RFP 72590.pdf
PDF 866 KB Posted
- Attached to
- Respirator Approval Program – Site Audits, Site Qualification Audits, and Interpreter Assistance IDIQ Federal contract opportunity
- Solicitation number
- 75D301-23-R-72590
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGES
15A. NAME
AND
ADDRESS
OF
OFFEROR
SEC. PAGE(S) SEC. PAGE(S)
(Date) (Hour)
CALENDAR DAYS
14. ACKNOWLEDGMENT OF AMENDMENTS
(The offeror acknowledges receipt of amend-ments to the SOLICITATION for offerors and related documents numbered and dated:
(Type or Print)
SOLICITATION, OFFER AND AWARD 1. THIS CONTRACT IS A RATED ORDER
UNDER DPAS (15 CFR 700)
RATING
PAGE OF
1 76
2. CONTRACT NO.
3. SOLICITATION NO.
75D301-23-R-72590
4. TYPE OF SOLICITATION
SEALED BID (IFB)
X NEGOTIATED (RFP)
5. DATE ISSUED
03/03/2023
6. REQUISITION/PURCHASE
NO.
000HCCLH-2023-73206
7. ISSUED BY CODE 3635 8. ADDRESS OFFER TO (If other than Item 7) Centers for Disease Control and Prevention (CDC)
Office of Acquisition Services (OAS) 626 Cochrans Mill Rd Pittsburgh, PA 15236-0070
Approved as to Form and Legality: _____________________________ NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”
SOLICITATION
9. Sealed offers in original and copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in until local time
CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
10. FOR INFORMATION
CALL:
A. NAME
Spencer Kahn
B. TELEPHONE (NO COLLECT CALLS)
AREA CODE NUMBER: EXT:
(412) 386-6112
C. E-MAIL ADDRESS
qnt8@cdc.gov
11. TABLE OF CONTENTS
(x) DESCRIPTION (x) DESCRIPTION
PART I – THE SCHEDULE PART II – CONTRACT CLAUSES
X A SOLICITATION/CONTRACT FORM 1 X I CONTRACT CLAUSES 38
X B SUPPLIES OR SERVICES AND PRICES/COSTS 2 PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X C DESCRIPTION/SPECS./WORK STATEMENT 4 X J LIST OF ATTACHMENTS 45
X D PACKAGING AND MARKING 25 PART IV – REPRESENTATIONS AND INSTRUCTIONS
X E INSPECTION AND ACCEPTANCE 26 REPRESENTATIONS, CERTIFICATIONS, AND
X F DELIVERIES OR PERFORMANCE 27 X K OTHER STATEMENTS OF OFFERORS 47
X G CONTRACT ADMINISTRATION DATA 29 X L INSTRS., CONDS., AND NOTICES TO OFFERORS 51
X H SPECIAL CONTRACT REQUIREMENTS 32 X M EVALUATION FACTORS FOR AWARD 62
OFFER (Must be fully completed by offeror) NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52-232-8)
10 CALENDAR DAYS
20 CALENDAR DAYS
30 CALENDAR DAYS
AMENDMENT NO. DATE AMENDMENT NO. DATE
CODE FACILITY 16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER
15B. TELEPHONE NO.
AREA CODE NUMBER EXT.
15C. CHECK IF REMITTANCE ADDRESS
IS DIFFERENT FROM ABOVE - ENTER
SUCH ADDRESS IN SCHEDULE.
17. SIGNATURE
18. OFFER DATE
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
21. ACCOUNTING AND APPROPRIATION
10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( ) 23. SUBMIT INVOICES TO ADDRESS SHOWN IN (4 copies unless otherwise specified)
ITEM
24. ADMINISTERED BY (If other than Item 7) CODE 3635 25. PAYMENT WILL BE MADE BY CODE 434 Centers for Disease Control and Prevention (CDC) Office of Acquisition Services (OAS) 626 Cochrans Mill Rd Pittsburgh PA 15236-0070
Centers for Disease Control and Prevention (FMO) PO Box 15580 404-718-8100
Atlanta GA 30333-0080
26. NAME OF CONTRACTING OFFICER (Type or print)
27. UNITED STATES OF AMERICA
28. AWARD DATE
IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 33 (REV. 9-97)
PREVIOUS EDITION IS UNUSABLE Prescribed by GSA
FAR (48 CFR) 53.214©
K
Section B - Supplies Or Services And Prices/Costs
ITEM SUPPLIES / SERVICES QTY / UNIT UNIT PRICE EXTENDED PRICE
0001 Respiratory Protective Devices –
On-Site Compliance Audit Assistance in Accordance with the Enclosed Statement of Work
Maximum Value
$2,628,483.0
$2,628,483.06
Not To Exceed
B.1 Description of Services The Contractor shall furnish all labor, equipment, and materials required to accomplish the project entitled “Respiratory Protective Devices - On-Site Compliance Audit Assistance.” This effort shall be performed in accordance with Section C, Description/Specifications/Work Statement.
B.2 Reimbursement of Travel Costs
When authorized in the contract as a direct cost, travel costs that are directly related to specific contract performance may be billed as a direct cost. Travel will be reimbursed in accordance with the Federal Travel Regulations and the travel cost detail should show:
(a) Name of traveler and official title,
(b) Purpose of trip,
(c) Dates of departure and return to starting point (station or airport),
(d) Transportation costs, identified as to rail, air, private automobile (including mileage and rate) and taxi.
(e) If claim for subsistence is on per diem basis, show number of days, rate and amount, as authorized in contract. If claim is based on actual cost of subsistence, show, on a daily basis, the amounts claimed for lodging and meals separately.
(1) All travel costs plus per diem or actual subsistence for personnel while in an actual travel status in direct performance of the work and services required under this contract. These costs will be in accordance with the Contractor’s policy and subject to the following:
(i) Air travel shall be by the most direct route using “air coach” or “air tourist” (less than first class) unless it is clearly unreasonable or impractical (e.g., not available for reasons other than avoidable delay in making reservations, would require circuitous routing or entail additional expense offsetting the savings on fare, or would not make necessary connections).
(ii) Rail travel shall be by the most direct route, first class with lower berth or nearest equivalent.
(iii) Costs incurred for lodging, meals, and incidental expenses shall be considered reasonable and allowable to the extent that they do not exceed on a daily basis the per diem rates set forth in the Federal Travel Regulation (FTR).
(iv) Travel via privately owned automobile shall be reimbursed at not more than the current General Services Administration (GSA) FTR established mileage rate.
(b) Except as stated herein, the Contractor shall not incur costs unless the prior written authorization of the Contracting Officer has been obtained. When costs are incurred without such prior authorization, with the intent of claiming reimbursement as direct costs, it shall be at the contractor’s risk.
(End of Clause)
B.3 Payment Schedule Invoices may be submitted upon completion of each audit or task order. The invoice amounts for the audits or tasks shall be fixed.
B.4 Guaranteed Contract Minimum The guaranteed minimum total task order awards for all contracts awarded is $2,500.00.
B.5 Maximum Amount The maximum amount for all contracts awarded shall not exceed $2,628,483.06 over a period of five years.
Section C - Description/Specification/Work Statement Statement of Work
Period of Performance: August 27, 2023 through August 26, 2028
Title: Respirator Approval Program – Site Audits, Site Qualification Audits, and Interpreter
Assistance
SECTION 1 – BACKGROUND
Since the implementation of Title 42, Code of Federal Regulations, Part 84 (42 CFR 84) in 1995, NIOSH has conducted on-site compliance audits of respirator approval holders’ facilities. The purpose of these audits is to assess the approval holders’ conformance to the quality assurance requirements in Subpart E of 42 CFR 84 and to the approved quality control plans. With the revision of 42 CFR 84 in 2015, fees were added to conduct site qualification audits prior to NIOSH issuing an approval decision. Since many of the approval requests are submitted by international companies, interpreter services have been acquired through various purchasing mechanisms.
Site audits consist of the following steps: 1) audit initiation, 2) audit planning, 3) on-site audit and assessment, 4) reporting of audit findings, and 5) follow-up activities to correct nonconformances found or to revoke approval where necessary. Site qualification audits consist of the following steps: 6) site qualification audit initiation, 7) site qualification audit planning, 8) on-site qualification audit and assessment, 9) reporting of site qualification audit findings, and
10) follow-up activities to evaluate corrections to nonconformances or denying/granting an approval request. Interpreter services vary based on the country and consist of the interpreter translating requirements from English to the native language or from the native language to English.
This acquisition is for site audit services to perform audit planning, conducting on-site audits and assessments, and reporting (steps 2 through 4 above); site qualification audit services to perform site qualification audit planning, conducting on-site qualification audits and assessments, and reporting (steps 7 through 9 above); and interpreter services on an as needed basis.
SECTION 2 – PURPOSE
The purpose of the services obtained under this contract is to create a pool of validated quality auditing firms familiar with the National Institute for Occupational Safety and Health (NIOSH) regulatory requirements, under 42 CFR 84, for conducting on-site compliance audits, on-site qualification audits, and/or interpreter services. A Firm-Fixed-Price (FFP), Indefinite-Delivery- Indefinite-Quantity (IDIQ) type service contract (with task orders) is anticipated.
Contractor staff will receive training on the specific NIOSH program requirements and existing audit skills and experience will be validated. Training will be conducted by NIOSH staff via remote technologies (Zoom or Teams). Audit skills will be validated by either a NIOSH representative accompanying the contract auditor on an actual audit or by the contractor providing evidence that the auditor has conducted an actual audit. Subsequently, the contract auditors will act as authorized NIOSH representatives in planning, conducting, and reporting the findings of on-site audits or site qualification audits in accordance with 42 CFR 84, approved quality system documents, NIOSH checklists, and Standard Operating Procedures (SOP). The contract auditors may perform the services of this acquisition in the United States and/or internationally, as defined within the specific task orders that will be generated.
A NIOSH representative may accompany the contractor at any time, participating as a team member and monitoring the contractor’s performance. Joint audits with the Mine Safety and Health Administration (MSHA) may also be conducted for specific sites with joint NIOSH and MSHA approvals. A NIOSH representative may also accompany the contractor when reports have demonstrated recurring issues with a specific site.
The Centers for Disease Control and Prevention, National Institute for Occupational Safety and Health, National Personal Protective Technology Laboratory (NPPTL), is mandated by Congress to review respiratory protective devices for approval. Currently, NPPTL monitors over 9000 approvals and over 119 NIOSH approval holders worldwide (covering 31 countries). The regulations, which are used to approve these respiratory protective devices, are found in 42 CFR 84, which includes quality assurance and minimum respirator performance requirements.
NIOSH conducts site qualification audits prior to issuing an approval decision. NIOSH conducts on-site compliance audits to verify continued compliance with the regulations after approval has been granted.
SECTION 3 – SCOPE OF WORK
(A) Site Audits
It is anticipated that approximately 100 sites will be audited annually. These site locations are currently about 40% within the U.S. and 60% outside the U.S. Manufacturing sites continue to be added and removed in response to business requirements and public health emergencies.
All approved sites have company-specific quality plans approved by NIOSH to the requirements of 42 CFR 84.
Each site audit must evaluate the approval holder’s complete quality plan with regard to NIOSH Approved® products to a level of assurance provided by current NIOSH staff and practices.
Current NIOSH practice is that a site audit can be accomplished by one auditor in one or two full working days, depending on the size of the organization. Additional resources may be assigned for sites with language, security, or unusual quality plan issues. NIOSH auditors may be assigned to the audit team for both assistance and monitoring purposes. The number of on-site working days for each audit will be determined by NIOSH and included in each task order.
This work will require each auditor to participate in training on the NIOSH specific requirements. To maintain qualification after the initial training, auditors may be asked to attend a refresher training every two years. The requirement for this additional training may be reduced at the discretion of NIOSH.
All approval holder documentation and audit results are confidential. Each contractor must establish binding confidentiality agreements on any employee, auditor, or other audit team member (such as an interpreter) exposed to approval holder information. Any approval holder may request that individual audit team members execute a separate confidentiality agreement with the approval holder. All audit team members must be prepared and willing to execute such a standard confidentiality agreement in the form attached as Appendix A.
Contractors must be prepared, as requested, to return or destroy any documentation provided by NIOSH or approval holders once it is no longer needed for the provision of services under this acquistion.
It is anticipated that a pool of no more than three (3) contractors will be established based on evaluations of proposals received in response to this acquisition. Assignment of actual work will be done through competitive proposals on specific task orders by contractors in the pool. These task orders will be to perform specific on-site compliance audits within one or more geographic region(s) as follows.
Asia (India, Singapore, Thailand, Vietnam) Australia Canada China (Eastern) China (Southern) Europe Japan/South Korea Mexico South America Taiwan United Kingdom United States
Auditors will travel to approval holders’ locations to conduct the on-site portion of the audit.
The Government will not make any travel arrangements for auditors; contractors will bear this responsibility. Travel costs will not be billed or paid separately; they must be anticipated by the contractor and included in the firm fixed price bid for each task order. Travel costs should be shown as separate costs on the cost proposal.
(B) Site Qualification Audits
It is anticipated that approximately 20 sites may be visited annually. These site locations are currently 100% outside the U.S. Requests for respirator approvals by new companies are sporadic in response to business needs, market conditions, and public health emergencies.
All sites will have a company-specific quality plan which should meet the requirements of 42
CFR 84.
Each site qualification audits must evaluate the manufacturer’s complete quality plan with regard to how NIOSH Approved® products are proposed to be manufactured. This visit must be conducted to a level of assurance provided by current NIOSH staff and practices. Current NIOSH practice is that a site qualification visit can be accomplished by one auditor in one or two full working days, depending on the size of the organization. Additional resources may be assigned for sites with language, security, or unusual quality plan issues. NIOSH auditors may be assigned to the audit team for both assistance and monitoring purposes. The number of on-site working days for each site qualification audit will be determined by NIOSH and included in each task order.
This work will require each auditor to participate in training on the NIOSH specific requirements. To maintain qualification after the initial training, auditors may be asked to attend a refresher training every two years. The requirement for this additional training may be reduced at the discretion of NIOSH.
All documentation and visit results are confidential. Each contractor must establish binding confidentiality agreements on any employee, auditor, or other audit team member (such as an interpreter) exposed to the potential approval holder information. Any potential approval holder may request that individual visit team members execute a separate confidentiality agreement with the potential approval holder. All visiting team members must be prepared and willing to execute such a standard confidentiality agreement in the form attached as Appendix A.
Contractors must be prepared, as requested, to return or destroy any documentation provided by NIOSH or potential approval holders once it is no longer needed for the provision of services under this acquisition.
It is anticipated that a pool of no more than three (3) contractors will be established based on evaluations of proposals received in response to this acquisition. Assignment of actual work will be done through competitive proposals on specific task orders by contractors in the pool. These task orders will be to perform specific site qualification audits within one or more geographic region(s) as follows.
Asia (India, Singapore, Thailand, Vietnam) Canada China (Eastern) China (Southern) Europe Japan/South Korea Mexico South America Taiwan United Kingdom
Auditors will travel to potential approval holders’ locations to conduct the site qualification visit.
The Government will not make any travel arrangements for auditors; contractors will bear this responsibility. Travel costs will not be billed or paid separately; they must be anticipated by the contractor and included in the firm fixed price bid for each task order. Travel costs should be shown as separate costs on the cost proposal.
(C) Interpreter Services
Interpreter services may be requested to support NIOSH staff conducing site audits and/or site qualification audits. These services will be on a case-by-case basis. When applicable, NIOSH will combine visits in like speaking countries.
NIOSH desires staff performing interpreter services to have knowledge of NIOSH requirements as defined in 42 CFR 84, have prior experience conducting site audits or site qualification audits, and experience with quality control plans and/or quality management systems.
It is anticipated that a pool of no more than three (3) contractors will be established based on evaluations of proposals received in response to this acquisition. Assignment of actual work will be done through competitive proposals on specific task orders by contractors in the pool.
When necessary, interpreters may need to travel to locations with NIOSH staff. The Government will not make any travel arrangements for interpreters; contractors will bear this responsibility. Travel costs will not be billed or paid separately; they must be anticipated by the contractor and included in the firm fixed price bid for each task order. Travel costs should be shown as separate costs on the cost proposal.
SECTION 4 – TASKS TO BE PERFORMED
The contractor will:
1. Communicate with NIOSH personnel during all phases of the services being provided.
2. Write acceptable draft announcement letters for official distribution by NIOSH.
3. Write acceptable plans for official distribution by NIOSH.
4. Review quality documentation and respirator-specific requirements provided by NIOSH in preparation for the audit/visit.
5. Travel to and conduct the on-site audits or site qualification audits.
6. Write acceptable draft reports for official distribution by NIOSH.
7. Provide insights and background on the acceptability of any corrective actions required by the audit or site qualification visit, with final evaluation done by NIOSH personnel.
8. As needed, provide interpreter services.
SECTION 5 – GOVERNMENT FURNISHED MATERIALS
NIOSH will provide templates and checklists for conducting site audits or site qualification audits. These files will be provided in Microsoft Word format.
NIOSH will also provide all necessary quality documentation and respirator-specific requirements to conduct the site audit or site qualification audits.
SECTION 6 – PERIOD OF PERFORMANCE
The Period of Performance for this solicitation is August 27, 2023 through August 26, 2028.
Specific task orders, organized by region, will be awarded annually over this five-year period.
All task orders will be subject to the availability of funds.
SECTION 7 – DELIVERABLES/REPORTING SCHEDULE
The following deliverables and reports will be furnished as part of this contract.
(A) Site Audits
1. Audit Intent Correspondence: Electronic correspondence (e-mail) between the Contractor, Approval Holder, and any other persons accompanying the site audit (such as interpreters, NIOSH staff, or MSHA staff) indicating agreement by all parties on the date(s) and location(s) of the site audit. Delivery is due 45 calendar days prior to the site audit date.
2. Draft Audit Announcement Letter and Audit Plan: The audit announcement letter and plan follow a standard NIOSH template format formally announcing the site audit date(s), location(s), and audit parameters. Delivery is due 30 calendar days prior to the site audit date.
3. Draft Audit Report: The draft audit report will contain the findings from the site audit.
The report will follow a standard NIOSH format. For each report section with a nonconformance, evidence will be provided. Nonconformances will be written describing the required audit criteria and the evidence showing that it is not met.
Delivery is due 14 calendar days after the site audit date.
Note: Draft audit reports will be reviewed by the COR (or designee) for acceptance, and must contain all pertinent information to allow for proper review/processing by NIOSH staff. Reports that are lacking the required information will be rejected and returned for additional response.
4. Post-Audit Clarification: Responses, generally via e-mail or telephone, answering questions from NIOSH staff on details or interpretation of audit evidence, occurrences during site audits, or the acceptability of corrective action undertaken by Approval
Holders in response to a nonconformance. Delivery is due 3 business days after the NIOSH request.
(B) Site Qualification Audits
1. Visit Intent Correspondence: Electronic correspondence (e-mail) between the Contractor, prospective approval holder, and any other persons accompanying the site qualification audit (such as interpreters or NIOSH staff) indicating agreement by all parties on the date(s) and location(s) of the site qualification audit. Delivery is due 45 calendar days prior to the site qualification audit date.
2. Draft Site Qualification Announcement Letter and Plan: The site qualification announcement letter and plan follow a standard NIOSH template format formally announcing the site qualification visit date(s), location(s), and visit parameters. Delivery is due 30 calendar days prior to the site qualification audit date.
3. Draft Site Qualification Report: The draft Audit Report will contain the findings from the site qualification audit. The report will follow a standard NIOSH format. For each report section with a nonconformance, evidence will be provided. Nonconformances will be written describing the required site qualification criteria and the evidence showing that it is not met. Delivery is due 14 calendar days after the site qualification audit date.
Note: Draft site qualification audit reports will be reviewed by the COR (or designee) for acceptance, and must contain all pertinent information to allow for proper review/processing by NIOSH staff. Reports that are lacking the required information will be rejected and returned for additional response.
4. Post-Audit Clarification: Responses, generally via e-mail or telephone, answering questions from NIOSH staff on details or interpretation of visit evidence, occurrences during site qualification audits, or the acceptability of corrective action undertaken by potential Approval Holders in response to a nonconformance. Delivery is due 3 business days after the NIOSH request.
(C) Interpreter Services
1. Interpreter Correspondence: Electronic correspondence (e-mail) between the Contractor and NIOSH staff requesting the services. Delivery is due 3 business days after the NIOSH request.
Delivery of documents shall be made in an electronic format readable by Microsoft Word, for example Word for Microsoft® 365 document (.docx), Word 2013-2016 document (.docx), Word 97-2003 document (.doc), OpenDocument Text (.odt), or Rich Text Format (.rtf). Delivery shall be made via upload to a secure FTP site. Once documents are uploaded, appropriate NIOSH staff shall be notified via email that the documents have been uploaded and are ready for review.
SECTION 8 – REFERENCE MATERIALS
Title 42, Code of Federal Regulations, Part 84. Currently available from the Government Printing Office at http://www.gpo.gov/fdsys/search/submitcitation.action?publication=CFR
NIOSH certified equipment list:
http://www.cdc.gov/niosh/npptl/topics/respirators/CEL/default.html
SECTION 9 – POINT OF CONTACT INFORMATION
The Points of Contact (POC) for this acquisition are:
NIOSH/NPPTL
Attn: John Powers 1000 Frederick Lane Morgantown, WV 26505
E-mail Address: JPowers@cdc.gov Telephone Number: 304.285.6219
NIOSH/NPPTL
Attn: Jeff Palcic 626 Cochrans Mill Road Pittsburgh, PA 15236
E-mail Address: JDPalcic@cdc.gov Telephone Number: 412.386.5247
Preferred method of communication: Email or Phone
SECTION 10 – PAYMENT TERMS
Partial payments may be issued upon completion of a specific site audit, site qualification audit, or interpreter service within a task order. Under the partial payment terms, the contractor shall submit an invoice upon completion of one specific site audit, one specific site qualification audit, or one specific interpreter service within the task order. Payment will be authorized upon acceptance of the draft report or completion of the interpreter service.
The contractor also has the option to submit one invoice at the completion of the task order.
Under these payment terms, the contractor will submit one invoice for all site audits, all site qualification audits, or all interpreter services conducted under a task order. Payment will be authorized upon acceptance of all draft reports or completion of all interpreter services associated with the task order.
http://www.gpo.gov/fdsys/search/submitcitation.action?publication=CFR http://www.cdc.gov/niosh/npptl/topics/respirators/CEL/default.html
SECTION 11 – MINIMUM VENDOR QUALIFICATIONS AND LEVEL OF EFFORT
The contractor’s staff must be competent to serve as an audit team leader for a quality system audit, site qualification audit, or for performing interpreter services. The contractor’s staff must be knowledgeable of Quality System Standards (e.g., ISO 9001 or MIL-STD-1916) and auditing techniques. They must also have experience leading quality system audits. Contractor staff performing interpreter services must be fluent in the language being requested. The contractor’s staff must be able to demonstrate adequate mastery of spoken and written English.
SECTION 12 – EVALUATION FACTORS
(A) Site Audits
It is anticipated that a typical task order will include three (3) to ten (10) sites for audit. Special circumstances may require non-typical task orders to be generated. Current practice is that most sites are to be audited on a two-year cycle. Some sites may be audited more or less frequently based on individual circumstances.
The evaluation criteria for the competitive award of site audit task orders will include the following categories:
1. Past performance of contractor.
2. Past performance of proposed auditor(s).
3. Auditor qualifications.
4. Conflicts of interest.
5. Special skills required for task.
6. Contractor prior experience with sites to be audited.
7. Price.
Award will be made based primarily on technical merit, with price used for selection among proposals of comparable quality.
(B) Site Qualification Audits
It is anticipated that a typical task order may include one (1) to five (5) sites for site qualification audit. Special circumstances may require non-typical task orders to be generated. Current practice is that new approval holders undergo a site qualification audit prior to receiving their first approval.
The evaluation criteria for the competitive award of site qualification audit task orders will include the following categories:
1. Auditor qualifications.
2. Conflicts of interest.
3. Special skills required for task.
4. Price.
Award will be made based primarily on technical merit, with price used for selection among proposals of comparable quality.
(C) Interpreter Services
It is anticipated that a typical task order may include one (1) to three (3) request for interpreter services. Special circumstances may require non-typical task orders to be generated.
The evaluation criteria for the competitive award of interpreter service task orders will include the following categories:
1. Interpreter’s native languge.
2. Conflicts of interest.
3. Special skills required for task.
4. Price.
Award will be made based primarily on technical merit, with price used for selection among proposals of comparable quality.
Appendix A
Confidentiality Agreement
This agreement is entered into between (Contractor and/or independent contractor or subcontractor name), an independent contractor of the National Institute for Occupational Safety and Health (NIOSH), and (Auditee firm name).
In consideration for granting (Contractor and/or independent contractor or subcontractor name) access to and the right to audit, examine, and/or review (Scope of Task and/or Auditee firm name), (Contractor and/or independent contractor or subcontractor name) promises (Auditee firm name) that it will not publish, divulge, disclose, or make known in any manner or to any extent, to any party other than NIOSH, any information, examination, or review, where information concerns or relates to trade secrets, processes, operations, style of work, or apparatus of (Auditee firm name).
(Contractor and/or independent contractor or subcontractor name)
(Auditee firm name)
Date: Date:
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2) Safeguarding Information and Information Systems. In accordance with the Federal
Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security
Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed..
3) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality: [ ] Low [X] Moderate [ ] High Integrity: [ ] Low [X] Moderate [ ] High Availability: [X] Low [ ] Moderate [ ] High Overall Risk Level: [ ] Low [X] Moderate [ ] High
Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:
[X] No PII [ ] Yes PII
Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother ‘s maiden name, biometric records, etc.
PII Confidentiality Impact Level has been determined to be: [X] Low [ ] Moderate [ ] High
4) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
mailto:fisma@hhs.gov http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf
b. disclosed to authorized personnel on a Need-To-Know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed. Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
5) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
6) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and CDC policies. Unauthorized disclosure of information will be subject to the HHS/CDC sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
7) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
8) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
d. Verify that the encryption solutions in use have been validated under the
Cryptographic Module Validation Program to confirm compliance with FIPS 140-2.
The Contractor shall provide a written copy of the validation documentation to the COR prior to performing any work on behalf of HHS.
e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys.
Encryption keys shall be provided to the COR upon request and at the conclusion of the contract.
9) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy.
A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, and CDC Implementation of the HHS Rules of Behavior for Use of HHS Information Technology Resources.
2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
D. Incident Response
The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by CDC Computer Security Incident Response Team (CSIRT) within 24 hours, whether the response is positive or negative.
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII” .
In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:
1) Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
2) NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send CDC approved notifications to affected individuals within 30 days.
3) Report all suspected and confirmed information security and privacy incidents and breaches to the CDC Computer Security Incident Response Team (CSIRT) at 866-655- 2245 and CSIRT@cdc.gov, COR, CO, CDC SOP (or his or her designee), and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one
(1) hour, and consistent with the applicable CDC and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:
a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
b. not include any sensitive information in the subject or body of any reporting e-mail;
and
c. encrypt sensitive information in attachments to email, media, etc.
4) Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally
Identifiable Information, HHS and CDC incident response policies when handling PII breaches.
5) Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.
This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation.
E. Position Sensitivity Designations All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies mailto:CSIRT@cdc.gov with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR).
F. Homeland Security Presidential Directive (HSPD)-12 The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO within 7 days of the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within 7 days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
G. Contract Initiation and Expiration
1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology and in accordance with the HHS Contract Closeout Guide (2012).
2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
3) Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .