RFP_NIHDA201800362.pdf
PDF 3 MB Posted
- Attached to
- National Addiction and HIV Data Archive Program Federal contract opportunity
- Solicitation number
- NIHDA201800362
About this file
Offerors are solely responsible for submitting proposals in a timely manner. Please note that creating an account to submit may take up to three (3) business days. Please plan accordingly. Additional instructions on how to submit a proposal via eCPS can be found at https://ecps.nih.gov/home/howto and in Attachment 01.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP_Amendment_01.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OMB #0990-0115
NATIONAL INSTITUTE ON DRUG ABUSE
REQUEST FOR PROPOSAL (RFP) No. NIHDA201800362
“National Addiction and HIV Data Archive Program”
Issued by:
Lisa V. Bielen, Contracting Officer NIDA Section, Contracts Management Branch Blue Office of Acquisition, NIDA 6001 Executive Blvd., Room 4211 – MSC 9559 Bethesda, MD 20892-9559
Point of Contact: Josh Lazarus, Contract Specialist E-Mail: josh.lazarus@nih.gov Phone: 301.443.6677
FAX: 301.443.7595
DATE ISSUED: November 21st, 2018
PROPOSAL DUE: December 21st, 2018, 12:00 P.M. (Eastern Time)
The National Institute on Drug Abuse (NIDA) invites you to submit a proposal responding to the requirements of this RFP No. NIHDA201800362 for the “National Addiction and HIV Data Archive Program.”
This Request for Proposal is released under FULL AND OPEN Competition Procedures.
NIDA prepared this Request for Proposal in accordance with the Uniform Contract Format prescribed for Government Wide application by the Federal Acquisition Regulation (FAR). The Uniform Contract Format is both a Request for Proposal and a contract award document. The resulting contract will consist of Parts I, II, and III of the Uniform Contract Format.
NIDA anticipates the award of a single cost reimbursement, severable (level of effort) contract with a 1-year base period, 4 option years and option quantities. However, any contract resulting from this Request for Proposal will be funded dependent on the previous year’s performance and the availability of funds. NIDA anticipates that the period of performance of the base contract will be from April 1, 2019 through March 31, 2020. You must respond with technical and pricing proposals for the entire project and total period of performance, including the option years and the additional option tasks. You must include separate pricing for each individual option period and option quantity. Offerors shall respond with technical and cost/price proposals based on the assumptions provided in Sections C and L.
General
Part IV of the RFP contains instructions, provisions, and evaluation factors for the submission and review of proposals. Attachment 2 is a "Proposal Intent Response Sheet." Please complete this form and return it to the below address on or before 4:00 p.m. on Monday, December 3rd, 2018. The balance of Parts I, II, and III contain provisions, clauses, and special requirements which will be made a part of any resultant award. Please review these sections and consider their impact on performance, capability, technical, and cost factors as you develop your proposal. Do not fill in blanks or otherwise complete portions of Parts I, II, and III which appear to require additional information. The Government will complete these items prior to contract award and, if negotiations are conducted, will tailor those items through final negotiations.
Requests for Information (RFIs)
Requests for clarification, additional information, or correction must be made in writing to the Contracting Officer. RFIs must be submitted on or before 4:00 p.m. on Monday, December 3rd, 2018. RFIs may be submitted by e-mail to josh.lazarus@nih.gov and andrew.hotaling@nih.gov with the subject line “RFI – RFP
NIHDA201800362.”
NOTE: Site visits will not be provided.
The Technical Proposal
Offerors shall complete and attach the “Technical Proposal Cover Sheet” for each copy of their technical proposal.
It is important that you list all professional personnel and organizations named in the proposal that have any role in the proposed work. This includes your staff, subcontractors, collaborating organizations, and consultants. Show organization affiliation(s) for every person named. You may use extra sheets, as needed, following the format shown in the Technical Proposal Cover Sheet. We will use this information to ensure that no conflicts of interest exist with the selected review committee members.
Technical Proposal are detailed in Section L.2.b.
The Business Proposal
You must have an authorized organizational official sign your Business Proposal. It must contain a detailed breakdown of costs by year and individual options. For each cost category/element, provide an explanation of the basis for all costs, and provide documentation to support these costs. We direct special attention to Breakdown of Proposed Estimated Costs (plus fixed fee) w/Excel Spreadsheet contained in the Business Proposal Cost Information, Attachment 10. Please submit business proposals with a spreadsheet in this format. Use of the above format will hasten review and award. A PDF copy of the spreadsheet must be included in the Business Proposal.
Additionally, an electronic copy should be provided utilizing NIH’s Secure File Transfer program at https://secureemail.nih.gov. Do not send encrypted files.
A completed Form NIH-2043, “Proposal Summary and Data Record” must be included with the Business Proposal.
Include the e-mail addresses of both the Principal Investigator and the responsible business representative on the form. Note that in addition to telephone and fax numbers, you should include the e-mail addresses of both the Principal Investigator and the responsible business representative on the form.
The Offeror must submit its Small Business Subcontracting Plan, Travel Policy, Total Compensation Plan and Annual Report with the initial Business Proposal. See Section L.2.c. for additional detail.
Submitting a Proposal
Proposals must be submitted via the electronic Contract Proposal Submission (eCPS) website (https://ecps.nih.gov) no later than December 21st, 2018, 12:00 P.M. Eastern Time. Proposals submitted by facsimile, e-mail, or hard copy will not be accepted. An official authorized to bind your organization must sign the proposal.
Offerors are solely responsible for submitting proposals in a timely manner. Please note that creating an account to submit may take up to three (3) business days. Please plan accordingly. Additional instructions on how to submit a proposal via eCPS can be found at https://ecps.nih.gov/home/howto and in Attachment 01.
All notices related to this solicitation will be posted on FedBizOpps (https://www.fbo.gov) as well as the NIDA Contracts Home Page (https://www.drugabuse.gov/funding/funding-opportunities/nida-requests-contract-proposals-rfps). If you would like to receive e-mail notifications of updates to this solicitation, please register with FedBizOpps.
In accordance with FAR 15.306(a)(3) and FAR 52.215-1, the Government intends to evaluate proposals and award a contract without discussions. Therefore, your initial proposal should contain the best terms from cost or price and technical standpoints. The Government does, however, reserve the right to conduct discussions if the Contracting Officer determines them to be necessary.
Disclaimers
This RFP does not commit the Government to pay the costs for the preparation and submission of a proposal. The Contracting Officer is the only individual who legally can commit the Government to the expenditure of public funds in connection with this acquisition.
Any contract award for this requirement is contingent on the availability of funds (see FAR 52.232-18, Availability of Funds – April 1984).
The National Institute on Drug Abuse appreciates your interest in this RFP and looks forward to receipt of your proposal. Requests for any information concerning this RFP should be directed to Josh Lazarus, or the undersigned, at the NIDA Section, Contracts Management Branch Blue. We may be reached at (301) 443-6677;
collect calls will not be accepted. Discussions with any other individual outside the NIDA Section, Contracts Management Branch Blue should not occur.
Sincerely, Lisa V. Bielen, Contracting Officer National Institutes of Health, Office of Acquisition, NIDA
Enclosure
- 1 -
SOLICITATION
SECTION A - SOLICITATION/CONTRACT FORM
1. Requisition or other Purchase Authority: P.L. 102-321 as amended
2. Request for Proposal (RFP) Number:
NIHDA201800362
3. Issue Date:
November 21, 2018
4. Set Aside:
[X] No
[ ] Yes See Part IV Section L
5. Title : National Addiction and HIV Data Archive Program
6. ISSUED BY:
NIDA Section Contracts Management Branch, Blue Office of Acquisition National Institute on Drug Abuse National Institutes of Health 6001 Executive Blvd., Suite 4211, MSC 9559 Bethesda, Maryland 20892-9559
7. SUBMIT OFFERS TO:
See Part III, Section J, "Packaging and Delivery of the Proposals for Use with the NIH electronic Contract Proposal Submission (eCPS) Website," ATTACHMENT 1 of this Solicitation.
8. Proposals for furnishing the supplies and/or services in THE SCHEDULE will be received at the place specified in, and in the number of copies specified in Attachment 1, "Packaging and Delivery of the Proposals for Use with the NIH electronic Contract Proposal Submission (eCPS) Website," until 12:00 p.m. Eastern Standard Time on December 21, 2018. Offers will be valid for 120 days unless a different period is specified by the offeror on the Attachment entitled, "Proposal Summary and Data Record, NIH 2043.
9. This solicitation requires delivery of proposals as stated in ATTACHMENT 1, "Packaging and Delivery of the Proposals for Use with the NIH electronic Contract Proposal Submission (eCPS) Website." If proposals are required to be delivered to two different locations, the OFFICIAL POINT OF RECEIPT for determining TIMELY DELIVERY is the eCPS Website.
IF YOUR PROPOSAL IS NOT RECEIVED BY THE CONTRACTING OFFICER OR HIS DESIGNEE AT THE PLACE AND TIME SPECIFIED FOR THE OFFICE OF ACQUISITIONS, THEN IT WILL BE CONSIDERED LATE AND HANDLED IN ACCORDANCE WITH subparagraph (c)(3) of FAR Clause 52.215-1, Instructions to Offerors--Competitive Acquisition," LOCATED IN SECTION L.1. OF THIS SOLICITATION.
10. Offeror must be registered in the System for Award Management (SAM) prior to award of a contract. Offerors must access the CCR through The System for Award Management (SAM) at http://www.sam.gov
11. FOR INFORMATION CALL: Josh Lazarus, Contract Specialist
PHONE: 301-443-6677
e-MAIL: josh.lazarus@nih.gov
COLLECT CALLS WILL NOT BE ACCEPTED.
Lisa V. Bielen, Contracting Officer NIDA Section Contracts Management Branch, Blue Office of Acquisition, NIDA http://www.sam.gov
RFP Number : NIHDA201800362
- 2 -
RFP TABLE OF CONTENTS
PART I - THE SCHEDULE
SECTION A - SOLICITATION/CONTRACT FORM
SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS
SECTION C - DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
SECTION D - PACKAGING, MARKING AND SHIPPING
SECTION E - INSPECTION AND ACCEPTANCE
SECTION F - DELIVERIES OR PERFORMANCE
SECTION G - CONTRACT ADMINISTRATION DATA
SECTION H - SPECIAL CONTRACT REQUIREMENTS
PART II - CONTRACT CLAUSES
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACHMENTS
SECTION J - LIST OF ATTACHMENTS
SOLICITATION ATTACHMENTS
TECHNICAL PROPOSAL ATTACHMENTS
BUSINESS PROPOSAL ATTACHMENTS
INFORMATIONAL ATTACHMENTS
PART IV - REPRESENTATIONS AND INSTRUCTIONS
SECTION K - REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF OFFERORS
SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS
1. GENERAL INFORMATION
a. INSTRUCTIONS TO OFFERORS--COMPETITIVE ACQUISITION
b. NAICS CODE AND SIZE STANDARD
c. TYPE OF CONTRACT AND NUMBER OF AWARDS
d. LEVEL OF EFFORT
e. COMMITMENT OF PUBLIC FUNDS
f. PROMOTING EFFICIENT SPENDING
g. COMMUNICATIONS PRIOR TO CONTRACT AWARD
h. RELEASE OF INFORMATION
i. PREPARATION COSTS
j. SERVICE OF PROTEST
2. INSTRUCTIONS TO OFFERORS
a. GENERAL INSTRUCTIONS
1. Contract Type and General Clauses
2. Authorized Official and Submission of Proposal
3. Proposal Summary and Data Record (NIH-2043)
4. Separation of Technical and Business Proposals
5. Alternate Proposals
6. Evaluation of Proposals
7. Potential Award Without Discussions
8. Use of the Metric System of Measurement
9. Standards for Privacy of Individually Identifiable Health Information
10. Specific Copyright Provisions Applicable to Software Development and/or Enhancement(s)
- 3 -
11. Privacy Act - Treatment of Proposal Information
12. Selection of Offerors
13. Institutional Responsibility Regarding Investigator Conflicts of Interest
14. ROTC Access and Federal Military Recruiting on Campus
15. Past Performance Information
16. HHS SECURITY AND PRIVACY LANGUGAGE FOR INFORMATION AND IT
PROCUREMENTS
17. Electronic Information Technology Accessibility Notice, HHSAR 352.239-73 (December 2015)
18. Solicitation Provisions Incorporated by Reference
b. TECHNICAL PROPOSAL INSTRUCTIONS
1. Technical Discussions
2. Other Considerations
3. Technical Evaluation
4. Obtaining and Disseminating Biomedical Research Resources
c. BUSINESS PROPOSAL INSTRUCTIONS
1. Basic Cost/Price Information
2. Proposal Cover Sheet
3. Information Other than Cost or Pricing Data
4. Requirements for Cost or Pricing Data or Information Other than Cost and Pricing Data
5. Salary Rate Limitation
6. Small Business Subcontracting Plan
7. Mentor Protege Program, HHSAR 352.219-70
8. HUBZone Small Business Concerns
9. Total Compensation Plan
10. Other Administrative Data
11. Qualifications of the Offeror
12. Subcontractors
13. Proposer's Annual Financial Report
14. Travel Costs/Travel Policy
SECTION M - EVALUATION FACTORS FOR AWARD
1. GENERAL
2. COST/PRICE EVALUATION
3. MANDATORY QUALIFICATION CRITERIA
4. EVALUATION OF OPTIONS
5. EVALUATION OF DATA SHARING PLAN
6. TECHNICAL EVALUATION FACTORS
7. EVALUATION OF ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY- SECTION
8. PAST PERFORMANCE FACTOR
- 4 -
PART I - THE SCHEDULE
THE INFORMATION SET FORTH IN SECTION A - SOLICITATION/CONTRACT FORM, HEREIN CONTAINS IMPORTANT INFORMATION FOR ANY OFFEROR INTERESTED IN RESPONDING TO THIS SOLICITATION.
ANY CONTRACT RESULTING FROM THIS SOLICITATION WILL INCLUDE IN ITS SECTION A - SOLICITATION/ CONTRACT FORM, ACCOUNTING, APPROPRIATION AND GENERAL INFORMATION APPLICABLE TO THE
CONTRACT AWARD.
THE CONTRACT SCHEDULE SET FORTH IN SECTIONS B THROUGH H, HEREIN, CONTAINS CONTRACTUAL INFORMATION PERTINENT TO THIS SOLICITATION. IT IS NOT AN EXACT REPRESENTATION OF THE CONTRACT DOCUMENT THAT WILL BE AWARDED AS A RESULT OF THIS SOLICITATION. THE CONTRACT COST OR PRICE AND OTHER CONTRACTUAL PROVISIONS PERTINENT TO THE OFFEROR (i.e., those relating to the organizational structure [e.g., Non-Profit, Commercial] and specific cost authorizations unique to the Offeror's proposal and requiring Contracting Officer Prior Approval) WILL BE DISCUSSED IN THE NEGOTIATION PROCESS (if necessary) AND WILL BE INCLUDED IN THE RESULTANT CONTRACT. THE ENCLOSED CONTRACT SCHEDULE IS INTENDED TO PROVIDE THE OFFEROR WITH THE NECESSARY INFORMATION
TO UNDERSTAND THE TERMS AND CONDITIONS OF THE RESULTANT CONTRACT.
SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS
ARTICLE B.1. BRIEF DESCRIPTION OF SUPPLIES OR SERVICES
The core objectives for the National Addiction and HIV Data Archive Program (NAHDAP) are to continue a data archive of drug abuse and drug abuse and HIV research data, primarily archiving social science and behavioral data though other data could be included. The Contractor must demonstrate the required capabilities and in-depth knowledge in the areas listed below:
1. Recruiting drug abuse or drug abuse and HIV social science and/or transdisciplinary researchers to deposit their data by actively working with the drug abuse and HIV research field;
2. Providing technical assistance and, with Contracting Officer’s Representative (COR) approval, support to investigators either with already collected drug abuse and HIV datasets or through assistance in preparing their data for archiving;
3. Working to ensure that deposited data get maximum use, in part by devising and implementing strategies to ensure the drug abuse and HIV research fields are aware of the special topic archive and of what datasets are available for secondary analysis and by displaying the utility of this approach for addressing new research questions;
4. Providing technical assistance to users of the datasets, including organized trainings when proposed and approved, or directed by the COR;
5. Providing technical assistance to investigators at the inception of research projects, determined by the COR, to be a high priority to ensure the data can be easily and effectively archived at project completion;
6. Developing a system to prioritize datasets and apply the appropriate level of curation to high priority datasets while making others available with less curation and cost; and
7. Staying abreast of advances in the field of data archiving and integrating cutting edge strategies into the archive and implementing them when directed by the COR.
ARTICLE B.2. ESTIMATED COST - OPTION
a. The estimated cost of the Base Period of this contract is $ .
b. The fixed fee for the Base Period of this contract is $ . The fixed fee shall be paid in direct ratio to the level of effort expended; that is, the percent of fee paid shall be equal to the percent of total effort expended.
Payment shall be subject to the withholding provisions of the clauses ALLOWABLE COST AND PAYMENT and FIXED FEE referenced in the General Clause Listing in Part II, ARTICLE I.1. of this contract.
- 5 -
c. The total estimated amount of the contract, represented by the sum of the estimated cost plus the fixed fee for the Base Period is $ .
d. If the Government exercises its option pursuant to the OPTION PROVISION Article in SECTION H of this contract, the Government's total estimated contract amount represented by the sum of the estimated cost plus the fixed fee will be increased as follows:
Period of Performance Estimated Cost
Fixed Fee
Estimated Cost Plus Fixed Fee ($)
Base Period Option Period 1, Contract Year 2
Option Period 2, Contract Year 3
Option Period 3, Contract Year 4
Option Period 4, Contract Year 5
Total Base Period and Option Period(s)
ARTICLE B.3. OPTION PRICES
a. Unless the Government exercises its option pursuant to the option clause referenced in ARTICLE I.3.
ADDITIONAL CONTRACT CLAUSES, this contract consists only of the Base Period specified in the Statement of Work as defined in SECTIONS C and F, for the price set forth in ARTICLE B.2. of this contract.
b. Pursuant to FAR Clause 52.217-7 set forth in ARTICLE I.3. ADDITIONAL CONTRACT CLAUSES of this contract, the Government may, by unilateral contract modification, require the Contractor to perform the Option Quantity Task(s) specified in the Statement of Work as defined in SECTIONS C and F of this contract. If the Government exercises this/these option(s), notice must be given before the expiration date of the contract.
The estimated cost plus fixed fee of this contract will be increased as set forth in paragraph c., below. Option Quantity Task A may be exercised once during the Base Period of the contract and once during the final contract year. Option Quantity Tasks B, C, and D, may each be exercised up to (5) times during each year of the contract. Specific information regarding the time frame for this notice is set forth in the OPTION PROVISION Article in SECTION H of this contract.
c. Upon the delivery and acceptance of the Option Item described in SECTION C of the contract and identified in the schedule of charges below, the Government shall pay the Contractor the amount set forth below:
Option Quantity Task Estimated Cost ($) Fixed Fee ($) Estimated Cost Plus Fixed Fee ($)
Option Quantity Task A, Base Period
Option Quantity Task A, Final Contract Year
Option Quantity Task B, Option Quantity Task C,
- 6 -
Option Quantity Task Estimated Cost ($) Fixed Fee ($) Estimated Cost Plus Fixed Fee ($)
Base Period
Option Quantity Task D, ARTICLE B.4. PROVISIONS APPLICABLE TO DIRECT COSTS
This article will prohibit or restrict the use of contract funds, unless otherwise approved by the Contracting Officer. The following is a list of items that may be included in the resultant contract as applicable. 1) Conferences & Meetings, 2) Food for Meals, Light Refreshments & Beverages, 3) Promotional Items, 4) Acquisition, by purchase or lease, of any interest in real property; 5) Special rearrangement or alteration of facilities; 6) Purchase or lease of any item of general purpose office furniture or office equipment regardless of dollar value; 7) Travel Costs including Foreign Travel; 8) Consultant Costs; 9) Subcontract Costs; 10) Patient Care Costs; 11) Accountable Government Property; 12) Printing costs; and 13) Research Funding.
ARTICLE B.5. ADVANCE UNDERSTANDINGS
Specific elements of cost, which normally require prior written approval of the Contracting Officer before incurrence of the cost (e.g., foreign travel, consultant fees, subcontracts) will be included in this Article if the Contracting Officer has granted his/her approval prior to contract award. NIDA reserves the right to have the contracted services in this contract benefit NIDA and other components of NIH.
[Remainder of Page Intentionally Left Blank]
- 7 -
SECTION C - DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
ARTICLE C.1. STATEMENT OF WORK
a. Independently and not as an agent of the Government, the Contractor shall be required to furnish all the necessary services, qualified personnel, material, equipment, and facilities, not otherwise provided by the Government, as needed to perform the Statement of Work, attached hereto and made a part of this Solicitation (See SECTION J - List of Attachments).
b. The applicable Privacy Act System of Records Number will be specified and shall be used in any design, development, or operation work to be performed under the resultant contract. Disposition of records shall be in accordance with SECTION C of the contract, and by direction of the Contracting Officer's Representative (COR).
ARTICLE C.2. REPORTING REQUIREMENTS
All reports required herein shall be submitted in electronic format as specified in the ARTICLE F DELIVERIES of the
RFP.
All electronic reports submitted shall be compliant with Section 508 of the Rehabilitation Act of 1973. Additional information about testing documents for Section 508 compliance, including guidance and specific checklists, by application, can be found at: http://www.hhs.gov/web/508/index.html under "Making Files Accessible."
a. Technical Progress Reports
1. In addition to the required reports set forth elsewhere in this Schedule, the preparation and submission of regularly recurring Technical Progress Reports will be required in any contract resulting from this solicitation. These reports will require descriptive information about the activities undertaken during the reporting period and will require information about planned activities for future reporting periods. The frequency and specific content of these reports will be determined prior to contract award. The Contractor shall include the applicable PubMed Central or NIH Manuscript Submission reference number when citing publications that arise from its NIH funded research.
For proposal purposes, electronic version(s) of the following reports will be required:
a. Reports in Response to COR Request: These reports shall be in response to any requests from the COR and will include all topics specified by the COR at the time of the request. If reports are requested they shall not exceed the quantity of one report per month. Requested reports will address progress on the contract and address any problems encountered.
b. Bi-Monthly Phone Calls: Phone call reports will be scheduled at the COR request to occur twice monthly. In the phone call the Contractor will report progress on the contract and problems encountered. The Contractor will provide minutes from these phone calls to include a list of any action items.
c. Monthly Budget Report: These reports shall detail expenditures and projected expenses by task on a monthly basis. The report must include a summary of personnel time in hours for the last month, by task (or major subtask, when appropriate); estimated percent of total time expended; and a chart of costs, by task (or major subtask when appropriate), for the month and cumulative total in a format approved by the COR. The report must comment on the expenditure of funds in any month that deviates from the expected expenditure.
d. Quarterly Dataset Matrix: These reports shall be an electronic printable matrix that lists all potentially upcoming datasets housed through NAHDAP as well as all current datasets.
http://www.hhs.gov/web/508/index.html
- 8 -
The Contractor shall identify potential datasets for deposit. The searchable and sortable matrix must contain, at a minimum, details on the name of the study, populations and topics covered, the sponsor and/or PI, the organization that conducted the study, whether the data are available through alternate sources, whether a disclosure analysis was or will be needed, and confidentiality assurances provided to respondents.
e. Outreach Plan: The Contractor shall provide an outreach plan to be approved by COR within 30 days of contract effective date and updated annually from contract award (if options are exercised). The plan must include potential conference participation and other activities.
Each activity and potential conference must be well justified with clear outcomes identified.
The Contractor shall anticipate between two and five professional conferences per year. The outreach plan must identify means to determine the efficacy of outreach activities.
f. Semi-annual Report: At the request of the COR the contractor will provide semi-annual reports.
This report shall contain an outline and summary of notable achievements, methods followed, results obtained, and problems encountered and their solutions during the last six months of the contract. This report shall be due within 15 calendar days following the six month period being reported on. The monthly report is not required when semi-annual report is submitted.
g. Annual Report: This report shall include a summation of results of the entire contract work for the period covered (monthly and semi-annual reports are not required when they coincide with the annual report).
h. Final Report: This report is to include a summation of the work performed and the results obtained for the entire contract period of performance and will be due when the contract is completed. The report shall be comprehensive and describe results achieved in adequate detail.
A monthly report and an annual report will not be required for the period when the final report is due. The Final Report shall be submitted in accordance with the ARTICLE F.1. DELIVERABLES of this contract.
2. Summary of Salient Results
The Contractor will be required to prepare and submit, with the final report, a summary (not to exceed 200 words) of salient results achieved during the performance of the contract. This report will be required on or before the expiration date of the contract.
b. Other Reports/Deliverables
1. Reporting of Financial Conflict of Interest (FCOI)
All reports and documentation required by 45 CFR Part 94, Responsible Prospective Contractors including, but not limited to, the New FCOI Report, Annual FCOI Report, Revised FCOI Report, and the Mitigation Report, shall be submitted to the Contracting Officer in Electronic format. Thereafter, reports shall be due in accordance with the regulatory compliance requirements in 45 CFR Part 94.
45 CFR Part 94 is available at: http://www.ecfr.gov/cgi-bin/text-idx?
c=ecfr&SID=0af84ca649a74846f102aaf664da1623&rgn=div5&view=text&node=45:1.0.1.1.51&idno=45.
See Part 94.5, Management and reporting of financial conflicts of interest for complete information on reporting requirements.
(Reference subparagraph g. of the INSTITUTIONAL RESPONSIBILITY REGARDING INVESTIGATOR FINANCIAL CONFLICTS OF INTEREST Article in SECTION H of this contract.)
2. Source Code and Object Code http://www.ecfr.gov/cgi-bin/text-idx?c=ecfr&SID=0af84ca649a74846f102aaf664da1623&rgn=div5&view=text&node=45:1.0.1.1.51&idno=45 http://www.ecfr.gov/cgi-bin/text-idx?c=ecfr&SID=0af84ca649a74846f102aaf664da1623&rgn=div5&view=text&node=45:1.0.1.1.51&idno=45
- 9 -
Unless otherwise specified herein, the Contractor shall deliver to the Government, upon the expiration date of the contract, all source code and object code developed, modified, and/or enhanced under this contract.
3. Information and/or Physical Security
The Contractor shall submit the following reports as required by the INFORMATION AND PHYSICAL ACCESS SECURITY Article in SECTION H of this contract. Note: Each report listed below includes a reference to the appropriate subparagraph of this article.
A. Security Assessment and Authorization (SA&A)- A valid authority to operate (ATO) certifies that the Contractor's information system meets the contract's requirements to protect the agency data. If the system under this contract does not have a valid ATO, the Contractor (and/or any subcontractor) shall work with the agency and supply the deliverables required to complete the ATO within the specified timeline(s) within three
(3) months after contract award. The Contractor shall conduct the SA&A requirements in accordance with HHS IS2P, NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach (latest revision).
For an existing ATO, the Contracting Officer Representative must make a determination if the existing ATO provides appropriate safeguards or if an additional ATO is required for the performance of the contract and state as such.
NIH acceptance of the ATO does not alleviate the Contractor's responsibility to ensure the system security and privacy controls are implemented and operating effectively.
B. SA&A Package Deliverables - The Contractor (and/or any subcontractor) shall provide an SA&A package within 30 calendar days of contract award to the CO and/or COR. The following SA&A deliverables are required to complete the SA&A package.
• System Security Plan (SSP) - due within 30 calendar days after contract award. The SSP shall comply with the NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, the Federal Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline requirements, and other applicable NIST guidance as well as HHS and NIH policies and other guidance. The SSP shall be consistent with and detail the approach to IT security contained in the Contractor's bid or proposal that resulted in the award of this contract. The SSP shall provide an overview of the system environment and security requirements to protect the information system as well as describe all applicable security controls in place or planned for meeting those requirements. It should provide a structured process for planning adequate, cost-effective security protection for a system. The Contractor shall update the SSP at least annually thereafter.
• Security Assessment Plan/Report (SAP/SAR) - Due 30 calendar days after the contract award. The security assessment shall be conducted by the assessor and be consistent with NIST SP 800-53A, NIST SP 800-30, and HHS and NIH policies. The assessor will document the assessment results in the SAR.
The NIH should determine which security control baseline applies and then make a determination on the appropriateness/necessity of obtaining an independent assessment. Assessments of controls can be performed by contractor, government, or third parties, with third party verification considered the strongest.
Thereafter, the Contractor, in coordination with the NIH shall conduct/assist in the assessment of the security controls and update the SAR at least annually.
• Independent Assessment - Due 90 calendar days after the contract award. The Contractor (and/or subcontractor) shall have an independent third-party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the Security Authorization package, and report on technical, operational, and management level deficiencies as outlined in NIST SP 800-53. The Contractor
- 10 -shall address all "high" deficiencies before submitting the package to the Government for acceptance. All remaining deficiencies must be documented in a system Plan of Actions and Milestones (POA&M).
• POA&M - Due 30 calendar days after contract award. The POA&M shall be documented consistent with the HHS Standard for Plan of Action and Milestones and NIH policies. All high-risk weaknesses must be mitigated within 30 calendar days and all medium weaknesses must be mitigated within 60 calendar days from the date the weaknesses are formally identified and documented. The NIH will determine the risk rating of vulnerabilities.
Identified risks stemming from deficiencies related to the security control baseline implementation, assessment, continuous monitoring, vulnerability scanning, and other security reviews and sources, as documented in the SAR, shall be documented and tracked by the Contractor for mitigation in the POA&M document. Depending on the severity of the risks, NIH may require designated POAM weaknesses to be remediated before an ATO is issued. Thereafter, the POA&M shall be updated at least quarterly.
C. Contingency Plan and Contingency Plan Test - Due 60 calendar days after contract award. The Contingency Plan must be developed in accordance with NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, and be consistent with HHS and NIH policies. Upon acceptance by the System Owner, the Contractor, in coordination with the System Owner, shall test the Contingency Plan and prepare a Contingency Plan Test Report that includes the test results, lessons learned and any action items that need to be addressed.
Thereafter, the Contractor shall update and test the Contingency Plan at least annually.
• E-Authentication Questionnaire - The Contractor (and/or any subcontractor) shall collaborate with government personnel to ensure that an E-Authentication Threshold Analysis (E-auth TA) is completed to determine if a full E-Authentication Risk Assessment (E-auth RA) is necessary. System documentation developed for a system using E-auth TA/E-auth RA methods shall follow OMB 04-04 and NIST SP 800-63, Rev. 2, Electronic Authentication Guidelines.
Based on the level of assurance determined by the E-Auth, the Contractor (and/or subcontractor) must ensure appropriate authentication to the system, including remote authentication, is in-place in accordance with the assurance level determined by the E-Auth (when required) in accordance with HHS policies.
D. Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) - The Contractor shall assist the NIH Office of the Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a full PIA needs to be completed.
The NIH PIA guide is located at https://oma.od.nih.gov/forms/Privacy%20Documents/Documents/NIH%20PIA %20Guide.pdf.
a. If the results of the PTA show that a full PIA is needed, the Contractor shall assist the OpDiv SOP or designee with completing a PIA for the system or information within 60 calendar days after completion of the PTA and in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.
b. The Contractor shall assist the NIH Office of the SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.
The Contractor shall update the PTA/PIA on an annual basis.
E. FIPS 199 Assessment - In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
- 11 -
• Availability , which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
d. Comply with the Privacy Act requirements.
In accordance with HHSAR Clause 352.239-72, Security Requirements For Federal Information Technology Resources, the Contractor shall submit a FIPS 199 Assessment within 30 calendar days after contract award and then annually within 30 calendar days of the contract anniversary. The FIPS 199 Assessment shall be consistent with the cited NIST standard.
F. POSITION SENSITIVITY DESIGNATIONS - All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract:
[ ] Level 6: Public Trust - High Risk. Contractor/subcontractor employees assigned to Level 6 positions shall undergo a Suitability Determination and Background Investigation (MBI).
[X] Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).
[ ] Level 1: Non-Sensitive. Contractor/subcontractor employees assigned to Level 1 positions shall undergo a Suitability Determination and National Check and Inquiry Investigation (NACI).
1. HOMELAND SECURITY PRESIDENTIAL DIRECTIVE (HSPD)-12
Roster-
a. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO within fourteen (14) calendar days after the effective date of this contract.
Any revisions to the roster as a result of staffing changes shall be submitted within seven (7) calendar days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at: https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/ SuitabilityRoster_10-15-12.xlsx.
b. If the Contractor is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 calendar days of the notification.
c. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 calendar days of the notification.
mailto:fisma@hhs.gov https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx
- 12 -
d. The Contractor shall notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the contract and if they have previously been the subject of national agency checks or background investigations.
e. All Contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract. Contractors may begin work after the fingerprint check has been completed.
f. Investigations are expensive and may delay performance, regardless of the outcome of the investigation.
Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-14. Accordingly, the Contractor shall ensure that any additional employees whose names it submits for work under this contract have a reasonable chance for approval.
g. Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the contract price of no more that the cost of the additional investigation(s).
h. The Contractor shall include language similar to this "HHS Controlled Facilities and Information Systems Security" language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).
i. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.
j. Within 7 calendar days after the Government's final acceptance of the work under this contract, or upon termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.
G. CONTRACT INITIATION AND EXPIRATION
1. General Security Requirements- The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology or and in accordance with the HHS Contract Closeout Guide (2012).
HHS EA requirements may be located here: https://www.hhs.gov/ocio/ea/documents/proplans.html
2. System Documentation- Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
3. Sanitization of Government Files and Information- As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation in accordance with the NIH Media Sanitization and Disposal Policy to the CO and/or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
4. Notification- The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO within fifteen days before an employee stops working under this contract.
5. Contractor Responsibilities Upon Physical Completion of the Contract- The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor shall provide a certification that all government information https://www.hhs.gov/ocio/ea/documents/proplans.html
- 13 -has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or NIH policies.
6. The Contractor (and/or any subcontractor) shall perform and document the actions identified in the NIH Contractor Employee Separation Checklist https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/ Documents/Emp-sep-checklist.pdf when an employee terminates work under this contract within 2 calendar days of the employee's exit from the contract. All documentation shall be made available to the CO and/or COR upon request.
H. Reporting of New and Departing Employees - The Contractor shall notify the Contracting Officer's Representative (COR) and Contracting Officer within five business days of staffing changes for positions that require suitability determinations as follows:
a. New Employees who have or will have access to HHS Information systems or data: Provide the name, position title, e-mail address, and phone number of the new employee. Provide the name, position title and suitability level held by the former incumbent. If the employee is filling a new position, provide a description of the position and the Government will determine the appropriate security level.
b. Departing Employees: 1) Provide the name, position title, and security clearance level held by or pending for the individual; and 2) Perform and document the actions identified in the "Employee Separation Checklist", attached in Section J, ATTACHMENTS of this contract, when a Contractor/Subcontractor employee terminates work under this contract. All documentation shall be made available to the COR and/ or Contracting Officer upon request.
I. Contractor Non-Disclosure Agreement (NDA)- Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the NIH non-disclosure agreement https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Nondisclosure.pdf, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
J. Vulnerability Scanning Reports- The Contractor shall report the results of the required monthly special vulnerability scans no later than 10 calendar days following the end of each reporting period. If required monthly, this report may be included as part of the Technical Progress Report. Otherwise, this report shall be submitted under a separate cover on monthly basis.
K. Government Access for Security Assessment- In addition to the Inspection Clause in the contract, the Contractor (and/or any subcontractor) shall afford the Government access to the Contractor's facilities, installations, operations, documentation, information systems, and personnel used in performance of this contract to the extent required to carry out a program of security assessment (to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the confidentiality, integrity, and availability of federal data or to the protection of information systems operated on behalf of HHS, including but are not limited to:
a. At any tier handling or accessing information, consent to and allow the Government, or an independent third party working at the Government's direction, without notice at any time during a weekday during regular business hours contractor local time, to access contractor and subcontractor installations, facilities, infrastructure, data centers, equipment (including but not limited to all servers, computing devices, and portable media), operations, documentation (whether in electronic, paper, or other forms), databases, and personnel which are used in performance of the contract.
The Government includes but is not limited to the U.S. Department of Justice, U.S. Government Accountability Office, and the HHS Office of the Inspector General (OIG). The purpose of the access is to facilitate performance inspections and reviews, security and compliance audits, and law enforcement investigations. For security audits, the audit may include but not be limited to such items as buffer overflows, open ports, unnecessary services, lack of user input filtering, cross site scripting vulnerabilities, SQL injection vulnerabilities, and any other known vulnerabilities.
b. At any tier handling or accessing protected information, fully cooperate with all audits, inspections, investigations, forensic analysis, or other reviews or requirements needed to carry out requirements
- 14 -presented in applicable law or policy. Beyond providing access, full cooperation also includes, but is not limited to, disclosure to investigators of information sufficient to identify the nature and extent of any criminal or fraudulent activity and the individuals responsible for that activity.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.