HT940624Q0017-0002 Solicitation PWS Update.pdf
PDF 793 KB Posted
- Attached to
- NMCP - Laboratory Document Management Control System Federal contract opportunity
- Solicitation number
- HT940624Q0017
- Issued by
- Defense Health Agency
About this file
This document is a Performance Work Statement for a non-personal services contract to provide Medialab Corporate Account Subscription Services. The key objectives include providing document control for 10 sites and 500 users, compliance and continuing education services, and other software solutions. The contract has a period of performance of one (1) Base Year. The work shall be performed at the contractor's facility. The contractor is required to have services available on federal holidays. The government will not provide any government furnished services, facilities, equipment, or materials. The contractor shall be responsible for obtaining and maintaining access to the PIEE/GFP Module application, meeting cybersecurity requirements, and ensuring all contractor personnel have the required training and certifications. The offer due date is 12:00 AM on 26 Apr 2024.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HT940624Q0017 .pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
HT940624Q0017 07-Feb-2024
b. TELEPHONE NUMBER
757-953-7570
8. OFFER DUE DATE/LOCAL TIME
12:00 AM 26 Apr 2024
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
HT94069. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
LINDSAY GRAY
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
0011990108-0001
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED ORX
SMALL BUSINESS
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
DHA CONTRACTING OFFICE TIDEWATER HT9406
7700 ARLINGTON BLVD
FALLS CHURCH VA 22042
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS A
13b. RATING
CODE15. DELIVER TO CODE HT0242 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
NAV MED CNT PORTSMOUTH VA - MM
KRISTEN COTE
ATTN SUPPLY OFFICER BLDG 250
54 LEWIS MINOR STREET
PORTSMOUTH VA 23708-2297
TEL: FAX:
FAX:
TEL: SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
$24,000,000
NAICS:
611710
X
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF52
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
HT940624Q0017
Section SF 1449 - CONTINUATION SHEET
SOLICITATION/CONTRACT FORM
VENDOR TO COMPLETE THE FOLLOWING:
CAGE: _____________________
UEI: _____________________
Vendor POC: _____________________
Vendor Phone: ____________________
Vendor E-mail: ____________________
Notes to Vendor:
-At a minimum, the SF1449 must be completed to be considered for this opportunity. Additional reqirement in order to be considered for the opportunity; submit a brochure, spec sheet, or past performance information. Please respond to blocks 17a and 30a-c on page 1 and the vendor information on page 3, as well as provide your price(s) on the
Contract Line Item Number(s) (CLINs). Cursive font signatures will not be accepted.
-Offeror will provide all license agreements, End User License Agreements (EULA), Terms of Service (TOS), Federal Payment Plans, Extended Payment Plans, and other similar instruments or agreements, required to be signed, or agreed to, by the Government that the offeror or any of its suppliers or subcontractors (at any level) require. The Government may review to ensure terms and conditions are consistent with Federal law and otherwise satisfy the Government’s needs. Among terms and conditions that are not acceptable, which makes an offer ineligible for award, include: those such as Government indemnification of any party; choice of law or forum for disputes; mandatory arbitration; any language that would or might require the Government to renew or extend performance or usage of any item, product, or service; or any other feature that unduly puts a burden or restriction on the Government.
-Vendor to reference request for quotes number (RFQ#) HT940624Q0017-0003 on all inquiries.
NOTE TO VENDOR:
Because the Government’s automated procurement system does not provide for the contractor’s electronic signature, a fully executed copy of this bilateral award, signed by both parties, will be retained in the Government’s official contract file.
-For competitive service buys, type: Award will be made on the basis of the lowest evaluated price and the capability to meet the requirement detailed in the Performance Work Statement.
PROMPT PAYMENT
For Prompt Payment Act purposes, this contract is subject to the 7 calendar day constructive acceptance period.
Billing / Payment in arrears
For all questions, POC:
Ms. Lindsay A. Gray Contract Specialist E: Lindsay.a.gray.civ@health.mil mailto:Lindsay.a.gray.civ@health.mil
PERFORMANCE WORK STATEMENT
PART 1
1.0 GENERAL INFORMATION
1.1 This is a non-personal services contract to provide Medialab Corporate Account
Subscription Services.
1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Medialab Corporate Account as defined in this
Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.
1.3 Background: Medialab is a software system that the NMC Portsmouth VA has been using to assist in the document control of laboratory SOP’s. This allows the NMCP Laboratory to stay within College of American Pathologists (CAP) compliance.
1.4 Objectives: Basic services include:
• Medialab Corporate Account Document Control for (10 sites, 500 users) to upload procedures and to provide secure traceable documentation.
• Histology Compliance & CE for (10 users).
• Compass system for (10 sites, 500 users).
• Compliance and CE for (10 sites, 500 users).
• InspectionProof – (10 sites, 500 users).
• IQE: (10 sites).
• Exam Simulator MLS, MT, MLT (13 users).
• Personnel Documentation for (10 sites, 500 users)
• Included standard support.
1.5 Scope: The contractor shall accomplish all services that are listed in the Medialab software master agreement.
1.6 Period of Performance (PoP): The period of performance shall be for one (1) Base Year.
1.7 Administrative specifications
1.7.1 Place of performance: The work shall be performed at the contractor facility.
1.7.2 Recognized Federal holidays: The contractor is required to have services available on holidays.
New Year’s Day Labor Day
Martin Luther King Jr.’s Birthday Columbus Day
President’s Day Veteran’s Day
Memorial Day Thanksgiving Day
Juneteenth Day Christmas Day
Independence Day
1.7.3 Hours of operation: The contractor is responsible for conducting business Monday thru
Friday between the hours of 10:00 am – 6:00 pm except Federal holidays or when the
Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.
1.8 Contractor travel: None authorized.
1.9 Other Direct Costs (ODC): None.
1.10 Non-Disclosure Agreement (NDA): All contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA contractor NDA (DHA Form 49) prior to beginning work on the subject contract. The contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors. The NDA shall be executed not later than first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the contractor. The contractor shall maintain originally signed NDAs of individual employees and provide copy to the COR.
1.11 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.
1.12 Contractor Identification
1.12.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy
Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel.
Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.
1.12.2 Contractor personnel will be required to attend meetings or otherwise communicate with
Government and/or other contract representatives to meet the requirements of this order.
Contractor personnel shall make their contractor status known during introductions.
1.12.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.
1.13 Contractor Access to Health Affairs (HA)/DHA Network(s)
1.13.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's
Personnel Security Office for a background investigation.
1.13.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the
DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.
1.14 Personnel Security
1.14.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce
Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated
March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance
Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care
Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA
Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM
5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:
1.14.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security
Office can be reached at (703) 275-6038.
1.14.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).
1.14.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.
PART 2
2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE
PUBLICATIONS/INSTRUCTIONS
2.1 Definitions:
2.1.1 CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.
2.1.2 CONTRACTING OFFICER (KO). A person with authority to enter into, administer, and/or terminate contracts, and make related determinations and findings on behalf of the government. This is the only individual who can legally bind the government.
2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.
2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.
2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The
Government may either prepare the QASP or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the
Government’s plan.
2.2 Acronyms:
AIS Automated Information System
APL Approved Products List APL
AQL Acceptable Quality Level
ARRT Acquisition Requirements Roadmap Tool
ATO Authority to Operate
B2B Business-2-Business
CAC Common Access Card
CAP Cloud Access Point
CCEVS Common Criteria Cybersecurity Evaluation and Validation Scheme
CDI Covered Defense Information
CE Computer Environment
CDRL Contract Data Requirement List
CIO Chief Information Officer
CJCSM Chairman of the Joint Chiefs of Staff Manual
CMMC Cybersecurity Maturity Model Certification
CMR Contractor Manpower Reporting
CNSSI Committee on National Security Systems Instruction
CO Contracting Officer(s)
CONUS Continental United States (excludes Alaska and Hawaii)
COR Contracting Officer Representative
COTR Contracting Officer's Technical Representative
CSP Cloud Service Provider
CSSP Cyber Security Service Provider
CUI Controlled Unclassified Information
DAD-A Deputy Assistant Director for Acquisition
DC3 DoD Cyber Crime Center
DD Form 254 Department of Defense Contract Security Requirement List (if applicable)
DB Design-Build
DBB Design-Bid-Build
DFARS Defense Federal Acquisition Regulation Supplement
DHA Defense Health Agency
DISA Defense Information System Agency
DoD Department of Defense
DoDD Department of Defense Directive
DoDI Department of Defense Instruction
DSAs Data Sharing Agreements
DSAA Data Sharing Agreement Application
DMZ Demilitarized Zone
DoDM Department of Defense Manual
DPCLO DHA Privacy and Civil Liberties Office
DUA Data Use Agreement eMSM Enhanced Multi-Service Markets
EULA End User License Agreement
EVM Earned Value Management
FAR Federal Acquisition Regulation
FCI Federal contract information
FE Facilities Enterprise
FedRAMP Federal Risk Authorization and Management Program
FISMA Federal Information Security Modernization Act
FRCS Facility Related Control Systems
FSO Facilities Security Officer
HA Health Affairs
HIPAA Health Insurance Portability and Accountability Act
HCA Head of the Contracting Activity
HIT Health Information Technology
IGCE Independent Government Cost Estimate
IA Information Assurance
IO Initial Outfitting
I/O In/Out Processing Portal
IPv Internet Protocol Version
IS Information System
ISP Internet Service Provider
IT Information Technology
ISCM Information Security Continuous Monitoring
IV&V Independent Verification & Validation
MedCOI Medical Community of Interest
MHS Military Health System
MIL-STD Military Standard
MTFs Military Treatment Facilities
NCR National Capitol Region
NDA Non-Disclosure Agreement
NIAP National Information Assurance Partnership
NIST National Institute of Standards and Technology
OCONUS Outside Continental United States (includes Alaska and Hawaii)
ODC Other Direct Costs
OPM Office of Personal Management
OSD Office of the Secretary of Defense
P-ATO Personal Authorization to Operate
P&R Personnel and Readiness
PGI Procedures, Guidance and Information
PDT Project Delivery Team
PHI Protected Health Information
PII Personally Identifiable Information
PIT Platform Information Technology
PK Public Key
PKI Public Key Infrastructure
POA&M Plan of Action and Milestones
POC Point of Contact
PMO Program Management Office
PoP Period of Performance
PP Personal Property
PPSM Ports, Protocols, and Services Management
PRS Performance Requirements Summary
PSP Personnel Security Program
PWS Performance Work Statement
QA Quality Assurance
QAP Quality Assurance Program
QASP Quality Assurance Surveillance Plan
QC Quality Control
QCP Quality Control Plan
RFP Request for Proposal
RFQ Request for Quotation
RMF Risk Management Framework
SP Special Publication
SPRS Supplier Performance Risk System
SRM Sustainment, Restoration and Modernization
SRG Security Requirements Guides
STIG Security Technical Implementation Guides
TOS Terms of Service
US United States
UFC Unified Facilities Criteria
VPN Virtual Private Network
XML Extensible Markup Language
PART 3
3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:
3.1 Services: The Government:
☒ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Government Furnished Services required in support of this contract/task orders. These Services are described below: provide
3.2 Facilities: The Government:
☒ Will NOT provide Facilities in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Facilities in support of this contract/task orders. The Government provided
Facilities are described below:
3.3 Utilities: The Government:
☒ Will NOT provide Utilities in support of this contract/task order. As a result, this paragraph is
Not Applicable.
☐ WILL provide Utilities in support of this contract/task orders. The Government provided
Utilities are described below:
3.4 Equipment: The Government:
☒ Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Equipment in support of this contract/task orders. The Government provided
Equipment is described below:
3.4.1 Procurement Integrated Enterprise (PIEE), GFP Module Application
The contractor shall be responsible for obtaining and maintaining access, training and successful operation of the PIEE/GFP Module application for the entirety of the contract/task order PoP.
The PIEE GFP Module application is located at the following website: https://wawf.eb.mil/piee-landing/. Access to PIEE/GFP Module application training materials and in-depth information applicable to the contractor’s responsibilities regarding GFP can be found at the following website: https://dodprocurementtoolbox.com/.
Contracting Office Responsibilities:
The Contracting Office shall ensure close coordination and validation of the GFP items with the
COR and DHA Accountable Property Officer prior to uploading the GFP Attachment into the
PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Contracting Office’s responsibility to prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The CO and COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.
The contracting office will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the
Contracting Office, and requested within the PIEE/GFP Module system.
Contractor Responsibilities:
A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a timely, complete and accurate accounting of the GFP applicable to the contract/task order. Contractors are required to report the receipt of any GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their contract. Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.
The contractor shall report semi-annually 100% inventories, reconciliations, and final disposition of GFP provided by the government. Final invoices will not be paid pending GFP reconciliation.
Contractors shall be aware of and ensure compliance with applicable FAR Part 45, DFARS 245 and 252.245, Defense Pricing and Contracting Policies, Procurement Integrated Enterprise
Environment Standards, DHA Administrative Instruction 094 and DHA Guidance.
3.5 Materials: The Government:
https://wawf.eb.mil/piee-landing/ https://wawf.eb.mil/piee-landing/ https://dodprocurementtoolbox.com/
☒ Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ IS providing Materials in support of this contract/task orders. The Government-provided
Materials are described below:
PART 4
4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES
4.1 Services: The Contractor:
☐ Will NOT provide Contractor Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ WILL provide Contractor Furnished Services required in support of this contract/task orders.
These Services are described below: provide access to Media Lab subscription services via the internet (web based program).
4.2 General: The contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 5 of this PWS.
PART 6
6.0 INFORMATION TECHNOLOGY & SECURITY
6.1 All work under this contract is unclassified.
6.2 The TIER 2 level and position sensitivity designation for positions under this contract is:
(Requirement must be checked in order to be a requirement for this PWS.)
6.2.1 TIER II: Non-critical sensitive position .
6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements:
6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes
PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office
(DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into
DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect
MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data.
After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.
6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.
6.4 Training
6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements:
6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity
Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoD 8570.01-M. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.
6.4.1.2 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoD
8570.01–M, IA Workforce Improvement Program. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-2001, including:
6.4.1.2.1 DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01–M; and
6.4.1.2.2 Appropriate operating system certification for IA technical positions as required by
DoD 8570.01–M.
6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.
6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.
6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.
6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS:
6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication (SP)
800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171), in accordance with DFARS clause 252.204-7012.
6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800-
171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment
Methodology requirement flows down to subcontractors.
6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier
Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/)
6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD
Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order.
See Attachment 2, Deliverable Schedule Table.
6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.
https://www.sprs.csd.disa.mil/
6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.
6.5.4 Cybersecurity Maturity Model Certification (CMMC). The CMMC (DFARS clause
252.204-7021) builds upon the NIST SP 800-171 DoD Assessment Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract information (FCI) and DoD
Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk.
The CMMC requirement flows down to subcontractors.
6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization
(3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.
6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or
COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.
6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management
Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.
6.5.8 Cyber Incident Reporting Requirement
6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the https://www.cmmcab.org/ https://www.fedramp.gov/ contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:
6.5.8.1.1 Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other IS on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and
6.5.8.1.2 In accordance with DFARS clause 252.204-7012, rapidly report (within 72 hours) cyber incidents involving DoD CUI to DoD Cyber Crime Center (DC3) via https://dibnet.dod.mil/portal/intranet/. In the event of a cybersecurity incident involving a CUI-
Specific breach (i.e., PII/PHI), the contractor, in addition to reporting to the DC3, shall follow the incident reporting guidance prescribed in the TRICARE Operations Manual, Chapter 1, Section 5, “Compliance with Federal Statutes” at https://manuals.health.mil/
6.5.8.2 Cyber incident report: The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements as prescribed at the https://dibnet.dod.mil/portal/intranet/.
6.5.8.3 Medium assurance certificate requirement: In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a
DoD-approved medium assurance certificate, see https://public.cyber.mil/
6.5.9 Malicious software: When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DC3 in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.
6.5.10 Media preservation and protection: When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected IS and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
6.5.11 Access to additional information or equipment necessary for forensic analysis: Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
6.5.12 Cyber incident damage assessment activities: If DoD elects to conduct a damage assessment, the CO will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of DFARS clause 252.204-7012.
6.5.13 Apply other IS security measures when the contractor reasonably determines that IS security measures may be required to provide adequate security in a dynamic environment or to https://dibnet.dod.mil/portal/intranet/ https://manuals.health.mil/ https://public.cyber.mil/ accommodate special circumstances (e.g., HIPAA) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
6.5.14 The contractor shall maintain within the US or US territories all Government data that is not physically located on DoD premises, unless the contractor receives written notification from the CO to use another location, in accordance with DFARS 239.7602-2(a).
6.5.15. The contractor shall mitigate supply chain risk to the government by complying with
DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN
Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).
6.6 Risk Management Framework (RMF) for DoD IT: All IS, Platform Information
Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data must be accredited in accordance with DoDI
8510.01, Risk Management Framework (RMF) for DoD IT and comply with annual Federal
Information Security Modernization Act (FISMA) security control testing. IS and PIT systems must be categorized in accordance with Committee on National Security Systems Instruction
(CNSSI) 1253, implement a corresponding set of security controls from the NIST SP 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.
6.6.1 All systems subject to RMF must present evidence of authorization in the System Security
Plan, Security Assessment Report) a Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD RMF or equivalent DoD Component PIT system accreditation decision that is current within 3 years within 5 business days of CO request.
Evidence of FISMA compliance must be presented in the form of a POA&M. Systems must have and maintain an Authority to Operate (ATO) or Authority to Operate with Conditions
(ATO-C) by contract award.
6.6.2 The contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37 Risk Management Framework
(RMF) and DoDI 8510.01, Risk Management Framework (RMF).
6.6.3 The contractor shall configure the information system in accordance with Defense
Information Agency (DISA) Security Requirements Guides (SRGs) and security technical implementation guides (STIGs).
6.6.4 The contractor shall ensure that the information system conforms to the requirements of
DoDI 8551.01 “Ports, Protocols, and Services Management (PPSM)”.
6.6.5 The contractor shall ensure that the information system shall authenticate all entities as specified in DoDI 8520.03 “Identity Authentication for Information Systems” prior to granting access.
https://aplits.disa.mil/processAPList
6.6.6 The contractor shall Public Key (PK) enable the information system, implementing digital signature and encryption requirements specified in DoDI 8520.02, “Public Key Infrastructure
(PKI) and Public Key (PK) Enabling”.
6.6.7 The contractor will be responsible for compliance with the Joint Force Head Quarters –
Department of Defense Information Network issuances and IA Vulnerability Management
(IAVM) issuances by ensuring that the issuances are assessed, implemented and maintained throughout development and sustainment in accordance with specified timelines.
6.6.8 The contractor shall support reciprocity, by providing all directed information in NIST security documents to the government.
6.6.9 The contractor shall implement system level protection and detection capabilities that are consistent with their contract for NIST Security requirements that meet DoD and DHA
Cybersecurity Architectures.
6.6.10 Cyber Incident Reporting Requirement: The contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.
6.6.11 Information security continuous monitoring (ISCM): ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur. The Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all ARRT and PIT systems under this requirement in accordance with NIST SP
800-137.
6.6.12 The contractor shall mitigate supply chain risk to the government by complying with
DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN
Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).
6.7. Facility Related Control Systems: The DHA’s Facilities Enterprise (FE) Program
Management Office (PMO) establishes the processes for acquisition, installation and sustainment of FRCS in DHA Facilities. Requirements for cybersecurity of FRCS are developed and specified by the FHA FE FRCS PMO. The scope of PIT and Control Systems within the DoD includes building control systems such as Heating Ventilation and Air Conditioning, Utility
Management Control System, Electronic Security Systems, Fire Alarm Systems, and other assets. The application of IT cybersecurity strategies is migrating into PIT and Control Systems in response to emerging threats. The requirements within this scope apply to all versions of
Design-Build (DB); Design-Bid-Build (DBB); and facilities Sustainment, Restoration and
Modernization (SRM) projects as well as Initial Outfitting (IO) requirements activities.
6.7.1 Applicability: Contractors shall agree to the DHA Cybersecurity requirements as outlined for those project-specific FRCS Systems selected from Military Standard (MIL-STD) 1691, https://aplits.disa.mil/processAPList
(https://home.facilities.health.mil/military-standard-milstd-1691-equipment) and identified in the
DBB design process, D-B RFP development, SRM procurement documentation, or IO requirements unless an exception has been granted for a system by the Government prior to project award or procurement order issuance.
6.7.2 Cybersecurity Design: Failure to meet the design requirements may result in Government non-acceptance of submittals or termination of the procurement delivery order for cause, in accordance with project documentation and FAR 52.212-4(m).
6.7.2.1 The contractor shall comply with Unified Facilities Criteria (UFC) 4-010-06
Cybersecurity of Facility-Related Control Systems, UFGS 25-05-11 Cyber Security for Facility-
Related Control Systems, and referenced standards to develop a Cybersecurity program for their
FRCS products to be installed in DoD facilities. The UFC system is prescribed by MIL-STD
3007 and provides planning, design, construction, sustainment, restoration, and modernization criteria, and applies to the Military Departments, the Defense Agencies, and the DoD Field
Activities in accordance with Under Secretary of Defense Acquisition, Technologies, and
Logistics Memorandum dated 29 May 2002. UFC will be used for all DoD projects and work for other customers where appropriate.
6.7.2.2 Contractors shall comply with the National Information Assurance Partnership (NIAP)
Common Criteria Cybersecurity Evaluation and Validation Scheme (CCEVS) evaluation
(https://www.niap-ccevs.org) which is published on the NIAP-CCEVS Products Compliance
List. The NIAP-certified products have been assessed from a security perspective, helping to reduce the existence of potential vulnerabilities. Contractors are required to continually maintain their products, mitigate vulnerabilities, and distribute fixes to licensed users.
6.7.2.3 The contractor agrees to comply with security regulations and guidance listed in
Attachment 3, Cybersecurity Regulations and Guidance, and all RMF requirements. The contractor shall establish appropriate administrative and technical safeguards to ensure the confidentiality, integrity, and availability of Government data under their control.
6.7.3 Funding of FRCS System/Device Requirements: Projects requiring new or replacement
FRCS, or upgrade/extension of existing devices/systems, employ either SRM, DB, or DBB acquisition strategies. Many FRCS are categorized as Real Property and are project funded.
Others are categorized through Military Standard 1691 as Personal Property (PP) requiring IO funding. The IO effort should preferably, and where feasible, be embedded in the SRM, DBB or
DB contract through Contract Line Items or another vehicle. This will optimize coordination of project-funded infrastructure design/construction with FRCS device/system design, installation, testing and commissioning. Where the project delivery team (PDT) determines that acquisition of PP devices/systems will be through IO action entirely separate to the SRM, DBB, or DB contract, the same RMF-related activities are required. These activities shall be fully integrated into the project master schedule.
6.7.3.1 Pricing for Cybersecurity: If there are any additional costs associated with any element of the Cybersecurity lifecycle including a test/laboratory environment, the Contractor shall provide those costs as follows:
https://home.facilities.health.mil/military-standard-milstd-1691-equipment https://www.niap-ccevs.org/
6.7.3.1.1 All costs to assist the Government to achieve a new ATO and maintain it during the equipment’s warranty shall be included in the initial quote/offer price for SRM, and in the proposal for DB/DBB projects.
6.7.4 FRCS Cybersecurity Requirements: The contractor shall provide a POC responsible for the cybersecurity of the contractor device or system, throughout the lifecycle of the product. The contractor shall provide Subject Matter Experts to support all assessments of contracted products and materials.
6.7.4.1 The contractor shall establish and utilize a test/laboratory environment that duplicates all contractor fielded equipment/product that falls within the FRCS system/device authorization boundary. The contractor shall ensure that all fielded equipment/product is maintained during the construction/installation period of performance, and for fifteen (15) years post acceptance or as long as the contractor commercially supports the equipment/product, whichever is longer.
6.7.4.2 The contractor’s test/laboratory environment shall be used to submit to the Government, either through the RFP response, procurement order offer/quote, or construction submittal process, with all sections of the FRCS Risk Assessment Questionnaire and a Nessus vulnerability assessment report.
6.7.4.3 Contractors must provide a fully credentialed Nessus scan of the laboratory environment utilizing the DoD policy template with the submission. In addition, Nessus scans shall be provided within ten (10) days of a request from the Government POC to ensure a continuous monitoring program. Nessus scanner must be procured by the contractor, at their own cost, in order to comply with RMF requirements. The contractor shall request the latest versions through the CO.
6.7.4.4 Contractors shall notify the assigned Government POC FRCS analyst of any updates/changes to the system and attain Government approval from the Military Treatment
Facilities (MTFs) Change Control Board prior to installation. This should include operating system updates/patches; contractor application and database upgrades, updates, and patches;
other software/firmware updates/patches; and addition/removal of components.
6.7.4.5 The contractor shall comply with DoDI 8500.01 Cybersecurity, Enclosure 3, paragraph
9.b.(11), requiring all cybersecurity products and IA-enabled products that require use of the product’s cybersecurity capabilities will comply with the evaluation and validation requirements of Committee on National Security Systems Policy 11, National Policy Governing the
Acquisition of IA and IA-Enabled Information Technology Products, June 2013, as amended.
6.7.4.6 The contractor shall comply with DoDI 8510.01, Enclosure 6, para 2.f(6)(a), ensuring systems must be reassessed for reauthorization prior to the Authorization Termination Date.
Government Program Offices or appropriate facilities organizations plan for this activity. The results of an annual cybersecurity review or a negative change to the system or environment at any time (i.e., a change increasing the residual risk) may result in a need for reauthorization prior to the regular three-year reauthorization.
6.7.4.7 If the FRCS is Internet Protocol capable, the proposed system shall be Internet…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .