N0042122Q0557.pdf
PDF 669 KB Posted
- Attached to
- Reverse engineering to a PC Fiberlynx Receiver Module Federal contract opportunity
- Solicitation number
- N0042122Q0557
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CDRL-A001.pdf | ||
| CDRL-A002.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
4.11.7.2
DERRICK SLAVINGS
COMMANDER
ATTN: RECEIVING OFFICER, BLDG 8115
17598 WEBSTER FIELD ROAD
ST INIGOES MD 20684-4013
TEL: 301-995-6308 FAX:
1301026368
REQUEST FOR QUOTATIONS
(THIS IS NOT AN ORDER) 1
PAGE OF PAGES
1. REQUEST NO. 2. DATE ISSUED RATING
N0042122Q0557 02-Sep-2022 5a. ISSUED BY
8. TO: NAME AND ADDRESS, INCLUDING ZIP CODE
IMPORTANT: This is a request for information, and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it to the address in Block 5a. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or services. Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this
Request for Quotations must be completed by the quoter.
11. SCHEDULE (Include applicable Federal, State, and local taxes)
ITEM NO.
(a)
SUPPLIES/ SERVICES
(b)
QUANTITY
(c)
UNIT
(d)
UNIT PRICE
(e) (f)
SEE SCHEDULE
AMOUNT
% No. %
NOTE: Additional provisions and representations [ ] are [ ] are not attached.
13. NAME AND ADDRESS OF QUOTER (Street, City, County, State, and ZIP Code)
14. SIGNATURE OF PERSON AUTHORIZED TO
SIGN QUOTATION
15. DATE OF
QUOTATION
16. NAME AND TITLE OF SIGNER (Type or print) (Include area code)
TELEPHONE NO.
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 18 (REV. 6-95)
PREVIOUS EDITION NOT USABLE Prescribed by GSA FAR (48 CFR) 53.215-1(a)
THIS RFQ X[ ] IS [ ] IS NOT A SMALL BUSINESS SET-ASIDE
6. DELIVER BY (Date)
SEE SCHEDULE
AND/OR DMS REG. 1
UNDER BDSA REG. 2
4. CERT. FOR NAT. DEF.3. REQUISITION/PURCHASE
REQUEST NO.
NAWCAD PROCUREMENT GROUP
21983 BUNDY ROAD, BLDG 441
PATUXENT RIVER MD 20670
9. DESTINATION (Consignee and address, including ZIP Code)
7. DELIVERY
[ ]X FOB
DESTINATION
[ ] OTHER
(See Schedule)
09-Sep-2022(Date)
PLEASE FURNISH QUOTATIONS TO THE ISSUING OFFICE IN BLOCK 5a ON OR BEFORE CLOSE OF BUSINESS:10.
301-342-7650KIMBERLY D. ABELL
(Name and Telephone no.) (No collect calls)5b. FOR INFORMATION CALL:
d. CALENDAR DAYSc. 30 CALENDAR DAYSb. 20 CALENDAR DAYS12. DISCOUNT FOR PROMPT PAYMENT a. 10 CALENDAR DAYS
N0042122Q0557
Section A - Solicitation/Contract Form
SECTION A
U.S. Government ~ Tax Exempt
All quotes/responses shall be submitted via email to Kimberly Silvernagel at kimberly.d.silvernagel.civ@us.navy.mil no later than 11:59 P.M EST September 09, 2022.
Items must be brand new. Quote all items or none.
Solicitation N00421-22-Q-0557 is issued as a competitive procurement. The Government intends to purchase on a firm fixed-price basis, and to solicit and award the proposed purchase order the reverse engineering of a discontinued Fiberlynx Receiver and Transmitter in support of the AN/SPN-35C (see RFQ) under the authority implemented by Federal Acquisition Regulation (FAR) by FAR Part 12 and FAR Part 13.
The Contractor shall perform reverse engineering to a PC Fiberlynx Receiver Module, P/N: 200.100.0101 and a PC Fiberlynx Transmitter Module, P/N: 200.100.0100 and provide below documentation within two to three months after receipt of order (ARO).
The Contractor shall provide the following documentation for PC Fiberlynx Receiver Module, P/N:
200.100.0101
Qty 1 - Schematic Development and Circuit Simulations for Fiberlynx Receiver Qty 1 - Schematic Capture and BOM for Fiberlynx Receiver Qty 1 - Layout, Gerbers and Verification for Fiberlynx Receiver Qty 1 - PCB Simulations for Fiberlynx Receiver
Offerors must be registered in the System for Award Management Registration (SAM) database prior to submission of an offer to be considered for award of any DoD contract. This may be accomplished electronically at http://www.sam.gov.
See Attached RFQ
Offers must complete the attached certification in Section K of this solicitation, 52.209-11, Representation by Corporation Regarding Delinquent Tax Liability or a Felony conviction under any Federal Law. Please complete certification and provide with your offer
All items must be TAA Compliant.
This is a firm fixed-price procurement; therefore, the offeror’s initial offer should represent the vendor’s best quote in terms of price and technical acceptability. Your quote will only be evaluated on the information you provide.
***Basis for Award*** All interested parties MUST submit a brand name quote no later than 11:59 P.M EST 09 September 2022. Award will be made to the vendor that submits the lowest, aggregate, firm fixed-price quote. The Government will not pay for any information received.
***Instructions to offerors*** Please include the following information with your response:
(1) FOB: Destination
(2) Shipping Cost: N/A
(3) Tax ID#
(4) UEI #
(5) Cage Code:
(6) Small Business – Yes ___ No ___
(7) Estimated Delivery Date:
(8) Commercial Catalog or Published Price List (if available)
(9) Total Cost:
Government Point of Contact:
Kimberly Silvernagel Naval Air Warfare Center AD (PAX)
2.5.1 RAC, 21983 Bundy Road, BLDG 441
Patuxent River, MD 20670-1127 Email: kimberly.d.silvernagel.civ@us.navy.mil
Section B - Supplies or Services and Prices
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 1 Each P/N: Reverse Engineering
FFP
Competitive buy in support of the AN/SPN-35C to reverse engineer a Fiberlynx Receiver and Transmitter and to provide equipment documentation IAW attached
SOW.
FOB: Destination MFR PART NR: P/N: Reverse Engineering
PURCHASE REQUEST NUMBER: 1301026368
ADDITIONAL MARKINGS: M/F: DERRICK SLAVINGS, 301-995-6308
PSC CD: C222
NET AMT
Section C - Descriptions and Specifications
STATEMENT OF WORK
STATEMENT OF WORK
Reverse Engineering of Fiberlynx Receiver and Transmitter for AN/SPN-35C
1.0 Introduction
The Naval Air Warfare Center Aircraft Division (NAWCAD) Air Traffic Control and Landing System (ATC&LS) requests the reverse engineer of a PC Fiberlynx Receiver Module and a PC Fiberlynx Transmitter Module. The PC Fiberlynx receivers and transmitters work in tandem to provide operable capabilities, specifically visual functionality between the main equipment and the Unit 5 user consoles. Without this service, ATC&LS will be unable to provide support for the AN/SPN-35C due to lack of parts.
2.0 Background
Lantronix is the Original Equipment Manufacturer (OEM) of the discontinued receiver and transmitter. These parts went obsolete in mid 2000. The PC Fiberlynx receiver/transmitter Modules were manufactured with no schematics, BOM, or troubleshooting guides and the documentation and service is needed for sustainment for the AN/SPN-35C for the next 10 years.
3.0 Government Furnished Property (GFP)
The Government shall provide (1) PC Fiberlynx Receiver Module, P/N: 200.100.0101 and (1) PC Fiberlynx Transmitter Module, P/N: 200.100.0100 to the Contractor, if required.
4.0 Tasks
The Contractor shall perform reverse engineering to a PC Fiberlynx Receiver Module, P/N: 200.100.0101 and a PC Fiberlynx Transmitter Module, P/N: 200.100.0100 and provide the below deliverables within two to three months after receipt of order (ARO).
5.0 Deliverables
The Contractor shall provide the following documentation for PC Fiberlynx Receiver Module, P/N:
200.100.0101 (CDRL A001):
Item Description Qty 1 Schematic Development and Circuit Simulations for Fiberlynx Receiver 1 2 Schematic Capture and BOM for Fiberlynx Receiver 1 3 Layout, Gerbers and Verification for Fiberlynx Receiver 1 4 PCB Simulations for Fiberlynx Receiver 1
The Contractor shall provide the following documentation for PC Fiberlynx Transmitter Module, P/N:
200.100.0100 (CDRL A002):
Item Description Qty 1 Schematic Development and Circuit Simulations for Fiberlynx Transmitter 1 2 Schematic Capture and BOM for Fiberlynx Transmitter 1
3 Layout, Gerbers and Verification for Fiberlynx Transmitter 1 4 PCB Simulations for Fiberlynx Transmitter 1
Section E - Inspection and Acceptance
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government
Section F - Deliveries or Performance
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /
CAGE
0001 30-DEC-2022 1 4.11.7.2
DERRICK SLAVINGS
COMMANDER
ATTN: RECEIVING OFFICER, BLDG 8115
17598 WEBSTER FIELD ROAD
ST INIGOES MD 20684-4013
301-995-6308 FOB: Destination
N3555A
CLAUSES INCORPORATED BY REFERENCE
52.247-34 F.O.B. Destination NOV 1991
Section G - Contract Administration Data
CLAUSES INCORPORATED BY FULL TEXT
252.232-7003 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS AND RECEIVING REPORTS (DEC 2018)
(a) Definitions. As used in this clause--
Contract financing payment means an authorized Government disbursement of monies to a contractor prior to acceptance of supplies or services by the Government.
(1) Contract financing payments include--
(i) Advance payments;
(ii) Performance-based payments;
(iii) Commercial advance and interim payments;
(iv) Progress payments based on cost under the clause at Federal Acquisition Regulation (FAR) 52.232-16, Progress Payments;
(v) Progress payments based on a percentage or stage of completion (see FAR 32.102(e)), except those made under the clause at FAR 52.232-5, Payments Under Fixed-Price Construction Contracts, or the clause at FAR 52.232-10, Payments Under Fixed-Price Architect-Engineer Contracts; and
(vi) Interim payments under a cost reimbursement contract, except for a cost reimbursement contract for services when Alternate I of the clause at FAR 52.232-25, Prompt Payment, is used.
(2) Contract financing payments do not include--
(i) Invoice payments;
(ii) Payments for partial deliveries; or
(iii) Lease and rental payments.
Electronic form means any automated system that transmits information electronically from the initiating system to affected systems.
Invoice payment means a Government disbursement of monies to a contractor under a contract or other authorization for supplies or services accepted by the Government.
(1) Invoice payments include--
(i) Payments for partial deliveries that have been accepted by the Government;
(ii) Final cost or fee payments where amounts owed have been settled between the Government and the contractor;
(iii) For purposes of subpart 32.9 only, all payments made under the clause at 52.232-5, Payments Under Fixed- Price Construction Contracts, and the clause at 52.232-10, Payments Under Fixed-Price
Architect-Engineer Contracts; and
(iv) Interim payments under a cost-reimbursement contract for services when Alternate I of the clause at 52.232-25, Prompt Payment, is used.
(2) Invoice payments do not include contract financing payments.
Payment request means any request for contract financing payment or invoice payment submitted by the Contractor under this contract or task or delivery order.
Receiving report means the data prepared in the manner and to the extent required by Appendix F, Material Inspection and Receiving Report, of the Defense Federal Acquisition Regulation Supplement.
(b) Except as provided in paragraph (d) of this clause, the Contractor shall submit payment requests and receiving reports in electronic form using Wide Area WorkFlow (WAWF). The Contractor shall prepare and furnish to the Government a receiving report at the time of each delivery of supplies or services under this contract or task or delivery order.
(c) Submit payment requests and receiving reports to WAWF in one of the following electronic formats:
(1) Electronic Data Interchange.
(2) Secure File Transfer Protocol.
(3) Direct input through the WAWF website.
(d) The Contractor may submit a payment request and receiving report using methods other than WAWF only when-
(1) The Contractor has requested permission in writing to do so, and the Contracting Officer has provided instructions for a temporary alternative method of submission of payment requests and receiving reports in the contract administration data section of this contract or task or delivery order;
(2) DoD makes payment for commercial transportation services provided under a Government rate tender or a contract for transportation services using a DoD-approved electronic third party payment system or other exempted vendor payment/invoicing system (e.g., PowerTrack, Transportation Financial Management System, and Cargo and Billing System);
(3) DoD makes payment on a contract or task or delivery order for rendered health care services using the TRICARE Encounter Data System; or
(4) The Governmentwide commercial purchase card is used as the method of payment, in which case submission of only the receiving report in WAWF is required.
(e) Information regarding WAWF is available at https://wawf.eb.mil/.
(f) In addition to the requirements of this clause, the Contractor shall meet the requirements of the appropriate payment clauses in this contract when submitting payment requests.
(End of clause)
252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (DEC 2018)
(a) Definitions. As used in this clause—
“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.
“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).
“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.
“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232- 7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall—
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.
(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:
(1) Document type. The Contractor shall submit payment requests using the following document type(s):
(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.
(ii) For fixed price line items—
(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.
COMBO____________________________________________________________
(Contracting Officer: Insert applicable invoice and receiving report document type(s) for fixed price line items that require shipment of a deliverable.)
(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.
(Contracting Officer: Insert either “Invoice 2in1” or the applicable invoice and receiving report document type(s) for fixed price line items for services.)
(iii) For customary progress payments based on costs incurred, submit a progress payment request.
(iv) For performance based payments, submit a performance based payment request.
(v) For commercial item financing, submit a commercial item financing request.
(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.
[Note: The Contractor may use a WAWF “combo” document type to create some combinations of invoice and receiving report in one step.]
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table*
Field Name in WAWF Data to be entered in WAWF
Pay Official DoDAAC N64142
Issue By DoDAAC N00421
Admin DoDAAC** N00421
Inspect By DoDAAC N3555A
Ship To Code N3555A
Ship From Code N/A
Mark For Code N/A
Service Approver (DoDAAC) N/A
Service Acceptor (DoDAAC) N/A
Accept at Other DoDAAC N/A
LPO DoDAAC N/A
DCAA Auditor DoDAAC N/A
Other DoDAAC(s) N/A
(*Contracting Officer: Insert applicable DoDAAC information. If multiple ship to/acceptance locations apply, insert “See Schedule” or “Not applicable.”)
(**Contracting Officer: If the contract provides for progress payments or performance-based payments, insert the DoDAAC for the contract administration office assigned the functions under FAR 42.302(a)(13).)
(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.
(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.
(g) WAWF point of contact.
(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contact.
michelle.l.hammett.civ@us.navy.mil
(Contracting Officer: Insert applicable information or “Not applicable.”)
(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.
Section I - Contract Clauses
52.204-13 System for Award Management Maintenance OCT 2018 52.212-4 Contract Terms and Conditions--Commercial Products and
Commercial Services
NOV 2021
52.212-5 Contract Terms and Conditions Required to Implement Statutes or Executive Orders--Commercial Products and Commercial Services
MAY 2022
52.232-39 Unenforceability of Unauthorized Obligations JUN 2013 52.244-6 Subcontracts for Commercial Products and Commercial
Services
JAN 2022
52.245-1 Government Property SEP 2021 52.245-9 Use And Charges APR 2012 252.203-7002 Requirement to Inform Employees of Whistleblower Rights SEP 2013 252.211-7007 Reporting of Government-Furnished Property MAR 2022 252.225-7048 Export-Controlled Items JUN 2013 252.245-7001 Tagging, Labeling, and Marking of Government-Furnished
Property
APR 2012
252.245-7002 Reporting Loss of Government Property JAN 2021 252.245-7003 Contractor Property Management System Administration APR 2012 252.245-7004 Reporting, Reutilization, and Disposal DEC 2017
52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION SYSTEMS (NOV 2021)
(a) Definitions. As used in this clause--
Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.
Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.
Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).
Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502).
Safeguarding means measures or controls that are prescribed to protect information systems.
(b) Safeguarding requirements and procedures.
(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:
(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).
(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
(iii) Verify and control/limit connections to and use of external information systems.
(iv) Control information posted or processed on publicly accessible information systems.
(v) Identify information system users, processes acting on behalf of users, or devices.
(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
(xii) Identify, report, and correct information and information system flaws in a timely manner.
(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.
(xiv) Update malicious code protection mechanisms when new releases are available.
(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.
(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (c), in subcontracts under this contract (including subcontracts for the acquisition of commercial products or commercial services, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.
52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN TELECOMMUNICATIONS AND VIDEO
SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)
(a) Definitions. As used in this clause--
Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet).
Covered foreign country means The People's Republic of China.
Covered telecommunications equipment or services means--
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary or affiliate of such entities);
(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);
(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.
Critical technology means--
(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled--
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or
(ii) For reasons relating to regional stability or surreptitious listening;
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).
Interconnection arrangements means arrangements governing the physical connection of two or more networks to allow the use of another's network to hand off traffic where it is ultimately delivered (e.g., connection of a customer of telephone provider A to a customer of telephone company B) or sharing data and other information resources.
Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include an internal or third-party audit.
Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high.
Substantial or essential component means any component necessary for the proper function or performance of a piece of equipment, system, or service.
(b) Prohibition.
(1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L.
115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The Contractor is prohibited from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104.
(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L.
115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract, or extending or renewing a contract, with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in FAR 4.2104. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract.
(c) Exceptions. This clause does not prohibit contractors from providing--
(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(2) Telecommunications equipment that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(d) Reporting requirement.
(1) In the event the Contractor identifies covered telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system, during contract performance, or the Contractor is notified of such by a subcontractor at any tier or by any other source, the Contractor shall report the information in paragraph (d)(2) of this clause to the Contracting Officer, unless elsewhere in this contract are established procedures for reporting the information; in the case of the Department of Defense, the Contractor shall report to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the
Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.
(2) The Contractor shall report the following information pursuant to paragraph (d)(1) of this clause:
(i) Within one business day from the date of such identification or notification: The contract number; the order number(s), if applicable; supplier name; supplier unique entity identifier (if known); supplier Commercial and Government Entity (CAGE) code (if known); brand; model number (original equipment manufacturer number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the information in paragraph (d)(2)(i) of this clause: Any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of covered telecommunications equipment or services, and any additional efforts that will be incorporated to prevent future use or submission of covered telecommunications equipment or services.
(e) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (e) and excluding paragraph (b)(2), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services.
52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address: https://www.acquisition.gov/browse/index/far.
252.204-7000 DISCLOSURE OF INFORMATION (OCT 2016)
(a) The Contractor shall not release to anyone outside the Contractor's organization any unclassified information, regardless of medium (e.g., film, tape, document), pertaining to any part of this contract or any program related to this contract, unless--
(1) The Contracting Officer has given prior written approval;
(2) The information is otherwise in the public domain before the date of release; or
(3) The information results from or arises during the performance of a project that involves no covered defense information (as defined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting) and has been scoped and negotiated by the contracting activity with the contractor and research performer and determined in writing by the contracting officer to be fundamental research (which by definition cannot involve any covered defense information), in accordance with National Security Decision Directive 189, National Policy on the Transfer of Scientific, Technical and Engineering Information, in effect on the date of contract award and the Under Secretary of Defense (Acquisition, Technology, and Logistics) memoranda on Fundamental Research, dated May 24, 2010, and on Contracted Fundamental Research, dated June 26, 2008 (available at DFARS PGI 204.4).
(b) Requests for approval under paragraph (a)(1) shall identify the specific information to be released, the medium to be used, and the purpose for the release. The Contractor shall submit its request to the Contracting Officer at least 10 business days before the proposed date for release.
(c) The Contractor agrees to include a similar requirement, including this paragraph(c), in each subcontract under this contract. Subcontractors shall submit requests for authorization to release through the prime contractor to the Contracting Officer.
252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT
REPORTING (DEC 2019)
(a) Definitions. As used in this clause--
Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
Contractor attributional/proprietary information means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
Controlled technical information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.
Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
Covered contractor information system means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
Covered defense information means unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is--
(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or
(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
Cyber incident means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
Forensic analysis means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
Malicious software means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
Media means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
Operationally critical support means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
Rapidly report means within 72 hours of discovery of any cyber incident.
Technical information means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data--Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The Contractor shall provide adequate security on all covered contractor information systems.
To provide adequate security, the Contractor shall implement, at a minimum, the following information security protections:
(1) For covered contractor information systems that are part of an information technology (IT) service or system operated on behalf of the Government, the following security requirements apply:
(i) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract.
(ii) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract.
(2) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1) of this clause, the following security requirements apply:
(i) Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171) in effect at the time the solicitation is issued or as authorized by the Contracting Officer.
(ii)(A) The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. For all contracts awarded prior to October 1, 2017, the Contractor shall notify the DoD Chief Information Officer (CIO), via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award.
(B) The Contractor shall submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer, for consideration by the DoD CIO. The Contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be nonapplicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
(C) If the DoD CIO has previously adjudicated the contractor's requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the Contracting Officer when requesting its recognition under this contract.
(D) If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/resources/documents/) and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
(3) Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraphs (b)(1) and (2) of this clause, may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
(c) Cyber incident reporting requirement.
(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall--
(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor's network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor's ability to provide operationally critical support; and
(ii) Rapidly report cyber incidents to DoD at https://dibnet.dod.mil.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at https://dibnet.dod.mil.
(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/eca/.
(d) Malicious software. When the Contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DoD Cyber Crime Center (DC3) in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.
(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.
(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.
(i) Use and release of contractor attributional/proprietary information not created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD--
(1) To entities with missions that may be affected by such information;
(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
(3) To Government entities that conduct counterintelligence or law enforcement investigations;
(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or
(5) To a support services contractor (“recipient”) that is directly supporting Government activities under a contract that includes the clause at 252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government's use and release of such information.
(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor's responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(m) Subcontracts. The Contractor shall--
(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial items, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer; and
(2) Require subcontractors to--
(i) Notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer, in accordance with paragraph (b)(2)(ii)(B) of this clause; and
(ii) Provide the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber incident to DoD as required in paragraph (c) of this clause.
252.204-7018 PROHIBITION ON THE ACQUISITION OF COVERED DEFENSE TELECOMMUNICATIONS
EQUIPMENT OR SERVICES (JAN 2021)
(a) Definitions. As used in this clause--
Covered defense telecommunications equipment or services means--
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation, or any subsidiary or affiliate of such entities;
(2) Telecommunications services provided by such entities or using such equipment; or
(3) Telecommunications equipment or services produced…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .