II_01 RFQ 205AE9-26-Q-00018 (2).pdf

PDF 910 KB Posted

Attached to
East Lansing Data Cabling Federal contract opportunity
Solicitation number
205AE9-26-Q-00018
Issued by
Department of the Treasury Internal Revenue Service

About this file

This is a Request for Quotation (RFQ) for a small business set-aside contract issued by the Internal Revenue Service (IRS) for network infrastructure modernization at the East Lansing, Michigan site. The solicitation seeks a contractor to provide comprehensive data cabling services, including cable plant planning, component procurement, installation design, cost estimation, project scheduling, structured cabling system installation, network rack setup, fiber infrastructure implementation, and detailed testing. The project involves 60 cable drops, with specific requirements for 55 data drops, 5 future access points, and 1 Q-Matic drop, along with termination and labeling of network infrastructure.

The RFQ (Solicitation Number 205AE9-26-Q-00018) is a Firm Fixed Price (FFP) purchase order with a performance period of 4-8 weeks. Quotes are due by December 12, 2025, at 1:00 PM EST, with submission directly to the Contracting Officer. The solicitation requires a technical proposal demonstrating cable plant planning, installation approach, and past performance, along with a detailed pricing proposal. The project emphasizes compliance with specific technical standards, including ANSI/TIA cabling specifications, grounding requirements, and IRS-specific clearance and cable management guidelines. The total project scope includes material procurement, installation, testing, and documentation of the network infrastructure upgrade.

View the file

Other files for this federal contract opportunity

Other files attached to East Lansing Data Cabling, newest first.
File Type Posted
205AE9-26-Q-00018-0002.pdf PDF
Attachment 3 Wage Determination 2015 4857.docx DOCX document
205AE9-26-Q-00018-0001.pdf PDF
Attachment 2 Monthly Workforce Report PostAward Contract Deliverable.xlsx XLSX spreadsheet
MI2101 Floor Plan.pdf PDF
MI2101 Floor Plan (2).pdf PDF
Attachment 1 Initial Staffing Plan Proposal Deliverable.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

REQUEST FOR QUOTATION

(THIS IS NOT AN ORDER)

THIS RFQ IS IS NOT A SMALL BUSINESS SET-ASIDE

15. DATE OF QUOTATION

16. SIGNER

a. NAME (Type or print)

c. TITLE (Type or print)

b. TELEPHONE

AREA CODE

NUMBER

STANDARD FORM 18 (REV. 6-95)

Prescribed by GSA-FAR (48 CFR) 53.215-1(a)

AUTHORIZED FOR LOCAL REPRODUCTION

Previous edition not usable

8. TO:

b. COMPANYa. NAME

c. STREET ADDRESS

d. CITY e. STATE f. ZIP CODE

9. DESTINATION

a. NAME OF CONSIGNEE

b. STREET ADDRESS

c. CITY

d. STATE e. ZIP CODE

7. DELIVERY

FOB DESTINATION

OTHER

(See Schedule)

10. PLEASE FURNISH QUOTATIONS TO THE

ISSUING OFFICE IN BLOCK 5a ON OR BEFORE CLOSE OF BUSINESS (Date)

IMPORTANT: This is a request for information and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it to the address in Block 5a. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or service. Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this Request for Quotation must be completed by the quoter.

11. SCHEDULE (Include applicable Federal, State and local taxes)

ITEM NO.

(a)

SUPPLIES/ SERVICES

(b)

QUANTITY

(c)

UNIT

(d)

UNIT PRICE

(e)

AMOUNT

(f)

12. DISCOUNT FOR PROMPT PAYMENT

a. 10 CALENDAR DAYS (%) b. 20 CALENDAR DAYS (%) c. 30 CALENDAR DAYS (%) d. CALENDAR DAYS

NUMBER PERCENTAGE

NOTE: Additional provisions and representations are are not attached.

13. NAME AND ADDRESS OF QUOTER

a. NAME OF QUOTER

b. STREET ADDRESS

c. COUNTY

d. CITY e. STATE f. ZIP CODE

14. SIGNATURE OF PERSON AUTHORIZED TO

SIGN QUOTATION

PAGE OF PAGES

1. REQUEST NO. 2. DATE ISSUED 3. REQUISITION/PURCHASE REQUEST NO. 4. CERT. FOR NAT. DEF.

UNDER BDSA REG. 2

AND/OR DMS REG. 1

RATING

5a. ISSUED BY 6. DELIVER BY (Date)

5b. FOR INFORMATION CALL (NO COLLECT CALLS)

NAME TELEPHONE NUMBER

AREA CODE NUMBER

12/8/25

JILLIAN STASKIN

12/15/25 12PM

609 625-7829

See Attached Schedule(s)

5000216045

Office of Procurement Operations-Office of Procurement Operations 5218 Atlantic Avenue Mays Landing, NJ 08330-2003 Attn: Jillian Staskin Tel: Email: jillian.n.staskin@irs.gov

205AE9-26-Q-00018

Section B. SERVICE PRICE

B.1 TYPE OF CONTRACT

It is the intent of the Internal Revenue Service (IRS) to award one Firm Fixed Price (FFP) Purchase Order.

Award will be made after evaluation of quotes based on the criteria as stated in Section L and Section M of this RFQ.

B.2 CLIN STRUCTURE

CLIN DESCRIPTION TYPE QTY Unit Price TOTAL AMOUNT 0001 East Lansing -IRA Network

Modernization IRA Network Modernization Project for East Lansing MI

FFP 6 $ $

Total Task Order Value

B.3 CONTRACTOR’S QUOTE

Performance of this Order by the Contractor shall be conducted and performed in accordance with the detailed obligations to which the Contractor committed itself in the submitted Technical and Price Quote in response to the solicitation. All proposed rates and labor categories submitted in the Quote are bound by the award and shall not be deviated unless approved in writing by the Contracting Officer. All rates and labor categories performed by the Contractor shall be at the lowest achievable labor category as to not jeopardize quality of the services performed.

B.4. PERIOD OF PERFORMANCE

The period of performance is expected to be 4-8 weeks after date of award. Hard dates will be defined in the task order award.

Section C. DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK

BACKGROUND

The Michigan MI2101 modernization project is a critical initiative supporting the Internal Revenue Service’s (IRS) efforts to enhance telecommunications infrastructure at the Michigan MI2101 Post of Duty. This project aims to improve operational efficiency, scalability, and compliance with federal standards.

Work shall be completed during business hours of 8:00 AM to 5:00 PM, Monday – Friday, per the General Contractor’s construction schedule. Noisy work shall be done before or after standard business hours. Will keep the area clean and clear of debris of each workday and ensure all excess materials and trash are removed.

SCOPE OF WORK

The contractor shall provide the following services:

1. Comprehensive cable plant planning and design review.

2. Selection and procurement of components.

3. Development of installation designs and specifications.

4. Accurate cost estimates for all project phases.

5. Phased project scheduling to ensure minimal disruption.

6. Installation of structured cabling systems, network racks, and fiber infrastructure.

7. Detailed testing and documentation of all installed systems.

Key Deliverables:

- 60 cable drops:

- 55 data drops.

- 5 future access points (APs).

- 1 Q-Matic drop.

- Termination of cables in the (Main Distribution Frame) MDF, and wall/furniture interface inserts (WSIs).

- Installation and labeling of all network racks and fiber infrastructure.

MATERIALS Quantity

General Cat 6A 10,000 FT

10’ CAT6 PATCH CORD BLUE 64

CAT32+PCD1B J-Hooks 128 Mod Furniture Cover Plate 26 Furniture Data Conn 5

CAT 6A PATCH CORD 34

Vertical Cable Management 6” 3

VERT CENTER BRACKET KIT 1

PANDUIT WMPSE HORZ CABLE 10

MGMT1

Panduit Cat 6A Patch Panel 2 CAT 6 Term 96 16’ 2 Post Rack ALUM 2 Ground Bar 1 Anchors (not bolts) 24 Panduit mini-conn Jack 6A 51

Items

DESIGN/INSTALLATION PLAN

The contractor shall develop a detailed design and installation plan for Government approval. This plan must include:

- Floor plans for (Main Distribution Frame) MDF, (Independent Distribution Frame) IDF, and associated telecommunications areas.

- Cable labeling and testing schemes in accordance with ANSI/TIA/EIA-606-B standards.

- Structured rack layouts showing patch panels, switches, and power distribution units (PDUs).

Change Control:

Any deviations from the approved design must be documented, estimated, and submitted for written approval by the Government. Verbal approvals for urgent changes must be followed by written confirmation.

SPECIFICATIONS

The installation must comply with the following standards and regulations:

- ANSI/TIA/EIA-568-C.2: Telecommunications Cabling Standard.

- ANSI/TIA-942: Data Center Infrastructure Standards.

- ANSI/TIA-607-C: Bonding and Grounding Requirements.

- ANSI/BICSI 002: Best Practices for Data Center Design.

IRS Compliance Requirements:

- Clearance Standards:

- Front Clearance: 36 inches.

- Rear Clearance: 24 inches.

- Side Clearance: 24 inches (if applicable).

- Grounding: Use dedicated grounding bars compliant with ANSI/TIA-607-C.

- Cable Management: Use J-hooks and secure cables with Velcro straps to prevent stress and maintain flexibility.

- Fire Safety: Implement fire-stopping measures with non-mechanical materials approved by local fire authorities.

NETWORK RACK MODERNIZATION

The vendor shall:

- Remove existing racks obstructed by HVAC systems or sprinklers.

- Install new network racks with the following configuration:

- Top Layer: Patch panels for structured cabling terminations.

- Middle Layer: Network switches (e.g., Cisco Catalyst).

- Bottom Layer: Power distribution units (PDUs).

- Deploy vertical and horizontal cable management systems for optimal routing.

- Utilize labeled, color-coded short patch cables (1-3 feet) to maintain a neat and professional appearance.

- Implement IRS-approved labeling schemes for cables, ports, and rack units.

TESTING

Testing must adhere to EIA/TIA-568-C standards, including:

- Continuity and wire map validation.

- Near-End Crosstalk (NEXT) and attenuation measurements.

- Fiber testing for power loss and continuity in compliance with ANSI/TIA/EIA-526-14A.

A comprehensive test report shall document results, including any corrections for failed tests.

Quality Assurance Surveillance Plan (QASP) The Government will use this Quality Assurance Surveillance Plan (QASP) to evaluate the Contractor’s performance in removing and disposing of existing telecommunications and network cabling. The objective of this QASP is to ensure all work is performed in accordance with the Statement of Work (SOW), applicable codes, and environmental standards. The Contracting Officer’s Representative (COR) will conduct inspections during and after removal activities using random sampling and 100% inspection methods for safety and regulatory compliance. Key performance metrics include (1) complete removal of all designated cabling and components, (2) prevention of damage to active systems or building structures,

(3) compliance with safety and environmental disposal requirements, and (4) timely completion of work within the approved schedule. Any identified deficiencies will be documented in a Corrective Action Report (CAR) and monitored until resolved. Unsatisfactory performance may result in withholding of payment or other contractual remedies as determined by the Contracting Officer.

Remove and Dispose of Existing Cabling

The Contractor shall remove all existing telecommunications and network cabling, including associated conduit, raceways, and termination hardware, as identified in the project drawings or directed by the Government. All removal activities shall be performed in a manner that prevents damage to active infrastructure, building systems, and structural elements. The Contractor shall properly coil, label, and transport removed materials to an approved staging area for inspection by the Contracting Officer’s Representative (COR) prior to disposal. All waste material, including copper, fiber, and related components, shall be disposed of or recycled in compliance with applicable federal, state, and local environmental regulations. The work area shall be cleaned and restored to a safe and orderly condition upon completion.

Delegated Buildings - Wall, Floor or Ceiling Permeation:

In IRS delegated buildings, the Building Delegation section must be contacted for approval prior to the start of the project to ensure there is no asbestos containing material present in the area prior to the start of work. The Building Delegation Manager will provide a written statement about status of asbestos containing or other hazardous materials at the designated work site. The project will not proceed until hazard(s) have been eliminated from the area. Contract personnel must have received Asbestos Awareness training by the employer prior to arriving on the worksite regardless of asbestos clearance. An email from the property manager is required to EHS Review Team with a statement that the project area(s) is/are free from any known hazards.

General Safety:

It is the contractor’s responsibility to know and understand which regulations and standards promulgated by the Occupational Health and Safety Administration applies to them and they’re sub-contractors, as well as any local or state health and safety regulations. Sub-contractors who have less than 10 employees are not exempt from OSHA regulations and standards while working on a federal contract.

Working at Heights (over 4 feet off ground) If ladders are to be used to reach ceilings to pull wires contractors and subcontractors shall be trained in ladder safety per 29 CFR 1910.23 and use the appropriate non-conductive ladders for any work involving electrical devices. The contractor shall not leave a ladder to climb onto any structures, in the ceiling spaces or anywhere else, that are not meant for human occupancy. The contractor shall ensure they provide the necessary equipment for their employees and subcontractors to work at heights safely and in compliance with 29 CFR 1910.28 and 1910 Subpart F.

Green Purchasing and Bio-Based Preferred When acquiring goods and services, the contractor shall acquire green products including bio-based, environmentally preferable, energy-efficient, water-efficient, and recycled-content products. The Contractor shall use paper of at least 30 percent post-consumer fiber content. When acquiring an electronic product to meet facility requirements, the contractor shall purchase Electronic Product Environmental Assessment Tool (EPEAT)-registered electronic products, unless there is no EPEAT standard for such product.

The contractor shall give preference to the purchase of:

• Recycled content products designated in EPA’s comprehensive procurement guidelines.

• Energy Star® products identified by DOE and EPA, as well as FEMP-designated energy-efficient products.

• Water-efficient products, including those meeting EPA’s Water Sense standards.

• Energy from renewable sources.

• Biobased products designated by the U.S. Department of Agriculture in the Bio Preferred program.

• Environmentally preferable products and services, including EPEAT-registered electronic products.

• Alternative fuel vehicles and alternative fuels required by EPAct.

• Products with low or no toxic or hazardous constituents’ non-ozone depleting substances, as identified in EPA’s Significant New Alternatives Program.

Biobased products are commercial or industrial products that are composed in whole, or in significant part, of biological products or renewable domestic agricultural materials or forestry materials. To the greatest extent feasible, the Contractor shall use “Green” products and services.

WARRANTY

The contractor must provide:

- A 1-year workmanship warranty, covering installation defects.

- A 25-year material warranty, covering all installed components and cabling.

DOCUMENTATION

The contractor shall submit the following within 30 days of project completion:

- As-built diagrams, including labeled rack and cable layouts.

- Comprehensive testing reports for all systems.

- Warranty documentation for materials and workmanship.

Post-Award Monthly Workforce Report (Recurring Deliverable)

The contractor shall submit the workforce report using the template at Attachment 2 with each invoice submitted.

Monthly Prime Contractor Certification. Contractors shall include with each monthly workforce report a certification signed by an authorized company officer affirming that, based on current performance data, the small business prime and its similarly situated subcontractors collectively performed at least 51 percent of the total contract cost for personnel during the reporting period. This information shall be used by the CO to verify compliance throughout performance.

FISMA Cybersecurity Requirements Language

Incorporate FISMA Cybersecurity Requirements language in all solicitations and delivery/task order contracts (Section C or H) when procuring information technology systems, applications, or services.

Information Systems and Information Security Controls for Contracting Actions Subject to Federal Information Security Modernization Act (FISMA) and Federal Risk and Authorization Management Program (FedRAMP)

In performance of this contract, the contractor agrees to comply with the following cybersecurity requirements and assumes responsibility for compliance by its personnel and subcontractors (and their personnel):

1. General. The contractor shall ensure IRS information and information systems are always protected. The contractor shall develop, implement, and maintain effective controls and methodologies in its business processes, physical environments, and human capital or personnel practices that meet or otherwise adhere to the security and privacy controls, requirements, and objectives described in applicable security and privacy control guidelines, and their respective contracts. Pursuant to the Federal Information Security Modernization Act (FISMA) and Federal Risk and Authorization Management Program (FedRAMP), the contractor shall provide minimum security controls required to protect Federal information and information systems in accordance with the Internal Revenue Manual (IRM) Part 10.8 series and the current version of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Security Privacy Controls for Information Systems and Organizations.

2. Business Entitlement Access Request System (BEARS) /Entitlement - Role-based user permission groups. The contractor shall ensure all applications and platforms integrate with the IRS to establish least privilege BEARS entitlements for all roles that prevent any one role from authorizing a transaction from end to end.

3. Privileged User Management and Access System (PUMAS). The contractor shall ensure all applications and platforms integrate with the IRS’s PUMAS to secure, provision, manage, control, and monitor all activities associated with all types of privileged identities to include, but not limited to, privileged user accounts, service accounts, and secrets management for on-premises and cloud-based applications and infrastructure.

4. Log Management and Enterprise Security Audit Trails (ESAT). The contractor shall ensure systems provide audit trails in an approved automated format acceptable to the IRS for all user actions and activities when using or maintaining the system. In accordance with NIST 800-53 Audit and Accountability (AU) controls, applications and platforms shall integrate with ESAT for audit logging to support organization-wide analysis and correlation for situational awareness.

The contractor shall provide to the IRS to be used in accordance with OMB Memo 21-31, the system logs for both services implemented on servers within the authorization boundary and services deployed on Cloud Service Offerings. The contractor shall collect and maintain network and system logs on Federal Information Systems for both on-premises systems and connections hosted by third parties, and when it is necessary to address a cyber incident on Federal Civilian Executive Branch Information Systems.

5. Federated Authentication Services Technology (FAST)/Homeland Security Presidential Directive 12 (HSPD-12) Compliant Authentication. The contractor shall ensure the system enforces the use of phishing resistant, modern multifactor authentication (MFA) compliant with Treasury, Federal and HSPD-12 Policy/Guidance. Use of MFA shall be at the exclusion of all other authentication methods i.e., username and password.

The contractor shall support a secure, multi-factor method of remote authentication and authorization to identified IRS Administrators that will allow IRS designated personnel the ability to perform management duties on the system. The contractor shall support MFA including phishing resistant MFA (e.g., Fast Identity Online/Web Authentication and public key infrastructure (PKI)) as required by Office of Management and Budget (OMB) Memo 22-09. The contractor shall support a secure, multi-factor method of remote authentication and authorization to identified contractor administrators that will allow contractor designated personnel the ability to perform management duties on the system.

Use of federated MFA may be leveraged by adopting one or more of the following Treasury/IRS Enterprise Services:

i. Secure Access Digital Identity (SADI) for authenticating external users.

ii. IRS Active Directory Federation Services (ADFS) for internal IRS users

iii. Common Access Identity Assurance (CAIA)/Treasury Enterprise Authentication Service (TEAS) in support of all Treasury

6. Cryptography Key Establishment and Management (System and Communications Protection (SC-12)). The contractor shall establish and manage cryptographic keys for required cryptography employed within the information system in accordance with centralized management of key generation, distribution, storage, access, and destruction in accordance with NIST SP 800-57, Recommendation for Key Management.

7. Data-at-Rest and Data-in-Motion Encryption of all IRS Data. The contractor shall ensure all applications encrypt data at rest (per NIST 800-53, latest revision, SC-28) and data in transit (per NIST 800-53, latest revision, SC-9). SC-28 and SC-9 must pass all objective criteria stated in NIST 800-53. In addition, the encryption solution must meet or exceed all Federal Information Processing Standards (FIPS) 140 standards. All web traffic will enforce Hypertext Transfer Protocol (HTTPS) Secure Sockets Layer/Transport Layer Security (SSL/TLS) protocols.

8. Data Jurisdiction. The contractor and subcontractors shall identify all data centers that the data at rest or data backup will reside. All data will be guaranteed to reside (and transit) within the United States (or U.S. territories).

9. Non-repudiation. The contractor shall ensure the sender of information is provided with proof of delivery, and the recipient is provided with proof of the sender’s identity. The IRS uses digital certificates to confirm the identity of Internet users sending x.509 standard encrypted information, to verify the integrity and origin of file contents. The contractor shall agree to install United States Treasury TLS site certificates for the purpose of authenticating traffic between the contractor application and the IRS. The use of SSL or TLS to facilitate arbitrary transmission control protocol (TCP) and user datagram protocol (UDP) or other protocols (effectively, anything other than HTTP) inside the encrypted TLS tunnel between an internal IRS client and an external server cannot be used.

Site-to-site virtual private network (VPN) or internet protocol security (IPsec) can be used as long as there are verifiable controls to ensure that the vendor end of that tunnel is an environment that is a closed environment. That is, the environment must be isolated at the network layer from other customers services by the offeror and does not provide for communications to other services (e.g., a gateway or routing service to endpoints outside of the control of the vendor submitting the proposal, etc.).

10. Media Transport. The contractor shall document activities associated with the transport of IRS agency information stored on digital and non-digital media and employ cryptographic mechanisms to protect the confidentiality and integrity of this information during transport outside of controlled areas. The contractor shall ensure all digital media, containing IRS information, that is transported outside of controlled areas must be encrypted using FIPS 140-2 level 2, FIPS 140-3 or National Security Agency (NSA) approved cryptography; nondigital media must be secured using the same policies and procedures as paper. The contractor shall ensure media, containing IRS information that is transported outside of controlled areas must ensure accountability. This can be accomplished through appropriate actions such as logging and a documented chain of custody form. IRS data that resides on mobile/portable devices (e.g., USB flash drives, external hard drives, and SD cards) must be encrypted. All IRS data residing on laptop computing devices must be protected with NIST-approved encryption software.

11. Boundary Protection. The contractor shall ensure that IRS information, other than unrestricted information, being transmitted from Federal government entities to external entities using cloud services is inspected by Trusted Internet Connections (TIC) processes, or the contractor shall route all external connections through a TIC in accordance with OMB Memo 19-26.

12. Security Alerts, Advisories, and Directives. The contractor, subcontractor or cloud service provider shall provide a list of personnel, identified by role, with system administration, monitoring, and/or security responsibilities who shall receive security alerts, advisories, and directives.

13. Developer Security Testing and Evaluation. The contractor shall provide the IRS with all test plans and test results developed under IRS IRM 10.8.24.3.15.9 (SA-11: Developer Security Testing and Evaluation) at least 30 days prior to the release of any new code, settings, enhancement(s) or deprecation of features.

14. Software Bill of Materials (SBOM)/Attestation. The contractor shall provide a software build/bill of materials, and attestation in accordance with OMB Memo 22-18 using CISA templates.

https://www.cisa.gov/sbom

15. RA-05 Vulnerability Mitigation. Per Binding Operational Directive (BOD) 22-01, the contractor shall ensure the application or system at the time of the Authority to Operation (ATO) must not contain any vulnerability listed in the Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog whose CISA remediation due date has been exceeded.

16. Vulnerability Monitoring and Scanning. Vulnerability monitoring includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or operating incorrectly. The contractor shall implement vulnerability scanning as defined by IRS IT Security Policy and NIST requirements to include NIST SP 800-70.

The contractor shall, monitor and scan for vulnerabilities in the system and hosted applications using vulnerability monitoring tools and techniques, and when new vulnerabilities potentially affecting the system are identified and reported, perform analysis and remediation activities.

The contractor will provide an environment that adheres to NIST SP 800-207 Zero Trust Architecture and CISA Binding Operational Directives. Non-compliant conditions are unacceptable for new technologies and cannot be remediated via a Risk Based Decision (RBD) or Risk Acceptance Form and Tool (RAFT). Non-compliance discovered in existing software (SW) or hardware (HW) will result in SW or HW being placed into quarantine until non-compliance issues are remediated to the satisfaction of the government.

https://www.cisa.gov/sbom https://www.cisa.gov/news-events/directives/binding-operational-directive-22-01 https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog

If approved for existing SW or HW, the contractor shall create a plan of actions and milestones Plan of Actions and Milestones (POA&Ms) to identify and track remediation of the identified risks/vulnerabilities for any vulnerabilities identified that cannot be remediated within 30 days.

The contractor shall report POA&Ms progress to the government as requested and at minimum monthly. The affected SW and HW shall remain in quarantine until such time the government is satisfied the remediation action/s have raised the level of compliance to an acceptable level (defined by the government).

The contractor shall provide all compliance scan results in an IRS acceptable format (i.e., CSV, JSON, or XML).

17. Cybersecurity Supply Chain Risk Management (C-SCRM). In accordance with the request for proposal (RFP), statement of work (SOW) or performance work statement (PWS) requirements, the contractor agrees to take complete responsibility for all actions of its Subcontractors.

Subcontractors are expected to meet all requirements set forth in the RFP, SOW, or PWS agreed to by the prime contract holder. The contractor shall identify all subcontractors who will perform services, including their name, the nature of services to be performed, address, telephone, email, federal tax identification number (TIN), and anticipated dollar value of each subcontract before any work is performed by the subcontractor. The IRS reserves the right to reject subcontractors identified by the contractor that pose a significant risk to IRS and the IRS IT Infrastructure as defined by Federally mandated C-SCRM requirements and Publication 4812.

Any subcontractors not listed in the contractor’s proposal submission, who are engaged by the contractor, must be pre-approved, in writing, by the IRS.

The contractor shall manage the supply chain risk lifecycle of their products, services and subcontractor tiers using risk assessment methods and procedures identified by the current version of NIST SP 800-161. The assessment must consider documented processes, documented controls, all-source intelligence, public information, foreign ownership, control, or influence (FOCI), Country of Origin (COO), ownership and leadership personnel, comparisons against Federal Government restriction lists, and identification of product vulnerabilities through the CISA national known vulnerability databases.

The contractor shall comply with NIST Secure Software Development Framework (SSDF) SP 800- 218 for its products and services or map to the SSDF to demonstrate a framework for well- secured products. The contractor shall apply the SSDF to the entire product lifecycle including design, development, testing and operations. The contractor shall secure all code in a software versioning library located in a secured environment with access enabled for the government requirements, software review and oversight roles. This tool must facilitate task management, versioning, check-in/check-out/commits, reporting, testing, automation, deficiencies, and vulnerabilities, debugging, flagging and traceability as examples. Additionally, the vendor shall identify all instances of artificial intelligence (AI) used in information and communication technology (ICT) product development or supporting ICT product capabilities.

The contractor will provide an environment that adheres to NIST SP 800-207 Zero Trust Architecture and CISA Binding Operational Directive 23-02. Non-compliant conditions are unacceptable for new technologies and cannot be remediated via a Risk Based Decision (RBD) or Risk Acceptance Form and Tool (RAFT). Non-compliance discovered in existing software or hardware will result in software or hardware being placed into quarantine until non-compliance issues are remediated to the satisfaction of the government.

The federal government has the authority to conduct site reviews for compliance validation. Full cooperation by contractor and third-party providers is required for audits and forensics. The contractor must support IRS in its efforts to assess and monitor the contractor systems and infrastructure. The contractor must provide logical and physical access to the contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases upon request.

Within 14 business days of a request from IRS Cybersecurity, the contractor shall provide the following:

i. The vendor shall provide the completed CISA Common Form documenting their attestation to the OMB 23-16 mandated secure software development requirements. The contractor shall only use software provided by software producers who can attest to and demonstrate compliance with the Government- specified secure software development practices, Security and Privacy controls and Cybersecurity Supply Chain Risk Management Practices, as described in the NIST Guidance, including software renewals and major version changes upon or prior to award. For any practices from the NIST guidance that the software producer cannot attest, the contractor shall provide documented practices in place to mitigate those risks along with a POA&M to remediate in accordance with OMB Memorandum M- 22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices (September 14, 2022) and M-23-16 Update to Memorandum M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices (June 9, 2023).

ii. The contractor shall develop and provide an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services as it relates to the products and services delivered to the IRS.

iii. The contractor shall provide evidence of a C-SCRM Plan that identifies supply chain risk with their product or services, components, suppliers, and contractors. The contractor shall review and update the supply chain risk management plan annually.

iv. During all contract phases, including the request for proposal (RFP) and/or request for information (RFI), the contractor may be required to provide responses to the IRS Cybersecurity Supply Chain Risk Assessment Questionnaire that contains a list of questions based on the current version of NIST SP 800-53 Supply Chain Risk Management security controls and the current version of NIST SP 800-161, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. The questionnaire will be provided to the vendor by IRS/Cybersecurity and is tailored for each procurement to assess the maturity of the contractor’s C-SCRM capabilities and any C-SCRM related risks relating to the contractor and its supplier supply chain components, subsystems, intellectual property, and other services relevant to the procurement.

18. Security Authorization/Certification and Accreditation Process. The IRS’ FIPS 199 baseline is a moderate. All solutions must, at a minimum, meet moderate NIST SP 800-53 security and privacy controls. However, after officially completing the FIPS 199 it may be determined that the solution is a FIPS 199 high or has additional control overlays above the standard baseline.

Cloud service providers and contractors developing vendor-built solutions must review NIST SP 800-63, use its decision trees to obtain an overview of all digital identity requirements, and read the applicable NIST SP 800-63 volumes to determine specific requirements that apply to their cloud offerings. A digital identity risk assessment (DIRA) will be completed to determine the appropriate authentication level; however, the IRS baseline is Identity Assurance Level 2 and the solution must integrate with the IRS authentication solution.

The cloud service provider/contractor systems that collect, maintain, contain or use agency information or an information system on behalf of the agency (a General Support System (GSS), with a FIPS 199 security categorization) must ensure annual reviews and continued security certification and accreditation. Some of the key elements of this IT risk and impact assessment process are project security deliverables such as the System Security Plan (SSP), Information System Contingency Plan (ISCP), Business Impact Analysis (BIA) with documentation of inclusion of the 12-hour Maximum Tolerable Downtime (MTD) for IRS Mission Essential Functions (MEFs) and evidence of recovery capability within that 12-hour timeframe, Interconnection Security Agreement (ISA), Security Risk Assessment (SRAs), Data Impact Assessments (DIAs), Risk Analyses, Security Threat Analyses, Audit Plan, Source Code Review, Security Control Assessment (SCA), and/or Event-Driven Security Control Assessment (ED-SCA). All systems that complete this process will, at a minimum, meet FedRAMP, Federal Continuity Directives (FCDs) 1 & 2, Treasury and IRS requirements. All systems must follow the NIST risk management framework (RMF) and the IRS processes supporting the RMF.

19. Data Loss Prevention (DLP) Software. The cloud service provider/contractor shall implement DLP software to assure existing software will operate effectively in the cloud.

The cloud service provider/contractor shall be responsible for all patching and vulnerability management (PVM) of software and other systems’ components supporting services when doing business with the IRS to prevent proactively the exploitation of IT vulnerabilities that may exist within the cloud service provider/contractor operating environment. Such patching and vulnerability management must meet the requirements and recommendations of NIST SP 800-40, as amended, with special emphasis on assuring that the vendor’s PVM systems and programs apply standardized configurations with automated continuous monitoring of the same to assess and mitigate risks associated with known and unknown IT vulnerabilities in the cloud service provider/contractor operating environment.

Furthermore, the cloud service provider/contractor shall apply standardized and automated acceptable versioning control systems that use a centralized model to capture, store, and authorize all software development control functions on a shared device that is accessible to all developers authorized to revise software supporting the services when doing business with the IRS. Such versioning control systems must be configured and maintained to make sure all software products deployed in the cloud service provider/contractor operating environment and serving the IRS are compatible with existing systems and architecture of the IRS.

20. Data Ownership. The delivery of data to the cloud service provider/credential service provider/contractor does not transfer any element of ownership; and as between the customer and data host, the IRS retains all right, title and interest in the data.

The cloud service provider/credential service provider/contractor role with respect to the data is limited to a storage function to fulfill its obligation to provide hosting services, and the cloud service provider/credential service provider/contractor will not interfere with the IRS’s access.

The cloud service provider/credential service provider/contractor is a “custodian” with respect to the data.

The cloud service provider/credential service provider/contractor shall delete or shall return the IRS’s data in an agreed-upon format, at any time at the user’s request. The cloud service provider/credential service provider/contractor shall provide the IRS Contracting Officer/Contracting Officer Representative with a copy of the disposal record and notification once disposal is complete.

Section D. PACKAGING AND MARKING

All deliverables under this Order shall be marked with the Contract No., Order No., Government Point of Contact, Contractor Point of Contact, Description of Deliverable, and Date.

Section E. INSPECTION AND ACCEPTANCE

E.1 INSPECTION

The Contractor shall ensure that all deliverables are clearly marked with the Contract and Task Order number and visible on all shipping/service documents, containers, and invoices.

Inspection will be at the same place as performance and delivery, unless otherwise specified. The Contractor shall provide the deliverables and receive acceptance/approval from the Government prior to invoicing for services performed

E.2 GENERAL ACCEPTANCE CRITERIA

Standard Acceptance Criteria The general quality measures as set forth below will be applied to each work product received from the contractor under this Order.

• Accuracy - Work products shall be accurate in presentation, technical content, and adherence to accepted elements of style.

• Clarity - Work products shall be clear and concise; engineering terms shall be used, as appropriate. All diagrams shall be easy to understand and relevant to the supporting narrative.

• Specifications Validity - All work products must satisfy the requirements of the Government as specified herein.

• Format - Work products shall be submitted in hard copy (where applicable) and in media defined in the PWS. Hard copy formats shall follow Department of the Treasury and IRS Directives and shall be consistent with other similar efforts. All text and diagrammatic files shall be editable by the Government.

• Timeliness - Work products shall be submitted on or before the due date specified in the PWS, or submitted in accordance with a later, scheduled date determined and approved by the CO in writing. If there is inconsistency with deliverables submittal date, the Contractor shall promptly notify the Contracting Officer to determine a date.

Customized Acceptance Criteria (Standard criteria plus the additional elements listed below). No additional elements required.

E.3 REVIEW OF DELIVERABLES

a) The Government will perform an initial review of deliverables, and if problems are encountered during the review, the Contractor must correct them. If necessary, a meeting may be convened to resolve any differences. The Contractor shall make all required changes to achieve an acceptable deliverable. The Government will perform its review within approximately fifteen (15) calendar days from receipt of the deliverable or as otherwise specified in the Task Order.

b) When the review of a deliverable results in necessary modifications, the Government will, in accordance with the approved Task Order schedule, provide the necessary documentation to correct the deliverable. It will then be the responsibility of the Contractor to properly and consistently incorporate the comments in the final product.

c) These procedures shall not be construed to constitute a waiver on the part of the Government of its rights under FAR Subpart 49.4, entitled “Termination for Default”, nor of any other rights or remedies provided by law or under this Task Order.

Section F. DELIVERIES OR PERFORMANCE

F.1 PERIOD OF PERFORMANCE

Period of performance is expected to be 8 weeks from date of award.

The dates as listed above are estimated based on estimated award date of Order. Actual dates will be revised if necessary based on date of award.

See Statement of Work for delivery details/

F.2 PLACE OF PERFORMANCE

Government’s site:

3100 West Road Building B-Suite 201 East Lansing, Michigan 48823

Contractor’s site, with reasonable access to Government site (Contractor personnel are able to travel to Government site for meetings within two hours’ notice and at reasonable travel costs).

Enter name of other potential site

F.3 DELIVERY SCHEDULE

The work products, content and due dates are identified in each of the respective task statements in Section C. All deliverables shall be received by the Government within the duration stated in Section C, SOW. If there is a discrepancy between the delivery schedule and the Task Order PWS, the Contractor shall promptly notify the Contracting Officer to mitigate any delays to the Government.

The period of performance is expected to be 4-8 weeks after date of award. Hard dates will be defined in the task order award.

Section G. CONTRACT ADMINISTRATION DATA

Clauses Incorporated by Reference

52.213-2 Invoices (APR 1984) 52.242-15 Stop-Work Order

G.1 ACCOUNTING AND APPROPRIATION DATA

CLIN/SLIN/SC Accounting Code Obligation Amt Period of Performance

G.2 IDENTIFICATION OF GOVERNMENT TASK ORDER PERSONNEL

Contracting Officer:

Jillian Staskin, jillian.n.staskin@irs.gov

Contracting Officer’s Representative (COR):

Jorge Miranda, Jorge.J.Miranda@irs.gov

Technical Point of Contact:

Jean Vegas Perez, Jean.C.VegasPerez@irs.gov

G.3 INVOICE

Electronic Invoicing and Payment Requirements for the Invoice Processing Platform (IPP) (Jul 2019)

(a) Definitions:

"Short payment" as used in this clause means the partial payment of an invoice for goods/services actually rendered at the time of payment when the invoice includes additional goods/services that have not yet been provided/rendered.

“Short payment” example: The contract requires the delivery of a set number of items, with the price, delivery location, and delivery due date also specified. The vendor delivers 50% of the items as specified but invoices for 100% of the items. Before implementation of the IPP, the IRS would have paid the vendor for the items delivered and instructed the vendor to re-invoice the IRS when the balances of the items were delivered. In other words, the IRS would "short pay" the invoice since the IRS did not remit payment for the full invoice amount. With implementation of the IPP, the IRS can no longer do this because the IRS cannot accept an electronic invoice that includes items not yet received.

The IRS will reject the invoice. The vendor needs to submit an invoice for only the items received by the IRS (in this case, 50%), and, if these items meet all other contract terms and conditions, the IRS will pay the invoiced amount. The vendor submits subsequent invoice(s) for items as they are delivered and accepted.

mailto:jillian.n.staskin@irs.gov mailto:Jean.C.VegasPerez@irs.gov

(b) The Invoice Processing Platform (IPP) is a secure Web-based electronic invoicing and payment information service available to all Federal agencies and their suppliers. Effective October1, 2012, invoicing for payment through the IPP will be mandatory for all new contract awards. Additional information regarding the IPP may be found at the IPP website address https://www.ipp.gov.

Contractors must complete the contractor point of contact information below and submit it with their proposal submissions. Contractors may contact the IPP Helpdesk for assistance via e-mail at ippgroup@stls.frb.org or via phone at (866) 973-3131. Once a contract award has been made, the contractor will be contacted by the IPP via e-mail to set-up an account. It will be necessary for contractors to login to their IPP accounts every 90 days to keep their IPP accounts active.

(c) Contractor Point of Contact Information Contractor Name:

Contractor IPP Point of Contact Name:

Contractor Phone Number:

Contractor E-mail Address:

(d) Electronic Invoicing and Payment Requirements Vendor invoices submitted electronically through the IPP should be in the proper format and contain the information required for payment processing. To be approved for payment, a “proper invoice” must list the items specified in FAR 52.232-25 (a)(3)(i) through (a)(3)(x), or in the case of a Commercial Item Contract, the items included in 52.212-4(g)(1)(i) through (g)(1)(x).

If the vendor is offering a discount via the IPP, the discount must be reflected on the invoice. The vendor will select 'Create Invoice'. The IPP system will default to ‘Net 30 Prompt Pay’ under the Payment Terms dropdown box. The vendor will select from 54 different discount options for the invoice that is being created. If the vendor chooses to offer a discount on the invoice screen, the information will interface to the payment system for processing. Discounts that are offered on attachments rather than the invoice itself cannot be accepted.

Under this contract, the following documents are required, at a minimum, to be submitted as an attachment to the invoice:

Contractor shall submit one (1) invoice per month to include all costs for both the Prime and any Subcontractors. The Contractor shall invoice for CAF funding per monthly invoice.

Please do not submit into IPP any documentation/attachments that conflict with what is stated on the invoice.

Payment and Invoice Questions :

For payment and invoice questions, contact the Ancillary Systems at (304) 254-3372 or via e- mail at cfo.fm.ipp.customer.support@irs.gov.

(e) Waiver If the Contractor is unable to use the IPP for submitting payment requests starting on October 1, 2012, then a waiver form must be completed and submitted with the contractor’s proposal submission for review and approval by the Contracting Officer based on one of the conditions listed in the waiver. The vendor will be notified prior to award as to whether their request for waiver has been approved or denied. If the waiver is granted, then a copy of the waiver must be submitted with each paper invoice that the vendor submits to the payment office or the invoice will be returned.

mailto:cfo.fm.ipp.customer.support@irs.gov

(f) Short Payment Short payment on vendor submitted invoices will no longer be processed or paid. If any portion of the invoice does not meet the requirements for a proper invoice, the entire invoice shall be rejected and returned to the vendor unpaid.

IRS Invoice Processing Platform (IPP) Waiver Form The IRS invoicing and payment requirements clause (IR1052.232-9000) requires that all invoices under awards made (or effective) on or after October 1, 2012, be submitted electronically via the IPP unless a waiver is requested and granted. If the Contractor is unable to submit its invoice through the IPP, the Contractor shall complete this waiver form indicating the reason for the waiver request by selecting the appropriate box below and providing a narrative summarizing in detail the circumstances requiring a waiver. For a solicitation, submit the waiver form with the proposal submission. For a modification that incorporates the IPP clause into an existing contract, submit the waiver form with the modification. The CO will notify the vendor via e-mail or another appropriate means of communication prior to award as to whether their waiver has been approved or denied. If the waiver is granted, then a copy of the approved waiver must be submitted with each invoice that the vendor submits to the payment office or the invoice will be returned. Reason for requesting a waiver of the requirement to submit an electronic invoice via the IPP:

1. Submission of invoices through IPP would impose a hardship on an individual (includes employees and sole proprietors) due to: either a physical or mental disability; a geographic, language, or literacy barrier; or an undue financial burden. The requirement to submit invoices through the IPP is automatically waived for all individuals who do not have payment capability using ACH with a U.S. financial institution.

2. The political, financial or communications infrastructure where the place of business is located does not support access to the IPP for submitting invoices electronically.

3. The contractor is located within an area designated by the President of the United States or an authorized agency administration as a disaster area. (Please identify area/location.)

4. The submission of invoices electronically may pose a threat to national security, the life or physical safety of an individual may be endangered, or a law enforcement action may be compromised.

5. The agency does not expect to receive more than one invoice from the same contractor within a one-year period. i.e., the invoice submission is non-recurring.

6. The contractor customarily submits a high volume of invoices on a regular basis via file format, not currently supported by the IPP (i.e., uses a file format other than XML or CSV) and the high volume of invoices would cause a significant burden to the contractor if submitted through the IPP individually. If utilizing this exception, please identify the file formats supported by your invoicing system so that the IPP may consider implementing the requested file format at a later date. File format(s) used:

7. Other - Please explain: ________________________________________________

Attach a separate sheet of paper with a summary narrative…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .