RFQ-19TH2026Q0014-Next Generation Firewall Rental Service.pdf

PDF 680 KB Posted

Attached to
Next-Generation Network Security Firewall Rental Service Federal contract opportunity
Solicitation number
19TH2026Q0014
Issued by
Department of State US Embassy Bangkok

About this file

This document is a Request for Quotations (RFQ) issued by the U.S. Embassy in Bangkok, Thailand for Next-Generation Network Security Firewall rental services. The solicitation number is 19TH2026Q0014, issued February 2, 2026, with quotations due by February 12, 2026 at 04:00 PM Bangkok local time. Questions must be submitted by February 4, 2026 at 12:00 PM Bangkok local time. The contracting officer is Ramon Menendez-Carreira, reachable at BangkokGSOProcurement@state.gov or 662-205-5320. All quotations must be submitted electronically in Adobe PDF format (maximum 25MB per file) to BangkokGSOProcurement@state.gov. All prices are quoted in Thai Baht, and Value Added Tax is not applicable due to the Embassy's tax exemption certificate from the Thai government.

The scope of work requires a 36-month rental agreement for a Palo Alto Networks PA-3410 firewall solution with bundled advanced security subscriptions and software updates, to be fully deployed and operational before February 26, 2026. Deliverables include complete installation and configuration migration of existing security policies without network disruption, 24x7 technical support with onsite incident response capability for four incidents during the rental period, 24x7 hardware maintenance and replacement support, active advanced security subscription services (threat prevention, malware analysis, URL filtering, DNS-based security, and SD-WAN), and comprehensive documentation. Offerors must be authorized Palo Alto distributors or partners operating an established business with permanent address in Thailand, provide evidence of prior experience deploying similar enterprise-grade firewalls in Thailand with client references, demonstrate qualified and certified staff, and possess technical capability to maintain compliance with WRAIR-AFRIMS IDS Security Technical Implementation Guides (STIGs). Evaluation will use comparative evaluation methodology based on technical capability, past performance, and price, with C-SCRM (Cybersecurity Supply Chain Risk Management) as a go/no-go factor. Offerors must submit SF-1449 form, pricing in Section 1, representations and certifications in Section 5, and the C-SCRM Questionnaire (Attachment 1) or equivalent third-party security assessment such as ISO 27001, ISO 9000, SOC II, or FedRAMP authorization.

View the file

Other files for this federal contract opportunity

Other files attached to Next-Generation Network Security Firewall Rental Service, newest first.
File Type Posted
Amendment0001_19TH2026Q0014_SF-30.pdf PDF
Attachment 1 - C-SCRM Questionnaire.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Embassy of the United States of America

Bangkok, Thailand

February 2, 2026

Dear Prospective Quoter:

Subject: Request for Quotations number 19TH2026Q0014

Enclosed is a Request for Quotations (RFQ) for Next-Generation Network Security Firewall rental service with support, security subscription and software subscription. If you would like to submit a quotation, follow the instructions in Section 3 of the solicitation, complete the required portions of the attached document, and submit it to the address shown on this letter.

The U.S. government intends to award a purchase order to the responsible offeror representing best value using comparative evaluation authorized under FAR 13.106-2(b)(3). A comparative evaluation is defined as the act of comparing two or more offers in response to the RFQ. The item-by-item comparison is performed by comparing each offer directly to one another to determine which provides the best value to the Government.

Comparative evaluation is NOT a low price technically acceptable (LPTA) or trade-off process.

Prospective offers must still meet basic standards for responsibility at FAR 9.104 and solicitation compliance to be eligible for award. We intend to award a purchase order based on initial quotations, without holding discussions, although we may hold discussions with companies in the competitive range if there is a need to do so.

Direct any questions regarding this solicitation in writing to Ramon Menendez-Carreira, Contracting Officer, email: BangkokGSOProcurement@state.gov. Questions must be written in English. Closing date for question submission will be on February 4, 2026 at 12:00 PM (Bangkok local time).

Quotations are due by February 12, 2026 at 04:00 PM (Bangkok local time). No quotations will be accepted after this time. Proposals must be in English and incomplete proposals will not be accepted.

Your quotation must be submitted electronically to BangkokGSOProcurement@state.gov. It is important to make sure the submission is made in specific size and format; in Adobe Acrobat (pdf) file format. The file size must not exceed 25MB. If the file size should exceed the 25MB, the submission must be made in separate files and attached to separate emails with less than 25MB each.

In order for a quotation to be considered, you must also complete and submit the following:

1. SF-1449

2. Section 1, Pricing

3. Section 5 Representations and Certifications mailto:BangkokGSOProcurement@state.gov mailto:BangkokGSOProcurement@state.gov

4. Additional information as required in Section 3

Sincerely, Ramon Menendez-Carreira Contracting Officer

Enclosure:

Attachment 1 – Cybersecurity Supply Chain Risk Management (C-SCRM) Questionnaire

TABLE OF CONTENTS

SECTION 1 - THE SCHEDULE

• SF 1449 cover sheet

• Continuation To SF-1449, RFQ Number 19TH2026Q0014, Prices, Block 23

• Continuation To SF-1449, RFQ Number 19TH2026Q0014, Schedule Of

Supplies/Services, Block 20 Description/Specifications/Work Statement

• Attachment 1 to Cybersecurity Supply Chain Risk Management (C-SCRM)

Questionnaire

SECTION 2 - CONTRACT CLAUSES

• Contract Clauses

• Addendum to Contract Clauses – FAR Clauses Prescribed in Part 12

• Addendum to Contract Clauses – FAR and DOSAR Clauses not Prescribed in Part 12

SECTION 3 - SOLICITATION PROVISIONS

• Solicitation Provisions

• Addendum to Solicitation Provisions – FAR Provisions Prescribed in Part 12

• Addendum to Solicitation Provisions - FAR and DOSAR Provisions not Prescribed in

Part 12

SECTION 4 - EVALUATION FACTORS

• Evaluation Factors

• Addendum to Evaluation Factors - FAR and DOSAR Provisions not Prescribed in

Part 12

SECTION 5 - REPRESENTATIONS AND CERTIFICATIONS

• Offeror Representations and Certifications

WOMEN-OWNED SMALL

BUSINESS (WOSB)

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

1. REQUISITION NUMBER PAGE 1 OF

2. CONTRACT NUMBER 3. AWARD/EFFECTIVE

DATE

4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE

DATE

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME b. TELEPHONE NUMBER (No collect calls)

8. OFFER DUE DATE/

LOCAL TIME

9. ISSUED BY

13b. RATING

14. METHOD OF SOLICITATION

CODE

15. DELIVER TO 16. ADMINISTERED BY CODE

18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/

OFFEROR

CODE

FACILITY

CODE

CODE

TELEPHONE NUMBER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

REQUEST

FOR QUOTE

(RFQ)

INVITATION

FOR BID

(IFB)

REQUEST

FOR

PROPOSAL

(RFP)

SEE ADDENDUM

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Government Use Only)

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH

AND DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND

ON ANY ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS

SPECIFIED

29. AWARD OF CONTRACT: REFERENCE OFFER

DATED . . YOUR OFFER ON SOLICITATION

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED

31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA - FAR (48 CFR) 53.212

10. THIS ACQUISITION IS UNRESTRICTED OR

NORTH AMERICAN

INDUSTRY CLASSIFICATION

STANDARD (NAICS):

SIZE STANDARD:

13a. THIS CONTRACT IS A

RATED ORDER UNDER

THE DEFENSE PRIORITIES

AND ALLOCATIONS

SYSTEM - DPAS (15 CFR 700)

SET ASIDE: % FOR:

11. DELIVERY FOR FREE ON

BOARD (FOB) DESTINATION

UNLESS BLOCK IS MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

ARE ARE NOT ATTACHED

ARE ARE NOT ATTACHED

27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4. FAR 52.212-3

AND 52.212-5 ARE ATTACHED. ADDENDA

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

8(A)

ECONOMICALLY

DISADVANTAGED

WOMEN-OWNED SMALL

BUSINESS (EDWOSB)

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

(SDVOSB)

HUBZONE SMALL

BUSINESS

SMALL BUSINESS

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30. 34

19TH2026Q0014

Ramon Menendez-Carreira 662-205-5320

U.S. Embassy Bangkok (See Attached)

1 Next-Generation Network Security Firewall Rental Services 1 Lot with Support, Security Subscription and Software Subscription

2/02/2026

2/12/2026

04:00 PM

U.S. Embassy Bangkok GSO/Procurement 120-122 Wireless Rd., Lumpini, Pathumwan, Bangkok, Thailand 10330

SECTION 1 - THE SCHEDULE

CONTINUATION TO SF-1449

RFQ NUMBER 19TH2026Q0014

PRICES, BLOCK 23

I. SCOPE OF CONTRACT

A. The purpose of this firm fixed price contract is for Next-Generation Network Security

Firewall rental service with support, security subscriptions and software subscriptions in accordance with the work statement specified in this contract. The contract will start from February 26, 2026.

B. The price listed below shall include all labor, materials, overhead, profit, and transportation necessary to provide the services to the Government. The payment will be made for the services that have been satisfactorily performed.

C. All prices are in Thai Baht.

D. The rates shall include all the costs necessary to accomplish the work as required by this contract, including all managerial costs, administrative costs and service costs.

II. PRICING

Description Quantity Unit Price Next-Generation Network Security Firewall Rental Service bundled with Support, Security Subscriptions and Software Subscriptions

1 LOT

II. VALUE ADDED TAX

VALUE ADDED TAX. Value Added Tax (VAT) is not applicable to this contract and shall not be included in the CLIN rates or invoices because the U.S. Embassy has a tax exemption certificate from the host government.

CONTINUATION TO SF-1449,

RFQ NUMBER 19TH2026Q0014

SCHEDULE OF SUPPLIES/SERVICES, BLOCK 20

DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

1. SCOPE OF WORK

The Contractor shall provide Next-Generation Network Security Firewall rental service bundled with support and advanced security subscription services, regular signature and software updates, and contractor’s technical support to maintain compliance with WRAIR-AFRIMS Intrusion Detection System Security Technical Implementation Guides (STIGS), applicable cybersecurity policies, and the Government’s security standards.

The Contractor shall replace the existing network security firewall with a next-generation firewall solution provided under 36-month rental agreement to ensure continued and enhanced protection against evolving cybersecurity threats. The firewall solution must be installed completely before February 26, 2026.

The Contractor shall implement advanced, subscription-based network security services, including threat prevention, malicious content filtering, malware analysis, DNS-based security, and secure connectivity capabilities, for the full duration of the rental term.

The Contractor shall migrate and implement all existing security configurations, policies, and rules from the current firewall to the new solution without disruption to network operations or degradation of security posture.

The Contractor shall ensure continuous compliance with WRAIR-AFRIMS Intrusion Detection System (IDS) Security Technical Implementation Guides (STIGs) and applicable organization cybersecurity policies through proper configuration, updates, and support.

The Contractor shall provide ongoing technical support and hardware maintenance services to maintain the operational effectiveness, availability, and reliability of the network security infrastructure throughout the rental period.

The Contractor shall provide all labor, equipment, subscriptions, and services necessary to deliver, implement, and support a Next-Generation Network Security Firewall solution under 36-month rental agreement.

The following firewall solution is compliant with cybersecurity requirements, and it is approved by WRAIR-AFRIMS:

Product No. Description PAN-PA-3410 Palo Alto Networks PA-3410 with redundant

AC power supplies PAN-SVC-BKLN-3410-3YR Partner enabled premium support 3-year term, PA-3410

PAN-PA-3410-BND-CORESEC-3YR Threat Prevention, Advanced URL Filtering, Advanced Wildfire, Advanced DNS Security and Advanced SD-WAN), 3 years (36 months) term

The Contractor shall provide the services which include but are not limited to following services:

1.1. Next-Generation Network Security Firewall Solution Rental Services

(a) The Contractor shall provide an enterprise-grade next-generation network security firewall solution under the 36-month usage rental agreement.

(b) The solution shall include redundant power components to ensure high availability.

(c) Ownership of the equipment shall remain with the Contractor; the Government shall be granted right to use the equipment solely for the duration of the rental period in accordance with the terms of the contract.

(d) The firewall solution must utilize a single-pass or unified traffic inspection architecture that performs application identification, user identification, content inspection, and threat prevention concurrently within a single policy evaluation engine, without degrading performance.

1.2. Security Subscription Services

The Contractor shall provide advanced, subscription-based network security services for the full rental term, including:

(a) Advanced Threat Prevention: Protection against malware, spyware, viruses, and known and unknown vulnerabilities.

(b) Advanced Malware Analysis and Sandboxing: Malware analysis and sandboxing utilizing native, cloud-delivered artificial intelligence-driven threat analysis, with automatic distribution of updated protections to the firewall platform.

(c) Advanced URL and Web Content Filtering: Real-time analysis and prevention of access to malicious or high-risk web resources.

(d) DNS-Based Security Protection: Any deviation from legacy configuration behavior shall be considered a failure to meet acceptance criteria unless explicitly approved in writing by the Government. DNS-based security protection shall include real-time domain reputation analysis and prevention of commence-and-control communications enforced directly within the firewall policy framework.

(e) Secure Connectivity and Traffic Optimization Services: Capabilities to support secure network connectivity and traffic management.

(f) All security subscription services shall remain active and uninterrupted for the full duration of the rental term, including hardware replacement or migration activities.

1.3. Implementation and Configuration Migration

(a) The Contractor shall perform full implementation of the new firewall solution within the existing network environment.

(b) The Contractor shall migrate all existing security configurations, policies, rules and settings from the current firewall to the new solution.

(c) The Contractor shall ensure migration and implementation activities are completed with no adverse impact to network operations or security posture.

(d) The Contractor shall validate configurations to endure compliance with WRAIR- AFRIMS IDS STIGs and applicable security policies.

(e) The Contractor shall perform a full migration of the existing intrusion detection and prevention system configuration from the currently deployed appliance to the replacement appliance.

(f) The migration must preserve all existing security policies, application-based rules, user-identity enforcement, network objects, routing, NAT, decryption policies, logging, reporting, and compliance configurations without redesign, recreation, or functional impact.

(g) The implementation shall ensure operational continuity with no degradation to security posture, policy behavior, or compliance with WRAIR-AFRIMS IDS STIGs and organizational security requirements.

(h) All configuration migration activities shall be performed using included licenses and subscriptions and shall not require the purchase of additional licenses beyond those provided under this contract.

(i) The migration shall preserve centralized management workflows, policy hierarchy, shared objects, device grouping, and role-based administrative access equivalent to the legacy system, without requiring operational process changes.

(j) Configuration migration shall be performed using native, vendor-supported configuration export/import or migration mechanisms, and shall not rely on manual policy re-creation, rule rewriting, or functional redesign.

1.4. Technical and Operational Support

(a) The Contractor shall provide 24x7 technical support for incident response and troubleshooting throughout the 36-month rental agreement period.

(b) The Contractor must provide onsite technical support services as required, including support for four (4) onsite incidents during the 36-month rental agreement period. Onsite support shall include but is not limited to assistance with system diagnostics, configuration adjustments, hardware replacement, and restoration of services in accordance with security and compliance requirements.

(c) The Contractor shall provide support services which cover configuration assistance, issue resolution, and operational guidance.

(d) The Contractor must have access to qualified technical personnel capable of responding to and resolving high-severity security incidents on a 24x7 basis.

(e) The Contractor shall provide locally based technical support resources to ensure timely response, onsite coordination, and effective issue resolution.

(f) Local support personnel must be capable of assisting with system configuration, maintenance, troubleshooting, and compliance with AFRIMS-WRAIR security policies and standards.

(g) The Contractor shall provide a telephone number for the purpose of reporting equipment problems and malfunctions and customer question regarding the firewall solution.

(h) The Contractor shall have a working system of firewall solution survivability in case of emergencies and serious disaster when parts of the firewall solution are destroyed.

(i) The Contractor shall provide 24x7 onsite/remote software support including software version updates and patches during the 36-month rental agreement period.

1.5. Hardware Maintenance and Replacement

(a) The Contractor shall provide 24x7 hardware maintenance and replacement support for the duration of 36-month rental agreement period.

(b) The Contractor shall ensure timely replacement of faulty hardware components, including advanced replacement where available, to maintain continuous operational availability of the firewall solution.

1.6. Testing, Cutover, and Acceptance

(a) The Contractor shall perform functional and security testing following implementation and migration.

(b) The Contractor shall support a controlled cutover from the existing firewall solution to the new solution.

(c) The Contractor shall confirm successful deployment and operational readiness upon completion of testing.

(d) Acceptance shall be based on successful verification that all migrated configurations operate identically to the legacy system, with no loss of functionality, policy enforcement, logging, or compliance controls.

(e) The replacement firewall solution shall meet or exceed the throughput, session capacity, and security inspection performance of the legacy system under equivalent traffic conditions.

(f) Acceptance testing shall include verification that application identification, user-based policies, logging, reporting, and threat prevention behavior function identically to the legacy system under equivalent traffic conditions.

(g) Cutover activities shall be planned and executed to minimize service disruption, and no unplanned outage impacting mission operations shall be acceptable during the migration.

(h) The Contractor shall perform full configuration backups of the legacy and replacement systems prior to cutover and maintain rollback capability until final acceptance is granted.

1.7. Compliance and Security Requirements

(a) The Contractor shall configure and maintain the firewall solution in accordance with WRAIR-AFRIMS IDS STIGs and applicable organizational cybersecurity policies.

(b) The Contractor shall ensure ongoing access to security updates, signatures, and software enhancements as required to maintain compliance and protection effectiveness.

1.8 Service Delivery and Project Management

(a) The Contractor must deliver all services in accordance with the agreed-upon schedule and maintain clear and consistent communication regarding project status and issue resolution.

(b) The Contract shall assign one a point of contact for this contract and shall be assigned for project coordination, escalation management, and operational support.

(c) All work must be performed in accordance with industry best practices and applicable government or WRAIR-AFRIMS security standards.

(d) The Contractor shall provide complete and accurate documentation for all implementation activities, configuration migrations, hardware maintenance actions, and support services performed.

(e) The Contractor shall provide documentation which include configuration records and confirmation of compliance with WRAIR-AFRIMS IDS STIGs.

(f) The Contractor shall provide status updates as required and a final implementation and acceptance report upon completion of the deployment and migration activities.

2. DELIVERABLES

The Contractor shall provide the following deliverables throughout a 36-month rental agreement period:

2.1. A fully deployed and operational next-generation network security firewall solution provided under a 36-month rental agreement.

2.2. Active advanced security subscription services for the full rental agreement term, including:

(a) Threat prevention capabilities to detect and block malware, spyware, viruses, and exploits.

(b) Advanced web and URL filtering with real-time analysis and malicious content prevention.

(c) Malware analysis and sandboxing utilizing artificial intelligence or equivalent advanced, continuously updated detection technologies.

(d) DNS-based threat detection and prevention services.

(e) Secure connectivity and traffic optimization capabilities.

2.3. Successful migration and implementation of all existing security configurations, policies, and rules from the current firewall to the new solution, completed without disruption to network operations.

2.4. A fully configured network security and intrusion detection/prevention system compliant with WRAIR-AFRIMS IDS STIGs and applicable organizational cybersecurity policies.

2.5. Active 24x7 technical support services, including onsite incident response in accordance with the contract terms.

2.6. Continuous hardware maintenance and replacement services, including 24x7 hardware replacement support, to ensure operational availability throughout the rental period.

2.7. Configuration and implementation documentation confirming system readiness and operational acceptance.

3. DELIVERY INSTRUCTIONS

3.1. The Contractor shall install firewall solution and deliver services to U.S. Embassy Bangkok.

The address is:

Department of Administration, WRAIR-AFRIMS 315/6 Rajvithi Road, Rajthevee, Bangkok 10400, Thailand

3.2. The Contractor shall complete firewall solution replacement and provide bundled advanced security subscription and software subscription before February 26, 2026.

3.3. Any contractor personnel involved with the delivery of the equipment and services shall comply with standard U.S. Embassy regulations for receiving equipment and services. The Contracting Officer’s Representative (COR) will be responsible for instructing contractor’s personnel at the time deliveries are made. Prior notice of at least three working days will be required.

3.4. The Contractor shall deliver equipment and services to the Government based on the following hours of operation:

Department of Administration, WRAIR-AFRIMS 8:00 am – 11:30 am or 1:00 PM – 4:00 PM from Monday to Friday except government holidays.

3.5. The below information shall be sent to the Government at least three working days prior to the delivery date:

(a) Name – Surname of driver and passengers in English which match with the national identification card or passport.

(b) Driver’s cellphone number

(c) Vehicle’s information

i. Vehicle type (e.g. pick-up truck, motorcycle)

ii. Vehicle’s plate number

iii. Vehicle’s brand and model

iv. Vehicle’s color

(d) Delivery date and time

(e) Delivery order number

The information shall be sent to email: thosapoll.fsn@afrims.org and jakkaphongm.ca@afrims.org.

4. TECHNOLOGICAL REFRESHMENT

After contract award, the Government may; pursuant to FAR clause 52.212-4 - Contract Terms and Conditions –Commercial Items, paragraph (c), Changes; request changes within the scope of the contract. These changes may be required to improve performance or react to changes in technology.

The Contractor may propose for the Government’s technological refreshment, substitutions or additions for any provided products or services that may become available as a result of technological improvements. The Government may, at any time during the term of this contract or any extensions thereof, modify the contract to acquire products which are similar to those under the contract and that the Contractor has, or has not, formally announced for marketing purposes. This action is considered to be within the scope of the contract. At the option of the Government, a demonstration of the substitute product may be required. The Government is under no obligation to modify the contract in response to the proposed additions or substitutions.

Such substitutions or additions may include any part of, or all of, a given product(s) provided that the following conditions are met and substantiated by documentation in the technological refreshment proposal:

mailto:thosapoll.fsn@afrims.org mailto:jakkaphongm.ca@afrims.org

The proposed product(s) shall meet all of the technical specifications of this document and conform to the terms and conditions cited in the contract.

The proposed product(s) shall have the capacity, performance, or functional characteristics equal to or greater than, the current product(s).

The proposal shall discuss the impact on hardware, services, and delivery schedules. The cost of the changes not specifically addressed in the proposal shall be borne entirely by the Contractor.

Contractor has the right to withdraw, in whole or in part, any technological refreshment proposal prior to acceptance by the Government. The Contractor will use commercially reasonable efforts to ensure that prices for substitutions or additions are comparable to replaced or discontinued products. If a technological refreshment proposal is accepted and made a part of this contract, an equitable adjustment, increasing or decreasing the contract price, may be required and any other affected provisions of this contract shall be made in accordance with FAR clause 52.212-4, paragraph (c), Changes, and other applicable clauses of the contract.

QUALITY ASSURANCE AND SURVEILLANCE PLAN (QASP)

This plan provides an effective method to promote satisfactory contractor performance. The QASP provides a method for the Contracting Officer's Representative (COR) to monitor Contractor performance, advise the Contractor of unsatisfactory performance, and notify the Contracting Officer of continued unsatisfactory performance. The Contractor, not the Government, is responsible for management and quality control to meet the terms of the contract.

The role of the Government is to monitor quality to ensure that contract standards are achieved.

Performance Objective Scope of Work

Paragraphs Performance Threshold

Services.

Performs all Next-Generation Network Security Firewall rental service bundled with support, security subscriptions and software subscriptions services set forth in the scope of work.

1 thru 4

All required services are performed and no more than one

(1) customer complaint is received per month.

1. SURVEILLANCE. The COR will receive and document all complaints from Government personnel regarding the services provided. If appropriate, the COR will send the complaints to the Contractor for corrective action.

2. STANDARD. The performance standard is that the Government receives no more than one

(1) customer complaint per month. The COR shall notify the Contracting Officer of the complaints so that the Contracting Officer may take appropriate action to enforce the inspection clause (FAR 52.212.4, Contract Terms and Conditions - Commercial Products and Commercial Services (NOV 2023), if any of the services exceed the standard.

3. PROCEDURES.

(a) If any Government personnel observe unacceptable services, either incomplete work or required services not being performed they should immediately contact the COR.

https://www.acquisition.gov/far/52.212-4

(b) The COR will complete appropriate documentation to record the complaint.

(c) If the COR determines the complaint is invalid, the COR will advise the complainant. The COR will retain the annotated copy of the written complaint for his/her files.

(d) If the COR determines the complaint is valid, the COR will inform the Contractor and give the Contractor additional time to correct the defect, if additional time is available. The COR shall determine how much time is reasonable.

(e) The COR shall, as a minimum, orally notify the Contractor of any valid complaints.

(f) If the Contractor disagrees with the complaint after investigation of the site and challenges the validity of the complaint, the Contractor will notify the COR. The COR will review the matter to determine the validity of the complaint.

(g) The COR will consider complaints as resolved unless notified otherwise by the complainant.

(h) Repeat customer complaints are not permitted for any services. If a repeat customer complaint is received for the same deficiency during the service period, the COR will contact the Contracting Officer for appropriate action under the Inspection clause.

SECTION 2 - CONTRACT CLAUSES

52.212-4 CONTRACT TERMS AND CONDITIONS – COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (NOV 2023) (DEVIATION JAN 2026) IS

INCORPORATED BY REFERENCE. (SEE SF-1449, BLOCK 27A)

ADD THE FOLLOWING CLAUSE IN FULL TEXT:

52.204-91 CONTRACTOR IDENTIFICATION (SEP 2025)

Definitions. As used in this clause—

(a) Commercial and Government Entity code means—

(1) An identifier assigned to entities located in the United States or its outlying areas by the Defense Logistics Agency (DLA) Commercial and Government Entity (CAGE) Branch to identify a commercial or government entity by unique location (referred to as “CAGE code”); or

(2) An identifier assigned by a member of the North Atlantic Treaty Organization (NATO) or by the NATO Support and Procurement Agency (NSPA) to entities located outside the United States and its outlying areas that the DLA CAGE Branch records and maintains in the CAGE master file (referred to as “NCAGE code”).

Unique entity identifier means an identifier used to identify a specific commercial, nonprofit, or Government entity.

(b) Unique entity identifier (UEI). The Contractor shall ensure that its UEI is maintained throughout the life of the contract.

(c) Commercial and Government Entity (CAGE) code. The Contractor shall ensure that the CAGE code is maintained throughout the life of the contract. The Contractor shall request changes to a CAGE code as indicated in the following table.

If the Contractor is…

Then…

Registered in the System for Award Management

(SAM)

Initiate the change by updating its SAM registration

Located in the United States or its outlying areas and is not registered in

SAM

Submit a change request to the DLA CAGE Branch via https://cage.dla.mil https://cage.dla.mil/

Located outside the United States and its outlying areas and is not registered in

SAM

Request a change by contacting the appropriate National Codification Bureau (https://www.nato.int/structur/ac/135/about/contacts) or NSPA(https://eportal.nspa.nato.int/AC135Public/scage/CageList.aspx)

(d) Communicating changes. The Contractor shall communicate any change to its UEI or CAGE code to the Contracting Officer within 30 days after the change, so a modification can be issued to update the UEI or CAGE code on this contract. A change in the UEI does not necessarily require a novation.

(End of clause)

ADDENDUM TO CONTRACT CLAUSES

FAR AND DOSAR CLAUSES PRESCRIBED IN PART 12

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. In addition, the full text of a clause may be accessed electronically at: Acquisition.gov this address is subject to change.

If the Federal Acquisition Regulation (FAR) is not available at the location indicated above, use the Department of State Acquisition website at e-CFR to see the links to the FAR. You may also use an Internet “search engine” (for example, Google, Yahoo or Excite) to obtain the latest location of the most current FAR.

THE FOLLOWING FEDERAL ACQUISITION REGULATIONS (FAR) CLAUSES ARE

INCORPORATED BY REFERENCE:

CLAUSE TITLE AND DATE

52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS (NOV 2023)

52.203-19 PROHIBITION ON REQUIRING CERTAIN INTERNAL CONFIDENTIALITY

AGREEMENTS OR STATEMENTS (JAN 2017)

52.209-6 PROTECTING THE GOVERNMENT’S INTEREST WHEN

SUBCONTRACTING WITH CONTRACTORS DEBARRED, SUSPENDED,

PROPOSED FOR DEBARMENT, OR VOLUNTARILY EXCLUDED (JAN

2025)

52.209-10 PROHIBITION ON CONTRACTING WITH INVERTED DOMESTIC

CORPORATIONS (NOV 2015)

https://www.nato.int/structur/ac/135/about/contacts https://eportal.nspa.nato.int/AC135Public/scage/CageList.aspx https://acquisition.gov/browse/index/far https://gov.ecfr.io/cgi-bin/text-idx?SID=d9a7851186785ba2b1896db79b1b6b29&mc=true&tpl=/ecfrbrowse/Title48/48tab_02.tpl

52.222-19 CHILD LABOR-COOPERATION WITH AUTHORITIES AND REMEDIES

(JAN 2025)

52.222-50 COMBATING TRAFFICKING IN PERSONS (OCT 2025)

52.226-8 ENCOURAGING CONTRACTOR POLICIES TO BAN TEXT MESSAGING

WHILE DRIVING (MAY 2024)

52.232-29 TERMS FOR FINANCING OF PURCHASES OF COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (NOV 2021)

52.232-34 PAYMENT BY ELECTRONIC FUNDS TRANSFER-OTHER THAN SYSTEM

FOR AWARD MANAGEMENT (JUL 2013)

52.232-40 PROVIDING ACCELERATED PAYMENTS TO SMALL BUSINESS

SUBCONTRACTORS (MAR 2023)

52.233-4 APPLICABLE LAW FOR BREACH OF CONTRACT CLAIM (OCT 2004)

52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (JAN 2026)

52.240-93 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION

SYSTEMS (JAN 2026)

52.244-6 SUBCONTRACTS FOR COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES (OCT 2025)

ADDENDUM TO CONTRACT CLAUSES

FAR AND DOSAR CLAUSES PRESCRIBED IN PART 12

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. In addition, the full text of a clause may be accessed electronically at: Acquisition.gov this address is subject to change.

If the Federal Acquisition Regulation (FAR) is not available at the location indicated above, use the Department of State Acquisition website at e-CFR to see the links to the FAR. You may also use an Internet “search engine” (for example, Google, Yahoo or Excite) to obtain the latest location of the most current FAR.

CLAUSE TITLE AND DATE

52.225-14 INCONSISTENCY BETWEEN ENGLISH VERSION AND TRANSLATION OF

CONTRACT (FEB 2000)

52.232-39 UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS (JUNE 2013)

https://gov.ecfr.io/cgi-bin/text-idx?SID=d9a7851186785ba2b1896db79b1b6b29&mc=true&tpl=/ecfrbrowse/Title48/48tab_02.tpl

THE FOLLOWING DOSAR CLAUSES ARE PROVIDED IN FULL TEXT:

CONTRACTOR IDENTIFICATION (JULY 2008)

Contract performance may require contractor personnel to attend meetings with government personnel and the public, work within government offices, and/or utilize government email.

Contractor personnel must take the following actions to identify themselves as non-federal employees:

1) Use an email signature block that shows name, the office being supported and company affiliation (e.g. “John Smith, Office of Human Resources, ACME Corporation Support Contractor”);

2) Clearly identify themselves and their contractor affiliation in meetings;

3) Identify their contractor affiliation in Departmental e-mail and phone listings whenever contractor personnel are included in those listings; and

4) Contractor personnel may not utilize Department of State logos or indicia on business cards.

(End of clause)

652.215-70 EXAMINATION OF RECORDS

(a) With respect to matters related to this contract or a subcontract hereunder, the Department of State Office of the Inspector General, or an authorized representative, shall have upon request:

(1) Complete, prompt, and free access to all Contractor and Subcontractor files (in any format), documents, records, data, premises, and employees, except as limited by law; and

(2) The right to interview any current Contractor and Subcontractor personnel, individually and directly, with respect to such matters.

(b) This clause may not be construed to require the contractor or any subcontractor to create or maintain any record that the contractor or subcontractor does not maintain in the ordinary course of business or pursuant to a provision of law.

(c) The Contractor shall insert a clause containing all the terms of this clause, including this paragraph (c), in all subcontracts under this contract other than acquisitions described in Federal Acquisition Regulation 15.209(b)(1).

652.229-70 EXCISE TAX EXEMPTION STATEMENT FOR CONTRACTORS WITHIN THE

UNITED STATES (JUL 1988)

This is to certify that the item(s) covered by this contract is/are for export solely for the use of the U.S. Foreign Service Post identified in the contract schedule.

https://www.ecfr.gov/current/title-48/section-652.215-70#p-652.215-70(c)

The Contractor shall use a photocopy of this contract as evidence of intent to export. Final proof of exportation may be obtained from the agent handling the shipment. Such proof shall be accepted in lieu of payment of excise tax.

652.232-70 PAYMENT SCHEDULE AND INVOICE SUBMISSION (FIXED-PRICE)

(AUG 1999)

(a) General. The Government shall pay the Contractor as full compensation for all work required, performed, and accepted under this contract the firm fixed-price stated in this contract.

(b) Invoice Submission. The Contractor shall submit invoices in an original to WRAIR- AFRIMS Administration Office. To constitute a proper invoice, the invoice shall include all the items required by FAR 32.905(e).

(c) Contractor Remittance Address. The Government will make payment to the contractor’s address stated on the cover page of this contract, unless a separate remittance address is shown below:

652.242-70 CONTRACTING OFFICER'S REPRESENTATIVE (COR) AUG 1999)

(a) The Contracting Officer may designate in writing one or more Government employees, by name or position title, to take action for the Contracting Officer under this contract. Each designee shall be identified as a Contracting Officer’s Representative (COR). Such designation(s) shall specify the scope and limitations of the authority so delegated; provided, that the designee shall not change the terms or conditions of the contract, unless the COR is a warranted Contracting Officer and this authority is delegated in the designation.

(b) The COR for this contract is Chief of Information Officer.

652.242-73 AUTHORIZATION AND PERFORMANCE (AUG 1999)

(a) The Contractor warrants the following:

(1) That is has obtained authorization to operate and do business in the country or countries in which this contract will be performed;

(2) That is has obtained all necessary licenses and permits required to perform this contract; and,

(3) That it shall comply fully with all laws, decrees, labor standards, and regulations of said country or countries during the performance of this contract.

(b) If the party actually performing the work will be a subcontractor or joint venture partner, then such subcontractor or joint venture partner agrees to the requirements of paragraph (a) of this clause.

652.243-70 NOTICES (AUG 1999)

Any notice or request relating to this contract given by either party to the other shall be in writing. Said notice or request shall be mailed or delivered by hand to the other party at the address provided in the schedule of the contract. All modifications to the contract must be made in writing by the Contracting Officer.

SECTION 3 - SOLICITATION PROVISIONS

52.212-1 INSTRUCTIONS TO OFFERORS -- COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (NOV 2023) (DEVIATION JAN 2026) IS

INCORPORATED BY REFERENCE (SEE SF-1449, BLOCK 27A)

ADDENDUM TO 52.212-1

A. Summary of Instructions. Each offer must consist of the following:

A.1. Cybersecurity Supply Chain Risk Management (C-SCRM) Proposal/Quote Instructions (corresponding instructions to the factor below)

Cybersecurity Supply Chain Risk Management (C-SCRM) Forms

The offeror shall include in its offer Attachment 1, C-SCRM Questionnaire. In lieu of a completed C-SCRM Questionnaire, the vendor may submit a third party authorizing official conducted assessment, such as ISO 27001, ISO 9000, SOC II, or FEDRAMP authorization.

A.2. A completed solicitation, in which the SF-1449 cover page (blocks 12, 17, 19-24, and 30 as appropriate), and Section 1 has been filled out.

A.3. Information demonstrating the offeror’s/quoter’s ability to perform, including:

(1) Name of a qualified point of contact who is appropriately trained, certified, or otherwise qualified to implement and support advanced network security solutions.

(2) Evidence that the offeror operates an established business with a permanent address in Thailand which include but not limited to company’s registration document, company’s VAT registration document (Por Por 20). The offeror must also provide telephone number listing in Thailand.

(3) List of clients over the past three (3) years, demonstrating prior experience in the deployment, configuration, migration, and support of enterprise-grade next generation network security firewall and intrusion detection/prevention systems in Thailand and references (provide dates of contracts, places of performance, value of contracts, contact names, telephone number and email addresses). Offerors are advised that the past performance information requested above may be discussed with the client’s contact person. In addition, the client’s contact person may be asked to comment on the offeror’s:

• Quality of services provided under the contract;

• Compliance with contract terms and conditions;

• Effectiveness of management;

• Willingness to cooperate with and assist the customer in routine matters, and when confronted by unexpected difficulties; and

• Business integrity / business conduct.

The Government will use past performance information primarily to assess an offeror’s capability to meet the solicitation performance requirements, including the relevance and successful performance of the offeror’s work experience. The Government may also use this data to evaluate the credibility of the offeror’s proposal. In addition, the Contracting Officer may use past performance information in making a determination of responsibility.

(4) Evidence that the offeror can provide the necessary personnel, equipment, and financial resources needed to perform the work.

(5) Evidence demonstrates that the offeror has experience in the deployment, configuration, migration, and support of enterprise-grade next generation network security firewall and intrusion detection/prevention systems.

(6) Evidence demonstrates that the offeror has technical capability to configure and maintain network security systems in compliance with WRAIR-AFRIMS IDS STIGs and applicable organizational cybersecurity policies.

(7) Evidence that the offeror has qualified personnel who will be assigned as the point of contact of the contract and that personnel is appropriately trained, certified, or otherwise qualified to implement and support advanced network security solutions.

(8) Evidence demonstrates that the offeror has the capability to provide timely hardware maintenance and replacement services, including 24x7 hardware replacement support for the duration of the rental agreement period.

(9) Evidence that the offeror can provide locally based technical support resources to ensure timely response, onsite coordination, and effective issue resolution.

(10) Evidence demonstrates that the offeror local support personnel is capable of assisting with system configuration, maintenance, troubleshooting, and compliance with organizational security policies and standards.

(11) Evidence that the offeror is the authorized distributor or partner of Palo Alto products, proof of partnership shall be provided.

(12) Quotation which covers all services listed in the solicitation. The quotation shall consist of descriptions, quantities, price of services and lead time for firewall solution installation and activation.

(13) Evidence that the offeror has qualified and certified staff who possess the proper certifications to provide installation including service support for Palo Alto system.

(14) Evidence that the offeror can provide new equipment, current/latest models, world-class brands, reliability and latest technology of the Next-Generation Network Security Firewall System.

ADDENDUM TO SOLICITATION PROVISIONS

FAR AND DOSAR PROVISIONS PRESCRIBED IN PART 12

52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE

(FEB 1998)

This solicitation incorporates one or more solicitation provisions by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. In addition, the full text of a clause may be accessed electronically at Acquisition.gov this address is subject to change.

If the Federal Acquisition Regulation (FAR) is not available at the location indicated above, use the Department of State Acquisition website at e-CFR to see the links to the FAR. You may also

THE FOLLOWING FEDERAL ACQUISITION REGULATION SOLICITATION

PROVISIONS ARE INCORPORATED BY REFERENCE:

PROVISION TITLE AND DATE

52.203-18 PROHIBITION ON CONTRACTING WITH ENTITIES THAT REQUIRE

CERTAIN INTERNAL CONFIDENTIALITY AGREEMENTS OR

STATEMENTS-REPRESENTATION (JAN 2017)

52.212-1 INSTRUCTIONS TO OFFERORS -- COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (SEP 2023)

ADDENDUM TO SOLICITATION PROVISIONS

FAR AND DOSAR PROVISIONS PRESCRIBED IN PART 12

52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE

(FEB 1998)

This solicitation incorporates one or more solicitation provisions by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. In addition, the full text of a clause may be accessed electronically at Acquisition.gov this address is subject to change.

If the Federal Acquisition Regulation (FAR) is not available at the location indicated above, use the Department of State Acquisition website at e-CFR to see the links to the FAR. You may also

THE FOLLOWING FEDERAL ACQUISITION REGULATION SOLICITATION

PROVISIONS ARE INCORPORATED BY REFERENCE:

PROVISION TITLE AND DATE

https://gov.ecfr.io/cgi-bin/text-idx?SID=d9a7851186785ba2b1896db79b1b6b29&mc=true&tpl=/ecfrbrowse/Title48/48tab_02.tpl https://gov.ecfr.io/cgi-bin/text-idx?SID=d9a7851186785ba2b1896db79b1b6b29&mc=true&tpl=/ecfrbrowse/Title48/48tab_02.tpl

52.214-34 SUBMISSION OF OFFERS IN THE ENGLISH LANGUAGE (APR 1991)

THE FOLLOWING DOSAR PROVISION(S) IS/ARE PROVIDED IN FULL TEXT:

652.206-70 ADVOCATE FOR COMPETITION/OMBUDSMAN (FEB 2015)

(a) The Department of State’s Advocate for Competition is responsible for assisting industry in removing restrictive requirements from Department of State solicitations and removing barriers to full and open competition and use of commercial items. If such a solicitation is considered competitively restrictive or does not appear properly conducive to competition and commercial practices, potential offerors are encouraged first to contact the contracting office for the solicitation. If concerns remain unresolved, contact:

(1) For solicitations issued by the Office of Acquisition Management (A/GA/AMD) or a Regional Procurement Support Office, the A/GA/AMD Advocate for Competition, at AQMCompetitionAdvocate@state.gov.

(2) For all others, the Department of State Advocate for Competition at cat@state.gov.

(b) The Department of State’s Acquisition Ombudsman has been appointed to hear concerns from potential offerors and contractors during the pre-award and post-award phases of this acquisition. The role of the ombudsman is not to diminish the authority of the contracting officer, the Technical Evaluation Panel or Source Evaluation Board, or the selection official. The purpose of the ombudsman is to facilitate the communication of concerns, issues, disagreements, and recommendations of interested parties to the appropriate Government personnel, and work to resolve them. When requested and appropriate, the ombudsman will maintain strict confidentiality as to the source of the concern. The ombudsman does not participate in the evaluation of proposals, the source selection process, or the adjudication of formal contract disputes. Interested parties are invited to contact the contracting activity ombudsman, Head of Contracting Activity, at +662-205-4000 . For an American Embassy or overseas post, refer to the numbers below for the Department Acquisition Ombudsman. Concerns, issues, disagreements, and recommendations which cannot be resolved at a contracting activity level may be referred to the Department of State Acquisition Ombudsman at (703) 516-1696 or write to: Department of State, Acquisition Ombudsman, Office of Global Acquisitions (A/GA), Suite 1060, SA-15, Washington, DC 20520.

(End of provision) mailto:AQMCompetitionAdvocate@state.gov mailto:cat@state.gov

SECTION 4 - EVALUATION FACTORS

The Government intends to establish a contract resulting from this solicitation to the responsible contractor whose quotation conforms to the solicitation and represents the best value to the Government, price and other factors considered utilizing FAR 13 Comparative Evaluation.

This selection process will utilize FAR 13 procedures.

After preliminary consideration of all offers, the Department will no longer consider offers that do not meet basic standards to be eligible for award. The offers that remain will be subject to a comparative evaluation.

The preliminary evaluation process shall include the following:

COMPLIANCE REVIEW. The Government will perform an initial review of proposals/quotations received to determine completeness and compliance with the terms of the solicitation to include Cybersecurity Supply Chain Risk Management (C-SCRM) Go/No-Go Evaluation Factor. The Government may reject as unacceptable proposals/quotations that do not conform to the solicitation.

C-SCRM Go/No-Go Evaluation Factor This factor is evaluated on go/no-go basis. The Government will evaluate whether the submitted C-SCRM Questionnaire and State Department Secure Software Development Attestation Form meet the definition for the “Go” or No-Go” ratings for this factor. The “Go” and “No-Go” ratings and their definitions are as follows:

RATING RATING DEFINITION

GO The proposal meets the criteria in the following two (2) paragraphs.

The C-SCRM Questionnaire contains both of the following: (1) C-SCRM Questionnaire instructions are completed; and (2) contains “Yes” answers for all questions in Sections 2 and 3 of the questionnaire; or the vendor has submitted a third party authorizing official conducted assessment such as, ISO 27001, ISO 9000, SOC II, or FEDRAMP authorization.

For suppliers offering any software, the State Department Secure Software Development Attestation Form (or another federal agency’s equivalent form) is signed and submitted in accordance with the form’s instructions.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .