Attachment 3 - Statement of Work Revised.pdf

PDF 814 KB Posted

Attached to
Wide-Format Printing Equipment IDIQ Federal contract opportunity
Solicitation number
SP7000-21-Q-1052
Issued by
Defense Logistics Agency

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DLA Information Operations Wide-Format Printer Statement of Work (SOW)

Attachment 3 - SP7000-21-Q-1052

As of September 29, 2021 Page 1

I. OVERVIEW

A. The Defense Logistics Agency (DLA) seeks to enter into 60-month multiple award Indefinite Delivery Indefinite Quantity (IDIQ) contracts with an estimated total maximum program ceiling of up to $2.8 Million for the purchase of Wide Format printing equipment (hereafter collectively referred to as “devices”) within the Contiguous United States (CONUS) as well as non-foreign Outside Contiguous United Stated (OCONUS) locations Alaska, Hawaii, and Puerto Rico, along with services associated with the purchased devices. Specific details are found in Sections II and III.

B. The services associated with the devices sought are delivery and installation (Section IV), end-user training (Section V), extended manufacturer warranties (Section VI), model substitutions (Section VII), reports (Section VIII), network functionality (Section X), and network security (Section XI).

II. DEVICES AND CONFIGURATIONS

A. All devices shall meet the following requirements:

1. Devices shall be Trade Agreement Act (TAA) compliant and manufactured new (not rebuilt or remanufactured). New means composed of previously unused components, whether manufactured from virgin material, recovered material in the form of raw material, or materials and by-products generated from, and reused within, an original manufacturing process; provided that the supplies meet contract requirements, including but not limited to, performance, reliability, and life expectancy.

2. 24” devices shall be capable of handling 11” or less to 24” rolls; 36” devices shall be capable of handling 11” or less to 36” rolls; 44” devices shall be capable of handling 11” or less to 44” rolls.

3. Capable of print resolution of 2400 x 1200 dots per inch (DPI).

4. Image preview on controller or built-in display unit.

5. Ink colors, shall, at a minimum, consist of Cyan, Magenta, Yellow, and Black (CMYK).

6. Configured to be floor-standing, to include printer stand.

7. Printing paths: printer driver, USB from client desktop.

8. Supports the following printer languages: Standard Page Description Language (PDL), Adobe PDF, TIFF, JPEG, CALS G4.

9. Minimum 1 GB of RAM; Hard Disk (if included): Minimum 250GB, AES-256 encrypted, level 2 certified Federal Information Processing Standard (FIPS) 140-2 or 140-3. Device equipped with hard drives (platter or solid state) shall have an encryption or overwrite Security Kit, and removable hard drives shall have a locking mechanism.

10. Support current desktop and server operating systems.

11. Driver software shall be compatible with Windows 10 or current Department of Defense (DOD) operating systems. (Both PC and Mac compatible).

12. Connectivity: Interfaces (standard) Gigabit Ethernet (1000 Base-T) and Hi-Speed USB 2.0 or higher certified.

13. Delivered with up-to-date software/firmware and drivers, with 32-bit and 64-bit architecture driver support, to include, but not limited to: print drivers and web interface drivers.

14. Provide all subsequent updates along with installation instructions to DLA.

15. Operate using 100-240V, 50/60Hz.

As of September 29, 2021 Page 2

16. All Universal Serial Bus (USB) ports/memory card slots on the devices shall be disabled when delivered except: the printer port used to connect the device to a single computer; Common Access Card (CAC) readers; and any USB ports needed for servicing/maintaining equipment. Additionally, unused ports, protocols and services on each device shall be able to be enabled/disabled by the local IT administrator.

17. Include a printed operator’s manual, in English, for each device.

18. Default to:

a. Automatically go into sleep mode after 20 minutes of inactivity

b. Automatically go into hibernation after an hour of inactivity.

c. Display all information in English.

B. Devices with scanning capability shall meet the following requirements:

1. CAC-enabled and shall have secure scanning functionality that complies with FIPS 140-2 or 140-3 encryption.

2. Ability to retrieve scanned image files with integrated Windows compatible client software to network share directory.

3. Secure scanning functionality with routing and full integration to standard network infrastructure destinations, which include: Scan-to-Email, Scan-to-Folder, Scan-to-OneDrive, Scan-to-Server and Scan-to-PC. Scanned documents shall be made available as a TIFF, JPEG and as a PDF file format.

The default scan resolution shall be 300 x 300 DPI. The default scan output file type shall be PDF.

Devices shall have Optical Character Recognition (OCR) in order to process and produce text-searchable documents to the scan destination. Note: Full integration does not mean scanning to proprietary back-end content, document or records management systems to support customized indexing or metadata requirements.

4. Shall be SIPR-capable devices, to include required SIPR tokens.

C. Contractors shall provide original equipment manufacturer (OEM) specification sheets, to include optional scanning equipment with proposal to the Contracting Officer.

III. VOLUME BAND SPECIFICATIONS:

A. In addition to the features/capabilities/configurations set forth in Section II (outlined above), the Contractor shall provide all devices in accordance with the chart below:

Volume Band NIPR/SIPR Configuration

VB1-24 NIPR 24” device without hard drive; single feed roll VB1-24PS NIPR/SIPR 24” device with removable hard drive and Postscript capability; single feed roll VB2-36 NIPR 36” device without hard drive; single feed roll VB2-36PS NIPR/SIPR 36” device with removable hard drive and Postscript capability; dual feed roll

VB2-36MFD NIPR/SIPR 36” device with removable hard drive and Postscript capability; dual feed roll; 36” scanner (600 dpi) with CAC reader

VB3-44PS NIPR/SIPR 44” device with removable hard drive and Postscript capability; dual feed roll; no vertical trimmer

VB3-44PSVT NIPR/SIPR 44” device with removable hard drive and Postscript capability; dual feed roll; vertical trimmer

As of September 29, 2021 Page 3

VB3-44MFD NIPR/SIPR 44” device with removable hard drive and Postscript capability; dual feed roll; no vertical trimmer; 44” scanner (1200 dpi) with CAC reader

VB3-44VTMFD NIPR/SIPR 44” device with removable hard drive and Postscript capability; dual feed roll; vertical trimmer; 44” scanner (1200 dpi) with CAC reader

SCAN-44 NIPR/SIPR

44” scanner (1200 dpi) with CAC reader; 4 GB RAM; 500 GB hard drive; color scan speed: up to 6 in/sec; grayscale: up to 13 in/sec; compatible with VB1-24PS/VB2-36PS/VB3-

44PS/VB3-44PSVT

B. Ink cartridges shall be available to order as additional CLINs.

IV. DELIVERY AND INSTALLATION

A. Delivery and Installation of Ordered Devices:

1. Delivery and Installation of ordered devices for CONUS shall be completed within thirty (30) days after receipt of order (ARO). Forty-five (45) days ARO shall be permitted for deliveries to non-foreign OCONUS locations: Alaska, Hawaii, and Puerto Rico.

2. Installation shall be defined as device is fully operational as ordered, to include network connectivity and scanning, if required and configured with scanning capability. The Contractor shall provide onsite technical and system analyst support and appropriate digital cards/products to successfully connect devices to DLA customers’ networks.

3. Upon completion of device delivery, the Contractor shall obtain customer signature and date on each bill of lading (BOL) or packing slip and provide this proof of delivery to the designated DLA Point of Contact (DLA POC) within ten (10) business days after delivery. The Contractor shall also provide the Installation Report (Appendix #1) or a modified delivery schedule with serial numbers added to the designated DLA POC within ten (10) business days after delivery and installation have been completed.

4. If a device cannot be delivered and installed within the delivery time that is given, the Contractor shall notify the issuing Contracting Officer as soon as the delay is realized and of the updated expected delivery date for the ordered device(s). Upon notification, the Ordering Agency may choose to cancel the order or request due consideration for the delay.

5. Upon installation, the Contractor shall affix on each device a sticker with the following information:

manufacturer’s name, model number, device serial number and toll-free telephone number to request repairs.

6. The Contractor shall provide English-speaking personnel at the toll-free number(s) provided.

V. TRAINING

A. The Contractor shall provide on-site training at time of delivery, in English, as specified in the order, to end-users.

B. Training shall include the following:

1. How to operate the basic functions of the device.

2. Diagnosis and resolution of basic device malfunctions, including paper jams.

3. Procedures for loading/unloading paper and replacing ink cartridges, print heads, and cutter blades.

C. The Contractor shall submit a Summary of Training Report (Microsoft Excel format), listing device serial number, personnel trained, and date training was completed, to the designated DLA POC within five (5) business days of training completion.

As of September 29, 2021 Page 4

D. In addition to on-site training, the Contractor shall provide a quick reference desk guide (single sheet, 8.5” x 11” paper size, laminated, full color and able to be easily stowed away with the device). The contractor shall also provide a CD-ROM/DVD and/or web-based training (URL printed on a sticker to be placed on the front of the device) to serve as follow-up training.

VI. EXTENDED MANUFACTURER WARRANTIES

A. An extended Manufacturer Warranty extends the time period of the standard manufacturer warranty to replace or repair defective devices.

B. The contractor MUST register each device with the Manufacturer to allow for DLA to, if it chooses, purchase an extended warranty.

C. If it chooses to repair, the contractor must ensure all service technicians are eligible for access to Department of Defense facilities in accordance with the authority in DoD manual 5200.08 Volume 3, which establishes DoD access control policy and the minimum DoD security standards for controlling entry to DoD installations and stand-alone facilities. Contractors must also check and follow installation access policies specific to each DoD installation. Technicians must be eligible for access at time of the award. In addition, in the case of devices cleared for CLASSIFIED material, the contractor’s repair technicians shall ensure they do not access the device without a Government employee escort present and observing during the support/repair services. To ensure an escort is present the contractor will call ahead to the site POC to schedule a date and time of arrival.

D. The contractor must offer for DLA’s purchase Extended Manufacturer Warranties in a minimum of a three-year package for each device.

VII. MODEL SUBSTITUTIONS

A. In the event the Contractor is no longer able to provide the products proposed, the Contractor may, only after written approval by the Contracting Officer, provide replacement devices which shall meet or exceed the requirements as listed in this SOW, at the contract price.

1. Prior to delivery, if replacement devices have not been previously tested by DLA, they shall be tested as outlined in Section XII.

VIII. REPORTS

A. The Contractor shall provide the following reports:

1. Installation Report (Appendix #1), as referenced in Section IV.A.3, which shall contain an accurate listing of all devices under contract (model, serial number, location). This report shall be submitted via Wide Area Work Flow (WAWF) to the DLA POC with the invoice.

2. Summary of Training Report, as referenced in Section V.C.

IX. INVOICING

A. All invoices shall be submitted with the Installation Report via Wide Area Work Flow (WAWF) and shall be submitted in United States Dollars. The following website provides additional information regarding WAWF including information for “vendors getting started” with the system:

https://wawf.eb.mil/xhtml/unauth/help/help.xhtml.

X. NETWORK FUNCTIONALITY

https://wawf.eb.mil/xhtml/unauth/help/help.xhtml

As of September 29, 2021 Page 5

A. DOD policy prohibits the publication of network configuration information; therefore, DOD installations shall not fill out pre-installation site surveys. The required information shall be provided at time of installation.

B. The Contractor shall provide devices that shall operate on and coexist on a network supporting all of the following:

1. Internet Protocol Version 4 (IPv4),

2. Internet Protocol Version 6 (IPv6),

3. A hybrid of IPv4 and IPv6.

C. Support shall be provided for network configurations based on agency hardware/software.

XI. NETWORK SECURITY

A. The Contractor shall provide devices that can be configured to comply with the current Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) titled Multifunction Device and Network Printer STIG (latest version and release), available at:

https://cyber.mil/. Any known deficiencies shall be identified to DLA prior to the Certification and Accreditation testing phase for evaluation of acceptance.

B. All hard drives that are put into service within Federal agencies shall remain in their custody. In the instance where a device is removed by the Contractor, all hard drives, whether internal, external, or otherwise, shall remain in possession of the Government and not be removed with the device.

C. Contractors shall monitor industry standard vulnerability sites (e.g. http://nvd.nist.gov/, https://www.us-cert.gov/ncas/alerts, http://oval.mitre.org/) and take appropriate actions if their equipment is subject to a known vulnerability. When vulnerabilities are identified by the Contractor, DLA or its customers, the Contractor shall provide remediation for distribution to all installed equipment in accordance with USCYBERCOM TASKORD regulations unless a different time period is directed by USCYBERCOM via DLA. The TASKORD is For Official Use Only. The following is authorized to be quoted from the TASKORD for reference:

1. Assured Compliance Assessment Solution (ACAS) assigns severity scores of critical, high, medium and low to plug-in findings.

a. Critical findings reflect discovery of a common vulnerability and exposure (CVE) that poses significant risk to the confidentiality, integrity, and availability of DODIN Networks. Actions to mitigate or remediate critical vulnerabilities shall be initiated upon discover with the goal of mitigation/remediation within seven (7) calendar days.

b. Findings with a severity score of high shall be addressed in the same manner as vulnerabilities addressed via Information Assurance Vulnerability Alert (IAVA) directives and mitigated or remediated within twenty-one (21) calendar days of discovery.

c. Findings with severity scores of medium and low shall be addressed in accordance with local Approving Official (AO), Information System Security Manager (ISSM), or Information System Security Officer (ISSO) guidance until further notice.

d. In all instances, DOD components shall consider exposure to threat, mission impact, sensitivity of data, and current mitigating security controls when prioritizing implementation of fix actions.

D. In the event remediation cannot be achieved within the mandated timeline, the Contractor shall provide a Plan of Action and Milestones and receive approval thereof by the Customer’s Agency Authorizing Official or designee for risk acceptance.

https://cyber.mil/ http://nvd.nist.gov/ https://www.us-cert.gov/ncas/alerts http://oval.mitre.org/

As of September 29, 2021 Page 6

E. For all devices configured with scanning capability:

1. The Contractor shall supply a SMARTCARD Public Key Infrastructure (PKI) Solution which is compliant with DODI 8520.03 and NIST FIPS 201 (PIV) standards. The Contractor shall provide card readers that shall read and process all approved CAC and PIV cards. The Contractor shall maintain compliance with DOD-wide SMARTCARD and DOD PKI standards, and support all approved physical cards during the coverage period.

2. The contractor shall provide a SMARTCARD PKI Solution with SIPRNet token capability, which is compliant with DOD requirements for PK-enabling and interoperability as set forth in DODI

8520.02. The Contractor shall provide card readers that shall read and process all approved SIPRNet token cards. The Contractor shall provide device support systems that incorporate the use of PKI for encryption of information in transit or at rest. The Contractor shall provide devices that are compatible with 3.3 volt SafeNet SC650 token and that are compatible with the 90Meter Middleware solution for CAC, known as CAC Smart Card Manager-90. The Contractor shall maintain compliance with DOD wide SIPR and DOD PKI standards, and support all approved physical cards and firmware during the coverage period. For current DODI instructions go to:

http://www.dtic.mil/whs/directives/corres/ins1.html.

3. For all CLASSIFIED designated devices, the Contractor shall ensure that CAC/SIPR token authentication is available for scanning, printing, and copying and shall be:

a. Capable of digitally signing emails using the senders DOD PKI Certificate(s).

b. Capable of encrypting emails using the receivers DOD PKI Certificate(s).

c. Capable of scan to file on networked devices.

d. In compliance with Homeland Security Presidential Directive-12 (HSOP-12).

e. The Contractor shall produce certificates of compliance, if requested.

XII. TESTING

A. Unless previously tested and approved by DLA, all devices proposed in response to the contract shall be tested for compliance with Network Security as defined in Section XI after award.

B. The estimated time for testing is twenty (20) business days. Testing and approval shall be performed by the DLA Information Operations EMS Division in conjunction with the Contractor’s assistance. The Contractor shall provide onsite engineering assistance and other support necessary to configure, setup, and test the equipment as needed.

1. DLA has agreements with our DOD customers to test devices to meet DOD RMF and STIG Compliance. If all devices pass the preliminary testing process, DLA shall submit a compliance memorandum to the Contractor informing them that the devices have passed the preliminary testing process. In some cases, prior to being added to the DLA customer’s network, additional certification procedures and testing shall be required prior to risk acceptance. If required by DLA, the Contractor shall deliver test devices to the DLA customer prior to proceeding with installation.

DLA shall exercise due diligence to assist with technical mitigation and resolve any questions and/or concerns raised by that agency during the testing review process.

2. Upon request, the Contractor shall provide a representative device from each common criteria certified family and engineering support to the NAVWAR test facility in San Diego, CA for all devices that are to be placed on the Navy & Marine Corps Intranet (NMCI). All devices will be tested to operate on the NMCI for the "printer, scanner and fax" functions. The NMCI Testing Checklist (Appendix #2) outlines what functionalities will be tested to operate on the NMCI network prior to placement of devices on the NMCI Certified Device List (CDL). The Device Manufacturer http://www.dtic.mil/whs/directives/corres/ins1.html

As of September 29, 2021 Page 7

Questionnaire (Appendix #3) shall be provided to the NAVWAR test facility prior to delivery. The NMCI certification process can take from 4 to 6 months.

3. If the devices do not pass any of the testing procedures for any reason, DLA shall not proceed with installation of said devices at the customer locations and DLA shall terminate the contract.

C. A device shall not be tested if it cannot be assigned to one of the Volume Bands as outlined in Section

III.

D. The devices shall be delivered with all required accessories, software, firmware, etc.

E. Approved devices previously submitted to DLA for testing are not required to be re-tested.

F. The Contractor shall deliver the devices to the DLA Information Operations J67E MFD Configuration Manager, located at 430 Mifflin Avenue, Building 430, New Cumberland, PA 17070, for testing, at no cost to the government. Delivery coordination shall take place within five (5) business days of contract award. The MFD Configuration Manager can be reached at (717) 770-4060.

G. The Contractor shall resolve non-compliance issues as quickly as possible. If the issues cannot be resolved within fourteen (14) calendar days, the test shall be suspended. After the non-compliance issues are resolved by the Contractor, the suspended session shall be scheduled when lab time is next available. If requested by DLA, the Contractor shall remove their devices from the lab to avoid delaying the next scheduled test.

H. For all devices tested and placed on the DLA contract, the Contractor shall collaborate with the DLA POC to develop the testing results package. The Contractor shall develop the device Implementation Guide. The Implementation Guide shall provide step-by-step instructions and screenshots to configure the devices in accordance with the testing results. Government acceptance of the Implementation Guide is at the discretion of the DLA EMS Division.

I. The security requirements set forth in this SOW are minimum device specifications and have been identified as the basic requirements common across Government agencies. These are the minimum-security requirements applicable to all devices awarded under this contract. Each ordering activity may have its own hardware/software acceptance processes. All devices shall be subject to ordering activity hardware/software evaluation processes at the order level. If the device fails a security evaluation, the Contractor may select a different technology or mitigate the failed controls to fulfill this requirement.

The Contractor shall be available to meet with the information technology (IT) and security personnel at a mutually convenient time during the evaluation process and shall identify a mutually acceptable solution. The Contractor shall provide the necessary equipment or expertise to complete security testing and integration into the existing environment. At the order level, the customer agency may require the Contractor to ship devices to a specific location for testing at time of order award.

J. If, during the life of the contract, a requirement in Section X and XI is changed, updated, or revised, the Contractor shall comply with the most current version of the requirement.

K. The Contractor shall remove all hardware from the DLA test lab within fourteen (14) calendar days upon notification of test completion.

XIII. SUPPLY CHAIN RISK MANAGEMENT

A. As part of its proposal, the Contractor shall provide written documentation demonstrating how the integrity and security of all equipment, components thereof, repair parts and consumables it will provide and/or use in performing this contract will meet the standards set forth in National Institute of Standards and Technology (NIST) Special Publication 800-161. This documentation shall clearly demonstrate how the Contractor is taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services DLA receives through this contract. Additionally, this documentation shall provide specific details of what -

As of September 29, 2021 Page 8

1. Policies the Contractor has in place to prevent both (a) the use of counterfeit or altered equipment, components thereof, consumables and parts and (b) their introduction into the Contractor’s supply chain;

2. Security procedures the Contractor uses to track the chain of custody of equipment, components thereof, consumables and parts, to include while this material is in storage and in transit; and

3. Steps the Contractor takes to ensure the integrity and authenticity of equipment, components thereof, repair parts and consumables to prevent tampering so they will perform according to specifications without additional unwanted functionality.

B. The Contractor shall continuously meet the standards of NIST Special Publication 800-161 while taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services provided through this contract.

Upon request, the Contractor shall provide written documentation meeting all requirements set forth in part A, above.

XIV. INSTALLATION SECURITY REQUIREMENTS

A. The Contractor shall comply with all rules and regulations to obtain Government installation access in order to meet all response times identified within the SOW.

B. The Contractor shall comply with Government base and building access requirements as set forth in the base/ command regulations.

C. The Contractor shall be responsible for any and all fees associated with the application process and/or enrollment to access any installation or facility.

D. For devices cleared for CLASSIFIED material, the Contractor’s repair technicians shall have a DOD security clearance equal to or higher than the classification of the device and shall provide verification when requested.

XV. GENERAL CONDITIONS

A. The Contractor shall assign a single point of contact (POC) to coordinate with the Contracting Officer in all aspects of this contract within 3 business days of receipt of the order. The Contractor shall provide its assigned POC’s name, title, business address, phone number and email address to the Contracting Officer.

B. The Contractor shall comply with the Health Insurance Portability and Accountability Act (HIPAA) when installing devices at Government medical sites.

C. The Contractor shall comply with the Section 508 accessibility requirements. By submission of its offer, the Contractor affirms that its Electronic Information Technology (EIT) supplies and services are accessible as outlined in the law, the standard, and FAR Subpart 39.2. The Contractor shall submit their completed Voluntary Product Accessible Template (VPAT®) or the provided VPAT document (Appendix #4) with their proposal.

XVI. APPENDICES

A. Appendix #1: Installation Report

B. Appendix #2: NMCI Testing Checklist

C. Appendix #3: Device Manufacturer Questionnaire

D. Appendix #4: VPAT® Template

As of September 29, 2021 Page 9

Appendix #1 INSTALLATION REPORT

Activity Name Customer Address

Customer POC Phone # Customer POC Email

Contract #

CLIN#

Manufacturer

Model #

Serial #

Install Date

Building Number

Floor Number/ Room Number

Continue on the back, if needed. Note: A Delivery Schedule or Spreadsheet can be used as an attachment to this install report.

Customer Accepting Receipt of Device (Print): Customer Signature

As of September 29, 2021 Page 10

CLIN#

Manufacturer

Model #

Serial #

Install Date

Building Number

Floor Number/ Room Number

(Page 2 – Appendix #1)

As of September 29, 2021 Page 11

NO

FUNCTION YES

Print Function Print monochrome, default to grayscale and draft mode Print color, default to grayscale and draft mode Print duplex & simplex with duplex default Print portrait & landscape Support PCL5 or PCL6, and Post Script Support multiple paper sizes: letter, legal, A4 Support image enlargement, reduction, and page fit Multi-position stapler finisher

Scan function Scan to email w/CAC authentication - sign and encrypt messages DIRECT/NATIVE Scan to Command Folder or H: drive using CAC authenticated credentials Scan via Autostore Scan output in PDF and TIFF format Scan color input and output Scan to Network folder without CAC

Fax function Modem-to-modem analog fax using industry standard speeds and error correction Disable network fax option if available

Copy function Copy all possible simplex/duplex options Support multiple paper sizes: Letter, Legal, A4 Image enlargement/reduction Automatic document feeder and flatbed copy Color copy input and output

Miscellaneous options NIAP compliant MFD and Network Print STIG compliant Secure print (CAC enabled Print) Secure print (User PIN/PW) SMARTCARD PKI solution compliant with DOD CAC and NIST FIPS 201 (PIV) standards Fax and scan under CAC control, print and copy set to walk up HDD overwrite or encryption Energy Settings - Default Sleep Mode SIPR/Classified NIPR/Unclassified

Primary test model Member of same model family

Appendix #2 – NMCI TESTING CHECKLIST

As of September 29, 2021 Page 12

Appendix #3 ___________________________ PROPRIETARY Device Manufacturer Questionnaire

SLIN x049 Hardware Certification Leidos – NMCI Enterprise Engineering

The purpose of this document is to gather the required information from hardware manufacturers for the Leidos Engineering team prior to devices being certified and available for use within NMCI.

1. Device to be certified:

Manufacturer/Make:

Device Model:

Driver/Software Version:

Firmware Version:

2. Is the hardware TAA Compliant?

Yes No

3. Vendor Technical Point of Contact (Person that can verify instructions for installing, testing, ports, and configuration of the software):

Name:

Phone:

Email:

Time Zone:

4. Has the device previously been certified for use within NMCI?

Yes No

If yes, using what version of firmware and drivers?

Firmware Version:

Driver/Software Version:

5. Is this a network device?

Yes No

If yes, is it compatible with Windows Server 2008?

Yes No

6. If this is a multi-function device, is it currently compatible with the certified NMCI Autostore Express Scan to File Solution Version 5.0?

Yes No Does it utilize user authentication or FTP to communicate to Autostore Express?

User Authentication FTP

7. If this is a multi-function device what version of Firmware and Drivers does this device require for it to function with NMCI Autostore Express Scan to File:

Firmware:

Driver:

Other added hardware, chipsets, internal cards:

Final, Version 2.0, September 21, 2021 1 NMCI/SMIT

Use or disclosure of data in this document is subject to the restrictions on page.

As of September 29, 2021 Page 13

8. What ports are required for this device to communicate? USB ports All open ports must be documented for operation of device.

Port Number: Port Number:

Port Number: Port Number:

Port Number: Port Number:

Additional TCP/IP or UDP ports that are open on device and are not required for printing or scanning.

Port Number: Port Number:

Port Number: Port Number:

Port Number: Port Number:

Please provide written technical instructions how to configure and close unused network ports on this device. No ports used

9. If device requires an administrative account for access to the set up please provide Account “name” and Account “password”.

Account Name:

Account Password:

10. If device requires an administrative account for access to an embedded web service please provide Account “name” and Account “password”.

Account Name:

Account Password:

11. Instructions to reset device back to factory default settings:

Instructions:

GOVERNMENT PURPOSE RIGHTS

Contract No. N00039-20-D-0054

Contractor Name: Leidos Contractor Address: 1750 Presidents Street

Reston, VA, 20190 The Government's rights to use, modify, reproduce, release, perform, display, or disclose this technical data/computer software are restricted by clause H-8 contained in the above identified contract. Any reproduction of this technical data/computer software or portions thereof marked with this legend must also reproduce the markings.

Final, Version 2.0, September 21, 2021 13 NMCI/SMIT

Use or disclosure of data in this document is subject to the restrictions on page 1

As of September 29, 2021 Page 14

Appendix #4

[Company] Accessibility Conformance Report

(Based on VPAT® Version 2.4)

Name of Product/Version:

Report Date:

Product Description:

Contact Information:

Notes:

Evaluation Methods Used:

Applicable Standards/Guidelines

This report covers the degree of conformance for the following accessibility standard/guidelines:

Standard/Guideline Included In Report Web Content Accessibility Guidelines 2.0 Level A (Yes / No )

Level AA (Yes / No ) Level AAA (Yes / No )

Web Content Accessibility Guidelines 2.1 Level A (Yes / No ) Level AA (Yes / No )

Level AAA (Yes / No ) Revised Section 508 standards published January 18, 2017 and corrected January 22, 2018

(Yes / No )

EN 301 549 Accessibility requirements suitable for public procurement of ICT products and services in Europe, - V3.1.1 (2019-11)

(Yes / No )

Terms

The terms used in the Conformance Level information are defined as follows:

• Supports: The functionality of the product has at least one method that meets the criterion without known defects or meets with equivalent facilitation.

• Partially Supports: Some functionality of the product does not meet the criterion.

• Does Not Support: The majority of product functionality does not meet the criterion.

• Not Applicable: The criterion is not relevant to the product.

• Not Evaluated: The product has not been evaluated against the criterion. This can be used only in WCAG

2.0 Level AAA.

As of September 29, 2021 Page 15

Revised Section 508 Report Notes:

Chapter 3: Functional Performance Criteria (FPC) Notes:

Criteria Conformance Level Remarks and Explanations

302.1 Without Vision.

Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that does not require user vision.

302.2 With Limited Vision.

Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited vision.

302.3 Without Perception of Color. Where a visual mode of operation is provided, ICT shall provide at least one visual mode of operation that does not require user perception of color.

302.4 Without Hearing.

Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that does not require user hearing.

302.5 With Limited Hearing.

Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited hearing.

302.6 Without Speech.

Where speech is used for input, control, or operation, ICT shall provide at least one mode of operation that does not require user speech.

302.7 With Limited Manipulation. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that does not require fine motor control or simultaneous manual operations.

302.8 With Limited Reach and Strength.

Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.

302.8 With Limited Reach and Strength.

Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.

302.9 With Limited Language, Cognitive, and Learning Abilities. ICT shall provide features making its use by individuals with limited cognitive, language, and learning abilities simpler and easier.

Chapter 4: Hardware

Criteria Conformance Level Remarks and Explanations

402.1 General. (Closed Functionality )

ICT with closed functionality shall be operable without requiring the user to attach or install assistive technology other than personal headsets or other audio couplers, and shall conform to 402.

Heading cell – no response required Heading cell – no response required

402.2.1 Information Displayed On-Screen.

Speech output shall be provided for all information displayed on-screen.

402.2.2 Transactional Outputs.

Where transactional outputs are provided, the speech output shall audibly provide all information necessary to verify a transaction.

402.2.3 Speech Delivery Type and Coordination.

Speech output shall be delivered through a mechanism that is readily available to all users, including, but not limited to, an industry standard

As of September 29, 2021 Page 16

Criteria Conformance Level Remarks and Explanations connector or a telephone handset. Speech shall be recorded or digitized human, or synthesized. Speech output shall be coordinated with information displayed on the screen.

402.2.4 User Control.

Speech output for any single function shall be automatically interrupted when a transaction is selected. Speech output shall be capable of being repeated and paused.

402.2.5 Braille Instructions.

Where speech output is required by 402.2, braille instructions for initiating the speech mode of operation shall be provided. Braille shall be contracted and shall conform to 36 CFR part 1191, Appendix D, Section 703.3.1.

402.3.1 Private Listening.

Where ICT provides private listening, it shall provide a mode of operation for controlling the volume. Where ICT delivers output by an audio transducer typically held up to the ear, a means for effective magnetic wireless coupling to hearing technologies shall be provided.

402.3.2 Non-private Listening.

Where ICT provides non-private listening, incremental volume control shall be provided with output amplification up to a level of at least 65 dB. A function shall be provided to automatically reset the volume to the default level after every use.

402.4 Characters on Display Screens.

At least one mode of characters displayed on the screen shall be in a sans serif font. Where ICT does not provide a screen enlargement feature, characters shall be 3/16 inch (4.8 mm) high minimum based on the uppercase letter “I”. Characters shall contrast with their background with either light characters on a dark background or dark characters on a light background.

402.5 Characters on Variable Message Signs.

Characters on variable message signs shall conform to section 703.7 Variable Message Signs of ICC A117.1:2009.

403.1 Biometrics

Where provided, biometrics shall not be the only means for user identification or control.

404.1 Preservation of Information Provided for Accessibility

ICT that transmits or converts information or communication shall not remove non-proprietary information provided for accessibility or shall restore it upon delivery.

405.1 Privacy.

The same degree of privacy of input and output shall be provided to all individuals. When speech output required by 402.2 is enabled, the screen shall not blank automatically.

406.1 Standard Connections

Where data connections used for input and output are provided, at least one of each type of connection shall conform to industry standard non-proprietary formats.

407.2 Contrast.

Where provided, keys and controls shall contrast visually from background surfaces. Characters and symbols shall contrast visually from background surfaces with either light characters or symbols on a dark background or dark characters or symbols on a light background.

407.3.1 Tactilely Discernible.

Input controls shall be operable by touch and tactilely discernible without activation.

407.3.2 Alphabetic Keys.

Where provided, individual alphabetic keys shall be arranged in a QWERTY-based keyboard layout and the ‘‘F’’ and ‘‘J’’ keys shall be tactilely distinct from the other keys.

407.3.3 Numeric Keys.

Where provided, numeric keys shall be arranged in a 12-key ascending or descending keypad layout. The number five key shall be tactilely distinct from the other keys. Where the ICT provides an alphabetic overlay on numeric keys, the relationships between letters and digits shall conform to ITU?T Recommendation E.161

As of September 29, 2021 Page 17

407.4 Key Repeat.

Where a keyboard with key repeat is provided, the delay before the key repeat feature is activated shall be fixed at, or adjustable to, 2 seconds minimum.

407.5 Timed Response.

Where a timed response is required, the user shall be alerted visually, as well as by touch or sound, and shall be given the opportunity to indicate that more time is needed.

407.6 Operation. (General)

At least one mode of operation shall be operable with one hand and shall not require tight grasping, pinching, or twisting of the wrist. The force required to activate operable parts shall be 5 pounds (22.2 N) maximum.

407.7 Tickets, Fare Cards, and Keycards.

Where tickets, fare cards, or keycards are provided, they shall have an orientation that is tactilely discernible if orientation is important to further use of the ticket, fare card, or keycard.

407.8.1 Vertical Reference Plane.

Operable parts shall be positioned for a side reach or a forward reach determined with respect to a vertical reference plane. The vertical reference plane shall be located in conformance to 407.8.2 or 407.8.3.

407.8.1.1 Vertical Plane for Side Reach. Where a side reach is provided, the vertical reference plane shall be 48 inches (1220 mm) long minimum.

407.8.1.2 Vertical Plane for Forward Reach. Where a forward reach is provided, the vertical reference plane shall be 30 inches (760 mm) long minimum.

407.8.2 Side Reach.

Operable parts of ICT providing a side reach shall conform to 407.8.2.1 or 407.8.2.2. The vertical reference plane shall be centered on the operable part and placed at the leading edge of the maximum protrusion of the ICT within the length of the vertical reference plane. Where a side reach requires a reach over a portion of the ICT, the height of that portion of the ICT shall be 34 inches (865 mm) maximum.

407.8.2.1 Unobstructed Side Reach.

Where the operable part is located 10 inches (255 mm) or less beyond the vertical reference plane, the operable part shall be 48 inches (1220

mm) high maximum and 15 inches (380 mm) high minimum above the floor.

407.8.2.2 Obstructed Side Reach.

Where the operable part is located more than 10 inches (255 mm), but not more than 24 inches (610 mm), beyond the vertical reference plane, the height of the operable part shall be 46 inches (1170 mm) high maximum and 15 inches (380 mm) high minimum above the floor. The operable part shall not be located more than 24 inches (610 mm) beyond the vertical reference plane.

407.8.3 Forward Reach.

Operable parts of ICT providing a forward reach shall conform to

407.8.3.1 or 407.8.3.2. The vertical reference plane shall be centered, and intersect with, the operable part. Where a forward reach allows a reach over a portion of the ICT, the height of that portion of the ICT shall be 34 inches (865 mm) maximum.

407.8.3.1 Unobstructed forward reach.

Where the operable part is located at the leading edge of the maximum protrusion within the length of the vertical reference plane of the ICT, the operable part shall be 48 inches (1220 mm) high maximum and 15 inches (380 mm) high minimum above the floor.

407.8.3.2 Obstructed Forward Reach.

Where the operable part is located beyond the leading edge of the maximum protrusion within the length of the vertical reference plane, the operable part shall conform to 407.12.3.2. The maximum allowable forward reach to an operable part shall be 25 inches (635 mm).

407.8.3.2.1 Height.

Where the operable part is located less than 20 inches (510 mm) beyond the vertical reference plane, the operable part shall be 48 inches (1220 mm) high maximum. Where the operable part is located 20 inches (510 mm) to 25 inches (635 mm) beyond the vertical

As of September 29, 2021 Page 18 reference plane, the operable part shall be 44 inches (1120 mm) high maximum.

407.8.3.2.2 Knee and Toe Space.

Knee and toe space under ICT shall be 27 inches (685 mm) high minimum, 25 inches (635 mm) deep maximum, and 30 inches (760

mm) wide minimum and shall be clear of obstructions.

408.2 Display Screens (General)

Where stationary ICT provides one or more display screens, at least one of each type of display screen shall be visible from a point located 40 inches (1015 mm) above the floor space where the display screen is viewed.

408.3 General. (Flashing)

Where ICT emits lights in flashes, there shall be no more than three flashes in any one-second period.

409.1 Status Indicators.

Status indicators, including all locking or toggle controls or keys (e.g., Caps Lock and Num Lock keys), shall be discernible visually and by touch or sound.

410.1 Color Coding.

Color coding shall not be used as the only means of conveying information, indicating an action, prompting a response, or distinguishing a visual element.

411.1 Audible Signals.

Where provided, audible signals or cues shall not be used as the only means of conveying information, indicating an action, or prompting a response.

412.2.1 Volume Gain for Wireline Telephones.

Volume gain conforming to 47 CFR 68.317 shall be provided on analog and digital wireline telephones.

412.2.2 Volume Gain for Non-Wireline ICT.

A method for increasing volume shall be provided for non-wireline ICT.

412.3.1 Wireless Handsets.

ICT in the form of wireless handsets shall conform to ANSI/IEEE C63.19-2011 (incorporated by reference, see 702.5.1).

412.3.2 Wireline Handsets.

ICT in the form of wireline handsets, including cordless handsets, shall conform to TIA-1083-B (incorporated by reference, see 702.9.1).

412.4 Digital Encoding of Speech.

ICT in IP-based networks shall transmit and receive speech that is digitally encoded in the manner specified by ITU-T Recommendation G.722.2 (incorporated by reference, see 702.7.2) or IETF RFC 6716 (incorporated by reference, see 702.8.1).

412.5 Real-Time Text Functionality (HCO and VCO Support)

Reserved. (Pending the outcome of rulemaking of the Federal Communications Commission(FCC) as discussed in Section III.D (Major Issues-Real-Time Text))

412.5 Real-Time Text Functionality (Interoperability) Reserved.

(Pending the outcome of rulemaking of the Federal

412.5 Real-Time Text Functionality (Compatibility with Interactive Voice Response).

Reserved. (Pending the outcome of rulemaking of the Federal

412.6 Caller ID.

Where provided, caller identification and similar telecommunications functions shall be visible and audible.

412.7 Video Communication.

Where ICT provides real-time video functionality, the quality of the video shall be sufficient to support communication using sign language.

412.8.1 TTY Connectability.

ICT shall include a standard non-acoustic connection point for TTYs.

412.8.2 Voice and Hearing Carry Over.

ICT shall provide a microphone capable of being turned on and off to

As of September 29, 2021 Page 19 allow the user to intermix speech with TTY use.

412.8.3 Signal Compatibility.

ICT shall support all commonly used cross-manufacturer non-proprietary standard TTY signal protocols where the system interoperates with the Public Switched Telephone Network (PSTN).

412.8.4 Voice Mail and Other Messaging Systems.

Where provided, voice mail, auto-attendant, interactive voice response, and caller identification systems shall be usable with a TTY.

413.1.1 Decoding and Display of Closed Captions.

Players and displays shall decode closed caption data and support display of captions.

413.1.2 Pass-Through of Closed Caption

Data. Cabling and ancillary equipment shall pass through caption data.

414.1.1 Digital Television Tuners.

Digital television tuners shall provide audio description processing that conforms to ATSC A/53 Digital Television Standard, Part 5 (2014) (incorporated by reference, see 702.2.1). Digital television tuners shall provide processing of audio description when encoded as a Visually Impaired (VI) associated audio service that is provided as a complete program mix containing audio description according to the ATSC A/53 standard.

414.1.2 Other ICT.

ICT other than digital television tuners shall provide audio description processing.

415.1.1 Caption Controls.

Where ICT provides operable parts for volume control, ICT shall also provide operable parts for caption selection.

415.1.2 Audio Description Controls.

Where ICT provides operable parts for program selection, ICT shall also provide operable parts for the selection of audio description.

6.2.1.2 Concurrent Voice and Text.

Where ICT supports two-way voice communication in a specified context of use, and enables a user to communicate with another user by RTT, it shall provide a mechanism to select a mode of operation which allows concurrent voice and text.

6.2.2.2 Programmatically Determinable Send and Receive Direction.

Where ICT has RTT send and receive capabilities, the send/receive direction of transmitted text shall be programmatically determinable, unless the RTT has closed functionality..

As of September 29, 2021 Page 20

Chapter 5: Software

Criteria Conformance Level Remarks and Explanations

502.2.1 User Control of Accessibility Features.

Platforms shall provide user control over platform features that are defined in the platform documentation as accessibility features.

502.2.2 No Disruption of Accessibility Features.

Software shall not disrupt platform features that are defined in the platform documentation as accessibility features.

502.3.1 Object Information.

The object role, state(s), boundary, name, and description shall be programmatically determinable.

502.3.2 Modification of Object Information.

States and properties that can be set by the user shall be capable of being set programmatically, including through assistive technology.

502.3.3 Row, Column, and Headers.

If an object is in a table, the occupied rows and columns, and any headers associated with those rows or columns, shall be

502.3.4 Values.

Any current value(s), and any set or range of allowable values associated with an object, shall be programmatically determinable.

502.3.5 Modification of Values.

Values that can be set by the user shall be capable of being set programmatically, including through assistive technology.

502.3.6 Label Relationships.

Any relationship that a component has as a label for another component, or of being labeled by another component, shall be

502.3.7 Hierarchical Relationships.

Any hierarchical (parent-child) relationship that a component has as a container for, or being contained by, another component shall be

502.3.8 Text

The content of text objects, text attributes, and the boundary of text rendered to the screen, shall be programmatically determinable.

502.3.9 Modification of Text

Text that can be set by the user shall be capable of being set programmatically, including through assistive technology.

502.3.10 List of Actions

A list of all actions that can be executed on an object shall be

502.3.11 Actions on Objects.

Applications shall allow assistive technology to programmatically…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .