About this file

This is a Request for Quotation (RFQ) for annual maintenance and subscription services for Itasca numerical modeling software.

The Centers for Disease Control and Prevention's Pittsburgh Mining Research Division seeks 12 months of maintenance and subscription support for three software products: two licenses of 3DEC, one license of FLAC3D, and one license of Griddle. The contract period runs from September 17, 2026, through September 16, 2027. The work will be performed at the contractor's facility, with the contractor providing uninterrupted software access, version upgrades, security patches, remote technical support during standard business hours (Monday-Friday, 8:00 AM to 5:00 PM Eastern Time), and license activation/renewal capabilities. Deliverables include annual software subscription activation via email within 5 business days of award, version updates and release notes as released, and technical support responses provided as needed. The contractor must be the original developer or authorized distributor of ITASCA modeling software and must provide 12-month maintenance coverage for four perpetual Government-owned licenses with specific serial numbers. Quotations are due by September 14, 2026, at 12:00 PM EST and should be submitted electronically in PDF format to Contract Specialist Alyssa Thomas at ah78@cdc.gov. The Government has identified Itasca Consulting Group, Inc. as the intended sole source but will consider quotations from other responsible sources demonstrating capability. Award will be made on a firm-fixed-price basis to the responsible quoter whose quotation conforms to requirements and whose price is determined fair and reasonable. The quotation must remain valid for 30 calendar days after the due date.

View the file

Other files for this federal contract opportunity

Other files attached to Annual Maintenance and Subscription for Itasca Numerical Modeling Software (3DEC, FLAC3D, and Griddle), newest first.
File Type Posted
A19 Attachment 1 AI Use Compliance and Risk Management Plan.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

11. DELIVERY FOR FOB

DESTINATION UNLESS

BLOCK IS MARKED

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

1. REQUISITION NUMBER

PAGE 1 OF

2. CONTRACT NO.

3. AWARD/EFFECTIVE

DATE

4. ORDER NUMBER

5. SOLICITATION NUMBER

75D301-26-Q-79230

6. SOLICITATION

ISSUE DATE

09/09/2026

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME Alyssa Thomas

b. TELEPHONE NUMBER (No collect calls)

(770) 488-2633

8. OFFER DUE DATE/

LOCAL TIME

09/14/2026

9. ISSUED BY CODE 8219 10. THIS ACQUISITION IS 12. DISCOUNT TERMS

Centers for Disease Control and Prevention Chamblee Campus Building 102, MS S102-4 4770 Buford Hwy Atlanta, GA 30341-3717

UNRESTRICTED

SET ASIDE: % FOR

SMALL BUSINESS

SMALL DISADV. BUSINESS

8(A)

NAICS: 513210

SIZE STANDARD: $47,000,000

X SEE SCHEDULE

13a. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

X RFQ IFB RFP

15. DELIVER TO CODE 993 16. ADMINISTERED BY CODE

NIOSH - PITTSBURGH

626 COCHRANS MILL RD

BLDG 166 RECEIVING

PITTSBURGH, PA 15236-3611

CODE CGF2AVBARZW7 18a. PAYMENT WILL BE MADE BY CODE 434

ITASCA CONSULTING GROUP INC

111 3RD AVE S

MINNEAPOLIS, MN 55401-

Centers for Disease Control and Prevention (FMO) PO Box 15580 404-718-8100

Atlanta, GA 30333-0080

TELEPHONE NO.

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW

SEE ADDENDUM

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

“See Continuation Page”

(Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

28.

CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN COPIES

TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET

FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT

TO THE TERMS AND CONDITIONS SPECIFIED HEREIN.

29.

AWARD OF CONTRACT: REFERENCE OFFER

DATED . YOUR OFFER ON SOLICITATION (BLOCK 5),

INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH

HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (Signature of Contracting Officer)

30b. NAME AND TITLE OF SIGNER (Type or print)

30c. DATE SIGNED

31b. NAME OF CONTRACTING OFFICER (Type or print)

31c. DATE SIGNED

32a. QUANTITY IN COLUMN 21 HAS BEEN 33. SHIP NUMBER 34. VOUCHER NUMBER

RECEIVED INSPECTED

PARTIAL FINAL

36. PAYMENT 37. CHECK NUMBER

32b. SIGNATURE OF AUTHORIZED GOV’T REPRESENTATIVE 32c. DATE COMPLETE PARTIAL FINAL

41a. I CERTIFY THIS AMOUNT IS CORRECT AND PROPER FOR PAYMENT 41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC’D 42d. TOTAL CONTAINERS

40. PAID BY

AUTHORIZED FOR LOCAL REPRODUCTION SEE REVERSE FOR OMB CONTROL NUMBER AND PAPERWORK BURDEN STATEMENT STANDARD FORM 1449 (10-95)

ACCEPTED, AND CONFORMS TO THE

CONTRACT, EXCEPT AS NOTED

35. AMOUNT VERIFIED

CORRECT FOR

17a. CONTRACTOR/

OFFEROR

FACILITY

CODE

IS CHECKED

RFQ: 75D301-26-Q-79230

TABLE OF CONTENTS

Section Document/Clause/Provision Page No.

A Standard Form 1449 – Solicitation/Contract/Order for Commercial

Products and Commercial Services

B Supplies or Services and Prices 3 C Statement of Work / Description / Specifications 3 G Contract Administration Data 10 H Special Contract Requirements 11 I Provisions and Clauses 16 J List of Attachments 19 L Instructions, Conditions, and Notices to Quoters 19 M Evaluation Factors for Award 21

SECTION B - SUPPLIES OR SERVICES AND PRICES

Pricing Basis: Firm-Fixed-Price (FFP) Period of Performance: 12 months, anticipated September 17, 2026 through September 16, 2027; final dates will be established in the purchase order.

Place of Performance: Contractor’s facility

ITEM SUPPLIES / SERVICES QTY /

UNIT

UNIT

PRICE

EXTENDED

PRICE

0001 Maintenance Subscription for

3DEC

Maintenance Subscription for

3DEC

2 Each $_________ $___________

0002 Maintenance Subscription for

FLAC3D

Maintenance Subscription for Maintenance Subscription for

FLAC3D

1 Each $_________ $__________

0003 Griddle Annual Subscription Griddle Annual Subscription - Prepaid

1 Each $_________ $_____________

Total: $____________

SECTION C - STATEMENT OF WORK / DESCRIPTION /

SPECIFICATION

Title: Annual Maintenance and Subscription for Itasca Numerical Modeling Software (3DEC, FLAC3D, and Griddle)

Period of performance of this contract is: 09/17/26 – 09/16/27

SECTION 1 – BACKGROUND

The Pittsburgh Mining Research Division (PMRD) of Center for Disease Control/National Institue for Occupational Safety and Health conducts research to improve the safety, health, and productivity of mine workers. As part of this mission, PMRD performs advanced geomechanical and ventilation analyses involving underground coal mine layouts, panel extraction, gas-well interactions, strata weakening, and other complex subsurface behaviors.

To support these research activities, PMRD relies on the ITASCA numerical modeling suite (3DEC, FLAC3D, and Griddle). These tools provide specialized computational modeling environments used to simulate rock mass behavior, material properties, discontinuities, mine openings, ventilation pathways, and interactions with gas wells. These analyses directly support NIOSH research on roof fall prevention, pillar stability, ventilation design optimization, and hazard mitigation.

This current effort continues the services previously established under contract 75D301-24-P- 18725. Ongoing access to annual software maintenance and subscription services ensures PMRD can continue its research with supported, updated, and secure modeling tools.

SECTION 2 – PURPOSE/OBJECTIVE

The purpose of this acquisition is to obtain annual maintenance and subscription support for the ITASCA numerical modeling suite (3DEC, FLAC3D, and Griddle). The objective is to ensure that PMRD researchers have continuous access to the latest software versions, technical support, security updates, and license management required to perform critical mining safety modeling tasks.

This acquisition enables PMRD to continue producing accurate, validated modeling outputs that inform field guidance, research publications, and mine‑safety recommendations.

SECTION 3 – SCOPE OF WORK

The contractor shall provide annual maintenance, subscription renewals, and technical support for the ITASCA modeling software suite used by PMRD.

This includes license updates, software patches, user support, and access to updated modeling libraries and capabilities.

Work includes:

• Contractor shall ensure uninterrupted access to the software suite.

• Contractor shall provide version upgrades and patches.

• Contractor sahll provide remote technical support as needed.

• Contractor shall maintain license activation and renewal capabilities.

The scope is limited to software maintenance and support services. No custom development or on‑site services are required.

SECTION 4 – TASKS TO BE PERFORMED

The Contractor shall provide annual maintenance and subscription support for the following Government-owned perpetual ITASCA software licenses:

Item Software Current Version Serial Number

Updated version Quantity

1 FLAC3D 9 242-001-0622-

96079

9.7 1

2 3DEC 9 215-001-0026-

18979

9.7 1

3 3DEC 9 215-001-0026-

93445

9.7 1

4 GRIDDLE 2 280-001-0057-

70557

9.7 1

For the licenses identified above, the Contractor shall provide, as applicable:

Task 1: Annual Software Maintenance and Subscription Services The contractor shall:

a. Provide renewal of two (2) - 3DEC, one (1) - FLAC3D, and one (1) -Griddle annual licenses.

b. Maintain active subscription status for all covered products.

c. Ensure compatibility with PMRD systems for the full period of performance.

Task 2: Software Updates and Version Releases The contractor shall:

a. Provide all version upgrades released during the period of performance.

b. Provide patches, performance enhancements, and security updates.

c. Notify PMRD of major release notes and changes impacting functionality.

Task 3: Technical Support The contractor shall:

a. Provide remote technical support for installation, configuration, and troubleshooting.

Respond to inquiries regarding model performance, licensing, or errors.

b. Provide guidance on updates or model file compatibility as needed.

SECTION 5 – GOVERNMENT FURNISHED PROPERTY

No Government Furnished Property will be provided.

SECTION 6 – PLACE OF PERFORMANCE AND CONTRACT SUPPORT

HOURS SUBSECTION A – PLACE OF PERFORMANCE

All work shall be performed at the contractor’s facility. PMRD will use the software at

CDC/NIOSH

facilities in Pittsburgh, PA under existing hardware and IT configurations.

SUBSECTION B – CONTRACT SUPPORT HOURS

Technical support shall be available during the contractor’s standard business hours (Monday through Friday, 8:00 AM to 5:00 PM, Eastern Time), with response times consistent with commercial software support norms.

SECTION 7 – DELIVERABLES/REPORTING SCHEDULE

Task Deliverable Quantity/Format Due Date Deliver To Task 1 Annual

Software Subscriptio n Activation

Email Within 5 business days of award or renewal

COR

Task 2 Version Updates & Release Notes

Email As released COR

Task 3 Technic al Support Respons es

Email/Remote Support Ticket

As required COR

SECTION 8 – MINIMUM VENDOR QUALIFICATIONS

The contractor must be the original developer or authorized distributor of ITASCA modeling software (3DEC, FLAC3D, and Griddle) and must be capable of providing annual maintenance and subscription services.

SECTION 9 – ADDITIONAL REQUIREMENTS

Information Security and Privacy Standard Language Section V.3, Other IT Procurements: Information Technology Application Design, Development, or Support

a. The Contractor (and/or any subcontractor) must ensure IT applications designed and developed for end users (including mobile applications and software licenses) run in the standard user context without requiring elevated administrative privileges.

b. The Contractor must consult the guidelines from NIST SP 800-160 volume 1, Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems, NIST SP 800- 160 volume 2, Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems, and NIST SP 800-53 to implement security during the development of all applications and throughout the life cycle stages of software development.

c. The Contractor (and/or any subcontractor) must follow secure coding best practice requirements, as directed by United States Computer Emergency Readiness Team (US- CERT) specified standards, the Open Web Application Security Project (OWASP), System Admin, Audit, Network and Security (SANS), HHS Policy for Software Development Secure Coding Practices, and CDC Secure Software Development Standard that will limit system software vulnerability exploits.

d. The Contractor (and/or any subcontractor) must ensure that computer software developed on behalf of CDC or tailored from an open-source product, is fully functional and operates correctly on systems configured in accordance with government policy and federal configuration standards.

The contractor must test applicable products and versions with all relevant and current updates and patches updated prior to installing in the CDC environment. No sensitive data must be used during software testing.

e. The Contractor must, at a minimum, segregate physically or logically, all test and development systems from production systems as applicable in accordance with the HHS Standard for Segregation of Dev/Test Environments from Production.

f. The Contractor (and/or any subcontractor) must protect information that is deemed sensitive from unauthorized disclosure to persons, organizations or subcontractors who do not have a need to know the information. Information which, either alone or when compared with other reasonably available information, is deemed sensitive or proprietary by CDC must be protected as instructed in accordance with the magnitude of the loss or harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the data. This language also applies to all subcontractors that are performing under this contract.

Human Subjects Protections in Research Not applicable.

Paperwork Reduction Act (PRA) Not applicable.

Section 508 Compliance No deliverables requiring accessibility review are anticipated. Any documentation delivered electronically must meet 508 acceptance criteria.

Part A – Provision

Reference HHSAR 352.239-73[8] Electronic Information and [Communication] Technology Accessibility Notice.

(Deviation)

(a) Any offeror responding to this solicitation must comply with established HHS Information and Communication Technology (ICT) accessibility standards.

Information about Section 508 is available at https://www.hhs.gov/web/section- 508/index.html.

(b) The Section 508 accessibility standards applicable to this solicitation are stated in https://www.hhs.gov/web/section-508/index.html the clause at 352.239-79 Information and Communication Technology Accessibility. In order to facilitate the Government’s determination whether proposed ICT supplies, products, platforms, information, and documentation meet applicable Section 508 accessibility standards, offerors must submit an appropriate HHS Section 508 Accessibility Conformance Checklist (see https://www.hhs.gov/web/section- 508/accessibility-checklists/index.html) or an Accessibility Conformance Report (ACR) (based on the Voluntary Product Accessibility Template (VPAT) see https://www.itic.org/policy/accessibility/vpat), in accordance with the completion instructions. The purpose of the checklists and conformance reports are to assist HHS acquisition and program officials in determining whether proposed ICT supplies, products, platforms, information, and documentation conform to applicable Section 508 accessibility standards. Checklists and ACRs evaluate—in detail—whether the ICT conforms to specific Section 508 accessibility standards and identifies remediation efforts needed to address conformance issues.

(c) If an offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies, products, platforms, information, documentation, or services support delivered do not conform to the described accessibility standards, remediation of the supplies, products, platforms, information, documentation, or services support to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.

(d) In order to facilitate the Government's determination whether proposed ICT supplies meet applicable Section 508 accessibility standards, offerors must submit an Accessibility Conformance Report, in accordance with its completion instructions and tailored to the requirements in the solicitation. The purpose of the Report is to assist HHS acquisition and program officials in determining whether proposed ICT supplies conform to applicable Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and document, in detail, whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the Template are available at https://www.section508.gov/.

(e) Additionally, offerors must provide enough information to assist the Government in determining that the ICT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.

(f) Respondents to this solicitation must identify any inability to conform to Section 508 requirements. If an offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the described accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.

(g) Items delivered as electronic content must be accessible to HHS acceptance https://www.hhs.gov/web/section-508/accessibility-checklists/index.html https://www.hhs.gov/web/section-508/accessibility-checklists/index.html https://www.hhs.gov/web/section-508/accessibility-checklists/index.html https://www.itic.org/policy/accessibility/vpat https://www.section508.gov/ criteria. Checklist for various formats are available at http://508.hhs.gov/. Materials, other than items incidental to contract management, that are final items for delivery should be accompanied by the appropriate checklist, except upon approval of the Contracting Officer or Contracting Officer’s Representative.

Part B - Clause

HHSAR 352.239-74[9] Electronic, Information, and Communication Technology Accessibility.

(Deviation)

(a) Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, all information and communication technology (ICT) supplies, products, platforms, information, documentation, and services, or support developed, acquired, maintained or delivered under this contract or order must comply with the Revised 508 Standards, which are located at 36 C.F.R.

1194.1 and Appendices A, B, and C, and are available at https://www.access-board.gov/ict/. Information about Section 508 is available at https://www.hhs.gov/web/section-508/index.html.

(b) Additional Section 508 accessibility standards applicable to this contract or order are identified as follows:

205 WCAG 2.0 Level A & AA Success Criteria 302 Functional Performance Criteria 502 Inoperability with Assistive Technology 503 Applications 504 Authoring Tools 602 Support Documentation 603 Support Services

If it is determined by the Government that ICT supplies, products, platforms, information, documentation, and services support provided by the Contractor do not conform to the described accessibility standards in the contract, remediation of the supplies, products, platforms, information, documentation, or services support to the level of conformance specified in the contract will be the responsibility of the Contractor at its own expense.

(c) In the event of a modification(s) to this contract or order, which adds new ICT supplies or services or revises the type of, or specifications for, supplies, products, platforms, information, documentation, or services support, the Contracting Officer shall require that the Contractor submit a completed HHS Section 508 Accessibility Conformance Checklist (see https://www.hhs.gov/web/section-508/accessibility-checklists/index.html) or an Accessibility Conformance Report (ACR) (based on the Voluntary Product Accessibility Template (VPAT) see https://www.itic.org/policy/accessibility/vpat), and any other additional information http://508.hhs.gov/ https://www.access-board.gov/ict/ https://www.access-board.gov/ict/ https://www.hhs.gov/web/section-508/index.html https://www.hhs.gov/web/section-508/accessibility-checklists/index.html https://www.hhs.gov/web/section-508/accessibility-checklists/index.html necessary to assist the Government in determining that the ICT supplies or services conform to Section 508 accessibility standards. If it is determined by the Government that ICT supplies, products, platforms, information, documentation, and services support provided by the Contractor do not conform to the described accessibility standards in the contract, remediation of the supplies, products, platforms, information, documentation, or services support to the level of conformance specified in the contract will be the responsibility of the Contractor at its own expense.

(d) If this is an Indefinite-Delivery type contract, a Blanket Purchase Agreement or a Basic Ordering Agreement, the task/delivery order requests that include ICT supplies, products, platforms, information, documentation, or services support will define the specifications and accessibility standards for the order. In those cases, the Contractor shall be required to provide a completed HHS Section 508 Accessibility Conformance Checklist (see https://www.hhs.gov/web/section-508/accessibility-checklists/index.html) or an ACR (based on the VPAT see https://www.itic.org/policy/accessibility/vpat), and any other additional information necessary to assist the Government in determining that the ICT supplies, products, platforms, information, documentation, or services support conform to Section 508 accessibility standards. If it is determined by the Government that ICT supplies and services provided by the Contractor do not conform to the described accessibility standards in the provided documentation, remediation of the supplies, products, platforms, information, documentation, or services support to the level of conformance specified in the contract will be the responsibility of the Contractor at its own expense.

(e) The contractor shall identify to the Contracting Officer any perceived exception or exemption to Section 508 requirements for review by the agency Section 508 Program.

Section 10 - Acceptance The Government will accept the requirement upon verification that maintenance/subscription coverage has been established for all four perpetual licenses and that the Government has access to the applicable updates and technical support for the required period of performance.

SECTION G – CONTRACT ADMINISTRATION DATA

CDCG.02 Contracting Officer’s Representative (COR) (Jul 2017) Performance of the work hereunder shall be subject to the technical directions of the designated COR for this contract.

As used herein, technical directions are directions to the Contractor which fill in details, suggests possible lines of inquiry, or otherwise completes the general scope of work set forth herein.

These technical directions must be within the general scope of work and may not alter the scope of work or cause changes of such a nature as to justify an adjustment in the stated contract price/cost, or any stated limitation thereof.

In the event that the Contractor believes full implementation of any of these directions may exceed the scope of the contract, he or she shall notify the originator of the technical direction and the Contracting Officer, immediately or as soon as possible, in a letter or e-mail separate of any required report(s). No technical direction, nor its fulfillment, shall alter or abrogate the rights and obligations fixed in this contract.

The Government COR is not authorized to change any of the terms and conditions of this contract. Contract changes shall be made only by the Contracting Officer through properly written modification(s) to the contract.

The Government will provide the Contractor with a copy of the COR delegation memorandum upon request.

CDCG.07 Payment by Electronic Funds Transfer (Jan 2026)

(a) The Government shall use electronic funds transfer to the maximum extent possible when making payments under this contract. FAR 52.232-33, Payment by Electronic Funds Transfer –System for Award Management, requires the contractor to designate in writing a financial institution for receipt of electronic funds transfer payments.

(b) In the case that EFT information is not within the System of Award Management, FAR

52.232-34, Payment by Electronic Funds Transfer-Other than System for Award Management, requires mandatory submission of Contractor’s EFT information directly to the office designated in this contract to receive that information (hereafter: “designated office”);

see below. The contractor shall submit the EFT information within the form titled “ACH Vendor/Miscellaneous Payment Enrollment Form” to the address indicated below. Note: The form is either attached to this contract (see Section J, List of Attachments) or may be obtained from the CDC Office of Financial Resources at 678-475-4500 or cpbapinv@cdc.gov.

(c) In cases where the contractor has previously provided such information, i.e., pursuant to a prior contract/order, and been enrolled in the program, the form is not required unless the designated financial institution has changed.

(d) The completed form shall be mailed or sent via facsimile after award, but no later than 15 calendar days before an invoice is submitted, to the following address:

The Centers for Disease Control and Prevention Office of Financial Resources (OFR) P.O. Box 15580 Atlanta, GA 30333

SECTION H - SPECIAL CONTRACT REQUIREMENTS

CDCH.10 Artificial Intelligence Compliance and Risk Management Plan (July 2026) The use of Artificial Intelligence (AI), including GenAI, is prohibited without an approved AI Compliance and Risk Management Plan. The contractor is responsible for updating the AI mailto:cpbapinv@cdc.gov

Compliance and Risk Management Plan throughout the life of the contract as changes occur. If a change to AI use, AI functionality, AI model, or deployment configuration is anticipated, the contractor must notify the contracting officer and Contracting Officer’s Representative (COR) immediately and provide a revised plan. The government will issue approval or disapproval before AI can be incorporated. The contractor must identify whether planned or potential AI use may involve a high-impact AI use case (as defined in defined in Appendix A of OMB-M-25-21) and must provide sufficient descriptive information for the Government to complete any required AI impact or high-impact assessment.

The AI Compliance and Risk Management Plan must:

1. Identify the specific tasks or functions where AI will be used.

2. Explain how logs, audits, or other forms of AI generated data will be stored, used, retained, or deleted.

3. State whether the AI technologies are open-source, proprietary, or any other type.

4. Include applicable model cards or system documentation describing the AI technologies used.

5. Describe how bias in AI models and outputs will be identified, monitored, and mitigated, including the origin, quality, and weighting of data.

6. Explain the AI safeguards in place, including compliance and risk management practices, protections against unauthorized data access, and steps taken to manage bias and reduce risk in alignment with applicable AI policies and directives.

7. Describe internal policies governing AI use, including transparency, accountability, data integrity, accuracy, protection of sensitive or proprietary information, foreseeable risks, and potential social impacts.

8. Explain how the contractor will assess and prevent unfair or disparate impacts, address privacy, civil rights, and civil liberties concerns, and prevent misuse, unauthorized use, or corruption of AI systems.

9. Confirm that the AI solution will not make or support decisions based on unlawful discrimination in violation of federal civil rights laws, including Title VII of the Civil Rights Act, the Americans with Disabilities Act (ADA), and the Age Discrimination in Employment Act (ADEA).

10. Describe how applicable technological or voluntary consensus standards will be incorporated to reduce acquisition and operational risk

11. The plan must describe how Government data, outputs, prompts, logs, and outputs be accessed, used, protected, retained, deleted, and transferred, and identify any proposed limitations on Government rights, access, or reuse.

12. The AI Compliance and Risk Management Plan will be reviewed by the Government and an approval or disapproval issued.

The vendor must ensure that any AI use adheres to the following requirements of the HHS AI Strategy:

AI Safeguards:

• The contractor must assess and reduce risks related to unintended disclosure of sensitive information, including conducting model-specific risk analyses before releasing or sharing AI models or model weights. Documentation must describe the origin, quality, https://www.hhs.gov/sites/default/files/hhs-artificial-intelligence-strategy.pdf https://www.hhs.gov/sites/default/files/hhs-artificial-intelligence-strategy.pdf and suitability of training data; how bias is identified and managed; how sensitive data is protected; and how models are selected, trained, tested, validated, audited, and maintained. The contractor must also document data sourcing, transparency practices, output weighting methods, and responsible data use. Compliance with NIST standards and HHS AI policy must be documented.

Data Portability and Interoperability:

• The contractor or service provider must ensure the use of open and standard Data formats and application programming interfaces (APIs) for all Data Outputs, Custom Developments, and AI Systems.

• The contractor or service provider must ensure that neither the Contractor nor any applicable Service Provider use proprietary technologies or formats that require additional licensing or create vendor dependencies

• The contractor or service provider must provide tools enabling government customers to export all Government Data and content (including user-generated content, conversational history, uploaded documents, media files, and custom knowledge bases) in open, machine-readable formats such as JSON or XML. The export must preserve the data's structural and relational integrity, including associated schema definitions. The exported data and schema must be sufficient to allow accurate and complete ingestion and reconstruction of the data and relationships within a separate system and must not otherwise create vendor lock-in situations.

CDCH.14 Records Management Obligations (Jun 2020) A. Applicability The following applies to all Contractors whose employees create, work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.

B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

The term Federal record:

1. includes Centers for Disease Control and Prevention (CDC) records.

2. does not include personal materials.

3. applies to records created, received, or maintained by Contractors pursuant to their CDC contract.

4. may include deliverables and documentation associated with deliverables.

C. Requirements

1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a).

These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

4. CDC and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of CDC or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to the Contracting Officer and the Contracting Officer’s Representative. The agency must report promptly to NARA in accordance with 36 CFR 1230.

5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the contract. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected.

The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to CDC control, or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the contract.

Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).

6. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and CDC guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with CDC policy.

8. The Contractor shall not create or maintain any records containing any non-public CDC information that are not specifically tied to or authorized by the contract.

9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.

10. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take CDC-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.

D. Flowdown of requirements to subcontractors

1. The Contractor shall incorporate the entire substance of the terms and conditions herein, including this paragraph, in all subcontracts under this contract, and must require written subcontractor acknowledgment of same.

2. Violation by a subcontractor of any provision set forth herein will be attributed to the Contractor.

CDCH.20 Non-Personal Services (Jun 2020)

(a) Personal services shall not be performed under this contract. Although the Government may provide sporadic or occasional instructions within the scope of the contract, the Contractor is responsible for control and supervision of its employees. If the Contractor (including its employees) believes any Government action or communication has been given that would create a personal services relationship between the Government and any Contractor employee, the Contractor shall promptly notify the Contracting Officer of this communication or action.

(b) The Contractor shall comply with, and ensure their employees and subcontractors comply with, CDC Policy titled Contractor Identification and Safeguarding of Non-Public Information (Policy No. CDC-IS-2006-01). No Contractor employee shall hold him or herself out to be a Government employee, agent, or representative. No Contractor employee shall state orally or in writing at any time that he or she is acting on behalf of the Government. In all communications with third parties in connection with this contract, Contractor employees shall identify themselves as Contractor employees and specify the name of the company for which they work.

(c) The Contractor shall ensure that all its employees and subcontractor employees working on this contract are informed of the terms and conditions herein. The Contractor agrees that this is a non-personal services contract; and that for all the purposes of the contract, the Contractor is not, nor shall it hold itself out to be an agent or partner of, or joint venture with, the Government. The Contractor shall notify its employees that they shall neither supervise nor accept supervision from Government employees. The substance of these terms shall be included in all subcontracts at any tier.

(d) The conditions above do not limit the Government's rights under other terms of the contract, including those related to the Government's right to inspect and accept or reject the services performed under this contract.

SECTION I - PROVISIONS AND CLAUSES

FAR Cluases Incorporated by Reference Number Title 52.203-17 Contractor Employee Whistleblower Rights (Nov 2023) 52.203-18 Prohibition on Contracting with Entities that Require Certain Internal

Confidentiality Agreements or Statements-Representation (Jan 2017) 52.203-19 Prohibition on Requiring Certain Internal Confidentiality Agreements or

Statements (Jan 2017) 52.204-7 System for Award Management—Registration (Deviation) RFO Aug2025) 52.204-13 System for Award Management Maintenance (Deviation) (RFO Apr 2025) 52.209-10 Prohibition on Contracting with Inverted Domestic Corporations

(Deviation) (RFO Apr 2025) 52.212-1 Instructions to Offerors—Commercial Products and Commercial Services 52.212-4 Contract Terms & Conditions – Commercial Products and Commercial Services

(Deviation) (RFO Apr 2025) 52.222-3 Convict Labor (Deviation) (RFO Apr 2025) 52.222-19 Child Labor—Cooperation with Authorities and Remedies (Deviation) (RFO Apr

2025) 52.222-50 Combating Trafficking in Persons (Deviation) (RFO Apr 2025) 52.222-90 Addressing DEI Discrimination by Federal Contractors (Deviation) (RFO April

2026) 52.225-1 Buy American-Supplies (Deviation) (RFO Apr 2025) 52.225-2 Buy American Certificate (Oct 2022) 52.225-3 Buy American-Free Trade Agreements-Israeli Trade Act (Deviation) (RFO Apr

2025) 52.225-4 Buy American-Free Trade Agreements-Israeli Trade Act Certificate (Deviation)

(RFO April 2026) 52.226-8 Encouraging Contractor Policies to Ban Text Messaging While Driving (May

2024) 52.232-33 Payment by Electronic Funds Transfer-System for Award Management (Oct

2018) 52.232-40 Providing Accelerated Payments to Small Business Subcontractors (Deviation)

(RFO Apr 2025)

52.233-3 Protest after Award (Deviation) (RFO Apr 2025) 52.233-4 Applicable Law for Breach of Contract Claim (Deviation) (RFO Apr 2025) 52.240-90 Security Prohibitions and Exclusions Representations and Certifications

(Deviation)(RFO Nov 2025) 52.240-91 Security Prohibitions and Exclusions (Deviation) (RFO Apr 2025) 52.244-6 Subcontracts for Commercial Products and Commercial Services (Deviation)

(RFO Apr 2025)

HHSAR Clauses Incorporated by Reference

Number Title 352.239-

Information and Communication Technology Accessibility (Feb 2024) (Deviation)

352.232-

Electronic Submission of Payment Requests (Apr 2026) (RFO Deviation)

FAR Clauses Incorporated by Full Text

FAR 52.252-2 Clauses Incorporated by Reference.

Clauses Incorporated by Reference (Feb 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

https://www.acquisition.gov/ https://www.acquisition.gov/far-overhaul https://www.acquisition.gov/hhsar https://www.hhs.gov/grants-contracts/contracts/contract-policies-regulations/hhsar-overhaul/rfo-part-352-solicitation-provisions-contract-clauses/index.html

(End of clause)

HHSAR 352.239-78 Information and Communication Technology Accessibility Notice. (FEB 2024) (Deviation) All solicitations

(a) Any offeror responding to this solicitation must comply with established HHS Information and Communication Technology (ICT) accessibility standards. Information about Section 508 is available at https://www.hhs.gov/web/section-508/index.html.

(b) The Section 508 accessibility standards applicable to this solicitation are stated in the clause at 352.239-79 Information and Communication Technology Accessibility. In order to facilitate the Government’s determination whether proposed ICT supplies, products, platforms, information, and documentation meet applicable Section 508 accessibility standards, offerors must submit an appropriate HHS Section 508 Accessibility Conformance Checklist https://www.acquisition.gov/ https://www.acquisition.gov/far-overhaul https://www.acquisition.gov/hhsar https://www.hhs.gov/grants-contracts/contracts/contract-policies-regulations/hhsar-overhaul/rfo-part-352-solicitation-provisions-contract-clauses/index.html https://www.hhs.gov/grants-contracts/contracts/contract-policies-regulations/hhsar-overhaul/rfo-part-352-solicitation-provisions-contract-clauses/index.html

(see https://www.hhs.gov/web/section-508/accessibility-checklists/index.html) or an Accessibility Conformance Report (ACR) (based on the Voluntary Product Accessibility Template (VPAT) see https://www.itic.org/policy/accessibility/vpat), in accordance with the completion instructions. The purpose of the checklists and conformance reports are to assist HHS acquisition and program officials in determining whether proposed ICT supplies, products, platforms, information, and documentation conform to applicable Section 508 accessibility standards. Checklists and ACRs evaluate—in detail—whether the ICT conforms to specific Section 508 accessibility standards and identifies remediation efforts needed to address conformance issues.

(c) If an offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies, products, platforms, information, documentation, or services support delivered do not conform to the described accessibility standards, remediation of the supplies, products, platforms, information, documentation, or services support to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.

(d) In order to facilitate the Government's determination whether proposed ICT supplies meet applicable Section 508 accessibility standards, offerors must submit an Accessibility Conformance Report, in accordance with its completion instructions and tailored to the requirements in the solicitation. The purpose of the Report is to assist HHS acquisition and program officials in determining whether proposed ICT supplies conform to applicable Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and document, in detail, whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the HHS Section 508 Evaluation Template are available at https://Section508.gov/.

(e) In order to facilitate the Government's determination whether proposed ICT services meet applicable Section 508 accessibility standards, offerors must provide enough information to assist the Government in determining that the ICT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.

(f) Respondents to this solicitation must identify any inability to conform to Section 508 requirements. If an offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the described accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.

(g) Items delivered as electronic content must be accessible to HHS acceptance criteria.

Checklist for various formats are available at http://508.hhs.gov/. Materials, other than items incidental to contract management, that are final items for delivery should be accompanied by the appropriate checklist, except upon approval of the Contracting Officer or Contracting Officer’s Representative.

(End of provision) https://section508.gov/

SECTION J - LIST OF ATTACHMENTS

Attachment Title Pages 1 AI Use Compliance and Risk Management Plan [7 ]

SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO

QUOTER

L.1 – Quotation Submission

The Quoter shall submit its quotation electronically by email to:

Contract Specialist: Alyssa Thomas Email: ah78@cdc.gov RFQ Number: 75D301-26-Q-79230

The quotation must be received no later than:

14 September 2026 at 12:00PM Eastern Standard Time (EST)

The email subject line shall state:

RFQ 75D301-26-Q-79230 – ITASCA Software Maintenance

The quotation and supporting documentation shall be submitted in PDF format, except that Government-provided forms may be returned in their original electronic format.

The Quoter should submit the quotation and supporting documentation in one email whenever practicable. If file-size limitations require multiple emails, each email shall clearly identify the RFQ number and sequence (e.g., “Email 1 of 2”).

The Government does not require a separate technical proposal, management proposal, staffing plan, resumes, oral presentation, or past-performance volume. The Quoter shall submit only the information identified in this Section G.

L.2 – Required Quotation Content

The Quoter shall submit one complete quotation package containing the information identified below.

L.2.1 – Quoter Information

Provide:

1. Legal business name;

2. Business address;

3. Unique Entity Identifier (UEI);

4. CAGE Code;

5. Name, title, telephone number, and email address of the individual authorized to coordinate the quotation;

6. Name and title of the individual authorized to bind the company, if different; and mailto:ah78@cdc.gov

7. Quotation date and expiration date.

The legal business name, UEI, and CAGE Code shall correspond to the Quoter's SAM.gov registration.

The Government will independently verify required SAM registration, exclusions, and responsibility/eligibility information prior to award.

L.2.2 – Pricing

The Quoter shall complete Section B – Supplies or Services and Prices.

The quotation shall provide:

• Firm-fixed unit price for each CLIN;

• Extended price for each CLIN; and

• Total firm-fixed price.

The quoted prices shall include all costs necessary to satisfy the requirements of this RFQ, including applicable maintenance/subscription coverage, software updates and upgrades, patches, license management/support, technical support, fees, and other costs necessary to perform the requirement.

Any applicable taxes or separately charged fees shall be clearly identified.

The Government will not be obligated to pay charges that are not identified in the quotation and incorporated into the resulting purchase order.

L.2.3 – License Coverage Confirmation

The Quoter shall affirmatively confirm that the quotation provides the required 12-month maintenance/subscription support for each of the following Government-owned perpetual licenses:

Software Version Serial Number

3DEC 9 215-001-0026-18979

3DEC 9 215-001-0026-93445

FLAC3D

GRIDDLE

242-001-0622-96079 280-001-0057-70557

The quotation shall clearly identify the maintenance/subscription product or coverage associated with each serial number.

The Quoter shall identify any license that cannot be covered as required by this RFQ.

L.2.4 – Artificial Intelligence Disclosure

CDCL.03 – Disclosure of Artificial Intelligence Use in Contract Performance (May 2026)

Offerors must affirmatively identify in their proposal whether or not Artificial Intelligence (AI), including Generative AI, is planned, expected, or may be used in the performance of this contract. If planned or potential AI use is identified, offerors must submit an AI Compliance and Risk Management Plan in accordance with CDCH.10 using the template provided.

L.4 – Questions

CDCL.01 Questions (Jan 2026)

Questions concerning this RFQ shall be submitted in writing by email to:

Alyssa Thomas ah78@cdc.gov

Questions shall be received no later than:

10 September 2026 at 3:00 PM EST

The email subject line shall state:

Question – RFQ 75D301-26-Q-79230 – ITASCA Software Maintenance

Any Government change to the solicitation will be made through an amendment when required.

L.5 – Quotation Validity

The quotation shall…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .