Combined Synopsis Solicitation_CDC_Comcast Renewal_75D301-23-Q-75953.pdf
PDF 535 KB Posted
- Attached to
- CDC Comcast Internet and Data Service Renewal 2023 - 2028 Federal contract opportunity
- Solicitation number
- 75D301-23-Q-75953
About this file
This is a combined synopsis/solicitation for commercial internet and data services from the Centers for Disease Control and Prevention. The CDC seeks to renew its Comcast internet and television services for five years from March 2023 through March 2028. Services required include commercial TV, internet circuits, and static IP addresses at multiple CDC locations in Atlanta, including buildings at 1600 Clifton Road, 4770 Buford Highway, and 2500 Century Parkway. The solicitation is issued as a request for quote using simplified acquisition procedures. Quotes are due by February 15, 2023. Evaluation will consider technical capacity, price, and past performance. The contract will have a base year and four option years subject to equitable price adjustment. The period of performance for the base year is March 11, 2023 through March 10, 2024.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Per FAR 12.206 (2)
(i) This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in
Federal Acquisition Requirements (FAR) Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested, and a written solicitation will not be issued.
(ii) The solicitation number for this requirement is 75D301-23-Q-75953 and is hereby issued as a Request for Quote (RFQ) using FAR Subpart 13.1 Simplified Acquisition Procedures.
iii) This solicitation document and incorporated provisions and clauses are those in effect through the
Federal Acquisition Circular (FAC) 2023-01 (December 30, 2022).
(iv) This acquisition is NOT set-aside under North American Industry Classification System (NAICS) code
515210. A Firm-Fixed Price with Economic Price Adjustment purchase order will be issued in writing to the successful offeror. To be eligible to receive an award resulting from this solicitation, contractor must be registered in the System for Award Management. To register apply via the Internet at http://www.sam.gov.
For questions on registration contact Federal Service Desk at 866-606-8220.
(v) The Centers for Disease Control and Prevention intends to award a contract for the following requirement, please either fill in the dollar amounts or provide a separate excel spreadsheet containing the same information including a list of line item number(s) and items, quantities, units of measure, and options, if applicable:
http://www.sam.gov/
Firm Fixed Price with Economic Price Adjustment
Base Period Items: 03/11/2023 – 03/10/2024
ITEM SUPPLIES / SERVICES QTY /
UNIT
UNIT
PRICE
EXTENDED
PRICE
0001 Commercial TV -- Standard
Channel Lineup 1600 Clifton RD
(BLDGS 16, 18, 19, 20, 21, 23, 24)
ACCOUNT #: 8220 20 416
0051160 renewal
12 Month
0002 Commercial TV -- Standard
Channel Lineup 4770 Buford
HWY (BLDGS 101, 102, 103, 106,
107, 109, 110)
12 Month
0003 Commercial TV -- Standard
Channel Lineup 2500 Century
PKWY NE
12 Month
0004 Commercial Internet Deluxe
250MB -- Equipment Fee -- 1 static
IP
12 Month
0005 CDC Chamblee PAN Bldg 101
Internet Serv Business Internet 150
12 Month
0006 CDC CSPO Bldg 101 Services
Business Internet 100
12 Month
0007 CDC Roybal Campus Bldg 23, Rm
2-616 Serv Business Internet 200
12 Month
0008 CDC Williams Bldg 4th Floor
Services Business Internet 300
12 Month
Option Period 1 Items: 03/11/2024 – 03/11/2025
UNIT
PRICE
EXTENDED
PRICE
1001 Commercial TV -- Standard
12 Month
1002 Commercial TV -- Standard
Channel Lineup 4770 Buford
12 Month
1003 Commercial TV -- Standard
12 Month
1004 Commercial Internet Deluxe
12 Month
1005 CDC Chamblee PAN Bldg 101
12 Month
1006 CDC CSPO Bldg 101 Services
12 Month
1007 CDC Roybal Campus Bldg 23, Rm
12 Month
1008 CDC Williams Bldg 4th Floor
Option Period 2 Items: 03/11/2025 – 03/10/2026
UNIT
PRICE
EXTENDED
PRICE
2001 Commercial TV -- Standard
12 Month
2002 Commercial TV -- Standard
Channel Lineup 4770 Buford
12 Month
2003 Commercial TV -- Standard
12 Month
2004 Commercial Internet Deluxe
12 Month
2005 CDC Chamblee PAN Bldg 101
12 Month
2006 CDC CSPO Bldg 101 Services
12 Month
2007 CDC Roybal Campus Bldg 23, Rm
12 Month
2008 CDC Williams Bldg 4th Floor
Option Period 3 Items: 03/11/2026 – 03/10/2027
UNIT
PRICE
EXTENDED
PRICE
3001 Commercial TV -- Standard
12 Month
3002 Commercial TV -- Standard
Channel Lineup 4770 Buford
12 Month
3003 Commercial TV -- Standard
12 Month
3004 Commercial Internet Deluxe
12 Month
3005 CDC Chamblee PAN Bldg 101
12 Month
3006 CDC CSPO Bldg 101 Services
12 Month
3007 CDC Roybal Campus Bldg 23, Rm
12 Month
3008 CDC Williams Bldg 4th Floor
Option Period 4 Items: 03/11/2027 – 03/10/2028
UNIT
PRICE
EXTENDED
PRICE
4001 Commercial TV -- Standard
12 Month
4002 Commercial TV -- Standard
Channel Lineup 4770 Buford
12 Month
4003 Commercial TV -- Standard
12 Month
4004 Commercial Internet Deluxe
12 Month
4005 CDC Chamblee PAN Bldg 101
12 Month
4006 CDC CSPO Bldg 101 Services
12 Month
4007 CDC Roybal Campus Bldg 23, Rm
12 Month
4008 CDC Williams Bldg 4th Floor
12 Month
(vi) CDC is seeking a renewal of their Comcast internet and TV services for the 5-year period of March 11, 2023 through March 10, 2028. This will include a base year contract with four-annual options, subject to
Equitable Price Adjustment per FAR 52.216-3.
(vii) Delivery Date: March 11, 2023
Delivery Address: Various CDC Atlanta-based Campuses
Acceptance and FOB point: CDC Project Officer (information to be released to awardee)
The quote format is at the discretion of the offeror.
It is the offeror's responsibility to be familiar with the applicable clauses and provisions. Clauses and provisions may be accessed via the Internet at website FAR | Acquisition.GOV
(viii) The provision at 52.212-1, Instructions to Offerors-Commercial Products and Commercial Services, applies to this acquisition and without any addenda to the provision.
(ix) The provision at 52.212-2, Evaluation-Commercial Products and Commercial Services, will be used, as follows:
EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)
(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the
Government, price and other factors considered. The following factors shall be used to evaluate offers: 1)
Technical Capacity to meet the Government Requirement; 2) Price and 4) Past Performance.
Technical and past performance, when combined, are more important than price.
(b) Options. The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. Evaluation of options shall not obligate the
Government to exercise the option(s).
(c) A written notice of award or acceptance of an offer, mailed or otherwise furnished to the successful offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer’s specified expiration time, the
Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.
(End of provision)
(x) Offerors are to include a completed copy of the provision at 52.212-3, Offeror Representations and
Certifications-Commercial Products and Commercial Services, with its offer.
(xi) The clause at 52.212-4, Contract Terms and Conditions-Commercial Products and Commercial
Services, applies to this acquisition without any addenda to the clause.
(xii) The clause at 52.212-5, Contract Terms and Conditions Required To Implement Statutes or Executive
Orders-Commercial Products and Commercial Services, applies to this acquisition. See Attachment 2 for additional information.
https://www.acquisition.gov/browse/index/far https://www.acquisition.gov/far/part-52#FAR_52_212_1 https://www.acquisition.gov/far/part-52#FAR_52_212_2 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_212_4 https://www.acquisition.gov/far/part-52#FAR_52_212_5
(xiii) See attachments for additional contract requirement(s) or terms and conditions determined by the contracting officer to be necessary for this acquisition and consistent with customary commercial practices.
(xiv) The Defense Priorities and Allocations System (DPAS) and assigned rating, is not applicable to this combined synopsis/solicitation.
(xv) No telephonic quotes will be processed. All responses must be received no later than 3:00 P.M., Eastern Standard Time on Wednesday, February 15, 2023. Please send any questions No Later Than
Tuesday, February 7, 2023.
All questions and quotes to be referred to (xvi) Nathan R. Amador at namador@cdc.gov, telephone
770.488.2690.
Include FAR 52.212-3, Offeror Representations and Certifications with Offer or indicate if it is available online at SAM.gov.
Attachments:
1. Statement of Work (SOW)
2. Clauses (separate document must include 52.212-1, 52.212-2 state how you will evaluate i.e. lowest priced technically acceptable offer (LPTA), 52.212-3, 52.212-4 (by reference) and 52.212-5 (check applicable clauses) mailto:namador@cdc.gov
Attachment 1: Statement of Work
Statement of Work
1T Period of Performance: 3/11/2023 – 3/10/2024
Title: Comcast Internet and Data Services
SECTION 1 – BACKGROUND
In metropolitan Atlanta Georgia, the Information Technology Services Office (ITSO), of CDC currently provides a robust, CATV/Data service. In the metropolitan Atlanta area, ITSO supports CATV/Data customers on three (3) major CDC campuses consisting of multiple buildings (an aggregate of approximately 16 buildings) and three (3) distinct sites, in either a single building or in shared space.
Currently, the CDC Atlanta locations have approximately 2500 CATV ports and 15 Data ports/circuits.
SECTION 2 - PROJECT OBJECTIVE:
The objective of this contract is to maintain an integrated Community Antenna Television or Cable
Television and high speed internet data circuits (CATV/Data) Solution that best satisfies the Government’s need and provide Internet and data services to the following CDC locations in Atlanta, GA: 1600 Clifton
Road (Buildings 16, 18, 19, 20, 21, 23, 24); 4770 Buford Highway (Buildings 101, 102, 103, 106, 107, 109, 110); 2500 Century Parkway NE; and Static IP V4/V6 services. In articulating the Centers for Disease
Control and Prevention’s (CDC’s) requirements within this statement of work (SOW), the primary goal is to provide best value to the CDC while increasing the performance and service levels provided to the programs and employees of the CDC. Every aspect of this SOW shall be conducted as such that the risk of loss of service to the CDC and/or disruption to the business operations of the CDC is minimized. The expected outcome is providing best value and increase in service levels and performance.
SECTION 3 - SCOPE OF WORK:
For the purposes of this SOW, the scope of CATV/Data services is defined to include the operations, management, maintenance and support of an integrated CATV/Data service. The solicitation requires an all-inclusive estimated total fixed price that meets the minimum requirements and incorporates the entire solution. It is a requirement of the Government that equipment/services (including but not limited to upgrades, hardware, software, firmware, etc.) are included in the ongoing maintenance and management provided to the Government as a part of the offered solution.
SECTION 4 - TECHNICAL REQUIREMENTS
1) The contract goes into effect 3/11/2023 and shall terminate on 3/10/2024
2) Provide full 24x7x365 support of the integrated CATV/Data services at the Royal (Clifton
Road), Chamblee and Century Center campuses.
3) If problems cannot be solved by phone or remote access, on-site support is required immediately.
4) Provide CDC with a integrated and robust CATV/Data service.
5) Provide CDC with the choice to select channels broadcasted on campus.
6) Provide Local and National weather and news services with no additional costs.
SECTION 5 - REPORTING SCHEDULE:
See Deliverables below
SECTION 6 - CONTRACTOR TRAVEL
None
SECTION 7 - GOVERNMENT FURNISHED MATERIALS:
SECTION 8 - DELIVERABLES/DELIVERY SCHEDULE:
The Contractor shall provide the following deliverables for review and acceptance by the COR. The deliverables listed in this section are the minimum desired from the successful Contractor. OCIO reserves the right to make changes to the deliverables and the deliverable schedule:
1) Comcast Internet and Data Service
2) CDC-Wide Integrated Community Antenna Television and/or Cable Television and high-speed internet data circuits (CATV/Data) Solution in the following CDC Bldgs:
• 1600 Clifton Road (Buildings 16, 18, 19, 20, 21, 23, 24)
• 4770 Buford Highway (Buildings 101, 102, 103, 106, 107, 109, 110)
• 2500 Century Parkway NE
• Deluxe 250; Static IP V4/V6
• CDC Williams Bldg 4th Floor Internet Circuit
• CDC Roybal Campus Internet Circuit CDC Chamblee PAN
• Bldg 101 Internet Circuit CDC CSPO
• Bldg 101 Internet Circuit
SECTION 9 - SPECIAL CONSIDERATIONS
SECTION 10 – PoP Dates
Base Year: 3/11/23 thru 3/10/24
Option Year 1: 3/11/24 thru 3/10/25
Option Year 2: 3/11/25 thru 3/10/26
Option Year 3: 3/11/26 thru 3/10/27
Option Year 4: 3/11/27 thru 3/10/28
SECTION 11- Identification of CDC POC
Nathan R. Amador, Contracting Officer, CDC/OCOO/OFR/OAS
Email: namador@cdc.gov
Telephone: 770.488.2690
SECTION 12 - Security Requirements:
mailto:namador@cdc.gov
INFORMATION SECURITY REQUIREMENTS
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter
“contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the
HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services
(including support services), and related resources.
2) Safeguarding Information and Information Systems. In accordance with the Federal
Information Processing Standards Publication (FIPS)199, Standards for Security
Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS
Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed..
3) Information Security Categorization. In accordance with FIPS 199 and National Institute of
Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to
Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf
Confidentiality: [X] Low [ ] Moderate [ ] High
Integrity: [X] Low [ ] Moderate [ ] High
Availability: [X] Low [ ] Moderate [ ] High
Overall Risk Level: [X] Low [ ] Moderate [ ] High
Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:
[ X ] No PII [ ] Yes PII
Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB)
Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.
4) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with
Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
b. disclosed to authorized personnel on a Need-To-Know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal
Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified
Information in Nonfederal Information Systems and Organizations if handled by internal
Contractor system; and
d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP
800-88, Guidelines for Media Sanitization.
5) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The
Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency
Information by securing it with a FIPS 140-2 validated solution.
6) Confidentiality and Nondisclosure of Information. Any information provided to the contractor
(and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of
Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and CDC policies. Unauthorized disclosure of information will be subject to the
HHS/CDC sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
7) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with
OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
8) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of
Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security
(HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain
HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
9) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
10) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information
[PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
d. Verify that the encryption solutions in use have been validated under the Cryptographic
Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR and ISSO within 30 days of contract award.
e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to the COR upon request and at the conclusion of the contract.
11) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
12) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf full PIA needs to be completed.
a. If the results of the PTA show that a full PIA is needed, the Contractor shall assist the CDC
SOP or designee with completing a PIA for the system or information within 30 days after completion of the PTA and in accordance with HHS policy and OMB M-03-22, Guidance for
Implementing the Privacy Provisions of the E-Government Act of 2002.
b. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor
Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC specific Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security
Responsibilities Memorandum.
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, and any CDC-specific rules, as applicable.
2) All Contractor employees performing on the contract must read and adhere to the Rules of
Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Information Security Awareness
Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
D. Incident Response
The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/CDC CSIRT teams within 24 hours, whether the response is positive or negative.
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act
(FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy
Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving
PII” .
In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:
1) Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS
140-2 validated encryption.
2) NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send CDC approved notifications to affected individuals following CDC’s designated process.
3) Report all suspected and confirmed information security and privacy incidents and breaches to the
CDC’s Computer Security Incident Response Team (CSIRT) [CSIRT@CDC.gov], COR, CO, CDC SOP (or his or her designee), and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour, and consistent with the applicable CDC and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum:
company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:
a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
b. not include any sensitive information in the subject or body of any reporting e-mail; and
c. encrypt sensitive information in attachments to email, media, etc.
4) Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally
Identifiable Information HHS and CDC’s incident response policies when handling PII breaches.
5) Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the
Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation.
E. Position Sensitivity Designations
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of
Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract:
Not Applicable
X Level 1: Non-sensitive
Level 2: Non-critical
Sensitive
Level 3: Critical
Sensitive
Level 4: Special
Sensitive
Level 5: Public Trust/Moderate Risk
Level 6: Public Trust/High Risk
F. Homeland Security Presidential Directive (HSPD)-12
The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security
Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2. For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12)
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO within the CDC Specified timeline of the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within 7 days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the
Government will determine the appropriate suitability level.
G. Contract Initiation and Expiration
1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the CDC EPLC framework and methodology and in accordance with the HHS Contract Closeout Guide (2012). CDC EPLC requirements may be located here: https://www2a.CDC.gov/CDCup/library/other/eplc.htm.
2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST
SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
3) Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
4) Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO within 7 days before an employee stops working under this contract.
5) Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the https://www.dhs.gov/homeland-security-presidential-directive-12 https://www2a.cdc.gov/cdcup/library/other/eplc.htm term of this contract to the CO and/or COR. Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from
Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or CDC policies.
6) The Contractor (and/or any subcontractor) shall perform and document the actions identified in the
CDC Contractor Employee Separation Checklist when an employee terminates work under this contract within 7 days of the employee’s exit from the contract. All documentation shall be made available to the CO and/or COR upon request.
H. Records Management and Retention
The Contractor (and/or any subcontractor) shall maintain all information in accordance with
Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records
Administration (NARA) records retention policies and schedules and HHS/CDC policies and shall not dispose of any records unless authorized by HHS/CDC.
In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS/CDC policies.
(End of clause)
SECTION 13 –
HHSAR 352.239-73 Electronic and Information Technology Accessibility Notice (December 18, 2015)
(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce
Investment Act of 1998 and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Standards (36 CFR part 1194), require that when Federal agencies develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by
Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.
(b) Accordingly, any offeror responding to this solicitation must comply with established HHS EIT accessibility standards. Information about Section 508 is available at https://www.hhs.gov/web/508. The complete text of the Section 508 Final Provisions can be accessed at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards.
(c) The Section 508 accessibility standards applicable to this solicitation are stated in the clause at 352.239-
74, Electronic and Information Technology Accessibility.
In order to facilitate the Government’s determination whether proposed EIT supplies meet applicable
Section 508 accessibility standards, offerors must submit an HHS Section 508 Product Assessment
Template, in accordance with its completion instructions. The purpose of the template is to assist HHS acquisition and program officials in determining whether proposed EIT supplies conform to applicable
Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and document—in detail—whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the HHS https://www.hhs.gov/web/508 https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.hhs.gov/grants/contracts/contract-policies-regulations/hhsar/part-352-solicitation-provisions-contract-clauses/index.html#352.239-74 https://www.hhs.gov/grants/contracts/contract-policies-regulations/hhsar/part-352-solicitation-provisions-contract-clauses/index.html#352.239-74
Section 508 Evaluation Template are available under Section 508 policy on the HHS website https://www.hhs.gov/web/508.
In order to facilitate the Government’s determination whether proposed EIT services meet applicable
Section 508 accessibility standards, offerors must provide enough information to assist the Government in determining that the EIT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.
(d) Respondents to this solicitation must identify any exception to Section 508 requirements. If a offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the described accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.
(End of provision)
HHSAR 352.239-74 Electronic and Information Technology Accessibility (December 18, 2015)
(a) Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the
Workforce Investment Act of 1998, all electronic and information technology (EIT) supplies and services developed, acquired, or maintained under this contract or order must comply with the “Architectural and
Transportation Barriers Compliance Board Electronic and Information Technology (EIT) Accessibility
Standards” set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in 36 CFR part 1194. Information about Section 508 is available at https://www.hhs.gov/web/508. The complete text of Section 508 Final Provisions can be accessed at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards.
(b) The Section 508 accessibility standards applicable to this contract or order are identified in the
Statement of Work or Specification or Performance Work Statement. The contractor must provide any necessary updates to the submitted HHS Product Assessment Template(s) at the end of each contract or order exceeding the simplified acquisition threshold (see FAR 2.101) when the contract or order duration is one year or less. If it is determined by the Government that EIT supplies and services provided by the
Contractor do not conform to the described accessibility standards in the contract, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the
Contractor at its own expense.
(c) The Section 508 accessibility standards applicable to this contract are: 1194.
205 WCAG 2.0 Level A & AA Success Criteria
302 Functional Performance Criteria
502 Inoperability with Assistive Technology
504 Authoring Tools
602 Support Documentation
603 Support Services
(d) In the event of a modification(s) to this contract or order, which adds new EIT supplies or services or revises the type of, or specifications for, supplies or services, the Contracting Officer may require that the contractor submit a completed HHS Section 508 Product Assessment Template and any other additional information necessary to assist the Government in determining that the EIT supplies or services conform to
Section 508 accessibility standards. Instructions for documenting accessibility via the HHS Section 508
Product Assessment Template may be found under Section 508 policy on the HHS website:
(https://www.hhs.gov/web/508). If it is determined by the Government that EIT supplies and services provided by the Contractor do not conform to the described accessibility standards in the contract, https://www.hhs.gov/web/508 https://www.hhs.gov/web/508 https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.ecfr.gov/cgi-bin/text-idx?node=pt48.1.2#se48.1.2_1101 https://www.hhs.gov/web/508 remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its own expense.
(e) If this is an Indefinite Delivery contract, a Blanket Purchase Agreement or a Basic Ordering Agreement, the task/delivery order requests that include EIT supplies or services will define the specifications and accessibility standards for the order. In those cases, the Contractor may be required to provide a completed
HHS Section 508 Product Assessment Template and any other additional information necessary to assist the Government in determining that the EIT supplies or services conform to Section 508 accessibility standards. Instructions for documenting accessibility via the HHS Section 508 Product Assessment
Template may be found at https://www.hhs.gov/web/508. If it is determined by the Government that EIT supplies and services provided by the Contractor do not conform to the described accessibility standards in the provided documentation, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its own expense.
https://www.hhs.gov/web/508
Attachment 2 – Clauses
SOURCE FAR/ HHSAR TITLE AND DATE
52.204-13 FAR System for Award Management Maintenance (Oct 2018)
52.204-18 FAR Commercial and Government Entity Code Maintenance (Aug 2020)
52.212-1 FAR Instructions to Offerors – Commercial Products and Commercial Services (Nov 2021)
52.212-3 FAR Offeror Representations and Certifications – Commercial Products and Commercial Services
(Dec 2022) via www.SAM.gov
52.212-4 FAR Contract Terms and Conditions- Commercial Items (Oct 2018)
52.217-5 FAR Evaluation of Options (July 1990)
52.232-39 FAR Unenforceability of Unauthorized Obligations (Jun 2013)
52.232-40 FAR Providing Accelerated Payments to Small Business Contractors (Nov 2022)
352.222-70 HHSAR Contractor Cooperation in Equal Employment Opportunity Investigations (Dec 2015)
352.203-70 HHSAR Anti-Lobbying (Dec 2015)
352.208-70 HHSAR Printing and Duplication (Dec 2015)
352.222-70 HHSAR Contractor Cooperation in Equal Employment Opportunity Investigations (Dec 2015)
352.224-70 HHSAR Privacy Act (Dec 2015)
352.227-70 HHSAR Publications and Publicity (Dec 2015)
FAR 52.252-2 -- CLAUSES INCORPORATED BY REFERENCE. (Feb 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):
http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/far1toc.htm http://www.hhs.gov/policies/hhsar/subpart301-1.html
(End of Clause)
52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)
(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the
Government, price and other factors considered. The following factors shall be used to evaluate offers: 1)
Technical Capacity to meet the Government Requirement; 2) Price and 4) Past Performance.
Technical and past performance, when combined, are more important than price.
(b) Options. The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. Evaluation of options shall not obligate the
Government to exercise the option(s).
(c) A written notice of award or acceptance of an offer, mailed or otherwise furnished to the successful offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer’s specified expiration time, the
Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.
http://www.sam.gov/ http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/far1toc.htm http://www.hhs.gov/policies/hhsar/subpart301-1.html
(End of provision)
FAR 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive
Orders—Commercial Products and Commercial Services. (DEC 2022)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN
2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations
Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).
(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance
Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).
(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015).
(5) 52.233-3, Protest After Award (AUG 1996) ( 31 U.S.C. 3553).
(6) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and 108-
78 ( 19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting
Officer has indicated as being incorporated in this contract by reference to implement provisions of law or
Executive orders applicable to acquisitions of commercial products and commercial services:
_X_ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (JUN
2020), with Alternate I (NOV 2021) ( 41 U.S.C. 4704 and 10 U.S.C. 4655).
_X_ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (NOV 2021) ( 41 U.S.C. 3509)).
__ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of
2009 (JUN 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American
Recovery and Reinvestment Act of 2009.)
_X_ (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (JUN
2020) (Pub. L. 109-282) ( 31 U.S.C. 6101 note).
__ (5) [Reserved].
__ (6) 52.204-14, Service Contract Reporting Requirements (OCT 2016) (Pub. L. 111-117, section
743 of Div. C).
__ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (OCT
2016) (Pub. L. 111-117, section 743 of Div. C).
https://www.acquisition.gov/far/part-52#FAR_52_203_19 https://www.acquisition.gov/far/part-52#FAR_52_204_23 https://www.acquisition.gov/far/part-52#FAR_52_204_25 https://www.acquisition.gov/far/part-52#FAR_52_209_10 https://www.acquisition.gov/far/part-52#FAR_52_233_3 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_233_4 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_203_6…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .