EIR_Combined_Synopsis_Solicitation.pdf

PDF 128 KB Posted

Attached to
NIH Consulting Entrepreneur Services Federal contract opportunity
Solicitation number
NHLBI-CSB-HL-2017-036-JML
Issued by
Department of Health and Human Services National Institutes of Health

About this file

NIH Consulting Entrepreneur Services RFQ.

View the file

Other files for this federal contract opportunity

Other files attached to NIH Consulting Entrepreneur Services, newest first.
File Type Posted
EIR_-_RFQ_Questions.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

COMBINED SYNOPSIS / SOLICITATION

(1) Action Code: Combined Synopsis / Solicitation

(2) Date: December 28, 2016

(3) Year: FY17

(4) Contracting Office Zip Code: 20892

(5) Classification Code: R499

(6) Contracting Office Address: 6701 Rockledge Drive, RKL2, Rm 6151, Bethesda, MD 20892

(7) Subject/Title: NIH Consulting Entrepreneur Services

(8) Proposed Solicitation Number: NHLBI-CSB-HL-2017-036-JML

(9) Closing Response Date: January 18, 2017

(10) Contact Point(s): Jonathan M. Lear, Contracting Officer and Kristi Cooper, Contracting Officer

(11) Description: See below for the following description:

(i) This is a combined synopsis/solicitation for commercial services prepared in accordance with the format in Subpart 12.6 as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotations are being requested and a written solicitation will not be issued.

(ii) The solicitation number is NHLBI-CSB-HL-2017-036-JML and is issued as a request for quotation (RFQ).

(iii) The solicitation/contract will include all applicable provisions and clauses in effect through

Federal Acquisition Circular (FAC) 2005-92-1 (December 19, 2016).

(iv) The North American Industry Classification System (NAICS) code applicable to this requirement is 541690 with a size standard of $15.0M. This solicitation is set aside for small businesses. This acquisition is being conducted using Simplified Acquisition Procedures in accordance with FAR Part 13.5.

(v) The National Institutes of Health (NIH), National Heart, Lung, and Blood Institute (NHLBI) intends to award a time and materials contract for services in accordance with the following information:

Statement of Work

NIH Consulting Entrepreneur Services

Background Information

The National Heart, Lung, and Blood Institute (NHLBI) Office of Translational Alliances & Coordination (OTAC), facilitates identification of emerging areas of translational opportunities and provides functional integration by developing interdependent teams that leverage resources and intellect across the NHLBI, and with other ICs, agencies, and organizations. To achieve these goals, OTAC (1) works across the NHLBI extramural and intramural programs to develop SBIR/STIR initiatives, and serves as the central point of contact for the NHLBI SBIR/STIR program; (2) provides business development and regulatory expertise to both the NHLBI extramural program staff and the external small business and academic communities; and (3) develops and implements strategies to actively engage public, private, and other federal agencies in developing the commercial potential of federally funded discoveries and innovations.

Purpose and Objectives

The NHLBI is seeking services from a contractor with experienced innovation and commercialization professionals who have worked extensively with the private sector.

The contractor shall have specialized expertise in the commercialization of biomedical innovation, increasing access to early-stage funding, and moving inventions and ideas from lab to market. The contractor’s expertise should focus on related industries that drive the research innovation economy, including biotechnology, pharmaceutical, medical devices, and health informatics. The contractor shall have established relationships with a variety of corporate, private, and angel investor groups that are active in the biomedical economy.

The contractor shall also demonstrate experience with federal technology transfer programs including the Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) assistance programs. Previous experience supporting Entrepreneur-In-Residence (EIR) or similar programs at the NIH is highly desirable.

Period of Performance

The period of performance for this contract is from February, 2017 and continuing for eighteen

(18) months thereafter, with one additional option period of eighteen (18) months. The recruitment of Consultant Entrepreneurs by the contractor may be staggered across the contract according to the business needs of the participating institutes.

Place of Performance

The work shall be performed at the government’s site(s). The NHLBI and/or other NIH Institutes and Centers (IC’s) may, according to the government’s need, retain the services of the contractor to provide one or more consultant personnel within their respective offices.

Tasks to be Performed

Contractor Responsibilities:

The contractor shall recruit and retain the services of up to six personnel as required by the government to: 1) act as full-time Consulting Entrepreneur(s) (aka EIRs) in each participating NIH institute or center; 2) facilitate collaboration between the NIH and leaders from the biomedical industry; 3) provide the agency with the private sector perspective on imperatives for innovation and commercialization in research and development; and 4) educate NIH scientists, NIH funded academic and small business innovators on commercialization best practices.

In order to successfully work across the science-business-regulatory interface, the contractor shall recruit EIR candidates that have a combination of multidisciplinary biomedical research experience; extensive biomedical technology development and commercialization experience;

knowledge of regulatory aspects; and business and product development expertise. The contractor shall also work collaboratively with participating institutes and centers to identify the additional skills and qualifications commensurate with the scientific and business needs of the specific institute or institutes they are recruited to serve. These qualifications will be conveyed to the contractor on a case-by- case basis.

In addition to recruiting and retaining qualified candidates to serve at the discretion of the IC business owners, the contractor shall budget for and manage the travel and accommodations for each consultant to attend up to six national meetings per year.

At the end of the base period of performance, and any option period thereafter, the contractor shall deliver a report, summarizing the program outcomes, providing best practices and lessons learned from individual projects, and providing recommendations on how best practices may be disseminated across the NIH.

The contractor shall submit monthly invoices tracking hours, rates, and associated indirect costs for each consultant for both the billing period and the cumulative amount.

Consultant Entrepreneur Responsibilities:

The Consultant Entrepreneurs shall be engaged in business planning and outreach coordination for a full range of cross-cutting small business technology development projects and activities in participating ICs, including providing strategic guidance to start-up companies, evaluating opportunities for new ventures, and leveraging NIH resources to provide information, intelligence, and insights that drive critical business decisions for research innovations.

The consultants shall be involved in developing effective scientific collaborations between federal agencies, industry including small businesses, and the private sector to:

- Facilitate access to NIH's research infrastructure and technology resources;

- Identify opportunities for collaboration with both NIH intramural and extramural scientists;

- Provide strategic advice to start-up companies, by evaluating opportunities for new ventures, and providing information, intelligence, and insights that drive critical business decisions for research innovations;

- Interface with private industry on the basis of specific technology areas to build partnerships for NIH funded advanced technology projects;

- Plan trans-NIH advanced technology programs with the extramural scientific community and implement and manage these broad-cross cutting strategic initiatives; and,

- Foster effective collaborations with the NIH and private, non-profit, and other government entities.

The Consultant Entrepreneurs may be required to submit periodic reports (at a frequency to be determined by the sponsoring IC’s) on the status of projects under their stewardship. Each consultant retained under this contract may be subject to an initial evaluation period of six months, which may then be extended at the discretion of the government for part or all of the full performance period.

(vi) The place of performance will be performed at the government’s site(s).

(vii) The FAR Provision 52.212-1, Instructions to Offerors – Commercial Items applies to this acquisition and is hereby incorporated by reference. All Federal Acquisition Regulation (FAR) clauses may be viewed at http://acquisition.gov/comp/far/index.html.

(viii) The FAR Provision 52.212-2, Evaluation – Commercial Items applies to the acquisition and is hereby incorporated by reference.

Evaluation of Quotations

The technical approach is the most important item in the evaluation of the contractor’s capability to perform the desired services. Therefore, the approach must present sufficient information to reflect a thorough understanding of the work requirements and a detailed technical approach for achieving project objectives as set forth in the SOW.

The technical approach may NOT contain any references to price-cost. However, resource information, such as data concerning proposed other direct costs, must be contained in the technical approach so that contractor’s understanding of the scope of work may be evaluated.

The award will be made on a competitive best value basis, using the “tradeoff’ approach among price-cost and non-price-cost factors. The Government may elect to award to other than the lowest priced offeror, or other than the highest rated non-price quote. In either case, a tradeoff will be conducted. The government reserves such right of flexibility in conducting the evaluation as necessary to assure an award with the contractor providing the best value to the government.

1. Understanding of the Requirement and Adequacy of the Proposed Approach 30 Points

Demonstrated understanding of the requirement, as outlined in the Statement of Work, as it relates to consistency of goals, objectives, purposes, and compliance with the program requirements. Understanding of the goals and objectives of the NIH with respect to the Consultant Entrepreneur responsibilities, as outlined in the Statement of Work.

2. Qualifications and Experience of the Proposed Personnel 50 Points

Adequacy of the proposed staff (including consultants proposed in writing but not yet working for the organization). Demonstrated experience of the proposed staff. Demonstrated ability of the company to provide consultants that are appropriate to perform the work as described in the Statement of Work.

Demonstrated ability to recruit consultants with the scientific knowledge and business expertise that are required to provide consultant entrepreneur services.

3. Corporate Experience and Resources 20 Points

Demonstrated experience and resources of the organization to meet the goals and objective of the work outlined in the statement of work. Demonstrated successful past performance in planning and conducting entrepreneurial consulting programs. Adequacy of facilities, management systems, conflict of interest policies, etc. for accomplishing the project goals and objectives.

Adequacy of plans for ensuring the security and confidentiality of project materials and data, including electronic data, that may be made available to the Consulting Entrepreneurs. Adequacy of risk mitigation strategies.

http://acquisition.gov/comp/far/index.html

Past Performance Factor

An evaluation of schedule contractors’ past performance information will be documented prior to any communications with the schedule contractor. However, a past performance evaluation will not be conducted on any schedule contractor whose technical approach is technically unacceptable.

The evaluation will be based on information obtained from references provided by the offeror, other relevant past performance information obtained from other sources known to the Government, and any information supplied by the offeror concerning problems encountered on the identified contracts and corrective action taken.

The Government will assess the relative risks associated with each offeror. Performance risks are those associated with an offeror's likelihood of success in performing the acquisition requirements as indicated by that offeror's record of past performance.

The assessment of performance risk is not intended to be the product of a mechanical or mathematical analysis of an offeror's performance on a list of contracts but rather the product of subjective judgment by the Government after it considers all available and relevant information.

When assessing performance risks, the Government will focus on the past performance of the offeror as it relates to all acquisition requirements, such as the offeror's record of performing according to specifications, including standards of good workmanship; the offeror's record of controlling and forecasting costs; the offeror's adherence to contract schedules, including the administrative aspects of performance; the offeror's reputation for reasonable and cooperative behavior and commitment to customer satisfaction; and generally, the offeror's business-like concern for the interest of the customer.

The Government will consider the currency and relevance of the information, source of the information, context of the data, and general trends in the offeror's performance.

The lack of a relevant performance record may result in an unknown performance risk assessment, which will neither be used to the advantage nor disadvantage of the offeror.

The following rating method shall be used in the evaluation of past performance information:

i. +2 Excellent - Based on the offeror's performance record, no doubt exists that the offeror will successfully perform the required effort.

Sources of information are consistently firm in stating that the offeror's performance was superior and that they would unhesitatingly do business with the offeror again.

ii. +1 Good - Based on the offeror's performance record, little doubt exists that the offeror will successfully perform the required effort.

Sources of information state that the offeror's performance was good, better than average, etc., and that they would do business with the offeror again.

iii. None - No past performance history identifiable.

iv. -1 Marginal - Based on the offeror's performance record, some doubt exists that the offeror will successfully perform the required effort.

Sources of information make unfavorable reports about the offeror's performance and express concern about doing business with the offeror again.

v. -2 Poor - Based on the offeror's performance record, serious doubt exists that the offeror will successfully perform the required effort.

Sources of information consistently stated that the offeror's performance was entirely unsatisfactory and that they would not do business with the offeror again.

The schedule contractors shall submit the following information as part of their quotation:

A list of the last three (3) delivery or task orders and / or contracts completed during the past three (3), years and the last three (3) delivery or task orders and / or contracts awarded currently in process that are similar in nature to the RFQ’s work scope. Delivery or task orders and / or contracts listed may include those entered into by the Federal Government, agencies of state and local governments and commercial concerns. Schedule contractors that are newly formed entities without prior delivery or task orders and / or contracts should list contracts and subcontracts as required above for all key personnel.

Include the following information for each delivery or task orders and / or contracts or subcontracts: Name of Contracting Organization;

(a) Contract Number (for subcontracts, provide the prime contract number and the subcontract number);

(b) Contract Type;

(c) Total Contract Value;

(d) Description of Requirement;

(e) Contracting Officer's Name and Telephone Number;

(f) Program Manager's Name and Telephone Number; and

(g) North American Industry Classification System(NAICS) Code

The schedule contractor may provide information on problems encountered on the identified contracts and the schedule contractor's corrective actions.

Each schedule contractor will be evaluated on its performance under existing and prior contracts for similar products or services. The Government is not required to contact all references provided by the schedule contractor. Also, references other than those identified by the schedule contractor may be contacted by the Government to obtain additional information that will be used in the evaluation of the schedule contractor's past performance.

Cost / Price Evaluation

Price-cost will be evaluated separately from past performance and other non-price-cost factors, and will be evaluated for fairness and reasonableness. For a price to be reasonable, it must represent a price to the government that a prudent person would pay when consideration is given to prices in the market. The total evaluated price-cost will be evaluated for reasonableness in terms of consistency with labor categories; level of effort, in that the proposed labor mix and labor hours are based on reasonable assumptions; and consistency with the technical approach, in that the prices are consistent with and reflect the proposed staffing requirement for all years.

Although technical factors are of paramount consideration in the award, cost/price is also important to the overall contract award decision. All evaluation factors other than cost or price, when combined, are significantly more important than cost or price. The Government intends to make an award(s) to that offeror whose quotation provides the best overall value to the Government.

(ix) In accordance with FAR clause 52.212-3, Offeror Representations and Certifications –

Commercial Items, offerors must complete annual representations and certifications on-line at www.sam.gov. If paragraph (j) of the provision applies, a written submission is required.

(x) FAR clause 52.212-4, Contract Terms and Conditions – Commercial Items applies to this acquisition.

Addendum to FAR 52.212-4

(1) Option Provisions

It is anticipated the award from this solicitation will contain option provision(s) in accordance with FAR Clause 52.217-4 – Evaluation of Options Exercised at Time of Contract Award (June 1988) and FAR Clause 52.217-6 – Option for Increased Quantity (March 1989), the Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement, except when it is determined in accordance with FAR 17.206(b) not to be in the Government's best interests. Evaluation of options will not obligate the Government to exercise the option(s).

(2) Contracting Officer’s Representative (COR)

Name [To be completed in the award document] Telephone:

FAX:

E-mail

a. The Contracting Officer's Representative (COR) will represent the Government for the purpose of this contract.

b. The COR is responsible for: (1) monitoring the Contractor's technical progress, including the surveillance and assessment of performance and recommending to the Contracting Officer changes in requirements; (2) interpreting the statement of work and any other technical performance requirements; (3) performing technical evaluation as required; (4) performing technical inspections and acceptances required by this contract; and (5) assisting in the resolution of technical problems encountered during performance.

c. The alternate COR is responsible for carrying out the duties of the COR only in the event that the COR can no longer perform his/her duties as assigned.

http://www.sam.gov/

d. The Contracting Officer is the only person with authority to act as agent of the Government under this contract. Only the Contracting Officer has authority to: (1) direct or negotiate any changes in the statement of work; (2) modify or extend the period of performance; (3) change the delivery schedule; (4) authorize reimbursement to the Contractor for any costs incurred during the performance of this contract; or (5) otherwise change any terms and conditions of this contract.

e. The Government may unilaterally change the COR designation.

(3) Post Award Evaluation of Contractor Performance

Contractor Performance Evaluations

Interim and final evaluations of Contractor performance will be prepared on this contract in accordance with FAR Subpart 42.15. The final performance evaluation will be prepared at the time of completion of work. In addition to the final evaluation, interim evaluations will be prepared annually prior to the exercise of options. Interim evaluations will not be prepared for awards with a period of performance of less than 18-months. Interim evaluations will be prepared annually for awards greater than 18-months.

Interim and final evaluations will be provided to the Contractor as soon as practicable after completion of the evaluation. The Contractor will be permitted thirty days to review the document and to submit additional information or a rebutting statement. If agreement cannot be reached between the parties, the matter will be referred to an individual one level above the Contracting Officer, whose decision will be final.

Copies of the evaluations, Contractor responses, and review comments, if any, will be retained as part of the contract file, and may be used to support future award decisions.

Electronic Access to Contractor Performance Evaluations

Contractors may access evaluations through a secure Web site for review and comment at the following address: http://www.cpars.gov.

(4) Key Personnel

The key personnel specified in this contract are considered to be essential to work performance. At least 30 days prior to diverting any of the specified individuals to other programs or contracts (or as soon as possible, if an individual must be replaced, for example, as a result of leaving the employ of the Contractor), the Contractor shall notify the Contracting Officer and shall submit comprehensive justification for the diversion or replacement request (including proposed substitutions for key personnel) to permit evaluation by the Government of the impact on performance under this contract. The Contractor shall not divert or otherwise replace any key personnel without the written consent of the Contracting Officer. The Government may modify the contract to add or delete key personnel at the request of the Contractor or Government. (End of Clause)

The following individual(s) is/are considered to be essential to the work being performed hereunder: [To be completed in the award document] http://www.cpars.gov./

(5) Confidentiality of Information

Confidential information, as used in this article, means information or data of a personal nature about an individual or proprietary information or data submitted by, or pertaining to, an institution or organization.

The Contracting Officer and the Contractor may, by mutual consent, identify elsewhere in this contract specific information and/or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential. Similarly, the Contracting Officer and the Contractor may, by mutual consent, identify such confidential information from time to time during the performance of the contract. Failure to agree will be settled pursuant to the "Disputes" clause.

If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, the Contractor will follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

Confidential information, as defined in paragraph (a) of this article, shall not be disclosed without the prior written consent of the individual, institution, or organization.

Whenever the Contractor is uncertain with regard to the proper handling of material under the contract, or if the material in question is subject to the Privacy Act or is confidential information subject to the provisions of this article, the Contractor should obtain a written determination from the Contracting Officer prior to any release, disclosure, dissemination, or publication.

Contracting Officer’s determination will reflect the result of internal coordination with appropriate program and legal officials.

The provisions of paragraph (d) of this article shall not apply to conflicting or overlapping provisions in other Federal, State or local laws.

The following information is covered by this article: [TBD]

(6) Non-Personal Services and Inherently Government Functions

a. Pursuant to FAR 37.1, no personal services shall be performed under this contract. All work requirements shall flow only from the Contracting Officer’s Representative (COR) to the Contractor’s Project Manager. No Contractor employee will be directly supervised by the Government. All individual employee assignments, and daily work direction, shall be given by the applicable employee supervisor. If the Contractor believes any Government action or communication has been given that would create a personal services relationship between the Government and any Contractor employee, the Contractor shall promptly notify the Contracting Officer of this communication or action.

b. Pursuant to FAR 7.5, the Contractor shall not perform any inherently governmental actions under this contract. No Contractor employee shall hold him or herself out to be a

Government employee, agent, or representative. No Contractor employee shall state orally or in writing at any time that he or she is acting on behalf of the Government. In all communications with third parties in connection with this contract, Contractor employees shall identify themselves as Contractor employees and specify the name of the company for which they work. In all communications with other Government contractors in connection with this contract, the Contractor employee shall state that they have no authority to in any way change the contract and that if the other contractor believes this communication to be a direction to change their contract, they should notify the Contracting Officer for that contract and not carry out the direction until a clarification has been issued by the Contracting Officer

(7) Travel

Arrangements for, and costs of all travel, transportation, meals, lodging, and incidentals are the responsibility of the contractor. Travel costs, including lodging and meals, shall be incurred and billed in accordance with FAR Part 31. Costs for these expenses will be reviewed, certified, and approved by the Contracting Officer’s Representative (COR). All travel and transportation shall utilize commercial sources and carriers. The government will not pay for business class or first-class travel.

(8) Non-Disclosure / Non-Use Agreement

The contractor shall ensure that a Non-Disclosure Statement is signed by all staff assigned to or performing on this contract before performing any work, including all subcontractors and consultants. The contractor shall also ensure that all staff understand and adhere to the terms of the non-disclosure statement protecting the procurement sensitive information of the government and the proprietary information of other contractors.

(xi) FAR clause 52.212-5, Contract Terms and Conditions Required to Implement Statutes or

Executive Orders – Commercial Items, including the following subparagraphs, apply to this acquisition:

52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards;

52.219-28, Post Award Small Business Program Representation;

52.222-3, Convict Labor;

52.222-19, Child Labor—Cooperation with Authorities and Remedies;

52.222-21, Prohibition of Segregated Facilities;

52.222-26, Equal Opportunity;

52.222-36, Affirmative Action for Workers with Disabilities;

52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving;

52.225-1, Buy American Act – Supplies;

52.225-13, Restrictions on Certain Foreign Purchases; and, 52.232-33, Payment by Electronic Funds Transfer – Central Contractor Registration.

(xii) The following Information Systems Security Clauses are applicable to this award:

HHS-Controlled Facilities and Information Systems Security

To perform the work specified herein, Contractor personnel are expected to have routine (1) physical access to an HHS-controlled facility; (2) physical access to an HHS-controlled information system; (3) access to sensitive HHS data or information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

To gain routine physical access to an HHS-controlled information system, and/or access to sensitive data or information, the Contractor and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; Office of Management and Budget Memorandum (M-05- 24); and Federal Information Processing Standards Publication (FIPS PUB) Number 201; and with the personal identity verification and investigations procedures contained in the following documents:

HHS-OCIO Information Systems Security and Privacy Policy (http://www.hhs.gov/ocio/policy/#Security )

HHS HSPD-12 Policy Document, v. 2.0 ( http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf )

Information regarding background checks/badges ( http://idbadge.nih.gov/background/index.asp )

Position Sensitivity Levels:

This contract will entail the following position sensitivity levels:

[ ] Level 6: Public Trust - High Risk. Contractor/subcontractor employees assigned to Level 6 positions shall undergo a Suitability Determination and Background Investigation (MBI).

[ ] Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

[X] Level 1: Non-Sensitive. Contractor/subcontractor employees assigned to Level 1 positions shall undergo a Suitability Determination and National Check and Inquiry Investigation (NACI).

The personnel investigation procedures for Contractor personnel require that the Contractor prepare and submit background check/investigation forms based on the type of investigation required. The minimum Government investigation for a non-sensitive position is a National Agency Check and Inquiries (NACI) with fingerprinting. More restricted positions - i.e., those above non-sensitive, require more extensive documentation and investigation.

The Contractor shall submit a roster, by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under the contract who will develop, have the ability to access and/or maintain a Federal Information System(s). The roster shall be submitted to the Contracting Officer's Representative (COR), with a copy to the Contracting Officer, within 14 calendar days after the effective date of the contract. The http://www.hhs.gov/ocio/policy/%23Security%20 http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf http://idbadge.nih.gov/background/index.asp

Contracting Officer shall notify the Contractor of the appropriate level of suitability investigations to be performed. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at:

https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15- 12.xlsx .

Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.

The Contractor shall notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the contract and if they have previously been the subject of national agency checks or background investigations.

All contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract.

Contractors may begin work after the fingerprint check has been completed.

Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-

14. Accordingly, the Contractor shall ensure that any additional employees whose names it submits for work under this contract have a reasonable chance for approval.

Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the contract price of no more that the cost of the additional investigation(s).

The Contractor shall include language similar to this "HHS Controlled Facilities and Information Systems Security" language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.

Within 7 calendar days after the Government's final acceptance of the work under this contract, or upon termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.

Standard for Security Configurations, HHSAR 352.239-70, (January 2010)

The Contractor shall configure its computers that contain HHS data with the applicable Federal Desktop Core Configuration (FDCC) (see http://nvd.nist.gov/fdcc/index.cfm ) and ensure that its computers have and maintain the latest operating system patch level and anti-virus software level.

Note: FDCC is applicable to all computing systems using Windows XPTM and Windows https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx http://nvd.nist.gov/fdcc/index.cfm

VistaTM, including desktops and laptops - regardless of function - but not including servers.

The Contractor shall apply approved security configurations to information technology (IT) that is used to process information on behalf of HHS. The following security configuration requirements apply:

The Contractor shall ensure IT applications operated on behalf of HHS are fully functional and operate correctly on systems configured in accordance with the above configuration requirements.

The Contractor shall use Security Content Automation Protocol (SCAP)-validated tools with FDCC Scanner capability to ensure its products operate correctly with FDCC configurations and do not alter FDCC settings - see http://scap.nist.gov/validation . The Contractor shall test applicable product versions with all relevant and current updates and patches installed. The Contractor shall ensure currently supported versions of information technology products met the latest FDCC major version and subsequent major versions.

The Contractor shall ensure IT applications designed for end users run in the standard user context without requiring elevated administrative privileges.

The Contractor shall ensure hardware and software installation, operation, maintenance, update, and patching will not alter the configuration settings or requirements specified above.

The Contractor shall (1) include Federal Information Processing Standard (FIPS) 201-compliant ( http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf ), Homeland Security Presidential Directive 12 (HSPD-12) card readers with the purchase of servers, desktops, and laptops; and (2) comply with FAR Subpart 4.13, Personal Identity Verification.

The Contractor shall ensure that its subcontractors (at all tiers) which perform work under this contract comply with the requirements contained in this clause.

Standard for Encryption language, HHSAR 352.239-71, (January 2010)

The Contractor shall use Federal Information processing Standard (FIPS) 140-2-compliant encryption (Security) Requirements for Cryptographic Module, as amended) to protect all instances of HHS sensitive information during storage and transmission. (Note: The Government has determined that HHS information under this contract is considered "sensitive" in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems, dated February 2004).

The Contractor shall verify that the selected encryption product has been validated under the Cryptographic Module Validation Program (see http://csrc.nist.gov/cryptval/ ) to confirm compliance with FIPS 140-2 (as amended). The Contractor shall provide a written copy of the validation documentation to the Contracting Officer and the Contracting Officer's Technical Representative.

The Contractor shall use the Key Management Key (see FIPS 201, Chapter 4, as amended) on the HHS personal identification verification (PIV) card; or alternatively, the Contractor shall establish and use a key recovery mechanism to ensure the ability for authorized personnel to decrypt and recover all encrypted information (see http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf ). The Contractor shall notify http://scap.nist.gov/validation http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf http://csrc.nist.gov/cryptval/ http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf the Contracting Officer and the Contracting Officer's Technical Representative of personnel authorized to decrypt and recover all encrypted information.

The Contractor shall securely generate and manage encryption keys to prevent unauthorized decryption of information in accordance with FIPS 140-2 (as amended).

The Contractor shall ensure that this standard is incorporated into the Contractor's property management/control system or establish a separate procedure to account for all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive HHS information.

The Contractor shall ensure that its subcontractors (all tiers) which perform work under this contract comply with the requirements contained in this clause.

Security Requirements For Federal Information Technology Resources, HHSAR 352.239- 72, (January 2010)

a. Applicability . This clause applies whether the entire contract or order (hereafter "contract"), or portion thereof, includes information technology resources or services in which the Contractor has physical or logical (electronic) access to, or operates a Department of Health and Human Services (HHS) system containing, information that directly supports HHS' mission. The term "information technology (IT)", as used in this clause, includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services) and related resources. This clause does not apply to national security systems as defined in FISMA.

b. Contractor responsibilities . The Contractor is responsible for the following:

1. Protecting Federal information and Federal information systems in order to ensure their -

a. Integrity, which means guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity;

b. Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and

c. Availability, which means ensuring timely and reliable access to and use of information.

2. Providing security of any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor, regardless of location, on behalf of HHS.

3. Adopting, and implementing, at a minimum, the policies, procedures, controls and standards of the HHS Information Security Program to ensure the integrity, confidentiality, and availability of Federal information and Federal information systems for which the Contractor is responsible under this contract or to which it may otherwise have access under this contract. The HHS Information Security Program is outlined in the HHS Information Security Program Policy, which is available on the HHS Office of the Chief Information Officer's (OCIO) Web site.

c. Contractor security deliverables . In accordance with the timeframes specified, the

Contractor shall prepare and submit the following security documents to the Contracting Officer for review, comment, and acceptance:

1. FIPS 199 Standards for Security Categorization of Federal Information and

Information Systems Assessment (FIPS 199 Assessment) - due within 30 days after contract award. The FIPS 199 Assessment shall be consistent with the cited NIST standard. After resolution of any comments by the Government on the draft FIPS 199 Assessment, the Contracting Officer shall accept the FIPS 199 Assessment and incorporate the Contractor's final version into the contract.

d. Personal identity verification. The Contractor shall identify its employees with access to systems operated by the Contractor for HHS or connected to HHS systems and networks. The Contracting Officer's Representative (COR) shall identify, for those identified employees, position sensitivity levels that are commensurate with the responsibilities and risks associated with their assigned positions. The Contractor shall comply with the HSPD-12 requirements contained in "HHS-Controlled Facilities and Information Systems Security" requirements specified in the SOW/PWS of this contract.

e. Contractor and subcontractor employee training. The Contractor shall ensure that its employees, and those of its subcontractors, performing under this contract complete HHS-furnished initial and refresher security and privacy education and awareness training before being granted access to systems operated by the Contractor on behalf of HHS or access to HHS systems and networks. The Contractor shall provide documentation to the COR evidencing that Contractor employees have completed the required training.

f. Government access for IT inspection. The Contractor shall afford the Government access to the Contractor's and subcontractors' facilities, installations, operations, documentation, databases, and personnel used in performance of this contract to the extent required to carry out a program of IT inspection (to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the integrity, confidentiality, and availability, of HHS data or to the protection of information systems operated on behalf of HHS.

g. Subcontracts. The Contractor shall incorporate the substance of this clause in all subcontracts that require protection of Federal information and Federal information systems as described in paragraph (a) of this clause, including those subcontracts that -

a. Have physical or electronic access to HHS' computer systems, networks, or IT infrastructure; or

b. Use information systems to generate, store, process, or exchange data with HHS or on behalf of HHS, regardless of whether the data resides on a HHS or the Contractor's information system.

h. Contractor employment notice. The Contractor shall immediately notify the

Contracting Officer when an employee either begins or terminates employment (or is no longer assigned to the HHS project under this contract), if that employee has, or had, access to HHS information systems or data.

i. Document information. The Contractor shall contact the Contracting Officer for any documents, information, or forms necessary to comply with the requirements of this clause.

j. Contractor responsibilities upon physical completion of the contract. The Contractor shall return all HHS information and IT resources provided to the Contractor during contract performance and certify that all HHS information has been purged from Contractor-owned systems used in contract performance.

k. Failure to comply. Failure on the part of the Contractor or its subcontractors to comply with the terms of this clause shall be grounds for the Contracting Officer to terminate this contract.

(End of Clause)

Note: The NIST Special Publication SP-800-26 cited in subparagraph c.1.a.(ii) of this clause has been superseded by NIST SP 800-53A, "Guide for Assessing the Security Controls in Federal Information Systems and Organizations" for use for the assessment of security control effectiveness. See http://csrc.nist.gov/publications/PubsSPs.html to access NIST Special Publications (800 Series).

Additional NIH Requirements

SECURITY CATEGORIZATION OF FEDERAL INFORMATION AND

INFORMATION SYSTEMS (FIPS 199 Assessment)

Information Type:

[ ] Administrative, Management and Support Information:

[X] Mission Based Information: See Statement of Work

Security Categories and Levels:

Confidentiality Level: [X ] Low [ ] Moderate [ ] High Integrity Level: [X] Low [ ] Moderate [ ] High Availability Level: [X] Low [ ] Moderate [ ] High Overall Level: [X ] Low [ ] Moderate [ ] High

In accordance with HHSAR Clause 352.239-72, the contractor shall submit a FIPS 199 Assessment within 30 days after contract award. Any differences between the contractor's assessment and the information contained herein, will be resolved, and if required, the contract will be modified to incorporate the final FIPS 199 Assessment.

INFORMATION SECURITY TRAINING

In addition to any training covered under paragraph (e) of HHSAR 352.239-72, the contractor shall comply with the below training:

Mandatory Training http://csrc.nist.gov/publications/PubsSPs.html

All Contractor employees having access to (1) Federal information or a Federal information system or (2) sensitive data/information as defined at HHSAR 304.1300(a)(4), shall complete the NIH Computer Security Awareness Training course at http://irtsectraining.nih.gov/ before performing any work under this contract. Thereafter, Contractor employees having access to the information identified above shall complete an annual NIH-specified refresher course during the life of this contract. The Contractor shall also ensure subcontractor compliance with this training requirement.

The Contractor shall maintain a listing by name and title of each Contractor/Subcontractor employee working on this contract and having access of the kind in paragraph 1.a(1) above, who has completed the NIH required training. Any additional security training completed by the Contractor/Subcontractor staff shall be included on this listing. The list shall be provided to the COR and/or Contracting Officer upon request.

Role-based Training HHS requires role-based training when responsibilities associated with a given role or position, could, upon execution, have the potential to adversely impact the security posture of one or more HHS systems. Read further guidance about "NIH Information Security Awareness and Training Policy," at: https://ocio.nih.gov/InfoSecurity/Policy/Documents/Final- InfoSecAwarenessTrainPol.doc .

The Contractor shall maintain a list of all information security training completed by each contractor/subcontractor employee working under this contract. The list shall be provided to the COR and/or Contracting Officer upon request.

Rules of Behavior The Contractor shall ensure that all employees, including subcontractor employees, comply with the NIH Information Technology General Rules of Behavior ( https://ocio.nih.gov/InfoSecurity/training/Pages/nihitrob.aspx ), which are contained in the NIH Information Security Awareness Training Course http://irtsectraining.nih.gov .

PERSONNEL SECURITY RESPONSIBILITIES

In addition to any personnel security responsibilities covered under HHSAR 352.239-72, the contractor shall comply with the below personnel security responsibilities:

Commitment to Protect Non-Public Departmental Information and Data.

The Contractor, and any subcontractors performing under this contract, shall not release, publish, or disclose non-public Departmental information to unauthorized personnel, and shall protect such information in accordance with provisions of the following laws and any other pertinent laws and regulations governing the confidentiality of such information:

- 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records)

- 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information)

- Public Law 96-511 (Paperwork Reduction Act)

Each employee, including subcontractors, having access to non-public Department information under this acquisition shall complete the "Commitment to Protect Non-Public Information -http://irtsectraining.nih.gov/ https://ocio.nih.gov/InfoSecurity/Policy/Documents/Final-InfoSecAwarenessTrainPol.doc…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .