CFPB RFQ_9531CB25Q0005 v1.pdf

PDF 590 KB Posted

Attached to
Remote User Testing Platform Federal contract opportunity
Solicitation number
9531CB25Q0005
Issued by
Consumer Financial Protection Bureau

About this file

This is a Request for Quotation (RFQ) issued by the Consumer Financial Protection Bureau (CFPB) seeking a Software as a Service (SaaS) remote user testing platform. The RFQ specifies requirements for a platform that enables both moderated and unmoderated usability testing, with annual testing volumes of approximately 30 moderated studies (190 participants) and 30 unmoderated studies (210 participants) sourced by vendor panel, plus 10 moderated and 10 unmoderated studies (60 participants each) sourced by CFPB.

The contract will be awarded as a single firm-fixed-price purchase order using Lowest Price Technically Acceptable (LPTA) procedures, with a base year and three option years for a total potential duration of 48 months. Key requirements include support for desktop and mobile testing, video recording capabilities, audio transcription, multilingual testing support (especially Spanish), and compliance with Section 508 accessibility standards. Quotes must be submitted to Michael.Villano@cfpb.gov by December 5, 2024 at 12:00pm ET, with questions due by December 2, 2024 at 11:00am ET. The contract period of performance begins December 16, 2024.

View the file

Other files for this federal contract opportunity

Other files attached to Remote User Testing Platform, newest first.
File Type Posted
Sole Source Justification- Userlytics - Redacted.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BUREAU OF CONSUMER FINANCIAL PROTECTION (BCFP), 1700 G STREET, NW WASHINGTON, DC 20552

CONSUMER FINANCIAL PROTECTION BUREAU (CFPB)

Date: November 25, 2024

To: Userlytics

Subject: Request for Quotation (RFQ) 9531CB25Q0005, Remote User Testing

Platform

Dear Userlytics:

The purpose of this Request for Quotation (RFQ) is to acquire a Remote User testing platform for the Consumer Financial Protection Bureau (CFPB or the Bureau). In accordance with the guidelines discussed below, CFPB requests that you provide a quote in response to this RFQ.

Detailed instructions for preparing and submitting a quote are contained in the RFQ, along with the criteria to be used by CFPB in evaluating quotes.

The following is the point of contact for this RFQ:

CFPB Contracting Officer:

MICHAEL VILLANO

OFFICE OF FINANCE & PROCUREMENT

BUREAU OF CONSUMER FINANCIAL PROTECTION

1700 G STREET, NW

WASHINGTON, DC 20552

E-mail Address: Michael.Villano@cfpb.gov

All responses to this request must be submitted via e-mail to Michael.Villano@cfpb.gov by no later than 12:00pm ET on December 05, 2024.

CFPB greatly appreciates your attention to this requirement.

Sincerely, /Signed/ Michael Villano Contracting Officer mailto:Michael.Villano@cfpb.gov mailto:Michael.Villano@cfpb.gov

9531CB25Q0005

Remote User Testing Platform

2 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

WASHINGTON, DC 20552

Request for Quotation (RFQ) No. 9531CB25Q0005 – Remote User Testing Platform

TABLE OF CONTENTS

SECTION I: STATEMENT OF REQUIREMENTS

SECTION II: SCHEDULE OF SERVICES AND PRICES

SECTION III: CONTRACT TERMS AND CONDITIONS AND PROVISIONS

SECTION IV: INSTRUCTIONS TO QUOTERS

3 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

SECTION I:

STATEMENT OF REQUIREMENTS

1.0 REQUIREMENTS

The Remote User Testing Platform must provide for all of the following:

• General access to the SaaS testing platform and all functionality (see functional requirements below)

• An account with seats for at least 12 researchers and an admin.

• Annual testing volume of at least:

Moderated Unmoderated Sourced by vendor panel

30 studies, approx.

190 participants

30 studies, approx.

210 participants

Sourced by CFPB 10 studies, approx.

60 participants

10 studies, approx.

60 participants o Estimates may be based on a general population profile with the understanding that should a given study have a narrow profile requiring special recruitment, the number of credits/tokens required per recruit would be higher.

o If Information Architecture (card sort, tree test) is priced separately, quote should include cost for at least 3 IA studies with at least 30 participants.

Functional Requirements:

Unmoderated Testing

The ability to run usability studies with participants in an asynchronous manner, without an interviewer or moderator present. Participant must be able to record themselves interacting with a prototype or website and speaking aloud throughout.

Moderated Testing The ability to run usability testing and interviews with a moderator present and asking questions. Additional testing staff able to listen in to the interview and take notes.

Open Participant Pool/Recruitment

Ability to schedule tests using either participants recruited by the CFPB (outside the tool) OR from vendor’s recruit pool. Participants recruited from vendor’s pool will receive incentives directly from the vendor.

4 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

Desktop/Mobile Testing Must be able to test both Desktop and Mobile applications, both through moderated and unmoderated testing methods.

Video Recording Must be able to record and save testing videos within the platform.

Audio Transcript Must be able to provide audio transcript of testing sessions.

Single Sign On compatible

Necessary to be able to meet CFPB requirements: Entra Id SSO OIDC is preferred but SAML is acceptable, prefer ability to enforce SSO-login only and/or ability to encrypt the SAML assertion.

Transparent pricing

Clear and accurate billing per test and recruits, accurately reflecting no-shows and used credits/costs. Clearly stated rules around how recruitment credits roll over from year to year.

Test storage Records of past tests and results archived within account for later access for a reasonable period of time.

Support participants who use assistive devices (and have such users in their testing pool)

Enable us to conduct accessibility usability testing via the tool to further support Section 508 requirements.

Ability to use opt-in screeners

For many studies, CFPB UX researchers use an “opt-in screener” to avoid collecting unnecessary PII. The tool needs to be able to show potential participants the opt-in statement and allow them to choose to participate in study from that point, without submitting further personal information.

Customer Service Reps Quality and transparent customer service representatives.

Support multilingual testing

Specifically Spanish-language testing, but ideally other languages as well to match all the CFPB’s supported non- English languages (Spanish, Chinese, Vietnamese, Korean, Tagalog, Russian, Arabic, Haitian Creole)

Information architecture and initial reaction testing Support tests such as tree tests, card sorts, first click.

Concurrent studies Ability to run more than one study at a time

5 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

Default ability to mix methods

Ability to use multiple test types in one session (first click along with talk-aloud task)

2.0 PERIOD OF PERFORMANCE

PERIOD OF PERFORMANCE

Base Year CLIN 0001 December 16, 2024 – December 15, 2025

Option Year 1 CLIN 1001 December 16, 2025 – December 15, 2026 Option Year 2 CLIN 2001 December 16, 2026 – December 15, 2027 Option Year 3 CLIN 3001 December 16, 2027 – December 15, 2028

3.0 DELIVERABLES

Delivery shall be made in accordance with best commercial practices.

6 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

SECTION II:

SCHEDULE OF SERVICES AND PRICES

Userlytics shall provide a firm fixed price in accordance with the Pricing Tables in Attachment I.

7 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

SECTION III:

CONTRACT ADMINISTRATION

TERMS AND CONDITIONS

1.0 CONTRACT CLAUSES AND PROVISIONS

1.1 HOURS OF OPERATION AND COVERAGE (SEPTEMBER 2018)

The contractor is responsible for conducting business between the hours of 8:30 a.m. and 5:00 p.m.

Eastern Time Mondays through Fridays, except Federal holidays (listed on the Office of Personnel Management’s (OPM) website at www.opm.gov) or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. However, certain contracts do require a 24/7 on-site operation schedule. The hours of operation are specifically stated in these contracts. For other than firm-fixed-price contracts, the Contractor will not be reimbursed when the Government facility is closed for the above reasons. The Contractor must maintain an adequate workforce for the uninterrupted performance of all tasks defined within the Statement of Work when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential. Under special circumstances in order to meet tight deadlines or deliverable schedules, contractors supporting other than firm-fixed-price contracts may be required to provide services outside the stated schedule, including weekends, Government observed holidays or Government directed closings. The Contracting Officer’s Representative (COR) must approve, in advance, any exceptions to services performed outside of the stated schedule.

2.0 BUREAU DELIVERIES (NOVEMBER 2021)

Deliveries to the Bureau via US Postal Service, or nation-wide delivery services such as Federal Express or United Parcel Service, courier or personal delivery should be shipped to 1700 G St., NW, Washington, DC 20552. The loading dock at 1700 G Street, NW is located on the back side of the building. Access to the loading dock is on F Street. The loading dock is restricted in size and delivery vehicles must be under 13 feet.

Deliveries must take place between the operating hours of 7:30 am and 4:30 pm local, Monday – Friday, unless otherwise approved and coordinated with a member of the Bureau’s Facilities Operations Management staff in advance of the delivery. All deliveries for the Bureau’s Technology & Innovation (T&I) division, consisting of laptops, printers, servers (or other high dollar items) may be received by CFPB personnel in Facilities but the official acceptance e.g.

verifying the contents of the shipment must be performed by a Government T&I employee. The loading dock personnel will notify the contact person when the truck arrives. All large deliveries require, at a minimum, one business day prior notification to a member of the Bureau’s Facilities

8 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

Operations Management Staff. Contact by email, cfpbfacilities@cfpb.gov (preferred) or by phone, 202-435-9390.

2.1 SECURITY REQUIREMENTS (MAY 2021)

Personnel Security To determine whether an individual is suitable to support the Bureau as a contractor personnel or subcontractor personnel, the contractor’s Project Manager (PM)/Point of Contact (POC), shall ensure that contractor personnel (includes subcontractor personnel) working under the contract meet the requirements defined within this clause.

a. Prior to performing any services under the contract, contractor personnel are required to pass an initial security check performed by the Bureau’s Personnel Security Office (PSO).

1. The steps required by contractor personnel for an initial security check are as follows:

a) Submits to the Contracting Officer Representative (COR) a completed Bureau provided Contractor Security Processing Packet (CSPP) which includes a Contractor Consumer/Credit Report Release form.

b) Provides fingerprints to the Bureau.

c) Complete an e-QIP application. (Upon receipt of the CSPP, PSO will provide the contractor instructions for completing the required questionnaire e.g., SF-85, SF-85P, OF- 306 in the e-QIP system).

b. If the PSO determines a contractor personnel successfully completed the initial security check and a full background investigation has been scheduled appropriate to the position sensitivity risk level (i.e., high, moderate or low) assigned by the Bureau, the COR will notify the contractor’s PM/POC of an approved Entry on Duty (EOD) date specific for each contractor personnel and specific to the base contract number. Contractor personnel shall not perform any work under the contract until receiving notice of an EOD date.

c. Following completion of the full background investigation the COR will notify the contractor’s PM/POC of the PSO final fitness determination. Contractor personnel providing support to the Bureau shall be United States citizens.

d. Any contractor personnel whose initial security check or full background investigation reveals derogatory information may be found unsuitable to provide support to the Bureau. The Bureau reserves the right to determine the suitability of each contractor personnel. If notification of a contractor personnel’s unfavorable suitability determination is provided, the contractor’s PM/POC shall immediately remove the impacted contractor personnel from the project.

e. Contractor personnel, including substitutions, are subject to the same investigation requirements throughout the contract’s period of performance.

f. Every five (5) years, contractor personnel are required to undergo a re-investigation which involves receiving an invite from the PSO to update their e-QIP application. The 5-year mark is https://sharepoint.cfpb.local/promgt/procure/eProcurement/_layouts/15/FormServer.aspx?XmlLocation=%2fpromgt%2fprocure%2feProcurement%2fePro%2fePRO-2022-14502.xml&ClientInstalled=false&DefaultItemOpen=1&Source=https%3a%2f%2fsharepoint.cfpb.local%2fpromgt%2fprocure%2feProcurement%2fePro%2fForms%2fPreAward%2520Actions%2520%2520Salinas.aspx

9 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

determined based on when a contractor personnel’s full background investigation was completed and includes cases when the Bureau accepts reciprocity from another federal agency.

Physical Security

a. All contractor personnel authorized to enter Bureau controlled space are subject to a security screening.

b. In accordance with Homeland Security Presidential Directive 12 (HSPD-12), Office of the Management and Budget (OMB) Memorandum M-19-17, and the CFPB Information System Security Policy, any contractor requiring routine physical access to a CFPB facility and/or routine access to a CFPB federally controlled information system will be required to obtain a CFPB issued Personal Identity Verification (PIV) card.

c. All contractor personnel when present in Bureau controlled space shall wear a badge provided by the Bureau or another accepted agency that is programmed for entry into Bureau controlled space. The badge shall be worn above the waist and be visible at all times while in Bureau controlled space. Bureau issued badges shall not be displayed in public.

d. Any badge, permanent or temporary, provided by the Bureau to a specific individual is non-transferable.

e. All contractor personnel shall abide by site applicable security regulations when at Bureau controlled space or when representing the Bureau in an official capacity at an off-site location.

f. Any badge provided to contractor personnel shall be returned to the COR at the point when the COR or the Contracting Officer determines it is no longer needed or to the Bureau’s Credentialing Center upon issuance of a new or updated Personnel Identity Verification (PIV) card. Any temporary badge (e.g., visitor) issued to contractor personnel shall be returned to the Security Officer at a Bureau entrance/exit location.

g. Contractor personnel shall report lost or stolen badges to the COR or Contracting Officer within 24 hours or the next business day, whichever is sooner.

h. The contractor’s PM/POC shall not conduct contractor personnel terminations or removals from a contract in Bureau controlled space.

Physical Safety (Mask-Wearing)

a. In accordance with Executive Order 13991, Protecting the Federal Workforce and Requiring Mask-Wearing, dated January 20, 2021 and OMB Memo M-21-15, COVID-19 Safe Federal Workplace: Agency Model Safety Principles, dated January 24, 2021, face masks are required to be consistently worn in all common areas and shared workspaces of Bureau facilities (Headquarters and any regional office) including bathrooms, elevators, conference rooms with more than one occupant, workstation (cubicle) areas, fitness center, lunchroom, Small Savers space, and any other spaces except for a limited time when a person is eating and drinking while maintaining social distancing.

10 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

b. Additionally, face masks are required to be worn in shared outdoor spaces such as the rooftop terrace, if social distancing of at least six feet cannot be maintained. Masks are not required when working alone in a room with floor to ceiling walls and a closed door.

c. Face masks must cover a person’s nose and mouth and fit snugly around a person’s nose and chin with no large gaps around the sides of their face.

d. CDC-recommended face masks included non-medical disposable masks, masks made of breathable fabric (such as cotton), masks made with tightly woven fabric (i.e. fabrics that do not let light pass through when held up to a light source), masks with two or three layers, and masks with inner filter pockets. Novelty or non-protective face masks, face coverings with ventilation valves, or face shields are not approved substitutes for face masks.

e. Contractor personnel who do not have a mask upon entering a Bureau-controlled facility will be provided one from the security officer located at any of the building entrances.

2.2 BUREAU OFFICE OF THE INSPECTOR GENERAL (September 2018)

For the avoidance of doubt, nothing in this contract shall limit the OIG's authority under the Inspector General Act to examine the Contractor's books, documents, papers, etc.

The Contractor and any subcontractor shall make notification (including posting notices in each of their respective facilities) to all Contractor and subcontractor employees working on this contract of the OIG’s hot line telephone number, 1-800-827-3340, and to report any suspected "waste, fraud, or abuse" transactions related to the performance of this contract.

2.3 CYBERSECURITY/INFORMATION SECURITY (February 2024)

a. The Consumer Financial Protection Bureau (CFPB) defines terms consistent with those determined by the National Institute of Standards and Technology (NIST) Glossary | CSRC (nist.gov).

1. Per NIST, an information system can be described as the following: “a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.”

2. An information system includes any computer that contains Bureau data and performs any of the above tasks, not just systems of records.

b. Contractors retained for purposes of providing expert witness services to provide analysis and/or testimony in support of the Federal Government in any current or anticipated litigation or dispute are not “working on behalf of, nor agents of the

CFPB.”

c. In accordance with Homeland Security Presidential Directive 12 (HSPD-12), Office of the Management and Budget (OMB) Memorandum M-19-17, CFPB https://csrc.nist.gov/glossary

11 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

Information System Security and Secure Access Controls Via Multi-Factor Authentication Policies, any Contractor requiring routine physical access to a CFPB facility and/or routine access to a CFPB federally controlled information system will be required to obtain a CFPB-issued Personal Identity Verification (PIV) card. Contractors shall take the necessary steps to obtain a PIV card, including enrollment and activation, within 45-calendar days of their CFPB start date, loss or expiration of their current PIV card. Contractors who fail to comply with this policy will be removed from their CFPB contract.

1. The Contractor shall provide its own PIV reader(s), if necessary.

2. In some situations, a PIV card may not be possible to use for CFPB information system access. If so, the Contractor shall use a CFPB authentication application on a personal or corporate mobile device.

d. The Contractor shall adhere to CFPB cybersecurity requirements for all information systems connected to CFPB network/resources or operated by the Contractor for, or on behalf of, the CFPB, regardless of location. The Contractor shall protect all CFPB-provided data to CFPB policies and standards, if stored in a Contractor system. This clause applies to all or any part of the contract that includes information technology, information resources, data, or services for which the Contractor must have physical or electronic access to CFPB information or data.

e. CFPB information technology and data provided to the Contractors shall remain in the United States. The receipt, transmission, backup, accessing, maintenance, operation, and/or processing of CFPB technology and information must take place, and originate from, within the United States. Any exceptions to this must be approved in writing by the Chief Operating Officer and the Chief Information Officer.

f. The Contractor shall maintain a complete and accurate inventory of all CFPB-provided data, along with complete access records. Upon request by the Contracting Officer (CO) or the Contracting Officer’s Representative (COR), the inventory and access records shall be made available for inspection within one business day.

g. Contractors serving as an agent of the Bureau or on the Bureau’s behalf, and are receiving, transmitting, storing, or processing intellectual property, records, or Bureau-provided data must use government-furnished equipment (GFE) or Citrix-based virtual desktop interface (VDI) to complete Bureau work. A contractor not serving as a CFPB agent or on CFPB’s behalf may elect to receive data via VDI or GFE. However, if a contractor is creating independent content (training, documentation, etc.) that the Bureau receives, approves, and then executes; the Contracting Officer’s Representative (COR) may elect to exclude specific contractor roles from requiring GFE. The COR may elect to exclude contractor roles from GFE/VDI, if the contractor role:

1. Does not access the Bureau network, resources, or data;

2. Does not manage Bureau social media or live links;

12 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

3. Does not act as a Bureau agent to generate, receive, transmit, store, or process Bureau data or act upon the Bureau’s behalf;

4. Contractor role does not generate, receive, transmit, store, or process Bureau data (i.e., records, intellectual property, etc.);

5. Produces the content without the input of Bureau data; and,

6. All federal decision-making happens after Bureau receipt of content.

Each exclusion must be documented by the COR, approved in writing by the Bureau Authorizing Official or designee, and revisited annually.

h. The Contractor system or facility hosting CFPB information resources must meet all applicable federal, state, and local zoning, environmental, and building laws and regulations. The system or facility must include protection against unauthorized access at all hours, including alarms and notification systems, should such protection be breached.

i. Detected or suspected security compromises to CFPB information must be reported to the CO or COR and soc@cfpb.gov within 60 minutes of discovery by the Contractor. In the event of a compromise, the Contractor shall grant the Government access to all facilities and information resources used in support of the contract to safeguard CFPB information resources.

j. The Contractor shall grant the Government access to all facilities and information resources used in support of the contract. The CFPB may conduct reviews to ensure that the security requirements in the contract are implemented, enforced, effective, and operating as intended. These reviews include, but are not limited to, comprehensive technical testing of the control environment used to safeguard CFPB information, data, or information resources.

k. At the expiration of the contract, the Contractor shall return all CFPB information resources provided to, or generated by, the Contractor during the period of the contract. The Contractor shall provide certification and artifacts to prove that all CFPB information/data has been sanitized from any non-GFE information system in accordance with CFPB standards and procedures. With advance notification, CFPB may surveil and/or inspect the sanitization/destruction/disposition. All equipment sanitization procedures must be environmentally sound as outlined by the U.S. Environmental Protection Agency (EPA).

l. To the extent the Contractor has Bureau assets or devices (i.e., laptop, thumb drive), the Contractor shall comply with the Bureau’s Asset Management Policy and is responsible for:

Using and protecting its assigned equipment in accordance with the Acceptable Use Policy and Guidance laid out in the Facilities Non-IT Asset Management Directive and IT Asset Management Directive; providing access to their assigned equipment when requested by the responsible Asset Management team; and immediately reporting the loss or theft of IT hardware, software, and/or data upon discovery to the COR, the CFPB Security Office at extension 59001 or (202) 435-9001, and to the Service Desk at extension 57777 or (202) 435-7777.

m. For the purposes of application development, the Contractor shall adhere to NIST Secure Software Development Framework (SSDF), SP 800-218, 800-161, and the mailto:soc@cfpb.gov

13 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

NIST Software Supply Chain Security Guidance for developing secure software or providing third-party software to include the adoption of open-source libraries or other application packages. CFPB encourages and prefers the use of cloud-hosted solutions. All cloud-hosted solutions will need to go through the Federal Risk and Authorization Management Program (FedRAMP) authorization, if not already FedRAMP authorized. If not cloud-based, CFPB prefers web-based, commercial off the shelf software that is browser agnostic. Cloud and non-cloud based solutions will need to go through CFPB’s authority to operate process. Data in cloud-based or non-cloud-based systems must be maintained within the United States at all times and may not be accessible by unauthorized individuals, including, but not limited to non-U.S. citizens.

n. The Contractor shall adhere to all CFPB common security configurations and practices or system operation. Security configurations and practices include:

1. The provider of information technology shall certify applications are fully functional and operate as intended on systems using the United States Government Configuration Baseline and other operating system and application standards.

2. Final acceptance of the product will be based on the CFPB interpretation of the National Institute of Standards and Technology, National Checklist Program Repository (NIST, NCPR). Checklists are available at the NIST, NCPR website. In situations where security configurations are not available for proposed technologies, the CFPB shall provide instruction.

3. The installation, operation, maintenance, and update of software shall not alter any CFPB-accepted or established security configuration.

4. Applications designed for users shall run in standard user context without elevated system administrator privileges.

o. The Contractor shall notify the CO and the COR within 30 calendar days of any organizational change or impact that may interfere with the full execution of the information security requirements under the contract.

p. Throughout the term of the contract, should the Contractor deliver a product or provide a service that does not meet (and maintain) CFPB’s information security requirements, the Contractor, at their own expense, shall correct non-compliant deliverables within 90 days of notification by the CO or the COR.

q. If not a CFPB agent or working on the Bureau’s behalf, the Contractor shall maintain a computing environment that complies with NIST SP 800-171 requirements and Bureau policy and standards at all times. These requirements include, but are not limited to, documentation of the processes and procedures that the Contractor shall follow to ensure the security of IT resources that are developed, processed, transmitted, used, or maintained under this contract and comprehensive technical testing of the Contractor’s computing environment by the CFPB or CFPB-approved independent third-party.

14 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

r. Prior to the execution of the contract, the CFPB may require validation to ensure adequate security controls in the Contractor environment. When a validation is required, the validation may be conducted by the CFPB as part of an on-site inspection process or CFPB-approved independent third-party.

s. Contractors providing services that are FedRAMP certified shall ensure their FedRAMP packages remain current throughout the life of the contract.

t. The Contractor shall demonstrate, upon request by the CO or COR, the technical, operational, and management safeguards that protect the confidentiality, integrity, and availability of CFPB information that it generates, develops, processes, transmits, uses, or maintains during the execution of this contract. This demonstration may include the delivery of artifacts within the scope of the FedRAMP package and independent from FedRAMP artifacts.

u. The Contractor shall ensure its computing environment complies with Federal laws that include, but are not limited to, the Federal Information Security Modernization Act of 2014 (FISMA), and with Federal policies and procedures that include, but are not limited to: the most current versions of NIST Special Publication (SP) 800-60, 800-63A, 800-218, 800-161, 800-53 or 800-171 (as determined by CFPB), Federal Information Processing Standard (FIPS) 200, 140, and CFPB Information Security Standards (CS-S-01). Copies of these documents are maintained by the CFPB Office of Cybersecurity and are available upon request. Failure to maintain compliance with applicable statutes, regulations, and guidance is a breach of the contract. The CO or COR may conduct one or more on-site inspections to ensure compliance.

1. All Contractors and systems shall adhere to the most current OMB

Circular A-130 and NIST SP 800-53 or 800-171 requirements in alignment with the Bureau-established FIPS Publication 199 determination for that authorized system, CFPB data extract, or derived data. Unless waived by the CFPB Authorizing Official (AO) in writing:

a. Information system(s) shall have the ability to transfer audit logs to the Bureau’s centralized log collection and analysis system, Splunk by using an application programming interface (API) or a secure system log file (syslog).

b. Information system(s) shall support Security Assertion Markup Language (SAML) 2.0 or OpenID Connect (OIDC) for federated login to any web console provided by the tool, if providing a log-in capability.

c. Information system(s) shall provide a user management application programming interface or web services capability that allows for the creation, updating, disabling and deletion of accounts and permissions, if the application requires accounts.

d. The project technical team shall submit an information system security baseline in alignment with Bureau common information security standards (ISS) and the system sensitivity classifications https://team.cfpb.local/wiki/images/0/05/CS-S-01_-_Information_Security_Standards_V4.0_05012018.pdf

15 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

per the Federal Information Processing Standard (FIPS) 199/200 assessments, if appropriate.

v. If not a CFPB agent or working on CFPB’s behalf, the Contractor shall adhere to applicable Federal laws, regulations, and directives as well as the most current NIST Special Publication (SP) 800-171 requirements and other security standards and policies set by CFPB for non-federal contractor information systems that receive, transmit, process, store, or collect any form of Controlled Unclassified Information (CUI) collected for or provided by the Bureau. This is applicable to sub-contractors and Vendors who also do not serve in any capacity as Bureau agents and do not have the authority to act on the Bureau’s behalf.

w. The Contractor shall adhere to NIST SP 800-218 and Bureau-defined requirements regarding all Bureau system development life cycle (SDLC) policies, procedures, and activities, as applicable. The Contractor shall adhere to NIST Secure Software Development Framework (SSDF) and the NIST Software Supply Chain Security Guidance for developing secure software or providing third-party software to include open-source software or other application packages. Further, this includes the removal and disposal of all Bureau data from Contractor-owned and operated information systems once no longer needed to complete the contract. The Contractor shall provide all requested artifacts required to verify and attest that all Bureau data has been permanently removed once the information system is no longer required to process, store, or transmit Bureau data. These artifacts include, but are not limited to:

1. Independent 800-171A or 800-53A Risk Assessment per NIST Standards, as assigned by CFPB.

2. Signed letter or document from the Contractor showing/attesting that all bureau level data has been properly and correctly removed per 800-171 or 800-53.

3. Information Security Program documentation

4. Screen captures, or equivalent, showing each step taken within the information system and result when permanently removing Bureau data.

5. On-site inspection or remote surveillance of the sanitization/disposal/disposition process.

x. If the Contractor does not report within 2 business days or does not adhere to the CFPB policy and standards, the Bureau may impose penalties until such time that the reporting and standards are remedied to the Bureau’s satisfaction and may have non-conformant systems or actions suspended until remediation conforms.

y. The Contractor shall adhere to CFBP blocking apps and sites on government-issued devices or contractor-operated networks/devices in support of CFPB work.

Exceptions can be made by the CFPB AO in coordination with OMB, if a compelling business need exists.

z. The Contractor shall maintain an active information security (infosec) program to 800-171 or 800-53 standards with detective, preventative, and responsive

16 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

elements to ensure administrative, managerial, technical, and physical controls per above. The program shall specifically address methods regarding handling and protecting CFPB information at the Contractor’s site (including any information stored, processed, or transmitted using the Contractor’s computer systems), and the secure management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems, to include end-user systems.

1. CFPB will review infosec program documentation and may interview for clarification with the proposed Contractor to assure confidence in the Contractor’s infosec program.

2. The Contractor, as deemed necessary, may use additional safeguards other than as provided for by the Contract to prevent use or disclosure of CFPB information.

aa. The Contractor shall, at its own expense, take action to mitigate any harmful effect that is known to the Contractor of a use or disclosure of CFPB information/data by the Contractor in violation of the requirements of this clause.

bb. The Contractor shall not use meta-data about CFPB’s use of the service for any purpose except for troubleshooting, technical performance monitoring, or ensuring security and functionality of the service.

cc. The CFPB Office of Cybersecurity maintains current information security requirements and standards and will provide details to the Contractor as needed after contract award. The CO or COR will notify the Contractor of any substantive changes to information security requirements that have a significant impact on the Contractor’s information security obligations under the Contract.

The accountable senior executive, such as a Company Risk Executive or Chief Information Security Officer must sign acknowledgement of receipt, understanding, and compliance with all current 800-171 or 800-53 standards.

dd. The Contractor shall include the substance of this clause in all subcontracts under this Contract.

2.4 ORGANIZATIONAL CONFLICT OF INTEREST (MARCH 2019)

Contractor and subcontractor personnel performing work under this contract, or who have previously performed related work and have a conflict of interest, may receive, have access to or participate in the development of proprietary or procurement sensitive information (i.e., cost or pricing information, budget information or analyses, specifications or work statements), perform evaluation services, or provide consulting services (such as, but not limited to, serving as an expert witness) which may create a current or subsequent Organizational Conflict of Interest (OCI) as defined in FAR subpart 2.101(b).

A. ATTESTATION REQUIREMENT: The Consumer Financial Protection Bureau (CFPB) has not waived any conflicts of interest. As part of its proposal/quote (“proposal”) submission, the offeror/quoter (“Offeror”), including its employees, officers and subcontractors, attests, by checking one of boxes below, that to the best of its knowledge it is:

17 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

Not aware of any facts that create any actual conflict, potential conflict or the appearance of a conflict(s) or unfair competitive advantage relating to the award of, or carrying out the responsibilities under, this contract or agreement.

Aware of facts that create an actual conflict, potential conflict or matter that may present the appearance of a conflict(s) or unfair competitive advantage related to the award of and/or carrying out the responsibilities under this contract or agreement. Included with this attestation is (a) a description of all actual or potential conflicts and/or facts presenting the appearance of a conflict or unfair competitive advantage; and (b) a list of all organizations that the offeror (including key personnel and subcontractors) has worked with or for during the past three years that relate to any OCI identified pursuant to a)(2)(a) of this clause.

B. MITIGATION PLAN REQUIREMENT: If the offeror attests to (2), above, and believes the actual or potential conflict(s) or appearance of a conflict(s) can be avoided, neutralized, or mitigated, the offeror must submit a detailed mitigation plan in its proposal. The mitigation plan shall generally provide all current information bearing on the existence of any actual conflict, potential conflict or matter that may present the appearance of a conflict(s) (to include its employees and subcontractors), and detail how the offeror would avoid, neutralize, or mitigate the conflict(s).

C. MITIGATION PLAN CONTENTS: Though each situation is unique, a mitigation plan shall, at a minimum, include the following:

• A detailed description of any possible OCI. This will include a listing of the offeror’s past and current relationship to any firm in the past three years that is related to the services being procured herein and any possible OCI associated thereto;

• A description of the actions the offeror will take to mitigate the possible OCI;

• A description of how the mitigation measures will not adversely affect contract performance;

• A description of the potential risks and issues of the OCI mitigation plan;

• A description of the offeror’s OCI monitoring process and how the OCI mitigation plan will be updated;

• Definition of company roles, responsibilities, and procedures for screening existing and new business opportunities for possible OCI issues;

• A list of any affiliated companies/entities associated with any possible OCI, including a parent company or a wholly-owned subsidiary, along with procedures for coordinating possible OCIs with such affiliated companies/entities;

• A description of how the offeror would require subcontractors to support the contract or agreement and a description of how the offeror would address OCI requirements with its subcontractor, including compliance with its mitigation plan;

• A description of a training program for employees involved with the OCI; and

• A definition of records related to the OCI mitigation plan to be made available to the

Government upon request.

18 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

D. CONTRACTING OFFICER DISCRETION: The Contracting Officer (CO) shall be the sole determiner of whether an OCI exists; if an OCI may be avoided, neutralized or mitigated; and how an OCI may be avoided, neutralized or mitigated. The CO must assess the offeror’s or Contractor’s information, internal information from the Bureau’s program office, and any other relevant information to make such determinations.

E. PROCEDURES FOR OCI IDENTIFIED DURING EVALUATION PROCESS: FAR subpart 9.504(e) provides unique procedures for the handling of an OCI determined during the evaluation process for contract award. In that circumstance, the CO shall award the contract to the apparent successful offeror, unless it is determined that an OCI exists that cannot be avoided or mitigated. Before determining to withhold award based upon such an OCI, the CO shall notify the offeror, explaining the nature of the OCI and providing the offeror an opportunity to respond. If in evaluating the information the CO believes it may be in the best interest of the United States to award to the offeror notwithstanding the OCI, the CO shall request that the offeror submit a written waiver request.

F. PROCEDURES FOR AN OCI WAIVER: If the CO determines that an OCI exists for which the offeror or Contractor wishes to seek waiver and/or the CO believes waiver may be in the best interest of the Government, waiver may only be granted by the Head of the Contracting Activity (HCA). Upon a written waiver request from the offeror or Contractor, the HCA will make a decision as to waiver based upon the best interests of the Government.

G. ONGOING CONTRACTOR OCI OBLIGATION AND DISCLOSURE: The offeror or Contractor has a continuing obligation to search for and to report any matter that may present itself as an actual conflict, potential conflict or give the appearance of a conflict. If the offeror or Contractor believes that its OCI status changes at any time during the evaluation process or over the course of the BPA or contract, it has an ongoing responsibility to notify the CO in writing with a prompt and full disclosure as soon as practicable, and in no instance later than ten (10) business days, after learning of any new or expanded possible OCI(s). The disclosure shall include a description of the action the contactor has taken or proposes to take in order to avoid or mitigate such conflict(s). Only the CO can determine whether an OCI actually exists.

H. REMEDIES: For breach of any of the above restrictions or for non-disclosure or misrepresentation of any relevant facts required to be disclosed by this clause, the Government may: disqualify an offeror from competing for a contract award; terminate the relevant contract for default; disqualify the Contractor from subsequent related contractual efforts if necessary to neutralize a resulting OCI; and pursue such other remedies as may be permitted by law or under the relevant contract. If, however, in compliance with this clause, a Contractor discovers and promptly reports an OCI (or potential thereof), the CO may terminate this contract for convenience if such termination is deemed to be in the best interest of the Government, or may take other appropriate actions.

I.SUBCONTRACTS: The Contractor shall include this clause in subcontracts, consulting agreements or other arrangements for services and supplies at any tier. The terms “contract”, “Contractor”, and “Contracting Officer” shall be appropriately modified to preserve the Government’s rights.

19 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

2.5 UNIVERSAL ACCESS AND DESIGN (SEPTEMBER 2018)

The Contractor shall ensure that all Electronic and Information Technology (EIT) deliverables meet or exceed accessibility and usability design requirements under Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended and refreshed January 2018, and under the Web Content Accessibility Guidelines 2.0 (WCAG 2.0) Level AA. The refreshed Section 508 Standards (January 2018) can be found at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule. The refreshed Section 508 Standards harmonize with WCAG 2.0 Level AA. EIT is also referred to as Information Computer Technology (ITC).

EIT deliverables include, but are not limited to: websites, mobile applications, web based applications, cloud solutions, software as a solution (SaaS), commercial off-the-shelf (COTS) products, software, hardware, webcasts, webinars, podcasts, multimedia, social media, collaborative workspaces and tools, surveys, print and electronic documents, PDFs, forms, and all training and related training materials.

The Contractor shall have the ability and experience in creating Section 508 conformant deliverables and in determining the Section 508 compliance of EIT including design specification, testing and verification, and remediation as required.

The Contractor shall acquire the necessary authoring and testing tools to create EIT deliverables and perform accessibility and usability testing in multiple environments to include a comprehensive selection of assistive technologies. The Contractor shall use the most updated version of an authoring tool that creates Section 508 conformant outputs in order to ensure its deliverables are Section 508 conformant and usable.

Upon the request of the Contracting Officer (CO) or the Contacting Officer’s Representative (COR), the Contractor shall present a Government Product Accessibility Template (GPAT) (https://www.section508.gov/) for each EIT deliverable. GPAT findings shall be presented in an accessible electronic format.

Materials intended for print shall also include an accessible, dynamic and Section 508 conformant electronic version of the deliverable. Print materials shall be made available in an alternate accessible format when requested.

When producing EIT deliverables, the Contractor shall follow the Bureau’s Design Manual (https://cfpb.github.io/design-manual/), including Bureau templates.

2.6 INSPECTION OF BOOKS & RECORDS (MARCH 2019)

The Contractor agrees that the Consumer Financial Protection Bureau (CFPB) (including its authorized representative and/or its Office of Inspector General) (collectively, "CFPB") shall, until expiration of three (3) years after final payment under this contract, have access to and the right to examine any directly pertinent books, documents, papers, and records of the Contractor involving transactions related to this Contract. The Contractor further agrees to include in all its subcontracts

20 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW

hereunder a provision to the effect that the subcontractor agrees that the CFPB shall have the same rights to the subcontractor books, documents, papers and records as specified above.

The periods of access and examination described above, for records which relate to (1) litigation or the settlement of claims arising out of the performance of this contract, or (2) costs and expenses of this contract as to which exception has been taken by the CFPB, shall continue until such litigation, claims, or exceptions have been disposed of, and CFPB has specified in writing that exception is no longer being taken.

2.7 FAR 52.232-39, UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS

(Jun 2013)

(a) Except as stated in paragraph (b) of this clause, when any supply or service acquired under this contract is subject to any End User License Agreement (EULA), Terms of Service (TOS), or similar legal instrument or agreement, that includes any clause requiring the Government to indemnify the Contractor or any person or entity for damages, costs, fees, or any other loss or liability that would create an Anti-Deficiency Act violation (31 U.S.C. 1341), the following shall govern:

(1) Any such clause is unenforceable against the Government.

(2) Neither the Government nor any Government authorized end user shall be deemed to have agreed to such clause by virtue of it appearing in the EULA, TOS, or similar legal instrument or agreement. If the EULA, TOS, or similar legal instrument or agreement is invoked through an “I agree” click box or other comparable mechanism (e.g., “click-wrap” or “browse-wrap” agreements), execution does not bind the Government or any Government authorized end-user to such clause.

(3) Any such clause is deemed stricken from the EULA, TOS, or similar legal instrument or agreement.

(b) Paragraph (a) of this clause does not apply to indemnification by the Government that is expressly authorized by statute and specifically authorized under applicable agency regulation and procedures.

2.8 RECORDS AND INFORMATION MANAGEMENT (MARCH 2019)

Definitions

“Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, 21 CONSUMER FINANCIAL PROTECTION BUREAU (CFPB), 1700 G STREET, NW procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chapters 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

Contractor shall treat all deliverables under the contract as the property of the U.S. Government for which the Government Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest.

Contractor shall not create or maintain any records that are not specifically tied to or authorized by the contract using Government IT equipment and/or Government records.

Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected by the Freedom of Information Act.

Contractor shall not create or maintain any records containing any Government Agency records that are not specifically tied to or authorized by the contract.

The Consumer Financial Protection Bureau (CFPB) owns the rights to all recorded information, regardless of form or characteristics, produced as part of this contract.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .