RFQ_70CDCR22Q00000017.pdf

PDF 381 KB Posted

Attached to
DHS/ICE El Paso Field Office Courier Service Federal contract opportunity
Solicitation number
70CDCR22Q00000017
Issued by
Immigration and Customs Enforcement

View the file

Other files for this federal contract opportunity

Other files attached to DHS/ICE El Paso Field Office Courier Service, newest first.
File Type Posted
70CDCR22Q00000017_QandA.pdf PDF
70CDCR22Q00000017_Price Schedule.xlsx XLSX spreadsheet
El Paso Courier Services_ SOW.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Request for Quote: 70CDCR22Q00000017 U.S. Immigration and Customs Enforcement

El Paso Courier Services

1. This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6 – Streamlined Procedures for Evaluation and Solicitation for Commercial Items, in conjunction with FAR Part 13, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested and a written solicitation will not be issued. This solicitation is issued as a Request for Quotation (RFQ) under 70CDCR22Q00000017. This notice incorporates provisions and clauses in effect through Federal Acquisition Circular (FAC) 2022-07 effective 10 AUG 2022, and Homeland Security Acquisition Regulations effective 29 March 2021. All responsible small business sources may submit a quote.

2. The associated North American Industrial Classification System (NAICS) code is 492110 – Couriers and Express Delivery. The applicable small business size standard is 1,500 employees.

3. The El Paso Field (ELP), a component of Enforcement and Removal Operations (ERO) under the Department of Homeland Security/ Immigration and Customs Enforcement has a requirement for courier services of sensitive document/files/packages, with a weight in excess of 80 pounds, to/from various locations daily (Monday – Friday) within the El Paso, Texas and Chaparral, New Mexico areas of responsibility. This order is anticipated to be awarded prior to 30 September 2022.

4. Quoters must price in accordance with the below Price Schedule.

Non-Personal Services: Courier vendor is to provide all labor, transportation, materials, equipment, supplies, supervision, licenses, fees, and training to perform the courier services required by the El Paso Field Office (ELP) Statement of Work (SOW). Vendor costs shall be inclusive of all fees and transportation costs when calculating the monthly unit price.

Line Item

Services Quantity Unit Unit Price Extended Amount

0001 BASE PERIOD: Courier services in support of ELP area in accordance with the SOW

Period of Performance (POP): Sept 30, 2022 – Sept 29, 2023

MO

1001 OPTION YEAR 1: Courier services in support of ELP area in accordance with the SOW

POP: Sept 30, 2023 – Sept 29, 2024

2001 OPTION YEAR 2: Courier services in support of ELP area in accordance with the SOW

POP: Sept 30, 2024 – Sept 29, 2025

Total for All 3 Periods $

5. For dates and places of delivery please refer to Table 1 of the Statement of Work.

6. FAR 52.212-1, Instructions to Offerors-Commercial Products and Commercial Services (Nov 2021), applies to this acquisition and no addendum to the provision is provided. Please read and comply.

7. FAR 52.212-2, Evaluation – Commercial Products and Commercial Services (Nov 2021), applies to this acquisition:

(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors shall be used to evaluate offers: Technical, Prior Relevant Experience, and Price. All three factors will be used in the tradeoff selection decision.

Quoters are cautioned that the award may not necessarily be made to the lowest price quotation.

Technical: The vendor shall document in no more than 3 pages its ability to meet the requirements outlined in the Statement of Work. Specifically, the vendor shall discuss a) their corporate capability handling sensitive and legal documents (preferably with federal, state, or legal entities), b) their current personnel availability and familiarity with tasks required by the SOW, c) the company’s ability to commence work immediately and d) proof of vehicle/insurance/bonding capabilities to meet the requirement.

Prior Relevant Experience: The vendor shall provide evidence of at least one (1) but no more than two (2) contracts that are currently active or have been physically completed in the last three years that represents their relevant experience and complexity. Each must demonstrate the handling and pick-up/delivery of sensitive documents to government/business locations within the Texas or New Mexico areas (preferably El Paso and Chaparral). The evidence should be provided in a table format and include the following:

Contract Number and Type Government/Business Point of Contact (name, address, telephone, and email) Place of Performance Period of Performance Contract value Description of the service provided

The Government will assess its confidence, based on the vendor’s technical response and prior relevant experience, using the following ratings:

High Confidence The Government has high confidence that the Offeror understands the requirement, proposes a sound approach, and will be successful in performing the task/contract; with little or no anticipation of Government intervention to be required.

Some Confidence

The Government has some confidence that the Offeror understands the requirement, proposes a sound approach, and will be successful in performing the task/contract; with some anticipation of Government intervention to be required.

Low Confidence The Government has low confidence that the Offeror understands the requirement, proposes a sound approach, or will be successful in performing the task/contract; with notable anticipation of Government intervention to be required.

Price: The vendor shall provide a completed pricing table which shows a proposed firm fixed price per each period and the cumulative price for all periods. The Government will evaluate the total price to determine if it is fair and reasonable.

The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. To account for the option periods possible under FAR 52.217-8 (maximum of six months), the Government will evaluate the option to extend services by adding six months of the offeror’s final option period price to the offeror’s total price. This amount will be the total evaluated price. The Government may choose to exercise the Option to Extend Services at the end of any performance period (base or option periods). Prices for the base and option periods, including the 6-month option available under FAR 52.217-8, will be evaluated to ensure that they are fair and reasonable for performance of the requirements established in this notice and as proposed in the technical submission. The price for the effort associated with FAR 52.217-8 will not be included in the total awarded value at contract award. If, at the end of the contract’s/order’s period of performance (the end of the base period or any option period) and within the time period established in the clause, the Government chooses to exercise this option, the pricing will be pursuant to the rates specified in the contract for the preceding performance period.

Technical and past performance, when combined, are significantly more important when compared to Price.

(b) Options. The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. Evaluation of options shall not obligate the Government to exercise the option(s).

(c) A written notice of award or acceptance of an offer, mailed or otherwise furnished to the successful offeror within the time for acceptance specified in the offer, shall result in a binding contract without further action by either party. Before the offer’s specified expiration time, the Government may accept an offer (or part of an offer), whether or not there are negotiations after its receipt, unless a written notice of withdrawal is received before award.

(End of provision)

8. Vendors shall ensure include a completed copy of the provision at 52.212-3, Offeror Representations and Certifications-Commercial Products and Commercial Services, with its offer or certify in their offer to its completion on SAM.gov. Vendor must also complete and return the following HSAR provision:

HSAR 3052.209-70 Prohibition on Contracts With Corporate Expatriates (JUN 2006)

(a) Prohibitions. Section 835 of the Homeland Security Act, 6 U.S.C. 395, prohibits the Department of Homeland Security from entering into any contract with a foreign incorporated entity which is treated as an inverted domestic corporation as defined in this provision, or with any subsidiary of such an entity.

The Secretary shall waive the prohibition with respect to any specific contract if the Secretary determines that the waiver is required in the interest of national security.

(b) Definitions. As used in this provision:

Expanded Affiliated Group means an affiliated group as defined in section 1504(a) of the Internal

Revenue Code of 1986 (without regard to section 1504(b) of such Code), except that section 1504 of such Code shall be applied by substituting ‘more than 50 percent’ for ‘at least 80 percent’ each place it appears.

https://www.acquisition.gov/far/part-52#FAR_52_212_3

Foreign Incorporated Entity means any entity which is, or but for subsection (b) of section 835 of the Homeland Security Act, 6 U.S.C. 395, would be, treated as a foreign corporation for purposes of the Internal Revenue Code of 1986.

Inverted Domestic Corporation. A foreign incorporated entity shall be treated as an inverted domestic corporation if, pursuant to a plan (or a series of related transactions) -

(1) The entity completes the direct or indirect acquisition of substantially all of the properties held directly or indirectly by a domestic corporation or substantially all of the properties constituting a trade or business of a domestic partnership;

(2) After the acquisition at least 80 percent of the stock (by vote or value) of the entity is held -

(i) In the case of an acquisition with respect to a domestic corporation, by former shareholders of the domestic corporation by reason of holding stock in the domestic corporation; or

(ii) In the case of an acquisition with respect to a domestic partnership, by former partners of the domestic partnership by reason of holding a capital or profits interest in the domestic partnership;

and

(3) The expanded affiliated group which after the acquisition includes the entity does not have substantial business activities in the foreign country in which or under the law of which the entity is created or organized when compared to the total business activities of such expanded affiliated group.

Person, domestic, and foreign have the meanings given such terms by paragraphs (1), (4), and (5) of section 7701(a) of the Internal Revenue Code of 1986, respectively.

(c) Special rules. The following definitions and special rules shall apply when determining whether a foreign incorporated entity should be treated as an inverted domestic corporation.

(1) Certain stock disregarded. For the purpose of treating a foreign incorporated entity as an inverted domestic corporation these shall not be taken into account in determining ownership:

(i) stock held by members of the expanded affiliated group which includes the foreign incorporated entity; or

(ii) Stock of such entity which is sold in a public offering related to an acquisition described in section 835(b)(1) of the Homeland Security Act, 6 U.S.C. 395(b)(1).

(2) Plan deemed in certain cases. If a foreign incorporated entity acquires directly or indirectly substantially all of the properties of a domestic corporation or partnership during the 4-year period beginning on the date which is 2 years before the ownership requirements of subsection (b)(2) are met, such actions shall be treated as pursuant to a plan.

(3) Certain transfers disregarded. The transfer of properties or liabilities (including by contribution or distribution) shall be disregarded if such transfers are part of a plan a principal purpose of which is to avoid the purposes of this section.

(d) Special rule for related partnerships. For purposes of applying section 835(b) of the Homeland Security Act, 6 U.S.C. 395(b) to the acquisition of a domestic partnership, except as provided in regulations, all domestic partnerships which are under common control (within the meaning of section 482 of the Internal Revenue Code of 1986) shall be treated as a partnership.

(e) Treatment of Certain Rights.

(1) Certain rights shall be treated as stocks to the extent necessary to reflect the present value of all equitable interests incident to the transaction, as follows:

(i) Warrants;

(ii) Options;

(iii) Contracts to acquire stock;

(iv) Convertible debt instruments;

(v) Others similar interests.

(2) Rights labeled as stocks shall not be treated as stocks whenever it is deemed appropriate to do so to reflect the present value of the transaction or to disregard transactions whose recognition would defeat the purpose of section 835.

(f) Disclosure. The offeror under this solicitation represents that [Check one]:

_ it is not a foreign incorporated entity that should be treated as an inverted domestic corporation pursuant to the criteria of (HSAR) 48 CFR 3009.108-7000 through 3009.108-7003;

_ it is a foreign incorporated entity that should be treated as an inverted domestic corporation pursuant to the criteria of (HSAR) 48 CFR 3009.108-7000 through 3009.108-7003, but it has submitted a request for waiver pursuant to 3009.108-7004, which has not been denied; or

_ it is a foreign incorporated entity that should be treated as an inverted domestic corporation pursuant to the criteria of (HSAR) 48 CFR 3009.108-7000 through 3009.108-7003, but it plans to submit a request for waiver pursuant to 3009.108-7004.

(g) A copy of the approved waiver, if a waiver has already been granted, or the waiver request, if a waiver has been applied for, shall be attached to the bid or proposal.

(End of provision)

9. FAR clause 52.212-4, Contract Terms and Conditions-Commercial Products and Commercial Services (Nov 2021), applies to this acquisition and an addendum to section (g) Invoice applies.

ICE INVOICE INSTRUCTIONS

1. The contractor shall be active in the System for Award Management (www.SAM.gov) for invoice processing. Besides the information identified below, a proper invoice shall also include;

contractor’s Unique Entity Identifier (UEI) number; the ICE Program Office; and state whether the invoice is “INTERIM” or “FINAL”.

2. In accordance with Contract Clauses, FAR 52.212-4 (g) (1), Contract Terms and Conditions - Commercial Items, or FAR 52.232-25 (a) (3), Prompt Payment, as applicable, the information required with each invoice submission is as follows:

An invoice must include-

(i) Name and address of the Contractor. The name, address and UEI number on the invoice MUST match the information in both the Contract/Agreement and the information in SAM;

(ii) Unique Entity Identifier (UEI) number;

(iii) Invoice date and number;

(iv) Contract number, line items and, if applicable, the order number;

(v) Description, quantity, unit of measure, unit price and extended price of the items delivered;

(vi) Shipping number and date of shipment, including the bill of lading number and weight of shipment if shipped on Government bill of lading;

(vii) Terms of any discount for prompt payment offered;

(viii) Remit to Address;

(ix) Name, title, and phone number of person to notify in event of defective invoice;

(x) ICE Program Office designated on the order/contract/agreement; and

(xi) Whether the invoice is “Interim” or “Final” https://www.acquisition.gov/far/part-52#FAR_52_212_4

3. Invoice submission: shall be submitted via one of the following two methods. Improper invoices or those submitted by means other than these two methods will be returned. Email is the preferred method.

a. Primary method of submission is email. The Contractor shall submit one (1) invoice in PDF format per e-mail and the subject line of the e-mail will reference the invoice number of the attached invoice to: Invoice.Consolidation@ice.dhs.gov, Attn: ICE-ERO-SPC-FEP-ELP Invoice

b. Mail:

DHS, ICE

Financial Service Center Burlington

Attn: CE-ERO-SPC-FEP-ELP Invoice P.O. Box 1620 Williston, VT 05495-1620

4. Payment Inquiries: Questions regarding invoice submission or payment, please contact Financial Service Center Burlington at 1-877-491-6521, Option # 3 or by e-mail at OCFO.CustomerService@ice.dhs.gov Invoices without the above information may be returned for resubmission.

10. FAR 52.212-5, Contract Terms and Conditions Required To Implement Statutes or Executive Orders-Commercial Products and Commercial Services (May 2022), applies to this acquisition and the additional FAR clauses cited are applicable to the acquisition.

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015).

(5) 52.233-3, Protest After Award (AUG 1996) ( 31 U.S.C. 3553).

(6) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and

108-78 ( 19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

_X_ (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (JUN 2020) (Pub. L. 109-282) ( 31 U.S.C. 6101 note).

https://www.acquisition.gov/far/part-52#FAR_52_212_5

_X_ (8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment. (NOV 2021) ( 31 U.S.C. 6101 note).

_X_ (14) (i) 52.219-6, Notice of Total Small Business Set-Aside (NOV 2020) ( 15 U.S.C. 644).

_X_ (27) 52.222-3, Convict Labor (JUN 2003) (E.O.11755).

_X_ (29) 52.222-21, Prohibition of Segregated Facilities (APR 2015).

_X_ (30) (i) 52.222-26, Equal Opportunity (SEP 2016) (E.O.11246).

_X_ (31) (i) 52.222-35, Equal Opportunity for Veterans (JUN 2020) ( 38 U.S.C. 4212).

_X_ (32) (i) 52.222-36, Equal Opportunity for Workers with Disabilities (JUN 2020) ( 29 U.S.C. 793).

_X_ (33) 52.222-37, Employment Reports on Veterans (JUN 2020) ( 38 U.S.C. 4212).

_X_ (35) (i) 52.222-50, Combating Trafficking in Persons (NOV 2021) ( 22 U.S.C. chapter 78 and E.O.

13627).

_X_ (36) 52.222-54, Employment Eligibility Verification (MAY 2022) (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial products or commercial services as prescribed in FAR 22.1803.)

_X_ (44) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving (JUN 2020) (E.O. 13513).

__ (47) (i) 52.224-3 Privacy Training (JAN 2017) (5 U.S.C. 552 a).

_X_ (ii) Alternate I (JAN 2017) of 52.224-3.

_X_(58) 52.232-33, Payment by Electronic Funds Transfer-System for Award Management (OCT2018) ( 31 U.S.C. 3332).

(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

_X_ (1) 52.222-41, Service Contract Labor Standards (AUG 2018) ( 41 U.S.C. chapter67).

_X_ (2) 52.222-42, Statement of Equivalent Rates for Federal Hires (MAY

2014) ( 29 U.S.C. 206 and 41 U.S.C. chapter 67).

_X_ (3) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards-Price

Adjustment (Multiple Year and Option Contracts) (AUG 2018) ( 29 U.S.C. 206 and 41 U.S.C. chapter 67).

(d) Comptroller General Examination of Record. The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold, as defined in FAR 2.101, on the date of award of this contract, and does not contain the clause at 52.215-2, Audit and Records-Negotiation.

(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor’s directly pertinent records involving transactions related to this contract.

(2) The Contractor shall make available at its offices at all reasonable times the records, materials, and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR subpart 4.7, Contractor Records Retention, of the other clauses of this contract. If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.

(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data, regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.

(e) (1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c), and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial products or commercial services. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause-

(i) 52.203-13, Contractor Code of Business Ethics and Conduct (NOV 2021) ( 41 U.S.C. 3509).

(ii) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or

Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(iii) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).

(iv) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(v) 52.219-8, Utilization of Small Business Concerns (OCT 2018) ( 15 U.S.C. 637(d)(2) and (3)), in all subcontracts that offer further subcontracting opportunities. If the subcontract (except subcontracts to small business concerns) exceeds the applicable threshold specified in FAR 19.702(a) on the date of subcontract award, the subcontractor must include 52.219-8 in lower tier subcontracts that offer subcontracting opportunities.

(vi) 52.222-21, Prohibition of Segregated Facilities (APR 2015).

(vii) 52.222-26, Equal Opportunity (SEP 2015) (E.O.11246).

(viii) 52.222-35, Equal Opportunity for Veterans (JUN 2020) ( 38 U.S.C. 4212).

(ix) 52.222-36, Equal Opportunity for Workers with Disabilities (JUN 2020) ( 29 U.S.C. 793).

(x) 52.222-37, Employment Reports on Veterans (JUN 2020) ( 38 U.S.C. 4212).

(xi) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (DEC

2010) (E.O. 13496). Flow down required in accordance with paragraph (f) of FAR clause 52.222-40.

(xii) 52.222-41, Service Contract Labor Standards (AUG 2018) ( 41 U.S.C. chapter 67).

(xiii)

(A) 52.222-50, Combating Trafficking in Persons (NOV 2021) ( 22 U.S.C. chapter 78 and E.O 13627).

(B) Alternate I (MAR 2015) of 52.222-50 ( 22 U.S.C. chapter 78 and E.O. 13627).

(xiv) 52.222-51, Exemption from Application of the Service Contract Labor Standards to

Contracts for Maintenance, Calibration, or Repair of Certain Equipment-Requirements (May2014) ( 41 U.S.C. chapter 67).

(xv) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements (MAY 2014) ( 41 U.S.C. chapter 67).

(xvi) 52.222-54, Employment Eligibility Verification (MAY 2022) (E.O. 12989).

(xvii) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026 (JAN

2022).

(xviii) 52.222-62, Paid Sick Leave Under Executive Order 13706 (JAN 2022) (E.O. 13706).

(xix)

(A) 52.224-3, Privacy Training (Jan 2017) ( 5 U.S.C. 552a).

https://www.acquisition.gov/far/part-52#FAR_52_203_13 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_203_19 https://www.acquisition.gov/far/part-52#FAR_52_204_23 https://www.acquisition.gov/far/part-52#FAR_52_204_25 https://www.acquisition.gov/far/part-52#FAR_52_219_8 http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title15-section637&num=0&edition=prelim https://www.acquisition.gov/far/part-19#FAR_19_702 https://www.acquisition.gov/far/part-52#FAR_52_219_8 https://www.acquisition.gov/far/part-52#FAR_52_222_21 https://www.acquisition.gov/far/part-52#FAR_52_222_26 https://www.acquisition.gov/far/part-52#FAR_52_222_35 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_222_36 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_222_37 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_222_40 https://www.acquisition.gov/far/part-52#FAR_52_222_40 https://www.acquisition.gov/far/part-52#FAR_52_222_41 http://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title41-chapter67-front&num=0&edition=prelim https://www.acquisition.gov/far/part-52#FAR_52_222_50 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_222_50 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_222_51 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_222_53 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_222_54 https://www.acquisition.gov/far/part-52#FAR_52_222_55 https://www.acquisition.gov/far/part-52#FAR_52_222_62 https://www.acquisition.gov/far/part-52#FAR_52_224_3 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3

(B) Alternate I (JAN 2017) of 52.224-3.

(xx) 52.225-26, Contractors Performing Private Security Functions Outside the United

States (OCT 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302 Note).

(xxi) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (JUN 2020) ( 42 U.S.C. 1792). Flow down required in accordance with paragraph (e) of FAR clause 52.226-6.

(xxii) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (NOV 2021) ( 46 U.S.C. 55305 and 10 U.S.C. 2631). Flow down required in accordance with paragraph (d) of FAR clause 52.247-64.

(2) While not required, the Contractor may include in its subcontracts for commercial products and commercial services a minimal number of additional clauses necessary to satisfy its contractual obligations.

(End of clause)

11. The following HSAR and FAR clauses apply to this acquisition. The full text can be found at:

https://www.acquisition.gov/content/regulations .

The following clauses are incorporated by reference:

HSAR 3052.204-71 Contractor Employee Access, Alternate II (Jun 2006) HSAR 3052.205-70 Advertisements, Publicizing Awards, and Releases (Sept 2012) HSAR 3052.242-72 Contracting Officer’s Representative (Dec 2003)

FAR 52.217-8 Option to Extend Services (Nov 1999)

The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 30 days of contract expiration.

FAR 52.217-9 Option to Extend the Term of the Contract (Mar 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 15 days of contract expiration; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 30 days before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 36 months.

Safeguarding of Sensitive Information (Mar 2015) https://www.acquisition.gov/far/part-52#FAR_52_224_3 https://www.acquisition.gov/far/part-52#FAR_52_225_26 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_226_6 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 https://www.acquisition.gov/far/part-52#FAR_52_247_64 https://www.govinfo.gov/content/pkg/USCODE-2019-title46/html/USCODE-2019-title46-subtitleV-partD-chap553-subchapI-sec55305.htm http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3

(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.

(b) Definitions. As used in this clause— “Personally Identifiable Information (PII)” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.

PII is a subset of sensitive information. Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:

(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107296, 196 Stat.

2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);

(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);

(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and

(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.

“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.

“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan. Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:

(1) Truncated SSN (such as last 4 digits)

(2) Date of birth (month, day, and year)

(3) Citizenship or immigration status

(4) Ethnic or religious affiliation

(5) Sexual orientation

(6) Criminal History

(7) Medical Information

(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN) Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.

(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at http://www.dhs.gov/dhs-security-and-training-requirements-contractors, or available upon request from the Contracting Officer, including but not limited to:

(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only)

Information

(2) DHS Sensitive Systems Policy Directive 4300A

(3) DHS 4300A Sensitive Systems Handbook and Attachments

(4) DHS Security Authorization Process Guide

(5) DHS Handbook for Safeguarding Sensitive Personally Identifiable Information

(6) DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program

(7) DHS Information Security Performance Plan (current fiscal year)

(8) DHS Privacy Incident Handling Guidance

(9) Federal Information Processing Standard (FIPS) 140-2 Security Requirements for Cryptographic Modules accessible at http://csrc.nist.gov/groups/STM/cmvp/standards.html (10) National Institute of Standards and Technology (NIST) Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations accessible at http://csrc.nist.gov/publications/PubsSPs.html

(11) NIST Special Publication 800-88 Guidelines for Media Sanitization accessible at http://csrc.nist.gov/publications/PubsSPs.html

(d) Handling of Sensitive Information. Contractor compliance with this clause, as well as the policies and procedures described below, is required.

(1) Department of Homeland Security (DHS) policies and procedures on Contractor personnel security requirements are set forth in various Management Directives (MDs), Directives, and Instructions. MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information describes how Contractors must handle sensitive but unclassified information. DHS uses the term “FOR OFFICIAL USE ONLY” to identify sensitive but unclassified information that is not otherwise categorized by statute or regulation. Examples of sensitive information that are categorized by statute or regulation are PCII, SSI, etc. The DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook provide the policies and procedures on security for Information Technology (IT) resources.

The DHS Handbook for Safeguarding Sensitive Personally Identifiable Information provides guidelines to help safeguard SPII in both paper and electronic form. DHS Instruction Handbook 121-01-007 Department of Homeland Security Personnel Suitability and Security Program establishes procedures, program responsibilities, minimum standards, and reporting protocols for the DHS Personnel Suitability and Security Program.

(2) The Contractor shall not use or redistribute any sensitive information processed, stored, and/or transmitted by the Contractor except as specified in the contract.

(3) All Contractor employees with access to sensitive information shall execute DHS Form 11000-6, Department of Homeland Security Non-Disclosure Agreement (NDA), as a condition of access to such information. The Contractor shall maintain signed copies of the NDA for all employees as a record of compliance. The Contractor shall provide copies of the signed NDA to the Contracting Officer’s Representative (COR) no later than two (2) days after execution of the form.

(4) The Contractor’s invoicing, billing, and other recordkeeping systems maintained to support financial or other administrative functions shall not maintain SPII. It is acceptable to maintain in these systems the names, titles and contact information for the COR or other Government personnel associated with the administration of the contract, as needed.

(e) Authority to Operate. The Contractor shall not input, store, process, output, and/or transmit sensitive information within a Contractor IT system without an Authority to Operate (ATO) signed by the Headquarters or Component CIO, or designee, in consultation with the Headquarters or Component Privacy Officer. Unless otherwise specified in the ATO letter, the ATO is valid for three (3) years. The Contractor shall adhere to current Government policies, procedures, and guidance for the Security Authorization (SA) process as defined below.

(1) Complete the Security Authorization process. The SA process shall proceed according to the DHS Sensitive Systems Policy Directive 4300A (Version 11.0, April 30, 2014), or any successor publication, DHS 4300A Sensitive Systems Handbook (Version 9.1, July 24, 2012), or any successor publication, and the Security Authorization Process Guide including templates.

(i) Security Authorization Process Documentation. SA documentation shall be developed using the Government provided Requirements Traceability Matrix and Government security documentation templates. SA documentation consists of the following: Security Plan, Contingency Plan, Contingency Plan Test Results, Configuration Management Plan, Security Assessment Plan, Security Assessment Report, and Authorization to Operate Letter.

Additional documents that may be required include a Plan(s) of Action and Milestones and Interconnection Security Agreement(s). During the development of SA documentation, the Contractor shall submit a signed SA package, validated by an independent third party, to the COR for acceptance by the Headquarters or Component CIO, or designee, at least thirty (30) days prior to the date of operation of the IT system. The Government is the final authority on the compliance of the SA package and may limit the number of resubmissions of a modified SA package. Once the ATO has been accepted by the Headquarters or Component CIO, or designee, the Contracting Officer shall incorporate the ATO into the contract as a compliance document. The Government’s acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the IT system controls are implemented and operating effectively.

(ii) Independent Assessment. Contractors shall have an independent third party validate the security and privacy controls in place for the system(s). The independent third party shall review and analyze the SA package, and report on technical, operational, and management level deficiencies as outlined in NIST Special Publication 800-53 Security and Privacy Controls for Federal Information Systems and Organizations. The Contractor shall address all deficiencies before submitting the SA package to the Government for acceptance.

(iii)Support the completion of the Privacy Threshold Analysis (PTA) as needed. As part of the SA process, the Contractor may be required to support the Government in the completion of the PTA.

The requirement to complete a PTA is triggered by the creation, use, modification, upgrade, or disposition of a Contractor IT system that will store, maintain and use PII, and must be renewed at least every three (3) years. Upon review of the PTA, the DHS Privacy Office determines whether a Privacy Impact Assessment (PIA) and/or Privacy Act System of Records Notice (SORN), or modifications thereto, are required. The Contractor shall provide all support necessary to assist the Department in completing the PIA in a timely manner and shall ensure that project management plans and schedules include time for the completion of the PTA, PIA, and SORN (to the extent required) as milestones. Support in this context includes responding timely to requests for information from the Government about the use, access, storage, and maintenance of PII on the Contractor’s system, and providing timely review of relevant compliance documents for factual accuracy. Information on the DHS privacy compliance process, including PTAs, PIAs, and SORNs, is accessible at http://www.dhs.gov/privacy-compliance.

(2) Renewal of ATO. Unless otherwise specified in the ATO letter, the ATO shall be renewed every three (3) years. The Contractor is required to update its SA package as part of the ATO renewal process.

The Contractor shall update its SA package by one of the following methods: (1) Updating the SA documentation in the DHS automated information assurance tool for acceptance by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls; or (2) Submitting an updated SA package directly to the COR for approval by the Headquarters or Component CIO, or designee, at least 90 days before the ATO expiration date for review and verification of security controls. The 90 day review process is independent of the system production date and therefore it is important that the Contractor build the review into project schedules. The reviews may include onsite visits that involve physical or logical inspection of the Contractor environment to ensure controls are in place.

(3) Security Review. The Government may elect to conduct random periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS, the Office of the Inspector General, and other Government organizations access to the Contractor’s facilities, installations, operations, documentation, databases and personnel used in the performance of this contract. The Contractor shall, through the Contracting Officer and COR, contact the Headquarters or Component CIO, or designee, to coordinate and participate in review and inspection activity by Government organizations external to the DHS. Access shall be provided, to the extent necessary as determined by the Government, for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of Government data or the function of computer systems used in performance of this contract and to preserve evidence of computer crime.

(4) Continuous Monitoring. All Contractor-operated systems that input, store, process, output, and/or transmit sensitive information shall meet or exceed the continuous monitoring requirements identified in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication.

The plan is updated on an annual basis. The Contractor shall also store monthly continuous monitoring data at its location for a period not less than one year from the date the data is created. The data shall be encrypted in accordance with FIPS 140-2 Security Requirements for Cryptographic Modules and shall not be stored on systems that are shared with other commercial or Government entities. The Government may elect to perform continuous monitoring and IT security scanning of Contractor systems from Government tools and infrastructure.

(5) Revocation of ATO. In the event of a sensitive information incident, the Government may suspend or revoke an existing ATO (either in part or in whole). If an ATO is suspended or revoked in accordance with this provision, the Contracting Officer may direct the Contractor to take additional security measures to secure sensitive information. These measures may include restricting access to sensitive information on the Contractor IT system under this contract. Restricting access may include disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.

(6) Federal Reporting Requirements. Contractors operating information systems on behalf of the Government or operating systems containing sensitive information shall comply with Federal reporting requirements. Annual and quarterly data collection will be coordinated by the Government.

Contractors shall provide the COR with requested information within three (3) business days of receipt of the request. Reporting requirements are determined by the Government and are defined in the Fiscal Year 2014 DHS Information Security Performance Plan, or successor publication. The Contractor shall provide the Government with all information to fully satisfy Federal reporting requirements for Contractor systems.

(f) Sensitive Information Incident Reporting Requirements.

(1) All known or suspected sensitive information incidents shall be reported to the Headquarters or Component Security Operations Center (SOC) within one hour of discovery in accordance with 4300A Sensitive Systems Handbook Incident Response and Reporting requirements. When notifying the Headquarters or Component SOC, the Contractor shall also notify the Contracting Officer, COR, Headquarters or Component Privacy Officer, and US-CERT using the contact information identified in the contract. If the incident is reported by phone or the Contracting Officer’s email address is not immediately available, the Contractor shall contact the Contracting Officer immediately after reporting the incident to the Headquarters or Component SOC. The Contractor shall not include any sensitive information in the subject or body of any e-mail. To transmit sensitive information, the Contractor shall use FIPS 140-2 Security Requirements for Cryptographic Modules compliant encryption methods to protect sensitive information in attachments to email. Passwords shall not be communicated in the same email as the attachment. A sensitive information incident shall not, by itself, be interpreted as evidence that the Contractor has failed to provide adequate information security safeguards for sensitive information, or has otherwise failed to meet the requirements of the contract.

(2) If a sensitive information incident involves PII or SPII, in addition to the reporting requirements in 4300A Sensitive…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .