RFQ_M68909-24-Q-7624 A003.pdf

PDF 321 KB Posted

Attached to
FY24 Cyber Assessment Tool Federal contract opportunity
Solicitation number
M68909-24-Q-7624
Issued by
United States Marine Corps

About this file

This document is an amendment to a solicitation for a Cyber Assessment Tool for the United States Marine Corps. The purpose of the amendment is to: 1) extend the offer due date, 2) update the NAICS and PSC codes, 3) update the contract line items (CLINs), and 4) add a brand name or equal requirement for the Picus Security software solution.

The solicitation is for a comprehensive automated security control assessment tool to enable the Marine Corps Tactical Systems Support Activity (MCTSSA) to efficiently evaluate the security posture of command and control (C2) and weapon systems. The tool must support various security frameworks including NIST Cybersecurity Framework, NIST SP 800-53, and Cyber Survivability Endorsement Implementation Guide (CSEIG) version 3. The tool must also provide detailed insights and recommendations to enhance the cyber resiliency of the systems under test. Key requirements include the ability to operate in an air-gapped environment, create custom attack scripts, import vulnerability scan data from Tenable, and emulate Advanced Persistent Threat (APT) groups. The procurement will utilize a brand name or equal approach, with vendors proposing "or equal" solutions required to explain how their offerings meet or exceed the listed Picus Security solution. The period of performance is 12 months with two 12-month option periods.

View the file

Other files for this federal contract opportunity

Other files attached to FY24 Cyber Assessment Tool, newest first.
File Type Posted
RFQ_M68909-24-Q-7624 A0005 Conformed.pdf PDF
RFQ_M68909-24-Q-7624 A0005.pdf PDF
RFQ_M68909-24-Q-7624 A004.pdf PDF
RFQ_M68909-24-Q-7624 A004 Conformed.pdf PDF
RFQ_M68909-24-Q-7624 A003 Conformed.pdf PDF
FY24 Cyber Assessment Tool Automated__Brand Name_Redacted.pdf PDF
RFQ_M68909-24-Q-7624 A003.pdf PDF
RFQ_M68909-24-Q-7624 A003 Conformed.pdf PDF
RFQ_M68909-24-Q-7624 A0002.pdf PDF
RFQ_M68909-24-Q-7624 A0002 Conformed.pdf PDF
RFQ_M68909-24-Q-7624__Amendment1.pdf PDF
RFQ_M68909-24-Q-7624.pdf PDF
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER (Type or print)

30-105-04EXCEPTION TO SF 30

APPROVED BY OIRM 11-84

STANDARD FORM 30 (Rev. 10-83) Prescribed by GSA

FAR (48 CFR) 53.243

The purpose of this amendment is to do the follow ing:

1. Extend the offer due date from 07/12/2024 at 12:00PM PDT to 8/09/2024 at 09:00AM PDT.

2. Update the NAICS Code and PSC Code.

3. Update the CLINs.

4. Add a brand name or equal requirement for Picus Security. Vendors proposing "or equal" softw are must explain how the solution meets or exceeds the listed Picus Security solution.

See the follow ing page for the Summary of Changes.

All other terms and conditions remain unchanged.

1. CONTRACT ID CODE PAGE OF PAGES

J 1 18

16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)

16C. DATE SIGNED

BY 22-Jul-2024

16B. UNITED STATES OF AMERICA15C. DATE SIGNED15B. CONTRACTOR/OFFEROR

(Signature of Contracting Officer)(Signature of person authorized to sign)

8. NAME AND ADDRESS OF CONTRACTOR (No., Street, County, State and Zip Code) X M6890924Q7624

X 9B. DATED (SEE ITEM 11)

27-Jun-2024

10B. DATED (SEE ITEM 13)

9A. AMENDMENT OF SOLICITATION NO.

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offer X is extended, is not extended.

Offer must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended by one of the following methods:

(a) By completing Items 8 and 15, and returning 1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;

or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

12. ACCOUNTING AND APPROPRIATION DATA (If required)

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE

CONTRACT ORDER NO. IN ITEM 10A.

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(B).

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority)

E. IMPORTANT: Contractor is not, is required to sign this document and return copies to the issuing office.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

10A. MOD. OF CONTRACT/ORDER NO.

2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO.(If applicable)

6. ISSUED BY

3. EFFECTIVE DATE

22-Jul-2024

CODE

COMMANDING OFFICER

CONTRACTS, MCTSSA

BOX 555171

CAMP PENDLETON CA 92055-5171

M68909 7. ADMINISTERED BY (If other than item 6)

4. REQUISITION/PURCHASE REQ. NO.

CODE

See Item 6

FACILITY CODECODE

EMAIL:TEL:

M6890924Q7624

SECTION SF 30 BLOCK 14 CONTINUATION PAGE

SUMMARY OF CHANGES

SECTION SF 30 - BLOCK 14 CONTINUATION PAGE

The following have been added by full text:

AMENDMENT 002

Amendment 002 changes NAICS and PSC Codes and add a brand name or other equal

The following have been modified:

AMENDMENT 001

Vendor Question: What cybersecurity platform does the Government intend to use to meet its requirements?

Government Answer: The Government does not intend to use any specific cybersecurity platform. Any platform with the capabilities detailed in the RFQ will meet the Government’s requirements for this procurement.

Vendor Question: What Tenable products must the contractor ensure compatibility with? Which version of these products must the contractor shape their solution to support?

Government Answer: Tenable Nessus (Latest Version)

Vendor Question: What specific requirements and limitations for operating in the air-gapped environment does the Government have in mind?

Government Answer: For any tool/vendor to be considered, the tool must be self-contained whether as a single Virtual Machine or multiple. There can be no reach back to vendor servers or the internet. Software updates must be delivered in a method where it can be downloaded to a disk and must be self-contained as well.

Custom scripts must be able to be imported without review, approval, and dissemination with vendor.

Vendor Question: Are there any specific hardware or software configurations offerors should be aware of?

Government Answer: Vendor solution must be able to be deployed on ESXi. Solution must also be able to ingest data from Rapid7 tools

Vendor Question: Are there any specific scripting languages or frameworks preferred for creating custom attack scripts?

Government Answer: Python (.py), Bash Script (.sh), Windows Batch (.bat) and Powershell (.ps1)

Vendor Question: Are there any specific data formats or APIs that the imported vulnerability scan data should adhere to?

Government Answer: At minimum: XML, CSV, HTML, .nessus

Vendor Question: Can the Government provide any guidelines or documentation on the required depth and complexity of the APT emulation?

Government Answer: Depth and Complexity should emulate APT campaigns from publicly available sources and follow steps from initial access to data exfiltration

Vendor Question: Can the Government provide an expected license count for nodes, users, or seats required to run this software?

Government Answer: Single instance, 15 users

Vendor Question: Are there specific pricing models or structures preferred for this procurement (milestone, subscription)?

Government Answer: Yearly Subscription

SECTION SF 1449 - CONTINUATION SHEET

SOLICITATION/CONTRACT FORM

The standard size code has changed from $47,000,000 to $34,000,000.

The set aside percentage 100.00% has been deleted.

The required response date/time has changed from 12-Jul-2024 12:00 PM to 09-Aug-

2024 09:00 AM.

The Acquisition Set Aside has changed from SVC-DISABLED VET-OWNED SB to No Preference / Not Listed.

SUPPLIES OR SERVICES AND PRICES

Global Changes

CLIN 0001 -- CLIN 0003

The NAICS code 513210 has been deleted.

CLIN 0001

The CLIN type priced has been deleted.

The CLIN description has changed from Cyber Assessment Tool Base to Cyber Assessment Tool.

The CLIN extended description has changed from:

To provide penetration testing, validation, and reporting software over a 12 month base period. The relevant software must have the following capabilities:1. Ability to operate in an air-gapped environment with no reliance on external connections. 2. Ability to create custom attack scripts without external oversight or approval.3. Ability to import vulnerability scan data from Tenable.4. Ability to emulate Advanced Persistent Threat (APT) groups.

To:

CLIN is for information only. Add pricing at SLIN level. Brand name or equal requirement for Picus Security.

Vendors proposing "or equal" software must explain how the solution meets or exceeds the listed Picus Security solution. A comprehensive automated security control assessment tool that will enable Marine Corps Tactical Systems Support Activity (MCTSSA) to efficiently evaluate the security posture of command and control (C2) and weapon systems. The tool must support various security frameworks to include, but not limited to: NIST Cybersecurity Framework, NIST SP 800-53, Cyber Survivability Endorsement Implementation Guide (CSEIG) version 3. The tool must also provide detailed insights and provide recommendations to enhance the cyber resiliency of the system under test.To provide penetration testing, validation, and reporting software for a 12 month period.

The relevant software must have the following capabilities:1. Ability to operate in an air-gapped environment with no reliance on external connections. 2. Ability to create custom attack scripts without external oversight or approval.3. Ability to import vulnerability scan data from Tenable.4. Ability to emulate Advanced Persistent Threat (APT) groups.

The FOB Destination has been deleted.

The PSC code 7A21 has been deleted.

CLIN 0002

This CLIN has been renumbered to CLIN 1001.

The CLIN type priced has been deleted.

The CLIN extended description has changed from:

Penetration testing, validation, and reporting software for one 12-month option period. The relevant software must have the following capabilities:1. Ability to operate in an air-gapped environment with no reliance on external connections. 2. Ability to create custom attack scripts without external oversight or approval.3. Ability to import vulnerability scan data from Tenable.4. Ability to emulate Advanced Persistent Threat (APT) groups.

CLIN is for information only. Add pricing at SLIN level. Brand name or equal requirement for Picus Security.

Vendors proposing "or equal" software must explain how the solution meets or exceeds the listed Picus Security solution. A comprehensive automated security control assessment tool that will enable Marine Corps Tactical Systems Support Activity (MCTSSA) to efficiently evaluate the security posture of command and control (C2) and weapon systems. The tool must support various security frameworks to include, but not limited to: NIST Cybersecurity Framework, NIST SP 800-53, Cyber Survivability Endorsement Implementation Guide (CSEIG) version 3. The tool must also provide detailed insights and provide recommendations to enhance the cyber resiliency of the system under test.To provide penetration testing, validation, and reporting software for a 12 month period.

The relevant software must have the following capabilities:1. Ability to operate in an air-gapped environment with no reliance on external connections. 2. Ability to create custom attack scripts without external oversight or approval.3. Ability to import vulnerability scan data from Tenable.4. Ability to emulate Advanced Persistent Threat (APT) groups.

The option status has changed from No Status to Option.

The FOB Destination has been deleted.

CLIN 0003

This CLIN has been renumbered to CLIN 2001.

The CLIN type priced has been deleted.

The CLIN extended description has changed from:

Penetration testing, validation and reporting software for one 12-month option period. The relevant software must have the following capabilities:1. Ability to operate in an air-gapped environment with no reliance on external connections. 2. Ability to create custom attack scripts without external oversight or approval.3. Ability to import vulnerability scan data from Tenable.4. Ability to emulate Advanced Persistent Threat (APT) groups.

CLIN is for information only. Add pricing at SLIN level. Brand name or equal requirement for Picus Security.

Vendors proposing "or equal" software must explain how the solution meets or exceeds the listed Picus Security solution. A comprehensive automated security control assessment tool that will enable Marine Corps Tactical Systems Support Activity (MCTSSA) to efficiently evaluate the security posture of command and control (C2) and weapon systems. The tool must support various security frameworks to include, but not limited to: NIST Cybersecurity Framework, NIST SP 800-53, Cyber Survivability Endorsement Implementation Guide (CSEIG) version 3. The tool must also provide detailed insights and provide recommendations to enhance the cyber resiliency of the system under test.To provide penetration testing, validation, and reporting software for a 12 month period.

The relevant software must have the following capabilities:1. Ability to operate in an air-gapped environment with no reliance on external connections. 2. Ability to create custom attack scripts without external oversight or approval.3. Ability to import vulnerability scan data from Tenable.4. Ability to emulate Advanced Persistent Threat (APT) groups.

The option status has changed from No Status to Option.

The FOB Destination has been deleted.

SUBCLIN 0001AA is added as follows:

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001AA 1 Each PL-OnPrm-AG-T3

FFP

Air-gapped Platform - Maintenance support for air-gapped deployments FOB: Destination MFR PART NR: PL-OnPrm-AG-T3

PSC CD: DA01

NET AMT

SUBCLIN 0001AB is added as follows:

0001AB 1,000 Each APV-Base

FFP

Attack Path Validation Base - Reveals and validates high-risk attack paths to critical assets, limiting the number of hosts discovered during assessments to the maximum number of hosts licensed.

FOB: Destination MFR PART NR: APV-Base

SUBCLIN 0001AC is added as follows:

0001AC 1 Each ASV-Base-T3

FFP

Attack Surface Validation - Cyber Asset Inventory for subscribed devices (includes integrations with AD, SCCM, Crowdstrike EDR,Tenable.sc) Up to 2500 assets FOB: Destination MFR PART NR: ASV-Base-T3

SUBCLIN 0001AD is added as follows:

0001AD 1 Each Bu-3+-T3

FFP

Complete Security Posture Bundle with Detection Analytics - Includes all attack modules (Network Infiltration, Email, Web Application, Endpoint, Data Exfiltration). Agents included: 10 simulation, 2 attacker.

FOB: Destination MFR PART NR: Bu-3+-T3

SUBCLIN 1001AA is added as follows:

1001AA 1 Each OPTION PL-OnPrm-AG-T3

FFP

Air-gapped Platform - Maintenance support for air-gapped deployments FOB: Destination

SUBCLIN 1001AB is added as follows:

1001AB 1,000 Each OPTION APV-Base

FFP

Attack Path Validation Base - Reveals and validates high-risk attack paths to critical assets, limiting the number of hosts discovered during assessments to the maximum number of hosts licensed.

FOB: Destination

SUBCLIN 1001AC is added as follows:

1001AC 1 Each OPTION ASV-Base-T3

FFP

Attack Surface Validation - Cyber Asset Inventory for subscribed devices (includes integrations with AD, SCCM, Crowdstrike EDR,Tenable.sc) Up to 2500 assets FOB: Destination

SUBCLIN 1001AD is added as follows:

1001AD 1 Each OPTION Bu-3+-T3

FFP

Complete Security Posture Bundle with Detection Analytics - Includes all attack modules (Network Infiltration, Email, Web Application, Endpoint, Data Exfiltration). Agents included: 10 simulation, 2 attacker.

FOB: Destination

SUBCLIN 2001AA is added as follows:

2001AA 1 Each OPTION PL-OnPrm-AG-T3

FFP

Air-gapped Platform - Maintenance support for air-gapped deployments FOB: Destination

SUBCLIN 2001AB is added as follows:

2001AB 1,000 Each OPTION APV-Base

FFP

Attack Path Validation Base - Reveals and validates high-risk attack paths to critical assets, limiting the number of hosts discovered during assessments to the maximum number of hosts licensed.

FOB: Destination

SUBCLIN 2001AC is added as follows:

2001AC 1 Each OPTION ASV-Base-T3

FFP

Attack Surface Validation - Cyber Asset Inventory for subscribed devices (includes integrations with AD, SCCM, Crowdstrike EDR,Tenable.sc) Up to 2500 assets FOB: Destination

SUBCLIN 2001AD is added as follows:

2001AD 1 Each OPTION Bu-3+-T3

FFP

Complete Security Posture Bundle with Detection Analytics - Includes all attack modules (Network Infiltration, Email, Web Application, Endpoint, Data Exfiltration). Agents included: 10 simulation, 2 attacker.

FOB: Destination

DELIVERIES AND PERFORMANCE

The following Delivery Schedule for CLIN 0001 has been deleted:

DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /

CAGE

18-AUG-2024 COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738 FOB: Destination

M68909

The following Delivery Schedule for SUBCLIN 0001AA has been added:

DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /

CAGE

POP 03-SEP-2024 TO

02-SEP-2025

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 0001AB has been added:

CAGE

POP 03-SEP-2024 TO

02-SEP-2025

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 0001AC has been added:

CAGE

POP 03-SEP-2024 TO

02-SEP-2025

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 0001AD has been added:

CAGE

POP 03-SEP-2024 TO

02-SEP-2025

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 1001AA has been added:

CAGE

POP 03-SEP-2025 TO

02-SEP-2026

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 1001AB has been added:

CAGE

POP 03-SEP-2025 TO

02-SEP-2026

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 1001AC has been added:

CAGE

POP 03-SEP-2025 TO

02-SEP-2026

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 1001AD has been added:

CAGE

POP 03-SEP-2025 TO

02-SEP-2026

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 2001AA has been added:

CAGE

POP 03-SEP-2026 TO

02-SEP-2027

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 2001AB has been added:

CAGE

POP 03-SEP-2026 TO

02-SEP-2027

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 2001AC has been added:

CAGE

POP 03-SEP-2026 TO

02-SEP-2027

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

The following Delivery Schedule for SUBCLIN 2001AD has been added:

CAGE

POP 03-SEP-2026 TO

02-SEP-2027

N/A COMMANDING OFFICER

MAJOR JOSEPH MEIER

MCTSSA SUPPLY

BLDG 31345

CAMP PENDLETON CA 92055-5171

760-846-6738

INSPECTION AND ACCEPTANCE

The Acceptance/Inspection Schedule for CLIN 0001 has been changed from:

INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY

Destination Government Destination Government

To:

INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY

N/A N/A N/A N/A

The following Acceptance/Inspection Schedule was added for SUBCLIN 0001AA:

Destination Government Destination Government

The following Acceptance/Inspection Schedule was added for SUBCLIN 0001AB:

The following Acceptance/Inspection Schedule was added for SUBCLIN 0001AC:

The following Acceptance/Inspection Schedule was added for SUBCLIN 0001AD:

The Acceptance/Inspection Schedule for CLIN 1001 has been changed from:

Destination Government Destination Government

To:

The following Acceptance/Inspection Schedule was added for SUBCLIN 1001AA:

The following Acceptance/Inspection Schedule was added for SUBCLIN 1001AB:

The following Acceptance/Inspection Schedule was added for SUBCLIN 1001AC:

The following Acceptance/Inspection Schedule was added for SUBCLIN 1001AD:

The Acceptance/Inspection Schedule for CLIN 2001 has been changed from:

Destination Government Destination Government

To:

The following Acceptance/Inspection Schedule was added for SUBCLIN 2001AA:

The following Acceptance/Inspection Schedule was added for SUBCLIN 2001AB:

The following Acceptance/Inspection Schedule was added for SUBCLIN 2001AC:

The following Acceptance/Inspection Schedule was added for SUBCLIN 2001AD:

The following have been modified:

252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (JAN 2023)

(a) Definitions. As used in this clause—

“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.

“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).

“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.

“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.

(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232- 7003, Electronic Submission of Payment Requests and Receiving Reports.

(c) WAWF access. To access WAWF, the Contractor shall—

(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov; and

(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.

(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.

(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.

(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:

(1) Document type. The Contractor shall submit payment requests using the following document type(s):

(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.

(ii) For fixed price line items—

(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.

N/A

(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.

Invoice 2in1

(iii) For customary progress payments based on costs incurred, submit a progress payment request.

(iv) For performance based payments, submit a performance based payment request.

(v) For commercial financing, submit a commercial financing request.

https://www.sam.gov/ https://wawf.eb.mil/ https://wawf.eb.mil/

(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.

(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.

Routing Data Table*

Field Name in WAWF Data to be entered in WAWF Pay Official DoDAAC HQ0871 Issue By DoDAAC M68909 Admin DoDAAC** M68909 Inspect By DoDAAC M68909 Ship To Code M68909 Ship From Code ____ Mark For Code ____ Service Approver (DoDAAC) M68909 Service Acceptor (DoDAAC) M68909 Accept at Other DoDAAC ____ LPO DoDAAC ____ DCAA Auditor DoDAAC ____ Other DoDAAC(s) ____

(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.

(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.

(g) WAWF point of contact.

(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contact.

_ Devin Crook, devin.crook@usmc.mil

(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.

(End of clause)

The following have been deleted:

252.211-7003 Item Unique Identification and Valuation JAN 2023

(End of Summary of Changes)

File details come from the government source that posted it. Updated .