FDA-RFQ-24 CDER-2024-123253 DM Image to Simulation (I2S).docx
DOCX document 140 KB Posted
- Attached to
- CDER-2024-123253-DM Image to Simulation (I2S). Image Processing, Modeling, and Drug Release Simulation Software. Federal contract opportunity
- Solicitation number
- FDA-RFQ-CDER-2024-123253
About this file
This document is a Request for Quotations (RFQ) from the U.S. Food & Drug Administration (FDA) Office of Acquisition and Grants Services (OAGS) to procure CDER-2024-123253-DM Image to Simulation (I2S), an image processing, modeling, and drug release simulation software package.
The RFQ seeks to acquire a cloud-based image processing platform that can provide comprehensive workflow, data management, storage management, and computing resource management capabilities. The platform must have the ability to segment complex imaging data, extract quantitative information, and predictively simulate critical quality attributes of pharmaceutical samples. The requested system must meet specific technical, operational, and functional requirements, and be deployed on the FDA's high-performance computing (HPC) cluster with Linux-based infrastructure. The procurement is set aside for small businesses only, with a Firm Fixed-Price contract type. Vendors must submit quotes by the close date of the solicitation and provide a one-year manufacturer's warranty on the system.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FDA-RFQ-24 CDER-2024-123253 DM Image to Simulation (I2S).docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Request for Quotations: FDA-RFQ-CDER-2024-123253-DM Image to Simulation (I2S). Image Processing, Modeling, and Drug Release Simulation Software.
Part-A (b) Continuation pages 1 – General- NOTICE OF COMBINED SYNOPSIS/SOLICITATION This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation. Quotes are being requested.
Solicitation Number # FDA-RFQ- FDA-RFQ-CDER-2024-123253-DM, is issued as a Request for Quotations (RFQ). The solicitation and incorporated provisions and clauses are those in effect through Federal Acquisition Circular FAC 2024-05. This is a solicitation for commercial items in accordance with the procedures of FAR Part 12-Acquisition of Commercial Items. This requirement is being solicited as a total small business only set-aside 100% (for small businesses only) FAR 52.219-6, Notice of Total Small Business Set-Aside, using the Simplified Acquisition Procedures per FAR Subpart 13.5. This solicitation cancels any other previous solicitation issued regarding this requirement. Vendors shall provide the country of origin of all listed items and their dollar value, as requested herein.
The U. S. Food & Drug Administration, (FDA) Office of Acquisition and Grants Services (OAGS) has a requirement to procure: CDER-2024-123253-DM Image to Simulation (I2S). Image Processing, Modeling, and Drug Release Simulation Software. under solicitation FDA-RFQ-CDER-2024-123253-DM.
2 - Contract Type The Government intends to award a Firm Fixed-Price (FFP) Purchase Order to procure the requested items/system/services.
The associated NAICS Code is: 334516-Analytical Laboratory Instrument Manufacturing. Offerors must have an active registration in www.SAM.gov, with completed representations and certifications, by the close date of the solicitation.
3.1. Background/Statement of Need
The Division of Product Quality and Research (DPQR) needs an advanced image analysis platform that can provide the reviewers and regulatory researchers to assess the impact of process parameters and material attributes on product quality attributes, such as content uniformity, microstructural deformation, and release profile. A cloud-based powerful image analysis platform can meet these requirements. DPQR has its own high-performance computing (HPC) environment. This HPC environment can provide few unique advantages as follows:
| I. | Host the cloud-based platform. |
| II. | Support the high storage requirement. |
| III. | Provide faster image processing capability. |
| IV. | Perform image-based long-acting drug release modeling. |
3.2. Purpose
The purpose of this requirement is to acquire a DM Image to Simulation (I2S). Image Processing, Modeling, and Drug Release Simulation Software.
3.3. Objective
FDA seeks to purchase a CFSAN-2024-121350 Multichannel Pipette Calibration and Verification Balance. The cloud-based image processing platform should provide a comprehensive workflow, data management, storage management, computing resource management capability. The platform needs to host unique analysis capability that can allow users to quickly analyze and correlate microstructural transformation due to process changes to assess the product’s critical quality attributes. The platform needs to demonstrate a proven track record on solving pharmaceutical and regulatory science challenges involving imaging data. The platform should perform AI-based image processing and should be able to optimize particle and porosity through structure generation and image-based simulation. This platform will be deployed on FDA High Performance Computing (HPC) clusters with a Linux based system that meets the required specifications.
As the system will be installed in FDA DPQR proprietary HPC cluster, there is no security risk. Technical risks on knowledge transfer are mitigated via training and support packages included. Administrative and financial risks are mitigated via annual renewal of the subscription contract.
3.4 - Description/Specifications, salient characteristics and Statement of Work At a minimum, the requested system shall have the technical/salient/functional, operational characteristics and specifications here below described:
4. Conditions: Note* that:
4.1. The Contractor shall indicate if the minimum salient characteristics have been met to be considered responsive for this requirement. The Contractor shall demonstrate how the requested items or services, “MEET” or “DO NO MEET” the salient/functional characteristics and specifications listed here-below. The Contractor shall annotate each salient/functional characteristics and specifications with the following: Meets (if it meets the specification) or Does not meet (if it fails to meet the specification).
4.2. Grey market or refurbished products will not be accepted.
4.3. The Vendor shall indicate if non-domestic items are included in the quote.
4.4. The Vendor shall provide all, of the items/services listed or none.
4.5. The Vendor shall meet all technical/salient/functional, operational characteristics and specifications listed, and if not the manufacturer, shall be able to provide the required service with OEM certified technicians and parts or show proof that they are an authorized third party re seller/provider.
V. Be advised that FDA does not accept documents which contain the use of macros. When submitting documents via email, DO NOT include .exe, mso, or any other executable file types that could potentially trigger email security protections (i.e. email blocks, quarantine). Document submissions required throughout the award period(s) shall not have macro enabled functionality and any document delivered having that functionality will be deemed delinquent, if not corrected prior to the due date.
5. Minimum Specifications and Salient Characteristics. Technical Specifications.
5.1. Specifications/Salient characteristics
The requested system/items/services, shall at a minimum, meet all the technical/salient/functional, operational characteristics and specifications here-in, below listed.
The required features of this equipment are:
Salient Characteristics Item 1 & 2: Image Processing and Drug Release Simulation, A Cloud-Based Platform
The required technical features of cloud-based image processing software are:
| i. | Provide a comprehensive workflow, data management, storage management, computing resource management capability. |
| ii. | Manage and share large volumes of image and quantitative data. |
| iii. | Create and manage complex image processing workflows. |
| iv. | Segment complex imaging data from pharmaceutical samples through the use of traditional, machine learning and deep learning techniques. |
| v. | Extract quantitative information from complex data that can be used to make real world decisions. |
| vi. | Predictively simulate critical quality attributes of various complex datasets. |
| vii. | Optimize particle and porosity through structure generation and image-based simulation. |
| viii. | Browser based user interface, with multi-user support. |
| ix. | The platform needs to be deployed on FDA HCP clusters with a linux based system that meets the required system specifications. |
| x. | Quality control, FDA 21 CFR Part 11 Compliance and Audit Trail Support. |
| xi. | Features a digital queue management system preventing users from overloading their computing resources. More or less resources can be allocated as need or lack of need arises. |
| xii. | Cloud-based, fully integrated software platform with proven regulatory science application. |
| xiii. | The platform needs to demonstrate a proven track record on solving pharmaceutical and regulatory science challenges involving imaging data. |
| xiv. | Perform image-based long-acting drug release modeling. |
The HPC system requirements are:
| i. | Google Chrome browser |
| ii. | CPU: 8 core or more |
| iii. | Memory: 128G or more |
| iv. | Instance Storage: 2T or more |
| v. | GPU |
| vi. | Operating System: Ubuntu 20.04 (or latest version of Redhat if Ubuntu cannot be used) |
| vii. | Software requirements: latest version of Docker and Docker compose should be installed. |
5.2. Other Considerations:
Warranty and Service: ONE-year manufacturer’s warranty, against defects in workmanship and component failure. A full 1-year manufacturer warranty shall be included on repair parts, labor, and travel. The entire system shall be warranted for parts and labor for twelve (12) months from date of installation and acceptance. Service shall be provided by service engineers who are trained and certified by the original manufacturer of the instrument.
Delivery, Installation, and On-site training Delivery, Installation, and On-site training The Vendor shall cover all costs associated with the following:
| i. | System software, shipping, and delivery. |
| ii. | Full system installation in person or screen sharing support on FDA DPQR in house HPC cluster with the help of client’s IT professional. |
| iii. | User training. |
| iv. | On-Demand customer support. |
5.3. Tasks/Deliverable Items/ Deliverable Schedule and Performance Requirements. To meet the purpose and objective of this requirement, the Vendor shall meet the established timelines to provide the below Deliverables. The Vendor shall be responsible for delivery and installation of the instrument to the FDA facility designated herein.
5.3.1. Specific Tasks
Project Milestones/Completion Dates (Estimates and as applicable)
| Work Milestones |
| Due Date |
| System/Warranty/Software/installation/training, and service. |
| 09/30/24 |
5.3.2. Deliverables/Schedule
Deliverable Quantity Delivery Date
| Multichannel Pipet Calibration balance |
| 1 |
| 09/29/2025 |
6.1. Contractor Facility Access: Contractor staff, belongings, and their vehicles are subject to search when they arrive at the FDA facility.
6.2. SECURITY CONSIDERATIONS
Government will provide escort of Contractor’s staff. The company engineer shall not be provided access to any material that involves Non-Public positions and involves the lowest degree of adverse impact on the efficiency of the Agency.
7. Period of Performance and Shipment Destination/Place of Performance
7.1.1. The period of performance shall be one year of 12 months, including a one-year warranty.
7.1.2. The Period of Performance shall be as follows:
| LIN |
| Description |
| POP |
| 1 |
| System/Delivery/Warranty/Software/licenses/installation/training, and service |
| 9/30/2024 to 9/29/2025 |
7.2. Packing, Marking, Delivery and Shipping
The Contractor shall deliver the items and quantities ordered, all or none. All deliverables required under this contract shall be packaged, marked and shipped in accordance with Government specifications. At a minimum, all deliverables shall be marked with the contract number and Contractor’s name. All required materials shall be delivered in immediate new, usable and acceptable condition, at the U. S. Food and Drug Administration (FDA) facility/address listed below:
Delivery Location:
Food and Drug Administration 10903 New Hampshire Ave Building 64, Room 1068 Silver Spring, MD 20993
The FDA’s TPOC will approve all tasks and deliverables. The delivery or services shall be performed during regular business hours (Monday-Friday) during the times of 8:00 AM – 4:00 PM Eastern, excluding holidays.
The TPOC will be responsible for determining the acceptance of the work that is completed. The Vendor shall contact the TPOC by email or phone to schedule delivery. Deliveries shall be coordinated with the TPOC prior to shipment. No deliveries will be accepted without prior authorization from the TPOC.
i. Delivery and Marking All deliverables shall be marked as follows:
(a) Name and address of the Contractor,
(b) Contract Number
(c) Description of item contained therein; and
(d) Consignee’s name and address.
(e) Each delivery location may provide specific delivery instructions.
(f) Travel and expenses shall be covered by the Contractor.
ii. Payment of Postage and Fees All postage and fees related to distribution of deliverable including forms, reports, etc., shall be paid by the Contractor.
8.1. Contracting Officer’s Technical Point of Contact (TPOC)
The TPOC is responsible for the acceptance of the items or services requested.
8.2. Technical Direction
A. Performance of the work under the resultant contract shall be subject to the technical direction of the TPOC. The term "technical direction" is defined to include the following:
i). Technical directions to the Contractor which shift work emphasis between work areas or tasks, require pursuit of certain lines of inquiry, fill in details or otherwise serve to accomplish the contractual scope of work, ii). Providing information to the Contractor for assistance in the interpretation of specifications, or technical portions of the work description, and iii). Reviewing and, where required by the contract, approving of technical reports, specifications, and technical information to be delivered by the Contractor to the Government under the requirement.
B. Technical direction shall be within the general scope of work stated in the contract. The TPOC does not have the authority to, and may not, issue any technical direction which (1) constitutes an assignment of additional work outside the general scope of the contract; (2) constitutes a change as defined in the contract clause entitled "Changes, FAR 52.212 – 4 (c)." (3) in any manner causes an increase or decrease in the total contract price; or (4) changes any of the expressed terms, conditions, or specifications of the contract.
C. All technical directions shall be issued in writing by the TPOC or shall be confirmed by him/her in writing within five (5) working days.
D. The Contractor shall proceed promptly with the performance of technical directions duly issued by the TPOC in the manner prescribed by this clause and within his/her authority under the provisions of this clause.
E. If, in the opinion of the Contractor, any instruction or direction issued by the TPOC is within one of the categories as defined in B. (1) through B. (4) above, the Contractor shall not proceed but shall notify the Contracting Officer, in writing, within five (5) working days after the receipt of any such instruction or direction and shall request the Contracting Officer to modify the Contract accordingly. Upon receiving such notification from the Contractor, the Contracting Officer shall issue an appropriate contract modification or advise the Contractor, in writing, that, in his/her opinion, the technical directions are within the scope of this clause and do not constitute a change under the "Changes" clause of the contract. The Contractor shall thereupon proceed immediately with the direction given. Any failure of the parties to agree upon the nature of the instruction or direction, or upon the contract action to be taken with respect thereto, shall be subject to the provisions of the contract clause entitled "Disputes."
8.3. Contracting Officer’s Authority
The Contracting Officer (CO) is the only person authorized to approve changes in any of the requirements of the statement of work. In the event the Contractor effects any changes at the direction of any person other than the CO or the TPOC the changes shall be considered to have been made without authority and no adjustment shall be made in the contract price to cover any increase in costs incurred as a result thereof. The CO shall be the only individual authorized to accept nonconforming work, waive any requirement of the contract and modify any term or condition of the contract. The Contracting Officer is the only individual who can legally obligate Government funds.
The Contracting Officer is the only person with authority to act as agent of the Government under the Contract. Only the Contracting Officer has authority to: (1) direct or negotiate any changes in the statement of work; (2) modify or extend the period of performance; (3) change the delivery schedule; (4) authorize reimbursement to the Contractor for any costs incurred during the performance of the Contract; or (5) otherwise change any terms and conditions of the Contract.
Part-B Contract Clauses
1. FAR 52.212-4 - Contract Terms and Conditions – Commercial – Items (Dec 2022).
2. FAR 52.252-2 - Clauses Incorporated by Reference (Feb 1998) This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at these addresses: https://www.acquisition.gov/browse/index/far; https://www.acquisition.gov/hhsar
| Clause |
| Title |
| Date |
| Reference |
| 52.204-21 |
| Basic Safeguarding of Covered Contractor Information Systems |
| Nov 2021 |
| 4.1903 |
| HHSAR |
| Title |
| Date |
| Reference |
| 352.211-3 |
| Paperwork Reduction Act. |
| Dec, 2015 |
| 311.7301 |
| 352.222-70 |
| Contractor Cooperation in Equal Employment Opportunity Investigations |
| Dec, 2015 |
| 322.810(h) |
Health and Human Services Acquisition Regulation (HHSAR) Clauses can be viewed in full text at: http://www.hhs.gov/policies/hhsar/subpart352.html#Subpart352.1- InstructionsforUsingProvisionsandClauses
3. FAR 52.217-8 - Option to Extend Services. (Nov 1999) The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor any time before the contract expires.
4. FDA Security and Privacy (NA)
1. Baseline Security Requirements
a. Applicability. The requirements herein apply whether the entire contract or modification (hereafter "contract"), or portion thereof, includes either or both of the following:
i. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
ii. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the FDA mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
b. Safeguarding Information and Information Systems. All government information and information systems must be protected in accordance with FDA policies and level of risk. At a minimum, the Contractor (and/or any subcontractor) must:
i. Protect the:
Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
Availability, which means ensuring timely and reliable access to and use of information. Note to the Requiring Activity Representative: Complete the following section using the information obtained from the Information Security and Privacy Certification Checklist.
ii. Categorize all information owned and/or collected/managed on behalf of FDA and information systems that store, process, and/or transmit FDA information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories. Based on information provided by the System/Data Owner, ISSO, privacy representative, or other POC, the impact level for each Security Objective (Confidentiality, Integrity, and Availability) and the Overall Impact Level, which is the highest watermark of the three factors of the information or information system are the following:
Confidentiality: [ ] Low [ ] Moderate [ ] High
Integrity: [ ] Low [ ] Moderate [ ] High
Availability: [ ] Low [ ] Moderate [ ] High
Overall Impact Level: [ ] Low [ ] Moderate [ ] High
iii. Based on the agreed-upon level of impact, implement the necessary safeguards to protect all information systems and information collected and/or managed on behalf of FDA regardless of location or purpose.
iv. Report any discovered or unanticipated threats or hazards by either the agency or contractor, or if existing safeguards have ceased to function immediately after discovery, within one (1) hour or less, to the government representative(s). This includes notifying the FDA Cybersecurity and Infrastructure Operations Coordination Center (CIOCC) within one (1) hour of discovery/detection in the event of a cybersecurity or privacy incident.
v. Adopt and implement all applicable policies, procedures, controls, and standards required by the FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the FDA Information Security Program security requirements, outlined in the FDA Information Security and Privacy Protection (IS2P) policy, by contacting the CO/COR or emailing your ISSO.
c. Privacy Act. Comply with the Privacy Act requirements (when applicable), and tailor FAR and HHSAR clauses as needed.
d. Privacy Compliance. Comply with the E-Government Act of 2002, NIST SP 800-53, and applicable FDA privacy policies and complete all the requirements below: Note to the Requiring Activity Representative: Complete this section using the information obtained from the Information Security and Privacy Certification Checklist. This information may be included after award in the event it is not yet available at the time of acquisition.
i. Per the Office of Management and Budget (OMB) Circular A-130, Personally Identifiable Information (PII), is "information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual." Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother's maiden name, biometric records, etc.
ii. Based on information provided by the ISSO, System/Data Owner, or other security or privacy representative, it has been determined that this solicitation/contract involves: [ ] No PII [ ] PII
iii. The Contractor must support the agency with conducting a Privacy Threshold Analysis (PTA) for the information system and/or information handled under this contract to determine whether or not a full Privacy Impact Assessment (PIA) needs to be completed. If the results of the PTA show that a full PIA is needed, the Contractor must support the agency with completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the
E-Government Act of 2002. The PTA/PIA must be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).
The Contractor must support the agency in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.
e. Controlled Unclassified Information (CUI). Executive Order 13556 defines CUI as "information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information." The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term "handling" refers to "…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information." 81 Fed. Reg. 63323. The requirements below apply only to nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, must be:
i. Marked appropriately.
ii. Disclosed to authorized personnel on a Need-To-Know basis.
iii. Protected in accordance with NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations applicable baseline if handled by a contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
iv. Returned to FDA control, destroyed when no longer needed, or held until otherwise directed. Information and/or data must be disposed of in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
f. Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) must protect all government information that is or may be sensitive by securing it with a solution that is validated with current FIPS 140 validation certificates from the NIST CMVP.
g. Government Furnished Equipment (GFE) for Foreign Travel. FDA personnel are prohibited from taking GFE when participating in personal, unofficial travel to foreign countries. FDA personnel are strictly prohibited from teleworking using GFE in foreign.
countries. FDA personnel must also request loaner GFE from the FDA Foreign Travel
h. Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of FDA must be used only for the purpose of carrying out the provisions of this contract and must not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and must ensure that all work performed by its employees and subcontractors must be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed must be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein. The confidentiality, integrity, and availability of such information must be protected in accordance with HHS and FDA policies. Unauthorized disclosure of information will be subject to the HHS and FDA sanction policies and/or governed by the following laws and regulations:
i. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
ii. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
iii. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
i. Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol must comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
j. Information and Communications Technology (ICT). ICT products and services from prohibited entities/sources must not be used/acquired in compliance with Public Law 115-232, Section 889 Parts A and B, FAR 4.21, FAR 52.204.23, FAR 52.204.24, and FAR 52.204.25. The contractor (and/or any subcontractor) must notify the government if they identify prohibited ICT products and/or services are used during the contract performance.
k. Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS must enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, HTTPS is not required, but it is highly recommended. Consult the HHS Policy for Internet and Email Security for additional information.
program for official travel to any foreign country. Please see the FDA IS2P, Appendix T Government Furnished Equipment for Foreign Travel.
l. Contract Documentation. The Contractor must use provided templates, policies, forms, and other agency documents to comply with contract deliverables as appropriate. Note to the Requiring Activity Representative: See Appendix C for baseline deliverables. Do NOT include in procurement documentation.
m. Standard for Encryption. The Contractor (and/or any subcontractor) must:
i. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
ii. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with an encryption solution that is validated with current FIPS 140 validation certificates from the NIST CMVP.
iii. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and FDA-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
iv. Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with current FIPS 140 validation certificates from the NIST CMVP. The Contractor must provide a written copy of the validation documentation to the COR.
v. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys http://csrc.nist.gov/publications/. Encryption keys must be provided to the COR upon request and at the conclusion of the contract.
n. Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract must complete the FDA non-disclosure agreement (3398 Form)], as applicable. Contractors (and/or subcontractors) must submit a copy of each signed and witnessed NDA to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition. Note to the Requiring Activity Representative: See Appendix D for the FDA Contractor Non-Disclosure Agreement. Do NOT include in procurement documentation.
2. Training Requirements
a. Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract must complete the applicable FDA information security awareness, privacy, and records management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees must complete FDA information security awareness, privacy, and records management training at least annually, during the life of this contract. All provided training must be compliant with HHS training policies.
b. Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy.
c. Training Records. The Contractor (and/or any subcontractor) must maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records must be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
3. Rules of Behavior
a. The Contractor (and/or any subcontractor) must ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, HHS Rules of Behavior for Privileged Users, and FDA policies and standards.
b. All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Agency data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
4. Incident Response
a. The Contractor (and/or any subcontractor) must respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/FDA CIOCC /Incident Response Team teams within 24 hours, whether the response is positive or negative. FISMA defines an incident as "an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. In accordance with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable
Information (PII), an incident is "an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies" and a privacy breach is "the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose." For additional information on the HHS breach response process, please see the FDA IS2P Appendix F: Incident Response and the HHS Policy and Plan for Preparing for and Responding to a Breach of Personally Identifiable Information (PII)."
b. In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) must:
i. Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract, with encryption solution that is validated with current FIPS 140 validation certificates from the NIST CMVP.
ii. NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so, instructed by the Contracting Officer or representative, the Contractor must send FDA approved notifications to affected individuals as directed by FDA’s SOP.
iii. Report all suspected and confirmed information security and privacy incidents and breaches to the FDA CIOCC, COR, CO, FDA SOP (or his or her designee), and other stakeholders, including breaches involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour, and consistent with the applicable FDA and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contact information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor must:
Cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach.
Not include any sensitive information in the subject or body of any reporting e-mail; and
Encrypt sensitive information in attachments to email, media, etc.
iv. Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, and HHS and FDA breach response policies when handling PII breaches.
v. Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation on demand.
5. Position Sensitivity Designations All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract (e.g. tier 1, 2, or 4): ____________. Note to the Requiring Activity Representative: The Requiring Activity Representative, in conjunction with Personnel Security, must use the OPM Position Sensitivity Designation automated tool (https://www.opm.gov/investigations/) to determine the sensitivity designation for background investigations. After making those determinations, include all applicable position sensitivity designations.
6. Homeland Security Presidential Directive (HSPD)-12 The Contractor (and/or any subcontractor) and its employees must comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; OMB M-19-17; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2. Note to the Requiring Activity Representative: For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12.
7. Roster. The Contractor (and/or any subcontractor) must submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster must be submitted to the COR and/or CO per the COR or CO’s direction. Any revisions to the roster as a result of staffing changes must be submitted within a timeline as directed by the COR and/or CO. The COR will notify the Contractor of the appropriate level of investigation required for each staff member. If the employee is filling a new position, the Contractor must provide a position description and the Government will determine the appropriate suitability level.
8. Contract Initiation and Expiration
a. General Security Requirements. The Contractor (and/or any subcontractor) must comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor must follow the FDA EPLC framework and methodology in accordance with the FDA EPLC Project documentation, located here: http://sharepoint.fda.gov/orgs/DelMgmtSupport/IntakeProc/EPLCv2/SitePages/v2/EPLCHome.aspx and in accordance with the HHS Contract Closeout Guide (2012).
b. System Documentation. Contractors (and/or any subcontractors) must follow and adhere to HHS System Development Life Cycle requirements, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
c. Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) must provide all required documentation in accordance with SMGs published by FDA’s Office of Acquisitions and Grant Services (OAGS) to the CO and/or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
d. Notification. The Contractor (and/or any subcontractor) must notify the CO and/or COR and system ISSO as soon as it is known that a contract employee will stop working under this contract.
e. Contractor Responsibilities upon Physical Completion of the Contract. The contractor (and/or any subcontractors) must return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor must provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and FDA policies.
f. The Contractor (and/or any subcontractor) must perform and document the actions identified in the FDA eDepart system http://inside.fda.gov:9003/EmployeeResources/NewEmployee/eDepartDepartureSystem/default.htm as soon as it is known that a contract an employee will terminate work under this contract. The Contractor (and/or any subcontractor) shall coordinate with the COR via email, copying the Contract Specialist, to ensure that the appropriate person performs and documents the actions identified in the FDA eDepart system.
9. Records Management and Retention
a. The Contractor (and/or any subcontractor) must maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS Policy for Records Management and HHS and FDA policies and must not dispose of any records unless authorized by HHSFDA.
b. In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, he/she must document and report the incident in accordance with HHS and FDA policies.
10. High Value Asset (HVA) If a system is identified as HVA,24 the contractor must comply with the FDA IS2P Appendix AB: High Value Asset (HVA) Program, the HHS Policy for the High Value Asset (HVA) Program, and the DHS HVA Control Overlay 25 in addition to the above requirements.
All documentation must be available to the CO and/or COR upon request.
5. FDA Privacy Act It has been determined that this contract is subject to the Privacy Act of 1974, because this contract provides for the design, development, or operation of a system of records about individuals from which records are retrieved by name or other identifying particular.
The System of Records Notice(s) (SORN(s)) that is applicable to this contract is: [FDA insert SORN name/number if one exists. If there is no SORN, indicate that a new or revised SORN will be developed].
The system of records design, development, or operation work the Contractor is to perform is: [FDA insert description of design, development, and/or operation work; see definitions in the FAR at 24.101 - Definitions].
The disposition to be made of the Privacy Act records upon completion of contract performance is: [FDA insert records disposition instructions the contractor and any subcontractor must follow upon completion of contract performance26].
6. Physical Access to Government Controlled Facilities:
"FDA reserves the right to exercise priorities and allocations authority with respect to this contract, to include rating this order in accordance with 45 CFR Part 101, Subpart A—Health Resources Priorities and Allocations System."
7. Contractor Performance Evaluation(s) In accordance with Federal Acquisition Regulation (FAR) 42.15, FDA will complete annual and final Contractor performance evaluations. Annual evaluations will be prepared to coincide with the anniversary date of the contract. Additional interim performance evaluations may be prepared at Contracting Officer discretion, as necessary. Final performance evaluations will be completed upon contract expiration. FDA will utilize the Contractor Performance Assessment Reporting System (CPARS) in order to execute annual and final contractor performance evaluations. CPARS is a secure Internet website located at http://www.cpars.csd.disa.mil/cparsmain.htm. FDA will register the Contractor in CPARS upon receipt of the name and email address of two (2) individuals who will be responsible for serving as the Contractor’s primary and alternate CPARS contacts. Once FDA registers the Contractor in CPARS, the Contractor will receive an automated CPARS email message which contains User IDs and instructions for creating a password.
Once a performance evaluation is issued, the Contractor’s primary and alternate CPARS contact will receive an email instructing them to logon to CPARS in order to review the performance evaluation. The Contractor has 30 days from the date of performance evaluation issuance in which to review the evaluation. If the Contractor is in agreement with the performance evaluation outcome, the evaluation becomes final. Should the Contractor be in disagreement with the performance evaluation outcome, rebuttal comments must be submitted via the CPARS within 30 days from date the evaluation was issued by FDA. Any disagreement between the Contracting Officer and the Contractor will be referred to a contracting official one level above the Contracting Officer, whose decision will be final.
Copies of each performance evaluation and Contractor responses, if any, will be retained as part of the official contract file and will be used to support future award decisions. Evaluations will also be stored for a 3-year period in the Contractor Performance Assessment Reporting System (CPARS) in order to execute annual and final contractor performance evaluations. CPARS is a secure Internet website located at http://www.cpars.csd.disa.mil/cparsmain.htm.
Contractors may obtain CPARS training material and register for on-line training at http://www.cpars.csd.disa.mil/allapps/cpcbtdlf.htm. There is no fee for registration or use of the CPARS.
8. Holidays FDA personnel observe the FDA following days as holidays:
i) New Year's Day
ii) Columbus Day
iii) Washington's Birthday
iv) Veterans' Day
v) Memorial Day
vi) Thanksgiving Day
vii) Independence Day
viii) Christmas Day
ix) Labor Day
x) Juneteenth
xi) Martin Luther King's Birthday
xii) Any other day designated by Federal statue
xiii) Any other day designated by Executive Order
xiv) Any other day designated by the President's Observance of such days by Government personnel shall not be cause for an extension to the delivery schedule or period of performance or adjustment to the price, estimated cost, or fee(s), if any, except as set forth in the Contract.
Except for designated around-the-clock or emergency operations, Contractor personnel shall not be able to perform on-site under the Contract with FDA on holidays set forth above. The Contractor shall not charge any holiday as direct charge to the Contract In the event Contractor personnel work during a holiday observed by the Contractor other than those above, no form of holiday or other premium compensation will be reimbursed as either a direct or indirect cost. However, this does not preclude reimbursement for authorized overtime work.
In the event the FDA grants administrative leave to its Government employees at the site, on-site Contractor personnel shall also be dismissed if the site is being closed. However, the Contractor shall continue to provide sufficient personnel to perform around-the-clock requirements of critical efforts already in progress or scheduled and shall be guided by the instructions issued by the Contracting Officer or her/his duly appointed representative.
In each instance when the site is closed to Contractor personnel as a result of inclement weather, potentially hazardous conditions, explosions, or other special circumstances, the Contractor shall direct its staff as necessary to take actions such as reporting to its own site(s) or taking appropriate leave consistent with its policies. The cost of salaries and wages to the Contractor for the period of any such site closure shall be a reimbursable item of direct cost under the Contract for employees whose regular time is normally a direct charge if they continue to perform on the work; otherwise, the costs are reimbursable as indirect costs in accordance with the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .