A1_-_WRBR_AFM_Scope_of_Work_-_Final_-_Revised_7-16-205.pdf
PDF 799 KB Posted
- Attached to
- WRBR AUTOMATED FEE MACHINES Federal contract opportunity
- Solicitation number
- 140P5325Q0046
About this file
This is a Statement of Work for the procurement of Automated Fee Machines (AFMs) for Wright Brothers National Memorial in Kill Devil Hills, North Carolina. The scope requires acquiring four commercial-off-the-shelf AFMs with necessary hardware, software, installation, configuration, training, technical support, system administration support, and managed services for PCI compliance. One machine will be installed inside the Visitor Center and three in the parking lot adjacent to the Visitor Center, all using cellular connectivity as primary connection with solar power for outdoor units and direct wired power for the indoor unit. The machines must accept credit cards only and be programmed for "Credit Card Only" quick-pick functionality.
Key technical requirements include PCI DSS and PA-DSS compliance, EMV chip and PIN capability, Near Field Communication (NFC) for contactless payments like Apple Pay and Google Pay, P2PE PTS 3.x payment device hardware encryption, and Section 508/ADA accessibility compliance. The contractor must provide comprehensive services including installation planning, onsite and remote training, user manuals, Service Level Agreement with minimum 8 AM-6 PM Eastern Time support Monday-Friday, hardware warranty, spare parts availability, and quarterly technical support reporting. Products to be programmed include Weekly Entrance Fee ($10 per person over 16) and Annual WRBR Pass ($35). The anticipated installation period runs from September 1, 2025 to November 30, 2025, with delivery required by November 30, 2025, followed by a base period through November 30, 2026 and four additional option years through 2030.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A5_-_Attachment_WRBR_PCI_Data_Protection_Addendum.pdf | ||
| A6_-_DOL_Wage_Determination.pdf | ||
| Sol_140P5325Q0046.pdf | ||
| A3_-_Attachment_WRBR_AFM_Section_508_GPAT_Accessibility.pdf | ||
| A4_-_Attachment_IT_and_Security_Requirements.pdf | ||
| A2_-_Price_Schedule.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work Automated Fee Machine for
Wright Brothers National Memorial (WRBR)
Version Date:
7/16/2025
*Procurement Sensitive* Page 1 of 32
The scope of this acquisition is to acquire industry-standard, Commercial-Off-The-Shelf (COTS), Automated Fee Machine(s) (AFM) hardware with the necessary software to perform, process, document, and report sales transactions; allow user role access control and product item management.
The scope includes all necessary software, hardware, configuration and installation, configuration, training, technical support, system administration support, including managed services for PCI compliance of the AFM units and warranty. These units will be installed at Wright Brothers National Memorial (WRBR) in Kill Devil Hills, NC a U.S. Department of the Interior (DOI), National Park Service (NPS) site).
The NPS considers an AFM to be a self-pay point-of-sale station. These stations are used to collect government fees at unstaffed park locations (such as but not limited to park entrances or visitor centers after business hours or in the off season), campgrounds, and day use parking lots and boat launch areas.
AFMs are programmed to accept payment for a product, print a receipt showing proof of purchase, and in some cases dispense a plastic card product (e.g., park-specific annual pass), and generate sales and transaction reports.
Products and services acquired through this procurement must be compliant with the following:
Payment Card Industry Data Security Standards (PCI DSS) and Payment Application Data Security Standards (PA-DSS), as applicable to the proposed solution; OMB Circular A-123 ("Management's Responsibility for Internal Control"); Federal Information Systems Management Act (FISMA) IT security;
Americans Disabilities Act (ADA); and Section 508 of the Rehabilitation Act requirements.
WRBR does not currently have any AFMs. This contract will provide the park with four AFMs to be used in operational locations at Visitor Center and parking areas.
The contractor must provide an AFM(s) and services which meet the requirements of this SOW.
Description of Equipment, Software, and Connectivity by Location
AFM Equipment and Software Overview
Option 1 The contractor must provide and install 4 AFMs at 4 different locations within the Wright Brothers National Memorial park: one inside the Visitors Center and 3 within the parking lot adjacent to the Visitors Center.
See Section2.2 AFM Connectivity and Programming by Location for a description of each installation location, its surrounding area, connectivity availability, and installation orientation (direction machine will be facing).
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 2 of 32
AFM Connectivity and Programming by Location
Refer to the Table below for names of the AFM installation sites and connectivity options available at the time of this procurement. See Section Error! Reference source not found. Error! Reference source no t found. and Appendix-Connectivity Description.
Some locations may have multiple connectivity options and others may have only intermittent connectivity. The contractor must outline how sites will maintain accountability and accuracy of sales transactions during connectivity disruptions.
If a wireless cellular signal is available as the Primary Connectivity or the contractor wants to propose using it if it is the secondary connectivity option, the contractor must acquire the service and manage the contract for this connectivity.
Table 1: AFM Connectivity and Programming by Location chart:
Location Name Primary Connectivity
Secondary Connectivity
Power Options Type of programming:
Quick-Pick/Pay-by-Space
Comments
Visitor Center (VC) Cellular Direct Wired Credit Card Only To be located where the old donation box was installed, near the water fountain
Outdoors, near VC parking lot
Cellular
Solar
Credit Card Only
To be located at the parking lot across from the Visitors Center/crosswalk.
Outdoors, near VC parking lot
Cellular Solar Credit Card Only To be located at the parking lot first median/crosswalk between the Visitors Center and flagpole.
Outdoors, near VC parking lot
Cellular Solar Credit Card Only To be located at the parking lot second median/crosswalk across from the flagpole.
Network Connectivity Diagram or Park Map
WRBR park map of the four (4) AFM locations
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 3 of 32
Software Licensing
Software purchased by the government is owned by the government. The contractor must identify all licensing requirements applicable to the hardware or software, including, but is not limited to the following:
• Applicable license renewal requirements and procedures.
• Number of users allowed and associated fees; user set up and registration, change process, limitations (e.g., use on all government computers or limited), etc.
• Other fees (e.g., transactional, monthly or annual fees for the use of software such as in Software-as-a-Service (SaaS) where the software is remotely hosted and accessed as a Web-based service).
• New releases and/or upgrades to software or firmware fees (include details about procedures for minor release to fix bugs and major release with new features; frequency of releases/upgrades).
Services and Deliverables Provided by Contractor
The contractor must provide services to ensure the equipment and/or software is installed and operational according to the functional and compliance requirements of this SOW. Examples of services
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 4 of 32 may include but are not limited to installation and configuration, training, operation manuals and related documents, service level agreement (SLA) and technical support, repairs and warranty terms, and system administration. In order to provide these services, the contractor must:
• Adhere to IT Security requirements; see Appendix-IT and Security Requirements.
• Maintain all payment application devices, software, and/or hardware included in the Cardholder Data Environment (CDE) and supported by this contract in accordance with the PA-DSS Implementation Guide for credit card application devices.
The contractor will not be granted DOI NPS network access to provide direct support for the installation, technical support or system administration of the solution as the machine will be using Cellular connectivity for communications and will not be placed on the NPS network. The Contractor must coordinate and support an authorized NPS employee who will perform these functions based on guidance received by the contractor. The contractor must indicate whether the NPS employee must be an IT Specialist, otherwise, the NPS will designate a non-IT NPS staff person as the point of contact.
Installation and Configuration Services
Installation Plan
The contractor must gather information from the park and provide an installation plan that includes the following considerations:
• Infrastructure, connectivity, and communications (if applicable) and power type and availability options that must be in place at the installation site prior to installation (e.g., machine pedestal, power, etc.).
• List of all peripherals and supplies required to be supplied by the park and available for the installation and to begin operations (e.g., receipt paper, surge protectors, etc.).
• Detailed network description and/or diagram of hardware, other related equipment and software with names, locations, type of connectivity and IP addresses (if applicable and known).
• Milestone dates and tasks for configuring, testing, installing, training, and implementing.
• NPS information required by the contractor for installation and staff training logistics (e.g. the following and any additional information):
o Location and positioning of the equipment to minimize environmental impacts and other obstacles that could impede successful use of the machine (e.g., glare, direct sunlight, driving rain, hail, sand, prevailing winds, etc.).
o Timing considerations for installation (e.g., during park hours, before park opens, after park closes, etc.).
o Access to NPS buildings and/or computers requiring an NPS escort or NPS staff with appropriate computer permissions (e.g. IT Specialist with administrative rights to install software).
o Travel time, road conditions/closures, seasonal traffic, etc. to/from/between installations (e.g., congestion, periods of high visitation, inclement weather, distances, etc.).
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 5 of 32 o Contact numbers for NPS staff, installation team, collection locations, main switchboard, etc.
o Communication constraints (e.g., cell phone reception).
o Training, planning, and logistics facility with adequate Internet connection, audio visual equipment support, access, size, etc.
Installation
The contractor must install the equipment and software at the locations described in Section 2.2 AFM Connectivity and Programming by Location. During installation, the AFM and its software must be configured according to Section 4.0 Credit Card Compliance, Processing, and Programming, Section 6.0 AFM Functional and Technical Equipment, and Section 8.0 Products to Program.
Upon installation, the contractor must also test data transfer and sales activity processing, and successful card authorization and settlement by completing the following:
3.1.2.1 Testing of Configuration after Installation
The contractor must configure the equipment and software, test the configuration and verify accurate sales of products, receipt generation, data transfer and sales activity processing, including transaction authorizations and settlement, prior to operation. This test must be coordinated with the park’s installation point of contact.
The contractor must perform a test in the production environment before the unit is put into operation to ensure the credit card merchant account authorization and settlement is correct.
The Contractor must coordinate with the park POC to verify that the test funds reached the proper GL Revenue Account in the NPS Accounting Operations Center (AOC) daily summary report of credit card deposits prior to live credit card sales being performed.
3.1.2.2 Install According to PA-DSS Implementation Guide
The contractor must install payment systems in accordance with the PA-DSS Implementation Guide for the payment application device and must deliver:
• The PA-DSS Implementation Guide for the credit card payment application installed in the equipment or software.
• Documentation attesting and verifying that configurations and installations have been performed according to the PA-DSS Implementation Guide.
3.1.2.3 Post Installation and Acceptance report
Within five (5) days after an installation, the contractor must provide the NPS a report detailing the following:
• An updated network diagram of the equipment and software installed by collection location name, machine names, type of connectivity, and IP addresses.
• Follow-up items to be completed by the contractor or NPS.
• Special notes, observations and/or obstacles identified during the installation.
• Training performed during the installation and remaining training to be provided.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 6 of 32
• Installation completion acceptance document for Park Contracting Officer’s Representative (COR) to sign acknowledging that the installation is complete.
Training
Onsite Training
The contractor must provide a comprehensive training session that includes a detailed agenda with objectives and outcome. There must be at least one (1) onsite training session for park end-users.
The contractor must provide the NPS with an electronic version of the training materials in Microsoft Word or PowerPoint at least one (1) week in advance of the installation and at least one (1) printed copy.
Training must cover the use and maintenance of the equipment and software to include at minimum the following topics:
• User operations: logging on/off; performing transactions, generating operational and sales reports, etc.
• Manager operations: adding and deleting authorized users, modifying products (i.e., adding products, changing prices, question prompts, editing receipt header and footer, etc.), generating reports, etc.
• Maintenance and troubleshooting guide: adding paper, clearing a paper jam, changing components, minor repairs, routine schedule of maintenance items to perform, common troubleshooting issues, etc.
• Help Desk procedures and contact information: level of service that will be provided, hours of contracted SLA, phone number(s), email, website, and shipping address.
Remote Training
In addition to the mandatory onsite training session(s), the contractor may propose to provide remote training to prepare the park for implementation or to improve operations post-implementation. The contractor must provide a conference line bridge number and web conferencing link.
Manuals and Documentation
PA-DSS Implementation Guide
The contractor must deliver its Payment Card Industry (PCI) Payment Application Data Security Standards (PA-DSSP) Implementation Guide for the delivered system’s integrated credit card payment application.
The contractor must also provide clear, detailed instructions describing park responsibilities for maintaining PCI DSS and PA-DSS compliance.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 7 of 32
User Manuals
The contractor must deliver the user manual in an electronic format and at least one (2) printed user manuals. User manuals must clearly explain all functions of the equipment and software including operations, programming products and users, maintenance, and troubleshooting.
Updated Manuals and Documentation
Within 30 days of any software or hardware update or new release, the contractor must provide the park with an updated user manual (electronic format) describing operational and technical changes. If the change is minor, a technical bulletin will be acceptable.
SLA and Technical Support
The contractor must provide technical support for the equipment and software to keep it operational with minimal down-time. The contractor must describe the technical support in writing in the form of a Service Level Agreement (SLA).
Service Level Agreement (SLA)
Items to be included in the technical support SLA:
• Support Mode: Methods by which users may access and receive assistance/service.
• Service Availability: Days and times when technical support will be available.
• Time Limit for Call Waiting: Average and maximum times that users may have to wait before speaking with a Support Representative.
• License Renewal Process: Timing and process for license renewal (if applicable).
• Access to Configurations: Methods by which contractor’s technical support team will access the park’s AFM(s) and software application to provide remote support.
• Patch Deployment Time: Verification that critical security patches will be deployed no more than one month from patch release, in accordance with PCI DSS Requirement 6.1.
• Hardware Repair: Options, availability and expected arrival time for hardware repairs, loaner parts, and spare parts to be received and operational at the park.
• Issue Resolution Time: Average and maximum times between report of a problem and resolution.
Help Desk Support Modes
The contractor must provide helpdesk support at minimum through the following modes: telephone and email.
Technical Support Days and Hours of Service
The Contractor’s proposal may include various service levels and pricing models (e.g., annual, monthly, or hourly support, 8-5 technical support vs. 24x7, etc.) along with the associated costs.
The contractor must provide technical support that meets the following minimum service level requirements:
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 8 of 32
3.4.3.1 Minimum Days and Hours of Service
The contractor must provide at minimum, unlimited remote support Monday thru Friday (excluding federal holidays), from 8:00 AM - 6:00 PM Eastern Time.
3.4.3.2 Expanded Days of Service
The contractor must provide expanded days of coverage, during the Minimum Hours of Service described above, with unlimited remote support seven (7) days per week (including holidays).
3.4.3.3 Expanded Hours of Service
The contractor must provide expanded hours of coverage with unlimited remote support from 8:00 AM-8:00 PM Eastern Time.
Urgent Technical Support Requests
The contractor must provide urgent* technical support to users according to the following minimum parameters:
• Response Time: 30 minutes for initial acknowledgement of the technical support request.
• Proposed Resolution Time: Resolution of the issue within two (2) hours, 95% of the time, unless it requires the shipment of a replacement part which must be shipped according to the contractor’s SLA.
*Urgent defined: Technical Support request conditions when one or more registers, printers, or card readers that are down at a location without an alternative or backup unit.
Normal Technical Support Requests
Contractor must resolve normal* technical support requests within the following parameters:
• Response Time: Two (2) hours for initial acknowledgement of the technical support request.
• Resolution Time: Resolution of issue within four (4) days, 95% of the time.
*Normal Technical support requests may include, but are not limited to:
• Responding to questions about usage of the system.
• Providing technical support to a NPS non-technical employee to troubleshoot and repair equipment.
• Direct database manipulation or repair.
• Modifying existing or adding new items/products.
• Upgrade of software licenses.
• Fixing or providing a workaround software bugs.
• Diagnosing and resolving communications issues between the equipment, software, and any connections like the NPS designated processing bank.
• Diagnosing and resolving credit card payment processing issues.
• Fixing reporting errors.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 9 of 32
Report of Technical Support
The contractor must deliver within ten (10) business days following the end of a quarter*, a help desk summary report for the previous quarter’s help desk activities.
The report must be formatted to print either Letter or Legal size, with title of document and date created in header, page count in “page 1 of #” format in footer. If the contractor provides the park point of contact (POC) access to an online help desk system with the required information a report submission is not necessary.
The report must include at minimum the following information:
• Date and time support, requested including hardware repairs and software upgrades.
• Short title to describe the nature of the support request.
• Name of person submitting request.
• Outstanding support requests by priority.
• Time to resolution for each support request.
• Resolutions outside of the allowable limits, per the SLA.
*Quarters defined: Qtr1-October through December; Qtr2-January thru March; Qtr3-April through June;
Qtr4-July through September.
Remote Technical Support
The contractor must provide remote technical support to a NPS employee who can perform non-technical tasks. The contractor’s technician may also access the equipment or software as long as they are compliant with the contractor access requirements described in Appendix-IT and Security Requirements.
Onsite Technical Support
If troubleshooting remotely does not resolve the hardware or software issue and the issue is not covered by the products warranty or contractors SLA, the contractor must provide an option for the government to procure onsite technical support through a contract modification, sections 3.5.2 Warranty for Hardware and Error! Reference source not found. Error! Reference source not found. ap ply to this requirement.
Hardware Repairs
Hardware Repairs
As part of the warranty, the contractor must perform remote troubleshooting of hardware supported under this SOW by guiding a NPS employee through performance of non-technical tasks with the equipment.
The contractor must describe the necessary tools for NPS employees to have on hand in order to perform the troubleshooting or repairs. If specialized tools are necessary, the contractor must provide them in a toolkit with the delivery of the AFM.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 10 of 32
If remote technical support does not resolve the problem and the problem is not covered under the warranty the park may ship, at the park’s expense, the hardware to the contractor for repair.
Prior to initiating the repair and as part of the services provided in this SOW, the contractor must provide a description of repair needed, including the costs and estimated time of the repair of any parts that are out of warranty. The parts may either be ordered through a contract modification or purchased under the micro purchase authority based on the price list included in the contracts bid schedule.
Warranty for Hardware
The contractor must provide warranty support for any hardware provided through this contract. The contractor may propose the terms and delivery method for the warranty support.
Items that must be covered in a warranty include:
• Length of Warranty.
• Point at which warranty begins.
• Warranty reporting procedures.
• Maximum time from defect report to equipment replacement or repair.
• Duration of warranty for replaced equipment.
• On-site vs. remote warranty service.
• Cost and process for extended warranties.
Return Material Authorization (RMA)
The contractor must provide a description of their Return Material Authorization (RMA) process for the repair of hardware under warranty.
Loaner Parts during Hardware Repairs
The contractor must provide an option in their SLA for the park to purchase loaner parts or equipment while the park’s part or equipment is under repair. The SLA must address how quickly the loaner parts may be expected to be available and shipped to the park.
Spare Parts
The contractor must provide a spare parts price list with the bid schedule which the park may purchase in order to make an emergency repair. The spare parts price list may be used for replacing parts during repairs of hardware that are out of warranty or to have on hand for immediate use. The spare parts price list should include individual and packages of the most common spare parts. Remanufactured parts must be indicated on the bid sheet for parts.
As part of Section 3.4.1 Service Level Agreement (SLA) and 3.5.1 Hardware Repairs, the contractor must provide remote technical support to the park POC who will install the spare part.
Destruction of Storage Devices
If any data storage device is removed from the AFM and is not reinstalled in the NPS AFM, the contractor must provide the NPS with certification that the data storage device was destroyed per guidelines in Draft NIST Special Publication 800-88 Revision 1, September 2012 or later.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 11 of 32
Managed Services (PCI)
PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.
For requirements related to PCI DSS review PCI DSS Quick Reference Guide. More information can be found at https://www.pcisecuritystandards.org/.
Managed System Administration Services
The payment device must be capable of processing Near Field Communication (NFC) transactions for contactless payments, supporting Apple Pay, Google Wallet and all other similar NFC-based payment systems before or when EMV Chip and PIN/signature processing is configured and functional. P2PE PTS 3.X Payment Device Hardware Encryption, the contractor must provide managed system administration in compliance with the PCI Data Security Standard (DSS).
Managed system administration services are defined as:
• Maintenance of firewall configuration on the deployed solution to prevent unauthorized access (DSS Requirement 1)
• Initial and ongoing configuration management and hardening of the underlying operating system (DSS Requirement 2)
• Regular updates to antivirus software (DSS Requirement 5)
• Updates and patching of operating system and critical software (DSS Requirement 6. 1)
• Logical access control, user account management, password and account lockout management and management of access control lists (DSS Requirements 7 and 8)
• Secure, remote access using two-factor authentication (DSS Requirement 8.3)
• Monitoring server security and reporting incidents (DSS Requirement 10)
• Vulnerability scanning and management – from within the network on which the equipment or software sits only (DSS Requirement 11.2)
• Host intrusion detection/prevention (DSS Requirement 11.4)
• File integrity monitoring (DSS Requirement 11.5)
Required Managed Services for Merchant PCI Compliance
The managed system administration services requirements in this solicitation will depend on the method by which the card processing payment devices or software will connect to the Internet.
The Managed Services for Merchant PCI Compliance table below shows managed services in each row;
the columns represent the various connectivity options. The contractor must perform the Managed Services based on the connectivity implemented at each location, as described in Section 2.2 Connectivity and Programming by Location, for the fields labeled as “Required by Contractor.” For example, maintenance of the firewall configuration on the network providing connectivity to the unit is required under this contract if the unit is connected via Commercial ISP but not if directly connected to the NPS Enterprise Service Network (ESN).
chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https:/listings.pcisecuritystandards.org/documents/PCIDSS_QRGv3_1.pdf https://www.pcisecuritystandards.org/
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 12 of 32
Managed Services for Merchant PCI Compliance
DSS
Requirement
P2PE
PTS 3.x
Wireless Cellular
Direct ESN VSAT
ESN
Commercia l ISP
Hardware
(L2L) VPN
Analog Only
No Connectio n
Maintenance of firewall configuration on the deployed solution to prevent unauthorized access
1 Not Applicable
Required by
Contractor
Performed by NPS
Performed by NPS
Required by
Contractor
Performed by NPS
Not Applicable
Not Applicable
Initial and ongoing configuration management and hardening of the underlying operating system
2 Not Applicable
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Not Applicable
Update of antivirus software (DSS Requirement 5)
5 Not Applicable
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Not Required
Not Applicable
Updates and patching of operating system and other critical software (DSS Requirement 6.1)
6.1 Not
Applicable
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Not Applicable
Logical access control, user account management, password and account lockout management and management of access control lists (DSS Requirements 7 and 8)
7,8 Not Applicable
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Performed by NPS
Secure remote access using two-factor authentication (DSS Requirement 8.3)
8.3 Not
Applicable
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Not Applicable
Monitoring of server security and incident reporting (DSS Requirement 10)
10 Not Applicable
Required by
Contractor
Performed by NPS
Performed by NPS
Required by
Contractor
Performed by NPS
Required by
Contractor
Not Applicable
Vulnerability scanning and management – internal only (DSS Requirement 11.2)
11.2 Not
Applicable
Required by
Contractor
Performed by NPS
Performed by NPS
Required by
Contractor
Performed by NPS
Required by
Contractor
Not Applicable
Host intrusion detection/prevention (DSS Requirement 11.4)
11.4 Not
Applicable
Required by
Contractor
Performed by NPS
Performed by NPS
Required by
Contractor
Performed by NPS
Required by
Contractor
Not Applicable
File integrity monitoring (DSS Requirement 11.5)
11.5 Not
Applicable
Required by
Contractor
Required by
Contractor
Required by
Contractor
Required by
Contractor
Performed by NPS
Required by
Contractor
Not Applicable
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 13 of 32
Validation of Managed Service Providers for Merchant PCI DSS Compliance
The contractor must achieve and maintain PCI DSS compliance for all of the managed services they are providing in accordance with the current version of PCI DSS published by the PCI Security Standards Council.
Annually, the contractor must provide validation of PCI compliance in the form of:
• A current Attestation of Compliance (AOC) that verifies compliance with the PCI DSS and,
• The executive summary from the Report on Compliance (ROC) or,
• A statement from a PCI Qualified Security Assessor (QSA) which certifies the scope of services covered by their annual assessment and states that the contractor’s AOC includes all relevant services related to their contract with the NPS.
The contractor must provide with their proposal either (a) the above documentation or (b) a statement that the contractor will provide the above documentation within three (3) months of the award of the contract.
PCI DSS Compliance for Managed Services
PCI Managed Service providers must be on the Visa Global Registry of Service Provider, see Validation of Managed Service Providers and 4.1.9 PCI Data Protection Addendum Contract for more details.
Service Providers
Service providers used to store or manage NPS credit cardholder data must be registered through the Visa Global Registry of Service Providers as a validated Level 1 Service Provider.
PCI Data Protection Addendum
Upon award of a contract for this SOW, the contractor must sign the Attachment: PCI Data Protection Addendum.
Report of Managed Services
The contractor must deliver a summary report for the previous quarter’s system administration activities within ten (10) business days of end of each quarter. This report must include all:
• System configuration changes
• Patches applied
• Vulnerabilities and the remediation performed
• Data recovery activities http://www.visa.com/splisting/index.html
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 14 of 32
3.6.8 Network Segmentation
If the equipment will be connected via the NPS ESN, the equipment’s network connection must be segmented so that other devices on the same IP network are not in scope for PCI compliance. The contractor must coordinate with the park point of contact to work with the park IT staff to achieve this requirement.
Software Restoration and Backup Services
If ordered on the contract, the contractor must perform additional services of restoring or migrating software to a new location.
If the contractor requires a park employee to assist, the contractor must notify the park what information is needed to conduct the restoration or migration. This includes specifying the park resources needed (e.g. scheduling specific time with the park employee(s) such as Park IT Specialists and identifying the time needed to complete the restoration or migration).
Software Restoration
If ordered on the contract, the contractor must restore the software after a computer/server failure.
Restoration includes but is not limited to:
• Restoring park-specific configuration files and equipment programming and,
• Restoring recoverable transactional data files, and
• Restoring equipment communications.
Migration of Software to New Location
If ordered on the contract, the contractor must move the current software and transactional data files from an existing computer or server to a new one designated by the park. This includes but is not limited to:
• Installing current versions of the applicable software to the new computer or server,
• Ensuring all transactional data files, including any archived data, has been transferred properly, and
• Ensuring communications to/from all equipment is functioning properly.
Software Configuration Back-up
The contractor must provide a current copy of the hardware and software system configuration as a back-up for restoration in case of equipment failure.
The contractor must either maintain the backup themselves or provide a written process for the park to maintain the back-up.
Notification and Scheduling
If the contractor requires a park employee to assist with any upgrade or relicensing, the contractor must schedule at least 14 calendar days in advance.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 15 of 32
The contractor must communicate to the park employee what information is needed, how much time installations or upgrades will take, and whether specialists (e.g., Park IT Specialists) are required in order to complete the upgrade or relicensing.
Upgrades to Current Versions of Software
The contractor must upgrade all equipment, payment applications, and back-office applications with the most current version of software or firmware available. The Contractor must notify the park within thirty (30) days of notification of software upgrades for any purchased equipment. Applicable upgrades must be implemented by the contractor within ninety (90) days. Available upgrades that address security vulnerabilities must be implemented by the contractor within thirty (30) days.
Credit Card Compliance, Processing, and Programming
Credit Card Compliance
Processing and Certification with Treasury-Designated Payment Processor
US Treasury regulation requires all credit card transactions collected by or on behalf of the government be deposited directly into a US Treasury NPS designated account through the Treasury’s Financial Management Services (FMS) Card Acquiring Service (CAS).
The contractor’s payment application software or device for processing credit card payments must be certified with the Treasury-designated payment processor.
Comply with FMS and Card Brand Card Processing Rules and Regulations
All card processing must follow the U.S. Treasury Financial Manual (TFM) Part 5 – Chapter 7000: Credit and Debit Card Collection Transactions and individual Card Brand Operating Regulations and Mandates.
The contractor must comply with any applicable rules and mandates in these regulations and mandates.
Accepted Card Brands
The payment application software must be able to process visitor tenders of the Treasury designated credit card brands (Visa, MasterCard, Discover, American Express, Diners Club International, JCB, and China Union Pay). The payment application devices must be able to be modified to match any changes to the credit card brand options made by Treasury.
PA-DSS Contract Requirements for Hardware/Software
The Payment Application Data Security Standards (PA-DSS) identifies the security controls with which the proposed solution must comply and ensures a payment application can be deployed in a way that will not negatively impact a merchant’s PCI DSS compliance.
The contractor must ensure that any credit card payment application version used in processing NPS cardholder data is a current, PA-DSS validated payment application.
http://fms.treas.gov/cas/index.html http://fms.treas.gov/cas/index.html https://tfx.treasury.gov/tfm/volume1/part5/chapter-7000-credit-and-debit-card-collection-transactions https://tfx.treasury.gov/tfm/volume1/part5/chapter-7000-credit-and-debit-card-collection-transactions
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 16 of 32
4.1.4.1 PA-DSS Validation Requirement
The PCI-DSS identifies the Payment Applications Data Security Standards (PA-DSS), security controls with which a payment application must comply. The contractor must ensure that any credit card payment application version used in processing NPS cardholder data is a current PA-DSS validated payment application. PA-DSS validation is specific to a payment application version number and includes a revalidation date and an expiration date.
The contractor must provide the specific name and version number of their payment application and must demonstrate that this name and version number have been validated as PA-DSS compliant.
The PA-DSS requirements are:
1. Do not retain full track data, card verification code or value (CAV2, CID, CVC2, CVV2), or PIN block data
2. Protect stored cardholder data
3. Provide secure authentication features
4. Log payment application activity
5. Develop secure payment applications
6. Protect wireless transmissions
7. Test payment applications to address vulnerabilities and maintain payment application updates
8. Facilitate secure network implementation
9. Never store cardholder data on a server connected to the internet
10. Facilitate secure remote access to payment application
11. Encrypt sensitive traffic over public networks
12. Encrypt all non-console administrative access
13. Maintain a PA DSS Implementation Guide for customers, resellers, and integrators
14. Assign PA DSS responsibilities for personnel, and maintain training programs for personnel, customers, resellers, and integrators
4.1.4.2 PA-DSS Implementation Guide Requirement
The contractor must ensure that the payment application is deployed in accordance with the instructions detailed in the PA-DSS Implementation Guide for the specific product suite and version that is associated with its PA-DSS validation.
The contractor must include the PA-DSS Implementation Guide as part of their proposal and must ensure that the document includes appropriate proprietary markings.
EMV Chip and PIN Technology
New, replacement, and upgraded credit card processing devices must be capable of supporting Europay, MasterCard and Visa (EMV) functionality.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 17 of 32
4.1.5.1 EMV Chip and Pin Compatible
The AFM must be delivered with the credit card payment devices capable of supporting EMV chip and PIN and chip and signature processing.
4.1.5.2 EMV Chip and Pin Configured and Functional
Credit card payment device must be functional for chip and PIN and chip and signature transactions. At or before delivery of this functionality, the contractor must provide proof of certification from Treasury’s designated payment processor.
At or prior to delivery, the contractor must provide instructions and operating procedures for chip and PIN and chip and signature processing in an electronic format that includes the following items: start up guide and troubleshooting guide.
Near Field Communication (NFC) Payments
The payment device must be capable of processing Near Field Communications (NFC) transactions for contactless payments, supporting Apple Pay, Google Wallet and all other similar NFC-based payment systems before or when EMV Chip and PIN/signature processing is configured and functional.
P2PE PTS 3.X Payment Device Hardware Encryption
Any payment devices that accept credit cards and communicate over an IP/SSL connection, including satellite or commercial DSL, must be compatible with the PCI PIN Transaction Security (PTS) 3.X standard and be deployed as part of a Point-to-Point Encryption (P2PE) solution supported by Vantiv.
The contractor must propose, configure, and install P2PE PTS 3.x credit card payment application device at each AFM which communicates using an IP connection.
NOTE: The contractor may propose to NOT implement this requirement and instead provide the services required under Section 3.6 System Administration (Managed Services) for the implemented connectivity.
4.1.7.1 P2PE Encryption and Processing per Transaction Fees
The contractor must include the encryption and/or transaction fees charged by the encryption provider, which may be a 3rd party gateway provider, supported by the Treasury designated bank Vantiv.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 18 of 32
Below is a monthly estimate through this contract’s period of performance:
Month Estimate # of Credit Card Transactions
January 724
February 1085
March 3115
April 4090
May 5448
June 7215
July 9057
August 6604
September 4959
October 4968
November 2740
December 1664
Yearly Total 51,669
4.1.7.2 Magnetic Credit Card Readers
If IP/SSL is used for connectivity, any magnetic strip reader (MSR) as part of the equipment solution must be PTS 3.x validated or they must be deactivated from reading the Cardholder Data Primary Account Number (PAN) and/or the Sensitive Authentication Data (SAD).
Credit Card Processing
Credit Card Authorization
The payment application solution must be able to obtain a credit card authorization and print a receipt in a pre-determined amount of time, set by the system administrator (i.e., 60 seconds for a dial-up, analog connection or 5 seconds for an IP connection). If this threshold is exceeded, the payment application must force the transaction and obtain authorization upon connection.
The AFM should allow the same credit card to be used more than once on the same day at any one machine and for the same dollar amount. This occurs when a visitor is purchasing a variety of pass or permit types that may have varying expiration dates.
If the AFM cannot be programmed to NOT allow the same credit card to be used more than once in a day, it must allow payment for multiple products as a single transaction but print separate receipts for each product/item with the relevant expiration dates. For example, a visitor pays for a campsite for 4 days and a 1-day boat permit during a single transaction. The visitor’s total would reflect the sum due for the campsite and the boat permit, but s/he would receive individual receipts for the campsite and the boat permit, showing the appropriate expiration date for each.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 19 of 32
Intermittent / Offline Store and Forward
When connectivity is intermittent or offline for an unexpected reason and communications are not available for card authorization-after a designated period of time (e.g. 15 seconds for IP and 60 seconds for dial-up connections), the payment application solution must securely (according to PCI DSS Standards) capture, process, store and forward the authorization request as soon as the network connection to the authorizing bank is reestablished.
All transactions stored in the offline mode and then rejected must be documented and included in a report to the NPS.
Cardholder Data Storage
No cardholder data may be stored in the machine, even if encrypted, after authorization or after settlement of any transaction.
Credit Card Programming
Merchant ID Account (MID)
The payment application device or software must use a Merchant ID (MID) account obtained from the US Treasury’s Fiscal Services- designated processor and its platform for each collection location.
The contractor must provide the name of the PA-DSS Validated payment application software that will be handling the credit card authorization and settlement.
Upon award for implementation, the contractor must provide any additional information necessary for the park POC to submit the application to create the MID account.
Terminal ID (TID) and Terminal Number (TIN) for MID
The contractor must program the payment application to ensure each AFM has a unique Terminal ID (TID)/TIN associated with a MID. This is required for the NPS fee collection equipment inventory purposes.
The contractor must work with the park and Treasury’s processor (Vantiv) to determine when there should be unique merchant IDs (MIDs) for multiple AFM units versus allowing multiple AFM units to share a single MID with unique TID/TINs.
The contractor is responsible for properly programming and providing a report of the payment application devices and software with the correct MID and TID/TIN.
Test Equipment and MID
Contractors, in coordination with NPS park/site and Vantiv, must conduct test transactions to ensure that the equipment is properly programmed before the equipment is operational and available to accept cards from visitors.
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 20 of 32
Cardholder Data Security on Reports
Credit cardholder data must be masked on all reports. If the PAN is included in any report, no more than the first 6 digits and the last 4 digits may be printed. The card expiration date and CVV number must never print. The contractor must handle and process cardholder data per PCI DSS standards as well as any requirements of the Fair and Accurate Credit Transactions Act (FACTA).
Federal and IT Compliance Requirements
Federal IT Security and Network Access
Protecting the NPS network and the visitor information is a high priority and compliance with all relevant security policies is essential. The contractor must agree to adhere to all relevant security standards.
Any user accessing the NPS ESN through the software VPN must have and use current NPS active directory credentials and a Personal Identity Verification (PIV) card (“smart card”). If the contractor requires access to the DOI/NPS network to support the equipment or software, refer to the procedures and requirements in Appendix: IT and Security Requirements.
Section 508 of the Rehabilitation Act
In 1998, Congress amended the Rehabilitation Act of 1973 to require Federal agencies to make their electronic and information technology (EIT) accessible to people with disabilities. Inaccessible technology interferes with an ability to obtain and use information quickly and easily. Section 508 was enacted to eliminate barriers in information technology, open new opportunities for people with disabilities, and encourage development of technologies that will help achieve these goals. The law applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology. All EIT procured under this RFP, including [EQUIPMENT] units and software applications, must comply with the requirements of Section 508. Additional information about Section 508 compliance can be found at http://www.section508.gov.
The contractor must complete Attachment– AFM Section 508 Accessibility Requirements for the applicable requirements. The contractor must indicate the compliance of the proposed solution as:
Fully, Partially, Not, or Don’t Know.
Americans Disabilities Act (ADA) Accessibility
The physical AFM must comply with the Americans Disabilities Act (ADA) accessibility requirements applicable to their design, user options and interfaces.
• All AFMs must be no more than 48 inches above ground to ensure customer operated controls are accessible.
More information on accessibility can be found at :
ADA Accessibility Guidelines for Self-Service Transaction Machines & Self-Service Kiosks and https://www.access-board.gov/ada/ http://www.section508.gov/ https://www.federalregister.gov/documents/2022/09/21/2022-20470/americans-with-disabilities-act-accessibility-guidelines-for-buildings-and-facilities-architectural https://www.access-board.gov/ada/
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 21 of 32
AFM Functional and Technical Equipment
Following are the functional requirements section defines the requirements that the AFM units must meet.
AFM Unit Basic Functional Requirements
The NPS uses terminology developed by the parking industry to describe choices or options available through an AFM. Two program options used by the NPS: “Quick-Pick” and “Pay-by-Space.” Refer to 2.2 AFM Connectivity and Programming by Location for the programming type for each machine.
Whichever program is selected, they must both meet the following basic requirements:
Ease of Transaction Processing
The AFM must have a user-friendly interface to prompt the customer through the purchase process in a clear and timely manner (e.g., payment and tender options, instructions for exchanging the AFM receipt for the appropriate product (entrance pass, camping permit, etc.), other information as necessary.
Menu prompts should be simple, instructions clear, and ease of use intuitive.
Product Pricing
The AFM programming must be flexible to allow sales of multiple products at varying prices. Park staff with the appropriate user rights must have the ability to change pricing for each product. See Section 8.0 Products to Program for a draft of product pricing. The contractor must review and confirm the product pricing with the designated park POC.
Applying a Discount to a Product
There should be no configuration for a discount function.
Multiply Price Charged by Quantity Entered
The AFM program must be configured to multiply the product by a quantity input by the visitor and then calculate the price for the total number of products and the payment due.
6.1.4.1 Apply specific questions prompts for multiplying the rate
The AFM will prompt the visitor to enter the quantity for each product being purchased based on specific question prompts (e.g., “How many camping nights are you camping?” or “How many people?”
or “How many daily entrance fee receipts?”). See section 8.0 Products to Program for the specific questions per rate.
Calculate Expiration Date & Time for Valid Thru Date
The AFM program must calculate and display the expiration date on the receipt based on the following:
• Number of days valid – the expiration date is calculated based on the number of days or months the product can be used beginning with the sale date and the appropriate validity
Wright Brothers National Memorial (WRBR)
*Procurement Sensitive* Page 22 of 32 period for the specific pass. (i.e., Daily passes expire at sundown on the date sold; Weekly pass is valid for up to 7 days including the date of purchase; Annual passes expire the end of the twelfth month of the month it was purchased).
• Rate Multiplier: the expiration date is calculated based on the quantity days the visitor chooses to purchase (i.e., camping nights x number of days up to the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .