Attachment 5 NAF Standard Clauses Incorporated By Reference Full Text.pdf
PDF 724 KB Posted
- Attached to
- Base Linen Cleaning Federal contract opportunity
- Solicitation number
- FA480325QB005
About this file
This document is a comprehensive compilation of Nonappropriated Fund (NAF) Standard Clauses covering various federal contracting provisions. The file contains multiple standardized clauses addressing topics such as procurement requirements, rights in technical data, computer software, workers' compensation, equal opportunity, cybersecurity, and restrictions on contracting with specific entities.
Key clauses include provisions on: prohibiting individuals convicted of fraud from contract work, restrictions on using hardware/software from entities like Kaspersky Lab, limitations on telecommunications equipment from certain countries, technical data rights, cloud computing services, child labor regulations, buy American requirements, workers' compensation insurance, and guidelines for contract changes. The clauses are designed to establish comprehensive legal and operational standards for federal contractors, covering everything from data protection and intellectual property rights to ethical employment practices and procurement regulations.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 0001 Question and Answers FA480325QB025.pdf | ||
| Amendment 0001 Attachment 1 Question and Answers FA480325QB005.pdf | ||
| Attachment 4 WD 2015-4439 Rev 25 23 Dec 2024.pdf | ||
| Attachment 1 Non-appropriated Fund Standard Clauses.pdf | ||
| Attachment 3 QASP Base Linen Cleaning.pdf | ||
| Attachment 6 Clause 52.212-5 By Reference Full Text.pdf | ||
| RFQ Service with Options FA480325QB005.pdf | ||
| Attachment 2 Laundry and Dry Cleaning PWS Revised v1 15 April 2025.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
1 May 2024 Page 1 of 135
NONAPPROPRIATED FUND STANDARD CLAUSES INCORPORATED BY REFERENCE
- FULL TEXT -
NFC-203-7001 - PROHIBITION ON PERSONS CONVICTED OF FRAUD OR OTHER DEFENSE –
CONTRACT FELONIES (JAN 2023)
(a) Definitions. As used in this clause-
(1) “Arising out of a contract with the DoD” means any act in connection with-
(i) Attempting to obtain;
(ii) Obtaining; or
(iii) Performing a contract or first-tier subcontract of any agency, department, or component of the Department of Defense (DoD).
(2) “Conviction of fraud or any other felony” means any conviction for fraud or a felony in violation of state or Federal criminal statutes, whether entered on a verdict or plea, including a plea of nolo contendere, for which sentence has been imposed.
(3) “Date of conviction” means the date judgment was entered against the individual.
(b) Any individual who is convicted after September 29, 1988, of fraud or any other felony arising out of a contract with the DoD is prohibited from serving-
(1) In a management or supervisory capacity on this contract;
(2) On the board of directors of the Contractor;
(3) As a consultant, agent, or representative for the Contractor; or
(4) In any other capacity with the authority to influence, advise, or control the decisions of the Contractor with regard to this contract.
(c) Unless waived, the prohibition in paragraph (b) of this clause applies for not less than 5 years from the date of conviction.
(d) 10 U.S.C. 2408 provides that the Contractor shall be subject to a criminal penalty of not more than $500,000 if convicted of knowingly-
(1) Employing a person under a prohibition specified in paragraph (b) of this clause; or
(2) Allowing such a person to serve on the board of directors of the contractor or first-tier subcontractor.
1 May 2024 Page 2 of 135
(e) In addition to the criminal penalties contained in 10 U.S.C. 4656, the NAFI may consider other available remedies, such as-
(1) Suspension or debarment;
(2) Cancellation of the contract at no cost to the NAFI; or
(3) Termination of the contract for default.
(f) The Contractor may submit written requests for waiver of the prohibition in paragraph (b) of this clause to the Contracting Officer. Requests shall clearly identify-
(1) The person involved;
(2) The nature of the conviction and resultant sentence or punishment imposed;
(3) The reasons for the requested waiver; and
(4) An explanation of why a waiver is in the interest of national security.
(g) Subcontracts. The Contractor agrees to include the substance of this clause, appropriately modified to reflect the identity and relationship of the parties, in all first-tier subcontracts exceeding the simplified acquisition threshold in Part 2 of the Federal Acquisition Regulation, except those for commercial items or components.
(h) Pursuant to 10 U.S.C. 4656(c), defense contractors and subcontractors may obtain information as to whether a particular person has been convicted of fraud or any other felony arising out of a contract with the DoD by contacting The Office of Justice Programs, The Denial of Federal Benefits Office, U.S.
Department of Justice, telephone 301-937-1542; www.ojp.usdoj.gov/BJA/grant/DPFC.html
(End of clause)
NFC-204-23 - PROHIBITION ON CONTRACTING FOR HARDWARE, SOFTWARE, AND
SERVICES DEVELOPED OR PROVIDED BY KASPERSKY LAB COVERED ENTITIES (DEC 2023)
(a) Definitions. As used in this clause-
Kaspersky Lab covered article means any hardware, software, or service that-
(1) Is developed or provided by a covered entity;
(2) Includes any hardware, software, or service developed or provided in whole or in part by a covered entity; or
(3) Contains components using any hardware or software developed in whole or in part by a covered entity.
http://www.ojp.usdoj.gov/BJA/grant/DPFC.html
1 May 2024 Page 3 of 135
Kapersky Lab covered entity means-
(1) Kaspersky Lab;
(2) Any successor entity to Kaspersky Lab;
(3) Any entity that controls, is controlled by, or is under common control with Kaspersky Lab; or
(4) Any entity of which Kaspersky Lab has a majority ownership.
(b) Prohibition. Section 1634 of Division A of the National Defense Authorization Act for Fiscal Year 2018 (Pub. L. 115-91) prohibits NAFI use of any covered article. The Contractor is prohibited from-
(1) Providing any Kapersky Lab covered article that the NAFI will use on or after October 1, 2018; and
(2) Using any Kapersky Lab covered article on or after October 1, 2018, in the development of data or deliverables first produced in the performance of the contract.
(c) Reporting requirement.
(1) In the event the Contractor identifies a Kapersky Lab covered article provided to the NAFI during contract performance, or the Contractor is notified of such by a subcontractor at any tier or any other source, the Contractor shall report, in writing, to the Contracting Officer or, in the case of the Department of Defense, to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil
(2) The Contractor shall report the following information pursuant to paragraph (c)(1) of this clause:
(i) Within 3 business days from the date of such identification or notification: the contract number;
the order number(s), if applicable; supplier name; brand; model number (Original Equipment Manufacturer (OEM) number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the report pursuant to paragraph (c)(1) of this clause: any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of a Kapersky Lab covered article, any reasons that led to the use or submission of the Kapersky Lab covered article, and any additional efforts that will be incorporated to prevent future use or submission of covered articles.
(d) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (d), in all subcontracts, including subcontracts for the acquisition of commercial products or commercial services.
(End of clause) https://dibnet.dod.mil/
1 May 2024 Page 4 of 135
NFC-204-25 - PROHIBITION FOR CERTAIN TELECOMMUNICATIONS AND VIDEO
SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)
(a) Definitions. As used in this clause-
Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge of the network (e.g., connecting cell phones/towers to the core telephone network).
Backhaul can be wireless (e.g., microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet).
Covered foreign country means The People’s Republic of China.
Covered telecommunications equipment or services means-
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary or affiliate of such entities);
(2) For the purpose of public safety, security of NAFI facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);
(3) Telecommunications or video surveillance services provided by such entities or using such equipment;
or
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.
Critical technology means-
(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled-
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or
(ii) For reasons relating to regional stability or surreptitious listening;
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);
1 May 2024 Page 5 of 135
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).
Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow the use of another's network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone provider A to a customer of telephone company B) or sharing data and other information resources.
Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include an internal or third-party audit.
Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high.
Substantial or essential component means any component necessary for the proper function or performance of a piece of equipment, system, or service.
(b) Prohibition.
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The Contractor is prohibited from providing to the NAFI any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in
FAR 4.2104.
(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract, or extending or renewing a contract, with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract.
https://www.acquisition.gov/far/4.2104#FAR_4_2104 https://www.acquisition.gov/far/4.2104#FAR_4_2104
1 May 2024 Page 6 of 135
(c) Exceptions. This clause does not prohibit contractors from providing-
(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(d) Reporting requirement.
(1) In the event the Contractor identifies covered telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during contract performance, or the Contractor is notified of such by a subcontractor at any tier or by any other source, the Contractor shall report the information in paragraph (d)(2) of this clause to the Contracting Officer, unless elsewhere in this contract are established procedures for reporting the information; in the case of the Department of Defense, the Contractor shall report to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.
(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause
(i) Within one business day from the date of such identification or notification: the contract number;
the order number(s), if applicable; supplier name; supplier unique entity identifier (if known);
supplier Commercial and Government Entity (CAGE) code (if known); brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number);
item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of covered telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.
(e) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (e) and excluding paragraph (b)(2), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services.
NFC-204-27 - PROHIBITION ON A BYTEDANCE COVERED APPLICATION (JUN 2023)
(a) Definitions. As used in this clause-
1 May 2024 Page 7 of 135
Covered application means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.
Information technology, as defined in 40 U.S.C. 11101(6)-
(1) Means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use-
(i) Of that equipment; or
(ii) Of that equipment to a significant extent in the performance of a service or the furnishing of a product;
(2) Includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but
(3) Does not include any equipment acquired by a Federal contractor incidental to a Federal contract.
(b) Prohibition. Section 102 of Division R of the Consolidated Appropriations Act, 2023 (Pub. L. 117-328), the No TikTok on Government Devices Act, and its implementing guidance under Office of Management and Budget (OMB) Memorandum M-23-13, dated February 27, 2023, “No TikTok on Government Devices” Implementation Guidance, collectively prohibit the presence or use of a covered application on executive agency information technology, including certain equipment used by Federal contractors. The Contractor is prohibited from having or using a covered application on any information technology owned or managed by the NAFI, or on any information technology used or provided by the Contractor under this contract, including equipment provided by the Contractor’s employees; however, this prohibition does not apply if the Contracting Officer provides written notification to the Contractor that an exception has been granted in accordance with OMB Memorandum M-23-13.
(c) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (c), in all subcontracts, including subcontracts for the acquisition of commercial products or commercial services.
NFC-204-7000 - DISCLOSURE OF INFORMATION (OCT 2016)
(a) The Contractor shall not release to anyone outside the Contractor's organization any unclassified information, regardless of medium (e.g., film, tape, document), pertaining to any part of this contract or any program related to this contract, unless-
(1) The Contracting Officer has given prior written approval;
1 May 2024 Page 8 of 135
(2) The information is otherwise in the public domain before the date of release; or
(3) The information results from or arises during the performance of a project that involves no covered defense information (as defined in the clause at NFC 204-7012) and has been scoped and negotiated by the contracting activity with the contractor and research performer and determined in writing by the contracting officer to be fundamental research (which by definition cannot involve any covered defense information), in accordance with National Security Decision Directive 189, National Policy on the Transfer of Scientific, Technical and Engineering Information, in effect on the date of contract award and the Under Secretary of Defense (Acquisition, Technology, and Logistics) memoranda on Fundamental Research, dated May 24, 2010, and on Contracted Fundamental Research, dated June 26, 2008.
(b) Requests for approval under paragraph (a)(1) shall identify the specific information to be released, the medium to be used, and the purpose for the release. The Contractor shall submit its request to the Contracting Officer at least 10 business days before the proposed date for release.
(c) The Contractor agrees to include a similar requirement, including this paragraph (c), in each subcontract under this contract. Subcontractors shall submit requests for authorization to release through the prime contractor to the Contracting Officer.
NFC 204-7009 - LIMITATIONS ON THE USE OR DISCLOSURE OF THIRD-PARTY
CONTRACTOR REPORTED CYBER INCIDENT INFORMATION (JAN 2023)
(a) Definitions. As used in this clause-
“Compromise” means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
“Controlled technical information” means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
“Covered defense information” means unclassified controlled technical information or other information (as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html) that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is-
(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
https://acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.#DFARS-252.204-7012
1 May 2024 Page 9 of 135
“Cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
“Information system” means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
“Media” means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
“Technical information” means technical data or computer software, as those terms are defined in the clause at NFC 227-7013, Rights in Technical Data-Other Than Commercial Products and Commercial Services, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Restrictions. The Contractor agrees that the following conditions apply to any information it receives or creates in the performance of this contract that is information obtained from a third-party’s reporting of a cyber incident pursuant to clause NFC 204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (or derived from such information obtained under that clause):
(1) The Contractor shall access and use the information only for the purpose of furnishing advice or technical assistance directly to the Government in support of the Government’s activities related to clause NFC 204-7012, and shall not be used for any other purpose.
(2) The Contractor shall protect the information against unauthorized release or disclosure.
(3) The Contractor shall ensure that its employees are subject to use and non-disclosure obligations consistent with this clause prior to the employees being provided access to or use of the information.
(4) The third-party contractor that reported the cyber incident is a third-party beneficiary of the non-disclosure agreement between the Government and Contractor, as required by paragraph (b)(3) of this clause.
(5) A breach of these obligations or restrictions may subject the Contractor to-
(i) Criminal, civil, administrative, and contractual actions in law and equity for penalties, damages, and other appropriate remedies by the United States; and
(ii) Civil actions for damages and other appropriate remedies by the third party that reported the cyber incident, as a third-party beneficiary of this clause.
(c) Subcontracts. The Contractor shall include this clause, including this paragraph (c), in subcontracts, or similar contractual instruments, for services that include support for the Government’s activities related to safeguarding covered defense information and cyber incident reporting, including subcontracts for commercial items, without alteration, except to identify the parties.
1 May 2024 Page 10 of 135
NFC 204-7012 - SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT
REPORTING (JAN 2023)
(a) Definitions. As used in this clause-
“Adequate security” means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
“Compromise” means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
“Contractor attributional/proprietary information” means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
“Controlled technical information” means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
“Covered contractor information system” means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
“Covered defense information” means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is-
(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
“Cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
“Forensic analysis” means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
“Information system” means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
“Malicious software” means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This
1 May 2024 Page 11 of 135 definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
“Media” means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
‘‘Operationally critical support’’ means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
“Rapidly report” means within 72 hours of discovery of any cyber incident.
“Technical information” means technical data or computer software, as those terms are defined in the clause NFC 227-7013, Rights in Technical Data - Other Than Commercial Products and Commercial Services, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:
(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:
(i) Cloud computing services shall be subject to the security requirements specified in the clause NFC 239-7010, Cloud Computing Services, of this contract.
(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.
(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:
(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171) in effect at the time the solicitation is issued or as authorized by the Contracting Officer.
(ii) (A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.
http://dx.doi.org/10.6028/NIST.SP.800-171
1 May 2024 Page 12 of 135
(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
(C) If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.
(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/resources/documents/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
(c) Cyber incident reporting requirement.
(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall-
(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor’s ability to provide operationally critical support; and
(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.
(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance https://www.fedramp.gov/resources/documents
1 May 2024 Page 13 of 135 certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.
(d) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.
(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.
(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.
(i) Use and release of contractor attributional/proprietary information not created by or for DoD.
Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD-
(1) To entities with missions that may be affected by such information;
(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
(3) To Government entities that conduct counterintelligence or law enforcement investigations;
(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or
(5) To a support services contractor (“recipient”) that is directly supporting Government activities under a contract that includes the clause at NFC 204-7009 , Limitations on the Use or Disclosure of Third- Party Contractor Reported Cyber Incident Information.
1 May 2024 Page 14 of 135
(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government’s use and release of such information.
(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor’s responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(m) Subcontracts. The Contractor shall-
(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and
(2) Require subcontractors to-
(i) Notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause; and
(ii) Provide the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber incident to DoD as required in paragraph (c) of this clause.
NFC-222-19 - CHILD LABOR-COOPERATION WITH AUTHORITIES AND REMEDIES (FEB 2024)
(a) Applicability. This clause does not apply to the extent that the Contractor is supplying end products mined, produced, or manufactured in-
(1) Israel, and the anticipated value of the acquisition is $50,000 or more;
(2) Mexico, and the anticipated value of the acquisition is $102,280 or more; or
(3) Armenia, Aruba, Australia, Austria, Belgium, Bulgaria, Canada, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hong Kong, Hungary, Iceland, Ireland, Italy, 1 May 2024 Page 15 of 135
Japan, Korea, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Montenegro, Netherlands, New Zealand, North Macedonia, Norway, Poland, Portugal, Romania, Singapore, Slovak Republic, Slovenia, Spain, Sweden, Switzerland, Taiwan, Ukraine, or the United Kingdom and the anticipated value of the acquisition is $174,000 or more.
(b) Cooperation with Authorities. To enforce the laws prohibiting the manufacture or importation of products mined, produced, or manufactured by forced or indentured child labor, authorized officials may need to conduct investigations to determine whether forced or indentured child labor was used to mine, produce, or manufacture any product furnished under this contract. If the solicitation includes the provision 52.222- 18, Certification Regarding Knowledge of Child Labor for Listed End Products, or the equivalent at 52.212-3(i), the Contractor agrees to cooperate fully with authorized officials of the contracting agency, the Department of the Treasury, or the Department of Justice by providing reasonable access to records, documents, persons, or premises upon reasonable request by the authorized officials.
(c) Violations. The NAFI may impose remedies set forth in paragraph (d) for the following violations:
(1) The Contractor has submitted a false certification regarding knowledge of the use of forced or indentured child labor for listed end products.
(2) The Contractor has failed to cooperate, if required, in accordance with paragraph (b) of this clause, with an investigation of the use of forced or indentured child labor by an Inspector General, Attorney General, or the Secretary of the Treasury.
(3) The Contractor uses forced or indentured child labor in its mining, production, or manufacturing processes.
(4) The Contractor has furnished under the contract end products or components that have been mined, produced, or manufactured wholly or in part by forced or indentured child labor. (The NAFI will not pursue remedies at paragraph (d)(2) or paragraph (d)(3) of this clause unless sufficient evidence indicates that the Contractor knew of the violation.)
(d) Remedies.
(1) The Contracting Officer may terminate the contract.
(2) The suspending official may suspend the Contractor in accordance with procedures in FAR subpart 9.4.
(3) The debarring official may debar the Contractor for a period not to exceed 3 years in accordance with the procedures in FAR subpart 9.4.
NFC-222-20 - CONTRACTS FOR MATERIALS, SUPPLIES, ARTICLES, AND EQUIPMENT
(JUN 2020)
If this contract is for the manufacture or furnishing of materials, supplies, articles or equipment in an amount that exceeds or may exceed the threshold specified in Federal Acquisition Regulation 22.602 on the date of award of this contract, and is subject to 41 U.S.C. chapter 65, the following terms and conditions apply:
https://www.acquisition.gov/far/52.222-18#FAR_52_222_18 https://www.acquisition.gov/far/52.222-18#FAR_52_222_18 https://www.acquisition.gov/far/52.212-3#FAR_52_212_3 https://www.acquisition.gov/far/subpart-9.4#FAR_Subpart_9_4 https://www.acquisition.gov/far/subpart-9.4#FAR_Subpart_9_4 https://www.acquisition.gov/far/22.602#FAR_22_602 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3
1 May 2024 Page 16 of 135
(a) All stipulations required by 41 U.S.C. chapter 65 and regulations issued by the Secretary of Labor (41 CFR Chapter 50) are incorporated by reference. These stipulations are subject to all applicable rulings and interpretations of the Secretary of Labor that are now, or may hereafter, be in effect.
(b) All employees whose work relates to this contract shall be paid not less than the minimum wage prescribed by regulations issued by the Secretary of Labor (41 CFR 50-202.2). Learners, student learners, apprentices, and workers with disabilities may be employed at less than the prescribed minimum wage (see 41 CFR 50-202.3) to the same extent that such employment is permitted under section 14 of the Fair Labor Standards Act (41 U.S.C. 6508).
NFC-222-21 - PROHIBITION OF SEGREGATED FACILITIES (APR 2015)
(a) Definitions. As used in this clause
Gender identity has the meaning given by the Department of Labor’s Office of Federal Contract Compliance Programs, and is found at http://www.dol.gov/ofccp/LGBT/LGBT_FAQs.html
Segregated facilities, means any waiting rooms, work areas, rest rooms and wash rooms, restaurants and other eating areas, time clocks, locker rooms and other storage or dressing areas, parking lots, drinking fountains, recreation or entertainment areas, transportation, and housing facilities provided for employees, that are segregated by explicit directive or are in fact segregated on the basis of race, color, religion, sex, sexual orientation, gender identity, or national origin because of written or oral policies or employee custom. The term does not include separate or single-user rest rooms or necessary dressing or sleeping areas provided to assure privacy between the sexes.
Sexual orientation has the meaning given by the Department of Labor’s Office of Federal Contract Compliance Programs, and is found at http://www.dol.gov/ofccp/LGBT/LGBT_FAQs.html
(b) The Contractor agrees that it does not and will not maintain or provide for its employees any segregated facilities at any of its establishments, and that it does not and will not permit its employees to perform their services at any location under its control where segregated facilities are maintained. The Contractor agrees that a breach of this clause is a violation of the Equal Opportunity clause in this contract.
(c) The Contractor shall include this clause in every subcontract and purchase order that is subject to the Equal Opportunity clause of this contract.
NFC-222-26 - EQUAL OPPORTUNITY (SEPT 2016)
(a) Definition. As used in this clause.
Compensation means any payments made to, or on behalf of, an employee or offered to an applicant as remuneration for employment, including but not limited to salary, wages, overtime pay, shift differentials, http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3
1 May 2024 Page 17 of 135 bonuses, commissions, vacation and holiday pay, allowances, insurance and other benefits, stock options and awards, profit sharing, and retirement.
Compensation information means the amount and type of compensation provided to employees or offered to applicants, including, but not limited to, the desire of the Contractor to attract and retain a particular employee for the value the employee is perceived to add to the Contractor's profit or productivity; the availability of employees with like skills in the marketplace; market research about the worth of similar jobs in the relevant marketplace; job analysis, descriptions, and evaluations; salary and pay structures; salary surveys; labor union agreements; and Contractor decisions, statements and policies related to setting or altering employee compensation.
Essential job functions means the fundamental job duties of the employment position an individual holds. A job function may be considered essential if-
(1) The access to compensation information is necessary in order to perform that function or another routinely assigned business task; or
(2) The function or duties of the position include protecting and maintaining the privacy of employee personnel records, including compensation information.
Gender identity has the meaning given by the Department of Labor’s Office of Federal Contract Compliance Programs, and is found at http://www.dol.gov/ofccp/LGBT/LGBT_FAQs.html.
Sexual orientation has the meaning given by the Department of Labor’s Office of Federal Contract Compliance Programs, and is found at http://www.dol.gov/ofccp/LGBT/LGBT_FAQs.html.
United States, means the 50 States, the District of Columbia, Puerto Rico, the Northern Mariana Islands, American Samoa, Guam, the U.S. Virgin Islands, and Wake Island.
(b) (1) If, during any 12-month period (including the 12 months preceding the award of this contract), the Contractor has been or is awarded nonexempt Federal contracts and/or subcontracts that have an aggregate value in excess of $10,000, the Contractor shall comply with this clause, except for work performed outside the United States by employees who were not recruited within the United States.
Upon request, the Contractor shall provide information necessary to determine the applicability of this clause.
(2) If the Contractor is a religious corporation, association, educational institution, or society, the requirements of this clause do not apply with…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .