RFP75N93024R00011.pdf
PDF 387 KB Posted
- Attached to
- NIAID Evaluation Services Federal contract opportunity
- Solicitation number
- 75N93024R00011
About this file
This document is a Request for Proposal (RFP) issued by the National Institute of Allergy and Infectious Diseases (NIAID), National Institutes of Health, for NIAID Evaluation Services. The purpose of this indefinite quantity contract is to provide design and implementation of program evaluation projects for NIAID's scientific research and management programs, as well as evaluation training and support. The contract period is from July 19, 2024 through July 18, 2029, with a minimum value of $10,000 and a maximum value of $8,624,675. The RFP includes a Statement of Work detailing the required services. Proposals are due by May 21, 2024, and the contract will be awarded to a small business concern. The RFP outlines detailed requirements for information security, privacy, incident response, and other contract administration and reporting obligations.
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
- 1 -
SOLICITATION
SECTION A - SOLICITATION/CONTRACT FORM
1. Requisition or other Purchase Authority: Public Law 81-692, as amended
2. Request for Proposal (RFP) Number:
75N93024R00011
3. Issue Date:
April 19, 2024
4. Set Aside:
[ ] No
[X]Yes See Part IV Section L
5. Title : NIAID Evaluation Services
6. ISSUED BY:
Office of Acquisitions National Institute of Allergy and Infectious Diseases (NIAID) National Institutes of Health (NIH) Department of Health and Human Services (DHHS) 5601 Fishers Lane, Room 3D10, MSC 9821 Bethesda, Maryland 20892-9821
7. SUBMIT OFFERS TO:
See Part III, Section J, "Packaging and Delivery of the Proposal," ATTACHMENT 1 of this Solicitation.
8. Proposals for furnishing the supplies and/or services will be received at the place specified in, and in the number of copies specified in Attachment 1, "Packaging and Delivery of the Proposal," until 3:00 pm Eastern Standard time on May 21, 2024. Offers will be valid for 120 days unless a different period is specified by the offeror on the Attachment entitled, "Proposal Summary and Data Record, NIH 2043. All questions regarding this Solicitation are due by 3:00pm on April 30, 2024.
9. This solicitation requires delivery of proposals as stated in ATTACHMENT 1, "PACKAGING AND DELIVERY OF THE PROPOSAL." If proposals are required to be delivered to two different locations, the OFFICIAL POINT OF RECEIPT for determining TIMELY DELIVERY is the address provided for the OFFICE OF ACQUISITIONS.
IF YOUR PROPOSAL IS NOT RECEIVED BY THE CONTRACTING OFFICER OR HIS DESIGNEE AT THE PLACE AND TIME SPECIFIED FOR THE OFFICE OF ACQUISITIONS, THEN IT WILL BE CONSIDERED LATE AND HANDLED IN ACCORDANCE WITH subparagraph (c)(3) of FAR Clause 52.215-1, Instructions to Offerors--Competitive Acquisition," LOCATED IN SECTION L.1. OF THIS SOLICITATION.
10. Offeror must be registered in the System for Award Management (SAM) prior to award of a contract. Offerors must access the CCR through The System for Award Management (SAM) at https://www.sam.gov/SAM/.
11. FOR INFORMATION CALL: Matt Lear
PHONE: 240-669-5109
e-MAIL: matt.lear@nih.gov
COLLECT CALLS WILL NOT BE ACCEPTED.
75N93024R00011
SOLICITATION, OFFER AND AWARD
4. TYPE OF SOLICITATION2. CONTRACT NUMBER 3. SOLICITATION NUMBER
7. ISSUED BY CODE 8. ADDRESS OFFER TO (If other than Item 7)
ORDER UNDER DPAS (15 CFR 700)
6. REQUISITION/PURCHASE NUMBER
NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".
NEGOTIATED (RFP)
SEALED BID (IFB)
5. DATE ISSUED
1. THIS CONTRACT IS A RATED RATING PAGE OF PAGES
1 76
C. E-MAIL ADDRESS
EXT.NUMBERAREA CODE
B. TELEPHONE (NO COLLECT CALLS)A. NAME
10. FOR
INFORMATION
CALL:
CAUTION: LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
(Date)(Hour) local timeuntildepository located in copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if hand carried, in the
SOLICITATION
9. Sealed offers in original and
PART IV - REPRESENTATIONS AND INSTRUCTIONS
OTHER STATEMENTS OF OFFERORS
EVALUATION FACTORS FOR AWARD
INSTRS., CONDS., AND NOTICES TO OFFERORS
REPRESENTATIONS, CERTIFICATIONS AND
LIST OF ATTACHMENTS
CONTRACT CLAUSES
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
I
J
K
L
M SPECIAL CONTRACT REQUIREMENTS
CONTRACT ADMINISTRATION DATA
DELIVERIES OR PERFORMANCE
INSPECTION AND ACCEPTANCE
PACKAGING AND MARKING
DESCRIPTION/SPECS./WORK STATEMENT
SUPPLIES OR SERVICES AND PRICES/COSTS
SOLICITATION/CONTRACT FORM
PART II - CONTRACT CLAUSESPART I - THE SCHEDULE
H
G
F
E
D
C
B
A
SEC. DESCRIPTION PAGE(S) (X) DESCRIPTION SEC. (X)
11. TABLE OF CONTENTS
18. OFFER DATE17. SIGNATURE
SUCH ADDRESS IN SCHEDULE.
IS DIFFERENT FROM ABOVE - ENTER
15C. CHECK IF REMITTANCE ADDRESS
EXT.NUMBERAREA CODE
15B. TELEPHONE NUMBER
(Type or print)AND
ADDRESS
OF
OFFEROR
CODE FACILITY
16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN OFFER15A. NAME
DATEAMENDMENT NO.DATEAMENDMENT NO.
and related documents numbered and dated):
amendments to the SOLICITATION for offerors
(The offeror acknowledges receipt of
14. ACKNOWLEDGEMENT OF AMENDMENTS
CALENDAR DAYS (%)30 CALENDAR DAYS (%)20 CALENDAR DAYS (%)10 CALENDAR DAYS (%)
(See Section I, Clause No. 52.232.8)
13. DISCOUNT FOR PROMPT PAYMENT
designated point(s), within the time specified in the schedule.
by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
OFFER (Must be fully completed by offeror)
IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.
28. AWARD DATE
(Signature of Contracting Officer)
27. UNITED STATES OF AMERICA
25. PAYMENT WILL BE MADE BY
26. NAME OF CONTRACTING OFFICER (Type or print)
CODE 24. ADMINISTERED BY (If other than Item 7)
ITEM
(4 copies unless otherwise specified)
23. SUBMIT INVOICES TO ADDRESS SHOWN IN
41 U.S.C. 3304 (a) ( 10 U.S.C. 2304 (c) (
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
21. ACCOUNTING AND APPROPRIATION20. AMOUNT19. ACCEPTED AS TO ITEMS NUMBERED
AWARD (To be completed by government)
CODE
X
NIAID-ROCK
National Institutes of Health National Institute of Allergy and Infectious Diseases Bethesda, MD 20892-7612
MATTHEW D LEAR +12 09
matt.lear@nih.gov
406-6951
X
X
X
X
X
X
X
X
X
X
X
X
PAGE(S)
AUTHORIZED FOR LOCAL REPRODUCTION
Previous edition is unusable
STANDARD FORM 33 (REV. 6/2014)
Prescribed by GSA - FAR (48 CFR) 53.214(c)
12. In compliance with the above, the undersigned agrees, if this offer is accepted within ______________ calendar days (60 calendar days unless a different period is inserted
SECTION B - Supplies or Services/Prices
1. BRIEF DESCRIPTION OF SUPPLIES OR SERVICES
2. PRICES/COSTS
3. PROVISIONS APPLICABLE TO DIRECT COSTS
4. ADVANCE UNDERSTANDINGS
5. Invoice Processing Platform (IPP)
SECTION C - Description/Specifications
1. REPORTING REQUIREMENTS
SECTION D - Packaging and Marking SECTION E - Inspection and Acceptance SECTION F - Deliveries or Performance
1. PERIOD OF PERFORMANCE
SECTION G - Contract Administration Data
1. CONTRACTING OFFICER REPRESENTATIVE (COR)
2. TASK ORDER PROCEDURE
3. INVOICE SUBMISSION/CONTRACT FINANCING REQUEST AND CONTRACT FINANCIAL REPORT
4. POST AWARD EVALUATION OF CONTRACTOR PERFORMANCE
SECTION H - Special Contract Requirements
1. HUMAN SUBJECTS
2. ACKNOWLEDGEMENT OF FEDERAL FUNDING
3. DISSEMINATION OF FALSE OR DELIBERATELY MISLEADING INFORMATION
4. OMB CLEARANCE
5. RESTRICTION ON PORNOGRAPHY ON COMPUTER NETWORKS
6. GUN CONTROL
7. OPTION PROVISION
8. HHS SECURITY AND PRIVACY LANGUAGE FOR INFORMATION AND IT PROCUREMENTS
9. PUBLICATION AND PUBLICITY
10. REPORTING MATTERS INVOLVING FRAUD, WASTE AND ABUSE
SECTION I - Contract Clauses
1. Authorized Substitutions REMOVE 52.219-9, 52.219-16
2. Authorized Substitutions ADD 52.219-9 *A2
3. Authorized Substitutions ADD 52.232-17
4. Authorized Substitutions REMOVE 52.232-25 *A1
16. FAR 52.219-3 Notice of HUBZone Set-Aside or Sole Source Award. (OCT 2022)
17. FAR 52.219-6 Notice of Total Small Business Set-Aside. (NOV 2020)
18. FAR 52.219-13 Notice of Set-Aside of Orders. (MAR 2020)
19. FAR 52.219-14 Limitations on Subcontracting. (OCT 2022)
21. FAR 52.219-30 Notice of Set-Aside for, or Sole-Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program. (OCT 2022)
31. FAR 52.252-2 Clauses Incorporated by Reference. (FEB 1998)
33. HHSAR 352.219-71 Mentor-Protege Program Reporting Requirements. (JAN 2010)
SECTION J - List of Documents, Exhibits and Other Attachments SECTION K - Representations, Certifications, and Other Statements of Bidders
1. FAR 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021)
SECTION L - Instructions, Conditions, and Notices to Bidders
1. FAR 52.216-1 Type of Contract. (APR 1984)
SECTION M - Evaluation Factors for Award
SECTION B - Supplies or Services/Prices
1. BRIEF DESCRIPTION OF SUPPLIES OR SERVICES
The purpose of this contract is to provide design and implement program evaluation projects for NIAID's scientific research and management programs as well as provide support for evaluation training and evaluation related activities.
Evaluation projects at NIAID often include feasibility studies, needs assessments, process evaluations, outcome and impact evaluations, and related evaluation support and training for NIAID staff.
2. PRICES/COSTS
a. This is an Indefinite Quantity contract as contemplated by FAR 16.504. The Contractor shall be reimbursed by the Government in an amount not less than a total of $ 10,000.00 (minimum) nor more than a total of $ 8,624,675.00 (maximum) for successful performance of this contract.
b. The costs/prices set forth in this ARTICLE will cover the contract period July 19, 2024 through July 18, 2029 .
c. The Government will issue Task Orders based on the work described in SECTION C of this contract.
3. PROVISIONS APPLICABLE TO DIRECT COSTS
This article will prohibit or restrict the use of contract funds, unless otherwise approved by the Contracting Officer. The following is a list of items that may be included in the resultant contract as applicable. 1) Conferences & Meetings, 2) Food for Meals, Light Refreshments & Beverages, 3) Promotional Items, 4) Acquisition, by purchase or lease, of any interest in real property; 5) Special rearrangement or alteration of facilities; 6) Purchase or lease of any item of general purpose office furniture or office equipment regardless of dollar value; 7) Travel Costs including Foreign Travel; 8) Consultant Costs; 9) Subcontract Costs; 10) Patient Care Costs; 11) Accountable Government Property;
12) Printing costs; and 13) Research Funding.
4. ADVANCE UNDERSTANDINGS
Specific elements of cost, which normally require prior written approval of the Contracting Officer before incurrence of the cost (e.g., foreign travel, consultant fees, subcontracts) will be included in this Article if the Contracting Officer has granted his/her approval prior to contract award.
5. Invoice Processing Platform (IPP)
NIH is using a phased transition approach from the NIH Office of Financial Management (OFM) Electronic Invoice Submission instructions to the Department of Treasury's Invoice Processing Platform
(IPP). This award will transition to IPP in the future. The Contractor/Vendor shall use the attached NIH OFM Electronic Invoice Submission Instructions until the Contractor/Vendor has transitioned to IPP as specified on the OALM IPP website at https://oalm.od.nih.gov/IPP. It is the Contractor/Vendor's responsibility to periodically check the OALM IPP website and be prepared to transition to IPP on the designated transition date. Questions concerning the transition to IPP should be directed to NIH- IPPinvoicing@mail.nih.gov. Questions concerning this award should be directed to the NIH Contracting Officer.
All IPP invoices must contain a Unique Entity Identifier (UEI) which is located in the System for Award Management (SAM) and replaces the Dun & Bradstreet Data Universal Numbering System (DUNS) number.
SECTION C - Description/Specifications
Statement of Work
Independently and not as an agent of the Government, the Contractor shall be required to furnish all the necessary services, qualified personnel, material, equipment, and facilities, not otherwise provided by the Government, as needed to perform the Statement of Work, dated 02/28/2024 , attached hereto and made a part of this Solicitation (See SECTION J - List of Attachments).
1. REPORTING REQUIREMENTS
All reports shall be submitted electronically. In addition, one hardcopy of each report shall be submitted to the Contracting Officer.
These reports shall be compliant with Section 508 of the Rehabilitation Act of 1973. Additional information about testing documents for Section 508 compliance, including guidance and specific checklists, by application, can be found at: https://www.hhs.gov/web/section-508/index.html and at:
https://www.section508.gov/create/documents , "Create Accessible Documents."
All paper/hardcopy documents/reports submitted under this contract shall be printed or copied, double-sided, on at least 30 percent post-consumer fiber paper, whenever practicable, in accordance with FAR 4.302(b).
1. Monthly Progress Report
This report shall include a description of the activities during the reporting period, and the activities planned for the ensuing reporting period. The first reporting period consists of the first full month of performance plus any fractional part of the initial month. Thereafter, the reporting period shall consist of each calendar month.
The first report shall be due 08/15/2024 . Thereafter, reports shall be due on or before the 15th calendar day following each reporting period.
2. Annual Progress Report
This report shall include a summation of the results of the entire contract work for the period covered.
An annual report will not be required for the period when the Final Report is due. A Monthly Report shall not be submitted when an Annual Report is due.
The first report shall cover the period 07/19/2024 through 07/18/2025 of this contract and shall be due within 30 days after the Anniversary Date of the Contract. Thereafter, reports shall be due on or before the 30 day following the reporting period.
3. Final Report
The Contractor shall provide the Contracting Officer with one copies of the Final Report in draft form (in accordance with the DELIVERIES Article in SECTION F of this contract/ 15 calendar days prior to the expiration date of this contract.) The Contracting Officer Representative (COR) will review the draft report and provide the Contracting Officer with comments within 7 days after receipt. The Final Report shall be corrected by the Contractor, if necessary and the final version delivered as specified in the above paragraph.
HHS SECURITY AND PRIVACY LANGUAGE FOR INFORMATION AND IT PROCUREMENTS
A. Assessment and Authorization (A&A)- A valid authority to operate (ATO) certifies that the Contractor's information system meets the contract's requirements to protect the agency data.
If the system under this contract does not have a valid ATO, the Contractor (and/or any subcontractor) must work with the agency and supply the deliverables required to complete the ATO within the specified timeline(s) within three (3) months after contract award. The Contractor must conduct the A&A requirements in accordance with HHS IS2P, NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach (latest revision).
For an existing ATO, Contracting Officer Representative must make a determination if the existing ATO provides appropriate safeguards or if an additional ATO is required for the performance of the contract and state as such.
NIH acceptance of the ATO does not alleviate the Contractor's responsibility to ensure the system security and privacy controls are implemented and operating effectively.
B. A&A Package Deliverables - The Contractor (and/or any subcontractor) must provide an A&A package within 30 days of contract award to the CO and/or COR. The following A&A deliverables are required to complete the A&A package.
C. System Security Plan (SSP) - due within 30 days after contract award. The SSP must comply with the NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, the Federal Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline requirements, and other applicable NIST guidance as well as HHS and NIH policies and other guidance. The SSP must be consistent with and detail the approach to IT security contained in the Contractor's bid or proposal that resulted in the award of this contract. The SSP must provide an overview of the system environment and security requirements to protect the information system as well as describe all applicable security controls in place or planned for meeting those requirements. It should provide a structured process for planning adequate, cost-effective security protection for a system. The Contractor must update the SSP at least annually thereafter.
D. Security Assessment Plan/Report (SAP/SAR) - due 30 days after the contract award. The security assessment must be conducted by the assessor and be consistent with NIST SP 800-
53A, NIST SP 800-30, and HHS and NIH policies. The assessor will document the assessment results in the SAR.
The NIH should determine which security control baseline applies and then make a determination on the appropriateness/necessity of obtaining an independent assessment.
Assessments of controls can be performed by Contractor, government, or third parties, with third party verification considered the strongest. If independent assessment is required, include statement below.
Thereafter, the Contractor, in coordination with the NIH shall conduct/assist in the assessment of the security controls and update the SAR at least annually.
E. Independent Assessment - due 90 days after the contract award. The Contractor (and/or subcontractor) must have an independent third-party validate the security and privacy controls in place for the system(s). The independent third party must review and analyze the Security Authorization package, and report on technical, operational, and management level deficiencies as outlined in NIST SP 800-53. The Contractor must address all 'high' deficiencies before submitting the package to the Government for acceptance. All remaining deficiencies must be documented in a system Plan of Actions and Milestones (POA&M).
F. Plan of Actions and Milestones (POA&M) - due 30 days after contract award. The POA&M must be documented consistent with the HHS Standard for Plan of Action and Milestones and NIH policies. All findings/weaknesses must be documented in the POA&M and remediated/mitigated from the date the weaknesses are formally identified and documented by the timelines below:
• Critical within 30 days;
• High within 60 days;
• Medium within 1 year; and
• Low within 1 year.
The NIH will determine the risk rating of vulnerabilities. Identified risks stemming from deficiencies related to the security control baseline implementation, assessment, continuous monitoring, vulnerability scanning, and other security reviews and sources, as documented in the SAR, must be documented and tracked by the Contractor for mitigation in the POA&M document. Depending on the severity of the risks, NIH may require designated POAM weaknesses to be remediated before an ATO is issued. Thereafter, the POA&M must be updated at least quarterly.
G. Contingency Plan and Contingency Plan Test - due 60 days after contract award. The Contingency Plan must be developed in accordance with NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, and be consistent with HHS and NIH policies. Upon acceptance by the System Owner, the Contractor, in coordination with the System Owner, must test the Contingency Plan and prepare a Contingency Plan Test Report that includes the test results, lessons learned and any action items that need to be addressed. Thereafter, the Contractor must update and test the Contingency Plan at least annually.
H. E-Authentication Questionnaire - The contractor (and/or any subcontractor) must collaborate with government personnel to ensure that an E-Authentication Threshold Analysis (E-auth TA) is completed to determine if a full E-Authentication Risk Assessment (E-auth RA) is necessary. System documentation developed for a system using E-auth TA/E-auth RA methods must follow OMB 04-04 and NIST SP 800-63, Rev. 2, Electronic Authentication Guidelines.
Based on the level of assurance determined by the E-Auth, the Contractor (and/or subcontractor) must ensure appropriate authentication to the system, including remote authentication, is in-place in accordance with the assurance level determined by the E-Auth (when required) in accordance with HHS policies.
I. POSITION SENSITIVITY DESIGNATIONS
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). To determine the designation, the Position Designation Tool (PDT) discussion is found at:
https://ors.od.nih.gov/ser/dpsac/administrators/onboarding-new-staff/Pages/position-designation-tool.aspx and the link to access the tool is found at: https://pdt.nbis.mil/ .
The following position sensitivity designation levels apply to this solicitation/contract:
[ ] Tier 5: Critical Sensitive and Special Sensitive National Security, including Top Secret, SCI, and 'Q' access eligibility.
[ ] Tier 5SR: Reinvestigation.
[ ] Tier 4: High Risk Public Trust (HRPT).
[ ] Tier 4SR: Reinvestigation.
[ ] Tier 3: Non-Critical Sensitive, National Security, including Secret and 'L' access eligibility.
[ ] Tier 3SR: Reinvestigation.
[ ] Tier 2S with Subject Interview: Moderate Risk Public Trust (MRPT).
[ ] Tier 2SR: Reinvestigation.
[X] Tier 1: Low Risk, Non-Sensitive, including HSPD-12 Credentialing.
J. HOMELAND SECURITY PRESIDENTIAL DIRECTIVE (HSPD)-12
Roster-
The Contractor (and/or any subcontractor) must submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster must be submitted to the COR and/or CO within fourteen (14) calendar days after the effective date of this contract. Any revisions to the roster as a result of staffing changes must be submitted within seven (7) calendar days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
An electronic template, 'Roster of Employees Requiring Suitability Investigations,' is available for contractor use at: https://oamp.od.nih.gov/nih-document-generation-system/dgs-workform-information/attachment-files-section-j
a. If the Contractor is filling a new position, the Contractor must provide a position description and the Government will determine the appropriate suitability level. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.
b. Upon receipt of the Government's notification of applicable Suitability Investigations required, the Contractor must complete and submit the required forms within 30 days of the notification.
c. The Contractor must notify the Contracting Officer in advance when any new personnel, who are subject to a background check/investigation, will work under the contract and if they have previously been the subject of national agency checks or background investigations.
d. All contractor and subcontractor employees must comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract. Contractors may begin work after the fingerprint check has been completed.
e. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays - see FAR 52.249-14. Accordingly, the Contractor must ensure that any additional employees whose names it submits for work under this contract have a reasonable chance for approval.
f. Typically, the Government investigates personnel at no cost to the Contractor.
However, multiple investigations for the same position may, at the Contracting Officer's discretion, justify reduction(s) in the contract price of no more that the cost of the additional investigation(s).
g. The Contractor must include language similar to this 'HHS Controlled Facilities and Information Systems Security' language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).
h. The Contractor must direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.
i. Within 7 calendar days after the Government's final acceptance of the work under this contract, or upon termination of the contract, the Contractor must return all identification badges to the Contracting Officer or designee.
K. CONTRACT INITIATION AND EXPIRATION
a. General Security Requirements - The Contractor (and/or any subcontractor) must comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the Contractor must follow the HHS EPLC framework and methodology or and in accordance with the HHS Contract Closeout Directive (2018) located at:
https://oamp.od.nih.gov/sites/default/files/DGS/contracting-forms/HHS-Closeout-Directive- 2018.pdf . HHS EA requirements located at: https://www.hhs.gov/sites/default/files/eplc-policy-dec-2016.pdf and NIH EA requirements are located at:
https://ocio.nih.gov/PM/Pages/EPLC.aspx .
b. System Documentation - Contractors (and/or any subcontractors) must follow and adhere to HHS System Development Life Cycle requirements, at a minimum, for system development and provide system documentation at designated intervals ( specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
c. Sanitization of Government Files and Information - As part of contract closeout and at expiration of the contract, the Contractor ( and/ or any subcontractor) must provide all required documentation in accordance with the NIH Media Sanitization and Disposal Policy to the CO and/ or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800- 88, Guidelines for Media Sanitization.
d. Notification - The Contractor ( and/ or any subcontractor) must notify the CO and/ or COR and system ISSO within fifteen days before an employee stops working under this contract.
e. Contractor Responsibilities Upon Physical Completion of the Contract- The Contractor (and/ or any subcontractors) must return all government information and IT resources ( i.e., government information in non- government- owned systems, media, and backup systems) acquired during the term of this contract to the CO and/ or COR. Additionally, the Contractor must provide a certification that all government information has been properly sanitized and purged from Contractor- owned systems, including backup systems and media used during contract performance, in accordance with HHS and/ or NIH policies.
f. The Contractor ( and/or any subcontractor) must perform and document the actions identified in the NIH Contractor Employee Separation Checklist https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Emp-sep-checklist.pdf when an employee terminates work under this contract within 2 days of the employee's exit from the contract. All documentation must be made available to the CO and/ or COR upon request.
g. Contractor Non- Disclosure Agreement (NDA)- Each Contractor ( and/ or any subcontractor) employee having access to non- public government information under this contract shall complete the NIH non- disclosure agreement:
https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/Nondisclosure.pdf , as applicable. A copy of each signed and witnessed NDA must be submitted to the Contracting Officer ( CO) and/ or CO Representative ( COR) prior to performing any work under this acquisition.
h. Vulnerability Scanning Reports - The Contractor must report the results of the required monthly special vulnerability scans no later than 10 days following the end of each reporting period. If required monthly, this report may be included as part of the Technical Progress Report. Otherwise, this report must be submitted under a separate cover on monthly basis.
i. Government Access for Security Assessment. In addition to the Inspection Clause in the contract, the Contractor (and/or any subcontractor) must afford the Government access to the Contractor's facilities, installations, operations, documentation, information systems, and personnel used in performance of this contract to the extent required to carry out a program of security assessment ( to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the confidentiality, integrity, and availability of federal data or to the protection of information systems operated on behalf of HHS, including but are not limited to:
i. At any tier handling or accessing information, consent to and allow the Government, or an independent third party working at the Government's direction, without notice at any time during a weekday during regular business hours contractor local time, to access contractor and subcontractor installations, facilities, infrastructure, data centers, equipment (including but not limited to all servers, computing devices, and portable media), operations, documentation (whether in electronic, paper, or other forms), databases, and personnel which are used in performance of the contract. The Government includes but is not limited to the U.S. Department of Justice, U.S.
Government Accountability Office, and the HHS Office of the Inspector General (OIG).
The purpose of the access is to facilitate performance inspections and reviews, security and compliance audits, and law enforcement investigations. For security audits, the audit may include but not be limited to such items as buffer overflows, open ports, unnecessary services, lack of user input filtering, cross site scripting vulnerabilities, SQL injection vulnerabilities, and any other known vulnerabilities.
ii. At any tier handling or accessing protected information, fully cooperate with all audits, inspections, investigations, forensic analysis, or other reviews or requirements needed to carry out requirements presented in applicable law or policy. Beyond providing access, full cooperation also includes, but is not limited to, disclosure to investigators of information sufficient to identify the nature and extent of any criminal or fraudulent activity and the individuals responsible for that activity. It includes timely and complete production of requested data, metadata, information, and records relevant to any inspection, audit, investigation, or review, and making employees of the contractor available for interview by inspectors, auditors, and investigators upon request. Full cooperation also includes allowing the Government to make reproductions or copies of information and equipment, including, if necessary, collecting a machine or system image capture.
iii. Segregate Government protected information and metadata on the handling of Government protected information from other information. Commingling of information is prohibited. Inspectors, auditors, and investigators will not be precluded from having access to the sought information if sought information is commingled with other information.
iv. Cooperate with inspections, audits, investigations, and reviews.
b. Section 508 Annual Report
The Contractor must submit an annual Section 508 report in accordance with the schedule set forth by the Contracting Officer (CO)/Contracting Officer's Representative (COR). The Section 508 Report Template and Instructions for completing the report are available at:
https://www.hhs.gov/sites/default/files/web/508/contracting/technology/section_508_annual _report.doc.
c. REPORTING REQUIREMENTS FOR USE WITH THE ELECTRONIC REPORT DELIVERABLE SUBMISSION (eRDS) SITE
All reports required herein must be submitted in electronic format. All electronic contract deliverables must be submitted via the NIAID electronic Report Deliverable Submission (eRDS) Site, available at the following website: https://erds.niaid.nih.gov/ . All electronic reports submitted must be compliant with Section 508 of the Rehabilitation Act of 1973. Additional information about testing documents for Section 508 compliance, including guidance and specific checklists, by application, can be found at https://www.hhs.gov/web/section-508/index.html and at:
https://www.section508.gov/create/documents , 'Create Accessible Documents.'
SECTION D - Packaging and Marking
A. PACKAGING, MARKING, AND SHIPPING
All deliverables required under this contract shall be packaged, marked and shipped in accordance with Government specifications. At a minimum, all deliverables shall be marked with the contract number and Contractor name. The Contractor shall guarantee that all required materials shall be delivered in immediate usable and acceptable condition.
SECTION E - Inspection and Acceptance
1. The Contracting Officer or the duly authorized representative will perform inspection and acceptance of materials and services to be provided.
b. For the purpose of this SECTION, Contracting Officer/s Representative is the authorized representative of the Contracting Officer.
c. Inspection and acceptance will be performed at:
5601 Fishers Lane Room 5F38 Rockville, Maryland 20852
2. This contract incorporates the following clause by reference, with the same force and effect as if it were given in full text. Upon request, the Contracting Officer will make its full text available.
1. FAR 52.246-4 Inspection of Services - Fixed-Price. (AUG 1996)
2. FAR 52.246-5 Inspection of Services - Cost-Reimbursement. (APR 1984)
SECTION F - Deliveries or Performance
1. PERIOD OF PERFORMANCE
The period of performance of this contract shall be from July 19, 2024 through July 18, 2029 .
SECTION G - Contract Administration Data
1. CONTRACTING OFFICER REPRESENTATIVE (COR)
The following Contracting Officer Representative (COR) will represent the Government for the purpose of this contract: To Be Determined
The COR is responsible for: (1) monitoring the Contractor's technical progress, including the surveillance and assessment of performance and recommending to the Contracting Officer changes in requirements; (2) interpreting the statement of work and any other technical performance requirements; (3) performing technical evaluation as required; (4) performing technical inspections and acceptances required by this contract; and (5) assisting in the resolution of technical problems encountered during performance.
The alternate COR is responsible for carrying out the duties of the COR only in the event that the COR can no longer perform his/her duties as assigned.
The Contracting Officer is the only person with authority to act as agent of the Government under this contract. Only the Contracting Officer has authority to: (1) direct or negotiate any changes in the statement of work; (2) modify or extend the period of performance; (3) change the delivery schedule;
(4) authorize reimbursement to the Contractor for any costs incurred during the performance of this contract; (5) otherwise change any terms and conditions of this contract; or (6) sign written licensing agreements. Any signed agreement shall be incorporated by reference in Section K of the contract
The Government may unilaterally change its COR designation.
2. TASK ORDER PROCEDURE
This contract provides for the issuance of Task Orders on a negotiated basis as follows:
a. General
Only the Contracting Officer may issue Task Orders to the Contractor, providing specific authorization or direction to perform work within the scope of the contract and as specified in the Statement of Work. Unless specifically authorized by the Contracting Officer, the Contractor shall not commence work until a fully executed Task Order has been awarded. The Contractor may incur costs under this contract in performance of task orders and task order modifications issued in accordance with this ARTICLE.
No other costs are authorized unless otherwise specified in the contract or expressly authorized by the Contracting Officer.
b. Requesting Task Order Proposals.
The Contracting Officer or a designated individual may solicit responses to requirements from the Contractor within a technical area covered by a task order requirement in writing. A Task Order Request for Proposals (TORFP) will be prepared and issued for each task order requirement.
Generally, the Task Order Request for Proposal (TORFP) will include but is not limited to the following:
1. Statement of Work;
2. Reporting Requirements and Deliverables;
3. Proposal Due Date and Location to Deliver Proposals;
4. Period of Performance of Task Order;
5. Anticipated type of Task Order;
6. Technical Proposal Instructions;
7. Business proposal Instructions
8. Evaluation Factors for Award
All contract clauses contained this contract shall be incorporated in the TORFP and the resultant task order. If conflicts exist between the contract clauses and the information outlined in the task order, the contract language takes precedence over the information in the task order.
c. Evaluation and Award of Task Order Proposals
The Government will evaluate the Task Order proposals against the requirements of the TORFP.
Specifically, the technical evaluation factors, cost/price, past performance and any other factor specifically identified in the TORFP will be used for evaluation of each proposal. In addition, the TORFP will identify the basis for selecting a Contractor for award. Generally, technical factors will be significantly more important than cost or price. However, each TORFP will specify how the award decision will be made.
Upon completion of evaluations, the Contracting Officer will issue a task order to the Contractor
The Contracting Officer will notify the Contractor(s) of the selection decision in writing.
3. INVOICE SUBMISSION/CONTRACT FINANCING REQUEST AND CONTRACT FINANCIAL
REPORT
a. The Contractor must submit invoices to the Department of Treasury's Invoice Processing Platform (IPP) at https://www.ipp.gov with a copy of the invoice to the approving official, as directed below.
The Contractor shall submit a copy of the electronic invoice to the following Approving Official (Contracting Officer) and Contracting Officer Representative:
Official: Contracting Officer
Name- Rosemary Gomes Email Address- rosemary.gomes@nih.gov
Contracting Officer Representative
Name- Juli Brown Email Address- jbrown@niaid.nih.gov
For inquiries regarding the status of invoices, contact OFM Customer Service via email at ofm_customer_service@mail-cmp.niceincontact.com or via phone at 301-496-6088. To send your inquiries via other available communication methods refer to the OFM Customer Service website at https://ofm.od.nih.gov/Pages/Customer-Service.aspx .
Note: The OFM Customer Service is open Eastern Standard Time Monday - Friday from 8:30 a.m. to 5:00 p.m. and is closed between 12:00 p.m. to 1:00 p.m.
c. In addition to the requirements specified in FAR 32.905 for a proper invoice, the Contractor shall include the following information on the face page of all payment requests:
a. Name of the Office of Acquisitions. The Office of Acquisitions for this contract is NIAID .
b. Federal Taxpayer Identification Number (TIN). If the Contractor does not have a valid TIN, it shall identify the Vendor Identification Number (VIN) on the payment request. The VIN is the number that appears after the Contractor's name on the face page of the contract. [Note: A VIN is assigned to new contracts awarded on or after June 4, 2007, and any existing contract modified to include the VIN number.] If the Contractor has neither a TIN, Unique Entity Identifier (UEI), or VIN, contact the Contracting Officer. Note: The Contractor shall not include TIN if it is a Social Security Number.
c. Unique Entity Identifier (UEI). The UEI is located in the System for Award Management (SAM) and replaces the Dun & Bradstreet Data Universal Numbering System (DUNS) number. The UEI number must identify the Contractor's name and address exactly as stated in the contract and as registered in the Central Contractor Registration (CCR) database. If the Contractor does not have a valid UEI number, it shall identify the Vendor
Identification Number (VIN) on the payment request. The VIN is the number that appears after the Contractor's name on the face page of the contract. [Note: A VIN is assigned to new contracts awarded on or after June 4, 2007, and any existing contract modified to include the VIN number.] If the Contractor has neither a TIN, UEI, or VIN, contact the Contracting Officer.
d. Invoice Matching Option. This contract requires a two-way match.
e. Unique Invoice Number. Each payment request must be identified by a unique invoice number, which can only be used one time regardless of the number of contracts or orders held by an organization.
f. The Contract Title is:
NIAID Evaluation Services
g. Contract Line Items as follows:
Line Item # Line Item Description
1. Inquiries regarding payment of invoices shall be directed to the designated billing office,
(301) 496-6088 .
2. Invoice Instructions for NIH Fixed-Price Type Contracts, NIH(RC)-2, are attached and made part of this contract. The Contractor shall follow the attached instructions and submission procedures specified below to meet the requirements of a "proper invoice" pursuant to FAR Subpart 32.9, Prompt Payment.
4. POST AWARD EVALUATION OF CONTRACTOR PERFORMANCE
a. Contractor Performance Evaluations
Interim and Final evaluations of Contractor performance will be prepared on this contract in accordance with FAR Subpart 42.15. The Final performance evaluation will be prepared at the time of completion of work. In addition to the Final evaluation, Interim evaluation(s) will be prepared Annually to coincide with the anniversary date of the contract.
Interim and Final evaluations will be provided to the Contractor as soon as practicable after completion of the evaluation. The Contractor will be permitted thirty days to review the document and to submit additional information or a rebutting statement. If agreement cannot be reached between the parties, the matter will be referred to an individual one level above the Contracting Officer, whose decision will be final.
Copies of the evaluations, Contractor responses, and review comments, if any, will be retained as part of the contract file, and may be used to support future award decisions.
b. Electronic Access to Contractor Performance Evaluations
Contractors may access evaluations through a secure Web site for review and comment at the following address:
https://www.cpars.gov
SECTION H - Special Contract Requirements
1. HUMAN SUBJECTS
It is hereby understood and agreed that research involving human subjects shall not be conducted under this contract, and that no material developed, modified, or delivered by or to the Government under this contract, or any subsequent modification of such material, will be used by the Contractor or made available by the Contractor for use by anyone other than the Government, for experimental or therapeutic use involving humans without the prior written approval of the Contracting Officer.
2. ACKNOWLEDGEMENT OF FEDERAL FUNDING
The Contractor shall clearly state, when issuing statements, press releases, requests for proposals, bid solicitations and other documents describing projects or programs funded in whole or in part with Federal money: (1) the percentage of the total costs of the program or project which will be financed with Federal money; (2) the dollar amount of Federal funds for the project or program; and (3) the percentage and dollar amount of the total costs of the project or program that will be financed by nongovernmental sources.
3. DISSEMINATION OF FALSE OR DELIBERATELY MISLEADING INFORMATION
The Contractor shall not use contract funds to disseminate information that is deliberately false or misleading.
4. OMB CLEARANCE
In accordance with HHSAR 352.211-3, Paperwork Reduction Act, the Contractor shall not proceed with surveys or interviews until such time as Office of Management and Budget (OMB) Clearance for conducting interviews has been obtained by the Contracting Officer Representative (COR) and the Contracting Officer has issued written approval to proceed.
5. RESTRICTION ON PORNOGRAPHY ON COMPUTER NETWORKS
The Contractor shall not use contract funds to maintain or establish a computer network unless such network blocks the viewing, downloading, and exchanging of pornography.
6. GUN CONTROL
The Contractor shall not use contract funds in whole or in part, to advocate or promote gun control.
7. OPTION PROVISION
Unless the Government exercises its option pursuant to the Option Clause set forth in SECTION I., the contract will consist only of the Base Period of the Statement of Work as defined in Sections C and F of the task order. Pursuant to FAR 52.217-8, Option to Extend Services set forth in SECTION I. of this contract, the Government may, by unilateral contract modification, require the Contractor to perform additional options set forth in the Statement of Work and also defined in Sections C and F of the task order. If the Government exercises this option, notice must be given at least 60 days prior to the expiration date of a task order, and the Use for Fixed-Price Contracts: price of the task order will be increased as set forth in the Option Prices Article in SECTION B of the task order.
8. HHS SECURITY AND PRIVACY LANGUAGE FOR INFORMATION AND IT
PROCUREMENTS
A. INFORMATION SECURITY AND/OR PHYSICAL ACCESS SECURITY
A. Baseline Security Requirements
1. Applicability. The requirements herein apply whether the entire contract or order (hereafter 'contract'), or portion thereof, includes either or both of the following:
i. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
ii. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of 'information technology' (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2. Safeguarding Information and Information Systems. All government information and information systems must be protected in accordance with HHS/NIH policies and level of risk.
At a minimum, the Contractor (and/or any subcontractor) must:
i. Protect the:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
ii. Categorize all information owned and/or collected/managed on behalf of HHS/NIH and information systems that store, process, and/or transmit HHS information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories . Based on information provided by the ISSO, CISO, OpDiv SOP, or other representative, the impact level for each Security Objective (Confidentiality, Integrity, and Availability) and the Overall Impact Level, which is the highest watermark of the three factors of the information or information system are the following:
• Confidentiality: X Low [ ] Moderate [ ] High
• Integrity: X Low [ ] Moderate [ ] High
• Availability: X Low [ ] Moderate [ ] High
• Overall Risk Level: X Low [ ] Moderate [ ] High
iii. Based on the agreed-upon level of impact, implement the necessary safeguards to protect all information systems and information collected and/or managed on behalf of HHS/NIH regardless of location or purpose.
iv. Report any discovered or unanticipated threats or hazards by either the agency or contractor, or if existing safeguards have ceased to function immediately after discovery, within one (1) hour or less, to the government representative(s).
v. Adopt and implement all applicable policies, procedures, controls, and standards required by the HHS/NIH Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain all applicable security and privacy policies by contacting the CO/COR or HHS/NIH security and/or privacy officials.
3. Privacy Act. Comply with the Privacy Act requirements (when applicable), and tailor FAR and HHSAR clauses as needed.
4. Privacy Compliance.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .