NCSES Analytical and Technical Support IDIQ_Solicitation_Final.pdf

PDF 326 KB Posted

Attached to
NCSES Technical and Analytical Support Services Federal contract opportunity
Solicitation number
49100421Q0050
Issued by
National Science Foundation Division of Acquisition and Cooperative Support

About this file

This is a combined synopsis and solicitation for analytical and technical support services issued by the National Science Foundation Division of Acquisition and Cooperative Support. The National Center for Science and Engineering Statistics requires expert analytic and technical support on tasks involving science and technology issues, including producing Science and Engineering Indicators reports, other reports, data analysis, data visualization, database management, data acquisition, data presentation, survey development, specialized statistical analysis for survey sampling, communications support, and organizing workshops. The solicitation will result in multiple IDIQ contracts awarded in accordance with FAR 16.5. Quotes are due by April 21, 2021 with advisory downselect notifications by May 13, 2021 and oral presentations by July 2, 2021. IDIQ contracts will have a base period of performance from August 2, 2021 to August 1, 2026. Pricing will be at the task order level with labor rates required for key personnel positions.

View the file

Other files for this federal contract opportunity

Other files attached to NCSES Technical and Analytical Support Services, newest first.
File Type Posted
Attachment 1_SOW_Appendix D.pdf PDF
NCSES Analytical and Technical Support IDIQ_Solicitation_Final_Amendment 1.pdf PDF
Attachment 1_SOW_Appendix C.pdf PDF
Attachment 3-RFQ Question Matrix_Government Responses_4_8_2021.xlsx XLSX spreadsheet
Attachment 3-RFQ Question Matrix.xlsx XLSX spreadsheet
Attachment 2-Key Personnel Qualifications_Final.pdf PDF
Attachment 1_IDIQ SOW_Final.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

21Q0050, Analytical and Technical Support IDIQ Combined Synopsis/Solicitation

1. Synopsis

a. Action Code/Solicitation Number. 49100421Q0050

b. Date. March 22, 2021

c. Product or Service Code. B599-Special Studies/Analysis-Other

d. Contracting Office Address. 2415 Eisenhower Avenue, Alexandria, VA 22314

e. Subject. Technical and Analytical Support Services, Indefinite Delivery/Indefinite Quantity Solicitation

f. Closing Response Date. April 21, 2021

g. Contact Point or Contracting Officer. Bethany Stutler, email: bstutler@nsf.gov

h. Description. This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation will not be issued. The Statement of Work (SOW) is included as Attachment 1 to this solicitation. This solicitation uses FAR part 12.6. FAR parts 8, 13, 14, and 15 are not used for purposes of forming any contract(s) resultant from this solicitation. The Government contemplates awarding multiple Indefinite Delivery/Indefinite Quantity (IDIQ) contracts in accordance with FAR 16.5.

2. The solicitation number is 49100421Q0050 and this solicitation is issued as a Request for Quote (RFQ).

3. A statement that the solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2021-04.

4. This solicitation is unrestricted. Multiple awards are contemplated. This solicitation is for indefinite delivery/indefinite quantity (IDIQ) contract(s). The relevant NAICS code is 541990-All Other Professional, Scientific, and Technical Services

5. The line item for this solicitation is as follows:

CLIN Description Period Price Minimum Maximum 0001 Technical and

Analytical Support Services

Ordering period is five years from date of contract

Individually priced task orders

$1,500 $35,000,000

6. The IDIQ SOW for this solicitation is attached to this solicitation as Attachment 1.

7. The ordering period for these IDIQ contract(s) is five (5) years from the date of contract award.

Deliverables will be made to the National Science Foundation (NSF). The maximum dollar amount of task orders for contracts resulting from this solicitation is $35,000,000.

8. The provision at 52.212-1, Instructions to Offerors-Commercial, applies to this acquisition without addenda.

https://www.acquisition.gov/far/part-12#FAR_Subpart_12_6 https://www.acquisition.gov/far/part-52#FAR_52_212_1

9. The provision at 52.212-2, Evaluation-Commercial Items, does not apply to this solicitation. The evaluation procedures for this solicitation are described below.

10. Offerors shall ensure that its Representations and Certifications are available at www.sam.gov, in accordance with 52.212-3.

11. The clause at 52.212-4, Contract Terms and Conditions-Commercial Items, applies to this acquisition without addenda.

12. The clause at 52.212-5, Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial Items, applies to this acquisition and the following optional clauses are included:

52.203-6; 52.203-13; 52.204-10; 52.204-14; 52.204-15; 52.209-6; 52.219-8; 52.219-9; 52.219-14; 52.219- 16; 52.219-32; 52.222-3; 52.222-19; 52.222-21; 52.222-26; 52.222-35; 52.222-36; 52.222-37; 52.222-40;

52.222-50; 52.222-52; 52.223-18; 52.225-13; 52.232-33; and 52.242-5.

13. Additional contract clauses applicable to this solicitation are described below.

14. This solicitation does not have a Defense Priorities and Allocations System (DPAS) assignment.

15. Phase 1 Quotes are due on April 21, 2021 at 4 p.m. EDT. Quotes must be emailed to Bethany Stutler at bstutler@nsf.gov.

16. Questions regarding this solicitation shall be emailed to Bethany Stutler at bstutler@nsf.gov no later than April 2, 2021 at 4 p.m. EST. All questions and responses will be posted on beta.SAM.gov as an amendment to this solicitation. Therefore, questions shall not contain proprietary information. All questions shall be submitted using Attachment 3-RFQ Question Matrix.

Additional FAR Clauses/Provisions

52.216-18 Ordering (AUG 2020)

(a) Any supplies and services to be furnished under this contract shall be ordered by issuance of delivery orders or task orders by the individuals or activities designated in the Schedule. Such orders may be issued five years from the award date of the contract.

(b) All delivery orders or task orders are subject to the terms and conditions of this contract. In the event of conflict between a delivery order or task order and this contract, the contract shall control.

(c) A delivery order or task order is considered “issued” when—

(1) If sent by mail (includes transmittal by U.S. mail or private delivery service), the Government deposits the order in the mail;

(2) If sent by fax, the Government transmits the order to the Contractor’s fax number; or

(3) If sent electronically, the Government either—

(i) Posts a copy of the delivery order or task order to a Government document access system, and notice is sent to the Contractor; or

(ii) Distributes the delivery order or task order via email to the Contractor’s email address.

https://www.acquisition.gov/far/part-52#FAR_52_212_2 http://www.sam.gov/ https://www.acquisition.gov/far/part-52#FAR_52_212_4 https://www.acquisition.gov/far/part-52#FAR_52_212_5 mailto:bstutler@nsf.gov

(d) Orders may be issued by methods other than those enumerated in this clause only if authorized in the contract.

(End of clause)

52.216-19 Order Limitations (OCT 1995)

(a) Minimum order. When the Government requires supplies or services covered by this contract in an amount of less than $1,500, the Government is not obligated to purchase, nor is the Contractor obligated to furnish, those supplies or services under the contract.

(b) Maximum order. The Contractor is not obligated to honor-

(1) Any order for a single item in excess of $10,000,000.

(2) Any order for a combination of items in excess of $35,000,000; or

(3) A series of orders from the same ordering office within 21 days that together call for quantities exceeding the limitation in paragraph (b)(1) or (2) of this section.

(c) If this is a requirements contract (i.e., includes the Requirements clause at subsection 52.216-21 of the Federal Acquisition Regulation (FAR)), the Government is not required to order a part of any one requirement from the Contractor if that requirement exceeds the maximum-order limitations in paragraph (b) of this section.

(d) Notwithstanding paragraphs (b) and (c) of this section, the Contractor shall honor any order exceeding the maximum order limitations in paragraph (b), unless that order (or orders) is returned to the ordering office within 5 days after issuance, with written notice stating the Contractor’s intent not to ship the item (or items) called for and the reasons. Upon receiving this notice, the Government may acquire the supplies or services from another source.

(End of clause)

52.216-22 Indefinite Quantity (OCT 1995)

(a) This is an indefinite-quantity contract for the supplies or services specified, and effective for the period stated, in the Schedule. The quantities of supplies and services specified in the Schedule are estimates only and are not purchased by this contract.

(b) Delivery or performance shall be made only as authorized by orders issued in accordance with the Ordering clause. The Contractor shall furnish to the Government, when and if ordered, the supplies or services specified in the Schedule up to and including the quantity designated in the Schedule as the “maximum.” The Government shall order at least the quantity of supplies or services designated in the Schedule as the “minimum.”

(c) Except for any limitations on quantities in the Order Limitations clause or in the Schedule, there is no limit on the number of orders that may be issued. The Government may issue orders requiring delivery to multiple destinations or performance at multiple locations.

https://www.acquisition.gov/far/part-52#FAR_52_216_21

(d) Any order issued during the effective period of this contract and not completed within that period shall be completed by the Contractor within the time specified in the order. The contract shall govern the Contractor’s and Government’s rights and obligations with respect to that order to the same extent as if the order were completed during the contract’s effective period; provided, that the Contractor shall not be required to make any deliveries under this contract two years after the expiration of the ordering period.

(End of clause)

52.216-27 Single or Multiple Awards (OCT 1995)

NSF anticipates making multiple awards.

(End of provision)

Additional NSF Specific Clauses

NSF 020 Authority of Government Personnel (APR 2013)

Contracting Officer

The Contracting Officer (CO) is the only person authorized to approve changes in any of the requirements under this contract. Notwithstanding any clause contained elsewhere in this contract, the said authority remains solely with the CO.

In the event the Contractor effects any change at the direction of any person other than the CO, including any change beyond the scope of authority given to the duly authorized Contracting Officer's Representative identified in the contract, the change will be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in charges incurred as a result thereof. The CO has the authority to perform any and all post-award functions in administering and enforcing this contract in accordance with its terms and conditions.

Contracting Officer’s Representative

The Contracting Officer’s Representative (COR), (insert COR name, contact information-Fill-In at Time of Award), is responsible for administering the performance of work under this contract. IN NO EVENT, however, will any understanding, agreement, modification, change order, or other matter deviating from the terms of this contract be effective or binding upon the Government unless formalized by proper contractual documents executed by the CO prior to completion of the contract.

The COR may give technical direction to the Contractor that fills in details, requires pursuit of certain lines of inquiry, or otherwise serves to facilitate the Contractor's compliance with the contract. To be valid, technical direction by the COR must be consistent with the general scope of work set forth in this contract; may not constitute new assignment of work nor change the expressed terms, conditions or specifications of this contract; and shall not constitute a basis for any increase in the contract estimated cost, or extension to the contract delivery schedule.

(End of clause)

NSF 030 Security Requirements and Access to National Science Foundation Facilities and Unclassified Information Technology Resources (FEB 2021)

Applicable Laws and Regulations

1. Records Management by Federal Agencies [44 USC 31]

2. Privacy Act of 1974 as amended [5 USC 552a]

3. Federal Information Security Modernization Act (FISMA) of 2014 [Title III, PL 113-283]

4. Homeland Security Presidential Directive 12 (HSPD-12), “Policy for a Common Identification

Standard for Federal Employees and Contractors”

5. Presidential Policy Directive 21 (PPD-21), "Critical Infrastructure Security and Resilience"

6. Federal Agency Responsibilities for Review, Reporting, and Publication Under the Privacy Act

[OMB Circular A-108, as amended]

7. Management's Responsibility for Enterprise Risk Management and Internal Control [OMB

Circular A-123, Revised 7/15/2016]

8. Managing Information as a Strategic Resource [OMB Circular A-130, revised 7/28/2016]

9. Guidance on Inter-Agency Sharing of Personal Data – Protecting Personal Privacy [OMB M-01-

05]

10. Safeguarding Against and Responding to the Breach of Personally Identifiable Information [OMB

M-07-16]

11. Ensuring New Acquisitions Include Common Security Configurations [OMB M-07-18]

12. Completing the Transition to Internet Protocol Version 6 (IPv6) [OMB M-21-07]

13. Controlled Unclassified Information [CFR 2002]

Applicable Standards and Guidance

1. Security Requirements for Cryptographic Modules [FIPS Publication 140-3]

2. Standards for Security Categorization of Federal Information and Information Systems [FIPS

Publication 199]

3. Minimum Security Requirements for Federal Information and Information Systems [FIPS

Publication 200]

4. Personal Identity Verification (PIV) of Federal Employees and Contractors [FIPS Publication 201-

2]

5. Guide for Developing Security Plans for Federal Information Systems [NIST SP 800-18]

6. Guide for Conducting Risk Assessments [NIST SP 800-30]

7. Contingency Planning Guide for Federal Information Systems [NIST SP 800-34]

8. Risk Management Framework for Information Systems and Organizations: A System Life Cycle

Approach for Security and Privacy [NIST SP 800-37]

9. Managing Information Security Risk: Organization, Mission, and Information System View [NIST

SP 800-39]

10. Security and Privacy Controls for Federal Information Systems and Organizations [NIST SP 800-

53]

11. Assessing Security and Privacy Controls in Federal Information Systems and Organizations:

Building Effective Assessment Plans [NIST SP 800-53A]

12. Guide for Mapping Types of Information and Information Systems to Security Categories [NIST

SP 800-60]

13. Computer Security Incident Handling Guide [NIST SP 800-61]

14. Security Considerations in the System Development Life Cycle [NIST SP 800-64]

15. Technical Guide to Information Security Testing and Assessment [NIST SP 800-115]

16. Guide for Security-Focused Configuration Management of Information Systems [NIST SP 800-

128]

17. Information Security Continuous Monitoring for Federal Information Systems and Organizations

[NIST SP 800-137]

18. Supply Chain Risk Management Practices for Federal Information Systems and Organizations

[NIST SP 800-161]

19. Framework for Improving Critical Infrastructure Cybersecurity [NIST Cybersecurity Framework

1.1, April 16, 2018]

20. Advanced Encryption Standard [FIPS 197]

21. Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations [NIST

SP 800-171R2]

22. Other guidance released by NSF during the life of this award.

NSF Policies (NSF Policies are available through the Contracting Officer)

1. NSF Evaluation Policy, available online

2. NSF Manual 7, "Information Security Handbook"

3. NSF Manual 14, "Personnel Manual (PER)"

4. NSF Bulletin 13-09 Onboarding and Separation Policy for Contractors

5. NSF Bulletin 18-07 Mobile Communications Devices

6. NSF Policy Regarding the Privacy of Sensitive Information

7. NSF Privacy Impact Assessment Policy

8. NSF Privacy Impact Assessment Guide and Template

9. NSF Privacy Threshold Analysis Guide and Template

10. NSF Privacy Breach Plan

11. NSF Computer Security Incident Response and Recovery Procedure

12. Information Security and Privacy Continuous Monitoring Program

1. General

a. Policy Compliance - All Contractor personnel performing under this contract and requiring access to NSF information systems, networks, or data must comply with all Federal Information Security Modernization Act (FISMA), Office of Management and Budget (OMB), Homeland Security Presidential Directive 12 (HSPD-12), National Institute of Standards and Technology (NIST) and NSF IT security and privacy policies, procedures and guidance.

b. Compliance with Onboarding and Separation Procedures - The Contractor is responsible for its employees’ conduct and establishing in- and out-processing procedures that ensure accomplishment of the actions identified in this clause.

c. Contractor Self-Identification - In accordance with requirements set forth in the Federal Acquisition Regulation (FAR) and guidance issued by OMB, all Contractor personnel attending meetings, interacting with NSF staff to complete work assignments, and working in other situations where their Contractor status is not obvious to third parties or internal agency staff, are required to identify themselves as Contractor employees, including email signature blocks and voicemail. Contractors interacting with Government staff or the public for purely administrative functions, such as for forwarding telephone calls, may be exempted from this self-identification requirement.

d. Expiration of Contract - Contractor personnel access to NSF facilities for work performance will be revoked upon expiration of this contract or task orders issued hereunder.

e. Incorporation in Subcontracts - The Contractor shall incorporate the substance of this clause in all subcontracts.

2. Personnel Onboarding

a. Federal Identity Card - Contractor personnel assigned to work at NSF facilities shall be issued a Personal Identity Verification (PIV) card that permits their entrance to NSF facilities without going through visitor access processes. Contractor personnel may also be granted certain other privileges such as NSF email accounts and/or access to NSF information systems. This access shall be provided solely at the discretion of the NSF, and may be revoked or withdrawn at any time, without notice or cause, by the Contracting Officer.

b. Background Investigation - Contractor personnel requiring routine physical access to NSF facilities for more than six months require a Personal Identity Verification (PIV) or Personal Identity Verification Interoperability (PIV-I) and shall be investigated (i.e., a Tier 1 or higher-level investigation). Contractor personnel requiring access to systems operated by a Contractor for the NSF or interconnected to a NSF network shall be investigated at an appropriate level. The Contractor shall not work on the contract until a favorable determination is granted. The FBI National Criminal History Check must be completed, and the investigation must be scheduled by the Office of Personnel Management (OPM) before the cards are issued. NSF shall submit the Tier 1 (or higher level) investigation to OPM using the standard personnel investigation forms listed in this clause. Contractors are required to report to the Division of Administrative Services (DAS) ID Card office during business hours to be electronically fingerprinted, inputted into the online Electronic Questionnaire for Investigations Processing (eQIP) system and provide other required documents to begin the investigations process. The Contractor shall submit the required forms to the NSF Personnel Security Office within five (5) days after award or assignment of an individual to a position requiring investigation.

c. Level of Investigation - Guidance for selecting the appropriate level of investigation is based on the risk of adverse impact to the NSF. The levels of risk for which investigation is required is as follows (IT-1 has the highest level of risk):

i. IT-1: Individuals having privileged access or limited privileged access to systems whose misuse can cause very serious adverse impact to NSF systems and programs.

ii. IT-2: Individuals having privileged access or limited privileged access to systems whose misuse can cause significant adverse impact to NSF programs. These systems include, for example, those that interconnect with a NSF network in a way that exceeds access by the general public, such as bypassing firewalls; and systems operated by a Contractor for NSF whose function or data has substantial cost to replace, even if these systems are not interconnected with a NSF network.

d. Required Forms - Investigation for individuals shall employ forms appropriate for the level of risk as follows:

i. IT-1: Electronic fingerprints, online Standard Form (SF) 85 Questionnaire for Non- Sensitive Positions, Official Form (OF) 306 Declaration for Federal Employment, Credit Report Notice Form and resume.

ii. IT-2: Electronic fingerprints, Electronic and Standard Form (SF) 85P Questionnaire for Public Trust Positions, Official Form (OF) 306 Declaration for Federal Employment, Credit Report Notice Form and resume.

e. Proof of Investigation - Investigation of Contractor personnel may be waived by the Personnel Security Office for individuals in cases where proof of prior investigation at the Tier 1, 2 or higher level within the last two years can be obtained.

f. Records Management Training – The Contractor shall ensure that its employees, in the performance of the contract, receive Records Management Training as it is made available in the learning management system.

g. IT Security and Privacy Awareness Training - The Contractor shall ensure that its employees, in performance of the contract, receive initial IT Security and Privacy Awareness Training before being granted access to NSF systems and networks, and receive refresher IT Security and Privacy Awareness Training annually. The Contractor may use web-based training available from the NSF to meet this requirement.

h. Rules of Behavior - The Contractor shall ensure that its employees, in performance of the contract, sign and submit the “National Science Foundation (NSF) IT Security and Privacy Awareness Training Rules of Behavior” before receiving access to NSF systems and networks. Additionally, the Rules of Behavior will be signed and submitted annually at the completion of the IT Security and Privacy Awareness Training referenced in 2.g. above.

i. Employee and Contractor Separation - At any time during the term of this contract or task orders issued hereunder, Contractor personnel issued a Personal Identity Verification (PIV) card, or granted access to NSF email or any other NSF information system, that do not require any further access, and/or at completion, expiration or termination of any such contract or task order where access has been granted, SHALL;

i. Complete and submit the online Contractor/Guest Exit Form, which will result in termination of all access to any NSF email accounts and information systems.

ii. Report to the lobby floor visitor center to identify themselves to the personnel present and surrender their Personal Identity Verification (PIV).

iii. Notify the Contracting Officer Representative (COR) and appropriate Property Custodian of any NSF equipment or information to be surrendered to NSF.

3. Access Controls for NSF Systems and Information - The Contractor shall be responsible for Information Technology security for all systems used in performance of this contract, or those which are connected to a NSF network. This clause is applicable to all or any part of the contract that includes information technology resources or services in which the Contractor must have physical or electronic access to NSF’s information, including sensitive information and personally identifiable information, contained in unclassified systems that directly support the mission of the Agency. The access includes information technology, hardware, software, and the management, operation, maintenance, programming, and system administration of computer systems, networks, and telecommunications systems.

4. Remote Access – The Contractor may have the need to access NSF information systems remotely.

The Contractor will remotely access NSF systems only through approved mechanisms. All remote access sessions will be encrypted using NSF services to protect NSF data.

5. Protection of Sensitive and Personally Identifiable Information (PII) - NSF's privacy program includes policies, plans, training, and technical safeguards to protect sensitive information, which includes Personally Identifiable Information (PII). NSF recognizes the importance of protecting sensitive information and implements policy, guidance, and best practices to safeguard information from inappropriate access, use, or disclosure.

a. Information Types - The term, Information, is synonymous with Data, regardless of format or medium. PII is a subset of Sensitive Information. Sensitive PII is a subset of PII, and therefore a subset of Sensitive Information. All requirements for Sensitive Information apply to PII and Sensitive PII. All requirements for PII apply to Sensitive PII.

i. Sensitive Information - Sensitive Information is any information, which if lost, compromised, or disclosed, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual, the Government, or the Government’s interests. Sensitive Information is subject to stricter handling requirements because of the increased risk if the data are compromised. Some categories of sensitive information include financial, medical or health, legal, strategic and business, human resources, PII and sensitive PII. These categories of information require appropriate protection as stand-alone information and may require additional protection in aggregate.

ii. Personally Identifiable Information (PII) - PII, as defined in OMB Memorandum M- 07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information, refers to information that can be used to distinguish or trace an individual’s identity, such as their name, social security number, biometric records, etc., either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, etc. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information that is publicly available — in any medium and from any source — is or can be combined to identify an individual. As an example, PII includes a name or an email address because these pieces of information uniquely identify an individual, but alone may not constitute Sensitive PII.

iii. Sensitive PII - Sensitive PII refers to information that can be used to target, harm, or coerce an individual or entity, assume or alter an individual’s or entity’s identity, or alter the outcome of an individual’s or entity’s activities. Sensitive PII requires stricter handling because of the increased risk to an individual if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as Social Security numbers (SSN) or biometric identifiers. Other information such as a financial account, date of birth, maiden names, citizenship status, or medical information, in conjunction with the identity of an individual (directly or indirectly inferred), are also considered Sensitive PII. The context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or compliant.

b. Access to Information - While performing official duties, Contractors may have the need to access sensitive information or PII. Sensitive information includes proposal reviews, reviewer identity tied to specific reviews or panels, unfunded proposals, proprietary parts of funded proposals; and other similar information. Most of the sensitive information maintained by NSF falls within Privacy Act systems of records, which places disclosure restrictions on NSF and provides access rights to individuals. Sensitive information may also exist in other types of records, such as databases, log files, email, and correspondence files.

All Contractor personnel are responsible for recognizing sensitive information and avoiding inappropriate or accidental access, use, or disclosure in accordance with Privacy Act and NSF IT security and privacy policies.

c. Responsibility to Identify and Protect PII - All Contractor personnel are responsible for recognizing Personally Identifiable Information and avoiding inappropriate or accidental access, use, or disclosure in accordance with NSF IT policies.

d. Information Use - The Contractor must not use or redistribute any NSF information processed, stored, or transmitted by the Contractor except as specified in the Contract.

e. NSF Privacy Program and PII - PII may be in the scope of the acquisition and PII may be stored, processed, or transmitted in the Contractor's information system. The collection, maintenance or dissemination of any PII that is subject to the Privacy Act and/or the E- Government Act will be handled in full accordance with all NSF rules of behavior and in accordance with NSF Privacy Program requirements. The Contractor shall ensure that any PII stored on any Contractor system as a function of the contract is encrypted in accordance with NSF policy.

f. PII Guidelines - PII (should it come into scope) will require the following guidelines be adhered to.

i. The Contractor’s information system must be authorized at least at the FIPS PUB 199 Moderate level.

ii. For any system that collects, maintains or disseminates PII, a Privacy Threshold Analysis (PTA) and Privacy Impact Assessment (PIA) must be completed by the contractor and provided to the NSF Privacy Office (https://www.nsf.gov/policies/privacy.jsp) for review along with the other authorization to operate (ATO) documents.

iii. If the system retrieves information using name or personal identifier, the Office of General Counsel should be consulted to make a determination as to whether the Privacy Act applies and whether a System of Records Notice (SORN) is in place.

iv. If a data collection involves Privacy Act protected information, a Privacy Act Statement (i.e., Privacy Notice) must be provided to users prior to their use of the application on what data is being collected and why, as well as the authority for the collection and the impact of not providing some or all of it. The Privacy Act Statement must be available to the individual directly on the form used to collect the information. Providing a link back to the Statement from the form is acceptable.

g. Privacy Training - All Contractor staff who have significant privacy information responsibilities must complete NSF's IT Security and Privacy Awareness Training. This includes contractors who work with PII as part of their work duties (e.g. Human Resource staff, Finance staff, and managers/supervisors).

6. Systems and Information Integrity

a. Vulnerability Management - If access, including remote access, is through a Contractor-managed system, the Contractor is responsible for IT security patching and maintenance of the system. NSF is responsible for security and patching of NSF managed devices, including Contractor devices if they have a NSF image, when the Contractor device is connected to the NSF network.

b. NSF Configuration Baseline - The Contractor shall certify applications are fully functional and operate correctly as intended on systems using the established NSF configuration baseline.

The standard installation, operation, maintenance, updates, and/or patching of software, including software purchased under this Agreement, shall not alter the configuration settings from the approved established NSF configuration baseline configuration. Offerings that require installation should follow OMB M-07-18, Ensuring New Acquisitions Include Common Security Configurations. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges. The Contractor shall use Security Content Automation Protocol (SCAP) validated tools with established NSF configuration baseline scanner capability to certify their products operate correctly with established NSF configuration baseline settings and do not alter established NSF configuration baselines.

c. Mobile Devices – Personally owned mobile devices are permitted to connect to NSF IT resources and services (such as email, calendar, contacts, etc.). If the Contractor wishes to use a personally owned mobile device, the device must first be enrolled in Mobile Device Services (MDS). Use of personally owned mobile devices must be in accordance with the NSF MDS Terms of Use and enrollment guides.

7. Continuous Monitoring and Ongoing Authorization

a. Security Assessment and Authorization (A&A)

i. Major Applications - For Information Systems NSF has identified as Major Applications or General Support Systems (GSS) that are not connected to a NSF network, but for which the Contractor has operational responsibility on behalf of NSF, the Contractor must conform to all NSF policy guidance and reporting requirements regarding Assessment and Authorization (A&A) of IT systems. NSF shall perform all the assessment activities as outlined in NIST SP 800-37, while the Contractor will provide full support and documentation to NSF for this effort. Unless otherwise specified by NSF, NSF shall fulfill the roles of “Senior Agency Information Security Officer" (or "Chief Information Security Officer”) and “Authorizing Official” as outlined in NIST SP 800-37 Appendix D. For all Contractor Operated systems, NSF shall establish accreditation boundaries and assessment schedules.

ii. Timeline - The A&A activities will be done prior to service commencement (go-live into Production) and periodically thereafter as required by Federal or NSF policies.

This is currently every three years or according to ongoing authorization plans unless there is a major change.

b. Continuous Monitoring – Continuous monitoring is an important activity of NSF’s IT Security and Privacy Program. Continuous monitoring assures NSF infrastructure and information assets are protected while maintaining an open and collaborative environment for scientific research and discovery. NSF’s Information Security Continuous Monitoring (ISCM) program contributes to NSF’s Enterprise Risk Management approach, which is charged to develop, mitigate, and manage significant risks to NSF.

ISCM activities incorporate compliance with the Federal Information Security Modernization Act (FISMA) and ongoing operational security for a system throughout its lifecycle. NSF’s continuous monitoring approach assesses the security state of information systems based on FISMA security requirements and National Institute for Standards and Technology (NIST) guidance.

c. Cloud Services – If cloud services are used to support NSF, the Contractor shall implement the controls contained within the Federal Risk and Authorization Management Program (FedRAMP) Cloud Computing Security Requirements Baseline and FedRAMP Continuous Monitoring Requirements for Low and Moderate impact systems (as defined in FIPS PUB 199). FedRAMP documents define requirements for compliance to meet minimum Federal information security and privacy requirements for Low or Moderate impact systems. The FedRAMP baseline controls are based on NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations and includes a set of additional controls for use within systems providing cloud services to the federal government.

The Contractor shall generally, substantially, and in good faith follow FedRAMP guidelines and security guidance. In situations where there are no procedural guides, the Contractor shall use generally accepted industry best practices for IT security.

d. Risk Management – NSF manages enterprise information security and privacy risk in compliance with NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View and the Framework for Improving Critical Infrastructure Cybersecurity (the Framework). The Framework encourages agencies to operate within an implementation tier that includes formally approved policies and procedures, an integrated risk management program, and collaboration and partnership with external parties to develop, maintain, and enhance a holistic cybersecurity environment. NSF uses the Framework's adaptive process to identify and respond to cybersecurity risk.

NSF monitoring activities are based on NIST Special Publication (SP) 800-37. Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy. The risk management framework process emphasizes the continuous monitoring of information systems through enhanced monitoring and providing essential information for risk-based decisions.

NSF leverages the Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM) Program to augment NSF’s capabilities for automated control monitoring.

The DHS CDM program improves NSF’s ability to implement a more robust continuous monitoring program and response to risks and emerging cyber threats.

The Contractor shall apply appropriate techniques to manage and mitigate risk during the acquisition, implementation, and operation of information technology at NSF. The techniques include but are not limited to: prudent project management; continuous collection and evaluation of risk-based assessment data; prototyping prior to implementation; post implementation reviews; and focusing on risks and returns using quantifiable measurements.

e. Supply Chain Risk Management – Supply chain risk means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of an information system (as that term is defined at 44 U.S.C. 3542(b)) so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system.

i. The Contractor shall provide information system(s) in compliance with the annual Consolidated and Further Continuing Appropriations Act regarding the acquisition of high impact or moderate impact systems in effect at the time of award.

ii. The Contractor shall mitigate supply chain risk in the provision of supplies and services to the Government.

iii. The Contractor shall maintain threat awareness while supplying the Government with products and services.

iv. The Contractor products and services shall comply with industry standard development and engineering principles to ensure security requirements are incorporated throughout the development and delivery process.

v. The Contractor shall incorporate secure configuration in products and services that are consistent with organizational risk management.

8. Cooperation with Audits

a. Contractor Cooperation - The Contractor (and subcontractors) shall fully cooperate with all audits, inspections, investigations, or other reviews conducted by or on behalf of the Contracting Officer or the Chief Information Security Officer or designated representative including the IT Security Officer. Full cooperation includes, but is not limited to, prompt disclosure to authorized requestors of information sufficient to identify the nature and extent of any computer security incident, including a breach of sensitive information or personally identifiable information and the individuals responsible for such activity. The Contractor’s (and any subcontractors’) cooperation with audits, inspections, investigations, and reviews conducted under this clause will be provided at no additional cost to the Government.

b. Government Data and Records - The Contractor (or subcontractor) shall timely produce to the Contracting Officer, a Contracting Officer’s Representative (COR), or the Chief Information Security Officer, Government data, information, or records under the control of or in the possession of the Contractor pursuant to this contract, which the Agency, may request in furtherance of other audits, inspections, investigations, reviews or litigation in which the Senior Agency Information Security Officer (or Chief Information Security Officer) is involved. Requests for production under this paragraph shall specify a reasonable deadline for compliance which will presumptively determine whether response to the request has been made in a timely manner. Unless expressly provided otherwise elsewhere in this contract, the production of data, information, or records under this paragraph will be at no additional cost to the Government.

9. Incident Response

a. Notification - In the event of any violation or computer security incident, the Contractor shall promptly notify the Chief Information Security Officer or the agency IT Security Officer.

b. Incident Data Preservation - In the event of any suspected violation of Federal laws and regulations such as illegal activity, computer security incidents, violations of Agency policy, malicious or otherwise prohibited use, (as defined in NIST Special Publication 800-61, Computer Security Incident Handling Guide), including but not limited to those constituting an actual or potential threat or hazard to the integrity, availability, or confidentiality of agency information in the possession or under the control of the Contractor (or subcontractor), or to the function of information systems operated by the Contractor (or subcontractor) in the performance of this contract, the Contractor (or subcontractor) shall preserve such data, records, logs and other evidence which are reasonably necessary to conduct a thorough investigation of the computer security incident.

c. Notification to Inspector General - If an incident is determined to be actual or suspected criminal activity, the Chief Information Security Officer will make the determination to notify the agency’s Office of the Inspector General (OIG).

(End of Clause)

NSF 110 Electronic Invoicing and Payment Requirements – Invoice Processing Platform (IPP) (FEB 2019)

Payment requests by the Contractor shall be submitted for reimbursement in the manner and format described herein.

"Payment request" means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in FAR 32.905(b), “Content of Invoices”, and all applicable payment clauses and provisions included in this contract.

Invoices must be submitted electronically through the U.S. Department of the Treasury’s Invoice Processing Platform System (IPP). The IPP website address is: https://www.ipp.gov. If you have multiple contracts with NSF, you cannot reuse the same invoice number when invoicing under different contracts. Each invoice number from your organization must be different. (When searching for your PO in the system, please use the abbreviated form. For example, instead of “NSFDACS17T1234”, please use “17T1234”.)

If you are not already enrolled, please go to https://www.ipp.gov and click on the “Vendors – Enroll Now” button for instructions on how to enroll.

Contractor assistance with enrollment can be obtained by contacting the IPP Customer Support Helpdesk via e-mail: IPPCustomerSupport@fiscal.treasury.gov or by phone: (866) 973-3131.

If any contract deliverables are rejected for failure to conform to the technical requirements of the contract or are otherwise unacceptable, the provisions of this clause will apply only to delivery of the acceptable contract deliverables, unless otherwise determined by the Contracting Officer.

All payments for proper invoices will be made via Electronic Fund Transfer (EFT).

Contractors that are small businesses under the appropriate NAICS code for this contract are permitted to request accelerated payments in accordance with the OMB Memorandum, Accelerating Payments to Small Businesses for Goods and Services, dated September 14, 2011. Requests for accelerated payments shall be made by typing “Small Business Invoice” in the Comments field of your IPP invoice screen. Per the OMB Memorandum, Accelerating Payments to Small Businesses for Goods and Services, dated September 14, 2011, the accomplishment of accelerated payments to small businesses is a goal and not a guarantee.

If the Contractor is unable to comply with the requirement to use IPP for submission of invoices, the Contractor must submit a waiver request in writing to the Contracting Officer with its proposal or quotation. The Contractor may submit payment requests using other than IPP only when the Contracting Officer expressly authorizes alternate procedures in writing.

Payment assistance for small businesses is available from the NSF Office of Small and Disadvantaged Business Utilization (OSDBU) (see https://www.nsf.gov/about/contracting/osdbu.jsp).

(End of Clause) https://www.ipp.gov/ https://www.ipp.gov/ mailto:IPPCustomerSupport@fiscal.treasury.gov https://www.nsf.gov/about/contracting/osdbu.jsp https://www.nsf.gov/about/contracting/osdbu.jsp https://www.nsf.gov/about/contracting/osdbu.jsp

NSF 140 NSF Task-Order and Delivery-Order Ombudsman (OCT 2018)

(a) A NSF Task-Order and Delivery-Order Ombudsman (Ombudsman) has been appointed to review complaints from contractors related to task-orders and delivery orders executed under procedures set forth in FAR 16.505 and ensure they are afforded a fair opportunity to be considered, consistent with the procedures in the applicable contract. The Ombudsman has no authority to substantively review complaints that relate to matters beyond 41 U.S.C § 4106(g) and/or FAR 16.505(b)(8). The existence of the Ombudsman does not affect the authority of the Contracting Officer, selection official, or contracting officer representative. Further, the Ombudsman does not participate in the evaluation of proposals, the source selection process, or the adjudication of protests or formal contract disputes. The Ombudsman may refer the party to another official who can resolve the concern.

(b) Before consulting with the Ombudsman, interested parties must first address their concerns, issues, disagreements, and/or recommendations to the Contracting Officer for resolution. Consulting the Ombudsman does not alter or postpone the timelines for any other processes (e.g., agency level bid protests, GAO bid protests, requests for debriefings, employee-employer actions).

(c) If resolution cannot be made by the Contracting Officer, concerned parties may contact the Ombudsman. When contacting the ombudsman, the interested party must include the IDIQ/GWAC number and the NSF RFQ or order number. If this information is not included in the communication, the vendor will not receive ombudsman consideration. The contact information for the Ombudsman may be found at: https://www.nsf.gov/bfa/dcca/ombud.jsp.

(d) The Ombudsman has no authority to render a decision that binds the agency.

(e) Do not contact the Ombudsman to request copies of the solicitation, verify offer due date, or clarify technical requirements. Such inquiries shall be directed to the Contracting Officer.

(End of clause)

NSF 150 NSF Systems Subject to Privacy Act Restrictions (AUG 2013)

Performance of work by the Contractor may require access to and operation of the following NSF system of records:

a. eJacket

b. iTRAK

This system of records is subject to the requirements of the Privacy Act of 1974 (5 U.S.C. 552a) and applicable NSF regulations governing their use. Violation of the Act may involve the imposition of criminal penalties and/or civil sanctions.

(End of clause)

NSF 230 Performance Evaluation System (SEPT 2014)

NSF utilizes the Department of Defense's (DOD) web-based Contractor Performance Assessment Reporting System (CPARS) to provide Contractor performance evaluations. Within 15 days of contract award, the Contractor shall notify the Contracting Officer (CO) of the name(s) and e-mail address(es) of https://www.nsf.gov/bfa/dcca/ombud.jsp the Contractor Representative(s) that need to be assigned in CPARS by the NSF CPARS Focal Point. The contractor is responsible for (1) updating the Contractor Representative information to the CO if and when it changes during the term of the contract and (2) reviewing and commenting on proposed ratings and remarks within the required 60 calendar days from receipt of notification of the availability of a rating for review from the CPARS system for all evaluations forwarded in the system by the Government Assessing Official, who is the CO. If the Contractor Representative sends comments within the first 14 days following the Assessing Official’s signature date and the Assessing Official or Reviewing Official closes the evaluation, the evaluation will become available in the Past Performance Information Retrieval System - Report Card (PPIRS-RC) within one day. On day 15 following the Assessing Official’s evaluation signature date, the evaluation will become available in PPIRS-RC with or without Contractor Representative comments and whether or not it has been closed by the Assessing Official or Reviewing Official. If no Contractor Representative comments have been sent and the evaluation has not been closed, it will be marked as “Pending” in PPIRS-RC. If the Contractor Representative sends comments at any time prior to 61 days following the Assessing Official’s evaluation signature date, those comments will be reflected in PPIRS-RC within one day. On day 61 following the Assessing Official’s evaluation signature date, the Contractor Rep will be “locked out” of the evaluation and may no longer send comments. Reference material concerning CPARS, including the CPARS User Manual and Guidance for CPARS, is available at the CPARS website which is at http://www.cpars.gov/main/refmatl.htm.

(End of Clause)

NSF 250 Restrictions Against Disclosure of Information (JAN 2014)

(a) The Contractor agrees that it will take such measures as are necessary to restrict access to applicant and panel records, as well as any other information related to work pursuant to this contract (including, but not limited to, any information relating to legal, policy, program, operational or other issues, whether concerning existing, proposed or contemplated legislation, regulations, policy issuances or similar matters or otherwise) to those employees and/or subcontractors of the Contractor needing such information to perform the work required there under, i.e., on a "need-to-know" basis. This Clause does not apply to information which has been released to the public by NSF or which is available to the public other than by the Contractor's breach of this Agreement.

(b) The Contractor agrees to keep the restricted information in the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .