Appendix B - Project Other Terms and Conditions.docx
DOCX document 310 KB Posted
- Attached to
- Self-Propelled Howitzer-Modernization (SPH-M) Mobile Tactical Cannon (MTC) Draft #2 and Industry Day Slides/Q&A Federal contract opportunity
- Solicitation number
- SPH-M_MTC_2
- Issued by
- Department of the Army
About this file
This document is Appendix B to a Prototype Project Agreement for the Self-Propelled Howitzer-Modernization (SPH-M) Mobile Tactical Cannon (MTC) program, containing the Other Terms and Conditions (OTCs) governing contract performance. The appendix is organized into five sections covering required terms, OPSEC/security requirements, government-furnished property management, patent rights and data rights, and miscellaneous conditions. Section A includes mandatory clauses addressing prohibition on covered telecommunications equipment (particularly equipment from Chinese manufacturers Huawei, ZTE, Hikvision, Dahua, and Hytera), safeguarding of covered defense information with cyber incident reporting requirements to https://dibnet.dod.mil, NIST SP 800-171 compliance and assessment procedures, duty-free entry for eligible products and qualifying country end products, and export control compliance. Section B establishes comprehensive security requirements including antiterrorism awareness training (AT Level I within 30 days), Common Access Card (CAC) processing through the Trusted Associate Sponsorship System (TASS), Information Assurance training and certification per DoD 8570.01-M, OPSEC Level II coordinator designation, iWATCH program briefing, threat awareness reporting program (TARP) training, and disclosure prohibitions for unclassified information without prior written approval from the Agreements Officer.
Section C addresses government property management, including contractor responsibility for control, use, preservation, and maintenance of all government property from acquisition through disposition, with specific procedures for recording transactions, conducting physical inventories, investigating losses, and processing inventory disposal schedules within defined timeframes (30 days for determination of excess property, 60 days following deliveries, 120 days following termination). Section D governs intellectual property rights, establishing that the government receives unlimited rights in data developed exclusively with government funds, government purpose rights (5-year period) in mixed-funding data, and limited rights in privately-developed data, with specific marking and assertion requirements for restrictive legends on technical data and computer software. Section E contains miscellaneous conditions covering hazardous material identification and material safety data sheet submission, safeguarding of arms, ammunition, and explosives per DoD Manual 5100.76, ammunition and explosives safety compliance with DoD 4145.26-M, quick-closeout procedures for settlements under $1 million or 10 percent of contract value, cloud computing security requirements per the Cloud Computing Security Requirements Guide, Wide Area WorkFlow (WAWF) payment processing at https://wawf.eb.mil, and specialty metals restrictions requiring U.S. production or melting.
View the file
Other files for this federal contract opportunity
Show all 31
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Appendix B Other Terms and Conditions (OTCs)
Appendix B contains a list of terms and conditions. Some terms and conditions are derived from the FAR and DFARs. Those terms and conditions are annotated with a FAR and DFARS clause number and may have been tailored for this Other Transaction Agreement (OTA). Some of the terms and conditions contain references to a clause, in those instances, the clause refers to that term or condition or to other FAR, DFARS, or Army Contracting Command – Detroit Arsenal (ACC-DTA) Local clauses as references. Some terms and conditions are derived from ACC-DTA local clauses. Those terms and conditions are annotated with a reference to ACC-DTA and may have been tailored for this OTA.
Following is a description of each Appendix B section and the full text of each term and condition within each section.
Section A – Required Terms and Conditions
Section B – OPSEC/Security Terms and Conditions
Section C – Government Furnished Property (GFP) Terms and Conditions
Section D – Patent Rights, Data Rights and Copyrights Terms and Conditions
Section E – Miscellaneous Terms and Conditions
Section A – Required Terms and Conditions
A.1. Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment
(See Offeror’s Certification in Appendix C - Representations and Certifications, Section D)
(a) Definitions. As used in this clause— Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet).
Covered foreign country means The People’s Republic of China.
Covered telecommunications equipment or services means–
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary or affiliate of such entities);
(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);
(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.
Critical technology means–
(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled-
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or
(ii) For reasons relating to regional stability or surreptitious listening;
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).
Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow the use of another's network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone provider A to a customer of telephone company B) or sharing data and other information resources.
Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include an internal or third-party audit.
Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high.
Substantial or essential component means any component necessary for the proper function or performance of a piece of equipment, system, or service.
(b) Prohibition.
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract/agreement to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The contractor is prohibited from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104.
(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract/agreement, or extending or renewing a contract/agreement, with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph
(c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract/agreement.
(c) Exceptions. This clause does not prohibit contractors from providing—
(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(d) Reporting requirement.
(1) In the event the contractor identifies covered telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during PPA performance, or the contractor is notified of such by a subcontractor at any tier or by any other source, the contractor shall report the information in paragraph (d)(2) of this clause to the Agreements Officer, unless elsewhere in this PPA are established procedures for reporting the information; in the case of the Department of Defense, the contractor shall report to the website at https://dibnet.dod.mil.
(2) The contractor shall report the following information pursuant to paragraph (d)(1) of this clause.
(i) Within one business day from the date of such identification or notification: the PPA number; the order number(s), if applicable; supplier name; supplier unique entity identifier (if known); supplier Commercial and Government Entity (CAGE) code (if known); brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available information about mitigation actions undertaken or recommended. In addition, the contractor shall describe the efforts it undertook to prevent use or submission of covered telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.
(e) Subcontracts. The contractor shall insert the substance of this clause, including this paragraph (e) and excluding paragraph (b)(2), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial items.
Referenced from FAR Clause 52.204-25 [End of A.1]
A.2. SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING
(a) Definitions. As used in this clause—
“Adequate security” means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
“Compromise” means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
“Contractor attributional/proprietary information” means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
“Controlled technical information” means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
“Covered contractor information system” means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
“Covered defense information” means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government wide policies, and is—
(1) Marked or otherwise identified in the PPA and provided to the contractor by or on behalf of DoD in support of the performance of the PPA; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the PPA.
“Cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
“Forensic analysis” means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
“Information system” means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
“Malicious software” means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
“Media” means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
“Operationally critical support’’ means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
“Rapidly report” means within 72 hours of discovery of any cyber incident.
“Technical information” means technical data or computer software, as those terms are defined in Appendix A, Article IX: Data Rights and Copy Rights, regardless of whether or not the clause is incorporated in the solicitation or PPA. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the contractor shall implement, at a minimum, the following information security protections:
(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:
(i) Cloud computing services shall be subject to the security requirements specified in the clause E.7, Cloud Computing Services, of this PPA.
(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this PPA.
(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:
(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171) in effect at the time the solicitation is issued or as authorized by the Agreements Officer.
(ii)(A) The contractor shall implement NIST SP 800-171, as soon as practical.
(B) The contractor shall submit requests to vary from NIST SP 800-171 in writing to the Agreements Officer, for consideration by the DoD CIO. The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
(C) If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Agreements Officer when requesting its recognition under this PPA.
(D) If the contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this PPA, the contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ( https://www.fedramp.gov/documents-templates/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
(3) Apply other information systems security measures when the contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
(c) Cyber incident reporting requirement.
(1) When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the PPA that are designated as operationally critical support and identified in the PPA, the contractor shall—
(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and
(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.
(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.
(d) Malicious software. When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with instructions provided by DC3 or the Agreements Officer. Do not send the malicious software to the Agreements Officer.
(e) Media preservation and protection. When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Agreements Officer will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.
(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.
(i) Use and release of contractor attributional/proprietary information not created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD—
(1) To entities with missions that may be affected by such information;
(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
(3) To Government entities that conduct counterintelligence or law enforcement investigations;
(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or
(5) To a support services contractor (“recipient”) that is directly supporting Government activities under a contract/agreement that includes the clause at E.5, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government’s use and release of such information.
(k) The contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the contractor’s responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this PPA, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(m) Subcontracts. The contractor shall—
(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial items, without alteration, except to identify the parties. The contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Agreements Officer; and
(2) Require subcontractors to—
(i) Notify the prime contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Agreements Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause; and
(ii) Provide the incident report number, automatically assigned by DoD, to the prime contractor (or next higher- tier subcontractor) as soon as practicable, when reporting a cyber incident to DoD as required in paragraph (c) of this clause.
Referenced from DFARS Clause 252.204-7012
[End of A.2]
A.3. NIST SP 800-171 DOD ASSESSMENT REQUIREMENTS
(a) Definitions.
“Basic Assessment” means a contractor’s self-assessment of the contractor’s implementation of NIST SP 800-171 that—
(1) Is based on the contractor’s review of their system security plan(s) associated with covered contractor information system(s);
(2) Is conducted in accordance with the NIST SP 800-171 DoD Assessment Methodology; and
(3) Results in a confidence level of “Low” in the resulting score, because it is a self-generated score.
“Covered contractor information system” has the meaning given in the clause A.2, Safeguarding Covered Defense Information and Cyber Incident Reporting, of this PPA.
“High Assessment” means an assessment that is conducted by Government personnel using NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information that—
(1) Consists of—
(i) A review of a contractor’s Basic Assessment;
(ii) A thorough document review;
(iii) Verification, examination, and demonstration of a contractor’s system security plan to validate that NIST SP 800-171 security requirements have been implemented as described in the contractor’s system security plan; and
(iv) Discussions with the contractor to obtain additional information or clarification, as needed; and
(2) Results in a confidence level of “High” in the resulting score.
“Medium Assessment” means an assessment conducted by the Government that—
(1) Consists of—
(i) A review of a contractor’s Basic Assessment;
(ii) A thorough document review; and
(iii) Discussions with the contractor to obtain additional information or clarification, as needed; and
(2) Results in a confidence level of “Medium” in the resulting score.
(b) Applicability. This clause applies to covered contractor information systems that are required to comply with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, in accordance with clause at A.2, Safeguarding Covered Defense Information and Cyber Incident Reporting, of this PPA.
(c) Requirements. The contractor shall provide access to its facilities, systems, and personnel necessary for the Government to conduct a Medium or High NIST SP 800-171 DoD Assessment, as described in NIST SP 800-171 DoD Assessment Methodology at https://www.acq.osd.mil/asda/dpc/cp/cyber/safeguarding.html#nistSP800171, if necessary.
Procedures. Summary level scores for all assessments will be posted in the Supplier Performance Risk System (SPRS) (https://www.sprs.csd.disa.mil/) to provide DoD Components visibility into the summary level scores of strategic assessments.
(1) Basic Assessments. A contractor may submit, via encrypted email, summary level scores of Basic Assessments conducted in accordance with the NIST SP 800-171 DoD Assessment Methodology to webptsmh@navy.mil for posting to SPRS.
(i) The email shall include the following information:
(A) Version of NIST SP 800-171 against which the assessment was conducted.
(B) Organization conducting the assessment (e.g., contractor self-assessment).
(C) For each system security plan (security requirement 3.12.4) supporting the performance of a DoD agreement—
(1) All industry Commercial and Government Entity (CAGE) code(s) associated with the information system(s) addressed by the system security plan; and
(2) A brief description of the system security plan architecture, if more than one plan exists.
(D) Date the assessment was completed.
(E) Summary level score (e.g., 95 out of 110, NOT the individual value for each requirement).
(F) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.
(ii) If multiple system security plans are addressed in the email described at paragraph (b)(1)(i) of this section, the contractor shall use the following format for the report:
| System Security Plan |
| CAGE |
Codes supported by this plan
| Brief description of the plan architecture |
| Date of assessment |
| Total Score |
| Date score of 110 will be achieved |
System Security Plan CAGE Codes supported by this plan Brief description of the plan architecture Date of assessment Total Score Date score of 110 will achieved
(2) Medium and High Assessments. DoD will post the following Medium and/or High Assessment summary level scores to SPRS for each system security plan assessed:
(i) The standard assessed (e.g., NIST SP 800-171 Rev 1).
(ii) Organization conducting the assessment, e.g., DCMA, or a specific organization (identified by Department of Defense Activity Address Code (DoDAAC)).
(iii) All industry CAGE code(s) associated with the information system(s) addressed by the system security plan.
(iv) A brief description of the system security plan architecture, if more than one system security plan exists.
(v) Date and level of the assessment, i.e., medium or high.
(vi) Summary level score (e.g., 105 out of 110, not the individual value assigned for each requirement).
(vii) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.
(e) Rebuttals.
(1) DoD will provide Medium and High Assessment summary level scores to the contractor and offer the opportunity for rebuttal and adjudication of assessment summary level scores prior to posting the summary level scores to SPRS (see SPRS User’s Guide https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf).
(2) Upon completion of each assessment, the contractor has 14 business days to provide additional information to demonstrate that they meet any security requirements not observed by the assessment team or to rebut the findings that may be of question.
(f) Accessibility.
(1) Assessment summary level scores posted in SPRS are available to DoD personnel, and are protected, in accordance with the standards set forth in DoD Instruction 5000.79, Defense-wide Sharing and Use of Supplier and Product Performance Information (PI).
(2) Authorized representatives of the contractor for which the assessment was conducted may access SPRS to view their own summary level scores, in accordance with the SPRS Software User’s Guide for Awardees/Contractors available at https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf.
(3) A High NIST SP 800-171 DoD Assessment may result in documentation in addition to that listed in this clause. DoD will retain and protect any such documentation as “Controlled Unclassified Information (CUI)” and intended for internal DoD use only. The information will be protected against unauthorized use and release, including through the exercise of applicable exemptions under the Freedom of Information Act (e.g., Exemption 4 covers trade secrets and commercial or financial information obtained from a contractor that is privileged or confidential).
(g) Subcontracts.
(1) The contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial items (excluding COTS items).
(2) The contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with clause A.2 of this PPA, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment, as described in https://www.acq.osd.mil/asda/dpc/cp/cyber/safeguarding.html#nistSP800171 for all covered contractor information systems relevant to its offer that are not part of an information technology service or system operated on behalf of the Government.
(3) If a subcontractor does not have summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) posted in SPRS, the subcontractor may conduct and submit a Basic Assessment, in accordance with the NIST SP 800-171 DoD Assessment Methodology, to webptsmh@navy.mil for posting to SPRS along with the information required by paragraph (d) of this clause.
Referenced from DFARS clause 252.204-7020 [End of A.3]
A.4. DUTY-FREE ENTRY
(a) Definitions. As used in this clause—
“Component,” means any item supplied to the Government as part of an end product or of another component.
“Customs territory of the United States” means the 50 States, the District of Columbia, and Puerto Rico.
“Eligible product” means—
(1) “Designated country end product,” means a World Trade Organization Government Procurement Agreement (WTO GPA) country end product, a Free Trade Agreement country end product, a least developed country end product, or a Caribbean Basin country end product.
(2) Free Trade Agreement country end product, other than a Bahraini end product, a Moroccan end product, a Panamanian end product, or a Peruvian end product,
(i) “Moroccan end product” means an article that—
(A) Is wholly the growth, product, or manufacture of Morocco; or
(B) In the case of an article that consists in whole or in part of materials from another country, has been substantially transformed in Morocco into a new and different article of commerce with a name, character, or use distinct from that of the article or articles from which it was transformed. The term refers to a product offered for purchase under a supply agreement, but for purposes of calculating the value of the end product includes services (except transportation services) incidental to its supply, provided that the value of those incidental services does not exceed the value of the product itself.
(ii) “Panamanian end product” means an article that—
(A) Is wholly the growth, product, or manufacture of Panama; or
(B) In the case of an article that consists in whole or in part of materials from another country, has been substantially transformed in Panama into a new and different article of commerce with a name, character, or use distinct from that of the article or articles from which it was transformed. The term refers to a product offered for purchase under a supply agreement, but for purposes of calculating the value of the end product includes services (except transportation services) incidental to its supply, provided that the value of those incidental services does not exceed the value of the product itself.
(iii) “Peruvian end product” means an article that—
(A) Is wholly the growth, product, or manufacture of Peru; or
(B) In the case of an article that consists in whole or in part of materials from another country, has been substantially transformed in Peru into a new and different article of commerce with a name, character, or use distinct from that of the article or articles from which it was transformed. The term refers to a product offered for purchase under a supply agreement, but for purposes of calculating the value of the end product includes services (except transportation services) incidental to its supply, provided that the value of those incidental services does not exceed the value of the product itself.
(3) Free Trade Agreement country end product other than a Bahraini end product, Korean end product, Moroccan end product, Panamanian end product, or Peruvian end product (see above sections (a)(2)(i), (a)(2)(ii), and (a)(2)(iii) for Moroccan end product, Panamanian end product, or Peruvian end product).
(i) “Korean end product” means an article that—
(A) Is wholly the growth, product, or manufacture of Korea; or
(B) In the case of an article that consists in whole or in part of materials from another country, has been substantially transformed in Korea (Republic of) into a new and different article of commerce with a name, character, or use distinct from that of the article or articles from which it was transformed. The term refers to a product offered for purchase under a supply agreement, but for purposes of calculating the value of the end product, includes services (except transportation services) incidental to its supply, provided that the value of those incidental services does not exceed the value of the product itself.
“Qualifying country” means a country with a reciprocal defense procurement memorandum of understanding or international agreement with the United States in which both countries agree to remove barriers to purchases of supplies produced in the other country or services performed by sources of the other country, and the memorandum or agreement complies, where applicable, with the requirements of section 36 of the Arms Export Control Act (22 U.S.C. 2776) and with 10 U.S.C. 2457. Accordingly, the following are qualifying countries:
Australia Austria Belgium Canada Czech Republic Denmark Egypt Estonia Finland France Germany Greece Israel Italy Japan Latvia Lithuania Luxembourg Netherlands Norway Poland Portugal Slovenia Spain Sweden Switzerland Turkey United Kingdom of Great Britain and Northern Ireland.
“Qualifying country end product” means—
(1) An unmanufactured end product mined or produced in a qualifying country; or
(2) An end product manufactured in a qualifying country if—
(i) The cost of the following types of components exceeds 60 percent of the cost of all its components, except that the percentage will be 65 percent for items delivered in calendar years 2024 through 2028 and 75 percent for items delivered starting in calendar year 2029, unless an alternate percentage is established for an agreement:
(A) Components mined, produced, or manufactured in a qualifying country.
(B) Components mined, produced, or manufactured in the United States.
(C) Components of foreign origin of a class or kind for which the Government has determined that sufficient and reasonably available commercial quantities of a satisfactory quality are not mined, produced, or manufactured in the United States; or
(ii) The end product is a COTS item.
(b) Except as provided in paragraph (i) of this clause, or unless supplies were imported into the customs territory of the United States before the date of this agreement or the applicable subagreement, the price of this agreement shall not include any amount for duty on—
(1) End items that are eligible products or qualifying country end products;
(2) Components (including, without limitation, raw materials and intermediate assemblies) produced or made in qualifying countries, that are to be incorporated in U.S.- made end products to be delivered under this agreement; or
(3) Other supplies for which the Contractor estimates that duty will exceed $300 per shipment into the customs territory of the United States.
(c) The Contractor shall—
(1) Claim duty-free entry only for supplies that the Contractor intends to deliver to the Government under this agreement, either as end items or components of end items; and
(2) Pay duty on supplies, or any portion thereof, that are diverted to nongovernmental use, other than—
(i) Scrap or salvage; or
(ii) Competitive sale made, directed, or authorized by the Agreements Officer.
(d) Except as the Contractor may otherwise agree, the Government will execute duty-free entry certificates and will afford such assistance as appropriate to obtain the duty-free entry of supplies—
(1) For which no duty is included in the agreement price in accordance with paragraph (b) of this clause; and
(2) For which shipping documents bear the notation specified in paragraph (e) of this clause.
(e) For foreign supplies for which the Government will issue duty-free entry certificates in accordance with this clause, shipping documents submitted to Customs shall—
(1) Consign the shipments to the appropriate—
(i) Military department in care of the Contractor, including the Contractor's delivery address; or
(ii) Military installation; and
(2) Include the following information:
(i) Prime agreement number and, if applicable, delivery order number.
(ii) Number of the subagreement for foreign supplies, if applicable.
(iii) Identification of the carrier.
(iv)
(A) For direct shipments to a U.S. military installation, the notation: “UNITED STATES GOVERNMENT, DEPARTMENT OF DEFENSE Duty-Free Entry to be claimed pursuant to Section XXII, Chapter 98, Subchapter VIII, Item 9808.00.30 of the Harmonized Tariff Schedule of the United States. Upon arrival of shipment at the appropriate port of entry, District Director of Customs, please release shipment under 19 CFR Part 142 and notify Commander, Defense Contract Management Agency (DCMA), St. Louis, MO, ATTN: Duty Free Entry Team, 1222 Spruce Street, Room 9.300, St. Louis, MO 63103-2812, for execution of Customs Form 7501, 7501A, or 7506 and any required duty-free entry certificates.”
(B) If the shipment will be consigned to other than a military installation, e.g., a domestic contractor's plant, the shipping document notation shall be altered to include the name and address of the contractor, agent, or broker who will notify Commander, DCMA New York, for execution of the duty-free entry certificate. (If the shipment will be consigned to a contractor’s plant and no duty-free entry certificate is required due to a trade agreement, the Contractor shall claim duty-free entry under the applicable trade agreement and shall comply with the U.S. Customs Service requirements. No notification to Commander, DCMA New York, is required.)
(v) Gross weight in pounds (if freight is based on space tonnage, state cubic feet in addition to gross shipping weight).
(vi) Estimated value in U.S. dollars.
(vii) Activity address number of the contract administration office administering the prime agreement, e.g., for DCMA Dayton, S3605A.
(f) Preparation of customs forms.
(1)
(i) Except for shipments consigned to a military installation, the Contractor shall—
(A) Prepare any customs forms required for the entry of foreign supplies into the customs territory of the United States in connection with this agreement; and
(B) Submit the completed customs forms to the District Director of Customs, with a copy to DCMA NY for execution of any required duty-free entry certificates.
(ii) Shipments consigned directly to a military installation will be released in accordance with sections 10.101 and 10.102 of the U.S. Customs regulations.
(2) For shipments containing both supplies that are to be accorded duty-free entry and supplies that are not, the Contractor shall identify on the customs forms those items that are eligible for duty-free entry.
(g) The Contractor shall—
(1) Prepare (if the Contractor is a foreign supplier), or shall instruct the foreign supplier to prepare, a sufficient number of copies of the bill of lading (or other shipping document) so that at least two of the copies accompanying the shipment will be available for use by the District Director of Customs at the port of entry;
(2) Consign the shipment as specified in paragraph (e) of this clause; and
(3) Mark on the exterior of all packages—
(i) “UNITED STATES GOVERNMENT, DEPARTMENT OF DEFENSE”; and
(ii) The activity address number of the contract administration office administering the prime agreement.
(h) The Contractor shall notify the Administrative Agreements Officer (AAO) in writing of any purchase of eligible products or qualifying country supplies to be accorded duty-free entry, that are to be imported into the customs territory of the United States for delivery to the Government or for incorporation in end items to be delivered to the Government. The Contractor shall furnish the notice to the AAO immediately upon award to the supplier and shall include in the notice—
(1) The Contractor’s name, address, and Commercial and Government Entity (CAGE) code;
(2) Prime agreement number and, if applicable, delivery order number;
(3) Total dollar value of the prime agreement or delivery order;
(4) Date of the last scheduled delivery under the prime agreement or delivery order;
(5) Foreign supplier's name and address;
(6) Number of the subagreement for foreign supplies;
(7) Total dollar value of the subagreement for foreign supplies;
(8) Date of the last scheduled delivery under the subagreement for foreign supplies;
(9) List of items purchased;
(10) An agreement that the Contractor will pay duty on supplies, or any portion thereof, that are diverted to nongovernmental use other than—
(i) Scrap or salvage; or
(ii) Competitive sale made, directed, or authorized by the Agreements Officer;
(11) Country of origin; and
(12) Scheduled delivery date(s).
(i) This clause does not apply to purchases of eligible products or qualifying country supplies in connection with this agreement if—
(1) The supplies are identical in nature to supplies purchased by the Contractor or any subcontractor in connection with its commercial business; and
(2) It is not economical or feasible to account for such supplies so as to ensure that the amount of the supplies for which duty-free entry is claimed does not exceed the amount purchased in connection with this agreement.
(j) The Contractor shall—
(1) Insert the substance of this clause, including this paragraph (j), in all subagreements for—
(i) Qualifying country components; or
(ii) Nonqualifying country components for which the Contractor estimates that duty will exceed $200 per unit;
(2) Require subcontractors to include the number of this contract/agreement on all shipping documents submitted to Customs for supplies for which duty-free entry is claimed pursuant to this clause; and
(3) Include in applicable subagreements—
(i) The name and address of the AAO for this agreement;
(ii) The name, address, and activity address number of the contract administration office specified in this agreement; and
(iii) The information required by paragraphs (h)(1), (2), and (3) of this clause.
Referenced from FAR clause 252.225-7013
[End of A.4]
Section B – OPSEC/Security Terms and Conditions
B.1. ANTITERRORISM AWARENESS TRAINING FOR CONTRACTORS (AT LEVEL I TRAINING)
All contractor employees, including subcontractor employees, requiring access to Army installations, facilities, or controlled access areas shall complete AT Level I awareness training within 30 calendar days after PPA start date or effective date of incorporation of this requirement into the PPA, whichever applies. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee to the Agreement Officer’s Representative (AOR) (or to the Agreements Officer, if an AOR is not assigned) within 30 calendar days after completion of training by all employees and subcontractor personnel. AT Level I awareness training is available at https://jkodirect.jten.mil Referenced from DFARS Clause 252.204-7004
[End of B.1]
B.2. ANTI TERRORISM (AT) AWARENESS TRAINING FOR CONTRACTOR PERSONNEL TRAVELING OVERSEAS Contractor employees and associated subcontractor employees shall receive government-provided Anti-Terrorism (AT) awareness training specific to the area of responsibility as directed by AR 525-13. Specific area of responsibility training content is to be directed by the combatant commander, with the unit Anti-Terrorism Officer (ATO) being the local point of contact.
Referenced from ACC-DTA Local Clause [End of B.2]
B.3. ACCESS AND GENERAL PROTECTION/SECURITY POLICY AND PROCEDURES
(a) The contractor and all associated subcontractors’ employees shall comply with applicable installation, facility, and area commander installation and facility access and local security policies and procedures (provided by the Government representative). The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by the installation Provost Marshal Office, Director of Emergency Services, or Security Office. The contractor workforce must comply with all personal identity verification requirements as directed by DoD, HQDA, and/or local policy. Should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.
(b) For contractors requiring Common Access Card (CAC). Before CAC issuance, the contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation in accordance with Army Directive 2014-05. The contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of six (6) months or more. At the discretion of the sponsoring activity, an initial CAC may be issued on a favorable review of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.
(c) For contractors that do not require CAC, but require access to a DOD facility or installation. The contractor and all associated sub- contractor’s employees shall comply with adjudication standards, and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .