ATTM 3c _OPM Clauses IBR and Full Text.pdf

PDF 354 KB Posted

Attached to
Federal Flexible Spending Account Program (FSAFEDS) Federal contract opportunity
Solicitation number
24322625R0004
Issued by
Office of Personnel Management

About this file

This document is Attachment 3C containing Office of Personnel Management (OPM) Clauses for a Federal Flexible Spending Account Program (FSAFEDS) contract opportunity. The clauses cover on-site working conditions, including smoking restrictions, normal operating hours (7:00 am to 5:30 pm Monday-Friday), and a comprehensive list of government holidays. Additional provisions address contractor personnel requirements such as obtaining security clearances, key personnel management, potential conflicts of interest, and strict information technology and cybersecurity protocols.

The clauses outline extensive requirements for contractors, including mandatory security and privacy training, use of Personal Identity Verification (PIV) cards, encryption standards for Controlled Unclassified Information, continuous security monitoring, and specific procedures for handling, returning, and securely destroying government-related information and equipment. Contractors must comply with numerous federal information security regulations, provide Software Bills of Materials, and submit to potential audits and inspections throughout the contract period. The document emphasizes rigorous security, information protection, and operational standards that contractors must meet when working with OPM systems and data.

View the file

Other files for this federal contract opportunity

Other files attached to Federal Flexible Spending Account Program (FSAFEDS), newest first.
File Type Posted
9l. Appendix L WeeklyOperationalSummaryReport_04.23.2025_Sanitized.xlsx XLSX spreadsheet
ATTM 4_RFP_Questions Response Form_Combined .xlsx XLSX spreadsheet
9a. Appendix A FedFlex Plan Document Dec 2024.pdf PDF
9b. Appendix B FedScope.docx DOCX document
9f. Appendix F Participating Agencies.docx DOCX document
9j. Appendix J Enrollment by Agency 2020-2024.xlsx XLSX spreadsheet
Revised_ATTM X_ Proposal Instructions - Evaluation 5.7.25.docx DOCX document
9c. Appendix C Communication Vehicles.docx DOCX document
9d. Appendix D FEHB FEDVIP Brochures.docx DOCX document
9g. Appendix G Historical Enrollment.docx DOCX document
9h. Appendix H Definitions.docx DOCX document
9k. Appendix K FSAFEDS_Enrollment_by_Agency_04212025.pdf PDF
ATTM_XI_Amendment_Acknowledgement.docx DOCX document
Revised_ATTM 1a_PERFORMANCE WORK STATEMENT 2025-05-08.docx DOCX document
ATTM 4_RFP_Questions Response Form_Combined .pdf PDF
9e. Appendix E Intelligence Community Security.docx DOCX document
Attach 2_ Pricing Proposal Schedule.xlsx XLSX spreadsheet
ATTM 4_ RFP Question Response Form.xlsx XLSX spreadsheet
ATTM 5 _PASS-FAIL Forms and Questionnaires.docx DOCX document
ATTM 6 _ACKNOWLEDGMENT OF AMENDMENTS.docx DOCX document
ATTM 8 _IT Security Affirmation.docx DOCX document
ATTM X_ Proposal Instructions - Evaluation.pdf PDF
ATTM 3b _FAR Clauses IBR and Full Text.pdf PDF
ATTM 7_SBPCD Template.docx DOCX document
ATTM 3a _Provisions IBR and Full Text.pdf PDF
ATTM 1a_PERFORMANCE WORK STATEMENT.pdf PDF
ATTM 1b_Appendices A through H and Exhibit J.pdf PDF
ATTM 9_ SB Subcontracting Plan Template.docx DOCX document
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP #24322625R0004

ATTACHMENT 3C

OPM CLAUSES

1752.200-70 - On-Site Working Conditions (May 2022)

(a) OPM facilities are smoking restricted workplaces. Due to the nature of the work, facilities, and requirements, contractor staff may only smoke outside in designated smoking areas.

(b) Normal operating hours are 7:00 am to 5:30 pm, Monday through Friday. Meeting task objectives within specific timeframes may require the working of extended/overtime hours. Any extended hours must be authorized in advance and certified as worked by the task Government Project Manager(s).

(c) Government personnel observe the following days as holidays:

New Year’s Day January 1 *

Birthday of Martin Luther King, Jr. Third Monday in January

Washington’s Birthday Third Monday in February

Memorial Day Last Monday in May

Juneteenth National Independence Day June 19*

Independence Day July 4*

Labor Day First Monday in September

Columbus Day Second Monday in October

Veterans Day November 11

Thanksgiving Day Fourth Thursday in November

Christmas Day December 25*

* If the date falls on a Saturday, the Government holiday is the preceding Friday. If the date falls on a Sunday, the Government holiday is the following Monday.

(d) In addition to the days designated as holidays, the Government observes the following days:

• Any other day designated by Federal Statute

• Any other day designated by Executive Order

• Presidential Inauguration Day

• Any other day designated by the President’s Proclamation

(e) It is understood and agreed between the Government and the Contractor that observance of such days by Government personnel shall not otherwise be a reason for an additional period of performance, or entitlement of compensation except as set forth within the contract. In the event the Contractor's personnel work during the holiday, they may be reimbursed by the Contractor, however, no form of holiday or other premium compensation will be reimbursed either as a direct or indirect cost, other than their normal compensation for the time worked. This provision does not preclude reimbursement for authorized overtime work if applicable to this contract.

(f) When the Federal, State, Local or other Governmental entity grants excused absence to its employees, assigned Contractor personnel may also be dismissed. The Contractor agrees to continue to provide sufficient personnel to perform critical tasks already in operation or scheduled, and must be guided by the instructions issued by the CO or COR.

(g) If Government personnel are unavailable due to furlough or any other reason, the Contractor must contact the CO or the COR to receive direction. It is the Government's decision as to whether the contract price/cost will be affected. Generally, the following situations apply:

(1) Contractor personnel who are able to continue contract performance (either on-site or at a site other than their normal workstation), must continue to work and the contract price shall not be reduced or increased.

(2) Contractor personnel who are not able to continue contract performance (e.g., support functions) may be asked to cease their work effort. This may result in a reduction to the contract price.

(End of Clause)

1752.204-70 - Contractor Personnel Security Requirements (Jan 2008)

(a) The U.S. Office of Management and Budget (OMB) Memorandum M-05-24, referenced in paragraph (a) of FAR 52.204-9, Personal Identity Verification of Contractor Personnel, is available on-line at http://www.whitehouse.gov/omb/memoranda/fy2005/m05-24.pdf.

(b) The Government may require security clearances for performance of this contract. The Contractor must obtain these clearances before beginning work on the contract (OPM will not allow Contractor employees without clearance in any of its facilities). The Contractor must obtain these clearances by using the eQIP system. If satisfactory security arrangements cannot be made with the Contractor, the required services must be obtained from other sources.

(c) The level of classified access required will be indicated on DD-254 or other appropriate form incorporated into each request requiring access to classified information. Contractors are required to have background investigations for suitability if they occupy positions of trust (e.g., systems administration) even if they do NOT have access to classified information.

(d) Necessary facility and/or staff clearances must be in place prior to start of work on the contract

(e) Contractors are responsible for the security, integrity and appropriate authorized use of their systems interfacing with the Government and or used for the transaction of any and all Government business.

The Government, through the Government's Contracting Officer, may require the use or modification of security and/or secure communications technologies related to Government systems access and use.

(f) The Government, at its discretion, may suspend or terminate the access and/or use of any or all Government access and systems for conducting business with any/or all Contractors when a security or other electronic access, use or misuse issue gives cause for such action. The suspension or termination may last until such time as the Government determines that the situation has been corrected or no longer exists.

1752.209-71 - Contractor’s Key Personnel (Jul 2005) http://www.whitehouse.gov/omb/memoranda/fy2005/m05-24.pdf

(a) In order to ensure a smooth and orderly start up of work, it is essential that the key personnel specified in the Contractor's proposal be available on the effective date of the contract. If these personnel are not made available at that time, the Contractor must notify the Government Contracting Officer and show cause. If the Contractor does not show cause, the Contractor may be subject to default action.

(b) The Contractor shall not of its own will remove or replace any personnel designated as "key" personnel without the written concurrence of the cognizant Contracting Officer. Prior to utilizing employees other than specified personnel, the Contractor shall notify the Government Contracting Officer and the COR. This notification must be no later than five (5) calendar days in advance of any proposed substitution and must include justification (including resume(s) of proposed substitution(s)) in sufficient detail to permit evaluation of the impact on contract performance.

(c) Substitute personnel qualifications must be equal to, or greater than, those of the personnel being substituted. If the Government Contracting Officer and the COR determine that the proposed substitute personnel is unacceptable, or that the reduction of effort would be so substantial as to impair the successful performance of the work under the contract, the Contractor may be subject to default action. If deemed necessary by the Government, substitute personnel must be given a one-

(1) day orientation by Contractor personnel at no additional cost to the Government and with no change in the delivery schedule.

(d) In the event that the performance of assigned Contractor personnel or any substitute(s) is determined by the Government to be unsatisfactory at any time during the life of the Contract, the Government reserves the right to request and receive satisfactory personnel replacement within five (5) calendar days of receipt by the Contractor of written notification. Notification will include the reason for requesting replacement personnel.

(e) The Contractor-supplied personnel are employees of the Contractor and under the administrative control and supervision of the Contractor. The Contractor, through its personnel, shall perform the tasks prescribed herein. The Contractor must select, supervise, and exercise control and direction over its employees (including subcontractors) under this Contract. The Government shall not exercise any supervision or control over the Contractor in its performance of contractual services under this contract. The Contractor is accountable to the Government for the action of its personnel.

(f) The Contractor is herewith notified that employee recruiting and employee retention practices shall be monitored on a regular basis.

1752.209-74 - Organizational Conflicts of Interest (Jul 2005)

(a) The Contractor warrants that, to the best of the Contractor’s knowledge and belief, there are no relevant facts or circumstances which could give rise to an organizational conflict of interest (OCI), as defined in FAR 9.5, Organizational and Consultants Conflicts of Interest, or that the Contractor has disclosed all such relevant information.

(b) The Contractor agrees that if an actual or potential OCI is discovered after award, the Contractor shall make a full disclosure in writing to the Contracting Officer. This disclosure must include a description of actions, which the Contractor has taken or proposes to take, after consultation with the Contracting Officer, to avoid, mitigate, or neutralize the actual or potential conflict.

(c) The Contracting Officer may terminate this contract for convenience, in whole or in part, if it deems such termination necessary to avoid an OCI. If the Contractor was aware of a potential OCI prior to award or discovered an actual or potential conflict after award and did not disclose or misrepresented relevant information to the Contacting Office, the Government may terminate the contract for default, debar the Contractor from Government contracting, or pursue such other remedies as may be permitted by law or this contract.

(d) The Contractor must include this clause in all subcontracts and in lower tier subcontracts unless a waiver is requested from, and granted by, the Contracting Officer.

(e) In the event that a requirement changes in such a way as to create a potential conflict of interest for the Contractor, the Contractor must:

(1) Notify the Contracting Officer of a potential conflict, and;

(2) Recommend to the Government an alternate approach which would avoid the potential conflict, or

(3) Present for approval a conflict of interest mitigation plan that will:

(i) Describe in detail the changed requirement that creates the potential conflict of interest;

and

(ii) Outline in detail the actions to be taken by the Contractor or the Government in the performance of the task to mitigate the conflict, division of subcontractor effort, and limited access to information, or other acceptable means.

(4) The Contractor must not commence work on a changed requirement related to a potential conflict of interest until specifically notified by the Contracting Officer to proceed.

(5) If the Contracting Officer determines that it is in the best interest of the Government to proceed with work, notwithstanding a conflict of interest, a request for waiver must be submitted in accordance with FAR 9.503.

1752.224-70 – Identification and Authentication (Dec 2023)

(a) Authentication designs shall be implemented in such a way that all user accounts are uniquely identified (e.g., firstname.lastname) and are not default or generic. Authentication designs shall be implemented in such a way that accounts uniquely identify system processes.

(b) Identification and authentication mechanisms for the Contractor’s solution used by OPM users shall be designed and implemented to leverage the PIV-based authentication, federated Single Sign On (SSO) capabilities, or other phishing-resistant authentication mechanism.

(c) Identification and authentication mechanisms for the Contractor’s solution used by non-OPM users (e.g., public users) shall be designed and implemented to offer phishing-resistant multifactor authentication to the greatest degree possible. In accordance with Key Integration Requirement [NIST SP 800-53-5; IA-02 (01, 02)], the Contractor's solution shall at the time of award have the capability to integrate directly with the OPM's identity provider and SSO mechanism; having the built-in ability to accept a Security Assertion Markup Language (SAML) assertion from a third-party software. The Contractor’s solution shall utilize multifactor authentication for all access. Phishing-resistant multifactor authentication shall be enforced for OPM users and made available to public users. Corresponding passphrases shall align to the OPM cybersecurity policy requirements

(provided to the Contractor upon award where access is limited and controlled or to Offerors upon request subject to vetting and where access is limited and controlled).

1752.224-71 – Identification and Authentication Certification (Dec 2023)

Offerors must include in their offer/quotation evidence, artifacts, or proof of the ability to integrate directly with the OPM's identity provider and SSO mechanism; having the built-in ability to accept a Security Assertion Markup Language (SAML) assertion from a third-party software.

(End of Provision)

1752.224-72 – Protecting Information (Dec 2023)

(a) Applicability

(1) This clause applies to the Contractor, its subcontractors and teaming partners, and employees (hereafter referred to collectively as “Contractor”).

(2) These requirements are applicable to all Controlled Unclassified Information (CUI) Information, regardless of medium or location, maintained by the Contractor for the performance of this contract.

(b) Authorization to Handle CUI

(1) Prior to receiving, collecting, transmitting, storing, using, accessing, sharing, marking, or removing CUI from any approved locations; the Contractor must receive approval in writing from the Chief Information Officer (CIO) through the Contracting Officer (CO) or Contracting Officer’s Representative (COR). All requests shall be sent to OCIO- ITContractSupport@opm.gov carbon copying the CO and COR with the subject CUI Approval Request.

(2) If the Contractor should begin to receive, collect, transmit, store, use, access, mark, or share CUI without appropriate approval, the Contractor must report this to Cybersolutions@opm.gov as an Information Security Incident (ISI).

(3) Prior to removing CUI from any approved location, electronic device, removable media, or storage container, approval must be received in writing from the CO or COR.

(4) The Contractor shall only store or handle CUI within the United States and its territories. To request approval to store or handle CUI outside of the United States or its territories, submit a request to OCIO-ITContractSupport@opm.gov carbon copying the CO and COR with the subject Geographic CUI Request.

(c) Authorization to Use Information Technology (IT) Systems

(1) Prior to designing, developing, operating, accessing, or using an IT system that will store or process Information other than non-CUI necessary to manage the contract (such as billing), the Contractor must receive approval in writing from the CIO through the CO or COR. To request such approval, submit a request to OCIO-ITContractSupport@opm.gov carbon copying the CO and COR with the subject “IT System Other Than General Use Request.”

(2) The time required to obtain approval may be lengthy, and the Contractor should identify this requirement as soon as possible.

(3) If the Contractor should begin to operate, access, or use an IT system without appropriate approval, it must be reported as an ISI. Report all ISI to CyberSolutions@opm.gov.

mailto:OCIO-ITContractSupport@opm.gov mailto:OCIO-ITContractSupport@opm.gov mailto:OCIO-ITContractSupport@opm.gov mailto:OCIO-ITContractSupport@opm.gov mailto:CyberSolutions@opm.gov

(4) The Contractor shall only access an IT system or use Government Furnished Equipment (GFE) within the United States and its territories. To request approval to access IT systems or take GFE outside of the United States, submit a request to OCIO-ITContractSupport@opm.gov carbon copying the CO and COR with the subject OCONUS GFE Access.

(d) Retention of Authorizing Documentation

(1) The Contractor must maintain a current and complete file of all system authorization documentation and documentation authorizing handling of CUI during the period of performance of the contract, unless otherwise instructed by the Contracting Officer.

(2) Documentation will be made accessible during inspections or upon written request by the CO or the COR.

1752.224-73 – Information Protection Policies and Procedures (Dec 2023)

The Contractor must ensure its policies and procedures address compliance with all information protection requirements of this contract. The policies and procedures must address the following:

(a) Proper identification, marking, control, storage, transmission, use, and handling of Controlled

Unclassified Information (CUI), regardless of medium.

(b) Proper control, storage, and protection of mobile devices, portable data storage devices, and communication devices containing CUI.

(c) Proper use of FIP-140-3. 3,4 compliant encryption, redaction, and masking methods to protect CUI while at rest and in transit throughout Contractor networks, and on server and client platforms.

(d) Proper use of FIP-140-3. 3,4 compliant encryption methods to protect CUI transmitted in email attachments, including policy that passwords must not be communicated in the same email as the attachment.

(e) Roles, responsibilities, and proper actions to be taken during Information Security Incidents (ISIs).

(f) Proper procedures for obtaining authorized access to information technology (IT) systems.

(g) General IT security and protection training for all employees.

(h) Specialized IT security and protection training for IT security staff.

(i) Information Systems policy compliance requirements and procedures.

1752.224-74 – Information Security Incidents (Dec 2023)

(a) Information Security Incidents (ISI) Reporting Activities

(1) Contractors must report all ISI (as defined in NIST Special Publication SP.800-61, latest revision) involving OPM Information to the OPM Security Operations Center (SOC) at CyberSolutions@opm.gov, 844-377-6109. The SOC is available 24 hours per day, 365 days per year.

(2) Contractors must report all ISI involving information technology (IT) systems or Controlled Unclassified Information (CUI) immediately upon becoming aware of the ISI but no later than 30 minutes after becoming aware of the ISI, regardless of day or time; regardless of internal investigation, evaluation, or confirmation of procedures or activities; and regardless of whether the ISI is suspected, known, or determined to involve IT systems operated in support of this contract.

mailto:CyberSolutions@opm.gov

(3) Contractors reporting an ISI to the SOC by email or phone must copy the Contracting Officer (CO) or Contracting Officer’s Representative (COR) if possible; but if not, must notify the CO or COR immediately after reporting to the SOC.

(4) When reporting an ISI to the SOC by email:

(i) Do not include any CUI in the subject or body of any email;

(ii) Use FIP-140-3. 3,4 compliant encryption methods to protect CUI to be included as an email attachment, and do not include passwords in the same email as the encrypted attachment; and

(iii) Provide any supplementary information or reports related to a previously reported incident directly to the OPM SOC with the following text in the subject line of the email:

“Supplementary Information / Report related to previously reported incident # [insert number].”

(b) ISI Review and Response Activities

(5) The Contractor must provide OPM, or its designate, full access and cooperation for all activities determined by CO or COR to be required to perform inspection and forensic analysis in the event of an ISI.

(6) The Contractor must promptly respond to all requests by the CO or COR for ISI and system-related information, including but not limited to disk images, log files, event information, and any other information determined by OPM to be required for a rapid but comprehensive technical and forensic review.

(7) OPM, at its sole discretion, may obtain the assistance of Federal agencies and/or third-party firms to aid in ISI Review and Response activities.

(c) ISI Determination Activities

(8) The Contractor must not make any determinations related to an ISI associated with

Information Systems or Information maintained by the Contractor in support of the activities authorized by this contract, including determinations related to notification of affected individuals and/or Federal agencies (except reporting criminal activity to Law Enforcement Organizations) and offering of services, such as credit monitoring.

(9) The Contractor must not conduct any internal ISI-related review or response activities that could modify or eliminate any existing technical configuration or information or forensic technical evidence existing at the time of the ISI without approval from the OPM Chief Information Officer (CIO) through the CO or COR.

(10) All determinations related to an ISI associated with Information Systems or Information maintained by the Contractor in support of the activities authorized by this contract will be made only by the OPM CIO through the CO or COR.

(11) The Contractor must report criminal activity to Law Enforcement Organizations upon becoming aware of such activity.

1752.224-75 – Information Security Inspections (Dec 2023)

(a) The Chief Information Officer (CIO), through the Contracting Officer (CO) or Contracting Officer’s

Representative (COR), reserves the right to verify compliance with information security requirements established by this contract. Verification may include, but is not limited to, onsite or offsite inspections, documentation reviews, process observation, network and IT system scanning.

The Contractor will fully comply with all OPM-initiated inspections as permissible by law.

(b) The Contractor must permit and cooperate with any pre-scheduled onsite or offsite information security inspections, such as:

(1) Before initiation of the performance period;

(2) As periodically scheduled for contract oversight and compliance purposes;

(3) As determined by the OPM CIO through the CO or COR to be required for evaluation of or in response to any reported Information Security Incident (ISI); or

(4) As determined by the OPM CIO through the CO or COR to be required to address any risk of non-compliance with the requirements of this contract.

(c) OPM will provide the Contractor with a Post-Inspection Report, which will state findings and specify the Contractor’s requirement for remediating findings to maintain compliance with this contract.

(d) The Contractor must provide a formal response to the OPM Post-Inspection Report within fifteen

(15) days of receipt of the report for critical/high-risk findings and within thirty (30) days for all other findings.

1752.232-72 - Limitation of Government’s Obligation (May 2009)

(a) Contract line item(s) through are incrementally funded. For these item(s), the sum of

$ of the total price is presently available for payment and allotted to this contract. An allotment schedule is set forth in paragraph (j) of this clause.

(b) For item(s) identified in paragraph (a) of this clause, the Contractor agrees to perform up to the point at which the total amount payable by the Government, including reimbursement in the event of termination of those item(s) for the Government’s convenience, approximates the total amount currently allotted to the contract. The Contractor is not authorized to continue work on those item(s) beyond that point. The Government will not be obligated in any event to reimburse the Contractor in excess of the amount allotted to the contract for those item(s) regardless of anything to the contrary in the clause entitled “Termination for Convenience of the Government.” As used in this clause, the total amount payable by the Government in the event of termination of applicable contract line item(s) for convenience includes costs, profit, and estimated termination settlement costs for those item(s).

(c) Notwithstanding the dates specified in the allotment schedule in paragraph (j) of this clause, the Contractor will notify the Contracting Officer in writing at least thirty days prior to the date when, in the Contractor’s best judgment, the work will reach the point at which the total amount payable by the Government, including any cost for termination for convenience, will approximate 85 percent of the total amount then allotted to the contract for performance of the applicable item(s). The notification will state (1) the estimated date when that point will be reached and (2) an estimate of additional funding, if any, needed to continue performance of applicable line items up to the next scheduled date for allotment of funds identified in paragraph (j) of this clause, or to a mutually agreed upon substitute date. The notification will also advise the Contracting Officer of the estimated amount of additional funds that will be required for the timely performance of the item(s) funded pursuant to this clause, for a subsequent period as may be specified in the allotment schedule in paragraph (j) of this clause or otherwise agreed to by the parties. If after such notification additional funds are not allotted by the date identified in the Contractor’s notification, or by an agreed substitute date, the Contracting Officer will terminate any item(s) for which additional funds have not been allotted, pursuant to the clause of this contract entitled “Termination for Convenience of the Government.”

(d) When additional funds are allotted for continued performance of the contract line item(s) identified in paragraph (a) of this clause, the parties will agree as to the period of contract performance which will be covered by the funds. The provisions of paragraphs (b) through (d) of this clause will apply in like manner to the additional allotted funds and agreed substitute date, and the contract will be modified accordingly.

(e) If, solely by reason of failure of the Government to allot additional funds, by the dates indicated below, in amounts sufficient for timely performance of the contract line item(s) identified in paragraph (a) of this clause, the Contractor incurs additional costs or is delayed in the performance of the work under this contract and if additional funds are allotted, an equitable adjustment will be made in the price or prices (including appropriate target, billing, and ceiling prices where applicable) of the item(s), or in the time of delivery, or both. Failure to agree to any such equitable adjustment hereunder will be a dispute concerning a question of fact within the meaning of the clause entitled “Disputes.”

(f) The Government may at any time prior to termination allot additional funds for the performance of the contract line item(s) identified in paragraph (a) of this clause.

(g) The termination provisions of this clause do not limit the rights of the Government under the clause entitled “Default.” The provisions of this clause are limited to the work and allotment of funds for the contract line item(s) set forth in paragraph (a) of this clause. This clause no longer applies once the contract is fully funded except with regard to the rights or obligations of the parties concerning equitable adjustments negotiated under paragraphs (d) and (e) of this clause.

(h) Nothing in this clause affects the right of the Government to terminate this contract pursuant to the clause of this contract entitled “Termination for Convenience of the Government.”

(i) Nothing in this clause shall be construed as authorization of voluntary services whose acceptance is otherwise prohibited under 31 U.S.C. 1342.

(j) The parties contemplate that the Government will allot funds to this contract in accordance with the following schedule:

On execution of contract $

(month) (day), (year) $

1752.232-75 - Electronic Submission of Invoices (May 2021)

(a) The Office of Personnel Management (OPM) will only accept electronic invoices submitted through the Delphi eInvoicing system.

(b) Payment system registration. All persons accessing the Delphi eInvoicing web-portal shall have a unique user Delphi eInvoicing ID and be authenticated through login.gov.

(1) Vendors must provide opmisupplieraccess@opm.gov the full name, valid email address, and current phone number of users who require access to the Delphi eInvoicing web-portal for invoice submission and payment tracking purposes. Each email address must be unique for each user.

(2) To make changes to vendor users who will have access to the Delphi eInvoicing web-portal, the vendor must notify opmisupplieraccess@opm.gov and include the full name, valid email address, and current phone number of any new vendor users.

(3) Vendors are responsible to contact the Delphi Help Desk when their firm's points of contacts will no longer be submitting invoices so they can be removed from the system. Instructions for contacting the Delphi Help Desk can be found at http://einvoice.esc.gov.

(4) Designated vendor users will be notified via e-mail when the account is created. The vendor user will be provided detailed instructions for logging into their Delphi eInvoicing account.

(5) Electronic authentication. Click on the following link to create a login.gov account:

https://login.gov.

(6) To create a login.gov account, the user will need a valid email address and a working phone number. The user will create a password and establish a secondary authentication method to keep their account secure.

(c) Training on Delphi. To facilitate use of DELPHI, comprehensive user information is available at http://einvoice.esc.gov.

(d) The Delphi eInvoicing system is managed by the Enterprise Services Center (ESC). In order to receive payment and in accordance with the Prompt Payment Act, all invoices and required supporting documentation must be attached in the Delphi eInvoicing web-portal and must contain the information specified in the appropriate clause in the vendor’s contract, for example, FAR 52.212-4 or 52.232-25.

(e) If the contract includes allowances for travel on a reimbursable basis, all invoices for charges pertaining to travel expenses must catalog a breakdown of reimbursable expenses with the appropriate receipts to substantiate the travel expenses.

http://einvoice.esc.gov/ https://login.gov/

1752.233-70 - OPM Protest Procedures (Jul 2023)

(a) An interested party who files a protest with OPM has the option of requesting review and consideration of the protest by either the Contracting Officer (CO) or the Senior Procurement Executive (SPE). The protest must clearly indicate the official to whom it is directed.

(b) If the protest is directed to the SPE, a copy of the protest must be sent to the Head of the Contracting Activity at the same time the protest is filed with the CO in accordance with FAR 52.233-2. The address of the Head of the Contracting Activity is:

Head of the Contracting Activity, Office of Procurement Operations U.S. Office of Personnel Management 1900 E Street N.W., Room 1342 Washington, DC 20415

(c) Review and consideration of a protest by the SPE is an alternative to review and consideration by the

CO.

1752.239-70 – Internet Protocol Version 6 Compliance (Dec 2023)

All information technology (IT) functionality, capabilities, and features must be supported and operational in both a dual-stack Internet Protocol Version 4 IPv4 (IPV4)/ Internet Protocol Version 6 (IPv6) environment and an IPv6 only environment. Furthermore, all management, user interfaces, configuration options, reports, and other administrative capabilities that support IPv4 functionality will support comparable IPv6 functionality.

1752.239-71 – Access to OPM Information Technology Systems (Dec 2023)

(a) The Contractor must provide to the distribution list “System Access Control"

(systemaccesscontrol@opm.gov) an initial and complete list of Contractor employee names that require access to OPM Information Technology (IT) systems or OPM information in a Contractor IT system. This list will be provided at least five (5) days prior to required access.

(b) The Contractor must send a staffing change report by the fifth day of each month after contract award to the Contracting Officer (CO), Contracting Officer’s Representative (COR), and systemaccesscontrol@opm.gov. The report must contain the listing of all staff members who separated or were hired under this contract in the past 60 days and the location where each employee works. This form must be submitted even if no separations or hires have occurred during this period. Failure to submit a ‘Contractor Staffing Change Report’ each month may, at the Government’s discretion, result in the suspension of all accounts associated with this contract.

(c) Each Contractor employee is required to utilize a Personal Identity Verification (PIV) card to access OPM IT systems or Controlled Unclassified Information (CUI), in accordance with the National mailto:systemaccesscontrol@opm.gov mailto:systemaccesscontrol@opm.gov

Institutes of Standards and Technology (NIST) Federal Information Processing Standard (FIPS) 201.

Using shared accounts to access OPM IT systems and CUI is strictly prohibited. OPM will disable accounts, and access to OPM IT systems will be revoked and denied if Contractor employees share accounts. Users of the IT systems will be subject to periodic auditing to ensure compliance with OPM policies.

(d) Each Contractor employee is required to access OPM IT systems and CUI from the United States.

The Contractor must receive written approval from the Chief Information Security Officer (CISO) through the CO or COR to access OPM IT systems and CUI outside of the United States. The approval must be retained on record and date of approval included on the monthly staffing change report.

(e) Upon request of the CO or COR, the Contractor must immediately return all Government Information, as well as any media type that houses or stores Government Information, regardless of potential violations of other contracts the Contractor may have in place, including, but not limited to, data stored on recovery media, tape backups, and images.

(f) The CO, COR, and the OPM Helpdesk (helpdesk@opm.gov or 202-606-4927) must be notified at least five (5) days prior to a Contractor employee being removed from a contract. For unplanned terminations or removals of Contractor employees from the Contractor organization, the CO, COR and OPM Helpdesk must be notified immediately. OPM PIV cards issued to Contractor employees must be surrendered immediately upon termination by the Contractor employee, retained by the contractor upon separation and returned to the COR within two (2) days of departure of a Contractor employee.

1752.239-72 – Section 508 Standards (Dec 2023)

In accordance with Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) and FAR 39.2, unless an exception at FAR 39.204 or an exemption at FAR 39.205 applies, ICT supplies and services shall meet the applicable ICT accessibility standards at 36 CFR 1194.1.

1752.239-73 – Information System Security Requirements (Dec 2023)

(a) The activities required by this contract necessitate the Contractor’s access to Government

Information, including Controlled Unclassified Information (CUI). Contractors are required to comply with current Federal laws, Executive Orders, regulations, and guidance at time of award, including the Federal Information Security Modernization Act (FISMA); Privacy Act of 1974; E- Government Act of 2002, Section 208; NIST guidance; Federal Information Processing Standards (FIPS); and the Federal Information Technology Acquisition Reform Act (FITARA).

(b) The Contractor shall comply with implementation of required security controls for protection of the Government Information based on the sensitivity of the data within the system as outlined by Federal law and regulatory requirements, including but not limited to, Health Insurance Portability and Accountability Act (HIPAA), IRS 1075 for federal tax information, Executive Order 13556 for mailto:helpdesk@opm.gov

CUI, and any additional implementing regulatory requirements or guidance.

(c) The Contractor shall implement and maintain an information security program that is compliant with FISMA, NIST Special Publications, OMB guidelines, and OPM security policies.

(d) The Contractor facilities and IT systems shall meet the security requirements for the same impact level or greater as defined by the FIPS 199 as required for the protection of Government Information. The OPM Chief Information Officer, through the Contracting Officer or Contracting Officer’s Representative shall provide written approval of the FIPS 199 security categorization.

1752.239-74 – Security Assessment and Authorization (Dec 2023)

(a) This contract requires the Contractor to develop, deploy, and/or use information technology (IT) systems to access and/or store Government Information, including Controlled Unclassified Information (CUI).

(b) All IT systems that input, store, process, and/or output Government Information must be provided an Authority to Operate (ATO) signed by the OPM’s Chief Information Officer (CIO) or higher-level executive prior to operation of the IT system. The Contractor must complete the Security Assessment and Authorization (SA&A) process independently of OPM, including the selection and funding of an approved Federal Risk and Authorization Management Program (FedRAMP) Third- Party Assessor Organization (3PAO) or other approved independent assessor to validate the security and privacy controls in place for the systems and the overall accuracy of SA&A packages.

(c) The Contractor must submit to the OPM Chief Information Officer (CIO), through the Contracting Officer (CO) or Contracting Officer’s Representative (COR) the signed SA&A package, along with the security assessment report and supporting documentation such as system and configuration scans from an independent assessor at least sixty (60) days prior to operation of the IT system for review and authorization by the OPM Authorizing Officials (AOs), through the CO or COR. Should the AOs not consider the signed package to meet OPM SA&A requirements for any reason, the AOs retain the right to not issue an ATO for the system. Should the AOs consider it possible for the Contractor to improve the compliance of the A&A package, the CO or COR may provide general or detailed information to the Contractor for possible modification to the package to improve compliance and resubmission to the CO or COR after modification. The CO or COR reserves the right to limit the number of re-submissions of a modified package before a final determination that a resubmitted package will not receive an ATO and no further resubmissions will be accepted. This may be grounds for contract termination. The OPM CIO is the final authority on the compliance of a submitted package with OPM SA&A requirements.

(d) The Contractor Security Assessment and Authorization (SA&A) SA&A documentation package must be developed with the use of OPM Security Assessment and Authorization (SA&A) documentation templates in accordance with the OPM Security Assessment and Authorization policy based on the most current NIST Risk Management Framework (RMF), as adapted for Contractor IT systems supporting OPM. Templates are available for all required security documentation including, but not limited to, the System Security Plan, the Security Assessment Plan, the Security Assessment Report, Contingency Plan and Incident Response Plan. The SA&A process must be followed throughout the IT system lifecycle process to ensure proper oversight by OPM.

(e) The IT systems must meet the security requirements for the same impact level or greater as defined by the Federal Information Process Standard (FIPS) 199 for the Information being accessed. The OPM CIO, through the CO or COR, must provide written approval of the FIPS 199 security categorization.

(f) The Contractor shall complete a Privacy Threshold Analysis (PTA) for all systems as a requirement for an ATO. Based on the PTA, the OPM Chief Privacy Officer will determine whether a Privacy Impact Assessment (PIA) is required to be completed by the Contractor as part of the SA&A package.

(g) The Contractor must submit an updated SA&A package, along with the assessment report, and supporting documentation to the CO or COR at least 90 days before the expiration of an existing ATO for security review and verification of security controls. Security reviews may include onsite visits that involve physical or logical inspection of the Contractor environment and IT systems.

(h) The Contractor must ensure a plan of action and milestones (POA&M) is generated for each security finding and is remediated within a time frame commensurate with the level of risk, as follows, or as otherwise negotiated and approved in writing by the OPM CIO, through the CO or COR:

(1) Critical Risk = 15 days;

(2) High Risk = 30 days;

(3) Moderate Risk = 90 days;

(4) Low Risk = 120 days; and

(5) Very Low = 180 days.

(i) When utilizing cloud services, the Contractor must obtain an OPM ATO prior to initiation of operations even though a Cloud Service Provider (CSP) may have been granted a Provisional ATO by the FEDRAMP Program Management Office (PMO). OPM has a responsibility to assess CSP environments and control implementations against OPM’s requirements to ensure that sufficient controls are implemented so that the confidentiality, integrity, and availability of OPM's information and information systems hosted in the CSP environment is assured in a manner that incorporates review of all the documentation relied on for issuance of an ATO. FedRAMP provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services. An AO can leverage ATO documentation from the FedRAMP PMO or other federal agency, to support an authorization decision, but it is not a substitute for an explicit authorization decision by an AO within OPM. All FedRAMP authorization packages are required to be reviewed and approved by OPM’s Chief Information Security Officer (CISO) prior to connecting the system to OPM’s network.

1752.239-75 – Cloud Computing (Dec 2023)

(a) Prior to using any cloud service provided by a commercial Cloud Service Provider (CSP), the

Contractor must obtain approval from the Chief Technology Officer (CTO), through the Contracting Officer (CO) or Contracting Officer’s Representative (COR), that the use of that cloud service has been authorized by the Chief Information Officer (CIO). To request approval submit a request to OCIO-ITContractSupport@opm.gov.

(b) Information stored in a cloud environment remains the sole property of OPM, not the Contractor or the CSP. OPM will retain unrestricted rights and access to all federally owned and/or federally managed data, schemas, metadata, and other artifacts that OPM either owns or manages that is handled under this contract, which may be required to ensure OPM can fully retrieve OPM information from the CSP. Specifically, OPM retains ownership of any user created/loaded data and applications collected, maintained, used, or operated on behalf of OPM and hosted on Contractor’s infrastructure, as well as maintains the right to request full copies of these at any time. If requested, data shall be available to OPM within one (1) business day from request date or within the timeframe specified otherwise. In addition, the data shall be provided at no additional cost to OPM.

(c) The CSP must meet all cybersecurity requirements levied in this contract, unless waived in writing by the OPM CIO, through the CO or COR. If Contractor must remove any information from the primary work area, they shall protect it to the same extent they would the proprietary data and/or company trade secrets and in accordance with OPM policies. The Contractor shall ensure that the facilities that house the network infrastructure are physically and logically secure in accordance with FedRAMP requirements and OPM policies.

(d) The disposition of all OPM data shall be at the written direction of OPM. This may include documents returned to OPM control; destroyed; or held as specified until otherwise directed.

Physical items returned to the Government shall be hand carried or sent by certified mail to the CO or COR.

(e) The CSP, and any subcontractor or teaming partner CSPs, must be evaluated by a Federal Risk and Authorization Management Program (FedRAMP) Third Party Assessment Organization (3PAO) or other CIO authorized and approved independent assessor. However, it is highly recommended that a FedRAMP authorized 3PAO be retained. The Contractor is responsible for the selection and funding of the 3PAO or independent assessor. The most current, and any subsequent, security assessment reports must be made available to the CIO, through the CO or COR, for consideration, including the CSP’s Systems Security Plan, as part of the Contractor’s Systems Security Plan.

(f) If any other approved independent assessor is authorized for use, the assessor must meet all of the following requirements:

(1) Is competent to perform inspections of CSP documents and technical system elements.

(2) Has a documented, fully operational, and adequately maintained Quality Management System

(QMS) that meets the standards of ISO/IEC 17020 (as revised).

(3) Is operating in accordance with its QMS.

(4) Demonstrates technical competence of individual assessors through education, training, technical knowledge, skills, and experience.

(5) Must be independent from the CSP.

(6) Is either a Type A or Type C inspection body.

(7) Demonstrate knowledge of Federal Information Security Management Act (FISMA), National

Institute of Standards and Technology (NIST), and FedRAMP-specific requirements.

1752.239-76 – Information Technology Awareness Training (Dec 2023)

(a) The Contractor must ensure that all Contractor employees complete OPM-provided mandatory security and privacy training prior to gaining access to OPM Information Technology (IT) systems and periodically thereafter based on OPM policy requirements. OPM will provide notification and instructions for completing this training. Non-compliance shall result in revocation of system access.

(b) With written permission and justification from the Chief Information Officer, through the Contracting Officer or Contracting Officer’s Representative (COR), in lieu of the OPM-provided training, the Contractor may provide its own continuous training and awareness for Contract employees. All costs and resource allocations required must be the sole responsibility of the Contractor. Evidence of training for Contractor employees shall be provided to OPM via email to the COR.

(c) All Contractors accessing OPM’s system and associated data shall sign the OPM Rules of Behavior (provided upon award) prior to gaining access to OPM IT systems and periodically thereafter based on OPM policy requirements.

1752.239-77 – Configuration Baseline (Dec 2023)

(a) The Contractor must certify applications are fully functional and operate correctly as intended on systems using the United States Government Configuration Baseline (USGCB), Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs), Center for Information Security (CIS) Security Benchmarks, or any other OPM-identified configuration baseline.

(b) The standard installation, operation, maintenance, updates, and/or patching of software must not alter the configuration settings from an approved OPM defined configuration baseline.

(c) Applications designed for normal end users must run in the standard user context without elevated system administration privileges.

(d) The Contractor must apply due diligence at all times to ensure that the required level of security is always in place to protect OPM systems and information.

(e) The Office of the Chief Information Officer through the Contracting Officer (CO) or Contracting Officer’s Representative (COR) reserves the right to verify compliance.

1752.239-78 – Data Protection Requirements (Dec 2023)

(a) All Controlled Unclassified Information (CUI) shall be encrypted in transit and at rest using Federal

Information Process Standard (FIPS) 140-3 and validated by the Cryptographic Module Validation Program (CMVP). Appropriate encryption will be employed for data in transit externally between server and client as well as data in transit internally between servers.

(b) Upon any changes to the cryptographic module, the Contractor shall provide the validation certificate number to the Contracting Officer or Contracting Officer’s Representative (COR) for verification.

(c) The Contractor shall redact or mask all CUI that is not essential to users, including privileged users.

1752.239-79 – Data Protection Requirements Certification (Dec 2023)

Offerors must include in their offer/quotation the validation certificate number for any cryptographic modules.

1752.239-80 – Security Monitoring and Alerting Requirements (Dec 2023)

(a) Security-related event auditing capabilities shall be employed throughout the protocol stack and on all components of the Contractor’s solution. Event logging shall ensure event visibility, consistent with the OMB M-21-31 or successor directive, at the following levels:

(1) Edge

(2) Server / Host

(3) Workstation / Laptop / Client

(4) Network

(5) Application

(6) Database

(7) Storage

(8) User

(b) The Contractor’s solution shall have the ability to alert the OPM in the event of an audit event processing failure and take one of the following actions: shut down information system, overwrite oldest audit records, or stop generating audit records.

(c) The Contractor’s solution shall be designed to produce audit event records that contain sufficient detail to establish what events occurred, the sources of the events, the outcomes of the events, and the time stamps when the activities occurred. Minimum requirements include successful and unsuccessful logon events, account management events, policy changes, privilege functions, process tracking, and system events; web applications should log all admin activity, authentication checks, data deletions, data access, data changes, and permission changes.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .