9531CB24Q0058 -Mortgage Rate Lock.pdf
PDF 614 KB Posted
- Attached to
- Mortgage Rate Lock Federal contract opportunity
- Solicitation number
- 9531CB24Q0058
- Issued by
- Consumer Financial Protection Bureau
About this file
This document is a Request for Quotation (RFQ) from the Consumer Financial Protection Bureau (CFPB) for a nationwide subscription to residential mortgage rate lock offering data. The CFPB's Research, Markets, and Regulations Division is seeking historical data from 2013-2023 and ongoing updates to provide a comprehensive picture of price trends in the residential mortgage market.
The data must include loan-level details such as property information, loan characteristics, pricing, and credit attributes. The CFPB also requires the ability to search mortgage pricing scenarios across originators. Proposals are due by May 27, 2022, and the initial contract period is for 36 months with two 12-month option periods. Optimal Blue is the identified vendor, and the contract will be awarded using the Lowest Priced Technically Acceptable evaluation procedure.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SSJ_Optimal Blue_Redacted.pdf | ||
| Attachment II - Pricing Table.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
9531CB24Q0058 – Mortgage Rate Lock
CONSUMER FINANCIAL PROTECTION BUREAU
WASHINGTON, DC 20552
Date: May 09, 2024
To: Optimal Blue
Subject: Request for Quotation (RFQ) No. 9531CB24Q0058, Mortgage Rate Lock
Dear Optimal Blue:
The purpose of this Request for Quotation (RFQ) is to acquire mortgage rate lock data in accordance with the requirements defined herein. In accordance with the guidelines below, CFPB requests that you provide a Quote in response to this RFQ.
This acquisition will be made using the Lowest Priced Technically Acceptable evaluation procedure.
Below is the point of contact for this RFQ:
CFPB Contracting Officer:
Michael Villano
OFFICE OF FINANCE & PROCUREMENT
CONSUMER FINANCIAL PROTECTION BUREAU (CFPB)
1700 G STREET, NW
WASHINGTON, DC 20552
E-mail Address: Michael.Villano@cfpb.gov
Questions concerning the RFQ must be submitted by e-mail to Michael.Villano@cfpb.gov no later than 12:00 p.m. Eastern Time on May 15, 2024.
All responses to this RFQ must be submitted via e-mail to Michael.Villano@cfpb.gov no later than 12:00 p.m. Eastern Time on May 27, 2022.
mailto:Michael.Villano@cfpb.gov
CFPB greatly appreciates your attention to this requirement.
Sincerely, //s//
Michael Villano Contracting Officer
Enclosures
Request for Quotation (RFQ) No. 9531CB24Q0058 Mortgage Rate Lock
TABLE OF CONTENTS
SECTION I: STATEMENT OF WORK (SOW)
SECTION II: SCHEDULE OF SERVICES AND PRICES
SECTION III: CONTRACT TERMS AND CONDITIONS AND PROVISIONS
SECTION IV: INSTRUCTIONS TO OFFERORS
ATTACHMENT I: NON-DISCLOSURE AGREEMENT
ATTACHMENT II: PRICING TEMPLATE
SECTION I:
STATEMENT OF WORK (SOW)
CONSUMER FINANCIAL PROTECTION BUREAU
Mortgage Rate Lock
1. Background
The Consumer Financial Protection Bureau (CFPB or Bureau) actively conducts research and market monitoring in support of the Bureau’s missions to protect consumers. To better assist in those efforts, the Research, Markets, and Regulations (RMR) Division seeks to subscribe to residential mortgage rate lock offering data with substantial national coverage, including capacity to search pricing offerings available under various scenarios. The Division via the Office of Research is seeking data that is also made available to other government agencies, regulators and researchers so that the CFPB could replicate and enhance the research by others to further the Bureau’s missions. These data can provide a more comprehensive picture of the price setting affecting residential mortgages and most recent market trends than what is currently available from other sources.
2. Data Format
Datasets will be made available in standard formats (e.g., csv, tab-delimited text, XML) that are natively compatible for loading into SAS Server, PostgreSQL, and MS SQL Server environments. Datasets will be made available to CFPB via common file transfer protocols (e.g., SFTP).
In addition, any Microsoft Office format (e.g., Word, PowerPoint, Excel) or PDF document deliverables to CFPB must be in an accessible format, per Section 508 Requirements.
The Contractor shall provide the tools and/or information necessary for accessing the data subscription.
3. Data Set/Data Coverage
The data subscription shall meet the below requirements and contain substantial coverage of residential mortgages in the entire US. Substantial is defined by the number of observations listed below.
- The data shall contain loan-level data on residential mortgage rate lock captured at time of initial lock request on a mortgage product pricing engine software platform that is used in the mortgage production process, meeting the minimum coverage criteria listed below.
- The historical rate lock data history should start no later than 2013. Between 2013 and 2023, the total number of observations of historical records should be no fewer than 28.5 million, with the minimum coverage criteria by year listed below:
• 2013: 1 million
• 2014: 1 million
• 2015: 1.5 million
• 2016: 2 million
• 2017: 2 million
• 2018: 2 million
• 2019: 3 million
• 2020: 6 million
• 2021: 5.5 million
• 2022: 3 million
• 2023: 1.5 million
In addition to the historical data, the rate lock data should provide daily updates that are passed through the provider’s product pricing engine software platform, reflecting the concurrent market trends and conditions. The overall coverage of the ongoing/concurrent rate lock data should be consistent with the coverage of the historical data.
In conjunction with the loan-level rate lock offering data, the CFPB is also seeking data that captures real-time search of mortgage pricing scenarios across originators nationwide that is derived from the same product price engine (scenarios pricing offering).
3.1 Timeframe
The Bureau is seeking residential rate lock data with coverage starting in 2013 and ongoing.
Specifically, for the Base Period (3 years), the Bureau requires historical data starting in 2013 through 2023, ongoing updates, and concurrent data. For each Option Year (12 months each), if exercised, the Bureau requires the historical data and ongoing updates of the concurrent data (i.e., the newest rate lock data that happen in the mortgage market).
3.2 Required Data Fields
Data fields refer to the name and label of specific data contained in the Contractor’s data set.
For the loan level rate lock offering data, the Contractor shall provide a list of all data fields contained in its data set, which must, at minimum, include the following fields:
• Time of initial lock request, captured to the second
• Geography of property, with specificity at the 5-digit zip code level
• Property detail including occupancy, property type, number of units, and purchase price or appraised value
• Loan purpose
• Loan amount
• Loan note rate
• Rate lock period
• “Buy price” attributed to the loan by the mortgage originator – before and after loan level pricing adjustments (LLPAs)
• Credit characteristics including Loan-to-Value (LTV), credit score, Debt-to- Income (DTI), and qualifying income
• Loan type, loan term, amortization type
The Bureau will not be able to intake any directly identifying and/or personally identifying information, such as residential real estate property buyer’s name, address, social security numbers, etc. The Contractor shall remove any and all such data fields at no additional cost to the Government and at the Bureau’s direction prior to actual data delivery.
For “scenario pricing offering”, the Bureau requires search scenario including, but not limited to the following:
• Metropolitan Statistical Area (MSA)
• Loan Type (Conforming, Non-Conforming, FHA, VA, USDA)
• Loan Purpose (Purchase, Cashout Refi, Rate/Term Refi)
• Loan Amount
• Property Type
• Occupancy
• Credit Score
• Loan-to-Value (LTV)
3.3 Data Quality and Documentation
At time of proposal submission, the Contractor shall provide:
o Information detailing the data collection and data compilation methodology;
o Data dictionaries describing the contents, format, and structure of the data and relationship between its elements for the data;
o Fields or values that have been constructed, estimated, edited, inferred, or otherwise built or modified shall be identified in a data dictionary or similar document;
o Information on the data collection and data compilation methodology may be sufficiently described for each field in the data dictionary; however, the Contractor may provide each document separately.
Data subscription access shall be effective on the due dates as outlined in the Deliverables table. Data shall not contain any directly identifying information, such as residential real estate property buyer’s name.
4.0 Deliverables
The following deliverables are required and shall be submitted to the Contracting Officer’s Representative (COR). The Contractor shall ensure all deliverables are clear, concise, technically accurate, well-organized, properly referenced, and complete by the appropriate due dates.
CLIN Deliverable Due Date (estimated)
0001 36-month Base Period: Residential Mortgage Rate Lock Offering data subscription, Nation-wide – includes Scenario Pricing Offering
September 30, 2024 – September 29, 2027
1001 12-month Option Period 1: Residential Mortgage Rate Lock Offering data subscription, Nation-wide -includes Scenario Pricing Offering
September 30, 2027 – September 29, 2028
2001 12-month Option Period 2: Residential Mortgage Rate Lock Offering data subscription, Nation-wide - includes Scenario Pricing Offering
September 30, 2028 – September 29, 2029
5.0 Analytical, Technical, and Administrative Support Requirements
The contractor shall provide support for users of the dataset throughout the duration of the contract. The contractor shall provide a single point of contact for technical and administrative questions (e.g., relating to the transfer of data). The contractor shall provide a single point of contact for analytical questions (e.g., relating to the interpretation of a data point). This point of contact may be the same as the technical point of contact provided that person is qualified to handle both types of issues. The contractor shall provide, at a minimum, a response time of two business days or less.
The following Government Use Rights must be provided by the Contractor at a minimum:
• Full right to publish Work Product (i.e. research; reports; and internal bureau products such as memos, internal drafts, and other work to support Bureau functions) based on these data
• No advance notice, advance review of, or permission for publication is required
• Right to reference use of the dataset in publications and other public communications using the data is provided during the time period of the contract and for a period of five years after the base period or last exercised option period, whichever is later;
• Right to archive and continue using the data for any Work Product that existed at the time of the expiration of the contract. (“Existing Work Product”), for a period of five years after the base period or last exercised option period, whichever is later. The Existing Work Product includes Work Product that, by the conclusion of the base year or last exercised option period:
Has appeared in public, including: submitted to a conference, submitted to a journal, appeared on the Bureau’s own website, published on the SSRN, including CFPB office of research working paper series OR
Had been drafted for internal memo, data report to CFPB executives, other internal CFPB publication, or entered the Bureau’s internal review process for external and internal publication
• Right to merge the data with all other datasets without affecting any CFPB usage or publication rights is provided
• “Government,” for purposes of Government Use, includes the CFPB, CFPB employees, and CFPB contractors with a business need to access the data in order to perform necessary analysis.
6.0 PERIOD OF PERFORMANCE
CLIN Period of Performance
CLIN 0001 Base Period: July 01, 2024 – June 30, 2027 (36 months)
CLIN 1001 Option Period 1: Expiration of the Base Period through 12 Months Thereafter
CLIN 2001 Option Period 2: Expiration of Option Period 1 through 12 Months Thereafter
SECTION II:
SCHEDULE OF SERVICES AND PRICES
1. Optimal Blue shall complete the attached Pricing Template (see Attachment II).
SECTION III:
CONTRACT TERMS AND CONDITIONS AND PROVISIONS
1.0 CFPB LOCAL CLAUSES
1.1 BUREAU DELIVERIES (NOVEMBER 2021)
Deliveries to the Bureau via US Postal Service, or nation-wide delivery services such as Federal Express or United Parcel Service, courier or personal delivery should be shipped to 1700 G St., NW, Washington, DC 20552.
The loading dock at 1700 G Street, NW is located on the back side of the building. Access to the loading dock is on F Street. The loading dock is restricted in size and delivery vehicles must be under 13 feet.
Deliveries must take place between the operating hours of 7:30 am and 4:30 pm local, Monday – Friday, unless otherwise approved and coordinated with a member of the Bureau’s Facilities Operations Management staff in advance of the delivery. All deliveries for the Bureau’s Technology & Innovation (T&I) division, consisting of laptops, printers, servers (or other high dollar items) may be received by CFPB personnel in Facilities but the official acceptance e.g.
verifying the contents of the shipment must be performed by a Government T&I employee. The loading dock personnel will notify the contact person when the truck arrives. All large deliveries require, at a minimum, one business day prior notification to a member of the Bureau’s Facilities Operations Management Staff. Contact by email, cfpbfacilities@cfpb.gov (preferred) or by phone, 202-435-9390.
1.2 BUREAU OFFICE OF THE INSPECTOR GENERAL (OIG) (SEPTEMBER 2018)
For the avoidance of doubt, nothing in this contract shall limit the OIG's authority under the Inspector General Act to examine the Contractor's books, documents, papers, etc.
The Contractor and any subcontractor shall make notification (including posting notices in each of their respective facilities) to all Contractor and subcontractor employees working on this contract of the OIG’s hot line telephone number, 1-800-827-3340, and to report any suspected "waste, fraud, or abuse" transactions related to the performance of this contract.
1.3 CONTRACTING OFFICER’S AUTHORITY (MARCH 2019)
The Contracting Officer for this Purchase Order is:
TBD, Contracting Officer Consumer Financial Protection Bureau Address: 1700 G St. NW, Washington, DC 20552
Email Address: TBD@cfpb.gov mailto:TBD@cfpb.gov
The Contracting Officer, in accordance with FAR Subpart 1.6, is the only person authorized to make or approve any changes in any of the requirements, and notwithstanding any clauses contained elsewhere, the said authority remains solely with the Contracting Officer. In the event the Contractor makes any changes at the direction of any person other than the Contracting Officer, the change will be considered to have been made without authority and no adjustment will be made in the terms or price to cover any increase in cost incurred as a result thereof.
1.4 CONTRACTING OFFICER’S REPRESENTATIVE (COR) DESIGNATION AND
AUTHORITY (JUNE 2019)
The Contracting Officer’s Representative (COR) is:
XXXXX XXXXXX
XXXXX.XXXXX@cfpb.gov
Performance of work must be subject to the technical direction of the COR identified, or a representative designated in writing. The term “technical direction” includes, without limitation, direction to the Contractor that directs or redirects the labor effort, shifts the work between work areas or locations, fills in details and otherwise serves to ensure that tasks outlined in the work statement are accomplished satisfactorily.
Technical direction must be within scope of the contract. Technical direction may be oral or in writing. The COR shall confirm oral direction in writing within five (5) workdays. The COR does not have authority to issue technical direction that:
• Constitutes a change of assignment or additional work outside the specification(s);
• Constitutes a change as defined in the clause entitled “Changes”;
• Causes a change to the price or time/period required for performance or delivery;
• Changes any of the terms, conditions, or requirements;
• Interferes with the Contractor’s right to perform under the terms and conditions of this Purchase Order, etc.; or
• Directs, supervises or otherwise controls the actions of the Contractor’s employees.
The Contractor shall proceed promptly with performance resulting from the technical direction issued by the COR. If, in the opinion of the Contractor, any direction of the COR, falls within the limitations noted above, the Contractor shall immediately notify the Contracting Officer.
Failure of the Contractor and the Contracting Officer to agree that technical direction is within the scope shall be subject to the terms of FAR clause 52.233-1, Disputes, hereby incorporated by reference.
mailto:XXXXX.XXXXX@cfpb.gov
1.5 CONTRACTOR POINT-OF-CONTACT (POC) (SEPTEMBER 2018)
The Contractor’s POC is identified here:
To Be Determined at Time of Award
The POC shall be responsible for the overall management and coordination of this Purchase Order and shall act as the central point of contact with the Government. The POC shall have full authority to act for the Contractor in the performance of the required supplies/services.
1.6 CONTRACTOR PERSONAL CONDUCT (OCTOBER 2023)
The Contractor shall inform its employees and its subcontractor employees of the CFPB’s Policy Prohibiting Harassment and Bullying at CFPB (and Related Enforcement Procedures). This Policy prohibits harassment and bullying (as defined therein) of any CFPB employee, applicant for employment, or contract/subcontract worker. This includes harassment or bullying perpetrated by anyone (or by any group), including by CFPB leaders, executives, managers, supervisors, and/or co-workers, as well as by Bureau contract/subcontract workers and/or external parties. A single confirmed act of prohibited harassment or bullying by any individual (or group) will violate this Policy. CFPB also prohibits related retaliation against anyone who reports harassment or bullying under the Policy or who participates in any way in an inquiry, investigation, or proceeding regarding alleged harassment or bullying at CFPB.
Accordingly, the Contractor, its employees, and its subcontractors (and subcontractor employees) shall comply with the Policy, which applies to harassment and bullying at all CFPB premises or workspaces, during official CFPB events, or otherwise facilitated by the targeted individual’s work at or for the CFPB. The Contractor/subcontractor shall take all reasonable steps necessary to inform their employees of this requirement. The Contracting Officer reserves the right to exclude or remove any employee of the contractor or of a subcontractor who has been found to have violated the Policy.
Any Contractor or subcontractor employee who has been subjected to or who has learned about or who witnesses alleged harassing or bullying conduct in connection with this CFPB contract shall immediately contact the applicable Contracting Officer’s Representative (COR). The COR will notify the responsible Contracting Officer who must in turn immediately report the allegation to the Bureau’s Office of Human Capital, at harassmentreferral@cfpb.gov. The CFPB will identify appropriate next steps which may include an investigator speaking with the complainant and or/witnesses. CFPB will also encourage contractors to report alleged harassment/bullying to their employers consistent with the employer’s internal policies.
Where the alleged perpetrator of harassment/bullying is a CFPB employee, CFPB will respond to the alleged harassment/bullying as appropriate under the Policy and/or other related and applicable CFPB policies.
If a Contractor of subcontractor employee is removed under the circumstances described in this clause, it shall not relieve the Contractor from full performance of the contract, nor will it provide the basis for an excusable delay or any claims against the government.
https://bcfp365.sharepoint.com/sites/cfpb-policies/Internal_Policies/Forms/AllItems.aspx?id=/sites/cfpb-policies/Internal_Policies/Anti-Harassment_and_Anti-Bullying.pdf&parent=/sites/cfpb-policies/Internal_Policies https://bcfp365.sharepoint.com/sites/cfpb-policies/Internal_Policies/Forms/AllItems.aspx?id=/sites/cfpb-policies/Internal_Policies/Anti-Harassment_and_Anti-Bullying.pdf&parent=/sites/cfpb-policies/Internal_Policies
1.7 CONTRACTOR PUBLICITY (SEPTEMBER 2018)
The Contractor, or any entity or representative acting on behalf of the Contractor, shall not refer to the equipment or services furnished pursuant to the provisions of this contract in any news release or commercial advertising, or in connection with any news release or commercial advertising, without first obtaining explicit written consent to do so from the Contracting Officer.
Should any reference to such equipment or services appear in any news release or commercial advertising issued by or on behalf of the Contractor without the required consent, the Government may institute all remedies available under applicable law. Further, any violation of this provision may be considered during the evaluation of past performance in future acquisitions.
1.8 COOPERATING WITH OTHER ORGANIZATIONS (SEPTEMBER 2018)
The Contractor(s) agrees to cooperate with representatives of other contractors, Federal Reserve Banks, Federal agencies, Governmental entities, and other organizations, as may be required by the Bureau, but only to the extent such cooperation does not violate the Contractor’s independence, create a conflict of interest, or materially interfere with the Contractor’s performance of services under this Purchase Order.
1.9 CYBERSECURITY/INFORMATION SECURITY (MARCH 2022)
a. The Consumer Financial Protection Bureau (CFPB) defines terms consistent with those determined by the National Institute of Standards and Technology (NIST -, https://csrc.nist.gov/glossary).
1. Per NIST, an information system can be described as the following: “a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.”
2. An information system includes any computer that contains Bureau data and performs any of the above tasks, not just systems of records.
b. The Contractor shall adhere to CFPB cybersecurity requirements for all information systems connected to a CFPB network or operated by the Contractor for, or on behalf of, the CFPB, regardless of location. In accordance with Homeland Security Presidential Directive 12 (HSPD-12), Office of the Management and Budget (OMB) Memorandum M-19-17, and the CFPB Information System Security Policy, any Contractor requiring routine physical access to a CFPB facility and/or routine access to a CFPB federally controlled information system will be required to obtain a CFPB issued Personal Identity Verification (PIV) card.
1. The Contractor shall provide its own PIV reader(s), if necessary.
2. In some situations, a PIV card may not be possible to use for CFPB information system access. If so, the Contractor shall use a CFPB authentication application on a personal or corporate mobile device.
c. The Contractor shall adhere to CFPB cybersecurity requirements for all information systems connected to a CFPB network or operated by the Contractor for, or on behalf of, the CFPB, regardless of location. This clause applies to all or any part of the contract that includes information technology, information, information resources or services for which the Contractor must have physical or electronic access to CFPB information.
d. CFPB information technology and information provided to the Contractor shall remain in the United States. The receipt, transmission, backup, accessing, maintenance, operation, and/or processing of CFPB technology and information must take place, and originate from, within the United States.
e. The Contractor shall maintain a complete and accurate inventory of all CFPB-provided data, along with complete access records. Upon request by the Contracting Officer (CO) or the Contracting Officer’s Representative (COR), the inventory and access records shall be made available for inspection.
f. Contractors serving as an agent of the Bureau or on the Bureau’s behalf, or are receiving, transmitting, storing, or processing intellectual property, records, or Bureau-provided data must use government-furnished equipment (GFE) or Citrix-based virtual desktop interface (VDI) to complete Bureau work. However, if a Contractor is creating independent content (training, documentation, etc.) that the Bureau receives, approves, and then executes; the Contracting Officer’s Representative (COR) may elect to exclude specific contractor roles from requiring GFE. The COR may elect to exclude contractor roles from GFE/VDI, if the contractor role:
1. Does not access the Bureau network or data;
2. Does not manage Bureau social media or live links;
3. Does not act as a Bureau agent or on the Bureau’s behalf;
4. Contractor role does not generate Bureau data (i.e. records, intellectual property, etc.);
5. Produces the content without the input of Bureau data; and
6. All federal decision-making happens after Bureau receipt of content.
Each exclusion must be documented by the COR, approved in writing by the Bureau Authorizing Official or designee, and revisited annually.
g. The Contractor system or facility hosting CFPB information resources must meet all applicable federal, state, and local zoning, environmental, and building laws and regulations. The system or facility must include protection against unauthorized access at all hours, including alarms and notification systems, should such protection be breached.
h. Detected or suspected security compromises to CFPB information must be reported to the CO or COR and soc@cfpb.gov within 60 minutes of discovery by the Contractor.
i. The Contractor shall grant the Government access to all facilities and information resources used in support of the contract. The CFPB shall conduct annual reviews to ensure that the security requirements in the contract are implemented, enforced, effective, and operating as intended. These reviews include, but are not limited to, comprehensive technical testing of the control environment used to safeguard CFPB information resources.
j. At the expiration of the contract, the Contractor shall return all CFPB information resources provided to, or generated by, the Contractor during the period of the contract. The Contractor shall provide certification that all CFPB information has been sanitized from any non-GFE information system in accordance with CFPB standards and procedures with advanced notification for CFPB surveillance and/or inspection of the sanitization/destruction/disposition. All equipment sanitization procedures must be environmentally sound as outlined by the U.S. Environmental Protection Agency (EPA).
k. The Contractor shall comply with the Bureau’s Asset Management Policy and is responsible for:
Using and protecting its assigned equipment in accordance with the Acceptable Use Policy and Guidance laid out in the Facilities Non-IT Asset Management Directive and IT Asset Management Directive; providing access to their assigned equipment when requested by the responsible Asset Management team; and Immediately reporting the loss or theft of IT hardware or software upon discovery to the COR, the CFPB Security Office at extension 59001 or (202) 435-9001, and to the Service Desk at extension 57777 or (202) 435-7777.
l. For the purposes of application development, the CFPB encourages and prefers the use of web-based, commercial-off-the-shelf solutions. The Contractor shall use web-based applications configured to work with multiple browser and operating system types and may not favor one browser type over another.
m. The Contractor shall adhere to all CFPB common security configurations and practices. Security configurations and practices include:
1. The provider of information technology shall certify applications are fully functional and operate as intended on systems using the United States Government Configuration Baseline and other operating system and application standards.
2. Final acceptance of the product will be based on the CFPB interpretation of the National Institute of Standards and Technology, National Checklist Program Repository (NIST, NCPR). Checklists are available at the NIST, NCPR website. In situations where security configurations are not available for proposed technologies, the CFPB shall provide instruction.
3. The installation, operation, maintenance, and update of software shall not alter any CFPB-accepted or established security configuration.
4. Applications designed for users shall run in standard user context without elevated system administrator privileges.
n. The Contractor shall notify the CO and the COR within 30 calendar days of any organizational change or impact that may interfere with the full execution of the information security requirements under the contract.
o. Throughout the term of the contract, should the Contractor deliver a product or provide a service that does not meet (and maintain) CFPB’s information security requirements, the Contractor, at their own expense, shall correct non-compliant deliverables within 90 days of notification by the CO or the COR.
p. The Contractor shall maintain a computing environment with federally-sufficient security at all times and in adherence with Bureau policy and standards. This includes, but is not limited to, the description and documentation of the processes and procedures that the Contractor shall follow to ensure the security of IT resources that are developed, processed, transmitted, used, or maintained under this contract and comprehensive technical testing of the Contractor’s computing environment by the CFPB.
q. Prior to the execution of the contract, the CFPB may require validation to ensure adequate security controls in the Contractor environment. When a validation is required, the validation will be conducted by the CFPB as part of an on-site inspection process.
r. Contractors providing services that are Federal Risk and Authorization Management Program (FedRAMP) certified shall ensure their FedRAMP packages remain current throughout the life of the contract.
s. The Contractor shall demonstrate, upon request by the CO or COR, the technical, operational, and management safeguards that protect the confidentiality, integrity, and availability of CFPB information that it develops, processes, transmits, uses, or maintains during the execution of this contract. This demonstration may include the delivery of artifacts within the scope of the FedRAMP package and independent from FedRAMP artifacts.
t. The Contractor shall ensure its computing environment complies with Federal laws that include, but are not limited to, the Federal Information Security Modernization Act of 2014 (FISMA), and with Federal policies and procedures that include, but are not limited to: NIST Special Publication (SP) 800-60, 800-63A, FIPS 200, and CFPB Information Security Standards (CS-S-01). Copies of these documents are maintained by the CFPB Office of Cybersecurity and are available upon request.
Failure to maintain compliance with applicable statutes, regulations, and guidance is a breach of the contract. The CO or COR may conduct one or more on-site inspections to ensure compliance.
1. If a Contractor is an Agent of the Bureau, or acting as on the Bureau’s behalf, all Contractors and systems shall adhere to the most current OMB Circular A-130 and NIST SP 800-53 requirements in alignment with the Bureau-established FIPS Publication 199 determination for that authorized system, data extract, or derived data.
a) All Contractors and systems shall adhere to the most current OMB Circular A- 130 and NIST SP 800-53 or 800-171 requirements in alignment with the Bureau-established FIPS Publication 199 determination for that authorized system, CFPB data extract, or derived data. Unless waived by the CFPB Authorizing Official (AO) in writing
b) Information system(s) shall have the ability to transfer audit logs to the Bureau’s centralized log collection and analysis system, Splunk by using an application programming interface (API) or a secure system log file (syslog).
c) Information system(s) shall support Security Assertion Markup Language (SAML) 2.0 or OpenID Connect (OIDC) for federated login to any web console provided by the tool, if providing a log-in capability.
d) Information system(s) shall provide a user management application programming interface or web services capability that allows for the creation, updating, disabling and deletion of accounts and permissions, if the application requires accounts.
e) The project technical team shall submit an information system security baseline in alignment with Bureau common information security standards (ISS) and the system sensitivity classifications per the Federal Information Processing Standard (FIPS) 199/200 assessments, if appropriate.
v. If not a CFPB agent or working on CFPB’s behalf, the Contractor shall adhere to applicable Federal laws, regulations, and directives as well as the most current NIST
Special Publication (SP) 800-171 requirements and other security standards and policies set by CFPB for non-federal contractor information systems that receive, transmit, process, store, or collect any form of Controlled Unclassified Information (CUI) collected for or provided by the Bureau. This is applicable to sub-contractors and Vendors who also do not serve in any capacity as Bureau agents and do not have the authority to act on the Bureau’s behalf.
w. The Contractor shall adhere to NIST SP 800-218 and Bureau-defined requirements regarding all Bureau system development life cycle (SDLC) policies, procedures, and activities, as applicable. The Contractor shall adhere to NIST Secure Software Development Framework (SSDF) and the NIST Software Supply Chain Security Guidance for developing secure software or providing third-party software to include open-source software or other application packages. Further, this includes the removal and disposal of all Bureau data from Contractor-owned and operated information systems once no longer needed to complete the contract. The Contractor shall provide all requested artifacts required to verify and attest that all Bureau data has been permanently removed once the information system is no longer required to process, store, or transmit Bureau data. These artifacts include, but are not limited to:
a. Independent 800-171A or 800-53A Risk Assessment per NIST Standards, as assigned by CFPB.
b. Signed letter or document from the Contractor showing/attesting that all bureau level data has been properly and correctly removed per 800-171 or 800-53.
c. Information Security Program documentation.
d. Screen captures, or equivalent, showing each step taken within the information system and result when permanently removing Bureau data.
e. On-site inspection or remote surveillance of the sanitization/disposal/disposition process.
x. If the Contractor does not report within 2 business days or does not adhere to the CFPB policy and standards, the Bureau may impose penalties until such time that the reporting and standards are remedied to the Bureau’s satisfaction and may have non-conformant systems or actions suspended until remediation conforms.
y. The Contractor shall adhere to CFBP blocking apps and sites on government-issued devices or contractor-operated networks/devices in support of CFPB work.
Exceptions can be made by the CFPB AO in coordination with OMB, if a compelling business need exists.
z. The Contractor shall maintain an active information security (INFOSEC) program to 800-171 or 800-53 standards with detective, preventative, and responsive elements to ensure administrative, managerial, technical, and physical controls per above. The program shall specifically address methods regarding handling and protecting CFPB information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems, to include end-user systems.
a. CFPB will review INFOSEC program documentation and may interview for clarification with the proposed Contractor to assure confidence in the Contractor’s INFOSEC program.
b. The Contractor, as deemed necessary, may use additional safeguards other than as provided for by the Contract to prevent use or disclosure of CFPB information.
aa. The Contractor shall, at its own expense, take action to mitigate any harmful effect that is known to the Contractor of a use or disclosure of CFPB information/data by the Contractor in violation of the requirements of this clause.
ab. The Contractor shall not use meta-data about CFPB’s use of the service for any purpose except for troubleshooting, technical performance monitoring, or ensuring security and functionality of the service.
ac. The CFPB Office of Cybersecurity maintains current information security requirements and standards and will provide details to the Contractor as needed after contract award. The CO or COR will notify the Contractor of any substantive changes to information security requirements that have a significant impact on the Contractor’s information security obligations under the Contract. The accountable senior executive, such as a Company Risk Executive or Chief Information Security Officer must sign acknowledgement of receipt, understanding, and compliance with all current 800-171 or 800-53 standards.
ad. The Contractor shall include the substance of this clause in all subcontracts under this Contract.
1.10 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (INVOICE
REQUIREMENTS) (JULY 2022)
a. Definition. As used in this clause, “Payment request” means a bill, voucher, invoice, or request for contract financing payment with associated supporting documentation. The payment request must comply with the requirements identified in FAR 32.905(b), "Payment documentation and process" and the applicable Payment clause included in this contract.
b. Except as provided in paragraph (c) of this clause, the Contractor shall submit payment requests electronically using the Invoice Processing Platform (IPP). Information regarding IPP is available on the Internet at ipp.gov. Assistance with enrollment can be obtained by contacting the IPP Production Helpdesk via email IPPCustomerSupport@fiscal.treasury.gov or phone
(866) 973-3131.
c. The Contractor may submit payment requests using other than IPP only when the Contracting Officer authorizes alternate payment procedures in writing.
d. If alternate payment procedures are authorized, the contractor shall include a copy of the Contracting Officer’s written authorization with each payment request.
e. Each payment request submitted shall be supported by appropriate documentation necessary to substantiate the request.
For commercial firm-fixed-price/fixed-price contracts/CLINs, payment requests shall be submitted in accordance with this local clause and FAR 52.212-4(g).
For commercial Time and Materials/Labor-Hour contracts, payment requests shall be submitted in accordance with FAR 52.212-4, Contract Terms and Conditions - Commercial Items and Alternate 1.
mailto:IPPCustomerSupport@fiscal.treasury.gov
Payment requests shall be submitted by the [10] calendar day of each month following the month of performance and shall meet the approval of the Contracting Officer Representative (COR). For payment and invoice questions, go to https://ipp.for.fiscal.treasury.gov/ or contact the Accounting Services Division at (304) 480-8000 or via email at AccountsPayable@fiscal.treasury.gov.
1.11 HOURS OF OPERATION AND COVERAGE (SEPTEMBER 2018)
The Contractor is responsible for conducting business between the hours of 8:00 a.m. to 5:00 p.m. ET Monday through Friday, except Federal holidays (listed on the Office of Personnel Management’s (OPM) website at www.opm.gov) or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. However, certain contracts do require a 24/7 on-site operation schedule. The hours of operation are specifically stated in these contracts. For other than firm-fixed-price contracts, the Contractor will not be reimbursed when the Government facility is closed for the above reasons.
The Contractor must maintain an adequate workforce for the uninterrupted performance of all tasks defined within the Statement of Objectives when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential. Under special circumstances in order to meet tight deadlines or deliverable schedules, contractors supporting other than firm-fixed-price contracts may be required to provide services outside the stated schedule, including weekends, Government observed holidays or Government directed closings. The Contracting Officer’s Representative (COR) must approve, in advance, any exceptions to services performed outside of the stated schedule.
1.12 INSPECTION OF BOOKS & RECORDS (MARCH 2019)
The Contractor agrees that the Consumer Financial Protection Bureau (CFPB) (including its authorized representative and/or its Office of Inspector General) (collectively, "CFPB") shall, until expiration of three (3) years after final payment under this contract, have access to and the right to examine any directly pertinent books, documents, papers, and records of the Contractor involving transactions related to this Contract. The Contractor further agrees to include in all its subcontracts hereunder a provision to the effect that the subcontractor agrees that CFPB shall have the same rights to the subcontractor books, documents, papers and records as specified above.
The periods of access and examination described above, for records which relate to (1) litigation or the settlement of claims arising out of the performance of this contract, or (2) costs and expenses of this contract as to which exception has been taken by CFPB, shall continue until such litigation, claims, or exceptions have been disposed of, and CFPB has specified in writing that exception is no longer being taken.
https://ipp.for.fiscal.treasury.gov/ mailto:AccountsPayable@fiscal.treasury.gov
1.13 INVOICE SCHEDULE (SEPTEMBER 2018)
The payment schedule shall be as follows:
The end of each month or as agreed upon with the COR.
1.14 LANGUAGE REQUIREMENTS (SEPTEMBER 2018)
Contractor personnel assigned to perform tasks under the Purchase Order must be able to fluently read, write, speak, and understand the English language.
1.15 NETWORK ACCESS TRAINING FOR CONTRACTORS (MARCH 2022)
Note: The solicitation and contract includes, or incorporates by reference, a copy of the “Acceptable Use of CFPB Information Technology Resources” policy (AUP). This will be provided upon award.
In accordance with Homeland Security Presidential Directive 12 (HSPD-12), Office of the Management and Budget (OMB) Memorandum M-19-17, and the CFPB Information System Security Policy, any Contractor requiring routine physical access to a CFPB facility and/or routine access to a CFPB federally controlled information system will be required to obtain a CFPB issued Personal Identity Verification (PIV) card. The Contractor shall provide its own PIV reader(s), if necessary. In some situations, a PIV card may not be possible to use for CFPB information system access. In those situations, the Contractor shall use a CFPB authentication application on a personal or corporate mobile device.
The Contractor agrees that any Contractor personnel who will have access to the Bureau’s network shall also comply with the “Acceptable Use of CFPB Information Technology Resources” Policy (AUP), prior to accessing the Bureau’s network. Once network access is permitted, the Contractor shall complete mandatory training to include, but not be limited to, the following:
Training Methodology Estimated
Duration Estimated Time
Frame
Cybersecurity Awareness Computer-based training
1 hour Within 30 calendar days of on-boarding and annually thereafter: Jan
- Mar
New Hire Privacy Training
Computer-based training
About 20 minutes
Within 30 calendar days of on-boarding.
2a
Annual Role-Based Privacy Training
Computer-based training
About 20-minutes
Mandatory annual training during Mandatory Compliance Training (MCT) cycle
Records Management Training
Computer-based training
1 hour Annually: Feb - Apr
Additional mandatory training may be required for Contractor personnel with elevated system access. The Contracting Officer’s Representative (COR) will notify the Contractor if such training is required. Additional mandatory training may include:
Training Methodology Estimated
Duration Estimated Time
Frame
Cybersecurity Role- Based Training (RBT)
Training provided by CFPB or relevant external training may count toward this requirement.
10 – 20 hours
Within 60 days of on-boarding or notification.
All training must be completed on an annual basis, unless otherwise stated above. Instructions for submitting certificates will be provided upon completion of each training module. Failure to complete mandatory training within the required time frames may result in suspending network access to a Contractor or certain Contractor staff.
The Contractor shall include the substance of this clause in all subcontracts under this Contract.
1.16 NON-DISCLOSURE (JANUARY 2022)
a. The Contractor recognizes that, in providing services under this contract, the Contractor may obtain access to or may become aware of confidential information pursuant to the Bureau’s regulations at 12 CFR Part 1070, et seq,.(including but not limited to information that may be privileged or proprietary in nature or contain Personally Identifiable Information (PII) and/or qualifies as Controlled Unclassified Information (CUI), as that term is defined under Executive Order 13556 (November 4, 2010) Without prior written approval by the Contracting Officer Representative (COR) or unless otherwise permitted by law, information acquired or prepared by the Contractor pursuant to providing services under this contract shall not be:
1. used by the Contractor for any purpose other than to perform work under the contract or;
2. disclosed by the Contractor to others outside
i. the approved Contractor personnel whether that personnel are providing services under this contract or another Bureau contract or
ii. the Government personnel serving in an oversight role or participating on a “need to know” basis.
b. The Contractor shall secure acquired or prepared information in a location with access limited to only the personnel groups previously stated or in a location that is determined by the COR to be acceptable. In accordance with the Contract Disputes Act, any unauthorized disclosure of non-public sensitive, confidential, or proprietary information, or Personally Identifiable
Information (PII) is considered a violation of a material term of this contract. Classified information will NOT be made available to the Contractor.
c. Prior to any Contractor personnel (i.e., individual personnel working for the Contractor as an employee or under a subcontract) performing services under this contract whereby such personnel will have conditional access to confidential information, and prior to any Contractor personnel participating in any discussions or receiving any confidential information specific to this contract, each such individual Contractor personnel shall sign a Non-Disclosure Agreement (NDA). [see Attachment 1] A signed NDA is required for each individual Contractor personnel meeting the criteria stated directly above. Signed NDAs are provided to the COR. If any individual Contractor personnel to be given conditional access to confidential information does not sign an NDA, the individual is not permitted to perform services, participate in discussions or receive information affiliated with this contract. The NDA covers all information relative to this contract that the Contractor may obtain access to or be made aware of, including, but not limited to, all deliverables, documents, or records.
1.17 PERIOD OF PERFORMANCE/DELIVERY REQUIRED (SEPTEMBER 2018)
Base Period: Number of Option Periods:
36 months 2 (12 months each)
1.18 PLACE OF PERFORMANCE (SEPTEMBER 2022)
Services performed under this Purchase Order shall primarily be performed at the Contractor’s site. If multiple locations are stated in the contract, the Contracting Officer’s Representative (COR) will inform the Contractor as to the correct location based on the requirement. Unless otherwise specified in the contract, the Contractor will not be reimbursed for any travel expenses.
Contractor personnel may be allowed to telecommute (on a routine or episodic basis) from a remote location only if pre-approved in writing by the Contracting officer or the COR. Approval to telecommute on a routine or episodic basis will be at the COR’s discretion based on the requirement. Before beginning to telecommute, Contractor personnel are subject to a waiting period which will be determined by the COR. If a routine telecommute day(s) is established, the COR may unilaterally incorporate a schedule adjustment that requires the work to be temporarily performed at the primary work location. The COR will provide notification of such adjustment(s) as soon as possible, but no less than by close of business the prior business day.
The COR may also request the Contractor’s PM POC to have their Contractor personnel telecommute due to a building or Government closure due to weather, natural disaster, etc. If telecommuting occurs, the Government is only responsible for providing the Contractor with a means to remotely access the Government network. The Government is not responsible for providing additional equipment, materials or facilities for work performed remotely. The Bureau will not reimburse the Contractor for any expenses incurred by Contractor personnel related to telecommuting, excluding actual time worked while telecommuting.
1.19 PROCESSING OF CONTRACTOR PERSONNEL (JANAUARY 2022)
On-boarding: In accordance with Homeland Security Presidential Directive 12 (HSPD-12), Office of the Management and Budget (OMB) Memorandum M-19-17, and the CFPB Information System Security Policy, any Contractor requiring routine physical access to a CFPB facility and/or routine access to a CFPB federally controlled information system will be required to obtain a CFPB issued Personal Identity Verification (PIV) card. The Contractor shall provide its own PIV reader(s), if necessary. In some situations, a PIV card may not be possible to use for CFPB information system access.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .