Solicitation Amendment FA857925Q00080001 SF 30.pdf
PDF 1 MB Posted
- Attached to
- BLDG 229N SCIF DOOR REPLACEMENT Federal contract opportunity
- Solicitation number
- FA857925Q0008
About this file
This document is a Standard Form 30 Amendment to Solicitation FA857925Q0008, extending the response deadline to 26 MAR 2025 and adding a Q&A document to the attachments. The solicitation is for a SCIF (Sensitive Compartmented Information Facility) door replacement project for the 402nd Software Engineering Group, specifically requiring a STC 50 rated door, frame casing, and installation.
The amendment modifies several key contract terms, including updating the response due date and adding clauses related to cybersecurity, contract closeout, and various federal acquisition regulations. Quotations should be emailed to Adam Hudson by Wednesday, 26 March 2025 at 2:00 pm EST. The solicitation is being conducted under Simplified Acquisition Procedures (SAP) as a Request for Quote (RFQ), and vendors are required to complete and sign the solicitation document and return it with their quote.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions - Answers for FA857925Q0008.xlsx | XLSX spreadsheet | |
| Service Contract Act WD 2015-4495 Revision 27 dated 23 DEC 2024.pdf | ||
| CDRL A002 Mishap Signed.pdf | ||
| PD (002).docx | DOCX document | |
| Solicitation - FA857925Q0008.pdf | ||
| CDRL A001 Safety Plan Signed.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
R
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers is extended. is not extended.
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:
(a) By completing items 8 and 15, and returning copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;
or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.
IT MODIFIES THE CONTRACT/ORDER NUMBER AS DESCRIBED IN ITEM 14.
CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER
NUMBER IN ITEM 10A.
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation data, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority)
E. IMPORTANT: Contractor is not is required to sign this document and return copies to the issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print) 16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)
15B. CONTRACTOR/OFFEROR
(Signature of person authorized to sign)
15C. DATE SIGNED 16B. UNITED STATES OF AMERICA
(Signature of Contracting Officer)
16C. DATE SIGNED
Previous edition unusable STANDARD FORM 30 (REV. 11/2016) Prescribed by GSA FAR (48 CFR) 53.243
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT 1. CONTRACT ID CODE PAGE OF PAGES
2. AMENDMENT/MODIFICATION NUMBER 3. EFFECTIVE DATE 4. REQUISITION/PURCHASE REQUISITION NUMBER 5. PROJECT NUMBER (If applicable)
6. ISSUED BY CODE 7. ADMINISTERED BY (If other than Item 6) CODE
8. NAME AND ADDRESS OF CONTRACTOR (Number, street, county, State and ZIP Code) (X) 9A. AMENDMENT OF SOLICITATION NUMBER
9B. DATED (SEE ITEM 11)
10A. MODIFICATION OF CONTRACT/ORDER NUMBE
10B. DATED (SEE ITEM 13)
CODE FACILITY CODE
Created On:
18 Mar 2025, 11:58 AM Central Daylight Time
SECTION SF 30 BLOCK 14 CONTINUATION PAGE
SUMMARY OF CHANGES
Solicitation/Contract Form
The following changes have been made:
INFORMATION FROM TO
Reference Description Header only - Purchase Requisition Number Reference Value F3QCBJ4197A001 Response Due Date 18 Mar 2025 26 Mar 2025
Supplies or Services & Prices or Costs
Miscellaneous text in this section has been modified to:
Solicitation FA857924Q0008 is issued as a request for quotation (RFQ).
This is a combined synopsis/solicitation for commercial supply prepared in accordance with the format in FAR subpart 12.6 as supplemented with additional information included in this notice. This announcement constitutes the only solicitation being issued; quotes are being requested and a written solicitation will not be issued. This solicitation is being conducted under Simplified Acquisition Procedures (SAP) as a Request for Quote (RFQ).
Quotations should be emailed to Adam Hudson (adam.hudson@us.af.mil) no later than Wednesday 26 March, 2025 at 2:00 pm EST. Vendors are required to complete and sign solicitation document and return it with their quote.
Contract Clauses
Miscellaneous text in this section has been modified to:
252.204-7022 Expediting Contract Closeout.
As prescribed in , use the following clause: 204.804-70
Expediting Contract Closeout (MAY 2021)
(a) At the conclusion of all applicable closeout requirements of Federal Acquisition Regulation 4.804, the Government and Contractor shall mutually agree on the residual dollar amount remaining on the contract. Both the Government and Contractor agree to waive payment of any residual dollar amount of $1,000 or less to which either party may be entitled at the time of contract closeout.
(b) A residual dollar amount includes all money owed to either party at the end of the contract and as a result of the contract, excluding amounts connected in any way with taxation or a violation of law or regulation.
(c) For purposes of determining residual dollar amounts, offsets (e.g., across multiple contracts or orders) may be considered only to the extent permitted by law.
(End of clause)
Statement of Equivalent Rates for Federal Hires (May 2014)
In compliance with the Service Contract Labor Standards statute and the regulations of the Secretary of Labor ( 29 CFR Part 4), this clause identifiesthe classes of service employees expected to be employed under the contract and states the wages and fringe benefits payable to each if they wereemployed by the contracting agency subject to the provisions of 5 U.S.C.5341 or 5 332.
This Statement is for Information Only: It is not a Wage Determination
FA857925Q00080001
https://www.acquisition.gov/dfars/part-204-administrative-and-information-matters#DFARS_204.804-70
Employee Class
__WG-4749-8__
52.209-10 Prohibition on Contracting with Inverted Domestic Corporations.
As prescribed in , insert the following clause: (b)9.108-5
Prohibition on with Contracting Inverted Domestic Corporations (Nov 2015)
(a) Definitions. As used in this clause-
Inverted domestic corporation means a foreign incorporated entity that meets the definition of an inverted domestic corporation under 6 U.S.C. 395(b), applied in accordance with the rules and definitions of 6 U.S.C. 395(c).
Subsidiary means an entity in which more than 50 percent of the entity is owned-
(1) Directly by a parent corporation; or
(2) Through another of a parent corporation. subsidiary
(b) If the contractor reorganizes as an or becomes a of an at any time during the period of inverted domestic corporation subsidiary inverted domestic corporation performance of this contract, the Government be prohibited from paying for Contractor activities performed after the date when it becomes an may inverted or . The Government seek any available remedies in the event the Contractor fails to perform in accordance with the terms and domestic corporation subsidiary may conditions of the contract as a result of Government action under this clause.
(c) Exceptions to this prohibition are located at . 9.108-2
(d) In the event the Contractor becomes either an , or a of an during contract performance, inverted domestic corporation subsidiary inverted domestic corporation the Contractor give written notice to the within five business days from the date of the inversion event. shall Contracting Officer
(End of clause)
.252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting As prescribed in 204.7304 (c), use the following clause:SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING (MAY
2024)(a) Definitions. As used in this clause--"Adequate security" means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information."Compromise" means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred."Contractor attributional/proprietary information" means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company."
Controlled technical information" means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions."Covered contractor information system" means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information."Covered defense information" means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry /category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is--(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract."Cyber incident" means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein."Forensic analysis" means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data."Information system" means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information."Malicious software" means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware."Media" means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.''Operationally critical support'' means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation."Rapidly report" means within 72 hours of discovery of any cyber incident."Technical information" means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013 , Rights in Technical Data--Other Than Commercial Products and Commercial Services, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010 , Cloud Computing Services, of this contract.(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, "Protecting Controlled Unclassified Information in
FA857925Q00080001
https://www.acquisition.gov/far/part-9#FAR_9_108_5 https://www.acquisition.gov/far/part-9#FAR_9_108_2
Nonfederal Information Systems and Organizations" (available via the internet at https://csrc.nist.gov/publications/sp800) in effect at the time the solicitation is issued or as authorized by the Contracting Officer.(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.(C) If the DoD CIO has previously adjudicated the contractor's requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/documents-templates/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.(c) Cyber incident reporting requirement.(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall--(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor's network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor's ability to provide operationally critical support; and(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.(3) Medium assurance certificate requirement.In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.(d) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.(e)
Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.(f) Access to additional information or equipment necessary for forensic analysis.
Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.(i) Use and release of contractor attributional/proprietary information not created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD--(1) To entities with missions that may be affected by such information;(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;(3) To Government entities that conduct counterintelligence or law enforcement investigations;(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or(5) To a support services contractor ("recipient") that is directly supporting Government activities under a contract that includes the clause at 252.204-7009 , Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government's use and release of such information.(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor's responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.(m) Subcontracts. The Contractor shall--(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and(2)
Require subcontractors to--(i) Notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause; and(ii) Provide the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber incident to DoD as required in paragraph (c) of this clause.
(End of clause)
252.204-7019 Notice of NISTSP 800-171 DoD Assessment Requirements.
As prescribed in 204.7304(d), use the following provision:
NOTICE OF NIST SP 800-171 DOD ASSESSMENT REQUIREMENTS (NOV 2023)
(a) Definitions.
"Basic Assessment", "Medium Assessment", and "High Assessment" have the meaning given in the clause 252.204-7020, NIST SP 800-171 DoD Assessments.
"Covered contractor information system" has the meaning given in the clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, of this solicitation.
(b) Requirement. In order to be considered for award, if the Offeror is required to implement NIST SP 800-171, the Offeror shall have a current assessment ( i.e., not more than 3 years old unless a lesser time is specified in the solicitation) (see 252.204-7020) for each covered contractor information system that is relevant to the offer, contract, task order, or delivery order. The Basic, Medium, and High NIST SP 800-171 DoD Assessments are described in the NIST SP 800-171 DoD Assessment Methodology located at https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-
6.24.2020.pdf .
(c) Procedures.
(1) The Offeror shall verify that summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) are posted in the Supplier Performance Risk System (SPRS) () for all covered contractor information systems relevant to the offer.
(2) If the Offeror does not have summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is
FA857925Q00080001
specified in the solicitation) posted in SPRS, the Offeror may conduct and submit a Basic Assessment to for posting to SPRS in the format identified in paragraph
(d) of this provision.
(d) Summary level scores. Summary level scores for all assessments will be posted 30 days post-assessment in SPRS to provide DoD Components visibility into the summary level scores of strategic assessments.
(1) Basic Assessments. An Offeror may follow the procedures in paragraph (c)(2) of this provision for posting Basic Assessments to SPRS.
(i) The email shall include the following information:
(A) Cybersecurity standard assessed (e.g., NIST SP 800-171 Rev 1).
(B) Organization conducting the assessment (e.g., Contractor self-assessment).
(C) For each system security plan (security requirement 3.12.4) supporting the performance of a DoD contract--
(1) All industry Commercial and Government Entity (CAGE) code(s) associated with the information system(s) addressed by the system security plan; and
(2) A brief description of the system security plan architecture, if more than one plan exists.
(D) Date the assessment was completed.
(E) Summary level score (e.g., 95 out of 110, NOT the individual value for each requirement).
(F) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan
(s) of action developed in accordance with NIST SP 800-171.
(ii) If multiple system security plans are addressed in the email described at paragraph (d)(1)(i) of this section, the Offeror shall use the following format for the report:
System Security Plan
CAGE Codes supported by this plan Brief description of the plan architecture
Date of assessment Total Score
Date score of 110 will achieved
(2) Medium and High Assessments. DoD will post the following Medium and/or High Assessment summary level scores to SPRS for each system assessed:
(i) The standard assessed (e.g., NIST SP 800-171 Rev 1).
(ii) Organization conducting the assessment, e.g., DCMA, or a specific organization (identified by Department of Defense Activity Address Code (DoDAAC)).
(iii) All industry CAGE code(s) associated with the information system(s) addressed by the system security plan.
(iv) A brief description of the system security plan architecture, if more than one system security plan exists.
(v) Date and level of the assessment, i.e., medium or high.
(vi) Summary level score (e.g., 105 out of 110, not the individual value assigned for each requirement).
(vii) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan
(s) of action developed in accordance with NIST SP 800-171.
(3) Accessibility.
(i) Assessment summary level scores posted in SPRS are available to DoD personnel, and are protected, in accordance with the standards set forth in DoD
Instruction 5000.79, Defense-wide Sharing and Use of Supplier and Product Performance Information (PI).
(ii) Authorized representatives of the Offeror for which the assessment was conducted may access SPRS to view their own summary level scores, in accordance with the SPRS Software User's Guide for Awardees/Contractors available at https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf.
(iii) A High NIST SP 800-171 DoD Assessment may result in documentation in addition to that listed in this section. DoD will retain and protect any such documentation as "Controlled Unclassified Information (CUI)" and intended for internal DoD use only. The information will be protected against unauthorized use and release, including through the exercise of applicable exemptions under the Freedom of Information Act (e.g., Exemption 4 covers trade secrets and commercial or financial information obtained from a contractor that is privileged or confidential).
(End of provision)
252.204-7020 NIST SP 800-171DoD Assessment Requirements.
As prescribed in 204.7304 (e), use the following clause:
NIST SP 800-171 DOD ASSESSMENT REQUIREMENTS (NOV 2023)
(a) Definitions.
Basic Assessment" means a contractor's self-assessment of the contractor's implementation of NIST SP 800-171 that--
(1) Is based on the Contractor's review of their system security plan(s) associated with covered contractor information system(s);
(2) Is conducted in accordance with the NIST SP 800-171 DoD Assessment Methodology; and
(3) Results in a confidence level of "Low" in the resulting score, because it is a self-generated score.
"Covered contractor information system" has the meaning given in the clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident
Reporting, of this contract.
"High Assessment" means an assessment that is conducted by Government personnel using NIST SP 800-171A, Assessing Security Requirements for Controlled
Unclassified Information that--
(1) Consists of--
(i) A review of a contractor's Basic Assessment;
(ii) A thorough document review;
(iii) Verification, examination, and demonstration of a Contractor's system security plan to validate that NIST SP 800-171 security requirements have been implemented as described in the contractor's system security plan; and
(iv) Discussions with the contractor to obtain additional information or clarification, as needed; and
(2) Results in a confidence level of "High" in the resulting score.
"Medium Assessment" means an assessment conducted by the Government that--
(1) Consists of--
(i) A review of a contractor's Basic Assessment;
(ii) A thorough document review; and
(iii) Discussions with the contractor to obtain additional information or clarification, as needed; and
(2) Results in a confidence level of "Medium" in the resulting score.
(b) Applicability. This clause applies to covered contractor information systems that are required to comply with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, in accordance with Defense Federal Acquisition Regulation System (DFARS) clause at 252.204-7012, Safeguarding
Covered Defense Information and Cyber Incident Reporting, of this contract.
(c) Requirements. The Contractor shall provide access to its facilities, systems, and personnel necessary for the Government to conduct a Medium or High NIST
SP 800-171 DoD Assessment, as described in NIST SP 800-171 DoD Assessment Methodology at https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding /NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf , if necessary.
(d) Procedures. Summary level scores for all assessments will be posted in the Supplier Performance Risk System (SPRS) () to provide DoD Components visibility into the summary level scores of strategic assessments.
(1) Basic Assessments. A contractor may submit, via encrypted email, summary level scores of Basic Assessments conducted in accordance with the NIST SP 800- 171 DoD Assessment Methodology to for posting to SPRS.
(i) The email shall include the following information:
(A) Version of NIST SP 800-171 against which the assessment was conducted.
(B) Organization conducting the assessment (e.g., Contractor self-assessment).
(C) For each system security plan (security requirement 3.12.4) supporting the performance of a DoD contract--
(1) All industry Commercial and Government Entity (CAGE) code(s) associated with the information system(s) addressed by the system security plan; and
(2) A brief description of the system security plan architecture, if more than one plan exists.
(D) Date the assessment was completed.
(E) Summary level score (e.g., 95 out of 110, NOT the individual value for each requirement).
(F) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan
(s) of action developed in accordance with NIST SP 800-171.
(ii) If multiple system security plans are addressed in the email described at paragraph (b)(1)(i) of this section, the Contractor shall use the following format for the report:
System Security Plan CAGE Codes supported by this plan
Brief description of the plan architecture Date of assessment
Total Score Date score of 110 will achieved
(2) Medium and High Assessments. DoD will post the following Medium and/or High Assessment summary level scores to SPRS for each system security plan assessed:
(i) The standard assessed (e.g., NIST SP 800-171 Rev 1).
(ii) Organization conducting the assessment, e.g., DCMA, or a specific organization (identified by Department of Defense Activity Address Code (DoDAAC)).
(iii) All industry CAGE code(s) associated with the information system(s) addressed by the system security plan.
(iv) A brief description of the system security plan architecture, if more than one system security plan exists.
(v) Date and level of the assessment, i.e., medium or high.
(vi) Summary level score (e.g., 105 out of 110, not the individual value assigned for each requirement).
(vii) Date that all requirements are expected to be implemented (i.e., a score of 110 is expected to be achieved) based on information gathered from associated plan
(s) of action developed in accordance with NIST SP 800-171.
(e) Rebuttals.
(1) DoD will provide Medium and High Assessment summary level scores to the Contractor and offer the opportunity for rebuttal and adjudication of assessment summary level scores prior to posting the summary level scores to SPRS (see SPRS User's Guide https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf).
(2) Upon completion of each assessment, the contractor has 14 business days to provide additional information to demonstrate that they meet any security requirements not observed by the assessment team or to rebut the findings that may be of question.
(f) Accessibility.
(1) Assessment summary level scores posted in SPRS are available to DoD personnel, and are protected, in accordance with the standards set forth in DoD Instruction 5000.79, Defense-wide Sharing and Use of Supplier and Product Performance Information (PI).
(2) Authorized representatives of the Contractor for which the assessment was conducted may access SPRS to view their own summary level scores, in accordance with the SPRS Software User's Guide for Awardees/Contractors available at .
(3) A High NIST SP 800-171 DoD Assessment may result in documentation in addition to that listed in this clause. DoD will retain and protect any such documentation as "Controlled Unclassified Information (CUI)" and intended for internal DoD use only. The information will be protected against unauthorized use and release, including through the exercise of applicable exemptions under the Freedom of Information Act (e.g., Exemption 4 covers trade secrets and commercial or financial information obtained from a contractor that is privileged or confidential).
(g) Subcontracts.
(1) The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf).
(2) The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171
DoD Assessment, as described in https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1- 6.24.2020.pdf , for all covered contractor information systems relevant to its offer that are not part of an information technology service or system operated on behalf of the Government.
(3) If a subcontractor does not have summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) posted in SPRS, the subcontractor may conduct and submit a Basic Assessment, in accordance with the NIST SP 800-171 DoD Assessment Methodology, to mailto:webptsmh@navy.mil for posting to SPRS along with the information required by paragraph (d) of this clause.
(End of clause)
Additional Information/Notes
The following clauses were modified:
52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial Products and Commercial Services. May 2024 hereby reads as follows:
As prescribed in , insert the following clause: 12.301(b)(4)
Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial Products and Commercial Services (Mar 2025)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (section 743 of Division E, Title VII, of the (Jan 2017) Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities (Section (Dec 2023) 1634 of Pub. L. 115-91).
(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (Section 889(a)(1)(A) of Pub. (Nov 2021) L. 115-232).
(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations .(Nov 2015)
(5) 52.232-40, Providing Accelerated Payments to Small Business Subcontractors (31 U.S.C. 3903 and 10 U.S.C. 3801).(Mar 2023)
(6) 52.233-3, Protest After Award (31 U.S.C. 3553).(Aug 1996)
(7) 52.233-4, Applicable Law for Breach of Contract Claim (Public Laws 108-77 and 108-78 ( 19 U.S.C. 3805 note)).(Oct 2004)
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
[ .]Contracting Officer check as appropriate
52.203-6, Restrictions on Subcontractor Sales to the Government with (41 U.S.C. 4704 and 10 U.S.C. 4655).(1) (Jun 2020), Alternate I (Nov 2021)
52.203-13, Contractor Code of Business Ethics and Conduct (41 U.S.C. 3509)).(2) (Nov 2021)
52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (Section 1553 of Pub. L. 111-5). (Applies to (3) (Jun 2010) contracts funded by the American Recovery and Reinvestment Act of 2009.)
52.203-17, Contractor Employee Whistleblower Rights (41 U.S.C. 4712); this clause does not apply to contracts of DoD, NASA, the Coast Guard, or (4) (Nov 2023) applicable elements of the intelligence community-see FAR 3.900(a).
52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (Pub. L. 109-282) ( 31 U.S.C. 6101 note).(5) (Jun 2020)
[Reserved].(6)
52.204-14, Service Contract Reporting Requirements (Pub. L. 111-117, section 743 of Div. C).(7) (Oct 2016)
52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Pub. L. 111-117, section 743 of Div. C).(8) (Oct 2016)
(9) 52.204-27, Prohibition on a ByteDance Covered Application (Jun 2023) (Section 102 of Division R of Pub. L. 117-328).X
52.204-28, Federal Acquisition Supply Chain Security Act Orders-Federal Supply Schedules, Governmentwide Acquisition Contracts, and Multi-Agency (10) Contracts. (Pub. L. 115-390, title II).(Dec 2023)
(11)
(i) 52.204-30, Federal Acquisition Supply Chain Security Act Orders-Prohibition. (Pub. L. 115-390, title II).(Dec 2023)
Alternate I of 52.204-30.(ii) (Dec 2023)
52.209-6, Protecting the Government's Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (31 U.S.(12) (Nov 2021) C. 6101 note).
52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (41 U.S.C. 2313).(13) (Oct 2018)
[Reserved].(14)
52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award ( ) (15 U.S.C. 657a).(15) Oct 2022
52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns ( ) (if the offeror elects to waive the preference, it shall so (16) Oct 2022 indicate in its offer) (15 U.S.C. 657a).
[Reserved](17)
(18)X
(i) 52.219-6, Notice of Total Small Business Set-Aside (15 U.S.C. 644).(Nov 2020)
Alternate I of 52.219-6.(ii) (Mar 2020)
(19)
(i) 52.219-7, Notice of Partial Small Business Set-Aside (15 U.S.C. 644).(Nov 2020)
Alternate I of 52.219-7.(ii) (Mar 2020)
52.219-8, Utilization of Small Business Concerns ( ) (15 U.S.C. 637(d)(2) and (3)).(20) Feb 2024
(21)
(i) 52.219-9, Small Business Subcontracting Plan ( ) (15 U.S.C. 637(d)(4)).Sep 2023
Alternate I of 52.219-9.(ii) (Nov 2016)
Alternate II of 52.219-9.(iii) (Nov 2016)
Alternate III of 52.219-9.(iv) (Jun 2020)
Alternate IV ( ) of 52.219-9.(v) Sep 2023
(22)
(i) 52.219-13, Notice of Set-Aside of Orders (15 U.S.C. 644(r)).(Mar 2020)
Alternate I of 52.219-13.(ii) (Mar 2020)
52.219-14, Limitations on Subcontracting ( ) (15 U.S.C. 637s).(23) Oct 2022
52.219-16, Liquidated Damages-Subcontracting Plan (15 U.S.C. 637(d)(4)(F)(i)).(24) (Sep 2021)
52.219-27, Notice of Set-Aside for, or Sole-Source Award to, Service-Disabled Veteran-Owned Small Business (SDVOSB) Concerns Eligible Under the (25) SDVOSB Program ( ) (15 U.S.C. 657f).Feb 2024
(26)
(i) 52.219-28, Post Award Small Business Program Rerepresentation ( ) (15 U.S.C. 632(a)(2)).Feb 2024
Alternate I of 52.219-28.(ii) (Mar 2020)
52.219-29, Notice of Set-Aside for, or Sole-Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns ( ) (15 U.S.(27) Oct 2022 C. 637(m)).
52.219-30, Notice of Set-Aside for, or Sole-Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business (28) Program ( ) (15 U.S.C. 637(m)).Oct 2022
52.219-32, Orders Issued Directly Under Small Business Reserves (15 U.S.C. 644(r)).(29) (Mar 2020)
52.219-33, Nonmanufacturer Rule (15U.S.C. 637(a)(17)).(30) (Sep 2021)
(31) 52.222-3, Convict Labor (Jun 2003) (E.O.11755).X
(32) 52.222-19, Child Labor-Cooperation with Authorities and Remedies (Feb 2024).X
[Reserved](33)
(34) [Reserved]
(35)
(i) 52.222-35, Equal Opportunity for Veterans (38 U.S.C. 4212).(Jun 2020)
Alternate I of 52.222-35.(ii) (Jul 2014)
(36)X
(i) 52.222-36, Equal Opportunity for Workers with Disabilities (29 U.S.C. 793).(Jun 2020)
Alternate I of 52.222-36.(ii) (Jul 2014)
52.222-37, Employment Reports on Veterans ( ) (38 U.S.C. 4212).(37) Jun 2020
52.222-40, Notification of Employee Rights Under the National Labor Relations Act (E.O. 13496).(38) (Dec 2010)
(39)X
(i) 52.222-50, Combating Trafficking in Persons (22 U.S.C. chapter 78 and E.O. 13627).(Nov 2021)
Alternate I of 52.222-50 (22 U.S.C. chapter 78 and E.O. 13627).(ii) (Mar 2015)
52.222-54, Employment Eligibility Verification (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf (40) (May 2022) items or certain other types of commercial products or commercial services as prescribed in FAR 22.1803.)
(41)
(i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA-Designated Items (May 2008) ( 42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
Alternate I of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)(ii) (May 2008)
(42) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (42 U.S.C. 7671, ).X (May 2024) et seq.
(43) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (42 U.S.C. 7671, ).(May 2024) et seq.
(44) 52.223-20, Aerosols (42 U.S.C. 7671, ).(May 2024) et seq.
(45) 52.223-21, Foams (42 U.S.C. 7671, ).(May 2024) et seq.
52.223-23, Sustainable Products and Services (MAR 2025) (DEVIATION 2025-O0004)) (7 U.S.C. 8102, 42 U.S.C. 6962, 42 U.S.C. 8259b, and 42 U.S.C. (46) 7671l).(May 2024)
(47)
(i) 52.224-3 Privacy Training (5 U.S.C. 552 a).(Jan 2017)
Alternate I of 52.224-3.(ii) (Jan 2017)
(48)X
(i) 52.225-1, Buy American-Supplies (41 U.S.C. chapter 83).(Oct 2022)
Alternate I of 52.225-1.(ii) (Oct 2022)
(49)
(i) 52.225-3, Buy American-Free Trade Agreements-Israeli Trade Act (19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. (NOV 2023) 4001 note, 19 U.S.C. chapter 29 (sections 4501-4732), Public Law 103-182, 108-77, 108-78, 108-286, 108-302, 109-53, 109-169, 109-283, 110-138, 112-41, 112- 42, and 112-43.
Alternate I [Reserved].(ii)
Alternate II of 52.225-3.(iii) ( 2022)Dec
Alternate III of 52.225-3.(iv) (Feb 2024)
Alternate IV (Oct 2022) of 52.225-3.(v)
52.225-5, Trade Agreements (19 U.S.C. 2501, ., 19 U.S.C. 3301 note).(50) (NOV 2023) et seq
(51) 52.225-13, Restrictions on Certain Foreign Purchases (Feb 2021) (E.O.'s, proclamations, and statutes administered by the Office of Foreign Assets Control X of the Department of the Treasury).
52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense (52) Authorization Act for Fiscal Year 2008; 10 U.S.C. Subtitle A, Part V, Subpart G Note).
52.226-4, Notice of Disaster or Emergency Area Set-Aside (Nov 2007) (42 U.S.C. 5150).(53)
52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (42 U.S.C. 5150).(54) (Nov 2007)
(55) 52.226-8, Encouraging Contractor Policies to Ban Text Messaging While Driving (E.O. 13513).(May 2024)
52.229-12, Tax on Certain Foreign Procurements .(56) (Feb 2021)
52.232-29, Terms for Financing of Purchases of Commercial Products and Commercial Services (41 U.S.C. 4505, 10 U.S.C. 3805).(57) (Nov 2021)
52.232-30, Installment Payments for Commercial Products and Commercial Services (41 U.S.C. 4505, 10 U.S.C. 3805).(58) (Nov 2021)
(59) 52.232-33, Payment by Electronic Funds Transfer-System for Award Management (Oct2018) (31 U.S.C. 3332).X
52.232-34, Payment by Electronic Funds Transfer-Other than System for Award Management (Jul 2013) (31 U.S.C. 3332).(60)
52.232-36, Payment by Third Party (31 U.S.C. 3332).(61) (May 2014)
52.239-1, Privacy or Security Safeguards (5 U.S.C. 552a).(62) (Aug 1996)
52.242-5, Payments to Small Business Subcontractors (15 U.S.C. 637(d)(13)).(63) (Jan 2017)
(64)
(i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (46 U.S.C. 55305 and 10 U.S.C. 2631).(Nov 2021)
Alternate I of 52.247-64.(ii) (Apr 2003)
Alternate II of 52.247-64.(iii) (Nov 2021)
(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
[ ]Contracting Officer check as appropriate.
(1) 52.222-41, Service Contract Labor Standards (Aug 2018) (41 U.S.C. chapter67).X
(2) 52.222-42, Statement of Equivalent Rates for Federal Hires (May 2014) (29 U.S.C. 206 and 41 U.S.C. chapter 67).X
52.222-43, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (Multiple Year and Option Contracts) (29 U.S.C. 206 (3) (Aug 2018) and 41 U.S.C. chapter 67).
52.222-44, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (May 2014) ( 29U.S.C.206 and 41 U.S.C. chapter 67).(4)
52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment-(5) Requirements (May 2014) (41 U.S.C. chapter 67).
52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements (41 U.S.(6) (May 2014) C. chapter 67).
(7) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026 (Jan 2022).X
52.222-62, Paid Sick Leave Under Executive Order 13706 (E.O. 13706).(8) (Jan 2022)
52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (Jun 2020) (42 U.S.C. 1792).(9)
(d) . The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than Comptroller General Examination of Record sealed bid, is in excess of the simplified acquisition threshold, as defined in FAR 2.101, on the date of award of this contract, and does not contain the clause at 52.215-2, Audit and Records-Negotiation.
(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor's directly pertinent records…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .