RFQ 36C25726Q0496.pdf
PDF 676 KB Posted
- Attached to
- NTX Access Control System Installation Federal contract opportunity
- Solicitation number
- 36C25726Q0496
About this file
This is a Solicitation/Contract/Order (SF 1449) for NTX Access Control System Installation services issued by the Department of Veterans Affairs, Network Contracting Office 17.
The solicitation seeks labor and materials to install access control systems, devices, and hardware in clinical addition 2J and building 3 of the Dallas VA Medical Center, located at 4500 S. Lancaster Road, Dallas, TX 75216. The work is classified under NAICS code 561621 (Security Systems Services) and PSC code N063 (Installation of Equipment - Alarm, Signal, and Security Detection Systems). The scope includes turnkey extension and upgrade of existing HIRSCH systems, encompassing low voltage installation of electric door hardware, wiring, project management, engineering, startup labor, commissioning, and miscellaneous installation materials with a one-year warranty. Specific work includes installing access control modules (5 MX-8 controllers, 16 card readers with keypads, 27 door contacts, 12 REX break glass exits), electric door hardware for 14 openings across multiple clinics and buildings, and magnetic locks. Work must be completed within 30 days of receipt and performed Monday through Friday during normal duty hours (8:00 a.m. to 5:00 p.m.) excluding federal holidays. The contract is set aside 100% for certified Service-Disabled Veteran-Owned Small Businesses (SDVOSB).
Proposals are due by June 11, 2026, at 1:00 p.m. CDT via email. The solicitation requires submission in five volumes: SF 1449 and certifications; technical approach (25-page maximum); price proposal; past performance (5 references maximum); and redacted technical approach (25-page maximum). Award is anticipated on May 22, 2026, with a performance period from June 25, 2026, through September 24, 2026. The Government will award a single firm-fixed-price contract to the technically acceptable offeror offering best value based on technical capability, price, and past performance. A pre-proposal site visit is scheduled for June 3, 2026, at 9:00 a.m. CDT. Offerors must be certified SDVOSB firms listed in the SBA certification database and comply with 50% limitations on subcontracting for services. Questions are due by June 5, 2026, at 1:00 p.m. CDT. Payment will be made by electronic funds transfer upon completion, inspection, and acceptance. The solicitation incorporates FAR Part 12 commercial item procedures and includes VA-specific clauses regarding personnel vetting, security prohibitions, and information technology security requirements.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C25726Q0496 0001.pdf | ||
| BLDG 2J 1ST FL 2024.pdf | ||
| Bldg 2J 3RD FL 2024.pdf | ||
| WD 2015-5227 rv 28 dtd 3-30-2026.pdf | ||
| Combined Synopsis 36C25726Q0496_1.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 1. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. UEI: EFT:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
36C25726Q0496 05-22-2026
Marcellus Jackson 210-986-3354 06-11-2026
13:00 CDT
36C257
Department Of Veterans Affairs
Network Contracting Office 17
5441 Babcock Road Ste. 302
San Antonio TX 78240
X 100
X
561621
$25 Million
N/A
X
36C549
VA North Texas Health Care System
Dallas VAMC
Engineering
4500 S. Lancaster Rd
Dallas TX 75216
36C257
Network Contracting Office 17
This is accomplished through the
Tungsten Network located at:
http://www.fsc.va.gov/einvoice.asp
This is mandatory and the sole method for submitting invoices.
(877) 353-9791 (512) 460-5540
See CONTINUATION Page
NTX Access Control Installation IAW the Statement of Work
(SOW).
Refer to Instructions of Offerors and Basis of Award for additional details, pages 30 - 35.
This acquisition is being conducted IAW FAR Part 12.
See CONTINUATION Page
X 1
36C25726Q0496
Table of Contents
SECTION A
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND
COMMERCIAL SERVICES
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
B.2 PRICE/COST SCHEDULE
ITEM INFORMATION
B.4 STATEMENT OF WORK
SECTION C - CONTRACT CLAUSES
C.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
C.2 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)
C.3 52.222-42 STATEMENT OF EQUIVALENT RATES FOR FEDERAL HIRES (MAY
2014)
C.4 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025)
(DEVIATION)
C.5 VAAR 852.204-72 PERSONNEL VETTING AND CREDENTIALING (DEVIATION)
(MAR 2026)
C.6 VAAR 852.219-73 VA NOTICE OF TOTAL SET-ASIDE FOR CERTIFIED SERVICE-
DISABLED VETERAN-OWNED SMALL BUSINESSES (JAN 2023) (DEVIATION)
C.7 VAAR 852.219-75 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING—
CERTIFICATE OF COMPLIANCE FOR SERVICES AND CONSTRUCTION (JAN 2023)
(DEVIATION)
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS
SECTION E - SOLICITATION PROVISIONS
E.1 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB
1998)
E.2 ADDENDUM to FAR 52.212-1 INSTRUCTIONS TO OFFERORS – COMMERCIAL
PRODUCTS AND COMMERCIAL SERVICES
E.3 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL
SERVICES (NOV 2021)
E.4 52.212-2 ADDENDUM to EVALUATION—COMMERCIAL PRODUCTS AND
COMMERCIAL SERVICES
E.5 52.240-90 SECURITY PROHIBITIONS AND EXCLUSIONS REPRESENTATIONS
AND CERTIFICATIONS (NOV 2025) (DEVIATION)
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR:
b. GOVERNMENT: Contracting Officer 36C257
Network Contracting Office 17
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[] 52.232-36, Payment by Third Party
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly []
b. Semi-Annually []
c. Other [X] Upon completion, inspection, and acceptance.
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.
Tungsten Network located at:
http://www.fsc.va.gov/einvoice.asp
ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the
Solicitation numbered and dated as follows:
AMENDMENT NO DATE
http://www.fsc.va.gov/einvoice.asp
B.2 PRICE/COST SCHEDULE
ITEM INFORMATION
ITEM
NUMBER
DESCRIPTION OF
SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
1.00 JB __________________ __________________
Labor and materials to install access control systems, devices, and hardware in clinical addition 2J and building 3.
PRINCIPAL NAICS CODE: 561621 - Security Systems Services (except
Locksmiths)
PRODUCT/SERVICE CODE: N063 - Installation of Equipment - Alarm, Signal, and
Security Detection Systems
GRAND TOTAL __________________
0001 SHIP TO: Department of Veterans Affairs
Dallas VA Medical Center
4500 S. Lancaster Road
Dallas, TX 75216
USA
1.00 6/25/2026 - 9/24/2026
MARK FOR: TBD
FOB: DESTINATION
B.3 STATEMENT OF WORK
NTX Access Control System Installation
General: Contractor shall provide services for the Physical Security systems at the Dallas VA Medical
Center to include All Material, Labor, Installation and Travel costs for Access Control upgrade. Dallas
VA Medical Center is located at 4500 S Lancaster Rd, Dallas, TX 75216. These services will correct physical security deficiencies noted during a physical security inspection and assessment. Products provided will be commercially procured and configured to comply with standards set forth in the Physical
Security Design Manual chapter 10, paying particular attention to the HSPD-12 and FICAM requirements contained therein.
Guidance: 10.2.1.7 “…Homeland Security Presidential Directive 12 (HSPD 12), dated August 27, 2004, Policy for a Common Identification Standard for Federal Employees and Contractors, directed the promulgation of a Federal standard for secure and reliable forms of identification for Federal employees and contractors. Identity, Credential and Access Management (ICAM) is the intersection of digital identities and associated attributes, credentials, and access controls into one comprehensive approach”
Background: Systems required by the VA Police.
Description of Work: This SOW includes the turnkey extension and upgrade of the existing HIRSCH systems. The scope of work includes all low voltage installation of electric door hardware, wiring, project management, engineering and start-up labor, commissioning, miscellaneous installation materials, one-year warranty:
Access Control – Hirsch - Velocity Software License - Add 16 Modules
• (5) each MX-8 Controller with SNIB3 on board & RREB and backup batteries o 8-Door Panels in enclosure with power for system and locks
• (16) card readers with keypads o uTrust TS Wallmount Keypad HF/LF Pigtail RS485/OSDP Reader
• (27) each Door contacts
• (12) each REX break glass emergency exit SDC491
Electric Door Hardware- 14 openings
• Building 2J Clinic 1 and 2 1st floor o Four sets of wood double egress doors.
o Provide and install 4' VD22 aluminum rim exit devices with motor (no REX), 230L trim, and 5" heavy-duty hinges.
• Building 2J Clinic 5 and 6 3rd floor o Four sets of wood double egress doors with existing VD22 SVR devices o Remove existing exit devices and install VD22 rim exit devices with motor and 5” heavy-duty hinges, or door loop if required.
o Reuse existing 230L trim
• Building 2J Clinic 7 and 8 3rd floor o Three sets of wood double egress doors with existing VD22 rim exit devices o Provide and install motor only with 5” heavy-duty hinges or door loop if required
• Building 2J Clinic 7 3rd floor o Hollow metal double egress doors with existing VD 22 rim exit devices o Provide and install new VD22 rim exit device with motor, 230L trim, and 5” heavy-duty hinges
• Building 3 2nd floor o Door 1 single hollow metal with existing EMHART mortise lock
▪ Provide and install a complete electrified mortise lock (SFIC) and standard hinge o Door 2 hallway corridor
▪ Provide and install magnetic locks
The Contractor shall provide a single written document outlining the warranty of the manufacturer(s) product and the contractor’s installation, on a single document and be provided in the bid response package.
The document shall warrant complete installation of all services and equipment to be free from defects in materials and workmanship for a period of no less than one year, starting with the date of Final System
Acceptance
Hours of Performance: Work shall occur Monday – Friday during normal duty hours (8:00 am – 5:00
pm) excluding Federal Holidays. New Year’s Day, Martin Luther King’s Birthday, Washington’s Birthday, Memorial Day, Juneteenth, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving
Day, Christmas.
Check in Requirements: The Field Service Engineer must report to VA Police Operations to obtain a badge and sign in before work begins. Submit any mobile media devices that would be used on the system to a virus scan.
Documentation: Contractor shall furnish a detailed field service report upon completion of work to the
Fire Alarm Shop. Payment will not be processed until a properly completed service report is received. The service report shall contain, at a minimum, the following information:
• Type, model and serial number (s) of all equipment on which maintenance was performed
• Total time spent performing maintenance.
• Detailed narrative description of the services required
• Date and time the installation is completed
The service report shall itemize every item in the specification. Each item shall state the "as found" condition or values, the "calibrated to" or "adjusted to" values, the factory design tolerances, and a complete description of all work performed concerning the items. Included will be a list of new parts used and recommended future repairs.
Period of Performance: Period of performance shall be done in a reasonable time frame (no longer than one 30 days after receipt of order) unless unforeseen circumstances arise which need to be discussed with
Fire Control shop Tech representative.
Place of performance: Dallas VA Medical Center | 4500 S Lancaster Rd, Dallas, TX 75216
Information technology security requirements: The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract. The contractor shall comply with all Federal laws and regulations the VA has developed when VA sensitive information is accessed, used, stored, generated, transmitted, or exchanged by and between VA and a contractor. The information made available to the contractor by VA for the performance of this contract will be used only for the purposes of performance under this contract. The certification and accreditation requirements do not apply to this requirement and a security accreditation package is not required.
NARA Records Management Language for Contracts (May 2017)
1. Contractor shall comply with all applicable records management laws and regulations, as well as
National Archives and Records Administration (NARA) records policies, including but not limited to the
Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII
Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C.
chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the
Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.
3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the
Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
4. VA North Texas Health Care System and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of VA North Texas Health Care System or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the
Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701.
In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to VA North Texas Health Care System. The agency must report promptly to
NARA in accordance with 36 CFR 1230.
5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to VA North Texas Health Care System control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the [contract vehicle]. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).
6. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The
Contractor (and any sub-contractor) is required to abide by Government and VA North Texas Health Care
System guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.
7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with VA North Texas Health Care System policy.
8. The Contractor shall not create or maintain any records containing any non-public VA North Texas
Health Care System information that are not specifically tied to or authorized by the contract.
9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.
10. The VA North Texas Health Care System owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which VA
North Texas Health Care System shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.
11. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take VHA-provided records management training, Talent Management
System (TMS) Item #3873736, Records Management for Records Officers and Liaisons. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.
Information Technology Security requirements section
As prescribed in 839.201, insert the following clause:
The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract.
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
b. All contractors, subcontractors, and third-party servicers and associates working with
VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive
Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a
Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security
Clearance must be processed through the Special Security Officer located in the Planning and
National Security Service within the Office of Operations, Security, and Preparedness.
d. Custom software development and outsourced operations must be located in the U.S.
to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
3. VA INFORMATION CUSTODIAL LANGUAGE
a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d)
(1).
b. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure
VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
c. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media
Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
g. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business
Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
h. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
i. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.
j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.
k. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.
l. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COTR.
GENERAL RULES OF BEHAVIOR
a. Rules of Behavior are part of a comprehensive program to provide complete information security. These rules establish standards of behavior in recognition of the fact that knowledgeable users are the foundation of a successful security program. Users must understand that taking personal responsibility for the security of their computer and the information it contains is an essential part of their job.
b. The following rules apply to all VA contractors. I agree to:
(1) Follow established procedures for requesting, accessing, and closing user accounts and access. I will not request or obtain access beyond what is normally granted to users or by what is outlined in the contract.
(2) Use only systems, software, databases, and data which I am authorized to use, including any copyright restrictions.
(3) I will not use other equipment (OE) (non-contractor owned) for the storage, transfer, or processing of VA sensitive information without a VA CIO approved waiver, unless it has been reviewed and approved by local management and is included in the language of the contract. If authorized to use OE IT equipment, I must ensure that the system meets all applicable 6500 Handbook requirements for OE.
(4) Not use my position of trust and access rights to exploit system controls or access information for any reason other than in the performance of the contract.
(5) Not attempt to override or disable security, technical, or management controls unless expressly permitted to do so as an explicit requirement under the contract or at the direction of the COTR or ISO. If I am allowed or required to have a local administrator account on a government-owned computer, that local administrative account does not confer me unrestricted access or use, nor the authority to bypass security or other controls except as expressly permitted by the VA CIO or CIO's designee.
(6) Contractors’ use of systems, information, or sites is strictly limited to fulfill the terms of the contract. I understand no personal use is authorized. I will only use other Federal government information systems as expressly authorized by the terms of those systems. I accept that the restrictions under ethics regulations and criminal law still apply.
(7) Grant access to systems and information only to those who have an official need to know.
(8) Protect passwords from access by other individuals.
(9) Create and change passwords in accordance with VA Handbook 6500 on systems and any devices protecting VA information as well as the rules of behavior and security settings for the particular system in question.
(10) Protect information and systems from unauthorized disclosure, use, modification, or destruction. I will only use encryption that is FIPS 140-2 validated to safeguard VA sensitive information, both safeguarding VA sensitive information in storage and in transit regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA.
(11) Follow VA Handbook 6500.1, Electronic Media Sanitization to protect VA information. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders.
(12) Ensure that the COTR has previously approved VA information for public dissemination, including e-mail communications outside of the VA as appropriate. I will not make any unauthorized disclosure of any VA sensitive information through the use of any means of communication including but not limited to e-mail, instant messaging, online chat, and web bulletin boards or logs.
(13) Not host, set up, administer, or run an Internet server related to my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA unless explicitly authorized under the contract or in writing by the COTR.
(14) Protect government property from theft, destruction, or misuse. I will follow VA directives and handbooks on handling Federal government IT equipment, information, and systems. I will not take VA sensitive information from the workplace without authorization from the COTR.
(15) Only use anti-virus software, antispyware, and firewall/intrusion detection software authorized by VA. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with VA.
(16) Not disable or degrade the standard anti-virus software, antispyware, and/or firewall/intrusion detection software on the computer I use to access and use information assets or resources associated with my performance of services under the contract terms with VA. I will report anti-virus, antispyware, firewall or intrusion detection software errors, or significant alert messages to the COTR.
(17) Understand that restoration of service of any VA system is a concern of all users of the system.
(18) Complete required information security and privacy training, and complete required training for the particular systems to which I require access.
(End of Statement of Work)
(END OF SECTION B)
SECTION C - CONTRACT CLAUSES
C.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):
https://www.acquisition.gov/browse/index/far https://www.va.gov/oal/library/vaar/
(End of Clause)
FAR
Number
Title Date
52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS NOV 2023
52.203-19 PROHIBITION ON REQUIRING CERTAIN INTERNAL
CONFIDENTIALITY AGREEMENTS OR STATEMENTS
JAN 2017
52.204-13 SYSTEM FOR AWARD MANAGEMENT—MAINTENANCE
(DEVIATION)
NOV 2025
52.204-9 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR
PERSONNEL
JAN 2011
52.209-6 PROTECTING THE GOVERNMENT'S INTEREST WHEN
SUBCONTRACTING WITH CONTRACTORS DEBARRED,
SUSPENDED, PROPOSED FOR DEBARMENT, OR
VOLUNTARILY EXCLUDED
JAN 2025
52.209-10 PROHIBITION ON CONTRACTING WITH INVERTED
DOMESTIC CORPORATIONS
NOV 2015
52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL
PRODUCTS AND COMMERCIAL SERVICES
NOV 2023
52.219-28 POSTAWARD SMALL BUSINESS PROGRAM
REREPRESENTATION (DEVIATION)
NOV 2025
52.222-3 CONVICT LABOR (DEVIATION) NOV 2025
52.222-41 SERVICE CONTRACT LABOR STANDARDS (DEVIATION) NOV 2025
52.222-50 COMBATING TRAFFICKING IN PERSONS (DEVIATION) NOV 2025
52.222-55 MINIMUM WAGES FOR CONTRACTOR WORKERS UNDER
EXECUTIVE ORDER 14026 (DEVIATION)
NOV 2025
52.222-62 PAID SICK LEAVE UNDER EXECUTIVE ORDER 13706
(DEVIATION)
NOV 2025
52.223-5 POLLUTION PREVENTION AND RIGHT-TO-KNOW
INFORMATION
MAY 2024
52.226-8 ENCOURAGING CONTRACTOR POLICIES TO BAN TEXT
MESSAGING WHILE DRIVING
MAY 2024
52.232-33 PAYMENT BY ELECTRONIC FUNDS TRANSFER—SYSTEM
FOR AWARD MANAGEMENT
OCT 2018
52.232-40 PROVIDING ACCELERATED PAYMENTS TO SMALL
BUSINESS SUBCONTRACTORS
MAR 2023
52.233-3 PROTEST AFTER AWARD AUG 1996
52.237-2 PROTECTION OF GOVERNMENT BUILDINGS,
EQUIPMENT, AND VEGETATION
APR 1984
52.244-
6DEV
SUBCONTRACTS FOR COMMERCIAL PRODUCTS AND
COMMERCIAL SERVICES
OCT 2025
852.203-70 COMMERCIAL ADVERTISING MAY 2018
852.204-70 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR
PERSONNEL
MAY 2020
852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS NOV 2018
852.239-70
852.242-71
SECURITY REQUIREMENTS FOR INFORMATION
TECHNOLOGY RESOURCES
ADMINISTRATIVE CONTRACTING OFFICER
FEB 2023
OCT 2020
C.2 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)
The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 30 calendar days.
(End of Clause)
C.3 52.222-42 STATEMENT OF EQUIVALENT RATES FOR FEDERAL HIRES
(MAY 2014)
In compliance with the Service Contract Labor Standards statute and the regulations of the Secretary of
Labor (29 CFR Part 4), this clause identifies the classes of service employees expected to be employed under the contract and states the wages and fringe benefits payable to each if they were employed by the contracting agency subject to the provisions of 5 U.S.C.5341 or 5332.
This Statement is for Information Only:
It is not a Wage Determination
Employee Class Monetary Wage-Fringe Benefits
WG‑08 Locksmith, Dallas County, TX $29.74/hr.
C.4 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025)
(DEVIATION)
(a) Definitions. As used in this clause—
American Security Drone Act-covered foreign entity means an entity included on a list that the Federal
Acquisition Security Council (FASC) develops and maintains and publishes in the System for Award
Management (SAM) at https://www.sam.gov (section 1822 of Pub. L. 118-31, 41 U.S.C. 3901 note prec.).
Backhaul means intermediate links between the core network, or backbone network, and the small subnetworks at the edge of the network (e.g., connecting cell phones/towers to the core telephone network). Backhaul can be wireless (e.g., microwave) or wired (e.g., fiber optic, coaxial cable, Ethernet).
Covered application means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.
Covered article, as defined in 41 U.S.C. 4713(k), means:
https://www.sam.gov
(1) Information technology, as defined in 40 U.S.C. 11101, including cloud computing services of all types;
(2) Telecommunications equipment or telecommunications service, as those terms are defined in section 3 of the Communications Act of 1934 (47 U.S.C. 153);
(3) The processing of information on a Federal or non-Federal information system, subject to the requirements of the Controlled Unclassified Information program (see 32 CFR part 2002); or
(4) Hardware, systems, devices, software, or services that include embedded or incidental information technology.
Covered foreign country means The People’s Republic of China.
Covered telecommunications equipment or services means—
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation
(or any subsidiary or affiliate of such entities);
(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology
Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);
(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.
Critical technology means—
(1) Defense articles or defense services included on the United States Munitions List set forth in the
International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal
Regulations;
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the
Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal
Regulations, and controlled—
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or
(ii) For reasons relating to regional stability or surreptitious listening;
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal
Regulations (relating to export and import of nuclear equipment and material);
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control
Reform Act of 2018 (50 U.S.C. 4817).
FASC-prohibited unmanned aircraft system means an unmanned aircraft system manufactured or assembled by an American Security Drone Act—covered foreign entity.
FASCSA order means any of the following orders issued under the Federal Acquisition Supply Chain
Security Act (FASCSA) requiring removing covered articles from executive agency information systems or excluding one or more named sources or named covered articles from executive agency procurement actions, as described in 41 CFR 201-1.303(d) and (e):
(1) The Secretary of Homeland Security may issue FASCSA orders that apply to civilian agencies, to the extent not covered by paragraph (2) or (3) of this definition. This type of FASCSA order may be referred to as a Department of Homeland Security (DHS) FASCSA order.
(2) The Secretary of Defense may issue FASCSA orders that apply to the Department of Defense
(DoD) and national security systems other than sensitive compartmented information systems. This type of FASCSA order may be referred to as a DoD FASCSA order.
(3) The Director of National Intelligence (DNI) may issue FASCSA orders that apply to the intelligence community and sensitive compartmented information systems, to the extent not covered by paragraph (2) of this definition. This type of FASCSA order may be referred to as a DNI FASCSA order.
Information technology, as defined in 40 U.S.C. 11101(6)—
(1) Means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use—
(i) Of that equipment; or
(ii) Of that equipment to a significant extent in the performance of a service or the furnishing of a product;
(2) Includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but
(3) Does not include any equipment acquired by a Federal contractor incidental to a Federal contract.
Intelligence community, as defined by 50 U.S.C. 3003(4), means the following—
(1) The Office of the Director of National Intelligence;
(2) The Central Intelligence Agency;
(3) The National Security Agency;
(4) The Defense Intelligence Agency;
(5) The National Geospatial-Intelligence Agency;
(6) The National Reconnaissance Office;
(7) Other offices within the Department of Defense for the collection of specialized national intelligence through reconnaissance programs;
(8) The intelligence elements of the Army, the Navy, the Air Force, the Marine Corps, the Coast Guard, the Federal Bureau of Investigation, the Drug Enforcement Administration, and the Department of
Energy;
(9) The Bureau of Intelligence and Research of the Department of State;
(10) The Office of Intelligence and Analysis of the Department of the Treasury;
(11) The Office of Intelligence and Analysis of the Department of Homeland Security; or
(12) Such other elements of any department or agency as may be designated by the President, or designated jointly by the Director of National Intelligence and the head of the department or agency concerned, as an element of the intelligence community.
Interconnection arrangement means arrangements governing the physical connection of two or more networks to allow the use of another’s network to hand off traffic where it is ultimately delivered (e.g., connecting a customer of telephone provider A to a customer of telephone company B) or sharing data and other information resources.
Kaspersky Lab-covered article means any hardware, software, or service that—
(1) Is developed or provided by a Kaspersky Lab-covered entity;
(2) Includes any hardware, software, or service developed or provided in whole or in part by a
Kaspersky Lab-covered entity; or
(3) Contains components using any hardware or software developed in whole or in part by a Kaspersky
Lab-covered entity.
Kaspersky Lab-covered entity means—
(1) Kaspersky Lab;
(2) Any successor entity to Kaspersky Lab, including any change in name, e.g., “Kaspersky”;
(3) Any entity that controls, is controlled by, or is under common control with Kaspersky Lab; or
(4) Any entity of which Kaspersky Lab has a majority ownership.
National security system, as defined in 44 U.S.C. 3552, means any information system (including any telecommunications system) used or operated by an agency or by a contractor of an agency, or other organization on behalf of an agency—
(1) The function, operation, or use of which involves intelligence activities; involves cryptologic activities related to national security; involves command and control of military forces; involves equipment that is an integral part of a weapon or weapons system; or is critical to the direct fulfillment of military or intelligence missions, but does not include a system that is to be used for routine administrative and business applications (including payroll, finance, logistics, and personnel management applications); or
(2) Is protected at all times by procedures established for information that have been specifically authorized under criteria established by an Executive order or an Act of Congress to be kept classified in the interest of national defense or foreign policy.
Roaming means cellular communications services (e.g., voice, video, data) received from a visited network when unable to connect to the facilities of the home network either because signal coverage is too weak or because traffic is too high.
Sensitive compartmented information means classified information concerning or derived from intelligence sources, methods, or analytical processes, which is required to be handled within formal access control systems established by the Director of National Intelligence.
Sensitive compartmented information system means a national security system authorized to process or store sensitive compartmented information.
Source means a non-Federal supplier, or potential supplier, of products or services, at any tier.
Subsidiary means an entity in which more than 50 percent of the entity is owned directly by a parent corporation or through another subsidiary of a parent corporation.
Substantial or essential component means any component necessary for the proper function or performance of a piece of equipment, system, or service.
Unmanned aircraft means an aircraft that is operated without the possibility of direct human intervention from within or on the aircraft (49 U.S.C. 44801(11)).
Unmanned aircraft system means an unmanned aircraft and associated elements (including communication links and the components that control the unmanned aircraft) that are required for the operator to operate safely and efficiently in the national airspace system (49 U.S.C. 44801(12)).
(b) Prohibitions on providing or using specific products or services in performance of contract. Unless a waiver or exception applies, the Contractor is prohibited from providing any products or services to the
Government or using in the performance of the contract any of the following:
(1) A covered application on any information technology owned or managed by the Government, or on any information technology used or provided by the Contractor under this contract, including equipment provided by the Contractor’s employees (section 102 of Division R of the Consolidated Appropriations
Act, 2023 (Pub. L. 117-328));
(2) A Kaspersky Lab-covered article (Section 1634 of Division A of the National Defense
Authorization Act for Fiscal Year 2018 (Pub. L. 115-91));
(3) Covered telecommunications equipment or services used as a substantial or essential component of any system, or as critical technology as part of any system (paragraphs (a)(1)(A) of section 889 of the
John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232)). This does not prohibit contractors from providing—
(i) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(ii) Telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(c) Prohibition on unmanned aircraft systems manufactured or assembled by American Security Drone
Act—covered foreign entities.
(1) Prohibition. The Contractor is prohibited from—
(i) Delivering any FASC-prohibited unmanned aircraft system, which includes unmanned aircraft
(i.e., drones) and associated elements (sections 1823 and 1826 of American Security Drone Act of 2023, within the National Defense Authorization Act for Fiscal Year 2024, Pub. L. 118-31, Div. A, Title XVIII, Subtitle B, 41 U.S.C. 3901 note prec.);
(ii) On or after December 22, 2025, operating a FASC-prohibited unmanned aircraft system in the performance of the contract (section 1824 of Pub. L. 118-31); and
(iii) On or after December 22, 2025, using Federal funds to procure or operate a FASC-prohibited unmanned aircraft system (section 1825 of Pub. L. 118-31).
(2) Procedures. The Contractor shall search SAM for the FASC-maintained list of American Security
Drone Act—covered foreign entities before proposing, or using in performance of the contract, any unmanned aircraft system. Also, the Contractor shall ensure any effort or expenditure associated with a
FASC-prohibited unmanned aircraft system is consistent with a corresponding exemption, exception, or waiver determination expressly stated in the contract.
(3) Exemptions, exceptions, and waivers. The prohibitions in paragraph (c) of this clause do not apply where the agency has determined an exemption, exception, or waiver applies, and the contract indicates that such a determination has been made.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .