Attachment 2 - Model Contract.pdf

PDF 7 MB Posted

Attached to
Enabling Cyber-Linked Physical Sensing Exploitation (ECLPSE) Federal contract opportunity
Solicitation number
FA8650-21-S-1016
Issued by
Department of the Air Force Materiel Command Research Laboratory

About this file

This is a solicitation for a two-step open Broad Agency Announcement (BAA) to support research on cyber-physical sensing, electronic warfare effects, and related topics. The effort aims to generate understanding of how cyber-connected devices interact with the physical environment across sectors like manufacturing, utilities, transportation, healthcare, and more. Additional objectives involve systems analysis of behaviors, interactions, and vulnerabilities; research and development; experiments and evaluations; small unmanned systems exploitation; cyber research; electronic warfare research; machine learning; autonomy; information fusion; and novel exploitation products. The projected Technology Readiness Levels range from 1 to 4. Potential also exists for incidental operations and maintenance work and procurement work using non-research, development, test, and evaluation funding. The issuing agency is the U.S. Air Force Materiel Command Research Laboratory. The estimated period of performance is 15 years with 15% of work involving basic research, 70% applied research, and 15% advanced research.

View the file

Other files for this federal contract opportunity

Other files attached to Enabling Cyber-Linked Physical Sensing Exploitation (ECLPSE), newest first.
File Type Posted
ECLPSE Amendment 4.pdf PDF
ECLPSE Amendment 3.pdf PDF
ECLPSE Amendment 2.pdf PDF
ECLPSE Amendment 1.pdf PDF
ECLPSE Qs and As.pdf PDF
ECLPSE Qs and As.pdf PDF
Attachment 5 - DD254.pdf PDF
Attachment 1 - Proposals for Assistance Instruments.pdf PDF
ECLPSE Open BAA.pdf PDF
Attachment 6 - SCI Addendum.pdf PDF
Attachment 3 - Proposal Adequacy Checklist.pdf PDF
Attachment 4 - Statement of Objectives.pdf PDF
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOLICITATION, OFFER AND AWARD

1. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 350)

RATING

DO-A7

PAGE OF PAGES

1 29

2. CONTRACT NO. 3. SOLICITATION NO. 4. TYPE OF SOLICITATION

SEALED BID (IFB)

NEGOTIATED (RFP)

5. DATE ISSUED

6. REQUISITION/PURCHASE NO.

FA8650-21-R-1016

7. ISSUED BY AFRL/RYKSR CODE FA8650 8. ADDRESS OFFER TO (If other than Item 7)

USAF/AFMC

AFRL WRIGHT RESEARCH SITE

2130 EIGHTH STREET, BUILDING 45

WRIGHT-PATTERSON AFB OH 45433-7541

JESSICA A. WARD 937-713-9853

JESSICA.WARD.15@US.AF.MIL

NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder”.

SOLICITATION

9.

10. FOR

INFORMATION

CALL:

A. NAME

See Block 7

B. TELEPHONE (Include area code)

(NO COLLECT CALLS)

C. E-MAIL ADDRESS

11. TABLE OF CONTENTS

() SEC. DESCRIPTION PAGE(S) () SEC DESCRIPTION PAGE(S)

PART I - THE SCHEDULE PART II - CONTRACT CLAUSES

A SOLICITATION/CONTRACT FORM 1 I CONTRACT CLAUSES 15

B SUPPLIES OR SERVICES AND PRICES/COSTS 2 PART III - LIST OF DOCUMENTS, EXHIBITS, AND OTHER ATTACH.

C DESCRIPTION/SPECS./WORK STATEMENT 5 J LIST OF ATTACHMENTS 29

D PACKAGING AND MARKING 6 PART IV - REPRESENTATIONS AND INSTRUCTIONS

E INSPECTION AND ACCEPTANCE 7 K REPRESENTATIONS, CERTIFICATIONS, K - 1

F DELIVERIES OR PERFORMANCE 8 AND OTHER STATEMENTS OF OFFERORS

G CONTRACT ADMINISTRATION DATA 11 L INSTRS, CONDS, AND NOTICES TO OFFERORS L - 1

H SPECIAL CONTRACT REQUIREMENTS 14 M EVALUATION FACTORS FOR AWARD M - 1

OFFER (Must be fully completed by offeror) NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

12. In compliance with the above, the undersigned agrees, if this offer is accepted within ________ calendar days (60 calendar days unless a different period is inserted by the offeror) from the date of receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause No. 52.232-8)

10 CALENDAR DAYS

20 CALENDAR DAYS

30 CALENDAR DAYS

CALENDAR DAYS

14. ACKNOWLEDGEMENTS OF AMENDMENTS

(The offeror acknowledges receipt of amend-

AMENDMENT NO. DATE AMENDMENT NO. DATE

ments to the SOLICITATION for offerors and related documents numbered and dated:

15A. NAME

AND

CODE FACILITY 16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN

OFFER (Type or print)

ADDRESS

OF

OFFEROR

15B. TELEPHONE NO. (Include area code)

15C. CHECK IF REMITTANCE ADDRESS

IS DIFFERENT FROM ABOVE - ENTER

SUCH ADDRESS IN SCHEDULE.

17. SIGNATURE 18. OFFER DATE

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETI-

TION: 23. SUBMIT INVOICES TO ADDRESS SHOWN IN

(4 copies unless otherwise specified)

ITEM

10 U.S.C. 2304(c) ( ) 41 U.S.C. 253(c) ( )

24. ADMINISTERED BY (If other than Item 7) CODE 25. PAYMENT WILL BE MADE BY CODE

26. NAME OF CONTRACTING OFFICER (Type or print) 27. UNITED STATES OF AMERICA

(Signature of Contracting Officer)

28. AWARD DATE

IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.

AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 33 (REV. 9-97)

PREVIOUS EDITION IS UNUSABLE Prescribed by GSA

ConWrite Version 7.4.1600 FAR (48 CFR) 53.21(c) Created 22 Feb 2021 1:29 PM

PART I - THE SCHEDULE

SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS

SECTION B FA8650-21-R-1016

Qty Unit Price ITEM SUPPLIES OR SERVICES Purch Unit Total Item Amount

0001 1 __________ Lot __________ Noun: RESEARCH AND DATA

PSC: AC12

NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: U - COST PLUS FIXED FEE Inspection: DESTINATION Acceptance: DESTINATION

FOB: DESTINATION

Descriptive Data:

The contractor shall conduct research entitled "XXXX" in accordance with the Statement of Work (SOW), dated DDMMYR, attached in Section J, Attachment 1. Deliver data in accordance with Section J, Exhibit A, Contract Data Requirements List (CDRLS), DD Form 1423-1, dated DDMMYR.

The estimated cost and fixed fee amounts are shown below:

Cost: To Be Determined Fixed Fee: To Be Determined CPFF: To Be Determined

Pursuant to FAR 52.232-22, "Limitation of Funds" in Section I, the total amount available for payment and allotted to this contract for CLIN(s) XXXX is $XXXX. It is estimated that this amount is sufficient to cover performance through DDMMYR.

If O&M and Procurement work is required, the following paragraph will be added in any resulting contract.

The total estimated CPFF value includes non-RDT&E work. Upon Government receipt of non-RDT&E funding, the non-RDT&E funding amount will be deobligated from the face value of CLIN 0001 and then obligated to a newly established non-RDT&E CLIN. For each occurence, O&M CLINs will be a To Be Determined contract type and Procurement CLINs will be a To Be Determined contract type. Neither O&M nor Procurement CLINs will effect the overall period of performance of the ECLPSE effort.

The following SOW paragraphs are not applicable to R&D work performed under CLIN 0001:

Operations & Maintenance To Be Determined

Procurement To Be Determined

When non-RDT&E work is required, a contract modification will incorporate the new non-

RDT&E CLIN.

Qty Unit Price ITEM SUPPLIES OR SERVICES Purch Unit Total Item Amount

0002 1 __________ Lot __________ Noun: SOFTWARE

PSC: AC12

NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: U - COST PLUS FIXED FEE Inspection: DESTINATION Acceptance: DESTINATION

FOB: DESTINATION

Descriptive Data:

The contractor shall deliver software in accordance with Section J, Attachment 1, Statement of Work (SOW), dated DDMMYR. The contractor shall deliver any and all software, source code, executables, and software documentation developed and/or acquired via the course of this effort. The cost of the software is included in the price of

CLIN 0001.

Software deliverables include, but are not limited to the following: To Be Determined

0003 1 __________ Lot __________ Noun: HARDWARE

PSC: AC12

NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: U - COST PLUS FIXED FEE Inspection: DESTINATION Acceptance: DESTINATION

FOB: DESTINATION

Descriptive Data:

The contractor shall deliver hardware in accordance with Section J, Attachment 1, Statement of Work (SOW), dated DDMMYR. The contractor shall deliver any and all hardware developed and/or acquired via the course of this effort.

The cost of the hardware is included in the price of CLIN 0001. Hardware deliverables include, but are not limited to the following: To Be Determined

In accordance with DFARS 252.211-7003 entitled, "Item Unique Identification Valuation", the contractor shall identify the unit acquisition cost for all deliverable end items for which item unique identification applies.

NO CLAUSES OR PROVISIONS IN THIS SECTION

SECTION C - DESCRIPTION/SPECS./WORK STATEMENT

SECTION C FA8650-21-R-1016

SECTION D - PACKAGING AND MARKING

SECTION D FA8650-21-R-1016

SECTION E - INSPECTION AND ACCEPTANCE

SECTION E FA8650-21-R-1016

NOTICE: The following contract clauses pertinent to this section are hereby incorporated by reference:

FEDERAL ACQUISITION REGULATION CONTRACT CLAUSES

52.246-09 INSPECTION OF RESEARCH AND DEVELOPMENT (SHORT FORM) (APR 1984)

SECTION F - DELIVERIES OR PERFORMANCE

SECTION F FA8650-21-R-1016

SHIP MARK TRANS

ITEM SUPPLIES SCHEDULE DATA QTY TO FOR PRI DATE

0001 1 F4FBBG ASREQ

Noun: RESEARCH AND DATA

ACRN: 9

Descriptive Data:

The scheduled delivery date for the approved final technical report is DDMMYR. The technical effort shall be completed no later than 3 months before the date above. The contractor shall deliver data in accordance with Exhibit A, Contract Data Requirements List (CDRLS), DD Form 1423-1, dated DDMMYR. See DD Form 1423-1 for mailing and delivery addresses.

GUARANTEED FINAL REPORT

If, pursuant to FAR 52.232-22, full funding is not provided, the Contractor is required to deliver the final report, including all data, in accordance with CDRL A001, Section J, Exhibit A. During the life of the contract, the contractor shall continuously reserve sufficient funds from the amount allotted to guarantee the preparation and delivery of the final report.

(a) All reports and correspondence submitted under this contract shall include the contract number and project number, if applicable, and be forwarded prepaid. A copy of the letters of transmittal shall be delivered to the Procuring Contracting Officer (PCO) and Administrative Contracting Officer (ACO). The addresses are set forth on the contract award cover page. All other address(es) and code(s) for consignee(s) are as set forth in the contract or incorporated by reference.

Program Office:

AFRL/RYA

Eric Lam 2241 Avionics Circle, Bldg 620 Wright-Patterson AFB, OH 45433 eric.lam.3@us.af.mil (CDRLs A001-A017)

Finance Office:

AFRL/RYF

TBD

2241 Avionics Circle, Bldg 620 Wright-Patterson AFB, OH 45433 tbd@us.af.mil (CDRLs A002-A003)

Contract Office:

AFRL/RYKSR - See SF26 Block 5 (CDRLs A002-A004)

ACO:

DCMA - See SF26 Block 6 (CDRLs A002-A004)

STINFO: AFRL/RYOX

Lolita Mitchell 2241 Avionics Circle Wright-Patterson AFB, OH 45433 lolita.mitchell.1@us.af.mil

(CDRL A001)

AFRL/DO:

1864 Fourth St., Bldg 15, Wright-Patterson AFB, OH 45433-7130 afrl.do.workflow@us.af.mil

(CDRL A007)

SHIP MARK TRANS

ITEM SUPPLIES SCHEDULE DATA QTY TO FOR PRI DATE

0002 1 F4FBBG ASREQ

Noun: SOFTWARE Descriptive Data:

The scheduled delivery date for software is DDMMYR. The shipping address is as follows:

Eric Lam, AFRL/RYAA 2241 Avionics Circle, Bldg 620 Wright-Patterson AFB, OH 45433 eric.lam.3@us.af.mil Mark For: TBD

(Include contract number and the AF Program Manager's name, office symbol, and phone number on the shipping documents)

0003 1 F4FBBG ASREQ

Noun: HARDWARE Descriptive Data:

The scheduled delivery date for hardware is DDMMYR. This shipping address is as follows:

Eric Lam, AFRL/RYAA 2241 Avionics Circle, Bldg 620 Wright-Patterson AFB, OH 45433 eric.lam.3@us.af.mil Mark For: TBD

(Include contract number and the AF Program Manager's name, office symbol, and phone number on the shipping documents)

See Attachment 6, "SOW Supplemental Requirements," dated DDMMYR for marking and/or packaging instructions.

NOTICE: The following contract clauses pertinent to this section are hereby incorporated by reference:

FEDERAL ACQUISITION REGULATION CONTRACT CLAUSES

52.242-15 STOP-WORK ORDER (AUG 1989) - ALTERNATE I (APR 1984)

52.247-34 F.O.B. DESTINATION (NOV 1991)

SECTION G - CONTRACT ADMINISTRATION DATA

SECTION G FA8650-21-R-1016

NOTICE: The following contract clauses pertinent to this section are hereby incorporated in full text:

DEFENSE FAR SUPP CONTRACT CLAUSES IN FULL TEXT

252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (DEC 2018)

(a) Definitions. As used in this clause-

“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.

“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).

“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.

“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.

(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.

(c) WAWF access. To access WAWF, the Contractor shall—

(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov; and

(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.

(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web- Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/

(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.

(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:

(1) Document type. The Contractor shall submit payment requests using the following document type(s):

(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.

(ii) For fixed price line items-

(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.

Invoice and Receiving Report (Combo) to fulfill Clauses 52.232-02, Payment Under Fixed-Price Research and Development Contracts; 252.232-7003, Electronic Submission of Payment Requests.

(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.

Invoice 2-in-1

(iii) For customary progress payments based on costs incurred, submit a progress payment request.

(iv) For performance based payments, submit a performance based payment request.

(v) For commercial item financing, submit a commercial item financing request.

(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.

[Note: The Contractor may use a WAWF “combo” document type to create some combinations of invoice and receiving report in one step.]

(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.

Routing Data Table* Field Name in WAWF Data to be entered in WAWF

Pay Official DoDAAC TBD Issue By DoDAAC FA8650 Admin DoDAAC TBD Inspect By DoDAAC Vendor will leave this Block Blank Ship To Code TBD Ship From Code N/A Mark For Code N/A Service Approver (DoDAAC) TBD Service Acceptor (DoDAAC) TBD Accept at Other DoDAAC N/A LPO DoDAAC N/A DCAA Auditor DoDAAC Vendor shall use Look Up DCAA from toolbar at left of WAWF screen Other DoDAAC(s) N/A

(*Contracting Officer: Insert applicable DoDAAC information. If multiple ship to/acceptance locations apply, insert “See Schedule” or “Not applicable.”)

(**Contracting Officer: If the contract provides for progress payments or performance-based payments, insert the DoDAAC for the contract administration office assigned the functions under FAR 42.302(a)(13).)

(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.

(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.

(g) WAWF point of contact.

(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contact.

TBD

(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.

OTHER CONTRACT CLAUSES IN FULL TEXT

DFARS PGI 204.7108(D)(12) OTHER PAYMENT INSTRUCTIONS (MAY 2019)

This contract is a cost-type contract funded by multiple funding types and/or customers spanning several years. Funding for the CLINs contained in this contract are received from various funding sources and applied to specific tasking as defined in the funding modifications.

Based on the type of work contracted for on behalf of DOD/Navy customers, payment by CLIN/SLIN/ACRN is significantly important and using any of the payment methods specified in the table identified in PGI 204.7108(b)(2) would result in the funding resources of one customer being paid for work received by another customer. The contractor completes the effort in a fluid environment; therefore, in order to accurately track and account for funding expenditures in accordance with the specific tasking associated with each funding line, payment instruction (d)(12) "Other" applies as expenditures must reflect the actual work performed, in alignment with the type of funding to avoid violations to the Anti- Deficiency Act.

Payment shall be made in accordance with the Contracting Officer/DCAA approved billing whereby the contractor shall include identification of the CLIN, SLIN, and ACRN on each invoice. This will allow for appropriate contractor invoicing based on the unique customer requirement funding and Contracting Officer's instructions. This approach also allows for proper matching of the charge to the activity that have received the service/product with the application of the payment to the corresponding entity.

SECTION H - SPECIAL CONTRACT REQUIREMENTS

SECTION H FA8650-21-R-1016

PART II - CONTRACT CLAUSES

SECTION I - CONTRACT CLAUSES

SECTION I FA8650-21-R-1016

Contract Clauses in this section are from the FAR, Defense FAR Sup, Air Force FAR Sup, and the Air Force Materiel Command FAR Sup, and are current through the following updates:

Database_Version: 7.4.x.1600; Issued: 12/3/2019; FAR: FAC 2020-01; DFAR: DPN20191127; DL.: DL 98-021;

Class Deviations: CD 2020-O0001; AFFAR: 2002 Edition; AFAC: AFAC 2017-1003; IPN: 98-009

I. NOTICE: The following contract clauses pertinent to this section are hereby incorporated by reference:

A. FEDERAL ACQUISITION REGULATION CONTRACT CLAUSES

52.202-01 DEFINITIONS (JUN 2020)

52.203-03 GRATUITIES (APR 1984)

52.203-05 COVENANT AGAINST CONTINGENT FEES (MAY 2014)

52.203-06 RESTRICTIONS ON SUBCONTRACTOR SALES TO THE GOVERNMENT (JUN 2020)

52.203-07 ANTI-KICKBACK PROCEDURES (JUN 2020)

52.203-08 CANCELLATION, RESCISSION, AND RECOVERY OF FUNDS FOR ILLEGAL OR

IMPROPER ACTIVITY (MAY 2014)

52.203-10 PRICE OR FEE ADJUSTMENT FOR ILLEGAL OR IMPROPER ACTIVITY (MAY 2014)

52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN FEDERAL TRANSACTIONS

(JUN 2020)

52.203-13 CONTRACTOR CODE OF BUSINESS ETHICS AND CONDUCT (JUN 2020)

52.203-14 DISPLAY OF HOTLINE POSTER(S) (JUN 2020)

Para (b)(3). CO inserts info for obtaining posters. 'TBD'

52.203-16 PREVENTING PERSONAL CONFLICTS OF INTEREST (JUN 2020)

52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS AND REQUIREMENT TO

INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (JUN 2020)

52.203-19 PROHIBITION ON REQUIRING CERTAIN INTERNAL CONFIDENTIALITY

AGREEMENTS OR STATEMENTS (JAN 2017)

52.204-02 SECURITY REQUIREMENTS (AUG 1996)

52.204-02 SECURITY REQUIREMENTS (AUG 1996) - ALTERNATE I (APR 1984)

52.204-04 PRINTED OR COPIED DOUBLE-SIDED ON POSTCONSUMER FIBER CONTENT

PAPER (MAY 2011)

52.204-09 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR PERSONNEL (JAN 2011)

52.204-10 REPORTING EXECUTIVE COMPENSATION AND FIRST-TIER SUBCONTRACT

AWARDS (JUN 2020)

52.204-13 SYSTEM FOR AWARD MANAGEMENT MAINTENANCE (OCT 2018)

52.204-18 COMMERCIAL AND GOVERNMENT ENTITY CODE MAINTENANCE (AUG 2020)

52.204-19 INCORPORATION BY REFERENCE OF REPRESENTATIONS AND CERTIFICATIONS

(DEC 2014)

52.204-22 ALTERNATIVE LINE ITEM PROPOSAL (JAN 2017)

52.204-23 PROHIBITION ON CONTRACTING FOR HARDWARE, SOFTWARE, AND SERVICES

DEVELOPED OR PROVIDED BY KASPERSKY LAB AND OTHER COVERED

ENTITIES (JUL 2018)

52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN TELECOMMUNICATIONS AND

VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (AUG 2020)

52.209-06 PROTECTING THE GOVERNMENT'S INTEREST WHEN SUBCONTRACTING WITH

CONTRACTORS DEBARRED, SUSPENDED, OR PROPOSED FOR DEBARMENT

(JUN 2020)

52.209-09 UPDATES OF PUBLICLY AVAILABLE INFORMATION REGARDING RESPONSIBILITY

MATTERS (OCT 2018)

52.209-10 PROHIBITION ON CONTRACTING WITH INVERTED DOMESTIC CORPORATIONS

(NOV 2015)

52.209-14 RESERVE OFFICER TRAINING CORPS AND MILITARY RECRUITING ON CAMPUS

(NOV 2020)

52.210-01 MARKET RESEARCH (JUN 2020)

52.211-05 MATERIAL REQUIREMENTS (AUG 2000)

52.215-02 AUDIT AND RECORDS -- NEGOTIATION (JUN 2020)

52.215-02 AUDIT AND RECORDS -- NEGOTIATION (JUN 2020) - ALTERNATE II (AUG 2016)

52.215-08 ORDER OF PRECEDENCE--UNIFORM CONTRACT FORMAT (OCT 1997)

52.215-11 PRICE REDUCTION FOR DEFECTIVE CERTIFIED COST OR PRICING DATA--

MODIFICATIONS (JUN 2020)

52.215-12 SUBCONTRACTOR CERTIFIED COST OR PRICING DATA (JUN 2020)

52.215-13 SUBCONTRACTOR CERTIFIED COST OR PRICING DATA--MODIFICATIONS

(DEVIATION 2018-O0015) (MAY 2018)

52.215-14 INTEGRITY OF UNIT PRICES (JUN 2020) - ALTERNATE I (OCT 1997)

52.215-15 PENSION ADJUSTMENTS AND ASSET REVERSIONS (OCT 2010)

52.215-17 WAIVER OF FACILITIES CAPITAL COST OF MONEY (OCT 1997)

52.215-18 REVERSION OR ADJUSTMENT OF PLANS FOR POSTRETIREMENT BENEFITS

(PRB) OTHER THAN PENSIONS (JUL 2005)

52.215-19 NOTIFICATION OF OWNERSHIP CHANGES (OCT 1997)

52.215-21 REQUIREMENTS FOR CERTIFIED COST OR PRICING DATA AND DATA OTHER

THAN CERTIFIED COST OR PRICING DATA--MODIFICATIONS (JUN 2020)

52.215-23 LIMITATIONS ON PASS-THROUGH CHARGES (JUN 2020)

52.216-07 ALLOWABLE COST AND PAYMENT (AUG 2018)

52.216-07 ALLOWABLE COST AND PAYMENT (AUG 2018) - ALTERNATE II (AUG 2012)

Para (a) (3), Day prescribed by agency head, or "30th". '30th'

52.216-07 ALLOWABLE COST AND PAYMENT (AUG 2018) - ALTERNATE IV (AUG 2012)

Para (a) (3), Day prescribed by agency head, or "30th". '30th'

52.216-08 FIXED FEE (JUN 2011)

52.217-06 OPTION FOR INCREASED QUANTITY (MAR 1989)

Period of time is 'TBD'

52.219-08 UTILIZATION OF SMALL BUSINESS CONCERNS (OCT 2018)

52.219-09 SMALL BUSINESS SUBCONTRACTING PLAN (JUN 2020)

52.219-09 SMALL BUSINESS SUBCONTRACTING PLAN (JUN 2020) - ALTERNATE II (NOV

2016)

52.219-16 LIQUIDATED DAMAGES -- SUBCONTRACTING PLAN (JAN 1999)

52.219-28 POST-AWARD SMALL BUSINESS PROGRAM REREPRESENTATION (NOV 2020)

52.222-02 PAYMENT FOR OVERTIME PREMIUMS (JUL 1990)

Para (a), Dollar amount is '0.00'

52.222-03 CONVICT LABOR (JUN 2003)

52.222-21 PROHIBITION OF SEGREGATED FACILITIES (APR 2015)

52.222-26 EQUAL OPPORTUNITY (SEP 2016)

52.222-35 EQUAL OPPORTUNITY FOR VETERANS (JUN 2020)

52.222-36 EQUAL OPPORTUNITY FOR WORKERS WITH DISABILITIES (JUN 2020)

52.222-37 EMPLOYMENT REPORTS ON VETERANS (JUN 2020)

52.222-40 NOTIFICATION OF EMPLOYEE RIGHTS UNDER THE NATIONAL LABOR RELATIONS

ACT (DEC 2010)

52.222-50 COMBATING TRAFFICKING IN PERSONS (OCT 2020)

52.222-54 EMPLOYMENT ELIGIBILITY VERIFICATION (OCT 2015)

52.223-05 POLLUTION PREVENTION AND RIGHT-TO-KNOW INFORMATION (MAY 2011)

52.223-05 POLLUTION PREVENTION AND RIGHT-TO-KNOW INFORMATION (MAY 2011) -

ALTERNATE I (MAY 2011)

52.223-06 DRUG-FREE WORKPLACE (MAY 2001)

52.223-18 ENCOURAGING CONTRACTOR POLICIES TO BAN TEXT MESSAGING WHILE

DRIVING (JUN 2020)

52.225-13 RESTRICTIONS ON CERTAIN FOREIGN PURCHASES (JUN 2008)

52.227-01 AUTHORIZATION AND CONSENT (JUN 2020) - ALTERNATE I (APR 1984)

52.227-02 NOTICE AND ASSISTANCE REGARDING PATENT AND COPYRIGHT

INFRINGEMENT (JUN 2020)

52.227-10 FILING OF PATENT APPLICATIONS -- CLASSIFIED SUBJECT MATTER (DEC 2007)

52.227-11 PATENT RIGHTS - OWNERSHIP BY THE CONTRACTOR (MAY 2014)

Para (j), Communications: 'TBD'

52.228-07 INSURANCE -- LIABILITY TO THIRD PERSONS (MAR 1996)

52.230-02 COST ACCOUNTING STANDARDS (DEVIATION 2018-O0015) (MAY 2018)

52.230-02 COST ACCOUNTING STANDARDS (JUN 2020)

52.230-05 COST ACCOUNTING STANDARDS - EDUCATIONAL INSTITUTION (JUN 2020)

52.230-06 ADMINISTRATION OF COST ACCOUNTING STANDARDS (JUN 2010)

52.232-09 LIMITATION ON WITHHOLDING OF PAYMENTS (APR 1984)

52.232-17 INTEREST (MAY 2014)

52.232-20 LIMITATION OF COST (APR 1984)

52.232-22 LIMITATION OF FUNDS (APR 1984)

52.232-23 ASSIGNMENT OF CLAIMS (MAY 2014) - ALTERNATE I (APR 1984)

52.232-25 PROMPT PAYMENT (JAN 2017)

52.232-33 PAYMENT BY ELECTRONIC FUNDS TRANSFER - SYSTEM FOR AWARD

MANAGEMENT (OCT 2018)

52.232-39 UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS (JUN 2013)

52.232-40 PROVIDING ACCELERATED PAYMENTS TO SMALL BUSINESS

SUBCONTRACTORS (DEC 2013)

52.233-01 DISPUTES (MAY 2014)

52.233-03 PROTEST AFTER AWARD (AUG 1996) - ALTERNATE I (JUN 1985)

52.233-04 APPLICABLE LAW FOR BREACH OF CONTRACT CLAIM (OCT 2004)

52.237-02 PROTECTION OF GOVERNMENT BUILDINGS, EQUIPMENT AND VEGETATION

(APR 1984)

52.242-01 NOTICE OF INTENT TO DISALLOW COSTS (APR 1984)

52.242-03 PENALTIES FOR UNALLOWABLE COSTS (MAY 2014)

52.242-04 CERTIFICATION OF FINAL INDIRECT COSTS (JAN 1997)

52.242-05 PAYMENTS TO SMALL BUSINESS SUBCONTRACTORS (JAN 2017)

52.242-13 BANKRUPTCY (JUL 1995)

52.243-02 CHANGES -- COST-REIMBURSEMENT (AUG 1987) - ALTERNATE V (APR 1984)

52.243-06 CHANGE ORDER ACCOUNTING (APR 1984)

52.243-07 NOTIFICATION OF CHANGES (JAN 2017)

Para (b), Number of calendar days is (insert 30 for RDSS/C) '30 days' Para (d), Number of calendar days is (insert 30 for RDSS/C) '30 days'

52.244-02 SUBCONTRACTS (JUN 2020)

Para (d), approval required on subcontracts: 'TBD' Para (j), Insert subcontracts evaluated during negotiations. 'TBD'

52.244-05 COMPETITION IN SUBCONTRACTING (DEC 1996)

52.244-06 SUBCONTRACTS FOR COMMERCIAL ITEMS (NOV 2020)

52.245-01 GOVERNMENT PROPERTY (JAN 2017)

52.245-01 GOVERNMENT PROPERTY (JAN 2017) - ALTERNATE II (APR 2012)

52.245-09 USE AND CHARGES (APR 2012)

52.246-23 LIMITATION OF LIABILITY (FEB 1997)

52.247-01 COMMERCIAL BILL OF LADING NOTATIONS (FEB 2006)

52.247-67 SUBMISSION OF TRANSPORTATION DOCUMENTS FOR AUDIT (FEB 2006)

Para (c). Insert address. 'TBD'

52.249-05 TERMINATION FOR CONVENIENCE OF THE GOVERNMENT (EDUCATIONAL AND

OTHER NONPROFIT INSTITUTIONS) (AUG 2016)

52.249-06 TERMINATION (COST-REIMBURSEMENT) (MAY 2004)

52.249-14 EXCUSABLE DELAYS (APR 1984)

52.251-01 GOVERNMENT SUPPLY SOURCES (APR 2012)

52.253-01 COMPUTER GENERATED FORMS (JAN 1991)

B. DEFENSE FEDERAL ACQUISITION REGULATION SUPPLEMENT CONTRACT CLAUSES

252.201-7000 CONTRACTING OFFICER'S REPRESENTATIVE (DEC 1991)

252.203-7000 REQUIREMENTS RELATING TO COMPENSATION OF FORMER DOD OFFICIALS

(SEP 2011)

252.203-7001 PROHIBITION ON PERSONS CONVICTED OF FRAUD OR OTHER DEFENSE-

CONTRACT-RELATED FELONIES (DEC 2008)

252.203-7002 REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (SEP

2013)

252.203-7003 AGENCY OFFICE OF THE INSPECTOR GENERAL (AUG 2019)

252.203-7004 DISPLAY OF HOTLINE POSTERS (AUG 2019)

252.204-7000 DISCLOSURE OF INFORMATION (OCT 2016)

252.204-7002 PAYMENT FOR SUBLINE ITEMS NOT SEPARATELY PRICED (APR 2020)

252.204-7003 CONTROL OF GOVERNMENT PERSONNEL WORK PRODUCT (APR 1992)

252.204-7004 LEVEL I ANTITERRORISM AWARENESS TRAINING FOR CONTRACTORS (FEB

2019)

252.204-7015 NOTICE OF AUTHORIZED DISCLOSURE OF INFORMATION TO LITIGATION

SUPPORT (MAY 2016)

252.204-7018 PROHIBITION ON THE ACQUISITION OF COVERED DEFENSE

TELECOMMUNICATIONS EQUIPMENT OR SERVICES (DEC 2019)

252.204-7020 NIST SP 800-171 DOD ASSESSMENT REQUIREMENTS (NOV 2020)

252.205-7000 PROVISION OF INFORMATION TO COOPERATIVE AGREEMENT HOLDERS (DEC

1991)

252.209-7004 SUBCONTRACTING WITH FIRMS THAT ARE OWNED OR CONTROLLED BY THE

GOVERNMENT OF A COUNTRY THAT IS A STATE SPONSOR OF TERRORISM

(MAY 2019)

252.211-7003 ITEM UNIQUE IDENTIFICATION AND VALUATION (MAR 2016)

Para (c)(1)(i). Insert Contract Line, Subline, or Exhibit Line Item Number and Item

Description or n/a. 'TBD' Para (c)(1)(ii). Identify Contract Line, Subline, or Exhibit Line Item Nr and Item

Description. If items are identified in the Schedule, insert "See Schedule" 'TBD' Para (c)(1)(iii). Attachment Nr. 'TBD' Para (c)(1)(iv). Attachment Nr. 'TBD' Para (f)(2)(iii). Line item number or n/a. 'TBD'

252.211-7007 REPORTING OF GOVERNMENT-FURNISHED PROPERTY (AUG 2012)

252.211-7008 USE OF GOVERNMENT-ASSIGNED SERIAL NUMBERS (SEP 2010)

252.215-7002 COST ESTIMATING SYSTEM REQUIREMENTS (DEC 2012)

252.216-7009 ALLOWABILITY OF LEGAL COSTS INCURRED IN CONNECTION WITH A

WHISTLEBLOWER PROCEEDING (SEP 2013)

252.219-7003 SMALL BUSINESS SUBCONTRACTING PLAN (DOD CONTRACTS) -- BASIC (DEC

2019)

252.222-7006 RESTRICTIONS ON THE USE OF MANDATORY ARBITRATION AGREEMENTS (DEC

2010)

252.223-7004 DRUG-FREE WORK FORCE (SEP 1988)

252.223-7006 PROHIBITION ON STORAGE, TREATMENT, AND DISPOSAL OF TOXIC OR

HAZARDOUS MATERIALS - BASIC (SEP 2014)

252.225-7012 PREFERENCE FOR CERTAIN DOMESTIC COMMODITIES (DEC 2017)

252.225-7048 EXPORT-CONTROLLED ITEMS (JUN 2013)

252.226-7001 UTILIZATION OF INDIAN ORGANIZATIONS, INDIAN-OWNED ECONOMIC

ENTERPRISES, AND NATIVE HAWAIIAN SMALL BUSINESS CONCERNS (APR 2019)

252.227-7013 RIGHTS IN TECHNICAL DATA--NONCOMMERCIAL ITEMS (FEB 2014)

252.227-7014 RIGHTS IN NONCOMMERCIAL COMPUTER SOFTWARE AND NONCOMMERCIAL

COMPUTER SOFTWARE DOCUMENTATION (FEB 2014)

252.227-7015 TECHNICAL DATA--COMMERCIAL ITEMS (FEB 2014)

252.227-7016 RIGHTS IN BID OR PROPOSAL INFORMATION (JAN 2011)

252.227-7019 VALIDATION OF ASSERTED RESTRICTIONS--COMPUTER SOFTWARE (SEP 2016)

252.227-7025 LIMITATIONS ON THE USE OR DISCLOSURE OF GOVERNMENT-FURNISHED

INFORMATION MARKED WITH RESTRICTIVE LEGENDS (MAY 2013)

252.227-7030 TECHNICAL DATA--WITHHOLDING OF PAYMENT (MAR 2000)

252.227-7037 VALIDATION OF RESTRICTIVE MARKINGS ON TECHNICAL DATA (SEP 2016)

252.227-7038 PATENT RIGHTS--OWNERSHIP BY THE CONTRACTOR (LARGE BUSINESS) (JUN

2012)

252.227-7039 PATENTS--REPORTING OF SUBJECT INVENTIONS (APR 1990)

252.228-7001 GROUND AND FLIGHT RISK (JUN 2010)

252.228-7005 MISHAP REPORTING AND INVESTIGATION INVOLVING AIRCRAFT, MISSILES, AND

SPACE LAUNCH VEHICLES (NOV 2019)

252.231-7000 SUPPLEMENTAL COST PRINCIPLES (DEC 1991)

252.232-7003 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS AND RECEIVING REPORTS

(DEC 2018)

252.232-7010 LEVIES ON CONTRACT PAYMENTS (DEC 2006)

252.232-7017 ACCELERATING PAYMENTS TO SMALL BUSINESS SUBCONTRACTORS—

PROHIBITION ON FEES AND CONSIDERATION (APR 2020)

252.235-7010 ACKNOWLEDGMENT OF SUPPORT AND DISCLAIMER (MAY 1995)

Para (a), name of contracting agency(ies): 'United States Air Force' Para (a), contract number(s): 'FA865021R1016' Para (b), name of contracting agency(ies): 'United States Air Force'

252.235-7011 FINAL SCIENTIFIC OR TECHNICAL REPORT (DEC 2019)

252.239-7018 SUPPLY CHAIN RISK (FEB 2019)

252.242-7004 MATERIAL MANAGEMENT AND ACCOUNTING SYSTEM (MAY 2011)

252.242-7005 CONTRACTOR BUSINESS SYSTEMS (FEB 2012)

252.242-7006 ACCOUNTING SYSTEM ADMINISTRATION (FEB 2012)

252.243-7002 REQUESTS FOR EQUITABLE ADJUSTMENT (DEC 2012)

252.244-7000 SUBCONTRACTS FOR COMMERCIAL ITEMS (OCT 2020)

252.244-7001 CONTRACTOR PURCHASING SYSTEM ADMINISTRATION - BASIC (MAY 2014)

252.245-7001 TAGGING, LABELING, AND MARKING OF GOVERNMENT-FURNISHED PROPERTY

(APR 2012)

252.245-7002 REPORTING LOSS OF GOVERNMENT PROPERTY (DEVIATION 2020-O0004) (FEB

2020)

252.245-7003 CONTRACTOR PROPERTY MANAGEMENT SYSTEM ADMINISTRATION (APR 2012)

252.245-7004 REPORTING, REUTILIZATION, AND DISPOSAL (DEC 2017)

Insert Item(s) 'TBD' Insert Item(s) 'TBD'

252.246-7003 NOTIFICATION OF POTENTIAL SAFETY ISSUES (JUN 2013)

252.246-7004 SAFETY OF FACILITIES, INFRASTRUCTURE, AND EQUIPMENT FOR MILITARY

OPERATIONS (OCT 2010)

252.246-7007 CONTRACTOR COUNTERFEIT ELECTRONIC PART DETECTION AND AVOIDANCE

SYSTEM (AUG 2016)

252.246-7008 SOURCES OF ELECTRONIC PARTS (MAY 2018)

252.247-7023 TRANSPORTATION OF SUPPLIES BY SEA - BASIC (FEB 2019)

252.251-7000 ORDERING FROM GOVERNMENT SUPPLY SOURCES (AUG 2012)

Para (f), Contractor's address is 'TBD' Para (f), Government remittance address is 'TBD'

C. AIR FORCE FEDERAL ACQUISITION REGULATION SUPPLEMENT CONTRACT CLAUSES

5352.201-9101 OMBUDSMAN (OCT 2019)

Para (c). Ombudsmen names, addresses, phone numbers, fax, and email addresses.

'AFRL/PK Director Alternate Ombudsman: AFRL/PK Deputy Director

1864 Fourth Street

Wright-Patterson AFB OH 45433-7130

(p) 937-904-9700

(f) 937-656-7321 afrl.pk.workflow@us.af.mil'

5352.204-9000 NOTIFICATION OF GOVERNMENT SECURITY ACTIVITY AND VISITOR GROUP

SECURITY AGREEMENTS (OCT 2019)

5352.223-9000 ELIMINATION OF USE OF CLASS I OZONE DEPLETING SUBSTANCES (ODS) (OCT

2019)

5352.223-9001 HEALTH AND SAFETY ON GOVERNMENT INSTALLATIONS (OCT 2019)

II. NOTICE: The following contract clauses pertinent to this section are hereby incorporated in full text:

FEDERAL ACQUISITION REGULATION CONTRACT CLAUSES IN FULL TEXT

52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION SYSTEMS (JUN

2016)

(a) Definitions. As used in this clause--

Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.

Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public Web sites) or simple transactional information, such as necessary to process payments.

Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).

Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502).

Safeguarding means measures or controls that are prescribed to protect information systems.

(b) Safeguarding requirements and procedures.

(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:

(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

(iii) Verify and control/limit connections to and use of external information systems.

(iv) Control information posted or processed on publicly accessible information systems.

(v) Identify information system users, processes acting on behalf of users, or devices.

(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

(xii) Identify, report, and correct information and information system flaws in a timely manner.

(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.

(xiv) Update malicious code protection mechanisms when new releases are available.

(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.

(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (c), in subcontracts under this contract (including subcontracts for the acquisition of commercial items, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.

52.211-15 DEFENSE PRIORITY AND ALLOCATION REQUIREMENTS (APR 2008)

This is a rated order certified for national defense, emergency preparedness, and energy program use, and the Contractor shall follow all the requirements of the Defense Priorities and Allocations System regulation (15 CFR 700).

52.252-02 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

https://www.acquisition.gov/browse/index/far https://www.acquisition.gov/dfars https://www.acquisition.gov/affars

52.252-06 AUTHORIZED DEVIATIONS IN CLAUSES (NOV 2020)

(a) The use in this solicitation or contract of any Federal Acquisition Regulation (48 CFR Chapter

1) clause with an authorized deviation is indicated by the addition of "(DEVIATION)" after the date of the clause.

(b) The use in this solicitation or contract of any Defense Federal Acquisition Regulation Supplement (48 CFR Chapter 2) clause with an authorized deviation is indicated by the addition of "(DEVIATION)" after the name of the regulation.

DEFENSE FAR SUPP CONTRACT CLAUSES IN FULL TEXT

252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT

REPORTING (DEC 2019)

(a) Definitions. As used in this clause—

“Adequate security” means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.

“Compromise” means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.

“Contractor attributional/proprietary information” means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.

“Contractor information system” means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.

“Controlled technical information” means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.

“Covered contractor information system” means an information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.

“Covered defense information” means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is—

(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or

(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.

“Cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.

“Forensic analysis” means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.

“Information system” means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

“Malicious software” means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.

“Media” means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.

‘‘Operationally critical support’’ means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.

“Rapidly report” means within 72 hours of discovery of any cyber incident.

“Technical information” means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.

(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:

(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:

(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract.

(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.

(2) For covered contractor information systems that are not part of an IT service of system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:

(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” (available via the Internet at http://dx.doi.org/10.6028/NIST.SP.800-171) in effect at the time the solicitation is issued or as authorized by the Contracting Officer.

(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.

(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.

(C) If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.

(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline https://www.fedramp.gov/resources/documents/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.

(c) Cyber incident reporting requirement.

(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contrac, the Contractor shall—

(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor’s ability to provide operationally critical support; and

(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.

(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.

(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.

(d) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime

Center (DC3) in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.

(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.

(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.

(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.

(i) Use and release of contractor attributional/proprietary information not created by or for DoD.

Information that is obtained from the contractor (or derived from information obtained from…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .