Dot_Gov_JOFOC_Final.pdf
PDF 579 KB Posted
- Attached to
- DotGov Federal contract opportunity
- Solicitation number
- ID11160005
About this file
DotGov JOFOC
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
JUSTIFICATION FOR OTHER THAN FULL AND OPEN COMPETITION (JOFOC)
1. Identification of the agency and contracting activity.
Contracting Activity: The U.S. General Services Administration, Federal Acquisition Service, Assisted Acquisition Service (GSA/FAS/AAS)
Customer Agency: GSA’s Office of Government-wide Policy (OGP), Office of Information, Integrity, and Access (OIIA).
2. The nature and/or description of the action being approved
The government intends to negotiate and award, on a sole source basis, a Firm Fixed Price (FFP) bridge contract to VeriSign Inc. to acquire registry and registrar services to continue support of OIIA’s responsibilities for managing the .gov generic Top Level Domain (.gov gTLD). The purpose of the bridge contract is to continue performance while the government prepares to release a competitive solicitation. Verisign is the current vendor for the .gov gTLD registry and registrar functions.
These services support the operations, management, and maintenance of the .gov gTLD registry and registrar function, in compliance with 41 CFR 102-173. The scope of the program extends to all U.S. Government entities - federal, state, and local governments, and native sovereign nations.
3. A description of the supplies or services required to meet the agency’s needs.
Broadly, the scope and description of these services are as follows: online domain name registration, billing, help desk functions, reporting, and daily operations of the root domain name servers for the .gov domain. Services also include securing and protecting the root domain name servers for the .gov domain, which contain security-sensitive information (the database of domain names and IP addresses). The .gov registry and registrar is a major information system and categorized at a Federal Information Processing Standard ( FIPS) 199 High Impact, and thorough security test & evaluation (or security assessments) will be required as part of the authorization process.
The estimated value of the bridge is $2.1M USD for 12 months.
4. The statutory authority permitting other than full and open competition.
The statutory authority permitting other than full and open competition is 41 U.S.C. § 3304(a)(1) as implemented by the Federal Acquisition Regulation (FAR) 6.302-1 “Only One Responsible Source and No Other Supplies or Services Will Satisfy Agency Requirements.”
5. A statement demonstrating the unique qualifications of the proposed contractor or the nature of the action requiring the use of the authority.
Verisign is uniquely positioned in that it currently has all required security and technical controls in place to continue to conduct all required tasks. No other vendor has a current Authority to Operate (ATO) for this requirement.
This bridge contract is required because any new contractor must provide evidence of their capability to obtain an Authority to Operate (ATO) for this requirement by the needed start date.
The ATO process is controlled by the GSA Office of the Chief Information Officer (OCIO) and is a lengthy process, normally lasting 4-6 months. The contractor must document and demonstrate that the registry, registrar, and related systems adhere to HIGH security controls as identified by the Federal Information Security Management Act (FISMA) and any successor acts. The contractor will maintain all documentation supporting FISMA compliance and ensure that documentation and system controls remain current throughout the system life-cycle, in accordance with GSA OCIO-IT Security-09-48, “Security Language for IT Acquisition Efforts.”
The .gov registry and registrar is a major information system and categorized at a FIPS 199 High Impact, and thorough security test & evaluation (or security assessments) will be required as part of the authorization process.
Registry and registrar services are available in the commercial marketplace. However, these services, as required by GSA, must conform to the government’s policy and security requirements and as such, require some physical and technical modification from what is customarily available (e.g. Federal Information Security Management Act (FISMA) and Federal Information Processing Standard Publication 199, Standards for Security Categorization of Federal Information and Information Systems (FIPS 199 High) conformance). The process of obtaining an ATO is thorough and rigorous, and having an official ATO means that services can be provided uninterrupted and without degradation. Only Verisign presently possesses an ATO for operating the .gov gTLD and is currently operating a system that meets the physical and security requirements under FISMA and National Institute of Standards and Technology (NIST) controls, therefore, they are the only vendor that is capable of executing the mission critical .gov requirement at this time.
6. A description of efforts made to ensure that offers are solicited from as many potential sources as is practicable, including whether a notice was or will be publicized as required by Subpart 5.2 and, if not, which exception under 5.202 applies.
A notice of intent to sole source will be posted on FBO 15 days prior to issuance of the solicitation. This JOFOC will be posted within 14 days after award.
7. A determination by the Contracting Officer that the anticipated cost to the Government will be fair and reasonable.
The Contracting Officer will determine that the anticipated price(s) will be fair and reasonable based on historical pricing and comparison of prices obtained through market research of the cost to deliver these services.
8. A description of the market research conducted and the results.
GSA issued a request for information on March 10, 2015 with a closing date of March 23, 2015. An RFI Industry Day open forum session was held on March 31, 2015 with the opportunity for vendors to engage with the DotGov leadership team.
There were seven (7) written responses to the RFI and five respondents provided answers indicating they could potentially meet some or all of the requirements.
In addition to the vendors who provided responses to the RFI and participated in the Industry Day, GSA conducted research on what vendors may potentially be considered as viable offerors. Given the criticality of the service, and in context of the current and continuing cyber threat, GSA believes there is a limited scope of viable offerors. These vendors fall into two general categories: 1) major telecommunications providers and 2) experienced, US-based gTLD or county-code (cc) TLD registry providers. A representative list of these vendors is provided below. This list, while not exhaustive, is representative of the providers that fall into one or both of these categories:
Verisign Neustar Verizon Century Link
AT&T
A loss of continuity of .gov gTLD services for any amount of time is not an acceptable risk; as such, the U.S. Government must ensure there is not the potential for a gap in contracted services for the .gov gTLD. Given the imperative to mitigate against any potential risk to a gap in .gov gTLD services capability, Verisign is determined to be the sole source who can provide continuity of .gov gTLD services under a “bridge” contract, which would follow after the end of the current contract in March 2016.
9. Any other facts supporting the use of other than full and open competition.
Issues Causing Delay in the Acquisition Planning Process
Beyond the activities described above, several other issues led to unforeseen and significant delays in the acquisition plan for a new .gov gTLD services contract.
a. The fundamental structure of the contract was overhauled, as responses to the RFI, Industry Day, convenings with Federal partners (such as the Office of Management and Budget and the Department of Homeland Security), and OGP market research found that soliciting .gov gTLD services through a no-cost contract (as the current contract is structured) would be insufficient for two main reasons:
(1) A no-cost contract could lead to the awarding of the .gov gTLD services contract to a vendor who is unable to meet U.S. Government security needs, and
(2) A no-cost contract would be a large financial disincentive for any vendor, leading to an insufficient vendor applicant pool.
b. Updates to FISMA (in accordance with guidance and policy updates required under S.2521 - Federal Information Security Modernization Act of 2014) and recent revisions to NIST security controls (in particular 800.53 rev 4) caused several of the technical and security requirements of the DotGov contract to change substantially, further delaying the finalization of a new solicitation.
10. A listing of any sources that expressed a written interest in the acquisition.
There were seven vendors that showed interest and provided written responses to the RFI.
Advanced Internet Technologies Dynamic Network Services Verisign NCC Group Infoblox, Inc.
Cyber Data Corporation Yadin Corporation
The only vendor that has a current ATO for this requirement is Verisign.
11. A statement of any actions the agency may take to remove or overcome any barriers to competition, if subsequent acquisitions are anticipated.
This one year bridge will enable OIIA to effectively, and in a timely manner, solicit full and open competition for proposals for the management of the .gov gTLD in subsequent years. GSA is currently conducting work to solicit this requirement for full and open competition.
Certification
The information contained in this justification for other than full and open competition is certified accurate and complete to the best of my knowledge and belief.
Concur:
Contracting Officer:
I certify that this justification is accurate and complete to the best of my knowledge and belief.
Signature
Review:
Raina Baker
One Level Above CO
Concur:
Lakita Ayers
Deputy Division Director
Approval:
Marilyn Jackson
Competition Advocate
| 2015-11-18T09:02:08-0500 | |
| FREDERICK THOMAS |
| 2015-11-18T09:02:53-0500 | |
| FREDERICK THOMAS |
| 2015-11-18T09:07:37-0500 | |
| RAINA BAKER |
| 2015-11-18T09:24:26-0500 | |
| LAKITA AYERS |
| 2015-11-18T10:50:50-0500 | |
| MARILYN JACKSON |
File details come from the government source that posted it. Updated .