Crypto Class 2 thru 4 - Attachment 6. Performance Work Statement 20240311.pdf

PDF 445 KB Posted

Attached to
Cryptocurrency Managed Services, Class 2 - 4 Federal contract opportunity
Solicitation number
15M50024QA4400003
Issued by
Department of Justice US Marshals Service

About this file

This document is a Performance Work Statement (PWS) for the "Cryptocurrency Managed Services, Class 2 - 4" contract opportunity issued by the U.S. Marshals Service (USMS), Department of Justice (DOJ).

The PWS outlines the requirements for providing custody, management, and disposal services for Class 2 through Class 4 cryptocurrency assets seized and forfeited under the DOJ's Asset Forfeiture Program (AFP). The contractor will be responsible for establishing the necessary accounts, acquiring hardware and software, and providing secure storage and management of the cryptocurrency assets from receipt through final disposal. Key requirements include maintaining an accurate inventory, monitoring the assets, managing forks and locked wallets, and providing industry-related consulting. The contractor must also comply with information security and auditing requirements. This is a 5-year Indefinite Delivery/Indefinite Quantity (IDIQ) contract set aside for Service-Disabled Veteran-Owned Small Businesses, with a Firm Fixed Price task order structure. The government will select the "best value" offeror.

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Marshals Service

Asset Forfeiture Division

Complex Assets Unit

Performance Work Statement for the Cryptocurrency Managed Services, Class 2 – 4

March 11, 2024

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 1 of 26

Table of Contents

1.0 GENERAL

1.1 Introduction

1.2 Background

1.3 Objective

1.4 Scope of Work

2.0 SPECIFIC REQUIREMENTS/TASKS

2.1 Custody

2.2 Storage

2.3 Management

2.4 Disposal

3.0 CONTRACTOR CUSTODY TRANSFER PLAN

4.0 DELIVERY OR DELIVERABLES

5.0 CONSTRAINTS

5.1 Liability

5.2 Compliance

5.3 Information Systems and Services

5.4 Information/Data

5.5 Continuity of Service

5.6 Qualified Contractor Personnel

5.7 Conflicts of Interest

6.0 MEETINGS AND REVIEWS

6.1 Post-award Conference

6.2 Intermittent Project Status Reviews

6.3 Monthly Project Status Reviews

6.4 Program Management Review

6.5 Technical Services Review

7.0 REQUIRED TRAVEL AND OTHER DIRECT COSTS

8.0 SPECIAL INSTRUCTIONS

8.1 General

8.2 Use of Cryptocurrency Exchanges

8.3 Relationship

9.0 GOVERNMENT FURNISHED PROPERTY/EQUIPMENT/INFORMATION

10.0 GLOSSARY OF ABBREVIATIONS AND ACRONYMS

10.1 Asset Forfeiture Process

Note that while, as a matter of policy, some agencies require the government to prepare the PWS, the guidance at FAR 37.602(a) stipulates that “a Performance work statement (PWS) may be prepared by the Government or result from a Statement of objectives (SOO) prepared by the Government where the offeror proposes the PWS.”

https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2037_6.html#wp1074648

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 2 of 26

Performance Work Statement (PWS) for the

Cryptocurrency Managed Services, Class 2-4

1.0 General

1.1 Introduction

The U.S. Marshals Service (USMS) serves to protect, defend, and enforce the American justice system and is a key component within the U.S. Department of Justice (DOJ) Asset Forfeiture Program (AFP). Asset forfeiture plays a critical role in disrupting and dismantling illegal enterprises, depriving criminals of the proceeds of illegal activity, deterring crime, and restoring property to victims. The effective use of both criminal and civil asset forfeiture is an essential component of the DOJ’s efforts to combat the most sophisticated criminal actors and organizations including terrorist financiers, cyber criminals, fraudsters, human traffickers, and transnational drug cartels.

The USMS is the primary custodian of seized assets for the DOJ AFP. Such assets include but are not limited to real estate, jewelry, art, antiques, collectibles, vehicles, vessels, aircraft, animals, cash, financial instruments, and cryptocurrency. In addition to core fiduciary responsibilities associated with the management and disposal of assets, the USMS also provides vital support to U.S. Attorney’s Offices (USAO) and investigative agencies by assisting with pre-seizure planning and financial investigations. As a world leader in asset management and disposal, the USMS also receives requests for technical assistance from countries around the world.

The Treasury Executive Office for Asset Forfeiture (TEOAF) administers the Treasury Forfeiture Fund (TFF). The TFF is the receipt account for deposit of non-tax forfeitures made pursuant to laws enforced or administered by participating Department of the Treasury (TREAS) and Department of Homeland Security (DHS) agencies. The Fund was established in 1992 as the successor to what was then the Customs Forfeiture Fund.

As the departmental custodians of all seized and forfeited assets, this contract will support the USMS in providing custody, management, and disposal services of cryptocurrency assets seized and forfeited under the DOJ AFP, TEOAF components and other U.S. Federal Government (Government) agencies with related law enforcement missions.

1.2 Background

The USMS has been self-managing cryptocurrency assets seized and forfeited by the DOJ and TEOAF forfeiture programs since 2014. Prior to 2020, the USMS custodied and liquidated 32 different types of cryptocurrencies. In 2021, the USMS broadened its capabilities to internally process over 220 different types of cryptocurrencies on a variety of blockchains. Today, as the popularity of cryptocurrency continues to grow, the USMS is expected to process all types of cryptocurrencies without limitation.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 3 of 26

1.3 Objective

This contract will assist the USMS in managing and disposing of cryptocurrency assets, known as Class 2 – 4 cryptocurrencies. These assets are less popular and typically require the use of software, and/or hardware wallets. This will require the use of multiple, industry leading, storage and liquidation techniques employed in a manner that is professional, lawful, and consistent with Department and USMS policy. This contract will also streamline custody, management, and disposal processes for cryptocurrency assets while allowing for the diversification of the type of cryptocurrency assets that can be managed and disposed of under the Government’s forfeiture programs.

The USMS has a duty to ensure all services in the contract provide maximum value while minimizing expenses to the USMS. The USMS expects the Contractor, as its agent, to take prudent action and good faith on the USMS’s behalf with the same duty of care while augmenting our capacity and efficiency regarding the custody, management, and disposal of cryptocurrency.

The USMS expects to improve its current custodial operations through this contract in several ways. Primarily among these is to ensure the security and accuracy of all cryptocurrency transactions. To that end, the Contractor shall ensure that a complete and accurate accounting of the Government’s cryptocurrency inventory is always maintained, and available from the point the Contractor receives custody through disposal.

1.4 Scope of Work

The purpose of this contract is to provide the full range of cryptocurrency custody, management, disposal, and consulting services that are in line with industry standards. This includes but is not limited to such activities as accounting, customer management, audit compliance, wallet creation and management, private encryption key generation and management, backup, and recovery of private encryption key material.

The USMS receives cryptocurrency seized in field offices in all 50 states and territories of Puerto Rico, U.S. Virgin Islands, Guam, and the Northern Marian Islands. The USMS may also receive cryptocurrency seized outside of the United States and territories. The USMS reserves the right to exclude any agency, field office location, or cryptocurrency type anytime from this contract at its sole discretion.

USMS Cryptocurrency Classification List The DOJ AFP seizes and forfeits five different classes of cryptocurrency and is identified in the USMS Cryptocurrency Classification List, as follows:

• Class 1: Cryptocurrencies that are supported by cold storage wallets and can be liquidated on most exchange platforms (e.g., Bitcoin, Ethereum, Litecoin, Tether).

• Class 2: Cryptocurrencies that are supported by cold storage wallets but cannot be liquidated on most exchange platforms. Cryptocurrency must be swapped for a supported cryptocurrency type prior to liquidation (e.g., Bitcoin Gold, Fantom, Tron, etc.).

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 4 of 26

• Class 3: Cryptocurrencies that are not supported by cold storage wallets but can be liquidated on most exchange platforms (e.g., Celo Gold, Mirror Protocol, BOBA Token, etc.).

• Class 4: Cryptocurrencies that are not supported by cold storage wallets and cannot be liquidated on most exchange platforms. These cryptocurrencies typically require coin/token specific software for custody and transacting. Cryptocurrency must be swapped for a supported cryptocurrency type prior to liquidation (e.g., Ark, Bitcoin SV, Ravencoin, etc.).

• Class 5: Cryptocurrencies that are considered an anonymity enhanced/privacy coin (e.g. Dash, Monero, Zcash, etc.).

The USMS Cryptocurrency Classification List is routinely updated to reflect the industry’s evolution and conditions. Cryptocurrency types encountered and not currently listed will be evaluated as encountered and added to the respective classification based on similar criteria.

The Contractor shall recommend and advise on the proper classification of new cryptocurrencies seized during the duration of this contract. The Contracting Officer’s Representative (COR) will provide final approval before the USMS Cryptocurrency Classification List is updated.

The USMS Cryptocurrency Portfolio Summary below, in Table 1, depicts the potential cryptocurrency portfolio that will be transitioned to the Contractor upon cont7ract execution.

The inventory the Contractor may manage at any given point during the life of the contract will fluctuate.

Crypto Class Asset Count Market Value Class 1 Not included in the requirement.

Class 2 100 $75,000,000 Class 3 15 $100,000 Class 4 85 $2,000,000 Class 5 Processed internally, not solicited.

Total: 200 $77.1 million

Table 1: Cryptocurrency Portfolio Summary

1.4.1 Type of Contract Contemplated

This contract will be a set aside for Service-Disabled Veteran Owned Small Business, Indefinite Delivery Indefinite Quantity (IDIQ) that includes firm fixed price line items.

Accordingly, Task Orders will be issued on a Firm Fixed Price (FFP) basis.

1.4.2 Period of Performance

The period of performance shall begin upon contract award to include a base period of twelve months and 4 twelve-month option periods. The option periods may be exercised by the government unilaterally. This contract will also include FAR clause 52.217-8 for an optional six-month extension.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 5 of 26

1.4.3 Place of Performance

The primary place of performance will be the Contractor’s facilities with occasional visits to the USMS Headquarters at 1215 South Clark Street, Arlington, VA 22202. The place of performance shall be within the continental United States.

1.4.4 Hours of Operation

The Contractor shall be available, at its facility(s), between the hours of 8:30 AM and 5:00 PM, Monday through Friday, excluding Federal Government holidays. The Contractor shall designate a 24/7/365 contact number and/or email with access to personnel with complete authority to handle all matters related to the work outlined in this contract.

2.0 Specific Requirements/Tasks

2.1 Custody

The seizure of assets under investigation is often completed with little to no notice. To realize the increased capacity and efficiencies expected from this contract, the Contractor shall remain capable of taking custody, and managing, all types and quantities of cryptocurrency, described as Class 2-4 without limitation, throughout the performance of this contract. This includes both cryptocurrencies and tokens. The Contractor shall establish necessary accounts and acquire necessary hardware and software to obtain, and maintain, custody of assets quickly and safely.

The Contractor shall provide a platform that allows for the issuing of cryptocurrency wallets, tracking, and monitoring of cryptocurrency wallets for Class 2-4 cryptocurrencies. Once assets are transferred from the USMS, the Contractor shall provide all aspects of secure storage and management of cryptocurrency in its custody from the time of receipt until disposal. Upon transfer, the Contractor shall provide notification, and confirmation, of the asset’s transfer, within two (2) business days, detailing the amount, type, and blockchain of the cryptocurrency transferred, the date of the transfer, and the transaction hash for the transfer.

2.1.2 Contract Transition

The Contractor, including the contractor’s facility(s), shall be fully equipped and ready to begin performance within 30 calendar days of the receipt of an Authorization to Use (ATU) designation. This includes providing all the documentation necessary to the COR for review by the USMS Information Technology Division (ITD) Security Office as outlined in this contract for consideration by the USMS Authorizing Official (AO) for an ATU. Once ready to begin performance, and upon approval by the COR, the Contractor has seven (7) calendar days, unless otherwise specified by the COR, to transfer all Government cryptocurrency assets, classified as Class 2-4, from their current location to the Contractor’s custody by providing the appropriate cryptocurrency wallet addresses.

2.1.3 Cryptocurrency Transferred from Investigating Agencies

For cryptocurrency being transferred from the Investigating Agency (IA), the Contractor’s custody platform shall allow for the issuing of cryptocurrency wallet addresses within three

(3) business days of request. Any potential delay shall be discussed in advance with the

COR.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 6 of 26

2.2 Storage

The Contractor shall maintain a complete and accurate accounting of the Government’s cryptocurrency inventory at all times. The Contractor shall ensure that each Government cryptocurrency asset is segregated by its wallet address. The Contractor shall ensure that cryptocurrency wallet addresses provided to the Government are not reused and/or provided to other agencies, institutions, and/or customers. The Contractor shall ensure that the Government’s cryptocurrency inventory is never comingled with any other wallets or addresses belonging to different owners.

The Contractor shall hold cryptocurrency assets in cold storage (not connected to the internet, intranet, or computer). Hardware used to store private keys associated with Government cryptocurrency assets shall not be connected to any local or external networks at any time unless actively transacting Government cryptocurrency assets. All cryptocurrency assets shall be backed up in redundant geographically separate logical locations, minimum 100 miles, and in a manner that prevents compromise by internal collusion, third party collusion, remote or local cyber-attacks, physical loss, fire or acts of nature.

2.3 Management

2.3.1 Asset Management Solution

The Contractor shall utilize a web-based Asset Management Solution that provides real-time tracking, up-to-date market pricing, and blockchain confirmation of all Government cryptocurrency assets in the Contractor’s custody regardless of location. The solution shall track the units and type of cryptocurrencies in custody, with the inclusion of internal USMS descriptors (tracking asset identification number, case name, seizing agency, etc.). The solution shall provide the real-time ability to check and monitor the assets being held in storage. If using an established solution, the Contractor shall ensure data related to Government cryptocurrency assets are not comingled and cannot be accessed by other institutions, agencies, and customers. The Contractor shall ensure the new and/or established solution limits access to only personnel with a need to know.

In addition to the managed assets, any Contractor-provided technical devices, systems, services, and digital information used for direct management of the USMS information (separate from the managed Cryptocurrency commercial systems, services, and assets) shall meet the DOJ and the USMS lifecycle compliance requirements. This includes compliance per DOJ-05 Security of Department Information and Systems (OCT 2023). The Contractor shall notify the COR if there are any issues.

2.3.1.1 Reporting within Asset Management Solution

Within the web-based Asset Management Solution, the Contractor shall provide capability to instantly execute ad hoc reporting. The system for reporting shall provide four nines (99.99%) continuous availability throughout the duration of the contract where technically feasible. The descriptors the Contractor shall make available for reporting include type and amount of cryptocurrency, custody receipt dates, cryptocurrency wallet addresses and transaction hashes, cryptocurrency airdrop amounts, valuation records of cryptocurrency, etc.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 7 of 26

In addition, the Contractor shall provide the USMS with ad hoc reports as requested. All reports must be provided in electronic format with the timeframes to be negotiated and codified at the time of award, and shall have read/write capability using applications that are compatible with USMS workstations (e.g., modern Microsoft products).

2.3.2 Monthly Statements

The Contractor shall utilize a platform that allows for a monthly inventory statement to be produced for all Government cryptocurrency assets in the custody of the Contractor. The report shall include all assets, including those which may have become forfeited and/or pending liquidation but are still in the custody of the Contractor. The Contractor’s platform shall allow for the COR and/or designee to execute previous and current monthly statements at any time.

2.3.3 Monitoring of Inventory

The Contractor shall utilize a monitoring process that alerts the COR and a designated email to be determined at contract award of any suspicious activities, unauthorized access and/or movement of assets, loss of assets and/or hardware, and cryptocurrency airdrops in real time.

The Contractor shall notify the COR of any reportable activity within 1 hour of discovery of a confirmed security incident and within 24 hours for potential security incidents, per DOJ-05 Security of Department Information and Systems (OCT 2023). The initial report of an incident can be a verbal or written notification to the COR with a final written report to follow.

2.3.4 Management of Forked Cryptocurrency

On some older assets forks need to be claimed. Within 30 days of receipt of an ATU designation, the Contractor shall claim the following forks:

• Bitcoin Cash (BCH) Bitcoin Gold (BTG)

• Bitcoin Satoshi Vision (BSV)

The Contractor shall pull the private key from the wallet, account for the forked tokens and airdrops and provide the U.S. Government (USG) with an updated accounting of these assets to include the new public address. When instructed, the Contractor shall dispose of the forked currency.

All future forks, regardless of type, shall be managed by the Contractor. The Contractor shall provide notice to the COR of any upcoming forks once identified and a plan to recognize and manage the additional assets.

2.3.5 Gas for Cryptocurrency Assets

Gas refers to the fee required to perform transactions on a blockchain network. Gas is paid in the native blockchain’s cryptocurrency (e.g., Ether needed to transact Tether) and allows cryptocurrency assets to be moved from one location to another and exchanged for other types of cryptocurrencies. The Contractor shall provide gas for the transfer of cryptocurrency, regardless of their network and irrespective of their custodial location

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 8 of 26

(USMS or Investigating Agency) or ultimate destination, immediately upon a written request from the COR. The Contractor shall bill the Government for reimbursement.

2.3.6 Management of Locked Wallets

The Contractor may be asked to troubleshoot and identify potential issues with cryptocurrency wallets that experienced issues during a software update, saving of key information, etc. When tasked, the Contractor shall identify the issue(s) and potentially open the wallet. If the wallet cannot be opened, documentation of efforts taken to unlock or open the wallet will be provided to the COR.

2.3.7 Management of Cryptocurrency-Related Hardware

There may be instances where maintenance of cryptocurrency-related hardware (ironkeys, nano ledgers, etc.) is needed. This may include taking custody of the hardware, recovering files, etc. Dependent on the situation, the Contractor shall identify any issues and assist the COR as needed to manage with reportable tracking of the cryptocurrency-hardware.

2.3.8 Industry-Related Consulting and Problem Solving

The cryptocurrency industry is constantly evolving and changing. The Contractor shall remain up to date on trends, technology updates, regulations, etc. and be ready to provide the Government with on-demand solutions and advisory support.

2.3.9 Risk Mitigation and Security

The Contractor shall take prudent steps to prevent the loss of Government cryptocurrency assets including but not limited to theft, human error, system failures, bankruptcy, and acts of nature. The Contractor shall provide a Risk Mitigation and Security Plan that provides an overview of the security standards and describes the internal controls in place that are in line with current industry standards (e.g., segregation of assets, multi-layer authentication, equipment, etc.). The Plan shall be provided in accordance with section 4.0 Delivery or Deliverables.

2.3.10 Use and Ownership of Government Assets

This contract uses a bailment relationship. The Contractor is not the beneficial owner of any assets held on behalf of the Government or other third parties. Beneficial ownership does not, and will not, reside with the Contractor at any time.

2.3.10.1 Use of Government Assets

The Contractor shall not swap, stake, pledge, hypothecate, borrow, invest, assign, convey, lend, or make other use of Government assets in the Contractor’s possession, nor shall any cryptocurrency held for the Government be assigned for the benefit of creditors. Any use of Government assets is strictly prohibited. Cryptocurrency held by the Contractor for the Government shall not be treated as fungible and shall be segregated from other assets until it is sold or returned to the Government or the Government’s designated recipient.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 9 of 26

2.3.10.2 Ownership of Government Assets

In the event of bankruptcy or other loss, the Contractor, or its Agents, shall ensure that cryptocurrency assets in custody and control of the Government are not made available to its creditors.

2.4 Disposal

The Contractor shall provide a platform that allows for the quick and efficient disposal of cryptocurrency assets. The Contractor-provided platform shall allow for the following methods of disposal:

• Direct exchange from cryptocurrency into fiat currency where markets exist.

• Exchange into a more liquidate form of cryptocurrency and then exchanged into USD where market exist.

• Return to Investigating Agency, owner, or other third party(ies).

Once a Government cryptocurrency asset has been approved for disposal, the USMS will notify the Contractor and indicate which asset(s) under custody will be disposed, via exchange or return, through written documentation (e.g., subtask orders, email, etc.). If the directed method chosen by the USMS is determined to not be feasible, the Contractor shall provide a written explanation of the mitigating factors and provide an alternative method and explanation of the choice, and the resulting change in pricing if any.

2.4.1 Standard Disposal via Exchange

The Contractor’s platform for disposal shall provide direct access to a cryptocurrency exchange that converts cryptocurrency into fiat currency. When necessary, the Contractor shall make recommendations regarding the most prudent method of disposal (exchange vs trade desk) for the amount and/or type of cryptocurrency that is forfeited, however the ultimate decision regarding the disposal method rests solely with the USMS.

Standard disposals via exchange shall be completed within five (5) business days of notification. The five-day disposal deadline will be considered complete when all proceeds are in the USMS Treasury Account. This may require approval from the COR to extend the disposal timeframe depending on exchange-based disposal restrictions.

2.4.1.1 Fees, Trade Statements, and Disposal Reports

The Contractor shall provide direct access, or copies, of trade statements detailing the date of the liquidation and the type, amount, and price of cryptocurrency. Any fees associated with the liquidation, that are deducted from the proceeds, shall be identified on the statement originating from the exchange. All reports and statements shall have the capability to be provided in multiple formats (Microsoft Excel, Adobe PDF, etc.).

2.4.1.2 Use of Exchanges for Liquidation

The Contractor’s platforms for disposal shall include the use of COR pre-approved, U.S.

based exchanges, encompassing the criteria listed below to perform direct exchanges for fiat currency or exchanges into a more liquid form of cryptocurrency.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 10 of 26

• Regulated cryptocurrency exchange.

• Anti-money laundering, Bank Secrecy Act, and Office of Foreign Assets Control compliant.

• Allows for institutional trading.

• Provides instant reporting capabilities.

On extremely rare circumstances, the Contractor may use exchanges based outside of the U.S., but only if pre-authorized by the COR after review of a Contractor-prepared risk-mitigation plan.

2.4.2 Exchange into More Liquid Cryptocurrency

Class 2 and Class 4 cryptocurrencies include assets that are not supported by most exchanges. In these situations, the Contractor shall provide a plan to exchange the cryptocurrency for a cryptocurrency that is supported by the Contractor’s exchange platform.

After completing the exchange, the Contractor shall provide documentation that details the type, amount, and value of cryptocurrency received. The Contractor shall ensure documentation of any fees assessed for the exchange is provided and comes directly from the platform used.

2.4.3 Return to Third Party, USMS, and/or Investigating Agencies In instances where the USMS and/or TEOAF shall return cryptocurrency to a third party USMS, and/or an Investigating Agency, the Contractor shall provide a platform that allows the processing of these returns in a timely and efficient manner. A return is at the sole discretion of the COR.

The platform that allows for the return of assets to a third party shall include methods that permit the return to be completed within 10 business days of initiation for standard returns (parties of 25 or less) and 20 business days of initiation for large returns (parties of 26 or more). The Contractor shall provide a transaction statement showing the return occurring on the blockchain and detailing the date of the return and the type and amount of cryptocurrency returned.

2.4.3.1 Rates for Standard Return to Third Party and/or USMS

Although the return of cryptocurrency is considered a type of disposal regarding the asset itself, the process of doing so is a function of the management requirement and not the disposal requirement. Therefore, in the event an asset is disposed of in this manner, the Contractor shall not be entitled to a commission, rather it shall be entitled to its regular monthly management rate only.

3.0 Contractor Custody Transfer Plan

The Contractor shall provide a proposed Custody Transfer Plan. The proposed Custody Transfer Plan will be negotiated with the USMS at the post award conference. The Contractor shall provide a final Custody Transfer Plan to the COR after the post award conference.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 11 of 26

The Custody Transfer Plan should include a detailed Phase-In plan for contract transition (including period for transition, security, personnel) as well as a detailed Phase-Out plan should the services need to be transferred at the end of the contract.

4.0 Delivery or Deliverables

Timely submission of deliverables and reports are essential to successfully completing this requirement. Schedules for deliverables are specified in the table below.

ITEM

DELIVERABLE/EVENT

DUE

DIST

1 Post Award Conference Within 30 business days after date of award

CO, COR

2 Final Contractor Custody Transfer Plan

Within 14 days of receipt of an ATU designation

CO, COR

3 Business Continuity Plan Within 14 days of receipt of an ATU designation

CO, COR

4 Updated Business Continuity Plan Annually CO, COR

5 Risk and Mitigation Plan Within 14 days of receipt of an ATU designation

CO, COR

6 Updated Risk and Mitigation Plan Annually or with major changes

CO, COR

7 Monthly Status Meetings and Progress Reports

Monthly CO, COR

8 Cybersecurity Lifecycle or Breach Notification

1 hour for confirmed and 24 hours for potential Incident

CO, COR

9 Monitoring Activities Within timeframe codified at Post Award

CO, COR

10 External Audits of the USMS Asset Forfeiture Portfolio

Within 1 business day of request

COR

11 Internal Audits of the USMS Asset Forfeiture Portfolio

Annually, within 5 days of completion

CO, COR

12 Cured Internal Audit Findings Within 20 days of identification

CO, COR

13 Independent Third-Party Compliance Audits

Annually, within 5 days of completion

CO, COR

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 12 of 26

ITEM

DELIVERABLE/EVENT

DUE

DIST

14 Cured Independent Third-Party

Compliance Audit Findings Within 20 days of identification

CO, COR

15 Technical Services Review meetings/reports

Monthly CO, COR

5.0 Constraints

5.1 Liability

The Contractor shall assume responsibility and financial liability, for all Government cryptocurrency assets, under their control at all times. The Contractor shall be liable for any act, omission, negligence, error, or lack of performance which results in the damage, devaluation, destruction, or loss of all physical or virtual property, parts, items, or derived portion that the Contractor handles during the performance of this contract. For avoidance of doubt, the foregoing list includes losses caused by the inability to recover encryption keys, the inability to transfer cryptocurrency and/or tokens, transfers of cryptocurrency and/or tokens to a destination other than as requested by the Government, and losses caused by force majeure for which the Contractor did not make adequate backup provisions. The Contractor shall make the USMS whole in the event of any losses not covered by the Contractor’s insurance.

5.1.1 Insurance

The Contractor shall, at its own expense, provide and maintain insurance during the entire performance of this contract and shall be in line with industry standards. Insurance coverage shall include commercial crime coverage for acts of dishonesty, theft, robbery, destruction, security breach, etc. Insurance coverage shall include cyber coverage for loss derived from security failures.

5.1.1.1 Insurance Coverage Amounts

Insurance coverage amounts shall be in line with industry standards. Insurance coverage amounts do not have to equal the full value of the Government’s inventory being held in the Contractor’s custody.

5.1.1.2 Species Insurance

Additional insurance coverage may be required on a situational basis. When directed, via contractual modification, the Contractor shall provide additional coverage through species insurance, at the Government’s expense. When needed, The COR will advise the Contractor to obtain three (3) quotes. Once approved the COR will submit a request for additional insurance to be obtained at the quoted price.

5.1.2 Technical Systems

The Contractor shall be responsible for technical systems under their direct control where unauthorized access and information disclosures occur. The Contractor shall be responsible for taking corrective action consistent with DOJ/USMS Data Breach Notification Procedures

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 13 of 26 and as directed by the DOJ, USMS and the Contracting Officer (CO), including all costs and expenses associated with such corrective action. Examples of technical systems under the Contractor’s direct control may include servers, laptop/desktop devices, USB devices, etc.

used for managing the USMS program information, program reporting services, asset tracking and management services. In accordance with DOJ-05 Security of Department Information and Systems (OCT 2023).

5.2 Compliance

5.2.1 External Audits of the USMS Asset Forfeiture Portfolio

To the extent deemed necessary by the USMS to carry out an inspection to safeguard against threats and hazards to the security, integrity, accuracy, and confidentiality of any non-public USMS data collected and stored by the Contractor, the Contractor shall afford the USMS access to the Contractor’s technical capabilities, operations, documentation, records, and databases at any time during the performance of the contract.

The Contractor shall remain available to respond and assist the USMS with responding to inquiries by its auditors, both internally and externally within one (1) business day of request.

The USMS and/or the Office of the Inspector General (OIG) may periodically contract for the services of an Independent Public Accountant (IPA) to perform a review of the program.

The Contractor shall allow and provide an onsite representative to assist the USMS and or OIG/IPA during visits.

5.2.2 Internal Audits of the USMS Asset Forfeiture Portfolio

The Chief Financial Officers Act of 1990 requires an annual audit of the Assets Forfeiture Fund (AFF) annual financial statements. As part of this audit, the Contractor is mandated to conduct a one hundred percent (100%) annual inventory reconciliation for all Government cryptocurrency assets in its custody, including assets which may have become forfeited and/or pending liquidation based on a disposition order but are still in the custody of the Contractor. The Contractor shall provide their internal audit report to the USMS within five business days of completion. Deficiencies identified by any audit findings shall be cured by the Contractor within 20 business days of such identification or as approved by the COR.

5.2.3 Independent Third-Party Audits

The USMS requires an annual System and Organization Controls 2 (SOC 2) Type 2 report provided by an independent third-party to provide assurance of the Contractor’s security, internal controls, data integrity, etc. The Contractor shall ensure compliance auditing activities will be aligned with the Federal Government’s fiscal year. The Contractor shall provide findings of their independent third-party obtained audit report to the USMS within five (5) business days of receipt. Deficiencies identified by any audit findings shall be cured by the Contractor within 20 business days of such identification or as approved by the COR.

Contractors who have not undergone a SOC 2 Type 2 assessment and have not been provided with a recent independent an independent third-party assessment report will be given up to 6 months to complete the audit processes and provide their independent third-party assessment results to the USMS. The Contractors independent third-party assessment results will be

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 14 of 26 reviewed by the USMS ITD Security Office. Deficiencies identified by any audit findings shall be cured by the Contractor within 20 business days of such identification or as approved by the COR. The COR will then issue a determination on the suitability of the Contractor system to begin the ATU process.

5.2.4 Information Technology Compliance Audits

The Contractor shall ensure compliance inclusive of audit support requested by the USMS ITD Security office. The standards outlined in Standards and Compliance Requirements (Appendix TBD), apply to systems, products, and services delivered directly in support of USMS information management performance deliverables by the Contractor, services maintained directly by the Contractor and service designs proposed by the Contractor and may change over the lifecycle of this contract in accordance with DOJ and USMS policy updates. The Contractor is accountable for ensuring compliant access to USMS information and the maintained USMS controls within public cryptocurrency clouds, systems, and services. However, the Contractor is not responsible under this contract for ensuring the compliance of the commercially owned services themselves.

5.2.4.1 Annual FISMA Audit Reviews

The Federal Information Security Modernization Act (FISMA 2014), defines a framework for security standards and requires all technical services maintain compliance with those standards. The DOJ selects programs, services, and systems annually for FISMA audit review. In addition to FISMA audits, an annual review of compliance controls is conducted by the USMS to ensure approval for continuance of a program, service, or systems Authority to Use (ATU). The Contractor shall provide support for any compliance activity review of security standards controls and mitigation as required.

5.2.4.2 Security Certification and Accreditation Validation Activities To ensure the security and privacy of federal information, an Authorization to Use (ATU) is mandatory for external information system services that either process, store, or transmit federal data or operate information systems on behalf of the federal government. These services must adhere to the same stringent security standards as federal agencies.

An ATU serves as a standardized process for safeguarding Controlled Unclassified Information (CUI) within nonfederal systems and organizations, aligned with the guidelines defined in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2. It empowers Authorizing Officials (AOs) to make informed, risk-based decisions regarding the authorization of external information systems services, taking into account the security and privacy controls implemented by the Contractor. It also allows the AO to explicitly accept commercial or international security frameworks, standards, assessments, or attestations that closely align with NIST 800-171 Rev2, providing flexibility in meeting federal security requirements.

While NIST promotes ATUs, it's crucial to note that obtaining an ATU does not absolve either the AO or the Contractor of their fundamental responsibility for risk management.

Both parties remain accountable for ensuring the ongoing protection of federal information.

https://www.congress.gov/bill/113th-congress/senate-bill/2521

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 15 of 26

The Contractor is obligated to provide full support and cooperation in all activities necessary to obtain and maintain an ATU.

The ATU process grants the USMS the ability to capitalize on existing security and privacy controls implemented by the Contractor, based on specific business needs and requirements. The Contractor is responsible for diligently implementing the requirements outlined in the ATU process to achieve authorization and safeguard the integrity of federal information. This collaborative effort between the Contractor and the AO is paramount in maintaining the confidentiality, integrity, and availability of sensitive federal data within external information system services.

The ATU process will include providing support for a security and privacy control assessment, evaluation, or attestation of the contractors most recent and detailed System and Organization Controls II (SOC 2) audit results. This evaluation and the ATU process ensure that the sharing of USMS information and information that USMS relies upon from the contractor system is protected by the correct implementation of security and privacy controls and basic risk management principles.

The Contractor shall assist the Government authorized representative, which may be a federal or contractor member of the USMS ITD Security Office, with the implementation and validation of security controls, Assessment and Authorization (A&A), vulnerability management, risk remediation or mitigation activities, and maintenance of information technology hosting USMS information. The contractor will provide information system documentation (or extracts thereof) and the associated corrective action or plans of action and milestones (POA&Ms) for any planned remediation/mitigation or implementations, as well as the mitigation of vulnerabilities. Transparency will be essential to achieve the assurance necessary to ensure adequate protection for USMS assets. The system will be registered, and the information and documentation gathered will be entered in the USMS instance of the Joint Cybersecurity Authorization and Management (JCAM) application.

If the contractor uses any other third-party services to deliver the service to the USMS, the third party service provider will be held to the same security and privacy requirements as the contractor.

System Categorization - The contractor will assist the COR and federal or contractor member of the USMS ITD Security Office to complete the security categorization process per the Federal Information Processing Standards (FIPS) Publication 199, Standards for Security Categorization of Federal Information and Information Systems, requirement in JCAM. This process includes selecting all the information types defined in the NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories, information types to determine the security categorization of Low, Moderate, or High. This process is necessary for the AO to make an informed risk-based decision when issuing the ATU and the potential impacts on the confidentiality, integrity, and availability of USMS information.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 16 of 26

Assessment - The contractor will provide all necessary support to the federal or contractor member of the USMS ITD Security Office in conducting a complete review and risk assessment of the most recent and detailed SOC 2 audit results, and any other supporting security artifacts for the system as requested by the federal or contractor member of the USMS ITD Security Office.

Supply Chain Risk Management (SCRM) - The contractor will follow the DOJ USMS SCRM for any information technology procurements. The contractor will support a supply chain risk assessment with the DOJ USMS SCRM team, with the goal of obtaining a recommendation that the contractor and system do not pose an unfavorable risk to USMS and DOJ.

Authorization – Various risk factors will be considered when the USMS AO evaluates the system for an ATU. The USMS AO, utilizing JCAM, will make an informed risk-based decision when issuing the ATU to include the potential impacts of the system security posture on the confidentiality, integrity, and availability of USMS and DOJ information.

If granted the system ATU will only be valid for one (1) year. The AO is required re-authorize the system annually to ensure that it does not introduce unacceptable risks to USMS and DOJ. Annual recertification will include the complete review of any updated security and privacy artifacts and documentation to included but not limited to the annual SOC II Type 2 compliance report in JCAM.

5.3 Information Systems and Services

Per DOJ Security Requirements and in accordance FISMA (DOJ-05 Security of Department Information and Systems (OCT 2023)), the organization and system shall follow, develop, and maintain technical services to standards to meet the ATU security authorization, DOJ Strong Authentication Policy, and ensure future policies and updates are met throughout the lifecycle for systems and services housing USMS information. The Contractor shall ensure all performance and new proposed solutions are compliant with applicable legal, regulatory, DOJ, and USMS policy requirements to maintain an ATU on all information technology systems and services hosting USMS information. The Contractor shall also ensure performance and new solutions are consistent with industry and technology guidance best practices.

5.3.1 Security Deficiencies and Cyber Risk

The Contractor shall develop Plan of Action and Milestones (POA&M) for identified security deficiencies and manage and resolve POA&Ms according to Government approved schedule(s). Cyber risk is measured through operational cyber protections and shall be embedded in delivery services for architecture, design and delivery of systems, solutions, and services. The Contractor shall provide architectural design documents, diagrams, configuration baselines, reports, patches, system updates, vulnerability mitigation, infrastructure protections, logging, monitoring, alerts, and response in support of specific security related questions, processes, or requested actions as needed and specified by the

COR.

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 17 of 26

The contractor will notify to USMS when there are changes to the ownership of the company or when there are major changes to the system used to deliver the service to the USMS.

External information service provider ownership changes such as a merger or acquisition may trigger a risk assessment to be completed by USMS.

The contractor will notify to USMS prior to and as working any major changes to the system to include software code changes, physical location, network architecture, infrastructure, or the replacement of security technologies in place to secure USMS information. The changes may cause a review of the ATU and re-authorization.

COR must be notified within one (1) hour of a confirmed security incident and within 24 hours of a potential security as defined in DOJ-05 Security of Department Information and Systems (OCT 2023) section VI. Information System Security Incident Security.

5.4 Information/Data

The USMS shall own the rights to all data/records produced under the performance of this contract and shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. The Contractor shall not create or maintain any records containing any USMS information that are not specifically tied to or authorized by the contract. Further, disposition and destruction of records is EXPRESSLY PROHIBITED unless authorized by the USMS COR. The Contractor shall prevent the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage, or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701.

All information related to this contract created or produced in part or in whole, regardless of type of media, is to be maintained for the duration of the contract, made available upon request, and upon termination of the contract shall be turned over to the USMS. This includes but is not limited to all electronic files, hard copy files, USB drives, data contained in electronic information systems, databases, etc., and all supporting documentation. The Contractor shall deliver sufficient technical documentation with all data deliverables to permit use of the data by the USMS. The contractor shall ensure technical documentation addresses measures taken toward system and services compliance with DOJ/USMS policy.

All data at rest shall reside within the contiguous United States, the District of Columbia, Hawaii and Alaska with a minimum of two geographically separated different and distant geographic locations by at least 100 miles. Data at rest and in transit shall be encrypted and protected to FIPS 140-3 Security Requirements for Cryptographic Modules.

5.5 Continuity of Service

The Contractor shall prepare and submit a Business Continuity Plan (BCP) to the USMS within 14 days of the post award conference. The BCP shall be due at the post award conference and will be updated on an annual basis. The BCP shall document Contractor plans and procedures to maintain support during an emergency, including natural disasters and acts of terrorism. The BCP, at a minimum, shall include the following:

PWS for Cryptocurrency Managed Services, Class 2 – 4 Page 18 of 26

• A description of the Contractor’s emergency management procedures and policy to ensure ongoing operations.

• How the Contractor shall communicate with the USMS during emergencies.

• A list of primary and alternate Contractor points of contact, each with primary and alternate:

o Telephone Numbers o E-mail addresses

Individual BCPs shall be activated immediately after determining that an emergency has occurred, shall be operational within 24 hours of activation or as directed by the USMS, and shall be sustainable until the emergency is resolved and normal conditions are restored or the contract is terminated, whichever comes first. In case of a life-threatening emergency, the COR shall immediately contact the Contractor’s Project Manager to ascertain the status of any Contractor personnel who were in a controlled space affected by the emergency. When any disruption of normal, daily operations occurs, the Contractor’s Project Manager and the COR shall promptly open an effective means of communication and verify:

• Key points of contact (USMS and Contractor).

• Means of communication available under the circumstances (e.g., email, webmail, telephone, FAX, courier, etc.)

• Essential Contractor work products expected to be continued, by priority.

• Availability of the recovery point objectives (RPO) in the specified recovery time objectives (RTO) for systems, services, and data.

• Cybersecurity status and posture of services.

The USMS and the Contractor’s Project Manager shall make use of the resources and tools available to continue contracted functions to the maximum extent possible under emergency circumstances. The Contractors performing work in support of authorized tasks within the scope of their contract shall charge those services accurately in accordance with the terms of this contract.

5.6 Qualified Contractor Personnel

The Contractor shall provide qualified personnel to perform all requirements specified in this

PWS.

5.6.1 Qualified Personnel for Transacting Cryptocurrency

Qualified personnel for those transacting cryptocurrency assets under the Government’s inventory are defined as having an undergraduate degree with at least three (3) years of experience in the cryptocurrency, blockchain and/or technology industry or seven (7) years of overall experience in the cryptocurrency, blockchain, and/or technology industry.

Qualified personnel for transacting cryptocurrency shall have experience in managing cryptocurrency and other digital assets for…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .