Attachment 7 52.204-23 (DEVIATION 20-05) (JUL 2024)_.pdf

PDF 86 KB Posted

Attached to
Guam Antenna Inspection Federal contract opportunity
Solicitation number
52800PR250000082
Issued by
Department of Homeland Security US Coast Guard

About this file

This is FAR clause 52.204-23 (Deviation 20-05) effective July 2024 that prohibits contractors from providing or using any hardware, software, or services developed or provided by Kaspersky Lab and its covered entities in government contracts.

The clause defines Kaspersky Lab covered articles as any hardware, software, or services developed/provided by Kaspersky Lab entities, including successor companies and those under common control. It requires contractors to report within 3 business days to the Contracting Officer and Enterprise Security Operations Center if they identify any covered articles, providing details like contract numbers, supplier information, and mitigation actions. Additional reporting is required within 10 business days with further mitigation information. The clause must be flowed down to all subcontractors, including commercial item subcontracts. This is tied to Section 1634 of the FY2018 National Defense Authorization Act which prohibits government use of Kaspersky products after October 1, 2018.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

52.204-23 (DEVIATION 20-05) (JUL 2024)

52.204-23 PROHIBITION ON CONTRACTING FOR HARDWARE, SOFTWARE, AND

SERVICES DEVELOPED OR PROVIDED BY KASPERSKY LAB COVERED ENTITIES

(DEVIATION 20-05) (JUL 2024)

(a) Definitions. As used in this clause- Kaspersky Lab covered article means any hardware, software, or service that–

(1) Is developed or provided by a Kaspersky Lab covered entity;

(2) Includes any hardware, software, or service developed or provided in whole or in part by a

Kaspersky Lab covered entity; or

(3) Contains components using any hardware or software developed in whole or in part by a

Kaspersky Lab covered entity.

Kaspersky Lab covered entity means–

(1) Kaspersky Lab;

(2) Any successor entity to Kaspersky Lab, including any change in name, e.g., “Kaspersky”;

(3) Any entity that controls, is controlled by, or is under common control with Kaspersky Lab; or

(4) Any entity of which Kaspersky Lab has a majority ownership.

(b) Prohibition. Section 1634 of Division A of the National Defense Authorization Act for Fiscal

Year 2018 (Pub. L. 115-91) prohibits Government use of any Kaspersky Lab covered article. The

Contractor is prohibited from—

(1) Providing any Kaspersky Lab covered article that the Government will use on or after October 1, 2018; and

(2) Using any Kaspersky Lab covered article on or after October 1, 2018, in the development of data or deliverables first produced in the performance of the contract.

(c) Reporting requirement.

(1) In the event the Contractor identifies covered article provided to the Government during contract performance, or the Contractor is notified of such by a subcontractor at any tier or by any other source, the Contractor shall report, in writing, via email, to the Contracting Officer, Contracting Officer's

Representative, and the Enterprise Security Operations Center (SOC) at NDAA Incidents@hq.dhs.gov, with required information in the body of the email. In the case of the Department of Defense, the

Contractor shall report to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the

Contractor shall report to the Enterprise SOC, Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) and Contracting Officer's Representative(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.

(2) The Contractor shall report the following information pursuant to paragraph (c)(1) of this clause:

(i) Within 3 business days from the date of such identification or notification:

the contract number; the order number(s), if applicable; supplier name;

brand; model number (Original Equipment Manufacturer (OEM) number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.

(ii) Within 10 business days of submitting the report pursuant to paragraph

(c)(1) of this clause: any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall mailto:Incidents@hq.dhs.gov https://dibnet.dod.mil/ https://dibnet.dod.mil/

52.204-23 (DEVIATION 20-05) (JUL 2024)

describe the efforts it undertook to prevent use or submission of a Kaspersky

Lab covered article, any reasons that led to the use or submission of the

Kaspersky Lab covered article, and any additional efforts that will be incorporated to prevent future use or submission of Kaspersky Lab covered articles.

(d) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (d), in all subcontracts, including subcontracts for the acquisition of commercial items.

(End of clause)

File details come from the government source that posted it. Updated .