FA8650-17-S-2002-Atch4.pdf
PDF 505 KB Posted
- Attached to
- Enabling Technologies for High-speed Operable Systems (ETHOS) Federal contract opportunity
- Solicitation number
- FA8650-17-S-2002
About this file
This is a solicitation for research and development services to identify, develop, mature, and demonstrate technologies that enable refurbishable high-speed capabilities for intelligence, surveillance, reconnaissance, and strike platforms. The Air Force Research Laboratory seeks proposals to conduct work in the areas of enabling technologies for high-speed operable systems through 2028 and for quick-turn fully reusable systems by 2035. Proposals are due by an unspecified date. The solicitation involves the Department of the Air Force Materiel Command Research Laboratory and focuses on products and services in the areas of refurbishable high-speed capabilities for ISR and strike platforms.
Model Contract with Section K
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FA8650-17-S-2002 updated 24Nov2021.pdf | ||
| FA8650-17-S-2002-Call2-NOCA.docx | DOCX document | |
| FA8650-17-S-2002-Amd1.pdf | ||
| FA8650-17-S-2002-Atch6.pdf | ||
| FA8650-17-S-2002-Call1-Amd1.pdf | ||
| FA8650-17-S-2002-Call1-Q&As.pdf | ||
| FA8650-17-S-2002-Call1-Atch4.pdf | ||
| FA8650-17-S-2002-Call1.pdf | ||
| FA8650-17-S-2002-Call1-Atch2.pdf | ||
| FA8650-17-S-2002-Call1-Atch3.pdf | ||
| FA8650-17-S-2002-Call1-Atch1.pdf | ||
| FA8650-17-S-2002-Atch3.pdf | ||
| FA8650-17-S-2002-Atch2.pdf | ||
| FA8650-17-S-2002-Atch1.pdf | ||
| FA8650-17-S-2002-Atch5.pdf | ||
| FA8650-17-S-2002.pdf | ||
| FA8650-17-S-2002.pdf |
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BAA
FA8650-17-S-2002
Attachment 4 - Model Contract
SOLICITATION, OFFER AND AWARD
1. THIS CONTRACT IS A RATED ORDER
UNDER DPAS (15 CFR 350)
RATING
DO-A1
PAGE OF PAGES
1 40
2. CONTRACT NO. 3. SOLICITATION NO. 4. TYPE OF SOLICITATION
SEALED BID (IFB)
NEGOTIATED (RFP)
5. DATE ISSUED
6. REQUISITION/PURCHASE NO.
FA8650-17-R-2002
7. ISSUED BY AFRL/RQKPA CODE FA8650 8. ADDRESS OFFER TO (If other than Item 7)
USAF/AFMC
AFRL WRIGHT RESEARCH SITE
2130 EIGHTH STREET, BUILDING 45
WRIGHT-PATTERSON AFB OH 45433-7541
PATRICK WALSH 937-713-9949
PATRICK.WALSH.19@US.AF.MIL
NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder”.
SOLICITATION
9.
10. FOR
INFORMATION
CALL:
A. NAME
See Block 7
B. TELEPHONE (Include area code)
(NO COLLECT CALLS)
C. E-MAIL ADDRESS
11. TABLE OF CONTENTS
() SEC. DESCRIPTION PAGE(S) () SEC DESCRIPTION PAGE(S)
PART I - THE SCHEDULE PART II - CONTRACT CLAUSES
A SOLICITATION/CONTRACT FORM 1 I CONTRACT CLAUSES 17
B SUPPLIES OR SERVICES AND PRICES/COSTS 2 PART III - LIST OF DOCUMENTS, EXHIBITS, AND OTHER ATTACH.
C DESCRIPTION/SPECS./WORK STATEMENT 8 J LIST OF ATTACHMENTS 40
D PACKAGING AND MARKING 9 PART IV - REPRESENTATIONS AND INSTRUCTIONS
E INSPECTION AND ACCEPTANCE 10 K REPRESENTATIONS, CERTIFICATIONS, K - 1
F DELIVERIES OR PERFORMANCE 11 AND OTHER STATEMENTS OF OFFERORS
G CONTRACT ADMINISTRATION DATA 14 L INSTRS, CONDS, AND NOTICES TO OFFERORS L - 1
H SPECIAL CONTRACT REQUIREMENTS 16 M EVALUATION FACTORS FOR AWARD M - 1
OFFER (Must be fully completed by offeror) NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within ____ ____ calendar days (60 calendar days unless a different period is inserted by the offeror) from the date of receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52.232-8)
10 CALENDAR DAYS
20 CALENDAR DAYS
30 CALENDAR DAYS
CALENDAR DAYS
14. ACKNOWLEDGEMENTS OF AMENDMENTS
(The offeror acknowledges receipt of amend-
AMENDMENT NO. DATE AMENDMENT NO. DATE
ments to the SOLICITATION for offerors and related documents numbered and dated:
15A. NAME
AND
CODE FACILITY 16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN
OFFER (Type or print)
ADDRESS
OF
OFFEROR
15B. TELEPHONE NO. (Include area code)
15C. CHECK IF REMITTANCE ADDRESS
IS DIFFERENT FROM ABOVE - ENTER
SUCH ADDRESS IN SCHEDULE.
17. SIGNATURE 18. OFFER DATE
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETI-
TION: 23. SUBMIT INVOICES TO ADDRESS SHOWN IN
(4 copies unless otherwise specified)
ITEM
10 U.S.C. 2304(c) ( ) 41 U.S.C. 253(c) ( )
24. ADMINISTERED BY (If other than Item 7) CODE 25. PAYMENT WILL BE MADE BY CODE
26. NAME OF CONTRACTING OFFICER (Type or print) 27. UNITED STATES OF AMERICA
(Signature of Contracting Officer)
28. AWARD DATE
IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 33 (REV. 9-97)
PREVIOUS EDITION IS UNUSABLE Prescribed by GSA ConWrite Version 6.15.2 FAR (48 CFR) 53.21(c) Created 13 Dec 2016 12:43 PM
PART I - THE SCHEDULE
SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS
SECTION B FA8650-17-R-2002
Qty Unit Price ITEM SUPPLIES OR SERVICES Purch Unit Total Item Amount
R&D - CPFF
0001 1 __________ Lot __________ Noun: RESEARCH & DATA
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: U - COST PLUS FIXED FEE Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall conduct research entitled "TBD" in accordance with Section J, Attachment 1, Statement of Work dated TBD.
The estimated cost and fixed amounts are shown below:
Cost: To Be Determined on each contract.
Fee: To Be Determined on each contract.
Pursuant to FAR 52.232-22, "Limitation of Funds" in Section I, the total amount available for payment and allotted to this contract for CLIN(s) To Be Determined on each contract is dollar amount To Be Determined on each contract. It is estimated that this amount is sufficient to cover performance through date To Be Determined on each contract.
HARDWARE
0002 1 __________ Lot __________ Noun: HARDWARE
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: U - COST PLUS FIXED FEE Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall deliver hardware in accordance with requirements of individual contracts. The contractor shall deliver any and all hardware developed and/or acquired via the course of this effort.
IAW Clause 252.211-7003, "Item Unique Identification and Valuation ", the contractor shall identify the unit acquisition cost for all deliverable end items for which item unique identification applies.
Qty Unit Price ITEM SUPPLIES OR SERVICES Purch Unit Total Item Amount
SOFTWARE
0003 1 __________ Lot __________ Noun: SOFTWARE
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: U - COST PLUS FIXED FEE Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall deliver software in accordance with requirements of individual contracts. The contractor shall deliver any and all software developed and/or acquired via the course of this effort.
Software shall be delivered with all source code and executable files unless expressly excluded in writing.
R&D - COST
0004 1 __________ Lot __________ Noun: RESEARCH & DATA
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: S - COST Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall conduct research entitled "TBD" in accordance with Section J, Attachment 1, Statement of Work dated TBD.
Pursuant to FAR 52.232-22, "Limitation of Funds" in Section I, the total amount available for payment and allotted to this contract for CLIN(s) To Be Determined on each contract is dollar amount To Be Determined on each contract. It is estimated that this amount is sufficient to cover performance through date To Be Determined on each contract.
Qty Unit Price ITEM SUPPLIES OR SERVICES Purch Unit Total Item Amount
HARDWARE
0005 1 __________ Lot __________ Noun: HARDWARE
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: S - COST Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall deliver hardware in accordance with requirements of individual contracts. The contractor shall deliver any and all hardware developed and/or acquired via the course of this effort.
IAW Clause 252.211-7003, "Item Unique Identification and Valuation ", the
SOFTWARE
0006 1 __________ Lot __________ Noun: SOFTWARE
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: S - COST Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall deliver software in accordance with requirements of individual contracts. The contractor shall deliver any and all software developed and/or acquired via the course of this effort.
Qty Unit Price ITEM SUPPLIES OR SERVICES Purch Unit Total Item Amount
R&D - FFP
0007 1 __________ Lot __________ Noun: RESEARCH & DATA
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: J - FIRM FIXED PRICE Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall conduct research entitled "TBD" in accordance with Section J, Attachment 1, Statement of Work dated TBD.
HARDWARE
0008 1 __________ Lot __________ Noun: HARDWARE
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: J - FIRM FIXED PRICE Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall deliver hardware in accordance with requirements of individual contracts. The contractor shall deliver any and all hardware developed and/or acquired via the course of this effort.
IAW Clause 252.211-7003, "Item Unique Identification and Valuation ", the
Qty Unit Price ITEM SUPPLIES OR SERVICES Purch Unit Total Item Amount
SOFTWARE
0009 1 __________ Lot __________ Noun: SOFTWARE
PSC: AC13
NSN: N - Not Applicable DD1423 is Exhibit: A Contract type: J - FIRM FIXED PRICE Inspection: DESTINATION Acceptance: DESTINATION
FOB: DESTINATION
Descriptive Data:
The Contractor shall deliver software in accordance with requirements of individual contracts. The contractor shall deliver any and all software developed and/or acquired via the course of this effort.
NO CLAUSES OR PROVISIONS IN THIS SECTION
SECTION C - DESCRIPTION/SPECS./WORK STATEMENT
SECTION C FA8650-17-R-2002
SECTION D - PACKAGING AND MARKING
SECTION D FA8650-17-R-2002
SECTION E - INSPECTION AND ACCEPTANCE
SECTION E FA8650-17-R-2002
NOTICE: The following contract clauses pertinent to this section are hereby incorporated by reference:
A. FEDERAL ACQUISITION REGULATION CONTRACT CLAUSES
52.246-07 INSPECTION OF RESEARCH AND DEVELOPMENT -- FIXED-PRICE (AUG 1996)
52.246-08 INSPECTION OF RESEARCH AND DEVELOPMENT -- COST-REIMBURSEMENT
(MAY 2001)
52.246-08 INSPECTION OF RESEARCH AND DEVELOPMENT -- COST-REIMBURSEMENT
(MAY 2001) - ALTERNATE I (APR 1984)
52.246-09 INSPECTION OF RESEARCH AND DEVELOPMENT (SHORT FORM) (APR 1984)
B. DEFENSE FEDERAL ACQUISITION REGULATION SUPPLEMENT CONTRACT CLAUSES
252.246-7000 MATERIAL INSPECTION AND RECEIVING REPORT (MAR 2008)
SECTION F - DELIVERIES OR PERFORMANCE
SECTION F FA8650-17-R-2002
SHIP MARK TRANS
ITEM SUPPLIES SCHEDULE DATA QTY TO FOR PRI DATE
0001 1 FA8650 ASREQ
Noun: RESEARCH & DATA Descriptive Data:
The technical Period of Performance (PoP) ends: TBD
The draft Scientific and Technical Report is due no later than: TBD (30 days after technical PoP ends)
The Government will provide comments on the draft Scientific and Technical Report no later than: TBD (60 days after technical PoP ends)
The Contractor shall deliver the final Scientific and Technical Report no later than: TBD (90 days after technical PoP ends)
All data shall be delivered in accordance with Exhibit A, Contract Data Requirements List, DD Form 1423-1, of the Basic Contract. See DD Form 1423 for mailing addressees by
CDRL.
0002 1 FA8650 ASREQ
Noun: HARDWARE Descriptive Data:
The scheduled delivery date for hardware is TBD. The shipping address is TBD.
0003 1 FA8650 ASREQ
Noun: SOFTWARE
The scheduled delivery date for software is TBD. The shipping address is TBD.
SHIP MARK TRANS
ITEM SUPPLIES SCHEDULE DATA QTY TO FOR PRI DATE
0004 1 FA8650 ASREQ
Noun: RESEARCH & DATA Descriptive Data:
The technical Period of Performance (PoP) ends: TBD
The draft Scientific and Technical Report is due no later than: TBD (30 days after technical PoP ends)
The Government will provide comments on the draft Scientific and Technical Report no later than: TBD (60 days after technical PoP ends)
The Contractor shall deliver the final Scientific and Technical Report no later than: TBD (90 days after technical PoP ends)
All data shall be delivered in accordance with Exhibit A, Contract Data Requirements List, 0005 1 FA8650 ASREQ
0006 1 FA8650 ASREQ
SHIP MARK TRANS
ITEM SUPPLIES SCHEDULE DATA QTY TO FOR PRI DATE
0007 1 FA8650 ASREQ
Noun: RESEARCH & DATA Descriptive Data:
The technical Period of Performance (PoP) ends: TBD
The draft Scientific and Technical Report is due no later than: TBD (30 days after technical PoP ends)
The Government will provide comments on the draft Scientific and Technical Report no later than: TBD (60 days after technical PoP ends)
The Contractor shall deliver the final Scientific and Technical Report no later than: TBD (90 days after technical PoP ends)
All data shall be delivered in accordance with Exhibit A, Contract Data Requirements List, 0008 1 FA8650 ASREQ
0009 1 FA8650 ASREQ
NOTICE: The following contract clauses pertinent to this section are hereby incorporated by reference:
FEDERAL ACQUISITION REGULATION CONTRACT CLAUSES
52.242-15 STOP-WORK ORDER (AUG 1989)
52.242-15 STOP-WORK ORDER (AUG 1989) - ALTERNATE I (APR 1984)
52.247-34 F.O.B. DESTINATION (NOV 1991)
SECTION G - CONTRACT ADMINISTRATION DATA
SECTION G FA8650-17-R-2002
NOTICE: The following contract clauses pertinent to this section are hereby incorporated in full text:
A. DEFENSE FAR SUPP CONTRACT CLAUSES IN FULL TEXT
252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (MAY 2013)
(a) Definitions. As used in this clause-
“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.
“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).
“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.
(b) Electronic invoicing. The WAWF system is the method to electronically process vendor payment requests and receiving reports, as authorized by DFARS 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall—
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.acquisition.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web- Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/
(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor must use the following information when submitting payment requests and receiving reports in WAWF for this contract/order:
(1) Document type. The Contractor shall use the following document type(s).
Use Cost Voucher with an invoice (or public voucher), supported by a statement of cost for performance shall be submitted to the cognizant Defense Contract Audit Agency (DCAA) office. Under the provisions of DFARS 242.803(b), the DCAA auditor, is designated as the authorized representative of the contracting officer (CO) for examining vouchers received directly from the contractor.
Use Receiving Report to fulfill DFARS 252.246-7000, Material Inspection and Receiving Report, and CDRL A001 (final Technical Report), Block 7 requirement for a DD250..
Note: If a “Combo” document type is identified but not supportable by the Contractor’s business systems, an “Invoice” (stand-alone) and “Receiving Report” (stand-alone) document type may be used instead.)
SECTION G - CONTRACT ADMINISTRATION DATA
SECTION G FA8650-17-R-2002
(2) Inspection/acceptance location. The Contractor shall select the following inspection/acceptance location(s) in WAWF, as specified by the contracting officer.
Destination/Destination
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table* Field Name in WAWF Data to be entered in WAWF
Pay Official DoDAAC [Block 12 on the cover page of the contract will contain this information] Issue By DoDAAC FA8650 Admin DoDAAC [Block 6 on the cover page of the contract will contain this information] Inspect By DoDAAC Vendor will leave this block blank Ship To Code TBD Ship From Code N/A Mark For Code N/A Service Approver (DoDAAC) [Block 6 on the cover page of the contract will contain this information]
Service Acceptor (DoDAAC) TBD Accept at Other DoDAAC N/A LPO DoDAAC N/A DCAA Auditor DoDAAC Contractor shall use Look Up DCAA from toolbar at left of WAWF screen.
Other DoDAAC(s) N/A
(*Contracting Officer: Insert applicable DoDAAC information or “See schedule” if multiple ship to/acceptance locations apply, or “Not applicable.”)
(4) Payment request and supporting documentation. The Contractor shall ensure a payment request includes appropriate contract line item and subline item descriptions of the work performed or supplies delivered, unit price/cost per unit, fee (if applicable), and all relevant back-up documentation, as defined in DFARS Appendix F, (e.g. timesheets) in support of each payment request.
(5) WAWF email notifications. The Contractor shall enter the e-mail address identified below in the “Send Additional Email Notifications” field of WAWF once a document is submitted in the system.
The Contractor shall enter the e-mail address identified below in the “Send Additional Email Notifications” field of WAWF once a document is submitted in the system.
E-mail address for the AFRL Project Engineer identified on the contract
(g) WAWF point of contact.
(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contact.
DCMA - ACO [Block 6 of the cover page of the contract will contain this information]
(2) For technical WAWF help, contact the WAWF helpdesk at 866-618-5988.
B. OTHER CONTRACT CLAUSES IN FULL TEXT
252.204-0007 CONTRACT-WIDE: SEQUENTIAL ACRN ORDER (SEP 2009)
The payment office shall make payment in sequential ACRN order within the contract or order, exhausting all funds in the previous ACRN before paying from the next ACRN using the following sequential order: alpha/alpha; alpha/numeric; numeric/alpha; and numeric/numeric.
SECTION H - SPECIAL CONTRACT REQUIREMENTS
SECTION H FA8650-17-R-2002
PART II - CONTRACT CLAUSES
SECTION I - CONTRACT CLAUSES
SECTION I FA8650-17-R-2002
252.204-7008 COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION
CONTROLS (OCT 2016)
(a) Definitions. As used in this provision- "Controlled technical information," "covered contractor information system," "covered defense information," "cyber incident," "information system," and "technical information" are defined in clause 252.204-7012 <252204.htm>, Safeguarding Covered Defense Information and Cyber Incident Reporting.
(b) The security requirements required by contract clause 252.204-7012 <252204.htm>, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.
(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see 252.204-7012 <252204.htm>(b)(2)-
(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations" (see <http://dx.doi.org/10.6028/NIST.SP.800-171>) that are in effect at the time the solicitation is issued or as authorized by the contracting officer not later than December 31, 2017.
(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of-
(A) Why a particular security requirement is not applicable; or
(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.
(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.
(End of provision)
252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT
REPORTING (OCT 2016)
(a) Definitions. As used in this clause-
"Adequate security" means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
"Compromise" means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
"Contractor attributional/proprietary information" means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
"Controlled technical information" means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
"Covered contractor information system" means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
"Covered defense information" means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is-
(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
"Cyber incident" means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
"Forensic analysis" means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
"Information system" means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
"Malicious software" means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
"Media" means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
''Operationally critical support'' means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
"Rapidly report" means within 72 hours of discovery of any cyber incident.
"Technical information" means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:
(1) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:
(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract.
(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.
(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:
(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations" (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171) in effect at the time the solicitation is issued or as authorized by the Contracting Officer.
(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.
(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
(C) If the DoD CIO has previously adjudicated the contractor's requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.
(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/resources/documents/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
(c) Cyber incident reporting requirement.
(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall-
(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor's network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor's ability to provide operationally critical support; and
(ii) Rapidly report cyber incidents to DoD at http://dibnet.dod.mil.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at http://dibnet.dod.mil.
(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see http://iase.disa.mil/pki/eca/Pages/index.aspx.
(d) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.
(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.
(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.
(i) Use and release of contractor attributional/proprietary information not created by or for DoD.
Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD-
(1) To entities with missions that may be affected by such information;
(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
(3) To Government entities that conduct counterintelligence or law enforcement investigations;
(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or
(5) To a support services contractor ("recipient") that is directly supporting Government activities under a contract that includes the clause at 252.204-7009, Limitations on the Use or Disclosure of Third- Party Contractor Reported Cyber Incident Information.
(j) Use and release of contractor attributional/proprietary information created by or for DoD.
Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph
(c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government's use and release of such information.
(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor's responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(m) Subcontracts. The Contractor shall-
(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial items, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and
(2) Require subcontractors to-
(i) Notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause; and
(ii) Provide the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber incident to DoD as required in paragraph (c) of this clause.
(End of clause)
Contract Clauses in this section are from the FAR, Defense FAR Sup, Air Force FAR Sup, and the Air Force Materiel Command FAR Sup, and are current through the following updates:
Database_Version: 6.15.x.400; Issued: 10/31/2016; FAR: FAC 2005-91; DFAR: DPN20160930; DL.: DL 98- 021; Class Deviations: CD 2016-O0009; AFFAR: 2002 Edition; AFAC: AFAC 2016-0603; IPN: 98-009
I. NOTICE: The following contract clauses pertinent to this section are hereby incorporated by reference:
A. FEDERAL ACQUISITION REGULATION CONTRACT CLAUSES
52.202-01 DEFINITIONS (NOV 2013)
52.203-03 GRATUITIES (APR 1984)
52.203-05 COVENANT AGAINST CONTINGENT FEES (MAY 2014)
52.203-06 RESTRICTIONS ON SUBCONTRACTOR SALES TO THE GOVERNMENT (SEP 2006)
52.203-07 ANTI-KICKBACK PROCEDURES (MAY 2014)
52.203-08 CANCELLATION, RESCISSION, AND RECOVERY OF FUNDS FOR ILLEGAL OR
IMPROPER ACTIVITY (MAY 2014)
52.203-10 PRICE OR FEE ADJUSTMENT FOR ILLEGAL OR IMPROPER ACTIVITY (MAY 2014)
52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN FEDERAL TRANSACTIONS
(OCT 2010)
52.203-13 CONTRACTOR CODE OF BUSINESS ETHICS AND CONDUCT (OCT 2015)
52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS AND REQUIREMENT TO
INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (APR 2014)
52.204-02 SECURITY REQUIREMENTS (AUG 1996)
52.204-04 PRINTED OR COPIED DOUBLE-SIDED ON POSTCONSUMER FIBER CONTENT
PAPER (MAY 2011)
52.204-09 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR PERSONNEL (JAN 2011)
52.204-10 REPORTING EXECUTIVE COMPENSATION AND FIRST-TIER SUBCONTRACT
AWARDS (OCT 2015)
52.204-13 SYSTEM FOR AWARD MANAGEMENT MAINTENANCE (JUL 2013)
52.204-18 COMMERCIAL AND GOVERNMENT ENTITY CODE MAINTENANCE (JUL 2016)
52.204-19 INCORPORATION BY REFERENCE OF REPRESENTATIONS AND CERTIFICATIONS
(DEC 2014)
52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION SYSTEMS
(JUN 2016)
52.209-06 PROTECTING THE GOVERNMENT'S INTEREST WHEN SUBCONTRACTING WITH
CONTRACTORS DEBARRED, SUSPENDED, OR PROPOSED FOR DEBARMENT
(OCT 2015)
52.209-09 UPDATES OF PUBLICLY AVAILABLE INFORMATION REGARDING RESPONSIBILITY
MATTERS (JUL 2013)
52.209-10 PROHIBITION ON CONTRACTING WITH INVERTED DOMESTIC CORPORATIONS
(NOV 2015)
52.210-01 MARKET RESEARCH (APR 2011)
52.211-05 MATERIAL REQUIREMENTS (AUG 2000)
52.215-02 AUDIT AND RECORDS -- NEGOTIATION (OCT 2010)
52.215-08 ORDER OF PRECEDENCE--UNIFORM CONTRACT FORMAT (OCT 1997)
52.215-10 PRICE REDUCTION FOR DEFECTIVE CERTIFIED COST OR PRICING DATA (AUG
2011)
52.215-11 PRICE REDUCTION FOR DEFECTIVE CERTIFIED COST OR PRICING DATA--
MODIFICATIONS (AUG 2011)
52.215-12 SUBCONTRACTOR CERTIFIED COST OR PRICING DATA (OCT 2010)
52.215-13 SUBCONTRACTOR CERTIFIED COST OR PRICING DATA--MODIFICATIONS (OCT
2010)
52.215-14 INTEGRITY OF UNIT PRICES (OCT 2010)
52.215-15 PENSION ADJUSTMENTS AND ASSET REVERSIONS (OCT 2010)
52.215-18 REVERSION OR ADJUSTMENT OF PLANS FOR POSTRETIREMENT BENEFITS
(PRB) OTHER THAN PENSIONS (JUL 2005)
52.215-19 NOTIFICATION OF OWNERSHIP CHANGES (OCT 1997)
52.215-21 REQUIREMENTS FOR CERTIFIED COST OR PRICING DATA AND DATA OTHER
THAN CERTIFIED COST OR PRICING DATA--MODIFICATIONS (OCT 2010)
52.215-23 LIMITATIONS ON PASS-THROUGH CHARGES (OCT 2009)
52.215-23 LIMITATIONS ON PASS-THROUGH CHARGES (OCT 2009) - ALTERNATE I (OCT
2009)
52.216-07 ALLOWABLE COST AND PAYMENT (JUN 2013)
52.216-08 FIXED FEE (JUN 2011)
52.216-11 COST CONTRACT -- NO FEE (APR 1984)
52.216-19 ORDER LIMITATIONS (OCT 1995)
Para (a). Insert Dollar amount or quantity. 'TEXT BEFORE SECTION I
252.204-7008 COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE
INFORMATION CONTROLS (OCT 2016)
(a) Definitions. As used in this provision- "Controlled technical information," "covered contractor information system," "covered defense information," "cyber incident," "information system," and "technical information" are defined in clause 252.204-7012 <252204.htm>, Safeguarding Covered Defense Information and Cyber Incident Reporting.
(b) The security requirements required by contract clause 252.204-7012 <252204.htm>, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.
(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see 252.204-7012 <252204.htm>(b)(2)-
(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations" (see <http://dx.doi.org/10.6028/NIST.SP.800- 171>) that are in effect at the time the solicitation is issued or as authorized by the contracting officer not later than December 31, 2017.
(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of-
(A) Why a particular security requirement is not applicable; or
(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.
(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.
(End of provision)
252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER
INCIDENT REPORTING (OCT 2016)
(a) Definitions. As used in this clause-
"Adequate security" means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
"Compromise" means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
"Contractor attributional/proprietary information" means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
"Controlled technical information" means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
"Covered contractor information system" means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
"Covered defense information" means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is-
(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
"Cyber incident" means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
"Forensic analysis" means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
"Information system" means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
"Malicious software" means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
"Media" means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
''Operationally critical support'' means supplies or services designated by the
Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
"Rapidly report" means within 72 hours of discovery of any cyber incident.
"Technical information" means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems. To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:
(1) For covered contractor information systems that are part of an Information
Technology (IT) service or system operated on behalf of the Government, the following security requirements apply:
(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract.
(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.
(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:
(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations" (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171) in effect at the time the solicitation is issued or as authorized by the Contracting Officer.
(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.
(B) The Contractor shall submit requests to vary from
NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO.
The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
(C) If the DoD CIO has previously adjudicated the contractor's requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.
(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/resources/documents/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .