Attachment 1_PWS_EMCS Recompete.pdf
PDF 373 KB Posted
- Attached to
- Energy Management and Control Services (EMCS) Federal contract opportunity
- Solicitation number
- FA487726QA002
About this file
This Performance Work Statement (PWS) details Energy Management and Control Services (EMCS) for the 355th Civil Engineer Squadron at Davis-Monthan Air Force Base (DMAFB) in Arizona. The contract requires a contractor to operate, maintain, and repair the EMCS system, with responsibilities including monitoring system performance, troubleshooting HVAC control issues, performing field work, coordinating equipment repairs, and providing cybersecurity services. The contractor must fill three key roles: EMCS Service User, EMCS Service Administrator, and EMCS IT Administrator, with the potential for a single person to fill multiple roles if all requirements are met.
Key technical requirements include maintaining Niagara software, complying with multiple cybersecurity regulations, performing maintenance and repairs on Siemens/Staefa control systems, and managing approximately 170,000 input/output points across 145 buildings. Contractor personnel must be US citizens, possess a Secret security clearance, have at least 5 years of experience with HVAC systems and EMCS automated systems, and be certified Siemens Controllers programmers. The contract specifies regular and peak season work hours, with emergency response capabilities required 24/7, and includes provisions for equipment replacement, cybersecurity compliance, and strict operational security protocols.
View the file
Other files for this federal contract opportunity
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA487726QA002
1 | P a g e
Performance Work Statement (PWS) For
Energy Management and Control Services (EMCS)
Objective. Operate, maintain, and repair the Energy Management and Control System (EMCS) system in support of the 355th Civil Engineer Squadron (355 CES) at DMAFB. Contractor personnel shall be responsible for operating the EMCS, aid technicians, modify HVAC systems, respond to outages, update EMCS software, perform maintenance and repairs to the EMCS system/components, and provide cybersecurity services per 4.19.
1.0. Description of Services. The contractor shall provide all personnel, labor, equipment, tools, materials, transportation, supervision, and other items and services necessary to operate, maintain, repair, and upgrade the daily execution of FRCS/ICS network and server operations for the 355 CES Energy Management and Control System (EMCS), at Davis-Monthan Air Force Base (DMAFB), AZ. EMCS is considered a controls system under Air Force Guidance Memorandum (DAFGM) 2024-32-01, Civil Engineer Control Systems Cybersecurity. As such, the contractor shall comply with DMAFB Design Guide, United Facilities Criteria (UFC) 04-10-06, Cybersecurity of Facility- Related Control Systems, Air Force Instruction (AFI) 17-101, Risk Management Framework (RMF) for Air Force Information Technology (IT), (or subsequent guidance from this memo) all cybersecurity guidance, Department of Defense Manual (DODM) 5200.02, Procedures for the DoD Personnel Security Program (PSP), AFGM 17-1303_AFGM 2019-01, Cybersecurity Workforce Improvement Program, DAFGM 2024-32-01, Civil Engineer Control Systems Cybersecurity, 355 Civil Engineer Squadron (355 CES) Energy Management Control Systems Configuration Management Plan and Contingency Plan.
1.0.1. Scope of Work. The purpose of the services requested under this PWS is to fill the roles of EMCS Service User, EMCS Service Administrator, and EMCS IT Administrator. A single person can fill multiple roles i.e. Service User & Service Administrator, if all requirements are met.
The EMCS Service User is responsible for monitoring system performance and connectivity;
troubleshooting functional HVAC control issues; performing field work and coordinating equipment and device repairs and replacement part acquisitions; working with 355 CS and 355 CES to resolve network outages and issues; and fulfilling the requirements contained in this PWS.
The EMCS Service Administrator is responsible for providing security expertise for the system, configuring and implementing industrial control solutions; performing field work and providing technical support and resolving operational issues; monitoring system performance; ensuring data requirements are met; coordinating repair and replacement of equipment, devices, and software ;
working with networks and communication protocols relevant to control systems; and fulfilling the requirements contained in this PWS.
The EMCS IT Administrator is responsible for the configuration, maintenance, and overall health of the EMCS IT infrastructure at the workstation, server, and building level. This includes programmable field devices and equipment, workstations, servers, networks, and enterprise software, ensuring they function efficiently and securely; optimizes internal IT infrastructure;
backups the building JACE and other field equipment and device configurations; and ensuring compliance with cybersecurity regulations; and fulfilling the requirements contained in this
PWS.
2 | P a g e
The contractor must understand and abide by applicable regulations listed throughout this PWS;
however, the contractor is not responsible for cybersecurity compliance. Contractor personnel shall support Government personnel that are responsible for cybersecurity compliance as required by this PWS. Support is defined as the supply of information necessary for the preparation of cybersecurity documentation that Government personnel are required to prepare on a regular basis.
Common examples are as follows:
• Government personnel shall process configuration change requests for the EMCS o Contractor personnel shall fill out hardware and software change requests
• Government personnel create and enter Plan of Action and Milestones (POA&Ms) o Contractor personnel shall provide adequate mitigation information in support of the Government’s POA&M
DMAFB’s EMCS needs hands-on field people that stand on ladders, get above ceilings, in hot rooms, outside, etc. as control system specialists that trouble shoot problem equipment and controllers, remove and replace controllers, map control points at the building level and EMCS head end, program JACEs, create EMCS graphics, trouble shoot network issues with the 355th Comm Squadron (355 CS) and 355 CES, understand HVAC systems, processes, and sequences, and provide cybersecurity updates at the server level and any field devices in conformance with DoD/USAF requirements. Contractors performing work on DMAFB’s EMCS server, software, related equipment and components, and field devices including, but not limited to, thermostats, VAV controllers, AHU controllers, network control cards/devices, JACEs, and other HVAC related products shall be Certified Siemens Contractors.
1.1. Deliverables/Reporting Requirements.
Deliverables PWS Para. Submit To
Reports 1.7.3. through 1.7.4.3. Contracting Officer’s Representative (COR) Price List for Parts 1.8.1. Contracting Officer (CO) & COR Facility Clearance 2.2. CO
Quality Control Plan 3.1-3.2 CO & COR
1.2. Operate EMCS. Operation of the EMCS includes all actions necessary to operate heating, ventilation, and air conditioning (HVAC) equipment to minimize total operating costs. This includes, but is not limited to, test and evaluation, integration, execution, construction, operation, maintenance, sustainment, upgrade or replacement, operation control, and adjustment of EMCS equipment; monitoring and control of HVAC equipment; remediation of alarm conditions;
hardware and software upgrades, maintenance and inspection of EMCS equipment; maintaining logs and producing reports; and assisting in the troubleshooting of HVAC equipment. The contractor shall perform recordkeeping of operations and conditions, analysis of records to correct non-optimal practices, monitor warranties, test operations and capabilities of equipment, periodic operation and inspection of EMCS equipment, purchasing of supplies (parts & materials), cleaning, preservation, calibration, and adjustment to the EMCS equipment. Maintenance records of the
3 | P a g e
EMCS system shall be provided to the government on a quarterly basis to support Cybersecurity continuous monitoring. The contractor shall continually monitor the Cybersecurity and Infrastructure Security Agency (CISA) vulnerability listings and notify the 355 CES Information System Owner (ISO) at 355CES.CEIA.IT@us.af.mil and the COR when CISA issues vulnerability notices for equipment installed in the EMCS and include proposed actions and mitigations per the “Proposed Actions” section below. The contractor’s maintenance and backup plan shall include the following:
a. Proposed Actions: Include a detailed description of each vulnerability and actions:
Resolve, Mitigate, Accept with dates and owner’s representatives (ISO, Information System Security Manager (ISSM), Information System Security Office (ISSO), and COR)
b. Status: Draft, Pending Approval, Expired, Completed
c. Risk: High, Medium, Low
d. Status: Pending, Approved
The contractor shall inspect each facility annually (per contract year) or as needed, verifying EMCS equipment is operating per the sequence of operations, including verification of all input/output devices functioning within designed specification, and determine if the building JACE is communicating properly with the Niagara head-end.
1.3. Operational Emergencies. During emergencies such as any environmental, health and safety hazardous situation, broken or shut off HVAC equipment, pipes, components, etc., which shall potentially cause a facility to be unable to comply with Occupational Safety and Health Act (OSHA), Environmental Protection Agency (EPA), and any other regulatory agency’s regulation, law, requirement, etc., and/or result in damage to equipment or the facility, the contractor shall report the situation to the COR, or 355 CES designated representative within 30 minutes of knowledge of the occurrence. If temporary EMCS modifications can fully or partially resolve the situation, those changes shall be made at the direction of a COR or 355 CES designated representative.
1.4. Assistance to Technicians. The contractor shall utilize EMCS equipment resources and provide information as required to assist service technicians (Government or other contractor personnel) in troubleshooting malfunctions and failures in equipment controlled or monitored by the EMCS, i.e. trouble shoot problem equipment and controllers, remove and replace controllers, map control points at the building level and EMCS head end, program JACEs, trouble shoot network issues with 355 CS and 355 CES designated representatives understand HVAC systems, processes, and sequences, provide cybersecurity updates at the server (Niagara) and workstation software level, and any field devices in conformance with DoD/USAF requirements. This includes configuring the EMCS equipment to produce logs, trends, system graphics, and graphs as necessary.
1.5. HVAC System Modifications. The contractor s h a l l install, program, edit, and modify hardware and software configurations and control sequences as necessary to accommodate HVAC system modifications and optimize system performance per DAFGM 2024-32-01, UFC and industry best practices, and train Government personnel when requested for new systems.
Network Outages (Re-stablishing Connectivity) The contractor shall notify 355 CS of an outage within mailto:355CES.CEIA.IT@us.af.mil
4 | P a g e
(2) hours of identification by creating a support ticket using the “Service Now” (EITaaS) system, and then e-mailing the 355 CS Focal Point (355CS.CFP@US.AF.MIL). Then notify 355 CES IT staff via email at 355CES.CEIA.IT@us.af.mil of the situation, provide the ticket number, and courtesy copy the COR. The contractor’s e-mail shall contain the building number, JACE identifier, Internet Protocol (IP) Address and Media Access Control Address (MAC), as well as a contact name and phone number to expedite processing.
The 355 CS Focal Point shall then address the support ticket. Where the outage is determined to be at the building JACE level the contractor shall actively assist 355 CS and 355 CES users to return the building JACE to network connected conditions until the building JACE is recognized at the EMCS server.
EMCS Equipment/Power Outages Where an outage is determined to be caused by an EMCS equipment failure the contractor shall notify 355 CES IT staff via email at 355CES.CEIA.IT@us.af.mil of the situation and courtesy copy the COR. . The contractor’s e-mail shall contain the building number, JACE identifier, and description of the outage cause.
The contractor shall check the JACE uninterruptible power supplies (UPS) at each building location at a minimum of once per year, verify the status and condition of the UPS, and replace the UPS when there are signs of failure or degraded performance.
1.6. Software updates. The contractor shall provide, install, and configure updates to operational software when required, including workstation, server, and network manager, at no additional cost to the Government. The contractor shall comply with AFI 17-101, DAFGM 2024-32-01, and all applicable existing standards and policies, including the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, UFC 04-010-06, NIST SP 800-82r2, Guide to Industrial Control Systems (ICS) Security, NIST SP 800-53r4 (or subsequent guidance from this memo), Security and Privacy Controls for Information Systems and Organizations.
1.7. Maintenance and Repairs. The contractor shall perform on-site maintenance and repairs to enable the EMCS to effectively control or monitor HVAC equipment. Most controls currently installed (as of contract start date), as well as associated software, are products of Siemens/Staefa Control Systems. These include MS 1800, Smart II, Talon Network Manager, Talon AX, Siemens Workbench, BACnet MS/TP Desigo and Apogee, and other product lines. All server systems currently under contract shall be upgraded to Niagara (N4.15 platform, JACE 8000 Network manager or most recent version compatible with both JACE 8000 and JACE 9000 devices, and Tridium products. The contractor shall perform maintenance and repairs in accordance with the most current manufacturer’s operating, maintenance, and repair manuals. The contractor shall repair electronics and physically replace valves when required. The contractor shall obtain and maintain mechanical licenses required to support valve replacement.
Maintenance, Repair, Upgrade Definitions are defined below:
• A bona fide “hardware repair” is defined as fixing a non-operational part of a piece of equipment or device to make the equipment or device fully operational.
• A bona fide “software repair” or “software update” is to change settings, install patches or firmware updates, or reset the software to factory conditions for reprogramming at the equipment, device, workstation, or server level.
• A “replacement” is defined as replacing a non-operational piece of equipment or device with a new one of the same make and model.
• An equipment or device “upgrade” is defined as replacing a non-operational or operational piece of equipment, or device with a newly purchased piece of equipment or device in full mailto:355CS.CFP@US.AF.MIL
5 | P a g e
• A software “upgrade” is defined as the installation of a newer software version that significantly improves or alters the existing software including, but not limited to, new features, functionality, and license key, in place of a prior software version that is no longer used at the equipment, device, workstation, or server level.
***Any and all parts provided by the government to maintain and or repair, not to include upgrades when warranted will be covered under the monthly summary contract line item number (CLIN). No additional labor will be authorized without written consent from the Contracting Officer.***
1.7.1. System Upgrades. The contractor shall comply with the most current version of DMAFB Design Guide and future revisions as adopted, UFC 04-10-06, AFI 17-101, DAFGM 2024-32-01 and all cybersecurity guidance DAFMAN 17-1301, Computer Security, and DAFMAN 17-1305, Cybersecurity Operations.
1.7.1.1. The contractor shall maintain Niagara software on one server and up to five clients with Niagara software in accordance with (IAW) current Authorization to Operate (ATO) requirements.
The contractor shall back up JACE configurations and provide a working copy to the COR on a minimum quarterly basis. The contractor must download all patches from applicable authorized software vendor sites (e.g. Tridium) for all applicable operating systems and applications. The contractor shall support Government vulnerability testing to ensure DoD cybersecurity compliance, continued availability of EMCS services, and to provide information necessary for Risk Management Framework (RMF) continuous monitoring. Any patch causing inoperability shall require on-site maintenance and troubleshooting, including any 3rd party vendor support, at no additional cost the Government. The contractor shall use 355 CES Configuration Management Plan procedures for all hardware and software changes.
1.7.2. Recordkeeping. The contractor s h a l l document inspections and maintain all inspection records, including inspection results. The contractor shall develop, implement, and maintain an organized method for storing and retrieving maintenance records, information, etc. Contractor inspection records must be kept and made available to the Government personnel throughout the contract performance period, and until final settlement of any claims under this contract. The contractor shall provide electronic file copies of all records to the COR before the 5th working day of each month. The contractor shall provide files in Microsoft Word/Excel etc., which is compatible with Government hardware and software. The contractor shall further provide (1) copy of operator, administrator, and/or maintenance manuals, copies of the system’s topology, hardware/software inventory, and configuration, as well as necessary training before the 5th working day of each month.
1.7.3. The contractor s h a l l prepare and maintain records associated with the EMCS hardware, software configuration, and firmware versions.
1.7.4. Reports. The contractor shall submit the following monthly reports to the COR, no later than the 5th working day of each month for the previous month:
1.7.4.1. Maintenance Report. The contractor shall submit a monthly report of all maintenance and repairs performed during the month. Reports shall include the building number, part description, cost, quantity, and actions taken to include system restarts.
6 | P a g e
1.7.4.2. Materials Costs Report. The contractor shall submit a monthly report of all parts replaced during the month. Reports must include building number, part description, cost, and quantity.
1.7.4.3. Operating Parameters Report. Upon request from the COR or CO, the contractor shall submit a report of specified operating parameters such as history blocks, trends and run-times, etc., for specified equipment. The reports must identify all operating parameters and conditions utilized to record the desired information.
1.8. Parts and Materials
1.8.1. The contractor shall repair/replace legacy parts with supplies on hand at no additional cost to the government. For new parts, the contractor shall procure all parts and materials required for operation, maintenance, and repairs of the EMCS. The contractor shall submit a price list for common parts to the CO and COR within 30 days of the contract award. The price list must be valid for one year and shall be updated and re-approved by the CO each subsequent contract option year.
Once the price list is approved, the contractor must submit written requests for approval of all parts to the COR, and include the quantity, price, location, impact, and repair time in the requests, prior to making any purchases.
1.8.3. Warranty Replacement. The contractor shall honor manufacturers and contract warranties, and the contractor shall maintain on-site records of equipment bearing warranties. The contractor shall provide support documentation for any warranty claims.
1.9 Estimates. The below are for estimate purposes only.
1.9.1. Estimated Input/Output Points and Buildings with Staefa Controls.
Quantities are expected to increase approximately five percent per year for the life of the contract.
Estimated total number of input/output points: 170,000 Estimated total number of buildings with Staefa/Siemens controls: 145 and growing
1.9.2. Estimated Annual Overtime for Service Calls.
After hours/weekends/holidays 60 hours
Most routine daily calls can be resolved via telephone coordination with the responding HVAC Technician.
2.0. Special Requirements
2.1. Continuation of Essential Contractor Services. The Government has determined that the services in PWS have been determined not to be mission essential and does not require continued support during crisis, as defined in Defense Federal Acquisition Regulation Supplement (DFARS), Subpart 237.76, Continuation of Essential Contractor Services.
2.2. Industrial Security. Contractor personnel shall have privileged access to Government systems and must meet investigative requirements of DoDM 8140.03, Cyberspace Workforce Qualification and Management Program, and DoDM 5200.02_DAFMAN 16-1405 Table 2 (T3), Department of
7 | P a g e
Air Force Personnel Security Program. Only contractors with an existing facility clearance (FCL) at the time of solicitation issuance can bid and/or work on this contract. A copy of the contractor’s FCL shall be submitted at the time of bid. Contractors must hold a minimum of a Secret facility clearance at time of bid submission and it must remain active throughout the life of the contract. The Contract Security Classification Specification (DD Form 254) shall encompass all security requirements. All contractor personnel shall also comply with Operations Security (OPSEC) requirements as set forth in DoD Directive 5205.02E, DoD Operations Security (OPSEC) Program and AFI 10-701, Operations Security (OPSEC). Application and cost for the appropriate Personnel Security Investigation (PSI) is the responsibility of the contractor.
2.3. Personnel Clearances. Contractor personnel assigned to this contract who shall perform server operations must possess and maintain a minimum US Government issued Secret security clearance at contract start, and throughout life of contract. All contractor employees performing services under this contract must be US citizens. The contractor may be required to provide employee background information to comply with contract requirements including Common Access Cards (CACs) and building access badges.
2.3.1. Clearance Revocation/Suspension. If the contractor is notified by any Government official having security cognizance over the contract that a contractor employee’s Security Clearance has been revoked or suspended, the contractor must notify the CO the same day the contractor receives the notice, and all access for the contractor employee must be revoked.
2.3.2. Contractor Employee Qualifications. Contractor EMCS technicians must read, write, speak, and understand English fluently. The contract technicians shall have at least 5 years of experience working with HVAC systems, 5 years of experience maintaining and operating EMCS automated systems, and be certified to program Siemens Controllers. EMCS contractor personnel consists of two roles, non-privileged user and non-critical sensitive privileged user/administrative user in accordance with 355 CES Energy Management Control System Policy Document 1.0.
Contractors performing work on DMAFB’s EMCS server, software, related equipment and components, and field devices including, but not limited to, thermostats, VAV controllers, AHU controllers, network control cards/devices, JACEs, and other HVAC related products shall be Certified Siemens Contractors.
Contractor personnel performing on unclassified automated information systems may be assigned to one of three position sensitivity designations (in accordance with DoDI 5200.02, DoD Personnel Security Program PSP and MINIMALLY investigated as follows:
ADP-II (AKA: IT-2): T3/T3R
ADP-III (AKA: IT-3):/T1
The contractor shall provide a DD Form 2875, System Authorization Access Request (SAAR), for each person, and a separate DD Form 2875 for each person’s differing role on the contract, Cyber Awareness Certificate, 355 CES Cybersecurity Training Certificate, and company secret clearance verification, to be submitted for approval. IAW DAFMAN 17-1301, para 2.12.8. all users must complete the Annual Cyber Awareness Challenge training located on the DISA website http:iase.disa.mil.
8 | P a g e
2.3.3. Non-Privileged Users. Non-privileged users must have a Tier 1 background investigation and Common Access Card (CAC) access to perform duties under this contract.
2.3.4. Privileged Users. This position is considered non-critical sensitive, privileged user IAT-II IAW Cyber security workforce requirements. Position accesses unclassified network information at the privileged user level which when aggregated can reach the level of Secret. The privileged level user shall have full access to sensitive network information/hardware to include network vulnerabilities and shall be instrumental in responding to any Cyber Security incident to gather data, take required actions to mitigate the incident, and restore the network to full capability. All incident responses shall be classified at the Secret classification level.
2.3.4.1. Privileged users must have DoD 8140.03, Cyberspace Workforce Qualification and Management Program, Information Assurance Technical Level II certification (IAT-II) and Information Technology Level II (T3 Secret) security clearance for all Administrative level IT access, programing, and repair in accordance with DoDM 5200.02, DODM 5200.02_DAFMAN16-1405, Department of the Air Force Personnel Security Program, and DoD 8140.03, Cyberspace Workforce Qualification and Management Program.
The contractor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions.
The contractor shall meet the applicable information assurance certification requirements, including: (1) DoD-approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DoD 8140.03; (2) Appropriate operating system certification for information assurance technical positions as required by DoD 8140.03.
Upon the Government’s request, the contractor shall provide documentation supporting the information assurance certification status of personnel performing information assurance functions. Contractor personnel who do not have proper and current certifications shall be denied access to DoD information systems for the purpose of performing information assurance functions.
For additional details on certifications meeting the IAT-LII requirements, please see DoD 8140.03 DoD 8140.03, Cyberspace Workforce Qualification and Management Program, Certification and Workforce Management Asked Questions at: https://cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/.(DoD Cyber Exchange/ CAC required).
2.4. Repairs. Under this contract repairs are required; payments for repairs shall be paid under Contract Line-Item Number (CLIN) 4 and must be invoiced in accordance with the contract instructions.
2.4.1. The contractor shall procure all parts and materials (not on the approved price list) required for repairs on a competitive basis. The contractor must submit the following to the COR for approval prior to purchasing anything required for repairs.
2.4.1.1. If there is a lack of competition, provide justification why competition was not obtained.
2.4.1.2. All quotes obtained for parts, equipment, materials, etc. are necessary to complete the repair.
2.4.1.3. Total quote (including labor, taxes, shipping), using the preferred quote received
9 | P a g e
2.4.2. Discounts and rebates on items provided to the contractor shall be passed on to the Government when invoiced by the contractor. All purchase documents shall be made available for COR to review and audit and must be attached to the invoice. The invoice shall be rejected if a copy of the purchase documents is not attached to the invoice. The Government reserves the right to specify quality, size, efficiency, and aesthetic requirements of all items.
2.4.3. The contractor shall invoice for all items each month. The invoice shall be supported by an itemized list of all parts and materials used, and include the item description, quantity, unit cost, total cost, and the end use of the item. The contractor shall maintain original delivery tickets, sales receipts, or other documents identifying the items purchased. Copies of sales tickets shall be submitted to COR with an invoice for monthly payment. If a copy of the sales ticket does not accompany the submission, the item shall not be paid.
3.0. Services Summary.
Performance Objective PWS Reference Performance Threshold
1. Operate EMCS 1.2.
through 1.6.
No more than 1 validated complaint per month
2. Provide effective maintenance and repair/replace of EMCS
1.7.
through 1.7.1.1.
No more than 1 validated complaint per month
3. Submit accurate operating, maintenance, and repair/replace reports
1.7.3.
through 1.7.4.3.
No validated complaint per month
3.1. Quality Control Program. In compliance with Federal Acquisition Regulation (FAR), clause 52.246-4, Inspection of Services – Fixed Price, the contractor shall maintain a quality control program to ensure services are performed in accordance with commonly accepted commercial practices and services identified in this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-performance and continual repeat of defective service does not occur. The contractor shall submit their quality control plan to the Contracting Officer and COR, no later than 30 days after contract award for acceptance. The plan shall include:
a. A description of the inspection system to cover all services listed in the PWS. Description will include specifics as to the areas to be inspected on both a scheduled and unscheduled basis, frequency of inspections, submission of quality control scheduling, and the title and organizational placement of the quality control inspectors.
b. A description of the methods to be used for identifying and preventing defects in the quality of service performed before the level of performance becomes unacceptable.
c. A description of the records to be kept to document inspections and corrective or preventive actions taken.
d. A description of the records which shal l be required to monitor EMCS for efficient and
10 | P a g e effective operations.
e. A procedural document demonstrating that a contractor understands the requirements of operating and preventive maintenance procedures respectively.
3.2. Government Quality Assurance. The Government shall inspect and evaluate the contractor’s performance to ensure services are received in accordance with the requirements set forth in the contract. The COR shall inspect by physically checking an attribute of the completed task, checking a management information report, investigating customer complaints, conferring with facility managers, or otherwise inspecting the task or its results to determine whether performance meets the standards contained in this PWS. The COR shall use the contractor’s work schedule, or modified version thereof, to record surveillance results. Periodic surveillance shall be conducted on a scheduled basis (daily, weekly, monthly, quarterly, semi-annual or annually) and may be adjusted, based on quality trends. Inspection results shall become the official Air Force record of the contractor’s performance. Any unsatisfactory surveillance result shall be recorded, and the contractor shall re-perform the service upon notification by COR. When a performance threshold has not been met or contractor performance has not been accomplished, COR shall initiate a Corrective Action Report (CAR) and provide the CAR to the CO for review. The CO shall issue the CAR to the contractor and the contractor shall respond to the CAR not later than the suspense date on the form, and return the completed form to the CO.
4.0. General Information
4.1. Data. The Government has unlimited rights to all deliverables of this contract to include intellectual property rights.
4.2. Government Training. The contractor shall provide fully qualified site personnel.
Government training shall be provided to the contractor personnel when the training is unique and available only to Government personnel. The Government shall provide workplace orientation, mission/system familiarization, and standard operational procedures training to the contractor at the place of performance.
4.3. List of Employees. Upon contract award, the contractor shall submit employee information to the COR as follows; front photocopy of employee driver’s license (or other means of positive identification), social security number, and citizenship status of all employees performing services on DMAFB. The contractor’s contract manager must be identified on the list. The contractor shall submit an updated list when an employee's status or information changes. Different levels of service require different TIERs of access; thus, the contractor shall conduct background checks based on the level of the individual’s access, in accordance with DoD 8140.03. Refer to AFMAN 17- 1303_AFGM 2019-01 for guidance on filling roles to Service Users and Service Admin rights.
4.4 Security Training. All contractor employees shall receive initial and recurring security education training from the 355 CES security manager. Training must be conducted in accordance with DoDM 5200.01 V1-V4, Information Security Program, and AFI 31-401, Air Force Information Security Program Management. Contractor personnel who work in Air Force controlled/restricted areas must be trained IAW AFI 31- 101, Integrated Defense.
4.5. Antiterrorism Awareness Training. Level I – Antiterrorism (AT) Awareness Training is available to all contractor employees. Non-Common Access Card (CAC) holders can accomplish
11 | P a g e
Level 1 - AT Awareness Training at https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf.
Additionally, contractor employees may contact the Government sponsoring agency’s Unit Antiterrorism Representative (UATR) to request Antiterrorism Awareness Training material.
4.6. Reporting Requirements. Contractor employees shall immediately report to an appropriate DMAFB authority any information or circumstances of which they are aware that may pose a threat to the security of Department of Defense personnel, contractor personnel, resources, and classified or unclassified defense information.
4.7. Incident Notification. Contractor personnel with access to a government computer shall update their AtHoc profile with current contact information to ensure receipt of incident notification. Contractor personnel without computer access should be alert for notifications from the base public address system (i.e. Giant Voice). Additional notifications can be received via the Davis Monthan AFB Facebook Page. In the event of an incident, contractor personnel should adhere to the guidance provided in the Antiterrorism Awareness Training.
4.8. Pass and Identification Items.
Real ID Requirement. Beginning May 7, 2025, Davis Monthan Air Force Base shall require all visitors seeking base access to possess a REAL ID in accordance with the REAL ID Act of 2005 and DoD Manual 5200.08 Vol 3, Physical Security Program: Access: to DoD Installations.
Federal installations, including Davis-Monthan AFB, shall no longer accept non-marked state-issued identification cards after May 6, 2025. As mandated by the Department of Homeland Security (DHS), state-issued licenses and identification cards must include a REAL ID-compliant marking– star markings, “Enhanced” verbiage, etc.—indicating adherence to federal standards. Enhanced Driver’s Licenses (EDLs) issued by Washington, Michigan, Minnesota, New York and Vermont are also acceptable for federal purposes. Although most EDLs do not contain the REAL ID star marking, they meet DHS criteria for access.
To obtain a REAL ID, individuals must visit their state’s driver licensing agency website for documentation requirements. At a minimum, applicants must provide proof of full legal name, date of birth, Social Security number, two proofs of address and lawful status. States may impose additional requirements. Minors under 18 years of age are not required to present REAL ID-compliant credentials for travel or base access, but their accompanying adult must be compliant.
Individuals issued a “LIMITED-TERM” REAL ID—commonly non-citizens with documentation such as a Permanent Resident Card, visa, or employment authorization—must present the same documentation when requesting access to DMAFB.
Common REAL ID-compliant credentials include U.S. passports, permanent resident cards and other identification approved under DODM5200.08v3. Current Defense Biometric Identification System (DBIDS) badges are not impacted by this change. However, new or replacement DBIDS badges shall only be issued upon presentation of REAL ID-compliant credentials. When screening visitors for DBIDS Contractor Badges and EAL sponsorship visitation requests, it is the direct responsibility of the DoD-affiliated sponsor to verify that the personnel they are requesting badging or visitation for are REAL ID compliant.
12 | P a g e
For DBIDS contractors, Visitor Control Center badging personnel shall confirm contractors’ REAL ID compliance when they come to receive their DBIDS badge. Security Forces personnel shall verify visitors’ driver’s licenses and identification cards to ensure REAL ID compliance is met.
Non-compliance shall result in immediate denial to the installation until REAL ID compliance is met.
Security Forces entry controllers shall verify REAL ID compliance of visitors when verifying their credentials with Entry Authorization Lists. Non-compliance shall result in immediate denial to the installation until REAL ID compliance is met.
For more information on REAL ID compliance and requirements, visit www.dhs.gov/real-id.
For questions regarding access to Davis-Monthan AFB, contact the 355th Security Forces Squadron Pass and Badge Office at 520-228-3224.
4.9. Retrieving Identification Media. The contractor shall retrieve all identification media, including vehicle passes from employees who depart for any reason before the contract expires.
e.g. terminated for cause, retirement, etc., or upon contract completion. The contractor shall immediately notify the Contracting Officer in writing when an employee departs and returns the employee’s identification to the office that issued it.
4.10. Traffic Laws. Contractor employees shall comply with all DMAFB traffic regulations and state traffic laws. Contractor employees are subject to random vehicle speed control checks. Failure to adhere to base traffic regulations may result in the loss of base driving privileges, debarment from the base, or other administrative action. The use of cell phones is strictly prohibited while driving on Davis-Monthan AFB, unless the phone is hands free. Seat belt use is mandatory for all drivers and vehicle passengers.
4.11. Random Personnel and Vehicle Searches. Contractor personnel are subject to random personnel and vehicle searches. If contractor personnel refuse to be searched, they shall be denied entry to the base. Denial of entry to contractor personnel who refuse to be searched, or detention of personnel found to be in possession of contraband, may result in loss of base driving privileges, debarment from the base, or other administrative action. Detention of contractor employees for any reason does not relieve the contractor of the requirement to perform contract services.
4.12. Weapons, Firearms, and Ammunition. Contractor employees are prohibited from possessing weapons, firearms, or ammunition on themselves or within their contractor owned vehicle or privately owned vehicle while on DMAFB.
4.13. Physical Security. Contractor employees shall safeguard all Government property and controlled forms provided for contractor use. At the end of each work period, the contractor shall secure all Government facilities, equipment, and materials. The contractor shall establish and implement methods of ensuring all Government lock keys and combinations are not lost, misplaced, or used by unauthorized persons. The contractor shall prohibit the use of lock keys and combinations, issued by the Government, by any person other than the contractor’s employees.
The contractor shall also prohibit the opening of locked areas by contractor employees to permit entrance of people other than contractor employees engaged in the performance of contract work requirements in those areas.
13 | P a g e
4.14. Contractor Personnel Travel on the Installation. All contractor personnel shall limit their travel on the installation only to specific areas required for the performance of services, specified break and meal areas, or travel directly to and from these locations.
4.15. Controlled/Restricted Areas. The contractor shall adhere to/implement local base procedures for entry to AF controlled/restricted areas where Contractor personnel work. An AF Form 2586, Unescorted Entry Authorization Certificate, must be completed and signed by the sponsoring agency’s Security Manager before a Restricted Area Badge shall be issued. Contractor employees must have a favorably completed National Agency Check plus written Inquires (NACI) investigation before receiving a Restricted Area Badge. Interim access can be granted in accordance with DoDM 5200.02_ DAFMAN 16-1405_DAFGM 2022-03, Air Force Personnel Security Program.
4.16. Key Control. The contractor shall establish and implement methods of making sure all keys/combinations issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized people. The contractor shall verify all JACE cabinet locks are in good working order and replace and maintain the locks on a minimum semi-annual basis. Where locks and keys and combinations are changed the contractor shall provide 355 CES with a minimum of four (4) sets of keys. The contractor shall not duplicate any keys issued by the Government. The contractor shall immediately report to the COR or Contracting Officer any occurrences of lost or duplicated keys. In the event keys, other than master keys, are lost or duplicated, the contractor may be required, upon written direction of the Contracting Officer, to re- key or replace the affected lock or locks without cost to the Government. The Government may, however, at its option, replace the affected lock or locks or perform re-keying and deduct the cost of such from the monthly payment due the contractor. In the event a master key is lost or duplicated, the Government shall replace all locks and keys for that system, and the total cost shall be deducted from the monthly payment due the contractor.
4.16.1. The contractor shall prohibit the use of keys and/or cipher lock combinations, issued by DMAFB, by any person other than the contractor’s employees and the opening of locked areas by contractor employees to permit entrance of persons other than contractor employees engaged in performance of contract work requirements in those areas.
4.16.2. The contractor shall control access to all Government provided lock combinations to preclude unauthorized entry. The contractor is not authorized to record lock combinations without written approval by the COR. Records with written combinations to authorized secure storage containers, secure storage rooms, or certified vaults, shall be marked and safeguarded at the highest classification level as the classified material maintained inside the approved containers.
4.17. Privacy Act. The Contractor shall ensure that its employees fully understand and comply with Title 5 of US Code, Section 552.a and DoD 5400.07, DoD Freedom of Information Act (FOIA) Program. These procedures must be followed to identify and safeguard reports and data accordingly. The contractor shall ensure that Contractor employees are briefed annually on properly identifying and handling Privacy Act data/information.
4.17.1. Controlled Unclassified Information (CUI). CUI is unclassified information requiring safeguarding and dissemination controls, consistent with applicable law, regulation, or government-wide policy. DoD Instruction 5200.48_Department of the Air Force Instruction
14 | P a g e
(DAFI)16-1403, Controlled Unclassified Information, sets policy, assigns responsibilities, and prescribes procedures for CUI in the identification, creation, sharing, marking, safeguarding, storage, dissemination, decontrol, disposition, destruction, and records management of CUI documents and materials and establishes training required. The contractor shall protect CUI, regardless of its form, at all times in a manner that minimizes the risk of unauthorized disclosure while allowing for access by authorized holders. Contractor personnel working with CUI must be careful not to expose CUI to unauthorized users or others who do not have a lawful government purpose to see it. When not under continuous monitoring or physical control, the contractor shall store hardcopy CUI documents in a locked desk, file cabinet, or similar means, where only authorized personnel have access. The following are examples of CUI:
• Personally Identifiable Information (PII)
• Sensitive Personally Identifiable Information (SPII)
• Proprietary Business Information (PBI)
• Unclassified Controlled Technical Information (UCTI)
• Operational Information
• Protected Health Information (PHI)
• Sensitive but Unclassified (SBU) Information
• Financial Information
4.17.2. Protection of Personally Identifiable Information. Personally Identifiable Information (PII) refers to information that can be used to distinguish or trace an individual’s identity either alone or when combined with other information that is linked or linkable to a specific individual.
PII may range from common data elements such as names, addresses, dates of birth, and places of employment, to identity documents, Social Security numbers (SSN) or other Government-issued identity, precise location information, medical history, and biometrics. The contractor shall protect all PII encountered in the performance of services in accordance with Department of Defense Directive 5400.11, Department of Defense Privacy Program, and DoD 5400.11-R, Department of Defense Privacy Program. If a PII breach results from the contractor's violation of the aforementioned policies, the contractor shall bear all notification costs, call-center support costs, and credit monitoring service costs for all individuals whose PII has been compromised.
4.17.3. Operations Security (OPSEC). The contractor shall maintain OPSEC in accordance with DOD Directive 5205.02, DOD Operations Security (OPSEC) Program, AFI 10-701, Operations Security (OPSEC), The contractor shall adhere to the following minimum OPSEC requirements.
• Contractor personnel shall not discuss government operations in public or over unprotected or unencrypted communications. Official business and controlled unclassified information may only be transmitted as directed in the PWS.
• The contractor shall not post to company websites, publications, newsletters, or other media any images, data or information that reveal sensitive Government operations, personnel, equipment, and/or classified or controlled unclassified information. When in doubt, company press releases related to this contract shall be coordinated through the Contracting Officer Representative (COR) or Contracting Officer, as applicable.
15 | P a g e
• Observation of events, operations, physical changes, etc. may reveal National Security information, therefore specific restrictions are required to preclude unintentional release of information to unauthorized parties. (Unauthorized disclosure and transfer of National Security Information is punishable under 18 USC § 793.)
• Contractor personnel shall not disclose to unauthorized third parties, post to unofficial sites (including Social Networking sites) images, data, or information, or observed events that reveal sensitive Government operations, personnel, equipment, including, but not limited to the following.
o Tactics, techniques and procedures, production or work schedules, any visible or concealed modifications, upgrades, increases, change, or decreases in work/deployment frequency or government personnel, vehicle, aircraft movements; specialized equipment orders, deliveries, shipments, etc., The contractor shall immediately report unauthorized disclosures and/or attempts to solicit this type of information by unauthorized third parties or others not affiliated with this contract to the COR or Contracting Officer.
o Government issued badges, identification shall be removed and/or concealed from plain sight when off base and shall not be left in vehicles or unprotected. Badges and passes may not be duplicated, copied or loaned to others. Lost or stolen identification badges, vehicle passes etc. shall be immediately reported to the COR, Contracting Officer, and/or installation Security Office.
o The contractor shall practice OPSEC and implement countermeasures to protect critical information (CI) and other sensitive unclassified information, if applicable. Protection of CI includes the adherence to and execution of countermeasures which the contractor initiates or as provided by the COR/CO, for CI on or related to this PWS.
o Where a contract requires long-term access to on-base facilities or other Government facilities, such as embedded contractors or participates in operations, they must complete applicable training and awareness familiarization, as required by the 612 AOC OPSEC Coordinator and 355th CES Training Manager. Initial training may be provided by computer-based training, live training or a combination of both. Completion of OPSEC training is required for contractor personnel initially within 30 days of assignment. The contractor is required to maintain individual training records for compliance purposes.
4.18. The contractor shall maintain cybersecurity in conformance with (DAFGM) 2024-32-01, Civil Engineer Control Systems Cybersecurity. As such, the contractor shall comply with DMAFB Design Guide, United Facilities Criteria (UFC) 04-10-06, Cybersecurity of Facility- Related Control Systems, Air Force Instruction (AFI) 17-101, Risk Management Framework (RMF) for Air Force Information Technology (IT), (or subsequent guidance from this memo) all cybersecurity guidance, Department of Defense Manual (DODM) 5200.02, Procedures for the DoD Personnel Security Program (PSP), AFGM 17-1303_AFGM 2019-01, Cybersecurity Workforce Improvement Program, DAFGM 2024-32-01, Civil Engineer Control Systems Cybersecurity, 355 Civil Engineer Squadron (355 CES) Energy Management Control Systems Configuration Management Plan and Contingency Plan.
• All contractor employees working with the 355th CES EMCS shall complete the 355th CES
16 | P a…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .