HT940624Q0017-0002 Solicitation PWS Update.pdf

PDF 793 KB Posted

Attached to
NMCP - Laboratory Document Management Control System Federal contract opportunity
Solicitation number
HT940624Q0017
Issued by
Defense Health Agency

About this file

This document is a Performance Work Statement for a non-personal services contract to provide Medialab Corporate Account Subscription Services. The key objectives include providing document control for 10 sites and 500 users, compliance and continuing education services, and other software solutions. The contract has a period of performance of one (1) Base Year. The work shall be performed at the contractor's facility. The contractor is required to have services available on federal holidays. The government will not provide any government furnished services, facilities, equipment, or materials. The contractor shall be responsible for obtaining and maintaining access to the PIEE/GFP Module application, meeting cybersecurity requirements, and ensuring all contractor personnel have the required training and certifications. The offer due date is 12:00 AM on 26 Apr 2024.

View the file

Other files for this federal contract opportunity

Other files attached to NMCP - Laboratory Document Management Control System, newest first.
File Type Posted
HT940624Q0017 .pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUM

(No Collect Calls)

HT940624Q0017 07-Feb-2024

b. TELEPHONE NUMBER

757-953-7570

8. OFFER DUE DATE/LOCAL TIME

12:00 AM 26 Apr 2024

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA – FAR (48 CFR) 53.212

(TYPE OR PRINT)

(SIGNATURE OF CONTRACTING OFFICER)

ADDENDA ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

23.

CODE 10. THIS ACQUISITION IS

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

TELEPHONE NO.

HT94069. ISSUED BY

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

LINDSAY GRAY

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

20.

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

0011990108-0001

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

. YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

% FOR:SET ASIDE:UNRESTRICTED ORX

SMALL BUSINESS

17a.CONTRACTOR/ CODE FACILITY

OFFEROR CODE

DHA CONTRACTING OFFICE TIDEWATER HT9406

7700 ARLINGTON BLVD

FALLS CHURCH VA 22042

18a. PAYMENT WILL BE MADE BY CODE

RATED ORDER UNDER

DPAS (15 CFR 700)

13a. THIS CONTRACT IS A

13b. RATING

CODE15. DELIVER TO CODE HT0242 16. ADMINISTERED BY

12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

14. METHOD OF SOLICITATION

RFQ IFB RFPX

NAV MED CNT PORTSMOUTH VA - MM

KRISTEN COTE

ATTN SUPPLY OFFICER BLDG 250

54 LEWIS MINOR STREET

PORTSMOUTH VA 23708-2297

TEL: FAX:

FAX:

TEL: SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

8(A)

HUBZONE SMALL

BUSINESS

SIZE STANDARD:

$24,000,000

NAICS:

611710

X

OFFER DATED

29. AWARD OF CONTRACT: REF.

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

EMAIL:

TEL:

31c. DATE SIGNED

SEE SCHEDULE

SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT

24.22.21.19.

WOMEN-OWNED SMALL BUSINESS (WOSB)

ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

PAGE 2 OF52

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 2/2012) BACK

Prescribed by GSA – FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

SEE SCHEDULE

20.

SCHEDULE OF SUPPLIES/ SERVICES

21.

QUANTITY UNIT

22. 23.

UNIT PRICE

24.

AMOUNT

19.

ITEM NO.

HT940624Q0017

Section SF 1449 - CONTINUATION SHEET

SOLICITATION/CONTRACT FORM

VENDOR TO COMPLETE THE FOLLOWING:

CAGE: _____________________

UEI: _____________________

Vendor POC: _____________________

Vendor Phone: ____________________

Vendor E-mail: ____________________

Notes to Vendor:

-At a minimum, the SF1449 must be completed to be considered for this opportunity. Additional reqirement in order to be considered for the opportunity; submit a brochure, spec sheet, or past performance information. Please respond to blocks 17a and 30a-c on page 1 and the vendor information on page 3, as well as provide your price(s) on the

Contract Line Item Number(s) (CLINs). Cursive font signatures will not be accepted.

-Offeror will provide all license agreements, End User License Agreements (EULA), Terms of Service (TOS), Federal Payment Plans, Extended Payment Plans, and other similar instruments or agreements, required to be signed, or agreed to, by the Government that the offeror or any of its suppliers or subcontractors (at any level) require. The Government may review to ensure terms and conditions are consistent with Federal law and otherwise satisfy the Government’s needs. Among terms and conditions that are not acceptable, which makes an offer ineligible for award, include: those such as Government indemnification of any party; choice of law or forum for disputes; mandatory arbitration; any language that would or might require the Government to renew or extend performance or usage of any item, product, or service; or any other feature that unduly puts a burden or restriction on the Government.

-Vendor to reference request for quotes number (RFQ#) HT940624Q0017-0003 on all inquiries.

NOTE TO VENDOR:

Because the Government’s automated procurement system does not provide for the contractor’s electronic signature, a fully executed copy of this bilateral award, signed by both parties, will be retained in the Government’s official contract file.

-For competitive service buys, type: Award will be made on the basis of the lowest evaluated price and the capability to meet the requirement detailed in the Performance Work Statement.

PROMPT PAYMENT

For Prompt Payment Act purposes, this contract is subject to the 7 calendar day constructive acceptance period.

Billing / Payment in arrears

For all questions, POC:

Ms. Lindsay A. Gray Contract Specialist E: Lindsay.a.gray.civ@health.mil mailto:Lindsay.a.gray.civ@health.mil

PERFORMANCE WORK STATEMENT

PART 1

1.0 GENERAL INFORMATION

1.1 This is a non-personal services contract to provide Medialab Corporate Account

Subscription Services.

1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Medialab Corporate Account as defined in this

Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.

1.3 Background: Medialab is a software system that the NMC Portsmouth VA has been using to assist in the document control of laboratory SOP’s. This allows the NMCP Laboratory to stay within College of American Pathologists (CAP) compliance.

1.4 Objectives: Basic services include:

• Medialab Corporate Account Document Control for (10 sites, 500 users) to upload procedures and to provide secure traceable documentation.

• Histology Compliance & CE for (10 users).

• Compass system for (10 sites, 500 users).

• Compliance and CE for (10 sites, 500 users).

• InspectionProof – (10 sites, 500 users).

• IQE: (10 sites).

• Exam Simulator MLS, MT, MLT (13 users).

• Personnel Documentation for (10 sites, 500 users)

• Included standard support.

1.5 Scope: The contractor shall accomplish all services that are listed in the Medialab software master agreement.

1.6 Period of Performance (PoP): The period of performance shall be for one (1) Base Year.

1.7 Administrative specifications

1.7.1 Place of performance: The work shall be performed at the contractor facility.

1.7.2 Recognized Federal holidays: The contractor is required to have services available on holidays.

New Year’s Day Labor Day

Martin Luther King Jr.’s Birthday Columbus Day

President’s Day Veteran’s Day

Memorial Day Thanksgiving Day

Juneteenth Day Christmas Day

Independence Day

1.7.3 Hours of operation: The contractor is responsible for conducting business Monday thru

Friday between the hours of 10:00 am – 6:00 pm except Federal holidays or when the

Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.

1.8 Contractor travel: None authorized.

1.9 Other Direct Costs (ODC): None.

1.10 Non-Disclosure Agreement (NDA): All contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA contractor NDA (DHA Form 49) prior to beginning work on the subject contract. The contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors. The NDA shall be executed not later than first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the contractor. The contractor shall maintain originally signed NDAs of individual employees and provide copy to the COR.

1.11 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.

1.12 Contractor Identification

1.12.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy

Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel.

Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.

1.12.2 Contractor personnel will be required to attend meetings or otherwise communicate with

Government and/or other contract representatives to meet the requirements of this order.

Contractor personnel shall make their contractor status known during introductions.

1.12.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.

1.13 Contractor Access to Health Affairs (HA)/DHA Network(s)

1.13.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's

Personnel Security Office for a background investigation.

1.13.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the

DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.

1.14 Personnel Security

1.14.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce

Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated

March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance

Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care

Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA

Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM

5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:

1.14.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security

Office can be reached at (703) 275-6038.

1.14.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).

1.14.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.

PART 2

2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE

PUBLICATIONS/INSTRUCTIONS

2.1 Definitions:

2.1.1 CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.

2.1.2 CONTRACTING OFFICER (KO). A person with authority to enter into, administer, and/or terminate contracts, and make related determinations and findings on behalf of the government. This is the only individual who can legally bind the government.

2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.

2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.

2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The

Government may either prepare the QASP or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the

Government’s plan.

2.2 Acronyms:

AIS Automated Information System

APL Approved Products List APL

AQL Acceptable Quality Level

ARRT Acquisition Requirements Roadmap Tool

ATO Authority to Operate

B2B Business-2-Business

CAC Common Access Card

CAP Cloud Access Point

CCEVS Common Criteria Cybersecurity Evaluation and Validation Scheme

CDI Covered Defense Information

CE Computer Environment

CDRL Contract Data Requirement List

CIO Chief Information Officer

CJCSM Chairman of the Joint Chiefs of Staff Manual

CMMC Cybersecurity Maturity Model Certification

CMR Contractor Manpower Reporting

CNSSI Committee on National Security Systems Instruction

CO Contracting Officer(s)

CONUS Continental United States (excludes Alaska and Hawaii)

COR Contracting Officer Representative

COTR Contracting Officer's Technical Representative

CSP Cloud Service Provider

CSSP Cyber Security Service Provider

CUI Controlled Unclassified Information

DAD-A Deputy Assistant Director for Acquisition

DC3 DoD Cyber Crime Center

DD Form 254 Department of Defense Contract Security Requirement List (if applicable)

DB Design-Build

DBB Design-Bid-Build

DFARS Defense Federal Acquisition Regulation Supplement

DHA Defense Health Agency

DISA Defense Information System Agency

DoD Department of Defense

DoDD Department of Defense Directive

DoDI Department of Defense Instruction

DSAs Data Sharing Agreements

DSAA Data Sharing Agreement Application

DMZ Demilitarized Zone

DoDM Department of Defense Manual

DPCLO DHA Privacy and Civil Liberties Office

DUA Data Use Agreement eMSM Enhanced Multi-Service Markets

EULA End User License Agreement

EVM Earned Value Management

FAR Federal Acquisition Regulation

FCI Federal contract information

FE Facilities Enterprise

FedRAMP Federal Risk Authorization and Management Program

FISMA Federal Information Security Modernization Act

FRCS Facility Related Control Systems

FSO Facilities Security Officer

HA Health Affairs

HIPAA Health Insurance Portability and Accountability Act

HCA Head of the Contracting Activity

HIT Health Information Technology

IGCE Independent Government Cost Estimate

IA Information Assurance

IO Initial Outfitting

I/O In/Out Processing Portal

IPv Internet Protocol Version

IS Information System

ISP Internet Service Provider

IT Information Technology

ISCM Information Security Continuous Monitoring

IV&V Independent Verification & Validation

MedCOI Medical Community of Interest

MHS Military Health System

MIL-STD Military Standard

MTFs Military Treatment Facilities

NCR National Capitol Region

NDA Non-Disclosure Agreement

NIAP National Information Assurance Partnership

NIST National Institute of Standards and Technology

OCONUS Outside Continental United States (includes Alaska and Hawaii)

ODC Other Direct Costs

OPM Office of Personal Management

OSD Office of the Secretary of Defense

P-ATO Personal Authorization to Operate

P&R Personnel and Readiness

PGI Procedures, Guidance and Information

PDT Project Delivery Team

PHI Protected Health Information

PII Personally Identifiable Information

PIT Platform Information Technology

PK Public Key

PKI Public Key Infrastructure

POA&M Plan of Action and Milestones

POC Point of Contact

PMO Program Management Office

PoP Period of Performance

PP Personal Property

PPSM Ports, Protocols, and Services Management

PRS Performance Requirements Summary

PSP Personnel Security Program

PWS Performance Work Statement

QA Quality Assurance

QAP Quality Assurance Program

QASP Quality Assurance Surveillance Plan

QC Quality Control

QCP Quality Control Plan

RFP Request for Proposal

RFQ Request for Quotation

RMF Risk Management Framework

SP Special Publication

SPRS Supplier Performance Risk System

SRM Sustainment, Restoration and Modernization

SRG Security Requirements Guides

STIG Security Technical Implementation Guides

TOS Terms of Service

US United States

UFC Unified Facilities Criteria

VPN Virtual Private Network

XML Extensible Markup Language

PART 3

3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:

3.1 Services: The Government:

☒ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Government Furnished Services required in support of this contract/task orders. These Services are described below: provide

3.2 Facilities: The Government:

☒ Will NOT provide Facilities in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Facilities in support of this contract/task orders. The Government provided

Facilities are described below:

3.3 Utilities: The Government:

☒ Will NOT provide Utilities in support of this contract/task order. As a result, this paragraph is

Not Applicable.

☐ WILL provide Utilities in support of this contract/task orders. The Government provided

Utilities are described below:

3.4 Equipment: The Government:

☒ Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Equipment in support of this contract/task orders. The Government provided

Equipment is described below:

3.4.1 Procurement Integrated Enterprise (PIEE), GFP Module Application

The contractor shall be responsible for obtaining and maintaining access, training and successful operation of the PIEE/GFP Module application for the entirety of the contract/task order PoP.

The PIEE GFP Module application is located at the following website: https://wawf.eb.mil/piee-landing/. Access to PIEE/GFP Module application training materials and in-depth information applicable to the contractor’s responsibilities regarding GFP can be found at the following website: https://dodprocurementtoolbox.com/.

Contracting Office Responsibilities:

The Contracting Office shall ensure close coordination and validation of the GFP items with the

COR and DHA Accountable Property Officer prior to uploading the GFP Attachment into the

PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Contracting Office’s responsibility to prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The CO and COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.

The contracting office will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the

Contracting Office, and requested within the PIEE/GFP Module system.

Contractor Responsibilities:

A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a timely, complete and accurate accounting of the GFP applicable to the contract/task order. Contractors are required to report the receipt of any GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their contract. Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.

The contractor shall report semi-annually 100% inventories, reconciliations, and final disposition of GFP provided by the government. Final invoices will not be paid pending GFP reconciliation.

Contractors shall be aware of and ensure compliance with applicable FAR Part 45, DFARS 245 and 252.245, Defense Pricing and Contracting Policies, Procurement Integrated Enterprise

Environment Standards, DHA Administrative Instruction 094 and DHA Guidance.

3.5 Materials: The Government:

https://wawf.eb.mil/piee-landing/ https://wawf.eb.mil/piee-landing/ https://dodprocurementtoolbox.com/

☒ Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ IS providing Materials in support of this contract/task orders. The Government-provided

Materials are described below:

PART 4

4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES

4.1 Services: The Contractor:

☐ Will NOT provide Contractor Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.

☒ WILL provide Contractor Furnished Services required in support of this contract/task orders.

These Services are described below: provide access to Media Lab subscription services via the internet (web based program).

4.2 General: The contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 5 of this PWS.

PART 6

6.0 INFORMATION TECHNOLOGY & SECURITY

6.1 All work under this contract is unclassified.

6.2 The TIER 2 level and position sensitivity designation for positions under this contract is:

(Requirement must be checked in order to be a requirement for this PWS.)

6.2.1 TIER II: Non-critical sensitive position .

6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements:

6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes

PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office

(DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into

DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect

MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data.

After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.

6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.

6.4 Training

6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements:

6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity

Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoD 8570.01-M. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.

6.4.1.2 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoD

8570.01–M, IA Workforce Improvement Program. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-2001, including:

6.4.1.2.1 DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01–M; and

6.4.1.2.2 Appropriate operating system certification for IA technical positions as required by

DoD 8570.01–M.

6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.

6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.

6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.

6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS:

6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication (SP)

800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171), in accordance with DFARS clause 252.204-7012.

6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800-

171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment

Methodology requirement flows down to subcontractors.

6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier

Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/)

6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD

Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order.

See Attachment 2, Deliverable Schedule Table.

6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.

https://www.sprs.csd.disa.mil/

6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.

6.5.4 Cybersecurity Maturity Model Certification (CMMC). The CMMC (DFARS clause

252.204-7021) builds upon the NIST SP 800-171 DoD Assessment Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract information (FCI) and DoD

Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk.

The CMMC requirement flows down to subcontractors.

6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization

(3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.

6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or

COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.

6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.

6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management

Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.

6.5.8 Cyber Incident Reporting Requirement

6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the https://www.cmmcab.org/ https://www.fedramp.gov/ contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:

6.5.8.1.1 Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other IS on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and

6.5.8.1.2 In accordance with DFARS clause 252.204-7012, rapidly report (within 72 hours) cyber incidents involving DoD CUI to DoD Cyber Crime Center (DC3) via https://dibnet.dod.mil/portal/intranet/. In the event of a cybersecurity incident involving a CUI-

Specific breach (i.e., PII/PHI), the contractor, in addition to reporting to the DC3, shall follow the incident reporting guidance prescribed in the TRICARE Operations Manual, Chapter 1, Section 5, “Compliance with Federal Statutes” at https://manuals.health.mil/

6.5.8.2 Cyber incident report: The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements as prescribed at the https://dibnet.dod.mil/portal/intranet/.

6.5.8.3 Medium assurance certificate requirement: In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a

DoD-approved medium assurance certificate, see https://public.cyber.mil/

6.5.9 Malicious software: When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DC3 in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.

6.5.10 Media preservation and protection: When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected IS and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

6.5.11 Access to additional information or equipment necessary for forensic analysis: Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.

6.5.12 Cyber incident damage assessment activities: If DoD elects to conduct a damage assessment, the CO will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of DFARS clause 252.204-7012.

6.5.13 Apply other IS security measures when the contractor reasonably determines that IS security measures may be required to provide adequate security in a dynamic environment or to https://dibnet.dod.mil/portal/intranet/ https://manuals.health.mil/ https://public.cyber.mil/ accommodate special circumstances (e.g., HIPAA) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.

6.5.14 The contractor shall maintain within the US or US territories all Government data that is not physically located on DoD premises, unless the contractor receives written notification from the CO to use another location, in accordance with DFARS 239.7602-2(a).

6.5.15. The contractor shall mitigate supply chain risk to the government by complying with

DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN

Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).

6.6 Risk Management Framework (RMF) for DoD IT: All IS, Platform Information

Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data must be accredited in accordance with DoDI

8510.01, Risk Management Framework (RMF) for DoD IT and comply with annual Federal

Information Security Modernization Act (FISMA) security control testing. IS and PIT systems must be categorized in accordance with Committee on National Security Systems Instruction

(CNSSI) 1253, implement a corresponding set of security controls from the NIST SP 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.

6.6.1 All systems subject to RMF must present evidence of authorization in the System Security

Plan, Security Assessment Report) a Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD RMF or equivalent DoD Component PIT system accreditation decision that is current within 3 years within 5 business days of CO request.

Evidence of FISMA compliance must be presented in the form of a POA&M. Systems must have and maintain an Authority to Operate (ATO) or Authority to Operate with Conditions

(ATO-C) by contract award.

6.6.2 The contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37 Risk Management Framework

(RMF) and DoDI 8510.01, Risk Management Framework (RMF).

6.6.3 The contractor shall configure the information system in accordance with Defense

Information Agency (DISA) Security Requirements Guides (SRGs) and security technical implementation guides (STIGs).

6.6.4 The contractor shall ensure that the information system conforms to the requirements of

DoDI 8551.01 “Ports, Protocols, and Services Management (PPSM)”.

6.6.5 The contractor shall ensure that the information system shall authenticate all entities as specified in DoDI 8520.03 “Identity Authentication for Information Systems” prior to granting access.

https://aplits.disa.mil/processAPList

6.6.6 The contractor shall Public Key (PK) enable the information system, implementing digital signature and encryption requirements specified in DoDI 8520.02, “Public Key Infrastructure

(PKI) and Public Key (PK) Enabling”.

6.6.7 The contractor will be responsible for compliance with the Joint Force Head Quarters –

Department of Defense Information Network issuances and IA Vulnerability Management

(IAVM) issuances by ensuring that the issuances are assessed, implemented and maintained throughout development and sustainment in accordance with specified timelines.

6.6.8 The contractor shall support reciprocity, by providing all directed information in NIST security documents to the government.

6.6.9 The contractor shall implement system level protection and detection capabilities that are consistent with their contract for NIST Security requirements that meet DoD and DHA

Cybersecurity Architectures.

6.6.10 Cyber Incident Reporting Requirement: The contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.

6.6.11 Information security continuous monitoring (ISCM): ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur. The Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all ARRT and PIT systems under this requirement in accordance with NIST SP

800-137.

6.6.12 The contractor shall mitigate supply chain risk to the government by complying with

DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN

Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).

6.7. Facility Related Control Systems: The DHA’s Facilities Enterprise (FE) Program

Management Office (PMO) establishes the processes for acquisition, installation and sustainment of FRCS in DHA Facilities. Requirements for cybersecurity of FRCS are developed and specified by the FHA FE FRCS PMO. The scope of PIT and Control Systems within the DoD includes building control systems such as Heating Ventilation and Air Conditioning, Utility

Management Control System, Electronic Security Systems, Fire Alarm Systems, and other assets. The application of IT cybersecurity strategies is migrating into PIT and Control Systems in response to emerging threats. The requirements within this scope apply to all versions of

Design-Build (DB); Design-Bid-Build (DBB); and facilities Sustainment, Restoration and

Modernization (SRM) projects as well as Initial Outfitting (IO) requirements activities.

6.7.1 Applicability: Contractors shall agree to the DHA Cybersecurity requirements as outlined for those project-specific FRCS Systems selected from Military Standard (MIL-STD) 1691, https://aplits.disa.mil/processAPList

(https://home.facilities.health.mil/military-standard-milstd-1691-equipment) and identified in the

DBB design process, D-B RFP development, SRM procurement documentation, or IO requirements unless an exception has been granted for a system by the Government prior to project award or procurement order issuance.

6.7.2 Cybersecurity Design: Failure to meet the design requirements may result in Government non-acceptance of submittals or termination of the procurement delivery order for cause, in accordance with project documentation and FAR 52.212-4(m).

6.7.2.1 The contractor shall comply with Unified Facilities Criteria (UFC) 4-010-06

Cybersecurity of Facility-Related Control Systems, UFGS 25-05-11 Cyber Security for Facility-

Related Control Systems, and referenced standards to develop a Cybersecurity program for their

FRCS products to be installed in DoD facilities. The UFC system is prescribed by MIL-STD

3007 and provides planning, design, construction, sustainment, restoration, and modernization criteria, and applies to the Military Departments, the Defense Agencies, and the DoD Field

Activities in accordance with Under Secretary of Defense Acquisition, Technologies, and

Logistics Memorandum dated 29 May 2002. UFC will be used for all DoD projects and work for other customers where appropriate.

6.7.2.2 Contractors shall comply with the National Information Assurance Partnership (NIAP)

Common Criteria Cybersecurity Evaluation and Validation Scheme (CCEVS) evaluation

(https://www.niap-ccevs.org) which is published on the NIAP-CCEVS Products Compliance

List. The NIAP-certified products have been assessed from a security perspective, helping to reduce the existence of potential vulnerabilities. Contractors are required to continually maintain their products, mitigate vulnerabilities, and distribute fixes to licensed users.

6.7.2.3 The contractor agrees to comply with security regulations and guidance listed in

Attachment 3, Cybersecurity Regulations and Guidance, and all RMF requirements. The contractor shall establish appropriate administrative and technical safeguards to ensure the confidentiality, integrity, and availability of Government data under their control.

6.7.3 Funding of FRCS System/Device Requirements: Projects requiring new or replacement

FRCS, or upgrade/extension of existing devices/systems, employ either SRM, DB, or DBB acquisition strategies. Many FRCS are categorized as Real Property and are project funded.

Others are categorized through Military Standard 1691 as Personal Property (PP) requiring IO funding. The IO effort should preferably, and where feasible, be embedded in the SRM, DBB or

DB contract through Contract Line Items or another vehicle. This will optimize coordination of project-funded infrastructure design/construction with FRCS device/system design, installation, testing and commissioning. Where the project delivery team (PDT) determines that acquisition of PP devices/systems will be through IO action entirely separate to the SRM, DBB, or DB contract, the same RMF-related activities are required. These activities shall be fully integrated into the project master schedule.

6.7.3.1 Pricing for Cybersecurity: If there are any additional costs associated with any element of the Cybersecurity lifecycle including a test/laboratory environment, the Contractor shall provide those costs as follows:

https://home.facilities.health.mil/military-standard-milstd-1691-equipment https://www.niap-ccevs.org/

6.7.3.1.1 All costs to assist the Government to achieve a new ATO and maintain it during the equipment’s warranty shall be included in the initial quote/offer price for SRM, and in the proposal for DB/DBB projects.

6.7.4 FRCS Cybersecurity Requirements: The contractor shall provide a POC responsible for the cybersecurity of the contractor device or system, throughout the lifecycle of the product. The contractor shall provide Subject Matter Experts to support all assessments of contracted products and materials.

6.7.4.1 The contractor shall establish and utilize a test/laboratory environment that duplicates all contractor fielded equipment/product that falls within the FRCS system/device authorization boundary. The contractor shall ensure that all fielded equipment/product is maintained during the construction/installation period of performance, and for fifteen (15) years post acceptance or as long as the contractor commercially supports the equipment/product, whichever is longer.

6.7.4.2 The contractor’s test/laboratory environment shall be used to submit to the Government, either through the RFP response, procurement order offer/quote, or construction submittal process, with all sections of the FRCS Risk Assessment Questionnaire and a Nessus vulnerability assessment report.

6.7.4.3 Contractors must provide a fully credentialed Nessus scan of the laboratory environment utilizing the DoD policy template with the submission. In addition, Nessus scans shall be provided within ten (10) days of a request from the Government POC to ensure a continuous monitoring program. Nessus scanner must be procured by the contractor, at their own cost, in order to comply with RMF requirements. The contractor shall request the latest versions through the CO.

6.7.4.4 Contractors shall notify the assigned Government POC FRCS analyst of any updates/changes to the system and attain Government approval from the Military Treatment

Facilities (MTFs) Change Control Board prior to installation. This should include operating system updates/patches; contractor application and database upgrades, updates, and patches;

other software/firmware updates/patches; and addition/removal of components.

6.7.4.5 The contractor shall comply with DoDI 8500.01 Cybersecurity, Enclosure 3, paragraph

9.b.(11), requiring all cybersecurity products and IA-enabled products that require use of the product’s cybersecurity capabilities will comply with the evaluation and validation requirements of Committee on National Security Systems Policy 11, National Policy Governing the

Acquisition of IA and IA-Enabled Information Technology Products, June 2013, as amended.

6.7.4.6 The contractor shall comply with DoDI 8510.01, Enclosure 6, para 2.f(6)(a), ensuring systems must be reassessed for reauthorization prior to the Authorization Termination Date.

Government Program Offices or appropriate facilities organizations plan for this activity. The results of an annual cybersecurity review or a negative change to the system or environment at any time (i.e., a change increasing the residual risk) may result in a need for reauthorization prior to the regular three-year reauthorization.

6.7.4.7 If the FRCS is Internet Protocol capable, the proposed system shall be Internet…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .