A40 Att 1 PWS.pdf

PDF 657 KB Posted

Attached to
Credit Reporting Federal contract opportunity
Solicitation number
HS0021-23-R-0016
Issued by
Defense Counterintelligence and Security Agency

About this file

This is a combined synopsis and solicitation for multiple award indefinite delivery indefinite quantity firm fixed price contracts to provide credit reporting services. The solicitation seeks proposals for single credit bureau reports and tri-merge reports combining data from the three major credit bureaus in Defense Counterintelligence and Security Agency formats. The 100% small business set-aside is under NAICS code 561450 with a response date of April 24, 2023 and a base period of performance of five years plus five one-year options. Minimum order quantities are specified for single reports and tri-merge reports with maximum order limitations also defined. Attachments include the performance work statement with data item descriptions, interconnection security agreement template, report examples, ordering guide templates, and applicable provisions and clauses.

View the file

Other files for this federal contract opportunity

Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

FOR

CREDIT REPORTING SERVICES

DEFENSE COUNTERINTELLIGENCE AND SECURITY AGENCY

ACQUISITION AND CONTRACTING

Version 1, February 19, 2023

1 DESCRIPTION OF SERVICES

1.1 Introduction

This is a non-personal services contract. The Government will neither supervise contractor employees nor control the method by which the contractor performs the required tasks. The contractor shall manage its employees and guard against any actions that are of the nature of personal services, or give the perception of personal services. The contractor shall notify the

Contracting Officer (KO) immediately if they perceive any actions constitute personal services. These services shall not be used to perform any Inherently Governmental Functions.

1.2 Background

The Personnel Security mission of the Defense Counterintelligence and Security Agency

(DCSA) is to deliver efficient and effective background investigations, continuous vetting, and adjudications to safeguard the integrity and trustworthiness of the federal and contractor workforce. This is accomplished through vetting, industry engagement, education, and counterintelligence and insider threat support, securing the trustworthiness of the United States

Government's workforce, the integrity of its cleared contractor support, and the uncompromised nature of its technologies, services, and supply chains. A segment of DCSA’s mission is to obtain data source records for inclusion in the Personnel Security program. This acquisition will allow DCSA to complete its mission by obtaining employment credit reports throughout the DCSA personnel security mission.

DCSA is specifically seeking access to employment credit report data, as required by the

Federal Investigative Standards and Trusted Workforce 2.0. This information is vital to the mission of DCSA in conducting initial background investigations (BI), continuous vetting, and adjudications for the departments and agencies of the federal Government. Personnel vetting is required to determine an individual’s eligibility for access to classified information, assignment to, or retention in positions with sensitive duties, or other designated duties requiring such investigations. Records may be obtained during the initial background investigation, continuous vetting, or the adjudication.

1.3 Scope

The contractor shall accomplish the following services:

1.3.1 Provide single credit bureau reports

1.3.1.1 Provide the Reports using a Department of Defense (DoD) format (defined at the Task Order level / adjustments to the example formats at Task Order level)

1.3.2 Provide Tri-Merge Report – data from all 3 credit bureaus merged into one report

1.3.2.1 Provide the Reports using a Department of Defense (DoD) format (defined at the Task Order level / adjustments to the example formats at Task Order level)

1.3.3 Provide a system to system connection for Legacy, Current, and Future DCSA systems to request and receive credit reports

1.3.3.1 Personnel Investigations Processing System (PIPS) (Legacy/Current)

- Connection for Tri-merge Credit Reports

1.3.3.2 Mirador (Legacy/Current)

- Connection to two Credit Bureaus: TransUnion, Experian

1.3.3.3 National Background Investigation Services (NBIS) (Current/Future)

- Connection for Tri-merge Credit Reports

- Connection to each of the three Credit Bureaus: TransUnion, Experian, and Equifax OR ability to provide single credit bureau reports based on specific Bureau requested by DCSA

1.3.4 Provide access to an on-demand web portal or graphical user interface (GUI) for

DCSA to request and receive single and tri-merge credit bureau reports

Contractors are required to establish connections to DCSA systems, current and future.

Connections are expected to take between 1 and 10 months.

PIPS (Legacy/Current) – Up to 10 months

Mirador (Legacy/Current) – Up to 3 months

NBIS (Current/Future) – Up to 10 months

Any future systems – Up to 10 months

The Contractor shall perform to the standards of the contract.

1.4 Period of Performance

The Government contemplates awarding multiple-award indefinite delivery indefinite quantity (IDIQs). Each IDIQ will have a 5-year ordering period with 5 one-year options.

Individual Task Orders will be competed as requiring activity needs arise and the period of performance for each Task Order will be no longer than 12 months for a base period and may include option periods not to exceed the period of performance of the IDIQ.

1.5 Ordering

Only appropriately warranted Government KOs are authorized to place orders under this

IDIQ. All IDIQ holders eligible for competition will only be those with already established connections to specific systems. The ordering activity may send the contractor a request for quote (RFQ) that will include the requirement, inclusive of any formatting requirements and system requirements, and evaluation criteria to the IDIQ holder, unless a separate determination is made in accordance with FAR 16.505. The Government will evaluate the response received and the KO will place the orders with the IDIQ holder, in accordance with the evaluation criteria provided with the RFQ. Contractors may be required to respond to an order RFQ in as little as one business day. Depending on the needs of the Government, individual orders may include option quantities. The type of option and the evaluation methodology will be established within the RFQ.

Ordering activities shall require the IDIQ awardee to identify any potential conflicts of interest. If any exist, the awardee shall address and resolve any concerns prior to order placement.

2 SPECIFIC TASKS

The Contractor shall provide support services to execute the following tasks at the task order level:

2.1 Task One: Single Credit Reports

The contractor will deliver Single Credit reports to the Government

Information will be reliable and include a timely delivery of credit information from

TransUnion, Experian, and Equifax, The timelines for queries are as follows:

XML Webservice or Application

Programming Interface (API) connections

Deliver single reports within 6 hours or less of initial query.

Batch or Connect Direct Exchanges

*Batch files for the Single Credit Reports

System are sent Monday-Friday, one day per week and ad-hoc as needed. Vendor will be made aware of batch requests in advance.

Deliver single reports within 24 hours of initial query.

Online/Web Interface Queries Deliver responses immediately

Provided information will include:

o Tradeline information, o Collection information, o Public Records relating to civil judgments, tax liens, bankruptcies, o Subject income, o Consumer identification to include names, AKAs, current and prior addresses, employment history information, and date of birth, o Credit history identifying creditors, debt payment(s) performance, current and past due charge off, collection and collection factored accounts, balances and past due amounts, and status of accounts for the past 24 months, o A listing of inquiries within the last 12 months, o Overall score based on DCSA requirements.

The vendor will provide the following features as required within the vendor environment:

o XML or API format via web service, o Ability to accept batch files or 1-for-1 exchange of requests/results, o Single credit report from the three major reporting bureaus (TransUnion, Experian, and Equifax) as requested by Customer, o Credit inquiries should be recorded as soft hits, o Be accessible over the internet using appropriate access control security features such as passwords, secure sockets layers, etc.

o Be accessible over the internet with no software requirement needed, such as to be loaded on individual computers, in order to access the reports, o System accessibility 24 hours a day, o Allow for the assignment of an unlimited quantity of account managers and user roles in the credit report access portal, o System request/review consumer credit reports for single bureau reports, ability to print report, o Alerts of suspicious activity and/or changes in credit file information, o Provide a manifest of responses provided, o Electronic method for obtaining missing tradeline addresses, o Archive capability for DCSA requested Credit Reports for 60 days, o A test environment, to include test data to mirror production, with vendor testing support, o Written agreements with each of the three credit bureaus to document FCRA awareness, o Ability to provide detailed invoices and quality control reports.

2.2 Task Two: Tri-Merge Reports

The contractor will deliver Tri-Merge reports to the Government

Information will be reliable and include a timely delivery of credit information from

TransUnion, Experian, and Equifax, o Vendor will confirm that each tri-merge report includes information from all three bureaus.

The timelines for queries are as follows:

XML Webservice or Application

Programming Interface (API) connections

Deliver tri-merge reports within 6 hours or less of initial query.

Batch or Connect Direct Exchanges

*Batch files for the Tri-Merge Reports System are sent Tuesday-Saturday. Work may be received Saturday and the response will need to be returned same day or NLT 6am the following designated work day as per COR.

Deliver tri-merge reports within 24 hours of initial query.

Online/Web Interface Queries Deliver responses immediately

Provided information will include:

o Tradeline information, o Collection information, o Public Records relating to civil judgments, tax liens, bankruptcies, o Subject income, o Consumer identification to include names, AKAs, current and prior addresses, employment history information, and date of birth, o Credit history identifying creditors, debt payment(s) performance, current and past due charge off, collection and collection factored accounts, balances and past due amounts, and status of accounts for the past 24 months, o A listing of inquiries within the last 12 months, o Overall score based on DCSA requirements (tri-merge).

The vendor will provide the following features as required within the vendor environment:

o XML or API format via web service, o Ability to accept batch files or 1-for-1 exchange of requests/results, o Ability to identify and document Errors in a summary report and re-process Errors via access to the DCSA NP2 Portal, o Tri-Merge (3 in 1) credit report from the three major reporting bureaus

(TransUnion, Experian, and Equifax), o Credit inquiries should be recorded as soft hits, o Be accessible over the internet using appropriate access control security features such as passwords, secure sockets layers, etc.

o Be accessible over the internet with no software requirement needed, such as to be loaded on individual computers, in order to access the reports, o System accessibility 24 hours a day, o Allow for the assignment of an unlimited quantity of account managers and user roles in the credit report access portal, o Alerts of suspicious activity and/or changes in credit file information, o Provide a manifest of responses provided, o Electronic method for obtaining missing tradeline addresses, o Archive capability for DCSA requested Credit Reports for 60 days, o A test environment, to include test data to mirror production, with vendor testing support, o Written agreements with each of the three credit bureaus to document FCRA awareness, o Ability to provide detailed invoices and quality control reports.

2.3 Task Three: Written Monthly Status Reports

The contractor will provide a written monthly status report to the KO, CS, and COR following completion of prior month;

o Must be provided within 5 business days of prior month ending, o The monthly status report shall summarize the work ordered and work performed;

To include summary of the number of credit reports provided, itemized list of reports provided with sufficient detail to validate invoices

To include performance issues.

Monthly status reports shall be submitted in conjunction with monthly invoices.

The monthly status report shall include quality control information;

total number of queried items, number provided, number provided with errors, and other information as requested by the COR, KO, or CS.

2.4 Connection

2.4.1 The contractor must establish and maintain connections, until no longer required, to

DCSA legacy/current systems (PIPS and Mirador) and also the National Background

Investigation Services (NBIS) system. Contractors awarded an IDIQ are required to complete and submit an Interconnection Security Agreement (ISA). Full completion by the contractor and acceptance by the Government is a condition required prior to receiving award. An ISA template is provided as Attachment 3.

2.4.1.1 – Personnel Investigations Processing System (PIPS) (Legacy/Current)

2.4.1.2 – Mirador (Legacy/Current)

2.4.1.3 – National Background Investigation Services (NBIS) (Current/Future)

2.4.1.4 – Any future systems

3 SERVICE SUMMARY

The contract service requirements are summarized in performance objectives that relate directly to mission essential services. The performance threshold briefly describes the minimally acceptable levels of service required for each requirement. The Service Summary (SS) provides information on contract requirements and the expected level of contractor performance to be successful. These thresholds are critical to mission success. Procedures as set forth in the applicable Inspection clause in the contract will be used to remedy all deficiencies. The

Government retains the right to inspect any item included in the contract.

Performance

Objective

PWS

Paragraph Performance Threshold

Method of

Surveillance

SS # 1

Requests for single credit reports and tri-merge credit reports, must be provided back to the

Government, in the requested format.

2.1, 2.2 Results are to be provided as described in the PWS

98% of the time.

The system shall be available 24 hours a day 7 days a week.

100% Inspection

SS # 2

Reports shall be operational, accessible and without system errors.

2.1, 2.2 Results are to meet the standard 98% of the time.

Results must be readable, legible, error free, and timely.

100% Inspection

SS # 3

The contractor shall notify the COR of any unplanned outages which impact system availability.

6.10.1

0 instances of system outage without COR notification.

For unplanned system outages the contractor will notify the COR in writing and via phone within 2 hours.

As reported by COR

4 GOVERNMENT FURNISHED SUPPLIES AND SERVICES

4.1 Property

There will be no Government furnished property issued at either the IDIQ or task order level.

4.2 Services

The Government will not provide any services.

4.3 Facilities

The Government will not provide any facilities.

4.4 Utilities

The Government will not provide any utilities.

4.5 Equipment

The Government will not provide any equipment.

4.6 Materials

The Government will provide example templates for reporting format.

4.7 Connections

Upon award, the Government will provide awardees with various support in order to obtain connection to DCSA systems.

5 CONTRACTOR FURNISHED ITEMS AND SERVICES

5.1 Contractor Furnished Items and Responsibilities:

5.1.1 General: The Contractor shall furnish all supplies, equipment, facilities and services required to perform work under this IDIQ and any awarded Task Orders.

5.1.2 Personnel Security: The Contractor to include employees shall be required to be

U.S. Citizens and must include record of a U.S. Citizenship verification. There is no required level of investigation, but rather U.S. Citizenship verification. Any changes to the eligibility/clearance requirement or investigation requirement will be detailed in the specific task orders. All PII must be handled in accordance with the Privacy Act of 1974.The Contractor must be able to process Controlled

Unclassified Information (CUI) in accordance with DoDI 8510.01 and DoDI

5200.48 Controlled Unclassified Information (CUI).

5.1.3 Materials: The Contractor shall furnish any materials necessary for work within the PWS of the IDIQ and individual Task Orders.

5.1.4 Equipment: The Contractor shall furnish any equipment necessary for work within the PWS of the IDIQ and individual Task Orders.

5.1.5 Information: The Contractor will provide information through the 24 hour available system in order to satisfy the terms of the IDIQ.

6 SPECIAL REQUIREMENT/INSTRUCTIONS

6.1 Contractor Identification in the Government Workplace

When conversing with Government personnel during business meetings, over the telephone or via electronic mail, the contractor shall identify themselves as such to avoid situations arising where sensitive topics might be better discussed solely between Government employees. The contractor shall identify themselves on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify their company affiliation.

They must also ensure that all documents or reports produced by Contractors are suitably marked as Contractor products or that Contractor participation is appropriately disclosed.

6.2 Industrial Security

6.2.1 Personnel Security

6.2.1.1 The Contractor to include employees shall be required to be U.S. Citizens and must include record of a U.S. Citizenship verification. There is no required level of investigation, but rather U.S. Citizenship verification. Any changes to the eligibility/clearance requirement or investigation requirement will be detailed in the specific task orders. All PII must be handled in accordance with the

Privacy Act of 1974.The Contractor must be able to process Controlled

Unclassified Information (CUI) in accordance with DoDI 8510.01 and DoDI

5200.48 Controlled Unclassified Information (CUI).

6.2.2 Non-Disclosure Agreements

6.2.2.1 The Contractor's assigned personnel shall complete and sign a Non-Disclosure

Agreement regarding protection of sensitive Government and third-party

Contractor information.

6.2.3 Communications Security Monitoring: Telecommunications networks are continually subject to interception by unfriendly intelligence organizations. All communications within DoD organizations are subject to secure communications review. Contractor personnel are required to comply with FCRA, which contains additional security requirements beyond the contract. The Government may conduct monitoring and recording of electronic or voice communications originating from or terminating at DoD organizations at any time. The Contractor shall ensure all assigned personnel are aware that any time they communicate to or from a Government facility, they are subject to review procedures. The Contractor shall ensure wide and frequent dissemination of the above information to all employees dealing with Government information.

6.2.4 Controlled Unclassified Information (CUI). The Contractor shall comply with

DoDI 5200.48, Chapters 3 and 4, Programmatic and Dissemination, Decontrolling, and Destruction of CUI. This regulation sets policy and procedures for the marking, handling, transmitting, and safeguarding CUI material.

6.3 Inherently Governmental Functions. The Contractor shall not perform any inherently governmental functions as defined by FAR Subpart 7.5 or as defined by the Office of

Federal Procurement Policy Letter 11-0l Performance of inherently Governmental and

Critical Functions, February 13, 2012. All program decisions shall be the sole responsibility of the Government. The Contractor shall not make judgements and/or discretionary decisions or perform any other activities related to or are perceived to constitute inherently Governmental functions, the Contractor shall notify the COR or KO immediately.

6.4 Ethics. The Contractor shall not employ any person who is an employee of the US

Government if employing that person would create a conflict of interest. Additionally, the

Contractor shall not employ any person who is an employee of the DoD, either military or civilian, unless such person seeks and receives approval according to DoDD 5500-7, Joint

Ethics Regulation.

6.5 Professional Appearance of Work Space. The Contractor shall keep work space areas neat and orderly and avoid conditions leading to safety violations.

6.6 Non-Personal Services. The Government shall not supervise or task Contractor employees in any manner that generates actions of the nature of personal services, or that creates the perception of personal services. It is the responsibility of the Contractor to manage its employees directly and to guard against any actions that are of the nature of personal services, or give the perception of personal services to the Government or to Government personnel. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it is the Contractor’s responsibility to notify the KO immediately. Non-personal Contractor services shall not be used to perform work of a policy/decision making or management nature.

6.7 Privacy Act

6.7.1 Work on this contract requires the contractor to have access to Privacy Information.

The contractor shall adhere to the Privacy Act, Title 5 of the US Code, Section 552a and applicable Agency rules and regulations.

6.8 Location(s) of Work

Place of Performance: The work to be performed under this IDIQ and awarded Task Orders will be performed at Contractor Facilities.

6.9 Hours of Operation

6.9.1 The Government expects the contractor to establish 24 hours a day system accessibility. The contractor, at all times, shall maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the

Government facility is not closed for the below reasons.

6.9.2 Recognized Holidays. The contractor is not required to provide service on the following days:

New Year’s Day January 1st*

Martin Luther King’s Birthday Third Monday in January

President’s Day Third Monday in February

Memorial Day Last Monday in May

Juneteenth National Independence Day June 19*

Independence Day July 4th*

Labor Day First Monday in September

Columbus Day Second Monday in October

Veterans Day November 11th*

Thanksgiving Day Fourth Thurs in November

Christmas Day December 25th*

*If the holiday falls on Saturday, it is observed on Friday. If the holiday falls on a

Sunday, it is observed on Monday.

6.9.2.1 In addition to the days designated as holidays, the Government observes the following days:

• Any other day designated by Federal Statute

• Any other day designated by Executive Order

• Any other day designated by the President’s Proclamation

6.9.2.2 It is understood and agreed between the Government and the Contractor that observance of such days by Government personnel shall not otherwise be a reason for an additional period of performance, or entitlement of compensation except as set forth within the contract. In the event the Contractor's personnel work during the holiday, they may be reimbursed by the Contractor, however, no form of holiday or other premium compensation will be reimbursed either as a direct or indirect cost, other than their normal compensation for the time worked.

6.9.2.3 When the Federal, State, Local or other Governmental entity grants excused absence to its employees, assigned Contractor personnel may also be dismissed.

The Contractor agrees to continue to provide sufficient personnel to perform critical tasks already in operation or scheduled, and must be guided by the instructions issued by the KO or COR.

6.9.2.4 If Government personnel are unavailable due to furlough or any other reason, the Contractor must contact the KO or the COR to receive direction. It is the

Government's decision as to whether the contract price/cost will be affected.

Generally, the following situations apply:

Contractor personnel who are able to continue contract performance

(either on-site or at a site other than their normal workstation), must continue to work and the contract price shall not be reduced or increased.

Contractor personnel who are not able to continue contract performance

(e.g., support functions) may be asked to cease their work effort. This may result in a reduction to the contract.

6.10 Records

The contractor shall create, maintain, and dispose of only those Government required records that are specifically cited in this PWS or required by the provisions of a mandatory directive listed in any added Appendix, Applicable Publications & Instructions. If requested by the Government, the contractor shall provide the original record or a reproducible copy of any such record within five (5) workdays of receipt of the request.

6.11 Contractor Personnel Training

6.11.1 In accordance with DoD Instruction 5200.48 (DoDI 5200.48) dated March 6, 2020, Contractors are required to ensure all personnel receive and complete Initial and

Annual Refresher CUI education and training and maintain documentation of this training for audit purposes. Initial and Annual Refresher CUI security education, training and awareness on the required topics identified in Section 2002:30 of Title

32 CFR, including protection and management of CUI, to DoD personnel and contractors through the Center for Development of Security Excellence (CDSE).

6.11.1.1 CUI Courses and Resources Created for Industry:

6.11.1.1.1 The Center for Development of Security Excellence (CDSE) has developed an eLearning course titled “DoD Controlled Unclassified

Information (CUI) Training For Contractors (IF141.06.FY21.CTR).

The course fulfills CUI training requirements for industry.

6.11.1.1.2 CDSE has a CUI Toolkit available at

https://www.cdse.edu/toolkits/cui/current.html. The Toolkit includes training, policy documents, resources, and an FAQ video.

6.11.1.1.3 Review the DoD CUI Registry at https://www.dodcui.mil to become familiar with CUI organizational index groupings and CUI categories.

6.11.2 Training Requirements:

6.11.2.1 Contractor personnel performing under this contract shall complete all applicable Government training. Training shall be completed and reported to the COR within 30 calendar days of award and annual refresher training for the remaining contract duration. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR. This training shall be completed and reported to the COR within

30 calendar days of award and annual refresher training for the remaining contract duration.

6.11.2.1.1 The following training is required:

6.11.2.1.1.1 Operations Security (OPSEC) Awareness Training: All

Contractor personnel are required to take initial OPSEC Awareness training, in accordance with DoD M 5205.02-M within 30 calendar days of the start of the period of performance an annual thereafter.

6.11.2.1.1.2 DoD Mandatory Controlled Unclassified Information (CUI)

Training for Contractors: Contractor personnel with access to controlled unclassified information shall complete this training within 30 calendar days of the start of the PoP and annually thereafter in accordance with DoDI 5200.48, Controlled

Unclassified Information (CUI) dated 06 Mar 2020.

6.11.2.1.1.3 Intelligence Oversight Awareness Training: All

Counterintelligence (CI) and non-counterintelligence, contractor personnel - are required to complete Intelligence Oversight training in accordance with DoD 5240.1-R and DSSR 18-9.

6.11.2.1.1.4 Privacy Act and Personally Identifiable Information

Training: DoD contractor personnel are required to take Privacy Act and Personally Identifiable Information training in accordance with

DoD D 5400.11, DoD M 5400.11-R, and OMB Cir A-130.

6.11.2.1.1.5 DCSA Annual Security Awareness: Required by all

personnel supporting DCSA.

6.11.3 The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR or to the KO. This training shall be completed and reported to the COR within 30 calendar days of contract assignment and annual refresher training for the remaining contract duration.

6.12 Kick-off Meeting and Quarterly Meetings

The contractor shall attend an initial kick-off meeting 5 days after contract award. The

KO, COR, and other Government personnel, as appropriate, may meet quarterly with the contractor to review the contractor's performance. At these meetings, the KO will apprise the contractor of how the Government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced.

Appropriate action shall be taken to resolve outstanding issues. The contractor shall provide minutes of these meetings to the Government within 3 business days. These meetings shall be at no additional cost to the Government.

6.13 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational

Conflict of Interests (OCI) as defined in FAR subpart 9.5. The Contractor shall notify the

KO immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the KO to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the KO and in the event the KO unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the KO may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the

OCI.

6.14 Contractor Travel – NO TRAVEL IS REQUIRED.

6.15 Contractor Manpower Reporting: The Contractor shall report ALL Contractor labor hours (including Subcontractor labor hours) required for performance of services provided under this contract for the DCSA via a secure data collection site. The

Contractor is required to completely fill in all required data fields using the following web address: https://www.sam.gov. Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs

October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. Contractors may direct questions to the help desk at: https://www.sam.gov. (see FAR Clause 52.204-14 –

Service Contract Reporting Requirements).

6.16 Contract Management: The Contractor shall provide a Contract Manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the Contractor when the manager is absent shall be designated in writing to the KO. The Contract Manager or alternate shall have full authority to act for the

Contractor on all contract matters relating to daily operation of this contract. The Contract

Manager or alternate shall be available between 8:00 a.m. to 4:30p.m., Monday thru

Friday except Federal holidays or when the Government facility is closed for administrative reasons.

6.17 Staffing and Retention

6.17.1 Phase-In: The first 30 days after contract start will constitute the phase-in period.

During the phase-in period, the Contractor shall prepare to assume full responsibility for all areas of operation in accordance with the terms and conditions of this contract. The Contractor shall take all actions necessary for a smooth transition of the contracted operations.

https://www.sam.gov/ https://www.sam.gov/

6.17.2 Phase-Out: The Contractor shall submit an updated Phase-Out Continuity Plan to affect a smooth and orderly transfer of contract responsibility to a successor. The

Contractor shall submit the Phase-Out Continuity Plan to the COR for evaluation and approval six- months (180 days) after contract start. The plan shall full describe how the Contractor shall, at a minimum, approach the following issues:

Employee notification;

Retention of Contract Management;

Turn-over of work-in-progress;

Electronic continuity folders;

Data and information transfer; and, Any other action required to ensure continuity of operations.

Contractor’s Phase-Out Procedures shall not disrupt or adversely impact the day-to-day conduct of Government business. The Contractor shall provide the COR with copies of changes and revisions for review and approval prior to implementation of this Phase-Out Plan. The Contractor shall fully cooperate with the succeeding Contractor and the Government so as not to interfere with their work duties.

6.17.3 List of Employees. The Contractor shall maintain a current listing of employees assigned under this contract and send to COR at start of the contract, NLT 5 days from award, and if any employees change. The list shall include the employee's name, and U.S. citizenship. The list shall be validated and signed by the company

Facility Security Officer (FSO) or other designated authorized person for personnel security, and provided to the KO and Program Manager. An updated listing shall be provided upon request.

6.17.4 Contractor professionalism. The contractor shall:

6.17.4.1 Present a professional appearance and maintain professional demeanor and conduct at all times.

6.17.4.2 Conduct their work assignments IAW project schedules

6.17.4.3 Function effectively and efficiently during extended periods of high pressure and stress.

6.17.4.4 Function as an integral member of a team of highly trained professionals responsible for the safety and security of personnel and resources.

6.18 Quality Control

6.18.1 Quality Assurance. The Government shall rely on the Contractors’ existing quality assurance system as the method to ensure that the requirements of the contract and performance thresholds are met; however, the Government reserves the right to monitor and evaluate the quality of services provided and compliance with the contract terms and conditions at any time.

6.18.2 Quality Control Plan (QCP). The Contractor shall develop and maintain an effective quality control program to ensure services are performed IAW this PWS, applicable laws and regulations, and best commercial practices. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services with special emphasis placed on those services listed in this PWS. The Contractor’s quality control program is the means by which it assures itself that the work complies with the requirement of the contract.

6.19 Emergency Operations/Mission Essential Personnel

6.19.1 Continuation of Essential Contractor Services during Crisis. All services in this

PWS HAVE NOT been defined or designated as essential services for performance during crisis IAW DFARs 252.237-7023, “Continuation of Essential Contractor

Services.”

6.20 Section 508 Accessibility Standards

The following Section 508 Accessibility Standard(s) are applicable to this application:

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment

Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use information and communication technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public who have disabilities must have access to, and use of, information and data that is comparable to people without disabilities.

1. Products, platforms and services delivered as part of this work statement that are ICT, or contain ICT, must conform to the Revised 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps. A, C & D, and at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines.

Item that contains ICT: Credit Reports

Applicable Functional Performance Criteria: All functional performance criteria apply when using an alternative design or technology that achieves substantially equivalent or greater accessibility and usability by individuals with disabilities, than would be provided by conformance to one or more of the requirements in

Chapters 4-6 of the Revised 508 Standards, or when Chapters 4-6 do not address one or more functions of ICT.

Applicable requirements for software features and components: All WCAG Level

AA Success Criteria, 502 Interoperability with Assistive Technology, 503

Application Applicable requirements for hardware features and components: All requirements apply.

Applicable support services and documentation: All requirements apply.

https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines

7 DELIVERABLES

Reports and other data required in this PWS shall be submitted IAW the Contract Data

Requirements List (CDRL) below:

CDRL

Data Item

Number

Data Item

Description

PWS

Para.

Delivery Schedule

A001 No DID found utilizing

FAR 46.105

Quality Control Plan 6.18.2 Shall be provided 60 days following award

A002 DI-MGMT-

80368A

Monthly Status Report 2.3 Shall be provided within 5 business days of prior month ending

A003 DI-MGMT-

81945

Phase-Out Transition

Plan

6.17.2 Shall be provided 180 days

after contract start

A004 DI-ADMIN-

81250C

Meeting Minutes 6.12 Shall be provided within 3 business days following meeting

A005 No DID found utilizing

FAR 52.203-

Code of Business

Ethics and Conduct

6.4 & applicable clause

Shall be provided 30 days following award

*DD1423s (CDRLS) and DIDs will be attached IAW Appendix D.

APPENDIX A – ACRONYMS AND ABBREVIATIONS AND DEFINITIONS

ACRONYMS:

CFR Code of Federal Regulations

COR Contracting Officer Representative

CS Contract Specialist

CUI Controlled Unclassified Information

DCSA Defense Counterintelligence and Security Agency

DFARS Defense Federal Acquisition Regulation Supplement

DOD Department of Defense

FAR Federal Acquisition Regulation

FedRAMP Federal Risk and Authorization Management Program

KO Contracting Officer

NBIS National Background Investigation Services

OCI Organizational Conflict of Interest

OPSEC Operational Security

PII Personally Identifiable Information

POC Point of Contact

PRS Performance Requirements Summary

PWS Performance Work Statement

QA Quality Assurance

QAP Quality Assurance Program

QASP Quality Assurance Surveillance Plan

QC Quality Control

QCP Quality Control Program

TE Technical Exhibit

DEFINITIONS:

Contractor. An offeror, supplier or vendor awarded a contract to provide specific supplies or service to the Government. The term used in this contract refers to the prime.

Contracting Officer. A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the Government. Note: The only individual who can legally bind the Government.

Contracting Officer’s Representative. An employee of the U.S. Government appointed by the

Contracting Officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.

Defective Service. A service output that does not meet the standard of performance associated with the Performance Work Statement.

Deliverable. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.

Physical Security. Actions that prevent the loss or damage of Government property.

Quality Assurance. The Government procedures to verify that services being performed by the

Contractor are performed according to acceptable standards.

Quality Assurance Surveillance Plan. An organized written document specifying the surveillance methodology to be used for surveillance of Contractor performance.

Quality Control. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.

Subcontractor. One that enters into a contract with a prime Contractor. The Government does not have privity of contract with the Subcontractor.

Work Day. The number of hours per day the Contractor provides services in accordance with the contract.

Work Week. Monday through Friday, other than Batch processing Tuesday through Saturday.

APPENDIX B – APPLICABLE PUBLICATIONS & INSTRUCTIONS

The Contractor must abide by all applicable regulations, publications, manuals, and local policies and procedures. The services provided must meet the DoD guidelines and requirements for the security and protection of DoD information. Specifics will be expounded upon at the task order level.

Document Number Document Title Date of Document

15 U.S.C. §§ 1681

Public Law 91-508

Title VI of the Consumer

Credit Protection Act

Fair Credit Reporting Act (FCRA) 26 October 1970

As amended

32 CFR Part 117 National Industrial Security Program

Operating Manual (NISPOM) 13 July 2021

DoDI 5200.48 Controlled Unclassified Information 06 March 2020

32 CFR 2002

National Archives and Records

Administration, Controlled

Unclassified Information

14 September 2016

DoDD 5400.07 DoD Freedom of Information Act

(FOIA) Program 05 April 2019

DoDM 5400.07 DoD Freedom of Information Act

(FOIA) Program 25 January 2017

DoDI 8500.01, DoDI

8510.01

Cybersecurity, Risk Management

Framework for DoD Information

Technology

07 October 2019

National Institute of

Standards and Technology

(NIST) Special

Publication 800-171 Rev.

Protecting Controlled Unclassified

Information in Nonfederal Systems and Organizations

28 January 2021

DoDD 5205.02E DoD Operations Security (OPSEC)

Program 20 August 2020

DoDI 5230.09 Clearance of DoD Information for

Public Release 25 January 2019

DoDI 5230.29 Security and Policy Review of DoD

Information for Public Release 14 April 2017

DoDI 5400.04 Provision of Information to

Congress 17 March 2009

DoDI 8170.01 Online Information Management and

Electronic Messaging 24 August 2021

CJCSI 6510.01D

Information Assurance (IA) and

Computer Network Defense (CND) 15 June 2004

APPENDIX C: ESTIMATED WORKLOAD DATA

Requirement Annual Estimate

Single Credit Reports 4,137,631

Tri-Merge Credit Reports 665,600

APPENDIX D: ATTACHMENTS

Reference Description

Attachment 2 PWS CDRLS

Attachment 3 PWS Interconnection Security Agreement

Attachment 4 PWS Single Report Examples

Attachment 5 PWS Tri-Merge Report Examples

Attachment 6 Ordering Guide (OG)

Attachment 7 OG PWS Template

Attachment 8 OG QASP Template

Attachment 9 OG TO Price Workbook

File details come from the government source that posted it. Updated .