Combined Synopsis Solicitation_CDC_Comcast Renewal_75D301-23-Q-75953.pdf

PDF 535 KB Posted

Attached to
CDC Comcast Internet and Data Service Renewal 2023 - 2028 Federal contract opportunity
Solicitation number
75D301-23-Q-75953
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

This is a combined synopsis/solicitation for commercial internet and data services from the Centers for Disease Control and Prevention. The CDC seeks to renew its Comcast internet and television services for five years from March 2023 through March 2028. Services required include commercial TV, internet circuits, and static IP addresses at multiple CDC locations in Atlanta, including buildings at 1600 Clifton Road, 4770 Buford Highway, and 2500 Century Parkway. The solicitation is issued as a request for quote using simplified acquisition procedures. Quotes are due by February 15, 2023. Evaluation will consider technical capacity, price, and past performance. The contract will have a base year and four option years subject to equitable price adjustment. The period of performance for the base year is March 11, 2023 through March 10, 2024.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Per FAR 12.206 (2)

(i) This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in

Federal Acquisition Requirements (FAR) Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested, and a written solicitation will not be issued.

(ii) The solicitation number for this requirement is 75D301-23-Q-75953 and is hereby issued as a Request for Quote (RFQ) using FAR Subpart 13.1 Simplified Acquisition Procedures.

iii) This solicitation document and incorporated provisions and clauses are those in effect through the

Federal Acquisition Circular (FAC) 2023-01 (December 30, 2022).

(iv) This acquisition is NOT set-aside under North American Industry Classification System (NAICS) code

515210. A Firm-Fixed Price with Economic Price Adjustment purchase order will be issued in writing to the successful offeror. To be eligible to receive an award resulting from this solicitation, contractor must be registered in the System for Award Management. To register apply via the Internet at http://www.sam.gov.

For questions on registration contact Federal Service Desk at 866-606-8220.

(v) The Centers for Disease Control and Prevention intends to award a contract for the following requirement, please either fill in the dollar amounts or provide a separate excel spreadsheet containing the same information including a list of line item number(s) and items, quantities, units of measure, and options, if applicable:

http://www.sam.gov/

Firm Fixed Price with Economic Price Adjustment

Base Period Items: 03/11/2023 – 03/10/2024

ITEM SUPPLIES / SERVICES QTY /

UNIT

UNIT

PRICE

EXTENDED

PRICE

0001 Commercial TV -- Standard

Channel Lineup 1600 Clifton RD

(BLDGS 16, 18, 19, 20, 21, 23, 24)

ACCOUNT #: 8220 20 416

0051160 renewal

12 Month

0002 Commercial TV -- Standard

Channel Lineup 4770 Buford

HWY (BLDGS 101, 102, 103, 106,

107, 109, 110)

12 Month

0003 Commercial TV -- Standard

Channel Lineup 2500 Century

PKWY NE

12 Month

0004 Commercial Internet Deluxe

250MB -- Equipment Fee -- 1 static

IP

12 Month

0005 CDC Chamblee PAN Bldg 101

Internet Serv Business Internet 150

12 Month

0006 CDC CSPO Bldg 101 Services

Business Internet 100

12 Month

0007 CDC Roybal Campus Bldg 23, Rm

2-616 Serv Business Internet 200

12 Month

0008 CDC Williams Bldg 4th Floor

Services Business Internet 300

12 Month

Option Period 1 Items: 03/11/2024 – 03/11/2025

UNIT

PRICE

EXTENDED

PRICE

1001 Commercial TV -- Standard

12 Month

1002 Commercial TV -- Standard

Channel Lineup 4770 Buford

12 Month

1003 Commercial TV -- Standard

12 Month

1004 Commercial Internet Deluxe

12 Month

1005 CDC Chamblee PAN Bldg 101

12 Month

1006 CDC CSPO Bldg 101 Services

12 Month

1007 CDC Roybal Campus Bldg 23, Rm

12 Month

1008 CDC Williams Bldg 4th Floor

Option Period 2 Items: 03/11/2025 – 03/10/2026

UNIT

PRICE

EXTENDED

PRICE

2001 Commercial TV -- Standard

12 Month

2002 Commercial TV -- Standard

Channel Lineup 4770 Buford

12 Month

2003 Commercial TV -- Standard

12 Month

2004 Commercial Internet Deluxe

12 Month

2005 CDC Chamblee PAN Bldg 101

12 Month

2006 CDC CSPO Bldg 101 Services

12 Month

2007 CDC Roybal Campus Bldg 23, Rm

12 Month

2008 CDC Williams Bldg 4th Floor

Option Period 3 Items: 03/11/2026 – 03/10/2027

UNIT

PRICE

EXTENDED

PRICE

3001 Commercial TV -- Standard

12 Month

3002 Commercial TV -- Standard

Channel Lineup 4770 Buford

12 Month

3003 Commercial TV -- Standard

12 Month

3004 Commercial Internet Deluxe

12 Month

3005 CDC Chamblee PAN Bldg 101

12 Month

3006 CDC CSPO Bldg 101 Services

12 Month

3007 CDC Roybal Campus Bldg 23, Rm

12 Month

3008 CDC Williams Bldg 4th Floor

Option Period 4 Items: 03/11/2027 – 03/10/2028

UNIT

PRICE

EXTENDED

PRICE

4001 Commercial TV -- Standard

12 Month

4002 Commercial TV -- Standard

Channel Lineup 4770 Buford

12 Month

4003 Commercial TV -- Standard

12 Month

4004 Commercial Internet Deluxe

12 Month

4005 CDC Chamblee PAN Bldg 101

12 Month

4006 CDC CSPO Bldg 101 Services

12 Month

4007 CDC Roybal Campus Bldg 23, Rm

12 Month

4008 CDC Williams Bldg 4th Floor

12 Month

(vi) CDC is seeking a renewal of their Comcast internet and TV services for the 5-year period of March 11, 2023 through March 10, 2028. This will include a base year contract with four-annual options, subject to

Equitable Price Adjustment per FAR 52.216-3.

(vii) Delivery Date: March 11, 2023

Delivery Address: Various CDC Atlanta-based Campuses

Acceptance and FOB point: CDC Project Officer (information to be released to awardee)

The quote format is at the discretion of the offeror.

It is the offeror's responsibility to be familiar with the applicable clauses and provisions. Clauses and provisions may be accessed via the Internet at website FAR | Acquisition.GOV

(viii) The provision at 52.212-1, Instructions to Offerors-Commercial Products and Commercial Services, applies to this acquisition and without any addenda to the provision.

(ix) The provision at 52.212-2, Evaluation-Commercial Products and Commercial Services, will be used, as follows:

EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)

(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the

Government, price and other factors considered. The following factors shall be used to evaluate offers: 1)

Technical Capacity to meet the Government Requirement; 2) Price and 4) Past Performance.

Technical and past performance, when combined, are more important than price.

(b) Options. The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. Evaluation of options shall not obligate the

Government to exercise the option(s).

(c) A written notice of award or acceptance of an offer, mailed or otherwise furnished to the successful offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer’s specified expiration time, the

Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.

(End of provision)

(x) Offerors are to include a completed copy of the provision at 52.212-3, Offeror Representations and

Certifications-Commercial Products and Commercial Services, with its offer.

(xi) The clause at 52.212-4, Contract Terms and Conditions-Commercial Products and Commercial

Services, applies to this acquisition without any addenda to the clause.

(xii) The clause at 52.212-5, Contract Terms and Conditions Required To Implement Statutes or Executive

Orders-Commercial Products and Commercial Services, applies to this acquisition. See Attachment 2 for additional information.

https://www.acquisition.gov/browse/index/far https://www.acquisition.gov/far/part-52#FAR_52_212_1 https://www.acquisition.gov/far/part-52#FAR_52_212_2 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_212_4 https://www.acquisition.gov/far/part-52#FAR_52_212_5

(xiii) See attachments for additional contract requirement(s) or terms and conditions determined by the contracting officer to be necessary for this acquisition and consistent with customary commercial practices.

(xiv) The Defense Priorities and Allocations System (DPAS) and assigned rating, is not applicable to this combined synopsis/solicitation.

(xv) No telephonic quotes will be processed. All responses must be received no later than 3:00 P.M., Eastern Standard Time on Wednesday, February 15, 2023. Please send any questions No Later Than

Tuesday, February 7, 2023.

All questions and quotes to be referred to (xvi) Nathan R. Amador at namador@cdc.gov, telephone

770.488.2690.

Include FAR 52.212-3, Offeror Representations and Certifications with Offer or indicate if it is available online at SAM.gov.

Attachments:

1. Statement of Work (SOW)

2. Clauses (separate document must include 52.212-1, 52.212-2 state how you will evaluate i.e. lowest priced technically acceptable offer (LPTA), 52.212-3, 52.212-4 (by reference) and 52.212-5 (check applicable clauses) mailto:namador@cdc.gov

Attachment 1: Statement of Work

Statement of Work

1T Period of Performance: 3/11/2023 – 3/10/2024

Title: Comcast Internet and Data Services

SECTION 1 – BACKGROUND

In metropolitan Atlanta Georgia, the Information Technology Services Office (ITSO), of CDC currently provides a robust, CATV/Data service. In the metropolitan Atlanta area, ITSO supports CATV/Data customers on three (3) major CDC campuses consisting of multiple buildings (an aggregate of approximately 16 buildings) and three (3) distinct sites, in either a single building or in shared space.

Currently, the CDC Atlanta locations have approximately 2500 CATV ports and 15 Data ports/circuits.

SECTION 2 - PROJECT OBJECTIVE:

The objective of this contract is to maintain an integrated Community Antenna Television or Cable

Television and high speed internet data circuits (CATV/Data) Solution that best satisfies the Government’s need and provide Internet and data services to the following CDC locations in Atlanta, GA: 1600 Clifton

Road (Buildings 16, 18, 19, 20, 21, 23, 24); 4770 Buford Highway (Buildings 101, 102, 103, 106, 107, 109, 110); 2500 Century Parkway NE; and Static IP V4/V6 services. In articulating the Centers for Disease

Control and Prevention’s (CDC’s) requirements within this statement of work (SOW), the primary goal is to provide best value to the CDC while increasing the performance and service levels provided to the programs and employees of the CDC. Every aspect of this SOW shall be conducted as such that the risk of loss of service to the CDC and/or disruption to the business operations of the CDC is minimized. The expected outcome is providing best value and increase in service levels and performance.

SECTION 3 - SCOPE OF WORK:

For the purposes of this SOW, the scope of CATV/Data services is defined to include the operations, management, maintenance and support of an integrated CATV/Data service. The solicitation requires an all-inclusive estimated total fixed price that meets the minimum requirements and incorporates the entire solution. It is a requirement of the Government that equipment/services (including but not limited to upgrades, hardware, software, firmware, etc.) are included in the ongoing maintenance and management provided to the Government as a part of the offered solution.

SECTION 4 - TECHNICAL REQUIREMENTS

1) The contract goes into effect 3/11/2023 and shall terminate on 3/10/2024

2) Provide full 24x7x365 support of the integrated CATV/Data services at the Royal (Clifton

Road), Chamblee and Century Center campuses.

3) If problems cannot be solved by phone or remote access, on-site support is required immediately.

4) Provide CDC with a integrated and robust CATV/Data service.

5) Provide CDC with the choice to select channels broadcasted on campus.

6) Provide Local and National weather and news services with no additional costs.

SECTION 5 - REPORTING SCHEDULE:

See Deliverables below

SECTION 6 - CONTRACTOR TRAVEL

None

SECTION 7 - GOVERNMENT FURNISHED MATERIALS:

SECTION 8 - DELIVERABLES/DELIVERY SCHEDULE:

The Contractor shall provide the following deliverables for review and acceptance by the COR. The deliverables listed in this section are the minimum desired from the successful Contractor. OCIO reserves the right to make changes to the deliverables and the deliverable schedule:

1) Comcast Internet and Data Service

2) CDC-Wide Integrated Community Antenna Television and/or Cable Television and high-speed internet data circuits (CATV/Data) Solution in the following CDC Bldgs:

• 1600 Clifton Road (Buildings 16, 18, 19, 20, 21, 23, 24)

• 4770 Buford Highway (Buildings 101, 102, 103, 106, 107, 109, 110)

• 2500 Century Parkway NE

• Deluxe 250; Static IP V4/V6

• CDC Williams Bldg 4th Floor Internet Circuit

• CDC Roybal Campus Internet Circuit CDC Chamblee PAN

• Bldg 101 Internet Circuit CDC CSPO

• Bldg 101 Internet Circuit

SECTION 9 - SPECIAL CONSIDERATIONS

SECTION 10 – PoP Dates

Base Year: 3/11/23 thru 3/10/24

Option Year 1: 3/11/24 thru 3/10/25

Option Year 2: 3/11/25 thru 3/10/26

Option Year 3: 3/11/26 thru 3/10/27

Option Year 4: 3/11/27 thru 3/10/28

SECTION 11- Identification of CDC POC

Nathan R. Amador, Contracting Officer, CDC/OCOO/OFR/OAS

Email: namador@cdc.gov

Telephone: 770.488.2690

SECTION 12 - Security Requirements:

mailto:namador@cdc.gov

INFORMATION SECURITY REQUIREMENTS

A. Baseline Security Requirements

1) Applicability. The requirements herein apply whether the entire contract or order (hereafter

“contract”), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the

HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services

(including support services), and related resources.

2) Safeguarding Information and Information Systems. In accordance with the Federal

Information Processing Standards Publication (FIPS)199, Standards for Security

Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS

Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed..

3) Information Security Categorization. In accordance with FIPS 199 and National Institute of

Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to

Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf

Confidentiality: [X] Low [ ] Moderate [ ] High

Integrity: [X] Low [ ] Moderate [ ] High

Availability: [X] Low [ ] Moderate [ ] High

Overall Risk Level: [X] Low [ ] Moderate [ ] High

Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[ X ] No PII [ ] Yes PII

Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB)

Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.

4) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with

Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:

a. marked appropriately;

b. disclosed to authorized personnel on a Need-To-Know basis;

c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal

Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified

Information in Nonfederal Information Systems and Organizations if handled by internal

Contractor system; and

d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.

Destruction of information and/or data shall be accomplished in accordance with NIST SP

800-88, Guidelines for Media Sanitization.

5) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The

Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency

Information by securing it with a FIPS 140-2 validated solution.

6) Confidentiality and Nondisclosure of Information. Any information provided to the contractor

(and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of

Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and CDC policies. Unauthorized disclosure of information will be subject to the

HHS/CDC sanction policies and/or governed by the following laws and regulations:

a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

7) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with

OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).

8) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of

Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security

(HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain

HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.

9) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.

10) Standard for Encryption. The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information

[PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.

c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use have been validated under the Cryptographic

Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR and ISSO within 30 days of contract award.

e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to the COR upon request and at the conclusion of the contract.

11) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.

12) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf full PIA needs to be completed.

a. If the results of the PTA show that a full PIA is needed, the Contractor shall assist the CDC

SOP or designee with completing a PIA for the system or information within 30 days after completion of the PTA and in accordance with HHS policy and OMB M-03-22, Guidance for

Implementing the Privacy Provisions of the E-Government Act of 2002.

b. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.

B. Training

1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor

Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC specific Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.

2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security

Responsibilities Memorandum.

3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

C. Rules of Behavior

1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, and any CDC-specific rules, as applicable.

2) All Contractor employees performing on the contract must read and adhere to the Rules of

Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Information Security Awareness

Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.

D. Incident Response

The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/CDC CSIRT teams within 24 hours, whether the response is positive or negative.

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act

(FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy

Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving

PII” .

In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:

1) Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS

140-2 validated encryption.

2) NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send CDC approved notifications to affected individuals following CDC’s designated process.

3) Report all suspected and confirmed information security and privacy incidents and breaches to the

CDC’s Computer Security Incident Response Team (CSIRT) [CSIRT@CDC.gov], COR, CO, CDC SOP (or his or her designee), and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour, and consistent with the applicable CDC and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum:

company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:

a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;

b. not include any sensitive information in the subject or body of any reporting e-mail; and

c. encrypt sensitive information in attachments to email, media, etc.

4) Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally

Identifiable Information HHS and CDC’s incident response policies when handling PII breaches.

5) Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the

Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation.

E. Position Sensitivity Designations

All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of

Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract:

Not Applicable

X Level 1: Non-sensitive

Level 2: Non-critical

Sensitive

Level 3: Critical

Sensitive

Level 4: Special

Sensitive

Level 5: Public Trust/Moderate Risk

Level 6: Public Trust/High Risk

F. Homeland Security Presidential Directive (HSPD)-12

The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security

Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2. For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12)

Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO within the CDC Specified timeline of the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within 7 days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.

If the employee is filling a new position, the Contractor shall provide a position description and the

Government will determine the appropriate suitability level.

G. Contract Initiation and Expiration

1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the CDC EPLC framework and methodology and in accordance with the HHS Contract Closeout Guide (2012). CDC EPLC requirements may be located here: https://www2a.CDC.gov/CDCup/library/other/eplc.htm.

2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST

SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.

3) Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

4) Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO within 7 days before an employee stops working under this contract.

5) Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the https://www.dhs.gov/homeland-security-presidential-directive-12 https://www2a.cdc.gov/cdcup/library/other/eplc.htm term of this contract to the CO and/or COR. Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from

Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or CDC policies.

6) The Contractor (and/or any subcontractor) shall perform and document the actions identified in the

CDC Contractor Employee Separation Checklist when an employee terminates work under this contract within 7 days of the employee’s exit from the contract. All documentation shall be made available to the CO and/or COR upon request.

H. Records Management and Retention

The Contractor (and/or any subcontractor) shall maintain all information in accordance with

Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records

Administration (NARA) records retention policies and schedules and HHS/CDC policies and shall not dispose of any records unless authorized by HHS/CDC.

In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS/CDC policies.

(End of clause)

SECTION 13 –

HHSAR 352.239-73 Electronic and Information Technology Accessibility Notice (December 18, 2015)

(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce

Investment Act of 1998 and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Standards (36 CFR part 1194), require that when Federal agencies develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by

Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.

(b) Accordingly, any offeror responding to this solicitation must comply with established HHS EIT accessibility standards. Information about Section 508 is available at https://www.hhs.gov/web/508. The complete text of the Section 508 Final Provisions can be accessed at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards.

(c) The Section 508 accessibility standards applicable to this solicitation are stated in the clause at 352.239-

74, Electronic and Information Technology Accessibility.

In order to facilitate the Government’s determination whether proposed EIT supplies meet applicable

Section 508 accessibility standards, offerors must submit an HHS Section 508 Product Assessment

Template, in accordance with its completion instructions. The purpose of the template is to assist HHS acquisition and program officials in determining whether proposed EIT supplies conform to applicable

Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and document—in detail—whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the HHS https://www.hhs.gov/web/508 https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.hhs.gov/grants/contracts/contract-policies-regulations/hhsar/part-352-solicitation-provisions-contract-clauses/index.html#352.239-74 https://www.hhs.gov/grants/contracts/contract-policies-regulations/hhsar/part-352-solicitation-provisions-contract-clauses/index.html#352.239-74

Section 508 Evaluation Template are available under Section 508 policy on the HHS website https://www.hhs.gov/web/508.

In order to facilitate the Government’s determination whether proposed EIT services meet applicable

Section 508 accessibility standards, offerors must provide enough information to assist the Government in determining that the EIT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.

(d) Respondents to this solicitation must identify any exception to Section 508 requirements. If a offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the described accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.

(End of provision)

HHSAR 352.239-74 Electronic and Information Technology Accessibility (December 18, 2015)

(a) Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the

Workforce Investment Act of 1998, all electronic and information technology (EIT) supplies and services developed, acquired, or maintained under this contract or order must comply with the “Architectural and

Transportation Barriers Compliance Board Electronic and Information Technology (EIT) Accessibility

Standards” set forth by the Architectural and Transportation Barriers Compliance Board (also referred to as the “Access Board”) in 36 CFR part 1194. Information about Section 508 is available at https://www.hhs.gov/web/508. The complete text of Section 508 Final Provisions can be accessed at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards.

(b) The Section 508 accessibility standards applicable to this contract or order are identified in the

Statement of Work or Specification or Performance Work Statement. The contractor must provide any necessary updates to the submitted HHS Product Assessment Template(s) at the end of each contract or order exceeding the simplified acquisition threshold (see FAR 2.101) when the contract or order duration is one year or less. If it is determined by the Government that EIT supplies and services provided by the

Contractor do not conform to the described accessibility standards in the contract, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the

Contractor at its own expense.

(c) The Section 508 accessibility standards applicable to this contract are: 1194.

205 WCAG 2.0 Level A & AA Success Criteria

302 Functional Performance Criteria

502 Inoperability with Assistive Technology

504 Authoring Tools

602 Support Documentation

603 Support Services

(d) In the event of a modification(s) to this contract or order, which adds new EIT supplies or services or revises the type of, or specifications for, supplies or services, the Contracting Officer may require that the contractor submit a completed HHS Section 508 Product Assessment Template and any other additional information necessary to assist the Government in determining that the EIT supplies or services conform to

Section 508 accessibility standards. Instructions for documenting accessibility via the HHS Section 508

Product Assessment Template may be found under Section 508 policy on the HHS website:

(https://www.hhs.gov/web/508). If it is determined by the Government that EIT supplies and services provided by the Contractor do not conform to the described accessibility standards in the contract, https://www.hhs.gov/web/508 https://www.hhs.gov/web/508 https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards https://www.ecfr.gov/cgi-bin/text-idx?node=pt48.1.2#se48.1.2_1101 https://www.hhs.gov/web/508 remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its own expense.

(e) If this is an Indefinite Delivery contract, a Blanket Purchase Agreement or a Basic Ordering Agreement, the task/delivery order requests that include EIT supplies or services will define the specifications and accessibility standards for the order. In those cases, the Contractor may be required to provide a completed

HHS Section 508 Product Assessment Template and any other additional information necessary to assist the Government in determining that the EIT supplies or services conform to Section 508 accessibility standards. Instructions for documenting accessibility via the HHS Section 508 Product Assessment

Template may be found at https://www.hhs.gov/web/508. If it is determined by the Government that EIT supplies and services provided by the Contractor do not conform to the described accessibility standards in the provided documentation, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its own expense.

https://www.hhs.gov/web/508

Attachment 2 – Clauses

SOURCE FAR/ HHSAR TITLE AND DATE

52.204-13 FAR System for Award Management Maintenance (Oct 2018)

52.204-18 FAR Commercial and Government Entity Code Maintenance (Aug 2020)

52.212-1 FAR Instructions to Offerors – Commercial Products and Commercial Services (Nov 2021)

52.212-3 FAR Offeror Representations and Certifications – Commercial Products and Commercial Services

(Dec 2022) via www.SAM.gov

52.212-4 FAR Contract Terms and Conditions- Commercial Items (Oct 2018)

52.217-5 FAR Evaluation of Options (July 1990)

52.232-39 FAR Unenforceability of Unauthorized Obligations (Jun 2013)

52.232-40 FAR Providing Accelerated Payments to Small Business Contractors (Nov 2022)

352.222-70 HHSAR Contractor Cooperation in Equal Employment Opportunity Investigations (Dec 2015)

352.203-70 HHSAR Anti-Lobbying (Dec 2015)

352.208-70 HHSAR Printing and Duplication (Dec 2015)

352.222-70 HHSAR Contractor Cooperation in Equal Employment Opportunity Investigations (Dec 2015)

352.224-70 HHSAR Privacy Act (Dec 2015)

352.227-70 HHSAR Publications and Publicity (Dec 2015)

FAR 52.252-2 -- CLAUSES INCORPORATED BY REFERENCE. (Feb 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/far1toc.htm http://www.hhs.gov/policies/hhsar/subpart301-1.html

(End of Clause)

52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)

(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the

Government, price and other factors considered. The following factors shall be used to evaluate offers: 1)

Technical Capacity to meet the Government Requirement; 2) Price and 4) Past Performance.

Technical and past performance, when combined, are more important than price.

(b) Options. The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. Evaluation of options shall not obligate the

Government to exercise the option(s).

(c) A written notice of award or acceptance of an offer, mailed or otherwise furnished to the successful offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer’s specified expiration time, the

Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.

http://www.sam.gov/ http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/far1toc.htm http://www.hhs.gov/policies/hhsar/subpart301-1.html

(End of provision)

FAR 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive

Orders—Commercial Products and Commercial Services. (DEC 2022)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN

2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations

Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance

Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015).

(5) 52.233-3, Protest After Award (AUG 1996) ( 31 U.S.C. 3553).

(6) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and 108-

78 ( 19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting

Officer has indicated as being incorporated in this contract by reference to implement provisions of law or

Executive orders applicable to acquisitions of commercial products and commercial services:

_X_ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (JUN

2020), with Alternate I (NOV 2021) ( 41 U.S.C. 4704 and 10 U.S.C. 4655).

_X_ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (NOV 2021) ( 41 U.S.C. 3509)).

__ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of

2009 (JUN 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American

Recovery and Reinvestment Act of 2009.)

_X_ (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (JUN

2020) (Pub. L. 109-282) ( 31 U.S.C. 6101 note).

__ (5) [Reserved].

__ (6) 52.204-14, Service Contract Reporting Requirements (OCT 2016) (Pub. L. 111-117, section

743 of Div. C).

__ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (OCT

2016) (Pub. L. 111-117, section 743 of Div. C).

https://www.acquisition.gov/far/part-52#FAR_52_203_19 https://www.acquisition.gov/far/part-52#FAR_52_204_23 https://www.acquisition.gov/far/part-52#FAR_52_204_25 https://www.acquisition.gov/far/part-52#FAR_52_209_10 https://www.acquisition.gov/far/part-52#FAR_52_233_3 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_233_4 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_203_6…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .