RFQ 15B50226Q00000010.pdf

PDF 239 KB Posted

Attached to
FY 2026 Landfill Services Federal contract opportunity
Solicitation number
15B50226Q00000010
Issued by
Department of Justice Bureau of Prisons Federal Correctional Complex Beaumont

About this file

This is a Request for Quote (RFQ) from the Federal Bureau of Prisons (FCC Beaumont) for Fiscal Year 2026 Landfill Services. The solicitation seeks a contractor to provide two types of waste disposal services: compacted trash/waste and non-compacted trash/waste disposal at a landfill located in Jefferson County, Texas. The estimated quantities are 2,880 tons of compacted waste and 900 tons of non-compacted waste, to be delivered between 10/01/2025 and 09/30/2026.

Key requirements include that the offeror must own or operate the permitted landfill, which must be located within Jefferson County, Texas. Subcontracting disposal services is not allowed. The solicitation is a Lowest Price Technically Acceptable procurement, with evaluation factors including technical acceptability (compliance with solicitation requirements), price reasonableness, and contractor responsibility. The anticipated award date is 09/18/2025, with a contract effective date of 10/01/2025. The contract will be a firm fixed price arrangement, and funds are not currently available, with funding expected to be added after October 1, 2026.

View the file

Other files for this federal contract opportunity

Other files attached to FY 2026 Landfill Services, newest first.
File Type Posted
Performance Work Statement - FY26 Landfill Services.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

15B50226Q00000010 Page 1 of 49

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 AND 30.

1. REQUISITION NUMBER PAGE 1 OF

5. SOLICITATION NUMBER

15B50226Q00000010

2. CONTRACT NUMBER 3. AWARD/EFFECTIVE

DATE

4. ORDER NUMBER 6. SOLICITATION ISSUE

DATE

09/12/2025

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

D. Tydlacka dtydlacka@bop.gov

b. TELEPHONE NUMBER (No collect calls) 8. OFFER DUE DATE / LOCAL

TIME

09/17/2025 14:00 CT

CODE 15B502

Federal Bureau of Prisons

FCC Beaumont

5430 Knauth Road

Beaumont, TX 77705

9. ISSUED BY X UNRESTRICTED OR SET ASIDE: % FOR

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

(SDVOSB)

WOMEN-OWNED SMALL

BUSINESS (WOSB)

ECONOMICALLY DISADVANTAGED

WOMEN-OWNED SMALL BUSINESS

(EDWOSB)

8(A)

NORTH AMERICAN

INDUSTRY CLASSIFICATION

STANDARD (NAICS):

562212

SIZE STANDARD:

10. THE ACQUISITION IS

SEE SCHEDULE

11. DELIVERY FOR FREE ON BOARD

(FOB) DESTINATION UNLESS

BLOCK IS MARKED

NET 30

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER THE

DEFENSE PRIORITIES AND

ALLOCATIONS SYSTEM -

DPAS (15 CFR 700)

13b. RATING

X REQUEST

FOR QUOTE

(RFQ)

INVITATION

FOR BID

(IFB)

REQUEST

FOR

PROPOSAL

(RFP)

14. METHOD OF SOLICITATION

CODE15. DELIVER TO

BEAUMONT, TX 77705

CODE 15B50216. ADMINISTERED BY

Federal Bureau of Prisons FCC Beaumont 5430 Knauth Road Beaumont, TX 77705

D. Tydlacka / C. Valderas dtydlacka@bop.gov / cvalderas@bop.gov

FACILITY

CODE

CODE

TELEPHONE NUMBER

17a. CONTRACTOR/

OFFEROR

BBMXCODE18a. PAYMENT WILL BE MADE BY

Federal Bureau of Prisons FCC Beaumont

PO BOX 26015

Beaumont, TX 77720

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER SEE ADDENDUM

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

Delivery Date: 10/01/2025

FY 2026 Landfill Services

UEI #: _____________________________________

TIN #: _______________________________________

EMAIL: ______________________________________

Firm Fixed Price

See Continuation Sheet(s) (Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)

X 27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4. FAR 52.212-3

AND 52.212-5 ARE ATTACHED. ADDENDA

X ARE ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

X 28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN 1 COPIES TO

ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH

OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE

TERMS AND CONDITIONS SPECIFIED.

29. AWARD OF CONTRACT: REFERENCE _____________________________

OFFER DATED _________________ . YOUR OFFER ON SOLICITATION (BLOCK

5) INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH

HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED 31b. NAME OF THE CONTRACTING OFFICER (Type or print)

Dillon Tydlacka

31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA - FAR (48 CFR) 53.212

15B50226Q00000010 Page 2 of 49

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: _________________________________

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

PARTIAL FINAL

33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED

CORRECT FOR

COMPLETE PARTIAL FINAL

36. PAYMENT 37. CHECK NUMBER

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 11/2021) BACK

15B50226Q00000010 Page 3 of 49

Table of Contents

Section Description Page Number

Solicitation/Contract Form 1 Commodity or Services Schedule

Tailoring 2 Contract Clauses

52.204-13 System for Award Management Maintenance (Oct 2018) 52.212-4 Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2023) 52.232-18 Availability of Funds (Apr 1984) 52.232-37 Multiple Payment Arrangements (May 1999) 52.232-40 Providing Accelerated Payments to Small Business Subcontractors (Mar 2023) 52.243-1 Changes-Fixed-Price (Aug 1987) 52.216-18 Ordering (Aug 2020) 52.216-21 Requirements (Oct 1995) 2852.201-70 Contracting Officer's Representative (COR) (NOV 2020)

BOP 2852.242-71 EVALUATION OF CONTRACTOR PERFORMANCE UTILIZING CPARS

(APR 2011)

DOJ-02 Contractor Privacy Requirements (JAN 2022) DOJ-03 Personnel Security Requirements For Contractor Employees (Nov 2021) DOJ-08 Continuing Contract Performance During a Pandemic Influenza or other National Emergency (OCT 2007) 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial Products and Commercial Services (Jan 2025)

3 List of Attachments 4 Solicitation Provisions

52.204-7 System for Award Management (Nov 2024) 52.212-1 Instructions to Offerors-Commercial Products and Commercial Services (Sep 2023) 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment (Nov 2021) 52.204-29 Federal Acquisition Supply Chain Security Act Orders-Representation and Disclosures (Dec 2023) 52.247-20 Estimated Quantities or Weights for Evaluation of Offers (Apr 1984) 2852.233-70 Protests Filed Directly with the Department of Justice (NOV 2020) BOP 2852.237-78 Submission/Evaluation of Quotations/Offers by Individuals (Nov 2014) 52.212-2 Evaluation-Commercial Products and Commercial Services (Nov 2021) 52.212-3 Offeror Representations and Certifications-Commercial Products and Commercial Services (May 2024)

15B50226Q00000010 Page 4 of 49

Section 1 - Commodity or Services Schedule

SCHEDULE OF SUPPLIES/SERVICES

CONTINUATION SHEET

ITEM NO. SUPPLIES/SERVICES MAX.

QUANTITY

UNIT UNIT PRICE AMOUNT

0001 Compacted trash/waste storage and disposal. Contractor will accept compacted trash/waste that is delivered by BOP personnel/ inmates. Contractor will weigh delivered trash/waste by tonnage and provide a scale ticket/receipt for each load.

PSC: S205

Line Period of Performance: 10/01/2025 - 09/30/2026

Delivery Schedule:

Delivery Description:

Delivery Number: 1 Delivery Period: 10/01/2025 - 09/30/2026 Quantity: 2,880.000000

2,880 TN $________ $_________________

ITEM NO. SUPPLIES/SERVICES MAX.

QUANTITY

UNIT UNIT PRICE AMOUNT

0002 Non-compacted trash/waste storage and disposal. Contractor will accept non-compacted trash/waste that is delivered by BOP personnel/inmates. Contractor will weigh delivered trash/waste by tonnage and provide a scale ticket/receipt for each load.

Quantities are estimates based on 12 months of services. The quantity of services to be provided by the Contractor is estimated.

These estimates are not a representation to a quoter or contractor that the estimated quantities will be required or ordered, or that conditions affecting these requirements will remain stable or normal. Contract pricing shall include all charges to the government for providing the services required by this solicitation.

PSC: S205

Line Period of Performance: 10/01/2025 - 09/30/2026

Delivery Schedule:

Delivery Description:

Delivery Number: 1 Delivery Period: 10/01/2025 - 09/30/2026 Quantity: 900.000000

900 TN $________ $_________________

Tailoring

All potential quoters are advised that this solicitation includes the clause FAR 52.232-18 Availability of Funds. Funds are not presently available for this solicitation. The initial award will not be funded.

On or after October 1, 2026, when upcoming fiscal year funds become available to the Contracting Officer, a modification to the award will be created to include the funding.

The Government reserves the right to cancel this solicitation at any time; either before or after the closing date. In the event of cancellation, the Government shall have no obligation to reimburse any quoter for any costs incurred in connection with the preperation or submission of its quote.

Anticipated date of award: 09/18/2025

15B50226Q00000010 Page 5 of 49

Anticipated effective date of award: 10/01/2025

H.1 Requirement for Landfill Ownership/Operation

(a) To be eligible for award, the Offeror must own or operate a permitted landfill. Subcontracting disposal services to third-party landfill operators will not be considered responsive to this solicitation.

(b) The landfill must be located within Jefferson County, Texas. Landfills located outside of Jefferson County, Texas will not be considered.

(c) The Offeror shall provide with its proposal:

1. The name, address, and permit number of the landfill to be used; and

2. Documentation demonstrating ownership or operation authority of the landfill.

H.2 Site Inspection

Offerors may be required to permit Government representatives to inspect the proposed landfill facility prior to award to verify compliance with solicitation requirements.

L.1 FAR 52.212-1 Instructions to Offerors—Commercial Products and Commercial Services

(NOV 2023)

(a) Offerors shall submit offers in accordance with this provision. Quoters should include their Unique Entity Identifier (UEI) number in their quotes.

(b) Submission of an offer constitutes the Offeror’s acknowledgment that it is registered in the System for Award Management (SAM) in accordance with FAR 4.1102 and that it has completed the representations and certifications required under FAR 52.212-3.

(c) All communications regarding this RFQ, including any of a technical nature, must be made in writing to the Contracting Officer. Questions will not be answered by telephone or in person. Please read the important instructions that are incorporated by reference in the provision at FAR 52.212-1, “Instructions to Offerors-Commercial Items”, and any addendum thereto. The Contracting Officer assigned to this procurement is the undersigned. Your attention is directed to the fact that the Contracting Officer is the only individual who can legally commit or obligate the Government to an expenditure of public funds should a contract result from this RFQ.

(d) Prospective quoters are also cautioned against discussing the preparation of their quote (or any technical questions) with Government technical personnel. The circumstances of such contact, when verified, may result in non-consideration of the quote. Accordingly, all communication prior to award shall be directed to the Contracting Officer, in writing, at the aforementioned address.

(e) Quotes mailed through the United States Postal Service shall be submitted to the following address: Federal Bureau of Prisons, Federal Correctional Complex, P.O. Box 26015, Beaumont, Texas 77720-6015, Attn: Dillon Tydlacka, Contract Specialist.

15B50226Q00000010 Page 6 of 49

(f) Quotations delivered by FEDEX or other carrier shall be submitted to the following address:

Federal Bureau of Prisons, Federal Correctional Complex, 5980 Knauth Rd, Beaumont, Texas 77705, Attn: Dillon Tydlacka, Contract Specialist.

(g) Faxed quotations and photocopies will not be accepted. However, emailed quotations will be accepted. Quotations delivered by email shall be submitted to the following email addresses:

dtydlacka@bop.gov and cvalderas@bop.gov.

(h) Please place any questions you may have in writing and email them to dtydlacka@bop.gov and cvalderas@bop.gov. We will consider all questions received and provide responses, where appropriate.

L.2 Responsibility Determination (FAR 9.103 and 9.104-1)

(a) Award will only be made to an Offeror determined to be responsible, in accordance with FAR Part 9.

(b) To be determined responsible, an Offeror must:

1. Be registered and active in SAM (no exclusions for debarment, suspension, or ineligibility).

2. Demonstrate adequate financial resources and the ability to comply with the required performance schedule.

3. Have a satisfactory record of integrity, business ethics, and past performance.

4. Possess the necessary organization, experience, and facilities to perform the work.

M.1 Basis for Award

The Government intends to make award to the responsible Offeror whose offer is technically acceptable and represents the lowest price to the Government.

M.2 Responsibility Determination

(a) Award will only be made to an Offeror that is determined responsible under FAR 9.103 and 9.104-1.

(b) The Contracting Officer will verify that the apparent successful Offeror:

1. Is registered and active in the System for Award Management (SAM), with no active exclusions.

2. Has a satisfactory record of integrity, ethics, and past performance.

3. Possesses the financial resources and organizational capacity to perform the requirement.

M.3 Evaluation Factors

The following factors will be evaluated:

1. Technical Acceptability – Compliance with the requirements of this solicitation, including landfill ownership/operation and Jefferson County, TX location.

2. Price – Reasonableness of proposed pricing.

3. Responsibility – Determination of responsibility in accordance with FAR 9.104-1, based on information in SAM, past performance records, and other sources as deemed appropriate.

15B50226Q00000010 Page 7 of 49

M.4 Award Without Discussions

The Government reserves the right to award without discussions. Offerors are encouraged to submit their best terms with their initial quote.

15B50226Q00000010 Page 8 of 49

Section 2 - Contract Clauses

A.1 ADDENDUM TO FAR 52.212-4, Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2023)

The terms and conditions for the following clauses are hereby incorporated into this solicitation and resulting contract as an addendum to FAR clause 52.212-4.

Clauses By Reference

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov

Clause Title Fill-ins (if applicable)

52.204-13 System for Award Management Maintenance (Oct 2018)

52.212-4 Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2023)

52.232-18 Availability of Funds (Apr 1984)

52.232-37 Multiple Payment Arrangements (May 1999)

52.232-40 Providing Accelerated Payments to Small Business

Subcontractors (Mar 2023)

52.243-1 Changes-Fixed-Price (Aug 1987)

Clauses By Full Text

52.252-2 Clauses Incorporated by Reference (Feb 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

www.acquisition.gov [Insert one or more Internet addresses]

(End of clause)

15B50226Q00000010 Page 9 of 49

52.216-18 Ordering (Aug 2020)

(a) Any supplies and services to be furnished under this contract shall be ordered by issuance of delivery orders or task orders by the individuals or activities designated in the Schedule. Such orders may be issued from 10/01/2025 through 09/30/2026 [insert dates].

(b) All delivery orders or task orders are subject to the terms and conditions of this contract. In the event of conflict between a delivery order or task order and this contract, the contract shall control.

(c) A delivery order or task order is considered "issued" when--

(1) If sent by mail (includes transmittal by U.S. mail or private delivery service), the Government deposits the order in the mail;

(2) If sent by fax, the Government transmits the order to the Contractor's fax number; or

(3) If sent electronically, the Government either--

(i) Posts a copy of the delivery order or task order to a Government document access system, and notice is sent to the Contractor; or

(ii) Distributes the delivery order or task order via email to the Contractor's email address.

(d) Orders may be issued by methods other than those enumerated in this clause only if authorized in the contract.

(End of clause)

52.216-21 Requirements (Oct 1995)

(a) This is a requirements contract for the supplies or services specified, and effective for the period stated, in the Schedule. The quantities of supplies or services specified in the Schedule are estimates only and are not purchased by this contract. Except as this contract may otherwise provide, if the Government's requirements do not result in orders in the quantities described as "estimated" or "maximum" in the Schedule, that fact shall not constitute the basis for an equitable price adjustment.

(b) Delivery or performance shall be made only as authorized by orders issued in accordance with the Ordering clause.

Subject to any limitations in the Order Limitations clause or elsewhere in this contract, the Contractor shall furnish to the Government all supplies or services specified in the Schedule and called for by orders issued in accordance with the Ordering clause. The Government may issue orders requiring delivery to multiple destinations or performance at multiple locations.

(c) Except as this contract otherwise provides, the Government shall order from the Contractor all the supplies or services specified in the Schedule that are required to be purchased by the Government activity or activities specified in the Schedule.

(d) The Government is not required to purchase from the Contractor requirements in excess of any limit on total orders under this contract.

(e) If the Government urgently requires delivery of any quantity of an item before the earliest date that delivery may be specified under this contract, and if the Contractor will not accept an order providing for the accelerated delivery, the Government may acquire the urgently required goods or services from another source.

(f) Any order issued during the effective period of this contract and not completed within that period shall be completed by the Contractor within the time specified in the order. The contract shall govern the Contractor's and Government's rights and obligations with respect to that order to the same extent as if the order were completed during the contract's effective period; provided, that the Contractor shall not be required to make any deliveries under this contract after 09/30/2026 [insert date].

15B50226Q00000010 Page 10 of 49

2852.201-70 Contracting Officer's Representative (COR) (NOV 2020)

(a) Mr./Ms. Logan Rogers of FCC Beaumont , 5430 Knauth Rd, Beaumont, TX 77705 , (409) 727-8187 , is hereby designated to act as Contracting Officer's Representative (COR) underthe contract that will result from this solicitation , for the period of 10/1/2025-09/30/2026 (specify the performance period of the contract that the designation covers).

(b) Performance of work under this contract is subject to the technical direction of the COR identified above, or another representative designated in writing by the Contracting Officer. The term “technical direction” includes, without limitation, the following:

(i) Receiving all deliverables;

(ii) Inspecting and accepting the supplies or services provided in accordance with the terms and conditions of this contract;

(iii) Clarifying, directing, or redirecting the contract effort, including shifting work between work areas and locations, filling in details, or otherwise serving to accomplish the contractual statement of work to ensure the work is accomplished satisfactorily;

(iv) Evaluating performance of the Contractor; and

(v) Certifying all invoices/vouchers for acceptance of the supplies or services furnished for payment.

(c) The COR does not have the authority to issue direction that:

(i) Constitutes a change of assignment or work outside the contract specification/work statement/scope of work.

(ii) Constitutes a change as defined in the clause entitled “Changes” or other similar contract term.

(iii) Causes, in any manner, an increase or decrease in the contract price or the time required for contract performance;

(iv) Causes, in any manner, any change in a term, condition, or specification or the work statement/scope of work of the contract;

(v) Causes, in any manner, any change or commitment that affects price, quality, quantity, delivery, or other term or condition of the contract or that, in any way, directs the contractor or its subcontractors to operate in conflict with the contract terms and conditions;

(vi) Interferes with the contractor's right to perform under the terms and conditions of the contract;

(vii) Directs, supervises, or otherwise controls the actions of the Contractor's employees or a Subcontractor's employees.

(d) The Contractor shall proceed promptly with performance resulting from the technical direction of the COR. If, in the opinion of the Contractor, any direction by the COR or the designated representative falls outside the authority of (b) above and/or within the limitations of (c) above, the Contractor shall immediately notify the Contracting Officer.

(e) Failure of the Contractor and Contracting Officer to agree that technical direction is within the scope of the contract is a dispute that shall be subject to the “Disputes” clause and/or other similar contract term.

(f) COR authority is not re-delegable.

(End of Clause)

BOP 2852.242-71 EVALUATION OF CONTRACTOR PERFORMANCE UTILIZING CPARS (APR 2011)

The services, although not directly supervised, shall be reviewed by Federal Bureau of Prisons (BOP) staff to ensure contract compliance. The contractor's performance will be evaluated in accordance with FAR 42.15. Contract monitoring reports will be prepared by the Contacting Officer's Representative (COR) and maintained in the contract file.

In accordance with FAR 42.1502 and 42.1503, agencies shall prepare an evaluation of contractor performance and submit it to the Past Performance Information Retrieval System (PPIRS). The BOP utilizes the Department of Defense (DOD) web-based Contractor Performance Assessment Reporting System (CPARS) to provide contractor performance evaluations. The contractor shall provide and maintain a current e-mail address throughout the life of the contract. The contractor will receive an e-mail from the Focal Point thru the following website addresswebptsmh@navy.milwhen the contract is registered in CPARS. The e-mail will contain a "user ID" and temporary password to register in the CPARS system. The contractor must be registered to access and review its evaluation and/or provide a response. If assistance is required when registering, please contact the Contracting Staff/Focal Point.

(End of Clause)

DOJ-02 Contractor Privacy Requirements (JAN 2022)

A. Limiting Access to Privacy Act and Other Sensitive Information

(1) Privacy Act Information

15B50226Q00000010 Page 11 of 49

In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.

(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment

Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.

(3) Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

(4) Separation Checklist for Contractor Employees

The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.

In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).

Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.

B. Privacy Training, Safeguarding, and Remediation

(1) Required Security and Privacy Training for Contractors

The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and

15B50226Q00000010 Page 12 of 49 reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj.

The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.

The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.

(2) Safeguarding PII Requirements

Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.

(3) Non-Disclosure Agreement Requirement

Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:

(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and

(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.

The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.

(4) Prohibition on Use of PII in Vendor Billing and Administrative Records

The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.

(5) Reporting Actual or Suspected Data Breach

Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose.

The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.

(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting and Response Procedures for a Breach of Personally Identifiable Information.

15B50226Q00000010 Page 13 of 49

(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and the Contracting Officer within one (1) hour of the initial discovery.

(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:

(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6] Date, time, and location of the incident.

(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.

(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]

(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.

(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]

(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.

(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.

(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.

(6) Victim Remediation

At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach.

The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.

C. Government Records Training, Ownership, and Management

(1) Records Management Training and Compliance

(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR.

This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.

(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.

15B50226Q00000010 Page 14 of 49

(2) Records Creation, Ownership, and Disposition

(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information.

The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.

(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.

D. Data Privacy and Oversight

(1) Restrictions on Testing or Training Using Real Data Containing PII

The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.

(2) Requirements for Contractor IT Systems Hosting Government Data

The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.

(3) Requirement to Support Privacy Compliance

(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.

(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the

15B50226Q00000010 Page 15 of 49 privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion.

The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.

[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).

[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.

[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.

[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”

[5] https://www.justice.gov/file/4336/download [6] As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used; extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.

[7] As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.

[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.

[9] As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.

[10] In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of information) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.

(End of Clause)

DOJ-03 Personnel Security Requirements For Contractor Employees (Nov 2021)

Work performed under this contract will involve any one or more of the following: access to DOJ Information, which may include Controlled Unclassified Information (CUI), i.e., unclassified, sensitive DOJ information, and/or access to DOJ

15B50226Q00000010 Page 16 of 49

Information Technology (IT) systems, and/or unescorted access to DOJ space or facilities. Contractor employees will occupy Public Trust Positions, unless clause alternates are applied.

1. General Requirements

(a) (1) All references to “contract(or) personnel” and “contract(or) employee” in this clause means all individuals, without limitation, to include individuals employed by the contractor, team member, subcontractor, consultant, and/or independent contractor, who will have access to information of the Department of Justice (DOJ) or information that is within the custody and control of the DOJ, access to DOJ IT systems, and/or unescorted access to DOJ facilities/space in connection with the performance of this contract. “Employment” as used herein does not create nor imply an employer/employee relationship between the DOJ and contractor employees.

(b) (1) The type of security investigation required for each contractor employee will be governed by the type and risk level of information made available to the contractor employee. The contractor will not be permitted to commence performance under this contract until a sufficient number of its personnel, as determined by the Security Programs Manager (SPM), in consultation with the Contracting Officer’s Representative if one is appointed, have received the requisite security approval.

(c) Except where specifically noted otherwise, the federal government will be responsible for the cost and conduct of the investigation.

(d) The contractor shall ensure that no contractor employee commences performance prior to receipt of a written authorization from the contracting officer, COR, or the SPM that performance by the respective contractor employee is authorized.

(e) The data and other information to which the contractor may have access as a result of this contract is the property of, and/or within the custody and control of, the Department, and its disclosure to third parties is governed by various statutes and regulations, the violation of which may subject the discloser to criminal penalties.

2. Citizenship and Residency Requirements

(a) Residency Requirement. (1) Contractor employees in Public Trust positions, both U.S. citizens and non-U.S.

citizens, must meet the Department’s residency requirement if they will require access to DOJ information, IT systems, or unescorted access to facilities. For three years (not necessarily consecutive years) out of the last five years immediately prior to employment under the Department contract the contractor employee must have: (i) resided in the U.S.; (ii) worked for the U.S. in a foreign country as either an employee or contractor in a federal civilian or military capacity; or, (iii) been a dependent of a federal civilian or military employee or contractor working for the U.S. in a foreign country.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .