, as well as DHS online Privacy training. Failure by the Contractor to comply with these requirements may result in termination of this agreement.

The Contractor shall be responsible for the security and prevention of data breaches of: i) all data that is generated by the contractor on behalf of the DHS, ii) DHS data transmitted by the contractor, and iii) DHS data otherwise stored or processed by the contractor regardless of who owns or controls the underlying systems while that data is under the contractor’s control.

The Contractor shall maintain data control according to the DHS security level of the data. Data separation shall include the use of discretionary access control methods, VPN encryption methods, data aggregation controls, data tagging, media marking, backup actions, and data disaster planning and recovery. Contractors handling PII must comply with DHS MD 3700.4, Handling Sensitive Personally Identifiable Information (current version).

Users of DHS IT assets shall adhere to all system security requirements to ensure the confidentiality, integrity, availability, and non-repudiation of information under their control. All users accessing DHS IT assets are expected to actively apply the practices specified in the DHS Information Technology Security Policy (ITSP) Handbook and applicable IT Security Technical Standards.

The Contractor shall comply with all data disposition requirements stated in the DHS IT Security Policy Handbook, applicable Technical Standards and DHS MD 3700.4, Handling Sensitive Personally Identifiable Information.

In the event of a breach or suspected breach, the Contractor shall immediately notify the Contracting Officer and Contracting Officer’s Representative to describe the incident, identity all information that has potentially been compromised due to the breach, and corrective action being taken to mitigate the breach. See HSAR Clause Safeguarding of Sensitive Information (Mar 2015) for notification timelines and additional requirements. Failure by the Contractor to comply with these requirements may result in termination for cause of this agreement in accordance with FAR 52.212-4(m).

5.5 Disposition of Government Resources

At the expiration of the Award, the contractor shall deliver to the government to the following:

a. All DHS information provided to or collected by the contractor along with detailed descriptor information (i.e. document catalogue, data dictionary, etc.)

b. IT resources provided to the contractor during the Award

c. Certification that all assets that contained or were used to process DHS information have been sanitized in accordance with the DHS MD 1400.3, DHS IT Security Policy Handbook and Technical Standards. Proof of sanitization shall be emailed to the COR

d. Master asset inventory list that reflects all assets, government furnished equipment (GFE) or non-GFE that were used to process DHS information.

5.6 Access to Unclassified Facilities, IT Resources, and Sensitive Information

The assurance of the security of unclassified facilities, Information Technology (IT) resources, and sensitive information during the acquisition process and contract performance are essential to the DHS mission. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive but Unclassified (For Official Use Only) Information https://www.dhs.gov/xlibrary/assets/foia/mgmt_directive_110421_safeguarding_sensitive_but_u nclassified_information.pdf, describes how contractors must handle sensitive but unclassified information. DHS MD 4300.1 Information Technology Systems Security and the DHS Sensitive Systems Handbook prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering contractors specifically for the award that require access to DHS facilities, IT resources or sensitive information. Contractor shall not use or redistribute any DHS information processed, stored, or transmitted by the contractor except as specified in the award.

5.7 Compliance with DHS IT Security Policy Terms and Conditions

All hardware, software, and services provided under this contract must be compliant with DHS 4300A DHS Sensitive System Policy and the DHS 4300A Sensitive Systems Handbook.

The IT solution shall meet all US Federal and DHS specific Systems and Security and Privacy requirements criteria.

5.9 PROTECTION OF INFORMATION NON-DISCLOSURE AGREEMENT

Contractor access to sensitive but unclassified information is required under this SOW. The Contractor shall ensure that all Contractor personnel having access to business or procurement sensitive information sign and submit an executed Attachment 3 – Contractor Non-Disclosure Agreement Form (DHS Form 11000-6) (3 Pages).

5.10 GOVERNMENT FURNISHED RESOURCES

The Government shall furnish the Contractor with the following for all onsite contractor personnel: enough workspace, computers, telephones, access to printers, access to photocopiers, and access to scanners.

The Contractor shall use Government furnished facilities, property, equipment and supplies only for the performance of work under this contract and shall be responsible for returning all Government furnished facilities, property, and equipment in good working condition, subject to normal wear and tear.

The Government will provide the Contractor with the available data necessary to complete the requirements of this award.

5.11 DISCLOSURE OF INFORMATION

The services required under the award constitute professional and management services, which are essential to the mission but not otherwise available within. The Government will neither supervise Contractor employees nor control the method by which the Contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual Contractor employees. It shall be the responsibility of the Contractor to manage their employees and to guard against any actions that have the nature of personal services or give the perception of personal services. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor’s further responsibility to notify the Contracting Officer immediately.

These services shall not be used to perform work of a policy/decision making or management nature. All decisions relative to programs supported by the Contractor will be the sole responsibility of the Government. Support services will not be ordered to circumvent personnel ceilings, pay limitations, or competitive employment procedures.

5.12 SECURITY

Personal Identification Verification (PIV) Credential Compliance Authorities:

• HSPD-12 “Policies for a Common Identification Standard for Federal Employees and Contractors”

• OMB M-11-11 "Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors"

• OMB M-06-16 “Acquisition of Products and Services for Implementation of HSPD-12”

• NIST FIPS 201 “Personal Identity Verification (PIV) of Federal Employees and Contractors”

• NIST SP 800-63 “Electronic Authentication Guideline”

• OMB M-10-15 “FY 2010 Reporting Instructions for the Federal Information Security

Management Act and Agency Privacy Management”

Procurements for products, systems, services, hardware, or software involving controlled facility or information system shall be PIV-enabled by accepting HSPD-12 PIV credentials as a method of identity verification and authentication.

SECTION D: PACKAGING AND MARKING

1 Packing, Packaging, Marking and Storage of Equipment

Unless otherwise specified, all items to be delivered under this contract shall be preserved, packaged, and packed in accordance with normal commercial practices to meet the packing requirements of the carrier and ensure safe delivery at destination at the most economical rate(s).

The Contractor shall use (where possible) packing materials which have the least impact on the environment when manufactured or discarded, including, brown cardboard in lieu of cardboard which has been bleached white and/or dyed, and materials which both decompose and are recyclable in lieu of recycle-only products such as plastic or Styrofoam.

All initial packing, marking and storage incidental to shipping of equipment to be provided under this contract shall be at the Contractor’s expense. The Contractor shall supervise the packing of all acquired equipment furnished by the Contractor and shall supervise the unpacking of equipment to be installed. The Contractor is fully liable for all damage, deterioration, or losses incurred during shipment and handling, unless the damage, deterioration, or losses are due to the fault of the Government.

2 Markings

As applicable, all deliverables submitted to the contract’s Contracting Officer (CO) and contract’s Contracting Officer’s Representative (COR) shall be accompanied by a packing list or other suitable shipping document that shall clearly indicate the following:

• Contract number;

• Name and address of the consignor;

• Name and address of the consignee;

• Government bill of lading number covering the shipment (if any); and

• Description of the item/material shipped, including item number, quantity, number of containers, and package number (if any).

The Contractor shall comply with the security requirements for packaging, marking, mailing, and shipping classified materials as prescribed by current Department of Homeland Security (DHS) directives.

3 Advertisements, Publicizing Awards and News Releases

Under no circumstances shall the Contractor, or anyone acting on behalf of the Contractor, refer to the supplies, services, or equipment furnished pursuant to the provisions of this contract in any publicity/news release or commercial advertising without first obtaining explicit written consent to do so from the contract’s Contracting Officer.

4 Branding

Use of Department of Homeland Security Seal:

In accordance with DHS Management Directive 123-06, 18 U.S.C. § 506, 18 U.S.C. § 701, 18 U.S.C. § 1017 and 28 U.S.C. § 1733(b), the usage of the DHS seal shall be requested by completing DHS Form 0030 (12/08).

Request shall be submitted to the Contracting Officer, who will be responsible for submitting the form for review by the DHS Office of Public Affairs.

DHS must be acknowledged in any presentation (oral or written) of work that is a direct result of contractor’s support work to DHS. Any presentation that contractor makes that relates to work conducted by or funded by or for DHS must be provided to the COR with a courtesy copy to the CO for review prior to presentation. Contractor must obtain COR or CO guidance and permission prior to development of presentation or acceptance of invitation to make presentation.

Contractor is not permitted to present DHS work or their participation in DHS work for business promotional purposes, prior to COR and CO permission.

Any questions, comments, or concerns on presentations shall be addressed to the respective COR and CO.

SECTION E: INSPECATION AND ACCEPTANCE

1 Clauses Incorporated by Reference (FAR 52.252-2) (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at www.acquisition.gov/far.

FAR Clause Title Date 52.212-4 Contract Terms and Conditions-Commercial Items (Oct 2018) (Alt I) http://www.acquisition.gov/far http://www.acquisition.gov/far

2 Inspection

(a) Inspection of all items under this contract shall be accomplished by the cognizant DHS Contracting Officer’s Representative (COR), or any other duly authorized Government representative in accordance with the applicable FAR clauses and Section C of this contract.

(b) All deliverables will be inspected for content, completeness, and accuracy and conformance to contract requirements. Inspection may include validation of information or software through the use of automated tools and/or testing of the deliverables, as specified in Section C. The scope and nature of this testing will be sufficiently comprehensive to ensure the completeness, quality and adequacy of all deliverables and services.

(c) The Government requires a period not to exceed thirty (30) business days after receipt of services and final deliverable items for inspection and acceptance or rejection unless otherwise specified in Section C. The Government shall provide written notification of acceptance or rejection of all final deliverables within 30 business days of receipt of services or deliverables. Absent written notification within 30 business days of receipt, final deliverables shall be construed as accepted. All notifications of rejection will be accompanied with an explanation of the specific deficiencies causing the rejection.

3 Acceptance

(a) Acceptance of all work and effort shall be accomplished in writing by the Contracting Officer or their duly designated representative.

(b) The basis for acceptance shall be in compliance with the requirements set forth in Section C, the terms and conditions of this contract, and other terms and conditions. Services and/or deliverable items rejected shall be corrected in accordance with the applicable clauses.

(c) Reports, documents and narrative type deliverables will be accepted when all discrepancies, errors or other deficiencies identified in writing by the government have been corrected.

(d) Non-conforming products or services will be rejected or revised as directed by the CO or COR as specified in Section C. Unless otherwise agreed by the parties, deficiencies will be corrected within ten (10) business days of the rejection notice. If the deficiencies cannot be corrected within the specified period, the Contractor will immediately notify the Contracting Officer of the reason for the delay and provide a proposed corrective action plan within ten

(10) business days.

SECTION F: DELIVERIES/PERFORMANCE

1 PERIOD OF PERFORMANCE

The period of performance for this contract is:

• One twelve-month base period of performance, and

• Four twelve-month option periods.

2 PLACES OF PERFORMANCE

The primary place of performance for this work will be Contractor facilities - including remote/virtual environments - within the United States. Some work may be completed at DHS facilities in the Washington, DC area; onsite arrangements and available hoteling space and schedules would be discussed with the Contractor at the time DHS exercised such support. If necessary, Key Personnel or should be able to attend virtual meetings within 48 hours’ notice. If necessary, Contract team personnel should be able to attend critical in-person meetings within 5 business days’ notice.

3 HOURS OF OPERATION

Contractor employees shall generally perform all work between the hours of 08:30am and 05:00pm ET, Monday through Friday (except Federal holidays). However, there may be occasions when Contractor employees shall be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this SOW.

Services will generally not be required on the following Federal holidays (or any other holidays declared by the Government); however, the Contractor may be required to provide services on these days in support of mission critical situations.

• New Year's Day - 1 January

• Martin Luther King's Birthday - Third Monday in January

• Inauguration Day – January 20 (or 21st if the 20th is a Sunday)

• Washington’s Birthday - Third Monday in February

• Memorial Day - Last Monday in May

• Independence Day - 4 July

• Labor Day - First Monday in September

• Columbus Day - Second Monday in October

• Veterans Day - 11 November (or as observed)

• Thanksgiving Day - 4th Thursday in November

• Christmas Day - 25 December

No work shall be performed by Contractor personnel on Government facilities on Federal holidays or other non-workdays without prior written approval of the COR.

4 DELIVERABLES AND DELIVERY SCHEDULE

For each deliverable, the Contractor shall, at a minimum, submit one soft copy via e-mail to the Contracting Officer and the designated Contracting Officer’s Representative (COR). All deliverables submitted in electronic format must contain read/write capability using applications that are compatible with Windows and Microsoft Office Applications.

Reference Deliverable / Event Due BY Distribution SOW 3.1 Ongoing assessments of the design and current state of the Cybersecurity Compensation System

On-going COR, Program Manager

SOW 3.2 Assist with identifying, obtaining, and using a compensation data analysis platform(s)/ solution(s) along with preparing DHS compensation data to enable participation in compensation surveys.

On-going COR, Program Manager

SOW 3.2 Identifying and using existing contactor platform(s)/ solution(s)

On-going COR, Program Manager

SOW 3.2 Assist in refining current compensation cost models, including estimation factors and projections in future years, to increase accuracy and utility for DHS in estimating and planning for

On-going COR, Program Manager employee compensation under

CTMS

SOW 3.2 Assist with identifying, obtaining, and analyzing relevant compensation survey data

On-going / At least annually

COR, Program Manager

SOW 3.2 Produce a comprehensive analysis of the state of the cybersecurity labor/talent market

Annually COR, Program Manager

SOW 3.3 Develop merit increase matrices

On-going COR, Program Manager

SOW 3.3 Develop templates and tools to assist with the allocation and calculation of awards

On-going COR, Program Manager

SOW 3.3 Develop and maintain compensation training and communication materials, including, guidance, tools, and templates

On-going COR, Program Manager

SOW 3.3 Preparing reports on competitiveness of compensation against the market

On-going / At least annually

COR, Program Manager

SOW 3.3 Developing and maintaining guidance, including templates, decision trees, matrices, and calculators

On-going COR, Program Manager

SOW 3.3 Developing and maintaining compensation communication and

On-going COR, Program negotiation procedures, including guidance for explaining compensation package strength

SOW 3.3 Preparing reports assessing current compensation in relationship to any applicable laws, regulations, policies, and SOPs, including compensation limitations or caps under the Cybersecurity Compensation System

On-going / At least annually

COR, Program Manager

SOW 3.3 Assist with and recommending modifications to salary setting, salary adjustment, and retention and recruitment incentive request/approval processes;

Preparing compensation packages for review/approval;

On-going COR, Program

4.2 Post Award

Conference

10 business days after award

CO or designated official, COR

4.3 Kick-off Meeting 15 business days after

award

COR, Program Manager

4.4 Project Management

Plan

Draft – Due at Kick-off meeting Final – Due 5 business days after draft plan approval

COR, Program

4.5 Transition-Out Plan 45 days before end of

award period of performance – at the request of the

COR/PM

COR, Program Manager

4.6 Monthly Progress

Report

10th calendar day of the month

CO or designated official, COR, Program Manager

4.7 Quarterly Progress

Meeting or Report

As requested by the COR or Program Manager

COR, Program Manager

4.8 Business Continuity

Plan

45 business days after award

COR, Contracting Officer

The COR shll also request up to two hard copies of each deliverable.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .