Bread.pdf
PDF 426 KB Posted
- Attached to
- Bread Items for USP Lee Qtr 4 Federal contract opportunity
- Solicitation number
- 15B11725Q00000014
About this file
This document is a Request for Quote (RFQ) for bread items issued by the Federal Bureau of Prisons for United States Penitentiary (USP) Lee in Pennington Gap, Virginia. The solicitation seeks whole wheat bread products, including whole wheat bread loaves, hamburger buns, and hot dog buns, to be delivered weekly from July 1, 2025 to September 30, 2025. The total quantities include 15,504 loaves of whole wheat bread, 69,800 hamburger buns, and 27,648 hot dog buns, with specific delivery requirements that fresh bread must be delivered within 48 hours after baking.
The solicitation is set aside 100% for small businesses and uses the North American Industry Classification System (NAICS) code 311999 with a size standard of 700 employees. The evaluation factors include past performance, technical capability of the items, and price. The offer due date is June 27, 2025 at 12:00 ET, with the solicitation issued on June 17, 2025. Potential offerors must be registered in the System for Award Management (SAM) and comply with various federal contracting representations and certifications, including provisions related to privacy, cybersecurity, and other standard government contract requirements.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ letter for Bread items.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
15B11725Q00000014 Page 1 of 32
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 AND 30.
1. REQUISITION NUMBER
15B11725PR000150
PAGE 1 OF
5. SOLICITATION NUMBER
15B11725Q00000014
2. CONTRACT NUMBER 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 6. SOLICITATION ISSUE
DATE
06/17/2025
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
J. Shuler j1shuler@bop.gov
b. TELEPHONE NUMBER (No collect calls)
2765460150
8. OFFER DUE DATE / LOCAL
TIME
06/27/2025 12:00 ET
CODE 15B117
Federal Bureau of Prisons
USP Lee
Lee County Industrial Park/Hickory Flats Road
Pennington Gap, VA 24277
9. ISSUED BY UNRESTRICTED OR X SET ASIDE:100.00 % FOR
X SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
(SDVOSB)
WOMEN-OWNED SMALL
BUSINESS (WOSB)
ECONOMICALLY DISADVANTAGED
WOMEN-OWNED SMALL BUSINESS
(EDWOSB)
8(A)
NORTH AMERICAN
INDUSTRY CLASSIFICATION
STANDARD (NAICS):
311999
SIZE STANDARD:
700 Employees
10. THE ACQUISITION IS
SEE SCHEDULE
11. DELIVERY FOR FREE ON BOARD
(FOB) DESTINATION UNLESS
BLOCK IS MARKED
NET 30
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER THE
DEFENSE PRIORITIES AND
ALLOCATIONS SYSTEM -
DPAS (15 CFR 700)
13b. RATING
X REQUEST
FOR QUOTE
(RFQ)
INVITATION
FOR BID
(IFB)
REQUEST
FOR
PROPOSAL
(RFP)
14. METHOD OF SOLICITATION
CODE15. DELIVER TO
SEE SCHEDULE
CODE16. ADMINISTERED BY
FACILITY
CODE
CODE
TELEPHONE NUMBER
17a. CONTRACTOR/
OFFEROR
15B117CODE18a. PAYMENT WILL BE MADE BY
Federal Bureau of Prisons USP Lee Lee County Industrial Park/Hickory Flats Road Pennington Gap, VA 24277
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER SEE ADDENDUM
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
19.
ITEM NUMBER
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
Bread Items for USP Lee for July 1, 2025 - September 30, Weekly delivers determined by the Food Service Administrator
UEID#__________________
Email____________________ Telephone#_____________ Firm Fixed Price
See Continuation Sheet(s) (Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)
X 27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4. FAR 52.212-3
AND 52.212-5 ARE ATTACHED. ADDENDA
ARE X ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN ____ COPIES TO
ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH
OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE
TERMS AND CONDITIONS SPECIFIED.
29. AWARD OF CONTRACT: REFERENCE _____________________________
OFFER DATED _________________ . YOUR OFFER ON SOLICITATION (BLOCK
5) INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH
HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED 31b. NAME OF THE CONTRACTING OFFICER (Type or print)
Jason Shuler
31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 11/2021)
Prescribed by GSA - FAR (48 CFR) 53.212
15B11725Q00000014 Page 2 of 32
19.
ITEM NUMBER
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: _________________________________
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
PARTIAL FINAL
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
COMPLETE PARTIAL FINAL
36. PAYMENT 37. CHECK NUMBER
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 11/2021) BACK
15B11725Q00000014 Page 3 of 32
Table of Contents
Section Description Page Number
Solicitation/Contract Form 1 Commodity or Services Schedule 2 Contract Clauses
52.204-27 Prohibition on a ByteDance Covered Application (Jun 2023) DOJ-02 Contractor Privacy Requirements (JAN 2022)
3 List of Attachments 4 Solicitation Provisions
52.212-1 Instructions to Offerors-Commercial Products and Commercial Services (Sep 2023) 52.204-7 System for Award Management (Nov 2024) 52.204-16 Commercial and Government Entity Code Reporting (Aug 2020) 52.212-2 Evaluation-Commercial Products and Commercial Services (Nov 2021) 52.212-3 Offeror Representations and Certifications-Commercial Products and Commercial Services (May 2024)
15B11725Q00000014 Page 4 of 32
Section 1 - Commodity or Services Schedule
SCHEDULE OF SUPPLIES/SERVICES
CONTINUATION SHEET
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 Whole Wheat Bread, Fresh, Loaf
PSC: 8920
Delivery Schedule:
Delivery Description:
Delivery Number: 1 Delivery Required On: 07/01/2025 Quantity: 15,504.000000
Delivery Address: Federal Bureau of Prisons USP Lee Lee County Industrial Park/Hickory Flats Road Pennington Gap, VA 24277
Brandon Miller 2765460150 b7miller@bop.gov
15,504 EA $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0002 Whole Wheat Hamburger Buns, Fresh, Each
Bread, Roll, Enriched, Sandwich (Hamburger), Whole Wheat, Part Whole Wheat, or Multigrain, Pan Baked, Sliced, Fresh, Seedless.
(CID A-A-20053C, Type I, Class of Roll C, Style of Roll 2, 3, or 4, Bake Type a, Slice Type i, Product State a, Seed type I, Agricultural practice (i)). Fresh bread shall be delivered within 48 hours after baking. State type and package size on bid.
PSC: 8920
Delivery Schedule:
Delivery Description:
Delivery Number: 1 Delivery Required On: 07/01/2025 Quantity: 69,800.000000
Delivery Address: Federal Bureau of Prisons USP Lee Lee County Industrial Park/Hickory Flats Road Pennington Gap, VA 24277
Brandon Miller 2765460150 b7miller@bop.gov
69,800 EA $________ $_________________
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0003 Whole Wheat Hot Dog Buns, Fresh, Each
Bread, Roll, Enriched, Finger (Hot Dog), Wheat, Pan Baked, Sliced, Fresh, Seedless. (CID A-A-20053C, Type I, Class of Roll D, Style of Roll 3, Bake Type a, Slice Type i, Product State a, Seed type I, Agricultural practice (i)). Fresh bread shall be delivered within 48 hours after baking. State package size on bid.
PSC: 8920
Delivery Schedule:
Delivery Description:
Delivery Number: 1 Delivery Required On: 07/01/2025 Quantity: 27,648.000000
Delivery Address: Federal Bureau of Prisons USP Lee Lee County Industrial Park/Hickory Flats Road Pennington Gap, VA 24277
Brandon Miller
27,648 EA $________ $_________________
15B11725Q00000014 Page 5 of 32
2765460150 b7miller@bop.gov
Evaluation Factors
1) Past Performance 2)Technical Capability of the Item
3) Price
15B11725Q00000014 Page 6 of 32
Section 2 - Contract Clauses
Clauses By Full Text
52.204-27 Prohibition on a ByteDance Covered Application (Jun 2023)
(a) Definitions. As used in this clause--
Covered application means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.
Information technology, as defined in 40 U.S.C. 11101(6)--
(1) Means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use--
(i) Of that equipment; or
(ii) Of that equipment to a significant extent in the performance of a service or the furnishing of a product;
(2) Includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but
(3) Does not include any equipment acquired by a Federal contractor incidental to a Federal contract.
(b) Prohibition. Section 102 of Division R of the Consolidated Appropriations Act, 2023 (Pub. L. 117-328), the No TikTok on Government Devices Act, and its implementing guidance under Office of Management and Budget (OMB) Memorandum M-23-13, dated February 27, 2023, "No TikTok on Government Devices" Implementation Guidance, collectively prohibit the presence or use of a covered application on executive agency information technology, including certain equipment used by Federal contractors. The Contractor is prohibited from having or using a covered application on any information technology owned or managed by the Government, or on any information technology used or provided by the Contractor under this contract, including equipment provided by the Contractor's employees; however, this prohibition does not apply if the Contracting Officer provides written notification to the Contractor that an exception has been granted in accordance with OMB Memorandum M-23-13.
(c) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (c), in all subcontracts, including subcontracts for the acquisition of commercial products or commercial services.
(End of clause)
DOJ-02 Contractor Privacy Requirements (JAN 2022)
A. Limiting Access to Privacy Act and Other Sensitive Information
(1) Privacy Act Information
In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by
15B11725Q00000014 Page 7 of 32 other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.
(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment
Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.
(3) Prior Approval Required to Hire Subcontractors
The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.
(4) Separation Checklist for Contractor Employees
The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.
In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).
Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.
B. Privacy Training, Safeguarding, and Remediation
(1) Required Security and Privacy Training for Contractors
The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj.
The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and
15B11725Q00000014 Page 8 of 32 agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.
The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.
(2) Safeguarding PII Requirements
Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.
(3) Non-Disclosure Agreement Requirement
Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:
(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and
(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.
The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.
(4) Prohibition on Use of PII in Vendor Billing and Administrative Records
The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.
(5) Reporting Actual or Suspected Data Breach
Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose.
The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.
(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting and Response Procedures for a Breach of Personally Identifiable Information.
(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and the Contracting Officer within one (1) hour of the initial discovery.
15B11725Q00000014 Page 9 of 32
(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:
(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6] Date, time, and location of the incident.
(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.
(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]
(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.
(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]
(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.
(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.
(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.
(6) Victim Remediation
At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach.
The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.
C. Government Records Training, Ownership, and Management
(1) Records Management Training and Compliance
(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR.
This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.
(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.
(2) Records Creation, Ownership, and Disposition
(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information.
15B11725Q00000014 Page 10 of 32
The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.
(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.
(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.
D. Data Privacy and Oversight
(1) Restrictions on Testing or Training Using Real Data Containing PII
The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.
(2) Requirements for Contractor IT Systems Hosting Government Data
The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.
(3) Requirement to Support Privacy Compliance
(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.
(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion.
The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government
15B11725Q00000014 Page 11 of 32
Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.
[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).
[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.
[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.
[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”
[5] https://www.justice.gov/file/4336/download [6] As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used; extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.
[7] As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.
[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.
[9] As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.
[10] In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of information) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.
(End of Clause)
15B11725Q00000014 Page 12 of 32
Section 3 - List of Attachments
This Section Is Intentionally Left Blank
15B11725Q00000014 Page 13 of 32
Section 4 - Solicitation Provisions
52.212-1 Instructions to Offerors-Commercial Products and Commercial Services (Sep 2023)
(a) North American Industry Classification System (NAICS) code and small business size standard. The NAICS code(s) and small business size standard(s) for this acquisition appear elsewhere in the solicitation. However, the small business size standard for a concern that submits an offer, other than on a construction or service acquisition, but proposes to furnish an end item that it did not itself manufacture, process, or produce is 500 employees, or 150 employees for information technology value-added resellers under NAICS code 541519, if the acquisition--
(1) Is set aside for small business and has a value above the simplified acquisition threshold;
(2) Uses the HUBZone price evaluation preference regardless of dollar value, unless the offeror waives the price evaluation preference; or
(3) Is an 8(a), HUBZone, service-disabled veteran-owned, economically disadvantaged women-owned, or women-owned small business set-aside or sole-source award regardless of dollar value.
(b) Submission of offers. Submit signed and dated offers to the office specified in this solicitation at or before the exact time specified in this solicitation. Offers may be submitted on the SF 1449, letterhead stationery, or as otherwise specified in the solicitation. As a minimum, offers must show--
(1) The solicitation number;
(2) The time specified in the solicitation for receipt of offers;
(3) The name, address, and telephone number of the offeror;
(4) A technical description of the items being offered in sufficient detail to evaluate compliance with the requirements in the solicitation. This may include product literature, or other documents, if necessary;
(5) Terms of any express warranty;
(6) Price and any discount terms;
(7) "Remit to" address, if different than mailing address;
(8) A completed copy of the representations and certifications at Federal Acquisition Regulation (FAR) 52.212-3 (see FAR 52.212-3(b) for those representations and certifications that the offeror shall complete electronically);
(9) Acknowledgment of Solicitation Amendments;
(10) Past performance information, when included as an evaluation factor, to include recent and relevant contracts for the same or similar items and other references (including contract numbers, points of contact with telephone numbers and other relevant information); and
(11) If the offer is not submitted on the SF 1449, include a statement specifying the extent of agreement with all terms, conditions, and provisions included in the solicitation. Offers that fail to furnish required representations or information, or reject the terms and conditions of the solicitation may be excluded from consideration.
(c) Period for acceptance of offers. The offeror agrees to hold the prices in its offer firm for 30 calendar days from the date specified for receipt of offers, unless another time period is specified in an addendum to the solicitation.
(d) Product samples. When required by the solicitation, product samples shall be submitted at or prior to the time specified for receipt of offers. Unless otherwise specified in this solicitation, these samples shall be submitted at no expense to the Government, and returned at the sender's request and expense, unless they are destroyed during preaward testing.
15B11725Q00000014 Page 14 of 32
(e) Multiple offers. Offerors are encouraged to submit multiple offers presenting alternative terms and conditions, including alternative line items (provided that the alternative line items are consistent with FAR subpart 4.10), or alternative commercial products or commercial services for satisfying the requirements of this solicitation. Each offer submitted will be evaluated separately.
(f) Late submissions, modifications, revisions, and withdrawals of offers.
(1) Offerors are responsible for submitting offers, and any modifications, revisions, or withdrawals, so as to reach the Government office designated in the solicitation by the time specified in the solicitation. If no time is specified in the solicitation, the time for receipt is 4:30 p.m., local time, for the designated Government office on the date that offers or revisions are due.
(2)(i) Any offer, modification, revision, or withdrawal of an offer received at the Government office designated in the solicitation after the exact time specified for receipt of offers is "late" and will not be considered unless it is received before award is made, the Contracting Officer determines that accepting the late offer would not unduly delay the acquisition;
and--
(A) If it was transmitted through an electronic commerce method authorized by the solicitation, it was received at the initial point of entry to the Government infrastructure not later than 5:00 p.m. one working day prior to the date specified for receipt of offers; or
(B) There is acceptable evidence to establish that it was received at the Government installation designated for receipt of offers and was under the Government's control prior to the time set for receipt of offers; or
(C) If this solicitation is a request for proposals, it was the only proposal received.
(ii) However, a late modification of an otherwise successful offer, that makes its terms more favorable to the Government, will be considered at any time it is received and may be accepted.
(3) Acceptable evidence to establish the time of receipt at the Government installation includes the time/date stamp of that installation on the offer wrapper, other documentary evidence of receipt maintained by the installation, or oral testimony or statements of Government personnel.
(4) If an emergency or unanticipated event interrupts normal Government processes so that offers cannot be received at the Government office designated for receipt of offers by the exact time specified in the solicitation, and urgent Government requirements preclude amendment of the solicitation or other notice of an extension of the closing date, the time specified for receipt of offers will be deemed to be extended to the same time of day specified in the solicitation on the first work day on which normal Government processes resume.
(5) Offers may be withdrawn by written notice received at any time before the exact time set for receipt of offers. Oral offers in response to oral solicitations may be withdrawn orally. If the solicitation authorizes facsimile offers, offers may be withdrawn via facsimile received at any time before the exact time set for receipt of offers, subject to the conditions specified in the solicitation concerning facsimile offers. An offer may be withdrawn in person by an offeror or its authorized representative if, before the exact time set for receipt of offers, the identity of the person requesting withdrawal is established and the person signs a receipt for the offer.
(g) Contract award (not applicable to Invitation for Bids). The Government intends to evaluate offers and award a contract without discussions with offerors. Therefore, the offeror's initial offer should contain the offeror's best terms from a price and technical standpoint. However, the Government reserves the right to conduct discussions if later determined by the Contracting Officer to be necessary. The Government may reject any or all offers if such action is in the public interest;
accept other than the lowest offer; and waive informalities and minor irregularities in offers received.
(h) Multiple awards. The Government may accept any item or group of items of an offer, unless the offeror qualifies the offer by specific limitations. Unless otherwise provided in the Schedule, offers may not be submitted for quantities less than those specified. The Government reserves the right to make an award on any item for a quantity less than the quantity offered, at the unit prices offered, unless the offeror specifies otherwise in the offer.
(i) Availability of requirements documents cited in the solicitation.
15B11725Q00000014 Page 15 of 32
(1)(i) The GSA Index of Federal Specifications, Standards and Commercial Item Descriptions, FPMR Part 101-29, and copies of Federal specifications, standards, and product descriptions can be downloaded from the ASSIST website at https://assist.dla.mil.
(ii) If the General Services Administration, Department of Agriculture, or Department of Veterans Affairs issued this solicitation, a copy of specifications, standards, and commercial item descriptions cited in this solicitation may be obtained from the address in paragraph (i)(1)(i) of this provision.
(2) Most unclassified Defense specifications and standards may be downloaded from the ASSIST website at https:// assist.dla.mil.
(3) Defense documents not available from the ASSIST website may be requested from the Defense Standardization Program Office by--
(i) Using the ASSIST feedback module (https://assist.dla.mil/feedback); or
(ii) Contacting the Defense Standardization Program Office by telephone at 571-767-6688 or email at assisthelp@dla.mil.
(4) Nongovernment (voluntary) standards must be obtained from the organization responsible for their preparation, publication, or maintenance.
(j) Unique entity identifier. (Applies to all offers that exceed the micro-purchase threshold, and offers at or below the micro-purchase threshold if the solicitation requires the Contractor to be registered in the System for Award Management (SAM).) The Offeror shall enter, in the block with its name and address on the cover page of its offer, the annotation "Unique Entity Identifier" followed by the unique entity identifier that identifies the Offeror's name and address. The Offeror also shall enter its Electronic Funds Transfer (EFT) indicator, if applicable. The EFT indicator is a four-character suffix to the unique entity identifier. The suffix is assigned at the discretion of the Offeror to establish additional SAM records for identifying alternative EFT accounts (see FAR subpart 32.11) for the same entity. If the Offeror does not have a unique entity identifier, it should contact the entity designated at www.sam.gov for unique entity identifier establishment directly to obtain one. The Offeror should indicate that it is an offeror for a Government contract when contacting the entity designated at www.sam.gov for establishing the unique entity identifier.
(k) [Reserved].
(l) Debriefing. If a post-award debriefing is given to requesting offerors, the Government shall disclose the following information, if applicable:
(1) The agency's evaluation of the significant weak or deficient factors in the debriefed offeror's offer.
(2) The overall evaluated cost or price and technical rating of the successful and the debriefed offeror and past performance information on the debriefed offeror.
(3) The overall ranking of all offerors, when any ranking was developed by the agency during source selection.
(4) A summary of the rationale for award;
(5) For acquisitions of commercial products, the make and model of the product to be delivered by the successful offeror.
(6) Reasonable responses to relevant questions posed by the debriefed offeror as to whether source-selection procedures set forth in the solicitation, applicable regulations, and other applicable authorities were followed by the agency.
(End of provision)
A.2 ADDENDUM TO FAR 52.212-1, Instructions to Offerors-Commercial Products and Commercial Services (Sep 2023)
15B11725Q00000014 Page 16 of 32
The terms and conditions for the following provisions are hereby incorporated into this solicitation as an addendum to FAR provision 52.212-1.
Provisions By Full Text
52.204-7 System for Award Management (Nov 2024)
(a) Definitions. As used in this provision--
"Electronic Funds Transfer (EFT) indicator" means a four-character suffix to the unique entity identifier. The suffix is assigned at the discretion of the commercial, nonprofit, or Government entity to establish additional System for Award Management records for identifying alternative EFT accounts (see subpart 32.11) for the same entity.
"Registered in the System for Award Management (SAM)" means that--
(1) The Offeror has entered all mandatory information, including the unique entity identifier and the EFT indicator, if applicable, the Commercial and Government Entity (CAGE) code, as well as data required by the Federal Funding Accountability and Transparency Act of 2006 (see subpart 4.14) into SAM;
(2) The offeror has completed the Core, Assertions, and Representations and Certifications, and Points of Contact sections of the registration in SAM;
(3) The Government has validated all mandatory data fields, to include validation of the Taxpayer Identification Number (TIN) with the Internal Revenue Service (IRS). The offeror will be required to provide consent for TIN validation to the Government as a part of the SAM registration process; and
(4) The Government has marked the record "Active".
"Unique entity identifier" means a number or other identifier used to identify a specific commercial, nonprofit, or Government entity. See www.sam.gov for the designated entity for establishing unique entity identifiers.
(b)(1) An Offeror is required to be registered in SAM when submitting an offer or quotation and at time of award (see FAR clause 52.204-13, System for Award Management Maintenance, for the requirement to maintain SAM registration during performance and through final payment).
(2) The Offeror shall enter, in the block with its name and address on the cover page of its offer, the annotation "Unique Entity Identifier" followed by the unique entity identifier that identifies the Offeror's name and address exactly as stated in the offer. The Offeror also shall enter its EFT indicator, if applicable. The unique entity identifier will be used by the Contracting Officer to verify that the Offeror is registered in the SAM.
(c) If the Offeror does not have a unique entity identifier, it should contact the entity designated at www.sam.gov for establishment of the unique entity identifier directly to obtain one. The Offeror should be prepared to provide the following information:
(1) Company legal business name.
(2) Tradestyle, doing business, or other name by which your entity is commonly recognized.
(3) Company physical street address, city, state, and Zip Code.
(4) Company mailing address, city, state and Zip Code (if separate from physical).
(5) Company telephone number.
(6) Date the company was started.
15B11725Q00000014 Page 17 of 32
(7) Number of employees at your location.
(8) Chief executive officer/key manager.
(9) Line of business (industry).
(10) Company headquarters name and address (reporting relationship within your entity).
(d) Processing time should be taken into consideration when registering. Offerors who are not registered in SAM should consider applying for registration immediately upon receipt of this solicitation. See https://www.sam.gov for information on registration.
(End of provision)
52.204-16 Commercial and Government Entity Code Reporting (Aug 2020)
(a) Definition. As used in this provision--
"Commercial and Government Entity (CAGE) code" means--
(1) An identifier assigned to entities located in the United States or its outlying areas by the Defense Logistics Agency (DLA) Commercial and Government Entity (CAGE) Branch to identify a commercial or government entity by unique location; or
(2) An identifier assigned by a member of the North Atlantic Treaty Organization (NATO) or by the NATO Support and Procurement Agency (NSPA) to entities located outside the United States and its outlying areas that the DLA Commercial and Government Entity (CAGE) Branch records and maintains in the CAGE master file. This type of code is known as a NATO CAGE (NCAGE) code.
(b) The Offeror shall provide its CAGE code with its offer with its name and location address or otherwise include it prominently in its proposal. The CAGE code must be for that name and location address. Insert the word "CAGE" before the number. The CAGE code is required prior to award.
(c) CAGE codes may be obtained via--
(1) Registration in the System for Award Management (SAM) at www.sam.gov. If the Offeror is located in the United States or its outlying areas and does not already have a CAGE code assigned, the DLA Commercial…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .