N68908-16-T-0068.pdf
PDF 101 KB Posted
- Attached to
- Solicitation Federal contract opportunity
- Solicitation number
- N68908-16-T-0068
About this file
Surgical Peg Board - Lateral Positioning System
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NAVAL HEALTH CLINIC CHERRY POINT
RECEIVING OFFICER
4389 BEAUFORT ROAD
CHERRY POINT NC 28533-0023
TEL: 252-466-0515 FAX: 252-466-0513
N6609416RC13C11
REQUEST FOR QUOTATIONS
(THIS IS NOT AN ORDER) 1
PAGE OF PAGES
1. REQUEST NO. 2. DATE ISSUED RATING
N68908-16-T-0068 25-Apr-2016 5a. ISSUED BY
8. TO: NAME AND ADDRESS, INCLUDING ZIP CODE
IMPORTANT: This is a request for information, and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it to the address in Block 5a. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or services. Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this
Request for Quotations must be completed by the quoter.
11. SCHEDULE (Include applicable Federal, State, and local taxes)
ITEM NO.
(a)
SUPPLIES/ SERVICES
(b)
QUANTITY
(c)
UNIT
(d)
UNIT PRICE
(e) (f)
SEE SCHEDULE
AMOUNT
% No. %
NOTE: Additional provisions and representations [ ] are [ ] are not attached.
13. NAME AND ADDRESS OF QUOTER (Street, City, County, State, and ZIP Code)
14. SIGNATURE OF PERSON AUTHORIZED TO
SIGN QUOTATION
15. DATE OF
QUOTATION
16. NAME AND TITLE OF SIGNER (Type or print) (Include area code)
TELEPHONE NO.
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 18 (REV. 6-95)
PREVIOUS EDITION NOT USABLE Prescribed by GSA FAR (48 CFR) 53.215-1(a)
THIS RFQ X[ ] IS [ ] IS NOT A SMALL BUSINESS SET-ASIDE
6. DELIVER BY (Date)
SEE SCHEDULE
AND/OR DMS REG. 1
UNDER BDSA REG. 2
4. CERT. FOR NAT. DEF.3. REQUISITION/PURCHASE
REQUEST NO.
NAVY MEDICINE EAST
ATTN: LYNN LOVEJOY
SUITE 1400
620 JOHN PAUL JONES CIRCLE
PORTSMOUTH VA 23708-2106
9. DESTINATION (Consignee and address, including ZIP Code)
7. DELIVERY
[ ]X FOB
DESTINATION
[ ] OTHER
(See Schedule)
05-May-2016(Date)
PLEASE FURNISH QUOTATIONS TO THE ISSUING OFFICE IN BLOCK 5a ON OR BEFORE CLOSE OF BUSINESS:10.
757-953-7920LYNN V. LOVEJOY
(Name and Telephone no.) (No collect calls)5b. FOR INFORMATION CALL:
d. CALENDAR DAYSc. 30 CALENDAR DAYSb. 20 CALENDAR DAYS12. DISCOUNT FOR PROMPT PAYMENT a. 10 CALENDAR DAYS
N68908-16-T-0068
Section A - Solicitation/Contract Form
SECTION A
TIN (tax ID):
CAGE:
DUNS:
VENDOR POC:
COMPANY TELEPHONE:
POINT OF CONTACT:
VENDOR EMAIL:
Billing/ Payment in Arrears
Navy Medicine East Regional Acquisition POC: Lynn Lovejoy Phone: 757-953-7324 Fax: 757-953-0361
Product/Service for:
U.S. Naval Health Clinic, Cherry Point User POC: Laurie Varner Com: 252-466-0323 Email: laurie.a.varner.civ@mail.mil
Vendor to reference RFQ Number N68908-16-T-0068 on all inquiries.
PROMPT PAYMENT
For Prompt Payment Act Purposes, this contract is:
Subject to the 7-calender day constructive acceptance period
Note: Vendor will be required provide billing electronically via the WAWF electronic Invoicing method. For additional information, a review of the following web sites may be required:
https://wawf.eb.mil http://wawftraining (email) WAWF@med.navy.mil
Section B - Supplies or Services and Prices
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 2 Each
SURGICAL PEG BOARD
FFP
PROCUREMENT OF TWO (2) PEG BOARD SYSTEMS AT NHC CHERRY
POINT, MCAS CHERRY POINT, NC. Original Equipment Manufacturer is David Scott, Surgical Peg Board - Lateral Positioning System, Item # WSHP0100, Complete Peg Board System PSC: H265 - Equipment and Materials Testing Services/Medical, Dental and Veterinary Equipment FOB: Destination
MILSTRIP: N6609416RC13C11
PURCHASE REQUEST NUMBER: N6609416RC13C11
NET AMT
Section E - Inspection and Acceptance
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government
Section F - Deliveries or Performance
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC
0001 15-APR-2016 2 NAVAL HEALTH CLINIC CHERRY POINT
RECEIVING OFFICER
4389 BEAUFORT ROAD
CHERRY POINT NC 28533-0023
252-466-0515 FOB: Destination
N66094
CLAUSES INCORPORATED BY REFERENCE
52.242-15 Stop-Work Order AUG 1989 52.242-17 Government Delay Of Work APR 1984 52.247-34 F.O.B. Destination NOV 1991
CLAUSES INCORPORATED BY FULL TEXT
52.211-17 DELIVERY OF EXCESS QUANTITIES (SEP 1989)
The Contractor is responsible for the delivery of each item quantity within allowable variations, if any. If the Contractor delivers and the Government receives quantities of any item in excess of the quantity called for (after considering any allowable variation in quantity), such excess quantities will be treated as being delivered for the convenience of the Contractor. The Government may retain such excess quantities up to $250 in value without compensating the Contractor therefor, and the Contractor waives all right, title, or interests therein. Quantities in excess of $250 will, at the option of the Government, either be returned at the Contractor's expense or retained and paid for by the Government at the contract unit price.
Section G - Contract Administration Data
252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (MAY 2013)
(a) Definitions. As used in this clause--
Department of Defense Activity Address Code (DoDAAC) is a six position code that uniquely identifies a unit, activity, or organization.
Document type means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).
Local processing office (LPO) is the office responsible for payment certification when payment certification is done external to the entitlement system.
(b) Electronic invoicing. The WAWF system is the method to electronically process vendor payment requests and receiving reports, as authorized by DFARS 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall--
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.acquisition.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this Web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.
(e) WAWF methods of document submission. Document submissions may be via Web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor must use the following information when submitting payment requests and receiving reports in WAWF for this contract/order:
(1) Document type. The Contractor shall use the following document type(s).
(Contracting Officer: Insert applicable document type(s). Note: If a “Combo” document type is identified but not supportable by the Contractor's business systems, an “Invoice” (stand-alone) and “Receiving Report” (stand-alone) document type may be used instead.)
(2) Inspection/acceptance location. The Contractor shall select the following inspection/acceptance location(s) in WAWF, as specified by the contracting officer.
(Contracting Officer: Insert inspection and acceptance locations or “Not applicable”.)
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table* Field Name in WAWF Data to be entered in WAWF Pay Official DoDAAC ____ Issue By DoDAAC ____ Admin DoDAAC ____ Inspect By DoDAAC ____ Ship To Code ____ Ship From Code ____ Mark For Code ____ Service Approver (DoDAAC) ____ Service Acceptor (DoDAAC) ____ Accept at Other DoDAAC ____ LPO DoDAAC ____ DCAA Auditor DoDAAC ____ Other DoDAAC(s) ____
(*Contracting Officer: Insert applicable DoDAAC information or “See schedule” if multiple ship to/acceptance locations apply, or “Not applicable.”)
(4) Payment request and supporting documentation. The Contractor shall ensure a payment request includes appropriate contract line item and subline item descriptions of the work performed or supplies delivered, unit price/cost per unit, fee (if applicable), and all relevant back-up documentation, as defined in DFARS Appendix F, (e.g. timesheets) in support of each payment request.
(5) WAWF email notifications. The Contractor shall enter the email address identified below in the “Send Additional Email Notifications” field of WAWF once a document is submitted in the system.
(Contracting Officer: Insert applicable email addresses or “Not applicable.”)
(g) WAWF point of contact. (1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity's WAWF point of contact.
(Contracting Officer: Insert applicable information or “Not applicable.”)
(2) For technical WAWF help, contact the WAWF helpdesk at 866-618-5988.
(End of clause)
Section H - Special Contract Requirements
SPECIAL CONTRACT REQUIREMENTS
PRIVACY AND SECURITY OF PROTECTED HEALTH INFORMATION
1. Introduction
In accordance with DoD 6025.18-R “Department of Defense Health Information Privacy Regulation,” January 24, 2003, the Business Associate meets the definition of Business Associate. Therefore, a Business Associate Agreement is required to comply with both the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security regulations. This clause serves as that agreement whereby the Business Associate agrees to abide by all applicable HIPAA Privacy and Security requirements regarding health information as defined in this clause, and in DoD 6025.18-R and DoD 8580.02-R, as amended. Additional requirements will be addressed when implemented.
a. Definitions. As used in this clause generally refer to the Code of Federal Regulations (CFR) definition unless a more specific provision exists in DoD 6025.18-R or DoD 8580.02-R.
(1) HITECH Act shall mean the Health Information Technology for Economic and Clinical Health Act included in the American Recovery and Reinvestment Act of 2009.
(2) Individual has the same meaning as the term “individual” in 45 CFR 160.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR 164.502(g).
(3) Privacy Rule means the Standards for Privacy of Individually Identifiable Health Information at 45 CFR part 160 and part 164, subparts A and E.
(4) Protected Health Information has the same meaning as the term “protected health information” in 45 CFR 160.103, limited to the information created or received by the Business Associate from or on behalf of the Government pursuant to the Contract.
(5) Electronic Protected Health Information has the same meaning as the term “electronic protected health information” in 45 CFR 160.103.
(6) Required by Law has the same meaning as the term “required by law” in 45 CFR 164.103.
(7) Secretary means the Secretary of the Department of Health and Human Services or his/her designee.
(8) Security Incident will have the same meaning as the term “security incident” in 45 CFR 164.304, limited to the information created or received by Business Associate from or on behalf of Covered Entity.
(9) Security Rule means the Health Insurance Reform: Security Standards at 45 CFR part 160, 162 and part 164, subpart C.
(10) Terms used, but not otherwise defined, in this Clause shall have the same meaning as those terms in 45 CFR 160.103, 160.502, 164.103, 164.304, and 164.501.
b. The Business Associate shall not use or further disclose Protected Health Information other than as permitted or required by the Contract or as Required by Law.
c. The Business Associate shall use appropriate safeguards to maintain the privacy of the Protected Health Information and to prevent use or disclosure of the Protected Health Information other than as provided for by this Contract.
d. The HIPAA Security administrative, physical, and technical safeguards in 45 CFR 164.308, 164.310, and 164.312, and the requirements for policies and procedures and documentation in 45 CFR 164.316 shall apply to Business Associate. The additional requirements of Title XIII of the HITECH Act that relate to the security and that are made applicable with respect to covered entities shall also be applicable to Business Associate. The Business Associate agrees to use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits in the execution of this Contract.
e. The Business Associate shall, at their own expense, take action to mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of Protected Health Information by the Business Associate in violation of the requirements of this Clause. These mitigation actions will include as a minimum those listed in the TMA Breach Notification Standard Operating Procedure (SOP), which is available at:
http://www.tricare.mil/tmaprivacy/breach.cfm
f. The Business Associate shall report to the Government any security incident involving protected health information of which it becomes aware.
g. The Business Associate shall report to the Government any use or disclosure of the Protected Health Information not provided for by this Contract of which the Business Associate becomes aware.
h. The Business Associate shall ensure that any agent, including a sub Business Associate, to whom it provides Protected Health Information received from, or created or received by the Business Associate, on behalf of the Government, agrees to the same restrictions and conditions that apply through this Contract to the Business Associate with respect to such information.
i. The Business Associate shall ensure that any agent, including a subBusiness Associate, to whom it provides electronic Protected Health Information, agrees to implement reasonable and appropriate safeguards to protect it.
j. The Business Associate shall provide access, at the request of the Government, and in the time and manner reasonably designated by the Government to Protected Health Information in a Designated Record Set, to the Government or, as directed by the Government, to an Individual in order to meet the requirements under 45 CFR 164.524.
k. The Business Associate shall make any amendment(s) to Protected Health Information in a Designated Record Set that the Government directs or agrees to pursuant to 45 CFR 164.526 at the request of the Government, and in the time and manner reasonably designated by the Government.
l. The Business Associate shall make internal practices, books, and records relating to the use and disclosure of Protected Health Information received from, or created or received by the Business Associate, on behalf of the Government, available to the Government, or at the request of the Government to the Secretary, in a time and manner reasonably designated by the Government or the Secretary, for purposes of the Secretary determining the Government’s compliance with the Privacy Rule.
m. The Business Associate shall document such disclosures of Protected Health Information and information related to such disclosures as would be required for the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.
n. The Business Associate shall provide to the Government or an Individual, in time and manner reasonably designated by the Government, information collected in accordance with this Clause of the Contract, to permit the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.
2. General Use and Disclosure Provisions
Except as otherwise limited in this Clause, the Business Associate may use or disclose Protected Health Information on behalf of, or to provide services to, the Government for treatment, payment, or healthcare operations purposes, in accordance with the specific use and disclosure provisions below, if such use or disclosure of Protected Health Information would not violate the HIPAA Privacy Rule, the HIPAA Security Rule, DoD 6025.18-R or DoD 8580.02-R if done by the Government. The additional requirements of Title XIII of the HITECH Act that relate to privacy and that are made applicable with respect to covered entities shall also be applicable to Business Associate.
3. Specific Use and Disclosure Provisions
a. Except as otherwise limited in this Clause, the Business Associate may use Protected Health Information for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate.
b. Except as otherwise limited in this Clause, the Business Associate may disclose Protected Health Information for the proper management and administration of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
c. Except as otherwise limited in this Clause, the Business Associate may use Protected Health Information to provide Data Aggregation services to the Government as permitted by 45 CFR 164.504(e)(2)(i)(B).
d. Business Associate may use Protected Health Information to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR 164.502(j)(1).
4. Obligations of the Government
Provisions for the Government to Inform the Business Associate of Privacy Practices and Restrictions
a. The Government shall provide the Business Associate with the notice of privacy practices that the Government produces in accordance with 45 CFR 164.520.
b. The Government shall provide the Business Associate with any changes in, or revocation of, permission by Individual to use or disclose Protected Health Information, if such changes affect the Business Associate’s permitted or required uses and disclosures.
c. The Government shall notify the Business Associate of any restriction to the use or disclosure of Protected Health Information that the Government has agreed to in accordance with 45 CFR 164.522.
5. Permissible Requests by the Government
The Government shall not request the Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the HIPAA Privacy Rule, the HIPAA Security Rule, or any applicable Government regulations (including without limitation, DoD 6025.18-R and DoD 8580.02-R) if done by the Government, except for providing Data Aggregation services to the Government and for management and administrative activities of the Business Associate as otherwise permitted by this clause.
6. Termination
a. Termination. A breach by the Business Associate of this clause, may subject the Business Associate to termination under any applicable default or termination provision of this Contract.
b. Effect of Termination.
(1) If this contract has records management requirements, the records subject to the Clause should be handled in accordance with the records management requirements. If this contract does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below
(2) If this contract does not have records management requirements, except as provided in paragraph (3) of this section, upon termination of this Contract, for any reason, the Business Associate shall return or destroy all Protected Health Information received from the Government, or created or received by the Business Associate on behalf of the Government. This provision shall apply to Protected Health Information that agents of the Business Associate may come in contact. The Business Associate shall retain no copies of the Protected Health Information.
(3) If this contract does not have records management provisions and the Business Associate determines that returning or destroying the Protected Health Information is infeasible, the Business Associate shall provide to the Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Government and the Business Associate that return or destruction of Protected Health Information is infeasible, the Business Associate shall extend the protections of this Contract to such Protected Health Information and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such Protected Health Information.
7. Miscellaneous
a. Regulatory References. A reference in this Clause to a section in DoD 6025.18-R, DoD 8580.02-R, Privacy Rule or Security Rule means the section currently in effect or as amended, and for which compliance is required.
b. Survival. The respective rights and obligations of Business Associate under the “Effect of Termination” provision of this Clause shall survive the termination of this Contract.
c. Interpretation. Any ambiguity in this Clause shall be resolved in favor of a meaning that permits the Government to comply with DoD 6025.18-R, DoD 8580.02-R, the HIPAA Privacy Rule or the HIPAA Security Rule.
Section I - Contract Clauses
52.203-3 Gratuities APR 1984 52.204-3 Taxpayer Identification OCT 1998 52.204-7 System for Award Management JUL 2013 52.204-9 Personal Identity Verification of Contractor Personnel JAN 2011 52.204-13 System for Award Management Maintenance JUL 2013 52.215-8 Order of Precedence--Uniform Contract Format OCT 1997 52.219-6 Notice Of Total Small Business Set-Aside NOV 2011 52.222-50 Combating Trafficking in Persons MAR 2015 52.223-6 Drug-Free Workplace MAY 2001 52.225-1 Buy American--Supplies MAY 2014 52.232-1 Payments APR 1984 52.232-8 Discounts For Prompt Payment FEB 2002 52.233-1 Disputes MAY 2014 52.233-3 Protest After Award AUG 1996 52.233-4 Applicable Law for Breach of Contract Claim OCT 2004 52.237-3 Continuity Of Services JAN 1991 52.237-7 Indemnification and Medical Liability Insurance JAN 1997 52.243-1 Changes--Fixed Price AUG 1987 52.246-1 Contractor Inspection Requirements APR 1984 52.249-8 Default (Fixed-Price Supply & Service) APR 1984 252.203-7000 Requirements Relating to Compensation of Former DoD
Officials
SEP 2011
252.203-7002 Requirement to Inform Employees of Whistleblower Rights SEP 2013 252.203-7998 (Dev) Prohibition on Contracting with Entities that Require Certain
Internal Confidentiality Agreements - Representation.
(DEVIATION 2015-O0010)
FEB 2015
252.204-7004 Alt A System for Award Management Alternate A FEB 2014 252.225-7048 Export-Controlled Items JUN 2013 252.232-7003 Electronic Submission of Payment Requests and Receiving
Reports
JUN 2012
252.232-7010 Levies on Contract Payments DEC 2006 252.243-7001 Pricing Of Contract Modifications DEC 1991
52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):
https://www.acquisition.gov/
252.203-7999 PROHIBITION ON CONTRACTING WITH ENTITIES THAT REQUIRE CERTAIN INTERNAL CONFIDENTIALITY
AGREEMENTS (DEVIATION 2015-O0010)(FEB 2015)
(a) The Contractor shall not require employees or subcontractors seeking to report fraud, waste, or abuse to sign or comply with internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or contactors from lawfully reporting such waste, fraud, or abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.
(b) The Contractor shall notify employees that the prohibitions and restrictions of any internal confidentiality agreements covered by this clause are no longer in effect. (c) The prohibition in paragraph (a) of this clause does not contravene requirements applicable to Standard Form 312, Form 4414, or any other form issued by a Federal department or agency governing the nondisclosure of classified information.
(d)(1) In accordance with section 743 of Division E, Title VIII, of the Consolidated and Further Continuing Resolution Appropriations Act, 2015, (Pub. L. 113-235), use of funds appropriated (or otherwise made available) under that or any other Act may be prohibited, if the Government determines that the Contractor is not in compliance with the provisions of this clause.
(2) The Government may seek any available remedies in the event the Contractor fails to perform in accordance with the terms and conditions of the contract as a result of Government action under this clause.
252.204-7006 BILLING INSTRUCTIONS (OCT 2005)
When submitting a request for payment, the Contractor shall--
(a) Identify the contract line item(s) on the payment request that reasonably reflect contract work performance; and
(b) Separately identify a payment amount for each contract line item included in the payment request.
252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT
REPORTING (DEC 2015)
(a) Definitions. As used in this clause--
Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
Contractor attributional/proprietary information means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
Contractor information system means an information system belonging to, or operated by or for, the Contractor.
Controlled technical information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.
Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.
Covered contractor information system means an information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
Covered defense information means unclassified information that--
(i) Is--
(A) Provided to the contractor by or on behalf of DoD in connection with the performance of the contract; or
(B) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract; and
(ii) Falls in any of the following categories:
(A) Controlled technical information.
(B) Critical information (operations security). Specific facts identified through the Operations Security process about friendly intentions, capabilities, and activities vitally needed by adversaries for them to plan and act effectively so as to guarantee failure or unacceptable consequences for friendly mission accomplishment (part of Operations Security process).
(C) Export control. Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. To include dual use items; items identified in export administration regulations, international traffic in arms regulations and munitions list; license applications; and sensitive nuclear technology information.
(D) Any other information, marked or otherwise identified in the contract, that requires safeguarding or disseminationcontrols pursuant to and consistent with law, regulations, and Governmentwide policies (e.g., privacy, proprietary business information).
Cyber incident means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
Forensic analysis means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
Malicious software means computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware.
Media means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which information is recorded, stored, or printed within an information system.
Operationally critical support means supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.
Rapid(ly) report(ing) means within 72 hours of discovery of any cyber incident.
Technical information means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data-Non Commercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
(b) Adequate security. The Contractor shall provide adequate security for all covered defense information on all covered contractor information systems that support the performance of work under this contract. To provide adequate security, the Contractor shall--
(1) Implement information systems security protections on all covered contractor information systems including, at a minimum--
(i) For covered contractor information systems that are part of an Information Technology (IT) service or system operated on behalf of the Government--
(A) Cloud computing services shall be subject to the security requirements specified in the clause 252.239-7010, Cloud Computing Services, of this contract; and
(B) Any other such IT service or system (i.e., other than cloud computing) shall be subject to the security requirements specified elsewhere in this contract; or
(ii) For covered contractor information systems that are not part of an IT service or system operated on behalf of the Government and therefore are not subject to the security requirement specified at paragraph (b)(1)(i) of this clause--
(A) The security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, ``Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,'' http://dx.doi.org/10.6028/NIST.SP.800-171 that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, as soon as practical, but not later than December 31, 2017. The Contractor shall notify the DoD CIO, via email at osd.dibcsia@mail.mil, within 30 days of contract award, of any security requirements specified by NIST SP 800-171 not implemented at the time of contract award; or
(B) Alternative but equally effective security measures used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection accepted in writing by an authorized representative of the DoD CIO;
and
(2) Apply other security measures when the Contractor reasonably determines that such measures, in addition to those identified in paragraph (b)(1) of this clause, may be required to provide adequate security in a dynamic environment based on an assessed risk or vulnerability.
(c) Cyber incident reporting requirement.
(1) When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support, the Contractor shall--
(i) Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor's network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor's ability to provide operationally critical support; and
(ii) Rapidly report cyber incidents to DoD at http://dibnet.dod.mil.
(2) Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at http://dibnet.dod.mil.
(3) Medium assurance certificate requirement. In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see http://iase.disa.mil/pki/eca/Pages/index.aspx.
(d) Malicious software. The Contractor or subcontractors that discover and isolate malicious software in connection with a reported cyber incident shall submit the malicious software in accordance with instructions provided by the Contracting Officer.
(e) Media preservation and protection. When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems identified in paragraph (c)(1)(i) of this clause and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
(f) Access to additional information or equipment necessary for forensic analysis. Upon request by DoD, the Contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
(g) Cyber incident damage assessment activities. If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of this clause.
(h) DoD safeguarding and use of contractor attributional/proprietary information. The Government shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) under this clause that includes contractor attributional/proprietary information, including such information submitted in accordance with paragraph (c). To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, the Government will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released.
(i) Use and release of contractor attributional/proprietary information not created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is not created by or for DoD is authorized to be released outside of DoD--
(1) To entities with missions that may be affected by such information;
(2) To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
(3) To Government entities that conduct counterintelligence or law enforcement investigations;
(4) For national security purposes, including cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or
(5) To a support services contractor (``recipient'') that is directly supporting Government activities under a contract that includes the clause at 252.204-7009, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
(j) Use and release of contractor attributional/proprietary information created by or for DoD. Information that is obtained from the contractor (or derived from information obtained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to paragraph (c) of this clause) is authorized to be used and released outside of DoD for purposes and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government's use and release of such information.
(k) The Contractor shall conduct activities under this clause in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
(l) Other safeguarding or reporting requirements. The safeguarding and cyber incident reporting required by this clause in no way abrogates the Contractor's responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information systems as required by other applicable clauses of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
(m) Subcontracts. The Contractor shall--
(1) Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve a covered contractor information system, including subcontracts for commercial items, without alteration, except to identify the parties;
and
(2) When this clause is included in a subcontract, require subcontractors to rapidly report cyber incidents directly to DoD at http://dibnet.dod.mil and the prime Contractor. This includes providing the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable.
Section K - Representations, Certifications and Other Statements of Offerors
52.225-18 Place of Manufacture MAR 2015
52.204-3 TAXPAYER IDENTIFICATION (OCT 1998)
(a) Definitions.
Common parent, as used in this provision, means that corporate entity that owns or controls an affiliated group of corporations that files its Federal income tax returns on a consolidated basis, and of which the offeror is a member.
Taxpayer Identification Number (TIN), as used in this provision, means the number required by the Internal Revenue Service (IRS) to be used by the offeror in reporting income tax and other returns. The TIN may be either a Social Security Number or an Employer Identification Number.
(b) All offerors must submit the information required in paragraphs (d) through (f) of this provision to comply with debt collection requirements of 31 U.S.C. 7701(c) and 3325(d), reporting requirements of 26 U.S.C. 6041, 6041A, and 6050M, and implementing regulations issued by the IRS. If the resulting contract is subject to the payment reporting requirements described in Federal Acquisition Regulation (FAR) 4.904, the failure or refusal by the offeror to furnish the information may result in a 31 percent reduction of payments otherwise due under the contract.
(c) The TIN may be used by the Government to collect and report on any delinquent amounts arising out of the offeror's relationship with the Government (31 U.S.C. 7701(c)(3)). If the resulting contract is subject to the payment reporting requirements described in FAR 4.904, the TIN provided hereunder may be matched with IRS records to verify the accuracy of the offeror's TIN.
(d) Taxpayer Identification Number (TIN).
___ TIN:.--------------------------------------------------------
___ TIN has been applied for.
___ TIN is not required because:
___ Offeror is a nonresident alien, foreign corporation, or foreign partnership that does not have income effectively connected with the conduct of a trade or business in the United States and does not have an office or place of business or a fiscal paying agent in the United States;
___ Offeror is an agency or instrumentality of a foreign government;
___ Offeror is an agency or instrumentality of the Federal Government.
(e) Type of organization.
___ Sole proprietorship;
___ Partnership;
___ Corporate entity (not tax-exempt);
___ Corporate entity (tax-exempt);
___ Government entity (Federal, State, or local);
___ Foreign government;
___ International organization per 26 CFR 1.6049-4;
___ Other--------------------------------------------------------
(f) Common parent.
___ Offeror is not owned or controlled by a common parent as defined in paragraph (a) of this provision.
___ Name and TIN of common parent:
Name-------------------------------------------------------------------
TIN--------------------------------------------------------------------
(End of provision)
52.222-25 AFFIRMATIVE ACTION COMPLIANCE (APR 1984)
The offeror represents that
(a) [ ] it has developed and has on file, [ ] has not developed and does not have on file, at each establishment, affirmative action programs required by the rules and regulations of the Secretary of Labor (41 CFR 60-1 and 60-2), or
(b) [ ] has not previously had contracts subject to the written affirmative action programs requirement of the rules and regulations of the Secretary of Labor.
Section L - Instructions, Conditions and Notices to Bidders
52.214-34 Submission Of Offers In The English Language APR 1991 52.214-35 Submission Of Offers In U.S. Currency APR 1991
52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)
This solicitation incorporates one or more solicitation provisions by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. The offeror is cautioned that the listed provisions may include blocks that must be completed by the offeror and submitted with its quotation or offer. In lieu of submitting the full text of those provisions, the offeror may identify the provision by paragraph identifier and provide the appropriate information with its quotation or offer. Also, the full text of a solicitation provision may be accessed electronically at this/these address(es):
https://www.acquisition.gov/
File details come from the government source that posted it. Updated .