HHSAR Class Deviation 2025-01 Provision and Clause_word version.docx
DOCX document 60 KB Posted
- Attached to
- NonSurgical Debridement Federal contract opportunity
- Solicitation number
- 75A50125R00007
About this file
This document is a HHSAR Class Deviation provision and clause related to Supply Chain Risk Assessment for the Department of Health and Human Services (HHS). The provision (352.204-74) and clause (352.204-75) require offerors and contractors to provide detailed information about their supply chain, foreign ownership, business affiliations, company leadership, and potential risks during both the proposal and contract performance stages.
The documents mandate comprehensive disclosure across multiple dimensions, including foreign ownership percentages, business relationships with foreign entities, company leadership's international ties, export control violations, prohibitions on doing business, affiliations with restricted entities, suspension/debarment history, bankruptcy, and litigation. The supply chain risk assessment will be conducted by HHS's Office of National Security (ONS), and findings may impact an offeror's responsibility, eligibility for award, and continued contract performance. Contractors must also include similar provisions in subcontracts involving mission-critical products or services, with the government reserving the right to implement mitigation plans based on the assessment results.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 75A50125R00007 Amendment 0001.pdf | ||
| 75A50125R00007 Amendment 0002.pdf | ||
| 75A50125R00007 Amendment 0001.pdf | ||
| 75A50125R00007.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
HHSAR Class Deviation 2025-01 SCRA Provision and Clause – Word Version 352.204-74 Supply Chain Risk Assessment (DEVIATION) As prescribed 304.7304(a) insert the following provision:
Supply Chain Risk Assessment (OCT 2024) (DEVIATION)
(a) Definitions. As used in this provision— Contract means as defined in FAR 2.101.
Foreign person means as defined in 31 CFR 800.224.
Mission-critical acquisition means the acquisition of products, materials, information, or services that are identified as—
(1) Contract support or development services for HHS or OpDiv/StaffDiv research and development;
(2) Contract support or development services for HHS or OpDiv/StaffDiv financial databases and services;
(3) Contract support services that require utilization or sharing of HHS or OpDiv/StaffDiv Intellectual property;
(4) Contract services supporting HHS or OpDiv/StaffDiv continuity of operations (COOP) mission essential functions;
(5) Contract support services or development initiatives for HHS or OpDiv/StaffDiv critical infrastructure;
(6) An HHS or OpDiv/StaffDiv high-value/dollar acquisition; or
(7) Other acquisitions for critical assets or services as identified by OpDiv/StaffDiv leadership.
Office of National Security (ONS) means the HHS office responsible for the management, oversight, policy, guidance, and implementation of the HHS Enterprise Supply Chain Risk Management (E-SCRM) Program, including the conducting of supply chain risk assessments.
State-owned enterprise means a legal entity that is created by a government in order to partake in commercial activities on the government's behalf. A state-owned enterprise or government-owned enterprise is a business enterprise where the government or state has significant control through full, majority, or significant minority ownership.
Supply chain risk means the potential for harm or compromise that arises as a result of security risks from suppliers, their supply chains, and their products, materials, information, or services. Supply chain risks include exposures, threats, and vulnerabilities associated with the products and services traversing the supply chain as well as the exposures, threats, and vulnerabilities to the supply chain.
Supply chain risk assessment means a systematic examination of supply chain risks, likelihoods of their occurrence, and potential impacts.
Supply chain risk management (SCRM) means a systematic process for managing risk to the integrity, trustworthiness, and authenticity of products, materials, information, and services within the supply chain. It addresses the activities of foreign and other adversaries aimed at compromising the supply chain, which may include the introduction of counterfeit or malicious items into the supply chain. It is conducted through identification of threats, vulnerabilities, and consequences throughout the supply chain and development of mitigation strategies to address the respective risks presented by the supplier, the supplied products, materials, information, and services, or the supply chain at any point during the life cycle.
(b) Supply chain risk assessment. The Office of National Security (ONS) or delegated designee may perform a supply chain risk assessment of the Offeror’s proposal. In performing the supply chain risk assessment, the Government may consider public and non-public information relating to the Offeror’s supply chain.
(c) Required information submittal. The Offeror shall provide the following information for products, materials, information, or services provided under their proposal:
(1) Description of the type of products, materials, information, or services provided.
(2) Vendor and manufacturer’s company, if applicable, including name and address.
(3) If known, vendor’s and manufacturer’s web site, and the Commercial and Government Entity (CAGE) code and Unique Entity Identifier (UEI).
(d) Representations. The Offeror represents that—
(1) It [ ] does, [ ] does not have any foreign ownership, outside of retail shareholders, who control more than 10% of the company’s total shares. If yes, identify the legal name of the owning organization/individual and their country of affiliation.
(2) It [ ] does, [ ] does not have any of the following business affiliations with foreign entities: technology development partnerships, strategic partnerships, joint ventures, foreign subsidiaries, grants from a foreign entity. If yes, identify the legal name of the organization, its foreign address, and the nature of the relationship.
(3) It [ ] does, [ ] does not have any foreign governments, or state-owned enterprises that have investments or ownership interest in the company. If yes, identify the foreign government, the ownership stake percentage, and the nature of the relationship.
(4) The company leadership (C-Suite executives, Board members, etc.) [ ] does, [ ] does not have any substantial ties to foreign countries, including being citizens of a foreign country, graduates of a foreign university, or investments in a foreign country. If yes, identify the individual, the nature of the tie, and the country they are tied to.
(5) It [ ] has, [ ] has not violated export controls or the Foreign Corrupt Practices Act within 5 years. If yes, enter the event, the date, and any remediation the company committed after the event.
(6) It [ ] has, [ ] has not been prohibited from doing business with the government of the US or any of its administrative subdivisions to include agencies, states, territories or municipalities. If yes, enter the event, the date, and any remediation the company committed after the event.
(7) It [ ] has, [ ] has not been prohibited from doing business with any foreign governments or subdivisions thereof. If yes, enter the event, the date, and any remediation the company committed after the event.
(8) It [ ] has had, [ ] has not had affiliations with any entities prohibited (e.g. Huawei, see SAM.gov “exclusions” page for additional information regarding prohibited entities) from doing business with the government of the US or any of its administrative subdivisions to include agencies, states, territories or municipalities? If yes, enter the event, the date, and any remediation the company committed after the event.
(9) It [ ] has, [ ] has not been suspended or debarred at any point while doing business with the U.S. Government or any of its administrative subdivisions to include agencies, states, territories or municipalities. If yes, enter the event, the date, and details below.
(10) It [ ] has previously filed for or is currently in, [ ] has not previously filed for or is not currently in bankruptcy in the last 10 years. If yes, enter the event, the date, and details below.
(11) It [ ] was or is currently in, [ ] was not or is not currently in litigation in the last 10 years. If yes, enter the event, the date, and details below.
(e) Supply chain risk determination. Findings from the supply chain risk assessment will be considered in connection with a determination of the Offeror’s responsibility and eligibility for award. Failure of the Offeror to furnish the information required in this provision or provide additional information as requested by the Contracting Officer may render the Offeror non-responsible and ineligible for award. The Government reserves the right to limit the disclosure of information to the Offeror regarding the risk in accordance with all applicable laws or regulations.
(f) Mitigation plans. Any mitigation plans and amendments determined necessary and to be implemented and sustained during contract performance will be incorporated into the contract.
(g) Subcontracts. The Offeror shall include the substance of this provision, including the information and representations at paragraphs (c) and (d), and including this paragraph (g), in subcontracts with persons or entities proposed to be used involving the development or delivery of any mission-critical products, materials, information, or services. The Offeror shall submit all potential subcontractor information and representations with its proposal for any mission-critical products, materials, information, or services provided for in the proposal.
(End of provision)
352.204-75 Supply Chain Risk Assessment During Contract Performance (DEVIATION) As prescribed in 304.7304(b) insert the following clause:
Supply Chain Risk Assessment During Contract Performance (OCT 2024) (DEVIATION)
(a) Definitions. As used in this clause— Contract means as defined in FAR 2.101.
Foreign person means as defined in 31 CFR 800.224.
Mission-critical acquisition means the acquisition of products, materials, information, or services that are identified as—
(1) Contract support or development services for HHS or OpDiv/StaffDiv research and development;
(2) Contract support or development services for HHS or OpDiv/StaffDiv Financial databases and services;
(3) Contract support services that require utilization or sharing of HHS or OpDiv/StaffDiv Intellectual property;
(4) Contract services supporting HHS or OpDiv/StaffDiv continuity of operations (COOP) mission essential functions;
(5) Contract support services or development initiatives for HHS or OpDiv/StaffDiv critical infrastructure;
(6) An HHS or OpDiv/StaffDiv high-value/dollar acquisition; or
(7) Other acquisitions for critical assets or services as identified by OpDiv/StaffDiv leadership.
Office of National Security (ONS) means the HHS office responsible for the management, oversight, policy, guidance, and implementation of the HHS Enterprise Supply Chain Risk Management (E-SCRM) Program, including the conducting of supply chain risk assessments.
State-owned enterprise means a legal entity that is created by a government in order to partake in commercial activities on the government's behalf. A state-owned enterprise or government-owned enterprise is a business enterprise where the government or state has significant control through full, majority, or significant minority ownership.
Supply chain risk means the potential for harm or compromise that arises as a result of security risks from suppliers, their supply chains, and their products, materials, information, or services. Supply chain risks include exposures, threats, and vulnerabilities associated with the products and services traversing the supply chain as well as the exposures, threats, and vulnerabilities to the supply chain.
Supply chain risk assessment means a systematic examination of supply chain risks, likelihoods of their occurrence, and potential impacts.
Supply chain risk management (SCRM) means a systematic process for managing risk to the integrity, trustworthiness, and authenticity of products, materials, information, and services within the supply chain. It addresses the activities of foreign and other adversaries aimed at compromising the supply chain, which may include the introduction of counterfeit or malicious items into the supply chain. It is conducted through identification of threats, vulnerabilities, and consequences throughout the supply chain and development of mitigation strategies to address the respective risks presented by the supplier, the supplied products, materials, information, and services, or the supply chain at any point during the life cycle.
(b) Supply chain risk assessment. The Office of National Security (ONS) or delegated designee may perform a supply chain risk assessment of the Contractor. In performing the supply chain risk assessment, the Government may consider public and non-public information relating to the Contractor’s supply chain.
(c) Updated information and representations. If requested by the Contracting Officer, or if there are any changes to the information or representations the Contractor has submitted prior to award or during contract performance, the Contractor must submit to the Contracting Officer the information and representations in paragraphs (d) or (e).
(d) Required information submittal. The Contractor shall provide the following information for products, materials, information, or services provided during contract performance:
(1) Description of the type of products, materials, information, or services provided.
(2) Vendor and manufacturer’s company, if applicable, including name and address.
(3) If known, vendor’s and manufacturer’s web site, and the Commercial and Government Entity (CAGE) code and Unique Entity Identifier (UEI).
(e) Representations. The Contractor represents that—
(1) It [ ] does, [ ] does not have any foreign ownership, outside of retail shareholders, who control more than 10% of the company’s total shares. If yes, identify the legal name of the owning organization/individual and their country of affiliation.
(2) It [ ] does, [ ] does not have any of the following business affiliations with foreign entities: technology development partnerships, strategic partnerships, joint ventures, foreign subsidiaries, grants from a foreign entity. If yes, identify the legal name of the organization, its foreign address, and the nature of the relationship.
(3) It [ ] does, [ ] does not have any foreign governments, or state-owned enterprises that have investments or ownership interest in the company. If yes, identify the foreign government, the ownership stake percentage, and the nature of the relationship.
(4) The company leadership (C-Suite executives, Board members, etc.) [ ] does, [ ] does not have any substantial ties to foreign countries, including being citizens of a foreign country, graduates of a foreign university, or investments in a foreign country. If yes, identify the individual, the nature of the tie, and the country they are tied to.
(5) It [ ] has, [ ] has not violated export controls or the Foreign Corrupt Practices Act within 5 years. If yes, enter the event, the date, and any remediation the company committed after the event.
(6) It [ ] has, [ ] has not been prohibited from doing business with the government of the US or any of its administrative subdivisions to include agencies, states, territories or municipalities. If yes, enter the event, the date, and any remediation the company committed after the event.
(7) It [ ] has, [ ] has not been prohibited from doing business with any foreign governments or subdivisions thereof. If yes, enter the event, the date, and any remediation the company committed after the event.
(8) It [ ] has had, [ ] has not had affiliations with any entities prohibited (e.g. Huawei, see SAM.gov “exclusions” page for additional information regarding prohibited entities) from doing business with the government of the US or any of its administrative subdivisions to include agencies, states, territories or municipalities? If yes, enter the event, the date, and any remediation the company committed after the event.
(9) It [ ] has, [ ] has not been suspended or debarred at any point while doing business with the U.S. Government or any of its administrative subdivisions to include agencies, states, territories or municipalities. If yes, enter the event, the date, and details below.
(10) It [ ] has previously filed for or is currently in, [ ] has not previously filed for or is not currently in bankruptcy in the last 10 years. If yes, enter the event, the date, and details below.
(11) It [ ] was or is currently in, [ ] was not or is not currently in litigation in the last 10 years. If yes, enter the event, the date, and details below.
(f) Supply chain risk determination. Findings from the supply chain risk assessment will be considered in connection with a determination of the Contractor’s eligibility to continue performance on the contract. The Government reserves the right to limit the disclosure of information to the Offeror regarding the risk in accordance with all applicable laws or regulations.
(g) Mitigation plans. Any mitigation plans and amendments determined necessary and to be implemented and sustained during contract performance will be incorporated into the contract.
(h) Subcontracts. The Contractor shall include the substance of this clause, including the information and representations in paragraphs (d) and (e), and this paragraph (h), in subcontracts with persons or entities involved the development or delivery of any mission-critical products, materials, information, or services. The Contractor shall submit all subcontractor information and representations with its proposal for any additional mission-critical products, materials, information, or services during performance of the contract.
(End of clause)
File details come from the government source that posted it. Updated .