Attachment 2 - CLS FA524024QM124 - Water Softener.pdf

PDF 326 KB Posted

Attached to
36FSS WATER SOFTENER SYSTEM AND INSTALLATION (GUAM) Federal contract opportunity
Solicitation number
FA524024QM124
Issued by
Department of the Air Force Pacific Air Forces

About this file

This document is a solicitation (Solicitation Number: FA524024QM124) issued by the Department of the Air Force Pacific Air Forces for a water softener system and installation in Guam. The key details are:

The solicitation requires the contractor to provide a water softener system and installation services. It includes various FAR and DFARS clauses related to things like compensation of former DoD officials, whistleblower rights, safeguarding covered defense information, utilization of Indian organizations and Native Hawaiian small businesses, electronic submission of payment requests, and sources of electronic parts. The solicitation has a response date but does not specify an award date. Pricing terms are not provided. It is unclear if there are any set-asides. No information is provided about incumbents. Overall, this document outlines the key requirements for the water softener system and installation services being procured by the Department of the Air Force Pacific Air Forces.

View the file

Other files for this federal contract opportunity

Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DOCUMENT NUMBER SOLICITATION NUMBER

FA524024QM124

CLAUSES INCORPORATED BY REFERENCE

CLAUSE

NO

ALT NO/

DEV NO

CLAUSE TITLE YEAR-

MO

SECTION

CLAUSES IN FULL TEXT

CLAUSE

NO

ALT NO/

DEV NO

CLAUSE TITLE YEAR-

MO

CLAUSE TEXT

252.203-7000 Requirements Relating to Compensation of Former DoD

Officials.

2011-09

As prescribed in 203.171-4(a), use the following clause:

REQUIREMENTS RELATING TO COMPENSATION OF FORMER DOD OFFICIALS (SEP 2011)

(a) . "Covered DoD official," as used in this clause, means an individual that- Definition

(1) Leaves or left DoD service on or after January 28, 2008; and

(2)(i) Participated personally and substantially in an acquisition as defined in 41 U.S.C. 131 with a value in excess of $10 million, and serves or served-

(A) In an Executive Schedule position under subchapter II of chapter 53 of Title 5, United States Code;

(B) In a position in the Senior Executive Service under subchapter VIII of chapter 53 of Title 5, United States Code; or

(C) In a general or flag officer position compensated at a rate of pay for grade O-7 or above under section 201 of Title 37, United States Code; or

(ii) Serves or served in DoD in one of the following positions: program manager, deputy program manager, procuring contracting officer, administrative contracting officer, source selection authority, member of the source selection evaluation board, or chief of a financial or technical evaluation team for a contract in an amount in excess of $10 million.

(b) The Contractor shall not knowingly provide compensation to a covered DoD official within 2 years after the official leaves DoD service, without first determining that the official has sought and received, or has not received after 30 days of seeking, a written opinion from the appropriate DoD ethics counselor regarding the applicability of post-employment restrictions to the activities that the official is expected to undertake on behalf of the Contractor.

(c) Failure by the Contractor to comply with paragraph (b) of this clause may subject the Contractor to rescission of this contract, suspension, or debarment in accordance with 41 U.S.C. 2105(c).

(End of clause)

252.203-7002 Requirement to Inform Employees of Whistleblower Rights. 2022-12

As prescribed in 203.970, use the following clause:

REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS

(DEC 2022)

(a) The Contractor shall inform its employees in writing, in the predominant native language of the workforce, of contractor employee whistleblower rights and protections under 10 U.S.C. 4701, as described in subpart 203.9 of the Defense Federal Acquisition Regulation Supplement.

(b) The Contractor shall include the substance of this clause, including this paragraph (b), in all subcontracts.

(End of clause)

252.203-7005 Representation Relating to Compensation of Former DoD

Officials.

2022-09

As prescribed in 203.171-4(b), insert the following provision:

REPRESENTATION RELATING TO COMPENSATION OF FORMER DOD OFFICIALS (SEP

2022)

(a) . "Covered DoD official" is defined in the clause at 252.203-7000, Requirements Definition Relating to Compensation of Former DoD Officials.

(b) By submission of this offer, the Offeror represents, to the best of its knowledge and belief, that all covered DoD officials employed by or otherwise receiving compensation from the Offeror, and who are expected to undertake activities on behalf of the Offeror for any resulting contract, are presently in compliance with all applicable post-employment restrictions, including those contained in 18 U.S.C. 207, 41 U.S.C. 2101-2107, 5 CFR part 2641, section 1045 of the National Defense Authorization Act for Fiscal Year 2018 (Pub. L. 115-91), and Federal Acquisition Regulation 3.104-2.

(End of provision)

252.204-7008 Compliance with Safeguarding Covered Defense Information

Controls.

2016-10

As prescribed in 204.7304(a), use the following provision:

COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS

(OCT 2016)

(a) . As used in this provision- Definitions

"Controlled technical information," "covered contractor information system," "covered defense information," "cyber incident," "information system," and "technical information" are defined in clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.

(b) The security requirements required by contract clause 252.204-7012, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.

(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see 252.204-7012(b)(2)-

(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations" (see http://dx.doi.org/10.6028/NIST.SP.800-171) that are in effect at the time the solicitation is issued or as authorized by the contracting officer not later than December 31, 2017.

(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of-

(A) Why a particular security requirement is not applicable; or

(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.

(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.

(End of provision)

252.204-7012 Safeguarding Covered Defense Information and Cyber Incident

Reporting.

2024-05

As prescribed in 204.7304(c), use the following clause:

SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT

REPORTING (MAY 2024)

(a) . As used in this clause- Definitions

"Adequate security" means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.

"Compromise" means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.

"Contractor attributional/proprietary information" means information that identifies the contractor (s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor

(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.

"Controlled technical information" means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.

"Covered contractor information system" means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.

"Covered defense information" means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.

archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is-

(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or

(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.

"Cyber incident" means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.

"Forensic analysis" means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.

"Information system" means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

"Malicious software" means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.

"Media" means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.

''Operationally critical support'' means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.

"Rapidly report" means within 72 hours of discovery of any cyber incident.

"Technical information" means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Other Than Commercial Products and Commercial Services, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.

(b) . The Contractor shall provide adequate security on all covered contractor Adequate security information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:

(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:

(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract.

(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.

(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:

(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations" (available via the internet at https://csrc.nist.gov

) in effect at the time the solicitation is issued or as authorized by the Contracting /publications/sp800 Officer.

(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.

(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.

(C) If the DoD CIO has previously adjudicated the contractor's requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.

(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ( ) and that the cloud https://www.fedramp.gov/documents-templates/ service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)

(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.

(c) Cyber incident reporting requirement.

(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall-

(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor's network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor's ability to provide operationally critical support; and

(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.

(2) The cyber incident report shall be treated as information created by Cyber incident report.

or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.

(3) . In order to report cyber incidents in accordance Medium assurance certificate requirement with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.

(d) . When the Contractor or subcontractors discover and isolate malicious Malicious software software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.

(e) . When a Contractor discovers a cyber incident has Media preservation and protection occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

(f) . Upon request Access to additional information or equipment necessary for forensic analysis by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.

(g) . If DoD elects to conduct a damage assessment, Cyber incident damage assessment activities the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.

(h) . The DoD safeguarding and use of contractor attributional/proprietary information Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.

(i) . Use and release of contractor attributional/proprietary information not created by or for DoD Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD-

(1) To entities with missions that may be affected by such information;

(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;

(3) To Government entities that conduct counterintelligence or law enforcement investigations;

(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or

(5) To a support services contractor ("recipient") that is directly supporting Government activities under a contract that includes the clause at 252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.

(j) . Use and release of contractor attributional/proprietary information created by or for DoD Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government's use and release of such information.

(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.

(l) . The safeguarding and cyber incident reporting Other safeguarding or reporting requirements required by this clause in no way abrogates the Contractor's responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.

(m) . The Contractor shall- Subcontracts

(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and

(2) Require subcontractors to-

(i) Notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause; and

(ii) Provide the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber incident to DoD as required in paragraph (c) of this clause.

(End of clause)

252.204-7015 Notice of Authorized Disclosure of Information for Litigation

Support.

2023-01

As prescribed in 204.7403(b), use the following clause:

NOTICE OF AUTHORIZED DISCLOSURE OF INFORMATION FOR LITIGATION SUPPORT

(JAN 2023)

(a) . As used in this clause- Definitions

"Computer software" means computer programs, source code, source code listings, object code listings, design details, algorithms, processes, flow charts, formulae, and related material that would enable the software to be reproduced, recreated, or recompiled. Computer software does not include computer data bases or computer software documentation.

"Litigation support" means administrative, technical, or professional services provided in support of the Government during or in anticipation of litigation.

"Litigation support contractor" means a contractor (including its experts, technical consultants, subcontractors, and suppliers) providing litigation support under a contract that contains the clause at 252.204-7014, Limitations on the Use or Disclosure of Information by Litigation Support Contractors.

"Sensitive information" means controlled unclassified information of a commercial, financial, proprietary, or privileged nature. The term includes technical data and computer software, but does not include information that is lawfully, publicly available without restriction.

"Technical data" means recorded information, regardless of the form or method of the recording, of a scientific or technical nature (including computer software documentation). The term does not include computer software or data incidental to contract administration, such as financial and/or management information.

(b) . Notwithstanding any other provision of this solicitation or Notice of authorized disclosures contract, the Government may disclose to a litigation support contractor, for the sole purpose of litigation support activities, any information, including sensitive information, received--

(1) Within or in connection with a quotation or offer; or

(2) In the performance of or in connection with a contract.

(c) . Include the substance of this clause, including this paragraph (c), in all Subcontracts subcontracts, including subcontracts for commercial products or commercial services.

(End of clause)

252.204-7018 Prohibition on the Acquisition of Covered Defense

Telecommunications Equipment or Services.

2023-01

As prescribed in 204.2105(c), use the following clause:

PROHIBITION ON THE ACQUISITION OF COVERED DEFENSE TELECOMMUNICATIONS

EQUIPMENT OR SERVICES (JAN 2023)

(a) . As used in this clause- Definitions

"Covered defense telecommunications equipment or services" means-

(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation, or any subsidiary or affiliate of such entities;

(2) Telecommunications services provided by such entities or using such equipment; or

(3) Telecommunications equipment or services produced or provided by an entity that the Secretary of Defense reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.

"Covered foreign country" means-

(1) The People's Republic of China; or

(2) The Russian Federation.

"Covered missions" means-

(1) The nuclear deterrence mission of DoD, including with respect to nuclear command, control, and communications, integrated tactical warning and attack assessment, and continuity of Government; or

(2) The homeland defense mission of DoD, including with respect to ballistic missile defense.

"Critical technology" means-

(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;

(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled-

(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or

(ii) For reasons relating to regional stability or surreptitious listening;

(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);

(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);

(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or

(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).

"Substantial or essential component" means any component necessary for the proper function or performance of a piece of equipment, system, or service.

(b) . In accordance with section 1656 of the National Defense Authorization Act for Prohibition Fiscal Year 2018 (Pub. L. 115-91), the contractor shall not provide to the Government any equipment, system, or service to carry out covered missions that uses covered defense telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless the covered defense telecommunication equipment or services are covered by a waiver described in Defense Federal Acquisition Regulation Supplement 204.2104.

(c) . The Contractor shall review the list of excluded parties in the System for Award Procedures Management (SAM) at for entities that are excluded when providing any https://www.sam.gov equipment, system, or service, to carry out covered missions, that uses covered defense telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless a waiver is granted.

(d) . Reporting

(1) In the event the Contractor identifies covered defense telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during contract performance, the Contractor shall report at the https://dibnet.dod.mil information in paragraph (d)(2) of this clause.

(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause:

(i) Within 3 business days from the date of such identification or notification: the contract number; the order number(s), if applicable; supplier name; brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.

(ii) Within 30 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of a covered defense telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.

(e) . The Contractor shall insert the substance of this clause, including this paragraph Subcontracts (e), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services.

(End of clause)

252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements. 2023-11

As prescribed in 204.7304(d), use the following provision:

NOTICE OF NIST SP 800-171 DOD ASSESSMENT REQUIREMENTS (NOV 2023)

(a) . Definitions

"Basic Assessment", "Medium Assessment", and "High Assessment" have the meaning given in the clause 252.204-7020, NIST SP 800-171 DoD Assessments.

"Covered contractor information system" has the meaning given in the clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, of this solicitation.

(b) . In order to be considered for award, if the Offeror is required to implement Requirement NIST SP 800-171, the Offeror shall have a current assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) (see 252.204-7020) for each covered contractor information system that is relevant to the offer, contract, task order, or delivery order. The Basic, Medium, and High NIST SP 800-171 DoD Assessments are described in the NIST SP 800-171 DoD Assessment Methodology located at https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-

.171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf

(c) . Procedures

(1) The Offeror shall verify that summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) are posted in the Supplier Performance Risk System (SPRS) (https://www.sprs.csd.disa.mil/) for all covered contractor information systems relevant to the offer.

(2) If the Offeror does not have summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) posted in SPRS, the Offeror may conduct and submit a Basic Assessment to webptsmh@navy.mil for posting to SPRS in the format identified in paragraph (d) of this provision.

(d) . Summary level scores for all assessments will be posted 30 days post- Summary level scores assessment in SPRS to provide DoD Components visibility into the summary level scores of strategic assessments.

(1) . An Offeror may follow the procedures in paragraph (c)(2) of this Basic Assessments provision for posting Basic Assessments to SPRS.

(i) The email shall include the following information:

(A) Cybersecurity standard assessed (e.g., NIST SP 800-171 Rev 1).

(B) Organization conducting the assessment (e.g., Contractor self-assessment).

(C) For each system security plan (security requirement 3.12.4) supporting the performance of a DoD contract-

( ) All industry Commercial and Government Entity (CAGE) code(s) associated with the information 1 system(s) addressed by the system security plan; and

( ) A brief description of the system security plan architecture, if more than one plan exists.2

(D) Date the assessment was completed.

(E) Summary level score (e.g., 95 out of 110, NOT the individual value for each requirement).

(F) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.

(ii) If multiple system security plans are addressed in the email described at paragraph (d) (1)(i) of this section, the Offeror shall use the following format for the report:

System Security Plan

CAGE Codes supported by this plan

Brief description of the plan architecture

Date of assessment

Total Score

Date score of 110 will achieved

(2) . DoD will post the following Medium and/or High Medium and High Assessments Assessment summary level scores to SPRS for each system assessed:

(i) The standard assessed (e.g., NIST SP 800-171 Rev 1).

(ii) Organization conducting the assessment, e.g., DCMA, or a specific organization (identified by Department of Defense Activity Address Code (DoDAAC)).

(iii) All industry CAGE code(s) associated with the information system(s) addressed by the system security plan.

(iv) A brief description of the system security plan architecture, if more than one system security plan exists.

(v) Date and level of the assessment, i.e., medium or high.

(vi) Summary level score (e.g., 105 out of 110, not the individual value assigned for each requirement).

(vii) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.

(3) . Accessibility

(i) Assessment summary level scores posted in SPRS are available to DoD personnel, and are protected, in accordance with the standards set forth in DoD Instruction 5000.79, Defense-wide Sharing and Use of Supplier and Product Performance Information (PI).

(ii) Authorized representatives of the Offeror for which the assessment was conducted may access SPRS to view their own summary level scores, in accordance with the SPRS Software User's Guide for Awardees/Contractors available at https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf.

(iii) A High NIST SP 800-171 DoD Assessment may result in documentation in addition to that listed in this section. DoD will retain and protect any such documentation as "Controlled Unclassified Information (CUI)" and intended for internal DoD use only. The information will be protected against unauthorized use and release, including through the exercise of applicable exemptions under the Freedom of Information Act (e.g., Exemption 4 covers trade secrets and commercial or financial information obtained from a contractor that is privileged or confidential).

(End of provision)

252.204-7020 NIST SP 800-171 DoD Assessment Requirements. 2023-11

As prescribed in 204.7304(e), use the following clause:

NIST SP 800-171 DOD ASSESSMENT REQUIREMENTS (NOV 2023)

(a) . Definitions

"Basic Assessment" means a contractor's self-assessment of the contractor's implementation of NIST SP 800-171 that-

(1) Is based on the Contractor's review of their system security plan(s) associated with covered contractor information system(s);

(2) Is conducted in accordance with the NIST SP 800-171 DoD Assessment Methodology; and

(3) Results in a confidence level of "Low" in the resulting score, because it is a self-generated score.

"Covered contractor information system" has the meaning given in the clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, of this contract.

"High Assessment" means an assessment that is conducted by Government personnel using NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information that-

(1) Consists of-

(i) A review of a contractor's Basic Assessment;

(ii) A thorough document review;

(iii) Verification, examination, and demonstration of a Contractor's system security plan to validate that NIST SP 800-171 security requirements have been implemented as described in the contractor's system security plan; and

(iv) Discussions with the contractor to obtain additional information or clarification, as needed; and

(2) Results in a confidence level of "High" in the resulting score.

"Medium Assessment" means an assessment conducted by the Government that-

(1) Consists of-

(i) A review of a contractor's Basic Assessment;

(ii) A thorough document review; and

(iii) Discussions with the contractor to obtain additional information or clarification, as needed; and

(2) Results in a confidence level of "Medium" in the resulting score.

(b) . This clause applies to covered contractor information systems that are required Applicability to comply with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800- 171, in accordance with Defense Federal Acquisition Regulation System (DFARS) clause at 252.204- 7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, of this contract.

(c) . The Contractor shall provide access to its facilities, systems, and personnel Requirements necessary for the Government to conduct a Medium or High NIST SP 800-171 DoD Assessment, as described in NIST SP 800-171 DoD Assessment Methodology at https://www.acq.osd.mil/asda/dpc/cp , if /cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf necessary.

(d) . Summary level scores for all assessments will be posted in the Supplier Procedures Performance Risk System (SPRS) (https://www.sprs.csd.disa.mil/) to provide DoD Components visibility into the summary level scores of strategic assessments.

(1) . A contractor may submit, via encrypted email, summary level scores Basic Assessments of Basic Assessments conducted in accordance with the NIST SP 800-171 DoD Assessment Methodology to webptsmh@navy.mil for posting to SPRS.

(i) The email shall include the following information:

(A) Version of NIST SP 800-171 against which the assessment was conducted.

(B) Organization conducting the assessment (e.g., Contractor self-assessment).

(C) For each system security plan (security requirement 3.12.4) supporting the performance of a DoD contract-

( ) All industry Commercial and Government Entity (CAGE) code(s) associated with the information 1 system(s) addressed by the system security plan; and

( ) A brief description of the system security plan architecture, if more than one plan exists.2

(D) Date the assessment was completed

(E) Summary level score (e.g., 95 out of 110, NOT the individual value for each requirement).

(F) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.

(ii) If multiple system security plans are addressed in the email described at paragraph (b) (1)(i) of this section, the Contractor shall use the following format for the report:

System Security Plan

CAGE Codes supported by this plan

Brief description of the plan architecture

Date of assessment

Total Score

Date score of 110 will achieved

(1) . DoD will post the following Medium and/or High Medium and High Assessments Assessment summary level scores to SPRS for each system security plan assessed:

(i) The standard assessed (e.g., NIST SP 800-171 Rev 1).

(ii) Organization conducting the assessment, e.g., DCMA, or a specific organization (identified by Department of Defense Activity Address Code (DoDAAC)).

(iii) All industry CAGE code(s) associated with the information system(s) addressed by the system security plan.

(iv) A brief description of the system security plan architecture, if more than one system security plan exists.

(v) Date and level of the assessment, i.e., medium or high.

(vi) Summary level score (e.g., 105 out of 110, not the individual value assigned for each requirement).

(vii) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan(s) of action developed in accordance with NIST SP 800-171.

(e) . Rebuttals

(1) DoD will provide Medium and High Assessment summary level scores to the Contractor and offer the opportunity for rebuttal and adjudication of assessment summary level scores prior to posting the summary level scores to SPRS (see SPRS User's Guide https://www.sprs.csd.disa.mil/pdf /SPRS_Awardee.pdf).

(2) Upon completion of each assessment, the contractor has 14 business days to provide additional information to demonstrate that they meet any security requirements not observed by the assessment team or to rebut the findings that may be of question.

(f) . Accessibility

(1) Assessment summary level scores posted in SPRS are available to DoD personnel, and are protected, in accordance with the standards set forth in DoD Instruction 5000.79, Defense-wide Sharing and Use of Supplier and Product Performance Information (PI).

(2) Authorized representatives of the Contractor for which the assessment was conducted may access SPRS to view their own summary level scores, in accordance with the SPRS Software User's Guide for Awardees/Contractors available at https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf.

(3) A High NIST SP 800-171 DoD Assessment may result in documentation in addition to that listed in this clause. DoD will retain and protect any such documentation as "Controlled Unclassified Information (CUI)" and intended for internal DoD use only. The information will be protected against unauthorized use and release, including through the exercise of applicable exemptions under the Freedom of Information Act (e.g., Exemption 4 covers trade secrets and commercial or financial information obtained from a contractor that is privileged or confidential).

(g) . Subcontracts

(1) The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf items).

(2) The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment, as described in https://www.acq.osd.mil/asda/dpc/cp

, for /cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf all covered contractor information systems relevant to its offer that are not part of an information technology service or system operated on behalf of the Government.

(3) If a subcontractor does not have summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) posted in SPRS, the subcontractor may conduct and submit a Basic Assessment, in accordance with the NIST SP 800-171 DoD Assessment Methodology, to webptsmh@navy.mil for posting to SPRS along with the information required by paragraph (d) of this clause.

(End of clause)

252.204-7024 Notice on the Use of the Supplier Performance Risk System. 2023-03

As prescribed in 204.7604, use the following provision:

NOTICE ON THE USE OF THE SUPPLIER PERFORMANCE RISK SYSTEM (MAR 2023)

(a) . As used in this provision- Definitions

"Item risk" means the probability that a product, based on intended use, will introduce performance risk resulting in safety issues, mission degradation, or monetary loss.

"Price risk" means a measure of whether a proposed price for a product or service is consistent with historical prices paid for that item or service.

"Supplier risk" means the probability that an award may subject the procurement to the risk of unsuccessful performance or to supply chain risk (see Defense Federal Acquisition Regulation Supplement 239.7301).

(b) The Supplier Performance Risk System (SPRS), available at , will be used https://piee.eb.mil/ in the evaluation of the Quoter or Offeror's performance. SPRS retrieves item, price, quality, delivery, and contractor information on contracts from Government reporting systems in order to develop risk assessments.

(c) The Contracting Officer will consider SPRS risk assessments during the evaluation of quotations or offers received in response to this solicitation as follows:

(1) Item risk will be considered to determine whether the procurement represents a high performance risk to the Government.

(2) Price risk will be considered in determining if a proposed price is consistent with historical prices paid for a product or a service or otherwise creates a risk to the Government.

(3) Supplier risk, including but not limited to quality and delivery, will be considered to assess the risk of unsuccessful performance and supply chain risk.

(d) SPRS risk assessments are generated daily. Quoters or Offerors are able to access their risk assessments by following the access instructions in the SPRS user's guide available at https://www.sprs.

. Quoters and Offerors are granted access to SPRS for their own risk csd.disa.mil/reference.htm assessment classifications only. SPRS reporting procedures and risk assessment methodology are detailed in the SPRS user's guide. The method to challenge a rating generated by SPRS is also provided in the user's guide. SPRS evaluation criteria are available at https://www.sprs.csd.disa.mil/pdf

./SPRS_DataEvaluationCriteria.pdf

(e) The Contracting Officer may consider any other available and relevant information when evaluating a quotation or an offer.

(End of provision)

252.215-7007 Notice of Intent to Resolicit. 2012-06

As prescribed at 215.371-6, use the following provision:

NOTICE OF INTENT TO RESOLICIT (JUN 2012)

This solicitation provides offerors fewer than 30 days to submit proposals. In the event that only one offer is received in response to this solicitation, the Contracting Officer may cancel the solicitation and resolicit for an additional period of at least 30 days in accordance with 215.371-2.

(End of provision)

252.223-7008 Prohibition of Hexavalent Chromium. 2023-01

As prescribed in 223.7306, use the following clause:

PROHIBITION OF HEXAVALENT CHROMIUM (JAN 2023)

(a) . As used in this clause- Definitions

"Homogeneous material" means a material that cannot be mechanically disjointed into different materials and is of uniform composition throughout.

(1) Examples of homogeneous materials include individual types of plastics, ceramics, glass, metals, alloys, paper, board, resins, and surface coatings.

(2) Homogeneous material does not include conversion coatings that chemically modify the substrate.

"Mechanically disjointed" means that the materials can, in principle, be separated by mechanical actions such as unscrewing, cutting, crushing, grinding, and abrasive processes.

(b) . Prohibition

(1) Unless otherwise specified by the Contracting Officer, the Contractor shall not provide any deliverable or construction material under this contract that-

(i) Contains hexavalent chromium in a concentration greater than 0.1 percent by weight in any homogenous material; or

(ii) Requires the removal or reapplication of hexavalent chromium materials during subsequent sustainment phases of the deliverable or construction material.

(2) This prohibition does not apply to hexavalent chromium produced as a by-product of manufacturing processes.

(c) If authorization for incorporation of hexavalent chromium in a deliverable or construction material is required, the Contractor shall submit a request to the Contracting Officer.

(d) . The Contractor shall include the substance of this clause, including this Subcontracts paragraph (d), in all subcontracts, including subcontracts for commercial products or commercial services, that are for supplies, maintenance and repair services, or construction materials.

(End of clause)

252.225-7012 Preference for Certain Domestic Commodities. 2022-04

As prescribed in 225.7002-3(a), use the following clause:

PREFERENCE FOR CERTAIN DOMESTIC COMMODITIES (APR 2022)

(a) As used in this clause- Definitions.

"Component" means any item supplied to the Government as part of an end product or of another component.

"End product" means supplies delivered under a line item of this contract.

"Qualifying country" means a country with a reciprocal defense procurement memorandum of understanding or international agreement with the United States in which both countries agree to remove barriers to purchases of supplies produced in the other country or services performed by sources of the other country, and the memorandum or agreement complies, where applicable, with the requirements of section 36 of the Arms Export Control Act (22 U.S.C. 2776) and with 10 U.S.C. 2457.

Accordingly, the following are qualifying countries:

Australia

Austria

Belgium

Canada

Czech Republic

Denmark

Egypt

Estonia

Finland

France

Germany

Greece

Israel

Italy

Japan

Latvia

Lithuania

Luxembourg

Netherlands

Norway

Poland

Portugal

Slovenia

Spain

Sweden

Switzerland

Turkey

United Kingdom of Great Britain and Northern Ireland.

"Structural component of a tent"-

(1) Means a component that contributes to the form and stability of the tent (e.g., poles, frames, flooring, guy ropes, pegs); and

(2) Does not include equipment such as heating, cooling, or lighting.

" " means the 50 States, the District of , and outlying areas. United States Columbia

"U.S.-flag vessel" means a vessel of the or belonging to the , United States United States…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .