Attachment 2 - DD 254 Final.pdf

PDF 83 KB Posted

Attached to
GSSE Request for Proposal Federal contract opportunity
Solicitation number
H9241524R0004
Issued by
United States Special Operations Command

About this file

This document is a Department of Defense (DoD) Contract Security Classification Specification (DD Form 254) associated with a Request for Proposal (RFP) for providing Global System Service Engineering Support for U.S. Special Operations Command (USSOCOM).

The DD Form 254 outlines the security requirements for the classified contract, including facility clearance level, safeguarding requirements, access to Sensitive Compartmented Information (SCI) and Special Access Program (SAP) information, Operations Security (OPSEC) requirements, and the need for Controlled Unclassified Information (CUI) handling procedures. The contract has a period of performance from July 1, 2024 to June 30, 2029 and requires a biennial review of the DD Form 254. Key details include the need for contractor personnel to hold a minimum of a SECRET clearance, restrictions on subcontracting, and specific security oversight and inspection responsibilities. The DD Form 254 also provides detailed guidance on the handling and safeguarding requirements for SCI, SAP, and CUI information related to this classified contract effort.

View the file

Other files for this federal contract opportunity

Other files attached to GSSE Request for Proposal, newest first.
File Type Posted
GSSE Questions and Answers 27Aug24.xlsx XLSX spreadsheet
GSSE Questions and Answers.xlsx XLSX spreadsheet
H92415-24-R-0004 GSSE Amendment 02 Mod.pdf PDF
GSSE Sections L and M FINAL Redlines 22 August.docx DOCX document
H92415-24-R-0004 GSSE Amendment 02 Conformed.pdf PDF
Attachment 3 - Cost and Pricing Matrix GSSE v2 20Aug2024.xlsx XLSX spreadsheet
GSSE Questions and Answers 20Aug24.xlsx XLSX spreadsheet
GSSE Amendment 1 Sections L and M Redline 20Aug24.docx DOCX document
H9241524R0004-0001 GSSE Amendment 1 20Aug24.pdf PDF
GSSE Amendment 1 PWS Redlined 20Aug24.docx DOCX document
H9241524R0004-0001 GSSE Conformed 20Aug24.pdf PDF
Attachment 3 - Updated Pricing Matrix GSSE 20Aug2024.xlsx XLSX spreadsheet
Attachment 1 - Updated PWS GSSE 20Aug24.pdf PDF
Attachment 4 - Cost and Pricing Matrix.xlsx XLSX spreadsheet
Attachment 3 - CDRL Package.pdf PDF
Attachment 1 - PWS Final.pdf PDF
H9241524R0004 GSSE RFP.pdf PDF
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

PREVIOUS EDITION IS OBSOLETE.

Page of

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

June 30, 2025 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification"

CurrentPage:
PageCount:
Select classification from drop-down list.:
SerialNum:
a. Facility clearance level. Select one.: 1
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4
Select for "original.": 1
Select for "original.": 1
Enter prime contract number.: TBD
Select for "revised.": 0
Select for "revised.": 0
Enter subcontract number.: SEE ITEM 13
Select for "final.": 0
Select for "final.": 0
Enter solicitation or other number.:
Enter due date in format YYYYMMDD.:
Enter date in format YYYYMMDD.:
Enter revision number.:
Enter date in format YYYYMMDD.:
Enter final specification.:
Enter date in format YYYYMMDD.:
Select for "no.": 1
Select for "no.": 1
Select for "no.": 0
Select for "no.": 0
Select for "yes.": 0
Select for "yes.": 0
Select for "yes.": 1
Select for "yes.": 1
Enter preceding contract number.:
Enter contractor's request date in format YYYYMMDD.:
Enter period.:
Enter typed name of certifying official (last, first, middle initial).: TBD - Newly Awarded Company
Enter typed name of certifying official (last, first, middle initial).: SEE ITEM 13
Enter typed name of certifying official (last, first, middle initial).: Fredette, John T.
Enter CAGE code of the prime contractor.: TBD
Enter CAGE code of the prime contractor.: N/A
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Defense Counterintelligence & Security Agency (DCSA)

TBD Field Office Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: HQ USSOCOM/SOCS-Z-SM 7701 Tampa Point Blvd MacDill AFB, FL 33621 813-826-4333 IndustrialSecurity@socom.mil Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 1 SOW/IPC 212 Lukasik, Suite 230 Hurlburt Field, FL 32544 850-884-5143 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 27 SOW/IPC 27 Special Operations Wing, Cannon AFB, NM 88101 Comm: 575-904-3436 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Security Manager 58th SOW Kirtland AFB, NM 87117

Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 75th Ranger Regiment 6480 Dawson Loop, Fort Benning, GA Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 21st STS 1526 Hurst Dr, Pope Field, NC 28308 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: MARSOC PSC Box 20116, Camp Lejeune, NC 28524 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: NSWC, 2000 Trident Way Coronado, CA 92118 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Naval Special Warfare Group TWO JEB Little Creek, VA 23518 Command Security Manager/SSO Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 160th SOAR(A)/RS2 Industrial Security Officer 7269 Nightstalker Way Fort Campbell, KY 42223 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: HQ, 5th SFG S2 Fort Campbell, KY42223

Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: USASOC, 2929 Desert Storm Drive, Fort Bragg, NC,
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 4545 Memorial Loop, Eglin AFB, FL 32542
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: HHC/10th Special Forces Group (A)
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Kelly Barracks

Unit 29951 Plieninger Strasse 289 70567 Stuttgart Moehringen

DSN 314-430-5268

Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: SOCCENT ATTN: Security Manager 7561 Blackbird St.

MacDill AFB, FL 33621 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: HQ SOCEUR Geb 2302 Patch Barracks 70569 Stuttgart, Germany +49 0711-680-4341

DSN 314-430-5268

Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Headquarters, Special Operations Command Korea

15622, APO AP 96271

Camp Humphreys, South Korea Security Management Office: DSN 315-757-3082 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Headquarters, Special Operations Command North 575 Kincheloe Loop (Building 104) Peterson Space Force Base, CO 80914-1194 Security Office: 719-554-7975 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Headquarters, Special Operations Command Pacific 1 Elrod Road Camp H.M. Smith, HI 96861

(808) 204-3634 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Headquarters, Special Operations Command South 29401 SW 125th Ave, Bld 600 Homestead, FL 33039 786-415-2041/2020 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 352nd SOW

DSN: 238-5041

Comm: 01638 545041 352sow.pa@us.af.mil Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Security Manager Torii Station, Okinawa Japan Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: 1/10th SFG Panzer Kaserne, Boeblingen, Germany

Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: TAPO, 1382 Lee Blvd, Fort Eustis, VA 23604
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: Dam Neck Annex

Virginia Beach, VA 23454 Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: NSWC, 2000 Trident Way Coronado, CA 92118

Select to add row to locations.:
Select to remove last row from locations.:
Select to delete all signatures.:
Enter location(s).: USSOCOM/SOF AT&L-PEO C4TIP/TACLAN PMO

7701 Tampa Point Blvd MacDill AFB, FL 3

Enter location(s).: Hurlburt Field FL. 1 SOW: 1OSS, 4 SOS, 6 SOS, 8 SOS, 9SOS, 15 SOS, 19 SOS, 34 SOS, 319 SOS. 623 AOC, 18 FLTS, 14 WPS, 150 SOS (ANG), 24 SOW. 919 OSS 711 SOS, HQ 10CWS - 4POG
Enter location(s).: Cannon AFB, NM

27 SOW: 27 OSS, 3 SOS, 16 SOS, 20 SOS, 33 SOS, 73 SOS, 318 SOS, 524 SOS, XX SOS, 26 STS Enter location(s).: Kirtland AFB, NM

58 TRSS, 550 SOS, 71 SOS

Enter location(s).: Fort Benning, GA 17 STS, 3-75th Ranger Regiment Enter location(s).: Pope Field, NC

21 STS, AFSOC SMU

Enter location(s).: JBLM, WA 22 STS, 4-160th SOAR, 1st SF GP, 2-75th Ranger Regiment Enter location(s).: Camp Lejeune, NC MARSOC Depot East (Main) Enter location(s).: NAB Coronado, CA NAVSOF Depot West (Main) Enter location(s).: JEB Little Creek - Fort Story VA NAVSOF Depot East Enter location(s).: Fort Campbell, KY 1-160th SOAR, 2-160th SOAR, SOATB, SIMO Enter location(s).: Fort Campbell, KY 5th SF GP Enter location(s).: Hunter AAF, GA 3-160th SOAR, 1-75th Ranger Regiment Enter location(s).: Fort Bragg, NC ARSOF Depot - USASFC, JFKSWCS, 95th CA Bde, MISO, 19th SF GP, 20th SF GP, 3rd SF GP Enter location(s).: Eglin AFB, FL 7th SF GP Enter location(s).: Fort Carson, CO 10th SF GP

Enter location(s).: SOCAFRICA
Enter location(s).: SOCCENT
Enter location(s).: SOCEUR
Enter location(s).: SOCKOR
Enter location(s).: SOCNORTH
Enter location(s).: SOCPAC
Enter location(s).: SOCSOUTH
Enter location(s).: RAF Mildenhall, UK

352 OSS, 7 SOS, 67 SOS, XX SOS, 321 STS

Enter location(s).: Kadena AB Japan

353 OSS, 1 SOS, 17 SOS, XX SOS, 320 STS

Enter location(s).: Okinawa, Japan 1/1st SF GP Enter location(s).: Stuttgart, Germany 1/10th SF GP Enter location(s).: Joint Base Langley-Eustis, VA

PMO, ARSOAC SMU

Enter location(s).: NAS Oceana-Dam Neck Annex
Enter location(s).: NAS North Island, CA

HSC-85/Naval Aviation TSU Enter general unclassified description of this procurement.: Provide Global System Service Engineering Support for USSOCOM.

Period of Performance: 1July 2024 – 30 June 2029 (Biennial DD Form 254 review required - See Item13)

Controlled by: HQ USSOCOM Controlled by: [Name of COR’s Directorate/Special Staff/Division/Branch/Office] CUI Category: OPSEC Distribution/Dissemination Control: DISTRO C POC: [COR’s Phone or email address]

THIS DD FORM 254 IS TENTATIVELY APPROVED. Upon company selection and identification of a Contract Number/Task Order, but prior to award and any classified release, this DD Form 254 with all pertinent information inserted in appropriate sections will be submitted to U.S. Special Operations Command Industrial Security for final review and approval.

Select for "a. CONTRACTOR.": 1
Select for "a. CONTRACTOR.": 1
Select for "a. CONTRACTOR.": 0
Select for "f. OTHER AS NECESSARY.": 1
Select for "f. OTHER AS NECESSARY.": 1
Select for "f. OTHER AS NECESSARY.": 0
Select for "b. SUBCONTRACTOR.": 1
Select for "b. SUBCONTRACTOR.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 1
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "h. REQUIRE A COMSEC ACCOUNT.": 1
Select for "h. REQUIRE A COMSEC ACCOUNT.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "i. HAVE A TEMPEST REQUIREMENT.": 1
Select for "i. HAVE A TEMPEST REQUIREMENT.": 0
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 1
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 1
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 0
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 0
Enter infomration for "other.": SEE ITEM 13
Enter infomration for "other.": SEE ITEM 13
Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0
Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0
Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1
Select for "m.OTHER.": 1
Select for "direct.": 0
Select for ": 1
Enter specification for "through".: SEE ITEM 13
Enter public release authority.:
Select to add signature.:
Select to remove last signature.:
text: The Contracting Officer’s Representative/Program Manager will provide a copy of all applicable security directives for this contract. Appropriate applicable HQ USSOCOM security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or Component/Theater Special Operations Command COR/PM). Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the USSOCOM Government Contracting Agency/Activity. Furthermore, the contractor will account for and return all Common Access Cards (CACs) to Contracting Officer's Representative, Program Manager, or Trusted Agent upon completion or termination of the classified contract, termination of employment, or suspension of classified clearance or access of any contractor employee. Security badges, installation entry passes/vehicle decals issued to contractor personnel will be returned to the appropriate issuing office as required.

Ref 2b: IAW NISPOM, Section §117.17, subcontracting/flow-down of this effort requires a Subcontract/Flow-Down DD FM 254. Subcontract/Flow-Down DD FM 254 must be approved by HQ USSOCOM prior to award. Forward requests and draft Subcontract DD FM 254s to the Contracting Officer’s Representative/Program Manager and USSOCOM Industrial Security (IndustrialSecurity@socom.mil). IAW USSOCOM R 380-9, Industrial Security, please allow 10 duty days for review/approval.

Ref 2b. Subcontractors with performance at HQ USSOCOM. IAW NISPOM, Section §117.16(a), Prime Contractor will forward subcontractor Visit Requests to HQ USSOCOM Personnel Security (PERSEC) via DISS SMO Code MA3DF8X94. Visit Requests must not be submitted to HQ USSOCOM until the Subcontract DD FM 254 is approved. Failure to follow this guidance will result in the cancellation of the Visit Request.

Ref 7: See guidance in Ref 2b.

Ref 9. Unless DD FM 254 revision is required due to change in the security requirements of the effort or there is a change in the contractor’s Facility Clearance (FCL) status, the responsible Contracting Officer’s Representative/Program Manager (COR/PM) must conduct a review of the DD FM 254 and associated Individual Work Plan, Performance Work Statement/Statement of Objectives/Statement of Work every 24 MONTHS (BIENNIALLY) in order to validate and/or update the requirements of the effort as required by DoDM 5220.32-V1, National Industrial Security Program: Industrial Security Procedures for Government Activities. Documentation of review (email is sufficient) should be forwarded to HQ USSOCOM Industrial Security via NIPRNet at IndustrialSecurity@socom.mil.

Ref 10e(1): See SCI Addendum.

Ref 10e(2): For non-SCI material, authorization and briefing shall be in accordance with the NISPOM and/or other appropriate directives. In any case, Contractor shall brief the employee or Contractor’s Security Officer on the employee’s obligation to safeguard the information, and the employee shall be debriefed according to the applicable regulations, when the access is terminated. When the Contractor briefs or debriefs an employee, the Contractor shall execute a separate SF Form 312, “Classified Information Nondisclosure Agreement” or another form, if required by the applicable regulation covering the material for each cleared employee who shall be afforded access to the classified/intelligence material. In each case, the form shall be appropriately annotated to indicate that a special briefing relative to safeguarding the material has been given.

Ref 10f: See SAP Addendum. IAW “Implementation Guidance for DoD Special Access Program Enterprise (11 July 2023); Attachment 5 “SAP Enterprise Reform Directed Actions” (page 13), all Performance Work Statements, Statements of Objectives, Statements of Work; as well as associated DD254s with a documented Special Access Program (SAP) access requirement will be marked as CUI. The required CUI Designation Indicator will include the following. The Indicator will be included at the bottom of the first page for PWSs/SOOs/SOWs and in Item 9 on DD254s below the Period of Performance.

Controlled by: HQ USSOCOM Controlled by: [Name of COR’s Directorate/Special Staff/Division/Branch/Office] CUI Category: OPSEC Distribution/Dissemination Control: DISTRO C POC: [COR’s Phone or email address]

Ref 10g. The contractor is permitted access to North Atlantic Treaty Organization (NATO) information in performance of this contract. Access to NATO information requires a final U.S. Government clearance at the appropriate level. The government program/project manager is the designated representative that will ensure the contractor security manager and concerned employees are NATO briefed prior to access being granted. The contractor will maintain strict compliance with regards to NATO information IAW NISPOM Section §117.19, Paragraph (g). Prior approval from the contracting activity is required for subcontracting and in accordance with NISPOM Section §117.19, Paragraph (g)(9).

Ref 10h. The contractor is permitted access to Foreign Government Information in the performance of this contract. Access to Foreign Government Information requires a final U.S. Government clearance at the appropriate level. Contractor employees will be briefed, and acknowledge in writing, their responsibilities for handling Foreign Government Information prior to being granted access. The contractor will maintain strict compliance with NISPOM, Section §117.19, Paragraph (c). Prior approval of the contracting activity is required for subcontracting and in accordance with NISPOM, Section §117.17, Paragraph a(3)(iv).

Ref 10i. Alternative Compensatory Control Measures (ACCM) Program information is governed by DoD M 5200.01-V3, DoD Information Security Program: Protection of Classified Information, Enclosure 2, Section 18; CJCS Manual 3213.02D, Joint Staff Alternative Compensatory Control Measures Program Management Manual, and supporting documentation for each ACCM sub-system, including security classification guides, program security plans, and governing directives. Inspections of ACCM information in USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), or Theater Special Operation Command (SOCNORTH, SOCAFRICA, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, or SOCKOR) owned and operated facilities are under the auspices of the respective Command or Component ACCM Coordinator/ACCM Program Control Officer (ACCM Coord/ACCM PCO). If applicable, ACCM material maintained by the Contractor within their facility must be afforded protection commensurate with DOD requirements and strictly controlled based on need-to-know and required briefings. DCSA personnel conducting inspections of the Contractor must be briefed on to the specific program by the appropriate government ACCM Coord/ACCM PCO responsible for the material prior to being granted access.

Ref 10j: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.

Ref 10k: NIPRNET/SIPRNET/JIANT/JWICS access required at government facilities only.

Ref 11a: Contractor performance is restricted to the government Performance Locations identified in Item 8. Government agency or activity will provide security classification guidance for performance of this contract. Submit visit request to COR and/or Security Management Office for need-to-know verification.

Ref 11l: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the CUI Addendum included with this specification.

Ref 11m: Access to all USSOCOM facilities requires contractors to possess a minimum of a SECRET clearance.

Ref 11m: Contractor will be authorized to courier classified information up to the SECRET level in performance of official duties upon approval of and designation by the COR, PM and/or SSO.

Ref 12: Requests must be forwarded through the responsible Contracting Officer’s Representative/Program Manager, Contracting Official (Item 16) and the HQ USSOCOM Special Operations Communication Office (SOCS-SOCO), Public.Affairs@socom.mil, (813) 826-4600, prior to public release.

SCI ADDENDUM

(14 SEPTEMBER 2020)

This supplement applies to:

Prime Contract Number: TBD Subcontract Number: N/A Delivery/Task Order Number: TBD Expiration Date: 30 Jun 2029

The following controls will apply to Sensitive Compartmented Information (SCI) provided under this contract.

1. Item 10e (2): Security clearances for contractors working within SCIF spaces must be adjudicated meeting Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5 eligibility requirements. Prior approval of the contracting activity is required for sub-contracting. Access to intelligence information requires special briefings and a final U.S. Government clearance at the appropriate level.

2. Item 13: Department of Defense (DOD) Manual 5105.21, Volumes 1-3, Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5, Intelligence Community Standard (ICS) 705-1&2 including the Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities (IC Tech Spec-for ICD/ICS 705, and Headquarters, United States Special Operations Command (HQ USSOCOM) 380-6, provide the necessary guidance for physical and information security measures and are part of the SCI security specifications for the contract.

3. Item 13: Inquiries pertaining to classification guidance will be directed to the responsible USSOCOM Contracting Officer’s Representative/Program Manager/Contract Monitor (TBD, 813-826-XXXX, firstname.lastname.civ@socom.mil).

4. Item 13: All SCI furnished to the contractor in support of this contract / delivery / task order remains the property of the DOD or the agency or command that releases the information. Upon termination of the contract, all furnished SCI will be returned to the HQ USSOCOM Special Security Office (SSO) or the prime contractor.

5. Item 14: This contract / delivery / task order requires that NUMBER TBD (XXX) contract billet be established in order to fulfill the contractual obligations incurred. Access will be granted by the government agency. Upon completion or cancellation of the contract, the Contractor SSO (CSSO) will debrief or notify the HQ USSOCOM SSO to debrief all personnel not required for contract closeout and those billets will be disestablished.

6. Item 14: Names of contractor personnel requiring access to SCI and justification for SCI billets will be submitted to HQ USSOCOM SSO after contract monitor coordination. Billet justifications will include the contract statement of work. If a Single-Scope Background (SSBI) Investigation has not been completed upon approval of billets by the HQ USSOCOM SSO, the CSSO will submit necessary forms to the Vetting Risk Operations Center (VROC) for a T5 investigation. An SSBI and access to SCI will comply with the National Industrial Security Program Operating Manual. Upon completion of the T5 investigation, a nomination for SCI access will be submitted to HQ USSOCOM SSO.

7. Item 14: The CSSO will advise HQ USSOCOM SSO, through the contract monitor, upon reassignment of personnel to other duties not associated with this contract. The Contract Monitor will also notify the SSO Office at SOCOM.SSO.PERSEC@SOCOM.MIL or 813-826-1287 so the SSO can remove their ownership of the contractor in DISS.

8. Item 14: The CSSO must coordinate with the SCI contract monitor before subcontracting any portion of SCI efforts involved in the contract. A separate DD Form 254 for the subcontractor will be processed and a copy provided to HQ USSOCOM SSO.

9. Item 14: The contractor will not use references to SCI access, even by unclassified acronyms, in advertisements, promotional efforts, or recruitment of employees.

10. Item 14: All SCI work will be performed at the locations specified below and in subsequent Task Orders.

a. Locations TBD

11. Item 15: HQ USSOCOM SSO has exclusive security responsibility for all SCI released to the contractor or developed under this contract. Defense Intelligence Agency and HQ USSOCOM SSO retain authority for all inspections of the contractor to ensure compliance with SCI directives, regulations, and instructions.

12. In accordance with DODM 5105.21 Volume 1-3, the following activity is designated User Agency Special Security Office for SCI requirement:

HQ USSOCOM

Special Security Office (SSO) 7701 Tampa Point Boulevard Telephone: DSN 299-1287 SOCOM.SSO.INDUSEC@SOCOM.MIL MacDill AFB, Florida 33621-5323 Commercial: (813) 826-1287

PROTECTING SPECIAL ACCESS PROGRAM (SAP) INFORMATIOM

Addendum (Version 1, 29 May 2024)

Special Access Program (SAP) discussion, storage, and processing associated with this effort will be conducted in SAP Facilities (SAPF) specifically approved, in writing, by the USSOCOM SAP Management Office (SAPMO) or designated USSOCOM Program Security Officer (PSO). Contact the SAP approval official in Block 13 for approved SAPF locations.

SAP activities are governed by 32 Code of Federal Regulation Part 117, “NISPOM rule”; DoD Manual 5200.01 (DoD Information Security Program) Volumes 1-4; DoD Directive 5205.07 (Special Access Program Policy); DoD Manual 5205.07 (DoD Special Access Program Security Manual), Volumes 1-4; DoD Instruction 5205.11, (Joint SAP Implementation Guide (JSIG);

USSOCOM Manual 380-2 (SAP Security Guide); USSOCOM Manual 380-7 (USSOCOM Arms Control Readiness Inspection Program); and applicable program security classification guides and subsequent versions.

Access to SAP information requires employees to undergo additional personnel security screening and meet the requirements of DoD SAP accessing directives and policies in accordance with DoDM 5205.07, Volume 2. The individual must meet applicable eligibility requirements and possess a final Secret or Top Secret security clearance depending on the level of access required in performance of this contract. Program Access Requests (PAR) for contractor personnel must be submitted by the Contractor Program Security Officer (CPSO) to the PSO for approval by the designated Access Approval Authority (AAA). Personnel approved for access will receive a program indoctrination briefing and must sign an SAP Indoctrination Agreement (PIA) prior to receiving access to program information or material. The CPSO will maintain the signed PIA and forward a copy to the PSO for entry into the appropriate database system.

The July 20, 2023, OSD Memorandum relieves the Defense Counterintelligence and Security Agency (DCSA) from industrial security oversight of cleared defense contractors performing on contracts that require DoD SAP access. SAP inspections and security oversight of USSOCOM or Component government or contractor SAP facilities are under the cognizance of the USSOCOM PSO or SAPMO representative, as appropriate. Additional Component SAP security requirements may apply for activities conducted at Service Component or Sub-unified command locations. The Performance Monitor or component command Contracting Officer Representative (COR) at these locations/facilities will provide specific or additional guidance.

OPSEC-sensitive or classified communication will be conducted via PSO-approved secure channels from within the SAPF. Transmission of documents via secure facsimile between terminals within SAPFs may be approved by the PSO. Only the U.S. Postal Service Registered or Certified mail, if authorized, will be used to mail program material unless an alternate method is approved by the PSO. Consult the PSO prior to mailing any SAP information. Briefed personnel are authorized to courier classified information within the continental United States with written approval from the CPSO or PSO. Two (program briefed) personnel are required to courier Top Secret material unless prior approval is obtained from the PSO. Couriers will be in the possession of PSO-issued courier authorization letters prior to travel. All material, to be mailed or carried, will be wrapped, and transmitted in accordance with DoDM 5205.07, Volume 1. An inventory of material to be couriered will be provided to the PSO prior to departure of the courier(s).

Prior to processing SAP information on any Automated Information System (AJS), the contractor will provide the PSO with a System Security Plan (SSP) and other documentation required in JSIG for Assessment & Authorization (A&A) from the Authorizing Official (AO), or subsequent policy. The PSO will issue program specific Security Authorization following verification of the A&A process. USSOCOM Special Access Program (SAP) Policy Memorandum: Removable Media and Two-Person Integrity Control Policy is applicable for this contract. All requirements of USSOCOM Manual 380-3 (Cybersecurity) and 380-19 (Mobility and Wireless Communications) will be adhered to.

Reproduction of program material will be conducted only be program indoctrinated personnel using only reproduction equipment and security procedures approved by the GPSO. A single person may reproduce non-accountable (Secret and below) classified material. All Top Secret (SAP) material must be reproduced by two program-indoctrinated individuals and must be documented and brought under formal accountability procedures.

Destruction of program material will be conducted only by program indoctrinated personnel. Destruction equipment and procedures approved by the PSO. A single person may destroy non accountable classified material. Accountable material must be destroyed and documented by two program cleared individuals.

The government PSO will be advised within 24 hours of any matters which affect the baseline facility clearance. The CPSO will also report any incident that may have an adverse impact on a personnel security clearance eligibility or access within 24 hours.

All personnel with a security clearance are required to report any information that could have an impact on their ability to protect classified information and/or as documented in Security Executive Agent Directive Three (SEAD 3) (Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position). CPSOs are reminded of their responsibilities to diligently report any significant action or any change in an employee’s eligibility to the PSO immediately.

A security incident is a broad term to describe security infractions, violations, and compromises. These terms have succinct meanings; are further explained, defined, and require specific actions by the CPSO. The DoD definitions for these terms are defined in DoD Manual 5200.01-V3. If work under this contract is authorized in contractor-controlled or operated workspaces, CPSOs are required to contact the PSO or USSOCOM SAPMO whenever a security incident occurs in the contractor-controlled workspace involving a contract employee under this effort.

Per DoD Manual 5205.07 Volume 1, Encl 11. Sec 3: "Any (contractual) relationship with a prospective subcontractor requires prior approval by the PSO." All security requirements levied upon the prime contractor will "flow-down'' to the subcontractor. SAP access and other requirements must be pre-coordinated and approved by the PSO prior to staffing and implementation. All new SAP DD Form 254s for acknowledged SOF SAPs shall be marked Controlled Unclassified Information (CUI) unless the contractor relationship is approved as a sensitive industrial relationship. Then the DD 254 will be marked at a higher level. All new DD254 for unacknowledged SOF SAPs may be marked CUI or a higher classification when required. All cleared defense contractors with contracts that require access to SOF SAPs must be registered in the USSOCOM Central Repository and utilize the National Industrial Security Program Classification System unless a sensitive industrial relationship is approved.

PROTECTING “CONTROLLED UNCLASSIFIED INFORMATION” (CUI)

CUI Addendum (Updated March 2021)

1. GENERAL:

a. Controlled Unclassified Information (CUI) is not a security classification, but designates unclassified information that requires any safeguarding or dissemination control per DoD Instruction 5200.48, “Controlled Unclassified Information” (6 March 2020).

b. With the implementation of DoDI 5200.48, DoDI 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information” (24 February 2012, as amended), has been cancelled and “For Official Use Only” (FOUO) and is no longer authorized. All new documents shall be marked in accordance with the guidance below.

c. In order to balance the need to safeguard CUI with the public interest the CUI Registry, established by DoDI 5200.48, lists categories of CUI Basic/Specified and identifies basis for controls, and includes guidance on handling procedures.

d. There are two subsets of CUI.

i. CUI Basic is the subset of CUI for which law, regulation, or government policy does not set out specific handling or dissemination controls. CUI Basic handling and dissemination controls are the same as previously used for FOUO.

ii. CUI Specified is the subset of CUI for which law, regulation, or government policy contains specific handling controls that differ from CUI Basic. The government will provide marking and handling guidance separately for CUI Specified.

e. Remarking legacy FOUO documents is not required as long as they remain under DoD control. When needed, FOUO information does not automatically become CUI, so the material must be reviewed by the information owner to determine if it meets the CUI requirements and marked appropriately.

f. When responding to FOIA requests, the responsible DoD agency must base its decision on the content of the information and applicability of any of the FOIA statutory exemptions regardless of whether an agency designates or marks the information as CUI.

2. DESIGNATION as CUI: Designating CUI occurs when an authorized holder, consistent with DoDI 5200.48 and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory. The information must be designated as either CUI Basic or CUI Specified and the authorized holder must ensure that appropriate markings are applied to documents to ensure recipients are aware of the CUI status. See the associated Security Classification Guide (SCG) or other guidance provided by the Government Contracting Agency (GCA) for specific categories of CUI related to this contract and guidance on storage, handling, and dissemination.

3. MARKING:

a. Unclassified documents containing CUI will be marked CUI at the top & bottom of each page. As a best practice each “portion” (i.e. titles, subject lines, paragraphs, bullets, charts, etc.) containing CUI may be Portion Marked (CUI). If portion marks are used then Unclassified portions will be Portion Marked (U). Do not use (U//CUI).

b. The government will provide marking, handling, and dissemination guidance separately for any CUI Specified information. For classified contracts, this guidance will be contained in the associated SCG.

c. The following CUI Designation Indicator information will be included on the first/title page or cover of all unclassified documents containing CUI:

Controlled by: [Name of DoD Component and Office] CUI Category: [List of Category or Categories of CUI] Distribution/Dissemination Control: [Use “None” for CUI Basic/As required for CUI Specified) POC: [Phone Number and/or E-mail]

d. Classified documents containing CUI will NOT include CUI in the banner marking at the top and bottom of each page. Each paragraph that contains only CUI will be portion marked (CUI). All other paragraphs will be marked according to their classification. Do not “co-mingle” CUI with classified information. The above CUI Designation Indicator information must be included on the first page or cover (same as unclassified documents). Additionally, the following statement must be included on the first page of documents that contain both CUI and classified information:

This content is classified at the [insert highest classification level of the document] level and may contain elements of controlled unclassified information (CUI), unclassified, or information classified at a lower level than the overall classification displayed. This content shall not be used as a source of derivative classification; refer to [cite specific reference or applicable Security Classification Guide]. It must be reviewed for both Classified National Security Information (CNSI) and CUI in accordance with DoDI 5230.09 prior to public release.

4. PROCESSING: Unclassified Automated Information Systems (AIS) used to process CUI under this contract must meet the basic security requirements listed in the NIST SP 800-171 REV 2, “Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations”, 21 February 2020. AIS accredited and approved for processing classified information under this contract are also approved to process DoD CUI.

5. DISSEMINATION: CUI may be disseminated between officials of DoD Agencies, DoD contractors, consultants and grantees to conduct official business for the DoD provided the dissemination is consistent with controls imposed by a Distribution Statement or Limited Dissemination Controls (LDC). Guidance on Distribution Statements and LDCs will be provided separately by the government for any prescribed CUI Specified information. For classified contracts, this information will be contained in the program SCG. CUI always requires Foreign Disclosure Decision before release outside of DoD Agencies, DoD contractors, consultants and grantees.

6. STORAGE: During working hours, to prevent unauthorized access, do not leave CUI unattended, read or discuss around unauthorized personnel. CUI shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During non-working hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.

7. TRANSMISSION: CUI may be transmitted using the following:

a. Mail – CUI may be sent via first class mail or parcel post. Bulk shipments may be sent by fourth class mail. Contents must be properly marked, but no markings will appear on the outer wrapper.

b. Fax – Normally CUI may be sent via Facsimile equipment. To prevent unauthorized disclosure, coversheets should be used, the locations of both fax machines should be considered, and availability of an authorized recipient at the receiving end should be confirmed. Secure classified fax machines may be used without the above verifications.

c. E-Mail/Web Sites – E-mail may be used on approved secure communication systems or systems using other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https). E-mail messages must be appropriately marked to identify CUI status. Personnel will not use unofficial or personal email accounts, messaging systems, or other non-DoD information systems, except approved government contractor systems to conduct official business involving CUI.

d. Video Teleconferencing – Only use Government Agency approved secure, encrypted video conferencing and collaborative platforms (i.e. SVTC, etc.). CUI may not be discussed over commercially available video conferencing applications.

e. Avoid wireless transmission unless no other means are available.

8. DESTRUCTION: When no longer needed, CUI must be disposed of in a way that will make it unreadable, indecipherable, and irrecoverable. Use of approved sensitive/classified material destruction devices is recommended. (ISOO CUI Notice 2019-03, “Destroying Controlled Unclassified Information in Paper Form”, 15 July 2019)

9. UNAUTHORIZED DISCLOSURE: Report misuse, mishandling, or Unauthorized Disclosure of CUI to the Unauthorized Disclosure Program Management Office, the Controlling Agency and the appropriate Military Department Counterintelligence Organization. While Unauthorized Disclosure of CUI does not constitute a security violation, a formal security inquiry/investigation is required if disciplinary action will be taken against the individual(s) responsible. Unauthorized Disclosure of certain CUI, such as export controlled-technical data, may also result in civil and criminal sanctions against responsible persons based on procedures codified in relevant law, regulation, or government-wide policy.

Click on this button to attach a file(s).:
rep:
Enter signature.:
Explain and identify specific areas and government activity responsible for inspections.: While performing duties at USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), Theater Special Operation Command (SOCNORTH, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, SOCAFRICA, or SOCKOR) or other U.S. Government owned and operated facilities, the contractor will adhere to the applicable Information Security Program, ADP and DODIIS Programs, Physical Security Program, Industrial Security Program, and SCI/SAP Program (if applicable). Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a U.S. Government clearance at the appropriate level.

Training Requirement: Contractors performing on this contract at military installations are required to conduct command and unit specific security training (Initial/Refresher INFOSEC, OPSEC, EMSEC, AT/FP, Intelligence Oversight, etc.). This training will be provided by the responsible military organization.

IA requirements: Specific Information Assurance requirements may be mandated and are authorized by the responsible command/unit where primary performance location is identified.

All classified information/hardware developed will be classified pursuant to derivative classification procedures or as any applicable classification guide so dictates (NISPOM Ch 4, Section 2) and Executive Order 12958 as amended. The United States Special Operations Command Security Classification Guide for the Distributed Common Ground/Surface System – Special Operations Forces (DCGS-SOF), dated 18 April 2011, can be made available by the program manager located in Item 13. Inquiries pertaining to classification guidance will be directed to the responsible USSOCOM contract monitor (Mr. Chad Raaymakers, 813-826-6095, chad.j.raaymakers.civ@socom.mil).

Contractor meetings or visits conducted IAW NISPOM, Section §117.16 & DoDM 5200.01-V3, Enclosure 2, Section 16.

All classified material generated under this contract will be derivatively classified IAW Executive Order 13526, based on existing source documents or applicable classification guides.

All transportation or transmission of classified information/material to and from USSOCOM facilities shall be conducted IAW USSOCOM Manual 380-1, Information Security Program, Chapter 7.

USSOCOM Contracting Activity will be notified prior to any subcontracting of this effort.

In the event that no government employee or military service member is otherwise available, the contractor may be required to conduct security-related functions (traditionally considered inherently government functions) such as escorting cleared/un-cleared visitors, opening/closing of security containers, conducting end-of-day security checks, and arming/de-arming alarm security systems within open/non-open Collateral storage areas and Sensitive Compartmented Information Facilities (SCIFs) used for the safeguarding of classified information/material. In support of this, the contractor is approved to conduct the above actions for the following facilities and buildings/rooms/suites.

- MacDill AFB, USSOCOM, Bldg. 501E, Room 236

In the event that the contractor fails to properly conduct these responsibilities and a security violation/incident occurs, the government will have the option to take action against…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .