Combined Synopsis and Solicitation RFQ No. 15A0002500000050.pdf

PDF 467 KB Posted

Attached to
Solidworks Training Federal contract opportunity
Solicitation number
15A0002500000050
Issued by
Department of Justice Bureau of Alcohol Tobacco Firearms and Explosives

About this file

This is a Combined Synopsis/Solicitation (RFQ No. 15A0002500000050) issued by the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) for SolidWorks training services. The solicitation seeks a contractor to provide training for ten (10) learners, with each learner able to select up to three unique SolidWorks classes from a predefined list including SolidWorks Essentials, Drawings, Advanced Part Modeling, Assembly Modeling, Sheet Metal, Weldments, and Simulation Essentials. Training can be delivered in-person, online, or through a hybrid model, with the in-person location limited to 2555 Westinghouse Blvd in Charlotte, NC or within 30 miles of that location.

The solicitation is unrestricted and will be awarded using the lowest price technically acceptable method. Quotes are due by May 2, 2025, at 5:00 PM ET, with all questions to be submitted in writing to Courtney Middleton via email by April 29, 2025. The period of performance is one year from the date of award, and the contractor must be an authorized educational SolidWorks vendor. The North American Industry Classification System (NAICS) code is 611420, with a small business size standard of $16M, and the Product Service Code is U0060 for Education/Training-Vocational/Technical.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

COMBINED SYNOPSIS/SOLICITATION

Contracting Office Zip Code: 20226 Solicitation Number: 15A0002500000050 Response Date/Time/Zone: May 2, 2025, 5PM EASTERN TIME Set-Aside: Unrestricted Product Service Code: U0060 NAICS Code: 611420 Contracting Office Address: Bureau of Alcohol, Tobacco, Firearms and Explosives

Acquisition Management Division (AMD) 99 New York Ave NE Washington, DC 20226

Point of Contact: Courtney Middleton Courtney.Middleton@ATF.gov

Place of Performance: See Description of Requirement

This is a combined synopsis/solicitation for commercial products and commercial services prepared in accordance with the format in Federal Acquisition Regulation (FAR) subpart 12.6, “Streamlined Procedures for Evaluation and Solicitation for Commercial Products and Commercial Services,” as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested, and a written solicitation document will not be issued.

This solicitation is issued as an RFQ. The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2024-05.

This solicitation is NOT set-aside for small business. This is an unrestricted solicitation.

The associated North American Industrial Classification System (NAICS) code for this procurement is 611420, with a small business size standard of $16M.

The FSC/PSC is U0060 Education/Training -Vocational/Technical

All interested companies shall provide quotations for the following:

Statement of Work (SOW)

1.0 BACKGROUND

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) requires training services for ten (10) learners. Each learner must have the ability to select up to three unique classes that best suit their individual training needs. The goal is to provide tailored educational opportunities that enhance the skills and knowledge of our personnel.

mailto:Courtney.Middleton@ATF.gov

2.0 SCOPE AND GENERAL REQUIREMENTS

The contractor must be an authorized educational SolidWorks vendor and shall provide training services for ten (10) learners, allowing each learner to select up to three unique classes SOLIDWORKS to meet their individual learning requirements.

PRICE SCHEDULE

CLINS DESCRIPTION QTY UNIT UNIT COST TOTAL COST

0001 SOLIDWORKS Training

Each learner selects 3 unique classes from the following:

SOLIDWORKS Essentials SOLIDWORKS Drawings SOLIDWORKS Advanced Part Modeling SOLIDWORKS Assembly Modeling SOLIDWORKS Sheet Metal SOLIDWORKS Weldments SOLIDWORKS Simulation Essentials

10 EA $ $

TOTAL COST $

Delivery Method and Place of Performance: Classes may be delivered in-person, online, or through a hybrid model, depending on the preferences of the government and the nature of the courses. In-person location can only be offered at:

2555 Westinghouse Blvd Charlotte, NC 28273, or training within 30 miles of location.

Schedule: The government shall coordinate with the contractor to schedule the classes at times.

Materials: The contractor shall provide all necessary training materials, including but not limited to textbooks, workbooks, and access to online resources.

Period of Performance: The period of performance for this contract shall be Date of award through one year.

3.0 CLAUSES

The contractor/awardee must comply with provisions and clauses/terms & conditions (T&Cs) incorporated herein via full text and by reference. FAR clauses and provisions may be accessed at www.aquisitions.gov/far.

Offeror Representations and Certifications – Commercial Items applies to this acquisition.

Prospective vendors must be actively registered with the System for Awards Management (SAM) website at http://www.SAM.gov. The clause at FAR 52.212-4, Contract Terms and Conditions – Commercial Items and FAR 52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders – Commercial Items applies to this acquisition. The http://www.aquisitions.gov/far http://www.sam.gov/ offeror must have a current profile in the Online Representations and Certifications (http://www.SAM.gov) prior to award.

The contractor/awardee must comply with provisions and clauses/terms & conditions (T&Cs) incorporated herein via full text and by reference.

The contractor shall complete the following ATF and FAR Clauses and return completed with their quote: 52.204-26, 52.204-24, 52.209-11 and 52.222-22 listed below.

52.204-26 Covered Telecommunications Equipment or Services-Representation (Oct 2020)

(a) Definitions. As used in this provision, "covered telecommunications equipment or services" and "reasonable inquiry" have the meaning provided in the clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(b) Procedures. The Offeror shall review the list of excluded parties in the System for Award Management (SAM) (https://www.sam.gov) for entities excluded from receiving federal awards for "covered telecommunications equipment or services". (c) Representations.

(1) The Offeror represents that it __ does, __ does not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in the performance of any contract, subcontract, or other contractual instrument.

(2) After conducting a reasonable inquiry for purposes of this representation, the offeror represents that it __ does, __ does not use covered telecommunications equipment or services, or any equipment, system, or service that uses covered telecommunications equipment or services.

(End of provision)

52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment (Nov 2021)

The Offeror shall not complete the representation at paragraph (d)(1) of this provision if the Offeror has represented that it "does not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in the performance of any contract, subcontract, or other contractual instrument" in paragraph (c)(1) in the provision at 52.204-26, Covered Telecommunications Equipment or Services-Representation, or in paragraph (v)(2)(i) of the provision at 52.212-3, Offeror Representations and Certifications-Commercial Products and Commercial Services. The Offeror shall not complete the representation in paragraph (d)(2) of this provision if the Offeror has represented that it "does not use covered telecommunications equipment or services, or any equipment, system, or service that uses covered telecommunications equipment or services" in paragraph (c)(2) of the provision at 52.204-26, or in paragraph (v)(2)(ii) of the provision at 52.212-3.

(a) Definitions. As used in this provision--http://www.sam.gov/

Backhaul, covered telecommunications equipment or services, critical technology, interconnection arrangements, reasonable inquiry, roaming, and substantial or essential component have the meanings provided in the clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(b) Prohibition.

(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system.

Nothing in the prohibition shall be construed to--

(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract or extending or renewing a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract. Nothing in the prohibition shall be construed to--

(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(c) Procedures. The Offeror shall review the list of excluded parties in the System for Award Management (SAM) (https://www.sam.gov) for entities excluded from receiving federal awards for "covered telecommunications equipment or services."

(d) Representations. The Offeror represents that--

(1) It __will, __will not provide covered telecommunications equipment or services to the Government in the performance of any contract, subcontract or other contractual instrument resulting from this solicitation. The Offeror shall provide the additional disclosure information required at paragraph (e)(1) of this section if the Offeror responds "will" in paragraph (d)(1) of this section; and

(2) After conducting a reasonable inquiry, for purposes of this representation, the Offeror represents that--

It __ does, __ does not use covered telecommunications equipment or services, or use any equipment, system, or service that uses covered telecommunications equipment or services. The Offeror shall provide the additional disclosure information required at paragraph (e)(2) of this section if the Offeror responds "does" in paragraph (d)(2) of this section.

(e) Disclosures.

(1) Disclosure for the representation in paragraph (d)(1) of this provision. If the Offeror has responded "will" in the representation in paragraph (d)(1) of this provision, the Offeror shall provide the following information as part of the offer:

(i) For covered equipment--

(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the original equipment manufacturer (OEM) or a distributor, if known);

(B) A description of all covered telecommunications equipment offered (include brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and

(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.

(ii) For covered services--

(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); or

(B) If not associated with maintenance, the Product Service Code (PSC) of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.

(2) Disclosure for the representation in paragraph (d)(2) of this provision. If the Offeror has responded "does" in the representation in paragraph (d)(2) of this provision, the Offeror shall provide the following information as part of the offer:

(i) For covered equipment--

(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the OEM or a distributor, if known);

(B) A description of all covered telecommunications equipment offered (include brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and

(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.

(ii) For covered services--

(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); or

(B) If not associated with maintenance, the PSC of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.

(End of provision)

52.209-11 Representation by Corporations Regarding Delinquent Tax Liability or a Felony Conviction under any Federal Law (Feb 2016)

(a) As required by sections 744 and 745 of Division E of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235), and similar provisions, if contained in subsequent appropriations acts, the Government will not enter into a contract with any corporation that--

(1) Has any unpaid Federal tax liability that has been assessed, for which all judicial and administrative remedies have been exhausted or have lapsed, and that is not being paid in a timely manner pursuant to an agreement with the authority responsible for collecting the tax liability, where the awarding agency is aware of the unpaid tax liability, unless an agency has considered suspension or debarment of the corporation and made a determination that suspension or debarment is not necessary to protect the interests of the Government; or

(2) Was convicted of a felony criminal violation under any Federal law within the preceding 24 months, where the awarding agency is aware of the conviction, unless an agency has considered suspension or debarment of the corporation and made a determination that this action is not necessary to protect the interests of the Government.

(b) The Offeror represents that--

(1) It is __ is not __ a corporation that has any unpaid Federal tax liability that has been assessed, for which all judicial and administrative remedies have been exhausted or have lapsed, and that is not being paid in a timely manner pursuant to an agreement with the authority responsible for collecting the tax liability; and

(2) It is __is not __ a corporation that was convicted of a felony criminal violation under a Federal law within the preceding 24 months.

(End of provision)

52.222-22 Previous Contracts and Compliance Reports (Feb 1999)

The offeror represents that--

It has, __ has not __ participated in a previous contract or subcontract subject to the Equal Opportunity clause of this solicitation;

It has, __ has not __ filed all required compliance reports; and

Representations indicating submission of required compliance reports, signed by proposed subcontractors, will be obtained before subcontract awards.

(End of provision)

The following subparagraphs of FAR 52.212-5 are applicable.

FAR 52.203-17 Contractor Employee Whistleblower Rights (Nov 2023) FAR 52.204-10 Reporting Executive Compensation & First-Tier Subcontract Awards (JUN 2020) FAR 52.204-27 Prohibition on a ByteDance Covered Application (Jun 2023) FAR 52.209-6 Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment (JUN 2020) FAR 52.219-28 Post Award Small Business Program Representation (NOV 2020) FAR 52.222-3 Convict Labor (JUN 2003) FAR 52.222-19 Child Labor—Cooperation with Authorities and Remedies (JUL 2020) FAR 52.222-21 Prohibition of Segregated Facilities (APR 2015) FAR 52.222-26 Equal Opportunity (SEP 2016) FAR 52.222-36 Equal Opportunity for Workers with Disabilities (JUN 2020) FAR 52.222-50 Combating Trafficking in Persons (OCT 2020) FAR 52.222-26 Encouraging Contractor Policies to Ban Text Messaging While Driving (MAY 2024) FAR 52.232-33 Payment by Electronic Funds Transfer—System for Award Management (Oct 2018)

FAR Clauses Incorporated by Reference

FAR 52.203-3 Gratuities (Apr 1984) FAR 52.204-13 System for Award Management Maintenance (Oct 2018) FAR 52.204-18 Commercial and Government Entity Code Maintenance (Aug 2020) FAR 52.204-23 Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by

Kaspersky Lab Covered Entities (Dec 2023) FAR 52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or

Equipment (Nov 2021) FAR 52.212-4 Contract Terms and Conditions - Commercial Items (Nov 2023) FAR 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial

Products and Commercial Services (Jan 2025) FAR 52.217-8 Option to Extend Services (Nov 1999) FAR 52.225-13 Restrictions on Certain Foreign Purchases (Feb 2021) FAR 52.232-1 Payments (Apr 1984) FAR 52.232-33 Payment by Electronic Funds Transfer-System for Award Management (Oct2018) FAR 52.232-39 Unenforceability of Unauthorized Obligations (Jun 2013) FAR 52.232-40 Providing Accelerated Payments to Small Business Subcontractors (Mar2023) FAR 52.233-3 Protest after Award (Aug 1996) FAR 52.233-4 Applicable Law for Breach of Contract Claim (Oct 2004)

Additional Contract Terms and Conditions

ATF-04 Personnel Security Requirements (FEB 2024) ATF-14 ELECTRONIC INVOICING (Revised October 27, 2008) ATF-17 NOTICE TO THE GOVERNMENT OF DELAYS (Revised July 19, 2007) ATF-19 AUTHORITY TO OBLIGATE THE GOVERNMENT (Revised July 19, 2007) ATF-23 PRIVACY OR SECURITY SAFEGUARDS (August 1, 2007) ATF-25 OBSERVANCE OF LEGAL HOLIDAYS / FEDERAL NON-WORK DAYS (Revised June 2021)

ATF-28 CONTRACTOR CERTIFICATION OF COMPLIANCE WITH FEDERAL TAX

REQUIREMENTS (Revised May 22, 2008) ATF-29 STATEMENT OF WORK/OBJECTIVES, PERFORMANCE WORK STATEMENT or SPECIFICATIONS (March 23, 2009)

ATF-41 DEPARTMENT POLICY ON DOMESTIC VIOLENCE, SEXUAL ASSAULT, AND

STALKING (July 2019)

ATF-46 CORPORATE REPRESENTATION REGARDING FELONY CONVICTION UNDER

ANY FEDERAL LAW OR UNPAID DELINQUENT TAX LIABILITY - Award (DEVIATION 2015-02) (March 2015)

ATF-47 CONTRACTOR INTERNAL CONFIDENTIALITY AGREEMENTS OR

STATEMENTSPROHIBITING OR RESTRICTING REPORTING OF WASTE, FRAUD, AND

ABUSE (DEVIATION 2015-02) (March 2015) ATF-48 Contractor Certification of Compliance with Federal Tax Requirements – Award (DEVIATION 2015-02) (March 2015) ATF-51 INDEPENDENT CONTRACTOR (March 9, 2021) ATF-52 INDEMNIFICATION CLAUSE (May 2021) DOJ-01 Whistleblower Information Distribution (Oct 2021)

DOJ-02 Contractor Privacy Requirements (JAN 2022) DOJ-05 Security of Department Information and Systems DOJ-05 (OCT 2023)

Solicitation Provisions

FAR 52.204-7 System for Award Management (Nov 2024) FAR 52.204-16 Commercial and Government Entity Code Reporting (Aug 2020) FAR 52.204-17 Ownership or Control of Offeror (Aug 2020) FAR 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or

Equipment (Nov 2021) FAR 52.212-1 Instructions to Offerors - Commercial Items; (Sep 2023) FAR 52.212-3 Offeror Representations and Certifications - Commercial Items (May 2024) ATF-44 Contractor Internal Confidentiality Agreements Or Statements Prohibiting Or Restricting

Reporting Of Waste, Fraud, And Abuse (Deviation 2015-02) (March 2015)

Justice Acquisition Regulation (JAR) T&Cs

The full text of the JAR clauses may be viewed via https://www.acquisition.gov/jar/.

JAR 2852.201-70, Contracting Officer’s Representative (COR) (NOV 2020), JAR 2852.222-70, Domestic Violence, Sexual Assault, and Stalking (DEC 2014); 2852.223-70, Unsafe Conditions Due to the Presence of Hazardous Material (NOV 2020); JAR 2852.233-70, Protests Filed Directly with the Department of Justice (NOV 2020); 2852.203-70, General Non-Disclosure Agreement (AUG 2016); & JAR 2852.212-4, Terms and Conditions – Commercial Items (NOV 2020)

Department of Justice (DOJ) T&Cs

DOJ-01, Whistleblower Information Distribution (OCT 2021)

Within 30 days of contract award, the contractor and its subcontractors must distribute the “Whistleblower Information for Employees of DOJ Contractors, Subcontractors, Grantees, or Sub- Grantees or Personal Services Contractors” (“Whistleblower Information”) document to their employees performing work in support of the products and services delivered under this contract (https://oig.justice.gov/sites/default/files/2020-04/NDAA-brochure.pdf). By agreeing to the terms and conditions of this contract, the prime contractor acknowledges receipt of this requirement, in accordance with 41 U.S.C. § 4712 and FAR 3.908 & 52.203-17 and commits to distribution.

Within 45 days of award, the contractor must provide confirmation to the contracting officer verifying that it has distributed the whistleblower information as required.

(End of Clause)

DOJ-02, Contractors Privacy Requirements (JAN 2022)

A. Limiting Access to Privacy Act and Other Sensitive Information https://www.acquisition.gov/far https://www.acquisition.gov/jar https://www.acquisition.gov/jar/

(1) Privacy Act Information

In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.

(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment

Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.

(3) Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract.

The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

(4) Separation Checklist for Contractor Employees

The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.

In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).

Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems.

Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.

B. Privacy Training, Safeguarding, and Remediation

(1) Required Security and Privacy Training for Contractors

The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter.

Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj. The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness.

Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.

The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.

(2) Safeguarding PII Requirements

Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.

(3) Non-Disclosure Agreement Requirement

Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:

(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and

(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.

The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.

(4) Prohibition on Use of PII in Vendor Billing and Administrative Records

The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.

(5) Reporting Actual or Suspected Data Breach

Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.

(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting and Response Procedures for a Breach of Personally Identifiable Information.

(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and the Contracting Officer within one (1) hour of the initial discovery.

(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:

(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6] Date, time, and location of the incident.

(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.

(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]

(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.

(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]

(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.

(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.

(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.

(6) Victim Remediation

At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach. The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.

C. Government Records Training, Ownership, and Management

(1) Records Management Training and Compliance

(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR. This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.

(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.

(2) Records Creation, Ownership, and Disposition

(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information. The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.

(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S.

Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.

D. Data Privacy and Oversight

(1) Restrictions on Testing or Training Using Real Data Containing PII

The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.

(2) Requirements for Contractor IT Systems Hosting Government Data

The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.

(3) Requirement to Support Privacy Compliance

(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties.

The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.

(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion. The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800- 53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.

[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).

[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.

[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.

[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”

[5] https://www.justice.gov/file/4336/download

[6] As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used; extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.

[7] As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.

[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.

[9] As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.

[10] In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of information) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.

(End of Clause)

Work performed under this contract will involve any one or more of the following: access to DOJ Information, which may include Controlled Unclassified Information (CUI), i.e., unclassified, sensitive DOJ information, and/or access to DOJ Information Technology (IT) systems, and/or unescorted access to DOJ space or facilities. Contractor employees will occupy Public Trust Positions, unless clause alternates are applied.

1. General Requirements

(a) (1) All references to “contract(or) personnel” and “contract(or) employee” in this clause means all individuals, without limitation, to include individuals employed by the contractor, team member, subcontractor, consultant, and/or independent contractor, who will have access to information of the Department of Justice (DOJ) or information that is within the custody and control of the DOJ, access to DOJ IT systems, and/or unescorted access to DOJ facilities/space in connection with the performance of this contract. “Employment” as used herein does not create nor imply an employer/employee relationship between the DOJ and contractor employees.

(b) (1) The type of security investigation required for each contractor employee will be governed by the type and risk level of information made available to the contractor employee.

The contractor will not be permitted to commence performance under this contract until a sufficient number of its personnel, as determined by the Security Programs Manager (SPM), in consultation with the Contracting Officer’s Representative if one is appointed, have received the requisite security approval.

(c) Except where specifically noted otherwise, the federal government will be responsible for the cost and conduct of the investigation.

(d) The contractor shall ensure that no contractor employee commences performance prior to receipt of a written authorization from the contracting officer, COR, or the SPM that performance by the respective contractor employee is authorized.

(e) The data and other information to which the contractor may have access as a result of this contract is the property of, and/or within the custody and control of, the Department, and its disclosure to third parties is governed by various statutes and regulations, the violation of which may subject the discloser to criminal penalties.

2. Citizenship and Residency Requirements

(a) Residency Requirement. (1) Contractor employees in Public Trust positions, both U.S.

citizens and non-U.S. citizens, must meet the Department’s residency requirement if they will require access to DOJ information, IT systems, or unescorted access to facilities. For three years (not necessarily consecutive years) out of the last five years immediately prior to employment under the Department contract the contractor employee must have: (i) resided in the U.S.; (ii) worked for the U.S. in a foreign country as either an employee or contractor in a federal civilian or military capacity; or, (iii) been a dependent of a federal civilian or military employee or contractor working for the U.S. in a foreign country. At the Department’s sole discretion, the residency requirement may be waived by the Department Security Officer (DSO) for contractor employees on a case-by-case basis where justified by extenuating circumstances. The residency requirement does not apply to contractor employees residing in foreign countries that are hired to work in American embassies/consulates/missions located outside of the United States and who require access to DOJ information, IT systems, or unescorted access provided that an adequate background investigation can be conducted, with favorable adjudication, as determined by the

DSO.

(b) Citizenship. (1) Aside from the specific exceptions set forth in Section 1.2(b)(2), for Public Trust positions, the DOJ requires that contractor employees be U.S. citizens and nationals, or lawful permanent residents seeking U.S. citizenship. Any prospective non-U.S. citizen contractor employee who requires access to DOJ information systems, DOJ information, and/or unescorted facilities access must also have been granted a waiver as described below in paragraphs 1.2(d) and/or (e). The contractor is responsible for verifying that the non-U.S. citizens working under this contract are lawful permanent residents seeking U.S. citizenship.

(2) Exception for Certain Non-U.S. Citizen Contractor Employees: (i) Non-U.S. citizen expert witnesses, litigative consultants, and interpreters in rare foreign languages are not required to be lawful permanent residents seeking U.S. citizenship. However, they must be granted a waiver for access to unclassified DOJ information, whether CUI or not, DOJ IT systems, and/or unescorted facility access, as described below in paragraph 1.2(d) and (e), regardless of the duration of their duties. (ii) Non-U.S.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .