DRAFT RFP_36C10B23R0011.docx

DOCX document 454 KB Posted

Attached to
DA01--Transformation Twenty-One Total Technology Next Generation 2 (T4NG2) Federal contract opportunity
Solicitation number
36C10B23R0011
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This draft request for proposal (RFP) is for the Transformation Twenty-One Total Technology Next Generation 2 (T4NG2) effort to provide information technology services and solutions to the Department of Veterans Affairs (VA). The RFP will be finalized in February 2023. Interested offerors can submit questions about the draft RFP by January 20, 2023 to the email address provided. The RFP will result in multiple award indefinite delivery/indefinite quantity contracts to support the full range of IT requirements for the VA, including systems/software engineering, cybersecurity, training, and facilities, over a five-year base period and one five-year option. Pricing will be on firm-fixed-price, time-and-materials, and cost reimbursement bases at the task order level. The maximum value of the contracts is $60.7 billion over ten years.

View the file

Other files for this federal contract opportunity

Other files attached to DA01--Transformation Twenty-One Total Technology Next Generation 2 (T4NG2), newest first.
File Type Posted
36C10B23R0011_26.docx DOCX document
36C10B23R0011_25.docx DOCX document
RFP_36C10B23R0011 v5.docx DOCX document
36C10B23R0011_21.docx DOCX document
36C10B23R0011_20.docx DOCX document
36C10B23R0011_19.docx DOCX document
36C10B23R0011_18.docx DOCX document
36C10B23R0011_17.docx DOCX document
RFP_36C10B23R0011 v4 - final.docx DOCX document
36C10B23R0011_16.docx DOCX document
015 -- T4NG2 Self Scoring Worksheet Amendment 2 v3.xlsx XLSX spreadsheet
36C10B23R0011_14.docx DOCX document
36C10B23R0011_13.docx DOCX document
Questions and Answers 20230420 (for posting).pdf PDF
Questions and Answers 20230410 (for posting).pdf PDF
015 -- T4NG2 Self Scoring Worksheet Amendment v2.xlsx XLSX spreadsheet
001 -- T4NG2 Price Attachment Final v2.xlsx XLSX spreadsheet
Questions and Answers 20230405.pdf PDF
010 -- T4NG2 SB Report Final v2.xlsx XLSX spreadsheet
Questions and Answers 20230320.pdf PDF
Questions and Answers.pdf PDF
014 -- PrimeOfferor_SBPC.xlsx XLSX spreadsheet
002 -- Labor Category Descriptions Final.xlsx XLSX spreadsheet
008 -- T4NG2 Manpower Report - Task Order.xlsx XLSX spreadsheet
018 -- Performance Risk Assessment Questionnaire.docx DOCX document
015 -- T4NG2 Self Scoring Worksheet.xlsx XLSX spreadsheet
013 -- Veterans Employment Certification.docx DOCX document
005 -- T4NG2 Contract Performance Report for CR.xlsx XLSX spreadsheet
004 -- T4NG2 Contract Performance Report for TM.xlsx XLSX spreadsheet
RFP_36C10B23R0011.docx DOCX document
011 -- T4NG2 Veterans Employment Certification Report Final.xlsx XLSX spreadsheet
010 -- T4NG2 SB Report Final.xlsx XLSX spreadsheet
36C10B23R0011_6.docx DOCX document
018 - PERFORMANCE RISK ASSESSMENT QUESTIONNAIRE.docx DOCX document
011 - T4NG2 Veterans Employment Certification Report draft.xlsx XLSX spreadsheet
36C10B23R0011_4.docx DOCX document
T4NG2 Industry Day - 20230201 - 1500hrs.pdf PDF
36C10B23R0011_3.docx DOCX document
36C10B23R0011_2.docx DOCX document
36C10B23R0011_1.docx DOCX document
001 - T4NG2_Price Attachment.xlsx XLSX spreadsheet
015 - T4NG2_Self_Scoring_Worksheet_Draft_RFP_Version.xlsx XLSX spreadsheet
011 - T4NG2 Veterans Employment Certification Report.xlsx XLSX spreadsheet
010 - T4NG2 SB Report.xlsx XLSX spreadsheet
003 - Contractor Progress Status and Management Report.docx DOCX document
014 - PrimeOfferor_SBPC.xlsx XLSX spreadsheet
013 - Veterans Employment Certification.docx DOCX document
006 - T4NG2 GFE Report.xlsx XLSX spreadsheet
004 - T4NG2 Contract Performance Report for TM.xlsx XLSX spreadsheet
002 - Labor Category Descriptions.xlsx XLSX spreadsheet
Show all 50

DA01--Transformation Twenty-One Total Technology Next Generation 2 (T4NG2) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C10B23R0011

PART I - THE SCHEDULE1. THIS CONTRACT IS A RATED ORDER

RATING

PAGE OF

PAGES

UNDER DPAS (15 CFR 700)

2. CONTRACT NUMBER

3. SOLICITATION NUMBER

4. TYPE OF SOLICITATION

5. DATE ISSUED

6. REQUISITION/PURCHASE NUMBER

SEALED BID (IFB)

NEGOTIATED (RFP)

7. ISSUED BY

CODE

8. ADDRESS OFFER TO

(If other than Item 7) NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".

9. Sealed offers in original and _____________________________ copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in Until local time _______________________ (Hour) (Date) CAUTION - LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All Offers are subject to all terms and conditions contained in this solicitation.

A. NAME

B. TELEPHONE (NO COLLECT CALLS)

C. E-MAIL ADDRESS

AREA CODE

NUMBER

EXT.

(X)

SEC.

DESCRIPTION

PAGE(S)

(X)

SEC.

DESCRIPTION

PAGE(S)

PART I - THE SCHEDULE

PART II - CONTRACT CLAUSES

A

SOLICITATION/CONTRACT FORM

I

CONTRACT CLAUSES

B

SUPPLIES OR SERVICES AND PRICES/COSTS

PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.

C

DESCRIPTION/SPECS./WORK STATEMENT

J

LIST OF ATTACHMENTS

D

PACKAGING AND MARKING

PART IV - REPRESENTATIONS AND INSTRUCTIONS

E

INSPECTION AND ACCEPTANCE

F

DELIVERIES OR PERFORMANCE

G

CONTRACT ADMINISTRATION DATA

L

INSTR., CONDS., AND NOTICES TO OFFERORS

H

SPECIAL CONTRACT REQUIREMENTS

M

EVALUATION FACTORS FOR AWARD

K

REPRESENTATIONS, CERTIFICATIONS AND OTHER

STATEMENTS OF OFFERORS

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

12. In compliance with the above, the undersigned agrees, if this offer is accepted within ________ calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

10 CALENDAR DAYS (%)

20 CALENDAR DAYS (%)

30 CALENDAR DAYS (%)

CALENDAR DAYS (%)

(See Section I, Clause No. 52-232-8)

14. ACKNOWLEDGEMENT OF AMENDMENTS

AMENDMENT NO.

DATE

AMENDMENT NO.

DATE

(The offeror acknowledges receipt of amendments to the SOLICITATION for offerors and related documents numbered and dated:

DUNS:

DUNS+4:

CODE

FACILITY

16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN OFFER

15A. NAME AND

ADDRESS OF

OFFEROR

(Type or print)

15B. TELEPHONE NUMBER

17. SIGNATURE

18. OFFER DATE

AREA CODE

NUMBER

EXT.

15C. CHECK IF REMITTANCE ADDRESS IS DIFFERENT FROM

ABOVE - ENTER SUCH ADDRESS IN SCHEDULE

19. ACCEPTED AS TO ITEMS NUMBERED

20. AMOUNT

21. ACCOUNTING AND APPROPRIATION

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

23. SUBMIT INVOICES TO ADDRESS SHOWN IN

ITEM

(4 copies unless otherwise specified) 10 U.S.C. 2304(a) ( ) 41 U.S.C. 253(c) ( )

24. ADMINISTERED BY (If other than Item 7)

25. PAYMENT WILL BE MADE BY

CODE

CODE

PHONE:

FAX:

26. NAME OF CONTRACTING OFFICER (Type or print)

27. UNITED STATES OF AMERICA

28. AWARD DATE

IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.

(Signature of Contracting Officer)

(REV. 9-97)

10. FOR INFORMATION CALL:

11. TABLE OF CONTENTS

AUTHORIZED FOR LOCAL REPRODUCTION

STANDARD FORM 33

Previous edition is unusable Prescribed by GSA-FAR (48 CFR) 53.214(c)

SOLICITATION, OFFER AND AWARD

SOLICITATION

OFFER (Must be fully completed by offeror) AWARD (To be completed by Government) N/A 36C10B23R0011 X Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 T4NG2.TAC@va.gov See Attached Table of Contents X X X X X X X X X X X X X Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 Department of Veterans Affairs Technology Acquisition Center Financial Services Center PO Box 149971 Austin TX 78714-8971

SECTION A - SOLICITATION/CONTRACT FORM

SF 33 SOLICITATION, OFFER AND A

CONTENTS

PART I - THE SCHEDULE1
SECTION A - SOLICITATION/CONTRACT FORM1
SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS3

SECTION C - DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK

SECTION D - PACKAGING AND MARKING82
SECTION E - INSPECTION AND ACCEPTANCE83
SECTION F - DELIVERIES OR PERFORMANCE84
SECTION G - CONTRACT ADMINISTRATION DATA85
SECTION H - SPECIAL CONTRACT REQUIREMENTS87
PART II - CONTRACT CLAUSES94
SECTION I - CONTRACT CLAUSES94
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACHMENTS119
SECTION J - LIST OF ATTACHMENTS119
PART IV - REPRESENTATIONS AND INSTRUCTIONS120
SECTION K - REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF OFFERORS120
SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS128
SECTION M - EVALUATION FACTOR FOR AWARD152

SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS

B.1 GOVERNING LAW

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.2 HYBRID CONTRACT TYPE

The contract type is a hybrid containing: Firm-fixed-Price (FFP), Time-and-Materials (T&M)/Labor-hour (LH), Cost reimbursement (CR) line items.

B.3 PRICE SCHEDULE:

NOTE: FOR PROPOSAL PURPOSES ONLY, CLIN PRICING IS NOT REQUIRED IN SECTION B OF THIS SOLICITATION.

All price proposals must be submitted in the format provided at Section J, Attachment 001. The deliverables associated with Contract Line Item Numbers (CLIN) 0004 through 0011 shall be submitted for each task order and included in the price/cost of each task order. The specific deliverables under CLINs 0004 through 0011 will not be set forth under individual Task Orders.

PRICE SCHEDULE

BASE PERIOD

CLIN
DESCRIPTION
QUANTITY
UNIT
UNIT COSTS
TOTAL COST
0001
Firm-Fixed-Price Line Item

SECURITY CLASS: Determined at Task Order Level This CLIN is to provide Information Technology (IT) services and incidental supplies on a FFP basis for a period of 60 months from date of award in accordance with (IAW) the Transformation Twenty-One Total Technology Next Generation Two (T4NG2) Performance Work Statement (PWS) set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and Free on Board (FOB) Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

The delivery or performance schedule shall be determined on each individual Task Order.

0002
Time-and-Materials/Labor-Hour Line Item

SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a T&M/LH basis for a period of 60 months from date of award IAW the T4NG2 PWS set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

0003
Cost Reimbursement Line Item

SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a CR basis for a period of 60 months from date of award IAW the T4NG2 PWS set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

0004
Contractor’s Progress, Status, and Management Report

Monthly Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.1(A) and (B)(C)(D) and (E), and Section J Attachment 003 when applicable to Task Order contract type.

FOB Point: Destination Inspection/Acceptance: Destination

NSP
NSP
0005
Contract Performance Report

Contract Performance Report shall be provided IAW Section C, PWS, Paragraph 8.1.2 (A) and (B), and Section J Attachments 004 (T&M) and 005 (CR) when applicable to Task Order contract type. Report not applicable for FFP Task Orders.

NSP
NSP
0006
Government Furnished Equipment Status Report

Government Furnished Equipment Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.3 (A-K) and Section J, Attachment 006.

NSP
NSP
0007
Personnel Contractor Manpower Report

Personnel Contractor Manpower Report shall be provided IAW Section C, PWS, Paragraph 8.1.4 (A-S) and Section J, Attachment 008.

NSP
NSP
0008
Contractor Staff Roster

Contractor Staff Roster shall be provided IAW Section C, PWS, Paragraph 8.1.5 and Section J, Attachment 009.

NSP
NSP
0009
Small Business Participation Report

Small Business Participation Report shall be provided IAW Section H, clause H-4 Small Business Participation Requirements, and Section J, Attachment 010.

NSP
NSP
0010
Veterans Employment Certification Report

Veterans Employment Certification Report IAW Section H, clause H-5 and Section J, Attachment 011.

NSP
NSP
0011
Final Section 508 Compliance Test Results

Final Section 508 Compliance Test Results IAW PWS Paragraph 8.1, Reporting Requirements.

NSP
NSP

Option Period One This 60-month option period may be exercised at the Government’s discretion IAW FAR 52.217-9, Option to Extend the Term of the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer (CO). If exercised, this option shall commence immediately after expiration of the base period.

PRICE SCHEDULE

OPTION PERIOD

CLIN
DESCRIPTION
QUANTITY
UNIT
UNIT COSTS
TOTAL COST
1001
Firm-Fixed-Price Line Item

SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a FFP basis for a period of 60 months from date of option exercise IAW the T4NG2 PWS set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and Free on Board (FOB) Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

1002
Time-and-Materials/Labor-Hour Line Item

SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a T&M/LH basis for a period of 60 months from date of option exercise IAW the T4NG2 PWS set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

1003
Cost Reimbursement Line Item

SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a CR basis for a period of 60 months from date of option exercise IAW the T4NG2 PWS set forth in Section C.

Specific requirements and pricing shall be set forth under individual Task Orders.

Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.

1004
Contractor’s Progress, Status, and Management Report – Task Order Level

Quarterly Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.1(A) and (B)(C)(D) and (E), and Section J Attachment 003 when applicable to Task Order contract type.

NSP
NSP
1005
Contract Performance Report -

Task Order Level

Quarterly Contract Performance Report shall be provided IAW Section C, PWS, Paragraph 8.1.2 (A) and (B), and Section J Attachments 004 (T&M) and 005 (CR) when applicable to Task Order contract type. Report not applicable for FFP Task Orders.

NSP
NSP
1006
Government Furnished Equipment Status Report – Task Order Level

Quarterly Government Furnished Equipment Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.3 (A-K) and Section J, Attachment 006.

NSP
NSP
1007
Personnel Contractor Manpower Report – Task Order Level

Quarterly Personnel Contractor Manpower Report shall be provided IAW Section C, PWS, Paragraph 8.1.4 (A-S) and Section J, Attachment 008.

NSP
NSP
1008
Contractor Staff Roster - Task Order Level

Due within thee (3) business days of Task Order award. Contractor Staff Roster shall be provided IAW Section C, PWS, Paragraph 8.1.5 and Section J, Attachment 009.

NSP
NSP
1009
Small Business Participation Report

Quarterly Small Business Participation Report shall be provided IAW Section H, clause H.4 Small Business Participation Requirements, PWS Paragraph 8.1.6 and Section J, Attachment 010.

NSP
NSP
1010
Veterans Employment Certification Report

Quarterly Veterans Employment Certification Report IAW Section H, clause H.5, PWS Paragraph 8.1.7 and Section J, Attachment 011.

NSP
NSP
1011
Final Section 508 Compliance Test Results

Final Section 508 Compliance Test Results IAW PWS Paragraph 8.1, Reporting Requirements.

NSP
NSP

Contract Maximum/Minimum Ceiling:

IAW Section I, clause 52.216-22 entitled, “Indefinite Quantity” the Maximum value of the T4NG2 contract is $60.7 Billion. The maximum overall value of the T4NG2 contract for both the base period and options is $60.7 Billion. IAW Section I, clause 52.216-22 entitled, “Indefinite Quantity” the Minimum guaranteed value under the T4NG2 contract is $1,000. The Government reserves the right to award initial orders at the time of the basic contract award on a sole source basis pursuant to FAR 16.505(b)(2)(iv) at amounts which may exceed the minimum guaranteed value. There will be no guaranteed minimum order for the option period, if exercised.

The ceiling price as set forth in Section I, clause 52.232-7 entitled, “Payments under Time-and-Materials and Labor-Hour contracts” will be established for each individual Time-and Materials Task Order.

36C10B23R0011

SECTION C - DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK

Performance Work Statement (PWS) for the

Transformation Twenty-One Total Technology Next Generation (T4NG)2 Program

DATE: December 5, 2022 Department of Veterans Affairs Office of Procurement, Acquisition and Logistics Technology Acquisition Center (TAC)

Version History

Version #
Version Description
Release Date

Contents

1.0SCOPE19
2.0APPLICABLE DOCUMENTS19
3.0GENERAL REQUIREMENTS23
3.1Contract Type23
3.2Ordering Period23
3.3Hours of Work23
3.4Place of Performance23
3.5Travel24
3.6Materials, Equipment and Locations24
3.6.1Government-Furnished24
3.6.2Contractor-Acquired24
3.6.3Non-Developmental Items and Commercial Processes24
3.6.4Connectivity24
3.6.5Facilities25
3.6.5.1Government Facilities25
3.6.5.2Non-Government Facilities25
3.6.6Warranty25
3.6.7Marking, Handling, Storage, Preservation, Packaging, Tracking & Shipping25
3.6.8Export Control25
3.7Safety and Environmental25
3.8Enterprise and IT Framework26
3.8.1VA Technical Reference Model26
3.8.2Federal Identity, Credential, And Access Management (FICAM)26
3.8.3Internet Protocol Version 6 (Ipv6)27
3.8.4Trusted Internet Connection (TIC)28
3.8.5Standard Computer Configuration28
3.8.6Enterprise Management Framework28
3.8.7Authoritative Data Sources29
3.8.8Social Security Number (SSN) Reduction29
3.9Development Methodologies30
3.10Integrated Product Teams30
3.11Quality Assurance31
3.12Transition and Orientation Support31
3.13Government Inspection and Oversight31
4.0TECHNICAL FUNCTIONAL AREAS33
4.1Program Management, Strategy, Enterprise Architecture and Planning Support33
4.1.1Strategy and Planning33
4.1.2Standards, Policy, Procedure and Process Development, and Implementation Support33
4.1.3Requirements Development and Analysis Support33
4.1.3.1Requirements Packages34
4.1.4Technology Refresh and Configuration Reviews34
4.1.5Studies and Analyses34
4.1.6Program Management Support35
4.1.7Product Data35
4.1.8IT Services Management Support35
4.1.9Development Toolkits36
4.2Systems/Software Engineering36
4.2.1Design and Development37
4.2.2Architecture Development37
4.2.3IT Service Management Implementation37
4.2.4Enterprise Application/Services38
4.2.5Cloud Computing38
4.2.6Web Application Design and Development38
4.2.7Mobile Application Design and Development38
4.2.8Human-Computer Interaction38
4.2.9System/Software Integration39
4.2.10Modeling and Simulation39
4.2.11Informatics Services39
4.2.12Engineering and Technical Documentation39
4.2.13Current System and Data Migration39
4.2.14Development Toolkit Support40
4.3Software Technology Demonstration and Transition40
4.4Test & Evaluation (T&E)40
4.5Independent Verification and Validation (IV&V)40
4.6Enterprise Network40
4.6.1Systems/Network Administration41
4.6.2Network and Telecommunications Infrastructures41
4.7Enterprise Management Framework42
4.8Operations and Maintenance (O&M)42
4.8.1Systems/Network Administration43
4.8.2Application Support43
4.8.3Hardware Support43
4.8.4Security Management43
4.8.5Disaster Recovery (DR) and Continuity of Operations (COOP)43
4.8.6Capacity/Availability Planning and Management44
4.8.7Service/Help Desk/Call Center Support44
4.8.8Asset Management44
4.8.9License Maintenance44
4.8.10Database and Data Warehouse Administration44
4.8.11Data Center Administration45
4.9Cyber Security45
4.9.1Information Assurance (IA)45
4.9.2Logical Security45
4.9.3Assessment and Authorization46
4.9.4Cyber Security Operational Support46
4.9.5Cyber Threat Intelligence46
4.9.6Cyber Business Intelligence46
4.9.7Insider Threat Analysis46
4.9.8External Assessment Services47
4.9.9Cyber Security Exercise Coordination Support47
4.10Training47
4.11Information Technology Facilities48
4.11.1Incidental Facility Design and Modification Services48
4.11.2Site Surveys48
4.11.3Facility Connectivity48
4.11.4Installation48
4.11.5Physical Security Systems49
5.0DELIVERABLES49
5.1Products49
5.2Data49
6.0SECURITY AND PRIVACY49
6.1Information Security and Privacy Security Requirements49
6.2Personnel Security Requirements49
6.3Facility/Resource Provisions51
6.4Badges52
6.5Classified Work52
6.6Incident Reporting and Management52
6.7Security and Privacy Awareness Training53
6.8Security Role Based Training53
7.0CONTRACT MANAGEMENT53
7.1Government Support53
7.1.1Task Order COR53
7.2Contractor Program Management53
7.2.1Work Control53
7.3Pre-Award Procedures53
7.3.1Request for Task Execution Plan (RTEP) Process53
7.3.1.1Yes/No Bids54
7.3.2Task Execution Plan (TEP)54
7.3.3TEP Evaluation58
7.4Issuance of Task Orders58
7.5Logical Follow-Ons58
8.0REPORTING AND MEETING REQUIREMENTS59
8.1Reporting Requirements59
8.1.1Contractor’s Progress, Status and Management Report59
8.1.2Contract Performance Report (CPR)60
8.1.3Status of Government Furnished Equipment (GFE) Report60
8.1.4Personnel Contractor Manpower Report61
8.1.5Contractor Staff Roster61
8.1.6Small Business Participation Report62
8.1.7Veterans Employment Certification Report63
8.2Meetings and Reviews63
8.2.1Project Office Initial Program Review (IPR)63
8.2.2Post-Award Conferences63
8.2.3Program Reviews63
8.2.4Quarterly Collective Prime Program Reviews64
ADDENDUM A– ADDITIONAL VA REQUIREMENTS, CONSOLIDATED65
ADDENDUM B- VA INFORMATION AND INFORMATION SYSTEM SECURITY / PRIVACY LANGUAGE71

1.0 SCOPE

This PWS establishes the requirements for Contractor-provided solutions and services in support of Information Technology (IT). Contractor-provided solutions may support the Department of Veterans Affairs (VA) and other Federal Agencies. The Contractor shall provide total IT service solutions to include the following functional areas: program management, strategy, enterprise architecture and planning; systems/software engineering; software technology demonstration and transition; test and evaluation; independent verification and validation; enterprise network; enterprise management framework; operations and maintenance; cybersecurity; training; IT facilities; and other solutions encompassing the entire range of IT and Health IT requirements, to include software and hardware incidental to the solution. Accordingly, Task Orders may include acquisitions of software and IT products. T4NG is not intended as a mechanism to solely purchase IT products. Such products may be purchased to the extent that those products are necessary to deliver the solution required. IT services, as well as related IT products, may encompass the entire life-cycle of a system. Moreover, IT services and related products covered under this contract shall be global in reach and the Contractors must be prepared to provide services and deliverables worldwide.

This PWS provides general requirements. Specific requirements shall be defined in individual Task Orders. Functional area requirements are described in Section 4.0 and are not mutually exclusive for Task Order requirements. Requirements may fall within one specific functional area but in many cases, the requirements will encompass and apply across and within multiple functional areas to provide the total life cycle solution.

2.0 APPLICABLE DOCUMENTS

The Contractor shall comply with the documents listed below. Additional documents may be listed in individual Task Orders.

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”

4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004

5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

8. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, title IX Information Security Matters

9. 10 U.S.C. § 2224, "Defense Information Assurance Program"

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, (https://www.va.gov/vapubs/index.cfm)

12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016 (https://www.va.gov/vapubs/index.cfm)

13. VA Directive 6102 (Internet/Intranet Services), August 5, 2019 (https://www.va.gov/vapubs/index.cfm)

14. VA Handbook 6102 (Internet/Intranet Services), August 5, 2019 (https://www.va.gov/vapubs/index.cfm)

15. Health Insurance Portability and Accountability Act (HIPAA); 45 CFR Part 160, 162, and 164; Health Insurance Reform: Security Standards; Final Rule dated February 20, 2003

16. VHA Directive 1605.05, Business Associate Agreements, November 17, 2020, (https://www.va.gov/vhapublications/ViewPublication.asp?pub_ID=9178)

17. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017

18. Office of Management and Budget Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

19. U.S.C. Section 552a, as amended

20. Title 32 CFR 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”

21. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008

22. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. Section § 794d), as amended, January 18, 2017

23. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

24. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021 (https://www.va.gov/vapubs/index.cfm)

25. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” February 24, 2021 (https://www.va.gov/vapubs/index.cfm)

26. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019 (https://www.va.gov/vapubs/index.cfm)

27. VA Handbook, 6500.5, Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010 (https://www.va.gov/vapubs/index.cfm)

28. VA Handbook 6500.6, “Contract Security,” March 12, 2010 (https://www.va.gov/vapubs/index.cfm)

29. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011 (https://www.va.gov/vapubs/index.cfm)

30. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018

31. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

32. Office of Information and Technology (OIT) Process Asset Library (PAL) https://www.va.gov/process/. Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

33. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

34. Federal Travel Regulation (FTR) (www.gsa.gov/federaltravelregulation)

35. One-VA Technical Reference Model (TRM) (https://www.va.gov/trm/TRMHomePage.aspx)

36. Federal Segment Architecture Methodology (FSAM) v1.0, December 2008

37. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014 (https://www.va.gov/vapubs/index.cfm)

38. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

39. VA Handbook 6510, “VA Identity and Access Management,” January 15, 2016

40. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017

41. VA Directive 6300, “Records and Information Management,” September 21, 2018 (https://www.va.gov/vapubs/index.cfm)

42. VA Handbook, 6300.1, “Records Management Procedures,” March 24, 2010 (https://www.va.gov/vapubs/index.cfm)

43. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

44. OMB Memorandum “Security Authorization of Information Systems in Cloud Computing Environments,” December 8, 2011 (FedRAMP Policy Memorandum)

45. VA Directive 6609, “Mailing of Sensitive Personal Information,” May 20, 2011 (https://www.va.gov/vapubs/index.cfm)

46. VA Enterprise Technology Strategic Plan, February 28, 2014

47. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015 (https://www.va.gov/vapubs/index.cfm)

48. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014 (https://www.va.gov/vapubs/index.cfm)

49. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

50. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

51. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

52. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)

53. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,” June 2018

54. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020

55. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

56. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile Devices (Draft),” October 2012

57. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

58. IAM Identity Management Business Requirements Guidance document, May 2013, (https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

59. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

60. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

61. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

62. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

63. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

64. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

65. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018

66. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

67. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013 (https://www.va.gov/vapubs/index.cfm)

68. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013 (https://www.va.gov/vapubs/index.cfm)

69. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

70. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

71. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

72. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

73. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

74. NIST SP 500-267B Revision 1, ”USGv6 Profile,” November 2020

75. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),“ November 19, 2020

76. Social Security Number (SSN) Fraud Prevention Act of 2017

77. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018

78. VA Enterprise Cloud (VAEC) Technical Reference Guide, July 2018 version 1.3

3.0 GENERAL REQUIREMENTS

The Contractor shall provide and/or acquire the services, hardware, and software required by individual Task Orders pursuant to the general requirements specified below.

3.1 Contract Type

This is an Indefinite Delivery/Indefinite Quantity (IDIQ) Multiple Award Task Order (MATO) contract. Individual Task Orders shall be issued on a performance-based T&M, CR, and/or FFP basis.

3.2 Ordering Period

The ordering period for the basic contract shall be five years with one five-year option.

3.3 Hours of Work

Generally, work at a Government site shall not take place on Federal holidays or weekends unless directed by the CO or individual Task Order; however, the Contractor may be required to support 24/7 operations 365 days per year as identified in individual Task Orders.

There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, five are set by date:

New Year's DayJanuary 1
JuneteenthJune 19
Independence DayJuly 4
Veterans DayNovember 11
Christmas DayDecember 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's BirthdayThird Monday in January
Washington's BirthdayThird Monday in February
Memorial DayLast Monday in May
Labor DayFirst Monday in September
Columbus DaySecond Monday in October
ThanksgivingFourth Thursday in November

3.4 Place of Performance

The place of performance shall be identified in individual Task Orders. Locations can be Government or non-Government sites within the continental United States (CONUS) and/or outside the continental United States (OCONUS). Locations may include but are not limited to Federal, State, VA, or military data centers, facilities, regional offices, benefits delivery centers, medical treatment facilities, health clinics and Tricare facilities as defined in individual Task Orders.

3.5 Travel

Travel shall be in accordance with (IAW) individual Task Order requirements. Travel details must be provided to and approved by the CO’s Representative (COR) or the Government designee prior to the commencement of travel. All travel shall be IAW the Federal Travel Regulations (FTR). OCONUS travel may require additional authorization and approvals as specified in the individual Task Order.

3.6 Materials, Equipment and Locations

3.6.1 Government-Furnished

Government Furnished Property (GFP) which includes Government Furnished Material (GFM), Government Furnished Information (GFI), and Government Furnished Equipment (GFE) may be provided and shall be identified in the individual Task Order. The Contractor shall be responsible for conducting all necessary examinations, inspections, maintenance, and tests upon receipt. The Contractor shall be responsible for reporting all inspection results, maintenance actions, losses, and damage to the Government through the VA Technology Acquisition Center (TAC) website.

VA may provide VA-specific software as appropriate and required in individual Task Orders. The Contractor may utilize VA-provided software development and test accounts, document and requirements repositories and others as required for the development, storage, maintenance and delivery of products. Contractors shall comply with VA security policies and procedures with respect to protecting sensitive data. See Section 6.0 for detailed security requirements.

3.6.2 Contractor-Acquired

The Contractor shall acquire and/or provide any hardware and/or software required to accomplish each Task Order that is not provided as GFP. Software integrity shall be maintained by the Contractor within the licensing agreement of the producer until such software is delivered to the Government, or otherwise disposed of IAW Government direction. Items delivered to the Government shall be approved by the Government in advance of purchase and shall be in compliance with PWS paragraphs 3.8 and A3.0. See Section 6.0 for detailed security requirements.

3.6.3 Non-Developmental Items and Commercial Processes

Non-Developmental Items (NDI), Commercial-Off-The-Shelf (COTS) and Government-Off-The-Shelf (GOTS) products shall be used to the maximum extent. The Contractor shall apply commercially available and industry best processes, standards and technologies to the maximum extent.

3.6.4 Connectivity

VA will provide connectivity to VA-specific systems/network as required for execution of the task via VA approved remote access technology. Currently this may include but is not limited to Citrix Access Gateway (CAG), Azure Virtual Desktop, site-to-site VPN, or VA Remote Access Security Compliance Update Environment (RESCUE). This remote access will provide connectivity to VA-specific software such as Veterans Health Information System and Technology Architecture (VistA), Electronic Health Record Modernization (EHRM), ServiceNow, ClearQuest, PAL, Primavera, and Remedy, including appropriate seat management and user licenses. VA may install equipment at the Contractor’s site to ensure security requirements are in place. The Contractor must meet the requirements of VA Handbook 6500 and will bear the cost to provide connectivity to VA. Other connectivity to VA systems may be authorized as appropriate in individual Task Orders.

3.6.5 Facilities

Work may be performed at either a Government or non-Government facility. Each Task Order shall delineate the facility and location requirements.

3.6.5.1 Government Facilities

Certain Government office or laboratory space may be made available for performance of individual Task Orders. Contractors may be required to establish operations and support Government locations and shall comply with VA and/or Federal assessment and authorization (A&A) requirements. Such facilities shall be specified in the individual Task Order.

3.6.5.2 Non-Government Facilities

Personnel may perform at Contractor or remote facilities if specified in the individual task order. Contractors may be required to establish operations and support Contractor facilities and shall comply with VA and/or Federal A&A requirements. Such facilities shall be specified in the individual Task Order. The Contractor shall disclose specific facility information during the Request for Task Execution Plan (RTEP) process. All facilities shall be approved by VA and in compliance with PWS paragraph 6.0, Security and Privacy.

3.6.6 Warranty

Items acquired under this contract may require warranty protection. Commercial warranties shall be transferred to the Government. The type of warranty and extent of coverage shall be determined on an individual Task Order basis.

3.6.7 Marking, Handling, Storage, Preservation, Packaging, Tracking & Shipping The Contractor shall establish/maintain procedures IAW VA Handbook 6500 and VA Directive 6609 for handling, storage, preservation, packaging, marking, tracking and shipping to protect the quality of products and prevent damage, loss, deterioration, degradation or substitution of products.

3.6.8 Export Control

The Contractor shall comply with all applicable laws and regulations regarding export-controlled information and technology and shall not use, distribute, transfer or transmit technology (even if incorporated into products, software or other information) except in compliance with such laws and regulations. In addition, the Contractor shall plan for, obtain, and maintain all export licensing required to satisfy individual Task Order requirements.

3.7 Safety and Environmental

Safety and environmental procedures shall be identified in individual Task Order requirements.

The Contractor shall comply with the Office of Federal Sustainability Acquisition and Electronics Stewardship initiatives as identified in individual Task Orders IAW the policies referenced at https://www.sustainability.gov/resources-eo-efo.html

3.8 Enterprise and IT Framework

3.8.1 VA Technical Reference Model

For VA-specific task orders, the Contractor shall support the VA Enterprise Management Framework (EMF). In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM) and consider the VA Enterprise Technology Strategic Plan. The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the IT used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT.

3.8.2 Federal Identity, Credential, And Access Management (FICAM) The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls,” and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19-17 can be found at: https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2005/m05-24.pdf and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems can support the following:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers is the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

3.8.3 Internet Protocol Version 6 (Ipv6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

3.8.4 Trusted Internet Connection (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.

3.8.5 Standard Computer Configuration

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

3.8.6 Enterprise Management Framework

The EMF provides an enterprise-wide view of VA IT systems comprised of tools, reports, databases, dashboards, and analytics. EMF enables OIT to view the health and performance of systems and provides intelligent analysis and trending that enables proactive enterprise system management. Performance, availability, user experience and reliability of IT service delivery is improved as OIT can make strategic, operational and investment decisions based on real-time information.

EMF supports a unified enterprise service management model including release management, configuration management, change management, and incident management aligned with industry standard IT Infrastructure Library (ITIL) service management best practices. The EMF Federated Data Repository (FDR) includes the implementation of a foundational component. The EMF FDR is a national repository that collects enterprise IT management data from VA Managed Data Repositories (MDRs) and integrates with existing VA monitoring and performance systems.

Additional frameworks may be specified in individual task orders.

3.8.7 Authoritative Data Sources

The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .